First MBAM log:
Malwarebytes' Anti-Malware 1.41
Database version: 2831
Windows 6.0.6002 Service Pack 2
9/20/2009 9:45:51 AM
mbam-log-2009-09-20 (09-45-51).txt
Scan type: Quick Scan
Objects scanned: 98456
Time elapsed: 4 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
________________________________________________________________________________
__________________________________________
Second MBAM Log:
Malwarebytes' Anti-Malware 1.41
Database version: 2831
Windows 6.0.6002 Service Pack 2
9/20/2009 10:31:08 AM
mbam-log-2009-09-20 (10-31-08).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 147655
Time elapsed: 39 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Windows\System32\cngaudit.dll.vir (Trojan.Sirefef) -> Quarantined and deleted successfully.
________________________________________________________________________________
_______
Third and Final MBAM log:
Malwarebytes' Anti-Malware 1.41
Database version: 2831
Windows 6.0.6002 Service Pack 2
9/20/2009 10:38:29 AM
mbam-log-2009-09-20 (10-38-29).txt
Scan type: Quick Scan
Objects scanned: 98217
Time elapsed: 4 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
________________________________________________________________________________
________________________
OTL.txt log:
OTL logfile created on: 9/20/2009 1:21:35 PM - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Users\Michelle\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
957.76 Mb Total Physical Memory | 294.02 Mb Available Physical Memory | 30.70% Memory free
2.30 Gb Paging File | 1.64 Gb Available in Paging File | 71.08% Paging File free
Paging file location(s): c:\pagefile.sys 1435 1435 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.05 Gb Total Space | 251.64 Gb Free Space | 87.36% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.37 Gb Free Space | 63.71% Space Free | Partition Type: NTFS
Drive E: | 487.16 Mb Total Space | 482.02 Mb Free Space | 98.94% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MICHELLE
Current User Name: Michelle
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Windows\System32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Users\Michelle\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AOL ACS [Disabled | Stopped]) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [On_Demand | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) – C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (RapiMgr [On_Demand | Running]) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (RoxMediaDB9 [On_Demand | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9 [Disabled | Stopped]) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (sprtsvc_dellsupportcenter [Disabled | Stopped]) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (WcesComm [On_Demand | Running]) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\System32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (Afc [Disabled | Stopped]) – C:\Windows\System32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\Windows\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (DSproct [Disabled | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Disabled | Stopped]) – C:\Program Files\DellSupport\Drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (e1express [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\e1e6032.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2 [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvlddmkm [On_Demand | Running]) – C:\Windows\System32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Boot | Running]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvrd32 [Disabled | Stopped]) – C:\Windows\system32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor [Boot | Running]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (nvstor32 [Boot | Running]) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{FBEA8B78-1B22F121-05040000} [Disabled | Stopped]) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (PxHelp20 [Disabled | Stopped]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (USB_RNDIS_VISTA [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (wanatw [On_Demand | Running]) – C:\Windows\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\System32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 17:10:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/14 13:15:36 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/14 13:15:11 | 00,000,000 | —D | M]
[2009/09/14 13:15:47 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\mozilla\Extensions
[2009/09/14 13:15:47 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/14 13:26:21 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\mozilla\Firefox\Profiles\sr3pjgbs.default\extensions
[2009/09/14 13:26:21 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\mozilla\Firefox\Profiles\sr3pjgbs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/14 13:15:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/09/14 13:15:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/24 13:15:25 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/24 13:15:26 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/24 13:15:27 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/08/24 11:45:46 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/24 11:45:46 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/08/24 11:45:46 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/24 11:45:46 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/08/24 11:45:46 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/08/24 11:45:46 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/24 11:45:46 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: netzero.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: netzero.net ([]* in Trusted sites)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Adventures%20of%20Robinson%20Crusoe/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Adventures%20of%20Robinson%20Crusoe/Images/armhelper.ocx (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\AutorunsDisabled - No CLSID value found
O18 - Protocol\Handler\AutorunsDisabled\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/09/20 13:20:40 | 00,514,560 | —- | C] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2009/09/20 11:59:14 | 00,000,046 | —- | C] () – C:\Users\Michelle\Desktop\jay.bat
[2009/09/20 11:40:09 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/09/20 11:25:44 | 01,592,965 | —- | C] () – C:\Users\Michelle\Documents\AutoRuns.arn
[2009/09/20 09:36:12 | 00,000,000 | —D | C] – C:\Windows\temp
[2009/09/20 09:36:12 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\temp
[2009/09/20 09:31:21 | 00,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2009/09/20 09:26:05 | 03,303,278 | -H– | C] () – C:\Users\Michelle\AppData\Local\IconCache.db
[2009/09/20 09:09:02 | 00,229,888 | —- | C] () – C:\Windows\PEV.exe
[2009/09/20 09:09:02 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2009/09/20 09:09:02 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2009/09/20 09:09:02 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2009/09/20 09:09:02 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2009/09/20 09:09:02 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2009/09/20 09:09:02 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2009/09/20 09:09:02 | 00,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2009/09/20 09:08:34 | 00,000,000 | —D | C] – C:\Qoobox
[2009/09/18 21:16:23 | 03,316,998 | R— | C] () – C:\Users\Michelle\Desktop\Combo-Fix.exe
[2009/09/18 15:51:00 | 00,047,616 | —- | C] () – C:\Users\Michelle\Desktop\Win32kDiag.exe
[2009/09/18 15:50:16 | 00,000,575 | —- | C] () – C:\Users\Michelle\Desktop\Fixswen.inf
[2009/09/18 15:49:29 | 00,000,000 | —D | C] – C:\Users\Michelle\Desktop\Moes
[2009/09/18 11:49:58 | 00,001,876 | —- | C] () – C:\Users\Michelle\Desktop\HijackThis.lnk
[2009/09/18 11:49:58 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/09/18 11:49:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Michelle\Desktop\HJTInstall.exe
[2009/09/15 13:50:43 | 00,000,015 | —- | C] () – C:\Users\Michelle\Desktop\settings.dat
[2009/09/15 12:56:18 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/09/15 12:55:41 | 00,000,735 | —- | C] () – C:\Users\Michelle\Desktop\NTREGOPT.lnk
[2009/09/15 12:55:41 | 00,000,716 | —- | C] () – C:\Users\Michelle\Desktop\ERUNT.lnk
[2009/09/15 12:55:40 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/09/15 12:53:40 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Users\Michelle\Desktop\erunt_setup.exe
[2009/09/15 12:53:40 | 00,472,064 | —- | C] ( ) – C:\Users\Michelle\Desktop\RootRepeal.exe
[2009/09/15 12:53:40 | 00,359,929 | —- | C] () – C:\Users\Michelle\Desktop\dds.scr
[2009/09/14 19:03:06 | 00,000,000 | —D | C] – C:\Program Files\Panda Security
[2009/09/14 19:03:01 | 00,175,888 | —- | C] () – C:\Users\Michelle\Desktop\activescan2_en.exe
[2009/09/14 18:03:21 | 17,895,0121 | —- | C] () – C:\Windows\MEMORY.DMP
[2009/09/14 17:36:08 | 00,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2009/09/14 17:01:36 | 00,000,049 | —- | C] () – C:\boot.ini
[2009/09/14 17:00:02 | 00,000,680 | —- | C] () – C:\Users\Michelle\AppData\Local\d3d9caps.dat
[2009/09/14 16:54:25 | 00,000,000 | -H-D | C] – C:\Windows\PIF
[2009/09/14 16:33:17 | 03,550,064 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Users\Michelle\Desktop\procexp.exe
[2009/09/14 16:17:09 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Malwarebytes
[2009/09/14 16:17:00 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/09/14 16:07:36 | 00,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2009/09/14 16:06:20 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/09/14 16:06:19 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\SUPERAntiSpyware.com
[2009/09/14 14:36:14 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\SupportSoft
[2009/09/14 13:15:21 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\Mozilla
[2009/09/14 13:15:21 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\Mozilla
[2009/09/14 10:46:26 | 00,000,000 | —D | C] – C:\ProgramData\Citrix
[2009/09/14 10:39:32 | 00,000,000 | —D | C] – C:\Program Files\Citrix
[2009/09/14 10:39:24 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\Citrix
[2009/09/14 10:38:38 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\Deployment
[2009/09/14 10:38:38 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Local\Apps
[2009/09/14 10:29:23 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\McAfee
[2009/09/14 10:19:28 | 00,000,000 | —D | C] – C:\Users\Michelle\Documents\DESKTOP ICONS
[2009/09/14 09:54:22 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/09/14 09:17:47 | 00,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2009/09/14 09:17:47 | 00,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2009/09/14 09:17:43 | 00,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2009/09/14 05:25:07 | 00,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2009/09/14 05:22:58 | 12,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2009/09/14 05:22:55 | 03,408,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe
[2009/09/14 05:22:55 | 01,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2009/09/14 05:22:54 | 02,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2009/09/14 05:22:54 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2009/09/14 05:22:52 | 02,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2009/09/14 05:22:50 | 01,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2009/09/14 05:22:49 | 00,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2009/09/14 05:22:48 | 01,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2009/09/14 05:22:47 | 00,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/09/14 05:22:46 | 00,561,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hdaudbus.sys
[2009/09/14 05:22:46 | 00,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2009/09/14 05:22:45 | 00,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2009/09/14 05:22:45 | 00,518,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2009/09/14 05:22:44 | 02,241,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msi.dll
[2009/09/14 05:22:43 | 00,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2009/09/14 05:22:42 | 00,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2009/09/14 05:22:42 | 00,558,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmain.dll
[2009/09/14 05:22:42 | 00,476,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2009/09/14 05:22:42 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2009/09/14 05:22:41 | 00,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/09/14 05:22:40 | 01,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2009/09/14 05:22:40 | 00,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorShell.dll
[2009/09/14 05:22:38 | 00,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2009/09/14 05:22:38 | 00,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2009/09/14 05:22:38 | 00,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2009/09/14 05:22:37 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2009/09/14 05:22:36 | 11,584,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shell32.dll
[2009/09/14 05:22:36 | 00,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2009/09/14 05:22:36 | 00,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2009/09/14 05:22:35 | 00,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2009/09/14 05:22:35 | 00,644,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2psvc.dll
[2009/09/14 05:22:35 | 00,441,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe
[2009/09/14 05:22:34 | 00,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2009/09/14 05:22:34 | 00,278,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/09/14 05:22:33 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2009/09/14 05:22:33 | 00,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2009/09/14 05:22:33 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2009/09/14 05:22:32 | 03,601,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/09/14 05:22:32 | 01,459,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2009/09/14 05:22:32 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/09/14 05:22:31 | 00,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2009/09/14 05:22:31 | 00,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2009/09/14 05:22:30 | 01,017,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtsvc.dll
[2009/09/14 05:22:30 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2009/09/14 05:22:30 | 00,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2009/09/14 05:22:30 | 00,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2009/09/14 05:22:30 | 00,041,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/09/14 05:22:29 | 00,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2009/09/14 05:22:29 | 00,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2009/09/14 05:22:29 | 00,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2009/09/14 05:22:29 | 00,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLC.dll
[2009/09/14 05:22:28 | 01,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2009/09/14 05:22:27 | 03,549,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/09/14 05:22:27 | 01,336,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6.dll
[2009/09/14 05:22:27 | 00,407,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MPSSVC.dll
[2009/09/14 05:22:26 | 01,381,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Query.dll
[2009/09/14 05:22:26 | 00,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2009/09/14 05:22:26 | 00,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qmgr.dll
[2009/09/14 05:22:25 | 01,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2009/09/14 05:22:25 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2009/09/14 05:22:25 | 00,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2009/09/14 05:22:24 | 01,316,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ole32.dll
[2009/09/14 05:22:24 | 01,202,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntdll.dll
[2009/09/14 05:22:24 | 01,183,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3.dll
[2009/09/14 05:22:24 | 00,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2009/09/14 05:22:23 | 01,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2009/09/14 05:22:23 | 00,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2009/09/14 05:22:23 | 00,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2009/09/14 05:22:23 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/09/14 05:22:23 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2009/09/14 05:22:22 | 02,092,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfsr.exe
[2009/09/14 05:22:22 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2009/09/14 05:22:22 | 00,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2009/09/14 05:22:22 | 00,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2009/09/14 05:22:21 | 00,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2009/09/14 05:22:21 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2009/09/14 05:22:20 | 02,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2009/09/14 05:22:20 | 00,891,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/09/14 05:22:20 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchProtocolHost.exe
[2009/09/14 05:22:20 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchFilterHost.exe
[2009/09/14 05:22:19 | 01,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2009/09/14 05:22:19 | 00,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2009/09/14 05:22:19 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schedsvc.dll
[2009/09/14 05:22:19 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolss.dll
[2009/09/14 05:22:19 | 00,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2009/09/14 05:22:19 | 00,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2009/09/14 05:22:18 | 00,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2009/09/14 05:22:18 | 00,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2009/09/14 05:22:17 | 00,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2009/09/14 05:22:17 | 00,406,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcp60.dll
[2009/09/14 05:22:17 | 00,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/09/14 05:22:16 | 03,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2009/09/14 05:22:16 | 00,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\es.dll
[2009/09/14 05:22:15 | 00,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2009/09/14 05:22:15 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2009/09/14 05:22:15 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2009/09/14 05:22:15 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2009/09/14 05:22:14 | 01,083,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ntfs.sys
[2009/09/14 05:22:14 | 00,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advapi32.dll
[2009/09/14 05:22:13 | 00,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2009/09/14 05:22:13 | 00,321,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2009/09/14 05:22:13 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/09/14 05:22:13 | 00,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WebClnt.dll
[2009/09/14 05:22:12 | 01,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
[2009/09/14 05:22:12 | 01,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comsvcs.dll
[2009/09/14 05:22:12 | 00,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2009/09/14 05:22:12 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2009/09/14 05:22:11 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2009/09/14 05:22:11 | 01,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vssapi.dll
[2009/09/14 05:22:10 | 01,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2009/09/14 05:22:10 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2009/09/14 05:22:09 | 00,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propsys.dll
[2009/09/14 05:22:09 | 00,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2009/09/14 05:22:09 | 00,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2009/09/14 05:22:09 | 00,323,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/09/14 05:22:08 | 02,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/09/14 05:22:08 | 00,978,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\crypt32.dll
[2009/09/14 05:22:08 | 00,576,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpsvc.dll
[2009/09/14 05:22:08 | 00,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2009/09/14 05:22:08 | 00,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2009/09/14 05:22:08 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/09/14 05:22:08 | 00,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/09/14 05:22:07 | 01,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2009/09/14 05:22:07 | 01,591,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupapi.dll
[2009/09/14 05:22:07 | 00,550,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/09/14 05:22:07 | 00,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2009/09/14 05:22:06 | 00,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2009/09/14 05:22:06 | 00,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/14 05:22:06 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2009/09/14 05:22:05 | 01,324,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browseui.dll
[2009/09/14 05:22:05 | 01,135,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2009/09/14 05:22:05 | 01,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2009/09/14 05:22:05 | 00,353,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shlwapi.dll
[2009/09/14 05:22:05 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2009/09/14 05:22:05 | 00,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2009/09/14 05:22:05 | 00,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/14 05:22:05 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2009/09/14 05:22:04 | 00,626,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgkrnl.sys
[2009/09/14 05:22:04 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\photowiz.dll
[2009/09/14 05:22:04 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2009/09/14 05:22:03 | 03,662,128 | —- | C] () – C:\Windows\System32\locale.nls
[2009/09/14 05:22:03 | 01,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2009/09/14 05:22:03 | 00,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\user32.dll
[2009/09/14 05:22:03 | 00,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2009/09/14 05:22:03 | 00,483,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samsrv.dll
[2009/09/14 05:22:02 | 00,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2009/09/14 05:22:02 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/09/14 05:22:02 | 00,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2009/09/14 05:22:02 | 00,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2009/09/14 05:22:01 | 03,174,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netshell.dll
[2009/09/14 05:22:01 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/09/14 05:22:01 | 00,563,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaut32.dll
[2009/09/14 05:22:01 | 00,438,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IKEEXT.DLL
[2009/09/14 05:22:00 | 01,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2009/09/14 05:22:00 | 00,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2009/09/14 05:22:00 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/09/14 05:22:00 | 00,225,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdbss.sys
[2009/09/14 05:22:00 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2009/09/14 05:21:59 | 00,807,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctf.dll
[2009/09/14 05:21:59 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\emdmgmt.dll
[2009/09/14 05:21:59 | 00,315,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiosrv.dll
[2009/09/14 05:21:59 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxdav.sys
[2009/09/14 05:21:59 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2009/09/14 05:21:58 | 00,679,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcrt.dll
[2009/09/14 05:21:58 | 00,297,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdi32.dll
[2009/09/14 05:21:58 | 00,223,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2009/09/14 05:21:57 | 01,160,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2009/09/14 05:21:57 | 01,055,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VSSVC.exe
[2009/09/14 05:21:57 | 00,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QAGENTRT.DLL
[2009/09/14 05:21:57 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iphlpsvc.dll
[2009/09/14 05:21:56 | 00,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2009/09/14 05:21:56 | 00,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2009/09/14 05:21:56 | 00,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2009/09/14 05:21:56 | 00,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2009/09/14 05:21:56 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2009/09/14 05:21:55 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBSTOR.SYS
[2009/09/14 05:21:54 | 00,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2009/09/14 05:21:54 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbc32.dll
[2009/09/14 05:21:54 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2009/09/14 05:21:53 | 01,068,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shdocvw.dll
[2009/09/14 05:21:53 | 00,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbhub.sys
[2009/09/14 05:21:52 | 01,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2009/09/14 05:21:52 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2009/09/14 05:21:52 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2009/09/14 05:21:51 | 02,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2009/09/14 05:21:51 | 00,747,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmSvc.dll
[2009/09/14 05:21:51 | 00,311,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\swprv.dll
[2009/09/14 05:21:50 | 00,502,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usp10.dll
[2009/09/14 05:21:50 | 00,385,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vds.exe
[2009/09/14 05:21:49 | 00,592,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netlogon.dll
[2009/09/14 05:21:49 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2009/09/14 05:21:49 | 00,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2009/09/14 05:21:49 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfp.dll
[2009/09/14 05:21:49 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2009/09/14 05:21:48 | 00,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2009/09/14 05:21:48 | 00,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BFE.DLL
[2009/09/14 05:21:48 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsldpc.dll
[2009/09/14 05:21:48 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2009/09/14 05:21:48 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2009/09/14 05:21:47 | 01,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2009/09/14 05:21:47 | 01,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2009/09/14 05:21:47 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/09/14 05:21:47 | 00,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2009/09/14 05:21:47 | 00,287,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wldap32.dll
[2009/09/14 05:21:46 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/09/14 05:21:46 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2009/09/14 05:21:46 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2009/09/14 05:21:46 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2009/09/14 05:21:46 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2009/09/14 05:21:46 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2009/09/14 05:21:45 | 01,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2009/09/14 05:21:45 | 00,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2009/09/14 05:21:45 | 00,450,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comdlg32.dll
[2009/09/14 05:21:45 | 00,279,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\services.exe
[2009/09/14 05:21:44 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcncsvc.dll
[2009/09/14 05:21:44 | 00,180,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msiscsi.sys
[2009/09/14 05:21:44 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2009/09/14 05:21:43 | 00,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/09/14 05:21:43 | 00,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2009/09/14 05:21:43 | 00,323,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certcli.dll
[2009/09/14 05:21:43 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/09/14 05:21:42 | 00,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2009/09/14 05:21:42 | 00,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2009/09/14 05:21:42 | 00,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2009/09/14 05:21:42 | 00,222,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umpnpmgr.dll
[2009/09/14 05:21:42 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2009/09/14 05:21:42 | 00,168,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsapi.dll
[2009/09/14 05:21:42 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2009/09/14 05:21:42 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2009/09/14 05:21:42 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2009/09/14 05:21:42 | 00,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/09/14 05:21:41 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/09/14 05:21:41 | 00,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2009/09/14 05:21:41 | 00,364,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPSECSVC.DLL
[2009/09/14 05:21:41 | 00,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/09/14 05:21:41 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\w32time.dll
[2009/09/14 05:21:41 | 00,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2009/09/14 05:21:40 | 00,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2009/09/14 05:21:40 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2009/09/14 05:21:40 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthserv.dll
[2009/09/14 05:21:40 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2009/09/14 05:21:39 | 00,527,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndis.sys
[2009/09/14 05:21:39 | 00,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2009/09/14 05:21:39 | 00,241,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rsaenh.dll
[2009/09/14 05:21:38 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2009/09/14 05:21:38 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2009/09/14 05:21:38 | 00,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2009/09/14 05:21:37 | 00,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcomm.dll
[2009/09/14 05:21:37 | 00,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netapi32.dll
[2009/09/14 05:21:37 | 00,093,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/09/14 05:21:36 | 00,310,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxclu.dll
[2009/09/14 05:21:36 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2009/09/14 05:21:36 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptsvc.dll
[2009/09/14 05:21:36 | 00,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/09/14 05:21:36 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hidserv.dll
[2009/09/14 05:21:35 | 00,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\termsrv.dll
[2009/09/14 05:21:35 | 00,343,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2009/09/14 05:21:35 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profsvc.dll
[2009/09/14 05:21:35 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2009/09/14 05:21:34 | 00,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsvcs.dll
[2009/09/14 05:21:34 | 00,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2009/09/14 05:21:34 | 00,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2009/09/14 05:21:34 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2009/09/14 05:21:34 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msiexec.exe
[2009/09/14 05:21:33 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2009/09/14 05:21:33 | 01,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2009/09/14 05:21:33 | 00,149,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pci.sys
[2009/09/14 05:21:32 | 00,262,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmans.dll
[2009/09/14 05:21:32 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2009/09/14 05:21:32 | 00,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2009/09/14 05:21:32 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2009/09/14 05:21:31 | 01,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2009/09/14 05:21:31 | 00,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2009/09/14 05:21:31 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolsv.exe
[2009/09/14 05:21:31 | 00,053,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\termdd.sys
[2009/09/14 05:21:31 | 00,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/09/14 05:21:30 | 00,265,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\acpi.sys
[2009/09/14 05:21:30 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2009/09/14 05:21:29 | 00,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2009/09/14 05:21:29 | 00,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2009/09/14 05:21:29 | 00,245,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clfs.sys
[2009/09/14 05:21:29 | 00,242,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdh.dll
[2009/09/14 05:21:29 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc.dll
[2009/09/14 05:21:29 | 00,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrrun.dll
[2009/09/14 05:21:29 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wersvc.dll
[2009/09/14 05:21:29 | 00,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2009/09/14 05:21:29 | 00,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2009/09/14 05:21:29 | 00,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2009/09/14 05:21:29 | 00,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2009/09/14 05:21:28 | 01,122,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appwiz.cpl
[2009/09/14 05:21:28 | 01,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2009/09/14 05:21:28 | 00,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2009/09/14 05:21:28 | 00,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2009/09/14 05:21:28 | 00,258,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winspool.drv
[2009/09/14 05:21:28 | 00,054,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\partmgr.sys
[2009/09/14 05:21:27 | 02,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2009/09/14 05:21:27 | 00,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winlogon.exe
[2009/09/14 05:21:25 | 01,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2009/09/14 05:21:25 | 00,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2009/09/14 05:21:25 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2009/09/14 05:21:25 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUINotify.dll
[2009/09/14 05:21:25 | 00,048,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mup.sys
[2009/09/14 05:21:24 | 00,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2009/09/14 05:21:24 | 00,053,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\disk.sys
[2009/09/14 05:21:24 | 00,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2009/09/14 05:21:23 | 00,347,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/09/14 05:21:23 | 00,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2009/09/14 05:21:23 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wisptis.exe
[2009/09/14 05:21:23 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2009/09/14 05:21:23 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2009/09/14 05:21:23 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spp.dll
[2009/09/14 05:21:23 | 00,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2009/09/14 05:21:22 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2009/09/14 05:21:22 | 00,292,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgrx.sys
[2009/09/14 05:21:22 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2009/09/14 05:21:22 | 00,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2009/09/14 05:21:22 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwm.exe
[2009/09/14 05:21:21 | 00,869,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printui.dll
[2009/09/14 05:21:21 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autochk.exe
[2009/09/14 05:21:21 | 00,226,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volsnap.sys
[2009/09/14 05:21:21 | 00,190,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fltMgr.sys
[2009/09/14 05:21:21 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2009/09/14 05:21:20 | 00,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2009/09/14 05:21:20 | 00,161,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msrpc.sys
[2009/09/14 05:21:20 | 00,141,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ecache.sys
[2009/09/14 05:21:19 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2009/09/14 05:21:19 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2009/09/14 05:21:19 | 00,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2009/09/14 05:21:18 | 01,541,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\onex.dll
[2009/09/14 05:21:18 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2009/09/14 05:21:18 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswsock.dll
[2009/09/14 05:21:18 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2009/09/14 05:21:18 | 00,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2009/09/14 05:21:18 | 00,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\userenv.dll
[2009/09/14 05:21:18 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2009/09/14 05:21:18 | 00,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2009/09/14 05:21:16 | 00,612,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2009/09/14 05:21:16 | 00,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2009/09/14 05:21:16 | 00,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winmm.dll
[2009/09/14 05:21:16 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netbt.sys
[2009/09/14 05:21:16 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSCard.dll
[2009/09/14 05:21:16 | 00,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2009/09/14 05:21:16 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2009/09/14 05:21:15 | 00,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2009/09/14 05:21:15 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2009/09/14 05:21:15 | 00,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2009/09/14 05:21:15 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsrslvr.dll
[2009/09/14 05:21:14 | 00,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2009/09/14 05:21:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2009/09/14 05:21:14 | 00,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2009/09/14 05:21:14 | 00,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2009/09/14 05:21:13 | 00,586,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\stobject.dll
[2009/09/14 05:21:13 | 00,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2009/09/14 05:21:13 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2009/09/14 05:21:13 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apphelp.dll
[2009/09/14 05:21:13 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2009/09/14 05:21:13 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2009/09/14 05:21:12 | 00,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/09/14 05:21:12 | 00,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2009/09/14 05:21:12 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaservc.dll
[2009/09/14 05:21:12 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\http.sys
[2009/09/14 05:21:12 | 00,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2009/09/14 05:21:12 | 00,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2009/09/14 05:21:12 | 00,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2009/09/14 05:21:12 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2009/09/14 05:21:12 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2009/09/14 05:21:12 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2009/09/14 05:21:11 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscript.exe
[2009/09/14 05:21:11 | 00,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2009/09/14 05:21:11 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2009/09/14 05:21:11 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/09/14 05:21:10 | 00,971,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptui.dll
[2009/09/14 05:21:10 | 00,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2009/09/14 05:21:10 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPHLPAPI.DLL
[2009/09/14 05:21:09 | 00,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2009/09/14 05:21:09 | 00,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2009/09/14 05:21:09 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastapi.dll
[2009/09/14 05:21:09 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2009/09/14 05:21:08 | 01,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2009/09/14 05:21:08 | 00,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2009/09/14 05:21:08 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2009/09/14 05:21:08 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/09/14 05:21:08 | 00,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2009/09/14 05:21:08 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2009/09/14 05:21:07 | 01,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2009/09/14 05:21:07 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2009/09/14 05:21:07 | 00,286,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasapi32.dll
[2009/09/14 05:21:07 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2009/09/14 05:21:07 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/09/14 05:21:07 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2009/09/14 05:21:07 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscsvc.dll
[2009/09/14 05:21:07 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2009/09/14 05:21:06 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regsvc.dll
[2009/09/14 05:21:05 | 00,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/09/14 05:21:04 | 00,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2009/09/14 05:21:04 | 00,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2009/09/14 05:21:04 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2009/09/14 05:21:03 | 02,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2009/09/14 05:21:03 | 01,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2009/09/14 05:21:03 | 00,342,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\zipfldr.dll
[2009/09/14 05:21:03 | 00,090,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshext.dll
[2009/09/14 05:21:02 | 00,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2009/09/14 05:21:02 | 00,825,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdlg.dll
[2009/09/14 05:21:02 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2009/09/14 05:21:02 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbehci.sys
[2009/09/14 05:21:01 | 01,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2009/09/14 05:21:01 | 00,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2009/09/14 05:21:01 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2009/09/14 05:21:00 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshom.ocx
[2009/09/14 05:21:00 | 00,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srvsvc.dll
[2009/09/14 05:21:00 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2009/09/14 05:21:00 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uxsms.dll
[2009/09/14 05:20:59 | 00,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2009/09/14 05:20:59 | 00,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2009/09/14 05:20:59 | 00,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msutb.dll
[2009/09/14 05:20:59 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntmarta.dll
[2009/09/14 05:20:59 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstlsapi.dll
[2009/09/14 05:20:59 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/09/14 05:20:59 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsbyuv.dll
[2009/09/14 05:20:58 | 03,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2009/09/14 05:20:58 | 01,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2009/09/14 05:20:58 | 00,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2009/09/14 05:20:58 | 00,678,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstsc.exe
[2009/09/14 05:20:58 | 00,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2009/09/14 05:20:58 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powrprof.dll
[2009/09/14 05:20:58 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2009/09/14 05:20:57 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/09/14 05:20:57 | 00,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3svc.dll
[2009/09/14 05:20:57 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authz.dll
[2009/09/14 05:20:57 | 00,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2009/09/14 05:20:56 | 01,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2009/09/14 05:20:56 | 00,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2009/09/14 05:20:55 | 02,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2009/09/14 05:20:55 | 00,615,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themeui.dll
[2009/09/14 05:20:55 | 00,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2009/09/14 05:20:55 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samlib.dll
[2009/09/14 05:20:55 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2009/09/14 05:20:55 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdhid.sys
[2009/09/14 05:20:54 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2009/09/14 05:20:54 | 01,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2009/09/14 05:20:54 | 00,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2009/09/14 05:20:54 | 00,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2009/09/14 05:20:54 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2009/09/14 05:20:53 | 00,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2009/09/14 05:20:53 | 00,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2009/09/14 05:20:53 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2009/09/14 05:20:53 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2009/09/14 05:20:53 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regapi.dll
[2009/09/14 05:20:52 | 00,242,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tapisrv.dll
[2009/09/14 05:20:52 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2009/09/14 05:20:52 | 00,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2009/09/14 05:20:51 | 00,306,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scesrv.dll
[2009/09/14 05:20:51 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/09/14 05:20:51 | 00,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\exfat.sys
[2009/09/14 05:20:51 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2009/09/14 05:20:51 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2009/09/14 05:20:51 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpr.dll
[2009/09/14 05:20:50 | 01,102,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmsys.cpl
[2009/09/14 05:20:50 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2009/09/14 05:20:50 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imm32.dll
[2009/09/14 05:20:50 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2009/09/14 05:20:50 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2009/09/14 05:20:50 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2009/09/14 05:20:50 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2009/09/14 05:20:50 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2009/09/14 05:20:49 | 01,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2009/09/14 05:20:49 | 01,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2009/09/14 05:20:49 | 00,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2009/09/14 05:20:49 | 00,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2009/09/14 05:20:49 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2009/09/14 05:20:49 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2009/09/14 05:20:49 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfdisk.dll
[2009/09/14 05:20:48 | 00,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2009/09/14 05:20:48 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2009/09/14 05:20:48 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2009/09/14 05:20:48 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2009/09/14 05:20:48 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scecli.dll
[2009/09/14 05:20:48 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2009/09/14 05:20:48 | 00,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2009/09/14 05:20:48 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBAUDIO.sys
[2009/09/14 05:20:47 | 00,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2009/09/14 05:20:47 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2009/09/14 05:20:47 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2009/09/14 05:20:47 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2009/09/14 05:20:47 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2009/09/14 05:20:46 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2009/09/14 05:20:46 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2009/09/14 05:20:46 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpmon.dll
[2009/09/14 05:20:46 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2009/09/14 05:20:46 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2009/09/14 05:20:46 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2009/09/14 05:20:46 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2009/09/14 05:20:45 | 00,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2009/09/14 05:20:45 | 00,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll
[2009/09/14 05:20:45 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2009/09/14 05:20:44 | 01,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSVidCtl.dll
[2009/09/14 05:20:44 | 00,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2009/09/14 05:20:44 | 00,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/09/14 05:20:44 | 00,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unimdm.tsp
[2009/09/14 05:20:44 | 00,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2009/09/14 05:20:44 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\afd.sys
[2009/09/14 05:20:44 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdmaud.drv
[2009/09/14 05:20:44 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontext.dll
[2009/09/14 05:20:44 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\npfs.sys
[2009/09/14 05:20:43 | 00,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2009/09/14 05:20:43 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2009/09/14 05:20:43 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasppp.dll
[2009/09/14 05:20:43 | 00,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2009/09/14 05:20:43 | 00,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2009/09/14 05:20:43 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2009/09/14 05:20:42 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdx.sys
[2009/09/14 05:20:42 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2009/09/14 05:20:41 | 02,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2009/09/14 05:20:41 | 00,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2009/09/14 05:20:41 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2009/09/14 05:20:41 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pacer.sys
[2009/09/14 05:20:40 | 06,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2009/09/14 05:20:40 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2009/09/14 05:20:40 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2009/09/14 05:20:39 | 00,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2009/09/14 05:20:39 | 00,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fastfat.sys
[2009/09/14 05:20:39 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2009/09/14 05:20:39 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2009/09/14 05:20:38 | 00,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2009/09/14 05:20:38 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netplwiz.dll
[2009/09/14 05:20:38 | 00,178,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\credui.dll
[2009/09/14 05:20:38 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2009/09/14 05:20:38 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\smss.exe
[2009/09/14 05:20:37 | 00,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2009/09/14 05:20:37 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2009/09/14 05:20:37 | 00,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2009/09/14 05:20:37 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certprop.dll
[2009/09/14 05:20:36 | 02,226,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkexplorer.dll
[2009/09/14 05:20:36 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcsvc.dll
[2009/09/14 05:20:36 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2009/09/14 05:20:36 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2009/09/14 05:20:35 | 00,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2009/09/14 05:20:35 | 00,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2009/09/14 05:20:35 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2009/09/14 05:20:35 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/09/14 05:20:35 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2009/09/14 05:20:35 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2009/09/14 05:20:34 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2009/09/14 05:20:34 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2009/09/14 05:20:34 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sendmail.dll
[2009/09/14 05:20:34 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2009/09/14 05:20:33 | 00,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2009/09/14 05:20:33 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olepro32.dll
[2009/09/14 05:20:33 | 00,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2009/09/14 05:20:33 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\smb.sys
[2009/09/14 05:20:33 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidusb.sys
[2009/09/14 05:20:32 | 00,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2009/09/14 05:20:32 | 00,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\udfs.sys
[2009/09/14 05:20:32 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/09/14 05:20:32 | 00,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2009/09/14 05:20:31 | 00,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2009/09/14 05:20:30 | 00,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2009/09/14 05:20:30 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/09/14 05:20:30 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2009/09/14 05:20:29 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2009/09/14 05:20:29 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprapi.dll
[2009/09/14 05:20:29 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshbth.dll
[2009/09/14 05:20:29 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\version.dll
[2009/09/14 05:20:29 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2009/09/14 05:20:28 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2009/09/14 05:20:27 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpwd.sys
[2009/09/14 05:20:27 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2009/09/14 05:20:27 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/09/14 05:20:27 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2009/09/14 05:20:26 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2009/09/14 05:20:26 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndiswan.sys
[2009/09/14 05:20:26 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscapi.dll
[2009/09/14 05:20:26 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/09/14 05:20:26 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2009/09/14 05:20:26 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2009/09/14 05:20:25 | 00,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2009/09/14 05:20:25 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/09/14 05:20:25 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2009/09/14 05:20:25 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2009/09/14 05:20:24 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/09/14 05:20:24 | 00,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2009/09/14 05:20:24 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2009/09/14 05:20:24 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscdll.dll
[2009/09/14 05:20:24 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2009/09/14 05:20:23 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2009/09/14 05:20:23 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2009/09/14 05:20:23 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2009/09/14 05:20:23 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2009/09/14 05:20:23 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2009/09/14 05:20:22 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappcfg.dll
[2009/09/14 05:20:22 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rassstp.sys
[2009/09/14 05:20:22 | 00,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2009/09/14 05:20:22 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2009/09/14 05:20:22 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2009/09/14 05:20:21 | 00,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2009/09/14 05:20:21 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscupgrd.exe
[2009/09/14 05:20:21 | 00,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2009/09/14 05:20:21 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2009/09/14 05:20:20 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2009/09/14 05:20:20 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidclass.sys
[2009/09/14 05:20:20 | 00,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2009/09/14 05:20:20 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2009/09/14 05:20:19 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2009/09/14 05:20:19 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2009/09/14 05:20:19 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2009/09/14 05:20:18 | 00,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\nwifi.sys
[2009/09/14 05:20:18 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dfsc.sys
[2009/09/14 05:20:18 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2009/09/14 05:20:18 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\cdrom.sys
[2009/09/14 05:20:18 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msacm32.drv
[2009/09/14 05:20:17 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2009/09/14 05:20:16 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2009/09/14 05:20:15 | 00,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2009/09/14 05:20:15 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2009/09/14 05:20:15 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2009/09/14 05:20:15 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2009/09/14 05:20:13 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2009/09/14 05:20:12 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2009/09/14 05:20:12 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2009/09/14 05:20:12 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2009/09/14 05:20:12 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2009/09/14 05:20:11 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrnr.dll
[2009/09/14 05:20:10 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\midimap.dll
[2009/09/14 05:20:10 | 00,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2009/09/14 05:20:07 | 00,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2009/09/14 05:20:06 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rndismpx.sys
[2009/09/14 05:20:06 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2009/09/14 05:20:05 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bridge.sys
[2009/09/14 05:20:04 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbohci.sys
[2009/09/14 05:20:04 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023x.sys
[2009/09/14 05:20:04 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2009/09/14 05:20:03 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\raspppoe.sys
[2009/09/14 05:20:02 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2009/09/14 05:20:01 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2009/09/14 05:19:52 | 00,000,153 | —- | C] () – C:\Windows\System32\RacUREx.xml
[2009/09/14 05:19:26 | 00,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2009/09/14 05:19:21 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2009/09/14 05:19:21 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2009/09/14 05:19:07 | 00,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2009/09/14 04:37:36 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/09/14 04:37:35 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/09/14 04:37:34 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/09/14 04:37:34 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/09/14 04:37:33 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/09/14 04:37:33 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/09/14 04:37:33 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/09/14 04:37:33 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/09/14 04:37:33 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/09/14 04:37:31 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/09/14 04:37:31 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/09/14 04:37:31 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/09/14 04:37:31 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/09/14 04:37:31 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/09/14 04:37:30 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/09/14 04:37:30 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/09/14 04:37:30 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/09/14 04:37:30 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/09/14 04:37:27 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/09/14 04:37:27 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/09/14 04:37:27 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/09/14 04:37:14 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/09/14 04:21:15 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/09/14 04:21:14 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/09/14 04:21:14 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/09/14 04:21:14 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/09/14 04:21:13 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/09/14 04:21:13 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/09/14 04:21:13 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/09/14 04:21:12 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/09/14 04:21:12 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/09/14 04:21:12 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/09/14 04:21:12 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/09/14 04:21:11 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/09/14 04:21:11 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/09/14 04:21:11 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/09/14 04:21:10 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/09/14 04:21:10 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/09/14 04:21:10 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/09/14 04:21:10 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/09/14 04:21:09 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/09/14 04:21:09 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/09/14 04:21:08 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/09/14 04:21:08 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/09/14 04:21:07 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/09/14 04:21:06 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/09/14 04:21:05 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/09/14 04:21:00 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/09/14 04:21:00 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/09/14 04:21:00 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/09/14 04:20:59 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/09/14 04:20:59 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/09/14 04:20:58 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/09/14 04:20:58 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/09/14 04:20:58 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/09/14 04:18:30 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/09/14 02:47:59 | 00,000,764 | —- | C] () – C:\Users\Michelle\Documents\My Sharing Folders.lnk
[2009/09/13 22:37:59 | 00,000,552 | —- | C] () – C:\Users\Michelle\AppData\Local\d3d8caps.dat
[2009/09/13 20:47:47 | 00,000,000 | —D | C] – C:\Windows\pss
[2009/09/13 12:35:56 | 00,000,000 | —D | C] – C:\Windows\CheckSur
[2009/09/10 15:26:42 | 00,016,384 | —- | C] () – C:\Windows\System32\Ikeext.etl
[2009/09/08 22:29:00 | 01,259,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/09/08 22:29:00 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kerberos.dll
[2009/09/08 22:29:00 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msv1_0.dll
[2009/09/08 22:28:59 | 00,270,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/09/08 22:28:59 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdigest.dll
[2009/09/08 22:28:56 | 00,439,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ksecdd.sys
[2009/09/08 22:28:56 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/09/08 22:28:54 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsass.exe
[2009/09/08 16:43:04 | 02,501,921 | —- | C] () – C:\Windows\System32\wlan.tmf
[2009/09/08 16:43:04 | 00,513,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansvc.dll
[2009/09/08 16:43:04 | 00,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2009/09/08 16:43:04 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2009/09/08 16:43:04 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2009/09/08 16:43:04 | 00,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2009/09/08 16:43:03 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2009/09/08 16:42:40 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/09/08 16:42:38 | 02,868,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/09/08 16:42:38 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2009/09/08 16:42:38 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2009/09/08 16:42:38 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2009/09/08 16:42:38 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2009/09/08 16:21:15 | 00,904,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/09/08 16:21:11 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2009/09/08 16:21:10 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2009/09/08 16:21:06 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2009/09/08 16:21:06 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2009/09/08 16:21:06 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TCPSVCS.EXE
[2009/09/08 16:21:05 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2009/09/08 16:21:05 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2009/09/08 16:21:04 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2009/09/08 16:21:04 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2009/09/08 16:21:01 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2009/09/06 16:07:48 | 00,000,000 | —D | C] – C:\Program Files\eGames
[2009/09/02 17:14:32 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/09/02 17:14:30 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/08/26 18:00:53 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2009/08/26 15:55:27 | 00,000,000 | —D | C] – C:\Program Files\The Mystery of the Mary Celeste
[2009/08/26 15:31:10 | 00,000,000 | —D | C] – C:\ProgramData\IronCode
[2009/08/26 15:30:59 | 00,000,000 | —D | C] – C:\Users\Michelle\AppData\Roaming\IronCode
[2009/08/26 15:29:27 | 00,000,000 | —D | C] – C:\Program Files\Pahelika - Secret Legends
[2009/08/26 10:55:02 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2009/08/25 16:18:28 | 01,696,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2009/08/23 18:02:09 | 00,000,000 | —D | C] – C:\ProgramData\Norton
[2009/08/23 18:01:31 | 00,000,000 | —D | C] – C:\ProgramData\NortonInstaller
[2009/08/23 15:55:57 | 02,034,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/08/23 15:55:53 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2009/08/23 15:55:52 | 00,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2009/08/23 15:55:52 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2009/08/23 15:55:52 | 00,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2009/08/23 15:55:52 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpk.dll
[2009/08/23 15:55:52 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2009/08/23 15:55:45 | 02,066,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstscax.dll
[2009/08/23 15:55:44 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2009/08/23 15:55:44 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2009/08/23 15:55:42 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wkssvc.dll
[2009/08/23 15:55:39 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\atl.dll
[2009/08/23 15:55:36 | 00,623,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/08/23 15:55:34 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2009/08/23 15:54:59 | 10,628,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmp.dll
[2009/08/23 15:54:55 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpdxm.dll
[2009/08/23 15:54:53 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/08/23 15:54:53 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/08/23 15:54:52 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/08/23 15:54:50 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/08/23 15:54:48 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2009/08/23 15:54:48 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2009/08/23 15:52:14 | 00,784,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcrt4.dll
[2008/12/12 04:10:48 | 00,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2008/06/28 21:41:15 | 00,000,000 | —- | C] () – C:\Windows\ka.ini
[2007/07/06 21:00:17 | 00,000,032 | —- | C] () – C:\Windows\AuthMgr.INI
[2006/11/07 12:25:58 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:44 | 00,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:31 | 00,000,356 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:23:31 | 00,000,215 | —- | C] () – C:\Windows\system.ini
[2006/11/02 00:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 21:36:50 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 21:36:50 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2002/03/13 13:46:46 | 00,053,248 | R— | C] () – C:\Windows\System32\zlib.dll
========== Files - Modified Within 30 Days ==========
[2009/09/20 13:19:24 | 00,514,560 | —- | M] (OldTimer Tools) – C:\Users\Michelle\Desktop\OTL.exe
[2009/09/20 13:13:17 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/09/20 13:13:17 | 00,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/09/20 13:13:17 | 00,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/09/20 11:57:52 | 00,000,046 | —- | M] () – C:\Users\Michelle\Desktop\jay.bat
[2009/09/20 11:46:50 | 00,047,616 | —- | M] () – C:\Users\Michelle\Desktop\Win32kDiag.exe
[2009/09/20 11:45:26 | 00,003,952 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/09/20 11:45:26 | 00,003,952 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/09/20 11:45:25 | 00,016,384 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2009/09/20 11:45:23 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/09/20 11:45:19 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/09/20 11:44:22 | 03,303,278 | -H– | M] () – C:\Users\Michelle\AppData\Local\IconCache.db
[2009/09/20 11:25:44 | 01,592,965 | —- | M] () – C:\Users\Michelle\Documents\AutoRuns.arn
[2009/09/20 09:31:12 | 00,000,215 | —- | M] () – C:\Windows\system.ini
[2009/09/20 09:31:09 | 00,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/09/18 21:20:58 | 00,000,015 | —- | M] () – C:\Users\Michelle\Desktop\settings.dat
[2009/09/18 15:54:22 | 03,316,998 | R— | M] () – C:\Users\Michelle\Desktop\Combo-Fix.exe
[2009/09/18 12:49:52 | 00,000,575 | —- | M] () – C:\Users\Michelle\Desktop\Fixswen.inf
[2009/09/18 11:49:58 | 00,001,876 | —- | M] () – C:\Users\Michelle\Desktop\HijackThis.lnk
[2009/09/18 11:46:54 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Michelle\Desktop\HJTInstall.exe
[2009/09/15 14:33:50 | 00,000,680 | —- | M] () – C:\Users\Michelle\AppData\Local\d3d9caps.dat
[2009/09/15 12:55:41 | 00,000,735 | —- | M] () – C:\Users\Michelle\Desktop\NTREGOPT.lnk
[2009/09/15 12:55:41 | 00,000,716 | —- | M] () – C:\Users\Michelle\Desktop\ERUNT.lnk
[2009/09/15 12:38:52 | 00,472,064 | —- | M] ( ) – C:\Users\Michelle\Desktop\RootRepeal.exe
[2009/09/15 12:38:10 | 00,359,929 | —- | M] () – C:\Users\Michelle\Desktop\dds.scr
[2009/09/15 12:34:08 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Users\Michelle\Desktop\erunt_setup.exe
[2009/09/14 19:03:02 | 00,175,888 | —- | M] () – C:\Users\Michelle\Desktop\activescan2_en.exe
[2009/09/14 18:14:10 | 00,000,356 | —- | M] () – C:\Windows\win.ini
[2009/09/14 18:03:21 | 17,895,0121 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/09/14 17:01:36 | 00,000,049 | —- | M] () – C:\boot.ini
[2009/09/14 16:39:33 | 00,319,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/09/14 04:18:30 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/09/14 02:47:59 | 00,000,764 | —- | M] () – C:\Users\Michelle\Documents\My Sharing Folders.lnk
[2009/09/14 02:45:37 | 00,000,596 | —- | M] () – C:\Users\Michelle\AppData\Roaming\wklnhst.dat
[2009/09/14 02:12:36 | 00,229,888 | —- | M] () – C:\Windows\PEV.exe
[2009/09/13 22:37:59 | 00,000,552 | —- | M] () – C:\Users\Michelle\AppData\Local\d3d8caps.dat
[2009/09/08 15:31:35 | 00,149,758 | —- | M] () – C:\Users\Michelle\AppData\Roaming\tmp6373.sql
[2009/08/28 17:27:49 | 04,240,384 | —- | M] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/08/28 17:14:38 | 00,028,672 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/08/28 14:38:20 | 24,689,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
========== LOP Check ==========
[2009/09/14 18:14:11 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming
[2009/01/17 17:32:52 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\7Wonders
[2008/11/27 01:17:24 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\ArcSoft
[2008/07/03 19:20:28 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\cerasus.media
[2008/12/01 14:52:34 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Earthlink
[2009/03/27 18:05:54 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\EnchantedCavern
[2009/06/28 08:20:21 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Flood Light Games
[2008/12/03 03:04:51 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Gogii Games
[2009/08/26 15:30:59 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\IronCode
[2008/04/11 15:44:20 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iWin
[2008/06/03 00:14:50 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\iWinArcade
[2009/09/08 22:24:56 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Key Folder
[2008/07/03 15:19:49 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Legends of pirates
[2008/06/25 14:06:35 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\LimeWire
[2006/11/02 05:37:34 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Media Center Programs
[2008/09/11 20:43:24 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\pixelStorm
[2009/08/26 16:01:07 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\PlayFirst
[2009/04/30 20:08:56 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\RobinsonCrusoeOM
[2007/12/08 20:28:23 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Roxio
[2009/04/30 19:49:45 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\SpinTop
[2009/02/09 22:44:15 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Template
[2009/04/03 19:08:28 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\TimeQuest
[2009/01/25 00:43:53 | 00,000,000 | —D | M] – C:\Users\Michelle\AppData\Roaming\Windows Live Writer
[2009/09/20 11:45:23 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/09/20 11:44:34 | 00,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:9A30D43E
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:6533A988
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:F7F201FE
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:5A9AF3C7
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:CEDA49F4
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:52110139
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:729F0E7F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:B838CD98
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:0C22BA56
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D5D1F833
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CFC8A5FD
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1C4D3509
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D8669B93
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:56486BDA
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A3F34956
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:EE9AD6CC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:3C5ABDC7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3550534F
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:E22FF3D0
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3B1DF498
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:1BFDB632
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:101708D3
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:EF1813D7
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:343BD036
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:2FE747C7
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A87B4345
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:C8A0BC27
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:5F3235B3
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:6B181B84
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:7A0EFE63
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:CDF8423E
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:22A44AC3
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:753B8DFE
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:3E5C6753
< End of report >