View Full Version : braviax plus more
breakawayjade
2008-10-05, 01:39
God help me, my computer got infected with the braviax virus or whatever, it took me two weeks to find something to remove it but in the meantime it downloaded everything under the sun including virtuemonde and smithfraud and something called fraudantimalware or somethign like that. either way everytime i run a scan on my comp the same things pop up and ill get rid of some of them but itll say i need to do i restart and scan to fix it but it never does. Everytime i rescan about 7 or 8 more new things pop up. its so bad now that my computer is shutting down on its own. teatimer is nonstop bringing up stuff to get my approval or deny on and ive denied so many things that i dont even know what im denying. everything seems to be hitting or coming from system32 and thats all that im getting asked for approvals on. Im not on my computer now because i cant seem to keep internet explorer open long enough to bring this page up. someone help!
Hello breakawayjade
Welcome to Safer Networking.
Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
That said, All advice given by anyone volunteering here, is taken at own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.
Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode with Network Support
Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)
Please download Malwarebytes' Anti-Malware from Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) or Here (http://www.besttechie.net/tools/mbam-setup.exe)
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.<-- Don't forget this
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and Paste the entire report in your next reply along with a New Hijackthis log.
Download Trendmicros Hijackthis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe) to your desktop.
Double click it to install
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
Open HJT Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
If you can't do this in Safemode, then try downloading both these programs on a known clean computer and copy them to a CD or Thumbdrive and transfer them to the infected computer and run Malwarebytes first, don't worry about updating it right now unless you can in safemode, we can run another scan later when your system is running more normally
I need to see the Malwarebytes log and a Hijackthis log please
breakawayjade
2008-10-06, 06:47
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:13 PM, on 10/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Defender Pro Anti-Scam - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - C:\Program Files\Defender Pro\Defender Pro Anti-Scam\mscoree.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.download.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219236903822
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: awtRIbBs - C:\WINDOWS\
O21 - SSODL: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - (no file)
O23 - Service: Windows Network Data Management System Service (bndmss) - Unknown owner - C:\WINDOWS\system32\bndmss.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Defender Pro LLC - C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5430 bytes
Malwarebytes' Anti-Malware 1.28
Database version: 1230
Windows 5.1.2600 Service Pack 2
10/5/2008 5:42:55 PM
mbam-log-2008-10-05 (17-42-55).txt
Scan type: Quick Scan
Objects scanned: 100655
Time elapsed: 33 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 60
Registry Values Infected: 7
Registry Data Items Infected: 3
Folders Infected: 9
Files Infected: 147
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\awtrSkLB.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jsd72hf4t.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2681de42-78ea-4813-8362-da97cd2e60aa} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{2681de42-78ea-4813-8362-da97cd2e60aa} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\oincs.oinanalytics (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6b221e01-f517-4959-8c41-81948e7f2f17} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\oincs.oinanalytics.1 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\testcpv6.bho.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e4a04a1-a24d-45ae-aca4-949778400813} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6c51f7e9-8542-4f25-a30f-2060157752e1} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9d573d0e-663c-435f-bf31-2c4497373c41} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f3777260-7308-464a-baa2-cc492c0ce7d2} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{4d25f920-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4d25f923-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f924-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{63334394-3da3-4b29-a041-03535909d361} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83ec9074-6cba-43e8-b7e0-6a3809c4a958} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d360501e-dc73-4de6-a61c-21925aed7835} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f9668ada-fc6b-47f4-8381-de861dba5115} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{f7fa36a4-3177-4b57-b9c1-e9c5b2e0d3a9} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{de8245fb-063f-4793-8423-eaba08457382} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e1d45a8-0368-4efa-a163-128b867624cd} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b5bf6844-ec92-4d15-bdc3-a458127d7ba7} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{36510bd1-6732-43bb-8c44-32535bcf0282} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9bda59fc-79c7-47f7-87f1-4d9dc861dac3} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fa43e537-7082-2a53-ae4f-7ba2e3cd4a91} (Adware.ClickSpring) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\458a6951 (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\458a6951 (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\458a6951 (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\d3d3c32d (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\d3d3c32d (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d3d3c32d (Rootkit.Rustok) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oinanalytics (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\OINAnalytics.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jnskdfmf9eldfd (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jnskdfmf9eldfd (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\awtrsklb -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\awtrsklb -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\WA7P (Unknown.Vundo.Related) -> Quarantined and deleted successfully.
C:\WA7P\Quar (Unknown.Vundo.Related) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\speedrunner (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\awtrSkLB.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\BLkSrtwa.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\BLkSrtwa.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awoqiwfm.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mfwiqowa.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\duhrasiq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qisarhud.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kouascch.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hccsauok.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ornwwqas.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\saqwwnro.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wbawmyxj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jxymwabw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jsd72hf4t.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Miss Casey\Local Settings\Temp\csrssc.exe (Trojan.Clicker) -> Delete on reboot.
C:\WINDOWS\Temp\csrssc.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics\OINAnalytics.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\USYP_0002_N91M0908NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\USYP_0002_N91M1708NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.10\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.12\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.13\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.14\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.15\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.16\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.17\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.18\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.19\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.20\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.7\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.8\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\CONFLICT.9\UWA6P_0001_N91M1807NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\0032920b.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\00330d07.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\00334eb4.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\0b6b0ca8.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\0b6b4915.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\81xBu0eE.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\alofptld.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ariuotyv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\crylulfy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ehgwdgww.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mulqwpre.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nljuyk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nvahdoou.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nvrsol32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\paso.el (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\plkkrx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\prldvd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rs32net.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uoauaa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vgwjdkkq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wtaxfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xauyvi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xkktmw.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ysvepp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\YWg4o6lm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\458a6951.sys (Rootkit.Rustok) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Rootkit.Rustok) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\d3d3c32d.sys (Rootkit.Rustok) -> Quarantined and deleted successfully.
C:\sqffic.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\svjy.exe (Trojan.ErtFor) -> Quarantined and deleted successfully.
C:\vapu.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\yvcmiucb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temp\2333607564.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\AL4FQOZI\a1[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KWFGPJ5V\c3[1].exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KWFGPJ5V\e5[1].exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KWFGPJ5V\install[1].exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KWFGPJ5V\meane[1].stf (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\P3C4MILB\e5[1].exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\PCMPUTHE\b2[1].exe (Trojan-Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\ZW2HQIEM\c3[1].exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\188UEEW2\vfccfst[3].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\188UEEW2\vfcpp[1].htm (Trojan.ErtFor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\44LY4X70\asuper2[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\44LY4X70\yrsfpthuh[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\4ZQIAVT7\burrsstgu[1].txt (Trojan.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\4ZQIAVT7\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\5B8Y4613\qajghhvijw[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\5B8Y4613\qnjkxuu[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\D4KW4SDR\qnjkxuu[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\D4KW4SDR\qnjkxuu[3].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\D4KW4SDR\yrsfpthuh[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\E0VHAYW3\cmijwkxllm[1].htm (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\E0VHAYW3\qajghhvijw[2].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\E0VHAYW3\vfccfst[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\ES1KQGEU\asuper1[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\ES1KQGEU\qajghhvijw[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\ES1KQGEU\vfccfst[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\M8JJR675\Install[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\NSH8V8ZB\asuper[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\NSH8V8ZB\qnjkxuu[2].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Local Settings\Temporary Internet Files\Content.IE5\NSH8V8ZB\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\Microsoft\wrgnqp.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\speedrunner\config.cfg (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\speedrunner\SpeedRunner.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\speedrunner\SRUninstall.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\can.sdr (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ffcty.sp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\io.e18 (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mnax.help (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\onmac.frv (Malware.Trace) -> Quarantined and deleted successfully.
C:\Program Files\SAV\SAV.exe (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\SAV\SAV.cpl (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\SAV\sav0.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\SAV\sav1.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\SAV\sav.ooo (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\userinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\81xBu0eE.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\YWg4o6lm.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdssserf1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\BM73d64617.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM73d64617.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\Desktop\System Antivirus 2008.lnk (Rogue.SystemAntivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat60.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat61.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat62.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat63.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat64.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat65.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat66.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat67.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat68.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat69.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6B.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6C.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Guest\Local Settings\Temp\dat6F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Miss Casey\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
breakawayjade
2008-10-06, 07:04
oh since i did that malware thing, no buttons or pictures show, i have to right click them and show picture for them to show up...that could get REALLY annoying really quickly, can we fix that too? Thanks sooo much, Casey
Good Morning,
Lets not worry about the pictures right now, this was and still is a very heavily infected computer.
Do this first...Important
Disable the TeaTimer, leave it disabled until we're done or it will prevent fixes from taking
Run Spybot-S&D in Advanced Mode.
If it is not already set to do this Go to the Mode menu select "Advanced Mode"
On the left hand side, Click on Tools
Then click on the Resident Icon in the List
Uncheck "Resident TeaTimer" and OK any prompts.
Restart your computer.<--You need to do this for it to take effect
Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: awtRIbBs - C:\WINDOWS\
O21 - SSODL: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - (no file)
O23 - Service: Windows Network Data Management System Service (bndmss) - Unknown owner - C:\WINDOWS\system32\bndmss.exe
Then do this next
Open HJT > Misc Tools > Delete an NT Service
Type in bndmss
Then click on OK, it will ask you to reboot, do so.
Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.
Download ComboFix from Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) or Here (http://subs.geekstogo.com/ComboFix.exe) to your Desktop.
In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
Click on this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
Remember to re enable the protection again afterwards before connecting to the net
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review
Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
I need to see the Combofix log and a new Hijackthis log in normal windows please, not safemode or it won't be showing everything
breakawayjade
2008-10-06, 17:23
so i ran hijack and delete all the items you said, then went to delete nt service and tried to delete bndmss and it said its running and cant be deleted, i tried to bring up task manager and end process, that wont end it and i tried to rescan with hijack and deleted 023 again and it still wont work. ??
Go to Start> Run and type in services.msc then press Enter
Scroll down to Windows Network Data Management System Service
Double Click that service to open it.
Click on Stop Service.
Then change the Startup Type to Disabled.
OK your way out of the program.
Open HJT > Misc Tools > Delete an NT Service
Type in bndmss
Then click on OK, it will ask you to reboot, do so.
Please download OTMoveIt2 (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\system32\bndmss.exe
Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Then run ATF Cleaner and Combofix
breakawayjade
2008-10-07, 04:27
sigh, i dont have the option to stop it, start stop pause and resume are all gray. I tried to disable it but it didnt work, i tried rebooting and it was still there, I ran the OTmoveit and this is what i got
C:\WINDOWS\system32\bndmss.exe moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10062008_182327
i went back to the services part, but its still there and i tried to run hijack again but its giving me the same message, it cant be moved because its in use.
im sorry, i hate my computer right now too.
Lets bypass that for the time being, run ATF Cleaner and Combofix
breakawayjade
2008-10-07, 04:43
i pulled up task manager and tried to end the bndmss...and for some random reason it worked, i used hijack to delete it and it worked and when i run the otmove it says it cant be found so...on to the other stuff...running it right now
breakawayjade
2008-10-07, 05:23
ComboFix 08-10-06.05 - Miss Casey 2008-10-06 18:56:25.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.480 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Miss Casey\Application Data\Adobe\Player.exe
C:\Documents and Settings\Miss Casey\err.log
C:\Documents and Settings\NetworkService\Application Data\FNTS~1
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\companion wizard\compwiz.exe
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\ppatch~1\??pPatch\
C:\Program Files\Common Files\ppatch~1\rundll32.exe
C:\Program Files\DefenderPro AntiSpy\AntiSpy\Def\CnsMin.dsc
C:\Program Files\DefenderPro AntiSpy\AntiSpy\Def\CnsMin.prf
C:\Program Files\install provider
C:\Program Files\install provider\data.ini
C:\Program Files\install provider\InstallProvider.dll
C:\Program Files\install provider\InstallProvider.dlldat
C:\Program Files\install provider\InstallProvider_1.dll
C:\Program Files\SAV
C:\Program Files\stem~1
C:\Program Files\stem~1\n?tdde.exe
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe
C:\WINDOWS\ecurit~1
C:\WINDOWS\system32\dfhkj.tmp
C:\WINDOWS\system32\dfhkj.tmp2
C:\WINDOWS\system32\gulrxbma.dll
C:\WINDOWS\system32\spgmpjyb.ini
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\TDSSerrors.log
----- BITS: Possible infected sites -----
hxxp://78.157.143.163
hxxp://78.157.143.198
hxxp://91.203.93.6
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
-------\Legacy_VSPF
-------\Legacy_VSPF_HK
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:47 . 2008-10-04 15:47 2,441 --a------ C:\rdafenj.exe
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-10-04 15:18 . 2008-10-04 15:18 10,240 --a------ C:\WINDOWS\system32\brastk.exe
2008-10-04 15:18 . 2008-10-04 15:18 10,240 --a------ C:\WINDOWS\brastk.exe
2008-10-04 15:18 . 2008-10-04 15:18 6,144 --a------ C:\WINDOWS\system32\karna.dat
2008-10-04 15:18 . 2008-10-04 15:18 6,144 --a------ C:\WINDOWS\karna.dat
2008-10-04 12:16 . 2008-10-05 09:56 31,744 --a------ C:\Documents and Settings\Miss Casey\skp66.exe
2008-09-27 17:22 . 2008-09-27 17:23 229,508 --a------ C:\WINDOWS\system32\0b6b235d.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-17 14:50 . 2008-09-17 14:50 69,120 --a------ C:\WINDOWS\system32\icalc32.exe
2008-09-14 20:08 . 2008-09-14 20:09 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-04 19:14 577,536 ----a-w C:\WINDOWS\system32\user32.DLL
2008-10-04 19:14 577,536 ----a-w C:\WINDOWS\system32\dllcache\user32.dll
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2008-08-08 16:43 --------- d-----w C:\Program Files\Diet Analysis Plus 8.0
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 05:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-28 20:51 712,724 --sh--w C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
2006-11-09 21:29 712,724 --sh--w C:\WINDOWS\java\sapa.dll
.
C:\WINDOWS\system32\user32.dll ... is infected !!
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2004-08-04 11:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\user32.DLL
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\dllcache\user32.dll
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 04:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\user32.DLL
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"[system]"=C:\WINDOWS\system32\drivers\services.exe
"ANTIVIRUS"=C:\Program Files\SAV\sav.exe
"Jnskdfmf9eldfd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\csrssc.exe
"ksjf93orkekfniw73nfdd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
"MSFox"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\a.exe
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"Windows Network Data Management System Service"="skp66.exe" *
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"[system]"=C:\WINDOWS\system32\drivers\services.exe
"70e5758b"=rundll32.exe "C:\WINDOWS\system32\byjpmgps.dll",b
"ANTIVIRUS"=C:\Program Files\SAV\sav.exe
"braviax"=C:\WINDOWS\system32\braviax.exe
"ksjf93orkekfniw73nfdd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"rs32net"=C:\WINDOWS\System32\rs32net.exe
"Windows Network Data Management System Service"="skp66.exe" *
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"C:\\Documents and Settings\\Miss Casey\\skp66.exe"=skp66.exe
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
.
Contents of the 'Scheduled Tasks' folder
2008-10-01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-10-03 C:\WINDOWS\Tasks\At1.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-01 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-05 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-05 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-01 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-05 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-04 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-04 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-04 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At25.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At26.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At27.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At28.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At29.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At30.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At31.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At32.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At33.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At34.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At35.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-01 C:\WINDOWS\Tasks\At36.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-05 C:\WINDOWS\Tasks\At37.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-05 C:\WINDOWS\Tasks\At38.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-01 C:\WINDOWS\Tasks\At39.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At40.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At41.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At42.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At43.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At44.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At45.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At46.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At47.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At48.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Local Page = hxxp://www.google.com/
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Local Page = hxxp://www.google.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
O15 -: Trusted Zone: www.download.com
O17 -: HKLM\CCS\Interface\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
C:\WINDOWS\Downloaded Program Files\OberonGameHost_dbg.inf
C:\WINDOWS\Downloaded Program Files\OberonGameHost.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 19:06:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
.
**************************************************************************
.
Completion time: 2008-10-06 19:20:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-07 02:20:09
Pre-Run: 46,720,147,456 bytes free
Post-Run: 49,660,870,656 bytes free
340 --- E O F --- 2008-09-12 10:19:39
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:23:00 PM, on 10/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Defender Pro Anti-Scam - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - C:\Program Files\Defender Pro\Defender Pro Anti-Scam\mscoree.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.download.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219236903822
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Defender Pro LLC - C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5272 bytes
Good Morning,
You have an infected windows file that can be fixed by Combofix only if you have the Recovery Console installed, so do this. There is more to fix also after this is done.
We need to run ComboFix. Please visit this webpage for download links, and instructions for running the tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New HijackThis log.
A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.
breakawayjade
2008-10-07, 22:38
is there an easier way of doing that because i dont have the windows cd and i dont know what kind of service pack i have to download from microsoft. does it matter which one i pick?
breakawayjade
2008-10-07, 22:39
no it doesnt matter because i dont have 6 blank disks to download the program to. i'm going to look for the windows disks...if i cant find them, we have to find a different way for that part. :(
Hi ,
You don't need the windows CD and you don't need any floppies. Drag Combofix to the trash and grap a fresh copy.
Download Combofix from any of the links below, and save it to your desktop. <-- Important
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)
Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System
Windows XP SP2 <---This is what your need to download
Download the file & save it as its originally named, next to ComboFix.exe.
http://i24.photobucket.com/albums/c30/ken545/RC1-4.gif
Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. You should get a message that the Recovery Console was installed and when prompted to run Combofix, do so and post the log
When you go to the Microsoft site and click on SP2, you will see a download link, download it to your desktop
breakawayjade
2008-10-08, 05:34
ComboFix 08-10-07.06 - Miss Casey 2008-10-07 16:50:37.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.440 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Miss Casey\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:47 . 2008-10-04 15:47 2,441 --a------ C:\rdafenj.exe
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-10-04 12:16 . 2008-10-05 09:56 31,744 --a------ C:\Documents and Settings\Miss Casey\skp66.exe
2008-09-27 17:22 . 2008-09-27 17:23 229,508 --a------ C:\WINDOWS\system32\0b6b235d.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-17 14:50 . 2008-09-17 14:50 69,120 --a------ C:\WINDOWS\system32\icalc32.exe
2008-09-14 20:08 . 2008-09-14 20:09 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2008-08-08 16:43 --------- d-----w C:\Program Files\Diet Analysis Plus 8.0
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-28 20:51 712,724 --sh--w C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
2006-11-09 21:29 712,724 --sh--w C:\WINDOWS\java\sapa.dll
.
file copied: C:\WINDOWS\system32\user32.dll -> C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir.vir ( 577536 bytes )
C:\WINDOWS\system32\user32.dll ... is infected !!
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2004-08-04 11:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\user32.dll
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\user32.DLL
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\dllcache\user32.dll
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 04:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\user32.DLL
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-06_19.18.50.57 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"[system]"=C:\WINDOWS\system32\drivers\services.exe
"ANTIVIRUS"=C:\Program Files\SAV\sav.exe
"Jnskdfmf9eldfd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\csrssc.exe
"ksjf93orkekfniw73nfdd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
"MSFox"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\a.exe
"Windows Network Data Management System Service"="skp66.exe" *
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"[system]"=C:\WINDOWS\system32\drivers\services.exe
"70e5758b"=rundll32.exe "C:\WINDOWS\system32\byjpmgps.dll",b
"ANTIVIRUS"=C:\Program Files\SAV\sav.exe
"braviax"=C:\WINDOWS\system32\braviax.exe
"ksjf93orkekfniw73nfdd"=C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"rs32net"=C:\WINDOWS\System32\rs32net.exe
"Windows Network Data Management System Service"="skp66.exe" *
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"C:\\Documents and Settings\\Miss Casey\\skp66.exe"=skp66.exe
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 drvmcdb;drvmcdb;C:\WINDOWS\system32\drivers\drvmcdb.sys [2004-08-04 87136]
R1 AFS2K;AFS2k;C:\WINDOWS\system32\drivers\AFS2K.sys [2004-10-07 35840]
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
R1 sscdbhk5;sscdbhk5;C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-07-14 5627]
R1 ssrtln;ssrtln;C:\WINDOWS\system32\drivers\ssrtln.sys [2004-07-14 23545]
R2 drvnddm;drvnddm;C:\WINDOWS\system32\drivers\drvnddm.sys [2004-08-13 40544]
R2 tfsnboio;tfsnboio;C:\WINDOWS\system32\dla\tfsnboio.sys [2004-08-13 25723]
R2 tfsncofs;tfsncofs;C:\WINDOWS\system32\dla\tfsncofs.sys [2004-08-13 34843]
R2 tfsndrct;tfsndrct;C:\WINDOWS\system32\dla\tfsndrct.sys [2004-08-13 4123]
R2 tfsndres;tfsndres;C:\WINDOWS\system32\dla\tfsndres.sys [2004-08-13 2239]
R2 tfsnifs;tfsnifs;C:\WINDOWS\system32\dla\tfsnifs.sys [2004-08-13 86202]
R2 tfsnopio;tfsnopio;C:\WINDOWS\system32\dla\tfsnopio.sys [2004-08-13 14715]
R2 tfsnpool;tfsnpool;C:\WINDOWS\system32\dla\tfsnpool.sys [2004-08-13 6363]
R2 tfsnudf;tfsnudf;C:\WINDOWS\system32\dla\tfsnudf.sys [2004-08-13 98714]
R2 tfsnudfa;tfsnudfa;C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-08-13 100603]
R3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-02-10 154112]
R3 IntelC51;IntelC51;C:\WINDOWS\system32\DRIVERS\IntelC51.sys [2004-03-06 1233525]
R3 IntelC52;IntelC52;C:\WINDOWS\system32\DRIVERS\IntelC52.sys [2004-03-06 647929]
R3 IntelC53;IntelC53;C:\WINDOWS\system32\DRIVERS\IntelC53.sys [2004-06-16 61157]
R3 mohfilt;mohfilt;C:\WINDOWS\system32\DRIVERS\mohfilt.sys [2004-03-06 37048]
R3 senfilt;senfilt;C:\WINDOWS\system32\drivers\senfilt.sys [2004-09-17 732928]
R3 smwdm;smwdm;C:\WINDOWS\system32\drivers\smwdm.sys [2004-10-29 260096]
S2 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 NetSvc;Intel NCS NetService;C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2003-12-17 143360]
S3 PalmUSBD;PalmUSBD;C:\WINDOWS\system32\drivers\PalmUSBD.sys [2003-07-16 16509]
S3 USB_RNDIS;USB Remote NDIS Network Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 12672]
S3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys [ ]
S3 WpdUsb;WpdUsb;C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
.
Contents of the 'Scheduled Tasks' folder
2008-10-01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-10-03 C:\WINDOWS\Tasks\At1.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-01 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-05 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-04 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-04 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At25.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At26.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At27.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At28.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At29.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At30.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At31.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At32.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At33.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At34.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At35.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-01 C:\WINDOWS\Tasks\At36.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-05 C:\WINDOWS\Tasks\At37.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At38.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At39.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At40.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At41.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At42.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At43.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-04 C:\WINDOWS\Tasks\At44.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At45.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At46.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-06 C:\WINDOWS\Tasks\At47.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At48.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-06 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
- - - - ORPHANS REMOVED - - - -
BHO-{abfad53a-f8cf-4a8c-ad0b-db8785cae777} - (no file)
BHO-{efaa1717-85b1-4647-a959-daa5c7d5913f} - (no file)
Notify-awtRIbBs - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Local Page = hxxp://www.google.com/
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Local Page = hxxp://www.google.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
O15 -: Trusted Zone: www.download.com
O17 -: HKLM\CCS\Interface\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
C:\WINDOWS\Downloaded Program Files\OberonGameHost_dbg.inf
C:\WINDOWS\Downloaded Program Files\OberonGameHost.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-07 17:01:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\update\update.exe
.
**************************************************************************
.
Completion time: 2008-10-07 17:16:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-08 00:16:37
ComboFix2.txt 2008-10-07 02:20:38
Pre-Run: 48,845,713,408 bytes free
Post-Run: 48,688,611,328 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
323 --- E O F --- 2008-10-07 14:17:27
You need to enable windows to show all files and folders, instructions Here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)
C:\WINDOWS\Tasks\At1.job <---Delete every At1.job inside the Tasks folder but not the folder itself
Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::
File::
C:\WINDOWS\system32\drivers\services.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\csrssc.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\a.exe
C:\Documents and Settings\Miss Casey\svchost.exe
C:\WINDOWS\system32\byjpmgps.dll
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\System32\rs32net.exe
C:\WINDOWS\system32\81xBu0eE.exe
C:\WINDOWS\system32\YWg4o6lm.exe
Folder::
C:\Program Files\SAV
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"[system]"=-
"ANTIVIRUS"=-
"Jnskdfmf9eldfd"=-
"ksjf93orkekfniw73nfdd"=-
"MSFox"=-
"Windows Network Data Management System Service"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"[system]"=-
"70e5758b"=-
"ANTIVIRUS"=-
"braviax"=-
"ksjf93orkekfniw73nfdd"=-
"rs32net"=-
"Windows Network Data Management System Service"=-
"winlogon"=-
Save this as CFScript to your desktop.
Then drag the CFScript into ComboFix.exe as you see in the screenshot below.
http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
breakawayjade
2008-10-08, 21:01
there isnt a file called at1.job, i have 48 files that start with at, am i deleted them all?
breakawayjade
2008-10-08, 21:56
i just deleted at1 and did the rest here are the results
ComboFix 08-10-07.06 - Miss Casey 2008-10-08 11:30:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.361 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Miss Casey\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\a.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\csrssc.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
C:\Documents and Settings\Miss Casey\svchost.exe
C:\WINDOWS\system32\81xBu0eE.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\byjpmgps.dll
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\System32\rs32net.exe
C:\WINDOWS\system32\YWg4o6lm.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:47 . 2008-10-04 15:47 2,441 --a------ C:\rdafenj.exe
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-10-04 12:16 . 2008-10-05 09:56 31,744 --a------ C:\Documents and Settings\Miss Casey\skp66.exe
2008-09-27 17:22 . 2008-09-27 17:23 229,508 --a------ C:\WINDOWS\system32\0b6b235d.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-17 14:50 . 2008-09-17 14:50 69,120 --a------ C:\WINDOWS\system32\icalc32.exe
2008-09-14 20:08 . 2008-09-14 20:09 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2008-08-08 16:43 --------- d-----w C:\Program Files\Diet Analysis Plus 8.0
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-28 20:51 712,724 --sh--w C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
2006-11-09 21:29 712,724 --sh--w C:\WINDOWS\java\sapa.dll
.
file copied: C:\WINDOWS\system32\user32.dll -> C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir.vir ( 577536 bytes )
C:\WINDOWS\system32\user32.dll ... is infected !!
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2004-08-04 11:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\user32.DLL
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\dllcache\user32.dll
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 04:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\user32.DLL
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"C:\\Documents and Settings\\Miss Casey\\skp66.exe"=skp66.exe
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
.
Contents of the 'Scheduled Tasks' folder
2008-10-08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-10-08 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-05 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-07 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At25.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At26.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At27.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At28.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At29.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At30.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At31.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At32.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At33.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At34.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At35.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At36.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-05 C:\WINDOWS\Tasks\At37.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At38.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-07 C:\WINDOWS\Tasks\At39.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At40.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At41.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At42.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At43.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At44.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At45.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At46.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At47.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At48.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
- - - - ORPHANS REMOVED - - - -
BHO-REGEDIT4 - (no file)
BHO-[HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks] - (no file)
BHO-{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=" - (no file)
BHO-{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=" - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 11:40:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
.
**************************************************************************
.
Completion time: 2008-10-08 11:48:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-08 18:48:04
ComboFix2.txt 2008-10-08 00:16:56
ComboFix3.txt 2008-10-07 02:20:38
Pre-Run: 49,152,462,848 bytes free
Post-Run: 49,059,295,232 bytes free
259 --- E O F --- 2008-10-07 14:17:27
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:55 AM, on 10/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Defender Pro Anti-Scam - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - C:\Program Files\Defender Pro\Defender Pro Anti-Scam\mscoree.dll
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.download.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219236903822
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Defender Pro LLC - C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5392 bytes
Hi,
Make sure you turn off the TeaTimer in Spybot.
Disable the TeaTimer, leave it disabled until we're done or it will prevent fixes from taking
Run Spybot-S&D in Advanced Mode.
If it is not already set to do this Go to the Mode menu select "Advanced Mode"
On the left hand side, Click on Tools
Then click on the Resident Icon in the List
Uncheck "Resident TeaTimer" and OK any prompts.
Restart your computer.<--You need to do this for it to take effect
You need to enable windows to show all files and folders, instructions Here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)
Go to VirusTotal (http://www.virustotal.com/) and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see.
C:\rdafenj.exe
C:\sisonvnp.exe
Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::
File::
C:\WINDOWS\system32\icalc32.exe
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\system32\81xBu0eE.exe
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\system32\YWg4o6lm.exe
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
C:\Documents and Settings\Miss Casey\svchost.exe
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"winlogon"=-
Save this as CFScript to your desktop.
Then drag the CFScript into ComboFix.exe as you see in the screenshot below.
http://i24.photobucket.com/albums/c30/ken545/CFScriptB-4.gif
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
breakawayjade
2008-10-09, 04:02
File has already been analysed:
MD5: e7f49e03b7caa6b310dfbf52c4e3e4af
First received: 10.01.2008 03:46:48 (CET)
Date: 10.08.2008 12:26:00 (CET) [<1D]
Results: 27/36
Permalink: analisis/79f58e4f95da8ef4acdaafc7e3b7f2b0
File has already been analysed:
MD5: f3fc1efdc74d2cb7b3b01b9539726e52
First received: 10.06.2008 14:56:34 (CET)
Date: 10.08.2008 20:35:23 (CET) [<1D]
Results: 6/36
Permalink: analisis/37eabe9de7aed1071377f37e202bd70a
from the virus tools
breakawayjade
2008-10-09, 04:37
ComboFix 08-10-08.02 - Miss Casey 2008-10-08 18:15:38.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.465 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Miss Casey\Desktop\cfscript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\a.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\csrssc.exe
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\winlogen.exe
C:\Documents and Settings\Miss Casey\svchost.exe
C:\WINDOWS\system32\81xBu0eE.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\byjpmgps.dll
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\System32\rs32net.exe
C:\WINDOWS\system32\YWg4o6lm.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:47 . 2008-10-04 15:47 2,441 --a------ C:\rdafenj.exe
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-10-04 12:16 . 2008-10-05 09:56 31,744 --a------ C:\Documents and Settings\Miss Casey\skp66.exe
2008-09-27 17:22 . 2008-09-27 17:23 229,508 --a------ C:\WINDOWS\system32\0b6b235d.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-17 14:50 . 2008-09-17 14:50 69,120 --a------ C:\WINDOWS\system32\icalc32.exe
2008-09-14 20:08 . 2008-09-14 20:09 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-28 20:51 712,724 --sh--w C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
2006-11-09 21:29 712,724 --sh--w C:\WINDOWS\java\sapa.dll
.
file copied: C:\WINDOWS\system32\user32.dll -> C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir.vir ( 577536 bytes )
C:\WINDOWS\system32\user32.dll ... is infected !!
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2004-08-04 11:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\user32.DLL
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\dllcache\user32.dll
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 04:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\user32.DLL
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"winlogon"=C:\Documents and Settings\Miss Casey\svchost.exe
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"C:\\Documents and Settings\\Miss Casey\\skp66.exe"=skp66.exe
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
.
Contents of the 'Scheduled Tasks' folder
2008-10-08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2008-10-08 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-09 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At25.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At26.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At27.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At28.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At29.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At30.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At31.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At32.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At33.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At34.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At35.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At36.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At37.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At38.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At39.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-03 C:\WINDOWS\Tasks\At40.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-03 C:\WINDOWS\Tasks\At41.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At42.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-09 C:\WINDOWS\Tasks\At43.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At44.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At45.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At46.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At47.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At48.job
- C:\WINDOWS\system32\YWg4o6lm.exe []
2008-10-08 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2008-10-08 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\81xBu0eE.exe []
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 18:24:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
.
**************************************************************************
.
Completion time: 2008-10-08 18:30:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-09 01:30:31
ComboFix2.txt 2008-10-08 18:48:12
ComboFix3.txt 2008-10-08 00:16:56
ComboFix4.txt 2008-10-07 02:20:38
Pre-Run: 48,966,782,976 bytes free
Post-Run: 48,833,929,216 bytes free
253 --- E O F --- 2008-10-07 14:17:27
Good Morning,
Did you use the New Combofix Script from my post # 20 ? All those AT job entries should be gone. If not try it again and post a new Combofix log
Please download OTMoveIt2 (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\Documents and Settings\Miss Casey\skp66.exe
C:\Documents and Settings\Miss Casey\svchost.exe
Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
breakawayjade
2008-10-09, 16:48
I did the script thing it asked me to download the latest version of combo so maybe when i did that it didnt take? idk ill try it again, here are the results for the moveit
C:\Documents and Settings\Miss Casey\skp66.exe moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10092008_064634
File/Folder C:\Documents and Settings\Miss Casey\svchost.exe not found.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10092008_064651
breakawayjade
2008-10-09, 17:09
ComboFix 08-10-08.02 - Miss Casey 2008-10-09 6:50:26.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.453 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Miss Casey\Desktop\CFSCRIPT.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\Documents and Settings\Miss Casey\svchost.exe
C:\WINDOWS\system32\81xBu0eE.exe
C:\WINDOWS\system32\icalc32.exe
C:\WINDOWS\system32\YWg4o6lm.exe
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\icalc32.exe
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:47 . 2008-10-04 15:47 2,441 --a------ C:\rdafenj.exe
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-09-27 17:22 . 2008-09-27 17:23 229,508 --a------ C:\WINDOWS\system32\0b6b235d.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-14 20:08 . 2008-09-14 20:09 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-28 20:51 712,724 --sh--w C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
2006-11-09 21:29 712,724 --sh--w C:\WINDOWS\java\sapa.dll
.
file copied: C:\WINDOWS\system32\user32.dll -> C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir.vir ( 577536 bytes )
C:\WINDOWS\system32\user32.dll ... is infected !!
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2004-08-04 11:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
578,560 2008-04-14 00:12:08 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
577,536 2008-10-04 19:14:17 C:\WINDOWS\system32\user32.DLL
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 04:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2008-10-04 12:14 577536 97e670921c1d622ef2629fd21132083c C:\WINDOWS\system32\user32.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
.
Contents of the 'Scheduled Tasks' folder
2008-10-08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 06:59:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
.
**************************************************************************
.
Completion time: 2008-10-09 7:06:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-09 14:06:10
ComboFix2.txt 2008-10-09 01:30:38
ComboFix3.txt 2008-10-08 18:48:12
ComboFix4.txt 2008-10-08 00:16:56
ComboFix5.txt 2008-10-09 13:49:03
Pre-Run: 48,861,163,520 bytes free
Post-Run: 48,743,546,880 bytes free
246 --- E O F --- 2008-10-07 14:17:27
Good, thanks :bigthumb:
I am not sure this has been fixed, I am checking on it
C:\WINDOWS\system32\user32.dll ... is infected !!
In the meantime, upload this file also to VirusTotal
You need to enable windows to show all files and folders, instructions Here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)
Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see.
C:\WINDOWS\system32\0b6b235d.exe
You have a marker in your Combofix log for Limewire, I need you to read this and fully understand it as this is the latest avenue of attacks by malware writers.
We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs.
Because of this, we changed our malware forum's policy on the use of P2P file sharing programs.
If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.
If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programs, volunteer analysts will refuse their help.
We do not ask you to do this without reason.
P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.
Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.
This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/...ID-theft_1.html (http://www.infoworld.com/article/07/09/06/Seattle-man-arrested-for-p-to-p-ID-theft_1.html)
When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.
Post the Virustotal report and let me see a new HJT log please
breakawayjade
2008-10-09, 22:47
File has already been analysed:
MD5: 5afa31035ba4a4fe74c73f507f17cf1e
First received: 09.30.2008 15:26:58 (CET)
Date: 09.30.2008 15:26:58 (CET) [>9D]
Results: 18/36
Permalink: analisis/e8af070adb67c7b5b5f928d0b68a023c
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:19 PM, on 10/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Defender Pro Anti-Scam - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - C:\Program Files\Defender Pro\Defender Pro Anti-Scam\mscoree.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.download.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219236903822
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Defender Pro LLC - C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5240 bytes
and are you asking me to delete limewire? i have downloaded maybe 5 songs since getting it and i havent used it in at least the past 4 months.
Hello,
Still looking into the user32.dll issue. The rest of your log looks fine.
Limewire <--- Downloading music or whatever with one of these programs is like playing Russian Roulette , why take the chance of getting infected again. This is your computer, I can only advise so its up to you, but keep in mind if you get infected again and post back here, help will not be available to you because you where warned of the dangers of these types of programs. Its not only us but most of the other Malware Removal forums have adopted the same policy.
How are things running now??
breakawayjade
2008-10-10, 00:51
things are running super better! I dont have any popups and my keyboard is working right again. Although the longer i keep my computer from restarting the more unknown random processes i have running, its kind of strange.
breakawayjade
2008-10-10, 00:55
and if i were to get infected again, whats saying that it was caused from a limewire download? I know for sure I didnt get these viruses and malwares from limewire. Also what programs besides teatimer do you suggest i have running? I obviously have spybot to do checks but I dont really have a program that stays running (like norton antivirus) to keep me protected at all times.
Lets do this and when we're done I will link you to some free Anti Virus programs and some other free programs to help keep you safe,
Please run this free online virus scanner from ESET (http://www.eset.eu/online-scanner)
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic with a new Hijackthis log
breakawayjade
2008-10-13, 07:10
.....and how about that?
breakawayjade
2008-10-13, 09:17
this thing takes FOREVER! 2 hours already.....ill post it tomorrow :)
That user32.dll may be still infected .We need to fix it.
After you finished with ESET, run this program
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, look if you can click next icon next to the files found: http://users.telenet.be/bluepatchy/miekiemoes/images/check.gif
If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
http://users.telenet.be/bluepatchy/miekiemoes/images/move.gif
This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
breakawayjade
2008-10-14, 02:10
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3517 (20081013)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=a85eb6ce3e998b4ea64906d5294ee0c6
# end=finished
# remove_checked=true
# unwanted_checked=false
# utc_time=2008-10-13 05:01:41
# local_time=2008-10-13 10:01:41 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=336652
# found=19
# scan_time=10057
C:\QooBox\Quarantine\C\Documents and Settings\Miss Casey\Application Data\Adobe\Player.exe.vir a variant of Win32/TrojanDownloader.FakeAlert.JI trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\Program Files\Common Files\PPATCH~1\rundll32.exe.vir probably a variant of Win32/Genetik trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\Program Files\STEM~1\n?tdde.exe.vir probably a variant of Win32/Adware.PurityScan application (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe.vir Win32/Adware.WinFixer application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\assembly\GAC\Regcode\cpbk.dll a variant of Win32/Adware.Virtumonde.O application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\java\sapa.dll a variant of Win32/Adware.Virtumonde.O application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\0b6b235d.exe probably a variant of Win32/Genetik trojan (deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\0b6b235d.exe »NSIS »Yazzle1554OinAdmin.exe probably a variant of Win32/Genetik trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\WINDOWS\system32\alcypbdc.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\bbfmtegj.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\biqgegkh.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\dgixpenc.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\dlxxmavt.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\lbtifman.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\lxsglksr.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\oflucnpv.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\omcrhaoa.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\ppogavtw.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\yyvprdix.exe Win32/Adware.Toolbar.SearchColours application (unable to clean - deleted) 00000000000000000000000000000000
i hope thats what you needed
Thats good, removed somemore bad stuff
You need to enable windows to show all files and folders, instructions Here (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)
Go to VirusTotal (http://www.virustotal.com/) and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see.
C:\WINDOWS\system32\user32.dll
breakawayjade
2008-10-14, 02:41
this eset program is picking up all the stuff we downloaded...like combofix...am i clicking yes to EVERYTHING?
breakawayjade
2008-10-14, 02:46
MD5: b26b135ff1b9f60c9388b4a7d16f600b
First received: 06.03.2008 22:40:10 (CET)
Date: 10.04.2008 14:05:54 (CET) [>9D]
Results: 0/36
Permalink: analisis/4f247659bdf8fe1a7b333be7c4434400
heres the virus tool
Its picking up some of the bad stuff Combofix quarantined
That can't be the whole report from VirusTotal ????
Run Dr. Web Curit
breakawayjade
2008-10-14, 07:23
im still running the dr web thing, its also taking a hundred years to finish and I clicked 'yes to all' but stuff is still popping up asking what to do with it and i dont have 5 hours to sit right in front of my computer and click yes every time something comes up...so its about half way through scanning C drive, there arent anyother options to select.
File has already been analysed:
MD5: b26b135ff1b9f60c9388b4a7d16f600b
First received: 06.03.2008 22:40:10 (CET)
Date: 10.04.2008 14:05:54 (CET) [>9D]
Results: 0/36
Permalink: analisis/4f247659bdf8fe1a7b333be7c4434400
and thats all for the virus thing
Hi,
The reason for the scans is to get you as clean as possible, I know some of them take awhile. The problem here is user32.dll, is it still infected, don't know. Can we delete it, NO, or you won't be able to log onto windows. Lets see what Dr Web Curit finds.
You can also try uploading that file here
Jotti Upload (http://virusscan.jotti.org/)
C:\WINDOWS\system32\user32.dll
breakawayjade
2008-10-14, 15:31
DesktopDoctor1.5.1.exe\data023;C:\DesktopDoctor1.5.1.exe;Probably DLOADER.Trojan;;
DesktopDoctor1.5.1.exe\data363;C:\DesktopDoctor1.5.1.exe;Probably DLOADER.Trojan;;
DesktopDoctor1.5.1.exe;C:\;Archive contains infected objects;Moved.;
rdafenj.exe;C:\;Trojan.DownLoad.5786;Deleted.;
RegUBP2b-Miss Casey.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
ComboFix.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe;Program.PsExec.171;;
ComboFix.exe;C:\Documents and Settings\Miss Casey\Desktop;Archive contains infected objects;Moved.;
SDFix2.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Miss Casey\Desktop\SDFix\SDFix2.exe;Tool.Prockill;;
SDFix2.exe;C:\Documents and Settings\Miss Casey\Desktop\SDFix;Archive contains infected objects;Moved.;
Process.exe;C:\Documents and Settings\Miss Casey\Desktop\SDFix\apps;Tool.Prockill;Moved.;
compwiz.exe.vir;C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard;Trojan.Fakealert;Deleted.;
WapCHK.dll.vir;C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard;Trojan.Fakealert;Deleted.;
A0050988.exe\data023;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0050988.exe;Probably DLOADER.Trojan;;
A0050988.exe\data363;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0050988.exe;Probably DLOADER.Trojan;;
A0050988.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Archive contains infected objects;Moved.;
A0050990.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Trojan.DownLoad.5786;Deleted.;
A0051186.reg;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Trojan.StartPage.1505;Deleted.;
A0051616.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0051616.exe;Tool.Prockill;;
A0051616.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Archive contains infected objects;Moved.;
A0051659.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Tool.Prockill;Moved.;
A0060677.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.TSAdvert;Moved.;
A0060895.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.MyWebSearch.2;Moved.;
A0063913.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Trojan.Virtumod;Deleted.;
A0066438.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Trojan.Virtumod;Deleted.;
A0069158.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069213.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069216.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069376.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069401.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069892.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0069932.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0070290.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0070308.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0070360.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0070962.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18;Adware.SearchColours;Moved.;
A0072425.exe\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP19\A0072425.exe;Program.PsExec.171;;
A0072425.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP19;Archive contains infected objects;Moved.;
A0072426.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP19\A0072426.exe;Tool.Prockill;;
A0072426.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP19;Archive contains infected objects;Moved.;
breakawayjade
2008-10-14, 15:41
not sure what you want from that online scan but this is everything that showed up.
Scan taken on 14 Oct 2008 12:38:11 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
File: user32.dll_
Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: b26b135ff1b9f60c9388b4a7d16f600b
Packers detected: -
Last file scanned at least one scanner reported something about: Setup+Patch.exe (MD5: d59757436aac8890c25057109328fce8, size: 1069056 bytes), detected by:
Scanner Malware name
A-Squared X
AntiVir X
ArcaVir X
Avast Win32:Trojan-gen {Other}
AVG Antivirus X
BitDefender Win32.Worm.P2P.Archivarius.B
ClamAV X
CPsecure Troj.W32.Agent.ecd
Dr.Web X
F-Prot Antivirus W32/Backdoor2.PMQ
F-Secure Anti-Virus Trojan-Dropper.Win32.Delf.chg
G DATA X
Ikarus Virus.Win32.Agent.OJX
Kaspersky Anti-Virus Trojan-Dropper.Win32.Delf.chg
NOD32 Win32/Archivarius.B
Norman Virus Control X
Panda Antivirus X
Sophos Antivirus X
VirusBuster X
VBA32 Trojan-Dropper.Win32.Delf.bvf
Two things, most of what the scans found where in your System Restore Program, the other things are bad entries that Combofix found and removed.
I can't emphasize enough how important it is for you to create a New Restore Point, please do not run Combofix until you have done so
System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points
Turn off System Restore.
Right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore on all Drives.
Click Apply, and then click OK.
Reboot your computer
Turn ON System Restore.
Right-click My Computer.
ClickProperties.
Click the System Restore tab.
UN-Check Turn off System Restore on all Drives.
Click Apply, and then click OK.
Create a new Restore Point <-- Very Important
Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You need to go into the Control Panel and switch to Catagory View to be able to Create a New Restore Point
System Restore Tutorial (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- If you need it
Lets double check and see if that file is still infected, according to Jotti, it looks ok.
Drag Combofix to the trash and lets grab a fresh copy and run the program
Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
breakawayjade
2008-10-15, 04:06
i restarted and turned back on whatever i needed to but when i went into control panel, i dont have a performance and maintenance folder....anywhere else it might be?
Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You need to go into the Control Panel and switch to Catagory View to be able to Create a New Restore Point
breakawayjade
2008-10-15, 06:06
ok, i dont know how to change it to catagory view and there is no folder titled performance and maintenance in control panel
Hello,
There are always more than one way into a program, you can do this
Click Start > All Programs > Accessories > System Tools, and then click System Restore > Create a Restore Point
Combofix will create a restore point for you, I was just being a bit more cautious, so drag the old Combofix to the trash and download and run a new copy and post the log please
Download Combofix from any of the links below, and save it to your desktop. <-- Important
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)
breakawayjade
2008-10-15, 18:23
um....the combo list is so long even half doesnt fit on one message, id have to post 4 or 5 messages just to get it all on there.?????
breakawayjade
2008-10-15, 18:25
half of it is system 32 files and the other half is files similar to this one
+ 2008-04-14 00:12:11 129,024 ------w C:\WINDOWS\ServicePackFiles\i386\xmlprov.dll <-----obviously not the exact same file each time.
Post the beginning and as much past this as will fit in one post
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
breakawayjade
2008-10-16, 15:41
ComboFix 08-10-14.07 - Miss Casey 2008-10-15 7:09:28.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.465 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
.
2008-10-13 16:14 . 2008-10-13 16:24 <DIR> d-------- C:\Documents and Settings\Miss Casey\DoctorWeb
2008-10-12 21:12 . 2008-10-13 10:01 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\system32\en
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-10 07:51 . 2008-10-10 07:51 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-10 07:38 . 2008-10-10 08:12 2,711 --a------ C:\WINDOWS\imsins.BAK
2008-10-10 07:32 . 2008-10-10 07:32 <DIR> d-------- C:\WINDOWS\EHome
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-13 06:16 --------- d-----w C:\Program Files\MSN Messenger
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 05:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
.
((((((((((((((((((((((((((((( snapshot@2008-10-06_19.18.50.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB938464_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB938464_0$\spuninst\updspapi.dll
- 2004-08-04 07:06:34 82,944 -c----w C:\WINDOWS\$NtUninstallKB946648$\msgsc.dll
+ 2004-08-04 07:06:34 82,944 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\spuninst\updspapi.dll
- 2006-07-13 08:48:58 202,240 -c----w C:\WINDOWS\$NtUninstallKB950762$\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\spuninst\updspapi.dll
- 2005-07-26 04:39:45 243,200 -c----w C:\WINDOWS\$NtUninstallKB950974$\es.dll
+ 2005-07-26 04:39:45 243,200 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\es.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\spuninst\updspapi.dll
- 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\$NtUninstallKB951066$\inetcomm.dll
+ 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\spuninst\updspapi.dll
- 2008-04-14 11:01:02 272,128 -c----w C:\WINDOWS\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 11:01:02 272,128 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376_0$\spuninst\updspapi.dll
- 2007-10-29 22:43:03 1,287,680 -c----w C:\WINDOWS\$NtUninstallKB951698$\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\spuninst\updspapi.dll
- 2004-08-04 11:00:00 138,496 -c----w C:\WINDOWS\$NtUninstallKB951748$\afd.sys
- 2008-02-20 05:32:43 148,992 -c----w C:\WINDOWS\$NtUninstallKB951748$\dnsapi.dll
- 2004-08-04 11:00:00 245,248 -c----w C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
- 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-04 11:00:00 138,496 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\afd.sys
+ 2008-02-20 05:32:43 148,992 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\dnsapi.dll
+ 2004-08-04 11:00:00 245,248 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\tcpip6.sys
- 2004-08-04 11:00:00 331,776 -c----w C:\WINDOWS\$NtUninstallKB952287$\msadce.dll
+ 2004-08-04 11:00:00 331,776 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\spuninst\updspapi.dll
- 2005-06-29 01:46:00 74,240 -c----w C:\WINDOWS\$NtUninstallKB952954$\mscms.dll
+ 2005-06-29 01:46:00 74,240 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\spuninst\updspapi.dll
- 2006-10-04 14:05:26 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
+ 2008-04-14 00:11:48 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
- 2004-08-04 11:00:00 1,852,416 ----a-w C:\WINDOWS\AppPatch\AcGenral.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
- 2004-08-04 11:00:00 450,048 -c--a-w C:\WINDOWS\AppPatch\AcLayers.dll
+ 2008-04-14 00:11:48 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
- 2004-08-04 11:00:00 137,728 -c--a-w C:\WINDOWS\AppPatch\AcLua.dll
+ 2008-04-14 00:11:48 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
- 2004-08-04 11:00:00 244,736 ----a-w C:\WINDOWS\AppPatch\AcSpecfc.dll
+ 2008-04-14 00:11:48 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
- 2004-08-04 11:00:00 116,224 -c--a-w C:\WINDOWS\AppPatch\AcXtrnal.dll
+ 2008-04-14 00:11:48 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
- 2008-06-13 13:10:50 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-06-13 11:05:51 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
- 2007-06-13 10:23:07 1,033,216 ----a-w C:\WINDOWS\explorer.exe
+ 2008-04-14 00:12:19 1,033,728 ----a-w C:\WINDOWS\explorer.exe
- 2004-08-04 11:00:00 34,816 -c--a-w C:\WINDOWS\Help\sniffpol.dll
+ 2008-04-14 00:12:06 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
- 2004-08-04 11:00:00 33,280 -c--a-w C:\WINDOWS\Help\sstub.dll
+ 2008-04-14 00:12:07 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
- 2004-08-04 11:00:00 279,040 -c--a-w C:\WINDOWS\Help\tshoot.dll
+ 2008-04-14 00:12:07 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
- 2005-05-26 23:22:01 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2008-04-14 00:12:21 10,752 ----a-w C:\WINDOWS\hh.exe
- 2004-08-04 11:00:00 220,160 -c--a-w C:\WINDOWS\ime\mscandui.dll
+ 2008-04-14 00:11:58 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
- 2004-08-04 11:00:00 130,048 -c--a-w C:\WINDOWS\ime\SOFTKBD.DLL
+ 2008-04-14 00:12:06 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
- 2004-08-04 11:00:00 62,976 -c--a-w C:\WINDOWS\ime\SPGRMR.dll
+ 2008-04-13 16:43:18 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
- 2004-08-04 11:00:00 250,880 -c--a-w C:\WINDOWS\ime\SPTIP.dll
+ 2008-04-14 00:12:06 250,368 ----a-w C:\WINDOWS\ime\sptip.dll
+ 2008-01-18 15:13:09 2,247 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscdsbl.bat
+ 2007-12-12 10:33:51 18,917 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscupdc.dll
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agentanm.dll
+ 2008-04-14 00:11:48 24,064 ----a-w C:\WINDOWS\msagent\agentanm.dll
- 2004-08-04 11:00:00 214,016 -c--a-w C:\WINDOWS\msagent\agentctl.dll
+ 2008-04-14 00:11:48 214,016 ----a-w C:\WINDOWS\msagent\agentctl.dll
- 2006-10-12 14:02:52 42,496 ----a-w C:\WINDOWS\msagent\agentdp2.dll
+ 2008-04-14 00:11:48 42,496 ----a-w C:\WINDOWS\msagent\agentdp2.dll
- 2007-03-09 13:58:57 57,344 ----a-w C:\WINDOWS\msagent\agentdpv.dll
+ 2008-04-14 00:11:48 57,344 ----a-w C:\WINDOWS\msagent\agentdpv.dll
- 2004-08-04 11:00:00 49,152 -c--a-w C:\WINDOWS\msagent\agentmpx.dll
+ 2008-04-14 00:11:48 49,152 ----a-w C:\WINDOWS\msagent\agentmpx.dll
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agentpsh.dll
+ 2008-04-14 00:11:48 24,064 ----a-w C:\WINDOWS\msagent\agentpsh.dll
- 2004-08-04 11:00:00 44,032 -c--a-w C:\WINDOWS\msagent\agentsr.dll
+ 2008-04-14 00:11:48 44,032 ----a-w C:\WINDOWS\msagent\agentsr.dll
- 2006-10-12 11:09:53 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2008-04-14 00:12:12 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agtintl.dll
+ 2008-04-14 00:11:49 24,064 ----a-w C:\WINDOWS\msagent\agtintl.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0405.dll
+ 2007-04-02 18:25:59 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0405.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0406.dll
+ 2007-04-02 18:25:59 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0406.dll
- 2004-08-04 11:00:00 21,504 -c--a-w C:\WINDOWS\msagent\intl\agt0407.dll
+ 2007-04-02 18:26:00 21,504 ----a-w C:\WINDOWS\msagent\intl\agt0407.dll
- 2004-08-04 11:00:00 22,016 -c--a-w C:\WINDOWS\msagent\intl\agt0408.dll
+ 2007-04-02 18:26:00 22,016 ----a-w C:\WINDOWS\msagent\intl\agt0408.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0409.dll
+ 2008-04-13 17:32:28 19,968 ----a-w C:\WINDOWS\msagent\intl\agt0409.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt040b.dll
+ 2007-04-02 18:26:00 19,456 ----a-w C:\WINDOWS\msagent\intl\agt040b.dll
- 2004-08-04 11:00:00 21,504 -c--a-w C:\WINDOWS\msagent\intl\agt040c.dll
+ 2007-04-02 18:26:00 21,504 ----a-w C:\WINDOWS\msagent\intl\agt040c.dll
- 2004-08-04 11:00:00 19,968 -c--a-w C:\WINDOWS\msagent\intl\agt040e.dll
+ 2007-04-02 18:26:00 19,968 ----a-w C:\WINDOWS\msagent\intl\agt040e.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0410.dll
+ 2007-04-02 18:26:00 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0410.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0413.dll
+ 2007-04-02 18:26:01 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0413.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0414.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0414.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0415.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0415.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\msagent\intl\agt0416.dll
+ 2007-04-02 18:26:01 20,480 ----a-w C:\WINDOWS\msagent\intl\agt0416.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0419.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0419.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt041d.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt041d.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt041f.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt041f.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0816.dll
+ 2007-04-02 18:26:02 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0816.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\msagent\intl\agt0c0a.dll
+ 2007-04-02 18:26:02 20,480 ----a-w C:\WINDOWS\msagent\intl\agt0c0a.dll
- 2004-08-04 11:00:00 39,936 -c--a-w C:\WINDOWS\msagent\mslwvtts.dll
+ 2008-04-14 00:12:00 39,936 ----a-w C:\WINDOWS\msagent\mslwvtts.dll
- 2006-06-03 11:40:49 33,792 ------w C:\WINDOWS\network diagnostic\custsat.dll
+ 2008-04-14 00:11:51 33,792 ------w C:\WINDOWS\network diagnostic\custsat.dll
- 2006-10-10 12:44:50 557,568 ------w C:\WINDOWS\network diagnostic\xpnetdiag.exe
+ 2008-04-13 18:53:32 558,080 ------w C:\WINDOWS\network diagnostic\xpnetdiag.exe
- 2004-08-04 11:00:00 69,120 ----a-w C:\WINDOWS\NOTEPAD.EXE
+ 2008-04-14 00:12:29 69,120 ----a-w C:\WINDOWS\notepad.exe
- 2004-08-04 11:00:00 768,512 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe
+ 2008-04-14 00:12:21 769,024 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
- 2004-08-04 11:00:00 743,936 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exe
+ 2008-04-14 00:12:21 744,448 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\HscUpd.exe
+ 2008-04-14 00:12:21 18,432 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\hscupd.exe
- 2004-08-04 11:00:00 158,208 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
+ 2008-04-14 00:12:27 169,984 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
- 2004-08-04 11:00:00 376,320 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msinfo.dll
+ 2008-04-14 00:11:59 376,832 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msinfo.dll
- 2004-08-04 11:00:00 102,400 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\pchshell.dll
+ 2008-04-14 00:12:02 102,912 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchshell.dll
- 2004-08-04 11:00:00 38,912 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
+ 2008-04-14 00:12:02 38,400 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
- 2005-02-03 13:02:16 77,915 -c--a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
+ 2008-10-10 15:07:33 77,915 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
- 2005-02-03 13:02:16 3,730 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2008-10-10 15:07:33 4,100 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
- 2004-08-04 11:00:00 150,528 -c--a-w C:\WINDOWS\pchealth\UploadLB\Binaries\UploadM.exe
+ 2008-04-14 00:12:38 150,528 ----a-w C:\WINDOWS\pchealth\UploadLB\Binaries\uploadm.exe
- 2004-08-04 11:00:00 151,552 -c--a-w C:\WINDOWS\PeerNet\sqldb20.dll
+ 2008-04-14 00:12:06 151,552 ----a-w C:\WINDOWS\PeerNet\sqldb20.dll
- 2004-08-04 11:00:00 462,848 -c--a-w C:\WINDOWS\PeerNet\sqlqp20.dll
+ 2008-04-14 00:12:06 462,848 ----a-w C:\WINDOWS\PeerNet\sqlqp20.dll
- 2004-08-04 11:00:00 110,592 -c--a-w C:\WINDOWS\PeerNet\sqlse20.dll
+ 2008-04-14 00:12:06 110,592 ----a-w C:\WINDOWS\PeerNet\sqlse20.dll
- 2004-08-04 11:00:00 146,432 ----a-w C:\WINDOWS\regedit.exe
+ 2008-04-14 00:12:32 146,432 ----a-w C:\WINDOWS\regedit.exe
+ 2008-04-13 18:46:18 53,376 ------w C:\WINDOWS\ServicePackFiles\i386\1394bus.sys
+ 2008-04-13 18:40:50 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\4mmdat.sys
+ 2008-04-13 18:46:20 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\61883.sys
+ 2008-04-14 00:11:48 100,352 ------w C:\WINDOWS\ServicePackFiles\i386\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 ------w C:\WINDOWS\ServicePackFiles\i386\aaclient.dll
+ 2004-08-04 05:32:22 231,552 ------w C:\WINDOWS\ServicePackFiles\i386\ac97ali.sys
+ 2004-08-04 05:32:32 84,480 ------w C:\WINDOWS\ServicePackFiles\i386\ac97via.sys
+ 2008-04-14 00:11:48 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\acadproc.dll
+ 2008-04-14 00:12:11 184,320 ------w C:\WINDOWS\ServicePackFiles\i386\accwiz.exe
+ 2008-04-14 00:11:48 1,852,928 ------w C:\WINDOWS\ServicePackFiles\i386\acgenral.dll
+ 2008-04-14 00:11:48 451,072 ------w C:\WINDOWS\ServicePackFiles\i386\aclayers.dll
+ 2008-04-14 00:11:48 141,312 ------w C:\WINDOWS\ServicePackFiles\i386\aclua.dll
+ 2008-04-14 00:11:48 115,712 ------w C:\WINDOWS\ServicePackFiles\i386\aclui.dll
+ 2008-04-13 18:36:35 187,776 ------w C:\WINDOWS\ServicePackFiles\i386\acpi.sys
+ 2008-04-14 00:11:48 245,248 ------w C:\WINDOWS\ServicePackFiles\i386\acspecfc.dll
+ 2008-04-14 00:11:48 193,536 ------w C:\WINDOWS\ServicePackFiles\i386\activeds.dll
+ 2008-04-14 00:12:12 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\actmovie.exe
+ 2008-04-14 00:11:48 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\actxprxy.dll
+ 2008-04-14 00:11:48 116,224 ------w C:\WINDOWS\ServicePackFiles\i386\acxtrnal.dll
+ 2008-04-14 00:11:48 20,540 ------w C:\WINDOWS\ServicePackFiles\i386\admin.dll
+ 2008-04-14 00:12:12 16,439 ------w C:\WINDOWS\ServicePackFiles\i386\admin.exe
+ 2004-08-04 05:32:24 10,880 ------w C:\WINDOWS\ServicePackFiles\i386\admjoy.sys
+ 2008-04-14 00:11:48 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\admparse.dll
+ 2008-04-14 00:11:48 175,616 ------w C:\WINDOWS\ServicePackFiles\i386\adsldp.dll
+ 2008-04-14 00:11:48 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\adsldpc.dll
+ 2008-04-14 00:11:48 68,096 ------w C:\WINDOWS\ServicePackFiles\i386\adsmsext.dll
+ 2008-04-14 00:11:48 263,680 ------w C:\WINDOWS\ServicePackFiles\i386\adsnt.dll
+ 2008-04-14 00:11:48 4,255 ------w C:\WINDOWS\ServicePackFiles\i386\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ------w C:\WINDOWS\ServicePackFiles\i386\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ------w C:\WINDOWS\ServicePackFiles\i386\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ------w C:\WINDOWS\ServicePackFiles\i386\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ------w C:\WINDOWS\ServicePackFiles\i386\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ------w C:\WINDOWS\ServicePackFiles\i386\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ------w C:\WINDOWS\ServicePackFiles\i386\adv11nt5.dll
+ 2008-04-14 00:11:48 617,472 ------w C:\WINDOWS\ServicePackFiles\i386\advapi32.dll
+ 2008-04-14 00:11:48 99,840 ------w C:\WINDOWS\ServicePackFiles\i386\advpack.dll
+ 2008-04-13 16:39:23 142,592 ------w C:\WINDOWS\ServicePackFiles\i386\aec.sys
+ 2008-04-13 19:19:23 138,112 ------w C:\WINDOWS\ServicePackFiles\i386\afd.sys
+ 2008-04-14 00:11:48 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agentanm.dll
+ 2008-04-14 00:11:48 214,016 ------w C:\WINDOWS\ServicePackFiles\i386\agentctl.dll
+ 2008-04-14 00:11:48 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\agentdp2.dll
+ 2008-04-14 00:11:48 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\agentdpv.dll
+ 2008-04-14 00:11:48 49,152 ------w C:\WINDOWS\ServicePackFiles\i386\agentmpx.dll
+ 2008-04-14 00:11:48 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agentpsh.dll
+ 2008-04-14 00:11:48 44,032 ------w C:\WINDOWS\ServicePackFiles\i386\agentsr.dll
+ 2008-04-14 00:12:12 256,512 ------w C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe
+ 2008-04-13 18:36:38 42,368 ------w C:\WINDOWS\ServicePackFiles\i386\agp440.sys
+ 2008-04-13 18:36:39 44,928 ------w C:\WINDOWS\ServicePackFiles\i386\agpcpq.sys
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0401.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0404.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0405.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0406.dll
+ 2007-04-02 18:26:00 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\agt0407.dll
+ 2007-04-02 18:26:00 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\agt0408.dll
+ 2008-04-13 17:32:28 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\agt0409.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt040b.dll
+ 2007-04-02 18:26:00 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\agt040c.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt040d.dll
+ 2007-04-02 18:26:00 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\agt040e.dll
+ 2007-04-02 18:26:00 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0410.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0411.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0412.dll
+ 2007-04-02 18:26:01 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0413.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0414.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0415.dll
+ 2007-04-02 18:26:01 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\agt0416.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0419.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt041d.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt041f.dll
+ 2007-04-02 18:26:02 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0804.dll
+ 2007-04-02 18:26:02 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0816.dll
+ 2007-04-02 18:26:02 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\agt0c0a.dll
+ 2008-04-14 00:11:49 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agtintl.dll
+ 2008-04-14 00:12:12 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\ahui.exe
+ 2008-04-14 00:12:12 44,544 ------w C:\WINDOWS\ServicePackFiles\i386\alg.exe
+ 2008-04-13 18:36:38 42,752 ------w C:\WINDOWS\ServicePackFiles\i386\alim1541.sys
+ 2008-04-14 00:11:49 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\alrsvc.dll
+ 2008-04-13 18:36:39 43,008 ------w C:\WINDOWS\ServicePackFiles\i386\amdagp.sys
+ 2008-04-13 18:31:32 37,376 ------w C:\WINDOWS\ServicePackFiles\i386\amdk6.sys
+ 2008-04-13 18:31:33 37,760 ------w C:\WINDOWS\ServicePackFiles\i386\amdk7.sys
+ 2008-04-14 00:11:49 70,656 ------w C:\WINDOWS\ServicePackFiles\i386\amstream.dll
+ 2004-08-04 05:31:20 36,224 ------w C:\WINDOWS\ServicePackFiles\i386\an983.sys
+ 2008-04-14 00:11:49 125,952 ------w C:\WINDOWS\ServicePackFiles\i386\apphelp.dll
+ 2008-04-14 00:11:49 331,264 ------w C:\WINDOWS\ServicePackFiles\i386\aqueue.dll
+ 2008-04-13 18:51:25 60,800 ------w C:\WINDOWS\ServicePackFiles\i386\arp1394.sys
+ 2008-04-14 00:11:49 65,024 ------w C:\WINDOWS\ServicePackFiles\i386\asycfilt.dll
+ 2008-04-13 18:57:27 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\asyncmac.sys
+ 2008-04-14 00:12:12 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\at.exe
+ 2008-04-13 18:40:30 96,512 ------w C:\WINDOWS\ServicePackFiles\i386\atapi.sys
+ 2004-08-04 05:29:30 56,623 ------w C:\WINDOWS\ServicePackFiles\i386\ati1btxx.sys
+ 2004-08-04 05:29:30 11,615 ------w C:\WINDOWS\ServicePackFiles\i386\ati1mdxx.sys
+ 2004-08-04 05:29:30 12,047 ------w C:\WINDOWS\ServicePackFiles\i386\ati1pdxx.sys
+ 2004-08-04 05:29:32 30,671 ------w C:\WINDOWS\ServicePackFiles\i386\ati1raxx.sys
+ 2004-08-04 05:29:32 63,663 ------w C:\WINDOWS\ServicePackFiles\i386\ati1rvxx.sys
+ 2004-08-04 05:29:32 26,367 ------w C:\WINDOWS\ServicePackFiles\i386\ati1snxx.sys
+ 2004-08-04 05:29:32 21,343 ------w C:\WINDOWS\ServicePackFiles\i386\ati1ttxx.sys
+ 2004-08-04 05:29:32 36,463 ------w C:\WINDOWS\ServicePackFiles\i386\ati1tuxx.sys
+ 2004-08-04 05:29:32 29,455 ------w C:\WINDOWS\ServicePackFiles\i386\ati1xbxx.sys
+ 2004-08-04 05:29:32 34,735 ------w C:\WINDOWS\ServicePackFiles\i386\ati1xsxx.sys
+ 2008-04-14 00:11:49 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ------w C:\WINDOWS\ServicePackFiles\i386\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ------w C:\WINDOWS\ServicePackFiles\i386\ati2dvag.dll
+ 2004-08-04 05:29:28 327,040 ------w C:\WINDOWS\ServicePackFiles\i386\ati2mtaa.sys
+ 2004-08-04 05:29:28 701,440 ------w C:\WINDOWS\ServicePackFiles\i386\ati2mtag.sys
+ 2008-04-14 00:11:49 870,784 ------w C:\WINDOWS\ServicePackFiles\i386\ati3d1ag.dll
+ 2008-04-14 00:11:49 1,057,760 ------w C:\WINDOWS\ServicePackFiles\i386\ati3d2ag.dll
+ 2008-04-14 00:11:50 1,888,992 ------w C:\WINDOWS\ServicePackFiles\i386\ati3duag.dll
+ 2004-08-04 05:29:28 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\atinbtxx.sys
+ 2004-08-04 05:29:30 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\atinmdxx.sys
+ 2004-08-04 05:29:30 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\atinpdxx.sys
+ 2004-08-04 05:29:30 52,224 ------w C:\WINDOWS\ServicePackFiles\i386\atinraxx.sys
+ 2004-08-04 05:29:32 104,960 ------w C:\WINDOWS\ServicePackFiles\i386\atinrvxx.sys
+ 2004-08-04 05:29:32 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\atinsnxx.sys
+ 2004-08-04 05:29:32 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\atinttxx.sys
+ 2004-08-04 05:29:32 73,216 ------w C:\WINDOWS\ServicePackFiles\i386\atintuxx.sys
+ 2004-08-04 05:29:32 31,744 ------w C:\WINDOWS\ServicePackFiles\i386\atinxbxx.sys
+ 2004-08-04 05:29:32 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\atinxsxx.sys
+ 2008-04-14 00:11:50 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ------w C:\WINDOWS\ServicePackFiles\i386\ativvaxx.dll
+ 2008-04-14 00:11:50 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\atl.dll
+ 2008-04-14 00:12:12 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\atmadm.exe
+ 2008-04-13 18:51:25 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\atmarpc.sys
+ 2008-04-14 00:09:01 285,696 ------w C:\WINDOWS\ServicePackFiles\i386\atmfd.dll
+ 2008-04-13 18:51:30 55,808 ------w C:\WINDOWS\ServicePackFiles\i386\atmlane.sys
+ 2008-04-14 00:11:50 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\atmlib.dll
+ 2008-04-14 00:12:12 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\attrib.exe
+ 2008-04-14 00:11:50 21,183 ------w C:\WINDOWS\ServicePackFiles\i386\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ------w C:\WINDOWS\ServicePackFiles\i386\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ------w C:\WINDOWS\ServicePackFiles\i386\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ------w C:\WINDOWS\ServicePackFiles\i386\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ------w C:\WINDOWS\ServicePackFiles\i386\atv10nt5.dll
+ 2008-04-14 00:11:50 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\audiosrv.dll
+ 2008-04-14 00:12:12 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\auditusr.exe
+ 2008-04-14 00:11:50 20,540 ------w C:\WINDOWS\ServicePackFiles\i386\author.dll
+ 2008-04-14 00:12:12 16,439 ------w C:\WINDOWS\ServicePackFiles\i386\author.exe
+ 2008-04-14 00:11:50 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\authz.dll
+ 2008-04-14 00:12:12 588,800 ------w C:\WINDOWS\ServicePackFiles\i386\autochk.exe
+ 2008-04-14 00:12:12 602,624 ------w C:\WINDOWS\ServicePackFiles\i386\autoconv.exe
+ 2008-04-14 00:12:13 580,608 ------w C:\WINDOWS\ServicePackFiles\i386\autofmt.exe
+ 2008-04-14 00:12:13 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\autolfn.exe
+ 2008-04-13 18:46:20 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\avc.sys
+ 2008-04-13 18:46:07 13,696 ------w C:\WINDOWS\ServicePackFiles\i386\avcstrm.sys
+ 2008-04-14 00:11:50 84,992 ------w C:\WINDOWS\ServicePackFiles\i386\avifil32.dll
+ 2008-04-14 00:11:50 233,472 ------w C:\WINDOWS\ServicePackFiles\i386\azroles.dll
+ 2008-04-14 00:11:50 52,736 ------w C:\WINDOWS\ServicePackFiles\i386\basesrv.dll
+ 2008-04-14 00:11:50 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\batmeter.dll
+ 2008-04-14 00:11:50 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\batt.dll
+ 2008-04-13 18:36:32 14,208 ------w C:\WINDOWS\ServicePackFiles\i386\battc.sys
+ 2008-04-13 18:46:21 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\bdasup.sys
+ 2008-04-14 00:11:50 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\bidispl.dll
+ 2008-04-14 00:11:50 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx2.dll
+ 2008-04-14 00:11:50 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx4.dll
+ 2008-04-14 00:12:13 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\blastcln.exe
+ 2008-04-13 18:53:23 71,552 ------w C:\WINDOWS\ServicePackFiles\i386\bridge.sys
+ 2008-04-13 17:03:24 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\browselc.dll
+ 2008-04-14 00:11:50 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\browser.dll
+ 2008-04-14 00:11:50 1,025,024 ------w C:\WINDOWS\ServicePackFiles\i386\browseui.dll
+ 2008-04-14 00:11:50 78,336 ------w C:\WINDOWS\ServicePackFiles\i386\browsewm.dll
+ 2008-04-14 00:11:50 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\bthci.dll
+ 2008-04-13 18:46:33 17,024 ------w C:\WINDOWS\ServicePackFiles\i386\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ------w C:\WINDOWS\ServicePackFiles\i386\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ------w C:\WINDOWS\ServicePackFiles\i386\bthpan.sys
+ 2008-04-13 18:46:32 273,024 ------w C:\WINDOWS\ServicePackFiles\i386\bthport.sys
+ 2008-04-13 18:46:31 36,480 ------w C:\WINDOWS\ServicePackFiles\i386\bthprint.sys
+ 2008-04-14 00:11:50 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\bthserv.dll
+ 2008-04-13 18:46:29 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\bthusb.sys
+ 2008-04-14 00:11:50 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\btpanui.dll
+ 2008-04-14 00:11:50 218,112 ------w C:\WINDOWS\ServicePackFiles\i386\c_g18030.dll
+ 2008-04-14 00:11:50 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\cabinet.dll
+ 2008-04-14 00:11:50 84,480 ------w C:\WINDOWS\ServicePackFiles\i386\cabview.dll
+ 2008-04-14 00:12:13 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\cacls.exe
+ 2008-04-14 00:11:50 385,024 ------w C:\WINDOWS\ServicePackFiles\i386\callcont.dll
+ 2008-04-14 00:11:50 121,856 ------w C:\WINDOWS\ServicePackFiles\i386\camext30.dll
+ 2008-04-14 00:11:50 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\camocx.dll
+ 2008-04-14 00:11:50 150,016 ------w C:\WINDOWS\ServicePackFiles\i386\capesnpn.dll
+ 2008-04-14 00:11:50 226,304 ------w C:\WINDOWS\ServicePackFiles\i386\catsrv.dll
+ 2008-04-14 00:11:50 85,504 ------w C:\WINDOWS\ServicePackFiles\i386\catsrvps.dll
+ 2008-04-14 00:11:50 625,664 ------w C:\WINDOWS\ServicePackFiles\i386\catsrvut.dll
+ 2008-04-13 18:46:23 17,024 ------w C:\WINDOWS\ServicePackFiles\i386\ccdecode.sys
+ 2008-04-13 19:14:21 63,744 ------w C:\WINDOWS\ServicePackFiles\i386\cdfs.sys
+ 2008-04-14 00:11:50 151,040 ------w C:\WINDOWS\ServicePackFiles\i386\cdfview.dll
+ 2008-04-14 00:11:50 66,560 ------w C:\WINDOWS\ServicePackFiles\i386\cdm.dll
+ 2008-04-14 00:11:50 2,091,520 ------w C:\WINDOWS\ServicePackFiles\i386\cdosys.dll
+ 2008-04-13 18:40:46 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
+ 2008-04-14 00:11:50 194,560 ------w C:\WINDOWS\ServicePackFiles\i386\certcli.dll
+ 2008-04-14 00:11:50 457,728 ------w C:\WINDOWS\ServicePackFiles\i386\certmgr.dll
+ 2008-04-14 00:11:50 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\cfgbkend.dll
+ 2008-04-14 00:09:05 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 ------w C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe
+ 2008-04-14 00:11:50 15,423 ------w C:\WINDOWS\ServicePackFiles\i386\ch7xxnt5.dll
+ 2008-04-13 18:40:58 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\changer.sys
+ 2008-04-14 00:11:50 148,480 ------w C:\WINDOWS\ServicePackFiles\i386\cic.dll
+ 2008-04-14 00:11:50 1,358,848 ------w C:\WINDOWS\ServicePackFiles\i386\cimwin32.dll
+ 2008-04-14 00:11:50 69,120 ------w C:\WINDOWS\ServicePackFiles\i386\ciodm.dll
+ 2008-04-14 00:12:14 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\cisvc.exe
+ 2008-04-13 19:16:22 49,536 ------w C:\WINDOWS\ServicePackFiles\i386\classpnp.sys
+ 2008-04-14 00:11:50 110,592 ------w C:\WINDOWS\ServicePackFiles\i386\clbcatex.dll
+ 2008-04-14 00:11:50 498,688 ------w C:\WINDOWS\ServicePackFiles\i386\clbcatq.dll
+ 2008-04-14 00:12:14 64,000 ------w C:\WINDOWS\ServicePackFiles\i386\cleanmgr.exe
+ 2008-04-14 00:11:50 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\cliconfg.dll
+ 2008-04-14 00:12:14 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\cliconfg.exe
+ 2008-04-14 00:12:14 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\clipbrd.exe
+ 2008-04-14 00:12:14 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\clipsrv.exe
+ 2008-04-14 00:11:50 58,368 ------w C:\WINDOWS\ServicePackFiles\i386\clusapi.dll
+ 2008-04-13 18:36:37 13,952 ------w C:\WINDOWS\ServicePackFiles\i386\cmbatt.sys
+ 2008-04-14 00:11:50 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\cmcfg32.dll
+ 2008-04-14 00:12:14 389,120 ------w C:\WINDOWS\ServicePackFiles\i386\cmd.exe
+ 2008-04-14 00:11:50 344,064 ------w C:\WINDOWS\ServicePackFiles\i386\cmdial32.dll
+ 2008-04-14 00:12:14 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\cmdl32.exe
+ 2008-04-14 00:12:15 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\cmmon32.exe
+ 2008-04-14 00:11:50 185,344 ------w C:\WINDOWS\ServicePackFiles\i386\cmprops.dll
+ 2008-04-14 00:11:50 13,312 ------w C:\WINDOWS\ServicePackFiles\i386\cmsetacl.dll
+ 2008-04-14 00:12:15 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\cmstp.exe
+ 2008-04-14 00:11:50 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\cmutil.dll
+ 2008-04-14 00:11:50 47,104 ------w C:\WINDOWS\ServicePackFiles\i386\cnbjmon.dll
+ 2008-04-14 00:11:50 79,360 ------w C:\WINDOWS\ServicePackFiles\i386\cnbjmon2.dll
+ 2008-04-13 16:44:16 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\cobramsg.dll
+ 2008-04-14 00:11:51 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\colbact.dll
+ 2008-04-14 00:11:51 28,160 ------w C:\WINDOWS\ServicePackFiles\i386\comaddin.dll
+ 2008-04-14 00:11:51 195,072 ------w C:\WINDOWS\ServicePackFiles\i386\comadmin.dll
+ 2008-04-14 00:11:51 617,472 ------w C:\WINDOWS\ServicePackFiles\i386\comctl32.dll
+ 2008-04-14 00:11:51 276,992 ------w C:\WINDOWS\ServicePackFiles\i386\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 ------w C:\WINDOWS\ServicePackFiles\i386\compatui.dll
+ 2008-04-13 18:36:37 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\compbatt.sys
+ 2008-04-14 00:11:51 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\compstui.dll
+ 2008-04-14 00:11:51 97,792 ------w C:\WINDOWS\ServicePackFiles\i386\comrepl.dll
+ 2008-04-14 00:12:15 9,728 ------w C:\WINDOWS\ServicePackFiles\i386\comrepl.exe
+ 2008-04-14 00:12:15 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\comrereg.exe
+ 2008-04-14 00:11:51 792,064 ------w C:\WINDOWS\ServicePackFiles\i386\comres.dll
+ 2008-04-14 00:11:51 274,944 ------w C:\WINDOWS\ServicePackFiles\i386\comsetup.dll
+ 2008-04-14 00:11:51 167,424 ------w C:\WINDOWS\ServicePackFiles\i386\comsnap.dll
+ 2008-04-14 00:11:51 1,267,200 ------w C:\WINDOWS\ServicePackFiles\i386\comsvcs.dll
+ 2008-04-14 00:11:51 539,648 ------w C:\WINDOWS\ServicePackFiles\i386\comuid.dll
+ 2008-04-14 00:12:15 1,032,192 ------w C:\WINDOWS\ServicePackFiles\i386\conf.exe
+ 2008-04-14 00:11:51 45,056 ------w C:\WINDOWS\ServicePackFiles\i386\confmrsl.dll
+ 2008-04-14 00:11:51 357,888 ------w C:\WINDOWS\ServicePackFiles\i386\confmsp.dll
+ 2008-04-14 00:12:15 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\conime.exe
+ 2008-04-14 00:11:51 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\corpol.dll
+ 2008-04-14 00:11:51 12,800 ------w C:\WINDOWS\ServicePackFiles\i386\credssp.dll
+ 2008-04-14 00:11:51 163,840 ------w C:\WINDOWS\ServicePackFiles\i386\credui.dll
+ 2008-04-13 18:31:32 36,736 ------w C:\WINDOWS\ServicePackFiles\i386\crusoe.sys
+ 2008-04-14 00:11:51 599,040 ------w C:\WINDOWS\ServicePackFiles\i386\crypt32.dll
+ 2008-04-14 00:11:51 74,752 ------w C:\WINDOWS\ServicePackFiles\i386\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\cryptext.dll
+ 2008-04-14 00:11:51 64,512 ------w C:\WINDOWS\ServicePackFiles\i386\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 ------w C:\WINDOWS\ServicePackFiles\i386\cryptui.dll
+ 2008-04-14 00:11:51 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\cscdll.dll
+ 2008-04-14 00:12:15 139,264 ------w C:\WINDOWS\ServicePackFiles\i386\cscript.exe
+ 2008-04-14 00:11:51 326,656 ------w C:\WINDOWS\ServicePackFiles\i386\cscui.dll
+ 2008-04-14 00:11:51 32,256 ------w C:\WINDOWS\ServicePackFiles\i386\csrsrv.dll
+ 2008-04-14 00:12:15 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\csrss.exe
+ 2008-04-14 00:12:16 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
+ 2008-04-14 00:11:51 249,856 ------w C:\WINDOWS\ServicePackFiles\i386\ctmasetp.dll
+ 2008-04-14 00:11:51 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\custsat.dll
+ 2004-08-04 05:32:26 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\cwrwdm.sys
+ 2008-04-14 00:11:51 1,179,648 ------w C:\WINDOWS\ServicePackFiles\i386\d3d8.dll
+ 2008-04-14 00:11:51 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\d3d8thk.dll
+ 2008-04-14 00:11:51 1,689,088 ------w C:\WINDOWS\ServicePackFiles\i386\d3d9.dll
+ 2008-04-14 00:11:51 824,320 ------w C:\WINDOWS\ServicePackFiles\i386\d3dim700.dll
+ 2008-04-14 00:11:51 1,054,208 ------w C:\WINDOWS\ServicePackFiles\i386\danim.dll
+ 2008-03-25 04:50:25 554,008 ------w C:\WINDOWS\ServicePackFiles\i386\dao360.dll
+ 2008-04-14 00:11:51 54,272 ------w C:\WINDOWS\ServicePackFiles\i386\dataclen.dll
+ 2008-04-14 00:11:51 165,376 ------w C:\WINDOWS\ServicePackFiles\i386\datime.dll
+ 2008-04-14 00:11:51 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\davclnt.dll
+ 2008-04-14 00:11:51 640,000 ------w C:\WINDOWS\ServicePackFiles\i386\dbghelp.dll
+ 2008-04-14 00:11:51 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\dbmsrpcn.dll
+ 2008-04-14 00:11:51 110,592 ------w C:\WINDOWS\ServicePackFiles\i386\dbnetlib.dll
+ 2008-04-14 00:11:51 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dbnmpntw.dll
+ 2008-04-14 00:25:26 1,804 ------w C:\WINDOWS\ServicePackFiles\i386\dcache.bin
+ 2008-04-14 00:11:51 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\dcap32.dll
+ 2008-04-14 00:11:51 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\dciman32.dll
+ 2008-04-14 00:12:16 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\dcomcnfg.exe
+ 2008-04-14 00:12:16 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\ddeshare.exe
+ 2008-04-14 00:11:51 279,552 ------w C:\WINDOWS\ServicePackFiles\i386\ddraw.dll
+ 2008-04-14 00:11:51 27,136 ------w C:\WINDOWS\ServicePackFiles\i386\ddrawex.dll
+ 2008-04-14 00:12:16 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\defrag.exe
+ 2008-04-14 00:11:51 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\devenum.dll
+ 2008-04-14 00:11:51 282,624 ------w C:\WINDOWS\ServicePackFiles\i386\devmgr.dll
+ 2008-04-14 00:12:16 82,944 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgfat.exe
+ 2008-04-14 00:12:16 105,472 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgntfs.exe
+ 2008-04-14 00:11:51 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgsnap.dll
+ 2008-04-14 00:11:51 124,416 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgui.dll
+ 2008-04-14 00:11:51 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dfsshlex.dll
+ 2008-04-14 00:11:51 111,104 ------w C:\WINDOWS\ServicePackFiles\i386\dgnet.dll
+ 2008-04-14 00:11:51 126,976 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpcsvc.dll
+ 2008-04-14 00:11:52 379,904 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpqec.dll
+ 2008-04-14 00:12:17 539,136 ------w C:\WINDOWS\ServicePackFiles\i386\dialer.exe
+ 2008-04-14 00:12:17 87,040 ------w C:\WINDOWS\ServicePackFiles\i386\diantz.exe
+ 2004-07-17 18:41:44 884,712 ------w C:\WINDOWS\ServicePackFiles\i386\digcore.exe
+ 2008-04-14 00:11:52 68,608 ------w C:\WINDOWS\ServicePackFiles\i386\digest.dll
+ 2008-04-14 00:11:52 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\dimsroam.dll
+ 2008-04-14 00:11:52 158,720 ------w C:\WINDOWS\ServicePackFiles\i386\dinput.dll
+ 2008-04-14 00:11:52 181,760 ------w C:\WINDOWS\ServicePackFiles\i386\dinput8.dll
+ 2008-04-14 00:11:52 86,528 ------w C:\WINDOWS\ServicePackFiles\i386\directdb.dll
+ 2008-04-13 18:40:47 36,352 ------w C:\WINDOWS\ServicePackFiles\i386\disk.sys
+ 2008-04-14 00:11:52 1,504,256 ------w C:\WINDOWS\ServicePackFiles\i386\diskcopy.dll
+ 2008-04-13 18:40:44 14,208 ------w C:\WINDOWS\ServicePackFiles\i386\diskdump.sys
+ 2008-04-14 00:12:17 163,840 ------w C:\WINDOWS\ServicePackFiles\i386\diskpart.exe
+ 2008-04-14 00:11:52 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\dispex.dll
+ 2008-04-14 00:12:17 5,120 ------w C:\WINDOWS\ServicePackFiles\i386\dllhost.exe
+ 2008-04-13 18:40:51 8,320 ------w C:\WINDOWS\ServicePackFiles\i386\dlttape.sys
+ 2008-04-14 00:12:17 224,768 ------w C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe
+ 2008-04-14 00:11:52 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dmband.dll
+ 2008-04-13 18:44:48 799,744 ------w C:\WINDOWS\ServicePackFiles\i386\dmboot.sys
+ 2008-04-14 00:11:52 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\dmcompos.dll
+ 2008-04-14 00:11:52 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\dmdlgs.dll
+ 2008-04-14 00:11:52 200,704 ------w C:\WINDOWS\ServicePackFiles\i386\dmdskmgr.dll
+ 2008-04-14 00:11:52 181,248 ------w C:\WINDOWS\ServicePackFiles\i386\dmime.dll
+ 2008-04-13 18:44:46 153,344 ------w C:\WINDOWS\ServicePackFiles\i386\dmio.sys
+ 2008-04-14 00:11:52 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\dmloader.dll
+ 2008-04-14 00:12:17 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\dmremote.exe
+ 2008-04-14 00:11:52 82,432 ------w C:\WINDOWS\ServicePackFiles\i386\dmscript.dll
+ 2008-04-14 00:11:52 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\dmserver.dll
+ 2008-04-14 00:11:52 105,984 ------w C:\WINDOWS\ServicePackFiles\i386\dmstyle.dll
+ 2008-04-14 00:11:52 103,424 ------w C:\WINDOWS\ServicePackFiles\i386\dmsynth.dll
+ 2008-04-14 00:11:52 104,448 ------w C:\WINDOWS\ServicePackFiles\i386\dmusic.dll
+ 2008-04-13 18:45:01 52,864 ------w C:\WINDOWS\ServicePackFiles\i386\dmusic.sys
+ 2008-04-14 00:11:52 52,224 ------w C:\WINDOWS\ServicePackFiles\i386\dmutil.dll
+ 2008-04-14 00:11:52 147,968 ------w C:\WINDOWS\ServicePackFiles\i386\dnsapi.dll
+ 2008-04-14 00:11:52 45,568 ------w C:\WINDOWS\ServicePackFiles\i386\dnsrslvr.dll
+ 2008-04-14 00:11:52 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\docprop2.dll
+ 2004-08-04 11:00:00 53,840 ------w C:\WINDOWS\ServicePackFiles\i386\dosx.exe
+ 2008-04-14 00:11:52 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\dot3cfg.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\dot3clnt.dll
+ 2008-04-14 00:11:52 9,216 ------w C:\WINDOWS\ServicePackFiles\i386\dot3dlg.dll
+ 2008-04-14 00:11:52 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ------w C:\WINDOWS\ServicePackFiles\i386\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ------w C:\WINDOWS\ServicePackFiles\i386\dot3ui.dll
+ 2008-04-13 18:39:46 206,976 ------w C:\WINDOWS\ServicePackFiles\i386\dot4.sys
+ 2008-04-13 21:00:49 103,424 ------w C:\WINDOWS\ServicePackFiles\i386\dpcdll.dll
+ 2008-04-14 00:12:17 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\dplaysvr.exe
+ 2008-04-14 00:11:52 229,888 ------w C:\WINDOWS\ServicePackFiles\i386\dplayx.dll
+ 2008-04-14 00:11:52 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\dpmodemx.dll
+ 2008-04-14 00:09:19 3,072 ------w C:\WINDOWS\ServicePackFiles\i386\dpnaddr.dll
+ 2008-04-14 00:11:52 375,296 ------w C:\WINDOWS\ServicePackFiles\i386\dpnet.dll
+ 2008-04-14 00:11:52 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\dpnhpast.dll
+ 2008-04-14 00:11:52 60,928 ------w C:\WINDOWS\ServicePackFiles\i386\dpnhupnp.dll
+ 2008-04-14 00:09:20 3,072 ------w C:\WINDOWS\ServicePackFiles\i386\dpnlobby.dll
+ 2008-04-14 00:12:17 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\dpnsvr.exe
+ 2008-04-14 00:11:52 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\dpvacm.dll
+ 2008-04-14 00:11:52 212,480 ------w C:\WINDOWS\ServicePackFiles\i386\dpvoice.dll
+ 2008-04-14 00:12:18 83,456 ------w C:\WINDOWS\ServicePackFiles\i386\dpvsetup.exe
+ 2008-04-14 00:11:52 116,736 ------w C:\WINDOWS\ServicePackFiles\i386\dpvvox.dll
+ 2008-04-14 00:11:52 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\dpwsockx.dll
+ 2008-04-13 18:45:14 60,160 ------w C:\WINDOWS\ServicePackFiles\i386\drmk.sys
+ 2008-04-13 18:45:13 2,944 ------w C:\WINDOWS\ServicePackFiles\i386\drmkaud.sys
+ 2008-04-14 00:11:52 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\drprov.dll
+ 2004-08-04 11:00:00 4,656 ------w C:\WINDOWS\ServicePackFiles\i386\ds16gt.dll
+ 2008-04-14 00:11:52 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\ds32gt.dll
+ 2008-04-14 00:11:52 181,248 ------w C:\WINDOWS\ServicePackFiles\i386\dsdmo.dll
+ 2008-04-14 00:11:52 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\dsdmoprp.dll
+ 2008-04-14 00:11:52 92,672 ------w C:\WINDOWS\ServicePackFiles\i386\dskquota.dll
+ 2008-04-14 00:11:52 155,648 ------w C:\WINDOWS\ServicePackFiles\i386\dskquoui.dll
+ 2008-04-14 00:11:52 367,616 ------w C:\WINDOWS\ServicePackFiles\i386\dsound.dll
+ 2008-04-14 00:11:52 1,293,824 ------w C:\WINDOWS\ServicePackFiles\i386\dsound3d.dll
+ 2008-04-14 00:11:52 142,848 ------w C:\WINDOWS\ServicePackFiles\i386\dsprop.dll
+ 2008-04-13 17:09:30 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\dsprpres.dll
+ 2008-04-14 00:11:52 239,104 ------w C:\WINDOWS\ServicePackFiles\i386\dsquery.dll
+ 2008-04-14 00:11:52 51,200 ------w C:\WINDOWS\ServicePackFiles\i386\dssec.dll
+ 2008-04-13 17:37:57 138,752 ------w C:\WINDOWS\ServicePackFiles\i386\dssenh.dll
+ 2008-04-14 00:11:52 113,152 ------w C:\WINDOWS\ServicePackFiles\i386\dsuiext.dll
+ 2008-04-14 00:11:52 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\dswave.dll
+ 2008-04-14 00:12:18 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\dumprep.exe
+ 2008-04-14 00:11:52 304,128 ------w C:\WINDOWS\ServicePackFiles\i386\duser.dll
+ 2008-04-14 00:12:18 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\dvdupgrd.exe
+ 2008-04-14 00:12:18 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\dwwin.exe
+ 2008-04-14 00:11:52 619,008 ------w C:\WINDOWS\ServicePackFiles\i386\dx7vb.dll
+ 2008-04-14 00:11:52 1,227,264 ------w C:\WINDOWS\ServicePackFiles\i386\dx8vb.dll
+ 2008-04-14 00:12:18 1,298,432 ------w C:\WINDOWS\ServicePackFiles\i386\dxdiag.exe
+ 2008-04-14 00:11:52 2,113,536 ------w C:\WINDOWS\ServicePackFiles\i386\dxdiagn.dll
+ 2008-04-13 18:38:29 71,168 ------w C:\WINDOWS\ServicePackFiles\i386\dxg.sys
+ 2008-04-14 00:11:52 357,888 ------w C:\WINDOWS\ServicePackFiles\i386\dxtmsft.dll
+ 2008-04-14 00:11:52 205,312 ------w C:\WINDOWS\ServicePackFiles\i386\dxtrans.dll
+ 2008-04-14 00:11:52 30,720 ------w C:\WINDOWS\ServicePackFiles\i386\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ------w C:\WINDOWS\ServicePackFiles\i386\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ------w C:\WINDOWS\ServicePackFiles\i386\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ------w C:\WINDOWS\ServicePackFiles\i386\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\eapsvc.dll
+ 2008-04-14 00:11:52 175,616 ------w C:\WINDOWS\ServicePackFiles\i386\ediskeer.dll
+ 2008-04-14 00:11:53 183,296 ------w C:\WINDOWS\ServicePackFiles\i386\els.dll
+ 2008-04-14 00:11:53 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\encapi.dll
+ 2008-04-14 00:11:53 186,880 ------w C:\WINDOWS\ServicePackFiles\i386\encdec.dll
+ 2008-04-13 16:26:02 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\ep9res.dll
+ 2004-07-17 18:39:36 120,320 ------w C:\WINDOWS\ServicePackFiles\i386\epcl5res.dll
+ 2008-04-14 00:11:53 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\ersvc.dll
+ 2008-04-14 00:11:53 246,272 ------w C:\WINDOWS\ServicePackFiles\i386\es.dll
+ 2008-04-14 00:11:53 1,082,368 ------w C:\WINDOWS\ServicePackFiles\i386\esent.dll
+ 2008-04-14 00:11:53 247,808 ------w C:\WINDOWS\ServicePackFiles\i386\esscli.dll
+ 2004-08-04 05:32:28 137,088 ------w C:\WINDOWS\ServicePackFiles\i386\essm2e.sys
+ 2008-04-14 00:12:19 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\eudcedit.exe
+ 2008-04-14 00:11:53 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
+ 2008-04-14 00:11:53 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\evntagnt.dll
+ 2008-04-14 00:12:19 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\evntcmd.exe
+ 2008-04-14 00:11:53 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\evntrprv.dll
+ 2008-04-14 00:12:19 92,160 ------w C:\WINDOWS\ServicePackFiles\i386\evntwin.exe
+ 2008-04-14 00:12:19 1,033,728 ------w C:\WINDOWS\ServicePackFiles\i386\explorer.exe
+ 2008-04-14 00:11:53 380,445 ------w C:\WINDOWS\ServicePackFiles\i386\expsrv.dll
+ 2008-04-14 00:11:53 55,808 ------w C:\WINDOWS\ServicePackFiles\i386\extmgr.dll
+ 2008-04-14 00:12:19 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\extrac32.exe
+ 2008-04-14 00:11:53 125,952 ------w C:\WINDOWS\ServicePackFiles\i386\exts.dll
+ 2008-04-14 00:09:30 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\f3ahvoas.dll
+ 2008-04-13 19:14:29 143,744 ------w C:\WINDOWS\ServicePackFiles\i386\fastfat.sys
+ 2008-04-14 00:11:53 472,064 ------w C:\WINDOWS\ServicePackFiles\i386\fastprox.dll
+ 2008-04-14 00:11:53 80,384 ------w C:\WINDOWS\ServicePackFiles\i386\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\faxpatch.exe
+ 2008-04-13 18:40:25 27,392 ------w C:\WINDOWS\ServicePackFiles\i386\fdc.sys
+ 2008-04-14 00:11:53 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\feclient.dll
+ 2008-04-14 00:11:53 337,920 ------w C:\WINDOWS\ServicePackFiles\i386\filemgmt.dll
+ 2008-04-14 00:12:20 27,136 ------w C:\WINDOWS\ServicePackFiles\i386\findstr.exe
+ 2008-04-13 18:33:28 44,544 ------w C:\WINDOWS\ServicePackFiles\i386\fips.sys
+ 2008-04-14 00:11:53 87,552 ------w C:\WINDOWS\ServicePackFiles\i386\fldrclnr.dll
+ 2008-04-13 18:40:25 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\flpydisk.sys
+ 2008-04-14 00:11:53 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\fltlib.dll
+ 2008-04-14 00:12:20 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\fltmc.exe
+ 2008-04-13 18:32:59 129,792 ------w C:\WINDOWS\ServicePackFiles\i386\fltmgr.sys
+ 2008-04-14 00:11:53 382,976 ------w C:\WINDOWS\ServicePackFiles\i386\fontext.dll
+ 2008-04-14 00:11:53 80,896 ------w C:\WINDOWS\ServicePackFiles\i386\fontsub.dll
+ 2008-04-14 00:12:20 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\fontview.exe
+ 2008-04-14 00:12:20 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\forcedos.exe
+ 2004-08-04 05:31:24 34,173 ------w C:\WINDOWS\ServicePackFiles\i386\forehe.sys
+ 2008-04-14 00:12:42 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\format.com
+ 2008-04-14 00:11:53 32,828 ------w C:\WINDOWS\ServicePackFiles\i386\fp40ext.dll
+ 2008-04-14 00:11:53 184,435 ------w C:\WINDOWS\ServicePackFiles\i386\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 ------w C:\WINDOWS\ServicePackFiles\i386\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 ------w C:\WINDOWS\ServicePackFiles\i386\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 ------w C:\WINDOWS\ServicePackFiles\i386\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 ------w C:\WINDOWS\ServicePackFiles\i386\fp4atxt.dll
+ 2008-04-14 00:11:53 618,605 ------w C:\WINDOWS\ServicePackFiles\i386\fp4autl.dll
+ 2008-04-14 00:11:53 41,020 ------w C:\WINDOWS\ServicePackFiles\i386\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 ------w C:\WINDOWS\ServicePackFiles\i386\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 ------w C:\WINDOWS\ServicePackFiles\i386\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 ------w C:\WINDOWS\ServicePackFiles\i386\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 ------w C:\WINDOWS\ServicePackFiles\i386\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 ------w C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe
+ 2008-04-14 00:12:20 24,632 ------w C:\WINDOWS\ServicePackFiles\i386\fpadmcgi.exe
+ 2008-04-14 00:11:53 20,541 ------w C:\WINDOWS\ServicePackFiles\i386\fpadmdll.dll
+ 2008-04-14 00:12:20 188,494 ------w C:\WINDOWS\ServicePackFiles\i386\fpcount.exe
+ 2008-04-14 00:11:53 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\fpencode.dll
+ 2008-04-14 00:11:53 20,541 ------w C:\WINDOWS\ServicePackFiles\i386\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 ------w C:\WINDOWS\ServicePackFiles\i386\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 ------w C:\WINDOWS\ServicePackFiles\i386\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 ------w C:\WINDOWS\ServicePackFiles\i386\fpremadm.exe
+ 2008-04-14 00:12:20 28,728 ------w C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe
+ 2008-04-14 00:09:33 9,344 ------w C:\WINDOWS\ServicePackFiles\i386\framebuf.dll
+ 2008-04-14 00:11:53 185,344 ------w C:\WINDOWS\ServicePackFiles\i386\framedyn.dll
+ 2008-04-14 00:12:20 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\fsquirt.exe
+ 2008-04-14 00:12:20 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\ftp.exe
+ 2008-04-14 00:11:53 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\fwcfg.dll
+ 2008-04-14 00:11:53 451,584 ------w C:\WINDOWS\ServicePackFiles\i386\fxsapi.dll
+ 2008-04-14 00:12:21 142,848 ------w C:\WINDOWS\ServicePackFiles\i386\fxsclnt.exe
+ 2008-04-14 00:11:54 72,192 ------w C:\WINDOWS\ServicePackFiles\i386\fxscom.dll
+ 2008-04-14 00:11:54 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\fxscomex.dll
+ 2008-04-14 00:12:21 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\fxscover.exe
+ 2008-04-14 00:11:54 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\fxsdrv.dll
+ 2008-04-14 00:11:54 55,296 ------w C:\WINDOWS\ServicePackFiles\i386\fxsevent.dll
+ 2008-04-14 00:11:54 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\fxsext32.dll
+ 2008-04-14 00:11:54 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\fxsmon.dll
+ 2008-04-14 00:11:54 132,608 ------w C:\WINDOWS\ServicePackFiles\i386\fxsocm.dll
+ 2008-04-14 00:11:54 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\fxsperf.dll
+ 2008-04-14 00:09:33 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\fxsres.dll
+ 2008-04-14 00:11:54 562,176 ------w C:\WINDOWS\ServicePackFiles\i386\fxsst.dll
+ 2008-04-14 00:12:21 267,776 ------w C:\WINDOWS\ServicePackFiles\i386\fxssvc.exe
+ 2008-04-14 00:11:54 246,272 ------w C:\WINDOWS\ServicePackFiles\i386\fxst30.dll
+ 2008-04-14 00:11:54 397,312 ------w C:\WINDOWS\ServicePackFiles\i386\fxstiff.dll
+ 2008-04-14 00:11:54 154,112 ------w C:\WINDOWS\ServicePackFiles\i386\fxsui.dll
+ 2008-04-14 00:11:54 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\fxswzrd.dll
+ 2008-04-14 00:11:54 400,384 ------w C:\WINDOWS\ServicePackFiles\i386\fxsxp32.dll
+ 2008-04-13 18:36:40 46,464 ------w C:\WINDOWS\ServicePackFiles\i386\gagp30kx.sys
+ 2008-04-13 18:45:29 10,624 ------w C:\WINDOWS\ServicePackFiles\i386\gameenum.sys
+ 2008-04-13 18:45:32 59,136 ------w C:\WINDOWS\ServicePackFiles\i386\gckernel.sys
+ 2008-04-14 00:11:54 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\gdi32.dll
+ 2008-04-14 00:11:54 122,880 ------w C:\WINDOWS\ServicePackFiles\i386\glu32.dll
+ 2004-08-04 11:00:00 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\gpkcsp.dll
+ 2006-12-31 01:26:44 9,728 ------w C:\WINDOWS\ServicePackFiles\i386\gpkrsrc.dll
+ 2008-04-14 00:12:21 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\grpconv.exe
+ 2008-04-13 18:40:21 28,288 ------w C:\WINDOWS\ServicePackFiles\i386\grserial.sys
+ 2008-04-14 00:11:54 133,120 ------w C:\WINDOWS\ServicePackFiles\i386\guitrn.dll
+ 2008-04-14 00:11:54 115,200 ------w C:\WINDOWS\ServicePackFiles\i386\guitrna.dll
+ 2008-04-14 00:11:54 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\h323cc.dll
+ 2008-04-14 00:11:54 614,912 ------w C:\WINDOWS\ServicePackFiles\i386\h323msp.dll
+ 2008-04-13 18:31:32 105,344 ------w C:\WINDOWS\ServicePackFiles\i386\hal.dll
+ 2008-04-13 18:31:28 131,840 ------w C:\WINDOWS\ServicePackFiles\i386\halaacpi.dll
+ 2008-04-13 18:31:27 81,152 ------w C:\WINDOWS\ServicePackFiles\i386\halacpi.dll
+ 2008-04-13 18:31:28 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\halapic.dll
+ 2008-04-13 18:31:28 134,400 ------w C:\WINDOWS\ServicePackFiles\i386\halmacpi.dll
+ 2008-04-13 18:31:32 152,576 ------w C:\WINDOWS\ServicePackFiles\i386\halmps.dll
+ 2008-04-13 18:31:31 77,696 ------w C:\WINDOWS\ServicePackFiles\i386\halsp.dll
+ 2008-04-14 00:11:54 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\hccoin.dll
+ 2008-04-13 16:36:05 144,384 ------w C:\WINDOWS\ServicePackFiles\i386\hdaudbus.sys
+ 2008-04-14 00:12:21 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\help.exe
+ 2008-04-14 00:12:21 769,024 ------w C:\WINDOWS\ServicePackFiles\i386\helpctr.exe
+ 2008-04-14 00:12:21 744,448 ------w C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe
+ 2008-04-14 00:12:21 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\hh.exe
+ 2008-04-14 00:11:54 41,472 ------w C:\WINDOWS\ServicePackFiles\i386\hhsetup.dll
+ 2008-04-14 00:11:54 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\hid.dll
+ 2008-04-13 18:36:38 20,352 ------w C:\WINDOWS\ServicePackFiles\i386\hidbatt.sys
+ 2008-04-13 18:46:30 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\hidbth.sys
+ 2008-04-13 18:45:26 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\hidclass.sys
+ 2008-04-13 18:45:26 19,200 ------w C:\WINDOWS\ServicePackFiles\i386\hidir.sys
+ 2008-04-13 18:45:22 24,960 ------w C:\WINDOWS\ServicePackFiles\i386\hidparse.sys
+ 2008-04-14 00:11:54 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\hidserv.dll
+ 2008-04-13 18:45:27 10,368 ------w C:\WINDOWS\ServicePackFiles\i386\hidusb.sys
+ 2008-04-14 00:11:54 72,704 ------w C:\WINDOWS\ServicePackFiles\i386\hlink.dll
+ 2008-04-14 00:11:54 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\hmmapi.dll
+ 2008-04-14 00:11:54 344,064 ------w C:\WINDOWS\ServicePackFiles\i386\hnetcfg.dll
+ 2008-04-14 00:11:54 330,752 ------w C:\WINDOWS\ServicePackFiles\i386\hnetwiz.dll
+ 2008-04-14 00:11:54 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\hostmib.dll
+ 2008-04-14 00:11:54 144,896 ------w C:\WINDOWS\ServicePackFiles\i386\hotplug.dll
+ 2008-04-14 00:11:54 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\hpcjrr.dll
+ 2008-04-14 00:11:54 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\hpcjrrps.dll
+ 2008-04-14 00:11:54 87,552 ------w C:\WINDOWS\ServicePackFiles\i386\hpfud50.dll
+ 2008-04-14 00:12:21 18,432 ------w C:\WINDOWS\ServicePackFiles\i386\hscupd.exe
+ 2004-08-04 05:41:48 220,032 ------w C:\WINDOWS\ServicePackFiles\i386\hsfbs2s2.sys
+ 2008-04-14 00:11:54 32,285 ------w C:\WINDOWS\ServicePackFiles\i386\hsfcisp2.dll
+ 2004-08-04 05:41:50 685,056 ------w C:\WINDOWS\ServicePackFiles\i386\hsfcxts2.sys
+ 2004-08-04 05:41:56 1,041,536 ------w C:\WINDOWS\ServicePackFiles\i386\hsfdpsp2.sys
+ 2008-04-13 18:53:53 264,832 ------w C:\WINDOWS\ServicePackFiles\i386\http.sys
+ 2008-04-14 00:11:54 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\httpapi.dll
+ 2008-04-14 00:11:54 41,984 ------w C:\WINDOWS\ServicePackFiles\i386\htui.dll
+ 2008-04-14 00:11:54 347,136 ------w C:\WINDOWS\ServicePackFiles\i386\hypertrm.dll
+ 2008-04-13 18:41:22 8,576 ------w C:\WINDOWS\ServicePackFiles\i386\i2omgmt.sys
breakawayjade
Help me out here, look through your Combofix log, do you still see this or is it gone??????????
C:\WINDOWS\system32\user32.dll ... is infected !!
breakawayjade
2008-10-16, 23:54
i dont see it! :) but where is all that other crap coming from?
i dont see it! but where is all that other crap coming from? I don't know, most or all of it is legit.
Do this, post the entire Combofix log, break it up into 3 or 4 sections and post them all using the submit reply, take as many replies as you need to post the entire log, dont miss any of it
breakawayjade
2008-10-17, 02:48
ComboFix 08-10-14.07 - Miss Casey 2008-10-15 7:09:28.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.465 [GMT -7:00]
Running from: C:\Documents and Settings\Miss Casey\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
.
2008-10-13 16:14 . 2008-10-13 16:24 <DIR> d-------- C:\Documents and Settings\Miss Casey\DoctorWeb
2008-10-12 21:12 . 2008-10-13 10:01 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\system32\en
2008-10-10 08:02 . 2008-10-10 08:02 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-10 07:51 . 2008-10-10 07:51 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-10 07:38 . 2008-10-10 08:12 2,711 --a------ C:\WINDOWS\imsins.BAK
2008-10-10 07:32 . 2008-10-10 07:32 <DIR> d-------- C:\WINDOWS\EHome
2008-10-06 18:23 . 2008-10-06 18:23 <DIR> d-------- C:\_OTMoveIt
2008-10-05 20:44 . 2008-10-05 20:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\Miss Casey\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-10-05 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 14:03 . 2008-09-10 00:08 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 14:03 . 2008-09-10 00:08 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:27 . 2008-10-04 15:47 59,392 --a------ C:\sisonvnp.exe
2008-09-27 10:37 . 2008-09-27 10:37 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
2008-09-20 12:30 . 2008-09-27 10:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-20 12:30 . 2008-09-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-13 06:16 --------- d-----w C:\Program Files\MSN Messenger
2008-10-02 13:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 03:14 90,112 ----a-w C:\WINDOWS\DUMP3306.tmp
2008-09-15 13:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 18:17 --------- d-----w C:\Program Files\DefenderPro AntiSpy
2008-09-11 18:15 --------- d-----w C:\Program Files\MSN Games
2008-09-05 20:55 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\LimeWire
2008-08-30 17:53 --------- d-----w C:\Program Files\Palm
2008-08-29 16:17 --------- d-----w C:\Program Files\World of Warcraft
2008-08-24 05:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 15:49 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\AdobeUM
2008-08-20 12:31 --------- d-----w C:\Program Files\DivX
2008-08-16 19:41 --------- d-----w C:\Program Files\Common Files\Real
2008-08-16 19:36 --------- d-----w C:\Program Files\Google
2008-08-16 19:36 --------- d-----w C:\Documents and Settings\Miss Casey\Application Data\PlayFirst
2008-08-16 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 19:22 --------- d-----w C:\Program Files\Java
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 05:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2007-08-28 03:57 24,140,200 ----a-w C:\Documents and Settings\Miss Casey\DivXInstaller.exe
2006-11-26 04:10 936,500 --sh--w C:\WINDOWS\java\apas.bak1
2006-11-28 20:50 943,803 --sh--w C:\WINDOWS\java\apas.bak2
.
((((((((((((((((((((((((((((( snapshot@2008-10-06_19.18.50.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB938464_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB938464_0$\spuninst\updspapi.dll
- 2004-08-04 07:06:34 82,944 -c----w C:\WINDOWS\$NtUninstallKB946648$\msgsc.dll
+ 2004-08-04 07:06:34 82,944 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB946648_0$\spuninst\updspapi.dll
- 2006-07-13 08:48:58 202,240 -c----w C:\WINDOWS\$NtUninstallKB950762$\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB950762_0$\spuninst\updspapi.dll
- 2005-07-26 04:39:45 243,200 -c----w C:\WINDOWS\$NtUninstallKB950974$\es.dll
+ 2005-07-26 04:39:45 243,200 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\es.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB950974_0$\spuninst\updspapi.dll
- 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\$NtUninstallKB951066$\inetcomm.dll
+ 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951066_0$\spuninst\updspapi.dll
- 2008-04-14 11:01:02 272,128 -c----w C:\WINDOWS\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 11:01:02 272,128 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376-v2_0$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376_0$\spuninst\updspapi.dll
- 2007-10-29 22:43:03 1,287,680 -c----w C:\WINDOWS\$NtUninstallKB951698$\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951698_0$\spuninst\updspapi.dll
- 2004-08-04 11:00:00 138,496 -c----w C:\WINDOWS\$NtUninstallKB951748$\afd.sys
- 2008-02-20 05:32:43 148,992 -c----w C:\WINDOWS\$NtUninstallKB951748$\dnsapi.dll
- 2004-08-04 11:00:00 245,248 -c----w C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
- 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-04 11:00:00 138,496 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\afd.sys
+ 2008-02-20 05:32:43 148,992 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\dnsapi.dll
+ 2004-08-04 11:00:00 245,248 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c----w C:\WINDOWS\$NtUninstallKB951748_0$\tcpip6.sys
- 2004-08-04 11:00:00 331,776 -c----w C:\WINDOWS\$NtUninstallKB952287$\msadce.dll
+ 2004-08-04 11:00:00 331,776 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB952287_0$\spuninst\updspapi.dll
- 2005-06-29 01:46:00 74,240 -c----w C:\WINDOWS\$NtUninstallKB952954$\mscms.dll
+ 2005-06-29 01:46:00 74,240 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB952954_0$\spuninst\updspapi.dll
- 2006-10-04 14:05:26 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
+ 2008-04-14 00:11:48 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
- 2004-08-04 11:00:00 1,852,416 ----a-w C:\WINDOWS\AppPatch\AcGenral.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
- 2004-08-04 11:00:00 450,048 -c--a-w C:\WINDOWS\AppPatch\AcLayers.dll
+ 2008-04-14 00:11:48 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
- 2004-08-04 11:00:00 137,728 -c--a-w C:\WINDOWS\AppPatch\AcLua.dll
+ 2008-04-14 00:11:48 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
- 2004-08-04 11:00:00 244,736 ----a-w C:\WINDOWS\AppPatch\AcSpecfc.dll
+ 2008-04-14 00:11:48 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
- 2004-08-04 11:00:00 116,224 -c--a-w C:\WINDOWS\AppPatch\AcXtrnal.dll
+ 2008-04-14 00:11:48 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
- 2008-06-13 13:10:50 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-06-13 11:05:51 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
- 2007-06-13 10:23:07 1,033,216 ----a-w C:\WINDOWS\explorer.exe
+ 2008-04-14 00:12:19 1,033,728 ----a-w C:\WINDOWS\explorer.exe
- 2004-08-04 11:00:00 34,816 -c--a-w C:\WINDOWS\Help\sniffpol.dll
+ 2008-04-14 00:12:06 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
- 2004-08-04 11:00:00 33,280 -c--a-w C:\WINDOWS\Help\sstub.dll
+ 2008-04-14 00:12:07 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
- 2004-08-04 11:00:00 279,040 -c--a-w C:\WINDOWS\Help\tshoot.dll
+ 2008-04-14 00:12:07 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
- 2005-05-26 23:22:01 10,752 ----a-w C:\WINDOWS\hh.exe
+ 2008-04-14 00:12:21 10,752 ----a-w C:\WINDOWS\hh.exe
- 2004-08-04 11:00:00 220,160 -c--a-w C:\WINDOWS\ime\mscandui.dll
+ 2008-04-14 00:11:58 220,160 ----a-w C:\WINDOWS\ime\mscandui.dll
- 2004-08-04 11:00:00 130,048 -c--a-w C:\WINDOWS\ime\SOFTKBD.DLL
+ 2008-04-14 00:12:06 130,048 ----a-w C:\WINDOWS\ime\softkbd.dll
- 2004-08-04 11:00:00 62,976 -c--a-w C:\WINDOWS\ime\SPGRMR.dll
+ 2008-04-13 16:43:18 62,976 ----a-w C:\WINDOWS\ime\spgrmr.dll
- 2004-08-04 11:00:00 250,880 -c--a-w C:\WINDOWS\ime\SPTIP.dll
+ 2008-04-14 00:12:06 250,368 ----a-w C:\WINDOWS\ime\sptip.dll
+ 2008-01-18 15:13:09 2,247 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscdsbl.bat
+ 2007-12-12 10:33:51 18,917 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 ------w C:\WINDOWS\Installer\tsclientmsitrans\tscupdc.dll
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agentanm.dll
+ 2008-04-14 00:11:48 24,064 ----a-w C:\WINDOWS\msagent\agentanm.dll
- 2004-08-04 11:00:00 214,016 -c--a-w C:\WINDOWS\msagent\agentctl.dll
+ 2008-04-14 00:11:48 214,016 ----a-w C:\WINDOWS\msagent\agentctl.dll
- 2006-10-12 14:02:52 42,496 ----a-w C:\WINDOWS\msagent\agentdp2.dll
+ 2008-04-14 00:11:48 42,496 ----a-w C:\WINDOWS\msagent\agentdp2.dll
- 2007-03-09 13:58:57 57,344 ----a-w C:\WINDOWS\msagent\agentdpv.dll
+ 2008-04-14 00:11:48 57,344 ----a-w C:\WINDOWS\msagent\agentdpv.dll
- 2004-08-04 11:00:00 49,152 -c--a-w C:\WINDOWS\msagent\agentmpx.dll
+ 2008-04-14 00:11:48 49,152 ----a-w C:\WINDOWS\msagent\agentmpx.dll
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agentpsh.dll
+ 2008-04-14 00:11:48 24,064 ----a-w C:\WINDOWS\msagent\agentpsh.dll
- 2004-08-04 11:00:00 44,032 -c--a-w C:\WINDOWS\msagent\agentsr.dll
+ 2008-04-14 00:11:48 44,032 ----a-w C:\WINDOWS\msagent\agentsr.dll
- 2006-10-12 11:09:53 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2008-04-14 00:12:12 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
- 2004-08-04 11:00:00 24,064 -c--a-w C:\WINDOWS\msagent\agtintl.dll
+ 2008-04-14 00:11:49 24,064 ----a-w C:\WINDOWS\msagent\agtintl.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0405.dll
+ 2007-04-02 18:25:59 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0405.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0406.dll
+ 2007-04-02 18:25:59 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0406.dll
- 2004-08-04 11:00:00 21,504 -c--a-w C:\WINDOWS\msagent\intl\agt0407.dll
+ 2007-04-02 18:26:00 21,504 ----a-w C:\WINDOWS\msagent\intl\agt0407.dll
- 2004-08-04 11:00:00 22,016 -c--a-w C:\WINDOWS\msagent\intl\agt0408.dll
+ 2007-04-02 18:26:00 22,016 ----a-w C:\WINDOWS\msagent\intl\agt0408.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0409.dll
+ 2008-04-13 17:32:28 19,968 ----a-w C:\WINDOWS\msagent\intl\agt0409.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt040b.dll
+ 2007-04-02 18:26:00 19,456 ----a-w C:\WINDOWS\msagent\intl\agt040b.dll
- 2004-08-04 11:00:00 21,504 -c--a-w C:\WINDOWS\msagent\intl\agt040c.dll
+ 2007-04-02 18:26:00 21,504 ----a-w C:\WINDOWS\msagent\intl\agt040c.dll
- 2004-08-04 11:00:00 19,968 -c--a-w C:\WINDOWS\msagent\intl\agt040e.dll
+ 2007-04-02 18:26:00 19,968 ----a-w C:\WINDOWS\msagent\intl\agt040e.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0410.dll
+ 2007-04-02 18:26:00 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0410.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0413.dll
+ 2007-04-02 18:26:01 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0413.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0414.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0414.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0415.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0415.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\msagent\intl\agt0416.dll
+ 2007-04-02 18:26:01 20,480 ----a-w C:\WINDOWS\msagent\intl\agt0416.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt0419.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt0419.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt041d.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt041d.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\msagent\intl\agt041f.dll
+ 2007-04-02 18:26:01 19,456 ----a-w C:\WINDOWS\msagent\intl\agt041f.dll
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\msagent\intl\agt0816.dll
+ 2007-04-02 18:26:02 20,992 ----a-w C:\WINDOWS\msagent\intl\agt0816.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\msagent\intl\agt0c0a.dll
+ 2007-04-02 18:26:02 20,480 ----a-w C:\WINDOWS\msagent\intl\agt0c0a.dll
- 2004-08-04 11:00:00 39,936 -c--a-w C:\WINDOWS\msagent\mslwvtts.dll
+ 2008-04-14 00:12:00 39,936 ----a-w C:\WINDOWS\msagent\mslwvtts.dll
- 2006-06-03 11:40:49 33,792 ------w C:\WINDOWS\network diagnostic\custsat.dll
+ 2008-04-14 00:11:51 33,792 ------w C:\WINDOWS\network diagnostic\custsat.dll
- 2006-10-10 12:44:50 557,568 ------w C:\WINDOWS\network diagnostic\xpnetdiag.exe
+ 2008-04-13 18:53:32 558,080 ------w C:\WINDOWS\network diagnostic\xpnetdiag.exe
- 2004-08-04 11:00:00 69,120 ----a-w C:\WINDOWS\NOTEPAD.EXE
+ 2008-04-14 00:12:29 69,120 ----a-w C:\WINDOWS\notepad.exe
- 2004-08-04 11:00:00 768,512 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe
+ 2008-04-14 00:12:21 769,024 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
- 2004-08-04 11:00:00 743,936 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\HelpSvc.exe
+ 2008-04-14 00:12:21 744,448 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\HscUpd.exe
+ 2008-04-14 00:12:21 18,432 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\hscupd.exe
- 2004-08-04 11:00:00 158,208 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
+ 2008-04-14 00:12:27 169,984 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
- 2004-08-04 11:00:00 376,320 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msinfo.dll
+ 2008-04-14 00:11:59 376,832 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msinfo.dll
- 2004-08-04 11:00:00 102,400 -c--a-w C:\WINDOWS\pchealth\helpctr\binaries\pchshell.dll
+ 2008-04-14 00:12:02 102,912 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchshell.dll
- 2004-08-04 11:00:00 38,912 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
+ 2008-04-14 00:12:02 38,400 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
- 2005-02-03 13:02:16 77,915 -c--a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
+ 2008-10-10 15:07:33 77,915 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
- 2005-02-03 13:02:16 3,730 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2008-10-10 15:07:33 4,100 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
- 2004-08-04 11:00:00 150,528 -c--a-w C:\WINDOWS\pchealth\UploadLB\Binaries\UploadM.exe
+ 2008-04-14 00:12:38 150,528 ----a-w C:\WINDOWS\pchealth\UploadLB\Binaries\uploadm.exe
- 2004-08-04 11:00:00 151,552 -c--a-w C:\WINDOWS\PeerNet\sqldb20.dll
+ 2008-04-14 00:12:06 151,552 ----a-w C:\WINDOWS\PeerNet\sqldb20.dll
- 2004-08-04 11:00:00 462,848 -c--a-w C:\WINDOWS\PeerNet\sqlqp20.dll
+ 2008-04-14 00:12:06 462,848 ----a-w C:\WINDOWS\PeerNet\sqlqp20.dll
- 2004-08-04 11:00:00 110,592 -c--a-w C:\WINDOWS\PeerNet\sqlse20.dll
+ 2008-04-14 00:12:06 110,592 ----a-w C:\WINDOWS\PeerNet\sqlse20.dll
- 2004-08-04 11:00:00 146,432 ----a-w C:\WINDOWS\regedit.exe
+ 2008-04-14 00:12:32 146,432 ----a-w C:\WINDOWS\regedit.exe
+ 2008-04-13 18:46:18 53,376 ------w C:\WINDOWS\ServicePackFiles\i386\1394bus.sys
+ 2008-04-13 18:40:50 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\4mmdat.sys
+ 2008-04-13 18:46:20 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\61883.sys
+ 2008-04-14 00:11:48 100,352 ------w C:\WINDOWS\ServicePackFiles\i386\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 ------w C:\WINDOWS\ServicePackFiles\i386\aaclient.dll
+ 2004-08-04 05:32:22 231,552 ------w C:\WINDOWS\ServicePackFiles\i386\ac97ali.sys
+ 2004-08-04 05:32:32 84,480 ------w C:\WINDOWS\ServicePackFiles\i386\ac97via.sys
+ 2008-04-14 00:11:48 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\acadproc.dll
+ 2008-04-14 00:12:11 184,320 ------w C:\WINDOWS\ServicePackFiles\i386\accwiz.exe
+ 2008-04-14 00:11:48 1,852,928 ------w C:\WINDOWS\ServicePackFiles\i386\acgenral.dll
+ 2008-04-14 00:11:48 451,072 ------w C:\WINDOWS\ServicePackFiles\i386\aclayers.dll
+ 2008-04-14 00:11:48 141,312 ------w C:\WINDOWS\ServicePackFiles\i386\aclua.dll
+ 2008-04-14 00:11:48 115,712 ------w C:\WINDOWS\ServicePackFiles\i386\aclui.dll
+ 2008-04-13 18:36:35 187,776 ------w C:\WINDOWS\ServicePackFiles\i386\acpi.sys
+ 2008-04-14 00:11:48 245,248 ------w C:\WINDOWS\ServicePackFiles\i386\acspecfc.dll
+ 2008-04-14 00:11:48 193,536 ------w C:\WINDOWS\ServicePackFiles\i386\activeds.dll
+ 2008-04-14 00:12:12 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\actmovie.exe
+ 2008-04-14 00:11:48 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\actxprxy.dll
+ 2008-04-14 00:11:48 116,224 ------w C:\WINDOWS\ServicePackFiles\i386\acxtrnal.dll
+ 2008-04-14 00:11:48 20,540 ------w C:\WINDOWS\ServicePackFiles\i386\admin.dll
+ 2008-04-14 00:12:12 16,439 ------w C:\WINDOWS\ServicePackFiles\i386\admin.exe
+ 2004-08-04 05:32:24 10,880 ------w C:\WINDOWS\ServicePackFiles\i386\admjoy.sys
+ 2008-04-14 00:11:48 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\admparse.dll
+ 2008-04-14 00:11:48 175,616 ------w C:\WINDOWS\ServicePackFiles\i386\adsldp.dll
+ 2008-04-14 00:11:48 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\adsldpc.dll
+ 2008-04-14 00:11:48 68,096 ------w C:\WINDOWS\ServicePackFiles\i386\adsmsext.dll
+ 2008-04-14 00:11:48 263,680 ------w C:\WINDOWS\ServicePackFiles\i386\adsnt.dll
+ 2008-04-14 00:11:48 4,255 ------w C:\WINDOWS\ServicePackFiles\i386\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ------w C:\WINDOWS\ServicePackFiles\i386\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ------w C:\WINDOWS\ServicePackFiles\i386\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ------w C:\WINDOWS\ServicePackFiles\i386\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ------w C:\WINDOWS\ServicePackFiles\i386\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ------w C:\WINDOWS\ServicePackFiles\i386\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ------w C:\WINDOWS\ServicePackFiles\i386\adv11nt5.dll
+ 2008-04-14 00:11:48 617,472 ------w C:\WINDOWS\ServicePackFiles\i386\advapi32.dll
+ 2008-04-14 00:11:48 99,840 ------w C:\WINDOWS\ServicePackFiles\i386\advpack.dll
+ 2008-04-13 16:39:23 142,592 ------w C:\WINDOWS\ServicePackFiles\i386\aec.sys
+ 2008-04-13 19:19:23 138,112 ------w C:\WINDOWS\ServicePackFiles\i386\afd.sys
+ 2008-04-14 00:11:48 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agentanm.dll
+ 2008-04-14 00:11:48 214,016 ------w C:\WINDOWS\ServicePackFiles\i386\agentctl.dll
+ 2008-04-14 00:11:48 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\agentdp2.dll
+ 2008-04-14 00:11:48 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\agentdpv.dll
+ 2008-04-14 00:11:48 49,152 ------w C:\WINDOWS\ServicePackFiles\i386\agentmpx.dll
+ 2008-04-14 00:11:48 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agentpsh.dll
+ 2008-04-14 00:11:48 44,032 ------w C:\WINDOWS\ServicePackFiles\i386\agentsr.dll
+ 2008-04-14 00:12:12 256,512 ------w C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe
+ 2008-04-13 18:36:38 42,368 ------w C:\WINDOWS\ServicePackFiles\i386\agp440.sys
+ 2008-04-13 18:36:39 44,928 ------w C:\WINDOWS\ServicePackFiles\i386\agpcpq.sys
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0401.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0404.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0405.dll
+ 2007-04-02 18:25:59 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0406.dll
+ 2007-04-02 18:26:00 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\agt0407.dll
+ 2007-04-02 18:26:00 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\agt0408.dll
+ 2008-04-13 17:32:28 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\agt0409.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt040b.dll
+ 2007-04-02 18:26:00 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\agt040c.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt040d.dll
+ 2007-04-02 18:26:00 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\agt040e.dll
+ 2007-04-02 18:26:00 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0410.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0411.dll
+ 2007-04-02 18:26:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0412.dll
+ 2007-04-02 18:26:01 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0413.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0414.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0415.dll
+ 2007-04-02 18:26:01 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\agt0416.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0419.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt041d.dll
+ 2007-04-02 18:26:01 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt041f.dll
+ 2007-04-02 18:26:02 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\agt0804.dll
+ 2007-04-02 18:26:02 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\agt0816.dll
+ 2007-04-02 18:26:02 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\agt0c0a.dll
+ 2008-04-14 00:11:49 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\agtintl.dll
+ 2008-04-14 00:12:12 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\ahui.exe
+ 2008-04-14 00:12:12 44,544 ------w C:\WINDOWS\ServicePackFiles\i386\alg.exe
+ 2008-04-13 18:36:38 42,752 ------w C:\WINDOWS\ServicePackFiles\i386\alim1541.sys
+ 2008-04-14 00:11:49 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\alrsvc.dll
+ 2008-04-13 18:36:39 43,008 ------w C:\WINDOWS\ServicePackFiles\i386\amdagp.sys
+ 2008-04-13 18:31:32 37,376 ------w C:\WINDOWS\ServicePackFiles\i386\amdk6.sys
+ 2008-04-13 18:31:33 37,760 ------w C:\WINDOWS\ServicePackFiles\i386\amdk7.sys
+ 2008-04-14 00:11:49 70,656 ------w C:\WINDOWS\ServicePackFiles\i386\amstream.dll
+ 2004-08-04 05:31:20 36,224 ------w C:\WINDOWS\ServicePackFiles\i386\an983.sys
+ 2008-04-14 00:11:49 125,952 ------w C:\WINDOWS\ServicePackFiles\i386\apphelp.dll
+ 2008-04-14 00:11:49 331,264 ------w C:\WINDOWS\ServicePackFiles\i386\aqueue.dll
+ 2008-04-13 18:51:25 60,800 ------w C:\WINDOWS\ServicePackFiles\i386\arp1394.sys
+ 2008-04-14 00:11:49 65,024 ------w C:\WINDOWS\ServicePackFiles\i386\asycfilt.dll
+ 2008-04-13 18:57:27 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\asyncmac.sys
+ 2008-04-14 00:12:12 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\at.exe
+ 2008-04-13 18:40:30 96,512 ------w C:\WINDOWS\ServicePackFiles\i386\atapi.sys
+ 2004-08-04 05:29:30 56,623 ------w C:\WINDOWS\ServicePackFiles\i386\ati1btxx.sys
+ 2004-08-04 05:29:30 11,615 ------w C:\WINDOWS\ServicePackFiles\i386\ati1mdxx.sys
+ 2004-08-04 05:29:30 12,047 ------w C:\WINDOWS\ServicePackFiles\i386\ati1pdxx.sys
+ 2004-08-04 05:29:32 30,671 ------w C:\WINDOWS\ServicePackFiles\i386\ati1raxx.sys
+ 2004-08-04 05:29:32 63,663 ------w C:\WINDOWS\ServicePackFiles\i386\ati1rvxx.sys
+ 2004-08-04 05:29:32 26,367 ------w C:\WINDOWS\ServicePackFiles\i386\ati1snxx.sys
+ 2004-08-04 05:29:32 21,343 ------w C:\WINDOWS\ServicePackFiles\i386\ati1ttxx.sys
+ 2004-08-04 05:29:32 36,463 ------w C:\WINDOWS\ServicePackFiles\i386\ati1tuxx.sys
+ 2004-08-04 05:29:32 29,455 ------w C:\WINDOWS\ServicePackFiles\i386\ati1xbxx.sys
+ 2004-08-04 05:29:32 34,735 ------w C:\WINDOWS\ServicePackFiles\i386\ati1xsxx.sys
+ 2008-04-14 00:11:49 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ------w C:\WINDOWS\ServicePackFiles\i386\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ------w C:\WINDOWS\ServicePackFiles\i386\ati2dvag.dll
+ 2004-08-04 05:29:28 327,040 ------w C:\WINDOWS\ServicePackFiles\i386\ati2mtaa.sys
+ 2004-08-04 05:29:28 701,440 ------w C:\WINDOWS\ServicePackFiles\i386\ati2mtag.sys
+ 2008-04-14 00:11:49 870,784 ------w C:\WINDOWS\ServicePackFiles\i386\ati3d1ag.dll
+ 2008-04-14 00:11:49 1,057,760 ------w C:\WINDOWS\ServicePackFiles\i386\ati3d2ag.dll
+ 2008-04-14 00:11:50 1,888,992 ------w C:\WINDOWS\ServicePackFiles\i386\ati3duag.dll
+ 2004-08-04 05:29:28 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\atinbtxx.sys
+ 2004-08-04 05:29:30 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\atinmdxx.sys
+ 2004-08-04 05:29:30 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\atinpdxx.sys
+ 2004-08-04 05:29:30 52,224 ------w C:\WINDOWS\ServicePackFiles\i386\atinraxx.sys
+ 2004-08-04 05:29:32 104,960 ------w C:\WINDOWS\ServicePackFiles\i386\atinrvxx.sys
+ 2004-08-04 05:29:32 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\atinsnxx.sys
+ 2004-08-04 05:29:32 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\atinttxx.sys
+ 2004-08-04 05:29:32 73,216 ------w C:\WINDOWS\ServicePackFiles\i386\atintuxx.sys
+ 2004-08-04 05:29:32 31,744 ------w C:\WINDOWS\ServicePackFiles\i386\atinxbxx.sys
+ 2004-08-04 05:29:32 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\atinxsxx.sys
+ 2008-04-14 00:11:50 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ------w C:\WINDOWS\ServicePackFiles\i386\ativvaxx.dll
+ 2008-04-14 00:11:50 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\atl.dll
+ 2008-04-14 00:12:12 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\atmadm.exe
+ 2008-04-13 18:51:25 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\atmarpc.sys
+ 2008-04-14 00:09:01 285,696 ------w C:\WINDOWS\ServicePackFiles\i386\atmfd.dll
+ 2008-04-13 18:51:30 55,808 ------w C:\WINDOWS\ServicePackFiles\i386\atmlane.sys
+ 2008-04-14 00:11:50 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\atmlib.dll
+ 2008-04-14 00:12:12 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\attrib.exe
+ 2008-04-14 00:11:50 21,183 ------w C:\WINDOWS\ServicePackFiles\i386\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ------w C:\WINDOWS\ServicePackFiles\i386\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ------w C:\WINDOWS\ServicePackFiles\i386\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ------w C:\WINDOWS\ServicePackFiles\i386\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ------w C:\WINDOWS\ServicePackFiles\i386\atv10nt5.dll
+ 2008-04-14 00:11:50 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\audiosrv.dll
+ 2008-04-14 00:12:12 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\auditusr.exe
+ 2008-04-14 00:11:50 20,540 ------w C:\WINDOWS\ServicePackFiles\i386\author.dll
+ 2008-04-14 00:12:12 16,439 ------w C:\WINDOWS\ServicePackFiles\i386\author.exe
+ 2008-04-14 00:11:50 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\authz.dll
+ 2008-04-14 00:12:12 588,800 ------w C:\WINDOWS\ServicePackFiles\i386\autochk.exe
+ 2008-04-14 00:12:12 602,624 ------w C:\WINDOWS\ServicePackFiles\i386\autoconv.exe
+ 2008-04-14 00:12:13 580,608 ------w C:\WINDOWS\ServicePackFiles\i386\autofmt.exe
+ 2008-04-14 00:12:13 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\autolfn.exe
+ 2008-04-13 18:46:20 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\avc.sys
+ 2008-04-13 18:46:07 13,696 ------w C:\WINDOWS\ServicePackFiles\i386\avcstrm.sys
+ 2008-04-14 00:11:50 84,992 ------w C:\WINDOWS\ServicePackFiles\i386\avifil32.dll
+ 2008-04-14 00:11:50 233,472 ------w C:\WINDOWS\ServicePackFiles\i386\azroles.dll
+ 2008-04-14 00:11:50 52,736 ------w C:\WINDOWS\ServicePackFiles\i386\basesrv.dll
+ 2008-04-14 00:11:50 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\batmeter.dll
+ 2008-04-14 00:11:50 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\batt.dll
+ 2008-04-13 18:36:32 14,208 ------w C:\WINDOWS\ServicePackFiles\i386\battc.sys
+ 2008-04-13 18:46:21 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\bdasup.sys
+ 2008-04-14 00:11:50 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\bidispl.dll
+ 2008-04-14 00:11:50 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx2.dll
+ 2008-04-14 00:11:50 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\bitsprx4.dll
+ 2008-04-14 00:12:13 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\blastcln.exe
+ 2008-04-13 18:53:23 71,552 ------w C:\WINDOWS\ServicePackFiles\i386\bridge.sys
+ 2008-04-13 17:03:24 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\browselc.dll
+ 2008-04-14 00:11:50 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\browser.dll
+ 2008-04-14 00:11:50 1,025,024 ------w C:\WINDOWS\ServicePackFiles\i386\browseui.dll
+ 2008-04-14 00:11:50 78,336 ------w C:\WINDOWS\ServicePackFiles\i386\browsewm.dll
+ 2008-04-14 00:11:50 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\bthci.dll
+ 2008-04-13 18:46:33 17,024 ------w C:\WINDOWS\ServicePackFiles\i386\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ------w C:\WINDOWS\ServicePackFiles\i386\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ------w C:\WINDOWS\ServicePackFiles\i386\bthpan.sys
+ 2008-04-13 18:46:32 273,024 ------w C:\WINDOWS\ServicePackFiles\i386\bthport.sys
+ 2008-04-13 18:46:31 36,480 ------w C:\WINDOWS\ServicePackFiles\i386\bthprint.sys
+ 2008-04-14 00:11:50 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\bthserv.dll
+ 2008-04-13 18:46:29 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\bthusb.sys
+ 2008-04-14 00:11:50 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\btpanui.dll
+ 2008-04-14 00:11:50 218,112 ------w C:\WINDOWS\ServicePackFiles\i386\c_g18030.dll
+ 2008-04-14 00:11:50 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\cabinet.dll
+ 2008-04-14 00:11:50 84,480 ------w C:\WINDOWS\ServicePackFiles\i386\cabview.dll
+ 2008-04-14 00:12:13 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\cacls.exe
+ 2008-04-14 00:11:50 385,024 ------w C:\WINDOWS\ServicePackFiles\i386\callcont.dll
+ 2008-04-14 00:11:50 121,856 ------w C:\WINDOWS\ServicePackFiles\i386\camext30.dll
+ 2008-04-14 00:11:50 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\camocx.dll
+ 2008-04-14 00:11:50 150,016 ------w C:\WINDOWS\ServicePackFiles\i386\capesnpn.dll
+ 2008-04-14 00:11:50 226,304 ------w C:\WINDOWS\ServicePackFiles\i386\catsrv.dll
+ 2008-04-14 00:11:50 85,504 ------w C:\WINDOWS\ServicePackFiles\i386\catsrvps.dll
+ 2008-04-14 00:11:50 625,664 ------w C:\WINDOWS\ServicePackFiles\i386\catsrvut.dll
+ 2008-04-13 18:46:23 17,024 ------w C:\WINDOWS\ServicePackFiles\i386\ccdecode.sys
+ 2008-04-13 19:14:21 63,744 ------w C:\WINDOWS\ServicePackFiles\i386\cdfs.sys
+ 2008-04-14 00:11:50 151,040 ------w C:\WINDOWS\ServicePackFiles\i386\cdfview.dll
+ 2008-04-14 00:11:50 66,560 ------w C:\WINDOWS\ServicePackFiles\i386\cdm.dll
+ 2008-04-14 00:11:50 2,091,520 ------w C:\WINDOWS\ServicePackFiles\i386\cdosys.dll
+ 2008-04-13 18:40:46 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
+ 2008-04-14 00:11:50 194,560 ------w C:\WINDOWS\ServicePackFiles\i386\certcli.dll
+ 2008-04-14 00:11:50 457,728 ------w C:\WINDOWS\ServicePackFiles\i386\certmgr.dll
+ 2008-04-14 00:11:50 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\cfgbkend.dll
+ 2008-04-14 00:09:05 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 ------w C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe
+ 2008-04-14 00:11:50 15,423 ------w C:\WINDOWS\ServicePackFiles\i386\ch7xxnt5.dll
+ 2008-04-13 18:40:58 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\changer.sys
+ 2008-04-14 00:11:50 148,480 ------w C:\WINDOWS\ServicePackFiles\i386\cic.dll
+ 2008-04-14 00:11:50 1,358,848 ------w C:\WINDOWS\ServicePackFiles\i386\cimwin32.dll
+ 2008-04-14 00:11:50 69,120 ------w C:\WINDOWS\ServicePackFiles\i386\ciodm.dll
+ 2008-04-14 00:12:14 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\cisvc.exe
+ 2008-04-13 19:16:22 49,536 ------w C:\WINDOWS\ServicePackFiles\i386\classpnp.sys
+ 2008-04-14 00:11:50 110,592 ------w C:\WINDOWS\ServicePackFiles\i386\clbcatex.dll
+ 2008-04-14 00:11:50 498,688 ------w C:\WINDOWS\ServicePackFiles\i386\clbcatq.dll
+ 2008-04-14 00:12:14 64,000 ------w C:\WINDOWS\ServicePackFiles\i386\cleanmgr.exe
+ 2008-04-14 00:11:50 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\cliconfg.dll
+ 2008-04-14 00:12:14 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\cliconfg.exe
+ 2008-04-14 00:12:14 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\clipbrd.exe
+ 2008-04-14 00:12:14 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\clipsrv.exe
+ 2008-04-14 00:11:50 58,368 ------w C:\WINDOWS\ServicePackFiles\i386\clusapi.dll
+ 2008-04-13 18:36:37 13,952 ------w C:\WINDOWS\ServicePackFiles\i386\cmbatt.sys
+ 2008-04-14 00:11:50 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\cmcfg32.dll
+ 2008-04-14 00:12:14 389,120 ------w C:\WINDOWS\ServicePackFiles\i386\cmd.exe
+ 2008-04-14 00:11:50 344,064 ------w C:\WINDOWS\ServicePackFiles\i386\cmdial32.dll
+ 2008-04-14 00:12:14 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\cmdl32.exe
+ 2008-04-14 00:12:15 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\cmmon32.exe
+ 2008-04-14 00:11:50 185,344 ------w C:\WINDOWS\ServicePackFiles\i386\cmprops.dll
+ 2008-04-14 00:11:50 13,312 ------w C:\WINDOWS\ServicePackFiles\i386\cmsetacl.dll
+ 2008-04-14 00:12:15 63,488 ------w C:\WINDOWS\ServicePackFiles\i386\cmstp.exe
+ 2008-04-14 00:11:50 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\cmutil.dll
+ 2008-04-14 00:11:50 47,104 ------w C:\WINDOWS\ServicePackFiles\i386\cnbjmon.dll
+ 2008-04-14 00:11:50 79,360 ------w C:\WINDOWS\ServicePackFiles\i386\cnbjmon2.dll
+ 2008-04-13 16:44:16 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\cobramsg.dll
+ 2008-04-14 00:11:51 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\colbact.dll
+ 2008-04-14 00:11:51 28,160 ------w C:\WINDOWS\ServicePackFiles\i386\comaddin.dll
+ 2008-04-14 00:11:51 195,072 ------w C:\WINDOWS\ServicePackFiles\i386\comadmin.dll
+ 2008-04-14 00:11:51 617,472 ------w C:\WINDOWS\ServicePackFiles\i386\comctl32.dll
+ 2008-04-14 00:11:51 276,992 ------w C:\WINDOWS\ServicePackFiles\i386\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 ------w C:\WINDOWS\ServicePackFiles\i386\compatui.dll
+ 2008-04-13 18:36:37 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\compbatt.sys
+ 2008-04-14 00:11:51 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\compstui.dll
+ 2008-04-14 00:11:51 97,792 ------w C:\WINDOWS\ServicePackFiles\i386\comrepl.dll
+ 2008-04-14 00:12:15 9,728 ------w C:\WINDOWS\ServicePackFiles\i386\comrepl.exe
+ 2008-04-14 00:12:15 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\comrereg.exe
+ 2008-04-14 00:11:51 792,064 ------w C:\WINDOWS\ServicePackFiles\i386\comres.dll
+ 2008-04-14 00:11:51 274,944 ------w C:\WINDOWS\ServicePackFiles\i386\comsetup.dll
+ 2008-04-14 00:11:51 167,424 ------w C:\WINDOWS\ServicePackFiles\i386\comsnap.dll
+ 2008-04-14 00:11:51 1,267,200 ------w C:\WINDOWS\ServicePackFiles\i386\comsvcs.dll
+ 2008-04-14 00:11:51 539,648 ------w C:\WINDOWS\ServicePackFiles\i386\comuid.dll
+ 2008-04-14 00:12:15 1,032,192 ------w C:\WINDOWS\ServicePackFiles\i386\conf.exe
+ 2008-04-14 00:11:51 45,056 ------w C:\WINDOWS\ServicePackFiles\i386\confmrsl.dll
+ 2008-04-14 00:11:51 357,888 ------w C:\WINDOWS\ServicePackFiles\i386\confmsp.dll
+ 2008-04-14 00:12:15 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\conime.exe
+ 2008-04-14 00:11:51 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\corpol.dll
+ 2008-04-14 00:11:51 12,800 ------w C:\WINDOWS\ServicePackFiles\i386\credssp.dll
+ 2008-04-14 00:11:51 163,840 ------w C:\WINDOWS\ServicePackFiles\i386\credui.dll
+ 2008-04-13 18:31:32 36,736 ------w C:\WINDOWS\ServicePackFiles\i386\crusoe.sys
+ 2008-04-14 00:11:51 599,040 ------w C:\WINDOWS\ServicePackFiles\i386\crypt32.dll
+ 2008-04-14 00:11:51 74,752 ------w C:\WINDOWS\ServicePackFiles\i386\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\cryptext.dll
+ 2008-04-14 00:11:51 64,512 ------w C:\WINDOWS\ServicePackFiles\i386\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 ------w C:\WINDOWS\ServicePackFiles\i386\cryptui.dll
+ 2008-04-14 00:11:51 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\cscdll.dll
+ 2008-04-14 00:12:15 139,264 ------w C:\WINDOWS\ServicePackFiles\i386\cscript.exe
+ 2008-04-14 00:11:51 326,656 ------w C:\WINDOWS\ServicePackFiles\i386\cscui.dll
+ 2008-04-14 00:11:51 32,256 ------w C:\WINDOWS\ServicePackFiles\i386\csrsrv.dll
+ 2008-04-14 00:12:15 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\csrss.exe
+ 2008-04-14 00:12:16 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
+ 2008-04-14 00:11:51 249,856 ------w C:\WINDOWS\ServicePackFiles\i386\ctmasetp.dll
+ 2008-04-14 00:11:51 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\custsat.dll
+ 2004-08-04 05:32:26 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\cwrwdm.sys
+ 2008-04-14 00:11:51 1,179,648 ------w C:\WINDOWS\ServicePackFiles\i386\d3d8.dll
+ 2008-04-14 00:11:51 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\d3d8thk.dll
+ 2008-04-14 00:11:51 1,689,088 ------w C:\WINDOWS\ServicePackFiles\i386\d3d9.dll
+ 2008-04-14 00:11:51 824,320 ------w C:\WINDOWS\ServicePackFiles\i386\d3dim700.dll
+ 2008-04-14 00:11:51 1,054,208 ------w C:\WINDOWS\ServicePackFiles\i386\danim.dll
+ 2008-03-25 04:50:25 554,008 ------w C:\WINDOWS\ServicePackFiles\i386\dao360.dll
+ 2008-04-14 00:11:51 54,272 ------w C:\WINDOWS\ServicePackFiles\i386\dataclen.dll
+ 2008-04-14 00:11:51 165,376 ------w C:\WINDOWS\ServicePackFiles\i386\datime.dll
+ 2008-04-14 00:11:51 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\davclnt.dll
+ 2008-04-14 00:11:51 640,000 ------w C:\WINDOWS\ServicePackFiles\i386\dbghelp.dll
+ 2008-04-14 00:11:51 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\dbmsrpcn.dll
+ 2008-04-14 00:11:51 110,592 ------w C:\WINDOWS\ServicePackFiles\i386\dbnetlib.dll
+ 2008-04-14 00:11:51 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dbnmpntw.dll
+ 2008-04-14 00:25:26 1,804 ------w C:\WINDOWS\ServicePackFiles\i386\dcache.bin
+ 2008-04-14 00:11:51 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\dcap32.dll
+ 2008-04-14 00:11:51 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\dciman32.dll
+ 2008-04-14 00:12:16 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\dcomcnfg.exe
+ 2008-04-14 00:12:16 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\ddeshare.exe
+ 2008-04-14 00:11:51 279,552 ------w C:\WINDOWS\ServicePackFiles\i386\ddraw.dll
+ 2008-04-14 00:11:51 27,136 ------w C:\WINDOWS\ServicePackFiles\i386\ddrawex.dll
+ 2008-04-14 00:12:16 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\defrag.exe
+ 2008-04-14 00:11:51 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\devenum.dll
+ 2008-04-14 00:11:51 282,624 ------w C:\WINDOWS\ServicePackFiles\i386\devmgr.dll
+ 2008-04-14 00:12:16 82,944 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgfat.exe
+ 2008-04-14 00:12:16 105,472 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgntfs.exe
+ 2008-04-14 00:11:51 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgsnap.dll
+ 2008-04-14 00:11:51 124,416 ------w C:\WINDOWS\ServicePackFiles\i386\dfrgui.dll
+ 2008-04-14 00:11:51 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dfsshlex.dll
+ 2008-04-14 00:11:51 111,104 ------w C:\WINDOWS\ServicePackFiles\i386\dgnet.dll
+ 2008-04-14 00:11:51 126,976 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpcsvc.dll
+ 2008-04-14 00:11:52 379,904 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\dhcpqec.dll
+ 2008-04-14 00:12:17 539,136 ------w C:\WINDOWS\ServicePackFiles\i386\dialer.exe
+ 2008-04-14 00:12:17 87,040 ------w C:\WINDOWS\ServicePackFiles\i386\diantz.exe
+ 2004-07-17 18:41:44 884,712 ------w C:\WINDOWS\ServicePackFiles\i386\digcore.exe
+ 2008-04-14 00:11:52 68,608 ------w C:\WINDOWS\ServicePackFiles\i386\digest.dll
+ 2008-04-14 00:11:52 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\dimsroam.dll
+ 2008-04-14 00:11:52 158,720 ------w C:\WINDOWS\ServicePackFiles\i386\dinput.dll
+ 2008-04-14 00:11:52 181,760 ------w C:\WINDOWS\ServicePackFiles\i386\dinput8.dll
+ 2008-04-14 00:11:52 86,528 ------w C:\WINDOWS\ServicePackFiles\i386\directdb.dll
+ 2008-04-13 18:40:47 36,352 ------w C:\WINDOWS\ServicePackFiles\i386\disk.sys
+ 2008-04-14 00:11:52 1,504,256 ------w C:\WINDOWS\ServicePackFiles\i386\diskcopy.dll
+ 2008-04-13 18:40:44 14,208 ------w C:\WINDOWS\ServicePackFiles\i386\diskdump.sys
+ 2008-04-14 00:12:17 163,840 ------w C:\WINDOWS\ServicePackFiles\i386\diskpart.exe
+ 2008-04-14 00:11:52 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\dispex.dll
+ 2008-04-14 00:12:17 5,120 ------w C:\WINDOWS\ServicePackFiles\i386\dllhost.exe
+ 2008-04-13 18:40:51 8,320 ------w C:\WINDOWS\ServicePackFiles\i386\dlttape.sys
+ 2008-04-14 00:12:17 224,768 ------w C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe
+ 2008-04-14 00:11:52 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\dmband.dll
+ 2008-04-13 18:44:48 799,744 ------w C:\WINDOWS\ServicePackFiles\i386\dmboot.sys
+ 2008-04-14 00:11:52 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\dmcompos.dll
+ 2008-04-14 00:11:52 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\dmdlgs.dll
+ 2008-04-14 00:11:52 200,704 ------w C:\WINDOWS\ServicePackFiles\i386\dmdskmgr.dll
+ 2008-04-14 00:11:52 181,248 ------w C:\WINDOWS\ServicePackFiles\i386\dmime.dll
+ 2008-04-13 18:44:46 153,344 ------w C:\WINDOWS\ServicePackFiles\i386\dmio.sys
+ 2008-04-14 00:11:52 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\dmloader.dll
+ 2008-04-14 00:12:17 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\dmremote.exe
+ 2008-04-14 00:11:52 82,432 ------w C:\WINDOWS\ServicePackFiles\i386\dmscript.dll
+ 2008-04-14 00:11:52 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\dmserver.dll
+ 2008-04-14 00:11:52 105,984 ------w C:\WINDOWS\ServicePackFiles\i386\dmstyle.dll
+ 2008-04-14 00:11:52 103,424 ------w C:\WINDOWS\ServicePackFiles\i386\dmsynth.dll
+ 2008-04-14 00:11:52 104,448 ------w C:\WINDOWS\ServicePackFiles\i386\dmusic.dll
+ 2008-04-13 18:45:01 52,864 ------w C:\WINDOWS\ServicePackFiles\i386\dmusic.sys
+ 2008-04-14 00:11:52 52,224 ------w C:\WINDOWS\ServicePackFiles\i386\dmutil.dll
+ 2008-04-14 00:11:52 147,968 ------w C:\WINDOWS\ServicePackFiles\i386\dnsapi.dll
+ 2008-04-14 00:11:52 45,568 ------w C:\WINDOWS\ServicePackFiles\i386\dnsrslvr.dll
+ 2008-04-14 00:11:52 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\docprop2.dll
+ 2004-08-04 11:00:00 53,840 ------w C:\WINDOWS\ServicePackFiles\i386\dosx.exe
+ 2008-04-14 00:11:52 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\dot3cfg.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\dot3clnt.dll
+ 2008-04-14 00:11:52 9,216 ------w C:\WINDOWS\ServicePackFiles\i386\dot3dlg.dll
+ 2008-04-14 00:11:52 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ------w C:\WINDOWS\ServicePackFiles\i386\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ------w C:\WINDOWS\ServicePackFiles\i386\dot3ui.dll
+ 2008-04-13 18:39:46 206,976 ------w C:\WINDOWS\ServicePackFiles\i386\dot4.sys
+ 2008-04-13 21:00:49 103,424 ------w C:\WINDOWS\ServicePackFiles\i386\dpcdll.dll
+ 2008-04-14 00:12:17 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\dplaysvr.exe
+ 2008-04-14 00:11:52 229,888 ------w C:\WINDOWS\ServicePackFiles\i386\dplayx.dll
+ 2008-04-14 00:11:52 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\dpmodemx.dll
+ 2008-04-14 00:09:19 3,072 ------w C:\WINDOWS\ServicePackFiles\i386\dpnaddr.dll
+ 2008-04-14 00:11:52 375,296 ------w C:\WINDOWS\ServicePackFiles\i386\dpnet.dll
+ 2008-04-14 00:11:52 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\dpnhpast.dll
+ 2008-04-14 00:11:52 60,928 ------w C:\WINDOWS\ServicePackFiles\i386\dpnhupnp.dll
+ 2008-04-14 00:09:20 3,072 ------w C:\WINDOWS\ServicePackFiles\i386\dpnlobby.dll
+ 2008-04-14 00:12:17 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\dpnsvr.exe
+ 2008-04-14 00:11:52 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\dpvacm.dll
+ 2008-04-14 00:11:52 212,480 ------w C:\WINDOWS\ServicePackFiles\i386\dpvoice.dll
+ 2008-04-14 00:12:18 83,456 ------w C:\WINDOWS\ServicePackFiles\i386\dpvsetup.exe
+ 2008-04-14 00:11:52 116,736 ------w C:\WINDOWS\ServicePackFiles\i386\dpvvox.dll
+ 2008-04-14 00:11:52 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\dpwsockx.dll
+ 2008-04-13 18:45:14 60,160 ------w C:\WINDOWS\ServicePackFiles\i386\drmk.sys
+ 2008-04-13 18:45:13 2,944 ------w C:\WINDOWS\ServicePackFiles\i386\drmkaud.sys
+ 2008-04-14 00:11:52 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\drprov.dll
+ 2004-08-04 11:00:00 4,656 ------w C:\WINDOWS\ServicePackFiles\i386\ds16gt.dll
+ 2008-04-14 00:11:52 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\ds32gt.dll
+ 2008-04-14 00:11:52 181,248 ------w C:\WINDOWS\ServicePackFiles\i386\dsdmo.dll
+ 2008-04-14 00:11:52 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\dsdmoprp.dll
+ 2008-04-14 00:11:52 92,672 ------w C:\WINDOWS\ServicePackFiles\i386\dskquota.dll
+ 2008-04-14 00:11:52 155,648 ------w C:\WINDOWS\ServicePackFiles\i386\dskquoui.dll
+ 2008-04-14 00:11:52 367,616 ------w C:\WINDOWS\ServicePackFiles\i386\dsound.dll
+ 2008-04-14 00:11:52 1,293,824 ------w C:\WINDOWS\ServicePackFiles\i386\dsound3d.dll
+ 2008-04-14 00:11:52 142,848 ------w C:\WINDOWS\ServicePackFiles\i386\dsprop.dll
+ 2008-04-13 17:09:30 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\dsprpres.dll
+ 2008-04-14 00:11:52 239,104 ------w C:\WINDOWS\ServicePackFiles\i386\dsquery.dll
+ 2008-04-14 00:11:52 51,200 ------w C:\WINDOWS\ServicePackFiles\i386\dssec.dll
+ 2008-04-13 17:37:57 138,752 ------w C:\WINDOWS\ServicePackFiles\i386\dssenh.dll
+ 2008-04-14 00:11:52 113,152 ------w C:\WINDOWS\ServicePackFiles\i386\dsuiext.dll
+ 2008-04-14 00:11:52 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\dswave.dll
+ 2008-04-14 00:12:18 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\dumprep.exe
+ 2008-04-14 00:11:52 304,128 ------w C:\WINDOWS\ServicePackFiles\i386\duser.dll
+ 2008-04-14 00:12:18 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\dvdupgrd.exe
+ 2008-04-14 00:12:18 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\dwwin.exe
+ 2008-04-14 00:11:52 619,008 ------w C:\WINDOWS\ServicePackFiles\i386\dx7vb.dll
+ 2008-04-14 00:11:52 1,227,264 ------w C:\WINDOWS\ServicePackFiles\i386\dx8vb.dll
+ 2008-04-14 00:12:18 1,298,432 ------w C:\WINDOWS\ServicePackFiles\i386\dxdiag.exe
+ 2008-04-14 00:11:52 2,113,536 ------w C:\WINDOWS\ServicePackFiles\i386\dxdiagn.dll
+ 2008-04-13 18:38:29 71,168 ------w C:\WINDOWS\ServicePackFiles\i386\dxg.sys
+ 2008-04-14 00:11:52 357,888 ------w C:\WINDOWS\ServicePackFiles\i386\dxtmsft.dll
+ 2008-04-14 00:11:52 205,312 ------w C:\WINDOWS\ServicePackFiles\i386\dxtrans.dll
+ 2008-04-14 00:11:52 30,720 ------w C:\WINDOWS\ServicePackFiles\i386\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ------w C:\WINDOWS\ServicePackFiles\i386\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ------w C:\WINDOWS\ServicePackFiles\i386\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ------w C:\WINDOWS\ServicePackFiles\i386\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\eapsvc.dll
+ 2008-04-14 00:11:52 175,616 ------w C:\WINDOWS\ServicePackFiles\i386\ediskeer.dll
+ 2008-04-14 00:11:53 183,296 ------w C:\WINDOWS\ServicePackFiles\i386\els.dll
+ 2008-04-14 00:11:53 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\encapi.dll
+ 2008-04-14 00:11:53 186,880 ------w C:\WINDOWS\ServicePackFiles\i386\encdec.dll
+ 2008-04-13 16:26:02 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\ep9res.dll
+ 2004-07-17 18:39:36 120,320 ------w C:\WINDOWS\ServicePackFiles\i386\epcl5res.dll
+ 2008-04-14 00:11:53 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\ersvc.dll
+ 2008-04-14 00:11:53 246,272 ------w C:\WINDOWS\ServicePackFiles\i386\es.dll
+ 2008-04-14 00:11:53 1,082,368 ------w C:\WINDOWS\ServicePackFiles\i386\esent.dll
+ 2008-04-14 00:11:53 247,808 ------w C:\WINDOWS\ServicePackFiles\i386\esscli.dll
+ 2004-08-04 05:32:28 137,088 ------w C:\WINDOWS\ServicePackFiles\i386\essm2e.sys
+ 2008-04-14 00:12:19 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\eudcedit.exe
+ 2008-04-14 00:11:53 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
+ 2008-04-14 00:11:53 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\evntagnt.dll
+ 2008-04-14 00:12:19 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\evntcmd.exe
+ 2008-04-14 00:11:53 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\evntrprv.dll
+ 2008-04-14 00:12:19 92,160 ------w C:\WINDOWS\ServicePackFiles\i386\evntwin.exe
+ 2008-04-14 00:12:19 1,033,728 ------w C:\WINDOWS\ServicePackFiles\i386\explorer.exe
+ 2008-04-14 00:11:53 380,445 ------w C:\WINDOWS\ServicePackFiles\i386\expsrv.dll
+ 2008-04-14 00:11:53 55,808 ------w C:\WINDOWS\ServicePackFiles\i386\extmgr.dll
+ 2008-04-14 00:12:19 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\extrac32.exe
+ 2008-04-14 00:11:53 125,952 ------w C:\WINDOWS\ServicePackFiles\i386\exts.dll
+ 2008-04-14 00:09:30 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\f3ahvoas.dll
+ 2008-04-13 19:14:29 143,744 ------w C:\WINDOWS\ServicePackFiles\i386\fastfat.sys
+ 2008-04-14 00:11:53 472,064 ------w C:\WINDOWS\ServicePackFiles\i386\fastprox.dll
+ 2008-04-14 00:11:53 80,384 ------w C:\WINDOWS\ServicePackFiles\i386\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\faxpatch.exe
+ 2008-04-13 18:40:25 27,392 ------w C:\WINDOWS\ServicePackFiles\i386\fdc.sys
+ 2008-04-14 00:11:53 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\feclient.dll
+ 2008-04-14 00:11:53 337,920 ------w C:\WINDOWS\ServicePackFiles\i386\filemgmt.dll
+ 2008-04-14 00:12:20 27,136 ------w C:\WINDOWS\ServicePackFiles\i386\findstr.exe
+ 2008-04-13 18:33:28 44,544 ------w C:\WINDOWS\ServicePackFiles\i386\fips.sys
+ 2008-04-14 00:11:53 87,552 ------w C:\WINDOWS\ServicePackFiles\i386\fldrclnr.dll
+ 2008-04-13 18:40:25 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\flpydisk.sys
+ 2008-04-14 00:11:53 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\fltlib.dll
+ 2008-04-14 00:12:20 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\fltmc.exe
+ 2008-04-13 18:32:59 129,792 ------w C:\WINDOWS\ServicePackFiles\i386\fltmgr.sys
+ 2008-04-14 00:11:53 382,976 ------w C:\WINDOWS\ServicePackFiles\i386\fontext.dll
+ 2008-04-14 00:11:53 80,896 ------w C:\WINDOWS\ServicePackFiles\i386\fontsub.dll
+ 2008-04-14 00:12:20 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\fontview.exe
+ 2008-04-14 00:12:20 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\forcedos.exe
+ 2004-08-04 05:31:24 34,173 ------w C:\WINDOWS\ServicePackFiles\i386\forehe.sys
+ 2008-04-14 00:12:42 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\format.com
+ 2008-04-14 00:11:53 32,828 ------w C:\WINDOWS\ServicePackFiles\i386\fp40ext.dll
+ 2008-04-14 00:11:53 184,435 ------w C:\WINDOWS\ServicePackFiles\i386\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 ------w C:\WINDOWS\ServicePackFiles\i386\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 ------w C:\WINDOWS\ServicePackFiles\i386\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 ------w C:\WINDOWS\ServicePackFiles\i386\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 ------w C:\WINDOWS\ServicePackFiles\i386\fp4atxt.dll
+ 2008-04-14 00:11:53 618,605 ------w C:\WINDOWS\ServicePackFiles\i386\fp4autl.dll
+ 2008-04-14 00:11:53 41,020 ------w C:\WINDOWS\ServicePackFiles\i386\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 ------w C:\WINDOWS\ServicePackFiles\i386\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 ------w C:\WINDOWS\ServicePackFiles\i386\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 ------w C:\WINDOWS\ServicePackFiles\i386\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 ------w C:\WINDOWS\ServicePackFiles\i386\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 ------w C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe
+ 2008-04-14 00:12:20 24,632 ------w C:\WINDOWS\ServicePackFiles\i386\fpadmcgi.exe
+ 2008-04-14 00:11:53 20,541 ------w C:\WINDOWS\ServicePackFiles\i386\fpadmdll.dll
+ 2008-04-14 00:12:20 188,494 ------w C:\WINDOWS\ServicePackFiles\i386\fpcount.exe
+ 2008-04-14 00:11:53 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\fpencode.dll
+ 2008-04-14 00:11:53 20,541 ------w C:\WINDOWS\ServicePackFiles\i386\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 ------w C:\WINDOWS\ServicePackFiles\i386\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 ------w C:\WINDOWS\ServicePackFiles\i386\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 ------w C:\WINDOWS\ServicePackFiles\i386\fpremadm.exe
+ 2008-04-14 00:12:20 28,728 ------w C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe
+ 2008-04-14 00:09:33 9,344 ------w C:\WINDOWS\ServicePackFiles\i386\framebuf.dll
+ 2008-04-14 00:11:53 185,344 ------w C:\WINDOWS\ServicePackFiles\i386\framedyn.dll
+ 2008-04-14 00:12:20 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\fsquirt.exe
+ 2008-04-14 00:12:20 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\ftp.exe
+ 2008-04-14 00:11:53 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\fwcfg.dll
+ 2008-04-14 00:11:53 451,584 ------w C:\WINDOWS\ServicePackFiles\i386\fxsapi.dll
+ 2008-04-14 00:12:21 142,848 ------w C:\WINDOWS\ServicePackFiles\i386\fxsclnt.exe
+ 2008-04-14 00:11:54 72,192 ------w C:\WINDOWS\ServicePackFiles\i386\fxscom.dll
+ 2008-04-14 00:11:54 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\fxscomex.dll
+ 2008-04-14 00:12:21 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\fxscover.exe
+ 2008-04-14 00:11:54 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\fxsdrv.dll
+ 2008-04-14 00:11:54 55,296 ------w C:\WINDOWS\ServicePackFiles\i386\fxsevent.dll
+ 2008-04-14 00:11:54 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\fxsext32.dll
+ 2008-04-14 00:11:54 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\fxsmon.dll
+ 2008-04-14 00:11:54 132,608 ------w C:\WINDOWS\ServicePackFiles\i386\fxsocm.dll
+ 2008-04-14 00:11:54 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\fxsperf.dll
+ 2008-04-14 00:09:33 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\fxsres.dll
+ 2008-04-14 00:11:54 562,176 ------w C:\WINDOWS\ServicePackFiles\i386\fxsst.dll
+ 2008-04-14 00:12:21 267,776 ------w C:\WINDOWS\ServicePackFiles\i386\fxssvc.exe
+ 2008-04-14 00:11:54 246,272 ------w C:\WINDOWS\ServicePackFiles\i386\fxst30.dll
+ 2008-04-14 00:11:54 397,312 ------w C:\WINDOWS\ServicePackFiles\i386\fxstiff.dll
+ 2008-04-14 00:11:54 154,112 ------w C:\WINDOWS\ServicePackFiles\i386\fxsui.dll
+ 2008-04-14 00:11:54 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\fxswzrd.dll
+ 2008-04-14 00:11:54 400,384 ------w C:\WINDOWS\ServicePackFiles\i386\fxsxp32.dll
+ 2008-04-13 18:36:40 46,464 ------w C:\WINDOWS\ServicePackFiles\i386\gagp30kx.sys
+ 2008-04-13 18:45:29 10,624 ------w C:\WINDOWS\ServicePackFiles\i386\gameenum.sys
+ 2008-04-13 18:45:32 59,136 ------w C:\WINDOWS\ServicePackFiles\i386\gckernel.sys
+ 2008-04-14 00:11:54 285,184 ------w C:\WINDOWS\ServicePackFiles\i386\gdi32.dll
+ 2008-04-14 00:11:54 122,880 ------w C:\WINDOWS\ServicePackFiles\i386\glu32.dll
+ 2004-08-04 11:00:00 101,888 ------w C:\WINDOWS\ServicePackFiles\i386\gpkcsp.dll
+ 2006-12-31 01:26:44 9,728 ------w C:\WINDOWS\ServicePackFiles\i386\gpkrsrc.dll
+ 2008-04-14 00:12:21 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\grpconv.exe
+ 2008-04-13 18:40:21 28,288 ------w C:\WINDOWS\ServicePackFiles\i386\grserial.sys
+ 2008-04-14 00:11:54 133,120 ------w C:\WINDOWS\ServicePackFiles\i386\guitrn.dll
+ 2008-04-14 00:11:54 115,200 ------w C:\WINDOWS\ServicePackFiles\i386\guitrna.dll
+ 2008-04-14 00:11:54 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\h323cc.dll
+ 2008-04-14 00:11:54 614,912 ------w C:\WINDOWS\ServicePackFiles\i386\h323msp.dll
+ 2008-04-13 18:31:32 105,344 ------w C:\WINDOWS\ServicePackFiles\i386\hal.dll
+ 2008-04-13 18:31:28 131,840 ------w C:\WINDOWS\ServicePackFiles\i386\halaacpi.dll
+ 2008-04-13 18:31:27 81,152 ------w C:\WINDOWS\ServicePackFiles\i386\halacpi.dll
+ 2008-04-13 18:31:28 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\halapic.dll
+ 2008-04-13 18:31:28 134,400 ------w C:\WINDOWS\ServicePackFiles\i386\halmacpi.dll
+ 2008-04-13 18:31:32 152,576 ------w C:\WINDOWS\ServicePackFiles\i386\halmps.dll
+ 2008-04-13 18:31:31 77,696 ------w C:\WINDOWS\ServicePackFiles\i386\halsp.dll
+ 2008-04-14 00:11:54 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\hccoin.dll
+ 2008-04-13 16:36:05 144,384 ------w C:\WINDOWS\ServicePackFiles\i386\hdaudbus.sys
+ 2008-04-14 00:12:21 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\help.exe
+ 2008-04-14 00:12:21 769,024 ------w C:\WINDOWS\ServicePackFiles\i386\helpctr.exe
+ 2008-04-14 00:12:21 744,448 ------w C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe
+ 2008-04-14 00:12:21 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\hh.exe
+ 2008-04-14 00:11:54 41,472 ------w C:\WINDOWS\ServicePackFiles\i386\hhsetup.dll
+ 2008-04-14 00:11:54 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\hid.dll
+ 2008-04-13 18:36:38 20,352 ------w C:\WINDOWS\ServicePackFiles\i386\hidbatt.sys
+ 2008-04-13 18:46:30 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\hidbth.sys
+ 2008-04-13 18:45:26 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\hidclass.sys
+ 2008-04-13 18:45:26 19,200 ------w C:\WINDOWS\ServicePackFiles\i386\hidir.sys
+ 2008-04-13 18:45:22 24,960 ------w C:\WINDOWS\ServicePackFiles\i386\hidparse.sys
+ 2008-04-14 00:11:54 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\hidserv.dll
+ 2008-04-13 18:45:27 10,368 ------w C:\WINDOWS\ServicePackFiles\i386\hidusb.sys
+ 2008-04-14 00:11:54 72,704 ------w C:\WINDOWS\ServicePackFiles\i386\hlink.dll
+ 2008-04-14 00:11:54 38,912 ------w C:\WINDOWS\ServicePackFiles\i386\hmmapi.dll
+ 2008-04-14 00:11:54 344,064 ------w C:\WINDOWS\ServicePackFiles\i386\hnetcfg.dll
+ 2008-04-14 00:11:54 330,752 ------w C:\WINDOWS\ServicePackFiles\i386\hnetwiz.dll
+ 2008-04-14 00:11:54 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\hostmib.dll
+ 2008-04-14 00:11:54 144,896 ------w C:\WINDOWS\ServicePackFiles\i386\hotplug.dll
+ 2008-04-14 00:11:54 10,752 ------w C:\WINDOWS\ServicePackFiles\i386\hpcjrr.dll
+ 2008-04-14 00:11:54 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\hpcjrrps.dll
+ 2008-04-14 00:11:54 87,552 ------w C:\WINDOWS\ServicePackFiles\i386\hpfud50.dll
+ 2008-04-14 00:12:21 18,432 ------w C:\WINDOWS\ServicePackFiles\i386\hscupd.exe
+ 2004-08-04 05:41:48 220,032 ------w C:\WINDOWS\ServicePackFiles\i386\hsfbs2s2.sys
+ 2008-04-14 00:11:54 32,285 ------w C:\WINDOWS\ServicePackFiles\i386\hsfcisp2.dll
+ 2004-08-04 05:41:50 685,056 ------w C:\WINDOWS\ServicePackFiles\i386\hsfcxts2.sys
breakawayjade
2008-10-17, 02:50
+ 2004-08-04 05:41:56 1,041,536 ------w C:\WINDOWS\ServicePackFiles\i386\hsfdpsp2.sys
+ 2008-04-13 18:53:53 264,832 ------w C:\WINDOWS\ServicePackFiles\i386\http.sys
+ 2008-04-14 00:11:54 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\httpapi.dll
+ 2008-04-14 00:11:54 41,984 ------w C:\WINDOWS\ServicePackFiles\i386\htui.dll
+ 2008-04-14 00:11:54 347,136 ------w C:\WINDOWS\ServicePackFiles\i386\hypertrm.dll
+ 2008-04-13 18:41:22 8,576 ------w C:\WINDOWS\ServicePackFiles\i386\i2omgmt.sys
+ 2008-04-13 18:41:22 18,560 ------w C:\WINDOWS\ServicePackFiles\i386\i2omp.sys
+ 2008-04-13 19:18:00 52,480 ------w C:\WINDOWS\ServicePackFiles\i386\i8042prt.sys
+ 2008-04-14 00:11:54 702,845 ------w C:\WINDOWS\ServicePackFiles\i386\i81xdnt5.dll
+ 2004-08-04 05:29:38 161,020 ------w C:\WINDOWS\ServicePackFiles\i386\i81xnt5.sys
+ 2008-04-14 00:11:54 119,808 ------w C:\WINDOWS\ServicePackFiles\i386\iasrad.dll
+ 2008-04-14 00:11:54 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\icaapi.dll
+ 2008-04-14 00:11:54 80,384 ------w C:\WINDOWS\ServicePackFiles\i386\iccvid.dll
+ 2008-04-14 00:11:54 254,976 ------w C:\WINDOWS\ServicePackFiles\i386\icm32.dll
+ 2008-04-14 00:09:40 3,584 ------w C:\WINDOWS\ServicePackFiles\i386\icmp.dll
+ 2008-04-13 16:44:29 2,560 ------w C:\WINDOWS\ServicePackFiles\i386\iconlib.dll
+ 2008-04-14 00:11:54 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\icwconn.dll
+ 2008-04-14 00:12:22 214,528 ------w C:\WINDOWS\ServicePackFiles\i386\icwconn1.exe
+ 2008-04-14 00:12:22 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\icwconn2.exe
+ 2008-04-14 00:11:54 73,728 ------w C:\WINDOWS\ServicePackFiles\i386\icwdial.dll
+ 2008-04-14 00:11:54 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\icwdl.dll
+ 2008-04-14 00:11:54 172,032 ------w C:\WINDOWS\ServicePackFiles\i386\icwhelp.dll
+ 2008-04-14 00:11:54 65,536 ------w C:\WINDOWS\ServicePackFiles\i386\icwphbk.dll
+ 2008-04-14 00:12:22 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\icwrmind.exe
+ 2008-04-14 00:11:54 49,152 ------w C:\WINDOWS\ServicePackFiles\i386\icwutil.dll
+ 2008-04-14 00:11:54 120,832 ------w C:\WINDOWS\ServicePackFiles\i386\idq.dll
+ 2008-04-14 00:12:22 34,304 ------w C:\WINDOWS\ServicePackFiles\i386\ie4uinit.exe
+ 2008-04-14 00:11:54 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\ieakeng.dll
+ 2008-04-14 00:11:54 216,576 ------w C:\WINDOWS\ServicePackFiles\i386\ieaksie.dll
+ 2008-04-14 00:11:54 323,584 ------w C:\WINDOWS\ServicePackFiles\i386\iedkcs32.dll
+ 2008-04-14 00:12:22 18,432 ------w C:\WINDOWS\ServicePackFiles\i386\iedw.exe
+ 2008-04-14 00:11:54 81,920 ------w C:\WINDOWS\ServicePackFiles\i386\ieencode.dll
+ 2008-04-14 00:11:54 251,904 ------w C:\WINDOWS\ServicePackFiles\i386\iepeers.dll
+ 2008-04-14 00:11:54 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\iernonce.dll
+ 2008-04-14 00:11:54 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\iesetup.dll
+ 2008-04-14 00:12:22 93,184 ------w C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
+ 2008-04-14 00:12:22 114,688 ------w C:\WINDOWS\ServicePackFiles\i386\iexpress.exe
+ 2008-04-14 00:11:54 135,680 ------w C:\WINDOWS\ServicePackFiles\i386\ifmon.dll
+ 2008-04-14 00:11:54 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\igmpagnt.dll
+ 2008-04-14 00:11:54 505,344 ------w C:\WINDOWS\ServicePackFiles\i386\iis.dll
+ 2008-04-14 00:11:54 81,920 ------w C:\WINDOWS\ServicePackFiles\i386\ils.dll
+ 2008-04-14 00:11:54 144,384 ------w C:\WINDOWS\ServicePackFiles\i386\imagehlp.dll
+ 2008-04-14 00:12:22 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\imapi.exe
+ 2008-04-13 18:40:58 42,112 ------w C:\WINDOWS\ServicePackFiles\i386\imapi.sys
+ 2008-04-14 00:11:54 36,921 ------w C:\WINDOWS\ServicePackFiles\i386\imeshare.dll
+ 2008-04-14 00:11:54 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\imgutil.dll
+ 2008-04-14 00:11:54 110,080 ------w C:\WINDOWS\ServicePackFiles\i386\imm32.dll
+ 2008-04-14 00:11:54 123,392 ------w C:\WINDOWS\ServicePackFiles\i386\imsinsnt.dll
+ 2008-04-14 00:11:54 274,432 ------w C:\WINDOWS\ServicePackFiles\i386\inetcfg.dll
+ 2008-04-14 00:11:54 691,712 ------w C:\WINDOWS\ServicePackFiles\i386\inetcomm.dll
+ 2008-04-14 00:11:55 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\inetmib1.dll
+ 2008-04-14 00:11:55 75,264 ------w C:\WINDOWS\ServicePackFiles\i386\inetpp.dll
+ 2008-04-14 00:11:55 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\inetppui.dll
+ 2008-04-13 16:22:12 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\inetres.dll
+ 2008-04-14 00:12:22 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\inetwiz.exe
+ 2008-04-14 00:11:55 147,456 ------w C:\WINDOWS\ServicePackFiles\i386\initpki.dll
+ 2008-04-14 00:11:55 123,392 ------w C:\WINDOWS\ServicePackFiles\i386\input.dll
+ 2008-04-14 00:11:55 96,256 ------w C:\WINDOWS\ServicePackFiles\i386\inseng.dll
+ 2008-04-13 18:40:29 5,504 ------w C:\WINDOWS\ServicePackFiles\i386\intelide.sys
+ 2008-04-13 18:31:32 36,352 ------w C:\WINDOWS\ServicePackFiles\i386\intelppm.sys
+ 2008-04-13 18:53:34 36,608 ------w C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
+ 2008-04-14 00:12:22 55,808 ------w C:\WINDOWS\ServicePackFiles\i386\ipconfig.exe
+ 2008-04-14 00:09:30 103,424 ------w C:\WINDOWS\ServicePackFiles\i386\ipevldpc.dll
+ 2008-04-14 00:09:23 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\ipevlpid.dll
+ 2008-04-14 00:11:55 94,720 ------w C:\WINDOWS\ServicePackFiles\i386\iphlpapi.dll
+ 2008-04-13 18:57:07 20,864 ------w C:\WINDOWS\ServicePackFiles\i386\ipinip.sys
+ 2008-04-14 00:11:55 161,280 ------w C:\WINDOWS\ServicePackFiles\i386\ipmontr.dll
+ 2008-04-13 18:57:15 152,832 ------w C:\WINDOWS\ServicePackFiles\i386\ipnat.sys
+ 2008-04-14 00:11:55 331,264 ------w C:\WINDOWS\ServicePackFiles\i386\ipnathlp.dll
+ 2008-04-14 00:11:55 330,752 ------w C:\WINDOWS\ServicePackFiles\i386\ippromon.dll
+ 2008-04-14 00:11:55 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\iprip.dll
+ 2008-04-14 00:11:55 177,152 ------w C:\WINDOWS\ServicePackFiles\i386\iprtrmgr.dll
+ 2008-04-13 19:19:42 75,264 ------w C:\WINDOWS\ServicePackFiles\i386\ipsec.sys
+ 2008-04-14 00:11:55 349,696 ------w C:\WINDOWS\ServicePackFiles\i386\ipsecsnp.dll
+ 2008-04-14 00:11:55 183,808 ------w C:\WINDOWS\ServicePackFiles\i386\ipsecsvc.dll
+ 2008-04-14 00:10:45 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\ipseldpc.dll
+ 2008-04-14 00:09:24 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\ipselpid.dll
+ 2008-04-14 00:11:55 384,000 ------w C:\WINDOWS\ServicePackFiles\i386\ipsmsnap.dll
+ 2008-04-14 00:12:23 53,248 ------w C:\WINDOWS\ServicePackFiles\i386\ipv6.exe
+ 2008-04-14 00:11:55 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\ipv6mon.dll
+ 2008-04-14 00:12:23 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\ipxroute.exe
+ 2008-04-14 00:11:55 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\ipxwan.dll
+ 2008-04-14 00:11:55 120,320 ------w C:\WINDOWS\ServicePackFiles\i386\ir41_qc.dll
+ 2008-04-14 00:11:55 338,432 ------w C:\WINDOWS\ServicePackFiles\i386\ir41_qcx.dll
+ 2008-04-14 00:11:55 755,200 ------w C:\WINDOWS\ServicePackFiles\i386\ir50_32.dll
+ 2008-04-14 00:11:55 200,192 ------w C:\WINDOWS\ServicePackFiles\i386\ir50_qc.dll
+ 2008-04-14 00:11:55 183,808 ------w C:\WINDOWS\ServicePackFiles\i386\ir50_qcx.dll
+ 2008-04-13 18:54:36 88,192 ------w C:\WINDOWS\ServicePackFiles\i386\irda.sys
+ 2008-04-13 18:54:28 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\irenum.sys
+ 2008-04-14 00:12:23 151,552 ------w C:\WINDOWS\ServicePackFiles\i386\irftp.exe
+ 2008-04-14 00:11:55 28,160 ------w C:\WINDOWS\ServicePackFiles\i386\irmon.dll
+ 2008-04-13 18:36:41 37,248 ------w C:\WINDOWS\ServicePackFiles\i386\isapnp.sys
+ 2008-04-14 00:10:32 105,984 ------w C:\WINDOWS\ServicePackFiles\i386\isdpc.dll
+ 2008-04-14 00:10:55 105,984 ------w C:\WINDOWS\ServicePackFiles\i386\isendpc.dll
+ 2008-04-14 00:10:55 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\isenpid.dll
+ 2008-04-14 00:11:55 81,920 ------w C:\WINDOWS\ServicePackFiles\i386\isign32.dll
+ 2008-04-14 00:10:32 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\ispid.dll
+ 2008-04-14 00:11:55 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\isrdbg32.dll
+ 2008-04-14 00:11:55 155,136 ------w C:\WINDOWS\ServicePackFiles\i386\itircl.dll
+ 2008-04-14 00:11:55 138,240 ------w C:\WINDOWS\ServicePackFiles\i386\itss.dll
+ 2008-04-14 00:11:55 191,488 ------w C:\WINDOWS\ServicePackFiles\i386\iuengine.dll
+ 2008-04-14 00:11:55 54,272 ------w C:\WINDOWS\ServicePackFiles\i386\ixsso.dll
+ 2008-04-14 00:11:55 47,616 ------w C:\WINDOWS\ServicePackFiles\i386\iyuv_32.dll
+ 2008-04-14 00:11:55 163,840 ------w C:\WINDOWS\ServicePackFiles\i386\jgdw400.dll
+ 2008-04-14 00:11:55 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\jgpl400.dll
+ 2008-04-14 00:11:56 512,000 ------w C:\WINDOWS\ServicePackFiles\i386\jscript.dll
+ 2008-04-14 00:11:56 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbd101.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbd106.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbd106n.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdax2.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdbhc.dll
+ 2008-04-13 18:39:47 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\kbdclass.sys
+ 2008-04-14 00:09:55 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\kbdfi1.dll
+ 2008-04-13 18:39:48 14,592 ------w C:\WINDOWS\ServicePackFiles\i386\kbdhid.sys
+ 2008-04-14 00:09:55 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\kbdibm02.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdinben.dll
+ 2008-04-14 00:09:55 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdiultn.dll
+ 2008-04-14 00:09:55 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\kbdlk41a.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdlk41j.dll
+ 2008-04-14 00:09:55 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\kbdmaori.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdmlt48.dll
+ 2008-04-14 00:09:55 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdnepr.dll
+ 2008-04-14 00:09:55 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\kbdpash.dll
+ 2008-04-14 00:09:55 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\kbdukx.dll
+ 2008-04-13 18:31:35 7,424 ------w C:\WINDOWS\ServicePackFiles\i386\kd1394.dll
+ 2008-04-14 00:11:56 184,832 ------w C:\WINDOWS\ServicePackFiles\i386\kdcsvc.dll
+ 2008-04-14 00:11:56 48,640 ------w C:\WINDOWS\ServicePackFiles\i386\kdsui.dll
+ 2008-04-14 00:11:56 253,952 ------w C:\WINDOWS\ServicePackFiles\i386\kdsusd.dll
+ 2008-04-14 00:11:56 299,520 ------w C:\WINDOWS\ServicePackFiles\i386\kerberos.dll
+ 2008-04-14 00:11:56 989,696 ------w C:\WINDOWS\ServicePackFiles\i386\kernel32.dll
+ 2004-08-04 11:00:00 42,537 ------w C:\WINDOWS\ServicePackFiles\i386\keyboard.sys
+ 2008-04-14 00:11:56 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\keymgr.dll
+ 2008-04-13 18:45:09 172,416 ------w C:\WINDOWS\ServicePackFiles\i386\kmixer.sys
+ 2008-04-14 00:11:56 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\kmsvc.dll
+ 2008-04-14 00:09:56 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\knperdpc.dll
+ 2008-04-14 00:09:56 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\knperpid.dll
+ 2008-04-14 00:09:56 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\knprodpc.dll
+ 2008-04-14 00:09:56 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\knpropid.dll
+ 2008-04-14 00:11:56 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\koc.dll
+ 2008-04-14 00:09:56 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\kperdpc.dll
+ 2008-04-14 00:09:56 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\kperpid.dll
+ 2008-04-14 00:09:56 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\kprodpc.dll
+ 2008-04-14 00:09:56 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\kpropid.dll
+ 2004-08-04 11:00:00 92,224 ------w C:\WINDOWS\ServicePackFiles\i386\krnl386.exe
+ 2008-04-14 00:11:56 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\krnlprov.dll
+ 2008-04-13 19:16:36 141,056 ------w C:\WINDOWS\ServicePackFiles\i386\ks.sys
+ 2008-04-13 18:31:43 92,288 ------w C:\WINDOWS\ServicePackFiles\i386\ksecdd.sys
+ 2008-04-14 00:11:56 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\ksuser.dll
+ 2008-04-14 00:11:56 37,376 ------w C:\WINDOWS\ServicePackFiles\i386\l2store.dll
+ 2008-04-14 00:09:05 97,792 ------w C:\WINDOWS\ServicePackFiles\i386\lang\chtmbx.dll
+ 2008-04-14 00:09:05 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\lang\chtskdic.dll
+ 2008-04-14 00:09:05 173,568 ------w C:\WINDOWS\ServicePackFiles\i386\lang\chtskf.dll
+ 2008-04-14 00:09:06 198,656 ------w C:\WINDOWS\ServicePackFiles\i386\lang\cintime.dll
+ 2004-08-04 05:31:56 480,256 ------w C:\WINDOWS\ServicePackFiles\i386\lang\cintsetp.exe
+ 2004-08-04 05:31:40 57,399 ------w C:\WINDOWS\ServicePackFiles\i386\lang\cplexe.exe
+ 2008-04-14 00:09:39 13,463,552 ------w C:\WINDOWS\ServicePackFiles\i386\lang\hwxjpn.dll
+ 2008-04-14 00:09:43 106,496 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imekrcic.dll
+ 2008-04-14 00:09:43 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imekrmbx.dll
+ 2008-04-14 00:09:44 811,064 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjp81k.dll
+ 2008-04-14 00:09:45 368,696 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpcic.dll
+ 2008-04-14 00:09:45 716,856 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpcus.dll
+ 2008-04-14 00:09:45 81,976 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.dll
+ 2004-08-04 05:31:54 307,257 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.exe
+ 2004-08-04 05:31:56 155,705 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdsvr.exe
+ 2004-08-04 05:31:58 196,665 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpinst.exe
+ 2004-08-04 05:32:00 208,952 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjpmig.exe
+ 2004-08-04 05:32:12 233,527 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjprw.exe
+ 2004-08-04 05:32:16 262,200 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjputy.exe
+ 2008-04-14 00:09:46 274,489 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imjputyc.dll
+ 2008-04-14 00:09:46 102,456 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imlang.dll
+ 2004-08-04 05:31:50 59,392 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imscinst.exe
+ 2008-04-14 00:09:47 315,455 ------w C:\WINDOWS\ServicePackFiles\i386\lang\imskf.dll
+ 2008-04-14 00:10:33 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\lang\padrs404.dll
+ 2008-04-14 00:10:33 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\lang\padrs804.dll
+ 2008-04-14 00:10:34 175,104 ------w C:\WINDOWS\ServicePackFiles\i386\lang\pintlcsa.dll
+ 2008-04-14 00:10:34 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\lang\pintlcsd.dll
+ 2008-04-13 16:43:36 70,144 ------w C:\WINDOWS\ServicePackFiles\i386\lang\pintlphr.exe
+ 2008-04-14 00:10:34 67,584 ------w C:\WINDOWS\ServicePackFiles\i386\lang\pmigrate.dll
+ 2004-08-04 05:32:16 44,032 ------w C:\WINDOWS\ServicePackFiles\i386\lang\tintlphr.exe
+ 2004-08-04 05:32:16 455,168 ------w C:\WINDOWS\ServicePackFiles\i386\lang\tintsetp.exe
+ 2008-04-14 00:10:59 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\lang\tmigrate.dll
+ 2008-04-14 00:11:01 76,288 ------w C:\WINDOWS\ServicePackFiles\i386\lang\uniime.dll
+ 2008-04-14 00:11:04 426,041 ------w C:\WINDOWS\ServicePackFiles\i386\lang\voicepad.dll
+ 2008-04-14 00:11:04 86,073 ------w C:\WINDOWS\ServicePackFiles\i386\lang\voicesub.dll
+ 2008-04-13 18:40:26 34,688 ------w C:\WINDOWS\ServicePackFiles\i386\lbrtfdc.sys
+ 2008-04-14 00:12:23 677,888 ------w C:\WINDOWS\ServicePackFiles\i386\lhmstsc.exe
+ 2008-04-14 00:11:56 2,061,824 ------w C:\WINDOWS\ServicePackFiles\i386\lhmstscx.dll
+ 2008-04-14 12:41:58 423,936 ------w C:\WINDOWS\ServicePackFiles\i386\licdll.dll
+ 2008-04-14 00:11:56 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\licmgr10.dll
+ 2008-04-14 00:11:56 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\licwmi.dll
+ 2008-04-14 00:11:56 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\linkinfo.dll
+ 2008-04-14 00:11:56 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\lmhsvc.dll
+ 2008-04-14 00:11:56 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\lmmib2.dll
+ 2008-04-14 00:11:56 399,872 ------w C:\WINDOWS\ServicePackFiles\i386\lmrt.dll
+ 2008-04-14 00:11:56 97,280 ------w C:\WINDOWS\ServicePackFiles\i386\loadperf.dll
+ 2008-04-14 00:11:56 221,696 ------w C:\WINDOWS\ServicePackFiles\i386\localsec.dll
+ 2008-04-14 00:11:56 343,040 ------w C:\WINDOWS\ServicePackFiles\i386\localspl.dll
+ 2008-04-14 00:11:56 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\localui.dll
+ 2008-04-14 00:12:24 75,264 ------w C:\WINDOWS\ServicePackFiles\i386\locator.exe
+ 2008-04-14 00:11:56 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\log.dll
+ 2008-04-14 00:12:24 59,392 ------w C:\WINDOWS\ServicePackFiles\i386\logman.exe
+ 2008-04-14 00:12:43 220,672 ------w C:\WINDOWS\ServicePackFiles\i386\logon.scr
+ 2008-04-14 00:12:24 514,560 ------w C:\WINDOWS\ServicePackFiles\i386\logonui.exe
+ 2008-04-14 00:11:56 22,528 ------w C:\WINDOWS\ServicePackFiles\i386\lpdsvc.dll
+ 2008-04-14 00:11:56 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\lpk.dll
+ 2008-04-14 00:11:56 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\lprhelp.dll
+ 2008-04-14 00:11:56 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\lprmon.dll
+ 2008-04-14 00:11:56 728,064 ------w C:\WINDOWS\ServicePackFiles\i386\lsasrv.dll
+ 2008-04-14 00:12:24 13,312 ------w C:\WINDOWS\ServicePackFiles\i386\lsass.exe
+ 2004-08-04 05:41:36 606,684 ------w C:\WINDOWS\ServicePackFiles\i386\ltmdmnt.sys
+ 2004-08-04 05:41:38 420,992 ------w C:\WINDOWS\ServicePackFiles\i386\ltmdmntt.sys
+ 2008-04-13 18:40:52 7,040 ------w C:\WINDOWS\ServicePackFiles\i386\ltotape.sys
+ 2004-08-04 05:39:32 20,864 ------w C:\WINDOWS\ServicePackFiles\i386\lwadihid.sys
+ 2008-04-14 00:12:24 72,704 ------w C:\WINDOWS\ServicePackFiles\i386\magnify.exe
+ 2008-04-14 00:12:25 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\makecab.exe
+ 2008-04-14 00:11:56 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\mcastmib.dll
+ 2008-04-14 00:11:56 84,480 ------w C:\WINDOWS\ServicePackFiles\i386\mciavi32.dll
+ 2008-04-14 00:11:56 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\mciqtz32.dll
+ 2008-04-14 00:11:56 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\mciseq.dll
+ 2008-04-14 00:11:56 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\mciwave.dll
+ 2008-04-14 00:11:56 118,272 ------w C:\WINDOWS\ServicePackFiles\i386\mdminst.dll
+ 2008-04-14 00:11:56 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\mdmxsdk.dll
+ 2004-08-04 05:41:56 11,868 ------w C:\WINDOWS\ServicePackFiles\i386\mdmxsdk.sys
+ 2008-04-13 18:41:21 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\memstpci.sys
+ 2008-04-13 18:36:41 63,744 ------w C:\WINDOWS\ServicePackFiles\i386\mf.sys
+ 2008-04-14 00:11:56 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\mf3216.dll
+ 2008-04-14 00:11:56 927,504 ------w C:\WINDOWS\ServicePackFiles\i386\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 ------w C:\WINDOWS\ServicePackFiles\i386\mfc42.dll
+ 2006-10-14 08:13:25 981,760 ------w C:\WINDOWS\ServicePackFiles\i386\mfc42u.dll
+ 2008-04-14 00:11:56 22,528 ------w C:\WINDOWS\ServicePackFiles\i386\mfcsubs.dll
+ 2008-04-14 00:11:56 14,848 ------w C:\WINDOWS\ServicePackFiles\i386\mgmtapi.dll
+ 2008-04-14 00:11:57 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\midimap.dll
+ 2008-04-14 00:11:57 274,432 ------w C:\WINDOWS\ServicePackFiles\i386\migism.dll
+ 2008-04-14 00:11:57 261,120 ------w C:\WINDOWS\ServicePackFiles\i386\migisma.dll
+ 2008-04-14 00:11:57 60,928 ------w C:\WINDOWS\ServicePackFiles\i386\miglibnt.dll
+ 2008-04-14 00:12:25 103,936 ------w C:\WINDOWS\ServicePackFiles\i386\migload.exe
+ 2008-04-14 00:12:25 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\migregdb.exe
+ 2008-04-14 00:12:25 245,248 ------w C:\WINDOWS\ServicePackFiles\i386\migwiz.exe
+ 2008-04-14 00:12:25 241,152 ------w C:\WINDOWS\ServicePackFiles\i386\migwiza.exe
+ 2008-04-14 00:11:57 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\mimefilt.dll
+ 2008-04-14 00:11:57 586,240 ------w C:\WINDOWS\ServicePackFiles\i386\mlang.dll
+ 2008-04-14 00:12:25 1,414,656 ------w C:\WINDOWS\ServicePackFiles\i386\mmc.exe
+ 2008-04-14 00:11:57 184,320 ------w C:\WINDOWS\ServicePackFiles\i386\mmc30.dll
+ 2008-04-14 00:11:57 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\mmc30r.dll
+ 2008-04-14 00:11:57 163,328 ------w C:\WINDOWS\ServicePackFiles\i386\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 ------w C:\WINDOWS\ServicePackFiles\i386\mmcex.dll
+ 2008-04-14 00:11:57 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\mmcexr.dll
+ 2008-04-14 00:11:57 106,496 ------w C:\WINDOWS\ServicePackFiles\i386\mmcfxc.dll
+ 2008-04-14 00:11:57 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\mmcfxcr.dll
+ 2008-04-14 00:11:57 1,872,896 ------w C:\WINDOWS\ServicePackFiles\i386\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\mmcperf.exe
+ 2008-04-14 00:11:57 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\mmcshext.dll
+ 2008-04-14 00:11:57 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\mmfutil.dll
+ 2004-08-04 11:00:00 68,768 ------w C:\WINDOWS\ServicePackFiles\i386\mmsystem.dll
+ 2008-04-14 00:11:57 34,560 ------w C:\WINDOWS\ServicePackFiles\i386\mnmdd.dll
+ 2008-04-14 00:12:25 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\mnmsrvc.exe
+ 2008-04-14 00:11:57 207,360 ------w C:\WINDOWS\ServicePackFiles\i386\mobsync.dll
+ 2008-04-14 00:12:26 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\mobsync.exe
+ 2008-04-13 19:00:19 30,080 ------w C:\WINDOWS\ServicePackFiles\i386\modem.sys
+ 2008-04-14 00:11:57 153,600 ------w C:\WINDOWS\ServicePackFiles\i386\modemui.dll
+ 2008-04-14 00:12:26 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\mofcomp.exe
+ 2008-04-14 00:11:57 123,904 ------w C:\WINDOWS\ServicePackFiles\i386\mofd.dll
+ 2008-04-14 00:12:42 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\more.com
+ 2008-04-13 16:45:30 216,064 ------w C:\WINDOWS\ServicePackFiles\i386\moricons.dll
+ 2008-04-13 18:39:47 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\mouclass.sys
+ 2008-04-13 18:39:46 42,368 ------w C:\WINDOWS\ServicePackFiles\i386\mountmgr.sys
+ 2008-04-14 00:12:27 3,558,912 ------w C:\WINDOWS\ServicePackFiles\i386\moviemk.exe
+ 2008-04-13 18:46:22 15,232 ------w C:\WINDOWS\ServicePackFiles\i386\mpe.sys
+ 2008-04-14 00:12:27 123,392 ------w C:\WINDOWS\ServicePackFiles\i386\mplay32.exe
+ 2008-04-14 00:11:57 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\mpr.dll
+ 2008-04-14 00:11:57 87,040 ------w C:\WINDOWS\ServicePackFiles\i386\mprapi.dll
+ 2008-04-14 00:11:57 53,248 ------w C:\WINDOWS\ServicePackFiles\i386\mprdim.dll
+ 2008-04-13 18:32:44 180,608 ------w C:\WINDOWS\ServicePackFiles\i386\mrxdav.sys
+ 2008-04-13 19:17:01 456,576 ------w C:\WINDOWS\ServicePackFiles\i386\mrxsmb.sys
+ 2008-04-14 00:11:58 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\msacm32.dll
+ 2008-04-14 00:11:58 331,776 ------w C:\WINDOWS\ServicePackFiles\i386\msadce.dll
+ 2008-04-13 17:25:57 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\msadcer.dll
+ 2008-04-14 00:11:58 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\msadcf.dll
+ 2008-04-13 17:25:57 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\msadco.dll
+ 2008-04-13 17:25:57 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msadcor.dll
+ 2008-04-14 00:11:58 53,248 ------w C:\WINDOWS\ServicePackFiles\i386\msadcs.dll
+ 2008-04-14 00:11:58 155,648 ------w C:\WINDOWS\ServicePackFiles\i386\msadds.dll
+ 2008-04-13 17:25:58 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\msader15.dll
+ 2008-04-14 00:11:58 536,576 ------w C:\WINDOWS\ServicePackFiles\i386\msado15.dll
+ 2008-04-14 00:11:58 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\msadomd.dll
+ 2008-04-14 00:11:58 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\msador15.dll
+ 2008-04-14 00:11:58 200,704 ------w C:\WINDOWS\ServicePackFiles\i386\msadox.dll
+ 2008-04-14 00:11:58 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\msadrh15.dll
+ 2008-04-14 00:10:06 3,584 ------w C:\WINDOWS\ServicePackFiles\i386\msafd.dll
+ 2008-04-14 00:11:58 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\msapsspc.dll
+ 2008-04-14 00:11:58 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\msasn1.dll
+ 2008-04-14 00:11:58 220,160 ------w C:\WINDOWS\ServicePackFiles\i386\mscandui.dll
+ 2008-04-14 00:11:58 73,728 ------w C:\WINDOWS\ServicePackFiles\i386\mscms.dll
+ 2008-04-14 00:11:58 69,632 ------w C:\WINDOWS\ServicePackFiles\i386\msconf.dll
+ 2008-04-14 00:12:27 169,984 ------w C:\WINDOWS\ServicePackFiles\i386\msconfig.exe
+ 2007-04-02 20:01:06 116,288 ------w C:\WINDOWS\ServicePackFiles\i386\msconv97.dll
+ 2008-04-13 17:26:07 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\mscpx32r.dll
+ 2008-04-14 00:11:58 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\mscpxl32.dll
+ 2008-04-14 00:11:58 297,984 ------w C:\WINDOWS\ServicePackFiles\i386\msctf.dll
+ 2008-04-14 00:11:58 68,608 ------w C:\WINDOWS\ServicePackFiles\i386\msctfp.dll
+ 2008-04-14 00:11:58 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\msdadc.dll
+ 2008-04-14 00:11:58 118,784 ------w C:\WINDOWS\ServicePackFiles\i386\msdadiag.dll
+ 2008-04-14 00:11:58 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\msdaer.dll
+ 2008-04-14 00:11:58 532,480 ------w C:\WINDOWS\ServicePackFiles\i386\msdaipp.dll
+ 2008-04-14 00:11:58 233,472 ------w C:\WINDOWS\ServicePackFiles\i386\msdaora.dll
+ 2008-04-13 17:24:14 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msdaorar.dll
+ 2008-04-14 00:11:58 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 ------w C:\WINDOWS\ServicePackFiles\i386\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 ------w C:\WINDOWS\ServicePackFiles\i386\msdaps.dll
+ 2008-04-14 00:11:59 118,784 ------w C:\WINDOWS\ServicePackFiles\i386\msdarem.dll
+ 2008-04-13 17:25:58 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msdaremr.dll
+ 2008-04-14 00:11:59 151,552 ------w C:\WINDOWS\ServicePackFiles\i386\msdart.dll
+ 2008-04-14 00:11:59 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\msdasc.dll
+ 2008-04-14 00:11:59 315,392 ------w C:\WINDOWS\ServicePackFiles\i386\msdasql.dll
+ 2008-04-13 17:26:07 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msdasqlr.dll
+ 2008-04-14 00:11:59 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\msdatl3.dll
+ 2008-04-14 00:11:59 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\msdatt.dll
+ 2008-04-14 00:11:59 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\msdfmap.dll
+ 2008-04-14 00:11:59 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\msdmo.dll
+ 2008-04-14 00:12:27 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\msdtc.exe
+ 2008-04-14 00:11:59 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\msdtclog.dll
+ 2008-04-14 00:11:59 427,008 ------w C:\WINDOWS\ServicePackFiles\i386\msdtcprx.dll
+ 2008-04-14 00:11:59 90,112 ------w C:\WINDOWS\ServicePackFiles\i386\msdtcstp.dll
+ 2008-04-14 00:11:59 956,928 ------w C:\WINDOWS\ServicePackFiles\i386\msdtctm.dll
+ 2008-04-14 00:11:59 161,792 ------w C:\WINDOWS\ServicePackFiles\i386\msdtcuiu.dll
+ 2008-04-13 18:46:09 51,200 ------w C:\WINDOWS\ServicePackFiles\i386\msdv.sys
+ 2008-03-25 04:50:28 518,944 ------w C:\WINDOWS\ServicePackFiles\i386\msexch40.dll
+ 2008-03-25 04:50:30 326,432 ------w C:\WINDOWS\ServicePackFiles\i386\msexcl40.dll
+ 2008-04-13 18:32:39 19,072 ------w C:\WINDOWS\ServicePackFiles\i386\msfs.sys
+ 2008-04-14 00:11:59 539,136 ------w C:\WINDOWS\ServicePackFiles\i386\msftedit.dll
+ 2008-04-14 00:11:59 997,376 ------w C:\WINDOWS\ServicePackFiles\i386\msgina.dll
+ 2008-04-13 18:56:32 35,072 ------w C:\WINDOWS\ServicePackFiles\i386\msgpc.sys
+ 2008-04-14 00:11:59 3,166,208 ------w C:\WINDOWS\ServicePackFiles\i386\msgr3en.dll
+ 2008-04-14 00:11:59 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\msgrocm.dll
+ 2008-04-14 00:11:59 82,944 ------w C:\WINDOWS\ServicePackFiles\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\msgslang.dll
+ 2008-04-14 00:11:59 33,792 ------w C:\WINDOWS\ServicePackFiles\i386\msgsvc.dll
+ 2008-04-14 00:12:45 188,416 ------w C:\WINDOWS\ServicePackFiles\i386\msh261.drv
+ 2008-04-14 00:12:45 294,912 ------w C:\WINDOWS\ServicePackFiles\i386\msh263.drv
+ 2008-04-14 00:12:27 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\mshta.exe
+ 2008-04-14 00:11:59 3,066,880 ------w C:\WINDOWS\ServicePackFiles\i386\mshtml.dll
+ 2008-04-14 00:11:59 449,024 ------w C:\WINDOWS\ServicePackFiles\i386\mshtmled.dll
+ 2008-04-13 16:26:26 56,832 ------w C:\WINDOWS\ServicePackFiles\i386\mshtmler.dll
+ 2008-04-14 00:11:59 2,843,136 ------w C:\WINDOWS\ServicePackFiles\i386\msi.dll
+ 2008-04-14 00:11:59 51,712 ------w C:\WINDOWS\ServicePackFiles\i386\msident.dll
+ 2008-04-14 00:11:59 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\msidle.dll
+ 2008-04-14 00:11:59 248,832 ------w C:\WINDOWS\ServicePackFiles\i386\msieftp.dll
+ 2008-04-14 00:12:28 78,848 ------w C:\WINDOWS\ServicePackFiles\i386\msiexec.exe
+ 2008-04-14 00:11:59 271,360 ------w C:\WINDOWS\ServicePackFiles\i386\msihnd.dll
+ 2008-04-14 00:11:59 4,608 ------w C:\WINDOWS\ServicePackFiles\i386\msimg32.dll
+ 2008-04-14 00:12:28 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\msimn.exe
+ 2008-04-13 15:39:43 884,736 ------w C:\WINDOWS\ServicePackFiles\i386\msimsg.dll
+ 2008-04-14 00:11:59 159,232 ------w C:\WINDOWS\ServicePackFiles\i386\msimtf.dll
+ 2008-04-14 00:11:59 376,832 ------w C:\WINDOWS\ServicePackFiles\i386\msinfo.dll
+ 2008-04-13 18:54:28 22,016 ------w C:\WINDOWS\ServicePackFiles\i386\msircomm.sys
+ 2008-04-14 00:12:28 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\msiregmv.exe
+ 2008-04-14 00:11:59 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\msisip.dll
+ 2008-03-25 04:50:34 1,516,568 ------w C:\WINDOWS\ServicePackFiles\i386\msjet40.dll
+ 2008-03-25 04:50:40 355,112 ------w C:\WINDOWS\ServicePackFiles\i386\msjetol1.dll
+ 2008-04-14 00:12:00 151,583 ------w C:\WINDOWS\ServicePackFiles\i386\msjint40.dll
+ 2008-04-14 00:12:00 102,400 ------w C:\WINDOWS\ServicePackFiles\i386\msjro.dll
+ 2008-03-25 04:50:42 60,192 ------w C:\WINDOWS\ServicePackFiles\i386\msjter40.dll
+ 2008-03-25 04:50:42 248,608 ------w C:\WINDOWS\ServicePackFiles\i386\msjtes40.dll
+ 2008-04-13 18:39:52 7,552 ------w C:\WINDOWS\ServicePackFiles\i386\mskssrv.sys
+ 2008-04-14 00:12:00 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\mslbui.dll
+ 2008-03-25 04:50:44 219,936 ------w C:\WINDOWS\ServicePackFiles\i386\msltus40.dll
+ 2008-04-14 00:12:00 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\mslwvtts.dll
+ 2008-04-14 00:12:28 1,695,232 ------w C:\WINDOWS\ServicePackFiles\i386\msmsgs.exe
+ 2004-07-17 18:41:46 11,053,008 ------w C:\WINDOWS\ServicePackFiles\i386\msncli.exe
+ 2008-04-14 00:12:00 290,816 ------w C:\WINDOWS\ServicePackFiles\i386\msnsspc.dll
+ 2004-07-17 18:41:46 1,327,320 ------w C:\WINDOWS\ServicePackFiles\i386\msnsusii.exe
+ 2008-04-14 00:12:00 122,368 ------w C:\WINDOWS\ServicePackFiles\i386\msobcomm.dll
+ 2008-04-14 00:12:00 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\msobdl.dll
+ 2008-04-14 00:12:00 565,248 ------w C:\WINDOWS\ServicePackFiles\i386\msobmain.dll
+ 2008-04-14 00:12:00 30,720 ------w C:\WINDOWS\ServicePackFiles\i386\msobshel.dll
+ 2008-04-14 00:12:00 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\msobweb.dll
+ 2008-04-14 00:12:00 1,314,816 ------w C:\WINDOWS\ServicePackFiles\i386\msoe.dll
+ 2008-04-14 00:12:00 252,928 ------w C:\WINDOWS\ServicePackFiles\i386\msoeacct.dll
+ 2008-04-13 16:23:54 2,479,616 ------w C:\WINDOWS\ServicePackFiles\i386\msoeres.dll
+ 2008-04-14 00:12:00 105,984 ------w C:\WINDOWS\ServicePackFiles\i386\msoert2.dll
+ 2008-04-14 00:12:28 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\msoobe.exe
+ 2008-04-13 17:24:14 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\msorc32r.dll
+ 2008-04-14 00:12:00 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\msorcl32.dll
+ 2008-04-14 00:12:28 343,040 ------w C:\WINDOWS\ServicePackFiles\i386\mspaint.exe
+ 2008-04-14 00:12:00 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\mspatcha.dll
+ 2008-03-25 04:50:45 355,104 ------w C:\WINDOWS\ServicePackFiles\i386\mspbde40.dll
+ 2008-04-13 18:39:50 5,376 ------w C:\WINDOWS\ServicePackFiles\i386\mspclock.sys
+ 2008-04-13 18:39:51 4,992 ------w C:\WINDOWS\ServicePackFiles\i386\mspqm.sys
+ 2008-04-13 16:23:31 48,128 ------w C:\WINDOWS\ServicePackFiles\i386\msprivs.dll
+ 2008-04-14 00:12:00 146,432 ------w C:\WINDOWS\ServicePackFiles\i386\msrating.dll
+ 2008-03-25 04:50:47 432,928 ------w C:\WINDOWS\ServicePackFiles\i386\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 ------w C:\WINDOWS\ServicePackFiles\i386\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 ------w C:\WINDOWS\ServicePackFiles\i386\msrepl40.dll
+ 2008-04-14 00:12:00 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\msrle32.dll
+ 2008-04-14 00:12:00 134,656 ------w C:\WINDOWS\ServicePackFiles\i386\mssap.dll
+ 2008-04-14 00:12:00 155,136 ------w C:\WINDOWS\ServicePackFiles\i386\mssha.dll
+ 2008-04-13 18:14:58 76,800 ------w C:\WINDOWS\ServicePackFiles\i386\msshamsg.dll
+ 2008-04-13 18:36:46 15,488 ------w C:\WINDOWS\ServicePackFiles\i386\mssmbios.sys
+ 2008-04-14 00:12:00 274,432 ------w C:\WINDOWS\ServicePackFiles\i386\mst120.dll
+ 2008-04-14 00:12:00 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\mst123.dll
+ 2008-04-13 18:46:08 49,024 ------w C:\WINDOWS\ServicePackFiles\i386\mstape.sys
+ 2008-04-14 00:12:00 274,944 ------w C:\WINDOWS\ServicePackFiles\i386\mstask.dll
+ 2008-04-13 18:39:50 5,504 ------w C:\WINDOWS\ServicePackFiles\i386\mstee.sys
+ 2008-03-25 04:50:55 264,992 ------w C:\WINDOWS\ServicePackFiles\i386\mstext40.dll
+ 2008-04-14 00:12:00 532,480 ------w C:\WINDOWS\ServicePackFiles\i386\mstime.dll
+ 2008-04-14 00:12:29 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\mstinit.exe
+ 2008-04-14 00:12:00 116,224 ------w C:\WINDOWS\ServicePackFiles\i386\mstlsapi.dll
+ 2008-04-14 00:12:00 195,072 ------w C:\WINDOWS\ServicePackFiles\i386\msutb.dll
+ 2008-04-14 00:12:00 132,608 ------w C:\WINDOWS\ServicePackFiles\i386\msv1_0.dll
+ 2008-04-14 00:12:00 1,384,479 ------w C:\WINDOWS\ServicePackFiles\i386\msvbvm60.dll
+ 2008-04-14 00:12:01 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\msvcirt.dll
+ 2008-04-14 00:12:01 413,696 ------w C:\WINDOWS\ServicePackFiles\i386\msvcp60.dll
+ 2008-04-14 00:12:01 343,040 ------w C:\WINDOWS\ServicePackFiles\i386\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\msvcrt40.dll
+ 2008-04-14 00:12:01 121,344 ------w C:\WINDOWS\ServicePackFiles\i386\msvfw32.dll
+ 2008-04-14 00:12:01 1,428,992 ------w C:\WINDOWS\ServicePackFiles\i386\msvidctl.dll
+ 2008-04-14 00:12:01 72,704 ------w C:\WINDOWS\ServicePackFiles\i386\msw3prt.dll
+ 2008-03-25 04:50:57 838,432 ------w C:\WINDOWS\ServicePackFiles\i386\mswdat10.dll
+ 2008-04-14 00:12:01 203,776 ------w C:\WINDOWS\ServicePackFiles\i386\mswebdvd.dll
+ 2008-04-14 00:12:01 245,248 ------w C:\WINDOWS\ServicePackFiles\i386\mswsock.dll
+ 2008-03-25 04:50:58 621,344 ------w C:\WINDOWS\ServicePackFiles\i386\mswstr10.dll
+ 2008-04-14 00:12:01 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\msxactps.dll
+ 2008-03-25 04:50:58 355,104 ------w C:\WINDOWS\ServicePackFiles\i386\msxbde40.dll
+ 2008-04-14 00:12:01 506,368 ------w C:\WINDOWS\ServicePackFiles\i386\msxml.dll
+ 2008-04-14 00:12:01 701,440 ------w C:\WINDOWS\ServicePackFiles\i386\msxml2.dll
+ 2008-04-14 00:12:01 1,104,896 ------w C:\WINDOWS\ServicePackFiles\i386\msxml3.dll
+ 2008-04-14 00:12:01 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\msyuv.dll
+ 2004-08-04 05:41:40 126,686 ------w C:\WINDOWS\ServicePackFiles\i386\mtlmnt5.sys
+ 2004-08-04 05:41:38 1,309,184 ------w C:\WINDOWS\ServicePackFiles\i386\mtlstrm.sys
+ 2008-04-14 00:12:29 119,808 ------w C:\WINDOWS\ServicePackFiles\i386\mtstocom.exe
+ 2008-04-14 00:12:01 66,560 ------w C:\WINDOWS\ServicePackFiles\i386\mtxclu.dll
+ 2008-04-14 00:12:01 30,720 ------w C:\WINDOWS\ServicePackFiles\i386\mtxdm.dll
+ 2008-04-14 00:12:01 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\mtxex.dll
+ 2008-04-14 00:12:01 34,304 ------w C:\WINDOWS\ServicePackFiles\i386\mtxlegih.dll
+ 2008-04-14 00:12:01 91,648 ------w C:\WINDOWS\ServicePackFiles\i386\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 ------w C:\WINDOWS\ServicePackFiles\i386\mtxparhd.dll
+ 2004-08-04 05:29:38 452,736 ------w C:\WINDOWS\ServicePackFiles\i386\mtxparhm.sys
+ 2008-04-14 00:12:29 90,624 ------w C:\WINDOWS\ServicePackFiles\i386\muisetup.exe
+ 2008-04-13 19:17:05 105,344 ------w C:\WINDOWS\ServicePackFiles\i386\mup.sys
+ 2008-04-13 18:43:55 12,672 ------w C:\WINDOWS\ServicePackFiles\i386\mutohpen.sys
+ 2008-04-14 00:12:01 90,624 ------w C:\WINDOWS\ServicePackFiles\i386\mydocs.dll
+ 2008-04-13 18:46:25 85,248 ------w C:\WINDOWS\ServicePackFiles\i386\nabtsfec.sys
+ 2008-04-14 00:12:01 221,184 ------w C:\WINDOWS\ServicePackFiles\i386\nac.dll
+ 2008-04-14 00:12:01 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\napipsec.dll
+ 2008-04-14 00:12:01 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\napmontr.dll
+ 2008-04-14 00:12:29 176,640 ------w C:\WINDOWS\ServicePackFiles\i386\napstat.exe
+ 2008-04-14 00:12:29 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\narrator.exe
+ 2008-04-14 00:12:01 36,352 ------w C:\WINDOWS\ServicePackFiles\i386\ncobjapi.dll
+ 2008-04-14 00:12:01 47,104 ------w C:\WINDOWS\ServicePackFiles\i386\ncprov.dll
+ 2008-04-14 00:12:01 9,728 ------w C:\WINDOWS\ServicePackFiles\i386\ncpsres.dll
+ 2008-04-14 00:12:01 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\nddeapi.dll
+ 2008-04-14 00:12:29 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\nddeapir.exe
+ 2008-04-14 00:12:01 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\nddenb32.dll
+ 2008-04-13 19:20:37 182,656 ------w C:\WINDOWS\ServicePackFiles\i386\ndis.sys
+ 2008-04-13 18:46:22 10,880 ------w C:\WINDOWS\ServicePackFiles\i386\ndisip.sys
+ 2008-04-14 00:12:01 57,344 ------w C:\WINDOWS\ServicePackFiles\i386\ndisnpp.dll
+ 2008-04-13 18:57:27 10,112 ------w C:\WINDOWS\ServicePackFiles\i386\ndistapi.sys
+ 2008-04-13 18:55:58 14,592 ------w C:\WINDOWS\ServicePackFiles\i386\ndisuio.sys
+ 2008-04-13 19:20:42 91,520 ------w C:\WINDOWS\ServicePackFiles\i386\ndiswan.sys
+ 2008-04-13 18:57:29 40,576 ------w C:\WINDOWS\ServicePackFiles\i386\ndproxy.sys
+ 2008-04-14 00:12:29 42,496 ------w C:\WINDOWS\ServicePackFiles\i386\net.exe
+ 2008-04-14 00:12:29 124,928 ------w C:\WINDOWS\ServicePackFiles\i386\net1.exe
+ 2008-04-14 00:12:01 337,408 ------w C:\WINDOWS\ServicePackFiles\i386\netapi32.dll
+ 2008-04-13 18:56:02 34,688 ------w C:\WINDOWS\ServicePackFiles\i386\netbios.sys
+ 2008-04-13 19:21:00 162,816 ------w C:\WINDOWS\ServicePackFiles\i386\netbt.sys
+ 2008-04-14 00:12:01 622,592 ------w C:\WINDOWS\ServicePackFiles\i386\netcfgx.dll
+ 2008-04-14 00:12:29 111,104 ------w C:\WINDOWS\ServicePackFiles\i386\netdde.exe
+ 2008-04-14 00:12:01 139,264 ------w C:\WINDOWS\ServicePackFiles\i386\netid.dll
+ 2008-04-14 00:12:01 407,040 ------w C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
+ 2008-04-14 00:12:01 198,144 ------w C:\WINDOWS\ServicePackFiles\i386\netman.dll
+ 2008-04-14 00:12:01 77,312 ------w C:\WINDOWS\ServicePackFiles\i386\netoc.dll
+ 2008-04-14 00:12:01 875,008 ------w C:\WINDOWS\ServicePackFiles\i386\netplwiz.dll
+ 2008-04-14 00:12:01 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\netrap.dll
+ 2008-04-14 00:16:51 329,728 ------w C:\WINDOWS\ServicePackFiles\i386\netsetup.exe
+ 2008-04-14 00:12:29 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\netsh.exe
+ 2008-04-14 00:12:02 1,703,936 ------w C:\WINDOWS\ServicePackFiles\i386\netshell.dll
+ 2008-04-14 00:12:29 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\netstat.exe
+ 2008-04-14 00:12:02 80,896 ------w C:\WINDOWS\ServicePackFiles\i386\netui0.dll
+ 2008-04-14 00:12:02 245,760 ------w C:\WINDOWS\ServicePackFiles\i386\netui1.dll
+ 2004-08-04 05:31:42 132,695 ------w C:\WINDOWS\ServicePackFiles\i386\netwlan5.sys
+ 2008-04-14 00:12:02 247,808 ------w C:\WINDOWS\ServicePackFiles\i386\newdev.dll
+ 2008-04-13 18:51:25 61,824 ------w C:\WINDOWS\ServicePackFiles\i386\nic1394.sys
+ 2008-04-14 00:12:02 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\nlhtml.dll
+ 2008-04-14 00:12:02 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\nmas.dll
+ 2008-04-14 00:12:02 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\nmasnt.dll
+ 2008-04-14 00:12:02 81,920 ------w C:\WINDOWS\ServicePackFiles\i386\nmchat.dll
+ 2008-04-14 00:12:02 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\nmcom.dll
+ 2008-04-14 00:12:02 151,552 ------w C:\WINDOWS\ServicePackFiles\i386\nmft.dll
+ 2008-04-14 00:12:02 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\nmmkcert.dll
+ 2008-04-13 18:53:09 40,320 ------w C:\WINDOWS\ServicePackFiles\i386\nmnt.sys
+ 2008-04-14 00:12:02 172,032 ------w C:\WINDOWS\ServicePackFiles\i386\nmoldwb.dll
+ 2008-04-14 00:12:02 188,416 ------w C:\WINDOWS\ServicePackFiles\i386\nmwb.dll
+ 2008-04-14 00:12:29 69,120 ------w C:\WINDOWS\ServicePackFiles\i386\notepad.exe
+ 2008-04-13 18:32:39 30,848 ------w C:\WINDOWS\ServicePackFiles\i386\npfs.sys
+ 2008-04-14 00:12:29 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\nppagent.exe
+ 2008-04-14 00:12:02 54,784 ------w C:\WINDOWS\ServicePackFiles\i386\npptools.dll
+ 2008-04-13 18:54:36 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\nscirda.sys
+ 2008-04-14 00:12:29 76,800 ------w C:\WINDOWS\ServicePackFiles\i386\nslookup.exe
+ 2004-08-04 11:00:00 47,564 ------w C:\WINDOWS\ServicePackFiles\i386\ntdetect.com
+ 2008-04-14 00:11:24 706,048 ------w C:\WINDOWS\ServicePackFiles\i386\ntdll.dll
+ 2008-04-14 00:12:02 67,072 ------w C:\WINDOWS\ServicePackFiles\i386\ntdsapi.dll
+ 2008-04-14 00:12:02 212,992 ------w C:\WINDOWS\ServicePackFiles\i386\ntevt.dll
+ 2008-04-13 19:15:53 574,976 ------w C:\WINDOWS\ServicePackFiles\i386\ntfs.sys
+ 2004-08-04 11:00:00 33,840 ------w C:\WINDOWS\ServicePackFiles\i386\ntio.sys
+ 2004-08-04 11:00:00 34,560 ------w C:\WINDOWS\ServicePackFiles\i386\ntio404.sys
+ 2004-08-04 11:00:00 35,648 ------w C:\WINDOWS\ServicePackFiles\i386\ntio411.sys
+ 2004-08-04 11:00:00 35,424 ------w C:\WINDOWS\ServicePackFiles\i386\ntio412.sys
+ 2004-08-04 11:00:00 34,560 ------w C:\WINDOWS\ServicePackFiles\i386\ntio804.sys
+ 2008-04-13 19:24:37 2,145,280 ------w C:\WINDOWS\ServicePackFiles\i386\ntkrnlmp.exe
+ 2008-04-13 18:31:21 2,065,792 ------w C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
+ 2008-04-13 18:31:21 2,023,936 ------w C:\WINDOWS\ServicePackFiles\i386\ntkrpamp.exe
+ 2008-04-14 00:12:02 44,032 ------w C:\WINDOWS\ServicePackFiles\i386\ntlanman.dll
+ 2008-04-14 00:12:02 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\ntlsapi.dll
+ 2008-04-14 00:12:02 118,784 ------w C:\WINDOWS\ServicePackFiles\i386\ntmarta.dll
+ 2008-04-14 00:12:02 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\ntmsapi.dll
+ 2008-04-14 00:12:02 179,200 ------w C:\WINDOWS\ServicePackFiles\i386\ntmsdba.dll
+ 2008-04-14 00:12:02 488,448 ------w C:\WINDOWS\ServicePackFiles\i386\ntmsmgr.dll
+ 2008-04-14 00:12:02 435,200 ------w C:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll
+ 2004-08-04 05:41:40 180,360 ------w C:\WINDOWS\ServicePackFiles\i386\ntmtlfax.sys
+ 2008-04-14 00:12:02 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\ntoc.dll
+ 2008-04-13 19:27:53 2,188,928 ------w C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
+ 2008-04-14 00:12:02 91,136 ------w C:\WINDOWS\ServicePackFiles\i386\ntprint.dll
+ 2008-04-14 00:12:02 143,360 ------w C:\WINDOWS\ServicePackFiles\i386\ntshrui.dll
+ 2008-04-14 00:12:30 420,864 ------w C:\WINDOWS\ServicePackFiles\i386\ntvdm.exe
+ 2008-04-14 00:12:02 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\ntvdmd.dll
+ 2008-04-14 00:12:02 4,274,816 ------w C:\WINDOWS\ServicePackFiles\i386\nv4_disp.dll
+ 2004-08-04 04:29:56 1,897,408 ------w C:\WINDOWS\ServicePackFiles\i386\nv4_mini.sys
+ 2008-04-13 18:56:06 88,320 ------w C:\WINDOWS\ServicePackFiles\i386\nwlnkipx.sys
+ 2008-04-14 00:12:02 142,336 ------w C:\WINDOWS\ServicePackFiles\i386\nwprovau.dll
+ 2008-04-14 00:12:02 270,336 ------w C:\WINDOWS\ServicePackFiles\i386\oakley.dll
+ 2008-04-14 00:10:30 229,376 ------w C:\WINDOWS\ServicePackFiles\i386\obelog.dll
+ 2008-04-14 00:10:30 966,656 ------w C:\WINDOWS\ServicePackFiles\i386\obemetal.dll
+ 2007-04-02 18:44:11 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\obemtllc.dll
+ 2008-04-14 00:10:30 86,016 ------w C:\WINDOWS\ServicePackFiles\i386\obepopc.dll
+ 2008-04-14 00:12:02 286,208 ------w C:\WINDOWS\ServicePackFiles\i386\objsel.dll
+ 2008-04-13 18:40:52 405,504 ------w C:\WINDOWS\ServicePackFiles\i386\obrb041b.dll
+ 2008-04-13 18:40:56 408,576 ------w C:\WINDOWS\ServicePackFiles\i386\obrb0424.dll
+ 2008-04-14 00:12:02 96,256 ------w C:\WINDOWS\ServicePackFiles\i386\occache.dll
+ 2008-04-14 00:12:02 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\ocgen.dll
+ 2008-04-14 00:12:02 67,584 ------w C:\WINDOWS\ServicePackFiles\i386\ocmanage.dll
+ 2008-04-14 00:12:02 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\ocmsn.dll
+ 2004-08-04 11:00:00 26,224 ------w C:\WINDOWS\ServicePackFiles\i386\odbc16gt.dll
+ 2008-04-14 00:12:02 249,856 ------w C:\WINDOWS\ServicePackFiles\i386\odbc32.dll
+ 2008-04-14 00:12:02 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\odbc32gt.dll
+ 2008-04-14 00:12:30 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\odbcad32.exe
+ 2008-04-14 00:12:02 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\odbcbcp.dll
+ 2008-04-14 00:12:02 135,168 ------w C:\WINDOWS\ServicePackFiles\i386\odbcconf.dll
+ 2008-04-14 00:12:30 69,632 ------w C:\WINDOWS\ServicePackFiles\i386\odbcconf.exe
+ 2008-04-14 00:12:02 106,496 ------w C:\WINDOWS\ServicePackFiles\i386\odbccp32.dll
+ 2008-04-14 00:12:02 65,536 ------w C:\WINDOWS\ServicePackFiles\i386\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 ------w C:\WINDOWS\ServicePackFiles\i386\odbccu32.dll
+ 2008-04-13 17:26:05 94,208 ------w C:\WINDOWS\ServicePackFiles\i386\odbcint.dll
+ 2008-04-14 00:10:31 53,279 ------w C:\WINDOWS\ServicePackFiles\i386\odbcji32.dll
+ 2008-04-14 00:12:02 278,559 ------w C:\WINDOWS\ServicePackFiles\i386\odbcjt32.dll
+ 2008-04-13 17:26:05 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\odbcp32r.dll
+ 2008-04-14 00:12:02 147,456 ------w C:\WINDOWS\ServicePackFiles\i386\odbctrac.dll
+ 2008-04-14 00:12:02 20,511 ------w C:\WINDOWS\ServicePackFiles\i386\oddbse32.dll
+ 2008-04-14 00:12:02 20,510 ------w C:\WINDOWS\ServicePackFiles\i386\odexl32.dll
+ 2008-04-14 00:12:02 20,510 ------w C:\WINDOWS\ServicePackFiles\i386\odfox32.dll
+ 2008-04-14 00:12:02 20,510 ------w C:\WINDOWS\ServicePackFiles\i386\odpdx32.dll
+ 2008-04-14 00:12:02 20,511 ------w C:\WINDOWS\ServicePackFiles\i386\odtext32.dll
+ 2008-04-14 00:12:02 104,448 ------w C:\WINDOWS\ServicePackFiles\i386\oeimport.dll
+ 2008-04-14 00:12:30 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\oemig50.exe
+ 2008-04-14 00:12:02 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\oemiglib.dll
+ 2008-04-14 00:12:02 192,000 ------w C:\WINDOWS\ServicePackFiles\i386\offfilt.dll
+ 2008-04-13 18:46:18 61,696 ------w C:\WINDOWS\ServicePackFiles\i386\ohci1394.sys
+ 2008-04-14 00:12:02 1,287,168 ------w C:\WINDOWS\ServicePackFiles\i386\ole32.dll
+ 2008-04-14 00:12:02 551,936 ------w C:\WINDOWS\ServicePackFiles\i386\oleaut32.dll
+ 2008-04-14 00:12:02 74,752 ------w C:\WINDOWS\ServicePackFiles\i386\olecli32.dll
+ 2008-04-14 00:12:02 37,376 ------w C:\WINDOWS\ServicePackFiles\i386\olecnv32.dll
+ 2008-04-14 00:12:02 487,424 ------w C:\WINDOWS\ServicePackFiles\i386\oledb32.dll
+ 2008-04-14 00:12:02 65,536 ------w C:\WINDOWS\ServicePackFiles\i386\oledb32r.dll
+ 2008-04-14 00:12:02 122,880 ------w C:\WINDOWS\ServicePackFiles\i386\oledlg.dll
+ 2008-04-14 00:12:02 107,008 ------w C:\WINDOWS\ServicePackFiles\i386\oleprn.dll
+ 2008-04-14 00:12:02 84,992 ------w C:\WINDOWS\ServicePackFiles\i386\olepro32.dll
+ 2008-04-14 00:12:02 144,384 ------w C:\WINDOWS\ServicePackFiles\i386\onex.dll
+ 2008-04-14 00:12:31 51,200 ------w C:\WINDOWS\ServicePackFiles\i386\oobebaln.exe
+ 2008-04-14 00:12:02 713,728 ------w C:\WINDOWS\ServicePackFiles\i386\opengl32.dll
+ 2008-04-13 18:32:32 166,912 ------w C:\WINDOWS\ServicePackFiles\i386\oschoice.exe
+ 2008-04-14 00:12:31 215,552 ------w C:\WINDOWS\ServicePackFiles\i386\osk.exe
+ 2008-04-13 18:31:43 230,400 ------w C:\WINDOWS\ServicePackFiles\i386\osloader.exe
+ 2008-04-14 00:12:02 67,584 ------w C:\WINDOWS\ServicePackFiles\i386\osuninst.dll
+ 2008-04-14 00:12:02 153,600 ------w C:\WINDOWS\ServicePackFiles\i386\p2p.dll
+ 2008-04-14 00:12:02 105,472 ------w C:\WINDOWS\ServicePackFiles\i386\p2pgasvc.dll
+ 2008-04-14 00:12:02 313,856 ------w C:\WINDOWS\ServicePackFiles\i386\p2pgraph.dll
+ 2008-04-14 00:12:02 115,712 ------w C:\WINDOWS\ServicePackFiles\i386\p2pnetsh.dll
+ 2008-04-14 00:12:02 554,496 ------w C:\WINDOWS\ServicePackFiles\i386\p2psvc.dll
+ 2008-04-13 18:31:31 42,752 ------w C:\WINDOWS\ServicePackFiles\i386\p3.sys
+ 2008-04-14 00:12:31 58,368 ------w C:\WINDOWS\ServicePackFiles\i386\packager.exe
+ 2008-04-13 18:40:10 80,128 ------w C:\WINDOWS\ServicePackFiles\i386\parport.sys
+ 2008-04-13 18:40:49 19,712 ------w C:\WINDOWS\ServicePackFiles\i386\partmgr.sys
+ 2008-04-14 00:12:02 67,584 ------w C:\WINDOWS\ServicePackFiles\i386\pautoenr.dll
+ 2004-08-04 05:31:24 29,502 ------w C:\WINDOWS\ServicePackFiles\i386\pca200e.sys
+ 2008-04-14 00:12:02 102,912 ------w C:\WINDOWS\ServicePackFiles\i386\pchshell.dll
+ 2008-04-14 00:12:02 38,400 ------w C:\WINDOWS\ServicePackFiles\i386\pchsvc.dll
+ 2008-04-13 18:36:44 68,224 ------w C:\WINDOWS\ServicePackFiles\i386\pci.sys
+ 2008-04-13 18:40:29 24,960 ------w C:\WINDOWS\ServicePackFiles\i386\pciidex.sys
+ 2007-05-15 08:08:11 288,768 ------w C:\WINDOWS\ServicePackFiles\i386\pcl4res.dll
+ 2007-05-15 08:08:13 1,058,816 ------w C:\WINDOWS\ServicePackFiles\i386\pcl5eres.dll
+ 2007-05-15 08:08:14 1,057,280 ------w C:\WINDOWS\ServicePackFiles\i386\pcl5ures.dll
+ 2007-05-15 08:08:14 207,872 ------w C:\WINDOWS\ServicePackFiles\i386\pclxl.dll
+ 2008-04-13 18:36:43 120,192 ------w C:\WINDOWS\ServicePackFiles\i386\pcmcia.sys
+ 2004-08-04 05:06:18 169,984 ------w C:\WINDOWS\ServicePackFiles\i386\pcx500.sys
+ 2008-04-14 00:12:02 284,160 ------w C:\WINDOWS\ServicePackFiles\i386\pdh.dll
+ 2008-04-14 00:12:02 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\perfctrs.dll
+ 2008-04-14 00:12:02 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\perfdisk.dll
+ 2008-04-14 00:12:31 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\perfmon.exe
+ 2008-04-14 00:12:02 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\perfnet.dll
+ 2008-04-14 00:12:02 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\perfos.dll
+ 2008-04-14 00:12:02 34,816 ------w C:\WINDOWS\ServicePackFiles\i386\perfproc.dll
+ 2008-04-13 18:44:29 27,904 ------w C:\WINDOWS\ServicePackFiles\i386\perm2.sys
+ 2008-04-14 00:10:34 211,584 ------w C:\WINDOWS\ServicePackFiles\i386\perm2dll.dll
+ 2008-04-13 18:44:30 28,032 ------w C:\WINDOWS\ServicePackFiles\i386\perm3.sys
+ 2008-04-14 00:10:34 259,328 ------w C:\WINDOWS\ServicePackFiles\i386\perm3dd.dll
+ 2008-04-14 00:12:02 176,128 ------w C:\WINDOWS\ServicePackFiles\i386\photowiz.dll
+ 2008-04-14 00:12:02 35,328 ------w C:\WINDOWS\ServicePackFiles\i386\pid.dll
+ 2008-04-13 18:35:22 24,064 ------w C:\WINDOWS\ServicePackFiles\i386\pidgen.dll
+ 2008-04-14 00:12:31 281,088 ------w C:\WINDOWS\ServicePackFiles\i386\pinball.exe
+ 2008-04-14 00:12:31 17,920 ------w C:\WINDOWS\ServicePackFiles\i386\ping.exe
+ 2008-04-14 00:12:02 15,360 ------w C:\WINDOWS\ServicePackFiles\i386\pjlmon.dll
+ 2008-04-14 00:12:02 44,544 ------w C:\WINDOWS\ServicePackFiles\i386\plotter.dll
+ 2008-04-14 00:12:02 52,736 ------w C:\WINDOWS\ServicePackFiles\i386\plotui.dll
+ 2008-04-14 00:12:02 412,160 ------w C:\WINDOWS\ServicePackFiles\i386\pmh.dll
+ 2008-04-14 00:12:02 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\pngfilt.dll
+ 2008-04-14 00:12:02 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\pnrpnsp.dll
+ 2008-04-14 00:12:02 105,472 ------w C:\WINDOWS\ServicePackFiles\i386\polstore.dll
+ 2008-04-13 19:19:41 146,048 ------w C:\WINDOWS\ServicePackFiles\i386\portcls.sys
+ 2008-04-14 00:12:31 49,152 ------w C:\WINDOWS\ServicePackFiles\i386\powercfg.exe
+ 2008-04-13 18:40:56 8,832 ------w C:\WINDOWS\ServicePackFiles\i386\powerfil.sys
+ 2008-04-14 00:12:03 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\powrprof.dll
+ 2008-04-13 18:41:00 17,664 ------w C:\WINDOWS\ServicePackFiles\i386\ppa3.sys
+ 2008-04-14 00:12:03 560,640 ------w C:\WINDOWS\ServicePackFiles\i386\printui.dll
+ 2008-04-13 18:31:30 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\processr.sys
+ 2008-04-14 00:12:03 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\profmap.dll
+ 2008-04-14 00:12:31 109,568 ------w C:\WINDOWS\ServicePackFiles\i386\progman.exe
+ 2008-04-14 00:12:32 50,176 ------w C:\WINDOWS\ServicePackFiles\i386\proquota.exe
+ 2008-04-14 00:12:03 237,056 ------w C:\WINDOWS\ServicePackFiles\i386\provthrd.dll
+ 2008-04-14 00:12:32 9,216 ------w C:\WINDOWS\ServicePackFiles\i386\proxycfg.exe
+ 2008-04-14 00:12:03 728,576 ------w C:\WINDOWS\ServicePackFiles\i386\ps5ui.dll
+ 2008-04-14 00:12:03 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\psapi.dll
+ 2008-04-14 00:12:03 96,768 ------w C:\WINDOWS\ServicePackFiles\i386\psbase.dll
+ 2008-04-13 18:56:38 69,120 ------w C:\WINDOWS\ServicePackFiles\i386\psched.sys
+ 2008-04-14 00:12:03 543,232 ------w C:\WINDOWS\ServicePackFiles\i386\pscript5.dll
+ 2008-04-14 00:12:03 363,520 ------w C:\WINDOWS\ServicePackFiles\i386\psisdecd.dll
+ 2008-04-14 00:12:03 43,520 ------w C:\WINDOWS\ServicePackFiles\i386\pstorec.dll
+ 2008-04-14 00:12:03 34,304 ------w C:\WINDOWS\ServicePackFiles\i386\pstorsvc.dll
+ 2008-04-14 00:12:03 159,232 ------w C:\WINDOWS\ServicePackFiles\i386\ptpusd.dll
+ 2008-04-14 00:12:03 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\qagent.dll
+ 2008-04-14 00:12:03 291,328 ------w C:\WINDOWS\ServicePackFiles\i386\qagentrt.dll
+ 2008-04-14 00:12:03 237,568 ------w C:\WINDOWS\ServicePackFiles\i386\qasf.dll
+ 2008-04-14 00:12:03 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\qcap.dll
+ 2008-04-14 00:12:03 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\qcliprov.dll
+ 2008-04-14 00:12:03 279,040 ------w C:\WINDOWS\ServicePackFiles\i386\qdv.dll
+ 2008-04-14 00:12:03 386,048 ------w C:\WINDOWS\ServicePackFiles\i386\qdvd.dll
+ 2008-04-14 00:12:03 562,176 ------w C:\WINDOWS\ServicePackFiles\i386\qedit.dll
+ 2008-04-13 17:21:32 733,696 ------w C:\WINDOWS\ServicePackFiles\i386\qedwipes.dll
+ 2008-04-13 18:40:52 6,016 ------w C:\WINDOWS\ServicePackFiles\i386\qic157.sys
+ 2008-04-14 00:12:03 409,088 ------w C:\WINDOWS\ServicePackFiles\i386\qmgr.dll
+ 2008-04-14 00:12:03 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\qmgrprxy.dll
+ 2008-04-14 00:12:32 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\qprocess.exe
+ 2008-04-14 00:12:03 1,288,192 ------w C:\WINDOWS\ServicePackFiles\i386\quartz.dll
+ 2008-04-14 00:12:03 1,435,648 ------w C:\WINDOWS\ServicePackFiles\i386\query.dll
breakawayjade
2008-10-17, 02:53
+ 2008-04-14 00:12:03 76,800 ------w C:\WINDOWS\ServicePackFiles\i386\qutil.dll
+ 2008-04-14 00:12:03 43,520 ------w C:\WINDOWS\ServicePackFiles\i386\racpldlg.dll
+ 2008-04-13 18:41:23 20,736 ------w C:\WINDOWS\ServicePackFiles\i386\ramdisk.sys
+ 2008-04-14 00:12:03 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\rasadhlp.dll
+ 2008-04-14 00:12:03 237,056 ------w C:\WINDOWS\ServicePackFiles\i386\rasapi32.dll
+ 2008-04-14 00:12:03 88,576 ------w C:\WINDOWS\ServicePackFiles\i386\rasauto.dll
+ 2008-04-14 00:12:03 79,872 ------w C:\WINDOWS\ServicePackFiles\i386\raschap.dll
+ 2008-04-14 00:12:03 658,432 ------w C:\WINDOWS\ServicePackFiles\i386\rasdlg.dll
+ 2008-04-13 19:19:43 51,328 ------w C:\WINDOWS\ServicePackFiles\i386\rasl2tp.sys
+ 2008-04-14 00:12:03 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\rasman.dll
+ 2008-04-14 00:12:03 186,368 ------w C:\WINDOWS\ServicePackFiles\i386\rasmans.dll
+ 2008-04-14 00:12:32 56,832 ------w C:\WINDOWS\ServicePackFiles\i386\rasphone.exe
+ 2008-04-14 00:12:03 210,944 ------w C:\WINDOWS\ServicePackFiles\i386\rasppp.dll
+ 2008-04-13 18:57:32 41,472 ------w C:\WINDOWS\ServicePackFiles\i386\raspppoe.sys
+ 2008-04-13 19:19:48 48,384 ------w C:\WINDOWS\ServicePackFiles\i386\raspptp.sys
+ 2008-04-14 00:12:03 61,952 ------w C:\WINDOWS\ServicePackFiles\i386\rasqec.dll
+ 2008-04-14 00:12:03 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\rassapi.dll
+ 2008-04-14 00:12:03 58,368 ------w C:\WINDOWS\ServicePackFiles\i386\rastapi.dll
+ 2008-04-14 00:12:03 150,016 ------w C:\WINDOWS\ServicePackFiles\i386\rastls.dll
+ 2008-04-14 00:12:03 102,400 ------w C:\WINDOWS\ServicePackFiles\i386\rcbdyctl.dll
+ 2008-04-14 00:12:32 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\rcimlby.exe
+ 2008-04-14 00:12:32 21,504 ------w C:\WINDOWS\ServicePackFiles\i386\rcp.exe
+ 2008-04-13 19:28:39 175,744 ------w C:\WINDOWS\ServicePackFiles\i386\rdbss.sys
+ 2008-04-14 00:12:03 147,968 ------w C:\WINDOWS\ServicePackFiles\i386\rdchost.dll
+ 2008-04-14 00:12:32 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\rdpclip.exe
+ 2008-04-14 00:13:22 92,424 ------w C:\WINDOWS\ServicePackFiles\i386\rdpdd.dll
+ 2008-04-13 18:32:51 196,224 ------w C:\WINDOWS\ServicePackFiles\i386\rdpdr.sys
+ 2008-04-14 00:12:04 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\rdpsnd.dll
+ 2008-04-14 00:13:22 139,656 ------w C:\WINDOWS\ServicePackFiles\i386\rdpwd.sys
+ 2008-04-14 00:13:22 87,176 ------w C:\WINDOWS\ServicePackFiles\i386\rdpwsx.dll
+ 2008-04-14 00:12:32 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\rdsaddin.exe
+ 2008-04-14 00:12:32 67,072 ------w C:\WINDOWS\ServicePackFiles\i386\rdshost.exe
+ 2004-08-04 05:41:40 13,776 ------w C:\WINDOWS\ServicePackFiles\i386\recagent.sys
+ 2008-04-13 18:40:27 57,600 ------w C:\WINDOWS\ServicePackFiles\i386\redbook.sys
+ 2004-08-04 11:00:00 3,338 ------w C:\WINDOWS\ServicePackFiles\i386\redir.exe
+ 2008-04-14 00:12:32 50,176 ------w C:\WINDOWS\ServicePackFiles\i386\reg.exe
+ 2008-04-14 00:12:04 49,664 ------w C:\WINDOWS\ServicePackFiles\i386\regapi.dll
+ 2008-04-14 00:12:32 146,432 ------w C:\WINDOWS\ServicePackFiles\i386\regedit.exe
+ 2008-04-14 00:12:04 59,904 ------w C:\WINDOWS\ServicePackFiles\i386\regsvc.dll
+ 2008-04-14 00:12:32 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\regsvr32.exe
+ 2008-04-14 00:12:04 397,824 ------w C:\WINDOWS\ServicePackFiles\i386\regwizc.dll
+ 2008-04-14 00:12:04 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\remotepg.dll
+ 2008-04-14 00:12:04 178,176 ------w C:\WINDOWS\ServicePackFiles\i386\repdrvfs.dll
+ 2008-04-14 00:12:04 58,880 ------w C:\WINDOWS\ServicePackFiles\i386\resutils.dll
+ 2008-04-14 00:12:33 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\rexec.exe
+ 2008-04-13 18:46:32 59,136 ------w C:\WINDOWS\ServicePackFiles\i386\rfcomm.sys
+ 2008-04-14 00:12:04 290,304 ------w C:\WINDOWS\ServicePackFiles\i386\rhttpaa.dll
+ 2008-04-14 00:12:04 123,392 ------w C:\WINDOWS\ServicePackFiles\i386\riafres.dll
+ 2008-04-14 00:12:04 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\riafui1.dll
+ 2008-04-14 00:12:04 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\riafui2.dll
+ 2008-04-14 00:12:04 433,664 ------w C:\WINDOWS\ServicePackFiles\i386\riched20.dll
+ 2008-04-13 18:55:08 202,624 ------w C:\WINDOWS\ServicePackFiles\i386\rmcast.sys
+ 2008-04-13 18:56:49 30,592 ------w C:\WINDOWS\ServicePackFiles\i386\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ------w C:\WINDOWS\ServicePackFiles\i386\rndismpx.sys
+ 2008-04-13 18:40:14 79,104 ------w C:\WINDOWS\ServicePackFiles\i386\rocket.sys
+ 2008-04-14 00:12:04 584,704 ------w C:\WINDOWS\ServicePackFiles\i386\rpcrt4.dll
+ 2008-04-14 00:12:04 399,360 ------w C:\WINDOWS\ServicePackFiles\i386\rpcss.dll
+ 2008-04-14 00:12:04 61,440 ------w C:\WINDOWS\ServicePackFiles\i386\rrcm.dll
+ 2008-04-13 17:37:57 208,384 ------w C:\WINDOWS\ServicePackFiles\i386\rsaenh.dll
+ 2008-04-14 00:12:33 14,848 ------w C:\WINDOWS\ServicePackFiles\i386\rsh.exe
+ 2008-04-14 00:12:04 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\rshx32.dll
+ 2008-04-14 00:12:04 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\rsmps.dll
+ 2008-04-14 00:12:33 380,416 ------w C:\WINDOWS\ServicePackFiles\i386\rstrui.exe
+ 2008-04-14 00:12:04 92,672 ------w C:\WINDOWS\ServicePackFiles\i386\rsvpsp.dll
+ 2008-04-14 00:12:33 77,312 ------w C:\WINDOWS\ServicePackFiles\i386\rtcshare.exe
+ 2008-04-14 00:12:04 31,744 ------w C:\WINDOWS\ServicePackFiles\i386\rtipxmib.dll
+ 2004-08-04 05:31:34 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\rtl8139.sys
+ 2008-04-14 00:12:04 44,032 ------w C:\WINDOWS\ServicePackFiles\i386\rtutils.dll
+ 2008-04-14 00:12:33 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\rundll32.exe
+ 2008-04-14 00:12:33 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\runonce.exe
+ 2008-04-14 00:12:04 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\rw001ext.dll
+ 2008-04-14 00:12:04 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\rw330ext.dll
+ 2008-04-14 00:12:04 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\rw430ext.dll
+ 2008-04-14 00:12:04 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\rw450ext.dll
+ 2008-04-14 00:12:04 397,056 ------w C:\WINDOWS\ServicePackFiles\i386\s3gnb.dll
+ 2004-08-04 05:29:52 166,912 ------w C:\WINDOWS\ServicePackFiles\i386\s3gnbm.sys
+ 2008-04-14 00:12:04 43,520 ------w C:\WINDOWS\ServicePackFiles\i386\safrcdlg.dll
+ 2008-04-14 00:12:04 29,696 ------w C:\WINDOWS\ServicePackFiles\i386\safrdm.dll
+ 2008-04-14 00:12:04 45,568 ------w C:\WINDOWS\ServicePackFiles\i386\safrslv.dll
+ 2008-04-14 00:12:04 64,000 ------w C:\WINDOWS\ServicePackFiles\i386\samlib.dll
+ 2008-04-14 00:12:04 415,744 ------w C:\WINDOWS\ServicePackFiles\i386\samsrv.dll
+ 2008-04-14 00:12:04 741,376 ------w C:\WINDOWS\ServicePackFiles\i386\sapi.dll
+ 2008-04-14 00:12:33 13,312 ------w C:\WINDOWS\ServicePackFiles\i386\savedump.exe
+ 2008-04-14 00:12:04 270,848 ------w C:\WINDOWS\ServicePackFiles\i386\sbe.dll
+ 2008-04-14 00:12:04 159,232 ------w C:\WINDOWS\ServicePackFiles\i386\sbeio.dll
+ 2008-04-13 18:40:48 43,904 ------w C:\WINDOWS\ServicePackFiles\i386\sbp2port.sys
+ 2008-04-14 00:12:04 69,632 ------w C:\WINDOWS\ServicePackFiles\i386\scarddlg.dll
+ 2008-04-14 00:12:33 95,744 ------w C:\WINDOWS\ServicePackFiles\i386\scardsvr.exe
+ 2004-08-04 11:00:00 169,984 ------w C:\WINDOWS\ServicePackFiles\i386\sccbase.dll
+ 2008-04-14 00:12:05 171,008 ------w C:\WINDOWS\ServicePackFiles\i386\sccsccp.dll
+ 2008-04-14 00:12:05 181,248 ------w C:\WINDOWS\ServicePackFiles\i386\scecli.dll
+ 2008-04-14 00:12:05 314,880 ------w C:\WINDOWS\ServicePackFiles\i386\scesrv.dll
+ 2008-04-14 00:12:05 144,384 ------w C:\WINDOWS\ServicePackFiles\i386\schannel.dll
+ 2008-04-14 00:12:05 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\schedsvc.dll
+ 2008-04-14 00:12:05 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\sclgntfy.dll
+ 2008-04-14 00:12:34 36,352 ------w C:\WINDOWS\ServicePackFiles\i386\scrcons.exe
+ 2008-04-14 00:12:05 215,552 ------w C:\WINDOWS\ServicePackFiles\i386\script.dll
+ 2008-04-14 00:12:05 199,680 ------w C:\WINDOWS\ServicePackFiles\i386\scripta.dll
+ 2008-04-14 00:12:43 9,216 ------w C:\WINDOWS\ServicePackFiles\i386\scrnsave.scr
+ 2008-04-14 00:12:05 180,224 ------w C:\WINDOWS\ServicePackFiles\i386\scrobj.dll
+ 2008-04-14 00:12:05 172,032 ------w C:\WINDOWS\ServicePackFiles\i386\scrrun.dll
+ 2008-04-13 18:40:30 96,384 ------w C:\WINDOWS\ServicePackFiles\i386\scsiport.sys
+ 2008-04-13 18:45:33 11,520 ------w C:\WINDOWS\ServicePackFiles\i386\scsiscan.sys
+ 2008-04-14 00:12:34 77,312 ------w C:\WINDOWS\ServicePackFiles\i386\sdbinst.exe
+ 2008-04-13 18:36:44 79,232 ------w C:\WINDOWS\ServicePackFiles\i386\sdbus.sys
+ 2008-04-14 00:12:05 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\sdhcinst.dll
+ 2007-11-13 10:25:53 20,480 ------w C:\WINDOWS\ServicePackFiles\i386\secdrv.sys
+ 2008-04-14 00:12:05 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\seclogon.dll
+ 2006-12-31 14:57:08 4,569 ------w C:\WINDOWS\ServicePackFiles\i386\secupd.dat
+ 2008-04-14 00:12:05 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\secur32.dll
+ 2008-04-14 00:12:05 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\security.dll
+ 2008-04-14 00:12:05 29,184 ------w C:\WINDOWS\ServicePackFiles\i386\sendcmsg.dll
+ 2008-04-14 00:12:05 54,784 ------w C:\WINDOWS\ServicePackFiles\i386\sendmail.dll
+ 2008-04-14 00:12:05 39,424 ------w C:\WINDOWS\ServicePackFiles\i386\sens.dll
+ 2008-04-14 00:12:05 7,168 ------w C:\WINDOWS\ServicePackFiles\i386\sensapi.dll
+ 2008-04-13 18:40:12 15,744 ------w C:\WINDOWS\ServicePackFiles\i386\serenum.sys
+ 2008-04-13 19:15:45 64,512 ------w C:\WINDOWS\ServicePackFiles\i386\serial.sys
+ 2008-04-14 00:12:05 56,320 ------w C:\WINDOWS\ServicePackFiles\i386\servdeps.dll
+ 2008-04-14 00:12:34 108,544 ------w C:\WINDOWS\ServicePackFiles\i386\services.exe
+ 2008-04-14 00:12:34 141,312 ------w C:\WINDOWS\ServicePackFiles\i386\sessmgr.exe
+ 2008-04-14 00:12:34 31,232 ------w C:\WINDOWS\ServicePackFiles\i386\sethc.exe
+ 2008-04-14 00:12:34 23,040 ------w C:\WINDOWS\ServicePackFiles\i386\setup.exe
+ 2008-04-14 00:12:34 73,216 ------w C:\WINDOWS\ServicePackFiles\i386\setup50.exe
+ 2008-04-14 12:42:06 985,088 ------w C:\WINDOWS\ServicePackFiles\i386\setupapi.dll
+ 2008-04-14 00:12:35 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\setupn.exe
+ 2008-04-14 00:12:05 101,376 ------w C:\WINDOWS\ServicePackFiles\i386\setupqry.dll
+ 2008-04-14 00:12:05 5,120 ------w C:\WINDOWS\ServicePackFiles\i386\sfc.dll
+ 2008-04-14 00:12:05 140,288 ------w C:\WINDOWS\ServicePackFiles\i386\sfc_os.dll
+ 2008-04-14 00:12:05 1,614,848 ------w C:\WINDOWS\ServicePackFiles\i386\sfcfiles.dll
+ 2008-04-13 18:40:47 11,904 ------w C:\WINDOWS\ServicePackFiles\i386\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 ------w C:\WINDOWS\ServicePackFiles\i386\sffp_mmc.sys
+ 2008-04-13 18:40:47 11,008 ------w C:\WINDOWS\ServicePackFiles\i386\sffp_sd.sys
+ 2008-04-13 18:40:48 11,392 ------w C:\WINDOWS\ServicePackFiles\i386\sfloppy.sys
+ 2008-04-13 17:03:19 549,376 ------w C:\WINDOWS\ServicePackFiles\i386\shdoclc.dll
+ 2008-04-14 00:12:05 1,499,136 ------w C:\WINDOWS\ServicePackFiles\i386\shdocvw.dll
+ 2008-04-14 00:12:05 8,461,312 ------w C:\WINDOWS\ServicePackFiles\i386\shell32.dll
+ 2008-04-14 00:12:05 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\shfolder.dll
+ 2008-04-14 00:12:05 68,096 ------w C:\WINDOWS\ServicePackFiles\i386\shgina.dll
+ 2008-04-14 00:12:05 65,024 ------w C:\WINDOWS\ServicePackFiles\i386\shimeng.dll
+ 2008-04-14 00:12:05 438,272 ------w C:\WINDOWS\ServicePackFiles\i386\shimgvw.dll
+ 2008-04-14 00:12:05 474,112 ------w C:\WINDOWS\ServicePackFiles\i386\shlwapi.dll
+ 2008-04-14 00:12:35 45,056 ------w C:\WINDOWS\ServicePackFiles\i386\shmgrate.exe
+ 2008-04-14 00:12:35 77,824 ------w C:\WINDOWS\ServicePackFiles\i386\shrpubw.exe
+ 2008-04-14 00:12:05 27,648 ------w C:\WINDOWS\ServicePackFiles\i386\shscrap.dll
+ 2008-04-14 00:12:05 135,168 ------w C:\WINDOWS\ServicePackFiles\i386\shsvcs.dll
+ 2008-04-14 00:12:05 20,536 ------w C:\WINDOWS\ServicePackFiles\i386\shtml.dll
+ 2008-04-14 00:12:35 16,437 ------w C:\WINDOWS\ServicePackFiles\i386\shtml.exe
+ 2008-04-14 00:12:35 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\shutdown.exe
+ 2008-04-14 00:12:05 13,312 ------w C:\WINDOWS\ServicePackFiles\i386\sigtab.dll
+ 2008-04-14 00:12:35 70,144 ------w C:\WINDOWS\ServicePackFiles\i386\sigverif.exe
+ 2008-04-14 00:12:05 3,901 ------w C:\WINDOWS\ServicePackFiles\i386\siint5.dll
+ 2008-04-13 18:36:39 40,960 ------w C:\WINDOWS\ServicePackFiles\i386\sisagp.sys
+ 2004-08-04 05:31:36 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\sisnic.sys
+ 2008-04-14 00:12:35 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\skeys.exe
+ 2004-08-04 05:31:42 63,547 ------w C:\WINDOWS\ServicePackFiles\i386\sla30nd5.sys
+ 2008-04-14 00:12:06 25,088 ------w C:\WINDOWS\ServicePackFiles\i386\slayerxp.dll
+ 2004-08-04 11:00:00 306,176 ------w C:\WINDOWS\ServicePackFiles\i386\slbcsp.dll
+ 2008-04-14 00:12:06 98,304 ------w C:\WINDOWS\ServicePackFiles\i386\slbiop.dll
+ 2008-04-14 00:12:06 73,832 ------w C:\WINDOWS\ServicePackFiles\i386\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 ------w C:\WINDOWS\ServicePackFiles\i386\slextspk.dll
+ 2008-04-14 00:12:06 188,508 ------w C:\WINDOWS\ServicePackFiles\i386\slgen.dll
+ 2008-04-13 18:46:23 11,136 ------w C:\WINDOWS\ServicePackFiles\i386\slip.sys
+ 2004-08-04 05:41:42 129,535 ------w C:\WINDOWS\ServicePackFiles\i386\slnt7554.sys
+ 2004-08-04 05:41:44 404,990 ------w C:\WINDOWS\ServicePackFiles\i386\slntamr.sys
+ 2004-08-04 05:41:46 95,424 ------w C:\WINDOWS\ServicePackFiles\i386\slnthal.sys
+ 2008-04-14 00:12:35 32,866 ------w C:\WINDOWS\ServicePackFiles\i386\slrundll.exe
+ 2008-04-14 00:12:35 73,796 ------w C:\WINDOWS\ServicePackFiles\i386\slserv.exe
+ 2004-08-04 05:41:46 13,240 ------w C:\WINDOWS\ServicePackFiles\i386\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 ------w C:\WINDOWS\ServicePackFiles\i386\smbali.sys
+ 2008-04-13 18:36:33 16,000 ------w C:\WINDOWS\ServicePackFiles\i386\smbbatt.sys
+ 2008-04-13 18:36:33 6,912 ------w C:\WINDOWS\ServicePackFiles\i386\smbclass.sys
+ 2008-04-14 00:12:35 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\smbinst.exe
+ 2008-04-14 00:12:35 236,544 ------w C:\WINDOWS\ServicePackFiles\i386\smi2smir.exe
+ 2008-04-14 00:12:06 362,496 ------w C:\WINDOWS\ServicePackFiles\i386\smlogcfg.dll
+ 2008-04-14 00:12:35 89,600 ------w C:\WINDOWS\ServicePackFiles\i386\smlogsvc.exe
+ 2008-04-14 00:12:36 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\smss.exe
+ 2008-04-14 00:12:06 456,192 ------w C:\WINDOWS\ServicePackFiles\i386\smtpsvc.dll
+ 2008-04-14 00:12:36 131,584 ------w C:\WINDOWS\ServicePackFiles\i386\sndrec32.exe
+ 2008-04-14 00:12:06 34,816 ------w C:\WINDOWS\ServicePackFiles\i386\sniffpol.dll
+ 2008-04-14 00:12:36 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\snmp.exe
+ 2008-04-14 00:12:06 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\snmpapi.dll
+ 2008-04-14 00:12:06 259,072 ------w C:\WINDOWS\ServicePackFiles\i386\snmpcl.dll
+ 2008-04-14 00:12:06 358,400 ------w C:\WINDOWS\ServicePackFiles\i386\snmpincl.dll
+ 2008-04-14 00:12:06 6,144 ------w C:\WINDOWS\ServicePackFiles\i386\snmpmib.dll
+ 2008-04-14 00:12:06 188,416 ------w C:\WINDOWS\ServicePackFiles\i386\snmpsmir.dll
+ 2008-04-14 00:12:06 182,272 ------w C:\WINDOWS\ServicePackFiles\i386\snmpsnap.dll
+ 2008-04-14 00:12:06 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\snmpthrd.dll
+ 2008-04-14 00:12:36 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\snmptrap.exe
+ 2008-04-14 00:12:06 130,048 ------w C:\WINDOWS\ServicePackFiles\i386\softkbd.dll
+ 2008-04-13 18:40:52 7,552 ------w C:\WINDOWS\ServicePackFiles\i386\sonyait.sys
+ 2008-04-13 18:46:07 25,344 ------w C:\WINDOWS\ServicePackFiles\i386\sonydcam.sys
+ 2008-04-14 00:12:36 24,576 ------w C:\WINDOWS\ServicePackFiles\i386\sort.exe
+ 2008-04-14 00:12:36 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\spdwnwxp.exe
+ 2008-04-13 16:43:18 62,976 ------w C:\WINDOWS\ServicePackFiles\i386\spgrmr.dll
+ 2008-04-14 00:12:36 538,624 ------w C:\WINDOWS\ServicePackFiles\i386\spider.exe
+ 2008-04-13 18:45:07 6,272 ------w C:\WINDOWS\ServicePackFiles\i386\splitter.sys
+ 2008-04-14 12:42:38 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\spnpinst.exe
+ 2008-04-14 00:12:06 75,264 ------w C:\WINDOWS\ServicePackFiles\i386\spoolss.dll
+ 2008-04-14 00:12:36 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
+ 2008-04-13 18:35:28 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\spra041b.dll
+ 2008-04-13 18:35:28 192,512 ------w C:\WINDOWS\ServicePackFiles\i386\spra0424.dll
+ 2008-04-13 18:38:37 757,248 ------w C:\WINDOWS\ServicePackFiles\i386\sprb041b.dll
+ 2008-04-13 18:38:36 732,160 ------w C:\WINDOWS\ServicePackFiles\i386\sprb0424.dll
+ 2008-04-13 18:40:04 577,536 ------w C:\WINDOWS\ServicePackFiles\i386\sprc041b.dll
+ 2008-04-13 18:40:05 576,512 ------w C:\WINDOWS\ServicePackFiles\i386\sprc0424.dll
+ 2008-04-14 00:12:06 250,368 ------w C:\WINDOWS\ServicePackFiles\i386\sptip.dll
+ 2008-04-14 00:12:36 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\spupdwxp.exe
+ 2008-04-14 00:12:06 151,552 ------w C:\WINDOWS\ServicePackFiles\i386\sqldb20.dll
+ 2008-04-14 00:12:06 528,384 ------w C:\WINDOWS\ServicePackFiles\i386\sqloledb.dll
+ 2008-04-14 00:12:06 462,848 ------w C:\WINDOWS\ServicePackFiles\i386\sqlqp20.dll
+ 2008-04-14 00:12:06 110,592 ------w C:\WINDOWS\ServicePackFiles\i386\sqlse20.dll
+ 2008-04-14 00:12:06 442,368 ------w C:\WINDOWS\ServicePackFiles\i386\sqlsrv32.dll
+ 2008-04-14 00:12:06 180,800 ------w C:\WINDOWS\ServicePackFiles\i386\sqlunirl.dll
+ 2008-04-14 00:12:06 217,088 ------w C:\WINDOWS\ServicePackFiles\i386\sqlxmlx.dll
+ 2008-04-13 18:36:52 73,472 ------w C:\WINDOWS\ServicePackFiles\i386\sr.sys
+ 2008-04-14 00:12:06 58,434 ------w C:\WINDOWS\ServicePackFiles\i386\srchctls.dll
+ 2008-04-14 00:12:07 726,078 ------w C:\WINDOWS\ServicePackFiles\i386\srchui.dll
+ 2008-04-14 00:12:07 67,584 ------w C:\WINDOWS\ServicePackFiles\i386\srclient.dll
+ 2008-04-14 00:12:07 239,104 ------w C:\WINDOWS\ServicePackFiles\i386\srrstr.dll
+ 2008-04-14 00:12:07 171,008 ------w C:\WINDOWS\ServicePackFiles\i386\srsvc.dll
+ 2008-04-13 19:15:11 334,848 ------w C:\WINDOWS\ServicePackFiles\i386\srv.sys
+ 2008-04-14 00:12:07 96,768 ------w C:\WINDOWS\ServicePackFiles\i386\srvsvc.dll
+ 2008-04-14 00:12:43 704,512 ------w C:\WINDOWS\ServicePackFiles\i386\ss3dfo.scr
+ 2008-04-14 00:12:43 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\ssbezier.scr
+ 2008-04-14 00:12:07 34,816 ------w C:\WINDOWS\ServicePackFiles\i386\ssdpapi.dll
+ 2008-04-14 00:12:07 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\ssdpsrv.dll
+ 2008-04-14 00:12:43 393,216 ------w C:\WINDOWS\ServicePackFiles\i386\ssflwbox.scr
+ 2008-04-14 00:12:44 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\ssmarque.scr
+ 2008-04-14 00:12:44 47,104 ------w C:\WINDOWS\ServicePackFiles\i386\ssmypics.scr
+ 2008-04-14 00:12:44 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\ssmyst.scr
+ 2008-04-14 00:12:44 610,304 ------w C:\WINDOWS\ServicePackFiles\i386\sspipes.scr
+ 2008-04-14 00:12:44 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\ssstars.scr
+ 2008-04-14 00:12:44 679,936 ------w C:\WINDOWS\ServicePackFiles\i386\sstext3d.scr
+ 2008-04-14 00:12:07 33,280 ------w C:\WINDOWS\ServicePackFiles\i386\sstub.dll
+ 2008-04-14 00:12:07 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\startoc.dll
+ 2008-04-14 00:12:07 59,392 ------w C:\WINDOWS\ServicePackFiles\i386\stclient.dll
+ 2008-04-14 00:12:07 86,528 ------w C:\WINDOWS\ServicePackFiles\i386\stdprov.dll
+ 2008-04-14 00:12:07 68,096 ------w C:\WINDOWS\ServicePackFiles\i386\sti.dll
+ 2008-04-14 00:12:07 136,704 ------w C:\WINDOWS\ServicePackFiles\i386\sti_ci.dll
+ 2008-04-14 00:12:36 14,848 ------w C:\WINDOWS\ServicePackFiles\i386\stimon.exe
+ 2008-04-14 00:12:07 121,856 ------w C:\WINDOWS\ServicePackFiles\i386\stobject.dll
+ 2008-04-14 00:12:07 74,752 ------w C:\WINDOWS\ServicePackFiles\i386\storprop.dll
+ 2008-04-13 18:45:15 49,408 ------w C:\WINDOWS\ServicePackFiles\i386\stream.sys
+ 2008-04-13 18:46:21 15,232 ------w C:\WINDOWS\ServicePackFiles\i386\streamip.sys
+ 2008-04-14 00:12:07 75,776 ------w C:\WINDOWS\ServicePackFiles\i386\strmfilt.dll
+ 2008-04-14 00:12:36 16,449 ------w C:\WINDOWS\ServicePackFiles\i386\stub_fpsrvadm.exe
+ 2008-04-14 00:12:36 65,601 ------w C:\WINDOWS\ServicePackFiles\i386\stub_fpsrvwin.exe
+ 2008-04-14 00:12:36 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\svchost.exe
+ 2008-04-13 18:39:53 4,352 ------w C:\WINDOWS\ServicePackFiles\i386\swenum.sys
+ 2008-04-13 18:45:09 56,576 ------w C:\WINDOWS\ServicePackFiles\i386\swmidi.sys
+ 2008-04-14 00:12:07 713,216 ------w C:\WINDOWS\ServicePackFiles\i386\sxs.dll
+ 2008-04-14 00:12:07 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\synceng.dll
+ 2008-04-14 00:12:07 191,488 ------w C:\WINDOWS\ServicePackFiles\i386\syncui.dll
+ 2008-04-13 19:15:55 60,800 ------w C:\WINDOWS\ServicePackFiles\i386\sysaudio.sys
+ 2008-04-14 00:12:07 193,024 ------w C:\WINDOWS\ServicePackFiles\i386\sysmod.dll
+ 2008-04-14 00:12:07 173,568 ------w C:\WINDOWS\ServicePackFiles\i386\sysmoda.dll
+ 2008-04-14 00:12:37 106,496 ------w C:\WINDOWS\ServicePackFiles\i386\sysocmgr.exe
+ 2008-04-14 00:12:07 990,208 ------w C:\WINDOWS\ServicePackFiles\i386\syssetup.dll
+ 2008-04-14 00:12:07 117,760 ------w C:\WINDOWS\ServicePackFiles\i386\t2embed.dll
+ 2008-04-13 18:40:50 14,976 ------w C:\WINDOWS\ServicePackFiles\i386\tape.sys
+ 2008-04-14 00:12:07 858,624 ------w C:\WINDOWS\ServicePackFiles\i386\tapi3.dll
+ 2008-04-14 00:12:07 181,760 ------w C:\WINDOWS\ServicePackFiles\i386\tapi32.dll
+ 2008-04-14 00:12:07 249,856 ------w C:\WINDOWS\ServicePackFiles\i386\tapisrv.dll
+ 2008-04-14 00:12:37 135,680 ------w C:\WINDOWS\ServicePackFiles\i386\taskmgr.exe
+ 2008-04-13 19:20:16 361,344 ------w C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
+ 2008-04-13 19:00:02 225,664 ------w C:\WINDOWS\ServicePackFiles\i386\tcpip6.sys
+ 2008-04-14 00:12:07 14,848 ------w C:\WINDOWS\ServicePackFiles\i386\tcpmib.dll
+ 2008-04-14 00:12:07 45,568 ------w C:\WINDOWS\ServicePackFiles\i386\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 ------w C:\WINDOWS\ServicePackFiles\i386\tcpmonui.dll
+ 2008-04-14 00:12:37 32,827 ------w C:\WINDOWS\ServicePackFiles\i386\tcptest.exe
+ 2007-04-02 16:36:07 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\tcptsat.dll
+ 2008-04-13 19:00:05 19,072 ------w C:\WINDOWS\ServicePackFiles\i386\tdi.sys
+ 2008-04-14 00:13:20 12,040 ------w C:\WINDOWS\ServicePackFiles\i386\tdpipe.sys
+ 2008-04-14 00:13:21 21,896 ------w C:\WINDOWS\ServicePackFiles\i386\tdtcp.sys
+ 2008-04-14 00:12:37 75,776 ------w C:\WINDOWS\ServicePackFiles\i386\telnet.exe
+ 2008-04-14 00:13:20 40,840 ------w C:\WINDOWS\ServicePackFiles\i386\termdd.sys
+ 2008-04-14 00:12:07 358,400 ------w C:\WINDOWS\ServicePackFiles\i386\termmgr.dll
+ 2008-04-14 00:12:07 295,424 ------w C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
+ 2008-04-13 18:40:50 149,376 ------w C:\WINDOWS\ServicePackFiles\i386\tffsport.sys
+ 2008-04-14 00:12:07 385,536 ------w C:\WINDOWS\ServicePackFiles\i386\themeui.dll
+ 2008-04-14 00:12:38 347,136 ------w C:\WINDOWS\ServicePackFiles\i386\tourstrt.exe
+ 2008-04-14 00:12:38 82,944 ------w C:\WINDOWS\ServicePackFiles\i386\tp4mon.exe
+ 2008-04-14 00:12:38 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\tracert.exe
+ 2008-04-14 00:12:42 12,800 ------w C:\WINDOWS\ServicePackFiles\i386\tree.com
+ 2008-04-14 00:12:07 153,088 ------w C:\WINDOWS\ServicePackFiles\i386\triedit.dll
+ 2008-04-14 00:12:07 90,112 ------w C:\WINDOWS\ServicePackFiles\i386\trkwks.dll
+ 2008-01-18 15:13:09 2,247 ------w C:\WINDOWS\ServicePackFiles\i386\tscdsbl.bat
+ 2008-04-14 00:12:07 93,696 ------w C:\WINDOWS\ServicePackFiles\i386\tscfgwmi.dll
+ 2007-12-12 10:33:51 18,917 ------w C:\WINDOWS\ServicePackFiles\i386\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 ------w C:\WINDOWS\ServicePackFiles\i386\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\tscupdc.dll
+ 2008-04-14 00:13:21 12,168 ------w C:\WINDOWS\ServicePackFiles\i386\tsddd.dll
+ 2008-04-14 00:12:07 53,248 ------w C:\WINDOWS\ServicePackFiles\i386\tsgqec.dll
+ 2008-04-14 00:12:07 279,040 ------w C:\WINDOWS\ServicePackFiles\i386\tshoot.dll
+ 2008-04-14 00:12:07 130,048 ------w C:\WINDOWS\ServicePackFiles\i386\tsoc.dll
+ 2008-04-14 00:12:07 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\tspkg.dll
+ 2008-04-14 00:12:07 8,704 ------w C:\WINDOWS\ServicePackFiles\i386\tty.dll
+ 2007-04-02 15:31:00 39,936 ------w C:\WINDOWS\ServicePackFiles\i386\ttyres.dll
+ 2008-04-14 00:12:07 16,384 ------w C:\WINDOWS\ServicePackFiles\i386\ttyui.dll
+ 2008-04-13 18:56:01 12,288 ------w C:\WINDOWS\ServicePackFiles\i386\tunmp.sys
+ 2008-04-14 00:12:07 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\twain_32.dll
+ 2008-04-14 00:12:07 57,856 ------w C:\WINDOWS\ServicePackFiles\i386\twext.dll
+ 2008-04-14 00:12:07 101,376 ------w C:\WINDOWS\ServicePackFiles\i386\txflog.dll
+ 2008-04-14 00:12:38 60,416 ------w C:\WINDOWS\ServicePackFiles\i386\tzchange.exe
+ 2008-04-13 18:36:40 44,672 ------w C:\WINDOWS\ServicePackFiles\i386\uagp35.sys
+ 2008-04-13 18:32:36 66,048 ------w C:\WINDOWS\ServicePackFiles\i386\udfs.sys
+ 2008-04-14 00:12:07 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\udhisapi.dll
+ 2008-04-14 00:12:07 275,456 ------w C:\WINDOWS\ServicePackFiles\i386\ulib.dll
+ 2008-04-14 00:12:07 35,840 ------w C:\WINDOWS\ServicePackFiles\i386\umandlg.dll
+ 2008-04-14 00:12:07 123,392 ------w C:\WINDOWS\ServicePackFiles\i386\umpnpmgr.dll
+ 2008-04-14 00:12:07 373,248 ------w C:\WINDOWS\ServicePackFiles\i386\unidrv.dll
+ 2008-04-14 00:12:07 744,448 ------w C:\WINDOWS\ServicePackFiles\i386\unidrvui.dll
+ 2008-04-14 00:12:07 74,240 ------w C:\WINDOWS\ServicePackFiles\i386\unimdmat.dll
+ 2008-04-14 00:12:07 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\uniplat.dll
+ 2007-05-15 08:08:53 761,344 ------w C:\WINDOWS\ServicePackFiles\i386\unires.dll
+ 2008-04-14 00:12:07 316,416 ------w C:\WINDOWS\ServicePackFiles\i386\untfs.dll
+ 2008-04-13 18:39:46 384,768 ------w C:\WINDOWS\ServicePackFiles\i386\update.sys
+ 2008-04-14 00:12:38 150,528 ------w C:\WINDOWS\ServicePackFiles\i386\uploadm.exe
+ 2008-04-14 00:12:08 133,632 ------w C:\WINDOWS\ServicePackFiles\i386\upnp.dll
+ 2008-04-14 00:12:38 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\upnpcont.exe
+ 2008-04-14 00:12:08 185,856 ------w C:\WINDOWS\ServicePackFiles\i386\upnphost.dll
+ 2008-04-14 00:12:08 239,616 ------w C:\WINDOWS\ServicePackFiles\i386\upnpui.dll
+ 2008-04-14 00:12:38 18,432 ------w C:\WINDOWS\ServicePackFiles\i386\ups.exe
+ 2008-04-14 00:12:08 37,888 ------w C:\WINDOWS\ServicePackFiles\i386\url.dll
+ 2008-04-14 00:12:08 619,520 ------w C:\WINDOWS\ServicePackFiles\i386\urlmon.dll
+ 2004-08-04 05:31:26 32,384 ------w C:\WINDOWS\ServicePackFiles\i386\usb101et.sys
+ 2008-04-13 18:56:49 12,800 ------w C:\WINDOWS\ServicePackFiles\i386\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ------w C:\WINDOWS\ServicePackFiles\i386\usb8023x.sys
+ 2008-04-13 18:45:12 60,032 ------w C:\WINDOWS\ServicePackFiles\i386\usbaudio.sys
+ 2008-04-13 18:45:40 25,600 ------w C:\WINDOWS\ServicePackFiles\i386\usbcamd.sys
+ 2008-04-13 18:45:41 25,728 ------w C:\WINDOWS\ServicePackFiles\i386\usbcamd2.sys
+ 2008-04-13 18:45:39 32,128 ------w C:\WINDOWS\ServicePackFiles\i386\usbccgp.sys
+ 2008-04-13 18:45:35 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\usbehci.sys
+ 2008-04-13 18:45:37 59,520 ------w C:\WINDOWS\ServicePackFiles\i386\usbhub.sys
+ 2008-04-13 18:45:43 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\usbintel.sys
+ 2008-04-14 00:12:08 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\usbmon.dll
+ 2008-04-13 18:45:35 17,152 ------w C:\WINDOWS\ServicePackFiles\i386\usbohci.sys
+ 2008-04-13 18:45:36 143,872 ------w C:\WINDOWS\ServicePackFiles\i386\usbport.sys
+ 2008-04-13 18:47:37 25,856 ------w C:\WINDOWS\ServicePackFiles\i386\usbprint.sys
+ 2008-04-13 18:45:34 15,104 ------w C:\WINDOWS\ServicePackFiles\i386\usbscan.sys
+ 2008-04-13 18:45:36 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\usbser.sys
+ 2008-04-13 18:45:38 26,368 ------w C:\WINDOWS\ServicePackFiles\i386\usbstor.sys
+ 2008-04-13 18:45:35 20,608 ------w C:\WINDOWS\ServicePackFiles\i386\usbuhci.sys
+ 2008-04-14 00:12:08 74,240 ------w C:\WINDOWS\ServicePackFiles\i386\usbui.dll
+ 2008-04-13 18:46:20 121,984 ------w C:\WINDOWS\ServicePackFiles\i386\usbvideo.sys
+ 2008-04-14 00:12:08 578,560 ------w C:\WINDOWS\ServicePackFiles\i386\user32.dll
+ 2008-04-14 00:12:08 727,040 ------w C:\WINDOWS\ServicePackFiles\i386\userenv.dll
+ 2008-04-14 00:12:38 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\userinit.exe
+ 2008-04-14 00:12:08 406,016 ------w C:\WINDOWS\ServicePackFiles\i386\usp10.dll
+ 2008-04-14 00:12:38 50,176 ------w C:\WINDOWS\ServicePackFiles\i386\utilman.exe
+ 2008-04-14 00:12:08 218,624 ------w C:\WINDOWS\ServicePackFiles\i386\uxtheme.dll
+ 2008-04-14 00:12:08 30,749 ------w C:\WINDOWS\ServicePackFiles\i386\vbajet32.dll
+ 2008-04-14 00:12:08 434,176 ------w C:\WINDOWS\ServicePackFiles\i386\vbscript.dll
+ 2008-04-14 00:12:08 11,325 ------w C:\WINDOWS\ServicePackFiles\i386\vchnt5.dll
+ 2008-04-14 00:12:08 26,112 ------w C:\WINDOWS\ServicePackFiles\i386\vdmdbg.dll
+ 2008-04-14 00:12:08 51,712 ------w C:\WINDOWS\ServicePackFiles\i386\vdmredir.dll
+ 2008-04-14 00:12:38 28,672 ------w C:\WINDOWS\ServicePackFiles\i386\verclsid.exe
+ 2008-04-14 00:12:08 26,624 ------w C:\WINDOWS\ServicePackFiles\i386\verifier.dll
+ 2008-04-14 00:12:08 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\version.dll
+ 2008-04-14 00:12:08 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\vfwwdm32.dll
+ 2008-04-13 18:44:40 20,992 ------w C:\WINDOWS\ServicePackFiles\i386\vga.sys
+ 2008-04-14 00:12:08 851,968 ------w C:\WINDOWS\ServicePackFiles\i386\vgx.dll
+ 2008-04-13 18:36:40 42,240 ------w C:\WINDOWS\ServicePackFiles\i386\viaagp.sys
+ 2008-04-13 18:40:31 5,376 ------w C:\WINDOWS\ServicePackFiles\i386\viaide.sys
+ 2008-04-13 18:44:40 81,664 ------w C:\WINDOWS\ServicePackFiles\i386\videoprt.sys
+ 2008-04-14 00:12:08 131,584 ------w C:\WINDOWS\ServicePackFiles\i386\viewprov.dll
+ 2008-04-13 18:41:01 52,352 ------w C:\WINDOWS\ServicePackFiles\i386\volsnap.sys
+ 2008-04-14 00:12:08 430,592 ------w C:\WINDOWS\ServicePackFiles\i386\vssapi.dll
+ 2008-04-14 00:12:38 289,792 ------w C:\WINDOWS\ServicePackFiles\i386\vssvc.exe
+ 2008-04-14 00:12:08 175,104 ------w C:\WINDOWS\ServicePackFiles\i386\w32time.dll
+ 2008-04-14 00:12:08 15,872 ------w C:\WINDOWS\ServicePackFiles\i386\w3ssl.dll
+ 2008-04-14 00:12:08 483,840 ------w C:\WINDOWS\ServicePackFiles\i386\w95upgnt.dll
+ 2008-04-14 00:12:38 46,080 ------w C:\WINDOWS\ServicePackFiles\i386\wab.exe
+ 2008-04-14 00:12:08 510,976 ------w C:\WINDOWS\ServicePackFiles\i386\wab32.dll
+ 2008-04-13 16:21:48 249,856 ------w C:\WINDOWS\ServicePackFiles\i386\wab32res.dll
+ 2008-04-14 00:12:08 32,768 ------w C:\WINDOWS\ServicePackFiles\i386\wabfind.dll
+ 2008-04-14 00:12:08 85,504 ------w C:\WINDOWS\ServicePackFiles\i386\wabimp.dll
+ 2008-04-14 00:12:39 30,208 ------w C:\WINDOWS\ServicePackFiles\i386\wabmig.exe
+ 2008-04-13 18:43:55 14,208 ------w C:\WINDOWS\ServicePackFiles\i386\wacompen.sys
+ 2004-08-04 05:29:38 12,415 ------w C:\WINDOWS\ServicePackFiles\i386\wadv01nt.sys
+ 2004-08-04 05:29:38 12,127 ------w C:\WINDOWS\ServicePackFiles\i386\wadv02nt.sys
+ 2004-08-04 05:29:38 11,775 ------w C:\WINDOWS\ServicePackFiles\i386\wadv05nt.sys
+ 2004-08-04 05:29:40 11,807 ------w C:\WINDOWS\ServicePackFiles\i386\wadv07nt.sys
+ 2004-08-04 05:29:40 11,295 ------w C:\WINDOWS\ServicePackFiles\i386\wadv08nt.sys
+ 2004-08-04 05:29:42 11,871 ------w C:\WINDOWS\ServicePackFiles\i386\wadv09nt.sys
+ 2004-08-04 05:29:42 11,935 ------w C:\WINDOWS\ServicePackFiles\i386\wadv11nt.sys
+ 2008-04-13 18:57:21 34,560 ------w C:\WINDOWS\ServicePackFiles\i386\wanarp.sys
+ 2008-04-13 18:44:59 17,664 ------w C:\WINDOWS\ServicePackFiles\i386\watchdog.sys
+ 2004-08-04 05:29:42 29,311 ------w C:\WINDOWS\ServicePackFiles\i386\watv01nt.sys
+ 2004-08-04 05:29:44 19,551 ------w C:\WINDOWS\ServicePackFiles\i386\watv02nt.sys
+ 2004-08-04 05:29:44 33,599 ------w C:\WINDOWS\ServicePackFiles\i386\watv04nt.sys
+ 2004-08-04 05:29:46 22,271 ------w C:\WINDOWS\ServicePackFiles\i386\watv06nt.sys
+ 2004-08-04 05:29:46 25,471 ------w C:\WINDOWS\ServicePackFiles\i386\watv10nt.sys
+ 2008-04-14 00:12:08 215,552 ------w C:\WINDOWS\ServicePackFiles\i386\wavemsp.dll
+ 2008-04-14 00:12:08 196,608 ------w C:\WINDOWS\ServicePackFiles\i386\wbemcntl.dll
+ 2008-04-14 00:12:08 214,528 ------w C:\WINDOWS\ServicePackFiles\i386\wbemcomn.dll
+ 2008-04-14 00:12:08 71,680 ------w C:\WINDOWS\ServicePackFiles\i386\wbemcons.dll
+ 2008-04-14 00:12:08 531,456 ------w C:\WINDOWS\ServicePackFiles\i386\wbemcore.dll
+ 2008-04-14 00:12:08 178,176 ------w C:\WINDOWS\ServicePackFiles\i386\wbemdisp.dll
+ 2008-04-14 00:12:08 273,920 ------w C:\WINDOWS\ServicePackFiles\i386\wbemess.dll
+ 2008-04-14 00:12:08 43,008 ------w C:\WINDOWS\ServicePackFiles\i386\wbemperf.dll
+ 2008-04-14 00:12:08 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\wbemprox.dll
+ 2008-04-14 00:12:08 43,520 ------w C:\WINDOWS\ServicePackFiles\i386\wbemsvc.dll
+ 2008-04-14 00:12:39 116,224 ------w C:\WINDOWS\ServicePackFiles\i386\wbemtest.exe
+ 2008-04-14 00:12:08 197,120 ------w C:\WINDOWS\ServicePackFiles\i386\wbemupgd.dll
+ 2008-04-13 18:45:38 31,744 ------w C:\WINDOWS\ServicePackFiles\i386\wceusbsh.sys
+ 2004-08-04 05:29:46 23,615 ------w C:\WINDOWS\ServicePackFiles\i386\wch7xxnt.sys
+ 2008-04-14 00:12:08 49,152 ------w C:\WINDOWS\ServicePackFiles\i386\wdigest.dll
+ 2008-04-14 00:12:45 23,552 ------w C:\WINDOWS\ServicePackFiles\i386\wdmaud.drv
+ 2008-04-13 19:17:18 83,072 ------w C:\WINDOWS\ServicePackFiles\i386\wdmaud.sys
+ 2008-04-14 00:12:08 276,480 ------w C:\WINDOWS\ServicePackFiles\i386\webcheck.dll
+ 2008-04-14 00:12:08 68,096 ------w C:\WINDOWS\ServicePackFiles\i386\webclnt.dll
+ 2008-04-14 00:12:08 135,680 ------w C:\WINDOWS\ServicePackFiles\i386\webvw.dll
+ 2008-04-14 00:12:39 65,024 ------w C:\WINDOWS\ServicePackFiles\i386\wextract.exe
+ 2008-04-14 00:12:39 433,664 ------w C:\WINDOWS\ServicePackFiles\i386\wiaacmgr.exe
+ 2008-04-14 00:12:08 463,360 ------w C:\WINDOWS\ServicePackFiles\i386\wiadefui.dll
+ 2008-04-14 00:12:08 124,416 ------w C:\WINDOWS\ServicePackFiles\i386\wiadss.dll
+ 2008-04-14 00:12:08 75,776 ------w C:\WINDOWS\ServicePackFiles\i386\wiascr.dll
+ 2008-04-14 00:12:08 333,824 ------w C:\WINDOWS\ServicePackFiles\i386\wiaservc.dll
+ 2008-04-14 00:12:08 589,312 ------w C:\WINDOWS\ServicePackFiles\i386\wiashext.dll
+ 2008-04-14 00:12:08 111,104 ------w C:\WINDOWS\ServicePackFiles\i386\wiavideo.dll
+ 2008-04-14 00:12:08 712,704 ------w C:\WINDOWS\ServicePackFiles\i386\wic.dll
+ 2008-04-14 00:12:08 346,112 ------w C:\WINDOWS\ServicePackFiles\i386\wicext.dll
+ 2008-04-13 19:30:10 1,845,632 ------w C:\WINDOWS\ServicePackFiles\i386\win32k.sys
+ 2008-04-14 00:12:08 102,400 ------w C:\WINDOWS\ServicePackFiles\i386\win32spl.dll
+ 2008-04-13 16:48:53 1,647,616 ------w C:\WINDOWS\ServicePackFiles\i386\winbrand.dll
+ 2008-04-14 00:12:39 283,648 ------w C:\WINDOWS\ServicePackFiles\i386\winhlp32.exe
+ 2008-04-14 00:12:08 354,304 ------w C:\WINDOWS\ServicePackFiles\i386\winhttp.dll
+ 2008-04-14 00:12:08 666,112 ------w C:\WINDOWS\ServicePackFiles\i386\wininet.dll
+ 2008-04-14 00:12:09 32,256 ------w C:\WINDOWS\ServicePackFiles\i386\winipsec.dll
+ 2008-04-14 00:12:39 507,904 ------w C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
+ 2008-04-14 00:12:09 176,128 ------w C:\WINDOWS\ServicePackFiles\i386\winmm.dll
+ 2004-08-04 11:00:00 5,120 ------w C:\WINDOWS\ServicePackFiles\i386\winnls.dll
+ 2008-04-14 00:11:11 756,224 ------w C:\WINDOWS\ServicePackFiles\i386\winntbbu.dll
+ 2008-04-14 00:12:09 16,896 ------w C:\WINDOWS\ServicePackFiles\i386\winrnr.dll
+ 2008-04-14 00:12:09 99,328 ------w C:\WINDOWS\ServicePackFiles\i386\winscard.dll
+ 2008-04-14 00:12:09 17,408 ------w C:\WINDOWS\ServicePackFiles\i386\winshfhc.dll
+ 2008-04-14 00:12:45 146,432 ------w C:\WINDOWS\ServicePackFiles\i386\winspool.drv
+ 2008-04-14 00:12:09 293,376 ------w C:\WINDOWS\ServicePackFiles\i386\winsrv.dll
+ 2008-04-14 00:12:09 53,760 ------w C:\WINDOWS\ServicePackFiles\i386\winsta.dll
+ 2008-04-14 00:12:09 176,640 ------w C:\WINDOWS\ServicePackFiles\i386\wintrust.dll
+ 2008-04-14 00:12:40 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\winver.exe
+ 2008-04-14 00:12:09 132,096 ------w C:\WINDOWS\ServicePackFiles\i386\wkssvc.dll
+ 2008-04-14 00:12:09 69,120 ------w C:\WINDOWS\ServicePackFiles\i386\wlanapi.dll
+ 2008-04-14 00:12:09 172,032 ------w C:\WINDOWS\ServicePackFiles\i386\wldap32.dll
+ 2004-08-04 05:31:28 154,624 ------w C:\WINDOWS\ServicePackFiles\i386\wlluc48.sys
+ 2008-04-14 00:12:09 92,672 ------w C:\WINDOWS\ServicePackFiles\i386\wlnotify.dll
+ 2008-04-14 00:11:15 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\wmi.dll
+ 2008-04-13 18:36:38 8,832 ------w C:\WINDOWS\ServicePackFiles\i386\wmiacpi.sys
+ 2008-04-14 00:12:40 196,608 ------w C:\WINDOWS\ServicePackFiles\i386\wmiadap.exe
+ 2008-04-13 17:10:20 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\wmiapres.dll
+ 2008-04-14 00:12:09 88,576 ------w C:\WINDOWS\ServicePackFiles\i386\wmiaprpl.dll
+ 2008-04-14 00:12:40 126,464 ------w C:\WINDOWS\ServicePackFiles\i386\wmiapsrv.exe
+ 2008-04-14 00:12:09 60,928 ------w C:\WINDOWS\ServicePackFiles\i386\wmicookr.dll
+ 2008-04-14 00:12:09 140,800 ------w C:\WINDOWS\ServicePackFiles\i386\wmidcprv.dll
+ 2008-04-14 00:12:09 156,672 ------w C:\WINDOWS\ServicePackFiles\i386\wmipcima.dll
+ 2008-04-14 00:12:09 132,096 ------w C:\WINDOWS\ServicePackFiles\i386\wmipdskq.dll
+ 2008-04-14 00:12:09 61,952 ------w C:\WINDOWS\ServicePackFiles\i386\wmipiprt.dll
+ 2008-04-14 00:12:09 62,464 ------w C:\WINDOWS\ServicePackFiles\i386\wmipjobj.dll
+ 2008-04-14 00:12:09 144,896 ------w C:\WINDOWS\ServicePackFiles\i386\wmiprov.dll
+ 2008-04-14 00:12:09 437,248 ------w C:\WINDOWS\ServicePackFiles\i386\wmiprvsd.dll
+ 2008-04-14 00:12:40 218,112 ------w C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe
+ 2008-04-14 00:12:09 41,472 ------w C:\WINDOWS\ServicePackFiles\i386\wmipsess.dll
+ 2008-04-14 00:12:09 144,896 ------w C:\WINDOWS\ServicePackFiles\i386\wmisvc.dll
+ 2008-04-14 00:12:09 95,232 ------w C:\WINDOWS\ServicePackFiles\i386\wmiutils.dll
+ 2008-04-14 00:12:09 167,936 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2ae.dll
+ 2008-04-14 00:12:09 4,096 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2eres.dll
+ 2008-04-14 00:12:09 7,680 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2ext.dll
+ 2008-04-14 00:12:09 402,432 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2filt.dll
+ 2008-04-14 00:12:09 502,272 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2fxa.dll
+ 2008-04-14 00:12:09 325,632 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2fxb.dll
+ 2008-04-14 00:12:09 4,256,768 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2res.dll
+ 2008-04-14 00:12:09 5,632 ------w C:\WINDOWS\ServicePackFiles\i386\wmm2res2.dll
+ 2008-04-14 00:12:09 276,992 ------w C:\WINDOWS\ServicePackFiles\i386\wmphoto.dll
+ 2008-04-14 00:12:40 214,528 ------w C:\WINDOWS\ServicePackFiles\i386\wordpad.exe
+ 2008-04-14 00:12:10 264,192 ------w C:\WINDOWS\ServicePackFiles\i386\wow32.dll
+ 2008-04-14 00:12:40 32,256 ------w C:\WINDOWS\ServicePackFiles\i386\wpabaln.exe
+ 2008-04-14 00:12:41 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\wpnpinst.exe
+ 2008-04-14 00:12:10 82,432 ------w C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
+ 2008-04-14 00:12:10 19,968 ------w C:\WINDOWS\ServicePackFiles\i386\ws2help.dll
+ 2008-04-14 00:12:41 13,824 ------w C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe
+ 2008-04-14 00:12:41 155,648 ------w C:\WINDOWS\ServicePackFiles\i386\wscript.exe
+ 2008-04-14 00:12:10 80,896 ------w C:\WINDOWS\ServicePackFiles\i386\wscsvc.dll
+ 2008-04-14 00:12:10 108,032 ------w C:\WINDOWS\ServicePackFiles\i386\wshbth.dll
+ 2008-04-14 00:12:10 36,864 ------w C:\WINDOWS\ServicePackFiles\i386\wshcon.dll
+ 2008-04-14 00:12:10 90,112 ------w C:\WINDOWS\ServicePackFiles\i386\wshext.dll
+ 2008-04-14 00:12:10 14,336 ------w C:\WINDOWS\ServicePackFiles\i386\wship6.dll
+ 2008-04-14 00:12:10 8,192 ------w C:\WINDOWS\ServicePackFiles\i386\wshirda.dll
+ 2008-04-14 00:12:10 11,264 ------w C:\WINDOWS\ServicePackFiles\i386\wshrm.dll
+ 2008-04-14 00:12:10 19,456 ------w C:\WINDOWS\ServicePackFiles\i386\wshtcpip.dll
+ 2004-08-04 05:29:48 12,063 ------w C:\WINDOWS\ServicePackFiles\i386\wsiintxx.sys
+ 2008-04-14 00:12:10 41,984 ------w C:\WINDOWS\ServicePackFiles\i386\wsnmp32.dll
+ 2008-04-14 00:12:10 22,528 ------w C:\WINDOWS\ServicePackFiles\i386\wsock32.dll
+ 2008-04-13 18:46:24 19,200 ------w C:\WINDOWS\ServicePackFiles\i386\wstcodec.sys
+ 2008-04-14 00:12:10 50,688 ------w C:\WINDOWS\ServicePackFiles\i386\wstdecod.dll
+ 2008-04-14 00:12:10 18,432 ------w C:\WINDOWS\ServicePackFiles\i386\wtsapi32.dll
+ 2008-04-14 00:12:10 430,592 ------w C:\WINDOWS\ServicePackFiles\i386\wuapi.dll
+ 2008-04-14 00:12:41 111,104 ------w C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe
+ 2008-04-14 00:12:41 165,888 ------w C:\WINDOWS\ServicePackFiles\i386\wuauclt1.exe
+ 2008-04-14 00:12:11 1,135,616 ------w C:\WINDOWS\ServicePackFiles\i386\wuaueng.dll
+ 2008-04-14 00:12:11 183,296 ------w C:\WINDOWS\ServicePackFiles\i386\wuaueng1.dll
+ 2008-04-14 00:12:11 6,656 ------w C:\WINDOWS\ServicePackFiles\i386\wuauserv.dll
+ 2008-04-14 00:12:11 112,640 ------w C:\WINDOWS\ServicePackFiles\i386\wucltui.dll
+ 2008-04-14 00:12:11 32,256 ------w C:\WINDOWS\ServicePackFiles\i386\wups.dll
+ 2008-04-14 00:12:11 120,320 ------w C:\WINDOWS\ServicePackFiles\i386\wuweb.dll
+ 2004-08-04 05:29:50 19,455 ------w C:\WINDOWS\ServicePackFiles\i386\wvchntxx.sys
+ 2008-04-14 00:12:11 383,488 ------w C:\WINDOWS\ServicePackFiles\i386\wzcdlg.dll
+ 2008-04-14 00:12:11 52,736 ------w C:\WINDOWS\ServicePackFiles\i386\wzcsapi.dll
+ 2008-04-14 00:12:11 483,840 ------w C:\WINDOWS\ServicePackFiles\i386\wzcsvc.dll
+ 2008-04-14 00:12:11 91,648 ------w C:\WINDOWS\ServicePackFiles\i386\xactsrv.dll
+ 2008-04-14 00:12:41 30,720 ------w C:\WINDOWS\ServicePackFiles\i386\xcopy.exe
+ 2004-08-04 11:00:00 174,200 ------w C:\WINDOWS\ServicePackFiles\i386\xenroll.dll
+ 2008-04-14 00:12:11 121,856 ------w C:\WINDOWS\ServicePackFiles\i386\xmllite.dll
+ 2008-04-14 00:12:11 129,024 ------w C:\WINDOWS\ServicePackFiles\i386\xmlprov.dll
+ 2008-04-14 00:12:11 50,176 ------w C:\WINDOWS\ServicePackFiles\i386\xmlprovi.dll
+ 2008-04-14 00:12:11 11,776 ------w C:\WINDOWS\ServicePackFiles\i386\xolehlp.dll
+ 2008-04-13 18:53:32 558,080 ------w C:\WINDOWS\ServicePackFiles\i386\xpnetdg.exe
+ 2008-04-13 17:39:29 438,784 ------w C:\WINDOWS\ServicePackFiles\i386\xpob2res.dll
+ 2008-04-13 17:39:22 187,392 ------w C:\WINDOWS\ServicePackFiles\i386\xpsp1res.dll
+ 2008-04-13 17:39:24 2,897,920 ------w C:\WINDOWS\ServicePackFiles\i386\xpsp2res.dll
+ 2008-04-13 17:39:26 689,152 ------w C:\WINDOWS\ServicePackFiles\i386\xpsp3res.dll
+ 2008-04-14 00:12:11 18,944 ------w C:\WINDOWS\ServicePackFiles\i386\xrxscnui.dll
+ 2008-04-14 00:12:11 116,224 ------w C:\WINDOWS\ServicePackFiles\i386\xrxwiadr.dll
+ 2008-04-14 00:12:11 338,432 ------w C:\WINDOWS\ServicePackFiles\i386\zipfldr.dll
+ 2008-04-14 00:11:51 33,792 ------w C:\WINDOWS\ServicePackFiles\ServicePackCache\i386\custsat.dll
+ 2008-04-14 00:11:59 82,944 ------w C:\WINDOWS\ServicePackFiles\ServicePackCache\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 ------w C:\WINDOWS\ServicePackFiles\ServicePackCache\i386\msgslang.dll
+ 2008-04-14 00:12:28 1,695,232 ------w C:\WINDOWS\ServicePackFiles\ServicePackCache\i386\msmsgs.exe
+ 2008-04-14 00:12:35 32,866 ------w C:\WINDOWS\slrundll.exe
- 2004-08-04 11:00:00 3,166,208 -c--a-w C:\WINDOWS\srchasst\msgr3en.dll
+ 2008-04-14 00:11:59 3,166,208 ----a-w C:\WINDOWS\srchasst\msgr3en.dll
- 2004-08-04 11:00:00 58,434 -c--a-w C:\WINDOWS\srchasst\srchctls.dll
+ 2008-04-14 00:12:06 58,434 ----a-w C:\WINDOWS\srchasst\srchctls.dll
- 2004-08-04 11:00:00 725,566 -c--a-w C:\WINDOWS\srchasst\srchui.dll
+ 2008-04-14 00:12:07 726,078 ----a-w C:\WINDOWS\srchasst\srchui.dll
- 2004-08-04 11:00:00 146,432 -c--a-w C:\WINDOWS\system\WINSPOOL.DRV
+ 2008-04-14 00:12:45 146,432 ----a-w C:\WINDOWS\system\winspool.drv
- 2006-08-16 11:58:05 100,352 ----a-w C:\WINDOWS\system32\6to4svc.dll
+ 2008-04-14 00:11:48 100,352 ----a-w C:\WINDOWS\system32\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 ------w C:\WINDOWS\system32\aaclient.dll
- 2004-08-04 11:00:00 183,808 ----a-w C:\WINDOWS\system32\accwiz.exe
+ 2008-04-14 00:12:11 184,320 ----a-w C:\WINDOWS\system32\accwiz.exe
- 2004-08-04 11:00:00 114,688 ----a-w C:\WINDOWS\system32\aclui.dll
+ 2008-04-14 00:11:48 115,712 ----a-w C:\WINDOWS\system32\aclui.dll
- 2004-08-04 11:00:00 194,048 ----a-w C:\WINDOWS\system32\activeds.dll
+ 2008-04-14 00:11:48 193,536 ----a-w C:\WINDOWS\system32\activeds.dll
- 2004-08-04 11:00:00 4,096 ----a-w C:\WINDOWS\system32\actmovie.exe
+ 2008-04-14 00:12:12 4,096 ----a-w C:\WINDOWS\system32\actmovie.exe
- 2004-08-04 11:00:00 101,888 ----a-w C:\WINDOWS\system32\actxprxy.dll
+ 2008-04-14 00:11:48 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
- 2004-08-04 11:00:00 175,616 -c--a-w C:\WINDOWS\system32\adsldp.dll
+ 2008-04-14 00:11:48 175,616 ----a-w C:\WINDOWS\system32\adsldp.dll
- 2004-08-04 11:00:00 143,360 ----a-w C:\WINDOWS\system32\adsldpc.dll
+ 2008-04-14 00:11:48 143,360 ----a-w C:\WINDOWS\system32\adsldpc.dll
- 2004-08-04 11:00:00 68,096 ----a-w C:\WINDOWS\system32\adsmsext.dll
+ 2008-04-14 00:11:48 68,096 ----a-w C:\WINDOWS\system32\adsmsext.dll
- 2004-08-04 11:00:00 263,680 -c--a-w C:\WINDOWS\system32\adsnt.dll
+ 2008-04-14 00:11:48 263,680 ----a-w C:\WINDOWS\system32\adsnt.dll
- 2004-08-04 11:00:00 616,960 ----a-w C:\WINDOWS\system32\advapi32.dll
+ 2008-04-14 00:11:48 617,472 ----a-w C:\WINDOWS\system32\advapi32.dll
- 2004-08-04 11:00:00 98,304 ----a-w C:\WINDOWS\system32\ahui.exe
+ 2008-04-14 00:12:12 98,304 ----a-w C:\WINDOWS\system32\ahui.exe
- 2004-08-04 11:00:00 44,544 ----a-w C:\WINDOWS\system32\alg.exe
+ 2008-04-14 00:12:12 44,544 ----a-w C:\WINDOWS\system32\alg.exe
- 2004-08-04 11:00:00 17,408 -c--a-w C:\WINDOWS\system32\alrsvc.dll
+ 2008-04-14 00:11:49 17,408 ----a-w C:\WINDOWS\system32\alrsvc.dll
- 2004-08-04 11:00:00 70,656 ----a-w C:\WINDOWS\system32\amstream.dll
+ 2008-04-14 00:11:49 70,656 ----a-w C:\WINDOWS\system32\amstream.dll
- 2004-08-04 11:00:00 126,976 ----a-w C:\WINDOWS\system32\apphelp.dll
+ 2008-04-14 00:11:49 125,952 ----a-w C:\WINDOWS\system32\apphelp.dll
- 2004-08-04 11:00:00 65,024 ----a-w C:\WINDOWS\system32\asycfilt.dll
+ 2008-04-14 00:11:49 65,024 ----a-w C:\WINDOWS\system32\asycfilt.dll
- 2004-08-04 11:00:00 25,088 ----a-w C:\WINDOWS\system32\at.exe
+ 2008-04-14 00:12:12 25,088 ----a-w C:\WINDOWS\system32\at.exe
+ 2008-04-14 00:11:49 229,376 ------w C:\WINDOWS\system32\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ------w C:\WINDOWS\system32\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ------w C:\WINDOWS\system32\ati2dvag.dll
+ 2008-04-14 00:11:49 870,784 ------w C:\WINDOWS\system32\ati3d1ag.dll
+ 2008-04-14 00:11:50 1,888,992 ------w C:\WINDOWS\system32\ati3duag.dll
+ 2008-04-14 00:11:50 32,768 ------w C:\WINDOWS\system32\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ------w C:\WINDOWS\system32\ativvaxx.dll
- 2004-08-04 11:00:00 58,880 ----a-w C:\WINDOWS\system32\atl.dll
+ 2008-04-14 00:11:50 58,880 ----a-w C:\WINDOWS\system32\atl.dll
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\atmadm.exe
+ 2008-04-14 00:12:12 11,264 ----a-w C:\WINDOWS\system32\atmadm.exe
- 2004-08-04 11:00:00 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
+ 2008-04-14 00:09:01 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
- 2004-08-04 11:00:00 30,208 ----a-w C:\WINDOWS\system32\atmlib.dll
+ 2008-04-14 00:11:50 30,208 ----a-w C:\WINDOWS\system32\atmlib.dll
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\attrib.exe
+ 2008-04-14 00:12:12 12,288 ----a-w C:\WINDOWS\system32\attrib.exe
- 2004-08-04 11:00:00 42,496 ----a-w C:\WINDOWS\system32\audiosrv.dll
+ 2008-04-14 00:11:50 42,496 ----a-w C:\WINDOWS\system32\audiosrv.dll
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\auditusr.exe
+ 2008-04-14 00:12:12 14,336 ----a-w C:\WINDOWS\system32\auditusr.exe
- 2005-03-02 18:09:29 56,832 ----a-w C:\WINDOWS\system32\authz.dll
+ 2008-04-14 00:11:50 62,464 ----a-w C:\WINDOWS\system32\authz.dll
- 2004-08-04 11:00:00 588,800 ----a-w C:\WINDOWS\system32\autochk.exe
+ 2008-04-14 00:12:12 588,800 ----a-w C:\WINDOWS\system32\autochk.exe
- 2004-08-04 11:00:00 602,624 ----a-w C:\WINDOWS\system32\autoconv.exe
+ 2008-04-14 00:12:12 602,624 ----a-w C:\WINDOWS\system32\autoconv.exe
- 2004-08-04 11:00:00 580,608 ----a-w C:\WINDOWS\system32\autofmt.exe
+ 2008-04-14 00:12:13 580,608 ----a-w C:\WINDOWS\system32\autofmt.exe
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\autolfn.exe
+ 2008-04-14 00:12:13 11,264 ----a-w C:\WINDOWS\system32\autolfn.exe
- 2004-08-04 11:00:00 84,992 ----a-w C:\WINDOWS\system32\avifil32.dll
+ 2008-04-14 00:11:50 84,992 ----a-w C:\WINDOWS\system32\avifil32.dll
+ 2008-04-14 00:11:50 233,472 ------w C:\WINDOWS\system32\azroles.dll
- 2004-08-04 11:00:00 52,736 ----a-w C:\WINDOWS\system32\basesrv.dll
+ 2008-04-14 00:11:50 52,736 ----a-w C:\WINDOWS\system32\basesrv.dll
- 2004-08-04 11:00:00 28,672 ----a-w C:\WINDOWS\system32\batmeter.dll
+ 2008-04-14 00:11:50 29,184 ----a-w C:\WINDOWS\system32\batmeter.dll
- 2004-08-04 11:00:00 8,704 ----a-w C:\WINDOWS\system32\batt.dll
+ 2008-04-14 00:11:50 8,704 ----a-w C:\WINDOWS\system32\batt.dll
- 2004-08-04 11:00:00 17,408 -c--a-w C:\WINDOWS\system32\bidispl.dll
+ 2008-04-14 00:11:50 17,408 ----a-w C:\WINDOWS\system32\bidispl.dll
- 2007-03-29 12:56:02 409,600 ------w C:\WINDOWS\system32\bits\qmgr.dll
+ 2008-04-14 00:12:03 409,088 ------w C:\WINDOWS\system32\bits\qmgr.dll
- 2007-03-29 12:56:02 8,192 ----a-w C:\WINDOWS\system32\bitsprx2.dll
+ 2008-04-14 00:11:50 8,192 ----a-w C:\WINDOWS\system32\bitsprx2.dll
- 2007-03-29 12:56:02 7,168 ----a-w C:\WINDOWS\system32\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ----a-w C:\WINDOWS\system32\bitsprx3.dll
- 2007-03-29 12:56:02 7,168 ------w C:\WINDOWS\system32\bitsprx4.dll
+ 2008-04-14 00:11:50 7,168 ------w C:\WINDOWS\system32\bitsprx4.dll
- 2004-08-04 11:00:00 71,680 ----a-w C:\WINDOWS\system32\blastcln.exe
+ 2008-04-14 00:12:13 71,680 ----a-w C:\WINDOWS\system32\blastcln.exe
- 2004-08-04 11:00:00 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
+ 2008-04-13 17:03:24 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
- 2004-08-04 11:00:00 77,312 ----a-w C:\WINDOWS\system32\browser.dll
+ 2008-04-14 00:11:50 77,824 ----a-w C:\WINDOWS\system32\browser.dll
- 2006-10-23 15:34:19 1,022,976 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2008-04-14 00:11:50 1,025,024 ----a-w C:\WINDOWS\system32\browseui.dll
- 2004-08-04 11:00:00 78,336 ----a-w C:\WINDOWS\system32\browsewm.dll
+ 2008-04-14 00:11:50 78,336 ----a-w C:\WINDOWS\system32\browsewm.dll
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\bthci.dll
+ 2008-04-14 00:11:50 20,992 ----a-w C:\WINDOWS\system32\bthci.dll
- 2004-08-04 11:00:00 30,208 -c--a-w C:\WINDOWS\system32\bthserv.dll
+ 2008-04-14 00:11:50 30,208 ----a-w C:\WINDOWS\system32\bthserv.dll
- 2004-08-04 11:00:00 50,688 -c--a-w C:\WINDOWS\system32\btpanui.dll
+ 2008-04-14 00:11:50 50,688 ----a-w C:\WINDOWS\system32\btpanui.dll
- 2004-08-04 11:00:00 59,904 ----a-w C:\WINDOWS\system32\cabinet.dll
+ 2008-04-14 00:11:50 60,416 ----a-w C:\WINDOWS\system32\cabinet.dll
- 2004-08-04 11:00:00 84,480 ----a-w C:\WINDOWS\system32\cabview.dll
+ 2008-04-14 00:11:50 84,480 ----a-w C:\WINDOWS\system32\cabview.dll
- 2004-08-04 11:00:00 18,432 ----a-w C:\WINDOWS\system32\cacls.exe
+ 2008-04-14 00:12:13 19,968 ----a-w C:\WINDOWS\system32\cacls.exe
- 2004-08-04 11:00:00 50,688 -c--a-w C:\WINDOWS\system32\camocx.dll
+ 2008-04-14 00:11:50 50,688 ----a-w C:\WINDOWS\system32\camocx.dll
- 2004-08-04 11:00:00 142,848 -c--a-w C:\WINDOWS\system32\capesnpn.dll
+ 2008-04-14 00:11:50 150,016 ----a-w C:\WINDOWS\system32\capesnpn.dll
- 2005-07-26 04:39:42 225,792 ----a-w C:\WINDOWS\system32\catsrv.dll
+ 2008-04-14 00:11:50 226,304 ----a-w C:\WINDOWS\system32\catsrv.dll
- 2004-08-04 11:00:00 85,504 ----a-w C:\WINDOWS\system32\catsrvps.dll
+ 2008-04-14 00:11:50 85,504 ----a-w C:\WINDOWS\system32\catsrvps.dll
- 2005-07-26 04:39:43 625,152 ----a-w C:\WINDOWS\system32\catsrvut.dll
+ 2008-04-14 00:11:50 625,664 ----a-w C:\WINDOWS\system32\catsrvut.dll
- 2006-10-23 15:34:19 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-04-14 00:11:50 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2005-09-10 01:53:41 2,067,968 ----a-w C:\WINDOWS\system32\cdosys.dll
+ 2008-04-14 00:11:50 2,091,520 ----a-w C:\WINDOWS\system32\cdosys.dll
- 2004-08-04 11:00:00 194,560 ----a-w C:\WINDOWS\system32\certcli.dll
+ 2008-04-14 00:11:50 194,560 ----a-w C:\WINDOWS\system32\certcli.dll
- 2004-08-04 11:00:00 457,728 -c--a-w C:\WINDOWS\system32\certmgr.dll
+ 2008-04-14 00:11:50 457,728 ----a-w C:\WINDOWS\system32\certmgr.dll
- 2004-08-04 11:00:00 38,912 -c--a-w C:\WINDOWS\system32\cfgbkend.dll
+ 2008-04-14 00:11:50 38,912 ----a-w C:\WINDOWS\system32\cfgbkend.dll
- 2004-08-04 11:00:00 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
+ 2008-04-14 00:09:05 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
- 2004-08-04 11:00:00 109,568 ----a-w C:\WINDOWS\system32\cic.dll
+ 2008-04-14 00:11:50 148,480 ----a-w C:\WINDOWS\system32\cic.dll
- 2006-06-22 05:06:29 69,120 ----a-w C:\WINDOWS\system32\ciodm.dll
+ 2008-04-14 00:11:50 69,120 ----a-w C:\WINDOWS\system32\ciodm.dll
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\system32\cisvc.exe
+ 2008-04-14 00:12:14 5,632 ----a-w C:\WINDOWS\system32\cisvc.exe
- 2005-07-26 04:39:43 110,080 ----a-w C:\WINDOWS\system32\clbcatex.dll
+ 2008-04-14 00:11:50 110,592 ----a-w C:\WINDOWS\system32\clbcatex.dll
- 2005-07-26 04:39:43 498,688 ----a-w C:\WINDOWS\system32\clbcatq.dll
+ 2008-04-14 00:11:50 498,688 ----a-w C:\WINDOWS\system32\clbcatq.dll
- 2004-08-04 11:00:00 64,000 ----a-w C:\WINDOWS\system32\cleanmgr.exe
+ 2008-04-14 00:12:14 64,000 ----a-w C:\WINDOWS\system32\cleanmgr.exe
- 2004-08-04 11:00:00 77,824 ----a-w C:\WINDOWS\system32\cliconfg.dll
+ 2008-04-14 00:11:50 77,824 ----a-w C:\WINDOWS\system32\cliconfg.dll
- 2004-08-04 11:00:00 20,480 ----a-w C:\WINDOWS\system32\cliconfg.exe
+ 2008-04-14 00:12:14 20,480 ----a-w C:\WINDOWS\system32\cliconfg.exe
- 2004-08-04 11:00:00 102,912 ----a-w C:\WINDOWS\system32\clipbrd.exe
+ 2008-04-14 00:12:14 102,912 ----a-w C:\WINDOWS\system32\clipbrd.exe
- 2004-08-04 11:00:00 33,280 ----a-w C:\WINDOWS\system32\clipsrv.exe
+ 2008-04-14 00:12:14 33,280 ----a-w C:\WINDOWS\system32\clipsrv.exe
- 2004-08-04 11:00:00 57,856 ----a-w C:\WINDOWS\system32\clusapi.dll
+ 2008-04-14 00:11:50 58,368 ----a-w C:\WINDOWS\system32\clusapi.dll
- 2004-08-04 11:00:00 15,872 -c--a-w C:\WINDOWS\system32\cmcfg32.dll
+ 2008-04-14 00:11:50 15,872 ----a-w C:\WINDOWS\system32\cmcfg32.dll
- 2004-08-04 11:00:00 388,608 ----a-w C:\WINDOWS\system32\cmd.exe
+ 2008-04-14 00:12:14 389,120 ----a-w C:\WINDOWS\system32\cmd.exe
- 2004-08-04 11:00:00 343,040 -c--a-w C:\WINDOWS\system32\cmdial32.dll
+ 2008-04-14 00:11:50 344,064 ----a-w C:\WINDOWS\system32\cmdial32.dll
- 2004-08-04 11:00:00 47,104 ----a-w C:\WINDOWS\system32\cmdl32.exe
+ 2008-04-14 00:12:14 25,600 ----a-w C:\WINDOWS\system32\cmdl32.exe
- 2004-08-04 11:00:00 39,936 ----a-w C:\WINDOWS\system32\cmmon32.exe
+ 2008-04-14 00:12:15 39,936 ----a-w C:\WINDOWS\system32\cmmon32.exe
- 2004-08-04 11:00:00 185,344 -c--a-w C:\WINDOWS\system32\cmprops.dll
+ 2008-04-14 00:11:50 185,344 ----a-w C:\WINDOWS\system32\cmprops.dll
- 2004-08-04 11:00:00 13,824 -c--a-w C:\WINDOWS\system32\cmsetACL.dll
+ 2008-04-14 00:11:50 13,312 ----a-w C:\WINDOWS\system32\cmsetacl.dll
- 2004-08-04 11:00:00 63,488 ----a-w C:\WINDOWS\system32\cmstp.exe
+ 2008-04-14 00:12:15 63,488 ----a-w C:\WINDOWS\system32\cmstp.exe
- 2004-08-04 11:00:00 39,936 ----a-w C:\WINDOWS\system32\cmutil.dll
+ 2008-04-14 00:11:50 39,424 ----a-w C:\WINDOWS\system32\cmutil.dll
- 2004-08-04 11:00:00 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
+ 2008-04-14 00:11:50 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
- 2005-07-26 04:39:43 60,416 ----a-w C:\WINDOWS\system32\colbact.dll
+ 2008-04-14 00:11:51 60,416 ----a-w C:\WINDOWS\system32\colbact.dll
- 2005-07-26 04:39:44 195,072 ----a-w C:\WINDOWS\system32\Com\comadmin.dll
+ 2008-04-14 00:11:51 195,072 ----a-w C:\WINDOWS\system32\Com\comadmin.dll
- 2004-08-04 11:00:00 9,728 -c--a-w C:\WINDOWS\system32\Com\comrepl.exe
+ 2008-04-14 00:12:15 9,728 ----a-w C:\WINDOWS\system32\Com\comrepl.exe
- 2004-08-04 11:00:00 5,120 -c--a-w C:\WINDOWS\system32\Com\comrereg.exe
+ 2008-04-14 00:12:15 6,144 ----a-w C:\WINDOWS\system32\Com\comrereg.exe
- 2004-08-04 11:00:00 25,600 -c--a-w C:\WINDOWS\system32\comaddin.dll
+ 2008-04-14 00:11:51 28,160 ----a-w C:\WINDOWS\system32\comaddin.dll
- 2006-08-25 15:45:58 617,472 ----a-w C:\WINDOWS\system32\comctl32.dll
+ 2008-04-14 00:11:51 617,472 ----a-w C:\WINDOWS\system32\comctl32.dll
- 2004-08-04 11:00:00 276,992 ----a-w C:\WINDOWS\system32\comdlg32.dll
+ 2008-04-14 00:11:51 276,992 ----a-w C:\WINDOWS\system32\comdlg32.dll
- 2004-08-04 11:00:00 252,928 ----a-w C:\WINDOWS\system32\compatUI.dll
+ 2008-04-14 00:11:51 252,928 ----a-w C:\WINDOWS\system32\compatui.dll
- 2004-08-04 11:00:00 229,376 -c--a-w C:\WINDOWS\system32\compstui.dll
+ 2008-04-14 00:11:51 229,376 ----a-w C:\WINDOWS\system32\compstui.dll
- 2005-07-26 04:39:44 97,792 ----a-w C:\WINDOWS\system32\comrepl.dll
+ 2008-04-14 00:11:51 97,792 ----a-w C:\WINDOWS\system32\comrepl.dll
- 2004-08-04 11:00:00 792,064 ----a-w C:\WINDOWS\system32\comres.dll
+ 2008-04-14 00:11:51 792,064 ----a-w C:\WINDOWS\system32\comres.dll
- 2004-08-04 11:00:00 147,456 -c--a-w C:\WINDOWS\system32\comsnap.dll
+ 2008-04-14 00:11:51 167,424 ----a-w C:\WINDOWS\system32\comsnap.dll
- 2005-07-26 04:39:44 1,267,200 ----a-w C:\WINDOWS\system32\comsvcs.dll
+ 2008-04-14 00:11:51 1,267,200 ----a-w C:\WINDOWS\system32\comsvcs.dll
- 2005-07-26 04:39:45 540,160 ----a-w C:\WINDOWS\system32\comuid.dll
+ 2008-04-14 00:11:51 539,648 ----a-w C:\WINDOWS\system32\comuid.dll
- 2008-10-05 16:59:21 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-10 15:28:00 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-05 16:59:21 49,152 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-10 15:28:00 49,152 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-10 15:27:53 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092920081006\index.dat
+ 2008-10-10 15:27:53 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101020081011\index.dat
- 2008-10-05 16:59:21 49,152 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 15:28:00 49,152 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-04 11:00:00 345,600 -c--a-w C:\WINDOWS\system32\confmsp.dll
+ 2008-04-14 00:11:51 357,888 ----a-w C:\WINDOWS\system32\confmsp.dll
- 2004-08-04 11:00:00 27,648 ----a-w C:\WINDOWS\system32\conime.exe
+ 2008-04-14 00:12:15 27,648 ----a-w C:\WINDOWS\system32\conime.exe
- 2007-01-09 03:01:14 17,408 ----a-w C:\WINDOWS\system32\corpol.dll
+ 2008-04-14 00:11:51 35,328 ----a-w C:\WINDOWS\system32\corpol.dll
+ 2008-04-14 00:11:51 12,800 ------w C:\WINDOWS\system32\credssp.dll
- 2004-08-04 11:00:00 163,840 ----a-w C:\WINDOWS\system32\credui.dll
+ 2008-04-14 00:11:51 163,840 ----a-w C:\WINDOWS\system32\credui.dll
- 2004-08-04 11:00:00 597,504 ----a-w C:\WINDOWS\system32\crypt32.dll
+ 2008-04-14 00:11:51 599,040 ----a-w C:\WINDOWS\system32\crypt32.dll
- 2004-08-04 11:00:00 74,752 ----a-w C:\WINDOWS\system32\cryptdlg.dll
+ 2008-04-14 00:11:51 74,752 ----a-w C:\WINDOWS\system32\cryptdlg.dll
- 2004-08-04 11:00:00 33,280 ----a-w C:\WINDOWS\system32\cryptdll.dll
+ 2008-04-14 00:11:51 33,280 ----a-w C:\WINDOWS\system32\cryptdll.dll
- 2004-08-04 11:00:00 53,760 ----a-w C:\WINDOWS\system32\cryptext.dll
+ 2008-04-14 00:11:51 53,760 ----a-w C:\WINDOWS\system32\cryptext.dll
- 2004-08-04 11:00:00 63,488 ----a-w C:\WINDOWS\system32\cryptnet.dll
+ 2008-04-14 00:11:51 64,512 ----a-w C:\WINDOWS\system32\cryptnet.dll
- 2004-08-04 11:00:00 60,416 ----a-w C:\WINDOWS\system32\cryptsvc.dll
+ 2008-04-14 00:11:51 62,464 ----a-w C:\WINDOWS\system32\cryptsvc.dll
- 2004-08-04 11:00:00 512,512 ----a-w C:\WINDOWS\system32\cryptui.dll
+ 2008-04-14 00:11:51 512,512 ----a-w C:\WINDOWS\system32\cryptui.dll
- 2004-08-04 11:00:00 101,888 ----a-w C:\WINDOWS\system32\cscdll.dll
+ 2008-04-14 00:11:51 101,888 ----a-w C:\WINDOWS\system32\cscdll.dll
- 2004-08-04 11:00:00 98,304 ----a-w C:\WINDOWS\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
- 2004-08-04 11:00:00 326,656 ----a-w C:\WINDOWS\system32\cscui.dll
+ 2008-04-14 00:11:51 326,656 ----a-w C:\WINDOWS\system32\cscui.dll
- 2004-08-04 11:00:00 32,768 ----a-w C:\WINDOWS\system32\csrsrv.dll
+ 2008-04-14 00:11:51 32,256 ----a-w C:\WINDOWS\system32\csrsrv.dll
- 2004-08-04 11:00:00 6,144 ----a-w C:\WINDOWS\system32\csrss.exe
+ 2008-04-14 00:12:15 6,144 ----a-w C:\WINDOWS\system32\csrss.exe
- 2004-08-04 11:00:00 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-04-14 00:12:16 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
breakawayjade
2008-10-17, 02:55
- 2004-08-04 11:00:00 1,179,648 ----a-w C:\WINDOWS\system32\d3d8.dll
+ 2008-04-14 00:11:51 1,179,648 ----a-w C:\WINDOWS\system32\d3d8.dll
- 2004-08-04 11:00:00 8,192 ----a-w C:\WINDOWS\system32\d3d8thk.dll
+ 2008-04-14 00:11:51 8,192 ----a-w C:\WINDOWS\system32\d3d8thk.dll
- 2004-08-04 11:00:00 1,689,088 ----a-w C:\WINDOWS\system32\d3d9.dll
+ 2008-04-14 00:11:51 1,689,088 ----a-w C:\WINDOWS\system32\d3d9.dll
- 2004-08-04 11:00:00 825,344 ----a-w C:\WINDOWS\system32\d3dim700.dll
+ 2008-04-14 00:11:51 824,320 ----a-w C:\WINDOWS\system32\d3dim700.dll
- 2006-10-23 15:34:20 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-04-14 00:11:51 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
- 2004-08-04 11:00:00 54,272 ----a-w C:\WINDOWS\system32\dataclen.dll
+ 2008-04-14 00:11:51 54,272 ----a-w C:\WINDOWS\system32\dataclen.dll
- 2004-08-04 11:00:00 152,064 -c--a-w C:\WINDOWS\system32\datime.dll
+ 2008-04-14 00:11:51 165,376 ----a-w C:\WINDOWS\system32\datime.dll
- 2004-08-04 11:00:00 24,576 ----a-w C:\WINDOWS\system32\davclnt.dll
+ 2008-04-14 00:11:51 25,088 ----a-w C:\WINDOWS\system32\davclnt.dll
- 2004-08-04 11:00:00 640,000 ----a-w C:\WINDOWS\system32\dbghelp.dll
+ 2008-04-14 00:11:51 640,000 ----a-w C:\WINDOWS\system32\dbghelp.dll
- 2004-08-04 11:00:00 24,576 -c--a-w C:\WINDOWS\system32\dbmsrpcn.dll
+ 2008-04-14 00:11:51 24,576 ----a-w C:\WINDOWS\system32\dbmsrpcn.dll
- 2004-08-04 11:00:00 110,592 ----a-w C:\WINDOWS\system32\dbnetlib.dll
+ 2008-04-14 00:11:51 110,592 ----a-w C:\WINDOWS\system32\dbnetlib.dll
- 2004-08-04 11:00:00 28,672 -c--a-w C:\WINDOWS\system32\dbnmpntw.dll
+ 2008-04-14 00:11:51 28,672 ----a-w C:\WINDOWS\system32\dbnmpntw.dll
- 2004-08-04 11:00:00 1,788 -c--a-w C:\WINDOWS\system32\Dcache.bin
+ 2008-04-14 00:25:26 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
- 2004-08-04 11:00:00 8,704 ----a-w C:\WINDOWS\system32\dciman32.dll
+ 2008-04-14 00:11:51 8,704 ----a-w C:\WINDOWS\system32\dciman32.dll
- 2004-08-04 11:00:00 5,120 ----a-w C:\WINDOWS\system32\dcomcnfg.exe
+ 2008-04-14 00:12:16 6,144 ----a-w C:\WINDOWS\system32\dcomcnfg.exe
- 2004-08-04 11:00:00 30,208 ----a-w C:\WINDOWS\system32\ddeshare.exe
+ 2008-04-14 00:12:16 30,208 ----a-w C:\WINDOWS\system32\ddeshare.exe
- 2004-08-04 11:00:00 266,240 ----a-w C:\WINDOWS\system32\ddraw.dll
+ 2008-04-14 00:11:51 279,552 ----a-w C:\WINDOWS\system32\ddraw.dll
- 2004-08-04 11:00:00 27,136 ----a-w C:\WINDOWS\system32\ddrawex.dll
+ 2008-04-14 00:11:51 27,136 ----a-w C:\WINDOWS\system32\ddrawex.dll
- 2004-08-04 11:00:00 25,088 ----a-w C:\WINDOWS\system32\defrag.exe
+ 2008-04-14 00:12:16 25,088 ----a-w C:\WINDOWS\system32\defrag.exe
- 2004-08-04 11:00:00 59,904 ----a-w C:\WINDOWS\system32\devenum.dll
+ 2008-04-14 00:11:51 59,904 ----a-w C:\WINDOWS\system32\devenum.dll
- 2004-08-04 11:00:00 282,624 ----a-w C:\WINDOWS\system32\devmgr.dll
+ 2008-04-14 00:11:51 282,624 ----a-w C:\WINDOWS\system32\devmgr.dll
- 2004-08-04 11:00:00 82,432 ----a-w C:\WINDOWS\system32\dfrgfat.exe
+ 2008-04-14 00:12:16 82,944 ----a-w C:\WINDOWS\system32\dfrgfat.exe
- 2004-08-04 11:00:00 104,960 ----a-w C:\WINDOWS\system32\dfrgntfs.exe
+ 2008-04-14 00:12:16 105,472 ----a-w C:\WINDOWS\system32\dfrgntfs.exe
- 2004-08-04 11:00:00 38,912 ----a-w C:\WINDOWS\system32\dfrgsnap.dll
+ 2008-04-14 00:11:51 39,424 ----a-w C:\WINDOWS\system32\dfrgsnap.dll
- 2004-08-04 11:00:00 123,904 ----a-w C:\WINDOWS\system32\dfrgui.dll
+ 2008-04-14 00:11:51 124,416 ----a-w C:\WINDOWS\system32\dfrgui.dll
- 2004-08-04 11:00:00 28,672 ----a-w C:\WINDOWS\system32\dfsshlex.dll
+ 2008-04-14 00:11:51 28,672 ----a-w C:\WINDOWS\system32\dfsshlex.dll
- 2004-08-04 11:00:00 111,104 ----a-w C:\WINDOWS\system32\dgnet.dll
+ 2008-04-14 00:11:51 111,104 ----a-w C:\WINDOWS\system32\dgnet.dll
- 2006-05-19 12:59:41 111,616 ----a-w C:\WINDOWS\system32\dhcpcsvc.dll
+ 2008-04-14 00:11:51 126,976 ----a-w C:\WINDOWS\system32\dhcpcsvc.dll
- 2004-08-04 11:00:00 370,176 -c--a-w C:\WINDOWS\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 379,904 ----a-w C:\WINDOWS\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ------w C:\WINDOWS\system32\dhcpqec.dll
- 2004-08-04 11:00:00 85,504 ----a-w C:\WINDOWS\system32\diantz.exe
+ 2008-04-14 00:12:17 87,040 ----a-w C:\WINDOWS\system32\diantz.exe
- 2004-08-04 11:00:00 68,608 ----a-w C:\WINDOWS\system32\digest.dll
+ 2008-04-14 00:11:52 68,608 ----a-w C:\WINDOWS\system32\digest.dll
+ 2008-04-14 00:11:52 19,456 ------w C:\WINDOWS\system32\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\system32\dimsroam.dll
- 2004-08-04 11:00:00 159,232 ----a-w C:\WINDOWS\system32\dinput.dll
+ 2008-04-14 00:11:52 158,720 ----a-w C:\WINDOWS\system32\dinput.dll
- 2004-08-04 11:00:00 181,760 -c--a-w C:\WINDOWS\system32\dinput8.dll
+ 2008-04-14 00:11:52 181,760 ----a-w C:\WINDOWS\system32\dinput8.dll
- 2004-08-04 11:00:00 1,501,696 ----a-w C:\WINDOWS\system32\diskcopy.dll
+ 2008-04-14 00:11:52 1,504,256 ----a-w C:\WINDOWS\system32\diskcopy.dll
- 2004-08-04 11:00:00 163,840 ----a-w C:\WINDOWS\system32\diskpart.exe
+ 2008-04-14 00:12:17 163,840 ----a-w C:\WINDOWS\system32\diskpart.exe
- 2004-08-04 11:00:00 45,083 ----a-w C:\WINDOWS\system32\dispex.dll
+ 2008-04-14 00:11:52 32,768 ----a-w C:\WINDOWS\system32\dispex.dll
- 2008-06-20 10:44:38 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
+ 2008-06-20 11:40:08 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
- 2008-06-13 13:10:50 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
+ 2008-06-13 11:05:51 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
+ 2008-05-07 09:07:23 135,168 ------w C:\WINDOWS\system32\dllcache\cscript.exe
- 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2006-08-22 12:05:26 498,742 ------w C:\WINDOWS\system32\dllcache\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 ------w C:\WINDOWS\system32\dllcache\dxmasf.dll
- 2008-07-07 20:32:22 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
+ 2008-07-07 20:26:58 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
- 2008-04-11 18:50:43 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
- 2006-10-17 20:00:00 491,520 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2008-05-09 10:53:39 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
- 2008-05-01 14:30:33 331,776 ------w C:\WINDOWS\system32\dllcache\msadce.dll
+ 2008-05-01 14:33:02 331,776 ------w C:\WINDOWS\system32\dllcache\msadce.dll
- 2008-06-24 16:23:05 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
+ 2008-06-24 16:43:16 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
- 2004-08-04 11:00:00 4,126 ----a-w C:\WINDOWS\system32\dllcache\msdxmlc.dll
+ 2008-04-14 00:10:08 4,126 ----a-w C:\WINDOWS\system32\dllcache\msdxmlc.dll
- 2008-06-20 17:41:10 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-06-20 17:46:57 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-04-14 00:12:01 1,306,624 ------w C:\WINDOWS\system32\dllcache\msxml6.dll
+ 2008-04-13 17:27:18 79,872 ------w C:\WINDOWS\system32\dllcache\msxml6r.dll
- 2004-08-04 11:00:00 226,816 ----a-w C:\WINDOWS\system32\dllcache\npdrmv2.dll
+ 2008-04-14 00:12:56 226,816 ----a-w C:\WINDOWS\system32\dllcache\npdrmv2.dll
- 2004-08-04 11:00:00 10,240 ----a-w C:\WINDOWS\system32\dllcache\npwmsdrm.dll
+ 2008-04-14 00:12:02 10,240 ----a-w C:\WINDOWS\system32\dllcache\npwmsdrm.dll
- 2008-05-07 05:18:48 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
- 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 14:02:52 203,136 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-09 10:53:39 180,224 ------w C:\WINDOWS\system32\dllcache\scrobj.dll
+ 2008-05-09 10:53:40 172,032 ------w C:\WINDOWS\system32\dllcache\scrrun.dll
- 2006-08-21 17:52:08 246,814 ------w C:\WINDOWS\system32\dllcache\strmdll.dll
+ 2008-04-14 00:12:07 246,814 ------w C:\WINDOWS\system32\dllcache\strmdll.dll
- 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 11:51:12 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
- 2006-11-08 05:03:36 413,696 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2008-05-09 10:53:40 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
- 2004-08-04 11:00:00 303,616 ----a-w C:\WINDOWS\system32\dllcache\wmstream.dll
+ 2008-04-14 00:12:10 303,616 ----a-w C:\WINDOWS\system32\dllcache\wmstream.dll
+ 2008-05-08 11:24:44 155,648 ------w C:\WINDOWS\system32\dllcache\wscript.exe
+ 2008-05-09 10:53:40 90,112 ------w C:\WINDOWS\system32\dllcache\wshext.dll
- 2004-08-04 11:00:00 5,120 ----a-w C:\WINDOWS\system32\dllhost.exe
+ 2008-04-14 00:12:17 5,120 ----a-w C:\WINDOWS\system32\dllhost.exe
- 2004-08-04 11:00:00 224,768 ----a-w C:\WINDOWS\system32\dmadmin.exe
+ 2008-04-14 00:12:17 224,768 ----a-w C:\WINDOWS\system32\dmadmin.exe
- 2004-08-04 11:00:00 28,672 -c--a-w C:\WINDOWS\system32\dmband.dll
+ 2008-04-14 00:11:52 28,672 ----a-w C:\WINDOWS\system32\dmband.dll
- 2004-08-04 11:00:00 61,440 -c--a-w C:\WINDOWS\system32\dmcompos.dll
+ 2008-04-14 00:11:52 61,440 ----a-w C:\WINDOWS\system32\dmcompos.dll
- 2004-08-04 11:00:00 273,920 -c--a-w C:\WINDOWS\system32\dmdlgs.dll
+ 2008-04-14 00:11:52 285,184 ----a-w C:\WINDOWS\system32\dmdlgs.dll
- 2004-08-04 11:00:00 200,704 ----a-w C:\WINDOWS\system32\dmdskmgr.dll
+ 2008-04-14 00:11:52 200,704 ----a-w C:\WINDOWS\system32\dmdskmgr.dll
- 2004-08-04 11:00:00 181,248 -c--a-w C:\WINDOWS\system32\dmime.dll
+ 2008-04-14 00:11:52 181,248 ----a-w C:\WINDOWS\system32\dmime.dll
- 2004-08-04 11:00:00 35,840 -c--a-w C:\WINDOWS\system32\dmloader.dll
+ 2008-04-14 00:11:52 35,840 ----a-w C:\WINDOWS\system32\dmloader.dll
- 2004-08-04 11:00:00 15,872 ----a-w C:\WINDOWS\system32\dmremote.exe
+ 2008-04-14 00:12:17 15,872 ----a-w C:\WINDOWS\system32\dmremote.exe
- 2004-08-04 11:00:00 82,432 ----a-w C:\WINDOWS\system32\dmscript.dll
+ 2008-04-14 00:11:52 82,432 ----a-w C:\WINDOWS\system32\dmscript.dll
- 2004-08-04 11:00:00 23,552 -c--a-w C:\WINDOWS\system32\dmserver.dll
+ 2008-04-14 00:11:52 23,552 ----a-w C:\WINDOWS\system32\dmserver.dll
- 2004-08-04 11:00:00 105,984 ----a-w C:\WINDOWS\system32\dmstyle.dll
+ 2008-04-14 00:11:52 105,984 ----a-w C:\WINDOWS\system32\dmstyle.dll
- 2004-08-04 11:00:00 103,424 ----a-w C:\WINDOWS\system32\dmsynth.dll
+ 2008-04-14 00:11:52 103,424 ----a-w C:\WINDOWS\system32\dmsynth.dll
- 2004-08-04 11:00:00 104,448 ----a-w C:\WINDOWS\system32\dmusic.dll
+ 2008-04-14 00:11:52 104,448 ----a-w C:\WINDOWS\system32\dmusic.dll
- 2004-08-04 11:00:00 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
+ 2008-04-14 00:11:52 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
- 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2008-02-20 05:32:43 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
+ 2008-04-14 00:11:52 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
- 2004-08-04 11:00:00 48,128 -c--a-w C:\WINDOWS\system32\docprop2.dll
+ 2008-04-14 00:11:52 48,128 ----a-w C:\WINDOWS\system32\docprop2.dll
+ 2008-04-14 00:11:52 26,112 ------w C:\WINDOWS\system32\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ------w C:\WINDOWS\system32\dot3cfg.dll
+ 2008-04-14 00:11:52 9,216 ------w C:\WINDOWS\system32\dot3dlg.dll
+ 2008-04-14 00:11:52 39,936 ------w C:\WINDOWS\system32\dot3gpclnt.dll
+ 2008-04-14 00:11:52 56,320 ------w C:\WINDOWS\system32\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ------w C:\WINDOWS\system32\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ------w C:\WINDOWS\system32\dot3ui.dll
- 2004-08-04 11:00:00 97,280 ----a-w C:\WINDOWS\system32\dpcdll.dll
+ 2008-04-13 21:00:49 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
- 2004-08-04 11:00:00 30,208 ----a-w C:\WINDOWS\system32\dplaysvr.exe
+ 2008-04-14 00:12:17 29,696 ----a-w C:\WINDOWS\system32\dplaysvr.exe
- 2004-08-04 11:00:00 229,888 -c--a-w C:\WINDOWS\system32\dplayx.dll
+ 2008-04-14 00:11:52 229,888 ----a-w C:\WINDOWS\system32\dplayx.dll
- 2004-08-04 11:00:00 23,552 -c--a-w C:\WINDOWS\system32\dpmodemx.dll
+ 2008-04-14 00:11:52 23,552 ----a-w C:\WINDOWS\system32\dpmodemx.dll
- 2004-08-04 11:00:00 3,584 -c--a-w C:\WINDOWS\system32\dpnaddr.dll
+ 2008-04-14 00:09:19 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
- 2004-08-04 11:00:00 375,296 -c--a-w C:\WINDOWS\system32\dpnet.dll
+ 2008-04-14 00:11:52 375,296 ----a-w C:\WINDOWS\system32\dpnet.dll
- 2004-08-04 11:00:00 35,328 -c--a-w C:\WINDOWS\system32\dpnhpast.dll
+ 2008-04-14 00:11:52 35,328 ----a-w C:\WINDOWS\system32\dpnhpast.dll
- 2004-08-04 11:00:00 60,928 ----a-w C:\WINDOWS\system32\dpnhupnp.dll
+ 2008-04-14 00:11:52 60,928 ----a-w C:\WINDOWS\system32\dpnhupnp.dll
- 2004-08-04 11:00:00 3,584 -c--a-w C:\WINDOWS\system32\dpnlobby.dll
+ 2008-04-14 00:09:20 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
- 2004-08-04 11:00:00 18,432 ----a-w C:\WINDOWS\system32\dpnsvr.exe
+ 2008-04-14 00:12:17 17,920 ----a-w C:\WINDOWS\system32\dpnsvr.exe
- 2004-08-04 11:00:00 21,504 -c--a-w C:\WINDOWS\system32\dpvacm.dll
+ 2008-04-14 00:11:52 21,504 ----a-w C:\WINDOWS\system32\dpvacm.dll
- 2004-08-04 11:00:00 212,480 -c--a-w C:\WINDOWS\system32\dpvoice.dll
+ 2008-04-14 00:11:52 212,480 ----a-w C:\WINDOWS\system32\dpvoice.dll
- 2004-08-04 11:00:00 83,456 ----a-w C:\WINDOWS\system32\dpvsetup.exe
+ 2008-04-14 00:12:18 83,456 ----a-w C:\WINDOWS\system32\dpvsetup.exe
- 2004-08-04 11:00:00 116,736 ----a-w C:\WINDOWS\system32\dpvvox.dll
+ 2008-04-14 00:11:52 116,736 ----a-w C:\WINDOWS\system32\dpvvox.dll
- 2004-08-04 11:00:00 57,344 ----a-w C:\WINDOWS\system32\dpwsockx.dll
+ 2008-04-14 00:11:52 57,344 ----a-w C:\WINDOWS\system32\dpwsockx.dll
- 2004-08-04 11:00:00 187,776 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
+ 2008-04-13 18:36:35 187,776 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
+ 2008-04-14 00:11:48 4,255 ------w C:\WINDOWS\system32\drivers\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ------w C:\WINDOWS\system32\drivers\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ------w C:\WINDOWS\system32\drivers\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ------w C:\WINDOWS\system32\drivers\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ------w C:\WINDOWS\system32\drivers\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ------w C:\WINDOWS\system32\drivers\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ------w C:\WINDOWS\system32\drivers\adv11nt5.dll
- 2006-02-15 00:22:26 142,464 ----a-w C:\WINDOWS\system32\drivers\aec.sys
+ 2008-04-13 16:39:23 142,592 ----a-w C:\WINDOWS\system32\drivers\aec.sys
- 2008-06-20 10:44:38 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
+ 2008-06-20 11:40:08 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
- 2004-08-04 05:07:42 42,368 ----a-w C:\WINDOWS\system32\drivers\AGP440.SYS
+ 2008-04-13 18:36:38 42,368 ----a-w C:\WINDOWS\system32\drivers\agp440.sys
- 2004-08-04 05:07:44 44,928 ----a-w C:\WINDOWS\system32\drivers\AGPCPQ.SYS
+ 2008-04-13 18:36:39 44,928 ----a-w C:\WINDOWS\system32\drivers\agpcpq.sys
- 2004-08-04 05:07:42 42,752 ----a-w C:\WINDOWS\system32\drivers\ALIM1541.SYS
+ 2008-04-13 18:36:38 42,752 ----a-w C:\WINDOWS\system32\drivers\alim1541.sys
- 2004-08-04 05:07:44 43,008 ----a-w C:\WINDOWS\system32\drivers\AMDAGP.SYS
+ 2008-04-13 18:36:39 43,008 ----a-w C:\WINDOWS\system32\drivers\amdagp.sys
- 2004-08-04 11:00:00 36,992 -c--a-w C:\WINDOWS\system32\drivers\amdk6.sys
+ 2008-04-13 18:31:32 37,376 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
- 2004-08-04 11:00:00 37,376 -c--a-w C:\WINDOWS\system32\drivers\amdk7.sys
+ 2008-04-13 18:31:33 37,760 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
- 2004-08-04 11:00:00 60,800 -c--a-w C:\WINDOWS\system32\drivers\arp1394.sys
+ 2008-04-13 18:51:25 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
+ 2008-04-13 18:57:27 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
- 2004-08-04 04:59:44 95,360 ----a-w C:\WINDOWS\system32\drivers\atapi.sys
+ 2008-04-13 18:40:30 96,512 ----a-w C:\WINDOWS\system32\drivers\atapi.sys
+ 2004-08-04 05:29:30 56,623 ------w C:\WINDOWS\system32\drivers\ati1btxx.sys
+ 2004-08-04 05:29:30 11,615 ------w C:\WINDOWS\system32\drivers\ati1mdxx.sys
+ 2004-08-04 05:29:30 12,047 ------w C:\WINDOWS\system32\drivers\ati1pdxx.sys
+ 2004-08-04 05:29:32 30,671 ------w C:\WINDOWS\system32\drivers\ati1raxx.sys
+ 2004-08-04 05:29:32 63,663 ------w C:\WINDOWS\system32\drivers\ati1rvxx.sys
+ 2004-08-04 05:29:32 26,367 ------w C:\WINDOWS\system32\drivers\ati1snxx.sys
+ 2004-08-04 05:29:32 21,343 ------w C:\WINDOWS\system32\drivers\ati1ttxx.sys
+ 2004-08-04 05:29:32 36,463 ------w C:\WINDOWS\system32\drivers\ati1tuxx.sys
+ 2004-08-04 05:29:32 29,455 ------w C:\WINDOWS\system32\drivers\ati1xbxx.sys
+ 2004-08-04 05:29:32 34,735 ------w C:\WINDOWS\system32\drivers\ati1xsxx.sys
+ 2004-08-04 05:29:28 327,040 ------w C:\WINDOWS\system32\drivers\ati2mtaa.sys
+ 2004-08-04 05:29:28 701,440 ------w C:\WINDOWS\system32\drivers\ati2mtag.sys
+ 2004-08-04 05:29:28 57,856 ------w C:\WINDOWS\system32\drivers\atinbtxx.sys
+ 2004-08-04 05:29:30 13,824 ------w C:\WINDOWS\system32\drivers\atinmdxx.sys
+ 2004-08-04 05:29:30 14,336 ------w C:\WINDOWS\system32\drivers\atinpdxx.sys
+ 2004-08-04 05:29:30 52,224 ------w C:\WINDOWS\system32\drivers\atinraxx.sys
+ 2004-08-04 05:29:32 104,960 ------w C:\WINDOWS\system32\drivers\atinrvxx.sys
+ 2004-08-04 05:29:32 28,672 ------w C:\WINDOWS\system32\drivers\atinsnxx.sys
+ 2004-08-04 05:29:32 13,824 ------w C:\WINDOWS\system32\drivers\atinttxx.sys
+ 2004-08-04 05:29:32 73,216 ------w C:\WINDOWS\system32\drivers\atintuxx.sys
+ 2004-08-04 05:29:32 31,744 ------w C:\WINDOWS\system32\drivers\atinxbxx.sys
+ 2004-08-04 05:29:32 63,488 ------w C:\WINDOWS\system32\drivers\atinxsxx.sys
- 2004-08-04 11:00:00 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
+ 2008-04-13 18:51:25 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
- 2004-08-04 11:00:00 55,936 -c--a-w C:\WINDOWS\system32\drivers\atmlane.sys
+ 2008-04-13 18:51:30 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
+ 2008-04-14 00:11:50 21,183 ------w C:\WINDOWS\system32\drivers\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ------w C:\WINDOWS\system32\drivers\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ------w C:\WINDOWS\system32\drivers\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ------w C:\WINDOWS\system32\drivers\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ------w C:\WINDOWS\system32\drivers\atv10nt5.dll
- 2004-08-04 11:00:00 71,552 -c--a-w C:\WINDOWS\system32\drivers\bridge.sys
+ 2008-04-13 18:53:23 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
+ 2008-04-13 18:46:33 17,024 ------w C:\WINDOWS\system32\drivers\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ------w C:\WINDOWS\system32\drivers\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ------w C:\WINDOWS\system32\drivers\bthpan.sys
- 2008-06-13 13:10:50 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
+ 2008-06-13 11:05:51 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
+ 2008-04-13 18:46:31 36,480 ------w C:\WINDOWS\system32\drivers\bthprint.sys
+ 2008-04-13 18:46:29 18,944 ------w C:\WINDOWS\system32\drivers\bthusb.sys
- 2004-08-04 11:00:00 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
+ 2008-04-13 19:14:21 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
- 2004-08-04 11:00:00 49,536 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys
+ 2008-04-13 18:40:46 62,976 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys
+ 2008-04-14 00:11:50 15,423 ------w C:\WINDOWS\system32\drivers\ch7xxnt5.dll
- 2004-08-04 11:00:00 49,664 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
+ 2008-04-13 19:16:22 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
- 2004-08-04 11:00:00 36,480 -c--a-w C:\WINDOWS\system32\drivers\crusoe.sys
+ 2008-04-13 18:31:32 36,736 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
- 2004-08-04 11:00:00 36,352 ----a-w C:\WINDOWS\system32\drivers\disk.sys
+ 2008-04-13 18:40:47 36,352 ----a-w C:\WINDOWS\system32\drivers\disk.sys
- 2004-08-04 11:00:00 14,208 -c--a-w C:\WINDOWS\system32\drivers\diskdump.sys
+ 2008-04-13 18:40:44 14,208 ----a-w C:\WINDOWS\system32\drivers\diskdump.sys
- 2004-08-04 11:00:00 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
+ 2008-04-13 18:44:48 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
- 2004-08-04 11:00:00 153,344 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
+ 2008-04-13 18:44:46 153,344 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
- 2004-08-04 05:07:40 52,864 ----a-w C:\WINDOWS\system32\drivers\DMusic.sys
+ 2008-04-13 18:45:01 52,864 ----a-w C:\WINDOWS\system32\drivers\dmusic.sys
- 2004-08-04 05:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
+ 2008-04-13 18:45:14 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
- 2004-08-04 05:07:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
+ 2008-04-13 18:45:13 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
- 2004-08-04 11:00:00 71,040 ----a-w C:\WINDOWS\system32\drivers\dxg.sys
+ 2008-04-13 18:38:29 71,168 ----a-w C:\WINDOWS\system32\drivers\dxg.sys
- 2004-08-04 11:00:00 143,360 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
+ 2008-04-13 19:14:29 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
- 2004-08-04 11:00:00 27,392 ----a-w C:\WINDOWS\system32\drivers\fdc.sys
+ 2008-04-13 18:40:25 27,392 ----a-w C:\WINDOWS\system32\drivers\fdc.sys
- 2004-08-04 11:00:00 34,944 ----a-w C:\WINDOWS\system32\drivers\fips.sys
+ 2008-04-13 18:33:28 44,544 ----a-w C:\WINDOWS\system32\drivers\fips.sys
- 2004-08-04 11:00:00 20,480 ----a-w C:\WINDOWS\system32\drivers\flpydisk.sys
+ 2008-04-13 18:40:25 20,480 ----a-w C:\WINDOWS\system32\drivers\flpydisk.sys
- 2006-08-21 09:14:58 128,896 ----a-w C:\WINDOWS\system32\drivers\fltmgr.sys
+ 2008-04-13 18:32:59 129,792 ----a-w C:\WINDOWS\system32\drivers\fltmgr.sys
+ 2008-04-13 18:36:40 46,464 ------w C:\WINDOWS\system32\drivers\gagp30kx.sys
+ 2008-04-13 16:36:05 144,384 ------w C:\WINDOWS\system32\drivers\hdaudbus.sys
+ 2008-04-13 18:46:30 25,600 ------w C:\WINDOWS\system32\drivers\hidbth.sys
- 2004-08-04 11:00:00 36,224 -c--a-w C:\WINDOWS\system32\drivers\hidclass.sys
+ 2008-04-13 18:45:26 36,864 ----a-w C:\WINDOWS\system32\drivers\hidclass.sys
+ 2008-04-13 18:45:26 19,200 ------w C:\WINDOWS\system32\drivers\hidir.sys
- 2004-08-04 11:00:00 24,960 -c--a-w C:\WINDOWS\system32\drivers\hidparse.sys
+ 2008-04-13 18:45:22 24,960 ----a-w C:\WINDOWS\system32\drivers\hidparse.sys
- 2001-08-17 22:02:20 9,600 ----a-w C:\WINDOWS\system32\drivers\hidusb.sys
+ 2008-04-13 18:45:27 10,368 ----a-w C:\WINDOWS\system32\drivers\hidusb.sys
+ 2004-08-04 05:41:48 220,032 ------w C:\WINDOWS\system32\drivers\hsfbs2s2.sys
+ 2004-08-04 05:41:50 685,056 ------w C:\WINDOWS\system32\drivers\hsfcxts2.sys
+ 2004-08-04 05:41:56 1,041,536 ------w C:\WINDOWS\system32\drivers\hsfdpsp2.sys
- 2006-03-17 00:33:10 262,784 ----a-w C:\WINDOWS\system32\drivers\http.sys
+ 2008-04-13 18:53:53 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys
- 2004-08-04 05:00:52 8,192 ----a-w C:\WINDOWS\system32\drivers\i2omgmt.sys
+ 2008-04-13 18:41:22 8,576 ----a-w C:\WINDOWS\system32\drivers\i2omgmt.sys
- 2004-08-04 05:00:52 18,560 ----a-w C:\WINDOWS\system32\drivers\i2omp.sys
+ 2008-04-13 18:41:22 18,560 ----a-w C:\WINDOWS\system32\drivers\i2omp.sys
- 2004-08-04 11:00:00 52,736 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
+ 2008-04-13 19:18:00 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
- 2004-08-04 11:00:00 41,856 ----a-w C:\WINDOWS\system32\drivers\imapi.sys
+ 2008-04-13 18:40:58 42,112 ----a-w C:\WINDOWS\system32\drivers\imapi.sys
- 2004-08-04 04:59:42 5,504 ----a-w C:\WINDOWS\system32\drivers\intelide.sys
+ 2008-04-13 18:40:29 5,504 ----a-w C:\WINDOWS\system32\drivers\intelide.sys
- 2004-08-04 11:00:00 36,096 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys
+ 2008-04-13 18:31:32 36,352 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys
- 2004-08-04 11:00:00 29,056 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
+ 2008-04-13 18:53:34 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
+ 2008-04-13 18:57:07 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
- 2004-09-29 22:28:37 134,912 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
+ 2008-04-13 18:57:15 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
- 2004-08-04 11:00:00 74,752 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
+ 2008-04-13 19:19:42 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
+ 2008-04-13 18:54:28 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
- 2001-08-17 19:58:02 35,840 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
+ 2008-04-13 18:36:41 37,248 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
- 2004-08-04 04:58:34 24,576 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
+ 2008-04-13 18:39:47 24,576 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
- 2006-06-14 08:47:45 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
+ 2008-04-13 18:45:09 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
- 2004-08-04 05:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2008-04-13 19:16:36 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2004-08-04 11:00:00 92,032 ----a-w C:\WINDOWS\system32\drivers\ksecdd.sys
+ 2008-04-13 18:31:43 92,288 ----a-w C:\WINDOWS\system32\drivers\ksecdd.sys
+ 2004-08-04 05:41:56 11,868 ------w C:\WINDOWS\system32\drivers\mdmxsdk.sys
- 2004-08-04 11:00:00 63,744 -c--a-w C:\WINDOWS\system32\drivers\mf.sys
+ 2008-04-13 18:36:41 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys
- 2004-08-04 11:00:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
+ 2008-04-13 19:00:19 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
- 2004-08-04 04:58:34 23,040 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
+ 2008-04-13 18:39:47 23,040 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
- 2004-08-04 11:00:00 42,240 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys
+ 2008-04-13 18:39:46 42,368 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys
- 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
+ 2008-04-13 18:32:44 180,608 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
- 2006-05-05 09:41:45 453,120 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
+ 2008-04-13 19:17:01 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
- 2004-08-04 11:00:00 19,072 ----a-w C:\WINDOWS\system32\drivers\msfs.sys
+ 2008-04-13 18:32:39 19,072 ----a-w C:\WINDOWS\system32\drivers\msfs.sys
- 2004-08-04 11:00:00 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
+ 2008-04-13 18:56:32 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
- 2004-08-04 04:58:42 7,552 ----a-w C:\WINDOWS\system32\drivers\MSKSSRV.sys
+ 2008-04-13 18:39:52 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
- 2004-08-04 04:58:40 5,376 ----a-w C:\WINDOWS\system32\drivers\MSPCLOCK.sys
+ 2008-04-13 18:39:50 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
- 2004-08-04 04:58:42 4,992 ----a-w C:\WINDOWS\system32\drivers\MSPQM.sys
+ 2008-04-13 18:39:51 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
- 2004-08-04 05:07:48 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys
+ 2008-04-13 18:36:46 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys
+ 2004-08-04 05:41:40 126,686 ------w C:\WINDOWS\system32\drivers\mtlmnt5.sys
+ 2004-08-04 05:41:38 1,309,184 ------w C:\WINDOWS\system32\drivers\mtlstrm.sys
+ 2004-08-04 05:29:38 452,736 ------w C:\WINDOWS\system32\drivers\mtxparhm.sys
- 2004-08-04 11:00:00 107,904 ----a-w C:\WINDOWS\system32\drivers\mup.sys
+ 2008-04-13 19:17:05 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
+ 2008-04-13 18:43:55 12,672 ------w C:\WINDOWS\system32\drivers\mutohpen.sys
- 2004-08-04 11:00:00 182,912 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
+ 2008-04-13 19:20:37 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
- 2004-08-04 11:00:00 9,600 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
+ 2008-04-13 18:57:27 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
- 2004-08-04 11:00:00 12,928 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
+ 2008-04-13 18:55:58 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
- 2004-08-04 11:00:00 91,776 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
+ 2008-04-13 19:20:42 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
- 2004-08-04 11:00:00 38,016 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
+ 2008-04-13 18:57:29 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
- 2004-08-04 11:00:00 34,560 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
+ 2008-04-13 18:56:02 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
- 2004-08-04 11:00:00 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
+ 2008-04-13 19:21:00 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
- 2004-08-04 11:00:00 61,824 -c--a-w C:\WINDOWS\system32\drivers\nic1394.sys
+ 2008-04-13 18:51:25 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
- 2004-08-04 11:00:00 40,320 -c--a-w C:\WINDOWS\system32\drivers\nmnt.sys
+ 2008-04-13 18:53:09 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
- 2004-08-04 11:00:00 30,848 ----a-w C:\WINDOWS\system32\drivers\npfs.sys
+ 2008-04-13 18:32:39 30,848 ----a-w C:\WINDOWS\system32\drivers\npfs.sys
- 2007-02-09 11:10:35 574,464 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
+ 2008-04-13 19:15:53 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
+ 2004-08-04 05:41:40 180,360 ------w C:\WINDOWS\system32\drivers\ntmtlfax.sys
- 2004-08-04 11:00:00 88,448 -c--a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
+ 2008-04-13 18:56:06 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
- 2004-08-04 11:00:00 42,496 -c--a-w C:\WINDOWS\system32\drivers\p3.sys
+ 2008-04-13 18:31:31 42,752 ----a-w C:\WINDOWS\system32\drivers\p3.sys
- 2004-08-04 11:00:00 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
+ 2008-04-13 18:40:10 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
- 2004-08-04 11:00:00 18,688 ----a-w C:\WINDOWS\system32\drivers\partmgr.sys
+ 2008-04-13 18:40:49 19,712 ----a-w C:\WINDOWS\system32\drivers\partmgr.sys
- 2004-08-04 05:07:48 68,224 ----a-w C:\WINDOWS\system32\drivers\pci.sys
+ 2008-04-13 18:36:44 68,224 ----a-w C:\WINDOWS\system32\drivers\pci.sys
- 2004-08-04 04:59:42 25,088 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys
+ 2008-04-13 18:40:29 24,960 ----a-w C:\WINDOWS\system32\drivers\pciidex.sys
- 2004-08-04 11:00:00 119,936 -c--a-w C:\WINDOWS\system32\drivers\pcmcia.sys
+ 2008-04-13 18:36:43 120,192 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
- 2004-08-04 05:15:50 145,792 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
+ 2008-04-13 19:19:41 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
- 2004-08-04 11:00:00 35,328 -c--a-w C:\WINDOWS\system32\drivers\processr.sys
+ 2008-04-13 18:31:30 35,840 ----a-w C:\WINDOWS\system32\drivers\processr.sys
- 2004-08-04 11:00:00 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
+ 2008-04-13 18:56:38 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
- 2004-08-04 11:00:00 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
+ 2008-04-13 19:19:43 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
- 2004-08-04 11:00:00 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
+ 2008-04-13 18:57:32 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
- 2004-08-04 11:00:00 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
+ 2008-04-13 19:19:48 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
- 2006-05-05 09:47:57 174,592 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
+ 2008-04-13 19:28:39 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
- 2004-08-04 05:01:16 196,864 ----a-w C:\WINDOWS\system32\drivers\rdpdr.sys
+ 2008-04-13 18:32:51 196,224 ----a-w C:\WINDOWS\system32\drivers\rdpdr.sys
- 2005-06-10 04:09:46 139,528 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
+ 2008-04-14 00:13:22 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
+ 2004-08-04 05:41:40 13,776 ------w C:\WINDOWS\system32\drivers\recagent.sys
- 2004-08-04 04:59:38 57,472 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
+ 2008-04-13 18:40:27 57,600 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
+ 2008-04-13 18:46:32 59,136 ------w C:\WINDOWS\system32\drivers\rfcomm.sys
- 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
+ 2008-05-08 14:02:52 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2004-08-04 11:00:00 30,080 -c--a-w C:\WINDOWS\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
+ 2004-08-04 05:29:52 166,912 ------w C:\WINDOWS\system32\drivers\s3gnbm.sys
- 2004-08-04 11:00:00 96,256 -c--a-w C:\WINDOWS\system32\drivers\scsiport.sys
+ 2008-04-13 18:40:30 96,384 ----a-w C:\WINDOWS\system32\drivers\scsiport.sys
- 2004-08-04 11:00:00 67,584 -c--a-w C:\WINDOWS\system32\drivers\sdbus.sys
+ 2008-04-13 18:36:44 79,232 ----a-w C:\WINDOWS\system32\drivers\sdbus.sys
- 2004-08-04 11:00:00 15,488 ----a-w C:\WINDOWS\system32\drivers\serenum.sys
+ 2008-04-13 18:40:12 15,744 ----a-w C:\WINDOWS\system32\drivers\serenum.sys
- 2004-08-04 11:00:00 64,896 ----a-w C:\WINDOWS\system32\drivers\serial.sys
+ 2008-04-13 19:15:45 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
- 2004-08-04 11:00:00 11,136 -c--a-w C:\WINDOWS\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:47 11,904 ----a-w C:\WINDOWS\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 ------w C:\WINDOWS\system32\drivers\sffp_mmc.sys
- 2004-08-04 11:00:00 10,240 -c--a-w C:\WINDOWS\system32\drivers\sffp_sd.sys
+ 2008-04-13 18:40:47 11,008 ----a-w C:\WINDOWS\system32\drivers\sffp_sd.sys
- 2004-08-04 11:00:00 11,392 ----a-w C:\WINDOWS\system32\drivers\sfloppy.sys
+ 2008-04-13 18:40:48 11,392 ----a-w C:\WINDOWS\system32\drivers\sfloppy.sys
+ 2008-04-14 00:12:05 3,901 ------w C:\WINDOWS\system32\drivers\siint5.dll
- 2004-08-04 05:07:44 41,088 ----a-w C:\WINDOWS\system32\drivers\SISAGP.SYS
+ 2008-04-13 18:36:39 40,960 ----a-w C:\WINDOWS\system32\drivers\sisagp.sys
+ 2004-08-04 05:41:42 129,535 ------w C:\WINDOWS\system32\drivers\slnt7554.sys
+ 2004-08-04 05:41:44 404,990 ------w C:\WINDOWS\system32\drivers\slntamr.sys
+ 2004-08-04 05:41:46 95,424 ------w C:\WINDOWS\system32\drivers\slnthal.sys
+ 2004-08-04 05:41:46 13,240 ------w C:\WINDOWS\system32\drivers\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 ------w C:\WINDOWS\system32\drivers\smbali.sys
- 2004-08-04 11:00:00 25,472 -c--a-w C:\WINDOWS\system32\drivers\sonydcam.sys
+ 2008-04-13 18:46:07 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
- 2006-06-14 08:47:46 6,400 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
+ 2008-04-13 18:45:07 6,272 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
- 2004-08-04 11:00:00 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys
+ 2008-04-13 18:36:52 73,472 ----a-w C:\WINDOWS\system32\drivers\sr.sys
- 2006-08-14 10:34:41 332,928 ----a-w C:\WINDOWS\system32\drivers\srv.sys
+ 2008-04-13 19:15:11 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
- 2004-08-04 05:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2008-04-13 18:45:15 49,408 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2004-08-04 04:58:42 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
+ 2008-04-13 18:39:53 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
- 2001-08-17 20:00:52 54,272 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
+ 2008-04-13 18:45:09 56,576 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
- 2004-08-04 05:15:56 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
+ 2008-04-13 19:15:55 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
- 2004-08-04 11:00:00 14,976 -c--a-w C:\WINDOWS\system32\drivers\tape.sys
+ 2008-04-13 18:40:50 14,976 ----a-w C:\WINDOWS\system32\drivers\tape.sys
- 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2008-06-20 11:51:12 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
- 2004-08-04 11:00:00 18,560 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
+ 2008-04-13 19:00:05 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
- 2004-08-04 11:00:00 12,040 -c--a-w C:\WINDOWS\system32\drivers\tdpipe.sys
+ 2008-04-14 00:13:20 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
- 2004-08-04 11:00:00 21,896 -c--a-w C:\WINDOWS\system32\drivers\tdtcp.sys
+ 2008-04-14 00:13:21 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
- 2004-08-04 07:01:08 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
+ 2008-04-14 00:13:20 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
- 2004-08-04 11:00:00 12,416 -c--a-w C:\WINDOWS\system32\drivers\tunmp.sys
+ 2008-04-13 18:56:01 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
+ 2008-04-13 18:36:40 44,672 ------w C:\WINDOWS\system32\drivers\uagp35.sys
- 2004-08-04 11:00:00 66,176 ----a-w C:\WINDOWS\system32\drivers\udfs.sys
+ 2008-04-13 18:32:36 66,048 ----a-w C:\WINDOWS\system32\drivers\udfs.sys
- 2007-04-23 10:14:23 364,160 ----a-w C:\WINDOWS\system32\drivers\update.sys
+ 2008-04-13 18:39:46 384,768 ----a-w C:\WINDOWS\system32\drivers\update.sys
- 2004-08-04 11:00:00 12,672 -c--a-w C:\WINDOWS\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
- 2004-08-04 11:00:00 23,808 -c--a-w C:\WINDOWS\system32\drivers\usbcamd.sys
+ 2008-04-13 18:45:40 25,600 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys
- 2004-08-04 11:00:00 23,936 -c--a-w C:\WINDOWS\system32\drivers\usbcamd2.sys
+ 2008-04-13 18:45:41 25,728 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys
- 2004-08-04 07:08:48 31,616 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys
+ 2008-04-13 18:45:39 32,128 ----a-w C:\WINDOWS\system32\drivers\usbccgp.sys
- 2004-08-04 11:00:00 26,624 ----a-w C:\WINDOWS\system32\drivers\usbehci.sys
+ 2008-04-13 18:45:35 30,208 ----a-w C:\WINDOWS\system32\drivers\usbehci.sys
- 2004-08-04 05:08:44 57,600 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys
+ 2008-04-13 18:45:37 59,520 ----a-w C:\WINDOWS\system32\drivers\usbhub.sys
- 2004-08-04 11:00:00 16,000 -c--a-w C:\WINDOWS\system32\drivers\usbintel.sys
+ 2008-04-13 18:45:43 15,872 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys
- 2004-08-04 05:08:44 142,976 ----a-w C:\WINDOWS\system32\drivers\usbport.sys
+ 2008-04-13 18:45:36 143,872 ----a-w C:\WINDOWS\system32\drivers\usbport.sys
- 2004-08-04 07:01:26 25,856 ----a-w C:\WINDOWS\system32\drivers\usbprint.sys
+ 2008-04-13 18:47:37 25,856 ----a-w C:\WINDOWS\system32\drivers\usbprint.sys
- 2004-08-04 06:58:46 15,104 ----a-w C:\WINDOWS\system32\drivers\usbscan.sys
+ 2008-04-13 18:45:34 15,104 ----a-w C:\WINDOWS\system32\drivers\usbscan.sys
- 2004-08-04 07:08:48 26,496 ----a-w C:\WINDOWS\system32\drivers\USBSTOR.SYS
+ 2008-04-13 18:45:38 26,368 ----a-w C:\WINDOWS\system32\drivers\usbstor.sys
- 2004-08-04 05:08:38 20,480 ----a-w C:\WINDOWS\system32\drivers\usbuhci.sys
+ 2008-04-13 18:45:35 20,608 ----a-w C:\WINDOWS\system32\drivers\usbuhci.sys
+ 2008-04-13 18:46:20 121,984 ------w C:\WINDOWS\system32\drivers\usbvideo.sys
+ 2008-04-14 00:12:08 11,325 ------w C:\WINDOWS\system32\drivers\vchnt5.dll
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
+ 2008-04-13 18:44:40 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
- 2004-08-04 05:07:44 42,240 ----a-w C:\WINDOWS\system32\drivers\VIAAGP.SYS
+ 2008-04-13 18:36:40 42,240 ----a-w C:\WINDOWS\system32\drivers\viaagp.sys
- 2004-08-04 04:59:44 5,376 ----a-w C:\WINDOWS\system32\drivers\viaide.sys
+ 2008-04-13 18:40:31 5,376 ----a-w C:\WINDOWS\system32\drivers\viaide.sys
- 2004-08-04 11:00:00 79,744 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
+ 2008-04-13 18:44:40 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
- 2004-08-04 11:00:00 52,352 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
+ 2008-04-13 18:41:01 52,352 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
+ 2008-04-13 18:43:55 14,208 ------w C:\WINDOWS\system32\drivers\wacompen.sys
+ 2004-08-04 05:29:40 11,807 ------w C:\WINDOWS\system32\drivers\wadv07nt.sys
+ 2004-08-04 05:29:40 11,295 ------w C:\WINDOWS\system32\drivers\wadv08nt.sys
+ 2004-08-04 05:29:42 11,871 ------w C:\WINDOWS\system32\drivers\wadv09nt.sys
+ 2004-08-04 05:29:42 11,935 ------w C:\WINDOWS\system32\drivers\wadv11nt.sys
- 2004-08-04 11:00:00 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
+ 2008-04-13 18:57:21 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
+ 2004-08-04 05:29:46 22,271 ------w C:\WINDOWS\system32\drivers\watv06nt.sys
+ 2004-08-04 05:29:46 25,471 ------w C:\WINDOWS\system32\drivers\watv10nt.sys
- 2006-06-14 09:00:45 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2008-04-13 19:17:18 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\drprov.dll
+ 2008-04-14 00:11:52 14,336 ----a-w C:\WINDOWS\system32\drprov.dll
- 2004-08-04 11:00:00 16,384 ----a-w C:\WINDOWS\system32\ds32gt.dll
+ 2008-04-14 00:11:52 16,384 ----a-w C:\WINDOWS\system32\ds32gt.dll
- 2004-08-04 11:00:00 181,760 -c--a-w C:\WINDOWS\system32\dsdmo.dll
+ 2008-04-14 00:11:52 181,248 ----a-w C:\WINDOWS\system32\dsdmo.dll
- 2004-08-04 11:00:00 71,680 ----a-w C:\WINDOWS\system32\dsdmoprp.dll
+ 2008-04-14 00:11:52 71,680 ----a-w C:\WINDOWS\system32\dsdmoprp.dll
- 2004-08-04 11:00:00 92,672 ----a-w C:\WINDOWS\system32\dskquota.dll
+ 2008-04-14 00:11:52 92,672 ----a-w C:\WINDOWS\system32\dskquota.dll
- 2004-08-04 11:00:00 144,384 ----a-w C:\WINDOWS\system32\dskquoui.dll
+ 2008-04-14 00:11:52 155,648 ----a-w C:\WINDOWS\system32\dskquoui.dll
- 2004-08-04 11:00:00 367,616 ----a-w C:\WINDOWS\system32\dsound.dll
+ 2008-04-14 00:11:52 367,616 ----a-w C:\WINDOWS\system32\dsound.dll
breakawayjade
2008-10-17, 02:56
- 2004-08-04 11:00:00 1,294,336 -c--a-w C:\WINDOWS\system32\dsound3d.dll
+ 2008-04-14 00:11:52 1,293,824 ----a-w C:\WINDOWS\system32\dsound3d.dll
- 2004-08-04 11:00:00 142,336 -c--a-w C:\WINDOWS\system32\dsprop.dll
+ 2008-04-14 00:11:52 142,848 ----a-w C:\WINDOWS\system32\dsprop.dll
- 2004-08-04 11:00:00 4,096 -c--a-w C:\WINDOWS\system32\dsprpres.dll
+ 2008-04-13 17:09:30 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
- 2004-08-04 11:00:00 239,104 -c--a-w C:\WINDOWS\system32\dsquery.dll
+ 2008-04-14 00:11:52 239,104 ----a-w C:\WINDOWS\system32\dsquery.dll
- 2004-08-04 11:00:00 51,200 ----a-w C:\WINDOWS\system32\dssec.dll
+ 2008-04-14 00:11:52 51,200 ----a-w C:\WINDOWS\system32\dssec.dll
- 2004-08-04 11:00:00 137,216 ----a-w C:\WINDOWS\system32\dssenh.dll
+ 2008-04-13 17:37:57 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
- 2004-08-04 11:00:00 113,152 -c--a-w C:\WINDOWS\system32\dsuiext.dll
+ 2008-04-14 00:11:52 113,152 ----a-w C:\WINDOWS\system32\dsuiext.dll
- 2004-08-04 11:00:00 19,456 -c--a-w C:\WINDOWS\system32\dswave.dll
+ 2008-04-14 00:11:52 19,456 ----a-w C:\WINDOWS\system32\dswave.dll
- 2004-08-04 11:00:00 10,752 ----a-w C:\WINDOWS\system32\dumprep.exe
+ 2008-04-14 00:12:18 10,752 ----a-w C:\WINDOWS\system32\dumprep.exe
- 2004-08-04 11:00:00 304,128 ----a-w C:\WINDOWS\system32\duser.dll
+ 2008-04-14 00:11:52 304,128 ----a-w C:\WINDOWS\system32\duser.dll
- 2004-08-04 11:00:00 17,920 ----a-w C:\WINDOWS\system32\dvdupgrd.exe
+ 2008-04-14 00:12:18 17,920 ----a-w C:\WINDOWS\system32\dvdupgrd.exe
- 2004-08-04 11:00:00 180,224 ----a-w C:\WINDOWS\system32\dwwin.exe
+ 2008-04-14 00:12:18 180,224 ----a-w C:\WINDOWS\system32\dwwin.exe
- 2004-08-04 11:00:00 619,008 -c--a-w C:\WINDOWS\system32\dx7vb.dll
+ 2008-04-14 00:11:52 619,008 ----a-w C:\WINDOWS\system32\dx7vb.dll
- 2004-08-04 11:00:00 1,227,264 -c--a-w C:\WINDOWS\system32\dx8vb.dll
+ 2008-04-14 00:11:52 1,227,264 ----a-w C:\WINDOWS\system32\dx8vb.dll
- 2004-08-04 11:00:00 1,298,432 ----a-w C:\WINDOWS\system32\dxdiag.exe
+ 2008-04-14 00:12:18 1,298,432 ----a-w C:\WINDOWS\system32\dxdiag.exe
- 2004-08-04 11:00:00 2,113,536 -c--a-w C:\WINDOWS\system32\dxdiagn.dll
+ 2008-04-14 00:11:52 2,113,536 ----a-w C:\WINDOWS\system32\dxdiagn.dll
- 2006-08-22 12:05:26 498,742 ----a-w C:\WINDOWS\system32\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 ----a-w C:\WINDOWS\system32\dxmasf.dll
+ 2008-04-14 00:11:52 30,720 ------w C:\WINDOWS\system32\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ------w C:\WINDOWS\system32\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ------w C:\WINDOWS\system32\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ------w C:\WINDOWS\system32\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ------w C:\WINDOWS\system32\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ------w C:\WINDOWS\system32\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ------w C:\WINDOWS\system32\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ------w C:\WINDOWS\system32\eapsvc.dll
- 2004-08-04 11:00:00 183,296 ----a-w C:\WINDOWS\system32\els.dll
+ 2008-04-14 00:11:53 183,296 ----a-w C:\WINDOWS\system32\els.dll
+ 2008-04-14 00:11:57 28,672 ------w C:\WINDOWS\system32\en\microsoft.managementconsole.resources.dll
+ 2008-04-14 00:11:57 40,960 ------w C:\WINDOWS\system32\en\mmcex.resources.dll
+ 2008-04-14 00:11:57 6,656 ------w C:\WINDOWS\system32\en\mmcfxcommon.resources.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\system32\encapi.dll
+ 2008-04-14 00:11:53 20,480 ----a-w C:\WINDOWS\system32\encapi.dll
- 2004-08-04 11:00:00 186,368 ----a-w C:\WINDOWS\system32\encdec.dll
+ 2008-04-14 00:11:53 186,880 ----a-w C:\WINDOWS\system32\encdec.dll
- 2004-08-04 11:00:00 23,040 ----a-w C:\WINDOWS\system32\ersvc.dll
+ 2008-04-14 00:11:53 23,040 ----a-w C:\WINDOWS\system32\ersvc.dll
- 2008-07-07 20:32:22 253,952 ----a-w C:\WINDOWS\system32\es.dll
+ 2008-07-07 20:26:58 253,952 ----a-w C:\WINDOWS\system32\es.dll
- 2005-10-20 22:20:03 1,082,368 ----a-w C:\WINDOWS\system32\esent.dll
+ 2008-04-14 00:11:53 1,082,368 ----a-w C:\WINDOWS\system32\esent.dll
- 2004-08-04 11:00:00 193,024 ----a-w C:\WINDOWS\system32\eudcedit.exe
+ 2008-04-14 00:12:19 193,024 ----a-w C:\WINDOWS\system32\eudcedit.exe
- 2004-08-04 11:00:00 55,808 ----a-w C:\WINDOWS\system32\eventlog.dll
+ 2008-04-14 00:11:53 56,320 ----a-w C:\WINDOWS\system32\eventlog.dll
- 2004-08-04 11:00:00 380,957 ----a-w C:\WINDOWS\system32\expsrv.dll
+ 2008-04-14 00:11:53 380,445 ----a-w C:\WINDOWS\system32\expsrv.dll
- 2004-08-04 11:00:00 45,568 ----a-w C:\WINDOWS\system32\extrac32.exe
+ 2008-04-14 00:12:19 24,064 ----a-w C:\WINDOWS\system32\extrac32.exe
- 2004-08-04 11:00:00 121,856 ----a-w C:\WINDOWS\system32\exts.dll
+ 2008-04-14 00:11:53 125,952 ----a-w C:\WINDOWS\system32\exts.dll
- 2004-08-04 11:00:00 80,384 ----a-w C:\WINDOWS\system32\faultrep.dll
+ 2008-04-14 00:11:53 80,384 ----a-w C:\WINDOWS\system32\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ------w C:\WINDOWS\system32\faxpatch.exe
- 2004-08-04 11:00:00 21,504 ----a-w C:\WINDOWS\system32\feclient.dll
+ 2008-04-14 00:11:53 21,504 ----a-w C:\WINDOWS\system32\feclient.dll
- 2004-08-04 11:00:00 337,920 ----a-w C:\WINDOWS\system32\filemgmt.dll
+ 2008-04-14 00:11:53 337,920 ----a-w C:\WINDOWS\system32\filemgmt.dll
- 2004-08-04 11:00:00 27,136 ----a-w C:\WINDOWS\system32\findstr.exe
+ 2008-04-14 00:12:20 27,136 ----a-w C:\WINDOWS\system32\findstr.exe
- 2004-08-04 11:00:00 87,552 ----a-w C:\WINDOWS\system32\fldrclnr.dll
+ 2008-04-14 00:11:53 87,552 ----a-w C:\WINDOWS\system32\fldrclnr.dll
- 2006-08-21 12:21:06 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll
+ 2008-04-14 00:11:53 16,896 ----a-w C:\WINDOWS\system32\fltlib.dll
- 2006-08-21 09:14:58 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe
+ 2008-04-14 00:12:20 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe
- 2008-08-30 20:47:36 192,184 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-10 15:27:15 193,776 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2004-08-04 11:00:00 382,976 ----a-w C:\WINDOWS\system32\fontext.dll
+ 2008-04-14 00:11:53 382,976 ----a-w C:\WINDOWS\system32\fontext.dll
- 2005-10-17 21:14:45 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll
+ 2008-04-14 00:11:53 80,896 ----a-w C:\WINDOWS\system32\fontsub.dll
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\fontview.exe
+ 2008-04-14 00:12:20 20,992 ----a-w C:\WINDOWS\system32\fontview.exe
- 2004-08-04 11:00:00 7,168 ----a-w C:\WINDOWS\system32\forcedos.exe
+ 2008-04-14 00:12:20 7,680 ----a-w C:\WINDOWS\system32\forcedos.exe
- 2004-08-04 11:00:00 25,600 -c--a-w C:\WINDOWS\system32\format.com
+ 2008-04-14 00:12:42 29,696 ----a-w C:\WINDOWS\system32\format.com
- 2004-08-04 11:00:00 9,344 -c--a-w C:\WINDOWS\system32\framebuf.dll
+ 2008-04-14 00:09:33 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
- 2004-08-04 11:00:00 193,024 ----a-w C:\WINDOWS\system32\fsquirt.exe
+ 2008-04-14 00:12:20 193,024 ----a-w C:\WINDOWS\system32\fsquirt.exe
- 2004-08-04 11:00:00 42,496 ----a-w C:\WINDOWS\system32\ftp.exe
+ 2008-04-14 00:12:20 42,496 ----a-w C:\WINDOWS\system32\ftp.exe
- 2004-08-04 11:00:00 60,416 -c--a-w C:\WINDOWS\system32\fwcfg.dll
+ 2008-04-14 00:11:53 60,416 ----a-w C:\WINDOWS\system32\fwcfg.dll
- 2004-08-04 11:00:00 452,096 ----a-w C:\WINDOWS\system32\fxsapi.dll
+ 2008-04-14 00:11:53 451,584 ----a-w C:\WINDOWS\system32\fxsapi.dll
- 2004-08-04 11:00:00 143,360 ----a-w C:\WINDOWS\system32\fxsclnt.exe
+ 2008-04-14 00:12:21 142,848 ----a-w C:\WINDOWS\system32\fxsclnt.exe
- 2004-08-04 11:00:00 72,192 ----a-w C:\WINDOWS\system32\fxscom.dll
+ 2008-04-14 00:11:54 72,192 ----a-w C:\WINDOWS\system32\fxscom.dll
- 2004-08-04 11:00:00 285,184 -c--a-w C:\WINDOWS\system32\fxscomex.dll
+ 2008-04-14 00:11:54 285,184 ----a-w C:\WINDOWS\system32\fxscomex.dll
- 2004-08-04 11:00:00 229,376 ----a-w C:\WINDOWS\system32\fxscover.exe
+ 2008-04-14 00:12:21 229,376 ----a-w C:\WINDOWS\system32\fxscover.exe
- 2004-08-04 11:00:00 27,136 -c--a-w C:\WINDOWS\system32\fxsdrv.dll
+ 2008-04-14 00:11:54 26,624 ----a-w C:\WINDOWS\system32\fxsdrv.dll
- 2004-08-04 11:00:00 55,296 ----a-w C:\WINDOWS\system32\fxsevent.dll
+ 2008-04-14 00:11:54 55,296 ----a-w C:\WINDOWS\system32\fxsevent.dll
- 2004-08-04 11:00:00 23,552 -c--a-w C:\WINDOWS\system32\fxsext32.dll
+ 2008-04-14 00:11:54 23,552 ----a-w C:\WINDOWS\system32\fxsext32.dll
- 2004-08-04 11:00:00 23,552 ----a-w C:\WINDOWS\system32\fxsmon.dll
+ 2008-04-14 00:11:54 23,552 ----a-w C:\WINDOWS\system32\fxsmon.dll
- 2004-08-04 11:00:00 8,704 -c--a-w C:\WINDOWS\system32\fxsperf.dll
+ 2008-04-14 00:11:54 8,704 ----a-w C:\WINDOWS\system32\fxsperf.dll
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\system32\fxsres.dll
+ 2008-04-14 00:09:33 6,656 ----a-w C:\WINDOWS\system32\fxsres.dll
- 2004-08-04 11:00:00 562,176 ----a-w C:\WINDOWS\system32\fxsst.dll
+ 2008-04-14 00:11:54 562,176 ----a-w C:\WINDOWS\system32\fxsst.dll
- 2004-08-04 11:00:00 267,776 ----a-w C:\WINDOWS\system32\fxssvc.exe
+ 2008-04-14 00:12:21 267,776 ----a-w C:\WINDOWS\system32\fxssvc.exe
- 2004-08-04 11:00:00 246,272 ----a-w C:\WINDOWS\system32\fxst30.dll
+ 2008-04-14 00:11:54 246,272 ----a-w C:\WINDOWS\system32\fxst30.dll
- 2004-08-04 11:00:00 397,312 ----a-w C:\WINDOWS\system32\fxstiff.dll
+ 2008-04-14 00:11:54 397,312 ----a-w C:\WINDOWS\system32\fxstiff.dll
- 2004-08-04 11:00:00 154,112 -c--a-w C:\WINDOWS\system32\fxsui.dll
+ 2008-04-14 00:11:54 154,112 ----a-w C:\WINDOWS\system32\fxsui.dll
- 2004-08-04 11:00:00 192,512 -c--a-w C:\WINDOWS\system32\fxswzrd.dll
+ 2008-04-14 00:11:54 192,512 ----a-w C:\WINDOWS\system32\fxswzrd.dll
- 2004-08-04 11:00:00 400,384 ----a-w C:\WINDOWS\system32\fxsxp32.dll
+ 2008-04-14 00:11:54 400,384 ----a-w C:\WINDOWS\system32\fxsxp32.dll
- 2008-02-20 06:51:05 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
+ 2008-04-14 00:11:54 285,184 ----a-w C:\WINDOWS\system32\gdi32.dll
- 2004-08-04 11:00:00 122,880 ----a-w C:\WINDOWS\system32\glu32.dll
+ 2008-04-14 00:11:54 122,880 ----a-w C:\WINDOWS\system32\glu32.dll
- 2004-08-04 11:00:00 9,728 -c--a-w C:\WINDOWS\system32\gpkrsrc.dll
+ 2006-12-31 01:26:44 9,728 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
- 2004-08-04 11:00:00 39,424 ----a-w C:\WINDOWS\system32\grpconv.exe
+ 2008-04-14 00:12:21 39,424 ----a-w C:\WINDOWS\system32\grpconv.exe
- 2004-08-04 11:00:00 614,912 -c--a-w C:\WINDOWS\system32\h323msp.dll
+ 2008-04-14 00:11:54 614,912 ----a-w C:\WINDOWS\system32\h323msp.dll
- 2004-08-04 11:00:00 131,968 ----a-w C:\WINDOWS\system32\hal.dll
+ 2008-04-13 18:31:28 131,840 ----a-w C:\WINDOWS\system32\HAL.DLL
- 2004-08-04 11:00:00 7,168 -c--a-w C:\WINDOWS\system32\hccoin.dll
+ 2008-04-14 00:11:54 7,168 ----a-w C:\WINDOWS\system32\hccoin.dll
- 2004-08-04 11:00:00 14,848 ----a-w C:\WINDOWS\system32\help.exe
+ 2008-04-14 00:12:21 15,872 ----a-w C:\WINDOWS\system32\help.exe
- 2005-05-27 02:04:27 41,472 ----a-w C:\WINDOWS\system32\hhsetup.dll
+ 2008-04-14 00:11:54 41,472 ----a-w C:\WINDOWS\system32\hhsetup.dll
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\hid.dll
+ 2008-04-14 00:11:54 20,992 ----a-w C:\WINDOWS\system32\hid.dll
- 2006-07-21 08:24:43 72,704 ----a-w C:\WINDOWS\system32\hlink.dll
+ 2008-04-14 00:11:54 72,704 ----a-w C:\WINDOWS\system32\hlink.dll
- 2004-08-04 11:00:00 344,064 ----a-w C:\WINDOWS\system32\hnetcfg.dll
+ 2008-04-14 00:11:54 344,064 ----a-w C:\WINDOWS\system32\hnetcfg.dll
- 2004-08-04 11:00:00 330,752 ----a-w C:\WINDOWS\system32\hnetwiz.dll
+ 2008-04-14 00:11:54 330,752 ----a-w C:\WINDOWS\system32\hnetwiz.dll
- 2004-08-04 11:00:00 144,896 -c--a-w C:\WINDOWS\system32\hotplug.dll
+ 2008-04-14 00:11:54 144,896 ----a-w C:\WINDOWS\system32\hotplug.dll
+ 2008-04-14 00:11:54 32,285 ------w C:\WINDOWS\system32\hsfcisp2.dll
- 2004-08-04 11:00:00 24,576 ----a-w C:\WINDOWS\system32\httpapi.dll
+ 2008-04-14 00:11:54 24,576 ----a-w C:\WINDOWS\system32\httpapi.dll
- 2004-08-04 11:00:00 41,984 ----a-w C:\WINDOWS\system32\htui.dll
+ 2008-04-14 00:11:54 41,984 ----a-w C:\WINDOWS\system32\htui.dll
- 2004-11-17 17:41:24 347,136 ----a-w C:\WINDOWS\system32\hypertrm.dll
+ 2008-04-14 00:11:54 347,136 ----a-w C:\WINDOWS\system32\hypertrm.dll
- 2004-08-04 11:00:00 119,808 ----a-w C:\WINDOWS\system32\iasrad.dll
+ 2008-04-14 00:11:54 119,808 ----a-w C:\WINDOWS\system32\iasrad.dll
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\icaapi.dll
+ 2008-04-14 00:11:54 11,264 ----a-w C:\WINDOWS\system32\icaapi.dll
- 2004-08-04 11:00:00 80,384 ----a-w C:\WINDOWS\system32\iccvid.dll
+ 2008-04-14 00:11:54 80,384 ----a-w C:\WINDOWS\system32\iccvid.dll
- 2005-06-29 01:46:00 254,976 ----a-w C:\WINDOWS\system32\icm32.dll
+ 2008-04-14 00:11:54 254,976 ----a-w C:\WINDOWS\system32\icm32.dll
- 2004-08-04 11:00:00 3,584 ----a-w C:\WINDOWS\system32\icmp.dll
+ 2008-04-14 00:09:40 3,584 ----a-w C:\WINDOWS\system32\icmp.dll
- 2004-08-04 11:00:00 73,728 ----a-w C:\WINDOWS\system32\icwdial.dll
+ 2008-04-14 00:11:54 73,728 ----a-w C:\WINDOWS\system32\icwdial.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\icwphbk.dll
+ 2008-04-14 00:11:54 65,536 ----a-w C:\WINDOWS\system32\icwphbk.dll
- 2004-08-04 11:00:00 120,832 -c--a-w C:\WINDOWS\system32\idq.dll
+ 2008-04-14 00:11:54 120,832 ----a-w C:\WINDOWS\system32\idq.dll
- 2006-10-17 20:06:00 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
+ 2008-04-14 00:11:54 81,920 ----a-w C:\WINDOWS\system32\ieencode.dll
- 2004-08-04 11:00:00 114,688 ----a-w C:\WINDOWS\system32\iexpress.exe
+ 2008-04-14 00:12:22 114,688 ----a-w C:\WINDOWS\system32\iexpress.exe
- 2004-08-04 11:00:00 135,680 ----a-w C:\WINDOWS\system32\ifmon.dll
+ 2008-04-14 00:11:54 135,680 ----a-w C:\WINDOWS\system32\ifmon.dll
- 2004-08-04 11:00:00 8,192 -c--a-w C:\WINDOWS\system32\igmpagnt.dll
+ 2008-04-14 00:11:54 8,192 ----a-w C:\WINDOWS\system32\igmpagnt.dll
- 2004-08-04 11:00:00 81,920 ----a-w C:\WINDOWS\system32\ils.dll
+ 2008-04-14 00:11:54 81,920 ----a-w C:\WINDOWS\system32\ils.dll
- 2004-08-04 11:00:00 144,384 ----a-w C:\WINDOWS\system32\imagehlp.dll
+ 2008-04-14 00:11:54 144,384 ----a-w C:\WINDOWS\system32\imagehlp.dll
- 2004-08-04 11:00:00 150,016 ----a-w C:\WINDOWS\system32\imapi.exe
+ 2008-04-14 00:12:22 150,528 ----a-w C:\WINDOWS\system32\imapi.exe
- 2004-08-04 11:00:00 36,921 -c--a-w C:\WINDOWS\system32\imeshare.dll
+ 2008-04-14 00:11:54 36,921 ----a-w C:\WINDOWS\system32\imeshare.dll
- 2004-08-04 11:00:00 110,080 ----a-w C:\WINDOWS\system32\imm32.dll
+ 2008-04-14 00:11:54 110,080 ----a-w C:\WINDOWS\system32\imm32.dll
- 2004-08-04 11:00:00 274,432 ----a-w C:\WINDOWS\system32\inetcfg.dll
+ 2008-04-14 00:11:54 274,432 ----a-w C:\WINDOWS\system32\inetcfg.dll
- 2008-04-11 18:50:43 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2004-08-04 11:00:00 33,280 ----a-w C:\WINDOWS\system32\inetmib1.dll
+ 2008-04-14 00:11:55 32,768 ----a-w C:\WINDOWS\system32\inetmib1.dll
- 2004-08-04 11:00:00 75,264 ----a-w C:\WINDOWS\system32\inetpp.dll
+ 2008-04-14 00:11:55 75,264 ----a-w C:\WINDOWS\system32\inetpp.dll
- 2004-08-04 11:00:00 15,872 -c--a-w C:\WINDOWS\system32\inetppui.dll
+ 2008-04-14 00:11:55 15,872 ----a-w C:\WINDOWS\system32\inetppui.dll
- 2004-08-04 11:00:00 48,128 -c--a-w C:\WINDOWS\system32\inetres.dll
+ 2008-04-13 16:22:12 48,128 ----a-w C:\WINDOWS\system32\inetres.dll
- 2004-08-04 11:00:00 147,456 -c--a-w C:\WINDOWS\system32\initpki.dll
+ 2008-04-14 00:11:55 147,456 ----a-w C:\WINDOWS\system32\initpki.dll
- 2004-08-04 11:00:00 123,392 -c--a-w C:\WINDOWS\system32\input.dll
+ 2008-04-14 00:11:55 123,392 ----a-w C:\WINDOWS\system32\input.dll
- 2004-08-04 11:00:00 55,808 ----a-w C:\WINDOWS\system32\ipconfig.exe
+ 2008-04-14 00:12:22 55,808 ----a-w C:\WINDOWS\system32\ipconfig.exe
- 2006-05-19 12:59:41 94,720 ----a-w C:\WINDOWS\system32\iphlpapi.dll
+ 2008-04-14 00:11:55 94,720 ----a-w C:\WINDOWS\system32\iphlpapi.dll
- 2004-08-04 11:00:00 154,112 -c--a-w C:\WINDOWS\system32\ipmontr.dll
+ 2008-04-14 00:11:55 161,280 ----a-w C:\WINDOWS\system32\ipmontr.dll
- 2004-08-04 11:00:00 331,264 ----a-w C:\WINDOWS\system32\ipnathlp.dll
+ 2008-04-14 00:11:55 331,264 ----a-w C:\WINDOWS\system32\ipnathlp.dll
- 2004-08-04 11:00:00 330,752 -c--a-w C:\WINDOWS\system32\ippromon.dll
+ 2008-04-14 00:11:55 330,752 ----a-w C:\WINDOWS\system32\ippromon.dll
- 2004-08-04 11:00:00 169,984 -c--a-w C:\WINDOWS\system32\iprtrmgr.dll
+ 2008-04-14 00:11:55 177,152 ----a-w C:\WINDOWS\system32\iprtrmgr.dll
- 2004-08-04 11:00:00 349,696 -c--a-w C:\WINDOWS\system32\ipsecsnp.dll
+ 2008-04-14 00:11:55 349,696 ----a-w C:\WINDOWS\system32\ipsecsnp.dll
- 2004-08-04 11:00:00 182,784 ----a-w C:\WINDOWS\system32\ipsecsvc.dll
+ 2008-04-14 00:11:55 183,808 ----a-w C:\WINDOWS\system32\ipsecsvc.dll
- 2004-08-04 11:00:00 384,000 -c--a-w C:\WINDOWS\system32\ipsmsnap.dll
+ 2008-04-14 00:11:55 384,000 ----a-w C:\WINDOWS\system32\ipsmsnap.dll
- 2004-08-04 11:00:00 53,248 ----a-w C:\WINDOWS\system32\ipv6.exe
+ 2008-04-14 00:12:23 53,248 ----a-w C:\WINDOWS\system32\ipv6.exe
- 2004-08-04 11:00:00 59,904 -c--a-w C:\WINDOWS\system32\ipv6mon.dll
+ 2008-04-14 00:11:55 59,904 ----a-w C:\WINDOWS\system32\ipv6mon.dll
- 2004-08-04 11:00:00 23,552 ----a-w C:\WINDOWS\system32\ipxroute.exe
+ 2008-04-14 00:12:23 23,552 ----a-w C:\WINDOWS\system32\ipxroute.exe
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\system32\ipxwan.dll
+ 2008-04-14 00:11:55 22,016 ----a-w C:\WINDOWS\system32\ipxwan.dll
- 2004-08-04 11:00:00 120,320 -c--a-w C:\WINDOWS\system32\ir41_qc.dll
+ 2008-04-14 00:11:55 120,320 ----a-w C:\WINDOWS\system32\ir41_qc.dll
- 2004-08-04 11:00:00 338,432 -c--a-w C:\WINDOWS\system32\ir41_qcx.dll
+ 2008-04-14 00:11:55 338,432 ----a-w C:\WINDOWS\system32\ir41_qcx.dll
- 2004-08-04 11:00:00 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll
+ 2008-04-14 00:11:55 755,200 ----a-w C:\WINDOWS\system32\ir50_32.dll
- 2004-08-04 11:00:00 200,192 -c--a-w C:\WINDOWS\system32\ir50_qc.dll
+ 2008-04-14 00:11:55 200,192 ----a-w C:\WINDOWS\system32\ir50_qc.dll
- 2004-08-04 11:00:00 183,808 -c--a-w C:\WINDOWS\system32\ir50_qcx.dll
+ 2008-04-14 00:11:55 183,808 ----a-w C:\WINDOWS\system32\ir50_qcx.dll
- 2004-08-04 11:00:00 81,920 ----a-w C:\WINDOWS\system32\isign32.dll
+ 2008-04-14 00:11:55 81,920 ----a-w C:\WINDOWS\system32\isign32.dll
- 2004-08-04 11:00:00 32,768 -c--a-w C:\WINDOWS\system32\isrdbg32.dll
+ 2008-04-14 00:11:55 32,768 ----a-w C:\WINDOWS\system32\isrdbg32.dll
- 2005-05-27 02:04:27 155,136 ----a-w C:\WINDOWS\system32\itircl.dll
+ 2008-04-14 00:11:55 155,136 ----a-w C:\WINDOWS\system32\itircl.dll
- 2005-05-27 02:04:27 137,216 ----a-w C:\WINDOWS\system32\itss.dll
+ 2008-04-14 00:11:55 138,240 ----a-w C:\WINDOWS\system32\itss.dll
- 2004-08-04 11:00:00 54,272 -c--a-w C:\WINDOWS\system32\ixsso.dll
+ 2008-04-14 00:11:55 54,272 ----a-w C:\WINDOWS\system32\ixsso.dll
- 2004-08-04 11:00:00 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
+ 2008-04-14 00:11:55 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
- 2006-06-01 18:47:07 163,840 ----a-w C:\WINDOWS\system32\jgdw400.dll
+ 2008-04-14 00:11:55 163,840 ----a-w C:\WINDOWS\system32\jgdw400.dll
- 2006-06-01 18:47:07 27,648 ----a-w C:\WINDOWS\system32\jgpl400.dll
+ 2008-04-14 00:11:55 27,648 ----a-w C:\WINDOWS\system32\jgpl400.dll
- 2006-10-17 20:00:00 491,520 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2008-05-09 10:53:39 512,000 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\system32\kbdbhc.dll
- 2004-08-04 11:00:00 7,168 -c--a-w C:\WINDOWS\system32\kbdfi1.dll
+ 2008-04-14 00:09:55 7,168 ----a-w C:\WINDOWS\system32\kbdfi1.dll
- 2004-08-04 11:00:00 6,144 -c--a-w C:\WINDOWS\system32\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 ----a-w C:\WINDOWS\system32\kbdinbe1.dll
- 2004-08-04 11:00:00 6,656 -c--a-w C:\WINDOWS\system32\kbdinben.dll
+ 2008-04-14 00:09:55 6,144 ----a-w C:\WINDOWS\system32\kbdinben.dll
- 2004-08-04 11:00:00 6,656 -c--a-w C:\WINDOWS\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,656 ----a-w C:\WINDOWS\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\system32\kbdiultn.dll
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\system32\kbdmaori.dll
+ 2008-04-14 00:09:55 5,632 ----a-w C:\WINDOWS\system32\kbdmaori.dll
- 2004-08-04 11:00:00 6,144 -c--a-w C:\WINDOWS\system32\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 ----a-w C:\WINDOWS\system32\kbdmlt47.dll
- 2004-08-04 11:00:00 6,144 ----a-w C:\WINDOWS\system32\kbdmlt48.dll
+ 2008-04-14 00:09:55 6,144 ----a-w C:\WINDOWS\system32\kbdmlt48.dll
- 2004-08-04 11:00:00 7,168 -c--a-w C:\WINDOWS\system32\kbdnec.dll
+ 2008-04-14 00:09:55 7,168 ----a-w C:\WINDOWS\system32\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\system32\kbdnepr.dll
- 2004-08-04 11:00:00 7,168 -c--a-w C:\WINDOWS\system32\kbdno1.dll
+ 2008-04-14 00:09:55 7,168 ----a-w C:\WINDOWS\system32\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 ------w C:\WINDOWS\system32\kbdpash.dll
- 2004-08-04 11:00:00 7,680 -c--a-w C:\WINDOWS\system32\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 ----a-w C:\WINDOWS\system32\kbdsmsfi.dll
- 2004-08-04 11:00:00 7,680 -c--a-w C:\WINDOWS\system32\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,680 ----a-w C:\WINDOWS\system32\kbdsmsno.dll
- 2004-08-04 11:00:00 7,168 -c--a-w C:\WINDOWS\system32\kbdukx.dll
+ 2008-04-14 00:09:55 7,168 ----a-w C:\WINDOWS\system32\kbdukx.dll
- 2004-08-04 11:00:00 7,424 -c--a-w C:\WINDOWS\system32\kd1394.dll
+ 2008-04-13 18:31:35 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
- 2005-06-15 17:49:30 295,936 ----a-w C:\WINDOWS\system32\kerberos.dll
+ 2008-04-14 00:11:56 299,520 ----a-w C:\WINDOWS\system32\kerberos.dll
- 2007-04-16 15:52:53 984,576 ----a-w C:\WINDOWS\system32\kernel32.dll
+ 2008-04-14 00:11:56 989,696 ----a-w C:\WINDOWS\system32\kernel32.dll
- 2004-08-04 11:00:00 150,528 -c--a-w C:\WINDOWS\system32\keymgr.dll
+ 2008-04-14 00:11:56 150,528 ----a-w C:\WINDOWS\system32\keymgr.dll
+ 2008-04-14 00:11:56 61,440 ------w C:\WINDOWS\system32\kmsvc.dll
- 2004-08-04 06:56:44 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2008-04-14 00:11:56 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2008-04-14 00:11:56 37,376 ------w C:\WINDOWS\system32\l2gpstore.dll
- 2004-08-04 11:00:00 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
+ 2008-04-14 12:41:58 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
- 2004-08-04 11:00:00 58,880 -c--a-w C:\WINDOWS\system32\licwmi.dll
+ 2008-04-14 00:11:56 58,880 ----a-w C:\WINDOWS\system32\licwmi.dll
- 2005-09-01 01:41:53 19,968 ----a-w C:\WINDOWS\system32\linkinfo.dll
+ 2008-04-14 00:11:56 19,968 ----a-w C:\WINDOWS\system32\linkinfo.dll
- 2004-08-04 11:00:00 13,824 ----a-w C:\WINDOWS\system32\lmhsvc.dll
+ 2008-04-14 00:11:56 13,824 ----a-w C:\WINDOWS\system32\lmhsvc.dll
- 2004-08-04 11:00:00 399,872 -c--a-w C:\WINDOWS\system32\lmrt.dll
+ 2008-04-14 00:11:56 399,872 ----a-w C:\WINDOWS\system32\lmrt.dll
+ 2007-07-27 22:49:02 196,683 ----a-w C:\WINDOWS\system32\lnod32apiA.dll
+ 2007-07-27 22:49:02 225,355 ----a-w C:\WINDOWS\system32\lnod32apiW.dll
+ 2005-12-06 03:25:22 139,264 ----a-w C:\WINDOWS\system32\lnod32umc.dll
+ 2005-12-05 20:37:10 106,496 ----a-w C:\WINDOWS\system32\lnod32upd.dll
- 2004-08-04 11:00:00 97,280 ----a-w C:\WINDOWS\system32\loadperf.dll
+ 2008-04-14 00:11:56 97,280 ----a-w C:\WINDOWS\system32\loadperf.dll
- 2004-08-04 11:00:00 221,696 ----a-w C:\WINDOWS\system32\localsec.dll
+ 2008-04-14 00:11:56 221,696 ----a-w C:\WINDOWS\system32\localsec.dll
- 2004-08-04 11:00:00 341,504 ----a-w C:\WINDOWS\system32\localspl.dll
+ 2008-04-14 00:11:56 343,040 ----a-w C:\WINDOWS\system32\localspl.dll
- 2004-08-04 11:00:00 11,776 -c--a-w C:\WINDOWS\system32\localui.dll
+ 2008-04-14 00:11:56 11,776 ----a-w C:\WINDOWS\system32\localui.dll
- 2004-08-04 11:00:00 75,264 ----a-w C:\WINDOWS\system32\locator.exe
+ 2008-04-14 00:12:24 75,264 ----a-w C:\WINDOWS\system32\locator.exe
- 2004-08-04 11:00:00 59,392 ----a-w C:\WINDOWS\system32\logman.exe
+ 2008-04-14 00:12:24 59,392 ----a-w C:\WINDOWS\system32\logman.exe
- 2004-08-04 11:00:00 220,672 ----a-w C:\WINDOWS\system32\logon.scr
+ 2008-04-14 00:12:43 220,672 ----a-w C:\WINDOWS\system32\logon.scr
- 2004-08-04 11:00:00 514,560 ----a-w C:\WINDOWS\system32\logonui.exe
+ 2008-04-14 00:12:24 514,560 ----a-w C:\WINDOWS\system32\logonui.exe
- 2004-08-04 11:00:00 22,016 -c--a-w C:\WINDOWS\system32\lpk.dll
+ 2008-04-14 00:11:56 22,016 ----a-w C:\WINDOWS\system32\lpk.dll
- 2004-08-04 11:00:00 10,240 ----a-w C:\WINDOWS\system32\lprhelp.dll
+ 2008-04-14 00:11:56 10,240 ----a-w C:\WINDOWS\system32\lprhelp.dll
- 2007-11-07 09:26:56 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
+ 2008-04-14 00:11:56 728,064 ----a-w C:\WINDOWS\system32\lsasrv.dll
- 2004-08-04 11:00:00 13,312 ----a-w C:\WINDOWS\system32\lsass.exe
+ 2008-04-14 00:12:24 13,312 ----a-w C:\WINDOWS\system32\lsass.exe
- 2004-08-04 11:00:00 72,704 ----a-w C:\WINDOWS\system32\magnify.exe
+ 2008-04-14 00:12:24 72,704 ----a-w C:\WINDOWS\system32\magnify.exe
- 2004-08-04 11:00:00 85,504 ----a-w C:\WINDOWS\system32\makecab.exe
+ 2008-04-14 00:12:25 57,344 ----a-w C:\WINDOWS\system32\makecab.exe
- 2004-08-04 11:00:00 14,848 -c--a-w C:\WINDOWS\system32\mcastmib.dll
+ 2008-04-14 00:11:56 14,336 ----a-w C:\WINDOWS\system32\mcastmib.dll
- 2004-08-04 11:00:00 84,480 ----a-w C:\WINDOWS\system32\mciavi32.dll
+ 2008-04-14 00:11:56 84,480 ----a-w C:\WINDOWS\system32\mciavi32.dll
- 2004-08-04 11:00:00 35,328 ----a-w C:\WINDOWS\system32\mciqtz32.dll
+ 2008-04-14 00:11:56 35,328 ----a-w C:\WINDOWS\system32\mciqtz32.dll
- 2004-08-04 11:00:00 23,040 ----a-w C:\WINDOWS\system32\mciseq.dll
+ 2008-04-14 00:11:56 23,040 ----a-w C:\WINDOWS\system32\mciseq.dll
- 2004-08-04 11:00:00 23,552 ----a-w C:\WINDOWS\system32\mciwave.dll
+ 2008-04-14 00:11:56 23,552 ----a-w C:\WINDOWS\system32\mciwave.dll
- 2004-08-04 11:00:00 118,272 ----a-w C:\WINDOWS\system32\mdminst.dll
+ 2008-04-14 00:11:56 118,272 ----a-w C:\WINDOWS\system32\mdminst.dll
+ 2008-04-14 00:11:56 86,016 ------w C:\WINDOWS\system32\mdmxsdk.dll
- 2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
+ 2008-04-14 00:11:56 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
- 2006-11-01 19:17:45 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll
+ 2008-04-14 00:11:56 927,504 ----a-w C:\WINDOWS\system32\mfc40u.dll
- 2004-08-04 11:00:00 1,028,096 ----a-w C:\WINDOWS\system32\mfc42.dll
+ 2008-04-14 00:11:56 1,028,096 ----a-w C:\WINDOWS\system32\mfc42.dll
- 2004-08-04 11:00:00 22,528 ----a-w C:\WINDOWS\system32\mfcsubs.dll
+ 2008-04-14 00:11:56 22,528 ----a-w C:\WINDOWS\system32\mfcsubs.dll
- 2004-08-04 11:00:00 14,848 -c--a-w C:\WINDOWS\system32\mgmtapi.dll
+ 2008-04-14 00:11:56 14,848 ----a-w C:\WINDOWS\system32\mgmtapi.dll
+ 2008-04-14 00:11:57 184,320 ------w C:\WINDOWS\system32\microsoft.managementconsole.dll
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\midimap.dll
+ 2008-04-14 00:11:57 18,944 ----a-w C:\WINDOWS\system32\midimap.dll
- 2004-08-04 11:00:00 60,928 -c--a-w C:\WINDOWS\system32\miglibnt.dll
+ 2008-04-14 00:11:57 60,928 ----a-w C:\WINDOWS\system32\miglibnt.dll
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\system32\mimefilt.dll
+ 2008-04-14 00:11:57 29,696 ----a-w C:\WINDOWS\system32\mimefilt.dll
- 2004-08-04 11:00:00 586,240 ----a-w C:\WINDOWS\system32\mlang.dll
+ 2008-04-14 00:11:57 586,240 ----a-w C:\WINDOWS\system32\mlang.dll
- 2004-08-04 11:00:00 815,104 ----a-w C:\WINDOWS\system32\mmc.exe
+ 2008-04-14 00:12:25 1,414,656 ----a-w C:\WINDOWS\system32\mmc.exe
- 2004-08-04 11:00:00 70,656 ----a-w C:\WINDOWS\system32\mmcbase.dll
+ 2008-04-14 00:11:57 163,328 ----a-w C:\WINDOWS\system32\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 ------w C:\WINDOWS\system32\mmcex.dll
+ 2008-04-14 00:11:57 106,496 ------w C:\WINDOWS\system32\mmcfxcommon.dll
- 2004-08-04 11:00:00 1,192,960 ----a-w C:\WINDOWS\system32\mmcndmgr.dll
+ 2008-04-14 00:11:57 1,872,896 ----a-w C:\WINDOWS\system32\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 ------w C:\WINDOWS\system32\mmcperf.exe
- 2004-08-04 11:00:00 50,688 ----a-w C:\WINDOWS\system32\mmcshext.dll
+ 2008-04-14 00:11:57 61,440 ----a-w C:\WINDOWS\system32\mmcshext.dll
- 2004-08-04 11:00:00 17,408 -c--a-w C:\WINDOWS\system32\mmfutil.dll
+ 2008-04-14 00:11:57 17,408 ----a-w C:\WINDOWS\system32\mmfutil.dll
- 2004-08-04 11:00:00 34,560 -c--a-w C:\WINDOWS\system32\mnmdd.dll
+ 2008-04-14 00:11:57 34,560 ----a-w C:\WINDOWS\system32\mnmdd.dll
- 2004-08-04 11:00:00 32,768 ----a-w C:\WINDOWS\system32\mnmsrvc.exe
+ 2008-04-14 00:12:25 32,768 ----a-w C:\WINDOWS\system32\mnmsrvc.exe
- 2004-08-04 11:00:00 207,360 -c--a-w C:\WINDOWS\system32\mobsync.dll
+ 2008-04-14 00:11:57 207,360 ----a-w C:\WINDOWS\system32\mobsync.dll
- 2004-08-04 11:00:00 143,360 ----a-w C:\WINDOWS\system32\mobsync.exe
+ 2008-04-14 00:12:26 143,360 ----a-w C:\WINDOWS\system32\mobsync.exe
- 2004-08-04 11:00:00 153,600 ----a-w C:\WINDOWS\system32\modemui.dll
+ 2008-04-14 00:11:57 153,600 ----a-w C:\WINDOWS\system32\modemui.dll
- 2004-08-04 11:00:00 15,872 -c--a-w C:\WINDOWS\system32\more.com
+ 2008-04-14 00:12:42 16,896 ----a-w C:\WINDOWS\system32\more.com
- 2004-08-04 11:00:00 216,064 -c--a-w C:\WINDOWS\system32\moricons.dll
+ 2008-04-13 16:45:30 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
- 2004-08-04 11:00:00 123,392 ----a-w C:\WINDOWS\system32\mplay32.exe
+ 2008-04-14 00:12:27 123,392 ----a-w C:\WINDOWS\system32\mplay32.exe
- 2004-08-04 11:00:00 59,904 ----a-w C:\WINDOWS\system32\mpr.dll
+ 2008-04-14 00:11:57 59,904 ----a-w C:\WINDOWS\system32\mpr.dll
- 2004-08-04 11:00:00 87,040 ----a-w C:\WINDOWS\system32\mprapi.dll
+ 2008-04-14 00:11:57 87,040 ----a-w C:\WINDOWS\system32\mprapi.dll
- 2004-08-04 11:00:00 49,152 -c--a-w C:\WINDOWS\system32\mprdim.dll
+ 2008-04-14 00:11:57 53,248 ----a-w C:\WINDOWS\system32\mprdim.dll
- 2004-08-04 11:00:00 71,680 ----a-w C:\WINDOWS\system32\msacm32.dll
+ 2008-04-14 00:11:58 71,680 ----a-w C:\WINDOWS\system32\msacm32.dll
- 2004-08-04 11:00:00 3,584 -c--a-w C:\WINDOWS\system32\msafd.dll
+ 2008-04-14 00:10:06 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
- 2004-08-04 11:00:00 86,016 ----a-w C:\WINDOWS\system32\msapsspc.dll
+ 2008-04-14 00:11:58 86,016 ----a-w C:\WINDOWS\system32\msapsspc.dll
- 2004-08-04 11:00:00 57,344 ----a-w C:\WINDOWS\system32\msasn1.dll
+ 2008-04-14 00:11:58 57,344 ----a-w C:\WINDOWS\system32\msasn1.dll
- 2008-06-24 16:23:05 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:43:16 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
- 2004-08-04 11:00:00 69,632 -c--a-w C:\WINDOWS\system32\msconf.dll
+ 2008-04-14 00:11:58 69,632 ----a-w C:\WINDOWS\system32\msconf.dll
- 2004-08-04 11:00:00 12,288 -c--a-w C:\WINDOWS\system32\mscpx32r.dLL
+ 2008-04-13 17:26:07 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
- 2004-08-04 11:00:00 36,864 ----a-w C:\WINDOWS\system32\mscpxl32.dLL
+ 2008-04-14 00:11:58 36,864 ----a-w C:\WINDOWS\system32\mscpxl32.dll
- 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
+ 2008-04-14 00:11:58 297,984 ----a-w C:\WINDOWS\system32\msctf.dll
- 2004-08-04 11:00:00 69,120 -c--a-w C:\WINDOWS\system32\MSCTFP.dll
+ 2008-04-14 00:11:58 68,608 ----a-w C:\WINDOWS\system32\msctfp.dll
- 2004-08-04 11:00:00 118,784 ----a-w C:\WINDOWS\system32\msdadiag.dll
+ 2008-04-14 00:11:58 118,784 ----a-w C:\WINDOWS\system32\msdadiag.dll
- 2004-08-04 11:00:00 151,552 ----a-w C:\WINDOWS\system32\msdart.dll
+ 2008-04-14 00:11:59 151,552 ----a-w C:\WINDOWS\system32\msdart.dll
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\msdmo.dll
+ 2008-04-14 00:11:59 14,336 ----a-w C:\WINDOWS\system32\msdmo.dll
- 2004-08-04 11:00:00 6,144 ----a-w C:\WINDOWS\system32\msdtc.exe
+ 2008-04-14 00:12:27 6,144 ----a-w C:\WINDOWS\system32\msdtc.exe
- 2004-08-04 11:00:00 58,880 -c--a-w C:\WINDOWS\system32\msdtclog.dll
+ 2008-04-14 00:11:59 58,880 ----a-w C:\WINDOWS\system32\msdtclog.dll
- 2006-03-01 19:42:42 426,496 ----a-w C:\WINDOWS\system32\msdtcprx.dll
+ 2008-04-14 00:11:59 427,008 ----a-w C:\WINDOWS\system32\msdtcprx.dll
- 2006-03-01 19:42:42 956,416 ----a-w C:\WINDOWS\system32\msdtctm.dll
+ 2008-04-14 00:11:59 956,928 ----a-w C:\WINDOWS\system32\msdtctm.dll
- 2006-03-01 19:42:42 161,280 ----a-w C:\WINDOWS\system32\msdtcuiu.dll
+ 2008-04-14 00:11:59 161,792 ----a-w C:\WINDOWS\system32\msdtcuiu.dll
- 2004-08-04 11:00:00 4,126 -c--a-w C:\WINDOWS\system32\msdxmlc.dll
+ 2008-04-14 00:10:08 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
- 2006-11-27 14:54:06 539,136 ----a-w C:\WINDOWS\system32\msftedit.dll
+ 2008-04-14 00:11:59 539,136 ----a-w C:\WINDOWS\system32\msftedit.dll
- 2004-08-04 11:00:00 994,304 ----a-w C:\WINDOWS\system32\msgina.dll
+ 2008-04-14 00:11:59 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
- 2004-08-04 11:00:00 33,792 -c--a-w C:\WINDOWS\system32\msgsvc.dll
+ 2008-04-14 00:11:59 33,792 ----a-w C:\WINDOWS\system32\msgsvc.dll
- 2004-08-04 11:00:00 188,416 ----a-w C:\WINDOWS\system32\msh261.drv
+ 2008-04-14 00:12:45 188,416 ----a-w C:\WINDOWS\system32\msh261.drv
- 2004-08-04 11:00:00 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
+ 2008-04-14 00:12:45 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
- 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
+ 2008-04-14 00:11:59 2,843,136 ----a-w C:\WINDOWS\system32\msi.dll
- 2004-08-04 11:00:00 51,712 -c--a-w C:\WINDOWS\system32\msident.dll
+ 2008-04-14 00:11:59 51,712 ----a-w C:\WINDOWS\system32\msident.dll
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\system32\msidle.dll
+ 2008-04-14 00:11:59 6,656 ----a-w C:\WINDOWS\system32\msidle.dll
- 2004-08-04 11:00:00 248,832 -c--a-w C:\WINDOWS\system32\msieftp.dll
+ 2008-04-14 00:11:59 248,832 ----a-w C:\WINDOWS\system32\msieftp.dll
- 2005-03-21 22:00:22 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe
+ 2008-04-14 00:12:28 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe
- 2005-03-21 22:00:22 271,360 ----a-w C:\WINDOWS\system32\msihnd.dll
+ 2008-04-14 00:11:59 271,360 ----a-w C:\WINDOWS\system32\msihnd.dll
- 2004-08-04 11:00:00 4,608 ----a-w C:\WINDOWS\system32\msimg32.dll
+ 2008-04-14 00:11:59 4,608 ----a-w C:\WINDOWS\system32\msimg32.dll
- 2005-03-21 22:00:22 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
+ 2008-04-13 15:39:43 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
- 2004-08-04 11:00:00 159,232 ----a-w C:\WINDOWS\system32\MSIMTF.dll
+ 2008-04-14 00:11:59 159,232 ----a-w C:\WINDOWS\system32\msimtf.dll
- 2005-03-21 22:00:22 15,360 ----a-w C:\WINDOWS\system32\msisip.dll
+ 2008-04-14 00:11:59 15,360 ----a-w C:\WINDOWS\system32\msisip.dll
- 2008-03-27 08:12:54 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
+ 2008-04-14 00:12:00 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
- 2004-08-04 11:00:00 25,088 -c--a-w C:\WINDOWS\system32\mslbui.dll
+ 2008-04-14 00:12:00 25,088 ----a-w C:\WINDOWS\system32\mslbui.dll
- 2004-08-04 11:00:00 290,816 -c--a-w C:\WINDOWS\system32\msnsspc.dll
+ 2008-04-14 00:12:00 290,816 ----a-w C:\WINDOWS\system32\msnsspc.dll
- 2004-08-04 11:00:00 252,928 ----a-w C:\WINDOWS\system32\msoeacct.dll
+ 2008-04-14 00:12:00 252,928 ----a-w C:\WINDOWS\system32\msoeacct.dll
- 2004-08-04 11:00:00 105,984 ----a-w C:\WINDOWS\system32\msoert2.dll
+ 2008-04-14 00:12:00 105,984 ----a-w C:\WINDOWS\system32\msoert2.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\system32\msorc32r.dll
+ 2008-04-13 17:24:14 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
- 2004-08-04 11:00:00 143,360 -c--a-w C:\WINDOWS\system32\msorcl32.dll
+ 2008-04-14 00:12:00 143,360 ----a-w C:\WINDOWS\system32\msorcl32.dll
- 2004-08-04 11:00:00 343,040 ----a-w C:\WINDOWS\system32\mspaint.exe
+ 2008-04-14 00:12:28 343,040 ----a-w C:\WINDOWS\system32\mspaint.exe
- 2004-08-04 11:00:00 30,208 ----a-w C:\WINDOWS\system32\mspatcha.dll
+ 2008-04-14 00:12:00 29,696 ----a-w C:\WINDOWS\system32\mspatcha.dll
- 2004-08-04 11:00:00 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
+ 2008-04-13 16:23:31 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\system32\msrle32.dll
+ 2008-04-14 00:12:00 11,264 ----a-w C:\WINDOWS\system32\msrle32.dll
- 2004-08-04 11:00:00 134,656 ----a-w C:\WINDOWS\system32\mssap.dll
+ 2008-04-14 00:12:00 134,656 ----a-w C:\WINDOWS\system32\mssap.dll
+ 2008-04-14 00:12:00 155,136 ------w C:\WINDOWS\system32\mssha.dll
+ 2008-04-13 18:14:58 76,800 ------w C:\WINDOWS\system32\msshavmsg.dll
- 2004-08-04 11:00:00 274,944 ----a-w C:\WINDOWS\system32\mstask.dll
+ 2008-04-14 00:12:00 274,944 ----a-w C:\WINDOWS\system32\mstask.dll
- 2004-08-04 11:00:00 12,288 ----a-w C:\WINDOWS\system32\mstinit.exe
+ 2008-04-14 00:12:29 12,288 ----a-w C:\WINDOWS\system32\mstinit.exe
- 2004-08-04 11:00:00 115,712 ----a-w C:\WINDOWS\system32\mstlsapi.dll
+ 2008-04-14 00:12:00 116,224 ----a-w C:\WINDOWS\system32\mstlsapi.dll
- 2004-08-04 11:00:00 407,552 ----a-w C:\WINDOWS\system32\mstsc.exe
+ 2008-04-14 00:12:23 677,888 ----a-w C:\WINDOWS\system32\mstsc.exe
- 2004-08-04 11:00:00 655,360 -c--a-w C:\WINDOWS\system32\mstscax.dll
+ 2008-04-14 00:11:56 2,061,824 ----a-w C:\WINDOWS\system32\mstscax.dll
- 2004-08-04 11:00:00 195,072 -c--a-w C:\WINDOWS\system32\msutb.dll
+ 2008-04-14 00:12:00 195,072 ----a-w C:\WINDOWS\system32\msutb.dll
- 2004-08-04 11:00:00 129,536 ----a-w C:\WINDOWS\system32\msv1_0.dll
+ 2008-04-14 00:12:00 132,608 ----a-w C:\WINDOWS\system32\msv1_0.dll
- 2005-09-06 22:14:10 1,386,496 ----a-w C:\WINDOWS\system32\msvbvm60.dll
+ 2008-04-14 00:12:00 1,384,479 ----a-w C:\WINDOWS\system32\msvbvm60.dll
- 2004-08-04 11:00:00 54,784 ----a-w C:\WINDOWS\system32\msvcirt.dll
+ 2008-04-14 00:12:01 57,344 ----a-w C:\WINDOWS\system32\msvcirt.dll
- 2004-08-04 11:00:00 413,696 ----a-w C:\WINDOWS\system32\msvcp60.dll
+ 2008-04-14 00:12:01 413,696 ----a-w C:\WINDOWS\system32\msvcp60.dll
- 2004-08-04 11:00:00 343,040 ----a-w C:\WINDOWS\system32\msvcrt.dll
+ 2008-04-14 00:12:01 343,040 ----a-w C:\WINDOWS\system32\msvcrt.dll
- 2004-08-04 11:00:00 61,440 ------w C:\WINDOWS\system32\msvcrt40.dll
+ 2008-04-13 18:30:46 61,440 ------w C:\WINDOWS\system32\msvcrt40.dll
- 2004-08-04 11:00:00 120,832 ----a-w C:\WINDOWS\system32\msvfw32.dll
+ 2008-04-14 00:12:01 121,344 ----a-w C:\WINDOWS\system32\msvfw32.dll
- 2004-08-04 11:00:00 1,428,480 -c--a-w C:\WINDOWS\system32\msvidctl.dll
+ 2008-04-14 00:12:01 1,428,992 ----a-w C:\WINDOWS\system32\msvidctl.dll
- 2004-08-04 11:00:00 72,704 ----a-w C:\WINDOWS\system32\msw3prt.dll
+ 2008-04-14 00:12:01 72,704 ----a-w C:\WINDOWS\system32\msw3prt.dll
- 2004-08-04 11:00:00 204,288 -c--a-w C:\WINDOWS\system32\mswebdvd.dll
+ 2008-04-14 00:12:01 203,776 ----a-w C:\WINDOWS\system32\mswebdvd.dll
- 2008-06-20 17:41:10 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
+ 2008-06-20 17:46:57 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
- 2004-08-04 11:00:00 506,368 -c--a-w C:\WINDOWS\system32\msxml.dll
+ 2008-04-14 00:12:01 506,368 ----a-w C:\WINDOWS\system32\msxml.dll
- 2004-08-04 11:00:00 701,440 -c--a-w C:\WINDOWS\system32\msxml2.dll
+ 2008-04-14 00:12:01 701,440 ----a-w C:\WINDOWS\system32\msxml2.dll
- 2007-06-26 06:08:16 1,104,896 ----a-w C:\WINDOWS\system32\msxml3.dll
+ 2008-04-14 00:12:01 1,104,896 ----a-w C:\WINDOWS\system32\msxml3.dll
+ 2008-04-14 00:12:01 1,306,624 ------w C:\WINDOWS\system32\msxml6.dll
+ 2008-04-13 17:27:18 79,872 ------w C:\WINDOWS\system32\msxml6r.dll
- 2004-08-04 11:00:00 17,408 ----a-w C:\WINDOWS\system32\msyuv.dll
+ 2008-04-14 00:12:01 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
- 2006-03-01 19:42:42 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll
+ 2008-04-14 00:12:01 66,560 ----a-w C:\WINDOWS\system32\mtxclu.dll
- 2004-08-04 11:00:00 20,480 -c--a-w C:\WINDOWS\system32\mtxdm.dll
+ 2008-04-14 00:12:01 30,720 ----a-w C:\WINDOWS\system32\mtxdm.dll
- 2004-08-04 11:00:00 4,096 -c--a-w C:\WINDOWS\system32\mtxex.dll
+ 2008-04-14 00:12:01 4,096 ----a-w C:\WINDOWS\system32\mtxex.dll
- 2004-08-04 11:00:00 25,088 -c--a-w C:\WINDOWS\system32\mtxlegih.dll
+ 2008-04-14 00:12:01 34,304 ----a-w C:\WINDOWS\system32\mtxlegih.dll
- 2006-03-01 19:42:42 91,136 ----a-w C:\WINDOWS\system32\mtxoci.dll
+ 2008-04-14 00:12:01 91,648 ----a-w C:\WINDOWS\system32\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 ------w C:\WINDOWS\system32\mtxparhd.dll
- 2004-08-04 11:00:00 405,504 -c--a-w C:\WINDOWS\system32\mui\041b\xpob2res.dll
+ 2008-04-13 18:40:52 405,504 ----a-w C:\WINDOWS\system32\mui\041b\xpob2res.dll
- 2004-08-04 11:00:00 193,024 -c--a-w C:\WINDOWS\system32\mui\041b\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 ----a-w C:\WINDOWS\system32\mui\041b\xpsp1res.dll
- 2004-08-04 11:00:00 757,248 -c--a-w C:\WINDOWS\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:38:37 757,248 ----a-w C:\WINDOWS\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:40:04 577,536 ------w C:\WINDOWS\system32\mui\041b\xpsp3res.dll
- 2004-08-04 11:00:00 408,576 -c--a-w C:\WINDOWS\system32\mui\0424\xpob2res.dll
+ 2008-04-13 18:40:56 408,576 ----a-w C:\WINDOWS\system32\mui\0424\xpob2res.dll
- 2004-08-04 11:00:00 192,512 -c--a-w C:\WINDOWS\system32\mui\0424\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 ----a-w C:\WINDOWS\system32\mui\0424\xpsp1res.dll
- 2004-08-04 11:00:00 732,160 -c--a-w C:\WINDOWS\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:38:36 732,160 ----a-w C:\WINDOWS\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:40:05 576,512 ------w C:\WINDOWS\system32\mui\0424\xpsp3res.dll
breakawayjade
2008-10-17, 02:58
- 2004-08-04 11:00:00 90,624 ----a-w C:\WINDOWS\system32\mydocs.dll
+ 2008-04-14 00:12:01 90,624 ----a-w C:\WINDOWS\system32\mydocs.dll
+ 2008-04-14 00:12:01 30,208 ------w C:\WINDOWS\system32\napipsec.dll
+ 2008-04-14 00:12:01 193,024 ------w C:\WINDOWS\system32\napmontr.dll
+ 2008-04-14 00:12:29 176,640 ------w C:\WINDOWS\system32\napstat.exe
- 2004-08-04 11:00:00 53,760 ----a-w C:\WINDOWS\system32\narrator.exe
+ 2008-04-14 00:12:29 53,760 ----a-w C:\WINDOWS\system32\narrator.exe
- 2004-08-04 11:00:00 36,352 ----a-w C:\WINDOWS\system32\ncobjapi.dll
+ 2008-04-14 00:12:01 36,352 ----a-w C:\WINDOWS\system32\ncobjapi.dll
- 2004-08-04 11:00:00 17,920 ----a-w C:\WINDOWS\system32\nddeapi.dll
+ 2008-04-14 00:12:01 17,920 ----a-w C:\WINDOWS\system32\nddeapi.dll
- 2004-08-04 11:00:00 4,096 ----a-w C:\WINDOWS\system32\nddeapir.exe
+ 2008-04-14 00:12:29 4,096 ----a-w C:\WINDOWS\system32\nddeapir.exe
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\nddenb32.dll
+ 2008-04-14 00:12:01 18,944 ----a-w C:\WINDOWS\system32\nddenb32.dll
- 2004-08-04 11:00:00 42,496 ----a-w C:\WINDOWS\system32\net.exe
+ 2008-04-14 00:12:29 42,496 ----a-w C:\WINDOWS\system32\net.exe
- 2004-08-04 11:00:00 124,928 ----a-w C:\WINDOWS\system32\net1.exe
+ 2008-04-14 00:12:29 124,928 ----a-w C:\WINDOWS\system32\net1.exe
- 2006-08-17 12:28:27 332,288 ----a-w C:\WINDOWS\system32\netapi32.dll
+ 2008-04-14 00:12:01 337,408 ----a-w C:\WINDOWS\system32\netapi32.dll
- 2004-08-04 11:00:00 622,080 ----a-w C:\WINDOWS\system32\netcfgx.dll
+ 2008-04-14 00:12:01 622,592 ----a-w C:\WINDOWS\system32\netcfgx.dll
- 2004-08-04 11:00:00 111,104 ----a-w C:\WINDOWS\system32\netdde.exe
+ 2008-04-14 00:12:29 111,104 ----a-w C:\WINDOWS\system32\netdde.exe
- 2004-08-04 11:00:00 139,264 ----a-w C:\WINDOWS\system32\netid.dll
+ 2008-04-14 00:12:01 139,264 ----a-w C:\WINDOWS\system32\netid.dll
- 2004-08-04 11:00:00 407,040 ----a-w C:\WINDOWS\system32\netlogon.dll
+ 2008-04-14 00:12:01 407,040 ----a-w C:\WINDOWS\system32\netlogon.dll
- 2005-08-22 18:29:46 197,632 ----a-w C:\WINDOWS\system32\netman.dll
+ 2008-04-14 00:12:01 198,144 ----a-w C:\WINDOWS\system32\netman.dll
- 2004-08-04 11:00:00 875,008 -c--a-w C:\WINDOWS\system32\netplwiz.dll
+ 2008-04-14 00:12:01 875,008 ----a-w C:\WINDOWS\system32\netplwiz.dll
- 2004-08-04 11:00:00 12,288 ----a-w C:\WINDOWS\system32\netrap.dll
+ 2008-04-14 00:12:01 11,776 ----a-w C:\WINDOWS\system32\netrap.dll
- 2004-08-04 11:00:00 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
+ 2008-04-14 00:16:51 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
- 2004-08-04 11:00:00 86,016 ----a-w C:\WINDOWS\system32\netsh.exe
+ 2008-04-14 00:12:29 86,016 ----a-w C:\WINDOWS\system32\netsh.exe
- 2004-08-04 11:00:00 1,708,032 ----a-w C:\WINDOWS\system32\netshell.dll
+ 2008-04-14 00:12:02 1,703,936 ----a-w C:\WINDOWS\system32\netshell.dll
- 2004-08-04 11:00:00 36,864 ----a-w C:\WINDOWS\system32\netstat.exe
+ 2008-04-14 00:12:29 36,864 ----a-w C:\WINDOWS\system32\netstat.exe
- 2004-08-04 11:00:00 80,896 ----a-w C:\WINDOWS\system32\netui0.dll
+ 2008-04-14 00:12:02 80,896 ----a-w C:\WINDOWS\system32\netui0.dll
- 2004-08-04 11:00:00 245,760 ----a-w C:\WINDOWS\system32\netui1.dll
+ 2008-04-14 00:12:02 245,760 ----a-w C:\WINDOWS\system32\netui1.dll
- 2004-08-04 11:00:00 248,832 ----a-w C:\WINDOWS\system32\newdev.dll
+ 2008-04-14 00:12:02 247,808 ----a-w C:\WINDOWS\system32\newdev.dll
- 2004-08-04 11:00:00 103,936 ----a-w C:\WINDOWS\system32\nlhtml.dll
+ 2008-04-14 00:12:02 98,304 ----a-w C:\WINDOWS\system32\nlhtml.dll
- 2004-08-04 11:00:00 28,672 -c--a-w C:\WINDOWS\system32\nmmkcert.dll
+ 2008-04-14 00:12:02 28,672 ----a-w C:\WINDOWS\system32\nmmkcert.dll
- 2004-08-04 11:00:00 69,120 ----a-w C:\WINDOWS\system32\notepad.exe
+ 2008-04-14 00:12:29 69,120 ----a-w C:\WINDOWS\system32\notepad.exe
- 2004-08-04 11:00:00 57,344 -c--a-w C:\WINDOWS\system32\npp\ndisnpp.dll
+ 2008-04-14 00:12:01 57,344 ----a-w C:\WINDOWS\system32\npp\ndisnpp.dll
- 2004-08-04 11:00:00 15,360 -c--a-w C:\WINDOWS\system32\npp\nppagent.exe
+ 2008-04-14 00:12:29 15,360 ----a-w C:\WINDOWS\system32\npp\nppagent.exe
- 2004-08-04 11:00:00 54,784 -c--a-w C:\WINDOWS\system32\npptools.dll
+ 2008-04-14 00:12:02 54,784 ----a-w C:\WINDOWS\system32\npptools.dll
- 2004-08-04 11:00:00 76,800 ----a-w C:\WINDOWS\system32\nslookup.exe
+ 2008-04-14 00:12:29 76,800 ----a-w C:\WINDOWS\system32\nslookup.exe
- 2004-08-04 11:00:00 708,096 ----a-w C:\WINDOWS\system32\ntdll.dll
+ 2008-04-14 00:11:24 706,048 ----a-w C:\WINDOWS\system32\ntdll.dll
- 2004-08-04 11:00:00 67,072 ----a-w C:\WINDOWS\system32\ntdsapi.dll
+ 2008-04-14 00:12:02 67,072 ----a-w C:\WINDOWS\system32\ntdsapi.dll
- 2007-02-28 08:38:55 2,057,600 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
+ 2008-04-13 18:31:21 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
- 2004-08-04 11:00:00 43,520 ----a-w C:\WINDOWS\system32\ntlanman.dll
+ 2008-04-14 00:12:02 44,032 ----a-w C:\WINDOWS\system32\ntlanman.dll
- 2004-08-04 11:00:00 8,192 ----a-w C:\WINDOWS\system32\ntlsapi.dll
+ 2008-04-14 00:12:02 8,192 ----a-w C:\WINDOWS\system32\ntlsapi.dll
- 2004-08-04 11:00:00 118,784 ----a-w C:\WINDOWS\system32\ntmarta.dll
+ 2008-04-14 00:12:02 118,784 ----a-w C:\WINDOWS\system32\ntmarta.dll
- 2004-08-04 11:00:00 40,960 ----a-w C:\WINDOWS\system32\ntmsapi.dll
+ 2008-04-14 00:12:02 40,960 ----a-w C:\WINDOWS\system32\ntmsapi.dll
- 2004-08-04 11:00:00 179,712 -c--a-w C:\WINDOWS\system32\ntmsdba.dll
+ 2008-04-14 00:12:02 179,200 ----a-w C:\WINDOWS\system32\ntmsdba.dll
- 2004-08-04 11:00:00 488,448 ----a-w C:\WINDOWS\system32\ntmsmgr.dll
+ 2008-04-14 00:12:02 488,448 ----a-w C:\WINDOWS\system32\ntmsmgr.dll
- 2004-08-04 11:00:00 435,200 -c--a-w C:\WINDOWS\system32\ntmssvc.dll
+ 2008-04-14 00:12:02 435,200 ----a-w C:\WINDOWS\system32\ntmssvc.dll
- 2007-02-28 09:10:57 2,180,352 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
+ 2008-04-13 19:27:53 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
- 2004-08-04 11:00:00 91,136 ----a-w C:\WINDOWS\system32\ntprint.dll
+ 2008-04-14 00:12:02 91,136 ----a-w C:\WINDOWS\system32\ntprint.dll
- 2004-08-04 11:00:00 143,872 ----a-w C:\WINDOWS\system32\ntshrui.dll
+ 2008-04-14 00:12:02 143,360 ----a-w C:\WINDOWS\system32\ntshrui.dll
- 2004-08-04 11:00:00 419,840 ----a-w C:\WINDOWS\system32\ntvdm.exe
+ 2008-04-14 00:12:30 420,864 ----a-w C:\WINDOWS\system32\ntvdm.exe
- 2004-08-04 11:00:00 13,312 -c--a-w C:\WINDOWS\system32\ntvdmd.dll
+ 2008-04-14 00:12:02 15,360 ----a-w C:\WINDOWS\system32\ntvdmd.dll
- 2004-08-04 06:56:46 4,274,816 -c--a-w C:\WINDOWS\system32\nv4_disp.dll
+ 2008-04-14 00:12:02 4,274,816 ----a-w C:\WINDOWS\system32\nv4_disp.dll
- 2006-10-13 12:35:12 142,336 ----a-w C:\WINDOWS\system32\nwprovau.dll
+ 2008-04-14 00:12:02 142,336 ----a-w C:\WINDOWS\system32\nwprovau.dll
- 2004-08-04 11:00:00 266,752 ----a-w C:\WINDOWS\system32\oakley.dll
+ 2008-04-14 00:12:02 270,336 ----a-w C:\WINDOWS\system32\oakley.dll
- 2004-08-04 11:00:00 285,696 -c--a-w C:\WINDOWS\system32\objsel.dll
+ 2008-04-14 00:12:02 286,208 ----a-w C:\WINDOWS\system32\objsel.dll
- 2004-08-04 11:00:00 60,928 ----a-w C:\WINDOWS\system32\ocmanage.dll
+ 2008-04-14 00:12:02 67,584 ----a-w C:\WINDOWS\system32\ocmanage.dll
- 2004-08-04 11:00:00 249,856 ----a-w C:\WINDOWS\system32\odbc32.dll
+ 2008-04-14 00:12:02 249,856 ----a-w C:\WINDOWS\system32\odbc32.dll
- 2004-08-04 11:00:00 16,384 ----a-w C:\WINDOWS\system32\odbc32gt.dll
+ 2008-04-14 00:12:02 16,384 ----a-w C:\WINDOWS\system32\odbc32gt.dll
- 2004-08-04 11:00:00 32,768 ----a-w C:\WINDOWS\system32\odbcad32.exe
+ 2008-04-14 00:12:30 32,768 ----a-w C:\WINDOWS\system32\odbcad32.exe
- 2004-08-04 11:00:00 24,576 ----a-w C:\WINDOWS\system32\odbcbcp.dll
+ 2008-04-14 00:12:02 24,576 ----a-w C:\WINDOWS\system32\odbcbcp.dll
- 2004-08-04 11:00:00 135,168 ----a-w C:\WINDOWS\system32\odbcconf.dll
+ 2008-04-14 00:12:02 135,168 ----a-w C:\WINDOWS\system32\odbcconf.dll
- 2004-08-04 11:00:00 69,632 ----a-w C:\WINDOWS\system32\odbcconf.exe
+ 2008-04-14 00:12:30 69,632 ----a-w C:\WINDOWS\system32\odbcconf.exe
- 2004-08-04 11:00:00 106,496 ----a-w C:\WINDOWS\system32\odbccp32.dll
+ 2008-04-14 00:12:02 106,496 ----a-w C:\WINDOWS\system32\odbccp32.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 ----a-w C:\WINDOWS\system32\odbccr32.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\odbccu32.dll
+ 2008-04-14 00:12:02 65,536 ----a-w C:\WINDOWS\system32\odbccu32.dll
- 2004-08-04 11:00:00 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
+ 2008-04-13 17:26:05 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
- 2004-08-04 11:00:00 53,279 -c--a-w C:\WINDOWS\system32\odbcji32.dll
+ 2008-04-14 00:10:31 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
- 2004-08-04 11:00:00 278,559 -c--a-w C:\WINDOWS\system32\odbcjt32.dll
+ 2008-04-14 00:12:02 278,559 ----a-w C:\WINDOWS\system32\odbcjt32.dll
- 2004-08-04 11:00:00 12,288 -c--a-w C:\WINDOWS\system32\odbcp32r.dll
+ 2008-04-13 17:26:05 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
- 2004-08-04 11:00:00 147,456 -c--a-w C:\WINDOWS\system32\odbctrac.dll
+ 2008-04-14 00:12:02 147,456 ----a-w C:\WINDOWS\system32\odbctrac.dll
- 2004-08-04 11:00:00 20,511 -c--a-w C:\WINDOWS\system32\oddbse32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w C:\WINDOWS\system32\oddbse32.dll
- 2004-08-04 11:00:00 20,510 -c--a-w C:\WINDOWS\system32\odexl32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w C:\WINDOWS\system32\odexl32.dll
- 2004-08-04 11:00:00 20,510 -c--a-w C:\WINDOWS\system32\odfox32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w C:\WINDOWS\system32\odfox32.dll
- 2004-08-04 11:00:00 20,510 -c--a-w C:\WINDOWS\system32\odpdx32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w C:\WINDOWS\system32\odpdx32.dll
- 2004-08-04 11:00:00 20,511 -c--a-w C:\WINDOWS\system32\odtext32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w C:\WINDOWS\system32\odtext32.dll
- 2004-08-04 11:00:00 120,832 -c--a-w C:\WINDOWS\system32\offfilt.dll
+ 2008-04-14 00:12:02 192,000 ----a-w C:\WINDOWS\system32\offfilt.dll
- 2005-07-26 04:39:48 1,285,120 ----a-w C:\WINDOWS\system32\ole32.dll
+ 2008-04-14 00:12:02 1,287,168 ----a-w C:\WINDOWS\system32\ole32.dll
- 2007-12-04 18:38:13 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
+ 2008-04-14 00:12:02 551,936 ----a-w C:\WINDOWS\system32\oleaut32.dll
- 2005-07-26 04:39:48 74,752 ----a-w C:\WINDOWS\system32\olecli32.dll
+ 2008-04-14 00:12:02 74,752 ----a-w C:\WINDOWS\system32\olecli32.dll
- 2005-07-26 04:39:49 37,888 ----a-w C:\WINDOWS\system32\olecnv32.dll
+ 2008-04-14 00:12:02 37,376 ----a-w C:\WINDOWS\system32\olecnv32.dll
- 2006-10-16 16:15:00 122,880 ----a-w C:\WINDOWS\system32\oledlg.dll
+ 2008-04-14 00:12:02 122,880 ----a-w C:\WINDOWS\system32\oledlg.dll
- 2004-08-04 11:00:00 107,008 ----a-w C:\WINDOWS\system32\oleprn.dll
+ 2008-04-14 00:12:02 107,008 ----a-w C:\WINDOWS\system32\oleprn.dll
- 2004-08-04 11:00:00 83,456 ----a-w C:\WINDOWS\system32\olepro32.dll
+ 2008-04-14 00:12:02 84,992 ----a-w C:\WINDOWS\system32\olepro32.dll
+ 2008-04-14 00:12:02 144,384 ------w C:\WINDOWS\system32\onex.dll
+ 2007-08-03 01:11:28 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
+ 2007-08-03 01:11:14 241,664 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
+ 2007-08-06 20:17:40 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
+ 2007-06-13 18:10:34 77,824 ----a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
- 2004-08-04 11:00:00 122,368 -c--a-w C:\WINDOWS\system32\oobe\msobcomm.dll
+ 2008-04-14 00:12:00 122,368 ----a-w C:\WINDOWS\system32\oobe\msobcomm.dll
- 2004-08-04 11:00:00 16,384 -c--a-w C:\WINDOWS\system32\oobe\msobdl.dll
+ 2008-04-14 00:12:00 16,384 ----a-w C:\WINDOWS\system32\oobe\msobdl.dll
- 2004-08-04 11:00:00 561,664 ----a-w C:\WINDOWS\system32\oobe\msobmain.dll
+ 2008-04-14 00:12:00 565,248 ----a-w C:\WINDOWS\system32\oobe\msobmain.dll
- 2004-08-04 11:00:00 30,720 -c--a-w C:\WINDOWS\system32\oobe\msobshel.dll
+ 2008-04-14 00:12:00 30,720 ----a-w C:\WINDOWS\system32\oobe\msobshel.dll
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\system32\oobe\msobweb.dll
+ 2008-04-14 00:12:00 19,456 ----a-w C:\WINDOWS\system32\oobe\msobweb.dll
- 2004-08-04 11:00:00 28,160 -c--a-w C:\WINDOWS\system32\oobe\msoobe.exe
+ 2008-04-14 00:12:28 29,184 ----a-w C:\WINDOWS\system32\oobe\msoobe.exe
- 2004-08-04 11:00:00 51,200 -c--a-w C:\WINDOWS\system32\oobe\oobebaln.exe
+ 2008-04-14 00:12:31 51,200 ----a-w C:\WINDOWS\system32\oobe\oobebaln.exe
- 2004-08-04 11:00:00 713,728 ----a-w C:\WINDOWS\system32\opengl32.dll
+ 2008-04-14 00:12:02 713,728 ----a-w C:\WINDOWS\system32\opengl32.dll
- 2004-08-04 11:00:00 215,552 ----a-w C:\WINDOWS\system32\osk.exe
+ 2008-04-14 00:12:31 215,552 ----a-w C:\WINDOWS\system32\osk.exe
- 2004-08-04 11:00:00 67,584 ----a-w C:\WINDOWS\system32\osuninst.dll
+ 2008-04-14 00:12:02 67,584 ----a-w C:\WINDOWS\system32\osuninst.dll
- 2004-08-04 11:00:00 116,224 ----a-w C:\WINDOWS\system32\p2p.dll
+ 2008-04-14 00:12:02 153,600 ----a-w C:\WINDOWS\system32\p2p.dll
- 2004-08-04 11:00:00 86,016 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
+ 2008-04-14 00:12:02 105,472 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
- 2004-08-04 11:00:00 312,320 -c--a-w C:\WINDOWS\system32\p2pgraph.dll
+ 2008-04-14 00:12:02 313,856 ----a-w C:\WINDOWS\system32\p2pgraph.dll
- 2004-08-04 11:00:00 88,064 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
+ 2008-04-14 00:12:02 115,712 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
- 2004-08-04 11:00:00 526,848 -c--a-w C:\WINDOWS\system32\p2psvc.dll
+ 2008-04-14 00:12:02 554,496 ----a-w C:\WINDOWS\system32\p2psvc.dll
- 2004-08-04 11:00:00 58,368 ----a-w C:\WINDOWS\system32\packager.exe
+ 2008-04-14 00:12:31 58,368 ----a-w C:\WINDOWS\system32\packager.exe
- 2004-08-04 11:00:00 62,976 -c--a-w C:\WINDOWS\system32\pautoenr.dll
+ 2008-04-14 00:12:02 67,584 ----a-w C:\WINDOWS\system32\pautoenr.dll
- 2004-08-04 11:00:00 283,648 ----a-w C:\WINDOWS\system32\pdh.dll
+ 2008-04-14 00:12:02 284,160 ----a-w C:\WINDOWS\system32\pdh.dll
- 2008-08-30 21:48:09 63,016 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-10 15:31:23 63,016 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2004-08-04 11:00:00 39,936 ----a-w C:\WINDOWS\system32\perfctrs.dll
+ 2008-04-14 00:12:02 39,936 ----a-w C:\WINDOWS\system32\perfctrs.dll
- 2004-08-04 11:00:00 26,624 -c--a-w C:\WINDOWS\system32\perfdisk.dll
+ 2008-04-14 00:12:02 26,624 ----a-w C:\WINDOWS\system32\perfdisk.dll
- 2008-08-30 21:48:09 402,406 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-10 15:31:23 402,406 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2004-08-04 11:00:00 15,872 ----a-w C:\WINDOWS\system32\perfmon.exe
+ 2008-04-14 00:12:31 15,872 ----a-w C:\WINDOWS\system32\perfmon.exe
- 2004-08-04 11:00:00 16,896 -c--a-w C:\WINDOWS\system32\perfnet.dll
+ 2008-04-14 00:12:02 17,920 ----a-w C:\WINDOWS\system32\perfnet.dll
- 2004-08-04 11:00:00 25,088 ----a-w C:\WINDOWS\system32\perfos.dll
+ 2008-04-14 00:12:02 25,088 ----a-w C:\WINDOWS\system32\perfos.dll
- 2004-08-04 11:00:00 34,816 -c--a-w C:\WINDOWS\system32\perfproc.dll
+ 2008-04-14 00:12:02 34,816 ----a-w C:\WINDOWS\system32\perfproc.dll
+ 2008-04-14 00:12:02 412,160 ------w C:\WINDOWS\system32\photometadatahandler.dll
- 2004-08-04 11:00:00 176,128 -c--a-w C:\WINDOWS\system32\photowiz.dll
+ 2008-04-14 00:12:02 176,128 ----a-w C:\WINDOWS\system32\photowiz.dll
- 2004-08-04 11:00:00 35,328 -c--a-w C:\WINDOWS\system32\pid.dll
+ 2008-04-14 00:12:02 35,328 ----a-w C:\WINDOWS\system32\pid.dll
- 2004-08-04 11:00:00 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
+ 2008-04-13 18:35:22 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
- 2004-08-04 11:00:00 17,920 ----a-w C:\WINDOWS\system32\ping.exe
+ 2008-04-14 00:12:31 17,920 ----a-w C:\WINDOWS\system32\ping.exe
- 2004-08-04 11:00:00 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
+ 2008-04-14 00:12:02 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
- 2004-08-04 11:00:00 48,640 -c--a-w C:\WINDOWS\system32\pnrpnsp.dll
+ 2008-04-14 00:12:02 58,880 ----a-w C:\WINDOWS\system32\pnrpnsp.dll
- 2004-08-04 11:00:00 105,472 ----a-w C:\WINDOWS\system32\polstore.dll
+ 2008-04-14 00:12:02 105,472 ----a-w C:\WINDOWS\system32\polstore.dll
- 2004-08-04 11:00:00 49,152 ----a-w C:\WINDOWS\system32\powercfg.exe
+ 2008-04-14 00:12:31 49,152 ----a-w C:\WINDOWS\system32\powercfg.exe
- 2004-08-04 11:00:00 17,408 ----a-w C:\WINDOWS\system32\powrprof.dll
+ 2008-04-14 00:12:03 17,408 ----a-w C:\WINDOWS\system32\powrprof.dll
- 2004-08-04 11:00:00 560,640 ----a-w C:\WINDOWS\system32\printui.dll
+ 2008-04-14 00:12:03 560,640 ----a-w C:\WINDOWS\system32\printui.dll
- 2004-08-04 11:00:00 27,648 ----a-w C:\WINDOWS\system32\profmap.dll
+ 2008-04-14 00:12:03 27,648 ----a-w C:\WINDOWS\system32\profmap.dll
- 2004-08-04 11:00:00 109,568 ----a-w C:\WINDOWS\system32\progman.exe
+ 2008-04-14 00:12:31 109,568 ----a-w C:\WINDOWS\system32\progman.exe
- 2004-08-04 11:00:00 50,176 ----a-w C:\WINDOWS\system32\proquota.exe
+ 2008-04-14 00:12:32 50,176 ----a-w C:\WINDOWS\system32\proquota.exe
- 2004-08-04 11:00:00 9,216 ----a-w C:\WINDOWS\system32\proxycfg.exe
+ 2008-04-14 00:12:32 9,216 ----a-w C:\WINDOWS\system32\proxycfg.exe
- 2004-08-04 11:00:00 23,040 ----a-w C:\WINDOWS\system32\psapi.dll
+ 2008-04-14 00:12:03 23,040 ----a-w C:\WINDOWS\system32\psapi.dll
- 2004-08-04 11:00:00 96,768 ----a-w C:\WINDOWS\system32\psbase.dll
+ 2008-04-14 00:12:03 96,768 ----a-w C:\WINDOWS\system32\psbase.dll
- 2004-08-04 11:00:00 43,520 -c--a-w C:\WINDOWS\system32\pstorec.dll
+ 2008-04-14 00:12:03 43,520 ----a-w C:\WINDOWS\system32\pstorec.dll
- 2004-08-04 11:00:00 34,304 ----a-w C:\WINDOWS\system32\pstorsvc.dll
+ 2008-04-14 00:12:03 34,304 ----a-w C:\WINDOWS\system32\pstorsvc.dll
+ 2008-04-14 00:12:03 150,528 ------w C:\WINDOWS\system32\qagent.dll
+ 2008-04-14 00:12:03 291,328 ------w C:\WINDOWS\system32\qagentrt.dll
- 2004-08-04 11:00:00 192,512 -c--a-w C:\WINDOWS\system32\qcap.dll
+ 2008-04-14 00:12:03 192,512 ----a-w C:\WINDOWS\system32\qcap.dll
+ 2008-04-14 00:12:03 62,464 ------w C:\WINDOWS\system32\qcliprov.dll
- 2004-08-04 11:00:00 279,040 ----a-w C:\WINDOWS\system32\qdv.dll
+ 2008-04-14 00:12:03 279,040 ----a-w C:\WINDOWS\system32\qdv.dll
- 2004-08-04 11:00:00 385,024 ----a-w C:\WINDOWS\system32\qdvd.dll
+ 2008-04-14 00:12:03 386,048 ----a-w C:\WINDOWS\system32\qdvd.dll
- 2004-08-04 11:00:00 562,176 -c--a-w C:\WINDOWS\system32\qedit.dll
+ 2008-04-14 00:12:03 562,176 ----a-w C:\WINDOWS\system32\qedit.dll
- 2004-08-04 11:00:00 733,696 -c--a-w C:\WINDOWS\system32\qedwipes.dll
+ 2008-04-13 17:21:32 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
- 2007-03-29 12:56:02 409,600 ----a-w C:\WINDOWS\system32\qmgr.dll
+ 2008-04-14 00:12:03 409,088 ----a-w C:\WINDOWS\system32\qmgr.dll
- 2007-03-29 12:56:02 18,944 ----a-w C:\WINDOWS\system32\qmgrprxy.dll
+ 2008-04-14 00:12:03 18,944 ----a-w C:\WINDOWS\system32\qmgrprxy.dll
- 2004-08-04 11:00:00 20,480 ----a-w C:\WINDOWS\system32\qprocess.exe
+ 2008-04-14 00:12:32 19,968 ----a-w C:\WINDOWS\system32\qprocess.exe
- 2008-05-07 05:18:48 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
- 2006-06-22 05:06:30 1,435,648 ----a-w C:\WINDOWS\system32\query.dll
+ 2008-04-14 00:12:03 1,435,648 ----a-w C:\WINDOWS\system32\query.dll
+ 2008-04-14 00:12:03 76,800 ------w C:\WINDOWS\system32\qutil.dll
- 2004-08-04 11:00:00 43,520 ----a-w C:\WINDOWS\system32\racpldlg.dll
+ 2008-04-14 00:12:03 43,520 ----a-w C:\WINDOWS\system32\racpldlg.dll
- 2006-06-26 17:37:10 8,192 ----a-w C:\WINDOWS\system32\rasadhlp.dll
+ 2008-04-14 00:12:03 7,680 ----a-w C:\WINDOWS\system32\rasadhlp.dll
- 2004-08-04 11:00:00 236,544 ----a-w C:\WINDOWS\system32\rasapi32.dll
+ 2008-04-14 00:12:03 237,056 ----a-w C:\WINDOWS\system32\rasapi32.dll
- 2004-08-04 11:00:00 89,088 ----a-w C:\WINDOWS\system32\rasauto.dll
+ 2008-04-14 00:12:03 88,576 ----a-w C:\WINDOWS\system32\rasauto.dll
- 2004-08-04 11:00:00 69,632 ----a-w C:\WINDOWS\system32\raschap.dll
+ 2008-04-14 00:12:03 79,872 ----a-w C:\WINDOWS\system32\raschap.dll
- 2004-08-04 11:00:00 657,920 ----a-w C:\WINDOWS\system32\rasdlg.dll
+ 2008-04-14 00:12:03 658,432 ----a-w C:\WINDOWS\system32\rasdlg.dll
- 2004-08-04 11:00:00 61,440 ----a-w C:\WINDOWS\system32\rasman.dll
+ 2008-04-14 00:12:03 61,440 ----a-w C:\WINDOWS\system32\rasman.dll
- 2006-05-14 08:44:08 181,248 ----a-w C:\WINDOWS\system32\rasmans.dll
+ 2008-04-14 00:12:03 186,368 ----a-w C:\WINDOWS\system32\rasmans.dll
- 2004-08-04 11:00:00 56,832 ----a-w C:\WINDOWS\system32\rasphone.exe
+ 2008-04-14 00:12:32 56,832 ----a-w C:\WINDOWS\system32\rasphone.exe
- 2004-08-04 11:00:00 206,336 ----a-w C:\WINDOWS\system32\rasppp.dll
+ 2008-04-14 00:12:03 210,944 ----a-w C:\WINDOWS\system32\rasppp.dll
+ 2008-04-14 00:12:03 61,952 ------w C:\WINDOWS\system32\rasqec.dll
- 2004-08-04 11:00:00 16,896 -c--a-w C:\WINDOWS\system32\rassapi.dll
+ 2008-04-14 00:12:03 16,384 ----a-w C:\WINDOWS\system32\rassapi.dll
- 2004-08-04 11:00:00 58,880 ----a-w C:\WINDOWS\system32\rastapi.dll
+ 2008-04-14 00:12:03 58,368 ----a-w C:\WINDOWS\system32\rastapi.dll
- 2004-08-04 11:00:00 112,128 ----a-w C:\WINDOWS\system32\rastls.dll
+ 2008-04-14 00:12:03 150,016 ----a-w C:\WINDOWS\system32\rastls.dll
- 2004-08-04 11:00:00 102,400 ----a-w C:\WINDOWS\system32\rcbdyctl.dll
+ 2008-04-14 00:12:03 102,400 ----a-w C:\WINDOWS\system32\rcbdyctl.dll
- 2004-08-04 11:00:00 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe
+ 2008-04-14 00:12:32 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe
- 2004-08-04 11:00:00 21,504 ----a-w C:\WINDOWS\system32\rcp.exe
+ 2008-04-14 00:12:32 21,504 ----a-w C:\WINDOWS\system32\rcp.exe
- 2004-08-04 11:00:00 147,968 -c--a-w C:\WINDOWS\system32\rdchost.dll
+ 2008-04-14 00:12:03 147,968 ----a-w C:\WINDOWS\system32\rdchost.dll
- 2004-08-04 11:00:00 62,464 ----a-w C:\WINDOWS\system32\rdpclip.exe
+ 2008-04-14 00:12:32 62,976 ----a-w C:\WINDOWS\system32\rdpclip.exe
- 2004-08-04 11:00:00 92,168 ----a-w C:\WINDOWS\system32\rdpdd.dll
+ 2008-04-14 00:13:22 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
- 2004-08-04 11:00:00 19,968 -c--a-w C:\WINDOWS\system32\rdpsnd.dll
+ 2008-04-14 00:12:04 19,968 ----a-w C:\WINDOWS\system32\rdpsnd.dll
- 2004-08-04 11:00:00 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
+ 2008-04-14 00:13:22 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
- 2004-08-04 11:00:00 13,824 ----a-w C:\WINDOWS\system32\rdsaddin.exe
+ 2008-04-14 00:12:32 13,824 ----a-w C:\WINDOWS\system32\rdsaddin.exe
- 2004-08-04 11:00:00 67,072 ----a-w C:\WINDOWS\system32\rdshost.exe
+ 2008-04-14 00:12:32 67,072 ----a-w C:\WINDOWS\system32\rdshost.exe
- 2004-08-04 11:00:00 50,176 ----a-w C:\WINDOWS\system32\reg.exe
+ 2008-04-14 00:12:32 50,176 ----a-w C:\WINDOWS\system32\reg.exe
- 2004-08-04 11:00:00 49,664 ----a-w C:\WINDOWS\system32\regapi.dll
+ 2008-04-14 00:12:04 49,664 ----a-w C:\WINDOWS\system32\regapi.dll
- 2004-08-04 11:00:00 59,904 -c--a-w C:\WINDOWS\system32\regsvc.dll
+ 2008-04-14 00:12:04 59,904 ----a-w C:\WINDOWS\system32\regsvc.dll
- 2004-08-04 11:00:00 11,776 ----a-w C:\WINDOWS\system32\regsvr32.exe
+ 2008-04-14 00:12:32 11,776 ----a-w C:\WINDOWS\system32\regsvr32.exe
- 2004-08-04 11:00:00 397,824 -c--a-w C:\WINDOWS\system32\regwizc.dll
+ 2008-04-14 00:12:04 397,824 ----a-w C:\WINDOWS\system32\regwizc.dll
+ 2004-08-04 11:00:00 36,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\intelppm.sys
- 2004-08-04 11:00:00 60,416 ----a-w C:\WINDOWS\system32\remotepg.dll
+ 2008-04-14 00:12:04 60,416 ----a-w C:\WINDOWS\system32\remotepg.dll
- 2004-08-04 11:00:00 380,416 ----a-w C:\WINDOWS\system32\Restore\rstrui.exe
+ 2008-04-14 00:12:33 380,416 ----a-w C:\WINDOWS\system32\Restore\rstrui.exe
- 2004-08-04 11:00:00 58,880 ----a-w C:\WINDOWS\system32\resutils.dll
+ 2008-04-14 00:12:04 58,880 ----a-w C:\WINDOWS\system32\resutils.dll
- 2004-08-04 11:00:00 13,824 ----a-w C:\WINDOWS\system32\rexec.exe
+ 2008-04-14 00:12:33 13,824 ----a-w C:\WINDOWS\system32\rexec.exe
+ 2008-04-14 00:12:04 290,304 ------w C:\WINDOWS\system32\rhttpaa.dll
- 2006-11-27 14:54:06 433,152 ----a-w C:\WINDOWS\system32\riched20.dll
+ 2008-04-14 00:12:04 433,664 ----a-w C:\WINDOWS\system32\riched20.dll
- 2007-07-09 13:16:16 582,656 ----a-w C:\WINDOWS\system32\rpcrt4.dll
+ 2008-04-14 00:12:04 584,704 ----a-w C:\WINDOWS\system32\rpcrt4.dll
- 2005-07-26 04:39:49 397,824 ----a-w C:\WINDOWS\system32\rpcss.dll
+ 2008-04-14 00:12:04 399,360 ----a-w C:\WINDOWS\system32\rpcss.dll
- 2004-08-04 11:00:00 152,576 ----a-w C:\WINDOWS\system32\rsaenh.dll
+ 2008-04-13 17:37:57 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
- 2004-08-04 11:00:00 14,848 ----a-w C:\WINDOWS\system32\rsh.exe
+ 2008-04-14 00:12:33 14,848 ----a-w C:\WINDOWS\system32\rsh.exe
- 2004-08-04 11:00:00 39,936 ----a-w C:\WINDOWS\system32\rshx32.dll
+ 2008-04-14 00:12:04 39,936 ----a-w C:\WINDOWS\system32\rshx32.dll
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\system32\rsmps.dll
+ 2008-04-14 00:12:04 18,944 ----a-w C:\WINDOWS\system32\rsmps.dll
- 2004-08-04 11:00:00 90,112 ----a-w C:\WINDOWS\system32\rsvpsp.dll
+ 2008-04-14 00:12:04 92,672 ----a-w C:\WINDOWS\system32\rsvpsp.dll
- 2004-08-04 11:00:00 77,312 ----a-w C:\WINDOWS\system32\rtcshare.exe
+ 2008-04-14 00:12:33 77,312 ----a-w C:\WINDOWS\system32\rtcshare.exe
- 2004-08-04 11:00:00 31,744 ----a-w C:\WINDOWS\system32\rtipxmib.dll
+ 2008-04-14 00:12:04 31,744 ----a-w C:\WINDOWS\system32\rtipxmib.dll
- 2004-08-04 11:00:00 44,032 ----a-w C:\WINDOWS\system32\rtutils.dll
+ 2008-04-14 00:12:04 44,032 ----a-w C:\WINDOWS\system32\rtutils.dll
- 2004-08-04 11:00:00 33,280 ----a-w C:\WINDOWS\system32\rundll32.exe
+ 2008-04-14 00:12:33 33,280 ----a-w C:\WINDOWS\system32\rundll32.exe
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\runonce.exe
+ 2008-04-14 00:12:33 14,336 ----a-w C:\WINDOWS\system32\runonce.exe
+ 2008-04-14 00:12:04 397,056 ------w C:\WINDOWS\system32\s3gnb.dll
- 2004-08-04 11:00:00 43,520 -c--a-w C:\WINDOWS\system32\safrcdlg.dll
+ 2008-04-14 00:12:04 43,520 ----a-w C:\WINDOWS\system32\safrcdlg.dll
- 2004-08-04 11:00:00 29,696 -c--a-w C:\WINDOWS\system32\safrdm.dll
+ 2008-04-14 00:12:04 29,696 ----a-w C:\WINDOWS\system32\safrdm.dll
- 2004-08-04 11:00:00 45,568 -c--a-w C:\WINDOWS\system32\safrslv.dll
+ 2008-04-14 00:12:04 45,568 ----a-w C:\WINDOWS\system32\safrslv.dll
- 2004-08-04 11:00:00 64,000 ----a-w C:\WINDOWS\system32\samlib.dll
+ 2008-04-14 00:12:04 64,000 ----a-w C:\WINDOWS\system32\samlib.dll
- 2004-08-04 11:00:00 415,744 ----a-w C:\WINDOWS\system32\samsrv.dll
+ 2008-04-14 00:12:04 415,744 ----a-w C:\WINDOWS\system32\samsrv.dll
- 2004-08-04 11:00:00 13,312 ----a-w C:\WINDOWS\system32\savedump.exe
+ 2008-04-14 00:12:33 13,312 ----a-w C:\WINDOWS\system32\savedump.exe
- 2004-08-04 11:00:00 270,848 -c--a-w C:\WINDOWS\system32\sbe.dll
+ 2008-04-14 00:12:04 270,848 ----a-w C:\WINDOWS\system32\sbe.dll
- 2004-08-04 11:00:00 159,232 -c--a-w C:\WINDOWS\system32\sbeio.dll
+ 2008-04-14 00:12:04 159,232 ----a-w C:\WINDOWS\system32\sbeio.dll
- 2004-08-04 11:00:00 69,632 -c--a-w C:\WINDOWS\system32\scarddlg.dll
+ 2008-04-14 00:12:04 69,632 ----a-w C:\WINDOWS\system32\scarddlg.dll
- 2004-08-04 11:00:00 95,744 ----a-w C:\WINDOWS\system32\scardsvr.exe
+ 2008-04-14 00:12:33 95,744 ----a-w C:\WINDOWS\system32\scardsvr.exe
- 2004-08-04 11:00:00 171,008 -c--a-w C:\WINDOWS\system32\sccsccp.dll
+ 2008-04-14 00:12:05 171,008 ----a-w C:\WINDOWS\system32\sccsccp.dll
- 2004-08-04 11:00:00 180,224 ----a-w C:\WINDOWS\system32\scecli.dll
+ 2008-04-14 00:12:05 181,248 ----a-w C:\WINDOWS\system32\scecli.dll
- 2004-08-04 11:00:00 313,856 ----a-w C:\WINDOWS\system32\scesrv.dll
+ 2008-04-14 00:12:05 314,880 ----a-w C:\WINDOWS\system32\scesrv.dll
- 2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
+ 2008-04-14 00:12:05 144,384 ----a-w C:\WINDOWS\system32\schannel.dll
- 2004-08-04 11:00:00 190,976 ----a-w C:\WINDOWS\system32\schedsvc.dll
+ 2008-04-14 00:12:05 192,512 ----a-w C:\WINDOWS\system32\schedsvc.dll
- 2004-08-04 11:00:00 20,992 ----a-w C:\WINDOWS\system32\sclgntfy.dll
+ 2008-04-14 00:12:05 20,480 ----a-w C:\WINDOWS\system32\sclgntfy.dll
- 2004-08-04 11:00:00 9,216 -c--a-w C:\WINDOWS\system32\scrnsave.scr
+ 2008-04-14 00:12:43 9,216 ----a-w C:\WINDOWS\system32\scrnsave.scr
- 2004-08-04 11:00:00 159,744 ----a-w C:\WINDOWS\system32\scrobj.dll
+ 2008-05-09 10:53:39 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
- 2004-08-04 11:00:00 151,552 ----a-w C:\WINDOWS\system32\scrrun.dll
+ 2008-05-09 10:53:40 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
- 2004-08-04 11:00:00 77,312 ----a-w C:\WINDOWS\system32\sdbinst.exe
+ 2008-04-14 00:12:34 77,312 ----a-w C:\WINDOWS\system32\sdbinst.exe
- 2004-08-04 11:00:00 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll
+ 2008-04-14 00:12:05 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\seclogon.dll
+ 2008-04-14 00:12:05 18,944 ----a-w C:\WINDOWS\system32\seclogon.dll
- 2004-08-04 11:00:00 55,808 ----a-w C:\WINDOWS\system32\secur32.dll
+ 2008-04-14 00:12:05 56,320 ----a-w C:\WINDOWS\system32\secur32.dll
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\system32\security.dll
+ 2008-04-14 00:12:05 5,632 ----a-w C:\WINDOWS\system32\security.dll
- 2004-08-04 11:00:00 29,184 -c--a-w C:\WINDOWS\system32\sendcmsg.dll
+ 2008-04-14 00:12:05 29,184 ----a-w C:\WINDOWS\system32\sendcmsg.dll
- 2004-08-04 11:00:00 55,296 -c--a-w C:\WINDOWS\system32\sendmail.dll
+ 2008-04-14 00:12:05 54,784 ----a-w C:\WINDOWS\system32\sendmail.dll
- 2004-08-04 11:00:00 38,912 ----a-w C:\WINDOWS\system32\sens.dll
+ 2008-04-14 00:12:05 39,424 ----a-w C:\WINDOWS\system32\sens.dll
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\system32\sensapi.dll
+ 2008-04-14 00:12:05 7,168 ----a-w C:\WINDOWS\system32\sensapi.dll
- 2004-08-04 11:00:00 56,320 ----a-w C:\WINDOWS\system32\servdeps.dll
+ 2008-04-14 00:12:05 56,320 ----a-w C:\WINDOWS\system32\servdeps.dll
- 2004-08-04 11:00:00 108,032 ----a-w C:\WINDOWS\system32\services.exe
+ 2008-04-14 00:12:34 108,544 ----a-w C:\WINDOWS\system32\services.exe
- 2004-08-04 11:00:00 140,800 ----a-w C:\WINDOWS\system32\sessmgr.exe
+ 2008-04-14 00:12:34 141,312 ----a-w C:\WINDOWS\system32\sessmgr.exe
- 2004-08-04 11:00:00 31,232 ----a-w C:\WINDOWS\system32\sethc.exe
+ 2008-04-14 00:12:34 31,232 ----a-w C:\WINDOWS\system32\sethc.exe
- 2004-08-04 11:00:00 23,040 ----a-w C:\WINDOWS\system32\setup.exe
+ 2008-04-14 00:12:34 23,040 ----a-w C:\WINDOWS\system32\setup.exe
- 2004-08-04 11:00:00 259,584 ----a-w C:\WINDOWS\system32\Setup\comsetup.dll
+ 2008-04-14 00:11:51 274,944 ----a-w C:\WINDOWS\system32\Setup\comsetup.dll
- 2004-08-04 11:00:00 32,828 ----a-w C:\WINDOWS\system32\Setup\fp40ext.dll
+ 2008-04-14 00:11:53 32,828 ----a-w C:\WINDOWS\system32\Setup\fp40ext.dll
- 2004-08-04 11:00:00 132,608 ----a-w C:\WINDOWS\system32\Setup\fxsocm.dll
+ 2008-04-14 00:11:54 132,608 ----a-w C:\WINDOWS\system32\Setup\fxsocm.dll
- 2004-08-04 11:00:00 505,344 ----a-w C:\WINDOWS\system32\Setup\iis.dll
+ 2008-04-14 00:11:54 505,344 ----a-w C:\WINDOWS\system32\Setup\iis.dll
- 2004-08-04 11:00:00 115,712 ----a-w C:\WINDOWS\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:54 123,392 ----a-w C:\WINDOWS\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:56 8,192 ----a-w C:\WINDOWS\system32\Setup\koc.dll
- 2004-08-04 11:00:00 82,432 ----a-w C:\WINDOWS\system32\Setup\msdtcstp.dll
+ 2008-04-14 00:11:59 90,112 ----a-w C:\WINDOWS\system32\Setup\msdtcstp.dll
- 2004-08-04 11:00:00 15,360 ----a-w C:\WINDOWS\system32\Setup\msgrocm.dll
+ 2008-04-14 00:11:59 15,360 ----a-w C:\WINDOWS\system32\Setup\msgrocm.dll
- 2004-08-04 11:00:00 77,312 ----a-w C:\WINDOWS\system32\Setup\netoc.dll
+ 2008-04-14 00:12:01 77,312 ----a-w C:\WINDOWS\system32\Setup\netoc.dll
- 2004-08-04 11:00:00 62,976 ----a-w C:\WINDOWS\system32\Setup\ntoc.dll
+ 2008-04-14 00:12:02 62,976 ----a-w C:\WINDOWS\system32\Setup\ntoc.dll
- 2004-08-04 11:00:00 15,872 ----a-w C:\WINDOWS\system32\Setup\ocgen.dll
+ 2008-04-14 00:12:02 15,360 ----a-w C:\WINDOWS\system32\Setup\ocgen.dll
- 2004-08-04 11:00:00 17,408 ----a-w C:\WINDOWS\system32\Setup\ocmsn.dll
+ 2008-04-14 00:12:02 17,408 ----a-w C:\WINDOWS\system32\Setup\ocmsn.dll
- 2004-08-04 11:00:00 101,376 ----a-w C:\WINDOWS\system32\Setup\setupqry.dll
+ 2008-04-14 00:12:05 101,376 ----a-w C:\WINDOWS\system32\Setup\setupqry.dll
- 2004-08-04 11:00:00 22,016 ----a-w C:\WINDOWS\system32\Setup\startoc.dll
+ 2008-04-14 00:12:07 26,624 ----a-w C:\WINDOWS\system32\Setup\startoc.dll
- 2004-08-04 11:00:00 121,856 ----a-w C:\WINDOWS\system32\Setup\tsoc.dll
+ 2008-04-14 00:12:07 130,048 ----a-w C:\WINDOWS\system32\Setup\tsoc.dll
- 2004-08-04 11:00:00 983,552 ----a-w C:\WINDOWS\system32\setupapi.dll
+ 2008-04-14 12:42:06 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
+ 2008-04-14 00:12:35 32,768 ------w C:\WINDOWS\system32\setupn.exe
- 2004-08-04 11:00:00 5,120 ----a-w C:\WINDOWS\system32\sfc.dll
+ 2008-04-14 00:12:05 5,120 ----a-w C:\WINDOWS\system32\sfc.dll
- 2004-08-04 11:00:00 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
+ 2008-04-14 00:12:05 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
- 2004-08-04 11:00:00 1,580,544 ----a-w C:\WINDOWS\system32\sfcfiles.dll
+ 2008-04-14 00:12:05 1,614,848 ----a-w C:\WINDOWS\system32\sfcfiles.dll
- 2004-08-04 11:00:00 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
+ 2008-04-13 17:03:19 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
- 2006-10-23 15:34:22 1,497,600 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2008-04-14 00:12:05 1,499,136 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2007-10-26 03:34:01 8,460,288 ----a-w C:\WINDOWS\system32\shell32.dll
+ 2008-04-14 00:12:05 8,461,312 ----a-w C:\WINDOWS\system32\shell32.dll
- 2004-08-04 11:00:00 25,088 ----a-w C:\WINDOWS\system32\shfolder.dll
+ 2008-04-14 00:12:05 25,088 ----a-w C:\WINDOWS\system32\shfolder.dll
- 2004-08-04 11:00:00 68,096 ----a-w C:\WINDOWS\system32\shgina.dll
+ 2008-04-14 00:12:05 68,096 ----a-w C:\WINDOWS\system32\shgina.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\shimeng.dll
+ 2008-04-14 00:12:05 65,024 ----a-w C:\WINDOWS\system32\shimeng.dll
- 2004-08-04 11:00:00 438,272 ----a-w C:\WINDOWS\system32\shimgvw.dll
+ 2008-04-14 00:12:05 438,272 ----a-w C:\WINDOWS\system32\shimgvw.dll
- 2006-10-23 15:34:22 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-04-14 00:12:05 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2004-08-04 11:00:00 151,552 ----a-w C:\WINDOWS\system32\shmedia.dll
+ 2008-04-14 00:12:05 152,064 ----a-w C:\WINDOWS\system32\shmedia.dll
- 2004-08-04 11:00:00 42,496 ----a-w C:\WINDOWS\system32\shmgrate.exe
+ 2008-04-14 00:12:35 45,056 ----a-w C:\WINDOWS\system32\shmgrate.exe
- 2004-08-04 11:00:00 77,824 ----a-w C:\WINDOWS\system32\shrpubw.exe
+ 2008-04-14 00:12:35 77,824 ----a-w C:\WINDOWS\system32\shrpubw.exe
- 2004-08-04 11:00:00 27,648 ----a-w C:\WINDOWS\system32\shscrap.dll
+ 2008-04-14 00:12:05 27,648 ----a-w C:\WINDOWS\system32\shscrap.dll
- 2006-12-19 21:52:18 134,656 ----a-w C:\WINDOWS\system32\shsvcs.dll
+ 2008-04-14 00:12:05 135,168 ----a-w C:\WINDOWS\system32\shsvcs.dll
- 2004-08-04 11:00:00 19,456 ----a-w C:\WINDOWS\system32\shutdown.exe
+ 2008-04-14 00:12:35 19,456 ----a-w C:\WINDOWS\system32\shutdown.exe
- 2004-08-04 11:00:00 13,312 -c--a-w C:\WINDOWS\system32\sigtab.dll
+ 2008-04-14 00:12:05 13,312 ----a-w C:\WINDOWS\system32\sigtab.dll
- 2004-08-04 11:00:00 70,144 ----a-w C:\WINDOWS\system32\sigverif.exe
+ 2008-04-14 00:12:35 70,144 ----a-w C:\WINDOWS\system32\sigverif.exe
- 2004-08-04 11:00:00 26,112 ----a-w C:\WINDOWS\system32\skeys.exe
+ 2008-04-14 00:12:35 26,112 ----a-w C:\WINDOWS\system32\skeys.exe
- 2004-08-04 11:00:00 25,088 -c--a-w C:\WINDOWS\system32\slayerxp.dll
+ 2008-04-14 00:12:06 25,088 ----a-w C:\WINDOWS\system32\slayerxp.dll
- 2004-08-04 11:00:00 98,304 ----a-w C:\WINDOWS\system32\slbiop.dll
+ 2008-04-14 00:12:06 98,304 ----a-w C:\WINDOWS\system32\slbiop.dll
+ 2008-04-14 00:12:06 73,832 ------w C:\WINDOWS\system32\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 ------w C:\WINDOWS\system32\slextspk.dll
+ 2008-04-14 00:12:06 188,508 ------w C:\WINDOWS\system32\slgen.dll
+ 2008-04-14 00:12:35 32,866 ------w C:\WINDOWS\system32\slrundll.exe
+ 2008-04-14 00:12:35 73,796 ------w C:\WINDOWS\system32\slserv.exe
- 2004-08-04 11:00:00 8,192 ----a-w C:\WINDOWS\system32\smbinst.exe
+ 2008-04-14 00:12:35 8,192 ----a-w C:\WINDOWS\system32\smbinst.exe
- 2004-08-04 11:00:00 363,008 ----a-w C:\WINDOWS\system32\smlogcfg.dll
+ 2008-04-14 00:12:06 362,496 ----a-w C:\WINDOWS\system32\smlogcfg.dll
- 2004-08-04 11:00:00 89,600 ----a-w C:\WINDOWS\system32\smlogsvc.exe
+ 2008-04-14 00:12:35 89,600 ----a-w C:\WINDOWS\system32\smlogsvc.exe
- 2004-08-04 11:00:00 50,688 ----a-w C:\WINDOWS\system32\smss.exe
+ 2008-04-14 00:12:36 50,688 ----a-w C:\WINDOWS\system32\smss.exe
- 2004-08-04 11:00:00 131,584 ----a-w C:\WINDOWS\system32\sndrec32.exe
+ 2008-04-14 00:12:36 131,584 ----a-w C:\WINDOWS\system32\sndrec32.exe
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\snmpapi.dll
+ 2008-04-14 00:12:06 18,944 ----a-w C:\WINDOWS\system32\snmpapi.dll
- 2004-08-04 11:00:00 182,272 -c--a-w C:\WINDOWS\system32\snmpsnap.dll
+ 2008-04-14 00:12:06 182,272 ----a-w C:\WINDOWS\system32\snmpsnap.dll
- 2004-08-04 11:00:00 23,552 ----a-w C:\WINDOWS\system32\sort.exe
+ 2008-04-14 00:12:36 24,576 ----a-w C:\WINDOWS\system32\sort.exe
+ 2008-04-14 00:12:36 7,680 ----a-w C:\WINDOWS\system32\spdwnwxp.exe
- 2004-08-04 11:00:00 538,624 ----a-w C:\WINDOWS\system32\spider.exe
+ 2008-04-14 00:12:36 538,624 ----a-w C:\WINDOWS\system32\spider.exe
- 2004-08-04 11:00:00 11,776 ----a-w C:\WINDOWS\system32\spnpinst.exe
+ 2008-04-14 12:42:38 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
- 2004-08-04 11:00:00 452,096 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSAPI.DLL
+ 2008-04-14 00:11:53 451,584 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxsapi.dll
- 2004-08-04 11:00:00 27,136 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSDRV.DLL
+ 2008-04-14 00:11:54 26,624 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxsdrv.dll
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSRES.DLL
+ 2008-04-14 00:09:33 6,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxsres.dll
- 2004-08-04 11:00:00 397,312 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSTIFF.DLL
+ 2008-04-14 00:11:54 397,312 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxstiff.dll
- 2004-08-04 11:00:00 154,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSUI.DLL
+ 2008-04-14 00:11:54 154,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxsui.dll
- 2004-08-04 11:00:00 192,512 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\FXSWZRD.DLL
+ 2008-04-14 00:11:54 192,512 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\fxswzrd.dll
- 2004-08-04 11:00:00 74,752 ----a-w C:\WINDOWS\system32\spoolss.dll
+ 2008-04-14 00:12:06 75,264 ----a-w C:\WINDOWS\system32\spoolss.dll
- 2005-06-10 23:53:32 57,856 ----a-w C:\WINDOWS\system32\spoolsv.exe
+ 2008-04-14 00:12:36 57,856 ----a-w C:\WINDOWS\system32\spoolsv.exe
- 2006-09-26 01:58:48 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2007-08-11 03:46:18 26,488 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2008-04-14 00:12:36 20,992 ------w C:\WINDOWS\system32\spupdwxp.exe
- 2004-08-04 11:00:00 442,368 -c--a-w C:\WINDOWS\system32\sqlsrv32.dll
+ 2008-04-14 00:12:06 442,368 ----a-w C:\WINDOWS\system32\sqlsrv32.dll
- 2004-08-04 11:00:00 180,800 -c--a-w C:\WINDOWS\system32\sqlunirl.dll
+ 2008-04-14 00:12:06 180,800 ----a-w C:\WINDOWS\system32\sqlunirl.dll
- 2004-08-04 11:00:00 67,584 ----a-w C:\WINDOWS\system32\srclient.dll
+ 2008-04-14 00:12:07 67,584 ----a-w C:\WINDOWS\system32\srclient.dll
- 2004-08-04 11:00:00 239,104 ----a-w C:\WINDOWS\system32\srrstr.dll
+ 2008-04-14 00:12:07 239,104 ----a-w C:\WINDOWS\system32\srrstr.dll
- 2004-08-04 11:00:00 170,496 ----a-w C:\WINDOWS\system32\srsvc.dll
+ 2008-04-14 00:12:07 171,008 ----a-w C:\WINDOWS\system32\srsvc.dll
- 2004-12-07 19:32:34 96,768 ----a-w C:\WINDOWS\system32\srvsvc.dll
+ 2008-04-14 00:12:07 96,768 ----a-w C:\WINDOWS\system32\srvsvc.dll
- 2004-08-04 11:00:00 704,512 -c--a-w C:\WINDOWS\system32\ss3dfo.scr
+ 2008-04-14 00:12:43 704,512 ----a-w C:\WINDOWS\system32\ss3dfo.scr
- 2004-08-04 11:00:00 19,968 -c--a-w C:\WINDOWS\system32\ssbezier.scr
+ 2008-04-14 00:12:43 19,968 ----a-w C:\WINDOWS\system32\ssbezier.scr
- 2004-08-04 11:00:00 34,816 ----a-w C:\WINDOWS\system32\ssdpapi.dll
+ 2008-04-14 00:12:07 34,816 ----a-w C:\WINDOWS\system32\ssdpapi.dll
- 2004-08-04 11:00:00 71,680 ----a-w C:\WINDOWS\system32\ssdpsrv.dll
+ 2008-04-14 00:12:07 71,680 ----a-w C:\WINDOWS\system32\ssdpsrv.dll
- 2004-08-04 11:00:00 393,216 -c--a-w C:\WINDOWS\system32\ssflwbox.scr
+ 2008-04-14 00:12:43 393,216 ----a-w C:\WINDOWS\system32\ssflwbox.scr
- 2004-08-04 11:00:00 20,992 -c--a-w C:\WINDOWS\system32\ssmarque.scr
+ 2008-04-14 00:12:44 20,992 ----a-w C:\WINDOWS\system32\ssmarque.scr
- 2004-08-04 11:00:00 47,104 -c--a-w C:\WINDOWS\system32\ssmypics.scr
+ 2008-04-14 00:12:44 47,104 ----a-w C:\WINDOWS\system32\ssmypics.scr
- 2004-08-04 11:00:00 18,944 -c--a-w C:\WINDOWS\system32\ssmyst.scr
+ 2008-04-14 00:12:44 18,944 ----a-w C:\WINDOWS\system32\ssmyst.scr
- 2004-08-04 11:00:00 610,304 -c--a-w C:\WINDOWS\system32\sspipes.scr
+ 2008-04-14 00:12:44 610,304 ----a-w C:\WINDOWS\system32\sspipes.scr
- 2004-08-04 11:00:00 14,336 -c--a-w C:\WINDOWS\system32\ssstars.scr
+ 2008-04-14 00:12:44 14,336 ----a-w C:\WINDOWS\system32\ssstars.scr
- 2004-08-04 11:00:00 679,936 -c--a-w C:\WINDOWS\system32\sstext3d.scr
+ 2008-04-14 00:12:44 679,936 ----a-w C:\WINDOWS\system32\sstext3d.scr
- 2004-08-04 11:00:00 54,272 -c--a-w C:\WINDOWS\system32\stclient.dll
+ 2008-04-14 00:12:07 59,392 ----a-w C:\WINDOWS\system32\stclient.dll
- 2004-08-04 11:00:00 67,584 ----a-w C:\WINDOWS\system32\sti.dll
+ 2008-04-14 00:12:07 68,096 ----a-w C:\WINDOWS\system32\sti.dll
- 2004-08-04 11:00:00 136,704 ----a-w C:\WINDOWS\system32\sti_ci.dll
+ 2008-04-14 00:12:07 136,704 ----a-w C:\WINDOWS\system32\sti_ci.dll
- 2004-08-04 11:00:00 14,848 ----a-w C:\WINDOWS\system32\stimon.exe
+ 2008-04-14 00:12:36 14,848 ----a-w C:\WINDOWS\system32\stimon.exe
- 2004-08-04 11:00:00 121,856 ----a-w C:\WINDOWS\system32\stobject.dll
+ 2008-04-14 00:12:07 121,856 ----a-w C:\WINDOWS\system32\stobject.dll
- 2004-08-04 06:56:46 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
+ 2008-04-14 00:12:07 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
- 2006-08-21 17:52:08 246,814 ----a-w C:\WINDOWS\system32\strmdll.dll
+ 2008-04-14 00:12:07 246,814 ----a-w C:\WINDOWS\system32\strmdll.dll
- 2004-08-04 11:00:00 75,776 ----a-w C:\WINDOWS\system32\strmfilt.dll
+ 2008-04-14 00:12:07 75,776 ----a-w C:\WINDOWS\system32\strmfilt.dll
- 2004-08-04 11:00:00 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
+ 2008-04-14 00:12:36 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
- 2006-10-19 13:56:32 713,216 ----a-w C:\WINDOWS\system32\sxs.dll
+ 2008-04-14 00:12:07 713,216 ----a-w C:\WINDOWS\system32\sxs.dll
- 2004-08-04 11:00:00 57,856 -c--a-w C:\WINDOWS\system32\synceng.dll
+ 2008-04-14 00:12:07 57,856 ----a-w C:\WINDOWS\system32\synceng.dll
- 2004-08-04 11:00:00 191,488 -c--a-w C:\WINDOWS\system32\syncui.dll
+ 2008-04-14 00:12:07 191,488 ----a-w C:\WINDOWS\system32\syncui.dll
- 2004-08-04 11:00:00 105,984 ----a-w C:\WINDOWS\system32\sysocmgr.exe
+ 2008-04-14 00:12:37 106,496 ----a-w C:\WINDOWS\system32\sysocmgr.exe
- 2004-08-04 11:00:00 984,576 ----a-w C:\WINDOWS\system32\syssetup.dll
+ 2008-04-14 00:12:07 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
- 2005-10-17 21:14:46 118,272 ----a-w C:\WINDOWS\system32\t2embed.dll
+ 2008-04-14 00:12:07 117,760 ----a-w C:\WINDOWS\system32\t2embed.dll
- 2004-08-04 11:00:00 858,624 -c--a-w C:\WINDOWS\system32\tapi3.dll
+ 2008-04-14 00:12:07 858,624 ----a-w C:\WINDOWS\system32\tapi3.dll
- 2004-08-04 11:00:00 181,760 ----a-w C:\WINDOWS\system32\tapi32.dll
+ 2008-04-14 00:12:07 181,760 ----a-w C:\WINDOWS\system32\tapi32.dll
- 2005-07-08 16:27:56 249,344 ----a-w C:\WINDOWS\system32\tapisrv.dll
+ 2008-04-14 00:12:07 249,856 ----a-w C:\WINDOWS\system32\tapisrv.dll
- 2004-08-04 11:00:00 135,680 ----a-w C:\WINDOWS\system32\taskmgr.exe
+ 2008-04-14 00:12:37 135,680 ----a-w C:\WINDOWS\system32\taskmgr.exe
- 2004-08-04 11:00:00 14,848 -c--a-w C:\WINDOWS\system32\tcpmib.dll
+ 2008-04-14 00:12:07 14,848 ----a-w C:\WINDOWS\system32\tcpmib.dll
- 2004-08-04 11:00:00 45,568 ----a-w C:\WINDOWS\system32\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 ----a-w C:\WINDOWS\system32\tcpmon.dll
- 2004-08-04 11:00:00 45,568 -c--a-w C:\WINDOWS\system32\tcpmonui.dll
+ 2008-04-14 00:12:07 45,568 ----a-w C:\WINDOWS\system32\tcpmonui.dll
- 2005-05-10 23:45:48 75,776 ----a-w C:\WINDOWS\system32\telnet.exe
+ 2008-04-14 00:12:37 75,776 ----a-w C:\WINDOWS\system32\telnet.exe
- 2004-08-04 11:00:00 358,400 ----a-w C:\WINDOWS\system32\termmgr.dll
+ 2008-04-14 00:12:07 358,400 ----a-w C:\WINDOWS\system32\termmgr.dll
- 2004-08-04 11:00:00 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
+ 2008-04-14 00:12:07 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
- 2004-08-04 11:00:00 385,536 ----a-w C:\WINDOWS\system32\themeui.dll
+ 2008-04-14 00:12:07 385,536 ----a-w C:\WINDOWS\system32\themeui.dll
- 2004-08-04 11:00:00 347,136 ----a-w C:\WINDOWS\system32\tourstart.exe
+ 2008-04-14 00:12:38 347,136 ----a-w C:\WINDOWS\system32\tourstart.exe
- 2004-08-04 11:00:00 12,288 ----a-w C:\WINDOWS\system32\tracert.exe
+ 2008-04-14 00:12:38 12,288 ----a-w C:\WINDOWS\system32\tracert.exe
- 2004-08-04 11:00:00 11,264 -c--a-w C:\WINDOWS\system32\tree.com
+ 2008-04-14 00:12:42 12,800 ----a-w C:\WINDOWS\system32\tree.com
- 2004-08-04 11:00:00 90,624 ----a-w C:\WINDOWS\system32\trkwks.dll
+ 2008-04-14 00:12:07 90,112 ----a-w C:\WINDOWS\system32\trkwks.dll
- 2004-08-04 11:00:00 93,696 ----a-w C:\WINDOWS\system32\tscfgwmi.dll
+ 2008-04-14 00:12:07 93,696 ----a-w C:\WINDOWS\system32\tscfgwmi.dll
- 2004-08-04 11:00:00 12,168 -c--a-w C:\WINDOWS\system32\tsddd.dll
+ 2008-04-14 00:13:21 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
+ 2008-04-14 00:12:07 53,248 ------w C:\WINDOWS\system32\tsgqec.dll
+ 2008-04-14 00:12:07 50,688 ------w C:\WINDOWS\system32\tspkg.dll
- 2004-08-04 11:00:00 44,032 ----a-w C:\WINDOWS\system32\twext.dll
+ 2008-04-14 00:12:07 57,856 ----a-w C:\WINDOWS\system32\twext.dll
- 2005-07-26 04:39:49 101,376 ----a-w C:\WINDOWS\system32\txflog.dll
+ 2008-04-14 00:12:07 101,376 ----a-w C:\WINDOWS\system32\txflog.dll
- 2008-07-14 11:09:18 62,976 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-04-14 00:12:38 60,416 ------w C:\WINDOWS\system32\tzchange.exe
- 2004-08-04 11:00:00 25,600 -c--a-w C:\WINDOWS\system32\udhisapi.dll
+ 2008-04-14 00:12:07 26,624 ----a-w C:\WINDOWS\system32\udhisapi.dll
- 2004-08-04 11:00:00 275,456 -c--a-w C:\WINDOWS\system32\ulib.dll
+ 2008-04-14 00:12:07 275,456 ----a-w C:\WINDOWS\system32\ulib.dll
- 2004-08-04 11:00:00 35,840 -c--a-w C:\WINDOWS\system32\umandlg.dll
+ 2008-04-14 00:12:07 35,840 ----a-w C:\WINDOWS\system32\umandlg.dll
- 2005-08-23 03:35:42 123,392 ----a-w C:\WINDOWS\system32\umpnpmgr.dll
+ 2008-04-14 00:12:07 123,392 ----a-w C:\WINDOWS\system32\umpnpmgr.dll
+ 2004-12-07 18:11:34 258,352 ----a-w C:\WINDOWS\system32\unicows.dll
- 2004-08-04 11:00:00 74,240 ----a-w C:\WINDOWS\system32\unimdmat.dll
+ 2008-04-14 00:12:07 74,240 ----a-w C:\WINDOWS\system32\unimdmat.dll
- 2004-08-04 11:00:00 13,824 ----a-w C:\WINDOWS\system32\uniplat.dll
+ 2008-04-14 00:12:07 13,824 ----a-w C:\WINDOWS\system32\uniplat.dll
- 2004-08-04 11:00:00 316,416 -c--a-w C:\WINDOWS\system32\untfs.dll
+ 2008-04-14 00:12:07 316,416 ----a-w C:\WINDOWS\system32\untfs.dll
- 2004-08-04 11:00:00 132,608 ----a-w C:\WINDOWS\system32\upnp.dll
+ 2008-04-14 00:12:08 133,632 ----a-w C:\WINDOWS\system32\upnp.dll
breakawayjade
2008-10-17, 02:59
- 2004-08-04 11:00:00 16,896 ----a-w C:\WINDOWS\system32\upnpcont.exe
+ 2008-04-14 00:12:38 16,896 ----a-w C:\WINDOWS\system32\upnpcont.exe
- 2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll
+ 2008-04-14 00:12:08 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll
- 2004-08-04 11:00:00 239,616 -c--a-w C:\WINDOWS\system32\upnpui.dll
+ 2008-04-14 00:12:08 239,616 ----a-w C:\WINDOWS\system32\upnpui.dll
- 2004-08-04 11:00:00 18,432 ----a-w C:\WINDOWS\system32\ups.exe
+ 2008-04-14 00:12:38 18,432 ----a-w C:\WINDOWS\system32\ups.exe
- 2004-08-04 11:00:00 16,896 ----a-w C:\WINDOWS\system32\usbmon.dll
+ 2008-04-14 00:12:08 16,896 ----a-w C:\WINDOWS\system32\usbmon.dll
- 2004-08-04 06:56:48 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
+ 2008-04-14 00:12:08 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
- 2008-10-04 19:14:17 577,536 ----a-w C:\WINDOWS\system32\user32.DLL
+ 2008-04-14 00:12:08 578,560 ----a-w C:\WINDOWS\system32\user32.dll
- 2004-08-04 11:00:00 723,456 ----a-w C:\WINDOWS\system32\userenv.dll
+ 2008-04-14 00:12:08 727,040 ----a-w C:\WINDOWS\system32\userenv.dll
- 2004-08-04 11:00:00 24,576 ----a-w C:\WINDOWS\system32\userinit.exe
+ 2008-04-14 00:12:38 26,112 ----a-w C:\WINDOWS\system32\userinit.exe
+ 2008-04-13 16:44:16 17,920 ------w C:\WINDOWS\system32\usmt\cobramsg.dll
- 2004-08-04 11:00:00 123,904 -c--a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 133,120 ----a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 115,200 ------w C:\WINDOWS\system32\usmt\guitrna.dll
- 2004-08-04 11:00:00 4,096 -c--a-w C:\WINDOWS\system32\usmt\iconlib.dll
+ 2008-04-13 16:44:29 2,560 ----a-w C:\WINDOWS\system32\usmt\iconlib.dll
- 2004-08-04 11:00:00 19,968 -c--a-w C:\WINDOWS\system32\usmt\log.dll
+ 2008-04-14 00:11:56 19,968 ----a-w C:\WINDOWS\system32\usmt\log.dll
- 2004-08-04 11:00:00 201,216 -c--a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 274,432 ----a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 261,120 ------w C:\WINDOWS\system32\usmt\migisma.dll
- 2004-08-04 11:00:00 103,424 -c--a-w C:\WINDOWS\system32\usmt\migload.exe
+ 2008-04-14 00:12:25 103,936 ----a-w C:\WINDOWS\system32\usmt\migload.exe
- 2004-08-04 11:00:00 240,128 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 245,248 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 241,152 ------w C:\WINDOWS\system32\usmt\migwiza.exe
- 2004-08-04 11:00:00 202,752 -c--a-w C:\WINDOWS\system32\usmt\script.dll
+ 2008-04-14 00:12:05 215,552 ----a-w C:\WINDOWS\system32\usmt\script.dll
+ 2008-04-14 00:12:05 199,680 ------w C:\WINDOWS\system32\usmt\scripta.dll
- 2004-08-04 11:00:00 168,960 -c--a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 193,024 ----a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 173,568 ------w C:\WINDOWS\system32\usmt\sysmoda.dll
- 2004-08-04 11:00:00 406,528 ----a-w C:\WINDOWS\system32\usp10.dll
+ 2008-04-14 00:12:08 406,016 ----a-w C:\WINDOWS\system32\usp10.dll
- 2004-08-04 11:00:00 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
+ 2008-04-14 00:12:38 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
- 2004-08-04 11:00:00 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
+ 2008-04-14 00:12:08 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
- 2004-08-04 11:00:00 30,749 ----a-w C:\WINDOWS\system32\vbajet32.dll
+ 2008-04-14 00:12:08 30,749 ----a-w C:\WINDOWS\system32\vbajet32.dll
- 2006-11-08 05:03:36 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2008-05-09 10:53:40 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2004-08-04 11:00:00 26,112 ----a-w C:\WINDOWS\system32\vdmdbg.dll
+ 2008-04-14 00:12:08 26,112 ----a-w C:\WINDOWS\system32\vdmdbg.dll
- 2004-08-04 11:00:00 51,712 -c--a-w C:\WINDOWS\system32\vdmredir.dll
+ 2008-04-14 00:12:08 51,712 ----a-w C:\WINDOWS\system32\vdmredir.dll
- 2006-03-17 00:38:01 28,672 ------w C:\WINDOWS\system32\verclsid.exe
+ 2008-04-14 00:12:38 28,672 ------w C:\WINDOWS\system32\verclsid.exe
- 2004-08-04 11:00:00 13,312 -c--a-w C:\WINDOWS\system32\verifier.dll
+ 2008-04-14 00:12:08 26,624 ----a-w C:\WINDOWS\system32\verifier.dll
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\version.dll
+ 2008-04-14 00:12:08 18,944 ----a-w C:\WINDOWS\system32\version.dll
- 2004-08-04 11:00:00 430,592 ----a-w C:\WINDOWS\system32\vssapi.dll
+ 2008-04-14 00:12:08 430,592 ----a-w C:\WINDOWS\system32\vssapi.dll
- 2004-08-04 11:00:00 289,792 ----a-w C:\WINDOWS\system32\vssvc.exe
+ 2008-04-14 00:12:38 289,792 ----a-w C:\WINDOWS\system32\vssvc.exe
- 2004-08-04 11:00:00 174,592 ----a-w C:\WINDOWS\system32\w32time.dll
+ 2008-04-14 00:12:08 175,104 ----a-w C:\WINDOWS\system32\w32time.dll
- 2004-08-04 11:00:00 15,872 ----a-w C:\WINDOWS\system32\w3ssl.dll
+ 2008-04-14 00:12:08 15,872 ----a-w C:\WINDOWS\system32\w3ssl.dll
- 2004-08-04 11:00:00 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
+ 2008-04-13 18:44:59 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
- 2004-08-04 11:00:00 208,896 -c--a-w C:\WINDOWS\system32\wavemsp.dll
+ 2008-04-14 00:12:08 215,552 ----a-w C:\WINDOWS\system32\wavemsp.dll
- 2004-08-04 11:00:00 1,352,192 ----a-w C:\WINDOWS\system32\wbem\cimwin32.dll
+ 2008-04-14 00:11:50 1,358,848 ----a-w C:\WINDOWS\system32\wbem\cimwin32.dll
- 2004-08-04 11:00:00 247,808 ----a-w C:\WINDOWS\system32\wbem\esscli.dll
+ 2008-04-14 00:11:53 247,808 ----a-w C:\WINDOWS\system32\wbem\esscli.dll
- 2004-08-04 11:00:00 22,016 -c--a-w C:\WINDOWS\system32\wbem\evntrprv.dll
+ 2008-04-14 00:11:53 21,504 ----a-w C:\WINDOWS\system32\wbem\evntrprv.dll
- 2004-08-04 11:00:00 472,064 ----a-w C:\WINDOWS\system32\wbem\fastprox.dll
+ 2008-04-14 00:11:53 472,064 ----a-w C:\WINDOWS\system32\wbem\fastprox.dll
- 2004-08-04 11:00:00 185,856 ----a-w C:\WINDOWS\system32\wbem\framedyn.dll
+ 2008-04-14 00:11:53 185,344 ----a-w C:\WINDOWS\system32\wbem\framedyn.dll
- 2004-08-04 11:00:00 24,576 -c--a-w C:\WINDOWS\system32\wbem\krnlprov.dll
+ 2008-04-14 00:11:56 24,576 ----a-w C:\WINDOWS\system32\wbem\krnlprov.dll
- 2004-08-04 11:00:00 16,384 -c--a-w C:\WINDOWS\system32\wbem\mofcomp.exe
+ 2008-04-14 00:12:26 16,384 ----a-w C:\WINDOWS\system32\wbem\mofcomp.exe
- 2004-08-04 11:00:00 123,904 -c--a-w C:\WINDOWS\system32\wbem\mofd.dll
+ 2008-04-14 00:11:57 123,904 ----a-w C:\WINDOWS\system32\wbem\mofd.dll
- 2004-08-04 11:00:00 47,104 ----a-w C:\WINDOWS\system32\wbem\ncprov.dll
+ 2008-04-14 00:12:01 47,104 ----a-w C:\WINDOWS\system32\wbem\ncprov.dll
- 2004-08-04 11:00:00 212,992 -c--a-w C:\WINDOWS\system32\wbem\ntevt.dll
+ 2008-04-14 00:12:02 212,992 ----a-w C:\WINDOWS\system32\wbem\ntevt.dll
- 2004-08-04 11:00:00 237,056 -c--a-w C:\WINDOWS\system32\wbem\provthrd.dll
+ 2008-04-14 00:12:03 237,056 ----a-w C:\WINDOWS\system32\wbem\provthrd.dll
- 2004-08-04 11:00:00 177,152 ----a-w C:\WINDOWS\system32\wbem\repdrvfs.dll
+ 2008-04-14 00:12:04 178,176 ----a-w C:\WINDOWS\system32\wbem\repdrvfs.dll
- 2004-08-04 11:00:00 36,864 -c--a-w C:\WINDOWS\system32\wbem\scrcons.exe
+ 2008-04-14 00:12:34 36,352 ----a-w C:\WINDOWS\system32\wbem\scrcons.exe
- 2004-08-04 11:00:00 86,528 -c--a-w C:\WINDOWS\system32\wbem\stdprov.dll
+ 2008-04-14 00:12:07 86,528 ----a-w C:\WINDOWS\system32\wbem\stdprov.dll
- 2004-08-04 11:00:00 131,584 -c--a-w C:\WINDOWS\system32\wbem\viewprov.dll
+ 2008-04-14 00:12:08 131,584 ----a-w C:\WINDOWS\system32\wbem\viewprov.dll
- 2004-08-04 11:00:00 196,608 -c--a-w C:\WINDOWS\system32\wbem\wbemcntl.dll
+ 2008-04-14 00:12:08 196,608 ----a-w C:\WINDOWS\system32\wbem\wbemcntl.dll
- 2004-08-04 11:00:00 214,528 ----a-w C:\WINDOWS\system32\wbem\wbemcomn.dll
+ 2008-04-14 00:12:08 214,528 ----a-w C:\WINDOWS\system32\wbem\wbemcomn.dll
- 2004-08-04 11:00:00 71,680 ----a-w C:\WINDOWS\system32\wbem\wbemcons.dll
+ 2008-04-14 00:12:08 71,680 ----a-w C:\WINDOWS\system32\wbem\wbemcons.dll
- 2004-08-04 11:00:00 530,944 ----a-w C:\WINDOWS\system32\wbem\wbemcore.dll
+ 2008-04-14 00:12:08 531,456 ----a-w C:\WINDOWS\system32\wbem\wbemcore.dll
- 2004-08-04 11:00:00 178,176 -c--a-w C:\WINDOWS\system32\wbem\wbemdisp.dll
+ 2008-04-14 00:12:08 178,176 ----a-w C:\WINDOWS\system32\wbem\wbemdisp.dll
- 2004-08-04 11:00:00 273,920 ----a-w C:\WINDOWS\system32\wbem\wbemess.dll
+ 2008-04-14 00:12:08 273,920 ----a-w C:\WINDOWS\system32\wbem\wbemess.dll
- 2004-08-04 11:00:00 43,008 -c--a-w C:\WINDOWS\system32\wbem\wbemperf.dll
+ 2008-04-14 00:12:08 43,008 ----a-w C:\WINDOWS\system32\wbem\wbemperf.dll
- 2004-08-04 11:00:00 18,944 ----a-w C:\WINDOWS\system32\wbem\wbemprox.dll
+ 2008-04-14 00:12:08 18,944 ----a-w C:\WINDOWS\system32\wbem\wbemprox.dll
- 2004-08-04 11:00:00 43,520 ----a-w C:\WINDOWS\system32\wbem\wbemsvc.dll
+ 2008-04-14 00:12:08 43,520 ----a-w C:\WINDOWS\system32\wbem\wbemsvc.dll
- 2004-08-04 11:00:00 116,224 -c--a-w C:\WINDOWS\system32\wbem\wbemtest.exe
+ 2008-04-14 00:12:39 116,224 ----a-w C:\WINDOWS\system32\wbem\wbemtest.exe
- 2004-08-04 11:00:00 197,120 -c--a-w C:\WINDOWS\system32\wbem\wbemupgd.dll
+ 2008-04-14 00:12:08 197,120 ----a-w C:\WINDOWS\system32\wbem\wbemupgd.dll
- 2004-08-04 11:00:00 196,608 -c--a-w C:\WINDOWS\system32\wbem\wmiadap.exe
+ 2008-04-14 00:12:40 196,608 ----a-w C:\WINDOWS\system32\wbem\wmiadap.exe
- 2004-08-04 11:00:00 6,656 -c--a-w C:\WINDOWS\system32\wbem\wmiapres.dll
+ 2008-04-13 17:10:20 6,656 ----a-w C:\WINDOWS\system32\wbem\wmiapres.dll
- 2004-08-04 11:00:00 89,088 -c--a-w C:\WINDOWS\system32\wbem\wmiaprpl.dll
+ 2008-04-14 00:12:09 88,576 ----a-w C:\WINDOWS\system32\wbem\wmiaprpl.dll
- 2004-08-04 11:00:00 126,464 ----a-w C:\WINDOWS\system32\wbem\wmiapsrv.exe
+ 2008-04-14 00:12:40 126,464 ----a-w C:\WINDOWS\system32\wbem\wmiapsrv.exe
- 2004-08-04 11:00:00 60,928 -c--a-w C:\WINDOWS\system32\wbem\wmicookr.dll
+ 2008-04-14 00:12:09 60,928 ----a-w C:\WINDOWS\system32\wbem\wmicookr.dll
- 2004-08-04 11:00:00 140,800 -c--a-w C:\WINDOWS\system32\wbem\wmidcprv.dll
+ 2008-04-14 00:12:09 140,800 ----a-w C:\WINDOWS\system32\wbem\wmidcprv.dll
- 2004-08-04 11:00:00 156,672 -c--a-w C:\WINDOWS\system32\wbem\wmipcima.dll
+ 2008-04-14 00:12:09 156,672 ----a-w C:\WINDOWS\system32\wbem\wmipcima.dll
- 2004-08-04 11:00:00 132,096 -c--a-w C:\WINDOWS\system32\wbem\wmipdskq.dll
+ 2008-04-14 00:12:09 132,096 ----a-w C:\WINDOWS\system32\wbem\wmipdskq.dll
- 2004-08-04 11:00:00 62,464 -c--a-w C:\WINDOWS\system32\wbem\wmipiprt.dll
+ 2008-04-14 00:12:09 61,952 ----a-w C:\WINDOWS\system32\wbem\wmipiprt.dll
- 2004-08-04 11:00:00 62,976 -c--a-w C:\WINDOWS\system32\wbem\wmipjobj.dll
+ 2008-04-14 00:12:09 62,464 ----a-w C:\WINDOWS\system32\wbem\wmipjobj.dll
- 2004-08-04 11:00:00 144,896 -c--a-w C:\WINDOWS\system32\wbem\wmiprov.dll
+ 2008-04-14 00:12:09 144,896 ----a-w C:\WINDOWS\system32\wbem\wmiprov.dll
- 2004-08-04 11:00:00 437,248 ----a-w C:\WINDOWS\system32\wbem\wmiprvsd.dll
+ 2008-04-14 00:12:09 437,248 ----a-w C:\WINDOWS\system32\wbem\wmiprvsd.dll
- 2004-08-04 11:00:00 218,112 ----a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
+ 2008-04-14 00:12:40 218,112 ----a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
- 2004-08-04 11:00:00 41,472 -c--a-w C:\WINDOWS\system32\wbem\wmipsess.dll
+ 2008-04-14 00:12:09 41,472 ----a-w C:\WINDOWS\system32\wbem\wmipsess.dll
- 2004-08-04 11:00:00 144,896 ----a-w C:\WINDOWS\system32\wbem\wmisvc.dll
+ 2008-04-14 00:12:09 144,896 ----a-w C:\WINDOWS\system32\wbem\wmisvc.dll
- 2004-08-04 11:00:00 95,232 ----a-w C:\WINDOWS\system32\wbem\wmiutils.dll
+ 2008-04-14 00:12:09 95,232 ----a-w C:\WINDOWS\system32\wbem\wmiutils.dll
- 2006-03-24 04:37:50 49,152 ----a-w C:\WINDOWS\system32\wdigest.dll
+ 2008-04-14 00:12:08 49,152 ----a-w C:\WINDOWS\system32\wdigest.dll
- 2004-08-04 06:56:58 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
+ 2008-04-14 00:12:45 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
- 2006-01-04 03:35:05 68,096 ----a-w C:\WINDOWS\system32\webclnt.dll
+ 2008-04-14 00:12:08 68,096 ----a-w C:\WINDOWS\system32\webclnt.dll
- 2004-08-04 11:00:00 135,680 ----a-w C:\WINDOWS\system32\webvw.dll
+ 2008-04-14 00:12:08 135,680 ----a-w C:\WINDOWS\system32\webvw.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\wextract.exe
+ 2008-04-14 00:12:39 65,024 ----a-w C:\WINDOWS\system32\wextract.exe
- 2004-08-04 11:00:00 433,664 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
+ 2008-04-14 00:12:39 433,664 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
- 2004-08-04 11:00:00 463,360 ----a-w C:\WINDOWS\system32\wiadefui.dll
+ 2008-04-14 00:12:08 463,360 ----a-w C:\WINDOWS\system32\wiadefui.dll
- 2004-08-04 11:00:00 124,416 ----a-w C:\WINDOWS\system32\wiadss.dll
+ 2008-04-14 00:12:08 124,416 ----a-w C:\WINDOWS\system32\wiadss.dll
- 2004-08-04 11:00:00 75,776 ----a-w C:\WINDOWS\system32\wiascr.dll
+ 2008-04-14 00:12:08 75,776 ----a-w C:\WINDOWS\system32\wiascr.dll
- 2006-12-19 18:16:47 333,824 ----a-w C:\WINDOWS\system32\wiaservc.dll
+ 2008-04-14 00:12:08 333,824 ----a-w C:\WINDOWS\system32\wiaservc.dll
- 2004-08-04 11:00:00 589,312 ----a-w C:\WINDOWS\system32\wiashext.dll
+ 2008-04-14 00:12:08 589,312 ----a-w C:\WINDOWS\system32\wiashext.dll
- 2004-08-04 11:00:00 111,104 ----a-w C:\WINDOWS\system32\wiavideo.dll
+ 2008-04-14 00:12:08 111,104 ----a-w C:\WINDOWS\system32\wiavideo.dll
- 2008-03-19 09:47:00 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
+ 2008-04-13 19:30:10 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
- 2004-08-04 11:00:00 101,888 ----a-w C:\WINDOWS\system32\win32spl.dll
+ 2008-04-14 00:12:08 102,400 ----a-w C:\WINDOWS\system32\win32spl.dll
- 2004-08-04 11:00:00 937,984 -c--a-w C:\WINDOWS\system32\winbrand.dll
+ 2008-04-13 16:48:53 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
+ 2008-04-14 00:12:08 712,704 ------w C:\WINDOWS\system32\windowscodecs.dll
+ 2008-04-14 00:12:08 346,112 ------w C:\WINDOWS\system32\windowscodecsext.dll
- 2004-08-04 11:00:00 351,232 ----a-w C:\WINDOWS\system32\winhttp.dll
+ 2008-04-14 00:12:08 354,304 ----a-w C:\WINDOWS\system32\winhttp.dll
- 2004-08-04 11:00:00 32,768 ----a-w C:\WINDOWS\system32\winipsec.dll
+ 2008-04-14 00:12:09 32,256 ----a-w C:\WINDOWS\system32\winipsec.dll
- 2004-08-04 11:00:00 502,272 ----a-w C:\WINDOWS\system32\winlogon.exe
+ 2008-04-14 00:12:39 507,904 ----a-w C:\WINDOWS\system32\winlogon.exe
- 2004-08-04 11:00:00 176,128 ----a-w C:\WINDOWS\system32\winmm.dll
+ 2008-04-14 00:12:09 176,128 ----a-w C:\WINDOWS\system32\winmm.dll
- 2004-08-04 11:00:00 764,928 -c--a-w C:\WINDOWS\system32\winntbbu.dll
+ 2008-04-14 00:11:11 756,224 ----a-w C:\WINDOWS\system32\winntbbu.dll
- 2004-08-04 11:00:00 16,896 ----a-w C:\WINDOWS\system32\winrnr.dll
+ 2008-04-14 00:12:09 16,896 ----a-w C:\WINDOWS\system32\winrnr.dll
- 2004-08-04 11:00:00 99,328 ----a-w C:\WINDOWS\system32\winscard.dll
+ 2008-04-14 00:12:09 99,328 ----a-w C:\WINDOWS\system32\winscard.dll
- 2004-08-04 11:00:00 17,408 ----a-w C:\WINDOWS\system32\winshfhc.dll
+ 2008-04-14 00:12:09 17,408 ----a-w C:\WINDOWS\system32\winshfhc.dll
- 2004-08-04 11:00:00 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
+ 2008-04-14 00:12:45 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
- 2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
+ 2008-04-14 00:12:09 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
- 2004-08-04 11:00:00 53,760 ----a-w C:\WINDOWS\system32\winsta.dll
+ 2008-04-14 00:12:09 53,760 ----a-w C:\WINDOWS\system32\winsta.dll
- 2004-08-04 11:00:00 176,640 ----a-w C:\WINDOWS\system32\wintrust.dll
+ 2008-04-14 00:12:09 176,640 ----a-w C:\WINDOWS\system32\wintrust.dll
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\system32\winver.exe
+ 2008-04-14 00:12:40 5,632 ----a-w C:\WINDOWS\system32\winver.exe
- 2006-08-17 12:28:27 132,096 ----a-w C:\WINDOWS\system32\wkssvc.dll
+ 2008-04-14 00:12:09 132,096 ----a-w C:\WINDOWS\system32\wkssvc.dll
+ 2008-04-14 00:12:09 69,120 ------w C:\WINDOWS\system32\wlanapi.dll
- 2004-08-04 11:00:00 172,032 ----a-w C:\WINDOWS\system32\wldap32.dll
+ 2008-04-14 00:12:09 172,032 ----a-w C:\WINDOWS\system32\wldap32.dll
- 2004-08-04 11:00:00 92,672 ----a-w C:\WINDOWS\system32\wlnotify.dll
+ 2008-04-14 00:12:09 92,672 ----a-w C:\WINDOWS\system32\wlnotify.dll
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
+ 2008-04-14 00:11:15 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
+ 2008-04-14 00:12:09 276,992 ------w C:\WINDOWS\system32\wmphoto.dll
- 2004-08-04 11:00:00 115,200 ----a-w C:\WINDOWS\system32\wmsdmoe.dll
+ 2008-04-14 00:12:09 115,200 ----a-w C:\WINDOWS\system32\wmsdmoe.dll
- 2004-08-04 11:00:00 303,616 -c--a-w C:\WINDOWS\system32\wmstream.dll
+ 2008-04-14 00:12:10 303,616 ----a-w C:\WINDOWS\system32\wmstream.dll
- 2004-08-04 11:00:00 264,192 ----a-w C:\WINDOWS\system32\wow32.dll
+ 2008-04-14 00:12:10 264,192 ----a-w C:\WINDOWS\system32\wow32.dll
- 2004-08-04 11:00:00 32,256 ----a-w C:\WINDOWS\system32\wpabaln.exe
+ 2008-04-14 00:12:40 32,256 ----a-w C:\WINDOWS\system32\wpabaln.exe
- 2004-08-04 11:00:00 32,256 ----a-w C:\WINDOWS\system32\wpnpinst.exe
+ 2008-04-14 00:12:41 11,264 ----a-w C:\WINDOWS\system32\wpnpinst.exe
- 2004-08-04 11:00:00 82,944 ----a-w C:\WINDOWS\system32\ws2_32.dll
+ 2008-04-14 00:12:10 82,432 ----a-w C:\WINDOWS\system32\ws2_32.dll
- 2004-08-04 11:00:00 19,968 ----a-w C:\WINDOWS\system32\ws2help.dll
+ 2008-04-14 00:12:10 19,968 ----a-w C:\WINDOWS\system32\ws2help.dll
- 2004-08-04 11:00:00 13,824 ----a-w C:\WINDOWS\system32\wscntfy.exe
+ 2008-04-14 00:12:41 13,824 ----a-w C:\WINDOWS\system32\wscntfy.exe
- 2004-08-04 11:00:00 114,688 ----a-w C:\WINDOWS\system32\wscript.exe
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
- 2004-08-04 11:00:00 81,408 ----a-w C:\WINDOWS\system32\wscsvc.dll
+ 2008-04-14 00:12:10 80,896 ----a-w C:\WINDOWS\system32\wscsvc.dll
- 2004-08-04 11:00:00 108,032 ----a-w C:\WINDOWS\system32\wshbth.dll
+ 2008-04-14 00:12:10 108,032 ----a-w C:\WINDOWS\system32\wshbth.dll
- 2004-08-04 11:00:00 28,672 -c--a-w C:\WINDOWS\system32\wshcon.dll
+ 2008-04-14 00:12:10 36,864 ----a-w C:\WINDOWS\system32\wshcon.dll
- 2004-08-04 11:00:00 65,536 ----a-w C:\WINDOWS\system32\wshext.dll
+ 2008-05-09 10:53:40 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
- 2004-08-04 11:00:00 14,336 -c--a-w C:\WINDOWS\system32\wship6.dll
+ 2008-04-14 00:12:10 14,336 ----a-w C:\WINDOWS\system32\wship6.dll
- 2004-08-04 11:00:00 11,776 -c--a-w C:\WINDOWS\system32\WshRm.dll
+ 2008-04-14 00:12:10 11,264 ----a-w C:\WINDOWS\system32\wshrm.dll
- 2004-08-04 11:00:00 19,968 ----a-w C:\WINDOWS\system32\wshtcpip.dll
+ 2008-04-14 00:12:10 19,456 ----a-w C:\WINDOWS\system32\wshtcpip.dll
- 2004-08-04 11:00:00 42,496 -c--a-w C:\WINDOWS\system32\wsnmp32.dll
+ 2008-04-14 00:12:10 41,984 ----a-w C:\WINDOWS\system32\wsnmp32.dll
- 2004-08-04 11:00:00 22,528 ----a-w C:\WINDOWS\system32\wsock32.dll
+ 2008-04-14 00:12:10 22,528 ----a-w C:\WINDOWS\system32\wsock32.dll
- 2004-08-04 11:00:00 50,688 ----a-w C:\WINDOWS\system32\wstdecod.dll
+ 2008-04-14 00:12:10 50,688 ----a-w C:\WINDOWS\system32\wstdecod.dll
- 2004-08-04 11:00:00 18,432 ----a-w C:\WINDOWS\system32\wtsapi32.dll
+ 2008-04-14 00:12:10 18,432 ----a-w C:\WINDOWS\system32\wtsapi32.dll
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\system32\wuauserv.dll
+ 2008-04-14 00:12:11 6,656 ----a-w C:\WINDOWS\system32\wuauserv.dll
- 2004-08-04 11:00:00 378,368 ----a-w C:\WINDOWS\system32\wzcdlg.dll
+ 2008-04-14 00:12:11 383,488 ----a-w C:\WINDOWS\system32\wzcdlg.dll
- 2004-08-04 11:00:00 51,712 ----a-w C:\WINDOWS\system32\wzcsapi.dll
+ 2008-04-14 00:12:11 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
- 2004-08-04 11:00:00 359,936 ----a-w C:\WINDOWS\system32\wzcsvc.dll
+ 2008-04-14 00:12:11 483,840 ----a-w C:\WINDOWS\system32\wzcsvc.dll
- 2004-08-04 11:00:00 91,648 ----a-w C:\WINDOWS\system32\xactsrv.dll
+ 2008-04-14 00:12:11 91,648 ----a-w C:\WINDOWS\system32\xactsrv.dll
- 2004-08-04 11:00:00 30,720 ----a-w C:\WINDOWS\system32\xcopy.exe
+ 2008-04-14 00:12:41 30,720 ----a-w C:\WINDOWS\system32\xcopy.exe
- 2006-07-14 15:51:51 121,856 ------w C:\WINDOWS\system32\xmllite.dll
+ 2008-04-14 00:12:11 121,856 ------w C:\WINDOWS\system32\xmllite.dll
- 2004-08-04 11:00:00 129,536 ----a-w C:\WINDOWS\system32\xmlprov.dll
+ 2008-04-14 00:12:11 129,024 ----a-w C:\WINDOWS\system32\xmlprov.dll
- 2004-08-04 11:00:00 50,176 -c--a-w C:\WINDOWS\system32\xmlprovi.dll
+ 2008-04-14 00:12:11 50,176 ----a-w C:\WINDOWS\system32\xmlprovi.dll
- 2006-03-01 19:42:42 11,776 ----a-w C:\WINDOWS\system32\xolehlp.dll
+ 2008-04-14 00:12:11 11,776 ----a-w C:\WINDOWS\system32\xolehlp.dll
- 2004-08-04 11:00:00 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
+ 2008-04-13 17:39:29 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
- 2004-08-04 11:00:00 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
+ 2008-04-13 17:39:22 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
- 2004-08-04 11:00:00 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
+ 2008-04-13 17:39:24 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
- 2007-10-29 10:04:03 350,720 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-04-13 17:39:26 689,152 ----a-w C:\WINDOWS\system32\xpsp3res.dll
- 2004-08-04 11:00:00 337,920 ----a-w C:\WINDOWS\system32\zipfldr.dll
+ 2008-04-14 00:12:11 338,432 ----a-w C:\WINDOWS\system32\zipfldr.dll
- 2004-08-04 11:00:00 50,688 ----a-w C:\WINDOWS\twain_32.dll
+ 2008-04-14 00:12:07 50,688 ----a-w C:\WINDOWS\twain_32.dll
- 2004-08-04 11:00:00 283,648 ----a-w C:\WINDOWS\winhlp32.exe
+ 2008-04-14 00:12:39 283,648 ----a-w C:\WINDOWS\winhlp32.exe
- 2007-01-19 20:15:24 74,802 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2008-04-14 00:12:50 74,802 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
- 2007-01-19 20:15:24 995,383 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2008-04-14 00:12:50 995,383 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2007-01-19 20:15:24 1,011,774 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2008-04-14 00:12:50 1,011,774 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
- 2007-01-19 20:15:24 401,462 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 00:12:50 401,462 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 00:12:51 1,054,208 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
+ 2008-04-14 00:12:51 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
+ 2008-04-14 00:12:51 343,040 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
+ 2008-04-14 00:12:47 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
- 2004-08-04 11:00:00 853,504 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 00:12:49 853,504 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
- 2004-08-04 11:00:00 991,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
+ 2008-04-14 00:12:50 991,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2004-08-04 11:00:00 132,096 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
+ 2008-04-13 18:26:33 132,096 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DPAS"="C:\Program Files\DefenderPro AntiSpy\DPASNT.exe"
"KAVPersonal50"="C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kav.exe" /minimize
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Anti-Virus\\kav.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.4.2.8278-to-2.4.3.8606-enUS-downloader.exe"=
"skp66.exe"= skp66.exe:BNDMSS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2005-10-03 10995]
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2005-02-16 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1108581549.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2005-02-16 C:\WINDOWS\Tasks\WebReg 20050216112055.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 02:01]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Local Page = hxxp://www.google.com/
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Local Page = hxxp://www.google.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
O15 -: Trusted Zone: www.download.com
O17 -: HKLM\CCS\Interface\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
C:\WINDOWS\Downloaded Program Files\OberonGameHost_dbg.inf
C:\WINDOWS\Downloaded Program Files\OberonGameHost.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-15 07:14:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\DOCUME~1\MISSCA~1\LOCALS~1\Temp\RGI10.tmp 7075 bytes
**************************************************************************
.
Completion time: 2008-10-15 7:18:56
ComboFix-quarantined-files.txt 2008-10-15 14:17:46
ComboFix2.txt 2008-10-09 14:06:15
ComboFix3.txt 2008-10-09 01:30:38
ComboFix4.txt 2008-10-08 18:48:12
ComboFix5.txt 2008-10-15 14:07:52
Pre-Run: 48,772,050,944 bytes free
Post-Run: 48,762,482,688 bytes free
4479 --- E O F --- 2008-10-11 18:18:03
The reason for you posting the entire log was to see if user32.dll was still infected, and it looks like it is not :bigthumb: What we removed and the newer version of Combofix fixed it. Post one last HJT log and lets make sure nothing has comeback, and if not you will be good to go.
breakawayjade
2008-10-17, 05:51
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:50:00 PM, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Defender Pro Anti-Scam - {102BAD8B-CD05-46ff-94FF-A2C1ABD5F7D5} - C:\Program Files\Defender Pro\Defender Pro Anti-Scam\mscoree.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.download.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219236903822
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B8AEC40-AC9F-4E61-BA22-67BE0E14EC96}: NameServer = 205.171.3.65,205.171.2.65
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Defender Pro LLC - C:\Program Files\Defender Pro\Defender Pro Anti-Virus\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5432 bytes
also dont forget to help me out on some programs that i can use to keep me from getting infected again!
You are super awesome, I really appreciate all the help you've given me.
Log looks good :bigthumb:
OTMoveIt <---Drag it to the trash
ATF Cleaner <-- Yours to keep, run it now and then to clean out the clutter.
Malwarebytes <-- Yours to keep also, check for updates and run a scan now and then.
Hijackthis <---Your call, hopefully you won't need it again, if you do you can redownload it
Combofix <---Is not a general cleaning tool, just run it with supervision or you can bork your system
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
When shown the disclaimer, Select "2"
The above procedure will:
Delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Reset System Restore.
How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
TonyKlein CastleCops (http://www.castlecops.com/postlite7736-.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)
Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.
Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
Spybot Search and Destroy 1.6 (http://www.safer-networking.org/en/download/)
Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html) It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
Spyware Guard (http://www.javacoolsoftware.com/spywareguard.html) It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
IE-Spyad (http://www.pcworld.com/downloads/file/fid,23332-order,1-page,1-c,antispywaretools/description.html)
IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
Firefox 3 (http://www.mozilla.org/products/firefox/) It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
Safe Surfn
Ken