Page 3 of 5 FirstFirst 12345 LastLast
Results 21 to 30 of 43

Thread: Various Trojans and slow computer

  1. #21
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    - 2004-08-04 10:00:00 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys
    + 2008-04-13 19:19:43 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys
    - 2004-08-04 10:00:00 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys
    + 2008-04-13 18:57:32 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys
    - 2004-08-04 10:00:00 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys
    + 2008-04-13 19:19:48 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys
    - 2006-05-05 09:47:57 174,592 ----a-w c:\windows\system32\drivers\rdbss.sys
    + 2008-04-13 19:28:39 175,744 ----a-w c:\windows\system32\drivers\rdbss.sys
    - 2004-08-04 05:01:16 196,864 ----a-w c:\windows\system32\drivers\rdpdr.sys
    + 2008-04-13 18:32:51 196,224 ----a-w c:\windows\system32\drivers\rdpdr.sys
    - 2005-06-10 04:09:46 139,528 ----a-w c:\windows\system32\drivers\rdpwd.sys
    + 2008-04-14 00:13:22 139,656 ----a-w c:\windows\system32\drivers\rdpwd.sys
    + 2004-08-04 02:41:40 13,776 ----a-w c:\windows\system32\drivers\recagent.sys
    - 2004-08-04 04:59:38 57,472 ----a-w c:\windows\system32\drivers\redbook.sys
    + 2008-04-13 18:40:27 57,600 ----a-w c:\windows\system32\drivers\redbook.sys
    + 2008-04-13 18:46:32 59,136 ----a-w c:\windows\system32\drivers\rfcomm.sys
    - 2005-10-14 14:40:18 28,544 ----a-w c:\windows\system32\drivers\rimmptsk.sys
    + 2006-11-15 05:16:24 32,256 ----a-w c:\windows\system32\drivers\rimmptsk.sys
    - 2005-10-14 14:40:18 51,328 ----a-w c:\windows\system32\drivers\rimsptsk.sys
    + 2006-11-15 00:42:46 43,520 ----a-w c:\windows\system32\drivers\rimsptsk.sys
    - 2005-10-14 14:40:18 307,968 ----a-w c:\windows\system32\drivers\rixdptsk.sys
    + 2006-11-14 22:35:20 37,376 ----a-w c:\windows\system32\drivers\rixdptsk.sys
    - 2006-07-13 08:48:58 202,240 ----a-w c:\windows\system32\drivers\rmcast.sys
    + 2008-05-08 14:02:52 203,136 ----a-w c:\windows\system32\drivers\rmcast.sys
    - 2004-08-04 10:00:00 30,080 ----a-w c:\windows\system32\drivers\rndismp.sys
    + 2008-04-13 18:56:49 30,592 ----a-w c:\windows\system32\drivers\rndismp.sys
    + 2008-04-13 18:56:49 30,592 ----a-w c:\windows\system32\drivers\rndismpx.sys
    - 2006-10-19 13:29:22 12,544 ----a-w c:\windows\system32\drivers\s24trans.sys
    + 2007-08-27 16:10:36 12,288 ----a-w c:\windows\system32\drivers\s24trans.sys
    + 2004-08-04 02:29:52 166,912 ----a-w c:\windows\system32\drivers\s3gnbm.sys
    - 2004-08-04 10:00:00 96,256 ----a-w c:\windows\system32\drivers\scsiport.sys
    + 2008-04-13 18:40:30 96,384 ----a-w c:\windows\system32\drivers\scsiport.sys
    - 2004-08-04 10:00:00 67,584 ----a-w c:\windows\system32\drivers\sdbus.sys
    + 2008-04-13 18:36:44 79,232 ----a-w c:\windows\system32\drivers\sdbus.sys
    - 2004-08-04 10:00:00 27,440 ----a-w c:\windows\system32\drivers\secdrv.sys
    + 2007-11-13 10:25:53 20,480 ----a-w c:\windows\system32\drivers\secdrv.sys
    - 2004-08-04 10:00:00 15,488 ----a-w c:\windows\system32\drivers\serenum.sys
    + 2008-04-13 18:40:12 15,744 ----a-w c:\windows\system32\drivers\serenum.sys
    - 2004-08-04 10:00:00 64,896 ----a-w c:\windows\system32\drivers\serial.sys
    + 2008-04-13 19:15:45 64,512 ----a-w c:\windows\system32\drivers\serial.sys
    - 2004-08-04 10:00:00 11,136 ----a-w c:\windows\system32\drivers\sffdisk.sys
    + 2008-04-13 18:40:47 11,904 ----a-w c:\windows\system32\drivers\sffdisk.sys
    + 2008-04-13 18:40:48 10,240 ----a-w c:\windows\system32\drivers\sffp_mmc.sys
    - 2004-08-04 10:00:00 10,240 ----a-w c:\windows\system32\drivers\sffp_sd.sys
    + 2008-04-13 18:40:47 11,008 ----a-w c:\windows\system32\drivers\sffp_sd.sys
    - 2004-08-04 10:00:00 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys
    + 2008-04-13 18:40:48 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys
    + 2008-04-14 00:12:05 3,901 ----a-w c:\windows\system32\drivers\siint5.dll
    - 2004-08-04 05:07:44 41,088 ----a-w c:\windows\system32\drivers\SISAGP.SYS
    + 2008-04-13 18:36:39 40,960 ----a-w c:\windows\system32\drivers\sisagp.sys
    + 2008-04-13 18:46:23 11,136 ----a-w c:\windows\system32\drivers\slip.sys
    + 2004-08-04 02:41:42 129,535 ----a-w c:\windows\system32\drivers\slnt7554.sys
    + 2004-08-04 02:41:44 404,990 ----a-w c:\windows\system32\drivers\slntamr.sys
    + 2004-08-04 02:41:46 95,424 ----a-w c:\windows\system32\drivers\slnthal.sys
    + 2004-08-04 02:41:46 13,240 ----a-w c:\windows\system32\drivers\slwdmsup.sys
    + 2008-04-13 18:36:34 5,888 ----a-w c:\windows\system32\drivers\smbali.sys
    - 2004-08-04 10:00:00 25,472 ----a-w c:\windows\system32\drivers\sonydcam.sys
    + 2008-04-13 18:46:07 25,344 ----a-w c:\windows\system32\drivers\sonydcam.sys
    - 2006-06-14 08:47:46 6,400 ----a-w c:\windows\system32\drivers\splitter.sys
    + 2008-04-13 18:45:07 6,272 ----a-w c:\windows\system32\drivers\splitter.sys
    - 2004-08-04 11:00:00 73,472 ----a-w c:\windows\system32\drivers\sr.sys
    + 2008-04-13 18:36:52 73,472 ----a-w c:\windows\system32\drivers\sr.sys
    - 2006-08-14 10:34:41 332,928 ----a-w c:\windows\system32\drivers\srv.sys
    + 2008-09-08 10:41:42 333,824 ----a-w c:\windows\system32\drivers\srv.sys
    - 2006-03-24 22:34:30 1,156,648 ----a-w c:\windows\system32\drivers\sthda.sys
    + 2007-05-10 15:24:34 1,222,840 ----a-w c:\windows\system32\drivers\sthda.sys
    - 2004-08-04 10:00:00 48,640 ----a-w c:\windows\system32\drivers\stream.sys
    + 2008-04-13 19:45:16 49,408 ----a-w c:\windows\system32\drivers\stream.sys
    + 2008-04-13 18:46:21 15,232 ----a-w c:\windows\system32\drivers\streamip.sys
    - 2004-08-04 10:00:00 4,352 ----a-w c:\windows\system32\drivers\swenum.sys
    + 2008-04-13 18:39:53 4,352 ----a-w c:\windows\system32\drivers\swenum.sys
    - 2004-08-04 10:00:00 54,272 ----a-w c:\windows\system32\drivers\swmidi.sys
    + 2008-04-13 18:45:09 56,576 ----a-w c:\windows\system32\drivers\swmidi.sys
    - 2004-08-04 10:00:00 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys
    + 2008-04-13 19:15:55 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys
    - 2004-08-04 10:00:00 14,976 ----a-w c:\windows\system32\drivers\tape.sys
    + 2008-04-13 18:40:50 14,976 ----a-w c:\windows\system32\drivers\tape.sys
    - 2006-04-20 11:51:50 359,808 ----a-w c:\windows\system32\drivers\tcpip.sys
    + 2008-06-20 11:51:12 361,600 ----a-w c:\windows\system32\drivers\tcpip.sys
    - 2006-08-16 09:37:30 225,664 ----a-w c:\windows\system32\drivers\tcpip6.sys
    + 2008-06-20 11:08:27 225,856 ----a-w c:\windows\system32\drivers\tcpip6.sys
    - 2004-08-04 10:00:00 18,560 ----a-w c:\windows\system32\drivers\tdi.sys
    + 2008-04-13 19:00:05 19,072 ----a-w c:\windows\system32\drivers\tdi.sys
    - 2004-08-04 11:00:00 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys
    + 2008-04-14 00:13:20 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys
    - 2004-08-04 11:00:00 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys
    + 2008-04-14 00:13:21 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys
    - 2004-08-04 07:01:08 40,840 ----a-w c:\windows\system32\drivers\termdd.sys
    + 2008-04-14 00:13:20 40,840 ----a-w c:\windows\system32\drivers\termdd.sys
    - 2004-08-04 10:00:00 12,416 ----a-w c:\windows\system32\drivers\tunmp.sys
    + 2008-04-13 18:56:01 12,288 ----a-w c:\windows\system32\drivers\tunmp.sys
    - 2004-08-04 10:00:00 44,672 ----a-w c:\windows\system32\drivers\uagp35.sys
    + 2008-04-13 18:36:40 44,672 ----a-w c:\windows\system32\drivers\uagp35.sys
    - 2004-08-04 10:00:00 66,176 ----a-w c:\windows\system32\drivers\udfs.sys
    + 2008-04-13 18:32:36 66,048 ----a-w c:\windows\system32\drivers\udfs.sys
    - 2007-04-23 10:32:54 364,160 ----a-w c:\windows\system32\drivers\update.sys
    + 2008-04-13 18:39:46 384,768 ----a-w c:\windows\system32\drivers\update.sys
    - 2004-08-04 10:00:00 12,672 ----a-w c:\windows\system32\drivers\usb8023.sys
    + 2008-04-13 18:56:49 12,800 ----a-w c:\windows\system32\drivers\usb8023.sys
    + 2008-04-13 18:56:49 12,800 ----a-w c:\windows\system32\drivers\usb8023x.sys
    + 2008-04-13 18:45:12 60,032 ----a-w c:\windows\system32\drivers\usbaudio.sys
    - 2004-08-04 10:00:00 23,808 ----a-w c:\windows\system32\drivers\usbcamd.sys
    + 2008-04-13 18:45:40 25,600 ----a-w c:\windows\system32\drivers\usbcamd.sys
    - 2004-08-04 10:00:00 23,936 ----a-w c:\windows\system32\drivers\usbcamd2.sys
    + 2008-04-13 18:45:41 25,728 ----a-w c:\windows\system32\drivers\usbcamd2.sys
    - 2004-08-04 10:00:00 31,616 ----a-w c:\windows\system32\drivers\usbccgp.sys
    + 2008-04-13 18:45:39 32,128 ----a-w c:\windows\system32\drivers\usbccgp.sys
    - 2004-08-04 10:00:00 26,624 ----a-w c:\windows\system32\drivers\usbehci.sys
    + 2008-04-13 18:45:35 30,208 ----a-w c:\windows\system32\drivers\usbehci.sys
    - 2004-08-04 10:00:00 57,600 ----a-w c:\windows\system32\drivers\usbhub.sys
    + 2008-04-13 18:45:37 59,520 ----a-w c:\windows\system32\drivers\usbhub.sys
    - 2004-08-04 10:00:00 16,000 ----a-w c:\windows\system32\drivers\usbintel.sys
    + 2008-04-13 18:45:43 15,872 ----a-w c:\windows\system32\drivers\usbintel.sys
    - 2004-08-04 10:00:00 142,976 ----a-w c:\windows\system32\drivers\usbport.sys
    + 2008-04-13 18:45:36 143,872 ----a-w c:\windows\system32\drivers\usbport.sys
    - 2004-08-04 02:58:46 15,104 ----a-w c:\windows\system32\drivers\usbscan.sys
    + 2008-04-13 18:45:34 15,104 ----a-w c:\windows\system32\drivers\usbscan.sys
    - 2004-08-04 10:00:00 26,496 ----a-w c:\windows\system32\drivers\usbstor.sys
    + 2008-04-13 18:45:38 26,368 ----a-w c:\windows\system32\drivers\usbstor.sys
    - 2004-08-04 10:00:00 20,480 ----a-w c:\windows\system32\drivers\usbuhci.sys
    + 2008-04-13 18:45:35 20,608 ----a-w c:\windows\system32\drivers\usbuhci.sys
    + 2008-04-13 18:46:20 121,984 ----a-w c:\windows\system32\drivers\usbvideo.sys
    + 2008-04-14 00:12:08 11,325 ----a-w c:\windows\system32\drivers\vchnt5.dll
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\drivers\vga.sys
    + 2008-04-13 18:44:40 20,992 ----a-w c:\windows\system32\drivers\vga.sys
    - 2004-08-04 05:07:44 42,240 ----a-w c:\windows\system32\drivers\VIAAGP.SYS
    + 2008-04-13 18:36:40 42,240 ----a-w c:\windows\system32\drivers\viaagp.sys
    - 2004-08-04 10:00:00 5,376 ----a-w c:\windows\system32\drivers\viaide.sys
    + 2008-04-13 18:40:31 5,376 ----a-w c:\windows\system32\drivers\viaide.sys
    - 2004-08-04 10:00:00 79,744 ----a-w c:\windows\system32\drivers\videoprt.sys
    + 2008-04-13 18:44:40 81,664 ----a-w c:\windows\system32\drivers\videoprt.sys
    - 2004-08-04 10:00:00 52,352 ----a-w c:\windows\system32\drivers\volsnap.sys
    + 2008-04-13 18:41:01 52,352 ----a-w c:\windows\system32\drivers\volsnap.sys
    + 2008-04-13 18:43:55 14,208 ----a-w c:\windows\system32\drivers\wacompen.sys
    + 2004-08-04 02:29:40 11,807 ----a-w c:\windows\system32\drivers\wadv07nt.sys
    + 2004-08-04 02:29:40 11,295 ----a-w c:\windows\system32\drivers\wadv08nt.sys
    + 2004-08-04 02:29:42 11,871 ----a-w c:\windows\system32\drivers\wadv09nt.sys
    + 2004-08-04 02:29:42 11,935 ----a-w c:\windows\system32\drivers\wadv11nt.sys
    - 2004-08-04 10:00:00 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys
    + 2008-04-13 18:57:21 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys
    + 2004-08-04 02:29:46 22,271 ----a-w c:\windows\system32\drivers\watv06nt.sys
    + 2004-08-04 02:29:46 25,471 ----a-w c:\windows\system32\drivers\watv10nt.sys
    - 2006-06-14 09:00:45 82,944 ----a-w c:\windows\system32\drivers\wdmaud.sys
    + 2008-04-13 19:17:18 83,072 ----a-w c:\windows\system32\drivers\wdmaud.sys
    - 2004-08-04 10:00:00 8,832 ----a-w c:\windows\system32\drivers\wmiacpi.sys
    + 2008-04-13 18:36:38 8,832 ----a-w c:\windows\system32\drivers\wmiacpi.sys
    + 2008-04-13 18:46:24 19,200 ----a-w c:\windows\system32\drivers\wstcodec.sys
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\drprov.dll
    + 2008-04-14 00:11:52 14,336 ----a-w c:\windows\system32\drprov.dll
    + 2006-11-21 09:20:26 49,507 -c--a-r c:\windows\system32\DRVSTORE\b44win_A4FF09C646CF97A72E7241C9A8D160636A21E4F9\bcm4sbe5.sys
    + 2006-11-21 09:25:44 45,568 -c--a-r c:\windows\system32\DRVSTORE\b44win_A4FF09C646CF97A72E7241C9A8D160636A21E4F9\bcm4sbxp.sys
    + 2008-04-17 17:12:54 107,368 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
    + 2008-04-17 17:12:54 15,464 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
    + 2007-03-31 00:59:08 102,400 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\hccutils.dll
    + 2007-03-31 01:00:16 162,584 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\hkcmd.exe
    + 2007-03-31 01:01:10 535,320 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxcfg.exe
    + 2007-03-31 00:59:06 204,800 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxdev.dll
    + 2007-03-31 00:59:36 135,168 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxdo.dll
    + 2007-03-31 00:59:36 24,576 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxexps.dll
    + 2007-03-31 00:59:34 166,680 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxext.exe
    + 2007-03-31 00:59:36 138,008 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxpers.exe
    + 2007-03-31 00:59:44 200,704 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxpph.dll
    + 2007-03-31 00:58:56 3,293,184 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxress.dll
    + 2007-03-31 00:59:28 47,616 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxsrvc.dll
    + 2007-03-31 00:59:26 252,696 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxsrvc.exe
    + 2007-03-31 01:00:02 138,008 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxtray.exe
    + 2007-03-31 00:59:20 170,776 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igfxzoom.exe
    + 2007-03-31 01:33:06 450,560 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igldev32.dll
    + 2007-03-31 01:31:28 2,334,720 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\iglicd32.dll
    + 2007-03-31 03:12:06 204,800 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxpco32.dll
    + 2007-03-31 02:33:36 1,612,992 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxpdv32.dll
    + 2007-03-31 02:34:44 2,556,928 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxpdx32.dll
    + 2007-03-31 02:33:50 149,504 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxpgd32.dll
    + 2007-03-31 02:34:14 5,704,672 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxpmp32.sys
    + 2007-03-31 02:33:56 57,344 -c--a-w c:\windows\system32\DRVSTORE\igxp32_453A810A6A9A3F8A6B98ECF50E6C2D6AFBD77BDE\igxprd32.dll
    + 2007-08-27 16:12:00 745,472 -c--a-w c:\windows\system32\DRVSTORE\netw4k32_4CD46BE21BE74C8D663C65B8DC2D7EEA091E50F5\NETw4c32.dll
    + 2007-09-26 10:59:38 2,230,912 -c--a-w c:\windows\system32\DRVSTORE\netw4k32_4CD46BE21BE74C8D663C65B8DC2D7EEA091E50F5\NETw4k32.sys
    + 2007-08-27 16:12:58 2,777,088 -c--a-w c:\windows\system32\DRVSTORE\netw4k32_4CD46BE21BE74C8D663C65B8DC2D7EEA091E50F5\NETw4r32.dll
    + 2007-08-27 16:12:00 745,472 -c--a-w c:\windows\system32\DRVSTORE\netw4x32_B0AEEEEDA759744D7D2AC236F54CA6D4CFC0961C\NETw4c32.dll
    + 2007-08-27 16:12:58 2,777,088 -c--a-w c:\windows\system32\DRVSTORE\netw4x32_B0AEEEEDA759744D7D2AC236F54CA6D4CFC0961C\NETw4r32.dll
    + 2007-09-26 11:01:32 2,236,032 -c--a-w c:\windows\system32\DRVSTORE\netw4x32_B0AEEEEDA759744D7D2AC236F54CA6D4CFC0961C\NETw4x32.sys
    + 2006-11-15 05:16:24 32,256 -c--a-w c:\windows\system32\DRVSTORE\rimmptsk_01759BDBD4096A5241053A76A22A5A5BAC1000AE\rimmptsk.sys
    + 2006-11-15 00:42:46 43,520 -c--a-w c:\windows\system32\DRVSTORE\rimsptsk_160EAF8844DAFFD63505557B90B41496E64C136A\rimsptsk.sys
    + 2004-09-03 15:00:00 90,112 -c--a-w c:\windows\system32\DRVSTORE\rimsptsk_160EAF8844DAFFD63505557B90B41496E64C136A\snymsico.dll
    + 2005-05-07 00:06:00 16,480 -c--a-w c:\windows\system32\DRVSTORE\rixdptsk_0D7A83C1B48CDC1DF8A41B44C97F2A9295350D76\rixdicon.dll
    + 2006-11-14 22:35:20 37,376 -c--a-w c:\windows\system32\DRVSTORE\rixdptsk_0D7A83C1B48CDC1DF8A41B44C97F2A9295350D76\rixdptsk.sys
    + 2008-11-07 19:23:30 32,000 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
    + 2007-02-12 17:40:44 557,056 -c--a-w c:\windows\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\Netw2c32.dll
    + 2007-02-12 17:41:44 2,732,032 -c--a-w c:\windows\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\Netw2r32.dll
    + 2007-07-25 22:45:42 2,206,464 -c--a-w c:\windows\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\w29n50.sys
    + 2007-07-25 22:44:28 2,210,048 -c--a-w c:\windows\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\w29n51.sys
    - 2004-08-04 10:00:00 16,384 ----a-w c:\windows\system32\ds32gt.dll
    + 2008-04-14 00:11:52 16,384 ----a-w c:\windows\system32\ds32gt.dll
    - 2004-08-04 10:00:00 181,760 ----a-w c:\windows\system32\dsdmo.dll
    + 2008-04-14 00:11:52 181,248 ----a-w c:\windows\system32\dsdmo.dll
    - 2004-08-04 10:00:00 71,680 ----a-w c:\windows\system32\dsdmoprp.dll
    + 2008-04-14 00:11:52 71,680 ----a-w c:\windows\system32\dsdmoprp.dll
    - 2004-08-04 10:00:00 92,672 ----a-w c:\windows\system32\dskquota.dll
    + 2008-04-14 00:11:52 92,672 ----a-w c:\windows\system32\dskquota.dll
    - 2004-08-04 10:00:00 144,384 ----a-w c:\windows\system32\dskquoui.dll
    + 2008-04-14 00:11:52 155,648 ----a-w c:\windows\system32\dskquoui.dll
    - 2004-08-04 10:00:00 367,616 ----a-w c:\windows\system32\dsound.dll
    + 2008-04-14 00:11:52 367,616 ----a-w c:\windows\system32\dsound.dll
    - 2004-08-04 10:00:00 1,294,336 ----a-w c:\windows\system32\dsound3d.dll
    + 2008-04-14 00:11:52 1,293,824 ----a-w c:\windows\system32\dsound3d.dll
    - 2004-08-04 10:00:00 142,336 ----a-w c:\windows\system32\dsprop.dll
    + 2008-04-14 00:11:52 142,848 ----a-w c:\windows\system32\dsprop.dll
    - 2004-08-04 10:00:00 4,096 ----a-w c:\windows\system32\dsprpres.dll
    + 2008-04-13 17:09:30 4,096 ----a-w c:\windows\system32\dsprpres.dll
    - 2004-08-04 10:00:00 239,104 ----a-w c:\windows\system32\dsquery.dll
    + 2008-04-14 00:11:52 239,104 ----a-w c:\windows\system32\dsquery.dll
    - 2004-08-04 10:00:00 51,200 ----a-w c:\windows\system32\dssec.dll
    + 2008-04-14 00:11:52 51,200 ----a-w c:\windows\system32\dssec.dll
    - 2004-08-04 10:00:00 137,216 ----a-w c:\windows\system32\dssenh.dll
    + 2008-04-13 17:37:57 138,752 ----a-w c:\windows\system32\dssenh.dll
    - 2004-08-04 10:00:00 113,152 ----a-w c:\windows\system32\dsuiext.dll
    + 2008-04-14 00:11:52 113,152 ----a-w c:\windows\system32\dsuiext.dll
    - 2004-08-04 10:00:00 19,456 ----a-w c:\windows\system32\dswave.dll
    + 2008-04-14 00:11:52 19,456 ----a-w c:\windows\system32\dswave.dll
    - 2004-08-04 10:00:00 10,752 ----a-w c:\windows\system32\dumprep.exe
    + 2008-04-14 00:12:18 10,752 ----a-w c:\windows\system32\dumprep.exe
    - 2004-08-04 10:00:00 304,128 ----a-w c:\windows\system32\duser.dll
    + 2008-04-14 00:11:52 304,128 ----a-w c:\windows\system32\duser.dll
    - 2004-08-04 10:00:00 17,920 ----a-w c:\windows\system32\dvdupgrd.exe
    + 2008-04-14 00:12:18 17,920 ----a-w c:\windows\system32\dvdupgrd.exe
    - 2004-08-04 10:00:00 180,224 ----a-w c:\windows\system32\dwwin.exe
    + 2008-04-14 00:12:18 180,224 ----a-w c:\windows\system32\dwwin.exe
    - 2004-08-04 10:00:00 619,008 ----a-w c:\windows\system32\dx7vb.dll
    + 2008-04-14 00:11:52 619,008 ----a-w c:\windows\system32\dx7vb.dll
    - 2004-08-04 10:00:00 1,227,264 ----a-w c:\windows\system32\dx8vb.dll
    + 2008-04-14 00:11:52 1,227,264 ----a-w c:\windows\system32\dx8vb.dll
    - 2004-08-04 10:00:00 1,298,432 ----a-w c:\windows\system32\dxdiag.exe
    + 2008-04-14 00:12:18 1,298,432 ----a-w c:\windows\system32\dxdiag.exe
    - 2004-08-04 10:00:00 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll
    + 2008-04-14 00:11:52 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll
    - 2006-08-22 08:05:26 498,742 ----a-w c:\windows\system32\dxmasf.dll
    + 2008-04-14 00:11:52 498,742 ----a-w c:\windows\system32\dxmasf.dll
    - 2006-10-17 15:58:06 346,624 ----a-w c:\windows\system32\dxtmsft.dll
    + 2008-08-26 07:24:28 347,136 ----a-w c:\windows\system32\dxtmsft.dll
    - 2007-08-20 10:04:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
    + 2008-08-26 07:24:28 214,528 ----a-w c:\windows\system32\dxtrans.dll
    - 2006-10-21 01:29:46 69,408 ----a-w c:\windows\system32\dxva2.dll
    + 2007-10-09 18:03:00 73,752 ----a-w c:\windows\system32\dxva2.dll

  2. #22
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    + 2008-04-14 00:11:52 30,720 ----a-w c:\windows\system32\eapolqec.dll
    + 2008-04-14 00:11:52 184,832 ----a-w c:\windows\system32\eapp3hst.dll
    + 2008-04-14 00:11:52 126,976 ----a-w c:\windows\system32\eappcfg.dll
    + 2008-04-14 00:11:52 94,208 ----a-w c:\windows\system32\eappgnui.dll
    + 2008-04-14 00:11:52 180,224 ----a-w c:\windows\system32\eapphost.dll
    + 2008-04-14 00:11:52 40,960 ----a-w c:\windows\system32\eappprxy.dll
    + 2008-04-14 00:11:52 59,392 ----a-w c:\windows\system32\eapqec.dll
    + 2008-04-14 00:11:52 33,792 ----a-w c:\windows\system32\eapsvc.dll
    - 2004-08-04 10:00:00 183,296 ----a-w c:\windows\system32\els.dll
    + 2008-04-14 00:11:53 183,296 ----a-w c:\windows\system32\els.dll
    + 2008-04-14 00:11:57 28,672 -c--a-w c:\windows\system32\en\microsoft.managementconsole.resources.dll
    + 2008-04-14 00:11:57 40,960 -c--a-w c:\windows\system32\en\mmcex.resources.dll
    + 2008-04-14 00:11:57 6,656 -c--a-w c:\windows\system32\en\mmcfxcommon.resources.dll
    - 2004-08-04 10:00:00 20,480 ----a-w c:\windows\system32\encapi.dll
    + 2008-04-14 00:11:53 20,480 ----a-w c:\windows\system32\encapi.dll
    - 2004-08-04 10:00:00 186,368 ----a-w c:\windows\system32\encdec.dll
    + 2008-04-14 00:11:53 186,880 ----a-w c:\windows\system32\encdec.dll
    - 2004-08-04 10:00:00 23,040 ----a-w c:\windows\system32\ersvc.dll
    + 2008-04-14 00:11:53 23,040 ----a-w c:\windows\system32\ersvc.dll
    - 2005-07-26 04:39:45 243,200 ----a-w c:\windows\system32\es.dll
    + 2008-07-07 20:26:58 253,952 ----a-w c:\windows\system32\es.dll
    - 2005-10-20 22:20:03 1,082,368 ----a-w c:\windows\system32\esent.dll
    + 2008-04-14 00:11:53 1,082,368 ----a-w c:\windows\system32\esent.dll
    - 2004-08-04 10:00:00 193,024 ----a-w c:\windows\system32\eudcedit.exe
    + 2008-04-14 00:12:19 193,024 ----a-w c:\windows\system32\eudcedit.exe
    - 2004-08-04 10:00:00 55,808 ----a-w c:\windows\system32\eventlog.dll
    + 2008-04-14 00:11:53 56,320 ----a-w c:\windows\system32\eventlog.dll
    - 2006-10-21 01:30:00 478,496 ----a-w c:\windows\system32\evr.dll
    + 2007-10-09 18:03:12 493,080 ----a-w c:\windows\system32\evr.dll
    - 2004-08-04 10:00:00 380,957 ----a-w c:\windows\system32\expsrv.dll
    + 2008-04-14 00:11:53 380,445 ----a-w c:\windows\system32\expsrv.dll
    - 2007-08-20 10:04:34 132,608 ----a-w c:\windows\system32\extmgr.dll
    + 2008-08-26 07:24:28 133,120 ----a-w c:\windows\system32\extmgr.dll
    - 2004-08-04 10:00:00 45,568 ----a-w c:\windows\system32\extrac32.exe
    + 2008-04-14 00:12:19 24,064 ----a-w c:\windows\system32\extrac32.exe
    - 2004-08-04 10:00:00 121,856 ----a-w c:\windows\system32\exts.dll
    + 2008-04-14 00:11:53 125,952 ----a-w c:\windows\system32\exts.dll
    - 2004-08-04 10:00:00 80,384 ----a-w c:\windows\system32\faultrep.dll
    + 2008-04-14 00:11:53 80,384 ----a-w c:\windows\system32\faultrep.dll
    + 2008-04-14 00:12:20 20,992 ----a-w c:\windows\system32\faxpatch.exe
    - 2004-08-04 10:00:00 21,504 ----a-w c:\windows\system32\feclient.dll
    + 2008-04-14 00:11:53 21,504 ----a-w c:\windows\system32\feclient.dll
    - 2004-08-04 10:00:00 337,920 ----a-w c:\windows\system32\filemgmt.dll
    + 2008-04-14 00:11:53 337,920 ----a-w c:\windows\system32\filemgmt.dll
    - 2004-08-04 10:00:00 27,136 ----a-w c:\windows\system32\findstr.exe
    + 2008-04-14 00:12:20 27,136 ----a-w c:\windows\system32\findstr.exe
    - 2004-08-04 10:00:00 87,552 ----a-w c:\windows\system32\fldrclnr.dll
    + 2008-04-14 00:11:53 87,552 ----a-w c:\windows\system32\fldrclnr.dll
    - 2006-08-21 12:21:06 16,896 ----a-w c:\windows\system32\fltlib.dll
    + 2008-04-14 00:11:53 16,896 ----a-w c:\windows\system32\fltlib.dll
    - 2006-08-21 09:14:58 23,040 ----a-w c:\windows\system32\fltmc.exe
    + 2008-04-14 00:12:20 23,040 ----a-w c:\windows\system32\fltmc.exe
    - 2007-10-21 15:53:49 267,800 ----a-w c:\windows\system32\FNTCACHE.DAT
    + 2008-11-29 13:22:34 274,968 ----a-w c:\windows\system32\FNTCACHE.DAT
    - 2004-08-04 10:00:00 382,976 ----a-w c:\windows\system32\fontext.dll
    + 2008-04-14 00:11:53 382,976 ----a-w c:\windows\system32\fontext.dll
    - 2005-10-17 21:14:45 80,896 ----a-w c:\windows\system32\fontsub.dll
    + 2008-04-14 00:11:53 80,896 ----a-w c:\windows\system32\fontsub.dll
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\fontview.exe
    + 2008-04-14 00:12:20 20,992 ----a-w c:\windows\system32\fontview.exe
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\forcedos.exe
    + 2008-04-14 00:12:20 7,680 ----a-w c:\windows\system32\forcedos.exe
    - 2004-08-04 10:00:00 25,600 ----a-w c:\windows\system32\format.com
    + 2008-04-14 00:12:42 29,696 ----a-w c:\windows\system32\format.com
    - 2004-08-04 10:00:00 9,344 ----a-w c:\windows\system32\framebuf.dll
    + 2008-04-14 00:09:33 9,344 ----a-w c:\windows\system32\framebuf.dll
    + 2008-07-27 20:41:22 2,084,864 ----a-w c:\windows\system32\FreeImage.dll
    - 2004-08-04 10:00:00 193,024 ----a-w c:\windows\system32\fsquirt.exe
    + 2008-04-14 00:12:20 193,024 ----a-w c:\windows\system32\fsquirt.exe
    - 2004-08-04 10:00:00 42,496 ----a-w c:\windows\system32\ftp.exe
    + 2008-04-14 00:12:20 42,496 ----a-w c:\windows\system32\ftp.exe
    - 2004-08-04 10:00:00 60,416 ----a-w c:\windows\system32\fwcfg.dll
    + 2008-04-14 00:11:53 60,416 ----a-w c:\windows\system32\fwcfg.dll
    - 2004-08-04 11:00:00 452,096 ----a-w c:\windows\system32\fxsapi.dll
    + 2008-04-14 00:11:53 451,584 ----a-w c:\windows\system32\fxsapi.dll
    - 2004-08-04 11:00:00 143,360 ----a-w c:\windows\system32\fxsclnt.exe
    + 2008-04-14 00:12:21 142,848 ----a-w c:\windows\system32\fxsclnt.exe
    - 2004-08-04 11:00:00 72,192 ----a-w c:\windows\system32\fxscom.dll
    + 2008-04-14 00:11:54 72,192 ----a-w c:\windows\system32\fxscom.dll
    - 2004-08-04 11:00:00 285,184 ----a-w c:\windows\system32\fxscomex.dll
    + 2008-04-14 00:11:54 285,184 ----a-w c:\windows\system32\fxscomex.dll
    - 2004-08-04 11:00:00 229,376 ----a-w c:\windows\system32\fxscover.exe
    + 2008-04-14 00:12:21 229,376 ----a-w c:\windows\system32\fxscover.exe
    - 2004-08-04 11:00:00 27,136 ----a-w c:\windows\system32\fxsdrv.dll
    + 2008-04-14 00:11:54 26,624 ----a-w c:\windows\system32\fxsdrv.dll
    - 2004-08-04 11:00:00 55,296 ----a-w c:\windows\system32\fxsevent.dll
    + 2008-04-14 00:11:54 55,296 ----a-w c:\windows\system32\fxsevent.dll
    - 2004-08-04 11:00:00 23,552 ----a-w c:\windows\system32\fxsext32.dll
    + 2008-04-14 00:11:54 23,552 ----a-w c:\windows\system32\fxsext32.dll
    - 2004-08-04 11:00:00 23,552 ----a-w c:\windows\system32\fxsmon.dll
    + 2008-04-14 00:11:54 23,552 ----a-w c:\windows\system32\fxsmon.dll
    - 2004-08-04 11:00:00 8,704 ----a-w c:\windows\system32\fxsperf.dll
    + 2008-04-14 00:11:54 8,704 ----a-w c:\windows\system32\fxsperf.dll
    - 2004-08-04 11:00:00 6,656 ----a-w c:\windows\system32\fxsres.dll
    + 2008-04-14 00:09:33 6,656 ----a-w c:\windows\system32\fxsres.dll
    - 2004-08-04 11:00:00 562,176 ----a-w c:\windows\system32\fxsst.dll
    + 2008-04-14 00:11:54 562,176 ----a-w c:\windows\system32\fxsst.dll
    - 2004-08-04 11:00:00 267,776 ----a-w c:\windows\system32\fxssvc.exe
    + 2008-04-14 00:12:21 267,776 ----a-w c:\windows\system32\fxssvc.exe
    - 2004-08-04 11:00:00 246,272 ----a-w c:\windows\system32\fxst30.dll
    + 2008-04-14 00:11:54 246,272 ----a-w c:\windows\system32\fxst30.dll
    - 2004-08-04 11:00:00 397,312 ----a-w c:\windows\system32\fxstiff.dll
    + 2008-04-14 00:11:54 397,312 ----a-w c:\windows\system32\fxstiff.dll
    - 2004-08-04 11:00:00 154,112 ----a-w c:\windows\system32\fxsui.dll
    + 2008-04-14 00:11:54 154,112 ----a-w c:\windows\system32\fxsui.dll
    - 2004-08-04 11:00:00 192,512 ----a-w c:\windows\system32\fxswzrd.dll
    + 2008-04-14 00:11:54 192,512 ----a-w c:\windows\system32\fxswzrd.dll
    - 2004-08-04 11:00:00 400,384 ----a-w c:\windows\system32\fxsxp32.dll
    + 2008-04-14 00:11:54 400,384 ----a-w c:\windows\system32\fxsxp32.dll
    - 2007-06-19 13:31:19 282,112 ----a-w c:\windows\system32\gdi32.dll
    + 2008-04-14 00:11:54 285,184 ----a-w c:\windows\system32\gdi32.dll
    - 2006-10-03 23:47:52 109,360 ----a-w c:\windows\system32\GEARAspi.dll
    + 2008-04-17 17:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
    - 2004-08-04 10:00:00 122,880 ----a-w c:\windows\system32\glu32.dll
    + 2008-04-14 00:11:54 122,880 ----a-w c:\windows\system32\glu32.dll
    - 2004-08-04 10:00:00 9,728 ----a-w c:\windows\system32\gpkrsrc.dll
    + 2006-12-31 01:26:44 9,728 ----a-w c:\windows\system32\gpkrsrc.dll
    + 2008-10-08 23:25:50 135,168 ----a-w c:\windows\system32\GraphicalDLL.dll
    - 2004-08-04 10:00:00 39,424 ----a-w c:\windows\system32\grpconv.exe
    + 2008-04-14 00:12:21 39,424 ----a-w c:\windows\system32\grpconv.exe
    - 2004-08-04 10:00:00 614,912 ----a-w c:\windows\system32\h323msp.dll
    + 2008-04-14 00:11:54 614,912 ----a-w c:\windows\system32\h323msp.dll
    - 2004-08-04 10:00:00 134,400 ----a-w c:\windows\system32\hal.dll
    + 2008-04-13 18:31:28 134,400 ----a-w c:\windows\system32\HAL.DLL
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\hccoin.dll
    + 2008-04-14 00:11:54 7,168 ----a-w c:\windows\system32\hccoin.dll
    - 2005-12-13 22:39:58 73,728 ----a-w c:\windows\system32\hccutils.dll
    + 2007-03-31 00:59:08 102,400 ----a-w c:\windows\system32\hccutils.dll
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\help.exe
    + 2008-04-14 00:12:21 15,872 ----a-w c:\windows\system32\help.exe
    - 2005-05-27 02:04:27 41,472 ----a-w c:\windows\system32\hhsetup.dll
    + 2008-04-14 00:11:54 41,472 ----a-w c:\windows\system32\hhsetup.dll
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\hid.dll
    + 2008-04-14 00:11:54 20,992 ----a-w c:\windows\system32\hid.dll
    - 2004-08-04 10:00:00 21,504 ----a-w c:\windows\system32\hidserv.dll
    + 2008-04-14 00:11:54 21,504 ----a-w c:\windows\system32\hidserv.dll
    - 2005-12-13 22:41:08 77,824 ----a-w c:\windows\system32\hkcmd.exe
    + 2007-03-31 01:00:16 162,584 ----a-w c:\windows\system32\hkcmd.exe
    - 2006-07-21 08:24:43 72,704 ----a-w c:\windows\system32\hlink.dll
    + 2008-04-14 00:11:54 72,704 ----a-w c:\windows\system32\hlink.dll
    - 2004-08-04 10:00:00 344,064 ----a-w c:\windows\system32\hnetcfg.dll
    + 2008-04-14 00:11:54 344,064 ----a-w c:\windows\system32\hnetcfg.dll
    - 2004-08-04 10:00:00 330,752 ----a-w c:\windows\system32\hnetwiz.dll
    + 2008-04-14 00:11:54 330,752 ----a-w c:\windows\system32\hnetwiz.dll
    - 2004-08-04 10:00:00 144,896 ----a-w c:\windows\system32\hotplug.dll
    + 2008-04-14 00:11:54 144,896 ----a-w c:\windows\system32\hotplug.dll
    + 2008-04-14 00:11:54 32,285 ----a-w c:\windows\system32\hsfcisp2.dll
    - 2004-08-04 10:00:00 24,576 ----a-w c:\windows\system32\httpapi.dll
    + 2008-04-14 00:11:54 24,576 ----a-w c:\windows\system32\httpapi.dll
    - 2004-08-04 10:00:00 41,984 ----a-w c:\windows\system32\htui.dll
    + 2008-04-14 00:11:54 41,984 ----a-w c:\windows\system32\htui.dll
    - 2004-11-17 17:41:24 347,136 ----a-w c:\windows\system32\hypertrm.dll
    + 2008-04-14 00:11:54 347,136 ----a-w c:\windows\system32\hypertrm.dll
    + 1998-11-18 19:33:16 144,384 ----a-w c:\windows\system32\Iacenc.dll
    - 2004-08-04 10:00:00 119,808 ----a-w c:\windows\system32\iasrad.dll
    + 2008-04-14 00:11:54 119,808 ----a-w c:\windows\system32\iasrad.dll
    - 2004-08-04 11:00:00 11,264 ----a-w c:\windows\system32\icaapi.dll
    + 2008-04-14 00:11:54 11,264 ----a-w c:\windows\system32\icaapi.dll
    - 2006-10-30 07:33:58 556,296 ----a-w c:\windows\system32\icardagt.exe
    + 2007-10-11 14:55:10 579,584 ----a-w c:\windows\system32\icardagt.exe
    - 2007-08-20 10:04:34 63,488 ----a-w c:\windows\system32\icardie.dll
    + 2008-08-26 07:24:28 63,488 ----a-w c:\windows\system32\icardie.dll
    - 2006-10-30 07:33:58 9,480 ----a-w c:\windows\system32\icardres.dll
    + 2007-10-11 14:55:10 11,776 ----a-w c:\windows\system32\icardres.dll
    - 2004-08-04 10:00:00 80,384 ----a-w c:\windows\system32\iccvid.dll
    + 2008-04-14 00:11:54 80,384 ----a-w c:\windows\system32\iccvid.dll
    - 2005-06-29 01:46:00 254,976 ----a-w c:\windows\system32\icm32.dll
    + 2008-04-14 00:11:54 254,976 ----a-w c:\windows\system32\icm32.dll
    - 2004-08-04 10:00:00 3,584 ----a-w c:\windows\system32\icmp.dll
    + 2008-04-14 00:09:40 3,584 ----a-w c:\windows\system32\icmp.dll
    - 2004-08-04 11:00:00 73,728 ----a-w c:\windows\system32\icwdial.dll
    + 2008-04-14 00:11:54 73,728 ----a-w c:\windows\system32\icwdial.dll
    - 2004-08-04 11:00:00 65,536 ----a-w c:\windows\system32\icwphbk.dll
    + 2008-04-14 00:11:54 65,536 ----a-w c:\windows\system32\icwphbk.dll
    - 2004-08-04 10:00:00 120,832 ----a-w c:\windows\system32\idq.dll
    + 2008-04-14 00:11:54 120,832 ----a-w c:\windows\system32\idq.dll
    - 2007-08-17 10:20:54 63,488 ----a-w c:\windows\system32\ie4uinit.exe
    + 2008-08-25 08:37:59 70,656 ----a-w c:\windows\system32\ie4uinit.exe
    - 2007-08-20 10:04:34 153,088 ----a-w c:\windows\system32\ieakeng.dll
    + 2008-08-26 07:24:28 153,088 ----a-w c:\windows\system32\ieakeng.dll
    - 2007-08-20 10:04:35 230,400 ----a-w c:\windows\system32\ieaksie.dll
    + 2008-08-26 07:24:28 230,400 ----a-w c:\windows\system32\ieaksie.dll
    - 2007-08-17 07:34:25 161,792 ----a-w c:\windows\system32\ieakui.dll
    + 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
    - 2007-08-20 10:04:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
    + 2008-08-26 07:24:28 383,488 ----a-w c:\windows\system32\ieapfltr.dll
    - 2007-08-20 10:04:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll
    + 2008-08-26 07:24:29 384,512 ----a-w c:\windows\system32\iedkcs32.dll
    - 2006-10-17 16:06:00 78,336 ----a-w c:\windows\system32\ieencode.dll
    + 2008-04-14 00:11:54 81,920 ----a-w c:\windows\system32\ieencode.dll
    - 2007-08-20 10:04:37 6,058,496 ----a-w c:\windows\system32\ieframe.dll
    + 2008-10-03 17:41:15 6,066,176 ----a-w c:\windows\system32\ieframe.dll
    - 2006-11-08 01:03:36 191,488 ----a-w c:\windows\system32\iepeers.dll
    + 2007-08-13 22:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll
    - 2007-08-20 10:04:38 44,544 ----a-w c:\windows\system32\iernonce.dll
    + 2008-08-26 07:24:29 44,544 ----a-w c:\windows\system32\iernonce.dll
    - 2007-08-20 10:04:38 267,776 ----a-w c:\windows\system32\iertutil.dll
    + 2008-08-26 07:24:29 267,776 ----a-w c:\windows\system32\iertutil.dll
    - 2006-11-07 07:26:42 55,296 ----a-w c:\windows\system32\iesetup.dll
    + 2007-08-13 22:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll
    - 2007-08-17 10:20:54 13,824 ----a-w c:\windows\system32\ieudinit.exe
    + 2008-08-25 08:38:00 13,824 ----a-w c:\windows\system32\ieudinit.exe
    - 2006-11-08 02:03:36 180,736 ----a-w c:\windows\system32\ieui.dll
    + 2007-08-13 22:54:10 180,736 ----a-w c:\windows\system32\ieui.dll
    - 2004-08-04 10:00:00 114,688 ----a-w c:\windows\system32\iexpress.exe
    + 2008-04-14 00:12:22 114,688 ----a-w c:\windows\system32\iexpress.exe
    - 2004-08-04 10:00:00 135,680 ----a-w c:\windows\system32\ifmon.dll
    + 2008-04-14 00:11:54 135,680 ----a-w c:\windows\system32\ifmon.dll
    - 2005-12-13 22:43:42 450,560 ----a-w c:\windows\system32\igfxcfg.exe
    + 2007-03-31 01:01:10 535,320 ----a-w c:\windows\system32\igfxcfg.exe
    + 2007-03-31 03:12:06 204,800 ----a-w c:\windows\system32\igfxCoIn_v4814.dll
    - 2005-12-13 22:40:12 139,264 ----a-w c:\windows\system32\igfxdev.dll
    + 2007-03-31 00:59:06 204,800 ----a-w c:\windows\system32\igfxdev.dll
    - 2005-12-13 22:41:14 86,016 ----a-w c:\windows\system32\igfxdo.dll
    + 2007-03-31 00:59:36 135,168 ----a-w c:\windows\system32\igfxdo.dll
    - 2005-12-13 22:44:52 40,960 ----a-w c:\windows\system32\igfxexps.dll
    + 2007-03-31 00:59:36 24,576 ----a-w c:\windows\system32\igfxexps.dll
    - 2005-12-13 22:44:52 94,208 ----a-w c:\windows\system32\igfxext.exe
    + 2007-03-31 00:59:34 166,680 ----a-w c:\windows\system32\igfxext.exe
    - 2005-12-13 22:45:00 118,784 ----a-w c:\windows\system32\igfxpers.exe
    + 2007-03-31 00:59:36 138,008 ----a-w c:\windows\system32\igfxpers.exe
    - 2005-12-13 22:44:02 147,456 ----a-w c:\windows\system32\igfxpph.dll
    + 2007-03-31 00:59:44 200,704 ----a-w c:\windows\system32\igfxpph.dll
    - 2005-12-13 22:40:18 135,168 ----a-w c:\windows\system32\igfxres.dll
    + 2007-03-31 00:58:56 172,032 ----a-w c:\windows\system32\igfxres.dll
    - 2005-12-13 22:44:08 1,503,232 ----a-w c:\windows\system32\igfxress.dll
    + 2007-03-31 00:58:56 3,293,184 ----a-w c:\windows\system32\igfxress.dll
    - 2005-12-13 22:41:02 57,344 ----a-w c:\windows\system32\igfxsrvc.dll
    + 2007-03-31 00:59:28 47,616 ----a-w c:\windows\system32\igfxsrvc.dll
    - 2005-12-13 22:41:00 159,744 ----a-w c:\windows\system32\igfxsrvc.exe
    + 2007-03-31 00:59:26 252,696 ----a-w c:\windows\system32\igfxsrvc.exe
    - 2005-12-13 22:44:18 98,304 ----a-w c:\windows\system32\igfxtray.exe
    + 2007-03-31 01:00:02 138,008 ----a-w c:\windows\system32\igfxtray.exe
    - 2005-12-13 22:44:46 114,688 ----a-w c:\windows\system32\igfxzoom.exe
    + 2007-03-31 00:59:20 170,776 ----a-w c:\windows\system32\igfxzoom.exe
    - 2005-12-13 22:53:32 524,288 ----a-w c:\windows\system32\igldev32.dll
    + 2007-03-31 01:33:06 450,560 ----a-w c:\windows\system32\igldev32.dll
    - 2005-12-13 22:51:42 2,310,144 ----a-w c:\windows\system32\iglicd32.dll
    + 2007-03-31 01:31:28 2,334,720 ----a-w c:\windows\system32\iglicd32.dll
    - 2004-08-04 10:00:00 8,192 ----a-w c:\windows\system32\igmpagnt.dll
    + 2008-04-14 00:11:54 8,192 ----a-w c:\windows\system32\igmpagnt.dll
    + 2007-03-31 02:33:36 1,612,992 ----a-w c:\windows\system32\igxpdv32.dll
    + 2007-03-31 02:34:44 2,556,928 ----a-w c:\windows\system32\igxpdx32.dll
    + 2007-03-31 02:33:50 149,504 ----a-w c:\windows\system32\igxpgd32.dll
    + 2007-03-31 02:33:56 57,344 ----a-w c:\windows\system32\igxprd32.dll
    + 2007-04-11 02:14:06 400,152 ----a-w c:\windows\system32\igxpun.exe
    + 2007-06-21 22:59:50 58,776 ----a-w c:\windows\system32\ijjiPlugin2.dll
    + 2007-09-27 16:08:06 692,224 ----a-w c:\windows\system32\ijjiSetup.exe
    - 2004-08-04 11:00:00 81,920 ----a-w c:\windows\system32\ils.dll
    + 2008-04-14 00:11:54 81,920 ----a-w c:\windows\system32\ils.dll
    - 2004-08-04 10:00:00 144,384 ----a-w c:\windows\system32\imagehlp.dll
    + 2008-04-14 00:11:54 144,384 ----a-w c:\windows\system32\imagehlp.dll
    - 2004-08-04 10:00:00 150,016 ----a-w c:\windows\system32\imapi.exe
    + 2008-04-14 00:12:22 150,528 ----a-w c:\windows\system32\imapi.exe
    - 2004-08-04 10:00:00 36,921 ----a-w c:\windows\system32\imeshare.dll
    + 2008-04-14 00:11:54 36,921 ----a-w c:\windows\system32\imeshare.dll
    - 2006-10-17 15:57:58 36,352 ----a-w c:\windows\system32\imgutil.dll
    + 2007-08-13 22:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll
    - 2004-08-04 10:00:00 110,080 ----a-w c:\windows\system32\imm32.dll
    + 2008-04-14 00:11:54 110,080 ----a-w c:\windows\system32\imm32.dll
    + 1999-01-27 17:39:06 65,024 ----a-w c:\windows\system32\indounin.dll
    - 2004-08-04 11:00:00 274,432 ----a-w c:\windows\system32\inetcfg.dll
    + 2008-04-14 00:11:54 274,432 ----a-w c:\windows\system32\inetcfg.dll
    - 2007-08-21 06:15:44 683,520 ----a-w c:\windows\system32\inetcomm.dll
    + 2008-04-11 19:04:26 691,712 ----a-w c:\windows\system32\inetcomm.dll
    - 2004-08-04 10:00:00 33,280 ----a-w c:\windows\system32\inetmib1.dll
    + 2008-04-14 00:11:55 32,768 ----a-w c:\windows\system32\inetmib1.dll
    - 2004-08-04 10:00:00 75,264 ----a-w c:\windows\system32\inetpp.dll
    + 2008-04-14 00:11:55 75,264 ----a-w c:\windows\system32\inetpp.dll
    - 2004-08-04 10:00:00 15,872 ----a-w c:\windows\system32\inetppui.dll
    + 2008-04-14 00:11:55 15,872 ----a-w c:\windows\system32\inetppui.dll
    - 2004-08-04 11:00:00 48,128 ----a-w c:\windows\system32\inetres.dll
    + 2008-04-13 16:22:12 48,128 ----a-w c:\windows\system32\inetres.dll
    - 2006-10-30 07:33:58 83,968 ----a-w c:\windows\system32\infocardapi.dll
    + 2007-10-11 14:55:10 88,576 ----a-w c:\windows\system32\infocardapi.dll
    - 2004-08-04 10:00:00 147,456 ----a-w c:\windows\system32\initpki.dll
    + 2008-04-14 00:11:55 147,456 ----a-w c:\windows\system32\initpki.dll
    - 2004-08-04 10:00:00 123,392 ----a-w c:\windows\system32\input.dll
    + 2008-04-14 00:11:55 123,392 ----a-w c:\windows\system32\input.dll
    - 2006-11-07 07:26:24 92,672 ----a-w c:\windows\system32\inseng.dll
    + 2007-08-13 22:39:02 92,672 ----a-w c:\windows\system32\inseng.dll
    + 2004-10-08 16:46:28 53,248 ----a-r c:\windows\system32\InstMed.exe
    - 2004-08-04 10:00:00 55,808 ----a-w c:\windows\system32\ipconfig.exe
    + 2008-04-14 00:12:22 55,808 ----a-w c:\windows\system32\ipconfig.exe
    - 2006-05-19 12:59:41 94,720 ----a-w c:\windows\system32\iphlpapi.dll
    + 2008-04-14 00:11:55 94,720 ----a-w c:\windows\system32\iphlpapi.dll
    - 2004-08-04 10:00:00 154,112 ----a-w c:\windows\system32\ipmontr.dll
    + 2008-04-14 00:11:55 161,280 ----a-w c:\windows\system32\ipmontr.dll
    - 2004-08-04 10:00:00 331,264 ----a-w c:\windows\system32\ipnathlp.dll
    + 2008-04-14 00:11:55 331,264 ----a-w c:\windows\system32\ipnathlp.dll
    - 2004-08-04 10:00:00 330,752 ----a-w c:\windows\system32\ippromon.dll
    + 2008-04-14 00:11:55 330,752 ----a-w c:\windows\system32\ippromon.dll
    - 2004-08-04 10:00:00 169,984 ----a-w c:\windows\system32\iprtrmgr.dll
    + 2008-04-14 00:11:55 177,152 ----a-w c:\windows\system32\iprtrmgr.dll
    - 2004-08-04 10:00:00 349,696 ----a-w c:\windows\system32\ipsecsnp.dll
    + 2008-04-14 00:11:55 349,696 ----a-w c:\windows\system32\ipsecsnp.dll
    - 2004-08-04 10:00:00 182,784 ----a-w c:\windows\system32\ipsecsvc.dll
    + 2008-04-14 00:11:55 183,808 ----a-w c:\windows\system32\ipsecsvc.dll
    - 2004-08-04 10:00:00 384,000 ----a-w c:\windows\system32\ipsmsnap.dll
    + 2008-04-14 00:11:55 384,000 ----a-w c:\windows\system32\ipsmsnap.dll
    - 2004-08-04 10:00:00 53,248 ----a-w c:\windows\system32\ipv6.exe
    + 2008-04-14 00:12:23 53,248 ----a-w c:\windows\system32\ipv6.exe
    - 2004-08-04 10:00:00 59,904 ----a-w c:\windows\system32\ipv6mon.dll
    + 2008-04-14 00:11:55 59,904 ----a-w c:\windows\system32\ipv6mon.dll
    - 2004-08-04 10:00:00 23,552 ----a-w c:\windows\system32\ipxroute.exe
    + 2008-04-14 00:12:23 23,552 ----a-w c:\windows\system32\ipxroute.exe
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\ipxwan.dll
    + 2008-04-14 00:11:55 22,016 ----a-w c:\windows\system32\ipxwan.dll
    - 2004-08-04 10:00:00 120,320 ----a-w c:\windows\system32\ir41_qc.dll
    + 2008-04-14 00:11:55 120,320 ----a-w c:\windows\system32\ir41_qc.dll
    - 2004-08-04 10:00:00 338,432 ----a-w c:\windows\system32\ir41_qcx.dll
    + 2008-04-14 00:11:55 338,432 ----a-w c:\windows\system32\ir41_qcx.dll
    - 2004-08-04 10:00:00 755,200 ----a-w c:\windows\system32\ir50_32.dll
    + 2008-04-14 00:11:55 755,200 ----a-w c:\windows\system32\ir50_32.dll
    - 2004-08-04 10:00:00 200,192 ----a-w c:\windows\system32\ir50_qc.dll
    + 2008-04-14 00:11:55 200,192 ----a-w c:\windows\system32\ir50_qc.dll
    - 2004-08-04 10:00:00 183,808 ----a-w c:\windows\system32\ir50_qcx.dll
    + 2008-04-14 00:11:55 183,808 ----a-w c:\windows\system32\ir50_qcx.dll
    - 2004-08-04 11:00:00 81,920 ----a-w c:\windows\system32\isign32.dll
    + 2008-04-14 00:11:55 81,920 ----a-w c:\windows\system32\isign32.dll
    - 2004-08-04 11:00:00 32,768 ----a-w c:\windows\system32\isrdbg32.dll
    + 2008-04-14 00:11:55 32,768 ----a-w c:\windows\system32\isrdbg32.dll
    - 2005-05-27 02:04:27 155,136 ----a-w c:\windows\system32\itircl.dll
    + 2008-04-14 00:11:55 155,136 ----a-w c:\windows\system32\itircl.dll
    - 2005-05-27 02:04:27 137,216 ----a-w c:\windows\system32\itss.dll
    + 2008-04-14 00:11:55 138,240 ----a-w c:\windows\system32\itss.dll
    - 2004-08-04 10:00:00 54,272 ----a-w c:\windows\system32\ixsso.dll
    + 2008-04-14 00:11:55 54,272 ----a-w c:\windows\system32\ixsso.dll
    - 2004-08-04 10:00:00 47,616 ----a-w c:\windows\system32\iyuv_32.dll
    + 2008-04-14 00:11:55 47,616 ----a-w c:\windows\system32\iyuv_32.dll
    + 1997-06-13 11:56:08 56,832 ----a-w c:\windows\system32\Iyvu9_32.dll
    - 2006-06-01 18:47:07 163,840 ----a-w c:\windows\system32\jgdw400.dll
    + 2008-04-14 00:11:55 163,840 ----a-w c:\windows\system32\jgdw400.dll
    - 2006-06-01 18:47:07 27,648 ----a-w c:\windows\system32\jgpl400.dll
    + 2008-04-14 00:11:55 27,648 ----a-w c:\windows\system32\jgpl400.dll
    - 2006-10-17 16:00:00 491,520 ----a-w c:\windows\system32\jscript.dll
    + 2008-05-09 10:53:39 512,000 ----a-w c:\windows\system32\jscript.dll
    - 2007-08-20 10:04:39 27,648 ----a-w c:\windows\system32\jsproxy.dll
    + 2008-08-26 07:24:30 27,648 ----a-w c:\windows\system32\jsproxy.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdbhc.dll
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\kbdfi1.dll
    + 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdfi1.dll
    - 2004-08-04 10:00:00 6,144 ----a-w c:\windows\system32\kbdinbe1.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdinbe1.dll
    - 2004-08-04 10:00:00 6,656 ----a-w c:\windows\system32\kbdinben.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdinben.dll
    - 2004-08-04 10:00:00 6,656 ----a-w c:\windows\system32\kbdinmal.dll
    + 2008-04-14 00:09:55 6,656 ----a-w c:\windows\system32\kbdinmal.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdiultn.dll
    - 2004-08-04 10:00:00 5,632 ----a-w c:\windows\system32\kbdmaori.dll
    + 2008-04-14 00:09:55 5,632 ----a-w c:\windows\system32\kbdmaori.dll
    - 2004-08-04 10:00:00 6,144 ----a-w c:\windows\system32\kbdmlt47.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdmlt47.dll
    - 2004-08-04 10:00:00 6,144 ----a-w c:\windows\system32\kbdmlt48.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdmlt48.dll
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\kbdnec.dll
    + 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdnec.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdnepr.dll
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\kbdno1.dll
    + 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdno1.dll
    + 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdpash.dll
    - 2004-08-04 10:00:00 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll
    + 2008-04-14 00:09:55 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll
    - 2004-08-04 10:00:00 7,680 ----a-w c:\windows\system32\kbdsmsno.dll
    + 2008-04-14 00:09:55 7,680 ----a-w c:\windows\system32\kbdsmsno.dll
    - 2004-08-04 10:00:00 7,168 ----a-w c:\windows\system32\kbdukx.dll
    + 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdukx.dll
    - 2004-08-04 10:00:00 7,424 ----a-w c:\windows\system32\kd1394.dll
    + 2008-04-13 18:31:35 7,424 ----a-w c:\windows\system32\kd1394.dll
    - 2005-06-15 17:49:30 295,936 ----a-w c:\windows\system32\kerberos.dll
    + 2008-04-14 00:11:56 299,520 ----a-w c:\windows\system32\kerberos.dll
    - 2007-04-16 15:52:53 984,576 ----a-w c:\windows\system32\kernel32.dll
    + 2008-04-14 00:11:56 989,696 ----a-w c:\windows\system32\kernel32.dll
    + 2004-08-04 10:00:00 2,000 ----a-w c:\windows\system32\keyboard.drv
    - 2004-08-04 10:00:00 150,528 ----a-w c:\windows\system32\keymgr.dll
    + 2008-04-14 00:11:56 150,528 ----a-w c:\windows\system32\keymgr.dll
    + 2008-12-12 05:31:10 3,870 --sha-w c:\windows\system32\KGyGaAvL.sys
    + 2008-04-14 00:11:56 61,440 ----a-w c:\windows\system32\kmsvc.dll
    - 2004-08-04 06:56:44 4,096 ----a-w c:\windows\system32\ksuser.dll
    + 2008-04-14 00:11:56 4,096 ----a-w c:\windows\system32\ksuser.dll

  3. #23
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    + 2008-04-14 00:11:56 37,376 ----a-w c:\windows\system32\l2gpstore.dll
    + 2007-04-11 02:14:14 50,688 ----a-w c:\windows\system32\Lang\HDMI\ENU\HDMIENU.dll
    + 2004-08-04 10:00:00 221,600 ----a-w c:\windows\system32\lanman.drv
    + 2005-01-18 21:35:02 462,848 ----a-w c:\windows\system32\LCamCpl.dll
    - 2007-04-24 15:32:06 1,485,696 ----a-w c:\windows\system32\LegitCheckControl.DLL
    + 2008-03-20 23:06:36 1,480,232 ----a-w c:\windows\system32\LegitCheckControl.dll
    + 2005-01-18 18:23:16 30,720 ----a-w c:\windows\system32\lfbmp12n.dll
    + 2005-01-18 18:23:18 328,704 ----a-w c:\windows\system32\LFCMP12n.DLL
    + 2005-01-18 18:23:18 78,336 ----a-w c:\windows\system32\lffax12n.dll
    + 2005-01-18 18:23:18 141,312 ----a-w c:\windows\system32\lftif12n.dll
    + 2006-04-13 15:30:06 1,073,152 ----a-w c:\windows\system32\libmysql_c.dll
    - 2004-08-04 10:00:00 423,936 ----a-w c:\windows\system32\licdll.dll
    + 2008-04-14 09:41:58 423,936 ----a-w c:\windows\system32\licdll.dll
    - 2006-10-17 16:05:10 40,960 ----a-w c:\windows\system32\licmgr10.dll
    + 2007-08-13 22:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll
    - 2004-08-04 11:00:00 58,880 ----a-w c:\windows\system32\licwmi.dll
    + 2008-04-14 00:11:56 58,880 ----a-w c:\windows\system32\licwmi.dll
    - 2005-09-01 01:41:53 19,968 ----a-w c:\windows\system32\linkinfo.dll
    + 2008-04-14 00:11:56 19,968 ----a-w c:\windows\system32\linkinfo.dll
    - 2004-08-04 10:00:00 13,824 ----a-w c:\windows\system32\lmhsvc.dll
    + 2008-04-14 00:11:56 13,824 ----a-w c:\windows\system32\lmhsvc.dll
    - 2004-08-04 10:00:00 399,872 ----a-w c:\windows\system32\lmrt.dll
    + 2008-04-14 00:11:56 399,872 ----a-w c:\windows\system32\lmrt.dll
    - 2004-08-04 10:00:00 97,280 ----a-w c:\windows\system32\loadperf.dll
    + 2008-04-14 00:11:56 97,280 ----a-w c:\windows\system32\loadperf.dll
    - 2004-08-04 10:00:00 221,696 ----a-w c:\windows\system32\localsec.dll
    + 2008-04-14 00:11:56 221,696 ----a-w c:\windows\system32\localsec.dll
    - 2004-08-04 10:00:00 341,504 ----a-w c:\windows\system32\localspl.dll
    + 2008-04-14 00:11:56 343,040 ----a-w c:\windows\system32\localspl.dll
    - 2004-08-04 10:00:00 11,776 ----a-w c:\windows\system32\localui.dll
    + 2008-04-14 00:11:56 11,776 ----a-w c:\windows\system32\localui.dll
    - 2004-08-04 10:00:00 75,264 ----a-w c:\windows\system32\locator.exe
    + 2008-04-14 00:12:24 75,264 ----a-w c:\windows\system32\locator.exe
    - 2004-08-04 10:00:00 59,392 ----a-w c:\windows\system32\logman.exe
    + 2008-04-14 00:12:24 59,392 ----a-w c:\windows\system32\logman.exe
    - 2004-08-04 10:00:00 220,672 ----a-w c:\windows\system32\logon.scr
    + 2008-04-14 00:12:43 220,672 ----a-w c:\windows\system32\logon.scr
    - 2004-08-04 10:00:00 514,560 ----a-w c:\windows\system32\logonui.exe
    + 2008-04-14 00:12:24 514,560 ----a-w c:\windows\system32\logonui.exe
    - 2004-08-04 10:00:00 22,016 ----a-w c:\windows\system32\lpk.dll
    + 2008-04-14 00:11:56 22,016 ----a-w c:\windows\system32\lpk.dll
    - 2004-08-04 10:00:00 10,240 ----a-w c:\windows\system32\lprhelp.dll
    + 2008-04-14 00:11:56 10,240 ----a-w c:\windows\system32\lprhelp.dll
    + 2005-01-18 21:02:12 90,112 ----a-w c:\windows\system32\LQCUI2.dll
    - 2006-08-17 12:28:27 721,920 ----a-w c:\windows\system32\lsasrv.dll
    + 2008-04-14 00:11:56 728,064 ----a-w c:\windows\system32\lsasrv.dll
    - 2004-08-04 10:00:00 13,312 ----a-w c:\windows\system32\lsass.exe
    + 2008-04-14 00:12:24 13,312 ----a-w c:\windows\system32\lsass.exe
    + 2005-01-18 18:23:22 259,072 ----a-w c:\windows\system32\LTDIS12n.dll
    + 2005-01-18 18:23:22 207,872 ----a-w c:\windows\system32\ltefx12n.dll
    + 2005-01-18 18:23:22 131,072 ----a-w c:\windows\system32\ltfil12n.DLL
    + 2005-01-18 18:23:22 164,864 ----a-w c:\windows\system32\ltimg12n.dll
    + 2005-01-18 18:23:24 406,016 ----a-w c:\windows\system32\ltkrn12n.dll
    + 2005-01-18 18:23:28 856,064 ----a-w c:\windows\system32\Ltwvc12n.dll
    + 2005-01-31 10:08:02 204,800 ----a-w c:\windows\system32\lvcodec2.dll
    + 2005-01-31 10:00:10 106,496 ----a-w c:\windows\system32\lvcoinst.dll
    + 2004-10-08 15:55:36 77,824 ----a-w c:\windows\system32\LVCOMCX.dll
    + 2004-10-08 15:52:32 221,184 ----a-w c:\windows\system32\LVCOMSX.EXE
    + 2005-01-18 18:23:30 215,552 ----a-w c:\windows\system32\Lvkrn12n.dll
    + 2004-10-08 15:52:58 258,048 ----a-w c:\windows\system32\LVMAENUM.dll
    + 2005-01-31 10:10:58 204,800 ----a-w c:\windows\system32\LVUI2.dll
    + 2005-01-31 10:18:04 372,736 ----a-w c:\windows\system32\LVUI2RC.dll
    + 2004-08-04 10:00:00 2,560 ----a-w c:\windows\system32\lz32.dll
    + 2008-03-15 03:31:26 57,344 ----a-w c:\windows\system32\Macromed\Common\SwSupport.dll
    + 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
    - 2006-11-09 20:20:00 2,111,096 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
    - 2006-11-09 20:20:00 190,072 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
    + 2008-10-05 03:24:04 235,936 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
    - 2007-10-06 23:50:17 48,749 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
    + 2008-11-28 01:59:49 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
    + 2008-11-28 03:33:19 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
    + 2008-03-15 03:29:22 581,632 -c--a-w c:\windows\system32\Macromed\Shockwave 10\Control.dll
    + 2008-03-15 03:12:30 1,490,944 -c--a-w c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
    + 2008-03-15 03:29:58 24,576 -c--a-w c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
    + 2008-03-15 03:10:06 606,208 -c--a-w c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
    + 2008-03-15 03:28:48 339,968 -c--a-w c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
    + 2008-03-15 03:28:56 475,136 -c--a-w c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
    + 2008-03-15 03:21:52 180,224 -c--a-w c:\windows\system32\Macromed\Shockwave 10\Proj.dll
    + 2008-03-15 03:31:28 77,824 -c--a-w c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
    + 2008-03-15 15:38:08 86,016 -c--a-w c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
    + 2008-03-15 03:31:28 98,304 -c--a-w c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
    - 2006-10-04 08:48:36 72,704 ----a-w c:\windows\system32\magnify.exe
    + 2008-04-14 00:12:24 72,704 ----a-w c:\windows\system32\magnify.exe
    - 2004-08-04 10:00:00 85,504 ----a-w c:\windows\system32\makecab.exe
    + 2008-04-14 00:12:25 57,344 ----a-w c:\windows\system32\makecab.exe
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\mcastmib.dll
    + 2008-04-14 00:11:56 14,336 ----a-w c:\windows\system32\mcastmib.dll
    + 2004-08-04 10:00:00 73,376 ----a-w c:\windows\system32\mciavi.drv
    - 2004-08-04 10:00:00 84,480 ----a-w c:\windows\system32\mciavi32.dll
    + 2008-04-14 00:11:56 84,480 ----a-w c:\windows\system32\mciavi32.dll
    - 2004-08-04 10:00:00 35,328 ----a-w c:\windows\system32\mciqtz32.dll
    + 2008-04-14 00:11:56 35,328 ----a-w c:\windows\system32\mciqtz32.dll
    - 2004-08-04 10:00:00 23,040 ----a-w c:\windows\system32\mciseq.dll
    + 2008-04-14 00:11:56 23,040 ----a-w c:\windows\system32\mciseq.dll
    + 2004-08-04 10:00:00 25,264 ----a-w c:\windows\system32\mciseq.drv
    - 2004-08-04 10:00:00 23,552 ----a-w c:\windows\system32\mciwave.dll
    + 2008-04-14 00:11:56 23,552 ----a-w c:\windows\system32\mciwave.dll
    + 2004-08-04 10:00:00 28,160 ----a-w c:\windows\system32\mciwave.drv
    - 2004-08-04 10:00:00 118,272 ----a-w c:\windows\system32\mdminst.dll
    + 2008-04-14 00:11:56 118,272 ----a-w c:\windows\system32\mdminst.dll
    - 2004-03-17 02:00:32 86,016 ----a-w c:\windows\system32\mdmxsdk.dll
    + 2005-10-05 04:56:44 86,016 ----a-w c:\windows\system32\mdmxsdk.dll
    - 2007-03-08 15:36:28 40,960 ----a-w c:\windows\system32\mf3216.dll
    + 2008-04-14 00:11:56 40,960 ----a-w c:\windows\system32\mf3216.dll
    - 2006-11-01 19:17:45 927,504 ----a-w c:\windows\system32\mfc40u.dll
    + 2008-04-14 00:11:56 927,504 ----a-w c:\windows\system32\mfc40u.dll
    - 2004-08-04 10:00:00 1,028,096 ----a-w c:\windows\system32\mfc42.dll
    + 2004-08-04 07:56:42 1,028,096 ----a-w c:\windows\system32\mfc42.dll
    - 2006-08-22 21:32:36 1,060,864 ----a-w c:\windows\system32\MFC71.dll
    + 2003-03-19 01:20:00 1,060,864 ----a-w c:\windows\system32\MFC71.dll
    + 2003-03-19 00:44:36 40,960 ----a-w c:\windows\system32\MFC71CHS.DLL
    + 2003-03-19 00:44:36 45,056 ----a-w c:\windows\system32\MFC71CHT.DLL
    + 2003-03-19 00:44:34 65,536 ----a-w c:\windows\system32\MFC71DEU.DLL
    + 2003-03-19 00:44:38 57,344 ----a-w c:\windows\system32\MFC71ENU.DLL
    + 2003-03-19 00:44:36 61,440 ----a-w c:\windows\system32\MFC71ESP.DLL
    + 2003-03-19 00:44:36 61,440 ----a-w c:\windows\system32\MFC71ITA.DLL
    + 2003-03-19 00:44:34 49,152 ----a-w c:\windows\system32\MFC71JPN.DLL
    + 2003-03-19 00:44:38 49,152 ----a-w c:\windows\system32\MFC71KOR.DLL
    - 2006-08-22 21:32:36 1,047,552 ----a-w c:\windows\system32\MFC71u.dll
    + 2003-03-19 01:12:12 1,047,552 ----a-w c:\windows\system32\MFC71u.dll
    - 2004-08-04 10:00:00 22,528 ----a-w c:\windows\system32\mfcsubs.dll
    + 2008-04-14 00:11:56 22,528 ----a-w c:\windows\system32\mfcsubs.dll
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\mgmtapi.dll
    + 2008-04-14 00:11:56 14,848 ----a-w c:\windows\system32\mgmtapi.dll
    + 2008-04-14 00:11:57 184,320 ----a-w c:\windows\system32\microsoft.managementconsole.dll
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\midimap.dll
    + 2008-04-14 00:11:57 18,944 ----a-w c:\windows\system32\midimap.dll
    - 2004-08-04 10:00:00 60,928 ----a-w c:\windows\system32\miglibnt.dll
    + 2008-04-14 00:11:57 60,928 ----a-w c:\windows\system32\miglibnt.dll
    - 2006-10-21 01:30:06 1,980,704 ----a-w c:\windows\system32\milcore.dll
    + 2007-10-09 18:03:14 1,986,072 ----a-w c:\windows\system32\milcore.dll
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\mimefilt.dll
    + 2008-04-14 00:11:57 29,696 ----a-w c:\windows\system32\mimefilt.dll
    - 2004-08-04 10:00:00 586,240 ----a-w c:\windows\system32\mlang.dll
    + 2008-04-14 00:11:57 586,240 ----a-w c:\windows\system32\mlang.dll
    + 2008-09-08 00:27:09 57,288 ---ha-w c:\windows\system32\mlfcache.dat
    - 2004-08-04 10:00:00 815,104 ----a-w c:\windows\system32\mmc.exe
    + 2008-04-14 00:12:25 1,414,656 ----a-w c:\windows\system32\mmc.exe
    - 2004-08-04 10:00:00 70,656 ----a-w c:\windows\system32\mmcbase.dll
    + 2008-04-14 00:11:57 163,328 ----a-w c:\windows\system32\mmcbase.dll
    + 2008-04-14 00:11:57 397,312 ----a-w c:\windows\system32\mmcex.dll
    + 2008-04-14 00:11:57 106,496 ----a-w c:\windows\system32\mmcfxcommon.dll
    - 2004-08-04 10:00:00 1,192,960 ----a-w c:\windows\system32\mmcndmgr.dll
    + 2008-04-14 00:11:57 1,872,896 ----a-w c:\windows\system32\mmcndmgr.dll
    + 2008-04-14 00:12:25 33,792 ----a-w c:\windows\system32\mmcperf.exe
    - 2004-08-04 10:00:00 50,688 ----a-w c:\windows\system32\mmcshext.dll
    + 2008-04-14 00:11:57 61,440 ----a-w c:\windows\system32\mmcshext.dll
    - 2004-08-04 11:00:00 17,408 ----a-w c:\windows\system32\mmfutil.dll
    + 2008-04-14 00:11:57 17,408 ----a-w c:\windows\system32\mmfutil.dll
    - 2004-08-04 11:00:00 34,560 ----a-w c:\windows\system32\mnmdd.dll
    + 2008-04-14 00:11:57 34,560 ----a-w c:\windows\system32\mnmdd.dll
    - 2004-08-04 11:00:00 32,768 ----a-w c:\windows\system32\mnmsrvc.exe
    + 2008-04-14 00:12:25 32,768 ----a-w c:\windows\system32\mnmsrvc.exe
    - 2004-08-04 10:00:00 207,360 ----a-w c:\windows\system32\mobsync.dll
    + 2008-04-14 00:11:57 207,360 ----a-w c:\windows\system32\mobsync.dll
    - 2004-08-04 10:00:00 143,360 ----a-w c:\windows\system32\mobsync.exe
    + 2008-04-14 00:12:26 143,360 ----a-w c:\windows\system32\mobsync.exe
    - 2004-08-04 10:00:00 153,600 ----a-w c:\windows\system32\modemui.dll
    + 2008-04-14 00:11:57 153,600 ----a-w c:\windows\system32\modemui.dll
    - 2004-08-04 10:00:00 15,872 ----a-w c:\windows\system32\more.com
    + 2008-04-14 00:12:42 16,896 ----a-w c:\windows\system32\more.com
    - 2004-08-04 10:00:00 216,064 ----a-w c:\windows\system32\moricons.dll
    + 2008-04-13 16:45:30 216,064 ----a-w c:\windows\system32\moricons.dll
    + 2004-08-04 10:00:00 2,032 ----a-w c:\windows\system32\mouse.drv
    - 2004-08-04 11:00:00 123,392 ----a-w c:\windows\system32\mplay32.exe
    + 2008-04-14 00:12:27 123,392 ----a-w c:\windows\system32\mplay32.exe
    - 2004-08-04 10:00:00 59,904 ----a-w c:\windows\system32\mpr.dll
    + 2008-04-14 00:11:57 59,904 ----a-w c:\windows\system32\mpr.dll
    - 2004-08-04 10:00:00 87,040 ----a-w c:\windows\system32\mprapi.dll
    + 2008-04-14 00:11:57 87,040 ----a-w c:\windows\system32\mprapi.dll
    - 2004-08-04 10:00:00 49,152 ----a-w c:\windows\system32\mprdim.dll
    + 2008-04-14 00:11:57 53,248 ----a-w c:\windows\system32\mprdim.dll
    - 2007-09-28 05:19:39 18,089,592 ----a-w c:\windows\system32\MRT.exe
    + 2008-11-04 00:10:25 17,318,336 ----a-w c:\windows\system32\MRT.exe
    - 2004-08-04 10:00:00 71,680 ----a-w c:\windows\system32\msacm32.dll
    + 2008-04-14 00:11:58 71,680 ----a-w c:\windows\system32\msacm32.dll
    + 2004-08-04 10:00:00 20,480 ----a-w c:\windows\system32\msacm32.drv
    - 2004-08-04 10:00:00 3,584 ----a-w c:\windows\system32\msafd.dll
    + 2008-04-14 00:10:06 3,584 ----a-w c:\windows\system32\msafd.dll
    - 2004-08-04 10:00:00 86,016 ----a-w c:\windows\system32\msapsspc.dll
    + 2008-04-14 00:11:58 86,016 ----a-w c:\windows\system32\msapsspc.dll
    - 2004-08-04 10:00:00 57,344 ----a-w c:\windows\system32\msasn1.dll
    + 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\msasn1.dll
    - 2005-06-29 01:46:00 74,240 ----a-w c:\windows\system32\mscms.dll
    + 2008-06-24 16:43:16 74,240 ----a-w c:\windows\system32\mscms.dll
    - 2004-08-04 11:00:00 69,632 ----a-w c:\windows\system32\msconf.dll
    + 2008-04-14 00:11:58 69,632 ----a-w c:\windows\system32\msconf.dll
    - 2007-04-13 07:21:14 271,360 ----a-w c:\windows\system32\mscoree.dll
    + 2007-10-24 06:47:38 282,112 ----a-w c:\windows\system32\mscoree.dll
    - 2005-09-23 12:28:52 150,016 ----a-w c:\windows\system32\mscorier.dll
    + 2007-10-24 06:47:38 158,720 ----a-w c:\windows\system32\mscorier.dll
    - 2005-09-23 12:28:52 74,240 ----a-w c:\windows\system32\mscories.dll
    + 2007-10-24 06:47:38 84,480 ----a-w c:\windows\system32\mscories.dll
    - 2004-08-04 10:00:00 12,288 ----a-w c:\windows\system32\mscpx32r.dLL
    + 2008-04-13 17:26:07 12,288 ----a-w c:\windows\system32\mscpx32r.dll
    - 2004-08-04 10:00:00 36,864 ----a-w c:\windows\system32\mscpxl32.dLL
    + 2008-04-14 00:11:58 36,864 ----a-w c:\windows\system32\mscpxl32.dll
    - 2004-08-04 10:00:00 294,400 ----a-w c:\windows\system32\MSCTF.dll
    + 2008-04-14 00:11:58 297,984 ----a-w c:\windows\system32\msctf.dll
    - 2004-08-04 10:00:00 69,120 ----a-w c:\windows\system32\MSCTFP.dll
    + 2008-04-14 00:11:58 68,608 ----a-w c:\windows\system32\msctfp.dll
    - 2004-08-04 10:00:00 118,784 ----a-w c:\windows\system32\msdadiag.dll
    + 2008-04-14 00:11:58 118,784 ----a-w c:\windows\system32\msdadiag.dll
    - 2004-08-04 10:00:00 151,552 ----a-w c:\windows\system32\msdart.dll
    + 2008-04-14 00:11:59 151,552 ----a-w c:\windows\system32\msdart.dll
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\msdmo.dll
    + 2008-04-14 00:11:59 14,336 ----a-w c:\windows\system32\msdmo.dll
    - 2004-08-04 11:00:00 6,144 ----a-w c:\windows\system32\msdtc.exe
    + 2008-04-14 00:12:27 6,144 ----a-w c:\windows\system32\msdtc.exe
    - 2004-08-04 11:00:00 58,880 ----a-w c:\windows\system32\msdtclog.dll
    + 2008-04-14 00:11:59 58,880 ----a-w c:\windows\system32\msdtclog.dll
    - 2006-03-01 19:42:42 426,496 ----a-w c:\windows\system32\msdtcprx.dll
    + 2008-04-14 00:11:59 427,008 ----a-w c:\windows\system32\msdtcprx.dll
    - 2006-03-01 19:42:42 956,416 ----a-w c:\windows\system32\msdtctm.dll
    + 2008-04-14 00:11:59 956,928 ----a-w c:\windows\system32\msdtctm.dll
    - 2006-03-01 19:42:42 161,280 ----a-w c:\windows\system32\msdtcuiu.dll
    + 2008-04-14 00:11:59 161,792 ----a-w c:\windows\system32\msdtcuiu.dll
    - 2004-08-04 10:00:00 4,126 ----a-w c:\windows\system32\msdxmlc.dll
    + 2008-04-14 00:10:08 4,126 ----a-w c:\windows\system32\msdxmlc.dll
    - 2004-08-04 10:00:00 512,029 ----a-w c:\windows\system32\msexch40.dll
    + 2008-03-25 04:50:28 518,944 ----a-w c:\windows\system32\msexch40.dll
    - 2004-08-04 10:00:00 319,517 ----a-w c:\windows\system32\msexcl40.dll
    + 2008-03-25 04:50:30 326,432 ----a-w c:\windows\system32\msexcl40.dll
    - 2007-08-20 10:04:39 459,264 ----a-w c:\windows\system32\msfeeds.dll
    + 2008-08-26 07:24:30 459,264 ----a-w c:\windows\system32\msfeeds.dll
    - 2007-08-20 10:04:39 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
    + 2008-08-26 07:24:30 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
    - 2006-10-17 16:58:32 12,288 ----a-w c:\windows\system32\msfeedssync.exe
    + 2007-08-13 22:36:40 12,288 ----a-w c:\windows\system32\msfeedssync.exe
    - 2006-11-27 14:54:06 539,136 ----a-w c:\windows\system32\msftedit.dll
    + 2008-04-14 00:11:59 539,136 ----a-w c:\windows\system32\msftedit.dll
    - 2004-08-04 10:00:00 994,304 ----a-w c:\windows\system32\msgina.dll
    + 2008-04-14 00:11:59 997,376 ----a-w c:\windows\system32\msgina.dll
    - 2004-08-04 10:00:00 33,792 ----a-w c:\windows\system32\msgsvc.dll
    + 2008-04-14 00:11:59 33,792 ----a-w c:\windows\system32\msgsvc.dll
    + 2008-04-14 00:12:45 188,416 ----a-w c:\windows\system32\msh261.drv
    + 2008-04-14 00:12:45 294,912 ----a-w c:\windows\system32\msh263.drv
    - 2006-10-17 15:56:10 45,568 ----a-w c:\windows\system32\mshta.exe
    + 2007-08-13 22:32:30 45,568 ----a-w c:\windows\system32\mshta.exe
    - 2007-08-20 10:04:41 3,584,512 ----a-w c:\windows\system32\mshtml.dll
    + 2008-08-27 08:24:32 3,593,216 ----a-w c:\windows\system32\mshtml.dll
    - 2007-08-20 10:04:41 477,696 ----a-w c:\windows\system32\mshtmled.dll
    + 2008-08-26 07:24:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
    - 2006-10-17 15:28:56 48,128 ----a-w c:\windows\system32\mshtmler.dll
    + 2007-08-13 22:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll
    - 2007-04-18 16:12:23 2,854,400 ----a-w c:\windows\system32\msi.dll
    + 2008-04-14 00:11:59 2,843,136 ----a-w c:\windows\system32\msi.dll
    - 2004-08-04 10:00:00 51,712 ----a-w c:\windows\system32\msident.dll
    + 2008-04-14 00:11:59 51,712 ----a-w c:\windows\system32\msident.dll
    - 2004-08-04 10:00:00 6,656 ----a-w c:\windows\system32\msidle.dll
    + 2008-04-14 00:11:59 6,656 ----a-w c:\windows\system32\msidle.dll
    - 2004-08-04 10:00:00 248,832 ----a-w c:\windows\system32\msieftp.dll
    + 2008-04-14 00:11:59 248,832 ----a-w c:\windows\system32\msieftp.dll
    - 2005-05-04 18:45:36 78,848 ----a-w c:\windows\system32\msiexec.exe
    + 2008-04-14 00:12:28 78,848 ----a-w c:\windows\system32\msiexec.exe
    - 2005-05-04 18:45:36 271,360 ----a-w c:\windows\system32\msihnd.dll
    + 2008-04-14 00:11:59 271,360 ----a-w c:\windows\system32\msihnd.dll
    - 2004-08-04 10:00:00 4,608 ----a-w c:\windows\system32\msimg32.dll
    + 2008-04-14 00:11:59 4,608 ----a-w c:\windows\system32\msimg32.dll
    - 2005-05-04 18:45:36 884,736 ----a-w c:\windows\system32\msimsg.dll
    + 2008-04-13 15:39:43 884,736 ----a-w c:\windows\system32\msimsg.dll
    - 2004-08-04 10:00:00 159,232 ----a-w c:\windows\system32\MSIMTF.dll
    + 2008-04-14 00:11:59 159,232 ----a-w c:\windows\system32\msimtf.dll
    - 2004-08-04 10:00:00 40,960 ----a-w c:\windows\system32\msiregmv.exe
    + 2008-04-14 00:12:28 40,960 ----a-w c:\windows\system32\msiregmv.exe
    - 2005-05-04 18:45:36 15,360 ----a-w c:\windows\system32\msisip.dll
    + 2008-04-14 00:11:59 15,360 ----a-w c:\windows\system32\msisip.dll
    - 2004-08-04 10:00:00 1,507,356 ----a-w c:\windows\system32\msjet40.dll
    + 2008-03-25 04:50:34 1,516,568 ----a-w c:\windows\system32\msjet40.dll
    - 2004-08-04 10:00:00 358,976 ----a-w c:\windows\system32\msjetoledb40.dll
    + 2008-03-25 04:50:40 355,112 ----a-w c:\windows\system32\msjetoledb40.dll
    - 2004-08-04 10:00:00 151,583 ----a-w c:\windows\system32\msjint40.dll
    + 2008-04-14 00:12:00 151,583 ----a-w c:\windows\system32\msjint40.dll
    - 2004-08-04 10:00:00 53,279 ----a-w c:\windows\system32\msjter40.dll
    + 2008-03-25 04:50:42 60,192 ----a-w c:\windows\system32\msjter40.dll
    - 2004-08-04 10:00:00 241,693 ----a-w c:\windows\system32\msjtes40.dll
    + 2008-03-25 04:50:42 248,608 ----a-w c:\windows\system32\msjtes40.dll
    - 2004-08-04 10:00:00 25,088 ----a-w c:\windows\system32\mslbui.dll
    + 2008-04-14 00:12:00 25,088 ----a-w c:\windows\system32\mslbui.dll
    - 2006-11-08 01:03:36 156,160 ----a-w c:\windows\system32\msls31.dll
    + 2007-08-13 22:54:10 156,160 ----a-w c:\windows\system32\msls31.dll
    - 2004-08-04 10:00:00 213,023 ----a-w c:\windows\system32\msltus40.dll
    + 2008-03-25 04:50:44 219,936 ----a-w c:\windows\system32\msltus40.dll
    - 2004-08-04 10:00:00 290,816 ----a-w c:\windows\system32\msnsspc.dll
    + 2008-04-14 00:12:00 290,816 ----a-w c:\windows\system32\msnsspc.dll
    - 2004-08-04 11:00:00 252,928 ----a-w c:\windows\system32\msoeacct.dll
    + 2008-04-14 00:12:00 252,928 ----a-w c:\windows\system32\msoeacct.dll
    - 2004-08-04 11:00:00 105,984 ----a-w c:\windows\system32\msoert2.dll
    + 2008-04-14 00:12:00 105,984 ----a-w c:\windows\system32\msoert2.dll
    - 2004-08-04 10:00:00 20,480 ----a-w c:\windows\system32\msorc32r.dll
    + 2008-04-13 17:24:14 20,480 ----a-w c:\windows\system32\msorc32r.dll
    - 2004-08-04 10:00:00 143,360 ----a-w c:\windows\system32\msorcl32.dll
    + 2008-04-14 00:12:00 143,360 ----a-w c:\windows\system32\msorcl32.dll
    - 2004-08-04 11:00:00 343,040 ----a-w c:\windows\system32\mspaint.exe
    + 2008-04-14 00:12:28 343,040 ----a-w c:\windows\system32\mspaint.exe
    - 2004-08-04 10:00:00 30,208 ----a-w c:\windows\system32\mspatcha.dll
    + 2008-04-14 00:12:00 29,696 ----a-w c:\windows\system32\mspatcha.dll
    - 2004-08-04 10:00:00 348,189 ----a-w c:\windows\system32\mspbde40.dll
    + 2008-03-25 04:50:45 355,104 ----a-w c:\windows\system32\mspbde40.dll
    - 2004-08-04 10:00:00 48,128 ----a-w c:\windows\system32\msprivs.dll
    + 2008-04-13 16:23:31 48,128 ----a-w c:\windows\system32\msprivs.dll
    - 2007-08-20 10:04:41 193,024 ----a-w c:\windows\system32\msrating.dll
    + 2008-08-26 07:24:30 193,024 ----a-w c:\windows\system32\msrating.dll
    - 2004-08-04 10:00:00 421,919 ----a-w c:\windows\system32\msrd2x40.dll
    + 2008-03-25 04:50:47 432,928 ----a-w c:\windows\system32\msrd2x40.dll
    - 2004-08-04 10:00:00 315,423 ----a-w c:\windows\system32\msrd3x40.dll
    + 2008-03-25 04:50:49 322,336 ----a-w c:\windows\system32\msrd3x40.dll
    - 2004-08-04 10:00:00 552,989 ----a-w c:\windows\system32\msrepl40.dll
    + 2008-03-25 04:50:52 559,904 ----a-w c:\windows\system32\msrepl40.dll
    - 2004-08-04 10:00:00 11,264 ----a-w c:\windows\system32\msrle32.dll
    + 2008-04-14 00:12:00 11,264 ----a-w c:\windows\system32\msrle32.dll
    - 2004-08-04 10:00:00 134,656 ----a-w c:\windows\system32\mssap.dll
    + 2008-04-14 00:12:00 134,656 ----a-w c:\windows\system32\mssap.dll
    + 2008-04-14 00:12:00 155,136 ----a-w c:\windows\system32\mssha.dll
    + 2008-04-13 18:14:58 76,800 ----a-w c:\windows\system32\msshavmsg.dll
    - 2000-05-24 04:45:58 118,784 ----a-w c:\windows\system32\MSSTDFMT.DLL
    + 2000-03-14 05:00:00 118,784 ----a-w c:\windows\system32\MSSTDFMT.DLL
    - 2004-08-04 11:00:00 274,944 ----a-w c:\windows\system32\mstask.dll
    + 2008-04-14 00:12:00 274,944 ----a-w c:\windows\system32\mstask.dll
    - 2004-08-04 10:00:00 258,077 ----a-w c:\windows\system32\mstext40.dll
    + 2008-03-25 04:50:55 264,992 ----a-w c:\windows\system32\mstext40.dll
    - 2007-08-20 10:04:42 671,232 ----a-w c:\windows\system32\mstime.dll
    + 2008-08-26 07:24:30 671,232 ----a-w c:\windows\system32\mstime.dll
    - 2004-08-04 11:00:00 12,288 ----a-w c:\windows\system32\mstinit.exe
    + 2008-04-14 00:12:29 12,288 ----a-w c:\windows\system32\mstinit.exe
    - 2004-08-04 10:00:00 115,712 ----a-w c:\windows\system32\mstlsapi.dll
    + 2008-04-14 00:12:00 116,224 ----a-w c:\windows\system32\mstlsapi.dll
    - 2006-11-07 08:06:47 600,576 ----a-w c:\windows\system32\mstsc.exe
    + 2008-04-14 00:12:23 677,888 ----a-w c:\windows\system32\mstsc.exe
    - 2006-11-13 06:02:58 1,866,240 ----a-w c:\windows\system32\mstscax.dll
    + 2008-04-14 00:11:56 2,061,824 ----a-w c:\windows\system32\mstscax.dll
    - 2004-08-04 10:00:00 195,072 ----a-w c:\windows\system32\msutb.dll
    + 2008-04-14 00:12:00 195,072 ----a-w c:\windows\system32\msutb.dll
    - 2004-08-04 10:00:00 129,536 ----a-w c:\windows\system32\msv1_0.dll
    + 2008-04-14 00:12:00 132,608 ----a-w c:\windows\system32\msv1_0.dll
    - 2004-08-04 10:00:00 1,392,671 ----a-w c:\windows\system32\msvbvm60.dll
    + 2008-04-14 00:12:00 1,384,479 ----a-w c:\windows\system32\msvbvm60.dll
    - 2004-08-04 10:00:00 54,784 ----a-w c:\windows\system32\msvcirt.dll
    + 2008-04-14 00:12:01 57,344 ----a-w c:\windows\system32\msvcirt.dll
    - 2004-08-04 10:00:00 413,696 ----a-w c:\windows\system32\msvcp60.dll
    + 2008-04-14 00:12:01 413,696 ----a-w c:\windows\system32\msvcp60.dll
    - 2003-03-19 04:14:52 499,712 ----a-r c:\windows\system32\msvcp71.dll
    + 2003-03-19 00:14:52 499,712 ----a-w c:\windows\system32\msvcp71.dll
    - 2003-02-21 10:42:22 348,160 ----a-r c:\windows\system32\msvcr71.dll
    + 2003-02-21 08:42:22 348,160 ----a-w c:\windows\system32\msvcr71.dll
    - 2004-08-04 10:00:00 343,040 ----a-w c:\windows\system32\msvcrt.dll
    + 2008-04-14 00:12:01 343,040 ----a-w c:\windows\system32\msvcrt.dll
    - 2004-08-04 10:00:00 61,440 ----a-w c:\windows\system32\msvcrt40.dll
    + 2008-04-13 18:30:46 61,440 ----a-w c:\windows\system32\msvcrt40.dll
    + 2000-03-07 05:00:00 434,252 ----a-w c:\windows\system32\MSVCRTD.DLL
    - 2004-08-04 10:00:00 120,832 ----a-w c:\windows\system32\msvfw32.dll
    + 2008-04-14 00:12:01 121,344 ----a-w c:\windows\system32\msvfw32.dll
    - 2004-08-04 10:00:00 1,428,480 ----a-w c:\windows\system32\msvidctl.dll
    + 2008-04-14 00:12:01 1,428,992 ----a-w c:\windows\system32\msvidctl.dll
    - 2004-08-04 10:00:00 72,704 ----a-w c:\windows\system32\msw3prt.dll
    + 2008-08-28 07:46:02 74,752 ----a-w c:\windows\system32\msw3prt.dll
    - 2004-08-04 10:00:00 831,519 ----a-w c:\windows\system32\mswdat10.dll
    + 2008-03-25 04:50:57 838,432 ----a-w c:\windows\system32\mswdat10.dll
    - 2004-08-04 10:00:00 204,288 ----a-w c:\windows\system32\mswebdvd.dll
    + 2008-04-14 00:12:01 203,776 ----a-w c:\windows\system32\mswebdvd.dll
    - 2004-08-04 10:00:00 245,248 ----a-w c:\windows\system32\mswsock.dll
    + 2008-06-20 17:46:57 245,248 ----a-w c:\windows\system32\mswsock.dll
    - 2004-08-04 10:00:00 614,429 ----a-w c:\windows\system32\mswstr10.dll
    + 2008-03-25 04:50:58 621,344 ----a-w c:\windows\system32\mswstr10.dll
    - 2004-08-04 10:00:00 348,189 ----a-w c:\windows\system32\msxbde40.dll
    + 2008-03-25 04:50:58 355,104 ----a-w c:\windows\system32\msxbde40.dll
    - 2004-08-04 10:00:00 506,368 ----a-w c:\windows\system32\msxml.dll
    + 2008-04-14 00:12:01 506,368 ----a-w c:\windows\system32\msxml.dll
    - 2004-08-04 10:00:00 701,440 ----a-w c:\windows\system32\msxml2.dll
    + 2008-04-14 00:12:01 701,440 ----a-w c:\windows\system32\msxml2.dll
    - 2007-06-26 06:08:16 1,104,896 ----a-w c:\windows\system32\msxml3.dll
    + 2008-09-04 17:15:04 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    - 2007-05-08 19:03:04 1,275,392 ----a-w c:\windows\system32\msxml4.dll
    + 2008-09-30 21:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    - 2007-05-15 19:43:10 1,320,800 ----a-w c:\windows\system32\msxml6.dll
    + 2008-09-10 01:14:56 1,307,648 ----a-w c:\windows\system32\msxml6.dll
    - 2006-10-19 17:33:20 86,728 ----a-w c:\windows\system32\msxml6r.dll
    + 2008-04-13 17:27:18 79,872 ----a-w c:\windows\system32\msxml6r.dll
    - 2004-08-04 10:00:00 17,408 ----a-w c:\windows\system32\msyuv.dll
    + 2008-04-14 00:12:01 16,896 ----a-w c:\windows\system32\msyuv.dll
    - 2006-03-01 19:42:42 66,560 ----a-w c:\windows\system32\mtxclu.dll
    + 2008-04-14 00:12:01 66,560 ----a-w c:\windows\system32\mtxclu.dll
    - 2004-08-04 11:00:00 20,480 ----a-w c:\windows\system32\mtxdm.dll
    + 2008-04-14 00:12:01 30,720 ----a-w c:\windows\system32\mtxdm.dll
    - 2004-08-04 11:00:00 4,096 ----a-w c:\windows\system32\mtxex.dll
    + 2008-04-14 00:12:01 4,096 ----a-w c:\windows\system32\mtxex.dll
    - 2004-08-04 11:00:00 25,088 ----a-w c:\windows\system32\mtxlegih.dll
    + 2008-04-14 00:12:01 34,304 ----a-w c:\windows\system32\mtxlegih.dll
    - 2006-03-01 19:42:42 91,136 ----a-w c:\windows\system32\mtxoci.dll
    + 2008-04-14 00:12:01 91,648 ----a-w c:\windows\system32\mtxoci.dll
    + 2008-04-14 00:12:01 1,737,856 ----a-w c:\windows\system32\mtxparhd.dll
    - 2007-07-30 23:19:10 271,224 ----a-w c:\windows\system32\mucltui.dll
    + 2008-10-16 19:06:48 268,648 ----a-w c:\windows\system32\mucltui.dll
    - 2006-12-22 17:02:36 6,144 ----a-w c:\windows\system32\mui\0409\mscorees.dll
    + 2007-10-24 06:47:44 15,360 -c--a-w c:\windows\system32\mui\0409\mscorees.dll
    - 2004-08-04 10:00:00 405,504 ----a-w c:\windows\system32\mui\041b\xpob2res.dll
    + 2008-04-13 18:40:52 405,504 -c--a-w c:\windows\system32\mui\041b\xpob2res.dll
    - 2004-08-04 10:00:00 193,024 ----a-w c:\windows\system32\mui\041b\xpsp1res.dll
    + 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\mui\041b\xpsp1res.dll
    - 2004-08-04 10:00:00 757,248 ----a-w c:\windows\system32\mui\041b\xpsp2res.dll
    + 2008-04-13 18:38:37 757,248 -c--a-w c:\windows\system32\mui\041b\xpsp2res.dll
    + 2008-04-13 18:40:04 577,536 -c--a-w c:\windows\system32\mui\041b\xpsp3res.dll
    - 2004-08-04 10:00:00 408,576 ----a-w c:\windows\system32\mui\0424\xpob2res.dll
    + 2008-04-13 18:40:56 408,576 -c--a-w c:\windows\system32\mui\0424\xpob2res.dll
    - 2004-08-04 10:00:00 192,512 ----a-w c:\windows\system32\mui\0424\xpsp1res.dll
    + 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\mui\0424\xpsp1res.dll
    - 2004-08-04 10:00:00 732,160 ----a-w c:\windows\system32\mui\0424\xpsp2res.dll
    + 2008-04-13 18:38:36 732,160 -c--a-w c:\windows\system32\mui\0424\xpsp2res.dll
    + 2008-04-13 18:40:05 576,512 -c--a-w c:\windows\system32\mui\0424\xpsp3res.dll
    - 2007-07-30 23:18:34 207,736 ----a-w c:\windows\system32\muweb.dll
    + 2008-10-16 19:06:48 208,744 ----a-w c:\windows\system32\muweb.dll
    - 2004-08-04 10:00:00 90,624 ----a-w c:\windows\system32\mydocs.dll
    + 2008-04-14 00:12:01 90,624 ----a-w c:\windows\system32\mydocs.dll

  4. #24
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    + 2008-04-14 00:12:01 30,208 ----a-w c:\windows\system32\napipsec.dll
    + 2008-04-14 00:12:01 193,024 ----a-w c:\windows\system32\napmontr.dll
    + 2008-04-14 00:12:29 176,640 ----a-w c:\windows\system32\napstat.exe
    - 2006-10-04 08:48:36 53,760 ----a-w c:\windows\system32\narrator.exe
    + 2008-04-14 00:12:29 53,760 ----a-w c:\windows\system32\narrator.exe
    - 2004-08-04 10:00:00 36,352 ----a-w c:\windows\system32\ncobjapi.dll
    + 2008-04-14 00:12:01 36,352 ----a-w c:\windows\system32\ncobjapi.dll
    - 2004-08-04 10:00:00 17,920 ----a-w c:\windows\system32\nddeapi.dll
    + 2008-04-14 00:12:01 17,920 ----a-w c:\windows\system32\nddeapi.dll
    - 2004-08-04 10:00:00 4,096 ----a-w c:\windows\system32\nddeapir.exe
    + 2008-04-14 00:12:29 4,096 ----a-w c:\windows\system32\nddeapir.exe
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\nddenb32.dll
    + 2008-04-14 00:12:01 18,944 ----a-w c:\windows\system32\nddenb32.dll
    - 2004-08-04 10:00:00 42,496 ----a-w c:\windows\system32\net.exe
    + 2008-04-14 00:12:29 42,496 ----a-w c:\windows\system32\net.exe
    - 2004-08-04 10:00:00 124,928 ----a-w c:\windows\system32\net1.exe
    + 2008-04-14 00:12:29 124,928 ----a-w c:\windows\system32\net1.exe
    - 2006-08-17 12:28:27 332,288 ----a-w c:\windows\system32\netapi32.dll
    + 2008-10-15 16:34:24 337,408 ----a-w c:\windows\system32\netapi32.dll
    - 2004-08-04 10:00:00 622,080 ----a-w c:\windows\system32\netcfgx.dll
    + 2008-04-14 00:12:01 622,592 ----a-w c:\windows\system32\netcfgx.dll
    - 2004-08-04 10:00:00 111,104 ----a-w c:\windows\system32\netdde.exe
    + 2008-04-14 00:12:29 111,104 ----a-w c:\windows\system32\netdde.exe
    - 2004-08-04 10:00:00 139,264 ----a-w c:\windows\system32\netid.dll
    + 2008-04-14 00:12:01 139,264 ----a-w c:\windows\system32\netid.dll
    - 2004-08-04 10:00:00 407,040 ----a-w c:\windows\system32\netlogon.dll
    + 2008-04-14 00:12:01 407,040 ----a-w c:\windows\system32\netlogon.dll
    - 2005-08-22 18:29:46 197,632 ----a-w c:\windows\system32\netman.dll
    + 2008-04-14 00:12:01 198,144 ----a-w c:\windows\system32\netman.dll
    - 2004-08-04 10:00:00 875,008 ----a-w c:\windows\system32\netplwiz.dll
    + 2008-04-14 00:12:01 875,008 ----a-w c:\windows\system32\netplwiz.dll
    + 2007-10-08 19:11:52 208,896 ----a-w c:\windows\system32\NetProvCredMan.dll
    - 2004-08-04 10:00:00 12,288 ----a-w c:\windows\system32\netrap.dll
    + 2008-04-14 00:12:01 11,776 ----a-w c:\windows\system32\netrap.dll
    - 2004-08-04 10:00:00 329,728 ----a-w c:\windows\system32\netsetup.exe
    + 2008-04-14 00:16:51 329,728 ----a-w c:\windows\system32\netsetup.exe
    - 2004-08-04 10:00:00 86,016 ----a-w c:\windows\system32\netsh.exe
    + 2008-04-14 00:12:29 86,016 ----a-w c:\windows\system32\netsh.exe
    - 2004-08-04 10:00:00 1,708,032 ----a-w c:\windows\system32\netshell.dll
    + 2008-04-14 00:12:02 1,703,936 ----a-w c:\windows\system32\netshell.dll
    - 2004-08-04 10:00:00 36,864 ----a-w c:\windows\system32\netstat.exe
    + 2008-04-14 00:12:29 36,864 ----a-w c:\windows\system32\netstat.exe
    - 2004-08-04 10:00:00 80,896 ----a-w c:\windows\system32\netui0.dll
    + 2008-04-14 00:12:02 80,896 ----a-w c:\windows\system32\netui0.dll
    - 2004-08-04 10:00:00 245,760 ----a-w c:\windows\system32\netui1.dll
    + 2008-04-14 00:12:02 245,760 ----a-w c:\windows\system32\netui1.dll
    + 2007-08-27 16:12:00 745,472 ----a-w c:\windows\system32\NETw4c32.dll
    + 2007-08-27 16:12:58 2,777,088 ----a-w c:\windows\system32\NETw4r32.dll
    - 2004-08-04 10:00:00 248,832 ----a-w c:\windows\system32\newdev.dll
    + 2008-04-14 00:12:02 247,808 ----a-w c:\windows\system32\newdev.dll
    - 2004-08-04 10:00:00 103,936 ----a-w c:\windows\system32\nlhtml.dll
    + 2008-04-14 00:12:02 98,304 ----a-w c:\windows\system32\nlhtml.dll
    - 2004-08-04 11:00:00 28,672 ----a-w c:\windows\system32\nmmkcert.dll
    + 2008-04-14 00:12:02 28,672 ----a-w c:\windows\system32\nmmkcert.dll
    - 2004-08-04 10:00:00 69,120 ----a-w c:\windows\system32\notepad.exe
    + 2008-04-14 00:12:29 69,120 ----a-w c:\windows\system32\notepad.exe
    + 1998-11-20 17:38:58 151,552 ----a-w c:\windows\system32\Npindeo.dll
    - 2004-08-04 10:00:00 57,344 ----a-w c:\windows\system32\npp\ndisnpp.dll
    + 2008-04-14 00:12:01 57,344 -c--a-w c:\windows\system32\npp\ndisnpp.dll
    - 2004-08-04 10:00:00 15,360 ----a-w c:\windows\system32\npp\nppagent.exe
    + 2008-04-14 00:12:29 15,360 -c--a-w c:\windows\system32\npp\nppagent.exe
    - 2004-08-04 10:00:00 54,784 ----a-w c:\windows\system32\npptools.dll
    + 2008-04-14 00:12:02 54,784 ----a-w c:\windows\system32\npptools.dll
    + 2001-03-03 00:52:42 8,704 ----a-w c:\windows\system32\npwmsdrm.dll
    - 2004-08-04 10:00:00 76,800 ----a-w c:\windows\system32\nslookup.exe
    + 2008-04-14 00:12:29 76,800 ----a-w c:\windows\system32\nslookup.exe
    - 2004-08-04 10:00:00 708,096 ----a-w c:\windows\system32\ntdll.dll
    + 2008-04-14 00:11:24 706,048 ----a-w c:\windows\system32\ntdll.dll
    - 2004-08-04 10:00:00 67,072 ----a-w c:\windows\system32\ntdsapi.dll
    + 2008-04-14 00:12:02 67,072 ----a-w c:\windows\system32\ntdsapi.dll
    - 2007-02-28 09:15:59 2,017,280 ----a-w c:\windows\system32\ntkrnlpa.exe
    + 2008-08-14 09:33:16 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
    - 2004-08-04 10:00:00 43,520 ----a-w c:\windows\system32\ntlanman.dll
    + 2008-04-14 00:12:02 44,032 ----a-w c:\windows\system32\ntlanman.dll
    - 2004-08-04 10:00:00 8,192 ----a-w c:\windows\system32\ntlsapi.dll
    + 2008-04-14 00:12:02 8,192 ----a-w c:\windows\system32\ntlsapi.dll
    - 2004-08-04 10:00:00 118,784 ----a-w c:\windows\system32\ntmarta.dll
    + 2008-04-14 00:12:02 118,784 ----a-w c:\windows\system32\ntmarta.dll
    - 2004-08-04 10:00:00 40,960 ----a-w c:\windows\system32\ntmsapi.dll
    + 2008-04-14 00:12:02 40,960 ----a-w c:\windows\system32\ntmsapi.dll
    - 2004-08-04 10:00:00 179,712 ----a-w c:\windows\system32\ntmsdba.dll
    + 2008-04-14 00:12:02 179,200 ----a-w c:\windows\system32\ntmsdba.dll
    - 2004-08-04 10:00:00 488,448 ----a-w c:\windows\system32\ntmsmgr.dll
    + 2008-04-14 00:12:02 488,448 ----a-w c:\windows\system32\ntmsmgr.dll
    - 2004-08-04 10:00:00 435,200 ----a-w c:\windows\system32\ntmssvc.dll
    + 2008-04-14 00:12:02 435,200 ----a-w c:\windows\system32\ntmssvc.dll
    - 2007-02-28 09:53:04 2,137,600 ----a-w c:\windows\system32\ntoskrnl.exe
    + 2008-08-14 10:09:26 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
    - 2004-08-04 10:00:00 91,136 ----a-w c:\windows\system32\ntprint.dll
    + 2008-04-14 00:12:02 91,136 ----a-w c:\windows\system32\ntprint.dll
    - 2004-08-04 10:00:00 143,872 ----a-w c:\windows\system32\ntshrui.dll
    + 2008-04-14 00:12:02 143,360 ----a-w c:\windows\system32\ntshrui.dll
    - 2004-08-04 10:00:00 419,840 ----a-w c:\windows\system32\ntvdm.exe
    + 2008-04-14 00:12:30 420,864 ----a-w c:\windows\system32\ntvdm.exe
    - 2004-08-04 10:00:00 13,312 ----a-w c:\windows\system32\ntvdmd.dll
    + 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\ntvdmd.dll
    - 2004-08-04 06:56:46 4,274,816 ----a-w c:\windows\system32\nv4_disp.dll
    + 2008-04-14 00:12:02 4,274,816 ----a-w c:\windows\system32\nv4_disp.dll
    - 2006-10-13 12:35:12 142,336 ----a-w c:\windows\system32\nwprovau.dll
    + 2008-04-14 00:12:02 142,336 ----a-w c:\windows\system32\nwprovau.dll
    - 2004-08-04 10:00:00 266,752 ----a-w c:\windows\system32\oakley.dll
    + 2008-04-14 00:12:02 270,336 ----a-w c:\windows\system32\oakley.dll
    - 2004-08-04 10:00:00 285,696 ----a-w c:\windows\system32\objsel.dll
    + 2008-04-14 00:12:02 286,208 ----a-w c:\windows\system32\objsel.dll
    - 2007-08-20 10:04:42 102,400 ----a-w c:\windows\system32\occache.dll
    + 2008-08-26 07:24:30 102,912 ----a-w c:\windows\system32\occache.dll
    - 2004-08-04 10:00:00 60,928 ----a-w c:\windows\system32\ocmanage.dll
    + 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\ocmanage.dll
    - 2004-08-04 10:00:00 249,856 ----a-w c:\windows\system32\odbc32.dll
    + 2008-04-14 00:12:02 249,856 ----a-w c:\windows\system32\odbc32.dll
    - 2004-08-04 10:00:00 16,384 ----a-w c:\windows\system32\odbc32gt.dll
    + 2008-04-14 00:12:02 16,384 ----a-w c:\windows\system32\odbc32gt.dll
    - 2004-08-04 10:00:00 32,768 ----a-w c:\windows\system32\odbcad32.exe
    + 2008-04-14 00:12:30 32,768 ----a-w c:\windows\system32\odbcad32.exe
    - 2004-08-04 10:00:00 24,576 ----a-w c:\windows\system32\odbcbcp.dll
    + 2008-04-14 00:12:02 24,576 ----a-w c:\windows\system32\odbcbcp.dll
    - 2004-08-04 10:00:00 135,168 ----a-w c:\windows\system32\odbcconf.dll
    + 2008-04-14 00:12:02 135,168 ----a-w c:\windows\system32\odbcconf.dll
    - 2004-08-04 10:00:00 69,632 ----a-w c:\windows\system32\odbcconf.exe
    + 2008-04-14 00:12:30 69,632 ----a-w c:\windows\system32\odbcconf.exe
    - 2004-08-04 10:00:00 106,496 ----a-w c:\windows\system32\odbccp32.dll
    + 2008-04-14 00:12:02 106,496 ----a-w c:\windows\system32\odbccp32.dll
    - 2004-08-04 10:00:00 65,536 ----a-w c:\windows\system32\odbccr32.dll
    + 2008-04-14 00:12:02 65,536 ----a-w c:\windows\system32\odbccr32.dll
    - 2004-08-04 10:00:00 65,536 ----a-w c:\windows\system32\odbccu32.dll
    + 2008-04-14 00:12:02 65,536 ----a-w c:\windows\system32\odbccu32.dll
    - 2004-08-04 10:00:00 94,208 ----a-w c:\windows\system32\odbcint.dll
    + 2008-04-13 17:26:05 94,208 ----a-w c:\windows\system32\odbcint.dll
    - 2004-08-04 10:00:00 53,279 ----a-w c:\windows\system32\odbcji32.dll
    + 2008-04-14 00:10:31 53,279 ----a-w c:\windows\system32\odbcji32.dll
    - 2004-08-04 10:00:00 278,559 ----a-w c:\windows\system32\odbcjt32.dll
    + 2008-04-14 00:12:02 278,559 ----a-w c:\windows\system32\odbcjt32.dll
    - 2004-08-04 10:00:00 12,288 ----a-w c:\windows\system32\odbcp32r.dll
    + 2008-04-13 17:26:05 12,288 ----a-w c:\windows\system32\odbcp32r.dll
    - 2004-08-04 10:00:00 147,456 ----a-w c:\windows\system32\odbctrac.dll
    + 2008-04-14 00:12:02 147,456 ----a-w c:\windows\system32\odbctrac.dll
    - 2004-08-04 10:00:00 20,511 ----a-w c:\windows\system32\oddbse32.dll
    + 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\oddbse32.dll
    - 2004-08-04 10:00:00 20,510 ----a-w c:\windows\system32\odexl32.dll
    + 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odexl32.dll
    - 2004-08-04 10:00:00 20,510 ----a-w c:\windows\system32\odfox32.dll
    + 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odfox32.dll
    - 2004-08-04 10:00:00 20,510 ----a-w c:\windows\system32\odpdx32.dll
    + 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odpdx32.dll
    - 2004-08-04 10:00:00 20,511 ----a-w c:\windows\system32\odtext32.dll
    + 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\odtext32.dll
    - 2004-08-04 10:00:00 120,832 ----a-w c:\windows\system32\offfilt.dll
    + 2008-04-14 00:12:02 192,000 ----a-w c:\windows\system32\offfilt.dll
    - 2005-07-26 04:39:48 1,285,120 ----a-w c:\windows\system32\ole32.dll
    + 2008-04-14 00:12:02 1,287,168 ----a-w c:\windows\system32\ole32.dll
    - 2007-05-17 11:28:05 549,376 ----a-w c:\windows\system32\oleaut32.dll
    + 2008-04-14 00:12:02 551,936 ----a-w c:\windows\system32\oleaut32.dll
    - 2005-07-26 04:39:48 74,752 ----a-w c:\windows\system32\olecli32.dll
    + 2008-04-14 00:12:02 74,752 ----a-w c:\windows\system32\olecli32.dll
    - 2005-07-26 04:39:49 37,888 ----a-w c:\windows\system32\olecnv32.dll
    + 2008-04-14 00:12:02 37,376 ----a-w c:\windows\system32\olecnv32.dll
    - 2006-10-16 16:15:00 122,880 ----a-w c:\windows\system32\oledlg.dll
    + 2008-04-14 00:12:02 122,880 ----a-w c:\windows\system32\oledlg.dll
    - 2004-08-04 10:00:00 107,008 ----a-w c:\windows\system32\oleprn.dll
    + 2008-04-14 00:12:02 107,008 ----a-w c:\windows\system32\oleprn.dll
    - 2004-08-04 10:00:00 83,456 ----a-w c:\windows\system32\olepro32.dll
    + 2008-04-14 00:12:02 84,992 ----a-w c:\windows\system32\olepro32.dll
    + 2008-04-14 00:12:02 144,384 ----a-w c:\windows\system32\onex.dll
    - 2004-08-04 11:00:00 122,368 ----a-w c:\windows\system32\oobe\msobcomm.dll
    + 2008-04-14 00:12:00 122,368 -c--a-w c:\windows\system32\oobe\msobcomm.dll
    - 2004-08-04 11:00:00 16,384 ----a-w c:\windows\system32\oobe\msobdl.dll
    + 2008-04-14 00:12:00 16,384 -c--a-w c:\windows\system32\oobe\msobdl.dll
    - 2004-08-04 11:00:00 561,664 ----a-w c:\windows\system32\oobe\msobmain.dll
    + 2008-04-14 00:12:00 565,248 -c--a-w c:\windows\system32\oobe\msobmain.dll
    - 2004-08-04 11:00:00 30,720 ----a-w c:\windows\system32\oobe\msobshel.dll
    + 2008-04-14 00:12:00 30,720 -c--a-w c:\windows\system32\oobe\msobshel.dll
    - 2004-08-04 11:00:00 18,944 ----a-w c:\windows\system32\oobe\msobweb.dll
    + 2008-04-14 00:12:00 19,456 -c--a-w c:\windows\system32\oobe\msobweb.dll
    - 2004-08-04 11:00:00 28,160 ----a-w c:\windows\system32\oobe\msoobe.exe
    + 2008-04-14 00:12:28 29,184 -c--a-w c:\windows\system32\oobe\msoobe.exe
    - 2004-08-04 11:00:00 51,200 ----a-w c:\windows\system32\oobe\oobebaln.exe
    + 2008-04-14 00:12:31 51,200 -c--a-w c:\windows\system32\oobe\oobebaln.exe
    - 2004-08-04 10:00:00 713,728 ----a-w c:\windows\system32\opengl32.dll
    + 2008-04-14 00:12:02 713,728 ----a-w c:\windows\system32\opengl32.dll
    - 2006-10-04 08:48:37 215,552 ----a-w c:\windows\system32\osk.exe
    + 2008-04-14 00:12:31 215,552 ----a-w c:\windows\system32\osk.exe
    - 2004-08-04 10:00:00 67,584 ----a-w c:\windows\system32\osuninst.dll
    + 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\osuninst.dll
    - 2006-10-11 16:24:45 153,088 ----a-w c:\windows\system32\p2p.dll
    + 2008-04-14 00:12:02 153,600 ----a-w c:\windows\system32\p2p.dll
    - 2006-10-11 16:24:45 104,960 ----a-w c:\windows\system32\p2pgasvc.dll
    + 2008-04-14 00:12:02 105,472 ----a-w c:\windows\system32\p2pgasvc.dll
    - 2006-10-11 16:24:45 313,344 ----a-w c:\windows\system32\p2pgraph.dll
    + 2008-04-14 00:12:02 313,856 ----a-w c:\windows\system32\p2pgraph.dll
    - 2006-10-11 16:24:45 116,224 ----a-w c:\windows\system32\p2pnetsh.dll
    + 2008-04-14 00:12:02 115,712 ----a-w c:\windows\system32\p2pnetsh.dll
    - 2006-10-11 16:24:45 553,984 ----a-w c:\windows\system32\p2psvc.dll
    + 2008-04-14 00:12:02 554,496 ----a-w c:\windows\system32\p2psvc.dll
    - 2004-08-04 10:00:00 58,368 ----a-w c:\windows\system32\packager.exe
    + 2008-04-14 00:12:31 58,368 ----a-w c:\windows\system32\packager.exe
    - 2004-08-04 10:00:00 62,976 ----a-w c:\windows\system32\pautoenr.dll
    + 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\pautoenr.dll
    - 2004-08-04 10:00:00 283,648 ----a-w c:\windows\system32\pdh.dll
    + 2008-04-14 00:12:02 284,160 ----a-w c:\windows\system32\pdh.dll
    - 2007-07-11 10:55:55 79,790 ----a-w c:\windows\system32\perfc009.dat
    + 2008-12-02 01:00:10 81,818 ----a-w c:\windows\system32\perfc009.dat
    - 2004-08-04 10:00:00 39,936 ----a-w c:\windows\system32\perfctrs.dll
    + 2008-04-14 00:12:02 39,936 ----a-w c:\windows\system32\perfctrs.dll
    - 2004-08-04 10:00:00 26,624 ----a-w c:\windows\system32\perfdisk.dll
    + 2008-04-14 00:12:02 26,624 ----a-w c:\windows\system32\perfdisk.dll
    - 2007-07-11 10:55:55 457,534 ----a-w c:\windows\system32\perfh009.dat
    + 2008-12-02 01:00:10 465,702 ----a-w c:\windows\system32\perfh009.dat
    - 2004-08-04 10:00:00 15,872 ----a-w c:\windows\system32\perfmon.exe
    + 2008-04-14 00:12:31 15,872 ----a-w c:\windows\system32\perfmon.exe
    - 2004-08-04 10:00:00 16,896 ----a-w c:\windows\system32\perfnet.dll
    + 2008-04-14 00:12:02 17,920 ----a-w c:\windows\system32\perfnet.dll
    - 2004-08-04 10:00:00 25,088 ----a-w c:\windows\system32\perfos.dll
    + 2008-04-14 00:12:02 25,088 ----a-w c:\windows\system32\perfos.dll
    - 2004-08-04 10:00:00 34,816 ----a-w c:\windows\system32\perfproc.dll
    + 2008-04-14 00:12:02 34,816 ----a-w c:\windows\system32\perfproc.dll
    - 2006-10-24 16:30:20 412,160 ------w c:\windows\system32\photometadatahandler.dll
    + 2008-04-14 00:12:02 412,160 ----a-w c:\windows\system32\photometadatahandler.dll
    - 2004-08-04 10:00:00 176,128 ----a-w c:\windows\system32\photowiz.dll
    + 2008-04-14 00:12:02 176,128 ----a-w c:\windows\system32\photowiz.dll
    - 2004-08-04 10:00:00 35,328 ----a-w c:\windows\system32\pid.dll
    + 2008-04-14 00:12:02 35,328 ----a-w c:\windows\system32\pid.dll
    - 2004-08-04 10:00:00 24,064 ----a-w c:\windows\system32\pidgen.dll
    + 2008-04-13 18:35:22 24,064 ----a-w c:\windows\system32\pidgen.dll
    - 2004-08-04 10:00:00 17,920 ----a-w c:\windows\system32\ping.exe
    + 2008-04-14 00:12:31 17,920 ----a-w c:\windows\system32\ping.exe
    - 2004-08-04 10:00:00 15,360 ----a-w c:\windows\system32\pjlmon.dll
    + 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\pjlmon.dll
    - 2006-10-17 15:58:08 44,544 ----a-w c:\windows\system32\pngfilt.dll
    + 2008-08-26 07:24:30 44,544 ----a-w c:\windows\system32\pngfilt.dll
    - 2006-10-11 16:24:45 58,880 ----a-w c:\windows\system32\pnrpnsp.dll
    + 2008-04-14 00:12:02 58,880 ----a-w c:\windows\system32\pnrpnsp.dll
    - 2004-08-04 10:00:00 105,472 ----a-w c:\windows\system32\polstore.dll
    + 2008-04-14 00:12:02 105,472 ----a-w c:\windows\system32\polstore.dll
    - 2004-08-04 10:00:00 49,152 ----a-w c:\windows\system32\powercfg.exe
    + 2008-04-14 00:12:31 49,152 ----a-w c:\windows\system32\powercfg.exe
    - 2004-08-04 10:00:00 17,408 ----a-w c:\windows\system32\powrprof.dll
    + 2008-04-14 00:12:03 17,408 ----a-w c:\windows\system32\powrprof.dll
    - 2006-10-21 01:29:52 104,224 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    + 2007-10-09 18:03:04 106,520 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    - 2006-10-21 01:29:58 344,352 ----a-w c:\windows\system32\PresentationHost.exe
    + 2007-10-09 18:03:08 350,744 ----a-w c:\windows\system32\PresentationHost.exe
    - 2006-10-21 01:29:46 20,768 ----a-w c:\windows\system32\PresentationHostProxy.dll
    + 2007-10-09 18:03:02 33,304 ----a-w c:\windows\system32\PresentationHostProxy.dll
    - 2006-10-21 01:30:02 769,312 ----a-w c:\windows\system32\PresentationNative_v0300.dll
    + 2007-10-09 18:03:12 779,800 ----a-w c:\windows\system32\PresentationNative_v0300.dll
    - 2004-08-04 10:00:00 560,640 ----a-w c:\windows\system32\printui.dll
    + 2008-04-14 00:12:03 560,640 ----a-w c:\windows\system32\printui.dll
    - 2004-08-04 10:00:00 27,648 ----a-w c:\windows\system32\profmap.dll
    + 2008-04-14 00:12:03 27,648 ----a-w c:\windows\system32\profmap.dll
    - 2004-08-04 10:00:00 109,568 ----a-w c:\windows\system32\progman.exe
    + 2008-04-14 00:12:31 109,568 ----a-w c:\windows\system32\progman.exe
    - 2004-08-04 10:00:00 50,176 ----a-w c:\windows\system32\proquota.exe
    + 2008-04-14 00:12:32 50,176 ----a-w c:\windows\system32\proquota.exe
    - 2004-08-04 10:00:00 9,216 ----a-w c:\windows\system32\proxycfg.exe
    + 2008-04-14 00:12:32 9,216 ----a-w c:\windows\system32\proxycfg.exe
    - 2004-08-04 10:00:00 23,040 ----a-w c:\windows\system32\psapi.dll
    + 2008-04-14 00:12:03 23,040 ----a-w c:\windows\system32\psapi.dll
    - 2004-08-04 10:00:00 96,768 ----a-w c:\windows\system32\psbase.dll
    + 2008-04-14 00:12:03 96,768 ----a-w c:\windows\system32\psbase.dll
    - 2004-08-04 10:00:00 43,520 ----a-w c:\windows\system32\pstorec.dll
    + 2008-04-14 00:12:03 43,520 ----a-w c:\windows\system32\pstorec.dll
    - 2004-08-04 10:00:00 34,304 ----a-w c:\windows\system32\pstorsvc.dll
    + 2008-04-14 00:12:03 34,304 ----a-w c:\windows\system32\pstorsvc.dll
    + 2008-04-14 00:12:03 150,528 ----a-w c:\windows\system32\qagent.dll
    + 2008-04-14 00:12:03 291,328 ----a-w c:\windows\system32\qagentrt.dll
    - 2004-08-04 10:00:00 192,512 ----a-w c:\windows\system32\qcap.dll
    + 2008-04-14 00:12:03 192,512 ----a-w c:\windows\system32\qcap.dll
    + 2008-04-14 00:12:03 62,464 ----a-w c:\windows\system32\qcliprov.dll
    + 2005-01-18 21:05:12 466,944 ----a-w c:\windows\system32\QCUI2.dll
    - 2004-08-04 10:00:00 279,040 ----a-w c:\windows\system32\qdv.dll
    + 2008-04-14 00:12:03 279,040 ----a-w c:\windows\system32\qdv.dll
    - 2004-08-04 10:00:00 385,024 ----a-w c:\windows\system32\qdvd.dll
    + 2008-04-14 00:12:03 386,048 ----a-w c:\windows\system32\qdvd.dll
    - 2004-08-04 10:00:00 562,176 ----a-w c:\windows\system32\qedit.dll
    + 2008-04-14 00:12:03 562,176 ----a-w c:\windows\system32\qedit.dll
    - 2004-08-04 10:00:00 733,696 ----a-w c:\windows\system32\qedwipes.dll
    + 2008-04-13 17:21:32 733,696 ----a-w c:\windows\system32\qedwipes.dll
    - 2004-08-04 11:00:00 382,464 ----a-w c:\windows\system32\qmgr.dll
    + 2008-04-14 00:12:03 409,088 ----a-w c:\windows\system32\qmgr.dll
    - 2004-08-04 11:00:00 18,944 ----a-w c:\windows\system32\qmgrprxy.dll
    + 2008-04-14 00:12:03 18,944 ----a-w c:\windows\system32\qmgrprxy.dll
    - 2004-08-04 11:00:00 20,480 ----a-w c:\windows\system32\qprocess.exe
    + 2008-04-14 00:12:32 19,968 ----a-w c:\windows\system32\qprocess.exe
    - 2005-08-30 03:54:26 1,287,168 ----a-w c:\windows\system32\quartz.dll
    + 2008-05-07 05:12:40 1,288,192 ----a-w c:\windows\system32\quartz.dll
    - 2006-06-22 05:06:30 1,435,648 ----a-w c:\windows\system32\query.dll
    + 2008-04-14 00:12:03 1,435,648 ----a-w c:\windows\system32\query.dll
    + 2008-04-14 00:12:03 76,800 ----a-w c:\windows\system32\qutil.dll

  5. #25
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    - 2004-08-04 11:00:00 43,520 ----a-w c:\windows\system32\racpldlg.dll
    + 2008-04-14 00:12:03 43,520 ----a-w c:\windows\system32\racpldlg.dll
    + 2007-09-12 14:19:56 8,784 ----a-w c:\windows\system32\ractrlkeyhook.dll
    - 2006-06-26 17:37:10 8,192 ----a-w c:\windows\system32\rasadhlp.dll
    + 2008-04-14 00:12:03 7,680 ----a-w c:\windows\system32\rasadhlp.dll
    - 2004-08-04 10:00:00 236,544 ----a-w c:\windows\system32\rasapi32.dll
    + 2008-04-14 00:12:03 237,056 ----a-w c:\windows\system32\rasapi32.dll
    - 2004-08-04 10:00:00 89,088 ----a-w c:\windows\system32\rasauto.dll
    + 2008-04-14 00:12:03 88,576 ----a-w c:\windows\system32\rasauto.dll
    - 2004-08-04 10:00:00 69,632 ----a-w c:\windows\system32\raschap.dll
    + 2008-04-14 00:12:03 79,872 ----a-w c:\windows\system32\raschap.dll
    - 2004-08-04 10:00:00 657,920 ----a-w c:\windows\system32\rasdlg.dll
    + 2008-04-14 00:12:03 658,432 ----a-w c:\windows\system32\rasdlg.dll
    - 2004-08-04 10:00:00 61,440 ----a-w c:\windows\system32\rasman.dll
    + 2008-04-14 00:12:03 61,440 ----a-w c:\windows\system32\rasman.dll
    - 2006-06-22 10:47:18 181,248 ----a-w c:\windows\system32\rasmans.dll
    + 2008-04-14 00:12:03 186,368 ----a-w c:\windows\system32\rasmans.dll
    - 2004-08-04 10:00:00 56,832 ----a-w c:\windows\system32\rasphone.exe
    + 2008-04-14 00:12:32 56,832 ----a-w c:\windows\system32\rasphone.exe
    - 2004-08-04 10:00:00 206,336 ----a-w c:\windows\system32\rasppp.dll
    + 2008-04-14 00:12:03 210,944 ----a-w c:\windows\system32\rasppp.dll
    + 2008-04-14 00:12:03 61,952 ----a-w c:\windows\system32\rasqec.dll
    - 2004-08-04 10:00:00 16,896 ----a-w c:\windows\system32\rassapi.dll
    + 2008-04-14 00:12:03 16,384 ----a-w c:\windows\system32\rassapi.dll
    - 2004-08-04 10:00:00 58,880 ----a-w c:\windows\system32\rastapi.dll
    + 2008-04-14 00:12:03 58,368 ----a-w c:\windows\system32\rastapi.dll
    - 2004-08-04 10:00:00 112,128 ----a-w c:\windows\system32\rastls.dll
    + 2008-04-14 00:12:03 150,016 ----a-w c:\windows\system32\rastls.dll
    - 2004-08-04 10:00:00 102,400 ----a-w c:\windows\system32\rcbdyctl.dll
    + 2008-04-14 00:12:03 102,400 ----a-w c:\windows\system32\rcbdyctl.dll
    - 2004-08-04 10:00:00 35,840 ----a-w c:\windows\system32\rcimlby.exe
    + 2008-04-14 00:12:32 35,840 ----a-w c:\windows\system32\rcimlby.exe
    - 2004-08-04 10:00:00 21,504 ----a-w c:\windows\system32\rcp.exe
    + 2008-04-14 00:12:32 21,504 ----a-w c:\windows\system32\rcp.exe
    - 2004-08-04 11:00:00 147,968 ----a-w c:\windows\system32\rdchost.dll
    + 2008-04-14 00:12:03 147,968 ----a-w c:\windows\system32\rdchost.dll
    - 2004-08-04 11:00:00 62,464 ----a-w c:\windows\system32\rdpclip.exe
    + 2008-04-14 00:12:32 62,976 ----a-w c:\windows\system32\rdpclip.exe
    - 2004-08-04 10:00:00 92,168 ----a-w c:\windows\system32\rdpdd.dll
    + 2008-04-14 00:13:22 92,424 ----a-w c:\windows\system32\rdpdd.dll
    - 2004-08-04 11:00:00 19,968 ----a-w c:\windows\system32\rdpsnd.dll
    + 2008-04-14 00:12:04 19,968 ----a-w c:\windows\system32\rdpsnd.dll
    - 2004-08-04 11:00:00 87,176 ----a-w c:\windows\system32\rdpwsx.dll
    + 2008-04-14 00:13:22 87,176 ----a-w c:\windows\system32\rdpwsx.dll
    - 2004-08-04 11:00:00 13,824 ----a-w c:\windows\system32\rdsaddin.exe
    + 2008-04-14 00:12:32 13,824 ----a-w c:\windows\system32\rdsaddin.exe
    - 2004-08-04 11:00:00 67,072 ----a-w c:\windows\system32\rdshost.exe
    + 2008-04-14 00:12:32 67,072 ----a-w c:\windows\system32\rdshost.exe
    - 2004-08-04 10:00:00 50,176 ----a-w c:\windows\system32\reg.exe
    + 2008-04-14 00:12:32 50,176 ----a-w c:\windows\system32\reg.exe
    - 2004-08-04 10:00:00 49,664 ----a-w c:\windows\system32\regapi.dll
    + 2008-04-14 00:12:04 49,664 ----a-w c:\windows\system32\regapi.dll
    - 2004-08-04 10:00:00 59,904 ----a-w c:\windows\system32\regsvc.dll
    + 2008-04-14 00:12:04 59,904 ----a-w c:\windows\system32\regsvc.dll
    - 2004-08-04 10:00:00 11,776 ----a-w c:\windows\system32\regsvr32.exe
    + 2008-04-14 00:12:32 11,776 ----a-w c:\windows\system32\regsvr32.exe
    - 2004-08-04 10:00:00 397,824 ----a-w c:\windows\system32\regwizc.dll
    + 2008-04-14 00:12:04 397,824 ----a-w c:\windows\system32\regwizc.dll
    + 2004-08-04 10:00:00 11,136 -c--a-w c:\windows\system32\ReinstallBackups\0015\DriverFiles\i386\sffdisk.sys
    + 2004-08-04 10:00:00 10,240 -c--a-w c:\windows\system32\ReinstallBackups\0015\DriverFiles\i386\sffp_sd.sys
    + 2004-08-04 10:00:00 36,096 -c--a-w c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\intelppm.sys
    + 2004-08-04 10:00:00 36,096 -c--a-w c:\windows\system32\ReinstallBackups\0017\DriverFiles\i386\intelppm.sys
    + 2004-08-04 10:00:00 67,584 -c--a-w c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\sdbus.sys
    + 2004-08-12 23:45:54 137,728 -c--a-w c:\windows\system32\ReinstallBackups\0019\DriverFiles\hdaudbus.sys
    + 2005-12-13 22:39:58 73,728 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\hccutils.dll
    + 2005-12-13 22:41:08 77,824 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\hkcmd.exe
    + 2005-12-13 23:01:16 61,440 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\iAlmCoIn.dll
    + 2005-12-13 23:08:32 899,196 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmdd5.dll
    + 2005-12-13 23:01:02 214,748 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmdev5.dll
    + 2005-12-13 23:01:14 119,933 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmdnt5.dll
    + 2005-12-13 23:09:34 1,364,574 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmnt5.sys
    + 2005-12-13 23:01:18 49,152 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmrem.dll
    + 2005-12-13 23:01:20 36,992 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\ialmrnt5.dll
    + 2005-12-13 22:43:42 450,560 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxcfg.exe
    + 2005-12-13 22:40:12 139,264 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxdev.dll
    + 2005-12-13 22:41:14 86,016 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxdo.dll
    + 2005-12-13 22:44:52 40,960 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxexps.dll
    + 2005-12-13 22:44:52 94,208 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxext.exe
    + 2005-12-13 22:45:00 118,784 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxpers.exe
    + 2005-12-13 22:44:02 147,456 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxpph.dll
    + 2005-12-13 22:44:08 1,503,232 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxress.dll
    + 2005-12-13 22:41:02 57,344 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxsrvc.dll
    + 2005-12-13 22:41:00 159,744 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxsrvc.exe
    + 2005-12-13 22:44:18 98,304 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxtray.exe
    + 2005-12-13 22:44:46 114,688 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igfxzoom.exe
    + 2005-12-13 22:53:32 524,288 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\igldev32.dll
    + 2005-12-13 22:51:42 2,310,144 ----a-w c:\windows\system32\ReinstallBackups\0020\DriverFiles\iglicd32.dll
    + 2007-03-31 00:59:08 102,400 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\hccutils.dll
    + 2007-03-31 01:00:16 162,584 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\hkcmd.exe
    + 2005-12-13 23:01:16 61,440 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\iAlmCoIn.dll
    + 2005-12-13 23:08:32 899,196 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmdd5.dll
    + 2005-12-13 23:01:02 214,748 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmdev5.dll
    + 2005-12-13 23:01:14 119,933 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmdnt5.dll
    + 2005-12-13 23:09:34 1,364,574 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmnt5.sys
    + 2005-12-13 23:01:18 49,152 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmrem.dll
    + 2005-12-13 23:01:20 36,992 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\ialmrnt5.dll
    + 2007-03-31 01:01:10 535,320 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxcfg.exe
    + 2007-03-31 00:59:06 204,800 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxdev.dll
    + 2007-03-31 00:59:36 135,168 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxdo.dll
    + 2007-03-31 00:59:36 24,576 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxexps.dll
    + 2007-03-31 00:59:34 166,680 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxext.exe
    + 2007-03-31 00:59:36 138,008 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxpers.exe
    + 2007-03-31 00:59:44 200,704 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxpph.dll
    + 2007-03-31 00:58:56 3,293,184 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxress.dll
    + 2007-03-31 00:59:28 47,616 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxsrvc.dll
    + 2007-03-31 00:59:26 252,696 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxsrvc.exe
    + 2007-03-31 01:00:02 138,008 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxtray.exe
    + 2007-03-31 00:59:20 170,776 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igfxzoom.exe
    + 2007-03-31 01:33:06 450,560 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\igldev32.dll
    + 2007-03-31 01:31:28 2,334,720 ----a-w c:\windows\system32\ReinstallBackups\0021\DriverFiles\iglicd32.dll
    + 2005-10-14 14:40:18 51,328 ----a-w c:\windows\system32\ReinstallBackups\0022\DriverFiles\rimsptsk.sys
    + 2005-10-14 14:40:18 90,112 ----a-w c:\windows\system32\ReinstallBackups\0022\DriverFiles\snymsico.dll
    + 2005-10-14 14:40:18 16,480 ----a-w c:\windows\system32\ReinstallBackups\0023\DriverFiles\rixdicon.dll
    + 2005-10-14 14:40:18 307,968 ----a-w c:\windows\system32\ReinstallBackups\0023\DriverFiles\rixdptsk.sys
    + 2005-10-14 14:40:18 28,544 ----a-w c:\windows\system32\ReinstallBackups\0024\DriverFiles\rimmptsk.sys
    + 2005-07-22 02:01:00 717,952 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\HSF_CNXT.sys
    + 2005-07-22 02:02:12 1,035,008 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\HSF_DPV.sys
    + 2005-07-22 02:01:08 201,600 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\HSFHWAZL.sys
    + 2005-06-24 02:48:28 577,536 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\HXFSetup.exe
    + 2004-03-17 02:00:32 86,016 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\mdmxsdk.dll
    + 2004-03-17 02:04:14 13,059 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\mdmxsdk.sys
    + 2005-06-20 00:57:20 110,592 ----a-w c:\windows\system32\ReinstallBackups\0025\DriverFiles\uci100.dll
    + 2006-10-19 13:30:48 561,152 ----a-w c:\windows\system32\ReinstallBackups\0026\DriverFiles\NETw3c32.dll
    + 2006-10-19 13:31:16 2,732,032 ----a-w c:\windows\system32\ReinstallBackups\0026\DriverFiles\NETw3r32.dll
    + 2006-10-17 15:55:28 1,711,104 ----a-w c:\windows\system32\ReinstallBackups\0026\DriverFiles\NETw3x32.sys
    - 2004-08-04 11:00:00 60,416 ----a-w c:\windows\system32\remotepg.dll
    + 2008-04-14 00:12:04 60,416 ----a-w c:\windows\system32\remotepg.dll
    - 2007-04-12 18:32:19 387,712 ----a-w c:\windows\system32\Restore\rstrlog.dat
    + 2008-03-20 21:49:33 1,233,028 -c--a-w c:\windows\system32\Restore\rstrlog.dat
    - 2004-08-04 11:00:00 380,416 ----a-w c:\windows\system32\Restore\rstrui.exe
    + 2008-04-14 00:12:33 380,416 ----a-w c:\windows\system32\Restore\rstrui.exe
    - 2004-08-04 10:00:00 58,880 ----a-w c:\windows\system32\resutils.dll
    + 2008-04-14 00:12:04 58,880 ----a-w c:\windows\system32\resutils.dll
    - 2004-08-04 10:00:00 13,824 ----a-w c:\windows\system32\rexec.exe
    + 2008-04-14 00:12:33 13,824 ----a-w c:\windows\system32\rexec.exe
    + 2005-08-30 04:00:00 771,584 ----a-w c:\windows\system32\RGSS100J.dll
    + 2005-08-30 04:00:00 778,752 ----a-w c:\windows\system32\RGSS102E.dll
    + 2005-08-30 04:00:00 781,312 ----a-w c:\windows\system32\RGSS102J.dll
    - 2006-11-13 06:02:58 288,768 ------w c:\windows\system32\rhttpaa.dll
    + 2008-04-14 00:12:04 290,304 ----a-w c:\windows\system32\rhttpaa.dll
    - 2006-11-27 14:54:06 433,152 ----a-w c:\windows\system32\riched20.dll
    + 2008-04-14 00:12:04 433,664 ----a-w c:\windows\system32\riched20.dll
    - 2005-10-14 14:40:18 16,480 ----a-w c:\windows\system32\rixdicon.dll
    + 2005-05-07 00:06:00 16,480 ----a-w c:\windows\system32\rixdicon.dll
    - 2007-07-09 13:16:16 582,656 ----a-w c:\windows\system32\rpcrt4.dll
    + 2008-04-14 00:12:04 584,704 ----a-w c:\windows\system32\rpcrt4.dll
    - 2005-07-26 04:39:49 397,824 ----a-w c:\windows\system32\rpcss.dll
    + 2008-04-14 00:12:04 399,360 ----a-w c:\windows\system32\rpcss.dll
    - 2004-08-04 10:00:00 152,576 ----a-w c:\windows\system32\rsaenh.dll
    + 2008-04-13 17:37:57 208,384 ----a-w c:\windows\system32\rsaenh.dll
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\rsh.exe
    + 2008-04-14 00:12:33 14,848 ----a-w c:\windows\system32\rsh.exe
    - 2004-08-04 10:00:00 39,936 ----a-w c:\windows\system32\rshx32.dll
    + 2008-04-14 00:12:04 39,936 ----a-w c:\windows\system32\rshx32.dll
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\rsmps.dll
    + 2008-04-14 00:12:04 18,944 ----a-w c:\windows\system32\rsmps.dll
    - 2004-08-04 10:00:00 90,112 ----a-w c:\windows\system32\rsvpsp.dll
    + 2008-04-14 00:12:04 92,672 ----a-w c:\windows\system32\rsvpsp.dll
    - 2004-08-04 10:00:00 77,312 ----a-w c:\windows\system32\rtcshare.exe
    + 2008-04-14 00:12:33 77,312 ----a-w c:\windows\system32\rtcshare.exe
    - 2004-08-04 10:00:00 31,744 ----a-w c:\windows\system32\rtipxmib.dll
    + 2008-04-14 00:12:04 31,744 ----a-w c:\windows\system32\rtipxmib.dll
    - 2004-08-04 10:00:00 44,032 ----a-w c:\windows\system32\rtutils.dll
    + 2008-04-14 00:12:04 44,032 ----a-w c:\windows\system32\rtutils.dll
    - 2004-08-04 10:00:00 33,280 ----a-w c:\windows\system32\rundll32.exe
    + 2008-04-14 00:12:33 33,280 ----a-w c:\windows\system32\rundll32.exe
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\runonce.exe
    + 2008-04-14 00:12:33 14,336 ----a-w c:\windows\system32\runonce.exe
    - 2006-07-13 16:51:44 30,938 ----a-w c:\windows\system32\s24NCfg.dll
    + 2007-08-27 16:09:54 14,848 ----a-w c:\windows\system32\s24NCfg.dll
    + 2008-04-14 00:12:04 397,056 ----a-w c:\windows\system32\s3gnb.dll
    - 2004-08-04 11:00:00 43,520 ----a-w c:\windows\system32\safrcdlg.dll
    + 2008-04-14 00:12:04 43,520 ----a-w c:\windows\system32\safrcdlg.dll
    - 2004-08-04 11:00:00 29,696 ----a-w c:\windows\system32\safrdm.dll
    + 2008-04-14 00:12:04 29,696 ----a-w c:\windows\system32\safrdm.dll
    - 2004-08-04 11:00:00 45,568 ----a-w c:\windows\system32\safrslv.dll
    + 2008-04-14 00:12:04 45,568 ----a-w c:\windows\system32\safrslv.dll
    - 2004-08-04 10:00:00 64,000 ----a-w c:\windows\system32\samlib.dll
    + 2008-04-14 00:12:04 64,000 ----a-w c:\windows\system32\samlib.dll
    - 2004-08-04 10:00:00 415,744 ----a-w c:\windows\system32\samsrv.dll
    + 2008-04-14 00:12:04 415,744 ----a-w c:\windows\system32\samsrv.dll
    - 2004-08-04 10:00:00 13,312 ----a-w c:\windows\system32\savedump.exe
    + 2008-04-14 00:12:33 13,312 ----a-w c:\windows\system32\savedump.exe
    - 2004-08-04 10:00:00 270,848 ----a-w c:\windows\system32\sbe.dll
    + 2008-04-14 00:12:04 270,848 ----a-w c:\windows\system32\sbe.dll
    - 2004-08-04 10:00:00 159,232 ----a-w c:\windows\system32\sbeio.dll
    + 2008-04-14 00:12:04 159,232 ----a-w c:\windows\system32\sbeio.dll
    - 2004-08-04 10:00:00 69,632 ----a-w c:\windows\system32\scarddlg.dll
    + 2008-04-14 00:12:04 69,632 ----a-w c:\windows\system32\scarddlg.dll
    - 2004-08-04 10:00:00 95,744 ----a-w c:\windows\system32\scardsvr.exe
    + 2008-04-14 00:12:33 95,744 ----a-w c:\windows\system32\scardsvr.exe
    - 2004-08-04 10:00:00 171,008 ----a-w c:\windows\system32\sccsccp.dll
    + 2008-04-14 00:12:05 171,008 ----a-w c:\windows\system32\sccsccp.dll
    - 2004-08-04 10:00:00 180,224 ----a-w c:\windows\system32\scecli.dll
    + 2008-04-14 00:12:05 181,248 ----a-w c:\windows\system32\scecli.dll
    - 2004-08-04 10:00:00 313,856 ----a-w c:\windows\system32\scesrv.dll
    + 2008-04-14 00:12:05 314,880 ----a-w c:\windows\system32\scesrv.dll
    - 2007-04-25 14:21:15 144,896 ----a-w c:\windows\system32\schannel.dll
    + 2008-04-14 00:12:05 144,384 ----a-w c:\windows\system32\schannel.dll
    - 2004-08-04 11:00:00 190,976 ----a-w c:\windows\system32\schedsvc.dll
    + 2008-04-14 00:12:05 192,512 ----a-w c:\windows\system32\schedsvc.dll
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\sclgntfy.dll
    + 2008-04-14 00:12:05 20,480 ----a-w c:\windows\system32\sclgntfy.dll
    - 2004-08-04 10:00:00 9,216 ----a-w c:\windows\system32\scrnsave.scr
    + 2008-04-14 00:12:43 9,216 ----a-w c:\windows\system32\scrnsave.scr
    - 2004-08-04 10:00:00 159,744 ----a-w c:\windows\system32\scrobj.dll
    + 2008-05-09 10:53:39 180,224 ----a-w c:\windows\system32\scrobj.dll
    - 2004-08-04 10:00:00 151,552 ----a-w c:\windows\system32\scrrun.dll
    + 2008-05-09 10:53:40 172,032 ----a-w c:\windows\system32\scrrun.dll
    - 2004-08-04 10:00:00 77,312 ----a-w c:\windows\system32\sdbinst.exe
    + 2008-04-14 00:12:34 77,312 ----a-w c:\windows\system32\sdbinst.exe
    - 2004-08-04 10:00:00 29,184 ----a-w c:\windows\system32\sdhcinst.dll
    + 2008-04-14 00:12:05 29,184 ----a-w c:\windows\system32\sdhcinst.dll
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\seclogon.dll
    + 2008-04-14 00:12:05 18,944 ----a-w c:\windows\system32\seclogon.dll
    - 2004-08-04 10:00:00 55,808 ----a-w c:\windows\system32\secur32.dll
    + 2008-04-14 00:12:05 56,320 ----a-w c:\windows\system32\secur32.dll
    - 2004-08-04 10:00:00 5,632 ----a-w c:\windows\system32\security.dll
    + 2008-04-14 00:12:05 5,632 ----a-w c:\windows\system32\security.dll
    - 2004-08-04 10:00:00 29,184 ----a-w c:\windows\system32\sendcmsg.dll
    + 2008-04-14 00:12:05 29,184 ----a-w c:\windows\system32\sendcmsg.dll
    - 2004-08-04 10:00:00 55,296 ----a-w c:\windows\system32\sendmail.dll
    + 2008-04-14 00:12:05 54,784 ----a-w c:\windows\system32\sendmail.dll
    - 2004-08-04 10:00:00 38,912 ----a-w c:\windows\system32\sens.dll
    + 2008-04-14 00:12:05 39,424 ----a-w c:\windows\system32\sens.dll
    - 2004-08-04 10:00:00 6,656 ----a-w c:\windows\system32\sensapi.dll
    + 2008-04-14 00:12:05 7,168 ----a-w c:\windows\system32\sensapi.dll
    - 2004-08-04 11:00:00 56,320 ----a-w c:\windows\system32\servdeps.dll
    + 2008-04-14 00:12:05 56,320 ----a-w c:\windows\system32\servdeps.dll
    - 2004-08-04 10:00:00 108,032 ----a-w c:\windows\system32\services.exe
    + 2008-04-14 00:12:34 108,544 ----a-w c:\windows\system32\services.exe
    - 2004-08-04 11:00:00 140,800 ----a-w c:\windows\system32\sessmgr.exe
    + 2008-04-14 00:12:34 141,312 ----a-w c:\windows\system32\sessmgr.exe
    - 2004-08-04 10:00:00 31,232 ----a-w c:\windows\system32\sethc.exe
    + 2008-04-14 00:12:34 31,232 ----a-w c:\windows\system32\sethc.exe
    - 2004-08-04 10:00:00 23,040 ----a-w c:\windows\system32\setup.exe
    + 2008-04-14 00:12:34 23,040 ----a-w c:\windows\system32\setup.exe
    - 2004-08-04 10:00:00 259,584 ----a-w c:\windows\system32\Setup\comsetup.dll
    + 2008-04-14 00:11:51 274,944 ----a-w c:\windows\system32\Setup\comsetup.dll
    - 2004-08-04 10:00:00 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll
    + 2008-04-14 00:11:53 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll
    - 2004-08-04 10:00:00 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll
    + 2008-04-14 00:11:54 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll
    - 2004-08-04 10:00:00 505,344 ------w c:\windows\system32\Setup\iis.dll
    + 2008-04-14 00:11:54 505,344 ----a-w c:\windows\system32\Setup\iis.dll
    - 2004-08-04 10:00:00 115,712 ----a-w c:\windows\system32\Setup\imsinsnt.dll
    + 2008-04-14 00:11:54 123,392 ----a-w c:\windows\system32\Setup\imsinsnt.dll
    + 2008-04-14 00:11:56 8,192 ----a-w c:\windows\system32\Setup\koc.dll
    - 2004-08-04 10:00:00 82,432 ----a-w c:\windows\system32\Setup\msdtcstp.dll
    + 2008-04-14 00:11:59 90,112 ----a-w c:\windows\system32\Setup\msdtcstp.dll
    - 2004-08-04 10:00:00 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll
    + 2008-04-14 00:11:59 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll
    - 2004-08-04 10:00:00 77,312 ----a-w c:\windows\system32\Setup\netoc.dll
    + 2008-04-14 00:12:01 77,312 ----a-w c:\windows\system32\Setup\netoc.dll
    - 2004-08-04 10:00:00 62,976 ----a-w c:\windows\system32\Setup\ntoc.dll
    + 2008-04-14 00:12:02 62,976 ----a-w c:\windows\system32\Setup\ntoc.dll
    - 2004-08-04 10:00:00 15,872 ----a-w c:\windows\system32\Setup\ocgen.dll
    + 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\Setup\ocgen.dll
    - 2004-08-04 10:00:00 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll
    + 2008-04-14 00:12:02 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll
    - 2004-08-04 10:00:00 101,376 ----a-w c:\windows\system32\Setup\setupqry.dll
    + 2008-04-14 00:12:05 101,376 ----a-w c:\windows\system32\Setup\setupqry.dll
    - 2004-08-04 10:00:00 22,016 ----a-w c:\windows\system32\Setup\startoc.dll
    + 2008-04-14 00:12:07 26,624 -c--a-w c:\windows\system32\Setup\startoc.dll
    - 2004-08-04 10:00:00 121,856 ----a-w c:\windows\system32\Setup\tsoc.dll
    + 2008-04-14 00:12:07 130,048 ----a-w c:\windows\system32\Setup\tsoc.dll
    - 2004-08-04 10:00:00 983,552 ----a-w c:\windows\system32\setupapi.dll
    + 2008-04-14 09:42:06 985,088 ----a-w c:\windows\system32\setupapi.dll
    + 2008-04-14 00:12:35 32,768 ----a-w c:\windows\system32\setupn.exe
    - 2004-08-04 10:00:00 5,120 ----a-w c:\windows\system32\sfc.dll
    + 2008-04-14 00:12:05 5,120 ----a-w c:\windows\system32\sfc.dll
    - 2004-08-04 10:00:00 140,288 ----a-w c:\windows\system32\sfc_os.dll
    + 2008-04-14 00:12:05 140,288 ----a-w c:\windows\system32\sfc_os.dll
    - 2004-08-04 10:00:00 1,580,544 ----a-w c:\windows\system32\sfcfiles.dll
    + 2008-04-14 00:12:05 1,614,848 ----a-w c:\windows\system32\sfcfiles.dll
    - 2004-08-04 10:00:00 549,376 ----a-w c:\windows\system32\shdoclc.dll
    + 2008-04-13 17:03:19 549,376 ----a-w c:\windows\system32\shdoclc.dll
    - 2007-02-20 09:48:13 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
    + 2008-04-14 00:12:05 1,499,136 ----a-w c:\windows\system32\shdocvw.dll
    - 2006-12-19 21:52:18 8,453,632 ----a-w c:\windows\system32\shell32.dll
    + 2008-04-14 00:12:05 8,461,312 ----a-w c:\windows\system32\shell32.dll
    - 2004-08-04 10:00:00 25,088 ----a-w c:\windows\system32\shfolder.dll
    + 2008-04-14 00:12:05 25,088 ----a-w c:\windows\system32\shfolder.dll
    - 2004-08-04 10:00:00 68,096 ----a-w c:\windows\system32\shgina.dll
    + 2008-04-14 00:12:05 68,096 ----a-w c:\windows\system32\shgina.dll
    - 2004-08-04 10:00:00 65,536 ----a-w c:\windows\system32\shimeng.dll
    + 2008-04-14 00:12:05 65,024 ----a-w c:\windows\system32\shimeng.dll
    - 2004-08-04 10:00:00 438,272 ----a-w c:\windows\system32\shimgvw.dll
    + 2008-04-14 00:12:05 438,272 ----a-w c:\windows\system32\shimgvw.dll
    - 2007-02-20 09:48:15 474,112 ----a-w c:\windows\system32\shlwapi.dll
    + 2008-04-14 00:12:05 474,112 ----a-w c:\windows\system32\shlwapi.dll
    - 2004-08-04 10:00:00 151,552 ----a-w c:\windows\system32\shmedia.dll
    + 2008-04-14 00:12:05 152,064 ----a-w c:\windows\system32\shmedia.dll
    - 2004-08-04 10:00:00 42,496 ----a-w c:\windows\system32\shmgrate.exe
    + 2008-04-14 00:12:35 45,056 ----a-w c:\windows\system32\shmgrate.exe
    - 2004-08-04 10:00:00 77,824 ----a-w c:\windows\system32\shrpubw.exe
    + 2008-04-14 00:12:35 77,824 ----a-w c:\windows\system32\shrpubw.exe
    - 2004-08-04 10:00:00 27,648 ----a-w c:\windows\system32\shscrap.dll
    + 2008-04-14 00:12:05 27,648 ----a-w c:\windows\system32\shscrap.dll
    - 2006-12-19 21:52:18 134,656 ----a-w c:\windows\system32\shsvcs.dll
    + 2008-04-14 00:12:05 135,168 ----a-w c:\windows\system32\shsvcs.dll
    - 2004-08-04 10:00:00 19,456 ----a-w c:\windows\system32\shutdown.exe
    + 2008-04-14 00:12:35 19,456 ----a-w c:\windows\system32\shutdown.exe
    - 2004-08-04 10:00:00 13,312 ----a-w c:\windows\system32\sigtab.dll
    + 2008-04-14 00:12:05 13,312 ----a-w c:\windows\system32\sigtab.dll
    - 2004-08-04 10:00:00 70,144 ----a-w c:\windows\system32\sigverif.exe
    + 2008-04-14 00:12:35 70,144 ----a-w c:\windows\system32\sigverif.exe
    - 2004-08-04 10:00:00 26,112 ----a-w c:\windows\system32\skeys.exe
    + 2008-04-14 00:12:35 26,112 ----a-w c:\windows\system32\skeys.exe
    - 2004-08-04 10:00:00 25,088 ----a-w c:\windows\system32\slayerxp.dll
    + 2008-04-14 00:12:06 25,088 ----a-w c:\windows\system32\slayerxp.dll
    - 2004-08-04 10:00:00 98,304 ----a-w c:\windows\system32\slbiop.dll
    + 2008-04-14 00:12:06 98,304 ----a-w c:\windows\system32\slbiop.dll
    + 2008-04-14 00:12:06 73,832 ----a-w c:\windows\system32\slcoinst.dll
    + 2008-04-14 00:12:06 286,792 ----a-w c:\windows\system32\slextspk.dll
    + 2008-04-14 00:12:06 188,508 ----a-w c:\windows\system32\slgen.dll
    + 2008-04-14 00:12:35 32,866 ----a-w c:\windows\system32\slrundll.exe
    + 2008-04-14 00:12:35 73,796 ----a-w c:\windows\system32\slserv.exe
    - 2004-08-04 10:00:00 8,192 ----a-w c:\windows\system32\smbinst.exe
    + 2008-04-14 00:12:35 8,192 ----a-w c:\windows\system32\smbinst.exe
    - 2004-08-04 10:00:00 363,008 ----a-w c:\windows\system32\smlogcfg.dll
    + 2008-04-14 00:12:06 362,496 ----a-w c:\windows\system32\smlogcfg.dll
    - 2004-08-04 10:00:00 89,600 ----a-w c:\windows\system32\smlogsvc.exe
    + 2008-04-14 00:12:35 89,600 ----a-w c:\windows\system32\smlogsvc.exe
    - 2004-08-04 10:00:00 50,688 ----a-w c:\windows\system32\smss.exe
    + 2008-04-14 00:12:36 50,688 ----a-w c:\windows\system32\smss.exe
    - 2006-07-13 16:51:44 53,248 ----a-w c:\windows\system32\SMSUnins.dll
    + 2006-08-29 18:59:32 53,248 ----a-w c:\windows\system32\SMSUnins.dll
    - 2004-08-04 11:00:00 131,584 ----a-w c:\windows\system32\sndrec32.exe
    + 2008-04-14 00:12:36 131,584 ----a-w c:\windows\system32\sndrec32.exe
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\snmpapi.dll
    + 2008-04-14 00:12:06 18,944 ----a-w c:\windows\system32\snmpapi.dll
    - 2004-08-04 10:00:00 182,272 ----a-w c:\windows\system32\snmpsnap.dll
    + 2008-04-14 00:12:06 182,272 ----a-w c:\windows\system32\snmpsnap.dll
    - 2005-10-14 14:40:18 90,112 ----a-w c:\windows\system32\snymsico.dll
    + 2004-09-03 15:00:00 90,112 ----a-w c:\windows\system32\snymsico.dll
    + 2008-07-19 02:10:20 36,552 -c--a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
    + 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
    + 2008-07-19 02:10:40 45,768 -c--a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
    + 2008-10-16 19:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
    - 2004-08-04 10:00:00 23,552 ----a-w c:\windows\system32\sort.exe
    + 2008-04-14 00:12:36 24,576 ----a-w c:\windows\system32\sort.exe
    + 2004-08-04 10:00:00 1,744 ----a-w c:\windows\system32\sound.drv
    + 2008-04-14 00:12:36 7,680 ----a-w c:\windows\system32\spdwnwxp.exe
    - 2004-08-04 11:00:00 538,624 ----a-w c:\windows\system32\spider.exe
    + 2008-04-14 00:12:36 538,624 ----a-w c:\windows\system32\spider.exe
    - 2006-10-16 20:10:58 14,640 ------w c:\windows\system32\spmsg.dll
    + 2008-07-08 13:02:01 17,272 ----a-w c:\windows\system32\spmsg.dll
    - 2004-08-04 10:00:00 11,776 ----a-w c:\windows\system32\spnpinst.exe
    + 2008-04-14 09:42:38 11,264 ----a-w c:\windows\system32\spnpinst.exe

  6. #26
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    - 2004-08-04 11:00:00 452,096 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSAPI.DLL
    + 2008-04-14 00:11:53 451,584 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxsapi.dll
    - 2004-08-04 11:00:00 27,136 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSDRV.DLL
    + 2008-04-14 00:11:54 26,624 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxsdrv.dll
    - 2004-08-04 11:00:00 6,656 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSRES.DLL
    + 2008-04-14 00:09:33 6,656 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxsres.dll
    - 2004-08-04 11:00:00 397,312 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSTIFF.DLL
    + 2008-04-14 00:11:54 397,312 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxstiff.dll
    - 2004-08-04 11:00:00 154,112 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSUI.DLL
    + 2008-04-14 00:11:54 154,112 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxsui.dll
    - 2004-08-04 11:00:00 192,512 ----a-w c:\windows\system32\spool\drivers\w32x86\3\FXSWZRD.DLL
    + 2008-04-14 00:11:54 192,512 ----a-w c:\windows\system32\spool\drivers\w32x86\3\fxswzrd.dll
    - 2004-08-04 04:56:44 87,552 ----a-w c:\windows\system32\spool\drivers\w32x86\3\HPFUD50.DLL
    + 2008-04-14 00:11:54 87,552 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpfud50.dll
    - 2007-03-23 00:24:06 376,832 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
    + 2008-04-14 00:12:07 373,248 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
    - 2007-03-23 01:03:54 749,568 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
    + 2008-04-14 00:12:07 744,448 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
    - 2004-08-04 10:00:00 74,752 ----a-w c:\windows\system32\spoolss.dll
    + 2008-04-14 00:12:06 75,264 ----a-w c:\windows\system32\spoolss.dll
    - 2005-06-10 23:53:32 57,856 ----a-w c:\windows\system32\spoolsv.exe
    + 2008-04-14 00:12:36 57,856 ----a-w c:\windows\system32\spoolsv.exe
    - 2006-10-16 20:10:58 23,856 ----a-w c:\windows\system32\spupdsvc.exe
    + 2007-08-11 00:46:18 26,488 ----a-w c:\windows\system32\spupdsvc.exe
    + 2008-04-14 00:12:36 20,992 ----a-w c:\windows\system32\spupdwxp.exe
    - 2004-08-04 10:00:00 442,368 ----a-w c:\windows\system32\sqlsrv32.dll
    + 2008-04-14 00:12:06 442,368 ----a-w c:\windows\system32\sqlsrv32.dll
    - 2004-08-04 10:00:00 180,800 ----a-w c:\windows\system32\sqlunirl.dll
    + 2008-04-14 00:12:06 180,800 ----a-w c:\windows\system32\sqlunirl.dll
    - 2004-08-04 11:00:00 67,584 ----a-w c:\windows\system32\srclient.dll
    + 2008-04-14 00:12:07 67,584 ----a-w c:\windows\system32\srclient.dll
    - 2004-08-04 11:00:00 239,104 ----a-w c:\windows\system32\srrstr.dll
    + 2008-04-14 00:12:07 239,104 ----a-w c:\windows\system32\srrstr.dll
    - 2004-08-04 11:00:00 170,496 ----a-w c:\windows\system32\srsvc.dll
    + 2008-04-14 00:12:07 171,008 ----a-w c:\windows\system32\srsvc.dll
    - 2004-12-07 19:32:34 96,768 ----a-w c:\windows\system32\srvsvc.dll
    + 2008-04-14 00:12:07 96,768 ----a-w c:\windows\system32\srvsvc.dll
    - 2004-08-04 10:00:00 704,512 ----a-w c:\windows\system32\ss3dfo.scr
    + 2008-04-14 00:12:43 704,512 ----a-w c:\windows\system32\ss3dfo.scr
    - 2004-08-04 10:00:00 19,968 ----a-w c:\windows\system32\ssbezier.scr
    + 2008-04-14 00:12:43 19,968 ----a-w c:\windows\system32\ssbezier.scr
    - 2004-08-04 10:00:00 34,816 ----a-w c:\windows\system32\ssdpapi.dll
    + 2008-04-14 00:12:07 34,816 ----a-w c:\windows\system32\ssdpapi.dll
    - 2004-08-04 10:00:00 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
    + 2008-04-14 00:12:07 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
    - 2004-08-04 10:00:00 393,216 ----a-w c:\windows\system32\ssflwbox.scr
    + 2008-04-14 00:12:43 393,216 ----a-w c:\windows\system32\ssflwbox.scr
    - 2004-08-04 10:00:00 20,992 ----a-w c:\windows\system32\ssmarque.scr
    + 2008-04-14 00:12:44 20,992 ----a-w c:\windows\system32\ssmarque.scr
    - 2004-08-04 10:00:00 47,104 ----a-w c:\windows\system32\ssmypics.scr
    + 2008-04-14 00:12:44 47,104 ----a-w c:\windows\system32\ssmypics.scr
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\ssmyst.scr
    + 2008-04-14 00:12:44 18,944 ----a-w c:\windows\system32\ssmyst.scr
    - 2004-08-04 10:00:00 610,304 ----a-w c:\windows\system32\sspipes.scr
    + 2008-04-14 00:12:44 610,304 ----a-w c:\windows\system32\sspipes.scr
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\ssstars.scr
    + 2008-04-14 00:12:44 14,336 ----a-w c:\windows\system32\ssstars.scr
    - 2004-08-04 10:00:00 679,936 ----a-w c:\windows\system32\sstext3d.scr
    + 2008-04-14 00:12:44 679,936 ----a-w c:\windows\system32\sstext3d.scr
    + 2007-08-21 14:58:12 146,944 ----a-w c:\windows\system32\st325602.dll
    - 2006-03-24 22:31:50 208,896 ----a-w c:\windows\system32\stacapi.dll
    + 2007-05-10 15:23:02 270,336 ----a-w c:\windows\system32\stacapi.dll
    - 2004-08-04 11:00:00 54,272 ----a-w c:\windows\system32\stclient.dll
    + 2008-04-14 00:12:07 59,392 ----a-w c:\windows\system32\stclient.dll
    - 2004-08-04 10:00:00 67,584 ----a-w c:\windows\system32\sti.dll
    + 2008-04-14 00:12:07 68,096 ----a-w c:\windows\system32\sti.dll
    - 2004-08-04 10:00:00 136,704 ----a-w c:\windows\system32\sti_ci.dll
    + 2008-04-14 00:12:07 136,704 ----a-w c:\windows\system32\sti_ci.dll
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\stimon.exe
    + 2008-04-14 00:12:36 14,848 ----a-w c:\windows\system32\stimon.exe
    - 2006-03-22 22:52:58 1,052,672 ----a-w c:\windows\system32\stlang.dll
    + 2007-04-10 22:02:00 1,601,536 ----a-w c:\windows\system32\stlang.dll
    - 2004-08-04 10:00:00 121,856 ----a-w c:\windows\system32\stobject.dll
    + 2008-04-14 00:12:07 121,856 ----a-w c:\windows\system32\stobject.dll
    - 2004-08-04 06:56:46 74,752 ----a-w c:\windows\system32\storprop.dll
    + 2008-04-14 00:12:07 74,752 ----a-w c:\windows\system32\storprop.dll
    - 2006-08-21 13:52:08 246,814 ----a-w c:\windows\system32\strmdll.dll
    + 2008-04-14 00:12:07 246,814 ----a-w c:\windows\system32\strmdll.dll
    - 2004-08-04 10:00:00 75,776 ----a-w c:\windows\system32\strmfilt.dll
    + 2008-04-14 00:12:07 75,776 ----a-w c:\windows\system32\strmfilt.dll
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\svchost.exe
    + 2008-04-14 00:12:36 14,336 ----a-w c:\windows\system32\svchost.exe
    - 2006-10-19 13:56:32 713,216 ----a-w c:\windows\system32\sxs.dll
    + 2008-04-14 00:12:07 713,216 ----a-w c:\windows\system32\sxs.dll
    - 2004-08-04 10:00:00 57,856 ----a-w c:\windows\system32\synceng.dll
    + 2008-04-14 00:12:07 57,856 ----a-w c:\windows\system32\synceng.dll
    - 2004-08-04 10:00:00 191,488 ----a-w c:\windows\system32\syncui.dll
    + 2008-04-14 00:12:07 191,488 ----a-w c:\windows\system32\syncui.dll
    - 2004-08-04 10:00:00 105,984 ----a-w c:\windows\system32\sysocmgr.exe
    + 2008-04-14 00:12:37 106,496 ----a-w c:\windows\system32\sysocmgr.exe
    - 2004-08-04 10:00:00 984,576 ----a-w c:\windows\system32\syssetup.dll
    + 2008-04-14 00:12:07 990,208 ----a-w c:\windows\system32\syssetup.dll
    + 2004-08-04 10:00:00 3,360 ----a-w c:\windows\system32\system.drv
    - 2005-10-17 21:14:46 118,272 ----a-w c:\windows\system32\t2embed.dll
    + 2008-04-14 00:12:07 117,760 ----a-w c:\windows\system32\t2embed.dll
    - 2004-08-04 10:00:00 858,624 ----a-w c:\windows\system32\tapi3.dll
    + 2008-04-14 00:12:07 858,624 ----a-w c:\windows\system32\tapi3.dll
    - 2004-08-04 10:00:00 181,760 ----a-w c:\windows\system32\tapi32.dll
    + 2008-04-14 00:12:07 181,760 ----a-w c:\windows\system32\tapi32.dll
    - 2005-07-08 16:27:56 249,344 ----a-w c:\windows\system32\tapisrv.dll
    + 2008-04-14 00:12:07 249,856 ----a-w c:\windows\system32\tapisrv.dll
    - 2004-08-04 10:00:00 135,680 ----a-w c:\windows\system32\taskmgr.exe
    + 2008-04-14 00:12:37 135,680 ----a-w c:\windows\system32\taskmgr.exe
    - 2004-08-04 10:00:00 14,848 ----a-w c:\windows\system32\tcpmib.dll
    + 2008-04-14 00:12:07 14,848 ----a-w c:\windows\system32\tcpmib.dll
    - 2004-08-04 10:00:00 45,568 ----a-w c:\windows\system32\tcpmon.dll
    + 2008-04-14 00:12:07 45,568 ----a-w c:\windows\system32\tcpmon.dll
    - 2004-08-04 10:00:00 45,568 ----a-w c:\windows\system32\tcpmonui.dll
    + 2008-04-14 00:12:07 45,568 ----a-w c:\windows\system32\tcpmonui.dll
    - 2005-05-10 23:45:48 75,776 ----a-w c:\windows\system32\telnet.exe
    + 2008-04-14 00:12:37 75,776 ----a-w c:\windows\system32\telnet.exe
    - 2004-08-04 10:00:00 358,400 ----a-w c:\windows\system32\termmgr.dll
    + 2008-04-14 00:12:07 358,400 ----a-w c:\windows\system32\termmgr.dll
    - 2004-08-04 11:00:00 295,424 ----a-w c:\windows\system32\termsrv.dll
    + 2008-04-14 00:12:07 295,424 ----a-w c:\windows\system32\termsrv.dll
    - 2004-08-04 10:00:00 385,536 ----a-w c:\windows\system32\themeui.dll
    + 2008-04-14 00:12:07 385,536 ----a-w c:\windows\system32\themeui.dll
    + 2004-08-04 10:00:00 4,048 ----a-w c:\windows\system32\timer.drv
    - 2004-08-04 10:00:00 347,136 ----a-w c:\windows\system32\tourstart.exe
    + 2008-04-14 00:12:38 347,136 ----a-w c:\windows\system32\tourstart.exe
    - 2004-08-04 10:00:00 12,288 ----a-w c:\windows\system32\tracert.exe
    + 2008-04-14 00:12:38 12,288 ----a-w c:\windows\system32\tracert.exe
    - 2004-08-04 10:00:00 11,264 ----a-w c:\windows\system32\tree.com
    + 2008-04-14 00:12:42 12,800 ----a-w c:\windows\system32\tree.com
    - 2004-08-04 10:00:00 90,624 ----a-w c:\windows\system32\trkwks.dll
    + 2008-04-14 00:12:07 90,112 ----a-w c:\windows\system32\trkwks.dll
    - 2004-08-04 11:00:00 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
    + 2008-04-14 00:12:07 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
    - 2004-08-04 10:00:00 12,168 ----a-w c:\windows\system32\tsddd.dll
    + 2008-04-14 00:13:21 12,168 ----a-w c:\windows\system32\tsddd.dll
    - 2006-11-13 06:02:58 36,352 ------w c:\windows\system32\tsgqec.dll
    + 2008-04-14 00:12:07 53,248 ----a-w c:\windows\system32\tsgqec.dll
    + 2008-04-14 00:12:07 50,688 ----a-w c:\windows\system32\tspkg.dll
    + 2007-10-09 17:58:20 16,896 ----a-w c:\windows\system32\tswpfwrp.exe
    - 2004-08-04 10:00:00 44,032 ----a-w c:\windows\system32\twext.dll
    + 2008-04-14 00:12:07 57,856 ----a-w c:\windows\system32\twext.dll
    - 2005-07-26 04:39:49 101,376 ----a-w c:\windows\system32\txflog.dll
    + 2008-04-14 00:12:07 101,376 ----a-w c:\windows\system32\txflog.dll
    - 2007-07-18 12:42:22 60,416 ----a-w c:\windows\system32\tzchange.exe
    + 2008-04-14 00:12:38 60,416 ----a-w c:\windows\system32\tzchange.exe
    + 2005-11-16 04:41:26 114,688 ----a-w c:\windows\system32\Uci32103.dll
    - 2004-08-04 10:00:00 25,600 ----a-w c:\windows\system32\udhisapi.dll
    + 2008-04-14 00:12:07 26,624 ----a-w c:\windows\system32\udhisapi.dll
    - 2006-10-21 01:29:54 159,008 ----a-w c:\windows\system32\UIAutomationCore.dll
    + 2007-10-09 18:03:08 161,304 ----a-w c:\windows\system32\UIAutomationCore.dll
    - 2004-08-04 10:00:00 275,456 ----a-w c:\windows\system32\ulib.dll
    + 2008-04-14 00:12:07 275,456 ----a-w c:\windows\system32\ulib.dll
    - 2006-10-04 13:33:38 35,840 ----a-w c:\windows\system32\umandlg.dll
    + 2008-04-14 00:12:07 35,840 ----a-w c:\windows\system32\umandlg.dll
    - 2005-08-23 03:35:42 123,392 ----a-w c:\windows\system32\umpnpmgr.dll
    + 2008-04-14 00:12:07 123,392 ----a-w c:\windows\system32\umpnpmgr.dll
    - 2004-08-04 10:00:00 74,240 ----a-w c:\windows\system32\unimdmat.dll
    + 2008-04-14 00:12:07 74,240 ----a-w c:\windows\system32\unimdmat.dll
    - 2004-08-04 10:00:00 13,824 ----a-w c:\windows\system32\uniplat.dll
    + 2008-04-14 00:12:07 13,824 ----a-w c:\windows\system32\uniplat.dll
    - 2004-08-04 10:00:00 316,416 ----a-w c:\windows\system32\untfs.dll
    + 2008-04-14 00:12:07 316,416 ----a-w c:\windows\system32\untfs.dll
    - 2004-08-04 10:00:00 132,608 ----a-w c:\windows\system32\upnp.dll
    + 2008-04-14 00:12:08 133,632 ----a-w c:\windows\system32\upnp.dll
    - 2004-08-04 10:00:00 16,896 ----a-w c:\windows\system32\upnpcont.exe
    + 2008-04-14 00:12:38 16,896 ----a-w c:\windows\system32\upnpcont.exe
    - 2007-02-05 20:17:02 185,344 ----a-w c:\windows\system32\upnphost.dll
    + 2008-04-14 00:12:08 185,856 ----a-w c:\windows\system32\upnphost.dll
    - 2004-08-04 10:00:00 239,616 ----a-w c:\windows\system32\upnpui.dll
    + 2008-04-14 00:12:08 239,616 ----a-w c:\windows\system32\upnpui.dll
    - 2004-08-04 10:00:00 18,432 ----a-w c:\windows\system32\ups.exe
    + 2008-04-14 00:12:38 18,432 ----a-w c:\windows\system32\ups.exe
    + 2007-08-13 22:44:30 105,984 ----a-w c:\windows\system32\url(2)(2).dll
    - 2007-08-20 10:04:42 105,984 ----a-w c:\windows\system32\url.dll
    + 2008-08-26 07:24:30 105,984 ----a-w c:\windows\system32\url.dll
    + 2007-08-13 22:54:10 1,162,240 ----a-w c:\windows\system32\urlmon(2)(2).dll
    - 2007-08-20 10:04:42 1,152,000 ----a-w c:\windows\system32\urlmon.dll
    + 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\system32\urlmon.dll
    - 2004-08-04 10:00:00 16,896 ----a-w c:\windows\system32\usbmon.dll
    + 2008-04-14 00:12:08 16,896 ----a-w c:\windows\system32\usbmon.dll
    - 2004-08-04 10:00:00 74,240 ----a-w c:\windows\system32\usbui.dll
    + 2008-04-14 00:12:08 74,240 ----a-w c:\windows\system32\usbui.dll
    - 2007-03-08 15:36:28 577,536 ----a-w c:\windows\system32\user32.dll
    + 2008-04-14 00:12:08 578,560 ----a-w c:\windows\system32\user32.dll
    - 2004-08-04 10:00:00 723,456 ----a-w c:\windows\system32\userenv.dll
    + 2008-04-14 00:12:08 727,040 ----a-w c:\windows\system32\userenv.dll
    - 2004-08-04 10:00:00 24,576 ----a-w c:\windows\system32\userinit.exe
    + 2008-04-14 00:12:38 26,112 ----a-w c:\windows\system32\userinit.exe
    - 2005-04-27 23:15:36 17,920 ------w c:\windows\system32\usmt\cobramsg.dll
    + 2008-04-13 16:44:16 17,920 -c--a-w c:\windows\system32\usmt\cobramsg.dll
    - 2005-04-28 19:16:29 133,120 ----a-w c:\windows\system32\usmt\guitrn.dll
    + 2008-04-14 00:11:54 133,120 -c--a-w c:\windows\system32\usmt\guitrn.dll
    - 2005-04-28 19:16:29 115,200 ------w c:\windows\system32\usmt\guitrna.dll
    + 2008-04-14 00:11:54 115,200 -c--a-w c:\windows\system32\usmt\guitrna.dll
    + 2008-04-13 16:44:29 2,560 -c--a-w c:\windows\system32\usmt\iconlib.dll
    - 2005-04-28 19:16:29 19,968 ----a-w c:\windows\system32\usmt\log.dll
    + 2008-04-14 00:11:56 19,968 -c--a-w c:\windows\system32\usmt\log.dll
    - 2005-04-28 19:16:29 274,432 ----a-w c:\windows\system32\usmt\migism.dll
    + 2008-04-14 00:11:57 274,432 -c--a-w c:\windows\system32\usmt\migism.dll
    - 2005-04-28 16:16:30 261,120 ------w c:\windows\system32\usmt\migisma.dll
    + 2008-04-14 00:11:57 261,120 -c--a-w c:\windows\system32\usmt\migisma.dll
    - 2005-04-28 00:12:58 103,424 ----a-w c:\windows\system32\usmt\migload.exe
    + 2008-04-14 00:12:25 103,936 -c--a-w c:\windows\system32\usmt\migload.exe
    - 2005-04-28 00:12:57 245,248 ----a-w c:\windows\system32\usmt\migwiz.exe
    + 2008-04-14 00:12:25 245,248 ----a-w c:\windows\system32\usmt\migwiz.exe
    - 2005-04-28 00:12:57 241,152 ------w c:\windows\system32\usmt\migwiza.exe
    + 2008-04-14 00:12:25 241,152 -c--a-w c:\windows\system32\usmt\migwiza.exe
    - 2005-04-28 19:16:29 215,552 ----a-w c:\windows\system32\usmt\script.dll
    + 2008-04-14 00:12:05 215,552 -c--a-w c:\windows\system32\usmt\script.dll
    - 2005-04-28 19:16:29 199,680 ------w c:\windows\system32\usmt\scripta.dll
    + 2008-04-14 00:12:05 199,680 -c--a-w c:\windows\system32\usmt\scripta.dll
    - 2005-04-28 19:16:29 193,024 ----a-w c:\windows\system32\usmt\sysmod.dll
    + 2008-04-14 00:12:07 193,024 -c--a-w c:\windows\system32\usmt\sysmod.dll
    - 2005-04-28 19:16:29 173,568 ------w c:\windows\system32\usmt\sysmoda.dll
    + 2008-04-14 00:12:07 173,568 -c--a-w c:\windows\system32\usmt\sysmoda.dll
    - 2004-08-04 10:00:00 406,528 ----a-w c:\windows\system32\usp10.dll
    + 2008-04-14 00:12:08 406,016 ----a-w c:\windows\system32\usp10.dll
    - 2006-10-04 08:48:37 50,176 ----a-w c:\windows\system32\utilman.exe
    + 2008-04-14 00:12:38 50,176 ----a-w c:\windows\system32\utilman.exe
    - 2004-08-04 10:00:00 218,624 ----a-w c:\windows\system32\uxtheme.dll
    + 2008-04-14 00:12:08 218,624 ----a-w c:\windows\system32\uxtheme.dll
    + 2000-07-15 03:00:00 101,888 -c--a-w c:\windows\system32\VB6STKIT.DLL
    - 2004-08-04 10:00:00 30,749 ----a-w c:\windows\system32\vbajet32.dll
    + 2008-04-14 00:12:08 30,749 ----a-w c:\windows\system32\vbajet32.dll
    - 2006-11-08 01:03:36 413,696 ----a-w c:\windows\system32\vbscript.dll
    + 2008-05-09 10:53:40 430,080 ----a-w c:\windows\system32\vbscript.dll
    - 2004-08-04 10:00:00 26,112 ----a-w c:\windows\system32\vdmdbg.dll
    + 2008-04-14 00:12:08 26,112 ----a-w c:\windows\system32\vdmdbg.dll
    - 2004-08-04 10:00:00 51,712 ----a-w c:\windows\system32\vdmredir.dll
    + 2008-04-14 00:12:08 51,712 ----a-w c:\windows\system32\vdmredir.dll
    - 2006-03-17 00:38:01 28,672 ----a-w c:\windows\system32\verclsid.exe
    + 2008-04-14 00:12:38 28,672 ----a-w c:\windows\system32\verclsid.exe
    - 2004-08-04 10:00:00 13,312 ----a-w c:\windows\system32\verifier.dll
    + 2008-04-14 00:12:08 26,624 ----a-w c:\windows\system32\verifier.dll
    - 2004-08-04 10:00:00 18,944 ----a-w c:\windows\system32\version.dll
    + 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\version.dll
    + 2008-04-14 00:12:08 53,760 ----a-w c:\windows\system32\vfwwdm32.dll
    + 2004-08-04 10:00:00 2,176 ----a-w c:\windows\system32\vga.drv
    - 2004-08-04 10:00:00 430,592 ----a-w c:\windows\system32\vssapi.dll
    + 2008-04-14 00:12:08 430,592 ----a-w c:\windows\system32\vssapi.dll
    - 2004-08-04 10:00:00 289,792 ----a-w c:\windows\system32\vssvc.exe
    + 2008-04-14 00:12:38 289,792 ----a-w c:\windows\system32\vssvc.exe
    - 2004-08-04 10:00:00 174,592 ----a-w c:\windows\system32\w32time.dll
    + 2008-04-14 00:12:08 175,104 ----a-w c:\windows\system32\w32time.dll
    - 2004-08-04 10:00:00 15,872 ----a-w c:\windows\system32\w3ssl.dll
    + 2008-04-14 00:12:08 15,872 ----a-w c:\windows\system32\w3ssl.dll
    - 2004-08-04 10:00:00 17,664 ----a-w c:\windows\system32\watchdog.sys
    + 2008-04-13 18:44:59 17,664 ----a-w c:\windows\system32\watchdog.sys
    - 2004-08-04 10:00:00 208,896 ----a-w c:\windows\system32\wavemsp.dll
    + 2008-04-14 00:12:08 215,552 ----a-w c:\windows\system32\wavemsp.dll
    - 2004-08-04 11:00:00 1,352,192 ----a-w c:\windows\system32\wbem\cimwin32.dll
    + 2008-04-14 00:11:50 1,358,848 ----a-w c:\windows\system32\wbem\cimwin32.dll
    - 2004-08-04 11:00:00 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
    + 2008-04-14 00:11:53 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
    - 2004-08-04 10:00:00 22,016 ----a-w c:\windows\system32\wbem\evntrprv.dll
    + 2008-04-14 00:11:53 21,504 -c--a-w c:\windows\system32\wbem\evntrprv.dll
    - 2004-08-04 11:00:00 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
    + 2008-04-14 00:11:53 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
    - 2004-08-04 11:00:00 185,856 ----a-w c:\windows\system32\wbem\framedyn.dll
    + 2008-04-14 00:11:53 185,344 ----a-w c:\windows\system32\wbem\framedyn.dll
    - 2004-08-04 11:00:00 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll
    + 2008-04-14 00:11:56 24,576 -c--a-w c:\windows\system32\wbem\krnlprov.dll
    - 2004-08-04 11:00:00 16,384 ----a-w c:\windows\system32\wbem\mofcomp.exe
    + 2008-04-14 00:12:26 16,384 -c--a-w c:\windows\system32\wbem\mofcomp.exe
    - 2004-08-04 11:00:00 123,904 ----a-w c:\windows\system32\wbem\mofd.dll
    + 2008-04-14 00:11:57 123,904 ----a-w c:\windows\system32\wbem\mofd.dll
    - 2004-08-04 11:00:00 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
    + 2008-04-14 00:12:01 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
    - 2004-08-04 11:00:00 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll
    + 2008-04-14 00:12:02 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll
    - 2004-08-04 11:00:00 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll
    + 2008-04-14 00:12:03 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll
    - 2004-08-04 11:00:00 177,152 ----a-w c:\windows\system32\wbem\repdrvfs.dll
    + 2008-04-14 00:12:04 178,176 ----a-w c:\windows\system32\wbem\repdrvfs.dll
    - 2004-08-04 11:00:00 36,864 ----a-w c:\windows\system32\wbem\scrcons.exe
    + 2008-04-14 00:12:34 36,352 -c--a-w c:\windows\system32\wbem\scrcons.exe
    - 2004-08-04 11:00:00 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll
    + 2008-04-14 00:12:07 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll
    - 2004-08-04 11:00:00 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
    + 2008-04-14 00:12:08 131,584 -c--a-w c:\windows\system32\wbem\viewprov.dll
    - 2004-08-04 11:00:00 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
    + 2008-04-14 00:12:08 196,608 -c--a-w c:\windows\system32\wbem\wbemcntl.dll
    - 2004-08-04 11:00:00 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
    + 2008-04-14 00:12:08 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
    - 2004-08-04 11:00:00 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
    + 2008-04-14 00:12:08 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
    - 2004-08-04 11:00:00 530,944 ----a-w c:\windows\system32\wbem\wbemcore.dll
    + 2008-04-14 00:12:08 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll
    - 2004-08-04 11:00:00 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
    + 2008-04-14 00:12:08 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
    - 2004-08-04 11:00:00 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
    + 2008-04-14 00:12:08 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
    - 2004-08-04 10:00:00 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
    + 2008-04-14 00:12:08 43,008 -c--a-w c:\windows\system32\wbem\wbemperf.dll
    - 2004-08-04 11:00:00 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
    + 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
    - 2004-08-04 11:00:00 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
    + 2008-04-14 00:12:08 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
    - 2004-08-04 11:00:00 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
    + 2008-04-14 00:12:39 116,224 -c--a-w c:\windows\system32\wbem\wbemtest.exe
    - 2004-08-04 11:00:00 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
    + 2008-04-14 00:12:08 197,120 -c--a-w c:\windows\system32\wbem\wbemupgd.dll
    - 2004-08-04 11:00:00 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
    + 2008-04-14 00:12:40 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
    - 2004-08-04 11:00:00 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
    + 2008-04-13 17:10:20 6,656 -c--a-w c:\windows\system32\wbem\wmiapres.dll
    - 2004-08-04 11:00:00 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
    + 2008-04-14 00:12:09 88,576 -c--a-w c:\windows\system32\wbem\wmiaprpl.dll
    - 2004-08-04 11:00:00 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
    + 2008-04-14 00:12:40 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
    - 2004-08-04 11:00:00 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
    + 2008-04-14 00:12:09 60,928 -c--a-w c:\windows\system32\wbem\wmicookr.dll
    - 2004-08-04 11:00:00 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
    + 2008-04-14 00:12:09 140,800 -c--a-w c:\windows\system32\wbem\wmidcprv.dll
    - 2004-08-04 11:00:00 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
    + 2008-04-14 00:12:09 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
    - 2004-08-04 11:00:00 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
    + 2008-04-14 00:12:09 132,096 -c--a-w c:\windows\system32\wbem\wmipdskq.dll
    - 2004-08-04 11:00:00 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll
    + 2008-04-14 00:12:09 61,952 -c--a-w c:\windows\system32\wbem\wmipiprt.dll
    - 2004-08-04 11:00:00 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll
    + 2008-04-14 00:12:09 62,464 -c--a-w c:\windows\system32\wbem\wmipjobj.dll
    - 2004-08-04 11:00:00 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
    + 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
    - 2004-08-04 11:00:00 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
    + 2008-04-14 00:12:09 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
    - 2004-08-04 11:00:00 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
    + 2008-04-14 00:12:40 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
    - 2004-08-04 11:00:00 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
    + 2008-04-14 00:12:09 41,472 -c--a-w c:\windows\system32\wbem\wmipsess.dll
    - 2004-08-04 11:00:00 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
    + 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
    - 2004-08-04 11:00:00 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
    + 2008-04-14 00:12:09 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
    - 2006-03-24 04:37:50 49,152 ----a-w c:\windows\system32\wdigest.dll
    + 2008-04-14 00:12:08 49,152 ----a-w c:\windows\system32\wdigest.dll
    + 2008-04-14 00:12:45 23,552 ----a-w c:\windows\system32\wdmaud.drv
    - 2007-08-20 10:04:42 232,960 ----a-w c:\windows\system32\webcheck.dll
    + 2008-08-26 07:24:31 233,472 ----a-w c:\windows\system32\webcheck.dll
    - 2006-01-04 03:35:05 68,096 ----a-w c:\windows\system32\webclnt.dll
    + 2008-04-14 00:12:08 68,096 ----a-w c:\windows\system32\webclnt.dll
    - 2004-08-04 10:00:00 135,680 ----a-w c:\windows\system32\webvw.dll
    + 2008-04-14 00:12:08 135,680 ----a-w c:\windows\system32\webvw.dll
    - 2004-08-04 10:00:00 65,536 ----a-w c:\windows\system32\wextract.exe
    + 2008-04-14 00:12:39 65,024 ----a-w c:\windows\system32\wextract.exe
    + 2004-08-04 10:00:00 13,600 ----a-w c:\windows\system32\wfwnet.drv
    - 2004-08-04 10:00:00 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
    + 2008-04-14 00:12:39 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
    + 2004-06-19 02:43:16 323,624 ----a-w c:\windows\system32\wiaaut.dll
    - 2004-08-04 10:00:00 463,360 ----a-w c:\windows\system32\wiadefui.dll
    + 2008-04-14 00:12:08 463,360 ----a-w c:\windows\system32\wiadefui.dll
    - 2004-08-04 10:00:00 124,416 ----a-w c:\windows\system32\wiadss.dll
    + 2008-04-14 00:12:08 124,416 ----a-w c:\windows\system32\wiadss.dll
    - 2004-08-04 10:00:00 75,776 ----a-w c:\windows\system32\wiascr.dll
    + 2008-04-14 00:12:08 75,776 ----a-w c:\windows\system32\wiascr.dll
    - 2006-12-19 18:16:47 333,824 ----a-w c:\windows\system32\wiaservc.dll
    + 2008-04-14 00:12:08 333,824 ----a-w c:\windows\system32\wiaservc.dll
    - 2004-08-04 10:00:00 589,312 ----a-w c:\windows\system32\wiashext.dll
    + 2008-04-14 00:12:08 589,312 ----a-w c:\windows\system32\wiashext.dll
    - 2004-08-04 10:00:00 111,104 ----a-w c:\windows\system32\wiavideo.dll
    + 2008-04-14 00:12:08 111,104 ----a-w c:\windows\system32\wiavideo.dll
    - 2007-03-08 13:47:48 1,843,584 ----a-w c:\windows\system32\win32k.sys
    + 2008-09-15 12:12:56 1,846,400 ----a-w c:\windows\system32\win32k.sys
    - 2004-08-04 10:00:00 101,888 ----a-w c:\windows\system32\win32spl.dll
    + 2008-08-28 07:46:02 104,960 ----a-w c:\windows\system32\win32spl.dll
    - 2004-08-04 10:00:00 937,984 ----a-w c:\windows\system32\winbrand.dll
    + 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll
    - 2006-10-24 16:30:06 716,288 ------w c:\windows\system32\WindowsCodecs.dll
    + 2008-04-14 00:12:08 712,704 ----a-w c:\windows\system32\windowscodecs.dll
    - 2006-10-24 16:29:50 352,256 ------w c:\windows\system32\WindowsCodecsExt.dll
    + 2008-04-14 00:12:08 346,112 ----a-w c:\windows\system32\windowscodecsext.dll
    - 2006-10-17 17:05:58 206,336 ----a-w c:\windows\system32\WinFXDocObj.exe
    + 2007-08-13 22:45:16 206,336 ----a-w c:\windows\system32\WinFXDocObj.exe
    - 2004-08-04 10:00:00 351,232 ----a-w c:\windows\system32\winhttp.dll
    + 2008-04-14 00:12:08 354,304 ----a-w c:\windows\system32\winhttp.dll
    + 2007-08-13 22:54:10 818,688 ----a-w c:\windows\system32\wininet(2)(2).dll
    - 2007-08-20 10:04:43 824,832 ----a-w c:\windows\system32\wininet.dll
    + 2008-08-26 07:24:31 826,368 ----a-w c:\windows\system32\wininet.dll
    - 2004-08-04 10:00:00 32,768 ----a-w c:\windows\system32\winipsec.dll
    + 2008-04-14 00:12:09 32,256 ----a-w c:\windows\system32\winipsec.dll
    - 2004-08-04 10:00:00 502,272 ----a-w c:\windows\system32\winlogon.exe
    + 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\winlogon.exe
    - 2004-08-04 10:00:00 176,128 ----a-w c:\windows\system32\winmm.dll
    + 2008-04-14 00:12:09 176,128 ----a-w c:\windows\system32\winmm.dll
    - 2004-08-04 10:00:00 764,928 ----a-w c:\windows\system32\winntbbu.dll
    + 2008-04-14 00:11:11 756,224 ----a-w c:\windows\system32\winntbbu.dll
    - 2004-08-04 10:00:00 16,896 ----a-w c:\windows\system32\winrnr.dll
    + 2008-04-14 00:12:09 16,896 ----a-w c:\windows\system32\winrnr.dll
    - 2004-08-04 10:00:00 99,328 ----a-w c:\windows\system32\winscard.dll
    + 2008-04-14 00:12:09 99,328 ----a-w c:\windows\system32\winscard.dll
    - 2004-08-04 10:00:00 17,408 ----a-w c:\windows\system32\winshfhc.dll
    + 2008-04-14 00:12:09 17,408 ----a-w c:\windows\system32\winshfhc.dll
    + 2004-08-04 10:00:00 2,864 ----a-w c:\windows\system32\winsock.dll
    + 2008-04-14 00:12:45 146,432 ----a-w c:\windows\system32\winspool.drv
    + 2004-08-04 10:00:00 2,112 ----a-w c:\windows\system32\winspool.exe
    - 2007-03-17 13:43:01 292,864 ----a-w c:\windows\system32\winsrv.dll
    + 2008-04-14 00:12:09 293,376 ----a-w c:\windows\system32\winsrv.dll
    - 2004-08-04 10:00:00 53,760 ----a-w c:\windows\system32\winsta.dll
    + 2008-04-14 00:12:09 53,760 ----a-w c:\windows\system32\winsta.dll
    - 2004-08-04 10:00:00 176,640 ----a-w c:\windows\system32\wintrust.dll
    + 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\wintrust.dll
    - 2004-08-04 10:00:00 5,632 ----a-w c:\windows\system32\winver.exe
    + 2008-04-14 00:12:40 5,632 ----a-w c:\windows\system32\winver.exe
    - 2006-08-17 12:28:27 132,096 ----a-w c:\windows\system32\wkssvc.dll
    + 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wkssvc.dll
    + 2008-04-14 00:12:09 69,120 ----a-w c:\windows\system32\wlanapi.dll
    - 2004-08-04 10:00:00 172,032 ----a-w c:\windows\system32\wldap32.dll
    + 2008-04-14 00:12:09 172,032 ----a-w c:\windows\system32\wldap32.dll
    - 2004-08-04 10:00:00 92,672 ----a-w c:\windows\system32\wlnotify.dll
    + 2008-04-14 00:12:09 92,672 ----a-w c:\windows\system32\wlnotify.dll
    - 2006-10-19 01:47:18 222,208 ----a-w c:\windows\system32\wmasf.dll
    + 2007-10-27 22:40:30 222,720 ----a-w c:\windows\system32\wmasf.dll
    - 2004-08-04 10:00:00 5,632 ----a-w c:\windows\system32\wmi.dll
    + 2008-04-14 00:11:15 5,632 ----a-w c:\windows\system32\wmi.dll
    - 2006-10-19 02:47:20 295,936 ----a-w c:\windows\system32\wmpeffects.dll
    + 2008-06-24 22:12:58 295,936 ----a-w c:\windows\system32\wmpeffects.dll
    - 2006-10-24 16:30:00 276,992 ------w c:\windows\system32\WMPhoto.dll
    + 2008-04-14 00:12:09 276,992 ----a-w c:\windows\system32\wmphoto.dll
    - 2004-08-04 10:00:00 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
    + 2008-04-14 00:12:09 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
    - 2004-08-04 10:00:00 303,616 ----a-w c:\windows\system32\wmstream.dll
    + 2008-04-14 00:12:10 303,616 ----a-w c:\windows\system32\wmstream.dll
    + 2001-05-09 21:40:50 309,584 ----a-w c:\windows\system32\wmv8dmod.dll
    + 2001-05-09 20:47:10 466,944 ----a-w c:\windows\system32\wmv8dmoe.dll
    + 2001-05-09 20:50:40 446,464 ----a-w c:\windows\system32\wmvdmoe.dll
    - 2004-08-04 10:00:00 264,192 ----a-w c:\windows\system32\wow32.dll
    + 2008-04-14 00:12:10 264,192 ----a-w c:\windows\system32\wow32.dll
    + 2004-08-04 10:00:00 2,736 ----a-w c:\windows\system32\wowdeb.exe
    - 2004-08-04 10:00:00 32,256 ----a-w c:\windows\system32\wpabaln.exe
    + 2008-04-14 00:12:40 32,256 ----a-w c:\windows\system32\wpabaln.exe
    - 2004-08-04 10:00:00 32,256 ----a-w c:\windows\system32\wpnpinst.exe
    + 2008-04-14 00:12:41 11,264 ----a-w c:\windows\system32\wpnpinst.exe
    - 2004-08-04 10:00:00 82,944 ----a-w c:\windows\system32\ws2_32.dll
    + 2008-04-14 00:12:10 82,432 ----a-w c:\windows\system32\ws2_32.dll
    - 2004-08-04 10:00:00 19,968 ----a-w c:\windows\system32\ws2help.dll
    + 2008-04-14 00:12:10 19,968 ----a-w c:\windows\system32\ws2help.dll
    - 2004-08-04 10:00:00 13,824 ----a-w c:\windows\system32\wscntfy.exe
    + 2008-04-14 00:12:41 13,824 ----a-w c:\windows\system32\wscntfy.exe
    - 2004-08-04 10:00:00 114,688 ----a-w c:\windows\system32\wscript.exe
    + 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe
    - 2004-08-04 10:00:00 81,408 ----a-w c:\windows\system32\wscsvc.dll
    + 2008-04-14 00:12:10 80,896 ----a-w c:\windows\system32\wscsvc.dll
    - 2004-08-04 10:00:00 108,032 ----a-w c:\windows\system32\wshbth.dll
    + 2008-04-14 00:12:10 108,032 ----a-w c:\windows\system32\wshbth.dll
    - 2004-08-04 10:00:00 28,672 ----a-w c:\windows\system32\wshcon.dll
    + 2008-04-14 00:12:10 36,864 ----a-w c:\windows\system32\wshcon.dll
    - 2004-08-04 10:00:00 65,536 ----a-w c:\windows\system32\wshext.dll
    + 2008-05-09 10:53:40 90,112 ----a-w c:\windows\system32\wshext.dll
    - 2004-08-04 10:00:00 14,336 ----a-w c:\windows\system32\wship6.dll
    + 2008-04-14 00:12:10 14,336 ----a-w c:\windows\system32\wship6.dll
    - 2004-08-04 10:00:00 11,776 ----a-w c:\windows\system32\WshRm.dll
    + 2008-04-14 00:12:10 11,264 ----a-w c:\windows\system32\wshrm.dll
    - 2004-08-04 10:00:00 19,968 ----a-w c:\windows\system32\wshtcpip.dll
    + 2008-04-14 00:12:10 19,456 ----a-w c:\windows\system32\wshtcpip.dll
    - 2004-08-04 10:00:00 42,496 ----a-w c:\windows\system32\wsnmp32.dll
    + 2008-04-14 00:12:10 41,984 ----a-w c:\windows\system32\wsnmp32.dll
    - 2004-08-04 10:00:00 22,528 ----a-w c:\windows\system32\wsock32.dll
    + 2008-04-14 00:12:10 22,528 ----a-w c:\windows\system32\wsock32.dll
    - 2004-08-04 10:00:00 50,688 ----a-w c:\windows\system32\wstdecod.dll
    + 2008-04-14 00:12:10 50,688 ----a-w c:\windows\system32\wstdecod.dll
    - 2004-08-04 10:00:00 18,432 ----a-w c:\windows\system32\wtsapi32.dll
    + 2008-04-14 00:12:10 18,432 ----a-w c:\windows\system32\wtsapi32.dll
    - 2007-07-30 23:19:36 549,720 ----a-w c:\windows\system32\wuapi.dll
    + 2008-10-16 19:12:20 561,688 ----a-w c:\windows\system32\wuapi.dll
    - 2007-07-30 23:19:16 53,080 ----a-w c:\windows\system32\wuauclt.exe
    + 2008-10-16 19:09:44 51,224 ----a-w c:\windows\system32\wuauclt.exe
    - 2007-07-30 23:19:42 1,712,984 ----a-w c:\windows\system32\wuaueng.dll
    + 2008-10-16 19:13:40 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    - 2004-08-04 11:00:00 6,656 ----a-w c:\windows\system32\wuauserv.dll
    + 2008-04-14 00:12:11 6,656 ----a-w c:\windows\system32\wuauserv.dll
    - 2007-07-30 23:19:32 325,976 ----a-w c:\windows\system32\wucltui.dll
    + 2008-10-16 19:12:22 323,608 ----a-w c:\windows\system32\wucltui.dll
    - 2007-07-30 23:18:40 33,624 ----a-w c:\windows\system32\wups.dll
    + 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\wups.dll
    - 2007-07-30 23:19:12 43,352 ----a-w c:\windows\system32\wups2.dll
    + 2008-10-16 19:09:44 43,544 ----a-w c:\windows\system32\wups2.dll
    - 2007-07-30 23:19:28 203,096 ----a-w c:\windows\system32\wuweb.dll
    + 2008-10-16 19:13:40 202,776 ----a-w c:\windows\system32\wuweb.dll
    - 2004-08-04 10:00:00 378,368 ----a-w c:\windows\system32\wzcdlg.dll
    + 2008-04-14 00:12:11 383,488 ----a-w c:\windows\system32\wzcdlg.dll
    - 2004-08-04 10:00:00 51,712 ----a-w c:\windows\system32\wzcsapi.dll
    + 2008-04-14 00:12:11 52,736 ----a-w c:\windows\system32\wzcsapi.dll
    - 2004-08-04 10:00:00 359,936 ----a-w c:\windows\system32\wzcsvc.dll
    + 2008-04-14 00:12:11 483,840 ----a-w c:\windows\system32\wzcsvc.dll
    + 2006-02-03 12:41:26 14,032 ----a-w c:\windows\system32\x3daudio1_0.dll
    + 2007-03-05 16:42:18 15,128 ----a-w c:\windows\system32\x3daudio1_1.dll
    + 2007-10-22 07:37:16 17,928 ----a-w c:\windows\system32\X3DAudio1_2.dll
    + 2006-02-03 12:42:06 230,096 ----a-w c:\windows\system32\xactengine2_0.dll
    + 2006-03-31 16:39:48 229,584 ----a-w c:\windows\system32\xactengine2_1.dll
    + 2007-10-22 07:39:54 267,272 ----a-w c:\windows\system32\xactengine2_10.dll
    + 2006-05-31 11:24:16 230,168 ----a-w c:\windows\system32\xactengine2_2.dll
    + 2006-07-28 13:30:32 236,824 ----a-w c:\windows\system32\xactengine2_3.dll
    + 2006-09-28 20:05:56 237,848 ----a-w c:\windows\system32\xactengine2_4.dll
    + 2006-12-08 16:02:00 251,672 ----a-w c:\windows\system32\xactengine2_5.dll
    + 2007-01-24 19:27:30 255,848 ----a-w c:\windows\system32\xactengine2_6.dll
    + 2007-04-04 22:55:00 261,480 ----a-w c:\windows\system32\xactengine2_7.dll
    + 2007-06-21 00:46:04 266,088 ----a-w c:\windows\system32\xactengine2_8.dll
    + 2007-07-20 04:57:12 267,112 ----a-w c:\windows\system32\xactengine2_9.dll
    - 2004-08-04 10:00:00 91,648 ----a-w c:\windows\system32\xactsrv.dll
    + 2008-04-14 00:12:11 91,648 ----a-w c:\windows\system32\xactsrv.dll
    - 2004-08-04 10:00:00 30,720 ----a-w c:\windows\system32\xcopy.exe
    + 2008-04-14 00:12:41 30,720 ----a-w c:\windows\system32\xcopy.exe
    + 2006-03-31 16:39:24 62,672 ----a-w c:\windows\system32\xinput1_1.dll
    + 2006-07-28 13:30:14 62,744 ----a-w c:\windows\system32\xinput1_2.dll
    + 2007-04-04 22:53:42 81,768 ----a-w c:\windows\system32\xinput1_3.dll
    - 2006-07-14 15:51:51 121,856 ----a-w c:\windows\system32\xmllite.dll
    + 2008-04-14 00:12:11 121,856 ----a-w c:\windows\system32\xmllite.dll
    - 2004-08-04 10:00:00 129,536 ----a-w c:\windows\system32\xmlprov.dll
    + 2008-04-14 00:12:11 129,024 ----a-w c:\windows\system32\xmlprov.dll
    - 2004-08-04 10:00:00 50,176 ----a-w c:\windows\system32\xmlprovi.dll
    + 2008-04-14 00:12:11 50,176 ----a-w c:\windows\system32\xmlprovi.dll
    - 2006-03-01 19:42:42 11,776 ----a-w c:\windows\system32\xolehlp.dll
    + 2008-04-14 00:12:11 11,776 ----a-w c:\windows\system32\xolehlp.dll
    - 2004-08-04 10:00:00 438,784 ----a-w c:\windows\system32\xpob2res.dll
    + 2008-04-13 17:39:29 438,784 ----a-w c:\windows\system32\xpob2res.dll
    - 2004-08-04 10:00:00 187,392 ----a-w c:\windows\system32\xpsp1res.dll
    + 2008-04-13 17:39:22 187,392 ----a-w c:\windows\system32\xpsp1res.dll
    - 2004-08-04 10:00:00 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
    + 2008-04-13 17:39:24 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
    - 2007-06-19 07:24:36 350,720 ----a-w c:\windows\system32\xpsp3res.dll
    + 2008-04-13 17:39:26 689,152 ----a-w c:\windows\system32\xpsp3res.dll
    - 2006-10-21 01:29:54 304,928 ----a-w c:\windows\system32\XPSViewer\XPSViewer.exe
    + 2007-10-09 18:03:08 308,760 ----a-w c:\windows\system32\XPSViewer\XPSViewer.exe
    - 2004-08-04 10:00:00 337,920 ----a-w c:\windows\system32\zipfldr.dll
    + 2008-04-14 00:12:11 338,432 ----a-w c:\windows\system32\zipfldr.dll
    + 2008-12-14 13:07:29 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_220.dat
    + 2008-12-14 13:08:12 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_5ac.dat
    - 2004-08-04 10:00:00 50,688 ----a-w c:\windows\twain_32.dll
    + 2008-04-14 00:12:07 50,688 -c--a-w c:\windows\twain_32.dll
    + 2004-10-08 16:02:54 315,392 -c--a-w c:\windows\twain_32\LogiVid\HPortal2.dll
    + 2004-10-08 16:02:38 212,992 -c--a-w c:\windows\twain_32\LogiVid\HVideoS2.exe
    + 2004-10-08 16:02:40 6,656 -c--a-w c:\windows\twain_32\LogiVid\HVidSp2.dll
    + 2004-10-08 16:47:40 49,152 -c--a-r c:\windows\twain_32\LogiVid\InstVid.exe
    + 2004-10-08 16:02:42 696,320 -c--a-w c:\windows\twain_32\LogiVid\LHPorta2.dll
    + 2004-10-08 15:52:04 14,848 -c--a-w c:\windows\twain_32\LogiVid\LQCT32_2.dll
    + 2003-03-19 01:14:52 499,712 -c--a-w c:\windows\twain_32\LogiVid\msvcp71.dll
    + 2003-02-21 09:42:22 348,160 -c--a-w c:\windows\twain_32\LogiVid\msvcr71.dll
    + 2004-10-08 16:02:28 221,184 -c--a-w c:\windows\twain_32\LogiVid\PCSmart2.dll
    + 2005-01-31 10:11:18 159,744 -c--a-w c:\windows\twain_32\QuickCam\lvWIAext.dll
    + 2008-03-18 05:38:13 2,548 -c--a-w c:\windows\unins000.dat
    + 2008-03-18 04:53:18 691,545 ----a-w c:\windows\unins000.exe
    + 2000-08-31 13:00:00 49,152 ----a-w c:\windows\VFIND.exe
    - 2004-08-04 10:00:00 283,648 ----a-w c:\windows\winhlp32.exe
    + 2008-04-14 00:12:39 283,648 ----a-w c:\windows\winhlp32.exe
    + 2008-07-29 09:23:06 59,904 -c--a-w c:\windows\WinSxS\amd64_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_bdb5a47a\vcomp90.dll
    + 2008-01-24 02:54:54 8,192 -c--a-w c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2008-09-30 21:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
    + 2008-09-30 21:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
    - 2007-01-19 20:15:24 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
    + 2008-04-14 00:12:50 74,802 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
    - 2007-01-19 20:15:24 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
    + 2008-04-14 00:12:50 995,383 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
    - 2007-01-19 20:15:24 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
    + 2008-04-14 00:12:50 1,011,774 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
    - 2007-01-19 20:15:24 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
    + 2008-04-14 00:12:50 401,462 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
    + 2006-12-02 02:56:00 96,256 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
    + 2007-10-24 06:47:56 479,232 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcm80.dll
    + 2007-10-24 06:47:56 558,080 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll
    + 2007-10-24 06:47:56 635,904 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll
    + 2006-12-02 04:25:52 1,101,824 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
    + 2006-12-02 04:25:56 1,093,120 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
    + 2006-12-02 04:25:58 69,632 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
    + 2006-12-02 04:26:00 57,856 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
    + 2006-12-02 04:08:00 40,960 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
    + 2006-12-02 04:08:00 45,056 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
    + 2006-12-02 04:08:00 65,536 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
    + 2006-12-02 04:08:00 57,344 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
    + 2006-12-02 04:08:00 61,440 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
    + 2006-12-02 04:08:00 61,440 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
    + 2006-12-02 04:08:00 61,440 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
    + 2006-12-02 04:08:00 49,152 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
    + 2006-12-02 04:08:00 49,152 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
    + 2006-12-02 04:46:44 65,536 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
    + 2007-11-07 00:23:58 224,768 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
    + 2007-11-07 05:19:34 568,832 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
    + 2007-11-07 05:19:34 655,872 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
    + 2008-07-29 12:05:08 54,272 -c--a-w c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_8babbe9a\vcomp90.dll
    + 2008-04-14 00:12:51 1,054,208 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
    + 2008-04-14 00:12:51 57,344 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
    + 2008-04-14 00:12:51 343,040 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
    + 2008-04-14 00:12:47 1,724,416 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
    + 2008-04-15 17:47:33 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
    - 2004-08-04 10:00:00 853,504 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
    + 2008-04-14 00:12:49 853,504 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
    - 2004-08-04 10:00:00 991,232 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
    + 2008-04-14 00:12:50 991,232 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
    - 2004-08-04 10:00:00 132,096 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
    + 2008-04-13 18:26:33 132,096 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
    - 2007-07-11 10:55:07 258,048 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2008-01-24 02:55:05 258,048 -c--a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    - 2007-07-11 10:55:07 114,176 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2008-01-24 02:55:05 113,664 -c--a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2000-08-31 13:00:00 68,096 ----a-w c:\windows\zip.exe
    .
    -- Snapshot reset to current date --
    .

  7. #27
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
    "CurseClient"="c:\program files\Curse\CurseClient.exe" [2008-10-10 4789760]
    "Google Update"="c:\documents and settings\Rozanne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-27 133104]
    "igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2008-08-01 1103216]
    "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 4670968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-30 138008]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-30 162584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-30 138008]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-02 24576]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.XFR1"= xfcodec.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
    backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
    backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
    backup=c:\windows\pss\Service Manager.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Rozanne^Start Menu^Programs^Startup^hamachi.lnk]
    path=c:\documents and settings\Rozanne\Start Menu\Programs\Startup\hamachi.lnk
    backup=c:\windows\pss\hamachi.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Rozanne^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=c:\documents and settings\Rozanne\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=c:\windows\pss\LimeWire On Startup.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Rozanne^Start Menu^Programs^Startup^SpywareGuard.lnk]
    path=c:\documents and settings\Rozanne\Start Menu\Programs\Startup\SpywareGuard.lnk
    backup=c:\windows\pss\SpywareGuard.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Rozanne^Start Menu^Programs^Startup^Xfire.lnk]
    path=c:\documents and settings\Rozanne\Start Menu\Programs\Startup\Xfire.lnk
    backup=c:\windows\pss\Xfire.lnkStartup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    c:\windows\system32\dumprep 0 -k [X]
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoOE
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoSA
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zango

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
    --a------ 2007-06-11 04:25 6731312 c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
    --a------ 2008-09-03 19:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
    --a--c--- 2006-08-14 15:20 462336 c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
    --a--c--- 2007-04-03 17:29 165784 c:\program files\DAEMON Tools\daemon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
    --a------ 2007-05-14 14:23 1191936 c:\program files\Dell\QuickSet\quickset.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
    --a--c--- 2004-12-06 02:05 127035 c:\windows\system32\dla\tfswctrl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
    --a------ 2007-03-30 20:00 162584 c:\windows\system32\hkcmd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
    --a------ 2007-03-30 19:59 138008 c:\windows\system32\igfxpers.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
    --a------ 2007-03-30 20:00 138008 c:\windows\system32\igfxtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
    --a------ 2008-08-01 15:36 1103216 c:\program files\Download Manager\DLM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    --a--c--- 2004-07-27 17:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
    --a--c--- 2004-07-27 17:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
    --a------ 2007-10-27 14:46 20480 c:\program files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
    --a--c--- 2005-01-18 16:07 196608 c:\program files\Logitech\Video\ManifestEngine.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
    --a--c--- 2005-01-18 16:47 458752 c:\program files\Logitech\Video\ISStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
    --a--c--- 2005-01-18 16:37 217088 c:\program files\Logitech\Video\LogiTray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
    --a------ 2004-10-08 10:52 221184 c:\windows\system32\LVCOMSX.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
    --a------ 2003-09-10 03:24 20480 c:\program files\NetWaiting\netwaiting.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
    --a--c--- 2005-07-12 20:05 1117184 c:\program files\McAfee\SpamKiller\MSKDetct.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
    --------- 2007-05-02 18:16 184320 c:\program files\Dell\MediaDirect\PCMService.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
    -ra--c--- 2005-10-26 16:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSA.exe]
    --a------ 2006-05-15 10:41 1986560 c:\program files\Bell\Sympatico Security Advisor\SSA.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    --a------ 2008-10-11 12:16 1410296 c:\program files\Steam\Steam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    --a--c--- 2007-03-14 02:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
    -ra--c--- 2008-01-02 20:15 103712 c:\program files\Macrogaming\SweetIM\SweetIM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-02-01 06:57 171448 c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    --a--c--- 2006-03-08 12:48 761947 c:\program files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
    --a--c--- 2007-09-09 08:31 1046688 c:\program files\TrojanHunter 5.0\THGuard.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    --a------ 2007-04-12 14:50 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayStartup]
    --a------ 2007-04-10 13:43 83536 c:\program files\Personal Vault\VaultClientTray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
    -ra--c--- 2006-03-30 15:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
    --a------ 2008-08-28 09:18 3660848 c:\program files\Veoh Networks\Veoh\VeohClient.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-03-27 14:22 4670968 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
    --a--c--- 2007-05-10 10:22 405504 c:\windows\stsystra.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "DisableNotifications"= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\MSN\\MSNCoreFiles\\msn.exe"=
    "c:\\Program Files\\Azureus\\Azureus.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\ijji\\ENGLISH\\u_skid.exe"=
    "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
    "c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
    "c:\\Program Files\\Hamachi\\hamachi.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\Curse\\CurseClient.exe"=
    "c:\\Ntreev\\Grand Chase\\main.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
    "29101:TCP"= 29101:TCP:???? ??

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-31 111184]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-03-31 20560]
    R2 VaultClientSRV;Personal Vault Backup Service;c:\program files\Personal Vault\VaultClientSRV.exe [2007-04-10 906832]
    S2 Apache2.2;Apache2.2;"c:\documents and settings\Rozanne\Desktop\Games\Pedregons_2.4.3_RepackV2\Pedregon's 2.4.3 RepackV2\Server\xampp\apache\bin\apache.exe" -k runservice []
    S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\w300mgmt.sys [2007-06-08 87824]
    S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\w300obex.sys [2007-06-08 85696]
    S3 XDva208;XDva208;\??\c:\windows\system32\XDva208.sys []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d6933af-ede2-11dc-89fe-0019b958ef8d}]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2008-12-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

    2008-12-14 c:\windows\Tasks\GoogleUpdateTaskUser.job
    - c:\documents and settings\Rozanne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-27 14:09]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{156E8AFB-D093-459E-8718-ADD84DE45B5B} - c:\windows\system32\rqRJDvus.dll
    BHO-{2F74F207-BCCD-4B19-B1D9-0971A2376299} - (no file)
    BHO-{527CF6BA-E4B2-433C-B54C-1D1F2EB1CBEF} - (no file)
    BHO-{7ECC9E80-7F7A-466E-8311-044AE36D3F34} - (no file)
    BHO-{857525F4-AB96-4D50-8D07-E91D13C6C0A2} - (no file)
    BHO-{D5C898C2-15D9-41FB-9F52-695CBBD166AF} - (no file)
    BHO-{DBE74FAD-D2B8-48FE-B1E9-142DF01ED682} - (no file)
    Notify-khfDvuus - khfDvuus.dll
    MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.ask.com?o=1607
    uInternet Connection Wizard,ShellNext = hxxp://www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=1070120
    uInternet Settings,ProxyOverride = *.local
    IE: &Download by DLExpert (Faster)
    IE: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZKfox000
    IE: &Windows Live Search
    IE: Download &All by DLExpert (Faster)
    IE: E&xport to Microsoft Excel
    IE: {{4AB89EA8-E2B8-11d4-AE71-00D00925CF52} - c:\program files\DLExpert\DLExpert.exe
    IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Rozanne\Start Menu\Programs\IMVU\Run IMVU.lnk
    IE: {{4AB89EA8-E2B8-11d4-AE71-00D00925CF52} - c:\program files\DLExpert\DLExpert.exe -
    IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Rozanne\Start Menu\Programs\IMVU\Run IMVU.lnk -

    O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
    FF - ProfilePath - c:\documents and settings\Rozanne\Application Data\Mozilla\Firefox\Profiles\8ohb3bvi.default\
    FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/?account_id=rozanne.chenier%40gmail.com#inbox|http://forums.spybot.info/forumdispl...lt.asp?mn=1.21
    FF - plugin: c:\documents and settings\Rozanne\Local Settings\Application Data\Google\Update\1.2.131.27\npGoogleOneClick6.dll
    FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
    FF - plugin: c:\program files\BYOND\bin\npbyond.dll
    FF - plugin: c:\program files\Download Manager\npfpdlm.dll
    FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
    FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
    FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npbyond.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
    FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
    FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
    FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
    FF - plugin: c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-14 08:07:40
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\BigWigs.toc 1423 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Changelog-BigWigs-r4833-release.txt 1302257 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Core.lua 25187 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Docs\Developers.txt 102 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Docs\Leader.txt 2148 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Docs\Participant.txt 1519 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Icons\core-disabled.tga 14610 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Icons\core-enabled.tga 14662 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceAddon-2.0\AceAddon-2.0.lua 46798 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceAddon-2.0\AceAddon-2.0.toc 347 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceConsole-2.0\AceConsole-2.0.lua 87035 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceConsole-2.0\AceConsole-2.0.toc 365 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceDB-2.0\AceDB-2.0.lua 66025 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceDB-2.0\AceDB-2.0.toc 355 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceEvent-2.0\AceEvent-2.0.lua 31341 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceEvent-2.0\AceEvent-2.0.toc 347 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceHook-2.1\AceHook-2.1.lua 15670 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceHook-2.1\AceHook-2.1.toc 345 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceLibrary\AceLibrary.lua 26225 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceLibrary\AceLibrary.toc 283 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceLocale-2.2\AceLocale-2.2.lua 20456 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceLocale-2.2\AceLocale-2.2.toc 338 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceModuleCore-2.0\AceModuleCore-2.0.lua 21351 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceModuleCore-2.0\AceModuleCore-2.0.toc 385 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceOO-2.0\AceOO-2.0.lua 26537 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\AceOO-2.0\AceOO-2.0.toc 330 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CallbackHandler-1.0\CallbackHandler-1.0.lua 8981 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CallbackHandler-1.0\CallbackHandler-1.0.xml 221 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\CandyBar-2.0.lua 49396 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\Libs\AceLibrary
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\Libs\AceLibrary\AceLibrary.lua 26225 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\Libs\AceLibrary\AceLibrary.toc 283 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\Libs\PaintChips-2.0
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\CandyBar-2.0\Libs\PaintChips-2.0\PaintChips-2.0.lua 4485 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Dewdrop-2.0\AceLibrary
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Dewdrop-2.0\AceLibrary\AceLibrary.toc 283 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Dewdrop-2.0\Dewdrop-2.0.lua 108547 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Boss-3.0\lib.xml 223 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Boss-3.0\LibBabble-Boss-3.0.lua 263650 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Boss-3.0\LibBabble-Boss-3.0.toc 615 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Boss-3.0\LibStub
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Boss-3.0\LibStub\LibStub.lua 1397 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Zone-3.0\lib.xml 221 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Zone-3.0\LibBabble-Zone-3.0.lua 96184 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Zone-3.0\LibBabble-Zone-3.0.toc 487 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Zone-3.0\LibStub
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibBabble-Zone-3.0\LibStub\LibStub.lua 1397 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibDataBroker-1.1\LibDataBroker-1.1.lua 2342 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibDBIcon-1.0\LibDBIcon-1.0.lua 8466 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibSharedMedia-3.0\lib.xml 221 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibSharedMedia-3.0\LibSharedMedia-3.0.lua 8416 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibSink-2.0\lib.xml 247 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\LibSink-2.0\LibSink-2.0.lua 26468 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\PaintChips-2.0\PaintChips-2.0.lua 4485 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Waterfall-1.0\AceLibrary
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Waterfall-1.0\AceLibrary\AceLibrary.lua 26225 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Libs\Waterfall-1.0\AceLibrary\AceLibrary.toc 283 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\Alarm.mp3 11622 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\Alert.mp3 9271 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\Info.mp3 6283 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\Long.mp3 52112 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\Victory.mp3 64731 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\VictoryClassic.mp3 46344 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Sounds\VictoryLong.mp3 88712 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\Charcoal.tga 49170 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\default.tga 24594 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\glaze.tga 24594 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\otravi-close.tga 2092 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\otravi-semi-full-border.tga 32812 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\otravi.tga 24594 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs\Textures\smooth.tga 24594 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\BigWigs_BlackTemple.toc 1148 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Council.lua 21775 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Gurtogg.lua 13634 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Illidan.lua 29258 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Najentus.lua 9336 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Shahraz.lua 9648 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Souls.lua 14783 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Supremus.lua 11706 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_BlackTemple\Teron.lua 7831 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\BigWigs_Extras.toc 1028 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\CustomBar.lua 10424 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\Flash.lua 11255 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\Proximity.lua 17201 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\Test.lua 7329 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\Tranq.lua 4437 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Extras\Version.lua 24378 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\Anetheron.lua 8868 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\Archimonde.lua 12728 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\Azgalor.lua 7984 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\BigWigs_Hyjal.toc 967 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\HyjalSummit.lua 28258 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\Kazrogal.lua 6393 bytes
    c:\docume~1\Rozanne\LOCALS~1\Temp\BigWigs Bossmods\BigWigs_Hyjal\Winterchill.lua 5995 bytes

    scan completed successfully
    hidden files: 94

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mysql]
    "ImagePath"="\"c:\pedregon's 2.4.3 repackv2\Server\xampp\mysql\bin\mysqld-nt\" \"--defaults-file=c:\pedregon's 2.4.3 repackv2\Server\xampp\mysql\bin\my.cnf\" mysql"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1036)
    c:\windows\system32\netprovcredman.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    c:\windows\system32\igfxsrvc.exe
    c:\pedregon's 2.4.3 repackv2\Server\xampp\mysql\bin\mysqld-nt.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
    c:\program files\Alwil Software\Avast4\ashWebSv.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-14 8:20:29 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-14 13:20:24
    ComboFix2.txt 2007-10-25 04:32:20

    Pre-Run: 5,708,873,728 bytes free
    Post-Run: 5,732,384,768 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    9118 --- E O F --- 2008-11-13 16:25:15

  8. #28
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    Holly geez that was long... ok, now for the HJT log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:33:40 AM, on 12/14/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Rozanne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Pedregon's 2.4.3 RepackV2\Server\xampp\mysql\bin\mysqld-nt.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Personal Vault\VaultClientSRV.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\something.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.ca/ig/dell?hl=en&c...ca&ibd=1070120
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Rozanne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZKfox000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: DLExpert - {4AB89EA8-E2B8-11d4-AE71-00D00925CF52} - C:\Program Files\DLExpert\DLExpert.exe
    O9 - Extra 'Tools' menuitem: &DLExpert - {4AB89EA8-E2B8-11d4-AE71-00D00925CF52} - C:\Program Files\DLExpert\DLExpert.exe
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Rozanne\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} (Talisma NetAgent Customer ActiveX Control version 3) - https://intuitcanada.ehosts.net/neta.../custappx3.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
    O16 - DPF: {5CB1506E-1DEA-4E63-89A7-E40E52AEA1FD} (OnagerCtrl Class) - http://fulfillment.puretracks.com/onager.cab
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/game...lugin11USA.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1180804911899
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1192979619546
    O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/down...auncherNew.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://activation.sympatico.ca/wizl...adaActiveX.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Apache2.2 - Unknown owner - C:\Documents and Settings\Rozanne\Desktop\Games\Pedregons_2.4.3_RepackV2\Pedregon's 2.4.3 RepackV2\Server\xampp\apache\bin\apache.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: mysql - Unknown owner - C:\Pedregon's.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: Personal Vault Backup Service (VaultClientSRV) - Unknown owner - C:\Program Files\Personal Vault\VaultClientSRV.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 12825 bytes

  9. #29
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent
    LimeWire
    Azureus


    I'd like you to read the this thread.

    Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

    Delete these folders afterwards if found:

    c:\documents and settings\Rozanne\Application Data\uTorrent
    c:\program files\utorrent
    c:\program files\azureus

    Empty Recycle Bin.

    After that:

    Start hjt, do a system scan, check:
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZKfox000

    Close browsers and fix checked.

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    c:\documents and settings\Rozanne\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    c:\windows\pss\LimeWire On Startup.lnkStartup
    
    Folder::
    c:\documents and settings\Rozanne\Application Data\uTorrent
    c:\program files\utorrent
    c:\program files\azureus
    
    Registry::
    [-HKLM\~\startupfolder\C:^Documents and Settings^Rozanne^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoOE]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoSA]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zango]
    
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Azureus\\Azureus.exe"=-
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=-

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.


    Uninstall old Adobe Reader versions and get the latest one here or get Foxit Reader here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 11.
    • Scroll down to where it says
      The J2SE Runtime Environment (JRE) allows end-users to run Java applications.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u11-windows-i586-p.exe to install the newest version. Note: Uncheck MSN toolbar option if you don't want to install it.



    Download ATF (Atribune Temp File) Cleanerİ by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh hjt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #30
    Member
    Join Date
    Apr 2007
    Location
    Ottawa, Ontario, Canada
    Posts
    70

    Default

    Before I continue, because I cannot do everything the first time, I'd rather ask before doing it half way.

    µTorrent
    LimeWire
    Azureus

    I do not use P2P programs, but I know my son uses µTorrent and Azureus for some of his games... LimeWire is the one I could not find in the Add/Remove Program, why I wanted to ask before doing anything more. I have uninstalled the other 2.

    Please advise.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •