Advertisement
Guest User

Untitled

a guest
Mar 15th, 2012
374
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 108.39 KB | None | 0 0
  1. 2012-03-15 17:15:11: ****************************************************
  2. 2012-03-15 17:15:11: Starting UP ... v 0.0.0.190
  3. 2012-03-15 17:15:11: ****************************************************
  4. 2012-03-15 17:15:11: Listing processes...
  5. 2012-03-15 17:15:11: :[System Process]:0
  6. 2012-03-15 17:15:11: :System:4
  7. 2012-03-15 17:15:11: :smss.exe:504
  8. 2012-03-15 17:15:11: :csrss.exe:568
  9. 2012-03-15 17:15:11: :winlogon.exe:592
  10. 2012-03-15 17:15:11: :services.exe:644
  11. 2012-03-15 17:15:11: :lsass.exe:656
  12. 2012-03-15 17:15:11: :svchost.exe:812
  13. 2012-03-15 17:15:11: :svchost.exe:892
  14. 2012-03-15 17:15:11: :svchost.exe:988
  15. 2012-03-15 17:15:11: :svchost.exe:1032
  16. 2012-03-15 17:15:11: :svchost.exe:1096
  17. 2012-03-15 17:15:11: :explorer.exe:1456
  18. 2012-03-15 17:15:11: :spoolsv.exe:1632
  19. 2012-03-15 17:15:11: :svchost.exe:1812
  20. 2012-03-15 17:15:11: :alg.exe:724
  21. 2012-03-15 17:15:11: :ctfmon.exe:956
  22. 2012-03-15 17:15:11: :svchost.exe:112
  23. 2012-03-15 17:15:11: :svchost.exe:720
  24. 2012-03-15 17:15:11: :yorkyt.exe:796
  25. 2012-03-15 17:15:11: :wmiprvse.exe:156
  26. 2012-03-15 17:15:11:
  27. 2012-03-15 17:15:11: Setting restore point
  28. 2012-03-15 17:15:12: Determining autonomous or dropped mode...
  29. 2012-03-15 17:15:12: Autonomus mode
  30. 2012-03-15 17:15:12: Installing drivers...
  31. 2012-03-15 17:15:12: Checking that it installed...
  32. 2012-03-15 17:15:12: Driver is installed...
  33. 2012-03-15 17:15:12: cmd.exe /c start "C:\Documents and Settings\thisisu\Desktop\yorkyt.exe"
  34. 2012-03-15 17:15:35: Restarting...
  35. 2012-03-15 17:16:08: ****************************************************
  36. 2012-03-15 17:16:08: Starting UP ... v 0.0.0.190
  37. 2012-03-15 17:16:08: ****************************************************
  38. 2012-03-15 17:16:08: Listing processes...
  39. 2012-03-15 17:16:08: :[System Process]:0
  40. 2012-03-15 17:16:08: :System:4
  41. 2012-03-15 17:16:08: :smss.exe:648
  42. 2012-03-15 17:16:08: :csrss.exe:728
  43. 2012-03-15 17:16:08: :winlogon.exe:756
  44. 2012-03-15 17:16:08: :services.exe:804
  45. 2012-03-15 17:16:08: :lsass.exe:820
  46. 2012-03-15 17:16:08: :svchost.exe:984
  47. 2012-03-15 17:16:08: :svchost.exe:1056
  48. 2012-03-15 17:16:08: :svchost.exe:1152
  49. 2012-03-15 17:16:08: :svchost.exe:1236
  50. 2012-03-15 17:16:08: :svchost.exe:1400
  51. 2012-03-15 17:16:08: :userinit.exe:1724
  52. 2012-03-15 17:16:08: :spoolsv.exe:1832
  53. 2012-03-15 17:16:08: :explorer.exe:1844
  54. 2012-03-15 17:16:08: :yorkyt.exe:1944
  55. 2012-03-15 17:16:08: :ctfmon.exe:316
  56. 2012-03-15 17:16:08: :wmiprvse.exe:420
  57. 2012-03-15 17:16:08:
  58. 2012-03-15 17:16:08: RUN mode
  59. 2012-03-15 17:16:08: Determining autonomous or dropped mode...
  60. 2012-03-15 17:16:08: Autonomus mode
  61. 2012-03-15 17:16:08: Waiting for Explorer.exe...
  62. 2012-03-15 17:16:38: Launching parsers...
  63. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\KDCOM.DLL kdcom.dll
  64. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\BOOTVID.DLL bootvid.dll
  65. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOT.SYS
  66. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOTD.SYS
  67. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOTK.SYS
  68. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOTI.SYS
  69. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOTS.SYS
  70. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ACPI.SYS ACPI.sys
  71. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS WmiLib.sys
  72. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\PCI.SYS pci.sys
  73. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ISAPNP.SYS isapnp.sys
  74. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\COMPBATT.SYS compbatt.sys
  75. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\BATTC.SYS battc.sys
  76. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\INTELIDE.SYS intelide.sys
  77. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\PCIIDEX.SYS pciidex.sys
  78. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\MOUNTMGR.SYS mountmgr.sys
  79. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\FTDISK.SYS ftdisk.sys
  80. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS dmload.sys
  81. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS dmio.sys
  82. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\PARTMGR.SYS partmgr.sys
  83. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\MVXXMM.SYS mvxxmm.sys
  84. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\VOLSNAP.SYS volsnap.sys
  85. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS atapi.sys
  86. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\MV61XXMM.SYS mv61xxmm.sys
  87. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\MV64XXMM.SYS mv64xxmm.sys
  88. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DISK.SYS scsidisk.sys
  89. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\CLASSPNP.SYS Classpnp.sys
  90. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\FLTMGR.SYS fltMgr.sys
  91. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\SR.SYS sr.sys
  92. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\KSECDD.SYS ksecdd.sys
  93. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\NTFS.SYS ntfs.sys
  94. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\NDIS.SYS NDIS.SYS
  95. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\MUP.SYS MUP.SYS
  96. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DASBOOTF.SYS
  97. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\I8042PRT.SYS i8042prt.sys
  98. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\KBDCLASS.SYS kbdclass.sys
  99. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MOUCLASS.SYS mouclass.sys
  100. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PARPORT.SYS parport.sys
  101. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\CDROM.SYS cdrom.sys
  102. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PCNTPCI5.SYS PCNTPCI5.SYS
  103. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\KS.SYS ks.sys
  104. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DRMK.SYS drmk.sys
  105. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\PORTCLS.SYS portcls.sys
  106. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\AC97INTC.SYS ichaud.sys
  107. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\USBPORT.SYS usbport.sys
  108. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\USBOHCI.SYS USBOHCI.sys
  109. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\CMBATT.SYS cmbatt.sys
  110. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\AUDSTUB.SYS audstub.sys
  111. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RASL2TP.SYS rasl2tp.sys
  112. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NDISTAPI.SYS NDISTAPI.SYS
  113. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NDISWAN.SYS NDISWAN.SYS
  114. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RASPPPOE.SYS raspppoe.sys
  115. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\TDI.SYS tdi.sys
  116. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RASPPTP.SYS RASPPTP.SYS
  117. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PSCHED.SYS PSCHED.SYS
  118. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MSGPC.SYS MSGPC.SYS
  119. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS ptilink.sys
  120. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RASPTI.SYS raspti.sys
  121. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RDPDR.SYS RDPDR.SYS
  122. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\TERMDD.SYS termdd.sys
  123. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SWENUM.SYS swenum.sys
  124. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\UPDATE.SYS update.sys
  125. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MSSMBIOS.SYS smbios.sys
  126. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NDPROXY.SYS ndproxy.sys
  127. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\USBD.SYS usbd.sys
  128. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\USBHUB.SYS usbhub.sys
  129. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\FDC.SYS fdc.sys
  130. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\FLPYDISK.SYS floppy.sys
  131. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SFLOPPY.SYS sfloppy.sys
  132. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\CDAUDIO.SYS cdaudio.sys
  133. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\FS_REC.SYS fs_rec.sys
  134. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NULL.SYS null.sys
  135. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS beep.sys
  136. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\VIDEOPRT.SYS videoprt.sys
  137. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\VGA.SYS vga.sys
  138. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MNMDD.SYS videosim.sys
  139. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RDPCDD.SYS RDPCDD.SYS
  140. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MSFS.SYS MSFS.SYS
  141. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NPFS.SYS npfs.sys
  142. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RASACD.SYS rasacd.sys
  143. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\IPSEC.SYS ipsec.sys
  144. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS tcpip.sys
  145. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NETBT.SYS netbt.sys
  146. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\IPNAT.SYS IPNAT.SYS
  147. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS ws2ifsl.sys
  148. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\AFD.SYS afd.sys
  149. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NETBIOS.SYS NETBIOS.SYS
  150. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\REDBOOK.SYS redbook.sys
  151. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RDBSS.SYS RDBSS.Sys
  152. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MRXSMB.SYS
  153. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\WANARP.SYS WANARP.SYS
  154. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\` MRXSMB.Sys
  155. 2012-03-15 17:16:39: Found replaced driver: FB2FCCC70F7174C7BF64F48E96D3ADF4 \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\` MRXSMB.Sys
  156. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\IMAPI.SYS IMAPI.sys
  157. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\FIPS.SYS fips.sys
  158. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\HIDPARSE.SYS hidparse.sys
  159. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\HIDCLASS.SYS hidclass.sys
  160. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\HIDUSB.SYS HIDUSB.SYS
  161. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\USBSTOR.SYS usbstor.sys
  162. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MOUHID.SYS mouhid.sys
  163. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\CDFS.SYS cdfs.sys
  164. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\WMILIB.SYS WmiLib.sys
  165. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\ATAPI.SYS atapi.sys
  166. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DXAPI.SYS dxapi.sys
  167. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\WATCHDOG.SYS watchdog.sys
  168. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\WIN32K.SYS win32k.sys
  169. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DXGTHK.SYS dxgthk.sys
  170. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\DRIVERS\DXG.SYS dxg.sys
  171. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\VGA.DLL vga.dll
  172. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\FRAMEBUF.DLL framebuf.dll
  173. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\VGA256.DLL vga256.dll
  174. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\SYSTEM32\VGA64K.DLL vga64k.dll
  175. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\NDISUIO.SYS NDISUIO.SYS
  176. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\RSPNDR.SYS RSPNDR.SYS
  177. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\WDMAUD.SYS WDMAUD.SYS
  178. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SYSAUDIO.SYS sysaudio.sys
  179. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SPLITTER.SYS splitter.sys
  180. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS aec.sys
  181. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SWMIDI.SYS swmidi.sys
  182. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\DMUSIC.SYS DMusic.sys
  183. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\DRMKAUD.SYS drmkaud.sys
  184. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\MRXDAV.SYS MRxDAV.Sys
  185. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PARVDM.SYS parvdm.sys
  186. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SERIAL.SYS serial.sys
  187. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\SRV.SYS SRV.SYS
  188. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS http.sys
  189. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\KMIXER.SYS kmixer.sys
  190. 2012-03-15 17:16:39: Looking at \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\DRIVERS\PRSBDRVR.SYS
  191. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ntdll.dll ntdll.dll
  192. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\i8042prt.sys i8042prt.sys
  193. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\kbdclass.sys kbdclass.sys
  194. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mouclass.sys mouclass.sys
  195. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\parport.sys parport.sys
  196. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\cdrom.sys cdrom.sys
  197. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\pcntpci5.sys PCNTPCI5.SYS
  198. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ac97intc.sys ichaud.sys
  199. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\portcls.sys portcls.sys
  200. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\drmk.sys drmk.sys
  201. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ks.sys ks.sys
  202. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\usbohci.sys USBOHCI.sys
  203. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\usbport.sys usbport.sys
  204. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\CmBatt.sys cmbatt.sys
  205. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\audstub.sys audstub.sys
  206. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rasl2tp.sys rasl2tp.sys
  207. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ndistapi.sys NDISTAPI.SYS
  208. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ndiswan.sys NDISWAN.SYS
  209. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\raspppoe.sys raspppoe.sys
  210. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\raspptp.sys RASPPTP.SYS
  211. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\tdi.sys tdi.sys
  212. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\psched.sys PSCHED.SYS
  213. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\msgpc.sys MSGPC.SYS
  214. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ptilink.sys ptilink.sys
  215. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\raspti.sys raspti.sys
  216. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rdpdr.sys RDPDR.SYS
  217. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\termdd.sys termdd.sys
  218. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\swenum.sys swenum.sys
  219. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\update.sys update.sys
  220. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mssmbios.sys smbios.sys
  221. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ndproxy.sys ndproxy.sys
  222. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\usbhub.sys usbhub.sys
  223. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\usbd.sys usbd.sys
  224. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\fdc.sys fdc.sys
  225. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\flpydisk.sys floppy.sys
  226. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\sfloppy.sys sfloppy.sys
  227. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\cdaudio.sys cdaudio.sys
  228. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\fs_rec.sys fs_rec.sys
  229. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\null.sys null.sys
  230. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\beep.sys beep.sys
  231. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\vga.sys vga.sys
  232. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\videoprt.sys videoprt.sys
  233. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mnmdd.sys videosim.sys
  234. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rdpcdd.sys RDPCDD.SYS
  235. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\msfs.sys MSFS.SYS
  236. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\npfs.sys npfs.sys
  237. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rasacd.sys rasacd.sys
  238. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ipsec.sys ipsec.sys
  239. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\tcpip.sys tcpip.sys
  240. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\netbt.sys netbt.sys
  241. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ipnat.sys IPNAT.SYS
  242. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ws2ifsl.sys ws2ifsl.sys
  243. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\afd.sys afd.sys
  244. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\netbios.sys NETBIOS.SYS
  245. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\redbook.sys redbook.sys
  246. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rdbss.sys RDBSS.Sys
  247. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mrxsmb.sys
  248. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\wanarp.sys WANARP.SYS
  249. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\` MRXSMB.Sys
  250. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\assembly\GAC_MSIL\Desktop.ini
  251. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\imapi.sys IMAPI.sys
  252. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\fips.sys fips.sys
  253. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\smss.exe smss.exe
  254. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\autochk.exe AutoChk.Exe
  255. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sfcfiles.dll
  256. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\advapi32.dll advapi32.dll
  257. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\comdlg32.dll comdlg32.dll
  258. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\gdi32.dll gdi32
  259. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\imagehlp.dll IMAGEHLP.DLL
  260. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\kernel32.dll kernel32
  261. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\lz32.dll LZ32.DLL
  262. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ole32.dll OLE32.DLL
  263. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\oleaut32.dll
  264. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\olecli32.dll OLECLI32.DLL
  265. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\olecnv32.dll OLECNV32.DLL
  266. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\olesvr32.dll OLESVR32.DLL
  267. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\olethk32.dll OLETHK32.DLL
  268. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rpcrt4.dll rpcrt4.dll
  269. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shell32.dll SHELL32.DLL
  270. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\url.dll URL.DLL
  271. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\urlmon.dll UrlMon.dll
  272. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\user32.dll user32
  273. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\version.dll VERSION.DLL
  274. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wininet.dll wininet.dll
  275. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wldap32.dll WLDAP32.DLL
  276. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\comctl32.dll COMCTL32.DLL
  277. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shlwapi.dll SHLWAPI.DLL
  278. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msvcrt.dll msvcrt.dll
  279. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mpr.dll mpr.dll
  280. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ntvdm.exe NTVDM.EXE
  281. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wow32.dll WOW32.DLL
  282. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\secur32.dll security.dll
  283. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\iertutil.dll IeRtUtil.dll
  284. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\hidusb.sys HIDUSB.SYS
  285. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\hidclass.sys hidclass.sys
  286. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\hidparse.sys hidparse.sys
  287. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\USBSTOR.SYS usbstor.sys
  288. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mouhid.sys mouhid.sys
  289. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ieframe.dll IEFRAME.DLL
  290. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\normaliz.dll normaliz.dll
  291. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\apphelp.dll Apphelp
  292. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\userenv.dll userenv.dll
  293. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\cdfs.sys cdfs.sys
  294. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\atapi.sys atapi.sys
  295. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\wmilib.sys WmiLib.sys
  296. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\win32k.sys win32k.sys
  297. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\dxapi.sys dxapi.sys
  298. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\watchdog.sys watchdog.sys
  299. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\csrss.exe CSRSS.Exe
  300. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\csrsrv.dll CSRSrv.DLL
  301. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\basesrv.dll basesrv
  302. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winsrv.dll winsrv.dll
  303. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\dxg.sys dxg.sys
  304. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\dxgthk.sys dxgthk.sys
  305. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\vga.dll vga.dll
  306. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\framebuf.dll framebuf.dll
  307. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\vga256.dll vga256.dll
  308. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\vga64k.dll vga64k.dll
  309. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winlogon.exe WINLOGON.EXE
  310. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\authz.dll authz.dll
  311. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\crypt32.dll CRYPT32.DLL
  312. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msasn1.dll msasn1.dll
  313. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\nddeapi.dll NDDEAPI.DLL
  314. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\profmap.dll userenv.dll
  315. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netapi32.dll NetApi32.DLL
  316. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\psapi.dll PSAPI
  317. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\regapi.dll regapi.dll
  318. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\setupapi.dll SETUPAPI.DLL
  319. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winsta.dll winsta.dll
  320. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wintrust.dll WINTRUST.DLL
  321. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ws2_32.dll ws2_32.dll
  322. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ws2help.dll ws2help.dll
  323. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\imm32.dll imm32
  324. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\kbdus.dll kbdus.dll
  325. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\MSCTFIME.IME MSCTFIME.IME
  326. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msgina.dll MSGINA.DLL
  327. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\odbc32.dll ODBC32
  328. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sxs.dll SXS.DLL
  329. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll comctl32.DLL
  330. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\WindowsShell.Manifest
  331. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\odbcint.dll ODBCINT
  332. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shsvcs.dll SHSVCS.DLL
  333. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sfc.dll sfc.dll
  334. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sfc_os.dll sfc.dll
  335. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\services.exe services.exe
  336. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\lsass.exe lsass.exe
  337. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ncobjapi.dll NCObjAPI.DLL
  338. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msvcp60.dll MSVCP60.DLL
  339. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\lsasrv.dll lsasrv.dll
  340. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\scesrv.dll scesrv
  341. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ntdsapi.dll ntdsapi.dll
  342. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\umpnpmgr.dll Umpnpmgr.DLL
  343. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dnsapi.dll dnsapi
  344. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shimeng.dll ShimEngineDLL(IAT)
  345. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\samlib.dll SAMLib.DLL
  346. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\AppPatch\AcAdProc.dll
  347. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\samsrv.dll samsrv.dll
  348. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cryptdll.dll cryptdll.dll
  349. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\AppPatch\AcGenral.dll
  350. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winmm.dll WINMM.DLL
  351. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msacm32.dll msfltr32.acm
  352. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\uxtheme.dll UxTheme.dll
  353. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msapsspc.dll MSAPSSPC.DLL
  354. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msvcrt40.dll msvcrt40.dll
  355. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\schannel.dll schannel.dll
  356. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\credssp.dll tssso.dll
  357. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\digest.dll digest.dll
  358. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msnsspc.dll MSNSSPC.DLL
  359. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\MSCTF.dll MSCTF.DLL
  360. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msprivs.dll mspriv.dll
  361. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\WindowsLogon.manifest
  362. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\kerberos.dll kerberos.dll
  363. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msv1_0.dll MSV1_0.DLL
  364. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\iphlpapi.dll iphlpapi.dll
  365. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netlogon.dll NetLogon.DLL
  366. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\w32time.dll w32time.dll
  367. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wdigest.dll WDIGEST.DLL
  368. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rsaenh.dll rsaenh.dll
  369. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\tspkg.dll TSpkg.dll
  370. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winscard.dll winscard.dll
  371. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wtsapi32.dll wtsapi32.dll
  372. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\scecli.dll scecli
  373. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\svchost.exe svchost.exe
  374. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ntmarta.dll ntmarta.dll
  375. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rpcss.dll rpcss.dll
  376. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\eventlog.dll Eventlog.DLL
  377. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\xpsp2res.dll xpsp2res.dll
  378. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mswsock.dll mswsock.dll
  379. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winrnr.dll winrnr
  380. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rasadhlp.dll rasadhlp.dll
  381. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\ndisuio.sys NDISUIO.SYS
  382. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\rspndr.sys RSPNDR.SYS
  383. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dhcpcsvc.dll dhcpcsvc.dll
  384. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dnsrslvr.dll dnsrslvr.dll
  385. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\hnetcfg.dll HNETCFG.DLL
  386. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wshtcpip.dll wshtcpip.dll
  387. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\Resources\Themes\Luna\luna.msstyles luna.mst
  388. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\clbcatq.dll
  389. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\lmhsvc.dll lmhsvc.dll
  390. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\comres.dll
  391. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wzcsvc.dll wzcsvc.dll
  392. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rtutils.dll RTUTILS.DLL
  393. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wmi.dll wmi.DLL
  394. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\eapolqec.dll EapolQec.dll
  395. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\atl.dll ATL.DLL
  396. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\qutil.dll QUtil.DLL
  397. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dot3api.dll dot3api.dll
  398. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\esent.dll esent.dll
  399. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\kmddsp.tsp KMDDSP.TSP
  400. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cabinet.dll cabinet.dll
  401. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\logonui.exe LOGONUI.EXE
  402. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\jscript.dll jscript.dll
  403. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cryptui.dll CRYPTUI.DLL
  404. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\duser.dll DUser.DLL
  405. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cscdll.dll CSCDLL.DLL
  406. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dimsntfy.dll dimsntfy.dll
  407. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wlnotify.dll WlNotify.dll
  408. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winspool.drv winspool.drv
  409. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wmisvc.dll wmisvc.dll
  410. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msimg32.dll gdiext
  411. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\oleacc.dll OLEACC.DLL
  412. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\vssapi.dll VSSAPI.DLL
  413. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rastls.dll rastls.dll
  414. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mprapi.dll mprapi.dll
  415. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\activeds.dll ADs
  416. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\adsldpc.dll adsldpc
  417. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rasapi32.dll rasapi32.dll
  418. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rasman.dll Rasman.dll
  419. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\tapi32.dll TAPI32.DLL
  420. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\riched20.dll riched20.dll
  421. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\raschap.dll raschap.dll
  422. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netman.dll netman.dll
  423. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shgina.dll SHGINA.DLL
  424. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netshell.dll netshell.dll
  425. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\credui.dll credui.dll
  426. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dot3dlg.dll dot3dlg.dll
  427. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\onex.dll onex.dll
  428. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\eappcfg.dll eappcfg.DLL
  429. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\eappprxy.dll eappprxy.dll
  430. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wzcsapi.dll wzcsapi.dll
  431. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cscui.dll cscui.dll
  432. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\es.dll
  433. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\powrprof.dll POWRPROF.DLL
  434. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dpcdll.dll Dpcdll.dll
  435. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\userinit.exe USERINIT.EXE
  436. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\Documents and Settings\thisisu\Local Settings\Application Data\02e7abf0\X
  437. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ipnathlp.dll IPNATHLP.DLL
  438. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\objsel.dll objsel.dll
  439. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\schedsvc.dll schedsvc.dll
  440. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\riched32.dll riched32.dll
  441. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\spoolsv.exe spoolsv.exe
  442. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msidle.dll MSIDLE.DLL
  443. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\explorer.exe EXPLORER.EXE
  444. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\audiosrv.dll audiosrv.dll
  445. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\browseui.dll BROWSEUI.DLL
  446. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wkssvc.dll WKSSVC.DLL
  447. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\shdocvw.dll SHDOCVW.DLL
  448. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\desk.cpl DESK.CPL
  449. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\themeui.dll ThemeUI.DLL
  450. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\actxprxy.dll ActXPrxy.dll
  451. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cmd.exe Cmd.Exe
  452. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\Documents and Settings\thisisu\Desktop\yorkyt.exe
  453. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\MSIMTF.dll MSIMTF.DLL
  454. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wsock32.dll wsock32.dll
  455. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msutb.dll MSUTB.DLL
  456. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\linkinfo.dll LINKINFO.DLL
  457. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ntshrui.dll ntshrui.dll
  458. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\verclsid.exe verclsid.exe
  459. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wdmaud.drv WDMAUD.DRV
  460. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\wdmaud.sys WDMAUD.SYS
  461. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\sysaudio.sys sysaudio.sys
  462. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\splitter.sys splitter.sys
  463. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\aec.sys aec.sys
  464. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\swmidi.sys swmidi.sys
  465. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\DMusic.sys DMusic.sys
  466. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\kmixer.sys kmixer.sys
  467. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\drmkaud.sys drmkaud.sys
  468. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ctfmon.exe CTFMON.EXE
  469. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemdisp.dll WBEMDISP.DLL
  470. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\upnp.dll upnp.dll
  471. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msacm32.drv msacm32.acm
  472. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\midimap.dll midimap.dll
  473. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winhttp.dll winhttp.dll
  474. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemprox.dll wbemprox.dll
  475. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\ime\SPTIP.dll SPTIP.DLL
  476. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ssdpapi.dll ssdpapi.dll
  477. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemcomn.dll wbemcomn.dll
  478. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wmiutils.dll wmiutils.dll
  479. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemcore.dll wbemcore.dll
  480. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\esscli.dll esscli.dll
  481. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\fastprox.dll fastprox.dll
  482. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemsvc.dll wbemsvc.dll
  483. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\repdrvfs.dll repdrvfs.dll
  484. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wmiprvsd.dll Wmiprvsd.dll
  485. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wbemess.dll wbemess.dll
  486. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netcfgx.dll netcfgx.dll
  487. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\clusapi.dll clusapi
  488. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wmiprvse.exe Wmiprvse.exe
  489. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\cimwin32.dll cimwin32.dll
  490. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\framedyn.dll framedyn.dll
  491. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\webcheck.dll WEBCHECK.DLL
  492. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mlang.dll MLANG.DLL
  493. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\stobject.dll stobject.dll
  494. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\batmeter.dll BATMETER.DLL
  495. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\mrxdav.sys MRxDAV.Sys
  496. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\webclnt.dll davsvc.dll
  497. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\parvdm.sys parvdm.sys
  498. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\serial.sys serial.sys
  499. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cryptsvc.dll cryptsvc.dll
  500. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ipsecsvc.dll ipsecsvc.dll
  501. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\regsvc.dll REGSVC.DLL
  502. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\oakley.dll oakley.dll
  503. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\certcli.dll CertCli
  504. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\winipsec.dll winipsec.dll
  505. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\pstorsvc.dll Protectedstorageserver
  506. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\psbase.dll psbase.dll
  507. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wuauserv.dll wuauserv.dll
  508. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\trkwks.dll trkwks.dll
  509. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dssenh.dll dssenh.dll
  510. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wuaueng.dll wuaueng.dll
  511. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mspatcha.dll mspatcha.dll
  512. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\srsvc.dll SERVICE.DLL
  513. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\seclogon.dll SECLOGON.EXE
  514. 2012-03-15 17:16:39: Bad Service: system32\csctl50.dll
  515. 2012-03-15 17:16:39: Found Service: Packet
  516. 2012-03-15 17:16:39: Display Name: AFGMp50
  517. 2012-03-15 17:16:39: Description: New service would allow parents to control their children's online activity.
  518. 2012-03-15 17:16:39: ServiceDLL: %systemroot%\system32\csctl50.dll
  519. 2012-03-15 17:16:39: MD5: B89CFBE8CB247B57D8C10ADAA66B462B
  520. 2012-03-15 17:16:39: Original file name:
  521. 2012-03-15 17:16:39: Company name:
  522. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\csctl50.dll adserxvice.exe
  523. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\srvsvc.dll SRVSVC.DLL
  524. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll PCHSVC.DLL
  525. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ersvc.dll ERSVC.DLL
  526. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netmsg.dll netmsg.DLL
  527. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\dmserver.dll dmserver.dll
  528. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sens.dll sens.dll
  529. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\srv.sys SRV.SYS
  530. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wups.dll wups.dll
  531. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wups2.dll wups2.dll
  532. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wuauclt.exe wuauclt.exe
  533. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\browser.dll browser.dll
  534. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\http.sys http.sys
  535. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\termsrv.dll termsrv.exe
  536. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\ssdpsrv.dll ssdpsrv.dll
  537. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\icaapi.dll icaapi.dll
  538. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mstlsapi.dll mstlsapi.dll
  539. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\comsvcs.dll
  540. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\colbact.dll
  541. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mtxclu.dll
  542. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\resutils.dll resutils
  543. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\alg.exe ALG.exe
  544. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\rasdlg.dll rasdlg.dll
  545. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\spoolss.dll spoolss.dll
  546. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\localspl.dll localspl.dll
  547. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cnbjmon.dll CNBJMON.DLL
  548. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\pjlmon.dll PJLMON.DLL
  549. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\tcpmon.dll tcpmon.dll
  550. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\usbmon.dll DynaMon.dll
  551. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\win32spl.dll win32spl.dll
  552. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\netrap.dll NetRap.DLL
  553. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\inetpp.dll inetpp.dll
  554. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\msisip.dll MSISIP.DLL
  555. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wshext.dll wshext.dll
  556. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mspaint.exe MSPAINT.EXE
  557. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mfc42u.dll MFC42.DLL
  558. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll gdiplus
  559. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wiaservc.dll WIASERVC.DLL
  560. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\cfgmgr32.dll CFGMGR32.DLL
  561. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\mscms.dll MSCMS.DLL
  562. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\sti.dll STI.DLL
  563. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\temp\yt\run.bat
  564. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\temp\yt\nemesiscmd.exe
  565. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\temp\yt\PRSBLib.dll
  566. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\drivers\PRSBDrvr.sys
  567. 2012-03-15 17:16:39: Looking at \Device\HarddiskVolume1\WINDOWS\system32\wbem\wmipcima.dll WMIPCIMA.dll
  568. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  569. 2012-03-15 17:16:39: Found Service: Alerter
  570. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\alrsvc.dll
  571. 2012-03-15 17:16:39: Display Name: Alerter
  572. 2012-03-15 17:16:39: Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start.
  573. 2012-03-15 17:16:39: ServiceDLL: system32\alrsvc.dll
  574. 2012-03-15 17:16:39: File size: 17408
  575. 2012-03-15 17:16:39: DLL File name: alrsvc.dll
  576. 2012-03-15 17:16:39: Original File Name: ALRSVC.DLL
  577. 2012-03-15 17:16:39: Company:
  578. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315171639
  579. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  580. 2012-03-15 17:16:39: Found Service: AppMgmt
  581. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\appmgmts.dll
  582. 2012-03-15 17:16:39: Display Name: Application Management
  583. 2012-03-15 17:16:39: Description: Provides software installation services such as Assign, Publish, and Remove.
  584. 2012-03-15 17:16:39: ServiceDLL: System32\appmgmts.dll
  585. 2012-03-15 17:16:39: File size: 167936
  586. 2012-03-15 17:16:39: DLL File name: appmgmts.dll
  587. 2012-03-15 17:16:39: Original File Name: appmgmts.dll
  588. 2012-03-15 17:16:39: Company:
  589. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  590. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  591. 2012-03-15 17:16:39: Found Service: AudioSrv
  592. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\audiosrv.dll
  593. 2012-03-15 17:16:39: Display Name: Windows Audio
  594. 2012-03-15 17:16:39: Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
  595. 2012-03-15 17:16:39: ServiceDLL: System32\audiosrv.dll
  596. 2012-03-15 17:16:39: File size: 42496
  597. 2012-03-15 17:16:39: DLL File name: audiosrv.dll
  598. 2012-03-15 17:16:39: Original File Name: audiosrv.dll
  599. 2012-03-15 17:16:39: Company:
  600. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  601. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  602. 2012-03-15 17:16:39: Found Service: BITS
  603. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\qmgr.dll
  604. 2012-03-15 17:16:39: Display Name: Background Intelligent Transfer Service
  605. 2012-03-15 17:16:39: Description: Transfers data between clients and servers in the background. If BITS is disabled, features such as Windows Update will not work correctly.
  606. 2012-03-15 17:16:39: ServiceDLL: system32\qmgr.dll
  607. 2012-03-15 17:16:39: File size: 409088
  608. 2012-03-15 17:16:39: DLL File name: qmgr.dll
  609. 2012-03-15 17:16:39: Original File Name: qmgr.dll
  610. 2012-03-15 17:16:39: Company:
  611. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20120229175059 20120315170551
  612. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  613. 2012-03-15 17:16:39: Found Service: Browser
  614. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\browser.dll
  615. 2012-03-15 17:16:39: Display Name: Computer Browser
  616. 2012-03-15 17:16:39: Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.
  617. 2012-03-15 17:16:39: ServiceDLL: System32\browser.dll
  618. 2012-03-15 17:16:39: File size: 77824
  619. 2012-03-15 17:16:39: DLL File name: browser.dll
  620. 2012-03-15 17:16:39: Original File Name: browser.dll
  621. 2012-03-15 17:16:39: Company:
  622. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  623. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  624. 2012-03-15 17:16:39: Found Service: CryptSvc
  625. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\cryptsvc.dll
  626. 2012-03-15 17:16:39: Display Name: CryptSvc
  627. 2012-03-15 17:16:39: Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
  628. 2012-03-15 17:16:39: ServiceDLL: System32\cryptsvc.dll
  629. 2012-03-15 17:16:39: File size: 62464
  630. 2012-03-15 17:16:39: DLL File name: cryptsvc.dll
  631. 2012-03-15 17:16:39: Original File Name: cryptsvc.dll
  632. 2012-03-15 17:16:39: Company:
  633. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  634. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  635. 2012-03-15 17:16:39: Found Service: DcomLaunch
  636. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\rpcss.dll
  637. 2012-03-15 17:16:39: Display Name: DCOM Server Process Launcher
  638. 2012-03-15 17:16:39: Description: Provides launch functionality for DCOM services.
  639. 2012-03-15 17:16:39: ServiceDLL: system32\rpcss.dll
  640. 2012-03-15 17:16:39: File size: 401408
  641. 2012-03-15 17:16:39: DLL File name: rpcss.dll
  642. 2012-03-15 17:16:39: Original File Name: rpcss.dll
  643. 2012-03-15 17:16:39: Company:
  644. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090407 20120112090407 20120315165510
  645. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  646. 2012-03-15 17:16:39: Found Service: Dhcp
  647. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\dhcpcsvc.dll
  648. 2012-03-15 17:16:39: Display Name: DHCP Client
  649. 2012-03-15 17:16:39: Description: Manages network configuration by registering and updating IP addresses and DNS names.
  650. 2012-03-15 17:16:39: ServiceDLL: System32\dhcpcsvc.dll
  651. 2012-03-15 17:16:39: File size: 126976
  652. 2012-03-15 17:16:39: DLL File name: dhcpcsvc.dll
  653. 2012-03-15 17:16:39: Original File Name: dhcpcsvc.dll
  654. 2012-03-15 17:16:39: Company:
  655. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090256 20120112090256 20120315170551
  656. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  657. 2012-03-15 17:16:39: Found Service: dmserver
  658. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\dmserver.dll
  659. 2012-03-15 17:16:39: Display Name: Logical Disk Manager
  660. 2012-03-15 17:16:39: Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start.
  661. 2012-03-15 17:16:39: ServiceDLL: System32\dmserver.dll
  662. 2012-03-15 17:16:39: File size: 23552
  663. 2012-03-15 17:16:39: DLL File name: dmserver.dll
  664. 2012-03-15 17:16:39: Original File Name: dmserver.dll
  665. 2012-03-15 17:16:39: Company:
  666. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  667. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  668. 2012-03-15 17:16:39: Found Service: Dnscache
  669. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\dnsrslvr.dll
  670. 2012-03-15 17:16:39: Display Name: DNS Client
  671. 2012-03-15 17:16:39: Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
  672. 2012-03-15 17:16:39: ServiceDLL: System32\dnsrslvr.dll
  673. 2012-03-15 17:16:39: File size: 45568
  674. 2012-03-15 17:16:39: DLL File name: dnsrslvr.dll
  675. 2012-03-15 17:16:39: Original File Name: dnsrslvr.dll
  676. 2012-03-15 17:16:39: Company:
  677. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090257 20120112090257 20120315170551
  678. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  679. 2012-03-15 17:16:39: Found Service: Dot3svc
  680. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\dot3svc.dll
  681. 2012-03-15 17:16:39: Display Name: Wired AutoConfig
  682. 2012-03-15 17:16:39: Description: This service performs IEEE 802.1X authentication on Ethernet interfaces
  683. 2012-03-15 17:16:39: ServiceDLL: System32\dot3svc.dll
  684. 2012-03-15 17:16:39: File size: 132096
  685. 2012-03-15 17:16:39: DLL File name: dot3svc.dll
  686. 2012-03-15 17:16:39: Original File Name: dot3svc.dll
  687. 2012-03-15 17:16:39: Company:
  688. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090257 20120112090257 20120315170551
  689. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  690. 2012-03-15 17:16:39: Found Service: EapHost
  691. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\eapsvc.dll
  692. 2012-03-15 17:16:39: Display Name: Extensible Authentication Protocol Service
  693. 2012-03-15 17:16:39: Description: Provides windows clients Extensible Authentication Protocol Service
  694. 2012-03-15 17:16:39: ServiceDLL: System32\eapsvc.dll
  695. 2012-03-15 17:16:39: File size: 33792
  696. 2012-03-15 17:16:39: DLL File name: eapsvc.dll
  697. 2012-03-15 17:16:39: Original File Name: eapsvc.dll
  698. 2012-03-15 17:16:39: Company:
  699. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  700. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  701. 2012-03-15 17:16:39: Found Service: ERSvc
  702. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\ersvc.dll
  703. 2012-03-15 17:16:39: Display Name: Error Reporting Service
  704. 2012-03-15 17:16:39: Description: Allows error reporting for services and applictions running in non-standard environments.
  705. 2012-03-15 17:16:39: ServiceDLL: System32\ersvc.dll
  706. 2012-03-15 17:16:39: File size: 23040
  707. 2012-03-15 17:16:39: DLL File name: ersvc.dll
  708. 2012-03-15 17:16:39: Original File Name: ERSVC.DLL
  709. 2012-03-15 17:16:39: Company:
  710. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  711. 2012-03-15 17:16:39: !!!!!!!
  712. 2012-03-15 17:16:39: Found Service: EventSystem
  713. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\es.dll
  714. 2012-03-15 17:16:39: Display Name: COM+ Event System
  715. 2012-03-15 17:16:39: Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start.
  716. 2012-03-15 17:16:39: ServiceDLL: system32\es.dll
  717. 2012-03-15 17:16:39: File size: 253952
  718. 2012-03-15 17:16:39: DLL File name: es.dll
  719. 2012-03-15 17:16:39: Original File Name:
  720. 2012-03-15 17:16:39: Company:
  721. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090258 20120112090258 20120315165609
  722. 2012-03-15 17:16:39: !!!!!!!!!
  723. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  724. 2012-03-15 17:16:39: Found Service: FastUserSwitchingCompatibility
  725. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\shsvcs.dll
  726. 2012-03-15 17:16:39: Display Name: Fast User Switching Compatibility
  727. 2012-03-15 17:16:39: Description: Provides management for applications that require assistance in a multiple user environment.
  728. 2012-03-15 17:16:39: ServiceDLL: System32\shsvcs.dll
  729. 2012-03-15 17:16:39: File size: 135168
  730. 2012-03-15 17:16:39: DLL File name: shsvcs.dll
  731. 2012-03-15 17:16:39: Original File Name: SHSVCS.DLL
  732. 2012-03-15 17:16:39: Company:
  733. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090420 20120112090420 20120315170551
  734. 2012-03-15 17:16:39: !!!!!!!
  735. 2012-03-15 17:16:39: Found Service: HidServ
  736. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\hidserv.dll
  737. 2012-03-15 17:16:39: Display Name: Human Interface Device Access
  738. 2012-03-15 17:16:39: Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.
  739. 2012-03-15 17:16:39: ServiceDLL: System32\hidserv.dll
  740. 2012-03-15 17:16:39: File size: 0
  741. 2012-03-15 17:16:39: DLL File name: hidserv.dll
  742. 2012-03-15 17:16:39: Original File Name:
  743. 2012-03-15 17:16:39: Company:
  744. 2012-03-15 17:16:39: Mod/Cre/Acc time:
  745. 2012-03-15 17:16:39: !!!!!!!!!
  746. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  747. 2012-03-15 17:16:39: Found Service: hkmsvc
  748. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\kmsvc.dll
  749. 2012-03-15 17:16:39: Display Name: Health Key and Certificate Management Service
  750. 2012-03-15 17:16:39: Description: Manages health certificates and keys (used by NAP)
  751. 2012-03-15 17:16:39: ServiceDLL: System32\kmsvc.dll
  752. 2012-03-15 17:16:39: File size: 61440
  753. 2012-03-15 17:16:39: DLL File name: kmsvc.dll
  754. 2012-03-15 17:16:39: Original File Name: KmSvc.DLL
  755. 2012-03-15 17:16:39: Company:
  756. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  757. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  758. 2012-03-15 17:16:39: Found Service: HTTPFilter
  759. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\w3ssl.dll
  760. 2012-03-15 17:16:39: Display Name: HTTP SSL
  761. 2012-03-15 17:16:39: Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start.
  762. 2012-03-15 17:16:39: ServiceDLL: System32\w3ssl.dll
  763. 2012-03-15 17:16:39: File size: 15872
  764. 2012-03-15 17:16:39: DLL File name: w3ssl.dll
  765. 2012-03-15 17:16:39: Original File Name: w3ssl.dll
  766. 2012-03-15 17:16:39: Company:
  767. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  768. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  769. 2012-03-15 17:16:39: Found Service: LanmanServer
  770. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\srvsvc.dll
  771. 2012-03-15 17:16:39: Display Name: Server
  772. 2012-03-15 17:16:39: Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
  773. 2012-03-15 17:16:39: ServiceDLL: System32\srvsvc.dll
  774. 2012-03-15 17:16:39: File size: 99840
  775. 2012-03-15 17:16:39: DLL File name: srvsvc.dll
  776. 2012-03-15 17:16:39: Original File Name: SRVSVC.DLL
  777. 2012-03-15 17:16:39: Company:
  778. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090422 20120112090422 20120315170551
  779. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  780. 2012-03-15 17:16:39: Found Service: lanmanworkstation
  781. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\wkssvc.dll
  782. 2012-03-15 17:16:39: Display Name: Workstation
  783. 2012-03-15 17:16:39: Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
  784. 2012-03-15 17:16:39: ServiceDLL: System32\wkssvc.dll
  785. 2012-03-15 17:16:39: File size: 134144
  786. 2012-03-15 17:16:39: DLL File name: wkssvc.dll
  787. 2012-03-15 17:16:39: Original File Name: WKSSVC.DLL
  788. 2012-03-15 17:16:39: Company:
  789. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090439 20120112090439 20120315170551
  790. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  791. 2012-03-15 17:16:39: Found Service: LmHosts
  792. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\lmhsvc.dll
  793. 2012-03-15 17:16:39: Display Name: TCP/IP NetBIOS Helper
  794. 2012-03-15 17:16:39: Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
  795. 2012-03-15 17:16:39: ServiceDLL: System32\lmhsvc.dll
  796. 2012-03-15 17:16:39: File size: 13824
  797. 2012-03-15 17:16:39: DLL File name: lmhsvc.dll
  798. 2012-03-15 17:16:39: Original File Name: lmhsvc.dll
  799. 2012-03-15 17:16:39: Company:
  800. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  801. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  802. 2012-03-15 17:16:39: Found Service: Messenger
  803. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\msgsvc.dll
  804. 2012-03-15 17:16:39: Display Name: Messenger
  805. 2012-03-15 17:16:39: Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start.
  806. 2012-03-15 17:16:39: ServiceDLL: System32\msgsvc.dll
  807. 2012-03-15 17:16:39: File size: 33792
  808. 2012-03-15 17:16:39: DLL File name: msgsvc.dll
  809. 2012-03-15 17:16:39: Original File Name: msgsvc.dll
  810. 2012-03-15 17:16:39: Company:
  811. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315171639
  812. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  813. 2012-03-15 17:16:39: Found Service: napagent
  814. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\qagentrt.dll
  815. 2012-03-15 17:16:39: Display Name: Network Access Protection Agent
  816. 2012-03-15 17:16:39: Description: Allows windows clients to participate in Network Access Protection
  817. 2012-03-15 17:16:39: ServiceDLL: System32\qagentrt.dll
  818. 2012-03-15 17:16:39: File size: 291328
  819. 2012-03-15 17:16:39: DLL File name: qagentrt.dll
  820. 2012-03-15 17:16:39: Original File Name: QAgentRT.DLL
  821. 2012-03-15 17:16:39: Company:
  822. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  823. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  824. 2012-03-15 17:16:39: Found Service: Netman
  825. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\netman.dll
  826. 2012-03-15 17:16:39: Display Name: Network Connections
  827. 2012-03-15 17:16:39: Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
  828. 2012-03-15 17:16:39: ServiceDLL: System32\netman.dll
  829. 2012-03-15 17:16:39: File size: 198144
  830. 2012-03-15 17:16:39: DLL File name: netman.dll
  831. 2012-03-15 17:16:39: Original File Name: netman.dll
  832. 2012-03-15 17:16:39: Company:
  833. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  834. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  835. 2012-03-15 17:16:39: Found Service: Nla
  836. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\mswsock.dll
  837. 2012-03-15 17:16:39: Display Name: Network Location Awareness (NLA)
  838. 2012-03-15 17:16:39: Description: Collects and stores network configuration and location information, and notifies applications when this information changes.
  839. 2012-03-15 17:16:39: ServiceDLL: System32\mswsock.dll
  840. 2012-03-15 17:16:39: File size: 245248
  841. 2012-03-15 17:16:39: DLL File name: mswsock.dll
  842. 2012-03-15 17:16:39: Original File Name: mswsock.dll
  843. 2012-03-15 17:16:39: Company:
  844. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090347 20120112090347 20120315170042
  845. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  846. 2012-03-15 17:16:39: Found Service: NtmsSvc
  847. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\ntmssvc.dll
  848. 2012-03-15 17:16:39: Display Name: Removable Storage
  849. 2012-03-15 17:16:39: Description:
  850. 2012-03-15 17:16:39: ServiceDLL: system32\ntmssvc.dll
  851. 2012-03-15 17:16:39: File size: 435200
  852. 2012-03-15 17:16:39: DLL File name: ntmssvc.dll
  853. 2012-03-15 17:16:39: Original File Name: ntmssvc.dll
  854. 2012-03-15 17:16:39: Company:
  855. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  856. 2012-03-15 17:16:39: !!!!!!!
  857. 2012-03-15 17:16:39: Found Service: Packet
  858. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\csctl50.dll.bad
  859. 2012-03-15 17:16:39: Display Name: AFGMp50
  860. 2012-03-15 17:16:39: Description: New service would allow parents to control their children's online activity.
  861. 2012-03-15 17:16:39: ServiceDLL: system32\csctl50.dll.bad
  862. 2012-03-15 17:16:39: File size: 0
  863. 2012-03-15 17:16:39: DLL File name: csctl50.dll.bad
  864. 2012-03-15 17:16:39: Original File Name:
  865. 2012-03-15 17:16:39: Company:
  866. 2012-03-15 17:16:39: Mod/Cre/Acc time:
  867. 2012-03-15 17:16:39: !!!!!!!!!
  868. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  869. 2012-03-15 17:16:39: Found Service: RasAuto
  870. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\rasauto.dll
  871. 2012-03-15 17:16:39: Display Name: Remote Access Auto Connection Manager
  872. 2012-03-15 17:16:39: Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
  873. 2012-03-15 17:16:39: ServiceDLL: System32\rasauto.dll
  874. 2012-03-15 17:16:39: File size: 88576
  875. 2012-03-15 17:16:39: DLL File name: rasauto.dll
  876. 2012-03-15 17:16:39: Original File Name: rasauto.dll
  877. 2012-03-15 17:16:39: Company:
  878. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170551
  879. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  880. 2012-03-15 17:16:39: Found Service: RasMan
  881. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\rasmans.dll
  882. 2012-03-15 17:16:39: Display Name: Remote Access Connection Manager
  883. 2012-03-15 17:16:39: Description: Creates a network connection.
  884. 2012-03-15 17:16:39: ServiceDLL: System32\rasmans.dll
  885. 2012-03-15 17:16:39: File size: 186368
  886. 2012-03-15 17:16:39: DLL File name: rasmans.dll
  887. 2012-03-15 17:16:39: Original File Name: Rasmans.dll
  888. 2012-03-15 17:16:39: Company:
  889. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170042
  890. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  891. 2012-03-15 17:16:39: Found Service: RemoteAccess
  892. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\mprdim.dll
  893. 2012-03-15 17:16:39: Display Name: Routing and Remote Access
  894. 2012-03-15 17:16:39: Description: Offers routing services to businesses in local area and wide area network environments.
  895. 2012-03-15 17:16:39: ServiceDLL: System32\mprdim.dll
  896. 2012-03-15 17:16:39: File size: 53248
  897. 2012-03-15 17:16:39: DLL File name: mprdim.dll
  898. 2012-03-15 17:16:39: Original File Name: MPRDIM.DLL
  899. 2012-03-15 17:16:39: Company:
  900. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315171639
  901. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  902. 2012-03-15 17:16:39: Found Service: RemoteRegistry
  903. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\regsvc.dll
  904. 2012-03-15 17:16:39: Display Name: Remote Registry
  905. 2012-03-15 17:16:39: Description: Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.
  906. 2012-03-15 17:16:39: ServiceDLL: system32\regsvc.dll
  907. 2012-03-15 17:16:39: File size: 59904
  908. 2012-03-15 17:16:39: DLL File name: regsvc.dll
  909. 2012-03-15 17:16:39: Original File Name: REGSVC.DLL
  910. 2012-03-15 17:16:39: Company:
  911. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  912. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  913. 2012-03-15 17:16:39: Found Service: RpcSs
  914. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\rpcss.dll
  915. 2012-03-15 17:16:39: Display Name: Remote Procedure Call (RPC)
  916. 2012-03-15 17:16:39: Description: Provides the endpoint mapper and other miscellaneous RPC services.
  917. 2012-03-15 17:16:39: ServiceDLL: System32\rpcss.dll
  918. 2012-03-15 17:16:39: File size: 401408
  919. 2012-03-15 17:16:39: DLL File name: rpcss.dll
  920. 2012-03-15 17:16:39: Original File Name: rpcss.dll
  921. 2012-03-15 17:16:39: Company:
  922. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090407 20120112090407 20120315165510
  923. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  924. 2012-03-15 17:16:39: Found Service: Schedule
  925. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\schedsvc.dll
  926. 2012-03-15 17:16:39: Display Name: Task Scheduler
  927. 2012-03-15 17:16:39: Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.
  928. 2012-03-15 17:16:39: ServiceDLL: system32\schedsvc.dll
  929. 2012-03-15 17:16:39: File size: 192512
  930. 2012-03-15 17:16:39: DLL File name: schedsvc.dll
  931. 2012-03-15 17:16:39: Original File Name: schedsvc.dll
  932. 2012-03-15 17:16:39: Company:
  933. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20120229175054 20120315170552
  934. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  935. 2012-03-15 17:16:39: Found Service: seclogon
  936. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\seclogon.dll
  937. 2012-03-15 17:16:39: Display Name: Secondary Logon
  938. 2012-03-15 17:16:39: Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
  939. 2012-03-15 17:16:39: ServiceDLL: System32\seclogon.dll
  940. 2012-03-15 17:16:39: File size: 18944
  941. 2012-03-15 17:16:39: DLL File name: seclogon.dll
  942. 2012-03-15 17:16:39: Original File Name: SECLOGON.EXE
  943. 2012-03-15 17:16:39: Company:
  944. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  945. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  946. 2012-03-15 17:16:39: Found Service: SENS
  947. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\sens.dll
  948. 2012-03-15 17:16:39: Display Name: System Event Notification
  949. 2012-03-15 17:16:39: Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
  950. 2012-03-15 17:16:39: ServiceDLL: system32\sens.dll
  951. 2012-03-15 17:16:39: File size: 39424
  952. 2012-03-15 17:16:39: DLL File name: sens.dll
  953. 2012-03-15 17:16:39: Original File Name: sens.dll
  954. 2012-03-15 17:16:39: Company:
  955. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170042
  956. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  957. 2012-03-15 17:16:39: Found Service: SharedAccess
  958. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\ipnathlp.dll
  959. 2012-03-15 17:16:39: Display Name: Windows Firewall/Internet Connection Sharing (ICS)
  960. 2012-03-15 17:16:39: Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.
  961. 2012-03-15 17:16:39: ServiceDLL: System32\ipnathlp.dll
  962. 2012-03-15 17:16:39: File size: 330752
  963. 2012-03-15 17:16:39: DLL File name: ipnathlp.dll
  964. 2012-03-15 17:16:39: Original File Name: IPNATHLP.DLL
  965. 2012-03-15 17:16:39: Company:
  966. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090308 20120112090308 20120315170552
  967. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  968. 2012-03-15 17:16:39: Found Service: ShellHWDetection
  969. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\shsvcs.dll
  970. 2012-03-15 17:16:39: Display Name: Shell Hardware Detection
  971. 2012-03-15 17:16:39: Description: Provides notifications for AutoPlay hardware events.
  972. 2012-03-15 17:16:39: ServiceDLL: System32\shsvcs.dll
  973. 2012-03-15 17:16:39: File size: 135168
  974. 2012-03-15 17:16:39: DLL File name: shsvcs.dll
  975. 2012-03-15 17:16:39: Original File Name: SHSVCS.DLL
  976. 2012-03-15 17:16:39: Company:
  977. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090420 20120112090420 20120315170551
  978. 2012-03-15 17:16:39: !!!!!!!
  979. 2012-03-15 17:16:39: Found Service: srservice
  980. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\srsvc.dll
  981. 2012-03-15 17:16:39: Display Name: System Restore Service
  982. 2012-03-15 17:16:39: Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties
  983. 2012-03-15 17:16:39: ServiceDLL: system32\srsvc.dll
  984. 2012-03-15 17:16:39: File size: 171008
  985. 2012-03-15 17:16:39: DLL File name: srsvc.dll
  986. 2012-03-15 17:16:39: Original File Name: SERVICE.DLL
  987. 2012-03-15 17:16:39: Company:
  988. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20120229175055 20120315170552
  989. 2012-03-15 17:16:39: !!!!!!!!!
  990. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  991. 2012-03-15 17:16:39: Found Service: SSDPSRV
  992. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\ssdpsrv.dll
  993. 2012-03-15 17:16:39: Display Name: SSDP Discovery Service
  994. 2012-03-15 17:16:39: Description: Enables discovery of UPnP devices on your home network.
  995. 2012-03-15 17:16:39: ServiceDLL: System32\ssdpsrv.dll
  996. 2012-03-15 17:16:39: File size: 71680
  997. 2012-03-15 17:16:39: DLL File name: ssdpsrv.dll
  998. 2012-03-15 17:16:39: Original File Name: ssdpsrv.dll
  999. 2012-03-15 17:16:39: Company:
  1000. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1001. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  1002. 2012-03-15 17:16:39: Found Service: stisvc
  1003. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\wiaservc.dll
  1004. 2012-03-15 17:16:39: Display Name: Windows Image Acquisition (WIA)
  1005. 2012-03-15 17:16:39: Description: Provides image acquisition services for scanners and cameras.
  1006. 2012-03-15 17:16:39: ServiceDLL: system32\wiaservc.dll
  1007. 2012-03-15 17:16:39: File size: 333824
  1008. 2012-03-15 17:16:39: DLL File name: wiaservc.dll
  1009. 2012-03-15 17:16:39: Original File Name: WIASERVC.DLL
  1010. 2012-03-15 17:16:39: Company:
  1011. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1012. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  1013. 2012-03-15 17:16:39: Found Service: TapiSrv
  1014. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\tapisrv.dll
  1015. 2012-03-15 17:16:39: Display Name: Telephony
  1016. 2012-03-15 17:16:39: Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
  1017. 2012-03-15 17:16:39: ServiceDLL: System32\tapisrv.dll
  1018. 2012-03-15 17:16:39: File size: 249856
  1019. 2012-03-15 17:16:39: DLL File name: tapisrv.dll
  1020. 2012-03-15 17:16:39: Original File Name: TAPISRV.EXE
  1021. 2012-03-15 17:16:39: Company:
  1022. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090426 20120112090426 20120315170042
  1023. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  1024. 2012-03-15 17:16:39: Found Service: TermService
  1025. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\termsrv.dll
  1026. 2012-03-15 17:16:39: Display Name: Terminal Services
  1027. 2012-03-15 17:16:39: Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server.
  1028. 2012-03-15 17:16:39: ServiceDLL: System32\termsrv.dll
  1029. 2012-03-15 17:16:39: File size: 296960
  1030. 2012-03-15 17:16:39: DLL File name: termsrv.dll
  1031. 2012-03-15 17:16:39: Original File Name: termsrv.exe
  1032. 2012-03-15 17:16:39: Company:
  1033. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090427 20120229175016 20120315170552
  1034. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  1035. 2012-03-15 17:16:39: Found Service: Themes
  1036. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\System32\shsvcs.dll
  1037. 2012-03-15 17:16:39: Display Name: Themes
  1038. 2012-03-15 17:16:39: Description: Provides user experience theme management.
  1039. 2012-03-15 17:16:39: ServiceDLL: System32\shsvcs.dll
  1040. 2012-03-15 17:16:39: File size: 135168
  1041. 2012-03-15 17:16:39: DLL File name: shsvcs.dll
  1042. 2012-03-15 17:16:39: Original File Name: SHSVCS.DLL
  1043. 2012-03-15 17:16:39: Company:
  1044. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20120112090420 20120112090420 20120315170551
  1045. 2012-03-15 17:16:39: ---------------------------------------------------------------------
  1046. 2012-03-15 17:16:39: Found Service: TrkWks
  1047. 2012-03-15 17:16:39: Real Path: C:\WINDOWS\system32\trkwks.dll
  1048. 2012-03-15 17:16:39: Display Name: Distributed Link Tracking Client
  1049. 2012-03-15 17:16:39: Description: Maintains links between NTFS files within a computer or across computers in a network domain.
  1050. 2012-03-15 17:16:39: ServiceDLL: system32\trkwks.dll
  1051. 2012-03-15 17:16:39: File size: 90112
  1052. 2012-03-15 17:16:39: DLL File name: trkwks.dll
  1053. 2012-03-15 17:16:39: Original File Name: trkwks.dll
  1054. 2012-03-15 17:16:39: Company:
  1055. 2012-03-15 17:16:39: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1056. 2012-03-15 17:16:40: !!!!!!!
  1057. 2012-03-15 17:16:40: Found Service: upnphost
  1058. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\System32\upnphost.dll
  1059. 2012-03-15 17:16:40: Display Name: Universal Plug and Play Device Host
  1060. 2012-03-15 17:16:40: Description: Provides support to host Universal Plug and Play devices.
  1061. 2012-03-15 17:16:40: ServiceDLL: System32\upnphost.dll
  1062. 2012-03-15 17:16:40: File size: 185856
  1063. 2012-03-15 17:16:40: DLL File name: upnphost.dll
  1064. 2012-03-15 17:16:40: Original File Name: unpnhost.dll
  1065. 2012-03-15 17:16:40: Company:
  1066. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1067. 2012-03-15 17:16:40: !!!!!!!!!
  1068. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1069. 2012-03-15 17:16:40: Found Service: W32Time
  1070. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\system32\w32time.dll
  1071. 2012-03-15 17:16:40: Display Name: Windows Time
  1072. 2012-03-15 17:16:40: Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.
  1073. 2012-03-15 17:16:40: ServiceDLL: system32\w32time.dll
  1074. 2012-03-15 17:16:40: File size: 175616
  1075. 2012-03-15 17:16:40: DLL File name: w32time.dll
  1076. 2012-03-15 17:16:40: Original File Name: w32time.dll
  1077. 2012-03-15 17:16:40: Company:
  1078. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20120112090433 20120112090433 20120315170552
  1079. 2012-03-15 17:16:40: !!!!!!!
  1080. 2012-03-15 17:16:40: Found Service: WebClient
  1081. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\System32\webclnt.dll
  1082. 2012-03-15 17:16:40: Display Name: WebClient
  1083. 2012-03-15 17:16:40: Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start.
  1084. 2012-03-15 17:16:40: ServiceDLL: System32\webclnt.dll
  1085. 2012-03-15 17:16:40: File size: 68096
  1086. 2012-03-15 17:16:40: DLL File name: webclnt.dll
  1087. 2012-03-15 17:16:40: Original File Name: davsvc.dll
  1088. 2012-03-15 17:16:40: Company:
  1089. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20120112090434 20120112090434 20120315170552
  1090. 2012-03-15 17:16:40: !!!!!!!!!
  1091. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1092. 2012-03-15 17:16:40: Found Service: winmgmt
  1093. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\system32\wbem\WMIsvc.dll
  1094. 2012-03-15 17:16:40: Display Name: Windows Management Instrumentation
  1095. 2012-03-15 17:16:40: Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
  1096. 2012-03-15 17:16:40: ServiceDLL: system32\wbem\WMIsvc.dll
  1097. 2012-03-15 17:16:40: File size: 144896
  1098. 2012-03-15 17:16:40: DLL File name: WMIsvc.dll
  1099. 2012-03-15 17:16:40: Original File Name: wmisvc.dll
  1100. 2012-03-15 17:16:40: Company:
  1101. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20080414060000 20120229175014 20120315170552
  1102. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1103. 2012-03-15 17:16:40: Found Service: WmdmPmSN
  1104. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\system32\mspmsnsv.dll
  1105. 2012-03-15 17:16:40: Display Name: Portable Media Serial Number Service
  1106. 2012-03-15 17:16:40: Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
  1107. 2012-03-15 17:16:40: ServiceDLL: system32\mspmsnsv.dll
  1108. 2012-03-15 17:16:40: File size: 52224
  1109. 2012-03-15 17:16:40: DLL File name: mspmsnsv.dll
  1110. 2012-03-15 17:16:40: Original File Name: MsPMSNSv.dll
  1111. 2012-03-15 17:16:40: Company:
  1112. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1113. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1114. 2012-03-15 17:16:40: Found Service: Wmi
  1115. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\System32\advapi32.dll
  1116. 2012-03-15 17:16:40: Display Name: Windows Management Instrumentation Driver Extensions
  1117. 2012-03-15 17:16:40: Description: Provides systems management information to and from drivers.
  1118. 2012-03-15 17:16:40: ServiceDLL: System32\advapi32.dll
  1119. 2012-03-15 17:16:40: File size: 617472
  1120. 2012-03-15 17:16:40: DLL File name: advapi32.dll
  1121. 2012-03-15 17:16:40: Original File Name: advapi32.dll
  1122. 2012-03-15 17:16:40: Company:
  1123. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20120112090244 20120112090244 20120315165510
  1124. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1125. 2012-03-15 17:16:40: Found Service: wuauserv
  1126. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\system32\wuauserv.dll
  1127. 2012-03-15 17:16:40: Display Name: Automatic Updates
  1128. 2012-03-15 17:16:40: Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site.
  1129. 2012-03-15 17:16:40: ServiceDLL: system32\wuauserv.dll
  1130. 2012-03-15 17:16:40: File size: 22520
  1131. 2012-03-15 17:16:40: DLL File name: wuauserv.dll
  1132. 2012-03-15 17:16:40: Original File Name: wuauserv.dll
  1133. 2012-03-15 17:16:40: Company:
  1134. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20120112090452 20120229175059 20120315170552
  1135. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1136. 2012-03-15 17:16:40: Found Service: WZCSVC
  1137. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\System32\wzcsvc.dll
  1138. 2012-03-15 17:16:40: Display Name: Wireless Zero Configuration
  1139. 2012-03-15 17:16:40: Description: Provides automatic configuration for the 802.11 adapters
  1140. 2012-03-15 17:16:40: ServiceDLL: System32\wzcsvc.dll
  1141. 2012-03-15 17:16:40: File size: 483328
  1142. 2012-03-15 17:16:40: DLL File name: wzcsvc.dll
  1143. 2012-03-15 17:16:40: Original File Name: wzcsvc.dll
  1144. 2012-03-15 17:16:40: Company:
  1145. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20120112090958 20080422120342 20120315170552
  1146. 2012-03-15 17:16:40: ---------------------------------------------------------------------
  1147. 2012-03-15 17:16:40: Found Service: xmlprov
  1148. 2012-03-15 17:16:40: Real Path: C:\WINDOWS\System32\xmlprov.dll
  1149. 2012-03-15 17:16:40: Display Name: Network Provisioning Service
  1150. 2012-03-15 17:16:40: Description: Manages XML configuration files on a domain basis for automatic network provisioning.
  1151. 2012-03-15 17:16:40: ServiceDLL: System32\xmlprov.dll
  1152. 2012-03-15 17:16:40: File size: 129024
  1153. 2012-03-15 17:16:40: DLL File name: xmlprov.dll
  1154. 2012-03-15 17:16:40: Original File Name: xmlprov.dll
  1155. 2012-03-15 17:16:40: Company:
  1156. 2012-03-15 17:16:40: Mod/Cre/Acc time: 20080414060000 20080414060000 20120315170552
  1157. 2012-03-15 17:16:40:
  1158. 2012-03-15 17:16:40: Looking for SHELL key
  1159. 2012-03-15 17:16:40: HKCU WINLOGON SHELL: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02E7ABF0\X
  1160. 2012-03-15 17:16:40: Folder: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02E7ABF0\
  1161. 2012-03-15 17:16:40: File: X
  1162. 2012-03-15 17:16:40: ...Will request C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02E7ABF0\X
  1163. 2012-03-15 17:16:40: ... New user shell: EXPLORER.EXE,
  1164. 2012-03-15 17:16:40: Checking for bad folder
  1165. 2012-03-15 17:16:40: Found 1 folders.
  1166. 2012-03-15 17:16:40: Checking C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0
  1167. 2012-03-15 17:16:40: ... Folder test returns: 1
  1168. 2012-03-15 17:16:40: Bad Folder found: 02e7abf0
  1169. 2012-03-15 17:16:40: ... Unhidding
  1170. 2012-03-15 17:16:40: ... Parse Point: 1 0
  1171. 2012-03-15 17:16:40: ... Folder: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U
  1172. 2012-03-15 17:16:40: xcacls.exe C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U /p Administrators:f SYSTEM:f /y
  1173. 2012-03-15 17:16:40: fsutil reparsepoint query C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U
  1174. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\@
  1175. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\X.BAD
  1176. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\00000001.@
  1177. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000c0.@
  1178. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cb.@
  1179. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cf.@
  1180. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\80000000.@
  1181. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000c0.@
  1182. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cb.@
  1183. 2012-03-15 17:16:40: ... File: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cf.@
  1184. 2012-03-15 17:16:43: Folder: GAC
  1185. 2012-03-15 17:16:43: Folder: GAC_MSIL
  1186. 2012-03-15 17:16:43: ... Fixing permissions on C:\WINDOWS\assembly\GAC_MSIL\desktop.ini
  1187. 2012-03-15 17:16:43: Checking for bad folder
  1188. 2012-03-15 17:16:43: Found 1 folders.
  1189. 2012-03-15 17:16:43: Checking C:\WINDOWS\$NtUninstallKB22248$
  1190. 2012-03-15 17:16:43: ... Folder test returns: 0
  1191. 2012-03-15 17:16:43: Bad Folder found: $NtUninstallKB22248$
  1192. 2012-03-15 17:16:43: ... Unhidding
  1193. 2012-03-15 17:16:43: ... Parse Point: 0 0
  1194. 2012-03-15 17:16:43: ... Deleting parse point
  1195. 2012-03-15 17:16:43: ... Folder: C:\WINDOWS\$NtUninstallKB22248$\48737264
  1196. 2012-03-15 17:16:43: ... Unhidding folder C:\WINDOWS\$NtUninstallKB22248$\48737264
  1197. 2012-03-15 17:16:44: xcacls.exe C:\WINDOWS\$NtUninstallKB22248$\48737264 /p Administrators:f SYSTEM:f /y
  1198. 2012-03-15 17:16:44: fsutil reparsepoint query C:\WINDOWS\$NtUninstallKB22248$\48737264
  1199. 2012-03-15 17:16:44: ... Folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1200. 2012-03-15 17:16:44: ... Unhidding folder C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1201. 2012-03-15 17:16:44: xcacls.exe C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb /p Administrators:f SYSTEM:f /y
  1202. 2012-03-15 17:16:44: fsutil reparsepoint query C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1203. 2012-03-15 17:16:44: ... Folder: C:\WINDOWS\$NtUninstallKB22248$\48737264
  1204. 2012-03-15 17:16:44: xcacls.exe C:\WINDOWS\$NtUninstallKB22248$\48737264 /p Administrators:f SYSTEM:f /y
  1205. 2012-03-15 17:16:44: fsutil reparsepoint query C:\WINDOWS\$NtUninstallKB22248$\48737264
  1206. 2012-03-15 17:16:44: ... Folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\L
  1207. 2012-03-15 17:16:44: xcacls.exe C:\WINDOWS\$NtUninstallKB22248$\48737264\L /p Administrators:f SYSTEM:f /y
  1208. 2012-03-15 17:16:44: fsutil reparsepoint query C:\WINDOWS\$NtUninstallKB22248$\48737264\L
  1209. 2012-03-15 17:16:44: ... Folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\U
  1210. 2012-03-15 17:16:44: xcacls.exe C:\WINDOWS\$NtUninstallKB22248$\48737264\U /p Administrators:f SYSTEM:f /y
  1211. 2012-03-15 17:16:44: fsutil reparsepoint query C:\WINDOWS\$NtUninstallKB22248$\48737264\U
  1212. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\859542333
  1213. 2012-03-15 17:16:44: ... Breaking file junction C:\WINDOWS\$NtUninstallKB22248$\859542333
  1214. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\@
  1215. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1216. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\L\lzxioeez
  1217. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@00000001
  1218. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000c0
  1219. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cb
  1220. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cf
  1221. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@80000000
  1222. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000c0
  1223. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cb
  1224. 2012-03-15 17:16:44: ... File: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cf
  1225. 2012-03-15 17:16:44: Found BAD driver: 4CCC07945B5C5DE7B78F659062E5AC32 (bad) -> FB2FCCC70F7174C7BF64F48E96D3ADF4(good) MRXSMB.Sys
  1226. 2012-03-15 17:16:44: Written to SPB
  1227. 2012-03-15 17:16:44: Found BAD EXE: EE6C7350FFA2EB9F6E57B5486FFDB784 [\Device\HarddiskVolume1\WINDOWS\assembly\GAC_MSIL\Desktop.ini]
  1228. 2012-03-15 17:16:44: Written to SPB
  1229. 2012-03-15 17:16:44: Found BAD EXE: B89CFBE8CB247B57D8C10ADAA66B462B [%systemroot%\system32\csctl50.dll]
  1230. 2012-03-15 17:16:44: Written to SPB
  1231. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\@
  1232. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\X.BAD
  1233. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\00000001.@
  1234. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000c0.@
  1235. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cb.@
  1236. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cf.@
  1237. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\80000000.@
  1238. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000c0.@
  1239. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cb.@
  1240. 2012-03-15 17:16:44: Requesting bad file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cf.@
  1241. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\assembly\GAC_MSIL\desktop.ini
  1242. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\859542333
  1243. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\@
  1244. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1245. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\L\lzxioeez
  1246. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@00000001
  1247. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000c0
  1248. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cb
  1249. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cf
  1250. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@80000000
  1251. 2012-03-15 17:16:44: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000c0
  1252. 2012-03-15 17:16:45: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cb
  1253. 2012-03-15 17:16:45: Requesting bad file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cf
  1254. 2012-03-15 17:16:45: Running Extractor
  1255. 2012-03-15 17:16:46: Uploading file
  1256. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\@
  1257. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\X.BAD
  1258. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\00000001.@
  1259. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000c0.@
  1260. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cb.@
  1261. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\000000cf.@
  1262. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\80000000.@
  1263. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000c0.@
  1264. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cb.@
  1265. 2012-03-15 17:17:20: Locking file: C:\DOCUMENTS AND SETTINGS\THISISU\LOCAL SETTINGS\APPLICATION DATA\02e7abf0\U\800000cf.@
  1266. 2012-03-15 17:17:20: Locking file: C:\WINDOWS\assembly\GAC_MSIL\desktop.ini
  1267. 2012-03-15 17:17:20: Locking file: C:\WINDOWS\$NtUninstallKB22248$\859542333
  1268. 2012-03-15 17:17:20: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\@
  1269. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1270. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\L\lzxioeez
  1271. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@00000001
  1272. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000c0
  1273. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cb
  1274. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cf
  1275. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@80000000
  1276. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000c0
  1277. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cb
  1278. 2012-03-15 17:17:21: Locking file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cf
  1279. 2012-03-15 17:17:21: Processing 4CCC07945B5C5DE7B78F659062E5AC32|FB2FCCC70F7174C7BF64F48E96D3ADF4|MRXSMB.Sys
  1280. 2012-03-15 17:17:21: ...Looking for proper driver for MRXSMB.Sys
  1281. 2012-03-15 17:17:21: ...Found driver for MRXSMB.Sys in FB2FCCC70F7174C7BF64F48E96D3ADF4
  1282. 2012-03-15 17:17:21: Driver MRXSMB set to system32\DRIVERS\20120315171721.MRXSMB.sys (Read: system32\DRIVERS\20120315171721.MRXSMB.sys)
  1283. 2012-03-15 17:17:21: Movedriver: Registry replacement done.
  1284. 2012-03-15 17:17:21: Registry driver replacement done...
  1285. 2012-03-15 17:17:21: Adding bad EXE to md5s... EE6C7350FFA2EB9F6E57B5486FFDB784
  1286. 2012-03-15 17:17:21: Adding bad EXE to md5s... B89CFBE8CB247B57D8C10ADAA66B462B
  1287. 2012-03-15 17:17:21: Adding bad DRIVER to md5s... 4CCC07945B5C5DE7B78F659062E5AC32
  1288. 2012-03-15 17:17:21: Some drivers where replaced. We need to enforce...
  1289. 2012-03-15 17:17:21: Drivers replaced:
  1290. MRXSMB.Sys
  1291. 2012-03-15 17:17:21: EE6C7350FFA2EB9F6E57B5486FFDB784
  1292.  
  1293. B89CFBE8CB247B57D8C10ADAA66B462B
  1294.  
  1295. 4CCC07945B5C5DE7B78F659062E5AC32
  1296.  
  1297. 2012-03-15 17:17:21: Autonomous mode, clearing out yt folder
  1298. 2012-03-15 17:17:21: cmd.exe /c start "C:\Documents and Settings\thisisu\Desktop\yorkyt.exe"
  1299. 2012-03-15 17:17:50: Restarting...
  1300. 2012-03-15 17:18:13: ****************************************************
  1301. 2012-03-15 17:18:13: Starting UP ... v 0.0.0.190
  1302. 2012-03-15 17:18:13: ****************************************************
  1303. 2012-03-15 17:18:13: Listing processes...
  1304. 2012-03-15 17:18:13: :[System Process]:0
  1305. 2012-03-15 17:18:13: :System:4
  1306. 2012-03-15 17:18:13: :smss.exe:392
  1307. 2012-03-15 17:18:13: :csrss.exe:568
  1308. 2012-03-15 17:18:13: :winlogon.exe:592
  1309. 2012-03-15 17:18:13: :services.exe:644
  1310. 2012-03-15 17:18:13: :lsass.exe:656
  1311. 2012-03-15 17:18:13: :svchost.exe:812
  1312. 2012-03-15 17:18:13: :svchost.exe:892
  1313. 2012-03-15 17:18:13: :svchost.exe:988
  1314. 2012-03-15 17:18:13: :svchost.exe:1048
  1315. 2012-03-15 17:18:13: :svchost.exe:1104
  1316. 2012-03-15 17:18:13: :userinit.exe:1540
  1317. 2012-03-15 17:18:13: :explorer.exe:1556
  1318. 2012-03-15 17:18:13: :spoolsv.exe:1588
  1319. 2012-03-15 17:18:13: :yorkyt.exe:1664
  1320. 2012-03-15 17:18:13: :ctfmon.exe:1752
  1321. 2012-03-15 17:18:13: :wmiprvse.exe:1836
  1322. 2012-03-15 17:18:13:
  1323. 2012-03-15 17:18:13: Starting cleanup mode...
  1324. 2012-03-15 17:18:13: At item: 1 C:\WINDOWS\$NtUninstallKB22248$\48737264
  1325. 2012-03-15 17:18:13: At item: 2 C:\WINDOWS\$NtUninstallKB22248$\859542333
  1326. 2012-03-15 17:18:13: At item: 3 C:\WINDOWS\$NtUninstallKB22248$\48737264\@
  1327. 2012-03-15 17:18:13: At item: 4 C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1328. 2012-03-15 17:18:13: At item: 5 C:\WINDOWS\$NtUninstallKB22248$\48737264\L\lzxioeez
  1329. 2012-03-15 17:18:13: At item: 6 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@00000001
  1330. 2012-03-15 17:18:13: At item: 7 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000c0
  1331. 2012-03-15 17:18:13: At item: 8 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cb
  1332. 2012-03-15 17:18:13: At item: 9 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cf
  1333. 2012-03-15 17:18:13: At item: 10 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@80000000
  1334. 2012-03-15 17:18:13: At item: 11 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000c0
  1335. 2012-03-15 17:18:13: At item: 12 C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1336. 2012-03-15 17:18:13: At item: 13 C:\WINDOWS\$NtUninstallKB22248$\48737264
  1337. 2012-03-15 17:18:13: At item: 14 C:\WINDOWS\$NtUninstallKB22248$\48737264\L
  1338. 2012-03-15 17:18:13: At item: 15 C:\WINDOWS\$NtUninstallKB22248$\48737264\U
  1339. 2012-03-15 17:18:13: At item: 16 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cb
  1340. 2012-03-15 17:18:13: At item: 17 C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cf
  1341. 2012-03-15 17:18:13: .... Skipping folder.
  1342. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\859542333
  1343. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1344. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\@
  1345. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1346. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1347. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1348. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\L\lzxioeez
  1349. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1350. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@00000001
  1351. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1352. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000c0
  1353. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1354. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cb
  1355. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1356. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@000000cf
  1357. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1358. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@80000000
  1359. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1360. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000c0
  1361. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1362. 2012-03-15 17:18:13: .... Skipping folder.
  1363. 2012-03-15 17:18:13: .... Skipping folder.
  1364. 2012-03-15 17:18:13: .... Skipping folder.
  1365. 2012-03-15 17:18:13: .... Skipping folder.
  1366. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cb
  1367. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1368. 2012-03-15 17:18:13: ... Delete file: C:\WINDOWS\$NtUninstallKB22248$\48737264\U\@800000cf
  1369. 2012-03-15 17:18:13: !... File does not exist. Cannot be deleted.
  1370. 2012-03-15 17:18:13: ... Done with files, now folders
  1371. 2012-03-15 17:18:13: ... Processing folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\U
  1372. 2012-03-15 17:18:13: ... Processing folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\L
  1373. 2012-03-15 17:18:13: ... Processing folder: C:\WINDOWS\$NtUninstallKB22248$\48737264
  1374. 2012-03-15 17:18:13: ... Processing folder: C:\WINDOWS\$NtUninstallKB22248$\48737264\loader.tlb
  1375. 2012-03-15 17:18:13: .... Folder is gone.
  1376. 2012-03-15 17:18:13: ... Processing folder: C:\WINDOWS\$NtUninstallKB22248$\48737264
  1377. 2012-03-15 17:18:13: .... Folder is gone.
  1378. 2012-03-15 17:18:13: ... Done with folders.
  1379. 2012-03-15 17:18:55: All DONE
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement