• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1112
  • Last Modified:

Trojan Hunter finds msad.exe but can't remove it

How do I get rid of msad.exe?
0
freddick
Asked:
freddick
  • 3
  • 2
  • 2
  • +2
1 Solution
 
Asta CuCommented:
Have you scanned your system with updated Viruscan program?  Scanned for Spyware?  Here are some links and tools.
HijackThis has fixed that problem....
http://www.experts-exchange.com/Web/Browser_Issues/Q_21149514.html
Once you've installed HijackThis, paste your log here:
http://www.hijackthis.de/index.php?langselect=english
0
 
Asta CuCommented:
In general, this is what has worked for me when I've been 'invaded' with trojan/worm/virus or spyware/malware/malicious BHOs....  The get more and more sophisticated and worms change in nature and tough to isolate, oftentimes.

Prior to doing Spyware removal, be sure to use a good Viruscan program and also be sure it is updated and you do a full, deep scan of all drives.

ALSO, important, turn off system restore before doing this and Spyware fixes, or the problem will return. Once cleaned, you should enable System Restore again.

If Pop Ups arise, and Browser is hijacked, the quickest way to close the Browser window is ALT+F4.

This is a central link here compiled by a number of our Experts with Spyware tools, links and cautions/recommendations:
http://www.experts-exchange.com/Web/Browser_Issues/Q_20975384.html 
HijackThis can scan your system and create a log (and fix some things) ...
once this log is created, post the log results in this free analyzer:
http://www.hijackthis.de/index.php?langselect=english 
This is the HijackThis Guideline and process that makes sense to me:
http://www.experts-exchange.com/Web/Browser_Issues/Q_21149514.html 

Once you've run the log through the Analyzer, you're guided for the most part with recommendations, and some can be fixed by HijackThis, but some may show as "nasty" which aren't and may cause problems for you. So do encourage you to read the above link for cautions on this. Let us know only the line items which need further analysis by us.

My personal choices on the Spyware/Malware and Malicious BHO issue is to use these two programs:
AdAware (I chose the paid version which is SE Professional) but both also have free versions and always welcome contributions. Be sure it is the most current and updated, also make sure you configure it to do Deep Scanning and to include the HOSTS file. For Spybot S&D, if you choose that, be sure to update it and use the Immunize function to block @ 2500 spyware/malware intrusions.   It is important to note that once you've installed Spybot S&D, and may have had it installed previously and configured it to include the Immunize function to block intrusions, that after an updated, you do the Immunize again, to include the new blocked intruders.

Hope this is of help to you. Best wishes, let us know your progress.

":0) Asta
0
 
freddickAuthor Commented:
Scannned with up to date NAV
Ran AdAware SE
Ran S&D
Ran Trojan Hunter

output Trojan Hunter:

Registry scan
Registry key exists: HKEY_CLASSES_ROOT\ATLEvents.ATLEvents (matches Adware.VirtuMonde.102)
Registry key exists: HKEY_CLASSES_ROOT\ATLEvents.ATLEvents.1 (matches Adware.VirtuMonde.102)
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan (autostarted files, running executables)
Found trojan file: C:\WINDOWS\Microsoft.NET\msad.exe (KLog.Antivga.100)
Found trojan file: C:\WINDOWS\Microsoft.NET\msad.exe (KLog.Antivga.100)
Found trojan file: C:\WINDOWS\system32\bkinst.exe (Adware.VirtuMonde.105)
Found trojan file: C:\WINDOWS\Microsoft.NET\msad.exe (KLog.Antivga.100)
2 trojan files found
___________________________

Logfile of HijackThis v1.97.7
Scan saved at 10:24:00 PM, on 11/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\Microsoft.NET\msad.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r4.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r4.attbi.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\RB\LOCALS~1\Temp\ccaniw.dat (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\RB\LOCALS~1\Temp\dasm.dat
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [*msad] C:\WINDOWS\Microsoft.NET\msad.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\RunOnce: [*msad] C:\WINDOWS\Microsoft.NET\msad.exe rerun
O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system32\bkinst.exe ren time:1100312249
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1088603021531
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/PPInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
_____________________________________

8 seconds of filemon.log

1      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
2      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
3      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
4      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
5      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
6      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
7      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
8      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
9      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
10      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
11      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
12      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileInternalInformation      
13      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
14      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
15      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
16      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
17      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
18      10:38:27 PM      explorer.exe:1484      SET INFORMATION       C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileBasicInformation      
19      10:38:27 PM      explorer.exe:1484      READ       C:\temp\NTFILMON\Filemon.exe      SUCCESS      Offset: 0 Length: 12      
20      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
21      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
22      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
23      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
24      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
25      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
26      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
27      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
28      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
29      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
30      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
31      10:38:27 PM      Navapw32.exe:288      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
32      10:38:27 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
33      10:38:27 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
34      10:38:27 PM      Navapw32.exe:288      CLOSE      C:\      SUCCESS            
35      10:38:27 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
36      10:38:27 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
37      10:38:27 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
38      10:38:27 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
39      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileInternalInformation      
40      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
41      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
42      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
43      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
44      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
45      10:38:27 PM      explorer.exe:1484      SET INFORMATION       C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileBasicInformation      
46      10:38:27 PM      explorer.exe:1484      READ       C:\temp\NTFILMON\Filemon.exe      SUCCESS      Offset: 0 Length: 12      
47      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
48      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
49      10:38:27 PM      THGuard.exe:392      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
50      10:38:27 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
51      10:38:27 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
52      10:38:27 PM      THGuard.exe:392      CLOSE      C:\      SUCCESS            
53      10:38:27 PM      explorer.exe:1484      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
54      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
55      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
56      10:38:27 PM      explorer.exe:1484      CLOSE      C:\      SUCCESS            
57      10:38:27 PM      PPControl.exe:312      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
58      10:38:27 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
59      10:38:27 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
60      10:38:27 PM      PPControl.exe:312      CLOSE      C:\      SUCCESS            
61      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
62      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
63      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
64      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
65      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
66      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
67      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
68      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
69      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
70      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileInternalInformation      
71      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
72      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
73      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
74      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
75      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
76      10:38:27 PM      explorer.exe:1484      SET INFORMATION       C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileBasicInformation      
77      10:38:27 PM      explorer.exe:1484      READ       C:\temp\NTFILMON\Filemon.exe      SUCCESS      Offset: 0 Length: 12      
78      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
79      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
80      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
81      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
82      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
83      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
84      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
85      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
86      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
87      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
88      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
89      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileInternalInformation      
90      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
91      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
92      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
93      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
94      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
95      10:38:27 PM      explorer.exe:1484      SET INFORMATION       C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileBasicInformation      
96      10:38:27 PM      explorer.exe:1484      READ       C:\temp\NTFILMON\Filemon.exe      SUCCESS      Offset: 0 Length: 12      
97      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
98      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
99      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
100      10:38:27 PM      explorer.exe:1484      READ       C:      SUCCESS      Offset: 18178048 Length: 4096      
101      10:38:27 PM      explorer.exe:1484      READ       C:      SUCCESS      Offset: 18489344 Length: 4096      
102      10:38:27 PM      explorer.exe:1484      READ       C:      SUCCESS      Offset: 18485248 Length: 4096      
103      10:38:27 PM      explorer.exe:1484      READ       C:      SUCCESS      Offset: 18481152 Length: 4096      
104      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
105      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
106      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
107      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
108      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
109      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
110      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: Execute      
111      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
112      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      FileInternalInformation      
113      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
114      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
115      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
116      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
117      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Length: 212992      
118      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
119      10:38:27 PM      explorer.exe:1484      OPEN      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Options: Open  Access: All      
120      10:38:27 PM      explorer.exe:1484      QUERY INFORMATION      C:\temp\NTFILMON\Filemon.exe      SUCCESS      Attributes: CA      
121      10:38:27 PM      explorer.exe:1484      CLOSE      C:\temp\NTFILMON\Filemon.exe      SUCCESS            
122      10:38:27 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
123      10:38:27 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
124      10:38:27 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
125      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en-US_580a28ff\      FILE NOT FOUND      Options: Open Directory  Access: All      
126      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\      FILE NOT FOUND      Options: Open Directory  Access: All      
127      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\System32\en-US      FILE NOT FOUND      Options: Open  Access: All      
128      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\System32\en      FILE NOT FOUND      Options: Open  Access: All      
129      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\System32\      SUCCESS      Options: Open  Access: All      
130      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\System32\      SUCCESS      Attributes: D      
131      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\System32\      SUCCESS            
132      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\System32\      SUCCESS      Options: Open  Access: All      
133      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\System32\      SUCCESS      Attributes: D      
134      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\System32\      SUCCESS            
135      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en-US_f6b1e800.Manifest      FILE NOT FOUND      Options: Open  Access: All      
136      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls\6.0.0.0_en-US_6595b64144ccf1df\Microsoft.Windows.Common-Controls.DLL      PATH NOT FOUND      Options: Open  Access: All      
137      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_en_66c5eee6\      FILE NOT FOUND      Options: Open Directory  Access: All      
138      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\      FILE NOT FOUND      Options: Open Directory  Access: All      
139      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_en_5cce9bd9.Manifest      FILE NOT FOUND      Options: Open  Access: All      
140      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls\6.0.0.0_en_6595b64144ccf1df\Microsoft.Windows.Common-Controls.DLL      PATH NOT FOUND      Options: Open  Access: All      
141      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      SUCCESS      Options: Open Directory  Access: All      
142      10:38:28 PM      csrss.exe:636      DIRECTORY      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      SUCCESS      FileBothDirectoryInformation: *.policy      
143      10:38:28 PM      csrss.exe:636      DIRECTORY      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      SUCCESS      FileBothDirectoryInformation      
144      10:38:28 PM      csrss.exe:636      DIRECTORY      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      NO MORE FILES      FileBothDirectoryInformation      
145      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\      SUCCESS            
146      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      Options: Open Sequential  Access: All      
147      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      Options: Open  Access: All      
148      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      FileInternalInformation      
149      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS            
150      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      Options: Open  Access: All      
151      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      Length: 621      
152      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS            
153      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      FileFsVolumeInformation      
154      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      BUFFER OVERFLOW      FileAllInformation      
155      10:38:28 PM      csrss.exe:636      READ       C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS      Offset: 0 Length: 4095      
156      10:38:28 PM      csrss.exe:636      READ      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      END OF FILE      Offset: 621 Length: 8178      
157      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.2180.Policy      SUCCESS            
158      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls\      FILE NOT FOUND      Options: Open Directory  Access: All      
159      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
160      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Attributes:       
161      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
162      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
163      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Attributes:       
164      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
165      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en-US_186470ec\      FILE NOT FOUND      Options: Open Directory  Access: All      
166      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls.mui\      FILE NOT FOUND      Options: Open Directory  Access: All      
167      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.2600.2180_en-US_90e45242.Manifest      FILE NOT FOUND      Options: Open  Access: All      
168      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls.mui\6.0.2600.2180_en-US_6595b64144ccf1df\Microsoft.Windows.Common-Controls.mui.DLL      PATH NOT FOUND      Options: Open  Access: All      
169      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Policies\x86_Policy.6.0.Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_en_272036d3\      FILE NOT FOUND      Options: Open Directory  Access: All      
170      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\Assembly\GAC\Policy.6.0.Microsoft.Windows.Common-Controls.mui\      FILE NOT FOUND      Options: Open Directory  Access: All      
171      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls.mui_6595b64144ccf1df_6.0.2600.2180_en_f701061b.Manifest      FILE NOT FOUND      Options: Open  Access: All      
172      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\assembly\GAC\Microsoft.Windows.Common-Controls.mui\6.0.2600.2180_en_6595b64144ccf1df\Microsoft.Windows.Common-Controls.mui.DLL      PATH NOT FOUND      Options: Open  Access: All      
173      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open Sequential  Access: All      
174      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
175      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      FileInternalInformation      
176      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
177      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
178      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Length: 1862      
179      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
180      10:38:28 PM      csrss.exe:636      READ       C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Offset: 0 Length: 2      
181      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
182      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open Sequential  Access: All      
183      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
184      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      FileInternalInformation      
185      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
186      10:38:28 PM      csrss.exe:636      OPEN      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Options: Open  Access: All      
187      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Length: 1862      
188      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
189      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      FileFsVolumeInformation      
190      10:38:28 PM      csrss.exe:636      QUERY INFORMATION      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      BUFFER OVERFLOW      FileAllInformation      
191      10:38:28 PM      csrss.exe:636      READ       C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS      Offset: 0 Length: 4095      
192      10:38:28 PM      csrss.exe:636      READ      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      END OF FILE      Offset: 1862 Length: 8178      
193      10:38:28 PM      csrss.exe:636      CLOSE      C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9.Manifest      SUCCESS            
194      10:38:28 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
195      10:38:28 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
196      10:38:28 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
197      10:38:28 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
198      10:38:28 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
199      10:38:28 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
200      10:38:28 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
201      10:38:28 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
202      10:38:28 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
203      10:38:28 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
204      10:38:28 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
205      10:38:28 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
206      10:38:28 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
207      10:38:28 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
208      10:38:28 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
209      10:38:28 PM      TrojanHunter.ex:2760      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
210      10:38:28 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
211      10:38:28 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
212      10:38:28 PM      TrojanHunter.ex:2760      CLOSE      C:\      SUCCESS            
213      10:38:28 PM      lsass.exe:716      READ       C:      SUCCESS      Offset: 189440 Length: 32768      
214      10:38:28 PM      iexplore.exe:788      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
215      10:38:28 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
216      10:38:28 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
217      10:38:28 PM      iexplore.exe:788      CLOSE      C:\      SUCCESS            
218      10:38:28 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
219      10:38:28 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
220      10:38:28 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
221      10:38:29 PM      HijackThis.exe:448      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
222      10:38:29 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
223      10:38:29 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
224      10:38:29 PM      HijackThis.exe:448      CLOSE      C:\      SUCCESS            
225      10:38:29 PM      iexplore.exe:1180      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
226      10:38:29 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
227      10:38:29 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
228      10:38:29 PM      iexplore.exe:1180      CLOSE      C:\      SUCCESS            
229      10:38:29 PM      notepad.exe:1632      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
230      10:38:29 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
231      10:38:29 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
232      10:38:29 PM      notepad.exe:1632      CLOSE      C:\      SUCCESS            
233      10:38:29 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
234      10:38:29 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
235      10:38:29 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
236      10:38:29 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
237      10:38:29 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
238      10:38:29 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
239      10:38:29 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
240      10:38:29 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
241      10:38:29 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
242      10:38:29 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
243      10:38:29 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
244      10:38:29 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
245      10:38:29 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
246      10:38:29 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
247      10:38:29 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
248      10:38:29 PM      Navapw32.exe:288      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
249      10:38:29 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
250      10:38:29 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
251      10:38:29 PM      Navapw32.exe:288      CLOSE      C:\      SUCCESS            
252      10:38:29 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
253      10:38:29 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
254      10:38:29 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
255      10:38:29 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
256      10:38:29 PM      THGuard.exe:392      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
257      10:38:29 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
258      10:38:29 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
259      10:38:29 PM      THGuard.exe:392      CLOSE      C:\      SUCCESS            
260      10:38:29 PM      explorer.exe:1484      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
261      10:38:29 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
262      10:38:29 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
263      10:38:29 PM      explorer.exe:1484      CLOSE      C:\      SUCCESS            
264      10:38:29 PM      PPControl.exe:312      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
265      10:38:29 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
266      10:38:29 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
267      10:38:29 PM      PPControl.exe:312      CLOSE      C:\      SUCCESS            
268      10:38:29 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
269      10:38:29 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
270      10:38:29 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
271      10:38:30 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
272      10:38:30 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
273      10:38:30 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
274      10:38:30 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
275      10:38:30 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
276      10:38:30 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
277      10:38:30 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
278      10:38:30 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
279      10:38:30 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
280      10:38:30 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
281      10:38:30 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
282      10:38:30 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
283      10:38:30 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
284      10:38:30 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
285      10:38:30 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
286      10:38:30 PM      TrojanHunter.ex:2760      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
287      10:38:30 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
288      10:38:30 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
289      10:38:30 PM      TrojanHunter.ex:2760      CLOSE      C:\      SUCCESS            
290      10:38:30 PM      iexplore.exe:788      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
291      10:38:30 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
292      10:38:30 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
293      10:38:30 PM      iexplore.exe:788      CLOSE      C:\      SUCCESS            
294      10:38:30 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
295      10:38:30 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
296      10:38:30 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
297      10:38:31 PM      HijackThis.exe:448      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
298      10:38:31 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
299      10:38:31 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
300      10:38:31 PM      HijackThis.exe:448      CLOSE      C:\      SUCCESS            
301      10:38:31 PM      iexplore.exe:1180      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
302      10:38:31 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
303      10:38:31 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
304      10:38:31 PM      iexplore.exe:1180      CLOSE      C:\      SUCCESS            
305      10:38:31 PM      msad.exe:304      CREATE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: OverwriteIf  Access: All      
306      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
307      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
308      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS      SUCCESS      Options: Open  Access: All      
309      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS      SUCCESS      FileAlternateNameInformation      
310      10:38:31 PM      msad.exe:304      CLOSE      C:\WINDOWS      SUCCESS            
311      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET      SUCCESS      Options: Open  Access: All      
312      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET      SUCCESS      FileAlternateNameInformation      
313      10:38:31 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET      SUCCESS            
314      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
315      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
316      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: 00000000      
317      10:38:31 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: All      
318      10:38:31 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET\      SUCCESS      FileBothDirectoryInformation: msad.exe      
319      10:38:31 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\      SUCCESS            
320      10:38:31 PM      winlogon.exe:660      DIRECTORY      C:\WINDOWS      SUCCESS      Change Notify      
321      10:38:31 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET      SUCCESS      Change Notify      
322      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
323      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
324      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
325      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
326      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
327      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
328      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
329      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
330      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
331      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
332      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
333      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
334      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
335      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
336      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
337      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
338      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
339      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
340      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
341      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
342      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
343      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
344      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
345      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
346      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
347      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 4096 Length: 4096      
348      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 8192 Length: 552960      
349      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8192 Length: 65536      
350      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 73728 Length: 65536      
351      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 139264 Length: 65536      
352      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 204800 Length: 57344      
353      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
354      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
355      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
356      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
357      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
358      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
359      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
360      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
361      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
362      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
363      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
364      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
365      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
366      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
367      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
368      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
369      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
370      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
371      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
372      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
373      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
374      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
375      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
376      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
377      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
378      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
379      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
380      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
381      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
382      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
383      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
384      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
385      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 561152 Length: 4096      
386      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 565248 Length: 651264      
387      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 565248 Length: 65536      
388      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 630784 Length: 65536      
389      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 696320 Length: 65536      
390      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 761856 Length: 24576      
391      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 786432 Length: 65536      
392      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 851968 Length: 65536      
393      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 917504 Length: 65536      
394      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 983040 Length: 65536      
395      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
396      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
397      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
398      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
399      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
400      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
401      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
402      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
403      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
404      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
405      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
406      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
407      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
408      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
409      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
410      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
411      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
412      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
413      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
414      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
415      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
416      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
417      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
418      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
419      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
420      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
421      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
422      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
423      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1216512 Length: 4096      
424      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1220608 Length: 675840      
425      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1220608 Length: 65536      
426      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1286144 Length: 24576      
427      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1310720 Length: 65536      
428      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1376256 Length: 65536      
429      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1441792 Length: 65536      
430      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1507328 Length: 65536      
431      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
432      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
433      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
434      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
435      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
436      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
437      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
438      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
439      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
440      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
441      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
442      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
443      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
444      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
445      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
446      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
447      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
448      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
449      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
450      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
451      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
452      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
453      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
454      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
455      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
456      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
457      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
458      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
459      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
460      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
461      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
462      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
463      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1896448 Length: 4096      
464      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1900544 Length: 651264      
465      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1900544 Length: 65536      
466      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1966080 Length: 65536      
467      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2031616 Length: 65536      
468      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2097152 Length: 65536      
469      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2162688 Length: 65536      
470      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2228224 Length: 65536      
471      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2293760 Length: 65536      
472      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
473      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
474      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
475      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
476      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
477      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
478      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
479      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
480      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
481      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
482      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
483      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
484      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
485      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
486      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
487      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
488      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
489      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
490      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
491      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
492      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
493      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
494      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
495      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
496      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
497      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
498      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
499      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
500      10:38:31 PM      notepad.exe:1632      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
501      10:38:31 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
502      10:38:31 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
503      10:38:31 PM      notepad.exe:1632      CLOSE      C:\      SUCCESS            
504      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 2551808 Length: 4096      
505      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 2555904 Length: 675840      
506      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2555904 Length: 65536      
507      10:38:31 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
508      10:38:31 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
509      10:38:31 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
510      10:38:31 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
511      10:38:31 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
512      10:38:31 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
513      10:38:31 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
514      10:38:31 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
515      10:38:31 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
516      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2621440 Length: 65536      
517      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
518      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
519      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
520      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
521      10:38:31 PM      Navapw32.exe:288      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
522      10:38:31 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
523      10:38:31 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
524      10:38:31 PM      Navapw32.exe:288      CLOSE      C:\      SUCCESS            
525      10:38:31 PM      THGuard.exe:392      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
526      10:38:31 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
527      10:38:31 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
528      10:38:31 PM      THGuard.exe:392      CLOSE      C:\      SUCCESS            
529      10:38:31 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
530      10:38:31 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
531      10:38:31 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
532      10:38:31 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
533      10:38:31 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
534      10:38:31 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
535      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2686976 Length: 65536      
536      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2752512 Length: 65536      
537      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2818048 Length: 65536      
538      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2883584 Length: 65536      
539      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2949120 Length: 65536      
540      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3014656 Length: 65536      
541      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3080192 Length: 65536      
542      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
543      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
544      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
545      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
546      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
547      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
548      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
549      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
550      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
551      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
552      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
553      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
554      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
555      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
556      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
557      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
558      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
559      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
560      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
561      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
562      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
563      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
564      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
565      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
566      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
567      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
568      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
569      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
570      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
571      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
572      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
573      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
574      10:38:31 PM      explorer.exe:1484      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
575      10:38:31 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
576      10:38:31 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
577      10:38:31 PM      explorer.exe:1484      CLOSE      C:\      SUCCESS            
578      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 3231744 Length: 4096      
579      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 3235840 Length: 651264      
580      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3235840 Length: 65536      
581      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3301376 Length: 65536      
582      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3366912 Length: 40960      
583      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3407872 Length: 65536      
584      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3473408 Length: 65536      
585      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3538944 Length: 65536      
586      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3604480 Length: 65536      
587      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
588      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
589      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
590      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
591      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
592      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
593      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
594      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
595      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
596      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
597      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
598      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
599      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
600      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
601      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
602      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
603      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
604      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
605      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
606      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
607      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
608      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
609      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
610      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
611      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
612      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
613      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
614      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
615      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 3887104 Length: 4096      
616      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 3891200 Length: 675840      
617      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3891200 Length: 40960      
618      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3932160 Length: 65536      
619      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 3997696 Length: 65536      
620      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4063232 Length: 65536      
621      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4128768 Length: 65536      
622      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4194304 Length: 65536      
623      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4259840 Length: 65536      
624      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4325376 Length: 65536      
625      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4390912 Length: 65536      
626      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
627      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
628      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
629      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
630      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
631      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
632      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
633      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
634      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
635      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
636      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
637      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
638      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
639      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
640      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
641      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
642      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
643      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
644      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
645      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
646      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
647      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
648      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
649      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
650      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
651      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
652      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
653      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
654      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
655      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
656      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
657      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
658      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 4567040 Length: 4096      
659      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 4571136 Length: 651264      
660      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4571136 Length: 65536      
661      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4636672 Length: 65536      
662      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4702208 Length: 16384      
663      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4718592 Length: 65536      
664      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4784128 Length: 65536      
665      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4849664 Length: 65536      
666      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 4915200 Length: 65536      
667      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
668      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
669      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
670      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
671      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
672      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
673      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
674      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
675      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
676      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
677      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
678      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
679      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
680      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
681      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
682      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
683      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
684      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
685      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
686      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
687      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
688      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
689      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
690      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
691      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
692      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
693      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
694      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
695      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 5222400 Length: 4096      
696      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 5226496 Length: 675840      
697      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5226496 Length: 16384      
698      10:38:31 PM      PPControl.exe:312      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
699      10:38:31 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
700      10:38:31 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
701      10:38:31 PM      PPControl.exe:312      CLOSE      C:\      SUCCESS            
702      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5242880 Length: 65536      
703      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5308416 Length: 65536      
704      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5373952 Length: 65536      
705      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5439488 Length: 65536      
706      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5505024 Length: 65536      
707      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5570560 Length: 65536      
708      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5636096 Length: 65536      
709      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5701632 Length: 65536      
710      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
711      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
712      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
713      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
714      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
715      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
716      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
717      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
718      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
719      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
720      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
721      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
722      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
723      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
724      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
725      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
726      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
727      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
728      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
729      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
730      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
731      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
732      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
733      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
734      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
735      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
736      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
737      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
738      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
739      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
740      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
741      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
742      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 5902336 Length: 4096      
743      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 5906432 Length: 651264      
744      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5906432 Length: 65536      
745      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 5971968 Length: 57344      
746      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6029312 Length: 65536      
747      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6094848 Length: 65536      
748      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6160384 Length: 65536      
749      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6225920 Length: 65536      
750      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
751      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
752      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
753      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
754      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
755      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
756      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
757      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
758      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
759      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
760      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
761      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
762      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
763      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
764      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
765      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
766      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
767      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
768      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
769      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
770      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
771      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
772      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
773      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
774      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
775      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
776      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
777      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
778      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 6557696 Length: 4096      
779      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 6561792 Length: 675840      
780      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6561792 Length: 65536      
781      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6627328 Length: 65536      
782      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6692864 Length: 65536      
783      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6758400 Length: 57344      
784      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6815744 Length: 65536      
785      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6881280 Length: 65536      
786      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 6946816 Length: 65536      
787      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7012352 Length: 65536      
788      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
789      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
790      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
791      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
792      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
793      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
794      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
795      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
796      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
797      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
798      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
799      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
800      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
801      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
802      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
803      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
804      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
805      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
806      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
807      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
808      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
809      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
810      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
811      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
812      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
813      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
814      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
815      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
816      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
817      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
818      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
819      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
820      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7237632 Length: 4096      
821      10:38:31 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7241728 Length: 651264      
822      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7241728 Length: 65536      
823      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7307264 Length: 32768      
824      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7340032 Length: 65536      
825      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7405568 Length: 65536      
826      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7471104 Length: 65536      
827      10:38:31 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7536640 Length: 65536      
828      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
829      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
830      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
831      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
832      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
833      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
834      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
835      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
836      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
837      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
838      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
839      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
840      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
841      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
842      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
843      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
844      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
845      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
846      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
847      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
848      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
849      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
850      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
851      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
852      10:38:31 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
853      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
854      10:38:31 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
855      10:38:31 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
856      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7892992 Length: 4096      
857      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7897088 Length: 675840      
858      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7897088 Length: 65536      
859      10:38:32 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
860      10:38:32 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
861      10:38:32 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
862      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 7962624 Length: 65536      
863      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8028160 Length: 65536      
864      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8093696 Length: 32768      
865      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8126464 Length: 65536      
866      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8192000 Length: 65536      
867      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8257536 Length: 65536      
868      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8323072 Length: 65536      
869      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
870      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
871      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
872      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
873      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
874      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
875      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
876      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
877      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
878      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
879      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
880      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
881      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
882      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
883      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
884      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
885      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
886      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
887      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
888      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
889      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
890      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
891      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
892      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
893      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
894      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
895      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
896      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
897      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
898      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
899      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
900      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
901      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 8572928 Length: 4096      
902      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 8577024 Length: 651264      
903      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8577024 Length: 65536      
904      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8642560 Length: 8192      
905      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8650752 Length: 65536      
906      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8716288 Length: 65536      
907      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8781824 Length: 65536      
908      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8847360 Length: 65536      
909      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
910      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
911      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
912      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
913      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
914      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
915      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
916      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
917      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
918      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
919      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
920      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
921      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
922      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
923      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
924      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
925      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
926      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
927      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
928      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
929      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
930      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
931      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
932      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
933      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
934      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
935      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
936      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
937      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 9228288 Length: 4096      
938      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 9232384 Length: 675840      
939      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9232384 Length: 65536      
940      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9297920 Length: 65536      
941      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9363456 Length: 65536      
942      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9428992 Length: 8192      
943      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9437184 Length: 65536      
944      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9502720 Length: 65536      
945      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9568256 Length: 65536      
946      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9633792 Length: 65536      
947      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
948      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
949      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
950      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
951      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
952      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
953      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
954      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
955      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
956      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
957      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
958      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
959      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
960      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
961      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
962      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
963      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
964      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
965      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
966      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
967      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
968      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
969      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
970      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
971      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
972      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
973      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
974      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
975      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
976      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
977      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
978      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
979      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 9908224 Length: 4096      
980      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 9912320 Length: 651264      
981      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9912320 Length: 49152      
982      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 9961472 Length: 65536      
983      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10027008 Length: 65536      
984      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10092544 Length: 65536      
985      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10158080 Length: 65536      
986      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10223616 Length: 65536      
987      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10289152 Length: 65536      
988      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10354688 Length: 65536      
989      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10420224 Length: 65536      
990      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
991      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
992      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
993      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
994      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
995      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
996      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
997      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
998      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
999      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1000      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1001      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1002      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1003      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1004      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1005      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1006      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1007      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1008      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1009      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1010      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1011      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1012      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1013      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1014      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1015      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1016      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1017      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1018      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 10563584 Length: 4096      
1019      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 10567680 Length: 675840      
1020      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10567680 Length: 65536      
1021      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10633216 Length: 65536      
1022      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10698752 Length: 49152      
1023      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10747904 Length: 65536      
1024      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10813440 Length: 65536      
1025      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10878976 Length: 65536      
1026      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 10944512 Length: 65536      
1027      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1028      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1029      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1030      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1031      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1032      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1033      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1034      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1035      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1036      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1037      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1038      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1039      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1040      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1041      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1042      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1043      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1044      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1045      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1046      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1047      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1048      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1049      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1050      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1051      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1052      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1053      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1054      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1055      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1056      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1057      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1058      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1059      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 11243520 Length: 4096      
1060      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 11247616 Length: 651264      
1061      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11247616 Length: 24576      
1062      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11272192 Length: 65536      
1063      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11337728 Length: 65536      
1064      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11403264 Length: 65536      
1065      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11468800 Length: 65536      
1066      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11534336 Length: 65536      
1067      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11599872 Length: 65536      
1068      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11665408 Length: 65536      
1069      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11730944 Length: 65536      
1070      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1071      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1072      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1073      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1074      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1075      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1076      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1077      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1078      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1079      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1080      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1081      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1082      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1083      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1084      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1085      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1086      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1087      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1088      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1089      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1090      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1091      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1092      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1093      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1094      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1095      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1096      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1097      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1098      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 11898880 Length: 4096      
1099      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 11902976 Length: 454656      
1100      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11902976 Length: 65536      
1101      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 11968512 Length: 65536      
1102      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12034048 Length: 24576      
1103      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1104      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1105      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1106      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1107      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1108      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1109      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1110      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1111      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1112      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1113      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1114      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1115      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1116      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1117      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1118      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1119      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1120      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1121      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1122      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1123      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1124      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1125      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1126      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1127      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1128      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1129      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1130      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1131      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1132      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1133      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1134      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1135      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 12357632 Length: 4096      
1136      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 12361728 Length: 651264      
1137      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12361728 Length: 65536      
1138      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12427264 Length: 65536      
1139      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12492800 Length: 65536      
1140      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12558336 Length: 24576      
1141      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12582912 Length: 65536      
1142      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12648448 Length: 65536      
1143      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12713984 Length: 65536      
1144      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 12779520 Length: 65536      
1145      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1146      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1147      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1148      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1149      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1150      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1151      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1152      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1153      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1154      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1155      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1156      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1157      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1158      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1159      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1160      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1161      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1162      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1163      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1164      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1165      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1166      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1167      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1168      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1169      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1170      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1171      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1172      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1173      10:38:32 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
1174      10:38:32 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
1175      10:38:32 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
1176      10:38:32 PM      TrojanHunter.ex:2760      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1177      10:38:32 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1178      10:38:32 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1179      10:38:32 PM      TrojanHunter.ex:2760      CLOSE      C:\      SUCCESS            
1180      10:38:32 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1181      10:38:32 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1182      10:38:32 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1183      10:38:32 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1184      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 13012992 Length: 4096      
1185      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 13017088 Length: 675840      
1186      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13017088 Length: 65536      
1187      10:38:32 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1188      10:38:32 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1189      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13082624 Length: 24576      
1190      10:38:32 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
1191      10:38:32 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
1192      10:38:32 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
1193      10:38:32 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
1194      10:38:32 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
1195      10:38:32 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
1196      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13107200 Length: 65536      
1197      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13172736 Length: 65536      
1198      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13238272 Length: 65536      
1199      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13303808 Length: 65536      
1200      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1201      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1202      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1203      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1204      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1205      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1206      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1207      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1208      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1209      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1210      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1211      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1212      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1213      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1214      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1215      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1216      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1217      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1218      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1219      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1220      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1221      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1222      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1223      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1224      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1225      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1226      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1227      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1228      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1229      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1230      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1231      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1232      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 13692928 Length: 4096      
1233      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 13697024 Length: 651264      
1234      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13697024 Length: 65536      
1235      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13762560 Length: 65536      
1236      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13828096 Length: 65536      
1237      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13893632 Length: 65536      
1238      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 13959168 Length: 65536      
1239      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14024704 Length: 65536      
1240      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14090240 Length: 65536      
1241      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1242      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1243      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1244      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1245      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1246      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1247      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1248      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1249      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1250      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1251      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1252      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1253      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1254      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1255      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1256      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1257      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1258      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1259      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1260      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1261      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1262      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1263      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1264      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1265      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1266      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1267      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1268      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1269      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 14348288 Length: 4096      
1270      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 14352384 Length: 675840      
1271      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14352384 Length: 65536      
1272      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14417920 Length: 65536      
1273      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14483456 Length: 65536      
1274      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14548992 Length: 65536      
1275      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14614528 Length: 65536      
1276      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14680064 Length: 65536      
1277      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14745600 Length: 65536      
1278      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14811136 Length: 65536      
1279      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 14876672 Length: 65536      
1280      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1281      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1282      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1283      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1284      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1285      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1286      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1287      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1288      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1289      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1290      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1291      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1292      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1293      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1294      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1295      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1296      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1297      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1298      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1299      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1300      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1301      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1302      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1303      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1304      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1305      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1306      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1307      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1308      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1309      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1310      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1311      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1312      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 15028224 Length: 4096      
1313      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 15032320 Length: 651264      
1314      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15032320 Length: 65536      
1315      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15097856 Length: 65536      
1316      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15163392 Length: 40960      
1317      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15204352 Length: 65536      
1318      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15269888 Length: 65536      
1319      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15335424 Length: 65536      
1320      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15400960 Length: 65536      
1321      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1322      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1323      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1324      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1325      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1326      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1327      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1328      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1329      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1330      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1331      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1332      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1333      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1334      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1335      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1336      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1337      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1338      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1339      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1340      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1341      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1342      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1343      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1344      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1345      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1346      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1347      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1348      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1349      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 15683584 Length: 4096      
1350      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 15687680 Length: 675840      
1351      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15687680 Length: 40960      
1352      10:38:32 PM      iexplore.exe:788      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1353      10:38:32 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1354      10:38:32 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1355      10:38:32 PM      iexplore.exe:788      CLOSE      C:\      SUCCESS            
1356      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15728640 Length: 65536      
1357      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15794176 Length: 65536      
1358      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15859712 Length: 65536      
1359      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15925248 Length: 65536      
1360      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 15990784 Length: 65536      
1361      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16056320 Length: 65536      
1362      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16121856 Length: 65536      
1363      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16187392 Length: 65536      
1364      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1365      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1366      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1367      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1368      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1369      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1370      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1371      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1372      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1373      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1374      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1375      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1376      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1377      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1378      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1379      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1380      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1381      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1382      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1383      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1384      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1385      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1386      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1387      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1388      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1389      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1390      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1391      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1392      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1393      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1394      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1395      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1396      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 16363520 Length: 4096      
1397      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 16367616 Length: 651264      
1398      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16367616 Length: 65536      
1399      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16433152 Length: 65536      
1400      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16498688 Length: 16384      
1401      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16515072 Length: 65536      
1402      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16580608 Length: 65536      
1403      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16646144 Length: 65536      
1404      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 16711680 Length: 65536      
1405      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1406      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1407      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1408      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1409      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1410      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1411      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1412      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1413      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1414      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1415      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1416      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1417      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1418      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1419      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1420      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1421      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1422      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1423      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1424      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1425      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1426      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1427      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1428      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1429      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1430      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1431      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1432      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1433      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 17018880 Length: 4096      
1434      10:38:32 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 17022976 Length: 675840      
1435      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17022976 Length: 16384      
1436      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17039360 Length: 65536      
1437      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17104896 Length: 65536      
1438      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17170432 Length: 65536      
1439      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17235968 Length: 65536      
1440      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17301504 Length: 65536      
1441      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17367040 Length: 65536      
1442      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17432576 Length: 65536      
1443      10:38:32 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17498112 Length: 65536      
1444      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1445      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1446      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1447      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1448      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1449      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1450      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1451      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1452      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1453      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1454      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1455      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1456      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1457      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1458      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1459      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1460      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1461      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1462      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1463      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1464      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1465      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1466      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1467      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1468      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1469      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1470      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1471      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1472      10:38:32 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1473      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1474      10:38:32 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1475      10:38:32 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1476      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 17698816 Length: 4096      
1477      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 17702912 Length: 651264      
1478      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17702912 Length: 65536      
1479      10:38:33 PM      HijackThis.exe:448      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1480      10:38:33 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1481      10:38:33 PM      HijackThis.exe:448      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1482      10:38:33 PM      HijackThis.exe:448      CLOSE      C:\      SUCCESS            
1483      10:38:33 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
1484      10:38:33 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
1485      10:38:33 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
1486      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17768448 Length: 57344      
1487      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17825792 Length: 65536      
1488      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17891328 Length: 65536      
1489      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 17956864 Length: 65536      
1490      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18022400 Length: 65536      
1491      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1492      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1493      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1494      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1495      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1496      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1497      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1498      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1499      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1500      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1501      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1502      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1503      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1504      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1505      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1506      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1507      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1508      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1509      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1510      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1511      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1512      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1513      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1514      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1515      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1516      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1517      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1518      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1519      10:38:33 PM      iexplore.exe:1180      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1520      10:38:33 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1521      10:38:33 PM      iexplore.exe:1180      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1522      10:38:33 PM      iexplore.exe:1180      CLOSE      C:\      SUCCESS            
1523      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 18354176 Length: 4096      
1524      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 18358272 Length: 675840      
1525      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18358272 Length: 65536      
1526      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18423808 Length: 65536      
1527      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18489344 Length: 65536      
1528      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18554880 Length: 57344      
1529      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18612224 Length: 65536      
1530      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18677760 Length: 65536      
1531      10:38:33 PM      notepad.exe:1632      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1532      10:38:33 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1533      10:38:33 PM      notepad.exe:1632      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1534      10:38:33 PM      notepad.exe:1632      CLOSE      C:\      SUCCESS            
1535      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18743296 Length: 65536      
1536      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 18808832 Length: 65536      
1537      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1538      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1539      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1540      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1541      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1542      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1543      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1544      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1545      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1546      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1547      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1548      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1549      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1550      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1551      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1552      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1553      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1554      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1555      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1556      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1557      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1558      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1559      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1560      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1561      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1562      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1563      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1564      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1565      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1566      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1567      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1568      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1569      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 19034112 Length: 4096      
1570      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 19038208 Length: 651264      
1571      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19038208 Length: 65536      
1572      10:38:33 PM      Navapw32.exe:288      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1573      10:38:33 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1574      10:38:33 PM      Navapw32.exe:288      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1575      10:38:33 PM      Navapw32.exe:288      CLOSE      C:\      SUCCESS            
1576      10:38:33 PM      THGuard.exe:392      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1577      10:38:33 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1578      10:38:33 PM      THGuard.exe:392      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1579      10:38:33 PM      THGuard.exe:392      CLOSE      C:\      SUCCESS            
1580      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1581      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1582      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1583      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1584      10:38:33 PM      explorer.exe:1484      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1585      10:38:33 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1586      10:38:33 PM      explorer.exe:1484      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1587      10:38:33 PM      explorer.exe:1484      CLOSE      C:\      SUCCESS            
1588      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19103744 Length: 32768      
1589      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19136512 Length: 65536      
1590      10:38:33 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
1591      10:38:33 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
1592      10:38:33 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
1593      10:38:33 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1594      10:38:33 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1595      10:38:33 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1596      10:38:33 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1597      10:38:33 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1598      10:38:33 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1599      10:38:33 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
1600      10:38:33 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
1601      10:38:33 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
1602      10:38:33 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
1603      10:38:33 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
1604      10:38:33 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
1605      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19202048 Length: 65536      
1606      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19267584 Length: 65536      
1607      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19333120 Length: 65536      
1608      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1609      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1610      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1611      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1612      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1613      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1614      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1615      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1616      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1617      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1618      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1619      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1620      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1621      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1622      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1623      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1624      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1625      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1626      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1627      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1628      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1629      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1630      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1631      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1632      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1633      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1634      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1635      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1636      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 19689472 Length: 4096      
1637      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 19693568 Length: 675840      
1638      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19693568 Length: 65536      
1639      10:38:33 PM      PPControl.exe:312      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1640      10:38:33 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1641      10:38:33 PM      PPControl.exe:312      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1642      10:38:33 PM      PPControl.exe:312      CLOSE      C:\      SUCCESS            
1643      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19759104 Length: 65536      
1644      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19824640 Length: 65536      
1645      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19890176 Length: 32768      
1646      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19922944 Length: 65536      
1647      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 19988480 Length: 65536      
1648      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20054016 Length: 65536      
1649      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20119552 Length: 65536      
1650      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1651      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1652      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1653      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1654      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1655      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1656      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1657      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1658      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1659      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1660      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1661      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1662      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1663      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1664      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1665      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1666      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1667      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1668      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1669      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1670      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1671      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1672      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1673      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1674      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1675      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1676      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1677      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1678      10:38:33 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1679      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1680      10:38:33 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1681      10:38:33 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1682      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 20369408 Length: 4096      
1683      10:38:33 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 20373504 Length: 651264      
1684      10:38:33 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20373504 Length: 65536      
1685      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20439040 Length: 8192      
1686      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20447232 Length: 65536      
1687      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20512768 Length: 65536      
1688      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20578304 Length: 65536      
1689      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 20643840 Length: 65536      
1690      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1691      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1692      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1693      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1694      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1695      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1696      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1697      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1698      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1699      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1700      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1701      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1702      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1703      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1704      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1705      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1706      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1707      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1708      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1709      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1710      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1711      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1712      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1713      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1714      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1715      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1716      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1717      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1718      10:38:34 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
1719      10:38:34 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
1720      10:38:34 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
1721      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 21024768 Length: 4096      
1722      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 21028864 Length: 675840      
1723      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21028864 Length: 65536      
1724      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21094400 Length: 65536      
1725      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21159936 Length: 65536      
1726      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21225472 Length: 8192      
1727      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21233664 Length: 65536      
1728      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21299200 Length: 65536      
1729      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21364736 Length: 65536      
1730      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21430272 Length: 65536      
1731      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1732      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1733      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1734      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1735      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1736      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1737      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1738      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1739      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1740      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1741      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1742      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1743      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1744      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1745      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1746      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1747      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1748      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1749      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1750      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1751      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1752      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1753      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1754      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1755      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1756      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1757      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1758      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1759      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1760      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1761      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1762      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1763      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 21704704 Length: 4096      
1764      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 21708800 Length: 651264      
1765      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21708800 Length: 49152      
1766      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21757952 Length: 65536      
1767      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21823488 Length: 65536      
1768      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21889024 Length: 65536      
1769      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 21954560 Length: 65536      
1770      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22020096 Length: 65536      
1771      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22085632 Length: 65536      
1772      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22151168 Length: 65536      
1773      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22216704 Length: 65536      
1774      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1775      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1776      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1777      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1778      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1779      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1780      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1781      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1782      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1783      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1784      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1785      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1786      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1787      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1788      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1789      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1790      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1791      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1792      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1793      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1794      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1795      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1796      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1797      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1798      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1799      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1800      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1801      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1802      10:38:34 PM      TrojanHunter.ex:2760      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1803      10:38:34 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1804      10:38:34 PM      TrojanHunter.ex:2760      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1805      10:38:34 PM      TrojanHunter.ex:2760      CLOSE      C:\      SUCCESS            
1806      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 22360064 Length: 4096      
1807      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 22364160 Length: 675840      
1808      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22364160 Length: 65536      
1809      10:38:34 PM      THGuard.exe:392      OPEN      C:\Program Files\TrojanHunter 4.0\      SUCCESS      Options: Open Directory  Access: All      
1810      10:38:34 PM      THGuard.exe:392      DIRECTORY      C:\Program Files\TrojanHunter 4.0\      SUCCESS      FileBothDirectoryInformation: ProcessRules.trf      
1811      10:38:34 PM      THGuard.exe:392      CLOSE      C:\Program Files\TrojanHunter 4.0\      SUCCESS            
1812      10:38:34 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1813      10:38:34 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1814      10:38:34 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1815      10:38:34 PM      PPMemCheck.exe:320      OPEN      C:\WINDOWS\system32\psapi.dll      SUCCESS      Options: Open  Access: All      
1816      10:38:34 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\WINDOWS\system32\psapi.dll      SUCCESS      Attributes: A      
1817      10:38:34 PM      PPMemCheck.exe:320      CLOSE      C:\WINDOWS\system32\psapi.dll      SUCCESS            
1818      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22429696 Length: 65536      
1819      10:38:34 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Options: Open  Access: All      
1820      10:38:34 PM      PPMemCheck.exe:320      QUERY INFORMATION      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS      Attributes: CA      
1821      10:38:34 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\CookiePatrol.exe      SUCCESS            
1822      10:38:34 PM      PPMemCheck.exe:320      OPEN      C:\PROGRA~1\PESTPA~1\      SUCCESS      Options: Open Directory  Access: All      
1823      10:38:34 PM      PPMemCheck.exe:320      DIRECTORY      C:\PROGRA~1\PESTPA~1\      SUCCESS      FileBothDirectoryInformation: CookiePatrol.exe      
1824      10:38:34 PM      PPMemCheck.exe:320      CLOSE      C:\PROGRA~1\PESTPA~1\      SUCCESS            
1825      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22495232 Length: 49152      
1826      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22544384 Length: 65536      
1827      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22609920 Length: 65536      
1828      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22675456 Length: 65536      
1829      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 22740992 Length: 65536      
1830      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1831      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1832      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1833      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1834      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1835      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1836      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1837      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1838      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1839      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1840      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1841      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1842      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1843      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1844      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1845      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1846      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1847      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1848      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1849      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1850      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1851      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1852      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1853      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1854      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1855      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1856      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1857      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1858      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1859      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1860      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1861      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1862      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23040000 Length: 4096      
1863      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23044096 Length: 651264      
1864      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23044096 Length: 24576      
1865      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23068672 Length: 65536      
1866      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23134208 Length: 65536      
1867      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23199744 Length: 65536      
1868      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23265280 Length: 65536      
1869      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23330816 Length: 65536      
1870      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23396352 Length: 65536      
1871      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23461888 Length: 65536      
1872      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 23527424 Length: 65536      
1873      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
1874      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
1875      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
1876      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
1877      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23695360 Length: 1499      
1878      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1879      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS      SUCCESS      Options: Open  Access: All      
1880      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS      SUCCESS      FileAlternateNameInformation      
1881      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS      SUCCESS            
1882      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET      SUCCESS      Options: Open  Access: All      
1883      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET      SUCCESS      FileAlternateNameInformation      
1884      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET      SUCCESS            
1885      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1886      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileAlternateNameInformation      
1887      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1888      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1889      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1890      10:38:34 PM      msad.exe:304      READ       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 256      
1891      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 512 Length: 256      
1892      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696347 Length: 512      
1893      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23695885 Length: 256      
1894      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1099 Length: 256      
1895      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23688920 Length: 256      
1896      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23687859 Length: 256      
1897      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23690715 Length: 256      
1898      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696048 Length: 256      
1899      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696029 Length: 256      
1900      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23690270 Length: 256      
1901      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7172 Length: 256      
1902      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1903      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1904      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 65024 Length: 512      
1905      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 2      
1906      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1907      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1908      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1909      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
1910      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23692763 Length: 4096      
1911      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
1912      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1913      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 64      
1914      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1915      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1916      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1917      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1918      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1919      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS      Options: Open  Access: All      
1920      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS      FileAttributeTagInformation      
1921      10:38:34 PM      msad.exe:304      DELETE       C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS            
1922      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS            
1923      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: All      
1924      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET\      SUCCESS      FileBothDirectoryInformation: msad.exe      
1925      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\      SUCCESS            
1926      10:38:34 PM      winlogon.exe:660      DIRECTORY      C:\WINDOWS      SUCCESS      Change Notify      
1927      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET      NOTIFY ENUM DIR      Change Notify      
1928      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1929      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileAttributeTagInformation      
1930      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Attributes: A      
1931      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS      Options: Open  Access: All      
1932      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      FILE NOT FOUND      Options: Open  Access: All      
1933      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      FILE NOT FOUND      Options: Open  Access: All      
1934      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS      SUCCESS      Options: Open  Access: All      
1935      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS      SUCCESS      FileAlternateNameInformation      
1936      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS      SUCCESS            
1937      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET      SUCCESS      Options: Open  Access: All      
1938      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET      SUCCESS      FileAlternateNameInformation      
1939      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET      SUCCESS            
1940      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      FILE NOT FOUND      Options: Open  Access: All      
1941      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      FILE NOT FOUND      Options: Open  Access: All      
1942      10:38:34 PM      msad.exe:304      SET INFORMATION       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileRenameInformation      
1943      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1944      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileBasicInformation      
1945      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1946      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1947      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileInternalInformation      
1948      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1949      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS      SUCCESS      Options: Open  Access: All      
1950      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS      SUCCESS      FileAlternateNameInformation      
1951      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS      SUCCESS            
1952      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET      SUCCESS      Options: Open  Access: All      
1953      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET      SUCCESS      FileAlternateNameInformation      
1954      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET      SUCCESS            
1955      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1956      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      FileAlternateNameInformation      
1957      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1958      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: Open  Access: All      
1959      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1960      10:38:34 PM      msad.exe:304      READ       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 256      
1961      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 512 Length: 256      
1962      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696347 Length: 512      
1963      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23695885 Length: 256      
1964      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1099 Length: 256      
1965      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23688920 Length: 256      
1966      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23687859 Length: 256      
1967      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23690715 Length: 256      
1968      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696048 Length: 256      
1969      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23696029 Length: 256      
1970      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23690270 Length: 256      
1971      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 7172 Length: 256      
1972      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1973      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1974      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 65024 Length: 512      
1975      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 2      
1976      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1977      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1978      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1979      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
1980      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 23692763 Length: 4096      
1981      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
1982      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1983      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 64      
1984      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1985      10:38:34 PM      msad.exe:304      READ      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 512      
1986      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1987      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Length: 23696859      
1988      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS            
1989      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: 00000000      
1990      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: All      
1991      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET\      SUCCESS      FileBothDirectoryInformation: msad.exe      
1992      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\      SUCCESS            
1993      10:38:34 PM      winlogon.exe:660      DIRECTORY      C:\WINDOWS      SUCCESS      Change Notify      
1994      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET      SUCCESS      Change Notify      
1995      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS            
1996      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS      Options: Open  Access: All      
1997      10:38:34 PM      msad.exe:304      SET INFORMATION       C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS      FileBasicInformation      
1998      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\dasm.ini      SUCCESS            
1999      10:38:34 PM      msad.exe:304      READ       C:      SUCCESS      Offset: 14077952 Length: 4096      
2000      10:38:34 PM      msad.exe:304      CREATE      C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Options: OverwriteIf  Access: All      
2001      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
2002      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
2003      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS      SUCCESS      Options: Open  Access: All      
2004      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS      SUCCESS      FileAlternateNameInformation      
2005      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS      SUCCESS            
2006      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET      SUCCESS      Options: Open  Access: All      
2007      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\WINDOWS\Microsoft.NET      SUCCESS      FileAlternateNameInformation      
2008      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET      SUCCESS            
2009      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
2010      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\dasm.tmp      FILE NOT FOUND      Options: Open  Access: All      
2011      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: 00000000      
2012      10:38:34 PM      msad.exe:304      OPEN      C:\WINDOWS\Microsoft.NET\      SUCCESS      Options: Open Directory  Access: All      
2013      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET\      SUCCESS      FileBothDirectoryInformation: msad.exe      
2014      10:38:34 PM      msad.exe:304      CLOSE      C:\WINDOWS\Microsoft.NET\      SUCCESS            
2015      10:38:34 PM      winlogon.exe:660      DIRECTORY      C:\WINDOWS            Change Notify      
2016      10:38:34 PM      msad.exe:304      DIRECTORY      C:\WINDOWS\Microsoft.NET            Change Notify      
2017      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 0 Length: 4096      
2018      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2019      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2020      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2021      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2022      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2023      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2024      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2025      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2026      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2027      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2028      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2029      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2030      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2031      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2032      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2033      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2034      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2035      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2036      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2037      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2038      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2039      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2040      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2041      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2042      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 4096 Length: 4096      
2043      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 8192 Length: 552960      
2044      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 8192 Length: 65536      
2045      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 73728 Length: 65536      
2046      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 139264 Length: 65536      
2047      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 204800 Length: 57344      
2048      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2049      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2050      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2051      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2052      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2053      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2054      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2055      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2056      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2057      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2058      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2059      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2060      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2061      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2062      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2063      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2064      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2065      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2066      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2067      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2068      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2069      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2070      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2071      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2072      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2073      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2074      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2075      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2076      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2077      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2078      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2079      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2080      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 561152 Length: 4096      
2081      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 565248 Length: 651264      
2082      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 565248 Length: 65536      
2083      10:38:34 PM      iexplore.exe:788      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2084      10:38:34 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2085      10:38:34 PM      iexplore.exe:788      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2086      10:38:34 PM      iexplore.exe:788      CLOSE      C:\      SUCCESS            
2087      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 630784 Length: 65536      
2088      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 696320 Length: 65536      
2089      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 761856 Length: 24576      
2090      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 786432 Length: 65536      
2091      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 851968 Length: 65536      
2092      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 917504 Length: 65536      
2093      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 983040 Length: 65536      
2094      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2095      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2096      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2097      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2098      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2099      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2100      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2101      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2102      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2103      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2104      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2105      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2106      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2107      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2108      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2109      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2110      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2111      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2112      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2113      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2114      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2115      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2116      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2117      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2118      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2119      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2120      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2121      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2122      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1216512 Length: 4096      
2123      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1220608 Length: 675840      
2124      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1220608 Length: 65536      
2125      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1286144 Length: 24576      
2126      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1310720 Length: 65536      
2127      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1376256 Length: 65536      
2128      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1441792 Length: 65536      
2129      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1507328 Length: 65536      
2130      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2131      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2132      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2133      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2134      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2135      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2136      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2137      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2138      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2139      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2140      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2141      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2142      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2143      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2144      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2145      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2146      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2147      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2148      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2149      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2150      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2151      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2152      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2153      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2154      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2155      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2156      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2157      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2158      10:38:34 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2159      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2160      10:38:34 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2161      10:38:34 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2162      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1896448 Length: 4096      
2163      10:38:34 PM      msad.exe:304      WRITE       C:\WINDOWS\Microsoft.NET\dasm.tmp      SUCCESS      Offset: 1900544 Length: 651264      
2164      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1900544 Length: 65536      
2165      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 1966080 Length: 65536      
2166      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2031616 Length: 65536      
2167      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2097152 Length: 65536      
2168      10:38:34 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2162688 Length: 65536      
2169      10:38:35 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2228224 Length: 65536      
2170      10:38:35 PM      msad.exe:304      WRITE       C:\$ConvertToNonresident      SUCCESS      Offset: 2293760 Length: 65536      
2171      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2172      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2173      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2174      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2175      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2176      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2177      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2178      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2179      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2180      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2181      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2182      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2183      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2184      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2185      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2186      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2187      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2188      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2189      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2190      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2191      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2192      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2193      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2194      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
2195      10:38:35 PM      msad.exe:304      OPEN      C:\      SUCCESS      Options: Open Directory  Access: All      
2196      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileNameInformation      
2197      10:38:35 PM      msad.exe:304      QUERY INFORMATION      C:\      SUCCESS      FileFsVolumeInformation      
2198      10:38:35 PM      msad.exe:304      CLOSE      C:\      SUCCESS            
0
2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

 
dheeruthakurCommented:
its necessary for you to fing the .dll file of this, use DllCpmpare you got this tool from locate.com. Use this tools (in this tools you have 2 options search through .dll or.exe, find  msad.exe and its dll )
0
 
freddickAuthor Commented:
???Not sure what it's supposed to look like???

*    DLLCompare Log version(1.0.0.125)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINDOWS\MICROS~1.NET\msad.exe       Fri Nov 12 2004  10:44:46p  ..SH.        855,040   835.00 K
________________________________________________

1 item found:  1 file (1 H/S), 0 directories.
Total of file sizes:  855,040 bytes    835.00 K

Administrator Account =  True

--------------------End log---------------------
0
 
freddickAuthor Commented:
Got rid of msad.exe !!!!

ran HJT
checked msad items
killbox'd msad for after reboot
fixed checked in HJT
booted Safe mode
deleted users temp dir under local settings
reboot

and it was gone. bye bye
0
 
Paul SCommented:
good job.
0
 
moduloCommented:
PAQed with points refunded (250)

modulo
Community Support Moderator
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

  • 3
  • 2
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now