This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis log, please review

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Ken,

Following the directions you posted above:

Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<
When it finishes, i do not get(or see) two logs. This is my result:


Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-20 10:07:18
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 20 GB (22%) free of 93 GB
Total RAM: 2045 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:08:16 AM, on 10/20/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Valued Customer\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Valued Customer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [StxTrayMenu] C:\Program Files\Seagate\SystemTray\FreeAgentLauncher.exe C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DeskSaverService - Unknown owner - C:\Program Files\1st Desktop Guard\desksaver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 15465 bytes

======Scheduled tasks folder======

C:\Windows\tasks\HPCeeScheduleForValued Customer.job
C:\Windows\tasks\McDefragTask.job
C:\Windows\tasks\User_Feed_Synchronization-{C76D0CE0-AD4F-4BAF-9792-923DF26B8FCF}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll [2008-05-15 817936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-02-10 370296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-11-09 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll [2008-05-15 817936]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-28 1045800]
"QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2006-11-06 159744]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-15 102400]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 849280]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-11-01 582992]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2008-02-29 76304]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2008-10-03 4344472]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2008-10-03 960376]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2008-10-03 165144]
"StxTrayMenu"=C:\Program Files\Seagate\SystemTray\FreeAgentLauncher.exe [2007-01-18 79416]
""= []
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-10-03 480560]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-12-19 468264]
"McAfee Backup"=C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe [2007-01-16 4838952]
"MBkLogOnHook"=C:\Program Files\McAfee\MBK\LogOnHook.exe [2007-01-08 20480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"=C:\Windows\SMINST\launcher.exe [2006-11-07 44128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Valued Customer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2008-07-28 575488]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Connections.lnk - C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mferkdk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mferkdk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdik]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdik.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{268a2f45-ec54-11dc-8b56-001b242b27eb}]
shell\AutoRun\command - ntdelect.com
shell\explore\command - K:\ntdeIect.com
shell\open\command - K:\ntdeIect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6566bd6a-d782-11dc-ae1e-001a6b74d254}]
shell\AutoRun\command - G:\launch.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93c6cf23-d4de-11dc-8a77-001a6b74d254}]
shell\AutoRun\command - G:\LiteAuto.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1b4a1ac-2a61-11dd-9415-001a6b74d254}]
shell\AutoRun\command - O:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e24d5450-9bd0-11dd-919a-001a6b74d254}]
shell\AutoRun\command - "N:\Install FreeAgent Tools.exe" /run

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc7560ec-dd76-11dc-97ba-001a6b74d254}]
shell\AutoRun\command - H:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc7560ed-dd76-11dc-97ba-001a6b74d254}]
shell\applet\command - I:\autorun\autorun.exe /s
shell\AutoRun\command - I:\autorun\autorun.exe
shell\directx\command - I:\dxsetup\dxinst.exe
shell\ereg\command - I:\ereg\ereg32.exe
shell\install\command - I:\setup.exe
shell\installdemo\command - I:\j3setup\is_setup.exe
shell\qtim\command - I:\qtwsetup\setup.exe
shell\readfile\command - Notepad Readme.txt


======List of files/folders created in the last 1 months======

2008-10-19 20:17:56 —-DC—- C:\rsit
2008-10-19 17:34:50 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Acronis
2008-10-18 16:08:21 —-DC—- C:\Users\Valued Customer\AppData\Roaming\McAfee
2008-10-18 13:50:45 —-DC—- C:\61883 Class Bus Device
2008-10-18 13:46:12 —-DC—- C:\Program Files\Driver-Soft
2008-10-18 10:53:16 —-SHDC—- C:\Config.Msi
2008-10-17 22:01:39 —-DC—- C:\BM2005
2008-10-17 17:17:45 —-DC—- C:\Program Files\Enigma Software Group
2008-10-16 12:44:11 —-RC—- C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-10-16 11:27:54 —-DC—- C:\Program Files\Common Files\eSellerate
2008-10-16 11:26:33 —-SDC—- C:\ProgramData\Seagate
2008-10-16 02:04:36 —-DC—- C:\Program Files\FreeAgent tools install
2008-10-14 18:41:46 —-DC—- C:\Program Files\ERUNT
2008-10-14 17:35:05 —-DC—- C:\Users\Valued Customer\AppData\Roaming\VSRevoGroup
2008-10-14 13:27:37 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Malwarebytes
2008-10-14 13:27:26 —-DC—- C:\ProgramData\Malwarebytes
2008-10-14 13:27:25 —-DC—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-14 12:10:54 —-DC—- C:\Program Files\Trend Micro
2008-10-13 19:16:01 —-DC—- C:\ProgramData\PC Tools
2008-10-13 14:44:01 —-DC—- C:\Program Files\Common Files\PC Tools
2008-10-13 13:18:26 —-DC—- C:\Users\Valued Customer\AppData\Roaming\PC Tools
2008-10-13 13:18:26 —-DC—- C:\Program Files\Spyware Doctor
2008-10-12 17:10:31 —-DC—- C:\Users\Valued Customer\AppData\Roaming\5
2008-10-12 16:03:38 —-DC—- C:\Program Files\Lavasoft
2008-10-12 00:16:48 —-DC—- C:\ProgramData\LightScribe
2008-10-11 22:41:39 —-DC—- C:\Program Files\Common Files\LightScribe
2008-10-10 10:08:34 —-AC—- C:\Windows\system32\BtCoreIf.dll
2008-10-10 10:07:32 —-DC—- C:\Program Files\Common Files\Logishrd
2008-10-09 20:51:40 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Logitech
2008-10-09 20:50:41 —-RC—- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-10-09 20:44:57 —-AC—- C:\Windows\system32\KemXML.dll
2008-10-09 20:44:57 —-AC—- C:\Windows\system32\KemWnd.dll
2008-10-09 20:44:57 —-AC—- C:\Windows\system32\KemUtil.dll
2008-10-09 20:44:57 —-AC—- C:\Windows\system32\kemutb.dll
2008-10-09 20:44:16 —-DC—- C:\ProgramData\Logitech
2008-10-09 20:44:12 —-DC—- C:\Program Files\Logitech
2008-10-09 20:44:05 —-DC—- C:\Program Files\Common Files\Logitech
2008-10-09 20:42:57 —-DC—- C:\ProgramData\LogiShrd
2008-10-04 10:40:09 —-HDC—- C:\1st Desktop Guard
2008-10-04 10:40:08 —-DC—- C:\Program Files\1st Desktop Guard
2008-10-03 12:53:42 —-AC—- C:\Windows\system32\msshooks.dll
2008-10-03 12:53:40 —-AC—- C:\Windows\system32\msscb.dll
2008-10-03 12:53:34 —-AC—- C:\Windows\system32\SearchFilterHost.exe
2008-10-03 12:53:34 —-AC—- C:\Windows\system32\propdefs.dll
2008-10-03 12:53:34 —-AC—- C:\Windows\system32\msstrc.dll
2008-10-03 12:53:34 —-AC—- C:\Windows\system32\mssitlb.dll
2008-10-03 12:53:34 —-AC—- C:\Windows\system32\msshsq.dll
2008-10-03 12:53:33 —-AC—- C:\Windows\system32\thawbrkr.dll
2008-10-03 12:53:33 —-AC—- C:\Windows\system32\srchadmin.dll
2008-10-03 12:53:33 —-AC—- C:\Windows\system32\propsys.dll
2008-10-03 12:53:33 —-AC—- C:\Windows\system32\mssprxy.dll
2008-10-03 12:53:33 —-AC—- C:\Windows\system32\korwbrkr.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\xmlfilter.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\wsepno.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\rtffilt.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\offfilt.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\nlhtml.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\msscntrs.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\mimefilt.dll
2008-10-03 12:53:31 —-AC—- C:\Windows\system32\chsbrkr.dll
2008-10-03 12:53:30 —-AC—- C:\Windows\system32\SearchProtocolHost.exe
2008-10-03 12:53:30 —-AC—- C:\Windows\system32\SearchIndexer.exe
2008-10-03 12:53:30 —-AC—- C:\Windows\system32\chtbrkr.dll
2008-10-03 12:53:29 —-AC—- C:\Windows\system32\tquery.dll
2008-10-03 12:53:29 —-AC—- C:\Windows\system32\mssvp.dll
2008-10-03 12:53:29 —-AC—- C:\Windows\system32\mssrch.dll
2008-10-03 12:53:29 —-AC—- C:\Windows\system32\mssphtb.dll
2008-10-03 12:53:29 —-AC—- C:\Windows\system32\mssph.dll
2008-10-03 12:51:27 —-AC—- C:\Windows\system32\rpcrt4.dll
2008-10-03 12:51:24 —-AC—- C:\Windows\system32\pacerprf.dll
2008-10-03 12:50:58 —-AC—- C:\Windows\system32\emdmgmt.dll
2008-10-03 12:50:57 —-AC—- C:\Windows\system32\dataclen.dll
2008-10-03 12:50:57 —-AC—- C:\Windows\system32\cdd.dll
2008-10-03 12:49:14 —-AC—- C:\Windows\system32\wshext.dll
2008-10-03 12:49:14 —-AC—- C:\Windows\system32\wscript.exe
2008-10-03 12:49:14 —-AC—- C:\Windows\system32\vbscript.dll
2008-10-03 12:49:14 —-AC—- C:\Windows\system32\jscript.dll
2008-10-03 12:49:13 —-AC—- C:\Windows\system32\scrrun.dll
2008-10-03 12:49:13 —-AC—- C:\Windows\system32\scrobj.dll
2008-10-03 12:49:13 —-AC—- C:\Windows\system32\cscript.exe
2008-10-02 22:05:31 —-DC—- C:\PerfLogs
2008-10-02 14:25:56 —-AC—- C:\Windows\system32\SLsvc.exe
2008-10-02 14:25:56 —-AC—- C:\Windows\system32\onex.dll
2008-10-02 14:25:31 —-AC—- C:\Windows\system32\PSHED.DLL
2008-10-02 14:25:30 —-AC—- C:\Windows\system32\imagesp1.dll
2008-10-02 14:25:20 —-AC—- C:\Windows\system32\dfsr.exe
2008-10-02 14:25:18 —-AC—- C:\Windows\system32\pidgenx.dll
2008-10-02 14:25:16 —-AC—- C:\Windows\system32\sstpsvc.dll
2008-10-02 14:25:16 —-AC—- C:\Windows\system32\mstscax.dll
2008-10-02 14:25:12 —-AC—- C:\Windows\system32\WsmSvc.dll
2008-10-02 14:25:12 —-AC—- C:\Windows\system32\winrscmd.dll
2008-10-02 14:25:10 —-AC—- C:\Windows\system32\sysmain.dll
2008-10-02 14:25:02 —-AC—- C:\Windows\system32\RMActivate.exe
2008-10-02 14:25:00 —-AC—- C:\Windows\system32\vssapi.dll
2008-10-02 14:24:58 —-AC—- C:\Windows\system32\VSSVC.exe
2008-10-02 14:24:57 —-AC—- C:\Windows\system32\PresentationNative_v0300.dll
2008-10-02 14:24:55 —-AC—- C:\Windows\system32\secproc.dll
2008-10-02 14:24:55 —-AC—- C:\Windows\system32\RMActivate_isv.exe
2008-10-02 14:24:54 —-AC—- C:\Windows\system32\iesetup.dll
2008-10-02 14:24:48 —-AC—- C:\Windows\system32\secproc_isv.dll
2008-10-02 14:24:44 —-AC—- C:\Windows\system32\drmv2clt.dll
2008-10-02 14:24:41 —-AC—- C:\Windows\system32\icardres.dll
2008-10-02 14:24:41 —-AC—- C:\Windows\system32\icardagt.exe
2008-10-02 14:24:39 —-AC—- C:\Windows\system32\xpssvcs.dll
2008-10-02 14:24:39 —-AC—- C:\Windows\system32\blackbox.dll
2008-10-02 14:24:33 —-AC—- C:\Windows\system32\RacEngn.dll
2008-10-02 14:24:32 —-AC—- C:\Windows\system32\RMActivate_ssp.exe
2008-10-02 14:24:31 —-AC—- C:\Windows\system32\RMActivate_ssp_isv.exe
2008-10-02 14:24:31 —-AC—- C:\Windows\system32\MSMPEG2VDEC.DLL
2008-10-02 14:24:30 —-AC—- C:\Windows\system32\rdpencom.dll
2008-10-02 14:24:29 —-AC—- C:\Windows\system32\spwizimg.dll
2008-10-02 14:24:28 —-AC—- C:\Windows\system32\lpremove.exe
2008-10-02 14:24:28 —-AC—- C:\Windows\bfsvc.exe
2008-10-02 14:24:27 —-AC—- C:\Windows\system32\msxml3.dll
2008-10-02 14:24:26 —-AC—- C:\Windows\system32\msxml6.dll
2008-10-02 14:24:26 —-AC—- C:\Windows\system32\msjet40.dll
2008-10-02 14:24:25 —-AC—- C:\Windows\system32\ntdll.dll
2008-10-02 14:24:25 —-AC—- C:\Windows\system32\lsasrv.dll
2008-10-02 14:24:24 —-AC—- C:\Windows\system32\qmgr.dll
2008-10-02 14:24:24 —-AC—- C:\Windows\system32\localspl.dll
2008-10-02 14:24:23 —-AC—- C:\Windows\system32\wevtsvc.dll
2008-10-02 14:24:23 —-AC—- C:\Windows\system32\IKEEXT.DLL
2008-10-02 14:24:22 —-AC—- C:\Windows\system32\wcncsvc.dll
2008-10-02 14:24:22 —-AC—- C:\Windows\system32\recdisc.exe
2008-10-02 14:24:22 —-AC—- C:\Windows\system32\mscoree.dll
2008-10-02 14:24:22 —-AC—- C:\Windows\system32\kernel32.dll
2008-10-02 14:24:21 —-AC—- C:\Windows\system32\TsWpfWrp.exe
2008-10-02 14:24:17 —-AC—- C:\Windows\system32\vds.exe
2008-10-02 14:24:17 —-AC—- C:\Windows\system32\CompMgmtLauncher.exe
2008-10-02 14:24:13 —-AC—- C:\Windows\system32\wmp.dll
2008-10-02 14:24:12 —-AC—- C:\Windows\system32\mstsc.exe
2008-10-02 14:24:11 —-AC—- C:\Windows\system32\wcnwiz.dll
2008-10-02 14:24:11 —-AC—- C:\Windows\system32\SMBHelperClass.dll
2008-10-02 14:24:10 —-AC—- C:\Windows\system32\msvbvm60.dll
2008-10-02 14:24:09 —-AC—- C:\Windows\system32\mf.dll
2008-10-02 14:24:07 —-AC—- C:\Windows\system32\termsrv.dll
2008-10-02 14:24:07 —-AC—- C:\Windows\system32\msdtctm.dll
2008-10-02 14:24:06 —-AC—- C:\Windows\system32\advapi32.dll
2008-10-02 14:24:05 —-AC—- C:\Windows\system32\kerberos.dll
2008-10-02 14:24:05 —-AC—- C:\Windows\system32\IMJP10K.DLL
2008-10-02 14:24:02 —-AC—- C:\Windows\system32\mmcndmgr.dll
2008-10-02 14:24:00 —-AC—- C:\Windows\system32\CertEnroll.dll
2008-10-02 14:23:59 —-AC—- C:\Windows\system32\MSMPEG2ADEC.DLL
2008-10-02 14:23:59 —-AC—- C:\Windows\system32\MPSSVC.dll
2008-10-02 14:23:58 —-AC—- C:\Windows\system32\Query.dll
2008-10-02 14:23:57 —-AC—- C:\Windows\system32\xolehlp.dll
2008-10-02 14:23:57 —-AC—- C:\Windows\system32\msdtcprx.dll
2008-10-02 14:23:56 —-AC—- C:\Windows\system32\ole32.dll
2008-10-02 14:23:54 —-AC—- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2008-10-02 14:23:54 —-AC—- C:\Windows\system32\netlogon.dll
2008-10-02 14:23:52 —-AC—- C:\Windows\system32\SSShim.dll
2008-10-02 14:23:52 —-AC—- C:\Windows\system32\msvcrt.dll
2008-10-02 14:23:51 —-AC—- C:\Windows\system32\mcupdate_GenuineIntel.dll
2008-10-02 14:23:50 —-AC—- C:\Windows\system32\nlmgp.dll
2008-10-02 14:23:50 —-AC—- C:\Windows\system32\DfsShlEx.dll
2008-10-02 14:23:49 —-AC—- C:\Windows\system32\shlwapi.dll
2008-10-02 14:23:49 —-AC—- C:\Windows\system32\schedsvc.dll
2008-10-02 14:23:49 —-AC—- C:\Windows\system32\IasMigPlugin.dll
2008-10-02 14:23:48 —-AC—- C:\Windows\system32\sdclt.exe
2008-10-02 14:23:48 —-AC—- C:\Windows\system32\printfilterpipelinesvc.exe
2008-10-02 14:23:47 —-AC—- C:\Windows\system32\milcore.dll
2008-10-02 14:23:46 —-AC—- C:\Windows\system32\wer.dll
2008-10-02 14:23:46 —-AC—- C:\Windows\system32\user32.dll
2008-10-02 14:23:45 —-AC—- C:\Windows\system32\clusapi.dll
2008-10-02 14:23:44 —-AC—- C:\Windows\system32\vdsdyn.dll
2008-10-02 14:23:44 —-AC—- C:\Windows\system32\d3d9.dll
2008-10-02 14:23:43 —-AC—- C:\Windows\system32\WSDApi.dll
2008-10-02 14:23:43 —-AC—- C:\Windows\system32\QAGENTRT.DLL
2008-10-02 14:23:43 —-AC—- C:\Windows\system32\diagperf.dll
2008-10-02 14:23:40 —-AC—- C:\Windows\system32\winrsmgr.dll
2008-10-02 14:23:40 —-AC—- C:\Windows\system32\mmc.exe
2008-10-02 14:23:38 —-AC—- C:\Windows\system32\mtxclu.dll
2008-10-02 14:23:36 —-AC—- C:\Windows\system32\SLC.dll
2008-10-02 14:23:35 —-AC—- C:\Windows\system32\vdsbas.dll
2008-10-02 14:23:34 —-AC—- C:\Windows\system32\swprv.dll
2008-10-02 14:23:33 —-AC—- C:\Windows\system32\msi.dll
2008-10-02 14:23:33 —-AC—- C:\Windows\system32\comctl32.dll
2008-10-02 14:23:31 —-AC—- C:\Windows\system32\MSVidCtl.dll
2008-10-02 14:23:29 —-AC—- C:\Windows\system32\msdtckrm.dll
2008-10-02 14:23:29 —-AC—- C:\Windows\system32\gpsvc.dll
2008-10-02 14:23:28 —-AC—- C:\Windows\system32\XPSSHHDR.dll
2008-10-02 14:23:27 —-AC—- C:\Windows\system32\sbe.dll
2008-10-02 14:23:27 —-AC—- C:\Windows\system32\samsrv.dll
2008-10-02 14:23:27 —-AC—- C:\Windows\system32\FWPUCLNT.DLL
2008-10-02 14:23:26 —-AC—- C:\Windows\system32\mfc42u.dll
2008-10-02 14:23:26 —-AC—- C:\Windows\system32\esent.dll
2008-10-02 14:23:25 —-AC—- C:\Windows\system32\wecutil.exe
2008-10-02 14:23:25 —-AC—- C:\Windows\system32\sdengin2.dll
2008-10-02 14:23:24 —-AC—- C:\Windows\system32\usp10.dll
2008-10-02 14:23:23 —-AC—- C:\Windows\system32\gacinstall.dll
2008-10-02 14:23:23 —-AC—- C:\Windows\system32\cmipnpinstall.dll
2008-10-02 14:23:23 —-AC—- C:\Windows\system32\cmicryptinstall.dll
2008-10-02 14:23:21 —-AC—- C:\Windows\system32\mfc42.dll
2008-10-02 14:23:19 —-AC—- C:\Windows\system32\comsvcs.dll
2008-10-02 14:23:18 —-AC—- C:\Windows\system32\crypt32.dll
2008-10-02 14:23:17 —-AC—- C:\Windows\system32\WSManMigrationPlugin.dll
2008-10-02 14:23:16 —-AC—- C:\Windows\system32\certutil.exe
2008-10-02 14:23:15 —-AC—- C:\Windows\system32\mswsock.dll
2008-10-02 14:23:14 —-AC—- C:\Windows\explorer.exe
2008-10-02 14:23:13 —-AC—- C:\Windows\system32\wmdrmsdk.dll
2008-10-02 14:23:13 —-AC—- C:\Windows\system32\oleaut32.dll
2008-10-02 14:23:12 —-AC—- C:\Windows\system32\FirewallAPI.dll
2008-10-02 14:23:11 —-AC—- C:\Windows\system32\sqlceqp30.dll
2008-10-02 14:23:11 —-AC—- C:\Windows\system32\setupapi.dll
2008-10-02 14:23:11 —-AC—- C:\Windows\system32\lsm.exe
2008-10-02 14:23:11 —-AC—- C:\Windows\system32\bcrypt.dll
2008-10-02 14:23:10 —-AC—- C:\Windows\system32\wecsvc.dll
2008-10-02 14:23:10 —-AC—- C:\Windows\system32\sdohlp.dll
2008-10-02 14:23:10 —-AC—- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2008-10-02 14:23:09 —-AC—- C:\Windows\system32\msv1_0.dll
2008-10-02 14:23:08 —-AC—- C:\Windows\system32\schannel.dll
2008-10-02 14:23:08 —-AC—- C:\Windows\system32\netapi32.dll
2008-10-02 14:23:08 —-AC—- C:\Windows\system32\iphlpsvc.dll
2008-10-02 14:23:08 —-AC—- C:\Windows\system32\eapp3hst.dll
2008-10-02 14:23:07 —-AC—- C:\Windows\system32\wmpmde.dll
2008-10-02 14:23:07 —-AC—- C:\Windows\system32\thumbcache.dll
2008-10-02 14:23:07 —-AC—- C:\Windows\system32\p2psvc.dll
2008-10-02 14:23:07 —-AC—- C:\Windows\system32\mcmde.dll
2008-10-02 14:23:05 —-AC—- C:\Windows\system32\riched20.dll
2008-10-02 14:23:04 —-AC—- C:\Windows\system32\vdsutil.dll
2008-10-02 14:23:04 —-AC—- C:\Windows\system32\d3d10_1.dll
2008-10-02 14:23:04 —-AC—- C:\Windows\system32\autofmt.exe
2008-10-02 14:23:04 —-AC—- C:\Windows\system32\autoconv.exe
2008-10-02 14:23:04 —-AC—- C:\Windows\system32\autochk.exe
2008-10-02 14:23:03 —-AC—- C:\Windows\system32\WinSAT.exe
2008-10-02 14:23:03 —-AC—- C:\Windows\system32\imapi2fs.dll
2008-10-02 14:23:02 —-AC—- C:\Windows\system32\authfwcfg.dll
2008-10-02 14:23:01 —-AC—- C:\Windows\system32\authui.dll
2008-10-02 14:23:00 —-AC—- C:\Windows\system32\wevtapi.dll
2008-10-02 14:23:00 —-AC—- C:\Windows\system32\dmvdsitf.dll
2008-10-02 14:23:00 —-AC—- C:\Windows\system32\d3d10_1core.dll
2008-10-02 14:23:00 —-AC—- C:\Windows\system32\browseui.dll
2008-10-02 14:22:59 —-AC—- C:\Windows\system32\mscories.dll
2008-10-02 14:22:59 —-AC—- C:\Windows\system32\comuid.dll
2008-10-02 14:22:59 —-AC—- C:\Windows\system32\comdlg32.dll
2008-10-02 14:22:58 —-AC—- C:\Windows\system32\WSDMon.dll
2008-10-02 14:22:58 —-AC—- C:\Windows\system32\eapphost.dll
2008-10-02 14:22:56 —-AC—- C:\Windows\system32\wevtfwd.dll
2008-10-02 14:22:56 —-AC—- C:\Windows\system32\uexfat.dll
2008-10-02 14:22:56 —-AC—- C:\Windows\system32\rasmans.dll
2008-10-02 14:22:55 —-AC—- C:\Windows\system32\untfs.dll
2008-10-02 14:22:55 —-AC—- C:\Windows\system32\eappcfg.dll
2008-10-02 14:22:54 —-AC—- C:\Windows\system32\sqlcese30.dll
2008-10-02 14:22:54 —-AC—- C:\Windows\system32\iassam.dll
2008-10-02 14:22:54 —-AC—- C:\Windows\system32\DfrgNtfs.exe
2008-10-02 14:22:53 —-AC—- C:\Windows\system32\wlansvc.dll
2008-10-02 14:22:53 —-AC—- C:\Windows\system32\whealogr.dll
2008-10-02 14:22:53 —-AC—- C:\Windows\system32\pcaui.dll
2008-10-02 14:22:48 —-AC—- C:\Windows\system32\dot3svc.dll
2008-10-02 14:22:44 —-AC—- C:\Windows\system32\rdpwsx.dll
2008-10-02 14:22:43 —-AC—- C:\Windows\system32\mssha.dll
2008-10-02 14:22:42 —-AC—- C:\Windows\system32\winhttp.dll
2008-10-02 14:22:42 —-AC—- C:\Windows\system32\msdrm.dll
2008-10-02 14:22:42 —-AC—- C:\Windows\system32\evr.dll
2008-10-02 14:22:42 —-AC—- C:\Windows\system32\dfrgui.exe
2008-10-02 14:22:41 —-AC—- C:\Windows\system32\zipfldr.dll
2008-10-02 14:22:41 —-AC—- C:\Windows\system32\WsmAuto.dll
2008-10-02 14:22:40 —-AC—- C:\Windows\system32\rpcss.dll
2008-10-02 14:22:40 —-AC—- C:\Windows\system32\nlasvc.dll
2008-10-02 14:22:39 —-AC—- C:\Windows\system32\rasppp.dll
2008-10-02 14:22:39 —-AC—- C:\Windows\system32\ncrypt.dll
2008-10-02 14:22:39 —-AC—- C:\Windows\system32\BFE.DLL
2008-10-02 14:22:38 —-AC—- C:\Windows\system32\msrepl40.dll
2008-10-02 14:22:38 —-AC—- C:\Windows\system32\audiosrv.dll
2008-10-02 14:22:37 —-AC—- C:\Windows\system32\WMVCORE.DLL
2008-10-02 14:22:37 —-AC—- C:\Windows\system32\wmdrmdev.dll
2008-10-02 14:22:36 —-AC—- C:\Windows\system32\ddraw.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\WsmWmiPl.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\win32spl.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\WebClnt.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\rastls.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\printui.dll
2008-10-02 14:22:35 —-AC—- C:\Windows\system32\dhcpcsvc6.dll
2008-10-02 14:22:34 —-AC—- C:\Windows\system32\themecpl.dll
2008-10-02 14:22:34 —-AC—- C:\Windows\system32\objsel.dll
2008-10-02 14:22:32 —-AC—- C:\Windows\system32\QAGENT.DLL
2008-10-02 14:22:32 —-AC—- C:\Windows\system32\dbghelp.dll
2008-10-02 14:22:31 —-AC—- C:\Windows\system32\sqlsrv32.dll
2008-10-02 14:22:31 —-AC—- C:\Windows\system32\iasnap.dll
2008-10-02 14:22:30 —-AC—- C:\Windows\system32\w32time.dll
2008-10-02 14:22:29 —-AC—- C:\Windows\system32\PresentationHost.exe
2008-10-02 14:22:29 —-AC—- C:\Windows\system32\icm32.dll
2008-10-02 14:22:28 —-AC—- C:\Windows\system32\wmdrmnet.dll
2008-10-02 14:22:28 —-AC—- C:\Windows\system32\WerFaultSecure.exe
2008-10-02 14:22:28 —-AC—- C:\Windows\system32\ncryptui.dll
2008-10-02 14:22:28 —-AC—- C:\Windows\system32\azroles.dll
2008-10-02 14:22:27 —-AC—- C:\Windows\system32\iprtrmgr.dll
2008-10-02 14:22:26 —-AC—- C:\Windows\system32\spoolss.dll
2008-10-02 14:22:25 —-AC—- C:\Windows\system32\msctf.dll
2008-10-02 14:22:25 —-AC—- C:\Windows\system32\infocardapi.dll
2008-10-02 14:22:24 —-AC—- C:\Windows\system32\wlangpui.dll
2008-10-02 14:22:24 —-AC—- C:\Windows\system32\winsrv.dll
2008-10-02 14:22:24 —-AC—- C:\Windows\system32\taskschd.dll
2008-10-02 14:22:24 —-AC—- C:\Windows\system32\bcdedit.exe
2008-10-02 14:22:24 —-AC—- C:\Windows\system32\basecsp.dll
2008-10-02 14:22:22 —-AC—- C:\Windows\system32\scksp.dll
2008-10-02 14:22:22 —-AC—- C:\Windows\system32\mstlsapi.dll
2008-10-02 14:22:22 —-AC—- C:\Windows\system32\AudioEng.dll
2008-10-02 14:22:20 —-AC—- C:\Windows\system32\winsta.dll
2008-10-02 14:22:20 —-AC—- C:\Windows\system32\netprofm.dll
2008-10-02 14:22:20 —-AC—- C:\Windows\system32\dbgeng.dll
2008-10-02 14:22:19 —-AC—- C:\Windows\system32\rsaenh.dll
2008-10-02 14:22:19 —-AC—- C:\Windows\system32\netcfgx.dll
2008-10-02 14:22:18 —-AC—- C:\Windows\system32\taskcomp.dll
2008-10-02 14:22:17 —-AC—- C:\Windows\system32\winlogon.exe
2008-10-02 14:22:17 —-AC—- C:\Windows\system32\wercon.exe
2008-10-02 14:22:17 —-AC—- C:\Windows\system32\lpksetup.exe
2008-10-02 14:22:17 —-AC—- C:\Windows\system32\cdosys.dll
2008-10-02 14:22:15 —-AC—- C:\Windows\system32\sqmapi.dll
2008-10-02 14:22:15 —-AC—- C:\Windows\system32\dfshim.dll
2008-10-02 14:22:14 —-AC—- C:\Windows\system32\wlansec.dll
2008-10-02 14:22:14 —-AC—- C:\Windows\system32\msdtcuiu.dll
2008-10-02 14:22:14 —-AC—- C:\Windows\system32\apds.dll
2008-10-02 14:22:13 —-AC—- C:\Windows\system32\mprddm.dll
2008-10-02 14:22:13 —-AC—- C:\Windows\system32\certcli.dll
2008-10-02 14:22:12 —-AC—- C:\Windows\system32\iasrad.dll
2008-10-02 14:22:12 —-AC—- C:\Windows\system32\AUDIOKSE.dll
2008-10-02 14:22:11 —-AC—- C:\Windows\system32\tsgqec.dll
2008-10-02 14:22:11 —-AC—- C:\Windows\system32\shdocvw.dll
2008-10-02 14:22:11 —-AC—- C:\Windows\system32\eapsvc.dll
2008-10-02 14:22:11 —-AC—- C:\Windows\system32\aaclient.dll
2008-10-02 14:22:10 —-AC—- C:\Windows\system32\bcdsrv.dll
2008-10-02 14:22:09 —-AC—- C:\Windows\system32\uDWM.dll
2008-10-02 14:22:09 —-AC—- C:\Windows\system32\certmgr.dll
2008-10-02 14:22:08 —-AC—- C:\Windows\system32\Wldap32.dll
2008-10-02 14:22:08 —-AC—- C:\Windows\system32\dnsapi.dll
2008-10-02 14:22:07 —-AC—- C:\Windows\system32\msidcrl30.dll
2008-10-02 14:22:06 —-AC—- C:\Windows\system32\umpnpmgr.dll
2008-10-02 14:22:05 —-AC—- C:\Windows\system32\WMVDECOD.DLL
2008-10-02 14:22:04 —-AC—- C:\Windows\system32\pla.dll
2008-10-02 14:22:03 —-AC—- C:\Windows\system32\dxgi.dll
2008-10-02 14:22:02 —-AC—- C:\Windows\system32\netshell.dll
2008-10-02 14:22:02 —-AC—- C:\Windows\system32\dot3gpui.dll
2008-10-02 14:22:01 —-AC—- C:\Windows\system32\wmicmiplugin.dll
2008-10-02 14:21:54 —-AC—- C:\Windows\system32\ntprint.dll
2008-10-02 14:21:53 —-AC—- C:\Windows\system32\shsvcs.dll
2008-10-02 14:21:53 —-AC—- C:\Windows\system32\cryptnet.dll
2008-10-02 14:21:53 —-AC—- C:\Windows\system32\comsnap.dll
2008-10-02 14:21:52 —-AC—- C:\Windows\system32\MMDevAPI.dll
2008-10-02 14:21:50 —-AC—- C:\Windows\system32\winmm.dll
2008-10-02 14:21:50 —-AC—- C:\Windows\system32\services.exe
2008-10-02 14:21:49 —-AC—- C:\Windows\system32\wscsvc.dll
2008-10-02 14:21:49 —-AC—- C:\Windows\system32\synceng.dll
2008-10-02 14:21:48 —-AC—- C:\Windows\system32\pnidui.dll
2008-10-02 14:21:48 —-AC—- C:\Windows\system32\cmifw.dll
2008-10-02 14:21:47 —-AC—- C:\Windows\system32\wscisvif.dll
2008-10-02 14:21:44 —-AC—- C:\Windows\system32\taskeng.exe
2008-10-02 14:21:44 —-AC—- C:\Windows\system32\msjtes40.dll
2008-10-02 14:21:44 —-AC—- C:\Windows\system32\msconfig.exe
2008-10-02 14:21:44 —-AC—- C:\Windows\system32\iassdo.dll
2008-10-02 14:21:44 —-AC—- C:\Windows\system32\cipher.exe
2008-10-02 14:21:43 —-AC—- C:\Windows\system32\WMVSDECD.DLL
2008-10-02 14:21:42 —-AC—- C:\Windows\system32\imapi2.dll
2008-10-02 14:21:41 —-AC—- C:\Windows\system32\wersvc.dll
2008-10-02 14:21:41 —-AC—- C:\Windows\system32\uxtheme.dll
2008-10-02 14:21:41 —-AC—- C:\Windows\system32\tdh.dll
2008-10-02 14:21:41 —-AC—- C:\Windows\system32\rasapi32.dll
2008-10-02 14:21:41 —-AC—- C:\Windows\system32\dmdskmgr.dll
2008-10-02 14:21:40 —-AC—- C:\Windows\system32\SessEnv.dll
2008-10-02 14:21:40 —-AC—- C:\Windows\system32\dot3api.dll
2008-10-02 14:21:40 —-AC—- C:\Windows\system32\cmd.exe
2008-10-02 14:21:39 —-AC—- C:\Windows\system32\cbsra.exe
2008-10-02 14:21:39 —-AC—- C:\Windows\system32\AuthFWSnapin.dll
2008-10-02 14:21:38 —-AC—- C:\Windows\system32\wkssvc.dll
2008-10-02 14:21:38 —-AC—- C:\Windows\system32\wevtutil.exe
2008-10-02 14:21:38 —-AC—- C:\Windows\system32\srvsvc.dll
2008-10-02 14:21:38 —-AC—- C:\Windows\system32\qdvd.dll
2008-10-02 14:21:38 —-AC—- C:\Windows\system32\msscp.dll
2008-10-02 14:21:37 —-AC—- C:\Windows\system32\WUDFx.dll
2008-10-02 14:21:37 —-AC—- C:\Windows\system32\wlanmsm.dll
2008-10-02 14:21:37 —-AC—- C:\Windows\system32\wlancfg.dll
2008-10-02 14:21:37 —-AC—- C:\Windows\system32\loadperf.dll
2008-10-02 14:21:36 —-AC—- C:\Windows\system32\msdtcVSp1res.dll
2008-10-02 14:21:36 —-AC—- C:\Windows\system32\comres.dll
2008-10-02 14:21:35 —-AC—- C:\Windows\system32\mshtmled.dll
2008-10-02 14:21:35 —-AC—- C:\Windows\system32\localsec.dll
2008-10-02 14:21:35 —-AC—- C:\Windows\system32\diskpart.exe
2008-10-02 14:21:34 —-AC—- C:\Windows\system32\rpchttp.dll
2008-10-02 14:21:34 —-AC—- C:\Windows\system32\rdpdd.dll
2008-10-02 14:21:34 —-AC—- C:\Windows\system32\fontext.dll
2008-10-02 14:21:33 —-AC—- C:\Windows\system32\wlanapi.dll
2008-10-02 14:21:33 —-AC—- C:\Windows\system32\hnetcfg.dll
2008-10-02 14:21:32 —-AC—- C:\Windows\system32\wsqmcons.exe
2008-10-02 14:21:32 —-AC—- C:\Windows\system32\WinSATAPI.dll
2008-10-02 14:21:32 —-AC—- C:\Windows\system32\dsound.dll
2008-10-02 14:21:31 —-AC—- C:\Windows\system32\WMADMOD.DLL
2008-10-02 14:21:31 —-AC—- C:\Windows\system32\wlanpref.dll
2008-10-02 14:21:31 —-AC—- C:\Windows\system32\NAPMONTR.DLL
2008-10-02 14:21:31 —-AC—- C:\Windows\system32\avifil32.dll
2008-10-02 14:21:30 —-AC—- C:\Windows\system32\RDPENCDD.dll
2008-10-02 14:21:30 —-AC—- C:\Windows\system32\profprov.dll
2008-10-02 14:21:30 —-AC—- C:\Windows\system32\filemgmt.dll
2008-10-02 14:21:29 —-AC—- C:\Windows\system32\WindowsCodecs.dll
2008-10-02 14:21:29 —-AC—- C:\Windows\system32\PresentationHostProxy.dll
2008-10-02 14:21:29 —-AC—- C:\Windows\system32\dnsrslvr.dll
2008-10-02 14:21:28 —-AC—- C:\Windows\system32\wsecedit.dll
2008-10-02 14:21:28 —-AC—- C:\Windows\system32\tracerpt.exe
2008-10-02 14:21:28 —-AC—- C:\Windows\system32\SLCommDlg.dll
2008-10-02 14:21:28 —-AC—- C:\Windows\system32\MuiUnattend.exe
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\WMSPDMOD.DLL
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\SmartcardCredentialProvider.dll
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\P2PGraph.dll
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\dwmredir.dll
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\dhcpcsvc.dll
2008-10-02 14:21:27 —-AC—- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2008-10-02 14:21:26 —-AC—- C:\Windows\system32\dwm.exe
2008-10-02 14:21:26 —-AC—- C:\Windows\system32\apphelp.dll
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\wininit.exe
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\spp.dll
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\rasdlg.dll
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\QSHVHOST.DLL
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\iassvcs.dll
2008-10-02 14:21:25 —-AC—- C:\Windows\system32\gpresult.exe
2008-10-02 14:21:24 —-AC—- C:\Windows\system32\iashost.exe
2008-10-02 14:21:24 —-AC—- C:\Windows\system32\azroleui.dll
2008-10-02 14:21:24 —-AC—- C:\Windows\HelpPane.exe
2008-10-02 14:21:23 —-AC—- C:\Windows\system32\mscorier.dll
2008-10-02 14:21:23 —-AC—- C:\Windows\system32\mcbuilder.exe
2008-10-02 14:21:22 —-AC—- C:\Windows\system32\srrstr.dll
2008-10-02 14:21:22 —-AC—- C:\Windows\system32\spwizeng.dll
2008-10-02 14:21:22 —-AC—- C:\Windows\system32\SLUI.exe
2008-10-02 14:21:22 —-AC—- C:\Windows\system32\PortableDeviceApi.dll
2008-10-02 14:21:21 —-AC—- C:\Windows\system32\wecapi.dll
2008-10-02 14:21:21 —-AC—- C:\Windows\system32\rasmontr.dll
2008-10-02 14:21:21 —-AC—- C:\Windows\system32\msra.exe
2008-10-02 14:21:21 —-AC—- C:\Windows\system32\lltdsvc.dll
2008-10-02 14:21:20 —-AC—- C:\Windows\system32\unbcl.dll
2008-10-02 14:21:20 —-AC—- C:\Windows\system32\tcpmon.dll
2008-10-02 14:21:20 —-AC—- C:\Windows\system32\shrink.dll
2008-10-02 14:21:19 —-AC—- C:\Windows\system32\IPHLPAPI.DLL
2008-10-02 14:21:19 —-AC—- C:\Windows\system32\brcpl.dll
2008-10-02 14:21:18 —-AC—- C:\Windows\system32\WMPEncEn.dll
2008-10-02 14:21:18 —-AC—- C:\Windows\system32\iashlpr.dll
2008-10-02 14:21:18 —-AC—- C:\Windows\system32\gpedit.dll
2008-10-02 14:21:17 —-AC—- C:\Windows\system32\oleacc.dll
2008-10-02 14:21:17 —-AC—- C:\Windows\system32\msdri.dll
2008-10-02 14:21:15 —-AC—- C:\Windows\system32\raschap.dll
2008-10-02 14:21:14 —-AC—- C:\Windows\system32\regsvc.dll
2008-10-02 14:21:14 —-AC—- C:\Windows\system32\framedynos.dll
2008-10-02 14:21:14 —-AC—- C:\Windows\system32\advpack.dll
2008-10-02 14:21:13 —-AC—- C:\Windows\system32\fdWSD.dll
2008-10-02 14:21:12 —-AC—- C:\Windows\system32\vsstrace.dll
2008-10-02 14:21:12 —-AC—- C:\Windows\system32\PerfCenterCPL.dll
2008-10-02 14:21:12 —-AC—- C:\Windows\system32\ntvdm.exe
2008-10-02 14:21:12 —-AC—- C:\Windows\system32\ipsmsnap.dll
2008-10-02 14:21:12 —-AC—- C:\Windows\system32\Faultrep.dll
2008-10-02 14:21:11 —-AC—- C:\Windows\system32\ntlanman.dll
2008-10-02 14:21:10 —-AC—- C:\Windows\system32\wpdshext.dll
2008-10-02 14:21:10 —-AC—- C:\Windows\system32\wdc.dll
2008-10-02 14:21:10 —-AC—- C:\Windows\system32\NetProjW.dll
2008-10-02 14:21:10 —-AC—- C:\Windows\system32\l2nacp.dll
2008-10-02 14:21:10 —-AC—- C:\Windows\system32\iedkcs32.dll
2008-10-02 14:21:09 —-AC—- C:\Windows\system32\Storprop.dll
2008-10-02 14:21:09 —-AC—- C:\Windows\system32\netman.dll
2008-10-02 14:21:09 —-AC—- C:\Windows\system32\ieapfltr.dll
2008-10-02 14:21:09 —-AC—- C:\Windows\system32\framedyn.dll
2008-10-02 14:21:09 —-AC—- C:\Windows\system32\dssenh.dll
2008-10-02 14:21:08 —-AC—- C:\Windows\system32\certreq.exe
2008-10-02 14:21:07 —-AC—- C:\Windows\system32\WlanMM.dll
2008-10-02 14:21:07 —-AC—- C:\Windows\system32\tcpipcfg.dll
2008-10-02 14:21:07 —-AC—- C:\Windows\system32\profsvc.dll
2008-10-02 14:21:07 —-AC—- C:\Windows\system32\adsnt.dll
2008-10-02 14:21:06 —-AC—- C:\Windows\system32\WLanConn.dll
2008-10-02 14:21:06 —-AC—- C:\Windows\system32\sxs.dll
2008-10-02 14:21:06 —-AC—- C:\Windows\system32\PhotoMetadataHandler.dll
2008-10-02 14:21:06 —-AC—- C:\Windows\system32\KMSVC.DLL
2008-10-02 14:21:05 —-AC—- C:\Windows\system32\WsmProv.dll
2008-10-02 14:21:04 —-AC—- C:\Windows\system32\wlanhlp.dll
2008-10-02 14:21:04 —-AC—- C:\Windows\system32\ncsi.dll
2008-10-02 14:21:04 —-AC—- C:\Windows\system32\IPBusEnum.dll
2008-10-02 14:21:03 —-AC—- C:\Windows\system32\wusa.exe
2008-10-02 14:21:03 —-AC—- C:\Windows\system32\WUDFHost.exe
2008-10-02 14:21:03 —-AC—- C:\Windows\system32\VAN.dll
2008-10-02 14:21:03 —-AC—- C:\Windows\system32\userenv.dll
2008-10-02 14:21:03 —-AC—- C:\Windows\system32\umb.dll
2008-10-02 14:21:02 —-AC—- C:\Windows\system32\WerFault.exe
2008-10-02 14:21:02 —-AC—- C:\Windows\system32\ie4uinit.exe
2008-10-02 14:21:02 —-AC—- C:\Windows\system32\fundisc.dll
2008-10-02 14:21:00 —-AC—- C:\Windows\system32\catsrvut.dll
2008-10-02 14:20:59 —-AC—- C:\Windows\system32\puiobj.dll
2008-10-02 14:20:59 —-AC—- C:\Windows\system32\cryptui.dll
2008-10-02 14:20:58 —-AC—- C:\Windows\system32\netid.dll
2008-10-02 14:20:58 —-AC—- C:\Windows\system32\dps.dll
2008-10-02 14:20:57 —-AC—- C:\Windows\system32\photowiz.dll
2008-10-02 14:20:57 —-AC—- C:\Windows\system32\netcenter.dll
2008-10-02 14:20:57 —-AC—- C:\Windows\system32\MdSched.exe
2008-10-02 14:20:57 —-AC—- C:\Windows\system32\InkEd.dll
2008-10-02 14:20:54 —-AC—- C:\Windows\system32\WinSCard.dll
2008-10-02 14:20:54 —-AC—- C:\Windows\system32\ipsecsnp.dll
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\ws2_32.dll
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\winrs.exe
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\spbcd.dll
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\secur32.dll
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\ntdsapi.dll
2008-10-02 14:20:53 —-AC—- C:\Windows\system32\msinfo32.exe
2008-10-02 14:20:52 —-AC—- C:\Windows\system32\odbcjt32.dll
2008-10-02 14:20:52 —-AC—- C:\Windows\system32\NAPSTAT.EXE
2008-10-02 14:20:50 —-AC—- C:\Windows\system32\prnntfy.dll
2008-10-02 14:20:49 —-AC—- C:\Windows\system32\mblctr.exe
2008-10-02 14:20:49 —-AC—- C:\Windows\system32\cryptsvc.dll
2008-10-02 14:20:47 —-AC—- C:\Windows\system32\schtasks.exe
2008-10-02 14:20:47 —-AC—- C:\Windows\system32\RelMon.dll
2008-10-02 14:20:47 —-AC—- C:\Windows\system32\msfeeds.dll
2008-10-02 14:20:47 —-AC—- C:\Windows\system32\iasacct.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\pdh.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\netdiagfx.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\dmdlgs.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\dhcpsapi.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\catsrv.dll
2008-10-02 14:20:46 —-AC—- C:\Windows\system32\activeds.dll
2008-10-02 14:20:44 —-AC—- C:\Windows\system32\TSpkg.dll
2008-10-02 14:20:44 —-AC—- C:\Windows\system32\dfrgfat.exe
2008-10-02 14:20:43 —-AC—- C:\Windows\system32\FirewallControlPanel.exe
2008-10-02 14:20:43 —-AC—- C:\Windows\system32\fdWCN.dll
2008-10-02 14:20:42 —-AC—- C:\Windows\system32\wvc.dll
2008-10-02 14:20:42 —-AC—- C:\Windows\system32\winrm.vbs
2008-10-02 14:20:42 —-AC—- C:\Windows\system32\qwave.dll
2008-10-02 14:20:42 —-AC—- C:\Windows\system32\AudioSes.dll
2008-10-02 14:20:41 —-AC—- C:\Windows\system32\dot3msm.dll
2008-10-02 14:20:41 —-AC—- C:\Windows\system32\dot3cfg.dll
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\rastapi.dll
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\netcorehc.dll
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\NAPHLPR.DLL
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\MSMPEG2ENC.DLL
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\msacm32.dll
2008-10-02 14:20:40 —-AC—- C:\Windows\system32\ifmon.dll
2008-10-02 14:20:39 —-AC—- C:\Windows\system32\wow32.dll
2008-10-02 14:20:39 —-AC—- C:\Windows\system32\adsldp.dll
2008-10-02 14:20:38 —-AC—- C:\Windows\system32\shsetup.dll
2008-10-02 14:20:36 —-AC—- C:\Windows\system32\ntshrui.dll
2008-10-02 14:20:36 —-AC—- C:\Windows\system32\msdt.dll
2008-10-02 14:20:36 —-AC—- C:\Windows\system32\els.dll
2008-10-02 14:20:35 —-AC—- C:\Windows\system32\wscntfy.dll
2008-10-02 14:20:35 —-AC—- C:\Windows\system32\iasdatastore.dll
2008-10-02 14:20:35 —-AC—- C:\Windows\system32\clbcatq.dll
2008-10-02 14:20:34 —-AC—- C:\Windows\system32\WMNetMgr.dll
2008-10-02 14:20:34 —-AC—- C:\Windows\system32\QUTIL.DLL
2008-10-02 14:20:34 —-AC—- C:\Windows\system32\iasrecst.dll
2008-10-02 14:20:33 —-AC—- C:\Windows\system32\stobject.dll
2008-10-02 14:20:33 —-AC—- C:\Windows\system32\sdrsvc.dll
2008-10-02 14:20:33 —-AC—- C:\Windows\system32\ipnathlp.dll
2008-10-02 14:20:33 —-AC—- C:\Windows\system32\fdSSDP.dll
2008-10-02 14:20:32 —-AC—- C:\Windows\system32\net1.exe
2008-10-02 14:20:31 —-AC—- C:\Windows\system32\wlanui.dll
2008-10-02 14:20:31 —-AC—- C:\Windows\system32\dsprop.dll
2008-10-02 14:20:30 —-AC—- C:\Windows\system32\wlgpclnt.dll
2008-10-02 14:20:30 —-AC—- C:\Windows\system32\smss.exe
2008-10-02 14:20:30 —-AC—- C:\Windows\system32\nci.dll
2008-10-02 14:20:30 —-AC—- C:\Windows\system32\Defrag.exe
2008-10-02 14:20:30 —-AC—- C:\Windows\system32\adsldpc.dll
2008-10-02 14:20:29 —-AC—- C:\Windows\system32\upnphost.dll
2008-10-02 14:20:29 —-AC—- C:\Windows\system32\systemcpl.dll
2008-10-02 14:20:29 —-AC—- C:\Windows\system32\mprmsg.dll
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\rasman.dll
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\P2P.dll
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\msftedit.dll
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\MSAC3ENC.DLL
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\CompatUI.dll
2008-10-02 14:20:27 —-AC—- C:\Windows\system32\ActiveContentWizard.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\t2embed.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\rascfg.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\PresentationSettings.exe
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\oleprn.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\loghours.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\L2SecHC.dll
2008-10-02 14:20:26 —-AC—- C:\Windows\system32\fde.dll
2008-10-02 14:20:24 —-AC—- C:\Windows\system32\dxdiag.exe
2008-10-02 14:20:23 —-AC—- C:\Windows\system32\Wpc.dll
2008-10-02 14:20:23 —-AC—- C:\Windows\system32\MigAutoPlay.exe
2008-10-02 14:20:22 —-AC—- C:\Windows\system32\wdigest.dll
2008-10-02 14:20:22 —-AC—- C:\Windows\system32\DFDWiz.exe
2008-10-02 14:20:22 —-AC—- C:\Windows\system32\AuxiliaryDisplayServices.dll
2008-10-02 14:20:21 —-AC—- C:\Windows\system32\setupcl.exe
2008-10-02 14:20:21 —-AC—- C:\Windows\system32\mprdim.dll
2008-10-02 14:20:21 —-AC—- C:\Windows\system32\gpapi.dll
2008-10-02 14:20:19 —-AC—- C:\Windows\system32\msutb.dll
2008-10-02 14:20:18 —-AC—- C:\Windows\system32\scansetting.dll
2008-10-02 14:20:18 —-AC—- C:\Windows\system32\rtm.dll
2008-10-02 14:20:18 —-AC—- C:\Windows\system32\devmgr.dll
2008-10-02 14:20:17 —-AC—- C:\Windows\system32\wiaservc.dll
2008-10-02 14:20:17 —-AC—- C:\Windows\system32\NAPCRYPT.DLL
2008-10-02 14:20:16 —-AC—- C:\Windows\system32\msihnd.dll
2008-10-02 14:20:16 —-AC—- C:\Windows\system32\CertEnrollUI.dll
2008-10-02 14:20:15 —-AC—- C:\Windows\system32\ifsutil.dll
2008-10-02 14:20:14 —-AC—- C:\Windows\system32\dimsroam.dll
2008-10-02 14:20:14 —-AC—- C:\Windows\system32\actxprxy.dll
2008-10-02 14:20:13 —-AC—- C:\Windows\system32\wdi.dll
2008-10-02 14:20:12 —-AC—- C:\Windows\system32\wscapi.dll
2008-10-02 14:20:12 —-AC—- C:\Windows\system32\kdusb.dll
2008-10-02 14:20:11 —-AC—- C:\Windows\system32\WinFXDocObj.exe
2008-10-02 14:20:11 —-AC—- C:\Windows\system32\usbmon.dll
2008-10-02 14:20:11 —-AC—- C:\Windows\system32\spoolsv.exe
2008-10-02 14:20:11 —-AC—- C:\Windows\system32\mswmdm.dll
2008-10-02 14:20:11 —-AC—- C:\Windows\system32\BOOTVID.DLL
2008-10-02 14:20:10 —-AC—- C:\Windows\system32\vssadmin.exe
2008-10-02 14:20:10 —-AC—- C:\Windows\system32\SyncCenter.dll
2008-10-02 14:20:10 —-AC—- C:\Windows\system32\msls31.dll
2008-10-02 14:20:10 —-AC—- C:\Windows\system32\imagehlp.dll
2008-10-02 14:20:10 —-AC—- C:\Windows\system32\audiodg.exe
2008-10-02 14:20:09 —-AC—- C:\Windows\system32\wlandlg.dll
2008-10-02 14:20:09 —-AC—- C:\Windows\system32\uudf.dll
2008-10-02 14:20:09 —-AC—- C:\Windows\system32\regapi.dll
2008-10-02 14:20:09 —-AC—- C:\Windows\system32\PortableDeviceWMDRM.dll
2008-10-02 14:20:09 —-AC—- C:\Windows\system32\mycomput.dll
2008-10-02 14:20:08 —-AC—- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2008-10-02 14:20:07 —-AC—- C:\Windows\system32\scecli.dll
2008-10-02 14:20:06 —-AC—- C:\Windows\system32\mspaint.exe
2008-10-02 14:20:05 —-AC—- C:\Windows\system32\SCardSvr.dll
2008-10-02 14:20:05 —-AC—- C:\Windows\system32\newdev.dll
2008-10-02 14:20:04 —-AC—- C:\Windows\system32\sud.dll
2008-10-02 14:20:04 —-AC—- C:\Windows\system32\mstask.dll
2008-10-02 14:20:04 —-AC—- C:\Windows\system32\kdcom.dll
2008-10-02 14:20:03 —-AC—- C:\Windows\system32\termmgr.dll
2008-10-02 14:20:03 —-AC—- C:\Windows\system32\ssdpsrv.dll
2008-10-02 14:20:03 —-AC—- C:\Windows\system32\samlib.dll
2008-10-02 14:20:03 —-AC—- C:\Windows\system32\puiapi.dll
2008-10-02 14:20:02 —-AC—- C:\Windows\system32\mtxoci.dll
2008-10-02 14:20:02 —-AC—- C:\Windows\system32\duser.dll
2008-10-02 14:20:02 —-AC—- C:\Windows\system32\adtschema.dll
2008-10-02 14:20:01 —-AC—- C:\Windows\system32\tapisrv.dll
2008-10-02 14:20:00 —-AC—- C:\Windows\system32\inetpp.dll
2008-10-02 14:20:00 —-AC—- C:\Windows\system32\cic.dll
2008-10-02 14:19:59 —-AC—- C:\Windows\system32\Robocopy.exe
2008-10-02 14:19:59 —-AC—- C:\Windows\system32\input.dll
2008-10-02 14:19:59 —-AC—- C:\Windows\system32\AzSqlExt.dll
2008-10-02 14:19:58 —-AC—- C:\Windows\system32\SLUINotify.dll
2008-10-02 14:19:57 —-AC—- C:\Windows\system32\wisptis.exe
2008-10-02 14:19:57 —-AC—- C:\Windows\system32\iasads.dll
2008-10-02 14:19:56 —-AC—- C:\Windows\system32\cscapi.dll
2008-10-02 14:19:55 —-AC—- C:\Windows\system32\PortableDeviceTypes.dll
2008-10-02 14:19:55 —-AC—- C:\Windows\system32\netiohlp.dll
2008-10-02 14:19:55 —-AC—- C:\Windows\system32\authz.dll
2008-10-02 14:19:54 —-AC—- C:\Windows\system32\sdshext.dll
2008-10-02 14:19:53 —-AC—- C:\Windows\system32\WUDFPlatform.dll
2008-10-02 14:19:53 —-AC—- C:\Windows\system32\msdt.exe
2008-10-02 14:19:52 —-AC—- C:\Windows\system32\webcheck.dll
2008-10-02 14:19:52 —-AC—- C:\Windows\system32\verifier.exe
2008-10-02 14:19:52 —-AC—- C:\Windows\system32\msdtclog.dll
2008-10-02 14:19:51 —-AC—- C:\Windows\system32\themeui.dll
2008-10-02 14:19:51 —-AC—- C:\Windows\system32\d3d8.dll
2008-10-02 14:19:51 —-AC—- C:\Windows\system32\cmdial32.dll
2008-10-02 14:19:50 —-AC—- C:\Windows\system32\wpcsvc.dll
2008-10-02 14:19:50 —-AC—- C:\Windows\system32\slcinst.dll
2008-10-02 14:19:50 —-AC—- C:\Windows\system32\PortableDeviceClassExtension.dll
2008-10-02 14:19:49 —-AC—- C:\Windows\system32\dxtmsft.dll
2008-10-02 14:19:48 —-AC—- C:\Windows\system32\wintrust.dll
2008-10-02 14:19:48 —-AC—- C:\Windows\system32\vdsldr.exe
2008-10-02 14:19:48 —-AC—- C:\Windows\system32\oledlg.dll
2008-10-02 14:19:48 —-AC—- C:\Windows\system32\clfsw32.dll
2008-10-02 14:19:47 —-AC—- C:\Windows\system32\SndVol.exe
2008-10-02 14:19:47 —-AC—- C:\Windows\system32\rasgcw.dll
2008-10-02 14:19:47 —-AC—- C:\Windows\system32\ntmarta.dll
2008-10-02 14:19:47 —-AC—- C:\Windows\system32\mmcbase.dll
2008-10-02 14:19:47 —-AC—- C:\Windows\system32\icardie.dll
2008-10-02 14:19:46 —-AC—- C:\Windows\system32\wpccpl.dll
2008-10-02 14:19:46 —-AC—- C:\Windows\system32\WMPhoto.dll
2008-10-02 14:19:46 —-AC—- C:\Windows\system32\SnippingTool.exe
2008-10-02 14:19:46 —-AC—- C:\Windows\system32\pnpsetup.dll
2008-10-02 14:19:46 —-AC—- C:\Windows\system32\icfupgd.dll
2008-10-02 14:19:45 —-AC—- C:\Windows\system32\ncobjapi.dll
2008-10-02 14:19:45 —-AC—- C:\Windows\system32\msaatext.dll
2008-10-02 14:19:45 —-AC—- C:\Windows\system32\mpr.dll
2008-10-02 14:19:45 —-AC—- C:\Windows\system32\mlang.dll
2008-10-02 14:19:44 —-AC—- C:\Windows\system32\rasqec.dll
2008-10-02 14:19:44 —-AC—- C:\Windows\system32\msrd3x40.dll
2008-10-02 14:19:44 —-AC—- C:\Windows\system32\diskraid.exe
2008-10-02 14:19:43 —-AC—- C:\Windows\system32\nslookup.exe
2008-10-02 14:19:42 —-AC—- C:\Windows\system32\wtsapi32.dll
2008-10-02 14:19:42 —-AC—- C:\Windows\system32\wpd_ci.dll
2008-10-02 14:19:42 —-AC—- C:\Windows\system32\syssetup.dll
2008-10-02 14:19:42 —-AC—- C:\Windows\system32\slmgr.vbs
2008-10-02 14:19:42 —-AC—- C:\Windows\system32\accessibilitycpl.dll
2008-10-02 14:19:41 —-AC—- C:\Windows\system32\unlodctr.exe
2008-10-02 14:19:41 —-AC—- C:\Windows\system32\mscms.dll
2008-10-02 14:19:41 —-AC—- C:\Windows\system32\lodctr.exe
2008-10-02 14:19:41 —-AC—- C:\Windows\system32\extmgr.dll
2008-10-02 14:19:40 —-AC—- C:\Windows\system32\sethc.exe
2008-10-02 14:19:40 —-AC—- C:\Windows\system32\pnpui.dll
2008-10-02 14:19:40 —-AC—- C:\Windows\system32\iaspolcy.dll
2008-10-02 14:19:39 —-AC—- C:\Windows\system32\ulib.dll
2008-10-02 14:19:39 —-AC—- C:\Windows\system32\fontsub.dll
2008-10-02 14:19:39 —-AC—- C:\Windows\system32\dxdiagn.dll
2008-10-02 14:19:39 —-AC—- C:\Windows\system32\cabinet.dll
2008-10-02 14:19:38 —-AC—- C:\Windows\system32\oobefldr.dll
2008-10-02 14:19:37 —-AC—- C:\Windows\system32\Utilman.exe
2008-10-02 14:19:37 —-AC—- C:\Windows\system32\Mcx2Svc.dll
2008-10-02 14:19:36 —-AC—- C:\Windows\system32\trkwks.dll
2008-10-02 14:19:36 —-AC—- C:\Windows\system32\scesrv.dll
2008-10-02 14:19:35 —-AC—- C:\Windows\system32\WSManHTTPConfig.exe
2008-10-02 14:19:35 —-AC—- C:\Windows\system32\unattend.dll
2008-10-02 14:19:35 —-AC—- C:\Windows\system32\occache.dll
2008-10-02 14:19:35 —-AC—- C:\Windows\system32\lnkstub.exe
2008-10-02 14:19:34 —-AC—- C:\Windows\system32\ogldrv.dll
2008-10-02 14:19:34 —-AC—- C:\Windows\system32\cabview.dll
2008-10-02 14:19:33 —-AC—- C:\Windows\system32\wermgr.exe
2008-10-02 14:19:32 —-AC—- C:\Windows\system32\dfdts.dll
2008-10-02 14:19:31 —-AC—- C:\Windows\system32\wpcao.dll
2008-10-02 14:19:31 —-AC—- C:\Windows\system32\bthci.dll
2008-10-02 14:19:30 —-AC—- C:\Windows\system32\iepeers.dll
2008-10-02 14:19:30 —-AC—- C:\Windows\system32\eappgnui.dll
2008-10-02 14:19:29 —-AC—- C:\Windows\system32\printfilterpipelineprxy.dll
2008-10-02 14:19:29 —-AC—- C:\Windows\system32\p2pcollab.dll
2008-10-02 14:19:29 —-AC—- C:\Windows\system32\msnetobj.dll
2008-10-02 14:19:29 —-AC—- C:\Windows\system32\ieaksie.dll
2008-10-02 14:19:29 —-AC—- C:\Windows\system32\basesrv.dll
2008-10-02 14:19:26 —-AC—- C:\Windows\system32\drvinst.exe
2008-10-02 14:19:26 —-AC—- C:\Windows\system32\dispdiag.exe
2008-10-02 14:19:26 —-AC—- C:\Windows\system32\DHCPQEC.DLL
2008-10-02 14:19:22 —-AC—- C:\Windows\system32\dsquery.dll
2008-10-02 14:19:21 —-AC—- C:\Windows\system32\mmcss.dll
2008-10-02 14:19:20 —-AC—- C:\Windows\system32\verifier.dll
2008-10-02 14:19:20 —-AC—- C:\Windows\system32\RstrtMgr.dll
2008-10-02 14:19:19 —-AC—- C:\Windows\system32\secproc_ssp_isv.dll
2008-10-02 14:19:19 —-AC—- C:\Windows\system32\secproc_ssp.dll
2008-10-02 14:19:19 —-AC—- C:\Windows\system32\mprapi.dll
2008-10-02 14:19:19 —-AC—- C:\Windows\system32\efsadu.dll
2008-10-02 14:19:16 —-AC—- C:\Windows\system32\WMVENCOD.DLL
2008-10-02 14:19:16 —-AC—- C:\Windows\system32\wercplsupport.dll
2008-10-02 14:19:16 —-AC—- C:\Windows\system32\qedit.dll
2008-10-02 14:19:15 —-AC—- C:\Windows\system32\WPDSp.dll
2008-10-02 14:19:15 —-AC—- C:\Windows\system32\WPDShServiceObj.dll
2008-10-02 14:19:15 —-AC—- C:\Windows\system32\msoeacct.dll
2008-10-02 14:19:14 —-AC—- C:\Windows\system32\setupugc.exe
2008-10-02 14:19:14 —-AC—- C:\Windows\system32\networkmap.dll
2008-10-02 14:19:14 —-AC—- C:\Windows\system32\iscsiexe.dll
2008-10-02 14:19:14 —-AC—- C:\Windows\system32\icacls.exe
2008-10-02 14:19:14 —-AC—- C:\Windows\system32\d3d10core.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\wiascanprofiles.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\wiaaut.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\QSVRMGMT.DLL
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\pnrpnsp.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\pngfilt.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\p2pnetsh.dll
2008-10-02 14:19:13 —-AC—- C:\Windows\system32\consent.exe
2008-10-02 14:19:12 —-AC—- C:\Windows\system32\usercpl.dll
2008-10-02 14:19:12 —-AC—- C:\Windows\system32\msrdc.dll
2008-10-02 14:19:12 —-AC—- C:\Windows\system32\msdmo.dll
2008-10-02 14:19:12 —-AC—- C:\Windows\system32\conime.exe
2008-10-02 14:19:11 —-AC—- C:\Windows\system32\xactsrv.dll
2008-10-02 14:19:11 —-AC—- C:\Windows\system32\PNPXAssocPrx.dll
2008-10-02 14:19:11 —-AC—- C:\Windows\system32\PNPXAssoc.dll
2008-10-02 14:19:11 —-AC—- C:\Windows\system32\lsass.exe
2008-10-02 14:19:11 —-AC—- C:\Windows\system32\autoplay.dll
2008-10-02 14:19:09 —-AC—- C:\Windows\system32\eappprxy.dll
2008-10-02 14:19:09 —-AC—- C:\Windows\system32\drmmgrtn.dll
2008-10-02 14:19:08 —-AC—- C:\Windows\system32\pcadm.dll
2008-10-02 14:19:08 —-AC—- C:\Windows\system32\lpk.dll
2008-10-02 14:19:08 —-AC—- C:\Windows\system32\findstr.exe
2008-10-02 14:19:08 —-AC—- C:\Windows\system32\dpapimig.exe
2008-10-02 14:19:07 —-AC—- C:\Windows\system32\systeminfo.exe
2008-10-02 14:19:07 —-AC—- C:\Windows\system32\netcfg.exe
2008-10-02 14:19:06 —-AC—- C:\Windows\system32\xwizards.dll
2008-10-02 14:19:06 —-AC—- C:\Windows\system32\msrating.dll
2008-10-02 14:19:06 —-AC—- C:\Windows\system32\mfplat.dll
2008-10-02 14:19:06 —-AC—- C:\Windows\system32\cmdl32.exe
2008-10-02 14:19:05 —-AC—- C:\Windows\system32\resutils.dll
2008-10-02 14:19:05 —-AC—- C:\Windows\system32\DWWIN.EXE
2008-10-02 14:19:04 —-AC—- C:\Windows\system32\dssec.dll
2008-10-02 14:19:04 —-AC—- C:\Windows\system32\dot3ui.dll
2008-10-02 14:19:04 —-AC—- C:\Windows\system32\dfrgifc.exe
2008-10-02 14:19:04 —-AC—- C:\Windows\system32\alg.exe
2008-10-02 14:19:03 —-AC—- C:\Windows\system32\powercpl.dll
2008-10-02 14:19:03 —-AC—- C:\Windows\system32\odbc32.dll
2008-10-02 14:19:03 —-AC—- C:\Windows\system32\netprof.dll
2008-10-02 14:19:03 —-AC—- C:\Windows\system32\MFWMAAEC.DLL
2008-10-02 14:19:03 —-AC—- C:\Windows\system32\dbnetlib.dll
2008-10-02 14:19:03 —-AC—- C:\Windows\regedit.exe
2008-10-02 14:19:02 —-AC—- C:\Windows\system32\nshhttp.dll
2008-10-02 14:19:02 —-AC—- C:\Windows\system32\imm32.dll
2008-10-02 14:19:02 —-AC—- C:\Windows\system32\btpanui.dll
2008-10-02 14:19:02 —-AC—- C:\Windows\system32\apircl.dll
2008-10-02 14:19:01 —-AC—- C:\Windows\system32\txflog.dll
2008-10-02 14:19:01 —-AC—- C:\Windows\system32\feclient.dll
2008-10-02 14:19:00 —-AC—- C:\Windows\system32\tbssvc.dll
2008-10-02 14:19:00 —-AC—- C:\Windows\system32\taskkill.exe
2008-10-02 14:19:00 —-AC—- C:\Windows\system32\iexpress.exe
2008-10-02 14:19:00 —-AC—- C:\Windows\system32\dxva2.dll
2008-10-02 14:19:00 —-AC—- C:\Windows\system32\dwmapi.dll
2008-10-02 14:18:59 —-AC—- C:\Windows\system32\msieftp.dll
2008-10-02 14:18:59 —-AC—- C:\Windows\system32\d3d10.dll
2008-10-02 14:18:59 —-AC—- C:\Windows\system32\bcdprov.dll
2008-10-02 14:18:59 —-AC—- C:\Windows\system32\ActionQueue.dll
2008-10-02 14:18:58 —-AC—- C:\Windows\system32\RASMM.dll
2008-10-02 14:18:58 —-AC—- C:\Windows\system32\provthrd.dll
2008-10-02 14:18:58 —-AC—- C:\Windows\system32\MediaMetadataHandler.dll
2008-10-02 14:18:57 —-AC—- C:\Windows\system32\svchost.exe
2008-10-02 14:18:57 —-AC—- C:\Windows\system32\shwebsvc.dll
2008-10-02 14:18:56 —-AC—- C:\Windows\system32\syncui.dll
2008-10-02 14:18:56 —-AC—- C:\Windows\system32\slwmi.dll
2008-10-02 14:18:56 —-AC—- C:\Windows\system32\EAPQEC.DLL
2008-10-02 14:18:56 —-AC—- C:\Windows\system32\dmocx.dll
2008-10-02 14:18:55 —-AC—- C:\Windows\system32\SLCExt.dll
2008-10-02 14:18:55 —-AC—- C:\Windows\system32\slcc.dll
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\WMASF.DLL
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\raserver.exe
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\olepro32.dll
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\networkexplorer.dll
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\connect.dll
2008-10-02 14:18:54 —-AC—- C:\Windows\system32\aclui.dll
2008-10-02 14:18:53 —-AC—- C:\Windows\system32\PnPUnattend.exe
2008-10-02 14:18:53 —-AC—- C:\Windows\system32\dnscacheugc.exe
2008-10-02 14:18:53 —-AC—- C:\Windows\system32\brcplsdw.dll
2008-10-02 14:18:52 —-AC—- C:\Windows\system32\audiodev.dll
2008-10-02 14:18:51 —-AC—- C:\Windows\system32\xcopy.exe
2008-10-02 14:18:51 —-AC—- C:\Windows\system32\uxsms.dll
2008-10-02 14:18:51 —-AC—- C:\Windows\system32\UIHub.dll
2008-10-02 14:18:51 —-AC—- C:\Windows\system32\taskmgr.exe
2008-10-02 14:18:51 —-AC—- C:\Windows\system32\ias.dll
2008-10-02 14:18:50 —-AC—- C:\Windows\system32\upnp.dll
2008-10-02 14:18:50 —-AC—- C:\Windows\system32\reg.exe
2008-10-02 14:18:50 —-AC—- C:\Windows\system32\QCLIPROV.DLL
2008-10-02 14:18:49 —-AC—- C:\Windows\system32\msoert2.dll
2008-10-02 14:18:49 —-AC—- C:\Windows\system32\icsfiltr.dll
2008-10-02 14:18:49 —-AC—- C:\Windows\system32\cmstp.exe
2008-10-02 14:18:49 —-AC—- C:\Windows\system32\atl.dll
2008-10-02 14:18:49 —-AC—- C:\Windows\system32\appinfo.dll
2008-10-02 14:18:48 —-AC—- C:\Windows\system32\NapiNSP.dll
2008-10-02 14:18:48 —-AC—- C:\Windows\system32\msjetoledb40.dll
2008-10-02 14:18:48 —-AC—- C:\Windows\system32\mountvol.exe
2008-10-02 14:18:48 —-AC—- C:\Windows\system32\mmcshext.dll
2008-10-02 14:18:47 —-AC—- C:\Windows\system32\wlanext.exe
2008-10-02 14:18:47 —-AC—- C:\Windows\system32\perfts.dll
2008-10-02 14:18:47 —-AC—- C:\Windows\system32\browser.dll
2008-10-02 14:18:47 —-AC—- C:\Windows\system32\AuxiliaryDisplayApi.dll
2008-10-02 14:18:46 —-AC—- C:\Windows\system32\wmpdxm.dll
2008-10-02 14:18:46 —-AC—- C:\Windows\system32\netplwiz.dll
2008-10-02 14:18:46 —-AC—- C:\Windows\system32\inetmib1.dll
2008-10-02 14:18:46 —-AC—- C:\Windows\system32\dskquoui.dll
2008-10-02 14:18:46 —-AC—- C:\Windows\system32\certprop.dll
2008-10-02 14:18:45 —-AC—- C:\Windows\system32\WMVXENCD.DLL
2008-10-02 14:18:45 —-AC—- C:\Windows\system32\PING.EXE
2008-10-02 14:18:45 —-AC—- C:\Windows\system32\httpapi.dll
2008-10-02 14:18:45 —-AC—- C:\Windows\system32\cewmdm.dll
2008-10-02 14:18:45 —-AC—- C:\Windows\system32\bitsadmin.exe
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\WUDFCoinstaller.dll
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\WpdMtpUS.dll
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\SoundRecorder.exe
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\qcap.dll
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\qasf.dll
2008-10-02 14:18:44 —-AC—- C:\Windows\system32\ieakeng.dll
2008-10-02 14:18:43 —-AC—- C:\Windows\system32\dsuiext.dll
2008-10-02 14:18:43 —-AC—- C:\Windows\system32\dmusic.dll
2008-10-02 14:18:42 —-AC—- C:\Windows\system32\WUDFSvc.dll
2008-10-02 14:18:42 —-AC—- C:\Windows\system32\SysFxUI.dll
2008-10-02 14:18:42 —-AC—- C:\Windows\system32\rekeywiz.exe
2008-10-02 14:18:42 —-AC—- C:\Windows\system32\auditpol.exe
2008-10-02 14:18:42 —-AC—- C:\Windows\system32\adsmsext.dll
2008-10-02 14:18:41 —-AC—- C:\Windows\system32\wmpsrcwp.dll
2008-10-02 14:18:41 —-AC—- C:\Windows\system32\Sens.dll
2008-10-02 14:18:41 —-AC—- C:\Windows\system32\SecEdit.exe
2008-10-02 14:18:41 —-AC—- C:\Windows\system32\mtstocom.exe
2008-10-02 14:18:41 —-AC—- C:\Windows\system32\mscandui.dll
2008-10-02 14:18:40 —-AC—- C:\Windows\system32\WMVSENCD.DLL
2008-10-02 14:18:40 —-AC—- C:\Windows\system32\makecab.exe
2008-10-02 14:18:40 —-AC—- C:\Windows\system32\lsmproxy.dll
2008-10-02 14:18:40 —-AC—- C:\Windows\system32\batt.dll
2008-10-02 14:18:39 —-AC—- C:\Windows\system32\xwtpw32.dll
2008-10-02 14:18:39 —-AC—- C:\Windows\system32\shimgvw.dll
2008-10-02 14:18:39 —-AC—- C:\Windows\system32\sbeio.dll
2008-10-02 14:18:39 —-AC—- C:\Windows\system32\ndfapi.dll
2008-10-02 14:18:39 —-AC—- C:\Windows\system32\dot3gpclnt.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\wzcdlg.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\wiashext.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\sppnp.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\seclogon.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\printcom.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\msdadiag.dll
2008-10-02 14:18:38 —-AC—- C:\Windows\system32\dxtrans.dll
2008-10-02 14:18:37 —-AC—- C:\Windows\system32\wscmisetup.dll
2008-10-02 14:18:37 —-AC—- C:\Windows\system32\wiadefui.dll
2008-10-02 14:18:37 —-AC—- C:\Windows\system32\msorcl32.dll
2008-10-02 14:18:37 —-AC—- C:\Windows\system32\apss.dll
2008-10-02 14:18:36 —-AC—- C:\Windows\system32\WMSPDMOE.DLL
2008-10-02 14:18:36 —-AC—- C:\Windows\system32\userinit.exe
2008-10-02 14:18:36 —-AC—- C:\Windows\system32\shacct.dll
2008-10-02 14:18:36 —-AC—- C:\Windows\system32\p2phost.exe
2008-10-02 14:18:36 —-AC—- C:\Windows\system32\napipsec.dll
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\wpdwcn.dll
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\sxstrace.exe
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\rrinstaller.exe
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\perfmon.exe
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\keymgr.dll
2008-10-02 14:18:35 —-AC—- C:\Windows\system32\HelpPaneProxy.dll
2008-10-02 14:18:34 —-AC—- C:\Windows\system32\winrshost.exe
2008-10-02 14:18:34 —-AC—- C:\Windows\system32\tasklist.exe
2008-10-02 14:18:34 —-AC—- C:\Windows\system32\ktmutil.exe
2008-10-02 14:18:34 —-AC—- C:\Windows\system32\csrsrv.dll
2008-10-02 14:18:33 —-AC—- C:\Windows\system32\TapiMigPlugin.dll
2008-10-02 14:18:33 —-AC—- C:\Windows\system32\prntvpt.dll
2008-10-02 14:18:33 —-AC—- C:\Windows\system32\notepad.exe
2008-10-02 14:18:33 —-AC—- C:\Windows\system32\MP4SDECD.DLL
2008-10-02 14:18:33 —-AC—- C:\Windows\system32\ftp.exe
2008-10-02 14:18:33 —-AC—- C:\Windows\notepad.exe
2008-10-02 14:18:32 —-AC—- C:\Windows\system32\fmifs.dll
2008-10-02 14:18:32 —-AC—- C:\Windows\system32\d3dim700.dll
2008-10-02 14:18:32 —-AC—- C:\Windows\system32\colorui.dll
2008-10-02 14:18:31 —-AC—- C:\Windows\system32\UIAutomationCore.dll
2008-10-02 14:18:31 —-AC—- C:\Windows\system32\netiougc.exe
2008-10-02 14:18:31 —-AC—- C:\Windows\system32\msiexec.exe
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\wscproxystub.dll
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\winethc.dll
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\nshipsec.dll
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\mfps.dll
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\driverquery.exe
2008-10-02 14:18:30 —-AC—- C:\Windows\system32\cryptdll.dll
2008-10-02 14:18:29 —-AC—- C:\Windows\system32\takeown.exe
2008-10-02 14:18:29 —-AC—- C:\Windows\system32\PnPutil.exe
2008-10-02 14:18:29 —-AC—- C:\Windows\system32\pcasvc.dll
2008-10-02 14:18:29 —-AC—- C:\Windows\system32\msimtf.dll
2008-10-02 14:18:28 —-AC—- C:\Windows\system32\txfw32.dll
2008-10-02 14:18:28 —-AC—- C:\Windows\system32\pots.dll
2008-10-02 14:18:28 —-AC—- C:\Windows\system32\logagent.exe
2008-10-02 14:18:28 —-AC—- C:\Windows\system32\inseng.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\wpdbusenum.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\wmiprop.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\WindowsCodecsExt.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\powrprof.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\findnetprinters.dll
2008-10-02 14:18:27 —-AC—- C:\Windows\system32\capisp.dll
2008-10-02 14:18:26 —-AC—- C:\Windows\system32\rasplap.dll
2008-10-02 14:18:26 —-AC—- C:\Windows\system32\mfpmp.exe
2008-10-02 14:18:26 —-AC—- C:\Windows\system32\dnshc.dll
2008-10-02 14:18:25 —-AC—- C:\Windows\system32\shrpubw.exe
2008-10-02 14:18:25 —-AC—- C:\Windows\system32\RESAMPLEDMO.DLL
2008-10-02 14:18:25 —-AC—- C:\Windows\system32\fsutil.exe
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\sfc_os.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\sendmail.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\perfnet.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\olecli32.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\nsisvc.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\luainstall.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\imapi.dll
2008-10-02 14:18:24 —-AC—- C:\Windows\system32\fdPHost.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\WLanHC.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\wextract.exe
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\TMM.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\shgina.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\rshx32.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\RpcPing.exe
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\ktmw32.dll
2008-10-02 14:18:23 —-AC—- C:\Windows\system32\cmmon32.exe
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\WMADMOE.DLL
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\wiaacmgr.exe
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\version.dll
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\runonce.exe
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\d3dim.dll
2008-10-02 14:18:22 —-AC—- C:\Windows\system32\compstui.dll
2008-10-02 14:18:21 —-AC—- C:\Windows\system32\unregmp2.exe
2008-10-02 14:18:21 —-AC—- C:\Windows\system32\getmac.exe
2008-10-02 14:18:21 —-AC—- C:\Windows\system32\dimsjob.dll
2008-10-02 14:18:21 —-AC—- C:\Windows\system32\cmlua.dll
2008-10-02 14:18:20 —-AC—- C:\Windows\system32\UI0Detect.exe
2008-10-02 14:18:20 —-AC—- C:\Windows\system32\mdminst.dll
2008-10-02 14:18:20 —-AC—- C:\Windows\system32\dsauth.dll
2008-10-02 14:18:19 —-AC—- C:\Windows\system32\w32tm.exe
2008-10-02 14:18:19 —-AC—- C:\Windows\system32\net.exe
2008-10-02 14:18:19 —-AC—- C:\Windows\system32\msvfw32.dll
2008-10-02 14:18:19 —-AC—- C:\Windows\system32\MPG4DECD.DLL
2008-10-02 14:18:19 —-AC—- C:\Windows\system32\MP43DECD.DLL
2008-10-02 14:18:18 —-AC—- C:\Windows\system32\tscupgrd.exe
2008-10-02 14:18:18 —-AC—- C:\Windows\system32\imgutil.dll
2008-10-02 14:18:17 —-AC—- C:\Windows\system32\wmpshell.dll
2008-10-02 14:18:16 —-AC—- C:\Windows\system32\sdchange.exe
2008-10-02 14:18:16 —-AC—- C:\Windows\system32\ipconfig.exe
2008-10-02 14:18:16 —-AC—- C:\Windows\system32\credui.dll
2008-10-02 14:18:16 —-AC—- C:\Windows\system32\ACW.exe
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\PortableDeviceWiaCompat.dll
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\pnpts.dll
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\migisol.dll
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\fdeploy.dll
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\dispci.dll
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\diantz.exe
2008-10-02 14:18:15 —-AC—- C:\Windows\system32\cmutil.dll
2008-10-02 14:18:14 —-AC—- C:\Windows\system32\comrepl.dll
2008-10-02 14:18:13 —-AC—- C:\Windows\system32\sfc.exe
2008-10-02 14:18:13 —-AC—- C:\Windows\system32\dinput8.dll
2008-10-02 14:18:10 —-AC—- C:\Windows\system32\TSTheme.exe
2008-10-02 14:18:09 —-AC—- C:\Windows\system32\remotepg.dll
2008-10-02 14:18:09 —-AC—- C:\Windows\system32\nlaapi.dll
2008-10-02 14:18:09 —-AC—- C:\Windows\system32\ExplorerFrame.dll
2008-10-02 14:18:09 —-AC—- C:\Windows\system32\EncDump.dll
2008-10-02 14:18:09 —-AC—- C:\Windows\system32\cfgbkend.dll
2008-10-02 14:18:08 —-AC—- C:\Windows\system32\WPDShextAutoplay.exe
2008-10-02 14:18:08 —-AC—- C:\Windows\system32\wmidx.dll
2008-10-02 14:18:08 —-AC—- C:\Windows\system32\pdhui.dll
2008-10-02 14:18:08 —-AC—- C:\Windows\system32\fwcfg.dll
2008-10-02 14:18:08 —-AC—- C:\Windows\system32\expand.exe
2008-10-02 14:18:07 —-AC—- C:\Windows\system32\vdmredir.dll
2008-10-02 14:18:07 —-AC—- C:\Windows\system32\softkbd.dll
2008-10-02 14:18:07 —-AC—- C:\Windows\system32\colbact.dll
2008-10-02 14:18:06 —-AC—- C:\Windows\system32\utildll.dll
2008-10-02 14:18:06 —-AC—- C:\Windows\system32\TpmInit.exe
2008-10-02 14:18:06 —-AC—- C:\Windows\system32\modemui.dll
2008-10-02 14:18:06 —-AC—- C:\Windows\system32\hlink.dll
2008-10-02 14:18:05 —-AC—- C:\Windows\system32\McxDriv.dll
2008-10-02 14:18:05 —-AC—- C:\Windows\system32\iernonce.dll
2008-10-02 14:18:05 —-AC—- C:\Windows\system32\bridgeunattend.exe
2008-10-02 14:18:04 —-AC—- C:\Windows\system32\wmvdspa.dll
2008-10-02 14:18:04 —-AC—- C:\Windows\system32\msfeedsbs.dll
2008-10-02 14:18:04 —-AC—- C:\Windows\system32\amstream.dll
2008-10-02 14:18:03 —-AC—- C:\Windows\system32\sti_ci.dll
2008-10-02 14:18:03 —-AC—- C:\Windows\system32\rdrleakdiag.exe
2008-10-02 14:18:03 —-AC—- C:\Windows\system32\bootcfg.exe
2008-10-02 14:18:02 —-AC—- C:\Windows\system32\wsnmp32.dll
2008-10-02 14:18:02 —-AC—- C:\Windows\system32\vds_ps.dll
2008-10-02 14:18:02 —-AC—- C:\Windows\system32\esentutl.exe
2008-10-02 14:18:02 —-AC—- C:\Windows\system32\cmcfg32.dll
2008-10-02 14:18:02 —-AC—- C:\Windows\system32\admparse.dll
2008-10-02 14:18:01 —-AC—- C:\Windows\system32\waitfor.exe
2008-10-02 14:18:01 —-AC—- C:\Windows\system32\tabcal.exe
2008-10-02 14:18:01 —-AC—- C:\Windows\system32\qdv.dll
2008-10-02 14:18:01 —-AC—- C:\Windows\system32\logman.exe
2008-10-02 14:18:01 —-AC—- C:\Windows\system32\iscsium.dll
2008-10-02 14:18:00 —-AC—- C:\Windows\system32\osblprov.dll
2008-10-02 14:18:00 —-AC—- C:\Windows\system32\odbccp32.dll
2008-10-02 14:18:00 —-AC—- C:\Windows\system32\dpnet.dll
2008-10-02 14:18:00 —-AC—- C:\Windows\system32\cacls.exe
2008-10-02 14:17:59 —-AC—- C:\Windows\system32\WsmCl.dll
2008-10-02 14:17:59 —-AC—- C:\Windows\system32\wfapigp.dll
2008-10-02 14:17:59 —-AC—- C:\Windows\system32\shutdown.exe
2008-10-02 14:17:58 —-AC—- C:\Windows\system32\wmpcm.dll
2008-10-02 14:17:58 —-AC—- C:\Windows\system32\olesvr32.dll
2008-10-02 14:17:58 —-AC—- C:\Windows\system32\msdtc.exe
2008-10-02 14:17:58 —-AC—- C:\Windows\system32\DpiScaling.exe
2008-10-02 14:17:58 —-AC—- C:\Windows\system32\dmsynth.dll
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\wpnpinst.exe
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\rasauto.dll
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\olethk32.dll
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\mfvdsp.dll
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\iscsiwmi.dll
2008-10-02 14:17:57 —-AC—- C:\Windows\system32\COLORCNV.DLL
2008-10-02 14:17:56 —-AC—- C:\Windows\system32\werdiagcontroller.dll
2008-10-02 14:17:56 —-AC—- C:\Windows\system32\mstext40.dll
2008-10-02 14:17:55 —-AC—- C:\Windows\system32\wavemsp.dll
2008-10-02 14:17:55 —-AC—- C:\Windows\system32\ufat.dll
2008-10-02 14:17:54 —-AC—- C:\Windows\system32\sxproxy.dll
2008-10-02 14:17:54 —-AC—- C:\Windows\system32\SLLUA.exe
2008-10-02 14:17:54 —-AC—- C:\Windows\system32\at.exe
2008-10-02 14:17:53 —-AC—- C:\Windows\system32\odbctrac.dll
2008-10-02 14:17:53 —-AC—- C:\Windows\system32\networkitemfactory.dll
2008-10-02 14:17:53 —-AC—- C:\Windows\system32\msctfui.dll
2008-10-02 14:17:52 —-AC—- C:\Windows\system32\WpdConns.dll
2008-10-02 14:17:52 —-AC—- C:\Windows\system32\ucsvc.exe
2008-10-02 14:17:52 —-AC—- C:\Windows\system32\rgb9rast.dll
2008-10-02 14:17:52 —-AC—- C:\Windows\system32\mshta.exe
2008-10-02 14:17:52 —-AC—- C:\Windows\system32\convert.exe
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\xmlprovi.dll
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\RegCtrl.dll
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\mobsync.exe
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\licmgr10.dll
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\itss.dll
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\csrstub.exe
2008-10-02 14:17:51 —-AC—- C:\Windows\system32\bitsigd.dll
2008-10-02 14:17:50 —-AC—- C:\Windows\system32\TimeDateMUICallback.dll
2008-10-02 14:17:50 —-AC—- C:\Windows\system32\prevhost.exe
2008-10-02 14:17:50 —-AC—- C:\Windows\system32\iscsied.dll
2008-10-02 14:17:50 —-AC—- C:\Windows\system32\AuthFWGP.dll
2008-10-02 14:17:49 —-AC—- C:\Windows\system32\tbs.dll
2008-10-02 14:17:49 —-AC—- C:\Windows\system32\rasdiag.dll
2008-10-02 14:17:49 —-AC—- C:\Windows\system32\netbtugc.exe
2008-10-02 14:17:49 —-AC—- C:\Windows\system32\dskquota.dll
2008-10-02 14:17:48 —-AC—- C:\Windows\system32\ocsetup.exe
2008-10-02 14:17:48 —-AC—- C:\Windows\system32\cscdll.dll
2008-10-02 14:17:48 —-AC—- C:\Windows\system32\AtBroker.exe
2008-10-02 14:17:47 —-AC—- C:\Windows\system32\unattendedjoin.exe
2008-10-02 14:17:47 —-AC—- C:\Windows\system32\setupcln.dll
2008-10-02 14:17:47 —-AC—- C:\Windows\system32\GuidedHelp.dll
2008-10-02 14:17:47 —-AC—- C:\Windows\system32\fphc.dll
2008-10-02 14:17:47 —-AC—- C:\Windows\system32\dmime.dll
2008-10-02 14:17:46 —-AC—- C:\Windows\system32\winnsi.dll
2008-10-02 14:17:46 —-AC—- C:\Windows\system32\mydocs.dll
2008-10-02 14:17:46 —-AC—- C:\Windows\system32\l2gpstore.dll
2008-10-02 14:17:46 —-AC—- C:\Windows\system32\cmpbk32.dll
2008-10-02 14:17:45 —-AC—- C:\Windows\system32\dsdmo.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\usbui.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\regini.exe
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\odbccu32.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\odbccr32.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\napdsnap.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\msident.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\msdart.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\dot3dlg.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\devenum.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\apilogen.dll
2008-10-02 14:17:44 —-AC—- C:\Windows\system32\amxread.dll
2008-10-02 14:17:43 —-AC—- C:\Windows\system32\VIDRESZR.DLL
2008-10-02 14:17:43 —-AC—- C:\Windows\system32\cmstplua.dll
2008-10-02 14:17:42 —-AC—- C:\Windows\system32\wpclsp.dll
2008-10-02 14:17:42 —-AC—- C:\Windows\system32\RacAgent.exe
2008-10-02 14:17:42 —-AC—- C:\Windows\system32\MsCtfMonitor.dll
2008-10-02 14:17:42 —-AC—- C:\Windows\system32\gpupdate.exe
2008-10-02 14:17:41 —-AC—- C:\Windows\system32\WINSRPC.DLL
2008-10-02 14:17:41 —-AC—- C:\Windows\system32\upnpcont.exe
2008-10-02 14:17:41 —-AC—- C:\Windows\system32\mtxlegih.dll
2008-10-02 14:17:41 —-AC—- C:\Windows\system32\mtxdm.dll
2008-10-02 14:17:41 —-AC—- C:\Windows\system32\avrt.dll
2008-10-02 14:17:40 —-AC—- C:\Windows\system32\vss_ps.dll
2008-10-02 14:17:40 —-AC—- C:\Windows\system32\nsi.dll
2008-10-02 14:17:40 —-AC—- C:\Windows\system32\nbtstat.exe
2008-10-02 14:17:39 —-AC—- C:\Windows\system32\srwmi.dll
2008-10-02 14:17:39 —-AC—- C:\Windows\system32\graftabl.com
2008-10-02 14:17:38 —-AC—- C:\Windows\system32\mfcsubs.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\wsock32.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\WavDest.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\vfwwdm32.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\syskey.exe
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\rasphone.exe
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\odbcbcp.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\netevent.dll
2008-10-02 14:17:37 —-AC—- C:\Windows\system32\msexcl40.dll
2008-10-02 14:17:36 —-AC—- C:\Windows\system32\wiarpc.dll
2008-10-02 14:17:36 —-AC—- C:\Windows\system32\ndfetw.dll
2008-10-02 14:17:36 —-AC—- C:\Windows\system32\extrac32.exe
2008-10-02 14:17:35 —-AC—- C:\Windows\system32\ROUTE.EXE
2008-10-02 14:17:35 —-AC—- C:\Windows\system32\procinst.dll
2008-10-02 14:17:35 —-AC—- C:\Windows\system32\MP3DMOD.DLL
2008-10-02 14:17:35 —-AC—- C:\Windows\system32\eventcls.dll
2008-10-02 14:17:34 —-AC—- C:\Windows\system32\csrss.exe
2008-10-02 14:17:33 —-AC—- C:\Windows\system32\WindowsAnytimeUpgrade.exe
2008-10-02 14:17:33 —-AC—- C:\Windows\system32\wiadss.dll
2008-10-02 14:17:33 —-AC—- C:\Windows\system32\TabbtnEx.dll
2008-10-02 14:17:33 —-AC—- C:\Windows\system32\d3dxof.dll
2008-10-02 14:17:33 —-AC—- C:\Windows\system32\atmfd.dll
2008-10-02 14:17:32 —-AC—- C:\Windows\system32\WlanMmHC.dll
2008-10-02 14:17:32 —-AC—- C:\Windows\system32\psbase.dll
2008-10-02 14:17:32 —-AC—- C:\Windows\system32\inetppui.dll
2008-10-02 14:17:32 —-AC—- C:\Windows\system32\dmscript.dll
2008-10-02 14:17:31 —-AC—- C:\Windows\system32\Tabbtn.dll
2008-10-02 14:17:31 —-AC—- C:\Windows\system32\CertEnrollCtrl.exe
2008-10-02 14:17:31 —-AC—- C:\Windows\fveupdate.exe
2008-10-02 14:17:30 —-AC—- C:\Windows\system32\msxbde40.dll
2008-10-02 14:17:30 —-AC—- C:\Windows\system32\dmloader.dll
2008-10-02 14:17:28 —-AC—- C:\Windows\system32\Netplwiz.exe
2008-10-02 14:17:28 —-AC—- C:\Windows\system32\msltus40.dll
2008-10-02 14:17:28 —-AC—- C:\Windows\system32\credssp.dll
2008-10-02 14:17:27 —-AC—- C:\Windows\system32\wshcon.dll
2008-10-02 14:17:26 —-AC—- C:\Windows\system32\mspbde40.dll
2008-10-02 14:17:26 —-AC—- C:\Windows\system32\icsunattend.exe
2008-10-02 14:17:25 —-AC—- C:\Windows\system32\WsmRes.dll
2008-10-02 14:17:25 —-AC—- C:\Windows\system32\PlaySndSrv.dll
2008-10-02 14:17:24 —-AC—- C:\Windows\system32\wship6.dll
2008-10-02 14:17:24 —-AC—- C:\Windows\system32\sxsstore.dll
2008-10-02 14:17:24 —-AC—- C:\Windows\system32\HotStartUserAgent.dll
2008-10-02 14:17:23 —-AC—- C:\Windows\system32\WSHTCPIP.DLL
2008-10-02 14:17:23 —-AC—- C:\Windows\system32\msvidc32.dll
2008-10-02 14:17:23 —-AC—- C:\Windows\system32\localui.dll
2008-10-02 14:17:23 —-AC—- C:\Windows\system32\lltdapi.dll
2008-10-02 14:17:23 —-AC—- C:\Windows\system32\ComputerDefaults.exe
2008-10-02 14:17:22 —-AC—- C:\Windows\system32\tcpmon.ini
2008-10-02 14:17:22 —-AC—- C:\Windows\system32\setupSNK.exe
2008-10-02 14:17:22 —-AC—- C:\Windows\system32\LangCleanupSysprepAction.dll
2008-10-02 14:17:22 —-AC—- C:\Windows\system32\icaapi.dll
2008-10-02 14:17:21 —-AC—- C:\Windows\system32\slwga.dll
2008-10-02 14:17:21 —-AC—- C:\Windows\system32\OptionalFeatures.exe
2008-10-02 14:17:19 —-AC—- C:\Windows\system32\sbunattend.exe
2008-10-02 14:17:19 —-AC—- C:\Windows\system32\dmutil.dll
2008-10-02 14:17:18 —-AC—- C:\Windows\system32\spopk.dll
2008-10-02 14:17:18 —-AC—- C:\Windows\system32\serialui.dll
2008-10-02 14:17:17 —-AC—- C:\Windows\system32\usbperf.dll
2008-10-02 14:17:17 —-AC—- C:\Windows\system32\NcdProp.dll
2008-10-02 14:17:14 —-AC—- C:\Windows\system32\cofiredm.dll
2008-10-02 14:17:13 —-AC—- C:\Windows\system32\odbcconf.dll
2008-10-02 14:17:12 —-AC—- C:\Windows\system32\msfeedssync.exe
2008-10-02 14:17:12 —-AC—- C:\Windows\system32\hbaapi.dll
2008-10-02 14:17:10 —-AC—- C:\Windows\system32\rasctrs.dll
2008-10-02 14:17:10 —-AC—- C:\Windows\system32\ieencode.dll
2008-10-02 14:17:09 —-AC—- C:\Windows\system32\msobjs.dll
2008-10-02 14:17:09 —-AC—- C:\Windows\system32\corpol.dll
2008-10-02 14:17:08 —-AC—- C:\Windows\system32\hnetmon.dll
2008-10-02 14:17:07 —-AC—- C:\Windows\system32\midimap.dll
2008-10-02 14:17:06 —-AC—- C:\Windows\system32\vdmdbg.dll
2008-10-02 14:17:06 —-AC—- C:\Windows\system32\InfDefaultInstall.exe
2008-10-02 14:17:06 —-AC—- C:\Windows\system32\esentprf.dll
2008-10-02 14:17:05 —-AC—- C:\Windows\system32\nlsbres.dll
2008-10-02 14:17:04 —-AC—- C:\Windows\system32\url.dll
2008-10-02 14:17:04 —-AC—- C:\Windows\system32\LogonUI.exe
2008-10-02 14:17:04 —-AC—- C:\Windows\system32\iprtprio.dll
2008-10-02 14:17:00 —-AC—- C:\Windows\system32\sdspres.dll
2008-10-02 14:16:55 —-AC—- C:\Windows\system32\osbaseln.dll
2008-10-02 14:16:55 —-AC—- C:\Windows\system32\cfgmgr32.dll
2008-10-02 14:16:50 —-AC—- C:\Windows\system32\msisip.dll
2008-10-02 14:16:49 —-AC—- C:\Windows\system32\msmmsp.dll
2008-10-02 14:16:45 —-AC—- C:\Windows\system32\dispex.dll
2008-10-02 14:16:44 —-AC—- C:\Windows\system32\winusb.dll
2008-10-02 14:16:44 —-AC—- C:\Windows\system32\rdpcfgex.dll
2008-10-02 14:16:35 —-AC—- C:\Windows\system32\Nlsdl.dll
2008-10-02 14:16:32 —-AC—- C:\Windows\system32\riched32.dll
2008-10-02 14:16:32 —-AC—- C:\Windows\system32\msidle.dll
2008-10-02 14:16:31 —-AC—- C:\Windows\system32\spwmp.dll
2008-10-02 14:16:31 —-AC—- C:\Windows\system32\idndl.dll
2008-10-02 14:16:27 —-AC—- C:\Windows\system32\KBDKOR.DLL
2008-10-02 14:16:27 —-AC—- C:\Windows\system32\KBDJPN.DLL
2008-10-02 14:16:23 —-AC—- C:\Windows\system32\iscsilog.dll
2008-10-02 14:16:18 —-AC—- C:\Windows\system32\vga256.dll
2008-10-02 14:16:18 —-AC—- C:\Windows\system32\dxmasf.dll
2008-10-02 14:16:17 —-AC—- C:\Windows\system32\wmploc.DLL
2008-10-02 14:16:17 —-AC—- C:\Windows\system32\tsddd.dll
2008-10-02 14:16:17 —-AC—- C:\Windows\system32\framebuf.dll
2008-10-02 14:16:16 —-AC—- C:\Windows\system32\vga64k.dll
2008-10-02 14:16:15 —-AC—- C:\Windows\system32\vga.dll
2008-10-02 14:16:14 —-AC—- C:\Windows\system32\bootstr.dll
2008-10-02 14:16:13 —-AC—- C:\Windows\system32\dmdskres2.dll
2008-10-02 14:16:11 —-AC—- C:\Windows\system32\spwizres.dll
2008-10-02 14:16:11 —-AC—- C:\Windows\system32\f3ahvoas.dll
2008-10-02 14:16:04 —-AC—- C:\Windows\system32\gatherWiredInfo.vbs
2008-10-02 14:16:02 —-AC—- C:\Windows\system32\gatherWirelessInfo.vbs
2008-10-02 14:16:01 —-AC—- C:\Windows\system32\fsmgmt.msc
2008-10-02 14:15:43 —-AC—- C:\Windows\system32\perfmon.msc
2008-10-02 14:15:42 —-AC—- C:\Windows\system32\vsp1cln.exe
2008-10-02 14:13:44 —-AC—- C:\Windows\system32\xmllite.dll
2008-10-02 14:13:40 —-AC—- C:\Windows\system32\wbemcomn.dll
2008-10-02 14:13:17 —-AC—- C:\Windows\system32\SmiInstaller.dll
2008-10-02 14:13:15 —-AC—- C:\Windows\system32\SmiEngine.dll
2008-10-02 14:12:52 —-AC—- C:\Windows\system32\wdscore.dll
2008-10-02 14:12:52 —-AC—- C:\Windows\system32\PkgMgr.exe
2008-10-02 14:11:48 —-AC—- C:\Windows\system32\drvstore.dll
2008-10-02 14:11:44 —-AC—- C:\Windows\system32\mspatcha.dll
2008-10-02 14:11:44 —-AC—- C:\Windows\system32\msdelta.dll
2008-10-02 14:11:44 —-AC—- C:\Windows\system32\dpx.dll
2008-10-02 11:45:44 —-AC—- C:\Windows\system32\STKIT432.DLL
2008-10-02 11:45:44 —-AC—- C:\Windows\system32\msxml.dll
2008-10-02 11:45:39 —-DC—- C:\Program Files\Registry Mechanic
2008-10-02 11:00:41 —-DC—- C:\ProgramData\SpeedBit
2008-10-02 11:00:26 —-DC—- C:\Program Files\DAP
2008-10-01 22:50:13 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Games
2008-10-01 22:43:30 —-DC—- C:\ProgramData\Tages
2008-10-01 22:40:57 —-DC—- C:\Windows\system32\AGEIA
2008-10-01 22:40:55 —-DC—- C:\Program Files\AGEIA Technologies
2008-10-01 22:31:07 —-DC—- C:\Program Files\The Adventure Company
2008-09-29 05:09:20 —-AC—- C:\Windows\system32\twnlib4.dll
2008-09-29 05:09:20 —-AC—- C:\Windows\system32\imagXRA7.dll
2008-09-29 05:09:20 —-AC—- C:\Windows\system32\imagXR7.dll
2008-09-29 05:09:20 —-AC—- C:\Windows\system32\imagXpr7.dll
2008-09-29 05:09:20 —-AC—- C:\Windows\system32\imagX7.dll




======List of files/folders modified in the last 1 months======

2008-10-20 10:07:49 —-DC—- C:\Windows\Temp
2008-10-20 10:05:05 —-DC—- C:\Windows\Prefetch
2008-10-20 09:58:58 —-DC—- C:\WINDOWS
2008-10-20 09:58:57 —-SHD—- C:\System Volume Information
2008-10-19 23:58:35 —-DC—- C:\Windows\Minidump
2008-10-19 23:52:49 —-DC—- C:\Windows\LiveKernelReports
2008-10-19 13:30:40 —-DC—- C:\Windows\system32\catroot2
2008-10-19 00:15:57 —-DC—- C:\ProgramData\CyberLink
2008-10-18 17:28:09 —-DC—- C:\Windows\system32\Tasks
2008-10-18 17:02:43 —-DC—- C:\Windows\system32\drivers
2008-10-18 16:47:04 —-DC—- C:\Windows\System32
2008-10-18 16:47:04 —-DC—- C:\Windows\inf
2008-10-18 16:47:04 —-AC—- C:\Windows\system32\PerfStringBackup.INI
2008-10-18 16:08:13 —-DC—- C:\ProgramData\McAfee
2008-10-18 13:56:22 —-RDC—- C:\Program Files
2008-10-18 12:36:46 —-ADC—- C:\ProgramData\TEMP
2008-10-18 10:53:38 —-SHDC—- C:\Windows\Installer
2008-10-18 10:53:26 —-HDC—- C:\ProgramData
2008-10-17 22:25:48 —-DC—- C:\Temp
2008-10-17 20:34:48 —-DC—- C:\Windows\Debug
2008-10-17 16:32:46 —-DC—- C:\ProgramData\Viewpoint
2008-10-17 16:32:42 —-DC—- C:\Program Files\Viewpoint
2008-10-17 15:36:14 —-DC—- C:\Windows\system32\config
2008-10-17 09:27:55 —-DC—- C:\Windows\Tasks
2008-10-16 17:49:28 —-DC—- C:\Program Files\Adobe
2008-10-16 13:43:08 —-DC—- C:\Windows\system32\Macromed
2008-10-16 13:21:30 —-DC—- C:\Windows\SMINST
2008-10-16 13:02:13 —-RSDC—- C:\Windows\Fonts
2008-10-16 12:59:33 —-DC—- C:\Program Files\HP
2008-10-16 12:59:14 —-HDC—- C:\Program Files\InstallShield Installation Information
2008-10-16 12:57:55 —-DC—- C:\SwSetup
2008-10-16 12:53:19 —-DC—- C:\Program Files\Hewlett-Packard
2008-10-16 12:46:45 —-DC—- C:\ProgramData\Hewlett-Packard
2008-10-16 12:36:20 —-RSDC—- C:\Windows\assembly
2008-10-16 12:32:18 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Hewlett-Packard
2008-10-16 12:31:41 —-HDC—- C:\System.sav
2008-10-16 12:24:15 —-DC—- C:\ProgramData\Yahoo! Companion
2008-10-16 12:24:07 —-DC—- C:\Program Files\DivX
2008-10-16 12:11:58 —-DC—- C:\ProgramData\Yahoo!
2008-10-16 12:05:08 —-SDC—- C:\Windows\Downloaded Program Files
2008-10-16 11:27:54 —-DC—- C:\Program Files\Common Files
2008-10-15 13:55:43 —-D—- C:\Windows\winsxs
2008-10-15 13:45:47 —-DC—- C:\Windows\Microsoft.NET
2008-10-15 13:45:30 —-DC—- C:\Windows\system32\catroot
2008-10-15 13:38:43 —-DC—- C:\Windows\ehome
2008-10-15 13:38:39 —-DC—- C:\Program Files\Windows Mail
2008-10-15 13:38:35 —-DC—- C:\Windows\system32\migration
2008-10-14 03:10:00 —-DC—- C:\Windows\HPCPCUninstall-6811507
2008-10-13 17:44:59 —-DC—- C:\Windows\system32\wbem
2008-10-13 17:42:58 —-DC—- C:\Windows\system32\spool
2008-10-13 17:42:58 —-DC—- C:\Windows\system32\Msdtc
2008-10-13 17:42:58 —-DC—- C:\Windows\system32\CodeIntegrity
2008-10-13 17:42:51 —-DC—- C:\ProgramData\WildTangent
2008-10-13 17:42:51 —-DC—- C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
2008-10-13 17:42:43 —-DC—- C:\ProgramData\Microsoft Help
2008-10-13 17:42:41 —-DC—- C:\ProgramData\Lavasoft
2008-10-13 17:42:40 —-DC—- C:\ProgramData\FLEXnet
2008-10-13 17:41:43 —-SDC—- C:\ProgramData\Microsoft
2008-10-12 17:05:52 —-DC—- C:\Users\Valued Customer\AppData\Roaming\Adobe
2008-10-12 16:01:44 —-DC—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-07 12:19:40 —-AC—- C:\Windows\system32\mrt.exe
2008-10-03 17:24:54 —-DC—- C:\Windows\Logs
2008-10-03 13:36:19 —-D—- C:\Windows\rescache
2008-10-03 13:13:12 —-DC—- C:\Windows\system32\en-US
2008-10-03 13:13:12 —-DC—- C:\Windows\PolicyDefinitions
2008-10-02 22:31:43 —-SHDC—- C:\boot
2008-10-02 22:31:39 —-ASH—- C:\Program Files\desktop.ini
2008-10-02 22:17:38 —-DC—- C:\Program Files\Windows Calendar
2008-10-02 22:17:37 —-DC—- C:\Program Files\Windows Sidebar
2008-10-02 22:17:37 —-DC—- C:\Program Files\Movie Maker
2008-10-02 22:17:33 —-DC—- C:\Program Files\Internet Explorer
2008-10-02 22:17:32 —-DC—- C:\Program Files\Windows Media Player
2008-10-02 22:17:30 —-D—- C:\Program Files\Windows Collaboration
2008-10-02 22:17:28 —-DC—- C:\Program Files\Windows Journal
2008-10-02 22:17:27 —-DC—- C:\Program Files\Windows Photo Gallery
2008-10-02 22:17:11 —-DC—- C:\Program Files\Common Files\System
2008-10-02 22:17:10 —-DC—- C:\Program Files\Windows Defender
2008-10-02 22:17:07 —-D—- C:\Windows\servicing
2008-10-02 22:16:35 —-DC—- C:\Windows\MSAgent
2008-10-02 22:16:31 —-DC—- C:\Windows\L2Schemas
2008-10-02 22:16:31 —-DC—- C:\Windows\IME
2008-10-02 22:16:31 —-DC—- C:\Windows\DigitalLocker
2008-10-02 22:16:28 —-DC—- C:\Windows\system32\XPSViewer
2008-10-02 22:16:28 —-DC—- C:\Windows\system32\com
2008-10-02 22:16:27 —-DC—- C:\Windows\system32\ko-KR
2008-10-02 22:16:27 —-DC—- C:\Windows\system32\da-DK
2008-10-02 22:16:04 —-DC—- C:\Windows\system32\it-IT
2008-10-02 22:16:04 —-DC—- C:\Windows\system32\el-GR
2008-10-02 22:16:04 —-DC—- C:\Windows\system32\de-DE
2008-10-02 22:16:03 —-DC—- C:\Windows\system32\oobe
2008-10-02 22:16:02 —-DC—- C:\Windows\system32\sysprep
2008-10-02 22:15:48 —-D—- C:\Windows\system32\AdvancedInstallers
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\sv-SE
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\setup
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\ru-RU
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\ias
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\he-IL
2008-10-02 22:15:47 —-DC—- C:\Windows\system32\fr-FR
2008-10-02 22:15:46 —-DC—- C:\Windows\system32\hu-HU
2008-10-02 22:15:46 —-DC—- C:\Windows\system32\fi-FI
2008-10-02 22:15:46 —-DC—- C:\Windows\system32\cs-CZ
2008-10-02 22:15:45 —-DC—- C:\Windows\system32\SLUI
2008-10-02 22:15:45 —-DC—- C:\Windows\system32\pt-PT
2008-10-02 22:15:38 —-DC—- C:\Windows\system32\zh-CN
2008-10-02 22:15:38 —-DC—- C:\Windows\system32\manifeststore
2008-10-02 22:15:38 —-DC—- C:\Windows\system32\es-ES
2008-10-02 22:15:38 —-DC—- C:\Windows\system32\en
2008-10-02 22:15:37 —-DC—- C:\Windows\system32\zh-TW
2008-10-02 22:15:37 —-DC—- C:\Windows\system32\pl-PL
2008-10-02 22:15:37 —-DC—- C:\Windows\system32\ja-JP
2008-10-02 22:15:36 —-DC—- C:\Windows\system32\ro-RO
2008-10-02 22:15:27 —-DC—- C:\Windows\system32\tr-TR
2008-10-02 22:15:17 —-DC—- C:\Windows\system32\nl-NL
2008-10-02 22:15:17 —-DC—- C:\Windows\system32\nb-NO
2008-10-02 22:15:17 —-DC—- C:\Windows\system32\ar-SA
2008-10-02 22:15:10 —-DC—- C:\Windows\system32\migwiz
2008-10-02 22:15:07 —-DC—- C:\Windows\system32\pt-BR
2008-10-02 22:11:34 —-DC—- C:\Windows\AppPatch
2008-10-02 22:05:55 —-D—- C:\Windows\Boot
2008-10-02 22:05:40 —-D—- C:\Windows\system32\Boot
2008-10-02 16:12:57 —-A—- C:\Windows\system32\ifxcardm.dll
2008-10-02 16:12:51 —-A—- C:\Windows\system32\axaltocm.dll
2008-10-02 10:40:50 —-DC—- C:\Windows\pss
2008-09-28 18:26:40 —-DC—- C:\Program Files\Mozilla Firefox
2008-09-28 10:46:00 —-SDC—- C:\Users\Valued Customer\AppData\Roaming\Microsoft
2008-09-22 21:42:12 —-DC—- C:\Users\Valued Customer\AppData\Roaming\LimeWire

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eabfiltr;eabfiltr; C:\Windows\system32\DRIVERS\eabfiltr.sys [2006-06-28 8192]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160]
R1 IDSvix86;Symantec Intrusion Prevention Driver; \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080314.001\IDSvix86.sys [2008-02-13 261680]
R1 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2007-11-22 201320]
R1 MPFP;MPFP; C:\Windows\System32\Drivers\Mpfp.sys [2007-07-13 125728]
R1 pctfw2;pctfw2; \??\C:\WINDOWS\System32\drivers\pctfw2.sys [2008-10-13 160792]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2007-08-06 33052]
R1 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2007-12-01 279088]
R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2007-12-01 43696]
R1 Uim_IM;UIM Drive Backup Image Plugin; C:\Windows\System32\Drivers\Uim_IM.sys [2008-02-14 131672]
R1 UimBus;Universal Image Mounter Controller; C:\Windows\system32\DRIVERS\UimBus.sys [2008-02-14 32080]
R2 aksfridge;aksfridge; C:\Windows\system32\drivers\aksfridge.sys [2007-03-12 351744]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2008-10-01 278984]
R2 Hardlock;Hardlock; C:\Windows\system32\drivers\hardlock.sys [2007-03-06 694272]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2008-10-01 25416]
R2 MCSTRM;MCSTRM; C:\Windows\system32\drivers\MCSTRM.sys [2008-02-09 8413]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-16 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-15 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-15 37376]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-18 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-18 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-28 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2006-11-21 78128]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2006-11-21 80176]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-21 16560]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-18 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-03-03 182272]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-02-06 218752]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-15 34760]
R3 ElbyDelay;ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [2007-02-15 11984]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2008-02-29 35344]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2008-02-29 36880]
R3 Maplom;Maplom; C:\Windows\system32\drivers\Maplom.sys [2008-05-02 37312]
R3 MaplomL;MaplomL; C:\Windows\system32\drivers\MaplomL.sys [2008-05-02 36288]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2007-11-22 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\Windows\system32\drivers\mfebopk.sys [2007-11-22 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\Windows\system32\drivers\mfesmfk.sys [2007-12-02 40488]
R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080316.002\NAVENG.SYS [2008-03-06 82256]
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080316.002\NAVEX15.SYS [2008-03-06 895408]
R3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-10-31 2252800]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-02-27 4465184]
R3 NWADI;NWADI Bus Enumerator; C:\Windows\system32\DRIVERS\NWADIenum.sys [2007-08-16 194048]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-18 49664]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-18 88576]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-08-22 1749760]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2008-02-06 123952]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-28 199472]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2008-01-18 45696]
S3 Avc;AVC Device; C:\Windows\system32\DRIVERS\avc.sys [2008-01-18 40448]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-28 220160]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 E100B;Intel® PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2006-12-12 148992]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-18 1380864]
S3 IKFileSec;File Security Driver; C:\Windows\system32\drivers\ikfilesec.sys [2008-08-25 40840]
S3 IKSysFlt;System Filter Driver; C:\Windows\system32\drivers\iksysflt.sys [2008-08-25 66952]
S3 IKSysSec;System Security Driver; C:\Windows\system32\drivers\iksyssec.sys [2008-08-25 81288]
S3 mferkdk;McAfee Inc. mferkdk; C:\Windows\system32\drivers\mferkdk.sys [2007-11-22 33832]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-18 52608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-09 1786880]
S3 NWUSBCDFIL;Novatel Wireless Installation CD; C:\Windows\system32\DRIVERS\NwUsbCdFil.sys [2007-08-16 13824]
S3 NWUSBModem;Novatel Wireless USB Modem Driver; C:\Windows\system32\DRIVERS\nwusbmdm.sys [2007-08-16 99200]
S3 NWUSBPort;Novatel Wireless USB Status Port Driver; C:\Windows\system32\DRIVERS\nwusbser.sys [2007-08-16 99200]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver; C:\Windows\system32\DRIVERS\nwusbser2.sys [2007-08-16 99200]
S3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys [2007-06-02 8192]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2006-11-08 24064]
S3 R5U870FLx86;R5U870 UVC Lower Filter ; C:\Windows\System32\Drivers\R5U870FLx86.sys []
S3 R5U870FUx86;R5U870 UVC Upper Filter ; C:\Windows\System32\Drivers\R5U870FUx86.sys []
S3 SBRE;SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys []
S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2007-12-01 317616]
S3 ST50220;Sonix ST50220 USB Video Camera Driver; C:\Windows\System32\Drivers\ST50220.sys [2006-11-24 26752]
S3 TfNetMon;TfNetMon; \??\C:\Windows\system32\drivers\TfNetMon.sys [2008-10-13 33088]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-18 73088]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-18 134016]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 DeskSaverService;DeskSaverService; C:\Program Files\1st Desktop Guard\desksaver.exe [2008-04-09 1305600]
R2 hasplms;HASP License Manager; C:\Windows\system32\hasplms.exe [2007-03-15 535807]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-06-16 94208]
R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
R2 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2007-01-16 71208]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-24 2458128]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
R2 McShield;McAfee Real-time Scanner; C:\Program Files\McAfee\VirusScan\McShield.exe [2007-07-24 144704]
R2 OSCM Utility Service;OSCM Utility Service; C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe [2007-08-24 155648]
R2 QBCFMonitorService;QuickBooks Database Manager Service; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-03-01 20480]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2007-12-19 271760]
R2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [2007-12-19 112016]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service; C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2007-02-22 2217416]
S2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S2 LiveUpdate Notice Ex;LiveUpdate Notice Service Ex; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S3 AddFiltr;AddFiltr; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe [2006-06-26 126976]
S3 BthServ;Bluetooth Support Service; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-02-11 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2008-05-02 121360]
S3 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
S3 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe /m C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll []
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2008-02-18 66872]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2006-11-09 65536]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2006-11-06 887544]
S3 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S3 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2008-09-22 1079176]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-11-01 73728]
S3 ThreatFire;ThreatFire; C:\Program Files\Spyware Doctor\TFEngine\TFService.exe [2008-10-13 66880]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 RelevantKnowledge;RelevantKnowledge; C:\Windows\system32\rlservice.exe /service []

—————–EOF—————–


I know this is long, thanks in advance Ken, the time and effort you have already given to my situation is greatly appreciated!!!
Hello,

Did you try uninstalling Symantec recently, I still see live update running as a service, sometimes when two AV programs are running they can cause issues.

You may or may not find this

  • Go to Start> Run and type in services.msc then press Enter
  • Scroll down to RelevantKnowledge
  • Double Click that service to open it.
  • Click on Stop Service.
  • Then change the Startup Type to Disabled.
  • OK your way out of the program.


  • Open HJT > Misc Tools > Delete an NT Service
  • Type in RelevantKnowledge
  • Then click on OK, it will ask you to reboot, do so.







Open Hijackthis
  • Go to Misc Tools> Open Uninstall Manager.
  • Click on Save List.
  • The list will open in Notepad.
  • Copy and Paste the List into this thread
1st Desktop Guard 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) Acronis Disk Director Suite Activation Assistant for the 2007 Microsoft Office suites ADG Aspect [removed] Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe After Effects CS3 Adobe After Effects CS3 Adobe After Effects CS3 Presets Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Default Language CS3 Adobe Device Central CS3 Adobe ExtendScript Toolkit 2 Adobe ExtendScript Toolkit 2 Adobe Flash CS3 Adobe Flash CS3 Professional Adobe Flash Player 10 ActiveX Adobe Flash Player 9 ActiveX Adobe Flash Player Plugin Adobe Flash Video Encoder Adobe Fonts All Adobe Help Viewer CS3 Adobe Illustrator CS3 Adobe Illustrator CS3 Adobe Linguistics CS3 Adobe MotionPicture Color Files Adobe PDF Library Files Adobe Photoshop CS3 Adobe Photoshop CS3 Adobe Reader 8.1.2 Adobe Setup Adobe Setup Adobe Setup Adobe Setup Adobe Setup Adobe Setup Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe Video Profiles Adobe WinSoft Linguistics Plugin Adobe XMP DVA Panels CS3 Adobe XMP Panels CS3 AGEIA PhysX v7.09.13 AIM 6 Battlefield 2™ Canon G.726 WMP-Decoder Canon MovieEdit Task for ZoomBrowser EX Canon RAW Codec Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch Canon Utilities RemoteCapture DC Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CCleaner (remove only) CDDRV_Installer Conexant HD Audio DC-Bass Source 1.1.1 DirectVobSub (remove only) DivX Converter DivX Player DivX Web Player Download Accelerator Plus (DAP) Driver Genius Professional Edition 2007 ERUNT 1.1j ESU for Microsoft Vista ffdshow [rev 1685] [2007-12-06] FreeAgent Pro Tools Game Jackal v3.0.1.5 (32 bit) Haali Media Splitter HDAUDIO Soft Data Fax Modem with SmartCP Hewlett-Packard Active Check for Health Check Hewlett-Packard Asset Agent for Health Check HijackThis 2.0.2 hkSFV (remove only) HP Active Support Library HP Connections (remove only) HP Customer Experience Enhancements HP Easy Setup - Core HP Easy Setup - Frontend HP Help and Support HP Integrated Module with Bluetooth wireless technology 6.0.1.3100 HP Product Detection HP Quick Launch Buttons 6.10 B9 HP QuickPlay 3.6 HP Total Care Advisor HP Update HP User Guide 0049 HP Wireless Assistant HPNetworkAssistant Intel® Network Connections Drivers Java™ 6 Update 7 Java™ SE Runtime Environment 6 KhalInstallWrapper Lightroom LightScribe System Software 1.14.17.1 LiveUpdate Notice (Symantec Corporation) Logitech Desktop Messenger Logitech SetPoint LogonStudio Vista Malwarebytes' Anti-Malware McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Streets & Trips 2008 Microsoft Virtual PC 2007 SP1 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable Microsoft Works Mozilla Firefox (3.0.2) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 Parser and SDK Myst Uru - Complete Chronicles neroxml Noiseware Professional Plug-in Norton Internet Security NVIDIA Drivers PDF Settings PinyinDictionary PunkBuster Services PurePlay Poker QuickBooks Premier Edition 2007 QuickBooks Product Listing Service QuickPlay SlingPlayer 0.4.6 RealPlayer Registry Mechanic 8.0 Revo Uninstaller 1.50 Rhapsody Rhapsody Player Engine Rhapsody Player Engine Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Security Update for Excel 2007 (KB946974) Security Update for Office 2007 (KB947801) Security Update for Outlook 2007 (KB946983) SHOUTcast Source (remove only) Sonic Activation Module Spelling Dictionaries Support For Adobe Reader 8 Sprint Mobile Broadband (Novatel Wireless) - Lite SpyHunter Spyware Doctor 6.0 SupportSoft Assisted Service Synaptics Pointing Device Driver TeamSpeak 2 RC2 UltimateBet Update for Outlook 2007 Junk Email Filter (kb956080) VideoLAN VLC media player 0.8.6f Windows Driver Package - SafeNet, Inc. (SNTNLUSB) USB (03/09/2006 7.3.0.0) Windows Live installer Windows Live Mail Windows Live Messenger Windows Live Sign-in Assistant Windows Live Writer WinRAR archiver WinZip 11.1 Yahoo! Browser Services Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar Zoom Player (remove only)
These are still in your Add Remove Programs.
LiveUpdate Notice (Symantec Corporation)
Norton Internet Security


Which do you want to keep, Mcafee or Norton ? You can't keep them both, two AVs are not recommended
I am using mcAfee, havent used noron in quite some time. i cannot find anything norton or symantec anywhere on this notebook. I went to add remove programs and clicked uninstall on live update, It seemed to uninstall it. Thank you Ken
You can run this tool from Symantec that will remove all of there products, its designed for bad installs and bad uninstalls

http://service1.symantec.com/SUPPORT/tsgen…005033108162039

Post a new HJT log and let me know how your system is running now
Ken, my notebook crashed. I cannot boot up. F8 does not work, holding F11 does not work. i get windows boot manager, and it says: windows failed to start. a recent hardware or sotware change might be the cause. to fix the problem: 1) insert your windows installation disk and restart 2)click repair your computer i dont have this disk. HP told me i have to order the recovery disk, and lose everything on both my internal hard drives, and re-install the operating system. Does this sound correct to you?
Jim, When did this happen? Your system was running fine after all the fixes. If it won't boot you will need the recovery CD to do a System Repair
Jim

I have been going over your logs , you had some minor malware issues that we removed, nothing really that bad. Nothing any of the scans removed would have caused this.

I had an issue Sunday, where it took me over 30 minutes to boot up. Everything i tried to do or open took 10 to 20 minutes(severe lag)

You posted this originally and I am wondering if there is an underlying hardware problem on your system like maybe a hard drive going bad. I am going to link you to a real good windows support site that maybe able to help you with this.

Windows Helpnet
Post in the Vista forum. From what I have been reading you will need either a windows or recovery CD

With your computer off, when you press the power button, can you not press the F8 key by tapping it rapidly, not holding it down and select Last Known Good
Here's where i am since last post, Ken. I spoke with Hp live support. They suggested i order a recovery cd from them, and reinstall the OS, losing everything on both internal hard drives.
I called Best Buy Geek Squad, They had me bring it in for a free 15 minute diagnostic. They had a special cd, and tried repairing the registry, That didn't work. Thay suggested that I use a Vista cd and try repairing or reinstall the OS. He told me that while repairing with the cd, there is a 50/50 chance i will lose everything on both hard drives, and ultimately reformat. He suggested i buy a sata to usb cable from Fry's, so I did. With this cable, i can remove both hard drives, and back them up to the external hd, with the use of another computer. Fry's told be i could not backup my programs, as they are copywrited.
I am wondering if i can use a program from Acronis, called True Image. I have a feeling this will backup all my programs and settings, so i am going to do some research on this.
I am getting ready to order the recovery cd from HP. I have to pay for this, and think it is rididculous these don't come from the mfgrs' with all new computers, though I do take partial blame for not making one myself when I got the notebook.
I found this link on the net:

http://neosmart.net/blog/2008/windows-vist…-disc-download/

What do you think of this, worth a try? Best Buy put a scare in me when i mentioned it, stating that it could contain some sort of computer bot, that would use a portion of my processor everytime i am on the net, and would be very difficult to know or detect, hiding itself from all spyware'virus software. I am thinking of maybe trying this, and trying the repair feature. If you suggest I do, do you also suggest that I first remove the hard drives and try backing up everything? Or, do I wait for the HP cd, back up to external, then repair?

I have some options here, what do you think ken?

Thanks again,
Jim
Ken, I downloaded the Vista disk from the link i posted above. I burned the ISO image to disk, loaded it into my notebook with the problem, clicked repair, and it worked!!! I put this disk away in a safe place, I think I was fortunate to find the download. It said it was repairing a problem with windows booting. I have been playing around with a couple of programs in the past couple weeks. Paragon hard disk manager, which i setup a boot manager with. Also, an Acronis program, called Disk Director, which i used to creat some partitions in my external hard drive, along with a 12 GB partition on an internal hard drive. I have plans to use this 12GB partition to install Windows XP on, and creat a dual boot system. I would like to have XP to run a laser printer i have, and also run some programs incompatible with Vista. It doesn't seem like Paragon or Acronis programs caused this issue. I have restarted the computer several times since last using either of the two programs. It seems to be starting or booting up nicely now Ken. I just restarted it, and I will post my HJT log in the following post.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:02:45 PM, on 10/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\taskeng.exe
C:\WINDOWS\system32\Dwm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\WINDOWS\System32\mobsync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [StxTrayMenu] C:\Program Files\Seagate\SystemTray\FreeAgentLauncher.exe C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [00DSKSVR00] "C:\Program Files\1st Desktop Guard\desksaver.exe" saskda
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\WINDOWS\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: SYSTRAN Lookup - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/lookup.js
O8 - Extra context menu item: SYSTRAN Translate - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/translate.js
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Valued Customer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DeskSaverService - Unknown owner - C:\Program Files\1st Desktop Guard\desksaver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\Windows\system32\hasplms.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe

–
End of file - 14147 bytes


Thank You for reviewing, Ken
Hello Jim,

I have been holding my breath hoping you would post back. I am so glad you got it up and running again. I am not familiar with the disk you downloaded but if it worked for you , great. You seem to have a lot of activity going on with dual booting, multi partitioning and so on, this could be the root of your problems, your playing around with a lot of things that could turn into a disaster. Years ago when you bought a new PC you always got the windows disk, but no more but I am surprised that you did not get a recovery disk included with your purchase of this computer.

Your log looks fine, its clean, no malware that I can see and it looks like you got rid of Norton. :thumbup:

  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.


Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
Great!!! Thanks so much for your help Ken, I really do appreciate it!!! By the way, i just finished making a complete back up of everything on both hard drives with the Acronis True Image, and i created the HP recovery disk. I feel I can experiment carefully with this XP partition and try and creat a dual boot system now. Thanks again Ken, Jim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI