Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93081 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Closed] Hijackthis log


  • This topic is locked This topic is locked
16 replies to this topic

#1 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 07 October 2009 - 10:07 AM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:20 AM, on 10/7/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
c:\PROGRA~2\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files (x86)\IncrediMail\bin\IMApp.exe
C:\Program Files (x86)\IncrediMail\bin\IncMail.exe
C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...;m=aspire_x1700
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cy...mallsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.winstonsa...craigslist.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...;m=aspire_x1700
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...;m=aspire_x1700
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~2\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~2\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] "C:\Program Files (x86)\Acer\Acer Assist\launcher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files (x86)\IncrediMail\bin\IncMail.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] "C:\Windows\ehome\ehTray.exe"
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [Zilla Popup Killer] "C:\Program Files (x86)\Zilla Popup Killer\ZillaPop.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-587824317-523569438-2809485909-1001\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (User 'Andrew')
O4 - Global Startup: sQusi Tracking Plus.lnk = C:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusiLaunch.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: c:\progra~2\squsi\squsit~1\squsi20stb.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files (x86)\a-squared Free\a2service.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Google Update Service (gupdate1c9f45e48d84d6e) (gupdate1c9f45e48d84d6e) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe

--
End of file - 12558 bytes

    Advertisements

Register to Remove


#2 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 07 October 2009 - 11:44 AM

Can you advise what issues you are having?

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#3 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 07 October 2009 - 11:54 AM

Some well known websites come up as just a blank page. Not able to access them. Or certain parts are missing from the page. Runtime errors and getting kicked off the internet. I typically run Firefox. Stalls when access web pages.

#4 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 07 October 2009 - 11:58 AM

Hi,

Please do the following:


Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Check the box that says 64 bit
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#5 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 07 October 2009 - 12:08 PM

OTS logfile created on: 10/7/2009 2:03:21 PM - Run 1
OTS by OldTimer - Version 3.0.20.3	 Folder = C:\Users\Yolanda\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 2.08 Gb Available Physical Memory | 52.11% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 289.58 Gb Total Space | 217.15 Gb Free Space | 74.99% Space Free | Partition Type: NTFS
Drive D: | 291.59 Gb Total Space | 280.51 Gb Free Space | 96.20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 702.31 Mb Total Space | 696.61 Mb Free Space | 99.19% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: YOLANDA-PC
Current User Name: Yolanda
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
a2service.exe -> C:\Program Files (x86)\a-squared Free\a2service.exe -> [2009/05/17 16:13:50 | 00,717,320 | ---- | M] (Emsi Software GmbH)
agentsvc.exe -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -> [2008/03/03 16:11:14 | 00,016,384 | ---- | M] (NewTech Infosystems, Inc.)
backupsvc.exe -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -> [2008/04/26 00:36:20 | 00,045,056 | ---- | M] (NewTech InfoSystems, Inc.)
bkuptray.exe -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe -> [2008/04/26 00:36:20 | 00,028,672 | ---- | M] ()
clmsserver.exe -> C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -> [2008/05/20 20:50:50 | 00,269,448 | ---- | M] (CyberLink)
clmsserver.exe -> C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -> [2008/05/20 20:50:50 | 00,269,448 | ---- | M] (CyberLink)
devdetect.exe -> C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe -> [2007/03/12 18:36:36 | 00,288,304 | ---- | M] (ACD Systems, Ltd.)
devdetect.exe -> C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe -> [2007/03/12 18:36:36 | 00,288,304 | ---- | M] (ACD Systems, Ltd.)
edsmsnloader32.exe -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe -> [2008/07/29 20:52:56 | 00,454,704 | ---- | M] (Egis inc.)
edsservice.exe -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008/07/29 20:53:00 | 00,500,784 | ---- | M] (Egis Incorporated)
edsservice.exe -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008/07/29 20:53:00 | 00,500,784 | ---- | M] (Egis Incorporated)
firefox.exe -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe -> [2009/09/12 11:00:38 | 00,908,280 | ---- | M] (Mozilla Corporation)
hijackthis.exe -> C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe -> [2009/10/07 10:25:10 | 00,396,288 | ---- | M] (Trend Micro Inc.)
imapp.exe -> C:\Program Files (x86)\IncrediMail\bin\IMApp.exe -> [2009/04/16 11:56:58 | 00,189,824 | ---- | M] (IncrediMail, Ltd.)
jusched.exe -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe -> [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
lssrvc.exe -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2007/01/17 14:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcagent.exe -> c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcmscsvc.exe -> C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -> [2009/03/25 17:25:20 | 00,797,864 | ---- | M] (McAfee, Inc.)
mcnasvc.exe -> c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -> [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
mcnasvc.exe -> c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -> [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
mcnasvc.exe -> c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -> [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
mcproxy.exe -> c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -> [2009/01/09 08:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.)
mcproxy.exe -> c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -> [2009/01/09 08:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.)
mcsacore.exe -> C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -> [2009/03/11 20:11:14 | 00,210,216 | ---- | M] ()
mcsysmon.exe -> C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -> [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.)
mpfsrv.exe -> C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -> [2009/03/19 11:42:02 | 00,884,360 | ---- | M] (McAfee, Inc.)
msksrver.exe -> C:\Program Files (x86)\McAfee\MSK\MskSrver.exe -> [2009/01/09 09:22:10 | 00,026,640 | ---- | M] (McAfee, Inc.)
ots.exe -> C:\Users\Yolanda\Downloads\OTS.exe -> [2009/10/07 14:00:59 | 00,519,168 | ---- | M] (OldTimer Tools)
ots.exe -> C:\Users\Yolanda\Downloads\OTS.exe -> [2009/10/07 14:00:59 | 00,519,168 | ---- | M] (OldTimer Tools)
ots.exe -> C:\Users\Yolanda\Downloads\OTS.exe -> [2009/10/07 14:00:59 | 00,519,168 | ---- | M] (OldTimer Tools)
richvideo.exe -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2008/06/13 00:17:38 | 00,241,734 | ---- | M] ()
richvideo.exe -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2008/06/13 00:17:38 | 00,241,734 | ---- | M] ()
schedulersvc.exe -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -> [2008/04/26 00:36:02 | 00,131,072 | ---- | M] ()
schedulersvc.exe -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -> [2008/04/26 00:36:02 | 00,131,072 | ---- | M] ()
softwareupdate.exe -> C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -> [2008/07/30 12:34:12 | 00,566,592 | ---- | M] (Apple Inc.)
softwareupdate.exe -> C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -> [2008/07/30 12:34:12 | 00,566,592 | ---- | M] (Apple Inc.)
spysweeper.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
spysweeper.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
spysweeper.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
spysweeper.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
spysweeper.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
spysweeperui.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe -> [2009/05/13 15:40:08 | 06,345,840 | ---- | M] (Webroot Software, Inc.)
squsi20.exe -> C:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20.exe -> [2008/10/17 15:51:02 | 00,555,008 | ---- | M] (GCNet Incorporated)
ssu.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\SSU.EXE -> [2009/04/21 18:26:50 | 00,165,232 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
wrconsumerservice.exe -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
 
[Win32 Services - Safe List]
64bit-(AgereModemAudio) Agere Modem Call Progress Audio [Win32_Own | Auto | Running] -> C:\Windows\SysNative\agr64svc.exe -> [2007/12/10 23:11:30 | 00,015,872 | ---- | M] (Agere Systems)
64bit-(ETService) Empowering Technology Service [Win32_Own | Auto | Running] -> C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -> [2008/08/19 17:27:22 | 00,024,576 | ---- | M] ()
64bit-(McODS) McAfee Scanner [Win32_Own | On_Demand | Stopped] -> C:\Program Files\McAfee\VirusScan\mcods.exe -> [2009/04/01 14:21:30 | 00,696,848 | ---- | M] (McAfee, Inc.)
64bit-(McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> C:\Program Files\McAfee\VirusScan\Mcshield.exe -> [2009/03/25 10:59:30 | 00,153,920 | ---- | M] (McAfee, Inc.)
64bit-(WinDefend) Windows Defender [Win32_Shared | Auto | Running] -> C:\Program Files\Windows Defender\mpsvc.dll -> [2008/01/20 22:47:32 | 00,383,544 | ---- | M] (Microsoft Corporation)
64bit-(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> C:\Program Files\Windows Media Player\wmpnetwk.exe -> [2008/01/20 22:52:15 | 01,216,000 | ---- | M] (Microsoft Corporation)
(a2free) a-squared Free Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\a-squared Free\a2service.exe -> [2009/05/17 16:13:50 | 00,717,320 | ---- | M] (Emsi Software GmbH)
(Acer HomeMedia Connect Service) Acer HomeMedia Connect Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -> [2008/05/20 20:50:50 | 00,269,448 | ---- | M] (CyberLink)
(BUNAgentSvc) NTI Backup Now 5 Agent Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -> [2008/03/03 16:11:14 | 00,016,384 | ---- | M] (NewTech Infosystems, Inc.)
(clr_optimization_v2.0.50727_32) Microsoft .NET Framework NGEN v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2009/03/30 00:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_64) Microsoft .NET Framework NGEN v2.0.50727_X64 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -> [2009/03/30 00:39:54 | 00,089,920 | ---- | M] (Microsoft Corporation)
(eDataSecurity Service) eDataSecurity Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -> [2008/07/29 20:53:00 | 00,500,784 | ---- | M] (Egis Incorporated)
(ehRecvr) Windows Media Center Receiver Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehRecvr.exe -> [2008/01/20 22:51:36 | 00,344,064 | ---- | M] (Microsoft Corporation)
(ehSched) Windows Media Center Scheduler Service [Win32_Own | On_Demand | Stopped] -> C:\Windows\ehome\ehsched.exe -> [2008/01/20 22:51:36 | 00,153,600 | ---- | M] (Microsoft Corporation)
(ehstart) Windows Media Center Service Launcher [Win32_Shared | Auto | Stopped] -> C:\Windows\ehome\ehstart.dll -> [2006/11/02 11:03:48 | 00,015,360 | ---- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -> [2009/02/18 14:40:04 | 00,042,840 | ---- | M] (Microsoft Corporation)
(gupdate1c9f45e48d84d6e) Google Update Service (gupdate1c9f45e48d84d6e) [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -> [2009/06/23 19:56:31 | 00,133,104 | ---- | M] (Google Inc.)
(gusvc) Google Software Updater [Win32_Own | Auto | Stopped] -> C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/06/23 19:56:02 | 00,183,280 | ---- | M] (Google)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -> [2009/02/18 14:39:11 | 00,857,432 | ---- | M] (Microsoft Corporation)
(KeyIso) CNG Key Isolation [Win32_Shared | On_Demand | Stopped] -> C:\Windows\SysWow64\keyiso.dll -> [2006/11/02 05:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -> [2007/01/17 14:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company)
(McAfee SiteAdvisor Service) McAfee SiteAdvisor Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -> [2009/03/11 20:11:14 | 00,210,216 | ---- | M] ()
(mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -> [2009/03/25 17:25:20 | 00,797,864 | ---- | M] (McAfee, Inc.)
(McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -> [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
(McProxy) McAfee Proxy Service [Win32_Own | Auto | Running] -> c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -> [2009/01/09 08:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.)
(McSysmon) McAfee SystemGuards [Win32_Own | On_Demand | Running] -> C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -> [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.)
(MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -> [2009/03/19 11:42:02 | 00,884,360 | ---- | M] (McAfee, Inc.)
(MSDTC) Distributed Transaction Coordinator [Win32_Own | Unknown | Stopped] -> C:\Windows\SysWow64\Msdtc -> [2006/11/02 09:34:14 | 00,000,000 | ---D | M]
(MSK80Service) McAfee Anti-Spam Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\McAfee\MSK\MskSrver.exe -> [2009/01/09 09:22:10 | 00,026,640 | ---- | M] (McAfee, Inc.)
(Netlogon) Netlogon [Win32_Shared | On_Demand | Stopped] -> C:\Windows\SysWow64\netlogon.dll -> [2009/04/11 02:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation)
(NTIBackupSvc) NTI Backup Now 5 Backup Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -> [2008/04/26 00:36:20 | 00,045,056 | ---- | M] (NewTech InfoSystems, Inc.)
(NTISchedulerSvc) NTI Backup Now 5 Scheduler Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -> [2008/04/26 00:36:02 | 00,131,072 | ---- | M] ()
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 17:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe -> [2008/06/13 00:17:38 | 00,241,734 | ---- | M] ()
(vds) Virtual Disk [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vds.mof -> [2006/11/02 02:35:15 | 00,060,994 | ---- | M] ()
(VSS) Volume Shadow Copy [Win32_Own | On_Demand | Stopped] -> C:\Windows\SysWow64\Wbem\vss.mof -> [2006/11/02 02:35:15 | 00,055,846 | ---- | M] ()
(WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe -> [2009/04/21 18:26:52 | 04,048,240 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
(WRConsumerService) Webroot Client Service [Win32_Own | Auto | Running] -> C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe -> [2009/06/12 08:54:24 | 01,205,760 | ---- | M] (Webroot Software, Inc. )
 
[Driver Services - Safe List]
64bit-(AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\agrsm64.sys -> [2008/03/05 02:22:34 | 01,253,376 | ---- | M] (Agere Systems)
64bit-(HdAudAddService) Microsoft 1.1 UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HdAudio.sys -> [2006/11/02 01:28:10 | 00,273,920 | ---- | M] (Microsoft Corporation)
64bit-(ITEIO.SYS) ITEIO.SYS [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ITEIO.sys -> [2008/02/25 19:29:24 | 00,013,144 | ---- | M] (Windows (R) Codename Longhorn DDK provider)
64bit-(mfeavfk) McAfee Inc. mfeavfk [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\mfeavfk.sys -> [2009/03/25 11:06:22 | 00,102,600 | ---- | M] (McAfee, Inc.)
64bit-(mfehidk) McAfee Inc. mfehidk [Kernel | System | Running] -> C:\Windows\SysNative\drivers\mfehidk.sys -> [2009/03/25 11:06:22 | 00,307,400 | ---- | M] (McAfee, Inc.)
64bit-(mferkdk) McAfee Inc. mferkdk [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\mferkdk.sys -> [2009/03/25 10:59:38 | 00,040,904 | ---- | M] (McAfee, Inc.)
64bit-(mfesmfk) McAfee Inc. mfesmfk [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\mfesmfk.sys -> [2009/03/25 11:06:22 | 00,049,480 | ---- | M] (McAfee, Inc.)
64bit-(MPFP) MPFP [Kernel | System | Running] -> C:\Windows\SysNative\Drivers\Mpfp.sys -> [2008/10/23 13:08:54 | 00,176,144 | ---- | M] (McAfee, Inc.)
64bit-(NTIDrvr) Upper Class Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\Drivers\NTIDrvr.sys -> [2008/01/30 20:48:32 | 00,016,384 | ---- | M] (NewTech Infosystems, Inc.)
64bit-(NVHDA) Service for NVIDIA High Definition Audio Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\nvhda64v.sys -> [2008/08/05 00:29:26 | 00,056,352 | ---- | M] (NVIDIA Corporation)
64bit-(PSDFilter) PSDFilter [File_System | Boot | Running] -> C:\Windows\SysNative\DRIVERS\psdfilter.sys -> [2008/07/29 20:53:48 | 00,022,064 | ---- | M] (Egis Incorporated)
64bit-(PSDNServ) PSDNServ [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSDNServ.sys -> [2008/07/29 20:53:50 | 00,021,040 | ---- | M] (Egis Incorporated)
64bit-(psdvdisk) psdvdisk [Kernel | Auto | Running] -> C:\Windows\SysNative\DRIVERS\PSDVdisk.sys -> [2008/07/29 20:53:50 | 00,060,976 | ---- | M] (Egis Incorporated)
64bit-(ssfs0bbc) ssfs0bbc [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\ssfs0bbc.sys -> [2009/04/21 18:27:04 | 00,037,488 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
64bit-(ssidrv) ssidrv [Kernel | Boot | Running] -> C:\Windows\SysNative\DRIVERS\ssidrv.sys -> [2009/04/21 18:27:06 | 00,135,280 | ---- | M] (Webroot Software, Inc. (www.webroot.com))
64bit-(UBHelper) UBHelper [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\UBHelper.sys -> [2008/01/30 20:48:16 | 00,016,384 | ---- | M] (NewTech Infosystems Corporation)
64bit-(WSVD) WSVD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\WSVD.sys -> [2008/05/26 14:54:28 | 00,120,816 | ---- | M] (CyberLink)
(int15) int15 [Kernel | Auto | Running] -> C:\Windows\SysWOW64\drivers\int15_64.sys -> [2008/08/19 17:23:00 | 00,017,952 | ---- | M] (Acer, Inc.)
(mpsdrv) Windows Firewall Authorization Driver [Kernel | On_Demand | Running] -> C:\Windows\SysWow64\Wbem\mpsdrv.mof -> [2006/09/18 17:35:23 | 00,001,088 | ---- | M] ()
(PSDFilter) PSDFilter [File_System | Boot | Running] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDFilter.inf -> [2007/12/13 06:07:34 | 00,003,481 | ---- | M] ()
(PSDNServ) PSDNServ [Kernel | Auto | Running] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDNserv.inf -> [2007/12/13 06:07:34 | 00,003,460 | ---- | M] ()
(psdvdisk) psdvdisk [Kernel | Auto | Running] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDVDisk.inf -> [2007/12/13 06:07:34 | 00,003,459 | ---- | M] ()
(Tcpip) TCP/IP Protocol Driver [Kernel | System | Running] -> C:\Windows\SysWow64\Wbem\tcpip.mof -> [2006/09/18 17:36:40 | 00,003,066 | ---- | M] ()
 
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"Default_Secondary_Page_URL" -> http://global.acer.com [binary data] -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"Local Page" -> C:\Windows\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"SearchDefaultBranded" -> 1 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"Start Page" -> http://www.winstonsalem.craigslist.org/ -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: Main\\"StartPageCache" -> 1 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\] > -> -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Default_Secondary_Page_URL" -> http://global.acer.com [binary data] -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Local Page" -> C:\Windows\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"SearchDefaultBranded" -> 1 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Secondary Start Pages" -> http://global.acer.com [binary data] -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=1006&m=aspire_x1700 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: Main\\"StartPageCache" -> 1 -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\: "ProxyEnable" -> 0 -> 
< FireFox Settings [Prefs.js] > -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\prefs.js -> 
browser.search.defaultenginename -> "Fast Browser Search" ->
browser.search.defaultthis.engineName -> "CommentsBar - Social Comments Customized Web Search" ->
browser.search.defaulturl -> "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=13&q=" ->
browser.search.order.1 -> "Fast Browser Search" ->
browser.search.selectedEngine -> "Fast Browser Search" ->
browser.search.useDBForOrder -> true ->
browser.startup.homepage -> "http://winstonsalem.craigslist.org/" ->
extensions.enabledItems -> anycolor.pavlos256@gmail.com:0.3.0 ->
extensions.enabledItems -> {47624dda-b77e-4feb-820a-e4f077d5d4ca}:9.8.6 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15 ->
extensions.enabledItems -> {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.1 ->
extensions.enabledItems -> {C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}:2.2.5 ->
extensions.enabledItems -> personas@christopher.beard:1.2.3 ->
extensions.enabledItems -> {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 ->
keyword.URL -> "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=13&tid={B87C538B-2BE7-BA59-95CD-7CE04D8C471B}&q=" ->
< FireFox Settings [User.js] > -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\user.js -> 
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/09/02 03:00:36 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45} -> C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR [C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR] -> [2009/08/29 21:22:58 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/09/12 11:00:43 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/09/12 11:00:43 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions -> [2009/09/02 22:04:01 | 00,000,000 | ---D | M]
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/09/02 22:04:01 | 00,000,000 | ---D | M]
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org -> [2009/09/02 22:04:01 | 00,000,000 | ---D | M]
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca} -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB} -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\anycolor.pavlos256@gmail.com -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
 -> C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\personas@christopher.beard -> [2009/09/15 14:44:08 | 00,103,209 | ---- | M] ()
< FireFox SearchPlugins [User Folders] > -> 
C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\ -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins -> [2009/08/27 10:24:36 | 00,000,000 | ---D | M]
conduit.xml -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\conduit.xml -> [2009/07/16 18:09:38 | 00,000,920 | ---- | M] ()
fast-browser-search.xml -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\fast-browser-search.xml -> [2009/05/16 19:24:29 | 00,005,407 | ---- | M] ()
MyStart Search.xml -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\MyStart Search.xml -> [2009/08/27 10:24:36 | 00,002,137 | ---- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions -> [2009/09/12 11:00:43 | 10,776,568 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/09/12 11:00:43 | 10,776,568 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -> [2009/09/12 11:00:43 | 10,776,568 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} -> [2009/09/12 11:00:43 | 10,776,568 | ---- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} -> [2009/09/12 11:00:43 | 10,776,568 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components -> [2009/09/12 11:00:43 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/09/12 11:00:37 | 00,023,544 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/09/12 11:00:37 | 00,137,208 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins -> [2009/09/12 11:00:43 | 00,000,000 | ---D | M]
npdeploytk.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npdeploytk.dll -> [2009/07/25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.)
npLegitCheckPlugin.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npLegitCheckPlugin.dll -> [2009/02/06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation)
npnul32.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/09/12 11:00:41 | 00,065,016 | ---- | M] (mozilla.org)
npqtplugin.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin.dll -> [2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin2.dll -> [2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin3.dll -> [2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin4.dll -> [2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin5.dll -> [2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin6.dll -> [2009/06/02 11:21:41 | 00,143,360 | ---- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\npqtplugin7.dll -> [2009/06/02 11:21:41 | 00,143,360 | ---- | M] (Apple Inc.)
QuickTimePlugin.class -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\plugins\QuickTimePlugin.cla -> [2009/06/02 11:21:40 | 00,004,208 | ---- | M] ()
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins -> [2009/08/29 10:01:42 | 00,000,000 | ---D | M]
amazondotcom.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/08/29 10:01:39 | 00,001,394 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/08/29 10:01:39 | 00,002,193 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/08/29 10:01:39 | 00,001,534 | ---- | M] ()
eBay.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/08/29 10:01:39 | 00,002,344 | ---- | M] ()
fast.png -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\fast.png -> [2009/06/13 17:11:39 | 00,003,700 | ---- | M] ()
fast.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\fast.xml -> [2009/06/13 17:11:39 | 00,001,963 | ---- | M] ()
google.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/08/29 10:01:39 | 00,002,371 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/08/29 10:01:39 | 00,001,178 | ---- | M] ()
yahoo.xml -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/08/29 10:01:39 | 00,000,792 | ---- | M] ()
< HOSTS File > (761 bytes and 20 lines) -> C:\Windows\SysNative\Drivers\etc\hosts -> 
Reset Hosts
127.0.0.1	   localhost
::1			 localhost
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{27B4851A-3207-45A2-B947-BE8AFE6163AB} [HKLM] -> c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll [McAfee Phishing Filter] -> [2009/01/09 09:22:10 | 00,337,424 | ---- | M] ()
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKLM] -> c:\Program Files\McAfee\VirusScan\scriptsn.dll [scriptproxy] -> [2009/03/25 10:59:38 | 00,060,224 | ---- | M] (McAfee, Inc.)
{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} [HKLM] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll [ShowBarObj Class] -> [2008/07/29 20:53:14 | 00,378,416 | ---- | M] (Egis)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar Helper] -> [2009/09/16 21:02:21 | 00,346,736 | ---- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg64.dll [Google Toolbar Notifier BHO] -> [2009/10/05 21:36:14 | 00,317,936 | ---- | M] (Google Inc.)
{B164E929-A1B6-4A06-B104-2CD0E90A88FF} [HKLM] -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [McAfee SiteAdvisor BHO] -> [2009/02/13 12:45:04 | 00,200,208 | ---- | M] ()
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/23 02:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{27B4851A-3207-45A2-B947-BE8AFE6163AB} [HKLM] -> c:\Program Files (x86)\McAfee\MSK\mskapbho.dll [McAfee Phishing Filter] -> [2009/01/09 09:22:10 | 00,246,800 | ---- | M] ()
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKLM] -> c:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll [scriptproxy] -> [2009/03/25 11:05:56 | 00,062,784 | ---- | M] (McAfee, Inc.)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar Helper] -> [2009/09/16 21:02:20 | 00,256,112 | ---- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [Google Toolbar Notifier BHO] -> [2009/10/05 21:36:14 | 00,762,864 | ---- | M] (Google Inc.)
{B164E929-A1B6-4A06-B104-2CD0E90A88FF} [HKLM] -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [McAfee SiteAdvisor BHO] -> [2009/02/13 12:44:56 | 00,150,032 | ---- | M] ()
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [Google Dictionary Compression sdch] -> [2009/09/16 21:02:17 | 00,458,736 | ---- | M] (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/07/25 05:23:03 | 00,041,760 | ---- | M] (Sun Microsystems, Inc.)
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}" [HKLM] -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [McAfee SiteAdvisor Toolbar] -> [2009/02/13 12:45:04 | 00,200,208 | ---- | M] ()
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2009/09/16 21:02:21 | 00,346,736 | ---- | M] (Google Inc.)
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/07/29 20:53:24 | 00,181,296 | ---- | M] (Egis Incorporated.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}" [HKLM] -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [McAfee SiteAdvisor Toolbar] -> [2009/02/13 12:44:56 | 00,150,032 | ---- | M] ()
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2009/09/16 21:02:20 | 00,256,112 | ---- | M] (Google Inc.)
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/07/29 20:52:08 | 00,142,896 | ---- | M] (Egis Incorporated.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\Software\Microsoft\Internet Explorer\Toolbar\ -> 
64bit-ShellBrowser\\"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/07/29 20:53:24 | 00,181,296 | ---- | M] (Egis Incorporated.)
ShellBrowser\\"{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}" [HKLM] -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [Acer eDataSecurity Management] -> [2008/07/29 20:52:08 | 00,142,896 | ---- | M] (Egis Incorporated.)
64bit-WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2009/09/16 21:02:21 | 00,346,736 | ---- | M] (Google Inc.)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2009/09/16 21:02:20 | 00,256,112 | ---- | M] (Google Inc.)
WebBrowser\\"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\Software\Microsoft\Internet Explorer\Toolbar\ -> 
64bit-WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2009/09/16 21:02:21 | 00,346,736 | ---- | M] (Google Inc.)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2009/09/16 21:02:20 | 00,256,112 | ---- | M] (Google Inc.)
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Acer Empowering Technology Monitor" -> C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ["C:\Program Files\Acer\Empowering Technology\SysMonitor.exe"] -> [2008/08/19 17:28:18 | 00,319,488 | ---- | M] ()
"eDataSecurity Loader" -> C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe ["C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe"] -> [2008/07/29 20:53:44 | 00,561,200 | ---- | M] (Egis Incorporated)
"EmpoweringTechnology" -> C:\Program Files\Acer\Empowering Technology\Framework.Lau ["C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" boot] -> File not found
"NvCplDaemon" -> C:\Windows\SysNative\NvCpl.DLL ["RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup] -> [2008/10/16 03:16:00 | 15,940,640 | ---- | M] (NVIDIA Corporation)
"RtHDVCpl" -> C:\Windows\RAVCpl64.exe ["RAVCpl64.exe"] -> [2008/08/19 06:28:00 | 06,456,352 | ---- | M] (Realtek Semiconductor)
"Skytel" -> C:\Windows\SkyTel.exe ["Skytel.exe"] -> [2008/08/19 06:29:00 | 01,833,504 | ---- | M] (Realtek Semiconductor Corp.)
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/20 22:47:32 | 01,584,184 | ---- | M] (Microsoft Corporation)
"WPCUMI" -> C:\Windows\SysNative\WpcUmi.exe ["C:\Windows\system32\WpcUmi.exe"] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Acer Assist Launcher" -> C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ["C:\Program Files (x86)\Acer\Acer Assist\launcher.exe"] -> [2007/11/19 18:17:40 | 01,261,568 | ---- | M] ()
"Acer Product Registration" -> C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe ["C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe" /startup] -> [2007/11/26 14:21:22 | 03,387,392 | ---- | M] (Leader Technologies)
"Adobe Reader Speed Launcher" -> C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2007/03/08 07:38:54 | 00,040,048 | ---- | M] (Adobe Systems Incorporated)
"BkupTray" -> C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ["C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"] -> [2008/04/26 00:36:20 | 00,028,672 | ---- | M] ()
"mcagent_exe" -> C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe ["C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey] -> [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.)
"PCMMediaSharing" -> C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ["C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"] -> [2008/05/20 20:50:52 | 00,204,908 | ---- | M] ()
"QuickTime Task" -> C:\Program Files (x86)\QuickTime\QTTask.exe ["C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime] -> [2009/05/26 17:18:30 | 00,413,696 | ---- | M] (Apple Inc.)
"SpySweeper" -> C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe ["C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray] -> [2009/05/13 15:40:08 | 06,345,840 | ---- | M] (Webroot Software, Inc.)
"SunJavaUpdateSched" -> C:\Program Files (x86)\Java\jre6\bin\jusched.exe ["C:\Program Files (x86)\Java\jre6\bin\jusched.exe"] -> [2009/07/25 05:23:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 02:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 02:28:23 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 02:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 02:28:23 | 02,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Device Detector" ->  [DevDetect.exe -autorun] -> File not found
"ehTray.exe" -> C:\Windows\ehome\ehTray.exe ["C:\Windows\ehome\ehTray.exe"] -> [2008/01/20 22:51:33 | 00,138,240 | ---- | M] (Microsoft Corporation)
"IncrediMail" -> C:\Program Files (x86)\IncrediMail\bin\IncMail.exe ["C:\Program Files (x86)\IncrediMail\bin\IncMail.exe" /c] -> [2009/04/16 11:57:02 | 00,251,264 | ---- | M] (IncrediMail, Ltd.)
"swg" -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ["C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"] -> [2009/05/05 13:25:38 | 00,068,856 | ---- | M] (Google Inc.)
"WMPNSCFG" -> C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe [C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe] -> File not found
"Zilla Popup Killer" -> C:\Program Files (x86)\Zilla Popup Killer\ZillaPop.exe ["C:\Program Files (x86)\Zilla Popup Killer\ZillaPop.exe"] -> File not found
< Run [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"swg" -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ["C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"] -> [2009/05/05 13:25:38 | 00,068,856 | ---- | M] (Google Inc.)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" ->  [1] -> File not found
\\"ForceActiveDesktopOn" ->  [0] -> File not found
\\"NoActiveDesktopChanges" ->  [0] -> File not found
\\"BindDirectlyToPropertySetStorage" ->  [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [2] -> File not found
\\"ConsentPromptBehaviorUser" ->  [1] -> File not found
\\"EnableInstallerDetection" ->  [1] -> File not found
\\"EnableLUA" ->  [1] -> File not found
\\"EnableSecureUIAPaths" ->  [1] -> File not found
\\"EnableVirtualization" ->  [1] -> File not found
\\"PromptOnSecureDesktop" ->  [1] -> File not found
\\"ValidateAdminCodeSignatures" ->  [0] -> File not found
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"scforceoption" ->  [0] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"FilterAdministratorToken" ->  [0] -> File not found
\\"EnableUIADesktopToggle" ->  [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
\UIPI\Clipboard\ExceptionFormats\\"CF_TEXT" ->  [1] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_BITMAP" ->  [2] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_OEMTEXT" ->  [7] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIB" ->  [8] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_PALETTE" ->  [9] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_UNICODETEXT" ->  [13] -> File not found
\UIPI\Clipboard\ExceptionFormats\\"CF_DIBV5" ->  [17] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"LogonHoursAction" ->  [2] -> File not found
\\"DontDisplayLogonHoursWarnings" ->  [1] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"LogonHoursAction" ->  [2] -> File not found
\\"DontDisplayLogonHoursWarnings" ->  [1] -> File not found
< 64bit-Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&Add animation to IncrediMail Style Box -> C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm [C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm] -> [2008/12/10 09:38:14 | 00,000,591 | ---- | M] ()
E&xport to Microsoft Excel -> C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | ---- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&Add animation to IncrediMail Style Box -> C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm [C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm] -> [2008/12/10 09:38:14 | 00,000,591 | ---- | M] ()
E&xport to Microsoft Excel -> C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000] -> [2009/05/04 08:40:04 | 18,333,536 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2008/10/25 07:52:00 | 00,604,056 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2008/10/25 07:52:00 | 00,604,056 | ---- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 00,039,464 | ---- | M] (Microsoft Corporation)
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab [Java Plug-in 1.6.0_15] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> 209.18.47.61 209.18.47.62 -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{C163FDE0-3634-4EAC-8584-85130DD122FA}\\DhcpNameServer -> 209.18.47.61 209.18.47.62   (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> 
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 
c:\progra~2\squsi\squsit~1\squsi20stb.dll -> c:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20Stb.dll -> [2008/10/17 15:52:26 | 00,225,280 | ---- | M] (GCNet Incorporated)
*MultiFile Done* -> -> 
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\explorer.exe -> [2009/04/11 03:10:17 | 03,079,168 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2009/04/11 02:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
64bit-*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
ows\S ->  -> File not found
*MultiFile Done* -> -> 
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
ows\S ->  -> File not found
*MultiFile Done* -> -> 
< LSA Security Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
64bit-*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
ication Packages settings... ->  -> File not found
ntrolSet ->  -> File not found
*MultiFile Done* -> -> 
*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
e not found ->  -> File not found
DataSecurity\x86\ication ->  -> File not found
*MultiFile Done* -> -> 
< Vista Public Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications -> 
< Vista Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications -> 
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{09C0EA47-EE29-4180-B09B-8715F78A942A} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{1542C11E-9699-47EA-9074-CE7B91748F0A} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system | 
{30555814-8EC4-4A6C-80C9-319B42C32422} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{59FC2C5D-B2C8-4401-B1F5-5367EDE7B7E4} -> lport=2869 | profile=domain | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system | 
{6D67033D-9011-48BA-A38C-D78016F91BB0} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system | 
{732C6E28-EF85-4FFA-B101-94935DC64C72} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{99B92C60-1372-4569-B920-7785F9A89D40} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{9FAF068E-F161-42E2-B64B-78866E6520AC} -> rport=1900 | profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
{F2D00664-F6BE-4735-9646-E95C1A8D9B76} -> lport=1900 | profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{11DE3C77-8D07-4ED4-8A9E-2C11CBB199C1} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe | 
{12D34FB7-EA9F-4378-9452-B0139F1CE503} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{1668E2CF-BBE3-4A2A-922B-9268236D8434} -> dir=in | action=allow | name=acer videomagician | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe | 
{19EA7827-1125-43E6-B135-E3F7A9880CCE} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{1CE9CFE3-97EB-4A1F-9382-BA8EB5504233} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system | 
{1DA4DF50-7A05-409D-BA6B-03E28E26184D} -> dir=in | action=allow | name=acer homemedia connect | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe | 
{239448E9-D534-4A4B-98B8-926E0E1665F3} -> profile=private | protocol=17 | dir=in | action=allow | name=limewire | app=c:\program files (x86)\limewire\limewire.exe | 
{24A29ABB-BAFB-422F-9B3B-1FA312F991AB} -> profile=domain | dir=in | action=allow | name=mcafee network agent | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe | 
{2FDC4712-0070-4C45-B27B-7328262E6169} -> profile=public | protocol=17 | dir=in | action=allow | name=backupsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe | 
{3AE451E9-91B6-4640-A19F-7D75F9584ABB} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{5A516DC0-C83C-4F92-91EF-4A21F674CACD} -> profile=public | protocol=17 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{5FB9C3C8-9BF6-4FCD-99DB-42D725DEFCA5} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{60A5F4A5-5D3F-44FB-B485-541C3A893C51} -> dir=in | action=allow | name=acer slideshow dvd | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe | 
{63F1225A-F8AA-4AA2-9974-D4C219D97A52} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{6FADE3B4-DBF8-4F3D-91DD-F7A32A087BA6} -> dir=in | action=allow | name=acer dv magician | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe | 
{743D8FE1-0953-4A9A-BF80-26A5E88361EA} -> dir=in | action=allow | name=acer dvdivine | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe | 
{7643B6C0-1B9E-482D-93BE-F0547AC92F6A} -> dir=in | action=allow | name=acer homemedia connect service | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe | 
{7B829611-6E88-4E5B-A5C1-7B28FB5B157C} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31325 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{7FE2CD36-9D58-4084-9106-C17CCD7CBBC7} -> profile=private | protocol=6 | dir=in | action=allow | name=limewire | app=c:\program files (x86)\limewire\limewire.exe | 
{7FF28C58-51D0-4A85-B313-34C36613D7D0} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost | 
{8CB91948-6C3F-40BA-8BC6-A3DAAA3394F1} -> profile=public | protocol=6 | dir=in | action=allow | name=backupsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe | 
{94B00D51-AAFF-484A-A6EA-AC69F9376F8B} -> dir=in | action=allow | name=acer arcade live | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe | 
{951E6639-C9F5-4DCC-AF59-7FB313285A95} -> profile=public | protocol=17 | dir=in | action=allow | name=schedulersvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe | 
{95F52980-D4E6-49F2-94AA-45C5D7CA06E8} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{A3EE557F-F25E-48D4-816F-DCC98A31A546} -> dir=in | action=allow | name=acer homemedia trial creator | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe | 
{A8B1FA73-577E-4033-8674-6F780465106E} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe | 
{AB77AFF3-2463-4364-B83B-FC34CC1F67C8} -> profile=public | protocol=6 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{ADB4489C-DCFF-47CE-9F39-90954D6A188D} -> profile=public | protocol=6 | dir=in | action=allow | name=schedulersvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe | 
{B72C613F-D27D-4AA3-991A-6E3557C32616} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe | 
{CE833960-7A3E-4151-9054-B1A046F77D46} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe | 
{D30D125C-EA08-4FBD-B228-905844300D7B} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31324 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{D4288692-7C3D-4D23-BBF5-39FD6A28DE8E} -> profile=public | protocol=17 | dir=in | action=allow | name=agentsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe | 
{D42AC248-F7A0-4079-AD02-1F1FBC06A1C0} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{D7DAAEDA-4209-4442-808D-BFFEF5DBA7E9} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31323 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{DBE52BFA-A4AC-42EE-AE12-B22F5E22DE45} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe | 
{EAE9D013-EC6C-4D68-A944-321CEE09B288} -> profile=public | protocol=6 | dir=in | action=allow | name=agentsvc.exe | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe | 
{ECF3DA71-4F36-4203-9B7B-38F3830A41A4} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe | 
{F042D123-C7C6-4813-9034-DBCA5F2EA3EB} -> dir=in | action=allow | name=acer homemedia | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe | 
TCP Query User{099E7E4B-3B02-4CBC-B242-50FF3E3C0A17}C:\program files (x86)\secondlife\slvoice.exe -> profile=private | protocol=6 | dir=in | action=block | name=slvoice | app=c:\program files (x86)\secondlife\slvoice.exe | 
TCP Query User{F5E3D0FC-9D65-415B-A97D-DE0C74D2ED8D}C:\program files (x86)\limewire\limewire.exe -> profile=public | protocol=6 | dir=in | action=block | name=limewire | app=c:\program files (x86)\limewire\limewire.exe | 
UDP Query User{115A8721-0F7D-4847-8180-E3C92101C42B}C:\program files (x86)\limewire\limewire.exe -> profile=public | protocol=17 | dir=in | action=block | name=limewire | app=c:\program files (x86)\limewire\limewire.exe | 
UDP Query User{751B5A46-A40A-4103-B13D-7729C8F7CFB5}C:\program files (x86)\secondlife\slvoice.exe -> profile=private | protocol=17 | dir=in | action=block | name=slvoice | app=c:\program files (x86)\secondlife\slvoice.exe | 
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> C:\Windows\SysNative\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2009/04/11 01:34:39 | 00,079,872 | ---- | M] (Microsoft Corporation)
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command -> 
64bit-comfile [open] -> "%1" %* -> File not found
64bit-exefile [open] -> "%1" %* -> File not found
comfile [open] -> "%1" %* -> File not found
exefile [open] -> "%1" %* -> File not found
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 9/10/2009 3:00:22 AM Computer Name = Yolanda-PC | Source = VSS | ID = 13 -> Description = 
Application [ Error ] 9/10/2009 3:00:22 AM Computer Name = Yolanda-PC | Source = VSS | ID = 12292 -> Description = 
Application [ Error ] 9/10/2009 3:00:22 AM Computer Name = Yolanda-PC | Source = System Restore | ID = 8193 -> Description = 
Application [ Error ] 9/10/2009 3:12:31 AM Computer Name = Yolanda-PC | Source = WinMgmt | ID = 10 -> Description = 
Application [ Error ] 9/10/2009 7:14:50 PM Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621 -> Description = 
Application [ Error ] 9/11/2009 9:25:57 PM Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621 -> Description = 
Application [ Error ] 9/14/2009 2:41:36 PM Computer Name = Yolanda-PC | Source = Application Hang | ID = 1002 -> Description = The program IncMail.exe version 5.8.6.4130 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.  Process ID: 1bf8  Start Time: 01ca33cccb4e79ad  Termination Time: 33
Application [ Error ] 9/14/2009 10:03:13 PM Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621 -> Description = 
Application [ Error ] 9/15/2009 7:46:06 AM Computer Name = Yolanda-PC | Source = Winlogon | ID = 4005 -> Description = The Windows logon process has unexpectedly terminated.
Application [ Error ] 9/15/2009 7:49:04 AM Computer Name = Yolanda-PC | Source = WinMgmt | ID = 10 -> Description = 
Media Center [ Error ] 6/9/2009 6:27:00 PM Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0 -> Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
Media Center [ Error ] 7/25/2009 12:25:21 AM Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0 -> Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Media Center [ Error ] 7/28/2009 12:25:35 AM Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0 -> Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
Media Center [ Error ] 7/31/2009 12:25:41 AM Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0 -> Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed due to an abandoned mutex.'.
System [ Error ] 9/8/2009 5:26:17 PM Computer Name = Yolanda-PC | Source = DCOM | ID = 10000 -> Description = 
System [ Error ] 9/8/2009 6:06:00 PM Computer Name = Yolanda-PC | Source = EventLog | ID = 6008 -> Description = The previous system shutdown at 6:05:05 PM on 9/8/2009 was unexpected.
System [ Error ] 9/8/2009 6:06:01 PM Computer Name = Yolanda-PC | Source = HTTP | ID = 15016 -> Description = 
System [ Error ] 9/8/2009 6:19:28 PM Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098 -> Description = Failed to set monitor event rule.
System [ Error ] 9/8/2009 8:19:55 PM Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098 -> Description = Failed to set monitor event rule.
System [ Error ] 9/8/2009 9:15:05 PM Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098 -> Description = Failed to set monitor event rule.
System [ Error ] 9/9/2009 4:48:02 PM Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098 -> Description = Failed to set monitor event rule.
System [ Error ] 9/9/2009 8:40:20 PM Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098 -> Description = Failed to set monitor event rule.
System [ Error ] 9/10/2009 3:00:22 AM Computer Name = Yolanda-PC | Source = DCOM | ID = 10005 -> Description = 
System [ Error ] 9/10/2009 3:00:22 AM Computer Name = Yolanda-PC | Source = Service Control Manager | ID = 7000 -> Description = 
 
[Files/Folders - Created Within 30 Days]
NVIDIA -> C:\ProgramData\NVIDIA -> [2009/09/18 14:02:36 | 00,000,000 | ---D | M]
Roaming -> C:\Users\Yolanda\AppData\Roaming -> [2009/10/01 17:13:05 | 00,000,000 | ---D | M]
Local -> C:\Users\Yolanda\AppData\Local -> [2009/10/05 09:19:41 | 00,000,000 | ---D | M]
Google -> C:\Users\Yolanda\AppData\Local\Google -> [2009/09/22 14:28:19 | 00,000,000 | ---D | M]
Temp -> C:\Users\Yolanda\AppData\Local\Temp -> [2009/10/07 14:00:56 | 00,000,000 | ---D | M]
VirtualStore -> C:\Users\Yolanda\AppData\Local\VirtualStore -> [2009/10/07 13:38:44 | 00,000,000 | ---D | M]
System -> C:\Program Files (x86)\Common Files\System -> [2009/09/18 13:56:23 | 00,000,000 | ---D | M]
Program Files (x86) -> C:\Program Files (x86) -> [2009/10/07 10:25:10 | 00,000,000 | R--D | M]
Google -> C:\Program Files (x86)\Google -> [2009/09/26 20:05:17 | 00,000,000 | ---D | M]
Internet Explorer -> C:\Program Files (x86)\Internet Explorer -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Microsoft Silverlight -> C:\Program Files (x86)\Microsoft Silverlight -> [2009/09/10 03:11:44 | 00,000,000 | ---D | M]
Mozilla Firefox -> C:\Program Files (x86)\Mozilla Firefox -> [2009/09/30 20:49:52 | 00,000,000 | ---D | M]
Trend Micro -> C:\Program Files (x86)\Trend Micro -> [2009/10/07 10:25:10 | 00,000,000 | ---D | M]
Windows Calendar -> C:\Program Files (x86)\Windows Calendar -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Windows Mail -> C:\Program Files (x86)\Windows Mail -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Windows Media Player -> C:\Program Files (x86)\Windows Media Player -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Windows Photo Gallery -> C:\Program Files (x86)\Windows Photo Gallery -> [2009/09/18 13:56:23 | 00,000,000 | ---D | M]
Windows Sidebar -> C:\Program Files (x86)\Windows Sidebar -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Program Files -> C:\Program Files -> [2009/09/16 21:11:02 | 00,000,000 | R--D | M]
Google -> C:\Program Files\Google -> [2009/09/16 21:11:02 | 00,000,000 | ---D | M]
Internet Explorer -> C:\Program Files\Internet Explorer -> [2009/09/18 13:56:26 | 00,000,000 | ---D | M]
Movie Maker -> C:\Program Files\Movie Maker -> [2009/09/18 13:56:27 | 00,000,000 | ---D | M]
Windows Collaboration -> C:\Program Files\Windows Collaboration -> [2009/09/18 13:56:26 | 00,000,000 | ---D | M]
Windows Defender -> C:\Program Files\Windows Defender -> [2009/09/18 13:56:24 | 00,000,000 | ---D | M]
Windows Journal -> C:\Program Files\Windows Journal -> [2009/09/18 13:56:26 | 00,000,000 | ---D | M]
Windows Mail -> C:\Program Files\Windows Mail -> [2009/09/18 13:56:27 | 00,000,000 | ---D | M]
Windows Media Player -> C:\Program Files\Windows Media Player -> [2009/09/18 13:56:26 | 00,000,000 | ---D | M]
Windows Photo Gallery -> C:\Program Files\Windows Photo Gallery -> [2009/09/18 13:56:25 | 00,000,000 | ---D | M]
Windows Sidebar -> C:\Program Files\Windows Sidebar -> [2009/09/18 13:56:27 | 00,000,000 | ---D | M]
MpSigStub.exe -> C:\Windows\SysNative\MpSigStub.exe -> [2009/10/02 19:07:58 | 00,238,960 | ---- | C] (Microsoft Corporation)
vi-VN -> C:\Windows\SysWow64\vi-VN -> [2009/09/18 13:55:02 | 00,000,000 | ---D | C]
eu-ES -> C:\Windows\SysWow64\eu-ES -> [2009/09/18 13:55:02 | 00,000,000 | ---D | C]
eu-ES -> C:\Windows\SysNative\eu-ES -> [2009/09/18 13:55:02 | 00,000,000 | ---D | C]
ca-ES -> C:\Windows\SysWow64\ca-ES -> [2009/09/18 13:55:02 | 00,000,000 | ---D | C]
ca-ES -> C:\Windows\SysNative\ca-ES -> [2009/09/18 13:55:02 | 00,000,000 | ---D | C]
vi-VN -> C:\Windows\SysNative\vi-VN -> [2009/09/18 13:55:01 | 00,000,000 | ---D | C]
EventProviders -> C:\Windows\SysNative\EventProviders -> [2009/09/18 13:14:31 | 00,000,000 | ---D | C]
lsasrv.dll -> C:\Windows\SysNative\lsasrv.dll -> [2009/09/18 13:06:44 | 01,689,600 | ---- | C] (Microsoft Corporation)
kerberos.dll -> C:\Windows\SysNative\kerberos.dll -> [2009/09/18 13:06:43 | 00,656,896 | ---- | C] (Microsoft Corporation)
msv1_0.dll -> C:\Windows\SysNative\msv1_0.dll -> [2009/09/18 13:06:43 | 00,269,312 | ---- | C] (Microsoft Corporation)
kerberos.dll -> C:\Windows\SysWow64\kerberos.dll -> [2009/09/18 13:06:42 | 00,499,712 | ---- | C] (Microsoft Corporation)
wdigest.dll -> C:\Windows\SysNative\wdigest.dll -> [2009/09/18 13:06:42 | 00,205,312 | ---- | C] (Microsoft Corporation)
ksecdd.sys -> C:\Windows\SysNative\drivers\ksecdd.sys -> [2009/09/18 13:06:41 | 00,515,656 | ---- | C] (Microsoft Corporation)
schannel.dll -> C:\Windows\SysNative\schannel.dll -> [2009/09/18 13:06:41 | 00,338,432 | ---- | C] (Microsoft Corporation)
msv1_0.dll -> C:\Windows\SysWow64\msv1_0.dll -> [2009/09/18 13:06:41 | 00,218,624 | ---- | C] (Microsoft Corporation)
wdigest.dll -> C:\Windows\SysWow64\wdigest.dll -> [2009/09/18 13:06:41 | 00,175,104 | ---- | C] (Microsoft Corporation)
schannel.dll -> C:\Windows\SysWow64\schannel.dll -> [2009/09/18 13:06:40 | 00,270,848 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\SysNative\secur32.dll -> [2009/09/18 13:06:40 | 00,094,720 | ---- | C] (Microsoft Corporation)
secur32.dll -> C:\Windows\SysWow64\secur32.dll -> [2009/09/18 13:06:40 | 00,077,312 | ---- | C] (Microsoft Corporation)
lsass.exe -> C:\Windows\SysNative\lsass.exe -> [2009/09/18 13:06:39 | 00,011,264 | ---- | C] (Microsoft Corporation)
NlsLexicons0007.dll -> C:\Windows\SysWow64\NlsLexicons0007.dll -> [2009/09/17 04:41:11 | 12,240,896 | ---- | C] (Microsoft Corporation)
NlsLexicons0007.dll -> C:\Windows\SysNative\NlsLexicons0007.dll -> [2009/09/17 04:41:11 | 12,240,896 | ---- | C] (Microsoft Corporation)
SLsvc.exe -> C:\Windows\SysNative\SLsvc.exe -> [2009/09/17 04:41:07 | 02,582,016 | ---- | C] (Microsoft Corporation)
SLCExt.dll -> C:\Windows\SysNative\SLCExt.dll -> [2009/09/17 04:41:07 | 00,710,144 | ---- | C] (Microsoft Corporation)
FunctionDiscoveryFolder.dll -> C:\Windows\SysNative\FunctionDiscoveryFolder.dll -> [2009/09/17 04:41:06 | 02,146,304 | ---- | C] (Microsoft Corporation)
FunctionDiscoveryFolder.dll -> C:\Windows\SysWow64\FunctionDiscoveryFolder.dll -> [2009/09/17 04:41:06 | 02,134,528 | ---- | C] (Microsoft Corporation)
NlsLexicons0009.dll -> C:\Windows\SysWow64\NlsLexicons0009.dll -> [2009/09/17 04:41:05 | 02,644,480 | ---- | C] (Microsoft Corporation)
NlsLexicons0009.dll -> C:\Windows\SysNative\NlsLexicons0009.dll -> [2009/09/17 04:41:05 | 02,644,480 | ---- | C] (Microsoft Corporation)
msscntrs.dll -> C:\Windows\SysNative\msscntrs.dll -> [2009/09/17 04:41:03 | 00,073,728 | ---- | C] (Microsoft Corporation)
msshooks.dll -> C:\Windows\SysNative\msshooks.dll -> [2009/09/17 04:41:03 | 00,011,776 | ---- | C] (Microsoft Corporation)
ntoskrnl.exe -> C:\Windows\SysNative\ntoskrnl.exe -> [2009/09/17 04:41:02 | 04,699,608 | ---- | C] (Microsoft Corporation)
mssrch.dll -> C:\Windows\SysNative\mssrch.dll -> [2009/09/17 04:41:02 | 02,280,448 | ---- | C] (Microsoft Corporation)
SLCExt.dll -> C:\Windows\SysWow64\SLCExt.dll -> [2009/09/17 04:41:02 | 01,081,344 | ---- | C] (Microsoft Corporation)
msstrc.dll -> C:\Windows\SysNative\msstrc.dll -> [2009/09/17 04:41:02 | 00,078,336 | ---- | C] (Microsoft Corporation)
xmlfilter.dll -> C:\Windows\SysNative\xmlfilter.dll -> [2009/09/17 04:41:02 | 00,067,072 | ---- | C] (Microsoft Corporation)
kd1394.dll -> C:\Windows\SysNative\kd1394.dll -> [2009/09/17 04:41:02 | 00,019,928 | ---- | C] (Microsoft Corporation)
mssrch.dll -> C:\Windows\SysWow64\mssrch.dll -> [2009/09/17 04:41:00 | 01,480,704 | ---- | C] (Microsoft Corporation)
tquery.dll -> C:\Windows\SysNative\tquery.dll -> [2009/09/17 04:40:57 | 02,204,672 | ---- | C] (Microsoft Corporation)
wcnwiz2.dll -> C:\Windows\SysNative\wcnwiz2.dll -> [2009/09/17 04:40:57 | 01,085,440 | ---- | C] (Microsoft Corporation)
wcnwiz2.dll -> C:\Windows\SysWow64\wcnwiz2.dll -> [2009/09/17 04:40:57 | 00,968,192 | ---- | C] (Microsoft Corporation)
hdaudbus.sys -> C:\Windows\SysNative\drivers\hdaudbus.sys -> [2009/09/17 04:40:57 | 00,948,736 | ---- | C] (Microsoft Corporation)
WscEapPr.dll -> C:\Windows\SysNative\WscEapPr.dll -> [2009/09/17 04:40:57 | 00,397,312 | ---- | C] (Microsoft Corporation)
WscEapPr.dll -> C:\Windows\SysWow64\WscEapPr.dll -> [2009/09/17 04:40:57 | 00,291,328 | ---- | C] (Microsoft Corporation)
infocardcpl.cpl -> C:\Windows\SysNative\infocardcpl.cpl -> [2009/09/17 04:40:57 | 00,046,944 | ---- | C] (Microsoft Corporation)
icardagt.exe -> C:\Windows\SysNative\icardagt.exe -> [2009/09/17 04:40:56 | 01,381,720 | ---- | C] (Microsoft Corporation)
PresentationNative_v0300.dll -> C:\Windows\SysNative\PresentationNative_v0300.dll -> [2009/09/17 04:40:56 | 01,165,664 | ---- | C] (Microsoft Corporation)
imapi2fs.dll -> C:\Windows\SysNative\imapi2fs.dll -> [2009/09/17 04:40:56 | 01,146,880 | ---- | C] (Microsoft Corporation)
tquery.dll -> C:\Windows\SysWow64\tquery.dll -> [2009/09/17 04:40:55 | 01,576,960 | ---- | C] (Microsoft Corporation)
RMActivate_isv.exe -> C:\Windows\SysNative\RMActivate_isv.exe -> [2009/09/17 04:40:55 | 00,600,576 | ---- | C] (Microsoft Corporation)
RMActivate.exe -> C:\Windows\SysNative\RMActivate.exe -> [2009/09/17 04:40:55 | 00,599,552 | ---- | C] (Microsoft Corporation)
msi.dll -> C:\Windows\SysNative\msi.dll -> [2009/09/17 04:40:54 | 03,108,864 | ---- | C] (Microsoft Corporation)
ntfs.sys -> C:\Windows\SysNative\drivers\ntfs.sys -> [2009/09/17 04:40:53 | 01,515,496 | ---- | C] (Microsoft Corporation)
sysmain.dll -> C:\Windows\SysNative\sysmain.dll -> [2009/09/17 04:40:53 | 00,886,784 | ---- | C] (Microsoft Corporation)
PresentationNative_v0300.dll -> C:\Windows\SysWow64\PresentationNative_v0300.dll -> [2009/09/17 04:40:53 | 00,779,136 | ---- | C] (Microsoft Corporation)
shell32.dll -> C:\Windows\SysNative\shell32.dll -> [2009/09/17 04:40:52 | 12,897,792 | ---- | C] (Microsoft Corporation)
ntdll.dll -> C:\Windows\SysNative\ntdll.dll -> [2009/09/17 04:40:52 | 01,582,792 | ---- | C] (Microsoft Corporation)
scavenge.dll -> C:\Windows\SysNative\scavenge.dll -> [2009/09/17 04:40:51 | 00,946,688 | ---- | C] (Microsoft Corporation)
spsys.sys -> C:\Windows\SysNative\drivers\spsys.sys -> [2009/09/17 04:40:51 | 00,594,432 | ---- | C] (Microsoft Corporation)
secproc.dll -> C:\Windows\SysNative\secproc.dll -> [2009/09/17 04:40:51 | 00,539,136 | ---- | C] (Microsoft Corporation)
secproc_isv.dll -> C:\Windows\SysNative\secproc_isv.dll -> [2009/09/17 04:40:51 | 00,538,624 | ---- | C] (Microsoft Corporation)
RMActivate_isv.exe -> C:\Windows\SysWow64\RMActivate_isv.exe -> [2009/09/17 04:40:51 | 00,526,336 | ---- | C] (Microsoft Corporation)
RMActivate.exe -> C:\Windows\SysWow64\RMActivate.exe -> [2009/09/17 04:40:51 | 00,518,144 | ---- | C] (Microsoft Corporation)
msi.dll -> C:\Windows\SysWow64\msi.dll -> [2009/09/17 04:40:50 | 02,241,536 | ---- | C] (Microsoft Corporation)
msxml3.dll -> C:\Windows\SysNative\msxml3.dll -> [2009/09/17 04:40:48 | 01,804,288 | ---- | C] (Microsoft Corporation)
imapi2fs.dll -> C:\Windows\SysWow64\imapi2fs.dll -> [2009/09/17 04:40:48 | 00,677,376 | ---- | C] (Microsoft Corporation)
secproc_isv.dll -> C:\Windows\SysWow64\secproc_isv.dll -> [2009/09/17 04:40:48 | 00,476,672 | ---- | C] (Microsoft Corporation)
mmcndmgr.dll -> C:\Windows\SysNative\mmcndmgr.dll -> [2009/09/17 04:40:47 | 03,263,488 | ---- | C] (Microsoft Corporation)
infocardcpl.cpl -> C:\Windows\SysWow64\infocardcpl.cpl -> [2009/09/17 04:40:47 | 00,035,168 | ---- | C] (Microsoft Corporation)
icardagt.exe -> C:\Windows\SysWow64\icardagt.exe -> [2009/09/17 04:40:46 | 00,619,864 | ---- | C] (Microsoft Corporation)
AuxiliaryDisplayCpl.dll -> C:\Windows\SysNative\AuxiliaryDisplayCpl.dll -> [2009/09/17 04:40:45 | 01,418,752 | ---- | C] (Microsoft Corporation)
kernel32.dll -> C:\Windows\SysNative\kernel32.dll -> [2009/09/17 04:40:45 | 01,217,536 | ---- | C] (Microsoft Corporation)
p2psvc.dll -> C:\Windows\SysNative\p2psvc.dll -> [2009/09/17 04:40:45 | 00,836,608 | ---- | C] (Microsoft Corporation)
spinstall.exe -> C:\Windows\SysNative\spinstall.exe -> [2009/09/17 04:40:45 | 00,435,712 | ---- | C] (Microsoft Corporation)
spreview.exe -> C:\Windows\SysNative\spreview.exe -> [2009/09/17 04:40:45 | 00,147,456 | ---- | C] (Microsoft Corporation)
mmc.exe -> C:\Windows\SysNative\mmc.exe -> [2009/09/17 04:40:44 | 02,715,136 | ---- | C] (Microsoft Corporation)
esent.dll -> C:\Windows\SysNative\esent.dll -> [2009/09/17 04:40:44 | 02,506,752 | ---- | C] (Microsoft Corporation)
drmv2clt.dll -> C:\Windows\SysNative\drmv2clt.dll -> [2009/09/17 04:40:44 | 01,185,280 | ---- | C] (Microsoft Corporation)
AuxiliaryDisplayCpl.dll -> C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll -> [2009/09/17 04:40:43 | 01,216,000 | ---- | C] (Microsoft Corporation)
SearchIndexer.exe -> C:\Windows\SysNative\SearchIndexer.exe -> [2009/09/17 04:40:43 | 00,597,504 | ---- | C] (Microsoft Corporation)
spwizui.dll -> C:\Windows\SysNative\spwizui.dll -> [2009/09/17 04:40:43 | 00,173,568 | ---- | C] (Microsoft Corporation)
spwizui.dll -> C:\Windows\SysWow64\spwizui.dll -> [2009/09/17 04:40:43 | 00,164,352 | ---- | C] (Microsoft Corporation)
ole32.dll -> C:\Windows\SysNative\ole32.dll -> [2009/09/17 04:40:40 | 01,915,392 | ---- | C] (Microsoft Corporation)
drmv2clt.dll -> C:\Windows\SysWow64\drmv2clt.dll -> [2009/09/17 04:40:40 | 00,978,432 | ---- | C] (Microsoft Corporation)
spinstall.exe -> C:\Windows\SysWow64\spinstall.exe -> [2009/09/17 04:40:40 | 00,289,792 | ---- | C] (Microsoft Corporation)
spreview.exe -> C:\Windows\SysWow64\spreview.exe -> [2009/09/17 04:40:40 | 00,112,640 | ---- | C] (Microsoft Corporation)
dfsr.exe -> C:\Windows\SysNative\dfsr.exe -> [2009/09/17 04:40:39 | 03,433,472 | ---- | C] (Microsoft Corporation)
sdohlp.dll -> C:\Windows\SysNative\sdohlp.dll -> [2009/09/17 04:40:39 | 00,499,200 | ---- | C] (Microsoft Corporation)
shell32.dll -> C:\Windows\SysWow64\shell32.dll -> [2009/09/17 04:40:38 | 11,584,000 | ---- | C] (Microsoft Corporation)
mssvp.dll -> C:\Windows\SysNative\mssvp.dll -> [2009/09/17 04:40:38 | 00,796,672 | ---- | C] (Microsoft Corporation)
MSMPEG2VDEC.DLL -> C:\Windows\SysNative\MSMPEG2VDEC.DLL -> [2009/09/17 04:40:38 | 00,778,752 | ---- | C] (Microsoft Corporation)
secproc.dll -> C:\Windows\SysWow64\secproc.dll -> [2009/09/17 04:40:38 | 00,472,064 | ---- | C] (Microsoft Corporation)
mssvp.dll -> C:\Windows\SysWow64\mssvp.dll -> [2009/09/17 04:40:37 | 00,670,720 | ---- | C] (Microsoft Corporation)
p2psvc.dll -> C:\Windows\SysWow64\p2psvc.dll -> [2009/09/17 04:40:37 | 00,644,608 | ---- | C] (Microsoft Corporation)
mssph.dll -> C:\Windows\SysNative\mssph.dll -> [2009/09/17 04:40:37 | 00,501,248 | ---- | C] (Microsoft Corporation)
SearchIndexer.exe -> C:\Windows\SysWow64\SearchIndexer.exe -> [2009/09/17 04:40:37 | 00,441,344 | ---- | C] (Microsoft Corporation)
mssphtb.dll -> C:\Windows\SysNative\mssphtb.dll -> [2009/09/17 04:40:37 | 00,312,832 | ---- | C] (Microsoft Corporation)
mcupdate_GenuineIntel.dll -> C:\Windows\SysNative\mcupdate_GenuineIntel.dll -> [2009/09/17 04:40:37 | 00,223,720 | ---- | C] (Microsoft Corporation)
EhStorPwdMgr.dll -> C:\Windows\SysNative\EhStorPwdMgr.dll -> [2009/09/17 04:40:37 | 00,042,496 | ---- | C] (Microsoft Corporation)
EhStorPwdMgr.dll -> C:\Windows\SysWow64\EhStorPwdMgr.dll -> [2009/09/17 04:40:37 | 00,037,376 | ---- | C] (Microsoft Corporation)
RMActivate_ssp_isv.exe -> C:\Windows\SysNative\RMActivate_ssp_isv.exe -> [2009/09/17 04:40:36 | 00,413,696 | ---- | C] (Microsoft Corporation)
kernel32.dll -> C:\Windows\SysWow64\kernel32.dll -> [2009/09/17 04:40:35 | 00,858,112 | ---- | C] (Microsoft Corporation)
MSMPEG2VDEC.DLL -> C:\Windows\SysWow64\MSMPEG2VDEC.DLL -> [2009/09/17 04:40:35 | 00,613,888 | ---- | C] (Microsoft Corporation)
imapi2.dll -> C:\Windows\SysNative\imapi2.dll -> [2009/09/17 04:40:35 | 00,506,880 | ---- | C] (Microsoft Corporation)
srv.sys -> C:\Windows\SysNative\drivers\srv.sys -> [2009/09/17 04:40:35 | 00,440,832 | ---- | C] (Microsoft Corporation)
RMActivate_ssp.exe -> C:\Windows\SysNative\RMActivate_ssp.exe -> [2009/09/17 04:40:35 | 00,409,600 | ---- | C] (Microsoft Corporation)
mscoree.dll -> C:\Windows\SysWow64\mscoree.dll -> [2009/09/17 04:40:35 | 00,278,848 | ---- | C] (Microsoft Corporation)
Query.dll -> C:\Windows\SysNative\Query.dll -> [2009/09/17 04:40:34 | 02,028,032 | ---- | C] (Microsoft Corporation)
ntdll.dll -> C:\Windows\SysWow64\ntdll.dll -> [2009/09/17 04:40:34 | 01,165,088 | ---- | C] (Microsoft Corporation)
imapi2.dll -> C:\Windows\SysWow64\imapi2.dll -> [2009/09/17 04:40:34 | 00,378,368 | ---- | C] (Microsoft Corporation)
mssph.dll -> C:\Windows\SysWow64\mssph.dll -> [2009/09/17 04:40:34 | 00,351,744 | ---- | C] (Microsoft Corporation)
mssphtb.dll -> C:\Windows\SysWow64\mssphtb.dll -> [2009/09/17 04:40:34 | 00,203,264 | ---- | C] (Microsoft Corporation)
korwbrkr.dll -> C:\Windows\SysNative\korwbrkr.dll -> [2009/09/17 04:40:34 | 00,180,736 | ---- | C] (Microsoft Corporation)
IMJP10K.DLL -> C:\Windows\SysNative\IMJP10K.DLL -> [2009/09/17 04:40:33 | 00,922,624 | ---- | C] (Microsoft Corporation)
mscoree.dll -> C:\Windows\SysNative\mscoree.dll -> [2009/09/17 04:40:33 | 00,403,280 | ---- | C] (Microsoft Corporation)
uDWM.dll -> C:\Windows\SysNative\uDWM.dll -> [2009/09/17 04:40:33 | 00,367,104 | ---- | C] (Microsoft Corporation)
WinSAT.exe -> C:\Windows\SysNative\WinSAT.exe -> [2009/09/17 04:40:32 | 03,894,272 | ---- | C] (Microsoft Corporation)
esent.dll -> C:\Windows\SysWow64\esent.dll -> [2009/09/17 04:40:32 | 01,459,200 | ---- | C] (Microsoft Corporation)
DevicePairing.dll -> C:\Windows\SysNative\DevicePairing.dll -> [2009/09/17 04:40:32 | 00,483,328 | ---- | C] (Microsoft Corporation)
DevicePairing.dll -> C:\Windows\SysWow64\DevicePairing.dll -> [2009/09/17 04:40:32 | 00,478,208 | ---- | C] (Microsoft Corporation)
sdohlp.dll -> C:\Windows\SysWow64\sdohlp.dll -> [2009/09/17 04:40:32 | 00,324,608 | ---- | C] (Microsoft Corporation)
IMJP10K.DLL -> C:\Windows\SysWow64\IMJP10K.DLL -> [2009/09/17 04:40:31 | 00,729,600 | ---- | C] (Microsoft Corporation)
msshsq.dll -> C:\Windows\SysNative\msshsq.dll -> [2009/09/17 04:40:31 | 00,316,928 | ---- | C] (Microsoft Corporation)
http.sys -> C:\Windows\SysNative\drivers\http.sys -> [2009/09/17 04:40:30 | 00,606,720 | ---- | C] (Microsoft Corporation)
RMActivate_ssp.exe -> C:\Windows\SysWow64\RMActivate_ssp.exe -> [2009/09/17 04:40:30 | 00,347,136 | ---- | C] (Microsoft Corporation)
sperror.dll -> C:\Windows\SysNative\sperror.dll -> [2009/09/17 04:40:30 | 00,238,592 | ---- | C] (Microsoft Corporation)
sperror.dll -> C:\Windows\SysWow64\sperror.dll -> [2009/09/17 04:40:30 | 00,190,464 | ---- | C] (Microsoft Corporation)
korwbrkr.dll -> C:\Windows\SysWow64\korwbrkr.dll -> [2009/09/17 04:40:30 | 00,143,872 | ---- | C] (Microsoft Corporation)
WindowsAnytimeUpgradeCPL.dll -> C:\Windows\SysNative\WindowsAnytimeUpgradeCPL.dll -> [2009/09/17 04:40:29 | 01,673,216 | ---- | C] (Microsoft Corporation)
IMJP10.IME -> C:\Windows\SysNative\IMJP10.IME -> [2009/09/17 04:40:29 | 01,019,904 | ---- | C] (Microsoft Corporation)
P2PGraph.dll -> C:\Windows\SysNative\P2PGraph.dll -> [2009/09/17 04:40:29 | 00,401,920 | ---- | C] (Microsoft Corporation)
SLC.dll -> C:\Windows\SysWow64\SLC.dll -> [2009/09/17 04:40:29 | 00,228,352 | ---- | C] (Microsoft Corporation)
PresentationHostProxy.dll -> C:\Windows\SysWow64\PresentationHostProxy.dll -> [2009/09/17 04:40:29 | 00,041,344 | ---- | C] (Microsoft Corporation)
crypt32.dll -> C:\Windows\SysNative\crypt32.dll -> [2009/09/17 04:40:28 | 01,259,520 | ---- | C] (Microsoft Corporation)
RMActivate_ssp_isv.exe -> C:\Windows\SysWow64\RMActivate_ssp_isv.exe -> [2009/09/17 04:40:28 | 00,346,624 | ---- | C] (Microsoft Corporation)
msshsq.dll -> C:\Windows\SysWow64\msshsq.dll -> [2009/09/17 04:40:28 | 00,231,424 | ---- | C] (Microsoft Corporation)
EhStorAPI.dll -> C:\Windows\SysNative\EhStorAPI.dll -> [2009/09/17 04:40:28 | 00,131,072 | ---- | C] (Microsoft Corporation)
EhStorAPI.dll -> C:\Windows\SysWow64\EhStorAPI.dll -> [2009/09/17 04:40:28 | 00,120,320 | ---- | C] (Microsoft Corporation)
setupapi.dll -> C:\Windows\SysNative\setupapi.dll -> [2009/09/17 04:40:27 | 01,925,120 | ---- | C] (Microsoft Corporation)
msjet40.dll -> C:\Windows\SysWow64\msjet40.dll -> [2009/09/17 04:40:27 | 01,589,248 | ---- | C] (Microsoft Corporation)
wevtsvc.dll -> C:\Windows\SysNative\wevtsvc.dll -> [2009/09/17 04:40:27 | 01,491,968 | ---- | C] (Microsoft Corporation)
msxml6.dll -> C:\Windows\SysWow64\msxml6.dll -> [2009/09/17 04:40:27 | 01,336,320 | ---- | C] (Microsoft Corporation)
IasMigPlugin.dll -> C:\Windows\SysNative\IasMigPlugin.dll -> [2009/09/17 04:40:27 | 00,581,632 | ---- | C] (Microsoft)
Storport.sys -> C:\Windows\SysNative\drivers\Storport.sys -> [2009/09/17 04:40:27 | 00,164,328 | ---- | C] (Microsoft Corporation)
PresentationHostProxy.dll -> C:\Windows\SysNative\PresentationHostProxy.dll -> [2009/09/17 04:40:27 | 00,049,496 | ---- | C] (Microsoft Corporation)
Query.dll -> C:\Windows\SysWow64\Query.dll -> [2009/09/17 04:40:26 | 01,381,376 | ---- | C] (Microsoft Corporation)
printfilterpipelinesvc.exe -> C:\Windows\SysNative\printfilterpipelinesvc.exe -> [2009/09/17 04:40:26 | 01,030,144 | ---- | C] (Microsoft Corporation)
ndis.sys -> C:\Windows\SysNative\drivers\ndis.sys -> [2009/09/17 04:40:26 | 00,738,264 | ---- | C] (Microsoft Corporation)
EncDec.dll -> C:\Windows\SysNative\EncDec.dll -> [2009/09/17 04:40:26 | 00,558,592 | ---- | C] (Microsoft Corporation)
SearchProtocolHost.exe -> C:\Windows\SysNative\SearchProtocolHost.exe -> [2009/09/17 04:40:26 | 00,258,560 | ---- | C] (Microsoft Corporation)
SearchFilterHost.exe -> C:\Windows\SysNative\SearchFilterHost.exe -> [2009/09/17 04:40:26 | 00,111,616 | ---- | C] (Microsoft Corporation)
compcln.exe -> C:\Windows\SysNative\compcln.exe -> [2009/09/17 04:40:26 | 00,056,320 | ---- | C] (Microsoft Corporation)
qmgr.dll -> C:\Windows\SysNative\qmgr.dll -> [2009/09/17 04:40:25 | 01,081,856 | ---- | C] (Microsoft Corporation)
winload.efi -> C:\Windows\SysNative\winload.efi -> [2009/09/17 04:40:25 | 01,078,232 | ---- | C] (Microsoft Corporation)
IMJP10.IME -> C:\Windows\SysWow64\IMJP10.IME -> [2009/09/17 04:40:25 | 00,883,712 | ---- | C] (Microsoft Corporation)
user32.dll -> C:\Windows\SysWow64\user32.dll -> [2009/09/17 04:40:25 | 00,648,704 | ---- | C] (Microsoft Corporation)
srchadmin.dll -> C:\Windows\SysNative\srchadmin.dll -> [2009/09/17 04:40:25 | 00,347,648 | ---- | C] (Microsoft Corporation)
infocardapi.dll -> C:\Windows\SysNative\infocardapi.dll -> [2009/09/17 04:40:25 | 00,171,360 | ---- | C] (Microsoft Corporation)
EhStorShell.dll -> C:\Windows\SysNative\EhStorShell.dll -> [2009/09/17 04:40:25 | 00,123,904 | ---- | C] (Microsoft Corporation)
EhStorShell.dll -> C:\Windows\SysWow64\EhStorShell.dll -> [2009/09/17 04:40:25 | 00,114,176 | ---- | C] (Microsoft Corporation)
fdBth.dll -> C:\Windows\SysNative\fdBth.dll -> [2009/09/17 04:40:25 | 00,112,640 | ---- | C] (Microsoft Corporation)
diagperf.dll -> C:\Windows\SysNative\diagperf.dll -> [2009/09/17 04:40:24 | 01,584,128 | ---- | C] (Microsoft Corporation)
vssapi.dll -> C:\Windows\SysNative\vssapi.dll -> [2009/09/17 04:40:24 | 01,495,040 | ---- | C] (Microsoft Corporation)
advapi32.dll -> C:\Windows\SysNative\advapi32.dll -> [2009/09/17 04:40:24 | 01,065,472 | ---- | C] (Microsoft Corporation)
winload.exe -> C:\Windows\SysNative\winload.exe -> [2009/09/17 04:40:24 | 01,064,920 | ---- | C] (Microsoft Corporation)
rpcss.dll -> C:\Windows\SysNative\rpcss.dll -> [2009/09/17 04:40:24 | 00,719,872 | ---- | C] (Microsoft Corporation)
IasMigReader.exe -> C:\Windows\SysWow64\IasMigReader.exe -> [2009/09/17 04:40:24 | 00,463,872 | ---- | C] (Microsoft Corporation)
msexch40.dll -> C:\Windows\SysWow64\msexch40.dll -> [2009/09/17 04:40:24 | 00,409,600 | ---- | C] (Microsoft Corporation)
P2PGraph.dll -> C:\Windows\SysWow64\P2PGraph.dll -> [2009/09/17 04:40:24 | 00,327,168 | ---- | C] (Microsoft Corporation)
explorer.exe -> C:\Windows\explorer.exe -> [2009/09/17 04:40:23 | 03,079,168 | ---- | C] (Microsoft Corporation)
ole32.dll -> C:\Windows\SysWow64\ole32.dll -> [2009/09/17 04:40:23 | 01,316,864 | ---- | C] (Microsoft Corporation)
msxml6.dll -> C:\Windows\SysNative\msxml6.dll -> [2009/09/17 04:40:22 | 01,733,120 | ---- | C] (Microsoft Corporation)
CertEnroll.dll -> C:\Windows\SysNative\CertEnroll.dll -> [2009/09/17 04:40:22 | 01,658,368 | ---- | C] (Microsoft Corporation)
VSSVC.exe -> C:\Windows\SysNative\VSSVC.exe -> [2009/09/17 04:40:22 | 01,433,600 | ---- | C] (Microsoft Corporation)
msxml3.dll -> C:\Windows\SysWow64\msxml3.dll -> [2009/09/17 04:40:22 | 01,183,232 | ---- | C] (Microsoft Corporation)
mblctr.exe -> C:\Windows\SysNative\mblctr.exe -> [2009/09/17 04:40:22 | 00,967,168 | ---- | C] (Microsoft Corporation)
EncDec.dll -> C:\Windows\SysWow64\EncDec.dll -> [2009/09/17 04:40:22 | 00,428,544 | ---- | C] (Microsoft Corporation)
srchadmin.dll -> C:\Windows\SysWow64\srchadmin.dll -> [2009/09/17 04:40:22 | 00,301,568 | ---- | C] (Microsoft Corporation)
psisrndr.ax -> C:\Windows\SysWow64\psisrndr.ax -> [2009/09/17 04:40:22 | 00,217,088 | ---- | C] (Microsoft Corporation)
mmc.exe -> C:\Windows\SysWow64\mmc.exe -> [2009/09/17 04:40:21 | 01,792,512 | ---- | C] (Microsoft Corporation)
comsvcs.dll -> C:\Windows\SysNative\comsvcs.dll -> [2009/09/17 04:40:21 | 01,686,528 | ---- | C] (Microsoft Corporation)
mfc42u.dll -> C:\Windows\SysNative\mfc42u.dll -> [2009/09/17 04:40:21 | 01,357,824 | ---- | C] (Microsoft Corporation)
gdi32.dll -> C:\Windows\SysWow64\gdi32.dll -> [2009/09/17 04:40:21 | 00,303,616 | ---- | C] (Microsoft Corporation)
spoolss.dll -> C:\Windows\SysNative\spoolss.dll -> [2009/09/17 04:40:21 | 00,238,080 | ---- | C] (Microsoft Corporation)
DevicePairingWizard.exe -> C:\Windows\SysNative\DevicePairingWizard.exe -> [2009/09/17 04:40:21 | 00,069,120 | ---- | C] (Microsoft Corporation)
DevicePairingWizard.exe -> C:\Windows\SysWow64\DevicePairingWizard.exe -> [2009/09/17 04:40:21 | 00,065,536 | ---- | C] (Microsoft Corporation)
d3d9.dll -> C:\Windows\SysNative\d3d9.dll -> [2009/09/17 04:40:20 | 01,930,240 | ---- | C] (Microsoft Corporation)
browseui.dll -> C:\Windows\SysNative\browseui.dll -> [2009/09/17 04:40:20 | 01,650,688 | ---- | C] (Microsoft Corporation)
Magnify.exe -> C:\Windows\SysWow64\Magnify.exe -> [2009/09/17 04:40:20 | 00,710,144 | ---- | C] (Microsoft Corporation)
riched20.dll -> C:\Windows\SysWow64\riched20.dll -> [2009/09/17 04:40:20 | 00,466,944 | ---- | C] (Microsoft Corporation)
IasMigPlugin.dll -> C:\Windows\SysWow64\IasMigPlugin.dll -> [2009/09/17 04:40:20 | 00,454,144 | ---- | C] (Microsoft)
afd.sys -> C:\Windows\SysNative\drivers\afd.sys -> [2009/09/17 04:40:20 | 00,406,016 | ---- | C] (Microsoft Corporation)
PresentationCFFRasterizerNative_v0300.dll -> C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll -> [2009/09/17 04:40:20 | 00,123,256 | ---- | C] (Microsoft Corporation)
mfc42.dll -> C:\Windows\SysNative\mfc42.dll -> [2009/09/17 04:40:19 | 01,395,712 | ---- | C] (Microsoft Corporation)
WsmSvc.dll -> C:\Windows\SysNative\WsmSvc.dll -> [2009/09/17 04:40:19 | 01,092,096 | ---- | C] (Microsoft Corporation)
fdBth.dll -> C:\Windows\SysWow64\fdBth.dll -> [2009/09/17 04:40:19 | 00,088,064 | ---- | C] (Microsoft Corporation)
milcore.dll -> C:\Windows\SysWow64\milcore.dll -> [2009/09/17 04:40:18 | 02,012,160 | ---- | C] (Microsoft Corporation)
CertEnroll.dll -> C:\Windows\SysWow64\CertEnroll.dll -> [2009/09/17 04:40:18 | 01,112,064 | ---- | C] (Microsoft Corporation)
RacEngn.dll -> C:\Windows\SysWow64\RacEngn.dll -> [2009/09/17 04:40:18 | 00,880,640 | ---- | C] (Microsoft Corporation)
WMPhoto.dll -> C:\Windows\SysNative\WMPhoto.dll -> [2009/09/17 04:40:18 | 00,379,392 | ---- | C] (Microsoft Corporation)
netio.sys -> C:\Windows\SysNative\drivers\netio.sys -> [2009/09/17 04:40:18 | 00,347,112 | ---- | C] (Microsoft Corporation)
bcrypt.dll -> C:\Windows\SysWow64\bcrypt.dll -> [2009/09/17 04:40:18 | 00,275,968 | ---- | C] (Microsoft Corporation)
SearchProtocolHost.exe -> C:\Windows\SysWow64\SearchProtocolHost.exe -> [2009/09/17 04:40:18 | 00,185,344 | ---- | C] (Microsoft Corporation)
SearchFilterHost.exe -> C:\Windows\SysWow64\SearchFilterHost.exe -> [2009/09/17 04:40:18 | 00,087,552 | ---- | C] (Microsoft Corporation)
Magnify.exe -> C:\Windows\SysNative\Magnify.exe -> [2009/09/17 04:40:17 | 00,859,648 | ---- | C] (Microsoft Corporation)
NaturalLanguage6.dll -> C:\Windows\SysWow64\NaturalLanguage6.dll -> [2009/09/17 04:40:17 | 00,805,376 | ---- | C] (Microsoft Corporation)
dpapimig.exe -> C:\Windows\SysNative\dpapimig.exe -> [2009/09/17 04:40:17 | 00,553,472 | ---- | C] (Microsoft Corporation)
iasrecst.dll -> C:\Windows\SysNative\iasrecst.dll -> [2009/09/17 04:40:17 | 00,192,000 | ---- | C] (Microsoft Corporation)
spoolss.dll -> C:\Windows\SysWow64\spoolss.dll -> [2009/09/17 04:40:17 | 00,160,768 | ---- | C] (Microsoft Corporation)
dbgeng.dll -> C:\Windows\SysNative\dbgeng.dll -> [2009/09/17 04:40:16 | 02,484,224 | ---- | C] (Microsoft Corporation)
apds.dll -> C:\Windows\SysNative\apds.dll -> [2009/09/17 04:40:16 | 02,112,000 | ---- | C] (Microsoft Corporation)
eudcedit.exe -> C:\Windows\SysNative\eudcedit.exe -> [2009/09/17 04:40:16 | 00,280,064 | ---- | C] (Microsoft Corporation)
gpedit.dll -> C:\Windows\SysNative\gpedit.dll -> [2009/09/17 04:40:15 | 01,013,248 | ---- | C] (Microsoft Corporation)
schedsvc.dll -> C:\Windows\SysNative\schedsvc.dll -> [2009/09/17 04:40:15 | 00,843,776 | ---- | C] (Microsoft Corporation)
vbscript.dll -> C:\Windows\SysNative\vbscript.dll -> [2009/09/17 04:40:15 | 00,602,624 | ---- | C] (Microsoft Corporation)
audiosrv.dll -> C:\Windows\SysNative\audiosrv.dll -> [2009/09/17 04:40:15 | 00,446,464 | ---- | C] (Microsoft Corporation)
es.dll -> C:\Windows\SysNative\es.dll -> [2009/09/17 04:40:15 | 00,361,984 | ---- | C] (Microsoft Corporation)
msjtes40.dll -> C:\Windows\SysWow64\msjtes40.dll -> [2009/09/17 04:40:15 | 00,290,816 | ---- | C] (Microsoft Corporation)
msctf.dll -> C:\Windows\SysNative\msctf.dll -> [2009/09/17 04:40:14 | 01,040,896 | ---- | C] (Microsoft Corporation)
gpedit.dll -> C:\Windows\SysWow64\gpedit.dll -> [2009/09/17 04:40:14 | 00,950,784 | ---- | C] (Microsoft Corporation)
comuid.dll -> C:\Windows\SysNative\comuid.dll -> [2009/09/17 04:40:14 | 00,918,528 | ---- | C] (Microsoft Corporation)
user32.dll -> C:\Windows\SysNative\user32.dll -> [2009/09/17 04:40:14 | 00,820,224 | ---- | C] (Microsoft Corporation)
evr.dll -> C:\Windows\SysNative\evr.dll -> [2009/09/17 04:40:14 | 00,647,680 | ---- | C] (Microsoft Corporation)
msdrm.dll -> C:\Windows\SysNative\msdrm.dll -> [2009/09/17 04:40:14 | 00,460,288 | ---- | C] (Microsoft Corporation)
msvcp60.dll -> C:\Windows\SysWow64\msvcp60.dll -> [2009/09/17 04:40:14 | 00,406,528 | ---- | C] (Microsoft Corporation)
infocardapi.dll -> C:\Windows\SysWow64\infocardapi.dll -> [2009/09/17 04:40:14 | 00,099,680 | ---- | C] (Microsoft Corporation)
slwmi.dll -> C:\Windows\SysNative\slwmi.dll -> [2009/09/17 04:40:14 | 00,088,064 | ---- | C] (Microsoft Corporation)
Storprop.dll -> C:\Windows\SysWow64\Storprop.dll -> [2009/09/17 04:40:14 | 00,055,808 | ---- | C] (Microsoft Corporation)
RacEngn.dll -> C:\Windows\SysNative\RacEngn.dll -> [2009/09/17 04:40:13 | 01,244,672 | ---- | C] (Microsoft Corporation)
oleaut32.dll -> C:\Windows\SysNative\oleaut32.dll -> [2009/09/17 04:40:13 | 00,847,360 | ---- | C] (Microsoft Corporation)
bthprops.cpl -> C:\Windows\SysNative\bthprops.cpl -> [2009/09/17 04:40:13 | 00,668,160 | ---- | C] (Microsoft Corporation)
ipsmsnap.dll -> C:\Windows\SysNative\ipsmsnap.dll -> [2009/09/17 04:40:13 | 00,620,544 | ---- | C] (Microsoft Corporation)
photowiz.dll -> C:\Windows\SysNative\photowiz.dll -> [2009/09/17 04:40:13 | 00,402,944 | ---- | C] (Microsoft Corporation)
fltMgr.sys -> C:\Windows\SysNative\drivers\fltMgr.sys -> [2009/09/17 04:40:12 | 00,275,432 | ---- | C] (Microsoft Corporation)
es.dll -> C:\Windows\SysWow64\es.dll -> [2009/09/17 04:40:12 | 00,268,800 | ---- | C] (Microsoft Corporation)
nlhtml.dll -> C:\Windows\SysNative\nlhtml.dll -> [2009/09/17 04:40:12 | 00,181,248 | ---- | C] (Microsoft Corporation)
advapi32.dll -> C:\Windows\SysWow64\advapi32.dll -> [2009/09/17 04:40:10 | 00,800,768 | ---- | C] (Microsoft Corporation)
msihnd.dll -> C:\Windows\SysNative\msihnd.dll -> [2009/09/17 04:40:10 | 00,503,296 | ---- | C] (Microsoft Corporation)
shlwapi.dll -> C:\Windows\SysNative\shlwapi.dll -> [2009/09/17 04:40:10 | 00,455,680 | ---- | C] (Microsoft Corporation)
wevtapi.dll -> C:\Windows\SysNative\wevtapi.dll -> [2009/09/17 04:40:10 | 00,394,240 | ---- | C] (Microsoft Corporation)
mstext40.dll -> C:\Windows\SysWow64\mstext40.dll -> [2009/09/17 04:40:10 | 00,282,624 | ---- | C] (Microsoft Corporation)
PresentationSettings.exe -> C:\Windows\SysNative\PresentationSettings.exe -> [2009/09/17 04:40:10 | 00,173,568 | ---- | C] (Microsoft Corporation)
SLC.dll -> C:\Windows\SysNative\SLC.dll -> [2009/09/17 04:40:10 | 00,151,552 | ---- | C] (Microsoft Corporation)
AuxiliaryDisplayServices.dll -> C:\Windows\SysNative\AuxiliaryDisplayServices.dll -> [2009/09/17 04:40:10 | 00,126,464 | ---- | C] (Microsoft Corporation)
quartz.dll -> C:\Windows\SysNative\quartz.dll -> [2009/09/17 04:40:09 | 01,570,304 | ---- | C] (Microsoft Corporation)
comsvcs.dll -> C:\Windows\SysWow64\comsvcs.dll -> [2009/09/17 04:40:09 | 01,209,856 | ---- | C] (Microsoft Corporation)
certcli.dll -> C:\Windows\SysNative\certcli.dll -> [2009/09/17 04:40:09 | 00,447,488 | ---- | C] (Microsoft Corporation)
msexcl40.dll -> C:\Windows\SysWow64\msexcl40.dll -> [2009/09/17 04:40:09 | 00,339,968 | ---- | C] (Microsoft Corporation)
WMPhoto.dll -> C:\Windows\SysWow64\WMPhoto.dll -> [2009/09/17 04:40:09 | 00,321,536 | ---- | C] (Microsoft Corporation)
psisrndr.ax -> C:\Windows\SysNative\psisrndr.ax -> [2009/09/17 04:40:09 | 00,289,792 | ---- | C] (Microsoft Corporation)
WebClnt.dll -> C:\Windows\SysWow64\WebClnt.dll -> [2009/09/17 04:40:09 | 00,199,680 | ---- | C] (Microsoft Corporation)
AuxiliaryDisplayDriverLib.dll -> C:\Windows\SysNative\AuxiliaryDisplayDriverLib.dll -> [2009/09/17 04:40:09 | 00,131,072 | ---- | C] (Microsoft Corporation)
slwmi.dll -> C:\Windows\SysWow64\slwmi.dll -> [2009/09/17 04:40:09 | 00,067,584 | ---- | C] (Microsoft Corporation)
wcnwiz.dll -> C:\Windows\SysNative\wcnwiz.dll -> [2009/09/17 04:40:08 | 01,681,920 | ---- | C] (Microsoft Corporation)
vssapi.dll -> C:\Windows\SysWow64\vssapi.dll -> [2009/09/17 04:40:08 | 01,077,248 | ---- | C] (Microsoft Corporation)
msvcrt.dll -> C:\Windows\SysNative\msvcrt.dll -> [2009/09/17 04:40:08 | 00,621,056 | ---- | C] (Microsoft Corporation)
devmgr.dll -> C:\Windows\SysNative\devmgr.dll -> [2009/09/17 04:40:08 | 00,498,688 | ---- | C] (Microsoft Corporation)
msfeeds.dll -> C:\Windows\SysWow64\msfeeds.dll -> [2009/09/17 04:40:08 | 00,461,824 | ---- | C] (Microsoft Corporation)
msxbde40.dll -> C:\Windows\SysWow64\msxbde40.dll -> [2009/09/17 04:40:08 | 00,454,656 | ---- | C] (Microsoft Corporation)
WcnNetsh.dll -> C:\Windows\SysNative\WcnNetsh.dll -> [2009/09/17 04:40:08 | 00,238,592 | ---- | C] (Microsoft Corporation)
srvnet.sys -> C:\Windows\SysNative\drivers\srvnet.sys -> [2009/09/17 04:40:08 | 00,143,360 | ---- | C] (Microsoft Corporation)
DevicePairingProxy.dll -> C:\Windows\SysNative\DevicePairingProxy.dll -> [2009/09/17 04:40:08 | 00,057,856 | ---- | C] (Microsoft Corporation)
DevicePairingProxy.dll -> C:\Windows\SysWow64\DevicePairingProxy.dll -> [2009/09/17 04:40:08 | 00,054,784 | ---- | C] (Microsoft Corporation)
authui.dll -> C:\Windows\SysWow64\authui.dll -> [2009/09/17 04:40:07 | 01,985,024 | ---- | C] (Microsoft Corporation)
NetProjW.dll -> C:\Windows\SysNative\NetProjW.dll -> [2009/09/17 04:40:07 | 01,098,240 | ---- | C] (Microsoft Corporation)
wcncsvc.dll -> C:\Windows\SysNative\wcncsvc.dll -> [2009/09/17 04:40:07 | 00,581,120 | ---- | C] (Microsoft Corporation)
msctfp.dll -> C:\Windows\SysNative\msctfp.dll -> [2009/09/17 04:40:07 | 00,230,400 | ---- | C] (Microsoft Corporation)
fdBthProxy.dll -> C:\Windows\SysNative\fdBthProxy.dll -> [2009/09/17 04:40:07 | 00,012,288 | ---- | C] (Microsoft Corporation)
msdtctm.dll -> C:\Windows\SysNative\msdtctm.dll -> [2009/09/17 04:40:06 | 01,499,136 | ---- | C] (Microsoft Corporation)
shdocvw.dll -> C:\Windows\SysNative\shdocvw.dll -> [2009/09/17 04:40:06 | 01,195,520 | ---- | C] (Microsoft Corporation)
msrepl40.dll -> C:\Windows\SysWow64\msrepl40.dll -> [2009/09/17 04:40:06 | 00,643,072 | ---- | C] (Microsoft Corporation)
msvcp60.dll -> C:\Windows\SysNative\msvcp60.dll -> [2009/09/17 04:40:06 | 00,598,016 | ---- | C] (Microsoft Corporation)
vbscript.dll -> C:\Windows\SysWow64\vbscript.dll -> [2009/09/17 04:40:06 | 00,430,080 | ---- | C] (Microsoft Corporation)
PresentationHost.exe -> C:\Windows\SysWow64\PresentationHost.exe -> [2009/09/17 04:40:06 | 00,323,952 | ---- | C] (Microsoft Corporation)
davclnt.dll -> C:\Windows\SysNative\davclnt.dll -> [2009/09/17 04:40:06 | 00,082,432 | ---- | C] (Microsoft Corporation)
certutil.exe -> C:\Windows\SysNative\certutil.exe -> [2009/09/17 04:40:05 | 01,060,864 | ---- | C] (Microsoft Corporation)
propsys.dll -> C:\Windows\SysWow64\propsys.dll -> [2009/09/17 04:40:05 | 00,754,688 | ---- | C] (Microsoft Corporation)
win32spl.dll -> C:\Windows\SysNative\win32spl.dll -> [2009/09/17 04:40:05 | 00,660,480 | ---- | C] (Microsoft Corporation)
bthprops.cpl -> C:\Windows\SysWow64\bthprops.cpl -> [2009/09/17 04:40:05 | 00,640,512 | ---- | C] (Microsoft Corporation)
newdev.dll -> C:\Windows\SysWow64\newdev.dll -> [2009/09/17 04:40:05 | 00,469,504 | ---- | C] (Microsoft Corporation)
w32time.dll -> C:\Windows\SysNative\w32time.dll -> [2009/09/17 04:40:05 | 00,372,736 | ---- | C] (Microsoft Corporation)
PresentationHost.exe -> C:\Windows\SysNative\PresentationHost.exe -> [2009/09/17 04:40:05 | 00,354,640 | ---- | C] (Microsoft Corporation)
rsaenh.dll -> C:\Windows\SysNative\rsaenh.dll -> [2009/09/17 04:40:05 | 00,289,768 | ---- | C] (Microsoft Corporation)
spoolsv.exe -> C:\Windows\SysNative\spoolsv.exe -> [2009/09/17 04:40:05 | 00,268,288 | ---- | C] (Microsoft Corporation)
netbt.sys -> C:\Windows\SysNative\drivers\netbt.sys -> [2009/09/17 04:40:05 | 00,248,320 | ---- | C] (Microsoft Corporation)
WebClnt.dll -> C:\Windows\SysNative\WebClnt.dll -> [2009/09/17 04:40:05 | 00,218,624 | ---- | C] (Microsoft Corporation)
Classpnp.sys -> C:\Windows\SysNative\drivers\Classpnp.sys -> [2009/09/17 04:40:05 | 00,164,840 | ---- | C] (Microsoft Corporation)
gpsvc.dll -> C:\Windows\SysNative\gpsvc.dll -> [2009/09/17 04:40:04 | 00,719,360 | ---- | C] (Microsoft Corporation)
SLCommDlg.dll -> C:\Windows\SysNative\SLCommDlg.dll -> [2009/09/17 04:40:04 | 00,631,296 | ---- | C] (Microsoft Corporation)
eudcedit.exe -> C:\Windows\SysWow64\eudcedit.exe -> [2009/09/17 04:40:04 | 00,205,824 | ---- | C] (Microsoft Corporation)
iasrecst.dll -> C:\Windows\SysWow64\iasrecst.dll -> [2009/09/17 04:40:04 | 00,119,296 | ---- | C] (Microsoft Corporation)
PresentationCFFRasterizerNative_v0300.dll -> C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll -> [2009/09/17 04:40:04 | 00,102,816 | ---- | C] (Microsoft Corporation)
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2009/09/17 04:40:03 | 02,926,592 | ---- | C] (Microsoft Corporation)
certmgr.dll -> C:\Windows\SysNative\certmgr.dll -> [2009/09/17 04:40:03 | 01,748,992 | ---- | C] (Microsoft Corporation)
crypt32.dll -> C:\Windows\SysWow64\crypt32.dll -> [2009/09/17 04:40:03 | 00,978,944 | ---- | C] (Microsoft Corporation)
msdtcprx.dll -> C:\Windows\SysNative\msdtcprx.dll -> [2009/09/17 04:40:03 | 00,727,552 | ---- | C] (Microsoft Corporation)
iedkcs32.dll -> C:\Windows\SysWow64\iedkcs32.dll -> [2009/09/17 04:40:03 | 00,398,848 | ---- | C] (Microsoft Corporation)
umpnpmgr.dll -> C:\Windows\SysNative\umpnpmgr.dll -> [2009/09/17 04:40:03 | 00,313,344 | ---- | C] (Microsoft Corporation)
d3d9.dll -> C:\Windows\SysWow64\d3d9.dll -> [2009/09/17 04:40:02 | 01,788,416 | ---- | C] (Microsoft Corporation)
setupapi.dll -> C:\Windows\SysWow64\setupapi.dll -> [2009/09/17 04:40:02 | 01,591,296 | ---- | C] (Microsoft Corporation)
PhotoScreensaver.scr -> C:\Windows\SysNative\PhotoScreensaver.scr -> [2009/09/17 04:40:02 | 00,840,704 | ---- | C] (Microsoft Corporation)
mspbde40.dll -> C:\Windows\SysWow64\mspbde40.dll -> [2009/09/17 04:40:02 | 00,368,640 | ---- | C] (Microsoft Corporation)
rdbss.sys -> C:\Windows\SysNative\drivers\rdbss.sys -> [2009/09/17 04:40:02 | 00,287,744 | ---- | C] (Microsoft Corporation)
swprv.dll -> C:\Windows\SysNative\swprv.dll -> [2009/09/17 04:40:01 | 00,480,768 | ---- | C] (Microsoft Corporation)
SLUI.exe -> C:\Windows\SysNative\SLUI.exe -> [2009/09/17 04:40:01 | 00,385,024 | ---- | C] (Microsoft Corporation)
davclnt.dll -> C:\Windows\SysWow64\davclnt.dll -> [2009/09/17 04:40:01 | 00,061,440 | ---- | C] (Microsoft Corporation)
WMNetMgr.dll -> C:\Windows\SysNative\WMNetMgr.dll -> [2009/09/17 04:40:00 | 01,245,696 | ---- | C] (Microsoft Corporation)
MPSSVC.dll -> C:\Windows\SysNative\MPSSVC.dll -> [2009/09/17 04:40:00 | 00,603,136 | ---- | C] (Microsoft Corporation)
gdi32.dll -> C:\Windows\SysNative\gdi32.dll -> [2009/09/17 04:40:00 | 00,389,632 | ---- | C] (Microsoft Corporation)
msltus40.dll -> C:\Windows\SysWow64\msltus40.dll -> [2009/09/17 04:40:00 | 00,241,664 | ---- | C] (Microsoft Corporation)
mfc42.dll -> C:\Windows\SysWow64\mfc42.dll -> [2009/09/17 04:39:59 | 01,135,104 | ---- | C] (Microsoft Corporation)
WindowsCodecs.dll -> C:\Windows\SysNative\WindowsCodecs.dll -> [2009/09/17 04:39:59 | 00,841,728 | ---- | C] (Microsoft Corporation)
wmicmiplugin.dll -> C:\Windows\SysNative\wmicmiplugin.dll -> [2009/09/17 04:39:59 | 00,497,152 | ---- | C] (Microsoft Corporation)
ci.dll -> C:\Windows\SysNative\ci.dll -> [2009/09/17 04:39:59 | 00,380,392 | ---- | C] (Microsoft Corporation)
shlwapi.dll -> C:\Windows\SysWow64\shlwapi.dll -> [2009/09/17 04:39:59 | 00,353,280 | ---- | C] (Microsoft Corporation)
msrd3x40.dll -> C:\Windows\SysWow64\msrd3x40.dll -> [2009/09/17 04:39:59 | 00,344,064 | ---- | C] (Microsoft Corporation)
PortableDeviceApi.dll -> C:\Windows\SysNative\PortableDeviceApi.dll -> [2009/09/17 04:39:59 | 00,324,608 | ---- | C] (Microsoft Corporation)
WMVSDECD.DLL -> C:\Windows\SysNative\WMVSDECD.DLL -> [2009/09/17 04:39:58 | 01,543,680 | ---- | C] (Microsoft Corporation)
browseui.dll -> C:\Windows\SysWow64\browseui.dll -> [2009/09/17 04:39:58 | 01,324,032 | ---- | C] (Microsoft Corporation)
ipsecsnp.dll -> C:\Windows\SysNative\ipsecsnp.dll -> [2009/09/17 04:39:58 | 00,935,424 | ---- | C] (Microsoft Corporation)
samsrv.dll -> C:\Windows\SysNative\samsrv.dll -> [2009/09/17 04:39:58 | 00,671,744 | ---- | C] (Microsoft Corporation)
sqlsrv32.dll -> C:\Windows\SysNative\sqlsrv32.dll -> [2009/09/17 04:39:58 | 00,581,632 | ---- | C] (Microsoft Corporation)
iassdo.dll -> C:\Windows\SysNative\iassdo.dll -> [2009/09/17 04:39:58 | 00,344,064 | ---- | C] (Microsoft Corporation)
usbhub.sys -> C:\Windows\SysNative\drivers\usbhub.sys -> [2009/09/17 04:39:58 | 00,273,920 | ---- | C] (Microsoft Corporation)
wevtapi.dll -> C:\Windows\SysWow64\wevtapi.dll -> [2009/09/17 04:39:58 | 00,250,368 | ---- | C] (Microsoft Corporation)
wercon.exe -> C:\Windows\SysNative\wercon.exe -> [2009/09/17 04:39:57 | 01,394,176 | ---- | C] (Microsoft Corporation)
dxgkrnl.sys -> C:\Windows\SysNative\drivers\dxgkrnl.sys -> [2009/09/17 04:39:57 | 00,885,248 | ---- | C] (Microsoft Corporation)
netapi32.dll -> C:\Windows\SysNative\netapi32.dll -> [2009/09/17 04:39:57 | 00,648,192 | ---- | C] (Microsoft Corporation)
photowiz.dll -> C:\Windows\SysWow64\photowiz.dll -> [2009/09/17 04:39:57 | 00,293,376 | ---- | C] (Microsoft Corporation)
nlhtml.dll -> C:\Windows\SysWow64\nlhtml.dll -> [2009/09/17 04:39:57 | 00,136,192 | ---- | C] (Microsoft Corporation)
authui.dll -> C:\Windows\SysNative\authui.dll -> [2009/09/17 04:39:56 | 02,272,256 | ---- | C] (Microsoft Corporation)
quartz.dll -> C:\Windows\SysWow64\quartz.dll -> [2009/09/17 04:39:56 | 01,314,816 | ---- | C] (Microsoft Corporation)
services.exe -> C:\Windows\SysNative\services.exe -> [2009/09/17 04:39:56 | 00,384,512 | ---- | C] (Microsoft Corporation)
USBSTOR.SYS -> C:\Windows\SysNative\drivers\USBSTOR.SYS -> [2009/09/17 04:39:56 | 00,077,824 | ---- | C] (Microsoft Corporation)
mshtmled.dll -> C:\Windows\SysNative\mshtmled.dll -> [2009/09/17 04:39:55 | 00,758,272 | ---- | C] (Microsoft Corporation)
SLCommDlg.dll -> C:\Windows\SysWow64\SLCommDlg.dll -> [2009/09/17 04:39:55 | 00,582,144 | ---- | C] (Microsoft Corporation)
oleaut32.dll -> C:\Windows\SysWow64\oleaut32.dll -> [2009/09/17 04:39:55 | 00,563,712 | ---- | C] (Microsoft Corporation)
win32spl.dll -> C:\Windows\SysWow64\win32spl.dll -> [2009/09/17 04:39:55 | 00,443,392 | ---- | C] (Microsoft Corporation)
QAGENTRT.DLL -> C:\Windows\SysNative\QAGENTRT.DLL -> [2009/09/17 04:39:55 | 00,409,600 | ---- | C] (Microsoft Corporation)
dnsapi.dll -> C:\Windows\SysNative\dnsapi.dll -> [2009/09/17 04:39:55 | 00,221,696 | ---- | C] (Microsoft Corporation)
WcnNetsh.dll -> C:\Windows\SysWow64\WcnNetsh.dll -> [2009/09/17 04:39:55 | 00,165,376 | ---- | C] (Microsoft Corporation)
netshell.dll -> C:\Windows\SysWow64\netshell.dll -> [2009/09/17 04:39:54 | 03,174,400 | ---- | C] (Microsoft Corporation)
apds.dll -> C:\Windows\SysWow64\apds.dll -> [2009/09/17 04:39:54 | 01,730,560 | ---- | C] (Microsoft Corporation)
comdlg32.dll -> C:\Windows\SysNative\comdlg32.dll -> [2009/09/17 04:39:54 | 00,549,888 | ---- | C] (Microsoft Corporation)
odbc32.dll -> C:\Windows\SysNative\odbc32.dll -> [2009/09/17 04:39:54 | 00,462,848 | ---- | C] (Microsoft Corporation)
mswsock.dll -> C:\Windows\SysNative\mswsock.dll -> [2009/09/17 04:39:54 | 00,304,128 | ---- | C] (Microsoft Corporation)
propdefs.dll -> C:\Windows\SysNative\propdefs.dll -> [2009/09/17 04:39:54 | 00,080,896 | ---- | C] (Microsoft Corporation)
msctf.dll -> C:\Windows\SysWow64\msctf.dll -> [2009/09/17 04:39:53 | 00,807,424 | ---- | C] (Microsoft Corporation)
netlogon.dll -> C:\Windows\SysNative\netlogon.dll -> [2009/09/17 04:39:53 | 00,717,312 | ---- | C] (Microsoft Corporation)
mswstr10.dll -> C:\Windows\SysWow64\mswstr10.dll -> [2009/09/17 04:39:53 | 00,618,496 | ---- | C] (Microsoft Corporation)
winhttp.dll -> C:\Windows\SysWow64\winhttp.dll -> [2009/09/17 04:39:53 | 00,375,808 | ---- | C] (Microsoft Corporation)
ws2_32.dll -> C:\Windows\SysNative\ws2_32.dll -> [2009/09/17 04:39:53 | 00,264,704 | ---- | C] (Microsoft Corporation)
mrxdav.sys -> C:\Windows\SysNative\drivers\mrxdav.sys -> [2009/09/17 04:39:53 | 00,139,264 | ---- | C] (Microsoft Corporation)
xmlfilter.dll -> C:\Windows\SysWow64\xmlfilter.dll -> [2009/09/17 04:39:53 | 00,056,320 | ---- | C] (Microsoft Corporation)
mfc42u.dll -> C:\Windows\SysWow64\mfc42u.dll -> [2009/09/17 04:39:52 | 01,160,704 | ---- | C] (Microsoft Corporation)
WerFaultSecure.exe -> C:\Windows\SysNative\WerFaultSecure.exe -> [2009/09/17 04:39:52 | 01,114,112 | ---- | C] (Microsoft Corporation)
msvcrt.dll -> C:\Windows\SysWow64\msvcrt.dll -> [2009/09/17 04:39:52 | 00,679,936 | ---- | C] (Microsoft Corporation)
emdmgmt.dll -> C:\Windows\SysNative\emdmgmt.dll -> [2009/09/17 04:39:52 | 00,399,360 | ---- | C] (Microsoft Corporation)
eapphost.dll -> C:\Windows\SysNative\eapphost.dll -> [2009/09/17 04:39:52 | 00,261,632 | ---- | C] (Microsoft Corporation)
winresume.efi -> C:\Windows\SysNative\winresume.efi -> [2009/09/17 04:39:51 | 00,992,728 | ---- | C] (Microsoft Corporation)
PhotoMetadataHandler.dll -> C:\Windows\SysNative\PhotoMetadataHandler.dll -> [2009/09/17 04:39:51 | 00,470,016 | ---- | C] (Microsoft Corporation)
newdev.dll -> C:\Windows\SysNative\newdev.dll -> [2009/09/17 04:39:51 | 00,215,552 | ---- | C] (Microsoft Corporation)
WinSCard.dll -> C:\Windows\SysNative\WinSCard.dll -> [2009/09/17 04:39:51 | 00,190,464 | ---- | C] (Microsoft Corporation)
eapphost.dll -> C:\Windows\SysWow64\eapphost.dll -> [2009/09/17 04:39:51 | 00,183,808 | ---- | C] (Microsoft Corporation)
FWPKCLNT.SYS -> C:\Windows\SysNative\drivers\FWPKCLNT.SYS -> [2009/09/17 04:39:51 | 00,166,888 | ---- | C] (Microsoft Corporation)
azroles.dll -> C:\Windows\SysNative\azroles.dll -> [2009/09/17 04:39:50 | 00,894,976 | ---- | C] (Microsoft Corporation)
IPSECSVC.DLL -> C:\Windows\SysNative\IPSECSVC.DLL -> [2009/09/17 04:39:50 | 00,533,504 | ---- | C] (Microsoft Corporation)
sqlsrv32.dll -> C:\Windows\SysWow64\sqlsrv32.dll -> [2009/09/17 04:39:50 | 00,524,288 | ---- | C] (Microsoft Corporation)
msrd2x40.dll -> C:\Windows\SysWow64\msrd2x40.dll -> [2009/09/17 04:39:50 | 00,319,488 | ---- | C] (Microsoft Corporation)
MMDevAPI.dll -> C:\Windows\SysNative\MMDevAPI.dll -> [2009/09/17 04:39:50 | 00,203,776 | ---- | C] (Microsoft Corporation)
wlanpref.dll -> C:\Windows\SysNative\wlanpref.dll -> [2009/09/17 04:39:49 | 01,792,512 | ---- | C] (Microsoft Corporation)
usp10.dll -> C:\Windows\SysNative\usp10.dll -> [2009/09/17 04:39:49 | 00,621,568 | ---- | C] (Microsoft Corporation)
odbc32.dll -> C:\Windows\SysWow64\odbc32.dll -> [2009/09/17 04:39:49 | 00,409,600 | ---- | C] (Microsoft Corporation)
wevtutil.exe -> C:\Windows\SysNative\wevtutil.exe -> [2009/09/17 04:39:49 | 00,248,832 | ---- | C] (Microsoft Corporation)
propdefs.dll -> C:\Windows\SysWow64\propdefs.dll -> [2009/09/17 04:39:49 | 00,071,680 | ---- | C] (Microsoft Corporation)
milcore.dll -> C:\Windows\SysNative\milcore.dll -> [2009/09/17 04:39:48 | 02,570,240 | ---- | C] (Microsoft Corporation)
shdocvw.dll -> C:\Windows\SysWow64\shdocvw.dll -> [2009/09/17 04:39:48 | 01,068,032 | ---- | C] (Microsoft Corporation)
ieapfltr.dll -> C:\Windows\SysNative\ieapfltr.dll -> [2009/09/17 04:39:48 | 00,422,400 | ---- | C] (Microsoft Corporation)
msscb.dll -> C:\Windows\SysNative\msscb.dll -> [2009/09/17 04:39:48 | 00,044,544 | ---- | C] (Microsoft Corporation)
dbgeng.dll -> C:\Windows\SysWow64\dbgeng.dll -> [2009/09/17 04:39:47 | 01,856,512 | ---- | C] (Microsoft Corporation)
WSDApi.dll -> C:\Windows\SysNative\WSDApi.dll -> [2009/09/17 04:39:47 | 00,441,856 | ---- | C] (Microsoft Corporation)
Wldap32.dll -> C:\Windows\SysNative\Wldap32.dll -> [2009/09/17 04:39:47 | 00,328,704 | ---- | C] (Microsoft Corporation)
iasnap.dll -> C:\Windows\SysNative\iasnap.dll -> [2009/09/17 04:39:47 | 00,213,504 | ---- | C] (Microsoft Corporation)
wevtutil.exe -> C:\Windows\SysWow64\wevtutil.exe -> [2009/09/17 04:39:47 | 00,163,840 | ---- | C] (Microsoft Corporation)
mssitlb.dll -> C:\Windows\SysNative\mssitlb.dll -> [2009/09/17 04:39:47 | 00,087,552 | ---- | C] (Microsoft Corporation)
mmcndmgr.dll -> C:\Windows\SysWow64\mmcndmgr.dll -> [2009/09/17 04:39:46 | 02,167,808 | ---- | C] (Microsoft Corporation)
mcmde.dll -> C:\Windows\SysNative\mcmde.dll -> [2009/09/17 04:39:46 | 01,074,176 | ---- | C] (Microsoft Corporation)
WsmSvc.dll -> C:\Windows\SysWow64\WsmSvc.dll -> [2009/09/17 04:39:46 | 00,747,008 | ---- | C] (Microsoft Corporation)
usp10.dll -> C:\Windows\SysWow64\usp10.dll -> [2009/09/17 04:39:46 | 00,502,272 | ---- | C] (Microsoft Corporation)
msiscsi.sys -> C:\Windows\SysNative\drivers\msiscsi.sys -> [2009/09/17 04:39:46 | 00,215,528 | ---- | C] (Microsoft Corporation)
mssitlb.dll -> C:\Windows\SysWow64\mssitlb.dll -> [2009/09/17 04:39:46 | 00,087,040 | ---- | C] (Microsoft Corporation)
wmpmde.dll -> C:\Windows\SysNative\wmpmde.dll -> [2009/09/17 04:39:45 | 01,090,048 | ---- | C] (Microsoft Corporation)
mshtmled.dll -> C:\Windows\SysWow64\mshtmled.dll -> [2009/09/17 04:39:45 | 00,477,184 | ---- | C] (Microsoft Corporation)
ieapfltr.dll -> C:\Windows\SysWow64\ieapfltr.dll -> [2009/09/17 04:39:45 | 00,380,928 | ---- | C] (Microsoft Corporation)
iassam.dll -> C:\Windows\SysNative\iassam.dll -> [2009/09/17 04:39:45 | 00,242,176 | ---- | C] (Microsoft Corporation)
bthserv.dll -> C:\Windows\SysNative\bthserv.dll -> [2009/09/17 04:39:45 | 00,053,760 | ---- | C] (Microsoft Corporation)
propsys.dll -> C:\Windows\SysNative\propsys.dll -> [2009/09/17 04:39:44 | 00,923,136 | ---- | C] (Microsoft Corporation)
netlogon.dll -> C:\Windows\SysWow64\netlogon.dll -> [2009/09/17 04:39:44 | 00,592,896 | ---- | C] (Microsoft Corporation)
winsrv.dll -> C:\Windows\SysNative\winsrv.dll -> [2009/09/17 04:39:44 | 00,450,560 | ---- | C] (Microsoft Corporation)
devmgr.dll -> C:\Windows\SysWow64\devmgr.dll -> [2009/09/17 04:39:44 | 00,378,368 | ---- | C] (Microsoft Corporation)
drvinst.exe -> C:\Windows\SysWow64\drvinst.exe -> [2009/09/17 04:39:44 | 00,194,048 | ---- | C] (Microsoft Corporation)
msctfp.dll -> C:\Windows\SysWow64\msctfp.dll -> [2009/09/17 04:39:44 | 00,084,992 | ---- | C] (Microsoft Corporation)
rtffilt.dll -> C:\Windows\SysNative\rtffilt.dll -> [2009/09/17 04:39:44 | 00,042,496 | ---- | C] (Microsoft Corporation)
fdBthProxy.dll -> C:\Windows\SysWow64\fdBthProxy.dll -> [2009/09/17 04:39:44 | 00,009,728 | ---- | C] (Microsoft Corporation)
wcnwiz.dll -> C:\Windows\SysWow64\wcnwiz.dll -> [2009/09/17 04:39:43 | 01,533,440 | ---- | C] (Microsoft Corporation)
evr.dll -> C:\Windows\SysWow64\evr.dll -> [2009/09/17 04:39:43 | 00,485,888 | ---- | C] (Microsoft Corporation)
adsldpc.dll -> C:\Windows\SysWow64\adsldpc.dll -> [2009/09/17 04:39:43 | 00,199,168 | ---- | C] (Microsoft Corporation)
srv2.sys -> C:\Windows\SysNative\drivers\srv2.sys -> [2009/09/17 04:39:43 | 00,174,592 | ---- | C] (Microsoft Corporation)
cryptsvc.dll -> C:\Windows\SysNative\cryptsvc.dll -> [2009/09/17 04:39:43 | 00,166,912 | ---- | C] (Microsoft Corporation)
msscb.dll -> C:\Windows\SysWow64\msscb.dll -> [2009/09/17 04:39:43 | 00,035,328 | ---- | C] (Microsoft Corporation)
WMVSDECD.DLL -> C:\Windows\SysWow64\WMVSDECD.DLL -> [2009/09/17 04:39:42 | 01,382,912 | ---- | C] (Microsoft Corporation)
mscms.dll -> C:\Windows\SysNative\mscms.dll -> [2009/09/17 04:39:42 | 00,519,680 | ---- | C] (Microsoft Corporation)
vds.exe -> C:\Windows\SysNative\vds.exe -> [2009/09/17 04:39:42 | 00,454,656 | ---- | C] (Microsoft Corporation)
PhotoMetadataHandler.dll -> C:\Windows\SysWow64\PhotoMetadataHandler.dll -> [2009/09/17 04:39:42 | 00,425,472 | ---- | C] (Microsoft Corporation)
winlogon.exe -> C:\Windows\SysNative\winlogon.exe -> [2009/09/17 04:39:42 | 00,405,504 | ---- | C] (Microsoft Corporation)
WSDApi.dll -> C:\Windows\SysWow64\WSDApi.dll -> [2009/09/17 04:39:42 | 00,355,328 | ---- | C] (Microsoft Corporation)
Wldap32.dll -> C:\Windows\SysWow64\Wldap32.dll -> [2009/09/17 04:39:42 | 00,287,744 | ---- | C] (Microsoft Corporation)
volsnap.sys -> C:\Windows\SysNative\drivers\volsnap.sys -> [2009/09/17 04:39:42 | 00,269,288 | ---- | C] (Microsoft Corporation)
scrrun.dll -> C:\Windows\SysNative\scrrun.dll -> [2009/09/17 04:39:42 | 00,198,656 | ---- | C] (Microsoft Corporation)
imapi.dll -> C:\Windows\SysNative\imapi.dll -> [2009/09/17 04:39:42 | 00,151,040 | ---- | C] (Microsoft Corporation)
reg.exe -> C:\Windows\SysNative\reg.exe -> [2009/09/17 04:39:42 | 00,074,240 | ---- | C] (Microsoft Corporation)
WindowsCodecs.dll -> C:\Windows\SysWow64\WindowsCodecs.dll -> [2009/09/17 04:39:41 | 00,712,704 | ---- | C] (Microsoft Corporation)
comdlg32.dll -> C:\Windows\SysWow64\comdlg32.dll -> [2009/09/17 04:39:41 | 00,450,560 | ---- | C] (Microsoft Corporation)
services.exe -> C:\Windows\SysWow64\services.exe -> [2009/09/17 04:39:41 | 00,279,552 | ---- | C] (Microsoft Corporation)
iertutil.dll -> C:\Windows\SysWow64\iertutil.dll -> [2009/09/17 04:39:41 | 00,270,336 | ---- | C] (Microsoft Corporation)
taskeng.exe -> C:\Windows\SysNative\taskeng.exe -> [2009/09/17 04:39:41 | 00,265,216 | ---- | C] (Microsoft Corporation)
quick.ime -> C:\Windows\SysWow64\quick.ime -> [2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation)
qintlgnt.ime -> C:\Windows\SysWow64\qintlgnt.ime -> [2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation)
phon.ime -> C:\Windows\SysWow64\phon.ime -> [2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation)
cintlgnt.ime -> C:\Windows\SysWow64\cintlgnt.ime -> [2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation)
chajei.ime -> C:\Windows\SysWow64\chajei.ime -> [2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation)
partmgr.sys -> C:\Windows\SysNative\drivers\partmgr.sys -> [2009/09/17 04:39:41 | 00,073,176 | ---- | C] (Microsoft Corporation)
fdProxy.dll -> C:\Windows\SysNative\fdProxy.dll -> [2009/09/17 04:39:41 | 00,065,536 | ---- | C] (Microsoft Corporation)
mimefilt.dll -> C:\Windows\SysNative\mimefilt.dll -> [2009/09/17 04:39:41 | 00,038,912 | ---- | C] (Microsoft Corporation)
brcpl.dll -> C:\Windows\SysNative\brcpl.dll -> [2009/09/17 04:39:40 | 01,538,560 | ---- | C] (Microsoft Corporation)
wdc.dll -> C:\Windows\SysNative\wdc.dll -> [2009/09/17 04:39:40 | 01,234,432 | ---- | C] (Microsoft Corporation)
stobject.dll -> C:\Windows\SysNative\stobject.dll -> [2009/09/17 04:39:40 | 00,748,544 | ---- | C] (Microsoft Corporation)
adtschema.dll -> C:\Windows\SysWow64\adtschema.dll -> [2009/09/17 04:39:40 | 00,617,984 | ---- | C] (Microsoft Corporation)
adtschema.dll -> C:\Windows\SysNative\adtschema.dll -> [2009/09/17 04:39:40 | 00,617,984 | ---- | C] (Microsoft Corporation)
wcncsvc.dll -> C:\Windows\SysWow64\wcncsvc.dll -> [2009/09/17 04:39:40 | 00,413,696 | ---- | C] (Microsoft Corporation)
msdrm.dll -> C:\Windows\SysWow64\msdrm.dll -> [2009/09/17 04:39:40 | 00,332,288 | ---- | C] (Microsoft Corporation)
certcli.dll -> C:\Windows\SysWow64\certcli.dll -> [2009/09/17 04:39:40 | 00,323,584 | ---- | C] (Microsoft Corporation)
PortableDeviceApi.dll -> C:\Windows\SysWow64\PortableDeviceApi.dll -> [2009/09/17 04:39:40 | 00,241,152 | ---- | C] (Microsoft Corporation)
dhcpcsvc6.dll -> C:\Windows\SysNative\dhcpcsvc6.dll -> [2009/09/17 04:39:40 | 00,163,328 | ---- | C] (Microsoft Corporation)
mimefilt.dll -> C:\Windows\SysWow64\mimefilt.dll -> [2009/09/17 04:39:40 | 00,041,984 | ---- | C] (Microsoft Corporation)
mswdat10.dll -> C:\Windows\SysWow64\mswdat10.dll -> [2009/09/17 04:39:39 | 00,856,064 | ---- | C] (Microsoft Corporation)
CertEnrollUI.dll -> C:\Windows\SysNative\CertEnrollUI.dll -> [2009/09/17 04:39:39 | 00,810,496 | ---- | C] (Microsoft Corporation)
msdtcprx.dll -> C:\Windows\SysWow64\msdtcprx.dll -> [2009/09/17 04:39:39 | 00,560,640 | ---- | C] (Microsoft Corporation)
ipsmsnap.dll -> C:\Windows\SysWow64\ipsmsnap.dll -> [2009/09/17 04:39:39 | 00,396,288 | ---- | C] (Microsoft Corporation)
rasmans.dll -> C:\Windows\SysNative\rasmans.dll -> [2009/09/17 04:39:39 | 00,309,760 | ---- | C] (Microsoft Corporation)
taskeng.exe -> C:\Windows\SysWow64\taskeng.exe -> [2009/09/17 04:39:39 | 00,169,984 | ---- | C] (Microsoft Corporation)
inetpp.dll -> C:\Windows\SysNative\inetpp.dll -> [2009/09/17 04:39:39 | 00,156,160 | ---- | C] (Microsoft Corporation)
rasl2tp.sys -> C:\Windows\SysNative\drivers\rasl2tp.sys -> [2009/09/17 04:39:39 | 00,124,928 | ---- | C] (Microsoft Corporation)
msjter40.dll -> C:\Windows\SysWow64\msjter40.dll -> [2009/09/17 04:39:39 | 00,061,440 | ---- | C] (Microsoft Corporation)
pciide.sys -> C:\Windows\SysNative\drivers\pciide.sys -> [2009/09/17 04:39:39 | 00,014,312 | ---- | C] (Microsoft Corporation)
WMNetMgr.dll -> C:\Windows\SysWow64\WMNetMgr.dll -> [2009/09/17 04:39:38 | 00,996,352 | ---- | C] (Microsoft Corporation)
certutil.exe -> C:\Windows\SysWow64\certutil.exe -> [2009/09/17 04:39:38 | 00,799,744 | ---- | C] (Microsoft Corporation)
PhotoScreensaver.scr -> C:\Windows\SysWow64\PhotoScreensaver.scr -> [2009/09/17 04:39:38 | 00,704,512 | ---- | C] (Microsoft Corporation)
wiaservc.dll -> C:\Windows\SysNative\wiaservc.dll -> [2009/09/17 04:39:38 | 00,572,416 | ---- | C] (Microsoft Corporation)
clfs.sys -> C:\Windows\SysNative\clfs.sys -> [2009/09/17 04:39:38 | 00,361,448 | ---- | C] (Microsoft Corporation)
pdh.dll -> C:\Windows\SysNative\pdh.dll -> [2009/09/17 04:39:38 | 00,307,712 | ---- | C] (Microsoft Corporation)
offfilt.dll -> C:\Windows\SysNative\offfilt.dll -> [2009/09/17 04:39:38 | 00,280,064 | ---- | C] (Microsoft Corporation)
dnsapi.dll -> C:\Windows\SysWow64\dnsapi.dll -> [2009/09/17 04:39:38 | 00,168,448 | ---- | C] (Microsoft Corporation)
ataport.sys -> C:\Windows\SysNative\drivers\ataport.sys -> [2009/09/17 04:39:38 | 00,123,368 | ---- | C] (Microsoft Corporation)
reg.exe -> C:\Windows\SysWow64\reg.exe -> [2009/09/17 04:39:38 | 00,061,952 | ---- | C] (Microsoft Corporation)
rtffilt.dll -> C:\Windows\SysWow64\rtffilt.dll -> [2009/09/17 04:39:38 | 00,038,400 | ---- | C] (Microsoft Corporation)
RelMon.dll -> C:\Windows\SysNative\RelMon.dll -> [2009/09/17 04:39:37 | 00,539,136 | ---- | C] (Microsoft Corporation)
sysmon.ocx -> C:\Windows\SysNative\sysmon.ocx -> [2009/09/17 04:39:37 | 00,475,648 | ---- | C] (Microsoft Corporation)
mtxclu.dll -> C:\Windows\SysNative\mtxclu.dll -> [2009/09/17 04:39:37 | 00,361,984 | ---- | C] (Microsoft Corporation)
winspool.drv -> C:\Windows\SysNative\winspool.drv -> [2009/09/17 04:39:37 | 00,342,016 | ---- | C] (Microsoft Corporation)
scrobj.dll -> C:\Windows\SysNative\scrobj.dll -> [2009/09/17 04:39:37 | 00,227,328 | ---- | C] (Microsoft Corporation)
fundisc.dll -> C:\Windows\SysNative\fundisc.dll -> [2009/09/17 04:39:37 | 00,174,080 | ---- | C] (Microsoft Corporation)
sysclass.dll -> C:\Windows\SysNative\sysclass.dll -> [2009/09/17 04:39:37 | 00,115,200 | ---- | C] (Microsoft Corporation)
raspptp.sys -> C:\Windows\SysNative\drivers\raspptp.sys -> [2009/09/17 04:39:37 | 00,098,816 | ---- | C] (Microsoft Corporation)
msscntrs.dll -> C:\Windows\SysWow64\msscntrs.dll -> [2009/09/17 04:39:37 | 00,060,416 | ---- | C] (Microsoft Corporation)
msshooks.dll -> C:\Windows\SysWow64\msshooks.dll -> [2009/09/17 04:39:37 | 00,011,776 | ---- | C] (Microsoft Corporation)
msinfo32.exe -> C:\Windows\SysNative\msinfo32.exe -> [2009/09/17 04:39:36 | 00,488,960 | ---- | C] (Microsoft Corporation)
msihnd.dll -> C:\Windows\SysWow64\msihnd.dll -> [2009/09/17 04:39:36 | 00,332,800 | ---- | C] (Microsoft Corporation)
mfplat.dll -> C:\Windows\SysNative\mfplat.dll -> [2009/09/17 04:39:36 | 00,276,992 | ---- | C] (Microsoft Corporation)
rsaenh.dll -> C:\Windows\SysWow64\rsaenh.dll -> [2009/09/17 04:39:36 | 00,241,128 | ---- | C] (Microsoft Corporation)
adsldpc.dll -> C:\Windows\SysNative\adsldpc.dll -> [2009/09/17 04:39:36 | 00,231,936 | ---- | C] (Microsoft Corporation)
pnpsetup.dll -> C:\Windows\SysNative\pnpsetup.dll -> [2009/09/17 04:39:36 | 00,207,872 | ---- | C] (Microsoft Corporation)
ndiswan.sys -> C:\Windows\SysNative\drivers\ndiswan.sys -> [2009/09/17 04:39:36 | 00,169,472 | ---- | C] (Microsoft Corporation)
MMDevAPI.dll -> C:\Windows\SysWow64\MMDevAPI.dll -> [2009/09/17 04:39:36 | 00,150,528 | ---- | C] (Microsoft Corporation)
msstrc.dll -> C:\Windows\SysWow64\msstrc.dll -> [2009/09/17 04:39:36 | 00,043,008 | ---- | C] (Microsoft Corporation)
sethc.exe -> C:\Windows\SysNative\sethc.exe -> [2009/09/17 04:39:35 | 00,776,192 | ---- | C] (Microsoft Corporation)
inetcomm.dll -> C:\Windows\SysWow64\inetcomm.dll -> [2009/09/17 04:39:35 | 00,738,816 | ---- | C] (Microsoft Corporation)
netapi32.dll -> C:\Windows\SysWow64\netapi32.dll -> [2009/09/17 04:39:35 | 00,467,456 | ---- | C] (Microsoft Corporation)
mtxclu.dll -> C:\Windows\SysWow64\mtxclu.dll -> [2009/09/17 04:39:35 | 00,310,272 | ---- | C] (Microsoft Corporation)
usbport.sys -> C:\Windows\SysNative\drivers\usbport.sys -> [2009/09/17 04:39:35 | 00,259,584 | ---- | C] (Microsoft Corporation)
pci.sys -> C:\Windows\SysNative\drivers\pci.sys -> [2009/09/17 04:39:35 | 00,178,664 | ---- | C] (Microsoft Corporation)
cryptsvc.dll -> C:\Windows\SysWow64\cryptsvc.dll -> [2009/09/17 04:39:35 | 00,129,024 | ---- | C] (Microsoft Corporation)
msiexec.exe -> C:\Windows\SysNative\msiexec.exe -> [2009/09/17 04:39:35 | 00,125,440 | ---- | C] (Microsoft Corporation)
dfshim.dll -> C:\Windows\SysWow64\dfshim.dll -> [2009/09/17 04:39:35 | 00,093,512 | ---- | C] (Microsoft Corporation)
rasdiag.dll -> C:\Windows\SysNative\rasdiag.dll -> [2009/09/17 04:39:35 | 00,065,536 | ---- | C] (Microsoft Corporation)
appwiz.cpl -> C:\Windows\SysNative\appwiz.cpl -> [2009/09/17 04:39:34 | 01,321,472 | ---- | C] (Microsoft Corporation)
wisptis.exe -> C:\Windows\SysNative\wisptis.exe -> [2009/09/17 04:39:34 | 00,287,744 | ---- | C] (Microsoft Corporation)
iasrad.dll -> C:\Windows\SysNative\iasrad.dll -> [2009/09/17 04:39:34 | 00,198,144 | ---- | C] (Microsoft Corporation)
fundisc.dll -> C:\Windows\SysWow64\fundisc.dll -> [2009/09/17 04:39:34 | 00,153,088 | ---- | C] (Microsoft Corporation)
dhcpcsvc6.dll -> C:\Windows\SysWow64\dhcpcsvc6.dll -> [2009/09/17 04:39:34 | 00,130,560 | ---- | C] (Microsoft Corporation)
mscories.dll -> C:\Windows\SysWow64\mscories.dll -> [2009/09/17 04:39:34 | 00,080,720 | ---- | C] (Microsoft Corporation)
hidserv.dll -> C:\Windows\SysWow64\hidserv.dll -> [2009/09/17 04:39:34 | 00,026,112 | ---- | C] (Microsoft Corporation)
autofmt.exe -> C:\Windows\SysNative\autofmt.exe -> [2009/09/17 04:39:33 | 00,722,944 | ---- | C] (Microsoft Corporation)
acpi.sys -> C:\Windows\SysNative\drivers\acpi.sys -> [2009/09/17 04:39:33 | 00,325,608 | ---- | C] (Microsoft Corporation)
mrxsmb10.sys -> C:\Windows\SysNative\drivers\mrxsmb10.sys -> [2009/09/17 04:39:33 | 00,273,408 | ---- | C] (Microsoft Corporation)
osk.exe -> C:\Windows\SysNative\osk.exe -> [2009/09/17 04:39:33 | 00,212,480 | ---- | C] (Microsoft Corporation)
AudioSes.dll -> C:\Windows\SysNative\AudioSes.dll -> [2009/09/17 04:39:33 | 00,190,976 | ---- | C] (Microsoft Corporation)
dfshim.dll -> C:\Windows\SysNative\dfshim.dll -> [2009/09/17 04:39:33 | 00,108,864 | ---- | C] (Microsoft Corporation)
termdd.sys -> C:\Windows\SysNative\drivers\termdd.sys -> [2009/09/17 04:39:33 | 00,062,440 | ---- | C] (Microsoft Corporation)
TsWpfWrp.exe -> C:\Windows\SysWow64\TsWpfWrp.exe -> [2009/09/17 04:39:33 | 00,035,680 | ---- | C] (Microsoft Corporation)
TsWpfWrp.exe -> C:\Windows\SysNative\TsWpfWrp.exe -> [2009/09/17 04:39:33 | 00,034,624 | ---- | C] (Microsoft Corporation)
cryptui.dll -> C:\Windows\SysNative\cryptui.dll -> [2009/09/17 04:39:32 | 01,035,776 | ---- | C] (Microsoft Corporation)
Utilman.exe -> C:\Windows\SysNative\Utilman.exe -> [2009/09/17 04:39:32 | 00,785,920 | ---- | C] (Microsoft Corporation)
termsrv.dll -> C:\Windows\SysNative\termsrv.dll -> [2009/09/17 04:39:32 | 00,547,328 | ---- | C] (Microsoft Corporation)
tcpipcfg.dll -> C:\Windows\SysNative\tcpipcfg.dll -> [2009/09/17 04:39:32 | 00,238,080 | ---- | C] (Microsoft Corporation)
mrxsmb.sys -> C:\Windows\SysNative\drivers\mrxsmb.sys -> [2009/09/17 04:39:32 | 00,135,168 | ---- | C] (Microsoft Corporation)
imapi.dll -> C:\Windows\SysWow64\imapi.dll -> [2009/09/17 04:39:32 | 00,107,520 | ---- | C] (Microsoft Corporation)
SLUINotify.dll -> C:\Windows\SysNative\SLUINotify.dll -> [2009/09/17 04:39:32 | 00,073,216 | ---- | C] (Microsoft Corporation)
msiexec.exe -> C:\Windows\SysWow64\msiexec.exe -> [2009/09/17 04:39:32 | 00,073,216 | ---- | C] (Microsoft Corporation)
iasdatastore.dll -> C:\Windows\SysNative\iasdatastore.dll -> [2009/09/17 04:39:32 | 00,065,536 | ---- | C] (Microsoft Corporation)
chsbrkr.dll -> C:\Windows\SysWow64\chsbrkr.dll -> [2009/09/17 04:39:31 | 01,671,680 | ---- | C] (Microsoft Corporation)
wdc.dll -> C:\Windows\SysWow64\wdc.dll -> [2009/09/17 04:39:31 | 01,020,928 | ---- | C] (Microsoft Corporation)
printui.dll -> C:\Windows\SysNative\printui.dll -> [2009/09/17 04:39:31 | 00,980,480 | ---- | C] (Microsoft Corporation)
iassdo.dll -> C:\Windows\SysWow64\iassdo.dll -> [2009/09/17 04:39:31 | 00,252,928 | ---- | C] (Microsoft Corporation)
shsvcs.dll -> C:\Windows\SysWow64\shsvcs.dll -> [2009/09/17 04:39:31 | 00,247,296 | ---- | C] (Microsoft Corporation)
winmm.dll -> C:\Windows\SysNative\winmm.dll -> [2009/09/17 04:39:31 | 00,211,968 | ---- | C] (Microsoft Corporation)
imm32.dll -> C:\Windows\SysWow64\imm32.dll -> [2009/09/17 04:39:31 | 00,116,224 | ---- | C] (Microsoft Corporation)
Kswdmcap.ax -> C:\Windows\SysWow64\Kswdmcap.ax -> [2009/09/17 04:39:31 | 00,093,696 | ---- | C] (Microsoft Corporation)
pnidui.dll -> C:\Windows\SysNative\pnidui.dll -> [2009/09/17 04:39:30 | 02,024,960 | ---- | C] (Microsoft Corporation)
pnidui.dll -> C:\Windows\SysWow64\pnidui.dll -> [2009/09/17 04:39:30 | 01,823,744 | ---- | C] (Microsoft Corporation)
connect.dll -> C:\Windows\SysNative\connect.dll -> [2009/09/17 04:39:30 | 01,691,648 | ---- | C] (Microsoft Corporation)
rdpencom.dll -> C:\Windows\SysNative\rdpencom.dll -> [2009/09/17 04:39:30 | 00,708,608 | ---- | C] (Microsoft Corporation)
WerFault.exe -> C:\Windows\SysNative\WerFault.exe -> [2009/09/17 04:39:30 | 00,260,608 | ---- | C] (Microsoft Corporation)
iasads.dll -> C:\Windows\SysNative\iasads.dll -> [2009/09/17 04:39:30 | 00,078,336 | ---- | C] (Microsoft Corporation)
crashdmp.sys -> C:\Windows\SysNative\drivers\crashdmp.sys -> [2009/09/17 04:39:30 | 00,039,400 | ---- | C] (Microsoft Corporation)
autofmt.exe -> C:\Windows\SysWow64\autofmt.exe -> [2009/09/17 04:39:29 | 00,636,416 | ---- | C] (Microsoft Corporation)
dsound.dll -> C:\Windows\SysNative\dsound.dll -> [2009/09/17 04:39:29 | 00,522,752 | ---- | C] (Microsoft Corporation)
volmgrx.sys -> C:\Windows\SysNative\drivers\volmgrx.sys -> [2009/09/17 04:39:29 | 00,408,024 | ---- | C] (Microsoft Corporation)
WindowsCodecsExt.dll -> C:\Windows\SysNative\WindowsCodecsExt.dll -> [2009/09/17 04:39:29 | 00,387,584 | ---- | C] (Microsoft Corporation)
scansetting.dll -> C:\Windows\SysNative\scansetting.dll -> [2009/09/17 04:39:29 | 00,302,080 | ---- | C] (Microsoft Corporation)
dhcpcsvc.dll -> C:\Windows\SysNative\dhcpcsvc.dll -> [2009/09/17 04:39:29 | 00,268,288 | ---- | C] (Microsoft Corporation)
ncrypt.dll -> C:\Windows\SysNative\ncrypt.dll -> [2009/09/17 04:39:29 | 00,253,952 | ---- | C] (Microsoft Corporation)
scrrun.dll -> C:\Windows\SysWow64\scrrun.dll -> [2009/09/17 04:39:29 | 00,172,032 | ---- | C] (Microsoft Corporation)
drvinst.exe -> C:\Windows\SysNative\drvinst.exe -> [2009/09/17 04:39:29 | 00,061,440 | ---- | C] (Microsoft Corporation)
spcmsg.dll -> C:\Windows\SysNative\spcmsg.dll -> [2009/09/17 04:39:29 | 00,014,336 | ---- | C] (Microsoft Corporation)
spcmsg.dll -> C:\Windows\SysWow64\spcmsg.dll -> [2009/09/17 04:39:29 | 00,013,312 | ---- | C] (Microsoft Corporation)
netcenter.dll -> C:\Windows\SysNative\netcenter.dll -> [2009/09/17 04:39:28 | 02,420,224 | ---- | C] (Microsoft Corporation)
pidgenx.dll -> C:\Windows\SysNative\pidgenx.dll -> [2009/09/17 04:39:28 | 01,093,120 | ---- | C] (Microsoft Corporation)
prnntfy.dll -> C:\Windows\SysNative\prnntfy.dll -> [2009/09/17 04:39:28 | 00,708,608 | ---- | C] (Microsoft Corporation)
untfs.dll -> C:\Windows\SysNative\untfs.dll -> [2009/09/17 04:39:28 | 00,372,224 | ---- | C] (Microsoft Corporation)
pdh.dll -> C:\Windows\SysWow64\pdh.dll -> [2009/09/17 04:39:28 | 00,242,176 | ---- | C] (Microsoft Corporation)
dhcpcsvc.dll -> C:\Windows\SysWow64\dhcpcsvc.dll -> [2009/09/17 04:39:28 | 00,204,288 | ---- | C] (Microsoft Corporation)
diskpart.exe -> C:\Windows\SysNative\diskpart.exe -> [2009/09/17 04:39:28 | 00,149,504 | ---- | C] (Microsoft Corporation)
SCardSvr.dll -> C:\Windows\SysNative\SCardSvr.dll -> [2009/09/17 04:39:28 | 00,147,968 | ---- | C] (Microsoft Corporation)
IPHLPAPI.DLL -> C:\Windows\SysNative\IPHLPAPI.DLL -> [2009/09/17 04:39:28 | 00,126,976 | ---- | C] (Microsoft Corporation)
mup.sys -> C:\Windows\SysNative\drivers\mup.sys -> [2009/09/17 04:39:28 | 00,059,880 | ---- | C] (Microsoft Corporation)
appwiz.cpl -> C:\Windows\SysWow64\appwiz.cpl -> [2009/09/17 04:39:27 | 01,122,304 | ---- | C] (Microsoft Corporation)
mmsys.cpl -> C:\Windows\SysNative\mmsys.cpl -> [2009/09/17 04:39:27 | 01,060,352 | ---- | C] (Microsoft Corporation)
rasdlg.dll -> C:\Windows\SysNative\rasdlg.dll -> [2009/09/17 04:39:27 | 00,911,872 | ---- | C] (Microsoft Corporation)
azroles.dll -> C:\Windows\SysWow64\azroles.dll -> [2009/09/17 04:39:27 | 00,757,248 | ---- | C] (Microsoft Corporation)
CertEnrollUI.dll -> C:\Windows\SysWow64\CertEnrollUI.dll -> [2009/09/17 04:39:27 | 00,633,856 | ---- | C] (Microsoft Corporation)
vdsdyn.dll -> C:\Windows\SysNative\vdsdyn.dll -> [2009/09/17 04:39:27 | 00,571,904 | ---- | C] (Microsoft Corporation)
spp.dll -> C:\Windows\SysNative\spp.dll -> [2009/09/17 04:39:27 | 00,188,928 | ---- | C] (Microsoft Corporation)
secproc_ssp_isv.dll -> C:\Windows\SysNative\secproc_ssp_isv.dll -> [2009/09/17 04:39:27 | 00,160,768 | ---- | C] (Microsoft Corporation)
secproc_ssp.dll -> C:\Windows\SysNative\secproc_ssp.dll -> [2009/09/17 04:39:27 | 00,160,768 | ---- | C] (Microsoft Corporation)
userenv.dll -> C:\Windows\SysNative\userenv.dll -> [2009/09/17 04:39:27 | 00,137,216 | ---- | C] (Microsoft Corporation)
chsbrkr.dll -> C:\Windows\SysNative\chsbrkr.dll -> [2009/09/17 04:39:26 | 01,676,800 | ---- | C] (Microsoft Corporation)
pidgenx.dll -> C:\Windows\SysWow64\pidgenx.dll -> [2009/09/17 04:39:26 | 01,107,968 | ---- | C] (Microsoft Corporation)
wmpmde.dll -> C:\Windows\SysWow64\wmpmde.dll -> [2009/09/17 04:39:26 | 00,867,328 | ---- | C] (Microsoft Corporation)
sysmon.ocx -> C:\Windows\SysWow64\sysmon.ocx -> [2009/09/17 04:39:26 | 00,389,632 | ---- | C] (Microsoft Corporation)
msrpc.sys -> C:\Windows\SysNative\drivers\msrpc.sys -> [2009/09/17 04:39:26 | 00,310,760 | ---- | C] (Microsoft Corporation)
InkEd.dll -> C:\Windows\SysNative\InkEd.dll -> [2009/09/17 04:39:26 | 00,276,480 | ---- | C] (Microsoft Corporation)
winspool.drv -> C:\Windows\SysWow64\winspool.drv -> [2009/09/17 04:39:26 | 00,258,048 | ---- | C] (Microsoft Corporation)
mscories.dll -> C:\Windows\SysNative\mscories.dll -> [2009/09/17 04:39:26 | 00,073,024 | ---- | C] (Microsoft Corporation)
ipfltdrv.sys -> C:\Windows\SysNative\drivers\ipfltdrv.sys -> [2009/09/17 04:39:26 | 00,067,584 | ---- | C] (Microsoft Corporation)
SyncCenter.dll -> C:\Windows\SysWow64\SyncCenter.dll -> [2009/09/17 04:39:25 | 02,205,184 | ---- | C] (Microsoft Corporation)
certmgr.dll -> C:\Windows\SysWow64\certmgr.dll -> [2009/09/17 04:39:25 | 01,502,720 | ---- | C] (Microsoft Corporation)
comuid.dll -> C:\Windows\SysWow64\comuid.dll -> [2009/09/17 04:39:25 | 00,593,408 | ---- | C] (Microsoft Corporation)
winlogon.exe -> C:\Windows\SysWow64\winlogon.exe -> [2009/09/17 04:39:25 | 00,314,368 | ---- | C] (Microsoft Corporation)
dskquoui.dll -> C:\Windows\SysNative\dskquoui.dll -> [2009/09/17 04:39:25 | 00,237,056 | ---- | C] (Microsoft Corporation)
disk.sys -> C:\Windows\SysNative\drivers\disk.sys -> [2009/09/17 04:39:25 | 00,067,032 | ---- | C] (Microsoft Corporation)
inetcomm.dll -> C:\Windows\SysNative\inetcomm.dll -> [2009/09/17 04:39:24 | 00,974,848 | ---- | C] (Microsoft Corporation)
sethc.exe -> C:\Windows\SysWow64\sethc.exe -> [2009/09/17 04:39:24 | 00,627,200 | ---- | C] (Microsoft Corporation)
WindowsCodecsExt.dll -> C:\Windows\SysWow64\WindowsCodecsExt.dll -> [2009/09/17 04:39:24 | 00,347,648 | ---- | C] (Microsoft Corporation)
untfs.dll -> C:\Windows\SysWow64\untfs.dll -> [2009/09/17 04:39:24 | 00,324,096 | ---- | C] (Microsoft Corporation)
ncrypt.dll -> C:\Windows\SysWow64\ncrypt.dll -> [2009/09/17 04:39:24 | 00,204,288 | ---- | C] (Microsoft Corporation)
iassam.dll -> C:\Windows\SysWow64\iassam.dll -> [2009/09/17 04:39:24 | 00,182,272 | ---- | C] (Microsoft Corporation)
scrobj.dll -> C:\Windows\SysWow64\scrobj.dll -> [2009/09/17 04:39:24 | 00,180,224 | ---- | C] (Microsoft Corporation)
spp.dll -> C:\Windows\SysWow64\spp.dll -> [2009/09/17 04:39:24 | 00,142,336 | ---- | C] (Microsoft Corporation)
iashlpr.dll -> C:\Windows\SysNative\iashlpr.dll -> [2009/09/17 04:39:24 | 00,085,504 | ---- | C] (Microsoft Corporation)
PSHED.DLL -> C:\Windows\SysNative\PSHED.DLL -> [2009/09/17 04:39:24 | 00,055,272 | ---- | C] (Microsoft Corporation)
kdcom.dll -> C:\Windows\SysNative\kdcom.dll -> [2009/09/17 04:39:24 | 00,019,432 | ---- | C] (Microsoft Corporation)
autoconv.exe -> C:\Windows\SysNative\autoconv.exe -> [2009/09/17 04:39:23 | 00,750,592 | ---- | C] (Microsoft Corporation)
msfeeds.dll -> C:\Windows\SysNative\msfeeds.dll -> [2009/09/17 04:39:23 | 00,580,608 | ---- | C] (Microsoft Corporation)
iedkcs32.dll -> C:\Windows\SysNative\iedkcs32.dll -> [2009/09/17 04:39:23 | 00,480,256 | ---- | C] (Microsoft Corporation)
imkr80.ime -> C:\Windows\SysWow64\imkr80.ime -> [2009/09/17 04:39:23 | 00,413,696 | ---- | C] (Microsoft Corporation)
rasapi32.dll -> C:\Windows\SysNative\rasapi32.dll -> [2009/09/17 04:39:23 | 00,337,408 | ---- | C] (Microsoft Corporation)
pciidex.sys -> C:\Windows\SysNative\drivers\pciidex.sys -> [2009/09/17 04:39:23 | 00,049,640 | ---- | C] (Microsoft Corporation)
mssprxy.dll -> C:\Windows\SysNative\mssprxy.dll -> [2009/09/17 04:39:23 | 00,040,448 | ---- | C] (Microsoft Corporation)
rtutils.dll -> C:\Windows\SysWow64\rtutils.dll -> [2009/09/17 04:39:23 | 00,036,352 | ---- | C] (Microsoft Corporation)
onex.dll -> C:\Windows\SysNative\onex.dll -> [2009/09/17 04:39:22 | 01,740,288 | ---- | C] (Microsoft Corporation)
autochk.exe -> C:\Windows\SysNative\autochk.exe -> [2009/09/17 04:39:22 | 00,734,720 | ---- | C] (Microsoft Corporation)
diskraid.exe -> C:\Windows\SysNative\diskraid.exe -> [2009/09/17 04:39:22 | 00,308,224 | ---- | C] (Microsoft Corporation)
rastls.dll -> C:\Windows\SysNative\rastls.dll -> [2009/09/17 04:39:22 | 00,281,088 | ---- | C] (Microsoft Corporation)
taskcomp.dll -> C:\Windows\SysWow64\taskcomp.dll -> [2009/09/17 04:39:22 | 00,270,336 | ---- | C] (Microsoft Corporation)
ntprint.dll -> C:\Windows\SysNative\ntprint.dll -> [2009/09/17 04:39:22 | 00,257,024 | ---- | C] (Microsoft Corporation)
ntmarta.dll -> C:\Windows\SysNative\ntmarta.dll -> [2009/09/17 04:39:22 | 00,159,232 | ---- | C] (Microsoft Corporation)
ecache.sys -> C:\Windows\SysNative\drivers\ecache.sys -> [2009/09/17 04:39:22 | 00,155,112 | ---- | C] (Microsoft Corporation)
samlib.dll -> C:\Windows\SysNative\samlib.dll -> [2009/09/17 04:39:22 | 00,099,328 | ---- | C] (Microsoft Corporation)
mpr.dll -> C:\Windows\SysNative\mpr.dll -> [2009/09/17 04:39:22 | 00,084,992 | ---- | C] (Microsoft Corporation)
volmgr.sys -> C:\Windows\SysNative\drivers\volmgr.sys -> [2009/09/17 04:39:22 | 00,067,048 | ---- | C] (Microsoft Corporation)
inetcpl.cpl -> C:\Windows\SysNative\inetcpl.cpl -> [2009/09/17 04:39:21 | 02,079,744 | ---- | C] (Microsoft Corporation)
WMVENCOD.DLL -> C:\Windows\SysNative\WMVENCOD.DLL -> [2009/09/17 04:39:21 | 01,891,840 | ---- | C] (Microsoft Corporation)
printui.dll -> C:\Windows\SysWow64\printui.dll -> [2009/09/17 04:39:21 | 00,869,888 | ---- | C] (Microsoft Corporation)
autochk.exe -> C:\Windows\SysWow64\autochk.exe -> [2009/09/17 04:39:21 | 00,643,072 | ---- | C] (Microsoft Corporation)
portcls.sys -> C:\Windows\SysNative\drivers\portcls.sys -> [2009/09/17 04:39:21 | 00,218,112 | ---- | C] (Microsoft Corporation)
srvsvc.dll -> C:\Windows\SysNative\srvsvc.dll -> [2009/09/17 04:39:21 | 00,176,640 | ---- | C] (Microsoft Corporation)
iasnap.dll -> C:\Windows\SysWow64\iasnap.dll -> [2009/09/17 04:39:21 | 00,150,528 | ---- | C] (Microsoft Corporation)
iassvcs.dll -> C:\Windows\SysNative\iassvcs.dll -> [2009/09/17 04:39:21 | 00,088,576 | ---- | C] (Microsoft Corporation)
WMVDECOD.DLL -> C:\Windows\SysWow64\WMVDECOD.DLL -> [2009/09/17 04:39:20 | 01,548,288 | ---- | C] (Microsoft Corporation)
PerfCenterCPL.dll -> C:\Windows\SysNative\PerfCenterCPL.dll -> [2009/09/17 04:39:20 | 01,444,352 | ---- | C] (Microsoft Corporation)
autoconv.exe -> C:\Windows\SysWow64\autoconv.exe -> [2009/09/17 04:39:20 | 00,656,896 | ---- | C] (Microsoft Corporation)
psisdecd.dll -> C:\Windows\SysNative\psisdecd.dll -> [2009/09/17 04:39:20 | 00,375,808 | ---- | C] (Microsoft Corporation)
scecli.dll -> C:\Windows\SysNative\scecli.dll -> [2009/09/17 04:39:20 | 00,235,520 | ---- | C] (Microsoft Corporation)
profsvc.dll -> C:\Windows\SysNative\profsvc.dll -> [2009/09/17 04:39:20 | 00,178,176 | ---- | C] (Microsoft Corporation)
rpchttp.dll -> C:\Windows\SysNative\rpchttp.dll -> [2009/09/17 04:39:20 | 00,164,352 | ---- | C] (Microsoft Corporation)
cscript.exe -> C:\Windows\SysWow64\cscript.exe -> [2009/09/17 04:39:20 | 00,135,168 | ---- | C] (Microsoft Corporation)
basecsp.dll -> C:\Windows\SysWow64\basecsp.dll -> [2009/09/17 04:39:20 | 00,130,024 | ---- | C] (Microsoft Corporation)
onex.dll -> C:\Windows\SysWow64\onex.dll -> [2009/09/17 04:39:19 | 01,541,120 | ---- | C] (Microsoft Corporation)
iphlpsvc.dll -> C:\Windows\SysNative\iphlpsvc.dll -> [2009/09/17 04:39:19 | 00,223,744 | ---- | C] (Microsoft Corporation)
basecsp.dll -> C:\Windows\SysNative\basecsp.dll -> [2009/09/17 04:39:19 | 00,153,064 | ---- | C] (Microsoft Corporation)
userenv.dll -> C:\Windows\SysWow64\userenv.dll -> [2009/09/17 04:39:19 | 00,108,544 | ---- | C] (Microsoft Corporation)
audiodg.exe -> C:\Windows\SysWow64\audiodg.exe -> [2009/09/17 04:39:19 | 00,088,576 | ---- | C] (Microsoft Corporation)
iasacct.dll -> C:\Windows\SysNative\iasacct.dll -> [2009/09/17 04:39:19 | 00,072,704 | ---- | C] (Microsoft Corporation)
Dumpata.sys -> C:\Windows\SysNative\drivers\Dumpata.sys -> [2009/09/17 04:39:19 | 00,029,656 | ---- | C] (Microsoft Corporation)
kdusb.dll -> C:\Windows\SysNative\kdusb.dll -> [2009/09/17 04:39:19 | 00,022,504 | ---- | C] (Microsoft Corporation)
networkmap.dll -> C:\Windows\SysNative\networkmap.dll -> [2009/09/17 04:39:18 | 03,235,328 | ---- | C] (Microsoft Corporation)
themecpl.dll -> C:\Windows\SysNative\themecpl.dll -> [2009/09/17 04:39:18 | 01,301,504 | ---- | C] (Microsoft Corporation)
mswsock.dll -> C:\Windows\SysWow64\mswsock.dll -> [2009/09/17 04:39:18 | 00,223,232 | ---- | C] (Microsoft Corporation)
osk.exe -> C:\Windows\SysWow64\osk.exe -> [2009/09/17 04:39:18 | 00,182,272 | ---- | C] (Microsoft Corporation)
wusa.exe -> C:\Windows\SysNative\wusa.exe -> [2009/09/17 04:39:18 | 00,147,968 | ---- | C] (Microsoft Corporation)
powrprof.dll -> C:\Windows\SysNative\powrprof.dll -> [2009/09/17 04:39:18 | 00,123,392 | ---- | C] (Microsoft Corporation)
dwm.exe -> C:\Windows\SysNative\dwm.exe -> [2009/09/17 04:39:18 | 00,098,304 | ---- | C] (Microsoft Corporation)
logman.exe -> C:\Windows\SysNative\logman.exe -> [2009/09/17 04:39:18 | 00,070,144 | ---- | C] (Microsoft Corporation)
atapi.sys -> C:\Windows\SysNative\drivers\atapi.sys -> [2009/09/17 04:39:18 | 00,020,952 | ---- | C] (Microsoft Corporation)
spldr.sys -> C:\Windows\SysNative\drivers\spldr.sys -> [2009/09/17 04:39:18 | 00,019,432 | ---- | C] (Microsoft Corporation)
wpccpl.dll -> C:\Windows\SysNative\wpccpl.dll -> [2009/09/17 04:39:17 | 01,882,624 | ---- | C] (Microsoft Corporation)
mspaint.exe -> C:\Windows\SysNative\mspaint.exe -> [2009/09/17 04:39:17 | 00,593,408 | ---- | C] (Microsoft Corporation)
iertutil.dll -> C:\Windows\SysNative\iertutil.dll -> [2009/09/17 04:39:17 | 00,375,808 | ---- | C] (Microsoft Corporation)
RelMon.dll -> C:\Windows\SysWow64\RelMon.dll -> [2009/09/17 04:39:17 | 00,340,992 | ---- | C] (Microsoft Corporation)
wow64win.dll -> C:\Windows\SysNative\wow64win.dll -> [2009/09/17 04:39:17 | 00,301,568 | ---- | C] (Microsoft Corporation)
regsvc.dll -> C:\Windows\SysNative\regsvc.dll -> [2009/09/17 04:39:17 | 00,206,848 | ---- | C] (Microsoft Corporation)
winmm.dll -> C:\Windows\SysWow64\winmm.dll -> [2009/09/17 04:39:17 | 00,189,952 | ---- | C] (Microsoft Corporation)
ks.sys -> C:\Windows\SysNative\drivers\ks.sys -> [2009/09/17 04:39:17 | 00,188,416 | ---- | C] (Microsoft Corporation)
exfat.sys -> C:\Windows\SysNative\drivers\exfat.sys -> [2009/09/17 04:39:17 | 00,187,904 | ---- | C] (Microsoft Corporation)
dnsrslvr.dll -> C:\Windows\SysNative\dnsrslvr.dll -> [2009/09/17 04:39:17 | 00,117,760 | ---- | C] (Microsoft Corporation)
rdpencom.dll -> C:\Windows\SysWow64\rdpencom.dll -> [2009/09/17 04:39:16 | 00,612,864 | ---- | C] (Microsoft Corporation)
msftedit.dll -> C:\Windows\SysWow64\msftedit.dll -> [2009/09/17 04:39:16 | 00,564,224 | ---- | C] (Microsoft Corporation)
scesrv.dll -> C:\Windows\SysNative\scesrv.dll -> [2009/09/17 04:39:16 | 00,399,360 | ---- | C] (Microsoft Corporation)
tapisrv.dll -> C:\Windows\SysNative\tapisrv.dll -> [2009/09/17 04:39:16 | 00,318,976 | ---- | C] (Microsoft Corporation)
Faultrep.dll -> C:\Windows\SysNative\Faultrep.dll -> [2009/09/17 04:39:16 | 00,176,640 | ---- | C] (Microsoft Corporation)
WinSCard.dll -> C:\Windows\SysWow64\WinSCard.dll -> [2009/09/17 04:39:16 | 00,115,712 | ---- | C] (Microsoft Corporation)
wsepno.dll -> C:\Windows\SysNative\wsepno.dll -> [2009/09/17 04:39:16 | 00,024,064 | ---- | C] (Microsoft Corporation)
inetcpl.cpl -> C:\Windows\SysWow64\inetcpl.cpl -> [2009/09/17 04:39:15 | 01,827,840 | ---- | C] (Microsoft Corporation)
WerFaultSecure.exe -> C:\Windows\SysWow64\WerFaultSecure.exe -> [2009/09/17 04:39:15 | 00,860,160 | ---- | C] (Microsoft Corporation)
Utilman.exe -> C:\Windows\SysWow64\Utilman.exe -> [2009/09/17 04:39:15 | 00,638,976 | ---- | C] (Microsoft Corporation)
stobject.dll -> C:\Windows\SysWow64\stobject.dll -> [2009/09/17 04:39:15 | 00,586,752 | ---- | C] (Microsoft Corporation)
diskraid.exe -> C:\Windows\SysWow64\diskraid.exe -> [2009/09/17 04:39:15 | 00,230,912 | ---- | C] (Microsoft Corporation)
WerFault.exe -> C:\Windows\SysWow64\WerFault.exe -> [2009/09/17 04:39:15 | 00,217,088 | ---- | C] (Microsoft Corporation)
mfplat.dll -> C:\Windows\SysWow64\mfplat.dll -> [2009/09/17 04:39:15 | 00,208,896 | ---- | C] (Microsoft Corporation)
offfilt.dll -> C:\Windows\SysWow64\offfilt.dll -> [2009/09/17 04:39:15 | 00,194,560 | ---- | C] (Microsoft Corporation)
secproc_ssp_isv.dll -> C:\Windows\SysWow64\secproc_ssp_isv.dll -> [2009/09/17 04:39:15 | 00,152,576 | ---- | C] (Microsoft Corporation)
secproc_ssp.dll -> C:\Windows\SysWow64\secproc_ssp.dll -> [2009/09/17 04:39:15 | 00,152,064 | ---- | C] (Microsoft Corporation)
authz.dll -> C:\Windows\SysNative\authz.dll -> [2009/09/17 04:39:15 | 00,143,360 | ---- | C] (Microsoft Corporation)
mstlsapi.dll -> C:\Windows\SysNative\mstlsapi.dll -> [2009/09/17 04:39:15 | 00,139,264 | ---- | C] (Microsoft Corporation)
prnntfy.dll -> C:\Windows\SysWow64\prnntfy.dll -> [2009/09/17 04:39:14 | 00,551,936 | ---- | C] (Microsoft Corporation)
AudioEng.dll -> C:\Windows\SysWow64\AudioEng.dll -> [2009/09/17 04:39:14 | 00,396,800 | ---- | C] (Microsoft Corporation)
mscms.dll -> C:\Windows\SysWow64\mscms.dll -> [2009/09/17 04:39:14 | 00,391,680 | ---- | C] (Microsoft Corporation)
shsvcs.dll -> C:\Windows\SysNative\shsvcs.dll -> [2009/09/17 04:39:14 | 00,301,568 | ---- | C] (Microsoft Corporation)
SndVol.exe -> C:\Windows\SysWow64\SndVol.exe -> [2009/09/17 04:39:14 | 00,197,632 | ---- | C] (Microsoft Corporation)
msnetobj.dll -> C:\Windows\SysWow64\msnetobj.dll -> [2009/09/17 04:39:14 | 00,179,712 | ---- | C] (Microsoft Corporation)
apphelp.dll -> C:\Windows\SysWow64\apphelp.dll -> [2009/09/17 04:39:14 | 00,171,008 | ---- | C] (Microsoft Corporation)
wscript.exe -> C:\Windows\SysWow64\wscript.exe -> [2009/09/17 04:39:14 | 00,155,648 | ---- | C] (Microsoft Corporation)
odbccp32.dll -> C:\Windows\SysWow64\odbccp32.dll -> [2009/09/17 04:39:14 | 00,114,688 | ---- | C] (Microsoft Corporation)
adsmsext.dll -> C:\Windows\SysWow64\adsmsext.dll -> [2009/09/17 04:39:14 | 00,075,264 | ---- | C] (Microsoft Corporation)
wsnmp32.dll -> C:\Windows\SysNative\wsnmp32.dll -> [2009/09/17 04:39:14 | 00,061,952 | ---- | C] (Microsoft Corporation)
TSTheme.exe -> C:\Windows\SysNative\TSTheme.exe -> [2009/09/17 04:39:14 | 00,045,568 | ---- | C] (Microsoft Corporation)
usercpl.dll -> C:\Windows\SysNative\usercpl.dll -> [2009/09/17 04:39:13 | 01,279,488 | ---- | C] (Microsoft Corporation)
systemcpl.dll -> C:\Windows\SysNative\systemcpl.dll -> [2009/09/17 04:39:13 | 00,995,328 | ---- | C] (Microsoft Corporation)
cryptui.dll -> C:\Windows\SysWow64\cryptui.dll -> [2009/09/17 04:39:13 | 00,971,264 | ---- | C] (Microsoft Corporation)
dsound.dll -> C:\Windows\SysWow64\dsound.dll -> [2009/09/17 04:39:13 | 00,444,416 | ---- | C] (Microsoft Corporation)
iepeers.dll -> C:\Windows\SysNative\iepeers.dll -> [2009/09/17 04:39:13 | 00,250,368 | ---- | C] (Microsoft Corporation)
dot3svc.dll -> C:\Windows\SysNative\dot3svc.dll -> [2009/09/17 04:39:13 | 00,208,896 | ---- | C] (Microsoft Corporation)
wshom.ocx -> C:\Windows\SysNative\wshom.ocx -> [2009/09/17 04:39:13 | 00,144,384 | ---- | C] (Microsoft Corporation)
Kswdmcap.ax -> C:\Windows\SysNative\Kswdmcap.ax -> [2009/09/17 04:39:13 | 00,115,200 | ---- | C] (Microsoft Corporation)
console.dll -> C:\Windows\SysNative\console.dll -> [2009/09/17 04:39:13 | 00,104,448 | ---- | C] (Microsoft Corporation)
ulib.dll -> C:\Windows\SysWow64\ulib.dll -> [2009/09/17 04:39:13 | 00,099,840 | ---- | C] (Microsoft Corporation)
IPHLPAPI.DLL -> C:\Windows\SysWow64\IPHLPAPI.DLL -> [2009/09/17 04:39:13 | 00,091,648 | ---- | C] (Microsoft Corporation)
iasdatastore.dll -> C:\Windows\SysWow64\iasdatastore.dll -> [2009/09/17 04:39:13 | 00,047,104 | ---- | C] (Microsoft Corporation)
wer.dll -> C:\Windows\SysNative\wer.dll -> [2009/09/17 04:39:12 | 01,110,528 | ---- | C] (Microsoft Corporation)
timedate.cpl -> C:\Windows\SysNative\timedate.cpl -> [2009/09/17 04:39:12 | 00,881,152 | ---- | C] (Microsoft Corporation)
ipsecsnp.dll -> C:\Windows\SysWow64\ipsecsnp.dll -> [2009/09/17 04:39:12 | 00,759,296 | ---- | C] (Microsoft Corporation)
wlangpui.dll -> C:\Windows\SysWow64\wlangpui.dll -> [2009/09/17 04:39:12 | 00,399,360 | ---- | C] (Microsoft Corporation)
zipfldr.dll -> C:\Windows\SysNative\zipfldr.dll -> [2009/09/17 04:39:12 | 00,387,072 | ---- | C] (Microsoft Corporation)
wow64.dll -> C:\Windows\SysNative\wow64.dll -> [2009/09/17 04:39:12 | 00,234,496 | ---- | C] (Microsoft Corporation)
wscntfy.dll -> C:\Windows\SysWow64\wscntfy.dll -> [2009/09/17 04:39:12 | 00,223,744 | ---- | C] (Microsoft Corporation)
pnpsetup.dll -> C:\Windows\SysWow64\pnpsetup.dll -> [2009/09/17 04:39:12 | 00,181,760 | ---- | C] (Microsoft Corporation)
odbccp32.dll -> C:\Windows\SysNative\odbccp32.dll -> [2009/09/17 04:39:12 | 00,126,976 | ---- | C] (Microsoft Corporation)
rastapi.dll -> C:\Windows\SysNative\rastapi.dll -> [2009/09/17 04:39:12 | 00,081,408 | ---- | C] (Microsoft Corporation)
rastapi.dll -> C:\Windows\SysWow64\rastapi.dll -> [2009/09/17 04:39:12 | 00,069,632 | ---- | C] (Microsoft Corporation)
fdProxy.dll -> C:\Windows\SysWow64\fdProxy.dll -> [2009/09/17 04:39:12 | 00,024,064 | ---- | C] (Microsoft Corporation)
themeui.dll -> C:\Windows\SysNative\themeui.dll -> [2009/09/17 04:39:11 | 00,688,640 | ---- | C] (Microsoft Corporation)
bcrypt.dll -> C:\Windows\SysNative\bcrypt.dll -> [2009/09/17 04:39:11 | 00,306,688 | ---- | C] (Microsoft Corporation)
rastls.dll -> C:\Windows\SysWow64\rastls.dll -> [2009/09/17 04:39:11 | 00,244,224 | ---- | C] (Microsoft Corporation)
diskpart.exe -> C:\Windows\SysWow64\diskpart.exe -> [2009/09/17 04:39:11 | 00,119,808 | ---- | C] (Microsoft Corporation)
mrxsmb20.sys -> C:\Windows\SysNative\drivers\mrxsmb20.sys -> [2009/09/17 04:39:11 | 00,105,984 | ---- | C] (Microsoft Corporation)
tdx.sys -> C:\Windows\SysNative\drivers\tdx.sys -> [2009/09/17 04:39:11 | 00,094,720 | ---- | C] (Microsoft Corporation)
gpapi.dll -> C:\Windows\SysWow64\gpapi.dll -> [2009/09/17 04:39:11 | 00,075,264 | ---- | C] (Microsoft Corporation)
iashlpr.dll -> C:\Windows\SysWow64\iashlpr.dll -> [2009/09/17 04:39:11 | 00,070,656 | ---- | C] (Microsoft Corporation)
perfdisk.dll -> C:\Windows\SysNative\perfdisk.dll -> [2009/09/17 04:39:11 | 00,035,328 | ---- | C] (Microsoft Corporation)
tsbyuv.dll -> C:\Windows\SysNative\tsbyuv.dll -> [2009/09/17 04:39:11 | 00,014,336 | ---- | C] (Microsoft Corporation)
WMVENCOD.DLL -> C:\Windows\SysWow64\WMVENCOD.DLL -> [2009/09/17 04:39:10 | 01,575,936 | ---- | C] (Microsoft Corporation)
powercpl.dll -> C:\Windows\SysNative\powercpl.dll -> [2009/09/17 04:39:10 | 00,898,560 | ---- | C] (Microsoft Corporation)
wpcao.dll -> C:\Windows\SysNative\wpcao.dll -> [2009/09/17 04:39:10 | 00,690,688 | ---- | C] (Microsoft Corporation)
autoplay.dll -> C:\Windows\SysNative\autoplay.dll -> [2009/09/17 04:39:10 | 00,667,648 | ---- | C] (Microsoft Corporation)
vdsdyn.dll -> C:\Windows\SysWow64\vdsdyn.dll -> [2009/09/17 04:39:10 | 00,507,904 | ---- | C] (Microsoft Corporation)
IKEEXT.DLL -> C:\Windows\SysNative\IKEEXT.DLL -> [2009/09/17 04:39:10 | 00,454,656 | ---- | C] (Microsoft Corporation)
iepeers.dll -> C:\Windows\SysWow64\iepeers.dll -> [2009/09/17 04:39:10 | 00,193,024 | ---- | C] (Microsoft Corporation)
wscript.exe -> C:\Windows\SysNative\wscript.exe -> [2009/09/17 04:39:10 | 00,166,912 | ---- | C] (Microsoft Corporation)
newdev.exe -> C:\Windows\SysNative\newdev.exe -> [2009/09/17 04:39:10 | 00,075,776 | ---- | C] (Microsoft Corporation)
logman.exe -> C:\Windows\SysWow64\logman.exe -> [2009/09/17 04:39:10 | 00,057,344 | ---- | C] (Microsoft Corporation)
pcaui.dll -> C:\Windows\SysNative\pcaui.dll -> [2009/09/17 04:39:09 | 00,617,984 | ---- | C] (Microsoft Corporation)
imkr80.ime -> C:\Windows\SysNative\imkr80.ime -> [2009/09/17 04:39:09 | 00,437,248 | ---- | C] (Microsoft Corporation)
rasapi32.dll -> C:\Windows\SysWow64\rasapi32.dll -> [2009/09/17 04:39:09 | 00,286,720 | ---- | C] (Microsoft Corporation)
ntprint.dll -> C:\Windows\SysWow64\ntprint.dll -> [2009/09/17 04:39:09 | 00,216,064 | ---- | C] (Microsoft Corporation)
SmartcardCredentialProvider.dll -> C:\Windows\SysNative\SmartcardCredentialProvider.dll -> [2009/09/17 04:39:09 | 00,161,280 | ---- | C] (Microsoft Corporation)
mscorier.dll -> C:\Windows\SysWow64\mscorier.dll -> [2009/09/17 04:39:09 | 00,155,456 | ---- | C] (Microsoft Corporation)
mscorier.dll -> C:\Windows\SysNative\mscorier.dll -> [2009/09/17 04:39:09 | 00,154,960 | ---- | C] (Microsoft Corporation)
DeviceEject.exe -> C:\Windows\SysNative\DeviceEject.exe -> [2009/09/17 04:39:09 | 00,026,624 | ---- | C] (Microsoft Corporation)
msisip.dll -> C:\Windows\SysNative\msisip.dll -> [2009/09/17 04:39:09 | 00,022,528 | ---- | C] (Microsoft Corporation)
sud.dll -> C:\Windows\SysNative\sud.dll -> [2009/09/17 04:39:08 | 01,382,912 | ---- | C] (Microsoft Corporation)
slcc.dll -> C:\Windows\SysNative\slcc.dll -> [2009/09/17 04:39:08 | 00,810,496 | ---- | C] (Microsoft Corporation)
zipfldr.dll -> C:\Windows\SysWow64\zipfldr.dll -> [2009/09/17 04:39:08 | 00,342,528 | ---- | C] (Microsoft Corporation)
modemui.dll -> C:\Windows\SysNative\modemui.dll -> [2009/09/17 04:39:08 | 00,302,592 | ---- | C] (Microsoft Corporation)
iasrad.dll -> C:\Windows\SysWow64\iasrad.dll -> [2009/09/17 04:39:08 | 00,158,208 | ---- | C] (Microsoft Corporation)
wusa.exe -> C:\Windows\SysWow64\wusa.exe -> [2009/09/17 04:39:08 | 00,140,800 | ---- | C] (Microsoft Corporation)
regapi.dll -> C:\Windows\SysNative\regapi.dll -> [2009/09/17 04:39:08 | 00,089,088 | ---- | C] (Microsoft Corporation)
hdwwiz.exe -> C:\Windows\SysNative\hdwwiz.exe -> [2009/09/17 04:39:08 | 00,080,896 | ---- | C] (Microsoft Corporation)
findstr.exe -> C:\Windows\SysWow64\findstr.exe -> [2009/09/17 04:39:08 | 00,060,928 | ---- | C] (Microsoft Corporation)
wshbth.dll -> C:\Windows\SysNative\wshbth.dll -> [2009/09/17 04:39:08 | 00,044,032 | ---- | C] (Microsoft Corporation)
accessibilitycpl.dll -> C:\Windows\SysNative\accessibilitycpl.dll -> [2009/09/17 04:39:07 | 02,680,832 | ---- | C] (Microsoft Corporation)
netcenter.dll -> C:\Windows\SysWow64\netcenter.dll -> [2009/09/17 04:39:07 | 02,225,664 | ---- | C] (Microsoft Corporation)
webcheck.dll -> C:\Windows\SysWow64\webcheck.dll -> [2009/09/17 04:39:07 | 00,233,984 | ---- | C] (Microsoft Corporation)
vdsutil.dll -> C:\Windows\SysNative\vdsutil.dll -> [2009/09/17 04:39:07 | 00,157,696 | ---- | C] (Microsoft Corporation)
ulib.dll -> C:\Windows\SysNative\ulib.dll -> [2009/09/17 04:39:07 | 00,128,000 | ---- | C] (Microsoft Corporation)
wshext.dll -> C:\Windows\SysWow64\wshext.dll -> [2009/09/17 04:39:07 | 00,090,112 | ---- | C] (Microsoft Corporation)
feclient.dll -> C:\Windows\SysNative\feclient.dll -> [2009/09/17 04:39:07 | 00,068,608 | ---- | C] (Microsoft Corporation)
usbehci.sys -> C:\Windows\SysNative\drivers\usbehci.sys -> [2009/09/17 04:39:07 | 00,049,664 | ---- | C] (Microsoft Corporation)
chtbrkr.dll -> C:\Windows\SysNative\chtbrkr.dll -> [2009/09/17 04:39:06 | 06,100,480 | ---- | C] (Microsoft Corporation)
wer.dll -> C:\Windows\SysWow64\wer.dll -> [2009/09/17 04:39:06 | 00,876,032 | ---- | C] (Microsoft Corporation)
rasdlg.dll -> C:\Windows\SysWow64\rasdlg.dll -> [2009/09/17 04:39:06 | 00,825,856 | ---- | C] (Microsoft Corporation)
mstsc.exe -> C:\Windows\SysNative\mstsc.exe -> [2009/09/17 04:39:06 | 00,731,648 | ---- | C] (Microsoft Corporation)
apphelp.dll -> C:\Windows\SysNative\apphelp.dll -> [2009/09/17 04:39:06 | 00,200,704 | ---- | C] (Microsoft Corporation)
imm32.dll -> C:\Windows\SysNative\imm32.dll -> [2009/09/17 04:39:06 | 00,163,840 | ---- | C] (Microsoft Corporation)
cscript.exe -> C:\Windows\SysNative\cscript.exe -> [2009/09/17 04:39:06 | 00,147,968 | ---- | C] (Microsoft Corporation)
wshext.dll -> C:\Windows\SysNative\wshext.dll -> [2009/09/17 04:39:06 | 00,101,888 | ---- | C] (Microsoft Corporation)
pacer.sys -> C:\Windows\SysNative\drivers\pacer.sys -> [2009/09/17 04:39:06 | 00,094,208 | ---- | C] (Microsoft Corporation)
iassvcs.dll -> C:\Windows\SysWow64\iassvcs.dll -> [2009/09/17 04:39:06 | 00,076,288 | ---- | C] (Microsoft Corporation)
themecpl.dll -> C:\Windows\SysWow64\themecpl.dll -> [2009/09/17 04:39:05 | 01,152,000 | ---- | C] (Microsoft Corporation)
timedate.cpl -> C:\Windows\SysWow64\timedate.cpl -> [2009/09/17 04:39:05 | 00,714,240 | ---- | C] (Microsoft Corporation)
pnpui.dll -> C:\Windows\SysNative\pnpui.dll -> [2009/09/17 04:39:05 | 00,691,712 | ---- | C] (Microsoft Corporation)
riched20.dll -> C:\Windows\SysNative\riched20.dll -> [2009/09/17 04:39:05 | 00,606,208 | ---- | C] (Microsoft Corporation)
ncryptui.dll -> C:\Windows\SysNative\ncryptui.dll -> [2009/09/17 04:39:05 | 00,589,312 | ---- | C] (Microsoft Corporation)
udfs.sys -> C:\Windows\SysNative\drivers\udfs.sys -> [2009/09/17 04:39:05 | 00,299,008 | ---- | C] (Microsoft Corporation)
tcpmon.dll -> C:\Windows\SysNative\tcpmon.dll -> [2009/09/17 04:39:05 | 00,168,960 | ---- | C] (Microsoft Corporation)
wsnmp32.dll -> C:\Windows\SysWow64\wsnmp32.dll -> [2009/09/17 04:39:05 | 00,050,688 | ---- | C] (Microsoft Corporation)
slcc.dll -> C:\Windows\SysWow64\slcc.dll -> [2009/09/17 04:39:04 | 00,777,216 | ---- | C] (Microsoft Corporation)
rasppp.dll -> C:\Windows\SysNative\rasppp.dll -> [2009/09/17 04:39:04 | 00,306,176 | ---- | C] (Microsoft Corporation)
scansetting.dll -> C:\Windows\SysWow64\scansetting.dll -> [2009/09/17 04:39:04 | 00,245,760 | ---- | C] (Microsoft Corporation)
msutb.dll -> C:\Windows\SysWow64\msutb.dll -> [2009/09/17 04:39:04 | 00,163,328 | ---- | C] (Microsoft Corporation)
wshom.ocx -> C:\Windows\SysWow64\wshom.ocx -> [2009/09/17 04:39:04 | 00,135,168 | ---- | C] (Microsoft Corporation)
ntmarta.dll -> C:\Windows\SysWow64\ntmarta.dll -> [2009/09/17 04:39:04 | 00,121,344 | ---- | C] (Microsoft Corporation)
wanarp.sys -> C:\Windows\SysNative\drivers\wanarp.sys -> [2009/09/17 04:39:04 | 00,086,528 | ---- | C] (Microsoft Corporation)
mstlsapi.dll -> C:\Windows\SysWow64\mstlsapi.dll -> [2009/09/17 04:39:04 | 00,084,992 | ---- | C] (Microsoft Corporation)
iasads.dll -> C:\Windows\SysWow64\iasads.dll -> [2009/09/17 04:39:04 | 00,057,344 | ---- | C] (Microsoft Corporation)
dataclen.dll -> C:\Windows\SysNative\dataclen.dll -> [2009/09/17 04:39:04 | 00,048,640 | ---- | C] (Microsoft Corporation)
mssprxy.dll -> C:\Windows\SysWow64\mssprxy.dll -> [2009/09/17 04:39:04 | 00,033,280 | ---- | C] (Microsoft Corporation)
tsbyuv.dll -> C:\Windows\SysWow64\tsbyuv.dll -> [2009/09/17 04:39:04 | 00,012,288 | ---- | C] (Microsoft Corporation)
networkmap.dll -> C:\Windows\SysWow64\networkmap.dll -> [2009/09/17 04:39:03 | 03,072,000 | ---- | C] (Microsoft Corporation)
mstsc.exe -> C:\Windows\SysWow64\mstsc.exe -> [2009/09/17 04:39:03 | 00,678,400 | ---- | C] (Microsoft Corporation)
srcore.dll -> C:\Windows\SysNative\srcore.dll -> [2009/09/17 04:39:03 | 00,474,624 | ---- | C] (Microsoft Corporation)
rasplap.dll -> C:\Windows\SysNative\rasplap.dll -> [2009/09/17 04:39:03 | 00,389,632 | ---- | C] (Microsoft Corporation)
ieaksie.dll -> C:\Windows\SysNative\ieaksie.dll -> [2009/09/17 04:39:03 | 00,268,288 | ---- | C] (Microsoft Corporation)
SndVolSSO.dll -> C:\Windows\SysNative\SndVolSSO.dll -> [2009/09/17 04:39:03 | 00,177,664 | ---- | C] (Microsoft Corporation)
powrprof.dll -> C:\Windows\SysWow64\powrprof.dll -> [2009/09/17 04:39:03 | 00,098,816 | ---- | C] (Microsoft Corporation)
iasacct.dll -> C:\Windows\SysWow64\iasacct.dll -> [2009/09/17 04:39:03 | 00,058,880 | ---- | C] (Microsoft Corporation)
ifmon.dll -> C:\Windows\SysNative\ifmon.dll -> [2009/09/17 04:39:03 | 00,036,352 | ---- | C] (Microsoft Corporation)
icardres.dll -> C:\Windows\SysWow64\icardres.dll -> [2009/09/17 04:39:03 | 00,009,048 | ---- | C] (Microsoft Corporation)
icardres.dll -> C:\Windows\SysNative\icardres.dll -> [2009/09/17 04:39:03 | 00,009,048 | ---- | C] (Microsoft Corporation)
connect.dll -> C:\Windows\SysWow64\connect.dll -> [2009/09/17 04:39:02 | 01,645,568 | ---- | C] (Microsoft Corporation)
PerfCenterCPL.dll -> C:\Windows\SysWow64\PerfCenterCPL.dll -> [2009/09/17 04:39:02 | 01,248,768 | ---- | C] (Microsoft Corporation)
powercpl.dll -> C:\Windows\SysWow64\powercpl.dll -> [2009/09/17 04:39:02 | 00,723,968 | ---- | C] (Microsoft Corporation)
WMVXENCD.DLL -> C:\Windows\SysNative\WMVXENCD.DLL -> [2009/09/17 04:39:02 | 00,622,592 | ---- | C] (Microsoft Corporation)
qedit.dll -> C:\Windows\SysNative\qedit.dll -> [2009/09/17 04:39:02 | 00,619,008 | ---- | C] (Microsoft Corporation)
wlangpui.dll -> C:\Windows\SysNative\wlangpui.dll -> [2009/09/17 04:39:02 | 00,489,984 | ---- | C] (Microsoft Corporation)
qdvd.dll -> C:\Windows\SysNative\qdvd.dll -> [2009/09/17 04:39:02 | 00,352,256 | ---- | C] (Microsoft Corporation)
oleprn.dll -> C:\Windows\SysNative\oleprn.dll -> [2009/09/17 04:39:02 | 00,115,712 | ---- | C] (Microsoft Corporation)
authz.dll -> C:\Windows\SysWow64\authz.dll -> [2009/09/17 04:39:02 | 00,079,872 | ---- | C] (Microsoft Corporation)
newdev.exe -> C:\Windows\SysWow64\newdev.exe -> [2009/09/17 04:39:02 | 00,074,752 | ---- | C] (Microsoft Corporation)
cmmon32.exe -> C:\Windows\SysNative\cmmon32.exe -> [2009/09/17 04:39:02 | 00,052,224 | ---- | C] (Microsoft Corporation)
fc.exe -> C:\Windows\SysNative\fc.exe -> [2009/09/17 04:39:02 | 00,024,064 | ---- | C] (Microsoft Corporation)
kbdhid.sys -> C:\Windows\SysNative\drivers\kbdhid.sys -> [2009/09/17 04:39:02 | 00,022,528 | ---- | C] (Microsoft Corporation)
accessibilitycpl.dll -> C:\Windows\SysWow64\accessibilitycpl.dll -> [2009/09/17 04:39:01 | 02,515,968 | ---- | C] (Microsoft Corporation)
sud.dll -> C:\Windows\SysWow64\sud.dll -> [2009/09/17 04:39:01 | 01,224,192 | ---- | C] (Microsoft Corporation)
systemcpl.dll -> C:\Windows\SysWow64\systemcpl.dll -> [2009/09/17 04:39:01 | 00,842,240 | ---- | C] (Microsoft Corporation)
themeui.dll -> C:\Windows\SysWow64\themeui.dll -> [2009/09/17 04:39:01 | 00,615,424 | ---- | C] (Microsoft Corporation)
pcaui.dll -> C:\Windows\SysWow64\pcaui.dll -> [2009/09/17 04:39:01 | 00,464,384 | ---- | C] (Microsoft Corporation)
BFE.DLL -> C:\Windows\SysNative\BFE.DLL -> [2009/09/17 04:39:01 | 00,458,240 | ---- | C] (Microsoft Corporation)
thawbrkr.dll -> C:\Windows\SysNative\thawbrkr.dll -> [2009/09/17 04:39:01 | 00,317,440 | ---- | C] (Microsoft Corporation)
raschap.dll -> C:\Windows\SysNative\raschap.dll -> [2009/09/17 04:39:01 | 00,295,936 | ---- | C] (Microsoft Corporation)
scksp.dll -> C:\Windows\SysNative\scksp.dll -> [2009/09/17 04:39:01 | 00,186,880 | ---- | C] (Microsoft Corporation)
npfs.sys -> C:\Windows\SysNative\drivers\npfs.sys -> [2009/09/17 04:39:01 | 00,044,544 | ---- | C] (Microsoft Corporation)
hidserv.dll -> C:\Windows\SysNative\hidserv.dll -> [2009/09/17 04:39:01 | 00,024,064 | ---- | C] (Microsoft Corporation)
wscisvif.dll -> C:\Windows\SysNative\wscisvif.dll -> [2009/09/17 04:39:01 | 00,020,992 | ---- | C] (Microsoft Corporation)
usercpl.dll -> C:\Windows\SysWow64\usercpl.dll -> [2009/09/17 04:39:00 | 01,123,840 | ---- | C] (Microsoft Corporation)
autoplay.dll -> C:\Windows\SysWow64\autoplay.dll -> [2009/09/17 04:39:00 | 00,516,608 | ---- | C] (Microsoft Corporation)
qdvd.dll -> C:\Windows\SysWow64\qdvd.dll -> [2009/09/17 04:39:00 | 00,497,152 | ---- | C] (Microsoft Corporation)
samlib.dll -> C:\Windows\SysWow64\samlib.dll -> [2009/09/17 04:39:00 | 00,057,344 | ---- | C] (Microsoft Corporation)
mmci.dll -> C:\Windows\SysWow64\mmci.dll -> [2009/09/17 04:39:00 | 00,052,224 | ---- | C] (Microsoft Corporation)
rtutils.dll -> C:\Windows\SysNative\rtutils.dll -> [2009/09/17 04:39:00 | 00,050,688 | ---- | C] (Microsoft Corporation)
iaspolcy.dll -> C:\Windows\SysNative\iaspolcy.dll -> [2009/09/17 04:39:00 | 00,037,888 | ---- | C] (Microsoft Corporation)
spwinsat.dll -> C:\Windows\SysNative\spwinsat.dll -> [2009/09/17 04:39:00 | 00,013,824 | ---- | C] (Microsoft Corporation)
SyncCenter.dll -> C:\Windows\SysNative\SyncCenter.dll -> [2009/09/17 04:38:59 | 02,575,360 | ---- | C] (Microsoft Corporation)
wlanpref.dll -> C:\Windows\SysWow64\wlanpref.dll -> [2009/09/17 04:38:59 | 01,671,680 | ---- | C] (Microsoft Corporation)
msinfo32.exe -> C:\Windows\SysWow64\msinfo32.exe -> [2009/09/17 04:38:59 | 00,408,064 | ---- | C] (Microsoft Corporation)
ieaksie.dll -> C:\Windows\SysWow64\ieaksie.dll -> [2009/09/17 04:38:59 | 00,230,400 | ---- | C] (Microsoft Corporation)
fastfat.sys -> C:\Windows\SysNative\drivers\fastfat.sys -> [2009/09/17 04:38:59 | 00,198,144 | ---- | C] (Microsoft Corporation)
rpchttp.dll -> C:\Windows\SysWow64\rpchttp.dll -> [2009/09/17 04:38:59 | 00,127,488 | ---- | C] (Microsoft Corporation)
pintlgnt.ime -> C:\Windows\SysWow64\pintlgnt.ime -> [2009/09/17 04:38:59 | 00,089,088 | ---- | C] (Microsoft Corporation)
smss.exe -> C:\Windows\SysNative\smss.exe -> [2009/09/17 04:38:59 | 00,075,264 | ---- | C] (Microsoft Corporation)
regapi.dll -> C:\Windows\SysWow64\regapi.dll -> [2009/09/17 04:38:59 | 00,067,584 | ---- | C] (Microsoft Corporation)
rekeywiz.exe -> C:\Windows\SysNative\rekeywiz.exe -> [2009/09/17 04:38:59 | 00,051,200 | ---- | C] (Microsoft Corporation)
msimtf.dll -> C:\Windows\SysNative\msimtf.dll -> [2009/09/17 04:38:59 | 00,041,472 | ---- | C] (Microsoft Corporation)
msftedit.dll -> C:\Windows\SysNative\msftedit.dll -> [2009/09/17 04:38:58 | 00,735,232 | ---- | C] (Microsoft Corporation)
msscp.dll -> C:\Windows\SysNative\msscp.dll -> [2009/09/17 04:38:58 | 00,534,528 | ---- | C] (Microsoft Corporation)
wpcao.dll -> C:\Windows\SysWow64\wpcao.dll -> [2009/09/17 04:38:58 | 00,532,992 | ---- | C] (Microsoft Corporation)
mscandui.dll -> C:\Windows\SysNative\mscandui.dll -> [2009/09/17 04:38:58 | 00,289,792 | ---- | C] (Microsoft Corporation)
tapisrv.dll -> C:\Windows\SysWow64\tapisrv.dll -> [2009/09/17 04:38:58 | 00,242,688 | ---- | C] (Microsoft Corporation)
scksp.dll -> C:\Windows\SysWow64\scksp.dll -> [2009/09/17 04:38:58 | 00,140,288 | ---- | C] (Microsoft Corporation)
vdsutil.dll -> C:\Windows\SysWow64\vdsutil.dll -> [2009/09/17 04:38:58 | 00,128,000 | ---- | C] (Microsoft Corporation)
rdpwsx.dll -> C:\Windows\SysNative\rdpwsx.dll -> [2009/09/17 04:38:58 | 00,117,760 | ---- | C] (Microsoft Corporation)
PnPUnattend.exe -> C:\Windows\SysNative\PnPUnattend.exe -> [2009/09/17 04:38:58 | 00,064,512 | ---- | C] (Microsoft Corporation)
feclient.dll -> C:\Windows\SysWow64\feclient.dll -> [2009/09/17 04:38:58 | 00,054,272 | ---- | C] (Microsoft Corporation)
printfilterpipelineprxy.dll -> C:\Windows\SysNative\printfilterpipelineprxy.dll -> [2009/09/17 04:38:58 | 00,035,840 | ---- | C] (Microsoft Corporation)
WMPEncEn.dll -> C:\Windows\SysNative\WMPEncEn.dll -> [2009/09/17 04:38:57 | 02,043,904 | ---- | C] (Microsoft Corporation)
WMPEncEn.dll -> C:\Windows\SysWow64\WMPEncEn.dll -> [2009/09/17 04:38:57 | 01,642,496 | ---- | C] (Microsoft Corporation)
wiaaut.dll -> C:\Windows\SysNative\wiaaut.dll -> [2009/09/17 04:38:57 | 00,669,184 | ---- | C] (Microsoft Corporation)
scesrv.dll -> C:\Windows\SysWow64\scesrv.dll -> [2009/09/17 04:38:57 | 00,306,176 | ---- | C] (Microsoft Corporation)
psisdecd.dll -> C:\Windows\SysWow64\psisdecd.dll -> [2009/09/17 04:38:57 | 00,293,376 | ---- | C] (Microsoft Corporation)
webcheck.dll -> C:\Windows\SysNative\webcheck.dll -> [2009/09/17 04:38:57 | 00,290,816 | ---- | C] (Microsoft Corporation)
dsprop.dll -> C:\Windows\SysNative\dsprop.dll -> [2009/09/17 04:38:57 | 00,164,864 | ---- | C] (Microsoft Corporation)
mpr.dll -> C:\Windows\SysWow64\mpr.dll -> [2009/09/17 04:38:57 | 00,068,608 | ---- | C] (Microsoft Corporation)
certprop.dll -> C:\Windows\SysNative\certprop.dll -> [2009/09/17 04:38:57 | 00,049,664 | ---- | C] (Microsoft Corporation)
mmsys.cpl -> C:\Windows\SysWow64\mmsys.cpl -> [2009/09/17 04:38:56 | 01,102,848 | ---- | C] (Microsoft Corporation)
FWPUCLNT.DLL -> C:\Windows\SysNative\FWPUCLNT.DLL -> [2009/09/17 04:38:56 | 00,779,776 | ---- | C] (Microsoft Corporation)
winhttp.dll -> C:\Windows\SysNative\winhttp.dll -> [2009/09/17 04:38:56 | 00,439,808 | ---- | C] (Microsoft Corporation)
AUDIOKSE.dll -> C:\Windows\SysNative\AUDIOKSE.dll -> [2009/09/17 04:38:56 | 00,313,856 | ---- | C] (Microsoft Corporation)
fontext.dll -> C:\Windows\SysNative\fontext.dll -> [2009/09/17 04:38:56 | 00,163,328 | ---- | C] (Microsoft Corporation)
Faultrep.dll -> C:\Windows\SysWow64\Faultrep.dll -> [2009/09/17 04:38:56 | 00,147,456 | ---- | C] (Microsoft Corporation)
AudioSes.dll -> C:\Windows\SysWow64\AudioSes.dll -> [2009/09/17 04:38:56 | 00,115,712 | ---- | C] (Microsoft Corporation)
oleprn.dll -> C:\Windows\SysWow64\oleprn.dll -> [2009/09/17 04:38:56 | 00,097,792 | ---- | C] (Microsoft Corporation)
dot3msm.dll -> C:\Windows\SysWow64\dot3msm.dll -> [2009/09/17 04:38:56 | 00,075,264 | ---- | C] (Microsoft Corporation)
rekeywiz.exe -> C:\Windows\SysWow64\rekeywiz.exe -> [2009/09/17 04:38:56 | 00,043,520 | ---- | C] (Microsoft Corporation)
iaspolcy.dll -> C:\Windows\SysWow64\iaspolcy.dll -> [2009/09/17 04:38:56 | 00,033,792 | ---- | C] (Microsoft Corporation)
whealogr.dll -> C:\Windows\SysNative\whealogr.dll -> [2009/09/17 04:38:56 | 00,033,280 | ---- | C] (Microsoft Corporation)
wsdchngr.dll -> C:\Windows\SysNative\wsdchngr.dll -> [2009/09/17 04:38:56 | 00,025,600 | ---- | C] (Microsoft Corporation)
wscisvif.dll -> C:\Windows\SysWow64\wscisvif.dll -> [2009/09/17 04:38:56 | 00,017,920 | ---- | C] (Microsoft Corporation)
wscui.cpl -> C:\Windows\SysWow64\wscui.cpl -> [2009/09/17 04:38:55 | 01,689,600 | ---- | C] (Microsoft Corporation)
qedit.dll -> C:\Windows\SysWow64\qedit.dll -> [2009/09/17 04:38:55 | 00,505,344 | ---- | C] (Microsoft Corporation)
ncryptui.dll -> C:\Windows\SysWow64\ncryptui.dll -> [2009/09/17 04:38:55 | 00,445,952 | ---- | C] (Microsoft Corporation)
dpapimig.exe -> C:\Windows\SysWow64\dpapimig.exe -> [2009/09/17 04:38:55 | 00,407,040 | ---- | C] (Microsoft Corporation)
unimdm.tsp -> C:\Windows\SysNative\unimdm.tsp -> [2009/09/17 04:38:55 | 00,320,000 | ---- | C] (Microsoft Corporation)
certreq.exe -> C:\Windows\SysWow64\certreq.exe -> [2009/09/17 04:38:55 | 00,215,552 | ---- | C] (Microsoft Corporation)
dot3msm.dll -> C:\Windows\SysNative\dot3msm.dll -> [2009/09/17 04:38:55 | 00,092,160 | ---- | C] (Microsoft Corporation)
perfdisk.dll -> C:\Windows\SysWow64\perfdisk.dll -> [2009/09/17 04:38:55 | 00,031,744 | ---- | C] (Microsoft Corporation)
wscui.cpl -> C:\Windows\SysNative\wscui.cpl -> [2009/09/17 04:38:54 | 01,738,752 | ---- | C] (Microsoft Corporation)
rasgcw.dll -> C:\Windows\SysWow64\rasgcw.dll -> [2009/09/17 04:38:54 | 00,642,560 | ---- | C] (Microsoft Corporation)
wmpeffects.dll -> C:\Windows\SysNative\wmpeffects.dll -> [2009/09/17 04:38:54 | 00,557,056 | ---- | C] (Microsoft Corporation)
hdwwiz.exe -> C:\Windows\SysWow64\hdwwiz.exe -> [2009/09/17 04:38:54 | 00,080,384 | ---- | C] (Microsoft Corporation)
netshell.dll -> C:\Windows\SysNative\netshell.dll -> [2009/09/17 04:38:53 | 03,341,312 | ---- | C] (Microsoft Corporation)
FWPUCLNT.DLL -> C:\Windows\SysWow64\FWPUCLNT.DLL -> [2009/09/17 04:38:53 | 00,595,456 | ---- | C] (Microsoft Corporation)
rasplap.dll -> C:\Windows\SysWow64\rasplap.dll -> [2009/09/17 04:38:53 | 00,376,832 | ---- | C] (Microsoft Corporation)
msnetobj.dll -> C:\Windows\SysNative\msnetobj.dll -> [2009/09/17 04:38:53 | 00,221,696 | ---- | C] (Microsoft Corporation)
extmgr.dll -> C:\Windows\SysNative\extmgr.dll -> [2009/09/17 04:38:53 | 00,207,360 | ---- | C] (Microsoft Corporation)
scecli.dll -> C:\Windows\SysWow64\scecli.dll -> [2009/09/17 04:38:53 | 00,177,152 | ---- | C] (Microsoft Corporation)
SmartcardCredentialProvider.dll -> C:\Windows\SysWow64\SmartcardCredentialProvider.dll -> [2009/09/17 04:38:53 | 00,134,656 | ---- | C] (Microsoft Corporation)
extmgr.dll -> C:\Windows\SysWow64\extmgr.dll -> [2009/09/17 04:38:53 | 00,133,120 | ---- | C] (Microsoft Corporation)
dimsroam.dll -> C:\Windows\SysNative\dimsroam.dll -> [2009/09/17 04:38:53 | 00,064,512 | ---- | C] (Microsoft Corporation)
USBCAMD2.sys -> C:\Windows\SysNative\drivers\USBCAMD2.sys -> [2009/09/17 04:38:53 | 00,032,640 | ---- | C] (Microsoft Corporation)
wmdrmdev.dll -> C:\Windows\SysNative\wmdrmdev.dll -> [2009/09/17 04:38:52 | 00,539,136 | ---- | C] (Microsoft Corporation)
drmmgrtn.dll -> C:\Windows\SysNative\drmmgrtn.dll -> [2009/09/17 04:38:52 | 00,365,568 | ---- | C] (Microsoft Corporation)
certreq.exe -> C:\Windows\SysNative\certreq.exe -> [2009/09/17 04:38:52 | 00,259,072 | ---- | C] (Microsoft Corporation)
rdpwd.sys -> C:\Windows\SysNative\drivers\rdpwd.sys -> [2009/09/17 04:38:52 | 00,209,920 | ---- | C] (Microsoft Corporation)
tcpipcfg.dll -> C:\Windows\SysWow64\tcpipcfg.dll -> [2009/09/17 04:38:52 | 00,170,496 | ---- | C] (Microsoft Corporation)
tcpmon.dll -> C:\Windows\SysWow64\tcpmon.dll -> [2009/09/17 04:38:52 | 00,135,168 | ---- | C] (Microsoft Corporation)
conime.exe -> C:\Windows\SysNative\conime.exe -> [2009/09/17 04:38:52 | 00,086,528 | ---- | C] (Microsoft Corporation)
fdWSD.dll -> C:\Windows\SysWow64\fdWSD.dll -> [2009/09/17 04:38:52 | 00,067,072 | ---- | C] (Microsoft Corporation)
cmmon32.exe -> C:\Windows\SysWow64\cmmon32.exe -> [2009/09/17 04:38:52 | 00,049,152 | ---- | C] (Microsoft Corporation)
TSTheme.exe -> C:\Windows\SysWow64\TSTheme.exe -> [2009/09/17 04:38:52 | 00,038,400 | ---- | C] (Microsoft Corporation)
PnPutil.exe -> C:\Windows\SysNative\PnPutil.exe -> [2009/09/17 04:38:52 | 00,036,864 | ---- | C] (Microsoft Corporation)
spwinsat.dll -> C:\Windows\SysWow64\spwinsat.dll -> [2009/09/17 04:38:52 | 00,011,776 | ---- | C] (Microsoft Corporation)
MSMPEG2ENC.DLL -> C:\Windows\SysNative\MSMPEG2ENC.DLL -> [2009/09/17 04:38:51 | 00,644,608 | ---- | C] (Microsoft Corporation)
msutb.dll -> C:\Windows\SysNative\msutb.dll -> [2009/09/17 04:38:51 | 00,227,840 | ---- | C] (Microsoft Corporation)
wlanui.dll -> C:\Windows\SysNative\wlanui.dll -> [2009/09/17 04:38:51 | 00,218,624 | ---- | C] (Microsoft Corporation)
netplwiz.dll -> C:\Windows\SysNative\netplwiz.dll -> [2009/09/17 04:38:51 | 00,197,632 | ---- | C] (Microsoft Corporation)
SndVol.exe -> C:\Windows\SysNative\SndVol.exe -> [2009/09/17 04:38:51 | 00,172,032 | ---- | C] (Microsoft Corporation)
rmcast.sys -> C:\Windows\SysNative\drivers\rmcast.sys -> [2009/09/17 04:38:51 | 00,140,288 | ---- | C] (Microsoft Corporation)
shsetup.dll -> C:\Windows\SysNative\shsetup.dll -> [2009/09/17 04:38:51 | 00,121,856 | ---- | C] (Microsoft Corporation)
MSNP.ax -> C:\Windows\SysNative\MSNP.ax -> [2009/09/17 04:38:51 | 00,101,376 | ---- | C] (Microsoft Corporation)
rassstp.sys -> C:\Windows\SysNative\drivers\rassstp.sys -> [2009/09/17 04:38:51 | 00,078,336 | ---- | C] (Microsoft Corporation)
watchdog.sys -> C:\Windows\SysNative\drivers\watchdog.sys -> [2009/09/17 04:38:51 | 00,040,448 | ---- | C] (Microsoft Corporation)
uxsms.dll -> C:\Windows\SysNative\uxsms.dll -> [2009/09/17 04:38:51 | 00,032,768 | ---- | C] (Microsoft Corporation)
whealogr.dll -> C:\Windows\SysWow64\whealogr.dll -> [2009/09/17 04:38:51 | 00,031,232 | ---- | C] (Microsoft Corporation)
oobefldr.dll -> C:\Windows\SysNative\oobefldr.dll -> [2009/09/17 04:38:50 | 02,438,656 | ---- | C] (Microsoft Corporation)
blackbox.dll -> C:\Windows\SysNative\blackbox.dll -> [2009/09/17 04:38:50 | 00,616,448 | ---- | C] (Microsoft Corporation)
cmdial32.dll -> C:\Windows\SysNative\cmdial32.dll -> [2009/09/17 04:38:50 | 00,521,216 | ---- | C] (Microsoft Corporation)
cmdial32.dll -> C:\Windows\SysWow64\cmdial32.dll -> [2009/09/17 04:38:50 | 00,481,792 | ---- | C] (Microsoft Corporation)
raschap.dll -> C:\Windows\SysWow64\raschap.dll -> [2009/09/17 04:38:50 | 00,281,088 | ---- | C] (Microsoft Corporation)
wdmaud.drv -> C:\Windows\SysWow64\wdmaud.drv -> [2009/09/17 04:38:50 | 00,167,424 | ---- | C] (Microsoft Corporation)
occache.dll -> C:\Windows\SysNative\occache.dll -> [2009/09/17 04:38:50 | 00,165,376 | ---- | C] (Microsoft Corporation)
fontext.dll -> C:\Windows\SysWow64\fontext.dll -> [2009/09/17 04:38:50 | 00,142,336 | ---- | C] (Microsoft Corporation)
SCardSvr.dll -> C:\Windows\SysWow64\SCardSvr.dll -> [2009/09/17 04:38:50 | 00,095,232 | ---- | C] (Microsoft Corporation)
wscsvc.dll -> C:\Windows\SysNative\wscsvc.dll -> [2009/09/17 04:38:50 | 00,074,752 | ---- | C] (Microsoft Corporation)
conime.exe -> C:\Windows\SysWow64\conime.exe -> [2009/09/17 04:38:50 | 00,069,120 | ---- | C] (Microsoft Corporation)
MsCtfMonitor.dll -> C:\Windows\SysNative\MsCtfMonitor.dll -> [2009/09/17 04:38:50 | 00,026,112 | ---- | C] (Microsoft Corporation)
MSVidCtl.dll -> C:\Windows\SysNative\MSVidCtl.dll -> [2009/09/17 04:38:49 | 02,535,424 | ---- | C] (Microsoft Corporation)
MSVidCtl.dll -> C:\Windows\SysWow64\MSVidCtl.dll -> [2009/09/17 04:38:49 | 01,544,704 | ---- | C] (Microsoft Corporation)
WMVXENCD.DLL -> C:\Windows\SysWow64\WMVXENCD.DLL -> [2009/09/17 04:38:49 | 00,657,408 | ---- | C] (Microsoft Corporation)
wiaaut.dll -> C:\Windows\SysWow64\wiaaut.dll -> [2009/09/17 04:38:49 | 00,547,840 | ---- | C] (Microsoft Corporation)
taskcomp.dll -> C:\Windows\SysNative\taskcomp.dll -> [2009/09/17 04:38:49 | 00,409,600 | ---- | C] (Microsoft Corporation)
unimdm.tsp -> C:\Windows\SysWow64\unimdm.tsp -> [2009/09/17 04:38:49 | 00,280,064 | ---- | C] (Microsoft Corporation)
wlanui.dll -> C:\Windows\SysWow64\wlanui.dll -> [2009/09/17 04:38:49 | 00,202,752 | ---- | C] (Microsoft Corporation)
nwifi.sys -> C:\Windows\SysNative\drivers\nwifi.sys -> [2009/09/17 04:38:49 | 00,187,392 | ---- | C] (Microsoft Corporation)
wlgpclnt.dll -> C:\Windows\SysNative\wlgpclnt.dll -> [2009/09/17 04:38:49 | 00,100,864 | ---- | C] (Microsoft Corporation)
fdWSD.dll -> C:\Windows\SysNative\fdWSD.dll -> [2009/09/17 04:38:49 | 00,081,408 | ---- | C] (Microsoft Corporation)
cipher.exe -> C:\Windows\SysNative\cipher.exe -> [2009/09/17 04:38:49 | 00,067,584 | ---- | C] (Microsoft Corporation)
oobefldr.dll -> C:\Windows\SysWow64\oobefldr.dll -> [2009/09/17 04:38:48 | 02,153,472 | ---- | C] (Microsoft Corporation)
WMVDECOD.DLL -> C:\Windows\SysNative\WMVDECOD.DLL -> [2009/09/17 04:38:48 | 01,702,912 | ---- | C] (Microsoft Corporation)
wmdrmsdk.dll -> C:\Windows\SysNative\wmdrmsdk.dll -> [2009/09/17 04:38:48 | 00,688,128 | ---- | C] (Microsoft Corporation)
shwebsvc.dll -> C:\Windows\SysWow64\shwebsvc.dll -> [2009/09/17 04:38:48 | 00,425,472 | ---- | C] (Microsoft Corporation)
rasppp.dll -> C:\Windows\SysWow64\rasppp.dll -> [2009/09/17 04:38:48 | 00,259,584 | ---- | C] (Microsoft Corporation)
dsprop.dll -> C:\Windows\SysWow64\dsprop.dll -> [2009/09/17 04:38:48 | 00,137,728 | ---- | C] (Microsoft Corporation)
l2nacp.dll -> C:\Windows\SysNative\l2nacp.dll -> [2009/09/17 04:38:48 | 00,056,832 | ---- | C] (Microsoft Corporation)
dimsroam.dll -> C:\Windows\SysWow64\dimsroam.dll -> [2009/09/17 04:38:48 | 00,054,784 | ---- | C] (Microsoft Corporation)
modemui.dll -> C:\Windows\SysWow64\modemui.dll -> [2009/09/17 04:38:47 | 00,288,256 | ---- | C] (Microsoft Corporation)
input.dll -> C:\Windows\SysNative\input.dll -> [2009/09/17 04:38:47 | 00,257,024 | ---- | C] (Microsoft Corporation)
softkbd.dll -> C:\Windows\SysNative\softkbd.dll -> [2009/09/17 04:38:47 | 00,158,208 | ---- | C] (Microsoft Corporation)
btpanui.dll -> C:\Windows\SysNative\btpanui.dll -> [2009/09/17 04:38:47 | 00,109,056 | ---- | C] (Microsoft Corporation)
occache.dll -> C:\Windows\SysWow64\occache.dll -> [2009/09/17 04:38:47 | 00,102,912 | ---- | C] (Microsoft Corporation)
shsetup.dll -> C:\Windows\SysWow64\shsetup.dll -> [2009/09/17 04:38:47 | 00,101,376 | ---- | C] (Microsoft Corporation)
chtbrkr.dll -> C:\Windows\SysWow64\chtbrkr.dll -> [2009/09/17 04:38:46 | 06,103,040 | ---- | C] (Microsoft Corporation)
wmdrmsdk.dll -> C:\Windows\SysWow64\wmdrmsdk.dll -> [2009/09/17 04:38:46 | 00,533,504 | ---- | C] (Microsoft Corporation)
mscandui.dll -> C:\Windows\SysWow64\mscandui.dll -> [2009/09/17 04:38:46 | 00,218,624 | ---- | C] (Microsoft Corporation)
rasmontr.dll -> C:\Windows\SysNative\rasmontr.dll -> [2009/09/17 04:38:46 | 00,216,064 | ---- | C] (Microsoft Corporation)
rasmontr.dll -> C:\Windows\SysWow64\rasmontr.dll -> [2009/09/17 04:38:46 | 00,155,136 | ---- | C] (Microsoft Corporation)
dataclen.dll -> C:\Windows\SysWow64\dataclen.dll -> [2009/09/17 04:38:46 | 00,045,056 | ---- | C] (Microsoft Corporation)
cscapi.dll -> C:\Windows\SysNative\cscapi.dll -> [2009/09/17 04:38:46 | 00,038,400 | ---- | C] (Microsoft Corporation)
NcdProp.dll -> C:\Windows\SysNative\NcdProp.dll -> [2009/09/17 04:38:46 | 00,024,064 | ---- | C] (Microsoft Corporation)
mstime.dll -> C:\Windows\SysNative\mstime.dll -> [2009/09/17 04:38:45 | 01,129,984 | ---- | C] (Microsoft Corporation)
blackbox.dll -> C:\Windows\SysWow64\blackbox.dll -> [2009/09/17 04:38:45 | 00,542,720 | ---- | C] (Microsoft Corporation)
rstrui.exe -> C:\Windows\SysNative\rstrui.exe -> [2009/09/17 04:38:45 | 00,339,968 | ---- | C] (Microsoft Corporation)
netplwiz.dll -> C:\Windows\SysWow64\netplwiz.dll -> [2009/09/17 04:38:45 | 00,180,736 | ---- | C] (Microsoft Corporation)
credui.dll -> C:\Windows\SysWow64\credui.dll -> [2009/09/17 04:38:45 | 00,178,176 | ---- | C] (Microsoft Corporation)
wlgpclnt.dll -> C:\Windows\SysWow64\wlgpclnt.dll -> [2009/09/17 04:38:45 | 00,083,456 | ---- | C] (Microsoft Corporation)
ohci1394.sys -> C:\Windows\SysNative\drivers\ohci1394.sys -> [2009/09/17 04:38:45 | 00,072,448 | ---- | C] (Microsoft Corporation)
findstr.exe -> C:\Windows\SysNative\findstr.exe -> [2009/09/17 04:38:45 | 00,029,696 | ---- | C] (Microsoft Corporation)
networkexplorer.dll -> C:\Windows\SysWow64\networkexplorer.dll -> [2009/09/17 04:38:44 | 02,226,688 | ---- | C] (Microsoft Corporation)
mstime.dll -> C:\Windows\SysWow64\mstime.dll -> [2009/09/17 04:38:44 | 00,671,232 | ---- | C] (Microsoft Corporation)
wmpeffects.dll -> C:\Windows\SysWow64\wmpeffects.dll -> [2009/09/17 04:38:44 | 00,303,616 | ---- | C] (Microsoft Corporation)
AUDIOKSE.dll -> C:\Windows\SysWow64\AUDIOKSE.dll -> [2009/09/17 04:38:44 | 00,274,944 | ---- | C] (Microsoft Corporation)
mstask.dll -> C:\Windows\SysNative\mstask.dll -> [2009/09/17 04:38:44 | 00,235,008 | ---- | C] (Microsoft Corporation)
mpg2splt.ax -> C:\Windows\SysNative\mpg2splt.ax -> [2009/09/17 04:38:44 | 00,227,328 | ---- | C] (Microsoft Corporation)
wpdwcn.dll -> C:\Windows\SysNative\wpdwcn.dll -> [2009/09/17 04:38:44 | 00,223,232 | ---- | C] (Microsoft Corporation)
PortableDeviceTypes.dll -> C:\Windows\SysNative\PortableDeviceTypes.dll -> [2009/09/17 04:38:44 | 00,214,528 | ---- | C] (Microsoft Corporation)
WSDMon.dll -> C:\Windows\SysWow64\WSDMon.dll -> [2009/09/17 04:38:44 | 00,177,664 | ---- | C] (Microsoft Corporation)
adsmsext.dll -> C:\Windows\SysNative\adsmsext.dll -> [2009/09/17 04:38:44 | 00,105,472 | ---- | C] (Microsoft Corporation)
deskmon.dll -> C:\Windows\SysNative\deskmon.dll -> [2009/09/17 04:38:44 | 00,046,592 | ---- | C] (Microsoft Corporation)
WMADMOD.DLL -> C:\Windows\SysNative\WMADMOD.DLL -> [2009/09/17 04:38:43 | 00,946,176 | ---- | C] (Microsoft Corporation)
msscp.dll -> C:\Windows\SysWow64\msscp.dll -> [2009/09/17 04:38:43 | 00,414,208 | ---- | C] (Microsoft Corporation)
InkEd.dll -> C:\Windows\SysWow64\InkEd.dll -> [2009/09/17 04:38:43 | 00,217,600 | ---- | C] (Microsoft Corporation)
msrating.dll -> C:\Windows\SysWow64\msrating.dll -> [2009/09/17 04:38:43 | 00,193,024 | ---- | C] (Microsoft Corporation)
wpcsvc.dll -> C:\Windows\SysWow64\wpcsvc.dll -> [2009/09/17 04:38:43 | 00,140,288 | ---- | C] (Microsoft Corporation)
gpresult.exe -> C:\Windows\SysWow64\gpresult.exe -> [2009/09/17 04:38:43 | 00,128,000 | ---- | C] (Microsoft Corporation)
msctfui.dll -> C:\Windows\SysNative\msctfui.dll -> [2009/09/17 04:38:43 | 00,113,664 | ---- | C] (Microsoft Corporation)
logagent.exe -> C:\Windows\SysWow64\logagent.exe -> [2009/09/17 04:38:43 | 00,094,720 | ---- | C] (Microsoft Corporation)
cipher.exe -> C:\Windows\SysWow64\cipher.exe -> [2009/09/17 04:38:43 | 00,058,368 | ---- | C] (Microsoft Corporation)
wscapi.dll -> C:\Windows\SysWow64\wscapi.dll -> [2009/09/17 04:38:43 | 00,033,280 | ---- | C] (Microsoft Corporation)
ifmon.dll -> C:\Windows\SysWow64\ifmon.dll -> [2009/09/17 04:38:43 | 00,029,696 | ---- | C] (Microsoft Corporation)
version.dll -> C:\Windows\SysNative\version.dll -> [2009/09/17 04:38:43 | 00,027,136 | ---- | C] (Microsoft Corporation)
wmdrmnet.dll -> C:\Windows\SysNative\wmdrmnet.dll -> [2009/09/17 04:38:42 | 00,428,032 | ---- | C] (Microsoft Corporation)
thawbrkr.dll -> C:\Windows\SysWow64\thawbrkr.dll -> [2009/09/17 04:38:42 | 00,313,344 | ---- | C] (Microsoft Corporation)
mdminst.dll -> C:\Windows\SysNative\mdminst.dll -> [2009/09/17 04:38:42 | 00,215,552 | ---- | C] (Microsoft Corporation)
wpdwcn.dll -> C:\Windows\SysWow64\wpdwcn.dll -> [2009/09/17 04:38:42 | 00,203,776 | ---- | C] (Microsoft Corporation)
credui.dll -> C:\Windows\SysNative\credui.dll -> [2009/09/17 04:38:42 | 00,190,976 | ---- | C] (Microsoft Corporation)
softkbd.dll -> C:\Windows\SysWow64\softkbd.dll -> [2009/09/17 04:38:42 | 00,125,952 | ---- | C] (Microsoft Corporation)
logagent.exe -> C:\Windows\SysNative\logagent.exe -> [2009/09/17 04:38:42 | 00,112,640 | ---- | C] (Microsoft Corporation)
sendmail.dll -> C:\Windows\SysWow64\sendmail.dll -> [2009/09/17 04:38:42 | 00,069,632 | ---- | C] (Microsoft Corporation)
cdd.dll -> C:\Windows\SysNative\cdd.dll -> [2009/09/17 04:38:42 | 00,047,104 | ---- | C] (Microsoft Corporation)
msimtf.dll -> C:\Windows\SysWow64\msimtf.dll -> [2009/09/17 04:38:42 | 00,031,232 | ---- | C] (Microsoft Corporation)
MediaMetadataHandler.dll -> C:\Windows\SysNative\MediaMetadataHandler.dll -> [2009/09/17 04:38:41 | 00,403,456 | ---- | C] (Microsoft Corporation)
MediaMetadataHandler.dll -> C:\Windows\SysWow64\MediaMetadataHandler.dll -> [2009/09/17 04:38:41 | 00,356,864 | ---- | C] (Microsoft Corporation)
WSDMon.dll -> C:\Windows\SysNative\WSDMon.dll -> [2009/09/17 04:38:41 | 00,214,016 | ---- | C] (Microsoft Corporation)
MSAC3ENC.DLL -> C:\Windows\SysNative\MSAC3ENC.DLL -> [2009/09/17 04:38:41 | 00,193,536 | ---- | C] (Microsoft Corporation)
olepro32.dll -> C:\Windows\SysWow64\olepro32.dll -> [2009/09/17 04:38:41 | 00,088,576 | ---- | C] (Microsoft Corporation)
msctfui.dll -> C:\Windows\SysWow64\msctfui.dll -> [2009/09/17 04:38:41 | 00,085,504 | ---- | C] (Microsoft Corporation)
rshx32.dll -> C:\Windows\SysNative\rshx32.dll -> [2009/09/17 04:38:41 | 00,053,760 | ---- | C] (Microsoft Corporation)
rasdial.exe -> C:\Windows\SysNative\rasdial.exe -> [2009/09/17 04:38:41 | 00,018,944 | ---- | C] (Microsoft Corporation)
hidusb.sys -> C:\Windows\SysNative\drivers\hidusb.sys -> [2009/09/17 04:38:41 | 00,015,872 | ---- | C] (Microsoft Corporation)
drmmgrtn.dll -> C:\Windows\SysWow64\drmmgrtn.dll -> [2009/09/17 04:38:40 | 00,284,672 | ---- | C] (Microsoft Corporation)
mpg2splt.ax -> C:\Windows\SysWow64\mpg2splt.ax -> [2009/09/17 04:38:40 | 00,177,664 | ---- | C] (Microsoft Corporation)
puiapi.dll -> C:\Windows\SysWow64\puiapi.dll -> [2009/09/17 04:38:40 | 00,166,400 | ---- | C] (Microsoft Corporation)
mprapi.dll -> C:\Windows\SysNative\mprapi.dll -> [2009/09/17 04:38:40 | 00,129,536 | ---- | C] (Microsoft Corporation)
dmsynth.dll -> C:\Windows\SysWow64\dmsynth.dll -> [2009/09/17 04:38:40 | 00,105,472 | ---- | C] (Microsoft Corporation)
smb.sys -> C:\Windows\SysNative\drivers\smb.sys -> [2009/09/17 04:38:40 | 00,088,064 | ---- | C] (Microsoft Corporation)
deskadp.dll -> C:\Windows\SysNative\deskadp.dll -> [2009/09/17 04:38:40 | 00,049,664 | ---- | C] (Microsoft Corporation)
cscdll.dll -> C:\Windows\SysNative\cscdll.dll -> [2009/09/17 04:38:40 | 00,028,672 | ---- | C] (Microsoft Corporation)
WMSPDMOD.DLL -> C:\Windows\SysNative\WMSPDMOD.DLL -> [2009/09/17 04:38:39 | 00,818,688 | ---- | C] (Microsoft Corporation)
wmdrmdev.dll -> C:\Windows\SysWow64\wmdrmdev.dll -> [2009/09/17 04:38:39 | 00,418,304 | ---- | C] (Microsoft Corporation)
input.dll -> C:\Windows\SysWow64\input.dll -> [2009/09/17 04:38:39 | 00,200,704 | ---- | C] (Microsoft Corporation)
mprapi.dll -> C:\Windows\SysWow64\mprapi.dll -> [2009/09/17 04:38:39 | 00,097,792 | ---- | C] (Microsoft Corporation)
fdSSDP.dll -> C:\Windows\SysNative\fdSSDP.dll -> [2009/09/17 04:38:39 | 00,083,968 | ---- | C] (Microsoft Corporation)
FwRemoteSvr.dll -> C:\Windows\SysNative\FwRemoteSvr.dll -> [2009/09/17 04:38:39 | 00,050,176 | ---- | C] (Microsoft Corporation)
wshbth.dll -> C:\Windows\SysWow64\wshbth.dll -> [2009/09/17 04:38:39 | 00,034,304 | ---- | C] (Microsoft Corporation)
ExplorerFrame.dll -> C:\Windows\SysWow64\ExplorerFrame.dll -> [2009/09/17 04:38:39 | 00,020,992 | ---- | C] (Microsoft Corporation)
version.dll -> C:\Windows\SysWow64\version.dll -> [2009/09/17 04:38:39 | 00,020,480 | ---- | C] (Microsoft Corporation)
msisip.dll -> C:\Windows\SysWow64\msisip.dll -> [2009/09/17 04:38:39 | 00,016,384 | ---- | C] (Microsoft Corporation)
WMADMOD.DLL -> C:\Windows\SysWow64\WMADMOD.DLL -> [2009/09/17 04:38:38 | 00,758,784 | ---- | C] (Microsoft Corporation)
wdmaud.drv -> C:\Windows\SysNative\wdmaud.drv -> [2009/09/17 04:38:38 | 00,212,992 | ---- | C] (Microsoft Corporation)
SMBHelperClass.dll -> C:\Windows\SysNative\SMBHelperClass.dll -> [2009/09/17 04:38:38 | 00,116,736 | ---- | C] (Microsoft)
gpapi.dll -> C:\Windows\SysNative\gpapi.dll -> [2009/09/17 04:38:38 | 00,084,480 | ---- | C] (Microsoft Corporation)
MSNP.ax -> C:\Windows\SysWow64\MSNP.ax -> [2009/09/17 04:38:38 | 00,080,896 | ---- | C] (Microsoft Corporation)
fdSSDP.dll -> C:\Windows\SysWow64\fdSSDP.dll -> [2009/09/17 04:38:38 | 00,068,096 | ---- | C] (Microsoft Corporation)
bthci.dll -> C:\Windows\SysNative\bthci.dll -> [2009/09/17 04:38:38 | 00,046,592 | ---- | C] (Microsoft Corporation)
fc.exe -> C:\Windows\SysWow64\fc.exe -> [2009/09/17 04:38:38 | 00,019,968 | ---- | C] (Microsoft Corporation)
networkexplorer.dll -> C:\Windows\SysNative\networkexplorer.dll -> [2009/09/17 04:38:37 | 02,247,168 | ---- | C] (Microsoft Corporation)
wmpps.dll -> C:\Windows\SysNative\wmpps.dll -> [2009/09/17 04:38:37 | 00,434,176 | ---- | C] (Microsoft Corporation)
eapp3hst.dll -> C:\Windows\SysNative\eapp3hst.dll -> [2009/09/17 04:38:37 | 00,291,840 | ---- | C] (Microsoft Corporation)
wscntfy.dll -> C:\Windows\SysNative\wscntfy.dll -> [2009/09/17 04:38:37 | 00,231,424 | ---- | C] (Microsoft Corporation)
eapp3hst.dll -> C:\Windows\SysWow64\eapp3hst.dll -> [2009/09/17 04:38:37 | 00,187,904 | ---- | C] (Microsoft Corporation)
tintlgnt.ime -> C:\Windows\SysWow64\tintlgnt.ime -> [2009/09/17 04:38:37 | 00,125,952 | ---- | C] (Microsoft Corporation)
dmusic.dll -> C:\Windows\SysWow64\dmusic.dll -> [2009/09/17 04:38:37 | 00,101,888 | ---- | C] (Microsoft Corporation)
dxg.sys -> C:\Windows\SysNative\drivers\dxg.sys -> [2009/09/17 04:38:37 | 00,098,816 | ---- | C] (Microsoft Corporation)
PNPXAssoc.dll -> C:\Windows\SysNative\PNPXAssoc.dll -> [2009/09/17 04:38:37 | 00,075,264 | ---- | C] (Microsoft Corporation)
dot3cfg.dll -> C:\Windows\SysNative\dot3cfg.dll -> [2009/09/17 04:38:37 | 00,062,976 | ---- | C] (Microsoft Corporation)
l2nacp.dll -> C:\Windows\SysWow64\l2nacp.dll -> [2009/09/17 04:38:37 | 00,048,128 | ---- | C] (Microsoft Corporation)
ftp.exe -> C:\Windows\SysNative\ftp.exe -> [2009/09/17 04:38:37 | 00,047,616 | ---- | C] (Microsoft Corporation)
cscapi.dll -> C:\Windows\SysWow64\cscapi.dll -> [2009/09/17 04:38:37 | 00,031,744 | ---- | C] (Microsoft Corporation)
msjint40.dll -> C:\Windows\SysWow64\msjint40.dll -> [2009/09/17 04:38:37 | 00,024,576 | ---- | C] (Microsoft Corporation)
MsCtfMonitor.dll -> C:\Windows\SysWow64\MsCtfMonitor.dll -> [2009/09/17 04:38:37 | 00,019,456 | ---- | C] (Microsoft Corporation)
CHxReadingStringIME.dll -> C:\Windows\SysNative\CHxReadingStringIME.dll -> [2009/09/17 04:38:37 | 00,012,800 | ---- | C] (Microsoft Corporation)
wmdrmnet.dll -> C:\Windows\SysWow64\wmdrmnet.dll -> [2009/09/17 04:38:36 | 00,347,648 | ---- | C] (Microsoft Corporation)
PortableDeviceClassExtension.dll -> C:\Windows\SysNative\PortableDeviceClassExtension.dll -> [2009/09/17 04:38:36 | 00,105,472 | ---- | C] (Microsoft Corporation)
PortableDeviceClassExtension.dll -> C:\Windows\SysWow64\PortableDeviceClassExtension.dll -> [2009/09/17 04:38:36 | 00,094,720 | ---- | C] (Microsoft Corporation)
SMBHelperClass.dll -> C:\Windows\SysWow64\SMBHelperClass.dll -> [2009/09/17 04:38:36 | 00,083,456 | ---- | C] (Microsoft)
Storprop.dll -> C:\Windows\SysNative\Storprop.dll -> [2009/09/17 04:38:36 | 00,065,024 | ---- | C] (Microsoft Corporation)
hidclass.sys -> C:\Windows\SysNative\drivers\hidclass.sys -> [2009/09/17 04:38:36 | 00,049,152 | ---- | C] (Microsoft Corporation)
ftp.exe -> C:\Windows\SysWow64\ftp.exe -> [2009/09/17 04:38:36 | 00,041,984 | ---- | C] (Microsoft Corporation)
tdi.sys -> C:\Windows\SysNative\drivers\tdi.sys -> [2009/09/17 04:38:36 | 00,026,112 | ---- | C] (Microsoft Corporation)
cscdll.dll -> C:\Windows\SysWow64\cscdll.dll -> [2009/09/17 04:38:36 | 00,022,016 | ---- | C] (Microsoft Corporation)
wsdchngr.dll -> C:\Windows\SysWow64\wsdchngr.dll -> [2009/09/17 04:38:36 | 00,020,992 | ---- | C] (Microsoft Corporation)
PortableDeviceTypes.dll -> C:\Windows\SysWow64\PortableDeviceTypes.dll -> [2009/09/17 04:38:35 | 00,160,768 | ---- | C] (Microsoft Corporation)
mydocs.dll -> C:\Windows\SysNative\mydocs.dll -> [2009/09/17 04:38:35 | 00,143,360 | ---- | C] (Microsoft Corporation)
eappcfg.dll -> C:\Windows\SysWow64\eappcfg.dll -> [2009/09/17 04:38:35 | 00,135,680 | ---- | C] (Microsoft Corporation)
fdWCN.dll -> C:\Windows\SysNative\fdWCN.dll -> [2009/09/17 04:38:35 | 00,089,088 | ---- | C] (Microsoft Corporation)
fdWCN.dll -> C:\Windows\SysWow64\fdWCN.dll -> [2009/09/17 04:38:35 | 00,069,120 | ---- | C] (Microsoft Corporation)
rasdiag.dll -> C:\Windows\SysWow64\rasdiag.dll -> [2009/09/17 04:38:35 | 00,052,736 | ---- | C] (Microsoft Corporation)
msfeedsbs.dll -> C:\Windows\SysWow64\msfeedsbs.dll -> [2009/09/17 04:38:35 | 00,052,224 | ---- | C] (Microsoft Corporation)
hbaapi.dll -> C:\Windows\SysNative\hbaapi.dll -> [2009/09/17 04:38:35 | 00,051,200 | ---- | C] (Microsoft Corporation)
dot3cfg.dll -> C:\Windows\SysWow64\dot3cfg.dll -> [2009/09/17 04:38:35 | 00,049,664 | ---- | C] (Microsoft Corporation)
bthudtask.exe -> C:\Windows\SysWow64\bthudtask.exe -> [2009/09/17 04:38:35 | 00,034,304 | ---- | C] (Microsoft Corporation)
ipconfig.exe -> C:\Windows\SysWow64\ipconfig.exe -> [2009/09/17 04:38:35 | 00,026,624 | ---- | C] (Microsoft Corporation)
rasdial.exe -> C:\Windows\SysWow64\rasdial.exe -> [2009/09/17 04:38:35 | 00,016,896 | ---- | C] (Microsoft Corporation)
CHxReadingStringIME.dll -> C:\Windows\SysWow64\CHxReadingStringIME.dll -> [2009/09/17 04:38:35 | 00,010,752 | ---- | C] (Microsoft Corporation)
MSMPEG2ENC.DLL -> C:\Windows\SysWow64\MSMPEG2ENC.DLL -> [2009/09/17 04:38:34 | 00,506,880 | ---- | C] (Microsoft Corporation)
eappcfg.dll -> C:\Windows\SysNative\eappcfg.dll -> [2009/09/17 04:38:34 | 00,211,456 | ---- | C] (Microsoft Corporation)
SLLUA.exe -> C:\Windows\SysNative\SLLUA.exe -> [2009/09/17 04:38:34 | 00,190,464 | ---- | C] (Microsoft Corporation)
MSAC3ENC.DLL -> C:\Windows\SysWow64\MSAC3ENC.DLL -> [2009/09/17 04:38:34 | 00,160,256 | ---- | C] (Microsoft Corporation)
nslookup.exe -> C:\Windows\SysWow64\nslookup.exe -> [2009/09/17 04:38:34 | 00,082,944 | ---- | C] (Microsoft Corporation)
tscupgrd.exe -> C:\Windows\SysWow64\tscupgrd.exe -> [2009/09/17 04:38:34 | 00,063,488 | ---- | C] (Microsoft Corporation)
tscupgrd.exe -> C:\Windows\SysNative\tscupgrd.exe -> [2009/09/17 04:38:34 | 00,062,464 | ---- | C] (Microsoft Corporation)
networkitemfactory.dll -> C:\Windows\SysNative\networkitemfactory.dll -> [2009/09/17 04:38:34 | 00,052,224 | ---- | C] (Microsoft Corporation)
slcinst.dll -> C:\Windows\SysWow64\slcinst.dll -> [2009/09/17 04:38:34 | 00,042,496 | ---- | C] (Microsoft Corporation)
networkitemfactory.dll -> C:\Windows\SysWow64\networkitemfactory.dll -> [2009/09/17 04:38:34 | 00,039,936 | ---- | C] (Microsoft Corporation)
eappgnui.dll -> C:\Windows\SysNative\eappgnui.dll -> [2009/09/17 04:38:33 | 00,104,448 | ---- | C] (Microsoft Corporation)
eappgnui.dll -> C:\Windows\SysWow64\eappgnui.dll -> [2009/09/17 04:38:33 | 00,093,696 | ---- | C] (Microsoft Corporation)
fdeploy.dll -> C:\Windows\SysWow64\fdeploy.dll -> [2009/09/17 04:38:33 | 00,053,760 | ---- | C] (Microsoft Corporation)
slcinst.dll -> C:\Windows\SysNative\slcinst.dll -> [2009/09/17 04:38:33 | 00,046,592 | ---- | C] (Microsoft Corporation)
hbaapi.dll -> C:\Windows\SysWow64\hbaapi.dll -> [2009/09/17 04:38:33 | 00,041,472 | ---- | C] (Microsoft Corporation)
ocsetup.exe -> C:\Windows\SysNative\ocsetup.exe -> [2009/09/17 04:38:33 | 00,038,400 | ---- | C] (Microsoft Corporation)
ocsetup.exe -> C:\Windows\SysWow64\ocsetup.exe -> [2009/09/17 04:38:33 | 00,035,840 | ---- | C] (Microsoft Corporation)
FwRemoteSvr.dll -> C:\Windows\SysWow64\FwRemoteSvr.dll -> [2009/09/17 04:38:33 | 00,028,672 | ---- | C] (Microsoft Corporation)
msacm32.drv -> C:\Windows\SysNative\msacm32.drv -> [2009/09/17 04:38:33 | 00,025,600 | ---- | C] (Microsoft Corporation)
dfsc.sys -> C:\Windows\SysNative\drivers\dfsc.sys -> [2009/09/17 04:38:32 | 00,097,792 | ---- | C] (Microsoft Corporation)
bitsigd.dll -> C:\Windows\SysNative\bitsigd.dll -> [2009/09/17 04:38:32 | 00,046,592 | ---- | C] (Microsoft Corporation)
msacm32.drv -> C:\Windows\SysWow64\msacm32.drv -> [2009/09/17 04:38:32 | 00,021,504 | ---- | C] (Microsoft Corporation)
mmcico.dll -> C:\Windows\SysWow64\mmcico.dll -> [2009/09/17 04:38:32 | 00,012,800 | ---- | C] (Microsoft Corporation)
cbsra.exe -> C:\Windows\SysNative\cbsra.exe -> [2009/09/17 04:38:31 | 00,047,104 | ---- | C] (Microsoft Corporation)
wscapi.dll -> C:\Windows\SysNative\wscapi.dll -> [2009/09/17 04:38:31 | 00,040,448 | ---- | C] (Microsoft Corporation)
gpupdate.exe -> C:\Windows\SysWow64\gpupdate.exe -> [2009/09/17 04:38:31 | 00,016,896 | ---- | C] (Microsoft Corporation)
bthudtask.exe -> C:\Windows\SysNative\bthudtask.exe -> [2009/09/17 04:38:30 | 00,035,840 | ---- | C] (Microsoft Corporation)
NcdProp.dll -> C:\Windows\SysWow64\NcdProp.dll -> [2009/09/17 04:38:30 | 00,019,968 | ---- | C] (Microsoft Corporation)
iscsilog.dll -> C:\Windows\SysNative\iscsilog.dll -> [2009/09/17 04:38:30 | 00,016,384 | ---- | C] (Microsoft Corporation)
vss_ps.dll -> C:\Windows\SysNative\vss_ps.dll -> [2009/09/17 04:38:29 | 00,060,416 | ---- | C] (Microsoft Corporation)
odbcconf.dll -> C:\Windows\SysNative\odbcconf.dll -> [2009/09/17 04:38:29 | 00,045,056 | ---- | C] (Microsoft Corporation)
odbcconf.dll -> C:\Windows\SysWow64\odbcconf.dll -> [2009/09/17 04:38:29 | 00,040,960 | ---- | C] (Microsoft Corporation)
vdmdbg.dll -> C:\Windows\SysWow64\vdmdbg.dll -> [2009/09/17 04:38:29 | 00,017,408 | ---- | C] (Microsoft Corporation)
inetppui.dll -> C:\Windows\SysNative\inetppui.dll -> [2009/09/17 04:38:29 | 00,017,408 | ---- | C] (Microsoft Corporation)
wmpps.dll -> C:\Windows\SysWow64\wmpps.dll -> [2009/09/17 04:38:28 | 00,131,072 | ---- | C] (Microsoft Corporation)
RNDISMP.sys -> C:\Windows\SysNative\drivers\RNDISMP.sys -> [2009/09/17 04:38:28 | 00,040,960 | ---- | C] (Microsoft Corporation)
winrnr.dll -> C:\Windows\SysWow64\winrnr.dll -> [2009/09/17 04:38:28 | 00,019,968 | ---- | C] (Microsoft Corporation)
usb8023.sys -> C:\Windows\SysNative\drivers\usb8023.sys -> [2009/09/17 04:38:28 | 00,019,456 | ---- | C] (Microsoft Corporation)
slwga.dll -> C:\Windows\SysWow64\slwga.dll -> [2009/09/17 04:38:28 | 00,012,288 | ---- | C] (Microsoft Corporation)
cdrom.sys -> C:\Windows\SysNative\drivers\cdrom.sys -> [2009/09/17 04:38:27 | 00,079,872 | ---- | C] (Microsoft Corporation)
usbohci.sys -> C:\Windows\SysNative\drivers\usbohci.sys -> [2009/09/17 04:38:27 | 00,024,064 | ---- | C] (Microsoft Corporation)
midimap.dll -> C:\Windows\SysNative\midimap.dll -> [2009/09/17 04:38:27 | 00,020,480 | ---- | C] (Microsoft Corporation)
midimap.dll -> C:\Windows\SysWow64\midimap.dll -> [2009/09/17 04:38:27 | 00,017,408 | ---- | C] (Microsoft Corporation)
stream.sys -> C:\Windows\SysNative\drivers\stream.sys -> [2009/09/17 04:38:24 | 00,068,224 | ---- | C] (Microsoft Corporation)
Diskdump.sys -> C:\Windows\SysNative\drivers\Diskdump.sys -> [2009/09/17 04:38:24 | 00,019,968 | ---- | C] (Microsoft Corporation)
html.iec -> C:\Windows\SysNative\html.iec -> [2009/09/17 04:38:23 | 00,485,376 | ---- | C] (Microsoft Corporation)
html.iec -> C:\Windows\SysWow64\html.iec -> [2009/09/17 04:38:23 | 00,389,632 | ---- | C] (Microsoft Corporation)
raspppoe.sys -> C:\Windows\SysNative\drivers\raspppoe.sys -> [2009/09/17 04:38:23 | 00,050,176 | ---- | C] (Microsoft Corporation)
wow64cpu.dll -> C:\Windows\SysNative\wow64cpu.dll -> [2009/09/17 04:38:23 | 00,017,408 | ---- | C] (Microsoft Corporation)
f3ahvoas.dll -> C:\Windows\SysNative\f3ahvoas.dll -> [2009/09/17 04:38:22 | 00,033,280 | ---- | C] (Microsoft Corporation)
f3ahvoas.dll -> C:\Windows\SysWow64\f3ahvoas.dll -> [2009/09/17 04:38:22 | 00,007,680 | ---- | C] (Microsoft Corporation)
msimsg.dll -> C:\Windows\SysWow64\msimsg.dll -> [2009/09/17 04:38:22 | 00,002,560 | ---- | C] (Microsoft Corporation)
msimsg.dll -> C:\Windows\SysNative\msimsg.dll -> [2009/09/17 04:38:22 | 00,002,560 | ---- | C] (Microsoft Corporation)
wdscore.dll -> C:\Windows\SysWow64\wdscore.dll -> [2009/09/17 04:38:02 | 00,218,624 | ---- | C] (Microsoft Corporation)
drvstore.dll -> C:\Windows\SysWow64\drvstore.dll -> [2009/09/17 04:37:56 | 00,247,808 | ---- | C] (Microsoft Corporation)
SmiEngine.dll -> C:\Windows\SysNative\SmiEngine.dll -> [2009/09/17 04:37:21 | 00,936,448 | ---- | C] (Microsoft Corporation)
wdscore.dll -> C:\Windows\SysNative\wdscore.dll -> [2009/09/17 04:37:19 | 00,293,888 | ---- | C] (Microsoft Corporation)
PkgMgr.exe -> C:\Windows\SysNative\PkgMgr.exe -> [2009/09/17 04:37:19 | 00,138,752 | ---- | C] (Microsoft Corporation)
drvstore.dll -> C:\Windows\SysNative\drvstore.dll -> [2009/09/17 04:37:12 | 00,315,904 | ---- | C] (Microsoft Corporation)
Ricky -> C:\Users\Yolanda\Documents\Ricky -> [2009/09/10 11:48:54 | 00,000,000 | ---D | C]
jscript.dll -> C:\Windows\SysNative\jscript.dll -> [2009/09/09 08:31:20 | 00,756,224 | ---- | C] (Microsoft Corporation)
jscript.dll -> C:\Windows\SysWow64\jscript.dll -> [2009/09/09 08:31:20 | 00,512,000 | ---- | C] (Microsoft Corporation)
WMVCORE.DLL -> C:\Windows\SysNative\WMVCORE.DLL -> [2009/09/09 08:31:12 | 02,900,480 | ---- | C] (Microsoft Corporation)
mf.dll -> C:\Windows\SysNative\mf.dll -> [2009/09/09 08:31:11 | 03,547,136 | ---- | C] (Microsoft Corporation)
WMVCORE.DLL -> C:\Windows\SysWow64\WMVCORE.DLL -> [2009/09/09 08:31:11 | 02,386,944 | ---- | C] (Microsoft Corporation)
mf.dll -> C:\Windows\SysWow64\mf.dll -> [2009/09/09 08:31:10 | 02,868,224 | ---- | C] (Microsoft Corporation)
mfps.dll -> C:\Windows\SysNative\mfps.dll -> [2009/09/09 08:31:09 | 00,194,560 | ---- | C] (Microsoft Corporation)
mfps.dll -> C:\Windows\SysWow64\mfps.dll -> [2009/09/09 08:31:09 | 00,098,816 | ---- | C] (Microsoft Corporation)
rrinstaller.exe -> C:\Windows\SysNative\rrinstaller.exe -> [2009/09/09 08:31:09 | 00,060,416 | ---- | C] (Microsoft Corporation)
rrinstaller.exe -> C:\Windows\SysWow64\rrinstaller.exe -> [2009/09/09 08:31:09 | 00,053,248 | ---- | C] (Microsoft Corporation)
mfpmp.exe -> C:\Windows\SysNative\mfpmp.exe -> [2009/09/09 08:31:08 | 00,034,304 | ---- | C] (Microsoft Corporation)
mfpmp.exe -> C:\Windows\SysWow64\mfpmp.exe -> [2009/09/09 08:31:08 | 00,024,576 | ---- | C] (Microsoft Corporation)
mferror.dll -> C:\Windows\SysWow64\mferror.dll -> [2009/09/09 08:31:07 | 00,002,048 | ---- | C] (Microsoft Corporation)
mferror.dll -> C:\Windows\SysNative\mferror.dll -> [2009/09/09 08:31:07 | 00,002,048 | ---- | C] (Microsoft Corporation)
tcpip.sys -> C:\Windows\SysNative\drivers\tcpip.sys -> [2009/09/09 08:30:45 | 01,425,992 | ---- | C] (Microsoft Corporation)
netiohlp.dll -> C:\Windows\SysNative\netiohlp.dll -> [2009/09/09 08:30:44 | 00,143,360 | ---- | C] (Microsoft Corporation)
netiohlp.dll -> C:\Windows\SysWow64\netiohlp.dll -> [2009/09/09 08:30:43 | 00,105,984 | ---- | C] (Microsoft Corporation)
tcpipreg.sys -> C:\Windows\SysNative\drivers\tcpipreg.sys -> [2009/09/09 08:30:43 | 00,040,448 | ---- | C] (Microsoft Corporation)
NETSTAT.EXE -> C:\Windows\SysNative\NETSTAT.EXE -> [2009/09/09 08:30:42 | 00,032,256 | ---- | C] (Microsoft Corporation)
ARP.EXE -> C:\Windows\SysNative\ARP.EXE -> [2009/09/09 08:30:42 | 00,023,040 | ---- | C] (Microsoft Corporation)
NETSTAT.EXE -> C:\Windows\SysWow64\NETSTAT.EXE -> [2009/09/09 08:30:41 | 00,027,136 | ---- | C] (Microsoft Corporation)
ARP.EXE -> C:\Windows\SysWow64\ARP.EXE -> [2009/09/09 08:30:41 | 00,019,968 | ---- | C] (Microsoft Corporation)
MRINFO.EXE -> C:\Windows\SysNative\MRINFO.EXE -> [2009/09/09 08:30:41 | 00,012,800 | ---- | C] (Microsoft Corporation)
finger.exe -> C:\Windows\SysWow64\finger.exe -> [2009/09/09 08:30:40 | 00,010,240 | ---- | C] (Microsoft Corporation)
TCPSVCS.EXE -> C:\Windows\SysWow64\TCPSVCS.EXE -> [2009/09/09 08:30:40 | 00,009,728 | ---- | C] (Microsoft Corporation)
HOSTNAME.EXE -> C:\Windows\SysWow64\HOSTNAME.EXE -> [2009/09/09 08:30:40 | 00,008,704 | ---- | C] (Microsoft Corporation)
MRINFO.EXE -> C:\Windows\SysWow64\MRINFO.EXE -> [2009/09/09 08:30:39 | 00,011,264 | ---- | C] (Microsoft Corporation)
finger.exe -> C:\Windows\SysNative\finger.exe -> [2009/09/09 08:30:39 | 00,011,264 | ---- | C] (Microsoft Corporation)
TCPSVCS.EXE -> C:\Windows\SysNative\TCPSVCS.EXE -> [2009/09/09 08:30:39 | 00,010,752 | ---- | C] (Microsoft Corporation)
HOSTNAME.EXE -> C:\Windows\SysNative\HOSTNAME.EXE -> [2009/09/09 08:30:39 | 00,010,240 | ---- | C] (Microsoft Corporation)
ROUTE.EXE -> C:\Windows\SysNative\ROUTE.EXE -> [2009/09/09 08:30:38 | 00,021,504 | ---- | C] (Microsoft Corporation)
ROUTE.EXE -> C:\Windows\SysWow64\ROUTE.EXE -> [2009/09/09 08:30:38 | 00,017,920 | ---- | C] (Microsoft Corporation)
netevent.dll -> C:\Windows\SysWow64\netevent.dll -> [2009/09/09 08:30:36 | 00,017,920 | ---- | C] (Microsoft Corporation)
netevent.dll -> C:\Windows\SysNative\netevent.dll -> [2009/09/09 08:30:36 | 00,017,920 | ---- | C] (Microsoft Corporation)
wlansvc.dll -> C:\Windows\SysNative\wlansvc.dll -> [2009/09/09 08:29:28 | 00,615,936 | ---- | C] (Microsoft Corporation)
wlanmsm.dll -> C:\Windows\SysNative\wlanmsm.dll -> [2009/09/09 08:29:28 | 00,353,280 | ---- | C] (Microsoft Corporation)
wlansec.dll -> C:\Windows\SysNative\wlansec.dll -> [2009/09/09 08:29:27 | 00,376,832 | ---- | C] (Microsoft Corporation)
wlanmsm.dll -> C:\Windows\SysWow64\wlanmsm.dll -> [2009/09/09 08:29:27 | 00,293,376 | ---- | C] (Microsoft Corporation)
L2SecHC.dll -> C:\Windows\SysNative\L2SecHC.dll -> [2009/09/09 08:29:27 | 00,157,184 | ---- | C] (Microsoft Corporation)
wlanhlp.dll -> C:\Windows\SysNative\wlanhlp.dll -> [2009/09/09 08:29:27 | 00,097,792 | ---- | C] (Microsoft Corporation)
wlanhlp.dll -> C:\Windows\SysWow64\wlanhlp.dll -> [2009/09/09 08:29:27 | 00,068,096 | ---- | C] (Microsoft Corporation)
wlansec.dll -> C:\Windows\SysWow64\wlansec.dll -> [2009/09/09 08:29:26 | 00,302,592 | ---- | C] (Microsoft Corporation)
L2SecHC.dll -> C:\Windows\SysWow64\L2SecHC.dll -> [2009/09/09 08:29:26 | 00,127,488 | ---- | C] (Microsoft Corporation)
wlanapi.dll -> C:\Windows\SysNative\wlanapi.dll -> [2009/09/09 08:29:26 | 00,086,528 | ---- | C] (Microsoft Corporation)
wlanapi.dll -> C:\Windows\SysWow64\wlanapi.dll -> [2009/09/09 08:29:26 | 00,065,024 | ---- | C] (Microsoft Corporation)
Interop.IWshRuntimeLibrary.dll -> C:\Windows\Interop.IWshRuntimeLibrary.dll -> [2009/03/13 21:28:09 | 00,049,152 | ---- | C] ( )
 
[Files/Folders - Modified Within 30 Days]
17 C:\Users\Yolanda\AppData\Local\Temp\*.tmp files -> C:\Users\Yolanda\AppData\Local\Temp\*.tmp -> 
NTUSER.DAT -> C:\Users\Yolanda\NTUSER.DAT -> [2009/10/07 14:02:46 | 02,621,440 | -HS- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2009/10/07 13:40:00 | 00,000,898 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2009/10/07 13:19:16 | 00,003,216 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2009/10/07 13:19:16 | 00,003,216 | -H-- | M] ()
HijackThis.lnk -> C:\Users\Yolanda\Desktop\HijackThis.lnk -> [2009/10/07 10:25:10 | 00,001,932 | ---- | M] ()
Google Software Updater.job -> C:\Windows\tasks\Google Software Updater.job -> [2009/10/07 10:08:10 | 00,000,880 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2009/10/06 20:51:38 | 00,000,894 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2009/10/05 09:24:13 | 00,690,960 | ---- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2009/10/05 09:24:13 | 00,595,446 | ---- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2009/10/05 09:24:13 | 00,101,144 | ---- | M] ()
Config.MPF -> C:\Windows\SysNative\Config.MPF -> [2009/10/05 09:19:53 | 00,023,955 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2009/10/05 09:19:11 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2009/10/05 09:19:08 | 00,067,584 | ---- | M] ()
wrSpySweeper_L9B99D5E5473E4E98B1969FBCED88C7CC.job -> C:\Windows\tasks\wrSpySweeper_L9B99D5E5473E4E98B1969FBCED88C7CC.job -> [2009/10/05 01:00:02 | 00,001,696 | ---- | M] ()
wklnhst.dat -> C:\Users\Yolanda\AppData\Roaming\wklnhst.dat -> [2009/10/01 17:13:05 | 00,000,534 | ---- | M] ()
MpSigStub.exe -> C:\Windows\SysNative\MpSigStub.exe -> [2009/10/01 10:29:14 | 00,238,960 | ---- | M] (Microsoft Corporation)
McQcTask.job -> C:\Windows\tasks\McQcTask.job -> [2009/10/01 01:00:00 | 00,000,348 | ---- | M] ()
NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Yolanda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms -> [2009/09/30 21:25:57 | 00,524,288 | -HS- | M] ()
NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf -> C:\Users\Yolanda\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf -> [2009/09/30 21:25:57 | 00,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\Yolanda\AppData\Local\IconCache.db -> [2009/09/25 22:44:01 | 02,025,919 | -H-- | M] ()
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2009/09/18 13:58:57 | 00,296,016 | ---- | M] ()
McDefragTask.job -> C:\Windows\tasks\McDefragTask.job -> [2009/09/15 01:00:00 | 00,000,356 | ---- | M] ()
 
[Files - No Company Name]
HijackThis.lnk -> C:\Users\Yolanda\Desktop\HijackThis.lnk -> [2009/10/07 10:25:10 | 00,001,932 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\SysNative\EhStorAuthn.dll -> [2009/09/17 04:40:37 | 00,121,856 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\SysWow64\EhStorAuthn.dll -> [2009/09/17 04:40:37 | 00,117,248 | ---- | C] ()
systemsf.ebd -> C:\Windows\SysNative\systemsf.ebd -> [2009/09/17 04:40:25 | 00,262,552 | ---- | C] ()
dot3.tmf -> C:\Windows\SysNative\dot3.tmf -> [2009/09/17 04:40:03 | 00,471,992 | ---- | C] ()
eaphost.tmf -> C:\Windows\SysNative\eaphost.tmf -> [2009/09/17 04:40:02 | 00,700,507 | ---- | C] ()
StructuredQuerySchema.bin -> C:\Windows\SysWow64\StructuredQuerySchema.bin -> [2009/09/17 04:39:59 | 00,107,612 | ---- | C] ()
StructuredQuerySchema.bin -> C:\Windows\SysNative\StructuredQuerySchema.bin -> [2009/09/17 04:39:59 | 00,107,612 | ---- | C] ()
locale.nls -> C:\Windows\SysWow64\locale.nls -> [2009/09/17 04:39:56 | 03,662,128 | ---- | C] ()
locale.nls -> C:\Windows\SysNative\locale.nls -> [2009/09/17 04:39:56 | 03,662,128 | ---- | C] ()
onex.tmf -> C:\Windows\SysNative\onex.tmf -> [2009/09/17 04:39:56 | 00,395,723 | ---- | C] ()
WFP.TMF -> C:\Windows\SysNative\WFP.TMF -> [2009/09/17 04:39:31 | 00,207,968 | ---- | C] ()
slmgr.vbs -> C:\Windows\SysWow64\slmgr.vbs -> [2009/09/17 04:39:29 | 00,092,918 | ---- | C] ()
slmgr.vbs -> C:\Windows\SysNative\slmgr.vbs -> [2009/09/17 04:39:29 | 00,092,918 | ---- | C] ()
msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2009/09/17 04:39:25 | 00,368,640 | ---- | C] ()
spcinstrumentation.man -> C:\Windows\SysWow64\spcinstrumentation.man -> [2009/09/17 04:38:57 | 00,009,239 | ---- | C] ()
spcinstrumentation.man -> C:\Windows\SysNative\spcinstrumentation.man -> [2009/09/17 04:38:57 | 00,009,239 | ---- | C] ()
RacUR.xml -> C:\Windows\SysWow64\RacUR.xml -> [2009/09/17 04:38:27 | 00,009,212 | ---- | C] ()
RacUR.xml -> C:\Windows\SysNative\RacUR.xml -> [2009/09/17 04:38:27 | 00,009,212 | ---- | C] ()
wlan.tmf -> C:\Windows\SysNative\wlan.tmf -> [2009/09/09 08:29:29 | 02,608,861 | ---- | C] ()
d3d9caps.dat -> C:\Users\Yolanda\AppData\Local\d3d9caps.dat -> [2009/09/02 16:00:47 | 00,000,680 | ---- | C] ()
nss16A5.dll -> C:\Windows\SysWow64\nss16A5.dll -> [2009/06/01 04:54:54 | 01,350,656 | ---- | C] ()
wklnhst.dat -> C:\Users\Yolanda\AppData\Roaming\wklnhst.dat -> [2009/05/18 14:11:41 | 00,000,534 | ---- | C] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\Yolanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/05/10 11:17:26 | 00,005,632 | ---- | C] ()
UserTile.png -> C:\Users\Yolanda\AppData\Roaming\UserTile.png -> [2009/05/10 11:12:35 | 00,024,226 | ---- | C] ()
IconCache.db -> C:\Users\Yolanda\AppData\Local\IconCache.db -> [2009/05/05 14:24:56 | 02,025,919 | -H-- | C] ()
GDIPFONTCACHEV1.DAT -> C:\Users\Yolanda\AppData\Local\GDIPFONTCACHEV1.DAT -> [2009/05/05 13:27:23 | 00,070,104 | ---- | C] ()
wrLZMA.dll -> C:\Windows\SysWow64\wrLZMA.dll -> [2009/04/21 18:26:56 | 00,031,088 | ---- | C] ()
NTIOFM4.dll -> C:\Windows\SysWow64\NTIOFM4.dll -> [2009/03/13 22:05:40 | 00,001,024 | RH-- | C] ()
NTIBUN5.dll -> C:\Windows\SysWow64\NTIBUN5.dll -> [2009/03/13 22:05:40 | 00,001,024 | RH-- | C] ()
tcpmon.ini -> C:\Windows\SysWow64\tcpmon.ini -> [2008/01/20 22:50:05 | 00,060,124 | ---- | C] ()
desktop.ini -> C:\Program Files\desktop.ini -> [2006/11/02 11:25:49 | 00,000,174 | -HS- | C] ()
desktop.ini -> C:\Program Files (x86)\desktop.ini -> [2006/11/02 11:25:49 | 00,000,174 | -HS- | C] ()
system.ini -> C:\Windows\system.ini -> [2006/11/02 08:34:27 | 00,000,219 | ---- | C] ()
win.ini -> C:\Windows\win.ini -> [2006/11/02 08:34:27 | 00,000,211 | ---- | C] ()
Acer(Normal).ini -> C:\Windows\Acer(Normal).ini -> [2006/10/10 22:09:24 | 00,000,044 | ---- | C] ()
Acer(Wide).ini -> C:\Windows\Acer(Wide).ini -> [2006/10/10 22:09:24 | 00,000,042 | ---- | C] ()
UNACEV2.DLL -> C:\Windows\SysWow64\UNACEV2.DLL -> [2002/03/21 15:39:02 | 00,073,728 | ---- | C] ()
multiplex_vcd.dll -> C:\Windows\SysWow64\multiplex_vcd.dll -> [2001/12/26 19:12:30 | 00,065,536 | ---- | C] ()
Hmpg12.dll -> C:\Windows\SysWow64\Hmpg12.dll -> [2001/09/04 02:46:38 | 00,110,592 | ---- | C] ()
HMPV2_ENC.dll -> C:\Windows\SysWow64\HMPV2_ENC.dll -> [2001/07/30 19:33:56 | 00,118,784 | ---- | C] ()
HMPV2_ENC_MMX.dll -> C:\Windows\SysWow64\HMPV2_ENC_MMX.dll -> [2001/07/24 01:04:36 | 00,118,784 | ---- | C] ()
 
[File - Lop Check]
 
[File - Purity Scan]
 
 
[Alternate Data Streams]
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:193426B4
< End of report >


#6 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 07 October 2009 - 12:41 PM

Hi,

Please do the following:

Start OTS

Copy/Paste
the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< FireFox Settings [Prefs.js] > -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\prefs.js
YN -> browser.search.defaultenginename -> "Fast Browser Search"
YN -> browser.search.defaultthis.engineName -> "CommentsBar - Social Comments Customized Web Search"
YN -> browser.search.defaulturl -> "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=13&q="
YN -> browser.search.order.1 -> "Fast Browser Search"
YN -> browser.search.selectedEngine -> "Fast Browser Search"
YN -> keyword.URL -> "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=13&tid={B87C538B-2BE7-BA59-95CD-7CE04D8C471B}&q="
< FireFox SearchPlugins [User Folders] > -> 
YY -> fast-browser-search.xml -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\fast-browser-search.xml
YY -> MyStart Search.xml -> C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\MyStart Search.xml
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\] > -> HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
[Files/Folders - Modified Within 30 Days]
NY -> 17 C:\Users\Yolanda\AppData\Local\Temp\*.tmp files -> C:\Users\Yolanda\AppData\Local\Temp\*.tmp
[Empty Temp Folders]
[Start Explorer]
[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


NEXT

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    Posted Image
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply



In your next reply please include
  • OTS Log
  • MBAM log
  • Kaspersky report

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#7 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 07 October 2009 - 04:45 PM

OTS results: All Processes Killed [Registry - Safe List] Prefs.js: "Fast Browser Search" removed from browser.search.defaultenginename Prefs.js: "CommentsBar - Social Comments Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "http://www.fastbrows...?s=DEF&v=13&q=" removed from browser.search.defaulturl Prefs.js: "Fast Browser Search" removed from browser.search.order.1 Prefs.js: "Fast Browser Search" removed from browser.search.selectedEngine Prefs.js: "http://www.fastbrows...E04D8C471B}&q=" removed from keyword.URL C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\fast-browser-search.xml moved successfully. C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\MyStart Search.xml moved successfully. Registry value HKEY_USERS\S-1-5-21-587824317-523569438-2809485909-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}\ not found. [Files/Folders - Modified Within 30 Days] [Empty Temp Folders] User: All Users User: Andrew ->Temp folder emptied: 4533469 bytes File delete failed. C:\Users\Andrew\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 2922027 bytes ->Java cache emptied: 915430 bytes ->FireFox cache emptied: 99434400 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Yolanda ->Temp folder emptied: 19691301 bytes File delete failed. C:\Users\Yolanda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33107979 bytes ->Java cache emptied: 24463086 bytes ->FireFox cache emptied: 46867967 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes File delete failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcafee_DHVFHu7ZGNPSsEX scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcafee_M7Ks55Uj3DVe6ER scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_8sKb2suIlNFZ4Am scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_lpRm2zb8bzcRnCf scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_UJG3QAicMgMivxR scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_47lqEEsjf1tUscf scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_fbnsBqYgia7LusS scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_hEscWbDmkFAcrMk scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_q0mfpL9JTbOugoo scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_QWiXbccOmM35QXs scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_rrdf5N62WVrO0Gx scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_XRVImHerFKm4to4 scheduled to be deleted on reboot. Windows Temp folder emptied: 27637583 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 247.58 mb < End of fix log > OTS by OldTimer - Version 3.0.20.3 fix logfile created on 10072009_145417 Files\Folders moved on Reboot... File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot. File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot. File\Folder C:\Windows\temp\mcafee_DHVFHu7ZGNPSsEX not found! File\Folder C:\Windows\temp\mcafee_M7Ks55Uj3DVe6ER not found! File\Folder C:\Windows\temp\mcmsc_8sKb2suIlNFZ4Am not found! File\Folder C:\Windows\temp\mcmsc_lpRm2zb8bzcRnCf not found! File\Folder C:\Windows\temp\mcmsc_UJG3QAicMgMivxR not found! File\Folder C:\Windows\temp\sqlite_47lqEEsjf1tUscf not found! File\Folder C:\Windows\temp\sqlite_fbnsBqYgia7LusS not found! C:\Windows\temp\sqlite_hEscWbDmkFAcrMk moved successfully. File\Folder C:\Windows\temp\sqlite_q0mfpL9JTbOugoo not found! File\Folder C:\Windows\temp\sqlite_QWiXbccOmM35QXs not found! C:\Windows\temp\sqlite_rrdf5N62WVrO0Gx moved successfully. C:\Windows\temp\sqlite_XRVImHerFKm4to4 moved successfully. Registry entries deleted on Reboot... Malwarebytes' Anti-Malware 1.41 Database version: 2775 Windows 6.0.6002 Service Pack 2 10/7/2009 3:20:02 PM mbam-log-2009-10-07 (15-20-02).txt Scan type: Quick Scan Objects scanned: 86874 Time elapsed: 3 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, October 7, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, October 07, 2009 22:22:25 Records in database: 2930975 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ F:\ G:\ H:\ Scan statistics: Objects scanned: 133095 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:37:31 No threats found. Scanned area is clean. Selected area has been scanned.

#8 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 07 October 2009 - 06:26 PM

Please do the following:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.


Also, please advise how your computer is running now and if there are any outstanding issues

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#9 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 08 October 2009 - 08:18 AM

Firefox has been shutting down randomly along with the other problems.
Here are the logs:

OTL logfile created on: 10/8/2009 9:38:01 AM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Users\Yolanda\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.34 Gb Available Physical Memory | 58.52% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 289.58 Gb Total Space | 215.64 Gb Free Space | 74.47% Space Free | Partition Type: NTFS
Drive D: | 291.59 Gb Total Space | 280.51 Gb Free Space | 96.20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 702.31 Mb Total Space | 696.61 Mb Free Space | 99.19% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOLANDA-PC
Current User Name: Yolanda
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\a-squared Free\a2service.exe (Emsi Software GmbH)
PRC - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)
PRC - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)
PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe ()
PRC - c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems, Ltd.)
PRC - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20.exe (GCNet Incorporated)
PRC - C:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20.exe (GCNet Incorporated)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe (Egis inc.)
PRC - C:\Program Files (x86)\IncrediMail\bin\IMApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Users\Yolanda\Downloads\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV:64bit: - (AgereModemAudio [Auto | Running]) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (ETService [Auto | Running]) -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV:64bit: - (McODS [On_Demand | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV:64bit: - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (a2free [Auto | Running]) -- C:\Program Files (x86)\a-squared Free\a2service.exe (Emsi Software GmbH)
SRV - (Acer HomeMedia Connect Service [Auto | Running]) -- C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)
SRV - (BUNAgentSvc [Auto | Running]) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (eDataSecurity Service [Auto | Running]) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c9f45e48d84d6e [Auto | Stopped]) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [Auto | Stopped]) -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (KeyIso [On_Demand | Stopped]) -- C:\Windows\SysWow64\keyiso.dll (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (McAfee SiteAdvisor Service [Auto | Running]) -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSDTC [Unknown | Stopped]) -- C:\Windows\SysWow64\Msdtc [2006/11/02 09:34:14 | 00,000,000 | ---D | M]
SRV - (MSK80Service [Auto | Running]) -- C:\Program Files (x86)\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (Netlogon [On_Demand | Stopped]) -- C:\Windows\SysWow64\netlogon.dll (Microsoft Corporation)
SRV - (NTIBackupSvc [Auto | Running]) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (NTISchedulerSvc [Auto | Running]) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RichVideo [Auto | Running]) -- C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe ()
SRV - (vds [On_Demand | Stopped]) -- C:\Windows\SysWow64\Wbem\vds.mof ()
SRV - (VSS [On_Demand | Stopped]) -- C:\Windows\SysWow64\Wbem\vss.mof ()
SRV - (WebrootSpySweeperService [Auto | Running]) -- C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (WRConsumerService [Auto | Running]) -- C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )

========== Driver Services (SafeList) ==========

DRV:64bit: - (AgereSoftModem [On_Demand | Running]) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV:64bit: - (HdAudAddService [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (ITEIO.SYS [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\ITEIO.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (mfeavfk [On_Demand | Running]) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk [System | Running]) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdk [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\mferkdk.sys (McAfee, Inc.)
DRV:64bit: - (mfesmfk [On_Demand | Running]) -- C:\Windows\SysNative\drivers\mfesmfk.sys (McAfee, Inc.)
DRV:64bit: - (MPFP [System | Running]) -- C:\Windows\SysNative\Drivers\Mpfp.sys (McAfee, Inc.)
DRV:64bit: - (NTIDrvr [On_Demand | Running]) -- C:\Windows\SysNative\Drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (NVHDA [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (PSDFilter [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\psdfilter.sys (Egis Incorporated)
DRV:64bit: - (PSDNServ [Auto | Running]) -- C:\Windows\SysNative\DRIVERS\PSDNServ.sys (Egis Incorporated)
DRV:64bit: - (psdvdisk [Auto | Running]) -- C:\Windows\SysNative\DRIVERS\PSDVdisk.sys (Egis Incorporated)
DRV:64bit: - (ssfs0bbc [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssidrv [Boot | Running]) -- C:\Windows\SysNative\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (UBHelper [Boot | Running]) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (WSVD [On_Demand | Stopped]) -- C:\Windows\SysNative\drivers\WSVD.sys (CyberLink)
DRV - (int15 [Auto | Running]) -- C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)
DRV - (mpsdrv [On_Demand | Running]) -- C:\Windows\SysWow64\Wbem\mpsdrv.mof ()
DRV - (PSDFilter [Boot | Running]) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDFilter.inf ()
DRV - (PSDNServ [Auto | Running]) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDNserv.inf ()
DRV - (psdvdisk [Auto | Running]) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\PSDVDisk.inf ()
DRV - (Tcpip [System | Running]) -- C:\Windows\SysWow64\Wbem\tcpip.mof ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...;m=aspire_x1700
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...;m=aspire_x1700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...;m=aspire_x1700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer...;m=aspire_x1700

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...;m=aspire_x1700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.winstonsa...craigslist.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrows...?s=DEF&v=13&q="
FF - prefs.js..browser.search.order.1: "Fast Browser Search"
FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://winstonsalem....raigslist.org/"
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.3.0
FF - prefs.js..extensions.enabledItems: {47624dda-b77e-4feb-820a-e4f077d5d4ca}:9.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}:2.2.5
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.2.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..keyword.URL: "http://www.fastbrows...E04D8C471B}&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 03:00:36 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2009/08/29 21:22:58 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/09/12 11:00:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/09/12 11:00:43 | 00,000,000 | ---D | M]

[2009/05/16 17:30:46 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions
[2009/05/05 15:37:22 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/16 17:30:46 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2009/10/07 14:02:57 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions
[2009/09/02 15:06:50 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/15 14:44:06 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca}
[2009/07/08 14:24:20 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/07/08 14:24:20 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2009/07/08 14:24:13 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\anycolor.pavlos256@gmail.com
[2009/09/15 14:44:08 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\mozilla\Firefox\Profiles\a88mzj9q.default\extensions\personas@christopher.beard
[2009/07/16 18:09:38 | 00,000,920 | ---- | M] () -- C:\Users\Yolanda\AppData\Roaming\Mozilla\FireFox\Profiles\a88mzj9q.default\searchplugins\conduit.xml
[2009/08/08 20:31:28 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2009/09/12 11:00:43 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/16 17:30:19 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/06/23 10:42:22 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/08 20:31:28 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/12 11:00:37 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/09/12 11:00:37 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/07/25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2009/02/06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/09/12 11:00:41 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/02 11:21:40 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/02 11:21:41 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/02 11:21:41 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2009/08/29 10:01:39 | 00,001,394 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/08/29 10:01:39 | 00,002,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/08/29 10:01:39 | 00,001,534 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/08/29 10:01:39 | 00,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/06/13 17:11:39 | 00,003,700 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fast.png
[2009/06/13 17:11:39 | 00,001,963 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fast.xml
[2009/08/29 10:01:39 | 00,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/08/29 10:01:39 | 00,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/08/29 10:01:39 | 00,000,792 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Lau File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Windows\Skytel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe File not found
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BkupTray] C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Device Detector] File not found
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - HKCU..\Run: [Zilla Popup Killer] C:\Program Files (x86)\Zilla Popup Killer\ZillaPop.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm ()
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files (x86)\IncrediMail\bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysNative\NLAapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysNative\napinsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWow64\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWow64\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWow64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWow64\pnrpnsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\msvidctl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O18:64bit: - Protocol\Filter: - application/octet-stream - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - application/x-complus - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - application/x-msdownload - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - deflate - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - gzip - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~2\squsi\squsit~1\squsi20stb.dll) - c:\Program Files (x86)\sQusi\sQusi Tracking Plus\sQusi20Stb.dll (GCNet Incorporated)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (ows\S) - File not found
O30 - LSA: Authentication Packages - (ows\S) - File not found
O30:64bit: - LSA: Security Packages - (T2㐀㠵ᘨ) - File not found
O30:64bit: - LSA: Security Packages - (協歰⹧汤l<뻯㠵ᘨ㠵ᘨ&) - File not found
O30:64bit: - LSA: Security Packages - (P) - File not found
O30:64bit: - LSA: Security Packages - () - File not found
O30 - LSA: Security Packages - (T2㐀㠵ᘨ) - File not found
O30 - LSA: Security Packages - (協歰⹧汤l<뻯㠵ᘨ㠵ᘨ&) - File not found
O30 - LSA: Security Packages - (P) - File not found
O30 - LSA: Security Packages - () - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/10/07 10:25:10 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2009/09/16 21:11:02 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/10/07 14:54:17 | 00,000,000 | ---D | C] -- C:\_OTS
[2009/10/02 19:07:58 | 00,238,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe
[2009/09/18 13:55:02 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\vi-VN
[2009/09/18 13:55:02 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\eu-ES
[2009/09/18 13:55:02 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\ca-ES
[2009/09/18 13:55:02 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\eu-ES
[2009/09/18 13:55:02 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\ca-ES
[2009/09/18 13:55:01 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\vi-VN
[2009/09/18 13:14:31 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[2009/09/18 13:06:44 | 01,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2009/09/18 13:06:43 | 00,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kerberos.dll
[2009/09/18 13:06:43 | 00,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msv1_0.dll
[2009/09/18 13:06:42 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kerberos.dll
[2009/09/18 13:06:42 | 00,205,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdigest.dll
[2009/09/18 13:06:41 | 00,515,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecdd.sys
[2009/09/18 13:06:41 | 00,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schannel.dll
[2009/09/18 13:06:41 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msv1_0.dll
[2009/09/18 13:06:41 | 00,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdigest.dll
[2009/09/18 13:06:40 | 00,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\schannel.dll
[2009/09/18 13:06:40 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2009/09/18 13:06:40 | 00,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secur32.dll
[2009/09/18 13:06:39 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsass.exe
[2009/09/17 04:41:11 | 12,240,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NlsLexicons0007.dll
[2009/09/17 04:41:11 | 12,240,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NlsLexicons0007.dll
[2009/09/17 04:41:07 | 02,582,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLsvc.exe
[2009/09/17 04:41:07 | 00,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLCExt.dll
[2009/09/17 04:41:06 | 02,146,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FunctionDiscoveryFolder.dll
[2009/09/17 04:41:06 | 02,134,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FunctionDiscoveryFolder.dll
[2009/09/17 04:41:05 | 02,644,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NlsLexicons0009.dll
[2009/09/17 04:41:05 | 02,644,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NlsLexicons0009.dll
[2009/09/17 04:41:03 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscntrs.dll
[2009/09/17 04:41:03 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msshooks.dll
[2009/09/17 04:41:02 | 04,699,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2009/09/17 04:41:02 | 02,280,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssrch.dll
[2009/09/17 04:41:02 | 01,081,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SLCExt.dll
[2009/09/17 04:41:02 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msstrc.dll
[2009/09/17 04:41:02 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmlfilter.dll
[2009/09/17 04:41:02 | 00,019,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd1394.dll
[2009/09/17 04:41:00 | 01,480,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssrch.dll
[2009/09/17 04:40:57 | 02,204,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tquery.dll
[2009/09/17 04:40:57 | 01,085,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcnwiz2.dll
[2009/09/17 04:40:57 | 00,968,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wcnwiz2.dll
[2009/09/17 04:40:57 | 00,948,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hdaudbus.sys
[2009/09/17 04:40:57 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WscEapPr.dll
[2009/09/17 04:40:57 | 00,291,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WscEapPr.dll
[2009/09/17 04:40:57 | 00,046,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\infocardcpl.cpl
[2009/09/17 04:40:56 | 01,381,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardagt.exe
[2009/09/17 04:40:56 | 01,165,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationNative_v0300.dll
[2009/09/17 04:40:56 | 01,146,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2fs.dll
[2009/09/17 04:40:55 | 01,576,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tquery.dll
[2009/09/17 04:40:55 | 00,600,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2009/09/17 04:40:55 | 00,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2009/09/17 04:40:54 | 03,108,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll
[2009/09/17 04:40:53 | 01,515,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ntfs.sys
[2009/09/17 04:40:53 | 00,886,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmain.dll
[2009/09/17 04:40:53 | 00,779,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationNative_v0300.dll
[2009/09/17 04:40:52 | 12,897,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shell32.dll
[2009/09/17 04:40:52 | 01,582,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2009/09/17 04:40:51 | 00,946,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scavenge.dll
[2009/09/17 04:40:51 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spsys.sys
[2009/09/17 04:40:51 | 00,539,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2009/09/17 04:40:51 | 00,538,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2009/09/17 04:40:51 | 00,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2009/09/17 04:40:51 | 00,518,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2009/09/17 04:40:50 | 02,241,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msi.dll
[2009/09/17 04:40:48 | 01,804,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3.dll
[2009/09/17 04:40:48 | 00,677,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2fs.dll
[2009/09/17 04:40:48 | 00,476,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2009/09/17 04:40:47 | 03,263,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmcndmgr.dll
[2009/09/17 04:40:47 | 00,035,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\infocardcpl.cpl
[2009/09/17 04:40:46 | 00,619,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardagt.exe
[2009/09/17 04:40:45 | 01,418,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayCpl.dll
[2009/09/17 04:40:45 | 01,217,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2009/09/17 04:40:45 | 00,836,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\p2psvc.dll
[2009/09/17 04:40:45 | 00,435,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spinstall.exe
[2009/09/17 04:40:45 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spreview.exe
[2009/09/17 04:40:44 | 02,715,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmc.exe
[2009/09/17 04:40:44 | 02,506,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\esent.dll
[2009/09/17 04:40:44 | 01,185,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll
[2009/09/17 04:40:43 | 01,216,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AuxiliaryDisplayCpl.dll
[2009/09/17 04:40:43 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchIndexer.exe
[2009/09/17 04:40:43 | 00,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwizui.dll
[2009/09/17 04:40:43 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwizui.dll
[2009/09/17 04:40:40 | 01,915,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2009/09/17 04:40:40 | 00,978,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll
[2009/09/17 04:40:40 | 00,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spinstall.exe
[2009/09/17 04:40:40 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spreview.exe
[2009/09/17 04:40:39 | 03,433,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfsr.exe
[2009/09/17 04:40:39 | 00,499,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sdohlp.dll
[2009/09/17 04:40:38 | 11,584,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shell32.dll
[2009/09/17 04:40:38 | 00,796,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssvp.dll
[2009/09/17 04:40:38 | 00,778,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2VDEC.DLL
[2009/09/17 04:40:38 | 00,472,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2009/09/17 04:40:37 | 00,670,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssvp.dll
[2009/09/17 04:40:37 | 00,644,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\p2psvc.dll
[2009/09/17 04:40:37 | 00,501,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssph.dll
[2009/09/17 04:40:37 | 00,441,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SearchIndexer.exe
[2009/09/17 04:40:37 | 00,312,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssphtb.dll
[2009/09/17 04:40:37 | 00,223,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcupdate_GenuineIntel.dll
[2009/09/17 04:40:37 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EhStorPwdMgr.dll
[2009/09/17 04:40:37 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EhStorPwdMgr.dll
[2009/09/17 04:40:36 | 00,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2009/09/17 04:40:35 | 00,858,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\kernel32.dll
[2009/09/17 04:40:35 | 00,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2VDEC.DLL
[2009/09/17 04:40:35 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi2.dll
[2009/09/17 04:40:35 | 00,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\srv.sys
[2009/09/17 04:40:35 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2009/09/17 04:40:35 | 00,278,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscoree.dll
[2009/09/17 04:40:34 | 02,028,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Query.dll
[2009/09/17 04:40:34 | 01,165,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntdll.dll
[2009/09/17 04:40:34 | 00,378,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi2.dll
[2009/09/17 04:40:34 | 00,351,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssph.dll
[2009/09/17 04:40:34 | 00,203,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssphtb.dll
[2009/09/17 04:40:34 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\korwbrkr.dll
[2009/09/17 04:40:33 | 00,922,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL
[2009/09/17 04:40:33 | 00,403,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscoree.dll
[2009/09/17 04:40:33 | 00,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uDWM.dll
[2009/09/17 04:40:32 | 03,894,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSAT.exe
[2009/09/17 04:40:32 | 01,459,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\esent.dll
[2009/09/17 04:40:32 | 00,483,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairing.dll
[2009/09/17 04:40:32 | 00,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairing.dll
[2009/09/17 04:40:32 | 00,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sdohlp.dll
[2009/09/17 04:40:31 | 00,729,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL
[2009/09/17 04:40:31 | 00,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msshsq.dll
[2009/09/17 04:40:30 | 00,606,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\http.sys
[2009/09/17 04:40:30 | 00,347,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2009/09/17 04:40:30 | 00,238,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sperror.dll
[2009/09/17 04:40:30 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sperror.dll
[2009/09/17 04:40:30 | 00,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\korwbrkr.dll
[2009/09/17 04:40:29 | 01,673,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsAnytimeUpgradeCPL.dll
[2009/09/17 04:40:29 | 01,019,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10.IME
[2009/09/17 04:40:29 | 00,401,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\P2PGraph.dll
[2009/09/17 04:40:29 | 00,228,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SLC.dll
[2009/09/17 04:40:29 | 00,041,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll
[2009/09/17 04:40:28 | 01,259,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2009/09/17 04:40:28 | 00,346,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2009/09/17 04:40:28 | 00,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msshsq.dll
[2009/09/17 04:40:28 | 00,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EhStorAPI.dll
[2009/09/17 04:40:28 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EhStorAPI.dll
[2009/09/17 04:40:27 | 01,925,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setupapi.dll
[2009/09/17 04:40:27 | 01,589,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjet40.dll
[2009/09/17 04:40:27 | 01,491,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wevtsvc.dll
[2009/09/17 04:40:27 | 01,336,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml6.dll
[2009/09/17 04:40:27 | 00,581,632 | ---- | C] (Microsoft) -- C:\Windows\SysNative\IasMigPlugin.dll
[2009/09/17 04:40:27 | 00,164,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Storport.sys
[2009/09/17 04:40:27 | 00,049,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll
[2009/09/17 04:40:26 | 01,381,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Query.dll
[2009/09/17 04:40:26 | 01,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printfilterpipelinesvc.exe
[2009/09/17 04:40:26 | 00,738,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ndis.sys
[2009/09/17 04:40:26 | 00,558,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2009/09/17 04:40:26 | 00,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchProtocolHost.exe
[2009/09/17 04:40:26 | 00,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFilterHost.exe
[2009/09/17 04:40:26 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\compcln.exe
[2009/09/17 04:40:25 | 01,081,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qmgr.dll
[2009/09/17 04:40:25 | 01,078,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2009/09/17 04:40:25 | 00,883,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10.IME
[2009/09/17 04:40:25 | 00,648,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user32.dll
[2009/09/17 04:40:25 | 00,347,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srchadmin.dll
[2009/09/17 04:40:25 | 00,171,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\infocardapi.dll
[2009/09/17 04:40:25 | 00,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EhStorShell.dll
[2009/09/17 04:40:25 | 00,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EhStorShell.dll
[2009/09/17 04:40:25 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdBth.dll
[2009/09/17 04:40:24 | 01,584,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diagperf.dll
[2009/09/17 04:40:24 | 01,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vssapi.dll
[2009/09/17 04:40:24 | 01,065,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2009/09/17 04:40:24 | 01,064,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2009/09/17 04:40:24 | 00,719,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcss.dll
[2009/09/17 04:40:24 | 00,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IasMigReader.exe
[2009/09/17 04:40:24 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msexch40.dll
[2009/09/17 04:40:24 | 00,327,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\P2PGraph.dll
[2009/09/17 04:40:23 | 03,079,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2009/09/17 04:40:23 | 01,316,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ole32.dll
[2009/09/17 04:40:22 | 01,733,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml6.dll
[2009/09/17 04:40:22 | 01,658,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnroll.dll
[2009/09/17 04:40:22 | 01,433,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\VSSVC.exe
[2009/09/17 04:40:22 | 01,183,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3.dll
[2009/09/17 04:40:22 | 00,967,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mblctr.exe
[2009/09/17 04:40:22 | 00,428,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2009/09/17 04:40:22 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\srchadmin.dll
[2009/09/17 04:40:22 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2009/09/17 04:40:21 | 01,792,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmc.exe
[2009/09/17 04:40:21 | 01,686,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comsvcs.dll
[2009/09/17 04:40:21 | 01,357,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42u.dll
[2009/09/17 04:40:21 | 00,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gdi32.dll
[2009/09/17 04:40:21 | 00,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spoolss.dll
[2009/09/17 04:40:21 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairingWizard.exe
[2009/09/17 04:40:21 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairingWizard.exe
[2009/09/17 04:40:20 | 01,930,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll
[2009/09/17 04:40:20 | 01,650,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browseui.dll
[2009/09/17 04:40:20 | 00,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Magnify.exe
[2009/09/17 04:40:20 | 00,466,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\riched20.dll
[2009/09/17 04:40:20 | 00,454,144 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\IasMigPlugin.dll
[2009/09/17 04:40:20 | 00,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\afd.sys
[2009/09/17 04:40:20 | 00,123,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2009/09/17 04:40:19 | 01,395,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfc42.dll
[2009/09/17 04:40:19 | 01,092,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmSvc.dll
[2009/09/17 04:40:19 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdBth.dll
[2009/09/17 04:40:18 | 02,012,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\milcore.dll
[2009/09/17 04:40:18 | 01,112,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnroll.dll
[2009/09/17 04:40:18 | 00,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RacEngn.dll
[2009/09/17 04:40:18 | 00,379,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2009/09/17 04:40:18 | 00,347,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2009/09/17 04:40:18 | 00,275,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bcrypt.dll
[2009/09/17 04:40:18 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SearchProtocolHost.exe
[2009/09/17 04:40:18 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SearchFilterHost.exe
[2009/09/17 04:40:17 | 00,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Magnify.exe
[2009/09/17 04:40:17 | 00,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NaturalLanguage6.dll
[2009/09/17 04:40:17 | 00,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapimig.exe
[2009/09/17 04:40:17 | 00,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasrecst.dll
[2009/09/17 04:40:17 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spoolss.dll
[2009/09/17 04:40:16 | 02,484,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbgeng.dll
[2009/09/17 04:40:16 | 02,112,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apds.dll
[2009/09/17 04:40:16 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eudcedit.exe
[2009/09/17 04:40:15 | 01,013,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gpedit.dll
[2009/09/17 04:40:15 | 00,843,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\schedsvc.dll
[2009/09/17 04:40:15 | 00,602,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2009/09/17 04:40:15 | 00,446,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiosrv.dll
[2009/09/17 04:40:15 | 00,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\es.dll
[2009/09/17 04:40:15 | 00,290,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjtes40.dll
[2009/09/17 04:40:14 | 01,040,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2009/09/17 04:40:14 | 00,950,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpedit.dll
[2009/09/17 04:40:14 | 00,918,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comuid.dll
[2009/09/17 04:40:14 | 00,820,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\user32.dll
[2009/09/17 04:40:14 | 00,647,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll
[2009/09/17 04:40:14 | 00,460,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2009/09/17 04:40:14 | 00,406,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp60.dll
[2009/09/17 04:40:14 | 00,099,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\infocardapi.dll
[2009/09/17 04:40:14 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slwmi.dll
[2009/09/17 04:40:14 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Storprop.dll
[2009/09/17 04:40:13 | 01,244,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RacEngn.dll
[2009/09/17 04:40:13 | 00,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2009/09/17 04:40:13 | 00,668,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthprops.cpl
[2009/09/17 04:40:13 | 00,620,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ipsmsnap.dll
[2009/09/17 04:40:13 | 00,402,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\photowiz.dll
[2009/09/17 04:40:12 | 00,275,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fltMgr.sys
[2009/09/17 04:40:12 | 00,268,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\es.dll
[2009/09/17 04:40:12 | 00,181,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nlhtml.dll
[2009/09/17 04:40:10 | 00,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advapi32.dll
[2009/09/17 04:40:10 | 00,503,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msihnd.dll
[2009/09/17 04:40:10 | 00,455,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shlwapi.dll
[2009/09/17 04:40:10 | 00,394,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wevtapi.dll
[2009/09/17 04:40:10 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstext40.dll
[2009/09/17 04:40:10 | 00,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationSettings.exe
[2009/09/17 04:40:10 | 00,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLC.dll
[2009/09/17 04:40:10 | 00,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayServices.dll
[2009/09/17 04:40:09 | 01,570,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2009/09/17 04:40:09 | 01,209,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comsvcs.dll
[2009/09/17 04:40:09 | 00,447,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2009/09/17 04:40:09 | 00,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msexcl40.dll
[2009/09/17 04:40:09 | 00,321,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2009/09/17 04:40:09 | 00,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2009/09/17 04:40:09 | 00,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WebClnt.dll
[2009/09/17 04:40:09 | 00,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AuxiliaryDisplayDriverLib.dll
[2009/09/17 04:40:09 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwmi.dll
[2009/09/17 04:40:08 | 01,681,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcnwiz.dll
[2009/09/17 04:40:08 | 01,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vssapi.dll
[2009/09/17 04:40:08 | 00,621,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcrt.dll
[2009/09/17 04:40:08 | 00,498,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\devmgr.dll
[2009/09/17 04:40:08 | 00,461,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2009/09/17 04:40:08 | 00,454,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxbde40.dll
[2009/09/17 04:40:08 | 00,238,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WcnNetsh.dll
[2009/09/17 04:40:08 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\srvnet.sys
[2009/09/17 04:40:08 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DevicePairingProxy.dll
[2009/09/17 04:40:08 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DevicePairingProxy.dll
[2009/09/17 04:40:07 | 01,985,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2009/09/17 04:40:07 | 01,098,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NetProjW.dll
[2009/09/17 04:40:07 | 00,581,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcncsvc.dll
[2009/09/17 04:40:07 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctfp.dll
[2009/09/17 04:40:07 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdBthProxy.dll
[2009/09/17 04:40:06 | 01,499,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdtctm.dll
[2009/09/17 04:40:06 | 01,195,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2009/09/17 04:40:06 | 00,643,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrepl40.dll
[2009/09/17 04:40:06 | 00,598,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcp60.dll
[2009/09/17 04:40:06 | 00,430,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vbscript.dll
[2009/09/17 04:40:06 | 00,323,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe
[2009/09/17 04:40:06 | 00,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\davclnt.dll
[2009/09/17 04:40:05 | 01,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe
[2009/09/17 04:40:05 | 00,754,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\propsys.dll
[2009/09/17 04:40:05 | 00,660,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2009/09/17 04:40:05 | 00,640,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bthprops.cpl
[2009/09/17 04:40:05 | 00,469,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\newdev.dll
[2009/09/17 04:40:05 | 00,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\w32time.dll
[2009/09/17 04:40:05 | 00,354,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe
[2009/09/17 04:40:05 | 00,289,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rsaenh.dll
[2009/09/17 04:40:05 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spoolsv.exe
[2009/09/17 04:40:05 | 00,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netbt.sys
[2009/09/17 04:40:05 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WebClnt.dll
[2009/09/17 04:40:05 | 00,164,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Classpnp.sys
[2009/09/17 04:40:04 | 00,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gpsvc.dll
[2009/09/17 04:40:04 | 00,631,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLCommDlg.dll
[2009/09/17 04:40:04 | 00,205,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eudcedit.exe
[2009/09/17 04:40:04 | 00,119,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasrecst.dll
[2009/09/17 04:40:04 | 00,102,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2009/09/17 04:40:03 | 02,926,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2009/09/17 04:40:03 | 01,748,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certmgr.dll
[2009/09/17 04:40:03 | 00,978,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\crypt32.dll
[2009/09/17 04:40:03 | 00,727,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdtcprx.dll
[2009/09/17 04:40:03 | 00,398,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
[2009/09/17 04:40:03 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\umpnpmgr.dll
[2009/09/17 04:40:02 | 01,788,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d9.dll
[2009/09/17 04:40:02 | 01,591,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setupapi.dll
[2009/09/17 04:40:02 | 00,840,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PhotoScreensaver.scr
[2009/09/17 04:40:02 | 00,368,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mspbde40.dll
[2009/09/17 04:40:02 | 00,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdbss.sys
[2009/09/17 04:40:01 | 00,480,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\swprv.dll
[2009/09/17 04:40:01 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLUI.exe
[2009/09/17 04:40:01 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\davclnt.dll
[2009/09/17 04:40:00 | 01,245,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMNetMgr.dll
[2009/09/17 04:40:00 | 00,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MPSSVC.dll
[2009/09/17 04:40:00 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2009/09/17 04:40:00 | 00,241,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msltus40.dll
[2009/09/17 04:39:59 | 01,135,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll
[2009/09/17 04:39:59 | 00,841,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2009/09/17 04:39:59 | 00,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmicmiplugin.dll
[2009/09/17 04:39:59 | 00,380,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2009/09/17 04:39:59 | 00,353,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shlwapi.dll
[2009/09/17 04:39:59 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrd3x40.dll
[2009/09/17 04:39:59 | 00,324,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceApi.dll
[2009/09/17 04:39:58 | 01,543,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVSDECD.DLL
[2009/09/17 04:39:58 | 01,324,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browseui.dll
[2009/09/17 04:39:58 | 00,935,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ipsecsnp.dll
[2009/09/17 04:39:58 | 00,671,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll
[2009/09/17 04:39:58 | 00,581,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sqlsrv32.dll
[2009/09/17 04:39:58 | 00,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iassdo.dll
[2009/09/17 04:39:58 | 00,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbhub.sys
[2009/09/17 04:39:58 | 00,250,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wevtapi.dll
[2009/09/17 04:39:57 | 01,394,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wercon.exe
[2009/09/17 04:39:57 | 00,885,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgkrnl.sys
[2009/09/17 04:39:57 | 00,648,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2009/09/17 04:39:57 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\photowiz.dll
[2009/09/17 04:39:57 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nlhtml.dll
[2009/09/17 04:39:56 | 02,272,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2009/09/17 04:39:56 | 01,314,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2009/09/17 04:39:56 | 00,384,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\services.exe
[2009/09/17 04:39:56 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBSTOR.SYS
[2009/09/17 04:39:55 | 00,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2009/09/17 04:39:55 | 00,582,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SLCommDlg.dll
[2009/09/17 04:39:55 | 00,563,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaut32.dll
[2009/09/17 04:39:55 | 00,443,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2009/09/17 04:39:55 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\QAGENTRT.DLL
[2009/09/17 04:39:55 | 00,221,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2009/09/17 04:39:55 | 00,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WcnNetsh.dll
[2009/09/17 04:39:54 | 03,174,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netshell.dll
[2009/09/17 04:39:54 | 01,730,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apds.dll
[2009/09/17 04:39:54 | 00,549,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2009/09/17 04:39:54 | 00,462,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2009/09/17 04:39:54 | 00,304,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mswsock.dll
[2009/09/17 04:39:54 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propdefs.dll
[2009/09/17 04:39:53 | 00,807,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctf.dll
[2009/09/17 04:39:53 | 00,717,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netlogon.dll
[2009/09/17 04:39:53 | 00,618,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mswstr10.dll
[2009/09/17 04:39:53 | 00,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winhttp.dll
[2009/09/17 04:39:53 | 00,264,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ws2_32.dll
[2009/09/17 04:39:53 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mrxdav.sys
[2009/09/17 04:39:53 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xmlfilter.dll
[2009/09/17 04:39:52 | 01,160,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll
[2009/09/17 04:39:52 | 01,114,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFaultSecure.exe
[2009/09/17 04:39:52 | 00,679,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcrt.dll
[2009/09/17 04:39:52 | 00,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\emdmgmt.dll
[2009/09/17 04:39:52 | 00,261,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapphost.dll
[2009/09/17 04:39:51 | 00,992,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2009/09/17 04:39:51 | 00,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PhotoMetadataHandler.dll
[2009/09/17 04:39:51 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\newdev.dll
[2009/09/17 04:39:51 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll
[2009/09/17 04:39:51 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapphost.dll
[2009/09/17 04:39:51 | 00,166,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2009/09/17 04:39:50 | 00,894,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\azroles.dll
[2009/09/17 04:39:50 | 00,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IPSECSVC.DLL
[2009/09/17 04:39:50 | 00,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sqlsrv32.dll
[2009/09/17 04:39:50 | 00,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrd2x40.dll
[2009/09/17 04:39:50 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MMDevAPI.dll
[2009/09/17 04:39:49 | 01,792,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanpref.dll
[2009/09/17 04:39:49 | 00,621,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll
[2009/09/17 04:39:49 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2009/09/17 04:39:49 | 00,248,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wevtutil.exe
[2009/09/17 04:39:49 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\propdefs.dll
[2009/09/17 04:39:48 | 02,570,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\milcore.dll
[2009/09/17 04:39:48 | 01,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shdocvw.dll
[2009/09/17 04:39:48 | 00,422,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2009/09/17 04:39:48 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscb.dll
[2009/09/17 04:39:47 | 01,856,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbgeng.dll
[2009/09/17 04:39:47 | 00,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSDApi.dll
[2009/09/17 04:39:47 | 00,328,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wldap32.dll
[2009/09/17 04:39:47 | 00,213,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasnap.dll
[2009/09/17 04:39:47 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wevtutil.exe
[2009/09/17 04:39:47 | 00,087,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssitlb.dll
[2009/09/17 04:39:46 | 02,167,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmcndmgr.dll
[2009/09/17 04:39:46 | 01,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcmde.dll
[2009/09/17 04:39:46 | 00,747,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmSvc.dll
[2009/09/17 04:39:46 | 00,502,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usp10.dll
[2009/09/17 04:39:46 | 00,215,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msiscsi.sys
[2009/09/17 04:39:46 | 00,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssitlb.dll
[2009/09/17 04:39:45 | 01,090,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2009/09/17 04:39:45 | 00,477,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2009/09/17 04:39:45 | 00,380,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2009/09/17 04:39:45 | 00,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iassam.dll
[2009/09/17 04:39:45 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthserv.dll
[2009/09/17 04:39:44 | 00,923,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2009/09/17 04:39:44 | 00,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netlogon.dll
[2009/09/17 04:39:44 | 00,450,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2009/09/17 04:39:44 | 00,378,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devmgr.dll
[2009/09/17 04:39:44 | 00,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe
[2009/09/17 04:39:44 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctfp.dll
[2009/09/17 04:39:44 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtffilt.dll
[2009/09/17 04:39:44 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdBthProxy.dll
[2009/09/17 04:39:43 | 01,533,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wcnwiz.dll
[2009/09/17 04:39:43 | 00,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll
[2009/09/17 04:39:43 | 00,199,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adsldpc.dll
[2009/09/17 04:39:43 | 00,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\srv2.sys
[2009/09/17 04:39:43 | 00,166,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsvc.dll
[2009/09/17 04:39:43 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscb.dll
[2009/09/17 04:39:42 | 01,382,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVSDECD.DLL
[2009/09/17 04:39:42 | 00,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscms.dll
[2009/09/17 04:39:42 | 00,454,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vds.exe
[2009/09/17 04:39:42 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2009/09/17 04:39:42 | 00,405,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2009/09/17 04:39:42 | 00,355,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSDApi.dll
[2009/09/17 04:39:42 | 00,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wldap32.dll
[2009/09/17 04:39:42 | 00,269,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\volsnap.sys
[2009/09/17 04:39:42 | 00,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scrrun.dll
[2009/09/17 04:39:42 | 00,151,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imapi.dll
[2009/09/17 04:39:42 | 00,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\reg.exe
[2009/09/17 04:39:41 | 00,712,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WindowsCodecs.dll
[2009/09/17 04:39:41 | 00,450,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comdlg32.dll
[2009/09/17 04:39:41 | 00,279,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\services.exe
[2009/09/17 04:39:41 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
[2009/09/17 04:39:41 | 00,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskeng.exe
[2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quick.ime
[2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qintlgnt.ime
[2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\phon.ime
[2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cintlgnt.ime
[2009/09/17 04:39:41 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\chajei.ime
[2009/09/17 04:39:41 | 00,073,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\partmgr.sys
[2009/09/17 04:39:41 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdProxy.dll
[2009/09/17 04:39:41 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mimefilt.dll
[2009/09/17 04:39:40 | 01,538,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\brcpl.dll
[2009/09/17 04:39:40 | 01,234,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdc.dll
[2009/09/17 04:39:40 | 00,748,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\stobject.dll
[2009/09/17 04:39:40 | 00,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2009/09/17 04:39:40 | 00,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2009/09/17 04:39:40 | 00,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wcncsvc.dll
[2009/09/17 04:39:40 | 00,332,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdrm.dll
[2009/09/17 04:39:40 | 00,323,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2009/09/17 04:39:40 | 00,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceApi.dll
[2009/09/17 04:39:40 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2009/09/17 04:39:40 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mimefilt.dll
[2009/09/17 04:39:39 | 00,856,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mswdat10.dll
[2009/09/17 04:39:39 | 00,810,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CertEnrollUI.dll
[2009/09/17 04:39:39 | 00,560,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdtcprx.dll
[2009/09/17 04:39:39 | 00,396,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipsmsnap.dll
[2009/09/17 04:39:39 | 00,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasmans.dll
[2009/09/17 04:39:39 | 00,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskeng.exe
[2009/09/17 04:39:39 | 00,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetpp.dll
[2009/09/17 04:39:39 | 00,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rasl2tp.sys
[2009/09/17 04:39:39 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjter40.dll
[2009/09/17 04:39:39 | 00,014,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pciide.sys
[2009/09/17 04:39:38 | 00,996,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMNetMgr.dll
[2009/09/17 04:39:38 | 00,799,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2009/09/17 04:39:38 | 00,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PhotoScreensaver.scr
[2009/09/17 04:39:38 | 00,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiaservc.dll
[2009/09/17 04:39:38 | 00,361,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\clfs.sys
[2009/09/17 04:39:38 | 00,307,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pdh.dll
[2009/09/17 04:39:38 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\offfilt.dll
[2009/09/17 04:39:38 | 00,168,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnsapi.dll
[2009/09/17 04:39:38 | 00,123,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
[2009/09/17 04:39:38 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\reg.exe
[2009/09/17 04:39:38 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtffilt.dll
[2009/09/17 04:39:37 | 00,539,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RelMon.dll
[2009/09/17 04:39:37 | 00,475,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx
[2009/09/17 04:39:37 | 00,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mtxclu.dll
[2009/09/17 04:39:37 | 00,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winspool.drv
[2009/09/17 04:39:37 | 00,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scrobj.dll
[2009/09/17 04:39:37 | 00,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fundisc.dll
[2009/09/17 04:39:37 | 00,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysclass.dll
[2009/09/17 04:39:37 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\raspptp.sys
[2009/09/17 04:39:37 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscntrs.dll
[2009/09/17 04:39:37 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msshooks.dll
[2009/09/17 04:39:36 | 00,488,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msinfo32.exe
[2009/09/17 04:39:36 | 00,332,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msihnd.dll
[2009/09/17 04:39:36 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2009/09/17 04:39:36 | 00,241,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rsaenh.dll
[2009/09/17 04:39:36 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adsldpc.dll
[2009/09/17 04:39:36 | 00,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnpsetup.dll
[2009/09/17 04:39:36 | 00,169,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ndiswan.sys
[2009/09/17 04:39:36 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MMDevAPI.dll
[2009/09/17 04:39:36 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msstrc.dll
[2009/09/17 04:39:35 | 00,776,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sethc.exe
[2009/09/17 04:39:35 | 00,738,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcomm.dll
[2009/09/17 04:39:35 | 00,467,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netapi32.dll
[2009/09/17 04:39:35 | 00,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mtxclu.dll
[2009/09/17 04:39:35 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbport.sys
[2009/09/17 04:39:35 | 00,178,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pci.sys
[2009/09/17 04:39:35 | 00,129,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptsvc.dll
[2009/09/17 04:39:35 | 00,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msiexec.exe
[2009/09/17 04:39:35 | 00,093,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2009/09/17 04:39:35 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasdiag.dll
[2009/09/17 04:39:34 | 01,321,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appwiz.cpl
[2009/09/17 04:39:34 | 00,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wisptis.exe
[2009/09/17 04:39:34 | 00,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasrad.dll
[2009/09/17 04:39:34 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fundisc.dll
[2009/09/17 04:39:34 | 00,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcsvc6.dll
[2009/09/17 04:39:34 | 00,080,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll
[2009/09/17 04:39:34 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hidserv.dll
[2009/09/17 04:39:33 | 00,722,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autofmt.exe
[2009/09/17 04:39:33 | 00,325,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\acpi.sys
[2009/09/17 04:39:33 | 00,273,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mrxsmb10.sys
[2009/09/17 04:39:33 | 00,212,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\osk.exe
[2009/09/17 04:39:33 | 00,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2009/09/17 04:39:33 | 00,108,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
[2009/09/17 04:39:33 | 00,062,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\termdd.sys
[2009/09/17 04:39:33 | 00,035,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TsWpfWrp.exe
[2009/09/17 04:39:33 | 00,034,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsWpfWrp.exe
[2009/09/17 04:39:32 | 01,035,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll
[2009/09/17 04:39:32 | 00,785,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Utilman.exe
[2009/09/17 04:39:32 | 00,547,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\termsrv.dll
[2009/09/17 04:39:32 | 00,238,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcpipcfg.dll
[2009/09/17 04:39:32 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mrxsmb.sys
[2009/09/17 04:39:32 | 00,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imapi.dll
[2009/09/17 04:39:32 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msiexec.exe
[2009/09/17 04:39:32 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLUINotify.dll
[2009/09/17 04:39:32 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasdatastore.dll
[2009/09/17 04:39:31 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\chsbrkr.dll
[2009/09/17 04:39:31 | 01,020,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdc.dll
[2009/09/17 04:39:31 | 00,980,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printui.dll
[2009/09/17 04:39:31 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iassdo.dll
[2009/09/17 04:39:31 | 00,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsvcs.dll
[2009/09/17 04:39:31 | 00,211,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmm.dll
[2009/09/17 04:39:31 | 00,116,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imm32.dll
[2009/09/17 04:39:31 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Kswdmcap.ax
[2009/09/17 04:39:30 | 02,024,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnidui.dll
[2009/09/17 04:39:30 | 01,823,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pnidui.dll
[2009/09/17 04:39:30 | 01,691,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\connect.dll
[2009/09/17 04:39:30 | 00,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpencom.dll
[2009/09/17 04:39:30 | 00,260,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe
[2009/09/17 04:39:30 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasads.dll
[2009/09/17 04:39:30 | 00,039,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\crashdmp.sys
[2009/09/17 04:39:29 | 00,636,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autofmt.exe
[2009/09/17 04:39:29 | 00,522,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsound.dll
[2009/09/17 04:39:29 | 00,408,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\volmgrx.sys
[2009/09/17 04:39:29 | 00,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll
[2009/09/17 04:39:29 | 00,302,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scansetting.dll
[2009/09/17 04:39:29 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc.dll
[2009/09/17 04:39:29 | 00,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2009/09/17 04:39:29 | 00,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scrrun.dll
[2009/09/17 04:39:29 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvinst.exe
[2009/09/17 04:39:29 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spcmsg.dll
[2009/09/17 04:39:29 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spcmsg.dll
[2009/09/17 04:39:28 | 02,420,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcenter.dll
[2009/09/17 04:39:28 | 01,093,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pidgenx.dll
[2009/09/17 04:39:28 | 00,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prnntfy.dll
[2009/09/17 04:39:28 | 00,372,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\untfs.dll
[2009/09/17 04:39:28 | 00,242,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pdh.dll
[2009/09/17 04:39:28 | 00,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcsvc.dll
[2009/09/17 04:39:28 | 00,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskpart.exe
[2009/09/17 04:39:28 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SCardSvr.dll
[2009/09/17 04:39:28 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IPHLPAPI.DLL
[2009/09/17 04:39:28 | 00,059,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mup.sys
[2009/09/17 04:39:27 | 01,122,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appwiz.cpl
[2009/09/17 04:39:27 | 01,060,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mmsys.cpl
[2009/09/17 04:39:27 | 00,911,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasdlg.dll
[2009/09/17 04:39:27 | 00,757,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\azroles.dll
[2009/09/17 04:39:27 | 00,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CertEnrollUI.dll
[2009/09/17 04:39:27 | 00,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsdyn.dll
[2009/09/17 04:39:27 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spp.dll
[2009/09/17 04:39:27 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2009/09/17 04:39:27 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2009/09/17 04:39:27 | 00,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\userenv.dll
[2009/09/17 04:39:26 | 01,676,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\chsbrkr.dll
[2009/09/17 04:39:26 | 01,107,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pidgenx.dll
[2009/09/17 04:39:26 | 00,867,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpmde.dll
[2009/09/17 04:39:26 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx
[2009/09/17 04:39:26 | 00,310,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\msrpc.sys
[2009/09/17 04:39:26 | 00,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InkEd.dll
[2009/09/17 04:39:26 | 00,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winspool.drv
[2009/09/17 04:39:26 | 00,073,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscories.dll
[2009/09/17 04:39:26 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ipfltdrv.sys
[2009/09/17 04:39:25 | 02,205,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SyncCenter.dll
[2009/09/17 04:39:25 | 01,502,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certmgr.dll
[2009/09/17 04:39:25 | 00,593,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comuid.dll
[2009/09/17 04:39:25 | 00,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winlogon.exe
[2009/09/17 04:39:25 | 00,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dskquoui.dll
[2009/09/17 04:39:25 | 00,067,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\disk.sys
[2009/09/17 04:39:24 | 00,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcomm.dll
[2009/09/17 04:39:24 | 00,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sethc.exe
[2009/09/17 04:39:24 | 00,347,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WindowsCodecsExt.dll
[2009/09/17 04:39:24 | 00,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\untfs.dll
[2009/09/17 04:39:24 | 00,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncrypt.dll
[2009/09/17 04:39:24 | 00,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iassam.dll
[2009/09/17 04:39:24 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scrobj.dll
[2009/09/17 04:39:24 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spp.dll
[2009/09/17 04:39:24 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iashlpr.dll
[2009/09/17 04:39:24 | 00,055,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PSHED.DLL
[2009/09/17 04:39:24 | 00,019,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdcom.dll
[2009/09/17 04:39:23 | 00,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoconv.exe
[2009/09/17 04:39:23 | 00,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2009/09/17 04:39:23 | 00,480,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iedkcs32.dll
[2009/09/17 04:39:23 | 00,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imkr80.ime
[2009/09/17 04:39:23 | 00,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasapi32.dll
[2009/09/17 04:39:23 | 00,049,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pciidex.sys
[2009/09/17 04:39:23 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mssprxy.dll
[2009/09/17 04:39:23 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rtutils.dll
[2009/09/17 04:39:22 | 01,740,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\onex.dll
[2009/09/17 04:39:22 | 00,734,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autochk.exe
[2009/09/17 04:39:22 | 00,308,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\diskraid.exe
[2009/09/17 04:39:22 | 00,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2009/09/17 04:39:22 | 00,270,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\taskcomp.dll
[2009/09/17 04:39:22 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntprint.dll
[2009/09/17 04:39:22 | 00,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntmarta.dll
[2009/09/17 04:39:22 | 00,155,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ecache.sys
[2009/09/17 04:39:22 | 00,099,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll
[2009/09/17 04:39:22 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpr.dll
[2009/09/17 04:39:22 | 00,067,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\volmgr.sys
[2009/09/17 04:39:21 | 02,079,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2009/09/17 04:39:21 | 01,891,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVENCOD.DLL
[2009/09/17 04:39:21 | 00,869,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\printui.dll
[2009/09/17 04:39:21 | 00,643,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autochk.exe
[2009/09/17 04:39:21 | 00,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\portcls.sys
[2009/09/17 04:39:21 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srvsvc.dll
[2009/09/17 04:39:21 | 00,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasnap.dll
[2009/09/17 04:39:21 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iassvcs.dll
[2009/09/17 04:39:20 | 01,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2009/09/17 04:39:20 | 01,444,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PerfCenterCPL.dll
[2009/09/17 04:39:20 | 00,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoconv.exe
[2009/09/17 04:39:20 | 00,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2009/09/17 04:39:20 | 00,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scecli.dll
[2009/09/17 04:39:20 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\profsvc.dll
[2009/09/17 04:39:20 | 00,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2009/09/17 04:39:20 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscript.exe
[2009/09/17 04:39:20 | 00,130,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\basecsp.dll
[2009/09/17 04:39:19 | 01,541,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\onex.dll
[2009/09/17 04:39:19 | 00,223,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iphlpsvc.dll
[2009/09/17 04:39:19 | 00,153,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\basecsp.dll
[2009/09/17 04:39:19 | 00,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\userenv.dll
[2009/09/17 04:39:19 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\audiodg.exe
[2009/09/17 04:39:19 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iasacct.dll
[2009/09/17 04:39:19 | 00,029,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Dumpata.sys
[2009/09/17 04:39:19 | 00,022,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kdusb.dll
[2009/09/17 04:39:18 | 03,235,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkmap.dll
[2009/09/17 04:39:18 | 01,301,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themecpl.dll
[2009/09/17 04:39:18 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mswsock.dll
[2009/09/17 04:39:18 | 00,182,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\osk.exe
[2009/09/17 04:39:18 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wusa.exe
[2009/09/17 04:39:18 | 00,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powrprof.dll
[2009/09/17 04:39:18 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwm.exe
[2009/09/17 04:39:18 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logman.exe
[2009/09/17 04:39:18 | 00,020,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\atapi.sys
[2009/09/17 04:39:18 | 00,019,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spldr.sys
[2009/09/17 04:39:17 | 01,882,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpccpl.dll
[2009/09/17 04:39:17 | 00,593,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mspaint.exe
[2009/09/17 04:39:17 | 00,375,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll
[2009/09/17 04:39:17 | 00,340,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RelMon.dll
[2009/09/17 04:39:17 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2009/09/17 04:39:17 | 00,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\regsvc.dll
[2009/09/17 04:39:17 | 00,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmm.dll
[2009/09/17 04:39:17 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ks.sys
[2009/09/17 04:39:17 | 00,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\exfat.sys
[2009/09/17 04:39:17 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsrslvr.dll
[2009/09/17 04:39:16 | 00,612,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpencom.dll
[2009/09/17 04:39:16 | 00,564,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll
[2009/09/17 04:39:16 | 00,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scesrv.dll
[2009/09/17 04:39:16 | 00,318,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tapisrv.dll
[2009/09/17 04:39:16 | 00,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Faultrep.dll
[2009/09/17 04:39:16 | 00,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WinSCard.dll
[2009/09/17 04:39:16 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsepno.dll
[2009/09/17 04:39:15 | 01,827,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2009/09/17 04:39:15 | 00,860,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFaultSecure.exe
[2009/09/17 04:39:15 | 00,638,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Utilman.exe
[2009/09/17 04:39:15 | 00,586,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\stobject.dll
[2009/09/17 04:39:15 | 00,230,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskraid.exe
[2009/09/17 04:39:15 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe
[2009/09/17 04:39:15 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2009/09/17 04:39:15 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\offfilt.dll
[2009/09/17 04:39:15 | 00,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2009/09/17 04:39:15 | 00,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2009/09/17 04:39:15 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authz.dll
[2009/09/17 04:39:15 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstlsapi.dll
[2009/09/17 04:39:14 | 00,551,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prnntfy.dll
[2009/09/17 04:39:14 | 00,396,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AudioEng.dll
[2009/09/17 04:39:14 | 00,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscms.dll
[2009/09/17 04:39:14 | 00,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shsvcs.dll
[2009/09/17 04:39:14 | 00,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SndVol.exe
[2009/09/17 04:39:14 | 00,179,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll
[2009/09/17 04:39:14 | 00,171,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apphelp.dll
[2009/09/17 04:39:14 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscript.exe
[2009/09/17 04:39:14 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll
[2009/09/17 04:39:14 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adsmsext.dll
[2009/09/17 04:39:14 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsnmp32.dll
[2009/09/17 04:39:14 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSTheme.exe
[2009/09/17 04:39:13 | 01,279,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usercpl.dll
[2009/09/17 04:39:13 | 00,995,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\systemcpl.dll
[2009/09/17 04:39:13 | 00,971,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll
[2009/09/17 04:39:13 | 00,444,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsound.dll
[2009/09/17 04:39:13 | 00,250,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2009/09/17 04:39:13 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3svc.dll
[2009/09/17 04:39:13 | 00,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshom.ocx
[2009/09/17 04:39:13 | 00,115,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Kswdmcap.ax
[2009/09/17 04:39:13 | 00,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\console.dll
[2009/09/17 04:39:13 | 00,099,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ulib.dll
[2009/09/17 04:39:13 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IPHLPAPI.DLL
[2009/09/17 04:39:13 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasdatastore.dll
[2009/09/17 04:39:12 | 01,110,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2009/09/17 04:39:12 | 00,881,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl
[2009/09/17 04:39:12 | 00,759,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipsecsnp.dll
[2009/09/17 04:39:12 | 00,399,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlangpui.dll
[2009/09/17 04:39:12 | 00,387,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\zipfldr.dll
[2009/09/17 04:39:12 | 00,234,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2009/09/17 04:39:12 | 00,223,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscntfy.dll
[2009/09/17 04:39:12 | 00,181,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pnpsetup.dll
[2009/09/17 04:39:12 | 00,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll
[2009/09/17 04:39:12 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastapi.dll
[2009/09/17 04:39:12 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastapi.dll
[2009/09/17 04:39:12 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdProxy.dll
[2009/09/17 04:39:11 | 00,688,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\themeui.dll
[2009/09/17 04:39:11 | 00,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bcrypt.dll
[2009/09/17 04:39:11 | 00,244,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2009/09/17 04:39:11 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\diskpart.exe
[2009/09/17 04:39:11 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mrxsmb20.sys
[2009/09/17 04:39:11 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tdx.sys
[2009/09/17 04:39:11 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpapi.dll
[2009/09/17 04:39:11 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iashlpr.dll
[2009/09/17 04:39:11 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\perfdisk.dll
[2009/09/17 04:39:11 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsbyuv.dll
[2009/09/17 04:39:10 | 01,575,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVENCOD.DLL
[2009/09/17 04:39:10 | 00,898,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\powercpl.dll
[2009/09/17 04:39:10 | 00,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpcao.dll
[2009/09/17 04:39:10 | 00,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\autoplay.dll
[2009/09/17 04:39:10 | 00,507,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdsdyn.dll
[2009/09/17 04:39:10 | 00,454,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IKEEXT.DLL
[2009/09/17 04:39:10 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2009/09/17 04:39:10 | 00,166,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscript.exe
[2009/09/17 04:39:10 | 00,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\newdev.exe
[2009/09/17 04:39:10 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logman.exe
[2009/09/17 04:39:09 | 00,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcaui.dll
[2009/09/17 04:39:09 | 00,437,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imkr80.ime
[2009/09/17 04:39:09 | 00,286,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasapi32.dll
[2009/09/17 04:39:09 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntprint.dll
[2009/09/17 04:39:09 | 00,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2009/09/17 04:39:09 | 00,155,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll
[2009/09/17 04:39:09 | 00,154,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll
[2009/09/17 04:39:09 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceEject.exe
[2009/09/17 04:39:09 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msisip.dll
[2009/09/17 04:39:08 | 01,382,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sud.dll
[2009/09/17 04:39:08 | 00,810,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slcc.dll
[2009/09/17 04:39:08 | 00,342,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\zipfldr.dll
[2009/09/17 04:39:08 | 00,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\modemui.dll
[2009/09/17 04:39:08 | 00,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasrad.dll
[2009/09/17 04:39:08 | 00,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wusa.exe
[2009/09/17 04:39:08 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\regapi.dll
[2009/09/17 04:39:08 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hdwwiz.exe
[2009/09/17 04:39:08 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\findstr.exe
[2009/09/17 04:39:08 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshbth.dll
[2009/09/17 04:39:07 | 02,680,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\accessibilitycpl.dll
[2009/09/17 04:39:07 | 02,225,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcenter.dll
[2009/09/17 04:39:07 | 00,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webcheck.dll
[2009/09/17 04:39:07 | 00,157,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vdsutil.dll
[2009/09/17 04:39:07 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ulib.dll
[2009/09/17 04:39:07 | 00,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshext.dll
[2009/09/17 04:39:07 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\feclient.dll
[2009/09/17 04:39:07 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbehci.sys
[2009/09/17 04:39:06 | 06,100,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\chtbrkr.dll
[2009/09/17 04:39:06 | 00,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2009/09/17 04:39:06 | 00,825,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasdlg.dll
[2009/09/17 04:39:06 | 00,731,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2009/09/17 04:39:06 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2009/09/17 04:39:06 | 00,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imm32.dll
[2009/09/17 04:39:06 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscript.exe
[2009/09/17 04:39:06 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshext.dll
[2009/09/17 04:39:06 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pacer.sys
[2009/09/17 04:39:06 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iassvcs.dll
[2009/09/17 04:39:05 | 01,152,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themecpl.dll
[2009/09/17 04:39:05 | 00,714,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl
[2009/09/17 04:39:05 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pnpui.dll
[2009/09/17 04:39:05 | 00,606,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched20.dll
[2009/09/17 04:39:05 | 00,589,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptui.dll
[2009/09/17 04:39:05 | 00,299,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\udfs.sys
[2009/09/17 04:39:05 | 00,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tcpmon.dll
[2009/09/17 04:39:05 | 00,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsnmp32.dll
[2009/09/17 04:39:04 | 00,777,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slcc.dll
[2009/09/17 04:39:04 | 00,306,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasppp.dll
[2009/09/17 04:39:04 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scansetting.dll
[2009/09/17 04:39:04 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msutb.dll
[2009/09/17 04:39:04 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshom.ocx
[2009/09/17 04:39:04 | 00,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntmarta.dll
[2009/09/17 04:39:04 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wanarp.sys
[2009/09/17 04:39:04 | 00,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstlsapi.dll
[2009/09/17 04:39:04 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasads.dll
[2009/09/17 04:39:04 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dataclen.dll
[2009/09/17 04:39:04 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mssprxy.dll
[2009/09/17 04:39:04 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsbyuv.dll
[2009/09/17 04:39:03 | 03,072,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkmap.dll
[2009/09/17 04:39:03 | 00,678,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2009/09/17 04:39:03 | 00,474,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2009/09/17 04:39:03 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasplap.dll
[2009/09/17 04:39:03 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2009/09/17 04:39:03 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVolSSO.dll
[2009/09/17 04:39:03 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powrprof.dll
[2009/09/17 04:39:03 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iasacct.dll
[2009/09/17 04:39:03 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ifmon.dll
[2009/09/17 04:39:03 | 00,009,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardres.dll
[2009/09/17 04:39:03 | 00,009,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardres.dll
[2009/09/17 04:39:02 | 01,645,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\connect.dll
[2009/09/17 04:39:02 | 01,248,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PerfCenterCPL.dll
[2009/09/17 04:39:02 | 00,723,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\powercpl.dll
[2009/09/17 04:39:02 | 00,622,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVXENCD.DLL
[2009/09/17 04:39:02 | 00,619,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2009/09/17 04:39:02 | 00,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlangpui.dll
[2009/09/17 04:39:02 | 00,352,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2009/09/17 04:39:02 | 00,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleprn.dll
[2009/09/17 04:39:02 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authz.dll
[2009/09/17 04:39:02 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\newdev.exe
[2009/09/17 04:39:02 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmmon32.exe
[2009/09/17 04:39:02 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fc.exe
[2009/09/17 04:39:02 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\kbdhid.sys
[2009/09/17 04:39:01 | 02,515,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\accessibilitycpl.dll
[2009/09/17 04:39:01 | 01,224,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sud.dll
[2009/09/17 04:39:01 | 00,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\systemcpl.dll
[2009/09/17 04:39:01 | 00,615,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\themeui.dll
[2009/09/17 04:39:01 | 00,464,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pcaui.dll
[2009/09/17 04:39:01 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BFE.DLL
[2009/09/17 04:39:01 | 00,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thawbrkr.dll
[2009/09/17 04:39:01 | 00,295,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\raschap.dll
[2009/09/17 04:39:01 | 00,186,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scksp.dll
[2009/09/17 04:39:01 | 00,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\npfs.sys
[2009/09/17 04:39:01 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hidserv.dll
[2009/09/17 04:39:01 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscisvif.dll
[2009/09/17 04:39:00 | 01,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usercpl.dll
[2009/09/17 04:39:00 | 00,516,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\autoplay.dll
[2009/09/17 04:39:00 | 00,497,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2009/09/17 04:39:00 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\samlib.dll
[2009/09/17 04:39:00 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmci.dll
[2009/09/17 04:39:00 | 00,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rtutils.dll
[2009/09/17 04:39:00 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iaspolcy.dll
[2009/09/17 04:39:00 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwinsat.dll
[2009/09/17 04:38:59 | 02,575,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncCenter.dll
[2009/09/17 04:38:59 | 01,671,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanpref.dll
[2009/09/17 04:38:59 | 00,408,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msinfo32.exe
[2009/09/17 04:38:59 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2009/09/17 04:38:59 | 00,198,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fastfat.sys
[2009/09/17 04:38:59 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2009/09/17 04:38:59 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pintlgnt.ime
[2009/09/17 04:38:59 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2009/09/17 04:38:59 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\regapi.dll
[2009/09/17 04:38:59 | 00,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rekeywiz.exe
[2009/09/17 04:38:59 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimtf.dll
[2009/09/17 04:38:58 | 00,735,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll
[2009/09/17 04:38:58 | 00,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll
[2009/09/17 04:38:58 | 00,532,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpcao.dll
[2009/09/17 04:38:58 | 00,289,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscandui.dll
[2009/09/17 04:38:58 | 00,242,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tapisrv.dll
[2009/09/17 04:38:58 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scksp.dll
[2009/09/17 04:38:58 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdsutil.dll
[2009/09/17 04:38:58 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpwsx.dll
[2009/09/17 04:38:58 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PnPUnattend.exe
[2009/09/17 04:38:58 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\feclient.dll
[2009/09/17 04:38:58 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printfilterpipelineprxy.dll
[2009/09/17 04:38:57 | 02,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPEncEn.dll
[2009/09/17 04:38:57 | 01,642,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPEncEn.dll
[2009/09/17 04:38:57 | 00,669,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wiaaut.dll
[2009/09/17 04:38:57 | 00,306,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scesrv.dll
[2009/09/17 04:38:57 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2009/09/17 04:38:57 | 00,290,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webcheck.dll
[2009/09/17 04:38:57 | 00,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dsprop.dll
[2009/09/17 04:38:57 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpr.dll
[2009/09/17 04:38:57 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certprop.dll
[2009/09/17 04:38:56 | 01,102,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmsys.cpl
[2009/09/17 04:38:56 | 00,779,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2009/09/17 04:38:56 | 00,439,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winhttp.dll
[2009/09/17 04:38:56 | 00,313,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll
[2009/09/17 04:38:56 | 00,163,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontext.dll
[2009/09/17 04:38:56 | 00,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Faultrep.dll
[2009/09/17 04:38:56 | 00,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AudioSes.dll
[2009/09/17 04:38:56 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleprn.dll
[2009/09/17 04:38:56 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3msm.dll
[2009/09/17 04:38:56 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rekeywiz.exe
[2009/09/17 04:38:56 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iaspolcy.dll
[2009/09/17 04:38:56 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\whealogr.dll
[2009/09/17 04:38:56 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsdchngr.dll
[2009/09/17 04:38:56 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscisvif.dll
[2009/09/17 04:38:55 | 01,689,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscui.cpl
[2009/09/17 04:38:55 | 00,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2009/09/17 04:38:55 | 00,445,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptui.dll
[2009/09/17 04:38:55 | 00,407,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpapimig.exe
[2009/09/17 04:38:55 | 00,320,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\unimdm.tsp
[2009/09/17 04:38:55 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certreq.exe
[2009/09/17 04:38:55 | 00,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3msm.dll
[2009/09/17 04:38:55 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\perfdisk.dll
[2009/09/17 04:38:54 | 01,738,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscui.cpl
[2009/09/17 04:38:54 | 00,642,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasgcw.dll
[2009/09/17 04:38:54 | 00,557,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpeffects.dll
[2009/09/17 04:38:54 | 00,080,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hdwwiz.exe
[2009/09/17 04:38:53 | 03,341,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netshell.dll
[2009/09/17 04:38:53 | 00,595,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2009/09/17 04:38:53 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasplap.dll
[2009/09/17 04:38:53 | 00,221,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll
[2009/09/17 04:38:53 | 00,207,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\extmgr.dll
[2009/09/17 04:38:53 | 00,177,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scecli.dll
[2009/09/17 04:38:53 | 00,134,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2009/09/17 04:38:53 | 00,133,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\extmgr.dll
[2009/09/17 04:38:53 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dimsroam.dll
[2009/09/17 04:38:53 | 00,032,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBCAMD2.sys
[2009/09/17 04:38:52 | 00,539,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmdev.dll
[2009/09/17 04:38:52 | 00,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll
[2009/09/17 04:38:52 | 00,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certreq.exe
[2009/09/17 04:38:52 | 00,209,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpwd.sys
[2009/09/17 04:38:52 | 00,170,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpipcfg.dll
[2009/09/17 04:38:52 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tcpmon.dll
[2009/09/17 04:38:52 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conime.exe
[2009/09/17 04:38:52 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdWSD.dll
[2009/09/17 04:38:52 | 00,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmmon32.exe
[2009/09/17 04:38:52 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSTheme.exe
[2009/09/17 04:38:52 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PnPutil.exe
[2009/09/17 04:38:52 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwinsat.dll
[2009/09/17 04:38:51 | 00,644,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSMPEG2ENC.DLL
[2009/09/17 04:38:51 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msutb.dll
[2009/09/17 04:38:51 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanui.dll
[2009/09/17 04:38:51 | 00,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netplwiz.dll
[2009/09/17 04:38:51 | 00,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SndVol.exe
[2009/09/17 04:38:51 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rmcast.sys
[2009/09/17 04:38:51 | 00,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shsetup.dll
[2009/09/17 04:38:51 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax
[2009/09/17 04:38:51 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rassstp.sys
[2009/09/17 04:38:51 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\watchdog.sys
[2009/09/17 04:38:51 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uxsms.dll
[2009/09/17 04:38:51 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\whealogr.dll
[2009/09/17 04:38:50 | 02,438,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oobefldr.dll
[2009/09/17 04:38:50 | 00,616,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll
[2009/09/17 04:38:50 | 00,521,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cmdial32.dll
[2009/09/17 04:38:50 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cmdial32.dll
[2009/09/17 04:38:50 | 00,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\raschap.dll
[2009/09/17 04:38:50 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdmaud.drv
[2009/09/17 04:38:50 | 00,165,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2009/09/17 04:38:50 | 00,142,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontext.dll
[2009/09/17 04:38:50 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SCardSvr.dll
[2009/09/17 04:38:50 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscsvc.dll
[2009/09/17 04:38:50 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\conime.exe
[2009/09/17 04:38:50 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsCtfMonitor.dll
[2009/09/17 04:38:49 | 02,535,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSVidCtl.dll
[2009/09/17 04:38:49 | 01,544,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVidCtl.dll
[2009/09/17 04:38:49 | 00,657,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVXENCD.DLL
[2009/09/17 04:38:49 | 00,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wiaaut.dll
[2009/09/17 04:38:49 | 00,409,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskcomp.dll
[2009/09/17 04:38:49 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unimdm.tsp
[2009/09/17 04:38:49 | 00,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanui.dll
[2009/09/17 04:38:49 | 00,187,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\nwifi.sys
[2009/09/17 04:38:49 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlgpclnt.dll
[2009/09/17 04:38:49 | 00,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdWSD.dll
[2009/09/17 04:38:49 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cipher.exe
[2009/09/17 04:38:48 | 02,153,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oobefldr.dll
[2009/09/17 04:38:48 | 01,702,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2009/09/17 04:38:48 | 00,688,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll
[2009/09/17 04:38:48 | 00,425,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shwebsvc.dll
[2009/09/17 04:38:48 | 00,259,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasppp.dll
[2009/09/17 04:38:48 | 00,137,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dsprop.dll
[2009/09/17 04:38:48 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\l2nacp.dll
[2009/09/17 04:38:48 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
[2009/09/17 04:38:47 | 00,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\modemui.dll
[2009/09/17 04:38:47 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\input.dll
[2009/09/17 04:38:47 | 00,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\softkbd.dll
[2009/09/17 04:38:47 | 00,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\btpanui.dll
[2009/09/17 04:38:47 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2009/09/17 04:38:47 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsetup.dll
[2009/09/17 04:38:46 | 06,103,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\chtbrkr.dll
[2009/09/17 04:38:46 | 00,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll
[2009/09/17 04:38:46 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscandui.dll
[2009/09/17 04:38:46 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasmontr.dll
[2009/09/17 04:38:46 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasmontr.dll
[2009/09/17 04:38:46 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dataclen.dll
[2009/09/17 04:38:46 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscapi.dll
[2009/09/17 04:38:46 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NcdProp.dll
[2009/09/17 04:38:45 | 01,129,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstime.dll
[2009/09/17 04:38:45 | 00,542,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll
[2009/09/17 04:38:45 | 00,339,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2009/09/17 04:38:45 | 00,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netplwiz.dll
[2009/09/17 04:38:45 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\credui.dll
[2009/09/17 04:38:45 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlgpclnt.dll
[2009/09/17 04:38:45 | 00,072,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ohci1394.sys
[2009/09/17 04:38:45 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\findstr.exe
[2009/09/17 04:38:44 | 02,226,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkexplorer.dll
[2009/09/17 04:38:44 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstime.dll
[2009/09/17 04:38:44 | 00,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpeffects.dll
[2009/09/17 04:38:44 | 00,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll
[2009/09/17 04:38:44 | 00,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstask.dll
[2009/09/17 04:38:44 | 00,227,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2009/09/17 04:38:44 | 00,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdwcn.dll
[2009/09/17 04:38:44 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceTypes.dll
[2009/09/17 04:38:44 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSDMon.dll
[2009/09/17 04:38:44 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adsmsext.dll
[2009/09/17 04:38:44 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\deskmon.dll
[2009/09/17 04:38:43 | 00,946,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMADMOD.DLL
[2009/09/17 04:38:43 | 00,414,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll
[2009/09/17 04:38:43 | 00,217,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InkEd.dll
[2009/09/17 04:38:43 | 00,193,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2009/09/17 04:38:43 | 00,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpcsvc.dll
[2009/09/17 04:38:43 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpresult.exe
[2009/09/17 04:38:43 | 00,113,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctfui.dll
[2009/09/17 04:38:43 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\logagent.exe
[2009/09/17 04:38:43 | 00,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cipher.exe
[2009/09/17 04:38:43 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wscapi.dll
[2009/09/17 04:38:43 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ifmon.dll
[2009/09/17 04:38:43 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\version.dll
[2009/09/17 04:38:42 | 00,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmnet.dll
[2009/09/17 04:38:42 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\thawbrkr.dll
[2009/09/17 04:38:42 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mdminst.dll
[2009/09/17 04:38:42 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpdwcn.dll
[2009/09/17 04:38:42 | 00,190,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2009/09/17 04:38:42 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\softkbd.dll
[2009/09/17 04:38:42 | 00,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\logagent.exe
[2009/09/17 04:38:42 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sendmail.dll
[2009/09/17 04:38:42 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2009/09/17 04:38:42 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimtf.dll
[2009/09/17 04:38:41 | 00,403,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MediaMetadataHandler.dll
[2009/09/17 04:38:41 | 00,356,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MediaMetadataHandler.dll
[2009/09/17 04:38:41 | 00,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSDMon.dll
[2009/09/17 04:38:41 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSAC3ENC.DLL
[2009/09/17 04:38:41 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\olepro32.dll
[2009/09/17 04:38:41 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctfui.dll
[2009/09/17 04:38:41 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rshx32.dll
[2009/09/17 04:38:41 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rasdial.exe
[2009/09/17 04:38:41 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidusb.sys
[2009/09/17 04:38:40 | 00,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll
[2009/09/17 04:38:40 | 00,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2009/09/17 04:38:40 | 00,166,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\puiapi.dll
[2009/09/17 04:38:40 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mprapi.dll
[2009/09/17 04:38:40 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmsynth.dll
[2009/09/17 04:38:40 | 00,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\smb.sys
[2009/09/17 04:38:40 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\deskadp.dll
[2009/09/17 04:38:40 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscdll.dll
[2009/09/17 04:38:39 | 00,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMSPDMOD.DLL
[2009/09/17 04:38:39 | 00,418,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmdev.dll
[2009/09/17 04:38:39 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\input.dll
[2009/09/17 04:38:39 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mprapi.dll
[2009/09/17 04:38:39 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdSSDP.dll
[2009/09/17 04:38:39 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FwRemoteSvr.dll
[2009/09/17 04:38:39 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshbth.dll
[2009/09/17 04:38:39 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2009/09/17 04:38:39 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\version.dll
[2009/09/17 04:38:39 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msisip.dll
[2009/09/17 04:38:38 | 00,758,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMADMOD.DLL
[2009/09/17 04:38:38 | 00,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdmaud.drv
[2009/09/17 04:38:38 | 00,116,736 | ---- | C] (Microsoft) -- C:\Windows\SysNative\SMBHelperClass.dll
[2009/09/17 04:38:38 | 00,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gpapi.dll
[2009/09/17 04:38:38 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax
[2009/09/17 04:38:38 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdSSDP.dll
[2009/09/17 04:38:38 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthci.dll
[2009/09/17 04:38:38 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fc.exe
[2009/09/17 04:38:37 | 02,247,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkexplorer.dll
[2009/09/17 04:38:37 | 00,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpps.dll
[2009/09/17 04:38:37 | 00,291,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapp3hst.dll
[2009/09/17 04:38:37 | 00,231,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscntfy.dll
[2009/09/17 04:38:37 | 00,187,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapp3hst.dll
[2009/09/17 04:38:37 | 00,125,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tintlgnt.ime
[2009/09/17 04:38:37 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dmusic.dll
[2009/09/17 04:38:37 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxg.sys
[2009/09/17 04:38:37 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PNPXAssoc.dll
[2009/09/17 04:38:37 | 00,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dot3cfg.dll
[2009/09/17 04:38:37 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\l2nacp.dll
[2009/09/17 04:38:37 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ftp.exe
[2009/09/17 04:38:37 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscapi.dll
[2009/09/17 04:38:37 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjint40.dll
[2009/09/17 04:38:37 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsCtfMonitor.dll
[2009/09/17 04:38:37 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CHxReadingStringIME.dll
[2009/09/17 04:38:36 | 00,347,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmnet.dll
[2009/09/17 04:38:36 | 00,105,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceClassExtension.dll
[2009/09/17 04:38:36 | 00,094,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceClassExtension.dll
[2009/09/17 04:38:36 | 00,083,456 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\SMBHelperClass.dll
[2009/09/17 04:38:36 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Storprop.dll
[2009/09/17 04:38:36 | 00,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidclass.sys
[2009/09/17 04:38:36 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ftp.exe
[2009/09/17 04:38:36 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tdi.sys
[2009/09/17 04:38:36 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscdll.dll
[2009/09/17 04:38:36 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsdchngr.dll
[2009/09/17 04:38:35 | 00,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceTypes.dll
[2009/09/17 04:38:35 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mydocs.dll
[2009/09/17 04:38:35 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappcfg.dll
[2009/09/17 04:38:35 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdWCN.dll
[2009/09/17 04:38:35 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdWCN.dll
[2009/09/17 04:38:35 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasdiag.dll
[2009/09/17 04:38:35 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
[2009/09/17 04:38:35 | 00,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hbaapi.dll
[2009/09/17 04:38:35 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dot3cfg.dll
[2009/09/17 04:38:35 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\bthudtask.exe
[2009/09/17 04:38:35 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ipconfig.exe
[2009/09/17 04:38:35 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rasdial.exe
[2009/09/17 04:38:35 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CHxReadingStringIME.dll
[2009/09/17 04:38:34 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSMPEG2ENC.DLL
[2009/09/17 04:38:34 | 00,211,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappcfg.dll
[2009/09/17 04:38:34 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SLLUA.exe
[2009/09/17 04:38:34 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSAC3ENC.DLL
[2009/09/17 04:38:34 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nslookup.exe
[2009/09/17 04:38:34 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tscupgrd.exe
[2009/09/17 04:38:34 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tscupgrd.exe
[2009/09/17 04:38:34 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\networkitemfactory.dll
[2009/09/17 04:38:34 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slcinst.dll
[2009/09/17 04:38:34 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\networkitemfactory.dll
[2009/09/17 04:38:33 | 00,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappgnui.dll
[2009/09/17 04:38:33 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappgnui.dll
[2009/09/17 04:38:33 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdeploy.dll
[2009/09/17 04:38:33 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\slcinst.dll
[2009/09/17 04:38:33 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\hbaapi.dll
[2009/09/17 04:38:33 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ocsetup.exe
[2009/09/17 04:38:33 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ocsetup.exe
[2009/09/17 04:38:33 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FwRemoteSvr.dll
[2009/09/17 04:38:33 | 00,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msacm32.drv
[2009/09/17 04:38:32 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dfsc.sys
[2009/09/17 04:38:32 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bitsigd.dll
[2009/09/17 04:38:32 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msacm32.drv
[2009/09/17 04:38:32 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mmcico.dll
[2009/09/17 04:38:31 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cbsra.exe
[2009/09/17 04:38:31 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wscapi.dll
[2009/09/17 04:38:31 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gpupdate.exe
[2009/09/17 04:38:30 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bthudtask.exe
[2009/09/17 04:38:30 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NcdProp.dll
[2009/09/17 04:38:30 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iscsilog.dll
[2009/09/17 04:38:29 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vss_ps.dll
[2009/09/17 04:38:29 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbcconf.dll
[2009/09/17 04:38:29 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcconf.dll
[2009/09/17 04:38:29 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vdmdbg.dll
[2009/09/17 04:38:29 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetppui.dll
[2009/09/17 04:38:28 | 00,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpps.dll
[2009/09/17 04:38:28 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
[2009/09/17 04:38:28 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrnr.dll
[2009/09/17 04:38:28 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2009/09/17 04:38:28 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\slwga.dll
[2009/09/17 04:38:27 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\cdrom.sys
[2009/09/17 04:38:27 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbohci.sys
[2009/09/17 04:38:27 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\midimap.dll
[2009/09/17 04:38:27 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\midimap.dll
[2009/09/17 04:38:24 | 00,068,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\stream.sys
[2009/09/17 04:38:24 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
[2009/09/17 04:38:23 | 00,485,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2009/09/17 04:38:23 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2009/09/17 04:38:23 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\raspppoe.sys
[2009/09/17 04:38:23 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2009/09/17 04:38:22 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\f3ahvoas.dll
[2009/09/17 04:38:22 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\f3ahvoas.dll
[2009/09/17 04:38:22 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msimsg.dll
[2009/09/17 04:38:22 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msimsg.dll
[2009/09/17 04:38:02 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wdscore.dll
[2009/09/17 04:37:56 | 00,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvstore.dll
[2009/09/17 04:37:21 | 00,936,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmiEngine.dll
[2009/09/17 04:37:19 | 00,293,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wdscore.dll
[2009/09/17 04:37:19 | 00,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PkgMgr.exe
[2009/09/17 04:37:12 | 00,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drvstore.dll
[2009/09/10 11:48:54 | 00,000,000 | ---D | C] -- C:\Users\Yolanda\Documents\Ricky
[2009/09/09 08:31:20 | 00,756,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2009/09/09 08:31:20 | 00,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2009/09/09 08:31:12 | 02,900,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVCORE.DLL
[2009/09/09 08:31:11 | 03,547,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2009/09/09 08:31:11 | 02,386,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVCORE.DLL
[2009/09/09 08:31:10 | 02,868,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2009/09/09 08:31:09 | 00,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2009/09/09 08:31:09 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll
[2009/09/09 08:31:09 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe
[2009/09/09 08:31:09 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe
[2009/09/09 08:31:08 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe
[2009/09/09 08:31:08 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe
[2009/09/09 08:31:07 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll
[2009/09/09 08:31:07 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll
[2009/09/09 08:30:45 | 01,425,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tcpip.sys
[2009/09/09 08:30:44 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netiohlp.dll
[2009/09/09 08:30:43 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netiohlp.dll
[2009/09/09 08:30:43 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\tcpipreg.sys
[2009/09/09 08:30:42 | 00,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\NETSTAT.EXE
[2009/09/09 08:30:42 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ARP.EXE
[2009/09/09 08:30:41 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\NETSTAT.EXE
[2009/09/09 08:30:41 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ARP.EXE
[2009/09/09 08:30:41 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MRINFO.EXE
[2009/09/09 08:30:40 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\finger.exe
[2009/09/09 08:30:40 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TCPSVCS.EXE
[2009/09/09 08:30:40 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\HOSTNAME.EXE
[2009/09/09 08:30:39 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MRINFO.EXE
[2009/09/09 08:30:39 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\finger.exe
[2009/09/09 08:30:39 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TCPSVCS.EXE
[2009/09/09 08:30:39 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\HOSTNAME.EXE
[2009/09/09 08:30:38 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ROUTE.EXE
[2009/09/09 08:30:38 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ROUTE.EXE
[2009/09/09 08:30:36 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2009/09/09 08:30:36 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2009/09/09 08:29:28 | 00,615,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlansvc.dll
[2009/09/09 08:29:28 | 00,353,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2009/09/09 08:29:27 | 00,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlansec.dll
[2009/09/09 08:29:27 | 00,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll
[2009/09/09 08:29:27 | 00,157,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\L2SecHC.dll
[2009/09/09 08:29:27 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanhlp.dll
[2009/09/09 08:29:27 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanhlp.dll
[2009/09/09 08:29:26 | 00,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlansec.dll
[2009/09/09 08:29:26 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\L2SecHC.dll
[2009/09/09 08:29:26 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanapi.dll
[2009/09/09 08:29:26 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanapi.dll
[2009/03/13 21:28:09 | 00,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll

========== Files - Modified Within 30 Days ==========

[2009/10/08 09:40:00 | 00,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/08 09:03:51 | 00,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/08 09:03:51 | 00,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/08 00:28:40 | 00,000,880 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2009/10/07 20:49:20 | 00,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/07 15:09:06 | 00,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2009/10/07 15:09:06 | 00,595,446 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2009/10/07 15:09:06 | 00,101,144 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2009/10/07 15:04:53 | 00,024,147 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2009/10/07 15:04:06 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/07 15:04:04 | 00,067,584 | ---- | M] () -- C:\Windows\bootstat.dat
[2009/10/07 15:03:20 | 02,232,377 | -H-- | M] () -- C:\Users\Yolanda\AppData\Local\IconCache.db
[2009/10/07 10:25:10 | 00,001,932 | ---- | M] () -- C:\Users\Yolanda\Desktop\HijackThis.lnk
[2009/10/05 01:00:02 | 00,001,696 | ---- | M] () -- C:\Windows\tasks\wrSpySweeper_L9B99D5E5473E4E98B1969FBCED88C7CC.job
[2009/10/01 17:13:05 | 00,000,534 | ---- | M] () -- C:\Users\Yolanda\AppData\Roaming\wklnhst.dat
[2009/10/01 10:29:14 | 00,238,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe
[2009/10/01 01:00:00 | 00,000,348 | ---- | M] () -- C:\Windows\tasks\McQcTask.job
[2009/09/18 13:58:57 | 00,296,016 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2009/09/15 01:00:00 | 00,000,356 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/09/10 14:53:52 | 00,022,104 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

========== Files - No Company Name ==========
[2009/10/07 10:25:10 | 00,001,932 | ---- | C] () -- C:\Users\Yolanda\Desktop\HijackThis.lnk
[2009/09/17 04:40:37 | 00,121,856 | ---- | C] () -- C:\Windows\SysNative\EhStorAuthn.dll
[2009/09/17 04:40:37 | 00,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/17 04:40:25 | 00,262,552 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd
[2009/09/17 04:40:03 | 00,471,992 | ---- | C] () -- C:\Windows\SysNative\dot3.tmf
[2009/09/17 04:40:02 | 00,700,507 | ---- | C] () -- C:\Windows\SysNative\eaphost.tmf
[2009/09/17 04:39:59 | 00,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/09/17 04:39:59 | 00,107,612 | ---- | C] () -- C:\Windows\SysNative\StructuredQuerySchema.bin
[2009/09/17 04:39:56 | 03,662,128 | ---- | C] () -- C:\Windows\SysWow64\locale.nls
[2009/09/17 04:39:56 | 03,662,128 | ---- | C] () -- C:\Windows\SysNative\locale.nls
[2009/09/17 04:39:56 | 00,395,723 | ---- | C] () -- C:\Windows\SysNative\onex.tmf
[2009/09/17 04:39:31 | 00,207,968 | ---- | C] () -- C:\Windows\SysNative\WFP.TMF
[2009/09/17 04:39:29 | 00,092,918 | ---- | C] () -- C:\Windows\SysWow64\slmgr.vbs
[2009/09/17 04:39:29 | 00,092,918 | ---- | C] () -- C:\Windows\SysNative\slmgr.vbs
[2009/09/17 04:39:25 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/09/17 04:38:57 | 00,009,239 | ---- | C] () -- C:\Windows\SysWow64\spcinstrumentation.man
[2009/09/17 04:38:57 | 00,009,239 | ---- | C] () -- C:\Windows\SysNative\spcinstrumentation.man
[2009/09/17 04:38:27 | 00,009,212 | ---- | C] () -- C:\Windows\SysWow64\RacUR.xml
[2009/09/17 04:38:27 | 00,009,212 | ---- | C] () -- C:\Windows\SysNative\RacUR.xml
[2009/09/09 08:29:29 | 02,608,861 | ---- | C] () -- C:\Windows\SysNative\wlan.tmf
[2009/09/02 16:00:47 | 00,000,680 | ---- | C] () -- C:\Users\Yolanda\AppData\Local\d3d9caps.dat
[2009/06/01 04:54:54 | 01,350,656 | ---- | C] () -- C:\Windows\SysWow64\nss16A5.dll
[2009/05/18 14:11:41 | 00,000,534 | ---- | C] () -- C:\Users\Yolanda\AppData\Roaming\wklnhst.dat
[2009/05/10 11:17:26 | 00,005,632 | ---- | C] () -- C:\Users\Yolanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/10 11:12:35 | 00,024,226 | ---- | C] () -- C:\Users\Yolanda\AppData\Roaming\UserTile.png
[2009/05/05 14:24:56 | 02,232,377 | -H-- | C] () -- C:\Users\Yolanda\AppData\Local\IconCache.db
[2009/05/05 13:27:23 | 00,070,104 | ---- | C] () -- C:\Users\Yolanda\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/04/21 18:26:56 | 00,031,088 | ---- | C] () -- C:\Windows\SysWow64\wrLZMA.dll
[2009/03/13 22:05:40 | 00,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIOFM4.dll
[2009/03/13 22:05:40 | 00,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIBUN5.dll
[2008/01/20 22:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 11:25:49 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 11:25:49 | 00,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini
[2006/11/02 08:34:27 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 08:34:27 | 00,000,211 | ---- | C] () -- C:\Windows\win.ini
[2006/10/10 22:09:24 | 00,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2006/10/10 22:09:24 | 00,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2002/03/21 15:39:02 | 00,073,728 | ---- | C] () -- C:\Windows\SysWow64\UNACEV2.DLL
[2001/12/26 19:12:30 | 00,065,536 | ---- | C] () -- C:\Windows\SysWow64\multiplex_vcd.dll
[2001/09/04 02:46:38 | 00,110,592 | ---- | C] () -- C:\Windows\SysWow64\Hmpg12.dll
[2001/07/30 19:33:56 | 00,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC.dll
[2001/07/24 01:04:36 | 00,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC_MMX.dll

========== LOP Check ==========

[2009/10/01 17:13:05 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming
[2009/07/06 17:01:05 | 00,000,000 | -HSD | M] -- C:\Users\Yolanda\AppData\Roaming\.#
[2009/06/10 18:28:11 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\ACD Systems
[2009/05/05 13:27:27 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\Acer
[2009/03/13 22:10:32 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\Acer GameZone Console
[2009/05/15 11:45:14 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\eSobi
[2009/05/05 13:27:27 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\Leadertech
[2009/08/29 10:02:15 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\LimeWire
[2006/11/02 11:07:25 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\Media Center Programs
[2009/05/10 11:12:35 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\PeerNetworking
[2009/05/26 17:42:34 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\SecondLife
[2009/05/18 14:11:44 | 00,000,000 | ---D | M] -- C:\Users\Yolanda\AppData\Roaming\Template
[2009/10/08 00:28:40 | 00,000,880 | ---- | M] () -- C:\Windows\Tasks\Google Software Updater.job
[2009/10/07 20:49:20 | 00,000,894 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/08 09:40:00 | 00,000,898 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2009/09/15 01:00:00 | 00,000,356 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2009/10/01 01:00:00 | 00,000,348 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2009/10/07 15:04:06 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/10/07 15:03:23 | 00,028,526 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009/10/05 01:00:02 | 00,001,696 | ---- | M] () -- C:\Windows\Tasks\wrSpySweeper_L9B99D5E5473E4E98B1969FBCED88C7CC.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:193426B4
< End of report >









OTL Extras logfile created on: 10/8/2009 9:38:01 AM - Run 1
OTL by OldTimer - Version 3.0.18.4 Folder = C:\Users\Yolanda\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.34 Gb Available Physical Memory | 58.52% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 289.58 Gb Total Space | 215.64 Gb Free Space | 74.47% Space Free | Partition Type: NTFS
Drive D: | 291.59 Gb Total Space | 280.51 Gb Free Space | 96.20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 702.31 Mb Total Space | 696.61 Mb Free Space | 99.19% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOLANDA-PC
Current User Name: Yolanda
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %* File not found
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [print] -- rundll32.exe C:\Windows\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Directory [ACDSee 9.0.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [ACDSee 9.0.Browse] -- "C:\Program Files (x86)\ACD Systems\ACDSee\9.0\ACDSeeQV.exe" "%1" (ACD Systems Ltd.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 93 84 20 CA 89 38 CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 1
"DoNotAllowExceptions" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09C0EA47-EE29-4180-B09B-8715F78A942A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1542C11E-9699-47EA-9074-CE7B91748F0A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{30555814-8EC4-4A6C-80C9-319B42C32422}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{59FC2C5D-B2C8-4401-B1F5-5367EDE7B7E4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6D67033D-9011-48BA-A38C-D78016F91BB0}" = lport=10243 | protocol=6 | dir=in | app=system |
"{732C6E28-EF85-4FFA-B101-94935DC64C72}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{99B92C60-1372-4569-B920-7785F9A89D40}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9FAF068E-F161-42E2-B64B-78866E6520AC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F2D00664-F6BE-4735-9646-E95C1A8D9B76}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{11DE3C77-8D07-4ED4-8A9E-2C11CBB199C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{12D34FB7-EA9F-4378-9452-B0139F1CE503}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1668E2CF-BBE3-4A2A-922B-9268236D8434}" = dir=in | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe |
"{19EA7827-1125-43E6-B135-E3F7A9880CCE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1CE9CFE3-97EB-4A1F-9382-BA8EB5504233}" = protocol=6 | dir=out | app=system |
"{1DA4DF50-7A05-409D-BA6B-03E28E26184D}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{239448E9-D534-4A4B-98B8-926E0E1665F3}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{24A29ABB-BAFB-422F-9B3B-1FA312F991AB}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{2FDC4712-0070-4C45-B27B-7328262E6169}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{3AE451E9-91B6-4640-A19F-7D75F9584ABB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5A516DC0-C83C-4F92-91EF-4A21F674CACD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{5FB9C3C8-9BF6-4FCD-99DB-42D725DEFCA5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{60A5F4A5-5D3F-44FB-B485-541C3A893C51}" = dir=in | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{63F1225A-F8AA-4AA2-9974-D4C219D97A52}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6FADE3B4-DBF8-4F3D-91DD-F7A32A087BA6}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe |
"{743D8FE1-0953-4A9A-BF80-26A5E88361EA}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{7643B6C0-1B9E-482D-93BE-F0547AC92F6A}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{7B829611-6E88-4E5B-A5C1-7B28FB5B157C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7FE2CD36-9D58-4084-9106-C17CCD7CBBC7}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{7FF28C58-51D0-4A85-B313-34C36613D7D0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{8CB91948-6C3F-40BA-8BC6-A3DAAA3394F1}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{94B00D51-AAFF-484A-A6EA-AC69F9376F8B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{951E6639-C9F5-4DCC-AF59-7FB313285A95}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{95F52980-D4E6-49F2-94AA-45C5D7CA06E8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A3EE557F-F25E-48D4-816F-DCC98A31A546}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{A8B1FA73-577E-4033-8674-6F780465106E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB77AFF3-2463-4364-B83B-FC34CC1F67C8}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{ADB4489C-DCFF-47CE-9F39-90954D6A188D}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{B72C613F-D27D-4AA3-991A-6E3557C32616}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CE833960-7A3E-4151-9054-B1A046F77D46}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D30D125C-EA08-4FBD-B228-905844300D7B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D4288692-7C3D-4D23-BBF5-39FD6A28DE8E}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{D42AC248-F7A0-4079-AD02-1F1FBC06A1C0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D7DAAEDA-4209-4442-808D-BFFEF5DBA7E9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DBE52BFA-A4AC-42EE-AE12-B22F5E22DE45}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EAE9D013-EC6C-4D68-A944-321CEE09B288}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{ECF3DA71-4F36-4203-9B7B-38F3830A41A4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F042D123-C7C6-4813-9034-DBCA5F2EA3EB}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe |
"TCP Query User{099E7E4B-3B02-4CBC-B242-50FF3E3C0A17}C:\program files (x86)\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\secondlife\slvoice.exe |
"TCP Query User{F5E3D0FC-9D65-415B-A97D-DE0C74D2ED8D}C:\program files (x86)\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"UDP Query User{115A8721-0F7D-4847-8180-E3C92101C42B}C:\program files (x86)\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"UDP Query User{751B5A46-A40A-4103-B13D-7729C8F7CFB5}C:\program files (x86)\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\secondlife\slvoice.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D8B2C435-8737-431E-8784-24CD13B0B821}" = PE585QAEncoder-64
"Agere Systems Soft Modem" = Agere Systems PCI-SV92EX Soft Modem
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{22E9CF2B-4063-4dab-A251-93FA46F7DECC}_is1" = Spy Sweeper
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 15
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112615863}" = Agatha Christie Death on the Nile
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92022F8E-2E55-4A16-88EB-B4778B35E942}" = ACDSee for PENTAX 3.0
"{A1575410-DF46-44B2-B02C-E3A6A2175796}" = sQusi Tracking Plus
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{B9B02A9E-8074-4C3F-AAE5-311528F34FED}" = NTI Photo Maker Hot Fix
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{DDA223A7-627F-4173-9CA4-A9C531BCBB62}" = NTI JewelCase Maker Hot Fix
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FE24D361-A3E8-11DE-88F3-005056806466}" = Google Earth Plug-in
"4704c764-6c8e-d735-c98d-b67c8a760b76" = Contextual Application Bignetdaddy
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Acer Registration" = Acer Registration
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"a-squared Free_is1" = a-squared Free 4.0
"AVIConverter" = AVIConverter 5.1
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IncrediMail" = IncrediMail
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"InstallShield_{B9B02A9E-8074-4C3F-AAE5-311528F34FED}" = NTI Photo Maker Hot Fix
"InstallShield_{DDA223A7-627F-4173-9CA4-A9C531BCBB62}" = NTI JewelCase Maker Hot Fix
"LimeWire" = LimeWire 5.1.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSC" = McAfee SecurityCenter

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/10/2009 7:14:50 PM | Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/11/2009 9:25:57 PM | Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/14/2009 2:41:36 PM | Computer Name = Yolanda-PC | Source = Application Hang | ID = 1002
Description = The program IncMail.exe version 5.8.6.4130 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1bf8 Start Time: 01ca33cccb4e79ad Termination Time: 33

Error - 9/14/2009 10:03:13 PM | Computer Name = Yolanda-PC | Source = EventSystem | ID = 4621
Description =

Error - 9/15/2009 7:46:06 AM | Computer Name = Yolanda-PC | Source = Winlogon | ID = 4005
Description = The Windows logon process has unexpectedly terminated.

Error - 9/15/2009 7:49:04 AM | Computer Name = Yolanda-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/15/2009 4:25:11 PM | Computer Name = Yolanda-PC | Source = Application Hang | ID = 1002
Description = The program MSWorks.exe version 8.5.822.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: c9c Start Time: 01ca3641b7475d10 Termination Time: 3

Error - 9/15/2009 4:25:28 PM | Computer Name = Yolanda-PC | Source = Application Hang | ID = 1002
Description = The program wkswp.exe version 8.5.818.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: e28 Start Time: 01ca364284355e80 Termination Time: 4

Error - 9/15/2009 4:26:43 PM | Computer Name = Yolanda-PC | Source = Application Hang | ID = 1002
Description = The program WksWP.exe version 8.5.818.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 1858 Start Time: 01ca3642b64030d0 Termination Time: 10

Error - 9/16/2009 9:11:01 PM | Computer Name = Yolanda-PC | Source = MsiInstaller | ID = 1002
Description =

[ Media Center Events ]
Error - 6/9/2009 6:27:00 PM | Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 7/25/2009 12:25:21 AM | Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

Error - 7/28/2009 12:25:35 AM | Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

Error - 7/31/2009 12:25:41 AM | Computer Name = Yolanda-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

[ System Events ]
Error - 9/8/2009 5:26:17 PM | Computer Name = Yolanda-PC | Source = DCOM | ID = 10000
Description =

Error - 9/8/2009 6:06:00 PM | Computer Name = Yolanda-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:05:05 PM on 9/8/2009 was unexpected.

Error - 9/8/2009 6:06:01 PM | Computer Name = Yolanda-PC | Source = HTTP | ID = 15016
Description =

Error - 9/8/2009 6:19:28 PM | Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098
Description = Failed to set monitor event rule.

Error - 9/8/2009 8:19:55 PM | Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098
Description = Failed to set monitor event rule.

Error - 9/8/2009 9:15:05 PM | Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098
Description = Failed to set monitor event rule.

Error - 9/9/2009 4:48:02 PM | Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098
Description = Failed to set monitor event rule.

Error - 9/9/2009 8:40:20 PM | Computer Name = Yolanda-PC | Source = ssidrv | ID = 131098
Description = Failed to set monitor event rule.

Error - 9/10/2009 3:00:22 AM | Computer Name = Yolanda-PC | Source = DCOM | ID = 10005
Description =

Error - 9/10/2009 3:00:22 AM | Computer Name = Yolanda-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >

#10 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 08 October 2009 - 09:16 AM

Hi,

Please do the following:

We need to run an OTL Fix

  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox. Do not include the word "Code"

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
    FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=13&q="
    FF - prefs.js..browser.search.order.1: "Fast Browser Search"
    FF - prefs.js..browser.search.selectedEngine: "Fast Browser Search"
    FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=13&tid={B87C538B-2BE7-BA59-95CD-7CE04D8C471B}&q="
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click Posted Image.
  • A report will open. Copy and Paste that report in your next reply.



NEXT


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015

    Advertisements

Register to Remove


#11 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 08 October 2009 - 09:39 AM

GooredFix by jpshortstuff (24.09.09.1) Log created at 11:37 on 08/10/2009 (Yolanda) Firefox version 3.5.3 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [19:37 05/05/2009] {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [21:30 16/05/2009] {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [14:42 23/06/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [00:31 09/08/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [22:44 05/05/2009] "{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [14:28 06/05/2009] ---------- Old Logs ---------- GooredFix[15.35.52_08-10-2009].txt -=E.O.F=- GooredFix by jpshortstuff (24.09.09.1) Log created at 11:37 on 08/10/2009 (Yolanda) Firefox version 3.5.3 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [19:37 05/05/2009] {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [21:30 16/05/2009] {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [14:42 23/06/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [00:31 09/08/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [22:44 05/05/2009] "{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [14:28 06/05/2009] ---------- Old Logs ---------- GooredFix[15.35.52_08-10-2009].txt -=E.O.F=- All processes killed ========== OTL ========== No active process named explorer.exe was found! Prefs.js: "Fast Browser Search" removed from browser.search.defaultenginename Prefs.js: "http://www.fastbrows...?s=DEF&v=13&q=" removed from browser.search.defaulturl Prefs.js: "Fast Browser Search" removed from browser.search.order.1 Prefs.js: "Fast Browser Search" removed from browser.search.selectedEngine Prefs.js: "http://www.fastbrows...E04D8C471B}&q=" removed from keyword.URL ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Andrew ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Yolanda File delete failed. C:\Users\Yolanda\AppData\Local\Temp\jkos-Yolanda\binaries\ScanningProcess.exe scheduled to be deleted on reboot. ->Temp folder emptied: 86245745 bytes File delete failed. C:\Users\Yolanda\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 6888782 bytes ->Java cache emptied: 25621446 bytes ->FireFox cache emptied: 57173854 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes File delete failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcafee_ccdEp4NH5AQAPCJ scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_bXz4AzQS2kwd8i6 scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_Eh4hlK8ZMaMCtoY scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\mcmsc_FpGEqH87Wslkz1a scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_0CnpN0AGMqfhAAm scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_3cym36VlrgzjkEq scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_9qe3gMj5V9ztqnD scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_AfBPWnqxncAeSvP scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_K31dZaf12kCrtS0 scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_MUw5UPH39csoWyX scheduled to be deleted on reboot. File delete failed. C:\Windows\temp\sqlite_PpgiVYQF5Qtmq0C scheduled to be deleted on reboot. Windows Temp folder emptied: 242140 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 168.01 mb OTL by OldTimer - Version 3.0.18.4 log created on 10082009_112706 Files\Folders moved on Reboot... C:\Users\Yolanda\AppData\Local\Temp\jkos-Yolanda\binaries\ScanningProcess.exe moved successfully. File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot. File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot. File\Folder C:\Windows\temp\mcafee_ccdEp4NH5AQAPCJ not found! File\Folder C:\Windows\temp\mcmsc_bXz4AzQS2kwd8i6 not found! File\Folder C:\Windows\temp\mcmsc_Eh4hlK8ZMaMCtoY not found! File\Folder C:\Windows\temp\mcmsc_FpGEqH87Wslkz1a not found! C:\Windows\temp\sqlite_0CnpN0AGMqfhAAm moved successfully. C:\Windows\temp\sqlite_3cym36VlrgzjkEq moved successfully. File\Folder C:\Windows\temp\sqlite_9qe3gMj5V9ztqnD not found! File\Folder C:\Windows\temp\sqlite_AfBPWnqxncAeSvP not found! C:\Windows\temp\sqlite_K31dZaf12kCrtS0 moved successfully. File\Folder C:\Windows\temp\sqlite_MUw5UPH39csoWyX not found! File\Folder C:\Windows\temp\sqlite_PpgiVYQF5Qtmq0C not found! Registry entries deleted on Reboot...

#12 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 08 October 2009 - 09:50 AM

Hi, Can you please advise how your computer is running now and if there are any outstanding issues

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#13 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 08 October 2009 - 03:43 PM

I still have pages that don't load or drag. Some web pages are totally blank for different reasons. One being the tab indicates it's an image/pixel, when it once use to work? Ugghhh! I appreciate all the help your giving me!

#14 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 08 October 2009 - 05:58 PM

To be honest, I'm running out of ideas. There doesn't appear to be any malware remaining on your system. Does this happen in both IE and FF what are some of the sites that are no longer working?

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#15 sparklebritches

sparklebritches

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 08 October 2009 - 08:13 PM

Here's one example: www.whitepages.com / it comes up a blank page and the tap at the top says "(GIF Image, 1x1 pixels)" And this is what comes up on a lot of pages I click on from search engines. I really don't know what it could be. I thought maybe my settings but I couldn't find anything obvious. If you think of anything else please let me know, it is very frustrating. Thanks again for all your help with this!

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users