Sponsored By

skywatcher

Members
  • Content Count

    26
  • Joined

  • Last visited

About skywatcher

  • Rank
    Member
  1. dear best techie, i have been having huge problems in the last weeks and as a result i have reinstalled windows 2000p three times but keep getting loads of trojans. i think one problem may be that there was a very small gap between getting web connected and installing avast again and also possibly that i forgot on opne occasion to update windows 2000 to service pack 4. i also keep getting the restore.fix pop up box. can anyone help? any help greatly appreciated. my hijack this log is as follows. thanks in advance, malcolm Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:44:02, on 21/05/2009 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINNT\System32\svchost.exe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINNT\system32\internat.exe C:\WINNT\system32\RUNDLL32.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\System32\logon.exe O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINNT\System32\algs.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1242889696188 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe -- End of file - 3050 bytes
  2. my win2000p computer has got trojans and backdoor bots again. i removed 2 of 3 from my machine but it could not touch the third. i have run a hijack this log. if anyone can help with a suggestion as to what i can try i would be very grateful. thanks. malcolm log follows... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:19:13, on 04/05/2009 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\csrss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\pROGRAM fILES\iNTERNET eXPLORER\iExPlOrE.eXe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\system32\tdctxte.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINNT\system32\internat.exe C:\WINNT\system32\RUNDLL32.EXE C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O10 - Unknown file in Winsock LSP: c:\winnt\system32\17341232431.dll O10 - Unknown file in Winsock LSP: c:\winnt\system32\17341232431.dll O10 - Unknown file in Winsock LSP: c:\winnt\system32\17341232431.dll O10 - Unknown file in Winsock LSP: c:\winnt\system32\17341232431.dll O10 - Unknown file in Winsock LSP: c:\winnt\system32\17341232431.dll O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1231600798538 O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Logicae Disk Manager Administu - Unknown owner - C:\WINNT\system32\srpsvrvte.exe O23 - Service: Networks - GlobalSCAPE Texas, LP - C:\WINNT\system32\nets.dll O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINNT\system32\tdctxte.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 8483 bytes
  3. skywatcher

    Hmmm

    my computer has started getting very uppity and running slow. i run win2000p and this is my hijackthis log................ thanks for any help offered, sky Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:07:28, on 03/04/2009 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINNT\system32\afisicx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINNT\System32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\pROGRAM fILES\iNTERNET eXPLORER\iExPlOrE.eXe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\sopidkc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\system32\tdctxte.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINNT\system32\internat.exe C:\WINNT\system32\RUNDLL32.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\WINNT\system32\rundll32.exe C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe C:\WINNT\system32\tpszxyd.sys C:\WINNT\system32\dpcxool64.sys C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1231600798538 O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINNT\system32\afisicx.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Logicae Disk Manager Administu - Unknown owner - C:\WINNT\system32\srpsvrvte.exe O23 - Service: Networks - GlobalSCAPE Texas, LP - C:\WINNT\system32\nets.dll O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINNT\system32\tdctxte.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 8292 bytes
  4. all done! there were losts of nasties in there. here is the log. thanks, malcolm Malwarebytes' Anti-Malware 1.34 Database version: 1799 Windows 5.0.2195 Service Pack 4 24/02/2009 22:22:18 mbam-log-2009-02-24 (22-22-18).txt Scan type: Quick Scan Objects scanned: 71169 Time elapsed: 7 minute(s), 39 second(s) Memory Processes Infected: 2 Memory Modules Infected: 0 Registry Keys Infected: 21 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 16 Memory Processes Infected: C:\WINNT\system32\mabidwe.exe (Trojan.Agent) -> Unloaded process successfully. C:\WINNT\system32\soxpeca.exe (Backdoor.Bot) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\noytcyr (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\roytctm (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\soxpeca (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\soxpeca (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\soxpeca (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\noytcyr (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\noytcyr (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\explorer (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\txtfile\shell\open\command\ (Hijack.Notepad) -> Bad: ("C:\WINNT\system32\nxtepad.exe" "%1") Good: (notepad.exe %1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\qn.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Default User.WINNT\Local Settings\Temporary Internet Files\Content.IE5\V6J9MIGB\w[1].bin (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINNT\system32\afisicx.exe (Trojan.Agent) -> Delete on reboot. C:\WINNT\system32\mabidwe.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINNT\system32\tdydowkc.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINNT\system32\wsldoekd.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINNT\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINNT\system32\msrstart.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\nxtepad.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\o.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\umtcdtw.sys (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\soxpeca.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\noytcyr.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\udxfytw.sys (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\tpszxyd.sys (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINNT\system32\roytctm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
  5. i forgot to apply email notification so this is just to add that for if or when someone is able to look at my post. thanks. malcolm
  6. hi sarah, thanks for your message. just to remind you in case you are looking at this a while later. you helped with a previous problem, and you thought that my computer would always be vulnerable as it runs win2000p. it was clean for a month or more with just the occasional warning bubble, but the last few days they have become more frequent and this evening i got quite an avalanche of them. so here is my hijack this log. thanks in advance, malcolm log follows..................... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:10:09, on 14/02/2009 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINNT\System32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINNT\system32\mabidwe.exe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINNT\system32\internat.exe C:\WINNT\system32\RUNDLL32.EXE C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe C:\WINNT\system32\rundll32.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINNT\DOWNLO~1\Manager.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1231600798538 O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINNT\system32\afisicx.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINNT\system32\mabidwe.exe O23 - Service: Networks - GlobalSCAPE Texas, LP - C:\WINNT\system32\nets.dll O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINNT\system32\noytcyr.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINNT\system32\roytctm.exe (file missing) O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINNT\system32\soxpeca.exe (file missing) O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINNT\system32\tdydowkc.exe (file missing) O23 - Service: wsldoekd Service (wsldoekd) - Unknown owner - C:\WINNT\system32\wsldoekd.exe (file missing) -- End of file - 8030 bytes
  7. hello again sarah, i have followed your suggestions and the log is posted below. thanks again! best regards, malcolm log follows.... Malwarebytes' Anti-Malware 1.33 Database version: 1656 Windows 5.0.2195 Service Pack 4 15/01/2009 23:51:11 mbam-log-2009-01-15 (23-51-11).txt Scan type: Quick Scan Objects scanned: 61614 Time elapsed: 11 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\BitDownload (Trojan.Lop) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Administrator.SARAH\Start Menu\Programs\BitDownload (Trojan.Lop) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Administrator.SARAH\Start Menu\Programs\BitDownload\BitDownload Downloads.lnk (Trojan.Lop) -> Quarantined and deleted successfully. C:\WINNT\system32\hguest.exe (Trojan.Agent) -> Quarantined and deleted successfully.
  8. hi there, i was very kindly helped with a serious problem by sarahw recently and i have just been getting some trojan horse messages from avast so i have run another hijack this log to ask if i still have a problem. any help would be very gratefully acknowledged! thanks in advance, malcolm log follows Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:00:25, on 14/01/2009 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\WINNT\System32\svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINNT\System32\nvsvc32.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINNT\system32\internat.exe C:\WINNT\system32\RUNDLL32.EXE C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe C:\WINNT\system32\wuauclt.exe C:\WINNT\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1231600798538 O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe -- End of file - 6840 bytes
  9. hi sarah, thanks again and this is really my last question! i have added the sunbelt firewall and followed a number of suggestions from your list and jason's site, and some from pc offensive to make my computer run quicker, but my computer is actually running slower in fact it is dawdling a bit now. can you suggest anything obvious i might have changed in all this that might have had that effect? i did follow jason's advice of setting active x for prompt, but i was getting so many prompts that i have set that back to accept. i know that really i should buy a new computer, but at this point in time i just don't have the readies. best regards, malcolm
  10. hi sarah, it all seems remarkably clean and clear now. i looked at your general advice page with the links which was very useful thanks and i used several. i have been confused about the firewall status of my computer for quite a while however. i think it comes from having had the virgin firewall previously (which i am not sure but i do not think is still on it). it never had an icon in the tray or any visible sign. and i periodically get (not last few days) warning pop ups in the bottom of the screen about this or that trying to access my computer and being blocked so i have thought maybe i did have a firewall of some type or another. my avast however just seems to be anti virus and i could not see any obvious firewall candidates listed in programmes. so i followed the two firewall links in your general advice sheet. the first one (zone something?)told me when it started trying to install itself that it was not suitable for windows 2000 and aborted, the second one was only available for a 30 day free trial. do you know if there is a way i can check if there is a firewall running on my machine? and is there a good and preferably free firewall i can use? thanks again so much for your help and i will leave you in peace now! malcolm
  11. hi sarah, i have given it a couple of days to make sure, but i am not getting any of the old problems at the moment and long may it continue! thanks a million for your perseverence and invaluable help, i really appreciate it. best regards, malcolm
  12. i think i have done that - let me know if you get it ok as i have never posted zip or any other files this way. thanks, malcolm
  13. hi sarah. all done and log below. my operating system is 2000p by the way. thanks, malcolm ComboFix 09-01-05.05 - Administrator 06/01/2009 11:45:25.5 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.542 [GMT 0:00] Running from: c:\documents and settings\Administrator.SARAH\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-06 09:45 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LimeWire 2009-01-05 19:29 --------- d-----w c:\program files\Kick'n'Rush 2006 2009-01-04 18:35 --------- d-----w c:\program files\Wyzo 2009-01-04 01:27 --------- d---a-w c:\program files\QuickTime 2009-01-02 12:26 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-01-02 12:26 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\Malwarebytes 2009-01-02 12:26 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\Malwarebytes 2009-01-01 22:08 --------- d---a-w c:\program files\Spybot - Search & Destroy 2009-01-01 22:08 --------- d---a-w c:\documents and settings\All Users.WINNT\Application Data\Spybot - Search & Destroy 2009-01-01 21:48 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-01 21:48 --------- d-----w c:\program files\LG PC Suite 2009-01-01 21:48 --------- d-----w c:\program files\LG Electronics 2009-01-01 21:47 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LG Electronics 2009-01-01 21:46 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\InstallShield 2008-12-24 13:43 88 ----a-w C:\_dele.bat 2008-12-24 01:02 --------- d---a-w c:\program files\Lavasoft 2008-12-24 01:00 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2008-12-24 00:40 --------- d-----w c:\program files\SpywareBlaster 2008-12-23 22:51 --------- d-----w c:\program files\Trend Micro 2008-12-23 11:58 410,984 ----a-w c:\winnt\system32\deploytk.dll 2008-12-23 11:58 --------- d---a-w c:\program files\Java 2008-12-23 11:52 --------- d---a-w c:\program files\LimeWire 2008-12-22 01:15 309,949 ----a-w c:\winnt\system32\hguest.exe 2008-12-18 18:48 --------- d-----w c:\program files\Football Champions Quiz 2008-12-18 18:47 --------- d-----w c:\program files\Five-A-Side Football 2008-12-16 17:46 85 ----a-w C:\ARP.BAT 2008-12-16 17:46 37 ----a-w C:\bat.bat 2008-12-13 15:49 --------- d-----w c:\program files\Sibelius Software 2008-12-03 19:59 38,496 ----a-w c:\winnt\system32\drivers\mbamswissarmy.sys 2008-12-03 19:59 15,504 ----a-w c:\winnt\system32\drivers\mbam.sys 2008-11-21 18:27 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\WinZip 2008-11-12 10:28 --------- d-----w c:\program files\NOS 2008-11-12 10:28 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\NOS 2008-11-11 16:17 --------- d-----w c:\program files\Common Files\Adobe AIR 2008-11-11 16:16 --------- d---a-w c:\program files\Common Files\Adobe 2008-10-18 20:52 271 ---h--w c:\program files\desktop.ini 2008-10-18 20:52 21,952 ---h--w c:\program files\folder.htt 2008-10-18 00:09 558,142 ----a-w c:\winnt\java\Packages\646JBDNL.ZIP 2008-10-18 00:09 155,995 ----a-w c:\winnt\java\Packages\8EUJ3VB5.ZIP 2006-01-03 22:06 664,161 -c--a-w c:\program files\JuiceUserGuide.pdf 2005-03-10 23:34 84,254 -c--a-w c:\program files\belkin manual.pdf 2000-07-26 17:00 32,528 ----a-w c:\winnt\inf\wbfirdma.sys . ((((((((((((((((((((((((((((( snapshot_Sun 04-01-2009_ 0.07.06.62 ))))))))))))))))))))))))))))))))))))))))) . + 2003-06-19 12:05:04 40,752 -c--a-w c:\winnt\system32\dllcache\1394bus.sys + 1999-10-07 15:29:12 22,992 -c--a-w c:\winnt\system32\dllcache\15_16wdm.sys + 1999-09-24 23:55:14 792,176 -c--a-w c:\winnt\system32\dllcache\3cisaadi.sys + 1999-09-24 23:55:14 774,928 -c--a-w c:\winnt\system32\dllcache\3cisati.sys + 1999-11-01 16:42:08 801,072 -c--a-w c:\winnt\system32\dllcache\3cpciadi.sys + 1999-09-24 23:55:14 763,024 -c--a-w c:\winnt\system32\dllcache\3cwmcru.sys + 2003-06-19 12:05:04 10,928 -c--a-w c:\winnt\system32\dllcache\4mmdat.sys + 1999-12-07 16:43:26 38,320 -c--a-w c:\winnt\system32\dllcache\8514a.dll + 1999-09-24 19:17:26 387,536 -c--a-w c:\winnt\system32\dllcache\a1base.sys + 1999-09-25 11:11:40 23,312 -c--a-w c:\winnt\system32\dllcache\abp480n5.sys + 2003-06-19 11:05:04 150,800 -c--a-w c:\winnt\system32\dllcache\accwiz.exe + 2003-06-19 11:05:04 78,096 -c--a-w c:\winnt\system32\dllcache\aclui.dll + 2003-06-19 11:05:04 163,120 -c--a-w c:\winnt\system32\dllcache\acpi.sys + 2003-06-19 11:05:04 11,536 -c--a-w c:\winnt\system32\dllcache\acpiec.sys + 1999-11-30 23:38:42 91,920 -c--a-w c:\winnt\system32\dllcache\acq32.dll + 2003-06-19 11:05:04 182,032 -c--a-w c:\winnt\system32\dllcache\activeds.dll + 2003-06-19 12:05:04 9,904 -c--a-w c:\winnt\system32\dllcache\adicsc.sys + 2003-06-19 12:05:04 9,968 -c--a-w c:\winnt\system32\dllcache\adicvls.sys + 1999-11-01 16:56:58 596,768 -c--a-w c:\winnt\system32\dllcache\adm8810.sys + 1999-11-01 16:56:58 601,600 -c--a-w c:\winnt\system32\dllcache\adm8820.sys + 1999-11-01 16:56:58 795,456 -c--a-w c:\winnt\system32\dllcache\adm8830.sys + 2003-06-19 11:05:04 28,432 -c--a-w c:\winnt\system32\dllcache\admexs.dll + 2003-03-24 16:52:04 20,540 -c--a-w c:\winnt\system32\dllcache\admin.dll + 2003-03-24 16:52:04 16,439 -c--a-w c:\winnt\system32\dllcache\admin.exe + 1999-10-18 15:03:28 10,560 -c--a-w c:\winnt\system32\dllcache\admjoy.sys + 1999-09-24 19:16:54 36,368 -c--a-w c:\winnt\system32\dllcache\adptsf50.sys + 2003-06-19 12:05:04 64,432 -c--a-w c:\winnt\system32\dllcache\adpu160m.sys + 2003-06-19 11:05:04 52,496 -c--a-w c:\winnt\system32\dllcache\adrot.dll - 2005-01-12 19:39:48 248,080 -c----w c:\winnt\system32\dllcache\adsiis.dll + 2003-06-19 11:05:04 246,544 -c--a-w c:\winnt\system32\dllcache\adsiis.dll + 2003-06-19 11:05:04 164,112 -c--a-w c:\winnt\system32\dllcache\adsnds.dll + 2003-06-19 11:05:04 201,488 -c--a-w c:\winnt\system32\dllcache\adsnt.dll + 2003-06-19 11:05:04 112,400 -c--a-w c:\winnt\system32\dllcache\adsnw.dll + 1999-11-30 23:38:42 7,440 -c--a-w c:\winnt\system32\dllcache\af450.dll + 2003-06-19 12:05:04 21,008 -c--a-w c:\winnt\system32\dllcache\agp440.sys + 2003-06-19 12:05:04 24,176 -c--a-w c:\winnt\system32\dllcache\agpcpq.sys + 1999-09-25 11:11:40 12,336 -c--a-w c:\winnt\system32\dllcache\aha154x.sys + 1999-09-25 11:11:40 95,536 -c--a-w c:\winnt\system32\dllcache\aic116x.sys + 1999-10-18 14:35:14 65,168 -c--a-w c:\winnt\system32\dllcache\aic78u2.sys + 2000-07-26 17:00:00 56,848 -c--a-w c:\winnt\system32\dllcache\aic78xx.sys + 1999-09-24 19:18:02 41,744 -c--a-w c:\winnt\system32\dllcache\alifir.sys + 1999-10-08 14:58:32 21,168 -c--a-w c:\winnt\system32\dllcache\alim1541.sys + 1999-10-07 15:32:00 3,056 -c--a-w c:\winnt\system32\dllcache\alsfm.sys + 1999-10-07 15:32:00 16,240 -c--a-w c:\winnt\system32\dllcache\alswdm.sys + 2003-06-19 12:05:04 597,776 -c--a-w c:\winnt\system32\dllcache\altnd5.sys + 1999-09-24 19:16:56 17,168 -c--a-w c:\winnt\system32\dllcache\amb8002.sys + 1999-09-24 19:16:56 55,056 -c--a-w c:\winnt\system32\dllcache\ambcbl.sys + 1999-09-28 15:37:34 22,064 -c--a-w c:\winnt\system32\dllcache\amd751.sys + 1999-09-25 11:11:40 11,824 -c--a-w c:\winnt\system32\dllcache\amsint.sys + 1999-09-25 10:36:48 6,320 -c--a-w c:\winnt\system32\dllcache\apmbatt.sys + 2003-06-19 11:05:04 120,592 -c--a-w c:\winnt\system32\dllcache\appmgmts.dll + 2003-06-19 11:05:04 224,016 -c--a-w c:\winnt\system32\dllcache\appmgr.dll + 1999-10-21 11:34:08 6,544 -c--a-w c:\winnt\system32\dllcache\archqic.sys + 1999-09-25 11:11:40 26,384 -c--a-w c:\winnt\system32\dllcache\asc.sys + 1999-09-25 11:11:40 22,256 -c--a-w c:\winnt\system32\dllcache\asc3350p.sys + 1999-09-25 11:11:40 14,576 -c--a-w c:\winnt\system32\dllcache\asc3550.sys - 2005-04-08 11:54:36 356,624 -c----w c:\winnt\system32\dllcache\ASP.DLL + 2003-06-19 11:05:04 338,704 -c--a-w c:\winnt\system32\dllcache\asp.dll + 1999-09-24 19:17:12 97,552 -c--a-w c:\winnt\system32\dllcache\aspndis3.sys + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\aspperf.dll + 2003-06-19 11:05:04 30,480 -c--a-w c:\winnt\system32\dllcache\asptxn.dll + 2003-06-19 11:05:04 143,632 -c--a-w c:\winnt\system32\dllcache\asycfilt.dll + 2003-06-19 11:05:04 17,840 -c--a-w c:\winnt\system32\dllcache\asyncmac.sys + 2003-06-19 11:05:04 23,824 -c--a-w c:\winnt\system32\dllcache\at.exe + 2003-06-19 11:05:04 86,672 -c--a-w c:\winnt\system32\dllcache\atapi.sys + 1999-12-07 16:43:28 96,112 -c--a-w c:\winnt\system32\dllcache\ati.dll + 1999-09-25 10:36:54 77,648 -c--a-w c:\winnt\system32\dllcache\ati.sys + 1999-12-07 16:43:28 139,952 -c--a-w c:\winnt\system32\dllcache\ati2draa.dll + 1999-10-27 15:11:44 250,896 -c--a-w c:\winnt\system32\dllcache\ati2mpaa.sys + 1999-10-21 15:09:46 42,192 -c--a-w c:\winnt\system32\dllcache\atibt829.sys + 1999-12-07 16:43:28 135,184 -c--a-w c:\winnt\system32\dllcache\atidrab.dll + 1999-11-10 15:34:08 71,632 -c--a-w c:\winnt\system32\dllcache\atimpab.sys + 1999-12-07 16:43:28 140,080 -c--a-w c:\winnt\system32\dllcache\atiraged.dll + 1999-11-05 15:43:14 70,352 -c--a-w c:\winnt\system32\dllcache\atiragem.sys + 1999-10-21 15:09:46 17,968 -c--a-w c:\winnt\system32\dllcache\atitunep.sys + 1999-10-21 15:09:46 16,976 -c--a-w c:\winnt\system32\dllcache\atitvsnd.sys + 1999-10-21 15:09:46 19,792 -c--a-w c:\winnt\system32\dllcache\atixbar.sys + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\atkctrs.dll + 2003-06-19 11:05:04 74,810 -c--a-w c:\winnt\system32\dllcache\atl.dll + 2003-06-19 12:05:04 9,424 -c--a-w c:\winnt\system32\dllcache\atlmc.sys + 2003-06-19 11:05:04 291,888 -c--a-w c:\winnt\system32\dllcache\atmfd.dll + 2003-06-19 11:05:04 48,496 -c--a-w c:\winnt\system32\dllcache\atmlane.sys + 2003-06-19 11:05:04 31,504 -c--a-w c:\winnt\system32\dllcache\atmlib.dll + 2003-06-19 11:05:04 331,088 -c--a-w c:\winnt\system32\dllcache\atmuni.sys + 1999-09-25 10:35:34 2,896 -c--a-w c:\winnt\system32\dllcache\audstub.sys + 2003-06-19 11:05:04 11,024 -c--a-w c:\winnt\system32\dllcache\authfilt.dll + 2003-03-24 16:52:04 20,540 -c--a-w c:\winnt\system32\dllcache\author.dll + 2003-03-24 16:52:04 16,439 -c--a-w c:\winnt\system32\dllcache\author.exe + 2003-06-19 11:05:04 589,072 -c--a-w c:\winnt\system32\dllcache\autoconv.exe + 2003-06-19 11:05:04 568,592 -c--a-w c:\winnt\system32\dllcache\autofmt.exe + 2003-06-19 11:05:04 8,976 -c--a-w c:\winnt\system32\dllcache\autolfn.exe + 2003-06-19 11:05:04 78,608 -c--a-w c:\winnt\system32\dllcache\avifil32.dll + 1999-11-30 23:38:44 62,224 -c--a-w c:\winnt\system32\dllcache\avmcoins.dll + 1999-10-19 14:27:30 29,968 -c--a-w c:\winnt\system32\dllcache\avmwan.sys + 2003-06-19 11:05:04 226,576 -c--a-w c:\winnt\system32\dllcache\avtapi.dll + 1999-10-07 15:35:20 33,168 -c--a-w c:\winnt\system32\dllcache\aztw2316.sys + 1999-10-07 15:35:20 36,368 -c--a-w c:\winnt\system32\dllcache\aztw2320.sys + 1999-10-07 15:35:20 43,472 -c--a-w c:\winnt\system32\dllcache\aztw3328.sys + 1999-09-24 19:17:28 63,088 -c--a-w c:\winnt\system32\dllcache\b1cbase.sys + 1999-12-07 16:43:28 257,264 -c--a-w c:\winnt\system32\dllcache\banshee.dll + 1999-10-29 15:00:58 38,928 -c--a-w c:\winnt\system32\dllcache\banshee.sys + 2003-06-19 11:05:04 20,752 -c--a-w c:\winnt\system32\dllcache\batmeter.dll + 2003-06-19 12:05:04 7,184 -c--a-w c:\winnt\system32\dllcache\battc.sys + 2003-06-19 12:05:04 9,392 -c--a-w c:\winnt\system32\dllcache\breecemc.sys + 2003-06-19 11:05:04 47,376 -c--a-w c:\winnt\system32\dllcache\browscap.dll + 1999-10-12 15:35:48 31,888 -c--a-w c:\winnt\system32\dllcache\brzwlan.sys + 1999-09-25 10:36:34 14,096 -c--a-w c:\winnt\system32\dllcache\bulltlp3.sys + 1999-09-25 11:11:42 38,992 -c--a-w c:\winnt\system32\dllcache\buslogic.sys + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\c_is2022.dll + 1999-09-24 19:17:22 40,208 -c--a-w c:\winnt\system32\dllcache\c20n5.sys + 1999-09-24 19:17:26 25,360 -c--a-w c:\winnt\system32\dllcache\c21n5.sys + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\cacls.exe + 2003-06-19 11:05:04 127,760 -c--a-w c:\winnt\system32\dllcache\capesnpn.dll + 1999-09-30 15:03:56 39,680 -c--a-w c:\winnt\system32\dllcache\cb325.sys + 1999-09-24 19:17:22 40,208 -c--a-w c:\winnt\system32\dllcache\cben5.sys + 1999-10-04 11:40:48 13,232 -c--a-w c:\winnt\system32\dllcache\ccdecode.sys + 1999-09-25 11:11:44 7,568 -c--a-w c:\winnt\system32\dllcache\cd20xrnt.sys + 2000-07-26 17:00:00 19,088 -c--a-w c:\winnt\system32\dllcache\cdaudio.sys + 2003-06-19 11:05:04 402,704 -c--a-w c:\winnt\system32\dllcache\cdonts.dll + 2003-06-19 11:05:04 27,984 -c--a-w c:\winnt\system32\dllcache\cdrom.sys + 1999-09-24 19:17:22 21,776 -c--a-w c:\winnt\system32\dllcache\ce2n5.sys + 1999-09-24 19:17:24 27,408 -c--a-w c:\winnt\system32\dllcache\ce3n5.sys + 1999-09-24 19:17:22 22,288 -c--a-w c:\winnt\system32\dllcache\cem28n5.sys + 1999-09-24 19:17:24 22,288 -c--a-w c:\winnt\system32\dllcache\cem33n5.sys + 1999-09-24 19:17:24 25,360 -c--a-w c:\winnt\system32\dllcache\cem56n5.sys + 2003-06-19 11:05:04 135,440 -c--a-w c:\winnt\system32\dllcache\certcli.dll + 2003-06-19 11:05:04 422,160 -c--a-w c:\winnt\system32\dllcache\certmgr.dll + 2003-03-24 16:52:04 188,480 -c--a-w c:\winnt\system32\dllcache\cfgwiz.exe + 1999-09-27 19:29:58 7,536 -c--a-w c:\winnt\system32\dllcache\changer.sys + 1999-12-07 16:43:28 84,688 -c--a-w c:\winnt\system32\dllcache\chipsd5.dll + 1999-09-25 10:36:56 34,032 -c--a-w c:\winnt\system32\dllcache\chipsm5.sys + 2003-06-19 11:05:04 13,072 -c--a-w c:\winnt\system32\dllcache\chkntfs.exe + 2003-06-19 11:05:04 156,944 -c--a-w c:\winnt\system32\dllcache\ciadmin.dll + 2003-06-19 11:05:04 1,089,637 -c--a-w c:\winnt\system32\dllcache\cimwin32.dll + 1999-09-25 10:36:02 282,864 -c--a-w c:\winnt\system32\dllcache\cinemclc.sys + 2000-07-26 17:00:00 272,496 -c--a-w c:\winnt\system32\dllcache\cinemst2.sys + 2003-06-19 11:05:04 36,112 -c--a-w c:\winnt\system32\dllcache\cipher.exe + 1999-12-07 16:43:28 89,840 -c--a-w c:\winnt\system32\dllcache\cirrus.dll + 1999-10-08 15:31:02 45,744 -c--a-w c:\winnt\system32\dllcache\cirrus.sys + 1999-12-07 16:43:28 115,568 -c--a-w c:\winnt\system32\dllcache\cl5465.dll + 1999-12-07 16:43:28 175,728 -c--a-w c:\winnt\system32\dllcache\cl546x.dll + 1999-09-25 10:37:06 248,272 -c--a-w c:\winnt\system32\dllcache\cl546xm.sys + 2003-06-19 11:05:04 34,832 -c--a-w c:\winnt\system32\dllcache\classpnp.sys + 2003-06-19 11:05:04 55,568 -c--a-w c:\winnt\system32\dllcache\clusapi.dll + 2003-06-19 11:05:04 130,832 -c--a-w c:\winnt\system32\dllcache\cluster.exe + 2003-06-19 12:05:04 9,904 -c--a-w c:\winnt\system32\dllcache\cmbatt.sys + 2003-06-19 11:05:04 193,808 -c--a-w c:\winnt\system32\dllcache\cmdial32.dll + 2003-06-19 11:05:04 82,704 -c--a-w c:\winnt\system32\dllcache\cmnquery.dll + 2003-06-19 11:05:04 159,807 -c--a-w c:\winnt\system32\dllcache\cmprops.dll + 2003-06-19 11:05:04 45,328 -c--a-w c:\winnt\system32\dllcache\cmstp.exe + 2003-06-19 11:05:04 22,288 -c--a-w c:\winnt\system32\dllcache\cmutil.dll + 2000-07-26 17:00:00 44,816 -c--a-w c:\winnt\system32\dllcache\cnbjmon.dll + 1999-11-30 23:38:48 24,848 -c--a-w c:\winnt\system32\dllcache\cnusd.dll + 2003-06-19 11:05:04 26,384 -c--a-w c:\winnt\system32\dllcache\cnvfat.dll + 2003-06-19 11:05:04 40,720 -c--a-w c:\winnt\system32\dllcache\coadmin.dll + 2003-06-19 11:05:04 3,856 -c--a-w c:\winnt\system32\dllcache\comcat.dll + 2003-06-19 11:05:04 241,424 -c--a-w c:\winnt\system32\dllcache\comdlg32.dll + 2003-06-19 12:05:04 9,264 -c--a-w c:\winnt\system32\dllcache\compbatt.sys + 2003-06-19 11:05:04 23,312 -c--a-w c:\winnt\system32\dllcache\compfilt.dll + 2003-06-19 11:05:04 659,728 -c--a-w c:\winnt\system32\dllcache\conf.exe + 2003-06-19 11:05:04 219,920 -c--a-w c:\winnt\system32\dllcache\confmsp.dll + 2003-06-19 11:05:04 25,872 -c--a-w c:\winnt\system32\dllcache\conime.exe + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\control.exe + 2003-06-19 11:05:04 36,112 -c--a-w c:\winnt\system32\dllcache\controt.dll + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\convert.exe + 2003-06-19 11:05:04 67,856 -c--a-w c:\winnt\system32\dllcache\convlog.exe + 2003-06-19 11:05:04 21,264 -c--a-w c:\winnt\system32\dllcache\counters.dll + 2003-06-19 11:05:04 27,097 -c--a-w c:\winnt\system32\dllcache\country.sys + 1999-09-24 19:17:24 25,360 -c--a-w c:\winnt\system32\dllcache\cpq550n5.sys + 2003-06-19 12:05:04 10,992 -c--a-w c:\winnt\system32\dllcache\cpqarray.sys + 1999-10-01 15:47:58 13,424 -c--a-w c:\winnt\system32\dllcache\cpqarry2.sys + 1999-09-24 19:17:24 27,408 -c--a-w c:\winnt\system32\dllcache\cpqepc.sys + 1999-09-25 11:11:50 58,352 -c--a-w c:\winnt\system32\dllcache\cpqfcalm.sys + 1999-09-25 11:11:50 43,184 -c--a-w c:\winnt\system32\dllcache\cpqfws2e.sys + 1999-09-24 19:17:22 21,776 -c--a-w c:\winnt\system32\dllcache\cpqndis5.sys + 1999-09-24 19:16:58 107,376 -c--a-w c:\winnt\system32\dllcache\cpqtrnd4.sys + 1999-09-24 19:16:58 61,072 -c--a-w c:\winnt\system32\dllcache\cpqtrnd5.sys + 2003-06-19 11:05:04 44,304 -c--a-w c:\winnt\system32\dllcache\cryptdll.dll + 1999-11-30 23:38:50 125,200 -c--a-w c:\winnt\system32\dllcache\csamsp.dll + 2003-06-19 11:05:04 65,593 -c--a-w c:\winnt\system32\dllcache\csapi3t1.dll + 2003-06-19 11:05:04 101,136 -c--a-w c:\winnt\system32\dllcache\cscdll.dll + 2003-06-19 11:05:04 242,960 -c--a-w c:\winnt\system32\dllcache\cscui.dll + 2003-06-19 11:05:04 5,392 -c--a-w c:\winnt\system32\dllcache\csrss.exe + 1999-12-07 16:43:30 93,456 -c--a-w c:\winnt\system32\dllcache\ctlegacy.dll + 1999-09-24 18:53:24 28,848 -c--a-w c:\winnt\system32\dllcache\ctlegacy.sys + 1999-10-07 15:38:10 4,128 -c--a-w c:\winnt\system32\dllcache\ctljystk.sys + 1999-10-23 13:10:34 141,904 -c--a-w c:\winnt\system32\dllcache\ctlsb16.sys + 1999-11-30 23:38:50 248,080 -c--a-w c:\winnt\system32\dllcache\ctmasetp.dll + 1999-11-30 23:38:50 12,560 -c--a-w c:\winnt\system32\dllcache\ctmrclas.dll + 1999-11-30 23:38:50 12,560 -c--a-w c:\winnt\system32\dllcache\ctmvclas.dll + 1999-10-08 13:31:52 3,104 -c--a-w c:\winnt\system32\dllcache\cwbase.sys + 1999-10-08 13:32:08 3,136 -c--a-w c:\winnt\system32\dllcache\cwbmidi.sys + 1999-11-01 22:10:56 79,264 -c--a-w c:\winnt\system32\dllcache\cwbwdm.sys + 1999-11-11 15:13:44 3,344 -c--a-w c:\winnt\system32\dllcache\cwcosnt5.sys + 1999-11-11 15:13:44 103,120 -c--a-w c:\winnt\system32\dllcache\cwcspud.sys + 1999-11-11 15:13:44 19,056 -c--a-w c:\winnt\system32\dllcache\cwcspud3.sys + 1999-11-11 15:13:44 67,440 -c--a-w c:\winnt\system32\dllcache\cwcwdm.sys + 1999-11-30 11:19:12 14,672 -c--a-w c:\winnt\system32\dllcache\dac960nt.sys + 2003-06-19 11:05:04 163,088 -c--a-w c:\winnt\system32\dllcache\dbghelp.dll + 1999-11-30 23:38:50 397,072 -c--a-w c:\winnt\system32\dllcache\dc120.dll + 1999-11-30 23:38:50 21,776 -c--a-w c:\winnt\system32\dllcache\dc120usd.dll + 1999-11-30 23:38:50 22,288 -c--a-w c:\winnt\system32\dllcache\dc200usd.dll + 1999-11-30 23:38:50 64,784 -c--a-w c:\winnt\system32\dllcache\dc210_32.dll + 1999-10-17 12:18:04 64,880 -c--a-w c:\winnt\system32\dllcache\dc21x4.sys + 2003-06-19 11:05:04 113,936 -c--a-w c:\winnt\system32\dllcache\dcomcnfg.exe + 2003-06-19 12:05:04 9,680 -c--a-w c:\winnt\system32\dllcache\ddsmc.sys + 1999-09-30 15:25:28 29,232 -c--a-w c:\winnt\system32\dllcache\defea.sys + 1999-10-04 14:06:42 21,360 -c--a-w c:\winnt\system32\dllcache\defpa.sys + 2003-06-19 11:05:04 221,968 -c--a-w c:\winnt\system32\dllcache\devmgr.dll + 2003-06-19 11:05:04 62,224 -c--a-w c:\winnt\system32\dllcache\dfrgfat.exe + 2003-06-19 11:05:04 76,048 -c--a-w c:\winnt\system32\dllcache\dfrgntfs.exe + 2003-06-19 11:05:04 42,768 -c--a-w c:\winnt\system32\dllcache\dfrgsnap.dll + 2003-06-19 11:05:04 22,800 -c--a-w c:\winnt\system32\dllcache\dfsshlex.dll + 1999-11-05 13:40:02 29,552 -c--a-w c:\winnt\system32\dllcache\dgapci.sys + 1999-09-30 21:28:52 25,840 -c--a-w c:\winnt\system32\dllcache\dgavnstr.sys + 1999-11-30 23:38:52 426,256 -c--a-w c:\winnt\system32\dllcache\dgconfig.dll + 2003-06-19 11:05:04 306,448 -c--a-w c:\winnt\system32\dllcache\dhcpmon.dll + 2003-06-19 11:05:04 75,536 -c--a-w c:\winnt\system32\dllcache\dhcpsapi.dll + 1999-11-30 23:38:52 107,280 -c--a-w c:\winnt\system32\dllcache\digidbp.dll + 1999-11-18 13:49:22 92,784 -c--a-w c:\winnt\system32\dllcache\digidxb.sys + 1999-09-30 21:28:54 90,384 -c--a-w c:\winnt\system32\dllcache\digifep5.sys + 1999-11-30 23:38:52 203,024 -c--a-w c:\winnt\system32\dllcache\digifwrk.dll + 1999-11-30 23:38:52 61,712 -c--a-w c:\winnt\system32\dllcache\digihlc.dll + 1999-11-30 23:38:52 52,496 -c--a-w c:\winnt\system32\dllcache\digiinf.dll + 1999-11-30 23:38:52 27,408 -c--a-w c:\winnt\system32\dllcache\digiisdn.dll + 1999-11-18 13:49:22 21,296 -c--a-w c:\winnt\system32\dllcache\digiisdn.sys + 1999-09-24 19:17:42 20,784 -c--a-w c:\winnt\system32\dllcache\digilan.sys + 1999-11-30 23:38:52 261,120 -c--a-w c:\winnt\system32\dllcache\digirlpt.dll + 1999-09-24 19:17:40 69,392 -c--a-w c:\winnt\system32\dllcache\digirlpt.sys + 1999-09-24 19:17:42 48,368 -c--a-w c:\winnt\system32\dllcache\digisxb.sys + 1999-11-30 23:40:00 598,800 -c--a-w c:\winnt\system32\dllcache\digiview.exe + 1999-09-24 19:17:42 34,096 -c--a-w c:\winnt\system32\dllcache\digiwanx.sys + 1999-10-12 14:34:42 68,400 -c--a-w c:\winnt\system32\dllcache\dimaint.sys + 2003-06-19 11:05:04 134,416 -c--a-w c:\winnt\system32\dllcache\dinput.dll + 2003-06-19 12:05:04 10,448 -c--a-w c:\winnt\system32\dllcache\discmc.sys + 1999-09-30 21:29:00 6,928 -c--a-w c:\winnt\system32\dllcache\disdnci.dll + 1999-09-30 21:29:00 220,944 -c--a-w c:\winnt\system32\dllcache\disdnsu.dll + 2003-06-19 11:05:04 30,768 -c--a-w c:\winnt\system32\dllcache\disk.sys + 2003-06-19 11:05:04 16,144 -c--a-w c:\winnt\system32\dllcache\diskcopy.dll + 2003-06-19 11:05:04 14,288 -c--a-w c:\winnt\system32\dllcache\diskdump.sys + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\diskperf.exe + 2003-06-19 11:05:04 7,728 -c--a-w c:\winnt\system32\dllcache\diskperf.sys + 1999-11-30 23:40:02 250,640 -c--a-w c:\winnt\system32\dllcache\ditrace.exe + 1999-11-08 16:48:50 612,976 -c--a-w c:\winnt\system32\dllcache\diwan.sys + 2003-06-19 11:05:04 56,112 -c--a-w c:\winnt\system32\dllcache\dlc.sys + 1999-09-24 19:17:00 23,216 -c--a-w c:\winnt\system32\dllcache\dlh5xnd5.sys + 2003-06-19 11:05:04 5,904 -c--a-w c:\winnt\system32\dllcache\dllhost.exe + 2003-06-19 11:05:04 5,904 -c--a-w c:\winnt\system32\dllcache\dllhst3g.exe + 2003-06-19 12:05:04 6,608 -c--a-w c:\winnt\system32\dllcache\dlttape.sys + 2003-06-19 11:05:04 147,728 -c--a-w c:\winnt\system32\dllcache\dmadmin.exe + 2003-06-19 11:05:04 369,104 -c--a-w c:\winnt\system32\dllcache\dmboot.sys + 2003-06-19 11:05:04 316,176 -c--a-w c:\winnt\system32\dllcache\dmconfig.dll + 2003-06-19 11:05:04 174,864 -c--a-w c:\winnt\system32\dllcache\dmdlgs.dll + 2003-06-19 11:05:04 163,600 -c--a-w c:\winnt\system32\dllcache\dmdskmgr.dll + 2003-06-19 11:05:04 122,368 -c--a-w c:\winnt\system32\dllcache\dmdskres.dll + 2003-06-19 11:05:04 13,072 -c--a-w c:\winnt\system32\dllcache\dmintf.dll + 2003-06-19 11:05:04 137,936 -c--a-w c:\winnt\system32\dllcache\dmio.sys + 2003-06-19 11:05:04 7,312 -c--a-w c:\winnt\system32\dllcache\dmload.sys + 2003-06-19 11:05:04 10,512 -c--a-w c:\winnt\system32\dllcache\dmremote.exe + 2003-06-19 11:05:04 12,048 -c--a-w c:\winnt\system32\dllcache\dmserver.dll + 1999-10-28 15:24:20 51,152 -c--a-w c:\winnt\system32\dllcache\dmusic.sys + 2003-06-19 11:05:04 43,280 -c--a-w c:\winnt\system32\dllcache\dmutil.dll + 2003-06-19 12:05:04 44,208 -c--a-w c:\winnt\system32\dllcache\dot4.sys + 2003-06-19 12:05:04 12,688 -c--a-w c:\winnt\system32\dllcache\dot4prt.sys + 1999-09-25 10:34:46 8,752 -c--a-w c:\winnt\system32\dllcache\dot4scan.sys + 1999-11-30 23:38:54 7,440 -c--a-w c:\winnt\system32\dllcache\dr3020.dll + 2003-06-19 11:05:04 72,464 -c--a-w c:\winnt\system32\dllcache\drwtsn32.exe + 1999-11-06 14:06:58 358,928 -c--a-w c:\winnt\system32\dllcache\ds1wdm.sys + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\ds32gt.dll + 2003-06-19 11:05:04 74,512 -c--a-w c:\winnt\system32\dllcache\dsauth.dll + 2003-06-19 11:05:04 41,744 -c--a-w c:\winnt\system32\dllcache\dsfolder.dll + 2003-06-19 11:05:04 92,944 -c--a-w c:\winnt\system32\dllcache\dskquota.dll + 2003-06-19 11:05:04 146,192 -c--a-w c:\winnt\system32\dllcache\dskquoui.dll + 1999-11-30 23:38:56 13,072 -c--a-w c:\winnt\system32\dllcache\dspimg32.dll + 2003-06-19 11:05:04 157,456 -c--a-w c:\winnt\system32\dllcache\dsquery.dll + 2003-06-19 11:05:04 145,680 -c--a-w c:\winnt\system32\dllcache\dssbase.dll + 2003-06-19 11:05:04 28,944 -c--a-w c:\winnt\system32\dllcache\dssec.dll + 2003-06-19 11:05:04 147,216 -c--a-w c:\winnt\system32\dllcache\dssenh.dll + 2003-06-19 11:05:04 110,864 -c--a-w c:\winnt\system32\dllcache\dsuiext.dll + 2000-07-26 17:00:00 120,592 -c--a-w c:\winnt\system32\dllcache\dvdplay.exe + 1999-11-30 23:38:56 16,656 -c--a-w c:\winnt\system32\dllcache\dvusd.dll + 2003-06-19 11:05:04 425,232 -c--a-w c:\winnt\system32\dllcache\dxdiag.exe + 2003-06-19 11:05:04 265,488 -c--a-w c:\winnt\system32\dllcache\dxmrtp.dll + 1999-09-24 19:17:06 21,264 -c--a-w c:\winnt\system32\dllcache\e100.sys + 1999-10-06 15:52:50 35,600 -c--a-w c:\winnt\system32\dllcache\e1000nt5.sys + 2003-06-19 12:05:04 85,776 -c--a-w c:\winnt\system32\dllcache\e100bnt5.sys + 1999-10-14 16:57:22 19,824 -c--a-w c:\winnt\system32\dllcache\e100isa4.sys + 1999-09-30 15:03:46 51,472 -c--a-w c:\winnt\system32\dllcache\e100snt5.sys + 1999-09-30 21:28:00 100,432 -c--a-w c:\winnt\system32\dllcache\eccommdd.sys + 1999-09-30 21:28:02 7,648 -c--a-w c:\winnt\system32\dllcache\ecdtrace.sys + 1999-09-30 21:28:02 23,664 -c--a-w c:\winnt\system32\dllcache\eclandd.sys + 1999-09-30 21:28:02 38,464 -c--a-w c:\winnt\system32\dllcache\ecnb.sys + 1999-09-30 21:28:02 133,200 -c--a-w c:\winnt\system32\dllcache\ecndis.sys + 1999-11-30 23:38:58 33,792 -c--a-w c:\winnt\system32\dllcache\ecpagex.dll + 1999-11-30 23:38:58 21,680 -c--a-w c:\winnt\system32\dllcache\ecpinst.dll + 1999-09-30 21:28:02 8,960 -c--a-w c:\winnt\system32\dllcache\ecsnadd.sys + 1999-09-30 21:28:02 7,648 -c--a-w c:\winnt\system32\dllcache\ecvbus.sys + 1999-09-30 21:28:02 70,784 -c--a-w c:\winnt\system32\dllcache\ecwan.sys + 1999-09-30 21:28:02 17,856 -c--a-w c:\winnt\system32\dllcache\ecwandd.sys + 1999-09-30 21:28:02 70,784 -c--a-w c:\winnt\system32\dllcache\ecwani.sys + 2003-06-19 11:05:04 27,440 -c--a-w c:\winnt\system32\dllcache\efs.sys + 1999-09-24 19:16:50 45,840 -c--a-w c:\winnt\system32\dllcache\el515.sys + 1999-09-24 19:16:50 21,264 -c--a-w c:\winnt\system32\dllcache\el562nd4.sys + 1999-09-24 19:16:52 24,848 -c--a-w c:\winnt\system32\dllcache\el574nd4.sys + 1999-10-19 14:50:42 77,072 -c--a-w c:\winnt\system32\dllcache\el575nd5.sys + 1999-09-24 19:16:50 26,384 -c--a-w c:\winnt\system32\dllcache\el589nd5.sys + 1999-09-24 19:16:52 39,184 -c--a-w c:\winnt\system32\dllcache\el59x.sys + 1999-09-24 23:55:16 469,072 -c--a-w c:\winnt\system32\dllcache\el656ct5.sys + 1999-09-24 19:16:52 75,536 -c--a-w c:\winnt\system32\dllcache\el656nd5.sys + 1999-09-24 23:55:16 72,304 -c--a-w c:\winnt\system32\dllcache\el656se5.sys + 1999-10-23 11:22:20 61,712 -c--a-w c:\winnt\system32\dllcache\el90xbc5.sys + 1999-11-01 16:43:48 78,096 -c--a-w c:\winnt\system32\dllcache\el90xnd5.sys + 1999-11-01 16:48:10 61,712 -c--a-w c:\winnt\system32\dllcache\el980n5.sys + 2003-06-19 12:05:04 9,776 -c--a-w c:\winnt\system32\dllcache\elmsmc.sys + 1999-09-24 19:16:50 37,136 -c--a-w c:\winnt\system32\dllcache\elnk3.sys + 2003-06-19 11:05:04 157,968 -c--a-w c:\winnt\system32\dllcache\els.dll + 1999-09-24 19:16:52 20,240 -c--a-w c:\winnt\system32\dllcache\em556n4.sys + 1999-10-15 14:35:04 214,848 -c--a-w c:\winnt\system32\dllcache\emu10k1.sys + 1999-09-24 19:17:24 27,408 -c--a-w c:\winnt\system32\dllcache\en22265.sys + 2003-06-19 11:05:04 24,336 -c--a-w c:\winnt\system32\dllcache\encinst.exe + 1999-09-24 19:17:24 27,408 -c--a-w c:\winnt\system32\dllcache\enet5.sys + 1999-09-24 19:17:00 51,152 -c--a-w c:\winnt\system32\dllcache\eni25p.sys + 1999-09-24 19:17:06 18,704 -c--a-w c:\winnt\system32\dllcache\epro4.sys + 1999-09-24 19:17:48 466,864 -c--a-w c:\winnt\system32\dllcache\eqn.sys + 1999-11-30 23:40:02 44,816 -c--a-w c:\winnt\system32\dllcache\eqndiag.exe + 1999-11-30 23:40:02 42,256 -c--a-w c:\winnt\system32\dllcache\eqnlogr.exe + 1999-11-30 23:40:02 54,032 -c--a-w c:\winnt\system32\dllcache\eqnloop.exe + 1999-11-12 16:12:34 41,328 -c--a-w c:\winnt\system32\dllcache\es1370mp.sys + 1999-11-06 10:11:56 44,528 -c--a-w c:\winnt\system32\dllcache\es1371mp.sys + 1999-09-30 16:47:46 227,120 -c--a-w c:\winnt\system32\dllcache\es56pci.sys + 2003-06-19 11:05:04 1,135,376 -c--a-w c:\winnt\system32\dllcache\esent.dll + 2003-06-19 11:05:04 55,568 -c--a-w c:\winnt\system32\dllcache\esentutl.exe + 1999-09-30 17:26:14 64,144 -c--a-w c:\winnt\system32\dllcache\ess.sys + 1999-11-05 15:55:46 156,496 -c--a-w c:\winnt\system32\dllcache\essm2e.sys + 1999-09-24 19:17:08 13,584 -c--a-w c:\winnt\system32\dllcache\et32nt.sys + 1999-09-25 10:36:58 25,840 -c--a-w c:\winnt\system32\dllcache\et4000.sys + 2003-06-19 11:05:04 187,152 -c--a-w c:\winnt\system32\dllcache\eudcedit.exe + 2003-06-19 11:05:04 98,576 -c--a-w c:\winnt\system32\dllcache\evntagnt.dll + 2003-06-19 11:05:04 90,384 -c--a-w c:\winnt\system32\dllcache\evntwin.exe + 1999-09-24 19:17:06 17,200 -c--a-w c:\winnt\system32\dllcache\ex10.sys + 1999-10-21 11:34:08 4,880 -c--a-w c:\winnt\system32\dllcache\exabyte1.sys + 1999-10-21 11:34:08 6,320 -c--a-w c:\winnt\system32\dllcache\exabyte2.sys + 2003-06-19 12:05:04 11,856 -c--a-w c:\winnt\system32\dllcache\examc.sys + 2003-06-19 11:05:04 243,472 -c--a-w c:\winnt\system32\dllcache\explorer.exe + 1999-09-24 19:17:00 12,048 -c--a-w c:\winnt\system32\dllcache\f3ab18xi.sys + 1999-09-24 19:17:00 11,536 -c--a-w c:\winnt\system32\dllcache\f3ab18xj.sys + 2003-06-19 11:05:04 155,749 -c--a-w c:\winnt\system32\dllcache\fastprox.dll + 2003-06-19 11:05:04 92,944 -c--a-w c:\winnt\system32\dllcache\faxadmin.dll + 2003-06-19 11:05:04 80,144 -c--a-w c:\winnt\system32\dllcache\faxcom.dll + 2003-06-19 11:05:04 15,120 -c--a-w c:\winnt\system32\dllcache\faxdrv.dll + 2003-06-19 11:05:04 94,992 -c--a-w c:\winnt\system32\dllcache\faxsvc.exe + 2003-06-19 11:05:04 185,616 -c--a-w c:\winnt\system32\dllcache\faxt30.dll - 2005-01-12 19:39:50 138,000 -c----w c:\winnt\system32\dllcache\faxui.dll + 2005-07-13 07:22:02 138,000 -c--a-w c:\winnt\system32\dllcache\faxui.dll + 1999-09-24 19:17:28 387,536 -c--a-w c:\winnt\system32\dllcache\fbase.sys + 1999-11-30 23:39:02 161,040 -c--a-w c:\winnt\system32\dllcache\fcpatwc.dll + 1999-09-25 11:11:42 11,280 -c--a-w c:\winnt\system32\dllcache\fd16_700.sys + 2003-06-19 11:05:04 26,256 -c--a-w c:\winnt\system32\dllcache\fdc.sys + 2003-06-19 11:05:04 50,448 -c--a-w c:\winnt\system32\dllcache\fdeploy.dll + 1999-09-24 19:16:52 21,776 -c--a-w c:\winnt\system32\dllcache\fem556n5.sys + 1999-09-24 19:17:20 21,264 -c--a-w c:\winnt\system32\dllcache\fetnd5.sys + 2003-06-19 11:05:04 294,672 -c--a-w c:\winnt\system32\dllcache\filemgmt.dll + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\find.exe + 2003-06-19 11:05:04 25,872 -c--a-w c:\winnt\system32\dllcache\findstr.exe + 2003-06-19 11:05:04 33,616 -c--a-w c:\winnt\system32\dllcache\fips.sys + 1999-10-27 14:58:16 22,416 -c--a-w c:\winnt\system32\dllcache\fireport.sys + 1999-11-30 23:39:02 10,000 -c--a-w c:\winnt\system32\dllcache\fjtwusd.dll + 1999-09-25 11:11:50 76,912 -c--a-w c:\winnt\system32\dllcache\flashpnt.sys + 2003-06-19 11:05:04 19,312 -c--a-w c:\winnt\system32\dllcache\flpydisk.sys + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\fmifs.dll + 1999-11-30 23:39:02 74,000 -c--a-w c:\winnt\system32\dllcache\fnfilter.dll + 1999-10-06 16:17:30 21,008 -c--a-w c:\winnt\system32\dllcache\foghorn.sys + 2003-06-19 11:05:04 200,976 -c--a-w c:\winnt\system32\dllcache\fontext.dll + 1999-11-05 15:19:34 32,528 -c--a-w c:\winnt\system32\dllcache\forehe.sys + 2003-06-19 11:05:04 15,120 -c--a-w c:\winnt\system32\dllcache\fortutil.exe + 2003-03-24 16:52:04 184,435 -c--a-w c:\winnt\system32\dllcache\fp4amsft.dll + 2003-03-24 16:52:04 82,035 -c--a-w c:\winnt\system32\dllcache\fp4anscp.dll + 2003-03-24 16:52:04 147,513 -c--a-w c:\winnt\system32\dllcache\fp4apws.dll + 2003-03-24 16:52:04 49,210 -c--a-w c:\winnt\system32\dllcache\fp4areg.dll + 2003-03-24 16:52:04 102,509 -c--a-w c:\winnt\system32\dllcache\fp4atxt.dll + 2003-06-19 19:05:04 618,605 -c--a-w c:\winnt\system32\dllcache\fp4autl.dll + 2003-03-24 16:52:04 41,020 -c--a-w c:\winnt\system32\dllcache\fp4avnb.dll + 2003-03-24 16:52:04 32,826 -c--a-w c:\winnt\system32\dllcache\fp4avss.dll + 2003-03-24 16:52:04 49,212 -c--a-w c:\winnt\system32\dllcache\fp4awebs.dll + 2003-06-02 23:41:06 876,653 -c--a-w c:\winnt\system32\dllcache\fp4awel.dll - 2000-05-25 14:48:26 14,608 -c--a-w c:\winnt\system32\dllcache\fp98sadm.exe + 2003-03-24 16:52:04 14,608 -c--a-w c:\winnt\system32\dllcache\fp98sadm.exe - 2000-05-25 14:48:26 109,328 -c--a-w c:\winnt\system32\dllcache\fp98swin.exe + 2003-03-24 16:52:04 109,328 -c--a-w c:\winnt\system32\dllcache\fp98swin.exe + 2003-03-24 16:52:04 24,632 -c--a-w c:\winnt\system32\dllcache\fpadmcgi.exe + 2003-03-24 16:52:04 20,541 -c--a-w c:\winnt\system32\dllcache\fpadmdll.dll + 1999-09-24 19:17:30 387,440 -c--a-w c:\winnt\system32\dllcache\fpcibase.sys + 1999-09-24 19:17:30 388,272 -c--a-w c:\winnt\system32\dllcache\fpcmbase.sys + 2003-03-24 16:52:04 188,494 -c--a-w c:\winnt\system32\dllcache\fpcount.exe + 2003-03-24 16:52:04 20,541 -c--a-w c:\winnt\system32\dllcache\fpexedll.dll + 2003-03-24 16:52:04 598,071 -c--a-w c:\winnt\system32\dllcache\fpmmc.dll + 2003-03-24 16:52:06 208,896 -c--a-w c:\winnt\system32\dllcache\fpmmcsat.dll + 1999-09-24 19:17:30 387,248 -c--a-w c:\winnt\system32\dllcache\fpnpbase.sys + 2003-03-24 16:52:04 20,538 -c--a-w c:\winnt\system32\dllcache\fpremadm.exe + 2003-06-19 11:05:04 168,009 -c--a-w c:\winnt\system32\dllcache\framedyn.dll + 2003-06-19 11:05:04 7,600 -c--a-w c:\winnt\system32\dllcache\fs_rec.sys + 2003-06-19 11:05:04 299,792 -c--a-w c:\winnt\system32\dllcache\fscfg.dll + 2000-07-26 17:00:00 12,368 -c--a-w c:\winnt\system32\dllcache\fsvga.sys + 2003-06-19 11:05:04 39,696 -c--a-w c:\winnt\system32\dllcache\ftp.exe + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\ftpctrs2.dll + 2003-06-19 11:05:04 6,416 -c--a-w c:\winnt\system32\dllcache\ftpmib.dll + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\ftpsapi2.dll + 2003-06-19 11:05:04 118,032 -c--a-w c:\winnt\system32\dllcache\ftpsvc2.dll + 1999-10-19 14:27:30 404,912 -c--a-w c:\winnt\system32\dllcache\fusbbase.sys + 1999-11-30 23:39:04 19,728 -c--a-w c:\winnt\system32\dllcache\fuusd.dll + 1999-10-19 14:27:30 404,528 -c--a-w c:\winnt\system32\dllcache\fxusbase.sys + 2003-06-19 12:05:04 9,808 -c--a-w c:\winnt\system32\dllcache\gameenum.sys + 1999-09-25 10:36:36 23,376 -c--a-w c:\winnt\system32\dllcache\gcr410p.sys + 1999-09-24 19:17:26 27,408 -c--a-w c:\winnt\system32\dllcache\genan5.sys + 1999-09-24 19:17:26 25,360 -c--a-w c:\winnt\system32\dllcache\genbn5.sys + 1999-12-02 15:30:38 148,240 -c--a-w c:\winnt\system32\dllcache\gfototwn.dll + 1999-09-25 10:36:36 16,016 -c--a-w c:\winnt\system32\dllcache\gpr400.sys + 2003-06-19 11:05:04 118,544 -c--a-w c:\winnt\system32\dllcache\gptext.dll + 2003-06-19 11:05:04 30,992 -c--a-w c:\winnt\system32\dllcache\gzip.dll + 2003-06-19 11:05:04 18,192 -c--a-w c:\winnt\system32\dllcache\hid.dll + 2003-06-19 12:05:04 18,928 -c--a-w c:\winnt\system32\dllcache\hidbatt.sys + 2003-06-19 11:05:04 24,752 -c--a-w c:\winnt\system32\dllcache\hidclass.sys + 1999-10-21 14:52:28 8,720 -c--a-w c:\winnt\system32\dllcache\hidgame.sys + 2003-06-19 11:05:04 23,056 -c--a-w c:\winnt\system32\dllcache\hidparse.sys + 2003-06-19 12:05:04 19,728 -c--a-w c:\winnt\system32\dllcache\hidserv.exe + 1999-10-04 15:03:32 13,904 -c--a-w c:\winnt\system32\dllcache\hidusb.sys + 2003-06-19 11:05:04 37,648 -c--a-w c:\winnt\system32\dllcache\hostmib.dll + 2003-06-19 11:05:04 76,560 -c--a-w c:\winnt\system32\dllcache\hotplug.dll + 1999-11-05 13:37:48 35,088 -c--a-w c:\winnt\system32\dllcache\hpddnd4.sys + 2003-06-19 12:05:04 12,912 -c--a-w c:\winnt\system32\dllcache\hpmc.sys + 1999-11-30 23:39:04 240,912 -c--a-w c:\winnt\system32\dllcache\hposcl10.dll + 1999-11-30 23:39:04 10,000 -c--a-w c:\winnt\system32\dllcache\hpousd10.dll + 1999-11-30 23:39:04 91,408 -c--a-w c:\winnt\system32\dllcache\hpscnmgr.dll + 1999-11-30 23:39:06 28,432 -c--a-w c:\winnt\system32\dllcache\hpsj32.dll + 1999-11-30 23:39:06 13,584 -c--a-w c:\winnt\system32\dllcache\hpsjinst.dll + 1999-11-30 23:40:04 16,144 -c--a-w c:\winnt\system32\dllcache\hpsjrreg.exe + 1999-11-30 23:39:06 8,464 -c--a-w c:\winnt\system32\dllcache\hpsjusd.dll + 1999-10-21 11:34:10 5,744 -c--a-w c:\winnt\system32\dllcache\hpt4qic.sys + 2003-06-19 12:05:04 85,776 -c--a-w c:\winnt\system32\dllcache\hptxnt5.sys + 1999-11-30 23:39:06 17,680 -c--a-w c:\winnt\system32\dllcache\hr132.dll + 2001-12-05 13:55:22 16,444 -c--a-w c:\winnt\system32\dllcache\htimage.exe + 2003-06-19 11:05:04 11,536 -c--a-w c:\winnt\system32\dllcache\htrn_jis.dll - 2005-01-12 19:39:52 247,056 -c----w c:\winnt\system32\dllcache\httpext.dll + 2003-06-19 11:05:04 246,544 -c--a-w c:\winnt\system32\dllcache\httpext.dll + 2003-06-19 11:05:04 9,488 -c--a-w c:\winnt\system32\dllcache\httpmib.dll + 2003-06-19 11:05:04 57,104 -c--a-w c:\winnt\system32\dllcache\httpodbc.dll + 1999-12-07 16:43:32 461,360 -c--a-w c:\winnt\system32\dllcache\i740dnt5.dll + 1999-10-05 15:09:48 58,800 -c--a-w c:\winnt\system32\dllcache\i740nt5.sys + 2003-06-19 11:05:04 46,992 -c--a-w c:\winnt\system32\dllcache\i8042prt.sys + 2003-06-19 12:05:04 489,712 -c--a-w c:\winnt\system32\dllcache\i81xdnt5.dll + 2003-06-19 12:05:04 68,336 -c--a-w c:\winnt\system32\dllcache\i81xnt5.sys + 2003-06-19 11:05:04 28,944 -c--a-w c:\winnt\system32\dllcache\iasacct.dll + 2003-06-19 11:05:04 75,536 -c--a-w c:\winnt\system32\dllcache\iasads.dll + 2003-06-19 11:05:04 60,176 -c--a-w c:\winnt\system32\dllcache\iasnap.dll + 2003-06-19 11:05:04 20,752 -c--a-w c:\winnt\system32\dllcache\iasperf.dll + 2003-06-19 11:05:04 97,040 -c--a-w c:\winnt\system32\dllcache\iasrad.dll + 2003-06-19 11:05:04 100,624 -c--a-w c:\winnt\system32\dllcache\iassam.dll + 2003-06-19 11:05:04 269,584 -c--a-w c:\winnt\system32\dllcache\iassdo.dll + 2003-06-19 11:05:04 60,176 -c--a-w c:\winnt\system32\dllcache\iassvcs.dll + 2003-06-19 11:05:04 20,240 -c--a-w c:\winnt\system32\dllcache\iasuserr.dll + 1999-09-24 19:17:22 40,208 -c--a-w c:\winnt\system32\dllcache\ibmcn5.sys + 1999-09-24 19:17:02 19,216 -c--a-w c:\winnt\system32\dllcache\ibmeimp.sys + 1999-10-04 13:56:00 28,944 -c--a-w c:\winnt\system32\dllcache\ibmexmp.sys + 2003-06-19 12:05:04 85,776 -c--a-w c:\winnt\system32\dllcache\ibmfent5.sys + 1999-10-06 15:52:08 35,600 -c--a-w c:\winnt\system32\dllcache\ibmgent5.sys + 1999-11-30 01:32:42 7,680 -c--a-w c:\winnt\system32\dllcache\ibmsgnet.dll + 1999-09-24 19:18:06 23,984 -c--a-w c:\winnt\system32\dllcache\ibmsync.sys + 1999-10-08 14:06:40 100,112 -c--a-w c:\winnt\system32\dllcache\ibmtok.sys + 2003-06-19 12:05:04 104,720 -c--a-w c:\winnt\system32\dllcache\ibmtrp.sys + 1999-10-26 13:12:30 39,184 -c--a-w c:\winnt\system32\dllcache\ibmvcap.sys + 2003-06-19 12:05:04 140,016 -c--a-w c:\winnt\system32\dllcache\icam3.sys + 1999-11-30 23:39:08 27,408 -c--a-w c:\winnt\system32\dllcache\icam3ext.dll + 1999-10-22 14:54:42 32,592 -c--a-w c:\winnt\system32\dllcache\ichaud.sys + 2003-06-19 11:05:04 186,640 -c--a-w c:\winnt\system32\dllcache\icwconn1.exe + 2003-06-19 11:05:04 122,128 -c--a-w c:\winnt\system32\dllcache\idq.dll - 2000-07-26 17:00:00 60,688 -c--a-w c:\winnt\system32\dllcache\iexplore.exe + 2002-08-29 06:14:40 91,136 -c--a-w c:\winnt\system32\dllcache\iexplore.exe + 2003-06-19 11:05:04 67,344 -c--a-w c:\winnt\system32\dllcache\ifsutil.dll + 2003-06-19 11:05:04 433,936 -c--a-w c:\winnt\system32\dllcache\iis.dll + 2003-06-19 11:05:04 16,144 -c--a-w c:\winnt\system32\dllcache\iisadmin.dll - 2005-01-12 19:39:52 122,640 -c----w c:\winnt\system32\dllcache\iischema.dll + 2003-06-19 11:05:04 121,616 -c--a-w c:\winnt\system32\dllcache\iischema.dll + 2003-06-19 11:05:04 20,240 -c--a-w c:\winnt\system32\dllcache\iiscrmap.dll - 2005-02-22 08:42:14 57,104 -c----w c:\winnt\system32\dllcache\iisext.dll + 2003-06-19 11:05:04 56,592 -c--a-w c:\winnt\system32\dllcache\iisext.dll + 2003-06-19 11:05:04 77,072 -c--a-w c:\winnt\system32\dllcache\iislog.dll + 2003-06-19 11:05:04 57,616 -c--a-w c:\winnt\system32\dllcache\iismap.dll + 2003-06-19 11:05:04 14,608 -c--a-w c:\winnt\system32\dllcache\iisreset.exe + 2003-06-19 11:05:04 28,432 -c--a-w c:\winnt\system32\dllcache\iisrstas.exe + 2003-06-19 11:05:04 124,176 -c--a-w c:\winnt\system32\dllcache\iisrtl.dll + 2003-06-19 11:05:04 301,840 -c--a-w c:\winnt\system32\dllcache\iisui.dll + 2003-06-19 11:05:04 128,784 -c--a-w c:\winnt\system32\dllcache\imagehlp.dll + 2001-12-05 13:55:22 16,445 -c--a-w c:\winnt\system32\dllcache\imagemap.exe + 2003-06-19 11:05:04 267,536 -c--a-w c:\winnt\system32\dllcache\imejpdct.dll + 2003-06-19 11:05:04 575,517 -c--a-w c:\winnt\system32\dllcache\imejpknl.dll + 2003-06-19 11:05:04 208,784 -c--a-w c:\winnt\system32\dllcache\imejputy.dll + 2003-06-19 11:05:04 293,136 -c--a-w c:\winnt\system32\dllcache\imepad.dll + 2003-06-19 11:05:04 87,344 -c--a-w c:\winnt\system32\dllcache\imeskdic.dll + 2003-06-19 11:05:04 303,680 -c--a-w c:\winnt\system32\dllcache\imeskf.dll + 2003-06-19 11:05:04 96,528 -c--a-w c:\winnt\system32\dllcache\imm32.dll + 2003-06-19 11:05:04 282,896 -c--a-w c:\winnt\system32\dllcache\imsinsnt.dll + 2003-06-19 11:05:04 14,608 -c--a-w c:\winnt\system32\dllcache\inetinfo.exe + 2003-06-19 11:05:04 179,472 -c--a-w c:\winnt\system32\dllcache\inetmgr.dll + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\inetmgr.exe + 2003-06-19 11:05:04 29,456 -c--a-w c:\winnt\system32\dllcache\inetmib1.dll + 2003-06-19 11:05:04 66,832 -c--a-w c:\winnt\system32\dllcache\inetpp.dll + 2003-06-19 11:05:04 20,752 -c--a-w c:\winnt\system32\dllcache\inetsloc.dll + 2003-06-19 11:05:04 13,584 -c--a-w c:\winnt\system32\dllcache\infoadmn.dll + 2003-06-19 11:05:04 248,080 -c--a-w c:\winnt\system32\dllcache\infocomm.dll + 2003-06-19 11:05:04 9,488 -c--a-w c:\winnt\system32\dllcache\infoctrs.dll + 2003-06-19 11:05:04 206,096 -c--a-w c:\winnt\system32\dllcache\infosoft.dll + 1999-09-25 11:11:44 16,208 -c--a-w c:\winnt\system32\dllcache\ini910u.sys + 2003-06-19 11:05:04 138,000 -c--a-w c:\winnt\system32\dllcache\initpki.dll + 1999-09-25 10:34:48 12,816 -c--a-w c:\winnt\system32\dllcache\inport.sys + 2003-06-19 11:05:04 164,112 -c--a-w c:\winnt\system32\dllcache\instdss5.dll + 2003-06-19 11:05:04 82,192 -c--a-w c:\winnt\system32\dllcache\instips5.dll + 2003-06-19 11:05:04 536,848 -c--a-w c:\winnt\system32\dllcache\instlsa5.dll + 2003-06-19 11:05:04 111,376 -c--a-w c:\winnt\system32\dllcache\instndi5.dll + 2003-06-19 11:05:04 152,336 -c--a-w c:\winnt\system32\dllcache\instrsa5.dll + 2003-06-19 11:05:04 165,648 -c--a-w c:\winnt\system32\dllcache\instsch5.dll + 2003-06-19 11:05:04 4,624 -c--a-w c:\winnt\system32\dllcache\intelide.sys + 1999-09-30 21:29:16 36,592 -c--a-w c:\winnt\system32\dllcache\io8.sys + 1999-10-19 14:28:16 46,160 -c--a-w c:\winnt\system32\dllcache\ip5515.sys + 1999-09-24 19:17:26 27,408 -c--a-w c:\winnt\system32\dllcache\ipc08a5.sys + 2003-06-19 11:05:04 4,368 -c--a-w c:\winnt\system32\dllcache\iprop.dll + 2003-06-19 11:05:04 159,504 -c--a-w c:\winnt\system32\dllcache\iprtrmgr.dll + 2003-04-21 18:19:42 80,848 -c--a-w c:\winnt\system32\dllcache\ipsec.sys + 1999-09-25 11:11:44 14,736 -c--a-w c:\winnt\system32\dllcache\ipsraidn.sys + 2003-06-19 11:05:04 57,296 -c--a-w c:\winnt\system32\dllcache\irda.sys + 2003-06-19 11:05:04 10,288 -c--a-w c:\winnt\system32\dllcache\irenum.sys + 2003-06-19 11:05:04 73,488 -c--a-w c:\winnt\system32\dllcache\irmon.dll + 2003-06-19 11:05:04 19,952 -c--a-w c:\winnt\system32\dllcache\irsir.sys + 1999-11-30 23:39:12 7,440 -c--a-w c:\winnt\system32\dllcache\is01.dll + 1999-11-30 23:39:12 7,440 -c--a-w c:\winnt\system32\dllcache\is410.dll + 1999-11-30 23:39:12 7,440 -c--a-w c:\winnt\system32\dllcache\is450.dll + 1999-11-30 23:39:12 7,440 -c--a-w c:\winnt\system32\dllcache\is4x.dll + 2003-06-19 11:05:04 46,992 -c--a-w c:\winnt\system32\dllcache\isapnp.sys + 1999-11-30 23:39:12 17,168 -c--a-w c:\winnt\system32\dllcache\isaprop.dll + 2003-06-19 11:05:04 62,736 -c--a-w c:\winnt\system32\dllcache\isatq.dll + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\iscomlog.dll + 2003-06-19 11:05:04 72,464 -c--a-w c:\winnt\system32\dllcache\isign32.dll + 2003-06-19 11:05:04 46,352 -c--a-w c:\winnt\system32\dllcache\ism.dll + 2003-06-19 11:05:04 49,936 -c--a-w c:\winnt\system32\dllcache\ixsso.dll + 1999-11-30 23:39:14 45,840 -c--a-w c:\winnt\system32\dllcache\iyuv_32.dll + 2003-06-19 11:05:04 374,032 -c--a-w c:\winnt\system32\dllcache\jet500.dll + 1999-09-24 19:17:08 35,856 -c--a-w c:\winnt\system32\dllcache\jt1nd5.sys + 1999-11-30 23:39:14 17,168 -c--a-w c:\winnt\system32\dllcache\jupi32.dll + 2003-06-19 12:05:04 9,968 -c--a-w c:\winnt\system32\dllcache\jvcmc.sys + 1999-11-30 01:33:02 6,416 -c--a-w c:\winnt\system32\dllcache\kbd101b.dll + 1999-11-30 01:33:02 6,928 -c--a-w c:\winnt\system32\dllcache\kbd101c.dll + 1999-11-30 01:33:02 6,416 -c--a-w c:\winnt\system32\dllcache\kbd103.dll + 1999-11-30 01:33:02 7,440 -c--a-w c:\winnt\system32\dllcache\kbd106.dll + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\kbdca.dll + 2003-06-19 11:05:04 24,528 -c--a-w c:\winnt\system32\dllcache\kbdclass.sys + 1999-10-04 15:04:22 13,744 -c--a-w c:\winnt\system32\dllcache\kbdhid.sys + 1999-11-30 01:33:04 8,976 -c--a-w c:\winnt\system32\dllcache\kbdjpn.dll + 1999-11-30 01:33:04 8,464 -c--a-w c:\winnt\system32\dllcache\kbdkor.dll + 2003-06-19 11:05:04 6,416 -c--a-w c:\winnt\system32\dllcache\kbdlt1.dll + 2003-06-19 11:05:04 6,416 -c--a-w c:\winnt\system32\dllcache\kbdro.dll + 1999-11-30 23:39:14 17,680 -c--a-w c:\winnt\system32\dllcache\kdusd.dll + 2003-06-19 11:05:04 42,809 -c--a-w c:\winnt\system32\dllcache\key01.sys + 2003-06-19 11:05:04 42,537 -c--a-w c:\winnt\system32\dllcache\keyboard.sys + 2003-06-19 11:05:04 148,304 -c--a-w c:\winnt\system32\dllcache\kmixer.sys + 1999-11-30 23:39:14 20,240 -c--a-w c:\winnt\system32\dllcache\kod2x0.dll + 2003-06-19 11:05:04 74,512 -c--a-w c:\winnt\system32\dllcache\korwbrkr.dll + 1999-11-30 23:39:14 18,192 -c--a-w c:\winnt\system32\dllcache\kousd.dll + 2003-06-19 11:05:04 113,744 -c--a-w c:\winnt\system32\dllcache\ks.sys + 1999-11-30 22:39:14 4,880 -c--a-w c:\winnt\system32\dllcache\ksuser.dll + 2003-06-19 11:05:04 11,024 -c--a-w c:\winnt\system32\dllcache\label.exe + 1999-09-24 19:17:18 26,640 -c--a-w c:\winnt\system32\dllcache\lanepic5.sys + 2003-06-19 11:05:04 26,896 -c--a-w c:\winnt\system32\dllcache\laprxy.dll + 1999-09-29 18:25:16 33,808 -c--a-w c:\winnt\system32\dllcache\lbrtfdc.sys + 1999-09-24 19:17:26 25,360 -c--a-w c:\winnt\system32\dllcache\le56n5.sys + 1999-11-30 23:39:14 24,848 -c--a-w c:\winnt\system32\dllcache\lgacrop.dll + 1999-11-30 23:39:14 42,256 -c--a-w c:\winnt\system32\dllcache\lgbclb.dll + 1999-11-30 23:39:14 29,968 -c--a-w c:\winnt\system32\dllcache\lgdclb.dll + 1999-11-30 23:39:14 30,992 -c--a-w c:\winnt\system32\dllcache\lgdecomp.dll + 1999-11-30 23:39:14 10,000 -c--a-w c:\winnt\system32\dllcache\lgdeskew.dll + 1999-11-30 23:39:14 23,824 -c--a-w c:\winnt\system32\dllcache\lgdpinnc.dll + 1999-11-30 01:33:08 8,976 -c--a-w c:\winnt\system32\dllcache\lgdvrc.dll + 1999-11-30 23:39:14 32,528 -c--a-w c:\winnt\system32\dllcache\lginstsc.dll + 1999-11-30 23:39:14 36,624 -c--a-w c:\winnt\system32\dllcache\lgmntr.dll + 1999-11-30 23:39:14 18,192 -c--a-w c:\winnt\system32\dllcache\lgprgres.dll + 1999-11-30 23:39:14 91,408 -c--a-w c:\winnt\system32\dllcache\lgpusb.dll + 1999-11-30 01:33:08 221,456 -c--a-w c:\winnt\system32\dllcache\lgpusbrc.dll + 1999-11-30 23:39:14 53,520 -c--a-w c:\winnt\system32\dllcache\lgpusbui.dll + 1999-11-30 23:39:14 80,144 -c--a-w c:\winnt\system32\dllcache\lgtw.dll + 1999-11-30 23:39:14 28,944 -c--a-w c:\winnt\system32\dllcache\lgusbcmd.dll + 1999-09-25 10:36:36 15,952 -c--a-w c:\winnt\system32\dllcache\lit220p.sys + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\lmhsvc.dll + 2003-06-19 11:05:04 29,968 -c--a-w c:\winnt\system32\dllcache\lmmib2.dll + 1999-09-24 19:17:08 30,992 -c--a-w c:\winnt\system32\dllcache\lne100tx.sys + 2003-06-19 11:05:04 66,320 -c--a-w c:\winnt\system32\dllcache\loadperf.dll + 2003-06-19 11:05:04 246,032 -c--a-w c:\winnt\system32\dllcache\localsec.dll + 2003-06-19 11:05:04 72,464 -c--a-w c:\winnt\system32\dllcache\locator.exe + 2003-06-19 11:05:04 25,872 -c--a-w c:\winnt\system32\dllcache\lodctr.exe + 2003-06-19 11:05:04 65,296 -c--a-w c:\winnt\system32\dllcache\logagent.exe + 2003-06-19 11:05:04 48,400 -c--a-w c:\winnt\system32\dllcache\loghours.dll + 2003-06-19 11:05:04 25,360 -c--a-w c:\winnt\system32\dllcache\logscrpt.dll + 2003-06-19 11:05:04 12,048 -c--a-w c:\winnt\system32\dllcache\lonsint.dll + 1999-09-30 15:25:32 5,008 -c--a-w c:\winnt\system32\dllcache\loop.sys + 2003-06-19 12:05:04 33,328 -c--a-w c:\winnt\system32\dllcache\lp6nds35.sys + 2003-06-19 11:05:04 21,776 -c--a-w c:\winnt\system32\dllcache\lpdsvc.dll + 2003-06-19 11:05:04 20,240 -c--a-w c:\winnt\system32\dllcache\lpk.dll + 2003-06-19 11:05:04 18,192 -c--a-w c:\winnt\system32\dllcache\lprmon.dll + 2007-10-16 11:34:39 513,808 -c--a-w c:\winnt\system32\dllcache\lsasrv.dll + 1999-09-27 19:26:50 55,120 -c--a-w c:\winnt\system32\dllcache\lsermous.sys + 1999-09-30 15:25:32 14,992 -c--a-w c:\winnt\system32\dllcache\lt200.sys + 1999-10-23 13:01:40 413,712 -c--a-w c:\winnt\system32\dllcache\ltmdmnt.sys + 1999-10-23 13:01:40 408,016 -c--a-w c:\winnt\system32\dllcache\ltmdmntc.sys + 1999-11-08 16:38:44 543,056 -c--a-w c:\winnt\system32\dllcache\ltmdmntl.sys + 1999-10-23 13:01:40 410,832 -c--a-w c:\winnt\system32\dllcache\ltmdmntt.sys + 2000-07-26 17:00:00 88,816 -c--a-w c:\winnt\system32\dllcache\lvcam.sys + 1999-11-30 23:39:16 99,600 -c--a-w c:\winnt\system32\dllcache\lvcod32.dll + 2000-07-26 17:00:00 79,120 -c--a-w c:\winnt\system32\dllcache\lvcodek.sys + 2000-07-26 17:00:00 17,424 -c--a-w c:\winnt\system32\dllcache\lvsound.sys + 1999-11-30 23:39:16 15,120 -c--a-w c:\winnt\system32\dllcache\lvui32.dll + 1999-11-30 23:39:16 24,848 -c--a-w c:\winnt\system32\dllcache\lvui32rc.dll + 1999-10-21 14:51:40 18,576 -c--a-w c:\winnt\system32\dllcache\lwadihid.sys + 1999-10-22 14:51:46 19,408 -c--a-w c:\winnt\system32\dllcache\lwusbhid.sys + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\lz32.dll + 1999-09-24 19:17:26 27,408 -c--a-w c:\winnt\system32\dllcache\m16a5.sys + 1999-09-24 19:17:24 25,360 -c--a-w c:\winnt\system32\dllcache\m16b5.sys + 1999-09-24 19:17:22 40,720 -c--a-w c:\winnt\system32\dllcache\m32a5.sys + 1999-11-22 16:01:42 48,368 -c--a-w c:\winnt\system32\dllcache\maestro.sys + 2003-06-19 11:05:04 43,792 -c--a-w c:\winnt\system32\dllcache\magnify.exe + 1999-10-21 11:34:10 6,128 -c--a-w c:\winnt\system32\dllcache\mammoth.sys + 2003-06-19 11:05:04 33,552 -c--a-w c:\winnt\system32\dllcache\md5filt.dll + 1999-10-04 14:01:34 150,992 -c--a-w c:\winnt\system32\dllcache\mdgndis5.sys + 2003-06-19 11:05:04 76,048 -c--a-w c:\winnt\system32\dllcache\mdhcp.dll + 2003-06-19 11:05:04 102,160 -c--a-w c:\winnt\system32\dllcache\mdminst.dll + 2003-06-19 11:05:04 26,896 -c--a-w c:\winnt\system32\dllcache\mdsync.dll - 1999-09-24 10:10:06 31,232 -c--a-w c:\winnt\system32\dllcache\mei32api.dll + 1999-09-24 11:10:06 31,232 -c--a-w c:\winnt\system32\dllcache\mei32api.dll - 1999-09-24 10:10:10 83,968 -c--a-w c:\winnt\system32\dllcache\meiw0439.dll + 1999-09-24 11:10:10 83,968 -c--a-w c:\winnt\system32\dllcache\meiw0439.dll + 1999-10-08 13:00:06 8,176 -c--a-w c:\winnt\system32\dllcache\memcard.sys + 2003-06-19 11:05:04 70,416 -c--a-w c:\winnt\system32\dllcache\metadata.dll + 2003-06-19 11:05:04 57,264 -c--a-w c:\winnt\system32\dllcache\mf.sys + 1999-11-30 23:39:16 7,440 -c--a-w c:\winnt\system32\dllcache\mf3.dll + 2003-06-19 11:05:04 1,015,859 -c--a-w c:\winnt\system32\dllcache\mfc42.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs06cx.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs06cz.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs06sp.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs08sp.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs12cx.dll + 1999-11-30 23:39:18 7,440 -c--a-w c:\winnt\system32\dllcache\mfs12sp.dll + 1999-12-07 16:43:34 91,824 -c--a-w c:\winnt\system32\dllcache\mga.dll + 1999-09-25 10:37:08 92,496 -c--a-w c:\winnt\system32\dllcache\mga.sys + 1999-12-07 16:43:34 551,536 -c--a-w c:\winnt\system32\dllcache\mga64d.dll + 1999-11-29 17:47:48 150,960 -c--a-w c:\winnt\system32\dllcache\mga64m.sys + 1999-09-30 21:29:14 53,232 -c--a-w c:\winnt\system32\dllcache\mgfr5.sys + 1999-11-30 23:40:06 97,040 -c--a-w c:\winnt\system32\dllcache\mgfrmon.exe + 1999-11-30 23:39:18 63,760 -c--a-w c:\winnt\system32\dllcache\mgfrpp.dll + 1999-09-24 19:17:52 10,000 -c--a-w c:\winnt\system32\dllcache\mgfrtrc5.sys + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\mgmtapi.dll + 1999-09-24 19:17:52 40,944 -c--a-w c:\winnt\system32\dllcache\mgsl5.sys + 1999-11-30 23:39:18 21,264 -c--a-w c:\winnt\system32\dllcache\mgslpp.dll + 1999-09-24 19:18:06 33,840 -c--a-w c:\winnt\system32\dllcache\mgsync5.sys + 1999-11-30 23:40:06 91,408 -c--a-w c:\winnt\system32\dllcache\mgwan.exe + 1999-09-24 19:17:54 67,504 -c--a-w c:\winnt\system32\dllcache\mgwan5.sys + 1999-11-30 23:39:18 41,984 -c--a-w c:\winnt\system32\dllcache\mgwanpp.dll + 1999-09-30 21:29:20 8,976 -c--a-w c:\winnt\system32\dllcache\mgwantr5.sys + 2003-06-19 11:05:04 19,728 -c--a-w c:\winnt\system32\dllcache\mimefilt.dll + 1999-10-21 11:34:10 6,608 -c--a-w c:\winnt\system32\dllcache\miniqic.sys + 1999-11-30 23:39:18 23,824 -c--a-w c:\winnt\system32\dllcache\miscan32.dll + 2003-06-19 11:05:04 169,232 -c--a-w c:\winnt\system32\dllcache\mobsync.dll + 2003-06-19 11:05:04 111,376 -c--a-w c:\winnt\system32\dllcache\mobsync.exe + 2003-06-19 11:05:04 29,168 -c--a-w c:\winnt\system32\dllcache\modem.sys + 1999-09-25 10:34:58 16,144 -c--a-w c:\winnt\system32\dllcache\modemcsa.sys + 2003-06-19 11:05:04 99,088 -c--a-w c:\winnt\system32\dllcache\modemui.dll + 2003-06-19 11:05:04 28,743 -c--a-w c:\winnt\system32\dllcache\mofcomp.exe + 2003-06-19 11:05:04 139,353 -c--a-w c:\winnt\system32\dllcache\mofd.dll + 2003-06-19 11:05:04 21,776 -c--a-w c:\winnt\system32\dllcache\mouclass.sys + 2003-06-19 12:05:04 11,632 -c--a-w c:\winnt\system32\dllcache\mouhid.sys + 1999-11-30 23:39:18 6,928 -c--a-w c:\winnt\system32\dllcache\mphase32.dll + 2003-06-19 11:05:04 4,639 -c--a-w c:\winnt\system32\dllcache\mplayer2.exe + 2003-06-19 11:05:04 69,904 -c--a-w c:\winnt\system32\dllcache\mprddm.dll + 2003-06-19 11:05:04 47,376 -c--a-w c:\winnt\system32\dllcache\mprdim.dll + 2003-06-19 11:05:04 56,080 -c--a-w c:\winnt\system32\dllcache\mprui.dll - 2008-08-12 08:41:26 296,720 -c--a-w c:\winnt\system32\dllcache\mq1repl.dll + 2003-06-19 11:05:04 281,872 -c--a-w c:\winnt\system32\dllcache\mq1repl.dll - 2008-08-12 07:47:42 14,096 -c--a-w c:\winnt\system32\dllcache\mq1sync.exe + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\mq1sync.exe - 2008-08-12 07:47:42 77,712 -c----w c:\winnt\system32\dllcache\mqac.sys + 2003-06-19 11:05:04 75,536 -c--a-w c:\winnt\system32\dllcache\mqac.sys - 2008-08-12 08:41:26 223,504 -c--a-w c:\winnt\system32\dllcache\mqads.dll + 2003-06-19 11:05:04 217,360 -c--a-w c:\winnt\system32\dllcache\mqads.dll - 2008-08-12 07:47:42 25,360 -c----w c:\winnt\system32\dllcache\mqbkup.exe + 2003-06-19 11:05:04 25,360 -c--a-w c:\winnt\system32\dllcache\mqbkup.exe - 2008-08-12 08:41:26 29,968 -c----w c:\winnt\system32\dllcache\mqcertui.dll + 2003-06-19 11:05:04 29,456 -c--a-w c:\winnt\system32\dllcache\mqcertui.dll - 2007-10-17 07:22:06 29,968 -c----w c:\winnt\system32\dllcache\mqdbodbc.dll + 2003-06-19 11:05:04 29,968 -c--a-w c:\winnt\system32\dllcache\mqdbodbc.dll - 2008-08-12 08:41:26 77,584 -c--a-w c:\winnt\system32\dllcache\mqdscli.dll + 2003-06-19 11:05:04 76,560 -c--a-w c:\winnt\system32\dllcache\mqdscli.dll - 2008-08-12 08:41:26 42,768 -c--a-w c:\winnt\system32\dllcache\mqdssrv.dll + 2003-06-19 11:05:04 42,256 -c--a-w c:\winnt\system32\dllcache\mqdssrv.dll - 2007-10-17 07:22:06 96,016 -c--a-w c:\winnt\system32\dllcache\mqlogmgr.dll + 2000-07-26 17:00:00 87,312 -c--a-w c:\winnt\system32\dllcache\mqlogmgr.dll - 2000-07-26 17:00:00 72,976 -c--a-w c:\winnt\system32\dllcache\mqmailoa.dll + 2003-06-19 11:05:04 72,976 -c--a-w c:\winnt\system32\dllcache\mqmailoa.dll + 2003-06-19 11:05:04 185,104 -c--a-w c:\winnt\system32\dllcache\mqmailvb.dll - 2008-08-12 07:47:44 98,064 -c--a-w c:\winnt\system32\dllcache\mqmig.exe + 2003-06-19 11:05:04 98,064 -c--a-w c:\winnt\system32\dllcache\mqmig.exe - 2008-08-12 08:41:26 272,144 -c--a-w c:\winnt\system32\dllcache\mqmigrat.dll + 2003-06-19 11:05:04 266,000 -c--a-w c:\winnt\system32\dllcache\mqmigrat.dll - 2008-08-12 08:41:26 222,992 -c--a-w c:\winnt\system32\dllcache\mqoa.dll + 2003-06-19 11:05:04 222,480 -c--a-w c:\winnt\system32\dllcache\mqoa.dll - 2008-08-12 08:41:26 10,000 -c--a-w c:\winnt\system32\dllcache\mqperf.dll + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\mqperf.dll - 2008-08-12 08:41:26 445,712 -c--a-w c:\winnt\system32\dllcache\mqqm.dll + 2003-06-19 11:05:04 428,304 -c--a-w c:\winnt\system32\dllcache\mqqm.dll - 2008-08-12 08:41:26 103,696 -c--a-w c:\winnt\system32\dllcache\mqrt.dll + 2003-06-19 11:05:04 102,672 -c--a-w c:\winnt\system32\dllcache\mqrt.dll - 2008-08-12 08:41:26 71,952 -c--a-w c:\winnt\system32\dllcache\mqsec.dll + 2003-06-19 11:05:04 70,928 -c--a-w c:\winnt\system32\dllcache\mqsec.dll - 2008-08-12 08:41:26 400,656 -c--a-w c:\winnt\system32\dllcache\mqsnap.dll + 2003-06-19 11:05:04 400,656 -c--a-w c:\winnt\system32\dllcache\mqsnap.dll - 2008-08-12 07:47:50 14,096 -c----w c:\winnt\system32\dllcache\mqsvc.exe + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\mqsvc.exe - 2008-08-12 08:41:26 23,824 -c--a-w c:\winnt\system32\dllcache\mqupgrd.dll + 2003-06-19 11:05:04 23,824 -c--a-w c:\winnt\system32\dllcache\mqupgrd.dll - 2008-08-12 08:41:26 112,400 -c--a-w c:\winnt\system32\dllcache\mqutil.dll + 2003-06-19 11:05:04 110,352 -c--a-w c:\winnt\system32\dllcache\mqutil.dll + 2003-06-19 11:05:04 297,744 -c--a-w c:\winnt\system32\dllcache\mqxp32.dll + 1999-11-05 21:23:34 9,488 -c--a-w c:\winnt\system32\dllcache\mraid35x.sys + 2003-06-19 11:05:04 16,384 -c--a-w c:\winnt\system32\dllcache\msadcer.dll + 2003-06-19 11:05:04 65,808 -c--a-w c:\winnt\system32\dllcache\msadcf.dll + 2003-06-19 11:05:04 12,288 -c--a-w c:\winnt\system32\dllcache\msadcfr.dll + 2003-06-19 11:05:04 16,384 -c--a-w c:\winnt\system32\dllcache\msadcor.dll + 2003-06-19 11:05:04 164,112 -c--a-w c:\winnt\system32\dllcache\msadds.dll + 2003-06-19 11:05:04 24,576 -c--a-w c:\winnt\system32\dllcache\msaddsr.dll + 2003-06-19 11:05:04 20,480 -c--a-w c:\winnt\system32\dllcache\msader15.dll + 2003-06-19 11:05:04 57,616 -c--a-w c:\winnt\system32\dllcache\msador15.dll + 2003-06-19 11:05:04 57,616 -c--a-w c:\winnt\system32\dllcache\msadrh15.dll + 2003-06-19 11:05:04 236,304 -c--a-w c:\winnt\system32\dllcache\msclus.dll + 2003-06-19 11:05:04 13,824 -c--a-w c:\winnt\system32\dllcache\mscpxl32.dll + 2003-06-19 11:05:04 5,392 -c--a-w c:\winnt\system32\dllcache\msdadc.dll + 2003-06-19 11:05:04 5,392 -c--a-w c:\winnt\system32\dllcache\msdaenum.dll + 2003-06-19 11:05:04 5,392 -c--a-w c:\winnt\system32\dllcache\msdaer.dll + 2003-06-19 11:05:04 209,168 -c--a-w c:\winnt\system32\dllcache\msdaora.dll + 2003-06-19 11:05:04 82,192 -c--a-w c:\winnt\system32\dllcache\msdaosp.dll + 2003-06-19 11:05:04 16,384 -c--a-w c:\winnt\system32\dllcache\msdaprsr.dll + 2003-06-19 11:05:04 123,152 -c--a-w c:\winnt\system32\dllcache\msdarem.dll + 2003-06-19 11:05:04 16,384 -c--a-w c:\winnt\system32\dllcache\msdaremr.dll + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\msdart32.dll + 2003-06-19 11:05:04 5,392 -c--a-w c:\winnt\system32\dllcache\msdasc.dll + 2003-06-19 11:05:04 303,376 -c--a-w c:\winnt\system32\dllcache\msdasql.dll + 2003-06-19 11:05:04 16,384 -c--a-w c:\winnt\system32\dllcache\msdasqlr.dll + 2003-06-19 11:05:04 78,096 -c--a-w c:\winnt\system32\dllcache\msdatl2.dll + 2003-06-19 11:05:04 53,520 -c--a-w c:\winnt\system32\dllcache\msdatt.dll + 2003-06-19 11:05:04 4,880 -c--a-w c:\winnt\system32\dllcache\msdaurl.dll + 2003-06-19 11:05:04 37,136 -c--a-w c:\winnt\system32\dllcache\msdfmap.dll + 2003-06-19 12:05:04 55,920 -c--a-w c:\winnt\system32\dllcache\msdv.sys + 2003-06-19 11:05:04 4,126 -c--a-w c:\winnt\system32\dllcache\msdxmlc.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf06cx.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf06cz.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf06sp.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf08sp.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf12cx.dll + 1999-11-30 23:39:22 7,440 -c--a-w c:\winnt\system32\dllcache\msf12sp.dll + 1999-09-25 10:36:30 5,776 -c--a-w c:\winnt\system32\dllcache\msfsio.sys + 1999-10-26 15:30:50 35,440 -c--a-w c:\winnt\system32\dllcache\msgame.sys + 2003-06-19 11:05:04 34,704 -c--a-w c:\winnt\system32\dllcache\msgpc.sys - 2003-09-20 04:53:04 64,512 -c----w c:\winnt\system32\dllcache\msiexec.exe + 2005-05-04 13:45:36 78,848 -c--a-w c:\winnt\system32\dllcache\msiexec.exe + 2005-05-04 13:45:36 271,360 -c--a-w c:\winnt\system32\dllcache\msihnd.dll + 2005-05-04 13:45:36 884,736 -c--a-w c:\winnt\system32\dllcache\msimsg.dll + 2003-06-19 11:05:04 319,760 -c--a-w c:\winnt\system32\dllcache\msinfo32.dll + 2003-06-19 11:05:04 16,144 -c--a-w c:\winnt\system32\dllcache\msinfo32.exe + 2003-06-19 11:05:04 20,208 -c--a-w c:\winnt\system32\dllcache\msircomm.sys + 2000-07-26 17:00:00 6,640 -c--a-w c:\winnt\system32\dllcache\mskssrv.sys + 1999-11-30 23:39:26 24,848 -c--a-w c:\winnt\system32\dllcache\msmgr32.dll + 1999-09-25 10:35:16 2,832 -c--a-w c:\winnt\system32\dllcache\msmpu401.sys + 1999-11-30 23:39:26 11,024 -c--a-w c:\winnt\system32\dllcache\msmusd.dll + 2003-06-19 11:05:04 155,920 -c--a-w c:\winnt\system32\dllcache\msorcl32.dll + 2003-06-19 11:05:04 319,760 -c--a-w c:\winnt\system32\dllcache\mspaint.exe + 2003-06-19 11:05:04 27,136 -c--a-w c:\winnt\system32\dllcache\mspatcha.dll + 2000-07-26 17:00:00 5,008 -c--a-w c:\winnt\system32\dllcache\mspclock.sys + 2000-07-26 17:00:00 4,816 -c--a-w c:\winnt\system32\dllcache\mspqm.sys + 2003-06-19 11:05:04 47,104 -c--a-w c:\winnt\system32\dllcache\msprivs.dll + 1999-09-25 10:36:34 12,208 -c--a-w c:\winnt\system32\dllcache\msriffwv.sys + 2003-06-19 11:05:04 11,024 -c--a-w c:\winnt\system32\dllcache\msrle32.dll + 2003-06-19 11:05:04 35,088 -c--a-w c:\winnt\system32\dllcache\mssign32.dll + 1999-11-30 23:39:26 8,464 -c--a-w c:\winnt\system32\dllcache\mssti.dll + 2003-06-19 11:05:04 14,608 -c--a-w c:\winnt\system32\dllcache\msswch.dll + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\msswchx.exe + 2003-06-19 11:05:04 39,696 -c--a-w c:\winnt\system32\dllcache\mst123.dll + 2003-06-19 12:05:04 5,168 -c--a-w c:\winnt\system32\dllcache\mstee.sys + 2003-06-19 11:05:04 286,773 -c--a-w c:\winnt\system32\dllcache\msvcrt.dll + 2003-06-19 11:05:04 116,496 -c--a-w c:\winnt\system32\dllcache\msvfw32.dll + 2003-06-19 11:05:04 76,560 -c--a-w c:\winnt\system32\dllcache\msw3prt.dll + 2003-06-19 11:05:04 28,944 -c--a-w c:\winnt\system32\dllcache\msxactps.dll + 2003-06-19 11:05:04 514,320 -c--a-w c:\winnt\system32\dllcache\msxml.dll + 2003-06-19 11:05:04 26,624 -c--a-w c:\winnt\system32\dllcache\msxmlr.dll + 1999-11-30 23:39:28 15,120 -c--a-w c:\winnt\system32\dllcache\msyuv.dll - 2005-08-30 05:05:22 155,408 -c----w c:\winnt\system32\dllcache\mtstocom.exe + 2003-06-19 11:05:04 151,312 -c--a-w c:\winnt\system32\dllcache\mtstocom.exe + 2003-06-19 11:05:04 177,056 -c--a-w c:\winnt\system32\dllcache\multibox.dll - 1999-09-24 10:09:58 50,688 -c--a-w c:\winnt\system32\dllcache\mwave.dll + 1999-09-24 11:09:58 50,688 -c--a-w c:\winnt\system32\dllcache\mwave.dll - 1999-09-24 10:10:02 129,024 -c--a-w c:\winnt\system32\dllcache\mwavesrv.dll + 1999-09-24 11:10:02 129,024 -c--a-w c:\winnt\system32\dllcache\mwavesrv.dll - 1998-03-17 09:09:20 56,832 -c--a-w c:\winnt\system32\dllcache\mwblw32.dll + 1998-03-17 10:09:20 56,832 -c--a-w c:\winnt\system32\dllcache\mwblw32.dll - 1999-09-23 20:40:12 71,168 -c--a-w c:\winnt\system32\dllcache\mwcicore.dll + 1999-09-23 21:40:12 71,168 -c--a-w c:\winnt\system32\dllcache\mwcicore.dll - 1999-09-24 10:10:14 56,832 -c--a-w c:\winnt\system32\dllcache\mwcload.exe + 1999-09-24 11:10:14 56,832 -c--a-w c:\winnt\system32\dllcache\mwcload.exe - 1999-09-24 10:10:18 60,928 -c--a-w c:\winnt\system32\dllcache\mwcloadw.exe + 1999-09-24 11:10:18 60,928 -c--a-w c:\winnt\system32\dllcache\mwcloadw.exe - 1999-09-24 10:10:22 90,624 -c--a-w c:\winnt\system32\dllcache\mwclw32.dll + 1999-09-24 11:10:22 90,624 -c--a-w c:\winnt\system32\dllcache\mwclw32.dll - 1998-12-16 09:38:12 33,280 -c--a-w c:\winnt\system32\dllcache\mwcnam32.dll + 1998-12-16 10:38:12 33,280 -c--a-w c:\winnt\system32\dllcache\mwcnam32.dll - 1998-08-10 08:39:52 26,112 -c--a-w c:\winnt\system32\dllcache\mwcpyrt.exe + 1998-08-10 09:39:52 26,112 -c--a-w c:\winnt\system32\dllcache\mwcpyrt.exe - 1999-05-24 09:00:28 160,256 -c--a-w c:\winnt\system32\dllcache\mwcsw32.exe + 1999-05-24 10:00:28 160,256 -c--a-w c:\winnt\system32\dllcache\mwcsw32.exe - 1999-09-24 10:10:32 50,688 -c--a-w c:\winnt\system32\dllcache\mwmdmsvc.exe + 1999-09-24 11:10:32 50,688 -c--a-w c:\winnt\system32\dllcache\mwmdmsvc.exe - 1999-07-12 10:03:52 262,144 -c--a-w c:\winnt\system32\dllcache\mwmlw32.dll + 1999-07-12 11:03:52 262,144 -c--a-w c:\winnt\system32\dllcache\mwmlw32.dll - 1999-06-09 15:42:24 40,448 -c--a-w c:\winnt\system32\dllcache\mwmmw32.dll + 1999-06-09 16:42:24 40,448 -c--a-w c:\winnt\system32\dllcache\mwmmw32.dll - 1999-06-09 14:46:40 164,352 -c--a-w c:\winnt\system32\dllcache\mwmpw32.dll + 1999-06-09 15:46:40 164,352 -c--a-w c:\winnt\system32\dllcache\mwmpw32.dll - 1999-06-09 15:40:14 121,344 -c--a-w c:\winnt\system32\dllcache\mwmw32.dll + 1999-06-09 16:40:14 121,344 -c--a-w c:\winnt\system32\dllcache\mwmw32.dll - 1998-09-15 16:49:16 42,496 -c--a-w c:\winnt\system32\dllcache\mwrcov16.exe + 1998-09-15 17:49:16 42,496 -c--a-w c:\winnt\system32\dllcache\mwrcov16.exe - 1999-04-01 11:56:30 202,752 -c--a-w c:\winnt\system32\dllcache\mwremind.exe + 1999-04-01 12:56:30 202,752 -c--a-w c:\winnt\system32\dllcache\mwremind.exe - 1999-09-24 10:09:54 29,184 -c--a-w c:\winnt\system32\dllcache\mwssw32.exe + 1999-09-24 11:09:54 29,184 -c--a-w c:\winnt\system32\dllcache\mwssw32.exe - 1999-09-24 10:10:28 39,200 -c--a-w c:\winnt\system32\dllcache\mwwdm.sys + 1999-09-24 11:10:28 39,200 -c--a-w c:\winnt\system32\dllcache\mwwdm.sys - 1999-09-24 10:10:44 30,720 -c--a-w c:\winnt\system32\dllcache\mwwdmhlp.dll + 1999-09-24 11:10:44 30,720 -c--a-w c:\winnt\system32\dllcache\mwwdmhlp.dll - 1999-06-24 12:07:00 108,032 -c--a-w c:\winnt\system32\dllcache\mwwtt32.dll + 1999-06-24 13:07:00 108,032 -c--a-w c:\winnt\system32\dllcache\mwwtt32.dll + 1999-11-01 16:49:04 20,112 -c--a-w c:\winnt\system32\dllcache\mxnic.sys + 2003-06-19 11:05:04 110,352 -c--a-w c:\winnt\system32\dllcache\mycomput.dll + 2003-06-19 11:05:04 57,104 -c--a-w c:\winnt\system32\dllcache\mydocs.dll + 2003-06-19 11:05:04 26,384 -c--a-w c:\winnt\system32\dllcache\myinfo.dll + 1999-10-12 15:35:26 34,576 -c--a-w c:\winnt\system32\dllcache\n1000nt5.sys + 1999-10-27 14:48:58 87,824 -c--a-w c:\winnt\system32\dllcache\n100nt5.sys + 1999-12-07 16:43:36 35,760 -c--a-w c:\winnt\system32\dllcache\n9i128.dll + 1999-09-25 10:37:12 13,936 -c--a-w c:\winnt\system32\dllcache\n9i128.sys + 1999-12-07 16:43:36 100,592 -c--a-w c:\winnt\system32\dllcache\n9i128v2.dll + 1999-09-25 10:37:14 33,392 -c--a-w c:\winnt\system32\dllcache\n9i128v2.sys + 1999-09-25 10:37:16 28,240 -c--a-w c:\winnt\system32\dllcache\n9i3d.sys + 1999-12-07 16:43:36 128,240 -c--a-w c:\winnt\system32\dllcache\n9i3disp.dll + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\narrator.exe + 2003-06-19 11:05:04 20,752 -c--a-w c:\winnt\system32\dllcache\nbtstat.exe + 1999-09-25 11:11:50 11,344 -c--a-w c:\winnt\system32\dllcache\ncrc710.sys + 2003-06-19 11:05:04 16,144 -c--a-w c:\winnt\system32\dllcache\nddeapi.dll + 2003-06-19 11:05:04 4,880 -c--a-w c:\winnt\system32\dllcache\nddeapir.exe + 2003-06-19 11:05:04 170,928 -c--a-w c:\winnt\system32\dllcache\ndis.sys + 2003-06-19 11:05:04 9,200 -c--a-w c:\winnt\system32\dllcache\ndistapi.sys + 2003-06-19 11:05:04 11,984 -c--a-w c:\winnt\system32\dllcache\ndisuio.sys + 2003-06-19 11:05:04 93,360 -c--a-w c:\winnt\system32\dllcache\ndiswan.sys + 1999-09-30 15:25:32 16,016 -c--a-w c:\winnt\system32\dllcache\ne2000.sys + 1999-12-07 16:43:36 60,944 -c--a-w c:\winnt\system32\dllcache\neo20xx.dll + 1999-10-18 14:39:12 39,888 -c--a-w c:\winnt\system32\dllcache\neo20xx.sys + 2003-06-19 11:05:04 124,176 -c--a-w c:\winnt\system32\dllcache\net1.exe + 1999-09-30 15:25:34 26,832 -c--a-w c:\winnt\system32\dllcache\netflx.sys + 1999-10-18 14:37:12 91,216 -c--a-w c:\winnt\system32\dllcache\netflx3.sys + 2003-06-19 11:05:04 131,344 -c--a-w c:\winnt\system32\dllcache\netid.dll + 2003-06-19 11:05:04 78,096 -c--a-w c:\winnt\system32\dllcache\netoc.dll + 2003-06-19 11:05:04 173,840 -c--a-w c:\winnt\system32\dllcache\netplwiz.dll + 2003-06-19 11:05:04 477,456 -c--a-w c:\winnt\system32\dllcache\netshell.dll + 2003-06-19 11:05:04 26,896 -c--a-w c:\winnt\system32\dllcache\netstat.exe + 2003-06-19 11:05:04 71,952 -c--a-w c:\winnt\system32\dllcache\netui0.dll + 2003-06-19 11:05:04 55,056 -c--a-w c:\winnt\system32\dllcache\nextlink.dll + 1999-09-24 19:17:08 30,992 -c--a-w c:\winnt\system32\dllcache\ngrpci.sys + 2003-06-19 11:05:04 89,600 -c--a-w c:\winnt\system32\dllcache\nlhtml.dll + 1999-10-06 16:17:14 111,920 -c--a-w c:\winnt\system32\dllcache\nm5a2wdm.sys + 1999-09-25 10:35:32 84,784 -c--a-w c:\winnt\system32\dllcache\nm6wdm.sys + 2003-06-19 11:05:04 212,240 -c--a-w c:\winnt\system32\dllcache\nmas.dll + 2003-06-19 11:05:04 136,464 -c--a-w c:\winnt\system32\dllcache\nmft.dll + 2003-06-19 11:05:04 37,552 -c--a-w c:\winnt\system32\dllcache\nmnt.sys + 2003-06-19 11:05:04 177,424 -c--a-w c:\winnt\system32\dllcache\nmwb.dll + 2005-11-29 15:27:06 364,544 -c--a-w c:\winnt\system32\dllcache\npdsplay.dll + 1999-09-30 15:26:18 35,600 -c--a-w c:\winnt\system32\dllcache\nscirda.sys + 2003-06-19 11:05:04 44,304 -c--a-w c:\winnt\system32\dllcache\nsepm.dll + 2003-06-19 11:05:04 88,336 -c--a-w c:\winnt\system32\dllcache\nslookup.exe + 2003-06-19 12:05:04 10,256 -c--a-w c:\winnt\system32\dllcache\nsmmc.sys + 1999-09-25 10:36:48 9,104 -c--a-w c:\winnt\system32\dllcache\ntapm.sys + 2003-06-19 11:05:04 1,164,048 -c--a-w c:\winnt\system32\dllcache\ntbackup.exe + 1999-11-05 13:40:04 28,272 -c--a-w c:\winnt\system32\dllcache\ntcx.sys - 2005-01-13 09:09:38 483,600 -c----w c:\winnt\system32\dllcache\ntdll.dll + 2005-08-16 09:39:00 483,600 -c--a-w c:\winnt\system32\dllcache\ntdll.dll + 2003-06-19 11:05:04 57,616 -c--a-w c:\winnt\system32\dllcache\ntdsapi.dll + 2003-06-19 11:05:04 32,016 -c--a-w c:\winnt\system32\dllcache\ntdsatq.dll + 2003-06-19 11:05:04 28,432 -c--a-w c:\winnt\system32\dllcache\ntdsbcli.dll + 2003-06-19 11:05:04 29,968 -c--a-w c:\winnt\system32\dllcache\ntdsbsrv.dll + 2003-06-19 11:05:04 67,344 -c--a-w c:\winnt\system32\dllcache\ntdsetup.dll + 2003-06-19 11:05:04 79,632 -c--a-w c:\winnt\system32\dllcache\ntdskcc.dll + 2003-06-19 11:05:04 165,136 -c--a-w c:\winnt\system32\dllcache\ntdsutil.exe + 1999-09-30 21:28:56 28,816 -c--a-w c:\winnt\system32\dllcache\ntepc.sys + 2003-06-19 11:05:04 196,671 -c--a-w c:\winnt\system32\dllcache\ntevt.dll + 2003-06-19 11:05:04 33,824 -c--a-w c:\winnt\system32\dllcache\ntio.sys + 2003-06-19 11:05:04 34,544 -c--a-w c:\winnt\system32\dllcache\ntio404.sys + 2003-06-19 11:05:04 35,648 -c--a-w c:\winnt\system32\dllcache\ntio411.sys + 2003-06-19 11:05:04 35,408 -c--a-w c:\winnt\system32\dllcache\ntio412.sys + 2003-06-19 11:05:04 34,544 -c--a-w c:\winnt\system32\dllcache\ntio804.sys + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\ntlsapi.dll + 2003-06-19 11:05:04 102,672 -c--a-w c:\winnt\system32\dllcache\ntmarta.dll + 2003-06-19 11:05:04 53,520 -c--a-w c:\winnt\system32\dllcache\ntmsapi.dll + 2003-06-19 11:05:04 173,328 -c--a-w c:\winnt\system32\dllcache\ntmsdba.dll + 2003-06-19 11:05:04 401,168 -c--a-w c:\winnt\system32\dllcache\ntmssvc.dll + 2003-06-19 11:05:04 46,352 -c--a-w c:\winnt\system32\dllcache\ntoc.dll + 2003-06-19 11:05:04 66,320 -c--a-w c:\winnt\system32\dllcache\ntprint.dll + 2003-06-19 11:05:04 85,776 -c--a-w c:\winnt\system32\dllcache\ntsdexts.dll + 1999-09-30 21:28:56 28,240 -c--a-w c:\winnt\system32\dllcache\ntxall.sys + 1999-09-30 21:28:56 26,480 -c--a-w c:\winnt\system32\dllcache\ntxem.sys + 1999-12-07 16:43:38 125,680 -c--a-w c:\winnt\system32\dllcache\nv3.dll + 1999-10-27 15:21:30 201,328 -c--a-w c:\winnt\system32\dllcache\nv3.sys + 1999-12-07 16:43:38 530,192 -c--a-w c:\winnt\system32\dllcache\nv4.dll + 1999-10-27 15:23:38 345,040 -c--a-w c:\winnt\system32\dllcache\nv4.sys + 2003-06-19 11:05:04 91,408 -c--a-w c:\winnt\system32\dllcache\nwlnkipx.sys + 2003-06-19 11:05:04 65,520 -c--a-w c:\winnt\system32\dllcache\nwlnknb.sys + 2003-06-19 11:05:04 214,800 -c--a-w c:\winnt\system32\dllcache\objsel.dll + 1999-10-27 15:17:34 38,960 -c--a-w c:\winnt\system32\dllcache\oca1pnd5.sys + 1999-10-27 15:18:42 41,648 -c--a-w c:\winnt\system32\dllcache\oca2pnd5.sys + 1999-09-24 19:17:14 35,600 -c--a-w c:\winnt\system32\dllcache\oce2xnd5.sys + 1999-09-24 19:17:14 23,824 -c--a-w c:\winnt\system32\dllcache\oce3xnd5.sys + 1999-09-30 15:02:34 31,984 -c--a-w c:\winnt\system32\dllcache\oce4xnd5.sys + 1999-10-17 12:12:28 57,936 -c--a-w c:\winnt\system32\dllcache\oce5xnd5.sys + 2003-06-19 11:05:04 57,104 -c--a-w c:\winnt\system32\dllcache\ocmanage.dll + 1999-09-24 19:17:14 175,376 -c--a-w c:\winnt\system32\dllcache\oct3xnd5.sys + 1999-09-24 19:17:16 65,808 -c--a-w c:\winnt\system32\dllcache\oct4pnd5.sys + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\odbc32gt.dll + 2003-06-19 11:05:04 37,136 -c--a-w c:\winnt\system32\dllcache\odbcad32.exe + 2003-06-19 11:05:04 41,232 -c--a-w c:\winnt\system32\dllcache\odbcconf.dll + 2003-06-19 11:05:04 41,232 -c--a-w c:\winnt\system32\dllcache\odbcconf.exe + 2003-06-19 11:05:04 196,880 -c--a-w c:\winnt\system32\dllcache\odbccr32.dll + 2003-06-19 11:05:04 200,976 -c--a-w c:\winnt\system32\dllcache\odbccu32.dll + 2003-06-19 11:05:04 90,112 -c--a-w c:\winnt\system32\dllcache\odbcint.dll + 2003-06-19 11:05:04 155,920 -c--a-w c:\winnt\system32\dllcache\odbctrac.dll + 2003-06-19 11:05:04 110,080 -c--a-w c:\winnt\system32\dllcache\offfilt.dll + 2003-06-19 12:05:04 37,680 -c--a-w c:\winnt\system32\dllcache\ohci1394.sys + 2003-06-19 11:05:04 65,808 -c--a-w c:\winnt\system32\dllcache\oledb32r.dll + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\oledb32x.dll + 2003-06-19 11:05:04 106,256 -c--a-w c:\winnt\system32\dllcache\oleprn.dll + 2003-06-19 11:05:04 164,112 -c--a-w c:\winnt\system32\dllcache\olepro32.dll + 2003-06-19 11:05:04 70,928 -c--a-w c:\winnt\system32\dllcache\olethk32.dll + 2003-06-19 11:05:04 692,496 -c--a-w c:\winnt\system32\dllcache\opengl32.dll + 2003-06-19 12:05:04 24,784 -c--a-w c:\winnt\system32\dllcache\openhci.sys + 1999-11-02 17:27:48 54,960 -c--a-w c:\winnt\system32\dllcache\opl3sax.sys + 2003-06-19 11:05:04 221,456 -c--a-w c:\winnt\system32\dllcache\osk.exe + 1999-09-24 19:17:16 43,792 -c--a-w c:\winnt\system32\dllcache\otceth5.sys + 1999-11-30 23:39:36 56,592 -c--a-w c:\winnt\system32\dllcache\p6xx_32.dll + 1999-11-30 23:39:36 9,488 -c--a-w c:\winnt\system32\dllcache\p6xxusd.dll + 2003-06-19 11:05:04 53,008 -c--a-w c:\winnt\system32\dllcache\packager.exe + 2003-06-19 11:05:04 35,088 -c--a-w c:\winnt\system32\dllcache\pagecnt.dll + 2003-06-19 11:05:04 60,208 -c--a-w c:\winnt\system32\dllcache\parallel.sys + 2003-06-19 11:05:04 25,104 -c--a-w c:\winnt\system32\dllcache\parport.sys + 2003-06-19 11:05:04 11,792 -c--a-w c:\winnt\system32\dllcache\partmgr.sys + 1999-09-24 19:17:08 24,016 -c--a-w c:\winnt\system32\dllcache\pc100nds.sys + 1999-09-24 19:17:00 30,064 -c--a-w c:\winnt\system32\dllcache\pca200e.sys + 2003-06-19 11:05:04 59,312 -c--a-w c:\winnt\system32\dllcache\pci.sys + 2003-06-19 11:05:04 3,088 -c--a-w c:\winnt\system32\dllcache\pciide.sys + 2003-06-19 11:05:04 22,064 -c--a-w c:\winnt\system32\dllcache\pciidex.sys + 1999-09-24 19:17:34 54,224 -c--a-w c:\winnt\system32\dllcache\pcimac.sys + 2003-06-19 11:05:04 109,584 -c--a-w c:\winnt\system32\dllcache\pcmcia.sys + 1999-09-24 19:16:56 28,944 -c--a-w c:\winnt\system32\dllcache\pcntn5hl.sys + 1999-11-03 17:29:32 29,968 -c--a-w c:\winnt\system32\dllcache\pcntn5m.sys + 1999-10-04 13:53:48 35,088 -c--a-w c:\winnt\system32\dllcache\pcx500.sys + 2003-06-19 11:05:04 151,824 -c--a-w c:\winnt\system32\dllcache\pdh.dll + 1999-11-30 23:40:10 108,304 -c--a-w c:\winnt\system32\dllcache\peer.exe + 2003-06-19 11:05:04 42,256 -c--a-w c:\winnt\system32\dllcache\perfctrs.dll + 2003-06-19 11:05:04 24,848 -c--a-w c:\winnt\system32\dllcache\perfdisk.dll + 2003-06-19 11:05:04 29,456 -c--a-w c:\winnt\system32\dllcache\perfproc.dll + 1999-10-29 12:23:46 26,576 -c--a-w c:\winnt\system32\dllcache\perm2.sys + 1999-12-07 16:43:38 142,320 -c--a-w c:\winnt\system32\dllcache\perm2dll.dll + 1999-11-30 23:39:36 40,720 -c--a-w c:\winnt\system32\dllcache\philcam1.dll + 1999-11-03 17:22:38 77,072 -c--a-w c:\winnt\system32\dllcache\philcam1.sys + 1999-11-30 23:39:36 30,480 -c--a-w c:\winnt\system32\dllcache\pid.dll + 2000-07-26 17:00:00 13,072 -c--a-w c:\winnt\system32\dllcache\pjlmon.dll + 2003-06-19 12:05:04 11,120 -c--a-w c:\winnt\system32\dllcache\plasmc.sys + 2003-06-19 12:05:04 9,808 -c--a-w c:\winnt\system32\dllcache\pnrmc.sys + 2003-06-19 11:05:04 148,208 -c--a-w c:\winnt\system32\dllcache\portcls.sys + 1999-11-30 23:40:12 149,264 -c--a-w c:\winnt\system32\dllcache\portmon.exe + 2003-06-19 11:05:04 13,584 -c--a-w c:\winnt\system32\dllcache\powrprof.dll + 2003-06-19 12:05:04 17,520 -c--a-w c:\winnt\system32\dllcache\ppa.sys + 2003-06-19 12:05:04 16,048 -c--a-w c:\winnt\system32\dllcache\ppa3.sys + 2003-06-19 11:05:04 381,712 -c--a-w c:\winnt\system32\dllcache\printui.dll + 2003-06-19 11:05:04 60,496 -c--a-w c:\winnt\system32\dllcache\psched.sys + 1999-09-25 10:36:34 16,240 -c--a-w c:\winnt\system32\dllcache\pscr.sys + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\ptilink.sys + 2003-06-19 11:05:04 378,128 -c--a-w c:\winnt\system32\dllcache\pws.exe + 2003-06-19 11:05:04 7,952 -c--a-w c:\winnt\system32\dllcache\pwsdata.dll + 2003-06-19 11:05:04 32,016 -c--a-w c:\winnt\system32\dllcache\pwstray.exe + 2003-06-19 11:05:04 166,672 -c--a-w c:\winnt\system32\dllcache\qcap.dll + 1999-10-21 11:34:10 5,008 -c--a-w c:\winnt\system32\dllcache\qic157.sys + 1999-09-25 11:11:46 40,464 -c--a-w c:\winnt\system32\dllcache\ql1080.sys + 1999-09-25 11:11:46 33,488 -c--a-w c:\winnt\system32\dllcache\ql10wnt.sys + 1999-09-25 11:11:46 40,592 -c--a-w c:\winnt\system32\dllcache\ql1240.sys + 1999-09-25 11:11:46 64,400 -c--a-w c:\winnt\system32\dllcache\ql2100.sys + 2003-06-19 12:05:04 10,768 -c--a-w c:\winnt\system32\dllcache\qlstrmc.sys + 2003-06-19 12:05:04 8,848 -c--a-w c:\winnt\system32\dllcache\qntmmc.sys - 1999-02-23 13:07:14 155,648 -c--a-w c:\winnt\system32\dllcache\qtest32.exe + 1999-02-23 14:07:14 155,648 -c--a-w c:\winnt\system32\dllcache\qtest32.exe - 1998-01-16 15:54:24 31,744 -c--a-w c:\winnt\system32\dllcache\qtestm32.dll + 1998-01-16 16:54:24 31,744 -c--a-w c:\winnt\system32\dllcache\qtestm32.dll + 1999-12-07 16:43:38 41,776 -c--a-w c:\winnt\system32\dllcache\qv.dll + 1999-09-25 10:36:58 28,592 -c--a-w c:\winnt\system32\dllcache\qv.sys + 1999-11-30 23:39:38 20,240 -c--a-w c:\winnt\system32\dllcache\qvusd.dll + 2003-06-19 11:05:04 25,360 -c--a-w c:\winnt\system32\dllcache\rapilib.dll + 2003-06-19 11:05:04 77,584 -c--a-w c:\winnt\system32\dllcache\rasauto.dll + 2003-06-19 11:05:04 60,688 -c--a-w c:\winnt\system32\dllcache\raschap.dll + 2003-06-19 11:05:04 19,920 -c--a-w c:\winnt\system32\dllcache\rasirda.sys + 2003-06-19 11:05:04 52,112 -c--a-w c:\winnt\system32\dllcache\rasl2tp.sys + 2003-06-19 11:05:04 154,896 -c--a-w c:\winnt\system32\dllcache\rasmontr.dll + 2003-06-19 11:05:04 198,928 -c--a-w c:\winnt\system32\dllcache\rasppp.dll + 2003-06-19 11:05:04 48,464 -c--a-w c:\winnt\system32\dllcache\raspptp.sys + 2003-06-19 11:05:04 14,608 -c--a-w c:\winnt\system32\dllcache\rassapi.dll + 2003-06-19 11:05:04 54,032 -c--a-w c:\winnt\system32\dllcache\rastapi.dll + 2003-06-19 11:05:04 100,624 -c--a-w c:\winnt\system32\dllcache\rastls.dll + 2000-07-26 17:00:00 21,712 -c--a-w c:\winnt\system32\dllcache\rca.sys + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\recover.exe + 2003-06-19 11:05:04 35,344 -c--a-w c:\winnt\system32\dllcache\redbook.sys + 1999-11-30 23:39:40 12,560 -c--a-w c:\winnt\system32\dllcache\reg32.dll + 2003-06-19 11:05:04 36,112 -c--a-w c:\winnt\system32\dllcache\regapi.dll + 2003-06-19 11:05:04 73,488 -c--a-w c:\winnt\system32\dllcache\regedit.exe + 2003-06-19 11:05:04 139,536 -c--a-w c:\winnt\system32\dllcache\regedt32.exe + 2003-06-19 11:05:04 68,368 -c--a-w c:\winnt\system32\dllcache\regsvc.exe + 2003-06-19 11:05:04 11,024 -c--a-w c:\winnt\system32\dllcache\regsvr32.exe + 2003-06-19 11:05:04 105,232 -c--a-w c:\winnt\system32\dllcache\rend.dll + 2003-06-19 11:05:04 40,720 -c--a-w c:\winnt\system32\dllcache\resutils.dll + 1999-09-24 19:17:16 37,808 -c--a-w c:\winnt\system32\dllcache\rlnet5.sys + 1999-09-25 10:36:36 13,680 -c--a-w c:\winnt\system32\dllcache\rnbo3531.sys + 2003-06-19 11:05:04 36,624 -c--a-w c:\winnt\system32\dllcache\rnr20.dll + 1997-07-11 01:39:14 36,480 -c--a-w c:\winnt\system32\dllcache\rnsfnet.sys + 1999-09-24 19:17:32 71,216 -c--a-w c:\winnt\system32\dllcache\rocket.sys + 2003-06-19 11:05:04 22,800 -c--a-w c:\winnt\system32\dllcache\routeext.dll + 2003-06-19 11:05:04 24,336 -c--a-w c:\winnt\system32\dllcache\rpcns4.dll - 2004-03-10 17:29:26 16,656 -c----w c:\winnt\system32\dllcache\rpcproxy.dll + 2003-06-19 11:05:04 16,656 -c--a-w c:\winnt\system32\dllcache\rpcproxy.dll + 2003-06-19 11:05:04 4,368 -c--a-w c:\winnt\system32\dllcache\rpcref.dll + 2003-06-19 11:05:04 132,368 -c--a-w c:\winnt\system32\dllcache\rsabase.dll + 2003-06-19 11:05:04 134,928 -c--a-w c:\winnt\system32\dllcache\rsaenh.dll + 2003-06-19 11:05:04 25,360 -c--a-w c:\winnt\system32\dllcache\rsfsaps.dll + 2003-06-19 11:05:04 14,096 -c--a-w c:\winnt\system32\dllcache\rsh.exe + 2003-06-19 11:05:04 35,088 -c--a-w c:\winnt\system32\dllcache\rshx32.dll + 2003-06-19 11:05:04 44,816 -c--a-w c:\winnt\system32\dllcache\rsm.exe + 2003-06-19 11:05:04 108,304 -c--a-w c:\winnt\system32\dllcache\rsnotify.exe + 2003-06-19 11:05:04 176,912 -c--a-w c:\winnt\system32\dllcache\rsvp.exe + 2003-06-19 11:05:04 77,072 -c--a-w c:\winnt\system32\dllcache\rsvpsp.dll + 1999-09-24 19:17:16 18,704 -c--a-w c:\winnt\system32\dllcache\rtl8029.sys + 1999-09-24 19:17:18 18,704 -c--a-w c:\winnt\system32\dllcache\rtl8139.sys + 2003-06-19 11:05:04 97,040 -c--a-w c:\winnt\system32\dllcache\rtm.dll + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\runas.exe + 1999-12-07 16:43:38 64,624 -c--a-w c:\winnt\system32\dllcache\s3legacy.dll + 1999-09-25 10:37:28 65,456 -c--a-w c:\winnt\system32\dllcache\s3legacy.sys + 1999-11-19 14:20:02 168,112 -c--a-w c:\winnt\system32\dllcache\s3m.sys + 1999-12-07 16:43:40 293,456 -c--a-w c:\winnt\system32\dllcache\s3mt3d.dll + 1999-10-29 13:11:42 41,008 -c--a-w c:\winnt\system32\dllcache\s3mt3d.sys + 1999-12-07 16:43:40 61,968 -c--a-w c:\winnt\system32\dllcache\s3mtrio.dll + 1999-12-07 16:43:40 304,688 -c--a-w c:\winnt\system32\dllcache\s3mvirge.dll + 1999-12-07 16:43:40 213,776 -c--a-w c:\winnt\system32\dllcache\s3sav3d.dll + 1999-09-30 17:13:08 62,960 -c--a-w c:\winnt\system32\dllcache\s3sav3dm.sys + 1999-12-07 16:43:40 246,256 -c--a-w c:\winnt\system32\dllcache\s3sav4.dll + 1999-10-25 15:35:34 65,072 -c--a-w c:\winnt\system32\dllcache\s3sav4m.sys + 1999-09-24 19:17:20 16,048 -c--a-w c:\winnt\system32\dllcache\s53c885.sys + 2003-06-19 11:05:04 67,856 -c--a-w c:\winnt\system32\dllcache\savedump.exe + 2003-06-19 12:05:04 35,760 -c--a-w c:\winnt\system32\dllcache\sbp2port.sys + 2003-06-19 11:05:04 100,112 -c--a-w c:\winnt\system32\dllcache\scardsvr.exe + 2007-04-25 07:52:16 147,216 -c--a-w c:\winnt\system32\dllcache\schannel.dll + 2003-06-19 11:05:04 20,752 -c--a-w c:\winnt\system32\dllcache\sclgntfy.dll + 1999-09-25 10:36:38 16,976 -c--a-w c:\winnt\system32\dllcache\scmstcs.sys + 2003-06-19 11:05:04 159,820 -c--a-w c:\winnt\system32\dllcache\scrcons.exe + 2003-06-19 11:05:04 77,584 -c--a-w c:\winnt\system32\dllcache\scripto.dll + 2003-06-19 12:05:04 11,632 -c--a-w c:\winnt\system32\dllcache\scsiprnt.sys + 2003-06-19 12:05:04 9,392 -c--a-w c:\winnt\system32\dllcache\seaddsmc.sys + 2003-06-19 11:05:04 17,168 -c--a-w c:\winnt\system32\dllcache\secedit.exe + 2003-06-19 11:05:04 48,912 -c--a-w c:\winnt\system32\dllcache\secur32.dll + 2003-06-19 11:05:04 38,160 -c--a-w c:\winnt\system32\dllcache\sens.dll + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\sensapi.dll + 2003-06-19 11:05:04 14,160 -c--a-w c:\winnt\system32\dllcache\serenum.sys + 2003-06-19 11:05:04 62,736 -c--a-w c:\winnt\system32\dllcache\serial.sys + 1999-09-25 10:34:52 17,136 -c--a-w c:\winnt\system32\dllcache\sermouse.sys + 1999-09-25 10:36:08 6,736 -c--a-w c:\winnt\system32\dllcache\serscan.sys + 2003-06-19 11:05:04 65,601 -c--a-w c:\winnt\system32\dllcache\servdeps.dll + 2003-06-19 11:05:04 570,128 -c--a-w c:\winnt\system32\dllcache\setupapi.dll + 2003-06-19 11:05:04 99,600 -c--a-w c:\winnt\system32\dllcache\setupqry.dll + 2003-06-19 11:05:04 95,024 -c--a-w c:\winnt\system32\dllcache\sfc.dll + 2003-06-19 11:05:04 10,384 -c--a-w c:\winnt\system32\dllcache\sfloppy.sys + 2003-06-19 11:05:04 148,400 -c--a-w c:\winnt\system32\dllcache\sfmatalk.sys + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\sfmpsprt.dll + 1999-12-07 16:43:40 493,424 -c--a-w c:\winnt\system32\dllcache\sgiul50.dll + 1999-10-29 15:25:32 97,808 -c--a-w c:\winnt\system32\dllcache\sgiulnt5.sys + 2000-07-26 17:00:00 9,136 -c--a-w c:\winnt\system32\dllcache\sglfb.dll + 2000-07-26 17:00:00 6,992 -c--a-w c:\winnt\system32\dllcache\sglfb.sys + 2003-06-19 11:05:04 11,536 -c--a-w c:\winnt\system32\dllcache\shcmn.dll + 2003-06-19 11:05:04 69,392 -c--a-w c:\winnt\system32\dllcache\shim.dll + 2003-06-19 11:05:04 33,552 -c--a-w c:\winnt\system32\dllcache\shmgrate.exe + 2003-03-24 16:52:04 20,536 -c--a-w c:\winnt\system32\dllcache\shtml.dll + 2003-03-24 16:52:04 16,437 -c--a-w c:\winnt\system32\dllcache\shtml.exe + 1999-10-29 15:28:02 52,272 -c--a-w c:\winnt\system32\dllcache\sis300p.sys + 1999-12-07 16:43:40 190,512 -c--a-w c:\winnt\system32\dllcache\sis300v.dll + 1999-09-27 20:02:18 71,280 -c--a-w c:\winnt\system32\dllcache\sis6306p.sys + 1999-12-07 16:43:40 179,792 -c--a-w c:\winnt\system32\dllcache\sis6306v.dll + 2003-06-19 11:05:04 15,120 -c--a-w c:\winnt\system32\dllcache\sisbkup.dll + 1999-09-27 20:02:18 49,904 -c--a-w c:\winnt\system32\dllcache\sisv.sys + 1999-12-07 16:43:40 188,688 -c--a-w c:\winnt\system32\dllcache\sisv256.dll + 1999-11-07 15:40:44 91,920 -c--a-w c:\winnt\system32\dllcache\sk98win.sys + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\skdll.dll + 2003-06-19 11:05:04 45,840 -c--a-w c:\winnt\system32\dllcache\skeys.exe + 2003-06-19 12:05:04 104,656 -c--a-w c:\winnt\system32\dllcache\skfpwin.sys + 1999-08-10 15:59:20 52,736 -c--a-w c:\winnt\system32\dllcache\slant.sys + 1999-11-30 23:39:44 19,728 -c--a-w c:\winnt\system32\dllcache\slpp.dll + 1999-11-30 23:39:44 24,848 -c--a-w c:\winnt\system32\dllcache\sm5932.dll + 1999-11-30 23:39:44 32,528 -c--a-w c:\winnt\system32\dllcache\sm8132.dll + 1999-11-30 23:39:44 32,016 -c--a-w c:\winnt\system32\dllcache\sm8732.dll + 1999-11-30 23:39:44 23,824 -c--a-w c:\winnt\system32\dllcache\sm8932.dll + 1999-11-30 23:39:44 23,824 -c--a-w c:\winnt\system32\dllcache\sm8a32.dll + 1999-11-30 23:39:44 25,872 -c--a-w c:\winnt\system32\dllcache\sm8c32.dll + 1999-11-30 23:39:44 23,824 -c--a-w c:\winnt\system32\dllcache\sm8d32.dll + 1999-11-30 23:39:44 23,824 -c--a-w c:\winnt\system32\dllcache\sm9032.dll + 1999-11-30 23:39:44 25,872 -c--a-w c:\winnt\system32\dllcache\sm9132.dll + 1999-11-30 23:39:44 28,432 -c--a-w c:\winnt\system32\dllcache\sma032.dll + 2003-06-19 12:05:04 27,376 -c--a-w c:\winnt\system32\dllcache\smbbatt.sys + 1999-09-25 10:35:10 6,096 -c--a-w c:\winnt\system32\dllcache\smbclass.sys + 1999-09-25 10:35:12 6,576 -c--a-w c:\winnt\system32\dllcache\smbhc.sys + 1999-09-24 19:17:18 23,824 -c--a-w c:\winnt\system32\dllcache\smc8000n.sys + 1999-09-24 19:18:02 36,112 -c--a-w c:\winnt\system32\dllcache\smcirda.sys + 1999-09-24 19:17:18 21,008 -c--a-w c:\winnt\system32\dllcache\smcpwr2n.sys + 2003-06-19 11:05:04 285,456 -c--a-w c:\winnt\system32\dllcache\smlogcfg.dll + 2003-06-19 11:05:04 85,776 -c--a-w c:\winnt\system32\dllcache\smlogsvc.exe + 2003-06-19 11:05:04 45,840 -c--a-w c:\winnt\system32\dllcache\smss.exe - 2000-07-06 19:03:58 6,416 -c--a-w c:\winnt\system32\dllcache\smtp_adsiisex.dll + 2003-06-19 19:44:54 6,416 -c--a-w c:\winnt\system32\dllcache\smtp_adsiisex.dll + 2003-06-19 19:44:54 45,328 -c--a-w c:\winnt\system32\dllcache\smtp_aqadmin.dll + 2003-06-19 19:44:54 322,320 -c--a-w c:\winnt\system32\dllcache\smtp_aqueue.dll + 2003-06-19 11:05:04 402,704 -c--a-w c:\winnt\system32\dllcache\smtp_cdonts.dll + 2003-06-19 19:44:58 15,632 -c--a-w c:\winnt\system32\dllcache\smtp_dt_ctrl.dll + 2003-06-19 19:45:00 44,816 -c--a-w c:\winnt\system32\dllcache\smtp_fcachdll.dll + 2003-06-19 19:45:04 67,344 -c--a-w c:\winnt\system32\dllcache\smtp_mailmsg.dll + 2003-06-19 19:45:10 38,672 -c--a-w c:\winnt\system32\dllcache\smtp_ntfsdrv.dll - 2000-06-21 20:00:36 24,336 -c--a-w c:\winnt\system32\dllcache\smtp_regtrace.exe + 2003-06-19 19:45:28 24,336 -c--a-w c:\winnt\system32\dllcache\smtp_regtrace.exe + 2003-06-19 19:45:12 11,024 -c--a-w c:\winnt\system32\dllcache\smtp_rwnh.dll + 2003-06-19 19:45:14 77,584 -c--a-w c:\winnt\system32\dllcache\smtp_scripto.dll + 2003-06-19 19:45:14 234,768 -c--a-w c:\winnt\system32\dllcache\smtp_seo.dll - 2000-07-06 19:04:36 26,896 -c--a-w c:\winnt\system32\dllcache\smtp_seos.dll + 2003-06-19 19:45:14 26,896 -c--a-w c:\winnt\system32\dllcache\smtp_seos.dll + 2003-06-19 19:45:14 183,568 -c--a-w c:\winnt\system32\dllcache\smtp_smtpadm.dll + 2003-06-19 19:45:14 11,024 -c--a-w c:\winnt\system32\dllcache\smtp_smtpapi.dll + 2003-06-19 19:45:14 13,584 -c--a-w c:\winnt\system32\dllcache\smtp_smtpctrs.dll - 2000-06-14 12:33:08 7,952 -c--a-w c:\winnt\system32\dllcache\smtp_smtpmib.dll + 2003-06-19 19:45:14 7,952 -c--a-w c:\winnt\system32\dllcache\smtp_smtpmib.dll + 2003-06-19 19:45:16 2,533,648 -c--a-w c:\winnt\system32\dllcache\smtp_smtpsnap.dll + 2003-06-19 19:45:16 444,176 -c--a-w c:\winnt\system32\dllcache\smtp_smtpsvc.dll - 2000-06-21 20:00:30 7,952 -c--a-w c:\winnt\system32\dllcache\smtp_snprfdll.dll + 2003-06-19 19:45:16 7,952 -c--a-w c:\winnt\system32\dllcache\smtp_snprfdll.dll + 2003-06-19 11:05:04 159,841 -c--a-w c:\winnt\system32\dllcache\smtpcons.dll + 2003-06-19 11:05:04 107,792 -c--a-w c:\winnt\system32\dllcache\sndrec32.exe + 2003-06-19 11:05:04 30,480 -c--a-w c:\winnt\system32\dllcache\snmp.exe + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\snmpapi.dll + 2003-06-19 11:05:04 214,288 -c--a-w c:\winnt\system32\dllcache\snmpsnap.dll + 2003-06-19 11:05:04 7,952 -c--a-w c:\winnt\system32\dllcache\snmptrap.exe + 2003-06-19 12:05:04 9,776 -c--a-w c:\winnt\system32\dllcache\snyaitmc.sys + 2003-06-19 11:05:04 120,448 -c--a-w c:\winnt\system32\dllcache\softkey.dll + 1999-11-08 16:38:30 63,024 -c--a-w c:\winnt\system32\dllcache\solo.sys + 1999-10-21 11:34:10 6,256 -c--a-w c:\winnt\system32\dllcache\sonyait.sys + 2003-06-19 11:05:04 22,064 -c--a-w c:\winnt\system32\dllcache\sonydcam.sys + 2003-06-19 12:05:04 12,432 -c--a-w c:\winnt\system32\dllcache\sonymc.sys + 2003-06-19 11:05:04 5,632 -c--a-w c:\winnt\system32\dllcache\sp2res.dll + 1999-09-28 15:14:04 19,376 -c--a-w c:\winnt\system32\dllcache\sparrow.sys + 2003-06-19 11:05:04 187,024 -c--a-w c:\winnt\system32\dllcache\spcmdcon.sys + 2003-06-19 12:05:04 10,160 -c--a-w c:\winnt\system32\dllcache\spctramc.sys + 1999-11-30 23:39:46 420,624 -c--a-w c:\winnt\system32\dllcache\spxports.dll + 1999-11-30 23:39:46 25,872 -c--a-w c:\winnt\system32\dllcache\srusd.dll + 2003-06-19 11:05:04 41,232 -c--a-w c:\winnt\system32\dllcache\ssinc.dll + 2003-06-19 11:05:04 43,792 -c--a-w c:\winnt\system32\dllcache\sspifilt.dll + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\staxmem.dll + 1999-10-13 15:21:58 16,400 -c--a-w c:\winnt\system32\dllcache\stcusb.sys + 2003-06-19 11:05:04 180,312 -c--a-w c:\winnt\system32\dllcache\stdprov.dll + 2003-06-19 11:05:04 41,744 -c--a-w c:\winnt\system32\dllcache\sti.dll + 2003-06-19 11:05:04 21,264 -c--a-w c:\winnt\system32\dllcache\stimon.exe + 2003-06-19 11:05:04 61,712 -c--a-w c:\winnt\system32\dllcache\stisvc.exe + 1999-11-30 23:39:46 186,640 -c--a-w c:\winnt\system32\dllcache\stivs32.dll + 2003-06-19 12:05:04 10,288 -c--a-w c:\winnt\system32\dllcache\stkmc.sys + 1999-11-03 08:37:36 280,912 -c--a-w c:\winnt\system32\dllcache\stlnata.sys + 1999-11-30 23:39:46 176,400 -c--a-w c:\winnt\system32\dllcache\stlnprop.dll + 2003-06-19 11:05:04 81,168 -c--a-w c:\winnt\system32\dllcache\stobject.dll + 2003-06-19 11:05:04 35,600 -c--a-w c:\winnt\system32\dllcache\storprop.dll + 2003-06-19 11:05:04 42,000 -c--a-w c:\winnt\system32\dllcache\stream.sys + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\subst.exe + 2003-06-19 11:05:04 40,720 -c--a-w c:\winnt\system32\dllcache\svcext.dll + 2000-07-26 17:00:00 7,952 -c--a-w c:\winnt\system32\dllcache\svchost.exe + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\svcpack.dll + 1999-11-30 23:39:48 45,328 -c--a-w c:\winnt\system32\dllcache\sw_effct.dll + 1999-11-30 23:39:48 60,176 -c--a-w c:\winnt\system32\dllcache\sw_wheel.dll + 2000-07-26 17:00:00 3,728 -c--a-w c:\winnt\system32\dllcache\swenum.sys + 2003-06-19 11:05:04 53,552 -c--a-w c:\winnt\system32\dllcache\swmidi.sys + 1999-09-30 21:29:18 97,936 -c--a-w c:\winnt\system32\dllcache\sx.sys + 1999-09-25 11:11:50 21,136 -c--a-w c:\winnt\system32\dllcache\sym_hi.sys + 1999-09-25 11:11:50 16,624 -c--a-w c:\winnt\system32\dllcache\symc810.sys + 2003-06-19 12:05:04 27,120 -c--a-w c:\winnt\system32\dllcache\symc8xx.sys + 1999-11-30 23:39:48 346,624 -c--a-w c:\winnt\system32\dllcache\syncprop.dll + 2003-06-19 11:05:04 47,568 -c--a-w c:\winnt\system32\dllcache\sysaudio.sys + 2003-06-19 11:05:04 509,712 -c--a-w c:\winnt\system32\dllcache\syssetup.dll + 1999-12-07 16:43:40 251,312 -c--a-w c:\winnt\system32\dllcache\t2r4disp.dll + 1999-10-14 17:04:24 37,104 -c--a-w c:\winnt\system32\dllcache\t2r4mini.sys + 1999-10-21 11:34:10 7,344 -c--a-w c:\winnt\system32\dllcache\tandqic.sys + 2003-06-19 11:05:04 10,928 -c--a-w c:\winnt\system32\dllcache\tape.sys + 2003-06-19 11:05:04 375,568 -c--a-w c:\winnt\system32\dllcache\tapi3.dll + 2003-06-19 11:05:04 126,736 -c--a-w c:\winnt\system32\dllcache\tapi32.dll + 2003-06-19 11:05:04 87,312 -c--a-w c:\winnt\system32\dllcache\taskmgr.exe + 1999-10-09 12:37:26 29,872 -c--a-w c:\winnt\system32\dllcache\tbatm155.sys + 2003-06-19 11:05:04 13,072 -c--a-w c:\winnt\system32\dllcache\tcpmib.dll + 2003-06-19 11:05:04 41,744 -c--a-w c:\winnt\system32\dllcache\tcpmon.dll + 2003-06-19 11:05:04 66,832 -c--a-w c:\winnt\system32\dllcache\tcpmonui.dll + 2003-03-24 16:52:04 32,827 -c--a-w c:\winnt\system32\dllcache\tcptest.exe + 2003-03-24 16:52:06 16,384 -c--a-w c:\winnt\system32\dllcache\tcptsat.dll + 2003-06-19 11:05:04 16,240 -c--a-w c:\winnt\system32\dllcache\tdi.sys + 2003-06-19 11:05:04 80,144 -c--a-w c:\winnt\system32\dllcache\telnet.exe + 1999-09-27 19:56:14 72,784 -c--a-w c:\winnt\system32\dllcache\tffsport.sys + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\tftp.exe + 1999-12-07 16:43:42 79,024 -c--a-w c:\winnt\system32\dllcache\tgiul50.dll + 1999-10-29 15:25:36 141,136 -c--a-w c:\winnt\system32\dllcache\tgiulnt5.sys + 2003-06-19 11:05:04 187,664 -c--a-w c:\winnt\system32\dllcache\thumbvw.dll + 1999-09-24 19:18:00 123,856 -c--a-w c:\winnt\system32\dllcache\tjisdn.sys + 2003-06-19 11:05:04 55,056 -c--a-w c:\winnt\system32\dllcache\tlntsess.exe + 2003-06-19 11:05:04 186,128 -c--a-w c:\winnt\system32\dllcache\tlntsvr.exe + 1999-10-20 14:49:22 28,432 -c--a-w c:\winnt\system32\dllcache\tos4mo.sys + 1999-09-24 19:18:02 33,552 -c--a-w c:\winnt\system32\dllcache\tos4mu.sys + 2000-07-26 17:00:00 52,048 -c--a-w c:\winnt\system32\dllcache\tosdvd.sys + 1999-10-06 15:50:16 242,256 -c--a-w c:\winnt\system32\dllcache\tosdvd02.sys + 1999-10-06 15:50:52 231,408 -c--a-w c:\winnt\system32\dllcache\tosdvd03.sys + 1999-11-30 23:39:48 35,088 -c--a-w c:\winnt\system32\dllcache\tp4.dll + 1999-11-30 23:40:16 86,288 -c--a-w c:\winnt\system32\dllcache\tp4mon.exe + 1999-11-30 01:34:36 28,672 -c--a-w c:\winnt\system32\dllcache\tp4res.dll + 1999-10-21 10:49:38 34,576 -c--a-w c:\winnt\system32\dllcache\tpro4.sys + 2003-06-19 11:05:04 31,504 -c--a-w c:\winnt\system32\dllcache\traffic.dll + 1999-12-07 16:43:42 277,520 -c--a-w c:\winnt\system32\dllcache\trid3d.dll + 1999-11-19 14:11:26 191,888 -c--a-w c:\winnt\system32\dllcache\trid3dm.sys + 1999-12-07 16:43:42 523,408 -c--a-w c:\winnt\system32\dllcache\tridkb.dll + 1999-11-19 14:11:26 154,384 -c--a-w c:\winnt\system32\dllcache\tridkbm.sys + 2003-06-19 11:05:04 90,384 -c--a-w c:\winnt\system32\dllcache\trkwks.dll + 1999-09-24 19:17:20 17,712 -c--a-w c:\winnt\system32\dllcache\tsbmce.sys + 2000-07-26 17:00:00 22,000 -c--a-w c:\winnt\system32\dllcache\tsbvcap.sys + 2000-07-26 17:00:00 12,560 -c--a-w c:\winnt\system32\dllcache\tsbyuv.dll + 1999-09-25 10:34:56 7,568 -c--a-w c:\winnt\system32\dllcache\twotrack.sys + 1999-11-30 01:34:38 484,112 -c--a-w c:\winnt\system32\dllcache\twrc120.dll + 1999-11-30 01:34:38 804,112 -c--a-w c:\winnt\system32\dllcache\twrc200.dll + 1999-11-30 23:39:50 165,648 -c--a-w c:\winnt\system32\dllcache\twui120.dll + 1999-11-30 23:39:50 323,856 -c--a-w c:\winnt\system32\dllcache\twui200.dll + 1999-11-30 23:39:50 61,200 -c--a-w c:\winnt\system32\dllcache\u1220_32.dll + 1999-11-30 23:39:50 9,488 -c--a-w c:\winnt\system32\dllcache\u1220usd.dll + 2003-06-19 11:05:04 83,216 -c--a-w c:\winnt\system32\dllcache\ufat.dll + 2003-06-19 11:05:04 32,848 -c--a-w c:\winnt\system32\dllcache\uhcd.sys + 2003-06-19 11:05:04 261,392 -c--a-w c:\winnt\system32\dllcache\ulib.dll + 1999-09-25 11:11:48 33,296 -c--a-w c:\winnt\system32\dllcache\ultra66.sys + 1999-09-25 10:51:26 23,472 -c--a-w c:\winnt\system32\dllcache\umaxpcls.sys + 1999-11-30 23:39:50 8,976 -c--a-w c:\winnt\system32\dllcache\umaxusd.dll + 2003-06-19 11:05:04 74,000 -c--a-w c:\winnt\system32\dllcache\uniime.dll + 2003-06-19 11:05:04 68,368 -c--a-w c:\winnt\system32\dllcache\unimdmat.dll + 2003-06-19 11:05:04 14,608 -c--a-w c:\winnt\system32\dllcache\uniplat.dll + 2002-12-11 15:08:28 192,512 -c--a-w c:\winnt\system32\dllcache\unregmp2.exe + 2003-06-19 11:05:04 32,837 -c--a-w c:\winnt\system32\dllcache\unsecapp.exe + 2003-06-19 11:05:04 173,232 -c--a-w c:\winnt\system32\dllcache\update.sys + 1999-10-12 15:57:12 68,912 -c--a-w c:\winnt\system32\dllcache\usbaudio.sys + 2000-07-26 17:00:00 23,888 -c--a-w c:\winnt\system32\dllcache\usbcamd.sys + 2003-06-19 11:05:04 20,688 -c--a-w c:\winnt\system32\dllcache\usbd.sys + 2003-06-19 11:05:04 40,176 -c--a-w c:\winnt\system32\dllcache\usbhub.sys + 2000-07-26 17:00:00 15,120 -c--a-w c:\winnt\system32\dllcache\usbintel.sys + 2003-06-19 11:05:04 11,536 -c--a-w c:\winnt\system32\dllcache\usbmon.dll + 2003-06-19 11:05:04 21,872 -c--a-w c:\winnt\system32\dllcache\usbprint.sys + 2003-06-19 12:05:04 22,768 -c--a-w c:\winnt\system32\dllcache\usbser.sys + 2000-07-26 17:00:00 59,664 -c--a-w c:\winnt\system32\dllcache\usbui.dll + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\userinit.exe + 2003-06-19 11:05:04 315,664 -c--a-w c:\winnt\system32\dllcache\usp10.dll + 2003-06-19 11:05:04 26,384 -c--a-w c:\winnt\system32\dllcache\utildll.dll + 2003-06-19 11:05:04 22,800 -c--a-w c:\winnt\system32\dllcache\utilman.exe + 2000-07-26 17:00:00 59,280 -c--a-w c:\winnt\system32\dllcache\vdmindvd.sys + 2003-06-19 11:05:04 16,144 -c--a-w c:\winnt\system32\dllcache\version.dll + 2003-06-19 11:05:04 977,680 -c--a-w c:\winnt\system32\dllcache\vfpodbc.dll + 2003-06-19 12:05:04 51,472 -c--a-w c:\winnt\system32\dllcache\vfwwdm32.dll + 2003-06-19 11:05:04 83,888 -c--a-w c:\winnt\system32\dllcache\vga.dll + 2003-06-19 12:05:04 22,416 -c--a-w c:\winnt\system32\dllcache\viaagp.sys + 2003-06-19 11:05:04 50,640 -c--a-w c:\winnt\system32\dllcache\videoprt.sys + 1999-12-07 16:43:42 333,168 -c--a-w c:\winnt\system32\dllcache\voodoo3.dll + 1999-10-29 15:00:58 53,008 -c--a-w c:\winnt\system32\dllcache\voodoo3.sys + 1999-09-24 19:17:30 80,304 -c--a-w c:\winnt\system32\dllcache\vslinka.sys + 1999-11-30 23:39:52 253,200 -c--a-w c:\winnt\system32\dllcache\vssetup.dll + 2003-06-19 11:05:04 20,240 -c--a-w c:\winnt\system32\dllcache\vwipxspx.dll + 1999-12-07 16:43:42 48,304 -c--a-w c:\winnt\system32\dllcache\w32.dll + 2003-06-19 11:05:04 7,440 -c--a-w c:\winnt\system32\dllcache\w3ctrs.dll + 2003-06-19 11:05:04 33,552 -c--a-w c:\winnt\system32\dllcache\w3ext.dll + 2003-06-19 11:05:04 425,232 -c--a-w c:\winnt\system32\dllcache\w3scfg.dll + 2003-06-19 11:05:04 6,928 -c--a-w c:\winnt\system32\dllcache\w3svapi.dll + 2003-06-19 11:05:04 346,384 -c--a-w c:\winnt\system32\dllcache\w3svc.dll + 1999-10-20 13:51:16 19,728 -c--a-w c:\winnt\system32\dllcache\w840nd.sys + 1999-09-24 19:17:22 17,264 -c--a-w c:\winnt\system32\dllcache\w926nd.sys + 1999-10-04 14:01:56 18,704 -c--a-w c:\winnt\system32\dllcache\w940nd.sys + 2003-06-19 11:05:04 353,552 -c--a-w c:\winnt\system32\dllcache\w95upgnt.dll + 2003-06-19 11:05:04 72,464 -c--a-w c:\winnt\system32\dllcache\wam.dll + 2003-06-19 11:05:04 46,864 -c--a-w c:\winnt\system32\dllcache\wamreg.dll + 2003-06-19 11:05:04 32,272 -c--a-w c:\winnt\system32\dllcache\wanarp.sys + 1999-10-21 11:34:10 8,976 -c--a-w c:\winnt\system32\dllcache\wangqic.sys + 2003-06-19 11:05:04 155,920 -c--a-w c:\winnt\system32\dllcache\wavemsp.dll + 2003-06-19 11:05:04 254,018 -c--a-w c:\winnt\system32\dllcache\wbemcntl.dll + 2003-06-19 11:05:04 708,696 -c--a-w c:\winnt\system32\dllcache\wbemcomn.dll + 2003-06-19 11:05:04 647,257 -c--a-w c:\winnt\system32\dllcache\wbemcore.dll + 2003-06-19 11:05:04 168,013 -c--a-w c:\winnt\system32\dllcache\wbemdisp.dll + 2003-06-19 11:05:04 372,825 -c--a-w c:\winnt\system32\dllcache\wbemess.dll + 2003-06-19 11:05:04 38,672 -c--a-w c:\winnt\system32\dllcache\wbemperf.dll + 2003-06-19 11:05:04 41,061 -c--a-w c:\winnt\system32\dllcache\wbemprox.dll + 2003-06-19 11:05:04 41,036 -c--a-w c:\winnt\system32\dllcache\wbemsvc.dll + 2003-06-19 11:05:04 163,927 -c--a-w c:\winnt\system32\dllcache\wbemtest.exe + 2000-07-26 17:00:00 32,528 -c--a-w c:\winnt\system32\dllcache\wbfirdma.sys + 1999-11-30 23:40:18 88,576 -c--a-w c:\winnt\system32\dllcache\wcom32.exe + 2003-06-19 11:05:04 73,872 -c--a-w c:\winnt\system32\dllcache\wdmaud.sys + 1999-09-25 10:37:42 27,024 -c--a-w c:\winnt\system32\dllcache\wdvga.sys + 2003-06-19 11:05:04 42,768 -c--a-w c:\winnt\system32\dllcache\webhits.dll + 1999-12-07 16:43:42 41,552 -c--a-w c:\winnt\system32\dllcache\weitekp9.dll + 1999-09-25 10:37:44 30,960 -c--a-w c:\winnt\system32\dllcache\weitekp9.sys + 1999-09-24 23:55:30 771,824 -c--a-w c:\winnt\system32\dllcache\winacisa.sys + 1999-09-24 23:55:30 602,128 -c--a-w c:\winnt\system32\dllcache\winacpci.sys + 2003-06-19 11:05:04 59,152 -c--a-w c:\winnt\system32\dllcache\winfax.dll + 2003-06-19 11:05:04 270,608 -c--a-w c:\winnt\system32\dllcache\winhlp32.exe + 2000-07-26 17:00:00 8,976 -c--a-w c:\winnt\system32\dllcache\winhstb.exe + 2003-06-19 11:05:04 196,706 -c--a-w c:\winnt\system32\dllcache\winmgmt.exe + 2003-06-19 11:05:04 193,296 -c--a-w c:\winnt\system32\dllcache\winrep.exe + 2003-06-19 11:05:04 79,120 -c--a-w c:\winnt\system32\dllcache\winscard.dll + 2003-06-19 11:05:04 239,376 -c--a-w c:\winnt\system32\dllcache\winsmon.dll + 2003-06-19 11:05:04 113,936 -c--a-w c:\winnt\system32\dllcache\winspool.drv + 2003-06-19 11:05:04 39,184 -c--a-w c:\winnt\system32\dllcache\winsta.dll + 2003-06-19 11:05:04 4,368 -c--a-w c:\winnt\system32\dllcache\winver.exe + 1999-09-24 19:17:16 35,088 -c--a-w c:\winnt\system32\dllcache\wlandrv2.sys + 1999-09-25 10:35:14 8,016 -c--a-w c:\winnt\system32\dllcache\wmiacpi.sys + 2003-06-19 11:05:04 74,512 -c--a-w c:\winnt\system32\dllcache\wmicore.dll + 2003-06-19 11:05:04 110,681 -c--a-w c:\winnt\system32\dllcache\wmiprov.dll + 2000-07-26 17:00:00 3,312 -c--a-w c:\winnt\system32\dllcache\wowfax.dll + 2000-07-26 17:00:00 14,608 -c--a-w c:\winnt\system32\dllcache\wowfaxui.dll + 2003-06-19 11:05:04 29,968 -c--a-w c:\winnt\system32\dllcache\wpnpinst.exe + 2003-06-19 11:05:04 69,904 -c--a-w c:\winnt\system32\dllcache\ws2_32.dll + 2003-06-19 11:05:04 542,480 -c--a-w c:\winnt\system32\dllcache\wsecedit.dll + 2003-06-19 11:05:04 10,000 -c--a-w c:\winnt\system32\dllcache\wshatm.dll + 2003-06-19 11:05:04 8,464 -c--a-w c:\winnt\system32\dllcache\wshirda.dll + 2003-06-19 11:05:04 17,680 -c--a-w c:\winnt\system32\dllcache\wshtcpip.dll + 2003-06-19 11:05:04 39,696 -c--a-w c:\winnt\system32\dllcache\wsnmp32.dll + 2003-06-19 11:05:04 21,776 -c--a-w c:\winnt\system32\dllcache\wsock32.dll + 2003-06-19 11:05:04 9,216 -c--a-w c:\winnt\system32\dllcache\wuauserv.dll + 2003-06-19 11:05:04 28,400 -c--a-w c:\winnt\system32\dllcache\wupdinfo.dll + 1999-09-24 19:17:10 24,848 -c--a-w c:\winnt\system32\dllcache\wvlan48.sys + 2003-06-19 11:05:04 52,496 -c--a-w c:\winnt\system32\dllcache\wzcdlg.dll + 2003-06-19 11:05:04 29,968 -c--a-w c:\winnt\system32\dllcache\wzcsapi.dll + 2003-06-19 11:05:04 34,576 -c--a-w c:\winnt\system32\dllcache\wzcsetup.exe + 2003-06-19 11:05:04 195,856 -c--a-w c:\winnt\system32\dllcache\wzcsvc.dll + 2003-06-19 11:05:04 92,432 -c--a-w c:\winnt\system32\dllcache\xactsrv.dll + 1999-09-24 19:16:54 17,168 -c--a-w c:\winnt\system32\dllcache\xem336n5.sys + 2003-06-19 11:05:04 172,664 -c--a-w c:\winnt\system32\dllcache\xenroll.dll - 1998-05-05 09:30:18 36,352 -c--a-w c:\winnt\system32\dllcache\xilinxit.dll + 1998-05-05 10:30:18 36,352 -c--a-w c:\winnt\system32\dllcache\xilinxit.dll + 1999-11-30 23:40:18 107,792 -c--a-w c:\winnt\system32\dllcache\xlog.exe + 2009-01-05 11:12:45 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_208.dat + 2009-01-04 16:01:25 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_20c.dat - 2009-01-02 14:17:04 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat + 2009-01-04 15:35:49 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat - 2009-01-02 12:22:15 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_21c.dat + 2009-01-06 09:43:52 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_21c.dat - 2009-01-02 12:22:08 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_27c.dat + 2009-01-06 09:43:46 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_27c.dat + 2009-01-06 11:44:43 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_36c.dat . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [21/05/07 14:56 68856] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\winnt\System32\NvCpl.dll" [02/05/03 13:19 4640768] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [26/11/08 17:18 81000] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [18/10/08 18:04 30192] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [12/06/08 02:38 34672] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [23/12/08 11:58 136600] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [04/01/09 01:27 413696] "Synchronization Manager"="mobsync.exe" [19/06/03 11:05 111376 c:\winnt\system32\mobsync.exe] "nwiz"="nwiz.exe" [02/05/03 13:19 323584 c:\winnt\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [19/06/03 11:05 186640] c:\documents and settings\Administrator.SARAH\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456] c:\documents and settings\All Users.WINNT\Start Menu\Programs\Startup\ Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-10 113664] EPSON Status Monitor 3 Environment Check 2.lnk - c:\winnt\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2008-10-19 113152] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] Phone Connection Monitor.lnk - c:\program files\Sony Ericsson\Mobile\audevicemgr.exe [2007-03-21 753664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= mmdrv.dll R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2008-10-18 111184] R1 cmosa;cmosa;c:\winnt\system32\drivers\cmosa.sys [2008-10-18 29344] R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2008-10-18 61712] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2008-10-18 602128] R4 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2008-12-17 20560] R4 aswMon;avast! Standard Shield Support;c:\winnt\system32\drivers\aswmon.sys [2008-10-18 93296] S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-11-14 30192] S3 scsiscan;SCSI Scanner Driver;c:\winnt\system32\drivers\scsiscan.sys [2008-10-21 10576] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s LSP: %SystemRoot%\system32\msafd.dll Trusted Zone: www.igindex.co.uk Trusted Zone: www.theaa.com O16 -: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab c:\winnt\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab c:\winnt\Downloaded Program Files\Microsoft XML Parser for Java.osd . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-06 11:48:39 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes ... \WINNT\explorer.exe [1668] 0x85950B40 scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(188) c:\winnt\system32\wzcdlg.dll c:\winnt\system32\WZCSAPI.DLL . Completion time: 06/01/2009 11:50:40 ComboFix-quarantined-files.txt 2009-01-06 11:50:36 ComboFix2.txt 2009-01-05 23:16:08 ComboFix3.txt 2009-01-05 21:17:57 ComboFix4.txt 2009-01-04 00:08:20 ComboFix5.txt 2009-01-06 11:44:14 Pre-Run: 29,769,363,456 bytes free Post-Run: 29,766,119,424 bytes free 1511
  14. hi sarah, further to my post above avast ran a boot check and found about five trojans which i deleted although one of them i had to leave as it could not be deleted or moved etc. i then ran combofix and during this avast popped up another trojan warning which again i could not delete and i had to click "no action". here is the log file. were you expecting this? thanks again for your persistence with this problem, malcolm combofix logfile follows.... ComboFix 09-01-05.03 - Administrator 05/01/2009 23:09:20.4 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.684 [GMT 0:00] Running from: c:\documents and settings\Administrator.SARAH\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-05 23:02 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LimeWire 2009-01-05 19:29 --------- d-----w c:\program files\Kick'n'Rush 2006 2009-01-04 18:35 --------- d-----w c:\program files\Wyzo 2009-01-04 01:27 --------- d---a-w c:\program files\QuickTime 2009-01-02 12:26 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-01-02 12:26 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\Malwarebytes 2009-01-02 12:26 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\Malwarebytes 2009-01-01 22:08 --------- d---a-w c:\program files\Spybot - Search & Destroy 2009-01-01 22:08 --------- d---a-w c:\documents and settings\All Users.WINNT\Application Data\Spybot - Search & Destroy 2009-01-01 21:48 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-01 21:48 --------- d-----w c:\program files\LG PC Suite 2009-01-01 21:48 --------- d-----w c:\program files\LG Electronics 2009-01-01 21:47 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LG Electronics 2009-01-01 21:46 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\InstallShield 2008-12-24 13:43 88 ----a-w C:\_dele.bat 2008-12-24 01:02 --------- d---a-w c:\program files\Lavasoft 2008-12-24 01:00 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2008-12-24 00:40 --------- d-----w c:\program files\SpywareBlaster 2008-12-23 22:51 --------- d-----w c:\program files\Trend Micro 2008-12-23 11:58 410,984 ----a-w c:\winnt\system32\deploytk.dll 2008-12-23 11:58 --------- d---a-w c:\program files\Java 2008-12-23 11:52 --------- d---a-w c:\program files\LimeWire 2008-12-22 01:15 309,949 ----a-w c:\winnt\system32\hguest.exe 2008-12-18 18:48 --------- d-----w c:\program files\Football Champions Quiz 2008-12-18 18:47 --------- d-----w c:\program files\Five-A-Side Football 2008-12-16 17:46 85 ----a-w C:\ARP.BAT 2008-12-16 17:46 37 ----a-w C:\bat.bat 2008-12-13 15:49 --------- d-----w c:\program files\Sibelius Software 2008-12-03 19:59 38,496 ----a-w c:\winnt\system32\drivers\mbamswissarmy.sys 2008-12-03 19:59 15,504 ----a-w c:\winnt\system32\drivers\mbam.sys 2008-11-21 18:27 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\WinZip 2008-11-12 10:28 --------- d-----w c:\program files\NOS 2008-11-12 10:28 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\NOS 2008-11-11 16:17 --------- d-----w c:\program files\Common Files\Adobe AIR 2008-11-11 16:16 --------- d---a-w c:\program files\Common Files\Adobe 2008-10-18 20:52 271 ---h--w c:\program files\desktop.ini 2008-10-18 20:52 21,952 ---h--w c:\program files\folder.htt 2008-10-18 00:09 558,142 ----a-w c:\winnt\java\Packages\646JBDNL.ZIP 2008-10-18 00:09 155,995 ----a-w c:\winnt\java\Packages\8EUJ3VB5.ZIP 2006-01-03 22:06 664,161 -c--a-w c:\program files\JuiceUserGuide.pdf 2005-03-10 23:34 84,254 -c--a-w c:\program files\belkin manual.pdf 2000-07-26 17:00 32,528 ----a-w c:\winnt\inf\wbfirdma.sys . c:\winnt\system32\svchost.exe ... Infected -- Win32.Qhost !! ----a-w 7,952 2000-07-26 17:00:00 c:\winnt\system32\svchost.exe ((((((((((((((((((((((((((((( snapshot_Sun 04-01-2009_ 0.07.06.62 ))))))))))))))))))))))))))))))))))))))))) . + 2009-01-05 11:12:45 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_208.dat + 2009-01-04 16:01:25 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_20c.dat + 2009-01-05 23:01:16 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_210.dat - 2009-01-02 14:17:04 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat + 2009-01-04 15:35:49 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat + 2009-01-05 23:08:41 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_37c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [21/05/07 14:56 68856] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\winnt\System32\NvCpl.dll" [02/05/03 13:19 4640768] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [26/11/08 17:18 81000] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [18/10/08 18:04 30192] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [12/06/08 02:38 34672] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [23/12/08 11:58 136600] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [04/01/09 01:27 413696] "Synchronization Manager"="mobsync.exe" [19/06/03 11:05 111376 c:\winnt\system32\mobsync.exe] "nwiz"="nwiz.exe" [02/05/03 13:19 323584 c:\winnt\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [19/06/03 11:05 186640] c:\documents and settings\Administrator.SARAH\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456] c:\documents and settings\All Users.WINNT\Start Menu\Programs\Startup\ Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-10 113664] EPSON Status Monitor 3 Environment Check 2.lnk - c:\winnt\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2008-10-19 113152] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] Phone Connection Monitor.lnk - c:\program files\Sony Ericsson\Mobile\audevicemgr.exe [2007-03-21 753664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= mmdrv.dll R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2008-10-18 111184] R1 cmosa;cmosa;c:\winnt\system32\drivers\cmosa.sys [2008-10-18 29344] R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2008-10-18 61712] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2008-10-18 602128] R4 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2008-12-17 20560] R4 aswMon;avast! Standard Shield Support;c:\winnt\system32\drivers\aswmon.sys [2008-10-18 93296] S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-11-14 30192] S3 scsiscan;SCSI Scanner Driver;c:\winnt\system32\drivers\scsiscan.sys [2008-10-21 10576] . - - - - ORPHANS REMOVED - - - - HKLM-Run-hgcheck - c:\winnt\system32\hgcheck.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s LSP: %SystemRoot%\system32\msafd.dll Trusted Zone: www.igindex.co.uk Trusted Zone: www.theaa.com O16 -: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab c:\winnt\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab c:\winnt\Downloaded Program Files\Microsoft XML Parser for Java.osd . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-05 23:14:22 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(188) c:\winnt\system32\wzcdlg.dll c:\winnt\system32\WZCSAPI.DLL . Completion time: 05/01/2009 23:16:04 ComboFix-quarantined-files.txt 2009-01-05 23:16:00 ComboFix2.txt 2009-01-05 21:17:57 ComboFix3.txt 2009-01-04 00:08:20 ComboFix4.txt 2009-01-01 22:35:26 Pre-Run: 29,880,381,440 bytes free Post-Run: 29,854,822,400 bytes free 146
  15. hi sarah, scan done. a few things came up as below and the scan log is below that. whilst combofix scanning an avast warning came up saying a trojan horse had been found and saying the following malware name - win32:Patched-IT [Trj] file name - C:\WINNT\system32\svchost.exe if i clicked the delete button the warning dialogue box just popped up again and again so in order ot proceed i had to click "no action" and delete on reboot. another thing was that combofix popped up several boxes toward end of scan saying i chose not to restore original windows files do i want to keep these non original files and i said yes - was that right?? i will reboot now and rerun combofix to see if the avast trojan warning pops up again. thanks again, malcolm (combofix log follows) ComboFix 09-01-05.02 - Administrator 05/01/2009 21:10:44.3 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.653 [GMT 0:00] Running from: c:\documents and settings\Administrator.SARAH\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-05 20:58 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LimeWire 2009-01-05 19:29 --------- d-----w c:\program files\Kick'n'Rush 2006 2009-01-04 18:35 --------- d-----w c:\program files\Wyzo 2009-01-04 01:27 --------- d---a-w c:\program files\QuickTime 2009-01-02 12:26 --------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-01-02 12:26 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\Malwarebytes 2009-01-02 12:26 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\Malwarebytes 2009-01-01 22:08 --------- d---a-w c:\program files\Spybot - Search & Destroy 2009-01-01 22:08 --------- d---a-w c:\documents and settings\All Users.WINNT\Application Data\Spybot - Search & Destroy 2009-01-01 21:48 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-01 21:48 --------- d-----w c:\program files\LG PC Suite 2009-01-01 21:48 --------- d-----w c:\program files\LG Electronics 2009-01-01 21:47 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\LG Electronics 2009-01-01 21:46 --------- d-----w c:\documents and settings\Administrator.SARAH\Application Data\InstallShield 2008-12-24 13:43 88 ----a-w C:\_dele.bat 2008-12-24 13:07 104,659 ----a-w c:\winnt\system32\hgcheck.exe 2008-12-24 01:02 --------- d---a-w c:\program files\Lavasoft 2008-12-24 01:00 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2008-12-24 00:40 --------- d-----w c:\program files\SpywareBlaster 2008-12-23 22:51 --------- d-----w c:\program files\Trend Micro 2008-12-23 11:58 410,984 ----a-w c:\winnt\system32\deploytk.dll 2008-12-23 11:58 --------- d---a-w c:\program files\Java 2008-12-23 11:52 --------- d---a-w c:\program files\LimeWire 2008-12-22 01:15 309,949 ----a-w c:\winnt\system32\hguest.exe 2008-12-18 18:48 --------- d-----w c:\program files\Football Champions Quiz 2008-12-18 18:47 --------- d-----w c:\program files\Five-A-Side Football 2008-12-16 17:46 85 ----a-w C:\ARP.BAT 2008-12-16 17:46 37 ----a-w C:\bat.bat 2008-12-13 15:49 --------- d-----w c:\program files\Sibelius Software 2008-12-03 19:59 38,496 ----a-w c:\winnt\system32\drivers\mbamswissarmy.sys 2008-12-03 19:59 15,504 ----a-w c:\winnt\system32\drivers\mbam.sys 2008-11-24 23:24 570,396 --sh--r c:\winnt\gfsse11452s.bat 2008-11-21 18:27 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\WinZip 2008-11-12 10:28 --------- d-----w c:\program files\NOS 2008-11-12 10:28 --------- d-----w c:\documents and settings\All Users.WINNT\Application Data\NOS 2008-11-11 16:17 --------- d-----w c:\program files\Common Files\Adobe AIR 2008-11-11 16:16 --------- d---a-w c:\program files\Common Files\Adobe 2008-10-18 20:52 271 ---h--w c:\program files\desktop.ini 2008-10-18 20:52 21,952 ---h--w c:\program files\folder.htt 2008-10-18 00:09 558,142 ----a-w c:\winnt\java\Packages\646JBDNL.ZIP 2008-10-18 00:09 155,995 ----a-w c:\winnt\java\Packages\8EUJ3VB5.ZIP 2006-01-03 22:06 664,161 -c--a-w c:\program files\JuiceUserGuide.pdf 2005-03-10 23:34 84,254 -c--a-w c:\program files\belkin manual.pdf 2000-07-26 17:00 32,528 ----a-w c:\winnt\inf\wbfirdma.sys . c:\winnt\system32\svchost.exe ... Infected -- Win32.Qhost !! ----a-w 7,952 2000-07-26 17:00:00 c:\winnt\system32\svchost.exe ((((((((((((((((((((((((((((( snapshot_Sun 04-01-2009_ 0.07.06.62 ))))))))))))))))))))))))))))))))))))))))) . + 2009-01-05 11:12:45 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_208.dat + 2009-01-04 16:01:25 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_20c.dat - 2009-01-02 14:17:04 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat + 2009-01-04 15:35:49 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_218.dat + 2009-01-05 20:57:01 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_280.dat + 2009-01-05 21:10:03 16,384 ----atw c:\winnt\system32\Perflib_Perfdata_3a0.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [21/05/07 14:56 68856] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\winnt\System32\NvCpl.dll" [02/05/03 13:19 4640768] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [26/11/08 17:18 81000] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [18/10/08 18:04 30192] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [12/06/08 02:38 34672] "hgcheck"="c:\winnt\system32\hgcheck.exe" [24/12/08 13:07 104659] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [23/12/08 11:58 136600] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [04/01/09 01:27 413696] "Synchronization Manager"="mobsync.exe" [19/06/03 11:05 111376 c:\winnt\system32\mobsync.exe] "nwiz"="nwiz.exe" [02/05/03 13:19 323584 c:\winnt\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "NvMediaCenter"="c:\winnt\System32\NVMCTRAY.DLL" [02/05/03 13:19 49152] "internat.exe"="internat.exe" [26/07/00 17:00 20752 c:\winnt\system32\internat.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [19/06/03 11:05 186640] c:\documents and settings\Administrator.SARAH\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456] c:\documents and settings\All Users.WINNT\Start Menu\Programs\Startup\ Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-10 113664] EPSON Status Monitor 3 Environment Check 2.lnk - c:\winnt\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2008-10-19 113152] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588] Phone Connection Monitor.lnk - c:\program files\Sony Ericsson\Mobile\audevicemgr.exe [2007-03-21 753664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= mmdrv.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:"*" /L:"English" /KBD:1 R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2008-10-18 111184] R1 cmosa;cmosa;c:\winnt\system32\drivers\cmosa.sys [2008-10-18 29344] R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2008-10-18 61712] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2008-10-18 602128] R4 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2008-12-17 20560] R4 aswMon;avast! Standard Shield Support;c:\winnt\system32\drivers\aswmon.sys [2008-10-18 93296] S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-11-14 30192] S3 scsiscan;SCSI Scanner Driver;c:\winnt\system32\drivers\scsiscan.sys [2008-10-21 10576] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s LSP: %SystemRoot%\system32\msafd.dll Trusted Zone: www.igindex.co.uk Trusted Zone: www.theaa.com O16 -: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab c:\winnt\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab c:\winnt\Downloaded Program Files\Microsoft XML Parser for Java.osd . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-05 21:16:11 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(188) c:\winnt\system32\wzcdlg.dll c:\winnt\system32\WZCSAPI.DLL . Completion time: 05/01/2009 21:17:54 ComboFix-quarantined-files.txt 2009-01-05 21:17:49 ComboFix2.txt 2009-01-04 00:08:20 ComboFix3.txt 2009-01-01 22:35:26 Pre-Run: 29,550,022,656 bytes free Post-Run: 29,853,282,304 bytes free 148