Takze RSIT log :
Logfile of random's system information tool 1.06 (written by random/random)
Run by mato at 2010-04-23 08:08:01
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 92 GB (30%) free of 305 GB
Total RAM: 3071 MB (69% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:21, on 23. 4. 2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\fraps\fraps.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Users\mato\Desktop\RSIT.exe
C:\Program Files\trend micro\mato.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/f ... wflash.cab
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
--
End of file - 5347 bytes
======Scheduled tasks folder======
C:\Windows\tasks\1-Click Maintenance.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-190942252-359916794-3278992379-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-190942252-359916794-3278992379-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-03-06 503808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-03-06 503808]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-11-16 2054360]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-06-17 85160]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel File Shell Monitor]
C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [2008-01-15 16200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe [2007-12-14 531784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus SX400 Series]
C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE [2007-12-17 188928]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-07 1394000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
C:\Program Files\Nokia pc suite\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^mato^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^NHL® 09 Registration.lnk]
C:\hry\NHL09~1\Support\EAREGI~1.EXE [2008-10-04 4374792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^mato^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PowerMenu.lnk]
C:\PROGRA~1\POWERM~1\POWERM~1.EXE [2002-12-20 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^mato^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registrace FIFA 10.lnk]
C:\hry\FIFA10~1\Support\EAREGI~1.EXE []
C:\Users\mato\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=255
"NoDriveTypeAutoRun"=255
"HonorAutoRunSetting"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-04-22 21:50:05 ----RASHD---- C:\autorun.inf
2010-04-22 19:14:56 ----D---- C:\UsbFix
2010-04-21 18:11:21 ----D---- C:\Windows\system32\eu-ES
2010-04-21 18:11:21 ----D---- C:\Windows\system32\ca-ES
2010-04-21 18:11:18 ----D---- C:\Windows\system32\vi-VN
2010-04-21 15:42:12 ----D---- C:\Windows\system32\EventProviders
2010-04-21 15:38:45 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2010-04-21 15:38:43 ----A---- C:\Windows\system32\SLCExt.dll
2010-04-21 15:38:42 ----A---- C:\Windows\system32\SLsvc.exe
2010-04-21 15:38:38 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2010-04-21 15:38:38 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2010-04-21 15:38:36 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2010-04-21 15:38:33 ----A---- C:\Windows\system32\mssrch.dll
2010-04-21 15:38:30 ----A---- C:\Windows\system32\tquery.dll
2010-04-21 15:38:28 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2010-04-21 15:38:27 ----A---- C:\Windows\system32\scavenge.dll
2010-04-21 15:38:26 ----A---- C:\Windows\system32\msi.dll
2010-04-21 15:38:24 ----A---- C:\Windows\system32\imapi2fs.dll
2010-04-21 15:38:23 ----A---- C:\Windows\system32\WscEapPr.dll
2010-04-21 15:38:23 ----A---- C:\Windows\system32\wcnwiz2.dll
2010-04-21 15:38:23 ----A---- C:\Windows\system32\sysmain.dll
2010-04-21 15:38:21 ----A---- C:\Windows\system32\icardagt.exe
2010-04-21 15:38:20 ----A---- C:\Windows\system32\EhStorShell.dll
2010-04-21 15:38:20 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2010-04-21 15:38:19 ----A---- C:\Windows\system32\spreview.exe
2010-04-21 15:38:19 ----A---- C:\Windows\system32\spinstall.exe
2010-04-21 15:38:18 ----A---- C:\Windows\system32\drmv2clt.dll
2010-04-21 15:38:17 ----A---- C:\Windows\system32\spwizui.dll
2010-04-21 15:38:17 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2010-04-21 15:38:16 ----A---- C:\Windows\system32\shell32.dll
2010-04-21 15:38:15 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-04-21 15:38:15 ----A---- C:\Windows\system32\p2psvc.dll
2010-04-21 15:38:14 ----A---- C:\Windows\system32\mssvp.dll
2010-04-21 15:38:13 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
2010-04-21 15:38:13 ----A---- C:\Windows\system32\mscoree.dll
2010-04-21 15:38:12 ----A---- C:\Windows\system32\mssphtb.dll
2010-04-21 15:38:12 ----A---- C:\Windows\system32\mssph.dll
2010-04-21 15:38:12 ----A---- C:\Windows\system32\imapi2.dll
2010-04-21 15:38:10 ----A---- C:\Windows\system32\sdohlp.dll
2010-04-21 15:38:10 ----A---- C:\Windows\system32\esent.dll
2010-04-21 15:38:09 ----A---- C:\Windows\system32\IMJP10K.DLL
2010-04-21 15:38:09 ----A---- C:\Windows\system32\DevicePairing.dll
2010-04-21 15:38:08 ----A---- C:\Windows\system32\sperror.dll
2010-04-21 15:38:07 ----A---- C:\Windows\system32\wevtsvc.dll
2010-04-21 15:38:07 ----A---- C:\Windows\system32\SLC.dll
2010-04-21 15:38:07 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-04-21 15:38:07 ----A---- C:\Windows\system32\korwbrkr.dll
2010-04-21 15:38:06 ----A---- C:\Windows\system32\msshsq.dll
2010-04-21 15:38:04 ----A---- C:\Windows\system32\msjet40.dll
2010-04-21 15:38:04 ----A---- C:\Windows\system32\MPSSVC.dll
2010-04-21 15:38:03 ----A---- C:\Windows\system32\Query.dll
2010-04-21 15:38:03 ----A---- C:\Windows\system32\qmgr.dll
2010-04-21 15:38:02 ----A---- C:\Windows\system32\msexch40.dll
2010-04-21 15:38:01 ----A---- C:\Windows\system32\P2PGraph.dll
2010-04-21 15:38:01 ----A---- C:\Windows\system32\ole32.dll
2010-04-21 15:38:01 ----A---- C:\Windows\system32\IasMigReader.exe
2010-04-21 15:38:01 ----A---- C:\Windows\system32\diagperf.dll
2010-04-21 15:38:00 ----A---- C:\Windows\system32\winload.exe
2010-04-21 15:38:00 ----A---- C:\Windows\system32\srchadmin.dll
2010-04-21 15:38:00 ----A---- C:\Windows\system32\ntdll.dll
2010-04-21 15:38:00 ----A---- C:\Windows\system32\mblctr.exe
2010-04-21 15:38:00 ----A---- C:\Windows\system32\EncDec.dll
2010-04-21 15:37:59 ----A---- C:\Windows\system32\uDWM.dll
2010-04-21 15:37:59 ----A---- C:\Windows\system32\riched20.dll
2010-04-21 15:37:59 ----A---- C:\Windows\system32\mmc.exe
2010-04-21 15:37:59 ----A---- C:\Windows\system32\IasMigPlugin.dll
2010-04-21 15:37:59 ----A---- C:\Windows\system32\dfsr.exe
2010-04-21 15:37:58 ----A---- C:\Windows\system32\fdBth.dll
2010-04-21 15:37:57 ----A---- C:\Windows\system32\RacEngn.dll
2010-04-21 15:37:57 ----A---- C:\Windows\system32\kernel32.dll
2010-04-21 15:37:56 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-04-21 15:37:56 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-04-21 15:37:56 ----A---- C:\Windows\system32\milcore.dll
2010-04-21 15:37:56 ----A---- C:\Windows\system32\EhStorAPI.dll
2010-04-21 15:37:56 ----A---- C:\Windows\system32\CertEnroll.dll
2010-04-21 15:37:55 ----A---- C:\Windows\system32\spoolss.dll
2010-04-21 15:37:55 ----A---- C:\Windows\system32\schedsvc.dll
2010-04-21 15:37:55 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2010-04-21 15:37:53 ----A---- C:\Windows\system32\msvcp60.dll
2010-04-21 15:37:53 ----A---- C:\Windows\system32\msjtes40.dll
2010-04-21 15:37:53 ----A---- C:\Windows\system32\gpedit.dll
2010-04-21 15:37:53 ----A---- C:\Windows\system32\fsquirt.exe
2010-04-21 15:37:53 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2010-04-21 15:37:52 ----A---- C:\Windows\system32\infocardapi.dll
2010-04-21 15:37:51 ----A---- C:\Windows\system32\WinSAT.exe
2010-04-21 15:37:51 ----A---- C:\Windows\system32\PresentationSettings.exe
2010-04-21 15:37:51 ----A---- C:\Windows\system32\es.dll
2010-04-21 15:37:50 ----A---- C:\Windows\system32\mstext40.dll
2010-04-21 15:37:50 ----A---- C:\Windows\system32\Magnify.exe
2010-04-21 15:37:50 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2010-04-21 15:37:49 ----A---- C:\Windows\system32\advapi32.dll
2010-04-21 15:37:48 ----A---- C:\Windows\system32\WMPhoto.dll
2010-04-21 15:37:48 ----A---- C:\Windows\system32\WebClnt.dll
2010-04-21 15:37:47 ----A---- C:\Windows\system32\slwmi.dll
2010-04-21 15:37:47 ----A---- C:\Windows\system32\msxbde40.dll
2010-04-21 15:37:47 ----A---- C:\Windows\system32\msexcl40.dll
2010-04-21 15:37:47 ----A---- C:\Windows\system32\comsvcs.dll
2010-04-21 15:37:46 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2010-04-21 15:37:45 ----A---- C:\Windows\system32\vssapi.dll
2010-04-21 15:37:45 ----A---- C:\Windows\system32\authui.dll
2010-04-21 15:37:44 ----A---- C:\Windows\system32\NetProjW.dll
2010-04-21 15:37:43 ----A---- C:\Windows\system32\PresentationHost.exe
2010-04-21 15:37:43 ----A---- C:\Windows\system32\newdev.dll
2010-04-21 15:37:43 ----A---- C:\Windows\system32\msrepl40.dll
2010-04-21 15:37:42 ----A---- C:\Windows\system32\propsys.dll
2010-04-21 15:37:42 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-04-21 15:37:42 ----A---- C:\Windows\system32\iasrecst.dll
2010-04-21 15:37:42 ----A---- C:\Windows\system32\gpsvc.dll
2010-04-21 15:37:42 ----A---- C:\Windows\system32\eudcedit.exe
2010-04-21 15:37:42 ----A---- C:\Windows\system32\crypt32.dll
2010-04-21 15:37:41 ----A---- C:\Windows\system32\setupapi.dll
2010-04-21 15:37:41 ----A---- C:\Windows\system32\rpcss.dll
2010-04-21 15:37:41 ----A---- C:\Windows\explorer.exe
2010-04-21 15:37:40 ----A---- C:\Windows\system32\mspbde40.dll
2010-04-21 15:37:40 ----A---- C:\Windows\system32\d3d9.dll
2010-04-21 15:37:39 ----A---- C:\Windows\system32\msltus40.dll
2010-04-21 15:37:39 ----A---- C:\Windows\system32\davclnt.dll
2010-04-21 15:37:38 ----A---- C:\Windows\system32\shlwapi.dll
2010-04-21 15:37:38 ----A---- C:\Windows\system32\msrd3x40.dll
2010-04-21 15:37:38 ----A---- C:\Windows\system32\mfc42.dll
2010-04-21 15:37:38 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2010-04-21 15:37:38 ----A---- C:\Windows\system32\EhStorAuthn.dll
2010-04-21 15:37:37 ----A---- C:\Windows\system32\msdtctm.dll
2010-04-21 15:37:37 ----A---- C:\Windows\system32\browseui.dll
2010-04-21 15:37:36 ----A---- C:\Windows\system32\wevtapi.dll
2010-04-21 15:37:36 ----A---- C:\Windows\system32\photowiz.dll
2010-04-21 15:37:36 ----A---- C:\Windows\system32\nlhtml.dll
2010-04-21 15:37:35 ----A---- C:\Windows\system32\user32.dll
2010-04-21 15:37:34 ----A---- C:\Windows\system32\samsrv.dll
2010-04-21 15:37:34 ----A---- C:\Windows\system32\ci.dll
2010-04-21 15:37:33 ----A---- C:\Windows\system32\win32spl.dll
2010-04-21 15:37:33 ----A---- C:\Windows\system32\WcnNetsh.dll
2010-04-21 15:37:33 ----A---- C:\Windows\system32\SLCommDlg.dll
2010-04-21 15:37:32 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-04-21 15:37:32 ----A---- C:\Windows\system32\oleaut32.dll
2010-04-21 15:37:31 ----A---- C:\Windows\system32\netshell.dll
2010-04-21 15:37:31 ----A---- C:\Windows\system32\IKEEXT.DLL
2010-04-21 15:37:31 ----A---- C:\Windows\system32\compcln.exe
2010-04-21 15:37:31 ----A---- C:\Windows\system32\apds.dll
2010-04-21 15:37:30 ----A---- C:\Windows\system32\mswstr10.dll
2010-04-21 15:37:30 ----A---- C:\Windows\system32\audiosrv.dll
2010-04-21 15:37:29 ----A---- C:\Windows\system32\xmlfilter.dll
2010-04-21 15:37:29 ----A---- C:\Windows\system32\msctf.dll
2010-04-21 15:37:29 ----A---- C:\Windows\system32\emdmgmt.dll
2010-04-21 15:37:28 ----A---- C:\Windows\system32\VSSVC.exe
2010-04-21 15:37:28 ----A---- C:\Windows\system32\QAGENTRT.DLL
2010-04-21 15:37:28 ----A---- C:\Windows\system32\msvcrt.dll
2010-04-21 15:37:28 ----A---- C:\Windows\system32\gdi32.dll
2010-04-21 15:37:27 ----A---- C:\Windows\system32\SLUI.exe
2010-04-21 15:37:27 ----A---- C:\Windows\system32\mfc42u.dll
2010-04-21 15:37:27 ----A---- C:\Windows\system32\eapphost.dll
2010-04-21 15:37:26 ----A---- C:\Windows\system32\sqlsrv32.dll
2010-04-21 15:37:26 ----A---- C:\Windows\system32\msrd2x40.dll
2010-04-21 15:37:25 ----A---- C:\Windows\system32\winresume.exe
2010-04-21 15:37:25 ----A---- C:\Windows\system32\propdefs.dll
2010-04-21 15:37:25 ----A---- C:\Windows\system32\odbc32.dll
2010-04-21 15:37:24 ----A---- C:\Windows\system32\shdocvw.dll
2010-04-21 15:37:23 ----A---- C:\Windows\system32\wevtutil.exe
2010-04-21 15:37:23 ----A---- C:\Windows\system32\dbgeng.dll
2010-04-21 15:37:22 ----A---- C:\Windows\system32\mssitlb.dll
2010-04-21 15:37:21 ----A---- C:\Windows\system32\WsmSvc.dll
2010-04-21 15:37:21 ----A---- C:\Windows\system32\swprv.dll
2010-04-21 15:37:20 ----A---- C:\Windows\system32\usp10.dll
2010-04-21 15:37:20 ----A---- C:\Windows\system32\mmcndmgr.dll
2010-04-21 15:37:19 ----A---- C:\Windows\system32\vds.exe
2010-04-21 15:37:19 ----A---- C:\Windows\system32\drvinst.exe
2010-04-21 15:37:18 ----A---- C:\Windows\system32\netlogon.dll
2010-04-21 15:37:18 ----A---- C:\Windows\system32\msscb.dll
2010-04-21 15:37:18 ----A---- C:\Windows\system32\msctfp.dll
2010-04-21 15:37:18 ----A---- C:\Windows\system32\fdBthProxy.dll
2010-04-21 15:37:18 ----A---- C:\Windows\system32\devmgr.dll
2010-04-21 15:37:17 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2010-04-21 15:37:17 ----A---- C:\Windows\system32\BFE.DLL
2010-04-21 15:37:17 ----A---- C:\Windows\system32\adsldpc.dll
2010-04-21 15:37:16 ----A---- C:\Windows\system32\Wldap32.dll
2010-04-21 15:37:16 ----A---- C:\Windows\system32\wcnwiz.dll
2010-04-21 15:37:16 ----A---- C:\Windows\system32\evr.dll
2010-04-21 15:37:15 ----A---- C:\Windows\system32\WMVSDECD.DLL
2010-04-21 15:37:15 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-04-21 15:37:15 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-04-21 15:37:14 ----A---- C:\Windows\system32\services.exe
2010-04-21 15:37:13 ----A---- C:\Windows\system32\wercon.exe
2010-04-21 15:37:13 ----A---- C:\Windows\system32\mimefilt.dll
2010-04-21 15:37:13 ----A---- C:\Windows\system32\comdlg32.dll
2010-04-21 15:37:13 ----A---- C:\Windows\system32\adtschema.dll
2010-04-21 15:37:12 ----A---- C:\Windows\system32\wcncsvc.dll
2010-04-21 15:37:12 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-04-21 15:37:12 ----A---- C:\Windows\system32\certcli.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\taskeng.exe
2010-04-21 15:37:11 ----A---- C:\Windows\system32\rtffilt.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\reg.exe
2010-04-21 15:37:11 ----A---- C:\Windows\system32\mswdat10.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\msjter40.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\msdtcprx.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\ipsmsnap.dll
2010-04-21 15:37:11 ----A---- C:\Windows\system32\dnsapi.dll
2010-04-21 15:37:10 ----A---- C:\Windows\system32\WMNetMgr.dll
2010-04-21 15:37:10 ----A---- C:\Windows\system32\w32time.dll
2010-04-21 15:37:10 ----A---- C:\Windows\system32\umpnpmgr.dll
2010-04-21 15:37:10 ----A---- C:\Windows\system32\certutil.exe
2010-04-21 15:37:09 ----A---- C:\Windows\system32\msshooks.dll
2010-04-21 15:37:09 ----A---- C:\Windows\system32\msscntrs.dll
2010-04-21 15:37:09 ----A---- C:\Windows\system32\IPSECSVC.DLL
2010-04-21 15:37:09 ----A---- C:\Windows\system32\bcrypt.dll
2010-04-21 15:37:08 ----A---- C:\Windows\system32\rsaenh.dll
2010-04-21 15:37:08 ----A---- C:\Windows\system32\bthserv.dll
2010-04-21 15:37:07 ----A---- C:\Windows\system32\TsWpfWrp.exe
2010-04-21 15:37:07 ----A---- C:\Windows\system32\msstrc.dll
2010-04-21 15:37:07 ----A---- C:\Windows\system32\msihnd.dll
2010-04-21 15:37:07 ----A---- C:\Windows\system32\MMDevAPI.dll
2010-04-21 15:37:06 ----A---- C:\Windows\system32\netapi32.dll
2010-04-21 15:37:06 ----A---- C:\Windows\system32\inetpp.dll
2010-04-21 15:37:06 ----A---- C:\Windows\system32\inetcomm.dll
2010-04-21 15:37:06 ----A---- C:\Windows\system32\dfshim.dll
2010-04-21 15:37:05 ----A---- C:\Windows\system32\mtxclu.dll
2010-04-21 15:37:05 ----A---- C:\Windows\system32\mscories.dll
2010-04-21 15:37:05 ----A---- C:\Windows\system32\hidserv.dll
2010-04-21 15:37:05 ----A---- C:\Windows\system32\fundisc.dll
2010-04-21 15:37:05 ----A---- C:\Windows\system32\cryptsvc.dll
2010-04-21 15:37:04 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-04-21 15:37:04 ----A---- C:\Windows\system32\termsrv.dll
2010-04-21 15:37:04 ----A---- C:\Windows\system32\profsvc.dll
2010-04-21 15:37:04 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2010-04-21 15:37:03 ----A---- C:\Windows\system32\wdc.dll
2010-04-21 15:37:03 ----A---- C:\Windows\system32\shsvcs.dll
2010-04-21 15:37:03 ----A---- C:\Windows\system32\msiexec.exe
2010-04-21 15:37:03 ----A---- C:\Windows\system32\imapi.dll
2010-04-21 15:37:03 ----A---- C:\Windows\system32\chsbrkr.dll
2010-04-21 15:37:02 ----A---- C:\Windows\system32\spoolsv.exe
2010-04-21 15:37:02 ----A---- C:\Windows\system32\rasmans.dll
2010-04-21 15:37:02 ----A---- C:\Windows\system32\pnidui.dll
2010-04-21 15:37:02 ----A---- C:\Windows\system32\icardres.dll
2010-04-21 15:37:02 ----A---- C:\Windows\system32\iassdo.dll
2010-04-21 15:37:01 ----A---- C:\Windows\system32\wersvc.dll
2010-04-21 15:37:01 ----A---- C:\Windows\system32\slmgr.vbs
2010-04-21 15:37:01 ----A---- C:\Windows\system32\scrrun.dll
2010-04-21 15:37:01 ----A---- C:\Windows\system32\PSHED.DLL
2010-04-21 15:37:01 ----A---- C:\Windows\system32\autofmt.exe
2010-04-21 15:37:00 ----A---- C:\Windows\system32\pdh.dll
2010-04-21 15:37:00 ----A---- C:\Windows\system32\dhcpcsvc.dll
2010-04-21 15:37:00 ----A---- C:\Windows\system32\CertEnrollUI.dll
2010-04-21 15:37:00 ----A---- C:\Windows\system32\azroles.dll
2010-04-21 15:36:59 ----A---- C:\Windows\system32\pidgenx.dll
2010-04-21 15:36:56 ----A---- C:\Windows\system32\wmpmde.dll
2010-04-21 15:36:56 ----A---- C:\Windows\system32\winlogon.exe
2010-04-21 15:36:56 ----A---- C:\Windows\system32\SyncCenter.dll
2010-04-21 15:36:55 ----A---- C:\Windows\system32\SLUINotify.dll
2010-04-21 15:36:55 ----A---- C:\Windows\system32\msjetoledb40.dll
2010-04-21 15:36:55 ----A---- C:\Windows\system32\comuid.dll
2010-04-21 15:36:55 ----A---- C:\Windows\system32\certmgr.dll
2010-04-21 15:36:54 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-04-21 15:36:54 ----A---- C:\Windows\system32\spp.dll
2010-04-21 15:36:54 ----A---- C:\Windows\system32\sethc.exe
2010-04-21 15:36:54 ----A---- C:\Windows\system32\ncrypt.dll
2010-04-21 15:36:54 ----A---- C:\Windows\system32\kd1394.dll
2010-04-21 15:36:54 ----A---- C:\Windows\system32\iassam.dll
2010-04-21 15:36:53 ----A---- C:\Windows\system32\wisptis.exe
2010-04-21 15:36:53 ----A---- C:\Windows\system32\untfs.dll
2010-04-21 15:36:53 ----A---- C:\Windows\system32\scrobj.dll
2010-04-21 15:36:53 ----A---- C:\Windows\system32\rtutils.dll
2010-04-21 15:36:52 ----A---- C:\Windows\system32\taskcomp.dll
2010-04-21 15:36:52 ----A---- C:\Windows\system32\dwm.exe
2010-04-21 15:36:52 ----A---- C:\Windows\system32\autochk.exe
2010-04-21 15:36:51 ----A---- C:\Windows\system32\winsrv.dll
2010-04-21 15:36:51 ----A---- C:\Windows\system32\printui.dll
2010-04-21 15:36:51 ----A---- C:\Windows\system32\iasnap.dll
2010-04-21 15:36:51 ----A---- C:\Windows\system32\autoconv.exe
2010-04-21 15:36:50 ----A---- C:\Windows\system32\kdcom.dll
2010-04-21 15:36:50 ----A---- C:\Windows\system32\cscript.exe
2010-04-21 15:36:50 ----A---- C:\Windows\system32\basecsp.dll
2010-04-21 15:36:49 ----A---- C:\Windows\system32\wow32.dll
2010-04-21 15:36:49 ----A---- C:\Windows\system32\userenv.dll
2010-04-21 15:36:49 ----A---- C:\Windows\system32\osk.exe
2010-04-21 15:36:49 ----A---- C:\Windows\system32\onex.dll
2010-04-21 15:36:49 ----A---- C:\Windows\system32\audiodg.exe
2010-04-21 15:36:48 ----A---- C:\Windows\system32\mswsock.dll
2010-04-21 15:36:47 ----A---- C:\Windows\system32\winmm.dll
2010-04-21 15:36:47 ----A---- C:\Windows\system32\RelMon.dll
2010-04-21 15:36:47 ----A---- C:\Windows\system32\rdpencom.dll
2010-04-21 15:36:47 ----A---- C:\Windows\system32\kdusb.dll
2010-04-21 15:36:46 ----A---- C:\Windows\system32\WinSCard.dll
2010-04-21 15:36:46 ----A---- C:\Windows\system32\WerFaultSecure.exe
2010-04-21 15:36:46 ----A---- C:\Windows\system32\spcmsg.dll
2010-04-21 15:36:46 ----A---- C:\Windows\system32\msftedit.dll
2010-04-21 15:36:45 ----A---- C:\Windows\system32\offfilt.dll
2010-04-21 15:36:45 ----A---- C:\Windows\system32\dnsrslvr.dll
2010-04-21 15:36:44 ----A---- C:\Windows\system32\wsepno.dll
2010-04-21 15:36:44 ----A---- C:\Windows\system32\WerFault.exe
2010-04-21 15:36:44 ----A---- C:\Windows\system32\Utilman.exe
2010-04-21 15:36:44 ----A---- C:\Windows\system32\stobject.dll
2010-04-21 15:36:43 ----A---- C:\Windows\system32\SndVol.exe
2010-04-21 15:36:43 ----A---- C:\Windows\system32\mfplat.dll
2010-04-21 15:36:43 ----A---- C:\Windows\system32\mcmde.dll
2010-04-21 15:36:43 ----A---- C:\Windows\system32\diskraid.exe
2010-04-21 15:36:43 ----A---- C:\Windows\system32\apphelp.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\wiaservc.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\sysclass.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\prnntfy.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\msnetobj.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\mscms.dll
2010-04-21 15:36:42 ----A---- C:\Windows\system32\adsmsext.dll
2010-04-21 15:36:41 ----A---- C:\Windows\system32\wscript.exe
2010-04-21 15:36:41 ----A---- C:\Windows\system32\ulib.dll
2010-04-21 15:36:41 ----A---- C:\Windows\system32\odbccp32.dll
2010-04-21 15:36:41 ----A---- C:\Windows\system32\iasdatastore.dll
2010-04-21 15:36:40 ----A---- C:\Windows\system32\dsound.dll
2010-04-21 15:36:39 ----A---- C:\Windows\system32\wscntfy.dll
2010-04-21 15:36:39 ----A---- C:\Windows\system32\rastapi.dll
2010-04-21 15:36:39 ----A---- C:\Windows\system32\pnpsetup.dll
2010-04-21 15:36:39 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2010-04-21 15:36:39 ----A---- C:\Windows\system32\cryptui.dll
2010-04-21 15:36:38 ----A---- C:\Windows\system32\wlangpui.dll
2010-04-21 15:36:38 ----A---- C:\Windows\system32\ipsecsnp.dll
2010-04-21 15:36:38 ----A---- C:\Windows\system32\gpapi.dll
2010-04-21 15:36:38 ----A---- C:\Windows\system32\fdProxy.dll
2010-04-21 15:36:38 ----A---- C:\Windows\system32\diskpart.exe
2010-04-21 15:36:38 ----A---- C:\Windows\system32\brcpl.dll
2010-04-21 15:36:37 ----A---- C:\Windows\system32\wscsvc.dll
2010-04-21 15:36:37 ----A---- C:\Windows\system32\WMVENCOD.DLL
2010-04-21 15:36:37 ----A---- C:\Windows\system32\vdsdyn.dll
2010-04-21 15:36:37 ----A---- C:\Windows\system32\logman.exe
2010-04-21 15:36:37 ----A---- C:\Windows\system32\iashlpr.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\wusa.exe
2010-04-21 15:36:36 ----A---- C:\Windows\system32\regsvc.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\rasapi32.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\ntprint.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\mscorier.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\iasrad.dll
2010-04-21 15:36:36 ----A---- C:\Windows\system32\findstr.exe
2010-04-21 15:36:35 ----A---- C:\Windows\system32\zipfldr.dll
2010-04-21 15:36:35 ----A---- C:\Windows\system32\wshext.dll
2010-04-21 15:36:35 ----A---- C:\Windows\system32\wpccpl.dll
2010-04-21 15:36:34 ----A---- C:\Windows\system32\rasdlg.dll
2010-04-21 15:36:34 ----A---- C:\Windows\system32\netcenter.dll
2010-04-21 15:36:34 ----A---- C:\Windows\system32\iassvcs.dll
2010-04-21 15:36:33 ----A---- C:\Windows\system32\wsnmp32.dll
2010-04-21 15:36:33 ----A---- C:\Windows\system32\wer.dll
2010-04-21 15:36:33 ----A---- C:\Windows\system32\themecpl.dll
2010-04-21 15:36:32 ----A---- C:\Windows\system32\uxsms.dll
2010-04-21 15:36:32 ----A---- C:\Windows\system32\mssprxy.dll
2010-04-21 15:36:31 ----A---- C:\Windows\system32\srvsvc.dll
2010-04-21 15:36:31 ----A---- C:\Windows\system32\scansetting.dll
2010-04-21 15:36:31 ----A---- C:\Windows\system32\ntmarta.dll
2010-04-21 15:36:31 ----A---- C:\Windows\system32\iasads.dll
2010-04-21 15:36:30 ----A---- C:\Windows\system32\slcc.dll
2010-04-21 15:36:30 ----A---- C:\Windows\system32\msutb.dll
2010-04-21 15:36:30 ----A---- C:\Windows\system32\mstlsapi.dll
2010-04-21 15:36:29 ----A---- C:\Windows\system32\powrprof.dll
2010-04-21 15:36:29 ----A---- C:\Windows\system32\networkmap.dll
2010-04-21 15:36:29 ----A---- C:\Windows\system32\mstsc.exe
2010-04-21 15:36:29 ----A---- C:\Windows\system32\iasacct.dll
2010-04-21 15:36:28 ----A---- C:\Windows\system32\powercpl.dll
2010-04-21 15:36:28 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2010-04-21 15:36:28 ----A---- C:\Windows\system32\authz.dll
2010-04-21 15:36:27 ----A---- C:\Windows\system32\sud.dll
2010-04-21 15:36:27 ----A---- C:\Windows\system32\newdev.exe
2010-04-21 15:36:27 ----A---- C:\Windows\system32\dot3svc.dll
2010-04-21 15:36:27 ----A---- C:\Windows\system32\connect.dll
2010-04-21 15:36:26 ----A---- C:\Windows\system32\themeui.dll
2010-04-21 15:36:26 ----A---- C:\Windows\system32\systemcpl.dll
2010-04-21 15:36:26 ----A---- C:\Windows\system32\pcaui.dll
2010-04-21 15:36:25 ----A---- C:\Windows\system32\samlib.dll
2010-04-21 15:36:25 ----A---- C:\Windows\system32\mmci.dll
2010-04-21 15:36:25 ----A---- C:\Windows\system32\accessibilitycpl.dll
2010-04-21 15:36:24 ----A---- C:\Windows\system32\wlanpref.dll
2010-04-21 15:36:24 ----A---- C:\Windows\system32\usercpl.dll
2010-04-21 15:36:24 ----A---- C:\Windows\system32\qdvd.dll
2010-04-21 15:36:24 ----A---- C:\Windows\system32\autoplay.dll
2010-04-21 15:36:23 ----A---- C:\Windows\system32\wpcao.dll
2010-04-21 15:36:23 ----A---- C:\Windows\system32\rpchttp.dll
2010-04-21 15:36:23 ----A---- C:\Windows\system32\regapi.dll
2010-04-21 15:36:23 ----A---- C:\Windows\system32\msinfo32.exe
2010-04-21 15:36:22 ----A---- C:\Windows\system32\vdsutil.dll
2010-04-21 15:36:22 ----A---- C:\Windows\system32\tapisrv.dll
2010-04-21 15:36:22 ----A---- C:\Windows\system32\scksp.dll
2010-04-21 15:36:22 ----A---- C:\Windows\system32\feclient.dll
2010-04-21 15:36:21 ----A---- C:\Windows\system32\scesrv.dll
2010-04-21 15:36:21 ----A---- C:\Windows\system32\psisdecd.dll
2010-04-21 15:36:21 ----A---- C:\Windows\system32\oleprn.dll
2010-04-21 15:36:21 ----A---- C:\Windows\system32\mpr.dll
2010-04-21 15:36:21 ----A---- C:\Windows\system32\AudioSes.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\wscisvif.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\sdclt.exe
2010-04-21 15:36:20 ----A---- C:\Windows\system32\rekeywiz.exe
2010-04-21 15:36:20 ----A---- C:\Windows\system32\imm32.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\iaspolcy.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\Faultrep.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\dot3msm.dll
2010-04-21 15:36:20 ----A---- C:\Windows\system32\DeviceEject.exe
2010-04-21 15:36:19 ----A---- C:\Windows\system32\rasgcw.dll
2010-04-21 15:36:19 ----A---- C:\Windows\system32\qedit.dll
2010-04-21 15:36:19 ----A---- C:\Windows\system32\pnpui.dll
2010-04-21 15:36:19 ----A---- C:\Windows\system32\perfdisk.dll
2010-04-21 15:36:19 ----A---- C:\Windows\system32\ncryptui.dll
2010-04-21 15:36:19 ----A---- C:\Windows\system32\hdwwiz.exe
2010-04-21 15:36:19 ----A---- C:\Windows\system32\dpapimig.exe
2010-04-21 15:36:19 ----A---- C:\Windows\system32\certreq.exe
2010-04-21 15:36:18 ----A---- C:\Windows\system32\TSTheme.exe
2010-04-21 15:36:18 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2010-04-21 15:36:18 ----A---- C:\Windows\system32\scecli.dll
2010-04-21 15:36:18 ----A---- C:\Windows\system32\rasplap.dll
2010-04-21 15:36:18 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2010-04-21 15:36:17 ----A---- C:\Windows\system32\spwinsat.dll
2010-04-21 15:36:16 ----A---- C:\Windows\system32\whealogr.dll
2010-04-21 15:36:16 ----A---- C:\Windows\system32\tcpmon.dll
2010-04-21 15:36:16 ----A---- C:\Windows\system32\tcpipcfg.dll
2010-04-21 15:36:16 ----A---- C:\Windows\system32\PnPUnattend.exe
2010-04-21 15:36:16 ----A---- C:\Windows\system32\fdWSD.dll
2010-04-21 15:36:16 ----A---- C:\Windows\system32\cmmon32.exe
2010-04-21 15:36:15 ----A---- C:\Windows\system32\srcore.dll
2010-04-21 15:36:15 ----A---- C:\Windows\system32\SnippingTool.exe
2010-04-21 15:36:15 ----A---- C:\Windows\system32\SCardSvr.dll
2010-04-21 15:36:15 ----A---- C:\Windows\system32\conime.exe
2010-04-21 15:36:15 ----A---- C:\Windows\system32\cmdial32.dll
2010-04-21 15:36:14 ----A---- C:\Windows\system32\wiaaut.dll
2010-04-21 15:36:14 ----A---- C:\Windows\system32\raschap.dll
2010-04-21 15:36:14 ----A---- C:\Windows\system32\MSVidCtl.dll
2010-04-21 15:36:14 ----A---- C:\Windows\system32\fontext.dll
2010-04-21 15:36:13 ----A---- C:\Windows\system32\WMVXENCD.DLL
2010-04-21 15:36:13 ----A---- C:\Windows\system32\wlanui.dll
2010-04-21 15:36:13 ----A---- C:\Windows\system32\rasppp.dll
2010-04-21 15:36:13 ----A---- C:\Windows\system32\PnPutil.exe
2010-04-21 15:36:13 ----A---- C:\Windows\system32\dsprop.dll
2010-04-21 15:36:12 ----A---- C:\Windows\system32\shwebsvc.dll
2010-04-21 15:36:12 ----A---- C:\Windows\system32\dimsroam.dll
2010-04-21 15:36:11 ----A---- C:\Windows\system32\shsetup.dll
2010-04-21 15:36:11 ----A---- C:\Windows\system32\oobefldr.dll
2010-04-21 15:36:10 ----A---- C:\Windows\system32\rasmontr.dll
2010-04-21 15:36:10 ----A---- C:\Windows\system32\mscandui.dll
2010-04-21 15:36:10 ----A---- C:\Windows\system32\modemui.dll
2010-04-21 15:36:09 ----A---- C:\Windows\system32\wmdrmsdk.dll
2010-04-21 15:36:09 ----A---- C:\Windows\system32\chtbrkr.dll
2010-04-21 15:36:08 ----A---- C:\Windows\system32\wlgpclnt.dll
2010-04-21 15:36:08 ----A---- C:\Windows\system32\dataclen.dll
2010-04-21 15:36:07 ----A---- C:\Windows\system32\smss.exe
2010-04-21 15:36:07 ----A---- C:\Windows\system32\rdpwsx.dll
2010-04-21 15:36:07 ----A---- C:\Windows\system32\credui.dll
2010-04-21 15:36:07 ----A---- C:\Windows\system32\blackbox.dll
2010-04-21 15:36:06 ----A---- C:\Windows\system32\WSDMon.dll
2010-04-21 15:36:06 ----A---- C:\Windows\system32\wmpeffects.dll
2010-04-21 15:36:06 ----A---- C:\Windows\system32\netplwiz.dll
2010-04-21 15:36:06 ----A---- C:\Windows\system32\certprop.dll
2010-04-21 15:36:05 ----A---- C:\Windows\system32\networkexplorer.dll
2010-04-21 15:36:05 ----A---- C:\Windows\system32\ifmon.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\wscapi.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\wpcsvc.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\msscp.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\msimtf.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\logagent.exe
2010-04-21 15:36:04 ----A---- C:\Windows\system32\InkEd.dll
2010-04-21 15:36:04 ----A---- C:\Windows\system32\gpresult.exe
2010-04-21 15:36:04 ----A---- C:\Windows\system32\cipher.exe
2010-04-21 15:36:03 ----A---- C:\Windows\system32\thawbrkr.dll
2010-04-21 15:36:03 ----A---- C:\Windows\system32\softkbd.dll
2010-04-21 15:36:03 ----A---- C:\Windows\system32\sendmail.dll
2010-04-21 15:36:02 ----A---- C:\Windows\system32\msctfui.dll
2010-04-21 15:36:02 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2010-04-21 15:36:01 ----A---- C:\Windows\system32\olepro32.dll
2010-04-21 15:36:01 ----A---- C:\Windows\system32\drmmgrtn.dll
2010-04-21 15:36:01 ----A---- C:\Windows\system32\dmsynth.dll
2010-04-21 15:36:00 ----A---- C:\Windows\system32\puiapi.dll
2010-04-21 15:36:00 ----A---- C:\Windows\system32\input.dll
2010-04-21 15:36:00 ----A---- C:\Windows\system32\cdd.dll
2010-04-21 15:35:59 ----A---- C:\Windows\system32\wshbth.dll
2010-04-21 15:35:59 ----A---- C:\Windows\system32\version.dll
2010-04-21 15:35:59 ----A---- C:\Windows\system32\mprapi.dll
2010-04-21 15:35:59 ----A---- C:\Windows\system32\ExplorerFrame.dll
2010-04-21 15:35:58 ----A---- C:\Windows\system32\SLLUA.exe
2010-04-21 15:35:58 ----A---- C:\Windows\system32\msisip.dll
2010-04-21 15:35:58 ----A---- C:\Windows\system32\fc.exe
2010-04-21 15:35:57 ----A---- C:\Windows\system32\fdSSDP.dll
2010-04-21 15:35:57 ----A---- C:\Windows\system32\dmusic.dll
2010-04-21 15:35:56 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-04-21 15:35:56 ----A---- C:\Windows\system32\msjint40.dll
2010-04-21 15:35:56 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2010-04-21 15:35:56 ----A---- C:\Windows\system32\cscapi.dll
2010-04-21 15:35:55 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-04-21 15:35:55 ----A---- C:\Windows\system32\l2nacp.dll
2010-04-21 15:35:55 ----A---- C:\Windows\system32\ftp.exe
2010-04-21 15:35:55 ----A---- C:\Windows\system32\eapp3hst.dll
2010-04-21 15:35:55 ----A---- C:\Windows\system32\cscdll.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\wsdchngr.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\Storprop.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\SMBHelperClass.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\rasdial.exe
2010-04-21 15:35:54 ----A---- C:\Windows\system32\rasdiag.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-04-21 15:35:54 ----A---- C:\Windows\system32\bthudtask.exe
2010-04-21 15:35:54 ----A---- C:\Windows\system32\bthci.dll
2010-04-21 15:35:53 ----A---- C:\Windows\system32\ipconfig.exe
2010-04-21 15:35:53 ----A---- C:\Windows\system32\fdWCN.dll
2010-04-21 15:35:53 ----A---- C:\Windows\system32\eappcfg.dll
2010-04-21 15:35:53 ----A---- C:\Windows\system32\dot3cfg.dll
2010-04-21 15:35:52 ----A---- C:\Windows\system32\tscupgrd.exe
2010-04-21 15:35:52 ----A---- C:\Windows\system32\slcinst.dll
2010-04-21 15:35:52 ----A---- C:\Windows\system32\nslookup.exe
2010-04-21 15:35:52 ----A---- C:\Windows\system32\networkitemfactory.dll
2010-04-21 15:35:52 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2010-04-21 15:35:51 ----A---- C:\Windows\system32\ocsetup.exe
2010-04-21 15:35:51 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2010-04-21 15:35:51 ----A---- C:\Windows\system32\eappgnui.dll
2010-04-21 15:35:50 ----A---- C:\Windows\system32\hbaapi.dll
2010-04-21 15:35:50 ----A---- C:\Windows\system32\fdeploy.dll
2010-04-21 15:35:49 ----A---- C:\Windows\system32\mmcico.dll
2010-04-21 15:35:48 ----A---- C:\Windows\system32\PNPXAssoc.dll
2010-04-21 15:35:48 ----A---- C:\Windows\system32\gpupdate.exe
2010-04-21 15:35:47 ----A---- C:\Windows\system32\iscsilog.dll
2010-04-21 15:35:47 ----A---- C:\Windows\system32\csrstub.exe
2010-04-21 15:35:47 ----A---- C:\Windows\system32\cbsra.exe
2010-04-21 15:35:47 ----A---- C:\Windows\system32\bitsigd.dll
2010-04-21 15:35:46 ----A---- C:\Windows\system32\NcdProp.dll
2010-04-21 15:35:44 ----A---- C:\Windows\system32\winrnr.dll
2010-04-21 15:35:44 ----A---- C:\Windows\system32\vdmdbg.dll
2010-04-21 15:35:44 ----A---- C:\Windows\system32\slwga.dll
2010-04-21 15:35:44 ----A---- C:\Windows\system32\odbcconf.dll
2010-04-21 15:35:44 ----A---- C:\Windows\system32\inetppui.dll
2010-04-21 15:35:43 ----A---- C:\Windows\system32\midimap.dll
2010-04-21 15:35:40 ----A---- C:\Windows\system32\msimsg.dll
2010-04-21 15:35:40 ----A---- C:\Windows\system32\f3ahvoas.dll
2010-04-21 15:35:24 ----A---- C:\Windows\system32\SmiEngine.dll
2010-04-21 15:35:16 ----A---- C:\Windows\system32\wdscore.dll
2010-04-21 15:35:16 ----A---- C:\Windows\system32\PkgMgr.exe
2010-04-21 15:34:56 ----A---- C:\Windows\system32\drvstore.dll
2010-04-21 06:21:20 ----D---- C:\rsit
2010-04-19 16:47:54 ----A---- C:\Windows\system32\vbscript.dll
2010-04-19 16:47:52 ----A---- C:\Windows\system32\jscript.dll
2010-04-19 15:28:04 ----SHD---- C:\ProgramData\SecuROM
2010-04-19 15:16:53 ----D---- C:\PerfLogs
2010-04-19 07:31:53 ----A---- C:\Windows\system32\imagesp1.dll
2010-04-19 07:31:49 ----A---- C:\Windows\system32\sstpsvc.dll
2010-04-19 07:31:46 ----A---- C:\Windows\system32\winrscmd.dll
2010-04-19 07:31:34 ----A---- C:\Windows\system32\xpssvcs.dll
2010-04-19 07:31:30 ----A---- C:\Windows\system32\spwizimg.dll
2010-04-19 07:31:30 ----A---- C:\Windows\system32\lpremove.exe
2010-04-19 07:31:30 ----A---- C:\Windows\bfsvc.exe
2010-04-19 07:31:25 ----A---- C:\Windows\system32\recdisc.exe
2010-04-19 07:31:23 ----A---- C:\Windows\system32\CompMgmtLauncher.exe
2010-04-19 07:31:19 ----A---- C:\Windows\system32\msvbvm60.dll
2010-04-19 07:31:14 ----A---- C:\Windows\system32\MSMPEG2ADEC.DLL
2010-04-19 07:31:12 ----A---- C:\Windows\system32\xolehlp.dll
2010-04-19 07:31:09 ----A---- C:\Windows\system32\SSShim.dll
2010-04-19 07:31:08 ----A---- C:\Windows\system32\nlmgp.dll
2010-04-19 07:31:08 ----A---- C:\Windows\system32\DfsShlEx.dll
2010-04-19 07:31:05 ----A---- C:\Windows\system32\clusapi.dll
2010-04-19 07:31:03 ----A---- C:\Windows\system32\winrsmgr.dll
2010-04-19 07:31:01 ----A---- C:\Windows\system32\vdsbas.dll
2010-04-19 07:30:59 ----A---- C:\Windows\system32\comctl32.dll
2010-04-19 07:30:57 ----A---- C:\Windows\system32\msdtckrm.dll
2010-04-19 07:30:56 ----A---- C:\Windows\system32\XPSSHHDR.dll
2010-04-19 07:30:55 ----A---- C:\Windows\system32\sbe.dll
2010-04-19 07:30:54 ----A---- C:\Windows\system32\wecutil.exe
2010-04-19 07:30:54 ----A---- C:\Windows\system32\sdengin2.dll
2010-04-19 07:30:53 ----A---- C:\Windows\system32\gacinstall.dll
2010-04-19 07:30:53 ----A---- C:\Windows\system32\cmipnpinstall.dll
2010-04-19 07:30:53 ----A---- C:\Windows\system32\cmicryptinstall.dll
2010-04-19 07:30:52 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2010-04-19 07:30:50 ----A---- C:\Windows\system32\FirewallAPI.dll
2010-04-19 07:30:49 ----A---- C:\Windows\system32\wecsvc.dll
2010-04-19 07:30:49 ----A---- C:\Windows\system32\sqlceqp30.dll
2010-04-19 07:30:49 ----A---- C:\Windows\system32\lsm.exe
2010-04-19 07:30:46 ----A---- C:\Windows\system32\thumbcache.dll
2010-04-19 07:30:44 ----A---- C:\Windows\system32\d3d10_1.dll
2010-04-19 07:30:43 ----A---- C:\Windows\system32\authfwcfg.dll
2010-04-19 07:30:42 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-04-19 07:30:41 ----A---- C:\Windows\system32\dmvdsitf.dll
2010-04-19 07:30:39 ----A---- C:\Windows\system32\wevtfwd.dll
2010-04-19 07:30:39 ----A---- C:\Windows\system32\uexfat.dll
2010-04-19 07:30:38 ----A---- C:\Windows\system32\DfrgNtfs.exe
2010-04-19 07:30:37 ----A---- C:\Windows\system32\sqlcese30.dll
2010-04-19 07:30:34 ----A---- C:\Windows\system32\mssha.dll
2010-04-19 07:30:33 ----A---- C:\Windows\system32\dfrgui.exe
2010-04-19 07:30:32 ----A---- C:\Windows\system32\WsmAuto.dll
2010-04-19 07:30:32 ----A---- C:\Windows\system32\nlasvc.dll
2010-04-19 07:30:30 ----A---- C:\Windows\system32\wmdrmdev.dll
2010-04-19 07:30:29 ----A---- C:\Windows\system32\ddraw.dll
2010-04-19 07:30:28 ----A---- C:\Windows\system32\WsmWmiPl.dll
2010-04-19 07:30:28 ----A---- C:\Windows\system32\objsel.dll
2010-04-19 07:30:27 ----A---- C:\Windows\system32\dbghelp.dll
2010-04-19 07:30:26 ----A---- C:\Windows\system32\QAGENT.DLL
2010-04-19 07:30:25 ----A---- C:\Windows\system32\wmdrmnet.dll
2010-04-19 07:30:25 ----A---- C:\Windows\system32\icm32.dll
2010-04-19 07:30:24 ----A---- C:\Windows\system32\iprtrmgr.dll
2010-04-19 07:30:23 ----A---- C:\Windows\system32\bcdedit.exe
2010-04-19 07:30:22 ----A---- C:\Windows\system32\taskschd.dll
2010-04-19 07:30:21 ----A---- C:\Windows\system32\netprofm.dll
2010-04-19 07:30:21 ----A---- C:\Windows\system32\AudioEng.dll
2010-04-19 07:30:20 ----A---- C:\Windows\system32\winsta.dll
2010-04-19 07:30:19 ----A---- C:\Windows\system32\netcfgx.dll
2010-04-19 07:30:17 ----A---- C:\Windows\system32\lpksetup.exe
2010-04-19 07:30:17 ----A---- C:\Windows\system32\cdosys.dll
2010-04-19 07:30:15 ----A---- C:\Windows\system32\msdtcuiu.dll
2010-04-19 07:30:15 ----A---- C:\Windows\system32\mprddm.dll
2010-04-19 07:30:14 ----A---- C:\Windows\system32\eapsvc.dll
2010-04-19 07:30:14 ----A---- C:\Windows\system32\AUDIOKSE.dll
2010-04-19 07:30:13 ----A---- C:\Windows\system32\bcdsrv.dll
2010-04-19 07:30:11 ----A---- C:\Windows\system32\msidcrl30.dll
2010-04-19 07:30:10 ----A---- C:\Windows\system32\WMVDECOD.DLL
2010-04-19 07:30:09 ----A---- C:\Windows\system32\pla.dll
2010-04-19 07:30:09 ----A---- C:\Windows\system32\dxgi.dll
2010-04-19 07:30:09 ----A---- C:\Windows\system32\dot3gpui.dll
2010-04-19 07:30:06 ----A---- C:\Windows\system32\cryptnet.dll
2010-04-19 07:30:06 ----A---- C:\Windows\system32\comsnap.dll
2010-04-19 07:30:01 ----A---- C:\Windows\system32\synceng.dll
2010-04-19 07:30:01 ----A---- C:\Windows\system32\cmifw.dll
2010-04-19 07:29:59 ----A---- C:\Windows\system32\msconfig.exe
2010-04-19 07:29:56 ----A---- C:\Windows\system32\uxtheme.dll
2010-04-19 07:29:56 ----A---- C:\Windows\system32\tdh.dll
2010-04-19 07:29:56 ----A---- C:\Windows\system32\dmdskmgr.dll
2010-04-19 07:29:55 ----A---- C:\Windows\system32\SessEnv.dll
2010-04-19 07:29:55 ----A---- C:\Windows\system32\dot3api.dll
2010-04-19 07:29:55 ----A---- C:\Windows\system32\cmd.exe
2010-04-19 07:29:54 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2010-04-19 07:29:53 ----A---- C:\Windows\system32\loadperf.dll
2010-04-19 07:29:52 ----A---- C:\Windows\system32\WUDFx.dll
2010-04-19 07:29:52 ----A---- C:\Windows\system32\wlancfg.dll
2010-04-19 07:29:52 ----A---- C:\Windows\system32\msdtcVSp1res.dll
2010-04-19 07:29:52 ----A---- C:\Windows\system32\comres.dll
2010-04-19 07:29:51 ----A---- C:\Windows\system32\rstrui.exe
2010-04-19 07:29:51 ----A---- C:\Windows\system32\rdpdd.dll
2010-04-19 07:29:51 ----A---- C:\Windows\system32\localsec.dll
2010-04-19 07:29:50 ----A---- C:\Windows\system32\hnetcfg.dll
2010-04-19 07:29:49 ----A---- C:\Windows\system32\wsqmcons.exe
2010-04-19 07:29:49 ----A---- C:\Windows\system32\WMADMOD.DLL
2010-04-19 07:29:49 ----A---- C:\Windows\system32\WinSATAPI.dll
2010-04-19 07:29:49 ----A---- C:\Windows\system32\NAPMONTR.DLL
2010-04-19 07:29:46 ----A---- C:\Windows\system32\RDPENCDD.dll
2010-04-19 07:29:46 ----A---- C:\Windows\system32\profprov.dll
2010-04-19 07:29:46 ----A---- C:\Windows\system32\filemgmt.dll
2010-04-19 07:29:45 ----A---- C:\Windows\system32\wsecedit.dll
2010-04-19 07:29:45 ----A---- C:\Windows\system32\tracerpt.exe
2010-04-19 07:29:45 ----A---- C:\Windows\system32\MuiUnattend.exe
2010-04-19 07:29:44 ----A---- C:\Windows\system32\dwmredir.dll
2010-04-19 07:29:43 ----A---- C:\Windows\system32\wininit.exe
2010-04-19 07:29:43 ----A---- C:\Windows\system32\QSHVHOST.DLL
2010-04-19 07:29:42 ----A---- C:\Windows\system32\iashost.exe
2010-04-19 07:29:42 ----A---- C:\Windows\system32\azroleui.dll
2010-04-19 07:29:42 ----A---- C:\Windows\HelpPane.exe
2010-04-19 07:29:41 ----A---- C:\Windows\system32\mcbuilder.exe
2010-04-19 07:29:40 ----A---- C:\Windows\system32\srrstr.dll
2010-04-19 07:29:40 ----A---- C:\Windows\system32\spwizeng.dll
2010-04-19 07:29:40 ----A---- C:\Windows\system32\lltdsvc.dll
2010-04-19 07:29:39 ----A---- C:\Windows\system32\wecapi.dll
2010-04-19 07:29:39 ----A---- C:\Windows\system32\unbcl.dll
2010-04-19 07:29:39 ----A---- C:\Windows\system32\shrink.dll
2010-04-19 07:29:39 ----A---- C:\Windows\system32\msra.exe
2010-04-19 07:29:37 ----A---- C:\Windows\system32\WMPEncEn.dll
2010-04-19 07:29:37 ----A---- C:\Windows\system32\oleacc.dll
2010-04-19 07:29:36 ----A---- C:\Windows\system32\msdri.dll
2010-04-19 07:29:35 ----A---- C:\Windows\system32\framedynos.dll
2010-04-19 07:29:34 ----A---- C:\Windows\system32\vsstrace.dll
2010-04-19 07:29:34 ----A---- C:\Windows\system32\ntvdm.exe
2010-04-19 07:29:33 ----A---- C:\Windows\system32\wpdshext.dll