Help - Search - Members - Calendar
Full Version: Wlan Has Stopped Working Properly, But Is Getting Better
Suggest A Fix PC Support Forums > Security > Malicious Code: Viruses, Trojans, Spyware and Browser HiJacking
blueice
QUOTE

Hi Clive,

the forum seems to have an error in our thread. I posted an answer but never manage to access it again.

Please repost the latest combofix and RSIT report on a new thread in the forum. I will take it from there.

Chris

Wow these viruses are clever hailpraise.gif or is it that I'm just jinxed?

I ran the Avenger with the code you suggested but there was no log produced on restart. I checked with "rgedit" and there were no signs of the registry keys you put in the code so I think it did the job anyway.

Here are the latest combofix: -



ComboFix 09-11-01.04 - Rute 02/11/2009 19:40.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.256 [GMT 0:00]
Running from: c:\documents and settings\Rute\My Documents\1812\SpyWare\ComboFix\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\_004668_.tmp.dll
c:\windows\system32\_004669_.tmp.dll
c:\windows\system32\_004670_.tmp.dll
c:\windows\system32\_004671_.tmp.dll
c:\windows\system32\_004678_.tmp.dll
c:\windows\system32\_004679_.tmp.dll
c:\windows\system32\_004680_.tmp.dll
c:\windows\system32\_004681_.tmp.dll
c:\windows\system32\_004683_.tmp.dll
c:\windows\system32\_004684_.tmp.dll
c:\windows\system32\_004687_.tmp.dll
c:\windows\system32\_004688_.tmp.dll
c:\windows\system32\_004690_.tmp.dll
c:\windows\system32\_004691_.tmp.dll
c:\windows\system32\_004692_.tmp.dll
c:\windows\system32\_004694_.tmp.dll
c:\windows\system32\_004697_.tmp.dll
c:\windows\system32\_004698_.tmp.dll
c:\windows\system32\_004702_.tmp.dll
c:\windows\system32\_004703_.tmp.dll
c:\windows\system32\_004705_.tmp.dll
c:\windows\system32\_004708_.tmp.dll
c:\windows\system32\_004710_.tmp.dll
c:\windows\system32\_004711_.tmp.dll
c:\windows\system32\_004712_.tmp.dll
c:\windows\system32\_004713_.tmp.dll
c:\windows\system32\_004714_.tmp.dll
c:\windows\system32\_004717_.tmp.dll
c:\windows\system32\_004718_.tmp.dll
c:\windows\system32\_004719_.tmp.dll
c:\windows\system32\_004720_.tmp.dll
c:\windows\system32\_004721_.tmp.dll
c:\windows\system32\_004726_.tmp.dll
c:\windows\system32\_004728_.tmp.dll
c:\windows\system32\bios_setup114.txt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CDBGEVTSVC
-------\Legacy_SYSREST.SYS


((((((((((((((((((((((((( Files Created from 2009-10-02 to 2009-11-02 )))))))))))))))))))))))))))))))
.

2009-11-02 14:30 . 2009-11-02 14:31 -------- d-----w- c:\windows\ERUNT
2009-11-02 14:21 . 2009-11-02 14:45 -------- d-----w- C:\SDFix
2009-11-02 10:23 . 2009-11-02 10:25 -------- d-----w- C:\LinhaDefensiva
2009-11-02 00:32 . 2009-11-02 14:11 -------- d-----w- c:\program files\trend micro
2009-11-02 00:31 . 2009-11-02 00:32 -------- d-----w- C:\rsit
2009-11-01 22:38 . 2004-08-04 00:56 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-11-01 22:38 . 2001-08-17 22:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-11-01 22:38 . 2001-08-17 22:36 17408 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-11-01 22:38 . 2001-08-17 22:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-11-01 22:38 . 2001-08-17 22:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-11-01 22:37 . 2001-08-17 22:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2009-11-01 22:37 . 2001-08-17 12:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-11-01 22:37 . 2004-08-03 22:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-11-01 22:37 . 2004-08-03 22:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-11-01 22:35 . 2004-08-03 22:29 11935 -c--a-w- c:\windows\system32\dllcache\wadv11nt.sys
2009-11-01 22:34 . 2001-08-17 13:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys
2009-11-01 22:33 . 2001-08-17 22:36 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll
2009-11-01 22:32 . 2001-08-17 12:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys
2009-11-01 22:31 . 2001-08-17 22:36 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll
2009-11-01 22:30 . 2001-08-17 13:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2009-11-01 22:29 . 2001-08-17 22:36 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll
2009-11-01 22:28 . 2001-07-21 14:29 161568 -c--a-w- c:\windows\system32\dllcache\sgsmusb.sys
2009-11-01 22:27 . 2001-08-17 12:50 75392 -c--a-w- c:\windows\system32\dllcache\s3savmxm.sys
2009-11-01 22:26 . 2001-08-17 22:36 9216 -c--a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2009-11-01 22:26 . 2001-08-17 12:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys
2009-11-01 22:26 . 2004-08-03 22:59 79104 -c--a-w- c:\windows\system32\dllcache\rocket.sys
2009-11-01 22:26 . 2004-08-03 23:04 30080 -c--a-w- c:\windows\system32\dllcache\rndismpx.sys
2009-11-01 22:26 . 2001-08-17 12:12 37563 -c--a-w- c:\windows\system32\dllcache\rlnet5.sys
2009-11-01 22:26 . 2004-08-03 23:10 59648 -c--a-w- c:\windows\system32\dllcache\rfcomm.sys
2009-11-01 22:26 . 2001-08-17 22:36 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll
2009-11-01 22:26 . 2004-08-03 22:41 13776 -c--a-w- c:\windows\system32\dllcache\recagent.sys
2009-11-01 22:26 . 2001-08-17 13:28 714762 -c--a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2009-11-01 22:26 . 2001-08-17 13:28 899146 -c--a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2009-11-01 22:26 . 2001-08-17 22:36 41472 -c--a-w- c:\windows\system32\dllcache\qvusd.dll
2009-11-01 22:26 . 2001-08-17 13:53 3328 -c--a-w- c:\windows\system32\dllcache\qv2kux.sys
2009-11-01 22:26 . 2001-08-17 13:52 49024 -c--a-w- c:\windows\system32\dllcache\ql1280.sys
2009-11-01 22:24 . 2001-08-17 14:04 92416 -c--a-w- c:\windows\system32\dllcache\phildec.sys
2009-11-01 22:23 . 2001-08-17 14:05 25216 -c--a-w- c:\windows\system32\dllcache\ovsound2.sys
2009-11-01 22:22 . 2001-08-17 12:49 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2009-11-01 22:21 . 2001-08-17 14:56 35392 -c--a-w- c:\windows\system32\dllcache\n9i128.dll
2009-11-01 22:20 . 2001-08-17 14:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2009-11-01 22:20 . 2001-08-17 13:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys
2009-11-01 22:20 . 2001-08-17 13:52 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys
2009-11-01 22:20 . 2001-08-17 13:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys
2009-11-01 22:20 . 2001-08-17 13:52 6528 -c--a-w- c:\windows\system32\dllcache\miniqic.sys
2009-11-01 22:20 . 2001-08-17 12:50 320384 -c--a-w- c:\windows\system32\dllcache\mgaum.sys
2009-11-01 22:20 . 2001-08-17 14:56 235648 -c--a-w- c:\windows\system32\dllcache\mgaud.dll
2009-11-01 22:20 . 2004-08-03 23:00 26112 -c--a-w- c:\windows\system32\dllcache\memstpci.sys
2009-11-01 22:18 . 2004-08-03 22:59 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2009-11-01 22:18 . 2001-08-17 12:12 26442 -c--a-w- c:\windows\system32\dllcache\lanepic5.sys
2009-11-01 22:18 . 2001-08-17 12:12 19016 -c--a-w- c:\windows\system32\dllcache\ktc111.sys
2009-11-01 22:18 . 2001-08-17 22:36 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2009-11-01 22:18 . 2001-08-17 22:36 242176 -c--a-w- c:\windows\system32\dllcache\kdsusd.dll
2009-11-01 22:18 . 2001-08-17 22:36 45568 -c--a-w- c:\windows\system32\dllcache\kdsui.dll
2009-11-01 22:18 . 2001-08-17 22:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2009-11-01 22:18 . 2001-08-17 22:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-11-01 22:18 . 2004-08-03 22:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-11-01 22:18 . 2001-08-17 14:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2009-11-01 22:18 . 2001-08-17 14:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2009-11-01 22:18 . 2001-08-17 14:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2009-11-01 22:18 . 2001-08-17 14:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2009-11-01 22:17 . 2001-08-17 13:49 26624 -c--a-w- c:\windows\system32\dllcache\irstusb.sys
2009-11-01 22:17 . 2001-08-17 13:49 23552 -c--a-w- c:\windows\system32\dllcache\irmk7.sys
2009-11-01 22:17 . 2004-08-03 23:08 40832 -c--a-w- c:\windows\system32\dllcache\irbus.sys
2009-11-01 22:17 . 2001-08-17 12:12 45632 -c--a-w- c:\windows\system32\dllcache\ip5515.sys
2009-11-01 22:17 . 2001-08-17 22:36 90200 -c--a-w- c:\windows\system32\dllcache\io8ports.dll
2009-11-01 22:17 . 2001-08-17 13:50 38784 -c--a-w- c:\windows\system32\dllcache\io8.sys
2009-11-01 22:17 . 2004-08-03 22:59 5504 -c--a-w- c:\windows\system32\dllcache\intelide.sys
2009-11-01 22:17 . 2001-08-17 13:47 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2009-11-01 22:17 . 2001-08-17 13:52 16000 -c--a-w- c:\windows\system32\dllcache\ini910u.sys
2009-11-01 22:15 . 2004-08-03 22:41 1041536 -c--a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2009-11-01 22:15 . 2004-08-03 22:41 685056 -c--a-w- c:\windows\system32\dllcache\hsfcxts2.sys
2009-11-01 22:15 . 2004-08-04 00:56 32285 -c--a-w- c:\windows\system32\dllcache\hsfcisp2.dll
2009-11-01 22:15 . 2004-08-03 22:41 220032 -c--a-w- c:\windows\system32\dllcache\hsfbs2s2.sys
2009-11-01 22:15 . 2001-08-17 13:28 488383 -c--a-w- c:\windows\system32\dllcache\hsf_v124.sys
2009-11-01 22:15 . 2001-08-17 13:28 50751 -c--a-w- c:\windows\system32\dllcache\hsf_tone.sys
2009-11-01 22:15 . 2001-08-17 13:28 73279 -c--a-w- c:\windows\system32\dllcache\hsf_spkp.sys
2009-11-01 22:15 . 2001-08-17 13:28 44863 -c--a-w- c:\windows\system32\dllcache\hsf_soar.sys
2009-11-01 22:15 . 2001-08-17 13:28 57471 -c--a-w- c:\windows\system32\dllcache\hsf_samp.sys
2009-11-01 22:15 . 2001-08-17 13:28 542879 -c--a-w- c:\windows\system32\dllcache\hsf_msft.sys
2009-11-01 22:15 . 2001-08-17 13:28 391199 -c--a-w- c:\windows\system32\dllcache\hsf_k56k.sys
2009-11-01 22:15 . 2001-08-17 22:36 9759 -c--a-w- c:\windows\system32\dllcache\hsf_inst.dll
2009-11-01 22:13 . 2001-08-17 13:28 907456 -c--a-w- c:\windows\system32\dllcache\hcf_msft.sys
2009-11-01 22:12 . 2001-08-17 12:13 27165 -c--a-w- c:\windows\system32\dllcache\fetnd5.sys
2009-11-01 22:11 . 2001-08-17 12:12 18503 -c--a-w- c:\windows\system32\dllcache\epro4.sys
2009-11-01 22:10 . 2001-08-17 12:11 29696 -c--a-w- c:\windows\system32\dllcache\dm9pci5.sys
2009-11-01 22:09 . 2001-08-17 22:36 27648 -c--a-w- c:\windows\system32\dllcache\cyzports.dll
2009-11-01 22:08 . 2004-08-03 23:00 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2009-11-01 22:07 . 2001-08-17 22:36 41472 -c--a-w- c:\windows\system32\dllcache\brmfusb.dll
2009-11-01 22:06 . 2004-08-03 22:29 11615 -c--a-w- c:\windows\system32\dllcache\ati1mdxx.sys
2009-11-01 22:05 . 2001-08-17 14:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-11-01 22:04 . 2004-08-03 23:18 2148352 -c--a-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-01 19:15 . 2007-08-10 20:46 33656 ----a-w- c:\windows\system32\sprecovr.exe
2009-11-01 19:10 . 2006-02-28 12:00 98304 -c--a-w- c:\windows\system32\dllcache\wmpband.dll
2009-11-01 19:10 . 2006-02-28 12:00 786432 -c--a-w- c:\windows\system32\dllcache\migrate.exe
2009-11-01 19:10 . 2006-02-28 12:00 368640 -c--a-w- c:\windows\system32\dllcache\mpvis.dll
2009-11-01 19:10 . 2006-02-28 12:00 221184 -c--a-w- c:\windows\system32\dllcache\wmpns.dll
2009-11-01 19:10 . 2006-02-28 12:00 1001472 -c--a-w- c:\windows\system32\dllcache\wmvdmoe2.dll
2009-11-01 19:10 . 2006-02-28 12:00 1001472 ----a-w- c:\windows\system32\wmvdmoe2.dll
2009-11-01 19:10 . 2006-02-28 12:00 896512 -c--a-w- c:\windows\system32\dllcache\wmspdmoe.dll
2009-11-01 19:10 . 2006-02-28 12:00 896512 ----a-w- c:\windows\system32\wmspdmoe.dll
2009-11-01 19:10 . 2006-02-28 12:00 484864 -c--a-w- c:\windows\system32\dllcache\wmspdmod.dll
2009-11-01 19:10 . 2006-02-28 12:00 484864 ----a-w- c:\windows\system32\wmspdmod.dll
2009-11-01 19:10 . 2006-02-28 12:00 1119744 -c--a-w- c:\windows\system32\dllcache\wmsdmoe2.dll
2009-11-01 19:10 . 2006-02-28 12:00 1119744 ----a-w- c:\windows\system32\wmsdmoe2.dll
2009-11-01 19:08 . 2006-02-28 12:00 96768 -c--a-w- c:\windows\system32\dllcache\dpcdll.dll
2009-11-01 19:07 . 2006-02-28 12:00 84992 -c--a-w- c:\windows\system32\dllcache\wabimp.dll
2009-11-01 19:06 . 2006-02-28 12:00 94208 -c--a-w- c:\windows\system32\dllcache\odbcint.dll
2009-11-01 18:51 . 2009-11-01 18:56 -------- d-----w- C:\c54a6d05e83307ead7db2bd86b09
2009-11-01 11:22 . 2009-11-01 11:22 -------- d-----w- c:\program files\CCleaner
2009-10-31 20:28 . 2009-10-31 20:34 -------- d-----w- C:\ecdf583faca82bc123a6e40196
2009-10-31 19:26 . 2009-10-31 19:31 -------- d-----w- C:\a8a4fdb52b43ca7799
2009-10-31 17:43 . 2009-10-31 15:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-31 15:30 . 2009-10-31 15:30 -------- d-----w- C:\809ce48a9298ca6fef
2009-10-31 15:30 . 2009-10-31 15:30 -------- d-----w- C:\036cf94b026c6c1a2abf5f9e
2009-10-31 15:14 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-31 15:11 . 2009-10-31 15:11 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-31 15:10 . 2009-10-31 15:10 -------- d-----w- c:\program files\Lavasoft
2009-10-31 14:16 . 2009-10-31 14:16 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-31 14:11 . 2009-10-31 14:50 54 ----a-w- c:\windows\system32\rp_stats.dat
2009-10-31 14:11 . 2009-10-31 14:50 39 ----a-w- c:\windows\system32\rp_rules.dat
2009-10-31 13:36 . 2009-10-31 15:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-31 13:07 . 2009-10-31 13:12 -------- d-----w- C:\79dbf129e5766d58c21d
2009-10-31 12:49 . 2009-10-31 12:49 -------- d-----w- C:\a77b669a6bc9a21afaf97f36b4e048f5
2009-10-31 12:40 . 2009-11-01 22:55 -------- d-----w- c:\windows\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-01 11:21 . 2008-08-18 11:41 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-01 11:21 . 2008-08-18 11:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-30 11:13 . 2008-08-18 09:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-30 11:12 . 2008-08-18 09:34 -------- d-----w- c:\program files\SpywareBlaster
2009-10-30 10:23 . 2008-08-18 10:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-28 09:09 . 2008-01-12 10:50 -------- d-----w- c:\program files\Java
2009-09-25 18:50 . 2009-09-25 18:49 79 ----a-w- C:\adobereader.bat
2009-09-10 14:54 . 2008-08-18 10:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 . 2008-08-18 10:48 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2003-02-13 493024]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"D-Link Air Utility"="c:\program files\D-Link\Air Utility\AirCFG.exe" [2003-06-26 2695168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-28 149280]
"D-Link AirPlus G"="c:\program files\D-Link\AirPlus G\AirGCFG.exe" [2005-07-22 1519616]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-13 16239616]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2006-02-28 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cloudmark Desktop for Outlook Express.lnk - c:\windows\Installer\{5B0A00E4-2F9F-49C7-B9A1-9A8E136E8869}\SC_1.ico [2007-8-27 3638]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkp62.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winot52.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwd27.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R?2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [19/03/2002 11:15 36864]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/10/2009 15:14 64288]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [20/09/2002 16:29 53248]
R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [27/09/2002 17:21 22912]
S0 Cxq69;Cxq69; [x]
S0 Winkp62;Winkp62;c:\windows\system32\Drivers\Winkp62.sys --> c:\windows\system32\Drivers\Winkp62.sys [?]
S0 Winot52;Winot52;c:\windows\system32\Drivers\Winot52.sys --> c:\windows\system32\Drivers\Winot52.sys [?]
S0 Winwd27;Winwd27;c:\windows\system32\Drivers\Winwd27.sys --> c:\windows\system32\Drivers\Winwd27.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 11:17 1179232]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [20/09/2002 16:27 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [20/09/2002 16:41 77824]
S3 NETDLWL;D-Link Air Wireless Adapter(DL) NT Driver;c:\windows\system32\drivers\NETDLWL.sys [27/08/2007 06:00 159104]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBR
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder

2009-10-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 15:13]

2009-11-02 c:\windows\Tasks\Every week.job
- c:\windows\system32\ntbackup.exe [2009-11-01 12:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-02 19:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1324)
c:\documents and settings\Rute\Local Settings\Application Data\Cloudmark\SpamNet\snoew32h_1.dll
c:\windows\system32\msi.dll
.
Completion time: 2009-11-02 19:47
ComboFix-quarantined-files.txt 2009-11-02 19:47

Pre-Run: 27,807,186,944 bytes free
Post-Run: 27,777,159,168 bytes free

- - End Of File - - 5B22E68439ECD08BCD2C7AE01D1BA63D


and RSIT report: -

Logfile of random's system information tool 1.06 (written by random/random)
Run by Rute at 2009-11-02 19:49:24
Microsoft Windows XP Professional Service Pack 2
System drive C: has 27 GB (69%) free of 38 GB
Total RAM: 502 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:49:27, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Cloudmark\SpamNet\OE\snoe.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Rute\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Rute.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Cloudmark Desktop for Outlook Express.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1199792268796
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\System32\brsvc01a.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe

--
End of file - 5884 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Every week.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-28 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"=C:\PROGRA~1\CA\ETRUST~1\realmon.exe [2003-02-13 493024]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648]
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2004-04-14 57393]
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2004-04-14 40960]
"D-Link Air Utility"=C:\Program Files\D-Link\Air Utility\AirCFG.exe [2003-06-26 2695168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-13 16239616]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2006-03-23 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2006-03-23 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2006-03-23 118784]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-28 149280]
"D-Link AirPlus G"=C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [2005-07-22 1519616]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2004-12-16 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cloudmark Desktop for Outlook Express.lnk - C:\WINDOWS\Installer\{5B0A00E4-2F9F-49C7-B9A1-9A8E136E8869}\SC_1.ico
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-03-23 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-02-28 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkp62.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winot52.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwd27.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkp62.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winot52.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwd27.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======List of files/folders created in the last 1 months======

2009-11-02 19:47:56 ----D---- C:\WINDOWS\temp
2009-11-02 19:47:54 ----A---- C:\ComboFix.txt
2009-11-02 19:47:53 ----A---- C:\log.txt
2009-11-02 19:24:25 ----A---- C:\WINDOWS\zip.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWSC.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWREG.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\sed.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\PEV.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\NIRCMD.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\MBR.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\grep.exe
2009-11-02 19:24:20 ----D---- C:\WINDOWS\ERDNT
2009-11-02 19:23:16 ----D---- C:\Qoobox
2009-11-02 14:30:59 ----D---- C:\WINDOWS\ERUNT
2009-11-02 14:21:25 ----D---- C:\SDFix
2009-11-02 10:45:07 ----D---- C:\Avenger
2009-11-02 10:45:06 ----A---- C:\avenger.txt
2009-11-02 10:23:58 ----D---- C:\LinhaDefensiva
2009-11-02 00:32:01 ----D---- C:\Program Files\trend micro
2009-11-02 00:31:58 ----D---- C:\rsit
2009-11-01 19:16:40 ----A---- C:\WINDOWS\system32\SET145.tmp
2009-11-01 19:16:37 ----D---- C:\WINDOWS\network diagnostic
2009-11-01 19:15:39 ----A---- C:\WINDOWS\system32\sprecovr.exe
2009-11-01 19:12:33 ----A---- C:\WINDOWS\002988_.tmp
2009-11-01 19:10:01 ----A---- C:\WINDOWS\system32\wmvdmoe2.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmoe.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmod.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmsdmoe2.dll
2009-11-01 19:09:59 ----N---- C:\WINDOWS\system32\mspmsnsv.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpasf.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmp.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmidx.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmerror.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp4sdmod.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp43dmod.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_32.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\hccoin.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\fsquirt.exe
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthserv.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthci.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wshbth.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wlanapi.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\sdhcinst.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-11-01 19:09:27 ----A---- C:\WINDOWS\system32\pidgen.dll
2009-11-01 19:09:25 ----A---- C:\WINDOWS\system32\spiisupd.exe
2009-11-01 19:09:18 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\secedit.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\dpcdll.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\p2pgasvc.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\kbdukx.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\dxdiagn.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\xpsp2res.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\encdec.dll
2009-11-01 19:08:54 ----N---- C:\WINDOWS\system32\wscntfy.exe
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\pnrpnsp.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\dsprpres.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\w3ssl.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\p2psvc.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\p2pgraph.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\msftedit.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdsmsno.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdfi1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbeio.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbe.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\msdadiag.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\kbdmlt47.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-11-01 19:08:50 ----A---- C:\WINDOWS\system32\httpapi.dll
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\smbinst.exe
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\iuengine.dll
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\fwcfg.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\mssap.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\d3d9.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\xmlprov.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\qmgr.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\xmlprovi.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\winbrand.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\twext.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\spnpinst.exe
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\p2pnetsh.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinmal.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\cmsetacl.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\powercfg.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\kbdsmsfi.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\fltmc.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\btpanui.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\xpsp1res.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\wscsvc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winshfhc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winhttp.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\p2p.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdno1.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdmlt48.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\encapi.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\auditusr.exe
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\xpob2res.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdmaori.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdinben.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\blastcln.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\gpresult.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventcreate.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\driverquery.exe
2009-11-01 19:08:40 ----N---- C:\WINDOWS\system32\appmgmts.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\systeminfo.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\schtasks.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\openfiles.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\appmgr.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\adsnw.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\gpedit.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\getmac.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fdeploy.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fde.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\efsadu.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\cipher.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\bootcfg.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2009-11-01 19:08:38 ----A---- C:\WINDOWS\system32\gptext.dll
2009-11-01 19:08:37 ----A---- C:\WINDOWS\system32\logman.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrtdep.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrt.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqqm.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqoa.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqise.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqdscli.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqbkup.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqad.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwwks.dll
blueice
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwapi32.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\ntbackup.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqutil.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqupgrd.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtrig.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsnap.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsec.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tracerpt.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvrp.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsess.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tasklist.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\taskkill.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\rsnotify.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\proxycfg.exe
2009-11-01 19:08:33 ----A---- C:\WINDOWS\system32\wsecedit.dll
2009-11-01 19:07:50 ----N---- C:\WINDOWS\explorer.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\winhlp32.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\twain_32.dll
2009-11-01 19:07:49 ----A---- C:\WINDOWS\regedit.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\hh.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\activeds.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\aclui.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\6to4svc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\amstream.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alrsvc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alg.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\ahui.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\advpack.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsnt.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsmsext.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldpc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldp.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\admparse.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actxprxy.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actmovie.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmfd.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmadm.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atl.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\at.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asycfilt.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asferror.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\apphelp.dll
2009-11-01 19:07:44 ----N---- C:\WINDOWS\system32\browser.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabview.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabinet.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browsewm.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browseui.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browselc.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\blackbox.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\bidispl.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batt.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batmeter.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\basesrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\avifil32.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autolfn.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autofmt.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\authz.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\audiosrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\attrib.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certmgr.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certcli.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdosys.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdfview.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\capesnpn.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\camocx.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdl32.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdial32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmcfg32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clusapi.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipsrv.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cisvc.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\ciodm.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cic.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgmgr32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cewmdm.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmmon32.exe
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comres.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compstui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compatui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\colbact.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon2.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmutil.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmstp.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\credui.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\corpol.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\conime.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\confmsp.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\comuid.dll
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\ctfmon.exe
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\cryptsvc.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\d3d8.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\csrss.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscript.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptnet.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptext.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\crypt32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\ddeshare.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dciman32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnmpntw.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnetlib.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbmsrpcn.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbghelp.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\davclnt.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\datime.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dataclen.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\danim.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3dim700.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3d8thk.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\diantz.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dhcpmon.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dgnet.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfsshlex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgui.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgsnap.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devmgr.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devenum.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\defrag.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddrawex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddraw.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmband.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmadmin.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dllhost.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dispex.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskpart.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskcopy.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput8.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\digest.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplayx.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\docprop2.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsapi.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmutil.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmusic.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmsynth.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmstyle.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmserver.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmscript.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmremote.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmloader.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmime.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdskmgr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdlgs.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmcompos.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\ds32gt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drprov.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmstor.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmclien.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpwsockx.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvvox.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvoice.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvacm.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnet.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpmodemx.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsquery.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsprop.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound3d.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquoui.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquota.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmoprp.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmo.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx8vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx7vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dwwin.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\duser.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dumprep.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dswave.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dsuiext.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssenh.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssec.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\eventlog.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\es.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\eudcedit.exe
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\esent.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\ersvc.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\els.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxmasf.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxdiag.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\gdi32.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\framebuf.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\forcedos.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontview.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontsub.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontext.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fldrclnr.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\findstr.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\filemgmt.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\feclient.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\faultrep.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\exts.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\extrac32.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\expsrv.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hnetcfg.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hlink.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hid.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hhsetup.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\help.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\h323msp.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\grpconv.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\gpkrsrc.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\glu32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icmp.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icm32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iccvid.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iasrad.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\htui.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hotplug.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hnetwiz.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iepeers.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\idq.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-11-01 19:07:25 ----N---- C:\WINDOWS\system32\imm32.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imeshare.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imapi.exe
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ils.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\igmpagnt.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ifmon.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\iexpress.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipmontr.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\iphlpapi.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipconfig.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\input.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\initpki.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetres.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetppui.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetpp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetmib1.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipxroute.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6mon.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsmsnap.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsvc.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsnp.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ippromon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ixsso.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itss.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itircl.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isign32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irmon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irftp.exe
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ipxwan.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\keymgr.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kerberos.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kd1394.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kbdnec.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jscript.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgpl400.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgdw400.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lsass.exe
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lpk.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\linkinfo.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\magnify.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lprhelp.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logonui.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logagent.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localui.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localsec.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\loadperf.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lmrt.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licdll.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\laprxy.dll
2009-11-01 19:07:19 ----N---- C:\WINDOWS\system32\mfc40u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\miglibnt.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\midimap.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfcsubs.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mf3216.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mdminst.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciwave.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciseq.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciqtz32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciavi32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mcastmib.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\makecab.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcshext.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcbase.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmc.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mlang.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mimefilt.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mprapi.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpr.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpg4dmod.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\moricons.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\more.com
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\modemui.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msdart.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctfp.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpxl32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpx32r.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msconf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscms.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msasn1.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msapsspc.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msafd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msacm32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mprdim.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdmo.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\mshta.exe
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msgina.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexcl40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexch40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msdxmlc.dll
2009-11-01 19:07:12 ----N---- C:\WINDOWS\system32\mshtml.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msieftp.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msidle.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msident.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msi.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimg32.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjter40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjint40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjetoledb40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjet40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msisip.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msiregmv.exe
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msimtf.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspatcha.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorcl32.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorc32r.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnsspc.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnetobj.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msltus40.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mslbui.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msjtes40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrepl40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd3x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd2x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrating.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msprivs.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspmsp.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspbde40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstime.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstext40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstask.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msscp.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msrle32.dll
2009-11-01 19:07:06 ----N---- C:\WINDOWS\system32\msvcrt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvfw32.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcrt40.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcp60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcirt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvbvm60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msutb.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\mstlsapi.dll
2009-11-01 19:07:05 ----N---- C:\WINDOWS\system32\mswsock.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswmdm.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswebdvd.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswdat10.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msw3prt.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msvidctl.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mtxclu.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msyuv.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml3.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml2.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxbde40.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mswstr10.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\netapi32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net1.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddenb32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapir.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\ncobjapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\narrator.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mydocs.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netman.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netlogon.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netsetup.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netrap.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netplwiz.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netid.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netdde.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netcfgx.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntlanman.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntdsapi.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\npptools.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\notepad.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nlhtml.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\newdev.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui1.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui0.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netstat.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netshell.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netsh.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\notepad.exe
2009-11-01 19:07:00 ----N---- C:\WINDOWS\system32\ntmssvc.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\occache.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\objsel.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\oakley.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntvdmd.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntshrui.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsmgr.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsdba.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsapi.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmarta.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcp32r.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcjt32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcji32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcint.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccu32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccr32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccp32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcbcp.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcad32.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32gt.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\ocmanage.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\packager.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osuninst.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osk.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\opengl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olepro32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oleprn.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oledlg.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olecli32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\ole32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\offfilt.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odtext32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odpdx32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odfox32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odexl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oddbse32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odbctrac.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\polstore.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pjlmon.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\ping.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pid.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\photowiz.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfproc.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfos.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfnet.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfmon.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfdisk.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pdh.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pautoenr.dll
2009-11-01 19:06:56 ----N---- C:\WINDOWS\system32\powrprof.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorsvc.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorec.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psisdecd.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psbase.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psapi.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\proquota.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\progman.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\profmap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedwipes.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedit.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdvd.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdv.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qcap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qasf.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\query.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\quartz.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpdd.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcp.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcimlby.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rastls.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rassapi.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasppp.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasphone.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasmans.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\raschap.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2009-11-01 19:06:52 ----N---- C:\WINDOWS\system32\regsvc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\riched20.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rexec.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\resutils.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regwizc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regsvr32.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regapi.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\reg.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\scecli.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\rpcss.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scesrv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\sccsccp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scarddlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\runonce.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rundll32.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtutils.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtipxmib.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtcshare.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsmps.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsh.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsaenh.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\sfc.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\schedsvc.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\setup.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sethc.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sensapi.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sens.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendmail.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendcmsg.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\security.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\secur32.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\seclogon.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sdbinst.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrrun.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrobj.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sclgntfy.dll
2009-11-01 19:06:49 ----N---- C:\WINDOWS\system32\sfcfiles.dll
2009-11-01 19:06:49 ----A---- C:\WINDOWS\system32\sfc_os.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdoclc.dll
2009-11-01 19:06:47 ----A---- C:\WINDOWS\system32\shell32.dll
2009-11-01 19:06:46 ----N---- C:\WINDOWS\system32\shsvcs.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\smlogcfg.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slbiop.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slayerxp.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\skeys.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigverif.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigtab.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shutdown.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shscrap.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shrpubw.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmgrate.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmedia.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shlwapi.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimgvw.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimeng.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shgina.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shfolder.dll
2009-11-01 19:06:45 ----N---- C:\WINDOWS\system32\spoolsv.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlunirl.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spoolss.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spider.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sort.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpsnap.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpapi.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\ssdpsrv.dll
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\srsvc.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-11-01 19:06:43 ----N---- C:\WINDOWS\system32\svchost.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\strmdll.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\storprop.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stobject.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stimon.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti_ci.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stclient.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi32.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi3.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\t2embed.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\syncui.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\synceng.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sxs.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\termsrv.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\tapisrv.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tsddd.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\trkwks.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tree.com
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tracert.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tourstart.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\themeui.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\termmgr.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\telnet.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmon.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmib.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\taskmgr.exe
2009-11-01 19:06:40 ----N---- C:\WINDOWS\system32\upnphost.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\url.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\ups.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpui.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpcont.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnp.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\uniplat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\unimdmat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umandlg.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\udhisapi.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\txflog.dll
2009-11-01 19:06:39 ----N---- C:\WINDOWS\system32\user32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\vbajet32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\utilman.exe
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usp10.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\userenv.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbui.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbmon.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webvw.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webclnt.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wdigest.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wavemsp.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\w32time.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssvc.exe
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssapi.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\version.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\verifier.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmredir.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmdbg.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vbscript.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaservc.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiascr.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadss.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadefui.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wextract.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\winlogon.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\wininet.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winsrv.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winscard.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winrnr.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winntbbu.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winmm.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winipsec.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiavideo.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiashext.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wlnotify.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wldap32.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winver.exe
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wintrust.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winsta.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmasf.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmoe.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmstream.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpui.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpshell.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmploc.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcore.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcd.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmnetmgr.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmi.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmps.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2009-11-01 19:06:32 ----N---- C:\WINDOWS\system32\ws2_32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wship6.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshext.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshcon.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wscript.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\ws2help.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpabaln.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wow32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvdmod.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvcore.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\zipfldr.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xcopy.exe
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xactsrv.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsvc.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsapi.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcdlg.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wtsapi32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wstdecod.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsock32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsnmp32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshtcpip.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshrm.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autoconv.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autochk.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\advapi32.dll
2009-11-01 19:06:28 ----N---- C:\WINDOWS\system32\comctl32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\format.com
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\csrsrv.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\comdlg32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cmd.exe
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cacls.exe
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\msgsvc.dll
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntprint.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntlsapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntdll.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\nslookup.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\msv1_0.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lsasrv.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\locator.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\localspl.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lmhsvc.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\imagehlp.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ftp.exe
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rshx32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rastapi.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasman.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasdlg.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasauto.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasapi32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\printui.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\perfctrs
Ironbender
<<Continued from http://www.suggestafix.com/index.php?showtopic=34046>>

Glad you could read my instructions. I'm still unable to access the previous thread. smile.gif

Please post a fresh RSIT log and let me know how is your system running.

Chris
blueice
QUOTE(Ironbender @ Nov 2 2009, 11:40 PM) *

Please post a fresh RSIT log and let me know how is your system running.

Chris

The system still keeps closing down Chris; although it does seem to be less regular unsure.gif Here goes with the latest RSIT: -

Logfile of random's system information tool 1.06 (written by random/random)
Run by Rute at 2009-11-02 23:54:46
Microsoft Windows XP Professional Service Pack 2
System drive C: has 27 GB (70%) free of 38 GB
Total RAM: 502 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:49, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Cloudmark\SpamNet\OE\snoe.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Rute\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Rute.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Cloudmark Desktop for Outlook Express.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1199792268796
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\System32\brsvc01a.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe

--
End of file - 6193 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Every week.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-28 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"=C:\PROGRA~1\CA\ETRUST~1\realmon.exe [2003-02-13 493024]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648]
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2004-04-14 57393]
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2004-04-14 40960]
"D-Link Air Utility"=C:\Program Files\D-Link\Air Utility\AirCFG.exe [2003-06-26 2695168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-13 16239616]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2006-03-23 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2006-03-23 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2006-03-23 118784]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-28 149280]
"D-Link AirPlus G"=C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [2005-07-22 1519616]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2004-12-16 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cloudmark Desktop for Outlook Express.lnk - C:\WINDOWS\Installer\{5B0A00E4-2F9F-49C7-B9A1-9A8E136E8869}\SC_1.ico
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-03-23 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-02-28 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkp62.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winot52.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwd27.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======List of files/folders created in the last 1 months======

2009-11-02 21:12:16 ----A---- C:\avenger.txt
2009-11-02 21:11:12 ----A---- C:\zip.exe
2009-11-02 21:11:12 ----A---- C:\cleanup.exe
2009-11-02 21:11:12 ----A---- C:\cleanup.bat
2009-11-02 19:47:56 ----D---- C:\WINDOWS\temp
2009-11-02 19:47:54 ----A---- C:\ComboFix.txt
2009-11-02 19:47:53 ----A---- C:\log.txt
2009-11-02 19:24:25 ----A---- C:\WINDOWS\zip.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWSC.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\SWREG.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\sed.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\PEV.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\NIRCMD.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\MBR.exe
2009-11-02 19:24:25 ----A---- C:\WINDOWS\grep.exe
2009-11-02 19:24:20 ----D---- C:\WINDOWS\ERDNT
2009-11-02 19:23:16 ----D---- C:\Qoobox
2009-11-02 14:30:59 ----D---- C:\WINDOWS\ERUNT
2009-11-02 14:21:25 ----D---- C:\SDFix
2009-11-02 10:45:07 ----D---- C:\Avenger
2009-11-02 10:23:58 ----D---- C:\LinhaDefensiva
2009-11-02 00:32:01 ----D---- C:\Program Files\trend micro
2009-11-02 00:31:58 ----D---- C:\rsit
2009-11-01 19:16:40 ----A---- C:\WINDOWS\system32\SET145.tmp
2009-11-01 19:16:37 ----D---- C:\WINDOWS\network diagnostic
2009-11-01 19:15:39 ----A---- C:\WINDOWS\system32\sprecovr.exe
2009-11-01 19:12:33 ----A---- C:\WINDOWS\002988_.tmp
2009-11-01 19:10:01 ----A---- C:\WINDOWS\system32\wmvdmoe2.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmoe.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmod.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmsdmoe2.dll
2009-11-01 19:09:59 ----N---- C:\WINDOWS\system32\mspmsnsv.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpasf.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmp.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmidx.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmerror.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp4sdmod.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp43dmod.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_32.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\hccoin.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\fsquirt.exe
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthserv.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthci.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wshbth.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wlanapi.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\sdhcinst.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-11-01 19:09:27 ----A---- C:\WINDOWS\system32\pidgen.dll
2009-11-01 19:09:25 ----A---- C:\WINDOWS\system32\spiisupd.exe
2009-11-01 19:09:18 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\secedit.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\dpcdll.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\p2pgasvc.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\kbdukx.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\dxdiagn.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\xpsp2res.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\encdec.dll
2009-11-01 19:08:54 ----N---- C:\WINDOWS\system32\wscntfy.exe
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\pnrpnsp.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\dsprpres.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\w3ssl.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\p2psvc.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\p2pgraph.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\msftedit.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdsmsno.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdfi1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbeio.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbe.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\msdadiag.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\kbdmlt47.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-11-01 19:08:50 ----A---- C:\WINDOWS\system32\httpapi.dll
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\smbinst.exe
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\iuengine.dll
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\fwcfg.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\mssap.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\d3d9.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\xmlprov.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\qmgr.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\xmlprovi.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\winbrand.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\twext.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\spnpinst.exe
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\p2pnetsh.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinmal.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\cmsetacl.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\powercfg.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\kbdsmsfi.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\fltmc.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\btpanui.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\xpsp1res.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\wscsvc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winshfhc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winhttp.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\p2p.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdno1.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdmlt48.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\encapi.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\auditusr.exe
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\xpob2res.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdmaori.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdinben.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\blastcln.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\gpresult.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventcreate.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\driverquery.exe
2009-11-01 19:08:40 ----N---- C:\WINDOWS\system32\appmgmts.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\systeminfo.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\schtasks.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\openfiles.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\appmgr.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\adsnw.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\gpedit.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\getmac.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fdeploy.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fde.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\efsadu.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\cipher.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\bootcfg.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2009-11-01 19:08:38 ----A---- C:\WINDOWS\system32\gptext.dll
2009-11-01 19:08:37 ----A---- C:\WINDOWS\system32\logman.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrtdep.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrt.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqqm.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqoa.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqise.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqdscli.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqbkup.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqad.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwwks.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwapi32.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\ntbackup.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqutil.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqupgrd.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtrig.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsnap.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsec.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tracerpt.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvrp.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsess.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tasklist.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\taskkill.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\rsnotify.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\proxycfg.exe
2009-11-01 19:08:33 ----A---- C:\WINDOWS\system32\wsecedit.dll
2009-11-01 19:07:50 ----N---- C:\WINDOWS\explorer.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\winhlp32.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\twain_32.dll
2009-11-01 19:07:49 ----A---- C:\WINDOWS\regedit.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\hh.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\activeds.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\aclui.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\6to4svc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\amstream.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alrsvc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alg.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\ahui.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\advpack.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsnt.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsmsext.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldpc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldp.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\admparse.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actxprxy.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actmovie.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmfd.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmadm.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atl.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\at.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asycfilt.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asferror.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\apphelp.dll
2009-11-01 19:07:44 ----N---- C:\WINDOWS\system32\browser.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabview.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabinet.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browsewm.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browseui.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browselc.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\blackbox.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\bidispl.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batt.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batmeter.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\basesrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\avifil32.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autolfn.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autofmt.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\authz.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\audiosrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\attrib.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certmgr.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certcli.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdosys.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdfview.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\capesnpn.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\camocx.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdl32.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdial32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmcfg32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clusapi.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipsrv.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cisvc.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\ciodm.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cic.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgmgr32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cewmdm.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmmon32.exe
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comres.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compstui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compatui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\colbact.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon2.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmutil.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmstp.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\credui.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\corpol.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\conime.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\confmsp.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\comuid.dll
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\ctfmon.exe
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\cryptsvc.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\d3d8.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\csrss.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscript.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptnet.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptext.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\crypt32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\ddeshare.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dciman32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnmpntw.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnetlib.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbmsrpcn.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbghelp.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\davclnt.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\datime.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dataclen.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\danim.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3dim700.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3d8thk.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\diantz.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dhcpmon.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dgnet.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfsshlex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgui.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgsnap.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devmgr.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devenum.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\defrag.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddrawex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddraw.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmband.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmadmin.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dllhost.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dispex.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskpart.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskcopy.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput8.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\digest.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplayx.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\docprop2.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsapi.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmutil.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmusic.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmsynth.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmstyle.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmserver.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmscript.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmremote.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmloader.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmime.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdskmgr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdlgs.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmcompos.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\ds32gt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drprov.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmstor.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmclien.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpwsockx.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvvox.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvoice.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvacm.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnet.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpmodemx.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsquery.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsprop.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound3d.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquoui.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquota.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmoprp.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmo.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx8vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx7vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dwwin.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\duser.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dumprep.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dswave.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dsuiext.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssenh.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssec.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\eventlog.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\es.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\eudcedit.exe
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\esent.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\ersvc.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\els.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxmasf.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxdiag.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\gdi32.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\framebuf.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\forcedos.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontview.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontsub.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontext.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fldrclnr.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\findstr.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\filemgmt.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\feclient.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\faultrep.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\exts.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\extrac32.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\expsrv.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hnetcfg.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hlink.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hid.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hhsetup.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\help.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\h323msp.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\grpconv.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\gpkrsrc.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\glu32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icmp.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icm32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iccvid.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iasrad.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\htui.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hotplug.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hnetwiz.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iepeers.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\idq.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-11-01 19:07:25 ----N---- C:\WINDOWS\system32\imm32.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imeshare.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imapi.exe
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ils.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\igmpagnt.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ifmon.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\iexpress.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipmontr.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\iphlpapi.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipconfig.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\input.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\initpki.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetres.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetppui.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetpp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetmib1.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipxroute.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6mon.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsmsnap.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsvc.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsnp.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ippromon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ixsso.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itss.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itircl.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isign32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irmon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irftp.exe
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ipxwan.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\keymgr.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kerberos.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kd1394.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kbdnec.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jscript.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgpl400.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgdw400.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lsass.exe
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lpk.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\linkinfo.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\magnify.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lprhelp.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logonui.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logagent.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localui.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localsec.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\loadperf.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lmrt.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licdll.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\laprxy.dll
2009-11-01 19:07:19 ----N---- C:\WINDOWS\system32\mfc40u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\miglibnt.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\midimap.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfcsubs.dll
blueice
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mf3216.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mdminst.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciwave.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciseq.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciqtz32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciavi32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mcastmib.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\makecab.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcshext.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcbase.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmc.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mlang.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mimefilt.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mprapi.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpr.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpg4dmod.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\moricons.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\more.com
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\modemui.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msdart.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctfp.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpxl32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpx32r.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msconf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscms.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msasn1.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msapsspc.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msafd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msacm32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mprdim.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdmo.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\mshta.exe
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msgina.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexcl40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexch40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msdxmlc.dll
2009-11-01 19:07:12 ----N---- C:\WINDOWS\system32\mshtml.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msieftp.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msidle.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msident.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msi.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimg32.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjter40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjint40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjetoledb40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjet40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msisip.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msiregmv.exe
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msimtf.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspatcha.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorcl32.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorc32r.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnsspc.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnetobj.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msltus40.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mslbui.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msjtes40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrepl40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd3x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd2x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrating.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msprivs.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspmsp.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspbde40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstime.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstext40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstask.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msscp.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msrle32.dll
2009-11-01 19:07:06 ----N---- C:\WINDOWS\system32\msvcrt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvfw32.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcrt40.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcp60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcirt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvbvm60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msutb.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\mstlsapi.dll
2009-11-01 19:07:05 ----N---- C:\WINDOWS\system32\mswsock.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswmdm.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswebdvd.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswdat10.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msw3prt.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msvidctl.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mtxclu.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msyuv.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml3.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml2.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxbde40.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mswstr10.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\netapi32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net1.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddenb32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapir.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\ncobjapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\narrator.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mydocs.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netman.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netlogon.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netsetup.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netrap.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netplwiz.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netid.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netdde.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netcfgx.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntlanman.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntdsapi.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\npptools.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\notepad.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nlhtml.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\newdev.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui1.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui0.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netstat.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netshell.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netsh.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\notepad.exe
2009-11-01 19:07:00 ----N---- C:\WINDOWS\system32\ntmssvc.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\occache.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\objsel.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\oakley.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntvdmd.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntshrui.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsmgr.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsdba.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsapi.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmarta.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcp32r.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcjt32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcji32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcint.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccu32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccr32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccp32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcbcp.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcad32.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32gt.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\ocmanage.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\packager.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osuninst.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osk.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\opengl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olepro32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oleprn.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oledlg.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olecli32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\ole32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\offfilt.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odtext32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odpdx32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odfox32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odexl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oddbse32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odbctrac.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\polstore.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pjlmon.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\ping.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pid.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\photowiz.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfproc.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfos.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfnet.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfmon.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfdisk.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pdh.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pautoenr.dll
2009-11-01 19:06:56 ----N---- C:\WINDOWS\system32\powrprof.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorsvc.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorec.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psisdecd.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psbase.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psapi.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\proquota.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\progman.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\profmap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedwipes.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedit.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdvd.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdv.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qcap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qasf.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\query.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\quartz.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpdd.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcp.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcimlby.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rastls.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rassapi.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasppp.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasphone.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasmans.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\raschap.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2009-11-01 19:06:52 ----N---- C:\WINDOWS\system32\regsvc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\riched20.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rexec.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\resutils.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regwizc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regsvr32.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regapi.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\reg.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\scecli.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\rpcss.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scesrv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\sccsccp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scarddlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\runonce.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rundll32.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtutils.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtipxmib.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtcshare.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsmps.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsh.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsaenh.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\sfc.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\schedsvc.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\setup.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sethc.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sensapi.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sens.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendmail.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendcmsg.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\security.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\secur32.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\seclogon.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sdbinst.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrrun.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrobj.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sclgntfy.dll
2009-11-01 19:06:49 ----N---- C:\WINDOWS\system32\sfcfiles.dll
2009-11-01 19:06:49 ----A---- C:\WINDOWS\system32\sfc_os.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdoclc.dll
2009-11-01 19:06:47 ----A---- C:\WINDOWS\system32\shell32.dll
2009-11-01 19:06:46 ----N---- C:\WINDOWS\system32\shsvcs.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\smlogcfg.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slbiop.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slayerxp.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\skeys.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigverif.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigtab.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shutdown.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shscrap.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shrpubw.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmgrate.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmedia.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shlwapi.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimgvw.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimeng.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shgina.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shfolder.dll
2009-11-01 19:06:45 ----N---- C:\WINDOWS\system32\spoolsv.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlunirl.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spoolss.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spider.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sort.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpsnap.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpapi.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\ssdpsrv.dll
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\srsvc.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-11-01 19:06:43 ----N---- C:\WINDOWS\system32\svchost.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\strmdll.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\storprop.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stobject.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stimon.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti_ci.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stclient.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi32.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi3.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\t2embed.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\syncui.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\synceng.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sxs.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\termsrv.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\tapisrv.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tsddd.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\trkwks.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tree.com
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tracert.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tourstart.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\themeui.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\termmgr.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\telnet.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmon.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmib.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\taskmgr.exe
2009-11-01 19:06:40 ----N---- C:\WINDOWS\system32\upnphost.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\url.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\ups.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpui.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpcont.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnp.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\uniplat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\unimdmat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umandlg.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\udhisapi.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\txflog.dll
2009-11-01 19:06:39 ----N---- C:\WINDOWS\system32\user32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\vbajet32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\utilman.exe
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usp10.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\userenv.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbui.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbmon.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webvw.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webclnt.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wdigest.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wavemsp.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\w32time.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssvc.exe
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssapi.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\version.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\verifier.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmredir.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmdbg.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vbscript.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaservc.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiascr.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadss.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadefui.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wextract.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\winlogon.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\wininet.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winsrv.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winscard.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winrnr.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winntbbu.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winmm.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winipsec.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiavideo.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiashext.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wlnotify.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wldap32.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winver.exe
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wintrust.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winsta.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmasf.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmoe.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmstream.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpui.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpshell.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmploc.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcore.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcd.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmnetmgr.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmi.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmps.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2009-11-01 19:06:32 ----N---- C:\WINDOWS\system32\ws2_32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wship6.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshext.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshcon.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wscript.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\ws2help.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpabaln.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wow32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvdmod.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvcore.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\zipfldr.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xcopy.exe
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xactsrv.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsvc.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsapi.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcdlg.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wtsapi32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wstdecod.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsock32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsnmp32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshtcpip.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshrm.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autoconv.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autochk.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\advapi32.dll
2009-11-01 19:06:28 ----N---- C:\WINDOWS\system32\comctl32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\format.com
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\csrsrv.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\comdlg32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cmd.exe
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cacls.exe
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\msgsvc.dll
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntprint.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntlsapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntdll.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\nslookup.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\msv1_0.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lsasrv.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\locator.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\localspl.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lmhsvc.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\imagehlp.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ftp.exe
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rshx32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rastapi.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasman.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasdlg.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasauto.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasapi32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\printui.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\perfctrs.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\olecnv32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\oleaut32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\nwprovau.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\ntvdm.exe
2009-11-01 19:06:25 ----N---- C:\WINDOWS\system32\services.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\setupapi.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\schannel.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\scardsvr.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\savedump.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\samsrv.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\samlib.dll
2009-11-01 19:06:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2009-11-01 19:06:24 ----A---- C:\WINDOWS\system32\smss.exe
2009-11-01 19:06:23 ----N---- C:\WINDOWS\system32\userinit.exe
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\wkssvc.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\win32spl.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\untfs.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\ulib.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\tcpmonui.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\syssetup.dll
2009-11-01 19:06:17 ----N---- C:\WINDOWS\system32\ntoskrnl.exe
2009-11-01 19:06:17 ----N---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\mspmspsv.dll
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\hal.dll
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\asfsipc.dll
2009-11-01 19:05:54 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-11-01 18:51:57 ----D---- C:\c54a6d05e83307ead7db2bd86b09
2009-11-01 11:22:32 ----D---- C:\Program Files\CCleaner
2009-10-31 20:28:08 ----D---- C:\ecdf583faca82bc123a6e40196
2009-10-31 19:26:53 ----D---- C:\a8a4fdb52b43ca7799
2009-10-31 17:43:03 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-10-31 15:30:46 ----D---- C:\809ce48a9298ca6fef
2009-10-31 15:30:22 ----D---- C:\036cf94b026c6c1a2abf5f9e
2009-10-31 15:11:23 ----HDC---- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-31 15:10:30 ----D---- C:\Program Files\Lavasoft
2009-10-31 14:08:59 ----D---- C:\Config.Msi
2009-10-31 13:36:15 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-10-31 13:07:20 ----D---- C:\79dbf129e5766d58c21d
2009-10-31 12:49:11 ----D---- C:\a77b669a6bc9a21afaf97f36b4e048f5
2009-10-31 12:40:48 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-10-31 12:34:57 ----D---- C:\272288eb39584362c97bff20419ad220
2009-10-30 09:36:53 ----D---- C:\WINDOWS\system32\appmgmt
2009-10-30 09:33:26 ----D---- C:\WINDOWS\OvtCam
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\java.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\deploytk.dll

======List of files/folders modified in the last 1 months======

2009-11-02 23:25:24 ----D---- C:\WINDOWS
2009-11-02 21:22:12 ----D---- C:\WINDOWS\Prefetch
2009-11-02 21:13:53 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-02 21:12:17 ----D---- C:\WINDOWS\system32\drivers
2009-11-02 21:11:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-02 19:45:24 ----A---- C:\WINDOWS\system.ini
2009-11-02 19:43:57 ----D---- C:\WINDOWS\system32
2009-11-02 19:43:57 ----D---- C:\WINDOWS\AppPatch
2009-11-02 19:43:47 ----D---- C:\Program Files\Common Files
2009-11-02 19:36:25 ----D---- C:\WINDOWS\Minidump
2009-11-02 19:31:50 ----D---- C:\WINDOWS\system32\config
2009-11-02 00:32:01 ----RD---- C:\Program Files
2009-11-02 00:27:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-01 23:04:08 ----HD---- C:\WINDOWS\inf
2009-11-01 22:57:22 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-01 21:41:57 ----D---- C:\WINDOWS\security
2009-11-01 19:23:02 ----RD---- C:\WINDOWS\Web
2009-11-01 19:23:02 ----D---- C:\WINDOWS\system32\wbem
2009-11-01 19:22:57 ----D---- C:\WINDOWS\system32\usmt
2009-11-01 19:22:56 ----D---- C:\WINDOWS\system32\Setup
2009-11-01 19:22:54 ----D---- C:\WINDOWS\system32\Restore
2009-11-01 19:22:54 ----D---- C:\WINDOWS\system32\oobe
2009-11-01 19:22:53 ----D---- C:\WINDOWS\system32\npp
2009-11-01 19:20:09 ----D---- C:\WINDOWS\system32\Com
2009-11-01 19:18:14 ----D---- C:\WINDOWS\system
2009-11-01 19:18:14 ----D---- C:\WINDOWS\srchasst
2009-11-01 19:18:13 ----D---- C:\WINDOWS\PeerNet
2009-11-01 19:18:12 ----D---- C:\WINDOWS\mui
2009-11-01 19:18:11 ----D---- C:\WINDOWS\msagent
2009-11-01 19:18:02 ----D---- C:\WINDOWS\ime
2009-11-01 19:18:01 ----D---- C:\WINDOWS\Help
2009-11-01 19:17:59 ----RSD---- C:\WINDOWS\Fonts
2009-11-01 19:17:54 ----D---- C:\Program Files\Windows NT
2009-11-01 19:17:54 ----D---- C:\Program Files\Windows Media Player
2009-11-01 19:17:52 ----D---- C:\Program Files\Outlook Express
2009-11-01 19:17:51 ----D---- C:\Program Files\NetMeeting
2009-11-01 19:17:49 ----D---- C:\Program Files\Movie Maker
2009-11-01 19:17:46 ----D---- C:\Program Files\Messenger
2009-11-01 19:17:44 ----D---- C:\Program Files\Internet Explorer
2009-11-01 19:17:39 ----D---- C:\Program Files\Common Files\System
2009-11-01 19:12:26 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-11-01 19:05:45 ----D---- C:\WINDOWS\ehome
2009-11-01 11:24:43 ----D---- C:\WINDOWS\Debug
2009-11-01 11:21:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-01 11:21:20 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-31 15:15:21 ----SD---- C:\WINDOWS\Tasks
2009-10-31 15:14:05 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-10-31 15:11:23 ----SHD---- C:\WINDOWS\Installer
2009-10-31 13:36:07 ----D---- C:\WINDOWS\WinSxS
2009-10-30 11:13:04 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-10-30 11:12:59 ----D---- C:\Program Files\SpywareBlaster
2009-10-30 10:23:12 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-30 09:36:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-30 09:33:26 ----D---- C:\WINDOWS\twain_32
2009-10-28 09:09:25 ----D---- C:\Program Files\Java
2009-10-26 11:32:59 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-02-28 36096]
R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS []
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 INO_FLTR;INO_FLTR; \??\C:\WINDOWS\System32\Drivers\ino_fltr.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\System32\DRIVERS\irda.sys [2004-08-03 87424]
R2 NIOC;NIOC Service; \??\C:\WINDOWS\System32\NIOC.SYS []
R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2003-12-19 15263]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2006-03-23 1166972]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-14 4299264]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\System32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RT61;D-Link Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2005-06-04 319104]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-02-28 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-02-28 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-28 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-02-28 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-02-28 20480]
S3 catchme;catchme; \??\C:\DOCUME~1\Rute\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2006-02-28 10880]
S3 NETDLWL;D-Link Air Wireless Adapter(DL) NT Driver; C:\WINDOWS\System32\DRIVERS\NETDLWL.SYS [2003-07-14 159104]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2006-02-28 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2006-02-28 15360]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 InoRPC;eTrust Antivirus RPC Server; C:\Program Files\CA\eTrust Antivirus\InoRpc.exe [2003-02-13 144864]
R2 InoRT;eTrust Antivirus Realtime Server; C:\Program Files\CA\eTrust Antivirus\InoRT.exe [2003-02-13 230880]
R2 InoTask;eTrust Antivirus Job Server; C:\Program Files\CA\eTrust Antivirus\InoTask.exe [2003-02-13 234976]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2006-02-28 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-28 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-10-31 1179232]
R2 LogWatch;Event Log Watch; C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 53248]
R2 WZCBDLService;WZCBDL Service; C:\Program Files\WZCBDL Service\WZCBDLS.exe [2002-03-19 36864]
S2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2004-10-22 49152]
S2 Brother XP spl Service;BrSplService; C:\WINDOWS\System32\brsvc01a.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 CA_LIC_CLNT;CA License Client; C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 77824]
S3 CA_LIC_SRVR;CA License Server; C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 77824]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-20 138168]

-----------------EOF-----------------

Ironbender
Well, at this point I don't know what else to try, apart a registry cleanup. beatsme.gif

The logs looks clean, although there are a lot of useless keys showing and that is no guarantee that some legit files on this system are not still infected...

Better backup all your critical data, in case you need to reformat it. Do not backup any .exe, .sys, .scr or .pif files, just documents, favorites, mail and addresses, pictures and music.

Let's perform some cleanup...

1 - Disable AdAware Service:
<Start/Run> type in services.msc (Enter)
Locate "Ad-Aware Service", Right click Properties, Change Startup Type to Disabled.
Click Apply and OK -->Close Services
Reboot.

2 - Uninstall Combofix:
<Start/Run> type in combofix /u (note the space before /u) --> Enter.
This will remove combofix and quarantined files from your system, thus avoiding false positives in the future.

3 - Run Disk Cleanup from -->Programs, Accessories, System Tools.
Click the "More Options" tab, System Restore, Clean -->Confirm, OK, Yes.

4 - Run Ccleaner;

5 - Clean the registry:
Start Ccleaner again;
Click the Registry icon at left;
Make sure that all checkboxes are checked;
Click the Scan for Issues button;
Select (checkmark) all problems found and click the Fix selected Issues button at right;
Click Yes on the "Do you want to backup changes to the registry" window;
Save the registry backup file;
Click Fix All Issues (you may need to confirm, please do so);
Close Ccleaner and restart your system.

6 - Re-enable AdAware service.

Post a final RSIT log when all done.

Chris
blueice
QUOTE(Ironbender @ Nov 3 2009, 09:31 AM) *

Well, at this point I don't know what else to try, apart a registry cleanup. beatsme.gif

The logs looks clean, although there are a lot of useless keys showing and that is no guarantee that some legit files on this system are not still infected...

Better backup all your critical data, in case you need to reformat it. Do not backup any .exe, .sys, .scr or .pif files, just documents, favorites, mail and addresses, pictures and music.


Ok Chris, Just want to say at this point how much I appreciate your efforts. flower.gif

I am backing up at the moment but I suspect it will take forever as the system will keep closing down. I will carry out your further suggestions when this is complet.

In the mean time can I just run a few questions by you?

Despite the "Crash" (new collective noun) of MalWare, I'm just wondering if the problem could be hardware? There is a definite click sound emitted from the inside of the tower when it switches off and although there is no exact pattern to when it happens, it doesn't always seem to be totally random, i.e. it can happen at the same time while one is attempting something.

The other thing I was wondering, and I haven't had chance to try this but it never happened while I was in "Safe Mode"; could this be significant and if so is it worth leaving it for sometime in safe mode to see if that was just coincidental?

Lastly, regarding the message received back from Microsoft, after sending the error report, is that of no significance, or just not meaning full? The Wlan it refers to is software associated with a redundant network cable connection. I can disable it but I cannot find a way of removing or uninstalling it, i.e. it doesn't show in the list of programs and windows components.

Clive
blueice
QUOTE(Ironbender @ Nov 3 2009, 09:31 AM) *


Post a final RSIT log when all done.

Chris


Here goes: -

Logfile of random's system information tool 1.06 (written by random/random)
Run by Rute at 2009-11-03 13:10:17
Microsoft Windows XP Professional Service Pack 2
System drive C: has 29 GB (75%) free of 38 GB
Total RAM: 502 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:10:21, on 03/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Cloudmark\SpamNet\OE\snoe.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Rute\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Rute.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Cloudmark Desktop for Outlook Express.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1199792268796
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: BrSplService (Brother XP spl Service) - Unknown owner - C:\WINDOWS\System32\brsvc01a.exe (file missing)
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe

--
End of file - 6127 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Every week.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-28 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-09-20 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"=C:\PROGRA~1\CA\ETRUST~1\realmon.exe [2003-02-13 493024]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2003-10-14 155648]
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2004-04-14 57393]
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2004-04-14 40960]
"D-Link Air Utility"=C:\Program Files\D-Link\Air Utility\AirCFG.exe [2003-06-26 2695168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-13 16239616]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2006-03-23 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2006-03-23 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2006-03-23 118784]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-28 149280]
"D-Link AirPlus G"=C:\Program Files\D-Link\AirPlus G\AirGCFG.exe [2005-07-22 1519616]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2004-12-16 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cloudmark Desktop for Outlook Express.lnk - C:\WINDOWS\Installer\{5B0A00E4-2F9F-49C7-B9A1-9A8E136E8869}\SC_1.ico
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-03-23 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-02-28 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winkp62.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winot52.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Winwd27.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe:LocalSubNet:Enabled:Ad-Aware"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

======List of files/folders created in the last 1 months======

2009-11-03 12:49:35 ----SD---- C:\ComboFix
2009-11-02 21:12:16 ----A---- C:\avenger.txt
2009-11-02 21:11:12 ----A---- C:\zip.exe
2009-11-02 21:11:12 ----A---- C:\cleanup.exe
2009-11-02 21:11:12 ----A---- C:\cleanup.bat
2009-11-02 19:47:56 ----D---- C:\WINDOWS\temp
2009-11-02 19:47:54 ----A---- C:\ComboFix.txt
2009-11-02 19:47:53 ----A---- C:\log.txt
2009-11-02 19:24:20 ----D---- C:\WINDOWS\ERDNT
2009-11-02 14:30:59 ----D---- C:\WINDOWS\ERUNT
2009-11-02 10:23:58 ----D---- C:\LinhaDefensiva
2009-11-02 00:32:01 ----D---- C:\Program Files\trend micro
2009-11-02 00:31:58 ----D---- C:\rsit
2009-11-01 19:16:40 ----A---- C:\WINDOWS\system32\SET145.tmp
2009-11-01 19:16:37 ----D---- C:\WINDOWS\network diagnostic
2009-11-01 19:15:39 ----A---- C:\WINDOWS\system32\sprecovr.exe
2009-11-01 19:12:33 ----A---- C:\WINDOWS\002988_.tmp
2009-11-01 19:10:01 ----A---- C:\WINDOWS\system32\wmvdmoe2.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmoe.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmspdmod.dll
2009-11-01 19:10:00 ----A---- C:\WINDOWS\system32\wmsdmoe2.dll
2009-11-01 19:09:59 ----N---- C:\WINDOWS\system32\mspmsnsv.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmpasf.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmp.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmidx.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\wmerror.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp4sdmod.dll
2009-11-01 19:09:59 ----A---- C:\WINDOWS\system32\mp43dmod.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir50_32.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\ir41_qc.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\hccoin.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\fsquirt.exe
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthserv.dll
2009-11-01 19:09:47 ----A---- C:\WINDOWS\system32\bthci.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wshbth.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\wlanapi.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\sdhcinst.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-11-01 19:09:46 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-11-01 19:09:27 ----A---- C:\WINDOWS\system32\pidgen.dll
2009-11-01 19:09:25 ----A---- C:\WINDOWS\system32\spiisupd.exe
2009-11-01 19:09:18 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\secedit.exe
2009-11-01 19:08:59 ----A---- C:\WINDOWS\system32\dpcdll.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\p2pgasvc.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\kbdukx.dll
2009-11-01 19:08:57 ----A---- C:\WINDOWS\system32\dxdiagn.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\xpsp2res.dll
2009-11-01 19:08:55 ----A---- C:\WINDOWS\system32\encdec.dll
2009-11-01 19:08:54 ----N---- C:\WINDOWS\system32\wscntfy.exe
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\pnrpnsp.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-11-01 19:08:54 ----A---- C:\WINDOWS\system32\dsprpres.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\w3ssl.dll
2009-11-01 19:08:53 ----A---- C:\WINDOWS\system32\p2psvc.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\p2pgraph.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\msftedit.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdsmsno.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\kbdfi1.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-11-01 19:08:52 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbeio.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\sbe.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\msdadiag.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\kbdmlt47.dll
2009-11-01 19:08:51 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-11-01 19:08:50 ----A---- C:\WINDOWS\system32\httpapi.dll
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-11-01 19:08:49 ----A---- C:\WINDOWS\system32\smbinst.exe
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\iuengine.dll
2009-11-01 19:08:48 ----A---- C:\WINDOWS\system32\fwcfg.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\mssap.dll
2009-11-01 19:08:47 ----A---- C:\WINDOWS\system32\d3d9.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\xmlprov.dll
2009-11-01 19:08:46 ----N---- C:\WINDOWS\system32\qmgr.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\xmlprovi.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\winbrand.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\twext.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\spnpinst.exe
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\p2pnetsh.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinmal.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
2009-11-01 19:08:46 ----A---- C:\WINDOWS\system32\cmsetacl.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\powercfg.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\kbdsmsfi.dll
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\fltmc.exe
2009-11-01 19:08:45 ----A---- C:\WINDOWS\system32\btpanui.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\xpsp1res.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\wscsvc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winshfhc.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\winhttp.dll
2009-11-01 19:08:44 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\p2p.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdno1.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\kbdmlt48.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\encapi.dll
2009-11-01 19:08:43 ----A---- C:\WINDOWS\system32\auditusr.exe
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\xpob2res.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\strmfilt.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdmaori.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\kbdinben.dll
2009-11-01 19:08:42 ----A---- C:\WINDOWS\system32\blastcln.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\gpresult.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\eventcreate.exe
2009-11-01 19:08:41 ----A---- C:\WINDOWS\system32\driverquery.exe
2009-11-01 19:08:40 ----N---- C:\WINDOWS\system32\appmgmts.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\systeminfo.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\schtasks.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\openfiles.exe
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\appmgr.dll
2009-11-01 19:08:40 ----A---- C:\WINDOWS\system32\adsnw.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\gpedit.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\getmac.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fdeploy.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\fde.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\efsadu.dll
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\cipher.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\bootcfg.exe
2009-11-01 19:08:39 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2009-11-01 19:08:38 ----A---- C:\WINDOWS\system32\gptext.dll
2009-11-01 19:08:37 ----A---- C:\WINDOWS\system32\logman.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrtdep.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqrt.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqqm.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqoa.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqise.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqdscli.dll
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqbkup.exe
2009-11-01 19:08:36 ----A---- C:\WINDOWS\system32\mqad.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwwks.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\nwapi32.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\ntbackup.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqutil.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqupgrd.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtrig.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsvc.exe
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsnap.dll
2009-11-01 19:08:35 ----A---- C:\WINDOWS\system32\mqsec.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tracerpt.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvrp.dll
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntsess.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\tasklist.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\taskkill.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\rsnotify.exe
2009-11-01 19:08:34 ----A---- C:\WINDOWS\system32\proxycfg.exe
2009-11-01 19:08:33 ----A---- C:\WINDOWS\system32\wsecedit.dll
2009-11-01 19:07:50 ----N---- C:\WINDOWS\explorer.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\winhlp32.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\twain_32.dll
2009-11-01 19:07:49 ----A---- C:\WINDOWS\regedit.exe
2009-11-01 19:07:49 ----A---- C:\WINDOWS\hh.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\activeds.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\aclui.dll
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-11-01 19:07:47 ----A---- C:\WINDOWS\system32\6to4svc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\amstream.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alrsvc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\alg.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\ahui.exe
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\advpack.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsnt.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsmsext.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldpc.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\adsldp.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\admparse.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actxprxy.dll
2009-11-01 19:07:46 ----A---- C:\WINDOWS\system32\actmovie.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmfd.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atmadm.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\atl.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\at.exe
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asycfilt.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\asferror.dll
2009-11-01 19:07:45 ----A---- C:\WINDOWS\system32\apphelp.dll
2009-11-01 19:07:44 ----N---- C:\WINDOWS\system32\browser.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabview.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\cabinet.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browsewm.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browseui.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\browselc.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\blackbox.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\bidispl.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batt.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\batmeter.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\basesrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\avifil32.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autolfn.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\autofmt.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\authz.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\audiosrv.dll
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\attrib.exe
2009-11-01 19:07:44 ----A---- C:\WINDOWS\system32\atmlib.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certmgr.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\certcli.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdosys.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\cdfview.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\capesnpn.dll
2009-11-01 19:07:43 ----A---- C:\WINDOWS\system32\camocx.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdl32.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmdial32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cmcfg32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clusapi.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipsrv.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cliconfg.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cisvc.exe
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\ciodm.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cic.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgmgr32.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-11-01 19:07:42 ----A---- C:\WINDOWS\system32\cewmdm.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-11-01 19:07:41 ----A---- C:\WINDOWS\system32\cmmon32.exe
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comres.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compstui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\compatui.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\colbact.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon2.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cnbjmon.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmutil.dll
2009-11-01 19:07:40 ----A---- C:\WINDOWS\system32\cmstp.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\credui.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\corpol.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\conime.exe
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\confmsp.dll
2009-11-01 19:07:39 ----A---- C:\WINDOWS\system32\comuid.dll
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\ctfmon.exe
2009-11-01 19:07:38 ----N---- C:\WINDOWS\system32\cryptsvc.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\d3d8.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\csrss.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscript.exe
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cscdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptui.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptnet.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptext.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdll.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\cryptdlg.dll
2009-11-01 19:07:38 ----A---- C:\WINDOWS\system32\crypt32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\ddeshare.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dciman32.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnmpntw.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbnetlib.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbmsrpcn.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dbghelp.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\davclnt.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\datime.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\dataclen.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\danim.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3dim700.dll
2009-11-01 19:07:37 ----A---- C:\WINDOWS\system32\d3d8thk.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\diantz.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dhcpmon.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dgnet.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfsshlex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgui.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgsnap.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devmgr.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\devenum.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\defrag.exe
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddrawex.dll
2009-11-01 19:07:36 ----A---- C:\WINDOWS\system32\ddraw.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmband.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dmadmin.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dllhost.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dispex.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskpart.exe
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\diskcopy.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput8.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\dinput.dll
2009-11-01 19:07:35 ----A---- C:\WINDOWS\system32\digest.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplayx.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\docprop2.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dnsapi.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmutil.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmusic.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmsynth.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmstyle.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmserver.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmscript.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmremote.exe
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmloader.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmime.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdskmgr.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmdlgs.dll
2009-11-01 19:07:34 ----A---- C:\WINDOWS\system32\dmcompos.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\ds32gt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drprov.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmstor.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\drmclien.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpwsockx.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvvox.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvoice.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpvacm.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnet.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2009-11-01 19:07:33 ----A---- C:\WINDOWS\system32\dpmodemx.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsquery.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsprop.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound3d.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsound.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquoui.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dskquota.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmoprp.dll
2009-11-01 19:07:32 ----A---- C:\WINDOWS\system32\dsdmo.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx8vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dx7vb.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dwwin.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\duser.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dumprep.exe
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dswave.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dsuiext.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssenh.dll
2009-11-01 19:07:31 ----A---- C:\WINDOWS\system32\dssec.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\eventlog.dll
2009-11-01 19:07:30 ----N---- C:\WINDOWS\system32\es.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\eudcedit.exe
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\esent.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\ersvc.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\els.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxmasf.dll
2009-11-01 19:07:30 ----A---- C:\WINDOWS\system32\dxdiag.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\gdi32.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\framebuf.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\forcedos.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontview.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontsub.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fontext.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\fldrclnr.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\findstr.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\filemgmt.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\feclient.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\faultrep.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\exts.dll
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\extrac32.exe
2009-11-01 19:07:29 ----A---- C:\WINDOWS\system32\expsrv.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hnetcfg.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hlink.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hid.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\hhsetup.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\help.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\h323msp.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\grpconv.exe
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\gpkrsrc.dll
2009-11-01 19:07:28 ----A---- C:\WINDOWS\system32\glu32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icmp.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icm32.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iccvid.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\iasrad.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\htui.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hotplug.dll
2009-11-01 19:07:27 ----A---- C:\WINDOWS\system32\hnetwiz.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iesetup.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iepeers.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\idq.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-11-01 19:07:26 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-11-01 19:07:25 ----N---- C:\WINDOWS\system32\imm32.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imgutil.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imeshare.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\imapi.exe
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ils.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\igmpagnt.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\ifmon.dll
2009-11-01 19:07:25 ----A---- C:\WINDOWS\system32\iexpress.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipmontr.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\iphlpapi.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\ipconfig.exe
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inseng.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\input.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\initpki.dll
blueice
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetres.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetppui.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetpp.dll
2009-11-01 19:07:24 ----A---- C:\WINDOWS\system32\inetmib1.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipxroute.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6mon.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipv6.exe
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsmsnap.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsvc.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ipsecsnp.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2009-11-01 19:07:23 ----A---- C:\WINDOWS\system32\ippromon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ixsso.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itss.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\itircl.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\isign32.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irmon.dll
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\irftp.exe
2009-11-01 19:07:22 ----A---- C:\WINDOWS\system32\ipxwan.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\keymgr.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kerberos.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kd1394.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\kbdnec.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jscript.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgpl400.dll
2009-11-01 19:07:21 ----A---- C:\WINDOWS\system32\jgdw400.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lsass.exe
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\lpk.dll
2009-11-01 19:07:20 ----N---- C:\WINDOWS\system32\linkinfo.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\magnify.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lprhelp.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logonui.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\logagent.exe
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localui.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\localsec.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\loadperf.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\lmrt.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licmgr10.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\licdll.dll
2009-11-01 19:07:20 ----A---- C:\WINDOWS\system32\laprxy.dll
2009-11-01 19:07:19 ----N---- C:\WINDOWS\system32\mfc40u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\miglibnt.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\midimap.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfcsubs.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42u.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mfc42.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mf3216.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mdminst.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciwave.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciseq.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciqtz32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mciavi32.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\mcastmib.dll
2009-11-01 19:07:19 ----A---- C:\WINDOWS\system32\makecab.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcshext.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmcbase.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mmc.exe
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mlang.dll
2009-11-01 19:07:18 ----A---- C:\WINDOWS\system32\mimefilt.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mprapi.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpr.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mpg4dmod.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\moricons.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\more.com
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\modemui.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mobsync.dll
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-11-01 19:07:17 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msdart.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctfp.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msctf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpxl32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscpx32r.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msconf.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mscms.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msasn1.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msapsspc.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msafd.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\msacm32.dll
2009-11-01 19:07:16 ----A---- C:\WINDOWS\system32\mprdim.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-11-01 19:07:15 ----A---- C:\WINDOWS\system32\msdmo.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\mshta.exe
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msgina.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexcl40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msexch40.dll
2009-11-01 19:07:14 ----A---- C:\WINDOWS\system32\msdxmlc.dll
2009-11-01 19:07:12 ----N---- C:\WINDOWS\system32\mshtml.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msieftp.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msidle.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msident.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\msi.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmler.dll
2009-11-01 19:07:12 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimsg.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msimg32.dll
2009-11-01 19:07:11 ----A---- C:\WINDOWS\system32\msihnd.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjter40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjint40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjetoledb40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msjet40.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msisip.dll
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msiregmv.exe
2009-11-01 19:07:10 ----A---- C:\WINDOWS\system32\msimtf.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspatcha.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorcl32.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msorc32r.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnsspc.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msnetobj.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msltus40.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\mslbui.dll
2009-11-01 19:07:09 ----A---- C:\WINDOWS\system32\msjtes40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrepl40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd3x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrd2x40.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msrating.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\msprivs.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspmsp.dll
2009-11-01 19:07:08 ----A---- C:\WINDOWS\system32\mspbde40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstime.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstext40.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\mstask.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msscp.dll
2009-11-01 19:07:07 ----A---- C:\WINDOWS\system32\msrle32.dll
2009-11-01 19:07:06 ----N---- C:\WINDOWS\system32\msvcrt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvfw32.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcrt40.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcp60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvcirt.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msvbvm60.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\msutb.dll
2009-11-01 19:07:06 ----A---- C:\WINDOWS\system32\mstlsapi.dll
2009-11-01 19:07:05 ----N---- C:\WINDOWS\system32\mswsock.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswmdm.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswebdvd.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\mswdat10.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msw3prt.dll
2009-11-01 19:07:05 ----A---- C:\WINDOWS\system32\msvidctl.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mtxclu.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msyuv.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml3.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml2.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxml.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\msxbde40.dll
2009-11-01 19:07:04 ----A---- C:\WINDOWS\system32\mswstr10.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\netapi32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net1.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\net.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddenb32.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapir.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\nddeapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\ncobjapi.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\narrator.exe
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mydocs.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-11-01 19:07:03 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netman.dll
2009-11-01 19:07:02 ----N---- C:\WINDOWS\system32\netlogon.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netsetup.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netrap.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netplwiz.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netid.dll
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netdde.exe
2009-11-01 19:07:02 ----A---- C:\WINDOWS\system32\netcfgx.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntlanman.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\ntdsapi.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\npptools.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\notepad.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\nlhtml.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\newdev.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui1.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netui0.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netstat.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netshell.dll
2009-11-01 19:07:01 ----A---- C:\WINDOWS\system32\netsh.exe
2009-11-01 19:07:01 ----A---- C:\WINDOWS\notepad.exe
2009-11-01 19:07:00 ----N---- C:\WINDOWS\system32\ntmssvc.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\occache.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\objsel.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\oakley.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntvdmd.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntshrui.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsmgr.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsdba.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmsapi.dll
2009-11-01 19:07:00 ----A---- C:\WINDOWS\system32\ntmarta.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcp32r.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcjt32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcji32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcint.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccu32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccr32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbccp32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcconf.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcbcp.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbcad32.exe
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32gt.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\odbc32.dll
2009-11-01 19:06:59 ----A---- C:\WINDOWS\system32\ocmanage.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\packager.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osuninst.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\osk.exe
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\opengl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olepro32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oleprn.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oledlg.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\olecli32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\ole32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\offfilt.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odtext32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odpdx32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odfox32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odexl32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\oddbse32.dll
2009-11-01 19:06:58 ----A---- C:\WINDOWS\system32\odbctrac.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\polstore.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pjlmon.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\ping.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pid.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\photowiz.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfproc.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfos.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfnet.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfmon.exe
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\perfdisk.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pdh.dll
2009-11-01 19:06:57 ----A---- C:\WINDOWS\system32\pautoenr.dll
2009-11-01 19:06:56 ----N---- C:\WINDOWS\system32\powrprof.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorsvc.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\pstorec.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psisdecd.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psbase.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\psapi.dll
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\proquota.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\progman.exe
2009-11-01 19:06:56 ----A---- C:\WINDOWS\system32\profmap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedwipes.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qedit.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdvd.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qdv.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qcap.dll
2009-11-01 19:06:55 ----A---- C:\WINDOWS\system32\qasf.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\query.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\quartz.dll
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-11-01 19:06:54 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpdd.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcp.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcimlby.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rastls.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rassapi.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasppp.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasphone.exe
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasmans.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\raschap.dll
2009-11-01 19:06:53 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2009-11-01 19:06:52 ----N---- C:\WINDOWS\system32\regsvc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\riched20.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rexec.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\resutils.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regwizc.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regsvr32.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\regapi.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\reg.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-11-01 19:06:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\scecli.dll
2009-11-01 19:06:51 ----N---- C:\WINDOWS\system32\rpcss.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scesrv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\sccsccp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\scarddlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\runonce.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rundll32.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtutils.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtipxmib.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rtcshare.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsmps.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsh.exe
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rsaenh.dll
2009-11-01 19:06:51 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\sfc.dll
2009-11-01 19:06:50 ----N---- C:\WINDOWS\system32\schedsvc.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\setup.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sethc.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sensapi.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sens.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendmail.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sendcmsg.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\security.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\secur32.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\seclogon.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sdbinst.exe
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrrun.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\scrobj.dll
2009-11-01 19:06:50 ----A---- C:\WINDOWS\system32\sclgntfy.dll
2009-11-01 19:06:49 ----N---- C:\WINDOWS\system32\sfcfiles.dll
2009-11-01 19:06:49 ----A---- C:\WINDOWS\system32\sfc_os.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdocvw.dll
2009-11-01 19:06:48 ----A---- C:\WINDOWS\system32\shdoclc.dll
2009-11-01 19:06:47 ----A---- C:\WINDOWS\system32\shell32.dll
2009-11-01 19:06:46 ----N---- C:\WINDOWS\system32\shsvcs.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\smlogcfg.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slbiop.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\slayerxp.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\skeys.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigverif.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\sigtab.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shutdown.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shscrap.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shrpubw.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmgrate.exe
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shmedia.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shlwapi.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimgvw.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shimeng.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shgina.dll
2009-11-01 19:06:46 ----A---- C:\WINDOWS\system32\shfolder.dll
2009-11-01 19:06:45 ----N---- C:\WINDOWS\system32\spoolsv.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\srclient.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlunirl.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spoolss.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\spider.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sort.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpsnap.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\snmpapi.dll
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-11-01 19:06:45 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\ssdpsrv.dll
2009-11-01 19:06:44 ----N---- C:\WINDOWS\system32\srsvc.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2009-11-01 19:06:44 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-11-01 19:06:43 ----N---- C:\WINDOWS\system32\svchost.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\strmdll.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\storprop.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stobject.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stimon.exe
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti_ci.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\sti.dll
2009-11-01 19:06:43 ----A---- C:\WINDOWS\system32\stclient.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi32.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\tapi3.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\t2embed.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\syncui.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\synceng.dll
2009-11-01 19:06:42 ----A---- C:\WINDOWS\system32\sxs.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\termsrv.dll
2009-11-01 19:06:41 ----N---- C:\WINDOWS\system32\tapisrv.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tsddd.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\trkwks.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tree.com
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tracert.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tourstart.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\themeui.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\termmgr.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\telnet.exe
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmon.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\tcpmib.dll
2009-11-01 19:06:41 ----A---- C:\WINDOWS\system32\taskmgr.exe
2009-11-01 19:06:40 ----N---- C:\WINDOWS\system32\upnphost.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\url.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\ups.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpui.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnpcont.exe
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\upnp.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\uniplat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\unimdmat.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\umandlg.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\udhisapi.dll
2009-11-01 19:06:40 ----A---- C:\WINDOWS\system32\txflog.dll
2009-11-01 19:06:39 ----N---- C:\WINDOWS\system32\user32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\vbajet32.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\utilman.exe
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usp10.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\userenv.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbui.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\usbmon.dll
2009-11-01 19:06:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webvw.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webclnt.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wdigest.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\wavemsp.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\w32time.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssvc.exe
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vssapi.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\version.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\verifier.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmredir.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vdmdbg.dll
2009-11-01 19:06:38 ----A---- C:\WINDOWS\system32\vbscript.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaservc.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiascr.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadss.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiadefui.dll
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2009-11-01 19:06:37 ----A---- C:\WINDOWS\system32\wextract.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\winlogon.exe
2009-11-01 19:06:36 ----N---- C:\WINDOWS\system32\wininet.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winsrv.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winscard.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winrnr.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winntbbu.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winmm.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\winipsec.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiavideo.dll
2009-11-01 19:06:36 ----A---- C:\WINDOWS\system32\wiashext.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wlnotify.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wldap32.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winver.exe
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\wintrust.dll
2009-11-01 19:06:35 ----A---- C:\WINDOWS\system32\winsta.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmasf.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmoe.dll
2009-11-01 19:06:34 ----A---- C:\WINDOWS\system32\wmadmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmstream.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmsdmod.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpui.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpshell.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmploc.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcore.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmpcd.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmnetmgr.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmi.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmps.dll
2009-11-01 19:06:33 ----A---- C:\WINDOWS\system32\wmdmlog.dll
2009-11-01 19:06:32 ----N---- C:\WINDOWS\system32\ws2_32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wship6.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshext.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wshcon.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wscript.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\ws2help.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wpabaln.exe
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wow32.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvdmod.dll
2009-11-01 19:06:32 ----A---- C:\WINDOWS\system32\wmvcore.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\zipfldr.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xcopy.exe
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\xactsrv.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsvc.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcsapi.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wzcdlg.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wtsapi32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wstdecod.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsock32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wsnmp32.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshtcpip.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshrm.dll
2009-11-01 19:06:31 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autoconv.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\autochk.exe
2009-11-01 19:06:29 ----A---- C:\WINDOWS\system32\advapi32.dll
2009-11-01 19:06:28 ----N---- C:\WINDOWS\system32\comctl32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\format.com
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\csrsrv.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\comdlg32.dll
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cmd.exe
2009-11-01 19:06:28 ----A---- C:\WINDOWS\system32\cacls.exe
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\msgsvc.dll
2009-11-01 19:06:27 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntprint.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntlsapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ntdll.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\nslookup.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\msv1_0.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lsasrv.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\locator.exe
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\localspl.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\lmhsvc.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\imagehlp.dll
2009-11-01 19:06:27 ----A---- C:\WINDOWS\system32\ftp.exe
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rshx32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rastapi.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasman.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasdlg.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasauto.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\rasapi32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\printui.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\perfctrs.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\olecnv32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\oleaut32.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\nwprovau.dll
2009-11-01 19:06:26 ----A---- C:\WINDOWS\system32\ntvdm.exe
2009-11-01 19:06:25 ----N---- C:\WINDOWS\system32\services.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\setupapi.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\schannel.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\scardsvr.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\savedump.exe
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\samsrv.dll
2009-11-01 19:06:25 ----A---- C:\WINDOWS\system32\samlib.dll
2009-11-01 19:06:24 ----A---- C:\WINDOWS\system32\srvsvc.dll
2009-11-01 19:06:24 ----A---- C:\WINDOWS\system32\smss.exe
2009-11-01 19:06:23 ----N---- C:\WINDOWS\system32\userinit.exe
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\wkssvc.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\win32spl.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\untfs.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\ulib.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\tcpmonui.dll
2009-11-01 19:06:23 ----A---- C:\WINDOWS\system32\syssetup.dll
2009-11-01 19:06:17 ----N---- C:\WINDOWS\system32\ntoskrnl.exe
2009-11-01 19:06:17 ----N---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\mspmspsv.dll
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\hal.dll
2009-11-01 19:06:17 ----A---- C:\WINDOWS\system32\asfsipc.dll
2009-11-01 19:05:54 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-11-01 18:51:57 ----D---- C:\c54a6d05e83307ead7db2bd86b09
2009-11-01 11:22:32 ----D---- C:\Program Files\CCleaner
2009-10-31 20:28:08 ----D---- C:\ecdf583faca82bc123a6e40196
2009-10-31 19:26:53 ----D---- C:\a8a4fdb52b43ca7799
2009-10-31 17:43:03 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-10-31 15:30:46 ----D---- C:\809ce48a9298ca6fef
2009-10-31 15:30:22 ----D---- C:\036cf94b026c6c1a2abf5f9e
2009-10-31 15:11:23 ----HDC---- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-31 15:10:30 ----D---- C:\Program Files\Lavasoft
2009-10-31 14:08:59 ----D---- C:\Config.Msi
2009-10-31 13:36:15 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-10-31 13:07:20 ----D---- C:\79dbf129e5766d58c21d
2009-10-31 12:49:11 ----D---- C:\a77b669a6bc9a21afaf97f36b4e048f5
2009-10-31 12:40:48 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-10-31 12:34:57 ----D---- C:\272288eb39584362c97bff20419ad220
2009-10-30 09:36:53 ----D---- C:\WINDOWS\system32\appmgmt
2009-10-30 09:33:26 ----D---- C:\WINDOWS\OvtCam
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\java.exe
2009-10-28 09:10:05 ----A---- C:\WINDOWS\system32\deploytk.dll

======List of files/folders modified in the last 1 months======

2009-11-03 13:08:47 ----D---- C:\WINDOWS
2009-11-03 13:07:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-03 12:56:27 ----D---- C:\WINDOWS\Prefetch
2009-11-03 12:53:15 ----D---- C:\WINDOWS\Minidump
2009-11-03 12:51:21 ----SHD---- C:\System Volume Information
2009-11-03 12:51:21 ----D---- C:\WINDOWS\system32\Restore
2009-11-03 10:49:56 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-02 21:12:17 ----D---- C:\WINDOWS\system32\drivers
2009-11-02 19:45:24 ----A---- C:\WINDOWS\system.ini
2009-11-02 19:43:57 ----D---- C:\WINDOWS\system32
2009-11-02 19:43:57 ----D---- C:\WINDOWS\AppPatch
2009-11-02 19:43:47 ----D---- C:\Program Files\Common Files
2009-11-02 19:31:50 ----D---- C:\WINDOWS\system32\config
2009-11-02 00:32:01 ----RD---- C:\Program Files
2009-11-02 00:27:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-01 23:04:08 ----HD---- C:\WINDOWS\inf
2009-11-01 22:57:22 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-01 21:41:57 ----D---- C:\WINDOWS\security
2009-11-01 19:23:02 ----RD---- C:\WINDOWS\Web
2009-11-01 19:23:02 ----D---- C:\WINDOWS\system32\wbem
2009-11-01 19:22:57 ----D---- C:\WINDOWS\system32\usmt
2009-11-01 19:22:56 ----D---- C:\WINDOWS\system32\Setup
2009-11-01 19:22:54 ----D---- C:\WINDOWS\system32\oobe
2009-11-01 19:22:53 ----D---- C:\WINDOWS\system32\npp
2009-11-01 19:20:09 ----D---- C:\WINDOWS\system32\Com
2009-11-01 19:18:14 ----D---- C:\WINDOWS\system
2009-11-01 19:18:14 ----D---- C:\WINDOWS\srchasst
2009-11-01 19:18:13 ----D---- C:\WINDOWS\PeerNet
2009-11-01 19:18:12 ----D---- C:\WINDOWS\mui
2009-11-01 19:18:11 ----D---- C:\WINDOWS\msagent
2009-11-01 19:18:02 ----D---- C:\WINDOWS\ime
2009-11-01 19:18:01 ----D---- C:\WINDOWS\Help
2009-11-01 19:17:59 ----RSD---- C:\WINDOWS\Fonts
2009-11-01 19:17:54 ----D---- C:\Program Files\Windows NT
2009-11-01 19:17:54 ----D---- C:\Program Files\Windows Media Player
2009-11-01 19:17:52 ----D---- C:\Program Files\Outlook Express
2009-11-01 19:17:51 ----D---- C:\Program Files\NetMeeting
2009-11-01 19:17:49 ----D---- C:\Program Files\Movie Maker
2009-11-01 19:17:46 ----D---- C:\Program Files\Messenger
2009-11-01 19:17:44 ----D---- C:\Program Files\Internet Explorer
2009-11-01 19:17:39 ----D---- C:\Program Files\Common Files\System
2009-11-01 19:12:26 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-11-01 19:05:45 ----D---- C:\WINDOWS\ehome
2009-11-01 11:24:43 ----D---- C:\WINDOWS\Debug
2009-11-01 11:21:21 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-01 11:21:20 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-31 15:15:21 ----SD---- C:\WINDOWS\Tasks
2009-10-31 15:14:05 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-10-31 15:11:23 ----SHD---- C:\WINDOWS\Installer
2009-10-31 13:36:07 ----D---- C:\WINDOWS\WinSxS
2009-10-30 11:13:04 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-10-30 11:12:59 ----D---- C:\Program Files\SpywareBlaster
2009-10-30 10:23:12 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-30 09:36:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-30 09:33:26 ----D---- C:\WINDOWS\twain_32
2009-10-28 09:09:25 ----D---- C:\Program Files\Java
2009-10-26 11:32:59 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-02-28 36096]
R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS []
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 INO_FLTR;INO_FLTR; \??\C:\WINDOWS\System32\Drivers\ino_fltr.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\System32\DRIVERS\irda.sys [2004-08-03 87424]
R2 NIOC;NIOC Service; \??\C:\WINDOWS\System32\NIOC.SYS []
R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2003-12-19 15263]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2006-03-23 1166972]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-14 4299264]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\System32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RT61;D-Link Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2005-06-04 319104]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2006-02-28 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-02-28 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-02-28 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-02-28 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-02-28 20480]
S3 catchme;catchme; \??\C:\DOCUME~1\Rute\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2006-02-28 10880]
S3 NETDLWL;D-Link Air Wireless Adapter(DL) NT Driver; C:\WINDOWS\System32\DRIVERS\NETDLWL.SYS [2003-07-14 159104]
S3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2006-02-28 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2006-02-28 15360]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 InoRPC;eTrust Antivirus RPC Server; C:\Program Files\CA\eTrust Antivirus\InoRpc.exe [2003-02-13 144864]
R2 InoRT;eTrust Antivirus Realtime Server; C:\Program Files\CA\eTrust Antivirus\InoRT.exe [2003-02-13 230880]
R2 InoTask;eTrust Antivirus Job Server; C:\Program Files\CA\eTrust Antivirus\InoTask.exe [2003-02-13 234976]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2006-02-28 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-28 153376]
R2 LogWatch;Event Log Watch; C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 53248]
R2 WZCBDLService;WZCBDL Service; C:\Program Files\WZCBDL Service\WZCBDLS.exe [2002-03-19 36864]
S2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2004-10-22 49152]
S2 Brother XP spl Service;BrSplService; C:\WINDOWS\System32\brsvc01a.exe []
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-10-31 1179232]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 CA_LIC_CLNT;CA License Client; C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 77824]
S3 CA_LIC_SRVR;CA License Server; C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 77824]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-20 138168]

-----------------EOF-----------------



Ironbender
Some bulknet-trojan registry leftovers are still showing, but I doubt that they are still active.

Apart of this, the logs are clean. smile.gif

As I told you before, there is no guarantee that some files are not still infected. You may perform a full scan using your antivirus to deeply check this. Also, you can run an online scan from here: http://www.superantispyware.com/onlinescan.html

You can start a new thread on this forum to check your other system.

Chris
blueice
I tried superantispyware Chris but, not surprisingly, it didn't find anything.

Not sure if you saw my last but one posting but I have verified that it still closes down, whether in safe mode or safe mode with Internet connection. I have also managed to remove the driver for the Wlan card, still to no avail. I'm becoming convinced that it is hardware and worried now that if I try to format and reinstall it will keep closing during he process.

Perhaps I should start by changing the mother (@#:^>*) board.

Anyway thanks again for your help Chris.

I’m about to make a new posting for my other system.

Clive
Ironbender
I would try a repair-install instead: http://www.microsoft.com/windowsxp/using/h...ips/doug92.mspx

This will reinstall Windows over-the-top (on the same folder), so you will not lost a thing and there is worth a try. smile.gif

Chris
blueice
Chris.
Can a virus change or set a BIOS password?
I originaly set the system up but don't remember setting it up to require a bios password, however it does now! And to follow the instructions of windowsxp/using/h...ips/doug92.mspx, I need to set the CD drive bootable, in the BIOS but I can't access it:(


I've found a facility called CmosPwd to, which allegedly decrypts cmos passwords, but I'm wary of using anything that might come along with a basket full of baddies too.

Any suggestions?
[/color]
Ironbender
Well, I don't think that a virus/baddie can set a BIOS password. Disconnect the main power cable, pop the left system cover out, remove the CMOS battery for 20~30 minutes, then replace it and reboot.
IPB Image
You may now have full access to BIOS.

Chris
blueice
Hi Chris
It took me a while to get around to doing it but I've done what you suggested and got into the BIOS.

I then reinstalled windows as you also suggested. I then upgraded to Service pack 3. It is too soon to tell if it has resolved the issue but there is now an error message appearing at start up.

AirGCFG.exe. WinXPPro - causes startup error "Entry Point Not Found"
The procedure entry point apsGetInterfaceCont could not be located in the dynamic link library wlanapi.

A quick look on the web suggests this is a D-link Wlan issue, which was the suggestion by Microsoft when the original problem was sent to them for comment.

Could this be the problem or is it coincident do you think.

Should I stop AirGCFG.exe running at startup?

Clive
Ironbender
QUOTE
Should I stop AirGCFG.exe running at startup?

I'd definitely try to disable it... rolleyes.gif

Chris
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.