Hey! so here ya go...
C:\Program Files\Adsense Helper Object moved successfully.
C:\Program Files\ActivationManager moved successfully.
Created on 10/30/2007 01:09:32
REPORT.TXTSDFix: Version 1.112
Run by Dan on 10/30/2007 at 01:19 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\Wolfenstein - Enemy Territory\\et.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\et.exe:*:Enabled:et"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
Files with Hidden Attributes:
Thu 10 Mar 2005 475 A.SH. --- "C:\WINDOWS\system32\ltwjjwe.dll"
Wed 9 Mar 2005 106 A..H. --- "C:\WINDOWS\system32\vt.dll"
Wed 24 Oct 2007 693,481 A.SH. --- "C:\WINDOWS\system32\yibhqvbe.tmp"
Wed 2 Mar 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 2 Mar 2005 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv18.bak"
Thu 28 Sep 2006 72 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti2A9.tmp"
Tue 19 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 2 Mar 2005 4,348 A..H. --- "C:\Documents and Settings\Dan\My Documents\My Music\License Backup\drmv1key.bak"
Wed 16 Mar 2005 401 A..H. --- "C:\Documents and Settings\Dan\My Documents\My Music\License Backup\drmv1lic.bak"
Sat 5 Mar 2005 400 A..H. --- "C:\Documents and Settings\Dan\My Documents\My Music\License Backup\drmv2key.bak"
Wed 16 Mar 2005 1,536 A..H. --- "C:\Documents and Settings\Dan\My Documents\My Music\License Backup\drmv2lic.bak"
Finished!
MAIN.TXTDeckard's System Scanner v20071014.68
Run by Dan on 2007-10-30 01:26:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Unable to create WMI object; The operation completed successfully.
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Dan.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:27:26 AM, on 10/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dan\Desktop\dss.exe
C:\DOCUME~1\Dan\Desktop\Dan.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.myspace.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-21-1957994488-616249376-1801674531-1003\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User '?')
O4 - S-1-5-21-1957994488-616249376-1801674531-1003 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User '?')
O4 - S-1-5-21-1957994488-616249376-1801674531-1003 Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe (User '?')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
--
End of file - 5579 bytes
-- HijackThis Fixed Entries (C:\DOCUME~1\Dan\Desktop\backups\) -----------------
backup-20071018-073753-965 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
backup-20071018-073754-276 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
backup-20071030-010738-165 O20 - Winlogon Notify: vtuvuvs - vtuvuvs.dll (file missing)
backup-20071030-010738-208 O4 - HKUS\S-1-5-21-1957994488-616249376-1801674531-1003\..\Run: [CS Update] copy /Y "C:\Program Files\ActivationManager\ActivationManager.dll.upd" "C:\Program Files\ActivationManager\ActivationManager.dll" (User '?')
backup-20071030-010738-297 O4 - HKUS\S-1-5-18\..\Run: [NAV Auto Updates] slserver.exe (User '?')
backup-20071030-010738-393 O4 - HKCU\..\Run: [CS Update] copy /Y "C:\Program Files\ActivationManager\ActivationManager.dll.upd" "C:\Program Files\ActivationManager\ActivationManager.dll"
backup-20071030-010738-496 O4 - HKUS\.DEFAULT\..\Run: [NAV Auto Updates] slserver.exe (User 'Default user')
backup-20071030-010738-667 O2 - BHO: Adsense Helper Object - {18FA53D3-B7A8-4309-8045-D43D6AA2DCE9} - C:\Program Files\Adsense Helper Object\aho.v5.dll
backup-20071030-010738-836 O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 catchme - c:\docume~1\dan\locals~1\temp\catchme.sys (file missing)
3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
3 IKFileFlt (File Filter Driver) - system32\drivers\ikfileflt.sys (file missing)
3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
3 scrcap - c:\windows\system32\drivers\scrcap.sys <Not Verified; ZD Soft; ZD Soft Screen Capture Series>
3 XTrapD12 - c:\windows\system32\xtrapd12.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
2 Diskeeper - c:\program files\executive software\diskeeper\dkservice.exe
3 FLEXnet Licensing Service - c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
2 WMP54Gv4SVC - c:\program files\linksys wireless-g pci wireless network monitor\wlservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Unable to create WMI object.
-- Scheduled Tasks -------------------------------------------------------------
2007-10-29 16:24:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-10-29 02:00:28 1494 --a------ C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
2007-10-26 15:00:00 410 --a----c- C:\WINDOWS\Tasks\Norton Security Scan.job
2007-10-25 19:00:00 324 --a----c- C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
-- Files created between 2007-09-30 and 2007-10-30 -----------------------------
2007-10-30 01:18:37 0 d-------- C:\WINDOWS\ERUNT
2007-10-28 18:45:38 589 --a------ C:\WINDOWS\system32\yfjxxguk.dll
2007-10-27 21:40:13 0 d-------- C:\Screen Recordings
2007-10-27 15:48:00 0 d-------- C:\Program Files\ZD Soft
2007-10-24 20:54:52 0 d-------- C:\Program Files\New Folder
2007-10-24 01:48:17 0 d-------- C:\Fraps
2007-10-23 22:29:48 0 d-------- C:\Program Files\Fraps
2007-10-23 22:03:34 0 d-------- C:\Documents and Settings\Dan\Application Data\Sony
2007-10-23 21:55:38 0 d-------- C:\Documents and Settings\Dan\Application Data\Sony Setup
2007-10-19 22:13:06 14900 --a------ C:\Program Files\3269.exe
2007-10-19 22:08:58 20480 --a------ C:\WINDOWS\system32\winjyg32.dll
2007-10-19 22:01:26 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2007-10-19 22:01:24 49152 --a------ C:\WINDOWS\system32\MultiSZ.dll <Not Verified; Ahead Software AG\r\nim Stoeckmaedle 6\r\n76307 Karlsbad, Germany\r\nFax: ++49-7248-911-888\r\ne-mail:
[email protected]; MultiSZ/ACL Installation Library>
2007-10-19 22:01:22 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2007-10-19 22:01:22 35328 --a------ C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2007-10-19 22:01:22 532480 --a------ C:\WINDOWS\system32\imagx5.dll <Not Verified; Pegasus Software, LLC; ImagXpress>
2007-10-19 22:01:22 507904 --a------ C:\WINDOWS\system32\imagr5.dll <Not Verified; Pegasus Software,LLC; ImagXpress>
2007-10-17 20:25:14 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-10-17 20:19:18 0 d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-10-17 20:19:10 0 d-------- C:\Program Files\Webroot
2007-10-17 20:19:10 0 d-------- C:\Documents and Settings\Dan\Application Data\Webroot
2007-10-17 20:19:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-10-17 20:18:32 164 --a------ C:\install.dat
2007-10-17 20:16:12 0 d-------- C:\Documents and Settings\Dan\Application Data\GetRightToGo
2007-10-17 18:44:26 0 d-------- C:\Documents and Settings\Dan\Application Data\Grisoft
2007-10-17 18:44:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-17 15:39:57 0 d-------- C:\VundoFix Backups
2007-10-17 15:38:46 0 d-------- C:\Program Files\Common Files\Java
2007-10-16 23:08:55 0 --a------ C:\WINDOWS\ativpsrm.bin
2007-10-16 23:05:04 593920 --a------ C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2007-10-16 23:04:46 0 d-------- C:\Program Files\ATI Technologies
2007-10-16 20:58:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-10-16 20:45:55 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-16 20:45:54 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-10-16 17:19:08 0 d-------- C:\Program Files\Bonjour
2007-10-16 17:04:45 4718592 --a------ C:\Documents and Settings\Dan\ntuser.dat
2007-10-16 15:15:20 0 d-------- C:\Documents and Settings\Dan\Application Data\BitTorrent
2007-10-16 14:47:43 0 d-------- C:\Documents and Settings\Dan\Application Data\X-Chat 2
2007-10-16 14:47:39 0 d-------- C:\Program Files\xchat
2007-10-16 13:40:36 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-16 13:30:53 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2007-10-05 19:49:34 0 d-------- C:\Documents and Settings\Dan\Application Data\mIRC
-- Find3M Report ---------------------------------------------------------------
2007-10-30 01:24:39 0 d-------- C:\Program Files\Microsoft AntiSpyware
2007-10-30 01:15:46 0 d---s---- C:\Program Files\Xfire
2007-10-29 15:28:30 0 d-------- C:\Documents and Settings\Dan\Application Data\Xfire
2007-10-29 14:33:31 0 d-------- C:\Program Files\Soulseek
2007-10-28 18:52:35 0 d-------- C:\Program Files\Common Files
2007-10-27 12:55:18 0 d-------- C:\Documents and Settings\Dan\Application Data\teamspeak2
2007-10-24 14:54:17 0 d-------- C:\Program Files\Wolfenstein - Enemy Territory
2007-10-24 00:06:50 0 d-------- C:\Program Files\Common Files\AOL
2007-10-24 00:02:53 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-10-20 19:56:02 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-10-20 13:53:05 0 d-------- C:\Program Files\Norton Security Scan
2007-10-19 22:01:19 0 d-------- C:\Program Files\Ahead
2007-10-17 17:18:15 0 d-------- C:\Program Files\Spyware Doctor
2007-10-17 15:39:41 0 d-------- C:\Program Files\Java
2007-10-17 09:46:44 4212 --ah---c- C:\WINDOWS\system32\zllictbl.dat
2007-10-17 02:12:53 146432 --a----c- C:\WINDOWS\regedit.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-17 02:10:03 99840 --a----c- C:\WINDOWS\UninstallFirefox.exe
2007-10-17 02:10:03 69632 --a----c- C:\WINDOWS\uinst001.exe
2007-10-17 02:10:03 25600 --a----c- C:\WINDOWS\twunk_32.exe <Not Verified; Twain Working Group; Twain Thunker>
2007-10-17 02:10:00 2560 --a----c- C:\WINDOWS\_MSRSTRT.EXE
2007-10-17 02:09:56 283648 --a----c- C:\WINDOWS\winhlp32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-17 02:01:44 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe <Not Verified; ATI Technologies, Inc.; ATI Default Resolution Update>
2007-10-16 22:17:04 94208 --a----c- C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2007-10-16 22:17:02 10752 --a----c- C:\WINDOWS\hh.exe <Not Verified; Microsoft Corporation; HTML Help>
2007-10-16 22:13:29 15360 --a----c- C:\WINDOWS\TASKMAN.EXE <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:29 21504 --a----c- C:\WINDOWS\system32\spupdwxp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:27 11776 --a----c- C:\WINDOWS\system32\spnpinst.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:26 12800 --a----c- C:\WINDOWS\system32\spiisupd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:26 538624 --a----c- C:\WINDOWS\system32\spider.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:25 9216 --a----c- C:\WINDOWS\system32\print.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:24 49152 --a----c- C:\WINDOWS\system32\powercfg.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:23 32256 --a----c- C:\WINDOWS\system32\wupdmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:23 146432 --a----c- C:\WINDOWS\system32\WudfHost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:21 30720 --a----c- C:\WINDOWS\system32\xcopy.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:21 77824 --a----c- C:\WINDOWS\system32\wmpstub.exe <Not Verified; Microsoft Corporation; Microsoft® Windows Media Player>
2007-10-16 22:13:20 114688 --a----c- C:\WINDOWS\system32\wscript.exe <Not Verified; Microsoft Corporation; Microsoft ® Windows Script Host>
2007-10-16 22:13:19 13824 --a----c- C:\WINDOWS\system32\wscntfy.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:19 5632 --a----c- C:\WINDOWS\system32\write.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:18 32256 --a----c- C:\WINDOWS\system32\wpnpinst.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:18 17408 --a----c- C:\WINDOWS\system32\wpdshextautoplay.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:17 32256 --a----c- C:\WINDOWS\system32\wpabaln.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:17 14848 --a----c- C:\WINDOWS\system32\shadow.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:16 9728 --a----c- C:\WINDOWS\system32\sfc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:15 23040 --a----c- C:\WINDOWS\system32\setup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:14 31232 --a----c- C:\WINDOWS\system32\sethc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:10 15872 --a----c- C:\WINDOWS\system32\expand.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:09 8704 --a----c- C:\WINDOWS\system32\eventvwr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:09 77824 --a----c- C:\WINDOWS\system32\eventtriggers.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:08 50176 --a----c- C:\WINDOWS\system32\eventcreate.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:08 193024 --a----c- C:\WINDOWS\system32\eudcedit.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:07 5632 --a----c- C:\WINDOWS\system32\winver.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:07 8192 --a----c- C:\WINDOWS\system32\winhlp32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:07 39424 --a----c- C:\WINDOWS\system32\esentutl.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:04 8192 --a----c- C:\WINDOWS\system32\spdwnwxp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:03 98304 --a----c- C:\WINDOWS\system32\verifier.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:03 28672 --a----c- C:\WINDOWS\system32\verclsid.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:02 8704 --a----c- C:\WINDOWS\system32\uwdf.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:02 50176 --a----c- C:\WINDOWS\system32\utilman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:02 14336 --a----c- C:\WINDOWS\system32\auditusr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:01 11264 --a----c- C:\WINDOWS\system32\attrib.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:01 11264 --a----c- C:\WINDOWS\system32\atmadm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:13:00 111104 --a----c- C:\WINDOWS\system32\netdde.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:59 124928 --a----c- C:\WINDOWS\system32\net1.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:59 42496 --a----c- C:\WINDOWS\system32\net.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:58 4096 --a----c- C:\WINDOWS\system32\nddeapir.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:58 123392 --a----c- C:\WINDOWS\system32\mplay32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:57 8192 --a----c- C:\WINDOWS\system32\mountvol.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:56 126976 --a----c- C:\WINDOWS\system32\mshearts.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:56 143360 --a----c- C:\WINDOWS\system32\mobsync.exe <Not Verified; Microsoft Corporation; Microsoft Synchronization Manager>
2007-10-16 22:12:55 20992 --a----c- C:\WINDOWS\system32\msg.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:54 126464 --a----c- C:\WINDOWS\system32\nwscript.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:53 21504 --a----c- C:\WINDOWS\system32\rcp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:53 35840 --a----c- C:\WINDOWS\system32\rcimlby.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:52 56832 --a----c- C:\WINDOWS\system32\rasphone.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:51 11264 --a----c- C:\WINDOWS\system32\rasdial.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:49 433664 --a----c- C:\WINDOWS\system32\wiaacmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:48 15360 --a----c- C:\WINDOWS\system32\ctfmon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:48 98304 --a----c- C:\WINDOWS\system32\cscript.exe <Not Verified; Microsoft Corporation; Microsoft ® Windows Script Host>
2007-10-16 22:12:40 114688 --a----c- C:\WINDOWS\system32\calc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:39 18432 --a----c- C:\WINDOWS\system32\cacls.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:37 9728 --a----c- C:\WINDOWS\system32\label.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:36 36352 --a----c- C:\WINDOWS\system32\typeperf.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:35 69632 --a------ C:\WINDOWS\system32\TWUNK_32.EXE <Not Verified; Twain Working Group; Twain Thunker>
2007-10-16 22:12:34 16896 --a----c- C:\WINDOWS\system32\tsshutdn.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:33 16384 --a----c- C:\WINDOWS\system32\tskill.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:33 14848 --a----c- C:\WINDOWS\system32\tsdiscon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:32 44544 --a----c- C:\WINDOWS\system32\tscupgrd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:32 14848 --a----c- C:\WINDOWS\system32\tscon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:31 31744 --a----c- C:\WINDOWS\system32\tracert6.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:31 12288 --a----c- C:\WINDOWS\system32\tracert.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:31 259584 --a----c- C:\WINDOWS\system32\tracerpt.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:27 65536 --a----c- C:\WINDOWS\system32\wextract.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:25 8704 --a----c- C:\WINDOWS\system32\wdfmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:17 49664 --a----c- C:\WINDOWS\system32\w32tm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:16 33792 --a----c- C:\WINDOWS\system32\vssadmin.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:15 69632 --a----c- C:\WINDOWS\system32\usrshuta.exe <Not Verified; U.S. Robotics Corporation; U.S. Robotics Modem Driver>
2007-10-16 22:12:14 61440 --a----c- C:\WINDOWS\system32\usrprbda.exe <Not Verified; U.S. Robotics Corporation; U.S. Robotics modem>
2007-10-16 22:12:14 77824 --a----c- C:\WINDOWS\system32\usrmlnka.exe <Not Verified; U.S. Robotics Corporation; U.S. Robotics Modem Driver>
2007-10-16 22:12:13 347136 --a----c- C:\WINDOWS\system32\tourstart.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:12 78336 --a----c- C:\WINDOWS\system32\tlntsess.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:11 61440 --a----c- C:\WINDOWS\system32\tlntadmn.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:11 16896 --a----c- C:\WINDOWS\system32\tftp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:10 75776 --a----c- C:\WINDOWS\system32\telnet.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:10 19456 --a----c- C:\WINDOWS\system32\tcpsvcs.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:09 12288 --a----c- C:\WINDOWS\system32\tcmsetup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:09 135680 --a----c- C:\WINDOWS\system32\taskmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:09 15360 --a----c- C:\WINDOWS\system32\taskman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:08 72192 --a----c- C:\WINDOWS\system32\tasklist.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:08 72192 --a----c- C:\WINDOWS\system32\taskkill.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:07 3072 --a----c- C:\WINDOWS\system32\systray.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:06 68096 --a----c- C:\WINDOWS\system32\systeminfo.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:06 105984 --a----c- C:\WINDOWS\system32\sysocmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:05 36864 --a----c- C:\WINDOWS\system32\syskey.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:05 51200 --a----c- C:\WINDOWS\system32\syncapp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:04 9216 --a----c- C:\WINDOWS\system32\subst.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:04 14848 --a----c- C:\WINDOWS\system32\stimon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:03 679936 --a----c- C:\WINDOWS\system32\sstext3d.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:02 14336 --a----c- C:\WINDOWS\system32\ssstars.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:01 610304 --a----c- C:\WINDOWS\system32\sspipes.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:00 18944 --a----c- C:\WINDOWS\system32\ssmyst.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:12:00 20992 --a----c- C:\WINDOWS\system32\ssmarque.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:59 393216 --a----c- C:\WINDOWS\system32\ssflwbox.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:59 19968 --a----c- C:\WINDOWS\system32\ssbezier.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:58 704512 --a----c- C:\WINDOWS\system32\ss3dfo.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:57 26112 --a----c- C:\WINDOWS\system32\skeys.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:57 70144 --a----c- C:\WINDOWS\system32\sigverif.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:56 19456 --a----c- C:\WINDOWS\system32\shutdown.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:56 77824 --a----c- C:\WINDOWS\system32\shrpubw.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:55 23552 --a----c- C:\WINDOWS\system32\sort.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:54 56832 --a----c- C:\WINDOWS\system32\sol.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:54 138752 --a----c- C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:53 131584 --a----c- C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:53 8192 --a----c- C:\WINDOWS\system32\smbinst.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:52 73728 --a----c- C:\WINDOWS\system32\slserv.exe <Not Verified; Smart Link; Soft Modem>
2007-10-16 22:11:52 32768 --a----c- C:\WINDOWS\system32\slrundll.exe <Not Verified; Smart Link; Soft Modem>
2007-10-16 22:11:51 19968 --a----c- C:\WINDOWS\system32\route.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:51 62464 --a----c- C:\WINDOWS\system32\rdpclip.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:50 16896 --a----c- C:\WINDOWS\system32\qappsrv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:50 33280 --a----c- C:\WINDOWS\system32\ping6.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:49 18432 --a----c- C:\WINDOWS\system32\secedit.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:48 77312 --a----c- C:\WINDOWS\system32\sdbinst.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:48 9216 --a----c- C:\WINDOWS\system32\scrnsave.scr <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:48 121856 --a----c- C:\WINDOWS\system32\schtasks.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:47 31232 --a----c- C:\WINDOWS\system32\sc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:47 13312 --a----c- C:\WINDOWS\system32\savedump.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:46 15872 --a----c- C:\WINDOWS\system32\rwinsta.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:46 14336 --a----c- C:\WINDOWS\system32\runonce.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:45 33280 --a----c- C:\WINDOWS\system32\rundll32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:45 16384 --a----c- C:\WINDOWS\system32\runas.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:44 77312 --a----c- C:\WINDOWS\system32\rtcshare.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:44 62976 --a----c- C:\WINDOWS\system32\rsopprov.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:43 107520 --a----c- C:\WINDOWS\system32\rsnotify.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:43 49152 --a----c- C:\WINDOWS\system32\rsmui.exe <Not Verified; Microsoft Corporation; Microsoft® Windows Whistler® Operating System>
2007-10-16 22:11:42 24576 --a----c- C:\WINDOWS\system32\rsmsink.exe <Not Verified; Microsoft Corporation; Microsoft® Windows Whistler® Operating System>
2007-10-16 22:11:42 49152 --a----c- C:\WINDOWS\system32\rsm.exe <Not Verified; Microsoft Corp; Microsoft® Windows ® 2000 Operating System>
2007-10-16 22:11:42 14848 --a----c- C:\WINDOWS\system32\rsh.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:41 25600 --a----c- C:\WINDOWS\system32\routemon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:40 11776 --a----c- C:\WINDOWS\system32\rasautou.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:40 22016 --a----c- C:\WINDOWS\system32\qwinsta.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:39 20480 --a----c- C:\WINDOWS\system32\qprocess.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:38 9216 --a----c- C:\WINDOWS\system32\proxycfg.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:37 50176 --a----c- C:\WINDOWS\system32\proquota.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:37 109568 --a----c- C:\WINDOWS\system32\progman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:36 17920 --a----c- C:\WINDOWS\system32\ping.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:35 15872 --a----c- C:\WINDOWS\system32\perfmon.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:29 419840 --a----c- C:\WINDOWS\system32\ntvdm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:27 1200128 --a----c- C:\WINDOWS\system32\ntbackup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:23 76800 --a----c- C:\WINDOWS\system32\nslookup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:22 69120 --a----c- C:\WINDOWS\system32\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:22 20480 --a----c- C:\WINDOWS\system32\nbtstat.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:21 53760 --a----c- C:\WINDOWS\system32\narrator.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:13 12800 --a----c- C:\WINDOWS\system32\mrinfo.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:12 117248 --a----c- C:\WINDOWS\system32\mqtgsvc.exe <Not Verified; Microsoft Corporation; Microsoft Message Queue>
2007-10-16 22:11:12 4608 --a----c- C:\WINDOWS\system32\mqsvc.exe <Not Verified; Microsoft Corporation; Microsoft Message Queue>
2007-10-16 22:11:11 815104 --a----c- C:\WINDOWS\system32\mmc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:10 51712 --a----c- C:\WINDOWS\system32\migpwd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:08 22016 --a----c- C:\WINDOWS\system32\mpnotify.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:07 29696 --a----c- C:\WINDOWS\system32\lights.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:06 85504 --a----c- C:\WINDOWS\system32\makecab.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:06 72704 --a----c- C:\WINDOWS\system32\magnify.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:11:04 19968 --a----c- C:\WINDOWS\system32\mqbkup.exe <Not Verified; Microsoft Corporation; Microsoft Message Queue>
2007-10-16 22:10:59 23552 --a----c- C:\WINDOWS\system32\ipxroute.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:59 53248 --a----c- C:\WINDOWS\system32\ipv6.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:58 44032 --a----c- C:\WINDOWS\system32\ipsec6.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:58 55808 --a----c- C:\WINDOWS\system32\ipconfig.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:55 7680 --a----c- C:\WINDOWS\system32\hostname.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:54 14848 --a----c- C:\WINDOWS\system32\help.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:54 39424 --a----c- C:\WINDOWS\system32\grpconv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:53 57344 --a----c- C:\WINDOWS\system32\gpupdate.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:53 119808 --a----c- C:\WINDOWS\system32\gpresult.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:52 55296 --a----c- C:\WINDOWS\system32\getmac.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:51 42496 --a----c- C:\WINDOWS\system32\ftp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:51 56320 --a----c- C:\WINDOWS\system32\fsutil.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:50 193024 --a----c- C:\WINDOWS\system32\fsquirt.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:50 55296 --a----c- C:\WINDOWS\system32\freecell.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:49 7168 --a----c- C:\WINDOWS\system32\forcedos.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:49 20992 --a----c- C:\WINDOWS\system32\fontview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:48 114688 --a----c- C:\WINDOWS\system32\iexpress.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:46 180224 --a----c- C:\WINDOWS\system32\dwwin.exe <Not Verified; Microsoft Corporation; Microsoft Application Error Reporting>
2007-10-16 22:10:46 17920 --a----c- C:\WINDOWS\system32\dvdupgrd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:46 55296 --a----c- C:\WINDOWS\system32\dvdplay.exe <Not Verified; ; dvdplay Application>
2007-10-16 22:10:45 10752 --a----c- C:\WINDOWS\system32\dumprep.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:44 45568 --a----c- C:\WINDOWS\system32\drwtsn32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:44 249856 --a----c- C:\WINDOWS\system32\drmupgds.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:27 58368 --a----c- C:\WINDOWS\system32\driverquery.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:27 83456 --a----c- C:\WINDOWS\system32\dpvsetup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:26 18432 --a----c- C:\WINDOWS\system32\dpnsvr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:26 30208 --a----c- C:\WINDOWS\system32\dplaysvr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:25 10752 --a----c- C:\WINDOWS\system32\doskey.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:10:25 15872 --a----c- C:\WINDOWS\system32\dmremote.exe <Not Verified; Microsoft Corp.; Logical Disk Manager for Windows NT>
2007-10-16 22:10:24 4608 --a----c- C:\WINDOWS\system32\dllhst3g.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:43 17920 --a----c- C:\WINDOWS\system32\diskperf.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:43 163840 --a----c- C:\WINDOWS\system32\diskpart.exe <Not Verified; Microsoft Corporation; Microsoft Corporation Diskpart Application>
2007-10-16 22:05:35 85504 --a----c- C:\WINDOWS\system32\diantz.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:34 30208 --a----c- C:\WINDOWS\system32\ddeshare.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:34 5120 --a----c- C:\WINDOWS\system32\dcomcnfg.exe <Not Verified; Microsoft Corporation; COM Services>
2007-10-16 22:05:32 82432 --a----c- C:\WINDOWS\system32\dfrgfat.exe <Not Verified; Microsoft Corp. and Executive Software International, Inc.; Windows Disk Defragmenter>
2007-10-16 22:05:31 25088 --a----c- C:\WINDOWS\system32\defrag.exe <Not Verified; Microsoft Corp. and Executive Software International, Inc.; Windows Disk Defragmenter>
2007-10-16 22:05:31 13824 --a----c- C:\WINDOWS\system32\convert.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:31 8192 --a----c- C:\WINDOWS\system32\control.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:30 27648 --a----c- C:\WINDOWS\system32\conime.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:26 9728 --a----c- C:\WINDOWS\system32\comsdupd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:25 17408 --a----c- C:\WINDOWS\system32\compact.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:25 15872 --a----c- C:\WINDOWS\system32\comp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:23 63488 --a----c- C:\WINDOWS\system32\cmstp.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2007-10-16 22:05:23 39936 --a----c- C:\WINDOWS\system32\cmmon32.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2007-10-16 22:05:23 47104 --a----c- C:\WINDOWS\system32\cmdl32.exe <Not Verified; Microsoft Corporation; Microsoft® Connection Manager>
2007-10-16 22:05:22 388608 --a----c- C:\WINDOWS\system32\cmd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:21 5120 --a----c- C:\WINDOWS\system32\bootvrfy.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:21 4608 --a----c- C:\WINDOWS\system32\bootok.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:20 136704 --a----c- C:\WINDOWS\system32\bootcfg.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:20 71680 --a----c- C:\WINDOWS\system32\blastcln.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:19 25088 --a----c- C:\WINDOWS\system32\at.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:18 32768 --a----c- C:\WINDOWS\system32\asr_pfu.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:18 32256 --a----c- C:\WINDOWS\system32\asr_ldm.exe <Not Verified; Microsoft Corp.; Logical Disk Manager for Windows NT>
2007-10-16 22:05:17 30208 --a----c- C:\WINDOWS\system32\asr_fmt.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:17 98304 --a----c- C:\WINDOWS\system32\ahui.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:16 13824 --a----c- C:\WINDOWS\system32\rexec.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:15 9728 --a----c- C:\WINDOWS\system32\reset.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:14 12800 --a----c- C:\WINDOWS\system32\replace.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:14 32768 --a----c- C:\WINDOWS\system32\relog.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:08 4608 --a----c- C:\WINDOWS\system32\regwiz.exe <Not Verified; Microsoft; RegWizExe>
2007-10-16 22:05:08 33792 --a----c- C:\WINDOWS\system32\regini.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:07 3584 --a----c- C:\WINDOWS\system32\regedt32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:07 50176 --a----c- C:\WINDOWS\system32\reg.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:07 7168 --a----c- C:\WINDOWS\system32\recover.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:07 67072 --a----c- C:\WINDOWS\system32\rdshost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:06 13824 --a----c- C:\WINDOWS\system32\rdsaddin.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:04 36864 --a----c- C:\WINDOWS\system32\netstat.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:04 86016 --a----c- C:\WINDOWS\system32\netsh.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:04 331776 --a----c- C:\WINDOWS\system32\netsetup.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:03 8192 --a----c- C:\WINDOWS\system32\lpr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:03 6144 --a----c- C:\WINDOWS\system32\lpq.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:02 514560 --a----c- C:\WINDOWS\system32\logonui.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:02 15360 --a----c- C:\WINDOWS\system32\logoff.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:02 59392 --a----c- C:\WINDOWS\system32\logman.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:01 100864 --a----c- C:\WINDOWS\system32\logagent.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:01 5120 --a----c- C:\WINDOWS\system32\lodctr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:05:00 25088 --a----c- C:\WINDOWS\system32\lnkstub.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:59 11776 --a----c- C:\WINDOWS\system32\winmsd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:59 119808 --a----c- C:\WINDOWS\system32\winmine.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:58 46592 --a----c- C:\WINDOWS\system32\dxdllreg.exe <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows® Operating System>
2007-10-16 22:04:58 33280 --a----c- C:\WINDOWS\system32\clipsrv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:57 102912 --a----c- C:\WINDOWS\system32\clipbrd.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:57 19456 --a----c- C:\WINDOWS\system32\arp.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:56 64000 --a------ C:\WINDOWS\system32\cleanmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:55 7680 --a----c- C:\WINDOWS\system32\ckcnv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:55 56320 --a----c- C:\WINDOWS\system32\cipher.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-16 22:04:55 8192 --a----c- C:\WINDOWS\system32\cidaemon.exe <Not Verified; Microsoft Corporation; Microso