MalwareBytes Log
Malwarebytes' Anti-Malware 1.29
Database version: 1300
Windows 5.1.2600 Service Pack 2
10/21/2008 10:35:26 PM
mbam-log-2008-10-21 (22-35-21).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 255301
Time elapsed: 1 hour(s), 33 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\7ADC2AB1.dll (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\system32\HBmhly.dll (Spyware.OnlineGames) -> No action taken.
Registry Keys Infected:
HKEY_CLASSES_ROOT\thunderadvise.thunderhlpobj (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{6d4c7e08-e021-414c-a42d-ab15a2302196} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{deef6582-9927-4cbd-897c-6a1f9e8c47de} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{97421d0d-e07f-40df-8f07-99597b9585ad} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97421d0d-e07f-40df-8f07-99597b9585ad} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\thunderadvise.thunderhlpobj.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7adc2ab1-5c6a-4178-82da-94863354af7c} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{da191de0-aa86-4ed0-4b87-293d48b2ae99} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hbkernel32 (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\hbkernel32 (Backdoor.Bot) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hbkernel32 (Backdoor.Bot) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{7adc2ab1-5c6a-4178-82da-94863354af7c} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\msnmsg (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\HBService32 (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll (Trojan.BHO) -> No action taken.
C:\WINDOWS\system32\7ADC2AB1.dll (Spyware.OnlineGames) -> No action taken.
C:\Program Files\Messenger\msgmr.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temp\24.cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\8EDV4ZAG\19[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\8EDV4ZAG\24[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\A6HXBV76\18[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\A6HXBV76\23[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\FVTWQWL2\02[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\FVTWQWL2\17[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\FVTWQWL2\20[1].cab (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\Deepak\Local Settings\Temporary Internet Files\Content.IE5\FVTWQWL2\21[1].cab (Spyware.OnlineGames) -> No action taken.
D:\fdrive\Warez\Goldfish_Aquarium\patch.exe (Trojan.Downloader) -> No action taken.
D:\fdrive\Warez\Goldfish_Aquarium\Goldfish_Aquarium\patch.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\System.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\HBKernel32.sys (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\HBmhly.dll (Spyware.OnlineGames) -> No action taken.
RSIT Log
Logfile of random's system information tool 1.04 (written by random/random)
Run by Deepak at 2002-01-01 20:44:44
Microsoft Windows XP Professional Service Pack 2
System drive C: has 17 GB (87%) free of 20 GB
Total RAM: 503 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:24 PM, on 1/1/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ping.exe
C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Deepak\Desktop\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Deepak\Desktop\Deepak.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O1 - Hosts: 127.1 localhost
O1 - Hosts: 127.1 fffff8888fsgfbghj88.cn
O1 - Hosts: 127.1 61.134.37.12
O1 - Hosts: 127.1 ko.ssa387.cn
O1 - Hosts: 127.1
www.ndxrr.cn
O1 - Hosts: 127.1 12345.ssa387.cn
O1 - Hosts: 127.1 lihai88.com
O1 - Hosts: 127.1 wwwwhf.cn
O1 - Hosts: 127.1 a89369093.sq.u9idc.com
O1 - Hosts: 127.1
www.mmd178.cn
O1 - Hosts: 127.1
www.178mmd.cn
O1 - Hosts: 127.1
www.wenzhuoyyy.cn
O1 - Hosts: 127.1 tw.lovechina.tw.cn
O1 - Hosts: 127.1 222.189.238.151
O1 - Hosts: 127.1 222.179.185.78
O1 - Hosts: 127.1
www.wq9q.cn
O1 - Hosts: 127.1 593ffcey.cn
O1 - Hosts: 127.1 set.yay520.cn
O1 - Hosts: 127.1 tenmoc999.cn
O1 - Hosts: 127.1 lihai88.com
O1 - Hosts: 127.1 121.kcuf-01.com
O1 - Hosts: 127.1
www.ew1q.cn
O1 - Hosts: 127.1
www.b3sk.cn
O1 - Hosts: 127.1 up.bizmd.cn
O1 - Hosts: 127.1
www.ms2a.cn
O1 - Hosts: 127.1
www.wo9188.cn
O1 - Hosts: 127.1
www.fgetchr.cn
O1 - Hosts: 127.1
www.e6zx.cn
O1 - Hosts: 127.1 hai067.com
O1 - Hosts: 127.1 hai088.com
O1 - Hosts: 127.1 778899.jd8j.cn
O1 - Hosts: 127.1 sql.78-11.net
O1 - Hosts: 127.1
www.bbbirdy.com
O1 - Hosts: 127.1
www.s1na1.com.cn
O1 - Hosts: 127.1
www.dianyinjzd.cn
O1 - Hosts: 127.1
www.dj5201314dj.com
O1 - Hosts: 127.1 max-2.cn
O1 - Hosts: 127.1 a.asp-o.cn
O1 - Hosts: 127.1 b.asp-o.cn
O1 - Hosts: 127.1 c.asp-o.cn
O1 - Hosts: 127.1 x.kprobb.cn
O1 - Hosts: 127.1 js.php-k.cn
O1 - Hosts: 127.1 max-1.cn
O1 - Hosts: 127.1 max-3.cn
O1 - Hosts: 127.1 max-4.cn
O1 - Hosts: 127.1 max-5.cn
O1 - Hosts: 127.1 max-6.cn
O1 - Hosts: 127.1 max-7.cn
O1 - Hosts: 127.1 max-8.cn
O1 - Hosts: 127.1 max-9.cn
O1 - Hosts: 127.1 max-10.cn
O1 - Hosts: 127.1 max-11.cn
O1 - Hosts: 127.1 max-12.cn
O1 - Hosts: 127.1 twocannon250.com.cn
O1 - Hosts: 127.1
www.133mm.cn
O1 - Hosts: 127.1
www.51vmm.cn
O1 - Hosts: 127.1
www.7mmoo.cn
O1 - Hosts: 127.1
www.99mmm.org.cn
O1 - Hosts: 127.1
www.hdec.cn
O1 - Hosts: 127.1
www.picc18.com
O1 - Hosts: 127.1
www.kissdh.com
O1 - Hosts: 127.1
www.x7v.cn
O1 - Hosts: 127.1 biqulu.cn
O1 - Hosts: 127.1 2008.qq2006.com.cn
O1 - Hosts: 127.1 giaitrisex.com
O1 - Hosts: 127.1
www.giaitrisex.com
O1 - Hosts: 127.1
www.giaitrituoitre.net
O1 - Hosts: 127.1 mekiep.com
O1 - Hosts: 127.1
www.1sex1day.com
O1 - Hosts: 127.1 a.9ymm.com
O1 - Hosts: 127.1 bobo.7wyt.com
O1 - Hosts: 127.1
www.591caobi.cn
O1 - Hosts: 127.1
www.hrz008.cn
O1 - Hosts: 127.1 asp-15.cn
O1 - Hosts: 127.1 asp-12.cn
O1 - Hosts: 127.1
www.jb88.net
O1 - Hosts: 127.1 6.a88a.com
O1 - Hosts: 127.1 w.b2c3.cn
O1 - Hosts: 127.1 m.c5x8.com
O1 - Hosts: 127.1
www.518sfw.cn
O1 - Hosts: 127.1
www.jjyyzmj.cn
O1 - Hosts: 127.1 u.cnmrx.net
O1 - Hosts: 127.1 duowan.czm.cn
O1 - Hosts: 127.1 xccxcxcxcxcx.cn
O1 - Hosts: 127.1 google-yahoo.org.cn
O1 - Hosts: 127.1 tudou-net.org.cn
O1 - Hosts: 127.1 downloads.zango.com
O1 - Hosts: 127.1 ftp.surfnet.nl
O1 - Hosts: 127.1 bis.180solutions.com
O1 - Hosts: 127.1 installs.hotbar.com
O1 - Hosts: 127.1
www.hbdownloads.com
O1 - Hosts: 127.1 static.zangocash.com
O1 - Hosts: 127.1
www.qq-songli.cn
O1 - Hosts: 127.1 aa.9234.net
O1 - Hosts: 127.1
www.97love.info
O1 - Hosts: 127.1 97love.info
O1 - Hosts: 127.1
www.zyzhuiku.cn
O1 - Hosts: 127.1 zyzhuiku.cn
O1 - Hosts: 127.1
www.lang18.com
O1 - Hosts: 127.1 lang18.com
O1 - Hosts: 127.1 sao6666.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [HBService32] System.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - Global Startup: 24Online Client.lnk = C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D56A5525-6B17-4A95-A765-E6FB5EFF99B9}: NameServer = 172.16.0.1
O20 - AppInit_DLLs: HBmhly.dll,HB1000Y.dll,HBWOOOL.dll,HBXY2.dll,HBJXSJ.dll,HBSO2.dll,HBFS2.dll,HBXY3.dll,HBSHQ.dll,HBFY.dll,HBWULIN2.dll,HBW2I.dll,HBKDXY.dll,HBWORLD2.dll,HBASKTAO.dll,HBZHUXIAN.dll,HBWOW.dll,HBZERO.dll,HBBO.dll,HBCONQUER.dll,HBSOUL.dll,HBCHIBI.dll,HBDNF.dll,HBWARLORDS.dll,HBTL.dll,HBPICKCHINA.dll,HBCT.dll,HBGC.dll,HBHM.dll,HBHX2.dll,HBQQHX.dll,HBTW2.dll,HBQQSG.dll,HBQQFFO.dll,HBZT.dll,HBMIR2.dll,HBRXJH.dll,HBYY.dll,HBMXD.dll,HBSQ.dll,HBTJ.dll,HBFHZL.dll,HBWLQX.dll,HBLYFX.dll,HBR2.dll,HBCHD.dll,HBTZ.dll,HBQQXX.dll,HBWD.dll,HBZG.dll,HBPPBL.dll,HBXMJ.dll,HBJTLQ.dll,HBQJSJ.dll
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
O21 - SSODL: Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll
--
End of file - 6792 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97421D0D-E07F-40DF-8F07-99597B9585AD}]
ThunderHlpObj Class - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll [2008-10-21 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HBService32"=C:\WINDOWS\system32\SYSTEM.EXE [2008-10-21 3572]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe [2005-05-23 3031040]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
24Online Client.lnk - C:\Program Files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="HBmhly.dll,HB1000Y.dll,HBWOOOL.dll,HBXY2.dll,HBJXSJ.dll,HBSO2.dll,HBFS2.dll,HBXY3.dll,HBSHQ.dll,HBFY.dll,HBWULIN2.dll,HBW2I.dll,HBKDXY.dll,HBWORLD2.dll,HBASKTAO.dll,HBZHUXIAN.dll,HBWOW.dll,HBZERO.dll,HBBO.dll,HBCONQUER.dll,HBSOUL.dll,HBCHIBI.dll,HBDNF.dll,HBWARLORDS.dll,HBTL.dll,HBPICKCHINA.dll,HBCT.dll,HBGC.dll,HBHM.dll,HBHX2.dll,HBQQHX.dll,HBTW2.dll,HBQQSG.dll,HBQQFFO.dll,HBZT.dll,HBMIR2.dll,HBRXJH.dll,HBYY.dll,HBMXD.dll,HBSQ.dll,HBTJ.dll,HBFHZL.dll,HBWLQX.dll,HBLYFX.dll,HBR2.dll,HBCHD.dll,HBTZ.dll,HBQQXX.dll,HBWD.dll,HBZG.dll,HBPPBL.dll,HBXMJ.dll,HBJTLQ.dll,HBQJSJ.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll [2008-10-21 15872]
Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll [2004-08-04 20480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{DE02F764-C51A-4788-9597-D78ECC2AC08F}"=C:\WINDOWS\system32\DE02F764.dll [2008-10-21 217178]
"{43ACDCC5-9009-4AF4-B80A-93BC656EF298}"=C:\WINDOWS\system32\43ACDCC5.dll [2008-10-21 13419]
"{58FF3024-8A83-4B1A-88E9-302F47646EEE}"=C:\WINDOWS\system32\58FF3024.dll [2008-10-21 12972]
"{D91BC61E-7D78-4A2A-A336-7B97E8E52F0B}"=C:\WINDOWS\system32\D91BC61E.dll [2008-10-21 12005]
"{82710040-F86E-42E0-B1F8-04EDF75856F8}"=C:\WINDOWS\system32\82710040.dll [2008-10-21 11379]
"{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426}"=C:\WINDOWS\system32\4D023DE9.dll [2008-10-21 11698]
"{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}"=C:\WINDOWS\system32\08223B03.dll [2008-10-21 12213]
"{7ADC2AB1-5C6A-4178-82DA-94863354AF7C}"=C:\WINDOWS\system32\7ADC2AB1.dll [2008-10-21 11261]
"{DA63E650-537C-4042-87BB-9D19D844680B}"=C:\WINDOWS\system32\DA63E650.dll [2008-10-21 12770]
"{C250CF20-5F89-4310-9854-4BC261FB14FB}"=C:\WINDOWS\system32\C250CF20.dll [2008-10-21 11657]
"{9CA963CA-107C-4089-B0AB-31380F90D7E3}"=C:\WINDOWS\system32\9CA963CA.dll [2008-10-21 11951]
"{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}"=C:\WINDOWS\system32\122B901E.dll [2008-10-21 12532]
"{495271CA-D0C6-4052-ABE6-5B01C73CDFB0}"=C:\WINDOWS\system32\495271CA.dll [2008-10-21 11971]
"{4F34C688-FD49-42FC-97F7-87D2F5791612}"=C:\WINDOWS\system32\4F34C688.dll [2008-10-21 11717]
"{C56BCC10-503E-43AB-B208-3CD37FCFCE40}"=C:\WINDOWS\system32\C56BCC10.dll [2008-10-21 216485]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9eb7e5a9-fef4-11d5-a6c0-806d6172696f}]
shell\AutoRun\command - E:\ASUSACPI.exe
======List of files/folders created in the last 1 months======
2008-10-22 00:35:59 ----SHD---- C:\RECYCLER
2008-10-21 22:49:51 ----D---- C:\rsit
2008-10-21 19:38:21 ----A---- C:\WINDOWS\system32\HBSO2.dll
2008-10-21 19:37:55 ----D---- C:\WINDOWS\Minidump
2008-10-21 19:08:17 ----D---- C:\Documents and Settings\Deepak\Application Data\Malwarebytes
2008-10-21 19:08:12 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-21 19:08:11 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-21 19:05:36 ----ASH---- C:\WINDOWS\system32\4BF9CBA3.dll
2008-10-21 19:05:26 ----ASH---- C:\WINDOWS\system32\C56BCC10.dll
2008-10-21 19:05:21 ----ASH---- C:\WINDOWS\system32\4F34C688.dll
2008-10-21 18:52:10 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-21 18:49:32 ----A---- C:\WINDOWS\system32\HBZG.dll
2008-10-21 18:49:28 ----A---- C:\WINDOWS\system32\HBZHUXIAN.dll
2008-10-21 18:49:22 ----A---- C:\WINDOWS\system32\HBBO.dll
2008-10-21 18:49:20 ----A---- C:\WINDOWS\system32\HBCHIBI.dll
2008-10-21 18:49:19 ----A---- C:\WINDOWS\system32\System.exe
2008-10-21 18:49:19 ----A---- C:\WINDOWS\system32\HBQQSG.dll
2008-10-21 18:49:12 ----ASH---- C:\WINDOWS\system32\495271CA.dll
2008-10-21 18:49:05 ----ASH---- C:\WINDOWS\system32\122B901E.dll
2008-10-21 18:48:57 ----ASH---- C:\WINDOWS\system32\9CA963CA.dll
2008-10-21 18:48:50 ----ASH---- C:\WINDOWS\system32\C250CF20.dll
2008-10-21 18:48:42 ----ASH---- C:\WINDOWS\system32\DA63E650.dll
2008-10-21 18:48:36 ----ASH---- C:\WINDOWS\system32\7ADC2AB1.dll
2008-10-21 18:48:27 ----ASH---- C:\WINDOWS\system32\08223B03.dll
2008-10-21 18:48:19 ----ASH---- C:\WINDOWS\system32\4D023DE9.dll
2008-10-21 18:48:10 ----ASH---- C:\WINDOWS\system32\82710040.dll
2008-10-21 18:48:03 ----ASH---- C:\WINDOWS\system32\D91BC61E.dll
2008-10-21 18:47:55 ----ASH---- C:\WINDOWS\system32\58FF3024.dll
2008-10-21 18:47:47 ----ASH---- C:\WINDOWS\system32\43ACDCC5.dll
2008-10-21 18:47:38 ----ASH---- C:\WINDOWS\system32\DE02F764.dll
2008-10-21 18:47:35 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-21 18:47:33 ----A---- C:\WINDOWS\system32\HBmhly.dll
2008-10-21 18:47:28 ----A---- C:\WINDOWS\Update.dll
2008-10-21 18:42:57 ----D---- C:\Program Files\WinRAR
2005-09-23 07:28:56 ----A---- C:\WINDOWS\system32\netfxperf.dll
2005-09-23 07:28:52 ----A---- C:\WINDOWS\system32\mscories.dll
2005-09-23 07:28:52 ----A---- C:\WINDOWS\system32\mscorier.dll
2005-09-23 07:28:52 ----A---- C:\WINDOWS\system32\mscoree.dll
2005-09-23 07:28:38 ----A---- C:\WINDOWS\system32\dfshim.dll
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wupdmgr.exe
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wshnetbs.dll
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wshisn.dll
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wshatm.dll
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wowexec.exe
2004-10-13 23:39:36 ----A---- C:\WINDOWS\system32\wowdeb.exe
2004-10-13 23:39:34 ----A---- C:\WINDOWS\winhelp.exe
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\wmiscmgr.dll
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\wmiprop.dll
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\wmerrenu.dll
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winstrm.dll
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winspool.exe
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winsock.dll
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winmsd.exe
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winhlp32.exe
2004-10-13 23:39:34 ----A---- C:\WINDOWS\system32\winfax.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\win.ini
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\win87em.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\win.com
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\wifeman.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\wiavusd.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\webhits.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\wavemsp.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\w32topl.dll
2004-10-13 23:39:32 ----A---- C:\WINDOWS\system32\w32tm.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\vmmreg32.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\twunk_32.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\twunk_16.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\twain.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vwipxspx.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vwipxspx.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vssadmin.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vss_ps.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vjoy.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vga64k.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vga256.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vga.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vfpodbc.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\verifier.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\verifier.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\ver.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\vcdex.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\utildll.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\user.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\ureg.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\unlodctr.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\umdmxfrm.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\ufat.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\typeperf.exe
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\typelib.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\tsd32.dll
2004-10-13 23:39:30 ----A---- C:\WINDOWS\system32\tsappcmp.dll
2004-10-13 23:39:28 ----A---- C:\WINDOWS\system32\tree.com
2004-10-13 23:39:28 ----A---- C:\WINDOWS\system32\traffic.dll
2004-10-13 23:39:28 ----A---- C:\WINDOWS\system32\tracert6.exe
2004-10-13 23:39:28 ----A---- C:\WINDOWS\system32\toolhelp.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tftp.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tcpsvcs.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tcmsetup.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\taskman.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tasklist.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\taskkill.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tapiui.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tapiperf.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\tapi.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\systray.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\systeminfo.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\syskey.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\sysinv.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\sysedit.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\syncapp.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\swprv.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\svcpack.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\subst.exe
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system32\storage.dll
2004-10-13 23:39:26 ----A---- C:\WINDOWS\system.ini
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\sqlwoa.dll
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\sqlwid.dll
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\sprestrt.exe
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\sort.exe
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\softpub.dll
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\slbrccsp.dll
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\skdll.dll
2004-10-13 23:39:24 ----A---- C:\WINDOWS\system32\sisbkup.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\shell.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\share.exe
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\sfmapi.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\sfc.exe
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\setver.exe
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\setupdll.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\serwvdrv.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\services.msc
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\serialui.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\senscfg.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\secpol.msc
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\sdpblb.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\scriptpw.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\scredir.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\scardssp.dll
2004-10-13 23:39:22 ----A---- C:\WINDOWS\system32\sc.exe
2004-10-13 23:39:20 ----R---- C:\WINDOWS\system32\rsop.msc
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\runas.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rtm.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsvpsp.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsvpperf.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsvpmsg.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsvp.ini
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsvp.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsopprov.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsmui.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsmsink.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsm.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rsfsaps.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rpcns4.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\routetab.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\routemon.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\route.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rnr20.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\riched32.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\replace.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rend.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\relog.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\regwiz.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\regedt32.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\recover.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasser.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasrad.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasmxs.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasmontr.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasdial.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasctrs.ini
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasctrs.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\rasautou.exe
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\qosname.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\pubprn.vbs
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\psnppagn.dll
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\pschdprf.ini
2004-10-13 23:39:20 ----A---- C:\WINDOWS\system32\pschdprf.dll
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prodspec.ini
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prnqctl.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prnport.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prnmngr.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prnjobs.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prndrvr.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prncnfg.vbs
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\print.exe
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\prflbmsg.dll
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\pmspl.dll
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\plustab.dll
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\ping6.exe
2004-10-13 23:39:18 ----A---- C:\WINDOWS\system32\pifmgr.dll
2004-10-13 23:39:16 ----R---- C:\WINDOWS\system32\perfmon.msc
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perfwci.ini
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perfts.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perfnw.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perfnet.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perffilt.ini
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\perfci.ini
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\pentnt.exe
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\pathping.exe
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\panmap.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\pagefileconfig.vbs
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\osuninst.exe
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olethk32.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olesvr32.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olesvr.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\oledlg.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olecnv32.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olecli32.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\olecli.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\oleaccrc.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\oleacc.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\ole2nls.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\ole2disp.dll
2004-10-13 23:39:16 ----A---- C:\WINDOWS\system32\ole2.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ocmanage.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nwscript.exe
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nwevent.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nwcfg.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nwapi32.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nwapi16.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\nw16.exe
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntvdmd.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntsdexts.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntsd.exe
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntmsoprq.msc
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntmsmgr.msc
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntmsevt.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntlanui2.dll
2004-10-13 23:39:14 ----A---- C:\WINDOWS\system32\ntlanui.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\ntdsbcli.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\nlsfunc.exe
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\netui2.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\netmsg.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\neth.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\netevent.dll
2004-10-13 23:39:12 ----A---- C:\WINDOWS\system32\netapi.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\ncxpnt.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\nbtstat.exe
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\narrhook.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\mycomput.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msxmlr.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msxml3r.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msxml2r.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msvideo.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msvidc32.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msvcrt20.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msvcp50.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msvbvm50.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msswchx.exe
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\msswch.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\mssip32.dll
2004-10-13 23:39:10 ----A---- C:\WINDOWS\system32\mssign32.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msrecr40.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msrclr40.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msratelc.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msr2cenu.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msr2c.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msports.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msobjs.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msls31.dll
2004-10-13 23:39:08 ----A---- C:\WINDOWS\system32\msidntld.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\msencode.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mscdexnt.exe
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mscat32.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\msaudite.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\msacm.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\msaatext.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mrinfo.exe
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mqperf.ini
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mqperf.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mqgentr.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mqcertui.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mprui.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mprmsg.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mprdim.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mprddm.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mpnotify.exe
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\mountvol.exe
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\more.com
2004-10-13 23:39:06 ----A---- C:\WINDOWS\system32\modex.dll
2004-10-13 23:39:06 ----A---- C:\WINDOWS\msdfmap.ini
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mode.com
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mmutilse.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mmdrv.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mll_qic.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mll_mtf.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mll_hp.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mimefilt.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\migpwd.exe
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mfc40u.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mfc40.dll
2004-10-13 23:39:04 ----A---- C:\WINDOWS\system32\mem.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mdhcp.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mciole32.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mciole16.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mcicda.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mchgrcoi.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mcdsrv32.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mcd32.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mapistub.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\mag_hook.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lzexpand.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lz32.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lusrmgr.msc
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lprmonui.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lpr.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lpq.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\loghours.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lodctr.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\loadfix.com
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lnkstub.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\lights.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\langwrbk.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\label.exe
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kdcom.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdusx.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdusr.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdusl.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdus.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbduk.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdsw.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdsp.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdsg.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdsf.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdpo.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdno.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdnec.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdne.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdmac.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdla.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdit142.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdit.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdir.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdic.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdgr1.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdgr.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdgae.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdfr.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdfo.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdfi.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdfc.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdes.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbddv.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdda.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdcan.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdca.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdbr.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdbene.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kbdbe.dll
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\kb16.com
2004-10-13 23:39:02 ----A---- C:\WINDOWS\system32\jobexec.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgsh400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgsd400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgpl400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgmd400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgdw400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jgaw400.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\jet500.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ir32_32.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxwan.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxsap.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxrtmgr.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxrip.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxpromn.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipxmontr.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipsec6.exe
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\iprtprio.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\iprop.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\ipmontr.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\iologmsg.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\infosoft.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\inetcplc.dll
2004-10-13 23:39:00 ----A---- C:\WINDOWS\system32\iissuba.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\ifsutil.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\ieakui.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\icmui.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iassvcs.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iassdo.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iassam.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iasrecst.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iaspolcy.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iasnap.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iashlpr.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iasads.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\iasacct.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\hostname.exe
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\hnetmon.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\hlink.dll
2004-10-13 23:38:58 ----A---- C:\WINDOWS\system32\help.exe
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\graphics.com
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\graftabl.com
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\gpupdate.exe
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\gpedit.msc
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\glmf32.dll
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\getmac.exe
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\gdi.exe
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\gcdef.dll
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\ftsrch.dll
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\fsutil.exe
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\fsusd.dll
2004-10-13 23:38:56 ----A---- C:\WINDOWS\system32\fsmgmt.msc
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\format.com
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\forcedos.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fontsub.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fmifs.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fixmapi.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\finger.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\find.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fde.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fc.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\fastopen.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\exts.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\expand.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\exe2bin.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eventvwr.msc
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eventvwr.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eventquery.vbs
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eventcls.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\eula.txt
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\esentutl.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\esentprf.ini
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\esentprf.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\esent97.dll
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\edlin.exe
2004-10-13 23:38:54 ----A---- C:\WINDOWS\system32\edit.com
2004-10-13 23:38:52 ----A---- C:\WINDOWS\system32\dskquoui.dll
2004-10-13 23:38:52 ----A---- C:\WINDOWS\system32\dsauth.dll
2004-10-13 23:38:52 ----A---- C:\WINDOWS\system32\drwtsn32.exe
2004-10-13 23:38:52 ----A---- C:\WINDOWS\system32\drwatson.exe
2004-10-13 23:38:52 ----A---- C:\WINDOWS\system32\driverquery.exe
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dpwsock.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dpserial.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dpnwsock.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dpnmodem.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dplay.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\doskey.exe
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\docprop.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dmocx.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dmintf.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dmdskres.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dmdlgs.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dmconfig.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dllhst3g.exe
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dispex.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diskperf.exe
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diskmgmt.msc
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diskcopy.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diskcopy.com
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diskcomp.com
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dimap.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\diactfrm.dll
2004-10-13 23:38:44 ----A---- C:\WINDOWS\system32\dhcpsapi.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\dhcpmon.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\dfrgres.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\dfrg.msc
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\devmgmt.msc
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\deskperf.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\deskmon.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\deskadp.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\debug.exe
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\ddeml.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\dbgeng.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\datime.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\d3dxof.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\d3drm.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\d3dramp.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\d3dpmesh.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\d3dim.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\ctl3dv2.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\ctl3d32.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\csseqchk.dll
2004-10-13 23:38:42 ----A---- C:\WINDOWS\system32\crtdll.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\convert.exe
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\control.exe
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\console.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\confmsp.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\compobj.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\compmgmt.msc
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\compact.exe
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\comp.exe
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\commdlg.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\command.com
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\comcat.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\cnvfat.dll
2004-10-13 23:38:40 ----A---- C:\WINDOWS\system32\cnetcfg.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\shellstyle.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\cmpbk32.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\clb.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\ckcnv.exe
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\cidaemon.exe
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\cic.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\ciadv.msc
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\ciadmin.dll
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\chkntfs.exe
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\chkdsk.exe
2004-10-13 23:38:38 ----A---- C:\WINDOWS\system32\chcp.com
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\certmgr.msc
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\ccfgnt.dll
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\cards.dll
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\capesnpn.dll
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\cacls.exe
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\bootvrfy.exe
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\bootvid.dll
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\bootok.exe
2004-10-13 23:38:36 ----A---- C:\WINDOWS\system32\bootcfg.exe
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\avifile.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\avicap32.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\avicap.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\autodisc.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\attrib.exe
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\atmpvcno.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\atkctrs.dll
2004-10-13 23:38:34 ----A---- C:\WINDOWS\system32\asr_ldm.exe
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\arp.exe
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\append.exe
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\apcups.dll
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\adsnw.dll
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\adsnds.dll
2004-10-13 23:38:32 ----A---- C:\WINDOWS\system32\adptif.dll
2004-10-13 23:38:30 ----A---- C:\WINDOWS\system32\acledit.dll
2004-10-13 23:38:30 ----A---- C:\WINDOWS\system32\aaaamon.dll
2004-08-04 06:32:46 ----A---- C:\WINDOWS\system32\netsetup.exe
2004-08-04 06:31:08 ----A---- C:\WINDOWS\system32\tsddd.dll
2004-08-04 06:31:08 ----A---- C:\WINDOWS\system32\rdpdd.dll
2004-08-04 06:27:06 ----A---- C:\WINDOWS\system32\drmclien.dll
2004-08-04 06:27:04 ----A---- C:\WINDOWS\system32\wmvcore.dll
2004-08-04 06:27:04 ----A---- C:\WINDOWS\system32\drmv2clt.dll
2004-08-04 06:27:02 ----A---- C:\WINDOWS\system32\msscp.dll
2004-08-04 06:27:02 ----A---- C:\WINDOWS\system32\msnetobj.dll
2004-08-04 06:26:58 ----A---- C:\WINDOWS\winhlp32.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\xcopy.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wscript.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wscntfy.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wpabaln.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\winver.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\winlogon.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\wextract.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\vssvc.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\utilman.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\userinit.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\ups.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\upnpcont.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tracert.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tracerpt.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tourstart.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tlntsess.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\telnet.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\taskmgr.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\svchost.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\stimon.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\spoolsv.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\spnpinst.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\smss.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\smbinst.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\skeys.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\sigverif.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\shutdown.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\shrpubw.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\shmgrate.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\setup.exe
2004-08-04 06:26:58 ----A---- C:\WINDOWS\system32\sethc.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\services.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\secedit.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\sdbinst.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\schtasks.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\scardsvr.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\savedump.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\runonce.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rundll32.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rtcshare.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rsnotify.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rsh.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rexec.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\regsvr32.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\reg.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rcp.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rcimlby.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\rasphone.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\proxycfg.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\proquota.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\progman.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\powercfg.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\ping.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\perfmon.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\packager.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\osk.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\openfiles.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\odbcconf.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\odbcad32.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\ntvdm.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\ntbackup.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\nslookup.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\notepad.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\netstat.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\netsh.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\netdde.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\net1.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\net.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\nddeapir.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\system32\narrator.exe
2004-08-04 06:26:56 ----A---- C:\WINDOWS\regedit.exe
2004-08-04 06:26:54 ----A---- C:\WINDOWS\system32\msiexec.exe
2004-08-04 06:26:54 ----A---- C:\WINDOWS\system32\mshta.exe
2004-08-04 06:26:54 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2004-08-04 06:26:54 ----A---- C:\WINDOWS\system32\mqsvc.exe
2004-08-04 06:26:54 ----A---- C:\WINDOWS\system32\mqbkup.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\mobsync.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\mmc.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\makecab.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\magnify.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\lsass.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\logonui.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\logman.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\logagent.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\locator.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\ipxroute.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\ipv6.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\ipconfig.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\imapi.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\iexpress.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2004-08-04 06:26:52 ----A---- C:\WINDOWS\hh.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\grpconv.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\gpresult.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\ftp.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\fsquirt.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\fontview.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\findstr.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\extrac32.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\eventcreate.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\eudcedit.exe
2004-08-04 06:26:50 ----A---- C:\WINDOWS\system32\dxdiag.exe