freddick
asked on
Trojan Hunter finds msad.exe but can't remove it
How do I get rid of msad.exe?
In general, this is what has worked for me when I've been 'invaded' with trojan/worm/virus or spyware/malware/malicious BHOs.... The get more and more sophisticated and worms change in nature and tough to isolate, oftentimes.
Prior to doing Spyware removal, be sure to use a good Viruscan program and also be sure it is updated and you do a full, deep scan of all drives.
ALSO, important, turn off system restore before doing this and Spyware fixes, or the problem will return. Once cleaned, you should enable System Restore again.
If Pop Ups arise, and Browser is hijacked, the quickest way to close the Browser window is ALT+F4.
This is a central link here compiled by a number of our Experts with Spyware tools, links and cautions/recommendations:
https://www.experts-exchange.com/questions/20975384/Standard-response-material-re-Spyware-Adware-BHOs-and-other-Malware.html
HijackThis can scan your system and create a log (and fix some things) ...
once this log is created, post the log results in this free analyzer:
http://www.hijackthis.de/index.php?langselect=english
This is the HijackThis Guideline and process that makes sense to me:
https://www.experts-exchange.com/questions/21149514/Instructions-regarding-the-handling-of-HIJACK-THIS-logs.html
Once you've run the log through the Analyzer, you're guided for the most part with recommendations, and some can be fixed by HijackThis, but some may show as "nasty" which aren't and may cause problems for you. So do encourage you to read the above link for cautions on this. Let us know only the line items which need further analysis by us.
My personal choices on the Spyware/Malware and Malicious BHO issue is to use these two programs:
AdAware (I chose the paid version which is SE Professional) but both also have free versions and always welcome contributions. Be sure it is the most current and updated, also make sure you configure it to do Deep Scanning and to include the HOSTS file. For Spybot S&D, if you choose that, be sure to update it and use the Immunize function to block @ 2500 spyware/malware intrusions. It is important to note that once you've installed Spybot S&D, and may have had it installed previously and configured it to include the Immunize function to block intrusions, that after an updated, you do the Immunize again, to include the new blocked intruders.
Hope this is of help to you. Best wishes, let us know your progress.
":0) Asta
Prior to doing Spyware removal, be sure to use a good Viruscan program and also be sure it is updated and you do a full, deep scan of all drives.
ALSO, important, turn off system restore before doing this and Spyware fixes, or the problem will return. Once cleaned, you should enable System Restore again.
If Pop Ups arise, and Browser is hijacked, the quickest way to close the Browser window is ALT+F4.
This is a central link here compiled by a number of our Experts with Spyware tools, links and cautions/recommendations:
https://www.experts-exchange.com/questions/20975384/Standard-response-material-re-Spyware-Adware-BHOs-and-other-Malware.html
HijackThis can scan your system and create a log (and fix some things) ...
once this log is created, post the log results in this free analyzer:
http://www.hijackthis.de/index.php?langselect=english
This is the HijackThis Guideline and process that makes sense to me:
https://www.experts-exchange.com/questions/21149514/Instructions-regarding-the-handling-of-HIJACK-THIS-logs.html
Once you've run the log through the Analyzer, you're guided for the most part with recommendations, and some can be fixed by HijackThis, but some may show as "nasty" which aren't and may cause problems for you. So do encourage you to read the above link for cautions on this. Let us know only the line items which need further analysis by us.
My personal choices on the Spyware/Malware and Malicious BHO issue is to use these two programs:
AdAware (I chose the paid version which is SE Professional) but both also have free versions and always welcome contributions. Be sure it is the most current and updated, also make sure you configure it to do Deep Scanning and to include the HOSTS file. For Spybot S&D, if you choose that, be sure to update it and use the Immunize function to block @ 2500 spyware/malware intrusions. It is important to note that once you've installed Spybot S&D, and may have had it installed previously and configured it to include the Immunize function to block intrusions, that after an updated, you do the Immunize again, to include the new blocked intruders.
Hope this is of help to you. Best wishes, let us know your progress.
":0) Asta
ASKER
Scannned with up to date NAV
Ran AdAware SE
Ran S&D
Ran Trojan Hunter
output Trojan Hunter:
Registry scan
Registry key exists: HKEY_CLASSES_ROOT\ATLEvent s.ATLEvent s (matches Adware.VirtuMonde.102)
Registry key exists: HKEY_CLASSES_ROOT\ATLEvent s.ATLEvent s.1 (matches Adware.VirtuMonde.102)
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan (autostarted files, running executables)
Found trojan file: C:\WINDOWS\Microsoft.NET\m sad.exe (KLog.Antivga.100)
Found trojan file: C:\WINDOWS\Microsoft.NET\m sad.exe (KLog.Antivga.100)
Found trojan file: C:\WINDOWS\system32\bkinst .exe (Adware.VirtuMonde.105)
Found trojan file: C:\WINDOWS\Microsoft.NET\m sad.exe (KLog.Antivga.100)
2 trojan files found
__________________________ _
Logfile of HijackThis v1.97.7
Scan saved at 10:24:00 PM, on 11/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\csrss. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools v.exe
C:\PROGRA~1\NORTON~1\navap w32.exe
C:\WINDOWS\Microsoft.NET\m sad.exe
C:\PROGRA~1\PESTPA~1\PPCon trol.exe
C:\PROGRA~1\PESTPA~1\PPMem Check.exe
C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e
C:\WINDOWS\System32\cisvc. exe
C:\WINDOWS\System32\CTsvcC DA.exe
C:\WINDOWS\System32\GEARSE C.EXE
C:\PROGRA~1\Iomega\System3 2\AppServi ces.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\wdfmgr .exe
C:\WINDOWS\System32\MsPMSP Sv.exe
C:\WINDOWS\System32\alg.ex e
C:\WINDOWS\system32\cidaem on.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Internet Settings,ProxyServer = sas.r4.attbi.com:8000
R1 - HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Internet Settings,ProxyOverride = *.r4.attbi.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH elper.ocx
O2 - BHO: (no name) - {3EC8E271-FAB9-418a-8A8E-6 5AEB4029E6 4} - C:\DOCUME~1\RB\LOCALS~1\Te mp\ccaniw. dat (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2 06D7942484 F} - C:\PROGRA~1\SPYBOT~1\SDHel per.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F ADC6B08487 2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F 0CF619D672 F} - C:\DOCUME~1\RB\LOCALS~1\Te mp\dasm.da t
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2 09B6AD74AC C} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7 859DF00B1D 6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 1.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo n.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navap w32.exe
O4 - HKLM\..\Run: [*msad] C:\WINDOWS\Microsoft.NET\m sad.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPCon trol.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMem Check.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\RunOnce: [*msad] C:\WINDOWS\Microsoft.NET\m sad.exe rerun
O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system32\bkinst .exe ren time:1100312249
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar 1.dll/cmse arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar 1.dll/cmba cklinks.ht ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar 1.dll/cmca che.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar 1.dll/cmsi milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar 1.dll/cmtr ans.html
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0 000C07D88C F} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2 407B42F57C 9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1088603021531
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4 1EE9F4C36C E} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-B FCD433CEE3 0} - http://www.surfsecret.com/inst/PPInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5 009F29E09E 1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4 4455354000 0} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
__________________________ __________ _
8 seconds of filemon.log
1 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
2 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
3 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
4 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
5 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
6 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
7 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
8 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
9 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
10 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
11 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
12 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileInternalInformation
13 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
14 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
15 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
16 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
17 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
18 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileBasicInformation
19 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e xe SUCCESS Offset: 0 Length: 12
20 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
21 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
22 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
23 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
24 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
25 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
26 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
27 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
28 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
29 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
30 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
31 10:38:27 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
32 10:38:27 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
33 10:38:27 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
34 10:38:27 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
35 10:38:27 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
36 10:38:27 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
37 10:38:27 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
38 10:38:27 PM msad.exe:304 CLOSE C:\ SUCCESS
39 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileInternalInformation
40 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
41 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
42 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
43 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
44 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
45 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileBasicInformation
46 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e xe SUCCESS Offset: 0 Length: 12
47 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
48 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
49 10:38:27 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
50 10:38:27 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
51 10:38:27 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
52 10:38:27 PM THGuard.exe:392 CLOSE C:\ SUCCESS
53 10:38:27 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
54 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
55 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
56 10:38:27 PM explorer.exe:1484 CLOSE C:\ SUCCESS
57 10:38:27 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
58 10:38:27 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
59 10:38:27 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
60 10:38:27 PM PPControl.exe:312 CLOSE C:\ SUCCESS
61 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
62 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
63 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
64 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
65 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
66 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
67 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
68 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
69 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
70 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileInternalInformation
71 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
72 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
73 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
74 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
75 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
76 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileBasicInformation
77 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e xe SUCCESS Offset: 0 Length: 12
78 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
79 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
80 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
81 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
82 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
83 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
84 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
85 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
86 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
87 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
88 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
89 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileInternalInformation
90 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
91 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
92 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
93 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
94 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
95 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileBasicInformation
96 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e xe SUCCESS Offset: 0 Length: 12
97 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
98 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
99 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
100 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18178048 Length: 4096
101 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18489344 Length: 4096
102 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18485248 Length: 4096
103 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18481152 Length: 4096
104 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
105 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
106 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
107 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
108 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
109 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
110 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: Execute
111 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
112 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS FileInternalInformation
113 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
114 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
115 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
116 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
117 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Length: 212992
118 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
119 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e xe SUCCESS Options: Open Access: All
120 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e xe SUCCESS Attributes: CA
121 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e xe SUCCESS
122 10:38:27 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
123 10:38:27 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
124 10:38:27 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
125 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_en- US_580a28f f\ FILE NOT FOUND Options: Open Directory Access: All
126 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po licy.6.0.M icrosoft.W indows.Com mon-Contro ls\ FILE NOT FOUND Options: Open Directory Access: All
127 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\en-US FILE NOT FOUND Options: Open Access: All
128 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\en FILE NOT FOUND Options: Open Access: All
129 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\ SUCCESS Options: Open Access: All
130 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\System32\ SUCCESS Attributes: D
131 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\System32\ SUCCESS
132 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\ SUCCESS Options: Open Access: All
133 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\System32\ SUCCESS Attributes: D
134 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\System32\ SUCCESS
135 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .0.0_en-US _f6b1e800. Manifest FILE NOT FOUND Options: Open Access: All
136 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi crosoft.Wi ndows.Comm on-Control s\6.0.0.0_ en-US_6595 b64144ccf1 df\Microso ft.Windows .Common-Co ntrols.DLL PATH NOT FOUND Options: Open Access: All
137 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_en_ 66c5eee6\ FILE NOT FOUND Options: Open Directory Access: All
138 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po licy.6.0.M icrosoft.W indows.Com mon-Contro ls\ FILE NOT FOUND Options: Open Directory Access: All
139 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .0.0_en_5c ce9bd9.Man ifest FILE NOT FOUND Options: Open Access: All
140 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi crosoft.Wi ndows.Comm on-Control s\6.0.0.0_ en_6595b64 144ccf1df\ Microsoft. Windows.Co mmon-Contr ols.DLL PATH NOT FOUND Options: Open Access: All
141 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \ SUCCESS Options: Open Directory Access: All
142 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \ SUCCESS FileBothDirectoryInformati on: *.policy
143 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \ SUCCESS FileBothDirectoryInformati on
144 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \ NO MORE FILES FileBothDirectoryInformati on
145 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \ SUCCESS
146 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS Options: Open Sequential Access: All
147 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS Options: Open Access: All
148 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS FileInternalInformation
149 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS
150 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS Options: Open Access: All
151 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS Length: 621
152 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS
153 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS FileFsVolumeInformation
154 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y BUFFER OVERFLOW FileAllInformation
155 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS Offset: 0 Length: 4095
156 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y END OF FILE Offset: 621 Length: 8178
157 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_x-w w_5ddad775 \6.0.2600. 2180.Polic y SUCCESS
158 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po licy.6.0.M icrosoft.W indows.Com mon-Contro ls\ FILE NOT FOUND Options: Open Directory Access: All
159 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
160 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Attributes:
161 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
162 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
163 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Attributes:
164 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
165 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls. mui_6595b6 4144ccf1df _en-US_186 470ec\ FILE NOT FOUND Options: Open Directory Access: All
166 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po licy.6.0.M icrosoft.W indows.Com mon-Contro ls.mui\ FILE NOT FOUND Options: Open Directory Access: All
167 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls. mui_6595b6 4144ccf1df _6.0.2600. 2180_en-US _90e45242. Manifest FILE NOT FOUND Options: Open Access: All
168 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi crosoft.Wi ndows.Comm on-Control s.mui\6.0. 2600.2180_ en-US_6595 b64144ccf1 df\Microso ft.Windows .Common-Co ntrols.mui .DLL PATH NOT FOUND Options: Open Access: All
169 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies \x86_Polic y.6.0.Micr osoft.Wind ows.Common -Controls. mui_6595b6 4144ccf1df _en_272036 d3\ FILE NOT FOUND Options: Open Directory Access: All
170 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po licy.6.0.M icrosoft.W indows.Com mon-Contro ls.mui\ FILE NOT FOUND Options: Open Directory Access: All
171 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls. mui_6595b6 4144ccf1df _6.0.2600. 2180_en_f7 01061b.Man ifest FILE NOT FOUND Options: Open Access: All
172 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi crosoft.Wi ndows.Comm on-Control s.mui\6.0. 2600.2180_ en_6595b64 144ccf1df\ Microsoft. Windows.Co mmon-Contr ols.mui.DL L PATH NOT FOUND Options: Open Access: All
173 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Sequential Access: All
174 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
175 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS FileInternalInformation
176 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
177 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
178 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Length: 1862
179 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
180 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Offset: 0 Length: 2
181 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
182 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Sequential Access: All
183 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
184 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS FileInternalInformation
185 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
186 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Options: Open Access: All
187 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Length: 1862
188 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
189 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS FileFsVolumeInformation
190 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est BUFFER OVERFLOW FileAllInformation
191 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS Offset: 0 Length: 4095
192 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est END OF FILE Offset: 1862 Length: 8178
193 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest s\x86_Micr osoft.Wind ows.Common -Controls_ 6595b64144 ccf1df_6.0 .2600.2180 _x-ww_a84f 1ff9.Manif est SUCCESS
194 10:38:28 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
195 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
196 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
197 10:38:28 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
198 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
199 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
200 10:38:28 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
201 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
202 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
203 10:38:28 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
204 10:38:28 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
205 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
206 10:38:28 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
207 10:38:28 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
208 10:38:28 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
209 10:38:28 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
210 10:38:28 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
211 10:38:28 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
212 10:38:28 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
213 10:38:28 PM lsass.exe:716 READ C: SUCCESS Offset: 189440 Length: 32768
214 10:38:28 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
215 10:38:28 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
216 10:38:28 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
217 10:38:28 PM iexplore.exe:788 CLOSE C:\ SUCCESS
218 10:38:28 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
219 10:38:28 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
220 10:38:28 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
221 10:38:29 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
222 10:38:29 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
223 10:38:29 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
224 10:38:29 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
225 10:38:29 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
226 10:38:29 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
227 10:38:29 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
228 10:38:29 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
229 10:38:29 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
230 10:38:29 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
231 10:38:29 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
232 10:38:29 PM notepad.exe:1632 CLOSE C:\ SUCCESS
233 10:38:29 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
234 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
235 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
236 10:38:29 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
237 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
238 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
239 10:38:29 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
240 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
241 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
242 10:38:29 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
243 10:38:29 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
244 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
245 10:38:29 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
246 10:38:29 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
247 10:38:29 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
248 10:38:29 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
249 10:38:29 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
250 10:38:29 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
251 10:38:29 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
252 10:38:29 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
253 10:38:29 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
254 10:38:29 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
255 10:38:29 PM msad.exe:304 CLOSE C:\ SUCCESS
256 10:38:29 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
257 10:38:29 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
258 10:38:29 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
259 10:38:29 PM THGuard.exe:392 CLOSE C:\ SUCCESS
260 10:38:29 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
261 10:38:29 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
262 10:38:29 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
263 10:38:29 PM explorer.exe:1484 CLOSE C:\ SUCCESS
264 10:38:29 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
265 10:38:29 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
266 10:38:29 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
267 10:38:29 PM PPControl.exe:312 CLOSE C:\ SUCCESS
268 10:38:29 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
269 10:38:29 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
270 10:38:29 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
271 10:38:30 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
272 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
273 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
274 10:38:30 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
275 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
276 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
277 10:38:30 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
278 10:38:30 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
279 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
280 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
281 10:38:30 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
282 10:38:30 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
283 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
284 10:38:30 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
285 10:38:30 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
286 10:38:30 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
287 10:38:30 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
288 10:38:30 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
289 10:38:30 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
290 10:38:30 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
291 10:38:30 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
292 10:38:30 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
293 10:38:30 PM iexplore.exe:788 CLOSE C:\ SUCCESS
294 10:38:30 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
295 10:38:30 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
296 10:38:30 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
297 10:38:31 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
298 10:38:31 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
299 10:38:31 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
300 10:38:31 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
301 10:38:31 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
302 10:38:31 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
303 10:38:31 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
304 10:38:31 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
305 10:38:31 PM msad.exe:304 CREATE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: OverwriteIf Access: All
306 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
307 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
308 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
309 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati on
310 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
311 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
312 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati on
313 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
314 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
315 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
316 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
317 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
318 10:38:31 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati on: msad.exe
319 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
320 10:38:31 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
321 10:38:31 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET SUCCESS Change Notify
322 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
323 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
324 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
325 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
326 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
327 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
328 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
329 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
330 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
331 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
332 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
333 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
334 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
335 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
336 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
337 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
338 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
339 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
340 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
341 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
342 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
343 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
344 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
345 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
346 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
347 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 4096 Length: 4096
348 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 8192 Length: 552960
349 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192 Length: 65536
350 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 73728 Length: 65536
351 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 139264 Length: 65536
352 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 204800 Length: 57344
353 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
354 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
355 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
356 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
357 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
358 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
359 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
360 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
361 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
362 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
363 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
364 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
365 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
366 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
367 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
368 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
369 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
370 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
371 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
372 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
373 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
374 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
375 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
376 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
377 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
378 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
379 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
380 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
381 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
382 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
383 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
384 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
385 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 561152 Length: 4096
386 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 565248 Length: 651264
387 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 565248 Length: 65536
388 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 630784 Length: 65536
389 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 696320 Length: 65536
390 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 761856 Length: 24576
391 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 786432 Length: 65536
392 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 851968 Length: 65536
393 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 917504 Length: 65536
394 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 983040 Length: 65536
395 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
396 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
397 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
398 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
399 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
400 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
401 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
402 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
403 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
404 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
405 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
406 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
407 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
408 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
409 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
410 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
411 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
412 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
413 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
414 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
415 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
416 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
417 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
418 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
419 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
420 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
421 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
422 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
423 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1216512 Length: 4096
424 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1220608 Length: 675840
425 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1220608 Length: 65536
426 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1286144 Length: 24576
427 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1310720 Length: 65536
428 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1376256 Length: 65536
429 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1441792 Length: 65536
430 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1507328 Length: 65536
431 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
432 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
433 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
434 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
435 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
436 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
437 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
438 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
439 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
440 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
441 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
442 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
443 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
444 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
445 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
446 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
447 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
448 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
449 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
450 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
451 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
452 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
453 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
454 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
455 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
456 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
457 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
458 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
459 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
460 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
461 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
462 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
463 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1896448 Length: 4096
464 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1900544 Length: 651264
465 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1900544 Length: 65536
466 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1966080 Length: 65536
467 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2031616 Length: 65536
468 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2097152 Length: 65536
469 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2162688 Length: 65536
470 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2228224 Length: 65536
471 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2293760 Length: 65536
472 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
473 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
474 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
475 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
476 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
477 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
478 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
479 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
480 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
481 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
482 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
483 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
484 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
485 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
486 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
487 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
488 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
489 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
490 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
491 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
492 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
493 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
494 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
495 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
496 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
497 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
498 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
499 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
500 10:38:31 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
501 10:38:31 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
502 10:38:31 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
503 10:38:31 PM notepad.exe:1632 CLOSE C:\ SUCCESS
504 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 2551808 Length: 4096
505 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 2555904 Length: 675840
506 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2555904 Length: 65536
507 10:38:31 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
508 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
509 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
510 10:38:31 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
511 10:38:31 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
512 10:38:31 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
513 10:38:31 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
514 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
515 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
516 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2621440 Length: 65536
517 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
518 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
519 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
520 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
521 10:38:31 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
522 10:38:31 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
523 10:38:31 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
524 10:38:31 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
525 10:38:31 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
526 10:38:31 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
527 10:38:31 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
528 10:38:31 PM THGuard.exe:392 CLOSE C:\ SUCCESS
529 10:38:31 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
530 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
531 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
532 10:38:31 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
533 10:38:31 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
534 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
535 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2686976 Length: 65536
536 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2752512 Length: 65536
537 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2818048 Length: 65536
538 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2883584 Length: 65536
539 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2949120 Length: 65536
540 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3014656 Length: 65536
541 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3080192 Length: 65536
542 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
543 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
544 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
545 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
546 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
547 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
548 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
549 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
550 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
551 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
552 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
553 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
554 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
555 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
556 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
557 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
558 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
559 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
560 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
561 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
562 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
563 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
564 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
565 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
566 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
567 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
568 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
569 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
570 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
571 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
572 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
573 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
574 10:38:31 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
575 10:38:31 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
576 10:38:31 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
577 10:38:31 PM explorer.exe:1484 CLOSE C:\ SUCCESS
578 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 3231744 Length: 4096
579 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 3235840 Length: 651264
580 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3235840 Length: 65536
581 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3301376 Length: 65536
582 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3366912 Length: 40960
583 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3407872 Length: 65536
584 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3473408 Length: 65536
585 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3538944 Length: 65536
586 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3604480 Length: 65536
587 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
588 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
589 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
590 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
591 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
592 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
593 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
594 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
595 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
596 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
597 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
598 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
599 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
600 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
601 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
602 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
603 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
604 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
605 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
606 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
607 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
608 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
609 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
610 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
611 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
612 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
613 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
614 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
615 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 3887104 Length: 4096
616 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 3891200 Length: 675840
617 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3891200 Length: 40960
618 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3932160 Length: 65536
619 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3997696 Length: 65536
620 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4063232 Length: 65536
621 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4128768 Length: 65536
622 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4194304 Length: 65536
623 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4259840 Length: 65536
624 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4325376 Length: 65536
625 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4390912 Length: 65536
626 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
627 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
628 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
629 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
630 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
631 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
632 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
633 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
634 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
635 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
636 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
637 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
638 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
639 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
640 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
641 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
642 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
643 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
644 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
645 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
646 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
647 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
648 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
649 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
650 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
651 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
652 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
653 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
654 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
655 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
656 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
657 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
658 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 4567040 Length: 4096
659 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 4571136 Length: 651264
660 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4571136 Length: 65536
661 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4636672 Length: 65536
662 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4702208 Length: 16384
663 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4718592 Length: 65536
664 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4784128 Length: 65536
665 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4849664 Length: 65536
666 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4915200 Length: 65536
667 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
668 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
669 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
670 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
671 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
672 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
673 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
674 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
675 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
676 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
677 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
678 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
679 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
680 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
681 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
682 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
683 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
684 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
685 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
686 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
687 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
688 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
689 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
690 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
691 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
692 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
693 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
694 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
695 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 5222400 Length: 4096
696 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 5226496 Length: 675840
697 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5226496 Length: 16384
698 10:38:31 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
699 10:38:31 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
700 10:38:31 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
701 10:38:31 PM PPControl.exe:312 CLOSE C:\ SUCCESS
702 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5242880 Length: 65536
703 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5308416 Length: 65536
704 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5373952 Length: 65536
705 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5439488 Length: 65536
706 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5505024 Length: 65536
707 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5570560 Length: 65536
708 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5636096 Length: 65536
709 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5701632 Length: 65536
710 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
711 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
712 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
713 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
714 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
715 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
716 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
717 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
718 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
719 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
720 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
721 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
722 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
723 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
724 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
725 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
726 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
727 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
728 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
729 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
730 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
731 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
732 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
733 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
734 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
735 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
736 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
737 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
738 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
739 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
740 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
741 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
742 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 5902336 Length: 4096
743 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 5906432 Length: 651264
744 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5906432 Length: 65536
745 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5971968 Length: 57344
746 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6029312 Length: 65536
747 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6094848 Length: 65536
748 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6160384 Length: 65536
749 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6225920 Length: 65536
750 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
751 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
752 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
753 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
754 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
755 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
756 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
757 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
758 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
759 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
760 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
761 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
762 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
763 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
764 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
765 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
766 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
767 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
768 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
769 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
770 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
771 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
772 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
773 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
774 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
775 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
776 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
777 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
778 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 6557696 Length: 4096
779 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 6561792 Length: 675840
780 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6561792 Length: 65536
781 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6627328 Length: 65536
782 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6692864 Length: 65536
783 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6758400 Length: 57344
784 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6815744 Length: 65536
785 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6881280 Length: 65536
786 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6946816 Length: 65536
787 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7012352 Length: 65536
788 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
789 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
790 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
791 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
792 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
793 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
794 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
795 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
796 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
797 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
798 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
799 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
800 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
801 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
802 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
803 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
804 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
805 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
806 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
807 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
808 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
809 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
810 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
811 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
812 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
813 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
814 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
815 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
816 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
817 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
818 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
819 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
820 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7237632 Length: 4096
821 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7241728 Length: 651264
822 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7241728 Length: 65536
823 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7307264 Length: 32768
824 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7340032 Length: 65536
825 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7405568 Length: 65536
826 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7471104 Length: 65536
827 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7536640 Length: 65536
828 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
829 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
830 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
831 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
832 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
833 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
834 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
835 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
836 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
837 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
838 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
839 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
840 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
841 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
842 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
843 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
844 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
845 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
846 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
847 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
848 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
849 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
850 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
851 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
852 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
853 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
854 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
855 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
856 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7892992 Length: 4096
857 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7897088 Length: 675840
858 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7897088 Length: 65536
859 10:38:32 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
860 10:38:32 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
861 10:38:32 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
862 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7962624 Length: 65536
863 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8028160 Length: 65536
864 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8093696 Length: 32768
865 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8126464 Length: 65536
866 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192000 Length: 65536
867 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8257536 Length: 65536
868 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8323072 Length: 65536
869 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
870 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
871 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
872 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
873 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
874 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
875 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
876 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
877 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
878 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
879 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
880 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
881 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
882 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
883 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
884 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
885 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
886 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
887 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
888 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
889 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
890 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
891 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
892 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
893 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
894 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
895 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
896 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
897 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
898 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
899 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
900 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
901 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 8572928 Length: 4096
902 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 8577024 Length: 651264
903 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8577024 Length: 65536
904 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8642560 Length: 8192
905 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8650752 Length: 65536
906 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8716288 Length: 65536
907 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8781824 Length: 65536
908 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8847360 Length: 65536
909 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
910 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
911 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
912 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
913 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
914 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
915 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
916 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
917 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
918 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
919 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
920 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
921 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
922 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
923 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
924 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
925 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
926 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
927 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
928 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
929 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
930 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
931 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
932 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
933 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
934 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
935 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
936 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
937 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 9228288 Length: 4096
938 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 9232384 Length: 675840
939 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9232384 Length: 65536
940 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9297920 Length: 65536
941 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9363456 Length: 65536
942 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9428992 Length: 8192
943 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9437184 Length: 65536
944 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9502720 Length: 65536
945 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9568256 Length: 65536
946 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9633792 Length: 65536
947 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
948 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
949 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
950 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
951 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
952 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
953 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
954 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
955 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
956 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
957 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
958 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
959 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
960 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
961 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
962 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
963 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
964 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
965 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
966 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
967 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
968 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
969 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
970 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
971 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
972 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
973 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
974 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
975 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
976 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
977 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
978 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
979 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 9908224 Length: 4096
980 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 9912320 Length: 651264
981 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9912320 Length: 49152
982 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9961472 Length: 65536
983 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10027008 Length: 65536
984 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10092544 Length: 65536
985 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10158080 Length: 65536
986 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10223616 Length: 65536
987 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10289152 Length: 65536
988 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10354688 Length: 65536
989 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10420224 Length: 65536
990 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
991 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
992 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
993 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
994 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
995 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
996 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
997 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
998 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
999 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1000 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1001 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1002 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1003 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1004 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1005 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1006 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1007 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1008 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1009 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1010 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1011 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1012 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1013 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1014 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1015 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1016 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1017 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1018 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 10563584 Length: 4096
1019 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 10567680 Length: 675840
1020 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10567680 Length: 65536
1021 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10633216 Length: 65536
1022 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10698752 Length: 49152
1023 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10747904 Length: 65536
1024 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10813440 Length: 65536
1025 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10878976 Length: 65536
1026 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10944512 Length: 65536
1027 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1028 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1029 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1030 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1031 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1032 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1033 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1034 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1035 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1036 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1037 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1038 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1039 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1040 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1041 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1042 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1043 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1044 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1045 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1046 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1047 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1048 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1049 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1050 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1051 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1052 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1053 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1054 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1055 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1056 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1057 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1058 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1059 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 11243520 Length: 4096
1060 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 11247616 Length: 651264
1061 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11247616 Length: 24576
1062 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11272192 Length: 65536
1063 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11337728 Length: 65536
1064 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11403264 Length: 65536
1065 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11468800 Length: 65536
1066 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11534336 Length: 65536
1067 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11599872 Length: 65536
1068 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11665408 Length: 65536
1069 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11730944 Length: 65536
1070 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1071 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1072 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1073 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1074 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1075 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1076 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1077 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1078 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1079 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1080 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1081 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1082 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1083 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1084 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1085 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1086 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1087 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1088 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1089 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1090 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1091 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1092 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1093 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1094 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1095 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1096 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1097 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1098 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 11898880 Length: 4096
1099 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 11902976 Length: 454656
1100 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11902976 Length: 65536
1101 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11968512 Length: 65536
1102 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12034048 Length: 24576
1103 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1104 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1105 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1106 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1107 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1108 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1109 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1110 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1111 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1112 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1113 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1114 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1115 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1116 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1117 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1118 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1119 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1120 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1121 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1122 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1123 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1124 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1125 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1126 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1127 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1128 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1129 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1130 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1131 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1132 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1133 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1134 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1135 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 12357632 Length: 4096
1136 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 12361728 Length: 651264
1137 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12361728 Length: 65536
1138 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12427264 Length: 65536
1139 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12492800 Length: 65536
1140 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12558336 Length: 24576
1141 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12582912 Length: 65536
1142 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12648448 Length: 65536
1143 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12713984 Length: 65536
1144 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12779520 Length: 65536
1145 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1146 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1147 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1148 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1149 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1150 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1151 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1152 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1153 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1154 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1155 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1156 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1157 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1158 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1159 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1160 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1161 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1162 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1163 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1164 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1165 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1166 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1167 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1168 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1169 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1170 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1171 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1172 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1173 10:38:32 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1174 10:38:32 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
1175 10:38:32 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1176 10:38:32 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
1177 10:38:32 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1178 10:38:32 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1179 10:38:32 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
1180 10:38:32 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1181 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1182 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1183 10:38:32 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1184 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 13012992 Length: 4096
1185 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 13017088 Length: 675840
1186 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13017088 Length: 65536
1187 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1188 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1189 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13082624 Length: 24576
1190 10:38:32 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
1191 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
1192 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
1193 10:38:32 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1194 10:38:32 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
1195 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1196 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13107200 Length: 65536
1197 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13172736 Length: 65536
1198 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13238272 Length: 65536
1199 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13303808 Length: 65536
1200 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1201 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1202 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1203 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1204 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1205 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1206 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1207 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1208 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1209 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1210 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1211 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1212 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1213 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1214 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1215 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1216 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1217 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1218 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1219 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1220 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1221 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1222 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1223 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1224 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1225 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1226 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1227 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1228 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1229 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1230 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1231 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1232 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 13692928 Length: 4096
1233 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 13697024 Length: 651264
1234 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13697024 Length: 65536
1235 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13762560 Length: 65536
1236 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13828096 Length: 65536
1237 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13893632 Length: 65536
1238 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13959168 Length: 65536
1239 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14024704 Length: 65536
1240 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14090240 Length: 65536
1241 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1242 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1243 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1244 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1245 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1246 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1247 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1248 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1249 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1250 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1251 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1252 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1253 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1254 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1255 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1256 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1257 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1258 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1259 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1260 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1261 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1262 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1263 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1264 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1265 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1266 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1267 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1268 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1269 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 14348288 Length: 4096
1270 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 14352384 Length: 675840
1271 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14352384 Length: 65536
1272 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14417920 Length: 65536
1273 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14483456 Length: 65536
1274 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14548992 Length: 65536
1275 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14614528 Length: 65536
1276 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14680064 Length: 65536
1277 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14745600 Length: 65536
1278 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14811136 Length: 65536
1279 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14876672 Length: 65536
1280 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1281 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1282 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1283 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1284 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1285 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1286 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1287 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1288 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1289 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1290 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1291 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1292 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1293 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1294 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1295 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1296 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1297 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1298 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1299 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1300 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1301 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1302 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1303 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1304 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1305 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1306 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1307 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1308 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1309 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1310 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1311 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1312 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 15028224 Length: 4096
1313 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 15032320 Length: 651264
1314 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15032320 Length: 65536
1315 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15097856 Length: 65536
1316 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15163392 Length: 40960
1317 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15204352 Length: 65536
1318 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15269888 Length: 65536
1319 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15335424 Length: 65536
1320 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15400960 Length: 65536
1321 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1322 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1323 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1324 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1325 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1326 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1327 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1328 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1329 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1330 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1331 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1332 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1333 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1334 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1335 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1336 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1337 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1338 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1339 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1340 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1341 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1342 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1343 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1344 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1345 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1346 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1347 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1348 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1349 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 15683584 Length: 4096
1350 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 15687680 Length: 675840
1351 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15687680 Length: 40960
1352 10:38:32 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
1353 10:38:32 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1354 10:38:32 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1355 10:38:32 PM iexplore.exe:788 CLOSE C:\ SUCCESS
1356 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15728640 Length: 65536
1357 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15794176 Length: 65536
1358 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15859712 Length: 65536
1359 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15925248 Length: 65536
1360 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15990784 Length: 65536
1361 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16056320 Length: 65536
1362 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16121856 Length: 65536
1363 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16187392 Length: 65536
1364 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1365 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1366 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1367 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1368 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1369 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1370 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1371 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1372 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1373 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1374 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1375 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1376 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1377 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1378 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1379 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1380 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1381 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1382 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1383 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1384 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1385 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1386 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1387 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1388 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1389 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1390 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1391 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1392 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1393 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1394 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1395 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1396 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 16363520 Length: 4096
1397 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 16367616 Length: 651264
1398 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16367616 Length: 65536
1399 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16433152 Length: 65536
1400 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16498688 Length: 16384
1401 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16515072 Length: 65536
1402 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16580608 Length: 65536
1403 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16646144 Length: 65536
1404 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16711680 Length: 65536
1405 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1406 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1407 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1408 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1409 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1410 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1411 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1412 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1413 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1414 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1415 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1416 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1417 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1418 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1419 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1420 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1421 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1422 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1423 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1424 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1425 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1426 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1427 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1428 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1429 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1430 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1431 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1432 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1433 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 17018880 Length: 4096
1434 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 17022976 Length: 675840
1435 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17022976 Length: 16384
1436 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17039360 Length: 65536
1437 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17104896 Length: 65536
1438 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17170432 Length: 65536
1439 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17235968 Length: 65536
1440 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17301504 Length: 65536
1441 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17367040 Length: 65536
1442 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17432576 Length: 65536
1443 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17498112 Length: 65536
1444 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1445 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1446 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1447 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1448 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1449 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1450 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1451 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1452 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1453 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1454 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1455 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1456 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1457 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1458 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1459 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1460 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1461 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1462 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1463 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1464 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1465 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1466 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1467 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1468 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1469 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1470 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1471 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1472 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1473 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1474 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1475 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1476 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 17698816 Length: 4096
1477 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 17702912 Length: 651264
1478 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17702912 Length: 65536
1479 10:38:33 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
1480 10:38:33 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1481 10:38:33 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1482 10:38:33 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
1483 10:38:33 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1484 10:38:33 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
1485 10:38:33 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1486 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17768448 Length: 57344
1487 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17825792 Length: 65536
1488 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17891328 Length: 65536
1489 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17956864 Length: 65536
1490 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18022400 Length: 65536
1491 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1492 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1493 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1494 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1495 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1496 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1497 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1498 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1499 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1500 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1501 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1502 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1503 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1504 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1505 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1506 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1507 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1508 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1509 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1510 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1511 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1512 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1513 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1514 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1515 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1516 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1517 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1518 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1519 10:38:33 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
1520 10:38:33 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1521 10:38:33 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1522 10:38:33 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
1523 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 18354176 Length: 4096
1524 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 18358272 Length: 675840
1525 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18358272 Length: 65536
1526 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18423808 Length: 65536
1527 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18489344 Length: 65536
1528 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18554880 Length: 57344
1529 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18612224 Length: 65536
1530 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18677760 Length: 65536
1531 10:38:33 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
1532 10:38:33 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1533 10:38:33 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1534 10:38:33 PM notepad.exe:1632 CLOSE C:\ SUCCESS
1535 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18743296 Length: 65536
1536 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18808832 Length: 65536
1537 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1538 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1539 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1540 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1541 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1542 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1543 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1544 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1545 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1546 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1547 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1548 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1549 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1550 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1551 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1552 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1553 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1554 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1555 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1556 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1557 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1558 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1559 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1560 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1561 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1562 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1563 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1564 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1565 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1566 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1567 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1568 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1569 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 19034112 Length: 4096
1570 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 19038208 Length: 651264
1571 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19038208 Length: 65536
1572 10:38:33 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
1573 10:38:33 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1574 10:38:33 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1575 10:38:33 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
1576 10:38:33 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
1577 10:38:33 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1578 10:38:33 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1579 10:38:33 PM THGuard.exe:392 CLOSE C:\ SUCCESS
1580 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1581 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1582 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1583 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1584 10:38:33 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
1585 10:38:33 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1586 10:38:33 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1587 10:38:33 PM explorer.exe:1484 CLOSE C:\ SUCCESS
1588 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19103744 Length: 32768
1589 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19136512 Length: 65536
1590 10:38:33 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1591 10:38:33 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
1592 10:38:33 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1593 10:38:33 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1594 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1595 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1596 10:38:33 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1597 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1598 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1599 10:38:33 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
1600 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
1601 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
1602 10:38:33 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1603 10:38:33 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
1604 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1605 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19202048 Length: 65536
1606 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19267584 Length: 65536
1607 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19333120 Length: 65536
1608 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1609 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1610 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1611 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1612 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1613 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1614 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1615 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1616 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1617 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1618 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1619 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1620 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1621 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1622 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1623 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1624 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1625 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1626 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1627 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1628 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1629 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1630 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1631 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1632 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1633 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1634 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1635 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1636 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 19689472 Length: 4096
1637 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 19693568 Length: 675840
1638 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19693568 Length: 65536
1639 10:38:33 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
1640 10:38:33 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1641 10:38:33 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1642 10:38:33 PM PPControl.exe:312 CLOSE C:\ SUCCESS
1643 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19759104 Length: 65536
1644 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19824640 Length: 65536
1645 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19890176 Length: 32768
1646 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19922944 Length: 65536
1647 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19988480 Length: 65536
1648 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20054016 Length: 65536
1649 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20119552 Length: 65536
1650 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1651 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1652 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1653 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1654 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1655 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1656 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1657 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1658 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1659 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1660 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1661 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1662 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1663 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1664 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1665 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1666 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1667 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1668 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1669 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1670 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1671 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1672 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1673 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1674 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1675 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1676 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1677 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1678 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1679 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1680 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1681 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1682 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 20369408 Length: 4096
1683 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 20373504 Length: 651264
1684 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20373504 Length: 65536
1685 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20439040 Length: 8192
1686 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20447232 Length: 65536
1687 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20512768 Length: 65536
1688 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20578304 Length: 65536
1689 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20643840 Length: 65536
1690 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1691 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1692 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1693 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1694 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1695 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1696 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1697 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1698 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1699 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1700 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1701 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1702 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1703 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1704 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1705 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1706 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1707 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1708 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1709 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1710 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1711 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1712 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1713 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1714 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1715 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1716 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1717 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1718 10:38:34 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1719 10:38:34 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
1720 10:38:34 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1721 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 21024768 Length: 4096
1722 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 21028864 Length: 675840
1723 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21028864 Length: 65536
1724 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21094400 Length: 65536
1725 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21159936 Length: 65536
1726 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21225472 Length: 8192
1727 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21233664 Length: 65536
1728 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21299200 Length: 65536
1729 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21364736 Length: 65536
1730 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21430272 Length: 65536
1731 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1732 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1733 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1734 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1735 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1736 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1737 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1738 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1739 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1740 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1741 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1742 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1743 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1744 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1745 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1746 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1747 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1748 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1749 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1750 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1751 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1752 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1753 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1754 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1755 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1756 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1757 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1758 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1759 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1760 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1761 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1762 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1763 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 21704704 Length: 4096
1764 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 21708800 Length: 651264
1765 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21708800 Length: 49152
1766 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21757952 Length: 65536
1767 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21823488 Length: 65536
1768 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21889024 Length: 65536
1769 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21954560 Length: 65536
1770 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22020096 Length: 65536
1771 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22085632 Length: 65536
1772 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22151168 Length: 65536
1773 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22216704 Length: 65536
1774 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1775 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1776 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1777 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1778 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1779 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1780 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1781 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1782 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1783 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1784 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1785 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1786 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1787 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1788 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1789 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1790 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1791 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1792 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1793 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1794 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1795 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1796 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1797 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1798 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1799 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1800 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1801 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1802 10:38:34 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
1803 10:38:34 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1804 10:38:34 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1805 10:38:34 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
1806 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 22360064 Length: 4096
1807 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 22364160 Length: 675840
1808 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22364160 Length: 65536
1809 10:38:34 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1810 10:38:34 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati on: ProcessRules.trf
1811 10:38:34 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1812 10:38:34 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1813 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1814 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1815 10:38:34 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi. dll SUCCESS Options: Open Access: All
1816 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi. dll SUCCESS Attributes: A
1817 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi. dll SUCCESS
1818 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22429696 Length: 65536
1819 10:38:34 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Options: Open Access: All
1820 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS Attributes: CA
1821 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki ePatrol.ex e SUCCESS
1822 10:38:34 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1823 10:38:34 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati on: CookiePatrol.exe
1824 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1825 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22495232 Length: 49152
1826 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22544384 Length: 65536
1827 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22609920 Length: 65536
1828 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22675456 Length: 65536
1829 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22740992 Length: 65536
1830 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1831 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1832 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1833 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1834 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1835 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1836 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1837 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1838 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1839 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1840 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1841 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1842 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1843 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1844 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1845 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1846 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1847 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1848 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1849 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1850 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1851 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1852 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1853 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1854 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1855 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1856 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1857 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1858 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1859 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1860 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1861 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1862 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23040000 Length: 4096
1863 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23044096 Length: 651264
1864 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23044096 Length: 24576
1865 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23068672 Length: 65536
1866 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23134208 Length: 65536
1867 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23199744 Length: 65536
1868 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23265280 Length: 65536
1869 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23330816 Length: 65536
1870 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23396352 Length: 65536
1871 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23461888 Length: 65536
1872 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23527424 Length: 65536
1873 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1874 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1875 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1876 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1877 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23695360 Length: 1499
1878 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1879 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1880 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati on
1881 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1882 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1883 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati on
1884 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1885 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1886 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileAlternateNameInformati on
1887 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1888 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1889 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1890 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 256
1891 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 512 Length: 256
1892 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696347 Length: 512
1893 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23695885 Length: 256
1894 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1099 Length: 256
1895 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23688920 Length: 256
1896 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23687859 Length: 256
1897 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23690715 Length: 256
1898 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696048 Length: 256
1899 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696029 Length: 256
1900 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23690270 Length: 256
1901 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7172 Length: 256
1902 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1903 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1904 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 65024 Length: 512
1905 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 2
1906 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1907 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1908 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1909 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
1910 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23692763 Length: 4096
1911 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
1912 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1913 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 64
1914 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1915 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1916 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1917 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1918 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1919 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS Options: Open Access: All
1920 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS FileAttributeTagInformatio n
1921 10:38:34 PM msad.exe:304 DELETE C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS
1922 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS
1923 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
1924 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati on: msad.exe
1925 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
1926 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
1927 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET NOTIFY ENUM DIR Change Notify
1928 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1929 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileAttributeTagInformatio n
1930 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Attributes: A
1931 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS Options: Open Access: All
1932 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini FILE NOT FOUND Options: Open Access: All
1933 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini FILE NOT FOUND Options: Open Access: All
1934 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1935 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati on
1936 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1937 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1938 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati on
1939 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1940 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini FILE NOT FOUND Options: Open Access: All
1941 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini FILE NOT FOUND Options: Open Access: All
1942 10:38:34 PM msad.exe:304 SET INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileRenameInformation
1943 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1944 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileBasicInformation
1945 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1946 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1947 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileInternalInformation
1948 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1949 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1950 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati on
1951 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1952 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1953 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati on
1954 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1955 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1956 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS FileAlternateNameInformati on
1957 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1958 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: Open Access: All
1959 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1960 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 256
1961 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 512 Length: 256
1962 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696347 Length: 512
1963 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23695885 Length: 256
1964 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1099 Length: 256
1965 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23688920 Length: 256
1966 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23687859 Length: 256
1967 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23690715 Length: 256
1968 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696048 Length: 256
1969 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23696029 Length: 256
1970 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23690270 Length: 256
1971 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 7172 Length: 256
1972 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1973 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1974 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 65024 Length: 512
1975 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 2
1976 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1977 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1978 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1979 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
1980 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 23692763 Length: 4096
1981 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
1982 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1983 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 64
1984 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1985 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 512
1986 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1987 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Length: 23696859
1988 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS
1989 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
1990 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
1991 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati on: msad.exe
1992 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
1993 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
1994 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET SUCCESS Change Notify
1995 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS
1996 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS Options: Open Access: All
1997 10:38:34 PM msad.exe:304 SET INFORMATION C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS FileBasicInformation
1998 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d asm.ini SUCCESS
1999 10:38:34 PM msad.exe:304 READ C: SUCCESS Offset: 14077952 Length: 4096
2000 10:38:34 PM msad.exe:304 CREATE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Options: OverwriteIf Access: All
2001 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
2002 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
2003 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
2004 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati on
2005 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
2006 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
2007 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati on
2008 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
2009 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
2010 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d asm.tmp FILE NOT FOUND Options: Open Access: All
2011 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
2012 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
2013 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati on: msad.exe
2014 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
2015 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS Change Notify
2016 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET Change Notify
2017 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 0 Length: 4096
2018 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2019 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2020 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2021 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2022 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2023 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2024 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2025 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2026 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2027 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2028 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2029 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2030 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2031 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2032 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2033 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2034 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2035 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2036 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2037 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2038 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2039 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2040 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2041 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2042 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 4096 Length: 4096
2043 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 8192 Length: 552960
2044 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192 Length: 65536
2045 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 73728 Length: 65536
2046 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 139264 Length: 65536
2047 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 204800 Length: 57344
2048 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2049 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2050 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2051 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2052 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2053 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2054 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2055 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2056 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2057 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2058 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2059 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2060 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2061 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2062 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2063 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2064 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2065 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2066 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2067 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2068 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2069 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2070 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2071 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2072 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2073 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2074 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2075 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2076 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2077 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2078 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2079 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2080 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 561152 Length: 4096
2081 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 565248 Length: 651264
2082 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 565248 Length: 65536
2083 10:38:34 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
2084 10:38:34 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2085 10:38:34 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2086 10:38:34 PM iexplore.exe:788 CLOSE C:\ SUCCESS
2087 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 630784 Length: 65536
2088 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 696320 Length: 65536
2089 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 761856 Length: 24576
2090 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 786432 Length: 65536
2091 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 851968 Length: 65536
2092 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 917504 Length: 65536
2093 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 983040 Length: 65536
2094 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2095 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2096 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2097 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2098 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2099 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2100 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2101 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2102 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2103 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2104 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2105 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2106 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2107 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2108 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2109 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2110 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2111 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2112 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2113 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2114 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2115 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2116 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2117 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2118 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2119 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2120 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2121 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2122 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1216512 Length: 4096
2123 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1220608 Length: 675840
2124 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1220608 Length: 65536
2125 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1286144 Length: 24576
2126 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1310720 Length: 65536
2127 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1376256 Length: 65536
2128 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1441792 Length: 65536
2129 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1507328 Length: 65536
2130 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2131 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2132 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2133 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2134 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2135 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2136 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2137 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2138 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2139 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2140 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2141 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2142 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2143 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2144 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2145 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2146 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2147 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2148 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2149 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2150 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2151 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2152 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2153 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2154 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2155 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2156 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2157 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2158 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2159 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2160 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2161 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2162 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1896448 Length: 4096
2163 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d asm.tmp SUCCESS Offset: 1900544 Length: 651264
2164 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1900544 Length: 65536
2165 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1966080 Length: 65536
2166 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2031616 Length: 65536
2167 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2097152 Length: 65536
2168 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2162688 Length: 65536
2169 10:38:35 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2228224 Length: 65536
2170 10:38:35 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2293760 Length: 65536
2171 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2172 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2173 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2174 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2175 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2176 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2177 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2178 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2179 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2180 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2181 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2182 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2183 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2184 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2185 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2186 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2187 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2188 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2189 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2190 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2191 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2192 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2193 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2194 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2195 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2196 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2197 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2198 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
Ran AdAware SE
Ran S&D
Ran Trojan Hunter
output Trojan Hunter:
Registry scan
Registry key exists: HKEY_CLASSES_ROOT\ATLEvent
Registry key exists: HKEY_CLASSES_ROOT\ATLEvent
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan (autostarted files, running executables)
Found trojan file: C:\WINDOWS\Microsoft.NET\m
Found trojan file: C:\WINDOWS\Microsoft.NET\m
Found trojan file: C:\WINDOWS\system32\bkinst
Found trojan file: C:\WINDOWS\Microsoft.NET\m
2 trojan files found
__________________________
Logfile of HijackThis v1.97.7
Scan saved at 10:24:00 PM, on 11/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\PROGRA~1\NORTON~1\navap
C:\WINDOWS\Microsoft.NET\m
C:\PROGRA~1\PESTPA~1\PPCon
C:\PROGRA~1\PESTPA~1\PPMem
C:\PROGRA~1\PESTPA~1\Cooki
C:\WINDOWS\System32\cisvc.
C:\WINDOWS\System32\CTsvcC
C:\WINDOWS\System32\GEARSE
C:\PROGRA~1\Iomega\System3
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\wdfmgr
C:\WINDOWS\System32\MsPMSP
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\cidaem
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\temp\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {3EC8E271-FAB9-418a-8A8E-6
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMo
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navap
O4 - HKLM\..\Run: [*msad] C:\WINDOWS\Microsoft.NET\m
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPCon
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMem
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\Cooki
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
O4 - HKLM\..\RunOnce: [*msad] C:\WINDOWS\Microsoft.NET\m
O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system32\bkinst
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2
O16 - DPF: {3E68E405-C6DE-49FF-83AE-4
O16 - DPF: {78A730D4-0DF3-4B65-8DD2-B
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
__________________________
8 seconds of filemon.log
1 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
2 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
3 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
4 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
5 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
6 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
7 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
8 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
9 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
10 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
11 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
12 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
13 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
14 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
15 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
16 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
17 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
18 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e
19 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e
20 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
21 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
22 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
23 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
24 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
25 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
26 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
27 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
28 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
29 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
30 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
31 10:38:27 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
32 10:38:27 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
33 10:38:27 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
34 10:38:27 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
35 10:38:27 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
36 10:38:27 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
37 10:38:27 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
38 10:38:27 PM msad.exe:304 CLOSE C:\ SUCCESS
39 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
40 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
41 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
42 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
43 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
44 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
45 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e
46 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e
47 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
48 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
49 10:38:27 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
50 10:38:27 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
51 10:38:27 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
52 10:38:27 PM THGuard.exe:392 CLOSE C:\ SUCCESS
53 10:38:27 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
54 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
55 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
56 10:38:27 PM explorer.exe:1484 CLOSE C:\ SUCCESS
57 10:38:27 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
58 10:38:27 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
59 10:38:27 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
60 10:38:27 PM PPControl.exe:312 CLOSE C:\ SUCCESS
61 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
62 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
63 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
64 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
65 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
66 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
67 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
68 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
69 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
70 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
71 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
72 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
73 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
74 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
75 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
76 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e
77 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e
78 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
79 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
80 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
81 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
82 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
83 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
84 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
85 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
86 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
87 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
88 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
89 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
90 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
91 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
92 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
93 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
94 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
95 10:38:27 PM explorer.exe:1484 SET INFORMATION C:\temp\NTFILMON\Filemon.e
96 10:38:27 PM explorer.exe:1484 READ C:\temp\NTFILMON\Filemon.e
97 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
98 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
99 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
100 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18178048 Length: 4096
101 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18489344 Length: 4096
102 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18485248 Length: 4096
103 10:38:27 PM explorer.exe:1484 READ C: SUCCESS Offset: 18481152 Length: 4096
104 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
105 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
106 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
107 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
108 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
109 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
110 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
111 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
112 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
113 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
114 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
115 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
116 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
117 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
118 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
119 10:38:27 PM explorer.exe:1484 OPEN C:\temp\NTFILMON\Filemon.e
120 10:38:27 PM explorer.exe:1484 QUERY INFORMATION C:\temp\NTFILMON\Filemon.e
121 10:38:27 PM explorer.exe:1484 CLOSE C:\temp\NTFILMON\Filemon.e
122 10:38:27 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
123 10:38:27 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
124 10:38:27 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
125 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
126 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po
127 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\en-US FILE NOT FOUND Options: Open Access: All
128 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\en FILE NOT FOUND Options: Open Access: All
129 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\ SUCCESS Options: Open Access: All
130 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\System32\ SUCCESS Attributes: D
131 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\System32\ SUCCESS
132 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\System32\ SUCCESS Options: Open Access: All
133 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\System32\ SUCCESS Attributes: D
134 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\System32\ SUCCESS
135 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
136 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi
137 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
138 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po
139 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
140 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi
141 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
142 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies
143 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies
144 10:38:28 PM csrss.exe:636 DIRECTORY C:\WINDOWS\WinSxS\Policies
145 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies
146 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
147 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
148 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies
149 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies
150 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
151 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies
152 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies
153 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies
154 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Policies
155 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Policies
156 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Policies
157 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Policies
158 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po
159 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
160 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
161 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
162 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
163 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
164 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
165 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
166 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po
167 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
168 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi
169 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Policies
170 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\Assembly\GAC\Po
171 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
172 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\assembly\GAC\Mi
173 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
174 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
175 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
176 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
177 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
178 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
179 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
180 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest
181 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
182 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
183 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
184 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
185 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
186 10:38:28 PM csrss.exe:636 OPEN C:\WINDOWS\WinSxS\Manifest
187 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
188 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
189 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
190 10:38:28 PM csrss.exe:636 QUERY INFORMATION C:\WINDOWS\WinSxS\Manifest
191 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest
192 10:38:28 PM csrss.exe:636 READ C:\WINDOWS\WinSxS\Manifest
193 10:38:28 PM csrss.exe:636 CLOSE C:\WINDOWS\WinSxS\Manifest
194 10:38:28 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
195 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
196 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
197 10:38:28 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
198 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
199 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
200 10:38:28 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
201 10:38:28 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
202 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
203 10:38:28 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
204 10:38:28 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
205 10:38:28 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
206 10:38:28 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
207 10:38:28 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
208 10:38:28 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
209 10:38:28 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
210 10:38:28 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
211 10:38:28 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
212 10:38:28 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
213 10:38:28 PM lsass.exe:716 READ C: SUCCESS Offset: 189440 Length: 32768
214 10:38:28 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
215 10:38:28 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
216 10:38:28 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
217 10:38:28 PM iexplore.exe:788 CLOSE C:\ SUCCESS
218 10:38:28 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
219 10:38:28 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
220 10:38:28 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
221 10:38:29 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
222 10:38:29 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
223 10:38:29 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
224 10:38:29 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
225 10:38:29 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
226 10:38:29 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
227 10:38:29 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
228 10:38:29 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
229 10:38:29 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
230 10:38:29 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
231 10:38:29 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
232 10:38:29 PM notepad.exe:1632 CLOSE C:\ SUCCESS
233 10:38:29 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
234 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
235 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
236 10:38:29 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
237 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
238 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
239 10:38:29 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
240 10:38:29 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
241 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
242 10:38:29 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
243 10:38:29 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
244 10:38:29 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
245 10:38:29 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
246 10:38:29 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
247 10:38:29 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
248 10:38:29 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
249 10:38:29 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
250 10:38:29 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
251 10:38:29 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
252 10:38:29 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
253 10:38:29 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
254 10:38:29 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
255 10:38:29 PM msad.exe:304 CLOSE C:\ SUCCESS
256 10:38:29 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
257 10:38:29 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
258 10:38:29 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
259 10:38:29 PM THGuard.exe:392 CLOSE C:\ SUCCESS
260 10:38:29 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
261 10:38:29 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
262 10:38:29 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
263 10:38:29 PM explorer.exe:1484 CLOSE C:\ SUCCESS
264 10:38:29 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
265 10:38:29 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
266 10:38:29 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
267 10:38:29 PM PPControl.exe:312 CLOSE C:\ SUCCESS
268 10:38:29 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
269 10:38:29 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
270 10:38:29 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
271 10:38:30 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
272 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
273 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
274 10:38:30 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
275 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
276 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
277 10:38:30 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
278 10:38:30 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
279 10:38:30 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
280 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
281 10:38:30 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
282 10:38:30 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
283 10:38:30 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
284 10:38:30 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
285 10:38:30 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
286 10:38:30 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
287 10:38:30 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
288 10:38:30 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
289 10:38:30 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
290 10:38:30 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
291 10:38:30 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
292 10:38:30 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
293 10:38:30 PM iexplore.exe:788 CLOSE C:\ SUCCESS
294 10:38:30 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
295 10:38:30 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
296 10:38:30 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
297 10:38:31 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
298 10:38:31 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
299 10:38:31 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
300 10:38:31 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
301 10:38:31 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
302 10:38:31 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
303 10:38:31 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
304 10:38:31 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
305 10:38:31 PM msad.exe:304 CREATE C:\WINDOWS\Microsoft.NET\d
306 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
307 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
308 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
309 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati
310 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
311 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
312 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati
313 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
314 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
315 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
316 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
317 10:38:31 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
318 10:38:31 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati
319 10:38:31 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
320 10:38:31 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
321 10:38:31 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET SUCCESS Change Notify
322 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
323 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
324 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
325 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
326 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
327 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
328 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
329 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
330 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
331 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
332 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
333 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
334 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
335 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
336 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
337 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
338 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
339 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
340 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
341 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
342 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
343 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
344 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
345 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
346 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
347 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
348 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
349 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192 Length: 65536
350 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 73728 Length: 65536
351 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 139264 Length: 65536
352 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 204800 Length: 57344
353 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
354 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
355 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
356 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
357 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
358 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
359 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
360 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
361 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
362 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
363 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
364 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
365 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
366 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
367 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
368 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
369 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
370 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
371 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
372 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
373 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
374 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
375 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
376 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
377 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
378 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
379 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
380 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
381 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
382 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
383 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
384 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
385 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
386 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
387 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 565248 Length: 65536
388 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 630784 Length: 65536
389 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 696320 Length: 65536
390 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 761856 Length: 24576
391 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 786432 Length: 65536
392 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 851968 Length: 65536
393 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 917504 Length: 65536
394 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 983040 Length: 65536
395 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
396 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
397 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
398 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
399 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
400 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
401 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
402 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
403 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
404 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
405 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
406 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
407 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
408 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
409 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
410 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
411 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
412 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
413 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
414 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
415 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
416 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
417 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
418 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
419 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
420 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
421 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
422 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
423 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
424 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
425 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1220608 Length: 65536
426 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1286144 Length: 24576
427 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1310720 Length: 65536
428 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1376256 Length: 65536
429 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1441792 Length: 65536
430 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1507328 Length: 65536
431 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
432 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
433 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
434 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
435 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
436 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
437 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
438 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
439 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
440 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
441 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
442 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
443 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
444 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
445 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
446 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
447 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
448 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
449 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
450 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
451 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
452 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
453 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
454 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
455 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
456 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
457 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
458 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
459 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
460 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
461 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
462 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
463 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
464 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
465 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1900544 Length: 65536
466 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1966080 Length: 65536
467 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2031616 Length: 65536
468 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2097152 Length: 65536
469 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2162688 Length: 65536
470 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2228224 Length: 65536
471 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2293760 Length: 65536
472 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
473 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
474 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
475 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
476 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
477 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
478 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
479 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
480 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
481 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
482 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
483 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
484 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
485 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
486 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
487 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
488 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
489 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
490 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
491 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
492 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
493 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
494 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
495 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
496 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
497 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
498 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
499 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
500 10:38:31 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
501 10:38:31 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
502 10:38:31 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
503 10:38:31 PM notepad.exe:1632 CLOSE C:\ SUCCESS
504 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
505 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
506 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2555904 Length: 65536
507 10:38:31 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
508 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
509 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
510 10:38:31 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
511 10:38:31 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
512 10:38:31 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
513 10:38:31 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
514 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
515 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
516 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2621440 Length: 65536
517 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
518 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
519 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
520 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
521 10:38:31 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
522 10:38:31 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
523 10:38:31 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
524 10:38:31 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
525 10:38:31 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
526 10:38:31 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
527 10:38:31 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
528 10:38:31 PM THGuard.exe:392 CLOSE C:\ SUCCESS
529 10:38:31 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
530 10:38:31 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
531 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
532 10:38:31 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
533 10:38:31 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
534 10:38:31 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
535 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2686976 Length: 65536
536 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2752512 Length: 65536
537 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2818048 Length: 65536
538 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2883584 Length: 65536
539 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2949120 Length: 65536
540 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3014656 Length: 65536
541 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3080192 Length: 65536
542 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
543 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
544 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
545 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
546 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
547 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
548 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
549 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
550 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
551 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
552 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
553 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
554 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
555 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
556 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
557 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
558 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
559 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
560 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
561 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
562 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
563 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
564 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
565 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
566 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
567 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
568 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
569 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
570 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
571 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
572 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
573 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
574 10:38:31 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
575 10:38:31 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
576 10:38:31 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
577 10:38:31 PM explorer.exe:1484 CLOSE C:\ SUCCESS
578 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
579 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
580 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3235840 Length: 65536
581 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3301376 Length: 65536
582 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3366912 Length: 40960
583 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3407872 Length: 65536
584 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3473408 Length: 65536
585 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3538944 Length: 65536
586 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3604480 Length: 65536
587 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
588 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
589 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
590 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
591 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
592 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
593 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
594 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
595 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
596 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
597 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
598 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
599 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
600 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
601 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
602 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
603 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
604 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
605 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
606 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
607 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
608 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
609 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
610 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
611 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
612 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
613 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
614 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
615 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
616 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
617 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3891200 Length: 40960
618 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3932160 Length: 65536
619 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 3997696 Length: 65536
620 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4063232 Length: 65536
621 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4128768 Length: 65536
622 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4194304 Length: 65536
623 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4259840 Length: 65536
624 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4325376 Length: 65536
625 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4390912 Length: 65536
626 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
627 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
628 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
629 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
630 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
631 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
632 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
633 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
634 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
635 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
636 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
637 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
638 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
639 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
640 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
641 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
642 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
643 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
644 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
645 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
646 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
647 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
648 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
649 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
650 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
651 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
652 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
653 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
654 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
655 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
656 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
657 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
658 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
659 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
660 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4571136 Length: 65536
661 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4636672 Length: 65536
662 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4702208 Length: 16384
663 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4718592 Length: 65536
664 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4784128 Length: 65536
665 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4849664 Length: 65536
666 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 4915200 Length: 65536
667 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
668 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
669 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
670 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
671 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
672 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
673 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
674 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
675 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
676 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
677 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
678 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
679 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
680 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
681 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
682 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
683 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
684 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
685 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
686 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
687 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
688 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
689 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
690 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
691 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
692 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
693 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
694 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
695 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
696 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
697 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5226496 Length: 16384
698 10:38:31 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
699 10:38:31 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
700 10:38:31 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
701 10:38:31 PM PPControl.exe:312 CLOSE C:\ SUCCESS
702 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5242880 Length: 65536
703 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5308416 Length: 65536
704 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5373952 Length: 65536
705 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5439488 Length: 65536
706 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5505024 Length: 65536
707 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5570560 Length: 65536
708 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5636096 Length: 65536
709 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5701632 Length: 65536
710 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
711 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
712 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
713 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
714 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
715 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
716 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
717 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
718 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
719 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
720 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
721 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
722 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
723 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
724 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
725 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
726 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
727 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
728 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
729 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
730 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
731 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
732 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
733 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
734 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
735 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
736 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
737 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
738 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
739 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
740 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
741 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
742 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
743 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
744 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5906432 Length: 65536
745 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 5971968 Length: 57344
746 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6029312 Length: 65536
747 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6094848 Length: 65536
748 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6160384 Length: 65536
749 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6225920 Length: 65536
750 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
751 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
752 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
753 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
754 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
755 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
756 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
757 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
758 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
759 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
760 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
761 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
762 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
763 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
764 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
765 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
766 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
767 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
768 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
769 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
770 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
771 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
772 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
773 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
774 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
775 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
776 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
777 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
778 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
779 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
780 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6561792 Length: 65536
781 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6627328 Length: 65536
782 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6692864 Length: 65536
783 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6758400 Length: 57344
784 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6815744 Length: 65536
785 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6881280 Length: 65536
786 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 6946816 Length: 65536
787 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7012352 Length: 65536
788 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
789 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
790 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
791 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
792 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
793 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
794 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
795 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
796 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
797 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
798 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
799 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
800 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
801 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
802 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
803 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
804 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
805 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
806 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
807 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
808 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
809 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
810 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
811 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
812 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
813 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
814 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
815 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
816 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
817 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
818 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
819 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
820 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
821 10:38:31 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
822 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7241728 Length: 65536
823 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7307264 Length: 32768
824 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7340032 Length: 65536
825 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7405568 Length: 65536
826 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7471104 Length: 65536
827 10:38:31 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7536640 Length: 65536
828 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
829 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
830 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
831 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
832 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
833 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
834 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
835 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
836 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
837 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
838 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
839 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
840 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
841 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
842 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
843 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
844 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
845 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
846 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
847 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
848 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
849 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
850 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
851 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
852 10:38:31 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
853 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
854 10:38:31 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
855 10:38:31 PM msad.exe:304 CLOSE C:\ SUCCESS
856 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
857 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
858 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7897088 Length: 65536
859 10:38:32 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
860 10:38:32 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
861 10:38:32 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
862 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 7962624 Length: 65536
863 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8028160 Length: 65536
864 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8093696 Length: 32768
865 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8126464 Length: 65536
866 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192000 Length: 65536
867 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8257536 Length: 65536
868 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8323072 Length: 65536
869 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
870 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
871 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
872 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
873 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
874 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
875 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
876 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
877 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
878 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
879 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
880 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
881 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
882 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
883 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
884 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
885 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
886 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
887 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
888 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
889 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
890 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
891 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
892 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
893 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
894 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
895 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
896 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
897 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
898 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
899 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
900 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
901 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
902 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
903 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8577024 Length: 65536
904 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8642560 Length: 8192
905 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8650752 Length: 65536
906 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8716288 Length: 65536
907 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8781824 Length: 65536
908 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8847360 Length: 65536
909 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
910 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
911 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
912 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
913 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
914 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
915 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
916 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
917 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
918 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
919 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
920 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
921 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
922 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
923 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
924 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
925 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
926 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
927 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
928 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
929 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
930 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
931 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
932 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
933 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
934 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
935 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
936 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
937 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
938 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
939 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9232384 Length: 65536
940 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9297920 Length: 65536
941 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9363456 Length: 65536
942 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9428992 Length: 8192
943 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9437184 Length: 65536
944 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9502720 Length: 65536
945 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9568256 Length: 65536
946 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9633792 Length: 65536
947 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
948 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
949 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
950 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
951 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
952 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
953 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
954 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
955 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
956 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
957 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
958 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
959 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
960 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
961 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
962 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
963 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
964 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
965 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
966 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
967 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
968 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
969 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
970 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
971 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
972 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
973 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
974 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
975 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
976 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
977 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
978 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
979 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
980 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
981 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9912320 Length: 49152
982 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 9961472 Length: 65536
983 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10027008 Length: 65536
984 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10092544 Length: 65536
985 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10158080 Length: 65536
986 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10223616 Length: 65536
987 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10289152 Length: 65536
988 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10354688 Length: 65536
989 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10420224 Length: 65536
990 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
991 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
992 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
993 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
994 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
995 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
996 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
997 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
998 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
999 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1000 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1001 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1002 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1003 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1004 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1005 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1006 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1007 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1008 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1009 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1010 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1011 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1012 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1013 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1014 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1015 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1016 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1017 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1018 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1019 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1020 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10567680 Length: 65536
1021 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10633216 Length: 65536
1022 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10698752 Length: 49152
1023 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10747904 Length: 65536
1024 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10813440 Length: 65536
1025 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10878976 Length: 65536
1026 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 10944512 Length: 65536
1027 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1028 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1029 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1030 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1031 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1032 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1033 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1034 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1035 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1036 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1037 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1038 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1039 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1040 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1041 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1042 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1043 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1044 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1045 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1046 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1047 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1048 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1049 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1050 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1051 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1052 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1053 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1054 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1055 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1056 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1057 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1058 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1059 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1060 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1061 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11247616 Length: 24576
1062 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11272192 Length: 65536
1063 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11337728 Length: 65536
1064 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11403264 Length: 65536
1065 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11468800 Length: 65536
1066 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11534336 Length: 65536
1067 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11599872 Length: 65536
1068 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11665408 Length: 65536
1069 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11730944 Length: 65536
1070 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1071 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1072 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1073 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1074 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1075 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1076 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1077 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1078 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1079 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1080 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1081 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1082 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1083 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1084 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1085 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1086 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1087 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1088 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1089 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1090 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1091 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1092 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1093 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1094 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1095 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1096 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1097 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1098 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1099 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1100 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11902976 Length: 65536
1101 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 11968512 Length: 65536
1102 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12034048 Length: 24576
1103 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1104 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1105 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1106 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1107 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1108 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1109 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1110 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1111 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1112 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1113 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1114 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1115 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1116 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1117 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1118 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1119 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1120 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1121 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1122 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1123 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1124 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1125 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1126 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1127 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1128 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1129 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1130 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1131 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1132 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1133 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1134 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1135 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1136 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1137 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12361728 Length: 65536
1138 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12427264 Length: 65536
1139 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12492800 Length: 65536
1140 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12558336 Length: 24576
1141 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12582912 Length: 65536
1142 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12648448 Length: 65536
1143 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12713984 Length: 65536
1144 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 12779520 Length: 65536
1145 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1146 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1147 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1148 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1149 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1150 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1151 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1152 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1153 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1154 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1155 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1156 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1157 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1158 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1159 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1160 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1161 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1162 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1163 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1164 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1165 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1166 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1167 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1168 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1169 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1170 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1171 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1172 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1173 10:38:32 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1174 10:38:32 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
1175 10:38:32 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1176 10:38:32 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
1177 10:38:32 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1178 10:38:32 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1179 10:38:32 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
1180 10:38:32 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1181 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1182 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1183 10:38:32 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1184 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1185 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1186 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13017088 Length: 65536
1187 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1188 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1189 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13082624 Length: 24576
1190 10:38:32 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
1191 10:38:32 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
1192 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
1193 10:38:32 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1194 10:38:32 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
1195 10:38:32 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1196 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13107200 Length: 65536
1197 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13172736 Length: 65536
1198 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13238272 Length: 65536
1199 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13303808 Length: 65536
1200 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1201 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1202 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1203 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1204 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1205 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1206 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1207 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1208 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1209 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1210 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1211 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1212 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1213 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1214 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1215 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1216 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1217 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1218 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1219 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1220 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1221 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1222 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1223 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1224 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1225 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1226 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1227 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1228 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1229 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1230 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1231 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1232 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1233 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1234 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13697024 Length: 65536
1235 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13762560 Length: 65536
1236 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13828096 Length: 65536
1237 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13893632 Length: 65536
1238 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 13959168 Length: 65536
1239 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14024704 Length: 65536
1240 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14090240 Length: 65536
1241 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1242 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1243 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1244 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1245 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1246 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1247 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1248 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1249 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1250 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1251 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1252 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1253 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1254 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1255 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1256 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1257 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1258 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1259 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1260 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1261 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1262 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1263 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1264 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1265 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1266 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1267 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1268 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1269 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1270 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1271 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14352384 Length: 65536
1272 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14417920 Length: 65536
1273 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14483456 Length: 65536
1274 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14548992 Length: 65536
1275 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14614528 Length: 65536
1276 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14680064 Length: 65536
1277 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14745600 Length: 65536
1278 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14811136 Length: 65536
1279 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 14876672 Length: 65536
1280 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1281 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1282 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1283 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1284 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1285 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1286 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1287 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1288 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1289 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1290 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1291 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1292 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1293 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1294 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1295 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1296 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1297 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1298 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1299 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1300 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1301 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1302 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1303 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1304 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1305 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1306 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1307 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1308 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1309 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1310 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1311 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1312 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1313 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1314 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15032320 Length: 65536
1315 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15097856 Length: 65536
1316 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15163392 Length: 40960
1317 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15204352 Length: 65536
1318 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15269888 Length: 65536
1319 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15335424 Length: 65536
1320 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15400960 Length: 65536
1321 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1322 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1323 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1324 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1325 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1326 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1327 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1328 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1329 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1330 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1331 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1332 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1333 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1334 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1335 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1336 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1337 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1338 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1339 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1340 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1341 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1342 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1343 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1344 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1345 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1346 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1347 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1348 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1349 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1350 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1351 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15687680 Length: 40960
1352 10:38:32 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
1353 10:38:32 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1354 10:38:32 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1355 10:38:32 PM iexplore.exe:788 CLOSE C:\ SUCCESS
1356 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15728640 Length: 65536
1357 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15794176 Length: 65536
1358 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15859712 Length: 65536
1359 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15925248 Length: 65536
1360 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 15990784 Length: 65536
1361 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16056320 Length: 65536
1362 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16121856 Length: 65536
1363 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16187392 Length: 65536
1364 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1365 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1366 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1367 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1368 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1369 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1370 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1371 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1372 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1373 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1374 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1375 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1376 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1377 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1378 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1379 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1380 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1381 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1382 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1383 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1384 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1385 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1386 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1387 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1388 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1389 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1390 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1391 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1392 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1393 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1394 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1395 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1396 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1397 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1398 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16367616 Length: 65536
1399 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16433152 Length: 65536
1400 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16498688 Length: 16384
1401 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16515072 Length: 65536
1402 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16580608 Length: 65536
1403 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16646144 Length: 65536
1404 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 16711680 Length: 65536
1405 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1406 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1407 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1408 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1409 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1410 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1411 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1412 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1413 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1414 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1415 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1416 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1417 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1418 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1419 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1420 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1421 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1422 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1423 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1424 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1425 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1426 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1427 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1428 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1429 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1430 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1431 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1432 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1433 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1434 10:38:32 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1435 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17022976 Length: 16384
1436 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17039360 Length: 65536
1437 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17104896 Length: 65536
1438 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17170432 Length: 65536
1439 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17235968 Length: 65536
1440 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17301504 Length: 65536
1441 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17367040 Length: 65536
1442 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17432576 Length: 65536
1443 10:38:32 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17498112 Length: 65536
1444 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1445 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1446 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1447 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1448 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1449 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1450 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1451 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1452 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1453 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1454 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1455 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1456 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1457 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1458 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1459 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1460 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1461 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1462 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1463 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1464 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1465 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1466 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1467 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1468 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1469 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1470 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1471 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1472 10:38:32 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1473 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1474 10:38:32 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1475 10:38:32 PM msad.exe:304 CLOSE C:\ SUCCESS
1476 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1477 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1478 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17702912 Length: 65536
1479 10:38:33 PM HijackThis.exe:448 OPEN C:\ SUCCESS Options: Open Directory Access: All
1480 10:38:33 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1481 10:38:33 PM HijackThis.exe:448 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1482 10:38:33 PM HijackThis.exe:448 CLOSE C:\ SUCCESS
1483 10:38:33 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1484 10:38:33 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
1485 10:38:33 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1486 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17768448 Length: 57344
1487 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17825792 Length: 65536
1488 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17891328 Length: 65536
1489 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 17956864 Length: 65536
1490 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18022400 Length: 65536
1491 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1492 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1493 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1494 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1495 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1496 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1497 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1498 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1499 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1500 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1501 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1502 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1503 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1504 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1505 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1506 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1507 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1508 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1509 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1510 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1511 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1512 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1513 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1514 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1515 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1516 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1517 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1518 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1519 10:38:33 PM iexplore.exe:1180 OPEN C:\ SUCCESS Options: Open Directory Access: All
1520 10:38:33 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1521 10:38:33 PM iexplore.exe:1180 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1522 10:38:33 PM iexplore.exe:1180 CLOSE C:\ SUCCESS
1523 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1524 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1525 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18358272 Length: 65536
1526 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18423808 Length: 65536
1527 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18489344 Length: 65536
1528 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18554880 Length: 57344
1529 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18612224 Length: 65536
1530 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18677760 Length: 65536
1531 10:38:33 PM notepad.exe:1632 OPEN C:\ SUCCESS Options: Open Directory Access: All
1532 10:38:33 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1533 10:38:33 PM notepad.exe:1632 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1534 10:38:33 PM notepad.exe:1632 CLOSE C:\ SUCCESS
1535 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18743296 Length: 65536
1536 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 18808832 Length: 65536
1537 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1538 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1539 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1540 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1541 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1542 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1543 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1544 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1545 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1546 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1547 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1548 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1549 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1550 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1551 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1552 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1553 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1554 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1555 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1556 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1557 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1558 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1559 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1560 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1561 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1562 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1563 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1564 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1565 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1566 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1567 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1568 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1569 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1570 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1571 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19038208 Length: 65536
1572 10:38:33 PM Navapw32.exe:288 OPEN C:\ SUCCESS Options: Open Directory Access: All
1573 10:38:33 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1574 10:38:33 PM Navapw32.exe:288 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1575 10:38:33 PM Navapw32.exe:288 CLOSE C:\ SUCCESS
1576 10:38:33 PM THGuard.exe:392 OPEN C:\ SUCCESS Options: Open Directory Access: All
1577 10:38:33 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1578 10:38:33 PM THGuard.exe:392 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1579 10:38:33 PM THGuard.exe:392 CLOSE C:\ SUCCESS
1580 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1581 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1582 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1583 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1584 10:38:33 PM explorer.exe:1484 OPEN C:\ SUCCESS Options: Open Directory Access: All
1585 10:38:33 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1586 10:38:33 PM explorer.exe:1484 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1587 10:38:33 PM explorer.exe:1484 CLOSE C:\ SUCCESS
1588 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19103744 Length: 32768
1589 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19136512 Length: 65536
1590 10:38:33 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1591 10:38:33 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
1592 10:38:33 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1593 10:38:33 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1594 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1595 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1596 10:38:33 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1597 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1598 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1599 10:38:33 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
1600 10:38:33 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
1601 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
1602 10:38:33 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1603 10:38:33 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
1604 10:38:33 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1605 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19202048 Length: 65536
1606 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19267584 Length: 65536
1607 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19333120 Length: 65536
1608 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1609 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1610 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1611 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1612 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1613 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1614 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1615 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1616 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1617 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1618 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1619 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1620 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1621 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1622 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1623 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1624 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1625 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1626 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1627 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1628 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1629 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1630 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1631 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1632 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1633 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1634 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1635 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1636 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1637 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1638 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19693568 Length: 65536
1639 10:38:33 PM PPControl.exe:312 OPEN C:\ SUCCESS Options: Open Directory Access: All
1640 10:38:33 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1641 10:38:33 PM PPControl.exe:312 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1642 10:38:33 PM PPControl.exe:312 CLOSE C:\ SUCCESS
1643 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19759104 Length: 65536
1644 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19824640 Length: 65536
1645 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19890176 Length: 32768
1646 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19922944 Length: 65536
1647 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 19988480 Length: 65536
1648 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20054016 Length: 65536
1649 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20119552 Length: 65536
1650 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1651 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1652 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1653 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1654 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1655 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1656 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1657 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1658 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1659 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1660 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1661 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1662 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1663 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1664 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1665 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1666 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1667 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1668 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1669 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1670 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1671 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1672 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1673 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1674 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1675 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1676 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1677 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1678 10:38:33 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1679 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1680 10:38:33 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1681 10:38:33 PM msad.exe:304 CLOSE C:\ SUCCESS
1682 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1683 10:38:33 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1684 10:38:33 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20373504 Length: 65536
1685 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20439040 Length: 8192
1686 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20447232 Length: 65536
1687 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20512768 Length: 65536
1688 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20578304 Length: 65536
1689 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 20643840 Length: 65536
1690 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1691 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1692 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1693 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1694 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1695 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1696 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1697 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1698 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1699 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1700 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1701 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1702 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1703 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1704 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1705 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1706 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1707 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1708 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1709 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1710 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1711 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1712 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1713 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1714 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1715 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1716 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1717 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1718 10:38:34 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1719 10:38:34 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
1720 10:38:34 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1721 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1722 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1723 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21028864 Length: 65536
1724 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21094400 Length: 65536
1725 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21159936 Length: 65536
1726 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21225472 Length: 8192
1727 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21233664 Length: 65536
1728 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21299200 Length: 65536
1729 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21364736 Length: 65536
1730 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21430272 Length: 65536
1731 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1732 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1733 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1734 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1735 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1736 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1737 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1738 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1739 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1740 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1741 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1742 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1743 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1744 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1745 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1746 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1747 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1748 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1749 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1750 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1751 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1752 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1753 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1754 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1755 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1756 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1757 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1758 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1759 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1760 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1761 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1762 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1763 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1764 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1765 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21708800 Length: 49152
1766 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21757952 Length: 65536
1767 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21823488 Length: 65536
1768 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21889024 Length: 65536
1769 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 21954560 Length: 65536
1770 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22020096 Length: 65536
1771 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22085632 Length: 65536
1772 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22151168 Length: 65536
1773 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22216704 Length: 65536
1774 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1775 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1776 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1777 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1778 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1779 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1780 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1781 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1782 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1783 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1784 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1785 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1786 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1787 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1788 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1789 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1790 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1791 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1792 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1793 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1794 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1795 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1796 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1797 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1798 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1799 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1800 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1801 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1802 10:38:34 PM TrojanHunter.ex:2760 OPEN C:\ SUCCESS Options: Open Directory Access: All
1803 10:38:34 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1804 10:38:34 PM TrojanHunter.ex:2760 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1805 10:38:34 PM TrojanHunter.ex:2760 CLOSE C:\ SUCCESS
1806 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1807 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1808 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22364160 Length: 65536
1809 10:38:34 PM THGuard.exe:392 OPEN C:\Program Files\TrojanHunter 4.0\ SUCCESS Options: Open Directory Access: All
1810 10:38:34 PM THGuard.exe:392 DIRECTORY C:\Program Files\TrojanHunter 4.0\ SUCCESS FileBothDirectoryInformati
1811 10:38:34 PM THGuard.exe:392 CLOSE C:\Program Files\TrojanHunter 4.0\ SUCCESS
1812 10:38:34 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1813 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1814 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1815 10:38:34 PM PPMemCheck.exe:320 OPEN C:\WINDOWS\system32\psapi.
1816 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\WINDOWS\system32\psapi.
1817 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\WINDOWS\system32\psapi.
1818 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22429696 Length: 65536
1819 10:38:34 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\Cooki
1820 10:38:34 PM PPMemCheck.exe:320 QUERY INFORMATION C:\PROGRA~1\PESTPA~1\Cooki
1821 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\Cooki
1822 10:38:34 PM PPMemCheck.exe:320 OPEN C:\PROGRA~1\PESTPA~1\ SUCCESS Options: Open Directory Access: All
1823 10:38:34 PM PPMemCheck.exe:320 DIRECTORY C:\PROGRA~1\PESTPA~1\ SUCCESS FileBothDirectoryInformati
1824 10:38:34 PM PPMemCheck.exe:320 CLOSE C:\PROGRA~1\PESTPA~1\ SUCCESS
1825 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22495232 Length: 49152
1826 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22544384 Length: 65536
1827 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22609920 Length: 65536
1828 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22675456 Length: 65536
1829 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 22740992 Length: 65536
1830 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1831 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1832 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1833 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1834 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1835 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1836 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1837 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1838 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1839 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1840 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1841 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1842 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1843 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1844 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1845 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1846 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1847 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1848 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1849 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1850 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1851 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1852 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1853 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1854 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1855 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1856 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1857 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1858 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1859 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1860 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1861 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1862 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1863 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1864 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23044096 Length: 24576
1865 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23068672 Length: 65536
1866 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23134208 Length: 65536
1867 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23199744 Length: 65536
1868 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23265280 Length: 65536
1869 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23330816 Length: 65536
1870 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23396352 Length: 65536
1871 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23461888 Length: 65536
1872 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 23527424 Length: 65536
1873 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
1874 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
1875 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
1876 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
1877 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
1878 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1879 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1880 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati
1881 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1882 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1883 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati
1884 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1885 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1886 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1887 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1888 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1889 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1890 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1891 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1892 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1893 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1894 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1895 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1896 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1897 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1898 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1899 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1900 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1901 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1902 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1903 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1904 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1905 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1906 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1907 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1908 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1909 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1910 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1911 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1912 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1913 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1914 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1915 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1916 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1917 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1918 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1919 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1920 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1921 10:38:34 PM msad.exe:304 DELETE C:\WINDOWS\Microsoft.NET\d
1922 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1923 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
1924 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati
1925 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
1926 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
1927 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET NOTIFY ENUM DIR Change Notify
1928 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1929 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1930 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1931 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1932 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1933 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1934 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1935 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati
1936 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1937 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1938 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati
1939 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1940 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1941 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1942 10:38:34 PM msad.exe:304 SET INFORMATION C:\WINDOWS\Microsoft.NET\d
1943 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1944 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1945 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1946 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1947 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1948 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1949 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
1950 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati
1951 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
1952 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
1953 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati
1954 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
1955 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1956 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1957 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1958 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1959 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1960 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1961 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1962 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1963 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1964 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1965 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1966 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1967 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1968 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1969 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1970 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1971 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1972 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1973 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1974 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1975 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1976 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1977 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1978 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1979 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1980 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1981 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1982 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1983 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1984 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1985 10:38:34 PM msad.exe:304 READ C:\WINDOWS\Microsoft.NET\d
1986 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1987 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET\d
1988 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1989 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
1990 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
1991 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati
1992 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
1993 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS SUCCESS Change Notify
1994 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET SUCCESS Change Notify
1995 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1996 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
1997 10:38:34 PM msad.exe:304 SET INFORMATION C:\WINDOWS\Microsoft.NET\d
1998 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\d
1999 10:38:34 PM msad.exe:304 READ C: SUCCESS Offset: 14077952 Length: 4096
2000 10:38:34 PM msad.exe:304 CREATE C:\WINDOWS\Microsoft.NET\d
2001 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
2002 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
2003 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS SUCCESS Options: Open Access: All
2004 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS SUCCESS FileAlternateNameInformati
2005 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS SUCCESS
2006 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET SUCCESS Options: Open Access: All
2007 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\WINDOWS\Microsoft.NET SUCCESS FileAlternateNameInformati
2008 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET SUCCESS
2009 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
2010 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\d
2011 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: 00000000
2012 10:38:34 PM msad.exe:304 OPEN C:\WINDOWS\Microsoft.NET\ SUCCESS Options: Open Directory Access: All
2013 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET\ SUCCESS FileBothDirectoryInformati
2014 10:38:34 PM msad.exe:304 CLOSE C:\WINDOWS\Microsoft.NET\ SUCCESS
2015 10:38:34 PM winlogon.exe:660 DIRECTORY C:\WINDOWS Change Notify
2016 10:38:34 PM msad.exe:304 DIRECTORY C:\WINDOWS\Microsoft.NET Change Notify
2017 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2018 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2019 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2020 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2021 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2022 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2023 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2024 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2025 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2026 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2027 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2028 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2029 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2030 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2031 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2032 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2033 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2034 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2035 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2036 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2037 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2038 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2039 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2040 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2041 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2042 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2043 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2044 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 8192 Length: 65536
2045 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 73728 Length: 65536
2046 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 139264 Length: 65536
2047 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 204800 Length: 57344
2048 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2049 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2050 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2051 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2052 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2053 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2054 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2055 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2056 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2057 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2058 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2059 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2060 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2061 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2062 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2063 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2064 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2065 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2066 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2067 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2068 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2069 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2070 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2071 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2072 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2073 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2074 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2075 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2076 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2077 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2078 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2079 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2080 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2081 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2082 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 565248 Length: 65536
2083 10:38:34 PM iexplore.exe:788 OPEN C:\ SUCCESS Options: Open Directory Access: All
2084 10:38:34 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2085 10:38:34 PM iexplore.exe:788 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2086 10:38:34 PM iexplore.exe:788 CLOSE C:\ SUCCESS
2087 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 630784 Length: 65536
2088 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 696320 Length: 65536
2089 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 761856 Length: 24576
2090 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 786432 Length: 65536
2091 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 851968 Length: 65536
2092 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 917504 Length: 65536
2093 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 983040 Length: 65536
2094 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2095 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2096 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2097 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2098 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2099 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2100 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2101 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2102 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2103 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2104 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2105 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2106 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2107 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2108 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2109 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2110 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2111 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2112 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2113 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2114 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2115 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2116 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2117 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2118 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2119 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2120 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2121 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2122 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2123 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2124 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1220608 Length: 65536
2125 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1286144 Length: 24576
2126 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1310720 Length: 65536
2127 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1376256 Length: 65536
2128 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1441792 Length: 65536
2129 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1507328 Length: 65536
2130 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2131 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2132 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2133 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2134 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2135 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2136 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2137 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2138 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2139 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2140 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2141 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2142 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2143 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2144 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2145 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2146 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2147 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2148 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2149 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2150 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2151 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2152 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2153 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2154 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2155 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2156 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2157 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2158 10:38:34 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2159 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2160 10:38:34 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2161 10:38:34 PM msad.exe:304 CLOSE C:\ SUCCESS
2162 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2163 10:38:34 PM msad.exe:304 WRITE C:\WINDOWS\Microsoft.NET\d
2164 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1900544 Length: 65536
2165 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 1966080 Length: 65536
2166 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2031616 Length: 65536
2167 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2097152 Length: 65536
2168 10:38:34 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2162688 Length: 65536
2169 10:38:35 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2228224 Length: 65536
2170 10:38:35 PM msad.exe:304 WRITE C:\$ConvertToNonresident SUCCESS Offset: 2293760 Length: 65536
2171 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2172 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2173 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2174 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2175 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2176 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2177 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2178 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2179 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2180 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2181 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2182 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2183 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2184 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2185 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2186 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2187 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2188 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2189 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2190 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2191 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2192 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2193 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2194 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
2195 10:38:35 PM msad.exe:304 OPEN C:\ SUCCESS Options: Open Directory Access: All
2196 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileNameInformation
2197 10:38:35 PM msad.exe:304 QUERY INFORMATION C:\ SUCCESS FileFsVolumeInformation
2198 10:38:35 PM msad.exe:304 CLOSE C:\ SUCCESS
its necessary for you to fing the .dll file of this, use DllCpmpare you got this tool from locate.com. Use this tools (in this tools you have 2 options search through .dll or.exe, find msad.exe and its dll )
ASKER
???Not sure what it's supposed to look like???
* DLLCompare Log version(1.0.0.125)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
__________________________ __________ __________ __
C:\WINDOWS\MICROS~1.NET\ms ad.exe Fri Nov 12 2004 10:44:46p ..SH. 855,040 835.00 K
__________________________ __________ __________ __
1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 855,040 bytes 835.00 K
Administrator Account = True
--------------------End log---------------------
* DLLCompare Log version(1.0.0.125)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
__________________________
C:\WINDOWS\MICROS~1.NET\ms
__________________________
1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 855,040 bytes 835.00 K
Administrator Account = True
--------------------End log---------------------
ASKER
Got rid of msad.exe !!!!
ran HJT
checked msad items
killbox'd msad for after reboot
fixed checked in HJT
booted Safe mode
deleted users temp dir under local settings
reboot
and it was gone. bye bye
ran HJT
checked msad items
killbox'd msad for after reboot
fixed checked in HJT
booted Safe mode
deleted users temp dir under local settings
reboot
and it was gone. bye bye
good job.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
HijackThis has fixed that problem....
https://www.experts-exchange.com/questions/21149514/Instructions-regarding-the-handling-of-HIJACK-THIS-logs.html
Once you've installed HijackThis, paste your log here:
http://www.hijackthis.de/index.php?langselect=english