rtl_support
asked on
Cannot remove Vundo/Virtumonde.dll trojan from my PC
Hi guys,
I've recently had a lot of trouble with my work PC being infected with what appears to be the Vundo trojan. I first spotted this when my McAfee VirusScan Enterprise alerted me that it had found various Trojans relating to the name Vundo. It said it had cleaned and deleted them but then i've continued to see the symptoms which relate to the Vundo Trojan.
As i type this every few minutes a random new webpage will open advertising some nonsense which definatly does not relate to the site im on. I scanned the PC with Spybot Search and Destroy which listed problems with "Virtumonde" and "Virtumonde.dll" which i believe are related to the Vundo trojan?? Again Spybot says it deletes them but i get the same problems. Next i tried a full system scan with McAfee which found the problems and says it delete but again the problems are still there. Next i tried to run Spyware Doctor with the latest updates in safe mode which found between 15 and 20 problems relating to the Vundo problems but....you've guess it, does not actually remove it. I'll reboot and scan again to find the same if not more problems there.
After doing a little research i tried running Vundofix in safe mode which didn't find anything which i thought was a good sign but im still getting these random popups when im not even surfing the net. I have exhausted all my (modest) knowledge on attempting to clean this trojan out but desperately need assistance if im to get rid of it.
I've installed the latest Hijackthis and have the log file for you guys to look at. Could anyone let me know what problems i have on my PC from the log file and suggest the proper way to fully clean them from my PC as at the moment i'm looking at formatting.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:15:36, on 02/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\csrss. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
D:\Program Files\Lavasoft\Ad-Aware\aa wservice.e xe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e xe
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\inetsr v\inetinfo .exe
C:\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex e
C:\Program Files\McAfee\Common Framework\FrameworkService .exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\HPZipm 12.exe
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter .exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\dllhos t.exe
d:\Program Files\RealVNC\VNC4\WinVNC4 .exe
C:\WINDOWS\system32\Search Indexer.ex e
C:\Program Files\Exchsrvr\bin\exmgmt. exe
C:\WINDOWS\system32\dllhos t.exe
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn apService. exe
C:\WINDOWS\System32\alg.ex e
C:\WINDOWS\system32\msdtc. exe
C:\WINDOWS\system32\igfxtr ay.exe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxpe rs.exe
C:\WINDOWS\system32\igfxsr vc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\SMINST\Schedule r.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper. exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\rundll 32.exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService .exe
C:\PROGRA~1\MICROS~2\Offic e12\OUTLOO K.EXE
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\mmc.ex e
C:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\SPYWAR~1\swdoc tor.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\woyt\Desktop\HiJa ckThis.exe
C:\WINDOWS\system32\wbem\w miprvse.ex e
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\In ternet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5 8F732D338C 0} - D:\Program Files\HP\Smart Web Printing\hpswp_fra
Thanks
I've recently had a lot of trouble with my work PC being infected with what appears to be the Vundo trojan. I first spotted this when my McAfee VirusScan Enterprise alerted me that it had found various Trojans relating to the name Vundo. It said it had cleaned and deleted them but then i've continued to see the symptoms which relate to the Vundo Trojan.
As i type this every few minutes a random new webpage will open advertising some nonsense which definatly does not relate to the site im on. I scanned the PC with Spybot Search and Destroy which listed problems with "Virtumonde" and "Virtumonde.dll" which i believe are related to the Vundo trojan?? Again Spybot says it deletes them but i get the same problems. Next i tried a full system scan with McAfee which found the problems and says it delete but again the problems are still there. Next i tried to run Spyware Doctor with the latest updates in safe mode which found between 15 and 20 problems relating to the Vundo problems but....you've guess it, does not actually remove it. I'll reboot and scan again to find the same if not more problems there.
After doing a little research i tried running Vundofix in safe mode which didn't find anything which i thought was a good sign but im still getting these random popups when im not even surfing the net. I have exhausted all my (modest) knowledge on attempting to clean this trojan out but desperately need assistance if im to get rid of it.
I've installed the latest Hijackthis and have the log file for you guys to look at. Could anyone let me know what problems i have on my PC from the log file and suggest the proper way to fully clean them from my PC as at the moment i'm looking at formatting.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:15:36, on 02/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
D:\Program Files\Lavasoft\Ad-Aware\aa
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\inetsr
C:\Program Files\Common Files\InterVideo\RegMgr\iv
C:\Program Files\McAfee\Common Framework\FrameworkService
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\HPZipm
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\dllhos
d:\Program Files\RealVNC\VNC4\WinVNC4
C:\WINDOWS\system32\Search
C:\Program Files\Exchsrvr\bin\exmgmt.
C:\WINDOWS\system32\dllhos
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\msdtc.
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\SMINST\Schedule
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\rundll
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService
C:\PROGRA~1\MICROS~2\Offic
C:\WINDOWS\system32\ctfmon
C:\WINDOWS\system32\mmc.ex
C:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\SPYWAR~1\swdoc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\woyt\Desktop\HiJa
C:\WINDOWS\system32\wbem\w
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5
Thanks
The log looks incomplete , can you please run another scan fron safe mode & post the log ?
also I have noticed there is IIS installed on this machine, do you host a website / FTP / mail server on this machine ?
if not this should be uninstalled
also I have noticed there is IIS installed on this machine, do you host a website / FTP / mail server on this machine ?
if not this should be uninstalled
download combofix from : www.bleepingcomputer.com/combofix/how-to-use-combofix and run it. Post the log file here once finshed as well as a complete HJT log as well.
ASKER
Hi guys, i'm not so sure its the vundo problem i have anymore. As my McAfee did a scan yesterday evening and found two files called NSPCA.TMP and nspCA.tmp and called them "prcviewer". Also it found a file called 00045c78.exe and called that "New Malware".
After running vundofix and such i can no longer locate any vundo related trojans, possibly some other problems?? Anyway i have the log files from combofix and hijackthis. Combofix log first.
Start Time= 03/07/2008 12:16:09.79
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((( (((((((((( (((((((((( (( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) )))))))
2008-07-03 11:45:18 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Apple Computer"
2008-07-03 10:25:28 ( .D... ) "C:\Documents and Settings\woyt\Application Data\PC Tools"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Macromedia"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\HPAppData"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Adobe"
2008-07-03 10:09:56 ( .DS.. ) "C:\Documents and Settings\woyt\Application Data\Microsoft"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Sun"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\SampleView"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\InstallShield"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Identities"
2008-07-02 10:58:02 102912 ( A.... ) "C:\WINDOWS\system32\retkf anb.dll"
2008-07-02 10:58:02 102912 ( A.... ) "C:\WINDOWS\system32\cerhe m.dll"
2008-07-02 10:55:02 82432 ( A.... ) "C:\WINDOWS\system32\mihjb qcn.dll"
2008-07-02 10:52:02 90112 ( A.... ) "C:\WINDOWS\system32\hhwwj irm.dll"
2008-07-01 16:26:54 ( .D... ) "C:\Program Files\Common Files\Wise Installation Wizard"
2008-07-01 13:31:16 103424 ( A.... ) "C:\WINDOWS\system32\mjdpw j.dll"
2008-07-01 13:31:16 103424 ( A.... ) "C:\WINDOWS\system32\jexqu fhr.dll"
2008-07-01 13:22:16 90624 ( A.... ) "C:\WINDOWS\system32\nsrbr lxa.dll"
2008-07-01 12:05:44 103424 ( A.... ) "C:\WINDOWS\system32\pwxeg q.dll"
2008-07-01 12:05:44 103424 ( A.... ) "C:\WINDOWS\system32\gvref thc.dll"
2008-07-01 12:05:30 90624 ( A.... ) "C:\WINDOWS\system32\yfnek gqb.dll"
2008-06-30 14:17:12 81920 ( A.... ) "C:\WINDOWS\system32\cdifg uhu.dll"
2008-06-30 14:12:48 25088 ( A.... ) "C:\WINDOWS\system32\vtUoP gDs.dll"
2008-06-30 14:12:00 25088 ( A.... ) "C:\WINDOWS\system32\yayYP JCv.dll"
2008-06-30 14:11:44 33280 ( A.... ) "C:\WINDOWS\system32\winpp p32.dll"
2008-06-30 14:11:42 25088 ( A.... ) "C:\WINDOWS\system32\qoMfG vVo.dll"
2008-06-30 14:11:34 33280 ( A.... ) "C:\WINDOWS\system32\winmb j32.dll"
2008-06-30 14:11:32 25088 ( A.... ) "C:\WINDOWS\system32\awtSK ASl.dll"
2008-06-30 14:11:22 25088 ( A.... ) "C:\WINDOWS\system32\cbXrS Mgd.dll"
2008-06-30 14:11:08 25088 ( A.... ) "C:\WINDOWS\system32\nnnlI cCv.dll.vi r"
2008-05-30 00:35:12 17486968 ( A.... ) "C:\WINDOWS\system32\MRT.e xe"
2008-05-29 09:56:40 ( .D... ) "C:\Program Files\Microsoft CAPICOM 2.1.0.2"
2008-05-28 15:22:14 ( .D... ) "C:\Program Files\Common Files\HP"
2008-05-28 15:20:52 ( .D... ) "C:\Program Files\Common Files\Hewlett-Packard"
2008-05-28 15:17:42 ( .D... ) "C:\Program Files\HP"
2008-05-27 10:57:24 ( .D... ) "C:\Program Files\Your Company Name"
2008-05-16 11:58:04 12632 ( A.... ) "C:\WINDOWS\system32\lsdel ete.exe"
2008-05-08 16:43:44 ( .D... ) "C:\Program Files\Microsoft Silverlight"
2008-05-07 16:46:56 215144 ( A...R ) "C:\WINDOWS\pw32a.dll"
2008-05-07 16:46:56 215144 ( A...R ) "C:\WINDOWS\patchw32.dll"
2008-05-07 16:44:38 107368 ( A.... ) "C:\WINDOWS\system32\GEARA spi.dll"
2008-05-07 06:12:40 1288192 ( A.... ) "C:\WINDOWS\system32\quart z.dll"
2008-04-23 22:16:30 3591680 ( A.... ) "C:\WINDOWS\system32\mshtm l.dll"
2008-04-23 05:16:30 1159680 ( A.... ) "C:\WINDOWS\system32\urlmo n.dll"
2008-04-23 05:16:30 826368 ( A.... ) "C:\WINDOWS\system32\winin et.dll"
2008-04-23 05:16:30 233472 ( A.... ) "C:\WINDOWS\system32\webch eck.dll"
2008-04-23 05:16:28 6066176 ( A.... ) "C:\WINDOWS\system32\iefra me.dll"
2008-04-23 05:16:28 671232 ( ..... ) "C:\WINDOWS\system32\mstim e.dll"
2008-04-23 05:16:28 478208 ( A.... ) "C:\WINDOWS\system32\mshtm led.dll"
2008-04-23 05:16:28 459264 ( A.... ) "C:\WINDOWS\system32\msfee ds.dll"
2008-04-23 05:16:28 384512 ( ..... ) "C:\WINDOWS\system32\iedkc s32.dll"
2008-04-23 05:16:28 383488 ( A.... ) "C:\WINDOWS\system32\ieapf ltr.dll"
2008-04-23 05:16:28 347136 ( A.... ) "C:\WINDOWS\system32\dxtms ft.dll"
2008-04-23 05:16:28 267776 ( A.... ) "C:\WINDOWS\system32\iertu til.dll"
2008-04-23 05:16:28 230400 ( ..... ) "C:\WINDOWS\system32\ieaks ie.dll"
2008-04-23 05:16:28 214528 ( A.... ) "C:\WINDOWS\system32\dxtra ns.dll"
2008-04-23 05:16:28 193024 ( ..... ) "C:\WINDOWS\system32\msrat ing.dll"
2008-04-23 05:16:28 153088 ( ..... ) "C:\WINDOWS\system32\ieake ng.dll"
2008-04-23 05:16:28 133120 ( ..... ) "C:\WINDOWS\system32\extmg r.dll"
2008-04-23 05:16:28 124928 ( A.... ) "C:\WINDOWS\system32\advpa ck.dll"
2008-04-23 05:16:28 105984 ( A.... ) "C:\WINDOWS\system32\url.d ll"
2008-04-23 05:16:28 102912 ( ..... ) "C:\WINDOWS\system32\occac he.dll"
2008-04-23 05:16:28 63488 ( A.... ) "C:\WINDOWS\system32\icard ie.dll"
2008-04-23 05:16:28 52224 ( A.... ) "C:\WINDOWS\system32\msfee dsbs.dll"
2008-04-23 05:16:28 44544 ( A.... ) "C:\WINDOWS\system32\pngfi lt.dll"
2008-04-23 05:16:28 44544 ( ..... ) "C:\WINDOWS\system32\ierno nce.dll"
2008-04-23 05:16:28 27648 ( A.... ) "C:\WINDOWS\system32\jspro xy.dll"
2008-04-22 08:39:58 70656 ( A.... ) "C:\WINDOWS\system32\ie4ui nit.exe"
2008-04-22 08:39:58 13824 ( A.... ) "C:\WINDOWS\system32\ieudi nit.exe"
2008-04-20 06:07:52 161792 ( ..... ) "C:\WINDOWS\system32\ieaku i.dll"
2008-04-17 10:56:44 83208 ( A.... ) "C:\WINDOWS\system32\S32EV NT1.DLL"
2008-04-14 05:42:38 11264 ( A.... ) "C:\WINDOWS\system32\spnpi nst.exe"
2008-04-14 05:42:06 985088 ( A.... ) "C:\WINDOWS\system32\setup api.dll"
2008-04-14 05:41:58 423936 ( A.... ) "C:\WINDOWS\system32\licdl l.dll"
2008-04-14 01:16:52 329728 ( A.... ) "C:\WINDOWS\system32\netse tup.exe"
2008-04-14 01:13:22 92424 ( A.... ) "C:\WINDOWS\system32\rdpdd .dll"
2008-04-14 01:13:22 87176 ( A.... ) "C:\WINDOWS\system32\rdpws x.dll"
2008-04-14 01:13:22 12168 ( A.... ) "C:\WINDOWS\system32\tsddd .dll"
2008-04-14 01:12:44 704512 ( A.... ) "C:\WINDOWS\system32\ss3df o.scr"
2008-04-14 01:12:44 679936 ( A.... ) "C:\WINDOWS\system32\sstex t3d.scr"
2008-04-14 01:12:44 610304 ( A.... ) "C:\WINDOWS\system32\sspip es.scr"
2008-04-14 01:12:44 393216 ( A.... ) "C:\WINDOWS\system32\ssflw box.scr"
2008-04-14 01:12:44 220672 ( A.... ) "C:\WINDOWS\system32\logon .scr"
2008-04-14 01:12:44 47104 ( A.... ) "C:\WINDOWS\system32\ssmyp ics.scr"
2008-04-14 01:12:44 20992 ( A.... ) "C:\WINDOWS\system32\ssmar que.scr"
2008-04-14 01:12:44 19968 ( A.... ) "C:\WINDOWS\system32\ssbez ier.scr"
2008-04-14 01:12:44 18944 ( A.... ) "C:\WINDOWS\system32\ssmys t.scr"
2008-04-14 01:12:44 14336 ( A.... ) "C:\WINDOWS\system32\sssta rs.scr"
2008-04-14 01:12:44 9216 ( A.... ) "C:\WINDOWS\system32\scrns ave.scr"
2008-04-14 01:12:42 165888 ( A.... ) "C:\WINDOWS\system32\wuauc lt1.exe"
2008-04-14 01:12:42 155648 ( A.... ) "C:\WINDOWS\system32\wscri pt.exe"
2008-04-14 01:12:42 30720 ( A.... ) "C:\WINDOWS\system32\xcopy .exe"
2008-04-14 01:12:42 29696 ( A.... ) "C:\WINDOWS\system32\forma t.com"
2008-04-14 01:12:42 16896 ( A.... ) "C:\WINDOWS\system32\more. com"
2008-04-14 01:12:42 13824 ( A.... ) "C:\WINDOWS\system32\wscnt fy.exe"
2008-04-14 01:12:42 12800 ( A.... ) "C:\WINDOWS\system32\tree. com"
2008-04-14 01:12:42 11264 ( A.... ) "C:\WINDOWS\system32\wpnpi nst.exe"
2008-04-14 01:12:40 507904 ( A.... ) "C:\WINDOWS\system32\winlo gon.exe"
2008-04-14 01:12:40 433664 ( A.... ) "C:\WINDOWS\system32\wiaac mgr.exe"
2008-04-14 01:12:40 283648 ( A.... ) "C:\WINDOWS\winhlp32.exe"
2008-04-14 01:12:40 65024 ( A.... ) "C:\WINDOWS\system32\wextr act.exe"
2008-04-14 01:12:40 32256 ( A.... ) "C:\WINDOWS\system32\wpaba ln.exe"
2008-04-14 01:12:40 5632 ( A.... ) "C:\WINDOWS\system32\winve r.exe"
2008-04-14 01:12:38 347136 ( A.... ) "C:\WINDOWS\system32\tours tart.exe"
2008-04-14 01:12:38 289792 ( A.... ) "C:\WINDOWS\system32\vssvc .exe"
2008-04-14 01:12:38 259584 ( A.... ) "C:\WINDOWS\system32\trace rpt.exe"
2008-04-14 01:12:38 135680 ( A.... ) "C:\WINDOWS\system32\taskm gr.exe"
2008-04-14 01:12:38 106496 ( A.... ) "C:\WINDOWS\system32\sysoc mgr.exe"
2008-04-14 01:12:38 78336 ( A.... ) "C:\WINDOWS\system32\tlnts ess.exe"
2008-04-14 01:12:38 77824 ( A.... ) "C:\WINDOWS\system32\taskl ist.exe"
2008-04-14 01:12:38 76288 ( A.... ) "C:\WINDOWS\system32\taskk ill.exe"
2008-04-14 01:12:38 75776 ( A.... ) "C:\WINDOWS\system32\telne t.exe"
2008-04-14 01:12:38 73216 ( A.... ) "C:\WINDOWS\system32\tlnts vr.exe"
2008-04-14 01:12:38 61440 ( A.... ) "C:\WINDOWS\system32\tlnta dmn.exe"
2008-04-14 01:12:38 60416 ( A.... ) "C:\WINDOWS\system32\tzcha nge.exe"
2008-04-14 01:12:38 50176 ( A.... ) "C:\WINDOWS\system32\utilm an.exe"
2008-04-14 01:12:38 28672 ( A.... ) "C:\WINDOWS\system32\vercl sid.exe"
2008-04-14 01:12:38 26112 ( A.... ) "C:\WINDOWS\system32\useri nit.exe"
2008-04-14 01:12:38 18432 ( A.... ) "C:\WINDOWS\system32\ups.e xe"
2008-04-14 01:12:38 16896 ( A.... ) "C:\WINDOWS\system32\upnpc ont.exe"
2008-04-14 01:12:38 12288 ( A.... ) "C:\WINDOWS\system32\trace rt.exe"
2008-04-14 01:12:36 538624 ( A.... ) "C:\WINDOWS\system32\spide r.exe"
2008-04-14 01:12:36 131584 ( A.... ) "C:\WINDOWS\system32\sndre c32.exe"
2008-04-14 01:12:36 89600 ( A.... ) "C:\WINDOWS\system32\smlog svc.exe"
2008-04-14 01:12:36 77824 ( A.... ) "C:\WINDOWS\system32\shrpu bw.exe"
2008-04-14 01:12:36 73796 ( A.... ) "C:\WINDOWS\system32\slser v.exe"
2008-04-14 01:12:36 71680 ( A.... ) "C:\WINDOWS\system32\syste minfo.exe"
2008-04-14 01:12:36 70144 ( A.... ) "C:\WINDOWS\system32\sigve rif.exe"
2008-04-14 01:12:36 57856 ( A.... ) "C:\WINDOWS\system32\spool sv.exe"
2008-04-14 01:12:36 50688 ( A.... ) "C:\WINDOWS\system32\smss. exe"
2008-04-14 01:12:36 45056 ( A.... ) "C:\WINDOWS\system32\shmgr ate.exe"
2008-04-14 01:12:36 32866 ( A.... ) "C:\WINDOWS\system32\slrun dll.exe"
2008-04-14 01:12:36 32866 ( ..... ) "C:\WINDOWS\slrundll.exe"
2008-04-14 01:12:36 32768 ( A.... ) "C:\WINDOWS\system32\setup n.exe"
2008-04-14 01:12:36 26112 ( A.... ) "C:\WINDOWS\system32\skeys .exe"
2008-04-14 01:12:36 24576 ( A.... ) "C:\WINDOWS\system32\sort. exe"
2008-04-14 01:12:36 20992 ( A.... ) "C:\WINDOWS\system32\spupd wxp.exe"
2008-04-14 01:12:36 19456 ( A.... ) "C:\WINDOWS\system32\shutd own.exe"
2008-04-14 01:12:36 14848 ( A.... ) "C:\WINDOWS\system32\stimo n.exe"
2008-04-14 01:12:36 14336 ( A.... ) "C:\WINDOWS\system32\svcho st.exe"
2008-04-14 01:12:36 8192 ( A.... ) "C:\WINDOWS\system32\smbin st.exe"
2008-04-14 01:12:36 7680 ( A.... ) "C:\WINDOWS\system32\spdwn wxp.exe"
2008-04-14 01:12:34 141312 ( A.... ) "C:\WINDOWS\system32\sessm gr.exe"
2008-04-14 01:12:34 121856 ( A.... ) "C:\WINDOWS\system32\schta sks.exe"
2008-04-14 01:12:34 108544 ( A.... ) "C:\WINDOWS\system32\servi ces.exe"
2008-04-14 01:12:34 107520 ( A.... ) "C:\WINDOWS\system32\rsnot ify.exe"
2008-04-14 01:12:34 95744 ( A.... ) "C:\WINDOWS\system32\scard svr.exe"
2008-04-14 01:12:34 77312 ( A.... ) "C:\WINDOWS\system32\sdbin st.exe"
2008-04-14 01:12:34 77312 ( A.... ) "C:\WINDOWS\system32\rtcsh are.exe"
2008-04-14 01:12:34 33280 ( A.... ) "C:\WINDOWS\system32\rundl l32.exe"
2008-04-14 01:12:34 31232 ( A.... ) "C:\WINDOWS\system32\sethc .exe"
2008-04-14 01:12:34 23040 ( A.... ) "C:\WINDOWS\system32\setup .exe"
2008-04-14 01:12:34 18944 ( A.... ) "C:\WINDOWS\system32\seced it.exe"
2008-04-14 01:12:34 14848 ( A.... ) "C:\WINDOWS\system32\rsh.e xe"
2008-04-14 01:12:34 14336 ( A.... ) "C:\WINDOWS\system32\runon ce.exe"
2008-04-14 01:12:34 13824 ( A.... ) "C:\WINDOWS\system32\rexec .exe"
2008-04-14 01:12:34 13312 ( A.... ) "C:\WINDOWS\system32\saved ump.exe"
2008-04-14 01:12:32 215552 ( A.... ) "C:\WINDOWS\system32\osk.e xe"
2008-04-14 01:12:32 146432 ( A.... ) "C:\WINDOWS\regedit.exe"
2008-04-14 01:12:32 109568 ( A.... ) "C:\WINDOWS\system32\progm an.exe"
2008-04-14 01:12:32 67584 ( A.... ) "C:\WINDOWS\system32\openf iles.exe"
2008-04-14 01:12:32 67072 ( A.... ) "C:\WINDOWS\system32\rdsho st.exe"
2008-04-14 01:12:32 62976 ( A.... ) "C:\WINDOWS\system32\rdpcl ip.exe"
2008-04-14 01:12:32 58368 ( A.... ) "C:\WINDOWS\system32\packa ger.exe"
2008-04-14 01:12:32 56832 ( A.... ) "C:\WINDOWS\system32\rasph one.exe"
2008-04-14 01:12:32 50176 ( A.... ) "C:\WINDOWS\system32\reg.e xe"
2008-04-14 01:12:32 50176 ( A.... ) "C:\WINDOWS\system32\proqu ota.exe"
2008-04-14 01:12:32 49152 ( A.... ) "C:\WINDOWS\system32\power cfg.exe"
2008-04-14 01:12:32 35840 ( A.... ) "C:\WINDOWS\system32\rciml by.exe"
2008-04-14 01:12:32 21504 ( A.... ) "C:\WINDOWS\system32\rcp.e xe"
2008-04-14 01:12:32 19968 ( A.... ) "C:\WINDOWS\system32\qproc ess.exe"
2008-04-14 01:12:32 17920 ( A.... ) "C:\WINDOWS\system32\ping. exe"
2008-04-14 01:12:32 15872 ( A.... ) "C:\WINDOWS\system32\perfm on.exe"
2008-04-14 01:12:32 13824 ( A.... ) "C:\WINDOWS\system32\rdsad din.exe"
2008-04-14 01:12:32 11776 ( A.... ) "C:\WINDOWS\system32\regsv r32.exe"
2008-04-14 01:12:32 9216 ( A.... ) "C:\WINDOWS\system32\proxy cfg.exe"
2008-04-14 01:12:30 1200640 ( A.... ) "C:\WINDOWS\system32\ntbac kup.exe"
2008-04-14 01:12:30 420864 ( A.... ) "C:\WINDOWS\system32\ntvdm .exe"
2008-04-14 01:12:30 176640 ( A.... ) "C:\WINDOWS\system32\napst at.exe"
2008-04-14 01:12:30 124928 ( A.... ) "C:\WINDOWS\system32\net1. exe"
2008-04-14 01:12:30 111104 ( A.... ) "C:\WINDOWS\system32\netdd e.exe"
2008-04-14 01:12:30 86016 ( A.... ) "C:\WINDOWS\system32\netsh .exe"
2008-04-14 01:12:30 76800 ( A.... ) "C:\WINDOWS\system32\nsloo kup.exe"
2008-04-14 01:12:30 69632 ( A.... ) "C:\WINDOWS\system32\odbcc onf.exe"
2008-04-14 01:12:30 69120 ( A.... ) "C:\WINDOWS\system32\notep ad.exe"
2008-04-14 01:12:30 69120 ( A.... ) "C:\WINDOWS\notepad.exe"
2008-04-14 01:12:30 53760 ( A.... ) "C:\WINDOWS\system32\narra tor.exe"
2008-04-14 01:12:30 42496 ( A.... ) "C:\WINDOWS\system32\net.e xe"
2008-04-14 01:12:30 36864 ( A.... ) "C:\WINDOWS\system32\netst at.exe"
2008-04-14 01:12:30 32768 ( A.... ) "C:\WINDOWS\system32\odbca d32.exe"
2008-04-14 01:12:30 12288 ( A.... ) "C:\WINDOWS\system32\mstin it.exe"
2008-04-14 01:12:30 4096 ( A.... ) "C:\WINDOWS\system32\nddea pir.exe"
2008-04-14 01:12:28 343040 ( A.... ) "C:\WINDOWS\system32\mspai nt.exe"
2008-04-14 01:12:28 123392 ( A.... ) "C:\WINDOWS\system32\mplay 32.exe"
2008-04-14 01:12:28 117248 ( A.... ) "C:\WINDOWS\system32\mqtgs vc.exe"
2008-04-14 01:12:28 78848 ( A.... ) "C:\WINDOWS\system32\msiex ec.exe"
2008-04-14 01:12:28 19968 ( A.... ) "C:\WINDOWS\system32\mqbku p.exe"
2008-04-14 01:12:28 6144 ( A.... ) "C:\WINDOWS\system32\msdtc .exe"
2008-04-14 01:12:28 4608 ( A.... ) "C:\WINDOWS\system32\mqsvc .exe"
2008-04-14 01:12:26 1414656 ( A.... ) "C:\WINDOWS\system32\mmc.e xe"
2008-04-14 01:12:26 143360 ( A.... ) "C:\WINDOWS\system32\mobsy nc.exe"
2008-04-14 01:12:26 57344 ( A.... ) "C:\WINDOWS\system32\makec ab.exe"
2008-04-14 01:12:26 33792 ( A.... ) "C:\WINDOWS\system32\mmcpe rf.exe"
2008-04-14 01:12:26 32768 ( A.... ) "C:\WINDOWS\system32\mnmsr vc.exe"
2008-04-14 01:12:24 677888 ( A.... ) "C:\WINDOWS\system32\mstsc .exe"
2008-04-14 01:12:24 514560 ( A.... ) "C:\WINDOWS\system32\logon ui.exe"
2008-04-14 01:12:24 75264 ( A.... ) "C:\WINDOWS\system32\locat or.exe"
2008-04-14 01:12:24 72704 ( A.... ) "C:\WINDOWS\system32\magni fy.exe"
2008-04-14 01:12:24 59392 ( A.... ) "C:\WINDOWS\system32\logma n.exe"
2008-04-14 01:12:24 53248 ( A.... ) "C:\WINDOWS\system32\ipv6. exe"
2008-04-14 01:12:24 23552 ( A.... ) "C:\WINDOWS\system32\ipxro ute.exe"
2008-04-14 01:12:24 13312 ( A.... ) "C:\WINDOWS\system32\lsass .exe"
2008-04-14 01:12:22 150528 ( A.... ) "C:\WINDOWS\system32\imapi .exe"
2008-04-14 01:12:22 120832 ( A.... ) "C:\WINDOWS\system32\gpres ult.exe"
2008-04-14 01:12:22 114688 ( A.... ) "C:\WINDOWS\system32\iexpr ess.exe"
2008-04-14 01:12:22 59904 ( A.... ) "C:\WINDOWS\system32\getma c.exe"
2008-04-14 01:12:22 55808 ( A.... ) "C:\WINDOWS\system32\ipcon fig.exe"
2008-04-14 01:12:22 39424 ( A.... ) "C:\WINDOWS\system32\grpco nv.exe"
2008-04-14 01:12:22 15872 ( A.... ) "C:\WINDOWS\system32\help. exe"
2008-04-14 01:12:22 10752 ( A.... ) "C:\WINDOWS\hh.exe"
2008-04-14 01:12:20 1033728 ( A.... ) "C:\WINDOWS\explorer.exe"
2008-04-14 01:12:20 193024 ( A.... ) "C:\WINDOWS\system32\fsqui rt.exe"
2008-04-14 01:12:20 193024 ( A.... ) "C:\WINDOWS\system32\eudce dit.exe"
2008-04-14 01:12:20 82944 ( A.... ) "C:\WINDOWS\system32\event triggers.e xe"
2008-04-14 01:12:20 50688 ( A.... ) "C:\WINDOWS\system32\event create.exe "
2008-04-14 01:12:20 42496 ( A.... ) "C:\WINDOWS\system32\ftp.exe"
2008-04-14 01:12:20 27136 ( A.... ) "C:\WINDOWS\system32\finds tr.exe"
2008-04-14 01:12:20 24064 ( A.... ) "C:\WINDOWS\system32\extra c32.exe"
2008-04-14 01:12:20 23040 ( A.... ) "C:\WINDOWS\system32\fltmc .exe"
2008-04-14 01:12:20 20992 ( A.... ) "C:\WINDOWS\system32\fontv iew.exe"
2008-04-14 01:12:20 20992 ( A.... ) "C:\WINDOWS\system32\faxpa tch.exe"
2008-04-14 01:12:20 7680 ( A.... ) "C:\WINDOWS\system32\force dos.exe"
2008-04-14 01:12:18 1298432 ( A.... ) "C:\WINDOWS\system32\dxdia g.exe"
2008-04-14 01:12:18 224768 ( A.... ) "C:\WINDOWS\system32\dmadm in.exe"
2008-04-14 01:12:18 180224 ( A.... ) "C:\WINDOWS\system32\dwwin .exe"
2008-04-14 01:12:18 163840 ( A.... ) "C:\WINDOWS\system32\diskp art.exe"
2008-04-14 01:12:18 87040 ( A.... ) "C:\WINDOWS\system32\diant z.exe"
2008-04-14 01:12:18 83456 ( A.... ) "C:\WINDOWS\system32\dpvse tup.exe"
2008-04-14 01:12:18 62976 ( A.... ) "C:\WINDOWS\system32\drive rquery.exe "
2008-04-14 01:12:18 29696 ( A.... ) "C:\WINDOWS\system32\dplay svr.exe"
2008-04-14 01:12:18 17920 ( A.... ) "C:\WINDOWS\system32\dvdup grd.exe"
2008-04-14 01:12:18 17920 ( A.... ) "C:\WINDOWS\system32\dpnsv r.exe"
2008-04-14 01:12:18 15872 ( A.... ) "C:\WINDOWS\system32\dmrem ote.exe"
2008-04-14 01:12:18 10752 ( A.... ) "C:\WINDOWS\system32\dumpr ep.exe"
2008-04-14 01:12:18 5120 ( A.... ) "C:\WINDOWS\system32\dllho st.exe"
2008-04-14 01:12:16 139264 ( A.... ) "C:\WINDOWS\system32\cscri pt.exe"
2008-04-14 01:12:16 105472 ( A.... ) "C:\WINDOWS\system32\dfrgn tfs.exe"
2008-04-14 01:12:16 82944 ( A.... ) "C:\WINDOWS\system32\dfrgf at.exe"
2008-04-14 01:12:16 63488 ( A.... ) "C:\WINDOWS\system32\cmstp .exe"
2008-04-14 01:12:16 39936 ( A.... ) "C:\WINDOWS\system32\cmmon 32.exe"
2008-04-14 01:12:16 30208 ( A.... ) "C:\WINDOWS\system32\ddesh are.exe"
2008-04-14 01:12:16 27648 ( A.... ) "C:\WINDOWS\system32\conim e.exe"
2008-04-14 01:12:16 25088 ( A.... ) "C:\WINDOWS\system32\defra g.exe"
2008-04-14 01:12:16 15360 ( A.... ) "C:\WINDOWS\system32\ctfmo n.exe"
2008-04-14 01:12:16 6144 ( A.... ) "C:\WINDOWS\system32\dcomc nfg.exe"
2008-04-14 01:12:16 6144 ( A.... ) "C:\WINDOWS\system32\csrss .exe"
2008-04-14 01:12:14 580608 ( A.... ) "C:\WINDOWS\system32\autof mt.exe"
2008-04-14 01:12:14 389120 ( A.... ) "C:\WINDOWS\system32\cmd.e xe"
2008-04-14 01:12:14 142848 ( A.... ) "C:\WINDOWS\system32\bootc fg.exe"
2008-04-14 01:12:14 102912 ( A.... ) "C:\WINDOWS\system32\clipb rd.exe"
2008-04-14 01:12:14 71680 ( A.... ) "C:\WINDOWS\system32\blast cln.exe"
2008-04-14 01:12:14 64000 ( A.... ) "C:\WINDOWS\system32\clean mgr.exe"
2008-04-14 01:12:14 56832 ( A.... ) "C:\WINDOWS\system32\ciphe r.exe"
2008-04-14 01:12:14 33280 ( A.... ) "C:\WINDOWS\system32\clips rv.exe"
2008-04-14 01:12:14 25600 ( A.... ) "C:\WINDOWS\system32\cmdl3 2.exe"
2008-04-14 01:12:14 20480 ( A.... ) "C:\WINDOWS\system32\clico nfg.exe"
2008-04-14 01:12:14 19968 ( A.... ) "C:\WINDOWS\system32\cacls .exe"
2008-04-14 01:12:14 11264 ( A.... ) "C:\WINDOWS\system32\autol fn.exe"
2008-04-14 01:12:14 5632 ( A.... ) "C:\WINDOWS\system32\cisvc .exe"
2008-04-14 01:12:12 602624 ( A.... ) "C:\WINDOWS\system32\autoc onv.exe"
2008-04-14 01:12:12 588800 ( A.... ) "C:\WINDOWS\system32\autoc hk.exe"
2008-04-14 01:12:12 483840 ( A.... ) "C:\WINDOWS\system32\wzcsv c.dll"
2008-04-14 01:12:12 383488 ( A.... ) "C:\WINDOWS\system32\wzcdl g.dll"
2008-04-14 01:12:12 338432 ( A.... ) "C:\WINDOWS\system32\zipfl dr.dll"
2008-04-14 01:12:12 184320 ( A.... ) "C:\WINDOWS\system32\accwi z.exe"
2008-04-14 01:12:12 183296 ( A.... ) "C:\WINDOWS\system32\wuaue ng1.dll"
2008-04-14 01:12:12 129024 ( A.... ) "C:\WINDOWS\system32\xmlpr ov.dll"
2008-04-14 01:12:12 121856 ( A.... ) "C:\WINDOWS\system32\xmlli te.dll"
2008-04-14 01:12:12 98304 ( A.... ) "C:\WINDOWS\system32\ahui. exe"
2008-04-14 01:12:12 91648 ( A.... ) "C:\WINDOWS\system32\xacts rv.dll"
2008-04-14 01:12:12 52736 ( A.... ) "C:\WINDOWS\system32\wzcsa pi.dll"
2008-04-14 01:12:12 50176 ( A.... ) "C:\WINDOWS\system32\xmlpr ovi.dll"
2008-04-14 01:12:12 44544 ( A.... ) "C:\WINDOWS\system32\alg.e xe"
2008-04-14 01:12:12 32768 ( A.... ) "C:\WINDOWS\system32\asr_p fu.exe"
2008-04-14 01:12:12 30208 ( A.... ) "C:\WINDOWS\system32\asr_f mt.exe"
2008-04-14 01:12:12 25088 ( A.... ) "C:\WINDOWS\system32\at.ex e"
2008-04-14 01:12:12 14336 ( A.... ) "C:\WINDOWS\system32\audit usr.exe"
2008-04-14 01:12:12 12288 ( A.... ) "C:\WINDOWS\system32\attri b.exe"
2008-04-14 01:12:12 11776 ( A.... ) "C:\WINDOWS\system32\xoleh lp.dll"
2008-04-14 01:12:12 11264 ( A.... ) "C:\WINDOWS\system32\atmad m.exe"
2008-04-14 01:12:12 6656 ( A.... ) "C:\WINDOWS\system32\wuaus erv.dll"
2008-04-14 01:12:12 4096 ( A.... ) "C:\WINDOWS\system32\actmo vie.exe"
2008-04-14 01:12:10 604160 ( A.... ) "C:\WINDOWS\system32\wsece dit.dll"
2008-04-14 01:12:10 303616 ( A.... ) "C:\WINDOWS\system32\wmstr eam.dll"
2008-04-14 01:12:10 293376 ( A.... ) "C:\WINDOWS\system32\winsr v.dll"
2008-04-14 01:12:10 276992 ( A.... ) "C:\WINDOWS\system32\wmpho to.dll"
2008-04-14 01:12:10 264192 ( A.... ) "C:\WINDOWS\system32\wow32 .dll"
2008-04-14 01:12:10 176640 ( A.... ) "C:\WINDOWS\system32\wintr ust.dll"
2008-04-14 01:12:10 176128 ( A.... ) "C:\WINDOWS\system32\winmm .dll"
2008-04-14 01:12:10 172032 ( A.... ) "C:\WINDOWS\system32\wldap 32.dll"
2008-04-14 01:12:10 132096 ( A.... ) "C:\WINDOWS\system32\wkssv c.dll"
2008-04-14 01:12:10 115200 ( A.... ) "C:\WINDOWS\system32\wmsdm oe.dll"
2008-04-14 01:12:10 108032 ( A.... ) "C:\WINDOWS\system32\wshbt h.dll"
2008-04-14 01:12:10 99328 ( A.... ) "C:\WINDOWS\system32\winsc ard.dll"
2008-04-14 01:12:10 92672 ( A.... ) "C:\WINDOWS\system32\wlnot ify.dll"
2008-04-14 01:12:10 90112 ( A.... ) "C:\WINDOWS\system32\wshex t.dll"
2008-04-14 01:12:10 82432 ( A.... ) "C:\WINDOWS\system32\ws2_3 2.dll"
2008-04-14 01:12:10 80896 ( A.... ) "C:\WINDOWS\system32\wscsv c.dll"
2008-04-14 01:12:10 69120 ( A.... ) "C:\WINDOWS\system32\wlana pi.dll"
2008-04-14 01:12:10 53760 ( A.... ) "C:\WINDOWS\system32\winst a.dll"
2008-04-14 01:12:10 50688 ( A.... ) "C:\WINDOWS\system32\wstde cod.dll"
2008-04-14 01:12:10 41984 ( A.... ) "C:\WINDOWS\system32\wsnmp 32.dll"
2008-04-14 01:12:10 36864 ( A.... ) "C:\WINDOWS\system32\wshco n.dll"
2008-04-14 01:12:10 32256 ( A.... ) "C:\WINDOWS\system32\winip sec.dll"
2008-04-14 01:12:10 22528 ( A.... ) "C:\WINDOWS\system32\wsock 32.dll"
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpui .dll"
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpco re.dll"
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpcd .dll"
2008-04-14 01:12:10 19968 ( A.... ) "C:\WINDOWS\system32\ws2he lp.dll"
2008-04-14 01:12:10 19456 ( A.... ) "C:\WINDOWS\system32\wshtc pip.dll"
2008-04-14 01:12:10 18432 ( A.... ) "C:\WINDOWS\system32\wtsap i32.dll"
2008-04-14 01:12:10 17408 ( A.... ) "C:\WINDOWS\system32\winsh fhc.dll"
2008-04-14 01:12:10 16896 ( A.... ) "C:\WINDOWS\system32\winrn r.dll"
2008-04-14 01:12:10 14336 ( A.... ) "C:\WINDOWS\system32\wship 6.dll"
2008-04-14 01:12:10 11264 ( A.... ) "C:\WINDOWS\system32\wshrm .dll"
2008-04-14 01:12:08 990208 ( A.... ) "C:\WINDOWS\system32\sysse tup.dll"
2008-04-14 01:12:08 858624 ( A.... ) "C:\WINDOWS\system32\tapi3 .dll"
2008-04-14 01:12:08 727040 ( A.... ) "C:\WINDOWS\system32\usere nv.dll"
2008-04-14 01:12:08 713216 ( A.... ) "C:\WINDOWS\system32\sxs.d ll"
2008-04-14 01:12:08 712704 ( A.... ) "C:\WINDOWS\system32\windo wscodecs.d ll"
2008-04-14 01:12:08 589312 ( A.... ) "C:\WINDOWS\system32\wiash ext.dll"
2008-04-14 01:12:08 578560 ( A.... ) "C:\WINDOWS\system32\user3 2.dll"
2008-04-14 01:12:08 463360 ( A.... ) "C:\WINDOWS\system32\wiade fui.dll"
2008-04-14 01:12:08 434176 ( A.... ) "C:\WINDOWS\system32\vbscr ipt.dll"
2008-04-14 01:12:08 430592 ( A.... ) "C:\WINDOWS\system32\vssap i.dll"
2008-04-14 01:12:08 406016 ( A.... ) "C:\WINDOWS\system32\usp10 .dll"
2008-04-14 01:12:08 385536 ( A.... ) "C:\WINDOWS\system32\theme ui.dll"
2008-04-14 01:12:08 358400 ( A.... ) "C:\WINDOWS\system32\termm gr.dll"
2008-04-14 01:12:08 354304 ( A.... ) "C:\WINDOWS\system32\winht tp.dll"
2008-04-14 01:12:08 346112 ( A.... ) "C:\WINDOWS\system32\windo wscodecsex t.dll"
2008-04-14 01:12:08 333824 ( A.... ) "C:\WINDOWS\system32\wiase rvc.dll"
2008-04-14 01:12:08 316416 ( A.... ) "C:\WINDOWS\system32\untfs .dll"
2008-04-14 01:12:08 295424 ( A.... ) "C:\WINDOWS\system32\terms rv.dll"
2008-04-14 01:12:08 275456 ( A.... ) "C:\WINDOWS\system32\ulib. dll"
2008-04-14 01:12:08 249856 ( A.... ) "C:\WINDOWS\system32\tapis rv.dll"
2008-04-14 01:12:08 246814 ( A.... ) "C:\WINDOWS\system32\strmd ll.dll"
2008-04-14 01:12:08 239616 ( A.... ) "C:\WINDOWS\system32\upnpu i.dll"
2008-04-14 01:12:08 239104 ( A.... ) "C:\WINDOWS\system32\srrst r.dll"
2008-04-14 01:12:08 218624 ( A.... ) "C:\WINDOWS\system32\uxthe me.dll"
2008-04-14 01:12:08 215552 ( A.... ) "C:\WINDOWS\system32\wavem sp.dll"
2008-04-14 01:12:08 191488 ( A.... ) "C:\WINDOWS\system32\syncu i.dll"
2008-04-14 01:12:08 185856 ( A.... ) "C:\WINDOWS\system32\upnph ost.dll"
2008-04-14 01:12:08 181760 ( A.... ) "C:\WINDOWS\system32\tapi3 2.dll"
2008-04-14 01:12:08 175104 ( A.... ) "C:\WINDOWS\system32\w32ti me.dll"
2008-04-14 01:12:08 171008 ( A.... ) "C:\WINDOWS\system32\srsvc .dll"
2008-04-14 01:12:08 136704 ( A.... ) "C:\WINDOWS\system32\sti_c i.dll"
2008-04-14 01:12:08 135680 ( A.... ) "C:\WINDOWS\system32\webvw .dll"
2008-04-14 01:12:08 133632 ( A.... ) "C:\WINDOWS\system32\upnp. dll"
2008-04-14 01:12:08 124416 ( A.... ) "C:\WINDOWS\system32\wiads s.dll"
2008-04-14 01:12:08 123392 ( A.... ) "C:\WINDOWS\system32\umpnp mgr.dll"
2008-04-14 01:12:08 121856 ( A.... ) "C:\WINDOWS\system32\stobj ect.dll"
2008-04-14 01:12:08 117760 ( A.... ) "C:\WINDOWS\system32\t2emb ed.dll"
2008-04-14 01:12:08 111104 ( A.... ) "C:\WINDOWS\system32\wiavi deo.dll"
2008-04-14 01:12:08 102400 ( A.... ) "C:\WINDOWS\system32\win32 spl.dll"
2008-04-14 01:12:08 101376 ( A.... ) "C:\WINDOWS\system32\txflo g.dll"
2008-04-14 01:12:08 96768 ( A.... ) "C:\WINDOWS\system32\srvsv c.dll"
2008-04-14 01:12:08 93696 ( A.... ) "C:\WINDOWS\system32\tscfg wmi.dll"
2008-04-14 01:12:08 90112 ( A.... ) "C:\WINDOWS\system32\trkwk s.dll"
2008-04-14 01:12:08 75776 ( A.... ) "C:\WINDOWS\system32\wiasc r.dll"
2008-04-14 01:12:08 75776 ( A.... ) "C:\WINDOWS\system32\strmf ilt.dll"
2008-04-14 01:12:08 74752 ( A.... ) "C:\WINDOWS\system32\storp rop.dll"
2008-04-14 01:12:08 74240 ( A.... ) "C:\WINDOWS\system32\usbui .dll"
2008-04-14 01:12:08 74240 ( A.... ) "C:\WINDOWS\system32\unimd mat.dll"
2008-04-14 01:12:08 71680 ( A.... ) "C:\WINDOWS\system32\ssdps rv.dll"
2008-04-14 01:12:08 68096 ( A.... ) "C:\WINDOWS\system32\webcl nt.dll"
2008-04-14 01:12:08 68096 ( A.... ) "C:\WINDOWS\system32\sti.d ll"
2008-04-14 01:12:08 67584 ( A.... ) "C:\WINDOWS\system32\srcli ent.dll"
2008-04-14 01:12:08 59392 ( A.... ) "C:\WINDOWS\system32\stcli ent.dll"
2008-04-14 01:12:08 57856 ( A.... ) "C:\WINDOWS\system32\twext .dll"
2008-04-14 01:12:08 57856 ( A.... ) "C:\WINDOWS\system32\synce ng.dll"
2008-04-14 01:12:08 53248 ( A.... ) "C:\WINDOWS\system32\tsgqe c.dll"
2008-04-14 01:12:08 51712 ( A.... ) "C:\WINDOWS\system32\vdmre dir.dll"
2008-04-14 01:12:08 50688 ( A.... ) "C:\WINDOWS\twain_32.dll"
2008-04-14 01:12:08 50688 ( A.... ) "C:\WINDOWS\system32\tspkg .dll"
2008-04-14 01:12:08 49152 ( A.... ) "C:\WINDOWS\system32\wdige st.dll"
2008-04-14 01:12:08 45568 ( A.... ) "C:\WINDOWS\system32\tcpmo nui.dll"
2008-04-14 01:12:08 45568 ( A.... ) "C:\WINDOWS\system32\tcpmo n.dll"
2008-04-14 01:12:08 35840 ( A.... ) "C:\WINDOWS\system32\umand lg.dll"
2008-04-14 01:12:08 34816 ( A.... ) "C:\WINDOWS\system32\ssdpa pi.dll"
2008-04-14 01:12:08 30749 ( A.... ) "C:\WINDOWS\system32\vbaje t32.dll"
2008-04-14 01:12:08 26624 ( A.... ) "C:\WINDOWS\system32\verif ier.dll"
2008-04-14 01:12:08 26624 ( A.... ) "C:\WINDOWS\system32\udhis api.dll"
2008-04-14 01:12:08 26112 ( A.... ) "C:\WINDOWS\system32\vdmdb g.dll"
2008-04-14 01:12:08 18944 ( A.... ) "C:\WINDOWS\system32\versi on.dll"
2008-04-14 01:12:08 16896 ( A.... ) "C:\WINDOWS\system32\usbmo n.dll"
2008-04-14 01:12:08 15872 ( A.... ) "C:\WINDOWS\system32\w3ssl .dll"
2008-04-14 01:12:08 14848 ( A.... ) "C:\WINDOWS\system32\tcpmi b.dll"
2008-04-14 01:12:08 13824 ( A.... ) "C:\WINDOWS\system32\unipl at.dll"
2008-04-14 01:12:08 8192 ( A.... ) "C:\WINDOWS\system32\staxm em.dll"
2008-04-14 01:12:08 7168 ( A.... ) "C:\WINDOWS\system32\tlnts vrp.dll"
2008-04-14 01:12:06 8461312 ( A.... ) "C:\WINDOWS\system32\shell 32.dll"
2008-04-14 01:12:06 1614848 ( A.... ) "C:\WINDOWS\system32\sfcfi les.dll"
2008-04-14 01:12:06 1499136 ( A.... ) "C:\WINDOWS\system32\shdoc vw.dll"
2008-04-14 01:12:06 474112 ( A.... ) "C:\WINDOWS\system32\shlwa pi.dll"
2008-04-14 01:12:06 442368 ( A.... ) "C:\WINDOWS\system32\sqlsr v32.dll"
2008-04-14 01:12:06 438272 ( A.... ) "C:\WINDOWS\system32\shimg vw.dll"
2008-04-14 01:12:06 362496 ( A.... ) "C:\WINDOWS\system32\smlog cfg.dll"
2008-04-14 01:12:06 314880 ( A.... ) "C:\WINDOWS\system32\scesr v.dll"
2008-04-14 01:12:06 286792 ( A.... ) "C:\WINDOWS\system32\slext spk.dll"
2008-04-14 01:12:06 192512 ( A.... ) "C:\WINDOWS\system32\sched svc.dll"
2008-04-14 01:12:06 188508 ( A.... ) "C:\WINDOWS\system32\slgen .dll"
2008-04-14 01:12:06 182272 ( A.... ) "C:\WINDOWS\system32\snmps nap.dll"
2008-04-14 01:12:06 181248 ( A.... ) "C:\WINDOWS\system32\scecl i.dll"
2008-04-14 01:12:06 180800 ( A.... ) "C:\WINDOWS\system32\sqlun irl.dll"
2008-04-14 01:12:06 180224 ( A.... ) "C:\WINDOWS\system32\scrob j.dll"
2008-04-14 01:12:06 172032 ( A.... ) "C:\WINDOWS\system32\scrru n.dll"
2008-04-14 01:12:06 171008 ( A.... ) "C:\WINDOWS\system32\sccsc cp.dll"
2008-04-14 01:12:06 152064 ( A.... ) "C:\WINDOWS\system32\shmed ia.dll"
2008-04-14 01:12:06 144384 ( A.... ) "C:\WINDOWS\system32\schan nel.dll"
2008-04-14 01:12:06 140288 ( A.... ) "C:\WINDOWS\system32\sfc_o s.dll"
2008-04-14 01:12:06 135168 ( A.... ) "C:\WINDOWS\system32\shsvc s.dll"
2008-04-14 01:12:06 98304 ( A.... ) "C:\WINDOWS\system32\slbio p.dll"
2008-04-14 01:12:06 75264 ( A.... ) "C:\WINDOWS\system32\spool ss.dll"
2008-04-14 01:12:06 73832 ( A.... ) "C:\WINDOWS\system32\slcoi nst.dll"
2008-04-14 01:12:06 68096 ( A.... ) "C:\WINDOWS\system32\shgin a.dll"
2008-04-14 01:12:06 65024 ( A.... ) "C:\WINDOWS\system32\shime ng.dll"
2008-04-14 01:12:06 56320 ( A.... ) "C:\WINDOWS\system32\servd eps.dll"
2008-04-14 01:12:06 56320 ( A.... ) "C:\WINDOWS\system32\secur 32.dll"
2008-04-14 01:12:06 54784 ( A.... ) "C:\WINDOWS\system32\sendm ail.dll"
2008-04-14 01:12:06 39424 ( A.... ) "C:\WINDOWS\system32\sens. dll"
2008-04-14 01:12:06 29184 ( A.... ) "C:\WINDOWS\system32\sendc msg.dll"
2008-04-14 01:12:06 29184 ( A.... ) "C:\WINDOWS\system32\sdhci nst.dll"
2008-04-14 01:12:06 27648 ( A.... ) "C:\WINDOWS\system32\shscr ap.dll"
2008-04-14 01:12:06 25088 ( A.... ) "C:\WINDOWS\system32\slaye rxp.dll"
2008-04-14 01:12:06 25088 ( A.... ) "C:\WINDOWS\system32\shfol der.dll"
2008-04-14 01:12:06 20480 ( A.... ) "C:\WINDOWS\system32\sclgn tfy.dll"
2008-04-14 01:12:06 18944 ( A.... ) "C:\WINDOWS\system32\snmpa pi.dll"
2008-04-14 01:12:06 18944 ( A.... ) "C:\WINDOWS\system32\seclo gon.dll"
2008-04-14 01:12:06 13312 ( A.... ) "C:\WINDOWS\system32\sigta b.dll"
2008-04-14 01:12:06 10752 ( A.... ) "C:\WINDOWS\system32\smtpa pi.dll"
2008-04-14 01:12:06 7168 ( A.... ) "C:\WINDOWS\system32\sensa pi.dll"
2008-04-14 01:12:06 5632 ( A.... ) "C:\WINDOWS\system32\secur ity.dll"
2008-04-14 01:12:06 5120 ( A.... ) "C:\WINDOWS\system32\sfc.d ll"
2008-04-14 01:12:04 1435648 ( A.... ) "C:\WINDOWS\system32\query .dll"
2008-04-14 01:12:04 658432 ( A.... ) "C:\WINDOWS\system32\rasdl g.dll"
2008-04-14 01:12:04 584704 ( A.... ) "C:\WINDOWS\system32\rpcrt 4.dll"
2008-04-14 01:12:04 562176 ( A.... ) "C:\WINDOWS\system32\qedit .dll"
2008-04-14 01:12:04 560640 ( A.... ) "C:\WINDOWS\system32\print ui.dll"
2008-04-14 01:12:04 433664 ( A.... ) "C:\WINDOWS\system32\riche d20.dll"
2008-04-14 01:12:04 415744 ( A.... ) "C:\WINDOWS\system32\samsr v.dll"
2008-04-14 01:12:04 409088 ( A.... ) "C:\WINDOWS\system32\qmgr. dll"
2008-04-14 01:12:04 399360 ( A.... ) "C:\WINDOWS\system32\rpcss .dll"
2008-04-14 01:12:04 397824 ( A.... ) "C:\WINDOWS\system32\regwi zc.dll"
2008-04-14 01:12:04 397056 ( A.... ) "C:\WINDOWS\system32\s3gnb .dll"
2008-04-14 01:12:04 386048 ( A.... ) "C:\WINDOWS\system32\qdvd. dll"
2008-04-14 01:12:04 291328 ( A.... ) "C:\WINDOWS\system32\qagen trt.dll"
2008-04-14 01:12:04 290304 ( A.... ) "C:\WINDOWS\system32\rhttp aa.dll"
2008-04-14 01:12:04 279040 ( A.... ) "C:\WINDOWS\system32\qdv.d ll"
2008-04-14 01:12:04 270848 ( A.... ) "C:\WINDOWS\system32\sbe.d ll"
2008-04-14 01:12:04 237056 ( A.... ) "C:\WINDOWS\system32\rasap i32.dll"
2008-04-14 01:12:04 210944 ( A.... ) "C:\WINDOWS\system32\raspp p.dll"
2008-04-14 01:12:04 192512 ( A.... ) "C:\WINDOWS\system32\qcap. dll"
2008-04-14 01:12:04 186368 ( A.... ) "C:\WINDOWS\system32\rasma ns.dll"
2008-04-14 01:12:04 159232 ( A.... ) "C:\WINDOWS\system32\sbeio .dll"
2008-04-14 01:12:04 150528 ( A.... ) "C:\WINDOWS\system32\qagen t.dll"
2008-04-14 01:12:04 150016 ( A.... ) "C:\WINDOWS\system32\rastl s.dll"
2008-04-14 01:12:04 147968 ( A.... ) "C:\WINDOWS\system32\rdcho st.dll"
2008-04-14 01:12:04 102400 ( A.... ) "C:\WINDOWS\system32\rcbdy ctl.dll"
2008-04-14 01:12:04 96768 ( A.... ) "C:\WINDOWS\system32\psbas e.dll"
2008-04-14 01:12:04 92672 ( A.... ) "C:\WINDOWS\system32\rsvps p.dll"
2008-04-14 01:12:04 88576 ( A.... ) "C:\WINDOWS\system32\rasau to.dll"
2008-04-14 01:12:04 79872 ( A.... ) "C:\WINDOWS\system32\rasch ap.dll"
2008-04-14 01:12:04 76800 ( A.... ) "C:\WINDOWS\system32\qutil .dll"
2008-04-14 01:12:04 69632 ( A.... ) "C:\WINDOWS\system32\scard dlg.dll"
2008-04-14 01:12:04 64000 ( A.... ) "C:\WINDOWS\system32\samli b.dll"
2008-04-14 01:12:04 62464 ( A.... ) "C:\WINDOWS\system32\qclip rov.dll"
2008-04-14 01:12:04 61952 ( A.... ) "C:\WINDOWS\system32\rasqe c.dll"
2008-04-14 01:12:04 61440 ( A.... ) "C:\WINDOWS\system32\rasma n.dll"
2008-04-14 01:12:04 60416 ( A.... ) "C:\WINDOWS\system32\remot epg.dll"
2008-04-14 01:12:04 59904 ( A.... ) "C:\WINDOWS\system32\regsv c.dll"
2008-04-14 01:12:04 58880 ( A.... ) "C:\WINDOWS\system32\resut ils.dll"
2008-04-14 01:12:04 58368 ( A.... ) "C:\WINDOWS\system32\rasta pi.dll"
2008-04-14 01:12:04 49664 ( A.... ) "C:\WINDOWS\system32\regap i.dll"
2008-04-14 01:12:04 45568 ( A.... ) "C:\WINDOWS\system32\safrs lv.dll"
2008-04-14 01:12:04 44032 ( A.... ) "C:\WINDOWS\system32\rtuti ls.dll"
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\safrc dlg.dll"
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\racpl dlg.dll"
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\pstor ec.dll"
2008-04-14 01:12:04 39936 ( A.... ) "C:\WINDOWS\system32\rshx3 2.dll"
2008-04-14 01:12:04 34304 ( A.... ) "C:\WINDOWS\system32\pstor svc.dll"
2008-04-14 01:12:04 31744 ( A.... ) "C:\WINDOWS\system32\rtipx mib.dll"
2008-04-14 01:12:04 29696 ( A.... ) "C:\WINDOWS\system32\safrd m.dll"
2008-04-14 01:12:04 27648 ( A.... ) "C:\WINDOWS\system32\profm ap.dll"
2008-04-14 01:12:04 23040 ( A.... ) "C:\WINDOWS\system32\psapi .dll"
2008-04-14 01:12:04 19968 ( A.... ) "C:\WINDOWS\system32\rdpsn d.dll"
2008-04-14 01:12:04 18944 ( A.... ) "C:\WINDOWS\system32\rsmps .dll"
2008-04-14 01:12:04 18944 ( A.... ) "C:\WINDOWS\system32\qmgrp rxy.dll"
2008-04-14 01:12:04 17408 ( A.... ) "C:\WINDOWS\system32\powrp rof.dll"
2008-04-14 01:12:04 16384 ( A.... ) "C:\WINDOWS\system32\rassa pi.dll"
2008-04-14 01:12:04 9728 ( A.... ) "C:\WINDOWS\system32\rwnh. dll"
2008-04-14 01:12:04 7680 ( A.... ) "C:\WINDOWS\system32\rasad hlp.dll"
2008-04-14 01:12:02 4274816 ( A.... ) "C:\WINDOWS\system32\nv4_d isp.dll"
2008-04-14 01:12:02 1737856 ( A.... ) "C:\WINDOWS\system32\mtxpa rhd.dll"
2008-04-14 01:12:02 1703936 ( A.... ) "C:\WINDOWS\system32\netsh ell.dll"
2008-04-14 01:12:02 1428992 ( A.... ) "C:\WINDOWS\system32\msvid ctl.dll"
2008-04-14 01:12:02 1306624 ( A.... ) "C:\WINDOWS\system32\msxml 6.dll"
2008-04-14 01:12:02 1287168 ( A.... ) "C:\WINDOWS\system32\ole32 .dll"
2008-04-14 01:12:02 1104896 ( A.... ) "C:\WINDOWS\system32\msxml 3.dll"
2008-04-14 01:12:02 875008 ( A.... ) "C:\WINDOWS\system32\netpl wiz.dll"
2008-04-14 01:12:02 713728 ( A.... ) "C:\WINDOWS\system32\openg l32.dll"
2008-04-14 01:12:02 701440 ( A.... ) "C:\WINDOWS\system32\msxml 2.dll"
2008-04-14 01:12:02 622592 ( A.... ) "C:\WINDOWS\system32\netcf gx.dll"
2008-04-14 01:12:02 554496 ( A.... ) "C:\WINDOWS\system32\p2psv c.dll"
2008-04-14 01:12:02 551936 ( A.... ) "C:\WINDOWS\system32\oleau t32.dll"
2008-04-14 01:12:02 506368 ( A.... ) "C:\WINDOWS\system32\msxml .dll"
2008-04-14 01:12:02 488448 ( A.... ) "C:\WINDOWS\system32\ntmsm gr.dll"
2008-04-14 01:12:02 435200 ( A.... ) "C:\WINDOWS\system32\ntmss vc.dll"
2008-04-14 01:12:02 413696 ( A.... ) "C:\WINDOWS\system32\msvcp 60.dll"
2008-04-14 01:12:02 412160 ( A.... ) "C:\WINDOWS\system32\photo metadataha ndler.dll"
2008-04-14 01:12:02 407040 ( A.... ) "C:\WINDOWS\system32\netlo gon.dll"
2008-04-14 01:12:02 343040 ( A.... ) "C:\WINDOWS\system32\msvcr t.dll"
2008-04-14 01:12:02 337408 ( A.... ) "C:\WINDOWS\system32\netap i32.dll"
2008-04-14 01:12:02 313856 ( A.... ) "C:\WINDOWS\system32\p2pgr aph.dll"
2008-04-14 01:12:02 286208 ( A.... ) "C:\WINDOWS\system32\objse l.dll"
2008-04-14 01:12:02 284160 ( A.... ) "C:\WINDOWS\system32\pdh.d ll"
2008-04-14 01:12:02 278559 ( A.... ) "C:\WINDOWS\system32\odbcj t32.dll"
2008-04-14 01:12:02 270336 ( A.... ) "C:\WINDOWS\system32\oakle y.dll"
2008-04-14 01:12:02 249856 ( A.... ) "C:\WINDOWS\system32\odbc3 2.dll"
2008-04-14 01:12:02 247808 ( A.... ) "C:\WINDOWS\system32\newde v.dll"
2008-04-14 01:12:02 245760 ( A.... ) "C:\WINDOWS\system32\netui 1.dll"
2008-04-14 01:12:02 245248 ( A.... ) "C:\WINDOWS\system32\mswso ck.dll"
2008-04-14 01:12:02 203776 ( A.... ) "C:\WINDOWS\system32\msweb dvd.dll"
2008-04-14 01:12:02 198144 ( A.... ) "C:\WINDOWS\system32\netma n.dll"
2008-04-14 01:12:02 193024 ( A.... ) "C:\WINDOWS\system32\napmo ntr.dll"
2008-04-14 01:12:02 192000 ( A.... ) "C:\WINDOWS\system32\offfi lt.dll"
2008-04-14 01:12:02 179200 ( A.... ) "C:\WINDOWS\system32\ntmsd ba.dll"
2008-04-14 01:12:02 176128 ( A.... ) "C:\WINDOWS\system32\photo wiz.dll"
2008-04-14 01:12:02 153600 ( A.... ) "C:\WINDOWS\system32\p2p.d ll"
2008-04-14 01:12:02 147456 ( A.... ) "C:\WINDOWS\system32\odbct rac.dll"
2008-04-14 01:12:02 144384 ( A.... ) "C:\WINDOWS\system32\onex. dll"
2008-04-14 01:12:02 143360 ( A.... ) "C:\WINDOWS\system32\ntshr ui.dll"
2008-04-14 01:12:02 142336 ( A.... ) "C:\WINDOWS\system32\nwpro vau.dll"
2008-04-14 01:12:02 139264 ( A.... ) "C:\WINDOWS\system32\netid .dll"
2008-04-14 01:12:02 135168 ( A.... ) "C:\WINDOWS\system32\odbcc onf.dll"
2008-04-14 01:12:02 122880 ( A.... ) "C:\WINDOWS\system32\oledl g.dll"
2008-04-14 01:12:02 121344 ( A.... ) "C:\WINDOWS\system32\msvfw 32.dll"
2008-04-14 01:12:02 118784 ( A.... ) "C:\WINDOWS\system32\ntmar ta.dll"
2008-04-14 01:12:02 115712 ( A.... ) "C:\WINDOWS\system32\p2pne tsh.dll"
2008-04-14 01:12:02 107008 ( A.... ) "C:\WINDOWS\system32\olepr n.dll"
2008-04-14 01:12:02 106496 ( A.... ) "C:\WINDOWS\system32\odbcc p32.dll"
2008-04-14 01:12:02 105472 ( A.... ) "C:\WINDOWS\system32\polst ore.dll"
2008-04-14 01:12:02 105472 ( A.... ) "C:\WINDOWS\system32\p2pga svc.dll"
2008-04-14 01:12:02 98304 ( A.... ) "C:\WINDOWS\system32\nlhtm l.dll"
2008-04-14 01:12:02 91648 ( A.... ) "C:\WINDOWS\system32\mtxoc i.dll"
2008-04-14 01:12:02 91136 ( A.... ) "C:\WINDOWS\system32\ntpri nt.dll"
2008-04-14 01:12:02 90624 ( A.... ) "C:\WINDOWS\system32\mydoc s.dll"
2008-04-14 01:12:02 84992 ( A.... ) "C:\WINDOWS\system32\olepr o32.dll"
2008-04-14 01:12:02 80896 ( A.... ) "C:\WINDOWS\system32\netui 0.dll"
2008-04-14 01:12:02 74752 ( A.... ) "C:\WINDOWS\system32\olecl i32.dll"
2008-04-14 01:12:02 72704 ( A.... ) "C:\WINDOWS\system32\msw3p rt.dll"
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\pauto enr.dll"
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\osuni nst.dll"
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\ocman age.dll"
2008-04-14 01:12:02 67072 ( A.... ) "C:\WINDOWS\system32\ntdsa pi.dll"
2008-04-14 01:12:02 66560 ( A.... ) "C:\WINDOWS\system32\mtxcl u.dll"
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\odbcc u32.dll"
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\odbcc r32.dll"
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\nwwks .dll"
2008-04-14 01:12:02 64000 ( A.... ) "C:\WINDOWS\system32\nwapi 32.dll"
2008-04-14 01:12:02 58880 ( A.... ) "C:\WINDOWS\system32\pnrpn sp.dll"
2008-04-14 01:12:02 57344 ( A.... ) "C:\WINDOWS\system32\msvci rt.dll"
2008-04-14 01:12:02 54784 ( A.... ) "C:\WINDOWS\system32\nppto ols.dll"
2008-04-14 01:12:02 44032 ( A.... ) "C:\WINDOWS\system32\ntlan man.dll"
2008-04-14 01:12:02 40960 ( A.... ) "C:\WINDOWS\system32\ntmsa pi.dll"
2008-04-14 01:12:02 39936 ( A.... ) "C:\WINDOWS\system32\perfc trs.dll"
2008-04-14 01:12:02 37376 ( A.... ) "C:\WINDOWS\system32\olecn v32.dll"
2008-04-14 01:12:02 36352 ( A.... ) "C:\WINDOWS\system32\ncobj api.dll"
2008-04-14 01:12:02 35328 ( A.... ) "C:\WINDOWS\system32\pid.d ll"
2008-04-14 01:12:02 34816 ( A.... ) "C:\WINDOWS\system32\perfp roc.dll"
2008-04-14 01:12:02 34304 ( A.... ) "C:\WINDOWS\system32\mtxle gih.dll"
2008-04-14 01:12:02 30720 ( A.... ) "C:\WINDOWS\system32\mtxdm .dll"
2008-04-14 01:12:02 30208 ( A.... ) "C:\WINDOWS\system32\napip sec.dll"
2008-04-14 01:12:02 28672 ( A.... ) "C:\WINDOWS\system32\nmmkc ert.dll"
2008-04-14 01:12:02 26624 ( A.... ) "C:\WINDOWS\system32\perfd isk.dll"
2008-04-14 01:12:02 25088 ( A.... ) "C:\WINDOWS\system32\perfo s.dll"
2008-04-14 01:12:02 24576 ( A.... ) "C:\WINDOWS\system32\odbcb cp.dll"
2008-04-14 01:12:02 20511 ( A.... ) "C:\WINDOWS\system32\odtex t32.dll"
2008-04-14 01:12:02 20511 ( A.... ) "C:\WINDOWS\system32\oddbs e32.dll"
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odpdx 32.dll"
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odfox 32.dll"
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odexl 32.dll"
2008-04-14 01:12:02 18944 ( A.... ) "C:\WINDOWS\system32\ndden b32.dll"
2008-04-14 01:12:02 17920 ( A.... ) "C:\WINDOWS\system32\perfn et.dll"
2008-04-14 01:12:02 17920 ( A.... ) "C:\WINDOWS\system32\nddea pi.dll"
2008-04-14 01:12:02 16896 ( A.... ) "C:\WINDOWS\system32\msyuv .dll"
2008-04-14 01:12:02 16384 ( A.... ) "C:\WINDOWS\system32\odbc3 2gt.dll"
2008-04-14 01:12:02 15360 ( A.... ) "C:\WINDOWS\system32\pjlmo n.dll"
2008-04-14 01:12:02 15360 ( A.... ) "C:\WINDOWS\system32\ntvdm d.dll"
2008-04-14 01:12:02 11776 ( A.... ) "C:\WINDOWS\system32\netra p.dll"
2008-04-14 01:12:02 8192 ( A.... ) "C:\WINDOWS\system32\ntlsa pi.dll"
2008-04-14 01:12:02 4096 ( A.... ) "C:\WINDOWS\system32\mtxex .dll"
2008-04-14 01:12:00 2843136 ( A.... ) "C:\WINDOWS\system32\msi.d ll"
2008-04-14 01:12:00 1384479 ( A.... ) "C:\WINDOWS\system32\msvbv m60.dll"
2008-04-14 01:12:00 997376 ( A.... ) "C:\WINDOWS\system32\msgin a.dll"
2008-04-14 01:12:00 956928 ( A.... ) "C:\WINDOWS\system32\msdtc tm.dll"
2008-04-14 01:12:00 539136 ( A.... ) "C:\WINDOWS\system32\msfte dit.dll"
2008-04-14 01:12:00 427008 ( A.... ) "C:\WINDOWS\system32\msdtc prx.dll"
2008-04-14 01:12:00 290816 ( A.... ) "C:\WINDOWS\system32\msnss pc.dll"
2008-04-14 01:12:00 274944 ( A.... ) "C:\WINDOWS\system32\mstas k.dll"
2008-04-14 01:12:00 271360 ( A.... ) "C:\WINDOWS\system32\msihn d.dll"
2008-04-14 01:12:00 252928 ( A.... ) "C:\WINDOWS\system32\msoea cct.dll"
2008-04-14 01:12:00 248832 ( A.... ) "C:\WINDOWS\system32\msieftp.dll"
2008-04-14 01:12:00 195072 ( A.... ) "C:\WINDOWS\system32\msutb .dll"
2008-04-14 01:12:00 161792 ( A.... ) "C:\WINDOWS\system32\msdtc uiu.dll"
2008-04-14 01:12:00 159232 ( A.... ) "C:\WINDOWS\system32\msimt f.dll"
2008-04-14 01:12:00 155136 ( A.... ) "C:\WINDOWS\system32\mssha .dll"
2008-04-14 01:12:00 151583 ( A.... ) "C:\WINDOWS\system32\msjin t40.dll"
2008-04-14 01:12:00 151552 ( A.... ) "C:\WINDOWS\system32\msdar t.dll"
2008-04-14 01:12:00 143360 ( A.... ) "C:\WINDOWS\system32\msorc l32.dll"
2008-04-14 01:12:00 134656 ( A.... ) "C:\WINDOWS\system32\mssap .dll"
2008-04-14 01:12:00 132608 ( A.... ) "C:\WINDOWS\system32\msv1_ 0.dll"
2008-04-14 01:12:00 116224 ( A.... ) "C:\WINDOWS\system32\mstls api.dll"
2008-04-14 01:12:00 105984 ( A.... ) "C:\WINDOWS\system32\msoer t2.dll"
2008-04-14 01:12:00 58880 ( A.... ) "C:\WINDOWS\system32\msdtc log.dll"
2008-04-14 01:12:00 51712 ( A.... ) "C:\WINDOWS\system32\mside nt.dll"
2008-04-14 01:12:00 33792 ( A.... ) "C:\WINDOWS\system32\msgsv c.dll"
2008-04-14 01:12:00 29696 ( A.... ) "C:\WINDOWS\system32\mspat cha.dll"
2008-04-14 01:12:00 25088 ( A.... ) "C:\WINDOWS\system32\mslbu i.dll"
2008-04-14 01:12:00 15360 ( A.... ) "C:\WINDOWS\system32\msisi p.dll"
2008-04-14 01:12:00 14336 ( A.... ) "C:\WINDOWS\system32\msdmo .dll"
2008-04-14 01:12:00 11264 ( A.... ) "C:\WINDOWS\system32\msrle 32.dll"
2008-04-14 01:12:00 6656 ( A.... ) "C:\WINDOWS\system32\msidl e.dll"
2008-04-14 01:12:00 4608 ( A.... ) "C:\WINDOWS\system32\msimg 32.dll"
2008-04-14 01:11:58 1872896 ( A.... ) "C:\WINDOWS\system32\mmcnd mgr.dll"
2008-04-14 01:11:58 663040 ( A.... ) "C:\WINDOWS\system32\mqqm. dll"
2008-04-14 01:11:58 586240 ( A.... ) "C:\WINDOWS\system32\mlang .dll"
2008-04-14 01:11:58 517632 ( A.... ) "C:\WINDOWS\system32\mqsna p.dll"
2008-04-14 01:11:58 471552 ( A.... ) "C:\WINDOWS\system32\mquti l.dll"
2008-04-14 01:11:58 397312 ( A.... ) "C:\WINDOWS\system32\mmcex .dll"
2008-04-14 01:11:58 297984 ( A.... ) "C:\WINDOWS\system32\msctf .dll"
2008-04-14 01:11:58 225280 ( A.... ) "C:\WINDOWS\system32\mqoa. dll"
2008-04-14 01:11:58 207360 ( A.... ) "C:\WINDOWS\system32\mobsy nc.dll"
2008-04-14 01:11:58 187392 ( A.... ) "C:\WINDOWS\system32\mqtri g.dll"
2008-04-14 01:11:58 184320 ( A.... ) "C:\WINDOWS\system32\micro soft.manag ementconso le.dll"
2008-04-14 01:11:58 177152 ( A.... ) "C:\WINDOWS\system32\mqrt. dll"
2008-04-14 01:11:58 163328 ( A.... ) "C:\WINDOWS\system32\mmcba se.dll"
2008-04-14 01:11:58 153600 ( A.... ) "C:\WINDOWS\system32\modem ui.dll"
2008-04-14 01:11:58 138240 ( A.... ) "C:\WINDOWS\system32\mqad. dll"
2008-04-14 01:11:58 123904 ( A.... ) "C:\WINDOWS\system32\mqrtd ep.dll"
2008-04-14 01:11:58 118784 ( A.... ) "C:\WINDOWS\system32\msdad iag.dll"
2008-04-14 01:11:58 106496 ( A.... ) "C:\WINDOWS\system32\mmcfx common.dll "
2008-04-14 01:11:58 95744 ( A.... ) "C:\WINDOWS\system32\mqsec .dll"
2008-04-14 01:11:58 89088 ( A.... ) "C:\WINDOWS\system32\mqlog mgr.dll"
2008-04-14 01:11:58 87040 ( A.... ) "C:\WINDOWS\system32\mprap i.dll"
2008-04-14 01:11:58 86016 ( A.... ) "C:\WINDOWS\system32\msaps spc.dll"
2008-04-14 01:11:58 73728 ( A.... ) "C:\WINDOWS\system32\mscms .dll"
2008-04-14 01:11:58 71680 ( A.... ) "C:\WINDOWS\system32\msacm 32.dll"
2008-04-14 01:11:58 69632 ( A.... ) "C:\WINDOWS\system32\mscon f.dll"
2008-04-14 01:11:58 68608 ( A.... ) "C:\WINDOWS\system32\msctf p.dll"
2008-04-14 01:11:58 61440 ( A.... ) "C:\WINDOWS\system32\mmcsh ext.dll"
2008-04-14 01:11:58 60928 ( A.... ) "C:\WINDOWS\system32\migli bnt.dll"
2008-04-14 01:11:58 59904 ( A.... ) "C:\WINDOWS\system32\mpr.d ll"
2008-04-14 01:11:58 57344 ( A.... ) "C:\WINDOWS\system32\msasn 1.dll"
2008-04-14 01:11:58 53248 ( A.... ) "C:\WINDOWS\system32\mprdi m.dll"
2008-04-14 01:11:58 49152 ( A.... ) "C:\WINDOWS\system32\mqupg rd.dll"
2008-04-14 01:11:58 47616 ( A.... ) "C:\WINDOWS\system32\mqdsc li.dll"
2008-04-14 01:11:58 36864 ( A.... ) "C:\WINDOWS\system32\mscpx l32.dll"
2008-04-14 01:11:58 34560 ( A.... ) "C:\WINDOWS\system32\mnmdd .dll"
2008-04-14 01:11:58 29696 ( A.... ) "C:\WINDOWS\system32\mimef ilt.dll"
2008-04-14 01:11:58 18944 ( A.... ) "C:\WINDOWS\system32\midim ap.dll"
2008-04-14 01:11:58 17408 ( A.... ) "C:\WINDOWS\system32\mmfut il.dll"
2008-04-14 01:11:58 16896 ( A.... ) "C:\WINDOWS\system32\mqise .dll"
2008-04-14 01:11:56 2061824 ( A.... ) "C:\WINDOWS\system32\mstsc ax.dll"
2008-04-14 01:11:56 1028096 ( A.... ) "C:\WINDOWS\system32\mfc42 .dll"
2008-04-14 01:11:56 989696 ( A.... ) "C:\WINDOWS\system32\kerne l32.dll"
2008-04-14 01:11:56 927504 ( A.... ) "C:\WINDOWS\system32\mfc40 u.dll"
2008-04-14 01:11:56 755200 ( A.... ) "C:\WINDOWS\system32\ir50_ 32.dll"
2008-04-14 01:11:56 728064 ( A.... ) "C:\WINDOWS\system32\lsasr v.dll"
2008-04-14 01:11:56 512000 ( A.... ) "C:\WINDOWS\system32\jscri pt.dll"
2008-04-14 01:11:56 399872 ( A.... ) "C:\WINDOWS\system32\lmrt. dll"
2008-04-14 01:11:56 384000 ( A.... ) "C:\WINDOWS\system32\ipsms nap.dll"
2008-04-14 01:11:56 349696 ( A.... ) "C:\WINDOWS\system32\ipsec snp.dll"
2008-04-14 01:11:56 343040 ( A.... ) "C:\WINDOWS\system32\local spl.dll"
2008-04-14 01:11:56 338432 ( A.... ) "C:\WINDOWS\system32\ir41_ qcx.dll"
2008-04-14 01:11:56 331264 ( A.... ) "C:\WINDOWS\system32\ipnat hlp.dll"
2008-04-14 01:11:56 330752 ( A.... ) "C:\WINDOWS\system32\ippro mon.dll"
2008-04-14 01:11:56 299520 ( A.... ) "C:\WINDOWS\system32\kerbe ros.dll"
2008-04-14 01:11:56 221696 ( A.... ) "C:\WINDOWS\system32\local sec.dll"
2008-04-14 01:11:56 200192 ( A.... ) "C:\WINDOWS\system32\ir50_ qc.dll"
2008-04-14 01:11:56 191488 ( A.... ) "C:\WINDOWS\system32\iueng ine.dll"
2008-04-14 01:11:56 183808 ( A.... ) "C:\WINDOWS\system32\ir50_ qcx.dll"
2008-04-14 01:11:56 183808 ( A.... ) "C:\WINDOWS\system32\ipsec svc.dll"
2008-04-14 01:11:56 177152 ( A.... ) "C:\WINDOWS\system32\iprtr mgr.dll"
2008-04-14 01:11:56 163840 ( A.... ) "C:\WINDOWS\system32\jgdw4 00.dll"
2008-04-14 01:11:56 161280 ( A.... ) "C:\WINDOWS\system32\ipmon tr.dll"
2008-04-14 01:11:56 155136 ( A.... ) "C:\WINDOWS\system32\itirc l.dll"
2008-04-14 01:11:56 150528 ( A.... ) "C:\WINDOWS\system32\keymg r.dll"
2008-04-14 01:11:56 147456 ( A.... ) "C:\WINDOWS\system32\initp ki.dll"
2008-04-14 01:11:56 138240 ( A.... ) "C:\WINDOWS\system32\itss. dll"
2008-04-14 01:11:56 123392 ( A.... ) "C:\WINDOWS\system32\input .dll"
2008-04-14 01:11:56 120320 ( A.... ) "C:\WINDOWS\system32\ir41_ qc.dll"
2008-04-14 01:11:56 118272 ( A.... ) "C:\WINDOWS\system32\mdmin st.dll"
2008-04-14 01:11:56 97280 ( A.... ) "C:\WINDOWS\system32\loadp erf.dll"
2008-04-14 01:11:56 94720 ( A.... ) "C:\WINDOWS\system32\iphlp api.dll"
2008-04-14 01:11:56 86016 ( A.... ) "C:\WINDOWS\system32\mdmxs dk.dll"
2008-04-14 01:11:56 84480 ( A.... ) "C:\WINDOWS\system32\mciav i32.dll"
2008-04-14 01:11:56 81920 ( A.... ) "C:\WINDOWS\system32\isign 32.dll"
2008-04-14 01:11:56 75264 ( A.... ) "C:\WINDOWS\system32\inetp p.dll"
2008-04-14 01:11:56 61440 ( A.... ) "C:\WINDOWS\system32\kmsvc .dll"
2008-04-14 01:11:56 59904 ( A.... ) "C:\WINDOWS\system32\ipv6m on.dll"
2008-04-14 01:11:56 58880 ( A.... ) "C:\WINDOWS\system32\licwm i.dll"
2008-04-14 01:11:56 54272 ( A.... ) "C:\WINDOWS\system32\ixsso .dll"
2008-04-14 01:11:56 47616 ( A.... ) "C:\WINDOWS\system32\iyuv_ 32.dll"
2008-04-14 01:11:56 40960 ( A.... ) "C:\WINDOWS\system32\mf321 6.dll"
2008-04-14 01:11:56 37376 ( A.... ) "C:\WINDOWS\system32\l2gps tore.dll"
2008-04-14 01:11:56 35328 ( A.... ) "C:\WINDOWS\system32\mciqt z32.dll"
2008-04-14 01:11:56 33792 ( A.... ) "C:\WINDOWS\system32\lmmib 2.dll"
2008-04-14 01:11:56 32768 ( A.... ) "C:\WINDOWS\system32\isrdb g32.dll"
2008-04-14 01:11:56 32768 ( A.... ) "C:\WINDOWS\system32\inetm ib1.dll"
2008-04-14 01:11:56 27648 ( A.... ) "C:\WINDOWS\system32\jgpl4 00.dll"
2008-04-14 01:11:56 23552 ( A.... ) "C:\WINDOWS\system32\mciwa ve.dll"
2008-04-14 01:11:56 23040 ( A.... ) "C:\WINDOWS\system32\mcise q.dll"
2008-04-14 01:11:56 22528 ( A.... ) "C:\WINDOWS\system32\mfcsu bs.dll"
2008-04-14 01:11:56 22016 ( A.... ) "C:\WINDOWS\system32\lpk.d ll"
2008-04-14 01:11:56 22016 ( A.... ) "C:\WINDOWS\system32\ipxwa n.dll"
2008-04-14 01:11:56 19968 ( A.... ) "C:\WINDOWS\system32\linki nfo.dll"
2008-04-14 01:11:56 15872 ( A.... ) "C:\WINDOWS\system32\inetp pui.dll"
2008-04-14 01:11:56 14848 ( A.... ) "C:\WINDOWS\system32\mgmta pi.dll"
2008-04-14 01:11:56 14336 ( A.... ) "C:\WINDOWS\system32\mcast mib.dll"
2008-04-14 01:11:56 13824 ( A.... ) "C:\WINDOWS\system32\lmhsv c.dll"
2008-04-14 01:11:56 13312 ( A.... ) "C:\WINDOWS\system32\infoa dmn.dll"
2008-04-14 01:11:56 11776 ( A.... ) "C:\WINDOWS\system32\local ui.dll"
2008-04-14 01:11:56 10240 ( A.... ) "C:\WINDOWS\system32\lprhe lp.dll"
2008-04-14 01:11:56 4096 ( A.... ) "C:\WINDOWS\system32\ksuse r.dll"
2008-04-14 01:11:54 1082368 ( A.... ) "C:\WINDOWS\system32\esent .dll"
2008-04-14 01:11:54 702845 ( A.... ) "C:\WINDOWS\system32\i81xd nt5.dll"
2008-04-14 01:11:54 691712 ( A.... ) "C:\WINDOWS\system32\inetc omm.dll"
2008-04-14 01:11:54 614912 ( A.... ) "C:\WINDOWS\system32\h323m sp.dll"
2008-04-14 01:11:54 382976 ( A.... ) "C:\WINDOWS\system32\fonte xt.dll"
2008-04-14 01:11:54 380445 ( A.... ) "C:\WINDOWS\system32\expsr v.dll"
2008-04-14 01:11:54 347136 ( A.... ) "C:\WINDOWS\system32\hyper trm.dll"
2008-04-14 01:11:54 344064 ( A.... ) "C:\WINDOWS\system32\hnetc fg.dll"
2008-04-14 01:11:54 337920 ( A.... ) "C:\WINDOWS\system32\filem gmt.dll"
2008-04-14 01:11:54 330752 ( A.... ) "C:\WINDOWS\system32\hnetw iz.dll"
2008-04-14 01:11:54 285184 ( A.... ) "C:\WINDOWS\system32\gdi32 .dll"
2008-04-14 01:11:54 274432 ( A.... ) "C:\WINDOWS\system32\inetc fg.dll"
2008-04-14 01:11:54 254976 ( A.... ) "C:\WINDOWS\system32\icm32 .dll"
2008-04-14 01:11:54 246272 ( A.... ) "C:\WINDOWS\system32\es.dl l"
2008-04-14 01:11:54 199680 ( A.... ) "C:\WINDOWS\system32\gptex t.dll"
2008-04-14 01:11:54 186880 ( A.... ) "C:\WINDOWS\system32\encde c.dll"
2008-04-14 01:11:54 183296 ( A.... ) "C:\WINDOWS\system32\els.d ll"
2008-04-14 01:11:54 144896 ( A.... ) "C:\WINDOWS\system32\hotpl ug.dll"
2008-04-14 01:11:54 144384 ( A.... ) "C:\WINDOWS\system32\image hlp.dll"
2008-04-14 01:11:54 135680 ( A.... ) "C:\WINDOWS\system32\ifmon .dll"
2008-04-14 01:11:54 133632 ( A.... ) "C:\WINDOWS\system32\iisrt l.dll"
2008-04-14 01:11:54 125952 ( A.... ) "C:\WINDOWS\system32\exts. dll"
2008-04-14 01:11:54 124928 ( A.... ) "C:\WINDOWS\system32\fde.d ll"
2008-04-14 01:11:54 122880 ( A.... ) "C:\WINDOWS\system32\glu32 .dll"
2008-04-14 01:11:54 120832 ( A.... ) "C:\WINDOWS\system32\idq.d ll"
2008-04-14 01:11:54 119808 ( A.... ) "C:\WINDOWS\system32\iasra d.dll"
2008-04-14 01:11:54 110080 ( A.... ) "C:\WINDOWS\system32\imm32 .dll"
2008-04-14 01:11:54 87552 ( A.... ) "C:\WINDOWS\system32\fldrc lnr.dll"
2008-04-14 01:11:54 81920 ( A.... ) "C:\WINDOWS\system32\ils.d ll"
2008-04-14 01:11:54 81920 ( A.... ) "C:\WINDOWS\system32\ieenc ode.dll"
2008-04-14 01:11:54 80896 ( A.... ) "C:\WINDOWS\system32\fonts ub.dll"
2008-04-14 01:11:54 80384 ( A.... ) "C:\WINDOWS\system32\iccvi d.dll"
2008-04-14 01:11:54 80384 ( A.... ) "C:\WINDOWS\system32\fault rep.dll"
2008-04-14 01:11:54 73728 ( A.... ) "C:\WINDOWS\system32\icwdi al.dll"
2008-04-14 01:11:54 73728 ( A.... ) "C:\WINDOWS\system32\fdepl oy.dll"
2008-04-14 01:11:54 72704 ( A.... ) "C:\WINDOWS\system32\hlink .dll"
2008-04-14 01:11:54 68608 ( A.... ) "C:\WINDOWS\system32\iisex t.dll"
2008-04-14 01:11:54 65536 ( A.... ) "C:\WINDOWS\system32\icwph bk.dll"
2008-04-14 01:11:54 64512 ( A.... ) "C:\WINDOWS\system32\iisma p.dll"
2008-04-14 01:11:54 60416 ( A.... ) "C:\WINDOWS\system32\fwcfg .dll"
2008-04-14 01:11:54 56320 ( A.... ) "C:\WINDOWS\system32\event log.dll"
2008-04-14 01:11:54 41984 ( A.... ) "C:\WINDOWS\system32\htui. dll"
2008-04-14 01:11:54 41472 ( A.... ) "C:\WINDOWS\system32\hhset up.dll"
2008-04-14 01:11:54 36921 ( A.... ) "C:\WINDOWS\system32\imesh are.dll"
2008-04-14 01:11:54 32285 ( A.... ) "C:\WINDOWS\system32\hsfci sp2.dll"
2008-04-14 01:11:54 24576 ( A.... ) "C:\WINDOWS\system32\httpa pi.dll"
2008-04-14 01:11:54 23040 ( A.... ) "C:\WINDOWS\system32\ersvc .dll"
2008-04-14 01:11:54 21504 ( A.... ) "C:\WINDOWS\system32\hidse rv.dll"
2008-04-14 01:11:54 21504 ( A.... ) "C:\WINDOWS\system32\fecli ent.dll"
2008-04-14 01:11:54 20992 ( A.... ) "C:\WINDOWS\system32\hid.d ll"
2008-04-14 01:11:54 20480 ( A.... ) "C:\WINDOWS\system32\encap i.dll"
2008-04-14 01:11:54 16896 ( A.... ) "C:\WINDOWS\system32\fltli b.dll"
2008-04-14 01:11:54 14336 ( A.... ) "C:\WINDOWS\system32\exstr ace.dll"
2008-04-14 01:11:54 11264 ( A.... ) "C:\WINDOWS\system32\icaap i.dll"
2008-04-14 01:11:54 8192 ( A.... ) "C:\WINDOWS\system32\igmpa gnt.dll"
2008-04-14 01:11:54 7168 ( A.... ) "C:\WINDOWS\system32\hccoi n.dll"
2008-04-14 01:11:52 2113536 ( A.... ) "C:\WINDOWS\system32\dxdia gn.dll"
2008-04-14 01:11:52 1689088 ( A.... ) "C:\WINDOWS\system32\d3d9. dll"
2008-04-14 01:11:52 1504256 ( A.... ) "C:\WINDOWS\system32\diskc opy.dll"
2008-04-14 01:11:52 1293824 ( A.... ) "C:\WINDOWS\system32\dsoun d3d.dll"
2008-04-14 01:11:52 1267200 ( A.... ) "C:\WINDOWS\system32\comsv cs.dll"
2008-04-14 01:11:52 1227264 ( A.... ) "C:\WINDOWS\system32\dx8vb .dll"
2008-04-14 01:11:52 1179648 ( A.... ) "C:\WINDOWS\system32\d3d8. dll"
2008-04-14 01:11:52 1054208 ( A.... ) "C:\WINDOWS\system32\danim .dll"
2008-04-14 01:11:52 824320 ( A.... ) "C:\WINDOWS\system32\d3dim 700.dll"
2008-04-14 01:11:52 792064 ( A.... ) "C:\WINDOWS\system32\comre s.dll"
2008-04-14 01:11:52 650752 ( A.... ) "C:\WINDOWS\system32\dot3u i.dll"
2008-04-14 01:11:52 640000 ( A.... ) "C:\WINDOWS\system32\dbghe lp.dll"
2008-04-14 01:11:52 619008 ( A.... ) "C:\WINDOWS\system32\dx7vb .dll"
2008-04-14 01:11:52 617472 ( A.... ) "C:\WINDOWS\system32\comct l32.dll"
2008-04-14 01:11:52 599040 ( A.... ) "C:\WINDOWS\system32\crypt 32.dll"
2008-04-14 01:11:52 539648 ( A.... ) "C:\WINDOWS\system32\comui d.dll"
2008-04-14 01:11:52 512512 ( A.... ) "C:\WINDOWS\system32\crypt ui.dll"
2008-04-14 01:11:52 498742 ( A.... ) "C:\WINDOWS\system32\dxmas f.dll"
2008-04-14 01:11:52 379904 ( A.... ) "C:\WINDOWS\system32\dhcpm on.dll"
2008-04-14 01:11:52 375296 ( A.... ) "C:\WINDOWS\system32\dpnet .dll"
2008-04-14 01:11:52 367616 ( A.... ) "C:\WINDOWS\system32\dsoun d.dll"
2008-04-14 01:11:52 357888 ( A.... ) "C:\WINDOWS\system32\confm sp.dll"
2008-04-14 01:11:52 326656 ( A.... ) "C:\WINDOWS\system32\cscui .dll"
2008-04-14 01:11:52 304128 ( A.... ) "C:\WINDOWS\system32\duser .dll"
2008-04-14 01:11:52 285184 ( A.... ) "C:\WINDOWS\system32\dmdlg s.dll"
2008-04-14 01:11:52 282624 ( A.... ) "C:\WINDOWS\system32\devmg r.dll"
2008-04-14 01:11:52 279552 ( A.... ) "C:\WINDOWS\system32\ddraw .dll"
2008-04-14 01:11:52 276992 ( A.... ) "C:\WINDOWS\system32\comdl g32.dll"
2008-04-14 01:11:52 252928 ( A.... ) "C:\WINDOWS\system32\compa tui.dll"
2008-04-14 01:11:52 239104 ( A.... ) "C:\WINDOWS\system32\dsque ry.dll"
2008-04-14 01:11:52 229888 ( A.... ) "C:\WINDOWS\system32\dplay x.dll"
2008-04-14 01:11:52 229376 ( A.... ) "C:\WINDOWS\system32\comps tui.dll"
2008-04-14 01:11:52 212480 ( A.... ) "C:\WINDOWS\system32\dpvoi ce.dll"
2008-04-14 01:11:52 200704 ( A.... ) "C:\WINDOWS\system32\dmdsk mgr.dll"
2008-04-14 01:11:52 184832 ( A.... ) "C:\WINDOWS\system32\eapp3 hst.dll"
2008-04-14 01:11:52 181760 ( A.... ) "C:\WINDOWS\system32\dinpu t8.dll"
2008-04-14 01:11:52 181248 ( A.... ) "C:\WINDOWS\system32\dsdmo .dll"
2008-04-14 01:11:52 181248 ( A.... ) "C:\WINDOWS\system32\dmime .dll"
2008-04-14 01:11:52 180224 ( A.... ) "C:\WINDOWS\system32\eapph ost.dll"
2008-04-14 01:11:52 167424 ( A.... ) "C:\WINDOWS\system32\comsn ap.dll"
2008-04-14 01:11:52 165376 ( A.... ) "C:\WINDOWS\system32\datim e.dll"
2008-04-14 01:11:52 163840 ( A.... ) "C:\WINDOWS\system32\credu i.dll"
2008-04-14 01:11:52 158720 ( A.... ) "C:\WINDOWS\system32\dinpu t.dll"
2008-04-14 01:11:52 155648 ( A.... ) "C:\WINDOWS\system32\dskqu oui.dll"
2008-04-14 01:11:52 147968 ( A.... ) "C:\WINDOWS\system32\dnsap i.dll"
2008-04-14 01:11:52 142848 ( A.... ) "C:\WINDOWS\system32\dspro p.dll"
2008-04-14 01:11:52 132096 ( A.... ) "C:\WINDOWS\system32\dot3s vc.dll"
2008-04-14 01:11:52 126976 ( A.... ) "C:\WINDOWS\system32\eappc fg.dll"
2008-04-14 01:11:52 126976 ( A.... ) "C:\WINDOWS\system32\dhcpc svc.dll"
2008-04-14 01:11:52 124416 ( A.... ) "C:\WINDOWS\system32\dfrgu i.dll"
2008-04-14 01:11:52 116736 ( A.... ) "C:\WINDOWS\system32\dpvvo x.dll"
2008-04-14 01:11:52 113152 ( A.... ) "C:\WINDOWS\system32\dsuie xt.dll"
2008-04-14 01:11:52 111104 ( A.... ) "C:\WINDOWS\system32\dgnet .dll"
2008-04-14 01:11:52 110592 ( A.... ) "C:\WINDOWS\system32\dbnet lib.dll"
2008-04-14 01:11:52 105984 ( A.... ) "C:\WINDOWS\system32\dmsty le.dll"
2008-04-14 01:11:52 104448 ( A.... ) "C:\WINDOWS\system32\dmusi c.dll"
2008-04-14 01:11:52 103424 ( A.... ) "C:\WINDOWS\system32\dmsyn th.dll"
2008-04-14 01:11:52 102912 ( A.... ) "C:\WINDOWS\system32\dpcdl l.dll"
2008-04-14 01:11:52 101888 ( A.... ) "C:\WINDOWS\system32\cscdl l.dll"
2008-04-14 01:11:52 97792 ( A.... ) "C:\WINDOWS\system32\comre pl.dll"
2008-04-14 01:11:52 94208 ( A.... ) "C:\WINDOWS\system32\eappg nui.dll"
2008-04-14 01:11:52 92672 ( A.... ) "C:\WINDOWS\system32\dskqu ota.dll"
2008-04-14 01:11:52 82432 ( A.... ) "C:\WINDOWS\system32\dmscr ipt.dll"
2008-04-14 01:11:52 74752 ( A.... ) "C:\WINDOWS\system32\crypt dlg.dll"
2008-04-14 01:11:52 71680 ( A.... ) "C:\WINDOWS\system32\dsdmo prp.dll"
2008-04-14 01:11:52 68608 ( A.... ) "C:\WINDOWS\system32\diges t.dll"
2008-04-14 01:11:52 64512 ( A.... ) "C:\WINDOWS\system32\crypt net.dll"
2008-04-14 01:11:52 62464 ( A.... ) "C:\WINDOWS\system32\crypt svc.dll"
2008-04-14 01:11:52 61440 ( A.... ) "C:\WINDOWS\system32\dmcom pos.dll"
2008-04-14 01:11:52 60928 ( A.... ) "C:\WINDOWS\system32\dpnhu pnp.dll"
2008-04-14 01:11:52 60416 ( A.... ) "C:\WINDOWS\system32\colba ct.dll"
2008-04-14 01:11:52 59904 ( A.... ) "C:\WINDOWS\system32\deven um.dll"
2008-04-14 01:11:52 59392 ( A.... ) "C:\WINDOWS\system32\eapqe c.dll"
2008-04-14 01:11:52 57856 ( A.... ) "C:\WINDOWS\system32\dot3c fg.dll"
2008-04-14 01:11:52 57344 ( A.... ) "C:\WINDOWS\system32\dpwso ckx.dll"
2008-04-14 01:11:52 56320 ( A.... ) "C:\WINDOWS\system32\dot3m sm.dll"
2008-04-14 01:11:52 54272 ( A.... ) "C:\WINDOWS\system32\datac len.dll"
2008-04-14 01:11:52 53760 ( A.... ) "C:\WINDOWS\system32\crypt ext.dll"
2008-04-14 01:11:52 52224 ( A.... ) "C:\WINDOWS\system32\dmuti l.dll"
2008-04-14 01:11:52 51200 ( A.... ) "C:\WINDOWS\system32\dssec .dll"
2008-04-14 01:11:52 48640 ( A.... ) "C:\WINDOWS\system32\dhcpq ec.dll"
2008-04-14 01:11:52 48128 ( A.... ) "C:\WINDOWS\system32\docpr op2.dll"
2008-04-14 01:11:52 45568 ( A.... ) "C:\WINDOWS\system32\dnsrs lvr.dll"
2008-04-14 01:11:52 40960 ( A.... ) "C:\WINDOWS\system32\eappp rxy.dll"
2008-04-14 01:11:52 39936 ( A.... ) "C:\WINDOWS\system32\dot3g pclnt.dll"
2008-04-14 01:11:52 39936 ( A.... ) "C:\WINDOWS\system32\dimsr oam.dll"
2008-04-14 01:11:52 39424 ( A.... ) "C:\WINDOWS\system32\dfrgs nap.dll"
2008-04-14 01:11:52 35840 ( A.... ) "C:\WINDOWS\system32\dmloa der.dll"
2008-04-14 01:11:52 35328 ( A.... ) "C:\WINDOWS\system32\dpnhp ast.dll"
2008-04-14 01:11:52 35328 ( ..... ) "C:\WINDOWS\system32\corpo l.dll"
2008-04-14 01:11:52 33792 ( A.... ) "C:\WINDOWS\system32\eapsv c.dll"
2008-04-14 01:11:52 33280 ( A.... ) "C:\WINDOWS\system32\crypt dll.dll"
2008-04-14 01:11:52 32768 ( A.... ) "C:\WINDOWS\system32\dispe x.dll"
2008-04-14 01:11:52 32256 ( A.... ) "C:\WINDOWS\system32\csrsr v.dll"
2008-04-14 01:11:52 30720 ( A.... ) "C:\WINDOWS\system32\eapol qec.dll"
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dmban d.dll"
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dfssh lex.dll"
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dbnmp ntw.dll"
2008-04-14 01:11:52 28160 ( A.... ) "C:\WINDOWS\system32\comad din.dll"
2008-04-14 01:11:52 27136 ( A.... ) "C:\WINDOWS\system32\ddraw ex.dll"
2008-04-14 01:11:52 26624 ( A.... ) "C:\WINDOWS\system32\efsad u.dll"
2008-04-14 01:11:52 26112 ( A.... ) "C:\WINDOWS\system32\dot3a pi.dll"
2008-04-14 01:11:52 25088 ( A.... ) "C:\WINDOWS\system32\davcl nt.dll"
2008-04-14 01:11:52 24576 ( A.... ) "C:\WINDOWS\system32\dbmsr pcn.dll"
2008-04-14 01:11:52 23552 ( A.... ) "C:\WINDOWS\system32\dpmod emx.dll"
2008-04-14 01:11:52 23552 ( A.... ) "C:\WINDOWS\system32\dmser ver.dll"
2008-04-14 01:11:52 21504 ( A.... ) "C:\WINDOWS\system32\dpvac m.dll"
2008-04-14 01:11:52 19456 ( A.... ) "C:\WINDOWS\system32\dswav e.dll"
2008-04-14 01:11:52 19456 ( A.... ) "C:\WINDOWS\system32\dimsn tfy.dll"
2008-04-14 01:11:52 16384 ( A.... ) "C:\WINDOWS\system32\ds32g t.dll"
2008-04-14 01:11:52 14336 ( A.... ) "C:\WINDOWS\system32\drpro v.dll"
2008-04-14 01:11:52 12800 ( A.... ) "C:\WINDOWS\system32\creds sp.dll"
2008-04-14 01:11:52 9216 ( A.... ) "C:\WINDOWS\system32\dot3d lg.dll"
2008-04-14 01:11:52 8704 ( A.... ) "C:\WINDOWS\system32\dcima n32.dll"
2008-04-14 01:11:52 8192 ( A.... ) "C:\WINDOWS\system32\d3d8t hk.dll"
2008-04-14 01:11:50 2091520 ( A.... ) "C:\WINDOWS\system32\cdosy s.dll"
2008-04-14 01:11:50 1888992 ( A.... ) "C:\WINDOWS\system32\ati3d uag.dll"
2008-04-14 01:11:50 1025024 ( A.... ) "C:\WINDOWS\system32\brows eui.dll"
2008-04-14 01:11:50 870784 ( A.... ) "C:\WINDOWS\system32\ati3d 1ag.dll"
2008-04-14 01:11:50 625664 ( A.... ) "C:\WINDOWS\system32\catsr vut.dll"
2008-04-14 01:11:50 516768 ( A.... ) "C:\WINDOWS\system32\ativv axx.dll"
2008-04-14 01:11:50 498688 ( A.... ) "C:\WINDOWS\system32\clbca tq.dll"
2008-04-14 01:11:50 457728 ( A.... ) "C:\WINDOWS\system32\certm gr.dll"
2008-04-14 01:11:50 377984 ( A.... ) "C:\WINDOWS\system32\ati2d vaa.dll"
2008-04-14 01:11:50 344064 ( A.... ) "C:\WINDOWS\system32\cmdia l32.dll"
2008-04-14 01:11:50 295936 ( A.... ) "C:\WINDOWS\system32\appmg r.dll"
2008-04-14 01:11:50 233472 ( A.... ) "C:\WINDOWS\system32\azrol es.dll"
2008-04-14 01:11:50 229376 ( A.... ) "C:\WINDOWS\system32\ati2c qag.dll"
2008-04-14 01:11:50 226304 ( A.... ) "C:\WINDOWS\system32\catsr v.dll"
2008-04-14 01:11:50 201728 ( A.... ) "C:\WINDOWS\system32\ati2d vag.dll"
2008-04-14 01:11:50 194560 ( A.... ) "C:\WINDOWS\system32\certc li.dll"
2008-04-14 01:11:50 185344 ( A.... ) "C:\WINDOWS\system32\cmpro ps.dll"
2008-04-14 01:11:50 167936 ( A.... ) "C:\WINDOWS\system32\appmg mts.dll"
2008-04-14 01:11:50 151040 ( A.... ) "C:\WINDOWS\system32\cdfvi ew.dll"
2008-04-14 01:11:50 150016 ( A.... ) "C:\WINDOWS\system32\capes npn.dll"
2008-04-14 01:11:50 148480 ( A.... ) "C:\WINDOWS\system32\cic.d ll"
2008-04-14 01:11:50 125952 ( A.... ) "C:\WINDOWS\system32\apphe lp.dll"
2008-04-14 01:11:50 110592 ( A.... ) "C:\WINDOWS\system32\clbca tex.dll"
2008-04-14 01:11:50 85504 ( A.... ) "C:\WINDOWS\system32\catsr vps.dll"
2008-04-14 01:11:50 84992 ( A.... ) "C:\WINDOWS\system32\avifi l32.dll"
2008-04-14 01:11:50 84480 ( A.... ) "C:\WINDOWS\system32\cabvi ew.dll"
2008-04-14 01:11:50 78336 ( A.... ) "C:\WINDOWS\system32\brows ewm.dll"
2008-04-14 01:11:50 77824 ( A.... ) "C:\WINDOWS\system32\clico nfg.dll"
2008-04-14 01:11:50 77824 ( A.... ) "C:\WINDOWS\system32\brows er.dll"
2008-04-14 01:11:50 70656 ( A.... ) "C:\WINDOWS\system32\amstr eam.dll"
2008-04-14 01:11:50 69120 ( A.... ) "C:\WINDOWS\system32\ciodm .dll"
2008-04-14 01:11:50 65024 ( A.... ) "C:\WINDOWS\system32\asycf ilt.dll"
2008-04-14 01:11:50 62464 ( A.... ) "C:\WINDOWS\system32\authz .dll"
2008-04-14 01:11:50 60416 ( A.... ) "C:\WINDOWS\system32\cabin et.dll"
2008-04-14 01:11:50 58880 ( A.... ) "C:\WINDOWS\system32\atl.d ll"
2008-04-14 01:11:50 58368 ( A.... ) "C:\WINDOWS\system32\clusa pi.dll"
2008-04-14 01:11:50 52736 ( A.... ) "C:\WINDOWS\system32\bases rv.dll"
2008-04-14 01:11:50 50688 ( A.... ) "C:\WINDOWS\system32\camoc x.dll"
2008-04-14 01:11:50 50688 ( A.... ) "C:\WINDOWS\system32\btpan ui.dll"
2008-04-14 01:11:50 47104 ( A.... ) "C:\WINDOWS\system32\cnbjm on.dll"
2008-04-14 01:11:50 42496 ( A.... ) "C:\WINDOWS\system32\audio srv.dll"
2008-04-14 01:11:50 39424 ( A.... ) "C:\WINDOWS\system32\cmuti l.dll"
2008-04-14 01:11:50 38912 ( A.... ) "C:\WINDOWS\system32\cfgbk end.dll"
2008-04-14 01:11:50 32768 ( A.... ) "C:\WINDOWS\system32\ativt mxx.dll"
2008-04-14 01:11:50 30208 ( A.... ) "C:\WINDOWS\system32\bthse rv.dll"
2008-04-14 01:11:50 30208 ( A.... ) "C:\WINDOWS\system32\atmli b.dll"
2008-04-14 01:11:50 29184 ( A.... ) "C:\WINDOWS\system32\batme ter.dll"
2008-04-14 01:11:50 20992 ( A.... ) "C:\WINDOWS\system32\bthci .dll"
2008-04-14 01:11:50 17408 ( A.... ) "C:\WINDOWS\system32\bidis pl.dll"
2008-04-14 01:11:50 17408 ( A.... ) "C:\WINDOWS\system32\alrsv c.dll"
2008-04-14 01:11:50 15872 ( A.... ) "C:\WINDOWS\system32\cmcfg 32.dll"
2008-04-14 01:11:50 13312 ( A.... ) "C:\WINDOWS\system32\cmset acl.dll"
2008-04-14 01:11:50 8704 ( A.... ) "C:\WINDOWS\system32\batt. dll"
2008-04-14 01:11:50 8192 ( A.... ) "C:\WINDOWS\system32\bitsp rx2.dll"
2008-04-14 01:11:50 7168 ( A.... ) "C:\WINDOWS\system32\bitsp rx4.dll"
2008-04-14 01:11:50 7168 ( A.... ) "C:\WINDOWS\system32\bitsp rx3.dll"
2008-04-14 01:11:48 617472 ( A.... ) "C:\WINDOWS\system32\advap i32.dll"
2008-04-14 01:11:48 290816 ( A.... ) "C:\WINDOWS\system32\adsii s.dll"
2008-04-14 01:11:48 263680 ( A.... ) "C:\WINDOWS\system32\adsnt .dll"
2008-04-14 01:11:48 193536 ( A.... ) "C:\WINDOWS\system32\activ eds.dll"
2008-04-14 01:11:48 175616 ( A.... ) "C:\WINDOWS\system32\adsld p.dll"
2008-04-14 01:11:48 143360 ( A.... ) "C:\WINDOWS\system32\adsld pc.dll"
2008-04-14 01:11:48 136192 ( A.... ) "C:\WINDOWS\system32\aacli ent.dll"
2008-04-14 01:11:48 123392 ( A.... ) "C:\WINDOWS\system32\adsnw .dll"
2008-04-14 01:11:48 115712 ( A.... ) "C:\WINDOWS\system32\aclui .dll"
2008-04-14 01:11:48 100352 ( A.... ) "C:\WINDOWS\system32\6to4s vc.dll"
2008-04-14 01:11:48 98304 ( A.... ) "C:\WINDOWS\system32\actxp rxy.dll"
2008-04-14 01:11:48 68096 ( A.... ) "C:\WINDOWS\system32\adsms ext.dll"
2008-04-14 01:11:48 43520 ( A.... ) "C:\WINDOWS\system32\admwp rox.dll"
2008-04-14 01:11:24 706048 ( A.... ) "C:\WINDOWS\system32\ntdll .dll"
2008-04-14 01:11:16 5632 ( A.... ) "C:\WINDOWS\system32\wmi.d ll"
2008-04-14 01:11:12 756224 ( A.... ) "C:\WINDOWS\system32\winnt bbu.dll"
2008-04-14 01:11:10 24064 ( A.... ) "C:\WINDOWS\system32\pidge n.dll"
2008-04-14 01:10:32 53279 ( A.... ) "C:\WINDOWS\system32\odbcj i32.dll"
2008-04-14 01:10:08 4126 ( A.... ) "C:\WINDOWS\system32\msdxm lc.dll"
2008-04-14 01:10:06 3584 ( A.... ) "C:\WINDOWS\system32\msafd .dll"
2008-04-14 01:09:56 7680 ( A.... ) "C:\WINDOWS\system32\kbdsm sno.dll"
2008-04-14 01:09:56 7680 ( A.... ) "C:\WINDOWS\system32\kbdsm sfi.dll"
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbduk x.dll"
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdno 1.dll"
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdne c.dll"
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdfi 1.dll"
2008-04-14 01:09:56 6656 ( A.... ) "C:\WINDOWS\system32\kbdin mal.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdpa sh.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdne pr.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdml t48.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdml t47.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdiu ltn.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdin ben.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdin be1.dll"
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdbh c.dll"
2008-04-14 01:09:56 5632 ( A.... ) "C:\WINDOWS\system32\kbdma ori.dll"
2008-04-14 01:09:40 3584 ( A.... ) "C:\WINDOWS\system32\icmp. dll"
2008-04-14 01:09:36 566784 ( A.... ) "C:\WINDOWS\system32\gpedi t.dll"
2008-04-14 01:09:34 9344 ( A.... ) "C:\WINDOWS\system32\frame buf.dll"
2008-04-14 01:09:20 3072 ( A.... ) "C:\WINDOWS\system32\dpnlo bby.dll"
2008-04-14 01:09:20 3072 ( A.... ) "C:\WINDOWS\system32\dpnad dr.dll"
2008-04-14 01:09:06 16896 ( A.... ) "C:\WINDOWS\system32\cfgmg r32.dll"
2008-04-14 01:09:02 285696 ( A.... ) "C:\WINDOWS\system32\atmfd .dll"
2008-04-13 20:30:10 1845632 ( A.... ) "C:\WINDOWS\system32\win32 k.sys"
2008-04-13 20:24:38 2145280 ( A.... ) "C:\WINDOWS\system32\ntosk rnl.exe"
2008-04-13 19:45:00 17664 ( A.... ) "C:\WINDOWS\system32\watch dog.sys"
2008-04-13 19:43:32 12800 ( A.... ) "C:\WINDOWS\system32\spiis upd.exe"
2008-04-13 19:43:32 9728 ( A.... ) "C:\WINDOWS\system32\comsd upd.exe"
2008-04-13 19:31:36 7424 ( A.... ) "C:\WINDOWS\system32\kd139 4.dll"
2008-04-13 19:31:28 134400 ( A.... ) "C:\WINDOWS\system32\HAL.D LL"
2008-04-13 19:31:22 2023936 ( A.... ) "C:\WINDOWS\system32\ntkrn lpa.exe"
2008-04-13 19:30:46 61440 ( A.... ) "C:\WINDOWS\system32\Msvcr t40.dll"
2008-04-13 19:14:58 76800 ( A.... ) "C:\WINDOWS\system32\mssha vmsg.dll"
2008-04-13 18:39:30 438784 ( A.... ) "C:\WINDOWS\system32\xpob2 res.dll"
2008-04-13 18:39:26 689152 ( A.... ) "C:\WINDOWS\system32\xpsp3 res.dll"
2008-04-13 18:39:24 2897920 ( A.... ) "C:\WINDOWS\system32\xpsp2 res.dll"
2008-04-13 18:39:22 187392 ( A.... ) "C:\WINDOWS\system32\xpsp1 res.dll"
2008-04-13 18:37:58 208384 ( A.... ) "C:\WINDOWS\system32\rsaen h.dll"
2008-04-13 18:37:58 138752 ( A.... ) "C:\WINDOWS\system32\dssen h.dll"
2008-04-13 18:27:18 79872 ( A.... ) "C:\WINDOWS\system32\msxml 6r.dll"
2008-04-13 18:26:08 12288 ( A.... ) "C:\WINDOWS\system32\mscpx 32r.dll"
2008-04-13 18:26:06 94208 ( A.... ) "C:\WINDOWS\system32\odbci nt.dll"
2008-04-13 18:26:06 12288 ( A.... ) "C:\WINDOWS\system32\odbcp 32r.dll"
2008-04-13 18:24:14 20480 ( A.... ) "C:\WINDOWS\system32\msorc 32r.dll"
2008-04-13 18:21:32 733696 ( A.... ) "C:\WINDOWS\system32\qedwi pes.dll"
2008-04-13 18:09:30 4096 ( A.... ) "C:\WINDOWS\system32\dsprp res.dll"
2008-04-13 18:03:24 63488 ( A.... ) "C:\WINDOWS\system32\brows elc.dll"
2008-04-13 18:03:20 549376 ( A.... ) "C:\WINDOWS\system32\shdoc lc.dll"
2008-04-13 17:48:54 1647616 ( A.... ) "C:\WINDOWS\system32\winbr and.dll"
2008-04-13 17:45:30 216064 ( A.... ) "C:\WINDOWS\system32\moric ons.dll"
2008-04-13 17:23:32 48128 ( A.... ) "C:\WINDOWS\system32\mspri vs.dll"
2008-04-13 17:22:12 48128 ( A.... ) "C:\WINDOWS\system32\inetr es.dll"
2008-04-13 16:39:44 884736 ( A.... ) "C:\WINDOWS\system32\msims g.dll"
(((((((((((((((((((((((((( (((((((((( ((((((((( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) )))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\run]
"IgfxTray"="C:\\WINDOWS\\s ystem32\\i gfxtray.ex e"
"HotKeysCmds"="C:\\WINDOWS \\system32 \\hkcmd.ex e"
"Persistence"="C:\\WINDOWS \\system32 \\igfxpers .exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.ex e"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.e xe\" /tray"
"SetRefresh"="C:\\Program Files\\Compaq\\SetRefresh\ \SetRefres h.exe"
"Recguard"="C:\\WINDOWS\\S minst\\Rec guard.exe"
"Reminder"="C:\\WINDOWS\\C reator\\Re mind_XP.ex e"
"Scheduler"="C:\\WINDOWS\\ SMINST\\Sc heduler.ex e"
"ShStatEXE"="\"C:\\Program Files\\McAfee\\VirusScan Enterprise\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\P rogram Files\\McAfee\\Common Framework\\UdaterUI.exe\" /StartedFromRunKey"
"Adobe Reader Speed Launcher"="\"D:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe \""
"QuickTime Task"="\"D:\\Program Files\\QuickTime\\qttask.e xe\" -atboottime"
"iTunesHelper"="\"C:\\Prog ram Files\\iTunes\\iTunesHelpe r.exe\""
"HP Software Update"="D:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"Norton Ghost 14.0"="\"D:\\Program Files\\Norton Ghost\\Agent\\VProTray.exe \""
"4d2468f1"="rundll32.exe \"C:\\WINDOWS\\system32\\m ihjbqcn.dl l\",b"
"BM4e175b6d"="Rundll32.exe \"C:\\WINDOWS\\system32\\h hwwjirm.dl l\",s"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\run\ OptionalCo mponents]
@=""
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\run\ OptionalCo mponents\I MAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\run\ OptionalCo mponents\M API]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\run\ OptionalCo mponents\M SFS]
"Installed"="1"
@=""
[HKEY_CURRENT_USER\softwar e\microsof t\windows\ currentver sion\run]
"ctfmon.exe"="C:\\WINDOWS\ \system32\ \ctfmon.ex e"
[HKEY_USERS\.default\softw are\micros oft\window s\currentv ersion\run ]
"CTFMON.EXE"="C:\\WINDOWS\ \system32\ \CTFMON.EX E"
"Spyware Doctor"="\"d:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\.default\softw are\micros oft\window s\currentv ersion\pol icies\expl orer]
"NoDriveTypeAutoRun"=dword :00000091
[HKEY_USERS\s-1-5-18\softw are\micros oft\window s\currentv ersion\run ]
"CTFMON.EXE"="C:\\WINDOWS\ \system32\ \CTFMON.EX E"
"Spyware Doctor"="\"d:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\softw are\micros oft\window s\currentv ersion\pol icies\expl orer]
"NoDriveTypeAutoRun"=dword :00000091
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\expl orer\share dtasksched uler]
"{438755C2-A8BA-11D1-B96B- 00A0C90312 E1}"="Brow seui preloader"
"{8C7461EF-2B13-11d2-BE35- 3078302C20 30}"="Comp onent Categories cache daemon"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\expl orer\shell executehoo ks]
"{AEB6717E-7E19-11d0-97EE- 00C04FD919 72}"=""
"{56F9679E-7826-4C84-81F3- 532071A8BC C5}"=""
"{427B37EF-B6C5-4823-A97C- 10B88977E3 98}"=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoft wareUpdate .job
Completion time: 03/07/2008 12:16:38.67
ComboFix ver 06.06.17 - This logfile is located at C:\ComboFix.txt
After running vundofix and such i can no longer locate any vundo related trojans, possibly some other problems?? Anyway i have the log files from combofix and hijackthis. Combofix log first.
Start Time= 03/07/2008 12:16:09.79
QuickScan did not find any signs of infected files
((((((((((((((((((((((((((
2008-07-03 11:45:18 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Apple Computer"
2008-07-03 10:25:28 ( .D... ) "C:\Documents and Settings\woyt\Application Data\PC Tools"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Macromedia"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\HPAppData"
2008-07-03 10:25:26 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Adobe"
2008-07-03 10:09:56 ( .DS.. ) "C:\Documents and Settings\woyt\Application Data\Microsoft"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Sun"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\SampleView"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\InstallShield"
2008-07-03 10:09:56 ( .D... ) "C:\Documents and Settings\woyt\Application Data\Identities"
2008-07-02 10:58:02 102912 ( A.... ) "C:\WINDOWS\system32\retkf
2008-07-02 10:58:02 102912 ( A.... ) "C:\WINDOWS\system32\cerhe
2008-07-02 10:55:02 82432 ( A.... ) "C:\WINDOWS\system32\mihjb
2008-07-02 10:52:02 90112 ( A.... ) "C:\WINDOWS\system32\hhwwj
2008-07-01 16:26:54 ( .D... ) "C:\Program Files\Common Files\Wise Installation Wizard"
2008-07-01 13:31:16 103424 ( A.... ) "C:\WINDOWS\system32\mjdpw
2008-07-01 13:31:16 103424 ( A.... ) "C:\WINDOWS\system32\jexqu
2008-07-01 13:22:16 90624 ( A.... ) "C:\WINDOWS\system32\nsrbr
2008-07-01 12:05:44 103424 ( A.... ) "C:\WINDOWS\system32\pwxeg
2008-07-01 12:05:44 103424 ( A.... ) "C:\WINDOWS\system32\gvref
2008-07-01 12:05:30 90624 ( A.... ) "C:\WINDOWS\system32\yfnek
2008-06-30 14:17:12 81920 ( A.... ) "C:\WINDOWS\system32\cdifg
2008-06-30 14:12:48 25088 ( A.... ) "C:\WINDOWS\system32\vtUoP
2008-06-30 14:12:00 25088 ( A.... ) "C:\WINDOWS\system32\yayYP
2008-06-30 14:11:44 33280 ( A.... ) "C:\WINDOWS\system32\winpp
2008-06-30 14:11:42 25088 ( A.... ) "C:\WINDOWS\system32\qoMfG
2008-06-30 14:11:34 33280 ( A.... ) "C:\WINDOWS\system32\winmb
2008-06-30 14:11:32 25088 ( A.... ) "C:\WINDOWS\system32\awtSK
2008-06-30 14:11:22 25088 ( A.... ) "C:\WINDOWS\system32\cbXrS
2008-06-30 14:11:08 25088 ( A.... ) "C:\WINDOWS\system32\nnnlI
2008-05-30 00:35:12 17486968 ( A.... ) "C:\WINDOWS\system32\MRT.e
2008-05-29 09:56:40 ( .D... ) "C:\Program Files\Microsoft CAPICOM 2.1.0.2"
2008-05-28 15:22:14 ( .D... ) "C:\Program Files\Common Files\HP"
2008-05-28 15:20:52 ( .D... ) "C:\Program Files\Common Files\Hewlett-Packard"
2008-05-28 15:17:42 ( .D... ) "C:\Program Files\HP"
2008-05-27 10:57:24 ( .D... ) "C:\Program Files\Your Company Name"
2008-05-16 11:58:04 12632 ( A.... ) "C:\WINDOWS\system32\lsdel
2008-05-08 16:43:44 ( .D... ) "C:\Program Files\Microsoft Silverlight"
2008-05-07 16:46:56 215144 ( A...R ) "C:\WINDOWS\pw32a.dll"
2008-05-07 16:46:56 215144 ( A...R ) "C:\WINDOWS\patchw32.dll"
2008-05-07 16:44:38 107368 ( A.... ) "C:\WINDOWS\system32\GEARA
2008-05-07 06:12:40 1288192 ( A.... ) "C:\WINDOWS\system32\quart
2008-04-23 22:16:30 3591680 ( A.... ) "C:\WINDOWS\system32\mshtm
2008-04-23 05:16:30 1159680 ( A.... ) "C:\WINDOWS\system32\urlmo
2008-04-23 05:16:30 826368 ( A.... ) "C:\WINDOWS\system32\winin
2008-04-23 05:16:30 233472 ( A.... ) "C:\WINDOWS\system32\webch
2008-04-23 05:16:28 6066176 ( A.... ) "C:\WINDOWS\system32\iefra
2008-04-23 05:16:28 671232 ( ..... ) "C:\WINDOWS\system32\mstim
2008-04-23 05:16:28 478208 ( A.... ) "C:\WINDOWS\system32\mshtm
2008-04-23 05:16:28 459264 ( A.... ) "C:\WINDOWS\system32\msfee
2008-04-23 05:16:28 384512 ( ..... ) "C:\WINDOWS\system32\iedkc
2008-04-23 05:16:28 383488 ( A.... ) "C:\WINDOWS\system32\ieapf
2008-04-23 05:16:28 347136 ( A.... ) "C:\WINDOWS\system32\dxtms
2008-04-23 05:16:28 267776 ( A.... ) "C:\WINDOWS\system32\iertu
2008-04-23 05:16:28 230400 ( ..... ) "C:\WINDOWS\system32\ieaks
2008-04-23 05:16:28 214528 ( A.... ) "C:\WINDOWS\system32\dxtra
2008-04-23 05:16:28 193024 ( ..... ) "C:\WINDOWS\system32\msrat
2008-04-23 05:16:28 153088 ( ..... ) "C:\WINDOWS\system32\ieake
2008-04-23 05:16:28 133120 ( ..... ) "C:\WINDOWS\system32\extmg
2008-04-23 05:16:28 124928 ( A.... ) "C:\WINDOWS\system32\advpa
2008-04-23 05:16:28 105984 ( A.... ) "C:\WINDOWS\system32\url.d
2008-04-23 05:16:28 102912 ( ..... ) "C:\WINDOWS\system32\occac
2008-04-23 05:16:28 63488 ( A.... ) "C:\WINDOWS\system32\icard
2008-04-23 05:16:28 52224 ( A.... ) "C:\WINDOWS\system32\msfee
2008-04-23 05:16:28 44544 ( A.... ) "C:\WINDOWS\system32\pngfi
2008-04-23 05:16:28 44544 ( ..... ) "C:\WINDOWS\system32\ierno
2008-04-23 05:16:28 27648 ( A.... ) "C:\WINDOWS\system32\jspro
2008-04-22 08:39:58 70656 ( A.... ) "C:\WINDOWS\system32\ie4ui
2008-04-22 08:39:58 13824 ( A.... ) "C:\WINDOWS\system32\ieudi
2008-04-20 06:07:52 161792 ( ..... ) "C:\WINDOWS\system32\ieaku
2008-04-17 10:56:44 83208 ( A.... ) "C:\WINDOWS\system32\S32EV
2008-04-14 05:42:38 11264 ( A.... ) "C:\WINDOWS\system32\spnpi
2008-04-14 05:42:06 985088 ( A.... ) "C:\WINDOWS\system32\setup
2008-04-14 05:41:58 423936 ( A.... ) "C:\WINDOWS\system32\licdl
2008-04-14 01:16:52 329728 ( A.... ) "C:\WINDOWS\system32\netse
2008-04-14 01:13:22 92424 ( A.... ) "C:\WINDOWS\system32\rdpdd
2008-04-14 01:13:22 87176 ( A.... ) "C:\WINDOWS\system32\rdpws
2008-04-14 01:13:22 12168 ( A.... ) "C:\WINDOWS\system32\tsddd
2008-04-14 01:12:44 704512 ( A.... ) "C:\WINDOWS\system32\ss3df
2008-04-14 01:12:44 679936 ( A.... ) "C:\WINDOWS\system32\sstex
2008-04-14 01:12:44 610304 ( A.... ) "C:\WINDOWS\system32\sspip
2008-04-14 01:12:44 393216 ( A.... ) "C:\WINDOWS\system32\ssflw
2008-04-14 01:12:44 220672 ( A.... ) "C:\WINDOWS\system32\logon
2008-04-14 01:12:44 47104 ( A.... ) "C:\WINDOWS\system32\ssmyp
2008-04-14 01:12:44 20992 ( A.... ) "C:\WINDOWS\system32\ssmar
2008-04-14 01:12:44 19968 ( A.... ) "C:\WINDOWS\system32\ssbez
2008-04-14 01:12:44 18944 ( A.... ) "C:\WINDOWS\system32\ssmys
2008-04-14 01:12:44 14336 ( A.... ) "C:\WINDOWS\system32\sssta
2008-04-14 01:12:44 9216 ( A.... ) "C:\WINDOWS\system32\scrns
2008-04-14 01:12:42 165888 ( A.... ) "C:\WINDOWS\system32\wuauc
2008-04-14 01:12:42 155648 ( A.... ) "C:\WINDOWS\system32\wscri
2008-04-14 01:12:42 30720 ( A.... ) "C:\WINDOWS\system32\xcopy
2008-04-14 01:12:42 29696 ( A.... ) "C:\WINDOWS\system32\forma
2008-04-14 01:12:42 16896 ( A.... ) "C:\WINDOWS\system32\more.
2008-04-14 01:12:42 13824 ( A.... ) "C:\WINDOWS\system32\wscnt
2008-04-14 01:12:42 12800 ( A.... ) "C:\WINDOWS\system32\tree.
2008-04-14 01:12:42 11264 ( A.... ) "C:\WINDOWS\system32\wpnpi
2008-04-14 01:12:40 507904 ( A.... ) "C:\WINDOWS\system32\winlo
2008-04-14 01:12:40 433664 ( A.... ) "C:\WINDOWS\system32\wiaac
2008-04-14 01:12:40 283648 ( A.... ) "C:\WINDOWS\winhlp32.exe"
2008-04-14 01:12:40 65024 ( A.... ) "C:\WINDOWS\system32\wextr
2008-04-14 01:12:40 32256 ( A.... ) "C:\WINDOWS\system32\wpaba
2008-04-14 01:12:40 5632 ( A.... ) "C:\WINDOWS\system32\winve
2008-04-14 01:12:38 347136 ( A.... ) "C:\WINDOWS\system32\tours
2008-04-14 01:12:38 289792 ( A.... ) "C:\WINDOWS\system32\vssvc
2008-04-14 01:12:38 259584 ( A.... ) "C:\WINDOWS\system32\trace
2008-04-14 01:12:38 135680 ( A.... ) "C:\WINDOWS\system32\taskm
2008-04-14 01:12:38 106496 ( A.... ) "C:\WINDOWS\system32\sysoc
2008-04-14 01:12:38 78336 ( A.... ) "C:\WINDOWS\system32\tlnts
2008-04-14 01:12:38 77824 ( A.... ) "C:\WINDOWS\system32\taskl
2008-04-14 01:12:38 76288 ( A.... ) "C:\WINDOWS\system32\taskk
2008-04-14 01:12:38 75776 ( A.... ) "C:\WINDOWS\system32\telne
2008-04-14 01:12:38 73216 ( A.... ) "C:\WINDOWS\system32\tlnts
2008-04-14 01:12:38 61440 ( A.... ) "C:\WINDOWS\system32\tlnta
2008-04-14 01:12:38 60416 ( A.... ) "C:\WINDOWS\system32\tzcha
2008-04-14 01:12:38 50176 ( A.... ) "C:\WINDOWS\system32\utilm
2008-04-14 01:12:38 28672 ( A.... ) "C:\WINDOWS\system32\vercl
2008-04-14 01:12:38 26112 ( A.... ) "C:\WINDOWS\system32\useri
2008-04-14 01:12:38 18432 ( A.... ) "C:\WINDOWS\system32\ups.e
2008-04-14 01:12:38 16896 ( A.... ) "C:\WINDOWS\system32\upnpc
2008-04-14 01:12:38 12288 ( A.... ) "C:\WINDOWS\system32\trace
2008-04-14 01:12:36 538624 ( A.... ) "C:\WINDOWS\system32\spide
2008-04-14 01:12:36 131584 ( A.... ) "C:\WINDOWS\system32\sndre
2008-04-14 01:12:36 89600 ( A.... ) "C:\WINDOWS\system32\smlog
2008-04-14 01:12:36 77824 ( A.... ) "C:\WINDOWS\system32\shrpu
2008-04-14 01:12:36 73796 ( A.... ) "C:\WINDOWS\system32\slser
2008-04-14 01:12:36 71680 ( A.... ) "C:\WINDOWS\system32\syste
2008-04-14 01:12:36 70144 ( A.... ) "C:\WINDOWS\system32\sigve
2008-04-14 01:12:36 57856 ( A.... ) "C:\WINDOWS\system32\spool
2008-04-14 01:12:36 50688 ( A.... ) "C:\WINDOWS\system32\smss.
2008-04-14 01:12:36 45056 ( A.... ) "C:\WINDOWS\system32\shmgr
2008-04-14 01:12:36 32866 ( A.... ) "C:\WINDOWS\system32\slrun
2008-04-14 01:12:36 32866 ( ..... ) "C:\WINDOWS\slrundll.exe"
2008-04-14 01:12:36 32768 ( A.... ) "C:\WINDOWS\system32\setup
2008-04-14 01:12:36 26112 ( A.... ) "C:\WINDOWS\system32\skeys
2008-04-14 01:12:36 24576 ( A.... ) "C:\WINDOWS\system32\sort.
2008-04-14 01:12:36 20992 ( A.... ) "C:\WINDOWS\system32\spupd
2008-04-14 01:12:36 19456 ( A.... ) "C:\WINDOWS\system32\shutd
2008-04-14 01:12:36 14848 ( A.... ) "C:\WINDOWS\system32\stimo
2008-04-14 01:12:36 14336 ( A.... ) "C:\WINDOWS\system32\svcho
2008-04-14 01:12:36 8192 ( A.... ) "C:\WINDOWS\system32\smbin
2008-04-14 01:12:36 7680 ( A.... ) "C:\WINDOWS\system32\spdwn
2008-04-14 01:12:34 141312 ( A.... ) "C:\WINDOWS\system32\sessm
2008-04-14 01:12:34 121856 ( A.... ) "C:\WINDOWS\system32\schta
2008-04-14 01:12:34 108544 ( A.... ) "C:\WINDOWS\system32\servi
2008-04-14 01:12:34 107520 ( A.... ) "C:\WINDOWS\system32\rsnot
2008-04-14 01:12:34 95744 ( A.... ) "C:\WINDOWS\system32\scard
2008-04-14 01:12:34 77312 ( A.... ) "C:\WINDOWS\system32\sdbin
2008-04-14 01:12:34 77312 ( A.... ) "C:\WINDOWS\system32\rtcsh
2008-04-14 01:12:34 33280 ( A.... ) "C:\WINDOWS\system32\rundl
2008-04-14 01:12:34 31232 ( A.... ) "C:\WINDOWS\system32\sethc
2008-04-14 01:12:34 23040 ( A.... ) "C:\WINDOWS\system32\setup
2008-04-14 01:12:34 18944 ( A.... ) "C:\WINDOWS\system32\seced
2008-04-14 01:12:34 14848 ( A.... ) "C:\WINDOWS\system32\rsh.e
2008-04-14 01:12:34 14336 ( A.... ) "C:\WINDOWS\system32\runon
2008-04-14 01:12:34 13824 ( A.... ) "C:\WINDOWS\system32\rexec
2008-04-14 01:12:34 13312 ( A.... ) "C:\WINDOWS\system32\saved
2008-04-14 01:12:32 215552 ( A.... ) "C:\WINDOWS\system32\osk.e
2008-04-14 01:12:32 146432 ( A.... ) "C:\WINDOWS\regedit.exe"
2008-04-14 01:12:32 109568 ( A.... ) "C:\WINDOWS\system32\progm
2008-04-14 01:12:32 67584 ( A.... ) "C:\WINDOWS\system32\openf
2008-04-14 01:12:32 67072 ( A.... ) "C:\WINDOWS\system32\rdsho
2008-04-14 01:12:32 62976 ( A.... ) "C:\WINDOWS\system32\rdpcl
2008-04-14 01:12:32 58368 ( A.... ) "C:\WINDOWS\system32\packa
2008-04-14 01:12:32 56832 ( A.... ) "C:\WINDOWS\system32\rasph
2008-04-14 01:12:32 50176 ( A.... ) "C:\WINDOWS\system32\reg.e
2008-04-14 01:12:32 50176 ( A.... ) "C:\WINDOWS\system32\proqu
2008-04-14 01:12:32 49152 ( A.... ) "C:\WINDOWS\system32\power
2008-04-14 01:12:32 35840 ( A.... ) "C:\WINDOWS\system32\rciml
2008-04-14 01:12:32 21504 ( A.... ) "C:\WINDOWS\system32\rcp.e
2008-04-14 01:12:32 19968 ( A.... ) "C:\WINDOWS\system32\qproc
2008-04-14 01:12:32 17920 ( A.... ) "C:\WINDOWS\system32\ping.
2008-04-14 01:12:32 15872 ( A.... ) "C:\WINDOWS\system32\perfm
2008-04-14 01:12:32 13824 ( A.... ) "C:\WINDOWS\system32\rdsad
2008-04-14 01:12:32 11776 ( A.... ) "C:\WINDOWS\system32\regsv
2008-04-14 01:12:32 9216 ( A.... ) "C:\WINDOWS\system32\proxy
2008-04-14 01:12:30 1200640 ( A.... ) "C:\WINDOWS\system32\ntbac
2008-04-14 01:12:30 420864 ( A.... ) "C:\WINDOWS\system32\ntvdm
2008-04-14 01:12:30 176640 ( A.... ) "C:\WINDOWS\system32\napst
2008-04-14 01:12:30 124928 ( A.... ) "C:\WINDOWS\system32\net1.
2008-04-14 01:12:30 111104 ( A.... ) "C:\WINDOWS\system32\netdd
2008-04-14 01:12:30 86016 ( A.... ) "C:\WINDOWS\system32\netsh
2008-04-14 01:12:30 76800 ( A.... ) "C:\WINDOWS\system32\nsloo
2008-04-14 01:12:30 69632 ( A.... ) "C:\WINDOWS\system32\odbcc
2008-04-14 01:12:30 69120 ( A.... ) "C:\WINDOWS\system32\notep
2008-04-14 01:12:30 69120 ( A.... ) "C:\WINDOWS\notepad.exe"
2008-04-14 01:12:30 53760 ( A.... ) "C:\WINDOWS\system32\narra
2008-04-14 01:12:30 42496 ( A.... ) "C:\WINDOWS\system32\net.e
2008-04-14 01:12:30 36864 ( A.... ) "C:\WINDOWS\system32\netst
2008-04-14 01:12:30 32768 ( A.... ) "C:\WINDOWS\system32\odbca
2008-04-14 01:12:30 12288 ( A.... ) "C:\WINDOWS\system32\mstin
2008-04-14 01:12:30 4096 ( A.... ) "C:\WINDOWS\system32\nddea
2008-04-14 01:12:28 343040 ( A.... ) "C:\WINDOWS\system32\mspai
2008-04-14 01:12:28 123392 ( A.... ) "C:\WINDOWS\system32\mplay
2008-04-14 01:12:28 117248 ( A.... ) "C:\WINDOWS\system32\mqtgs
2008-04-14 01:12:28 78848 ( A.... ) "C:\WINDOWS\system32\msiex
2008-04-14 01:12:28 19968 ( A.... ) "C:\WINDOWS\system32\mqbku
2008-04-14 01:12:28 6144 ( A.... ) "C:\WINDOWS\system32\msdtc
2008-04-14 01:12:28 4608 ( A.... ) "C:\WINDOWS\system32\mqsvc
2008-04-14 01:12:26 1414656 ( A.... ) "C:\WINDOWS\system32\mmc.e
2008-04-14 01:12:26 143360 ( A.... ) "C:\WINDOWS\system32\mobsy
2008-04-14 01:12:26 57344 ( A.... ) "C:\WINDOWS\system32\makec
2008-04-14 01:12:26 33792 ( A.... ) "C:\WINDOWS\system32\mmcpe
2008-04-14 01:12:26 32768 ( A.... ) "C:\WINDOWS\system32\mnmsr
2008-04-14 01:12:24 677888 ( A.... ) "C:\WINDOWS\system32\mstsc
2008-04-14 01:12:24 514560 ( A.... ) "C:\WINDOWS\system32\logon
2008-04-14 01:12:24 75264 ( A.... ) "C:\WINDOWS\system32\locat
2008-04-14 01:12:24 72704 ( A.... ) "C:\WINDOWS\system32\magni
2008-04-14 01:12:24 59392 ( A.... ) "C:\WINDOWS\system32\logma
2008-04-14 01:12:24 53248 ( A.... ) "C:\WINDOWS\system32\ipv6.
2008-04-14 01:12:24 23552 ( A.... ) "C:\WINDOWS\system32\ipxro
2008-04-14 01:12:24 13312 ( A.... ) "C:\WINDOWS\system32\lsass
2008-04-14 01:12:22 150528 ( A.... ) "C:\WINDOWS\system32\imapi
2008-04-14 01:12:22 120832 ( A.... ) "C:\WINDOWS\system32\gpres
2008-04-14 01:12:22 114688 ( A.... ) "C:\WINDOWS\system32\iexpr
2008-04-14 01:12:22 59904 ( A.... ) "C:\WINDOWS\system32\getma
2008-04-14 01:12:22 55808 ( A.... ) "C:\WINDOWS\system32\ipcon
2008-04-14 01:12:22 39424 ( A.... ) "C:\WINDOWS\system32\grpco
2008-04-14 01:12:22 15872 ( A.... ) "C:\WINDOWS\system32\help.
2008-04-14 01:12:22 10752 ( A.... ) "C:\WINDOWS\hh.exe"
2008-04-14 01:12:20 1033728 ( A.... ) "C:\WINDOWS\explorer.exe"
2008-04-14 01:12:20 193024 ( A.... ) "C:\WINDOWS\system32\fsqui
2008-04-14 01:12:20 193024 ( A.... ) "C:\WINDOWS\system32\eudce
2008-04-14 01:12:20 82944 ( A.... ) "C:\WINDOWS\system32\event
2008-04-14 01:12:20 50688 ( A.... ) "C:\WINDOWS\system32\event
2008-04-14 01:12:20 42496 ( A.... ) "C:\WINDOWS\system32\ftp.exe"
2008-04-14 01:12:20 27136 ( A.... ) "C:\WINDOWS\system32\finds
2008-04-14 01:12:20 24064 ( A.... ) "C:\WINDOWS\system32\extra
2008-04-14 01:12:20 23040 ( A.... ) "C:\WINDOWS\system32\fltmc
2008-04-14 01:12:20 20992 ( A.... ) "C:\WINDOWS\system32\fontv
2008-04-14 01:12:20 20992 ( A.... ) "C:\WINDOWS\system32\faxpa
2008-04-14 01:12:20 7680 ( A.... ) "C:\WINDOWS\system32\force
2008-04-14 01:12:18 1298432 ( A.... ) "C:\WINDOWS\system32\dxdia
2008-04-14 01:12:18 224768 ( A.... ) "C:\WINDOWS\system32\dmadm
2008-04-14 01:12:18 180224 ( A.... ) "C:\WINDOWS\system32\dwwin
2008-04-14 01:12:18 163840 ( A.... ) "C:\WINDOWS\system32\diskp
2008-04-14 01:12:18 87040 ( A.... ) "C:\WINDOWS\system32\diant
2008-04-14 01:12:18 83456 ( A.... ) "C:\WINDOWS\system32\dpvse
2008-04-14 01:12:18 62976 ( A.... ) "C:\WINDOWS\system32\drive
2008-04-14 01:12:18 29696 ( A.... ) "C:\WINDOWS\system32\dplay
2008-04-14 01:12:18 17920 ( A.... ) "C:\WINDOWS\system32\dvdup
2008-04-14 01:12:18 17920 ( A.... ) "C:\WINDOWS\system32\dpnsv
2008-04-14 01:12:18 15872 ( A.... ) "C:\WINDOWS\system32\dmrem
2008-04-14 01:12:18 10752 ( A.... ) "C:\WINDOWS\system32\dumpr
2008-04-14 01:12:18 5120 ( A.... ) "C:\WINDOWS\system32\dllho
2008-04-14 01:12:16 139264 ( A.... ) "C:\WINDOWS\system32\cscri
2008-04-14 01:12:16 105472 ( A.... ) "C:\WINDOWS\system32\dfrgn
2008-04-14 01:12:16 82944 ( A.... ) "C:\WINDOWS\system32\dfrgf
2008-04-14 01:12:16 63488 ( A.... ) "C:\WINDOWS\system32\cmstp
2008-04-14 01:12:16 39936 ( A.... ) "C:\WINDOWS\system32\cmmon
2008-04-14 01:12:16 30208 ( A.... ) "C:\WINDOWS\system32\ddesh
2008-04-14 01:12:16 27648 ( A.... ) "C:\WINDOWS\system32\conim
2008-04-14 01:12:16 25088 ( A.... ) "C:\WINDOWS\system32\defra
2008-04-14 01:12:16 15360 ( A.... ) "C:\WINDOWS\system32\ctfmo
2008-04-14 01:12:16 6144 ( A.... ) "C:\WINDOWS\system32\dcomc
2008-04-14 01:12:16 6144 ( A.... ) "C:\WINDOWS\system32\csrss
2008-04-14 01:12:14 580608 ( A.... ) "C:\WINDOWS\system32\autof
2008-04-14 01:12:14 389120 ( A.... ) "C:\WINDOWS\system32\cmd.e
2008-04-14 01:12:14 142848 ( A.... ) "C:\WINDOWS\system32\bootc
2008-04-14 01:12:14 102912 ( A.... ) "C:\WINDOWS\system32\clipb
2008-04-14 01:12:14 71680 ( A.... ) "C:\WINDOWS\system32\blast
2008-04-14 01:12:14 64000 ( A.... ) "C:\WINDOWS\system32\clean
2008-04-14 01:12:14 56832 ( A.... ) "C:\WINDOWS\system32\ciphe
2008-04-14 01:12:14 33280 ( A.... ) "C:\WINDOWS\system32\clips
2008-04-14 01:12:14 25600 ( A.... ) "C:\WINDOWS\system32\cmdl3
2008-04-14 01:12:14 20480 ( A.... ) "C:\WINDOWS\system32\clico
2008-04-14 01:12:14 19968 ( A.... ) "C:\WINDOWS\system32\cacls
2008-04-14 01:12:14 11264 ( A.... ) "C:\WINDOWS\system32\autol
2008-04-14 01:12:14 5632 ( A.... ) "C:\WINDOWS\system32\cisvc
2008-04-14 01:12:12 602624 ( A.... ) "C:\WINDOWS\system32\autoc
2008-04-14 01:12:12 588800 ( A.... ) "C:\WINDOWS\system32\autoc
2008-04-14 01:12:12 483840 ( A.... ) "C:\WINDOWS\system32\wzcsv
2008-04-14 01:12:12 383488 ( A.... ) "C:\WINDOWS\system32\wzcdl
2008-04-14 01:12:12 338432 ( A.... ) "C:\WINDOWS\system32\zipfl
2008-04-14 01:12:12 184320 ( A.... ) "C:\WINDOWS\system32\accwi
2008-04-14 01:12:12 183296 ( A.... ) "C:\WINDOWS\system32\wuaue
2008-04-14 01:12:12 129024 ( A.... ) "C:\WINDOWS\system32\xmlpr
2008-04-14 01:12:12 121856 ( A.... ) "C:\WINDOWS\system32\xmlli
2008-04-14 01:12:12 98304 ( A.... ) "C:\WINDOWS\system32\ahui.
2008-04-14 01:12:12 91648 ( A.... ) "C:\WINDOWS\system32\xacts
2008-04-14 01:12:12 52736 ( A.... ) "C:\WINDOWS\system32\wzcsa
2008-04-14 01:12:12 50176 ( A.... ) "C:\WINDOWS\system32\xmlpr
2008-04-14 01:12:12 44544 ( A.... ) "C:\WINDOWS\system32\alg.e
2008-04-14 01:12:12 32768 ( A.... ) "C:\WINDOWS\system32\asr_p
2008-04-14 01:12:12 30208 ( A.... ) "C:\WINDOWS\system32\asr_f
2008-04-14 01:12:12 25088 ( A.... ) "C:\WINDOWS\system32\at.ex
2008-04-14 01:12:12 14336 ( A.... ) "C:\WINDOWS\system32\audit
2008-04-14 01:12:12 12288 ( A.... ) "C:\WINDOWS\system32\attri
2008-04-14 01:12:12 11776 ( A.... ) "C:\WINDOWS\system32\xoleh
2008-04-14 01:12:12 11264 ( A.... ) "C:\WINDOWS\system32\atmad
2008-04-14 01:12:12 6656 ( A.... ) "C:\WINDOWS\system32\wuaus
2008-04-14 01:12:12 4096 ( A.... ) "C:\WINDOWS\system32\actmo
2008-04-14 01:12:10 604160 ( A.... ) "C:\WINDOWS\system32\wsece
2008-04-14 01:12:10 303616 ( A.... ) "C:\WINDOWS\system32\wmstr
2008-04-14 01:12:10 293376 ( A.... ) "C:\WINDOWS\system32\winsr
2008-04-14 01:12:10 276992 ( A.... ) "C:\WINDOWS\system32\wmpho
2008-04-14 01:12:10 264192 ( A.... ) "C:\WINDOWS\system32\wow32
2008-04-14 01:12:10 176640 ( A.... ) "C:\WINDOWS\system32\wintr
2008-04-14 01:12:10 176128 ( A.... ) "C:\WINDOWS\system32\winmm
2008-04-14 01:12:10 172032 ( A.... ) "C:\WINDOWS\system32\wldap
2008-04-14 01:12:10 132096 ( A.... ) "C:\WINDOWS\system32\wkssv
2008-04-14 01:12:10 115200 ( A.... ) "C:\WINDOWS\system32\wmsdm
2008-04-14 01:12:10 108032 ( A.... ) "C:\WINDOWS\system32\wshbt
2008-04-14 01:12:10 99328 ( A.... ) "C:\WINDOWS\system32\winsc
2008-04-14 01:12:10 92672 ( A.... ) "C:\WINDOWS\system32\wlnot
2008-04-14 01:12:10 90112 ( A.... ) "C:\WINDOWS\system32\wshex
2008-04-14 01:12:10 82432 ( A.... ) "C:\WINDOWS\system32\ws2_3
2008-04-14 01:12:10 80896 ( A.... ) "C:\WINDOWS\system32\wscsv
2008-04-14 01:12:10 69120 ( A.... ) "C:\WINDOWS\system32\wlana
2008-04-14 01:12:10 53760 ( A.... ) "C:\WINDOWS\system32\winst
2008-04-14 01:12:10 50688 ( A.... ) "C:\WINDOWS\system32\wstde
2008-04-14 01:12:10 41984 ( A.... ) "C:\WINDOWS\system32\wsnmp
2008-04-14 01:12:10 36864 ( A.... ) "C:\WINDOWS\system32\wshco
2008-04-14 01:12:10 32256 ( A.... ) "C:\WINDOWS\system32\winip
2008-04-14 01:12:10 22528 ( A.... ) "C:\WINDOWS\system32\wsock
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpui
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpco
2008-04-14 01:12:10 20480 ( A.... ) "C:\WINDOWS\system32\wmpcd
2008-04-14 01:12:10 19968 ( A.... ) "C:\WINDOWS\system32\ws2he
2008-04-14 01:12:10 19456 ( A.... ) "C:\WINDOWS\system32\wshtc
2008-04-14 01:12:10 18432 ( A.... ) "C:\WINDOWS\system32\wtsap
2008-04-14 01:12:10 17408 ( A.... ) "C:\WINDOWS\system32\winsh
2008-04-14 01:12:10 16896 ( A.... ) "C:\WINDOWS\system32\winrn
2008-04-14 01:12:10 14336 ( A.... ) "C:\WINDOWS\system32\wship
2008-04-14 01:12:10 11264 ( A.... ) "C:\WINDOWS\system32\wshrm
2008-04-14 01:12:08 990208 ( A.... ) "C:\WINDOWS\system32\sysse
2008-04-14 01:12:08 858624 ( A.... ) "C:\WINDOWS\system32\tapi3
2008-04-14 01:12:08 727040 ( A.... ) "C:\WINDOWS\system32\usere
2008-04-14 01:12:08 713216 ( A.... ) "C:\WINDOWS\system32\sxs.d
2008-04-14 01:12:08 712704 ( A.... ) "C:\WINDOWS\system32\windo
2008-04-14 01:12:08 589312 ( A.... ) "C:\WINDOWS\system32\wiash
2008-04-14 01:12:08 578560 ( A.... ) "C:\WINDOWS\system32\user3
2008-04-14 01:12:08 463360 ( A.... ) "C:\WINDOWS\system32\wiade
2008-04-14 01:12:08 434176 ( A.... ) "C:\WINDOWS\system32\vbscr
2008-04-14 01:12:08 430592 ( A.... ) "C:\WINDOWS\system32\vssap
2008-04-14 01:12:08 406016 ( A.... ) "C:\WINDOWS\system32\usp10
2008-04-14 01:12:08 385536 ( A.... ) "C:\WINDOWS\system32\theme
2008-04-14 01:12:08 358400 ( A.... ) "C:\WINDOWS\system32\termm
2008-04-14 01:12:08 354304 ( A.... ) "C:\WINDOWS\system32\winht
2008-04-14 01:12:08 346112 ( A.... ) "C:\WINDOWS\system32\windo
2008-04-14 01:12:08 333824 ( A.... ) "C:\WINDOWS\system32\wiase
2008-04-14 01:12:08 316416 ( A.... ) "C:\WINDOWS\system32\untfs
2008-04-14 01:12:08 295424 ( A.... ) "C:\WINDOWS\system32\terms
2008-04-14 01:12:08 275456 ( A.... ) "C:\WINDOWS\system32\ulib.
2008-04-14 01:12:08 249856 ( A.... ) "C:\WINDOWS\system32\tapis
2008-04-14 01:12:08 246814 ( A.... ) "C:\WINDOWS\system32\strmd
2008-04-14 01:12:08 239616 ( A.... ) "C:\WINDOWS\system32\upnpu
2008-04-14 01:12:08 239104 ( A.... ) "C:\WINDOWS\system32\srrst
2008-04-14 01:12:08 218624 ( A.... ) "C:\WINDOWS\system32\uxthe
2008-04-14 01:12:08 215552 ( A.... ) "C:\WINDOWS\system32\wavem
2008-04-14 01:12:08 191488 ( A.... ) "C:\WINDOWS\system32\syncu
2008-04-14 01:12:08 185856 ( A.... ) "C:\WINDOWS\system32\upnph
2008-04-14 01:12:08 181760 ( A.... ) "C:\WINDOWS\system32\tapi3
2008-04-14 01:12:08 175104 ( A.... ) "C:\WINDOWS\system32\w32ti
2008-04-14 01:12:08 171008 ( A.... ) "C:\WINDOWS\system32\srsvc
2008-04-14 01:12:08 136704 ( A.... ) "C:\WINDOWS\system32\sti_c
2008-04-14 01:12:08 135680 ( A.... ) "C:\WINDOWS\system32\webvw
2008-04-14 01:12:08 133632 ( A.... ) "C:\WINDOWS\system32\upnp.
2008-04-14 01:12:08 124416 ( A.... ) "C:\WINDOWS\system32\wiads
2008-04-14 01:12:08 123392 ( A.... ) "C:\WINDOWS\system32\umpnp
2008-04-14 01:12:08 121856 ( A.... ) "C:\WINDOWS\system32\stobj
2008-04-14 01:12:08 117760 ( A.... ) "C:\WINDOWS\system32\t2emb
2008-04-14 01:12:08 111104 ( A.... ) "C:\WINDOWS\system32\wiavi
2008-04-14 01:12:08 102400 ( A.... ) "C:\WINDOWS\system32\win32
2008-04-14 01:12:08 101376 ( A.... ) "C:\WINDOWS\system32\txflo
2008-04-14 01:12:08 96768 ( A.... ) "C:\WINDOWS\system32\srvsv
2008-04-14 01:12:08 93696 ( A.... ) "C:\WINDOWS\system32\tscfg
2008-04-14 01:12:08 90112 ( A.... ) "C:\WINDOWS\system32\trkwk
2008-04-14 01:12:08 75776 ( A.... ) "C:\WINDOWS\system32\wiasc
2008-04-14 01:12:08 75776 ( A.... ) "C:\WINDOWS\system32\strmf
2008-04-14 01:12:08 74752 ( A.... ) "C:\WINDOWS\system32\storp
2008-04-14 01:12:08 74240 ( A.... ) "C:\WINDOWS\system32\usbui
2008-04-14 01:12:08 74240 ( A.... ) "C:\WINDOWS\system32\unimd
2008-04-14 01:12:08 71680 ( A.... ) "C:\WINDOWS\system32\ssdps
2008-04-14 01:12:08 68096 ( A.... ) "C:\WINDOWS\system32\webcl
2008-04-14 01:12:08 68096 ( A.... ) "C:\WINDOWS\system32\sti.d
2008-04-14 01:12:08 67584 ( A.... ) "C:\WINDOWS\system32\srcli
2008-04-14 01:12:08 59392 ( A.... ) "C:\WINDOWS\system32\stcli
2008-04-14 01:12:08 57856 ( A.... ) "C:\WINDOWS\system32\twext
2008-04-14 01:12:08 57856 ( A.... ) "C:\WINDOWS\system32\synce
2008-04-14 01:12:08 53248 ( A.... ) "C:\WINDOWS\system32\tsgqe
2008-04-14 01:12:08 51712 ( A.... ) "C:\WINDOWS\system32\vdmre
2008-04-14 01:12:08 50688 ( A.... ) "C:\WINDOWS\twain_32.dll"
2008-04-14 01:12:08 50688 ( A.... ) "C:\WINDOWS\system32\tspkg
2008-04-14 01:12:08 49152 ( A.... ) "C:\WINDOWS\system32\wdige
2008-04-14 01:12:08 45568 ( A.... ) "C:\WINDOWS\system32\tcpmo
2008-04-14 01:12:08 45568 ( A.... ) "C:\WINDOWS\system32\tcpmo
2008-04-14 01:12:08 35840 ( A.... ) "C:\WINDOWS\system32\umand
2008-04-14 01:12:08 34816 ( A.... ) "C:\WINDOWS\system32\ssdpa
2008-04-14 01:12:08 30749 ( A.... ) "C:\WINDOWS\system32\vbaje
2008-04-14 01:12:08 26624 ( A.... ) "C:\WINDOWS\system32\verif
2008-04-14 01:12:08 26624 ( A.... ) "C:\WINDOWS\system32\udhis
2008-04-14 01:12:08 26112 ( A.... ) "C:\WINDOWS\system32\vdmdb
2008-04-14 01:12:08 18944 ( A.... ) "C:\WINDOWS\system32\versi
2008-04-14 01:12:08 16896 ( A.... ) "C:\WINDOWS\system32\usbmo
2008-04-14 01:12:08 15872 ( A.... ) "C:\WINDOWS\system32\w3ssl
2008-04-14 01:12:08 14848 ( A.... ) "C:\WINDOWS\system32\tcpmi
2008-04-14 01:12:08 13824 ( A.... ) "C:\WINDOWS\system32\unipl
2008-04-14 01:12:08 8192 ( A.... ) "C:\WINDOWS\system32\staxm
2008-04-14 01:12:08 7168 ( A.... ) "C:\WINDOWS\system32\tlnts
2008-04-14 01:12:06 8461312 ( A.... ) "C:\WINDOWS\system32\shell
2008-04-14 01:12:06 1614848 ( A.... ) "C:\WINDOWS\system32\sfcfi
2008-04-14 01:12:06 1499136 ( A.... ) "C:\WINDOWS\system32\shdoc
2008-04-14 01:12:06 474112 ( A.... ) "C:\WINDOWS\system32\shlwa
2008-04-14 01:12:06 442368 ( A.... ) "C:\WINDOWS\system32\sqlsr
2008-04-14 01:12:06 438272 ( A.... ) "C:\WINDOWS\system32\shimg
2008-04-14 01:12:06 362496 ( A.... ) "C:\WINDOWS\system32\smlog
2008-04-14 01:12:06 314880 ( A.... ) "C:\WINDOWS\system32\scesr
2008-04-14 01:12:06 286792 ( A.... ) "C:\WINDOWS\system32\slext
2008-04-14 01:12:06 192512 ( A.... ) "C:\WINDOWS\system32\sched
2008-04-14 01:12:06 188508 ( A.... ) "C:\WINDOWS\system32\slgen
2008-04-14 01:12:06 182272 ( A.... ) "C:\WINDOWS\system32\snmps
2008-04-14 01:12:06 181248 ( A.... ) "C:\WINDOWS\system32\scecl
2008-04-14 01:12:06 180800 ( A.... ) "C:\WINDOWS\system32\sqlun
2008-04-14 01:12:06 180224 ( A.... ) "C:\WINDOWS\system32\scrob
2008-04-14 01:12:06 172032 ( A.... ) "C:\WINDOWS\system32\scrru
2008-04-14 01:12:06 171008 ( A.... ) "C:\WINDOWS\system32\sccsc
2008-04-14 01:12:06 152064 ( A.... ) "C:\WINDOWS\system32\shmed
2008-04-14 01:12:06 144384 ( A.... ) "C:\WINDOWS\system32\schan
2008-04-14 01:12:06 140288 ( A.... ) "C:\WINDOWS\system32\sfc_o
2008-04-14 01:12:06 135168 ( A.... ) "C:\WINDOWS\system32\shsvc
2008-04-14 01:12:06 98304 ( A.... ) "C:\WINDOWS\system32\slbio
2008-04-14 01:12:06 75264 ( A.... ) "C:\WINDOWS\system32\spool
2008-04-14 01:12:06 73832 ( A.... ) "C:\WINDOWS\system32\slcoi
2008-04-14 01:12:06 68096 ( A.... ) "C:\WINDOWS\system32\shgin
2008-04-14 01:12:06 65024 ( A.... ) "C:\WINDOWS\system32\shime
2008-04-14 01:12:06 56320 ( A.... ) "C:\WINDOWS\system32\servd
2008-04-14 01:12:06 56320 ( A.... ) "C:\WINDOWS\system32\secur
2008-04-14 01:12:06 54784 ( A.... ) "C:\WINDOWS\system32\sendm
2008-04-14 01:12:06 39424 ( A.... ) "C:\WINDOWS\system32\sens.
2008-04-14 01:12:06 29184 ( A.... ) "C:\WINDOWS\system32\sendc
2008-04-14 01:12:06 29184 ( A.... ) "C:\WINDOWS\system32\sdhci
2008-04-14 01:12:06 27648 ( A.... ) "C:\WINDOWS\system32\shscr
2008-04-14 01:12:06 25088 ( A.... ) "C:\WINDOWS\system32\slaye
2008-04-14 01:12:06 25088 ( A.... ) "C:\WINDOWS\system32\shfol
2008-04-14 01:12:06 20480 ( A.... ) "C:\WINDOWS\system32\sclgn
2008-04-14 01:12:06 18944 ( A.... ) "C:\WINDOWS\system32\snmpa
2008-04-14 01:12:06 18944 ( A.... ) "C:\WINDOWS\system32\seclo
2008-04-14 01:12:06 13312 ( A.... ) "C:\WINDOWS\system32\sigta
2008-04-14 01:12:06 10752 ( A.... ) "C:\WINDOWS\system32\smtpa
2008-04-14 01:12:06 7168 ( A.... ) "C:\WINDOWS\system32\sensa
2008-04-14 01:12:06 5632 ( A.... ) "C:\WINDOWS\system32\secur
2008-04-14 01:12:06 5120 ( A.... ) "C:\WINDOWS\system32\sfc.d
2008-04-14 01:12:04 1435648 ( A.... ) "C:\WINDOWS\system32\query
2008-04-14 01:12:04 658432 ( A.... ) "C:\WINDOWS\system32\rasdl
2008-04-14 01:12:04 584704 ( A.... ) "C:\WINDOWS\system32\rpcrt
2008-04-14 01:12:04 562176 ( A.... ) "C:\WINDOWS\system32\qedit
2008-04-14 01:12:04 560640 ( A.... ) "C:\WINDOWS\system32\print
2008-04-14 01:12:04 433664 ( A.... ) "C:\WINDOWS\system32\riche
2008-04-14 01:12:04 415744 ( A.... ) "C:\WINDOWS\system32\samsr
2008-04-14 01:12:04 409088 ( A.... ) "C:\WINDOWS\system32\qmgr.
2008-04-14 01:12:04 399360 ( A.... ) "C:\WINDOWS\system32\rpcss
2008-04-14 01:12:04 397824 ( A.... ) "C:\WINDOWS\system32\regwi
2008-04-14 01:12:04 397056 ( A.... ) "C:\WINDOWS\system32\s3gnb
2008-04-14 01:12:04 386048 ( A.... ) "C:\WINDOWS\system32\qdvd.
2008-04-14 01:12:04 291328 ( A.... ) "C:\WINDOWS\system32\qagen
2008-04-14 01:12:04 290304 ( A.... ) "C:\WINDOWS\system32\rhttp
2008-04-14 01:12:04 279040 ( A.... ) "C:\WINDOWS\system32\qdv.d
2008-04-14 01:12:04 270848 ( A.... ) "C:\WINDOWS\system32\sbe.d
2008-04-14 01:12:04 237056 ( A.... ) "C:\WINDOWS\system32\rasap
2008-04-14 01:12:04 210944 ( A.... ) "C:\WINDOWS\system32\raspp
2008-04-14 01:12:04 192512 ( A.... ) "C:\WINDOWS\system32\qcap.
2008-04-14 01:12:04 186368 ( A.... ) "C:\WINDOWS\system32\rasma
2008-04-14 01:12:04 159232 ( A.... ) "C:\WINDOWS\system32\sbeio
2008-04-14 01:12:04 150528 ( A.... ) "C:\WINDOWS\system32\qagen
2008-04-14 01:12:04 150016 ( A.... ) "C:\WINDOWS\system32\rastl
2008-04-14 01:12:04 147968 ( A.... ) "C:\WINDOWS\system32\rdcho
2008-04-14 01:12:04 102400 ( A.... ) "C:\WINDOWS\system32\rcbdy
2008-04-14 01:12:04 96768 ( A.... ) "C:\WINDOWS\system32\psbas
2008-04-14 01:12:04 92672 ( A.... ) "C:\WINDOWS\system32\rsvps
2008-04-14 01:12:04 88576 ( A.... ) "C:\WINDOWS\system32\rasau
2008-04-14 01:12:04 79872 ( A.... ) "C:\WINDOWS\system32\rasch
2008-04-14 01:12:04 76800 ( A.... ) "C:\WINDOWS\system32\qutil
2008-04-14 01:12:04 69632 ( A.... ) "C:\WINDOWS\system32\scard
2008-04-14 01:12:04 64000 ( A.... ) "C:\WINDOWS\system32\samli
2008-04-14 01:12:04 62464 ( A.... ) "C:\WINDOWS\system32\qclip
2008-04-14 01:12:04 61952 ( A.... ) "C:\WINDOWS\system32\rasqe
2008-04-14 01:12:04 61440 ( A.... ) "C:\WINDOWS\system32\rasma
2008-04-14 01:12:04 60416 ( A.... ) "C:\WINDOWS\system32\remot
2008-04-14 01:12:04 59904 ( A.... ) "C:\WINDOWS\system32\regsv
2008-04-14 01:12:04 58880 ( A.... ) "C:\WINDOWS\system32\resut
2008-04-14 01:12:04 58368 ( A.... ) "C:\WINDOWS\system32\rasta
2008-04-14 01:12:04 49664 ( A.... ) "C:\WINDOWS\system32\regap
2008-04-14 01:12:04 45568 ( A.... ) "C:\WINDOWS\system32\safrs
2008-04-14 01:12:04 44032 ( A.... ) "C:\WINDOWS\system32\rtuti
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\safrc
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\racpl
2008-04-14 01:12:04 43520 ( A.... ) "C:\WINDOWS\system32\pstor
2008-04-14 01:12:04 39936 ( A.... ) "C:\WINDOWS\system32\rshx3
2008-04-14 01:12:04 34304 ( A.... ) "C:\WINDOWS\system32\pstor
2008-04-14 01:12:04 31744 ( A.... ) "C:\WINDOWS\system32\rtipx
2008-04-14 01:12:04 29696 ( A.... ) "C:\WINDOWS\system32\safrd
2008-04-14 01:12:04 27648 ( A.... ) "C:\WINDOWS\system32\profm
2008-04-14 01:12:04 23040 ( A.... ) "C:\WINDOWS\system32\psapi
2008-04-14 01:12:04 19968 ( A.... ) "C:\WINDOWS\system32\rdpsn
2008-04-14 01:12:04 18944 ( A.... ) "C:\WINDOWS\system32\rsmps
2008-04-14 01:12:04 18944 ( A.... ) "C:\WINDOWS\system32\qmgrp
2008-04-14 01:12:04 17408 ( A.... ) "C:\WINDOWS\system32\powrp
2008-04-14 01:12:04 16384 ( A.... ) "C:\WINDOWS\system32\rassa
2008-04-14 01:12:04 9728 ( A.... ) "C:\WINDOWS\system32\rwnh.
2008-04-14 01:12:04 7680 ( A.... ) "C:\WINDOWS\system32\rasad
2008-04-14 01:12:02 4274816 ( A.... ) "C:\WINDOWS\system32\nv4_d
2008-04-14 01:12:02 1737856 ( A.... ) "C:\WINDOWS\system32\mtxpa
2008-04-14 01:12:02 1703936 ( A.... ) "C:\WINDOWS\system32\netsh
2008-04-14 01:12:02 1428992 ( A.... ) "C:\WINDOWS\system32\msvid
2008-04-14 01:12:02 1306624 ( A.... ) "C:\WINDOWS\system32\msxml
2008-04-14 01:12:02 1287168 ( A.... ) "C:\WINDOWS\system32\ole32
2008-04-14 01:12:02 1104896 ( A.... ) "C:\WINDOWS\system32\msxml
2008-04-14 01:12:02 875008 ( A.... ) "C:\WINDOWS\system32\netpl
2008-04-14 01:12:02 713728 ( A.... ) "C:\WINDOWS\system32\openg
2008-04-14 01:12:02 701440 ( A.... ) "C:\WINDOWS\system32\msxml
2008-04-14 01:12:02 622592 ( A.... ) "C:\WINDOWS\system32\netcf
2008-04-14 01:12:02 554496 ( A.... ) "C:\WINDOWS\system32\p2psv
2008-04-14 01:12:02 551936 ( A.... ) "C:\WINDOWS\system32\oleau
2008-04-14 01:12:02 506368 ( A.... ) "C:\WINDOWS\system32\msxml
2008-04-14 01:12:02 488448 ( A.... ) "C:\WINDOWS\system32\ntmsm
2008-04-14 01:12:02 435200 ( A.... ) "C:\WINDOWS\system32\ntmss
2008-04-14 01:12:02 413696 ( A.... ) "C:\WINDOWS\system32\msvcp
2008-04-14 01:12:02 412160 ( A.... ) "C:\WINDOWS\system32\photo
2008-04-14 01:12:02 407040 ( A.... ) "C:\WINDOWS\system32\netlo
2008-04-14 01:12:02 343040 ( A.... ) "C:\WINDOWS\system32\msvcr
2008-04-14 01:12:02 337408 ( A.... ) "C:\WINDOWS\system32\netap
2008-04-14 01:12:02 313856 ( A.... ) "C:\WINDOWS\system32\p2pgr
2008-04-14 01:12:02 286208 ( A.... ) "C:\WINDOWS\system32\objse
2008-04-14 01:12:02 284160 ( A.... ) "C:\WINDOWS\system32\pdh.d
2008-04-14 01:12:02 278559 ( A.... ) "C:\WINDOWS\system32\odbcj
2008-04-14 01:12:02 270336 ( A.... ) "C:\WINDOWS\system32\oakle
2008-04-14 01:12:02 249856 ( A.... ) "C:\WINDOWS\system32\odbc3
2008-04-14 01:12:02 247808 ( A.... ) "C:\WINDOWS\system32\newde
2008-04-14 01:12:02 245760 ( A.... ) "C:\WINDOWS\system32\netui
2008-04-14 01:12:02 245248 ( A.... ) "C:\WINDOWS\system32\mswso
2008-04-14 01:12:02 203776 ( A.... ) "C:\WINDOWS\system32\msweb
2008-04-14 01:12:02 198144 ( A.... ) "C:\WINDOWS\system32\netma
2008-04-14 01:12:02 193024 ( A.... ) "C:\WINDOWS\system32\napmo
2008-04-14 01:12:02 192000 ( A.... ) "C:\WINDOWS\system32\offfi
2008-04-14 01:12:02 179200 ( A.... ) "C:\WINDOWS\system32\ntmsd
2008-04-14 01:12:02 176128 ( A.... ) "C:\WINDOWS\system32\photo
2008-04-14 01:12:02 153600 ( A.... ) "C:\WINDOWS\system32\p2p.d
2008-04-14 01:12:02 147456 ( A.... ) "C:\WINDOWS\system32\odbct
2008-04-14 01:12:02 144384 ( A.... ) "C:\WINDOWS\system32\onex.
2008-04-14 01:12:02 143360 ( A.... ) "C:\WINDOWS\system32\ntshr
2008-04-14 01:12:02 142336 ( A.... ) "C:\WINDOWS\system32\nwpro
2008-04-14 01:12:02 139264 ( A.... ) "C:\WINDOWS\system32\netid
2008-04-14 01:12:02 135168 ( A.... ) "C:\WINDOWS\system32\odbcc
2008-04-14 01:12:02 122880 ( A.... ) "C:\WINDOWS\system32\oledl
2008-04-14 01:12:02 121344 ( A.... ) "C:\WINDOWS\system32\msvfw
2008-04-14 01:12:02 118784 ( A.... ) "C:\WINDOWS\system32\ntmar
2008-04-14 01:12:02 115712 ( A.... ) "C:\WINDOWS\system32\p2pne
2008-04-14 01:12:02 107008 ( A.... ) "C:\WINDOWS\system32\olepr
2008-04-14 01:12:02 106496 ( A.... ) "C:\WINDOWS\system32\odbcc
2008-04-14 01:12:02 105472 ( A.... ) "C:\WINDOWS\system32\polst
2008-04-14 01:12:02 105472 ( A.... ) "C:\WINDOWS\system32\p2pga
2008-04-14 01:12:02 98304 ( A.... ) "C:\WINDOWS\system32\nlhtm
2008-04-14 01:12:02 91648 ( A.... ) "C:\WINDOWS\system32\mtxoc
2008-04-14 01:12:02 91136 ( A.... ) "C:\WINDOWS\system32\ntpri
2008-04-14 01:12:02 90624 ( A.... ) "C:\WINDOWS\system32\mydoc
2008-04-14 01:12:02 84992 ( A.... ) "C:\WINDOWS\system32\olepr
2008-04-14 01:12:02 80896 ( A.... ) "C:\WINDOWS\system32\netui
2008-04-14 01:12:02 74752 ( A.... ) "C:\WINDOWS\system32\olecl
2008-04-14 01:12:02 72704 ( A.... ) "C:\WINDOWS\system32\msw3p
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\pauto
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\osuni
2008-04-14 01:12:02 67584 ( A.... ) "C:\WINDOWS\system32\ocman
2008-04-14 01:12:02 67072 ( A.... ) "C:\WINDOWS\system32\ntdsa
2008-04-14 01:12:02 66560 ( A.... ) "C:\WINDOWS\system32\mtxcl
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\odbcc
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\odbcc
2008-04-14 01:12:02 65536 ( A.... ) "C:\WINDOWS\system32\nwwks
2008-04-14 01:12:02 64000 ( A.... ) "C:\WINDOWS\system32\nwapi
2008-04-14 01:12:02 58880 ( A.... ) "C:\WINDOWS\system32\pnrpn
2008-04-14 01:12:02 57344 ( A.... ) "C:\WINDOWS\system32\msvci
2008-04-14 01:12:02 54784 ( A.... ) "C:\WINDOWS\system32\nppto
2008-04-14 01:12:02 44032 ( A.... ) "C:\WINDOWS\system32\ntlan
2008-04-14 01:12:02 40960 ( A.... ) "C:\WINDOWS\system32\ntmsa
2008-04-14 01:12:02 39936 ( A.... ) "C:\WINDOWS\system32\perfc
2008-04-14 01:12:02 37376 ( A.... ) "C:\WINDOWS\system32\olecn
2008-04-14 01:12:02 36352 ( A.... ) "C:\WINDOWS\system32\ncobj
2008-04-14 01:12:02 35328 ( A.... ) "C:\WINDOWS\system32\pid.d
2008-04-14 01:12:02 34816 ( A.... ) "C:\WINDOWS\system32\perfp
2008-04-14 01:12:02 34304 ( A.... ) "C:\WINDOWS\system32\mtxle
2008-04-14 01:12:02 30720 ( A.... ) "C:\WINDOWS\system32\mtxdm
2008-04-14 01:12:02 30208 ( A.... ) "C:\WINDOWS\system32\napip
2008-04-14 01:12:02 28672 ( A.... ) "C:\WINDOWS\system32\nmmkc
2008-04-14 01:12:02 26624 ( A.... ) "C:\WINDOWS\system32\perfd
2008-04-14 01:12:02 25088 ( A.... ) "C:\WINDOWS\system32\perfo
2008-04-14 01:12:02 24576 ( A.... ) "C:\WINDOWS\system32\odbcb
2008-04-14 01:12:02 20511 ( A.... ) "C:\WINDOWS\system32\odtex
2008-04-14 01:12:02 20511 ( A.... ) "C:\WINDOWS\system32\oddbs
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odpdx
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odfox
2008-04-14 01:12:02 20510 ( A.... ) "C:\WINDOWS\system32\odexl
2008-04-14 01:12:02 18944 ( A.... ) "C:\WINDOWS\system32\ndden
2008-04-14 01:12:02 17920 ( A.... ) "C:\WINDOWS\system32\perfn
2008-04-14 01:12:02 17920 ( A.... ) "C:\WINDOWS\system32\nddea
2008-04-14 01:12:02 16896 ( A.... ) "C:\WINDOWS\system32\msyuv
2008-04-14 01:12:02 16384 ( A.... ) "C:\WINDOWS\system32\odbc3
2008-04-14 01:12:02 15360 ( A.... ) "C:\WINDOWS\system32\pjlmo
2008-04-14 01:12:02 15360 ( A.... ) "C:\WINDOWS\system32\ntvdm
2008-04-14 01:12:02 11776 ( A.... ) "C:\WINDOWS\system32\netra
2008-04-14 01:12:02 8192 ( A.... ) "C:\WINDOWS\system32\ntlsa
2008-04-14 01:12:02 4096 ( A.... ) "C:\WINDOWS\system32\mtxex
2008-04-14 01:12:00 2843136 ( A.... ) "C:\WINDOWS\system32\msi.d
2008-04-14 01:12:00 1384479 ( A.... ) "C:\WINDOWS\system32\msvbv
2008-04-14 01:12:00 997376 ( A.... ) "C:\WINDOWS\system32\msgin
2008-04-14 01:12:00 956928 ( A.... ) "C:\WINDOWS\system32\msdtc
2008-04-14 01:12:00 539136 ( A.... ) "C:\WINDOWS\system32\msfte
2008-04-14 01:12:00 427008 ( A.... ) "C:\WINDOWS\system32\msdtc
2008-04-14 01:12:00 290816 ( A.... ) "C:\WINDOWS\system32\msnss
2008-04-14 01:12:00 274944 ( A.... ) "C:\WINDOWS\system32\mstas
2008-04-14 01:12:00 271360 ( A.... ) "C:\WINDOWS\system32\msihn
2008-04-14 01:12:00 252928 ( A.... ) "C:\WINDOWS\system32\msoea
2008-04-14 01:12:00 248832 ( A.... ) "C:\WINDOWS\system32\msieftp.dll"
2008-04-14 01:12:00 195072 ( A.... ) "C:\WINDOWS\system32\msutb
2008-04-14 01:12:00 161792 ( A.... ) "C:\WINDOWS\system32\msdtc
2008-04-14 01:12:00 159232 ( A.... ) "C:\WINDOWS\system32\msimt
2008-04-14 01:12:00 155136 ( A.... ) "C:\WINDOWS\system32\mssha
2008-04-14 01:12:00 151583 ( A.... ) "C:\WINDOWS\system32\msjin
2008-04-14 01:12:00 151552 ( A.... ) "C:\WINDOWS\system32\msdar
2008-04-14 01:12:00 143360 ( A.... ) "C:\WINDOWS\system32\msorc
2008-04-14 01:12:00 134656 ( A.... ) "C:\WINDOWS\system32\mssap
2008-04-14 01:12:00 132608 ( A.... ) "C:\WINDOWS\system32\msv1_
2008-04-14 01:12:00 116224 ( A.... ) "C:\WINDOWS\system32\mstls
2008-04-14 01:12:00 105984 ( A.... ) "C:\WINDOWS\system32\msoer
2008-04-14 01:12:00 58880 ( A.... ) "C:\WINDOWS\system32\msdtc
2008-04-14 01:12:00 51712 ( A.... ) "C:\WINDOWS\system32\mside
2008-04-14 01:12:00 33792 ( A.... ) "C:\WINDOWS\system32\msgsv
2008-04-14 01:12:00 29696 ( A.... ) "C:\WINDOWS\system32\mspat
2008-04-14 01:12:00 25088 ( A.... ) "C:\WINDOWS\system32\mslbu
2008-04-14 01:12:00 15360 ( A.... ) "C:\WINDOWS\system32\msisi
2008-04-14 01:12:00 14336 ( A.... ) "C:\WINDOWS\system32\msdmo
2008-04-14 01:12:00 11264 ( A.... ) "C:\WINDOWS\system32\msrle
2008-04-14 01:12:00 6656 ( A.... ) "C:\WINDOWS\system32\msidl
2008-04-14 01:12:00 4608 ( A.... ) "C:\WINDOWS\system32\msimg
2008-04-14 01:11:58 1872896 ( A.... ) "C:\WINDOWS\system32\mmcnd
2008-04-14 01:11:58 663040 ( A.... ) "C:\WINDOWS\system32\mqqm.
2008-04-14 01:11:58 586240 ( A.... ) "C:\WINDOWS\system32\mlang
2008-04-14 01:11:58 517632 ( A.... ) "C:\WINDOWS\system32\mqsna
2008-04-14 01:11:58 471552 ( A.... ) "C:\WINDOWS\system32\mquti
2008-04-14 01:11:58 397312 ( A.... ) "C:\WINDOWS\system32\mmcex
2008-04-14 01:11:58 297984 ( A.... ) "C:\WINDOWS\system32\msctf
2008-04-14 01:11:58 225280 ( A.... ) "C:\WINDOWS\system32\mqoa.
2008-04-14 01:11:58 207360 ( A.... ) "C:\WINDOWS\system32\mobsy
2008-04-14 01:11:58 187392 ( A.... ) "C:\WINDOWS\system32\mqtri
2008-04-14 01:11:58 184320 ( A.... ) "C:\WINDOWS\system32\micro
2008-04-14 01:11:58 177152 ( A.... ) "C:\WINDOWS\system32\mqrt.
2008-04-14 01:11:58 163328 ( A.... ) "C:\WINDOWS\system32\mmcba
2008-04-14 01:11:58 153600 ( A.... ) "C:\WINDOWS\system32\modem
2008-04-14 01:11:58 138240 ( A.... ) "C:\WINDOWS\system32\mqad.
2008-04-14 01:11:58 123904 ( A.... ) "C:\WINDOWS\system32\mqrtd
2008-04-14 01:11:58 118784 ( A.... ) "C:\WINDOWS\system32\msdad
2008-04-14 01:11:58 106496 ( A.... ) "C:\WINDOWS\system32\mmcfx
2008-04-14 01:11:58 95744 ( A.... ) "C:\WINDOWS\system32\mqsec
2008-04-14 01:11:58 89088 ( A.... ) "C:\WINDOWS\system32\mqlog
2008-04-14 01:11:58 87040 ( A.... ) "C:\WINDOWS\system32\mprap
2008-04-14 01:11:58 86016 ( A.... ) "C:\WINDOWS\system32\msaps
2008-04-14 01:11:58 73728 ( A.... ) "C:\WINDOWS\system32\mscms
2008-04-14 01:11:58 71680 ( A.... ) "C:\WINDOWS\system32\msacm
2008-04-14 01:11:58 69632 ( A.... ) "C:\WINDOWS\system32\mscon
2008-04-14 01:11:58 68608 ( A.... ) "C:\WINDOWS\system32\msctf
2008-04-14 01:11:58 61440 ( A.... ) "C:\WINDOWS\system32\mmcsh
2008-04-14 01:11:58 60928 ( A.... ) "C:\WINDOWS\system32\migli
2008-04-14 01:11:58 59904 ( A.... ) "C:\WINDOWS\system32\mpr.d
2008-04-14 01:11:58 57344 ( A.... ) "C:\WINDOWS\system32\msasn
2008-04-14 01:11:58 53248 ( A.... ) "C:\WINDOWS\system32\mprdi
2008-04-14 01:11:58 49152 ( A.... ) "C:\WINDOWS\system32\mqupg
2008-04-14 01:11:58 47616 ( A.... ) "C:\WINDOWS\system32\mqdsc
2008-04-14 01:11:58 36864 ( A.... ) "C:\WINDOWS\system32\mscpx
2008-04-14 01:11:58 34560 ( A.... ) "C:\WINDOWS\system32\mnmdd
2008-04-14 01:11:58 29696 ( A.... ) "C:\WINDOWS\system32\mimef
2008-04-14 01:11:58 18944 ( A.... ) "C:\WINDOWS\system32\midim
2008-04-14 01:11:58 17408 ( A.... ) "C:\WINDOWS\system32\mmfut
2008-04-14 01:11:58 16896 ( A.... ) "C:\WINDOWS\system32\mqise
2008-04-14 01:11:56 2061824 ( A.... ) "C:\WINDOWS\system32\mstsc
2008-04-14 01:11:56 1028096 ( A.... ) "C:\WINDOWS\system32\mfc42
2008-04-14 01:11:56 989696 ( A.... ) "C:\WINDOWS\system32\kerne
2008-04-14 01:11:56 927504 ( A.... ) "C:\WINDOWS\system32\mfc40
2008-04-14 01:11:56 755200 ( A.... ) "C:\WINDOWS\system32\ir50_
2008-04-14 01:11:56 728064 ( A.... ) "C:\WINDOWS\system32\lsasr
2008-04-14 01:11:56 512000 ( A.... ) "C:\WINDOWS\system32\jscri
2008-04-14 01:11:56 399872 ( A.... ) "C:\WINDOWS\system32\lmrt.
2008-04-14 01:11:56 384000 ( A.... ) "C:\WINDOWS\system32\ipsms
2008-04-14 01:11:56 349696 ( A.... ) "C:\WINDOWS\system32\ipsec
2008-04-14 01:11:56 343040 ( A.... ) "C:\WINDOWS\system32\local
2008-04-14 01:11:56 338432 ( A.... ) "C:\WINDOWS\system32\ir41_
2008-04-14 01:11:56 331264 ( A.... ) "C:\WINDOWS\system32\ipnat
2008-04-14 01:11:56 330752 ( A.... ) "C:\WINDOWS\system32\ippro
2008-04-14 01:11:56 299520 ( A.... ) "C:\WINDOWS\system32\kerbe
2008-04-14 01:11:56 221696 ( A.... ) "C:\WINDOWS\system32\local
2008-04-14 01:11:56 200192 ( A.... ) "C:\WINDOWS\system32\ir50_
2008-04-14 01:11:56 191488 ( A.... ) "C:\WINDOWS\system32\iueng
2008-04-14 01:11:56 183808 ( A.... ) "C:\WINDOWS\system32\ir50_
2008-04-14 01:11:56 183808 ( A.... ) "C:\WINDOWS\system32\ipsec
2008-04-14 01:11:56 177152 ( A.... ) "C:\WINDOWS\system32\iprtr
2008-04-14 01:11:56 163840 ( A.... ) "C:\WINDOWS\system32\jgdw4
2008-04-14 01:11:56 161280 ( A.... ) "C:\WINDOWS\system32\ipmon
2008-04-14 01:11:56 155136 ( A.... ) "C:\WINDOWS\system32\itirc
2008-04-14 01:11:56 150528 ( A.... ) "C:\WINDOWS\system32\keymg
2008-04-14 01:11:56 147456 ( A.... ) "C:\WINDOWS\system32\initp
2008-04-14 01:11:56 138240 ( A.... ) "C:\WINDOWS\system32\itss.
2008-04-14 01:11:56 123392 ( A.... ) "C:\WINDOWS\system32\input
2008-04-14 01:11:56 120320 ( A.... ) "C:\WINDOWS\system32\ir41_
2008-04-14 01:11:56 118272 ( A.... ) "C:\WINDOWS\system32\mdmin
2008-04-14 01:11:56 97280 ( A.... ) "C:\WINDOWS\system32\loadp
2008-04-14 01:11:56 94720 ( A.... ) "C:\WINDOWS\system32\iphlp
2008-04-14 01:11:56 86016 ( A.... ) "C:\WINDOWS\system32\mdmxs
2008-04-14 01:11:56 84480 ( A.... ) "C:\WINDOWS\system32\mciav
2008-04-14 01:11:56 81920 ( A.... ) "C:\WINDOWS\system32\isign
2008-04-14 01:11:56 75264 ( A.... ) "C:\WINDOWS\system32\inetp
2008-04-14 01:11:56 61440 ( A.... ) "C:\WINDOWS\system32\kmsvc
2008-04-14 01:11:56 59904 ( A.... ) "C:\WINDOWS\system32\ipv6m
2008-04-14 01:11:56 58880 ( A.... ) "C:\WINDOWS\system32\licwm
2008-04-14 01:11:56 54272 ( A.... ) "C:\WINDOWS\system32\ixsso
2008-04-14 01:11:56 47616 ( A.... ) "C:\WINDOWS\system32\iyuv_
2008-04-14 01:11:56 40960 ( A.... ) "C:\WINDOWS\system32\mf321
2008-04-14 01:11:56 37376 ( A.... ) "C:\WINDOWS\system32\l2gps
2008-04-14 01:11:56 35328 ( A.... ) "C:\WINDOWS\system32\mciqt
2008-04-14 01:11:56 33792 ( A.... ) "C:\WINDOWS\system32\lmmib
2008-04-14 01:11:56 32768 ( A.... ) "C:\WINDOWS\system32\isrdb
2008-04-14 01:11:56 32768 ( A.... ) "C:\WINDOWS\system32\inetm
2008-04-14 01:11:56 27648 ( A.... ) "C:\WINDOWS\system32\jgpl4
2008-04-14 01:11:56 23552 ( A.... ) "C:\WINDOWS\system32\mciwa
2008-04-14 01:11:56 23040 ( A.... ) "C:\WINDOWS\system32\mcise
2008-04-14 01:11:56 22528 ( A.... ) "C:\WINDOWS\system32\mfcsu
2008-04-14 01:11:56 22016 ( A.... ) "C:\WINDOWS\system32\lpk.d
2008-04-14 01:11:56 22016 ( A.... ) "C:\WINDOWS\system32\ipxwa
2008-04-14 01:11:56 19968 ( A.... ) "C:\WINDOWS\system32\linki
2008-04-14 01:11:56 15872 ( A.... ) "C:\WINDOWS\system32\inetp
2008-04-14 01:11:56 14848 ( A.... ) "C:\WINDOWS\system32\mgmta
2008-04-14 01:11:56 14336 ( A.... ) "C:\WINDOWS\system32\mcast
2008-04-14 01:11:56 13824 ( A.... ) "C:\WINDOWS\system32\lmhsv
2008-04-14 01:11:56 13312 ( A.... ) "C:\WINDOWS\system32\infoa
2008-04-14 01:11:56 11776 ( A.... ) "C:\WINDOWS\system32\local
2008-04-14 01:11:56 10240 ( A.... ) "C:\WINDOWS\system32\lprhe
2008-04-14 01:11:56 4096 ( A.... ) "C:\WINDOWS\system32\ksuse
2008-04-14 01:11:54 1082368 ( A.... ) "C:\WINDOWS\system32\esent
2008-04-14 01:11:54 702845 ( A.... ) "C:\WINDOWS\system32\i81xd
2008-04-14 01:11:54 691712 ( A.... ) "C:\WINDOWS\system32\inetc
2008-04-14 01:11:54 614912 ( A.... ) "C:\WINDOWS\system32\h323m
2008-04-14 01:11:54 382976 ( A.... ) "C:\WINDOWS\system32\fonte
2008-04-14 01:11:54 380445 ( A.... ) "C:\WINDOWS\system32\expsr
2008-04-14 01:11:54 347136 ( A.... ) "C:\WINDOWS\system32\hyper
2008-04-14 01:11:54 344064 ( A.... ) "C:\WINDOWS\system32\hnetc
2008-04-14 01:11:54 337920 ( A.... ) "C:\WINDOWS\system32\filem
2008-04-14 01:11:54 330752 ( A.... ) "C:\WINDOWS\system32\hnetw
2008-04-14 01:11:54 285184 ( A.... ) "C:\WINDOWS\system32\gdi32
2008-04-14 01:11:54 274432 ( A.... ) "C:\WINDOWS\system32\inetc
2008-04-14 01:11:54 254976 ( A.... ) "C:\WINDOWS\system32\icm32
2008-04-14 01:11:54 246272 ( A.... ) "C:\WINDOWS\system32\es.dl
2008-04-14 01:11:54 199680 ( A.... ) "C:\WINDOWS\system32\gptex
2008-04-14 01:11:54 186880 ( A.... ) "C:\WINDOWS\system32\encde
2008-04-14 01:11:54 183296 ( A.... ) "C:\WINDOWS\system32\els.d
2008-04-14 01:11:54 144896 ( A.... ) "C:\WINDOWS\system32\hotpl
2008-04-14 01:11:54 144384 ( A.... ) "C:\WINDOWS\system32\image
2008-04-14 01:11:54 135680 ( A.... ) "C:\WINDOWS\system32\ifmon
2008-04-14 01:11:54 133632 ( A.... ) "C:\WINDOWS\system32\iisrt
2008-04-14 01:11:54 125952 ( A.... ) "C:\WINDOWS\system32\exts.
2008-04-14 01:11:54 124928 ( A.... ) "C:\WINDOWS\system32\fde.d
2008-04-14 01:11:54 122880 ( A.... ) "C:\WINDOWS\system32\glu32
2008-04-14 01:11:54 120832 ( A.... ) "C:\WINDOWS\system32\idq.d
2008-04-14 01:11:54 119808 ( A.... ) "C:\WINDOWS\system32\iasra
2008-04-14 01:11:54 110080 ( A.... ) "C:\WINDOWS\system32\imm32
2008-04-14 01:11:54 87552 ( A.... ) "C:\WINDOWS\system32\fldrc
2008-04-14 01:11:54 81920 ( A.... ) "C:\WINDOWS\system32\ils.d
2008-04-14 01:11:54 81920 ( A.... ) "C:\WINDOWS\system32\ieenc
2008-04-14 01:11:54 80896 ( A.... ) "C:\WINDOWS\system32\fonts
2008-04-14 01:11:54 80384 ( A.... ) "C:\WINDOWS\system32\iccvi
2008-04-14 01:11:54 80384 ( A.... ) "C:\WINDOWS\system32\fault
2008-04-14 01:11:54 73728 ( A.... ) "C:\WINDOWS\system32\icwdi
2008-04-14 01:11:54 73728 ( A.... ) "C:\WINDOWS\system32\fdepl
2008-04-14 01:11:54 72704 ( A.... ) "C:\WINDOWS\system32\hlink
2008-04-14 01:11:54 68608 ( A.... ) "C:\WINDOWS\system32\iisex
2008-04-14 01:11:54 65536 ( A.... ) "C:\WINDOWS\system32\icwph
2008-04-14 01:11:54 64512 ( A.... ) "C:\WINDOWS\system32\iisma
2008-04-14 01:11:54 60416 ( A.... ) "C:\WINDOWS\system32\fwcfg
2008-04-14 01:11:54 56320 ( A.... ) "C:\WINDOWS\system32\event
2008-04-14 01:11:54 41984 ( A.... ) "C:\WINDOWS\system32\htui.
2008-04-14 01:11:54 41472 ( A.... ) "C:\WINDOWS\system32\hhset
2008-04-14 01:11:54 36921 ( A.... ) "C:\WINDOWS\system32\imesh
2008-04-14 01:11:54 32285 ( A.... ) "C:\WINDOWS\system32\hsfci
2008-04-14 01:11:54 24576 ( A.... ) "C:\WINDOWS\system32\httpa
2008-04-14 01:11:54 23040 ( A.... ) "C:\WINDOWS\system32\ersvc
2008-04-14 01:11:54 21504 ( A.... ) "C:\WINDOWS\system32\hidse
2008-04-14 01:11:54 21504 ( A.... ) "C:\WINDOWS\system32\fecli
2008-04-14 01:11:54 20992 ( A.... ) "C:\WINDOWS\system32\hid.d
2008-04-14 01:11:54 20480 ( A.... ) "C:\WINDOWS\system32\encap
2008-04-14 01:11:54 16896 ( A.... ) "C:\WINDOWS\system32\fltli
2008-04-14 01:11:54 14336 ( A.... ) "C:\WINDOWS\system32\exstr
2008-04-14 01:11:54 11264 ( A.... ) "C:\WINDOWS\system32\icaap
2008-04-14 01:11:54 8192 ( A.... ) "C:\WINDOWS\system32\igmpa
2008-04-14 01:11:54 7168 ( A.... ) "C:\WINDOWS\system32\hccoi
2008-04-14 01:11:52 2113536 ( A.... ) "C:\WINDOWS\system32\dxdia
2008-04-14 01:11:52 1689088 ( A.... ) "C:\WINDOWS\system32\d3d9.
2008-04-14 01:11:52 1504256 ( A.... ) "C:\WINDOWS\system32\diskc
2008-04-14 01:11:52 1293824 ( A.... ) "C:\WINDOWS\system32\dsoun
2008-04-14 01:11:52 1267200 ( A.... ) "C:\WINDOWS\system32\comsv
2008-04-14 01:11:52 1227264 ( A.... ) "C:\WINDOWS\system32\dx8vb
2008-04-14 01:11:52 1179648 ( A.... ) "C:\WINDOWS\system32\d3d8.
2008-04-14 01:11:52 1054208 ( A.... ) "C:\WINDOWS\system32\danim
2008-04-14 01:11:52 824320 ( A.... ) "C:\WINDOWS\system32\d3dim
2008-04-14 01:11:52 792064 ( A.... ) "C:\WINDOWS\system32\comre
2008-04-14 01:11:52 650752 ( A.... ) "C:\WINDOWS\system32\dot3u
2008-04-14 01:11:52 640000 ( A.... ) "C:\WINDOWS\system32\dbghe
2008-04-14 01:11:52 619008 ( A.... ) "C:\WINDOWS\system32\dx7vb
2008-04-14 01:11:52 617472 ( A.... ) "C:\WINDOWS\system32\comct
2008-04-14 01:11:52 599040 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 539648 ( A.... ) "C:\WINDOWS\system32\comui
2008-04-14 01:11:52 512512 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 498742 ( A.... ) "C:\WINDOWS\system32\dxmas
2008-04-14 01:11:52 379904 ( A.... ) "C:\WINDOWS\system32\dhcpm
2008-04-14 01:11:52 375296 ( A.... ) "C:\WINDOWS\system32\dpnet
2008-04-14 01:11:52 367616 ( A.... ) "C:\WINDOWS\system32\dsoun
2008-04-14 01:11:52 357888 ( A.... ) "C:\WINDOWS\system32\confm
2008-04-14 01:11:52 326656 ( A.... ) "C:\WINDOWS\system32\cscui
2008-04-14 01:11:52 304128 ( A.... ) "C:\WINDOWS\system32\duser
2008-04-14 01:11:52 285184 ( A.... ) "C:\WINDOWS\system32\dmdlg
2008-04-14 01:11:52 282624 ( A.... ) "C:\WINDOWS\system32\devmg
2008-04-14 01:11:52 279552 ( A.... ) "C:\WINDOWS\system32\ddraw
2008-04-14 01:11:52 276992 ( A.... ) "C:\WINDOWS\system32\comdl
2008-04-14 01:11:52 252928 ( A.... ) "C:\WINDOWS\system32\compa
2008-04-14 01:11:52 239104 ( A.... ) "C:\WINDOWS\system32\dsque
2008-04-14 01:11:52 229888 ( A.... ) "C:\WINDOWS\system32\dplay
2008-04-14 01:11:52 229376 ( A.... ) "C:\WINDOWS\system32\comps
2008-04-14 01:11:52 212480 ( A.... ) "C:\WINDOWS\system32\dpvoi
2008-04-14 01:11:52 200704 ( A.... ) "C:\WINDOWS\system32\dmdsk
2008-04-14 01:11:52 184832 ( A.... ) "C:\WINDOWS\system32\eapp3
2008-04-14 01:11:52 181760 ( A.... ) "C:\WINDOWS\system32\dinpu
2008-04-14 01:11:52 181248 ( A.... ) "C:\WINDOWS\system32\dsdmo
2008-04-14 01:11:52 181248 ( A.... ) "C:\WINDOWS\system32\dmime
2008-04-14 01:11:52 180224 ( A.... ) "C:\WINDOWS\system32\eapph
2008-04-14 01:11:52 167424 ( A.... ) "C:\WINDOWS\system32\comsn
2008-04-14 01:11:52 165376 ( A.... ) "C:\WINDOWS\system32\datim
2008-04-14 01:11:52 163840 ( A.... ) "C:\WINDOWS\system32\credu
2008-04-14 01:11:52 158720 ( A.... ) "C:\WINDOWS\system32\dinpu
2008-04-14 01:11:52 155648 ( A.... ) "C:\WINDOWS\system32\dskqu
2008-04-14 01:11:52 147968 ( A.... ) "C:\WINDOWS\system32\dnsap
2008-04-14 01:11:52 142848 ( A.... ) "C:\WINDOWS\system32\dspro
2008-04-14 01:11:52 132096 ( A.... ) "C:\WINDOWS\system32\dot3s
2008-04-14 01:11:52 126976 ( A.... ) "C:\WINDOWS\system32\eappc
2008-04-14 01:11:52 126976 ( A.... ) "C:\WINDOWS\system32\dhcpc
2008-04-14 01:11:52 124416 ( A.... ) "C:\WINDOWS\system32\dfrgu
2008-04-14 01:11:52 116736 ( A.... ) "C:\WINDOWS\system32\dpvvo
2008-04-14 01:11:52 113152 ( A.... ) "C:\WINDOWS\system32\dsuie
2008-04-14 01:11:52 111104 ( A.... ) "C:\WINDOWS\system32\dgnet
2008-04-14 01:11:52 110592 ( A.... ) "C:\WINDOWS\system32\dbnet
2008-04-14 01:11:52 105984 ( A.... ) "C:\WINDOWS\system32\dmsty
2008-04-14 01:11:52 104448 ( A.... ) "C:\WINDOWS\system32\dmusi
2008-04-14 01:11:52 103424 ( A.... ) "C:\WINDOWS\system32\dmsyn
2008-04-14 01:11:52 102912 ( A.... ) "C:\WINDOWS\system32\dpcdl
2008-04-14 01:11:52 101888 ( A.... ) "C:\WINDOWS\system32\cscdl
2008-04-14 01:11:52 97792 ( A.... ) "C:\WINDOWS\system32\comre
2008-04-14 01:11:52 94208 ( A.... ) "C:\WINDOWS\system32\eappg
2008-04-14 01:11:52 92672 ( A.... ) "C:\WINDOWS\system32\dskqu
2008-04-14 01:11:52 82432 ( A.... ) "C:\WINDOWS\system32\dmscr
2008-04-14 01:11:52 74752 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 71680 ( A.... ) "C:\WINDOWS\system32\dsdmo
2008-04-14 01:11:52 68608 ( A.... ) "C:\WINDOWS\system32\diges
2008-04-14 01:11:52 64512 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 62464 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 61440 ( A.... ) "C:\WINDOWS\system32\dmcom
2008-04-14 01:11:52 60928 ( A.... ) "C:\WINDOWS\system32\dpnhu
2008-04-14 01:11:52 60416 ( A.... ) "C:\WINDOWS\system32\colba
2008-04-14 01:11:52 59904 ( A.... ) "C:\WINDOWS\system32\deven
2008-04-14 01:11:52 59392 ( A.... ) "C:\WINDOWS\system32\eapqe
2008-04-14 01:11:52 57856 ( A.... ) "C:\WINDOWS\system32\dot3c
2008-04-14 01:11:52 57344 ( A.... ) "C:\WINDOWS\system32\dpwso
2008-04-14 01:11:52 56320 ( A.... ) "C:\WINDOWS\system32\dot3m
2008-04-14 01:11:52 54272 ( A.... ) "C:\WINDOWS\system32\datac
2008-04-14 01:11:52 53760 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 52224 ( A.... ) "C:\WINDOWS\system32\dmuti
2008-04-14 01:11:52 51200 ( A.... ) "C:\WINDOWS\system32\dssec
2008-04-14 01:11:52 48640 ( A.... ) "C:\WINDOWS\system32\dhcpq
2008-04-14 01:11:52 48128 ( A.... ) "C:\WINDOWS\system32\docpr
2008-04-14 01:11:52 45568 ( A.... ) "C:\WINDOWS\system32\dnsrs
2008-04-14 01:11:52 40960 ( A.... ) "C:\WINDOWS\system32\eappp
2008-04-14 01:11:52 39936 ( A.... ) "C:\WINDOWS\system32\dot3g
2008-04-14 01:11:52 39936 ( A.... ) "C:\WINDOWS\system32\dimsr
2008-04-14 01:11:52 39424 ( A.... ) "C:\WINDOWS\system32\dfrgs
2008-04-14 01:11:52 35840 ( A.... ) "C:\WINDOWS\system32\dmloa
2008-04-14 01:11:52 35328 ( A.... ) "C:\WINDOWS\system32\dpnhp
2008-04-14 01:11:52 35328 ( ..... ) "C:\WINDOWS\system32\corpo
2008-04-14 01:11:52 33792 ( A.... ) "C:\WINDOWS\system32\eapsv
2008-04-14 01:11:52 33280 ( A.... ) "C:\WINDOWS\system32\crypt
2008-04-14 01:11:52 32768 ( A.... ) "C:\WINDOWS\system32\dispe
2008-04-14 01:11:52 32256 ( A.... ) "C:\WINDOWS\system32\csrsr
2008-04-14 01:11:52 30720 ( A.... ) "C:\WINDOWS\system32\eapol
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dmban
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dfssh
2008-04-14 01:11:52 28672 ( A.... ) "C:\WINDOWS\system32\dbnmp
2008-04-14 01:11:52 28160 ( A.... ) "C:\WINDOWS\system32\comad
2008-04-14 01:11:52 27136 ( A.... ) "C:\WINDOWS\system32\ddraw
2008-04-14 01:11:52 26624 ( A.... ) "C:\WINDOWS\system32\efsad
2008-04-14 01:11:52 26112 ( A.... ) "C:\WINDOWS\system32\dot3a
2008-04-14 01:11:52 25088 ( A.... ) "C:\WINDOWS\system32\davcl
2008-04-14 01:11:52 24576 ( A.... ) "C:\WINDOWS\system32\dbmsr
2008-04-14 01:11:52 23552 ( A.... ) "C:\WINDOWS\system32\dpmod
2008-04-14 01:11:52 23552 ( A.... ) "C:\WINDOWS\system32\dmser
2008-04-14 01:11:52 21504 ( A.... ) "C:\WINDOWS\system32\dpvac
2008-04-14 01:11:52 19456 ( A.... ) "C:\WINDOWS\system32\dswav
2008-04-14 01:11:52 19456 ( A.... ) "C:\WINDOWS\system32\dimsn
2008-04-14 01:11:52 16384 ( A.... ) "C:\WINDOWS\system32\ds32g
2008-04-14 01:11:52 14336 ( A.... ) "C:\WINDOWS\system32\drpro
2008-04-14 01:11:52 12800 ( A.... ) "C:\WINDOWS\system32\creds
2008-04-14 01:11:52 9216 ( A.... ) "C:\WINDOWS\system32\dot3d
2008-04-14 01:11:52 8704 ( A.... ) "C:\WINDOWS\system32\dcima
2008-04-14 01:11:52 8192 ( A.... ) "C:\WINDOWS\system32\d3d8t
2008-04-14 01:11:50 2091520 ( A.... ) "C:\WINDOWS\system32\cdosy
2008-04-14 01:11:50 1888992 ( A.... ) "C:\WINDOWS\system32\ati3d
2008-04-14 01:11:50 1025024 ( A.... ) "C:\WINDOWS\system32\brows
2008-04-14 01:11:50 870784 ( A.... ) "C:\WINDOWS\system32\ati3d
2008-04-14 01:11:50 625664 ( A.... ) "C:\WINDOWS\system32\catsr
2008-04-14 01:11:50 516768 ( A.... ) "C:\WINDOWS\system32\ativv
2008-04-14 01:11:50 498688 ( A.... ) "C:\WINDOWS\system32\clbca
2008-04-14 01:11:50 457728 ( A.... ) "C:\WINDOWS\system32\certm
2008-04-14 01:11:50 377984 ( A.... ) "C:\WINDOWS\system32\ati2d
2008-04-14 01:11:50 344064 ( A.... ) "C:\WINDOWS\system32\cmdia
2008-04-14 01:11:50 295936 ( A.... ) "C:\WINDOWS\system32\appmg
2008-04-14 01:11:50 233472 ( A.... ) "C:\WINDOWS\system32\azrol
2008-04-14 01:11:50 229376 ( A.... ) "C:\WINDOWS\system32\ati2c
2008-04-14 01:11:50 226304 ( A.... ) "C:\WINDOWS\system32\catsr
2008-04-14 01:11:50 201728 ( A.... ) "C:\WINDOWS\system32\ati2d
2008-04-14 01:11:50 194560 ( A.... ) "C:\WINDOWS\system32\certc
2008-04-14 01:11:50 185344 ( A.... ) "C:\WINDOWS\system32\cmpro
2008-04-14 01:11:50 167936 ( A.... ) "C:\WINDOWS\system32\appmg
2008-04-14 01:11:50 151040 ( A.... ) "C:\WINDOWS\system32\cdfvi
2008-04-14 01:11:50 150016 ( A.... ) "C:\WINDOWS\system32\capes
2008-04-14 01:11:50 148480 ( A.... ) "C:\WINDOWS\system32\cic.d
2008-04-14 01:11:50 125952 ( A.... ) "C:\WINDOWS\system32\apphe
2008-04-14 01:11:50 110592 ( A.... ) "C:\WINDOWS\system32\clbca
2008-04-14 01:11:50 85504 ( A.... ) "C:\WINDOWS\system32\catsr
2008-04-14 01:11:50 84992 ( A.... ) "C:\WINDOWS\system32\avifi
2008-04-14 01:11:50 84480 ( A.... ) "C:\WINDOWS\system32\cabvi
2008-04-14 01:11:50 78336 ( A.... ) "C:\WINDOWS\system32\brows
2008-04-14 01:11:50 77824 ( A.... ) "C:\WINDOWS\system32\clico
2008-04-14 01:11:50 77824 ( A.... ) "C:\WINDOWS\system32\brows
2008-04-14 01:11:50 70656 ( A.... ) "C:\WINDOWS\system32\amstr
2008-04-14 01:11:50 69120 ( A.... ) "C:\WINDOWS\system32\ciodm
2008-04-14 01:11:50 65024 ( A.... ) "C:\WINDOWS\system32\asycf
2008-04-14 01:11:50 62464 ( A.... ) "C:\WINDOWS\system32\authz
2008-04-14 01:11:50 60416 ( A.... ) "C:\WINDOWS\system32\cabin
2008-04-14 01:11:50 58880 ( A.... ) "C:\WINDOWS\system32\atl.d
2008-04-14 01:11:50 58368 ( A.... ) "C:\WINDOWS\system32\clusa
2008-04-14 01:11:50 52736 ( A.... ) "C:\WINDOWS\system32\bases
2008-04-14 01:11:50 50688 ( A.... ) "C:\WINDOWS\system32\camoc
2008-04-14 01:11:50 50688 ( A.... ) "C:\WINDOWS\system32\btpan
2008-04-14 01:11:50 47104 ( A.... ) "C:\WINDOWS\system32\cnbjm
2008-04-14 01:11:50 42496 ( A.... ) "C:\WINDOWS\system32\audio
2008-04-14 01:11:50 39424 ( A.... ) "C:\WINDOWS\system32\cmuti
2008-04-14 01:11:50 38912 ( A.... ) "C:\WINDOWS\system32\cfgbk
2008-04-14 01:11:50 32768 ( A.... ) "C:\WINDOWS\system32\ativt
2008-04-14 01:11:50 30208 ( A.... ) "C:\WINDOWS\system32\bthse
2008-04-14 01:11:50 30208 ( A.... ) "C:\WINDOWS\system32\atmli
2008-04-14 01:11:50 29184 ( A.... ) "C:\WINDOWS\system32\batme
2008-04-14 01:11:50 20992 ( A.... ) "C:\WINDOWS\system32\bthci
2008-04-14 01:11:50 17408 ( A.... ) "C:\WINDOWS\system32\bidis
2008-04-14 01:11:50 17408 ( A.... ) "C:\WINDOWS\system32\alrsv
2008-04-14 01:11:50 15872 ( A.... ) "C:\WINDOWS\system32\cmcfg
2008-04-14 01:11:50 13312 ( A.... ) "C:\WINDOWS\system32\cmset
2008-04-14 01:11:50 8704 ( A.... ) "C:\WINDOWS\system32\batt.
2008-04-14 01:11:50 8192 ( A.... ) "C:\WINDOWS\system32\bitsp
2008-04-14 01:11:50 7168 ( A.... ) "C:\WINDOWS\system32\bitsp
2008-04-14 01:11:50 7168 ( A.... ) "C:\WINDOWS\system32\bitsp
2008-04-14 01:11:48 617472 ( A.... ) "C:\WINDOWS\system32\advap
2008-04-14 01:11:48 290816 ( A.... ) "C:\WINDOWS\system32\adsii
2008-04-14 01:11:48 263680 ( A.... ) "C:\WINDOWS\system32\adsnt
2008-04-14 01:11:48 193536 ( A.... ) "C:\WINDOWS\system32\activ
2008-04-14 01:11:48 175616 ( A.... ) "C:\WINDOWS\system32\adsld
2008-04-14 01:11:48 143360 ( A.... ) "C:\WINDOWS\system32\adsld
2008-04-14 01:11:48 136192 ( A.... ) "C:\WINDOWS\system32\aacli
2008-04-14 01:11:48 123392 ( A.... ) "C:\WINDOWS\system32\adsnw
2008-04-14 01:11:48 115712 ( A.... ) "C:\WINDOWS\system32\aclui
2008-04-14 01:11:48 100352 ( A.... ) "C:\WINDOWS\system32\6to4s
2008-04-14 01:11:48 98304 ( A.... ) "C:\WINDOWS\system32\actxp
2008-04-14 01:11:48 68096 ( A.... ) "C:\WINDOWS\system32\adsms
2008-04-14 01:11:48 43520 ( A.... ) "C:\WINDOWS\system32\admwp
2008-04-14 01:11:24 706048 ( A.... ) "C:\WINDOWS\system32\ntdll
2008-04-14 01:11:16 5632 ( A.... ) "C:\WINDOWS\system32\wmi.d
2008-04-14 01:11:12 756224 ( A.... ) "C:\WINDOWS\system32\winnt
2008-04-14 01:11:10 24064 ( A.... ) "C:\WINDOWS\system32\pidge
2008-04-14 01:10:32 53279 ( A.... ) "C:\WINDOWS\system32\odbcj
2008-04-14 01:10:08 4126 ( A.... ) "C:\WINDOWS\system32\msdxm
2008-04-14 01:10:06 3584 ( A.... ) "C:\WINDOWS\system32\msafd
2008-04-14 01:09:56 7680 ( A.... ) "C:\WINDOWS\system32\kbdsm
2008-04-14 01:09:56 7680 ( A.... ) "C:\WINDOWS\system32\kbdsm
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbduk
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdno
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdne
2008-04-14 01:09:56 7168 ( A.... ) "C:\WINDOWS\system32\kbdfi
2008-04-14 01:09:56 6656 ( A.... ) "C:\WINDOWS\system32\kbdin
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdpa
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdne
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdml
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdml
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdiu
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdin
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdin
2008-04-14 01:09:56 6144 ( A.... ) "C:\WINDOWS\system32\kbdbh
2008-04-14 01:09:56 5632 ( A.... ) "C:\WINDOWS\system32\kbdma
2008-04-14 01:09:40 3584 ( A.... ) "C:\WINDOWS\system32\icmp.
2008-04-14 01:09:36 566784 ( A.... ) "C:\WINDOWS\system32\gpedi
2008-04-14 01:09:34 9344 ( A.... ) "C:\WINDOWS\system32\frame
2008-04-14 01:09:20 3072 ( A.... ) "C:\WINDOWS\system32\dpnlo
2008-04-14 01:09:20 3072 ( A.... ) "C:\WINDOWS\system32\dpnad
2008-04-14 01:09:06 16896 ( A.... ) "C:\WINDOWS\system32\cfgmg
2008-04-14 01:09:02 285696 ( A.... ) "C:\WINDOWS\system32\atmfd
2008-04-13 20:30:10 1845632 ( A.... ) "C:\WINDOWS\system32\win32
2008-04-13 20:24:38 2145280 ( A.... ) "C:\WINDOWS\system32\ntosk
2008-04-13 19:45:00 17664 ( A.... ) "C:\WINDOWS\system32\watch
2008-04-13 19:43:32 12800 ( A.... ) "C:\WINDOWS\system32\spiis
2008-04-13 19:43:32 9728 ( A.... ) "C:\WINDOWS\system32\comsd
2008-04-13 19:31:36 7424 ( A.... ) "C:\WINDOWS\system32\kd139
2008-04-13 19:31:28 134400 ( A.... ) "C:\WINDOWS\system32\HAL.D
2008-04-13 19:31:22 2023936 ( A.... ) "C:\WINDOWS\system32\ntkrn
2008-04-13 19:30:46 61440 ( A.... ) "C:\WINDOWS\system32\Msvcr
2008-04-13 19:14:58 76800 ( A.... ) "C:\WINDOWS\system32\mssha
2008-04-13 18:39:30 438784 ( A.... ) "C:\WINDOWS\system32\xpob2
2008-04-13 18:39:26 689152 ( A.... ) "C:\WINDOWS\system32\xpsp3
2008-04-13 18:39:24 2897920 ( A.... ) "C:\WINDOWS\system32\xpsp2
2008-04-13 18:39:22 187392 ( A.... ) "C:\WINDOWS\system32\xpsp1
2008-04-13 18:37:58 208384 ( A.... ) "C:\WINDOWS\system32\rsaen
2008-04-13 18:37:58 138752 ( A.... ) "C:\WINDOWS\system32\dssen
2008-04-13 18:27:18 79872 ( A.... ) "C:\WINDOWS\system32\msxml
2008-04-13 18:26:08 12288 ( A.... ) "C:\WINDOWS\system32\mscpx
2008-04-13 18:26:06 94208 ( A.... ) "C:\WINDOWS\system32\odbci
2008-04-13 18:26:06 12288 ( A.... ) "C:\WINDOWS\system32\odbcp
2008-04-13 18:24:14 20480 ( A.... ) "C:\WINDOWS\system32\msorc
2008-04-13 18:21:32 733696 ( A.... ) "C:\WINDOWS\system32\qedwi
2008-04-13 18:09:30 4096 ( A.... ) "C:\WINDOWS\system32\dsprp
2008-04-13 18:03:24 63488 ( A.... ) "C:\WINDOWS\system32\brows
2008-04-13 18:03:20 549376 ( A.... ) "C:\WINDOWS\system32\shdoc
2008-04-13 17:48:54 1647616 ( A.... ) "C:\WINDOWS\system32\winbr
2008-04-13 17:45:30 216064 ( A.... ) "C:\WINDOWS\system32\moric
2008-04-13 17:23:32 48128 ( A.... ) "C:\WINDOWS\system32\mspri
2008-04-13 17:22:12 48128 ( A.... ) "C:\WINDOWS\system32\inetr
2008-04-13 16:39:44 884736 ( A.... ) "C:\WINDOWS\system32\msims
((((((((((((((((((((((((((
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\softwa
"IgfxTray"="C:\\WINDOWS\\s
"HotKeysCmds"="C:\\WINDOWS
"Persistence"="C:\\WINDOWS
"SoundMAXPnP"="C:\\Program
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.e
"SetRefresh"="C:\\Program Files\\Compaq\\SetRefresh\
"Recguard"="C:\\WINDOWS\\S
"Reminder"="C:\\WINDOWS\\C
"Scheduler"="C:\\WINDOWS\\
"ShStatEXE"="\"C:\\Program
"McAfeeUpdaterUI"="\"C:\\P
"Adobe Reader Speed Launcher"="\"D:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe
"QuickTime Task"="\"D:\\Program Files\\QuickTime\\qttask.e
"iTunesHelper"="\"C:\\Prog
"HP Software Update"="D:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"Norton Ghost 14.0"="\"D:\\Program Files\\Norton Ghost\\Agent\\VProTray.exe
"4d2468f1"="rundll32.exe \"C:\\WINDOWS\\system32\\m
"BM4e175b6d"="Rundll32.exe
[HKEY_LOCAL_MACHINE\softwa
@=""
[HKEY_LOCAL_MACHINE\softwa
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\softwa
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\softwa
"Installed"="1"
@=""
[HKEY_CURRENT_USER\softwar
"ctfmon.exe"="C:\\WINDOWS\
[HKEY_USERS\.default\softw
"CTFMON.EXE"="C:\\WINDOWS\
"Spyware Doctor"="\"d:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\.default\softw
"NoDriveTypeAutoRun"=dword
[HKEY_USERS\s-1-5-18\softw
"CTFMON.EXE"="C:\\WINDOWS\
"Spyware Doctor"="\"d:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\softw
"NoDriveTypeAutoRun"=dword
[HKEY_LOCAL_MACHINE\softwa
"{438755C2-A8BA-11D1-B96B-
"{8C7461EF-2B13-11d2-BE35-
[HKEY_LOCAL_MACHINE\softwa
"{AEB6717E-7E19-11d0-97EE-
"{56F9679E-7826-4C84-81F3-
"{427B37EF-B6C5-4823-A97C-
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoft
Completion time: 03/07/2008 12:16:38.67
ComboFix ver 06.06.17 - This logfile is located at C:\ComboFix.txt
ASKER
And here is the HiJackThis log, in full this time. Thanks for the help so far
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:52, on 03/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\csrss. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
D:\Program Files\Lavasoft\Ad-Aware\aa wservice.e xe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e xe
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\inetsr v\inetinfo .exe
C:\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex e
C:\Program Files\McAfee\Common Framework\FrameworkService .exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\HPZipm 12.exe
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter .exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\dllhos t.exe
d:\Program Files\RealVNC\VNC4\WinVNC4 .exe
C:\WINDOWS\system32\Search Indexer.ex e
C:\Program Files\Exchsrvr\bin\exmgmt. exe
C:\WINDOWS\system32\dllhos t.exe
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn apService. exe
C:\WINDOWS\System32\alg.ex e
C:\WINDOWS\system32\msdtc. exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr ay.exe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxpe rs.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxsr vc.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\SMINST\Schedule r.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper. exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\rundll 32.exe
C:\WINDOWS\system32\Rundll 32.exe
C:\WINDOWS\system32\ctfmon .exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService .exe
D:\PROGRA~1\SPYWAR~1\swdoc tor.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
D:\Program Files\HP\Smart Web Printing\hpswp_clipbook.ex e
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\woyt\Desktop\HiJa ckThis.exe
C:\WINDOWS\system32\wbem\w miprvse.ex e
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\In ternet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5 8F732D338C 0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.d ll
O2 - BHO: (no name) - {05CD9087-92C0-44AC-B068-2 2257AA4B39 0} - C:\WINDOWS\system32\iifday ya.dll (file missing)
O2 - BHO: (no name) - {1C028F3B-5919-4041-815D-F 4836C4C6E6 6} - C:\WINDOWS\system32\rqRHxw VP.dll (file missing)
O2 - BHO: {4fdb7420-52c1-d03b-0d94-e 58b0e5d78b 3} - {3b87d5e0-b85e-49d0-b30d-1 c250247bdf 4} - C:\WINDOWS\system32\cerhem .dll
O2 - BHO: (no name) - {3C082AB6-E103-44BB-A3F3-D 745CDF9875 4} - C:\WINDOWS\system32\rqRLbX nl.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2 06D7942484 F} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D 426709BBFE B} - D:\PROGRA~1\SPYWAR~1\tools \iesdsg.dl l
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D 4DAF1D92D4 3} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5 164760863C 6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1 7DF180C71A C} - D:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd. exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe rs.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe " /tray
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se tRefresh.e xe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard .exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_ XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Schedule r.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "D:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [4d2468f1] rundll32.exe "C:\WINDOWS\system32\mihjb qcn.dll",b
O4 - HKLM\..\Run: [BM4e175b6d] Rundll32.exe "C:\WINDOWS\system32\hhwwj irm.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon .exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "d:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2 \Office12\ EXCEL.EXE/ 3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4 C56B4E14E8 4} - D:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-1 0282ABF65E 7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions. dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3 250410481E 8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions. dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D 32B190E9B0 7} - C:\Program Files\Skype\Toolbars\Inter net Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3 C9C571A826 3} - C:\PROGRA~1\MICROS~2\Offic e12\REFIEB AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5 8CAB36FD2A 2} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5 8CAB36FD2A 2} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {26700CD9-6157-4B72-B46F-E C93C952F19 C} (SWToolSet.Engine) - http://itapps:8080/SWToolset.exe
O16 - DPF: {6414512B-B978-451D-A0D8-F CFDF33E833 C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208301416265
O16 - DPF: {6E32070A-766D-4EE6-879C-D C1FA91D2FC 3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208362371890
O16 - DPF: {A90A5822-F108-45AD-8482-9 BC8B12DD53 9} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0 060082AA75 C} (GpcContainer Class) - https://synaptrismeetings.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O17 - HKLM\Software\..\Telephony : DomainName = radiotaxis.co.uk
O17 - HKLM\System\CS1\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O17 - HKLM\System\CS2\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1 830C7DD7F5 D} - C:\PROGRA~1\COMMON~1\Skype \SKYPE4~1. DLL
O20 - Winlogon Notify: winppp32 - C:\WINDOWS\SYSTEM32\winppp 32.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aa wservice.e xe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\ awhost32.e xe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex e
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU P~1\LUCOMS ~1.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService .exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel. exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm 12.exe
O23 - Service: Remote Task Manager service (RTM) - Unknown owner - d:\Program Files\Remote Task Manager\RTMService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - d:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSn apService. exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - d:\Program Files\RealVNC\VNC4\WinVNC4 .exe
--
End of file - 12415 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:52, on 03/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
D:\Program Files\Lavasoft\Ad-Aware\aa
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\inetsr
C:\Program Files\Common Files\InterVideo\RegMgr\iv
C:\Program Files\McAfee\Common Framework\FrameworkService
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\HPZipm
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\dllhos
d:\Program Files\RealVNC\VNC4\WinVNC4
C:\WINDOWS\system32\Search
C:\Program Files\Exchsrvr\bin\exmgmt.
C:\WINDOWS\system32\dllhos
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\msdtc.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\SMINST\Schedule
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\rundll
C:\WINDOWS\system32\Rundll
C:\WINDOWS\system32\ctfmon
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService
D:\PROGRA~1\SPYWAR~1\swdoc
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
D:\Program Files\HP\Smart Web Printing\hpswp_clipbook.ex
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\woyt\Desktop\HiJa
C:\WINDOWS\system32\wbem\w
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5
O2 - BHO: (no name) - {05CD9087-92C0-44AC-B068-2
O2 - BHO: (no name) - {1C028F3B-5919-4041-815D-F
O2 - BHO: {4fdb7420-52c1-d03b-0d94-e
O2 - BHO: (no name) - {3C082AB6-E103-44BB-A3F3-D
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Schedule
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "D:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [4d2468f1] rundll32.exe "C:\WINDOWS\system32\mihjb
O4 - HKLM\..\Run: [BM4e175b6d] Rundll32.exe "C:\WINDOWS\system32\hhwwj
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "d:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-1
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {26700CD9-6157-4B72-B46F-E
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {A90A5822-F108-45AD-8482-9
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
O20 - Winlogon Notify: winppp32 - C:\WINDOWS\SYSTEM32\winppp
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aa
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iv
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
O23 - Service: Remote Task Manager service (RTM) - Unknown owner - d:\Program Files\Remote Task Manager\RTMService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - d:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSn
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - d:\Program Files\RealVNC\VNC4\WinVNC4
--
End of file - 12415 bytes
There are vundo/conhook entries showing in the combofix log. The log seems to be missing the header, can you post the top part of the log?
Is that a fresh download of combofix? If not. please delete that one and download a fresh copy.
Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply along with a fresh HJT log
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Is that a fresh download of combofix? If not. please delete that one and download a fresh copy.
Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply along with a fresh HJT log
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I think the Combofix that you have there is an old one (2 years, right?)
Please download and run a fresh copy of Combofix.
Please download and run a fresh copy of Combofix.
ASKER
Thanks rpggamergirl, downloaded the latest version and ran it last night and have the log here now. Interestingly my McAfee picked up combofix as a remote handler/controller type virus and says it deleted it :s Ok here is the combofix log from the latest version, will follow with a post of the most up to date HJT log.ComboFix 08-07-02.5 - Administrator 2008-07-03 17:49:57.1 - NTFSx86 MINIMALMicrosoft Windows XP Professional 5.1.2600.3.1252.1.1033.18. 1755 [GMT 1:00]Running from: C:\Documents and Settings\Administrator\Des ktop\Combo Fix.exe[co lor=red][b ]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color].((((((((((( (((((((((( (((((((((( (((((((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) ))).C:\WIN DOWS\cooki es.iniC:\W INDOWS\psk t.iniC:\WI NDOWS\syst em32\AutoR un.infC:\W INDOWS\sys tem32\awtS KASl.dllC: \WINDOWS\s ystem32\ay yadfii.ini C:\WINDOWS \system32\ ayyadfii.i ni2C:\WIND OWS\system 32\CacheC: \WINDOWS\s ystem32\cb XrSMgd.dll C:\WINDOWS \system32\ cdifguhu.d llC:\WINDO WS\system3 2\cerhem.d llC:\WINDO WS\system3 2\gvrefthc .dllC:\WIN DOWS\syste m32\hhwwji rm.dllC:\W INDOWS\sys tem32\iflk ltsi.iniC: \WINDOWS\s ystem32\je xqufhr.dll C:\WINDOWS \system32\ lnXbLRqr.i niC:\WINDO WS\system3 2\lnXbLRqr .ini2C:\WI NDOWS\syst em32\mihjb qcn.dllC:\ WINDOWS\sy stem32\mjd pwj.dllC:\ WINDOWS\sy stem32\ncq bjhim.iniC :\WINDOWS\ system32\n srbrlxa.dl lC:\WINDOW S\system32 \PVwxHRqr. iniC:\WIND OWS\system 32\PVwxHRq r.ini2C:\W INDOWS\sys tem32\pwxe gq.dllC:\W INDOWS\sys tem32\qoMf GvVo.dllC: \WINDOWS\s ystem32\re tkfanb.dll C:\WINDOWS \system32\ uhugfidc.i niC:\WINDO WS\system3 2\vtUoPgDs .dllC:\WIN DOWS\syste m32\wbaear in.iniC:\W INDOWS\sys tem32\winm bj32.dllC: \WINDOWS\s ystem32\wi nppp32.dll C:\WINDOWS \system32\ x64C:\WIND OWS\system 32\yayYPJC v.dllC:\WI NDOWS\syst em32\yfnek gqb.dllK:\ Autorun.in f.(((((((( (((((((((( ((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))) ))))).2008 -07-03 12:31 . 2008-07-03 12:31 0 --a------ C:\WINDO WS\nsreg.d at2008-07- 03 11:45 . 2008-07-03 11:45 <DIR> d-------- C:\D ocuments and Settings\woyt\Application Data\Apple Computer2008-07-03 11:10 . 2008-07-03 11:10 0 --a------ C:\WINDO WS\AUTORUN .INI2008-0 7-03 10:25 . 2008-07-03 10:25 <DIR> d-------- C:\D ocuments and Settings\woyt\Application Data\PC Tools2008-07-03 10:25 . 2008-07-03 10:25 <DIR> d-------- C:\D ocuments and Settings\woyt\Application Data\HPAppData2008-07-03 10:09 . 2008-04-04 11:44 <DIR> d-------- C:\D ocuments and Settings\woyt\Application Data\SampleView2008-07-03 10:09 . 2008-04-04 11:34 <DIR> d-------- C:\D ocuments and Settings\woyt\Application Data\InstallShield2008-07- 03 10:09 . 2008-07-03 15:49 <DIR> d-------- C:\D ocuments and Settings\woyt2008-07-03 10:08 . 2008-04-04 11:44 <DIR> d-------- C:\D ocuments and Settings\serverops\Applica tion Data\SampleView2008-07-03 10:08 . 2008-04-04 11:34 <DIR> d-------- C:\D ocuments and Settings\serverops\Applica tion Data\InstallShield2008-07- 03 10:08 . 2008-07-03 10:09 <DIR> d-------- C:\D ocuments and Settings\serverops2008-07- 02 14:22 . 2008-07-02 14:22 <DIR> d-------- C:\D ocuments and Settings\Administrator\App lication Data\HPAppData2008-07-02 14:08 . 2008-07-02 14:08 <DIR> d-------- C:\V undoFix Backups2008-07-02 13:06 . 2008-07-02 13:06 <DIR> d-------- C:\D ocuments and Settings\Administrator\App lication Data\PC Tools2008-07-02 11:26 . 2008-07-03 12:29 891 --a------ C:\WIN DOWS\win.t mp2008-07- 02 11:26 . 2006-04-25 11:19 231 --a------ C:\WIN DOWS\syste m.tmp2008- 07-01 16:28 . 2008-07-01 16:30 <DIR> d-------- C:\D ocuments and Settings\All Users\Application Data\Lavasoft2008-07-01 16:26 . 2008-07-01 16:26 <DIR> d-------- C:\P rogram Files\Common Files\Wise Installation Wizard2008-07-01 12:52 . 2008-07-02 10:46 327 --a------ C:\WIN DOWS\winin it.ini2008 -07-01 12:05 . 2008-07-03 12:06 110,419 --a------ C: \WINDOWS\B M4e175b6d. xml2008-07 -01 11:55 . 2008-07-01 11:55 25 --a------ C:\WIND OWS\RTMSer vices.INI2 008-06-30 14:11 . 2008-06-30 14:11 25,088 --a------ C:\ WINDOWS\sy stem32\nnn lIcCv.dll. vir2008-06 -30 14:04 . 2008-06-30 15:13 1,205 --a------ C:\W INDOWS\aox ppr.ini200 8-06-26 15:37 . 2008-06-26 15:37 <DIR> d-------- C:\W INDOWS\AiO Temp2008-0 6-26 15:37 . 2008-06-26 15:37 <DIR> d-------- C:\T emp\hp_off icejet_710 0_series20 08-06-23 14:08 . 2008-06-23 14:08 <DIR> d--h----- C:\W INDOWS\PIF 2008-06-18 10:58 . 2008-06-18 10:58 <DIR> d-------- C:\D ocuments and Settings\All Users\Application Data\WEBREG2008-06-18 10:52 . 2008-06-18 10:52 <DIR> d-------- C:\D ocuments and Settings\All Users\Application Data\HPSSUPPLY2008-06-18 10:51 . 2008-06-18 10:51 <DIR> d-------- C:\D ocuments and Settings\All Users\Application Data\HP Product Assistant2008-06-18 10:48 . 2008-06-18 10:48 <DIR> d-------- C:\D ocuments and Settings\All Users\Application Data\Hewlett-Packard2008-0 6-18 10:47 . 2007-03-30 16:11 267,864 -ra------ C: \WINDOWS\s ystem32\hp zids01.dll 2008-06-18 10:47 . 2007-03-28 14:01 117,760 --a------ C: \WINDOWS\s ystem32\hp zll5ha.dll 2008-06-13 12:55 . 2008-06-13 12:55 <DIR> d-------- C:\W INDOWS\Sun 2008-06-11 15:16 . 2008-06-13 12:05 272,128 --------- C: \WINDOWS\s ystem32\dl lcache\bth port.sys20 08-06-11 15:16 . 2008-05-08 15:02 203,136 --------- C: \WINDOWS\s ystem32\dl lcache\rmc ast.sys200 8-06-10 15:54 . 1998-10-28 12:03 743,504 --a------ C: \WINDOWS\s ystem32\Ss 32x25.ocx2 008-06-09 14:26 . 2008-06-09 14:26 <DIR> d-------- C:\W INDOWS\sys tem32\Adob e2008-06-0 9 11:25 . 2008-06-09 11:25 <DIR> d-------- C:\I VODBC2008- 06-05 13:00 . 2008-05-07 16:46 215,144 -ra------ C: \WINDOWS\p w32a.dll20 08-06-05 13:00 . 2008-05-07 16:46 215,144 -ra------ C: \WINDOWS\p atchw32.dl l2008-06-0 5 12:52 . 2008-05-07 12:30 137,952 --a------ C: \WINDOWS\s ystem32\dr ivers\syms nap.sys200 8-06-05 12:52 . 2008-01-19 20:12 128,104 --a------ C: \WINDOWS\s ystem32\dr ivers\WimF ltr.sys200 8-06-05 12:52 . 2008-01-19 19:45 38,112 --a------ C:\ WINDOWS\sy stem32\dri vers\v2imo unt.sys200 8-06-05 12:52 . 2008-01-19 19:40 15,088 --a------ C:\ WINDOWS\sy stem32\dri vers\vproe ventmonito r.sys2008- 06-04 10:55 . 2002-08-14 15:03 45,056 --a------ C:\ WINDOWS\sy stem32\WNA SPI32.DLL2 008-06-04 10:55 . 2002-08-14 15:03 17,005 --a------ C:\ WINDOWS\sy stem32\dri vers\ASPI3 2.SYS2008- 06-04 10:55 . 2002-08-14 15:03 5,600 --a------ C:\W INDOWS\sys tem\WINASP I.DLL2008- 06-04 10:55 . 2002-08-14 15:03 4,672 --a------ C:\W INDOWS\sys tem\WOWPOS T.EXE.(((( (((((((((( (((((((((( (((((((((( (((((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) )))))).200 8-07-03 09:05 --------- d-----w C: \Documents and Settings\Administrator\App lication Data\Skype2008-06-27 15:24 --------- d-----w C: \Program Files\Common Files\Symantec Shared2008-06-27 15:23 --------- d--h--w C: \Program Files\InstallShield Installation Information2008-06-18 09:52 --------- d-----w C: \Program Files\HP2008-06-18 09:51 --------- d-----w C: \Documents and Settings\All Users\Application Data\HP2008-06-13 11:05 272,128 ------w C:\W INDOWS\sys tem32\driv ers\bthpor t.sys2008- 06-05 11:55 --------- d-----w C: \Documents and Settings\All Users\Application Data\Symantec2008-05-29 08:56 --------- d-----w C: \Program Files\Microsoft CAPICOM 2.1.0.22008-05-28 14:22 --------- d-----w C: \Program Files\Common Files\HP2008-05-28 14:21 --------- d-----w C: \Program Files\Hewlett-Packard2008- 05-28 14:20 --------- d-----w C: \Program Files\Common Files\Hewlett-Packard2008- 05-27 09:57 --------- d-----w C: \Program Files\Your Company Name2008-05-20 09:07 --------- d-----w C: \Program Files\Microsoft Silverlight2008-05-16 09:29 --------- d-----w C: \Documents and Settings\Administrator\App lication Data\Windows Desktop Search2008-05-14 16:30 --------- d-----w C: \Documents and Settings\All Users\Application Data\Microsoft Help2008-05-08 14:02 203,136 ----a-w C:\W INDOWS\sys tem32\driv ers\rmcast .sys2008-0 5-07 15:44 16,168 ----a-w C:\WI NDOWS\syst em32\drive rs\GEARAsp iWDM.sys20 08-04-25 09:25 32 ----a-w C:\Docume nts and Settings\All Users\Application Data\ezsid.dat2008-04-14 00:12 69,120 ----a-w C:\WI NDOWS\note pad.exe200 8-04-14 00:12 50,688 ----a-w C:\WI NDOWS\twai n_32.dll20 08-04-14 00:12 32,866 ------w C:\WI NDOWS\slru ndll.exe20 08-04-14 00:12 283,648 ----a-w C:\W INDOWS\win hlp32.exe2 008-04-14 00:12 146,432 ----a-w C:\W INDOWS\reg edit.exe20 08-04-14 00:12 10,752 ----a-w C:\WI NDOWS\hh.e xe2008-04- 14 00:12 1,033,728 ----a-w C: \WINDOWS\e xplorer.ex e.(((((((( (((((((((( (((((((((( ((((((((( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))..*Not e* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER \SOFTWARE\ Microsoft\ Windows\Cu rrentVersi on\Run]"ct fmon.exe"= "C:\WINDOW S\system32 \ctfmon.ex e" [2008-04-14 01:12 15360]"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]"Skype"="C:\Progra m Files\Skype\Phone\Skype.ex e" [2008-04-03 16:48 21898024]"MsnMsgr"="C:\Pro gram Files\Windows Live\Messenger\MsnMsgr.Exe " [2007-10-18 11:34 5724184][HKEY_LOCAL_MACHIN E\SOFTWARE \Microsoft \Windows\C urrentVers ion\Run]"I gfxTray"=" C:\WINDOWS \system32\ igfxtray.e xe" [2007-09-07 11:22 141848]"HotKeysCmds"="C:\W INDOWS\sys tem32\hkcm d.exe" [2007-09-07 11:22 166424]"Persistence"="C:\W INDOWS\sys tem32\igfx pers.exe" [2007-09-07 11:22 137752]"SoundMAXPnP"="C:\P rogram Files\Analog Devices\Core\smax4pnp.exe" [2007-07-10 05:39 1036288]"SetRefresh"="C:\P rogram Files\Compaq\SetRefresh\Se tRefresh.e xe" [2003-11-20 20:01 525824]"Recguard"="C:\WIND OWS\Sminst \Recguard. exe" [2006-05-12 21:50 1138688]"Reminder"="C:\WIN DOWS\Creat or\Remind_ XP.exe" [2006-03-31 23:44 761856]"Scheduler"="C:\WIN DOWS\SMINS T\Schedule r.exe" [2006-07-10 19:53 872448]"ShStatEXE"="C:\Pro gram Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-10-16 20:50 111952]"McAfeeUpdaterUI"=" C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 13:39 136768]"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe " [2008-03-28 23:37 413696]"iTunesHelper"="C:\ Program Files\iTunes\iTunesHelper. exe" [2008-03-30 10:36 267048]"HP Software Update"="D:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]"Norton Ghost 14.0"="D:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-05-07 17:13 2245984][HKEY_USERS\.DEFAU LT\Softwar e\Microsof t\Windows\ CurrentVer sion\Run]" CTFMON.EXE "="C:\WIND OWS\system 32\CTFMON. EXE" [2008-04-14 01:12 15360]"Spyware Doctor"="d:\Program Files\Spyware Doctor\swdoctor.exe" [2005-11-24 13:14 1947872]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [3/11/2007 9:26:24 PM 210520]VPN Client.lnk - C:\WINDOWS\Installer\{CCBA A1F7-E5E1- 48B2-9ED9- A79C6A37CE 78}\Icon3E 5562ED7.ic o [4/16/2008 11:19:32 PM 6144]WinZip Quick Pick.lnk - D:\Program Files\WinZip\WZQKPICK.EXE [4/16/2008 10:21:07 PM 106560][hkey_local_machine \software\ microsoft\ windows\cu rrentversi on\explore r\ShellExe cuteHooks] "{56F9679E -7826-4C84 -81F3-5320 71A8BCC5}" = "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dl l" [2007-02-05 15:39 294400][HKEY_LOCAL_MACHINE \software\ microsoft\ windows nt\currentversion\winlogon \notify\PC ANotify]20 03-05-29 11:00 8704 C:\WINDOWS\system32\PCANot ify.dll[HK LM\~\servi ces\shared access\par ameters\fi rewallpoli cy\standar dprofile\A uthorizedA pplication s\List]"%w indir%\\sy stem32\\se ssmgr.exe" ="C:\\Prog ram Files\\Microsoft Office\\Office12\\OUTLOOK. EXE"="C:\\ WINDOWS\\S MINST\\Sch eduler.exe "="C:\\Pro gram Files\\McAfee\\Common Framework\\FrameworkServic e.exe"="%w indir%\\Ne twork Diagnostic\\xpnetdiag.exe" ="D:\Progr am Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169 .254.2.0/2 55.255.255 .0:Enabled :ActiveSyn c RAPI Manager"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:16 9.254.2.0/ 255.255.25 5.0:Enable d:ActiveSy nc Connection Manager"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169 .254.2.0/2 55.255.255 .0:Enabled :ActiveSyn c Application"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e xe"="C:\\P rogram Files\\Windows Live\\Messenger\\livecall. exe"=[HKLM \~\service s\sharedac cess\param eters\fire wallpolicy \standardp rofile\Glo ballyOpenP orts\List] "5800:TCP" = 5800:TCP:VNC1"5900:TCP"= 5900:TCP:VNC2"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22 009"26675: TCP"= 26675:TCP:169.254.2.0/255. 255.255.0: Enabled:Ac tiveSync ServiceR2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e xe" [2008-01-11 17:50]R2 MSExchangeMGMT;Microsoft Exchange Management;"C:\Program Files\Exchsrvr\bin\exmgmt. exe" [2007-04-27 10:00]R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\WINDOWS\system 32\dllhost .exe [2008-04-14 01:12]R3 IFXTPM;IFXTPM;C:\WINDOWS\s ystem32\DR IVERS\IFXT PM.SYS [2007-01-23 21:13]R3 SymSnapService;SymSnapServ ice;"D:\Pr ogram Files\Norton Ghost\Shared\Drivers\SymSn apService. exe" [2008-05-07 12:30]S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\ sqlservr.e xe" -sMSSMLBIZ [][HKEY_LOCAL_MACHINE\soft ware\micro soft\windo ws nt\currentversion\svchost] hpdevmgmt REG_MULTI_ SZ hpqcxs08 hpqddsvc[HKEY_CURRENT_USER \software\ microsoft\ windows\cu rrentversi on\explore r\mountpoi nts2\K]\Sh ell\AutoRu n\command - C:\WINDOWS\system32\RunDLL 32.EXE Shell32.DLL,ShellExec_RunD LL Info.exe protect.ed 480 480.Contents of the 'Scheduled Tasks' folder"2008-06-05 07:21:01 C:\WINDOWS\Tasks\AppleSoft wareUpdate .job"- C:\Program Files\Apple Software Update\SoftwareUpdate.exe. - - - - ORPHANS REMOVED - - - -BHO-{05CD9087-92C0-44AC-B 068-22257A A4B390} - C:\WINDOWS\system32\iifday ya.dllBHO- {1C028F3B- 5919-4041- 815D-F4836 C4C6E66} - C:\WINDOWS\system32\rqRHxw VP.dllBHO- {3C082AB6- E103-44BB- A3F3-D745C DF98754} - C:\WINDOWS\system32\rqRLbX nl.dllHKLM -Run-4d246 8f1 - C:\WINDOWS\system32\mihjbq cn.dllHKLM -Run-BM4e1 75b6d - C:\WINDOWS\system32\hhwwji rm.dllShel lExecuteHo oks-{427B3 7EF-B6C5-4 823-A97C-1 0B88977E39 8} - (no file)Notify-winppp32 - winppp32.dll************** ********** ********** ********** ********** ********** ********** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-07-03 17:54:35Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0************************* ********** ********** ********** ********** *********. ---------- ---------- ---- Other Running Processes ------------------------.D :\Program Files\Lavasoft\Ad-Aware\aa wservice.e xeC:\Progr am Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exeD:\Pro gram Files\Cisco Systems\VPN Client\cvpnd.exeD:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exeC :\WINDOWS\ system32\i netsrv\ine tinfo.exeC :\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex eC:\Progra m Files\McAfee\Common Framework\FrameworkService .exeC:\Pro gram Files\McAfee\VirusScan Enterprise\Mcshield.exeC:\ Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exeD:\ Program Files\Norton Ghost\Agent\VProSvc.exeC:\ Program Files\McAfee\Common Framework\naPrdMgr.exeC:\W INDOWS\sys tem32\HPZi pm12.exeD: \Program Files\Remote Task Manager\rtmservice.exeD:\P rogram Files\Spyware Doctor\sdhelp.exeC:\Progra m Files\Microsoft SQL Server\90\Shared\sqlwriter .exeD:\Pro gram Files\RealVNC\VNC4\winvnc4 .exeC:\WIN DOWS\syste m32\search indexer.ex eC:\WINDOW S\system32 \msdtc.exe C:\WINDOWS \system32\ igfxsrvc.e xeC:\WINDO WS\system3 2\rundll32 .exeC:\WIN DOWS\syste m32\rundll 32.exeC:\P rogram Files\McAfee\Common Framework\Mctray.exeD:\PRO GRA~1\MICR OS~1\rapim gr.exeC:\W INDOWS\sys tem32\sear chprotocol host.exeC: \WINDOWS\s ystem32\se archfilter host.exeC: \Program Files\iPod\bin\iPodService .exe.***** ********** ********** ********** ********** ********** ********** *********. Completion time: 2008-07-03 17:56:38 - machine was rebootedComboFix-quarantin ed-files.t xt 2008-07-03 16:56:35ComboFix2.txt 2008-07-03 11:16:38Pre-Run: 59,253,743,616 bytes freePost-Run: 57,075,183,616 bytes free244 --- E O F --- 2008-06-20 16:05:00
ASKER
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:08:45, on 04/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\csrss. exe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\svchos t.exe
D:\Program Files\Lavasoft\Ad-Aware\aa wservice.e xe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e xe
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\inetsr v\inetinfo .exe
C:\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex e
C:\Program Files\McAfee\Common Framework\FrameworkService .exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter .exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\system32\dllhos t.exe
d:\Program Files\RealVNC\VNC4\WinVNC4 .exe
C:\WINDOWS\system32\Search Indexer.ex e
C:\Program Files\Exchsrvr\bin\exmgmt. exe
C:\WINDOWS\system32\dllhos t.exe
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn apService. exe
C:\WINDOWS\System32\alg.ex e
C:\WINDOWS\system32\msdtc. exe
C:\WINDOWS\system32\igfxtr ay.exe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxpe rs.exe
C:\WINDOWS\system32\igfxsr vc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\SMINST\Schedule r.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper. exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\ctfmon .exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
D:\PROGRA~1\MICROS~1\rapim gr.exe
C:\Program Files\Skype\Phone\Skype.ex e
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService .exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepa d.exe
C:\WINDOWS\system32\wuaucl t.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\HP\Smart Web Printing\hpswp_clipbook.ex e
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\PROGRA~1\SPYWAR~1\swdoc tor.exe
C:\Documents and Settings\woyt\Desktop\HiJa ckThis.exe
C:\WINDOWS\system32\wbem\w miprvse.ex e
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=74&bd=smb&pf=desktop
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\In ternet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=74&bd=smb&pf=desktop
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5 8F732D338C 0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.d ll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2 06D7942484 F} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D 426709BBFE B} - D:\PROGRA~1\SPYWAR~1\tools \iesdsg.dl l
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D 4DAF1D92D4 3} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5 164760863C 6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1 7DF180C71A C} - D:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd. exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe rs.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se tRefresh.e xe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard .exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_ XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Schedule r.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "D:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon .exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex e" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe " /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "d:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2 \Office12\ EXCEL.EXE/ 3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.6.0_02\bin \ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4 C56B4E14E8 4} - D:\PROGRA~1\SPYWAR~1\tools \iesdpb.dl l
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0 0C04FAE2D4 F} - D:\PROGRA~1\MICROS~1\INetR epl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-1 0282ABF65E 7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions. dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3 250410481E 8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions. dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D 32B190E9B0 7} - C:\Program Files\Skype\Toolbars\Inter net Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3 C9C571A826 3} - C:\PROGRA~1\MICROS~2\Offic e12\REFIEB AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5 8CAB36FD2A 2} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5 8CAB36FD2A 2} - D:\PROGRA~1\SPYBOT~1\SDHel per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {26700CD9-6157-4B72-B46F-E C93C952F19 C} (SWToolSet.Engine) - http://itapps:8080/SWToolset.exe
O16 - DPF: {6414512B-B978-451D-A0D8-F CFDF33E833 C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208301416265
O16 - DPF: {6E32070A-766D-4EE6-879C-D C1FA91D2FC 3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208362371890
O16 - DPF: {A90A5822-F108-45AD-8482-9 BC8B12DD53 9} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0 060082AA75 C} (GpcContainer Class) - https://synaptrismeetings.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O17 - HKLM\Software\..\Telephony : DomainName = radiotaxis.co.uk
O17 - HKLM\System\CS1\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O17 - HKLM\System\CS2\Services\T cpip\Param eters: Domain = radiotaxis.co.uk
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1 830C7DD7F5 D} - C:\PROGRA~1\COMMON~1\Skype \SKYPE4~1. DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aa wservice.e xe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\ awhost32.e xe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe rvice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iv iRegMgr.ex e
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU P~1\LUCOMS ~1.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService .exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel. exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm 12.exe
O23 - Service: Remote Task Manager service (RTM) - Unknown owner - d:\Program Files\Remote Task Manager\RTMService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - d:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSn apService. exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - d:\Program Files\RealVNC\VNC4\WinVNC4 .exe
--
End of file - 12041 bytes
Scan saved at 10:08:45, on 04/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
D:\Program Files\Lavasoft\Ad-Aware\aa
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.e
D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\inetsr
C:\Program Files\Common Files\InterVideo\RegMgr\iv
C:\Program Files\McAfee\Common Framework\FrameworkService
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
d:\Program Files\Remote Task Manager\RTMService.exe
d:\Program Files\Spyware Doctor\sdhelp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\dllhos
d:\Program Files\RealVNC\VNC4\WinVNC4
C:\WINDOWS\system32\Search
C:\Program Files\Exchsrvr\bin\exmgmt.
C:\WINDOWS\system32\dllhos
D:\Program Files\Norton Ghost\Shared\Drivers\SymSn
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\msdtc.
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\SMINST\Schedule
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\ctfmon
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
D:\PROGRA~1\MICROS~1\rapim
C:\Program Files\Skype\Phone\Skype.ex
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepa
C:\WINDOWS\system32\wuaucl
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\HP\Smart Web Printing\hpswp_clipbook.ex
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\PROGRA~1\SPYWAR~1\swdoc
C:\Documents and Settings\woyt\Desktop\HiJa
C:\WINDOWS\system32\wbem\w
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Schedule
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Norton Ghost 14.0] "D:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "d:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-1
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {26700CD9-6157-4B72-B46F-E
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {A90A5822-F108-45AD-8482-9
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aa
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iv
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Norton Ghost - Symantec Corporation - D:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
O23 - Service: Remote Task Manager service (RTM) - Unknown owner - d:\Program Files\Remote Task Manager\RTMService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - d:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SymSnapService - Symantec - D:\Program Files\Norton Ghost\Shared\Drivers\SymSn
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - d:\Program Files\RealVNC\VNC4\WinVNC4
--
End of file - 12041 bytes
Hi,
The formatting is so messed up, hard to analyze, is it possible to make it easier to read? like when you open the log in notepad can you check or uncheck wordwrap and see if they display correctly? like your first log, each entry in one separate line, thanks.
Oh, that's why is't important to STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
The formatting is so messed up, hard to analyze, is it possible to make it easier to read? like when you open the log in notepad can you check or uncheck wordwrap and see if they display correctly? like your first log, each entry in one separate line, thanks.
Oh, that's why is't important to STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks rpggamergirl, I have indeed installed a few office password recovery tools in the last week or so which i wondered might have caused the problems. I'll give that script a try today and let you know how it goes. The PC has seemed better but i'll find out after running a few scans later when i try the script. I'll let you know how it goes.
I thought you might've purposely installed a Password Recovery tool, so I didn't include the file in the above script.
there are a few ways to get rid of this
http://www.bleepingcomputer.com/forums/topic18610.html
go there and download the VundoFix. run that and let it scan
if that doesn't work then download and run the VirtumundoBegone.
i've removed this from a few computers this week, and they seem to work out well
let me know how this works out for you