cgesuald
2009-01-03, 15:11
OTViewIt logfile created on: 1/3/2009 7:57:24 AM - Run 2
OTViewIt by OldTimer - Version 1.0.20.1 Folder = C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\VCR2PEVD
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 6.0.3790.3959)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.34 Mb Total Physical Memory | 169.51 Mb Available Physical Memory | 37.89% Memory free
1.04 Gb Paging File | 0.83 Gb Available in Paging File | 79.55% Paging File free
Paging file location(s): c:\pagefile.sys 670 1024;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 28.93 Gb Free Space | 38.82% Space Free | Partition Type: NTFS
Drive D: | 74.53 Gb Total Space | 12.20 Gb Free Space | 16.37% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ROME
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2004/03/23 11:49:08 | 00,397,312 | ---- | M] () -- C:\WINDOWS\system32\ati2evxx.exe
[2004/06/09 20:31:08 | 00,255,096 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
[2004/06/09 20:31:14 | 00,242,808 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
[2004/08/16 13:55:52 | 00,030,024 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
[2008/12/06 18:04:44 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2002/12/17 17:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
[2002/12/04 11:52:36 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
[2007/02/17 03:57:48 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2004/06/09 20:31:06 | 00,066,680 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[2008/12/06 18:04:45 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2006/11/21 18:16:02 | 00,724,992 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
[2002/12/17 17:23:32 | 00,074,308 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
[2007/02/17 04:09:46 | 00,207,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2007/02/17 03:57:48 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2009/01/03 07:56:59 | 00,423,424 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\VCR2PEVD\OTViewIt[1].exe
========== (O23) Win32 Services ==========
[2004/03/23 11:49:08 | 00,397,312 | ---- | M] () -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
[2004/06/09 20:31:08 | 00,255,096 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
[2004/06/09 20:31:12 | 00,087,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped])
[2004/06/09 20:31:14 | 00,242,808 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
[2004/08/16 13:55:52 | 00,030,024 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
[2007/02/17 02:50:02 | 00,164,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dfssvc.exe -- (Dfs [On_Demand | Stopped])
[2007/02/17 03:20:52 | 00,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ismserv.exe -- (IsmServ [Disabled | Stopped])
[2008/12/06 18:04:44 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2007/02/18 00:30:26 | 00,094,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\llssrv.exe -- (LicenseService [Disabled | Stopped])
[2002/12/04 11:52:36 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe -- (MSSEARCH [Auto | Running])
[2002/12/17 17:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -- (MSSQLSERVER [Auto | Running])
[2002/12/17 17:23:30 | 00,066,112 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
[2007/02/17 03:41:50 | 00,792,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntfrs.exe -- (NtFrs [On_Demand | Stopped])
[2007/02/17 03:55:56 | 00,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsopprov.exe -- (RSoPProv [On_Demand | Stopped])
[2004/08/02 19:36:36 | 00,173,392 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam [On_Demand | Stopped])
[2004/06/11 18:28:30 | 00,201,944 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped])
[2002/12/17 17:23:30 | 00,311,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.exe -- (SQLSERVERAGENT [On_Demand | Stopped])
[2004/08/16 13:56:00 | 01,267,024 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [On_Demand | Stopped])
[2007/02/17 04:07:00 | 00,071,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tssdis.exe -- (Tssdis [Disabled | Stopped])
[2007/02/17 04:08:32 | 00,039,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [On_Demand | Stopped])
[2007/02/18 00:36:40 | 00,352,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\vds.exe -- (vds [On_Demand | Stopped])
========== Driver Services ==========
[2004/03/23 11:59:52 | 00,701,440 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2003/11/05 23:22:10 | 00,013,842 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\atisgkaf.SYS -- (caboagp [Boot | Running])
[2007/02/17 02:31:14 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\clusdisk.sys -- (ClusDisk [Disabled | Stopped])
[2004/05/04 11:42:04 | 00,818,432 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmuda.sys -- (cmuda [On_Demand | Running])
[2007/02/17 02:34:58 | 00,017,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\crcdisk.sys -- (crcdisk [Boot | Running])
[2007/02/17 02:49:38 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\dfs.sys -- (DfsDriver [Boot | Running])
[2004/05/19 19:01:54 | 00,041,984 | ---- | M] (DeviceGuys, Inc.) -- C:\WINDOWS\system32\drivers\DgivEcp.sys -- (DgiVecp [Auto | Stopped])
[2004/03/23 12:05:36 | 00,045,568 | ---- | M] (VIA Networking Technologies, Inc. ) -- C:\WINDOWS\system32\drivers\getnd5b.sys -- (GETNDIS [On_Demand | Running])
[2008/12/25 04:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081225.002\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2008/12/25 04:00:00 | 00,876,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081225.002\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2003/07/17 03:10:06 | 00,007,040 | R--- | M] (VIA Networking Technologies, Inc. ) -- C:\WINDOWS\system32\ntsim.sys -- (NTSIM [On_Demand | Stopped])
[2007/02/17 03:54:52 | 00,020,480 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2004/02/09 15:43:56 | 00,301,200 | R--- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running])
[2004/02/09 15:43:56 | 00,037,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [Auto | Running])
[2007/02/17 06:24:02 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2004/03/04 23:46:46 | 00,082,832 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2004/06/11 18:28:08 | 00,016,280 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Stopped])
[2004/06/11 18:28:10 | 00,263,736 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [System | Running])
[2007/02/17 04:07:52 | 00,024,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\vgapnp.sys -- (vga [On_Demand | Stopped])
[2007/02/17 04:09:26 | 00,169,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wlbs.sys -- (WLBS [On_Demand | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=res://shdoclc.dll/hardAdmin.htm
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.yahoo.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=res://shdoclc.dll/hardAdmin.htm
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.yahoo.com/
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{1526D07D-733E-4877-A04B-79E88AE645C0} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{9F1AD5CF-7A06-4EBD-A1B7-D81ABCE2D872} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{8E718888-423F-11D2-876E-00A0C9082467}" (HKLM) -- C:\WINDOWS\system32\msdxm.ocx ()
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"=Ati2mdxx.exe (ATI Technologies, Inc.)
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
"MRT"="C:\WINDOWS\system32\MRT.exe" /R File not found
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tabelovako"=Rundll32.exe "C:\WINDOWS\system32\tegowupa.dll",s File not found
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tabelovako"=Rundll32.exe "C:\WINDOWS\system32\tegowupa.dll",s File not found
========== (O4) RunOnce Keys ==========
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe (Microsoft Corporation)
========== (O4) Startup Folders ==========
[2006/11/21 18:16:02 | 00,724,992 | ---- | M] (Intuit, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
[2002/12/17 17:23:32 | 00,074,308 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"ShowSuperHidden"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"disablecad"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- Reg Error: Key does not exist or could not be opened. File not found
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Sun Java Console] -> File not found
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> [Sun Java Console] -> File not found
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
2 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-4173798362-227457503-3234019532-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
2 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{166B1BCA-3F9C-11CF-8075-444553540000}: http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab -- Shockwave ActiveX Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab -- Java Plug-in 1.6.0_11
{9F1C11AA-197B-4942-BA54-47A8489BB47F}: http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38318.6522800926 -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{61E096E3-5DB6-46E4-9E6C-ED8ABB674314} (Servers: | Description: VIA Networking Velocity Family Giga-bit Ethernet Adapter)
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2004/11/27 18:27:56 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
cgesuald
2009-01-03, 15:12
========== Files/Folders - Created Within 30 Days ==========
[12 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/01/01 16:01:14 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2009/01/01 13:13:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/01/01 13:13:33 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/01 13:13:33 | 00,000,703 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/01 13:13:30 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/01 13:13:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/01 13:13:28 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/01 13:11:02 | 00,369,663 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/01/01 12:54:38 | 00,132,608 | ---- | C] () -- C:\WINDOWS\System32\eyxhut.dll
[2009/01/01 12:54:37 | 00,132,608 | ---- | C] () -- C:\WINDOWS\System32\swtlfwlc.dll
[2008/12/31 10:57:33 | 01,262,918 | -HS- | C] () -- C:\WINDOWS\System32\emadisem.ini
[2008/12/30 22:57:23 | 01,262,900 | -HS- | C] () -- C:\WINDOWS\System32\oseyulim.ini
[2008/12/30 10:57:07 | 01,262,893 | -HS- | C] () -- C:\WINDOWS\System32\emutitar.ini
[2008/12/27 13:21:24 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2008/12/25 23:11:40 | 00,001,374 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Security Configuration Wizard.lnk
[2008/12/25 23:11:40 | 00,000,099 | -HS- | C] () -- C:\Documents and Settings\All Users\Desktop\desktop.ini
[2008/12/25 23:09:25 | 00,138,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dpcdll.dll
[2008/12/25 23:09:25 | 00,138,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpcdll.dll
[2008/12/25 23:09:15 | 00,203,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\whsbrand.dll
[2008/12/25 23:09:15 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cd2chain.exe
[2008/12/25 23:09:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\adam
[2008/12/25 23:09:12 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ipmidrv.sys
[2008/12/25 23:09:12 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\uddisp.exe
[2008/12/25 23:09:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ipmi
[2008/12/25 23:09:10 | 00,130,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fltmgr.sys
[2008/12/25 23:09:10 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gagp30kx.sys
[2008/12/25 23:09:10 | 00,043,520 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\drivers\arc.sys
[2008/12/25 23:09:10 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\intelppm.sys
[2008/12/25 23:09:10 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ip6fw.sys
[2008/12/25 23:09:10 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mssmbios.sys
[2008/12/25 23:09:10 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\amdide.sys
[2008/12/25 23:09:09 | 00,479,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\audiodev.dll
[2008/12/25 23:09:09 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfscommonuifx.dll
[2008/12/25 23:09:09 | 00,152,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rdpwd.sys
[2008/12/25 23:09:09 | 00,122,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbvideo.sys
[2008/12/25 23:09:09 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nv_agp.sys
[2008/12/25 23:09:09 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\uliagpkx.sys
[2008/12/25 23:09:09 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\uagp35.sys
[2008/12/25 23:09:09 | 00,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismpx.sys
[2008/12/25 23:09:09 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccid.sys
[2008/12/25 23:09:09 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aelupsvc.dll
[2008/12/25 23:09:09 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wpdusb.sys
[2008/12/25 23:09:09 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmsetacl.dll
[2008/12/25 23:09:09 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023x.sys
[2008/12/25 23:09:09 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\auditusr.exe
[2008/12/25 23:09:09 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2008/12/25 23:09:09 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\azrlreg.exe
[2008/12/25 23:09:08 | 02,949,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dfsmgmt.dll
[2008/12/25 23:09:08 | 01,690,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d9.dll
[2008/12/25 23:09:08 | 00,720,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dfsobjectmodel.dll
[2008/12/25 23:09:08 | 00,040,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsroam.dll
[2008/12/25 23:09:08 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dimsntfy.dll
[2008/12/25 23:09:07 | 01,765,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxdiagn.dll
[2008/12/25 23:09:07 | 00,424,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[2008/12/25 23:09:07 | 00,163,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drmupgds.exe
[2008/12/25 23:09:07 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fsmsnap.dll
[2008/12/25 23:09:07 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\firewall.cpl
[2008/12/25 23:09:07 | 00,082,432 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2008/12/25 23:09:07 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fwcfg.dll
[2008/12/25 23:09:07 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fsmmsg.dll
[2008/12/25 23:09:07 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\extmgr.dll
[2008/12/25 23:09:07 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icacls.exe
[2008/12/25 23:09:07 | 00,038,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hbaapi.dll
[2008/12/25 23:09:07 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltmc.exe
[2008/12/25 23:09:07 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\encapi.dll
[2008/12/25 23:09:07 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltlib.dll
[2008/12/25 23:09:06 | 00,364,544 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\l3codecp.acm
[2008/12/25 23:09:06 | 00,289,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\r2brand.dll
[2008/12/25 23:09:06 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\microsoft.storage.vds.dll
[2008/12/25 23:09:06 | 00,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdadiag.dll
[2008/12/25 23:09:06 | 00,062,976 | ---- | C] () -- C:\WINDOWS\System32\mpeg2data.ax
[2008/12/25 23:09:06 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netset03.exe
[2008/12/25 23:09:06 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netsetup.cpl
[2008/12/25 23:09:06 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oobechk.exe
[2008/12/25 23:09:06 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntfrsutl.exe
[2008/12/25 23:09:06 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsmsno.dll
[2008/12/25 23:09:06 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsmsfi.dll
[2008/12/25 23:09:06 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdukx.dll
[2008/12/25 23:09:06 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdno1.dll
[2008/12/25 23:09:06 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdfi1.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpash.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnepr.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmlt48.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmlt47.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdiultn.dll
[2008/12/25 23:09:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbhc.dll
[2008/12/25 23:09:06 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmaori.dll
[2008/12/25 23:09:05 | 00,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmdrmdev.dll
[2008/12/25 23:09:05 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmdrmnet.dll
[2008/12/25 23:09:05 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\secoobe.dll
[2008/12/25 23:09:05 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uwdf.exe
[2008/12/25 23:09:05 | 00,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
[2008/12/25 23:09:05 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srmlib.dll
[2008/12/25 23:09:05 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax
[2008/12/25 23:09:05 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\verclsid.exe
[2008/12/25 23:09:05 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\setupn.exe
[2008/12/25 23:09:05 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfapi.dll
[2008/12/25 23:09:05 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\smbinst.exe
[2008/12/25 23:09:05 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tlsbln.exe
[2008/12/25 23:09:05 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winshfhc.dll
[2008/12/25 23:09:04 | 01,592,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpencen.dll
[2008/12/25 23:09:04 | 01,512,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmvadve.dll
[2008/12/25 23:09:04 | 01,215,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmvadvd.dll
[2008/12/25 23:09:04 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wssbrand.dll
[2008/12/25 23:09:04 | 00,331,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdmtpdr.dll
[2008/12/25 23:09:04 | 00,327,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdsp.dll
[2008/12/25 23:09:04 | 00,175,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpsrcwp.dll
[2008/12/25 23:09:04 | 00,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdmtp.dll
[2008/12/25 23:09:04 | 00,066,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdmtpus.dll
[2008/12/25 23:09:04 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdconns.dll
[2008/12/25 23:09:04 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpd_ci.dll
[2008/12/25 23:09:04 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wpdtrace.dll
[2008/12/25 23:09:03 | 02,897,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp2res.dll
[2008/12/25 23:09:03 | 01,041,920 | ---- | C] () -- C:\WINDOWS\adfs.msp
[2008/12/25 23:09:03 | 00,438,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpob2res.dll
[2008/12/25 23:09:03 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmlprov.dll
[2008/12/25 23:09:03 | 00,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmllite.dll
[2008/12/25 23:09:03 | 00,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xmlprovi.dll
[2008/12/25 23:09:03 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauserv.dll
[2008/12/25 23:09:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2008/12/25 23:09:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\adfs
[2008/12/25 23:08:54 | 00,000,000 | ---D | C] -- C:\Program Files\cmak
[2008/12/25 23:08:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\my music
[2008/12/25 23:08:53 | 00,000,000 | ---D | C] -- C:\WINDOWS\provisioning
[2008/12/25 23:05:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2008/12/25 23:05:48 | 00,041,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sainstall.dll
[2008/12/25 23:05:48 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rassfm.dll
[2008/12/25 23:05:15 | 01,053,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
[2008/12/25 23:05:14 | 00,200,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\activeds.dll
[2008/12/25 23:05:14 | 00,098,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\actxprxy.dll
[2008/12/25 23:05:12 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\adsldpc.dll
[2008/12/25 23:05:12 | 00,100,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\advpack.dll
[2008/12/25 23:05:11 | 00,148,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\apphelp.dll
[2008/12/25 23:05:10 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\authz.dll
[2008/12/25 23:05:10 | 00,052,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\basesrv.dll
[2008/12/25 23:05:10 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\audiosrv.dll
[2008/12/25 23:05:09 | 01,033,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browseui.dll
[2008/12/25 23:05:09 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browser.dll
[2008/12/25 23:05:09 | 00,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batmeter.dll
[2008/12/25 23:05:08 | 00,233,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\certcli.dll
[2008/12/25 23:05:07 | 00,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatq.dll
[2008/12/25 23:05:06 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clusapi.dll
[2008/12/25 23:05:06 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cnbjmon.dll
[2008/12/25 23:05:05 | 01,295,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsvcs.dll
[2008/12/25 23:05:05 | 00,797,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comres.dll
[2008/12/25 23:05:05 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe
[2008/12/25 23:05:04 | 00,595,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\crypt32.dll
[2008/12/25 23:05:04 | 00,506,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptui.dll
[2008/12/25 23:05:04 | 00,165,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\credui.dll
[2008/12/25 23:05:04 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptnet.dll
[2008/12/25 23:05:04 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptsvc.dll
[2008/12/25 23:05:04 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptdll.dll
[2008/12/25 23:05:03 | 00,326,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cscui.dll
[2008/12/25 23:05:03 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cscdll.dll
[2008/12/25 23:05:03 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\csrsrv.dll
[2008/12/25 23:05:02 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\davclnt.dll
[2008/12/25 23:05:01 | 00,164,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dfssvc.exe
[2008/12/25 23:04:59 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dnsapi.dll
[2008/12/25 23:04:59 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dnsrslvr.dll
[2008/12/25 23:04:59 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dmserver.dll
[2008/12/25 23:04:58 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drprov.dll
[2008/12/25 23:04:56 | 00,147,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dssenh.dll
[2008/12/25 23:04:55 | 01,044,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\esent.dll
[2008/12/25 23:04:55 | 00,238,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\es.dll
[2008/12/25 23:04:55 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ersvc.dll
[2008/12/25 23:04:54 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\eventlog.dll
[2008/12/25 23:04:52 | 00,546,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hhctrl.ocx
[2008/12/25 23:04:52 | 00,355,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hnetcfg.dll
[2008/12/25 23:04:51 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icaapi.dll
[2008/12/25 23:04:50 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\imm32.dll
[2008/12/25 23:04:50 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetpp.dll
[2008/12/25 23:04:49 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsecsvc.dll
[2008/12/25 23:04:49 | 00,095,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iphlpapi.dll
[2008/12/25 23:04:49 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\iprop.dll
[2008/12/25 23:04:47 | 00,350,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kerberos.dll
[2008/12/25 23:04:47 | 00,219,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kdcsvc.dll
[2008/12/25 23:04:47 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2008/12/25 23:04:46 | 01,037,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kernel32.dll
[2008/12/25 23:04:46 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\linkinfo.dll
[2008/12/25 23:04:45 | 00,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdminst.dll
[2008/12/25 23:04:44 | 01,163,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mfc42u.dll
[2008/12/25 23:04:44 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\midimap.dll
[2008/12/25 23:04:43 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\modemui.dll
[2008/12/25 23:04:43 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mpr.dll
[2008/12/25 23:04:42 | 00,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mprapi.dll
[2008/12/25 23:04:40 | 00,071,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msacm32.dll
[2008/12/25 23:04:40 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msasn1.dll
[2008/12/25 23:04:40 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msacm32.drv
[2008/12/25 23:04:39 | 00,468,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll
[2008/12/25 23:04:39 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdart.dll
[2008/12/25 23:04:39 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll
[2008/12/25 23:04:39 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtc.exe
[2008/12/25 23:04:38 | 01,019,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll
[2008/12/25 23:04:37 | 01,208,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msgina.dll
[2008/12/25 23:04:36 | 02,848,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msi.dll
[2008/12/25 23:04:36 | 00,884,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msimsg.dll
[2008/12/25 23:04:36 | 00,271,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msihnd.dll
[2008/12/25 23:04:36 | 00,078,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msiexec.exe
[2008/12/25 23:04:36 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msidle.dll
[2008/12/25 23:04:35 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msisip.dll
[2008/12/25 23:04:33 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstlsapi.dll
[2008/12/25 23:04:32 | 00,402,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp60.dll
[2008/12/25 23:04:32 | 00,348,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcrt.dll
[2008/12/25 23:04:32 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msv1_0.dll
[2008/12/25 23:04:31 | 01,131,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml3.dll
[2008/12/25 23:04:31 | 00,256,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mswsock.dll
[2008/12/25 23:04:31 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml3r.dll
[2008/12/25 23:04:30 | 00,111,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxoci.dll
[2008/12/25 23:04:30 | 00,079,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxclu.dll
[2008/12/25 23:04:30 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ncobjapi.dll
[2008/12/25 23:04:30 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nddeapi.dll
[2008/12/25 23:04:29 | 00,430,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netlogon.dll
[2008/12/25 23:04:29 | 00,345,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netapi32.dll
[2008/12/25 23:04:29 | 00,263,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netman.dll
[2008/12/25 23:04:28 | 01,809,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\netshell.dll
[2008/12/25 23:04:28 | 00,255,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\newdev.dll
[2008/12/25 23:04:27 | 01,522,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntdsa.dll
[2008/12/25 23:04:26 | 00,121,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntmarta.dll
[2008/12/25 23:04:26 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntdsapi.dll
[2008/12/25 23:04:26 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntlanman.dll
[2008/12/25 23:04:26 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntdsatq.dll
[2008/12/25 23:04:25 | 00,352,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oakley.dll
[2008/12/25 23:04:25 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbc32.dll
[2008/12/25 23:04:25 | 00,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntshrui.dll
[2008/12/25 23:04:25 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcbcp.dll
[2008/12/25 23:04:24 | 01,267,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ole32.dll
[2008/12/25 23:04:24 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbcint.dll
[2008/12/25 23:04:23 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oleacc.dll
[2008/12/25 23:04:23 | 00,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oledlg.dll
[2008/12/25 23:04:23 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\olecli32.dll
[2008/12/25 23:04:23 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\olethk32.dll
[2008/12/25 23:04:22 | 00,299,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pdh.dll
[2008/12/25 23:04:21 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfdisk.dll
[2008/12/25 23:04:21 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\perfos.dll
[2008/12/25 23:04:21 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\profmap.dll
[2008/12/25 23:04:21 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\powrprof.dll
[2008/12/25 23:04:21 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pjlmon.dll
[2008/12/25 23:04:20 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\psbase.dll
[2008/12/25 23:04:20 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pstorsvc.dll
[2008/12/25 23:04:20 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\psapi.dll
[2008/12/25 23:04:19 | 00,380,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgr.dll
[2008/12/25 23:04:19 | 00,122,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\raschap.dll
[2008/12/25 23:04:19 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rasadhlp.dll
[2008/12/25 23:04:18 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rastls.dll
[2008/12/25 23:04:18 | 00,104,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll
[2008/12/25 23:04:18 | 00,100,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpdd.dll
[2008/12/25 23:04:17 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regsvc.dll
[2008/12/25 23:04:17 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regapi.dll
[2008/12/25 23:04:16 | 00,642,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rpcrt4.dll
[2008/12/25 23:04:16 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rpcss.dll
[2008/12/25 23:04:16 | 00,443,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\riched20.dll
[2008/12/25 23:04:16 | 00,063,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\resutils.dll
[2008/12/25 23:04:15 | 00,213,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rsaenh.dll
[2008/12/25 23:04:15 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rundll32.exe
[2008/12/25 23:04:15 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rtutils.dll
[2008/12/25 23:04:14 | 00,334,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scesrv.dll
[2008/12/25 23:04:14 | 00,202,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\schedsvc.dll
[2008/12/25 23:04:14 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\scecli.dll
[2008/12/25 23:04:14 | 00,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\schannel.dll
[2008/12/25 23:04:13 | 00,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\secur32.dll
[2008/12/25 23:04:13 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sens.dll
[2008/12/25 23:04:13 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\seclogon.dll
[2008/12/25 23:04:13 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sensapi.dll
[2008/12/25 23:04:12 | 00,141,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sfc_os.dll
[2008/12/25 23:04:11 | 08,359,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shell32.dll
[2008/12/25 23:04:11 | 01,508,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shdocvw.dll
[2008/12/25 23:04:10 | 00,320,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shlwapi.dll
[2008/12/25 23:04:10 | 00,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shimeng.dll
[2008/12/25 23:04:10 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shfolder.dll
[2008/12/25 23:04:09 | 00,135,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shsvcs.dll
[2008/12/25 23:04:09 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\snmpapi.dll
[2008/12/25 23:04:08 | 00,180,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sqlunirl.dll
[2008/12/25 23:04:08 | 00,122,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stobject.dll
[2008/12/25 23:04:08 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spoolss.dll
[2008/12/25 23:04:08 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spoolsv.exe
[2008/12/25 23:04:07 | 00,762,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sxs.dll
[2008/12/25 23:04:07 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\svchost.exe
[2008/12/25 23:04:06 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tapi32.dll
[2008/12/25 23:04:06 | 00,168,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\taskmgr.exe
[2008/12/25 23:04:05 | 00,386,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\themeui.dll
[2008/12/25 23:04:05 | 00,245,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\termsrv.dll
[2008/12/25 23:04:05 | 00,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpmon.dll
[2008/12/25 23:04:04 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\umpnpmgr.dll
[2008/12/25 23:04:04 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\trkwks.dll
[2008/12/25 23:04:03 | 00,697,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\urlmon.dll
[2008/12/25 23:04:03 | 00,207,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\unimdm.tsp
[2008/12/25 23:04:03 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\unimdmat.dll
[2008/12/25 23:04:03 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2008/12/25 23:04:03 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uniplat.dll
[2008/12/25 23:04:02 | 00,206,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uxtheme.dll
[2008/12/25 23:04:02 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\utildll.dll
[2008/12/25 23:04:02 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbmon.dll
[2008/12/25 23:04:01 | 00,561,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vssapi.dll
[2008/12/25 23:04:01 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\version.dll
[2008/12/25 23:04:00 | 00,276,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\webcheck.dll
[2008/12/25 23:04:00 | 00,227,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\w32time.dll
[2008/12/25 23:04:00 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdigest.dll
[2008/12/25 23:04:00 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdmaud.drv
[2008/12/25 23:03:59 | 00,670,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wininet.dll
[2008/12/25 23:03:59 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiarpc.dll
[2008/12/25 23:03:58 | 00,528,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winlogon.exe
[2008/12/25 23:03:58 | 00,174,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winmm.dll
[2008/12/25 23:03:58 | 00,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winscard.dll
[2008/12/25 23:03:58 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winipsec.dll
[2008/12/25 23:03:58 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winrnr.dll
[2008/12/25 23:03:57 | 00,165,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wintrust.dll
[2008/12/25 23:03:57 | 00,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlbsctrl.dll
[2008/12/25 23:03:57 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winsta.dll
[2008/12/25 23:03:56 | 00,179,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wldap32.dll
[2008/12/25 23:03:56 | 00,096,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wlnotify.dll
[2008/12/25 23:03:54 | 00,285,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wow32.dll
[2008/12/25 23:03:53 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ws2_32.dll
[2008/12/25 23:03:53 | 00,044,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wsnmp32.dll
[2008/12/25 23:03:53 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshqos.dll
[2008/12/25 23:03:53 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ws2help.dll
[2008/12/25 23:03:53 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshtcpip.dll
[2008/12/25 23:03:52 | 00,489,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wzcsvc.dll
[2008/12/25 23:03:52 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wzcsapi.dll
[2008/12/25 23:03:52 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wtsapi32.dll
[2008/12/25 23:03:51 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll
[2008/12/25 22:58:30 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2008/12/25 22:58:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\PolicyBackup
[2008/12/25 19:05:15 | 00,000,940 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2008/12/25 19:05:07 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2008/12/25 19:05:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/25 18:59:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2008/12/19 21:22:20 | 00,000,326 | ---- | C] () -- C:\WINDOWS\tasks\ppijyerz.job
[2008/12/06 20:02:18 | 00,000,000 | ---D | C] -- C:\test
[2008/12/06 18:22:04 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2008/12/06 18:20:54 | 00,000,197 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/12/06 16:45:59 | 00,000,138 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Online Casino.url
[2008/12/06 16:45:59 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\My Videos
[2008/12/06 16:45:59 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\My Pictures
[2008/12/06 16:45:55 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\Administrator\Desktop\A0165C2C33FCC9C0
[2008/12/06 14:45:15 | 00,301,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winsrv.dll
[2008/12/06 14:45:15 | 00,301,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsrv.dll
[2008/12/06 14:45:10 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\gdi32.dll
[2008/12/06 14:45:10 | 00,282,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gdi32.dll
[2008/12/06 14:45:10 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mf3216.dll
[2008/12/06 14:45:09 | 01,845,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2008/12/06 14:45:09 | 01,845,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2008/12/06 14:45:09 | 00,583,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\user32.dll
[2008/12/06 14:45:09 | 00,583,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2008/12/06 14:43:37 | 02,469,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2008/12/06 14:43:37 | 02,430,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2008/12/06 14:43:36 | 02,280,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2008/12/06 14:43:35 | 02,321,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2008/12/06 14:42:53 | 00,812,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ws03res.dll
[2008/12/06 14:42:53 | 00,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\w03a2409.dll
[2008/12/06 14:42:53 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agentdpv.dll
[2008/12/06 14:40:51 | 00,031,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll.mui
[2008/12/06 14:40:51 | 00,023,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl.mui
[2008/12/06 14:40:51 | 00,023,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2008/12/06 14:40:51 | 00,018,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng.dll.mui
[2008/12/06 14:40:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2008/12/06 14:39:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2008/12/06 14:39:28 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2008/12/06 14:39:28 | 00,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2008/12/06 14:39:28 | 00,213,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl
[2008/12/06 14:39:28 | 00,202,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuweb.dll
[2008/12/06 14:39:28 | 00,194,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll
[2008/12/06 14:39:28 | 00,172,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe
[2008/12/06 14:39:28 | 00,043,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups2.dll
[2008/12/06 14:39:28 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
========== Files - Modified Within 30 Days ==========
[12 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/01/01 16:03:08 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/01/01 15:00:00 | 00,000,326 | ---- | M] () -- C:\WINDOWS\tasks\ppijyerz.job
[2009/01/01 14:21:13 | 00,471,728 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/01 14:21:13 | 00,405,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/01/01 14:21:13 | 00,059,050 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/01/01 14:17:01 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/01 14:16:58 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/01 14:09:40 | 00,006,456 | -H-- | M] () -- C:\WINDOWS\System32\kiwofiku
[2009/01/01 13:13:33 | 00,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/01 13:11:03 | 00,369,663 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/01/01 12:54:38 | 00,132,608 | ---- | M] () -- C:\WINDOWS\System32\swtlfwlc.dll
[2009/01/01 12:54:38 | 00,132,608 | ---- | M] () -- C:\WINDOWS\System32\eyxhut.dll
[2009/01/01 12:48:17 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/01 12:47:03 | 00,083,638 | -HS- | M] () -- C:\WINDOWS\System32\tepenune.dll
[2009/01/01 12:01:06 | 00,083,645 | -HS- | M] () -- C:\WINDOWS\System32\dasusuzo.dll
[2009/01/01 11:38:21 | 00,083,770 | -HS- | M] () -- C:\WINDOWS\System32\kijijuvu.dll
[2009/01/01 11:15:49 | 00,086,091 | -HS- | M] () -- C:\WINDOWS\System32\juzibogo.dll
[2008/12/31 16:28:58 | 01,262,918 | -HS- | M] () -- C:\WINDOWS\System32\emadisem.ini
[2008/12/30 22:57:28 | 01,262,900 | -HS- | M] () -- C:\WINDOWS\System32\oseyulim.ini
[2008/12/30 10:57:17 | 01,262,893 | -HS- | M] () -- C:\WINDOWS\System32\emutitar.ini
[2008/12/27 22:56:16 | 00,061,188 | -HS- | M] () -- C:\WINDOWS\System32\gusehuto.dll
[2008/12/27 13:21:26 | 00,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2008/12/25 23:35:25 | 00,000,084 | -HS- | M] () -- C:\Documents and Settings\Administrator\My Documents\desktop.ini
[2008/12/25 23:33:03 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2008/12/25 23:30:40 | 00,097,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/25 23:11:40 | 00,001,374 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Security Configuration Wizard.lnk
[2008/12/25 23:11:40 | 00,000,099 | -HS- | M] () -- C:\Documents and Settings\All Users\Desktop\desktop.ini
[2008/12/25 23:09:58 | 00,000,208 | RHS- | M] () -- C:\boot.ini
[2008/12/25 23:03:28 | 00,297,072 | RHS- | M] () -- C:\ntldr
[2008/12/25 23:03:28 | 00,047,772 | RHS- | M] () -- C:\NTDETECT.COM
[2008/12/25 19:51:05 | 00,000,153 | ---- | M] () -- C:\WINDOWS\Wininit.ini
[2008/12/25 19:05:15 | 00,000,940 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2008/12/23 12:06:28 | 00,062,255 | -HS- | M] () -- C:\WINDOWS\System32\hituyake.dll
[2008/12/20 18:23:00 | 06,933,964 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2008/12/06 18:21:58 | 00,003,423 | ---- | M] () -- C:\WINDOWS\imsins.BAK