Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 11-28-2006, 02:48 PM   #1 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
programs do not open/close right, pop ups, and IE home page changes

This is the HJT log from my computer at work. It was in storage for 2 years. Then brouhgt to the office and hooked up to the internet. The AV was not activated for 4 months. It had no protection for that time. I followed all the steps, before posting. I thank You for your help.

Brain Stew
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 11-28-2006, 03:15 PM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


Hi Brain Stew -

I think you left something out.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-28-2006, 04:00 PM   #3 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
Suprised Sorry

I was at work after hours and in a Hurry. I will have to post my log tommorow. Thank You for your time, and your quick resopnce.
Brain Stew
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-29-2006, 07:25 AM   #4 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
not today

I am not going to post my HJT log just yet. Spybot keeps finding smithfruad/Zlob. It tells me it is fixed, Yet I keep getting thier pop ups.

I will try smithfruadFix in sasfemode and see if that helps. Thank You for your time.
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-29-2006, 07:03 PM   #5 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
Here is My Log

I Think I have done all I can. My last 4 scans have all come up clean. 3 were in safe mode and the last one was eTrust. If You have time, could you look at my log and let me know thank You.

Quote:
Logfile of HijackThis v1.99.1
Scan saved at 5:30:30 PM, on 11/29/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sourcelink.mclaneco.com/login.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hastings KFC Jomida Inc.
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,asus.exe,
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\System32\mntkctlg.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Rwfpt Class - {0BDB22C0-BD18-4A40-9A9D-71F314BB75DB} - C:\WINDOWS\System32\lt5vsrs.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AECBB5D5-03BD-4A18-8A1E-FDF34FD183C4} - \
O2 - BHO: (no name) - {CC1A2C48-84F4-4DAC-AEAC-41DF6344C84D} - (no file)
O2 - BHO: (no name) - {E25B21B7-1E8E-44E2-AC8C-63FC8CFC9EDB} - C:\WINDOWS\Fonts\sissvs.dll (file missing)
O2 - BHO: (no name) - {ECC0749B-9C28-4FD5-AF5B-367DF325CF9F} - \
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/reso...scbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159410032375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1164659162875
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Filter: text/html - {D1C66A56-872E-4489-BA60-04AA1E2996BB} - C:\WINDOWS\System32\lt5vsrs.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: rqrrpmj - rqrrpmj.dll (file missing)
O20 - Winlogon Notify: sissvs - C:\WINDOWS\Fonts\sissvs.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-29-2006, 09:51 PM   #6 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


You've still got a bit of a mess there. I'd like to see logs from AVG AntiSpyware (C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports) and SmitfraudFix (C:\rapport.txt).

What 'last 4 scans' came up clean?

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\System32\mntkctlg.dll (file missing)
O2 - BHO: Rwfpt Class - {0BDB22C0-BD18-4A40-9A9D-71F314BB75DB} - C:\WINDOWS\System32\lt5vsrs.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {AECBB5D5-03BD-4A18-8A1E-FDF34FD183C4} - \
O2 - BHO: (no name) - {CC1A2C48-84F4-4DAC-AEAC-41DF6344C84D} - (no file)
O2 - BHO: (no name) - {E25B21B7-1E8E-44E2-AC8C-63FC8CFC9EDB} - C:\WINDOWS\Fonts\sissvs.dll (file missing)
O2 - BHO: (no name) - {ECC0749B-9C28-4FD5-AF5B-367DF325CF9F} - \
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run
O18 - Filter: text/html - {D1C66A56-872E-4489-BA60-04AA1E2996BB} - C:\WINDOWS\System32\lt5vsrs.dll
O20 - Winlogon Notify: rqrrpmj - rqrrpmj.dll (file missing)
O20 - Winlogon Notify: sissvs - C:\WINDOWS\Fonts\sissvs.dll (file missing)


Close HijackThis now.

---------------------------------------------------------------------------------------------

Go to My Computer->Tools->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Also make sure there is no checkmark beside Hide file extensions for known file types
* Click Yes to confirm and then click OK.


Delete the following if they exist:

C:\WINDOWS\System32\eaovmp.exe
C:\WINDOWS\System32\lt5vsrs.dll


---------------------------------------------------------------------------------------------
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.

Also, please do this:
  1. Download combofix.exe to your desktop.
  2. Double click on combofix.exe & follow the prompts.
  3. When finished, it shall produce a log for you. Post that log in your next reply.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Establish an internet connection & perform an online scan using Internet Explorer at http://www.kaspersky.com/service?chapter=161739400

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

---------------------------------------------------------------------------------------------

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.

---------------------------------------------------------------------------------------------

Open Hijack This and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

---------------------------------------------------------------------------------------------

Please return with results from:

AVG A/S (if you ran it before posting HJT log)
C:\rapport.txt (as you said you ran the tool)
C:\SDFix\report.txt
ComboFix.txt
Kaspersky online scan


How is your system behaving?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 06:37 AM   #7 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
raport. txt

my last 4 scans were sapybot, avg 7.5 av, SuperAntispyware, in safemode. Then I went to eTrust online scan. spybot, SuperAtispyware, and eTrust found nothing. AVG found a trojan horse.

Quote:
SmitFraudFix v2.125

Scan done at 16:27:58.95, Wed 11/29/2006
Run from C:\Documents and Settings\Brain Stew\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
I will print and follow your directions, and enclose the reports you need in my next post. Thank You
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 06:56 AM   #8 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
system is not behaving right.

office programs, excel, outlook, will not "save as" or close right. explorer.exe will shutdown and restart on its own. I will go to open somthing on my desktop, as soon click on what I want everything will be gone for a second or two and then come back. There have been a couple of times I used start>run, or task manager> new task to get explorer.exe to come back. Also there have been times when the webpage we need will not load, but we will get a popup. These popups tell me I am infected and they have the software I need to fix it. It runs very slow, all the time.
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 08:35 AM   #9 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


Sounds like there are serious OS corruption issues, and no amount of malware removal might address them.

The popups you describe are indicative of a smitfraud infection, but the log shows clean. However, the bad guys and the tool author are updating all the time.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #4 - Check for Updates by typing 4 and press "Enter"

Follow the prompts and make sure your firewall allows access to the interent.

Then,
Select option #1 - Search by typing 1 and press "Enter"
and a text file will appear which lists infected files (if present).
Please copy/paste the content of that report into your next reply.



Once I have the next logs, we can think about the corruption issues.

Do you have a Windows XP install disk available?

I'd still like to see a recent AVG A/S report, to see what infections it removed.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 08:29 PM   #10 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
reports

when I ran my avg A/S I quarantined everything and my reports folder was empty. How ever I also ran a bit defender online scan after I ran avg a/s. The items on the bitdefender report looked very much like those in qurantine, so I will post that report. I do not have the os recovery disk, need be I could get it though.

Quote:
Logfile of HijackThis v1.99.1
Scan saved at 20:18, on 06-11-30
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sourcelink.mclaneco.com/login.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/reso...scbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159410032375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1164659162875
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{569CD1C4-218E-451D-A155-CF233584F8D7}: NameServer = 64.136.173.4 64.136.164.76
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Quote:
BitDefender Online Scanner - Real Time Virus ReportBitDefender Online
Scanner - Real Time Virus Report
Generated at: Tue, Nov 28, 2006 - 10:22:01




Scan Info
Scanned Files237406
Infected Files39


Virus Detected
Trojan.BHO.G26
Trojan.Downloader.VB.QB1
Trojan.PWS.Lineage.E4
Trojan.Downloader.VB.RV2
Trojan.Downloader.Small.ALG1
GenPack:Generic.Sdbot.5408C4F22
Backdoor.Pcclient.CC1
Trojan.Downloader.Qoologic.BC2





This summary of the scan process will be used by the BitDefender Antivirus
Lab to create agregate statistics about virus activity around the world.

Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 08:47 PM   #11 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
SDFix

Quote:
SDFix: Version 1.44
-------------------

Thu 11/30/2006 - 15:37:05.07


Microsoft Windows XP [Version 5.1.2600]

Running from C:\SDFix

Stage One - Safe Mode
Service Check...

Service Name:
------------

FilePath:
--------


Starting Registry Repairs...


Restoring Default Hosts File...

Stage One Complete

Rebooting...

Stage Two - Normal Mode

Checking For Malware:
--------------------

C:\MC44A36.EXE

Backing Up and Removing any Files Found...

Final Check:

Services:
---------


Authorized Applications Export:


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List

Files:
------

Checking For Hidden Files:

C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\WINDOWS\Fonts\svssis.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\3a84255fa53bf624e6efd81d8d5d3ebf\download\BITC1.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\da2f0608e733122385625f65db46b421\BIT1.tmp
C:\WINDOWS\SYSTEM32\uvvwa.tmp


Backups folder: - C:\SDFix\backups\backups.zip

FINISHED!
Quote:
Hastings KFC - 06-11-30 17:09:26.28 Service Pack 1
ComboFix 06.12.01W - Running from: "C:\Documents and Settings\Hastings KFC\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-11-06 09:37 142 dvude.dll.qoo
06-11-01 09:21 53 nnopbe.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\deskbar_e29.exe
C:\deskbar_e31.exe
C:\deskbar_e34.exe
C:\Installer4.exe
C:\WINDOWS\system32\drivers\fad.sys


((((((((((((((((((((((((((((((( Files Created from 2006-10-30 to 2006-11-30 ))))))))))))))))))))))))))))))))))


2006-11-30 17:13 <DIR> d-------- C:\WINDOWS\erdnt
2006-11-30 17:08 <DIR> d-------- C:\WINDOWS\temp
2006-11-30 16:57 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2006-11-30 16:37 <DIR> d-------- C:\Program Files\Java
2006-11-30 16:37 <DIR> d-------- C:\Program Files\Common Files\Java
2006-11-30 15:12 <DIR> d-------- C:\SDFix
2006-11-30 14:52 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\AVG7
2006-11-30 14:50 <DIR> dr-h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\SendTo
2006-11-30 14:50 <DIR> dr-h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\Recent
2006-11-30 14:50 <DIR> dr-h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\.
2006-11-30 14:50 <DIR> dr-h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data
2006-11-30 14:50 <DIR> dr------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Start Menu
2006-11-30 14:50 <DIR> dr------- C:\Documents and Settings\Brain Stew.D4ZR6H41\My Documents
2006-11-30 14:50 <DIR> dr------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Favorites
2006-11-30 14:50 <DIR> d--h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\Templates
2006-11-30 14:50 <DIR> d--h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\PrintHood
2006-11-30 14:50 <DIR> d--h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\NetHood
2006-11-30 14:50 <DIR> d--h----- C:\Documents and Settings\Brain Stew.D4ZR6H41\Local Settings
2006-11-30 14:50 <DIR> d---s---- C:\Documents and Settings\Brain Stew.D4ZR6H41\Cookies
2006-11-30 14:50 <DIR> d---s---- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Microsoft
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Desktop
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Symantec
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Sun
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Real
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Jasc Software Inc
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\Identities
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\Application Data\..
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\..
2006-11-30 14:50 <DIR> d-------- C:\Documents and Settings\Brain Stew.D4ZR6H41\.
2006-11-29 16:28 3,040 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2006-11-28 15:35 <DIR> d-------- C:\HJT
2006-11-28 14:41 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2006-11-27 11:06 <DIR> d-------- C:\Program Files\CCleaner
2006-11-27 09:32 11,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxscrmbl.sys
2006-11-26 14:48 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2006-11-26 14:41 21,312 --a------ C:\WINDOWS\choice.exe
2006-11-26 14:40 <DIR> d-------- C:\ie-spyad
2006-11-26 14:37 <DIR> d-------- C:\Program Files\CleanUp!
2006-11-26 08:48 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2006-11-26 08:44 <DIR> d-------- C:\Program Files\SpywareBlaster
2006-11-26 08:43 90,112 --a------ C:\WINDOWS\SYSTEM32\SnoopFreeSvc.exe
2006-11-26 08:43 9,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SnopFree.sys
2006-11-26 08:43 45,056 --a------ C:\WINDOWS\SnoopFreeDll.dll
2006-11-26 08:43 221,184 --a------ C:\WINDOWS\SnoopFreeUI.exe
2006-11-25 10:56 <DIR> dr-h----- C:\$VAULT$.AVG
2006-11-25 09:09 816,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys
2006-11-25 09:09 4,224 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsw.sys
2006-11-25 09:09 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
2006-11-25 09:09 28,416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsxp.sys
2006-11-25 09:09 18,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
2006-11-25 09:09 110,592 --a------ C:\WINDOWS\SYSTEM32\avgfwafu.dll
2006-11-25 09:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2006-11-25 09:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2006-11-22 14:31 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2006-11-22 14:30 <DIR> d-------- C:\Program Files\Grisoft
2006-11-21 11:58 155,648 --a------ C:\WINDOWS\SYSTEM32\igfxres.dll
2006-11-21 11:18 <DIR> d-------- C:\WINDOWS\Prefetch
2006-11-15 10:38 <DIR> d-------- C:\Program Files\Google
2006-11-15 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google
2006-11-14 18:08 <DIR> d-------- C:\WINDOWS\SYSTEM32\appmgmt
2006-11-14 15:20 <DIR> d-------- C:\WINDOWS\WBEM
2006-11-14 15:20 <DIR> d-------- C:\WINDOWS\SYSTEM32\en-US
2006-11-14 15:19 221,184 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-14 15:19 146,432 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-14 15:18 121,856 --------- C:\WINDOWS\SYSTEM32\xmllite.dll
2006-11-14 13:39 221,184 --a------ C:\WINDOWS\SYSTEM32\wmpns.dll
2006-11-14 13:36 <DIR> d-------- C:\WINDOWS\provisioning
2006-11-14 13:36 <DIR> d-------- C:\WINDOWS\peernet
2006-11-14 13:24 20,480 --a------ C:\WINDOWS\SYSTEM32\sprecovr.exe
2006-11-14 13:22 997,888 --a------ C:\WINDOWS\SYSTEM32\wmvdmoe2.dll
2006-11-14 13:22 9,216 --a------ C:\WINDOWS\SYSTEM32\wuauserv.dll
2006-11-14 13:22 892,416 --a------ C:\WINDOWS\SYSTEM32\wmspdmoe.dll
2006-11-14 13:22 891,711 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys
2006-11-14 13:22 755,200 --a------ C:\WINDOWS\SYSTEM32\ir50_32.dll
2006-11-14 13:22 52,224 --a------ C:\WINDOWS\SYSTEM32\mspmsnsv.dll
2006-11-14 13:22 504,832 --a------ C:\WINDOWS\SYSTEM32\msftedit.dll
2006-11-14 13:22 486,536 --a------ C:\WINDOWS\SYSTEM32\wmspdmod.dll
2006-11-14 13:22 403,456 --a------ C:\WINDOWS\SYSTEM32\winbrand.dll
2006-11-14 13:22 384,512 --a------ C:\WINDOWS\SYSTEM32\mp4sdmod.dll
2006-11-14 13:22 361,984 --a------ C:\WINDOWS\SYSTEM32\qmgr.dll
2006-11-14 13:22 338,432 --a------ C:\WINDOWS\SYSTEM32\ir41_qcx.dll
2006-11-14 13:22 331,776 --a------ C:\WINDOWS\SYSTEM32\winhttp.dll
2006-11-14 13:22 32,512 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\amdk7.sys
2006-11-14 13:22 316,040 --a------ C:\WINDOWS\SYSTEM32\mp43dmod.dll
2006-11-14 13:22 3,584 --a------ C:\WINDOWS\SYSTEM32\dsprpres.dll
2006-11-14 13:22 3,494,303 --a------ C:\WINDOWS\SYSTEM32\nv4_disp.dll
2006-11-14 13:22 29,696 --a------ C:\WINDOWS\SYSTEM32\asr_pfu.exe
2006-11-14 13:22 29,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\agpcpq.sys
2006-11-14 13:22 27,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys
2006-11-14 13:22 27,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\alim1541.sys
2006-11-14 13:22 27,392 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\viaagp.sys
2006-11-14 13:22 26,112 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys
2006-11-14 13:22 25,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
2006-11-14 13:22 218,112 --a------ C:\WINDOWS\SYSTEM32\sbe.dll
2006-11-14 13:22 200,192 --a------ C:\WINDOWS\SYSTEM32\ir50_qc.dll
2006-11-14 13:22 187,904 --a------ C:\WINDOWS\SYSTEM32\xpsp1res.dll
2006-11-14 13:22 183,808 --a------ C:\WINDOWS\SYSTEM32\ir50_qcx.dll
2006-11-14 13:22 18,944 --a------ C:\WINDOWS\SYSTEM32\encapi.dll
2006-11-14 13:22 172,032 --a------ C:\WINDOWS\SYSTEM32\mssap.dll
2006-11-14 13:22 16,896 --a------ C:\WINDOWS\SYSTEM32\secedit.exe
2006-11-14 13:22 159,232 --a------ C:\WINDOWS\SYSTEM32\xpob2res.dll
2006-11-14 13:22 155,648 --a------ C:\WINDOWS\SYSTEM32\encdec.dll
2006-11-14 13:22 143,360 --a------ C:\WINDOWS\SYSTEM32\wmidx.dll
2006-11-14 13:22 120,320 --a------ C:\WINDOWS\SYSTEM32\ir41_qc.dll
2006-11-14 13:22 110,080 --a------ C:\WINDOWS\SYSTEM32\sbeio.dll
2006-11-14 13:22 10,752 --a------ C:\WINDOWS\SYSTEM32\spiisupd.exe
2006-11-14 13:22 1,675,264 --a------ C:\WINDOWS\SYSTEM32\dxdiagn.dll
2006-11-14 13:22 1,634,304 --a------ C:\WINDOWS\SYSTEM32\d3d9.dll
2006-11-14 13:22 1,111,040 --a------ C:\WINDOWS\SYSTEM32\wmsdmoe2.dll
2006-11-14 13:21 97,792 --a------ C:\WINDOWS\SYSTEM32\mqtgsvc.exe
2006-11-14 13:21 88,576 --a------ C:\WINDOWS\SYSTEM32\mqsec.dll
2006-11-14 13:21 73,728 --a------ C:\WINDOWS\SYSTEM32\tlntsess.exe
2006-11-14 13:21 7,680 --a------ C:\WINDOWS\SYSTEM32\bitsprx2.dll
2006-11-14 13:21 7,168 --a------ C:\WINDOWS\SYSTEM32\tlntsvrp.dll
2006-11-14 13:21 7,168 --a------ C:\WINDOWS\SYSTEM32\bitsprx3.dll
2006-11-14 13:21 67,584 --a------ C:\WINDOWS\SYSTEM32\tlntsvr.exe
2006-11-14 13:21 67,584 --a------ C:\WINDOWS\SYSTEM32\fdeploy.dll
2006-11-14 13:21 67,456 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mqac.sys
2006-11-14 13:21 61,440 --a------ C:\WINDOWS\SYSTEM32\openfiles.exe
2006-11-14 13:21 608,768 --a------ C:\WINDOWS\SYSTEM32\mqqm.dll
2006-11-14 13:21 595,968 --a------ C:\WINDOWS\SYSTEM32\xpsp2res.dll
2006-11-14 13:21 57,856 --a------ C:\WINDOWS\SYSTEM32\tlntadmn.exe
2006-11-14 13:21 57,856 --a------ C:\WINDOWS\SYSTEM32\nwwks.dll
2006-11-14 13:21 55,808 --a------ C:\WINDOWS\SYSTEM32\mqlogmgr.dll
2006-11-14 13:21 55,296 --a------ C:\WINDOWS\SYSTEM32\logman.exe
2006-11-14 13:21 545,792 --a------ C:\WINDOWS\SYSTEM32\wsecedit.dll
2006-11-14 13:21 5,632 --a------ C:\WINDOWS\SYSTEM32\hccoin.dll
2006-11-14 13:21 488,960 --a------ C:\WINDOWS\SYSTEM32\gpedit.dll
2006-11-14 13:21 478,720 --a------ C:\WINDOWS\SYSTEM32\mqsnap.dll
2006-11-14 13:21 47,616 --a------ C:\WINDOWS\SYSTEM32\eventcreate.exe
2006-11-14 13:21 467,456 --a------ C:\WINDOWS\SYSTEM32\mqutil.dll
2006-11-14 13:21 45,056 --a------ C:\WINDOWS\SYSTEM32\cipher.exe
2006-11-14 13:21 44,544 --a------ C:\WINDOWS\SYSTEM32\mqupgrd.dll
2006-11-14 13:21 44,032 --a------ C:\WINDOWS\SYSTEM32\mqdscli.dll
2006-11-14 13:21 4,608 --a------ C:\WINDOWS\SYSTEM32\mqsvc.exe
2006-11-14 13:21 28,160 --a------ C:\WINDOWS\SYSTEM32\pidgen.dll
2006-11-14 13:21 277,504 --a------ C:\WINDOWS\SYSTEM32\appmgr.dll
2006-11-14 13:21 27,136 --a------ C:\WINDOWS\SYSTEM32\asr_fmt.exe
2006-11-14 13:21 25,216 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbehci.sys
2006-11-14 13:21 24,576 --a------ C:\WINDOWS\SYSTEM32\efsadu.dll
2006-11-14 13:21 231,936 --a------ C:\WINDOWS\SYSTEM32\tracerpt.exe
2006-11-14 13:21 23,040 --a------ C:\WINDOWS\SYSTEM32\proxycfg.exe
2006-11-14 13:21 214,016 --a------ C:\WINDOWS\SYSTEM32\mqoa.dll
2006-11-14 13:21 183,808 --a------ C:\WINDOWS\SYSTEM32\gptext.dll
2006-11-14 13:21 17,408 --a------ C:\WINDOWS\SYSTEM32\mqbkup.exe
2006-11-14 13:21 165,888 --a------ C:\WINDOWS\SYSTEM32\mqrt.dll
2006-11-14 13:21 164,352 --a------ C:\WINDOWS\SYSTEM32\mqtrig.dll
2006-11-14 13:21 156,672 --a------ C:\WINDOWS\SYSTEM32\appmgmts.dll
2006-11-14 13:21 156,544 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nwrdr.sys
2006-11-14 13:21 14,848 --a------ C:\WINDOWS\SYSTEM32\mqise.dll
2006-11-14 13:21 130,048 --a------ C:\WINDOWS\SYSTEM32\mqad.dll
2006-11-14 13:21 115,200 --a------ C:\WINDOWS\SYSTEM32\mqrtdep.dll
2006-11-14 13:21 115,200 --a------ C:\WINDOWS\SYSTEM32\dpcdll.dll
2006-11-14 13:21 113,664 --a------ C:\WINDOWS\SYSTEM32\schtasks.exe
2006-11-14 13:21 113,152 --a------ C:\WINDOWS\SYSTEM32\gpresult.exe
2006-11-14 13:21 11,776 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys
2006-11-14 13:21 103,936 --a------ C:\WINDOWS\SYSTEM32\rsnotify.exe
2006-11-14 13:21 1,135,616 --a------ C:\WINDOWS\SYSTEM32\ntbackup.exe
2006-11-14 13:20 991,232 --a------ C:\WINDOWS\SYSTEM32\esent.dll
2006-11-14 13:20 98,816 --a------ C:\WINDOWS\SYSTEM32\dmstyle.dll
2006-11-14 13:20 98,816 --a------ C:\WINDOWS\SYSTEM32\clipbrd.exe
2006-11-14 13:20 98,304 --a------ C:\WINDOWS\SYSTEM32\actxprxy.dll
2006-11-14 13:20 95,232 --a------ C:\WINDOWS\SYSTEM32\6to4svc.dll
2006-11-14 13:20 937,984 --a------ C:\WINDOWS\SYSTEM32\dxdiag.exe
2006-11-14 13:20 92,160 --a------ C:\WINDOWS\SYSTEM32\cscdll.dll
2006-11-14 13:20 91,648 --a------ C:\WINDOWS\SYSTEM32\ahui.exe
2006-11-14 13:20 91,136 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-14 13:20 9,216 --a------ C:\WINDOWS\SYSTEM32\dumprep.exe
2006-11-14 13:20 85,504 --a------ C:\WINDOWS\SYSTEM32\catsrvps.dll
2006-11-14 13:20 84,992 --a------ C:\WINDOWS\SYSTEM32\dskquota.dll
2006-11-14 13:20 82,432 --a------ C:\WINDOWS\SYSTEM32\fldrclnr.dll
2006-11-14 13:20 82,432 --a------ C:\WINDOWS\SYSTEM32\drmstor.dll
2006-11-14 13:20 80,896 --a------ C:\WINDOWS\SYSTEM32\dpvsetup.exe
2006-11-14 13:20 80,384 --a------ C:\WINDOWS\SYSTEM32\cabview.dll
2006-11-14 13:20 8,832 --a------ C:\WINDOWS\SYSTEM32\framebuf.dll
2006-11-14 13:20 8,192 --a------ C:\WINDOWS\SYSTEM32\d3d8thk.dll
2006-11-14 13:20 8,192 --a------ C:\WINDOWS\SYSTEM32\autolfn.exe
2006-11-14 13:20 797,184 --a------ C:\WINDOWS\SYSTEM32\d3dim700.dll
2006-11-14 13:20 792,064 --a------ C:\WINDOWS\SYSTEM32\comres.dll
2006-11-14 13:20 79,360 --a------ C:\WINDOWS\SYSTEM32\diantz.exe
2006-11-14 13:20 77,824 --a------ C:\WINDOWS\SYSTEM32\dpmodemx.dll
2006-11-14 13:20 77,824 --a------ C:\WINDOWS\SYSTEM32\asycfilt.dll
2006-11-14 13:20 76,800 --a------ C:\WINDOWS\SYSTEM32\dpwsockx.dll
2006-11-14 13:20 76,800 --a------ C:\WINDOWS\SYSTEM32\dmscript.dll
2006-11-14 13:20 76,288 --a------ C:\WINDOWS\SYSTEM32\dfrgfat.exe
2006-11-14 13:20 76,288 --a------ C:\WINDOWS\SYSTEM32\avifil32.dll
2006-11-14 13:20 74,810 --a------ C:\WINDOWS\SYSTEM32\atl.dll
2006-11-14 13:20 723,968 --a------ C:\WINDOWS\SYSTEM32\dpnet.dll
2006-11-14 13:20 71,680 --a------ C:\WINDOWS\SYSTEM32\browsewm.dll
2006-11-14 13:20 70,656 --a------ C:\WINDOWS\SYSTEM32\defrag.exe
2006-11-14 13:20 70,144 --a------ C:\WINDOWS\SYSTEM32\cryptdlg.dll
2006-11-14 13:20 7,680 --a------ C:\WINDOWS\SYSTEM32\dciman32.dll
2006-11-14 13:20 7,168 --a------ C:\WINDOWS\SYSTEM32\fxsperf.dll
2006-11-14 13:20 68,096 --a------ C:\WINDOWS\SYSTEM32\fxscom.dll
2006-11-14 13:20 68,096 --a------ C:\WINDOWS\SYSTEM32\dpnhupnp.dll
2006-11-14 13:20 678,912 --a------ C:\WINDOWS\SYSTEM32\drmv2clt.dll
2006-11-14 13:20 66,560 --a------ C:\WINDOWS\SYSTEM32\faultrep.dll
2006-11-14 13:20 64,512 --a------ C:\WINDOWS\SYSTEM32\ciodm.dll
2006-11-14 13:20 64,512 --a------ C:\WINDOWS\SYSTEM32\amstream.dll
2006-11-14 13:20 62,976 --a------ C:\WINDOWS\SYSTEM32\browselc.dll
2006-11-14 13:20 62,464 --a------ C:\WINDOWS\SYSTEM32\colbact.dll
2006-11-14 13:20 62,464 --a------ C:\WINDOWS\SYSTEM32\adsmsext.dll
2006-11-14 13:20 61,440 --a------ C:\WINDOWS\SYSTEM32\dbnetlib.dll
2006-11-14 13:20 61,440 --a------ C:\WINDOWS\SYSTEM32\cleanmgr.exe
2006-11-14 13:20 602,624 --a------ C:\WINDOWS\SYSTEM32\dx7vb.dll
2006-11-14 13:20 6,656 --a------ C:\WINDOWS\SYSTEM32\fxsres.dll
2006-11-14 13:20 6,656 --a------ C:\WINDOWS\SYSTEM32\batt.dll
2006-11-14 13:20 59,904 --a------ C:\WINDOWS\SYSTEM32\cabinet.dll
2006-11-14 13:20 581,632 --a------ C:\WINDOWS\SYSTEM32\catsrvut.dll
2006-11-14 13:20 58,368 --a------ C:\WINDOWS\SYSTEM32\dmcompos.dll
2006-11-14 13:20 57,344 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-14 13:20 559,616 --a------ C:\WINDOWS\SYSTEM32\fxsst.dll
2006-11-14 13:20 558,592 --a------ C:\WINDOWS\SYSTEM32\autofmt.exe
2006-11-14 13:20 55,296 --a------ C:\WINDOWS\SYSTEM32\digest.dll
2006-11-14 13:20 544,256 --a------ C:\WINDOWS\SYSTEM32\crypt32.dll
2006-11-14 13:20 54,784 --a------ C:\WINDOWS\SYSTEM32\cmstp.exe
2006-11-14 13:20 54,272 --a------ C:\WINDOWS\SYSTEM32\clusapi.dll
2006-11-14 13:20 53,840 --a------ C:\WINDOWS\SYSTEM32\dosx.exe
2006-11-14 13:20 53,760 --a------ C:\WINDOWS\SYSTEM32\fxsevent.dll
2006-11-14 13:20 53,760 --a------ C:\WINDOWS\SYSTEM32\authz.dll
2006-11-14 13:20 53,248 --a------ C:\WINDOWS\SYSTEM32\cryptsvc.dll
2006-11-14 13:20 53,248 --a------ C:\WINDOWS\SYSTEM32\cryptnet.dll
2006-11-14 13:20 51,712 --a------ C:\WINDOWS\SYSTEM32\dataclen.dll
2006-11-14 13:20 50,688 --a------ C:\WINDOWS\SYSTEM32\dmutil.dll
2006-11-14 13:20 5,120 --a------ C:\WINDOWS\SYSTEM32\cisvc.exe
2006-11-14 13:20 5,120 --a------ C:\WINDOWS\SYSTEM32\asferror.dll
2006-11-14 13:20 499,200 --a------ C:\WINDOWS\SYSTEM32\comuid.dll
2006-11-14 13:20 498,205 --a------ C:\WINDOWS\SYSTEM32\dxmasf.dll
2006-11-14 13:20 497,152 --a------ C:\WINDOWS\SYSTEM32\clbcatq.dll
2006-11-14 13:20 491,520 --a------ C:\WINDOWS\SYSTEM32\dsdmoprp.dll
2006-11-14 13:20 49,152 --a------ C:\WINDOWS\SYSTEM32\eventlog.dll
2006-11-14 13:20 49,152 --a------ C:\WINDOWS\SYSTEM32\browser.dll
2006-11-14 13:20 489,984 --a------ C:\WINDOWS\SYSTEM32\dbghelp.dll
2006-11-14 13:20 48,640 --a------ C:\WINDOWS\SYSTEM32\cryptext.dll
2006-11-14 13:20 477,696 --a------ C:\WINDOWS\SYSTEM32\cryptui.dll
2006-11-14 13:20 47,104 --a------ C:\WINDOWS\SYSTEM32\dssec.dll
2006-11-14 13:20 46,592 --a------ C:\WINDOWS\twain_32.dll
2006-11-14 13:20 45,632 --a------ C:\WINDOWS\SYSTEM32\cliconfg.exe
2006-11-14 13:20 45,568 --a------ C:\WINDOWS\SYSTEM32\docprop2.dll
2006-11-14 13:20 45,568 --a------ C:\WINDOWS\SYSTEM32\cnbjmon.dll
2006-11-14 13:20 45,056 --a------ C:\WINDOWS\SYSTEM32\camocx.dll
2006-11-14 13:20 443,392 --a------ C:\WINDOWS\SYSTEM32\fxsapi.dll
2006-11-14 13:20 44,032 --a------ C:\WINDOWS\SYSTEM32\dnsrslvr.dll
2006-11-14 13:20 44,032 --a------ C:\WINDOWS\SYSTEM32\basesrv.dll
2006-11-14 13:20 436,736 --a------ C:\WINDOWS\SYSTEM32\certmgr.dll
2006-11-14 13:20 41,984 --a------ C:\WINDOWS\SYSTEM32\alg.exe
2006-11-14 13:20 41,472 --a------ C:\WINDOWS\SYSTEM32\cmdl32.exe
2006-11-14 13:20 40,960 --a------ C:\WINDOWS\SYSTEM32\extrac32.exe
2006-11-14 13:20 4,096 --a------ C:\WINDOWS\SYSTEM32\actmovie.exe
2006-11-14 13:20 395,264 --a------ C:\WINDOWS\SYSTEM32\fxsxp32.dll
2006-11-14 13:20 391,168 --a------ C:\WINDOWS\SYSTEM32\fxstiff.dll
2006-11-14 13:20 381,952 --a------ C:\WINDOWS\SYSTEM32\dpvoice.dll
2006-11-14 13:20 380,445 --a------ C:\WINDOWS\SYSTEM32\expsrv.dll
2006-11-14 13:20 38,912 --a------ C:\WINDOWS\SYSTEM32\audiosrv.dll
2006-11-14 13:20 361,472 --a------ C:\WINDOWS\SYSTEM32\fontext.dll
2006-11-14 13:20 36,352 --a------ C:\WINDOWS\SYSTEM32\cmutil.dll
2006-11-14 13:20 355,328 --a------ C:\WINDOWS\SYSTEM32\dsound.dll
2006-11-14 13:20 35,840 --a------ C:\WINDOWS\SYSTEM32\cmmon32.exe
2006-11-14 13:20 35,328 --a------ C:\WINDOWS\SYSTEM32\dfrgsnap.dll
2006-11-14 13:20 33,280 --a------ C:\WINDOWS\SYSTEM32\dmloader.dll
2006-11-14 13:20 324,608 --a------ C:\WINDOWS\SYSTEM32\cmdial32.dll
2006-11-14 13:20 323,072 --a------ C:\WINDOWS\SYSTEM32\filemgmt.dll
2006-11-14 13:20 32,768 --a------ C:\WINDOWS\SYSTEM32\dpnhpast.dll
2006-11-14 13:20 32,768 --a------ C:\WINDOWS\SYSTEM32\cfgbkend.dll
2006-11-14 13:20 307,712 --a------ C:\WINDOWS\SYSTEM32\cscui.dll
2006-11-14 13:20 301,712 --a------ C:\WINDOWS\SYSTEM32\drmclien.dll
2006-11-14 13:20 30,720 --a------ C:\WINDOWS\SYSTEM32\clipsrv.exe
2006-11-14 13:20 3,072 --a------ C:\WINDOWS\SYSTEM32\dpnlobby.dll
2006-11-14 13:20 3,072 --a------ C:\WINDOWS\SYSTEM32\dpnaddr.dll
2006-11-14 13:20 29,184 --a------ C:\WINDOWS\SYSTEM32\cryptdll.dll
2006-11-14 13:20 284,160 --a------ C:\WINDOWS\SYSTEM32\ddraw.dll
2006-11-14 13:20 28,672 --a------ C:\WINDOWS\SYSTEM32\dbnmpntw.dll
2006-11-14 13:20 28,160 --a------ C:\WINDOWS\SYSTEM32\dplaysvr.exe
2006-11-14 13:20 272,768 --a------ C:\WINDOWS\SYSTEM32\atmfd.dll
2006-11-14 13:20 271,360 --a------ C:\WINDOWS\SYSTEM32\fxscomex.dll
2006-11-14 13:20 27,136 --a------ C:\WINDOWS\SYSTEM32\dmband.dll
2006-11-14 13:20 27,136 --a------ C:\WINDOWS\SYSTEM32\ddeshare.exe
2006-11-14 13:20 27,136 --a------ C:\WINDOWS\SYSTEM32\batmeter.dll
2006-11-14 13:20 27,136 --a------ C:\WINDOWS\SYSTEM32\atmlib.dll
2006-11-14 13:20 266,752 --a------ C:\WINDOWS\winhlp32.exe
2006-11-14 13:20 263,680 --a------ C:\WINDOWS\SYSTEM32\duser.dll
2006-11-14 13:20 263,168 --a------ C:\WINDOWS\SYSTEM32\devmgr.dll
2006-11-14 13:20 260,608 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2006-11-14 13:20 250,368 --a------ C:\WINDOWS\SYSTEM32\fxssvc.exe
2006-11-14 13:20 25,600 --a------ C:\WINDOWS\SYSTEM32\dfsshlex.dll
2006-11-14 13:20 25,088 --a------ C:\WINDOWS\SYSTEM32\findstr.exe
2006-11-14 13:20 24,576 --a------ C:\WINDOWS\SYSTEM32\dbmsrpcn.dll
2006-11-14 13:20 24,576 --a------ C:\WINDOWS\SYSTEM32\conime.exe
2006-11-14 13:20 24,064 --a------ C:\WINDOWS\SYSTEM32\fxsdrv.dll
2006-11-14 13:20 24,064 --a------ C:\WINDOWS\SYSTEM32\ddrawex.dll
2006-11-14 13:20 239,616 --a------ C:\WINDOWS\SYSTEM32\adsnt.dll
2006-11-14 13:20 238,592 --a------ C:\WINDOWS\SYSTEM32\compatui.dll
2006-11-14 13:20 236,032 --a------ C:\WINDOWS\SYSTEM32\fxst30.dll
2006-11-14 13:20 232,960 --a------ C:\WINDOWS\SYSTEM32\blackbox.dll
2006-11-14 13:20 227,840 --a------ C:\WINDOWS\SYSTEM32\dsquery.dll
2006-11-14 13:20 227,328 --a------ C:\WINDOWS\SYSTEM32\es.dll
2006-11-14 13:20 222,208 --a------ C:\WINDOWS\SYSTEM32\compstui.dll
2006-11-14 13:20 220,672 --a------ C:\WINDOWS\SYSTEM32\catsrv.dll
2006-11-14 13:20 22,528 --a------ C:\WINDOWS\SYSTEM32\at.exe
2006-11-14 13:20 22,016 --a------ C:\WINDOWS\SYSTEM32\fxsmon.dll
2006-11-14 13:20 22,016 --a------ C:\WINDOWS\SYSTEM32\davclnt.dll
2006-11-14 13:20 217,600 --a------ C:\WINDOWS\SYSTEM32\dplayx.dll
2006-11-14 13:20 216,064 --a------ C:\WINDOWS\SYSTEM32\fxscover.exe
2006-11-14 13:20 21,504 --a------ C:\WINDOWS\SYSTEM32\dmserver.dll
2006-11-14 13:20 204,800 --a------ C:\WINDOWS\SYSTEM32\dmadmin.exe
2006-11-14 13:20 20,992 --a------ C:\WINDOWS\SYSTEM32\fxsext32.dll
2006-11-14 13:20 2,025,984 --a------ C:\WINDOWS\SYSTEM32\cdosys.dll
2006-11-14 13:20 19,968 --a------ C:\WINDOWS\SYSTEM32\dpvacm.dll
2006-11-14 13:20 19,456 --a------ C:\WINDOWS\SYSTEM32\fontview.exe
2006-11-14 13:20 19,456 --a------ C:\WINDOWS\SYSTEM32\ersvc.dll
2006-11-14 13:20 186,880 --a------ C:\WINDOWS\SYSTEM32\dsdmo.dll
2006-11-14 13:20 186,880 --a------ C:\WINDOWS\SYSTEM32\certcli.dll
2006-11-14 13:20 185,856 --a------ C:\WINDOWS\SYSTEM32\fxswzrd.dll
2006-11-14 13:20 184,320 --a------ C:\WINDOWS\SYSTEM32\dmdskmgr.dll
2006-11-14 13:20 181,760 --a------ C:\WINDOWS\SYSTEM32\activeds.dll
2006-11-14 13:20 180,224 --a------ C:\WINDOWS\SYSTEM32\dwwin.exe
2006-11-14 13:20 18,432 --a------ C:\WINDOWS\SYSTEM32\feclient.dll
2006-11-14 13:20 18,432 --a------ C:\WINDOWS\SYSTEM32\dswave.dll
2006-11-14 13:20 179,200 --a------ C:\WINDOWS\SYSTEM32\accwiz.exe
2006-11-14 13:20 178,688 --a------ C:\WINDOWS\SYSTEM32\eudcedit.exe
2006-11-14 13:20 174,592 --a------ C:\WINDOWS\SYSTEM32\cmprops.dll
2006-11-14 13:20 171,520 --a------ C:\WINDOWS\SYSTEM32\dmime.dll
2006-11-14 13:20 168,960 --a------ C:\WINDOWS\SYSTEM32\dinput8.dll
2006-11-14 13:20 165,376 --a------ C:\WINDOWS\SYSTEM32\els.dll
2006-11-14 13:20 162,816 --a------ C:\WINDOWS\SYSTEM32\adsldp.dll
2006-11-14 13:20 16,896 --a------ C:\WINDOWS\SYSTEM32\dpnsvr.exe
2006-11-14 13:20 16,896 --a------ C:\WINDOWS\SYSTEM32\cfgmgr32.dll
2006-11-14 13:20 16,384 --a------ C:\WINDOWS\SYSTEM32\ds32gt.dll
2006-11-14 13:20 159,232 --a------ C:\WINDOWS\SYSTEM32\cewmdm.dll
2006-11-14 13:20 158,720 --a------ C:\WINDOWS\SYSTEM32\credui.dll
2006-11-14 13:20 151,552 --a------ C:\WINDOWS\SYSTEM32\dinput.dll
2006-11-14 13:20 15,872 --a------ C:\WINDOWS\SYSTEM32\dvdupgrd.exe
2006-11-14 13:20 15,872 --a------ C:\WINDOWS\SYSTEM32\alrsvc.dll
2006-11-14 13:20 149,504 --a------ C:\WINDOWS\SYSTEM32\fxsui.dll
2006-11-14 13:20 145,920 --a------ C:\WINDOWS\SYSTEM32\diskpart.exe
2006-11-14 13:20 14,877 --a------ C:\WINDOWS\SYSTEM32\corpol.dll
2006-11-14 13:20 14,848 --a------ C:\WINDOWS\SYSTEM32\bidispl.dll
2006-11-14 13:20 14,336 --a------ C:\WINDOWS\SYSTEM32\dmremote.exe
2006-11-14 13:20 139,776 --a------ C:\WINDOWS\SYSTEM32\adsldpc.dll
2006-11-14 13:20 135,680 --a------ C:\WINDOWS\SYSTEM32\dsprop.dll
2006-11-14 13:20 134,144 --a------ C:\WINDOWS\regedit.exe
2006-11-14 13:20 132,608 --a------ C:\WINDOWS\SYSTEM32\devenum.dll
2006-11-14 13:20 130,048 --a------ C:\WINDOWS\SYSTEM32\fxsclnt.exe
2006-11-14 13:20 13,312 --a------ C:\WINDOWS\SYSTEM32\ctfmon.exe
2006-11-14 13:20 127,552 --a------ C:\WINDOWS\SYSTEM32\cliconfg.dll
2006-11-14 13:20 124,928 --a------ C:\WINDOWS\SYSTEM32\dssenh.dll
2006-11-14 13:20 12,288 --a------ C:\WINDOWS\SYSTEM32\cmcfg32.dll
2006-11-14 13:20 116,736 --a------ C:\WINDOWS\SYSTEM32\dmusic.dll
2006-11-14 13:20 115,712 --a------ C:\WINDOWS\SYSTEM32\apphelp.dll
2006-11-14 13:20 113,152 --a------ C:\WINDOWS\SYSTEM32\dfrgui.dll
2006-11-14 13:20 112,128 --a------ C:\WINDOWS\SYSTEM32\dpvvox.dll
2006-11-14 13:20 110,080 --a------ C:\WINDOWS\SYSTEM32\clbcatex.dll
2006-11-14 13:20 11,776 --a------ C:\WINDOWS\SYSTEM32\drprov.dll
2006-11-14 13:20 107,008 --a------ C:\WINDOWS\SYSTEM32\aclui.dll
2006-11-14 13:20 106,496 --a------ C:\WINDOWS\SYSTEM32\dsuiext.dll
2006-11-14 13:20 103,424 --a------ C:\WINDOWS\SYSTEM32\dgnet.dll
2006-11-14 13:20 102,450 --a------ C:\WINDOWS\SYSTEM32\cscript.exe
2006-11-14 13:20 100,864 --a------ C:\WINDOWS\SYSTEM32\dmsynth.dll
2006-11-14 13:20 10,752 --a------ C:\WINDOWS\hh.exe
2006-11-14 13:20 10,240 --a------ C:\WINDOWS\SYSTEM32\atmadm.exe
2006-11-14 13:20 1,294,336 --a------ C:\WINDOWS\SYSTEM32\dsound3d.dll
2006-11-14 13:20 1,189,888 --a------ C:\WINDOWS\SYSTEM32\dx8vb.dll
2006-11-14 13:20 1,179,136 --a------ C:\WINDOWS\SYSTEM32\comsvcs.dll
2006-11-14 13:20 1,177,600 --a------ C:\WINDOWS\SYSTEM32\d3d8.dll
2006-11-14 13:20 1,004,032 --a------ C:\WINDOWS\explorer.exe
2006-11-14 13:19 995,384 --a------ C:\WINDOWS\SYSTEM32\mfc42u.dll
2006-11-14 13:19 995,383 --a------ C:\WINDOWS\SYSTEM32\mfc42.dll
2006-11-14 13:19 99,840 --a------ C:\WINDOWS\SYSTEM32\iexpress.exe
2006-11-14 13:19 981,504 --a------ C:\WINDOWS\SYSTEM32\wmnetmgr.dll
2006-11-14 13:19 98,304 --a------ C:\WINDOWS\SYSTEM32\polstore.dll
2006-11-14 13:19 98,304 --a------ C:\WINDOWS\SYSTEM32\oleprn.dll
2006-11-14 13:19 974,336 --a------ C:\WINDOWS\SYSTEM32\msdtctm.dll
2006-11-14 13:19 971,264 --a------ C:\WINDOWS\SYSTEM32\msgina.dll
2006-11-14 13:19 97,280 --a------ C:\WINDOWS\SYSTEM32\txflog.dll
2006-11-14 13:19 96,256 --a------ C:\WINDOWS\SYSTEM32\rcbdyctl.dll
2006-11-14 13:19 95,744 --a------ C:\WINDOWS\SYSTEM32\nlhtml.dll
2006-11-14 13:19 94,208 --a------ C:\WINDOWS\SYSTEM32\odbccp32.dll
2006-11-14 13:19 938,496 --a------ C:\WINDOWS\SYSTEM32\syssetup.dll
2006-11-14 13:19 932,864 --a------ C:\WINDOWS\SYSTEM32\setupapi.dll
2006-11-14 13:19 93,184 --a------ C:\WINDOWS\SYSTEM32\winscard.dll
2006-11-14 13:19 93,184 --a------ C:\WINDOWS\SYSTEM32\scardsvr.exe
2006-11-14 13:19 92,160 --a------ C:\WINDOWS\SYSTEM32\krnl386.exe
2006-11-14 13:19 91,648 --a------ C:\WINDOWS\SYSTEM32\loadperf.dll
2006-11-14 13:19 91,136 --a------ C:\WINDOWS\SYSTEM32\rastls.dll
2006-11-14 13:19 91,136 --a------ C:\WINDOWS\SYSTEM32\msoert2.dll
2006-11-14 13:19 90,112 --a------ C:\WINDOWS\SYSTEM32\odbcint.dll
2006-11-14 13:19 9,728 --a------ C:\WINDOWS\SYSTEM32\regsvr32.exe
2006-11-14 13:19 9,728 --a------ C:\WINDOWS\SYSTEM32\mstinit.exe
2006-11-14 13:19 9,728 --a------ C:\WINDOWS\SYSTEM32\gpkrsrc.dll
2006-11-14 13:19 9,216 --a------ C:\WINDOWS\SYSTEM32\icaapi.dll
2006-11-14 13:19 89,600 --a------ C:\WINDOWS\SYSTEM32\slbiop.dll
2006-11-14 13:19 88,064 --a------ C:\WINDOWS\SYSTEM32\tscfgwmi.dll
2006-11-14 13:19 88,064 --a------ C:\WINDOWS\SYSTEM32\mydocs.dll
2006-11-14 13:19 87,552 --a------ C:\WINDOWS\SYSTEM32\occache.dll
2006-11-14 13:19 87,552 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ndiswan.sys
2006-11-14 13:19 87,304 --a------ C:\WINDOWS\SYSTEM32\rdpdd.dll
2006-11-14 13:19 87,296 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
2006-11-14 13:19 86,528 --a------ C:\WINDOWS\SYSTEM32\wlnotify.dll
2006-11-14 13:19 86,016 --a------ C:\WINDOWS\SYSTEM32\xactsrv.dll
2006-11-14 13:19 857,600 --a------ C:\WINDOWS\SYSTEM32\netplwiz.dll
2006-11-14 13:19 84,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys
2006-11-14 13:19 831,562 --a------ C:\WINDOWS\SYSTEM32\mswdat10.dll
2006-11-14 13:19 83,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nabtsfec.sys
2006-11-14 13:19 83,456 --a------ C:\WINDOWS\SYSTEM32\netsh.exe
2006-11-14 13:19 83,456 --a------ C:\WINDOWS\SYSTEM32\mtxoci.dll
2006-11-14 13:19 829,952 --a------ C:\WINDOWS\SYSTEM32\tapi3.dll
2006-11-14 13:19 82,944 --a------ C:\WINDOWS\SYSTEM32\smlogsvc.exe
2006-11-14 13:19 82,944 --a------ C:\WINDOWS\SYSTEM32\rasauto.dll
2006-11-14 13:19 82,944 --a------ C:\WINDOWS\SYSTEM32\psbase.dll
2006-11-14 13:19 816,264 --a------ C:\WINDOWS\SYSTEM32\wmvdmod.dll
2006-11-14 13:19 81,920 --a------ C:\WINDOWS\SYSTEM32\trkwks.dll
2006-11-14 13:19 81,408 --a------ C:\WINDOWS\SYSTEM32\logagent.exe
2006-11-14 13:19 80,896 --a------ C:\WINDOWS\SYSTEM32\ntprint.dll
2006-11-14 13:19 80,384 --a------ C:\WINDOWS\SYSTEM32\mciavi32.dll
2006-11-14 13:19 80,128 --a------ C:\WINDOWS\SYSTEM32\msapsspc.dll
2006-11-14 13:19 8,704 --a------ C:\WINDOWS\SYSTEM32\lprhelp.dll
2006-11-14 13:19 8,456 --a------ C:\WINDOWS\SYSTEM32\tsddd.dll
2006-11-14 13:19 8,192 --a------ C:\WINDOWS\SYSTEM32\scrnsave.scr
2006-11-14 13:19 8,192 --a------ C:\WINDOWS\SYSTEM32\igmpagnt.dll
2006-11-14 13:19 79,872 --a------ C:\WINDOWS\SYSTEM32\srvsvc.dll
2006-11-14 13:19 79,744 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ksecdd.sys
2006-11-14 13:19 79,488 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ipnat.sys
2006-11-14 13:19 79,360 --a------ C:\WINDOWS\SYSTEM32\mprapi.dll
2006-11-14 13:19 79,360 --a------ C:\WINDOWS\SYSTEM32\makecab.exe
2006-11-14 13:19 780,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dmboot.sys
2006-11-14 13:19 774,144 --a------ C:\WINDOWS\SYSTEM32\mmc.exe
2006-11-14 13:19 77,824 --a------ C:\WINDOWS\SYSTEM32\wmpshell.dll
2006-11-14 13:19 77,824 --a------ C:\WINDOWS\SYSTEM32\isign32.dll
2006-11-14 13:19 762,368 --a------ C:\WINDOWS\SYSTEM32\winntbbu.dll
2006-11-14 13:19 760,968 --a------ C:\WINDOWS\SYSTEM32\wmsdmod.dll
2006-11-14 13:19 75,912 --a------ C:\WINDOWS\SYSTEM32\rdpwsx.dll
2006-11-14 13:19 74,752 --a------ C:\WINDOWS\SYSTEM32\netui0.dll
2006-11-14 13:19 74,368 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys
2006-11-14 13:19 74,240 --a------ C:\WINDOWS\SYSTEM32\rtcshare.exe
2006-11-14 13:19 733,184 --a------ C:\WINDOWS\SYSTEM32\qedwipes.dll
2006-11-14 13:19 73,728 --a------ C:\WINDOWS\SYSTEM32\ils.dll
2006-11-14 13:19 72,192 --a------ C:\WINDOWS\SYSTEM32\telnet.exe
2006-11-14 13:19 71,680 --a------ C:\WINDOWS\SYSTEM32\nslookup.exe
2006-11-14 13:19 71,168 --a------ C:\WINDOWS\SYSTEM32\storprop.dll
2006-11-14 13:19 71,168 --a------ C:\WINDOWS\SYSTEM32\sdbinst.exe
2006-11-14 13:19 700,928 --a------ C:\WINDOWS\SYSTEM32\sxs.dll
2006-11-14 13:19 70,656 --a------ C:\WINDOWS\SYSTEM32\ws2_32.dll
2006-11-14 13:19 70,656 --a------ C:\WINDOWS\SYSTEM32\wiascr.dll
2006-11-14 13:19 7,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\i2omgmt.sys
2006-11-14 13:19 7,424 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mskssrv.sys
2006-11-14 13:19 7,040 --a------ C:\WINDOWS\SYSTEM32\kd1394.dll
2006-11-14 13:19 699,392 --a------ C:\WINDOWS\SYSTEM32\msxml2.dll
2006-11-14 13:19 69,632 --a------ C:\WINDOWS\SYSTEM32\shrpubw.exe
2006-11-14 13:19 69,632 --a------ C:\WINDOWS\SYSTEM32\icwdial.dll
2006-11-14 13:19 69,120 --a------ C:\WINDOWS\SYSTEM32\unimdmat.dll
2006-11-14 13:19 686,080 --a------ C:\WINDOWS\SYSTEM32\opengl32.dll
2006-11-14 13:19 681,984 --a------ C:\WINDOWS\SYSTEM32\lsasrv.dll
2006-11-14 13:19 68,992 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dxg.sys
2006-11-14 13:19 68,928 --a------ C:\WINDOWS\SYSTEM32\mmsystem.dll
2006-11-14 13:19 68,928 --a------ C:\WINDOWS\SYSTEM\mmsystem.dll
2006-11-14 13:19 68,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bridge.sys
2006-11-14 13:19 68,608 --a------ C:\WINDOWS\SYSTEM32\mscms.dll
2006-11-14 13:19 68,096 --a------ C:\WINDOWS\SYSTEM32\locator.exe
2006-11-14 13:19 68,096 --a------ C:\WINDOWS\SYSTEM32\inetpp.dll
2006-11-14 13:19 670,208 --a------ C:\WINDOWS\SYSTEM32\wmadmoe.dll
2006-11-14 13:19 67,584 --a------ C:\WINDOWS\SYSTEM32\msctfp.dll
2006-11-14 13:19 67,584 --a------ C:\WINDOWS\SYSTEM32\magnify.exe
2006-11-14 13:19 67,072 --a------ C:\WINDOWS\SYSTEM32\usbui.dll
2006-11-14 13:19 67,072 --a------ C:\WINDOWS\SYSTEM32\msacm32.dll
2006-11-14 13:19 668,672 --a------ C:\WINDOWS\SYSTEM32\ntdll.dll
2006-11-14 13:19 667,648 --a------ C:\WINDOWS\SYSTEM32\ss3dfo.scr
2006-11-14 13:19 667,136 --a------ C:\WINDOWS\SYSTEM32\userenv.dll
2006-11-14 13:19 66,560 --a------ C:\WINDOWS\SYSTEM32\spoolss.dll
2006-11-14 13:19 66,560 --a------ C:\WINDOWS\SYSTEM32\scarddlg.dll
2006-11-14 13:19 66,560 --a------ C:\WINDOWS\SYSTEM32\mmcbase.dll
2006-11-14 13:19 66,048 --a------ C:\WINDOWS\SYSTEM32\sigverif.exe
2006-11-14 13:19 66,048 --a------ C:\WINDOWS\SYSTEM32\notepad.exe
2006-11-14 13:19 66,048 --a------ C:\WINDOWS\SYSTEM32\msw3prt.dll
2006-11-14 13:19 66,048 --a------ C:\WINDOWS\notepad.exe
2006-11-14 13:19 65,585 --a------ C:\WINDOWS\SYSTEM32\wshext.dll
2006-11-14 13:19 65,536 --a------ C:\WINDOWS\SYSTEM32\msconf.dll
2006-11-14 13:19 65,024 --a------ C:\WINDOWS\SYSTEM32\msvcrt40.dll
2006-11-14 13:19 64,512 --a------ C:\WINDOWS\SYSTEM32\ntdsapi.dll
2006-11-14 13:19 64,512 --a------ C:\WINDOWS\SYSTEM32\mtxclu.dll
2006-11-14 13:19 64,000 --a------ C:\WINDOWS\SYSTEM32\webclnt.dll
2006-11-14 13:19 638,976 --a------ C:\WINDOWS\SYSTEM32\sstext3d.scr
2006-11-14 13:19 631,808 --a------ C:\WINDOWS\SYSTEM32\rasdlg.dll
2006-11-14 13:19 63,488 --a------ C:\WINDOWS\SYSTEM32\srclient.dll
2006-11-14 13:19 62,976 --a------ C:\WINDOWS\SYSTEM32\shgina.dll
2006-11-14 13:19 62,208 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mf.sys
2006-11-14 13:19 614,474 --a------ C:\WINDOWS\SYSTEM32\mswstr10.dll
2006-11-14 13:19 61,952 --a------ C:\WINDOWS\SYSTEM32\sti.dll
2006-11-14 13:19 61,952 --a------ C:\WINDOWS\SYSTEM32\rdshost.exe
2006-11-14 13:19 61,952 --a------ C:\WINDOWS\SYSTEM32\osuninst.dll
2006-11-14 13:19 61,440 --a------ C:\WINDOWS\SYSTEM32\odbccu32.dll
2006-11-14 13:19 61,440 --a------ C:\WINDOWS\SYSTEM32\odbccr32.dll
2006-11-14 13:19 61,440 --a------ C:\WINDOWS\SYSTEM32\icwphbk.dll
2006-11-14 13:19 60,416 --a------ C:\WINDOWS\SYSTEM32\wextract.exe
2006-11-14 13:19 60,416 --a------ C:\WINDOWS\SYSTEM32\shimeng.dll
2006-11-14 13:19 6,656 --a------ C:\WINDOWS\SYSTEM32\ntlsapi.dll
2006-11-14 13:19 6,656 --a------ C:\WINDOWS\SYSTEM32\laprxy.dll
2006-11-14 13:19 6,144 --a------ C:\WINDOWS\SYSTEM32\sensapi.dll
2006-11-14 13:19 6,144 --a------ C:\WINDOWS\SYSTEM32\msdtc.exe
2006-11-14 13:19 598,016 --a------ C:\WINDOWS\SYSTEM32\mstscax.dll
2006-11-14 13:19 596,480 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-14 13:19 593,408 --a------ C:\WINDOWS\SYSTEM32\h323msp.dll
2006-11-14 13:19 59,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cdfs.sys
2006-11-14 13:19 59,392 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-14 13:19 585,344 --a------ C:\WINDOWS\SYSTEM32\i81xdnt5.dll
2006-11-14 13:19 584,192 --a------ C:\WINDOWS\SYSTEM32\netcfgx.dll
2006-11-14 13:19 58,880 --a------ C:\WINDOWS\SYSTEM32\pautoenr.dll
2006-11-14 13:19 578,560 --a------ C:\WINDOWS\SYSTEM32\autoconv.exe
2006-11-14 13:19 577,024 --a------ C:\WINDOWS\SYSTEM32\mlang.dll
2006-11-14 13:19 57,984 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nic1394.sys
2006-11-14 13:19 57,856 --a------ C:\WINDOWS\SYSTEM32\raschap.dll
2006-11-14 13:19 57,856 --a------ C:\WINDOWS\SYSTEM32\licwmi.dll
2006-11-14 13:19 57,856 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\drmk.sys
2006-11-14 13:19 57,344 --a------ C:\WINDOWS\SYSTEM32\wzcdlg.dll
2006-11-14 13:19 57,344 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\arp1394.sys
2006-11-14 13:19 57,216 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\atmarpc.sys
2006-11-14 13:19 569,344 --a------ C:\WINDOWS\SYSTEM32\sspipes.scr
2006-11-14 13:19 569,344 --a------ C:\WINDOWS\SYSTEM32\oleaut32.dll
2006-11-14 13:19 568,832 --a------ C:\WINDOWS\SYSTEM32\wiashext.dll
2006-11-14 13:19 565,760 --a------ C:\WINDOWS\SYSTEM32\autochk.exe
2006-11-14 13:19 561,920 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ntfs.sys
2006-11-14 13:19 561,664 --a------ C:\WINDOWS\SYSTEM32\comctl32.dll
2006-11-14 13:19 561,152 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2006-11-14 13:19 56,320 --a------ C:\WINDOWS\SYSTEM32\remotepg.dll
2006-11-14 13:19 56,320 --a------ C:\WINDOWS\SYSTEM32\mshtmler.dll
2006-11-14 13:19 56,320 --a------ C:\WINDOWS\SYSTEM32\miglibnt.dll
2006-11-14 13:19 558,080 --a------ C:\WINDOWS\SYSTEM32\advapi32.dll
2006-11-14 13:19 552,991 --a------ C:\WINDOWS\SYSTEM32\msrepl40.dll
2006-11-14 13:19 55,808 --a------ C:\WINDOWS\SYSTEM32\rasman.dll
2006-11-14 13:19 55,808 --a------ C:\WINDOWS\SYSTEM32\mpr.dll
2006-11-14 13:19 548,864 --a------ C:\WINDOWS\SYSTEM32\shdoclc.dll
2006-11-14 13:19 54,784 --a------ C:\WINDOWS\SYSTEM32\samlib.dll
2006-11-14 13:19 54,784 --a------ C:\WINDOWS\SYSTEM32\resutils.dll
2006-11-14 13:19 54,784 --a------ C:\WINDOWS\SYSTEM32\msdtclog.dll
2006-11-14 13:19 54,272 --a------ C:\WINDOWS\SYSTEM32\rastapi.dll
2006-11-14 13:19 54,272 --a------ C:\WINDOWS\SYSTEM32\rasphone.exe
2006-11-14 13:19 54,272 --a------ C:\WINDOWS\SYSTEM32\ipv6mon.dll
2006-11-14 13:19 535,552 --a------ C:\WINDOWS\SYSTEM32\rpcrt4.dll
2006-11-14 13:19 534,016 --a------ C:\WINDOWS\SYSTEM32\spider.exe
2006-11-14 13:19 53,888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\atmlane.sys
2006-11-14 13:19 53,322 --a------ C:\WINDOWS\SYSTEM32\msjter40.dll
2006-11-14 13:19 53,279 --a------ C:\WINDOWS\SYSTEM32\odbcji32.dll
2006-11-14 13:19 53,248 --a------ C:\WINDOWS\SYSTEM32\spoolsv.exe
2006-11-14 13:19 53,248 --a------ C:\WINDOWS\SYSTEM32\servdeps.dll
2006-11-14 13:19 53,248 --a------ C:\WINDOWS\SYSTEM32\sendmail.dll
2006-11-14 13:19 53,248 --a------ C:\WINDOWS\SYSTEM32\packager.exe
2006-11-14 13:19 53,248 --a------ C:\WINDOWS\SYSTEM32\odbcconf.exe
2006-11-14 13:19 522,240 --a------ C:\WINDOWS\SYSTEM32\printui.dll
2006-11-14 13:19 52,224 --a------ C:\WINDOWS\SYSTEM32\secur32.dll
2006-11-14 13:19 52,096 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msdv.sys
2006-11-14 13:19 516,608 --a------ C:\WINDOWS\SYSTEM32\winlogon.exe
2006-11-14 13:19 512,031 --a------ C:\WINDOWS\SYSTEM32\msexch40.dll
2006-11-14 13:19 51,712 --a------ C:\WINDOWS\SYSTEM32\synceng.dll
2006-11-14 13:19 51,712 --a------ C:\WINDOWS\SYSTEM32\regsvc.dll
2006-11-14 13:19 51,712 --a------ C:\WINDOWS\SYSTEM32\msasn1.dll
2006-11-14 13:19 51,712 --a------ C:\WINDOWS\SYSTEM32\ipconfig.exe
2006-11-14 13:19 51,200 --a------ C:\WINDOWS\SYSTEM32\narrator.exe
2006-11-14 13:19 51,072 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\i8042prt.sys
2006-11-14 13:19 504,320 --a------ C:\WINDOWS\SYSTEM32\logonui.exe
2006-11-14 13:19 50,688 --a------ C:\WINDOWS\SYSTEM32\msvcirt.dll
2006-11-14 13:19 50,048 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dmusic.sys
2006-11-14 13:19 5,632 --a------ C:\WINDOWS\SYSTEM32\wmi.dll
2006-11-14 13:19 5,632 --a------ C:\WINDOWS\SYSTEM32\security.dll
2006-11-14 13:19 5,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mstee.sys
2006-11-14 13:19 5,248 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mspclock.sys
2006-11-14 13:19 5,120 --a------ C:\WINDOWS\SYSTEM32\msidle.dll
2006-11-14 13:19 495,376 --a------ C:\WINDOWS\SYSTEM32\msxml.dll
2006-11-14 13:19 493,056 --a------ C:\WINDOWS\SYSTEM32\hypertrm.dll
2006-11-14 13:19 49,664 --a------ C:\WINDOWS\SYSTEM32\ixsso.dll
2006-11-14 13:19 49,152 --a------ C:\WINDOWS\SYSTEM32\npptools.dll
2006-11-14 13:19 48,640 --a------ C:\WINDOWS\SYSTEM32\vdmredir.dll
2006-11-14 13:19 48,640 --a------ C:\WINDOWS\SYSTEM32\ipv6.exe
2006-11-14 13:19 48,128 --a------ C:\WINDOWS\SYSTEM32\winsta.dll
2006-11-14 13:19 48,128 --a------ C:\WINDOWS\SYSTEM32\reg.exe
2006-11-14 13:19 479,261 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-14 13:19 47,616 --a------ C:\WINDOWS\SYSTEM32\utilman.exe
2006-11-14 13:19 47,616 --a------ C:\WINDOWS\SYSTEM32\inetres.dll
2006-11-14 13:19 47,488 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cdrom.sys
2006-11-14 13:19 47,104 --a------ C:\WINDOWS\SYSTEM32\wstdecod.dll
2006-11-14 13:19 460,288 --a------ C:\WINDOWS\SYSTEM32\ntmsmgr.dll
2006-11-14 13:19 46,592 --a------ C:\WINDOWS\SYSTEM32\wdigest.dll
2006-11-14 13:19 46,592 --a------ C:\WINDOWS\SYSTEM32\mmcshext.dll
2006-11-14 13:19 46,336 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\classpnp.sys
2006-11-14 13:19 45,568 --a------ C:\WINDOWS\SYSTEM32\smss.exe
2006-11-14 13:19 45,568 --a------ C:\WINDOWS\SYSTEM32\iyuv_32.dll
2006-11-14 13:19 45,056 --a------ C:\WINDOWS\SYSTEM32\proquota.exe
2006-11-14 13:19 45,056 --a------ C:\WINDOWS\SYSTEM32\msprivs.dll
2006-11-14 13:19 449,536 --a------ C:\WINDOWS\SYSTEM32\wiadefui.dll
2006-11-14 13:19 449,024 --a------ C:\WINDOWS\SYSTEM32\qdvd.dll
2006-11-14 13:19 44,032 --a------ C:\WINDOWS\SYSTEM32\regapi.dll
2006-11-14 13:19 44,032 --a------ C:\WINDOWS\SYSTEM32\rdpclip.exe
2006-11-14 13:19 44,032 --a------ C:\WINDOWS\SYSTEM32\msident.dll
2006-11-14 13:19 439,808 --a------ C:\WINDOWS\SYSTEM32\ipnathlp.dll
2006-11-14 13:19 433,152 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mrxsmb.sys
2006-11-14 13:19 43,008 --a------ C:\WINDOWS\SYSTEM32\ssmypics.scr
2006-11-14 13:19 43,008 --a------ C:\WINDOWS\SYSTEM32\ssdpsrv.dll
2006-11-14 13:19 423,424 --a------ C:\WINDOWS\SYSTEM32\riched20.dll
2006-11-14 13:19 421,919 --a------ C:\WINDOWS\SYSTEM32\msrd2x40.dll
2006-11-14 13:19 420,864 --a------ C:\WINDOWS\SYSTEM32\shimgvw.dll
2006-11-14 13:19 42,496 --a------ C:\WINDOWS\SYSTEM32\ncobjapi.dll
2006-11-14 13:19 414,720 --a------ C:\WINDOWS\SYSTEM32\wiaacmgr.exe
2006-11-14 13:19 411,136 --a------ C:\WINDOWS\SYSTEM32\samsrv.dll
2006-11-14 13:19 410,248 --a------ C:\WINDOWS\SYSTEM32\wmadmod.dll
2006-11-14 13:19 409,088 --a------ C:\WINDOWS\SYSTEM32\vssapi.dll
2006-11-14 13:19 401,462 --a------ C:\WINDOWS\SYSTEM32\msvcp60.dll
2006-11-14 13:19 40,960 --a------ C:\WINDOWS\SYSTEM32\tscupgrd.exe
2006-11-14 13:19 40,960 --a------ C:\WINDOWS\SYSTEM32\tcpmonui.dll
2006-11-14 13:19 40,960 --a------ C:\WINDOWS\SYSTEM32\safrslv.dll
2006-11-14 13:19 40,448 --a------ C:\WINDOWS\SYSTEM32\tcpmon.dll
2006-11-14 13:19 40,448 --a------ C:\WINDOWS\SYSTEM32\ftp.exe
2006-11-14 13:19 4,736 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\intelide.sys
2006-11-14 13:19 4,608 --a------ C:\WINDOWS\SYSTEM32\msimg32.dll
2006-11-14 13:19 4,608 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mspqm.sys
2006-11-14 13:19 4,126 --a------ C:\WINDOWS\SYSTEM32\msdxmlc.dll
2006-11-14 13:19 4,096 --a------ C:\WINDOWS\SYSTEM32\winver.exe
2006-11-14 13:19 4,096 --a------ C:\WINDOWS\SYSTEM32\sfc.dll
2006-11-14 13:19 4,096 --a------ C:\WINDOWS\SYSTEM32\nddeapir.exe
2006-11-14 13:19 4,096 --a------ C:\WINDOWS\SYSTEM32\ksuser.dll
2006-11-14 13:19 399,360 --a------ C:\WINDOWS\SYSTEM32\netlogon.dll
2006-11-14 13:19 395,776 --a------ C:\WINDOWS\SYSTEM32\ntvdm.exe
2006-11-14 13:19 392,704 --a------ C:\WINDOWS\SYSTEM32\ntmssvc.dll
2006-11-14 13:19 39,936 --a------ C:\WINDOWS\SYSTEM32\rtutils.dll
2006-11-14 13:19 39,936 --a------ C:\WINDOWS\SYSTEM32\htui.dll
2006-11-14 13:19 39,808 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\imapi.sys
2006-11-14 13:19 39,424 --a------ C:\WINDOWS\SYSTEM32\safrcdlg.dll
2006-11-14 13:19 39,424 --a------ C:\WINDOWS\SYSTEM32\net.exe
2006-11-14 13:19 388,608 --a------ C:\WINDOWS\SYSTEM32\mstsc.exe
2006-11-14 13:19 387,584 --a------ C:\WINDOWS\SYSTEM32\regwizc.dll
2006-11-14 13:19 385,024 --a------ C:\WINDOWS\SYSTEM32\sqlsrv32.dll
2006-11-14 13:19 384,000 --a------ C:\WINDOWS\SYSTEM32\themeui.dll
2006-11-14 13:19 381,440 --a------ C:\WINDOWS\SYSTEM32\lmrt.dll
2006-11-14 13:19 38,912 --a------ C:\WINDOWS\SYSTEM32\wsnmp32.dll
2006-11-14 13:19 38,912 --a------ C:\WINDOWS\SYSTEM32\hhsetup.dll
2006-11-14 13:19 38,400 --a------ C:\WINDOWS\SYSTEM32\ntmsapi.dll
2006-11-14 13:19 38,400 --a------ C:\WINDOWS\SYSTEM32\ntlanman.dll
2006-11-14 13:19 38,272 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys
2006-11-14 13:19 375,808 --a------ C:\WINDOWS\SYSTEM32\cmd.exe
2006-11-14 13:19 37,888 --a------ C:\WINDOWS\SYSTEM32\pstorec.dll
2006-11-14 13:19 37,888 --a------ C:\WINDOWS\SYSTEM32\grpconv.exe
2006-11-14 13:19 37,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mountmgr.sys
2006-11-14 13:19 37,376 --a------ C:\WINDOWS\SYSTEM32\perfctrs.dll
2006-11-14 13:19 368,640 --a------ C:\WINDOWS\SYSTEM32\msdtcprx.dll
2006-11-14 13:19 367,616 --a------ C:\WINDOWS\SYSTEM32\licdll.dll
2006-11-14 13:19 364,544 --a------ C:\WINDOWS\SYSTEM32\ssflwbox.scr
2006-11-14 13:19 364,544 --a------ C:\WINDOWS\SYSTEM32\ipsmsnap.dll
2006-11-14 13:19 36,922 --a------ C:\WINDOWS\SYSTEM32\imeshare.dll
2006-11-14 13:19 36,864 --a------ C:\WINDOWS\SYSTEM32\mscpxl32.dll
2006-11-14 13:19 36,864 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2006-11-14 13:19 36,352 --a------ C:\WINDOWS\SYSTEM32\sens.dll
2006-11-14 13:19 36,352 --a------ C:\WINDOWS\SYSTEM32\rshx32.dll
2006-11-14 13:19 358,912 --a------ C:\WINDOWS\SYSTEM32\msscp.dll
2006-11-14 13:19 354,816 --a------ C:\WINDOWS\SYSTEM32\psisdecd.dll
2006-11-14 13:19 35,632 --a------ C:\WINDOWS\SYSTEM32\ntio411.sys
2006-11-14 13:19 35,392 --a------ C:\WINDOWS\SYSTEM32\ntio412.sys
2006-11-14 13:19 348,195 --a------ C:\WINDOWS\SYSTEM32\msjetoledb40.dll
2006-11-14 13:19 348,191 --a------ C:\WINDOWS\SYSTEM32\mspbde40.dll
2006-11-14 13:19 346,624 --a------ C:\WINDOWS\SYSTEM32\tourstart.exe
2006-11-14 13:19 344,095 --a------ C:\WINDOWS\SYSTEM32\msxbde40.dll
2006-11-14 13:19 343,552 --a------ C:\WINDOWS\SYSTEM32\termmgr.dll
2006-11-14 13:19 34,560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hidclass.sys
2006-11-14 13:19 34,528 --a------ C:\WINDOWS\SYSTEM32\ntio804.sys
2006-11-14 13:19 34,528 --a------ C:\WINDOWS\SYSTEM32\ntio404.sys
2006-11-14 13:19 34,304 --a------ C:\WINDOWS\SYSTEM32\rcimlby.exe
2006-11-14 13:19 34,304 --a------ C:\WINDOWS\SYSTEM32\mciqtz32.dll
2006-11-14 13:19 339,968 --a------ C:\WINDOWS\SYSTEM32\mspaint.exe
2006-11-14 13:19 339,456 --a------ C:\WINDOWS\SYSTEM32\usp10.dll
2006-11-14 13:19 334,848 --a------ C:\WINDOWS\SYSTEM32\smlogcfg.dll
2006-11-14 13:19 334,848 --a------ C:\WINDOWS\SYSTEM32\ipsecsnp.dll
2006-11-14 13:19 33,808 --a------ C:\WINDOWS\SYSTEM32\ntio.sys
2006-11-14 13:19 33,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msgpc.sys
2006-11-14 13:19 33,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\disk.sys
2006-11-14 13:19 33,280 --a------ C:\WINDOWS\SYSTEM32\shmgrate.exe
2006-11-14 13:19 33,280 --a------ C:\WINDOWS\SYSTEM32\racpldlg.dll
2006-11-14 13:19 33,152 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\netbios.sys
2006-11-14 13:19 326,656 --a------ C:\WINDOWS\SYSTEM32\netsetup.exe
2006-11-14 13:19 324,096 --a------ C:\WINDOWS\SYSTEM32\mswebdvd.dll
2006-11-14 13:19 323,072 --a------ C:\WINDOWS\SYSTEM32\msvcrt.dll
2006-11-14 13:19 32,768 --a------ C:\WINDOWS\SYSTEM32\odbcad32.exe
2006-11-14 13:19 32,768 --a------ C:\WINDOWS\SYSTEM32\mnmsrvc.exe
2006-11-14 13:19 32,256 --a------ C:\WINDOWS\SYSTEM32\umandlg.dll
2006-11-14 13:19 32,256 --a------ C:\WINDOWS\SYSTEM32\perfproc.dll
2006-11-14 13:19 32,256 --a------ C:\WINDOWS\SYSTEM32\msgsvc.dll
2006-11-14 13:19 32,256 --a------ C:\WINDOWS\SYSTEM32\mnmdd.dll
2006-11-14 13:19 32,000 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\amdk6.sys
2006-11-14 13:19 319,760 --a------ C:\WINDOWS\SYSTEM32\msnsspc.dll
2006-11-14 13:19 319,519 --a------ C:\WINDOWS\SYSTEM32\msexcl40.dll
2006-11-14 13:19 318,464 --a------ C:\WINDOWS\SYSTEM32\ippromon.dll
2006-11-14 13:19 316,928 --a------ C:\WINDOWS\SYSTEM32\zipfldr.dll
2006-11-14 13:19 316,416 --a------ C:\WINDOWS\SYSTEM32\wiaservc.dll
2006-11-14 13:19 315,466 --a------ C:\WINDOWS\SYSTEM32\msrd3x40.dll
2006-11-14 13:19 315,392 --a------ C:\WINDOWS\SYSTEM32\hnetwiz.dll
2006-11-14 13:19 311,808 --a------ C:\WINDOWS\SYSTEM32\qdv.dll
2006-11-14 13:19 31,744 --a------ C:\WINDOWS\SYSTEM32\rundll32.exe
2006-11-14 13:19 31,744 --a------ C:\WINDOWS\SYSTEM32\pid.dll
2006-11-14 13:19 31,488 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\crusoe.sys
2006-11-14 13:19 31,232 --a------ C:\WINDOWS\SYSTEM32\wzcsapi.dll
2006-11-14 13:19 31,232 --a------ C:\WINDOWS\SYSTEM32\wpabaln.exe
2006-11-14 13:19 31,232 --a------ C:\WINDOWS\SYSTEM32\inetmib1.dll
2006-11-14 13:19 302,080 --a------ C:\WINDOWS\SYSTEM32\untfs.dll
2006-11-14 13:19 30,992 --a------ C:\WINDOWS\SYSTEM32\vbajet32.dll
2006-11-14 13:19 30,720 --a------ C:\WINDOWS\SYSTEM32\netstat.exe
2006-11-14 13:19 30,208 --a------ C:\WINDOWS\SYSTEM32\imgutil.dll
2006-11-14 13:19 3,584 --a------ C:\WINDOWS\SYSTEM32\msafd.dll
2006-11-14 13:19 3,338 --a------ C:\WINDOWS\SYSTEM32\redir.exe
2006-11-14 13:19 3,072 --a------ C:\WINDOWS\SYSTEM32\icmp.dll
2006-11-14 13:19 297,984 --a------ C:\WINDOWS\SYSTEM32\scesrv.dll
2006-11-14 13:19 296,448 --a------ C:\WINDOWS\SYSTEM32\wmstream.dll
2006-11-14 13:19 295,936 --a------ C:\WINDOWS\SYSTEM32\localspl.dll
2006-11-14 13:19 294,912 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-14 13:19 29,696 --a------ C:\WINDOWS\SYSTEM32\rtipxmib.dll
2006-11-14 13:19 29,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\npfs.sys
2006-11-14 13:19 29,184 --a------ C:\WINDOWS\SYSTEM32\wpnpinst.exe
2006-11-14 13:19 29,184 --a------ C:\WINDOWS\SYSTEM32\winipsec.dll
2006-11-14 13:19 29,184 --a------ C:\WINDOWS\SYSTEM32\csrsrv.dll
2006-11-14 13:19 285,184 --a------ C:\WINDOWS\SYSTEM32\kerberos.dll
2006-11-14 13:19 281,088 --a------ C:\WINDOWS\SYSTEM32\wzcsvc.dll
2006-11-14 13:19 28,800 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\modem.sys
2006-11-14 13:19 28,721 --a------ C:\WINDOWS\SYSTEM32\wshcon.dll
2006-11-14 13:19 28,672 --a------ C:\WINDOWS\SYSTEM32\sethc.exe
2006-11-14 13:19 28,672 --a------ C:\WINDOWS\SYSTEM32\profmap.dll
2006-11-14 13:19 28,672 --a------ C:\WINDOWS\SYSTEM32\isrdbg32.dll
2006-11-14 13:19 28,672 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-14 13:19 28,160 --a------ C:\WINDOWS\SYSTEM32\xcopy.exe
2006-11-14 13:19 278,016 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2006-11-14 13:19 276,992 --a------ C:\WINDOWS\SYSTEM32\rpcss.dll
2006-11-14 13:19 276,480 --a------ C:\WINDOWS\SYSTEM32\slbcsp.dll
2006-11-14 13:19 275,456 --a------ C:\WINDOWS\SYSTEM32\vssvc.exe
2006-11-14 13:19 271,360 --a------ C:\WINDOWS\SYSTEM32\objsel.dll
2006-11-14 13:19 270,365 --a------ C:\WINDOWS\SYSTEM32\odbcjt32.dll
2006-11-14 13:19 27,136 --a------ C:\WINDOWS\SYSTEM32\wmdmlog.dll
2006-11-14 13:19 27,136 --a------ C:\WINDOWS\SYSTEM32\ssdpapi.dll
2006-11-14 13:19 27,136 --a------ C:\WINDOWS\SYSTEM32\sendcmsg.dll
2006-11-14 13:19 27,136 --a------ C:\WINDOWS\SYSTEM32\mspatcha.dll
2006-11-14 13:19 268,800 --a------ C:\WINDOWS\SYSTEM32\ulib.dll
2006-11-14 13:19 266,752 --a------ C:\WINDOWS\SYSTEM32\msctf.dll
2006-11-14 13:19 266,240 --a------ C:\WINDOWS\SYSTEM32\inetcfg.dll
2006-11-14 13:19 26,624 --a------ C:\WINDOWS\SYSTEM32\safrdm.dll
2006-11-14 13:19 26,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\fdc.sys
2006-11-14 13:19 258,048 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-14 13:19 258,048 --a------ C:\WINDOWS\SYSTEM32\comdlg32.dll
2006-11-14 13:19 257,536 --a------ C:\WINDOWS\SYSTEM32\oakley.dll
2006-11-14 13:19 257,024 --a------ C:\WINDOWS\SYSTEM32\qcap.dll
2006-11-14 13:19 254,976 --a------ C:\WINDOWS\SYSTEM32\pdh.dll
2006-11-14 13:19 253,983 --a------ C:\WINDOWS\SYSTEM32\mstext40.dll
2006-11-14 13:19 253,952 --a------ C:\WINDOWS\SYSTEM32\wmpcd.dll
2006-11-14 13:19 253,952 --a------ C:\WINDOWS\SYSTEM32\msnetobj.dll
2006-11-14 13:19 251,904 --a------ C:\WINDOWS\SYSTEM32\strmdll.dll
2006-11-14 13:19 250,368 --a------ C:\WINDOWS\SYSTEM32\mstask.dll
2006-11-14 13:19 25,600 --a------ C:\WINDOWS\SYSTEM32\pstorsvc.dll
2006-11-14 13:19 247,808 --a------ C:\WINDOWS\SYSTEM32\wow32.dll
2006-11-14 13:19 245,760 --a------ C:\WINDOWS\SYSTEM32\mswmdm.dll
2006-11-14 13:19 241,695 --a------ C:\WINDOWS\SYSTEM32\msjtes40.dll
2006-11-14 13:19 241,664 --a------ C:\WINDOWS\SYSTEM32\qasf.dll
2006-11-14 13:19 241,664 --a------ C:\WINDOWS\SYSTEM32\mpg4dmod.dll
2006-11-14 13:19 240,640 --a------ C:\WINDOWS\SYSTEM32\hnetcfg.dll
2006-11-14 13:19 24,576 --a------ C:\WINDOWS\SYSTEM32\odbcbcp.dll
2006-11-14 13:19 24,576 --a------ C:\WINDOWS\SYSTEM32\nmmkcert.dll
2006-11-14 13:19 24,064 --a------ C:\WINDOWS\SYSTEM32\vdmdbg.dll
2006-11-14 13:19 24,064 --a------ C:\WINDOWS\SYSTEM32\skeys.exe
2006-11-14 13:19 24,064 --a------ C:\WINDOWS\SYSTEM32\mshta.exe
2006-11-14 13:19 238,592 --a------ C:\WINDOWS\SYSTEM32\tapisrv.dll
2006-11-14 13:19 238,080 --a------ C:\WINDOWS\SYSTEM32\newdev.dll
2006-11-14 13:19 237,056 --a------ C:\WINDOWS\SYSTEM32\icm32.dll
2006-11-14 13:19 231,424 --a------ C:\WINDOWS\SYSTEM32\upnpui.dll
2006-11-14 13:19 230,400 --a------ C:\WINDOWS\SYSTEM32\netui1.dll
2006-11-14 13:19 230,400 --a------ C:\WINDOWS\SYSTEM32\msieftp.dll
2006-11-14 13:19 23,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hidparse.sys
2006-11-14 13:19 23,552 --a------ C:\WINDOWS\SYSTEM32\wmdmps.dll
2006-11-14 13:19 23,552 --a------ C:\WINDOWS\SYSTEM32\perfdisk.dll
2006-11-14 13:19 23,424 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kbdclass.sys
2006-11-14 13:19 23,040 --a------ C:\WINDOWS\SYSTEM32\shscrap.dll
2006-11-14 13:19 23,040 --a------ C:\WINDOWS\SYSTEM32\perfos.dll
2006-11-14 13:19 23,040 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-14 13:19 229,376 --a------ C:\WINDOWS\SYSTEM32\msoeacct.dll
2006-11-14 13:19 228,352 --a------ C:\WINDOWS\SYSTEM32\mswsock.dll
2006-11-14 13:19 226,816 --a------ C:\WINDOWS\SYSTEM32\srrstr.dll
2006-11-14 13:19 22,528 --a------ C:\WINDOWS\SYSTEM32\slayerxp.dll
2006-11-14 13:19 22,528 --a------ C:\WINDOWS\SYSTEM32\shfolder.dll
2006-11-14 13:19 22,528 --a------ C:\WINDOWS\SYSTEM32\mslbui.dll
2006-11-14 13:19 22,528 --a------ C:\WINDOWS\SYSTEM32\hid.dll
2006-11-14 13:19 22,016 --a------ C:\WINDOWS\SYSTEM32\userinit.exe
2006-11-14 13:19 22,016 --a------ C:\WINDOWS\SYSTEM32\udhisapi.dll
2006-11-14 13:19 22,016 --a------ C:\WINDOWS\SYSTEM32\mciwave.dll
2006-11-14 13:19 22,016 --a------ C:\WINDOWS\SYSTEM32\ipxroute.exe
2006-11-14 13:19 22,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mouclass.sys
2006-11-14 13:19 219,648 --a------ C:\WINDOWS\SYSTEM32\logon.scr
2006-11-14 13:19 218,112 --a------ C:\WINDOWS\SYSTEM32\wmasf.dll
2006-11-14 13:19 217,088 --a------ C:\WINDOWS\SYSTEM32\rasapi32.dll
2006-11-14 13:19 213,023 --a------ C:\WINDOWS\SYSTEM32\msltus40.dll
2006-11-14 13:19 212,480 --a------ C:\WINDOWS\SYSTEM32\osk.exe
2006-11-14 13:19 210,944 --a------ C:\WINDOWS\SYSTEM32\moricons.dll
2006-11-14 13:19 21,504 --a------ C:\WINDOWS\SYSTEM32\wsock32.dll
2006-11-14 13:19 205,824 --a------ C:\WINDOWS\SYSTEM32\progman.exe
2006-11-14 13:19 204,288 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-14 13:19 203,264 --a------ C:\WINDOWS\SYSTEM32\uxtheme.dll
2006-11-14 13:19 202,752 --a------ C:\WINDOWS\SYSTEM32\localsec.dll
2006-11-14 13:19 201,728 --a------ C:\WINDOWS\SYSTEM32\mspmsp.dll
2006-11-14 13:19 200,704 --a------ C:\WINDOWS\SYSTEM32\odbc32.dll
2006-11-14 13:19 200,192 --a------ C:\WINDOWS\SYSTEM32\termsrv.dll
2006-11-14 13:19 20,992 --a------ C:\WINDOWS\SYSTEM32\setup.exe
2006-11-14 13:19 20,992 --a------ C:\WINDOWS\SYSTEM32\seclogon.dll
2006-11-14 13:19 20,992 --a------ C:\WINDOWS\SYSTEM32\mfcsubs.dll
2006-11-14 13:19 20,992 --a------ C:\WINDOWS\SYSTEM32\mciseq.dll
2006-11-14 13:19 20,554 --a------ C:\WINDOWS\SYSTEM32\odtext32.dll
2006-11-14 13:19 20,554 --a------ C:\WINDOWS\SYSTEM32\oddbse32.dll
2006-11-14 13:19 20,553 --a------ C:\WINDOWS\SYSTEM32\odpdx32.dll
2006-11-14 13:19 20,553 --a------ C:\WINDOWS\SYSTEM32\odfox32.dll
2006-11-14 13:19 20,553 --a------ C:\WINDOWS\SYSTEM32\odexl32.dll
2006-11-14 13:19 20,480 --a------ C:\WINDOWS\SYSTEM32\stimon.exe
2006-11-14 13:19 20,480 --a------ C:\WINDOWS\SYSTEM32\msorc32r.dll
2006-11-14 13:19 2,816 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\drmkaud.sys
2006-11-14 13:19 2,058,888 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-11-14 13:19 196,096 --a------ C:\WINDOWS\SYSTEM32\mobsync.dll
2006-11-14 13:19 193,536 --a------ C:\WINDOWS\SYSTEM32\rasppp.dll
2006-11-14 13:19 19,968 --a------ C:\WINDOWS\SYSTEM32\rcp.exe
2006-11-14 13:19 19,712 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\flpydisk.sys
2006-11-14 13:19 19,584 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ipinip.sys
2006-11-14 13:19 19,456 --a------ C:\WINDOWS\SYSTEM32\ssmarque.scr
2006-11-14 13:19 19,456 --a------ C:\WINDOWS\SYSTEM32\savedump.exe
2006-11-14 13:19 19,456 --a------ C:\WINDOWS\SYSTEM32\licmgr10.dll
2006-11-14 13:19 183,296 --a------ C:\WINDOWS\SYSTEM32\syncui.dll
2006-11-14 13:19 182,784 --a------ C:\WINDOWS\SYSTEM32\msutb.dll
2006-11-14 13:19 180,800 --a------ C:\WINDOWS\SYSTEM32\sqlunirl.dll
2006-11-14 13:19 18,944 --a------ C:\WINDOWS\SYSTEM32\ws2help.dll
2006-11-14 13:19 18,944 --a------ C:\WINDOWS\SYSTEM32\ssbezier.scr
2006-11-14 13:19 18,944 --a------ C:\WINDOWS\SYSTEM32\lpk.dll
2006-11-14 13:19 18,432 --a------ C:\WINDOWS\SYSTEM32\sclgntfy.dll
2006-11-14 13:19 18,432 --a------ C:\WINDOWS\SYSTEM32\rsmps.dll
2006-11-14 13:19 18,432 --a------ C:\WINDOWS\SYSTEM32\qprocess.exe
2006-11-14 13:19 18,048 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msfs.sys
2006-11-14 13:19 179,328 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\acpi.sys
2006-11-14 13:19 174,592 --a------ C:\WINDOWS\SYSTEM32\scecli.dll
2006-11-14 13:19 173,312 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mrxdav.sys
2006-11-14 13:19 172,664 --a------ C:\WINDOWS\SYSTEM32\xenroll.dll
2006-11-14 13:19 172,032 --a------ C:\WINDOWS\SYSTEM32\snmpsnap.dll
2006-11-14 13:19 171,520 --a------ C:\WINDOWS\SYSTEM32\winmm.dll
2006-11-14 13:19 171,008 --a------ C:\WINDOWS\SYSTEM32\sccsccp.dll
2006-11-14 13:19 17,920 --a------ C:\WINDOWS\SYSTEM32\shutdown.exe
2006-11-14 13:19 17,920 --a------ C:\WINDOWS\SYSTEM32\midimap.dll
2006-11-14 13:19 17,536 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\i2omp.sys
2006-11-14 13:19 17,408 --a------ C:\WINDOWS\SYSTEM32\wtsapi32.dll
2006-11-14 13:19 17,408 --a------ C:\WINDOWS\SYSTEM32\wshtcpip.dll
2006-11-14 13:19 17,408 --a------ C:\WINDOWS\SYSTEM32\ssmyst.scr
2006-11-14 13:19 17,408 --a------ C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2006-11-14 13:19 17,408 --a------ C:\WINDOWS\SYSTEM32\psapi.dll
2006-11-14 13:19 168,448 --a------ C:\WINDOWS\SYSTEM32\wldap32.dll
2006-11-14 13:19 168,192 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ndis.sys
2006-11-14 13:19 166,912 --a------ C:\WINDOWS\SYSTEM32\wintrust.dll
2006-11-14 13:19 166,912 --a------ C:\WINDOWS\SYSTEM32\photowiz.dll
2006-11-14 13:19 165,888 --a------ C:\WINDOWS\SYSTEM32\ntmsdba.dll
2006-11-14 13:19 165,376 --a------ C:\WINDOWS\SYSTEM32\w32time.dll
2006-11-14 13:19 165,376 --a------ C:\WINDOWS\SYSTEM32\tapi32.dll
2006-11-14 13:19 164,864 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
2006-11-14 13:19 16,896 --a------ C:\WINDOWS\SYSTEM32\snmpapi.dll
2006-11-14 13:19 16,896 --a------ C:\WINDOWS\SYSTEM32\msyuv.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\watchdog.sys
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\version.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\ups.exe
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\ping.exe
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\odbc32gt.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\nddenb32.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\mmfutil.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\linkinfo.dll
2006-11-14 13:19 16,384 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ccdecode.sys
2006-11-14 13:19 159,744 --a------ C:\WINDOWS\SYSTEM32\ipsecsvc.dll
2006-11-14 13:19 159,360 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kmixer.sys
2006-11-14 13:19 159,232 --a------ C:\WINDOWS\SYSTEM32\schedsvc.dll
2006-11-14 13:19 158,720 --a------ C:\WINDOWS\SYSTEM32\srsvc.dll
2006-11-14 13:19 157,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\netbt.sys
2006-11-14 13:19 155,675 --a------ C:\WINDOWS\SYSTEM32\scrobj.dll
2006-11-14 13:19 154,624 --a------ C:\WINDOWS\SYSTEM32\netman.dll
2006-11-14 13:19 151,626 --a------ C:\WINDOWS\SYSTEM32\msjint40.dll
2006-11-14 13:19 150,528 --a------ C:\WINDOWS\SYSTEM32\msdtcuiu.dll
2006-11-14 13:19 15,360 --a------ C:\WINDOWS\SYSTEM32\nddeapi.dll
2006-11-14 13:19 15,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mpe.sys
2006-11-14 13:19 147,483 --a------ C:\WINDOWS\SYSTEM32\scrrun.dll
2006-11-14 13:19 147,456 --a------ C:\WINDOWS\SYSTEM32\odbctrac.dll
2006-11-14 13:19 146,432 --a------ C:\WINDOWS\SYSTEM32\keymgr.dll
2006-11-14 13:19 146,304 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dmio.sys
2006-11-14 13:19 145,408 --a------ C:\WINDOWS\SYSTEM32\modemui.dll
2006-11-14 13:19 145,152 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\fastfat.sys
2006-11-14 13:19 144,896 --a------ C:\WINDOWS\SYSTEM32\initpki.dll
2006-11-14 13:19 143,872 --a------ C:\WINDOWS\SYSTEM32\msimtf.dll
2006-11-14 13:19 143,872 --a------ C:\WINDOWS\SYSTEM32\itircl.dll
2006-11-14 13:19 142,208 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aec.sys
2006-11-14 13:19 14,848 --a------ C:\WINDOWS\SYSTEM32\winrnr.dll
2006-11-14 13:19 14,848 --a------ C:\WINDOWS\SYSTEM32\usbmon.dll
2006-11-14 13:19 14,848 --a------ C:\WINDOWS\SYSTEM32\upnpcont.exe
2006-11-14 13:19 14,848 --a------ C:\WINDOWS\SYSTEM32\rdpsnd.dll
2006-11-14 13:19 14,848 --a------ C:\WINDOWS\SYSTEM32\powrprof.dll
2006-11-14 13:19 14,336 --a------ C:\WINDOWS\SYSTEM32\perfmon.exe
2006-11-14 13:19 14,336 --a------ C:\WINDOWS\SYSTEM32\inetppui.dll
2006-11-14 13:19 138,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys
2006-11-14 13:19 137,216 --a------ C:\WINDOWS\SYSTEM32\ntshrui.dll
2006-11-14 13:19 137,216 --a------ C:\WINDOWS\SYSTEM32\hotplug.dll
2006-11-14 13:19 136,704 --a------ C:\WINDOWS\SYSTEM32\schannel.dll
2006-11-14 13:19 135,680 --a------ C:\WINDOWS\SYSTEM32\rdchost.dll
2006-11-14 13:19 135,680 --a------ C:\WINDOWS\SYSTEM32\mobsync.exe
2006-11-14 13:19 134,656 --a------ C:\WINDOWS\SYSTEM32\netid.dll
2006-11-14 13:19 133,632 --a------ C:\WINDOWS\SYSTEM32\rsaenh.dll
2006-11-14 13:19 133,632 --a------ C:\WINDOWS\SYSTEM32\nwprovau.dll
2006-11-14 13:19 133,120 --a------ C:\WINDOWS\SYSTEM32\sfc_os.dll
2006-11-14 13:19 131,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\afd.sys
2006-11-14 13:19 131,072 --a------ C:\WINDOWS\SYSTEM32\msorcl32.dll
2006-11-14 13:19 130,560 --a------ C:\WINDOWS\SYSTEM32\sti_ci.dll
2006-11-14 13:19 130,304 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ks.sys
2006-11-14 13:19 13,824 --a------ C:\WINDOWS\SYSTEM32\uniplat.dll
2006-11-14 13:19 13,824 --a------ C:\WINDOWS\SYSTEM32\rassapi.dll
2006-11-14 13:19 13,568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\asyncmac.sys
2006-11-14 13:19 13,312 --a------ C:\WINDOWS\SYSTEM32\wship6.dll
2006-11-14 13:19 13,312 --a------ C:\WINDOWS\SYSTEM32\tcpmib.dll
2006-11-14 13:19 13,312 --a------ C:\WINDOWS\SYSTEM32\ssstars.scr
2006-11-14 13:19 13,312 --a------ C:\WINDOWS\SYSTEM32\rsh.exe
2006-11-14 13:19 13,312 --a------ C:\WINDOWS\SYSTEM32\msdmo.dll
2006-11-14 13:19 13,184 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\diskdump.sys
2006-11-14 13:19 129,024 --a------ C:\WINDOWS\SYSTEM32\sessmgr.exe
2006-11-14 13:19 128,512 --a------ C:\WINDOWS\SYSTEM32\taskmgr.exe
2006-11-14 13:19 128,000 --a------ C:\WINDOWS\SYSTEM32\itss.dll
2006-11-14 13:19 126,976 --a------ C:\WINDOWS\SYSTEM32\msdart.dll
2006-11-14 13:19 126,976 --a------ C:\WINDOWS\SYSTEM32\imagehlp.dll
2006-11-14 13:19 126,976 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-14 13:19 125,952 --a------ C:\WINDOWS\SYSTEM32\ifmon.dll
2006-11-14 13:19 125,440 --a------ C:\WINDOWS\SYSTEM32\shmedia.dll
2006-11-14 13:19 124,928 --a------ C:\WINDOWS\SYSTEM32\webvw.dll
2006-11-14 13:19 124,416 --a------ C:\WINDOWS\SYSTEM32\sndrec32.exe
2006-11-14 13:19 123,904 --a------ C:\WINDOWS\SYSTEM32\imapi.exe
2006-11-14 13:19 122,880 --a------ C:\WINDOWS\SYSTEM32\odbcconf.dll
2006-11-14 13:19 120,320 --a------ C:\WINDOWS\SYSTEM32\upnp.dll
2006-11-14 13:19 12,800 --a------ C:\WINDOWS\SYSTEM32\svchost.exe
2006-11-14 13:19 12,800 --a------ C:\WINDOWS\SYSTEM32\runonce.exe
2006-11-14 13:19 12,800 --a------ C:\WINDOWS\SYSTEM32\pjlmon.dll
2006-11-14 13:19 12,800 --a------ C:\WINDOWS\SYSTEM32\mgmtapi.dll
2006-11-14 13:19 12,800 --a------ C:\WINDOWS\SYSTEM32\mcastmib.dll
2006-11-14 13:19 12,416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ndisuio.sys
2006-11-14 13:19 12,288 --a------ C:\WINDOWS\SYSTEM32\rdsaddin.exe
2006-11-14 13:19 12,288 --a------ C:\WINDOWS\SYSTEM32\odbcp32r.dll
2006-11-14 13:19 12,288 --a------ C:\WINDOWS\SYSTEM32\mscpx32r.dll
2006-11-14 13:19 12,288 --a------ C:\WINDOWS\SYSTEM32\lmhsvc.dll
2006-11-14 13:19 119,808 --a------ C:\WINDOWS\SYSTEM32\wkssvc.dll
2006-11-14 13:19 119,808 --a------ C:\WINDOWS\SYSTEM32\wiadss.dll
2006-11-14 13:19 118,834 --a------ C:\WINDOWS\SYSTEM32\wscript.exe
2006-11-14 13:19 118,784 --a------ C:\WINDOWS\SYSTEM32\wmsdmoe.dll
2006-11-14 13:19 117,760 --a------ C:\WINDOWS\SYSTEM32\stobject.dll
2006-11-14 13:19 116,736 --a------ C:\WINDOWS\SYSTEM32\shsvcs.dll
2006-11-14 13:19 116,736 --a------ C:\WINDOWS\SYSTEM32\mplay32.exe
2006-11-14 13:19 116,736 --a------ C:\WINDOWS\SYSTEM32\glu32.dll
2006-11-14 13:19 116,224 --a------ C:\WINDOWS\SYSTEM32\iasrad.dll
2006-11-14 13:19 115,200 --a------ C:\WINDOWS\SYSTEM32\net1.exe
2006-11-14 13:19 114,176 --a------ C:\WINDOWS\SYSTEM32\input.dll
2006-11-14 13:19 113,664 --a------ C:\WINDOWS\SYSTEM32\msvfw32.dll
2006-11-14 13:19 113,152 --a------ C:\WINDOWS\SYSTEM32\idq.dll
2006-11-14 13:19 112,128 --a------ C:\WINDOWS\SYSTEM32\ntmarta.dll
2006-11-14 13:19 111,104 --a------ C:\WINDOWS\SYSTEM32\umpnpmgr.dll
2006-11-14 13:19 110,592 --a------ C:\WINDOWS\SYSTEM32\iccvid.dll
2006-11-14 13:19 11,776 --a------ C:\WINDOWS\SYSTEM32\xolehlp.dll
2006-11-14 13:19 11,776 --a------ C:\WINDOWS\SYSTEM32\sigtab.dll
2006-11-14 13:19 11,776 --a------ C:\WINDOWS\SYSTEM32\rexec.exe
2006-11-14 13:19 11,776 --a------ C:\WINDOWS\SYSTEM32\lsass.exe
2006-11-14 13:19 11,392 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bdasup.sys
2006-11-14 13:19 109,568 --a------ C:\WINDOWS\SYSTEM32\offfilt.dll
2006-11-14 13:19 108,544 --a------ C:\WINDOWS\SYSTEM32\msv1_0.dll
2006-11-14 13:19 108,544 --a------ C:\WINDOWS\SYSTEM32\mdminst.dll
2006-11-14 13:19 106,496 --a------ C:\WINDOWS\SYSTEM32\url.dll
2006-11-14 13:19 106,496 --a------ C:\WINDOWS\SYSTEM32\olepro32.dll
2006-11-14 13:19 105,984 --a------ C:\WINDOWS\SYSTEM32\netdde.exe
2006-11-14 13:19 104,448 --a------ C:\WINDOWS\SYSTEM32\wiavideo.dll
2006-11-14 13:19 104,064 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mup.sys
2006-11-14 13:19 103,936 --a------ C:\WINDOWS\SYSTEM32\sysocmgr.exe
2006-11-14 13:19 103,936 --a------ C:\WINDOWS\SYSTEM32\mstlsapi.dll
2006-11-14 13:19 103,936 --a------ C:\WINDOWS\SYSTEM32\imm32.dll
2006-11-14 13:19 102,400 --a------ C:\WINDOWS\SYSTEM32\win32spl.dll
2006-11-14 13:19 101,376 --a------ C:\WINDOWS\SYSTEM32\services.exe
2006-11-14 13:19 10,752 --a------ C:\WINDOWS\SYSTEM32\tracert.exe
2006-11-14 13:19 10,752 --a------ C:\WINDOWS\SYSTEM32\netrap.dll
2006-11-14 13:19 10,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\irenum.sys
2006-11-14 13:19 10,240 --a------ C:\WINDOWS\SYSTEM32\wshrm.dll
2006-11-14 13:19 10,240 --a------ C:\WINDOWS\SYSTEM32\msrle32.dll
2006-11-14 13:19 10,240 --a------ C:\WINDOWS\SYSTEM32\localui.dll
2006-11-14 13:19 10,112 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ndisip.sys
2006-11-14 13:19 1,998,848 --a------ C:\WINDOWS\SYSTEM32\wmploc.dll
2006-11-14 13:19 1,799,552 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2006-11-14 13:19 1,798,144 --a------ C:\WINDOWS\SYSTEM32\qedit.dll
2006-11-14 13:19 1,630,208 --a------ C:\WINDOWS\SYSTEM32\netshell.dll
2006-11-14 13:19 1,503,262 --a------ C:\WINDOWS\SYSTEM32\msjet40.dll
2006-11-14 13:19 1,425,680 --a------ C:\WINDOWS\SYSTEM32\wmpui.dll
2006-11-14 13:19 1,388,544 --a------ C:\WINDOWS\SYSTEM32\msvbvm60.dll
2006-11-14 13:19 1,350,144 --a------ C:\WINDOWS\SYSTEM32\query.dll
2006-11-14 13:19 1,298,432 --a------ C:\WINDOWS\SYSTEM32\wmpcore.dll
2006-11-14 13:19 1,230,336 --a------ C:\WINDOWS\SYSTEM32\msvidctl.dll
2006-11-14 13:19 1,227,776 --a------ C:\WINDOWS\SYSTEM32\quartz.dll
2006-11-14 13:19 1,190,400 --a------ C:\WINDOWS\SYSTEM32\ole32.dll
2006-11-14 13:19 1,157,632 --a------ C:\WINDOWS\SYSTEM32\sfcfiles.dll
2006-11-14 13:19 1,128,960 --a------ C:\WINDOWS\SYSTEM32\mmcndmgr.dll
2006-11-14 13:18 91,648 --a------ C:\WINDOWS\SYSTEM32\iuctl.dll
2006-11-14 13:18 90,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\scsiport.sys
2006-11-14 13:18 802,304 --a------ C:\WINDOWS\SYSTEM32\dxmrtp.dll
2006-11-14 13:18 77,440 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wdmaud.sys
2006-11-14 13:18 76,032 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\parport.sys
2006-11-14 13:18 70,912 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\videoprt.sys
2006-11-14 13:18 69,248 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sr.sys
2006-11-14 13:18 66,048 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\psched.sys
2006-11-14 13:18 64,000 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\udfs.sys
2006-11-14 13:18 62,976 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pci.sys
2006-11-14 13:18 62,464 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\serial.sys
2006-11-14 13:18 56,832 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sysaudio.sys
2006-11-14 13:18 56,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\redbook.sys
2006-11-14 13:18 548,352 --a------ C:\WINDOWS\SYSTEM32\rtcdll.dll
2006-11-14 13:18 53,120 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbhub.sys
2006-11-14 13:18 5,888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\splitter.sys
2006-11-14 13:18 49,152 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\volsnap.sys
2006-11-14 13:18 48,384 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rasl2tp.sys
2006-11-14 13:18 47,104 --a------ C:\WINDOWS\SYSTEM32\mspmspsv.dll
2006-11-14 13:18 46,336 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\raspptp.sys
2006-11-14 13:18 45,696 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\stream.sys
2006-11-14 13:18 44,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\watv03nt.sys
2006-11-14 13:18 4,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\viaide.sys
2006-11-14 13:18 4,096 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\swenum.sys
2006-11-14 13:18 38,912 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\raspppoe.sys
2006-11-14 13:18 38,024 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\termdd.sys
2006-11-14 13:18 37,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\p3.sys
2006-11-14 13:18 340,480 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys
2006-11-14 13:18 33,280 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wanarp.sys
2006-11-14 13:18 321,536 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\srv.sys
2006-11-14 13:18 31,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys
2006-11-14 13:18 30,592 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\processr.sys
2006-11-14 13:18 29,440 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys
2006-11-14 13:18 27,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rndismp.sys
2006-11-14 13:18 24,960 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbprint.sys
2006-11-14 13:18 24,448 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sonydcam.sys
2006-11-14 13:18 23,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys
2006-11-14 13:18 23,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pciidex.sys
2006-11-14 13:18 205,120 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
2006-11-14 13:18 20,232 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tdtcp.sys
2006-11-14 13:18 2,040,832 --a------ C:\WINDOWS\SYSTEM32\ntoskrnl.exe
2006-11-14 13:18 19,712 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\vga.sys
2006-11-14 13:18 19,456 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys
2006-11-14 13:18 19,328 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbuhci.sys
2006-11-14 13:18 182,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rdpdr.sys
2006-11-14 13:18 18,688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys
2006-11-14 13:18 18,688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wstcodec.sys
2006-11-14 13:18 166,656 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rdbss.sys
2006-11-14 13:18 16,256 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tdi.sys
2006-11-14 13:18 15,232 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbintel.sys
2006-11-14 13:18 14,976 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\streamip.sys
2006-11-14 13:18 14,976 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\serenum.sys
2006-11-14 13:18 14,366 --a------ C:\WINDOWS\SYSTEM32\asfsipc.dll
2006-11-14 13:18 138,752 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbport.sys
2006-11-14 13:18 137,088 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\update.sys
2006-11-14 13:18 134,272 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\portcls.sys
2006-11-14 13:18 13,824 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tape.sys
2006-11-14 13:18 12,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys
2006-11-14 13:18 12,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys
2006-11-14 13:18 12,160 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys
2006-11-14 13:18 12,032 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys
2006-11-14 13:18 116,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\rdpwd.sys
2006-11-14 13:18 115,712 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pcmcia.sys
2006-11-14 13:18 11,144 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tdpipe.sys
2006-11-14 13:18 11,136 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usb8023.sys
2006-11-14 13:18 10,880 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\slip.sys
2006-11-14 13:18 10,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sfloppy.sys
2006-11-14 13:18 1,955,840 --a------ C:\WINDOWS\SYSTEM32\ntkrnlpa.exe
2006-11-14 13:17 <DIR> d-------- C:\WINDOWS\EHome
2006-11-14 09:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-11-13 16:55 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2006-11-13 16:04 <DIR> d-------- C:\Program Files\NoAdware4
2006-11-13 11:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2006-11-06 15:57 <DIR> d--h----- C:\WINDOWS\PIF
2006-11-03 14:59 0 --a------ C:\WINDOWS\SYSTEM32\tingctoa.exe
2006-11-03 14:59 <DIR> d-------- C:\Program Files\VSAdd-in
2006-11-02 17:01 10,344 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys
2006-11-02 16:07 <DIR> d-------- C:\Program Files\PerformanceTest
2006-11-02 16:06 <DIR> d-------- C:\Program Files\CheckIt
2006-11-02 15:52 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2006-11-02 15:24 <DIR> d-------- C:\Program Files\Lavasoft
2006-11-02 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-11-02 13:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2006-10-30 15:57 0 --a------ C:\WINDOWS\SYSTEM32\dr2.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-30 16:37 -------- d-------- C:\Program Files\Common Files
2006-11-30 14:51 -------- d-------- C:\Program Files\Windows Media Player
2006-11-26 09:51 28256 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\MxlW2k.sys
2006-11-26 08:39 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-11-21 11:17 -------- d-------- C:\Program Files\Messenger
2006-11-21 11:17 -------- d-------- C:\Program Files\Internet Explorer
2006-11-21 10:51 -------- d-------- C:\Program Files\Windows NT
2006-11-21 10:51 -------- d-------- C:\Program Files\Outlook Express
2006-11-21 10:51 -------- d-------- C:\Program Files\NetMeeting
2006-11-21 10:51 -------- d-------- C:\Program Files\Movie Maker
2006-11-21 10:51 -------- d-------- C:\Program Files\Common Files\System
2006-11-06 17:07 0 --a------ C:\WINDOWS\SYSTEM32\dr1.exe
2006-11-06 17:06 0 --a------ C:\WINDOWS\kq82.exe
2006-11-06 17:06 0 --a------ C:\WINDOWS\ipv7.exe
2006-11-01 18:03 -------- d-------- C:\Program Files\Norton AntiVirus
2006-10-27 02:44 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-10-12 19:48 82 --a------ C:\WINDOWS\SYSTEM32\drrm.bat
2006-10-12 07:07 28955 --a------ C:\919_133.exe
2006-09-15 13:57 632 --a------ C:\WINDOWS\SYSTEM32\zoxter.exe
2006-09-12 23:09 1110528 --a------ C:\WINDOWS\SYSTEM32\msxml3.dll
2006-09-06 17:43 22752 --a------ C:\WINDOWS\SYSTEM32\spupdsvc.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"mmtask"="c:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"SnoopFreeUI"="SnoopFreeUI.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"aoapn"="C:\\WINDOWS\\System32\\eaovmp.exe reg_run"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"aoapn"="C:\\WINDOWS\\System32\\eaovmp.exe reg_run"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{CC1A2C48-84F4-4DAC-AEAC-41DF6344C84D}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Ad-Aware SE Personal.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\Disk Defragmenter.job
C:\WINDOWS\tasks\Spybot - Search & Destroy.job

Completion time: 06-11-30 17:15:08.62
C:\ComboFix.txt ... 06-11-30 17:15
C:\ComboFix2.txt ... 06-11-30 16:03
C:\ComboFix3.txt ... 06-11-30 15:46
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-30-2006, 08:51 PM   #12 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
Kaspersky

Quote:
KASPERSKY ONLINE SCANNER REPORT
06-11-30 20:15
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 1/12/2006
Kaspersky Anti-Virus database records: 233133


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\

Scan Statistics
Total number of scanned objects 34397
Number of viruses found 1
Number of infected objects 0 / 0
Number of suspicious objects 2
Duration of the scan process 00:25:50

Infected Object Name Virus Name Last Action
C:\Documents and Settings\administrat\Application Data\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Application Data\HP\Install\LaunchPad.htm Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Lavasoft\Ad-Aware\description.ini Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Lavasoft\Ad-Aware\Quarantine\auto-quarantine- 2006-09-27 20-05-50.bckp Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Lavasoft\Ad-Aware\settings.awc Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Lavasoft\Ad-Aware\stats.awd Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\BRNDLOG.BAK Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\BRNDLOG.TXT Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\MUSICMATCH Jukebox.lnk Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Office\MSOut11.pip Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Office\Word11.pip Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Outlook\Outlook.xml Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Protect\S-1-5-21-3556314377-1988665382-1352871011-1007\3b5d0f63-a10d-4f38-b3ab-dd53589f6f63 Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Protect\S-1-5-21-3556314377-1988665382-1352871011-1007\Preferred Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Protect\S-1-5-21-3556314377-1988665382-1352871011-500\cf5eafbb-ac00-4c97-aa94-66a5280fdcc3 Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Protect\S-1-5-21-3556314377-1988665382-1352871011-500\Preferred Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Real\rnadmin\rnsystem.dat Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Sun\Java\Deployment\deployment.properties Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Symantec\Shared\MyProfile.UserProfile Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Symantec\Shared\Options.VcPref Object is locked skipped

C:\Documents and Settings\administrat\Application Data\Symantec\Shared\Sessions\20051108194751937.liveReg Object is locked skipped

C:\Documents and Settings\administrat\Cookies\administrat@c.microsoft[1].txt Object is locked skipped

C:\Documents and Settings\administrat\Cookies\administrat@microsoft[2].txt Object is locked skipped

C:\Documents and Settings\administrat\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\administrat\Desktop\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Desktop\Windows Media Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Dell\Dell Auction.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Dell\Dell.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Dell\Gigabuys.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Dell\Support.Dell.com.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN CarPoint.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN Home.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN HomeAdvisor.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN Hotmail.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN Money.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN People & Chat.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN Shopping.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Financial Links\MSN Web Search.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Links\Customize Links.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Links\Free Hotmail.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Links\Windows Media.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Links\Windows.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\MSN.com.url Object is locked skipped

C:\Documents and Settings\administrat\Favorites\Radio Station Guide.url Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\ApplicationHistory\NotifyAlert.exe.83a8f8c0.ini.inuse Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\ApplicationHistory\rng.exe.ac4aa698.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\GDIPFONTCACHEV1.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\IconCache.db Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Outlook\extend.dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\1033.MST Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}\Java 2 Runtime Environment, SE v1.4.2.msi Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\History\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\History\History.IE5\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\acs2420aa\acsuninstall.exe Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\acs2420aa\AcsUninstallRes.dll Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\GLF10B.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_BufferChm.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_Destinations.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_DeviceFunctionQFolder.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_DeviceManagementQFolder.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_dj3900.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_eSupportQFolder.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_hpproductassistant.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_HPSoftwareUpdate.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_ImageZoneExpress.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_SolutionCenter.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_Status.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_TrayApp.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpfMSI_WebReg.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpodvd09.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp004.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzarp005.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzcdl000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzchk000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzdui000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzgat000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzgat001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\HPZIDS.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi004.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi005.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi006.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi007.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi008.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi009.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi010.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi011.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzmsi012.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop004.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpznop005.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzopt000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpnp000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpnp001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpnp002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpnp003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl004.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl005.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl006.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl007.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzprl008.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpsc000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzpsl000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzrcv000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzrcv001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzrcv002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzrei000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset004.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzset005.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzshl000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzshl001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzshl002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzshl003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzsui000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwis000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwis001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwrp000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwrp001.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwrp002.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwrp003.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\hpzwup000.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\IDSinst.LOG Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\is-62M3S.tmp\_isetup\_shfoldr.dll Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\LRPatch.exe Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\LRSetup.exe Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\LSInstall.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR1.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR12.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR2.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR3.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR4.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR5.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR6.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR7.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR8.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MAR9.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MARA.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MARA0.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MARB.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MARBA.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\masters.mst Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\Ad-Aware\Ad-Aware log2006-09-27 20-02-51.txt Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\Ad-Aware\AD-AWARE.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\Ad-Aware\DEFS.REF Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_2000.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_95.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_98.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_ME.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_NT4.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_XP.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CONTROL_XPSP1.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\CWS START.CHM FIX.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\MSCONFIG_98.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\MSCONFIG_98SE.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\MSCONFIG_ME.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\MSCONFIG_XP.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\MSCONFIG_XPSP1.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_2000.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_95.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_98.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_ME.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_NT4.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\NOTEPAD_XP.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_2000.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_95.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_98.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_ME.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_NT4.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\RUNDLL32_XP.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\SDHELPER13.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\SHELL_98.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\SHELL_NT.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\WMPLAYER_7.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\WMPLAYER_8.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\WMPLAYER_9.ZIP Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\ADDITIONAL CWS FIXES\_HOW TO USE THESE FILES.TXT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\CWSHREDDER\CWSHREDDER.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\CLSID.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\CONTEXT.DLL Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\ENGINE.DLL Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\error.txt Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\EWIDO.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\GUARD.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\GUARD.SYS Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\HELP.DLL Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\HEURISTIC.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\LANG.INI Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\LOGFILE.TXT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\QUARANTINE\fil5E17FC71.dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SHELLEXECUTEHOOK.DLL Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1710.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1711.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1712.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1713.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1714.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1715.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1716.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1717.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1718.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1719.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1720.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1721.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1722.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1723.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1724.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1725.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1726.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1727.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1728.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1729.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1730.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1731.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1732.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1733.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1734.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1735.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1736.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1737.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1738.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1739.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1740.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1741.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1742.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1743.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1744.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1745.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1746.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1747.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1748.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1749.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1750.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1751.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1752.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1753.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1754.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1755.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1756.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1757.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1758.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1759.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1760.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1761.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1762.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1763.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1764.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1765.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1766.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1767.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1768.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1769.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1770.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1771.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1772.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1773.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1774.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1775.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1776.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1777.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1778.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1779.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1780.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1781.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1782.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1783.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1784.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1785.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1786.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1787.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1788.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1789.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1790.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1791.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1792.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1793.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1794.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1795.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1796.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1797.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1798.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1799.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1800.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1801.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1802.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1803.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1804.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1805.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1806.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1807.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1808.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1809.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1810.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1811.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1812.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1813.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1814.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1815.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1816.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1817.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1818.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1819.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1820.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1821.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1822.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1823.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1824.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1825.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1826.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1827.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1828.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1829.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1830.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1831.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1832.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1833.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1834.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1835.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1836.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1837.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1838.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1839.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1840.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1841.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1842.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1843.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1844.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1845.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1846.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1847.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1848.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1849.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1850.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1851.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1852.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1853.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1854.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1855.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1856.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1857.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1858.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1859.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1860.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1861.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1862.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1863.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1864.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1865.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1866.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1867.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1868.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1869.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1870.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1871.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1872.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1873.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1874.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1875.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1876.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1877.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1878.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1879.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1880.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1881.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1882.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1883.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1884.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1885.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1886.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1887.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1888.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1889.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1890.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1891.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1892.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1893.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1894.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1895.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1896.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1897.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1898.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1899.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1900.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1901.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1902.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1903.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1904.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1905.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1906.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1907.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1908.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1909.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1910.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1911.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1912.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1913.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1914.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1915.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1916.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1917.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1918.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1919.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1920.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1921.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1922.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1923.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1924.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1925.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1926.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1927.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1928.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1929.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1930.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1931.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1932.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1933.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1934.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1935.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1936.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1937.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1938.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1939.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1940.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1941.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1942.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1943.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1944.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1945.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1946.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1947.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1948.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1949.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1950.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1951.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1952.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1953.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1954.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1955.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1956.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1957.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1958.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1959.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1960.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1961.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1962.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1963.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1964.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1965.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1966.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1967.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1968.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1969.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1970.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1971.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1972.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1973.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1974.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\SIGNATURES\1975.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\TRANSLATIONS\CZECH.MO Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\TRANSLATIONS\ENGLISH.MO Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\TRANSLATIONS\GERMAN.MO Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\MRI_LASER\EWIDO\UNINSTALL.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\outlook logging\firstrun.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\Perflib_Perfdata_a20.dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\Perflib_Perfdata_df0.dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\SNDSetup544.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\SNDUpdater544I.log Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\SPY SWEEPER V5.0.5.1286 TRIAL.EXE Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS10.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS11.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS14.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS3.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS6.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS7.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STS9.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSA.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSAB.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSB.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSBD.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSC.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSE.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\STSF.tmp Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\SYMEVENT.LOG Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temp\uninst.dll Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\au_bg_leftmiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\au_bg_lefttop[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\au_button_right[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\blank[1].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\defs[1].ref Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\failed-lg[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\hdr_welcome[1].jpg Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\icon.plus[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\info_icon[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\iuengine[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\mu_getstarted-part1top_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\mu_getstarted-part2top_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\news_bg_lefttop[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\news_bg_topmiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\redirect[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\remaining-lg[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\success-sm[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\tgar[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\tgar[2].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\toc[1].css Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\webcomtop[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\wuaucpl[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\wuident[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\4PQ7052J\wups[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\au_bg_bottommiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\au_bg_leftbottom[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\au_shieldred[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\au_shieldyellow[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\cdm[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\commontop[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\content[1].css Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\content[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\content[2].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\content[3].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\content[4].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\ewido-signatures-full-current[1].exe Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\footer[1].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\hcp[1].css Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\mstoolbar[1].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\mu_getstarted-center[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\mu_getstarted-part1middle_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\news_bg_bottommiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\news_bg_leftbottom[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\remaining-sm[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\success-lg[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\tgar[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\toc[1].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\trans_pixel[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\wuauclt1[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\wucltui[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\wuredir[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\arrowsquare[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\au_bg_rightmiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\au_button_left[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\au_shieldgreen[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\banner-bg[1].jpg Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\content[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\content[2].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\failed-sm[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\mu_getstarted-part1bottom_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\mu_getstarted-part2middle_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\news_bg_rightmiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\news_bg_righttop[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\redirect[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\resultslist[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\tgar[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\tgar[2].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\tgar[3].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\tgar[4].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\toc[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\WindowsPCA[1].crl Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\windowsupdate.microsoft[1].htm Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\wuauclt[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\C9M7KX6B\wuaueng1[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\arrow[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\au_bg_rightbottom[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\au_bg_righttop[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\au_button_middle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\banner-right[1].jpg Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\content[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\default[2].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\hdr_finish_left[1].jpg Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\InstallStatus[1].aspx Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\masters[1].mst Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\mu_getstarted-part2bottom_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\news_bg_leftmiddle[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\news_info[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\spupdateids[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\tgar[1].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\tgar[2].js Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\version[1].dat Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\welcome-bg[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\welcome-right[1].jpg Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\windows_masthead_ltr[1].gif Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\wuapi[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\wuaueng[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\wups2[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\wusetup[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\Content.IE5\KPABW9QF\wuweb_site[1].cab Object is locked skipped

C:\Documents and Settings\administrat\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\My Documents\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Canyon__Mansion_On_The_Mountain.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Chuck_Prophet__What_Makes_the_Monkey_Dance.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Cordero__Vamos_Nenas.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Drive_by_Truckers__My_Sweet_Annette.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Get More with Jukebox Plus.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Imperial_Teen__Sugar.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Jon_Dee_Graham__One_Moment.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Sample Music.lnk Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Secondhand_Jive__San_Francisco96.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Slobberbone__Sister_Beams.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\The_Flatlanders__Julia.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Music\Vic_Chestnut__Im_Through.mp3 Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Pictures\Desktop.ini Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript1.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript2.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript3.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript4.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript5.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript6.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript7.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript8.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My PSP8 Files\Scripts-Restricted\BoundScript9.PspScript Object is locked skipped

C:\Documents and Settings\administrat\My Documents\My Videos\Experience.mpg Object is locked skipped

C:\Documents and Settings\administrat\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\administrat\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\administrat\NTUSER.INI Object is locked skipped

C:\Documents and Settings\administrat\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped

C:\Documents and Settings\administrat\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped

C:\Documents and Settings\administrat\SendTo\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\SendTo\Mail Recipient.MAPIMail Object is locked skipped

C:\Documents and Settings\administrat\SendTo\MUSICMATCH Burner Plus.lnk Object is locked skipped

C:\Documents and Settings\administrat\SendTo\My Documents.mydocs Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Accessibility\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Entertainment\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Entertainment\RealOne Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Dell Accessories\Express Service Code.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Outlook Express.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Startup\DESKTOP.INI Object is locked skipped

C:\Documents and Settings\administrat\Start Menu\Programs\Windows Media Player.lnk Object is locked skipped

C:\Documents and Settings\administrat\Templates\AMIPRO.SAM Object is locked skipped

C:\Documents and Settings\administrat\Templates\EXCEL.XLS Object is locked skipped

C:\Documents and Settings\administrat\Templates\EXCEL4.XLS Object is locked skipped

C:\Documents and Settings\administrat\Templates\LOTUS.WK4 Object is locked skipped

C:\Documents and Settings\administrat\Templates\POWERPNT.PPT Object is locked skipped

C:\Documents and Settings\administrat\Templates\PRESENTA.SHW Object is locked skipped

C:\Documents and Settings\administrat\Templates\QUATTRO.WB2 Object is locked skipped

C:\Documents and Settings\administrat\Templates\SNDREC.WAV Object is locked skipped

C:\Documents and Settings\administrat\Templates\WINWORD.DOC Object is locked skipped

C:\Documents and Settings\administrat\Templates\WINWORD2.DOC Object is locked skipped

C:\Documents and Settings\administrat\Templates\WORDPFCT.WPD Object is locked skipped

C:\Documents and Settings\administrat\Templates\WORDPFCT.WPG Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\AvgFwLog.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\AvgFwLog.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver2.zip/MTE3NDI6ODoxNgMTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver2.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\Brain Stew.D4ZR6H41\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Brain Stew.D4ZR6H41\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Brain Stew.D4ZR6H41\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Hastings KFC\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\Local Settings\History\History.IE5\MSHist012006113020061201\index.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Hastings KFC\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Hastings KFC\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped

C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP7\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\ModemLog_Conexant SmartHSFi V.9x 56K DF PCI Modem.txt Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

Scan was interrupted by user!
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-01-2006, 10:16 PM   #13 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


From a couple of files that combo removed, I can tell this system has been infected for quite a while.

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked

O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run

Close HijackThis now.

---------------------------------------------------------------------------------------------

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new HJT log.

Are you still experiencing problems with the programs?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-03-2006, 09:36 AM   #14 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
Dr. Web

I will have to run this program in the morning(Monday). As far as the behavior of the computer gose, the winpro antivirus pop ups have stoped. We are still getting netflix popups. I have been told that outlook and excel seem to be running better, over all the speed and response of the computer seem to be better. Than You.
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-04-2006, 03:43 PM   #15 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
The Logs you ask for DR Web, HJT

Quote:
RegUBP2b-Hastings KFC.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots;Trojan.StartPage.1505;Deleted.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
A0000875.reg;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP10;Trojan.StartPage.1505;Deleted.;
A0000110.reg;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP3;Trojan.StartPage.1505;Deleted.;
A0000262.exe;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP4;Tool.Prockill;;
A0000264.exe;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP4;Tool.ShutDown.11;;
A0000459.dll;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP5;Probably STPAGE.Trojan;;
A0000655.exe;C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP7;Adware.Look2me;;
Quote:
Logfile of HijackThis v1.99.1
Scan saved at 16:29, on 06-12-04
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sourcelink.mclaneco.com/login.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/reso...scbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159410032375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1164659162875
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-04-2006, 05:45 PM   #16 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


netflix popups or popunders might be controlled by IE's popup blocker, using Firefox, or Google Toolbar and it's popup blocker. If netflix is installed on the system, you might consider removing it. These popunders can come from affiliate sites, however.

http://www.hackingnetflix.com/2006/0...x_popunde.html

Other than that, your logs appear clean.

Well done. Any more issues? If not you should be good to go. We still have a few items to address.


Reset hidden/system files and folders
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

Create a new System Restore point
  • click Start >> Run - type SYSDM.CPL & press Enter
  • select the System Restore Tab
  • tick on the checkbox - "Turn off System Restore on all drives"
  • click Apply
  • then untick the same checkbox & click OK


Enable Windows Auto Update
  • Go to Start>Run - type wuaucpl.cpl
  • tick on the checkbox - "Keep my computer up to date"
  • Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
  • Click on "OK".

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
    • Install & update SpywareBlaster with the latest definitions.
      After you have updated, click the button - enable protection for all unprotected items
  • SpywareGuard to catch and block spyware before it can execute.
  • SPYBOT - SEARCH & DESTROY
    Download and install Spybot - Search & Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with the program on a regular basis just as you would an antivirus software. A tutorial on installing & using this product can be found here
  • AD-AWARE
    Download and install Ad-Aware. You should use this program to scan your computer on a regular basis just as you would an antivirus software in conjunction with Spybot. A tutorial on installing & using this product can be found here

  • IE-SPYAD - IE/Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
    • Download IE-SpyAD - Extract the contents to a new folder
      From within the folder, double-click install.bat
      Select Option #2 - Install the new IE-SPYAD list.
      Then return to the main menu.
      Select option #4 - Add the old porn sites domain


  • MVPS HOST FILE
    The MVPS Hosts file replaces your current HOSTS file with one that will restrict known ad sites form serving you unsolicited advertisements. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is the IP of your local computer.
    • Download Host.zip to your desktop.
    • From your Desktop right-click (hosts.zip) and select:
      Extract All from the menu.
    • Click Next, click Next, select the option:
      "Show Extracted files", click Finish
    • This will open the newly created hosts folder on your Desktop.
    • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.


  • ANTIVIRUS SOFTWARE
    It is very important that you have anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    Here are a few very good free Antivirus products which are available:Select one of these, or another of your choice. Do not install more than one antivirus program because they will conflict with each other. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.
See this link for a listing of some online antivirus scanners:

Anti-Spyware Tutorial

If you do not have a firewall, here are a couple of free ones available for personal use:


In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-04-2006, 09:38 PM   #17 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
Thank You

I want to say thank You. It seemed like a lot of work. It is a relief to know that my logs are clean. All of the programs you suggested that I install, I have already done. While you were reading my logs I was reading the tutorials. The only difference is I installed sygate firewall instead of zone alarm.
When I run windows updates can I now get sp2?

I noticed something that I thought was odd. More than once you asked me to look for O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run. The thing of it was I had a hard time finding it. I ran 4 HJT before I found it. I only sent you 3 of those logs. The reason for this is 2 of them were from MY desktop. One of them (the last one) came from My administrators desktop. When I ran HJT on my desktop, O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run, would not show up on a scan only. Also when I ran scan and save log on my desktop, it would not show up. I could not put a check by it, yet it showed up in the logfile. In your last post you ask me to look for it again. So I ran HJT twice today. Once on my desktop. The same, still could not see it. So I logged off my desktop. Had my administrator log in, ran it on his desktop, and guess I saw the first time I looked. It was right there in front of me. Did I do somthing wrong? Once again Thank You.

Last edited by Brain Stew; 12-04-2006 at 09:49 PM. Reason: spelling errors
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-04-2006, 11:36 PM   #18 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


HJT scans are user account specific. Not all items are global. Therein lies the issue. HJT does not show what account the scan is being run from, though we can sometimes tell from certain entries, if there's a Docs and Settings location in an entry.

Do me this one thing now....post a HJT log from each account you've been using. Label them accordingly. This way we can ensure they are both clean.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-05-2006, 08:10 AM   #19 (permalink)
Registered User
 
Join Date: Nov 2006
Posts: 23
OS: xp


Send a message via Yahoo to Brain Stew
the logs you asked for

this one is from my account:

Quote:
Logfile of HijackThis v1.99.1
Scan saved at 9:01:28 AM, on 12/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/reso...scbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159410032375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1164659162875
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
This 0ne is from admin account:

Quote:
Logfile of HijackThis v1.99.1
Scan saved at 08:59, on 06-12-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sourcelink.mclaneco.com/login.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/reso...scbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159410032375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1164659162875
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Brain Stew is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 12-05-2006, 09:43 AM   #20 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,179
OS: 2000 Pro; XP Pro; XP Home


Hi Brain Stew -

OK, that looks good.

One last detail which should be taken care of....

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 10.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop. Note: this is a very large download. Allow time.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_10-windowsi586-p.exe to install the newest version.

---------------------------------------------------------------------------------------------

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 11:58 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85