Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Win32Tr New help request to an old problem

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 26th, 2009, 8:26 pm

Hello there,

This is a new request for an old problem I see, but I have never seen an end result over all the posts I have read, so I am posting one myslef. I am quite computer savy, but the ont time I wish to try something new, I get hit with this bugger of a Malware program. I know where it came from, but can't get rid of it.

My husband is the IT guy in the family but is currently in TX for the next month. As a Realtor, I sort of need my computer for just about everything. The GOOD thing about my home is I also have a back-up laptop which I am using now while I'm trying to clean the infected one.

I got this little bugger earlier today. I am a night owl and have all evening to address this if there is someone willing to walk me through the cleaning process.

Thank you so much!!!

Daniele

PS I've already downloaded the Hijack this and ran the log. It is as follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:02:37 PM, on 8/26/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\temp\21419140.tmp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Starfield\Desktop Notifier\wben.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Printkey2000.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Daniele\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [wben] "C:\Program Files\Starfield\Desktop Notifier\wben.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Printkey2000.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://www.homesteadhotels.com/minisite ... SurVid.cab
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) - http://realist2.firstamres.com/mapviewer/mapviewer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EE6AB44-0BF6-4916-9C24-87BECAB10B24}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS1\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS2\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Windows MSI - Unknown owner - \\?\globalrootC:\Windows\system32\msihost.exe (file missing)

--
End of file - 8736 bytes
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm
Advertisement
Register to Remove

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 29th, 2009, 6:16 am

Hi Summerfield_DIY

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<< will be maximized) and info.txt (<< will be minimized)

Post:

- mbam log
- rsit logs (taken after mbam run)

Note: If you can't run mbam, rename its executable and it should run.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 30th, 2009, 12:06 am

Thank you for the reply and instructions, but there is one major problem.... I can not access the internet on the machine. It runs a "boot cleaner" and then bluescreens. I am sorry if I wasted your time. Looks like I will have to continue to use my backup computer and wait till my husband returns from TX to rebuild. - D
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 30th, 2009, 1:24 am

Can you maybe use a memory stick to transfer needed tools to infected computer?
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 30th, 2009, 12:17 pm

I downloaded your program to a thumb drive and installed it on my other laptop. This was done only after I was able to remove some of the files by removing the HD and hooking it up to a clean desktop usine it as an extrenal drive and running all the antivirus/spyware programs. Even though the bugger came back I was able to solve my bluescreen problem.

So I installed this Malware program on the infected machine and it won't run. nothing... Thoughts?
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 30th, 2009, 1:19 pm

Does it run after renaming mbam.exe?
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 30th, 2009, 2:05 pm

The program installs fine, but does not startup, so once again I removed the HD and brought it over to the safe Desktop, Installed the file there, updated it and it's in the process of doing a full scan.
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 30th, 2009, 2:54 pm

Good :)

Post back log when done, please.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 30th, 2009, 5:57 pm

ok.... all scans complete and the bugger is still there after reloading back into laptop. Below are the logs you requested.

From Malware (still does not run on infected machine)

Malwarebytes' Anti-Malware 1.40
Database version: 2719
Windows 6.0.6002 Service Pack 2

8/30/2009 4:01:48 PM
mbam-log-2009-08-30 (16-01-48).txt

Scan type: Full Scan (D:\|)
Objects scanned: 214319
Time elapsed: 58 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Users\Daniele\AppData\Local\Temp\.exe (Trojan.Alureon) -> Quarantined and deleted successfully.
D:\Windows\System32\ESQULitbqnremjqtvxvpxoervfjihxgjponql.dll (Trojan.Alureon) -> Quarantined and deleted successfully.



This is from the RSIT tool
Scanned in the laptop in safe mode.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Daniele at 2009-08-30 17:50:50
Microsoft® Windows Vista™ Business Service Pack 2
System drive C: has 37 GB (48%) free of 76 GB
Total RAM: 2037 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:50:53 PM, on 8/30/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
E:\RSIT.exe
C:\Windows\system32\DllHost.exe
C:\Users\Daniele\Desktop\Daniele.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [wben] "C:\Program Files\Starfield\Desktop Notifier\wben.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Printkey2000.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://www.homesteadhotels.com/minisite ... SurVid.cab
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) - http://realist2.firstamres.com/mapviewer/mapviewer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EE6AB44-0BF6-4916-9C24-87BECAB10B24}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS1\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CS2\Services\Tcpip\..\{1D351CBE-21F7-4B92-A9F5-016719119598}: NameServer = 85.255.112.193,85.255.112.174
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.193,85.255.112.174
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Windows MSI - Unknown owner - \\?\globalrootC:\Windows\system32\msihost.exe (file missing)

--
End of file - 8112 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{DCFF116E-0102-4418-A7BC-524103B7C742}.job
C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll [2008-05-22 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-26 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA}]
C:\Program Files\PicLensIE\cooliris.dll [2009-07-16 4700128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-20 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-08-13 520024]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\udaterui.exe [2008-03-14 136512]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2008-05-22 111952]
""= []
"HotSync"=C:\Program Files\PalmSource\Desktop\HotSync.exe -AllUsers []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-08-26 149280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-08-03 419088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-10 1233920]
"wben"=C:\Program Files\Starfield\Desktop Notifier\wben.exe [2009-06-25 338456]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Printkey2000.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-08-30 17:39:58 ----D---- C:\rsit
2009-08-30 12:06:06 ----D---- C:\ProgramData\Malwarebytes
2009-08-30 12:06:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-26 19:45:32 ----D---- C:\Windows\Minidump
2009-08-26 18:55:48 ----A---- C:\Windows\system32\javaws.exe
2009-08-26 18:55:48 ----A---- C:\Windows\system32\javaw.exe
2009-08-26 18:55:48 ----A---- C:\Windows\system32\java.exe
2009-08-26 17:05:29 ----A---- C:\Windows\ntbtlog.txt
2009-08-26 16:52:50 ----A---- C:\Windows\system32\lsdelete.exe
2009-08-26 01:34:12 ----A---- C:\Windows\Autorun MAX! 2.0 (Home Edition) Trial Uninstall Log.txt
2009-08-26 01:13:44 ----A---- C:\Windows\Autorun MAX!.INI
2009-08-26 01:13:42 ----AD---- C:\ProgramData\TEMP
2009-08-26 01:12:50 ----A---- C:\Windows\Autorun MAX! 2.0 (Home Edition) Trial Setup Log.txt
2009-08-25 23:10:48 ----D---- C:\Users\Daniele\AppData\Roaming\avidemux
2009-08-25 22:17:34 ----D---- C:\Users\Daniele\AppData\Roaming\IndigoRose
2009-08-25 22:16:58 ----D---- C:\Program Files\Autorun MAX
2009-08-25 22:16:17 ----A---- C:\Windows\Autorun MAX! 1.0 [Trial Edition] Setup Log.txt
2009-08-25 18:06:50 ----D---- C:\Users\Daniele\AppData\Roaming\U3
2009-08-25 03:00:22 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-08-23 23:48:07 ----A---- C:\Windows\system32\LVUI2RC.dll
2009-08-23 23:48:07 ----A---- C:\Windows\system32\LVUI2.dll
2009-08-23 23:48:07 ----A---- C:\Windows\system32\lvcoinst.ini
2009-08-23 23:48:07 ----A---- C:\Windows\system32\lvcodec2.dll
2009-08-23 23:48:07 ----A---- C:\Windows\system32\lvci1201278.dll
2009-08-23 23:47:14 ----D---- C:\ProgramData\LogiShrd
2009-08-23 23:47:14 ----D---- C:\Program Files\Logitech
2009-08-23 23:47:14 ----D---- C:\Program Files\Common Files\LogiShrd
2009-08-22 14:47:22 ----A---- C:\Windows\system32\GEARAspi.dll
2009-08-22 14:47:04 ----D---- C:\Program Files\iPod
2009-08-22 14:47:02 ----D---- C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-22 14:47:02 ----D---- C:\Program Files\iTunes
2009-08-22 14:45:13 ----D---- C:\Program Files\QuickTime
2009-08-22 14:39:42 ----D---- C:\Program Files\Bonjour
2009-08-17 11:29:32 ----A---- C:\Windows\system32\AUCPLMNT.DLL
2009-08-17 11:26:46 ----D---- C:\Program Files\Canon
2009-08-17 11:21:32 ----D---- C:\32BIT
2009-08-16 22:13:49 ----D---- C:\Program Files\Common Files\Roxio Shared
2009-08-16 12:31:57 ----D---- C:\Windows\system32\appmgmt
2009-08-15 22:51:46 ----D---- C:\Users\Daniele\AppData\Roaming\Research In Motion
2009-08-15 00:21:38 ----A---- C:\Windows\system32\deploytk.dll
2009-08-15 00:21:24 ----D---- C:\Program Files\Java
2009-08-15 00:21:02 ----D---- C:\Program Files\LimeWire
2009-08-14 23:24:38 ----D---- C:\Program Files\OverDrive Media Console
2009-08-14 23:21:08 ----D---- C:\Rfwin
2009-08-14 23:10:33 ----A---- C:\Windows\system32\cdintf251.dll
2009-08-14 23:10:32 ----A---- C:\RfLog.txt
2009-08-14 23:02:55 ----A---- C:\Windows\system32\InetClnt.dll
2009-08-14 23:02:49 ----D---- C:\Program Files\Common Files\AnswerWorks 4.0
2009-08-14 23:02:25 ----D---- C:\Program Files\Common Files\Intuit
2009-08-14 23:01:52 ----A---- C:\Windows\system32\cdintf.dll
2009-08-14 23:01:47 ----D---- C:\Program Files\Intuit
2009-08-14 23:01:40 ----A---- C:\Windows\system32\vba6.dll
2009-08-14 23:01:40 ----A---- C:\Windows\system32\spr32d30.dll
2009-08-14 23:01:39 ----A---- C:\Windows\system32\msvcr70.dll
2009-08-14 23:01:39 ----A---- C:\Windows\system32\msvcp70.dll
2009-08-14 23:01:39 ----A---- C:\Windows\system32\msvci70.dll
2009-08-14 23:01:39 ----A---- C:\Windows\system32\mfc70.dll
2009-08-14 23:01:37 ----HD---- C:\Program Files\Installshield Installation Information
2009-08-14 22:52:44 ----D---- C:\Windows\Intuit
2009-08-14 22:40:44 ----D---- C:\Program Files\Picasa2
2009-08-14 22:39:01 ----D---- C:\Program Files\Picasa_2
2009-08-14 22:34:13 ----D---- C:\Program Files\WebEx
2009-08-14 22:22:04 ----D---- C:\Users\Daniele\AppData\Roaming\Apple Computer
2009-08-14 22:20:57 ----D---- C:\ProgramData\Apple Computer
2009-08-14 22:20:45 ----D---- C:\Program Files\Apple Software Update
2009-08-14 22:20:20 ----D---- C:\ProgramData\Apple
2009-08-14 22:20:20 ----D---- C:\Program Files\Common Files\Apple
2009-08-14 22:17:51 ----D---- C:\Program Files\PicLensIE
2009-08-14 22:15:28 ----D---- C:\Program Files\Avidemux 2.4
2009-08-14 22:10:43 ----D---- C:\Users\Daniele\AppData\Roaming\Arcsoft
2009-08-14 22:10:12 ----D---- C:\Program Files\Palm
2009-08-14 22:09:19 ----D---- C:\Users\Daniele\AppData\Roaming\HotSync
2009-08-14 22:09:19 ----D---- C:\ProgramData\HotSync
2009-08-14 22:08:58 ----D---- C:\Program Files\Common Files\InstallShield
2009-08-14 22:03:51 ----D---- C:\Program Files\Common Files\Research In Motion
2009-08-14 22:03:43 ----D---- C:\Program Files\Research In Motion
2009-08-14 21:56:01 ----D---- C:\Users\Daniele\AppData\Roaming\DivX
2009-08-14 21:46:09 ----D---- C:\Program Files\Google
2009-08-14 21:37:45 ----D---- C:\Program Files\Microsoft
2009-08-14 21:37:25 ----D---- C:\Program Files\Windows Live SkyDrive
2009-08-14 21:34:07 ----D---- C:\Program Files\Common Files\Windows Live
2009-08-14 21:10:39 ----A---- C:\Windows\system32\gpprefcl.dll
2009-08-14 21:09:55 ----D---- C:\Program Files\MSXML 4.0
2009-08-14 21:05:00 ----A---- C:\Windows\IsUninst.exe
2009-08-14 20:37:03 ----D---- C:\Incomplete
2009-08-14 20:36:58 ----D---- C:\Web Site
2009-08-14 20:36:53 ----D---- C:\temp
2009-08-14 01:14:46 ----D---- C:\Windows\Panther
2009-08-14 01:14:32 ----RAS---- C:\BOOTSECT.BAK
2009-08-14 01:14:31 ----SHD---- C:\Boot
2009-08-14 01:14:14 ----D---- C:\Windows\system32\OEM
2009-08-14 01:06:55 ----D---- C:\Program Files\Microsoft Streets & Trips
2009-08-14 01:06:55 ----D---- C:\Program Files\Microsoft Location Finder
2009-08-14 01:01:59 ----D---- C:\Program Files\Starfield
2009-08-14 01:00:42 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-08-14 01:00:28 ----D---- C:\Program Files\DivX
2009-08-14 01:00:28 ----D---- C:\Program Files\Common Files\DivX Shared
2009-08-14 00:43:31 ----A---- C:\Windows\ODBC.INI
2009-08-14 00:43:28 ----A---- C:\Windows\system32\mdimon.dll
2009-08-14 00:42:12 ----D---- C:\Program Files\Common Files\L&H
2009-08-14 00:41:58 ----D---- C:\Program Files\Microsoft ActiveSync
2009-08-14 00:41:36 ----D---- C:\Program Files\Common Files\DESIGNER
2009-08-14 00:41:33 ----D---- C:\Program Files\Microsoft Works
2009-08-14 00:41:26 ----D---- C:\Program Files\Microsoft Visual Studio
2009-08-14 00:40:24 ----D---- C:\Program Files\Microsoft.NET
2009-08-14 00:40:24 ----D---- C:\Program Files\Microsoft Office
2009-08-14 00:38:19 ----RHD---- C:\MSOCache
2009-08-14 00:22:01 ----D---- C:\Windows\Debug
2009-08-14 00:18:07 ----D---- C:\Windows\SoftwareDistribution
2009-08-14 00:17:46 ----D---- C:\IE_Shares
2009-08-14 00:16:54 ----D---- C:\Windows\CSC
2009-08-14 00:15:29 ----D---- C:\Windows\Prefetch
2009-08-14 00:15:19 ----SHD---- C:\System Volume Information
2009-08-13 23:47:06 ----D---- C:\Users\Daniele\AppData\Roaming\Nero
2009-08-13 23:46:37 ----A---- C:\Windows\system32\MsiExec.exe.log
2009-08-13 23:44:40 ----D---- C:\ProgramData\Nero
2009-08-13 23:44:40 ----D---- C:\Program Files\Nero
2009-08-13 23:44:39 ----D---- C:\Program Files\Common Files\Nero
2009-08-13 23:42:01 ----A---- C:\Windows\system32\d3dx9_30.dll
2009-08-13 23:42:00 ----A---- C:\Windows\system32\d3dx9_28.dll
2009-08-13 23:29:13 ----D---- C:\ProgramData\FLEXnet
2009-08-13 23:29:03 ----D---- C:\Program Files\Common Files\Macrovision Shared
2009-08-13 23:28:46 ----RA---- C:\Windows\system32\AdobePDF.dll
2009-08-13 23:22:46 ----D---- C:\ProgramData\Adobe
2009-08-13 23:22:46 ----D---- C:\Program Files\Common Files\Adobe
2009-08-13 23:22:46 ----D---- C:\Program Files\Adobe
2009-08-13 23:11:08 ----D---- C:\Users\Daniele\AppData\Roaming\Macromedia
2009-08-13 23:11:08 ----D---- C:\Users\Daniele\AppData\Roaming\Adobe
2009-08-13 23:00:55 ----D---- C:\Windows\system32\Macromed
2009-08-13 23:00:47 ----D---- C:\QUARANTINE
2009-08-13 23:00:22 ----D---- C:\ProgramData\Yahoo!
2009-08-13 23:00:21 ----D---- C:\Program Files\Yahoo!
2009-08-13 22:58:30 ----D---- C:\Windows\PCHEALTH
2009-08-13 22:58:30 ----D---- C:\Program Files\Windows Live
2009-08-13 22:40:15 ----D---- C:\Program Files\Common Files\McAfee
2009-08-13 22:38:47 ----D---- C:\Program Files\Common Files\Cisco Systems
2009-08-13 22:38:45 ----D---- C:\ProgramData\McAfee
2009-08-13 22:38:45 ----D---- C:\Program Files\McAfee
2009-08-13 22:33:04 ----DC---- C:\Windows\system32\DRVSTORE
2009-08-13 22:31:18 ----D---- C:\Windows\system32\x64
2009-08-13 22:31:18 ----A---- C:\Windows\system32\igxpun.exe
2009-08-13 22:31:17 ----A---- C:\Windows\system32\difxapi.dll
2009-08-13 22:27:43 ----A---- C:\Windows\system32\occache.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\wininet.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\msfeeds.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\jsproxy.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\ieui.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\iesetup.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\iernonce.dll
2009-08-13 22:27:42 ----A---- C:\Windows\system32\iepeers.dll
2009-08-13 22:27:41 ----A---- C:\Windows\system32\urlmon.dll
2009-08-13 22:27:41 ----A---- C:\Windows\system32\msfeedssync.exe
2009-08-13 22:27:41 ----A---- C:\Windows\system32\ieUnatt.exe
2009-08-13 22:27:41 ----A---- C:\Windows\system32\iesysprep.dll
2009-08-13 22:27:41 ----A---- C:\Windows\system32\iertutil.dll
2009-08-13 22:27:41 ----A---- C:\Windows\system32\iedkcs32.dll
2009-08-13 22:27:41 ----A---- C:\Windows\system32\ie4uinit.exe
2009-08-13 22:27:40 ----A---- C:\Windows\system32\mshtml.dll
2009-08-13 22:27:40 ----A---- C:\Windows\system32\ieframe.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\msls31.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\mshtmler.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\mshtmled.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\icardie.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\corpol.dll
2009-08-13 22:27:05 ----A---- C:\Windows\system32\admparse.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\msrating.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\licmgr10.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\inseng.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\imgutil.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\ieaksie.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\ieakeng.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\dxtrans.dll
2009-08-13 22:27:04 ----A---- C:\Windows\system32\dxtmsft.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-08-13 22:27:03 ----A---- C:\Windows\system32\wextract.exe
2009-08-13 22:27:03 ----A---- C:\Windows\system32\webcheck.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\pngfilt.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\mstime.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\ieapfltr.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\ieakui.dll
2009-08-13 22:27:03 ----A---- C:\Windows\system32\advpack.dll
2009-08-13 22:27:02 ----A---- C:\Windows\system32\vbscript.dll
2009-08-13 22:27:02 ----A---- C:\Windows\system32\url.dll
2009-08-13 22:27:02 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-08-13 22:27:02 ----A---- C:\Windows\system32\SetDepNx.exe
2009-08-13 22:27:02 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-08-13 22:27:02 ----A---- C:\Windows\system32\PDMSetup.exe
2009-08-13 22:27:02 ----A---- C:\Windows\system32\mshta.exe
2009-08-13 22:27:02 ----A---- C:\Windows\system32\jscript.dll
2009-08-13 22:27:02 ----A---- C:\Windows\system32\iexpress.exe
2009-08-13 22:25:31 ----A---- C:\Windows\system32\wdigest.dll
2009-08-13 22:25:31 ----A---- C:\Windows\system32\schannel.dll
2009-08-13 22:25:31 ----A---- C:\Windows\system32\msv1_0.dll
2009-08-13 22:25:31 ----A---- C:\Windows\system32\kerberos.dll
2009-08-13 22:25:30 ----A---- C:\Windows\system32\secur32.dll
2009-08-13 22:25:30 ----A---- C:\Windows\system32\lsass.exe
2009-08-13 22:25:30 ----A---- C:\Windows\system32\lsasrv.dll
2009-08-13 22:25:28 ----A---- C:\Windows\system32\avifil32.dll
2009-08-13 22:25:10 ----A---- C:\Windows\system32\wmp.dll
2009-08-13 22:25:08 ----A---- C:\Windows\system32\wmploc.DLL
2009-08-13 22:25:08 ----A---- C:\Windows\system32\wmpdxm.dll
2009-08-13 22:25:08 ----A---- C:\Windows\system32\spwmp.dll
2009-08-13 22:25:08 ----A---- C:\Windows\system32\dxmasf.dll
2009-08-13 22:25:06 ----A---- C:\Windows\system32\mstscax.dll
2009-08-13 22:25:05 ----A---- C:\Windows\system32\atl.dll
2009-08-13 22:25:04 ----A---- C:\Windows\system32\localspl.dll
2009-08-13 22:25:03 ----A---- C:\Windows\system32\t2embed.dll
2009-08-13 22:25:03 ----A---- C:\Windows\system32\lpk.dll
2009-08-13 22:25:03 ----A---- C:\Windows\system32\fontsub.dll
2009-08-13 22:25:03 ----A---- C:\Windows\system32\dciman32.dll
2009-08-13 22:25:03 ----A---- C:\Windows\system32\atmfd.dll
2009-08-13 22:25:01 ----A---- C:\Windows\system32\wkssvc.dll
2009-08-13 22:23:11 ----A---- C:\Windows\system32\rpcrt4.dll
2009-08-13 22:21:03 ----HDC---- C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-08-13 22:20:58 ----D---- C:\ProgramData\Lavasoft
2009-08-13 22:20:58 ----D---- C:\Program Files\Lavasoft
2009-08-13 22:20:14 ----A---- C:\Windows\system32\wups2.dll
2009-08-13 22:20:14 ----A---- C:\Windows\system32\wucltux.dll
2009-08-13 22:20:14 ----A---- C:\Windows\system32\wuauclt.exe
2009-08-13 22:20:13 ----A---- C:\Windows\system32\wuaueng.dll
2009-08-13 22:20:03 ----A---- C:\Windows\system32\wups.dll
2009-08-13 22:20:03 ----A---- C:\Windows\system32\wudriver.dll
2009-08-13 22:20:02 ----A---- C:\Windows\system32\wuapi.dll
2009-08-13 22:19:56 ----A---- C:\Windows\system32\wuwebv.dll
2009-08-13 22:19:56 ----A---- C:\Windows\system32\wuapp.exe
2009-08-13 22:17:22 ----D---- C:\EasyPicture
2009-08-13 22:17:20 ----N---- C:\Windows\Setup1.exe
2009-08-13 22:16:42 ----A---- C:\Windows\ST6UNST.EXE
2009-08-13 22:09:39 ----D---- C:\Windows\system32\vi-VN
2009-08-13 22:09:39 ----D---- C:\Windows\system32\eu-ES
2009-08-13 22:09:39 ----D---- C:\Windows\system32\ca-ES
2009-08-13 22:07:33 ----D---- C:\Windows\system32\SPReview
2009-08-13 22:01:29 ----A---- C:\Windows\system32\scavenge.dll
2009-08-13 22:01:25 ----A---- C:\Windows\system32\compcln.exe
2009-08-13 22:01:09 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2009-08-13 22:01:09 ----A---- C:\Windows\system32\secproc_ssp.dll
2009-08-13 22:01:09 ----A---- C:\Windows\system32\secproc_isv.dll
2009-08-13 22:01:09 ----A---- C:\Windows\system32\secproc.dll
2009-08-13 22:01:09 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2009-08-13 22:01:09 ----A---- C:\Windows\system32\SearchFilterHost.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\SearchIndexer.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\sdohlp.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\sdclt.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scrrun.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scrptadm.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scrobj.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scksp.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\schedsvc.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scesrv.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scecli.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\SCardSvr.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\scansetting.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\samsrv.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\samlib.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rwinsta.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rtutils.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rtffilt.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rsaenh.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rrinstaller.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rpcss.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\rpchttp.dll
2009-08-13 22:01:08 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\RMActivate.exe
2009-08-13 22:01:08 ----A---- C:\Windows\system32\riched20.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\powercpl.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PNPXAssoc.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PnPutil.exe
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PnPUnattend.exe
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pnpui.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pnpsetup.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pnidui.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pmcsnap.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PkgMgr.exe
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pidgenx.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\photowiz.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\perfdisk.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pdh.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\pcaui.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\p2psvc.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\P2PGraph.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\ntdll.dll
2009-08-13 22:01:06 ----A---- C:\Windows\system32\nslookup.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rastls.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rastapi.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasmontr.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasmans.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasgcw.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasdlg.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasdial.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasdiag.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\raschap.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\rasapi32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\osk.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\oobefldr.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\onex.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\olepro32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\oleprn.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\oleaut32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ole32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\offfilt.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\odbccp32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\odbcconf.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\odbc32.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ocsetup.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ntprint.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ntmarta.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-08-13 22:01:05 ----A---- C:\Windows\system32\NlsLexicons0009.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\NlsLexicons0007.dll
2009-08-13 22:01:05 ----A---- C:\Windows\system32\nlhtml.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\reset.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\RelMon.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rekeywiz.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\regsvc.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\regapi.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\reg.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rdpwsx.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rdpendp.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rdpencom.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rdpclip.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rasppp.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\rasplap.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\RacEngn.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\query.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\Query.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\quartz.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\qprocess.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\qmgr.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\qedit.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\prnntfy.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\printui.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PrintBrmUi.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PresentationSettings.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PresentationHost.exe
2009-08-13 22:01:04 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-08-13 22:01:04 ----A---- C:\Windows\system32\powrprof.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\shlwapi.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\shell32.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\shdocvw.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\sendmail.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\qdvd.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\qappsrv.exe
2009-08-13 22:01:03 ----A---- C:\Windows\system32\QAGENTRT.DLL
2009-08-13 22:01:03 ----A---- C:\Windows\system32\puiapi.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\psisdecd.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\PSHED.DLL
2009-08-13 22:01:03 ----A---- C:\Windows\system32\propsys.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\propdefs.dll
2009-08-13 22:01:03 ----A---- C:\Windows\system32\profsvc.dll
2009-08-13 22:01:02 ----A---- C:\Windows\system32\shadow.exe
2009-08-13 22:01:02 ----A---- C:\Windows\system32\setupapi.dll
2009-08-13 22:01:02 ----A---- C:\Windows\system32\sethc.exe
2009-08-13 22:01:02 ----A---- C:\Windows\system32\services.exe
2009-08-13 22:01:00 ----A---- C:\Windows\system32\EhStorAPI.dll
2009-08-13 22:01:00 ----A---- C:\Windows\system32\eapphost.dll
2009-08-13 22:01:00 ----A---- C:\Windows\system32\eappgnui.dll
2009-08-13 22:01:00 ----A---- C:\Windows\system32\eappcfg.dll
2009-08-13 22:01:00 ----A---- C:\Windows\system32\eapp3hst.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\f3ahvoas.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\ExplorerFrame.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\evr.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\eudcedit.exe
2009-08-13 22:00:59 ----A---- C:\Windows\system32\esent.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\EncDec.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\emdmgmt.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\EhStorPwdMgr.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\EhStorAuthn.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\dwm.exe
2009-08-13 22:00:59 ----A---- C:\Windows\system32\dsprop.dll
2009-08-13 22:00:59 ----A---- C:\Windows\system32\dsound.dll
2009-08-13 22:00:59 ----A---- C:\Windows\explorer.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\hbaapi.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\gpscript.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\gpresult.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\gpprnext.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\es.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\EhStorShell.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\drvstore.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\drvinst.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\drmv2clt.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\drmmgrtn.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dpapimig.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dot3svc.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dot3msm.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dot3cfg.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dnsrslvr.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dnsapi.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dmusic.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dmsynth.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\diskraid.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\diskpart.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dimsroam.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\diagperf.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dhcpcsvc.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dfsr.exe
2009-08-13 22:00:58 ----A---- C:\Windows\system32\dfshim.dll
2009-08-13 22:00:58 ----A---- C:\Windows\system32\devmgr.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\iasnap.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\IasMigReader.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\IasMigPlugin.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\iashlpr.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\iasdatastore.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\iasads.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\iasacct.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\hidserv.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\hdwwiz.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\gpupdate.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\gpsvc.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\gpscript.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\gpapi.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\gdi32.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fontext.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\findstr.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\feclient.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdWSD.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdWCN.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdSSDP.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdProxy.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdeploy.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdBthProxy.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fdBth.dll
2009-08-13 22:00:57 ----A---- C:\Windows\system32\fc.exe
2009-08-13 22:00:57 ----A---- C:\Windows\system32\Faultrep.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\gpedit.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\gameux.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\FwRemoteSvr.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2009-08-13 22:00:56 ----A---- C:\Windows\system32\fundisc.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\FunctionDiscoveryFolder.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\ftp.exe
2009-08-13 22:00:56 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\autoplay.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\autofmt.exe
2009-08-13 22:00:56 ----A---- C:\Windows\system32\autoconv.exe
2009-08-13 22:00:56 ----A---- C:\Windows\system32\autochk.exe
2009-08-13 22:00:56 ----A---- C:\Windows\system32\authz.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\authui.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\audiosrv.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\AudioSes.dll
2009-08-13 22:00:56 ----A---- C:\Windows\system32\audiodg.exe
2009-08-13 22:00:56 ----A---- C:\Windows\system32\atmlib.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\bthci.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\browseui.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\brcplsiw.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\brcpl.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\blackbox.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\bitsigd.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\BFE.DLL
2009-08-13 22:00:55 ----A---- C:\Windows\system32\bcrypt.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\basecsp.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\azroles.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\apphelp.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\apds.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\accessibilitycpl.dll
2009-08-13 22:00:55 ----A---- C:\Windows\system32\aaclient.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\DevicePairingWizard.exe
2009-08-13 22:00:54 ----A---- C:\Windows\system32\DevicePairingProxy.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\DevicePairing.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\DeviceEject.exe
2009-08-13 22:00:54 ----A---- C:\Windows\system32\dbgeng.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\davclnt.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\dataclen.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\d3d9.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\CscMig.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\cscdll.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\crypt32.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\credui.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\connect.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\conime.exe
2009-08-13 22:00:54 ----A---- C:\Windows\system32\comuid.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\comsvcs.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\comdlg32.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\cmmon32.exe
2009-08-13 22:00:54 ----A---- C:\Windows\system32\cmdial32.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\appmgmts.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\advapi32.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\adtschema.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\adsmsext.dll
2009-08-13 22:00:54 ----A---- C:\Windows\system32\adsldpc.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\msftedit.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\csrstub.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cscui.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cscsvc.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cscript.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cscobj.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cscapi.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cryptui.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cryptsvc.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cipher.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\ci.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\chtbrkr.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\chsbrkr.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\chgusr.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\chgport.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\chglogon.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\change.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\certutil.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\certreq.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\certprop.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\certmgr.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\CertEnrollUI.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\CertEnroll.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\certcli.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cdd.dll
2009-08-13 22:00:53 ----A---- C:\Windows\system32\cbsra.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\bthudtask.exe
2009-08-13 22:00:53 ----A---- C:\Windows\system32\bthserv.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msimsg.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msihnd.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msiexec.exe
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msi.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msexcl40.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msexch40.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msdtctm.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msdtcprx.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msdrm.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msctfui.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msctfp.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\MsCtfMonitor.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\msctf.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\MPSSVC.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\mprapi.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\mpr.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\modemui.dll
2009-08-13 22:00:52 ----A---- C:\Windows\system32\MMDevAPI.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\NetProjW.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\netplwiz.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\netlogon.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\netiohlp.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\netcenter.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\netapi32.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\ncryptui.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\ncrypt.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mtxclu.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mscories.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mscorier.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mscoree.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mscms.dll
2009-08-13 22:00:51 ----A---- C:\Windows\system32\mscandui.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\newdev.exe
2009-08-13 22:00:50 ----A---- C:\Windows\system32\newdev.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\networkmap.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\networkitemfactory.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\networkexplorer.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\netshell.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\NcdProp.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msxml6.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msxml3.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msxbde40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mswstr10.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mswsock.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mswdat10.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\MSVidCtl.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msvcrt.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msvcp60.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msutb.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mssrch.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mssprxy.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mssphtb.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mssph.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mssitlb.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msshsq.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msshooks.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msscp.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msscntrs.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msscb.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msrepl40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msrd3x40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msrd2x40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\mspbde40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msnetobj.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msltus40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msjtes40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msjter40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msjint40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msjetoledb40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msjet40.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msisip.dll
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msinfo32.exe
2009-08-13 22:00:50 ----A---- C:\Windows\system32\msimtf.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\mstsc.exe
2009-08-13 22:00:49 ----A---- C:\Windows\system32\mstlsapi.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\mstext40.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\mssvp.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\msstrc.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\iscsilog.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\ipsmsnap.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\IPSECSVC.DLL
2009-08-13 22:00:49 ----A---- C:\Windows\system32\ipsecsnp.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\input.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\InkEd.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\infocardapi.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\inetppui.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\inetpp.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\inetcomm.dll
2009-08-13 22:00:49 ----A---- C:\Windows\system32\imm32.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iphlpsvc.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2009-08-13 22:00:48 ----A---- C:\Windows\system32\ipconfig.exe
2009-08-13 22:00:48 ----A---- C:\Windows\system32\ifmon.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\icardres.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\icardagt.exe
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iassvcs.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iassdo.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iassam.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iasrecst.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iasrad.dll
2009-08-13 22:00:48 ----A---- C:\Windows\system32\iaspolcy.dll
2009-08-13 22:00:47 ----A---- C:\Windows\system32\IMJP10K.DLL
2009-08-13 22:00:47 ----A---- C:\Windows\system32\imapi2fs.dll
2009-08-13 22:00:47 ----A---- C:\Windows\system32\imapi2.dll
2009-08-13 22:00:47 ----A---- C:\Windows\system32\imapi.dll
2009-08-13 22:00:47 ----A---- C:\Windows\system32\IKEEXT.DLL
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mmcndmgr.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mmcico.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mmci.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mmc.exe
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mimefilt.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\milcore.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\midimap.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mfps.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mfpmp.exe
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mfplat.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mferror.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mfc42u.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mfc42.dll
2009-08-13 22:00:46 ----A---- C:\Windows\system32\mf.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\wercon.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\wer.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\WebClnt.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\wdscore.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\wdc.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\shsetup.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\mblctr.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\Magnify.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\logoff.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\logman.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\logagent.exe
2009-08-13 22:00:45 ----A---- C:\Windows\system32\l2nacp.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\korwbrkr.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\kernel32.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\kdusb.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\kdcom.dll
2009-08-13 22:00:45 ----A---- C:\Windows\system32\kd1394.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wscisvif.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WscEapPr.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wscapi.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\winhttp.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\win32spl.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wiaservc.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wiaaut.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\whealogr.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WFS.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wevtutil.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wevtsvc.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wevtapi.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wersvc.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WerFaultSecure.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WerFault.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wcnwiz2.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wcnwiz.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\WcnNetsh.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wcncsvc.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\wbengine.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\w32time.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\VSSVC.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\vssapi.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\version.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\vdsutil.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\vdsdyn.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\vds.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\vdmdbg.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\uxsms.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\Utilman.exe
2009-08-13 22:00:44 ----A---- C:\Windows\system32\usp10.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\userenv.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\usercpl.dll
2009-08-13 22:00:44 ----A---- C:\Windows\system32\user32.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\xmlfilter.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wusa.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wsnmp32.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WsmSvc.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wshext.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wshbth.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wsepno.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WSDMon.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wsdchngr.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WSDApi.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wscsvc.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wscript.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wscntfy.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wow32.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMVXENCD.DLL
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMVSDECD.DLL
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMVENCOD.DLL
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wmpmde.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMPhoto.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wmpeffects.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WMNetMgr.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlgpclnt.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\Wldap32.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlanui.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlansvc.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlanpref.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlanmsm.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlanhlp.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wlangpui.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\wisptis.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winsrv.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WinSCard.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\WinSAT.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winrnr.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winresume.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winmm.dll
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winlogon.exe
2009-08-13 22:00:43 ----A---- C:\Windows\system32\winload.exe
2009-08-13 22:00:42 ----A---- C:\Windows\system32\wmicmiplugin.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\wmdrmsdk.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\sysmain.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\sud.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\Storprop.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\stobject.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\srvsvc.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\srcore.dll
2009-08-13 22:00:42 ----A---- C:\Windows\system32\srchadmin.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\sysclass.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SyncCenter.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\swprv.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\spoolss.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\spinstall.exe
2009-08-13 22:00:41 ----A---- C:\Windows\system32\smss.exe
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SmiEngine.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SMBHelperClass.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\slwmi.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\slwga.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLUINotify.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLUI.exe
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLsvc.exe
2009-08-13 22:00:41 ----A---- C:\Windows\system32\slmgr.vbs
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLLUA.exe
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLCommDlg.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\slcinst.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLCExt.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\slcc.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\SLC.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\shwebsvc.dll
2009-08-13 22:00:41 ----A---- C:\Windows\system32\shsvcs.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\zipfldr.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\untfs.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\TsWpfWrp.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\TSTheme.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\tskill.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\tsgqec.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\tsdiscon.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\tscupgrd.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\sqlsrv32.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spwizui.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spwinsat.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spreview.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spp.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spoolsv.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\sperror.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\spcmsg.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\softkbd.dll
2009-08-13 22:00:40 ----A---- C:\Windows\system32\SnippingTool.exe
2009-08-13 22:00:40 ----A---- C:\Windows\system32\SndVol.exe
2009-08-13 22:00:39 ----A---- C:\Windows\system32\umrdp.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\umpnpmgr.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\ulib.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\uDWM.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\tscon.exe
2009-08-13 22:00:39 ----A---- C:\Windows\system32\tscfgwmi.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\tsbyuv.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\tquery.dll
2009-08-13 22:00:39 ----A---- C:\Windows\system32\systemcpl.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\themeui.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\themecpl.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\thawbrkr.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\termsrv.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\tcpmon.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\tcpipcfg.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\taskeng.exe
2009-08-13 22:00:38 ----A---- C:\Windows\system32\taskcomp.dll
2009-08-13 22:00:38 ----A---- C:\Windows\system32\tapisrv.dll
2009-08-13 21:57:56 ----D---- C:\Windows\system32\EventProviders
2009-08-13 21:46:20 ----D---- C:\Program Files\Brice Lambson
2009-08-13 21:42:57 ----D---- C:\Program Files\Microsoft Games
2009-08-13 21:36:54 ----D---- C:\Users\Daniele\AppData\Roaming\Intel
2009-08-13 21:36:53 ----D---- C:\ProgramData\Roaming
2009-08-13 21:36:30 ----D---- C:\Program Files\Cisco
2009-08-13 21:36:28 ----D---- C:\ProgramData\Intel
2009-08-13 21:36:28 ----D---- C:\Program Files\Intel
2009-08-13 21:36:28 ----D---- C:\Program Files\Common Files\Intel
2009-08-13 21:36:13 ----A---- C:\Windows\iProInstLog.txt
2009-08-13 21:36:10 ----SHD---- C:\Windows\Installer
2009-08-13 21:21:11 ----D---- C:\Users\Daniele\AppData\Roaming\Identities
2009-08-13 21:21:03 ----SD---- C:\Users\Daniele\AppData\Roaming\Microsoft

======List of files/folders modified in the last 1 months======

2009-08-30 17:42:19 ----D---- C:\Windows\system32\drivers
2009-08-30 17:38:15 ----D---- C:\Windows\System32
2009-08-30 13:48:55 ----D---- C:\Windows\Temp
2009-08-30 13:47:42 ----D---- C:\Windows
2009-08-30 12:06:06 ----RD---- C:\Program Files
2009-08-30 12:06:06 ----HD---- C:\ProgramData
2009-08-29 20:56:30 ----SHD---- C:\$Recycle.Bin
2009-08-26 19:48:24 ----D---- C:\Windows\system32\catroot2
2009-08-26 19:45:47 ----D---- C:\Windows\system32\Tasks
2009-08-26 19:45:43 ----D---- C:\Windows\Tasks
2009-08-26 18:15:02 ----RD---- C:\Users
2009-08-26 10:50:17 ----D---- C:\Windows\inf
2009-08-26 09:29:44 ----D---- C:\Windows\system32\catroot
2009-08-26 09:29:38 ----D---- C:\Windows\winsxs
2009-08-25 01:01:41 ----D---- C:\Windows\system32\LogFiles
2009-08-24 10:05:05 ----D---- C:\Windows\system32\WDI
2009-08-23 23:50:23 ----D---- C:\Windows\twain_32
2009-08-23 23:47:14 ----D---- C:\Program Files\Common Files
2009-08-18 15:02:00 ----SD---- C:\Windows\Downloaded Program Files
2009-08-15 01:32:30 ----RSD---- C:\Windows\assembly
2009-08-15 01:31:33 ----A---- C:\Windows\win.ini
2009-08-14 23:01:43 ----RSD---- C:\Windows\Fonts
2009-08-14 22:47:41 ----D---- C:\Windows\Microsoft.NET
2009-08-14 22:21:20 ----D---- C:\Program Files\Internet Explorer
2009-08-14 21:37:32 ----D---- C:\Program Files\Common Files\microsoft shared
2009-08-14 21:33:53 ----SD---- C:\ProgramData\Microsoft
2009-08-14 21:21:46 ----D---- C:\Windows\rescache
2009-08-14 21:10:46 ----D---- C:\Windows\system32\wbem
2009-08-14 21:10:46 ----D---- C:\Windows\system32\en-US
2009-08-14 03:43:20 ----D---- C:\Windows\Logs
2009-08-14 02:02:41 ----D---- C:\Windows\system32\NDF
2009-08-14 00:44:53 ----D---- C:\Windows\system
2009-08-14 00:42:06 ----D---- C:\Windows\IME
2009-08-14 00:42:04 ----D---- C:\Windows\ShellNew
2009-08-14 00:41:19 ----D---- C:\Program Files\Common Files\System
2009-08-14 00:41:11 ----D---- C:\Windows\Help
2009-08-13 23:44:38 ----D---- C:\Windows\Cursors
2009-08-13 22:33:29 ----D---- C:\Windows\system32\migration
2009-08-13 22:33:29 ----D---- C:\Program Files\Windows Media Player
2009-08-13 22:33:29 ----D---- C:\Program Files\Windows Mail
2009-08-13 22:33:28 ----D---- C:\Windows\PolicyDefinitions
2009-08-13 22:09:54 ----D---- C:\Windows\servicing
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Sidebar
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Photo Gallery
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Journal
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Defender
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Collaboration
2009-08-13 22:09:54 ----D---- C:\Program Files\Windows Calendar
2009-08-13 22:09:54 ----D---- C:\Program Files\Movie Maker
2009-08-13 22:09:53 ----D---- C:\Windows\system32\XPSViewer
2009-08-13 22:09:53 ----D---- C:\Windows\system32\sk-SK
2009-08-13 22:09:53 ----D---- C:\Windows\system32\lv-LV
2009-08-13 22:09:53 ----D---- C:\Windows\system32\ko-KR
2009-08-13 22:09:53 ----D---- C:\Windows\system32\hr-HR
2009-08-13 22:09:53 ----D---- C:\Windows\system32\et-EE
2009-08-13 22:09:53 ----D---- C:\Windows\system32\da-DK
2009-08-13 22:09:52 ----D---- C:\Windows\system32\zh-TW
2009-08-13 22:09:52 ----D---- C:\Windows\system32\zh-CN
2009-08-13 22:09:52 ----D---- C:\Windows\system32\uk-UA
2009-08-13 22:09:52 ----D---- C:\Windows\system32\sv-SE
2009-08-13 22:09:52 ----D---- C:\Windows\system32\sr-Latn-CS
2009-08-13 22:09:52 ----D---- C:\Windows\system32\SLUI
2009-08-13 22:09:52 ----D---- C:\Windows\system32\sl-SI
2009-08-13 22:09:52 ----D---- C:\Windows\system32\setup
2009-08-13 22:09:52 ----D---- C:\Windows\system32\ru-RU
2009-08-13 22:09:52 ----D---- C:\Windows\system32\ro-RO
2009-08-13 22:09:52 ----D---- C:\Windows\system32\pt-PT
2009-08-13 22:09:52 ----D---- C:\Windows\system32\pl-PL
2009-08-13 22:09:52 ----D---- C:\Windows\system32\oobe
2009-08-13 22:09:52 ----D---- C:\Windows\system32\manifeststore
2009-08-13 22:09:52 ----D---- C:\Windows\system32\ja-JP
2009-08-13 22:09:52 ----D---- C:\Windows\system32\it-IT
2009-08-13 22:09:52 ----D---- C:\Windows\system32\hu-HU
2009-08-13 22:09:52 ----D---- C:\Windows\system32\he-IL
2009-08-13 22:09:52 ----D---- C:\Windows\system32\fr-FR
2009-08-13 22:09:52 ----D---- C:\Windows\system32\fi-FI
2009-08-13 22:09:52 ----D---- C:\Windows\system32\es-ES
2009-08-13 22:09:52 ----D---- C:\Windows\system32\en
2009-08-13 22:09:52 ----D---- C:\Windows\system32\el-GR
2009-08-13 22:09:52 ----D---- C:\Windows\system32\de-DE
2009-08-13 22:09:52 ----D---- C:\Windows\system32\cs-CZ
2009-08-13 22:09:52 ----D---- C:\Windows\system32\bg-BG
2009-08-13 22:09:52 ----D---- C:\Windows\system32\AdvancedInstallers
2009-08-13 22:09:51 ----D---- C:\Windows\system32\tr-TR
2009-08-13 22:09:51 ----D---- C:\Windows\system32\th-TH
2009-08-13 22:09:48 ----D---- C:\Windows\system32\pt-BR
2009-08-13 22:09:48 ----D---- C:\Windows\system32\nl-NL
2009-08-13 22:09:48 ----D---- C:\Windows\system32\nb-NO
2009-08-13 22:09:48 ----D---- C:\Windows\system32\migwiz
2009-08-13 22:09:48 ----D---- C:\Windows\system32\lt-LT
2009-08-13 22:09:48 ----D---- C:\Windows\system32\ar-SA
2009-08-13 22:09:43 ----D---- C:\Windows\AppPatch
2009-08-13 22:09:39 ----D---- C:\Windows\system32\Boot
2009-08-13 21:36:14 ----D---- C:\Windows\system32\restore

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-20 11264]
S1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2009-04-10 351744]
S1 mferkdk;VSCore mferkdk; \??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys [2008-05-22 31816]
S1 mfetdik;McAfee Inc.; C:\Windows\system32\drivers\mfetdik.sys [2008-05-22 52104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-08 179712]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-20 14208]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-20 5632]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-10 236544]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-20 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-20 200704]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 lvpopflt;Logitech POP Suppression Filter; C:\Windows\system32\DRIVERS\lvpopflt.sys [2009-04-30 114712]
S3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2009-04-30 25624]
S3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2009-04-30 265496]
S3 LVUVC;QuickCam for Notebooks Deluxe(UVC); C:\Windows\system32\DRIVERS\lvuvc.sys [2009-04-30 6754712]
S3 mfeapfk;McAfee Inc.; C:\Windows\system32\drivers\mfeapfk.sys [2008-05-22 64232]
S3 mfeavfk;McAfee Inc.; C:\Windows\system32\drivers\mfeavfk.sys [2008-05-22 72936]
S3 mfebopk;McAfee Inc.; C:\Windows\system32\drivers\mfebopk.sys [2008-05-22 33960]
S3 mfehidk;McAfee Inc.; C:\Windows\system32\drivers\mfehidk.sys [2008-05-22 174952]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-20 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-20 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-20 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-20 6016]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-08-28 3664384]
S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2009-05-09 14736]
S3 PalmUSBD;PalmUSBD; C:\Windows\system32\drivers\PalmUSBD.sys [2007-12-04 16640]
S3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial.sys [2009-01-09 27136]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-20 8192]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-10 73216]
S3 USBCCID;USB Smart Card reader; C:\Windows\system32\DRIVERS\usbccid.sys [2009-04-10 30208]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-20 134016]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-20 654336]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-20 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-08-13 1029456]
S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-20 21504]
S2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-08-20 860160]
S2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-04-30 154136]
S2 McAfeeFramework;McAfee Framework Service; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [2008-03-14 103744]
S2 McShield;McAfee McShield; C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [2008-05-22 144704]
S2 McTaskManager;McAfee Task Manager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [2008-05-22 54608]
S2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
S2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-08-20 466944]
S2 Windows MSI;Windows MSI; \\?\globalroot\systemroot\system32\msihost.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-20 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-20 523776]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-13 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-07-13 542496]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-20 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-04-10 918528]
S4 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-08-14 133104]
S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-02-18 877864]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-02-28 529704]

-----------------EOF-----------------
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 30th, 2009, 11:48 pm

Yes but reason can be seen from log; there is a rootkit.

We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
If you need help to disable your protection programs see here.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 31st, 2009, 2:50 am

I want to thank you for your recommendations. I asked my husband about this next step you want me to do and he said he doesnt trust that program. You see he is like you and workes with computers, viruses and networks all day. I explained what we have done and he asked me to stop what I'm doing and wait until he returns from his business trip. You can go ahead and close this thread if you like.

Thanks again for your assistance!
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm

Re: Win32Tr New help request to an old problem

Unread postby Shaba » August 31st, 2009, 5:37 am

Well that program is safe to use when user is assisted by a person trained in its use and I think it is only because of that he doesn't recognize it.

On the other hand, just some googling would have shown that combofix is used against this rootkit.

But if he wants to do it his way, that is fine :)
User avatar
Shaba
Admin/Teacher Emeritus
 
Posts: 26974
Joined: March 24th, 2006, 4:42 am
Location: Finland

Re: Win32Tr New help request to an old problem

Unread postby Summerfield_DIY » August 31st, 2009, 3:39 pm

Please don't think that he doesnt know about the program. He knows plenty of it. He's BOA's IT guru so he has seen his fair share of viruses and has the best tools to protect BOA's information against them. I thought I would see if I can kill this bug before he returns from his business trip.

Thank you again for your assistance.
Summerfield_DIY
Active Member
 
Posts: 7
Joined: August 26th, 2009, 8:17 pm
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 296 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware