Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:13:33 PM, on 12/24/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Users\Puyang\AppData\Local\Temp\yyy1080.exe
C:\Users\Puyang\AppData\Local\Temp\~tmpa.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Gainward] C:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSFox] C:\Users\Puyang\AppData\Local\Temp\yyy1080.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onec...s/wlscctrl2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEFA90EC-36EA-4C3E-B8B3-C45D7547BE4B}: NameServer = 165.21.100.88 165.21.83.88
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 6160 bytes
Logfile of random's system information tool 1.05 (written by random/random)
Run by Puyang at 2008-12-24 16:20:52
Microsoft® Windows Vista™ Home Basic Service Pack 1
System drive C: has 39 GB (26%) free of 153 GB
Total RAM: 2557 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:20:55 PM, on 12/24/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Users\Puyang\AppData\Local\Temp\yyy1080.exe
C:\Users\Puyang\AppData\Local\Temp\~tmpa.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Puyang\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CE64SUC2\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\Puyang.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Gainward] C:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSFox] C:\Users\Puyang\AppData\Local\Temp\yyy1080.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onec...s/wlscctrl2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEFA90EC-36EA-4C3E-B8B3-C45D7547BE4B}: NameServer = 165.21.100.88 165.21.83.88
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 6277 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-12-01 304736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2007-05-30 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-30 1261336]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]
"Gainward"=C:\Program Files\Vtune\TBPanel.exe [2006-09-13 2154496]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-12-01 185872]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-09-17 13580832]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-09-17 92704]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"MSFox"=C:\Users\Puyang\AppData\Local\Temp\yyy1080.exe [2008-12-23 86020]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2008-12-24 16:20:52 ----D---- C:\rsit
2008-12-24 16:12:55 ----D---- C:\Program Files\Trend Micro
2008-12-24 13:10:48 ----D---- C:\ProgramData\Lavasoft
2008-12-24 13:10:48 ----D---- C:\Program Files\Lavasoft
2008-12-24 13:10:21 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-23 22:56:53 ----D---- C:\Program Files\Windows Live Safety Center
2008-12-23 20:28:13 ----D---- C:\Program Files\Exterminate It!
2008-12-23 18:36:51 ----D---- C:\ProgramData\CrucialSoft Ltd
2008-12-23 03:00:25 ----A---- C:\Windows\system32\mshtml.dll
2008-12-12 21:53:49 ----A---- C:\Windows\ODBC.INI
2008-12-12 21:52:42 ----D---- C:\Program Files\Microsoft ActiveSync
2008-12-12 21:52:29 ----D---- C:\Program Files\Common Files\Designer
2008-12-12 21:51:15 ----D---- C:\Windows\ShellNew
2008-12-12 21:51:07 ----D---- C:\Program Files\Microsoft Office
2008-12-11 21:57:12 ----D---- C:\Program Files\Garena
2008-12-11 21:56:33 ----D---- C:\Users\Puyang\AppData\Roaming\InstallShield
2008-12-11 21:43:29 ----A---- C:\Windows\system32\d3dx10_40.dll
2008-12-11 21:43:29 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2008-12-11 21:43:28 ----A---- C:\Windows\system32\D3DX9_40.dll
2008-12-11 21:43:24 ----A---- C:\Windows\system32\XAudio2_3.dll
2008-12-11 21:43:24 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2008-12-11 21:43:23 ----A---- C:\Windows\system32\xactengine3_3.dll
2008-12-11 21:43:23 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2008-12-11 21:43:22 ----A---- C:\Windows\system32\XAudio2_2.dll
2008-12-11 21:43:22 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2008-12-11 21:43:18 ----A---- C:\Windows\system32\xactengine3_2.dll
2008-12-11 21:43:16 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2008-12-11 21:43:15 ----A---- C:\Windows\system32\d3dx10_39.dll
2008-12-11 21:43:14 ----A---- C:\Windows\system32\D3DX9_39.dll
2008-12-11 21:42:08 ----HD---- C:\Windows\msdownld.tmp
2008-12-11 21:41:56 ----D---- C:\Windows\system32\directx
2008-12-11 18:57:21 ----D---- C:\Users\Puyang\AppData\Roaming\WinRAR
2008-12-11 14:27:44 ----D---- C:\Users\Puyang\AppData\Roaming\DAEMON Tools Lite
2008-12-11 13:11:31 ----D---- C:\Program Files\Common Files\Steam
2008-12-11 13:11:30 ----D---- C:\Program Files\Steam
2008-12-11 00:40:58 ----A---- C:\Windows\system32\tzres.dll
2008-12-10 21:11:52 ----A---- C:\Windows\system32\gdi32.dll
2008-12-10 21:11:50 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-12-10 21:11:49 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-12-10 21:11:43 ----A---- C:\Windows\system32\shell32.dll
2008-12-10 21:11:39 ----A---- C:\Windows\explorer.exe
2008-12-10 21:11:35 ----A---- C:\Windows\system32\wininet.dll
2008-12-10 21:11:35 ----A---- C:\Windows\system32\urlmon.dll
2008-12-10 21:11:35 ----A---- C:\Windows\system32\mstime.dll
2008-12-10 21:11:35 ----A---- C:\Windows\system32\iertutil.dll
2008-12-10 21:11:35 ----A---- C:\Windows\system32\ieframe.dll
2008-12-10 21:11:34 ----A---- C:\Windows\system32\jsproxy.dll
2008-12-10 21:11:31 ----A---- C:\Windows\system32\WMVCORE.DLL
2008-12-10 21:11:31 ----A---- C:\Windows\system32\mf.dll
2008-12-10 21:11:30 ----A---- C:\Windows\system32\WMNetMgr.dll
2008-12-10 21:11:30 ----A---- C:\Windows\system32\logagent.exe
2008-12-10 12:21:50 ----HD---- C:\$AVG8.VAULT$
2008-12-10 00:50:10 ----A---- C:\Windows\system32\msshooks.dll
2008-12-10 00:50:10 ----A---- C:\Windows\system32\msscb.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\thawbrkr.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\srchadmin.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\SearchFilterHost.exe
2008-12-10 00:50:08 ----A---- C:\Windows\system32\propsys.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\propdefs.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\msstrc.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\mssprxy.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\mssitlb.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\msshsq.dll
2008-12-10 00:50:08 ----A---- C:\Windows\system32\korwbrkr.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\xmlfilter.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\wsepno.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2008-12-10 00:50:07 ----A---- C:\Windows\system32\SearchIndexer.exe
2008-12-10 00:50:07 ----A---- C:\Windows\system32\rtffilt.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\offfilt.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\nlhtml.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\msscntrs.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\mimefilt.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\chtbrkr.dll
2008-12-10 00:50:07 ----A---- C:\Windows\system32\chsbrkr.dll
2008-12-10 00:50:06 ----A---- C:\Windows\system32\tquery.dll
2008-12-10 00:50:06 ----A---- C:\Windows\system32\mssvp.dll
2008-12-10 00:50:06 ----A---- C:\Windows\system32\mssrch.dll
2008-12-10 00:50:06 ----A---- C:\Windows\system32\mssphtb.dll
2008-12-10 00:50:06 ----A---- C:\Windows\system32\mssph.dll
2008-12-10 00:03:28 ----D---- C:\Users\Puyang\AppData\Roaming\DivX
2008-12-10 00:02:54 ----D---- C:\Program Files\Common Files\PX Storage Engine
2008-12-10 00:02:44 ----D---- C:\Program Files\DivX
2008-12-10 00:02:17 ----D---- C:\Users\Puyang\AppData\Roaming\Leawo
2008-12-10 00:01:58 ----A---- C:\Windows\system32\xvidcore.dll
2008-12-10 00:01:55 ----D---- C:\Program Files\Leawo
2008-12-09 21:49:28 ----A---- C:\Windows\system32\rpcrt4.dll
2008-12-09 21:49:27 ----A---- C:\Windows\system32\pacerprf.dll
2008-12-09 21:41:08 ----A---- C:\Windows\system32\emdmgmt.dll
2008-12-09 21:41:08 ----A---- C:\Windows\system32\dataclen.dll
2008-12-09 21:41:08 ----A---- C:\Windows\system32\cdd.dll
2008-12-09 21:33:57 ----A---- C:\Windows\system32\wersvc.dll
2008-12-09 21:33:57 ----A---- C:\Windows\system32\Faultrep.dll
2008-12-09 21:32:47 ----A---- C:\Windows\system32\wshext.dll
2008-12-09 21:32:47 ----A---- C:\Windows\system32\wscript.exe
2008-12-09 21:32:47 ----A---- C:\Windows\system32\vbscript.dll
2008-12-09 21:32:47 ----A---- C:\Windows\system32\scrobj.dll
2008-12-09 21:32:47 ----A---- C:\Windows\system32\jscript.dll
2008-12-09 21:32:47 ----A---- C:\Windows\system32\cscript.exe
2008-12-09 21:32:46 ----A---- C:\Windows\system32\scrrun.dll
2008-12-09 15:23:13 ----D---- C:\Users\Puyang\AppData\Roaming\Canon
2008-12-09 12:50:13 ----D---- C:\ProgramData\NVIDIA
2008-12-09 12:48:06 ----A---- C:\Windows\system32\nvexpbar.dll
2008-12-09 12:48:06 ----A---- C:\Windows\system32\nvcpluir.dll
2008-12-09 12:48:06 ----A---- C:\Windows\system32\nvcplui.exe
2008-12-09 12:46:12 ----A---- C:\Windows\system32\NVUNINST.EXE
2008-12-09 01:23:52 ----D---- C:\Windows\Minidump
2008-12-08 23:53:58 ----A---- C:\Windows\system32\SLsvc.exe
2008-12-08 23:53:58 ----A---- C:\Windows\system32\onex.dll
2008-12-08 23:53:50 ----A---- C:\Windows\system32\PSHED.DLL
2008-12-08 23:53:49 ----A---- C:\Windows\system32\imagesp1.dll
2008-12-08 23:53:48 ----A---- C:\Windows\system32\dfsr.exe
2008-12-08 23:53:47 ----A---- C:\Windows\system32\pidgenx.dll
2008-12-08 23:53:46 ----A---- C:\Windows\system32\sstpsvc.dll
2008-12-08 23:53:46 ----A---- C:\Windows\system32\mstscax.dll
2008-12-08 23:53:45 ----A---- C:\Windows\system32\WsmSvc.dll
2008-12-08 23:53:45 ----A---- C:\Windows\system32\winrscmd.dll
2008-12-08 23:53:44 ----A---- C:\Windows\system32\sysmain.dll
2008-12-08 23:53:44 ----A---- C:\Windows\system32\RMActivate.exe
2008-12-08 23:53:41 ----A---- C:\Windows\system32\VSSVC.exe
2008-12-08 23:53:41 ----A---- C:\Windows\system32\vssapi.dll
2008-12-08 23:53:41 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2008-12-08 23:53:40 ----A---- C:\Windows\system32\secproc.dll
2008-12-08 23:53:38 ----A---- C:\Windows\system32\RMActivate_isv.exe
2008-12-08 23:53:36 ----A---- C:\Windows\system32\iesetup.dll
2008-12-08 23:53:35 ----A---- C:\Windows\system32\secproc_isv.dll
2008-12-08 23:53:33 ----A---- C:\Windows\system32\icardres.dll
2008-12-08 23:53:33 ----A---- C:\Windows\system32\drmv2clt.dll
2008-12-08 23:53:32 ----A---- C:\Windows\system32\xpssvcs.dll
2008-12-08 23:53:32 ----A---- C:\Windows\system32\icardagt.exe
2008-12-08 23:53:32 ----A---- C:\Windows\system32\blackbox.dll
2008-12-08 23:53:31 ----A---- C:\Windows\system32\RacEngn.dll
2008-12-08 23:53:30 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2008-12-08 23:53:28 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2008-12-08 23:53:25 ----A---- C:\Windows\system32\spwizimg.dll
2008-12-08 23:53:25 ----A---- C:\Windows\system32\rdpencom.dll
2008-12-08 23:53:25 ----A---- C:\Windows\system32\lpremove.exe
2008-12-08 23:53:25 ----A---- C:\Windows\bfsvc.exe
2008-12-08 23:53:24 ----A---- C:\Windows\system32\ntdll.dll
2008-12-08 23:53:24 ----A---- C:\Windows\system32\msjet40.dll
2008-12-08 23:53:23 ----A---- C:\Windows\system32\qmgr.dll
2008-12-08 23:53:23 ----A---- C:\Windows\system32\lsasrv.dll
2008-12-08 23:53:23 ----A---- C:\Windows\system32\localspl.dll
2008-12-08 23:53:22 ----A---- C:\Windows\system32\wevtsvc.dll
2008-12-08 23:53:22 ----A---- C:\Windows\system32\wcncsvc.dll
2008-12-08 23:53:22 ----A---- C:\Windows\system32\mscoree.dll
2008-12-08 23:53:22 ----A---- C:\Windows\system32\kernel32.dll
2008-12-08 23:53:22 ----A---- C:\Windows\system32\IKEEXT.DLL
2008-12-08 23:53:21 ----A---- C:\Windows\system32\TsWpfWrp.exe
2008-12-08 23:53:21 ----A---- C:\Windows\system32\recdisc.exe
2008-12-08 23:53:21 ----A---- C:\Windows\system32\CompMgmtLauncher.exe
2008-12-08 23:53:20 ----A---- C:\Windows\system32\wmp.dll
2008-12-08 23:53:20 ----A---- C:\Windows\system32\vds.exe
2008-12-08 23:53:19 ----A---- C:\Windows\system32\wcnwiz.dll
2008-12-08 23:53:19 ----A---- C:\Windows\system32\SMBHelperClass.dll
2008-12-08 23:53:19 ----A---- C:\Windows\system32\msvbvm60.dll
2008-12-08 23:53:19 ----A---- C:\Windows\system32\mstsc.exe
2008-12-08 23:53:18 ----A---- C:\Windows\system32\msdtctm.dll
2008-12-08 23:53:17 ----A---- C:\Windows\system32\termsrv.dll
2008-12-08 23:53:17 ----A---- C:\Windows\system32\kerberos.dll
2008-12-08 23:53:17 ----A---- C:\Windows\system32\IMJP10K.DLL
2008-12-08 23:53:17 ----A---- C:\Windows\system32\advapi32.dll
2008-12-08 23:53:16 ----A---- C:\Windows\system32\mmcndmgr.dll
2008-12-08 23:53:15 ----A---- C:\Windows\system32\xolehlp.dll
2008-12-08 23:53:15 ----A---- C:\Windows\system32\Query.dll
2008-12-08 23:53:15 ----A---- C:\Windows\system32\msdtcprx.dll
2008-12-08 23:53:15 ----A---- C:\Windows\system32\MPSSVC.dll
2008-12-08 23:53:15 ----A---- C:\Windows\system32\CertEnroll.dll
2008-12-08 23:53:14 ----A---- C:\Windows\system32\ole32.dll
2008-12-08 23:53:13 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
2008-12-08 23:53:13 ----A---- C:\Windows\system32\netlogon.dll
2008-12-08 23:53:12 ----A---- C:\Windows\system32\SSShim.dll
2008-12-08 23:53:12 ----A---- C:\Windows\system32\nlmgp.dll
2008-12-08 23:53:12 ----A---- C:\Windows\system32\msvcrt.dll
2008-12-08 23:53:12 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
2008-12-08 23:53:12 ----A---- C:\Windows\system32\DfsShlEx.dll
2008-12-08 23:53:11 ----A---- C:\Windows\system32\user32.dll
2008-12-08 23:53:11 ----A---- C:\Windows\system32\shlwapi.dll
2008-12-08 23:53:11 ----A---- C:\Windows\system32\sdclt.exe
2008-12-08 23:53:11 ----A---- C:\Windows\system32\schedsvc.dll
2008-12-08 23:53:11 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2008-12-08 23:53:11 ----A---- C:\Windows\system32\milcore.dll
2008-12-08 23:53:11 ----A---- C:\Windows\system32\IasMigPlugin.dll
2008-12-08 23:53:10 ----A---- C:\Windows\system32\WSDApi.dll
2008-12-08 23:53:10 ----A---- C:\Windows\system32\wer.dll
2008-12-08 23:53:10 ----A---- C:\Windows\system32\vdsdyn.dll
2008-12-08 23:53:10 ----A---- C:\Windows\system32\QAGENTRT.DLL
2008-12-08 23:53:10 ----A---- C:\Windows\system32\d3d9.dll
2008-12-08 23:53:10 ----A---- C:\Windows\system32\clusapi.dll
2008-12-08 23:53:09 ----A---- C:\Windows\system32\winrsmgr.dll
2008-12-08 23:53:09 ----A---- C:\Windows\system32\mtxclu.dll
2008-12-08 23:53:09 ----A---- C:\Windows\system32\mmc.exe
2008-12-08 23:53:09 ----A---- C:\Windows\system32\diagperf.dll
2008-12-08 23:53:08 ----A---- C:\Windows\system32\vdsbas.dll
2008-12-08 23:53:08 ----A---- C:\Windows\system32\swprv.dll
2008-12-08 23:53:08 ----A---- C:\Windows\system32\SLC.dll
2008-12-08 23:53:08 ----A---- C:\Windows\system32\msi.dll
2008-12-08 23:53:08 ----A---- C:\Windows\system32\comctl32.dll
2008-12-08 23:53:07 ----A---- C:\Windows\system32\MSVidCtl.dll
2008-12-08 23:53:07 ----A---- C:\Windows\system32\gpsvc.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\XPSSHHDR.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\sbe.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\samsrv.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\msdtckrm.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\mfc42u.dll
2008-12-08 23:53:06 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2008-12-08 23:53:06 ----A---- C:\Windows\system32\esent.dll
2008-12-08 23:53:05 ----A---- C:\Windows\system32\wecutil.exe
2008-12-08 23:53:05 ----A---- C:\Windows\system32\usp10.dll
2008-12-08 23:53:05 ----A---- C:\Windows\system32\sdengin2.dll
2008-12-08 23:53:05 ----A---- C:\Windows\system32\gacinstall.dll
2008-12-08 23:53:05 ----A---- C:\Windows\system32\cmicryptinstall.dll
2008-12-08 23:53:04 ----A---- C:\Windows\system32\mfc42.dll
2008-12-08 23:53:04 ----A---- C:\Windows\system32\comsvcs.dll
2008-12-08 23:53:04 ----A---- C:\Windows\system32\cmipnpinstall.dll
2008-12-08 23:53:03 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2008-12-08 23:53:03 ----A---- C:\Windows\system32\crypt32.dll
2008-12-08 23:53:03 ----A---- C:\Windows\system32\certutil.exe
2008-12-08 23:53:02 ----A---- C:\Windows\system32\wmdrmsdk.dll
2008-12-08 23:53:02 ----A---- C:\Windows\system32\oleaut32.dll
2008-12-08 23:53:02 ----A---- C:\Windows\system32\mswsock.dll
2008-12-08 23:53:02 ----A---- C:\Windows\system32\FirewallAPI.dll
2008-12-08 23:53:01 ----A---- C:\Windows\system32\wecsvc.dll
2008-12-08 23:53:01 ----A---- C:\Windows\system32\sqlceqp30.dll
2008-12-08 23:53:01 ----A---- C:\Windows\system32\setupapi.dll
2008-12-08 23:53:01 ----A---- C:\Windows\system32\sdohlp.dll
2008-12-08 23:53:01 ----A---- C:\Windows\system32\lsm.exe
2008-12-08 23:53:01 ----A---- C:\Windows\system32\bcrypt.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\wmpmde.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\thumbcache.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\schannel.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\p2psvc.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\msv1_0.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\iphlpsvc.dll
2008-12-08 23:53:00 ----A---- C:\Windows\system32\eapp3hst.dll
2008-12-08 23:52:59 ----A---- C:\Windows\system32\WinSAT.exe
2008-12-08 23:52:59 ----A---- C:\Windows\system32\vdsutil.dll
2008-12-08 23:52:59 ----A---- C:\Windows\system32\riched20.dll
2008-12-08 23:52:59 ----A---- C:\Windows\system32\imapi2fs.dll
2008-12-08 23:52:59 ----A---- C:\Windows\system32\d3d10_1.dll
2008-12-08 23:52:59 ----A---- C:\Windows\system32\autofmt.exe
2008-12-08 23:52:59 ----A---- C:\Windows\system32\autoconv.exe
2008-12-08 23:52:59 ----A---- C:\Windows\system32\autochk.exe
2008-12-08 23:52:58 ----A---- C:\Windows\system32\authui.dll
2008-12-08 23:52:58 ----A---- C:\Windows\system32\authfwcfg.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\WSDMon.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\wevtapi.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\mscories.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\eapphost.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\dmvdsitf.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\d3d10_1core.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\comuid.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\comdlg32.dll
2008-12-08 23:52:57 ----A---- C:\Windows\system32\browseui.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\wevtfwd.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\untfs.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\uexfat.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\rasmans.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\iassam.dll
2008-12-08 23:52:56 ----A---- C:\Windows\system32\eappcfg.dll
2008-12-08 23:52:55 ----A---- C:\Windows\system32\wlansvc.dll
2008-12-08 23:52:55 ----A---- C:\Windows\system32\whealogr.dll
2008-12-08 23:52:55 ----A---- C:\Windows\system32\sqlcese30.dll
2008-12-08 23:52:55 ----A---- C:\Windows\system32\pcaui.dll
2008-12-08 23:52:55 ----A---- C:\Windows\system32\DfrgNtfs.exe
2008-12-08 23:52:53 ----A---- C:\Windows\system32\dot3svc.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\zipfldr.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\WsmAuto.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\winhttp.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\rdpwsx.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\nlasvc.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\mssha.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\msdrm.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\evr.dll
2008-12-08 23:52:51 ----A---- C:\Windows\system32\dfrgui.exe
2008-12-08 23:52:50 ----A---- C:\Windows\system32\rpcss.dll
2008-12-08 23:52:50 ----A---- C:\Windows\system32\rasppp.dll
2008-12-08 23:52:50 ----A---- C:\Windows\system32\ncrypt.dll
2008-12-08 23:52:50 ----A---- C:\Windows\system32\msrepl40.dll
2008-12-08 23:52:50 ----A---- C:\Windows\system32\BFE.DLL
2008-12-08 23:52:50 ----A---- C:\Windows\system32\audiosrv.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\WsmWmiPl.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\wmdrmdev.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\rastls.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\printui.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\dhcpcsvc6.dll
2008-12-08 23:52:49 ----A---- C:\Windows\system32\ddraw.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\WebClnt.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\themecpl.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\sqlsrv32.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\QAGENT.DLL
2008-12-08 23:52:48 ----A---- C:\Windows\system32\objsel.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\iasnap.dll
2008-12-08 23:52:48 ----A---- C:\Windows\system32\dbghelp.dll
2008-12-08 23:52:47 ----A---- C:\Windows\system32\w32time.dll
2008-12-08 23:52:47 ----A---- C:\Windows\system32\PresentationHost.exe
2008-12-08 23:52:47 ----A---- C:\Windows\system32\ncryptui.dll
2008-12-08 23:52:47 ----A---- C:\Windows\system32\icm32.dll
2008-12-08 23:52:46 ----A---- C:\Windows\system32\wmdrmnet.dll
2008-12-08 23:52:46 ----A---- C:\Windows\system32\WerFaultSecure.exe
2008-12-08 23:52:46 ----A---- C:\Windows\system32\spoolss.dll
2008-12-08 23:52:46 ----A---- C:\Windows\system32\iprtrmgr.dll
2008-12-08 23:52:46 ----A---- C:\Windows\system32\azroles.dll
2008-12-08 23:52:45 ----A---- C:\Windows\system32\winsrv.dll
2008-12-08 23:52:45 ----A---- C:\Windows\system32\taskschd.dll
2008-12-08 23:52:45 ----A---- C:\Windows\system32\msctf.dll
2008-12-08 23:52:45 ----A---- C:\Windows\system32\infocardapi.dll
2008-12-08 23:52:45 ----A---- C:\Windows\system32\bcdedit.exe
2008-12-08 23:52:45 ----A---- C:\Windows\system32\basecsp.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\wlangpui.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\winsta.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\scksp.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\netprofm.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\mstlsapi.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\dbgeng.dll
2008-12-08 23:52:44 ----A---- C:\Windows\system32\AudioEng.dll
2008-12-08 23:52:43 ----A---- C:\Windows\system32\rsaenh.dll
2008-12-08 23:52:43 ----A---- C:\Windows\system32\netcfgx.dll
2008-12-08 23:52:42 ----A---- C:\Windows\system32\winlogon.exe
2008-12-08 23:52:42 ----A---- C:\Windows\system32\wercon.exe
2008-12-08 23:52:42 ----A---- C:\Windows\system32\taskcomp.dll
2008-12-08 23:52:42 ----A---- C:\Windows\system32\lpksetup.exe
2008-12-08 23:52:42 ----A---- C:\Windows\system32\dfshim.dll
2008-12-08 23:52:42 ----A---- C:\Windows\system32\cdosys.dll
2008-12-08 23:52:41 ----A---- C:\Windows\system32\wlansec.dll
2008-12-08 23:52:41 ----A---- C:\Windows\system32\msdtcuiu.dll
2008-12-08 23:52:41 ----A---- C:\Windows\system32\mprddm.dll
2008-12-08 23:52:41 ----A---- C:\Windows\system32\certcli.dll
2008-12-08 23:52:41 ----A---- C:\Windows\system32\apds.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\tsgqec.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\shdocvw.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\iasrad.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\eapsvc.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\AUDIOKSE.dll
2008-12-08 23:52:40 ----A---- C:\Windows\system32\aaclient.dll
2008-12-08 23:52:39 ----A---- C:\Windows\system32\bcdsrv.dll
2008-12-08 23:52:35 ----A---- C:\Windows\system32\uDWM.dll
2008-12-08 23:52:35 ----A---- C:\Windows\system32\certmgr.dll
2008-12-08 23:52:34 ----A---- C:\Windows\system32\Wldap32.dll
2008-12-08 23:52:34 ----A---- C:\Windows\system32\umpnpmgr.dll
2008-12-08 23:52:34 ----A---- C:\Windows\system32\msidcrl30.dll
2008-12-08 23:52:34 ----A---- C:\Windows\system32\dnsapi.dll
2008-12-08 23:52:33 ----A---- C:\Windows\system32\WMVDECOD.DLL
2008-12-08 23:52:33 ----A---- C:\Windows\system32\pla.dll
2008-12-08 23:52:33 ----A---- C:\Windows\system32\dxgi.dll
2008-12-08 23:52:32 ----A---- C:\Windows\system32\wmicmiplugin.dll
2008-12-08 23:52:32 ----A---- C:\Windows\system32\netshell.dll
2008-12-08 23:52:32 ----A---- C:\Windows\system32\dot3gpui.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\winmm.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\shsvcs.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\ntprint.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\MMDevAPI.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\cryptnet.dll
2008-12-08 23:52:31 ----A---- C:\Windows\system32\comsnap.dll
2008-12-08 23:52:30 ----A---- C:\Windows\system32\wscsvc.dll
2008-12-08 23:52:30 ----A---- C:\Windows\system32\wscisvif.dll
2008-12-08 23:52:30 ----A---- C:\Windows\system32\synceng.dll
2008-12-08 23:52:30 ----A---- C:\Windows\system32\services.exe
2008-12-08 23:52:30 ----A---- C:\Windows\system32\pnidui.dll
2008-12-08 23:52:30 ----A---- C:\Windows\system32\cmifw.dll
2008-12-08 23:52:29 ----A---- C:\Windows\system32\WMVSDECD.DLL
2008-12-08 23:52:29 ----A---- C:\Windows\system32\taskeng.exe
2008-12-08 23:52:29 ----A---- C:\Windows\system32\msjtes40.dll
2008-12-08 23:52:29 ----A---- C:\Windows\system32\msconfig.exe
2008-12-08 23:52:29 ----A---- C:\Windows\system32\iassdo.dll
2008-12-08 23:52:29 ----A---- C:\Windows\system32\cipher.exe
2008-12-08 23:52:28 ----A---- C:\Windows\system32\uxtheme.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\tdh.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\SessEnv.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\rasapi32.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\imapi2.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\dot3api.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\dmdskmgr.dll
2008-12-08 23:52:28 ----A---- C:\Windows\system32\cmd.exe
2008-12-08 23:52:27 ----A---- C:\Windows\system32\wlanmsm.dll
2008-12-08 23:52:27 ----A---- C:\Windows\system32\wkssvc.dll
2008-12-08 23:52:27 ----A---- C:\Windows\system32\wevtutil.exe
2008-12-08 23:52:27 ----A---- C:\Windows\system32\srvsvc.dll
2008-12-08 23:52:27 ----A---- C:\Windows\system32\qdvd.dll
2008-12-08 23:52:27 ----A---- C:\Windows\system32\msscp.dll
2008-12-08 23:52:27 ----A---- C:\Windows\system32\cbsra.exe
2008-12-08 23:52:27 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\WUDFx.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\wlancfg.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\mshtmled.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\msdtcVSp1res.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\localsec.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\loadperf.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\fontext.dll
2008-12-08 23:52:26 ----A---- C:\Windows\system32\diskpart.exe
2008-12-08 23:52:26 ----A---- C:\Windows\system32\comres.dll
2008-12-08 23:52:25 ----A---- C:\Windows\system32\wlanapi.dll
2008-12-08 23:52:25 ----A---- C:\Windows\system32\rpchttp.dll
2008-12-08 23:52:25 ----A---- C:\Windows\system32\rdpdd.dll
2008-12-08 23:52:25 ----A---- C:\Windows\system32\hnetcfg.dll
2008-12-08 23:52:24 ----A---- C:\Windows\system32\wsqmcons.exe
2008-12-08 23:52:24 ----A---- C:\Windows\system32\WMADMOD.DLL
2008-12-08 23:52:24 ----A---- C:\Windows\system32\wlanpref.dll
2008-12-08 23:52:24 ----A---- C:\Windows\system32\WinSATAPI.dll
2008-12-08 23:52:24 ----A---- C:\Windows\system32\NAPMONTR.DLL
2008-12-08 23:52:24 ----A---- C:\Windows\system32\dsound.dll
2008-12-08 23:52:23 ----A---- C:\Windows\system32\RDPENCDD.dll
2008-12-08 23:52:23 ----A---- C:\Windows\system32\profprov.dll
2008-12-08 23:52:23 ----A---- C:\Windows\system32\filemgmt.dll
2008-12-08 23:52:23 ----A---- C:\Windows\system32\avifil32.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\wsecedit.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\WMSPDMOD.DLL
2008-12-08 23:52:22 ----A---- C:\Windows\system32\tracerpt.exe
2008-12-08 23:52:22 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\SLCommDlg.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\P2PGraph.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\MuiUnattend.exe
2008-12-08 23:52:22 ----A---- C:\Windows\system32\dwmredir.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\dnsrslvr.dll
2008-12-08 23:52:22 ----A---- C:\Windows\system32\dhcpcsvc.dll
2008-12-08 23:52:21 ----A---- C:\Windows\system32\wininit.exe
2008-12-08 23:52:21 ----A---- C:\Windows\system32\spp.dll
2008-12-08 23:52:21 ----A---- C:\Windows\system32\QSHVHOST.DLL
2008-12-08 23:52:21 ----A---- C:\Windows\system32\iassvcs.dll
2008-12-08 23:52:21 ----A---- C:\Windows\system32\gpresult.exe
2008-12-08 23:52:21 ----A---- C:\Windows\system32\dwm.exe
2008-12-08 23:52:21 ----A---- C:\Windows\system32\apphelp.dll
2008-12-08 23:52:20 ----A---- C:\Windows\system32\rasdlg.dll
2008-12-08 23:52:20 ----A---- C:\Windows\system32\mscorier.dll
2008-12-08 23:52:20 ----A---- C:\Windows\system32\iashost.exe
2008-12-08 23:52:20 ----A---- C:\Windows\system32\azroleui.dll
2008-12-08 23:52:20 ----A---- C:\Windows\HelpPane.exe
2008-12-08 23:52:19 ----A---- C:\Windows\system32\srrstr.dll
2008-12-08 23:52:19 ----A---- C:\Windows\system32\spwizeng.dll
2008-12-08 23:52:19 ----A---- C:\Windows\system32\SLUI.exe
2008-12-08 23:52:19 ----A---- C:\Windows\system32\rasmontr.dll
2008-12-08 23:52:19 ----A---- C:\Windows\system32\mcbuilder.exe
2008-12-08 23:52:18 ----A---- C:\Windows\system32\wecapi.dll
2008-12-08 23:52:18 ----A---- C:\Windows\system32\unbcl.dll
2008-12-08 23:52:18 ----A---- C:\Windows\system32\tcpmon.dll
2008-12-08 23:52:18 ----A---- C:\Windows\system32\shrink.dll
2008-12-08 23:52:18 ----A---- C:\Windows\system32\msra.exe
2008-12-08 23:52:18 ----A---- C:\Windows\system32\lltdsvc.dll
2008-12-08 23:52:18 ----A---- C:\Windows\system32\IPHLPAPI.DLL
2008-12-08 23:52:17 ----A---- C:\Windows\system32\WMPEncEn.dll
2008-12-08 23:52:17 ----A---- C:\Windows\system32\raschap.dll
2008-12-08 23:52:17 ----A---- C:\Windows\system32\oleacc.dll
2008-12-08 23:52:17 ----A---- C:\Windows\system32\iashlpr.dll
2008-12-08 23:52:17 ----A---- C:\Windows\system32\gpedit.dll
2008-12-08 23:52:17 ----A---- C:\Windows\system32\brcpl.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\vsstrace.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\regsvc.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\PerfCenterCPL.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\ntvdm.exe
2008-12-08 23:52:16 ----A---- C:\Windows\system32\ipsmsnap.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\framedynos.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\fdWSD.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\EncDec.dll
2008-12-08 23:52:16 ----A---- C:\Windows\system32\advpack.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\wpdshext.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\wdc.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\Storprop.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\ntlanman.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\netman.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\l2nacp.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\iedkcs32.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\ieapfltr.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\framedyn.dll
2008-12-08 23:52:15 ----A---- C:\Windows\system32\dssenh.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\WlanMM.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\WLanConn.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\tcpipcfg.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\sxs.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\profsvc.dll
2008-12-08 23:52:14 ----A---- C:\Windows\system32\KMSVC.DLL
2008-12-08 23:52:14 ----A---- C:\Windows\system32\certreq.exe
2008-12-08 23:52:14 ----A---- C:\Windows\system32\adsnt.dll
2008-12-08 23:52:13 ----A---- C:\Windows\system32\wusa.exe
2008-12-08 23:52:13 ----A---- C:\Windows\system32\WUDFHost.exe
2008-12-08 23:52:13 ----A---- C:\Windows\system32\WsmProv.dll
2008-12-08 23:52:13 ----A---- C:\Windows\system32\wlanhlp.dll
2008-12-08 23:52:13 ----A---- C:\Windows\system32\userenv.dll
2008-12-08 23:52:13 ----A---- C:\Windows\system32\ncsi.dll
2008-12-08 23:52:13 ----A---- C:\Windows\system32\IPBusEnum.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\WerFault.exe
2008-12-08 23:52:12 ----A---- C:\Windows\system32\VAN.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\umb.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\puiobj.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\netid.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\ie4uinit.exe
2008-12-08 23:52:12 ----A---- C:\Windows\system32\fundisc.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\dps.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\cryptui.dll
2008-12-08 23:52:12 ----A---- C:\Windows\system32\catsrvut.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\ws2_32.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\WinSCard.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\spbcd.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\photowiz.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\netcenter.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\msinfo32.exe
2008-12-08 23:52:11 ----A---- C:\Windows\system32\MdSched.exe
2008-12-08 23:52:11 ----A---- C:\Windows\system32\ipsecsnp.dll
2008-12-08 23:52:11 ----A---- C:\Windows\system32\InkEd.dll
2008-12-08 23:52:10 ----A---- C:\Windows\system32\winrs.exe
2008-12-08 23:52:10 ----A---- C:\Windows\system32\secur32.dll
2008-12-08 23:52:10 ----A---- C:\Windows\system32\prnntfy.dll
2008-12-08 23:52:10 ----A---- C:\Windows\system32\odbcjt32.dll
2008-12-08 23:52:10 ----A---- C:\Windows\system32\ntdsapi.dll
2008-12-08 23:52:10 ----A---- C:\Windows\system32\NAPSTAT.EXE
2008-12-08 23:52:09 ----A---- C:\Windows\system32\schtasks.exe
2008-12-08 23:52:09 ----A---- C:\Windows\system32\RelMon.dll
2008-12-08 23:52:09 ----A---- C:\Windows\system32\msfeeds.dll
2008-12-08 23:52:09 ----A---- C:\Windows\system32\mblctr.exe
2008-12-08 23:52:09 ----A---- C:\Windows\system32\cryptsvc.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\TSpkg.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\pdh.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\netdiagfx.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\iasacct.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\FirewallControlPanel.exe
2008-12-08 23:52:08 ----A---- C:\Windows\system32\dmdlgs.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\dhcpsapi.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\dfrgfat.exe
2008-12-08 23:52:08 ----A---- C:\Windows\system32\catsrv.dll
2008-12-08 23:52:08 ----A---- C:\Windows\system32\activeds.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32\wvc.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32\winrm.vbs
2008-12-08 23:52:07 ----A---- C:\Windows\system32\qwave.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32\netcorehc.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32\NAPHLPR.DLL
2008-12-08 23:52:07 ----A---- C:\Windows\system32\msacm32.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32\ifmon.dll
2008-12-08 23:52:07 ----A---- C:\Windows\system32