1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive [InActive] bolivar27.exe ..I think it's a virus, I cant seem to remove it.

Discussion in 'Malware and Virus Removal Archive' started by Aslan9, 2008/11/24.

  1. 2008/12/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes, there were some rogue files and services left to remove. Please open the C:\Qoobox folder then the ComboFix-quarantined-files.txt file and post it's contents here.

    There is still a service left from the Tiny Proxy infection to remove. Please highlight and coppy the bolded command below, quotes included.

    sc delete "COM+ Event System (EventSystem) "

    Make sure the space between the end parenthesis ) and the end quote " remains .... it belongs there.
    Now click Start then Run and paste the copied text in the Run dialog. Hit Enter.
     
  2. 2008/12/01
    Aslan9

    Aslan9 Inactive Thread Starter

    Joined:
    2008/11/24
    Messages:
    21
    Likes Received:
    0
    2006-06-01 12:01:40 A------- 53 C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML.vir
    2007-08-01 20:43:22 A------- 53 C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML.vir
    2008-11-23 23:07:21 A------- 1 C:\Qoobox\Quarantine\C\WINDOWS\fmark2.dat.vir
    2008-11-23 23:07:43 A------- 23,552 C:\Qoobox\Quarantine\C\WINDOWS\che6.exe.vir
    2008-11-23 23:07:47 A------- 6,912 C:\Qoobox\Quarantine\C\Program Files\tinyproxy\tinyproxy.exe.vir
    2008-11-23 23:07:51 A------- 1 C:\Qoobox\Quarantine\C\WINDOWS\bemark2.dat.vir
    2008-11-23 23:08:03 A------- 1 C:\Qoobox\Quarantine\C\WINDOWS\f49f4daa.dat.vir
    2008-11-27 18:03:23 A------- 116 C:\Qoobox\Quarantine\catchme.log
    2008-11-27 18:06:46 A------- 11,965 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
    2008-11-27 18:09:50 A------- 53 C:\Qoobox\Quarantine\D\Autorun.inf.vir
    2008-11-27 18:10:21 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
    2008-11-27 18:10:21 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
    2008-11-27 18:10:21 A------- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat
    2008-11-27 18:10:25 A------- 99 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-PCDrProfiler.reg.dat
    2008-11-27 18:10:25 A------- 122 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-M1000Mnt.reg.dat
    2008-11-27 18:10:25 A------- 172 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TkBellExe.reg.dat
    2008-11-28 16:57:57 A------- 74,703 C:\Qoobox\Quarantine\C\WINDOWS\system32\mfc45.dll.vir
    2008-12-01 20:09:13 A------- 22,409 C:\Qoobox\Quarantine\[4]-Submit_2008-12-01@20.09.zip
    2008-12-01 20:11:53 A------- 286 C:\Qoobox\Quarantine\Registry_backups\Legacy_GKMIXERN.reg.dat
    2008-12-01 20:11:54 A------- 2,372 C:\Qoobox\Quarantine\Registry_backups\Service_gkmixern.reg.dat
    2008-12-01 20:18:06 A------- 761 C:\Qoobox\Quarantine\Registry_backups\BHO-{CFC4F59B-A2DA-4e12-B337-52A4F871E10C}.reg.dat
    2008-12-01 20:18:07 A------- 2,149 C:\Qoobox\Quarantine\Registry_backups\Toolbar-{196C3A46-4758-433D-A600-802C804AF39C}.reg.dat
    2008-12-01 20:18:08 A------- 2,035 C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{196C3A46-4758-433D-A600-802C804AF39C}.reg.dat
     

  3. to hide this advert.

  4. 2008/12/01
    Aslan9

    Aslan9 Inactive Thread Starter

    Joined:
    2008/11/24
    Messages:
    21
    Likes Received:
    0
    Hi, when I hit run the first time nothing happened. So I did it again and a black DOS box flashed up for a split second and disappeared.
     
  5. 2008/12/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please go here and upload the following file.

    C:\Qoobox\Quarantine\[4]-Submit_2008-12-01@20.09.zip

    You can copy that path and paste it into the Browse to the file you want to submit: field or Browse to and select it, leave a link to this topic, then click Send File.



    Please run RSIT again and post the log.txt file it creates.
     
  6. 2008/12/02
    Aslan9

    Aslan9 Inactive Thread Starter

    Joined:
    2008/11/24
    Messages:
    21
    Likes Received:
    0
    Logfile of random's system information tool 1.04 (written by random/random)
    Run by HP_Administrator at 2008-12-02 20:19:34
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 146 GB (80%) free of 182 GB
    Total RAM: 1023 MB (46% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:19:44 p.m., on 2/12/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\ARPWRMSG.EXE
    C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\HP\KBD\KBD.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Documents and Settings\HP_Administrator\Desktop\RSIT.exe
    C:\Program Files\trend micro\HP_Administrator.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_NZ&c=64&bd=PAVILION&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://signupcd.ihug.co.nz/acnts/signup.pl?version=8&base=5:1&pop=Anywhere+in+New+Zealand
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe "
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe "
    O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
    O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
    O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HP_Administrator\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 10257 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-14 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2007-01-20 2403392]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-16 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-14 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-14 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2007-01-20 2403392]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ehTray "=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
    "ftutil2 "=C:\WINDOWS\system32\ftutil2.dll [2004-06-07 106496]
    "RTHDCPL "=C:\WINDOWS\RTHDCPL.EXE [2006-06-14 16239616]
    "AlwaysReady Power Message APP "=C:\WINDOWS\ARPWRMSG.EXE [2005-08-03 77312]
    "NvCplDaemon "=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
    "nwiz "=nwiz.exe /install []
    "DMAScheduler "=c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe [2006-04-13 90112]
    "Recguard "=C:\WINDOWS\SMINST\RECGUARD.EXE [2005-07-23 237568]
    "HPBootOp "=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2006-02-16 249856]
    "avast! "=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-19 81000]
    "NeroFilterCheck "=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
    "PC Suite for Smartphones "=C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe [2007-05-28 528384]
    "ZoneAlarm Client "=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-07-09 919016]
    "QuickTime Task "=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg "=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-08-05 68856]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} "=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-12-23 143360]
    "mRouterConfig "=C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe [2006-03-02 290816]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2004-08-10 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
    Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1
    "InstallVisualStyle "=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme "=C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives "=0
    "NoDriveAutoRun "=67108863
    "NoDriveTypeAutoRun "=323

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=
    "NoDrives "=
    "NoDriveAutoRun "=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe "= "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP "
    "C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe "= "C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe:*:Enabled:Kaspersky AV Scanner "
    "C:\Program Files\Messenger\msmsgs.exe "= "C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger "
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe "= "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe "= "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe "
    "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe "= "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe "
    "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe "= "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe "
    "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe "= "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "
    "C:\Program Files\LimeWire\LimeWire.exe "= "C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe "= "C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "

    ======File associations======

    .js - open - NOTEPAD.EXE %1
    .vbs - open - NOTEPAD.EXE %1

    ======List of files/folders created in the last 3 months======

    2008-12-01 20:27:28 ----SHD---- C:\RECYCLER
    2008-12-01 20:18:49 ----A---- C:\ComboFix.txt
    2008-12-01 15:01:41 ----A---- C:\WINDOWS\system32\hidserv.dll
    2008-12-01 12:13:21 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
    2008-12-01 12:11:46 ----D---- C:\Program Files\Common Files\Apple
    2008-12-01 12:11:41 ----D---- C:\Program Files\QuickTime
    2008-12-01 12:11:34 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-12-01 12:11:12 ----D---- C:\Program Files\Apple Software Update
    2008-12-01 12:11:11 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
    2008-11-30 18:23:21 ----D---- C:\Documents and Settings\All Users\Application Data\15DA
    2008-11-30 18:13:23 ----D---- C:\Program Files\Shareaza Applications
    2008-11-30 17:50:31 ----D---- C:\Program Files\ReflexiveArcade
    2008-11-28 19:23:58 ----D---- C:\Program Files\VS Revo Group
    2008-11-28 16:29:22 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2008-11-28 16:29:12 ----A---- C:\WINDOWS\system32\STKIT432.DLL
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\zip.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\VFIND.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\SWXCACLS.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\SWSC.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\SWREG.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\sed.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\NIRCMD.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\grep.exe
    2008-11-27 18:03:30 ----A---- C:\WINDOWS\fdsv.exe
    2008-11-27 18:03:23 ----D---- C:\WINDOWS\ERDNT
    2008-11-27 18:03:23 ----AD---- C:\Qoobox
    2008-11-27 17:57:28 ----RASHD---- C:\autorun.inf
    2008-11-26 11:28:48 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
    2008-11-26 11:28:48 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
    2008-11-26 11:28:48 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
    2008-11-26 11:28:47 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
    2008-11-26 11:28:47 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
    2008-11-26 11:28:46 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
    2008-11-26 11:28:46 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
    2008-11-26 11:28:45 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
    2008-11-26 11:28:45 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
    2008-11-26 11:28:44 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
    2008-11-26 11:28:44 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
    2008-11-26 11:28:44 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
    2008-11-26 11:28:43 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
    2008-11-26 11:28:42 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
    2008-11-26 11:28:42 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
    2008-11-26 11:28:42 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
    2008-11-26 11:28:41 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
    2008-11-26 11:28:41 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
    2008-11-26 11:28:41 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
    2008-11-26 11:28:40 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
    2008-11-26 11:28:39 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
    2008-11-26 11:28:39 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
    2008-11-26 11:28:38 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
    2008-11-26 11:28:37 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
    2008-11-26 11:28:37 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
    2008-11-26 11:28:37 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
    2008-11-26 11:28:36 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
    2008-11-26 11:28:35 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
    2008-11-26 11:28:35 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
    2008-11-26 11:28:34 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
    2008-11-26 11:28:33 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
    2008-11-26 11:28:33 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
    2008-11-26 11:28:33 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
    2008-11-26 11:28:32 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
    2008-11-26 11:28:31 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
    2008-11-26 11:28:31 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
    2008-11-26 11:28:31 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
    2008-11-26 11:28:31 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
    2008-11-26 11:28:30 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
    2008-11-26 11:28:29 ----A---- C:\WINDOWS\system32\xinput1_3.dll
    2008-11-26 11:28:28 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
    2008-11-26 11:28:26 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
    2008-11-26 11:28:26 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
    2008-11-26 11:28:23 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
    2008-11-26 11:28:22 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
    2008-11-26 11:28:22 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
    2008-11-26 11:28:21 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
    2008-11-26 11:28:21 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
    2008-11-26 11:28:21 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
    2008-11-26 11:28:20 ----A---- C:\WINDOWS\system32\xinput1_2.dll
    2008-11-26 11:28:20 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
    2008-11-26 11:28:20 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
    2008-11-26 11:28:19 ----A---- C:\WINDOWS\system32\xinput1_1.dll
    2008-11-26 11:28:19 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
    2008-11-26 11:28:18 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
    2008-11-26 11:28:14 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
    2008-11-26 11:28:14 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
    2008-11-26 11:28:14 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
    2008-11-26 11:28:13 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
    2008-11-26 11:28:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
    2008-11-26 11:28:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
    2008-11-26 11:28:11 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
    2008-11-26 11:28:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
    2008-11-26 11:25:49 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-11-26 11:25:39 ----D---- C:\WINDOWS\Logs
    2008-11-24 22:05:10 ----D---- C:\Program Files\trend micro
    2008-11-24 22:05:09 ----D---- C:\rsit
    2008-11-24 17:59:37 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Mozilla
    2008-11-15 13:15:53 ----A---- C:\WINDOWS\ntbtlog.txt
    2008-11-14 21:45:47 ----AH---- C:\WINDOWS\system32\RBK5C04.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BFF.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BFC.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BF7.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BF4.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BEF.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BEC.tmp.LOG
    2008-11-14 21:45:46 ----AH---- C:\WINDOWS\system32\RBK5BE7.tmp.LOG
    2008-11-14 21:45:44 ----AH---- C:\WINDOWS\system32\RBK5BE4.tmp.LOG
    2008-11-14 21:45:44 ----AH---- C:\WINDOWS\system32\RBK5BDF.tmp.LOG
    2008-11-14 21:45:44 ----AH---- C:\WINDOWS\system32\RBK5BDC.tmp.LOG
    2008-11-14 21:45:44 ----AH---- C:\WINDOWS\system32\RBK5BD7.tmp.LOG
    2008-11-14 21:27:19 ----D---- C:\WINDOWS\Prefetch
    2008-11-14 20:30:50 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Systweak
    2008-11-14 20:29:48 ----D---- C:\Program Files\Advanced System Optimizer
    2008-11-14 20:18:41 ----HDC---- C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
    2008-11-14 19:51:54 ----D---- C:\WINDOWS\system32\scripting
    2008-11-14 19:51:53 ----D---- C:\WINDOWS\l2schemas
    2008-11-14 19:51:52 ----D---- C:\WINDOWS\system32\en
    2008-11-14 19:51:52 ----D---- C:\WINDOWS\system32\bits
    2008-11-14 19:44:16 ----A---- C:\WINDOWS\system32\sprecovr.exe
    2008-11-14 19:40:50 ----A---- C:\WINDOWS\system32\hccoin.dll
    2008-11-14 19:40:50 ----A---- C:\WINDOWS\system32\fsquirt.exe
    2008-11-14 19:40:50 ----A---- C:\WINDOWS\system32\bthserv.dll
    2008-11-14 19:40:50 ----A---- C:\WINDOWS\system32\bthci.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\wshbth.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\verclsid.exe
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\tzchange.exe
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\sdhcinst.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\mstscax.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\mstsc.exe
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\ir50_qcx.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\ir50_qc.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\ir50_32.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\ir41_qcx.dll
    2008-11-14 19:40:49 ----A---- C:\WINDOWS\system32\ir41_qc.dll
    2008-11-14 19:40:48 ----A---- C:\WINDOWS\system32\xpsp3res.dll
    2008-11-14 19:40:48 ----A---- C:\WINDOWS\system32\xmllite.dll
    2008-11-14 19:40:38 ----A---- C:\WINDOWS\system32\pidgen.dll
    2008-11-14 19:40:37 ----A---- C:\WINDOWS\system32\spiisupd.exe
    2008-11-14 19:40:36 ----A---- C:\WINDOWS\system32\asr_pfu.exe
    2008-11-14 19:40:34 ----A---- C:\WINDOWS\system32\secedit.exe
    2008-11-14 19:40:34 ----A---- C:\WINDOWS\system32\p2pgasvc.dll
    2008-11-14 19:40:34 ----A---- C:\WINDOWS\system32\kbdukx.dll
    2008-11-14 19:40:34 ----A---- C:\WINDOWS\system32\dxdiagn.dll
    2008-11-14 19:40:34 ----A---- C:\WINDOWS\system32\dpcdll.dll
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\xpsp2res.dll
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\wscntfy.exe
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\w3ssl.dll
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\pnrpnsp.dll
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\p2psvc.dll
    2008-11-14 19:40:33 ----A---- C:\WINDOWS\system32\dsprpres.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\wuaueng1.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\sbeio.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\p2pgraph.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\msftedit.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\kbdsmsno.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\kbdmlt47.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\kbdfi1.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\fltlib.dll
    2008-11-14 19:40:32 ----A---- C:\WINDOWS\system32\bitsprx2.dll
    2008-11-14 19:40:31 ----A---- C:\WINDOWS\system32\smbinst.exe
    2008-11-14 19:40:31 ----A---- C:\WINDOWS\system32\msdadiag.dll
    2008-11-14 19:40:31 ----A---- C:\WINDOWS\system32\ieencode.dll
    2008-11-14 19:40:31 ----A---- C:\WINDOWS\system32\httpapi.dll
    2008-11-14 19:40:30 ----A---- C:\WINDOWS\system32\wuauclt1.exe
    2008-11-14 19:40:30 ----A---- C:\WINDOWS\system32\mssap.dll
    2008-11-14 19:40:30 ----A---- C:\WINDOWS\system32\iuengine.dll
    2008-11-14 19:40:30 ----A---- C:\WINDOWS\system32\fwcfg.dll
    2008-11-14 19:40:30 ----A---- C:\WINDOWS\system32\d3d9.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\xmlprovi.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\xmlprov.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\winbrand.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\twext.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\spnpinst.exe
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\qmgr.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\p2pnetsh.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\kbdinmal.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\kbdinbe1.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\fltmc.exe
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\cmsetacl.dll
    2008-11-14 19:40:29 ----A---- C:\WINDOWS\system32\btpanui.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\xpsp1res.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\wscsvc.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\winshfhc.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\winhttp.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\powercfg.exe
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\kbdsmsfi.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\encapi.dll
    2008-11-14 19:40:28 ----A---- C:\WINDOWS\system32\bitsprx3.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\xpob2res.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\wuauserv.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\strmfilt.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\p2p.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\kbdno1.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\kbdmlt48.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\kbdinben.dll
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\blastcln.exe
    2008-11-14 19:40:27 ----A---- C:\WINDOWS\system32\auditusr.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\systeminfo.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\schtasks.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\openfiles.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\kbdmaori.dll
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\gpresult.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\eventtriggers.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\eventcreate.exe
    2008-11-14 19:40:26 ----A---- C:\WINDOWS\system32\driverquery.exe
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\efsadu.dll
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\cipher.exe
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\bootcfg.exe
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\asr_fmt.exe
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\appmgr.dll
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\appmgmts.dll
    2008-11-14 19:40:25 ----A---- C:\WINDOWS\system32\adsnw.dll
    2008-11-14 19:40:24 ----A---- C:\WINDOWS\system32\gptext.dll
    2008-11-14 19:40:24 ----A---- C:\WINDOWS\system32\gpedit.dll
    2008-11-14 19:40:24 ----A---- C:\WINDOWS\system32\getmac.exe
    2008-11-14 19:40:24 ----A---- C:\WINDOWS\system32\fdeploy.dll
    2008-11-14 19:40:24 ----A---- C:\WINDOWS\system32\fde.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqoa.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqise.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqdscli.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqbkup.exe
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\mqad.dll
    2008-11-14 19:40:23 ----A---- C:\WINDOWS\system32\logman.exe
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\nwwks.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\nwapi32.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\ntbackup.exe
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqutil.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqupgrd.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqtrig.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqsvc.exe
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqsnap.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqsec.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqrtdep.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqrt.dll
    2008-11-14 19:40:22 ----A---- C:\WINDOWS\system32\mqqm.dll
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tracerpt.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tlntsvrp.dll
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tlntsvr.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tlntsess.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tlntadmn.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\tasklist.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\taskkill.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\rsnotify.exe
    2008-11-14 19:40:21 ----A---- C:\WINDOWS\system32\proxycfg.exe
    2008-11-14 19:40:20 ----A---- C:\WINDOWS\system32\wsecedit.dll
    2008-11-14 19:39:51 ----A---- C:\WINDOWS\winhlp32.exe
    2008-11-14 19:39:51 ----A---- C:\WINDOWS\twain_32.dll
    2008-11-14 19:39:51 ----A---- C:\WINDOWS\regedit.exe
    2008-11-14 19:39:51 ----A---- C:\WINDOWS\hh.exe
    2008-11-14 19:39:51 ----A---- C:\WINDOWS\explorer.exe
    2008-11-14 19:39:50 ----A---- C:\WINDOWS\system32\6to4svc.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\alrsvc.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\alg.exe
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\ahui.exe
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\adsnt.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\adsmsext.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\adsldpc.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\adsldp.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\actxprxy.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\actmovie.exe
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\activeds.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\aclui.dll
    2008-11-14 19:39:49 ----A---- C:\WINDOWS\system32\accwiz.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\batmeter.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\basesrv.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\avifil32.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\autolfn.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\autofmt.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\authz.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\audiosrv.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\attrib.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\atmlib.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\atmfd.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\atmadm.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\atl.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\at.exe
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\asycfilt.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\apphelp.dll
    2008-11-14 19:39:48 ----A---- C:\WINDOWS\system32\amstream.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\catsrvut.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\catsrvps.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\catsrv.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\capesnpn.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\camocx.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\cabview.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\cabinet.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\c_g18030.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\browsewm.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\browseui.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\browser.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\browselc.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\bidispl.dll
    2008-11-14 19:39:47 ----A---- C:\WINDOWS\system32\batt.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\clbcatex.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cisvc.exe
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\ciodm.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cic.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cfgmgr32.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cfgbkend.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\certmgr.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\certcli.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cdosys.dll
    2008-11-14 19:39:46 ----A---- C:\WINDOWS\system32\cdfview.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\compatui.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\comaddin.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\colbact.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cnbjmon.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmutil.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmstp.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmprops.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmmon32.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmdl32.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmdial32.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cmcfg32.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\clusapi.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\clipsrv.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\clipbrd.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cliconfg.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cliconfg.dll
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\cleanmgr.exe
    2008-11-14 19:39:45 ----A---- C:\WINDOWS\system32\clbcatq.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\crypt32.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\credui.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\corpol.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\conime.exe
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\confmsp.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\comuid.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\comsvcs.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\comsnap.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\comres.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\comrepl.dll
    2008-11-14 19:39:44 ----A---- C:\WINDOWS\system32\compstui.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\d3dim700.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\d3d8thk.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\d3d8.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\ctfmon.exe
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\csrss.exe
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cscui.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cscript.exe
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cscdll.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptui.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptsvc.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptnet.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptext.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptdll.dll
    2008-11-14 19:39:43 ----A---- C:\WINDOWS\system32\cryptdlg.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\defrag.exe
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\ddrawex.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\ddraw.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\ddeshare.exe
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dciman32.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dbnmpntw.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dbnetlib.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dbmsrpcn.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dbghelp.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\davclnt.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\datime.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\dataclen.dll
    2008-11-14 19:39:42 ----A---- C:\WINDOWS\system32\danim.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dhcpmon.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dgnet.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dfsshlex.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dfrgui.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dfrgsnap.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\dfrgfat.exe
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\devmgr.dll
    2008-11-14 19:39:41 ----A---- C:\WINDOWS\system32\devenum.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmloader.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmime.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmdskmgr.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmdlgs.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmcompos.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmband.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dmadmin.exe
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dllhost.exe
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dispex.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\diskpart.exe
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\diskcopy.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dinput8.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\dinput.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\digest.dll
    2008-11-14 19:39:40 ----A---- C:\WINDOWS\system32\diantz.exe
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnsvr.exe
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnlobby.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnhpast.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnet.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpnaddr.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dpmodemx.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dplayx.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dplaysvr.exe
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\docprop2.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dnsapi.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmutil.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmusic.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmsynth.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmstyle.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmserver.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmscript.dll
    2008-11-14 19:39:39 ----A---- C:\WINDOWS\system32\dmremote.exe
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dswave.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsuiext.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dssenh.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dssec.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsquery.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsprop.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsound3d.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsound.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dskquoui.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dskquota.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsdmoprp.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dsdmo.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\ds32gt.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\drprov.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dpwsockx.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dpvvox.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dpvsetup.exe
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dpvoice.dll
    2008-11-14 19:39:38 ----A---- C:\WINDOWS\system32\dpvacm.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\ersvc.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\els.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dxmasf.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dxdiag.exe
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dx8vb.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dx7vb.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dwwin.exe
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\duser.dll
    2008-11-14 19:39:37 ----A---- C:\WINDOWS\system32\dumprep.exe
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\findstr.exe
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\filemgmt.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\feclient.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\faultrep.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\f3ahvoas.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\exts.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\extrac32.exe
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\expsrv.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\eventlog.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\eudcedit.exe
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\esent.dll
    2008-11-14 19:39:36 ----A---- C:\WINDOWS\system32\es.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsres.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsperf.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsmon.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsext32.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsevent.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsdrv.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxscover.exe
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxscomex.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxscom.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsclnt.exe
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fxsapi.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\framebuf.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\forcedos.exe
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fontview.exe
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fontsub.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fontext.dll
    2008-11-14 19:39:35 ----A---- C:\WINDOWS\system32\fldrclnr.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\h323msp.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\grpconv.exe
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\gpkrsrc.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\glu32.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\gdi32.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxsxp32.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxswzrd.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxsui.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxstiff.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxst30.dll
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxssvc.exe
    2008-11-14 19:39:34 ----A---- C:\WINDOWS\system32\fxsst.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\icwphbk.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\icwdial.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\icmp.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\icm32.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\iccvid.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\icaapi.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\iasrad.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hypertrm.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\htui.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hotplug.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hnetwiz.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hnetcfg.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hlink.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hid.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\hhsetup.dll
    2008-11-14 19:39:33 ----A---- C:\WINDOWS\system32\help.exe
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\inetcfg.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\imm32.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\imjp81k.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\imeshare.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\imapi.exe
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\ils.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\igmpagnt.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\ifmon.dll
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\iexpress.exe
     
  7. 2008/12/02
    Aslan9

    Aslan9 Inactive Thread Starter

    Joined:
    2008/11/24
    Messages:
    21
    Likes Received:
    0
    2008-11-14 19:39:32 ----A---- C:\WINDOWS\system32\idq.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\ippromon.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\ipnathlp.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\ipmontr.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\iphlpapi.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\ipconfig.exe
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\input.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\initpki.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\inetres.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\inetppui.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\inetpp.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\inetmib1.dll
    2008-11-14 19:39:31 ----A---- C:\WINDOWS\system32\inetcomm.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\jgpl400.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\jgdw400.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\iyuv_32.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ixsso.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\itss.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\itircl.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\isrdbg32.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\isign32.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipxwan.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipxroute.exe
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipv6mon.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipv6.exe
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipsmsnap.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipsecsvc.dll
    2008-11-14 19:39:30 ----A---- C:\WINDOWS\system32\ipsecsnp.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\loadperf.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\lmrt.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\linkinfo.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\licwmi.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\licdll.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\ksuser.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\keymgr.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kerberos.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kd1394.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbdnec.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbdlk41j.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbdlk41a.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbdibm02.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbdax2.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbd106n.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbd106.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\kbd101.dll
    2008-11-14 19:39:29 ----A---- C:\WINDOWS\system32\jscript.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mf3216.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mdminst.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mciwave.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mciseq.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mciqtz32.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mciavi32.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\mcastmib.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\makecab.exe
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\magnify.exe
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\lsass.exe
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\lprhelp.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\lpk.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\logonui.exe
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\localui.dll
    2008-11-14 19:39:28 ----A---- C:\WINDOWS\system32\localsec.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mmcbase.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mmc.exe
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mlang.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mimefilt.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\miglibnt.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\midimap.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mfcsubs.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mfc42u.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mfc42.dll
    2008-11-14 19:39:27 ----A---- C:\WINDOWS\system32\mfc40u.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mpr.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mplay32.exe
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\moricons.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\more.com
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\modemui.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mobsync.exe
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mobsync.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mnmdd.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mmfutil.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mmcshext.dll
    2008-11-14 19:39:26 ----A---- C:\WINDOWS\system32\mmcndmgr.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msdart.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msctfp.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msctf.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\mscpxl32.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\mscpx32r.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msconf.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\mscms.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msasn1.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msapsspc.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msafd.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\msacm32.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\mprdim.dll
    2008-11-14 19:39:25 ----A---- C:\WINDOWS\system32\mprapi.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msgina.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msexcl40.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msexch40.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdxmlc.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdtctm.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdtcprx.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdtclog.dll
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdtc.exe
    2008-11-14 19:39:24 ----A---- C:\WINDOWS\system32\msdmo.dll
    2008-11-14 19:39:23 ----A---- C:\WINDOWS\system32\msiexec.exe
    2008-11-14 19:39:23 ----A---- C:\WINDOWS\system32\msieftp.dll
    2008-11-14 19:39:23 ----A---- C:\WINDOWS\system32\msidle.dll
    2008-11-14 19:39:23 ----A---- C:\WINDOWS\system32\msident.dll
    2008-11-14 19:39:23 ----A---- C:\WINDOWS\system32\msi.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msnsspc.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msltus40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\mslbui.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msjtes40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msjter40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msjint40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msjetoledb40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msjet40.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msisip.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msimtf.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msimsg.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msimg32.dll
    2008-11-14 19:39:22 ----A---- C:\WINDOWS\system32\msihnd.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msrepl40.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msrd3x40.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msrd2x40.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msprivs.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\mspbde40.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\mspatcha.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\mspaint.exe
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msorcl32.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msorc32r.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msoert2.dll
    2008-11-14 19:39:21 ----A---- C:\WINDOWS\system32\msoeacct.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msvcrt40.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msvcrt.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msvcp60.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msvcirt.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msvbvm60.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msutb.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\mstlsapi.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\mstinit.exe
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\mstext40.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\mstask.dll
    2008-11-14 19:39:20 ----A---- C:\WINDOWS\system32\msrle32.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msyuv.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msxml2.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msxml.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msxbde40.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\mswstr10.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\mswsock.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\mswebdvd.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\mswdat10.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msw3prt.dll
    2008-11-14 19:39:19 ----A---- C:\WINDOWS\system32\msvfw32.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\netcfgx.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\net1.exe
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\net.exe
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\nddenb32.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\nddeapir.exe
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\nddeapi.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\ncobjapi.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\narrator.exe
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mydocs.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mtxoci.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mtxlegih.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mtxex.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mtxdm.dll
    2008-11-14 19:39:18 ----A---- C:\WINDOWS\system32\mtxclu.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\newdev.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netui1.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netui0.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netstat.exe
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netshell.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netsh.exe
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netsetup.exe
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netrap.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netplwiz.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netman.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netlogon.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netid.dll
    2008-11-14 19:39:17 ----A---- C:\WINDOWS\system32\netdde.exe
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntshrui.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntmssvc.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntmsmgr.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntmsdba.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntmsapi.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntmarta.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntlanman.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\ntdsapi.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\npptools.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\notepad.exe
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\nmmkcert.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\system32\nlhtml.dll
    2008-11-14 19:39:16 ----A---- C:\WINDOWS\notepad.exe
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbctrac.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcp32r.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcjt32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcji32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcint.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbccu32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbccr32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbccp32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcconf.exe
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcconf.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcbcp.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbcad32.exe
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbc32gt.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\odbc32.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\ocmanage.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\objsel.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\oakley.dll
    2008-11-14 19:39:15 ----A---- C:\WINDOWS\system32\ntvdmd.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\packager.exe
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\osuninst.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\osk.exe
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\opengl32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\olepro32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\oleprn.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\oledlg.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\olecli32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\ole32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\offfilt.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\odtext32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\odpdx32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\odfox32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\odexl32.dll
    2008-11-14 19:39:14 ----A---- C:\WINDOWS\system32\oddbse32.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\psbase.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\psapi.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\proquota.exe
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\progman.exe
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\profmap.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\powrprof.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\polstore.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\pjlmon.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\ping.exe
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\pid.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\photowiz.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\perfproc.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\perfos.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\perfnet.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\perfmon.exe
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\perfdisk.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\pdh.dll
    2008-11-14 19:39:13 ----A---- C:\WINDOWS\system32\pautoenr.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\raschap.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\rasadhlp.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\racpldlg.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\query.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\quartz.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qprocess.exe
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qedwipes.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qedit.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qdvd.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qdv.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\qcap.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\pstorsvc.dll
    2008-11-14 19:39:12 ----A---- C:\WINDOWS\system32\pstorec.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\regsvr32.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\regsvc.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\regapi.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\reg.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdshost.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdsaddin.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdpwsx.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdpsnd.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdpdd.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdpclip.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rdchost.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rcp.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rcimlby.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rcbdyctl.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rastls.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rassapi.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rasppp.dll
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rasphone.exe
    2008-11-14 19:39:11 ----A---- C:\WINDOWS\system32\rasmans.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rtutils.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rtipxmib.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rtcshare.exe
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rsvpsp.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rsmps.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rsh.exe
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rsaenh.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rpcss.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rpcrt4.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\riched20.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\rexec.exe
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\resutils.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\remotepg.dll
    2008-11-14 19:39:10 ----A---- C:\WINDOWS\system32\regwizc.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\sdbinst.exe
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\scrrun.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\scrobj.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\sclgntfy.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\schedsvc.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\scesrv.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\scecli.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\sccsccp.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\scarddlg.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\safrslv.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\safrdm.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\safrcdlg.dll
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\runonce.exe
    2008-11-14 19:39:09 ----A---- C:\WINDOWS\system32\rundll32.exe
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sfc.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\setup.exe
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sethc.exe
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\servdeps.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sensapi.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sens.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sendmail.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\sendcmsg.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\security.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\secur32.dll
    2008-11-14 19:39:08 ----A---- C:\WINDOWS\system32\seclogon.dll
    2008-11-14 19:39:07 ----A---- C:\WINDOWS\system32\shdoclc.dll
    2008-11-14 19:39:07 ----A---- C:\WINDOWS\system32\sfcfiles.dll
    2008-11-14 19:39:07 ----A---- C:\WINDOWS\system32\sfc_os.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shimgvw.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shimeng.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shgina.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shfolder.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shell32.dll
    2008-11-14 19:39:06 ----A---- C:\WINDOWS\system32\shdocvw.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\snmpapi.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\sndrec32.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\smlogsvc.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\smlogcfg.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\slbiop.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\slayerxp.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\skeys.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\sigverif.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\sigtab.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shutdown.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shsvcs.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shscrap.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shrpubw.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shmgrate.exe
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shmedia.dll
    2008-11-14 19:39:05 ----A---- C:\WINDOWS\system32\shlwapi.dll
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\sqlsrv32.dll
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\spoolsv.exe
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\spoolss.dll
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\spider.exe
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\sort.exe
    2008-11-14 19:39:04 ----A---- C:\WINDOWS\system32\snmpsnap.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\ssdpsrv.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\ssdpapi.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\srsvc.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\srrstr.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\srclient.dll
    2008-11-14 19:39:03 ----A---- C:\WINDOWS\system32\sqlunirl.dll
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\storprop.dll
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\stobject.dll
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\stimon.exe
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\sti_ci.dll
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\sti.dll
    2008-11-14 19:39:02 ----A---- C:\WINDOWS\system32\stclient.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\tcpmon.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\tcpmib.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\taskmgr.exe
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\tapisrv.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\tapi32.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\tapi3.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\t2embed.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\sysocmgr.exe
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\syncui.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\synceng.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\sxs.dll
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\svchost.exe
    2008-11-14 19:39:01 ----A---- C:\WINDOWS\system32\strmdll.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\umpnpmgr.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\umandlg.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\udhisapi.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\txflog.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\tsddd.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\trkwks.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\tree.com
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\tracert.exe
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\tourstart.exe
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\themeui.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\termsrv.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\termmgr.dll
    2008-11-14 19:39:00 ----A---- C:\WINDOWS\system32\telnet.exe
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\utilman.exe
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\usp10.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\userenv.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\user32.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\usbui.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\usbmon.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\ups.exe
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\upnpui.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\upnphost.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\upnpcont.exe
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\upnp.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\uniplat.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\unimdmat.dll
    2008-11-14 19:38:59 ----A---- C:\WINDOWS\system32\uniime.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\wdigest.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\wavemsp.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\w32time.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vssvc.exe
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vssapi.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\version.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\verifier.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vdmredir.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vdmdbg.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vbscript.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\vbajet32.dll
    2008-11-14 19:38:58 ----A---- C:\WINDOWS\system32\uxtheme.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiavideo.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiashext.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiaservc.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiascr.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiadss.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiadefui.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\wextract.exe
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\webvw.dll
    2008-11-14 19:38:57 ----A---- C:\WINDOWS\system32\webclnt.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winver.exe
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\wintrust.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winsta.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winsrv.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winscard.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winrnr.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winntbbu.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winmm.dll
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winlogon.exe
    2008-11-14 19:38:56 ----A---- C:\WINDOWS\system32\winipsec.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\ws2help.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\ws2_32.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wpnpinst.exe
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wpabaln.exe
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wow32.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmstream.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmsdmoe.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmpui.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmpcore.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmpcd.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wmi.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wlnotify.dll
    2008-11-14 19:38:55 ----A---- C:\WINDOWS\system32\wldap32.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\xactsrv.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wzcsvc.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wzcsapi.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wzcdlg.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wtsapi32.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wstdecod.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wsock32.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wsnmp32.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wshtcpip.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wshrm.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wship6.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wshext.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wshcon.dll
    2008-11-14 19:38:54 ----A---- C:\WINDOWS\system32\wscript.exe
    2008-11-14 19:38:53 ----A---- C:\WINDOWS\system32\zipfldr.dll
    2008-11-14 19:38:53 ----A---- C:\WINDOWS\system32\xolehlp.dll
    2008-11-14 19:38:53 ----A---- C:\WINDOWS\system32\xcopy.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\lmhsvc.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\kernel32.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\imagehlp.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\ftp.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\format.com
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\csrsrv.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\comdlg32.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\comctl32.dll
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\cmd.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\cacls.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\autoconv.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\autochk.exe
    2008-11-14 19:38:52 ----A---- C:\WINDOWS\system32\advapi32.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\ntvdm.exe
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\ntprint.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\ntlsapi.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\ntdll.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\nslookup.exe
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\msv1_0.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\msgsvc.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\mgmtapi.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\lsasrv.dll
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\locator.exe
    2008-11-14 19:38:51 ----A---- C:\WINDOWS\system32\localspl.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\samlib.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rshx32.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rastapi.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rasman.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rasdlg.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rasauto.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\rasapi32.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\printui.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\perfctrs.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\olecnv32.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\oleaut32.dll
    2008-11-14 19:38:50 ----A---- C:\WINDOWS\system32\nwprovau.dll
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\syssetup.dll
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\srvsvc.dll
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\smss.exe
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\setupapi.dll
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\sessmgr.exe
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\services.exe
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\schannel.dll
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\scardsvr.exe
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\savedump.exe
    2008-11-14 19:38:49 ----A---- C:\WINDOWS\system32\samsrv.dll
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\wkssvc.dll
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\win32spl.dll
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\userinit.exe
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\untfs.dll
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\ulib.dll
    2008-11-14 19:38:48 ----A---- C:\WINDOWS\system32\tcpmonui.dll
    2008-11-14 19:38:40 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
    2008-11-14 19:38:40 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
    2008-11-14 19:38:40 ----A---- C:\WINDOWS\system32\hal.dll
    2008-11-14 19:21:19 ----D---- C:\WINDOWS\ie7updates
    2008-11-14 19:19:16 ----HDC---- C:\WINDOWS\ie7
    2008-11-14 19:15:46 ----D---- C:\WINDOWS\network diagnostic
    2008-11-14 19:15:45 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$
    2008-11-14 19:15:30 ----HDC---- C:\WINDOWS\$NtUninstallKB904942$
    2008-11-14 19:10:53 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-11-14 18:25:01 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-11-14 18:24:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-11-14 18:13:09 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-11-14 18:13:09 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-11-14 18:13:09 ----A---- C:\WINDOWS\system32\java.exe
    2008-11-14 18:13:09 ----A---- C:\WINDOWS\system32\deploytk.dll
    2008-11-14 17:46:27 ----D---- C:\WINDOWS\system32\Adobe
    2008-11-14 14:14:06 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
    2008-11-14 13:49:23 ----D---- C:\WINDOWS\system32\CatRoot_bak
    2008-11-14 00:42:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-11-14 00:42:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-11-14 00:42:13 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-11-14 00:42:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-11-14 00:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB935448$
    2008-11-14 00:41:51 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
    2008-11-14 00:41:45 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-11-14 00:41:37 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-11-14 00:41:29 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-11-14 00:41:21 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2008-11-14 00:41:12 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-11-14 00:40:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-11-14 00:40:53 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-11-14 00:40:25 ----HDC---- C:\WINDOWS\$NtUninstallKB913800$
    2008-11-14 00:39:00 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
    2008-11-14 00:38:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2008-11-14 00:38:22 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2008-11-14 00:38:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
    2008-11-14 00:38:04 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-11-14 00:37:57 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
    2008-11-14 00:37:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-11-14 00:37:10 ----HDC---- C:\WINDOWS\$NtUninstallKB930494$
    2008-11-14 00:36:41 ----HDC---- C:\WINDOWS\$NtUninstallKB885884$
    2008-11-14 00:36:31 ----HDC---- C:\WINDOWS\$NtUninstallKB901190$
    2008-11-14 00:36:25 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-11-14 00:36:17 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-11-14 00:36:08 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2008-11-14 00:35:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
    2008-11-14 00:35:39 ----D---- C:\Program Files\MSXML 4.0
    2008-11-14 00:35:14 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
    2008-11-14 00:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
    2008-11-14 00:34:25 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
    2008-11-14 00:13:13 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Shareaza
    2008-11-13 21:09:17 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\IMVUClient
    2008-11-13 20:40:29 ----D---- C:\Program Files\Microsoft Silverlight
    2008-11-13 20:18:36 ----N---- C:\WINDOWS\kb913800.exe
    2008-11-13 20:09:22 ----A---- C:\WINDOWS\system32\muweb.dll
    2008-11-13 20:09:22 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2008-11-13 20:09:22 ----A---- C:\WINDOWS\system32\mucltui.dll
    2008-11-07 07:56:46 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll
    2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll

    ======List of files/folders modified in the last 3 months======

    2008-12-02 19:34:34 ----D---- C:\WINDOWS\Temp
    2008-12-02 16:50:18 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-12-02 15:28:17 ----AD---- C:\WINDOWS
    2008-12-02 15:27:47 ----D---- C:\WINDOWS\Registration
    2008-12-02 14:13:30 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-12-02 13:52:01 ----D---- C:\WINDOWS\Internet Logs
    2008-12-02 01:09:34 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\LimeWire
    2008-12-01 20:18:55 ----D---- C:\WINDOWS\system32\drivers
    2008-12-01 20:18:55 ----D---- C:\WINDOWS\system32
    2008-12-01 20:14:34 ----A---- C:\WINDOWS\system.ini
    2008-12-01 20:12:49 ----D---- C:\WINDOWS\system32\config
    2008-12-01 20:11:03 ----D---- C:\WINDOWS\AppPatch
    2008-12-01 20:11:03 ----D---- C:\Program Files\Common Files
    2008-12-01 15:25:26 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-12-01 15:01:51 ----RSHD---- C:\WINDOWS\system32\dllcache
    2008-12-01 15:01:34 ----HD---- C:\WINDOWS\inf
    2008-12-01 13:58:02 ----SHD---- C:\WINDOWS\Installer
    2008-12-01 13:58:02 ----HD---- C:\Config.Msi
    2008-12-01 12:24:45 ----D---- C:\Program Files\Movie Maker
    2008-12-01 12:24:34 ----D---- C:\WINDOWS\RegisteredPackages
    2008-12-01 12:11:41 ----RD---- C:\Program Files
    2008-12-01 12:11:16 ----SD---- C:\WINDOWS\Tasks
    2008-12-01 11:58:28 ----D---- C:\WINDOWS\SoftwareDistribution
    2008-11-30 17:50:54 ----A---- C:\WINDOWS\win.ini
    2008-11-28 19:33:32 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-11-28 19:27:01 ----D---- C:\Program Files\Sonic
    2008-11-28 17:27:54 ----D---- C:\WINDOWS\Help
    2008-11-28 17:27:54 ----D---- C:\WINDOWS\Debug
    2008-11-28 17:07:36 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\iolo
    2008-11-28 17:05:05 ----RD---- C:\WINDOWS\Offline Web Pages
    2008-11-28 16:59:21 ----D---- C:\Documents and Settings\All Users\Application Data\iolo
    2008-11-27 18:23:47 ----D---- C:\WINDOWS\system32\CatRoot
    2008-11-27 16:45:15 ----D---- C:\WINDOWS\system32\FxsTmp
    2008-11-26 11:30:39 ----D---- C:\WINDOWS\system32\Macromed
    2008-11-26 11:28:51 ----D---- C:\WINDOWS\system32\DirectX
    2008-11-26 11:28:05 ----D---- C:\WINDOWS\Microsoft.NET
    2008-11-26 11:24:50 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-11-26 10:57:16 ----D---- C:\Program Files\Oberon Media
    2008-11-26 10:05:24 ----A---- C:\WINDOWS\ModemLog_D-Link DFM-562IS HSFi PCI Modem.txt
    2008-11-25 08:45:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-11-23 23:24:46 ----D---- C:\Program Files\PolderbitS
    2008-11-22 10:18:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-11-19 06:41:38 ----A---- C:\WINDOWS\system32\aswBoot.exe
    2008-11-17 00:07:32 ----D---- C:\WINDOWS\nview
    2008-11-16 23:29:18 ----D---- C:\WINDOWS\nvidia icons
    2008-11-16 23:28:55 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-11-16 22:46:11 ----D---- C:\Program Files\LimeWire
    2008-11-15 13:19:45 ----D---- C:\WINDOWS\security
    2008-11-15 12:42:02 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-11-14 21:48:28 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-11-14 21:26:17 ----D---- C:\WINDOWS\system32\wbem
    2008-11-14 21:26:11 ----RSD---- C:\WINDOWS\Fonts
    2008-11-14 21:21:07 ----D---- C:\WINDOWS\WinSxS
    2008-11-14 21:20:41 ----D---- C:\Program Files\Messenger
    2008-11-14 21:20:35 ----D---- C:\WINDOWS\system32\usmt
    2008-11-14 21:20:33 ----D---- C:\WINDOWS\system32\Setup
    2008-11-14 21:20:31 ----D---- C:\WINDOWS\system32\Restore
    2008-11-14 21:20:31 ----D---- C:\WINDOWS\system32\oobe
    2008-11-14 21:20:30 ----D---- C:\WINDOWS\system32\npp
    2008-11-14 21:18:13 ----D---- C:\WINDOWS\system32\Com
    2008-11-14 21:16:15 ----D---- C:\WINDOWS\system
    2008-11-14 21:16:14 ----D---- C:\WINDOWS\srchasst
    2008-11-14 21:16:14 ----D---- C:\WINDOWS\PeerNet
    2008-11-14 21:16:12 ----D---- C:\WINDOWS\mui
    2008-11-14 21:16:10 ----D---- C:\WINDOWS\msagent
    2008-11-14 21:15:53 ----D---- C:\WINDOWS\ime
    2008-11-14 21:15:45 ----D---- C:\Program Files\Windows NT
    2008-11-14 21:15:44 ----D---- C:\Program Files\Outlook Express
    2008-11-14 21:15:43 ----D---- C:\Program Files\NetMeeting
    2008-11-14 21:15:32 ----D---- C:\Program Files\Common Files\System
    2008-11-14 21:03:43 ----D---- C:\WINDOWS\system32\inetsrv
    2008-11-14 21:03:43 ----D---- C:\WINDOWS\system32\en-US
    2008-11-14 20:51:08 ----D---- C:\WINDOWS\Minidump
    2008-11-14 20:51:07 ----D---- C:\WINDOWS\twain_32
    2008-11-14 20:33:07 ----D---- C:\WINDOWS\repair
    2008-11-14 19:38:16 ----AD---- C:\WINDOWS\ehome
    2008-11-14 19:23:23 ----D---- C:\Program Files\Internet Explorer
    2008-11-14 19:21:15 ----HD---- C:\WINDOWS\$hf_mig$
    2008-11-14 19:20:32 ----D---- C:\WINDOWS\WBEM
    2008-11-14 19:20:23 ----D---- C:\WINDOWS\Media
    2008-11-14 18:25:38 ----D---- C:\Program Files\Lavasoft
    2008-11-14 18:25:36 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Lavasoft
    2008-11-14 18:12:45 ----D---- C:\Program Files\Java
    2008-11-14 18:10:12 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-11-14 17:47:26 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\Adobe
    2008-11-13 22:13:42 ----D---- C:\Valve
    2008-11-13 21:27:07 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-11-13 21:26:54 ----D---- C:\Program Files\Common Files\Adobe
    2008-11-13 21:26:53 ----D---- C:\Program Files\Adobe
    2008-11-13 21:10:23 ----D---- C:\Documents and Settings\HP_Administrator\Application Data\IMVU
    2008-11-13 21:09:28 ----D---- C:\Program Files\IMVU
    2008-11-13 19:29:32 ----D---- C:\WINDOWS\system32\ZoneLabs
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
    2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
    2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
    2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
    2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
    2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
    2008-10-06 19:54:26 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
    2008-10-04 06:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-09-05 05:42:02 ----A---- C:\WINDOWS\system32\msxml3.dll

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-19 26944]
    R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-19 110160]
    R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-19 50864]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
    R1 KLIF;KLIF; C:\WINDOWS\system32\DRIVERS\klif.sys [2007-07-19 127768]
    R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-07-09 394952]
    R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-19 20560]
    R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-19 94032]
    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
    R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-03 22784]
    R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 5376]
    R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 4992]
    R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-11 60800]
    R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-03 10112]
    R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-19 23152]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
    R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-09-29 1036928]
    R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2004-09-29 219136]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-15 4299264]
    R3 M1000Srv;Trek 320R Driver; C:\WINDOWS\System32\Drivers\M1000KNT.sys [2005-07-01 276926]
    R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
    R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-11 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
    R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-13 19072]
    R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-28 81408]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-03-31 27008]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-10 57600]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
    R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 26496]
    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-09-29 702592]
    R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM); C:\WINDOWS\system32\DRIVERS\zebrceb.sys [2007-04-13 62984]
    S3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-03 19200]
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
    S3 Diag69xp;Diag69xp; C:\WINDOWS\System32\Drivers\Diag69xp.sys [2006-05-11 11648]
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-02-01 49664]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-02-01 16496]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-02-01 21568]
    S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
    S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
    S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023k.sys [2008-01-11 11136]
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-10 20480]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S3 zebrbus;Sony Ericsson Composite Device driver; C:\WINDOWS\system32\DRIVERS\zebrbus.sys [2007-04-13 83080]
    S3 zebrmdfl;Sony Ericsson Modem Filter; C:\WINDOWS\system32\DRIVERS\zebrmdfl.sys [2007-04-13 15112]
    S3 zebrmdm;Sony Ericsson Port (WDM); C:\WINDOWS\system32\DRIVERS\zebrmdm.sys [2007-04-13 108296]
    S3 zebrmdmc;Sony Ericsson mRouter Port (WDM); C:\WINDOWS\system32\DRIVERS\zebrmdmc.sys [2007-04-13 108424]
    S3 zebrsce;Sony Ericsson PC-Connect Port; C:\WINDOWS\system32\DRIVERS\zebrsce.sys [2007-04-13 90888]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
    R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-03 58880]
    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-19 18752]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-19 155160]
    R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
    R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-14 152984]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
    R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
    R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
    R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-19 254040]
    R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-19 352920]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]
    R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-11-22 69632]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-10 267776]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-05 138168]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-05 774144]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

    -----------------EOF-----------------
     
  8. 2008/12/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looks great! Computer seem to be working properly again?
    Lets get an online scan to make sure we haven't overlooked anything. Please do an online scan with Kaspersky Online Scanner

    Click Accept, when prompted to download and install the program files and database of malware definitions.
    • Click Run at the Security prompt.
    • The program will then begin downloading and installing and will also update the database.
    • Please be patient as this can take several minutes.
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click View scan report at the bottom.
    • Click the Save Report As... button.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


    Post the Kaspersky log here.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.