PDA

View Full Version : Can't Stop Virus Apparently Attempting To Send Emails



EasyEEE
2008-12-25, 02:21
No idea what or when I downloaded something that could have possibly given me this virus.

I use the latest Spybot, Spyware Blaster, SpywareGuard, Norton's Endpoint, and even scan with Lavasoft's Ad-aware.

All of a sudden today, I keep getting pop-ups from Symantec Email Proxy saying, "Your email message was unable to be sent because your mail server rejected the message: 451 4.3.2 Please try again later"

And

554 5.1.1 WARNING: Your email was not delivered because it appears to be spam. Questions? Contact ithelp@ucdavis.edu or (530) 754-HELP.

I don't use Outlook or Outlook Express.

I only use Gmail. Although, I recently downloaded Yahoo Messenger from their web site. I logged in, but later, I couldn't log in to the application, while I could log in to the web site version. I changed password several times, and never could again log into the application version of messenger. I just say that in case maybe something is related. Also, I had to actually re-install Messenger as it wasn't appearing in the uninstall list. It did finally appear, and I've uninstalled it.

I've also booted up in Safe Mode and ran all the above programs (except Norton's, I couldn't get their anti-virus to run in safe mode.)

Would appreciate any help. Since I started writing this, I've received 20+ Symantec Email Proxy winders. None of it making sense.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:33 PM, on 12/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 15186 bytes

Shaba
2008-12-29, 12:02
Hi EasyEEE

Download gmer.zip (http://gmer.net/gmer.zip) and save to your desktop.
alternate download site 1 (http://hype.free.googlepages.com/gmer.zip)
alternate download site 2 (http://www.castlecops.com/downloads-file-546.html)

Unzip/extract the file to its own folder. (Click here (http://www.bleepingcomputer.com/tutorials/tutorial105.html) for information on how to do this if not sure. Win 2000 users click here (http://www.bleepingcomputer.com/tutorials/tutorial106.html).
When you have done this, disconnect from the Internet and close all running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double-click on Gmer.exe to start the program.
Allow the gmer.sys driver to load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
Click on "Settings", then check the first five settings:
*System Protection and Tracing
*Processes
*Save created processes to the log
*Drivers
*Save loaded drivers to the log
You will be prompted to restart your computer. Please do so.

Run Gmer again and click on the Rootkit tab.
Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
Click on the "Scan" and wait for the scan to finish.
Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
Note: If you have any problems, try running GMER in SAFE MODE (http://www.bleepingcomputer.com/forums/tutorial61.html)"
Important! Please do not select the "Show all" checkbox during the scan..

EasyEEE
2008-12-29, 16:34
Here is the requested file. Appreciate your time.

1. The text that you have entered is too long (230280 characters). Please shorten it to 64000 characters long.

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-29 10:21:57
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.14 ----

SSDT 8A88CDD0 ZwAlertResumeThread
SSDT 8A854E70 ZwAlertThread
SSDT 8A2346E8 ZwAllocateVirtualMemory
SSDT 8A8C3990 ZwConnectPort
SSDT sptd.sys ZwCreateKey [0xB9EBE0D0]
SSDT 8A23D6E8 ZwCreateMutant
SSDT 8A6D3C30 ZwCreateThread
SSDT sptd.sys ZwEnumerateKey [0xB9EC3FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xB9EC4340]
SSDT 8A2496E8 ZwFreeVirtualMemory
SSDT 8A828858 ZwImpersonateAnonymousToken
SSDT 8A8904C8 ZwImpersonateThread
SSDT 8A6D3E78 ZwMapViewOfSection
SSDT 8A6A3108 ZwOpenEvent
SSDT sptd.sys ZwOpenKey [0xB9EBE0B0]
SSDT 8A7230F8 ZwOpenProcessToken
SSDT 8A2366E8 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB8BA5240]
SSDT SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation) ZwQueryDefaultLocale [0xB9BA9790]
SSDT sptd.sys ZwQueryKey [0xB9EC4418]
SSDT sptd.sys ZwQueryValueKey [0xB9EC4298]
SSDT 8A6D3BF0 ZwResumeThread
SSDT 8A7006D8 ZwSetContextThread
SSDT 8A2486E8 ZwSetInformationProcess
SSDT 8A2676E8 ZwSetInformationThread
SSDT sptd.sys ZwSetValueKey [0xB9EC44AA]
SSDT 8A7CB988 ZwSuspendProcess
SSDT 8A7E3DF8 ZwSuspendThread
SSDT 8A65E5E0 ZwTerminateProcess
SSDT 8A86DDF8 ZwTerminateThread
SSDT 8A6B4C70 ZwUnmapViewOfSection
SSDT 8A2356E8 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.14 ----

.text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + AFD 8053D631 5 Bytes JMP B9BAAAD0 SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? System32\Drivers\awdnpolt.SYS The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B84138AC 5 Bytes JMP 8AE4E770
.text ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4
.text ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E
.text ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648
.text ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682
.text ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC
.text ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6
.text ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730
.text ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A
.text ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE

---- User code sections - GMER 1.0.14 ----

.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

EasyEEE
2008-12-29, 16:35
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

EasyEEE
2008-12-29, 16:35
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

EasyEEE
2008-12-29, 16:36
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EBEAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EBEC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EBEB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EBF748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EBF61E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9ED429A] sptd.sys

---- Devices - GMER 1.0.14 ----

Device \FileSystem\Ntfs \Ntfs 8AFF61E8
Device \FileSystem\Fastfat \FatCdrom 8A6E8790
Device \FileSystem\Udfs \UdfsCdRom 8A6F4790
Device \FileSystem\Udfs \UdfsDisk 8A6F4790

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\usbohci \Device\USBPDO-0 8AD945C0
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmConfig 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmPnP 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmInfo 8B07F1E8
Device \Driver\usbehci \Device\USBPDO-1 8AD8B790

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\nvata \Device\000000a1 8AFF81E8
Device \Driver\nvata \Device\000000a2 8AFF81E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8B0151E8
Device \Driver\Cdrom \Device\CdRom0 8AE3A790
Device \Driver\usbstor \Device\000000b0 89BBB1E8
Device \Driver\Cdrom \Device\CdRom1 8AE3A790
Device \Driver\usbstor \Device\000000b1 89BBB1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A705428
Device \Driver\NetBT \Device\NetbiosSmb 8A705428

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\usbohci \Device\USBFDO-0 8AD945C0
Device \Driver\usbstor \Device\000000ab 89BBB1E8
Device \Driver\nvata \Device\NvAta0 8AFF81E8
Device \Driver\usbehci \Device\USBFDO-1 8AD8B790
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A70D3C8
Device \Driver\NetBT \Device\NetBT_Tcpip_{3FE5131D-2573-40B6-A366-9EE7F9CDA625} 8A705428
Device \Driver\usbstor \Device\000000ae 89BBB1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A70D3C8
Device \Driver\usbstor \Device\000000af 89BBB1E8
Device \Driver\Ftdisk \Device\FtControl 8B0151E8
Device \Driver\PCI_NTPNP4120 \Device\0000007e sptd.sys
Device \Driver\PCI_NTPNP4120 \Device\0000007f sptd.sys
Device \Driver\awdnpolt \Device\Scsi\awdnpolt1 8AE5B568
Device \FileSystem\Fastfat \Fat 8A6E8790

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 8A6EC790

---- Registry - GMER 1.0.14 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x3D 0x04 0xE4 0x1D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...

---- EOF - GMER 1.0.14 ----

Shaba
2008-12-29, 16:41
That appears to be ok.

Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

EasyEEE
2008-12-29, 16:42
- That's it. "SHOW ALL" was UN-CHECKED and greyed out. Still looks like a lot of data.

Attached is a screen shot of all the pop-ups.

Again, thanks for your time.

EasyEEE
2008-12-29, 16:53
Logfile of random's system information tool 1.05 (written by random/random)
Run by Owner at 2008-12-29 10:43:52
Microsoft Windows XP Professional Service Pack 3
System drive C: has 260 GB (54%) free of 477 GB
Total RAM: 3070 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:39 AM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Documents and Settings\Owner\Desktop\Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 14803 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\Norton Security Scan for Owner.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2}]
SpywareGuardDLBLOCK.CBrowserHelper - C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-02 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-04-02 2554944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-17 652784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-12-05 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-12-05 81920]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"Power2GoExpress"=C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe [2008-01-14 2667816]
"CLJ"=0 []
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2007-10-17 128296]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-09-14 14820864]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2007-08-06 115560]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2008-03-21 91432]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2008-08-04 160800]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-02 68856]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"Power2GoExpress"=NA []
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
"CTSyncU.exe"=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2007-07-17 868352]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2008-11-10 2356088]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2008-05-28 87352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=C:\Program Files\SpywareGuard\spywareguard.dll [2003-08-02 126976]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmcService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Symantec Antvirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2 Update"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\CyberLink\PowerDirector\PDR.exe"="C:\Program Files\CyberLink\PowerDirector\PDR.exe:*:Enabled:CyberLink PowerDirector"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe"="C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service"
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE"="C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service"
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Active WebCam\WebCam.exe"="C:\Program Files\Active WebCam\WebCam.exe:*:Enabled:Active WebCam"
"C:\Program Files\Active WebCam\Watchdog.exe"="C:\Program Files\Active WebCam\Watchdog.exe:*:Enabled:Watchdog"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe"="C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:*:Enabled:PandoRest Application Name"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======List of files/folders created in the last 1 months======

2008-12-29 10:43:52 ----D---- C:\rsit
2008-12-29 09:57:50 ----A---- C:\WINDOWS\gmer.ini
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer.exe
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer.dll
2008-12-29 09:55:34 ----D---- C:\Gmer
2008-12-26 16:50:48 ----D---- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-12-26 16:50:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-26 16:50:42 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-26 16:39:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-26 13:15:45 ----D---- C:\Program Files\Malware Removal Tool
2008-12-26 13:14:42 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-26 13:14:22 ----D---- C:\Program Files\CleanUp!
2008-12-26 13:11:52 ----D---- C:\Program Files\CCleaner
2008-12-22 00:24:29 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-12-22 00:24:25 ----D---- C:\Program Files\Yahoo!
2008-12-12 21:52:23 ----D---- C:\Documents and Settings\Owner\Application Data\RToolDS
2008-12-12 21:52:20 ----D---- C:\Program Files\RToolDS
2008-12-12 20:16:11 ----D---- C:\Sarah's DS
2008-12-11 21:37:39 ----D---- C:\WINDOWS\Minidump
2008-12-11 19:19:02 ----D---- C:\Music
2008-12-11 16:35:43 ----D---- C:\Program Files\iPod
2008-12-11 16:35:40 ----D---- C:\Program Files\iTunes
2008-12-11 16:35:40 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:35:08 ----D---- C:\Program Files\Bonjour
2008-12-11 16:33:04 ----D---- C:\Program Files\Apple Software Update
2008-12-10 03:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2008-12-10 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-10 03:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2008-12-10 03:00:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2008-12-06 17:11:30 ----D---- C:\Program Files\ABC Amber LIT Converter
2008-12-04 22:55:58 ----D---- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache

======List of files/folders modified in the last 1 months======

2008-12-29 10:33:55 ----D---- C:\WINDOWS\Temp
2008-12-29 10:26:35 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-12-29 10:23:52 ----D---- C:\Program Files\Mozilla Firefox
2008-12-29 10:07:38 ----D---- C:\WINDOWS\Registration
2008-12-29 10:06:45 ----D---- C:\WINDOWS
2008-12-29 10:06:38 ----D---- C:\WINDOWS\system32\Lang
2008-12-29 09:57:49 ----D---- C:\WINDOWS\system32\drivers
2008-12-29 01:11:26 ----D---- C:\Documents and Settings\Owner\Application Data\NewsBin
2008-12-28 18:00:01 ----D---- C:\Program Files\Norton Security Scan
2008-12-28 13:26:00 ----D---- C:\WINDOWS\Prefetch
2008-12-28 13:21:52 ----D---- C:\Program Files\Active WebCam
2008-12-28 10:19:02 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-28 09:46:56 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-28 09:46:53 ----D---- C:\Program Files\SpywareBlaster
2008-12-27 07:18:18 ----D---- C:\Voyager
2008-12-26 16:57:08 ----D---- C:\WINDOWS\system32
2008-12-26 16:50:42 ----RD---- C:\Program Files
2008-12-26 13:48:40 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-26 13:15:23 ----D---- C:\WINDOWS\Debug
2008-12-26 13:05:22 ----D---- C:\WINDOWS\system32\config
2008-12-25 15:42:53 ----D---- C:\NDS
2008-12-24 12:47:00 ----SHD---- C:\WINDOWS\Installer
2008-12-24 12:46:54 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-12-23 20:14:03 ----D---- C:\Program Files\SpywareGuard
2008-12-23 19:20:19 ----RASH---- C:\WINDOWS\system32\userinit.exe
2008-12-23 10:05:16 ----D---- C:\Program Files\eMule
2008-12-17 13:44:47 ----HD---- C:\WINDOWS\inf
2008-12-17 13:44:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-17 13:44:29 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-13 23:49:30 ----D---- C:\SYSPREP
2008-12-13 09:36:20 ----D---- C:\NDS_DPG
2008-12-13 01:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-12 23:10:49 ----D---- C:\NDS Roms Full
2008-12-11 21:15:21 ----D---- C:\Program Files\QuickTime
2008-12-11 16:35:55 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-12-11 16:35:42 ----D---- C:\Program Files\Common Files\Apple
2008-12-11 16:33:07 ----SD---- C:\WINDOWS\Tasks
2008-12-10 03:00:55 ----D---- C:\Program Files\Internet Explorer
2008-12-09 15:24:38 ----A---- C:\WINDOWS\system32\MRT.exe
2008-12-04 23:05:58 ----D---- C:\Program Files\Hospital Hustle
2008-12-03 16:09:38 ----A---- C:\WINDOWS\AviSplitter.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2008-12-29 85969]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2007-08-14 250416]
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2007-08-14 25136]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2007-01-09 191544]
R1 WPS;WPS; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-14 3856896]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-02-28 10144]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2008-08-04 33808]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS []
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-12-05 7435392]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2007-01-09 27576]
R3 Teefer2;Teefer2 Miniport; C:\WINDOWS\system32\DRIVERS\teefer2.sys [2007-08-06 49024]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 WpsHelper;WpsHelper; \??\C:\WINDOWS\system32\drivers\WpsHelper.sys []
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 42752]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
S3 awdnpolt;awdnpolt; C:\WINDOWS\system32\drivers\awdnpolt.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\system32\DRIVERS\mxnic.sys [2001-08-17 19968]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2007-08-14 277040]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
S4 vsdatant;vsdatant; a []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-07-13 611664]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 Capture Device Service;Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [2006-08-11 200704]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-08-06 108392]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-08-06 108392]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-02-17 20543]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-17 168432]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-08-22 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2008-08-04 164896]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-02-17 61503]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-12-05 155716]
R2 OpenCASE Media Agent;OpenCASE Media Agent; C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-05 835208]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-19 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-04-19 107832]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-04-07 241734]
R2 SmcService;Symantec Management Client; C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe [2007-09-07 2532736]
R2 Symantec AntiVirus;Symantec Endpoint Protection; C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2007-09-06 2177464]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2007-01-18 67056]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-04-03 654848]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S2 gupdate1c8e207f066345c;Google Update Service (gupdate1c8e207f066345c); C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-29 133104]
S3 ACTIVEWEBCAMWATCHDOG;Active WebCam Watchdog; C:\Program Files\Active WebCam\Watchdog.exe [2008-07-27 719696]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-08-11 3093872]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 SNAC;Symantec Network Access Control; C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE [2007-09-07 234888]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-06-14 74656]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

EasyEEE
2008-12-29, 16:55
info.txt logfile of random's system information tool 1.05 2008-12-29 10:44:40

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\InstallShield Installation Information\{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}\setup.exe" --u:{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABC Amber LIT Converter-->C:\PROGRA~1\ABCAMB~1\UNWISE.EXE C:\PROGRA~1\ABCAMB~1\INSTALL.LOG
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Active WebCam-->"C:\Program Files\Active WebCam\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 8.1.2 Professional-->msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced PDF Repair v1.1-->C:\PROGRA~1\APDFR\UNWISE.EXE C:\PROGRA~1\APDFR\INSTALL.LOG
Advanced Word Repair v1.2-->C:\PROGRA~1\AWR\UNWISE.EXE C:\PROGRA~1\AWR\INSTALL.LOG
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
Avi2Dvd 0.4.5 beta-->C:\Program Files\Avi2Dvd\uninst.exe
AviScript 2.9 (Lite Version)-->"C:\Program Files\AviScript 2.9 (Lite Version)\unins000.exe"
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Beach Party Craze-->C:\PROGRA~1\GAMEHO~1\BEACHP~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\BEACHP~1\INSTALL.LOG
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Cinema Craft Encoder SP-->C:\PROGRA~1\CUSTOM~1\CINEMA~1\uinst.exe
CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
CoffeeCup HTML Editor 2008-->C:\PROGRA~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\INSTALL.LOG
Cooking Academy-->C:\PROGRA~1\GAMEHO~1\COOKIN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\COOKIN~1\INSTALL.LOG
Corel Paint Shop Pro Photo X2-->MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
CyberLink PhotoNow-->"C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DocRepair-->C:\PROGRA~1\Jufsoft\DOCREP~1\UNWISE.EXE C:\PROGRA~1\Jufsoft\DOCREP~1\INSTALL.LOG
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVD-lab PRO 2.5-->"C:\Program Files\DVDlabPro2\unins000.exe"
EA Download Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
EasyRecovery Professional-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{268723B7-A994-4286-9F85-B974D5CAFC7B} /l1033
eMule-->"C:\Program Files\eMule\Uninstall.exe"
ffdshow [rev 2060] [2008-08-01]-->"C:\Program Files\ffdshow\unins000.exe"
FileZilla Client 3.1.0.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
GameHouse Solitaire Challenge-->C:\PROGRA~1\GAMEHO~1\GAMEHO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\GAMEHO~1\INSTALL.LOG
Golden Eagle FlightPrep 2007 SP1-->C:\Program Files\InstallShield Installation Information\{B4AC94AE-A5CE-4BB5-897C-E45E558F3277}\setup.exe -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Update-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hidden Wonders of the Depths-->C:\PROGRA~1\GAMEHO~1\HIDDEN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\HIDDEN~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB895961-v4)-->"C:\WINDOWS\$NtUninstallKB895961-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HTML-Kit-->"C:\Program Files\Chami\HTML-Kit\unins000.exe"
InterVideo DeviceService-->MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jojo's Fashion Show 2-->C:\PROGRA~1\GAMEHO~1\JOJO'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\JOJO'S~1\INSTALL.LOG
Kaspersky Online Scanner-->C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
KissYouTube.com Offline Version 1.1 Freeware-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\kiss\ST6UNST.LOG"
LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
LightScribe Template Designs - Art Pack 1-->MsiExec.exe /X{2CDB2DCD-1153-4ED4-9D0A-606231CEFE9A}
LightScribe Template Designs - Fantasy Pack 1-->MsiExec.exe /X{DE72186D-A4A5-4504-839C-B14FC3432DA1}
LightScribe Template Designs - Holiday Pack 1-->MsiExec.exe /X{CEF736FF-8133-42F3-8E18-BDFE293B87FF}
LightScribe Template Designs - Special Occasion Pack 1-->MsiExec.exe /X{B6C766E9-B26D-4D54-A22B-A52B069C6C14}
LightScribe Template Designs - Sports Pack 1-->MsiExec.exe /X{725F0ABA-808A-4256-885C-1E60245521D0}
LightScribe Template Designs - Tattoo Pack 1-->MsiExec.exe /X{E35A1183-F6D8-4DCA-A111-296AFFA00A5C}
LightScribe Template Designs - Urban Pack 1-->MsiExec.exe /X{85548764-32DC-43ED-BAA5-5386FDB2500A}
LightScribe Template Designs - Wedding Pack 1-->MsiExec.exe /X{15B6EAD9-E83D-458F-AF6F-B8F865FA4F28}
LightScribeTemplateLabeler-->MsiExec.exe /X{305D4B08-5807-4475-B1C8-D54685534864}
Lively by Google-->MsiExec.exe /X{2DE38C17-DD7E-41BA-88BC-0A2387D29657}
LiveUpdate 3.3 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lucy's Expedition-->C:\PROGRA~1\GAMEHO~1\LUCY'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\LUCY'S~1\INSTALL.LOG
Malware Removal Tool-->"C:\Program Files\Malware Removal Tool\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaMonkey 3.0-->"C:\Program Files\MediaMonkey\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Corporation-->MsiExec.exe /I{7B08D306-7266-4647-A926-2F78817ED1E0}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft LifeCam-->MsiExec.exe /X{6BCB7EAA-598C-4836-B7EA-3642E41AA222}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Monopoly by Parker Brothers-->C:\PROGRA~1\GAMEHO~1\MONOPO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MONOPO~1\INSTALL.LOG
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 Audio Editor v6.6-->"C:\Program Files\Mp3 Audio Editor\unins000.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Mysteryville-->C:\PROGRA~1\GAMEHO~1\MYSTER~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MYSTER~1\INSTALL.LOG
NBC Direct Beta-->MsiExec.exe /I{7A647B7A-9FE7-44A2-9041-C04528D44EB9}
NewsBin Pro-->C:\Program Files\NewsBin\uninst.exe
No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
Norton Security Scan (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe" /X
Norton Security Scan-->MsiExec.exe /X{3FADAA19-E595-44CA-A072-58B6B0851768}
Nucleus Kernel Word Demo ver 4.03-->"C:\Program Files\Nucleus Kernel Word Demo\unins000.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
OpenCASE Media Agent-->MsiExec.exe /I{1771FDC8-D846-4B77-996A-C80DAD42C03F}
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RichFLV-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall de.benz.RichFLV 452D2865B2D5CE6F34BBFAC997E63D0882A4858D.1
RichFLV-->MsiExec.exe /I{46B62454-F462-E952-0EA3-3FB1CDF552A9}
Ricochet Lost Worlds Recharged-->C:\PROGRA~1\GAMEHO~1\RICOCH~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\RICOCH~1\INSTALL.LOG
RToolDS v0.3.1382-->C:\Program Files\RToolDS\uninst.exe
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\setup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2-->"C:\Program Files\SpywareGuard\unins000.exe"
SureThing CD Labeler LightScribe 5.0.581.0-->"C:\Program Files\SureThing CD Labeler 5\unins000.exe"
Symantec Endpoint Protection-->MsiExec.exe /I{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TBS WMP Plug-in-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{13515135-48BB-4184-8C1F-2FAE0138E200}
TMPGEnc Plus 2.5-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A1E27FF-BE53-45B4-950F-060236E98E3D}
Tom Clancy's Rainbow Six Vegas 2-->"C:\Program Files\InstallShield Installation Information\{FD416706-875C-4B0B-A23A-9E740DAE029E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Ulead DVD MovieFactory 6 TBYB-->C:\Program Files\InstallShield Installation Information\{CCC4E428-411E-4605-B515-317D50ABD477}\setup.exe -runfromtemp -l0x0409
Ulead GIF Animator 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\Setup.exe"
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Vuze-->C:\Program Files\Vuze\uninstall.exe
Wedding Dash 2 Rings Around the World-->MsiExec.exe /X{851A0AB9-E984-47B8-9194-96CE096FB7C9}
Wheel of Fortune 2-->C:\PROGRA~1\GAMEHO~1\WHEELO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\WHEELO~1\INSTALL.LOG
Wii Max Media Manager Pro-->"C:\Program Files\Datel\Wii Max Media Manager Pro\unins000.exe"
Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail-->MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WMPCDText 1.0-->"C:\Program Files\WMPCDText\unins000.exe"
Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009

======Hosts File======

127.0.0.1 localhost
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 a9rhiwa.cn #[Google.Warning]
127.0.0.1 www.a9rhiwa.cn
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net

======Security center information======

AV: Symantec Endpoint Protection
FW: Symantec Endpoint Protection

System event log

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12609
Source Name: Service Control Manager
Time Written: 20081117185700.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12608
Source Name: Service Control Manager
Time Written: 20081117175650.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12607
Source Name: Service Control Manager
Time Written: 20081117165641.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12606
Source Name: Service Control Manager
Time Written: 20081117155631.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12605
Source Name: Service Control Manager
Time Written: 20081117145621.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000109fb.

Record Number: 3309
Source Name: Application Error
Time Written: 20081222123438.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3308
Source Name: Application Error
Time Written: 20081222103234.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3307
Source Name: Application Error
Time Written: 20081222103232.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3306
Source Name: Application Error
Time Written: 20081222093158.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3305
Source Name: Application Error
Time Written: 20081222092812.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 55 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=3702
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------

Shaba
2008-12-29, 17:03
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

eMule
Vuze

I'd like you to read the this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Delete info.txt from c:\rsit folder.

Please run a new RSIT scan when finished and post the log back here.

EasyEEE
2008-12-29, 17:11
Thanks. I knew about eMule. Tried to send video of son's birthday to his older brother. Not sure about Vuze. Here's the info.txt

info.txt logfile of random's system information tool 1.05 2008-12-29 11:08:49

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\InstallShield Installation Information\{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}\setup.exe" --u:{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABC Amber LIT Converter-->C:\PROGRA~1\ABCAMB~1\UNWISE.EXE C:\PROGRA~1\ABCAMB~1\INSTALL.LOG
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Active WebCam-->"C:\Program Files\Active WebCam\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 8.1.2 Professional-->msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced PDF Repair v1.1-->C:\PROGRA~1\APDFR\UNWISE.EXE C:\PROGRA~1\APDFR\INSTALL.LOG
Advanced Word Repair v1.2-->C:\PROGRA~1\AWR\UNWISE.EXE C:\PROGRA~1\AWR\INSTALL.LOG
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
Avi2Dvd 0.4.5 beta-->C:\Program Files\Avi2Dvd\uninst.exe
AviScript 2.9 (Lite Version)-->"C:\Program Files\AviScript 2.9 (Lite Version)\unins000.exe"
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Beach Party Craze-->C:\PROGRA~1\GAMEHO~1\BEACHP~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\BEACHP~1\INSTALL.LOG
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Cinema Craft Encoder SP-->C:\PROGRA~1\CUSTOM~1\CINEMA~1\uinst.exe
CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
CoffeeCup HTML Editor 2008-->C:\PROGRA~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\INSTALL.LOG
Cooking Academy-->C:\PROGRA~1\GAMEHO~1\COOKIN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\COOKIN~1\INSTALL.LOG
Corel Paint Shop Pro Photo X2-->MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
CyberLink PhotoNow-->"C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DocRepair-->C:\PROGRA~1\Jufsoft\DOCREP~1\UNWISE.EXE C:\PROGRA~1\Jufsoft\DOCREP~1\INSTALL.LOG
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVD-lab PRO 2.5-->"C:\Program Files\DVDlabPro2\unins000.exe"
EA Download Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
EasyRecovery Professional-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{268723B7-A994-4286-9F85-B974D5CAFC7B} /l1033
ffdshow [rev 2060] [2008-08-01]-->"C:\Program Files\ffdshow\unins000.exe"
FileZilla Client 3.1.0.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
GameHouse Solitaire Challenge-->C:\PROGRA~1\GAMEHO~1\GAMEHO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\GAMEHO~1\INSTALL.LOG
Golden Eagle FlightPrep 2007 SP1-->C:\Program Files\InstallShield Installation Information\{B4AC94AE-A5CE-4BB5-897C-E45E558F3277}\setup.exe -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Update-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hidden Wonders of the Depths-->C:\PROGRA~1\GAMEHO~1\HIDDEN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\HIDDEN~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB895961-v4)-->"C:\WINDOWS\$NtUninstallKB895961-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HTML-Kit-->"C:\Program Files\Chami\HTML-Kit\unins000.exe"
InterVideo DeviceService-->MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jojo's Fashion Show 2-->C:\PROGRA~1\GAMEHO~1\JOJO'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\JOJO'S~1\INSTALL.LOG
Kaspersky Online Scanner-->C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
KissYouTube.com Offline Version 1.1 Freeware-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\kiss\ST6UNST.LOG"
LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
LightScribe Template Designs - Art Pack 1-->MsiExec.exe /X{2CDB2DCD-1153-4ED4-9D0A-606231CEFE9A}
LightScribe Template Designs - Fantasy Pack 1-->MsiExec.exe /X{DE72186D-A4A5-4504-839C-B14FC3432DA1}
LightScribe Template Designs - Holiday Pack 1-->MsiExec.exe /X{CEF736FF-8133-42F3-8E18-BDFE293B87FF}
LightScribe Template Designs - Special Occasion Pack 1-->MsiExec.exe /X{B6C766E9-B26D-4D54-A22B-A52B069C6C14}
LightScribe Template Designs - Sports Pack 1-->MsiExec.exe /X{725F0ABA-808A-4256-885C-1E60245521D0}
LightScribe Template Designs - Tattoo Pack 1-->MsiExec.exe /X{E35A1183-F6D8-4DCA-A111-296AFFA00A5C}
LightScribe Template Designs - Urban Pack 1-->MsiExec.exe /X{85548764-32DC-43ED-BAA5-5386FDB2500A}
LightScribe Template Designs - Wedding Pack 1-->MsiExec.exe /X{15B6EAD9-E83D-458F-AF6F-B8F865FA4F28}
LightScribeTemplateLabeler-->MsiExec.exe /X{305D4B08-5807-4475-B1C8-D54685534864}
Lively by Google-->MsiExec.exe /X{2DE38C17-DD7E-41BA-88BC-0A2387D29657}
LiveUpdate 3.3 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lucy's Expedition-->C:\PROGRA~1\GAMEHO~1\LUCY'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\LUCY'S~1\INSTALL.LOG
Malware Removal Tool-->"C:\Program Files\Malware Removal Tool\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaMonkey 3.0-->"C:\Program Files\MediaMonkey\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Corporation-->MsiExec.exe /I{7B08D306-7266-4647-A926-2F78817ED1E0}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft LifeCam-->MsiExec.exe /X{6BCB7EAA-598C-4836-B7EA-3642E41AA222}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Monopoly by Parker Brothers-->C:\PROGRA~1\GAMEHO~1\MONOPO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MONOPO~1\INSTALL.LOG
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 Audio Editor v6.6-->"C:\Program Files\Mp3 Audio Editor\unins000.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Mysteryville-->C:\PROGRA~1\GAMEHO~1\MYSTER~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MYSTER~1\INSTALL.LOG
NBC Direct Beta-->MsiExec.exe /I{7A647B7A-9FE7-44A2-9041-C04528D44EB9}
NewsBin Pro-->C:\Program Files\NewsBin\uninst.exe
No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
Norton Security Scan (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe" /X
Norton Security Scan-->MsiExec.exe /X{3FADAA19-E595-44CA-A072-58B6B0851768}
Nucleus Kernel Word Demo ver 4.03-->"C:\Program Files\Nucleus Kernel Word Demo\unins000.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
OpenCASE Media Agent-->MsiExec.exe /I{1771FDC8-D846-4B77-996A-C80DAD42C03F}
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RichFLV-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall de.benz.RichFLV 452D2865B2D5CE6F34BBFAC997E63D0882A4858D.1
RichFLV-->MsiExec.exe /I{46B62454-F462-E952-0EA3-3FB1CDF552A9}
Ricochet Lost Worlds Recharged-->C:\PROGRA~1\GAMEHO~1\RICOCH~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\RICOCH~1\INSTALL.LOG
RToolDS v0.3.1382-->C:\Program Files\RToolDS\uninst.exe
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\setup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2-->"C:\Program Files\SpywareGuard\unins000.exe"
SureThing CD Labeler LightScribe 5.0.581.0-->"C:\Program Files\SureThing CD Labeler 5\unins000.exe"
Symantec Endpoint Protection-->MsiExec.exe /I{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TBS WMP Plug-in-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{13515135-48BB-4184-8C1F-2FAE0138E200}
TMPGEnc Plus 2.5-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A1E27FF-BE53-45B4-950F-060236E98E3D}
Tom Clancy's Rainbow Six Vegas 2-->"C:\Program Files\InstallShield Installation Information\{FD416706-875C-4B0B-A23A-9E740DAE029E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Ulead DVD MovieFactory 6 TBYB-->C:\Program Files\InstallShield Installation Information\{CCC4E428-411E-4605-B515-317D50ABD477}\setup.exe -runfromtemp -l0x0409
Ulead GIF Animator 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\Setup.exe"
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Wedding Dash 2 Rings Around the World-->MsiExec.exe /X{851A0AB9-E984-47B8-9194-96CE096FB7C9}
Wheel of Fortune 2-->C:\PROGRA~1\GAMEHO~1\WHEELO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\WHEELO~1\INSTALL.LOG
Wii Max Media Manager Pro-->"C:\Program Files\Datel\Wii Max Media Manager Pro\unins000.exe"
Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail-->MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WMPCDText 1.0-->"C:\Program Files\WMPCDText\unins000.exe"
Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009

======Hosts File======

127.0.0.1 localhost
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 a9rhiwa.cn #[Google.Warning]
127.0.0.1 www.a9rhiwa.cn
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net

======Security center information======

AV: Symantec Endpoint Protection
FW: Symantec Endpoint Protection

System event log

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12612
Source Name: Service Control Manager
Time Written: 20081117215729.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12611
Source Name: Service Control Manager
Time Written: 20081117205720.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12610
Source Name: Service Control Manager
Time Written: 20081117195710.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12609
Source Name: Service Control Manager
Time Written: 20081117185700.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12608
Source Name: Service Control Manager
Time Written: 20081117175650.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000109fb.

Record Number: 3309
Source Name: Application Error
Time Written: 20081222123438.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3308
Source Name: Application Error
Time Written: 20081222103234.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3307
Source Name: Application Error
Time Written: 20081222103232.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3306
Source Name: Application Error
Time Written: 20081222093158.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3305
Source Name: Application Error
Time Written: 20081222092812.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 55 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=3702
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------

Shaba
2008-12-29, 17:17
Please download ComboFix from one of these locations:

Link 1 (http://subs.geekstogo.com/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

EasyEEE
2008-12-29, 17:55
ComboFix 08-12-28.04 - Owner 2008-12-29 11:22:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2303 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
FW: Symantec Endpoint Protection *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3550P


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-29 10:43 . 2008-12-29 11:08 <DIR> d-------- C:\rsit
2008-12-29 09:57 . 2008-12-29 10:08 345 --a------ c:\windows\gmer.ini
2008-12-29 09:55 . 2008-12-29 09:55 <DIR> d-------- C:\Gmer
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-26 16:50 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-26 16:50 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-26 13:15 . 2008-12-26 13:15 <DIR> d-------- c:\program files\Malware Removal Tool
2008-12-26 13:14 . 2008-12-26 13:14 <DIR> d-------- c:\program files\CleanUp!
2008-12-26 13:11 . 2008-12-26 13:11 <DIR> d-------- c:\program files\CCleaner
2008-12-22 00:24 . 2008-12-24 19:58 <DIR> d-------- c:\program files\Yahoo!
2008-12-22 00:24 . 2008-12-24 19:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-12 21:52 . 2008-12-12 21:52 <DIR> d-------- c:\program files\RToolDS
2008-12-12 21:52 . 2008-12-25 15:46 <DIR> d-------- c:\documents and settings\Owner\Application Data\RToolDS
2008-12-12 20:16 . 2008-12-12 20:16 <DIR> d-------- C:\Sarah's DS
2008-12-11 19:19 . 2008-12-13 23:49 <DIR> d-------- C:\Music
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\iTunes
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\iPod
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\Bonjour
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:33 . 2008-12-11 16:33 <DIR> d-------- c:\program files\Apple Software Update
2008-12-08 21:47 . 2008-12-08 21:47 244 --ah----- C:\sqmnoopt06.sqm
2008-12-08 21:47 . 2008-12-08 21:47 232 --ah----- C:\sqmdata06.sqm
2008-12-06 17:11 . 2008-12-06 21:09 <DIR> d-------- c:\program files\ABC Amber LIT Converter
2008-12-04 22:55 . 2008-12-04 22:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\BigFishGamesCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 16:20 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-29 16:06 --------- d-----w c:\program files\eMule
2008-12-29 15:26 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-29 06:11 --------- d-----w c:\documents and settings\Owner\Application Data\NewsBin
2008-12-28 23:00 --------- d-----w c:\program files\Norton Security Scan
2008-12-28 18:21 --------- d-----w c:\program files\Active WebCam
2008-12-28 14:46 --------- d-----w c:\program files\SpywareBlaster
2008-12-26 18:48 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-24 17:46 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-24 01:14 --------- d-----w c:\program files\SpywareGuard
2008-12-12 02:15 --------- d-----w c:\program files\QuickTime
2008-12-11 21:35 --------- d-----w c:\program files\Common Files\Apple
2008-12-05 04:05 --------- d-----w c:\program files\Hospital Hustle
2008-11-29 12:37 1,140 ----a-w C:\drmHeader.bin
2008-11-28 19:53 --------- d-----w c:\documents and settings\Owner\Application Data\GameInvest
2008-11-28 19:52 --------- d-----w c:\documents and settings\Owner\Application Data\SpinTop
2008-11-27 20:18 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-21 16:34 --------- d-----w c:\program files\GameHouse
2008-11-21 16:34 --------- d-----w c:\documents and settings\Owner\Application Data\GameHouse
2008-11-21 16:34 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-21 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-11-20 18:16 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org
2008-11-20 18:15 --------- d-----w c:\program files\OpenOffice.org 3
2008-11-20 18:15 --------- d-----w c:\program files\JRE
2008-11-20 18:14 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-11-20 18:10 149,286,272 ----a-w C:\OOo_3.0.0_Win32Intel_install_wJRE_en-US.exe
2008-11-20 18:03 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2008-11-17 04:40 --------- d-----w c:\documents and settings\Owner\Application Data\BeachPartyCraze
2008-11-16 03:49 --------- d-----w c:\program files\DVDlabPro2
2008-11-16 00:26 --------- d-----w c:\documents and settings\Owner\Application Data\Ulead Systems
2008-11-15 22:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 22:19 --------- d-----w c:\program files\DivX
2008-11-15 22:19 --------- d-----w c:\program files\Common Files\InterVideo
2008-11-15 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\InterVideo
2008-11-15 22:18 --------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2008-11-15 22:17 --------- d-----w c:\program files\Ulead Systems
2008-11-15 22:17 --------- d-----w c:\program files\Common Files\Ulead Systems
2008-11-15 20:24 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-15 20:23 --------- d-----w c:\program files\DVD Shrink
2008-11-14 20:36 --------- d-----w c:\program files\WorldOfGoo
2008-11-14 20:36 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2008-04-19 18:46 22,328 ----a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2008-07-14 00:37 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071320080714\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-07-13_13.08.25.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-02 13:42:10 83,968 -c--a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 -c--a-w c:\windows\$hf_mig$\KB946648\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
+ 2008-07-07 20:23:18 253,952 -c--a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 -c--a-w c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:19 382,840 -c--a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-04-12 04:22:26 691,712 -c--a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
+ 2007-12-03 15:25:31 755,576 -c--a-w c:\windows\$hf_mig$\KB951066\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
+ 2008-07-11 12:51:51 62,976 -c--a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 -c--a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 -c--a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-05-07 09:07:23 135,168 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 -c--a-w c:\windows\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 -c--a-w c:\windows\$hf_mig$\KB951978\update\updspapi.dll
+ 2008-05-01 14:38:05 331,776 -c--a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2007-11-30 11:18:51 17,272 -c--a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2007-11-30 11:18:51 231,288 -c--a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2007-11-30 11:18:51 26,488 -c--a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 -c--a-w c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2007-11-30 11:18:51 382,840 -c--a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2008-06-24 16:53:10 74,240 -c--a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 -c--a-w c:\windows\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-06-23 16:01:38 124,928 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\advpack.dll
+ 2008-06-23 16:01:38 347,136 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtmsft.dll
+ 2008-06-23 16:01:39 214,528 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtrans.dll
+ 2008-06-23 16:01:39 132,608 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\extmgr.dll
+ 2008-06-23 16:01:39 63,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\icardie.dll
+ 2008-06-23 08:23:18 70,656 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe
+ 2008-06-23 16:01:39 153,088 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakeng.dll
+ 2008-06-23 16:01:39 230,400 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieaksie.dll
+ 2008-06-21 05:23:53 161,792 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dat
+ 2008-06-23 16:01:40 383,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dll
+ 2008-06-23 16:01:40 388,608 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iedkcs32.dll
+ 2008-06-23 16:01:43 6,068,736 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieframe.dll
+ 2008-06-23 16:01:43 44,544 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iernonce.dll
+ 2008-06-23 16:01:44 267,776 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iertutil.dll
+ 2008-06-23 08:23:18 13,824 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe
+ 2008-06-23 08:23:52 625,664 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
+ 2008-06-23 16:01:46 27,648 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\jsproxy.dll
+ 2008-06-23 16:01:46 459,264 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeeds.dll
+ 2008-06-23 16:01:46 52,224 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeedsbs.dll
+ 2008-06-23 16:01:49 3,594,240 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
+ 2008-06-23 16:01:49 477,696 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtmled.dll
+ 2008-06-23 16:01:49 193,024 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msrating.dll
+ 2008-06-23 16:01:50 671,232 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mstime.dll
+ 2008-06-23 16:01:50 102,912 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\occache.dll
+ 2008-06-23 16:01:50 44,544 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\pngfilt.dll
+ 2008-06-23 16:01:50 105,984 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\url.dll
+ 2008-06-23 16:01:51 1,162,752 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\urlmon.dll
+ 2008-06-23 16:01:51 233,472 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\webcheck.dll
+ 2008-06-23 16:01:51 827,904 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB953839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB953839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB953839\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 -c--a-w c:\windows\$hf_mig$\KB953839\update\update.exe
+ 2007-11-30 11:18:51 382,840 -c--a-w c:\windows\$hf_mig$\KB953839\update\updspapi.dll
+ 2008-09-15 12:25:27 1,846,912 ----a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB954211\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
+ 2008-09-10 01:10:56 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2008-09-04 17:12:27 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 18:08:38 382,840 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-08-26 09:08:35 124,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\advpack.dll
+ 2008-08-26 09:08:36 347,136 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
+ 2008-08-26 09:08:36 214,528 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
+ 2008-08-26 09:08:36 132,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\extmgr.dll
+ 2008-08-26 09:08:36 63,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
+ 2008-08-25 08:43:21 70,656 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
+ 2008-08-26 09:08:36 153,088 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
+ 2008-08-26 09:08:36 230,400 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieaksie.dll
+ 2008-08-23 05:54:50 161,792 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
+ 2008-08-26 09:08:36 380,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dll
+ 2008-08-26 09:08:37 388,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-03 17:26:50 6,068,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
+ 2008-08-26 09:08:39 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
+ 2008-08-26 09:08:39 267,776 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
+ 2008-08-25 08:43:21 13,824 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
+ 2008-08-26 09:08:40 27,648 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
+ 2008-08-26 09:08:40 459,264 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
+ 2008-08-26 09:08:40 52,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
+ 2008-08-26 09:08:43 3,594,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
+ 2008-08-26 09:08:43 477,696 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
+ 2008-08-26 09:08:44 193,024 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
+ 2008-08-26 09:08:44 671,232 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
+ 2008-08-26 09:08:44 102,912 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
+ 2008-08-26 09:08:44 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
+ 2008-08-26 09:08:44 105,984 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
+ 2008-08-26 09:08:45 1,162,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
+ 2008-08-26 09:08:45 233,472 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\webcheck.dll
+ 2008-08-26 09:08:45 827,904 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-08-14 10:34:26 138,496 ----a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-08-14 10:39:28 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
+ 2008-08-14 19:39:46 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
+ 2008-08-14 10:09:44 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
+ 2008-08-14 20:11:10 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956841\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
+ 2008-09-08 11:37:19 333,824 ----a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
+ 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 13:02:04 755,576 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 13:02:12 382,840 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-10-15 16:25:53 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2004-08-04 07:10:08 53,248 -c----w c:\windows\$NtServicePackUninstall$\1394bus.sys
+ 2006-08-16 11:58:05 100,352 -c----w c:\windows\$NtServicePackUninstall$\6to4svc.dll
+ 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll
+ 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll.000
+ 2004-08-10 19:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\accwiz.exe
+ 2004-08-10 19:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll
+ 2004-08-10 19:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll.000
+ 2004-08-10 19:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll
+ 2004-08-10 19:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll.000
+ 2004-08-10 19:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll
+ 2004-08-10 19:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll.000
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\aclui.dll
+ 2004-08-10 19:00:00 187,776 -c----w c:\windows\$NtServicePackUninstall$\acpi.sys
+ 2004-08-10 19:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll
+ 2004-08-10 19:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll.000
+ 2004-08-10 19:00:00 194,048 -c----w c:\windows\$NtServicePackUninstall$\activeds.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\actmovie.exe
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\actxprxy.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll.000
+ 2004-08-10 19:00:00 175,616 -c----w c:\windows\$NtServicePackUninstall$\adsldp.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\adsldpc.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\adsmsext.dll
+ 2004-08-10 19:00:00 263,680 -c----w c:\windows\$NtServicePackUninstall$\adsnt.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\adsnw.dll
+ 2004-08-10 19:00:00 616,960 -c----w c:\windows\$NtServicePackUninstall$\advapi32.dll
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys.000
+ 2008-06-20 10:44:38 138,368 -c----w c:\windows\$NtServicePackUninstall$\afd.sys
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentanm.dll
+ 2004-08-10 19:00:00 214,016 -c----w c:\windows\$NtServicePackUninstall$\agentctl.dll
+ 2006-10-12 14:02:52 42,496 -c----w c:\windows\$NtServicePackUninstall$\agentdp2.dll
+ 2007-03-09 13:58:57 57,344 -c----w c:\windows\$NtServicePackUninstall$\agentdpv.dll
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\agentmpx.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentpsh.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\agentsr.dll
+ 2006-10-12 11:09:53 256,512 -c----w c:\windows\$NtServicePackUninstall$\agentsvr.exe
+ 2004-08-03 23:07:42 42,368 -c----w c:\windows\$NtServicePackUninstall$\agp440.sys
+ 2004-08-03 23:07:44 44,928 -c----w c:\windows\$NtServicePackUninstall$\agpcpq.sys
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0405.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0406.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt0407.dll
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\agt0408.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0409.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt040b.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt040c.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\agt040e.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0410.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0413.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0414.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0415.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0416.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0419.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041d.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041f.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0816.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0c0a.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agtintl.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\ahui.exe
+ 2004-08-10 19:00:00 44,544 -c----w c:\windows\$NtServicePackUninstall$\alg.exe
+ 2004-08-03 23:07:42 42,752 -c----w c:\windows\$NtServicePackUninstall$\alim1541.sys
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\alrsvc.dll
+ 2004-08-03 23:07:44 43,008 -c----w c:\windows\$NtServicePackUninstall$\amdagp.sys
+ 2004-08-03 22:59:20 36,992 -c----w c:\windows\$NtServicePackUninstall$\amdk6.sys
+ 2004-08-03 22:59:22 37,376 -c----w c:\windows\$NtServicePackUninstall$\amdk7.sys
+ 2004-08-10 19:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\amstream.dll
+ 2004-08-10 19:00:00 126,976 -c----w c:\windows\$NtServicePackUninstall$\apphelp.dll
+ 2004-08-10 19:00:00 167,936 -c----w c:\windows\$NtServicePackUninstall$\appmgmts.dll
+ 2004-08-10 19:00:00 295,936 -c----w c:\windows\$NtServicePackUninstall$\appmgr.dll
+ 2004-08-03 22:58:30 60,800 -c----w c:\windows\$NtServicePackUninstall$\arp1394.sys
+ 2002-06-22 08:31:20 20,480 -c----w c:\windows\$NtServicePackUninstall$\aspnet_filter.dll
+ 2007-01-02 21:34:04 200,704 -c----w c:\windows\$NtServicePackUninstall$\aspnet_isapi.dll
+ 2004-08-04 13:11:06 24,576 -c----w c:\windows\$NtServicePackUninstall$\aspnet_regiis.exe
+ 2002-06-22 08:31:22 32,768 -c----w c:\windows\$NtServicePackUninstall$\aspnet_state.exe
+ 2007-01-02 21:34:04 32,768 -c----w c:\windows\$NtServicePackUninstall$\aspnet_wp.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\asr_fmt.exe
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\asr_pfu.exe
+ 2004-08-10 19:00:00 65,024 -c----w c:\windows\$NtServicePackUninstall$\asycfilt.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\asyncmac.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\at.exe
+ 2004-08-10 19:00:00 95,360 -c----w c:\windows\$NtServicePackUninstall$\atapi.sys
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\atl.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\atmadm.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\atmarpc.sys
+ 2004-08-10 19:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\atmfd.dll
+ 2004-08-10 19:00:00 55,936 -c----w c:\windows\$NtServicePackUninstall$\atmlane.sys
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\atmlib.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\attrib.exe
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\audiosrv.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\auditusr.exe
+ 2005-03-02 18:09:29 56,832 -c----w c:\windows\$NtServicePackUninstall$\authz.dll
+ 2004-08-10 19:00:00 588,800 -c----w c:\windows\$NtServicePackUninstall$\autochk.exe
+ 2004-08-10 19:00:00 602,624 -c----w c:\windows\$NtServicePackUninstall$\autoconv.exe
+ 2004-08-10 19:00:00 580,608 -c----w c:\windows\$NtServicePackUninstall$\autofmt.exe
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\autolfn.exe
+ 2004-08-10 19:00:00 84,992 -c----w c:\windows\$NtServicePackUninstall$\avifil32.dll
+ 2004-08-10 19:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\basesrv.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\batmeter.dll
+ 2004-08-10 19:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\batt.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\bidispl.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\bitsprx2.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\bitsprx3.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\blastcln.exe
+ 2004-08-10 19:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\bootcfg.exe
+ 2004-08-10 19:00:00 71,552 -c----w c:\windows\$NtServicePackUninstall$\bridge.sys
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\browselc.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\browser.dll
+ 2007-12-07 00:44:30 1,024,000 -c----w c:\windows\$NtServicePackUninstall$\browseui.dll
+ 2004-08-10 19:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\browsewm.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\bthci.dll
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys.000
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\bthserv.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\btpanui.dll
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\cabinet.dll
+ 2004-08-10 19:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\cabview.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\cacls.exe
+ 2004-08-10 19:00:00 385,024 -c----w c:\windows\$NtServicePackUninstall$\callcont.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\camocx.dll
+ 2004-08-10 19:00:00 142,848 -c----w c:\windows\$NtServicePackUninstall$\capesnpn.dll
+ 2005-07-26 04:39:42 225,792 -c----w c:\windows\$NtServicePackUninstall$\catsrv.dll
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\catsrvps.dll
+ 2005-07-26 04:39:43 625,152 -c----w c:\windows\$NtServicePackUninstall$\catsrvut.dll
+ 2004-08-10 19:00:00 63,744 -c----w c:\windows\$NtServicePackUninstall$\cdfs.sys
+ 2007-12-07 00:44:30 151,040 -c----w c:\windows\$NtServicePackUninstall$\cdfview.dll
+ 2005-09-10 01:53:41 2,067,968 -c----w c:\windows\$NtServicePackUninstall$\cdosys.dll
+ 2004-08-10 19:00:00 49,536 -c----w c:\windows\$NtServicePackUninstall$\cdrom.sys
+ 2004-08-10 19:00:00 194,560 -c----w c:\windows\$NtServicePackUninstall$\certcli.dll
+ 2004-08-10 19:00:00 457,728 -c----w c:\windows\$NtServicePackUninstall$\certmgr.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\cfgbkend.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\cfgmgr32.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\cic.dll
+ 2004-08-10 19:00:00 1,352,192 -c----w c:\windows\$NtServicePackUninstall$\cimwin32.dll
+ 2006-06-22 05:06:29 69,120 -c----w c:\windows\$NtServicePackUninstall$\ciodm.dll
+ 2004-08-10 19:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\cipher.exe
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\cisvc.exe
+ 2004-08-10 19:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\classpnp.sys
+ 2005-07-26 04:39:43 110,080 -c----w c:\windows\$NtServicePackUninstall$\clbcatex.dll
+ 2005-07-26 04:39:43 498,688 -c----w c:\windows\$NtServicePackUninstall$\clbcatq.dll
+ 2004-08-10 19:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\cleanmgr.exe
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.exe
+ 2004-08-10 19:00:00 102,912 -c----w c:\windows\$NtServicePackUninstall$\clipbrd.exe
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\clipsrv.exe
+ 2004-08-10 19:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\clusapi.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\cmcfg32.dll
+ 2004-08-10 19:00:00 388,608 -c----w c:\windows\$NtServicePackUninstall$\cmd.exe
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\cmdevtgprov.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\cmdial32.dll
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cmdl32.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmmon32.exe
+ 2004-08-10 19:00:00 185,344 -c----w c:\windows\$NtServicePackUninstall$\cmprops.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\cmsetacl.dll
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cmstp.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmutil.dll
+ 2004-08-04 00:56:42 47,104 -c----w c:\windows\$NtServicePackUninstall$\cnbjmon.dll
+ 2005-07-26 04:39:43 60,416 -c----w c:\windows\$NtServicePackUninstall$\colbact.dll
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\comaddin.dll
+ 2005-07-26 04:39:44 195,072 -c----w c:\windows\$NtServicePackUninstall$\comadmin.dll
+ 2006-08-25 15:45:58 617,472 -c----w c:\windows\$NtServicePackUninstall$\comctl32.dll
+ 2004-08-10 19:00:00 276,992 -c----w c:\windows\$NtServicePackUninstall$\comdlg32.dll
+ 2004-08-10 19:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\compatui.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\compstui.dll
+ 2005-07-26 04:39:44 97,792 -c----w c:\windows\$NtServicePackUninstall$\comrepl.dll
+ 2004-08-10 19:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\comrepl.exe
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\comrereg.exe
+ 2004-08-10 19:00:00 792,064 -c----w c:\windows\$NtServicePackUninstall$\comres.dll
+ 2004-08-10 19:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\comsetup.dll
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\comsnap.dll
+ 2005-07-26 04:39:44 1,267,200 -c----w c:\windows\$NtServicePackUninstall$\comsvcs.dll
+ 2005-07-26 04:39:45 540,160 -c----w c:\windows\$NtServicePackUninstall$\comuid.dll
+ 2004-08-10 19:00:00 1,032,192 -c----w c:\windows\$NtServicePackUninstall$\conf.exe
+ 2004-08-10 19:00:00 45,056 -c----w c:\windows\$NtServicePackUninstall$\confmrsl.dll
+ 2004-08-10 19:00:00 345,600 -c----w c:\windows\$NtServicePackUninstall$\confmsp.dll
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\conime.exe
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\corpol.dll
+ 2004-08-10 19:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\credui.dll
+ 2004-08-03 22:59:22 36,480 -c----w c:\windows\$NtServicePackUninstall$\crusoe.sys
+ 2004-08-10 19:00:00 597,504 -c----w c:\windows\$NtServicePackUninstall$\crypt32.dll
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\cryptdlg.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\cryptdll.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\cryptext.dll
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cryptnet.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\cryptsvc.dll
+ 2004-08-10 19:00:00 512,512 -c----w c:\windows\$NtServicePackUninstall$\cryptui.dll
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\cscdll.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\cscript.exe
+ 2004-08-10 19:00:00 326,656 -c----w c:\windows\$NtServicePackUninstall$\cscui.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\csrsrv.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\csrss.exe
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\ctfmon.exe
+ 2006-06-03 11:40:49 33,792 -c----w c:\windows\$NtServicePackUninstall$\custsat.dll
+ 2004-08-10 19:00:00 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\d3d8.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\d3d8thk.dll
+ 2004-08-10 19:00:00 1,689,088 -c----w c:\windows\$NtServicePackUninstall$\d3d9.dll
+ 2004-08-10 19:00:00 825,344 -c----w c:\windows\$NtServicePackUninstall$\d3dim700.dll
+ 2007-12-07 00:44:32 1,054,208 -c----w c:\windows\$NtServicePackUninstall$\danim.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\dataclen.dll
+ 2004-08-10 19:00:00 152,064 -c----w c:\windows\$NtServicePackUninstall$\datime.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\davclnt.dll
+ 2004-08-10 19:00:00 640,000 -c----w c:\windows\$NtServicePackUninstall$\dbghelp.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\dbmsrpcn.dll
+ 2004-08-10 19:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\dbnetlib.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dbnmpntw.dll
+ 2004-08-10 19:00:00 1,788 -c----w c:\windows\$NtServicePackUninstall$\dcache.bin
+ 2004-08-10 19:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\dcap32.dll
+ 2004-08-10 19:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\dciman32.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dcomcnfg.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\ddeshare.exe
+ 2004-08-10 19:00:00 266,240 -c----w c:\windows\$NtServicePackUninstall$\ddraw.dll
+ 2004-08-10 19:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\ddrawex.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\defrag.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\devenum.dll
+ 2004-08-10 19:00:00 282,624 -c----w c:\windows\$NtServicePackUninstall$\devmgr.dll
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dfrgfat.exe
+ 2004-08-10 19:00:00 104,960 -c----w c:\windows\$NtServicePackUninstall$\dfrgntfs.exe
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\dfrgsnap.dll
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\dfrgui.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dfsshlex.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\dgnet.dll
+ 2006-05-19 12:59:41 111,616 -c----w c:\windows\$NtServicePackUninstall$\dhcpcsvc.dll
+ 2004-08-10 19:00:00 370,176 -c----w c:\windows\$NtServicePackUninstall$\dhcpmon.dll
+ 2004-08-10 19:00:00 539,136 -c----w c:\windows\$NtServicePackUninstall$\dialer.exe
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\diantz.exe
+ 2004-08-10 19:00:00 68,608 -c----w c:\windows\$NtServicePackUninstall$\digest.dll
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\dinput.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dinput8.dll
+ 2007-05-16 15:12:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\directdb.dll
+ 2004-08-10 19:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\disk.sys
+ 2004-08-10 19:00:00 1,501,696 -c----w c:\windows\$NtServicePackUninstall$\diskcopy.dll
+ 2004-08-10 19:00:00 14,208 -c----w c:\windows\$NtServicePackUninstall$\diskdump.sys
+ 2004-08-10 19:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\diskpart.exe
+ 2004-08-10 19:00:00 45,083 -c----w c:\windows\$NtServicePackUninstall$\dispex.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dllhost.exe
+ 2004-08-10 19:00:00 224,768 -c----w c:\windows\$NtServicePackUninstall$\dmadmin.exe
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dmband.dll
+ 2004-08-10 19:00:00 799,744 -c----w c:\windows\$NtServicePackUninstall$\dmboot.sys
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\dmcompos.dll
+ 2004-08-10 19:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\dmdlgs.dll
+ 2004-08-10 19:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\dmdskmgr.dll
+ 2004-08-10 19:00:00 181,248 -c----w c:\windows\$NtServicePackUninstall$\dmime.dll
+ 2004-08-10 19:00:00 153,344 -c----w c:\windows\$NtServicePackUninstall$\dmio.sys
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\dmloader.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\dmremote.exe
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dmscript.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dmserver.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\dmstyle.dll
+ 2004-08-10 19:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\dmsynth.dll
+ 2004-08-10 19:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\dmusic.dll
+ 2004-08-04 03:07:40 52,864 -c----w c:\windows\$NtServicePackUninstall$\dmusic.sys
+ 2004-08-04 00:56:44 52,224 -c----w c:\windows\$NtServicePackUninstall$\dmutil.dll
+ 2008-06-20 17:41:10 148,992 -c----w c:\windows\$NtServicePackUninstall$\dnsapi.dll
+ 2008-02-20 05:32:43 45,568 -c----w c:\windows\$NtServicePackUninstall$\dnsrslvr.dll
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\docprop2.dll
+ 2004-08-10 19:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\dpcdll.dll
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\dplaysvr.exe
+ 2004-08-10 19:00:00 229,888 -c----w c:\windows\$NtServicePackUninstall$\dplayx.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dpmodemx.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnaddr.dll
+ 2004-08-10 19:00:00 375,296 -c----w c:\windows\$NtServicePackUninstall$\dpnet.dll
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\dpnhpast.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\dpnhupnp.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnlobby.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\dpnsvr.exe
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\dpvacm.dll
+ 2004-08-10 19:00:00 212,480 -c----w c:\windows\$NtServicePackUninstall$\dpvoice.dll
+ 2004-08-10 19:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\dpvsetup.exe
+ 2004-08-10 19:00:00 116,736 -c----w c:\windows\$NtServicePackUninstall$\dpvvox.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\dpwsockx.dll
+ 2004-08-10 19:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\driverquery.exe
+ 2004-08-04 03:08:00 60,288 -c----w c:\windows\$NtServicePackUninstall$\drmk.sys
+ 2004-08-04 03:07:58 2,944 -c----w c:\windows\$NtServicePackUninstall$\drmkaud.sys
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\drprov.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\ds32gt.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dsdmo.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\dsdmoprp.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\dskquota.dll
+ 2004-08-10 19:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\dskquoui.dll
+ 2004-08-10 19:00:00 367,616 -c----w c:\windows\$NtServicePackUninstall$\dsound.dll
+ 2004-08-10 19:00:00 1,294,336 -c----w c:\windows\$NtServicePackUninstall$\dsound3d.dll
+ 2004-08-10 19:00:00 142,336 -c----w c:\windows\$NtServicePackUninstall$\dsprop.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\dsprpres.dll
+ 2004-08-10 19:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\dsquery.dll
+ 2004-08-10 19:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\dssec.dll
+ 2004-08-10 19:00:00 137,216 -c----w c:\windows\$NtServicePackUninstall$\dssenh.dll
+ 2004-08-10 19:00:00 113,152 -c----w c:\windows\$NtServicePackUninstall$\dsuiext.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\dswave.dll
+ 2004-08-10 19:00:00 10,752 -c----w c:\windows\$NtServicePackUninstall$\dumprep.exe
+ 2004-08-10 19:00:00 304,128 -c----w c:\windows\$NtServicePackUninstall$\duser.dll
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\dvdupgrd.exe
+ 2004-08-10 19:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\dwwin.exe
+ 2004-08-10 19:00:00 619,008 -c----w c:\windows\$NtServicePackUninstall$\dx7vb.dll
+ 2004-08-10 19:00:00 1,227,264 -c----w c:\windows\$NtServicePackUninstall$\dx8vb.dll
+ 2004-08-10 19:00:00 1,298,432 -c----w c:\windows\$NtServicePackUninstall$\dxdiag.exe
+ 2004-08-10 19:00:00 2,113,536 -c----w c:\windows\$NtServicePackUninstall$\dxdiagn.dll
+ 2004-08-10 19:00:00 71,040 -c----w c:\windows\$NtServicePackUninstall$\dxg.sys
+ 2006-08-22 09:05:26 498,742 -c----w c:\windows\$NtServicePackUninstall$\dxmasf.dll
+ 2004-08-10 19:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\efsadu.dll
+ 2004-08-10 19:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\els.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\encapi.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\ersvc.dll
+ 2005-07-26 04:39:45 243,200 -c----w c:\windows\$NtServicePackUninstall$\es.dll
+ 2005-10-20 22:20:03 1,082,368 -c----w c:\windows\$NtServicePackUninstall$\esent.dll
+ 2004-08-10 19:00:00 247,808 -c----w c:\windows\$NtServicePackUninstall$\esscli.dll
+ 2004-08-10 19:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\eudcedit.exe
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\eventcreate.exe
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\eventlog.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\eventtriggers.exe
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\evntrprv.dll
+ 2007-06-13 10:23:07 1,033,216 -c----w c:\windows\$NtServicePackUninstall$\explorer.exe
+ 2004-08-10 19:00:00 380,957 -c----w c:\windows\$NtServicePackUninstall$\expsrv.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\extrac32.exe
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\exts.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fastfat.sys
+ 2004-08-10 19:00:00 472,064 -c----w c:\windows\$NtServicePackUninstall$\fastprox.dll
+ 2004-08-10 19:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\faultrep.dll
+ 2004-08-10 19:00:00 27,392 -c----w c:\windows\$NtServicePackUninstall$\fdc.sys
+ 2004-08-10 19:00:00 117,760 -c----w c:\windows\$NtServicePackUninstall$\fde.dll
+ 2004-08-10 19:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\fdeploy.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\feclient.dll
+ 2004-08-10 19:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\filemgmt.dll
+ 2004-08-10 19:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\findstr.exe
+ 2004-08-10 19:00:00 34,944 -c----w c:\windows\$NtServicePackUninstall$\fips.sys
+ 2004-08-10 19:00:00 87,552 -c----w c:\windows\$NtServicePackUninstall$\fldrclnr.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\flpydisk.sys
+ 2006-08-21 12:21:06 16,896 -c----w c:\windows\$NtServicePackUninstall$\fltlib.dll
+ 2006-08-21 09:14:58 23,040 -c----w c:\windows\$NtServicePackUninstall$\fltmc.exe
+ 2006-08-21 09:14:58 128,896 -c----w c:\windows\$NtServicePackUninstall$\fltmgr.sys
+ 2004-08-10 19:00:00 382,976 -c----w c:\windows\$NtServicePackUninstall$\fontext.dll
+ 2005-10-17 21:14:45 80,896 -c----w c:\windows\$NtServicePackUninstall$\fontsub.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\fontview.exe
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\forcedos.exe
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\format.com
+ 2004-08-10 19:00:00 32,828 -c----w c:\windows\$NtServicePackUninstall$\fp40ext.dll
+ 2003-03-25 07:52:04 618,605 -c----w c:\windows\$NtServicePackUninstall$\fp4autl.dll
+ 2004-08-10 19:00:00 9,344 -c----w c:\windows\$NtServicePackUninstall$\framebuf.dll
+ 2004-08-10 19:00:00 185,856 -c----w c:\windows\$NtServicePackUninstall$\framedyn.dll
+ 2004-08-10 19:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\fsquirt.exe
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\ftp.exe
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\fwcfg.dll
+ 2004-08-10 19:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\fxsocm.dll
+ 2007-01-15 21:10:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\gacutil.exe
+ 2008-02-20 06:51:05 282,624 -c----w c:\windows\$NtServicePackUninstall$\gdi32.dll
+ 2004-08-10 19:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\getmac.exe
+ 2004-08-10 19:00:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\glu32.dll
+ 2004-08-10 19:00:00 566,784 -c----w c:\windows\$NtServicePackUninstall$\gpedit.dll
+ 2004-08-10 19:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\gpkrsrc.dll
+ 2004-08-10 19:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\gpresult.exe
+ 2004-08-10 19:00:00 198,656 -c----w c:\windows\$NtServicePackUninstall$\gptext.dll
+ 2004-08-10 19:00:00 39,424 -c----w c:\windows\$NtServicePackUninstall$\grpconv.exe
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\guitrn.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\h323cc.dll
+ 2004-08-10 19:00:00 614,912 -c----w c:\windows\$NtServicePackUninstall$\h323msp.dll
+ 2004-08-04 03:59:10 131,968 -c----w c:\windows\$NtServicePackUninstall$\hal.dll
+ 2004-08-04 08:56:44 7,168 -c----w c:\windows\$NtServicePackUninstall$\hccoin.dll
+ 2005-01-07 21:07:18 138,752 -c----w c:\windows\$NtServicePackUninstall$\hdaudbus.sys
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\help.exe
+ 2004-08-10 19:00:00 768,512 -c----w c:\windows\$NtServicePackUninstall$\helpctr.exe
+ 2004-08-10 19:00:00 743,936 -c----w c:\windows\$NtServicePackUninstall$\helpsvc.exe
+ 2005-05-26 23:22:01 10,752 -c----w c:\windows\$NtServicePackUninstall$\hh.exe
+ 2005-05-27 02:04:27 41,472 -c----w c:\windows\$NtServicePackUninstall$\hhsetup.dll
+ 2004-08-04 00:56:44 20,992 -c----w c:\windows\$NtServicePackUninstall$\hid.dll
+ 2004-08-10 19:00:00 36,224 -c----w c:\windows\$NtServicePackUninstall$\hidclass.sys
+ 2005-06-29 06:43:35 19,200 -c----w c:\windows\$NtServicePackUninstall$\hidir.sys
+ 2005-06-29 06:43:35 19,200 -c----w c:\windows\$NtServicePackUninstall$\hidir.sys.000
+ 2004-08-10 19:00:00 24,960 -c----w c:\windows\$NtServicePackUninstall$\hidparse.sys
+ 2001-08-17 22:02:20 9,600 -c----w c:\windows\$NtServicePackUninstall$\hidusb.sys
+ 2006-07-21 08:24:43 72,704 -c----w c:\windows\$NtServicePackUninstall$\hlink.dll
+ 2004-08-10 19:00:00 344,064 -c----w c:\windows\$NtServicePackUninstall$\hnetcfg.dll
+ 2004-08-10 19:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\hnetwiz.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\hotplug.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\hscupd.exe
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys.000
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\httpapi.dll
+ 2004-08-10 19:00:00 41,984 -c----w c:\windows\$NtServicePackUninstall$\htui.dll
+ 2004-11-17 17:41:24 347,136 -c----w c:\windows\$NtServicePackUninstall$\hypertrm.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\i2omgmt.sys
+ 2004-08-10 19:00:00 18,560 -c----w c:\windows\$NtServicePackUninstall$\i2omp.sys
+ 2004-08-10 19:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\i8042prt.sys
+ 2004-08-10 19:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\iasrad.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\icaapi.dll
+ 2004-08-10 19:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\iccvid.dll
+ 2005-06-29 01:46:00 254,976 -c----w c:\windows\$NtServicePackUninstall$\icm32.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\icmp.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\iconlib.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\icwconn.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\icwconn1.exe
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\icwconn2.exe
+ 2004-08-10 19:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\icwdial.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\icwdl.dll
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\icwhelp.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\icwphbk.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\icwrmind.exe
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\icwutil.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\idq.dll
+ 2007-08-13 23:45:18 78,336 -c----w c:\windows\$NtServicePackUninstall$\ieencode.dll
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\iexpress.exe
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\ifmon.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\igmpagnt.dll
+ 2004-08-10 19:00:00 505,344 -c----w c:\windows\$NtServicePackUninstall$\iis.dll
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\ils.dll
+ 2004-08-10 19:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\imagehlp.dll
+ 2004-08-10 19:00:00 150,016 -c----w c:\windows\$NtServicePackUninstall$\imapi.exe
+ 2004-08-10 19:00:00 41,856 -c----w c:\windows\$NtServicePackUninstall$\imapi.sys
+ 2004-08-10 19:00:00 36,921 -c----w c:\windows\$NtServicePackUninstall$\imeshare.dll
+ 2004-08-10 19:00:00 110,080 -c----w c:\windows\$NtServicePackUninstall$\imm32.dll
+ 2004-08-10 19:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\imsinsnt.dll
+ 2004-08-10 19:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\inetcfg.dll
+ 2007-08-21 06:15:44 683,520 -c----w c:\windows\$NtServicePackUninstall$\inetcomm.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\inetmib1.dll
+ 2004-08-10 19:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\inetpp.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\inetppui.dll
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\inetres.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\inetwiz.exe
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\initpki.dll
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\input.dll
+ 2004-08-10 19:00:00 5,504 -c----w c:\windows\$NtServicePackUninstall$\intelide.sys
+ 2004-08-10 19:00:00 36,096 -c----w c:\windows\$NtServicePackUninstall$\intelppm.sys
+ 2004-08-10 19:00:00 29,056 -c----w c:\windows\$NtServicePackUninstall$\ip6fw.sys
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\ipconfig.exe
+ 2006-05-19 12:59:41 94,720 -c----w c:\windows\$NtServicePackUninstall$\iphlpapi.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipinip.sys
+ 2004-08-10 19:00:00 154,112 -c----w c:\windows\$NtServicePackUninstall$\ipmontr.dll
+ 2004-09-29 22:28:37 134,912 -c----w c:\windows\$NtServicePackUninstall$\ipnat.sys
+ 2004-08-10 19:00:00 331,264 -c----w c:\windows\$NtServicePackUninstall$\ipnathlp.dll
+ 2004-08-10 19:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\ippromon.dll
+ 2004-08-10 19:00:00 169,984 -c----w c:\windows\$NtServicePackUninstall$\iprtrmgr.dll
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\ipsec.sys
+ 2004-08-10 19:00:00 349,696 -c----w c:\windows\$NtServicePackUninstall$\ipsecsnp.dll
+ 2004-08-10 19:00:00 182,784 -c----w c:\windows\$NtServicePackUninstall$\ipsecsvc.dll
+ 2004-08-10 19:00:00 384,000 -c----w c:\windows\$NtServicePackUninstall$\ipsmsnap.dll
+ 2004-08-10 19:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\ipv6.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\ipv6mon.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\ipxroute.exe

EasyEEE
2008-12-29, 18:02
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipxwan.dll
+ 2004-08-10 19:00:00 120,320 -c----w c:\windows\$NtServicePackUninstall$\ir41_qc.dll
+ 2004-08-10 19:00:00 338,432 -c----w c:\windows\$NtServicePackUninstall$\ir41_qcx.dll
+ 2004-08-10 19:00:00 755,200 -c----w c:\windows\$NtServicePackUninstall$\ir50_32.dll
+ 2004-08-10 19:00:00 200,192 -c----w c:\windows\$NtServicePackUninstall$\ir50_qc.dll
+ 2004-08-10 19:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\ir50_qcx.dll
+ 2005-06-29 06:43:39 46,592 -c----w c:\windows\$NtServicePackUninstall$\irbus.sys
+ 2005-06-29 06:43:39 46,592 -c----w c:\windows\$NtServicePackUninstall$\irbus.sys.000
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\irenum.sys
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\isapnp.sys
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\isign32.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\isrdbg32.dll
+ 2005-05-27 02:04:27 155,136 -c----w c:\windows\$NtServicePackUninstall$\itircl.dll
+ 2005-05-27 02:04:27 137,216 -c----w c:\windows\$NtServicePackUninstall$\itss.dll
+ 2004-08-10 19:00:00 192,000 -c----w c:\windows\$NtServicePackUninstall$\iuengine.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\ixsso.dll
+ 2004-08-04 00:56:44 47,616 -c----w c:\windows\$NtServicePackUninstall$\iyuv_32.dll
+ 2006-06-01 18:47:07 163,840 -c----w c:\windows\$NtServicePackUninstall$\jgdw400.dll
+ 2006-06-01 18:47:07 27,648 -c----w c:\windows\$NtServicePackUninstall$\jgpl400.dll
+ 2007-08-13 23:38:04 491,520 -c----w c:\windows\$NtServicePackUninstall$\jscript.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\kbdclass.sys
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdfi1.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdinbe1.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinben.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinmal.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\kbdmaori.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt47.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt48.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdnec.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdno1.dll
+ 2004-08-10 19:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsfi.dll
+ 2004-08-10 19:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsno.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdukx.dll
+ 2004-08-10 19:00:00 7,424 -c----w c:\windows\$NtServicePackUninstall$\kd1394.dll
+ 2005-06-15 17:49:30 295,936 -c----w c:\windows\$NtServicePackUninstall$\kerberos.dll
+ 2007-04-16 15:52:53 984,576 -c----w c:\windows\$NtServicePackUninstall$\kernel32.dll
+ 2004-08-10 19:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\keymgr.dll
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys.000
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\krnlprov.dll
+ 2004-08-04 03:15:22 140,928 -c----w c:\windows\$NtServicePackUninstall$\ks.sys
+ 2004-08-10 19:00:00 92,032 -c----w c:\windows\$NtServicePackUninstall$\ksecdd.sys
+ 2004-08-04 04:56:44 4,096 -c----w c:\windows\$NtServicePackUninstall$\ksuser.dll
+ 2004-08-10 19:00:00 423,936 -c----w c:\windows\$NtServicePackUninstall$\licdll.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\licwmi.dll
+ 2005-09-01 01:41:53 19,968 -c----w c:\windows\$NtServicePackUninstall$\linkinfo.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\lmhsvc.dll
+ 2004-08-10 19:00:00 399,872 -c----w c:\windows\$NtServicePackUninstall$\lmrt.dll
+ 2004-08-10 19:00:00 97,280 -c----w c:\windows\$NtServicePackUninstall$\loadperf.dll
+ 2004-08-10 19:00:00 221,696 -c----w c:\windows\$NtServicePackUninstall$\localsec.dll
+ 2004-08-10 19:00:00 341,504 -c----w c:\windows\$NtServicePackUninstall$\localspl.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\localui.dll
+ 2004-08-10 19:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\locator.exe
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\log.dll
+ 2004-08-10 19:00:00 59,392 -c----w c:\windows\$NtServicePackUninstall$\logman.exe
+ 2004-08-10 19:00:00 220,672 -c----w c:\windows\$NtServicePackUninstall$\logon.scr
+ 2004-08-10 19:00:00 514,560 -c----w c:\windows\$NtServicePackUninstall$\logonui.exe
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\lpk.dll
+ 2004-08-10 19:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\lprhelp.dll
+ 2007-11-07 09:26:56 721,920 -c----w c:\windows\$NtServicePackUninstall$\lsasrv.dll
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\lsass.exe
+ 2004-08-10 19:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\magnify.exe
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\makecab.exe
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mcastmib.dll
+ 2004-08-10 19:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\mciavi32.dll
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\mciqtz32.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\mciseq.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\mciwave.dll
+ 2004-08-10 19:00:00 118,272 -c----w c:\windows\$NtServicePackUninstall$\mdminst.dll
+ 2004-08-03 23:07:46 63,744 -c----w c:\windows\$NtServicePackUninstall$\mf.sys
+ 2007-03-08 15:36:28 40,960 -c----w c:\windows\$NtServicePackUninstall$\mf3216.dll
+ 2006-11-01 19:17:45 927,504 -c----w c:\windows\$NtServicePackUninstall$\mfc40u.dll
+ 2004-08-10 19:00:00 1,028,096 -c----w c:\windows\$NtServicePackUninstall$\mfc42.dll
+ 2004-08-10 19:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\mfcsubs.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mgmtapi.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\midimap.dll
+ 2004-08-10 19:00:00 201,216 -c----w c:\windows\$NtServicePackUninstall$\migism.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\miglibnt.dll
+ 2004-08-10 19:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\migload.exe
+ 2004-08-10 19:00:00 240,128 -c----w c:\windows\$NtServicePackUninstall$\migwiz.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\mimefilt.dll
+ 2004-08-10 19:00:00 586,240 -c----w c:\windows\$NtServicePackUninstall$\mlang.dll
+ 2004-08-10 19:00:00 815,104 -c----w c:\windows\$NtServicePackUninstall$\mmc.exe
+ 2004-08-10 19:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\mmcbase.dll
+ 2004-08-10 19:00:00 1,192,960 -c----w c:\windows\$NtServicePackUninstall$\mmcndmgr.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\mmcshext.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\mmfutil.dll
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\mnmdd.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\mnmsrvc.exe
+ 2004-08-10 19:00:00 207,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.exe
+ 2004-08-03 23:08:06 30,080 -c----w c:\windows\$NtServicePackUninstall$\modem.sys
+ 2004-08-10 19:00:00 153,600 -c----w c:\windows\$NtServicePackUninstall$\modemui.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\mofcomp.exe
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\mofd.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\more.com
+ 2004-08-10 19:00:00 216,064 -c----w c:\windows\$NtServicePackUninstall$\moricons.dll
+ 2004-08-03 22:58:34 23,040 -c----w c:\windows\$NtServicePackUninstall$\mouclass.sys
+ 2004-08-10 19:00:00 42,240 -c----w c:\windows\$NtServicePackUninstall$\mountmgr.sys
+ 2004-08-10 19:00:00 3,555,328 -c----w c:\windows\$NtServicePackUninstall$\moviemk.exe
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\mplay32.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\mpr.dll
+ 2004-08-10 19:00:00 87,040 -c----w c:\windows\$NtServicePackUninstall$\mprapi.dll
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\mprdim.dll
+ 2007-07-06 10:05:47 72,960 -c----w c:\windows\$NtServicePackUninstall$\mqac.sys
+ 2007-07-06 12:46:59 138,240 -c----w c:\windows\$NtServicePackUninstall$\mqad.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\mqbkup.exe
+ 2007-07-06 12:46:59 47,104 -c----w c:\windows\$NtServicePackUninstall$\mqdscli.dll
+ 2007-07-06 12:46:59 16,896 -c----w c:\windows\$NtServicePackUninstall$\mqise.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\mqlogmgr.dll
+ 2004-08-10 19:00:00 225,280 -c----w c:\windows\$NtServicePackUninstall$\mqoa.dll
+ 2007-07-06 12:46:59 660,992 -c----w c:\windows\$NtServicePackUninstall$\mqqm.dll
+ 2007-07-06 12:46:59 177,152 -c----w c:\windows\$NtServicePackUninstall$\mqrt.dll
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\mqrtdep.dll
+ 2007-07-06 12:46:59 95,744 -c----w c:\windows\$NtServicePackUninstall$\mqsec.dll
+ 2004-08-10 19:00:00 517,632 -c----w c:\windows\$NtServicePackUninstall$\mqsnap.dll
+ 2004-08-10 19:00:00 4,608 -c----w c:\windows\$NtServicePackUninstall$\mqsvc.exe
+ 2004-08-10 19:00:00 117,248 -c----w c:\windows\$NtServicePackUninstall$\mqtgsvc.exe
+ 2004-08-10 19:00:00 186,880 -c----w c:\windows\$NtServicePackUninstall$\mqtrig.dll
+ 2007-07-06 12:46:59 48,640 -c----w c:\windows\$NtServicePackUninstall$\mqupgrd.dll
+ 2007-07-06 12:46:59 471,552 -c----w c:\windows\$NtServicePackUninstall$\mqutil.dll
+ 2007-12-18 09:51:35 179,584 -c----w c:\windows\$NtServicePackUninstall$\mrxdav.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys.000
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\msacm32.dll
+ 2004-08-10 19:00:00 331,776 -c----w c:\windows\$NtServicePackUninstall$\msadce.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msadcer.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msadcf.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcfr.dll
+ 2006-03-23 05:44:21 143,360 -c----w c:\windows\$NtServicePackUninstall$\msadco.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcor.dll
+ 2004-08-10 19:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\msadcs.dll
+ 2004-08-10 19:00:00 155,648 -c----w c:\windows\$NtServicePackUninstall$\msadds.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msaddsr.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msader15.dll
+ 2006-12-26 13:07:23 536,576 -c----w c:\windows\$NtServicePackUninstall$\msado15.dll
+ 2006-12-26 13:07:23 180,224 -c----w c:\windows\$NtServicePackUninstall$\msadomd.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msador15.dll
+ 2006-12-26 13:07:23 200,704 -c----w c:\windows\$NtServicePackUninstall$\msadox.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msadrh15.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\msafd.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\msapsspc.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msasn1.dll
+ 2004-08-10 19:00:00 220,160 -c----w c:\windows\$NtServicePackUninstall$\mscandui.dll
+ 2005-06-29 01:46:00 74,240 -c----w c:\windows\$NtServicePackUninstall$\mscms.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\msconf.dll
+ 2004-08-10 19:00:00 158,208 -c----w c:\windows\$NtServicePackUninstall$\msconfig.exe
+ 2007-01-02 21:28:28 2,273,280 -c----w c:\windows\$NtServicePackUninstall$\mscorsvr.dll
+ 2007-01-02 21:28:46 2,281,472 -c----w c:\windows\$NtServicePackUninstall$\mscorwks.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mscpx32r.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\mscpxl32.dll
+ 2008-02-26 11:59:50 294,912 -c----w c:\windows\$NtServicePackUninstall$\msctf.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\msctfp.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdadc.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdadiag.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaenum.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaer.dll
+ 2002-05-25 03:22:16 532,480 -c----w c:\windows\$NtServicePackUninstall$\msdaipp.dll
+ 2004-08-10 19:00:00 233,472 -c----w c:\windows\$NtServicePackUninstall$\msdaora.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaorar.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\msdaosp.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaprsr.dll
+ 2004-08-10 19:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\msdaprst.dll
+ 2004-08-10 19:00:00 204,800 -c----w c:\windows\$NtServicePackUninstall$\msdaps.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdarem.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaremr.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\msdart.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdasc.dll
+ 2004-08-10 19:00:00 315,392 -c----w c:\windows\$NtServicePackUninstall$\msdasql.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdasqlr.dll
+ 2004-08-10 19:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\msdatl3.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msdatt.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaurl.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\msdfmap.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\msdmo.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\msdtc.exe
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\msdtclog.dll
+ 2006-03-01 19:42:42 426,496 -c----w c:\windows\$NtServicePackUninstall$\msdtcprx.dll
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\msdtcstp.dll
+ 2006-03-01 19:42:42 956,416 -c----w c:\windows\$NtServicePackUninstall$\msdtctm.dll
+ 2006-03-01 19:42:42 161,280 -c----w c:\windows\$NtServicePackUninstall$\msdtcuiu.dll
+ 2004-08-10 19:00:00 4,126 -c----w c:\windows\$NtServicePackUninstall$\msdxmlc.dll
+ 2004-08-10 19:00:00 19,072 -c----w c:\windows\$NtServicePackUninstall$\msfs.sys
+ 2006-11-27 14:54:06 539,136 -c----w c:\windows\$NtServicePackUninstall$\msftedit.dll
+ 2004-08-10 19:00:00 994,304 -c----w c:\windows\$NtServicePackUninstall$\msgina.dll
+ 2004-08-10 19:00:00 35,072 -c----w c:\windows\$NtServicePackUninstall$\msgpc.sys
+ 2004-08-10 19:00:00 3,166,208 -c----w c:\windows\$NtServicePackUninstall$\msgr3en.dll
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\msgrocm.dll
+ 2004-08-04 16:06:34 82,944 -c----w c:\windows\$NtServicePackUninstall$\msgsc.dll
+ 2004-08-04 16:06:34 180,224 -c----w c:\windows\$NtServicePackUninstall$\msgslang.dll
+ 2004-08-10 19:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\msgsvc.dll
+ 2004-08-10 19:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\msh261.drv
+ 2004-08-04 00:56:58 294,912 -c----w c:\windows\$NtServicePackUninstall$\msh263.drv
+ 2007-04-18 16:12:23 2,854,400 -c----w c:\windows\$NtServicePackUninstall$\msi.dll
+ 2004-08-10 19:00:00 51,712 -c----w c:\windows\$NtServicePackUninstall$\msident.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\msidle.dll
+ 2004-08-10 19:00:00 248,832 -c----w c:\windows\$NtServicePackUninstall$\msieftp.dll
+ 2005-05-04 19:45:36 78,848 -c----w c:\windows\$NtServicePackUninstall$\msiexec.exe
+ 2005-05-04 19:45:36 271,360 -c----w c:\windows\$NtServicePackUninstall$\msihnd.dll
+ 2004-08-10 19:00:00 4,608 -c----w c:\windows\$NtServicePackUninstall$\msimg32.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\msimn.exe
+ 2005-05-04 19:45:36 884,736 -c----w c:\windows\$NtServicePackUninstall$\msimsg.dll
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\msimtf.dll
+ 2004-08-10 19:00:00 376,320 -c----w c:\windows\$NtServicePackUninstall$\msinfo.dll
+ 2005-05-04 19:45:36 15,360 -c----w c:\windows\$NtServicePackUninstall$\msisip.dll
+ 2008-03-27 08:12:54 151,583 -c----w c:\windows\$NtServicePackUninstall$\msjint40.dll
+ 2006-12-26 13:07:23 102,400 -c----w c:\windows\$NtServicePackUninstall$\msjro.dll
+ 2004-08-04 02:58:42 7,552 -c----w c:\windows\$NtServicePackUninstall$\mskssrv.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mslbui.dll
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\mslwvtts.dll
+ 2004-08-10 19:00:00 169,984 -c----w c:\windows\$NtServicePackUninstall$\msmqocm.dll
+ 2004-10-13 23:24:37 1,694,208 -c----w c:\windows\$NtServicePackUninstall$\msmsgs.exe
+ 2004-08-10 19:00:00 290,816 -c----w c:\windows\$NtServicePackUninstall$\msnsspc.dll
+ 2004-08-10 19:00:00 122,368 -c----w c:\windows\$NtServicePackUninstall$\msobcomm.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msobdl.dll
+ 2004-08-10 19:00:00 561,664 -c----w c:\windows\$NtServicePackUninstall$\msobmain.dll
+ 2004-08-10 19:00:00 30,720 -c----w c:\windows\$NtServicePackUninstall$\msobshel.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\msobweb.dll
+ 2007-05-16 15:12:08 1,314,816 -c----w c:\windows\$NtServicePackUninstall$\msoe.dll
+ 2004-08-10 19:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\msoeacct.dll
+ 2004-08-10 19:00:00 2,479,616 -c----w c:\windows\$NtServicePackUninstall$\msoeres.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\msoert2.dll
+ 2004-08-10 19:00:00 28,160 -c----w c:\windows\$NtServicePackUninstall$\msoobe.exe
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msorc32r.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\msorcl32.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\mspaint.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\mspatcha.dll
+ 2004-08-04 02:58:40 5,376 -c----w c:\windows\$NtServicePackUninstall$\mspclock.sys
+ 2004-08-04 02:58:42 4,992 -c----w c:\windows\$NtServicePackUninstall$\mspqm.sys
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\msprivs.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\msrle32.dll
+ 2004-08-10 19:00:00 134,656 -c----w c:\windows\$NtServicePackUninstall$\mssap.dll
+ 2004-08-03 23:07:48 15,488 -c----w c:\windows\$NtServicePackUninstall$\mssmbios.sys
+ 2004-08-10 19:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\mst120.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\mst123.dll
+ 2004-08-10 19:00:00 274,944 -c----w c:\windows\$NtServicePackUninstall$\mstask.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mstinit.exe
+ 2004-08-10 19:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\mstlsapi.dll
+ 2004-08-10 19:00:00 407,552 -c----w c:\windows\$NtServicePackUninstall$\mstsc.exe
+ 2004-08-10 19:00:00 655,360 -c----w c:\windows\$NtServicePackUninstall$\mstscax.dll
+ 2004-08-10 19:00:00 195,072 -c----w c:\windows\$NtServicePackUninstall$\msutb.dll
+ 2004-08-10 19:00:00 129,536 -c----w c:\windows\$NtServicePackUninstall$\msv1_0.dll
+ 2004-08-10 19:00:00 1,392,671 -c----w c:\windows\$NtServicePackUninstall$\msvbvm60.dll
+ 2004-08-10 19:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\msvcirt.dll
+ 2004-08-10 19:00:00 413,696 -c----w c:\windows\$NtServicePackUninstall$\msvcp60.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\msvcrt.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msvcrt40.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\msvfw32.dll
+ 2004-08-10 19:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\msw3prt.dll
+ 2004-08-10 19:00:00 204,288 -c----w c:\windows\$NtServicePackUninstall$\mswebdvd.dll
+ 2008-06-20 17:41:10 245,248 -c----w c:\windows\$NtServicePackUninstall$\mswsock.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msxactps.dll
+ 2004-08-10 19:00:00 506,368 -c----w c:\windows\$NtServicePackUninstall$\msxml.dll
+ 2004-08-10 19:00:00 701,440 -c----w c:\windows\$NtServicePackUninstall$\msxml2.dll
+ 2007-06-26 06:08:16 1,104,896 -c----w c:\windows\$NtServicePackUninstall$\msxml3.dll
+ 2004-08-04 00:56:46 17,408 -c----w c:\windows\$NtServicePackUninstall$\msyuv.dll
+ 2006-03-01 19:42:42 66,560 -c----w c:\windows\$NtServicePackUninstall$\mtxclu.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\mtxdm.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\mtxex.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mtxlegih.dll
+ 2006-03-01 19:42:42 91,136 -c----w c:\windows\$NtServicePackUninstall$\mtxoci.dll
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\muisetup.exe
+ 2004-08-10 19:00:00 107,904 -c----w c:\windows\$NtServicePackUninstall$\mup.sys
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\mydocs.dll
+ 2004-08-10 19:00:00 221,184 -c----w c:\windows\$NtServicePackUninstall$\nac.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\narrator.exe
+ 2004-08-10 19:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\ncobjapi.dll
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ncprov.dll
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\nddeapi.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\nddeapir.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\nddenb32.dll
+ 2004-08-10 19:00:00 182,912 -c----w c:\windows\$NtServicePackUninstall$\ndis.sys
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\ndisnpp.dll
+ 2004-08-10 19:00:00 9,600 -c----w c:\windows\$NtServicePackUninstall$\ndistapi.sys
+ 2005-06-21 08:52:55 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys
+ 2005-06-21 08:52:55 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys.000
+ 2004-08-10 19:00:00 91,776 -c----w c:\windows\$NtServicePackUninstall$\ndiswan.sys
+ 2004-08-10 19:00:00 38,016 -c----w c:\windows\$NtServicePackUninstall$\ndproxy.sys
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\net.exe
+ 2004-08-10 19:00:00 124,928 -c----w c:\windows\$NtServicePackUninstall$\net1.exe
+ 2006-08-17 12:28:27 332,288 -c----w c:\windows\$NtServicePackUninstall$\netapi32.dll
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\netbios.sys
+ 2004-08-10 19:00:00 162,816 -c----w c:\windows\$NtServicePackUninstall$\netbt.sys
+ 2004-08-10 19:00:00 622,080 -c----w c:\windows\$NtServicePackUninstall$\netcfgx.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\netdde.exe
+ 2007-01-15 21:11:26 73,728 -c----w c:\windows\$NtServicePackUninstall$\netfxupdate.exe
+ 2004-08-10 19:00:00 139,264 -c----w c:\windows\$NtServicePackUninstall$\netid.dll
+ 2004-08-10 19:00:00 407,040 -c----w c:\windows\$NtServicePackUninstall$\netlogon.dll
+ 2005-08-22 18:29:46 197,632 -c----w c:\windows\$NtServicePackUninstall$\netman.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\netoc.dll
+ 2004-08-10 19:00:00 875,008 -c----w c:\windows\$NtServicePackUninstall$\netplwiz.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\netrap.dll
+ 2004-08-10 19:00:00 329,728 -c----w c:\windows\$NtServicePackUninstall$\netsetup.exe
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\netsh.exe
+ 2005-06-22 05:00:18 1,705,472 -c----w c:\windows\$NtServicePackUninstall$\netshell.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\netstat.exe
+ 2004-08-10 19:00:00 80,896 -c----w c:\windows\$NtServicePackUninstall$\netui0.dll
+ 2004-08-10 19:00:00 245,760 -c----w c:\windows\$NtServicePackUninstall$\netui1.dll
+ 2004-08-10 19:00:00 248,832 -c----w c:\windows\$NtServicePackUninstall$\newdev.dll
+ 2004-08-03 22:58:30 61,824 -c----w c:\windows\$NtServicePackUninstall$\nic1394.sys
+ 2004-08-10 19:00:00 103,936 -c----w c:\windows\$NtServicePackUninstall$\nlhtml.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\nmas.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmasnt.dll
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\nmchat.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\nmcom.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\nmft.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmmkcert.dll
+ 2004-08-10 19:00:00 40,320 -c----w c:\windows\$NtServicePackUninstall$\nmnt.sys
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\nmoldwb.dll
+ 2004-08-10 19:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\nmwb.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\notepad.exe
+ 2004-08-10 19:00:00 30,848 -c----w c:\windows\$NtServicePackUninstall$\npfs.sys
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\nppagent.exe
+ 2004-08-10 19:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\npptools.dll
+ 2004-08-10 19:00:00 76,800 -c----w c:\windows\$NtServicePackUninstall$\nslookup.exe
+ 2004-08-10 19:00:00 1,200,128 -c----w c:\windows\$NtServicePackUninstall$\ntbackup.exe
+ 2004-08-10 19:00:00 708,096 -c----w c:\windows\$NtServicePackUninstall$\ntdll.dll
+ 2004-08-10 19:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\ntdsapi.dll
+ 2004-08-10 19:00:00 212,992 -c----w c:\windows\$NtServicePackUninstall$\ntevt.dll
+ 2007-02-09 11:10:35 574,464 -c----w c:\windows\$NtServicePackUninstall$\ntfs.sys
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe.000
+ 2007-02-28 08:38:55 2,057,600 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
+ 2007-02-28 08:38:55 2,057,600 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe.000
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe.000
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\ntlanman.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\ntlsapi.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\ntmarta.dll
+ 2004-08-10 19:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\ntmsapi.dll
+ 2004-08-10 19:00:00 179,712 -c----w c:\windows\$NtServicePackUninstall$\ntmsdba.dll
+ 2004-08-10 19:00:00 488,448 -c----w c:\windows\$NtServicePackUninstall$\ntmsmgr.dll
+ 2004-08-10 19:00:00 435,200 -c----w c:\windows\$NtServicePackUninstall$\ntmssvc.dll
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\ntoc.dll
+ 2007-02-28 09:10:57 2,180,352 -c----w c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
+ 2007-02-28 09:10:57 2,180,352 -c----w c:\windows\$NtServicePackUninstall$\ntoskrnl.exe.000
+ 2004-08-10 19:00:00 91,136 -c----w c:\windows\$NtServicePackUninstall$\ntprint.dll
+ 2004-08-10 19:00:00 143,872 -c----w c:\windows\$NtServicePackUninstall$\ntshrui.dll
+ 2004-08-10 19:00:00 419,840 -c----w c:\windows\$NtServicePackUninstall$\ntvdm.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\ntvdmd.dll
+ 2006-10-13 12:35:12 64,000 -c----w c:\windows\$NtServicePackUninstall$\nwapi32.dll
+ 2004-08-10 19:00:00 88,448 -c----w c:\windows\$NtServicePackUninstall$\nwlnkipx.sys
+ 2006-10-13 12:35:12 142,336 -c----w c:\windows\$NtServicePackUninstall$\nwprovau.dll
+ 2006-10-13 10:23:15 163,584 -c----w c:\windows\$NtServicePackUninstall$\nwrdr.sys
+ 2006-10-13 12:35:12 65,536 -c----w c:\windows\$NtServicePackUninstall$\nwwks.dll
+ 2004-08-10 19:00:00 266,752 -c----w c:\windows\$NtServicePackUninstall$\oakley.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\obelog.dll
+ 2004-08-10 19:00:00 966,656 -c----w c:\windows\$NtServicePackUninstall$\obemetal.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\obemtllc.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\obepopc.dll
+ 2004-08-10 19:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\objsel.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\ocgen.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\ocmanage.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\ocmsn.dll
+ 2004-08-10 19:00:00 249,856 -c----w c:\windows\$NtServicePackUninstall$\odbc32.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\odbc32gt.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\odbcad32.exe
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\odbcbcp.dll
+ 2004-08-10 19:00:00 135,168 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.exe
+ 2004-08-10 19:00:00 106,496 -c----w c:\windows\$NtServicePackUninstall$\odbccp32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccr32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccu32.dll
+ 2004-08-10 19:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\odbcint.dll
+ 2004-08-10 19:00:00 53,279 -c----w c:\windows\$NtServicePackUninstall$\odbcji32.dll
+ 2004-08-10 19:00:00 278,559 -c----w c:\windows\$NtServicePackUninstall$\odbcjt32.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\odbcp32r.dll
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\odbctrac.dll
+ 2004-08-10 19:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\oddbse32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odexl32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odfox32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odpdx32.dll
+ 2004-08-10 19:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\odtext32.dll
+ 2004-08-10 19:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\oeimport.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\oemig50.exe
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\oemiglib.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\offfilt.dll
+ 2004-08-04 07:10:10 61,056 -c----w c:\windows\$NtServicePackUninstall$\ohci1394.sys
+ 2005-07-26 04:39:48 1,285,120 -c----w c:\windows\$NtServicePackUninstall$\ole32.dll
+ 2007-12-04 18:38:13 550,912 -c----w c:\windows\$NtServicePackUninstall$\oleaut32.dll
+ 2005-07-26 04:39:48 74,752 -c----w c:\windows\$NtServicePackUninstall$\olecli32.dll
+ 2005-07-26 04:39:49 37,888 -c----w c:\windows\$NtServicePackUninstall$\olecnv32.dll
+ 2004-08-10 19:00:00 487,424 -c----w c:\windows\$NtServicePackUninstall$\oledb32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\oledb32r.dll
+ 2006-10-16 16:15:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\oledlg.dll
+ 2004-08-10 19:00:00 107,008 -c----w c:\windows\$NtServicePackUninstall$\oleprn.dll
+ 2004-08-10 19:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\olepro32.dll
+ 2004-08-10 19:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\oobebaln.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\openfiles.exe
+ 2004-08-10 19:00:00 713,728 -c----w c:\windows\$NtServicePackUninstall$\opengl32.dll
+ 2004-08-10 19:00:00 215,552 -c----w c:\windows\$NtServicePackUninstall$\osk.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\osuninst.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\p2p.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\p2pgasvc.dll
+ 2004-08-10 19:00:00 312,320 -c----w c:\windows\$NtServicePackUninstall$\p2pgraph.dll
+ 2004-08-10 19:00:00 88,064 -c----w c:\windows\$NtServicePackUninstall$\p2pnetsh.dll
+ 2004-08-10 19:00:00 526,848 -c----w c:\windows\$NtServicePackUninstall$\p2psvc.dll
+ 2004-08-03 22:59:20 42,496 -c----w c:\windows\$NtServicePackUninstall$\p3.sys
+ 2004-08-10 19:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\packager.exe
+ 2004-08-03 22:59:08 80,128 -c----w c:\windows\$NtServicePackUninstall$\parport.sys
+ 2004-08-10 19:00:00 18,688 -c----w c:\windows\$NtServicePackUninstall$\partmgr.sys
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\pautoenr.dll
+ 2004-08-10 19:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\pchshell.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\pchsvc.dll
+ 2004-08-10 19:00:00 68,224 -c----w c:\windows\$NtServicePackUninstall$\pci.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\pciidex.sys
+ 2004-08-10 19:00:00 119,936 -c----w c:\windows\$NtServicePackUninstall$\pcmcia.sys
+ 2004-08-10 19:00:00 283,648 -c----w c:\windows\$NtServicePackUninstall$\pdh.dll
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\perfctrs.dll
+ 2004-08-10 19:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\perfdisk.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\perfmon.exe
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\perfnet.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\perfos.dll
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\perfproc.dll
+ 2004-08-10 19:00:00 176,128 -c----w c:\windows\$NtServicePackUninstall$\photowiz.dll
+ 2004-08-04 00:56:46 35,328 -c----w c:\windows\$NtServicePackUninstall$\pid.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\pidgen.dll
+ 2004-08-10 19:00:00 281,088 -c----w c:\windows\$NtServicePackUninstall$\pinball.exe
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\ping.exe
+ 2004-08-04 00:56:46 15,360 -c----w c:\windows\$NtServicePackUninstall$\pjlmon.dll
+ 2004-08-10 19:00:00 48,640 -c----w c:\windows\$NtServicePackUninstall$\pnrpnsp.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\policman.dll
+ 2004-08-10 19:00:00 105,472 -c----w c:\windows\$NtServicePackUninstall$\polstore.dll
+ 2004-03-16 14:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys
+ 2004-03-16 14:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys.000
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\powercfg.exe
+ 2005-06-25 06:47:40 8,832 -c----w c:\windows\$NtServicePackUninstall$\powerfil.sys
+ 2005-06-25 06:47:40 8,832 -c----w c:\windows\$NtServicePackUninstall$\powerfil.sys.000
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\powrprof.dll
+ 2004-08-10 19:00:00 560,640 -c----w c:\windows\$NtServicePackUninstall$\printui.dll
+ 2004-08-03 22:59:18 35,328 -c----w c:\windows\$NtServicePackUninstall$\processr.sys
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\profmap.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\progman.exe
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\proquota.exe
+ 2004-08-10 19:00:00 237,056 -c----w c:\windows\$NtServicePackUninstall$\provthrd.dll
+ 2004-08-10 19:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\proxycfg.exe
+ 2003-05-05 20:47:20 129,024 -c----w c:\windows\$NtServicePackUninstall$\ps5ui.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\psapi.dll
+ 2004-08-10 19:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\psbase.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\psched.sys
+ 2003-05-05 20:47:20 455,168 -c----w c:\windows\$NtServicePackUninstall$\pscript5.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\pstorec.dll
+ 2004-08-10 19:00:00 34,304 -c----w c:\windows\$NtServicePackUninstall$\pstorsvc.dll
+ 2004-08-10 19:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\qcap.dll
+ 2004-08-10 19:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\qdv.dll
+ 2005-06-29 08:55:07 385,024 -c----w c:\windows\$NtServicePackUninstall$\qdvd.dll
+ 2004-08-10 19:00:00 562,176 -c----w c:\windows\$NtServicePackUninstall$\qedit.dll
+ 2004-08-10 19:00:00 733,696 -c----w c:\windows\$NtServicePackUninstall$\qedwipes.dll
+ 2004-08-10 19:00:00 382,464 -c----w c:\windows\$NtServicePackUninstall$\qmgr.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\qmgrprxy.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\qprocess.exe
+ 2008-05-07 04:55:40 1,288,192 -c----w c:\windows\$NtServicePackUninstall$\quartz.dll
+ 2006-06-22 05:06:30 1,435,648 -c----w c:\windows\$NtServicePackUninstall$\query.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\racpldlg.dll
+ 2006-06-26 17:37:10 8,192 -c----w c:\windows\$NtServicePackUninstall$\rasadhlp.dll
+ 2004-08-10 19:00:00 236,544 -c----w c:\windows\$NtServicePackUninstall$\rasapi32.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\rasauto.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\raschap.dll
+ 2004-08-10 19:00:00 657,920 -c----w c:\windows\$NtServicePackUninstall$\rasdlg.dll
+ 2004-08-10 19:00:00 51,328 -c----w c:\windows\$NtServicePackUninstall$\rasl2tp.sys
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rasman.dll
+ 2006-06-22 10:47:18 181,248 -c----w c:\windows\$NtServicePackUninstall$\rasmans.dll
+ 2004-08-10 19:00:00 56,832 -c----w c:\windows\$NtServicePackUninstall$\rasphone.exe
+ 2004-08-10 19:00:00 206,336 -c----w c:\windows\$NtServicePackUninstall$\rasppp.dll
+ 2004-08-10 19:00:00 41,472 -c----w c:\windows\$NtServicePackUninstall$\raspppoe.sys
+ 2004-08-10 19:00:00 48,384 -c----w c:\windows\$NtServicePackUninstall$\raspptp.sys
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\rassapi.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\rastapi.dll
+ 2004-08-10 19:00:00 112,128 -c----w c:\windows\$NtServicePackUninstall$\rastls.dll
+ 2004-08-10 19:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\rcbdyctl.dll
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\rcimlby.exe
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\rcp.exe
+ 2006-05-05 09:47:57 174,592 -c----w c:\windows\$NtServicePackUninstall$\rdbss.sys
+ 2004-08-10 19:00:00 147,968 -c----w c:\windows\$NtServicePackUninstall$\rdchost.dll
+ 2004-08-10 19:00:00 62,464 -c----w c:\windows\$NtServicePackUninstall$\rdpclip.exe
+ 2004-08-10 19:00:00 92,168 -c----w c:\windows\$NtServicePackUninstall$\rdpdd.dll
+ 2004-08-03 23:01:16 196,864 -c----w c:\windows\$NtServicePackUninstall$\rdpdr.sys
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\rdpsnd.dll
+ 2005-06-10 04:09:46 139,528 -c----w c:\windows\$NtServicePackUninstall$\rdpwd.sys
+ 2004-08-10 19:00:00 87,176 -c----w c:\windows\$NtServicePackUninstall$\rdpwsx.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rdsaddin.exe
+ 2004-08-10 19:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\rdshost.exe
+ 2004-08-03 22:59:38 57,472 -c----w c:\windows\$NtServicePackUninstall$\redbook.sys
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\reg.exe
+ 2004-08-10 19:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\regapi.dll
+ 2004-08-10 19:00:00 146,432 -c----w c:\windows\$NtServicePackUninstall$\regedit.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\regsvc.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\regsvr32.exe
+ 2004-08-10 19:00:00 397,824 -c----w c:\windows\$NtServicePackUninstall$\regwizc.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\remotepg.dll
+ 2004-08-10 19:00:00 177,152 -c----w c:\windows\$NtServicePackUninstall$\repdrvfs.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\resutils.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rexec.exe
+ 2006-11-27 14:54:06 433,152 -c----w c:\windows\$NtServicePackUninstall$\riched20.dll
+ 2008-05-08 12:28:49 202,752 -c----w c:\windows\$NtServicePackUninstall$\rmcast.sys
+ 2004-08-10 19:00:00 30,080 -c----w c:\windows\$NtServicePackUninstall$\rndismp.sys
+ 2007-07-09 13:16:16 582,656 -c----w c:\windows\$NtServicePackUninstall$\rpcrt4.dll
+ 2005-07-26 04:39:49 397,824 -c----w c:\windows\$NtServicePackUninstall$\rpcss.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rrcm.dll
+ 2004-08-10 19:00:00 152,576 -c----w c:\windows\$NtServicePackUninstall$\rsaenh.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\rsh.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\rshx32.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\rsmps.dll
+ 2004-08-10 19:00:00 107,520 -c----w c:\windows\$NtServicePackUninstall$\rsnotify.exe
+ 2004-08-10 19:00:00 380,416 -c----w c:\windows\$NtServicePackUninstall$\rstrui.exe
+ 2004-08-10 19:00:00 90,112 -c----w c:\windows\$NtServicePackUninstall$\rsvpsp.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\rtcshare.exe
+ 2004-08-10 19:00:00 31,744 -c----w c:\windows\$NtServicePackUninstall$\rtipxmib.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\rtutils.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\rundll32.exe
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\runonce.exe
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\safrcdlg.dll
+ 2004-08-10 19:00:00 29,696 -c----w c:\windows\$NtServicePackUninstall$\safrdm.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\safrslv.dll
+ 2004-08-10 19:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\samlib.dll
+ 2004-08-10 19:00:00 415,744 -c----w c:\windows\$NtServicePackUninstall$\samsrv.dll
+ 2004-08-10 19:00:00 741,376 -c----w c:\windows\$NtServicePackUninstall$\sapi.dll
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\savedump.exe
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\sbeio.dll
+ 2005-06-01 06:46:29 43,264 -c----w c:\windows\$NtServicePackUninstall$\sbp2port.sys
+ 2005-06-01 06:46:29 43,264 -c----w c:\windows\$NtServicePackUninstall$\sbp2port.sys.000
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\scarddlg.dll
+ 2004-08-10 19:00:00 95,744 -c----w c:\windows\$NtServicePackUninstall$\scardsvr.exe
+ 2004-08-10 19:00:00 171,008 -c----w c:\windows\$NtServicePackUninstall$\sccsccp.dll
+ 2004-08-10 19:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\scecli.dll
+ 2004-08-10 19:00:00 313,856 -c----w c:\windows\$NtServicePackUninstall$\scesrv.dll
+ 2007-04-25 14:21:15 144,896 -c----w c:\windows\$NtServicePackUninstall$\schannel.dll
+ 2004-08-10 19:00:00 190,976 -c----w c:\windows\$NtServicePackUninstall$\schedsvc.dll
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\schtasks.exe
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\sclgntfy.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\scrcons.exe
+ 2004-08-10 19:00:00 202,752 -c----w c:\windows\$NtServicePackUninstall$\script.dll
+ 2004-08-10 19:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\scrnsave.scr
+ 2004-08-10 19:00:00 159,744 -c----w c:\windows\$NtServicePackUninstall$\scrobj.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\scrrun.dll
+ 2004-08-10 19:00:00 96,256 -c----w c:\windows\$NtServicePackUninstall$\scsiport.sys
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\sdbinst.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sdbus.sys
+ 2004-08-10 19:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sdhcinst.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\secedit.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\seclogon.dll
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\secur32.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\security.dll
+ 2004-08-10 19:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sendcmsg.dll
+ 2004-08-10 19:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\sendmail.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\sens.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\sensapi.dll
+ 2004-08-10 19:00:00 15,488 -c----w c:\windows\$NtServicePackUninstall$\serenum.sys
+ 2004-08-10 19:00:00 64,896 -c----w c:\windows\$NtServicePackUninstall$\serial.sys
+ 2004-08-10 19:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\servdeps.dll
+ 2004-08-10 19:00:00 108,032 -c----w c:\windows\$NtServicePackUninstall$\services.exe
+ 2004-08-10 19:00:00 140,800 -c----w c:\windows\$NtServicePackUninstall$\sessmgr.exe
+ 2004-08-10 19:00:00 31,232 -c----w c:\windows\$NtServicePackUninstall$\sethc.exe
+ 2007-01-15 21:11:30 57,344 -c----w c:\windows\$NtServicePackUninstall$\setregni.exe
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\setup.exe
+ 2004-08-10 19:00:00 73,216 -c----w c:\windows\$NtServicePackUninstall$\setup50.exe
+ 2004-08-10 19:00:00 983,552 -c----w c:\windows\$NtServicePackUninstall$\setupapi.dll
+ 2004-08-10 19:00:00 101,376 -c----w c:\windows\$NtServicePackUninstall$\setupqry.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\sfc.dll
+ 2004-08-10 19:00:00 140,288 -c----w c:\windows\$NtServicePackUninstall$\sfc_os.dll
+ 2004-08-10 19:00:00 1,580,544 -c----w c:\windows\$NtServicePackUninstall$\sfcfiles.dll
+ 2004-08-10 19:00:00 11,136 -c----w c:\windows\$NtServicePackUninstall$\sffdisk.sys
+ 2004-08-10 19:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\sffp_sd.sys
+ 2004-08-10 19:00:00 11,392 -c----w c:\windows\$NtServicePackUninstall$\sfloppy.sys
+ 2004-08-10 19:00:00 549,376 -c----w c:\windows\$NtServicePackUninstall$\shdoclc.dll
+ 2007-12-07 00:44:37 1,499,136 -c----w c:\windows\$NtServicePackUninstall$\shdocvw.dll
+ 2007-10-26 03:34:01 8,460,288 -c----w c:\windows\$NtServicePackUninstall$\shell32.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\shfolder.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\shgina.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\shimeng.dll
+ 2004-08-10 19:00:00 438,272 -c----w c:\windows\$NtServicePackUninstall$\shimgvw.dll
+ 2007-12-07 00:44:38 474,112 -c----w c:\windows\$NtServicePackUninstall$\shlwapi.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\shmedia.dll
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\shmgrate.exe
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\shrpubw.exe
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\shscrap.dll
+ 2006-12-19 21:52:18 134,656 -c----w c:\windows\$NtServicePackUninstall$\shsvcs.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\shutdown.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\sigtab.dll
+ 2004-08-10 19:00:00 70,144 -c----w c:\windows\$NtServicePackUninstall$\sigverif.exe
+ 2004-08-03 23:07:44 41,088 -c----w c:\windows\$NtServicePackUninstall$\sisagp.sys
+ 2004-08-10 19:00:00 26,112 -c----w c:\windows\$NtServicePackUninstall$\skeys.exe
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\slayerxp.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\slbiop.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\smbinst.exe
+ 2004-08-10 19:00:00 363,008 -c----w c:\windows\$NtServicePackUninstall$\smlogcfg.dll
+ 2004-08-10 19:00:00 89,600 -c----w c:\windows\$NtServicePackUninstall$\smlogsvc.exe
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\smss.exe
+ 2004-08-10 19:00:00 131,584 -c----w c:\windows\$NtServicePackUninstall$\sndrec32.exe
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\sniffpol.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\snmpapi.dll
+ 2004-08-10 19:00:00 182,272 -c----w c:\windows\$NtServicePackUninstall$\snmpsnap.dll
+ 2004-08-10 19:00:00 130,048 -c----w c:\windows\$NtServicePackUninstall$\softkbd.dll
+ 2004-08-03 23:09:56 25,472 -c----w c:\windows\$NtServicePackUninstall$\sonydcam.sys
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\sort.exe
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\spgrmr.dll
+ 2004-08-10 19:00:00 538,624 -c----w c:\windows\$NtServicePackUninstall$\spider.exe
+ 2004-08-10 19:00:00 12,800 -c----w c:\windows\$NtServicePackUninstall$\spiisupd.exe
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys.000
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\spnpinst.exe
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\spoolss.dll
+ 2005-06-10 23:53:32 57,856 -c----w c:\windows\$NtServicePackUninstall$\spoolsv.exe
+ 2004-08-10 19:00:00 250,880 -c----w c:\windows\$NtServicePackUninstall$\sptip.dll
+ 2008-04-14 09:42:08 438,272 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spcompat.dll
+ 2007-08-11 00:46:18 231,288 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe
+ 2007-08-11 00:46:28 382,840 -c----w c:\windows\$NtServicePackUninstall$\spuninst\updspapi.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\sqldb20.dll
+ 2004-08-10 19:00:00 528,384 -c----w c:\windows\$NtServicePackUninstall$\sqloledb.dll
+ 2004-08-10 19:00:00 462,848 -c----w c:\windows\$NtServicePackUninstall$\sqlqp20.dll
+ 2004-08-10 19:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\sqlse20.dll
+ 2004-08-10 19:00:00 442,368 -c----w c:\windows\$NtServicePackUninstall$\sqlsrv32.dll
+ 2004-08-10 19:00:00 180,800 -c----w c:\windows\$NtServicePackUninstall$\sqlunirl.dll
+ 2004-08-10 19:00:00 217,088 -c----w c:\windows\$NtServicePackUninstall$\sqlxmlx.dll
+ 2004-08-10 19:00:00 73,472 -c----w c:\windows\$NtServicePackUninstall$\sr.sys
+ 2004-08-10 19:00:00 58,434 -c----w c:\windows\$NtServicePackUninstall$\srchctls.dll
+ 2004-08-10 19:00:00 725,566 -c----w c:\windows\$NtServicePackUninstall$\srchui.dll
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\srclient.dll
+ 2004-08-10 19:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\srrstr.dll
+ 2004-08-10 19:00:00 170,496 -c----w c:\windows\$NtServicePackUninstall$\srsvc.dll
+ 2006-08-14 10:34:41 332,928 -c----w c:\windows\$NtServicePackUninstall$\srv.sys
+ 2004-12-07 19:32:34 96,768 -c----w c:\windows\$NtServicePackUninstall$\srvsvc.dll
+ 2004-08-10 19:00:00 704,512 -c----w c:\windows\$NtServicePackUninstall$\ss3dfo.scr
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ssbezier.scr
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\ssdpapi.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
+ 2004-08-10 19:00:00 393,216 -c----w c:\windows\$NtServicePackUninstall$\ssflwbox.scr
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ssmarque.scr
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ssmypics.scr
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\ssmyst.scr
+ 2004-08-10 19:00:00 610,304 -c----w c:\windows\$NtServicePackUninstall$\sspipes.scr
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\ssstars.scr
+ 2004-08-10 19:00:00 679,936 -c----w c:\windows\$NtServicePackUninstall$\sstext3d.scr
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\sstub.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\stclient.dll
+ 2004-08-10 19:00:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\stdprov.dll
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sti.dll
+ 2004-08-10 19:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\sti_ci.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\stimon.exe
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\stobject.dll
+ 2004-08-04 00:56:46 74,752 -c----w c:\windows\$NtServicePackUninstall$\storprop.dll
+ 2004-08-04 03:08:04 48,640 -c----w c:\windows\$NtServicePackUninstall$\stream.sys
+ 2006-08-21 14:52:08 246,814 -c----w c:\windows\$NtServicePackUninstall$\strmdll.dll
+ 2004-08-10 19:00:00 75,776 -c----w c:\windows\$NtServicePackUninstall$\strmfilt.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\svchost.exe
+ 2004-08-03 22:58:42 4,352 -c----w c:\windows\$NtServicePackUninstall$\swenum.sys
+ 2001-08-17 18:00:52 54,272 -c----w c:\windows\$NtServicePackUninstall$\swmidi.sys
+ 2006-10-19 13:56:32 713,216 -c----w c:\windows\$NtServicePackUninstall$\sxs.dll
+ 2004-08-10 19:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\synceng.dll
+ 2004-08-10 19:00:00 191,488 -c----w c:\windows\$NtServicePackUninstall$\syncui.dll
+ 2004-08-04 03:15:56 60,800 -c----w c:\windows\$NtServicePackUninstall$\sysaudio.sys
+ 2004-08-10 19:00:00 168,960 -c----w c:\windows\$NtServicePackUninstall$\sysmod.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\sysocmgr.exe
+ 2004-08-10 19:00:00 984,576 -c----w c:\windows\$NtServicePackUninstall$\syssetup.dll
+ 2004-07-20 09:54:18 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\system.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\systeminfo.exe
+ 2005-10-17 21:14:46 118,272 -c----w c:\windows\$NtServicePackUninstall$\t2embed.dll
+ 2004-08-10 19:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\tabletoc.dll
+ 2004-08-10 19:00:00 14,976 -c----w c:\windows\$NtServicePackUninstall$\tape.sys
+ 2004-08-10 19:00:00 858,624 -c----w c:\windows\$NtServicePackUninstall$\tapi3.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\tapi32.dll
+ 2005-07-08 16:27:56 249,344 -c----w c:\windows\$NtServicePackUninstall$\tapisrv.dll
+ 2004-08-10 19:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\taskkill.exe
+ 2004-08-10 19:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\tasklist.exe
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\taskmgr.exe
+ 2008-06-20 10:45:13 360,320 -c----w c:\windows\$NtServicePackUninstall$\tcpip.sys
+ 2008-06-20 09:52:06 225,920 -c----w c:\windows\$NtServicePackUninstall$\tcpip6.sys
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\tcpmib.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmon.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmonui.dll
+ 2004-08-10 19:00:00 18,560 -c----w c:\windows\$NtServicePackUninstall$\tdi.sys
+ 2004-08-10 19:00:00 12,040 -c----w c:\windows\$NtServicePackUninstall$\tdpipe.sys
+ 2004-08-10 19:00:00 21,896 -c----w c:\windows\$NtServicePackUninstall$\tdtcp.sys
+ 2005-05-10 23:45:48 75,776 -c----w c:\windows\$NtServicePackUninstall$\telnet.exe
+ 2004-08-04 01:01:08 40,840 -c----w c:\windows\$NtServicePackUninstall$\termdd.sys
+ 2004-08-10 19:00:00 358,400 -c----w c:\windows\$NtServicePackUninstall$\termmgr.dll
+ 2005-03-10 14:49:51 295,424 -c----w c:\windows\$NtServicePackUninstall$\termsrv.dll
+ 2004-08-10 19:00:00 385,536 -c----w c:\windows\$NtServicePackUninstall$\themeui.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\tlntadmn.exe
+ 2004-08-10 19:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\tlntsess.exe
+ 2004-08-10 19:00:00 73,216 -c----w c:\windows\$NtServicePackUninstall$\tlntsvr.exe
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\tlntsvrp.dll
+ 2007-01-15 21:11:30 57,344 -c----w c:\windows\$NtServicePackUninstall$\togac.exe
+ 2004-08-10 19:00:00 347,136 -c----w c:\windows\$NtServicePackUninstall$\tourstart.exe
+ 2004-08-10 19:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\tracerpt.exe
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\tracert.exe
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\tree.com
+ 2004-08-10 19:00:00 153,088 -c----w c:\windows\$NtServicePackUninstall$\triedit.dll
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\trkwks.dll
+ 2004-08-10 19:00:00 93,696 -c----w c:\windows\$NtServicePackUninstall$\tscfgwmi.dll
+ 2004-08-10 19:00:00 12,168 -c----w c:\windows\$NtServicePackUninstall$\tsddd.dll
+ 2004-08-10 19:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\tshoot.dll
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\tsoc.dll
+ 2004-08-03 23:03:18 12,416 -c----w c:\windows\$NtServicePackUninstall$\tunmp.sys
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\twain_32.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\twext.dll
+ 2005-07-26 04:39:49 101,376 -c----w c:\windows\$NtServicePackUninstall$\txflog.dll
+ 2007-11-13 11:31:11 60,416 -c----w c:\windows\$NtServicePackUninstall$\tzchange.exe
+ 2004-08-10 19:00:00 66,176 -c----w c:\windows\$NtServicePackUninstall$\udfs.sys
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\udhisapi.dll
+ 2004-08-10 19:00:00 275,456 -c----w c:\windows\$NtServicePackUninstall$\ulib.dll
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\umandlg.dll
+ 2005-08-23 03:35:42 123,392 -c----w c:\windows\$NtServicePackUninstall$\umpnpmgr.dll
+ 2004-08-10 19:00:00 74,240 -c----w c:\windows\$NtServicePackUninstall$\unimdmat.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\uniplat.dll
+ 2004-08-10 19:00:00 316,416 -c----w c:\windows\$NtServicePackUninstall$\untfs.dll
+ 2004-08-10 19:00:00 209,408 -c----w c:\windows\$NtServicePackUninstall$\update.sys
+ 2004-08-10 19:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\uploadm.exe
+ 2004-08-10 19:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\upnp.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\upnpcont.exe
+ 2007-02-05 20:17:02 185,344 -c----w c:\windows\$NtServicePackUninstall$\upnphost.dll
+ 2004-08-10 19:00:00 239,616 -c----w c:\windows\$NtServicePackUninstall$\upnpui.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\ups.exe
+ 2004-08-10 19:00:00 12,672 -c----w c:\windows\$NtServicePackUninstall$\usb8023.sys
+ 2001-08-17 14:03:42 23,808 -c----w c:\windows\$NtServicePackUninstall$\usbcamd.sys
+ 2001-08-17 14:03:44 23,936 -c----w c:\windows\$NtServicePackUninstall$\usbcamd2.sys
+ 2004-08-04 07:08:38 26,624 -c----w c:\windows\$NtServicePackUninstall$\usbehci.sys
+ 2004-08-10 19:00:00 57,600 -c----w c:\windows\$NtServicePackUninstall$\usbhub.sys
+ 2004-08-03 23:08:58 16,000 -c----w c:\windows\$NtServicePackUninstall$\usbintel.sys
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\usbmon.dll
+ 2004-08-04 07:08:38 17,024 -c----w c:\windows\$NtServicePackUninstall$\usbohci.sys
+ 2004-08-10 19:00:00 142,976 -c----w c:\windows\$NtServicePackUninstall$\usbport.sys
+ 2004-08-10 19:00:00 26,496 -c----w c:\windows\$NtServicePackUninstall$\usbstor.sys
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\usbuhci.sys
+ 2004-08-04 00:56:48 74,240 -c----w c:\windows\$NtServicePackUninstall$\usbui.dll
+ 2007-03-08 15:36:28 577,536 -c----w c:\windows\$NtServicePackUninstall$\user32.dll
+ 2004-08-10 19:00:00 723,456 -c----w c:\windows\$NtServicePackUninstall$\userenv.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\userinit.exe

EasyEEE
2008-12-29, 18:03
+ 2004-08-10 19:00:00 406,528 -c----w c:\windows\$NtServicePackUninstall$\usp10.dll
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\utilman.exe
+ 2004-08-10 19:00:00 218,624 -c----w c:\windows\$NtServicePackUninstall$\uxtheme.dll
+ 2004-08-10 19:00:00 30,749 -c----w c:\windows\$NtServicePackUninstall$\vbajet32.dll
+ 2007-08-13 23:54:10 413,696 -c----w c:\windows\$NtServicePackUninstall$\vbscript.dll
+ 2004-08-10 19:00:00 26,112 -c----w c:\windows\$NtServicePackUninstall$\vdmdbg.dll
+ 2004-08-10 19:00:00 51,712 -c----w c:\windows\$NtServicePackUninstall$\vdmredir.dll
+ 2006-03-17 00:38:01 28,672 -c----w c:\windows\$NtServicePackUninstall$\verclsid.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\verifier.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\version.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\vga.sys
+ 2004-08-03 23:07:44 42,240 -c----w c:\windows\$NtServicePackUninstall$\viaagp.sys
+ 2004-08-10 19:00:00 5,376 -c----w c:\windows\$NtServicePackUninstall$\viaide.sys
+ 2004-08-10 19:00:00 79,744 -c----w c:\windows\$NtServicePackUninstall$\videoprt.sys
+ 2004-08-10 19:00:00 131,584 -c----w c:\windows\$NtServicePackUninstall$\viewprov.dll
+ 2004-08-10 19:00:00 52,352 -c----w c:\windows\$NtServicePackUninstall$\volsnap.sys
+ 2004-08-10 19:00:00 430,592 -c----w c:\windows\$NtServicePackUninstall$\vssapi.dll
+ 2004-08-10 19:00:00 289,792 -c----w c:\windows\$NtServicePackUninstall$\vssvc.exe
+ 2004-08-10 19:00:00 174,592 -c----w c:\windows\$NtServicePackUninstall$\w32time.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\w3ssl.dll
+ 2004-08-10 19:00:00 46,080 -c----w c:\windows\$NtServicePackUninstall$\wab.exe
+ 2007-05-16 15:12:12 510,976 -c----w c:\windows\$NtServicePackUninstall$\wab32.dll
+ 2004-08-10 19:00:00 249,856 -c----w c:\windows\$NtServicePackUninstall$\wab32res.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\wabfind.dll
+ 2007-05-16 15:12:15 85,504 -c----w c:\windows\$NtServicePackUninstall$\wabimp.dll
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\wabmig.exe
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\wanarp.sys
+ 2004-08-10 19:00:00 17,664 -c----w c:\windows\$NtServicePackUninstall$\watchdog.sys
+ 2004-08-10 19:00:00 208,896 -c----w c:\windows\$NtServicePackUninstall$\wavemsp.dll
+ 2004-08-10 19:00:00 196,608 -c----w c:\windows\$NtServicePackUninstall$\wbemcntl.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\wbemcomn.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\wbemcons.dll
+ 2004-08-10 19:00:00 530,944 -c----w c:\windows\$NtServicePackUninstall$\wbemcore.dll
+ 2004-08-10 19:00:00 178,176 -c----w c:\windows\$NtServicePackUninstall$\wbemdisp.dll
+ 2004-08-10 19:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\wbemess.dll
+ 2004-08-10 19:00:00 43,008 -c----w c:\windows\$NtServicePackUninstall$\wbemperf.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\wbemprox.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\wbemsvc.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\wbemtest.exe
+ 2004-08-10 19:00:00 197,120 -c----w c:\windows\$NtServicePackUninstall$\wbemupgd.dll
+ 2006-03-24 04:37:50 49,152 -c----w c:\windows\$NtServicePackUninstall$\wdigest.dll
+ 2004-08-04 00:56:58 23,552 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.drv
+ 2006-06-14 09:00:45 82,944 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.sys
+ 2006-06-14 09:00:45 82,944 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.sys.000
+ 2006-01-04 03:35:05 68,096 -c----w c:\windows\$NtServicePackUninstall$\webclnt.dll
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\webvw.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\wextract.exe
+ 2004-08-10 19:00:00 433,664 -c----w c:\windows\$NtServicePackUninstall$\wiaacmgr.exe
+ 2004-08-10 19:00:00 463,360 -c----w c:\windows\$NtServicePackUninstall$\wiadefui.dll
+ 2004-08-10 19:00:00 124,416 -c----w c:\windows\$NtServicePackUninstall$\wiadss.dll
+ 2004-08-10 19:00:00 75,776 -c----w c:\windows\$NtServicePackUninstall$\wiascr.dll
+ 2006-12-19 18:16:47 333,824 -c----w c:\windows\$NtServicePackUninstall$\wiaservc.dll
+ 2004-08-10 19:00:00 589,312 -c----w c:\windows\$NtServicePackUninstall$\wiashext.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\wiavideo.dll
+ 2008-03-19 09:47:00 1,845,248 -c----w c:\windows\$NtServicePackUninstall$\win32k.sys
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\win32spl.dll
+ 2004-08-10 19:00:00 937,984 -c----w c:\windows\$NtServicePackUninstall$\winbrand.dll
+ 2004-08-10 19:00:00 283,648 -c----w c:\windows\$NtServicePackUninstall$\winhlp32.exe
+ 2004-08-10 19:00:00 351,232 -c----w c:\windows\$NtServicePackUninstall$\winhttp.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\winipsec.dll
+ 2004-08-10 19:00:00 502,272 -c----w c:\windows\$NtServicePackUninstall$\winlogon.exe
+ 2004-08-10 19:00:00 176,128 -c----w c:\windows\$NtServicePackUninstall$\winmm.dll
+ 2004-08-10 19:00:00 764,928 -c----w c:\windows\$NtServicePackUninstall$\winntbbu.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\winrnr.dll
+ 2004-08-10 19:00:00 99,328 -c----w c:\windows\$NtServicePackUninstall$\winscard.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\winshfhc.dll
+ 2004-08-10 19:00:00 146,432 -c----w c:\windows\$NtServicePackUninstall$\winspool.drv
+ 2007-03-17 13:43:01 292,864 -c----w c:\windows\$NtServicePackUninstall$\winsrv.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\winsta.dll
+ 2004-08-10 19:00:00 176,640 -c----w c:\windows\$NtServicePackUninstall$\wintrust.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\winver.exe
+ 2006-08-17 12:28:27 132,096 -c----w c:\windows\$NtServicePackUninstall$\wkssvc.dll
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\wldap32.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\wlnotify.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\wmi.dll
+ 2004-08-10 19:00:00 196,608 -c----w c:\windows\$NtServicePackUninstall$\wmiadap.exe
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\wmiapres.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\wmiaprpl.dll
+ 2004-08-10 19:00:00 126,464 -c----w c:\windows\$NtServicePackUninstall$\wmiapsrv.exe
+ 2004-08-10 19:00:00 358,912 -c----w c:\windows\$NtServicePackUninstall$\wmic.exe
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\wmicookr.dll
+ 2004-08-10 19:00:00 140,800 -c----w c:\windows\$NtServicePackUninstall$\wmidcprv.dll
+ 2004-08-10 19:00:00 156,672 -c----w c:\windows\$NtServicePackUninstall$\wmipcima.dll
+ 2004-08-10 19:00:00 132,096 -c----w c:\windows\$NtServicePackUninstall$\wmipdskq.dll
+ 2004-08-10 19:00:00 62,464 -c----w c:\windows\$NtServicePackUninstall$\wmipiprt.dll
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\wmipjobj.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\wmiprov.dll
+ 2004-08-10 19:00:00 437,248 -c----w c:\windows\$NtServicePackUninstall$\wmiprvsd.dll
+ 2004-08-10 19:00:00 218,112 -c----w c:\windows\$NtServicePackUninstall$\wmiprvse.exe
+ 2004-08-10 19:00:00 41,472 -c----w c:\windows\$NtServicePackUninstall$\wmipsess.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\wmisvc.dll
+ 2004-08-10 19:00:00 95,232 -c----w c:\windows\$NtServicePackUninstall$\wmiutils.dll
+ 2004-08-10 19:00:00 167,936 -c----w c:\windows\$NtServicePackUninstall$\wmm2ae.dll
+ 2004-08-10 19:00:00 402,432 -c----w c:\windows\$NtServicePackUninstall$\wmm2filt.dll
+ 2004-08-10 19:00:00 502,272 -c----w c:\windows\$NtServicePackUninstall$\wmm2fxa.dll
+ 2004-08-10 19:00:00 325,632 -c----w c:\windows\$NtServicePackUninstall$\wmm2fxb.dll
+ 2004-08-10 19:00:00 4,256,768 -c----w c:\windows\$NtServicePackUninstall$\wmm2res.dll

EasyEEE
2008-12-29, 18:05
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\wmm2res2.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpcd.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpcore.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpui.dll
+ 2004-08-10 19:00:00 115,200 -c----w c:\windows\$NtServicePackUninstall$\wmsdmoe.dll
+ 2004-08-10 19:00:00 303,616 -c----w c:\windows\$NtServicePackUninstall$\wmstream.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\wordpad.exe
+ 2004-08-10 19:00:00 264,192 -c----w c:\windows\$NtServicePackUninstall$\wow32.dll
+ 2004-08-10 19:00:00 32,256 -c----w c:\windows\$NtServicePackUninstall$\wpabaln.exe
+ 2004-08-10 19:00:00 32,256 -c----w c:\windows\$NtServicePackUninstall$\wpnpinst.exe
+ 2004-08-10 19:00:00 82,944 -c----w c:\windows\$NtServicePackUninstall$\ws2_32.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ws2help.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\wscntfy.exe
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\wscript.exe
+ 2004-08-10 19:00:00 81,408 -c----w c:\windows\$NtServicePackUninstall$\wscsvc.dll
+ 2004-08-10 19:00:00 596,992 -c----w c:\windows\$NtServicePackUninstall$\wsecedit.dll
+ 2004-08-10 19:00:00 108,032 -c----w c:\windows\$NtServicePackUninstall$\wshbth.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\wshcon.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\wshext.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\wship6.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\wshrm.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\wshtcpip.dll
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\wsnmp32.dll
+ 2004-08-10 19:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\wsock32.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\wstdecod.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\wtsapi32.dll
+ 2004-08-10 19:00:00 165,888 -c----w c:\windows\$NtServicePackUninstall$\wuauclt1.exe
+ 2004-08-10 19:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\wuaueng1.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\wuauserv.dll
+ 2005-06-22 05:00:18 383,488 -c----w c:\windows\$NtServicePackUninstall$\wzcdlg.dll
+ 2005-06-22 05:00:18 52,736 -c----w c:\windows\$NtServicePackUninstall$\wzcsapi.dll
+ 2005-06-22 05:00:18 52,736 -c----w c:\windows\$NtServicePackUninstall$\wzcsapi.dll.000
+ 2005-06-22 05:00:18 474,624 -c----w c:\windows\$NtServicePackUninstall$\wzcsvc.dll
+ 2005-06-22 05:00:18 474,624 -c----w c:\windows\$NtServicePackUninstall$\wzcsvc.dll.000
+ 2004-08-10 19:00:00 91,648 -c----w c:\windows\$NtServicePackUninstall$\xactsrv.dll
+ 2004-08-10 19:00:00 30,720 -c----w c:\windows\$NtServicePackUninstall$\xcopy.exe
+ 2006-07-14 15:51:51 121,856 -c----w c:\windows\$NtServicePackUninstall$\xmllite.dll
+ 2004-08-10 19:00:00 129,536 -c----w c:\windows\$NtServicePackUninstall$\xmlprov.dll
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\xmlprovi.dll
+ 2006-03-01 19:42:42 11,776 -c----w c:\windows\$NtServicePackUninstall$\xolehlp.dll
+ 2006-10-10 12:44:50 557,568 -c----w c:\windows\$NtServicePackUninstall$\xpnetdiag.exe
+ 2004-08-10 19:00:00 438,784 -c----w c:\windows\$NtServicePackUninstall$\xpob2res.dll
+ 2004-08-10 19:00:00 187,392 -c----w c:\windows\$NtServicePackUninstall$\xpsp1res.dll
+ 2004-08-10 19:00:00 187,392 -c----w c:\windows\$NtServicePackUninstall$\xpsp1res.dll.026
+ 2004-08-10 19:00:00 2,897,920 -c----w c:\windows\$NtServicePackUninstall$\xpsp2res.dll
+ 2007-12-06 09:38:31 350,720 -c----w c:\windows\$NtServicePackUninstall$\xpsp3res.dll
+ 2004-08-10 19:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\zipfldr.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB895961-v4$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB895961-v4$\spuninst\updspapi.dll
+ 2008-04-14 00:12:07 295,424 -c----w c:\windows\$NtUninstallKB895961-v4$\termsrv.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB938464$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB938464$\spuninst\updspapi.dll
+ 2008-04-14 00:11:59 82,944 -c----w c:\windows\$NtUninstallKB946648$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB946648$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB946648$\spuninst\updspapi.dll
- 2006-07-13 08:48:58 202,240 -c----w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2008-04-13 18:55:08 202,624 -c----w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c----w c:\windows\$NtUninstallKB950762_0$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB950762_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB950762_0$\spuninst\updspapi.dll
+ 2008-04-14 00:11:53 246,272 -c----w c:\windows\$NtUninstallKB950974$\es.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB950974$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB950974$\spuninst\updspapi.dll
+ 2008-04-14 00:11:54 691,712 -c----w c:\windows\$NtUninstallKB951066$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951066$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951066$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951072-v2$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951072-v2$\spuninst\updspapi.dll
+ 2008-04-14 00:12:38 60,416 -c----w c:\windows\$NtUninstallKB951072-v2$\tzchange.exe
- 2008-04-14 11:01:02 272,128 -c----w c:\windows\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 12:30:49 272,128 -c----w c:\windows\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 11:01:02 272,128 -c----w c:\windows\$NtUninstallKB951376-v2_0$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951376-v2_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB951376-v2_0$\spuninst\updspapi.dll
+ 2008-04-13 18:46:32 273,024 -c----w c:\windows\$NtUninstallKB951376$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951376_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB951376_0$\spuninst\updspapi.dll
- 2007-10-29 22:35:13 1,287,680 -c----w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2008-04-14 00:12:03 1,288,192 -c----w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2007-10-29 22:35:13 1,287,680 -c----w c:\windows\$NtUninstallKB951698_0$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951698_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951698_0$\spuninst\updspapi.dll
- 2004-08-10 19:00:00 138,496 -c----w c:\windows\$NtUninstallKB951748$\afd.sys
+ 2008-04-13 19:19:23 138,112 -c----w c:\windows\$NtUninstallKB951748$\afd.sys
- 2008-02-20 05:32:43 148,992 -c----w c:\windows\$NtUninstallKB951748$\dnsapi.dll
+ 2008-04-14 00:11:52 147,968 -c----w c:\windows\$NtUninstallKB951748$\dnsapi.dll
- 2004-08-10 19:00:00 245,248 -c----w c:\windows\$NtUninstallKB951748$\mswsock.dll
+ 2008-04-14 00:12:01 245,248 -c----w c:\windows\$NtUninstallKB951748$\mswsock.dll
- 2007-10-30 17:20:55 360,064 -c----w c:\windows\$NtUninstallKB951748$\tcpip.sys
+ 2008-04-13 19:20:16 361,344 -c----w c:\windows\$NtUninstallKB951748$\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c----w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2008-04-13 19:00:02 225,664 -c----w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-10 19:00:00 138,496 -c----w c:\windows\$NtUninstallKB951748_0$\afd.sys
+ 2008-02-20 05:32:43 148,992 -c----w c:\windows\$NtUninstallKB951748_0$\dnsapi.dll
+ 2004-08-10 19:00:00 245,248 -c----w c:\windows\$NtUninstallKB951748_0$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951748_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB951748_0$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c----w c:\windows\$NtUninstallKB951748_0$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c----w c:\windows\$NtUninstallKB951748_0$\tcpip6.sys
+ 2008-04-14 00:12:15 139,264 -c----w c:\windows\$NtUninstallKB951978$\cscript.exe
+ 2008-04-14 00:11:56 512,000 -c----w c:\windows\$NtUninstallKB951978$\jscript.dll
+ 2008-04-14 00:12:05 180,224 -c----w c:\windows\$NtUninstallKB951978$\scrobj.dll
+ 2008-04-14 00:12:05 172,032 -c----w c:\windows\$NtUninstallKB951978$\scrrun.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951978$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB951978$\spuninst\updspapi.dll
+ 2008-04-14 00:12:08 434,176 -c----w c:\windows\$NtUninstallKB951978$\vbscript.dll
+ 2008-04-14 00:12:41 155,648 -c----w c:\windows\$NtUninstallKB951978$\wscript.exe
+ 2008-04-14 00:12:10 90,112 -c----w c:\windows\$NtUninstallKB951978$\wshext.dll
+ 2008-04-14 00:11:58 331,776 -c----w c:\windows\$NtUninstallKB952287$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB952287$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB952287$\spuninst\updspapi.dll
+ 2008-04-14 00:11:58 73,728 -c----w c:\windows\$NtUninstallKB952954$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB952954$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB952954$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB953839$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB953839$\spuninst\updspapi.dll
+ 2007-07-27 14:41:48 231,288 -c----w c:\windows\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe
+ 2007-07-27 14:41:48 382,840 -c----w c:\windows\$NtUninstallKB954154_WM11$\spuninst\updspapi.dll
+ 2006-10-19 01:47:20 295,936 -c----w c:\windows\$NtUninstallKB954154_WM11$\wmpeffects.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB954211$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB954211$\spuninst\updspapi.dll

EasyEEE
2008-12-29, 18:06
+ 2008-04-13 19:30:10 1,845,632 -c----w c:\windows\$NtUninstallKB954211$\win32k.sys
+ 2008-04-14 00:12:01 1,306,624 -c----w c:\windows\$NtUninstallKB954459$\msxml6.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB954459$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB954459$\spuninst\updspapi.dll
+ 2008-04-14 00:12:01 1,104,896 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe
+ 2008-07-09 18:08:38 382,840 -c----w c:\windows\$NtUninstallKB955069$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB956391$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB956391$\spuninst\updspapi.dll
+ 2008-06-20 11:40:08 138,496 -c----w c:\windows\$NtUninstallKB956803$\afd.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956803$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB956803$\spuninst\updspapi.dll
+ 2008-04-13 18:31:21 2,065,792 -c----w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
+ 2008-04-13 19:27:53 2,188,928 -c----w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956841$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB956841$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB957095$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB957095$\spuninst\updspapi.dll
+ 2008-04-13 19:15:11 334,848 -c----w c:\windows\$NtUninstallKB957095$\srv.sys
+ 2008-04-13 19:17:01 456,576 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
+ 2008-07-08 13:02:02 231,288 -c----w c:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe
+ 2008-07-08 13:02:12 382,840 -c----w c:\windows\$NtUninstallKB957097$\spuninst\updspapi.dll
+ 2008-04-14 00:12:01 337,408 -c----w c:\windows\$NtUninstallKB958644$\netapi32.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB958644$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958644$\spuninst\updspapi.dll
- 2006-10-04 14:05:26 39,424 ------w c:\windows\AppPatch\acadproc.dll
+ 2008-04-14 00:11:48 39,424 ----a-w c:\windows\AppPatch\acadproc.dll
- 2004-08-10 19:00:00 1,852,416 ----a-w c:\windows\AppPatch\AcGenral.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w c:\windows\AppPatch\acgenral.dll
- 2004-08-10 19:00:00 450,048 ----a-w c:\windows\AppPatch\AcLayers.dll
+ 2008-04-14 00:11:48 451,072 -c--a-w c:\windows\AppPatch\aclayers.dll
- 2004-08-10 19:00:00 137,728 ----a-w c:\windows\AppPatch\AcLua.dll
+ 2008-04-14 00:11:48 141,312 -c--a-w c:\windows\AppPatch\aclua.dll
- 2004-08-10 19:00:00 244,736 ----a-w c:\windows\AppPatch\AcSpecfc.dll
+ 2008-04-14 00:11:48 245,248 ----a-w c:\windows\AppPatch\acspecfc.dll
- 2004-08-10 19:00:00 116,224 ----a-w c:\windows\AppPatch\AcXtrnal.dll
+ 2008-04-14 00:11:48 116,224 -c--a-w c:\windows\AppPatch\acxtrnal.dll
- 2005-01-10 01:08:31 8,704 ----a-w c:\windows\assembly\GAC\Accessibility\1.0.3300.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-07-14 00:33:10 8,704 -c--a-w c:\windows\assembly\GAC\Accessibility\1.0.3300.0__b03f5f7f11d50a3a\Accessibility.dll
- 2005-01-10 01:38:39 117,248 ----a-w c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
+ 2008-07-14 00:40:50 117,248 ----a-w c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
- 2005-01-10 01:08:31 12,288 ----a-w c:\windows\assembly\GAC\cscompmgd\7.0.3300.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-07-14 00:33:09 12,288 -c--a-w c:\windows\assembly\GAC\cscompmgd\7.0.3300.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2005-01-10 01:08:31 34,816 ----a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-07-14 00:33:10 34,816 -c--a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2005-01-10 01:38:38 102,400 ----a-w c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
+ 2008-07-14 00:40:49 102,400 ----a-w c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
- 2008-04-21 15:59:14 1,863,680 ----a-w c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
+ 2008-07-14 00:40:50 1,863,680 ----a-w c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\EhCM.dll
- 2005-01-10 01:38:39 192,512 ----a-w c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
+ 2008-07-14 00:40:50 192,512 ----a-w c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
- 2008-04-21 15:59:14 868,352 ----a-w c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2008-07-14 00:40:50 868,352 ----a-w c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
- 2005-01-10 01:38:38 126,976 ----a-w c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
+ 2008-07-14 00:40:50 126,976 ----a-w c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
- 2005-01-10 01:38:40 110,592 ----a-w c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
+ 2008-07-14 00:40:50 110,592 -c--a-w c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
- 2005-01-10 01:38:38 8,192 ----a-w c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
+ 2008-07-14 00:40:49 8,192 ----a-w c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
- 2005-01-10 01:38:38 73,728 ----a-w c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
+ 2008-07-14 00:40:49 73,728 ----a-w c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
- 2005-01-10 01:38:39 167,936 ----a-w c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
+ 2008-07-14 00:40:50 167,936 -c--a-w c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
- 2008-04-21 15:59:15 204,800 ----a-w c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiplay.dll
+ 2008-07-14 00:40:50 204,800 ----a-w c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
- 2005-01-10 01:38:39 389,120 ----a-w c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
+ 2008-07-14 00:40:50 389,120 ----a-w c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
- 2005-01-10 01:38:39 18,944 ----a-w c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
+ 2008-07-14 00:40:50 18,944 ----a-w c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
- 2005-01-10 01:38:39 278,528 ----a-w c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
+ 2008-07-14 00:40:50 278,528 -c--a-w c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
- 2005-01-10 01:38:38 122,880 ----a-w c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
+ 2008-07-14 00:40:49 122,880 -c--a-w c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
- 2005-01-10 01:38:39 53,248 ----a-w c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
+ 2008-07-14 00:40:50 53,248 ----a-w c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
- 2005-01-10 01:38:38 389,120 ----a-w c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
+ 2008-07-14 00:40:49 389,120 ----a-w c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
- 2005-01-10 01:08:32 7,168 ----a-w c:\windows\assembly\GAC\IEExecRemote\1.0.3300.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-07-14 00:33:12 7,168 -c--a-w c:\windows\assembly\GAC\IEExecRemote\1.0.3300.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2005-01-10 01:08:32 32,768 ----a-w c:\windows\assembly\GAC\IEHost\1.0.3300.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-07-14 00:33:12 32,768 -c--a-w c:\windows\assembly\GAC\IEHost\1.0.3300.0__b03f5f7f11d50a3a\IEHost.dll
- 2005-01-10 01:08:32 4,096 ----a-w c:\windows\assembly\GAC\IIEHost\1.0.3300.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-07-14 00:33:13 4,096 -c--a-w c:\windows\assembly\GAC\IIEHost\1.0.3300.0__b03f5f7f11d50a3a\IIEHost.dll
- 2005-01-10 01:08:32 27,136 ----a-w c:\windows\assembly\GAC\ISymWrapper\1.0.3300.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-07-14 00:33:13 27,136 -c--a-w c:\windows\assembly\GAC\ISymWrapper\1.0.3300.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2005-01-10 01:08:31 712,704 ----a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-07-14 00:33:09 712,704 -c--a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2005-01-10 01:38:39 45,056 ----a-w c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
+ 2008-07-14 00:40:50 45,056 ----a-w c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
+ 2008-08-24 02:48:53 8,011,400 -c--a-w c:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
- 2005-01-10 01:08:31 28,672 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-07-14 00:33:09 28,672 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2005-01-10 01:08:31 286,720 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-07-14 00:33:10 286,720 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2005-01-10 01:08:31 5,632 ----a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2008-07-14 00:33:10 5,632 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
- 2005-01-10 01:08:31 11,264 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-07-14 00:33:08 11,264 -c--a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2005-01-10 01:08:31 18,944 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-07-14 00:33:09 18,944 -c--a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2005-01-10 01:08:31 6,656 ----a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.3300.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-07-14 00:33:08 6,656 -c--a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.3300.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2005-01-10 01:08:32 1,564,672 ----a-w c:\windows\assembly\GAC\mscorcfg\1.0.3300.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2008-07-14 00:33:13 1,564,672 -c--a-w c:\windows\assembly\GAC\mscorcfg\1.0.3300.0__b03f5f7f11d50a3a\mscorcfg.dll
- 2005-01-10 01:08:31 32,768 ----a-w c:\windows\assembly\GAC\Regcode\1.0.3300.0__b03f5f7f11d50a3a\RegCode.dll
+ 2008-07-14 00:33:10 32,768 -c--a-w c:\windows\assembly\GAC\Regcode\1.0.3300.0__b03f5f7f11d50a3a\RegCode.dll
- 2005-01-10 01:38:39 77,824 ----a-w c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
+ 2008-07-14 00:40:50 77,824 -c--a-w c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
- 2005-01-10 01:08:31 77,824 ----a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.3300.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-07-14 00:33:11 77,824 -c--a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.3300.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2005-01-10 01:08:31 1,179,648 ----a-w c:\windows\assembly\GAC\System.Data\1.0.3300.0__b77a5c561934e089\System.Data.dll
+ 2008-07-14 00:33:12 1,179,648 -c--a-w c:\windows\assembly\GAC\System.Data\1.0.3300.0__b77a5c561934e089\System.Data.dll
- 2005-01-10 01:08:31 1,695,744 ----a-w c:\windows\assembly\GAC\System.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-07-14 00:33:12 1,695,744 -c--a-w c:\windows\assembly\GAC\System.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Design.dll
- 2005-01-10 01:08:31 86,016 ----a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.3300.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-07-14 00:33:11 86,016 -c--a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.3300.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2005-01-10 01:08:31 65,536 ----a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-07-14 00:33:11 65,536 -c--a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2005-01-10 01:08:32 462,848 ----a-w c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-07-14 00:33:12 462,848 -c--a-w c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2005-01-10 01:08:31 212,992 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-07-14 00:33:10 212,992 -c--a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2005-01-10 01:08:31 48,640 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2008-07-14 00:33:10 48,640 -c--a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
- 2005-01-10 01:08:32 352,256 ----a-w c:\windows\assembly\GAC\System.Management\1.0.3300.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-07-14 00:33:13 352,256 -c--a-w c:\windows\assembly\GAC\System.Management\1.0.3300.0__b03f5f7f11d50a3a\System.Management.dll
- 2005-01-10 01:08:32 241,664 ----a-w c:\windows\assembly\GAC\System.Messaging\1.0.3300.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-07-14 00:33:12 241,664 -c--a-w c:\windows\assembly\GAC\System.Messaging\1.0.3300.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2005-01-10 01:08:32 311,296 ----a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.3300.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-07-14 00:33:13 311,296 -c--a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.3300.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2005-01-10 01:08:32 131,072 ----a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.3300.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-14 00:33:13 131,072 -c--a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.3300.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2005-01-10 01:08:31 77,824 ----a-w c:\windows\assembly\GAC\System.Security\1.0.3300.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-07-14 00:33:10 77,824 -c--a-w c:\windows\assembly\GAC\System.Security\1.0.3300.0__b03f5f7f11d50a3a\System.Security.dll
- 2005-01-10 01:08:31 126,976 ----a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.3300.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-07-14 00:33:11 126,976 -c--a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.3300.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2005-01-10 01:08:31 61,440 ----a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.3300.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-07-14 00:33:11 61,440 -c--a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.3300.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2005-01-10 01:08:31 507,904 ----a-w c:\windows\assembly\GAC\System.Web.Services\1.0.3300.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-07-14 00:33:11 507,904 -c--a-w c:\windows\assembly\GAC\System.Web.Services\1.0.3300.0__b03f5f7f11d50a3a\System.Web.Services.dll

EasyEEE
2008-12-29, 18:06
- 2008-04-03 03:03:06 1,200,128 ----a-w c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-07-14 00:33:11 1,200,128 -c--a-w c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2005-01-10 01:08:31 2,002,944 ----a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-07-14 00:33:11 2,002,944 -c--a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
- 2005-01-10 01:08:31 1,302,528 ----a-w c:\windows\assembly\GAC\System.Xml\1.0.3300.0__b77a5c561934e089\System.Xml.dll
+ 2008-07-14 00:33:12 1,302,528 -c--a-w c:\windows\assembly\GAC\System.Xml\1.0.3300.0__b77a5c561934e089\System.Xml.dll
- 2005-01-10 01:08:32 1,179,648 ----a-w c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
+ 2008-07-14 00:33:12 1,179,648 -c--a-w c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
+ 2008-11-20 18:15:27 60,928 ----a-w c:\windows\assembly\GAC_32\cli_cppuhelper\1.0.14.0__ce2cb7e279207b9e\cli_cppuhelper.dll
+ 2008-08-24 02:48:14 106,120 ----a-w c:\windows\assembly\GAC_32\CSMInterface\5.3.1.1__6cba14bfb4f12ba0\CSMInterface.dll
+ 2008-08-24 02:48:14 45,056 ----a-w c:\windows\assembly\GAC_32\CSMRemotable\5.3.1.1__93c818616a5c6d1f\CSMRemotable.dll
+ 2008-09-11 15:21:35 69,120 -c--a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-09-11 15:21:38 72,192 -c--a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-09-11 15:23:35 151,552 -c--a-w c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-09-11 15:21:27 4,444,160 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-11-20 18:15:33 3,072 ----a-w c:\windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\14.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_cppuhelper.dll
+ 2008-09-11 15:23:40 4,174,336 ----a-w c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2008-09-11 15:21:38 483,840 -c--a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-09-11 15:21:32 3,036,160 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2008-09-11 15:21:40 258,048 -c--a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-09-11 15:21:40 113,664 -c--a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2008-09-11 15:23:39 346,624 -c--a-w c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2008-09-11 15:21:38 261,120 -c--a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2008-09-11 15:21:31 5,431,296 -c--a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-09-11 15:21:33 10,752 -c--a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-09-11 15:21:31 507,904 -c--a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2008-11-20 18:15:04 11,264 ----a-w c:\windows\assembly\GAC_MSIL\cli_basetypes\1.0.11.0__ce2cb7e279207b9e\cli_basetypes.dll
+ 2008-11-20 18:15:28 823,296 ----a-w c:\windows\assembly\GAC_MSIL\cli_oootypes\1.0.0.0__ce2cb7e279207b9e\cli_oootypes.dll
+ 2008-11-20 18:15:04 7,680 ----a-w c:\windows\assembly\GAC_MSIL\cli_ure\1.0.14.0__ce2cb7e279207b9e\cli_ure.dll
+ 2008-11-20 18:15:04 114,688 ----a-w c:\windows\assembly\GAC_MSIL\cli_uretypes\1.0.0.0__ce2cb7e279207b9e\cli_uretypes.dll
+ 2008-09-11 15:21:35 13,312 -c--a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-09-11 15:21:36 8,192 -c--a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-09-11 15:21:37 77,824 -c--a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-09-11 15:21:37 6,656 -c--a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-08-24 02:48:13 130,696 -c--a-w c:\windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__6cba14bfb4f12ba0\Interop.SHDocVw.dll
+ 2008-09-11 15:21:40 348,160 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2008-09-11 15:21:40 36,864 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2008-09-11 15:21:41 655,360 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2008-09-11 15:21:41 77,824 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2008-09-11 15:21:37 749,568 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-09-11 18:24:17 87,072 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.LifeCam.Framework\2.4.542.0__31bf3856ad364e35\Microsoft.LifeCam.Framework.dll
+ 2008-09-11 18:24:17 46,112 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.LifeCam.Interfaces\2.4.542.0__31bf3856ad364e35\Microsoft.LifeCam.Interfaces.dll
+ 2008-09-11 15:23:35 397,312 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2008-09-11 15:21:36 110,592 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-09-11 15:21:36 372,736 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2008-09-11 15:21:39 28,672 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-09-11 15:21:36 671,744 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-09-11 15:21:29 5,632 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2008-09-11 15:21:39 12,800 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-09-11 15:21:35 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-09-11 15:21:35 7,168 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_basetypes\11.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_basetypes.dll
+ 2008-11-20 18:15:33 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_oootypes\1.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_oootypes.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_ure\14.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_ure.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_uretypes\1.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_uretypes.dll
+ 2008-09-11 15:23:33 602,112 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2008-09-11 15:23:40 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2008-09-11 15:23:38 184,320 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2008-09-11 15:23:38 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2008-09-11 15:23:38 376,832 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2008-09-11 15:23:38 151,552 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2008-09-11 15:23:37 5,210,112 ----a-w c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2008-09-11 15:23:37 897,024 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2008-09-11 15:23:39 528,384 -c--a-w c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2008-09-11 15:23:35 102,400 -c--a-w c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2008-09-11 15:21:37 110,592 -c--a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2008-09-11 15:21:37 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-09-11 15:21:31 425,984 -c--a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2008-09-11 15:21:32 741,376 -c--a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2008-09-11 15:21:32 933,888 -c--a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2008-09-11 15:21:42 5,070,848 -c--a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-09-11 15:21:41 188,416 -c--a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2008-09-11 15:21:34 401,408 -c--a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-09-11 15:21:39 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-09-11 15:21:29 630,784 -c--a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-09-11 15:23:41 126,976 -c--a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2008-09-11 15:23:41 430,080 -c--a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2008-09-11 15:23:35 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2008-09-11 15:21:40 372,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-09-11 15:21:39 258,048 -c--a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-09-11 15:21:38 299,008 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-09-11 15:21:38 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-09-11 15:23:35 929,792 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2008-09-11 15:21:30 258,048 -c--a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-09-11 15:23:33 159,744 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2008-09-11 15:23:33 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2008-09-11 15:23:34 5,971,968 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2008-09-11 15:21:30 114,688 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-09-11 15:23:33 688,128 -c--a-w c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2008-09-11 15:21:33 884,736 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-09-11 15:21:33 90,112 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-09-11 15:21:33 839,680 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-09-11 15:21:34 5,013,504 -c--a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-09-11 15:23:41 1,152,040 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2008-09-11 15:23:40 1,635,376 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2008-09-11 15:23:40 578,592 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2008-09-11 15:21:30 2,068,480 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2008-09-11 15:21:32 3,076,096 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2008-09-11 15:23:32 163,840 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2008-09-11 15:23:32 372,736 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2008-09-11 15:23:39 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2008-09-11 15:23:39 86,016 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2008-09-11 15:23:39 1,204,224 ----a-w c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2008-09-11 15:23:32 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2008-08-06 15:34:22 26,624 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\052b01d5f41165c75040614d03e64545\Accessibility.ni.dll
+ 2008-09-11 15:26:49 27,136 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll
+ 2008-08-06 15:34:24 888,832 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\52e6f71030afecf866e37de57592535e\AspNetMMCExt.ni.dll
+ 2008-09-11 15:31:49 884,736 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll
+ 2008-08-06 15:34:48 499,712 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\baa716dbee42118add871bd21d5ab9fc\ComSvcConfig.ni.exe
+ 2008-09-11 15:32:23 503,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\bb3c2f59a821abc54f420f3a9e051d6a\ComSvcConfig.ni.exe
+ 2008-09-11 15:32:30 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll
+ 2008-08-06 15:36:06 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c67b101d9842e334154243a5e4da0aa3\CustomMarshalers.ni.dll
+ 2008-09-11 15:32:22 15,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe
+ 2008-08-06 15:34:48 15,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\eb54a996a7fe35fb2b4e4ef98f02a4ed\dfsvc.ni.exe
+ 2008-08-06 15:36:07 880,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5f50f3da9811bfaa72382173ee82d1dd\Microsoft.Build.Engine.ni.dll
+ 2008-09-11 15:32:31 876,544 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll
+ 2008-08-06 15:36:07 81,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\613b88256a517b5b3af9f922267e19b0\Microsoft.Build.Framework.ni.dll
+ 2008-09-11 15:32:32 81,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll
+ 2008-09-11 15:32:34 1,695,744 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll
+ 2008-08-06 15:36:09 1,687,552 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\8004ef004a54b4c2e0d05ed5e8335219\Microsoft.Build.Tasks.ni.dll
+ 2008-09-11 15:32:35 167,936 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll
+ 2008-08-06 15:36:09 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\bfcffe6e05507159e93263c5242e22a1\Microsoft.Build.Utilities.ni.dll
+ 2008-08-06 15:34:50 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\2882820964bda08740ebd2fd3afe45ab\Microsoft.Transactions.Bridge.ni.dll
+ 2008-08-06 15:34:51 405,504 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\d1a80d409e6595eecefe926e1f7a05a4\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2008-09-11 15:32:25 1,232,896 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\e3dce636e798c53ec2b44d1d4aadb850\Microsoft.Transactions.Bridge.ni.dll
+ 2008-09-11 15:32:26 401,408 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f3902a808549b40d648206c9303f2788\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2008-09-11 15:32:37 1,740,800 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll
+ 2008-08-06 15:36:11 1,720,320 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c5d3c0594e7f7d5ea8c9888f0e14c2f9\Microsoft.VisualBasic.ni.dll
+ 2008-08-06 15:35:02 17,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\b7f503038312fbdb46d541be8767dc0b\Microsoft.VisualC.ni.dll
+ 2008-09-11 15:26:50 17,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\cd0730694ba5927a6efd32129783e1b4\Microsoft.VisualC.ni.dll
+ 2008-09-11 15:25:09 11,722,752 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll
+ 2008-08-06 14:49:48 11,304,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3d2a91a6c545200f624700ac2ae86375\mscorlib.ni.dll
+ 2008-08-06 15:36:13 1,568,768 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\53efd2da70401b56c4a9877fab797aee\PresentationBuildTasks.ni.dll
+ 2008-09-11 15:32:39 1,581,056 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\ab2b2664932688ae7c8e0bd9d10448ef\PresentationBuildTasks.ni.dll
+ 2008-08-06 15:36:05 40,448 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\2af82cbb3977e66a69fae5b83ebdd35f\PresentationCFFRasterizer.ni.dll
+ 2008-09-11 15:27:11 40,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3df824565150953afd560ca20237b881\PresentationCFFRasterizer.ni.dll
+ 2008-09-11 15:27:10 12,570,624 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\011f8e31d197b4ccb6a61c2267a38e5c\PresentationCore.ni.dll
+ 2008-08-06 15:35:42 11,984,896 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\46dc43af4b8173a8761b4c9ee1b3f039\PresentationCore.ni.dll
+ 2008-08-06 15:34:53 48,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\26f9d960635bfc56e0312f6d3446d7bc\PresentationFontCache.ni.exe
+ 2008-09-11 15:26:11 48,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\4ce7fd62d4107fbe996ab305eb21ee6a\PresentationFontCache.ni.exe
+ 2008-08-06 15:48:24 14,680,064 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\06c18ef796aea6f5e9fa845e8a25dd80\PresentationFramework.ni.dll
+ 2008-09-11 15:28:25 393,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\36c6cfd5d4e80d5c548f823b2bbf5457\PresentationFramework.Aero.ni.dll
+ 2008-09-11 15:28:28 552,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3f18bff5107c9a8accae6c248fdf3c2e\PresentationFramework.Luna.ni.dll
+ 2008-08-06 15:48:41 393,216 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43a7f7d305d55c956d459aafff07f871\PresentationFramework.Aero.ni.dll
+ 2008-09-11 15:27:37 15,036,416 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60421dda88800b14dc101ed9dca422fe\PresentationFramework.ni.dll
+ 2008-08-06 15:48:46 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6880aea2c464caf8759ac13f1b2a61ae\PresentationFramework.Classic.ni.dll
+ 2008-09-11 15:28:30 274,432 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\81d2540bc1c18190d0431d9a61bee65b\PresentationFramework.Royale.ni.dll
+ 2008-09-11 15:28:27 245,760 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9df61ec7aad39fe0bac82139cd84e5e5\PresentationFramework.Classic.ni.dll
+ 2008-08-06 15:48:51 548,864 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f5f05fc603c6ed0d66f6f6c6bc4a3c3f\PresentationFramework.Luna.ni.dll
+ 2008-08-06 15:48:55 270,336 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fec099bb1b7ad687d034df56c1e87b84\PresentationFramework.Royale.ni.dll
+ 2008-09-11 15:27:39 2,035,712 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6d2716a55eb8ce6fc4cbf83f3ab329e3\PresentationUI.ni.dll
+ 2008-08-06 15:48:32 1,982,464 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\8ab7eb8fe1cba4ab55caf5b012ce94e5\PresentationUI.ni.dll
+ 2008-08-06 15:48:39 2,396,160 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\4dae59b5c525bc0c6ba738dfc13f66ef\ReachFramework.ni.dll
+ 2008-09-11 15:27:43 2,416,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\840c64bba900a6ed333ca39e63a9ca3b\ReachFramework.ni.dll
+ 2008-08-06 15:34:51 135,168 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\3ac95d73de52011ee0f7edd5a6d3730b\ServiceModelReg.ni.exe
+ 2008-09-11 15:32:27 139,264 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\feac66e81309d67b48f7a9f4cb98f7c8\ServiceModelReg.ni.exe
+ 2008-09-11 15:32:27 299,008 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\169ba2fe1a4d87ede3ab8dd3d44d867e\SMDiagnostics.ni.dll
+ 2008-08-06 15:34:52 286,720 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\d4b9cf1f94a59870fe4c96e1e9c5d041\SMDiagnostics.ni.dll
+ 2008-08-06 15:34:52 323,584 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\3eee8f72df72d4b86b812d2eef31096d\SMSvcHost.ni.exe
+ 2008-09-11 15:32:28 323,584 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\a098c66aa40d958878f3f5344e6ae1a4\SMSvcHost.ni.exe
+ 2008-09-11 15:32:48 262,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\6a075eb8e0f13de87d1278aa8562d51e\sysglobl.ni.dll
+ 2008-08-06 15:49:15 262,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\f1291e1269ca53fda5d9c2f85bddfb28\sysglobl.ni.dll
+ 2008-08-06 15:34:59 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\331f31454e9328cfd4adad646ae07f57\System.Configuration.Install.ni.dll
+ 2008-09-11 15:26:34 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\c46625ea87db53ccf6194fe17ee05c19\System.Configuration.Install.ni.dll
+ 2008-08-06 15:34:55 1,003,520 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ec99be9da6a99bd8d655b71e1ab340ca\System.Configuration.ni.dll
+ 2008-09-11 15:26:19 1,011,712 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll
+ 2008-09-11 15:28:22 1,183,744 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\1abdb47765d0696a2fc0a1095bac0249\System.Data.OracleClient.ni.dll
+ 2008-08-06 15:36:03 1,179,648 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f26873ac98747631a7726745e89b223c\System.Data.OracleClient.ni.dll
+ 2008-08-06 15:34:58 2,695,168 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\b2f4ae6f29d5a3078f344c92b54bca02\System.Data.SqlXml.ni.dll
+ 2008-09-11 15:26:32 2,756,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e59504af41afab5e04681af951d9b302\System.Data.SqlXml.ni.dll
+ 2008-08-06 14:50:49 6,676,480 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\280871d92ac03759dcfd7078f76887d6\System.Data.ni.dll
+ 2008-09-11 15:27:53 7,049,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll
+ 2008-08-06 15:35:01 1,724,416 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\06305b5a0a0dd6b25225704887c66e13\System.Deployment.ni.dll
+ 2008-09-11 15:26:50 1,798,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll
+ 2008-08-06 14:51:15 10,702,848 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\a60b40f4a220b217c807966d3a2a4592\System.Design.ni.dll
+ 2008-09-11 15:28:20 10,969,088 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll
+ 2008-09-11 15:27:46 1,224,704 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll
+ 2008-08-06 15:36:04 512,000 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\bb5362bc478cd680b3413c70630efabc\System.DirectoryServices.Protocols.ni.dll
+ 2008-09-11 15:28:23 512,000 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll
+ 2008-08-06 15:35:45 1,216,512 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f9dd15355dd9047c3c371714bf985bef\System.DirectoryServices.ni.dll
+ 2008-08-06 14:51:18 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\02160e0e625f78d5830d9b563e100331\System.Drawing.Design.ni.dll
+ 2008-09-11 15:28:20 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll
+ 2008-09-11 15:26:36 1,667,072 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll
+ 2008-08-06 14:51:17 1,601,536 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ccb5d6542f8954915f9964b17b46bd7c\System.Drawing.ni.dll
+ 2008-09-11 15:27:55 659,456 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll
+ 2008-09-11 15:27:55 294,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll
+ 2008-08-06 15:35:44 659,456 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2db2e33c3ff91993737b98a47ba5e99\System.EnterpriseServices.ni.dll
+ 2008-08-06 15:35:44 294,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2db2e33c3ff91993737b98a47ba5e99\System.EnterpriseServices.Wrapper.dll
+ 2008-08-06 15:34:25 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\26b0767aafa118512edcb09b4007bbaf\System.IdentityModel.Selectors.ni.dll
+ 2008-09-11 15:31:51 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\492d16599426c7ab35ad2c499a9d4ae6\System.IdentityModel.Selectors.ni.dll
+ 2008-09-11 15:31:51 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\bdd94a4c46e4424787dfed9381196cb3\System.IdentityModel.ni.dll
+ 2008-08-06 15:34:25 987,136 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\f8f516e657a16c1770cf77749aae9540\System.IdentityModel.ni.dll
+ 2008-08-06 15:34:26 421,888 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a66fada0648afd51c59029cd58d5ae7e\System.IO.Log.ni.dll
+ 2008-09-11 15:31:52 417,792 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e1e6aa5272543f1d9dad98be897b693e\System.IO.Log.ni.dll
+ 2008-09-11 15:33:05 655,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\00e3750e478bac4913ee7a6c3b7cd392\System.Messaging.ni.dll
+ 2008-08-06 15:49:36 655,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\ed190de5880e259667ae7dc60c3aa3ff\System.Messaging.ni.dll
+ 2008-08-06 15:48:40 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\454f85e8d514523698d295500e659cef\System.Printing.ni.dll
+ 2008-09-11 15:27:45 1,134,592 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\f94fbbe7d7c6e76d02cd9fb94ee8d910\System.Printing.ni.dll
+ 2008-09-11 15:27:57 815,104 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll
+ 2008-08-06 15:35:46 815,104 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\ecb6e302ca6264f422d77e40f8976c55\System.Runtime.Remoting.ni.dll
+ 2008-09-11 15:26:34 339,968 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1f5cf8178029f5b959a9af75cb8cfedb\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-08-06 15:34:29 2,363,392 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\7bf1b63ce7872a0a968825a5b98f68fd\System.Runtime.Serialization.ni.dll
+ 2008-08-06 15:35:00 339,968 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a33827fda63dcbbc207985eb4f1a9cef\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-09-11 15:31:56 2,445,312 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e27527e67611d8acc0d8dff6d286af23\System.Runtime.Serialization.ni.dll
+ 2008-09-11 15:26:33 733,184 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll
+ 2008-08-06 15:34:59 729,088 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\779aee6971d8dac0a75bf00fa2b01740\System.Security.ni.dll
+ 2008-08-06 15:34:47 17,534,976 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\02ad21fb5d0fdd242895be699763de66\System.ServiceModel.ni.dll
+ 2008-09-11 15:32:20 18,071,552 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\350903c091629396c08742c996c1caba\System.ServiceModel.ni.dll
+ 2008-09-11 15:26:15 233,472 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll
+ 2008-08-06 15:34:53 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\389b18e556e6a5f1e09650d06002cf76\System.ServiceProcess.ni.dll

EasyEEE
2008-12-29, 18:07
+ 2008-08-06 15:49:14 2,031,616 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\18ae104b9705a3bdf68cfe6fa8d61832\System.Speech.ni.dll
+ 2008-09-11 15:32:48 2,039,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\d4147c99010667b5c547fcfc56ed7bd5\System.Speech.ni.dll
+ 2008-09-11 15:27:54 679,936 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll
+ 2008-08-06 15:35:43 684,032 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\e88c997aa1c8a48e48f43fd6cbd0e03f\System.Transactions.ni.dll
+ 2008-08-06 15:49:18 2,306,048 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\0e4ce5082b36961bcc4b9191c1e8e798\System.Web.Mobile.ni.dll
+ 2008-09-11 15:32:51 2,342,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll
+ 2008-08-06 15:36:04 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\55cd271d60f6f2adcb5d54ba5d82865e\System.Web.RegularExpressions.ni.dll
+ 2008-09-11 15:28:23 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll
+ 2008-09-11 15:28:11 1,986,560 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll
+ 2008-08-06 15:36:02 1,941,504 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\80cd7c9e54415f07b1ad767be9795dc5\System.Web.Services.ni.dll
+ 2008-09-11 15:28:08 12,509,184 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll
+ 2008-08-06 15:35:59 12,185,600 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\f9476232b313bcdad5b484ac91b37cf9\System.Web.ni.dll
+ 2008-09-11 15:26:48 13,193,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll
+ 2008-08-06 14:51:31 13,107,200 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6afdd8862913a1788c068c5e8d59f4e8\System.Windows.Forms.ni.dll
+ 2008-08-06 15:49:22 2,994,176 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\3acfa0050500b276ac5a98d09c6fb4a3\System.Workflow.Activities.ni.dll
+ 2008-09-11 15:32:56 3,084,288 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\9798b3ba448ba7d5f1dd70a8a1fb7562\System.Workflow.Activities.ni.dll
+ 2008-09-11 15:33:01 4,579,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\575dad1c0dc9d035acbab10846802ce0\System.Workflow.ComponentModel.ni.dll
+ 2008-08-06 15:49:28 4,587,520 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\db1187eb1adaac7bdd7e8a4904954627\System.Workflow.ComponentModel.ni.dll
+ 2008-09-11 15:33:04 2,088,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\9d89b57d703aefe4938b45f8b398d378\System.Workflow.Runtime.ni.dll
+ 2008-08-06 15:49:34 2,101,248 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\bc074f562df871499f1b36f545ab1aa3\System.Workflow.Runtime.ni.dll
+ 2008-09-11 15:26:28 5,771,264 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll
+ 2008-08-06 14:51:37 5,623,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\e4fc736d0feeee9e0c9a0bea73237236\System.Xml.ni.dll
+ 2008-08-06 14:50:11 8,130,560 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\55f79c8f77fdcc590f75307fe36f0c5c\System.ni.dll
+ 2008-09-11 15:26:10 8,265,728 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll
+ 2008-08-06 15:49:44 483,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\5f49138e9421ea25db46ca4ed4b88337\UIAutomationClient.ni.dll
+ 2008-09-11 15:33:07 483,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\c2e5aa36c753a605bdefb97ab83e8806\UIAutomationClient.ni.dll
+ 2008-08-06 15:49:49 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\7b3705542d3e9d844e2548318b4154de\UIAutomationClientsideProviders.ni.dll
+ 2008-09-11 15:33:09 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\ae395b4b568f0d71fec35e3902a46a99\UIAutomationClientsideProviders.ni.dll
+ 2008-08-06 15:36:05 50,688 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\4281d4028d407c149249fcb8f4c5e3ed\UIAutomationProvider.ni.dll
+ 2008-09-11 15:27:10 50,688 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\9e249f5c0ef3e391c5aec1f9da805519\UIAutomationProvider.ni.dll
+ 2008-09-11 15:27:11 196,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\46e3ec015dd7b25d5ddc185534458122\UIAutomationTypes.ni.dll
+ 2008-08-06 15:36:05 196,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\8d337259cd6341dd0c6604008320733a\UIAutomationTypes.ni.dll
+ 2008-09-11 15:26:54 3,395,584 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\0703021437c2ec71213a6b701771be86\WindowsBase.ni.dll
+ 2008-08-06 15:35:10 3,272,704 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\ebac3191ed25ac642d2d7100a40530da\WindowsBase.ni.dll
+ 2008-08-06 15:49:58 274,432 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\8254771659c96404746d3103a2b934be\WindowsFormsIntegration.ni.dll
+ 2008-09-11 15:33:12 270,336 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b7c202147607f93463ead99e743c78b9\WindowsFormsIntegration.ni.dll
+ 2008-09-11 15:32:29 380,928 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\13f498f606b7cb97c086eea149b8c872\WsatConfig.ni.exe
+ 2008-08-06 15:34:53 380,928 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\74d81b9484635f801be67c0b9680254b\WsatConfig.ni.exe
+ 2008-07-14 00:32:34 1,855,488 -c--a-w c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_9b2c904d\System.dll
+ 2008-07-14 00:39:50 258,048 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\BDATunePIA\6.0.3000.0__31bf3856ad364e35_0c06c066\BDATunePIA.dll
+ 2008-07-14 00:39:13 159,744 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehCIR\6.0.3000.0__31bf3856ad364e35_ec9fd77f\ehCIR.dll
+ 2008-07-14 00:39:47 2,326,528 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\EhCM\6.0.3000.0__31bf3856ad364e35_f0ff3687\EhCM.dll
+ 2008-07-14 00:39:49 299,008 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehcommon\6.0.3000.0__31bf3856ad364e35_c90aafd6\ehcommon.dll
+ 2008-07-14 00:39:39 1,306,624 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehepg\6.0.3000.0__31bf3856ad364e35_bd8f3664\ehepg.dll
+ 2008-07-14 00:39:22 167,936 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehepgdat\6.0.3000.0__31bf3856ad364e35_1ca833c8\ehepgdat.dll
+ 2008-07-14 00:40:18 167,936 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehExtCOM\6.0.3000.0__31bf3856ad364e35_45509c73\ehExtCOM.dll
+ 2008-07-14 00:40:41 155,648 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehExtHost\6.0.3000.0__31bf3856ad364e35_0e3517d1\ehExtHost.exe
+ 2008-07-14 00:39:06 10,752 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiExtCOM\6.0.3000.0__31bf3856ad364e35_d7f5b581\ehiExtCOM.dll
+ 2008-07-14 00:39:07 102,400 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiExtens\6.0.3000.0__31bf3856ad364e35_0ae249af\ehiExtens.dll
+ 2008-07-14 00:39:33 266,240 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiMsgr\6.0.3000.0__31bf3856ad364e35_f497e71d\ehiMsgr.dll
+ 2008-07-14 00:39:25 380,928 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiPlay\6.0.3000.0__31bf3856ad364e35_37939819\ehiPlay.dll
+ 2008-07-14 00:39:28 565,248 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiProxy\6.0.3000.0__31bf3856ad364e35_bff8b29d\ehiProxy.dll
+ 2008-07-14 00:39:29 40,960 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiUserXp\6.0.3000.0__31bf3856ad364e35_7ea28c0d\ehiUserXp.dll
+ 2008-07-14 00:39:31 458,752 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiVidCtl\6.0.3000.0__31bf3856ad364e35_41728c4a\ehiVidCtl.dll
+ 2008-07-14 00:39:05 180,224 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiwmp\6.0.3000.0__31bf3856ad364e35_8a1592ca\ehiwmp.dll
+ 2008-07-14 00:39:51 69,632 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiWUapi\6.0.3000.0__31bf3856ad364e35_3fb292ce\ehiWUapi.dll
+ 2008-07-14 00:39:11 684,032 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehRecObj\6.0.3000.0__31bf3856ad364e35_417cfdb5\ehRecObj.dll
+ 2008-07-14 00:40:49 6,336,512 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehshell\6.0.3000.0__31bf3856ad364e35_842d3c99\ehshell.exe
+ 2008-07-14 00:39:54 65,536 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35_d32d0e7f\Microsoft.MediaCenter.dll
+ 2008-07-14 00:40:10 20,480 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0_78cc1837\SonicMCEBurnEngine.dll
+ 2003-11-16 04:28:28 129,024 ----a-w c:\windows\Downloaded Program Files\GSM_codec.dll
+ 2007-01-25 01:24:24 299,432 ----a-w c:\windows\Downloaded Program Files\StProxy.dll
- 2008-06-13 13:10:50 272,128 ------w c:\windows\Driver Cache\i386\bthport.sys
+ 2008-06-13 11:05:51 272,128 -c----w c:\windows\Driver Cache\i386\bthport.sys
- 2006-05-05 09:41:45 453,120 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
- 2007-02-28 09:08:48 2,136,064 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 10:09:26 2,145,280 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:33:16 2,023,936 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2005-10-21 00:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
- 2007-06-13 10:23:07 1,033,216 ----a-w c:\windows\explorer.exe
+ 2008-04-14 00:12:19 1,033,728 ----a-w c:\windows\explorer.exe
+ 2008-12-29 14:57:49 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-18 02:13:02 811,008 ----a-w c:\windows\gmer.exe
- 2004-08-10 19:00:00 34,816 ----a-w c:\windows\Help\sniffpol.dll
+ 2008-04-14 00:12:06 34,816 -c--a-w c:\windows\Help\sniffpol.dll
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\Help\sstub.dll
+ 2008-04-14 00:12:07 33,280 -c--a-w c:\windows\Help\sstub.dll
- 2004-08-10 19:00:00 279,040 ----a-w c:\windows\Help\tshoot.dll
+ 2008-04-14 00:12:07 279,040 -c--a-w c:\windows\Help\tshoot.dll
- 2005-05-26 23:22:01 10,752 ----a-w c:\windows\hh.exe
+ 2008-04-14 00:12:21 10,752 ----a-w c:\windows\hh.exe
+ 2008-04-23 04:16:28 124,928 -c----w c:\windows\ie7updates\KB953838-IE7\advpack.dll
+ 2008-04-23 04:16:28 347,136 -c----w c:\windows\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2008-04-23 04:16:28 214,528 -c----w c:\windows\ie7updates\KB953838-IE7\dxtrans.dll
+ 2008-04-23 04:16:28 133,120 -c----w c:\windows\ie7updates\KB953838-IE7\extmgr.dll
+ 2008-04-23 04:16:28 63,488 -c----w c:\windows\ie7updates\KB953838-IE7\icardie.dll
+ 2008-04-22 07:39:58 70,656 -c----w c:\windows\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2008-04-23 04:16:28 153,088 -c----w c:\windows\ie7updates\KB953838-IE7\ieakeng.dll
+ 2008-04-23 04:16:28 230,400 -c----w c:\windows\ie7updates\KB953838-IE7\ieaksie.dll
+ 2008-04-20 05:07:51 161,792 -c----w c:\windows\ie7updates\KB953838-IE7\ieakui.dll
+ 2008-04-23 04:16:28 383,488 -c----w c:\windows\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2008-04-23 04:16:28 384,512 -c----w c:\windows\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2008-04-23 04:16:28 6,066,176 -c----w c:\windows\ie7updates\KB953838-IE7\ieframe.dll

EasyEEE
2008-12-29, 18:07
+ 2008-04-23 04:16:28 44,544 -c----w c:\windows\ie7updates\KB953838-IE7\iernonce.dll
+ 2008-04-23 04:16:28 267,776 -c----w c:\windows\ie7updates\KB953838-IE7\iertutil.dll
+ 2008-04-22 07:39:58 13,824 -c----w c:\windows\ie7updates\KB953838-IE7\ieudinit.exe
+ 2008-04-22 07:40:18 625,664 -c----w c:\windows\ie7updates\KB953838-IE7\iexplore.exe
+ 2008-04-23 04:16:28 27,648 -c----w c:\windows\ie7updates\KB953838-IE7\jsproxy.dll
+ 2008-04-23 04:16:28 459,264 -c----w c:\windows\ie7updates\KB953838-IE7\msfeeds.dll
+ 2008-04-23 04:16:28 52,224 -c----w c:\windows\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2008-04-24 02:16:30 3,591,680 -c----w c:\windows\ie7updates\KB953838-IE7\mshtml.dll
+ 2008-04-23 04:16:28 478,208 -c----w c:\windows\ie7updates\KB953838-IE7\mshtmled.dll
+ 2008-04-23 04:16:28 193,024 -c----w c:\windows\ie7updates\KB953838-IE7\msrating.dll
+ 2008-04-23 04:16:28 671,232 -c----w c:\windows\ie7updates\KB953838-IE7\mstime.dll
+ 2008-04-23 04:16:28 102,912 -c----w c:\windows\ie7updates\KB953838-IE7\occache.dll
+ 2008-04-23 04:16:28 44,544 -c----w c:\windows\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2008-04-23 04:16:28 105,984 -c----w c:\windows\ie7updates\KB953838-IE7\url.dll
+ 2008-04-23 04:16:29 1,159,680 -c----w c:\windows\ie7updates\KB953838-IE7\urlmon.dll
+ 2008-04-23 04:16:29 233,472 -c----w c:\windows\ie7updates\KB953838-IE7\webcheck.dll
+ 2008-04-23 04:16:29 826,368 -c----w c:\windows\ie7updates\KB953838-IE7\wininet.dll
+ 2008-06-23 16:57:27 124,928 -c----w c:\windows\ie7updates\KB956390-IE7\advpack.dll
+ 2008-06-23 16:57:27 347,136 -c----w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll
+ 2008-06-23 16:57:27 214,528 -c----w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll
+ 2008-06-23 16:57:27 133,120 -c----w c:\windows\ie7updates\KB956390-IE7\extmgr.dll
+ 2008-06-23 16:57:28 63,488 -c----w c:\windows\ie7updates\KB956390-IE7\icardie.dll
+ 2008-06-23 09:20:25 70,656 -c----w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe
+ 2008-06-23 16:57:29 153,088 -c----w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll
+ 2008-06-23 16:57:29 230,400 -c----w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll
+ 2008-06-21 05:23:54 161,792 -c----w c:\windows\ie7updates\KB956390-IE7\ieakui.dll
+ 2008-06-23 16:57:29 383,488 -c----w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll
+ 2008-06-23 16:57:29 384,512 -c----w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll
+ 2008-06-23 16:57:33 6,066,176 -c----w c:\windows\ie7updates\KB956390-IE7\ieframe.dll
+ 2008-06-23 16:57:33 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\iernonce.dll
+ 2008-06-23 16:57:34 267,776 -c----w c:\windows\ie7updates\KB956390-IE7\iertutil.dll
+ 2008-06-23 09:20:26 13,824 -c----w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe
+ 2008-06-23 09:20:52 625,664 -c----w c:\windows\ie7updates\KB956390-IE7\iexplore.exe
+ 2008-06-23 16:57:35 27,648 -c----w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll
+ 2008-06-23 16:57:36 459,264 -c----w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll
+ 2008-06-23 16:57:36 52,224 -c----w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll
+ 2008-06-24 14:57:40 3,592,192 -c----w c:\windows\ie7updates\KB956390-IE7\mshtml.dll
+ 2008-06-23 16:57:39 477,696 -c----w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll
+ 2008-06-23 16:57:39 193,024 -c----w c:\windows\ie7updates\KB956390-IE7\msrating.dll
+ 2008-06-23 16:57:40 671,232 -c----w c:\windows\ie7updates\KB956390-IE7\mstime.dll
+ 2008-06-23 16:57:40 102,912 -c----w c:\windows\ie7updates\KB956390-IE7\occache.dll
+ 2008-06-23 16:57:40 44,544 -c----w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll
+ 2008-06-23 16:57:40 105,984 -c----w c:\windows\ie7updates\KB956390-IE7\url.dll
+ 2008-06-23 16:57:40 1,159,680 -c----w c:\windows\ie7updates\KB956390-IE7\urlmon.dll
+ 2008-06-23 16:57:41 233,472 -c----w c:\windows\ie7updates\KB956390-IE7\webcheck.dll
+ 2008-06-23 16:57:41 826,368 -c----w c:\windows\ie7updates\KB956390-IE7\wininet.dll
+ 2008-08-26 07:24:28 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-10-17 07:08:40 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
- 2004-08-10 19:00:00 220,160 ----a-w c:\windows\ime\mscandui.dll
+ 2008-04-14 00:11:58 220,160 -c--a-w c:\windows\ime\mscandui.dll
- 2004-08-10 19:00:00 130,048 ----a-w c:\windows\ime\SOFTKBD.DLL
+ 2008-04-14 00:12:06 130,048 -c--a-w c:\windows\ime\softkbd.dll
- 2004-08-10 19:00:00 62,976 ----a-w c:\windows\ime\SPGRMR.dll
+ 2008-04-13 16:43:18 62,976 -c--a-w c:\windows\ime\spgrmr.dll
- 2004-08-10 19:00:00 250,880 ----a-w c:\windows\ime\SPTIP.dll
+ 2008-04-14 00:12:06 250,368 ----a-w c:\windows\ime\sptip.dll
+ 2008-09-13 15:37:27 10,134 ----a-r c:\windows\Installer\{13515135-48BB-4184-8C1F-2FAE0138E200}\ARPPRODUCTICON.exe
+ 2008-08-24 02:48:22 22,486 -c--a-r c:\windows\Installer\{1771FDC8-D846-4B77-996A-C80DAD42C03F}\_6FEFF9B68218417F98F549.exe
+ 2008-08-06 01:15:40 86,746 ----a-r c:\windows\Installer\{184E7118-0295-43C4-B72C-1D54AA75AAF7}\wlmail.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ARPPRODUCTICON.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2008-07-30 05:34:37 26,694 -c--a-r c:\windows\Installer\{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
- 2008-06-25 11:28:11 77,211 ----a-r c:\windows\Installer\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\ARPPRODUCTICON.exe
+ 2008-07-27 00:43:59 77,211 ----a-r c:\windows\Installer\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\ARPPRODUCTICON.exe
+ 2008-10-13 01:45:46 300,318 ----a-r c:\windows\Installer\{2DE38C17-DD7E-41BA-88BC-0A2387D29657}\livelyac.dll
+ 2008-12-11 21:36:06 102,400 ----a-r c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2008-10-24 23:10:54 29,184 ----a-r c:\windows\Installer\{3FADAA19-E595-44CA-A072-58B6B0851768}\Icon3FADAA191.exe
+ 2008-08-06 03:46:25 29,926 -c--a-r c:\windows\Installer\{508CE775-4BA4-4748-82DF-FE28DA9F03B0}\MsblIco.Exe
+ 2008-09-01 21:40:21 394,534 -c--a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\ARPPRODUCTICON.exe
+ 2008-09-01 21:40:21 22,486 -c--a-r c:\windows\Installer\{64E72FB1-2343-4977-B4A8-262CD53D0BD3}\NewShortcut1.73D5A293_D496_4B44_B535_AA8F98088895.exe
+ 2008-12-11 21:33:07 27,136 ----a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2008-11-13 22:28:24 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2008-12-11 21:35:10 86,016 ----a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
+ 2008-09-02 02:44:37 32,768 -c--a-r c:\windows\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}\icon.exe
+ 2008-11-15 22:18:22 360,518 ----a-r c:\windows\Installer\{CCC4E428-411E-4605-B515-317D50ABD477}\ARPPRODUCTICON.exe
+ 2008-10-12 01:58:04 15,086 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\ARPPRODUCTICON.exe
+ 2008-10-12 01:58:04 65,536 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\LightScribeWebsite_9607541794D946E89D5752F753E35CC4.exe
+ 2008-10-12 01:58:04 323,584 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\NewShortcut1_C673DF680CDE41FC9DFBF63D31DE4F28.exe
+ 2008-10-12 01:58:04 339,968 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\NewShortcut1_FE82206EF6124B479F4EDD27A1E056A4.exe
+ 2008-10-12 01:58:04 323,584 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\NewShortcut2_C673DF680CDE41FC9DFBF63D31DE4F28.exe
+ 2008-10-12 01:58:04 65,536 ----a-r c:\windows\Installer\{DA9DAC64-C947-47BA-B411-8A1959B177CF}\QuickDemoUrl_E9752251A5AD4678977047FD65566D18.exe
+ 2008-09-07 19:53:30 7,598 ----a-r c:\windows\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ARPPRODUCTICON.exe
+ 2008-09-07 19:53:30 7,598 -c--a-r c:\windows\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ead_desktop_shortcut_F557710133CC471182353A95BCD49DB0.exe
+ 2008-09-07 19:53:30 7,598 -c--a-r c:\windows\Installer\{EF7E931D-DC84-471B-8DB6-A83358095474}\ead_startmenu_shortc_F557710133CC471182353A95BCD49DB0.exe
+ 2008-11-20 18:15:57 7,424,000 ----a-r c:\windows\Installer\{F44DA61E-720D-4E79-871F-F6E628B33242}\soffice.exe
- 2008-07-13 13:19:24 21,446 ----a-r c:\windows\Installer\{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}\ARPPRODUCTICON.exe
+ 2008-12-24 17:46:57 21,446 ----a-r c:\windows\Installer\{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}\ARPPRODUCTICON.exe
+ 2008-01-18 15:13:09 2,247 -c----w c:\windows\Installer\tsclientmsitrans\tscdsbl.bat
+ 2007-12-12 10:33:51 18,917 -c----w c:\windows\Installer\tsclientmsitrans\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 -c----w c:\windows\Installer\tsclientmsitrans\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 -c----w c:\windows\Installer\tsclientmsitrans\tscupdc.dll
- 2003-02-21 10:09:46 57,344 ----a-w c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2007-10-24 05:47:38 82,944 -c--a-w c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
- 2003-02-21 10:09:32 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2007-10-24 05:47:38 16,896 -c--a-w c:\windows\Microsoft.NET\Framework\sbscmp10.dll
+ 2007-10-24 05:47:40 16,896 -c--a-w c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
+ 2007-10-24 05:47:42 16,896 -c--a-w c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
+ 2007-10-24 05:47:40 16,896 -c--a-w c:\windows\Microsoft.NET\Framework\SharedReg12.dll
- 2002-06-22 08:31:20 20,480 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_filter.dll
+ 2008-04-13 16:09:58 20,480 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_filter.dll
- 2007-01-02 21:34:04 200,704 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2008-04-13 16:09:59 200,704 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
- 2004-08-04 13:11:06 24,576 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_regiis.exe
+ 2008-04-13 16:10:01 24,576 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_regiis.exe
- 2002-06-22 08:31:22 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2008-04-13 16:10:01 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
- 2007-01-02 21:34:04 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
+ 2008-04-13 16:10:01 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
- 2007-01-15 21:10:00 61,440 ------w c:\windows\Microsoft.NET\Framework\v1.0.3705\gacutil.exe
+ 2008-04-13 16:10:32 61,440 -c----w c:\windows\Microsoft.NET\Framework\v1.0.3705\gacutil.exe
- 2003-02-21 09:43:50 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2007-10-24 05:47:38 97,280 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
- 2007-01-02 21:28:28 2,273,280 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
+ 2007-12-17 11:58:53 2,273,280 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
- 2007-01-02 21:28:46 2,281,472 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
+ 2007-12-17 11:59:26 2,281,472 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- 2007-01-15 21:11:26 73,728 ------w c:\windows\Microsoft.NET\Framework\v1.0.3705\netfxupdate.exe
+ 2007-12-17 11:59:53 82,976 -c----w c:\windows\Microsoft.NET\Framework\v1.0.3705\netfxupdate.exe
- 2007-01-15 21:11:30 57,344 ------w c:\windows\Microsoft.NET\Framework\v1.0.3705\SetRegNI.exe
+ 2007-12-17 11:59:54 66,592 -c----w c:\windows\Microsoft.NET\Framework\v1.0.3705\setregni.exe
- 2004-07-20 09:54:18 1,179,648 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\System.dll
+ 2007-12-17 11:59:56 1,179,648 -c--a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\system.dll
- 2007-01-15 21:11:30 57,344 ------w c:\windows\Microsoft.NET\Framework\v1.0.3705\ToGac.exe
+ 2007-12-17 12:00:05 66,592 -c----w c:\windows\Microsoft.NET\Framework\v1.0.3705\togac.exe
+ 2007-10-24 05:47:26 28,672 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
+ 2007-10-24 05:47:30 145,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
+ 2007-10-24 05:47:32 13,824 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
+ 2007-10-24 05:47:48 193,016 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
+ 2007-10-24 05:47:20 218,112 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
+ 2007-10-24 05:47:40 10,752 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
+ 2007-10-24 05:47:42 147,968 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
+ 2007-10-24 05:47:26 99,320 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
+ 2007-10-24 05:47:42 59,392 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
+ 2007-10-24 05:47:22 36,864 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
+ 2007-10-24 05:47:22 22,024 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
+ 2007-10-24 05:47:22 17,928 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
+ 2007-10-24 05:47:22 33,288 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
+ 2007-10-24 05:47:22 84,480 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
+ 2007-10-24 05:47:22 24,576 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
+ 2007-10-24 05:47:22 32,776 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
+ 2007-10-24 05:47:22 106,496 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
+ 2007-10-24 05:47:22 33,800 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
+ 2007-10-24 05:47:22 33,280 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
+ 2007-10-24 05:47:22 507,904 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
+ 2007-10-24 05:47:40 106,496 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
+ 2007-10-24 05:47:40 101,896 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
+ 2007-10-24 05:47:30 80,376 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
+ 2007-10-24 05:47:30 1,162,744 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2007-10-24 05:47:30 13,312 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
+ 2007-10-24 05:47:42 27,136 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
+ 2007-10-24 05:47:40 69,120 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
+ 2007-10-24 05:47:30 35,320 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
+ 2007-10-24 05:47:28 66,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
+ 2007-10-24 05:47:28 5,120 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
+ 2007-10-24 05:47:54 572,936 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
+ 2007-10-24 05:47:40 798,224 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
+ 2007-10-24 05:47:36 18,936 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
+ 2007-10-24 05:47:40 9,728 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
+ 2007-10-24 05:47:40 8,192 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
+ 2007-10-24 05:47:40 77,824 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
+ 2007-10-24 05:47:40 6,656 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
+ 2007-10-24 05:47:40 230,904 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
+ 2007-10-24 05:47:40 28,672 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
+ 2007-10-24 05:47:40 65,032 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
+ 2007-10-24 05:47:40 72,192 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
+ 2007-10-24 05:47:34 40,960 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
+ 2007-10-24 05:47:36 348,160 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
+ 2007-10-24 05:47:36 36,864 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
+ 2007-10-24 05:47:36 655,360 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
+ 2007-10-24 05:47:36 77,824 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
+ 2007-10-24 05:47:34 749,568 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
+ 2007-10-24 05:47:52 110,592 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2007-10-24 05:47:52 372,736 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
+ 2007-10-24 05:47:50 671,744 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
+ 2007-10-24 05:47:20 28,672 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
+ 2007-10-24 05:47:52 5,632 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
+ 2007-10-24 05:47:20 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
+ 2007-10-24 05:47:20 12,800 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2007-10-24 05:47:20 7,168 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
+ 2007-10-24 05:47:22 97,792 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
+ 2007-10-24 05:47:36 69,632 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
+ 2007-10-24 05:47:40 822,280 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
+ 2007-10-24 05:47:40 83,456 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
+ 2007-10-24 05:47:40 308,224 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
+ 2007-10-24 05:47:40 47,104 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
+ 2007-10-24 05:47:40 348,672 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
+ 2007-10-24 05:47:40 94,208 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
+ 2007-10-24 05:47:40 4,444,160 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2007-10-24 05:47:40 114,688 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
+ 2007-10-24 05:47:44 340,992 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
+ 2007-10-24 05:47:40 77,312 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
+ 2007-10-24 05:47:36 18,944 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
+ 2007-10-24 05:47:40 242,688 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
+ 2007-10-24 05:47:40 70,144 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
+ 2007-10-24 05:47:40 19,456 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
+ 2007-10-24 05:47:36 5,814,784 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2007-10-24 05:47:44 31,744 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
+ 2007-10-24 05:47:40 101,880 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
+ 2007-10-24 05:47:40 24,584 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
+ 2007-10-24 05:47:40 89,096 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
+ 2007-10-24 05:47:36 144,896 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
+ 2007-10-24 05:47:40 53,248 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
+ 2007-10-24 05:47:40 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
+ 2007-10-24 05:47:46 61,952 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
+ 2007-10-24 05:47:42 16,896 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
+ 2007-10-24 05:47:40 119,296 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
+ 2007-10-24 05:47:44 95,232 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
+ 2007-10-24 05:47:40 392,696 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
+ 2007-10-24 05:47:40 110,592 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll

EasyEEE
2008-12-29, 18:08
+ 2007-10-24 05:47:42 425,984 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
+ 2007-10-24 05:47:40 81,920 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
+ 2007-10-24 05:47:40 3,036,160 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2007-10-24 05:47:40 483,840 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
+ 2007-10-24 05:47:40 741,376 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
+ 2007-10-24 05:47:28 933,888 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
+ 2007-10-24 05:47:40 5,070,848 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2007-10-24 05:47:40 401,408 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
+ 2007-10-24 05:47:40 188,416 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
+ 2007-10-24 05:47:40 3,076,096 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2007-10-24 05:47:40 81,920 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
+ 2007-10-24 05:47:40 630,784 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
+ 2007-10-24 05:47:40 258,048 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
+ 2007-10-24 05:47:40 57,392 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
+ 2007-10-24 05:47:40 113,664 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
+ 2007-10-24 05:47:40 372,736 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
+ 2007-10-24 05:47:40 258,048 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
+ 2007-10-24 05:47:40 299,008 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
+ 2007-10-24 05:47:40 131,072 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
+ 2007-10-24 05:47:40 258,048 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
+ 2007-10-24 05:47:40 114,688 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
+ 2007-10-24 05:47:40 261,120 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
+ 2007-10-24 05:47:40 5,431,296 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2007-10-24 05:47:40 884,736 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
+ 2007-10-24 05:47:40 90,112 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
+ 2007-10-24 05:47:40 839,680 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
+ 2007-10-24 05:47:40 5,013,504 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2007-10-24 05:47:40 2,068,480 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2007-10-24 05:47:40 81,400 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
+ 2007-10-24 05:47:48 1,172,472 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2007-10-24 05:47:20 1,344,000 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2007-10-24 05:47:22 434,688 -c--a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
+ 2007-10-24 05:47:40 37,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
+ 2007-10-11 13:55:14 159,744 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
+ 2007-10-11 13:55:10 864,256 ----a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
+ 2007-10-11 13:55:12 397,312 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
+ 2007-10-11 13:55:12 151,552 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
+ 2007-10-11 13:55:14 2,560 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
+ 2007-10-11 13:55:14 61,440 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
+ 2007-10-11 13:55:14 11,264 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2007-10-11 13:55:14 102,400 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMDiagnostics.dll
+ 2007-10-11 13:55:14 122,880 ----a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
+ 2007-10-11 13:55:14 929,792 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2007-10-11 13:55:14 5,971,968 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2007-10-11 13:55:14 159,744 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2007-10-11 13:55:14 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2007-10-11 13:55:14 143,360 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
+ 2007-10-06 07:18:12 16,936 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
+ 2006-10-20 20:08:52 797,696 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\NaturalLanguage6.dll
+ 2006-10-20 20:09:02 4,874,240 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsData0009.dll
+ 2006-10-20 18:03:40 2,628,608 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsLexicons0009.dll
+ 2007-10-09 17:03:00 76,312 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
+ 2007-10-09 16:58:12 32,768 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
+ 2007-10-09 16:58:12 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
+ 2007-10-09 17:03:08 121,368 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2007-10-09 16:58:14 897,024 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
+ 2007-10-09 16:58:20 14,848 -c--a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
- 2004-08-10 19:00:00 24,064 ----a-w c:\windows\msagent\agentanm.dll
+ 2008-04-14 00:11:48 24,064 -c--a-w c:\windows\msagent\agentanm.dll
- 2004-08-10 19:00:00 214,016 ----a-w c:\windows\msagent\agentctl.dll
+ 2008-04-14 00:11:48 214,016 -c--a-w c:\windows\msagent\agentctl.dll
- 2006-10-12 14:02:52 42,496 ----a-w c:\windows\msagent\agentdp2.dll
+ 2008-04-14 00:11:48 42,496 ----a-w c:\windows\msagent\agentdp2.dll
- 2007-03-09 13:58:57 57,344 ----a-w c:\windows\msagent\agentdpv.dll
+ 2008-04-14 00:11:48 57,344 -c--a-w c:\windows\msagent\agentdpv.dll
- 2004-08-10 19:00:00 49,152 ----a-w c:\windows\msagent\agentmpx.dll
+ 2008-04-14 00:11:48 49,152 -c--a-w c:\windows\msagent\agentmpx.dll
- 2004-08-10 19:00:00 24,064 ----a-w c:\windows\msagent\agentpsh.dll
+ 2008-04-14 00:11:48 24,064 ----a-w c:\windows\msagent\agentpsh.dll
- 2004-08-10 19:00:00 44,032 ----a-w c:\windows\msagent\agentsr.dll
+ 2008-04-14 00:11:48 44,032 -c--a-w c:\windows\msagent\agentsr.dll
- 2006-10-12 11:09:53 256,512 ----a-w c:\windows\msagent\agentsvr.exe
+ 2008-04-14 00:12:12 256,512 -c--a-w c:\windows\msagent\agentsvr.exe
- 2004-08-10 19:00:00 24,064 ----a-w c:\windows\msagent\agtintl.dll
+ 2008-04-14 00:11:49 24,064 -c--a-w c:\windows\msagent\agtintl.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0405.dll
+ 2007-04-02 18:25:59 19,456 -c--a-w c:\windows\msagent\intl\agt0405.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0406.dll
+ 2007-04-02 18:25:59 19,456 -c--a-w c:\windows\msagent\intl\agt0406.dll
- 2004-08-10 19:00:00 21,504 ----a-w c:\windows\msagent\intl\agt0407.dll
+ 2007-04-02 18:26:00 21,504 -c--a-w c:\windows\msagent\intl\agt0407.dll
- 2004-08-10 19:00:00 22,016 ----a-w c:\windows\msagent\intl\agt0408.dll
+ 2007-04-02 18:26:00 22,016 -c--a-w c:\windows\msagent\intl\agt0408.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0409.dll
+ 2008-04-13 17:32:28 19,968 -c--a-w c:\windows\msagent\intl\agt0409.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt040b.dll
+ 2007-04-02 18:26:00 19,456 -c--a-w c:\windows\msagent\intl\agt040b.dll
- 2004-08-10 19:00:00 21,504 ----a-w c:\windows\msagent\intl\agt040c.dll
+ 2007-04-02 18:26:00 21,504 -c--a-w c:\windows\msagent\intl\agt040c.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\msagent\intl\agt040e.dll
+ 2007-04-02 18:26:00 19,968 -c--a-w c:\windows\msagent\intl\agt040e.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\msagent\intl\agt0410.dll
+ 2007-04-02 18:26:00 20,992 -c--a-w c:\windows\msagent\intl\agt0410.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\msagent\intl\agt0413.dll
+ 2007-04-02 18:26:01 20,992 -c--a-w c:\windows\msagent\intl\agt0413.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0414.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\msagent\intl\agt0414.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0415.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\msagent\intl\agt0415.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\msagent\intl\agt0416.dll
+ 2007-04-02 18:26:01 20,480 -c--a-w c:\windows\msagent\intl\agt0416.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt0419.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\msagent\intl\agt0419.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt041d.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\msagent\intl\agt041d.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\msagent\intl\agt041f.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\msagent\intl\agt041f.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\msagent\intl\agt0816.dll
+ 2007-04-02 18:26:02 20,992 -c--a-w c:\windows\msagent\intl\agt0816.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\msagent\intl\agt0c0a.dll
+ 2007-04-02 18:26:02 20,480 -c--a-w c:\windows\msagent\intl\agt0c0a.dll
- 2004-08-10 19:00:00 39,936 ----a-w c:\windows\msagent\mslwvtts.dll
+ 2008-04-14 00:12:00 39,936 -c--a-w c:\windows\msagent\mslwvtts.dll
- 2004-08-10 19:00:00 90,624 ----a-w c:\windows\mui\muisetup.exe
+ 2008-04-14 00:12:29 90,624 -c--a-w c:\windows\mui\muisetup.exe
- 2006-06-03 11:40:49 33,792 ------w c:\windows\network diagnostic\custsat.dll
+ 2008-04-14 00:11:51 33,792 -c----w c:\windows\network diagnostic\custsat.dll
- 2006-10-10 12:44:50 557,568 ------w c:\windows\network diagnostic\xpnetdiag.exe
+ 2008-04-13 18:53:32 558,080 ------w c:\windows\network diagnostic\xpnetdiag.exe
- 2000-08-31 12:00:00 28,672 ----a-w c:\windows\Nircmd.exe
+ 2000-08-31 13:00:00 28,672 -c--a-w c:\windows\Nircmd.exe
- 2004-08-10 19:00:00 69,120 ----a-w c:\windows\NOTEPAD.EXE
+ 2008-04-14 00:12:29 69,120 -c--a-w c:\windows\notepad.exe
- 2004-08-10 19:00:00 768,512 ----a-w c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
+ 2008-04-14 00:12:21 769,024 ----a-w c:\windows\pchealth\helpctr\binaries\helpctr.exe
- 2004-08-10 19:00:00 743,936 ----a-w c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
+ 2008-04-14 00:12:21 744,448 ----a-w c:\windows\pchealth\helpctr\binaries\helpsvc.exe
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\pchealth\helpctr\binaries\HscUpd.exe
+ 2008-04-14 00:12:21 18,432 -c--a-w c:\windows\pchealth\helpctr\binaries\hscupd.exe
- 2004-08-10 19:00:00 158,208 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
+ 2008-04-14 00:12:27 169,984 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe
- 2004-08-10 19:00:00 376,320 ----a-w c:\windows\pchealth\helpctr\binaries\msinfo.dll
+ 2008-04-14 00:11:59 376,832 ----a-w c:\windows\pchealth\helpctr\binaries\msinfo.dll
- 2004-08-10 19:00:00 102,400 ----a-w c:\windows\pchealth\helpctr\binaries\pchshell.dll
+ 2008-04-14 00:12:02 102,912 ----a-w c:\windows\pchealth\helpctr\binaries\pchshell.dll
- 2004-08-10 19:00:00 38,912 ----a-w c:\windows\pchealth\helpctr\binaries\pchsvc.dll
+ 2008-04-14 00:12:02 38,400 ----a-w c:\windows\pchealth\helpctr\binaries\pchsvc.dll
- 2005-01-10 01:33:43 86,811 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2008-07-14 00:33:07 86,811 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2005-01-10 01:33:43 2,970 ----a-w c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2008-07-14 00:33:07 3,708 ----a-w c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
- 2004-08-10 19:00:00 150,528 ----a-w c:\windows\pchealth\UploadLB\Binaries\UploadM.exe
+ 2008-04-14 00:12:38 150,528 -c--a-w c:\windows\pchealth\UploadLB\Binaries\uploadm.exe
- 2004-08-10 19:00:00 151,552 ----a-w c:\windows\PeerNet\sqldb20.dll
+ 2008-04-14 00:12:06 151,552 -c--a-w c:\windows\PeerNet\sqldb20.dll
- 2004-08-10 19:00:00 462,848 ----a-w c:\windows\PeerNet\sqlqp20.dll
+ 2008-04-14 00:12:06 462,848 -c--a-w c:\windows\PeerNet\sqlqp20.dll
- 2004-08-10 19:00:00 110,592 ----a-w c:\windows\PeerNet\sqlse20.dll
+ 2008-04-14 00:12:06 110,592 -c--a-w c:\windows\PeerNet\sqlse20.dll
- 2004-08-10 19:00:00 146,432 ----a-w c:\windows\regedit.exe
+ 2008-04-14 00:12:32 146,432 ----a-w c:\windows\regedit.exe
+ 2008-04-13 18:46:18 53,376 -c----w c:\windows\ServicePackFiles\i386\1394bus.sys
+ 2008-04-13 18:40:50 12,288 -c----w c:\windows\ServicePackFiles\i386\4mmdat.sys
+ 2008-04-13 18:46:20 48,128 -c----w c:\windows\ServicePackFiles\i386\61883.sys
+ 2008-04-14 00:11:48 100,352 -c----w c:\windows\ServicePackFiles\i386\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 -c----w c:\windows\ServicePackFiles\i386\aaclient.dll
+ 2004-08-04 02:32:22 231,552 -c----w c:\windows\ServicePackFiles\i386\ac97ali.sys
+ 2004-08-04 02:32:32 84,480 -c----w c:\windows\ServicePackFiles\i386\ac97via.sys
+ 2008-04-14 00:11:48 39,424 -c----w c:\windows\ServicePackFiles\i386\acadproc.dll
+ 2008-04-14 00:12:11 184,320 -c----w c:\windows\ServicePackFiles\i386\accwiz.exe
+ 2008-04-14 00:11:48 1,852,928 -c----w c:\windows\ServicePackFiles\i386\acgenral.dll
+ 2008-04-14 00:11:48 451,072 -c----w c:\windows\ServicePackFiles\i386\aclayers.dll
+ 2008-04-14 00:11:48 141,312 -c----w c:\windows\ServicePackFiles\i386\aclua.dll
+ 2008-04-14 00:11:48 115,712 -c----w c:\windows\ServicePackFiles\i386\aclui.dll
+ 2008-04-13 18:36:35 187,776 -c----w c:\windows\ServicePackFiles\i386\acpi.sys
+ 2008-04-14 00:11:48 245,248 -c----w c:\windows\ServicePackFiles\i386\acspecfc.dll
+ 2008-04-14 00:11:48 193,536 -c----w c:\windows\ServicePackFiles\i386\activeds.dll
+ 2008-04-14 00:12:12 4,096 -c----w c:\windows\ServicePackFiles\i386\actmovie.exe
+ 2008-04-14 00:11:48 98,304 -c----w c:\windows\ServicePackFiles\i386\actxprxy.dll
+ 2008-04-14 00:11:48 116,224 -c----w c:\windows\ServicePackFiles\i386\acxtrnal.dll
+ 2008-04-14 00:11:48 29,696 -c----w c:\windows\ServicePackFiles\i386\admexs.dll
+ 2008-04-14 00:11:48 20,540 -c----w c:\windows\ServicePackFiles\i386\admin.dll
+ 2008-04-14 00:12:12 16,439 -c----w c:\windows\ServicePackFiles\i386\admin.exe
+ 2004-08-04 02:32:24 10,880 -c----w c:\windows\ServicePackFiles\i386\admjoy.sys
+ 2008-04-14 00:11:48 61,440 -c----w c:\windows\ServicePackFiles\i386\admparse.dll
+ 2008-04-14 00:11:48 43,520 -c----w c:\windows\ServicePackFiles\i386\admwprox.dll
+ 2008-04-14 00:11:48 290,816 -c----w c:\windows\ServicePackFiles\i386\adsiis51.dll
+ 2008-04-14 00:11:48 175,616 -c----w c:\windows\ServicePackFiles\i386\adsldp.dll
+ 2008-04-14 00:11:48 143,360 -c----w c:\windows\ServicePackFiles\i386\adsldpc.dll
+ 2008-04-14 00:11:48 68,096 -c----w c:\windows\ServicePackFiles\i386\adsmsext.dll
+ 2008-04-14 00:11:48 263,680 -c----w c:\windows\ServicePackFiles\i386\adsnt.dll
+ 2008-04-14 00:11:48 123,392 -c----w c:\windows\ServicePackFiles\i386\adsnw.dll
+ 2004-07-17 15:35:20 85,813 -c----w c:\windows\ServicePackFiles\i386\adsutil.vbs
+ 2008-04-14 00:11:48 4,255 -c----w c:\windows\ServicePackFiles\i386\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 -c----w c:\windows\ServicePackFiles\i386\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 -c----w c:\windows\ServicePackFiles\i386\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 -c----w c:\windows\ServicePackFiles\i386\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 -c----w c:\windows\ServicePackFiles\i386\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 -c----w c:\windows\ServicePackFiles\i386\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 -c----w c:\windows\ServicePackFiles\i386\adv11nt5.dll
+ 2008-04-14 00:11:48 617,472 -c----w c:\windows\ServicePackFiles\i386\advapi32.dll
+ 2008-04-14 00:11:48 99,840 -c----w c:\windows\ServicePackFiles\i386\advpack.dll
+ 2008-04-13 16:39:23 142,592 -c----w c:\windows\ServicePackFiles\i386\aec.sys
+ 2008-04-13 19:19:23 138,112 -c----w c:\windows\ServicePackFiles\i386\afd.sys
+ 2008-04-14 00:11:48 24,064 -c----w c:\windows\ServicePackFiles\i386\agentanm.dll
+ 2008-04-14 00:11:48 214,016 -c----w c:\windows\ServicePackFiles\i386\agentctl.dll
+ 2008-04-14 00:11:48 42,496 -c----w c:\windows\ServicePackFiles\i386\agentdp2.dll
+ 2008-04-14 00:11:48 57,344 -c----w c:\windows\ServicePackFiles\i386\agentdpv.dll
+ 2008-04-14 00:11:48 49,152 -c----w c:\windows\ServicePackFiles\i386\agentmpx.dll
+ 2008-04-14 00:11:48 24,064 -c----w c:\windows\ServicePackFiles\i386\agentpsh.dll
+ 2008-04-14 00:11:48 44,032 -c----w c:\windows\ServicePackFiles\i386\agentsr.dll
+ 2008-04-14 00:12:12 256,512 -c----w c:\windows\ServicePackFiles\i386\agentsvr.exe
+ 2008-04-13 18:36:38 42,368 -c----w c:\windows\ServicePackFiles\i386\agp440.sys
+ 2008-04-13 18:36:39 44,928 -c----w c:\windows\ServicePackFiles\i386\agpcpq.sys
+ 2007-04-02 18:25:59 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0401.dll
+ 2007-04-02 18:25:59 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0404.dll
+ 2007-04-02 18:25:59 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0405.dll
+ 2007-04-02 18:25:59 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0406.dll
+ 2007-04-02 18:26:00 21,504 -c----w c:\windows\ServicePackFiles\i386\agt0407.dll
+ 2007-04-02 18:26:00 22,016 -c----w c:\windows\ServicePackFiles\i386\agt0408.dll
+ 2008-04-13 17:32:28 19,968 -c----w c:\windows\ServicePackFiles\i386\agt0409.dll
+ 2007-04-02 18:26:00 19,456 -c----w c:\windows\ServicePackFiles\i386\agt040b.dll
+ 2007-04-02 18:26:00 21,504 -c----w c:\windows\ServicePackFiles\i386\agt040c.dll
+ 2007-04-02 18:26:00 19,456 -c----w c:\windows\ServicePackFiles\i386\agt040d.dll
+ 2007-04-02 18:26:00 19,968 -c----w c:\windows\ServicePackFiles\i386\agt040e.dll
+ 2007-04-02 18:26:00 20,992 -c----w c:\windows\ServicePackFiles\i386\agt0410.dll
+ 2007-04-02 18:26:00 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0411.dll
+ 2007-04-02 18:26:00 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0412.dll
+ 2007-04-02 18:26:01 20,992 -c----w c:\windows\ServicePackFiles\i386\agt0413.dll
+ 2007-04-02 18:26:01 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0414.dll
+ 2007-04-02 18:26:01 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0415.dll
+ 2007-04-02 18:26:01 20,480 -c----w c:\windows\ServicePackFiles\i386\agt0416.dll
+ 2007-04-02 18:26:01 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0419.dll
+ 2007-04-02 18:26:01 19,456 -c----w c:\windows\ServicePackFiles\i386\agt041d.dll
+ 2007-04-02 18:26:01 19,456 -c----w c:\windows\ServicePackFiles\i386\agt041f.dll
+ 2007-04-02 18:26:02 19,456 -c----w c:\windows\ServicePackFiles\i386\agt0804.dll
+ 2007-04-02 18:26:02 20,992 -c----w c:\windows\ServicePackFiles\i386\agt0816.dll
+ 2007-04-02 18:26:02 20,480 -c----w c:\windows\ServicePackFiles\i386\agt0c0a.dll
+ 2008-04-14 00:11:49 24,064 -c----w c:\windows\ServicePackFiles\i386\agtintl.dll
+ 2008-04-14 00:12:12 98,304 -c----w c:\windows\ServicePackFiles\i386\ahui.exe
+ 2008-04-14 00:12:12 44,544 -c----w c:\windows\ServicePackFiles\i386\alg.exe
+ 2008-04-13 18:36:38 42,752 -c----w c:\windows\ServicePackFiles\i386\alim1541.sys
+ 2008-04-14 00:11:49 17,408 -c----w c:\windows\ServicePackFiles\i386\alrsvc.dll
+ 2008-04-13 18:36:39 43,008 -c----w c:\windows\ServicePackFiles\i386\amdagp.sys
+ 2008-04-13 18:31:32 37,376 -c----w c:\windows\ServicePackFiles\i386\amdk6.sys
+ 2008-04-13 18:31:33 37,760 -c----w c:\windows\ServicePackFiles\i386\amdk7.sys
+ 2008-04-14 00:11:49 70,656 -c----w c:\windows\ServicePackFiles\i386\amstream.dll
+ 2004-08-04 02:31:20 36,224 -c----w c:\windows\ServicePackFiles\i386\an983.sys
+ 2008-04-14 00:11:49 108,544 -c----w c:\windows\ServicePackFiles\i386\appconf.dll
+ 2008-04-14 00:11:49 125,952 -c----w c:\windows\ServicePackFiles\i386\apphelp.dll
+ 2008-04-14 00:11:49 167,936 -c----w c:\windows\ServicePackFiles\i386\appmgmts.dll
+ 2008-04-14 00:11:49 295,936 -c----w c:\windows\ServicePackFiles\i386\appmgr.dll
+ 2008-04-14 00:11:49 331,264 -c----w c:\windows\ServicePackFiles\i386\aqueue.dll
+ 2008-04-13 18:51:25 60,800 -c----w c:\windows\ServicePackFiles\i386\arp1394.sys
+ 2008-04-14 00:11:49 369,664 -c----w c:\windows\ServicePackFiles\i386\asp51.dll
+ 2008-04-13 16:09:58 20,480 -c----w c:\windows\ServicePackFiles\i386\aspnet_filter.dll
+ 2008-04-13 16:09:59 200,704 -c----w c:\windows\ServicePackFiles\i386\aspnet_isapi.dll
+ 2008-04-13 16:10:01 24,576 -c----w c:\windows\ServicePackFiles\i386\aspnet_regiis.exe
+ 2008-04-13 16:10:01 32,768 -c----w c:\windows\ServicePackFiles\i386\aspnet_state.exe
+ 2008-04-13 16:10:01 32,768 -c----w c:\windows\ServicePackFiles\i386\aspnet_wp.exe
+ 2008-04-14 00:12:12 30,208 -c----w c:\windows\ServicePackFiles\i386\asr_fmt.exe
+ 2008-04-14 00:12:12 32,768 -c----w c:\windows\ServicePackFiles\i386\asr_pfu.exe
+ 2008-04-14 00:11:49 65,024 -c----w c:\windows\ServicePackFiles\i386\asycfilt.dll
+ 2008-04-13 18:57:27 14,336 -c----w c:\windows\ServicePackFiles\i386\asyncmac.sys
+ 2008-04-14 00:12:12 25,088 -c----w c:\windows\ServicePackFiles\i386\at.exe
+ 2008-04-13 18:40:30 96,512 -c----w c:\windows\ServicePackFiles\i386\atapi.sys
+ 2004-08-04 02:29:30 56,623 -c----w c:\windows\ServicePackFiles\i386\ati1btxx.sys
+ 2004-08-04 02:29:30 11,615 -c----w c:\windows\ServicePackFiles\i386\ati1mdxx.sys
+ 2004-08-04 02:29:30 12,047 -c----w c:\windows\ServicePackFiles\i386\ati1pdxx.sys
+ 2004-08-04 02:29:32 30,671 -c----w c:\windows\ServicePackFiles\i386\ati1raxx.sys
+ 2004-08-04 02:29:32 63,663 -c----w c:\windows\ServicePackFiles\i386\ati1rvxx.sys
+ 2004-08-04 02:29:32 26,367 -c----w c:\windows\ServicePackFiles\i386\ati1snxx.sys
+ 2004-08-04 02:29:32 21,343 -c----w c:\windows\ServicePackFiles\i386\ati1ttxx.sys
+ 2004-08-04 02:29:32 36,463 -c----w c:\windows\ServicePackFiles\i386\ati1tuxx.sys
+ 2004-08-04 02:29:32 29,455 -c----w c:\windows\ServicePackFiles\i386\ati1xbxx.sys
+ 2004-08-04 02:29:32 34,735 -c----w c:\windows\ServicePackFiles\i386\ati1xsxx.sys
+ 2008-04-14 00:11:49 229,376 -c----w c:\windows\ServicePackFiles\i386\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 -c----w c:\windows\ServicePackFiles\i386\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 -c----w c:\windows\ServicePackFiles\i386\ati2dvag.dll
+ 2004-08-04 02:29:28 327,040 -c----w c:\windows\ServicePackFiles\i386\ati2mtaa.sys
+ 2004-08-04 02:29:28 701,440 -c----w c:\windows\ServicePackFiles\i386\ati2mtag.sys
+ 2008-04-14 00:11:49 870,784 -c----w c:\windows\ServicePackFiles\i386\ati3d1ag.dll
+ 2008-04-14 00:11:49 1,057,760 -c----w c:\windows\ServicePackFiles\i386\ati3d2ag.dll
+ 2008-04-14 00:11:50 1,888,992 -c----w c:\windows\ServicePackFiles\i386\ati3duag.dll
+ 2004-08-04 02:29:28 57,856 -c----w c:\windows\ServicePackFiles\i386\atinbtxx.sys
+ 2004-08-04 02:29:30 13,824 -c----w c:\windows\ServicePackFiles\i386\atinmdxx.sys
+ 2004-08-04 02:29:30 14,336 -c----w c:\windows\ServicePackFiles\i386\atinpdxx.sys
+ 2004-08-04 02:29:30 52,224 -c----w c:\windows\ServicePackFiles\i386\atinraxx.sys
+ 2004-08-04 02:29:32 104,960 -c----w c:\windows\ServicePackFiles\i386\atinrvxx.sys
+ 2004-08-04 02:29:32 28,672 -c----w c:\windows\ServicePackFiles\i386\atinsnxx.sys
+ 2004-08-04 02:29:32 13,824 -c----w c:\windows\ServicePackFiles\i386\atinttxx.sys
+ 2004-08-04 02:29:32 73,216 -c----w c:\windows\ServicePackFiles\i386\atintuxx.sys
+ 2004-08-04 02:29:32 31,744 -c----w c:\windows\ServicePackFiles\i386\atinxbxx.sys
+ 2004-08-04 02:29:32 63,488 -c----w c:\windows\ServicePackFiles\i386\atinxsxx.sys
+ 2008-04-14 00:11:50 32,768 -c----w c:\windows\ServicePackFiles\i386\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 -c----w c:\windows\ServicePackFiles\i386\ativvaxx.dll
+ 2008-04-14 00:11:50 58,880 -c----w c:\windows\ServicePackFiles\i386\atl.dll
+ 2008-04-14 00:12:12 11,264 -c----w c:\windows\ServicePackFiles\i386\atmadm.exe
+ 2008-04-13 18:51:25 59,904 -c----w c:\windows\ServicePackFiles\i386\atmarpc.sys
+ 2008-04-14 00:09:01 285,696 -c----w c:\windows\ServicePackFiles\i386\atmfd.dll
+ 2008-04-13 18:51:30 55,808 -c----w c:\windows\ServicePackFiles\i386\atmlane.sys
+ 2008-04-14 00:11:50 30,208 -c----w c:\windows\ServicePackFiles\i386\atmlib.dll
+ 2008-04-14 00:12:12 12,288 -c----w c:\windows\ServicePackFiles\i386\attrib.exe
+ 2008-04-14 00:11:50 21,183 -c----w c:\windows\ServicePackFiles\i386\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 -c----w c:\windows\ServicePackFiles\i386\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 -c----w c:\windows\ServicePackFiles\i386\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 -c----w c:\windows\ServicePackFiles\i386\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 -c----w c:\windows\ServicePackFiles\i386\atv10nt5.dll
+ 2008-04-14 00:11:50 42,496 -c----w c:\windows\ServicePackFiles\i386\audiosrv.dll
+ 2008-04-14 00:12:12 14,336 -c----w c:\windows\ServicePackFiles\i386\auditusr.exe
+ 2008-04-14 00:11:50 20,540 -c----w c:\windows\ServicePackFiles\i386\author.dll
+ 2008-04-14 00:12:12 16,439 -c----w c:\windows\ServicePackFiles\i386\author.exe
+ 2008-04-14 00:11:50 62,464 -c----w c:\windows\ServicePackFiles\i386\authz.dll
+ 2008-04-14 00:12:12 588,800 -c----w c:\windows\ServicePackFiles\i386\autochk.exe
+ 2008-04-14 00:12:12 602,624 -c----w c:\windows\ServicePackFiles\i386\autoconv.exe
+ 2008-04-14 00:12:13 580,608 -c----w c:\windows\ServicePackFiles\i386\autofmt.exe
+ 2008-04-14 00:12:13 11,264 -c----w c:\windows\ServicePackFiles\i386\autolfn.exe
+ 2008-04-13 18:46:20 38,912 -c----w c:\windows\ServicePackFiles\i386\avc.sys
+ 2008-04-13 18:46:07 13,696 -c----w c:\windows\ServicePackFiles\i386\avcstrm.sys
+ 2008-04-14 00:11:50 84,992 -c----w c:\windows\ServicePackFiles\i386\avifil32.dll
+ 2008-04-14 00:11:50 233,472 -c----w c:\windows\ServicePackFiles\i386\azroles.dll
+ 2008-04-14 00:11:50 52,736 -c----w c:\windows\ServicePackFiles\i386\basesrv.dll
+ 2008-04-14 00:11:50 29,184 -c----w c:\windows\ServicePackFiles\i386\batmeter.dll
+ 2008-04-14 00:11:50 8,704 -c----w c:\windows\ServicePackFiles\i386\batt.dll
+ 2008-04-13 18:36:32 14,208 -c----w c:\windows\ServicePackFiles\i386\battc.sys
+ 2008-04-13 18:46:21 11,776 -c----w c:\windows\ServicePackFiles\i386\bdasup.sys
+ 2008-04-14 00:11:50 17,408 -c----w c:\windows\ServicePackFiles\i386\bidispl.dll
+ 2008-04-14 00:11:50 8,192 -c----w c:\windows\ServicePackFiles\i386\bitsprx2.dll
+ 2008-04-14 00:11:50 7,168 -c----w c:\windows\ServicePackFiles\i386\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 -c----w c:\windows\ServicePackFiles\i386\bitsprx4.dll
+ 2008-04-14 00:12:13 71,680 -c----w c:\windows\ServicePackFiles\i386\blastcln.exe
+ 2008-04-14 00:12:13 142,848 -c----w c:\windows\ServicePackFiles\i386\bootcfg.exe
+ 2008-04-13 18:53:23 71,552 -c----w c:\windows\ServicePackFiles\i386\bridge.sys
+ 2008-04-13 17:03:24 63,488 -c----w c:\windows\ServicePackFiles\i386\browselc.dll
+ 2008-04-14 00:11:50 77,824 -c----w c:\windows\ServicePackFiles\i386\browser.dll
+ 2008-04-14 00:11:50 1,025,024 -c----w c:\windows\ServicePackFiles\i386\browseui.dll
+ 2008-04-14 00:11:50 78,336 -c----w c:\windows\ServicePackFiles\i386\browsewm.dll
+ 2008-04-14 00:11:50 20,992 -c----w c:\windows\ServicePackFiles\i386\bthci.dll
+ 2008-04-13 18:46:33 17,024 -c----w c:\windows\ServicePackFiles\i386\bthenum.sys
+ 2008-04-13 18:46:33 37,888 -c----w c:\windows\ServicePackFiles\i386\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 -c----w c:\windows\ServicePackFiles\i386\bthpan.sys
+ 2008-04-13 18:46:32 273,024 -c----w c:\windows\ServicePackFiles\i386\bthport.sys
+ 2008-04-13 18:46:31 36,480 -c----w c:\windows\ServicePackFiles\i386\bthprint.sys
+ 2008-04-14 00:11:50 30,208 -c----w c:\windows\ServicePackFiles\i386\bthserv.dll
+ 2008-04-13 18:46:29 18,944 -c----w c:\windows\ServicePackFiles\i386\bthusb.sys
+ 2008-04-14 00:11:50 50,688 -c----w c:\windows\ServicePackFiles\i386\btpanui.dll
+ 2008-04-14 00:11:50 218,112 -c----w c:\windows\ServicePackFiles\i386\c_g18030.dll
+ 2008-04-14 00:11:50 60,416 -c----w c:\windows\ServicePackFiles\i386\cabinet.dll
+ 2008-04-14 00:11:50 84,480 -c----w c:\windows\ServicePackFiles\i386\cabview.dll
+ 2008-04-14 00:12:13 19,968 -c----w c:\windows\ServicePackFiles\i386\cacls.exe
+ 2008-04-14 00:11:50 385,024 -c----w c:\windows\ServicePackFiles\i386\callcont.dll
+ 2008-04-14 00:11:50 121,856 -c----w c:\windows\ServicePackFiles\i386\camext30.dll
+ 2008-04-14 00:11:50 50,688 -c----w c:\windows\ServicePackFiles\i386\camocx.dll
+ 2008-04-14 00:11:50 150,016 -c----w c:\windows\ServicePackFiles\i386\capesnpn.dll
+ 2004-07-20 09:54:04 94,208 -c----w c:\windows\ServicePackFiles\i386\caspol.exe
+ 2008-04-14 00:11:50 226,304 -c----w c:\windows\ServicePackFiles\i386\catsrv.dll
+ 2008-04-14 00:11:50 85,504 -c----w c:\windows\ServicePackFiles\i386\catsrvps.dll
+ 2008-04-14 00:11:50 625,664 -c----w c:\windows\ServicePackFiles\i386\catsrvut.dll
+ 2008-04-13 18:46:23 17,024 -c----w c:\windows\ServicePackFiles\i386\ccdecode.sys
+ 2008-04-13 19:14:21 63,744 -c----w c:\windows\ServicePackFiles\i386\cdfs.sys
+ 2008-04-14 00:11:50 151,040 -c----w c:\windows\ServicePackFiles\i386\cdfview.dll
+ 2008-04-14 00:11:50 66,560 -c----w c:\windows\ServicePackFiles\i386\cdm.dll
+ 2008-04-14 00:11:50 2,091,520 -c----w c:\windows\ServicePackFiles\i386\cdosys.dll
+ 2008-04-13 18:40:46 62,976 -c----w c:\windows\ServicePackFiles\i386\cdrom.sys
+ 2008-04-14 00:11:50 194,560 -c----w c:\windows\ServicePackFiles\i386\certcli.dll
+ 2008-04-14 00:11:50 457,728 -c----w c:\windows\ServicePackFiles\i386\certmgr.dll
+ 2008-04-14 00:11:50 38,912 -c----w c:\windows\ServicePackFiles\i386\cfgbkend.dll
+ 2008-04-14 00:09:05 16,896 -c----w c:\windows\ServicePackFiles\i386\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 -c----w c:\windows\ServicePackFiles\i386\cfgwiz.exe
+ 2008-04-14 00:11:50 15,423 -c----w c:\windows\ServicePackFiles\i386\ch7xxnt5.dll
+ 2008-04-13 18:40:58 8,192 -c----w c:\windows\ServicePackFiles\i386\changer.sys
+ 2008-04-14 00:11:50 148,480 -c----w c:\windows\ServicePackFiles\i386\cic.dll
+ 2008-04-14 00:11:50 1,358,848 -c----w c:\windows\ServicePackFiles\i386\cimwin32.dll
+ 2008-04-14 00:11:50 69,120 -c----w c:\windows\ServicePackFiles\i386\ciodm.dll
+ 2008-04-14 00:12:14 56,832 -c----w c:\windows\ServicePackFiles\i386\cipher.exe
+ 2008-04-14 00:12:14 5,632 -c----w c:\windows\ServicePackFiles\i386\cisvc.exe
+ 2008-04-13 19:16:22 49,536 -c----w c:\windows\ServicePackFiles\i386\classpnp.sys
+ 2008-04-14 00:11:50 110,592 -c----w c:\windows\ServicePackFiles\i386\clbcatex.dll
+ 2008-04-14 00:11:50 498,688 -c----w c:\windows\ServicePackFiles\i386\clbcatq.dll
+ 2008-04-14 00:12:14 64,000 -c----w c:\windows\ServicePackFiles\i386\cleanmgr.exe
+ 2008-04-14 00:11:50 77,824 -c----w c:\windows\ServicePackFiles\i386\cliconfg.dll
+ 2008-04-14 00:12:14 20,480 -c----w c:\windows\ServicePackFiles\i386\cliconfg.exe
+ 2008-04-14 00:12:14 102,912 -c----w c:\windows\ServicePackFiles\i386\clipbrd.exe
+ 2008-04-14 00:12:14 33,280 -c----w c:\windows\ServicePackFiles\i386\clipsrv.exe
+ 2008-04-14 00:11:50 58,368 -c----w c:\windows\ServicePackFiles\i386\clusapi.dll
+ 2008-04-13 18:36:37 13,952 -c----w c:\windows\ServicePackFiles\i386\cmbatt.sys
+ 2008-04-14 00:11:50 15,872 -c----w c:\windows\ServicePackFiles\i386\cmcfg32.dll
+ 2008-04-14 00:12:14 389,120 -c----w c:\windows\ServicePackFiles\i386\cmd.exe
+ 2008-04-14 00:11:50 344,064 -c----w c:\windows\ServicePackFiles\i386\cmdial32.dll
+ 2008-04-14 00:12:14 25,600 -c----w c:\windows\ServicePackFiles\i386\cmdl32.exe
+ 2008-04-14 00:12:15 39,936 -c----w c:\windows\ServicePackFiles\i386\cmmon32.exe
+ 2008-04-14 00:11:50 185,344 -c----w c:\windows\ServicePackFiles\i386\cmprops.dll
+ 2008-04-14 00:11:50 13,312 -c----w c:\windows\ServicePackFiles\i386\cmsetacl.dll
+ 2008-04-14 00:12:15 63,488 -c----w c:\windows\ServicePackFiles\i386\cmstp.exe
+ 2008-04-14 00:11:50 39,424 -c----w c:\windows\ServicePackFiles\i386\cmutil.dll
+ 2008-04-14 00:11:50 47,104 -c----w c:\windows\ServicePackFiles\i386\cnbjmon.dll
+ 2008-04-14 00:11:50 79,360 -c----w c:\windows\ServicePackFiles\i386\cnbjmon2.dll
+ 2008-04-14 00:11:51 46,592 -c----w c:\windows\ServicePackFiles\i386\coadmin.dll
+ 2008-04-13 16:44:16 17,920 -c----w c:\windows\ServicePackFiles\i386\cobramsg.dll
+ 2008-04-14 00:11:51 60,416 -c----w c:\windows\ServicePackFiles\i386\colbact.dll
+ 2008-04-14 00:11:51 28,160 -c----w c:\windows\ServicePackFiles\i386\comaddin.dll
+ 2008-04-14 00:11:51 195,072 -c----w c:\windows\ServicePackFiles\i386\comadmin.dll
+ 2008-04-14 00:11:51 617,472 -c----w c:\windows\ServicePackFiles\i386\comctl32.dll
+ 2008-04-14 00:11:51 276,992 -c----w c:\windows\ServicePackFiles\i386\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 -c----w c:\windows\ServicePackFiles\i386\compatui.dll
+ 2008-04-13 18:36:37 10,240 -c----w c:\windows\ServicePackFiles\i386\compbatt.sys
+ 2008-04-14 00:11:51 24,064 -c----w c:\windows\ServicePackFiles\i386\compfilt.dll
+ 2008-04-14 00:11:51 229,376 -c----w c:\windows\ServicePackFiles\i386\compstui.dll
+ 2008-04-14 00:11:51 97,792 -c----w c:\windows\ServicePackFiles\i386\comrepl.dll
+ 2008-04-14 00:12:15 9,728 -c----w c:\windows\ServicePackFiles\i386\comrepl.exe
+ 2008-04-14 00:12:15 6,144 -c----w c:\windows\ServicePackFiles\i386\comrereg.exe
+ 2008-04-14 00:11:51 792,064 -c----w c:\windows\ServicePackFiles\i386\comres.dll
+ 2008-04-13 18:43:32 9,728 -c----w c:\windows\ServicePackFiles\i386\comsdupd.exe
+ 2008-04-14 00:11:51 274,944 -c----w c:\windows\ServicePackFiles\i386\comsetup.dll
+ 2008-04-14 00:11:51 167,424 -c----w c:\windows\ServicePackFiles\i386\comsnap.dll
+ 2008-04-14 00:11:51 1,267,200 -c----w c:\windows\ServicePackFiles\i386\comsvcs.dll
+ 2008-04-14 00:11:51 539,648 -c----w c:\windows\ServicePackFiles\i386\comuid.dll
+ 2008-04-14 00:12:15 1,032,192 -c----w c:\windows\ServicePackFiles\i386\conf.exe
+ 2008-04-14 00:11:51 45,056 -c----w c:\windows\ServicePackFiles\i386\confmrsl.dll
+ 2008-04-14 00:11:51 357,888 -c----w c:\windows\ServicePackFiles\i386\confmsp.dll
+ 2008-04-14 00:12:15 27,648 -c----w c:\windows\ServicePackFiles\i386\conime.exe
+ 2004-08-04 13:11:12 69,632 -c----w c:\windows\ServicePackFiles\i386\corperfmonext.dll
+ 2008-04-14 00:11:51 35,328 -c----w c:\windows\ServicePackFiles\i386\corpol.dll
+ 2008-04-14 00:11:51 12,800 -c----w c:\windows\ServicePackFiles\i386\credssp.dll
+ 2008-04-14 00:11:51 163,840 -c----w c:\windows\ServicePackFiles\i386\credui.dll
+ 2008-04-13 18:31:32 36,736 -c----w c:\windows\ServicePackFiles\i386\crusoe.sys
+ 2008-04-14 00:11:51 599,040 -c----w c:\windows\ServicePackFiles\i386\crypt32.dll
+ 2008-04-14 00:11:51 74,752 -c----w c:\windows\ServicePackFiles\i386\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 -c----w c:\windows\ServicePackFiles\i386\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 -c----w c:\windows\ServicePackFiles\i386\cryptext.dll
+ 2008-04-14 00:11:51 64,512 -c----w c:\windows\ServicePackFiles\i386\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 -c----w c:\windows\ServicePackFiles\i386\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 -c----w c:\windows\ServicePackFiles\i386\cryptui.dll
+ 2004-08-04 13:11:18 49,152 -c----w c:\windows\ServicePackFiles\i386\csc.exe
+ 2008-04-14 00:11:51 101,888 -c----w c:\windows\ServicePackFiles\i386\cscdll.dll
+ 2004-07-20 09:54:04 589,824 -c----w c:\windows\ServicePackFiles\i386\cscomp.dll
+ 2008-04-14 00:12:15 139,264 -c----w c:\windows\ServicePackFiles\i386\cscript.exe
+ 2008-04-14 00:11:51 326,656 -c----w c:\windows\ServicePackFiles\i386\cscui.dll
+ 2008-04-14 00:11:51 32,256 -c----w c:\windows\ServicePackFiles\i386\csrsrv.dll
+ 2008-04-14 00:12:15 6,144 -c----w c:\windows\ServicePackFiles\i386\csrss.exe
+ 2008-04-14 00:12:16 15,360 -c----w c:\windows\ServicePackFiles\i386\ctfmon.exe
+ 2008-04-14 00:11:51 249,856 -c----w c:\windows\ServicePackFiles\i386\ctmasetp.dll
+ 2008-04-14 00:11:51 33,792 -c----w c:\windows\ServicePackFiles\i386\custsat.dll
+ 2004-08-04 02:32:26 48,640 -c----w c:\windows\ServicePackFiles\i386\cwrwdm.sys
+ 2008-04-14 00:11:51 1,179,648 -c----w c:\windows\ServicePackFiles\i386\d3d8.dll
+ 2008-04-14 00:11:51 8,192 -c----w c:\windows\ServicePackFiles\i386\d3d8thk.dll
+ 2008-04-14 00:11:51 1,689,088 -c----w c:\windows\ServicePackFiles\i386\d3d9.dll
+ 2008-04-14 00:11:51 824,320 -c----w c:\windows\ServicePackFiles\i386\d3dim700.dll
+ 2008-04-14 00:11:51 1,054,208 -c----w c:\windows\ServicePackFiles\i386\danim.dll
+ 2008-03-25 04:50:25 554,008 -c----w c:\windows\ServicePackFiles\i386\dao360.dll
+ 2008-04-14 00:11:51 54,272 -c----w c:\windows\ServicePackFiles\i386\dataclen.dll
+ 2008-04-14 00:11:51 165,376 -c----w c:\windows\ServicePackFiles\i386\datime.dll
+ 2008-04-14 00:12:16 42,496 -c----w c:\windows\ServicePackFiles\i386\davcdata.exe
+ 2008-04-14 00:11:51 25,088 -c----w c:\windows\ServicePackFiles\i386\davclnt.dll
+ 2008-04-14 00:11:51 640,000 -c----w c:\windows\ServicePackFiles\i386\dbghelp.dll
+ 2008-04-14 00:11:51 24,576 -c----w c:\windows\ServicePackFiles\i386\dbmsrpcn.dll
+ 2008-04-14 00:11:51 110,592 -c----w c:\windows\ServicePackFiles\i386\dbnetlib.dll
+ 2008-04-14 00:11:51 28,672 -c----w c:\windows\ServicePackFiles\i386\dbnmpntw.dll
+ 2008-04-14 00:25:26 1,804 -c----w c:\windows\ServicePackFiles\i386\dcache.bin
+ 2008-04-14 00:11:51 40,960 -c----w c:\windows\ServicePackFiles\i386\dcap32.dll
+ 2008-04-14 00:11:51 8,704 -c----w c:\windows\ServicePackFiles\i386\dciman32.dll
+ 2008-04-14 00:12:16 6,144 -c----w c:\windows\ServicePackFiles\i386\dcomcnfg.exe
+ 2008-04-14 00:12:16 30,208 -c----w c:\windows\ServicePackFiles\i386\ddeshare.exe

EasyEEE
2008-12-29, 18:10
+ 2008-04-14 00:11:51 279,552 -c----w c:\windows\ServicePackFiles\i386\ddraw.dll
+ 2008-04-14 00:11:51 27,136 -c----w c:\windows\ServicePackFiles\i386\ddrawex.dll
+ 2008-04-14 00:12:16 25,088 -c----w c:\windows\ServicePackFiles\i386\defrag.exe
+ 2008-04-14 00:11:51 59,904 -c----w c:\windows\ServicePackFiles\i386\devenum.dll
+ 2008-04-14 00:11:51 282,624 -c----w c:\windows\ServicePackFiles\i386\devmgr.dll
+ 2008-04-14 00:12:16 82,944 -c----w c:\windows\ServicePackFiles\i386\dfrgfat.exe
+ 2008-04-14 00:12:16 105,472 -c----w c:\windows\ServicePackFiles\i386\dfrgntfs.exe
+ 2008-04-14 00:11:51 39,424 -c----w c:\windows\ServicePackFiles\i386\dfrgsnap.dll
+ 2008-04-14 00:11:51 124,416 -c----w c:\windows\ServicePackFiles\i386\dfrgui.dll
+ 2008-04-14 00:11:51 28,672 -c----w c:\windows\ServicePackFiles\i386\dfsshlex.dll
+ 2008-04-14 00:11:51 111,104 -c----w c:\windows\ServicePackFiles\i386\dgnet.dll
+ 2008-04-14 00:11:51 126,976 -c----w c:\windows\ServicePackFiles\i386\dhcpcsvc.dll
+ 2008-04-14 00:11:52 379,904 -c----w c:\windows\ServicePackFiles\i386\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 -c----w c:\windows\ServicePackFiles\i386\dhcpqec.dll
+ 2008-04-14 00:12:17 539,136 -c----w c:\windows\ServicePackFiles\i386\dialer.exe
+ 2008-04-14 00:12:17 87,040 -c----w c:\windows\ServicePackFiles\i386\diantz.exe
+ 2004-08-10 19:00:00 884,712 -c----w c:\windows\ServicePackFiles\i386\digcore.exe
+ 2008-04-14 00:11:52 68,608 -c----w c:\windows\ServicePackFiles\i386\digest.dll
+ 2008-04-14 00:11:52 19,456 -c----w c:\windows\ServicePackFiles\i386\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 -c----w c:\windows\ServicePackFiles\i386\dimsroam.dll
+ 2008-04-14 00:11:52 158,720 -c----w c:\windows\ServicePackFiles\i386\dinput.dll
+ 2008-04-14 00:11:52 181,760 -c----w c:\windows\ServicePackFiles\i386\dinput8.dll
+ 2008-04-14 00:11:52 86,528 -c----w c:\windows\ServicePackFiles\i386\directdb.dll
+ 2008-04-13 18:40:47 36,352 -c----w c:\windows\ServicePackFiles\i386\disk.sys
+ 2008-04-14 00:11:52 1,504,256 -c----w c:\windows\ServicePackFiles\i386\diskcopy.dll
+ 2008-04-13 18:40:44 14,208 -c----w c:\windows\ServicePackFiles\i386\diskdump.sys
+ 2008-04-14 00:12:17 163,840 -c----w c:\windows\ServicePackFiles\i386\diskpart.exe
+ 2008-04-14 00:11:52 32,768 -c----w c:\windows\ServicePackFiles\i386\dispex.dll
+ 2008-04-14 00:12:17 5,120 -c----w c:\windows\ServicePackFiles\i386\dllhost.exe
+ 2008-04-13 18:40:51 8,320 -c----w c:\windows\ServicePackFiles\i386\dlttape.sys
+ 2008-04-14 00:12:17 224,768 -c----w c:\windows\ServicePackFiles\i386\dmadmin.exe
+ 2008-04-14 00:11:52 28,672 -c----w c:\windows\ServicePackFiles\i386\dmband.dll
+ 2008-04-13 18:44:48 799,744 -c----w c:\windows\ServicePackFiles\i386\dmboot.sys
+ 2008-04-14 00:11:52 61,440 -c----w c:\windows\ServicePackFiles\i386\dmcompos.dll
+ 2008-04-14 00:11:52 285,184 -c----w c:\windows\ServicePackFiles\i386\dmdlgs.dll
+ 2008-04-14 00:11:52 200,704 -c----w c:\windows\ServicePackFiles\i386\dmdskmgr.dll
+ 2008-04-14 00:11:52 181,248 -c----w c:\windows\ServicePackFiles\i386\dmime.dll
+ 2008-04-13 18:44:46 153,344 -c----w c:\windows\ServicePackFiles\i386\dmio.sys
+ 2008-04-14 00:11:52 35,840 -c----w c:\windows\ServicePackFiles\i386\dmloader.dll
+ 2008-04-14 00:12:17 15,872 -c----w c:\windows\ServicePackFiles\i386\dmremote.exe
+ 2008-04-14 00:11:52 82,432 -c----w c:\windows\ServicePackFiles\i386\dmscript.dll
+ 2008-04-14 00:11:52 23,552 -c----w c:\windows\ServicePackFiles\i386\dmserver.dll
+ 2008-04-14 00:11:52 105,984 -c----w c:\windows\ServicePackFiles\i386\dmstyle.dll
+ 2008-04-14 00:11:52 103,424 -c----w c:\windows\ServicePackFiles\i386\dmsynth.dll
+ 2008-04-14 00:11:52 104,448 -c----w c:\windows\ServicePackFiles\i386\dmusic.dll
+ 2008-04-13 18:45:01 52,864 -c----w c:\windows\ServicePackFiles\i386\dmusic.sys
+ 2008-04-14 00:11:52 52,224 -c----w c:\windows\ServicePackFiles\i386\dmutil.dll
+ 2008-04-14 00:11:52 147,968 -c----w c:\windows\ServicePackFiles\i386\dnsapi.dll
+ 2008-04-14 00:11:52 45,568 -c----w c:\windows\ServicePackFiles\i386\dnsrslvr.dll
+ 2008-04-14 00:11:52 48,128 -c----w c:\windows\ServicePackFiles\i386\docprop2.dll
+ 2004-08-10 19:00:00 53,840 -c----w c:\windows\ServicePackFiles\i386\dosx.exe
+ 2008-04-14 00:11:52 26,112 -c----w c:\windows\ServicePackFiles\i386\dot3api.dll
+ 2008-04-14 00:11:52 57,856 -c----w c:\windows\ServicePackFiles\i386\dot3cfg.dll
+ 2008-04-14 00:11:52 39,936 -c----w c:\windows\ServicePackFiles\i386\dot3clnt.dll
+ 2008-04-14 00:11:52 9,216 -c----w c:\windows\ServicePackFiles\i386\dot3dlg.dll
+ 2008-04-14 00:11:52 56,320 -c----w c:\windows\ServicePackFiles\i386\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 -c----w c:\windows\ServicePackFiles\i386\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 -c----w c:\windows\ServicePackFiles\i386\dot3ui.dll
+ 2008-04-13 18:39:46 206,976 -c----w c:\windows\ServicePackFiles\i386\dot4.sys
+ 2008-04-14 00:11:52 102,912 -c----w c:\windows\ServicePackFiles\i386\dpcdll.dll
+ 2008-04-14 00:12:17 29,696 -c----w c:\windows\ServicePackFiles\i386\dplaysvr.exe
+ 2008-04-14 00:11:52 229,888 -c----w c:\windows\ServicePackFiles\i386\dplayx.dll
+ 2008-04-14 00:11:52 23,552 -c----w c:\windows\ServicePackFiles\i386\dpmodemx.dll
+ 2008-04-14 00:09:19 3,072 -c----w c:\windows\ServicePackFiles\i386\dpnaddr.dll
+ 2008-04-14 00:11:52 375,296 -c----w c:\windows\ServicePackFiles\i386\dpnet.dll
+ 2008-04-14 00:11:52 35,328 -c----w c:\windows\ServicePackFiles\i386\dpnhpast.dll
+ 2008-04-14 00:11:52 60,928 -c----w c:\windows\ServicePackFiles\i386\dpnhupnp.dll
+ 2008-04-14 00:09:20 3,072 -c----w c:\windows\ServicePackFiles\i386\dpnlobby.dll
+ 2008-04-14 00:12:17 17,920 -c----w c:\windows\ServicePackFiles\i386\dpnsvr.exe
+ 2008-04-14 00:11:52 21,504 -c----w c:\windows\ServicePackFiles\i386\dpvacm.dll
+ 2008-04-14 00:11:52 212,480 -c----w c:\windows\ServicePackFiles\i386\dpvoice.dll
+ 2008-04-14 00:12:18 83,456 -c----w c:\windows\ServicePackFiles\i386\dpvsetup.exe
+ 2008-04-14 00:11:52 116,736 -c----w c:\windows\ServicePackFiles\i386\dpvvox.dll
+ 2008-04-14 00:11:52 57,344 -c----w c:\windows\ServicePackFiles\i386\dpwsockx.dll
+ 2008-04-13 18:45:14 60,160 -c----w c:\windows\ServicePackFiles\i386\drmk.sys
+ 2008-04-13 18:45:13 2,944 -c----w c:\windows\ServicePackFiles\i386\drmkaud.sys
+ 2008-04-14 00:11:52 14,336 -c----w c:\windows\ServicePackFiles\i386\drprov.dll
+ 2008-04-14 00:12:18 62,976 -c----w c:\windows\ServicePackFiles\i386\drvqry.exe
+ 2004-08-10 19:00:00 4,656 -c----w c:\windows\ServicePackFiles\i386\ds16gt.dll
+ 2008-04-14 00:11:52 16,384 -c----w c:\windows\ServicePackFiles\i386\ds32gt.dll
+ 2008-04-14 00:11:52 181,248 -c----w c:\windows\ServicePackFiles\i386\dsdmo.dll
+ 2008-04-14 00:11:52 71,680 -c----w c:\windows\ServicePackFiles\i386\dsdmoprp.dll
+ 2008-04-14 00:11:52 92,672 -c----w c:\windows\ServicePackFiles\i386\dskquota.dll
+ 2008-04-14 00:11:52 155,648 -c----w c:\windows\ServicePackFiles\i386\dskquoui.dll
+ 2008-04-14 00:11:52 367,616 -c----w c:\windows\ServicePackFiles\i386\dsound.dll
+ 2008-04-14 00:11:52 1,293,824 -c----w c:\windows\ServicePackFiles\i386\dsound3d.dll
+ 2008-04-14 00:11:52 142,848 -c----w c:\windows\ServicePackFiles\i386\dsprop.dll
+ 2008-04-13 17:09:30 4,096 -c----w c:\windows\ServicePackFiles\i386\dsprpres.dll
+ 2008-04-14 00:11:52 239,104 -c----w c:\windows\ServicePackFiles\i386\dsquery.dll
+ 2008-04-14 00:11:52 51,200 -c----w c:\windows\ServicePackFiles\i386\dssec.dll
+ 2008-04-13 17:37:57 138,752 -c----w c:\windows\ServicePackFiles\i386\dssenh.dll
+ 2008-04-14 00:11:52 113,152 -c----w c:\windows\ServicePackFiles\i386\dsuiext.dll
+ 2008-04-14 00:11:52 19,456 -c----w c:\windows\ServicePackFiles\i386\dswave.dll
+ 2008-04-14 00:12:18 10,752 -c----w c:\windows\ServicePackFiles\i386\dumprep.exe
+ 2008-04-14 00:11:52 304,128 -c----w c:\windows\ServicePackFiles\i386\duser.dll
+ 2008-04-14 00:12:18 17,920 -c----w c:\windows\ServicePackFiles\i386\dvdupgrd.exe
+ 2008-04-14 00:12:18 180,224 -c----w c:\windows\ServicePackFiles\i386\dwwin.exe
+ 2008-04-14 00:11:52 619,008 -c----w c:\windows\ServicePackFiles\i386\dx7vb.dll
+ 2008-04-14 00:11:52 1,227,264 -c----w c:\windows\ServicePackFiles\i386\dx8vb.dll
+ 2008-04-14 00:12:18 1,298,432 -c----w c:\windows\ServicePackFiles\i386\dxdiag.exe
+ 2008-04-14 00:11:52 2,113,536 -c----w c:\windows\ServicePackFiles\i386\dxdiagn.dll
+ 2008-04-13 18:38:29 71,168 -c----w c:\windows\ServicePackFiles\i386\dxg.sys
+ 2008-04-14 00:11:52 357,888 -c----w c:\windows\ServicePackFiles\i386\dxtmsft.dll
+ 2008-04-14 00:11:52 205,312 -c----w c:\windows\ServicePackFiles\i386\dxtrans.dll
+ 2008-04-14 00:11:52 30,720 -c----w c:\windows\ServicePackFiles\i386\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 -c----w c:\windows\ServicePackFiles\i386\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 -c----w c:\windows\ServicePackFiles\i386\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 -c----w c:\windows\ServicePackFiles\i386\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 -c----w c:\windows\ServicePackFiles\i386\eapphost.dll
+ 2008-04-14 00:11:52 40,960 -c----w c:\windows\ServicePackFiles\i386\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 -c----w c:\windows\ServicePackFiles\i386\eapqec.dll
+ 2008-04-14 00:11:52 33,792 -c----w c:\windows\ServicePackFiles\i386\eapsvc.dll
+ 2008-04-14 00:11:52 26,624 -c----w c:\windows\ServicePackFiles\i386\efsadu.dll
+ 2008-04-14 00:11:53 183,296 -c----w c:\windows\ServicePackFiles\i386\els.dll
+ 2008-04-14 00:11:53 20,480 -c----w c:\windows\ServicePackFiles\i386\encapi.dll
+ 2008-04-14 00:11:53 186,880 -c----w c:\windows\ServicePackFiles\i386\encdec.dll
+ 2008-04-13 16:26:02 40,960 -c----w c:\windows\ServicePackFiles\i386\ep9res.dll
+ 2004-07-17 15:39:36 120,320 -c----w c:\windows\ServicePackFiles\i386\epcl5res.dll
+ 2008-04-14 00:11:53 23,040 -c----w c:\windows\ServicePackFiles\i386\ersvc.dll
+ 2008-04-14 00:11:53 246,272 -c----w c:\windows\ServicePackFiles\i386\es.dll
+ 2008-04-14 00:11:53 1,082,368 -c----w c:\windows\ServicePackFiles\i386\esent.dll
+ 2008-04-14 00:11:53 247,808 -c----w c:\windows\ServicePackFiles\i386\esscli.dll
+ 2004-08-04 02:32:28 137,088 -c----w c:\windows\ServicePackFiles\i386\essm2e.sys
+ 2008-04-14 00:12:19 193,024 -c----w c:\windows\ServicePackFiles\i386\eudcedit.exe
+ 2008-04-14 00:12:19 50,688 -c----w c:\windows\ServicePackFiles\i386\evcreate.exe
+ 2008-04-14 00:11:53 56,320 -c----w c:\windows\ServicePackFiles\i386\eventlog.dll
+ 2004-07-20 09:54:06 798,720 -c----w c:\windows\ServicePackFiles\i386\eventlogmessages.dll
+ 2008-04-14 00:11:53 101,888 -c----w c:\windows\ServicePackFiles\i386\evntagnt.dll
+ 2008-04-14 00:12:19 24,064 -c----w c:\windows\ServicePackFiles\i386\evntcmd.exe
+ 2008-04-14 00:11:53 21,504 -c----w c:\windows\ServicePackFiles\i386\evntrprv.dll
+ 2008-04-14 00:12:19 92,160 -c----w c:\windows\ServicePackFiles\i386\evntwin.exe
+ 2008-04-14 00:11:53 45,056 -c----w c:\windows\ServicePackFiles\i386\evtgprov.dll
+ 2008-04-14 00:12:19 82,944 -c----w c:\windows\ServicePackFiles\i386\evtrig.exe
+ 2008-04-14 00:12:19 1,033,728 ------w c:\windows\ServicePackFiles\i386\explorer.exe
+ 2008-04-14 00:11:53 380,445 -c----w c:\windows\ServicePackFiles\i386\expsrv.dll
+ 2008-04-14 00:11:53 14,336 -c----w c:\windows\ServicePackFiles\i386\exstrace.dll
+ 2008-04-14 00:11:53 55,808 -c----w c:\windows\ServicePackFiles\i386\extmgr.dll
+ 2008-04-14 00:12:19 24,064 -c----w c:\windows\ServicePackFiles\i386\extrac32.exe
+ 2008-04-14 00:11:53 125,952 -c----w c:\windows\ServicePackFiles\i386\exts.dll
+ 2008-04-14 00:09:30 7,168 -c----w c:\windows\ServicePackFiles\i386\f3ahvoas.dll
+ 2008-04-13 19:14:29 143,744 -c----w c:\windows\ServicePackFiles\i386\fastfat.sys
+ 2008-04-14 00:11:53 472,064 -c----w c:\windows\ServicePackFiles\i386\fastprox.dll
+ 2008-04-14 00:11:53 80,384 -c----w c:\windows\ServicePackFiles\i386\faultrep.dll
+ 2008-04-14 00:12:20 20,992 -c----w c:\windows\ServicePackFiles\i386\faxpatch.exe
+ 2008-04-13 18:40:25 27,392 -c----w c:\windows\ServicePackFiles\i386\fdc.sys
+ 2008-04-14 00:11:53 124,928 -c----w c:\windows\ServicePackFiles\i386\fde.dll
+ 2008-04-14 00:11:53 73,728 -c----w c:\windows\ServicePackFiles\i386\fdeploy.dll
+ 2008-04-14 00:11:53 21,504 -c----w c:\windows\ServicePackFiles\i386\feclient.dll
+ 2008-04-14 00:11:53 337,920 -c----w c:\windows\ServicePackFiles\i386\filemgmt.dll
+ 2008-04-14 00:12:20 27,136 -c----w c:\windows\ServicePackFiles\i386\findstr.exe
+ 2008-04-13 18:33:28 44,544 -c----w c:\windows\ServicePackFiles\i386\fips.sys
+ 2008-04-14 00:11:53 87,552 -c----w c:\windows\ServicePackFiles\i386\fldrclnr.dll
+ 2008-04-13 18:40:25 20,480 -c----w c:\windows\ServicePackFiles\i386\flpydisk.sys
+ 2008-04-14 00:11:53 16,896 -c----w c:\windows\ServicePackFiles\i386\fltlib.dll
+ 2008-04-14 00:12:20 23,040 -c----w c:\windows\ServicePackFiles\i386\fltmc.exe
+ 2008-04-13 18:32:59 129,792 -c----w c:\windows\ServicePackFiles\i386\fltmgr.sys
+ 2008-04-14 00:11:53 382,976 -c----w c:\windows\ServicePackFiles\i386\fontext.dll
+ 2008-04-14 00:11:53 80,896 -c----w c:\windows\ServicePackFiles\i386\fontsub.dll
+ 2008-04-14 00:12:20 20,992 -c----w c:\windows\ServicePackFiles\i386\fontview.exe
+ 2008-04-14 00:12:20 7,680 -c----w c:\windows\ServicePackFiles\i386\forcedos.exe
+ 2004-08-04 02:31:24 34,173 -c----w c:\windows\ServicePackFiles\i386\forehe.sys
+ 2008-04-14 00:12:42 29,696 -c----w c:\windows\ServicePackFiles\i386\format.com
+ 2008-04-14 00:11:53 32,828 -c----w c:\windows\ServicePackFiles\i386\fp40ext.dll
+ 2008-04-14 00:11:53 184,435 -c----w c:\windows\ServicePackFiles\i386\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 -c----w c:\windows\ServicePackFiles\i386\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 -c----w c:\windows\ServicePackFiles\i386\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 -c----w c:\windows\ServicePackFiles\i386\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 -c----w c:\windows\ServicePackFiles\i386\fp4atxt.dll
+ 2008-04-14 00:11:53 618,605 -c----w c:\windows\ServicePackFiles\i386\fp4autl.dll
+ 2008-04-14 00:11:53 41,020 -c----w c:\windows\ServicePackFiles\i386\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 -c----w c:\windows\ServicePackFiles\i386\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 -c----w c:\windows\ServicePackFiles\i386\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 -c----w c:\windows\ServicePackFiles\i386\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 -c----w c:\windows\ServicePackFiles\i386\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 -c----w c:\windows\ServicePackFiles\i386\fp98swin.exe
+ 2008-04-14 00:12:20 24,632 -c----w c:\windows\ServicePackFiles\i386\fpadmcgi.exe
+ 2008-04-14 00:11:53 20,541 -c----w c:\windows\ServicePackFiles\i386\fpadmdll.dll
+ 2008-04-14 00:12:20 188,494 -c----w c:\windows\ServicePackFiles\i386\fpcount.exe
+ 2008-04-14 00:11:53 94,208 -c----w c:\windows\ServicePackFiles\i386\fpencode.dll
+ 2008-04-14 00:11:53 20,541 -c----w c:\windows\ServicePackFiles\i386\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 -c----w c:\windows\ServicePackFiles\i386\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 -c----w c:\windows\ServicePackFiles\i386\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 -c----w c:\windows\ServicePackFiles\i386\fpremadm.exe
+ 2008-04-14 00:12:20 28,728 -c----w c:\windows\ServicePackFiles\i386\fpsrvadm.exe
+ 2008-04-14 00:09:33 9,344 -c----w c:\windows\ServicePackFiles\i386\framebuf.dll
+ 2008-04-14 00:11:53 185,344 -c----w c:\windows\ServicePackFiles\i386\framedyn.dll
+ 2008-04-14 00:12:20 193,024 -c----w c:\windows\ServicePackFiles\i386\fsquirt.exe
+ 2008-04-14 00:12:20 42,496 -c----w c:\windows\ServicePackFiles\i386\ftp.exe
+ 2008-04-14 00:11:53 6,144 -c----w c:\windows\ServicePackFiles\i386\ftpmib.dll
+ 2008-04-14 00:11:53 125,952 -c----w c:\windows\ServicePackFiles\i386\ftpsv251.dll
+ 2004-07-20 09:54:06 233,472 -c----w c:\windows\ServicePackFiles\i386\fusion.dll
+ 2008-04-14 00:11:53 60,416 -c----w c:\windows\ServicePackFiles\i386\fwcfg.dll
+ 2008-04-14 00:11:53 451,584 -c----w c:\windows\ServicePackFiles\i386\fxsapi.dll
+ 2008-04-14 00:12:21 142,848 -c----w c:\windows\ServicePackFiles\i386\fxsclnt.exe
+ 2008-04-14 00:11:54 72,192 -c----w c:\windows\ServicePackFiles\i386\fxscom.dll
+ 2008-04-14 00:11:54 285,184 -c----w c:\windows\ServicePackFiles\i386\fxscomex.dll
+ 2008-04-14 00:12:21 229,376 -c----w c:\windows\ServicePackFiles\i386\fxscover.exe
+ 2008-04-14 00:11:54 26,624 -c----w c:\windows\ServicePackFiles\i386\fxsdrv.dll
+ 2008-04-14 00:11:54 55,296 -c----w c:\windows\ServicePackFiles\i386\fxsevent.dll
+ 2008-04-14 00:11:54 23,552 -c----w c:\windows\ServicePackFiles\i386\fxsext32.dll
+ 2008-04-14 00:11:54 23,552 -c----w c:\windows\ServicePackFiles\i386\fxsmon.dll
+ 2008-04-14 00:11:54 132,608 -c----w c:\windows\ServicePackFiles\i386\fxsocm.dll
+ 2008-04-14 00:11:54 8,704 -c----w c:\windows\ServicePackFiles\i386\fxsperf.dll
+ 2008-04-14 00:09:33 6,656 -c----w c:\windows\ServicePackFiles\i386\fxsres.dll
+ 2008-04-14 00:11:54 562,176 -c----w c:\windows\ServicePackFiles\i386\fxsst.dll
+ 2008-04-14 00:12:21 267,776 -c----w c:\windows\ServicePackFiles\i386\fxssvc.exe
+ 2008-04-14 00:11:54 246,272 -c----w c:\windows\ServicePackFiles\i386\fxst30.dll
+ 2008-04-14 00:11:54 397,312 -c----w c:\windows\ServicePackFiles\i386\fxstiff.dll
+ 2008-04-14 00:11:54 154,112 -c----w c:\windows\ServicePackFiles\i386\fxsui.dll
+ 2008-04-14 00:11:54 192,512 -c----w c:\windows\ServicePackFiles\i386\fxswzrd.dll
+ 2008-04-14 00:11:54 400,384 -c----w c:\windows\ServicePackFiles\i386\fxsxp32.dll
+ 2008-04-13 18:36:40 46,464 -c----w c:\windows\ServicePackFiles\i386\gagp30kx.sys
+ 2008-04-13 18:45:29 10,624 -c----w c:\windows\ServicePackFiles\i386\gameenum.sys
+ 2008-04-13 18:45:32 59,136 -c----w c:\windows\ServicePackFiles\i386\gckernel.sys
+ 2008-04-14 00:11:54 285,184 -c----w c:\windows\ServicePackFiles\i386\gdi32.dll
+ 2008-04-14 00:12:21 59,904 -c----w c:\windows\ServicePackFiles\i386\getmac.exe
+ 2008-04-14 00:11:54 122,880 -c----w c:\windows\ServicePackFiles\i386\glu32.dll
+ 2008-04-14 00:09:35 566,784 -c----w c:\windows\ServicePackFiles\i386\gpedit.dll
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\ServicePackFiles\i386\gpkcsp.dll
+ 2006-12-31 01:26:44 9,728 -c----w c:\windows\ServicePackFiles\i386\gpkrsrc.dll
+ 2008-04-14 00:12:21 120,832 -c----w c:\windows\ServicePackFiles\i386\gprslt.exe
+ 2008-04-14 00:11:54 199,680 -c----w c:\windows\ServicePackFiles\i386\gptext.dll
+ 2008-04-14 00:12:21 39,424 -c----w c:\windows\ServicePackFiles\i386\grpconv.exe
+ 2008-04-13 18:40:21 28,288 -c----w c:\windows\ServicePackFiles\i386\grserial.sys
+ 2008-04-14 00:11:54 133,120 -c----w c:\windows\ServicePackFiles\i386\guitrn.dll
+ 2008-04-14 00:11:54 115,200 -c----w c:\windows\ServicePackFiles\i386\guitrna.dll
+ 2008-04-14 00:11:54 32,256 -c----w c:\windows\ServicePackFiles\i386\gzip.dll
+ 2008-04-14 00:11:54 57,344 -c----w c:\windows\ServicePackFiles\i386\h323cc.dll
+ 2008-04-14 00:11:54 614,912 -c----w c:\windows\ServicePackFiles\i386\h323msp.dll
+ 2008-04-13 18:31:32 105,344 -c----w c:\windows\ServicePackFiles\i386\hal.dll
+ 2008-04-13 18:31:28 131,840 -c----w c:\windows\ServicePackFiles\i386\halaacpi.dll
+ 2008-04-13 18:31:27 81,152 -c----w c:\windows\ServicePackFiles\i386\halacpi.dll
+ 2008-04-13 18:31:28 150,528 -c----w c:\windows\ServicePackFiles\i386\halapic.dll
+ 2008-04-13 18:31:28 134,400 -c----w c:\windows\ServicePackFiles\i386\halmacpi.dll
+ 2008-04-13 18:31:32 152,576 -c----w c:\windows\ServicePackFiles\i386\halmps.dll
+ 2008-04-13 18:31:31 77,696 -c----w c:\windows\ServicePackFiles\i386\halsp.dll
+ 2008-04-14 00:11:54 7,168 -c----w c:\windows\ServicePackFiles\i386\hccoin.dll
+ 2008-04-13 16:36:05 144,384 -c----w c:\windows\ServicePackFiles\i386\hdaudbus.sys
+ 2008-04-14 00:12:21 15,872 -c----w c:\windows\ServicePackFiles\i386\help.exe
+ 2008-04-14 00:12:21 769,024 -c----w c:\windows\ServicePackFiles\i386\helpctr.exe
+ 2008-04-14 00:12:21 744,448 -c----w c:\windows\ServicePackFiles\i386\helpsvc.exe
+ 2008-04-14 00:12:21 10,752 -c----w c:\windows\ServicePackFiles\i386\hh.exe
+ 2008-04-14 00:11:54 41,472 -c----w c:\windows\ServicePackFiles\i386\hhsetup.dll
+ 2008-04-14 00:11:54 20,992 -c----w c:\windows\ServicePackFiles\i386\hid.dll
+ 2008-04-13 18:36:38 20,352 -c----w c:\windows\ServicePackFiles\i386\hidbatt.sys
+ 2008-04-13 18:46:30 25,600 -c----w c:\windows\ServicePackFiles\i386\hidbth.sys
+ 2008-04-13 18:45:26 36,864 -c----w c:\windows\ServicePackFiles\i386\hidclass.sys
+ 2008-04-13 18:45:26 19,200 -c----w c:\windows\ServicePackFiles\i386\hidir.sys
+ 2008-04-13 18:45:22 24,960 -c----w c:\windows\ServicePackFiles\i386\hidparse.sys
+ 2008-04-14 00:11:54 21,504 -c----w c:\windows\ServicePackFiles\i386\hidserv.dll
+ 2008-04-13 18:45:27 10,368 -c----w c:\windows\ServicePackFiles\i386\hidusb.sys
+ 2008-04-14 00:11:54 72,704 -c----w c:\windows\ServicePackFiles\i386\hlink.dll
+ 2008-04-14 00:11:54 38,912 -c----w c:\windows\ServicePackFiles\i386\hmmapi.dll
+ 2008-04-14 00:11:54 344,064 -c----w c:\windows\ServicePackFiles\i386\hnetcfg.dll
+ 2008-04-14 00:11:54 330,752 -c----w c:\windows\ServicePackFiles\i386\hnetwiz.dll
+ 2008-04-14 00:11:54 39,936 -c----w c:\windows\ServicePackFiles\i386\hostmib.dll
+ 2008-04-14 00:11:54 144,896 -c----w c:\windows\ServicePackFiles\i386\hotplug.dll
+ 2008-04-14 00:11:54 10,752 -c----w c:\windows\ServicePackFiles\i386\hpcjrr.dll
+ 2008-04-14 00:11:54 10,240 -c----w c:\windows\ServicePackFiles\i386\hpcjrrps.dll
+ 2008-04-14 00:11:54 87,552 -c----w c:\windows\ServicePackFiles\i386\hpfud50.dll
+ 2008-04-14 00:12:21 18,432 -c----w c:\windows\ServicePackFiles\i386\hscupd.exe
+ 2004-08-04 02:41:48 220,032 -c----w c:\windows\ServicePackFiles\i386\hsfbs2s2.sys
+ 2008-04-14 00:11:54 32,285 -c----w c:\windows\ServicePackFiles\i386\hsfcisp2.dll
+ 2004-08-04 02:41:50 685,056 -c----w c:\windows\ServicePackFiles\i386\hsfcxts2.sys
+ 2004-08-04 02:41:56 1,041,536 -c----w c:\windows\ServicePackFiles\i386\hsfdpsp2.sys
+ 2008-04-13 18:53:53 264,832 -c----w c:\windows\ServicePackFiles\i386\http.sys
+ 2008-04-14 00:11:54 24,576 -c----w c:\windows\ServicePackFiles\i386\httpapi.dll
+ 2008-04-14 00:11:54 268,288 -c----w c:\windows\ServicePackFiles\i386\httpext.dll
+ 2008-04-14 00:11:54 8,192 -c----w c:\windows\ServicePackFiles\i386\httpmb51.dll
+ 2008-04-14 00:11:54 61,440 -c----w c:\windows\ServicePackFiles\i386\httpod51.dll
+ 2008-04-14 00:11:54 41,984 -c----w c:\windows\ServicePackFiles\i386\htui.dll
+ 2008-04-14 00:11:54 347,136 -c----w c:\windows\ServicePackFiles\i386\hypertrm.dll
+ 2008-04-13 18:41:22 8,576 -c----w c:\windows\ServicePackFiles\i386\i2omgmt.sys
+ 2008-04-13 18:41:22 18,560 -c----w c:\windows\ServicePackFiles\i386\i2omp.sys
+ 2008-04-13 19:18:00 52,480 -c----w c:\windows\ServicePackFiles\i386\i8042prt.sys
+ 2008-04-14 00:11:54 702,845 -c----w c:\windows\ServicePackFiles\i386\i81xdnt5.dll
+ 2004-08-04 02:29:38 161,020 -c----w c:\windows\ServicePackFiles\i386\i81xnt5.sys
+ 2008-04-14 00:11:54 119,808 -c----w c:\windows\ServicePackFiles\i386\iasrad.dll
+ 2008-04-14 00:11:54 11,264 -c----w c:\windows\ServicePackFiles\i386\icaapi.dll
+ 2008-04-14 00:11:54 80,384 -c----w c:\windows\ServicePackFiles\i386\iccvid.dll
+ 2008-04-14 00:11:54 254,976 -c----w c:\windows\ServicePackFiles\i386\icm32.dll
+ 2008-04-14 00:09:40 3,584 -c----w c:\windows\ServicePackFiles\i386\icmp.dll
+ 2008-04-13 16:44:29 2,560 -c----w c:\windows\ServicePackFiles\i386\iconlib.dll
+ 2008-04-14 00:11:54 61,440 -c----w c:\windows\ServicePackFiles\i386\icwconn.dll
+ 2008-04-14 00:12:22 214,528 -c----w c:\windows\ServicePackFiles\i386\icwconn1.exe
+ 2008-04-14 00:12:22 86,016 -c----w c:\windows\ServicePackFiles\i386\icwconn2.exe
+ 2008-04-14 00:11:54 73,728 -c----w c:\windows\ServicePackFiles\i386\icwdial.dll
+ 2008-04-14 00:11:54 32,768 -c----w c:\windows\ServicePackFiles\i386\icwdl.dll
+ 2008-04-14 00:11:54 172,032 -c----w c:\windows\ServicePackFiles\i386\icwhelp.dll
+ 2008-04-14 00:11:54 65,536 -c----w c:\windows\ServicePackFiles\i386\icwphbk.dll
+ 2008-04-14 00:12:22 24,576 -c----w c:\windows\ServicePackFiles\i386\icwrmind.exe
+ 2008-04-14 00:11:54 49,152 -c----w c:\windows\ServicePackFiles\i386\icwutil.dll
+ 2008-04-14 00:11:54 120,832 -c----w c:\windows\ServicePackFiles\i386\idq.dll
+ 2008-04-14 00:12:22 34,304 -c----w c:\windows\ServicePackFiles\i386\ie4uinit.exe
+ 2008-04-14 00:11:54 143,360 -c----w c:\windows\ServicePackFiles\i386\ieakeng.dll
+ 2008-04-14 00:11:54 216,576 -c----w c:\windows\ServicePackFiles\i386\ieaksie.dll
+ 2008-04-14 00:11:54 323,584 -c----w c:\windows\ServicePackFiles\i386\iedkcs32.dll
+ 2008-04-14 00:12:22 18,432 -c----w c:\windows\ServicePackFiles\i386\iedw.exe
+ 2008-04-14 00:11:54 81,920 -c----w c:\windows\ServicePackFiles\i386\ieencode.dll
+ 2007-01-02 21:29:28 8,192 -c----w c:\windows\ServicePackFiles\i386\ieexec.exe
+ 2004-07-20 09:54:06 7,168 -c----w c:\windows\ServicePackFiles\i386\ieexecremote.dll
+ 2004-07-20 09:54:06 32,768 -c----w c:\windows\ServicePackFiles\i386\iehost.dll
+ 2008-04-14 00:11:54 251,904 -c----w c:\windows\ServicePackFiles\i386\iepeers.dll
+ 2008-04-14 00:11:54 48,640 -c----w c:\windows\ServicePackFiles\i386\iernonce.dll
+ 2008-04-14 00:11:54 62,976 -c----w c:\windows\ServicePackFiles\i386\iesetup.dll
+ 2008-04-14 00:12:22 93,184 -c----w c:\windows\ServicePackFiles\i386\iexplore.exe
+ 2008-04-14 00:12:22 114,688 -c----w c:\windows\ServicePackFiles\i386\iexpress.exe
+ 2008-04-14 00:11:54 135,680 -c----w c:\windows\ServicePackFiles\i386\ifmon.dll
+ 2008-04-14 00:11:54 8,192 -c----w c:\windows\ServicePackFiles\i386\igmpagnt.dll
+ 2008-04-14 00:11:54 505,344 -c----w c:\windows\ServicePackFiles\i386\iis.dll
+ 2008-04-14 00:11:54 25,088 -c----w c:\windows\ServicePackFiles\i386\iisadmin.dll
+ 2008-04-14 00:11:54 145,408 -c----w c:\windows\ServicePackFiles\i386\iische51.dll
+ 2008-04-14 00:11:54 68,608 -c----w c:\windows\ServicePackFiles\i386\iisext51.dll
+ 2008-04-14 00:11:54 7,168 -c----w c:\windows\ServicePackFiles\i386\iisfecnv.dll
+ 2008-04-14 00:11:54 79,872 -c----w c:\windows\ServicePackFiles\i386\iislog51.dll
+ 2008-04-14 00:11:54 64,512 -c----w c:\windows\ServicePackFiles\i386\iismap.dll
+ 2008-04-14 00:12:22 30,720 -c----w c:\windows\ServicePackFiles\i386\iisrstas.exe
+ 2008-04-14 00:11:54 133,632 -c----w c:\windows\ServicePackFiles\i386\iisrtl.dll
+ 2004-08-04 13:11:48 184,320 -c----w c:\windows\ServicePackFiles\i386\ilasm.exe
+ 2008-04-14 00:11:54 81,920 -c----w c:\windows\ServicePackFiles\i386\ils.dll
+ 2008-04-14 00:11:54 144,384 -c----w c:\windows\ServicePackFiles\i386\imagehlp.dll
+ 2008-04-14 00:12:22 150,528 -c----w c:\windows\ServicePackFiles\i386\imapi.exe
+ 2008-04-13 18:40:58 42,112 -c----w c:\windows\ServicePackFiles\i386\imapi.sys
+ 2008-04-14 00:11:54 36,921 -c----w c:\windows\ServicePackFiles\i386\imeshare.dll
+ 2008-04-14 00:11:54 35,840 -c----w c:\windows\ServicePackFiles\i386\imgutil.dll
+ 2008-04-14 00:11:54 110,080 -c----w c:\windows\ServicePackFiles\i386\imm32.dll
+ 2008-04-14 00:11:54 123,392 -c----w c:\windows\ServicePackFiles\i386\imsinsnt.dll
+ 2008-04-14 00:11:54 274,432 -c----w c:\windows\ServicePackFiles\i386\inetcfg.dll
+ 2008-04-14 00:11:54 691,712 -c----w c:\windows\ServicePackFiles\i386\inetcomm.dll
+ 2008-04-14 00:12:22 15,360 -c----w c:\windows\ServicePackFiles\i386\inetin51.exe
+ 2008-04-14 00:11:55 829,440 -c----w c:\windows\ServicePackFiles\i386\inetmgr.dll
+ 2008-04-14 00:11:55 32,768 -c----w c:\windows\ServicePackFiles\i386\inetmib1.dll
+ 2008-04-14 00:11:55 75,264 -c----w c:\windows\ServicePackFiles\i386\inetpp.dll
+ 2008-04-14 00:11:55 15,872 -c----w c:\windows\ServicePackFiles\i386\inetppui.dll
+ 2008-04-13 16:22:12 48,128 -c----w c:\windows\ServicePackFiles\i386\inetres.dll
+ 2008-04-14 00:12:22 20,480 -c----w c:\windows\ServicePackFiles\i386\inetwiz.exe
+ 2008-04-14 00:11:55 13,312 -c----w c:\windows\ServicePackFiles\i386\infoadmn.dll
+ 2008-04-14 00:11:55 257,024 -c----w c:\windows\ServicePackFiles\i386\infocomm.dll
+ 2008-04-14 00:11:55 147,456 -c----w c:\windows\ServicePackFiles\i386\initpki.dll
+ 2008-04-14 00:11:55 123,392 -c----w c:\windows\ServicePackFiles\i386\input.dll
+ 2008-04-14 00:11:55 96,256 -c----w c:\windows\ServicePackFiles\i386\inseng.dll
+ 2004-07-20 09:54:06 24,576 -c----w c:\windows\ServicePackFiles\i386\installutil.exe
+ 2008-04-13 18:40:29 5,504 -c----w c:\windows\ServicePackFiles\i386\intelide.sys
+ 2008-04-13 18:31:32 36,352 -c----w c:\windows\ServicePackFiles\i386\intelppm.sys
+ 2008-04-13 18:53:34 36,608 -c----w c:\windows\ServicePackFiles\i386\ip6fw.sys
+ 2008-04-14 00:12:22 55,808 -c----w c:\windows\ServicePackFiles\i386\ipconfig.exe
+ 2008-04-14 00:09:30 103,424 -c----w c:\windows\ServicePackFiles\i386\ipevldpc.dll
+ 2008-04-14 00:09:23 24,064 -c----w c:\windows\ServicePackFiles\i386\ipevlpid.dll
+ 2008-04-14 00:11:55 94,720 -c----w c:\windows\ServicePackFiles\i386\iphlpapi.dll
+ 2008-04-13 18:57:07 20,864 -c----w c:\windows\ServicePackFiles\i386\ipinip.sys
+ 2008-04-14 00:11:55 161,280 -c----w c:\windows\ServicePackFiles\i386\ipmontr.dll
+ 2008-04-13 18:57:15 152,832 -c----w c:\windows\ServicePackFiles\i386\ipnat.sys
+ 2008-04-14 00:11:55 331,264 -c----w c:\windows\ServicePackFiles\i386\ipnathlp.dll
+ 2008-04-14 00:11:55 330,752 -c----w c:\windows\ServicePackFiles\i386\ippromon.dll
+ 2008-04-14 00:11:55 35,328 -c----w c:\windows\ServicePackFiles\i386\iprip.dll
+ 2008-04-14 00:11:55 177,152 -c----w c:\windows\ServicePackFiles\i386\iprtrmgr.dll
+ 2008-04-13 19:19:42 75,264 -c----w c:\windows\ServicePackFiles\i386\ipsec.sys
+ 2008-04-14 00:11:55 349,696 -c----w c:\windows\ServicePackFiles\i386\ipsecsnp.dll
+ 2008-04-14 00:11:55 183,808 -c----w c:\windows\ServicePackFiles\i386\ipsecsvc.dll
+ 2008-04-14 00:10:45 102,912 -c----w c:\windows\ServicePackFiles\i386\ipseldpc.dll
+ 2008-04-14 00:09:24 24,064 -c----w c:\windows\ServicePackFiles\i386\ipselpid.dll
+ 2008-04-14 00:11:55 384,000 -c----w c:\windows\ServicePackFiles\i386\ipsmsnap.dll
+ 2008-04-14 00:12:23 53,248 -c----w c:\windows\ServicePackFiles\i386\ipv6.exe
+ 2008-04-14 00:11:55 59,904 -c----w c:\windows\ServicePackFiles\i386\ipv6mon.dll
+ 2008-04-14 00:12:23 23,552 -c----w c:\windows\ServicePackFiles\i386\ipxroute.exe
+ 2008-04-14 00:11:55 22,016 -c----w c:\windows\ServicePackFiles\i386\ipxwan.dll
+ 2008-04-14 00:11:55 120,320 -c----w c:\windows\ServicePackFiles\i386\ir41_qc.dll
+ 2008-04-14 00:11:55 338,432 -c----w c:\windows\ServicePackFiles\i386\ir41_qcx.dll
+ 2008-04-14 00:11:55 755,200 -c----w c:\windows\ServicePackFiles\i386\ir50_32.dll
+ 2008-04-14 00:11:55 200,192 -c----w c:\windows\ServicePackFiles\i386\ir50_qc.dll
+ 2008-04-14 00:11:55 183,808 -c----w c:\windows\ServicePackFiles\i386\ir50_qcx.dll
+ 2008-04-13 18:45:34 46,592 -c----w c:\windows\ServicePackFiles\i386\irbus.sys
+ 2008-04-13 18:54:36 88,192 -c----w c:\windows\ServicePackFiles\i386\irda.sys
+ 2008-04-13 18:54:28 11,264 -c----w c:\windows\ServicePackFiles\i386\irenum.sys
+ 2008-04-14 00:12:23 151,552 -c----w c:\windows\ServicePackFiles\i386\irftp.exe
+ 2008-04-14 00:11:55 28,160 -c----w c:\windows\ServicePackFiles\i386\irmon.dll
+ 2008-04-13 18:36:41 37,248 -c----w c:\windows\ServicePackFiles\i386\isapnp.sys
+ 2008-04-14 00:11:55 68,608 -c----w c:\windows\ServicePackFiles\i386\isatq.dll
+ 2008-04-14 00:11:55 26,624 -c----w c:\windows\ServicePackFiles\i386\iscomlog.dll
+ 2008-04-14 00:10:32 105,984 -c----w c:\windows\ServicePackFiles\i386\isdpc.dll
+ 2008-04-14 00:10:55 105,984 -c----w c:\windows\ServicePackFiles\i386\isendpc.dll
+ 2008-04-14 00:10:55 24,064 -c----w c:\windows\ServicePackFiles\i386\isenpid.dll
+ 2008-04-14 00:11:55 81,920 -c----w c:\windows\ServicePackFiles\i386\isign32.dll
+ 2008-04-14 00:10:32 24,064 -c----w c:\windows\ServicePackFiles\i386\ispid.dll
+ 2008-04-14 00:11:55 32,768 -c----w c:\windows\ServicePackFiles\i386\isrdbg32.dll
+ 2008-04-14 00:11:55 155,136 -c----w c:\windows\ServicePackFiles\i386\itircl.dll
+ 2008-04-14 00:11:55 138,240 -c----w c:\windows\ServicePackFiles\i386\itss.dll
+ 2008-04-14 00:11:55 191,488 -c----w c:\windows\ServicePackFiles\i386\iuengine.dll
+ 2008-04-14 00:11:55 54,272 -c----w c:\windows\ServicePackFiles\i386\ixsso.dll
+ 2008-04-14 00:11:55 47,616 -c----w c:\windows\ServicePackFiles\i386\iyuv_32.dll
+ 2008-04-14 00:11:55 163,840 -c----w c:\windows\ServicePackFiles\i386\jgdw400.dll
+ 2008-04-14 00:11:55 27,648 -c----w c:\windows\ServicePackFiles\i386\jgpl400.dll
+ 2004-07-20 09:54:06 40,960 -c----w c:\windows\ServicePackFiles\i386\jsc.exe
+ 2008-04-14 00:11:56 512,000 -c----w c:\windows\ServicePackFiles\i386\jscript.dll
+ 2008-04-14 00:11:56 15,872 -c----w c:\windows\ServicePackFiles\i386\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbd101.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbd106.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbd106n.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdax2.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdbhc.dll
+ 2008-04-13 18:39:47 24,576 -c----w c:\windows\ServicePackFiles\i386\kbdclass.sys
+ 2008-04-14 00:09:55 7,168 -c----w c:\windows\ServicePackFiles\i386\kbdfi1.dll
+ 2008-04-13 18:39:48 14,592 -c----w c:\windows\ServicePackFiles\i386\kbdhid.sys
+ 2008-04-14 00:09:55 7,168 -c----w c:\windows\ServicePackFiles\i386\kbdibm02.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdinben.dll
+ 2008-04-14 00:09:55 6,656 -c----w c:\windows\ServicePackFiles\i386\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdiultn.dll
+ 2008-04-14 00:09:55 6,656 -c----w c:\windows\ServicePackFiles\i386\kbdlk41a.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdlk41j.dll
+ 2008-04-14 00:09:55 5,632 -c----w c:\windows\ServicePackFiles\i386\kbdmaori.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdmlt48.dll
+ 2008-04-14 00:09:55 7,168 -c----w c:\windows\ServicePackFiles\i386\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdnepr.dll
+ 2008-04-14 00:09:55 7,168 -c----w c:\windows\ServicePackFiles\i386\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 -c----w c:\windows\ServicePackFiles\i386\kbdpash.dll
+ 2008-04-14 00:09:55 7,680 -c----w c:\windows\ServicePackFiles\i386\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 -c----w c:\windows\ServicePackFiles\i386\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,168 -c----w c:\windows\ServicePackFiles\i386\kbdukx.dll
+ 2008-04-13 18:31:35 7,424 -c----w c:\windows\ServicePackFiles\i386\kd1394.dll
+ 2008-04-14 00:11:56 184,832 -c----w c:\windows\ServicePackFiles\i386\kdcsvc.dll
+ 2008-04-14 00:11:56 48,640 -c----w c:\windows\ServicePackFiles\i386\kdsui.dll
+ 2008-04-14 00:11:56 253,952 -c----w c:\windows\ServicePackFiles\i386\kdsusd.dll
+ 2008-04-14 00:11:56 299,520 -c----w c:\windows\ServicePackFiles\i386\kerberos.dll
+ 2008-04-14 00:11:56 989,696 -c----w c:\windows\ServicePackFiles\i386\kernel32.dll
+ 2004-08-10 19:00:00 42,537 -c----w c:\windows\ServicePackFiles\i386\keyboard.sys
+ 2008-04-14 00:11:56 150,528 -c----w c:\windows\ServicePackFiles\i386\keymgr.dll
+ 2008-04-13 18:45:09 172,416 -c----w c:\windows\ServicePackFiles\i386\kmixer.sys
+ 2008-04-14 00:11:56 61,440 -c----w c:\windows\ServicePackFiles\i386\kmsvc.dll
+ 2008-04-14 00:09:56 102,912 -c----w c:\windows\ServicePackFiles\i386\knperdpc.dll
+ 2008-04-14 00:09:56 24,064 -c----w c:\windows\ServicePackFiles\i386\knperpid.dll
+ 2008-04-14 00:09:56 102,912 -c----w c:\windows\ServicePackFiles\i386\knprodpc.dll
+ 2008-04-14 00:09:56 24,576 -c----w c:\windows\ServicePackFiles\i386\knpropid.dll
+ 2008-04-14 00:11:56 8,192 -c----w c:\windows\ServicePackFiles\i386\koc.dll
+ 2008-04-14 00:09:56 102,912 -c----w c:\windows\ServicePackFiles\i386\kperdpc.dll
+ 2008-04-14 00:09:56 24,064 -c----w c:\windows\ServicePackFiles\i386\kperpid.dll
+ 2008-04-14 00:09:56 102,912 -c----w c:\windows\ServicePackFiles\i386\kprodpc.dll
+ 2008-04-14 00:09:56 24,576 -c----w c:\windows\ServicePackFiles\i386\kpropid.dll
+ 2004-08-10 19:00:00 92,224 -c----w c:\windows\ServicePackFiles\i386\krnl386.exe
+ 2008-04-14 00:11:56 24,576 -c----w c:\windows\ServicePackFiles\i386\krnlprov.dll
+ 2008-04-13 19:16:36 141,056 -c----w c:\windows\ServicePackFiles\i386\ks.sys
+ 2008-04-13 18:31:43 92,288 -c----w c:\windows\ServicePackFiles\i386\ksecdd.sys
+ 2008-04-14 00:11:56 4,096 -c----w c:\windows\ServicePackFiles\i386\ksuser.dll
+ 2008-04-14 00:11:56 37,376 -c----w c:\windows\ServicePackFiles\i386\l2store.dll
+ 2008-04-14 00:09:05 97,792 -c----w c:\windows\ServicePackFiles\i386\lang\chtmbx.dll
+ 2008-04-14 00:09:05 56,320 -c----w c:\windows\ServicePackFiles\i386\lang\chtskdic.dll
+ 2008-04-14 00:09:05 173,568 -c----w c:\windows\ServicePackFiles\i386\lang\chtskf.dll
+ 2008-04-14 00:09:06 198,656 -c----w c:\windows\ServicePackFiles\i386\lang\cintime.dll
+ 2004-08-04 02:31:56 480,256 -c----w c:\windows\ServicePackFiles\i386\lang\cintsetp.exe
+ 2004-08-04 02:31:40 57,399 -c----w c:\windows\ServicePackFiles\i386\lang\cplexe.exe
+ 2008-04-14 00:09:39 13,463,552 -c----w c:\windows\ServicePackFiles\i386\lang\hwxjpn.dll
+ 2008-04-14 00:09:43 106,496 -c----w c:\windows\ServicePackFiles\i386\lang\imekrcic.dll
+ 2008-04-14 00:09:43 86,016 -c----w c:\windows\ServicePackFiles\i386\lang\imekrmbx.dll
+ 2008-04-14 00:09:44 811,064 -c----w c:\windows\ServicePackFiles\i386\lang\imjp81k.dll
+ 2008-04-14 00:09:45 368,696 -c----w c:\windows\ServicePackFiles\i386\lang\imjpcic.dll
+ 2008-04-14 00:09:45 716,856 -c----w c:\windows\ServicePackFiles\i386\lang\imjpcus.dll
+ 2008-04-14 00:09:45 81,976 -c----w c:\windows\ServicePackFiles\i386\lang\imjpdct.dll
+ 2004-08-04 02:31:54 307,257 -c----w c:\windows\ServicePackFiles\i386\lang\imjpdct.exe
+ 2004-08-04 02:31:56 155,705 -c----w c:\windows\ServicePackFiles\i386\lang\imjpdsvr.exe
+ 2004-08-04 02:31:58 196,665 -c----w c:\windows\ServicePackFiles\i386\lang\imjpinst.exe
+ 2004-08-04 02:32:00 208,952 -c----w c:\windows\ServicePackFiles\i386\lang\imjpmig.exe
+ 2004-08-04 02:32:12 233,527 -c----w c:\windows\ServicePackFiles\i386\lang\imjprw.exe
+ 2004-08-04 02:32:16 262,200 -c----w c:\windows\ServicePackFiles\i386\lang\imjputy.exe
+ 2008-04-14 00:09:46 274,489 -c----w c:\windows\ServicePackFiles\i386\lang\imjputyc.dll
+ 2008-04-14 00:09:46 102,456 -c----w c:\windows\ServicePackFiles\i386\lang\imlang.dll
+ 2004-08-04 02:31:50 59,392 -c----w c:\windows\ServicePackFiles\i386\lang\imscinst.exe
+ 2008-04-14 00:09:47 315,455 -c----w c:\windows\ServicePackFiles\i386\lang\imskf.dll
+ 2008-04-14 00:10:33 15,872 -c----w c:\windows\ServicePackFiles\i386\lang\padrs404.dll
+ 2008-04-14 00:10:33 15,360 -c----w c:\windows\ServicePackFiles\i386\lang\padrs804.dll
+ 2008-04-14 00:10:34 175,104 -c----w c:\windows\ServicePackFiles\i386\lang\pintlcsa.dll
+ 2008-04-14 00:10:34 53,760 -c----w c:\windows\ServicePackFiles\i386\lang\pintlcsd.dll
+ 2008-04-13 16:43:36 70,144 -c----w c:\windows\ServicePackFiles\i386\lang\pintlphr.exe
+ 2008-04-14 00:10:34 67,584 -c----w c:\windows\ServicePackFiles\i386\lang\pmigrate.dll
+ 2004-08-04 02:32:16 44,032 -c----w c:\windows\ServicePackFiles\i386\lang\tintlphr.exe
+ 2004-08-04 02:32:16 455,168 -c----w c:\windows\ServicePackFiles\i386\lang\tintsetp.exe
+ 2008-04-14 00:10:59 10,240 -c----w c:\windows\ServicePackFiles\i386\lang\tmigrate.dll
+ 2008-04-14 00:11:01 76,288 -c----w c:\windows\ServicePackFiles\i386\lang\uniime.dll
+ 2008-04-14 00:11:04 426,041 -c----w c:\windows\ServicePackFiles\i386\lang\voicepad.dll
+ 2008-04-14 00:11:04 86,073 -c----w c:\windows\ServicePackFiles\i386\lang\voicesub.dll
+ 2008-04-13 18:40:26 34,688 -c----w c:\windows\ServicePackFiles\i386\lbrtfdc.sys
+ 2008-04-14 00:12:23 677,888 -c----w c:\windows\ServicePackFiles\i386\lhmstsc.exe
+ 2008-04-14 00:11:56 2,061,824 -c----w c:\windows\ServicePackFiles\i386\lhmstscx.dll
+ 2008-04-14 09:41:58 423,936 -c----w c:\windows\ServicePackFiles\i386\licdll.dll
+ 2008-04-14 00:11:56 22,016 -c----w c:\windows\ServicePackFiles\i386\licmgr10.dll
+ 2008-04-14 00:11:56 58,880 -c----w c:\windows\ServicePackFiles\i386\licwmi.dll
+ 2008-04-14 00:11:56 19,968 -c----w c:\windows\ServicePackFiles\i386\linkinfo.dll
+ 2008-04-14 00:11:56 13,824 -c----w c:\windows\ServicePackFiles\i386\lmhsvc.dll
+ 2008-04-14 00:11:56 33,792 -c----w c:\windows\ServicePackFiles\i386\lmmib2.dll
+ 2008-04-14 00:11:56 399,872 -c----w c:\windows\ServicePackFiles\i386\lmrt.dll
+ 2008-04-14 00:11:56 97,280 -c----w c:\windows\ServicePackFiles\i386\loadperf.dll
+ 2008-04-14 00:11:56 221,696 -c----w c:\windows\ServicePackFiles\i386\localsec.dll
+ 2008-04-14 00:11:56 343,040 -c----w c:\windows\ServicePackFiles\i386\localspl.dll
+ 2008-04-14 00:11:56 11,776 -c----w c:\windows\ServicePackFiles\i386\localui.dll
+ 2008-04-14 00:12:24 75,264 -c----w c:\windows\ServicePackFiles\i386\locator.exe
+ 2008-04-14 00:11:56 19,968 -c----w c:\windows\ServicePackFiles\i386\log.dll
+ 2008-04-14 00:12:24 59,392 -c----w c:\windows\ServicePackFiles\i386\logman.exe
+ 2008-04-14 00:12:43 220,672 -c----w c:\windows\ServicePackFiles\i386\logon.scr
+ 2008-04-14 00:12:24 514,560 -c----w c:\windows\ServicePackFiles\i386\logonui.exe
+ 2008-04-14 00:11:56 13,312 -c----w c:\windows\ServicePackFiles\i386\lonsint.dll
+ 2008-04-14 00:11:56 22,528 -c----w c:\windows\ServicePackFiles\i386\lpdsvc.dll
+ 2008-04-14 00:11:56 22,016 -c----w c:\windows\ServicePackFiles\i386\lpk.dll
+ 2008-04-14 00:11:56 10,240 -c----w c:\windows\ServicePackFiles\i386\lprhelp.dll
+ 2008-04-14 00:11:56 18,944 -c----w c:\windows\ServicePackFiles\i386\lprmon.dll
+ 2008-04-14 00:11:56 728,064 -c----w c:\windows\ServicePackFiles\i386\lsasrv.dll
+ 2008-04-14 00:12:24 13,312 -c----w c:\windows\ServicePackFiles\i386\lsass.exe
+ 2004-08-04 02:41:36 606,684 -c----w c:\windows\ServicePackFiles\i386\ltmdmnt.sys
+ 2004-08-04 02:41:38 420,992 -c----w c:\windows\ServicePackFiles\i386\ltmdmntt.sys
+ 2008-04-13 18:40:52 7,040 -c----w c:\windows\ServicePackFiles\i386\ltotape.sys
+ 2004-08-04 02:39:32 20,864 -c----w c:\windows\ServicePackFiles\i386\lwadihid.sys
+ 2008-04-14 00:12:24 72,704 -c----w c:\windows\ServicePackFiles\i386\magnify.exe
+ 2008-04-14 00:12:25 57,344 -c----w c:\windows\ServicePackFiles\i386\makecab.exe
+ 2008-04-14 00:11:56 14,336 -c----w c:\windows\ServicePackFiles\i386\mcastmib.dll
+ 2008-04-14 00:11:56 84,480 -c----w c:\windows\ServicePackFiles\i386\mciavi32.dll
+ 2008-04-14 00:11:56 35,328 -c----w c:\windows\ServicePackFiles\i386\mciqtz32.dll
+ 2008-04-14 00:11:56 23,040 -c----w c:\windows\ServicePackFiles\i386\mciseq.dll
+ 2008-04-14 00:11:56 23,552 -c----w c:\windows\ServicePackFiles\i386\mciwave.dll
+ 2008-04-14 00:11:56 37,888 -c----w c:\windows\ServicePackFiles\i386\md5filt.dll
+ 2008-04-14 00:11:56 118,272 -c----w c:\windows\ServicePackFiles\i386\mdminst.dll
+ 2008-04-14 00:11:56 86,016 -c----w c:\windows\ServicePackFiles\i386\mdmxsdk.dll
+ 2004-08-04 02:41:56 11,868 -c----w c:\windows\ServicePackFiles\i386\mdmxsdk.sys
+ 2008-04-14 00:11:56 16,896 -c----w c:\windows\ServicePackFiles\i386\medctroc.dll
+ 2008-04-13 18:41:21 26,112 -c----w c:\windows\ServicePackFiles\i386\memstpci.sys
+ 2008-04-14 00:11:56 85,504 -c----w c:\windows\ServicePackFiles\i386\metada51.dll
+ 2008-04-13 18:36:41 63,744 -c----w c:\windows\ServicePackFiles\i386\mf.sys
+ 2008-04-14 00:11:56 40,960 -c----w c:\windows\ServicePackFiles\i386\mf3216.dll
+ 2008-04-14 00:11:56 927,504 -c----w c:\windows\ServicePackFiles\i386\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 -c----w c:\windows\ServicePackFiles\i386\mfc42.dll
+ 2006-10-14 08:13:25 981,760 -c----w c:\windows\ServicePackFiles\i386\mfc42u.dll
+ 2008-04-14 00:11:56 22,528 -c----w c:\windows\ServicePackFiles\i386\mfcsubs.dll
+ 2008-04-14 00:11:56 14,848 -c----w c:\windows\ServicePackFiles\i386\mgmtapi.dll
+ 2004-07-20 09:54:06 712,704 -c----w c:\windows\ServicePackFiles\i386\microsoft.jscript.dll
+ 2004-07-20 09:54:06 286,720 -c----w c:\windows\ServicePackFiles\i386\microsoft.visualbasic.dll
+ 2008-04-14 00:11:57 18,944 -c----w c:\windows\ServicePackFiles\i386\midimap.dll
+ 2008-04-14 00:11:57 274,432 -c----w c:\windows\ServicePackFiles\i386\migism.dll
+ 2008-04-14 00:11:57 261,120 -c----w c:\windows\ServicePackFiles\i386\migisma.dll
+ 2008-04-14 00:11:57 60,928 -c----w c:\windows\ServicePackFiles\i386\miglibnt.dll
+ 2008-04-14 00:12:25 103,936 -c----w c:\windows\ServicePackFiles\i386\migload.exe
+ 2008-04-14 00:12:25 7,680 -c----w c:\windows\ServicePackFiles\i386\migregdb.exe
+ 2008-04-14 00:12:25 245,248 -c----w c:\windows\ServicePackFiles\i386\migwiz.exe
+ 2008-04-14 00:12:25 241,152 -c----w c:\windows\ServicePackFiles\i386\migwiza.exe
+ 2008-04-14 00:11:57 29,696 -c----w c:\windows\ServicePackFiles\i386\mimefilt.dll
+ 2008-04-14 00:11:57 586,240 -c----w c:\windows\ServicePackFiles\i386\mlang.dll
+ 2008-04-14 00:12:25 1,414,656 -c----w c:\windows\ServicePackFiles\i386\mmc.exe
+ 2008-04-14 00:11:57 184,320 -c----w c:\windows\ServicePackFiles\i386\mmc30.dll
+ 2008-04-14 00:11:57 28,672 -c----w c:\windows\ServicePackFiles\i386\mmc30r.dll
+ 2008-04-14 00:11:57 163,328 -c----w c:\windows\ServicePackFiles\i386\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 -c----w c:\windows\ServicePackFiles\i386\mmcex.dll
+ 2008-04-14 00:11:57 40,960 -c----w c:\windows\ServicePackFiles\i386\mmcexr.dll
+ 2008-04-14 00:11:57 106,496 -c----w c:\windows\ServicePackFiles\i386\mmcfxc.dll
+ 2008-04-14 00:11:57 6,656 -c----w c:\windows\ServicePackFiles\i386\mmcfxcr.dll
+ 2008-04-14 00:11:57 1,872,896 -c----w c:\windows\ServicePackFiles\i386\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 -c----w c:\windows\ServicePackFiles\i386\mmcperf.exe
+ 2008-04-14 00:11:57 61,440 -c----w c:\windows\ServicePackFiles\i386\mmcshext.dll
+ 2008-04-14 00:11:57 17,408 -c----w c:\windows\ServicePackFiles\i386\mmfutil.dll
+ 2004-08-10 19:00:00 68,768 -c----w c:\windows\ServicePackFiles\i386\mmsystem.dll
+ 2008-04-14 00:11:57 34,560 -c----w c:\windows\ServicePackFiles\i386\mnmdd.dll
+ 2008-04-14 00:12:25 32,768 -c----w c:\windows\ServicePackFiles\i386\mnmsrvc.exe
+ 2008-04-14 00:11:57 207,360 -c----w c:\windows\ServicePackFiles\i386\mobsync.dll
+ 2008-04-14 00:12:26 143,360 -c----w c:\windows\ServicePackFiles\i386\mobsync.exe
+ 2008-04-13 19:00:19 30,080 -c----w c:\windows\ServicePackFiles\i386\modem.sys
+ 2008-04-14 00:11:57 153,600 -c----w c:\windows\ServicePackFiles\i386\modemui.dll
+ 2008-04-14 00:12:26 16,384 -c----w c:\windows\ServicePackFiles\i386\mofcomp.exe
+ 2008-04-14 00:11:57 123,904 -c----w c:\windows\ServicePackFiles\i386\mofd.dll
+ 2008-04-14 00:12:42 16,896 -c----w c:\windows\ServicePackFiles\i386\more.com
+ 2008-04-13 16:45:30 216,064 -c----w c:\windows\ServicePackFiles\i386\moricons.dll
+ 2008-04-13 18:39:47 23,040 -c----w c:\windows\ServicePackFiles\i386\mouclass.sys
+ 2008-04-13 18:39:46 42,368 -c----w c:\windows\ServicePackFiles\i386\mountmgr.sys
+ 2008-04-14 00:12:27 3,558,912 -c----w c:\windows\ServicePackFiles\i386\moviemk.exe
+ 2008-04-13 18:46:22 15,232 -c----w c:\windows\ServicePackFiles\i386\mpe.sys
+ 2008-04-14 00:12:27 123,392 -c----w c:\windows\ServicePackFiles\i386\mplay32.exe
+ 2008-04-14 00:11:57 59,904 -c----w c:\windows\ServicePackFiles\i386\mpr.dll
+ 2008-04-14 00:11:57 87,040 -c----w c:\windows\ServicePackFiles\i386\mprapi.dll
+ 2008-04-14 00:11:57 53,248 -c----w c:\windows\ServicePackFiles\i386\mprdim.dll
+ 2008-04-13 18:39:44 92,544 -c----w c:\windows\ServicePackFiles\i386\mqac.sys
+ 2008-04-14 00:11:57 138,240 -c----w c:\windows\ServicePackFiles\i386\mqad.dll
+ 2008-04-14 00:12:27 19,968 -c----w c:\windows\ServicePackFiles\i386\mqbkup.exe
+ 2008-04-14 00:11:57 47,616 -c----w c:\windows\ServicePackFiles\i386\mqdscli.dll
+ 2008-04-14 00:11:57 16,896 -c----w c:\windows\ServicePackFiles\i386\mqise.dll
+ 2008-04-14 00:11:57 89,088 -c----w c:\windows\ServicePackFiles\i386\mqlogmgr.dll
+ 2008-04-14 00:11:57 225,280 -c----w c:\windows\ServicePackFiles\i386\mqoa.dll
+ 2008-04-14 00:11:57 663,040 -c----w c:\windows\ServicePackFiles\i386\mqqm.dll
+ 2008-04-14 00:11:57 177,152 -c----w c:\windows\ServicePackFiles\i386\mqrt.dll
+ 2008-04-14 00:11:57 123,904 -c----w c:\windows\ServicePackFiles\i386\mqrtdep.dll
+ 2008-04-14 00:11:57 95,744 -c----w c:\windows\ServicePackFiles\i386\mqsec.dll
+ 2008-04-14 00:11:58 517,632 -c----w c:\windows\ServicePackFiles\i386\mqsnap.dll
+ 2008-04-14 00:12:27 4,608 -c----w c:\windows\ServicePackFiles\i386\mqsvc.exe
+ 2008-04-14 00:12:27 117,248 -c----w c:\windows\ServicePackFiles\i386\mqtgsvc.exe
+ 2008-04-14 00:11:58 187,392 -c----w c:\windows\ServicePackFiles\i386\mqtrig.dll
+ 2008-04-14 00:11:58 49,152 -c----w c:\windows\ServicePackFiles\i386\mqupgrd.dll
+ 2008-04-14 00:11:58 471,552 -c----w c:\windows\ServicePackFiles\i386\mqutil.dll
+ 2008-04-13 18:32:44 180,608 -c----w c:\windows\ServicePackFiles\i386\mrxdav.sys
+ 2008-04-13 19:17:01 456,576 -c----w c:\windows\ServicePackFiles\i386\mrxsmb.sys
+ 2008-04-14 00:11:58 71,680 -c----w c:\windows\ServicePackFiles\i386\msacm32.dll
+ 2008-04-14 00:11:58 331,776 -c----w c:\windows\ServicePackFiles\i386\msadce.dll
+ 2008-04-13 17:25:57 20,480 -c----w c:\windows\ServicePackFiles\i386\msadcer.dll
+ 2008-04-14 00:11:58 61,440 -c----w c:\windows\ServicePackFiles\i386\msadcf.dll
+ 2008-04-13 17:25:57 16,384 -c----w c:\windows\ServicePackFiles\i386\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 -c----w c:\windows\ServicePackFiles\i386\msadco.dll
+ 2008-04-13 17:25:57 16,384 -c----w c:\windows\ServicePackFiles\i386\msadcor.dll
+ 2008-04-14 00:11:58 53,248 -c----w c:\windows\ServicePackFiles\i386\msadcs.dll
+ 2008-04-14 00:11:58 155,648 -c----w c:\windows\ServicePackFiles\i386\msadds.dll
+ 2008-04-13 17:25:58 24,576 -c----w c:\windows\ServicePackFiles\i386\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 -c----w c:\windows\ServicePackFiles\i386\msader15.dll
+ 2008-04-14 00:11:58 536,576 -c----w c:\windows\ServicePackFiles\i386\msado15.dll
+ 2008-04-14 00:11:58 180,224 -c----w c:\windows\ServicePackFiles\i386\msadomd.dll
+ 2008-04-14 00:11:58 57,344 -c----w c:\windows\ServicePackFiles\i386\msador15.dll
+ 2008-04-14 00:11:58 200,704 -c----w c:\windows\ServicePackFiles\i386\msadox.dll
+ 2008-04-14 00:11:58 57,344 -c----w c:\windows\ServicePackFiles\i386\msadrh15.dll
+ 2008-04-14 00:10:06 3,584 -c----w c:\windows\ServicePackFiles\i386\msafd.dll
+ 2008-04-14 00:11:58 86,016 -c----w c:\windows\ServicePackFiles\i386\msapsspc.dll
+ 2008-04-14 00:11:58 57,344 -c----w c:\windows\ServicePackFiles\i386\msasn1.dll
+ 2008-04-14 00:11:58 220,160 -c----w c:\windows\ServicePackFiles\i386\mscandui.dll
+ 2008-04-14 00:11:58 73,728 -c----w c:\windows\ServicePackFiles\i386\mscms.dll
+ 2008-04-14 00:11:58 69,632 -c----w c:\windows\ServicePackFiles\i386\msconf.dll
+ 2008-04-14 00:12:27 169,984 -c----w c:\windows\ServicePackFiles\i386\msconfig.exe
+ 2004-08-10 19:00:00 116,288 -c----w c:\windows\ServicePackFiles\i386\msconv97.dll
+ 2004-07-20 09:54:06 1,564,672 -c----w c:\windows\ServicePackFiles\i386\mscorcfg.dll
+ 2004-08-04 13:12:02 69,632 -c----w c:\windows\ServicePackFiles\i386\mscordbc.dll
+ 2004-08-04 13:12:02 221,184 -c----w c:\windows\ServicePackFiles\i386\mscordbi.dll
+ 2007-06-27 12:55:10 131,072 -c----w c:\windows\ServicePackFiles\i386\mscoree.dll
+ 2007-01-02 21:29:12 73,728 -c----w c:\windows\ServicePackFiles\i386\mscorie.dll
+ 2004-07-20 09:54:08 303,104 -c----w c:\windows\ServicePackFiles\i386\mscorjit.dll
+ 2007-01-02 21:29:12 86,016 -c----w c:\windows\ServicePackFiles\i386\mscorld.dll
+ 2007-01-02 21:21:20 1,998,848 -c----w c:\windows\ServicePackFiles\i386\mscorlib.dll
+ 2004-08-04 13:12:08 94,208 -c----w c:\windows\ServicePackFiles\i386\mscorpe.dll
+ 2004-08-04 13:12:08 143,360 -c----w c:\windows\ServicePackFiles\i386\mscorrc.chs.dll
+ 2004-08-04 13:12:08 143,360 -c----w c:\windows\ServicePackFiles\i386\mscorrc.cht.dll
+ 2004-08-04 13:12:08 143,360 -c----w c:\windows\ServicePackFiles\i386\mscorrc.dll
+ 2004-08-04 13:12:10 172,032 -c----w c:\windows\ServicePackFiles\i386\mscorrc.es.dll
+ 2004-08-04 13:12:10 172,032 -c----w c:\windows\ServicePackFiles\i386\mscorrc.fr.dll
+ 2004-08-04 13:12:10 167,936 -c----w c:\windows\ServicePackFiles\i386\mscorrc.ger.dll
+ 2004-08-04 13:12:10 167,936 -c----w c:\windows\ServicePackFiles\i386\mscorrc.it.dll
+ 2004-08-04 13:12:10 143,360 -c----w c:\windows\ServicePackFiles\i386\mscorrc.ja.dll
+ 2004-08-04 13:12:10 143,360 -c----w c:\windows\ServicePackFiles\i386\mscorrc.kor.dll
+ 2004-08-04 13:12:10 46,592 -c----w c:\windows\ServicePackFiles\i386\mscorsec.dll
+ 2004-08-04 13:12:10 69,632 -c----w c:\windows\ServicePackFiles\i386\mscorsn.dll
+ 2007-12-17 11:58:53 2,273,280 -c----w c:\windows\ServicePackFiles\i386\mscorsvr.dll
+ 2004-08-04 13:12:14 8,704 -c----w c:\windows\ServicePackFiles\i386\mscortim.dll
+ 2007-12-17 11:59:26 2,281,472 -c----w c:\windows\ServicePackFiles\i386\mscorwks.dll
+ 2008-04-13 17:26:07 12,288 -c----w c:\windows\ServicePackFiles\i386\mscpx32r.dll
+ 2008-04-14 00:11:58 36,864 -c----w c:\windows\ServicePackFiles\i386\mscpxl32.dll
+ 2008-04-14 00:11:58 297,984 -c----w c:\windows\ServicePackFiles\i386\msctf.dll
+ 2008-04-14 00:11:58 68,608 -c----w c:\windows\ServicePackFiles\i386\msctfp.dll
+ 2008-04-14 00:11:58 4,096 -c----w c:\windows\ServicePackFiles\i386\msdadc.dll
+ 2008-04-14 00:11:58 118,784 -c----w c:\windows\ServicePackFiles\i386\msdadiag.dll
+ 2008-04-14 00:11:58 4,096 -c----w c:\windows\ServicePackFiles\i386\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 -c----w c:\windows\ServicePackFiles\i386\msdaer.dll
+ 2008-04-14 00:11:58 532,480 -c----w c:\windows\ServicePackFiles\i386\msdaipp.dll
+ 2008-04-14 00:11:58 233,472 -c----w c:\windows\ServicePackFiles\i386\msdaora.dll
+ 2008-04-13 17:24:14 16,384 -c----w c:\windows\ServicePackFiles\i386\msdaorar.dll
+ 2008-04-14 00:11:58 77,824 -c----w c:\windows\ServicePackFiles\i386\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 -c----w c:\windows\ServicePackFiles\i386\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 -c----w c:\windows\ServicePackFiles\i386\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 -c----w c:\windows\ServicePackFiles\i386\msdaps.dll
+ 2008-04-14 00:11:59 118,784 -c----w c:\windows\ServicePackFiles\i386\msdarem.dll
+ 2008-04-13 17:25:58 16,384 -c----w c:\windows\ServicePackFiles\i386\msdaremr.dll
+ 2008-04-14 00:11:59 151,552 -c----w c:\windows\ServicePackFiles\i386\msdart.dll
+ 2008-04-14 00:11:59 4,096 -c----w c:\windows\ServicePackFiles\i386\msdasc.dll
+ 2008-04-14 00:11:59 315,392 -c----w c:\windows\ServicePackFiles\i386\msdasql.dll
+ 2008-04-13 17:26:07 16,384 -c----w c:\windows\ServicePackFiles\i386\msdasqlr.dll
+ 2008-04-14 00:11:59 94,208 -c----w c:\windows\ServicePackFiles\i386\msdatl3.dll
+ 2008-04-14 00:11:59 20,480 -c----w c:\windows\ServicePackFiles\i386\msdatt.dll
+ 2008-04-14 00:11:59 4,096 -c----w c:\windows\ServicePackFiles\i386\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 -c----w c:\windows\ServicePackFiles\i386\msdfmap.dll
+ 2008-04-14 00:11:59 14,336 -c----w c:\windows\ServicePackFiles\i386\msdmo.dll
+ 2008-04-14 00:12:27 6,144 -c----w c:\windows\ServicePackFiles\i386\msdtc.exe
+ 2008-04-14 00:11:59 58,880 -c----w c:\windows\ServicePackFiles\i386\msdtclog.dll
+ 2008-04-14 00:11:59 427,008 -c----w c:\windows\ServicePackFiles\i386\msdtcprx.dll
+ 2008-04-14 00:11:59 90,112 -c----w c:\windows\ServicePackFiles\i386\msdtcstp.dll
+ 2008-04-14 00:11:59 956,928 -c----w c:\windows\ServicePackFiles\i386\msdtctm.dll
+ 2008-04-14 00:11:59 161,792 -c----w c:\windows\ServicePackFiles\i386\msdtcuiu.dll
+ 2008-04-13 18:46:09 51,200 -c----w c:\windows\ServicePackFiles\i386\msdv.sys
+ 2008-03-25 04:50:28 518,944 -c----w c:\windows\ServicePackFiles\i386\msexch40.dll
+ 2008-03-25 04:50:30 326,432 -c----w c:\windows\ServicePackFiles\i386\msexcl40.dll
+ 2008-04-13 18:32:39 19,072 -c----w c:\windows\ServicePackFiles\i386\msfs.sys
+ 2008-04-14 00:11:59 539,136 -c----w c:\windows\ServicePackFiles\i386\msftedit.dll
+ 2008-04-14 00:11:59 997,376 -c----w c:\windows\ServicePackFiles\i386\msgina.dll
+ 2008-04-13 18:56:32 35,072 -c----w c:\windows\ServicePackFiles\i386\msgpc.sys
+ 2008-04-14 00:11:59 3,166,208 -c----w c:\windows\ServicePackFiles\i386\msgr3en.dll
+ 2008-04-14 00:11:59 15,360 -c----w c:\windows\ServicePackFiles\i386\msgrocm.dll
+ 2008-04-14 00:11:59 82,944 -c----w c:\windows\ServicePackFiles\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 -c----w c:\windows\ServicePackFiles\i386\msgslang.dll
+ 2008-04-14 00:11:59 33,792 -c----w c:\windows\ServicePackFiles\i386\msgsvc.dll
+ 2008-04-14 00:12:45 188,416 -c----w c:\windows\ServicePackFiles\i386\msh261.drv
+ 2008-04-14 00:12:45 294,912 -c----w c:\windows\ServicePackFiles\i386\msh263.drv
+ 2008-04-14 00:12:27 29,184 -c----w c:\windows\ServicePackFiles\i386\mshta.exe
+ 2008-04-14 00:11:59 3,066,880 -c----w c:\windows\ServicePackFiles\i386\mshtml.dll
+ 2008-04-14 00:11:59 449,024 -c----w c:\windows\ServicePackFiles\i386\mshtmled.dll
+ 2008-04-13 16:26:26 56,832 -c----w c:\windows\ServicePackFiles\i386\mshtmler.dll
+ 2008-04-14 00:11:59 2,843,136 -c----w c:\windows\ServicePackFiles\i386\msi.dll
+ 2008-04-14 00:11:59 51,712 -c----w c:\windows\ServicePackFiles\i386\msident.dll
+ 2008-04-14 00:11:59 6,656 -c----w c:\windows\ServicePackFiles\i386\msidle.dll
+ 2008-04-14 00:11:59 248,832 -c----w c:\windows\ServicePackFiles\i386\msieftp.dll
+ 2008-04-14 00:12:28 78,848 -c----w c:\windows\ServicePackFiles\i386\msiexec.exe
+ 2008-04-14 00:11:59 271,360 -c----w c:\windows\ServicePackFiles\i386\msihnd.dll
+ 2008-04-14 00:11:59 4,608 -c----w c:\windows\ServicePackFiles\i386\msimg32.dll
+ 2008-04-14 00:12:28 60,416 -c----w c:\windows\ServicePackFiles\i386\msimn.exe
+ 2008-04-13 15:39:43 884,736 -c----w c:\windows\ServicePackFiles\i386\msimsg.dll
+ 2008-04-14 00:11:59 159,232 -c----w c:\windows\ServicePackFiles\i386\msimtf.dll
+ 2008-04-14 00:11:59 376,832 -c----w c:\windows\ServicePackFiles\i386\msinfo.dll
+ 2008-04-13 18:54:28 22,016 -c----w c:\windows\ServicePackFiles\i386\msircomm.sys
+ 2008-04-14 00:12:28 40,960 -c----w c:\windows\ServicePackFiles\i386\msiregmv.exe
+ 2008-04-14 00:11:59 15,360 -c----w c:\windows\ServicePackFiles\i386\msisip.dll
+ 2008-03-25 04:50:34 1,516,568 -c----w c:\windows\ServicePackFiles\i386\msjet40.dll
+ 2008-03-25 04:50:40 355,112 -c----w c:\windows\ServicePackFiles\i386\msjetol1.dll
+ 2008-04-14 00:12:00 151,583 -c----w c:\windows\ServicePackFiles\i386\msjint40.dll
+ 2008-04-14 00:12:00 102,400 -c----w c:\windows\ServicePackFiles\i386\msjro.dll
+ 2008-03-25 04:50:42 60,192 -c----w c:\windows\ServicePackFiles\i386\msjter40.dll
+ 2008-03-25 04:50:42 248,608 -c----w c:\windows\ServicePackFiles\i386\msjtes40.dll
+ 2008-04-13 18:39:52 7,552 -c----w c:\windows\ServicePackFiles\i386\mskssrv.sys
+ 2008-04-14 00:12:00 25,088 -c----w c:\windows\ServicePackFiles\i386\mslbui.dll
+ 2008-03-25 04:50:44 219,936 -c----w c:\windows\ServicePackFiles\i386\msltus40.dll
+ 2008-04-14 00:12:00 39,936 -c----w c:\windows\ServicePackFiles\i386\mslwvtts.dll
+ 2008-04-14 00:12:00 170,496 -c----w c:\windows\ServicePackFiles\i386\msmqocm.dll
+ 2008-04-14 00:12:28 1,695,232 -c----w c:\windows\ServicePackFiles\i386\msmsgs.exe
+ 2004-08-10 19:00:00 11,053,008 -c----w c:\windows\ServicePackFiles\i386\msncli.exe
+ 2008-04-14 00:12:00 290,816 -c----w c:\windows\ServicePackFiles\i386\msnsspc.dll
+ 2004-08-10 19:00:00 1,327,320 -c----w c:\windows\ServicePackFiles\i386\msnsusii.exe
+ 2008-04-14 00:12:00 122,368 -c----w c:\windows\ServicePackFiles\i386\msobcomm.dll
+ 2008-04-14 00:12:00 16,384 -c----w c:\windows\ServicePackFiles\i386\msobdl.dll
+ 2008-04-14 00:12:00 565,248 -c----w c:\windows\ServicePackFiles\i386\msobmain.dll
+ 2008-04-14 00:12:00 30,720 -c----w c:\windows\ServicePackFiles\i386\msobshel.dll
+ 2008-04-14 00:12:00 19,456 -c----w c:\windows\ServicePackFiles\i386\msobweb.dll
+ 2008-04-14 00:12:00 1,314,816 -c----w c:\windows\ServicePackFiles\i386\msoe.dll
+ 2008-04-14 00:12:00 252,928 -c----w c:\windows\ServicePackFiles\i386\msoeacct.dll
+ 2008-04-13 16:23:54 2,479,616 -c----w c:\windows\ServicePackFiles\i386\msoeres.dll
+ 2008-04-14 00:12:00 105,984 -c----w c:\windows\ServicePackFiles\i386\msoert2.dll
+ 2008-04-14 00:12:28 29,184 -c----w c:\windows\ServicePackFiles\i386\msoobe.exe
+ 2008-04-13 17:24:14 20,480 -c----w c:\windows\ServicePackFiles\i386\msorc32r.dll
+ 2008-04-14 00:12:00 143,360 -c----w c:\windows\ServicePackFiles\i386\msorcl32.dll
+ 2008-04-14 00:12:28 343,040 -c----w c:\windows\ServicePackFiles\i386\mspaint.exe
+ 2008-04-14 00:12:00 29,696 -c----w c:\windows\ServicePackFiles\i386\mspatcha.dll
+ 2008-03-25 04:50:45 355,104 -c----w c:\windows\ServicePackFiles\i386\mspbde40.dll
+ 2008-04-13 18:39:50 5,376 -c----w c:\windows\ServicePackFiles\i386\mspclock.sys
+ 2008-04-13 18:39:51 4,992 -c----w c:\windows\ServicePackFiles\i386\mspqm.sys
+ 2008-04-13 16:23:31 48,128 -c----w c:\windows\ServicePackFiles\i386\msprivs.dll
+ 2008-04-14 00:12:00 146,432 -c----w c:\windows\ServicePackFiles\i386\msrating.dll
+ 2008-03-25 04:50:47 432,928 -c----w c:\windows\ServicePackFiles\i386\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 -c----w c:\windows\ServicePackFiles\i386\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 -c----w c:\windows\ServicePackFiles\i386\msrepl40.dll
+ 2008-04-14 00:12:00 11,264 -c----w c:\windows\ServicePackFiles\i386\msrle32.dll
+ 2008-04-14 00:12:00 134,656 -c----w c:\windows\ServicePackFiles\i386\mssap.dll
+ 2008-04-14 00:12:00 155,136 -c----w c:\windows\ServicePackFiles\i386\mssha.dll
+ 2008-04-13 18:14:58 76,800 -c----w c:\windows\ServicePackFiles\i386\msshamsg.dll
+ 2008-04-13 18:36:46 15,488 -c----w c:\windows\ServicePackFiles\i386\mssmbios.sys
+ 2008-04-14 00:12:00 274,432 -c----w c:\windows\ServicePackFiles\i386\mst120.dll
+ 2008-04-14 00:12:00 57,344 -c----w c:\windows\ServicePackFiles\i386\mst123.dll
+ 2008-04-13 18:46:08 49,024 -c----w c:\windows\ServicePackFiles\i386\mstape.sys
+ 2008-04-14 00:12:00 274,944 -c----w c:\windows\ServicePackFiles\i386\mstask.dll
+ 2008-04-13 18:39:50 5,504 -c----w c:\windows\ServicePackFiles\i386\mstee.sys
+ 2008-03-25 04:50:55 264,992 -c----w c:\windows\ServicePackFiles\i386\mstext40.dll
+ 2008-04-14 00:12:00 532,480 -c----w c:\windows\ServicePackFiles\i386\mstime.dll
+ 2008-04-14 00:12:29 12,288 -c----w c:\windows\ServicePackFiles\i386\mstinit.exe
+ 2008-04-14 00:12:00 116,224 -c----w c:\windows\ServicePackFiles\i386\mstlsapi.dll
+ 2008-04-14 00:12:00 195,072 -c----w c:\windows\ServicePackFiles\i386\msutb.dll
+ 2008-04-14 00:12:00 132,608 -c----w c:\windows\ServicePackFiles\i386\msv1_0.dll
+ 2008-04-14 00:12:00 1,384,479 -c----w c:\windows\ServicePackFiles\i386\msvbvm60.dll
+ 2008-04-14 00:12:01 57,344 -c----w c:\windows\ServicePackFiles\i386\msvcirt.dll
+ 2008-04-14 00:12:01 413,696 -c----w c:\windows\ServicePackFiles\i386\msvcp60.dll
+ 2008-04-14 00:12:01 343,040 -c----w c:\windows\ServicePackFiles\i386\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 -c----w c:\windows\ServicePackFiles\i386\msvcrt40.dll
+ 2008-04-14 00:12:01 121,344 -c----w c:\windows\ServicePackFiles\i386\msvfw32.dll
+ 2008-04-14 00:12:01 1,428,992 -c----w c:\windows\ServicePackFiles\i386\msvidctl.dll

EasyEEE
2008-12-29, 18:11
Halfway done! Woot...

+ 2008-04-14 00:12:01 72,704 -c----w c:\windows\ServicePackFiles\i386\msw3prt.dll
+ 2008-03-25 04:50:57 838,432 -c----w c:\windows\ServicePackFiles\i386\mswdat10.dll
+ 2008-04-14 00:12:01 203,776 -c----w c:\windows\ServicePackFiles\i386\mswebdvd.dll
+ 2008-04-14 00:12:01 245,248 -c----w c:\windows\ServicePackFiles\i386\mswsock.dll
+ 2008-03-25 04:50:58 621,344 -c----w c:\windows\ServicePackFiles\i386\mswstr10.dll
+ 2008-04-14 00:12:01 24,576 -c----w c:\windows\ServicePackFiles\i386\msxactps.dll
+ 2008-03-25 04:50:58 355,104 -c----w c:\windows\ServicePackFiles\i386\msxbde40.dll
+ 2008-04-14 00:12:01 506,368 -c----w c:\windows\ServicePackFiles\i386\msxml.dll
+ 2008-04-14 00:12:01 701,440 -c----w c:\windows\ServicePackFiles\i386\msxml2.dll
+ 2008-04-14 00:12:01 1,104,896 -c----w c:\windows\ServicePackFiles\i386\msxml3.dll
+ 2008-04-14 00:12:01 16,896 -c----w c:\windows\ServicePackFiles\i386\msyuv.dll
+ 2004-08-04 02:41:40 126,686 -c----w c:\windows\ServicePackFiles\i386\mtlmnt5.sys
+ 2004-08-04 02:41:38 1,309,184 -c----w c:\windows\ServicePackFiles\i386\mtlstrm.sys
+ 2008-04-14 00:12:29 119,808 -c----w c:\windows\ServicePackFiles\i386\mtstocom.exe
+ 2008-04-14 00:12:01 66,560 -c----w c:\windows\ServicePackFiles\i386\mtxclu.dll
+ 2008-04-14 00:12:01 30,720 -c----w c:\windows\ServicePackFiles\i386\mtxdm.dll
+ 2008-04-14 00:12:01 4,096 -c----w c:\windows\ServicePackFiles\i386\mtxex.dll
+ 2008-04-14 00:12:01 34,304 -c----w c:\windows\ServicePackFiles\i386\mtxlegih.dll
+ 2008-04-14 00:12:01 91,648 -c----w c:\windows\ServicePackFiles\i386\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 -c----w c:\windows\ServicePackFiles\i386\mtxparhd.dll
+ 2004-08-04 02:29:38 452,736 -c----w c:\windows\ServicePackFiles\i386\mtxparhm.sys
+ 2008-04-14 00:12:29 90,624 -c----w c:\windows\ServicePackFiles\i386\muisetup.exe
+ 2008-04-13 19:17:05 105,344 -c----w c:\windows\ServicePackFiles\i386\mup.sys
+ 2008-04-13 18:43:55 12,672 -c----w c:\windows\ServicePackFiles\i386\mutohpen.sys
+ 2008-04-14 00:12:01 90,624 -c----w c:\windows\ServicePackFiles\i386\mydocs.dll
+ 2008-04-13 18:46:25 85,248 -c----w c:\windows\ServicePackFiles\i386\nabtsfec.sys
+ 2008-04-14 00:12:01 221,184 -c----w c:\windows\ServicePackFiles\i386\nac.dll
+ 2008-04-14 00:12:01 30,208 -c----w c:\windows\ServicePackFiles\i386\napipsec.dll
+ 2008-04-14 00:12:01 193,024 -c----w c:\windows\ServicePackFiles\i386\napmontr.dll
+ 2008-04-14 00:12:29 176,640 -c----w c:\windows\ServicePackFiles\i386\napstat.exe
+ 2008-04-14 00:12:29 53,760 -c----w c:\windows\ServicePackFiles\i386\narrator.exe
+ 2008-04-14 00:12:01 36,352 -c----w c:\windows\ServicePackFiles\i386\ncobjapi.dll
+ 2008-04-14 00:12:01 47,104 -c----w c:\windows\ServicePackFiles\i386\ncprov.dll
+ 2008-04-14 00:12:01 9,728 -c----w c:\windows\ServicePackFiles\i386\ncpsres.dll
+ 2008-04-14 00:12:01 17,920 -c----w c:\windows\ServicePackFiles\i386\nddeapi.dll
+ 2008-04-14 00:12:29 4,096 -c----w c:\windows\ServicePackFiles\i386\nddeapir.exe
+ 2008-04-14 00:12:01 18,944 -c----w c:\windows\ServicePackFiles\i386\nddenb32.dll
+ 2008-04-13 19:20:37 182,656 -c----w c:\windows\ServicePackFiles\i386\ndis.sys
+ 2008-04-13 18:46:22 10,880 -c----w c:\windows\ServicePackFiles\i386\ndisip.sys
+ 2008-04-14 00:12:01 57,344 -c----w c:\windows\ServicePackFiles\i386\ndisnpp.dll
+ 2008-04-13 18:57:27 10,112 -c----w c:\windows\ServicePackFiles\i386\ndistapi.sys
+ 2008-04-13 18:55:58 14,592 -c----w c:\windows\ServicePackFiles\i386\ndisuio.sys
+ 2008-04-13 19:20:42 91,520 -c----w c:\windows\ServicePackFiles\i386\ndiswan.sys
+ 2008-04-13 18:57:29 40,576 -c----w c:\windows\ServicePackFiles\i386\ndproxy.sys
+ 2008-04-14 00:12:29 42,496 -c----w c:\windows\ServicePackFiles\i386\net.exe
+ 2008-04-14 00:12:29 124,928 -c----w c:\windows\ServicePackFiles\i386\net1.exe
+ 2008-04-14 00:12:01 337,408 -c----w c:\windows\ServicePackFiles\i386\netapi32.dll
+ 2008-04-13 18:56:02 34,688 -c----w c:\windows\ServicePackFiles\i386\netbios.sys
+ 2008-04-13 19:21:00 162,816 -c----w c:\windows\ServicePackFiles\i386\netbt.sys
+ 2008-04-14 00:12:01 622,592 -c----w c:\windows\ServicePackFiles\i386\netcfgx.dll
+ 2008-04-14 00:12:29 111,104 -c----w c:\windows\ServicePackFiles\i386\netdde.exe
+ 2004-08-10 19:00:00 126,976 -c----w c:\windows\ServicePackFiles\i386\netfxocm.dll
+ 2007-12-17 11:59:53 82,976 -c----w c:\windows\ServicePackFiles\i386\netfxupdate.exe
+ 2008-04-14 00:12:01 139,264 -c----w c:\windows\ServicePackFiles\i386\netid.dll
+ 2008-04-14 00:12:01 407,040 -c----w c:\windows\ServicePackFiles\i386\netlogon.dll
+ 2008-04-14 00:12:01 198,144 -c----w c:\windows\ServicePackFiles\i386\netman.dll
+ 2008-04-14 00:12:01 77,312 -c----w c:\windows\ServicePackFiles\i386\netoc.dll
+ 2008-04-14 00:12:01 875,008 -c----w c:\windows\ServicePackFiles\i386\netplwiz.dll
+ 2008-04-14 00:12:01 11,776 -c----w c:\windows\ServicePackFiles\i386\netrap.dll
+ 2008-04-14 00:16:51 329,728 -c----w c:\windows\ServicePackFiles\i386\netsetup.exe
+ 2008-04-14 00:12:29 86,016 -c----w c:\windows\ServicePackFiles\i386\netsh.exe
+ 2008-04-14 00:12:02 1,703,936 -c----w c:\windows\ServicePackFiles\i386\netshell.dll
+ 2008-04-14 00:12:29 36,864 -c----w c:\windows\ServicePackFiles\i386\netstat.exe
+ 2008-04-14 00:12:02 80,896 -c----w c:\windows\ServicePackFiles\i386\netui0.dll
+ 2008-04-14 00:12:02 245,760 -c----w c:\windows\ServicePackFiles\i386\netui1.dll
+ 2004-08-04 02:31:42 132,695 -c----w c:\windows\ServicePackFiles\i386\netwlan5.sys
+ 2008-04-14 00:12:02 247,808 -c----w c:\windows\ServicePackFiles\i386\newdev.dll
+ 2004-08-04 13:12:20 147,456 -c----w c:\windows\ServicePackFiles\i386\ngen.exe
+ 2008-04-13 18:51:25 61,824 -c----w c:\windows\ServicePackFiles\i386\nic1394.sys
+ 2008-04-14 00:12:02 98,304 -c----w c:\windows\ServicePackFiles\i386\nlhtml.dll
+ 2008-04-14 00:12:02 229,376 -c----w c:\windows\ServicePackFiles\i386\nmas.dll
+ 2008-04-14 00:12:02 28,672 -c----w c:\windows\ServicePackFiles\i386\nmasnt.dll
+ 2008-04-14 00:12:02 81,920 -c----w c:\windows\ServicePackFiles\i386\nmchat.dll
+ 2008-04-14 00:12:02 77,824 -c----w c:\windows\ServicePackFiles\i386\nmcom.dll
+ 2008-04-14 00:12:02 151,552 -c----w c:\windows\ServicePackFiles\i386\nmft.dll
+ 2008-04-14 00:12:02 28,672 -c----w c:\windows\ServicePackFiles\i386\nmmkcert.dll
+ 2008-04-13 18:53:09 40,320 -c----w c:\windows\ServicePackFiles\i386\nmnt.sys
+ 2008-04-14 00:12:02 172,032 -c----w c:\windows\ServicePackFiles\i386\nmoldwb.dll
+ 2008-04-14 00:12:02 188,416 -c----w c:\windows\ServicePackFiles\i386\nmwb.dll
+ 2008-04-14 00:12:29 69,120 -c----w c:\windows\ServicePackFiles\i386\notepad.exe
+ 2008-04-13 18:32:39 30,848 -c----w c:\windows\ServicePackFiles\i386\npfs.sys
+ 2008-04-14 00:12:29 15,360 -c----w c:\windows\ServicePackFiles\i386\nppagent.exe
+ 2008-04-14 00:12:02 54,784 -c----w c:\windows\ServicePackFiles\i386\npptools.dll
+ 2008-04-13 18:54:36 28,672 -c----w c:\windows\ServicePackFiles\i386\nscirda.sys
+ 2008-04-14 00:12:02 44,544 -c----w c:\windows\ServicePackFiles\i386\nsepm.dll
+ 2008-04-14 00:12:29 76,800 -c----w c:\windows\ServicePackFiles\i386\nslookup.exe
+ 2008-04-14 00:12:30 1,200,640 -c----w c:\windows\ServicePackFiles\i386\ntbackup.exe
+ 2004-08-10 19:00:00 47,564 ------w c:\windows\ServicePackFiles\i386\ntdetect.com
+ 2008-04-14 00:11:24 706,048 -c----w c:\windows\ServicePackFiles\i386\ntdll.dll
+ 2008-04-14 00:12:02 67,072 -c----w c:\windows\ServicePackFiles\i386\ntdsapi.dll
+ 2008-04-14 00:12:02 212,992 -c----w c:\windows\ServicePackFiles\i386\ntevt.dll
+ 2008-04-13 19:15:53 574,976 -c----w c:\windows\ServicePackFiles\i386\ntfs.sys
+ 2004-08-10 19:00:00 33,840 -c----w c:\windows\ServicePackFiles\i386\ntio.sys
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\ServicePackFiles\i386\ntio404.sys
+ 2004-08-10 19:00:00 35,648 -c----w c:\windows\ServicePackFiles\i386\ntio411.sys
+ 2004-08-10 19:00:00 35,424 -c----w c:\windows\ServicePackFiles\i386\ntio412.sys
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\ServicePackFiles\i386\ntio804.sys
+ 2008-04-13 19:24:37 2,145,280 -c----w c:\windows\ServicePackFiles\i386\ntkrnlmp.exe
+ 2008-04-13 18:31:21 2,065,792 -c----w c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
+ 2008-04-13 18:31:21 2,023,936 -c----w c:\windows\ServicePackFiles\i386\ntkrpamp.exe
+ 2008-04-14 00:12:02 44,032 -c----w c:\windows\ServicePackFiles\i386\ntlanman.dll
+ 2008-04-14 00:12:02 8,192 -c----w c:\windows\ServicePackFiles\i386\ntlsapi.dll
+ 2008-04-14 00:12:02 118,784 -c----w c:\windows\ServicePackFiles\i386\ntmarta.dll
+ 2008-04-14 00:12:02 40,960 -c----w c:\windows\ServicePackFiles\i386\ntmsapi.dll
+ 2008-04-14 00:12:02 179,200 -c----w c:\windows\ServicePackFiles\i386\ntmsdba.dll
+ 2008-04-14 00:12:02 488,448 -c----w c:\windows\ServicePackFiles\i386\ntmsmgr.dll
+ 2008-04-14 00:12:02 435,200 -c----w c:\windows\ServicePackFiles\i386\ntmssvc.dll
+ 2004-08-04 02:41:40 180,360 -c----w c:\windows\ServicePackFiles\i386\ntmtlfax.sys
+ 2008-04-14 00:12:02 62,976 -c----w c:\windows\ServicePackFiles\i386\ntoc.dll
+ 2008-04-13 19:27:53 2,188,928 -c----w c:\windows\ServicePackFiles\i386\ntoskrnl.exe
+ 2008-04-14 00:12:02 91,136 -c----w c:\windows\ServicePackFiles\i386\ntprint.dll
+ 2008-04-14 00:12:02 143,360 -c----w c:\windows\ServicePackFiles\i386\ntshrui.dll
+ 2008-04-14 00:12:30 420,864 -c----w c:\windows\ServicePackFiles\i386\ntvdm.exe
+ 2008-04-14 00:12:02 15,360 -c----w c:\windows\ServicePackFiles\i386\ntvdmd.dll
+ 2008-04-14 00:12:02 4,274,816 -c----w c:\windows\ServicePackFiles\i386\nv4_disp.dll
+ 2004-08-04 02:29:56 1,897,408 -c----w c:\windows\ServicePackFiles\i386\nv4_mini.sys
+ 2008-04-14 00:12:02 64,000 -c----w c:\windows\ServicePackFiles\i386\nwapi32.dll
+ 2008-04-13 18:56:06 88,320 -c----w c:\windows\ServicePackFiles\i386\nwlnkipx.sys
+ 2008-04-14 00:12:02 142,336 -c----w c:\windows\ServicePackFiles\i386\nwprovau.dll
+ 2008-04-13 18:34:12 163,584 -c----w c:\windows\ServicePackFiles\i386\nwrdr.sys
+ 2008-04-14 00:12:02 65,536 -c----w c:\windows\ServicePackFiles\i386\nwwks.dll
+ 2008-04-14 00:12:02 270,336 -c----w c:\windows\ServicePackFiles\i386\oakley.dll
+ 2008-04-14 00:10:30 229,376 -c----w c:\windows\ServicePackFiles\i386\obelog.dll
+ 2008-04-14 00:10:30 966,656 -c----w c:\windows\ServicePackFiles\i386\obemetal.dll
+ 2007-04-02 18:44:11 77,824 -c----w c:\windows\ServicePackFiles\i386\obemtllc.dll
+ 2008-04-14 00:10:30 86,016 -c----w c:\windows\ServicePackFiles\i386\obepopc.dll
+ 2008-04-14 00:12:02 286,208 -c----w c:\windows\ServicePackFiles\i386\objsel.dll
+ 2008-04-13 18:40:07 393,728 -c----w c:\windows\ServicePackFiles\i386\obrb0401.dll
+ 2008-04-13 18:40:23 212,480 -c----w c:\windows\ServicePackFiles\i386\obrb0404.dll
+ 2008-04-13 18:40:24 428,032 -c----w c:\windows\ServicePackFiles\i386\obrb0405.dll
+ 2008-04-13 18:40:27 418,816 -c----w c:\windows\ServicePackFiles\i386\obrb0406.dll
+ 2008-04-13 18:40:34 403,456 -c----w c:\windows\ServicePackFiles\i386\obrb0407.dll
+ 2008-04-13 18:40:30 419,328 -c----w c:\windows\ServicePackFiles\i386\obrb0408.dll
+ 2008-04-13 18:40:32 405,504 -c----w c:\windows\ServicePackFiles\i386\obrb040b.dll
+ 2008-04-13 18:40:33 410,624 -c----w c:\windows\ServicePackFiles\i386\obrb040c.dll
+ 2008-04-13 18:40:32 384,000 -c----w c:\windows\ServicePackFiles\i386\obrb040d.dll
+ 2008-04-13 18:40:39 434,176 -c----w c:\windows\ServicePackFiles\i386\obrb040e.dll
+ 2008-04-13 18:40:39 413,696 -c----w c:\windows\ServicePackFiles\i386\obrb0410.dll
+ 2008-04-13 18:40:44 275,456 -c----w c:\windows\ServicePackFiles\i386\obrb0411.dll
+ 2008-04-13 18:40:48 306,688 -c----w c:\windows\ServicePackFiles\i386\obrb0412.dll
+ 2008-04-13 18:40:44 401,920 -c----w c:\windows\ServicePackFiles\i386\obrb0413.dll
+ 2008-04-13 18:40:44 353,792 -c----w c:\windows\ServicePackFiles\i386\obrb0414.dll
+ 2008-04-13 18:40:47 391,680 -c----w c:\windows\ServicePackFiles\i386\obrb0415.dll
+ 2008-04-13 18:40:10 409,600 -c----w c:\windows\ServicePackFiles\i386\obrb0416.dll
+ 2008-04-13 18:40:50 427,008 -c----w c:\windows\ServicePackFiles\i386\obrb0419.dll
+ 2008-04-13 18:40:52 405,504 -c----w c:\windows\ServicePackFiles\i386\obrb041b.dll
+ 2008-04-13 18:40:56 363,008 -c----w c:\windows\ServicePackFiles\i386\obrb041d.dll
+ 2008-04-13 18:41:00 390,144 -c----w c:\windows\ServicePackFiles\i386\obrb041f.dll
+ 2008-04-13 18:40:56 408,576 -c----w c:\windows\ServicePackFiles\i386\obrb0424.dll
+ 2008-04-13 18:40:24 270,336 -c----w c:\windows\ServicePackFiles\i386\obrb0804.dll
+ 2008-04-13 18:40:48 435,200 -c----w c:\windows\ServicePackFiles\i386\obrb0816.dll
+ 2008-04-13 18:40:30 446,464 -c----w c:\windows\ServicePackFiles\i386\obrb0c0a.dll
+ 2008-04-14 00:12:02 96,256 -c----w c:\windows\ServicePackFiles\i386\occache.dll
+ 2008-04-14 00:12:02 15,360 -c----w c:\windows\ServicePackFiles\i386\ocgen.dll
+ 2008-04-14 00:12:02 67,584 -c----w c:\windows\ServicePackFiles\i386\ocmanage.dll
+ 2008-04-14 00:12:02 17,408 -c----w c:\windows\ServicePackFiles\i386\ocmsn.dll
+ 2004-08-10 19:00:00 26,224 -c----w c:\windows\ServicePackFiles\i386\odbc16gt.dll
+ 2008-04-14 00:12:02 249,856 -c----w c:\windows\ServicePackFiles\i386\odbc32.dll
+ 2008-04-14 00:12:02 16,384 -c----w c:\windows\ServicePackFiles\i386\odbc32gt.dll
+ 2008-04-14 00:12:30 32,768 -c----w c:\windows\ServicePackFiles\i386\odbcad32.exe
+ 2008-04-14 00:12:02 24,576 -c----w c:\windows\ServicePackFiles\i386\odbcbcp.dll
+ 2008-04-14 00:12:02 135,168 -c----w c:\windows\ServicePackFiles\i386\odbcconf.dll
+ 2008-04-14 00:12:30 69,632 -c----w c:\windows\ServicePackFiles\i386\odbcconf.exe
+ 2008-04-14 00:12:02 106,496 -c----w c:\windows\ServicePackFiles\i386\odbccp32.dll
+ 2008-04-14 00:12:02 65,536 -c----w c:\windows\ServicePackFiles\i386\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 -c----w c:\windows\ServicePackFiles\i386\odbccu32.dll
+ 2008-04-13 17:26:05 94,208 -c----w c:\windows\ServicePackFiles\i386\odbcint.dll
+ 2008-04-14 00:10:31 53,279 -c----w c:\windows\ServicePackFiles\i386\odbcji32.dll
+ 2008-04-14 00:12:02 278,559 -c----w c:\windows\ServicePackFiles\i386\odbcjt32.dll
+ 2008-04-13 17:26:05 12,288 -c----w c:\windows\ServicePackFiles\i386\odbcp32r.dll
+ 2008-04-14 00:12:02 147,456 -c----w c:\windows\ServicePackFiles\i386\odbctrac.dll
+ 2008-04-14 00:12:02 20,511 -c----w c:\windows\ServicePackFiles\i386\oddbse32.dll
+ 2008-04-14 00:12:02 20,510 -c----w c:\windows\ServicePackFiles\i386\odexl32.dll
+ 2008-04-14 00:12:02 20,510 -c----w c:\windows\ServicePackFiles\i386\odfox32.dll
+ 2008-04-14 00:12:02 20,510 -c----w c:\windows\ServicePackFiles\i386\odpdx32.dll
+ 2008-04-14 00:12:02 20,511 -c----w c:\windows\ServicePackFiles\i386\odtext32.dll
+ 2008-04-14 00:12:02 104,448 -c----w c:\windows\ServicePackFiles\i386\oeimport.dll
+ 2008-04-14 00:12:30 60,416 -c----w c:\windows\ServicePackFiles\i386\oemig50.exe
+ 2008-04-14 00:12:02 35,328 -c----w c:\windows\ServicePackFiles\i386\oemiglib.dll
+ 2008-04-14 00:12:02 192,000 -c----w c:\windows\ServicePackFiles\i386\offfilt.dll
+ 2008-04-13 18:46:18 61,696 -c----w c:\windows\ServicePackFiles\i386\ohci1394.sys
+ 2008-04-14 00:12:02 1,287,168 -c----w c:\windows\ServicePackFiles\i386\ole32.dll
+ 2008-04-14 00:12:02 551,936 -c----w c:\windows\ServicePackFiles\i386\oleaut32.dll
+ 2008-04-14 00:12:02 74,752 -c----w c:\windows\ServicePackFiles\i386\olecli32.dll
+ 2008-04-14 00:12:02 37,376 -c----w c:\windows\ServicePackFiles\i386\olecnv32.dll
+ 2008-04-14 00:12:02 487,424 -c----w c:\windows\ServicePackFiles\i386\oledb32.dll
+ 2008-04-14 00:12:02 65,536 -c----w c:\windows\ServicePackFiles\i386\oledb32r.dll
+ 2008-04-14 00:12:02 122,880 -c----w c:\windows\ServicePackFiles\i386\oledlg.dll
+ 2008-04-14 00:12:02 107,008 -c----w c:\windows\ServicePackFiles\i386\oleprn.dll
+ 2008-04-14 00:12:02 84,992 -c----w c:\windows\ServicePackFiles\i386\olepro32.dll
+ 2008-04-14 00:12:02 144,384 -c----w c:\windows\ServicePackFiles\i386\onex.dll
+ 2008-04-14 00:12:31 51,200 -c----w c:\windows\ServicePackFiles\i386\oobebaln.exe
+ 2008-04-14 00:12:02 713,728 -c----w c:\windows\ServicePackFiles\i386\opengl32.dll
+ 2008-04-14 00:12:31 67,584 -c----w c:\windows\ServicePackFiles\i386\opnfiles.exe
+ 2008-04-13 18:32:32 166,912 -c----w c:\windows\ServicePackFiles\i386\oschoice.exe
+ 2008-04-14 00:12:31 215,552 -c----w c:\windows\ServicePackFiles\i386\osk.exe
+ 2008-04-13 18:31:43 230,400 ------w c:\windows\ServicePackFiles\i386\osloader.exe
+ 2008-04-14 00:12:02 67,584 -c----w c:\windows\ServicePackFiles\i386\osuninst.dll
+ 2008-04-14 00:12:02 153,600 -c----w c:\windows\ServicePackFiles\i386\p2p.dll
+ 2008-04-14 00:12:02 105,472 -c----w c:\windows\ServicePackFiles\i386\p2pgasvc.dll
+ 2008-04-14 00:12:02 313,856 -c----w c:\windows\ServicePackFiles\i386\p2pgraph.dll
+ 2008-04-14 00:12:02 115,712 -c----w c:\windows\ServicePackFiles\i386\p2pnetsh.dll
+ 2008-04-14 00:12:02 554,496 -c----w c:\windows\ServicePackFiles\i386\p2psvc.dll
+ 2008-04-13 18:31:31 42,752 -c----w c:\windows\ServicePackFiles\i386\p3.sys
+ 2008-04-14 00:12:31 58,368 -c----w c:\windows\ServicePackFiles\i386\packager.exe
+ 2008-04-13 18:40:10 80,128 -c----w c:\windows\ServicePackFiles\i386\parport.sys
+ 2008-04-13 18:40:49 19,712 -c----w c:\windows\ServicePackFiles\i386\partmgr.sys
+ 2008-04-14 00:12:02 67,584 -c----w c:\windows\ServicePackFiles\i386\pautoenr.dll
+ 2004-08-04 02:31:24 29,502 -c----w c:\windows\ServicePackFiles\i386\pca200e.sys
+ 2008-04-14 00:12:02 102,912 -c----w c:\windows\ServicePackFiles\i386\pchshell.dll
+ 2008-04-14 00:12:02 38,400 -c----w c:\windows\ServicePackFiles\i386\pchsvc.dll
+ 2008-04-13 18:36:44 68,224 -c----w c:\windows\ServicePackFiles\i386\pci.sys
+ 2008-04-13 18:40:29 24,960 -c----w c:\windows\ServicePackFiles\i386\pciidex.sys
+ 2007-05-15 08:08:11 288,768 -c----w c:\windows\ServicePackFiles\i386\pcl4res.dll
+ 2007-05-15 08:08:13 1,058,816 -c----w c:\windows\ServicePackFiles\i386\pcl5eres.dll
+ 2007-05-15 08:08:14 1,057,280 -c----w c:\windows\ServicePackFiles\i386\pcl5ures.dll
+ 2007-05-15 08:08:14 207,872 -c----w c:\windows\ServicePackFiles\i386\pclxl.dll
+ 2008-04-13 18:36:43 120,192 -c----w c:\windows\ServicePackFiles\i386\pcmcia.sys
+ 2004-08-04 02:06:18 169,984 -c----w c:\windows\ServicePackFiles\i386\pcx500.sys
+ 2008-04-14 00:12:02 284,160 -c----w c:\windows\ServicePackFiles\i386\pdh.dll
+ 2004-08-04 13:12:20 20,480 -c----w c:\windows\ServicePackFiles\i386\perfcounter.dll
+ 2008-04-14 00:12:02 39,936 -c----w c:\windows\ServicePackFiles\i386\perfctrs.dll
+ 2008-04-14 00:12:02 26,624 -c----w c:\windows\ServicePackFiles\i386\perfdisk.dll
+ 2008-04-14 00:12:31 15,872 -c----w c:\windows\ServicePackFiles\i386\perfmon.exe
+ 2008-04-14 00:12:02 17,920 -c----w c:\windows\ServicePackFiles\i386\perfnet.dll
+ 2008-04-14 00:12:02 25,088 -c----w c:\windows\ServicePackFiles\i386\perfos.dll
+ 2008-04-14 00:12:02 34,816 -c----w c:\windows\ServicePackFiles\i386\perfproc.dll
+ 2008-04-13 18:44:29 27,904 -c----w c:\windows\ServicePackFiles\i386\perm2.sys
+ 2008-04-14 00:10:34 211,584 -c----w c:\windows\ServicePackFiles\i386\perm2dll.dll
+ 2008-04-13 18:44:30 28,032 -c----w c:\windows\ServicePackFiles\i386\perm3.sys
+ 2008-04-14 00:10:34 259,328 -c----w c:\windows\ServicePackFiles\i386\perm3dd.dll
+ 2008-04-14 00:12:02 176,128 -c----w c:\windows\ServicePackFiles\i386\photowiz.dll
+ 2008-04-14 00:12:02 35,328 -c----w c:\windows\ServicePackFiles\i386\pid.dll
+ 2008-04-14 00:11:09 24,064 -c----w c:\windows\ServicePackFiles\i386\pidgen.dll
+ 2008-04-14 00:12:31 281,088 -c----w c:\windows\ServicePackFiles\i386\pinball.exe
+ 2008-04-14 00:12:31 17,920 -c----w c:\windows\ServicePackFiles\i386\ping.exe
+ 2008-04-14 00:12:02 15,360 -c----w c:\windows\ServicePackFiles\i386\pjlmon.dll
+ 2008-04-14 00:12:02 44,544 -c----w c:\windows\ServicePackFiles\i386\plotter.dll
+ 2008-04-14 00:12:02 52,736 -c----w c:\windows\ServicePackFiles\i386\plotui.dll
+ 2008-04-14 00:12:02 412,160 -c----w c:\windows\ServicePackFiles\i386\pmh.dll
+ 2008-04-14 00:12:02 39,424 -c----w c:\windows\ServicePackFiles\i386\pngfilt.dll
+ 2008-04-14 00:12:02 58,880 -c----w c:\windows\ServicePackFiles\i386\pnrpnsp.dll
+ 2008-04-14 00:12:02 92,672 -c----w c:\windows\ServicePackFiles\i386\policman.dll
+ 2008-04-14 00:12:02 105,472 -c----w c:\windows\ServicePackFiles\i386\polstore.dll
+ 2008-04-13 19:19:41 146,048 -c----w c:\windows\ServicePackFiles\i386\portcls.sys
+ 2008-04-14 00:12:31 49,152 -c----w c:\windows\ServicePackFiles\i386\powercfg.exe
+ 2008-04-13 18:40:56 8,832 -c----w c:\windows\ServicePackFiles\i386\powerfil.sys
+ 2008-04-14 00:12:03 17,408 -c----w c:\windows\ServicePackFiles\i386\powrprof.dll
+ 2008-04-13 18:41:00 17,664 -c----w c:\windows\ServicePackFiles\i386\ppa3.sys
+ 2008-04-14 00:12:03 560,640 -c----w c:\windows\ServicePackFiles\i386\printui.dll
+ 2008-04-13 18:31:30 35,840 -c----w c:\windows\ServicePackFiles\i386\processr.sys
+ 2008-04-14 00:12:03 27,648 -c----w c:\windows\ServicePackFiles\i386\profmap.dll
+ 2008-04-14 00:12:31 109,568 -c----w c:\windows\ServicePackFiles\i386\progman.exe
+ 2008-04-14 00:12:32 50,176 -c----w c:\windows\ServicePackFiles\i386\proquota.exe
+ 2008-04-14 00:12:03 237,056 -c----w c:\windows\ServicePackFiles\i386\provthrd.dll
+ 2008-04-14 00:12:32 9,216 -c----w c:\windows\ServicePackFiles\i386\proxycfg.exe
+ 2008-04-14 00:12:03 728,576 -c----w c:\windows\ServicePackFiles\i386\ps5ui.dll
+ 2008-04-14 00:12:03 23,040 -c----w c:\windows\ServicePackFiles\i386\psapi.dll
+ 2008-04-14 00:12:03 96,768 -c----w c:\windows\ServicePackFiles\i386\psbase.dll
+ 2008-04-13 18:56:38 69,120 -c----w c:\windows\ServicePackFiles\i386\psched.sys
+ 2008-04-14 00:12:03 543,232 -c----w c:\windows\ServicePackFiles\i386\pscript5.dll
+ 2008-04-14 00:12:03 363,520 -c----w c:\windows\ServicePackFiles\i386\psisdecd.dll
+ 2008-04-14 00:12:03 43,520 -c----w c:\windows\ServicePackFiles\i386\pstorec.dll
+ 2008-04-14 00:12:03 34,304 -c----w c:\windows\ServicePackFiles\i386\pstorsvc.dll
+ 2008-04-14 00:12:03 159,232 -c----w c:\windows\ServicePackFiles\i386\ptpusd.dll
+ 2008-04-14 00:12:03 7,680 -c----w c:\windows\ServicePackFiles\i386\pwsdata.dll
+ 2008-04-14 00:12:03 150,528 -c----w c:\windows\ServicePackFiles\i386\qagent.dll
+ 2008-04-14 00:12:03 291,328 -c----w c:\windows\ServicePackFiles\i386\qagentrt.dll
+ 2008-04-14 00:12:03 237,568 -c----w c:\windows\ServicePackFiles\i386\qasf.dll
+ 2008-04-14 00:12:03 192,512 -c----w c:\windows\ServicePackFiles\i386\qcap.dll
+ 2008-04-14 00:12:03 62,464 -c----w c:\windows\ServicePackFiles\i386\qcliprov.dll
+ 2008-04-14 00:12:03 279,040 -c----w c:\windows\ServicePackFiles\i386\qdv.dll
+ 2008-04-14 00:12:03 386,048 -c----w c:\windows\ServicePackFiles\i386\qdvd.dll
+ 2008-04-14 00:12:03 562,176 -c----w c:\windows\ServicePackFiles\i386\qedit.dll
+ 2008-04-13 17:21:32 733,696 -c----w c:\windows\ServicePackFiles\i386\qedwipes.dll
+ 2008-04-13 18:40:52 6,016 -c----w c:\windows\ServicePackFiles\i386\qic157.sys
+ 2008-04-14 00:12:03 409,088 -c----w c:\windows\ServicePackFiles\i386\qmgr.dll
+ 2008-04-14 00:12:03 18,944 -c----w c:\windows\ServicePackFiles\i386\qmgrprxy.dll
+ 2008-04-14 00:12:32 19,968 -c----w c:\windows\ServicePackFiles\i386\qprocess.exe
+ 2008-04-14 00:12:03 1,288,192 -c----w c:\windows\ServicePackFiles\i386\quartz.dll
+ 2008-04-14 00:12:03 1,435,648 -c----w c:\windows\ServicePackFiles\i386\query.dll
+ 2008-04-14 00:12:03 76,800 -c----w c:\windows\ServicePackFiles\i386\qutil.dll
+ 2008-04-14 00:12:03 43,520 -c----w c:\windows\ServicePackFiles\i386\racpldlg.dll
+ 2008-04-13 18:41:23 20,736 -c----w c:\windows\ServicePackFiles\i386\ramdisk.sys
+ 2008-04-14 00:12:03 7,680 -c----w c:\windows\ServicePackFiles\i386\rasadhlp.dll
+ 2008-04-14 00:12:03 237,056 -c----w c:\windows\ServicePackFiles\i386\rasapi32.dll
+ 2008-04-14 00:12:03 88,576 -c----w c:\windows\ServicePackFiles\i386\rasauto.dll
+ 2008-04-14 00:12:03 79,872 -c----w c:\windows\ServicePackFiles\i386\raschap.dll
+ 2008-04-14 00:12:03 658,432 -c----w c:\windows\ServicePackFiles\i386\rasdlg.dll
+ 2008-04-13 19:19:43 51,328 -c----w c:\windows\ServicePackFiles\i386\rasl2tp.sys
+ 2008-04-14 00:12:03 61,440 -c----w c:\windows\ServicePackFiles\i386\rasman.dll
+ 2008-04-14 00:12:03 186,368 -c----w c:\windows\ServicePackFiles\i386\rasmans.dll
+ 2008-04-14 00:12:32 56,832 -c----w c:\windows\ServicePackFiles\i386\rasphone.exe
+ 2008-04-14 00:12:03 210,944 -c----w c:\windows\ServicePackFiles\i386\rasppp.dll
+ 2008-04-13 18:57:32 41,472 -c----w c:\windows\ServicePackFiles\i386\raspppoe.sys
+ 2008-04-13 19:19:48 48,384 -c----w c:\windows\ServicePackFiles\i386\raspptp.sys
+ 2008-04-14 00:12:03 61,952 -c----w c:\windows\ServicePackFiles\i386\rasqec.dll
+ 2008-04-14 00:12:03 16,384 -c----w c:\windows\ServicePackFiles\i386\rassapi.dll
+ 2008-04-14 00:12:03 58,368 -c----w c:\windows\ServicePackFiles\i386\rastapi.dll
+ 2008-04-14 00:12:03 150,016 -c----w c:\windows\ServicePackFiles\i386\rastls.dll
+ 2008-04-14 00:12:03 102,400 -c----w c:\windows\ServicePackFiles\i386\rcbdyctl.dll
+ 2008-04-14 00:12:32 35,840 -c----w c:\windows\ServicePackFiles\i386\rcimlby.exe
+ 2008-04-14 00:12:32 21,504 -c----w c:\windows\ServicePackFiles\i386\rcp.exe
+ 2008-04-13 19:28:39 175,744 -c----w c:\windows\ServicePackFiles\i386\rdbss.sys
+ 2008-04-14 00:12:03 147,968 -c----w c:\windows\ServicePackFiles\i386\rdchost.dll
+ 2008-04-14 00:12:32 62,976 -c----w c:\windows\ServicePackFiles\i386\rdpclip.exe
+ 2008-04-14 00:13:22 92,424 -c----w c:\windows\ServicePackFiles\i386\rdpdd.dll
+ 2008-04-13 18:32:51 196,224 -c----w c:\windows\ServicePackFiles\i386\rdpdr.sys
+ 2008-04-14 00:12:04 19,968 -c----w c:\windows\ServicePackFiles\i386\rdpsnd.dll
+ 2008-04-14 00:13:22 139,656 -c----w c:\windows\ServicePackFiles\i386\rdpwd.sys
+ 2008-04-14 00:13:22 87,176 -c----w c:\windows\ServicePackFiles\i386\rdpwsx.dll
+ 2008-04-14 00:12:32 13,824 -c----w c:\windows\ServicePackFiles\i386\rdsaddin.exe
+ 2008-04-14 00:12:32 67,072 -c----w c:\windows\ServicePackFiles\i386\rdshost.exe
+ 2004-08-04 02:41:40 13,776 -c----w c:\windows\ServicePackFiles\i386\recagent.sys
+ 2008-04-13 18:40:27 57,600 -c----w c:\windows\ServicePackFiles\i386\redbook.sys
+ 2004-08-10 19:00:00 3,338 -c----w c:\windows\ServicePackFiles\i386\redir.exe
+ 2008-04-14 00:12:32 50,176 -c----w c:\windows\ServicePackFiles\i386\reg.exe
+ 2008-04-14 00:12:04 49,664 -c----w c:\windows\ServicePackFiles\i386\regapi.dll
+ 2004-07-20 09:54:16 28,672 -c----w c:\windows\ServicePackFiles\i386\regasm.exe
+ 2004-07-20 09:54:16 32,768 -c----w c:\windows\ServicePackFiles\i386\regcode.dll
+ 2008-04-14 00:12:32 146,432 -c----w c:\windows\ServicePackFiles\i386\regedit.exe
+ 2008-04-14 00:12:04 59,904 -c----w c:\windows\ServicePackFiles\i386\regsvc.dll
+ 2004-07-20 09:54:16 11,264 -c----w c:\windows\ServicePackFiles\i386\regsvcs.exe
+ 2008-04-14 00:12:32 11,776 -c----w c:\windows\ServicePackFiles\i386\regsvr32.exe
+ 2008-04-14 00:12:04 397,824 -c----w c:\windows\ServicePackFiles\i386\regwizc.dll
+ 2008-04-14 00:12:04 60,416 -c----w c:\windows\ServicePackFiles\i386\remotepg.dll
+ 2008-04-14 00:12:04 178,176 -c----w c:\windows\ServicePackFiles\i386\repdrvfs.dll
+ 2008-04-14 00:12:04 58,880 -c----w c:\windows\ServicePackFiles\i386\resutils.dll
+ 2008-04-14 00:12:33 13,824 -c----w c:\windows\ServicePackFiles\i386\rexec.exe
+ 2008-04-13 18:46:32 59,136 -c----w c:\windows\ServicePackFiles\i386\rfcomm.sys
+ 2008-04-14 00:12:04 290,304 -c----w c:\windows\ServicePackFiles\i386\rhttpaa.dll
+ 2008-04-14 00:12:04 123,392 -c----w c:\windows\ServicePackFiles\i386\riafres.dll
+ 2008-04-14 00:12:04 11,776 -c----w c:\windows\ServicePackFiles\i386\riafui1.dll
+ 2008-04-14 00:12:04 11,776 -c----w c:\windows\ServicePackFiles\i386\riafui2.dll
+ 2008-04-14 00:12:04 433,664 -c----w c:\windows\ServicePackFiles\i386\riched20.dll
+ 2008-04-13 18:55:08 202,624 -c----w c:\windows\ServicePackFiles\i386\rmcast.sys
+ 2008-04-13 18:56:49 30,592 -c----w c:\windows\ServicePackFiles\i386\rndismp.sys
+ 2008-04-13 18:56:49 30,592 -c----w c:\windows\ServicePackFiles\i386\rndismpx.sys
+ 2008-04-13 18:40:14 79,104 -c----w c:\windows\ServicePackFiles\i386\rocket.sys
+ 2008-04-14 00:12:04 4,096 -c----w c:\windows\ServicePackFiles\i386\rpcref.dll
+ 2008-04-14 00:12:04 584,704 -c----w c:\windows\ServicePackFiles\i386\rpcrt4.dll
+ 2008-04-14 00:12:04 399,360 -c----w c:\windows\ServicePackFiles\i386\rpcss.dll
+ 2008-04-14 00:12:04 61,440 -c----w c:\windows\ServicePackFiles\i386\rrcm.dll
+ 2008-04-13 17:37:57 208,384 -c----w c:\windows\ServicePackFiles\i386\rsaenh.dll
+ 2008-04-14 00:12:33 14,848 -c----w c:\windows\ServicePackFiles\i386\rsh.exe
+ 2008-04-14 00:12:04 39,936 -c----w c:\windows\ServicePackFiles\i386\rshx32.dll
+ 2008-04-14 00:12:04 18,944 -c----w c:\windows\ServicePackFiles\i386\rsmps.dll
+ 2008-04-14 00:12:33 107,520 -c----w c:\windows\ServicePackFiles\i386\rsnotify.exe
+ 2008-04-14 00:12:33 380,416 -c----w c:\windows\ServicePackFiles\i386\rstrui.exe
+ 2008-04-14 00:12:04 92,672 -c----w c:\windows\ServicePackFiles\i386\rsvpsp.dll
+ 2008-04-14 00:12:33 77,312 -c----w c:\windows\ServicePackFiles\i386\rtcshare.exe
+ 2008-04-14 00:12:04 31,744 -c----w c:\windows\ServicePackFiles\i386\rtipxmib.dll
+ 2004-08-04 02:31:34 20,992 -c----w c:\windows\ServicePackFiles\i386\rtl8139.sys
+ 2008-04-14 00:12:04 44,032 -c----w c:\windows\ServicePackFiles\i386\rtutils.dll
+ 2008-04-14 00:12:33 33,280 -c----w c:\windows\ServicePackFiles\i386\rundll32.exe
+ 2008-04-14 00:12:33 14,336 -c----w c:\windows\ServicePackFiles\i386\runonce.exe
+ 2008-04-14 00:12:04 27,648 -c----w c:\windows\ServicePackFiles\i386\rw001ext.dll
+ 2008-04-14 00:12:04 29,184 -c----w c:\windows\ServicePackFiles\i386\rw330ext.dll
+ 2008-04-14 00:12:04 27,648 -c----w c:\windows\ServicePackFiles\i386\rw430ext.dll
+ 2008-04-14 00:12:04 29,696 -c----w c:\windows\ServicePackFiles\i386\rw450ext.dll
+ 2008-04-14 00:12:04 9,728 -c----w c:\windows\ServicePackFiles\i386\rwnh.dll
+ 2008-04-14 00:12:04 397,056 -c----w c:\windows\ServicePackFiles\i386\s3gnb.dll
+ 2004-08-04 02:29:52 166,912 -c----w c:\windows\ServicePackFiles\i386\s3gnbm.sys
+ 2008-04-14 00:12:04 43,520 -c----w c:\windows\ServicePackFiles\i386\safrcdlg.dll
+ 2008-04-14 00:12:04 29,696 -c----w c:\windows\ServicePackFiles\i386\safrdm.dll
+ 2008-04-14 00:12:04 45,568 -c----w c:\windows\ServicePackFiles\i386\safrslv.dll
+ 2008-04-14 00:12:04 64,000 -c----w c:\windows\ServicePackFiles\i386\samlib.dll
+ 2008-04-14 00:12:04 415,744 -c----w c:\windows\ServicePackFiles\i386\samsrv.dll
+ 2008-04-14 00:12:04 741,376 -c----w c:\windows\ServicePackFiles\i386\sapi.dll
+ 2008-04-14 00:12:33 13,312 -c----w c:\windows\ServicePackFiles\i386\savedump.exe
+ 2008-04-14 00:12:04 270,848 -c----w c:\windows\ServicePackFiles\i386\sbe.dll
+ 2008-04-14 00:12:04 159,232 -c----w c:\windows\ServicePackFiles\i386\sbeio.dll
+ 2008-04-13 18:40:48 43,904 -c----w c:\windows\ServicePackFiles\i386\sbp2port.sys
+ 2008-04-14 00:12:04 69,632 -c----w c:\windows\ServicePackFiles\i386\scarddlg.dll
+ 2008-04-14 00:12:33 95,744 -c----w c:\windows\ServicePackFiles\i386\scardsvr.exe
+ 2004-08-10 19:00:00 169,984 -c----w c:\windows\ServicePackFiles\i386\sccbase.dll
+ 2008-04-14 00:12:05 171,008 -c----w c:\windows\ServicePackFiles\i386\sccsccp.dll
+ 2008-04-14 00:12:05 181,248 -c----w c:\windows\ServicePackFiles\i386\scecli.dll
+ 2008-04-14 00:12:05 314,880 -c----w c:\windows\ServicePackFiles\i386\scesrv.dll
+ 2008-04-14 00:12:05 144,384 -c----w c:\windows\ServicePackFiles\i386\schannel.dll
+ 2008-04-14 00:12:05 192,512 -c----w c:\windows\ServicePackFiles\i386\schedsvc.dll
+ 2008-04-14 00:12:05 20,480 -c----w c:\windows\ServicePackFiles\i386\sclgntfy.dll
+ 2008-04-14 00:12:34 36,352 -c----w c:\windows\ServicePackFiles\i386\scrcons.exe
+ 2008-04-14 00:12:05 215,552 -c----w c:\windows\ServicePackFiles\i386\script.dll
+ 2008-04-14 00:12:05 199,680 -c----w c:\windows\ServicePackFiles\i386\scripta.dll
+ 2008-04-14 00:12:43 9,216 -c----w c:\windows\ServicePackFiles\i386\scrnsave.scr
+ 2008-04-14 00:12:05 180,224 -c----w c:\windows\ServicePackFiles\i386\scrobj.dll
+ 2008-04-14 00:12:05 172,032 -c----w c:\windows\ServicePackFiles\i386\scrrun.dll
+ 2008-04-13 18:40:30 96,384 -c----w c:\windows\ServicePackFiles\i386\scsiport.sys
+ 2008-04-13 18:45:33 11,520 -c----w c:\windows\ServicePackFiles\i386\scsiscan.sys
+ 2008-04-14 00:12:34 121,856 -c----w c:\windows\ServicePackFiles\i386\sctasks.exe
+ 2008-04-14 00:12:34 77,312 -c----w c:\windows\ServicePackFiles\i386\sdbinst.exe
+ 2008-04-13 18:36:44 79,232 -c----w c:\windows\ServicePackFiles\i386\sdbus.sys
+ 2008-04-14 00:12:05 29,184 -c----w c:\windows\ServicePackFiles\i386\sdhcinst.dll
+ 2007-11-13 10:25:53 20,480 -c----w c:\windows\ServicePackFiles\i386\secdrv.sys
+ 2008-04-14 00:12:34 18,944 -c----w c:\windows\ServicePackFiles\i386\secedit.exe
+ 2008-04-14 00:12:05 18,944 -c----w c:\windows\ServicePackFiles\i386\seclogon.dll
+ 2006-12-31 11:57:08 4,569 -c----w c:\windows\ServicePackFiles\i386\secupd.dat
+ 2008-04-14 00:12:05 56,320 -c----w c:\windows\ServicePackFiles\i386\secur32.dll
+ 2008-04-14 00:12:05 5,632 -c----w c:\windows\ServicePackFiles\i386\security.dll
+ 2008-04-14 00:12:05 29,184 -c----w c:\windows\ServicePackFiles\i386\sendcmsg.dll
+ 2008-04-14 00:12:05 54,784 -c----w c:\windows\ServicePackFiles\i386\sendmail.dll
+ 2008-04-14 00:12:05 39,424 -c----w c:\windows\ServicePackFiles\i386\sens.dll
+ 2008-04-14 00:12:05 7,168 -c----w c:\windows\ServicePackFiles\i386\sensapi.dll
+ 2008-04-14 00:12:05 221,696 -c----w c:\windows\ServicePackFiles\i386\seo.dll
+ 2008-04-13 18:40:12 15,744 -c----w c:\windows\ServicePackFiles\i386\serenum.sys
+ 2008-04-13 19:15:45 64,512 -c----w c:\windows\ServicePackFiles\i386\serial.sys
+ 2008-04-14 00:12:05 56,320 -c----w c:\windows\ServicePackFiles\i386\servdeps.dll
+ 2008-04-14 00:12:34 108,544 -c----w c:\windows\ServicePackFiles\i386\services.exe
+ 2008-04-14 00:12:34 141,312 -c----w c:\windows\ServicePackFiles\i386\sessmgr.exe
+ 2008-04-14 00:12:34 31,232 -c----w c:\windows\ServicePackFiles\i386\sethc.exe
+ 2007-12-17 11:59:54 66,592 -c----w c:\windows\ServicePackFiles\i386\setregni.exe
+ 2008-04-14 00:12:34 23,040 -c----w c:\windows\ServicePackFiles\i386\setup.exe
+ 2008-04-14 00:12:34 73,216 -c----w c:\windows\ServicePackFiles\i386\setup50.exe
+ 2008-04-14 09:42:06 985,088 -c----w c:\windows\ServicePackFiles\i386\setupapi.dll
+ 2008-04-14 00:12:35 32,768 -c----w c:\windows\ServicePackFiles\i386\setupn.exe
+ 2008-04-14 00:12:05 101,376 -c----w c:\windows\ServicePackFiles\i386\setupqry.dll
+ 2008-04-14 00:12:05 5,120 -c----w c:\windows\ServicePackFiles\i386\sfc.dll
+ 2008-04-14 00:12:05 140,288 -c----w c:\windows\ServicePackFiles\i386\sfc_os.dll
+ 2008-04-14 00:12:05 1,614,848 -c----w c:\windows\ServicePackFiles\i386\sfcfiles.dll

EasyEEE
2008-12-29, 18:12
+ 2008-04-13 18:40:47 11,904 -c----w c:\windows\ServicePackFiles\i386\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 -c----w c:\windows\ServicePackFiles\i386\sffp_mmc.sys
+ 2008-04-13 18:40:47 11,008 -c----w c:\windows\ServicePackFiles\i386\sffp_sd.sys
+ 2008-04-13 18:40:48 11,392 -c----w c:\windows\ServicePackFiles\i386\sfloppy.sys
+ 2008-04-13 17:03:19 549,376 -c----w c:\windows\ServicePackFiles\i386\shdoclc.dll
+ 2008-04-14 00:12:05 1,499,136 -c----w c:\windows\ServicePackFiles\i386\shdocvw.dll
+ 2008-04-14 00:12:05 8,461,312 -c----w c:\windows\ServicePackFiles\i386\shell32.dll
+ 2008-04-14 00:12:05 25,088 -c----w c:\windows\ServicePackFiles\i386\shfolder.dll
+ 2008-04-14 00:12:05 68,096 -c----w c:\windows\ServicePackFiles\i386\shgina.dll
+ 2008-04-14 00:12:05 65,024 -c----w c:\windows\ServicePackFiles\i386\shimeng.dll
+ 2008-04-14 00:12:05 438,272 -c----w c:\windows\ServicePackFiles\i386\shimgvw.dll
+ 2008-04-14 00:12:05 474,112 -c----w c:\windows\ServicePackFiles\i386\shlwapi.dll
+ 2008-04-14 00:12:35 45,056 -c----w c:\windows\ServicePackFiles\i386\shmgrate.exe
+ 2008-04-14 00:12:35 77,824 -c----w c:\windows\ServicePackFiles\i386\shrpubw.exe
+ 2008-04-14 00:12:05 27,648 -c----w c:\windows\ServicePackFiles\i386\shscrap.dll
+ 2008-04-14 00:12:05 135,168 -c----w c:\windows\ServicePackFiles\i386\shsvcs.dll
+ 2008-04-14 00:12:05 20,536 -c----w c:\windows\ServicePackFiles\i386\shtml.dll
+ 2008-04-14 00:12:35 16,437 -c----w c:\windows\ServicePackFiles\i386\shtml.exe
+ 2008-04-14 00:12:35 19,456 -c----w c:\windows\ServicePackFiles\i386\shutdown.exe
+ 2008-04-14 00:12:05 13,312 -c----w c:\windows\ServicePackFiles\i386\sigtab.dll
+ 2008-04-14 00:12:35 70,144 -c----w c:\windows\ServicePackFiles\i386\sigverif.exe
+ 2008-04-14 00:12:05 3,901 -c----w c:\windows\ServicePackFiles\i386\siint5.dll
+ 2008-04-13 18:36:39 40,960 -c----w c:\windows\ServicePackFiles\i386\sisagp.sys
+ 2004-08-04 02:31:36 32,768 -c----w c:\windows\ServicePackFiles\i386\sisnic.sys
+ 2008-04-14 00:12:35 26,112 -c----w c:\windows\ServicePackFiles\i386\skeys.exe
+ 2004-08-04 02:31:42 63,547 -c----w c:\windows\ServicePackFiles\i386\sla30nd5.sys
+ 2008-04-14 00:12:06 25,088 -c----w c:\windows\ServicePackFiles\i386\slayerxp.dll
+ 2004-08-10 19:00:00 306,176 -c----w c:\windows\ServicePackFiles\i386\slbcsp.dll
+ 2008-04-14 00:12:06 98,304 -c----w c:\windows\ServicePackFiles\i386\slbiop.dll
+ 2008-04-14 00:12:06 73,832 -c----w c:\windows\ServicePackFiles\i386\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 -c----w c:\windows\ServicePackFiles\i386\slextspk.dll
+ 2008-04-14 00:12:06 188,508 -c----w c:\windows\ServicePackFiles\i386\slgen.dll
+ 2008-04-13 18:46:23 11,136 -c----w c:\windows\ServicePackFiles\i386\slip.sys
+ 2004-08-04 02:41:42 129,535 -c----w c:\windows\ServicePackFiles\i386\slnt7554.sys
+ 2004-08-04 02:41:44 404,990 -c----w c:\windows\ServicePackFiles\i386\slntamr.sys
+ 2004-08-04 02:41:46 95,424 -c----w c:\windows\ServicePackFiles\i386\slnthal.sys
+ 2008-04-14 00:12:35 32,866 -c----w c:\windows\ServicePackFiles\i386\slrundll.exe
+ 2008-04-14 00:12:35 73,796 -c----w c:\windows\ServicePackFiles\i386\slserv.exe
+ 2004-08-04 02:41:46 13,240 -c----w c:\windows\ServicePackFiles\i386\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 -c----w c:\windows\ServicePackFiles\i386\smbali.sys
+ 2008-04-13 18:36:33 16,000 -c----w c:\windows\ServicePackFiles\i386\smbbatt.sys
+ 2008-04-13 18:36:33 6,912 -c----w c:\windows\ServicePackFiles\i386\smbclass.sys
+ 2008-04-14 00:12:35 8,192 -c----w c:\windows\ServicePackFiles\i386\smbinst.exe
+ 2008-04-14 00:12:35 236,544 -c----w c:\windows\ServicePackFiles\i386\smi2smir.exe
+ 2008-04-14 00:12:06 362,496 -c----w c:\windows\ServicePackFiles\i386\smlogcfg.dll
+ 2008-04-14 00:12:35 89,600 -c----w c:\windows\ServicePackFiles\i386\smlogsvc.exe
+ 2008-04-14 00:12:36 50,688 -c----w c:\windows\ServicePackFiles\i386\smss.exe
+ 2008-04-14 00:12:06 189,440 -c----w c:\windows\ServicePackFiles\i386\smtpadm.dll
+ 2008-04-14 00:12:06 10,752 -c----w c:\windows\ServicePackFiles\i386\smtpapi.dll
+ 2008-04-14 00:12:06 2,134,528 -c----w c:\windows\ServicePackFiles\i386\smtpsnap.dll
+ 2008-04-14 00:12:06 456,192 -c----w c:\windows\ServicePackFiles\i386\smtpsvc.dll
+ 2008-04-14 00:12:36 131,584 -c----w c:\windows\ServicePackFiles\i386\sndrec32.exe
+ 2008-04-14 00:12:06 34,816 -c----w c:\windows\ServicePackFiles\i386\sniffpol.dll
+ 2008-04-14 00:12:36 33,280 -c----w c:\windows\ServicePackFiles\i386\snmp.exe
+ 2008-04-14 00:12:06 18,944 -c----w c:\windows\ServicePackFiles\i386\snmpapi.dll
+ 2008-04-14 00:12:06 259,072 -c----w c:\windows\ServicePackFiles\i386\snmpcl.dll
+ 2008-04-14 00:12:06 358,400 -c----w c:\windows\ServicePackFiles\i386\snmpincl.dll
+ 2008-04-14 00:12:06 6,144 -c----w c:\windows\ServicePackFiles\i386\snmpmib.dll
+ 2008-04-14 00:12:06 188,416 -c----w c:\windows\ServicePackFiles\i386\snmpsmir.dll
+ 2008-04-14 00:12:06 182,272 -c----w c:\windows\ServicePackFiles\i386\snmpsnap.dll
+ 2008-04-14 00:12:06 39,936 -c----w c:\windows\ServicePackFiles\i386\snmpthrd.dll
+ 2008-04-14 00:12:36 8,704 -c----w c:\windows\ServicePackFiles\i386\snmptrap.exe
+ 2008-04-14 00:12:06 130,048 -c----w c:\windows\ServicePackFiles\i386\softkbd.dll
+ 2008-04-13 18:40:52 7,552 -c----w c:\windows\ServicePackFiles\i386\sonyait.sys
+ 2008-04-13 18:46:07 25,344 -c----w c:\windows\ServicePackFiles\i386\sonydcam.sys
+ 2008-04-14 00:12:36 24,576 -c----w c:\windows\ServicePackFiles\i386\sort.exe
+ 2008-04-14 00:12:36 7,680 -c----w c:\windows\ServicePackFiles\i386\spdwnwxp.exe
+ 2008-04-13 16:43:18 62,976 -c----w c:\windows\ServicePackFiles\i386\spgrmr.dll
+ 2008-04-14 00:12:36 538,624 -c----w c:\windows\ServicePackFiles\i386\spider.exe
+ 2008-04-13 18:43:31 12,800 -c----w c:\windows\ServicePackFiles\i386\spiisupd.exe
+ 2008-04-13 18:45:07 6,272 -c----w c:\windows\ServicePackFiles\i386\splitter.sys
+ 2008-04-14 09:42:38 11,264 -c----w c:\windows\ServicePackFiles\i386\spnpinst.exe
+ 2008-04-14 00:12:06 75,264 -c----w c:\windows\ServicePackFiles\i386\spoolss.dll
+ 2008-04-14 00:12:36 57,856 -c----w c:\windows\ServicePackFiles\i386\spoolsv.exe
+ 2008-04-13 18:35:06 186,880 -c----w c:\windows\ServicePackFiles\i386\spra0401.dll
+ 2008-04-13 18:35:08 189,440 -c----w c:\windows\ServicePackFiles\i386\spra0402.dll
+ 2008-04-13 18:35:09 161,280 -c----w c:\windows\ServicePackFiles\i386\spra0404.dll
+ 2008-04-13 18:35:09 188,928 -c----w c:\windows\ServicePackFiles\i386\spra0405.dll
+ 2008-04-13 18:35:09 192,000 -c----w c:\windows\ServicePackFiles\i386\spra0406.dll
+ 2008-04-13 18:35:21 199,680 -c----w c:\windows\ServicePackFiles\i386\spra0407.dll
+ 2008-04-13 18:35:11 197,632 -c----w c:\windows\ServicePackFiles\i386\spra0408.dll
+ 2008-04-13 18:35:11 186,368 -c----w c:\windows\ServicePackFiles\i386\spra040b.dll
+ 2008-04-13 18:35:20 197,632 -c----w c:\windows\ServicePackFiles\i386\spra040c.dll
+ 2008-04-13 18:35:21 181,760 -c----w c:\windows\ServicePackFiles\i386\spra040d.dll
+ 2008-04-13 18:35:23 195,584 -c----w c:\windows\ServicePackFiles\i386\spra040e.dll
+ 2008-04-13 18:35:23 195,072 -c----w c:\windows\ServicePackFiles\i386\spra0410.dll
+ 2008-04-13 18:35:23 171,008 -c----w c:\windows\ServicePackFiles\i386\spra0411.dll
+ 2008-04-13 18:35:23 167,936 -c----w c:\windows\ServicePackFiles\i386\spra0412.dll
+ 2008-04-13 18:35:25 196,096 -c----w c:\windows\ServicePackFiles\i386\spra0413.dll
+ 2008-04-13 18:35:25 189,440 -c----w c:\windows\ServicePackFiles\i386\spra0414.dll
+ 2008-04-13 18:35:26 194,560 -c----w c:\windows\ServicePackFiles\i386\spra0415.dll
+ 2008-04-13 18:35:08 192,512 -c----w c:\windows\ServicePackFiles\i386\spra0416.dll
+ 2008-04-13 18:35:27 190,464 -c----w c:\windows\ServicePackFiles\i386\spra0418.dll
+ 2008-04-13 18:35:27 192,512 -c----w c:\windows\ServicePackFiles\i386\spra0419.dll
+ 2008-04-13 18:35:21 188,928 -c----w c:\windows\ServicePackFiles\i386\spra041a.dll
+ 2008-04-13 18:35:28 192,512 -c----w c:\windows\ServicePackFiles\i386\spra041b.dll
+ 2008-04-13 18:35:28 188,928 -c----w c:\windows\ServicePackFiles\i386\spra041d.dll
+ 2008-04-13 18:35:29 188,416 -c----w c:\windows\ServicePackFiles\i386\spra041e.dll
+ 2008-04-13 18:35:30 188,928 -c----w c:\windows\ServicePackFiles\i386\spra041f.dll
+ 2008-04-13 18:35:28 192,512 -c----w c:\windows\ServicePackFiles\i386\spra0424.dll
+ 2008-04-13 18:35:11 186,880 -c----w c:\windows\ServicePackFiles\i386\spra0425.dll
+ 2008-04-13 18:35:24 188,928 -c----w c:\windows\ServicePackFiles\i386\spra0426.dll
+ 2008-04-13 18:35:24 189,952 -c----w c:\windows\ServicePackFiles\i386\spra0427.dll
+ 2008-04-13 18:35:06 161,280 -c----w c:\windows\ServicePackFiles\i386\spra0804.dll
+ 2008-04-13 18:35:26 194,560 -c----w c:\windows\ServicePackFiles\i386\spra0816.dll
+ 2008-04-13 18:35:11 196,096 -c----w c:\windows\ServicePackFiles\i386\spra0c0a.dll
+ 2008-04-13 18:35:49 2,869,248 -c----w c:\windows\ServicePackFiles\i386\sprb0401.dll
+ 2008-04-13 18:36:10 477,696 -c----w c:\windows\ServicePackFiles\i386\sprb0404.dll
+ 2008-04-13 18:36:10 734,720 -c----w c:\windows\ServicePackFiles\i386\sprb0405.dll
+ 2008-04-13 18:36:10 742,912 -c----w c:\windows\ServicePackFiles\i386\sprb0406.dll
+ 2008-04-13 18:37:03 788,480 -c----w c:\windows\ServicePackFiles\i386\sprb0407.dll
+ 2008-04-13 18:36:35 801,280 -c----w c:\windows\ServicePackFiles\i386\sprb0408.dll
+ 2008-04-13 18:36:39 729,088 -c----w c:\windows\ServicePackFiles\i386\sprb040b.dll
+ 2008-04-13 18:36:55 793,088 -c----w c:\windows\ServicePackFiles\i386\sprb040c.dll
+ 2008-04-13 18:37:07 2,842,112 -c----w c:\windows\ServicePackFiles\i386\sprb040d.dll
+ 2008-04-13 18:37:22 769,536 -c----w c:\windows\ServicePackFiles\i386\sprb040e.dll
+ 2008-04-13 18:37:22 769,536 -c----w c:\windows\ServicePackFiles\i386\sprb0410.dll
+ 2008-04-13 18:37:34 562,688 -c----w c:\windows\ServicePackFiles\i386\sprb0411.dll
+ 2008-04-13 18:37:37 543,744 -c----w c:\windows\ServicePackFiles\i386\sprb0412.dll
+ 2008-04-13 18:38:00 769,024 -c----w c:\windows\ServicePackFiles\i386\sprb0413.dll
+ 2008-04-13 18:38:02 716,288 -c----w c:\windows\ServicePackFiles\i386\sprb0414.dll
+ 2008-04-13 18:38:05 759,808 -c----w c:\windows\ServicePackFiles\i386\sprb0415.dll
+ 2008-04-13 18:35:43 752,128 -c----w c:\windows\ServicePackFiles\i386\sprb0416.dll
+ 2008-04-13 18:38:28 736,768 -c----w c:\windows\ServicePackFiles\i386\sprb0419.dll
+ 2008-04-13 18:38:37 757,248 -c----w c:\windows\ServicePackFiles\i386\sprb041b.dll
+ 2008-04-13 18:38:47 724,480 -c----w c:\windows\ServicePackFiles\i386\sprb041d.dll
+ 2008-04-13 18:38:51 724,480 -c----w c:\windows\ServicePackFiles\i386\sprb041f.dll
+ 2008-04-13 18:38:36 732,160 -c----w c:\windows\ServicePackFiles\i386\sprb0424.dll
+ 2008-04-13 18:35:54 470,016 -c----w c:\windows\ServicePackFiles\i386\sprb0804.dll
+ 2008-04-13 18:38:06 751,616 -c----w c:\windows\ServicePackFiles\i386\sprb0816.dll
+ 2008-04-13 18:36:38 773,632 -c----w c:\windows\ServicePackFiles\i386\sprb0c0a.dll
+ 2008-04-13 18:39:02 656,896 -c----w c:\windows\ServicePackFiles\i386\sprc0401.dll
+ 2008-04-13 18:39:13 327,680 -c----w c:\windows\ServicePackFiles\i386\sprc0404.dll
+ 2008-04-13 18:39:02 601,088 -c----w c:\windows\ServicePackFiles\i386\sprc0405.dll
+ 2008-04-13 18:39:12 605,696 -c----w c:\windows\ServicePackFiles\i386\sprc0406.dll
+ 2008-04-13 18:39:19 663,552 -c----w c:\windows\ServicePackFiles\i386\sprc0407.dll
+ 2008-04-13 18:39:12 679,936 -c----w c:\windows\ServicePackFiles\i386\sprc0408.dll
+ 2008-04-13 18:39:17 604,672 -c----w c:\windows\ServicePackFiles\i386\sprc040b.dll
+ 2008-04-13 18:39:20 663,040 -c----w c:\windows\ServicePackFiles\i386\sprc040c.dll
+ 2008-04-13 18:39:28 620,544 -c----w c:\windows\ServicePackFiles\i386\sprc040d.dll
+ 2008-04-13 18:39:28 645,120 -c----w c:\windows\ServicePackFiles\i386\sprc040e.dll
+ 2008-04-13 18:39:28 658,432 -c----w c:\windows\ServicePackFiles\i386\sprc0410.dll
+ 2008-04-13 18:39:49 412,672 -c----w c:\windows\ServicePackFiles\i386\sprc0411.dll
+ 2008-04-13 18:39:49 392,704 -c----w c:\windows\ServicePackFiles\i386\sprc0412.dll
+ 2008-04-13 18:39:47 645,120 -c----w c:\windows\ServicePackFiles\i386\sprc0413.dll
+ 2008-04-13 18:39:48 591,872 -c----w c:\windows\ServicePackFiles\i386\sprc0414.dll
+ 2008-04-13 18:39:52 641,024 -c----w c:\windows\ServicePackFiles\i386\sprc0415.dll
+ 2008-04-13 18:38:56 620,032 -c----w c:\windows\ServicePackFiles\i386\sprc0416.dll
+ 2008-04-13 18:39:56 627,200 -c----w c:\windows\ServicePackFiles\i386\sprc0419.dll
+ 2008-04-13 18:40:04 577,536 -c----w c:\windows\ServicePackFiles\i386\sprc041b.dll
+ 2008-04-13 18:40:05 590,848 -c----w c:\windows\ServicePackFiles\i386\sprc041d.dll
+ 2008-04-13 18:40:09 592,896 -c----w c:\windows\ServicePackFiles\i386\sprc041f.dll
+ 2008-04-13 18:40:05 576,512 -c----w c:\windows\ServicePackFiles\i386\sprc0424.dll
+ 2008-04-13 18:39:03 322,560 -c----w c:\windows\ServicePackFiles\i386\sprc0804.dll
+ 2008-04-13 18:39:53 639,488 -c----w c:\windows\ServicePackFiles\i386\sprc0816.dll
+ 2008-04-13 18:39:13 648,704 -c----w c:\windows\ServicePackFiles\i386\sprc0c0a.dll
+ 2008-04-14 00:12:06 250,368 -c----w c:\windows\ServicePackFiles\i386\sptip.dll
+ 2008-04-14 00:12:36 20,992 -c----w c:\windows\ServicePackFiles\i386\spupdwxp.exe
+ 2008-04-14 00:12:06 151,552 -c----w c:\windows\ServicePackFiles\i386\sqldb20.dll
+ 2008-04-14 00:12:06 528,384 -c----w c:\windows\ServicePackFiles\i386\sqloledb.dll
+ 2008-04-14 00:12:06 462,848 -c----w c:\windows\ServicePackFiles\i386\sqlqp20.dll
+ 2008-04-14 00:12:06 110,592 -c----w c:\windows\ServicePackFiles\i386\sqlse20.dll
+ 2008-04-14 00:12:06 442,368 -c----w c:\windows\ServicePackFiles\i386\sqlsrv32.dll
+ 2008-04-14 00:12:06 180,800 -c----w c:\windows\ServicePackFiles\i386\sqlunirl.dll
+ 2008-04-14 00:12:06 217,088 -c----w c:\windows\ServicePackFiles\i386\sqlxmlx.dll
+ 2008-04-13 18:36:52 73,472 -c----w c:\windows\ServicePackFiles\i386\sr.sys
+ 2008-04-14 00:12:06 58,434 -c----w c:\windows\ServicePackFiles\i386\srchctls.dll
+ 2008-04-14 00:12:07 726,078 -c----w c:\windows\ServicePackFiles\i386\srchui.dll
+ 2008-04-14 00:12:07 67,584 -c----w c:\windows\ServicePackFiles\i386\srclient.dll
+ 2008-04-14 00:12:07 239,104 -c----w c:\windows\ServicePackFiles\i386\srrstr.dll
+ 2008-04-14 00:12:07 171,008 -c----w c:\windows\ServicePackFiles\i386\srsvc.dll
+ 2008-04-13 19:15:11 334,848 -c----w c:\windows\ServicePackFiles\i386\srv.sys
+ 2008-04-14 00:12:07 96,768 -c----w c:\windows\ServicePackFiles\i386\srvsvc.dll
+ 2008-04-14 00:12:43 704,512 -c----w c:\windows\ServicePackFiles\i386\ss3dfo.scr
+ 2008-04-14 00:12:43 19,968 -c----w c:\windows\ServicePackFiles\i386\ssbezier.scr
+ 2008-04-14 00:12:07 34,816 -c----w c:\windows\ServicePackFiles\i386\ssdpapi.dll
+ 2008-04-14 00:12:07 71,680 -c----w c:\windows\ServicePackFiles\i386\ssdpsrv.dll
+ 2008-04-14 00:12:43 393,216 -c----w c:\windows\ServicePackFiles\i386\ssflwbox.scr
+ 2008-04-14 00:12:07 45,056 -c----w c:\windows\ServicePackFiles\i386\ssinc51.dll
+ 2008-04-14 00:12:44 20,992 -c----w c:\windows\ServicePackFiles\i386\ssmarque.scr
+ 2008-04-14 00:12:44 47,104 -c----w c:\windows\ServicePackFiles\i386\ssmypics.scr
+ 2008-04-14 00:12:44 18,944 -c----w c:\windows\ServicePackFiles\i386\ssmyst.scr
+ 2008-04-14 00:12:07 46,592 -c----w c:\windows\ServicePackFiles\i386\sspifilt.dll
+ 2008-04-14 00:12:44 610,304 -c----w c:\windows\ServicePackFiles\i386\sspipes.scr
+ 2008-04-14 00:12:44 14,336 -c----w c:\windows\ServicePackFiles\i386\ssstars.scr
+ 2008-04-14 00:12:44 679,936 -c----w c:\windows\ServicePackFiles\i386\sstext3d.scr
+ 2008-04-14 00:12:07 33,280 -c----w c:\windows\ServicePackFiles\i386\sstub.dll
+ 2008-04-14 00:12:07 8,192 -c----w c:\windows\ServicePackFiles\i386\staxmem.dll
+ 2008-04-14 00:12:07 59,392 -c----w c:\windows\ServicePackFiles\i386\stclient.dll
+ 2008-04-14 00:12:07 86,528 -c----w c:\windows\ServicePackFiles\i386\stdprov.dll
+ 2008-04-14 00:12:07 68,096 -c----w c:\windows\ServicePackFiles\i386\sti.dll
+ 2008-04-14 00:12:07 136,704 -c----w c:\windows\ServicePackFiles\i386\sti_ci.dll
+ 2008-04-14 00:12:36 14,848 -c----w c:\windows\ServicePackFiles\i386\stimon.exe
+ 2008-04-14 00:12:07 121,856 -c----w c:\windows\ServicePackFiles\i386\stobject.dll
+ 2008-04-14 00:12:07 74,752 -c----w c:\windows\ServicePackFiles\i386\storprop.dll
+ 2008-04-13 18:45:15 49,408 -c----w c:\windows\ServicePackFiles\i386\stream.sys
+ 2008-04-13 18:46:21 15,232 -c----w c:\windows\ServicePackFiles\i386\streamip.sys
+ 2008-04-14 00:12:07 75,776 -c----w c:\windows\ServicePackFiles\i386\strmfilt.dll
+ 2008-04-14 00:12:36 16,449 -c----w c:\windows\ServicePackFiles\i386\stub_fpsrvadm.exe
+ 2008-04-14 00:12:36 65,601 -c----w c:\windows\ServicePackFiles\i386\stub_fpsrvwin.exe
+ 2008-04-14 00:12:07 46,592 -c----w c:\windows\ServicePackFiles\i386\svcext51.dll
+ 2008-04-14 00:12:36 14,336 -c----w c:\windows\ServicePackFiles\i386\svchost.exe
+ 2008-04-13 18:39:53 4,352 -c----w c:\windows\ServicePackFiles\i386\swenum.sys
+ 2008-04-13 18:45:09 56,576 -c----w c:\windows\ServicePackFiles\i386\swmidi.sys
+ 2008-04-14 00:12:07 713,216 -c----w c:\windows\ServicePackFiles\i386\sxs.dll
+ 2007-12-17 11:59:56 1,179,648 -c----w c:\windows\ServicePackFiles\i386\sy52106.dll
+ 2008-04-14 00:12:07 57,856 -c----w c:\windows\ServicePackFiles\i386\synceng.dll
+ 2008-04-14 00:12:07 191,488 -c----w c:\windows\ServicePackFiles\i386\syncui.dll
+ 2008-04-13 19:15:55 60,800 -c----w c:\windows\ServicePackFiles\i386\sysaudio.sys
+ 2008-04-14 00:12:36 71,680 -c----w c:\windows\ServicePackFiles\i386\sysinfo.exe
+ 2008-04-14 00:12:07 193,024 -c----w c:\windows\ServicePackFiles\i386\sysmod.dll
+ 2008-04-14 00:12:07 173,568 -c----w c:\windows\ServicePackFiles\i386\sysmoda.dll
+ 2008-04-14 00:12:37 106,496 -c----w c:\windows\ServicePackFiles\i386\sysocmgr.exe
+ 2008-04-14 00:12:07 990,208 -c----w c:\windows\ServicePackFiles\i386\syssetup.dll
+ 2004-07-20 09:54:18 77,824 -c----w c:\windows\ServicePackFiles\i386\system.configuration.install.dll
+ 2004-07-20 09:54:18 1,179,648 -c----w c:\windows\ServicePackFiles\i386\system.data.dll
+ 2004-07-20 09:54:18 1,695,744 -c----w c:\windows\ServicePackFiles\i386\system.design.dll
+ 2004-07-20 09:54:18 86,016 -c----w c:\windows\ServicePackFiles\i386\system.directoryservices.dll
+ 2004-07-20 09:54:18 65,536 -c----w c:\windows\ServicePackFiles\i386\system.drawing.design.dll
+ 2004-07-20 09:54:18 462,848 -c----w c:\windows\ServicePackFiles\i386\system.drawing.dll
+ 2004-07-20 09:54:18 212,992 -c----w c:\windows\ServicePackFiles\i386\system.enterpriseservices.dll
+ 2004-08-04 13:12:34 48,640 -c----w c:\windows\ServicePackFiles\i386\system.enterpriseservices.thunk.dll
+ 2004-07-20 09:54:18 352,256 -c----w c:\windows\ServicePackFiles\i386\system.management.dll
+ 2004-07-20 09:54:18 241,664 -c----w c:\windows\ServicePackFiles\i386\system.messaging.dll
+ 2004-07-20 09:54:20 311,296 -c----w c:\windows\ServicePackFiles\i386\system.runtime.remoting.dll
+ 2004-07-20 09:54:20 131,072 -c----w c:\windows\ServicePackFiles\i386\system.runtime.serialization.formatters.soap.dll
+ 2004-07-20 09:54:20 77,824 -c----w c:\windows\ServicePackFiles\i386\system.security.dll
+ 2004-07-20 09:54:20 126,976 -c----w c:\windows\ServicePackFiles\i386\system.serviceprocess.dll
+ 2007-01-02 21:40:24 1,200,128 -c----w c:\windows\ServicePackFiles\i386\system.web.dll
+ 2004-07-20 09:54:20 61,440 -c----w c:\windows\ServicePackFiles\i386\system.web.regularexpressions.dll
+ 2004-07-20 09:54:20 507,904 -c----w c:\windows\ServicePackFiles\i386\system.web.services.dll
+ 2004-07-20 09:54:22 2,002,944 -c----w c:\windows\ServicePackFiles\i386\system.windows.forms.dll
+ 2004-07-20 09:54:22 1,302,528 -c----w c:\windows\ServicePackFiles\i386\system.xml.dll
+ 2008-04-14 00:12:07 117,760 -c----w c:\windows\ServicePackFiles\i386\t2embed.dll
+ 2008-04-14 00:12:07 33,792 -c----w c:\windows\ServicePackFiles\i386\tabletoc.dll
+ 2008-04-13 18:40:50 14,976 -c----w c:\windows\ServicePackFiles\i386\tape.sys
+ 2008-04-14 00:12:07 858,624 -c----w c:\windows\ServicePackFiles\i386\tapi3.dll
+ 2008-04-14 00:12:07 181,760 -c----w c:\windows\ServicePackFiles\i386\tapi32.dll
+ 2008-04-14 00:12:07 249,856 -c----w c:\windows\ServicePackFiles\i386\tapisrv.dll
+ 2008-04-14 00:12:37 76,288 -c----w c:\windows\ServicePackFiles\i386\taskkill.exe
+ 2008-04-14 00:12:37 77,824 -c----w c:\windows\ServicePackFiles\i386\tasklist.exe
+ 2008-04-14 00:12:37 135,680 -c----w c:\windows\ServicePackFiles\i386\taskmgr.exe
+ 2008-04-13 19:20:16 361,344 -c----w c:\windows\ServicePackFiles\i386\tcpip.sys
+ 2008-04-13 19:00:02 225,664 -c----w c:\windows\ServicePackFiles\i386\tcpip6.sys
+ 2008-04-14 00:12:07 14,848 -c----w c:\windows\ServicePackFiles\i386\tcpmib.dll
+ 2008-04-14 00:12:07 45,568 -c----w c:\windows\ServicePackFiles\i386\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 -c----w c:\windows\ServicePackFiles\i386\tcpmonui.dll
+ 2008-04-14 00:12:37 32,827 -c----w c:\windows\ServicePackFiles\i386\tcptest.exe
+ 2007-04-02 16:36:07 16,384 -c----w c:\windows\ServicePackFiles\i386\tcptsat.dll
+ 2008-04-13 19:00:05 19,072 -c----w c:\windows\ServicePackFiles\i386\tdi.sys
+ 2008-04-14 00:13:20 12,040 -c----w c:\windows\ServicePackFiles\i386\tdpipe.sys
+ 2008-04-14 00:13:21 21,896 -c----w c:\windows\ServicePackFiles\i386\tdtcp.sys
+ 2008-04-14 00:12:37 75,776 -c----w c:\windows\ServicePackFiles\i386\telnet.exe
+ 2008-04-14 00:13:20 40,840 -c----w c:\windows\ServicePackFiles\i386\termdd.sys
+ 2008-04-14 00:12:07 358,400 -c----w c:\windows\ServicePackFiles\i386\termmgr.dll
+ 2008-04-14 00:12:07 295,424 -c----w c:\windows\ServicePackFiles\i386\termsrv.dll

EasyEEE
2008-12-29, 18:13
+ 2008-04-13 18:40:50 149,376 -c----w c:\windows\ServicePackFiles\i386\tffsport.sys
+ 2008-04-14 00:12:07 385,536 -c----w c:\windows\ServicePackFiles\i386\themeui.dll
+ 2008-04-14 00:12:37 61,440 -c----w c:\windows\ServicePackFiles\i386\tlntadmn.exe
+ 2008-04-14 00:12:37 78,336 -c----w c:\windows\ServicePackFiles\i386\tlntsess.exe
+ 2008-04-14 00:12:38 73,216 -c----w c:\windows\ServicePackFiles\i386\tlntsvr.exe
+ 2008-04-14 00:12:07 7,168 -c----w c:\windows\ServicePackFiles\i386\tlntsvrp.dll
+ 2007-12-17 12:00:05 66,592 -c----w c:\windows\ServicePackFiles\i386\togac.exe
+ 2008-04-14 00:12:07 33,792 -c----w c:\windows\ServicePackFiles\i386\tools.dll
+ 2008-04-14 00:12:38 347,136 -c----w c:\windows\ServicePackFiles\i386\tourstrt.exe
+ 2008-04-14 00:12:38 82,944 -c----w c:\windows\ServicePackFiles\i386\tp4mon.exe
+ 2008-04-14 00:12:38 259,584 -c----w c:\windows\ServicePackFiles\i386\tracerpt.exe
+ 2008-04-14 00:12:38 12,288 -c----w c:\windows\ServicePackFiles\i386\tracert.exe
+ 2008-04-14 00:12:42 12,800 -c----w c:\windows\ServicePackFiles\i386\tree.com
+ 2008-04-14 00:12:07 153,088 -c----w c:\windows\ServicePackFiles\i386\triedit.dll
+ 2008-04-14 00:12:07 90,112 -c----w c:\windows\ServicePackFiles\i386\trkwks.dll
+ 2008-01-18 15:13:09 2,247 -c----w c:\windows\ServicePackFiles\i386\tscdsbl.bat
+ 2008-04-14 00:12:07 93,696 -c----w c:\windows\ServicePackFiles\i386\tscfgwmi.dll
+ 2007-12-12 10:33:51 18,917 -c----w c:\windows\ServicePackFiles\i386\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 -c----w c:\windows\ServicePackFiles\i386\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 -c----w c:\windows\ServicePackFiles\i386\tscupdc.dll
+ 2008-04-14 00:13:21 12,168 -c----w c:\windows\ServicePackFiles\i386\tsddd.dll
+ 2008-04-14 00:12:07 53,248 -c----w c:\windows\ServicePackFiles\i386\tsgqec.dll
+ 2008-04-14 00:12:07 279,040 -c----w c:\windows\ServicePackFiles\i386\tshoot.dll
+ 2008-04-14 00:12:07 130,048 -c----w c:\windows\ServicePackFiles\i386\tsoc.dll
+ 2008-04-14 00:12:07 50,688 -c----w c:\windows\ServicePackFiles\i386\tspkg.dll
+ 2008-04-14 00:12:07 8,704 -c----w c:\windows\ServicePackFiles\i386\tty.dll
+ 2007-04-02 15:31:00 39,936 -c----w c:\windows\ServicePackFiles\i386\ttyres.dll
+ 2008-04-14 00:12:07 16,384 -c----w c:\windows\ServicePackFiles\i386\ttyui.dll
+ 2008-04-13 18:56:01 12,288 -c----w c:\windows\ServicePackFiles\i386\tunmp.sys
+ 2008-04-14 00:12:07 50,688 -c----w c:\windows\ServicePackFiles\i386\twain_32.dll
+ 2008-04-14 00:12:07 57,856 -c----w c:\windows\ServicePackFiles\i386\twext.dll
+ 2008-04-14 00:12:07 101,376 -c----w c:\windows\ServicePackFiles\i386\txflog.dll
+ 2008-04-14 00:12:38 60,416 -c----w c:\windows\ServicePackFiles\i386\tzchange.exe
+ 2008-04-13 18:36:40 44,672 -c----w c:\windows\ServicePackFiles\i386\uagp35.sys
+ 2008-04-13 18:32:36 66,048 -c----w c:\windows\ServicePackFiles\i386\udfs.sys
+ 2008-04-14 00:12:07 26,624 -c----w c:\windows\ServicePackFiles\i386\udhisapi.dll
+ 2008-04-14 00:12:07 103,424 -c----w c:\windows\ServicePackFiles\i386\uihelper.dll
+ 2008-04-14 00:12:07 275,456 -c----w c:\windows\ServicePackFiles\i386\ulib.dll
+ 2008-04-14 00:12:07 35,840 -c----w c:\windows\ServicePackFiles\i386\umandlg.dll
+ 2008-04-14 00:12:07 123,392 -c----w c:\windows\ServicePackFiles\i386\umpnpmgr.dll
+ 2008-04-14 00:12:07 373,248 -c----w c:\windows\ServicePackFiles\i386\unidrv.dll
+ 2008-04-14 00:12:07 744,448 -c----w c:\windows\ServicePackFiles\i386\unidrvui.dll
+ 2008-04-14 00:12:07 74,240 -c----w c:\windows\ServicePackFiles\i386\unimdmat.dll
+ 2008-04-14 00:12:07 13,824 -c----w c:\windows\ServicePackFiles\i386\uniplat.dll
+ 2007-05-15 08:08:53 761,344 -c----w c:\windows\ServicePackFiles\i386\unires.dll
+ 2008-04-14 00:12:07 316,416 -c----w c:\windows\ServicePackFiles\i386\untfs.dll
+ 2008-04-13 18:39:46 384,768 -c----w c:\windows\ServicePackFiles\i386\update.sys
+ 2008-04-14 00:12:38 150,528 -c----w c:\windows\ServicePackFiles\i386\uploadm.exe
+ 2008-04-14 00:12:08 133,632 -c----w c:\windows\ServicePackFiles\i386\upnp.dll
+ 2008-04-14 00:12:38 16,896 -c----w c:\windows\ServicePackFiles\i386\upnpcont.exe
+ 2008-04-14 00:12:08 185,856 -c----w c:\windows\ServicePackFiles\i386\upnphost.dll
+ 2008-04-14 00:12:08 239,616 -c----w c:\windows\ServicePackFiles\i386\upnpui.dll
+ 2008-04-14 00:12:38 18,432 -c----w c:\windows\ServicePackFiles\i386\ups.exe
+ 2008-04-14 00:12:08 37,888 -c----w c:\windows\ServicePackFiles\i386\url.dll
+ 2008-04-14 00:12:08 619,520 -c----w c:\windows\ServicePackFiles\i386\urlmon.dll
+ 2004-08-04 02:31:26 32,384 -c----w c:\windows\ServicePackFiles\i386\usb101et.sys
+ 2008-04-13 18:56:49 12,800 -c----w c:\windows\ServicePackFiles\i386\usb8023.sys
+ 2008-04-13 18:56:49 12,800 -c----w c:\windows\ServicePackFiles\i386\usb8023x.sys
+ 2008-04-13 18:45:12 60,032 -c----w c:\windows\ServicePackFiles\i386\usbaudio.sys
+ 2008-04-13 18:45:40 25,600 -c----w c:\windows\ServicePackFiles\i386\usbcamd.sys
+ 2008-04-13 18:45:41 25,728 -c----w c:\windows\ServicePackFiles\i386\usbcamd2.sys
+ 2008-04-13 18:45:39 32,128 -c----w c:\windows\ServicePackFiles\i386\usbccgp.sys
+ 2008-04-13 18:45:35 30,208 -c----w c:\windows\ServicePackFiles\i386\usbehci.sys
+ 2008-04-13 18:45:37 59,520 -c----w c:\windows\ServicePackFiles\i386\usbhub.sys
+ 2008-04-13 18:45:43 15,872 -c----w c:\windows\ServicePackFiles\i386\usbintel.sys
+ 2008-04-14 00:12:08 16,896 -c----w c:\windows\ServicePackFiles\i386\usbmon.dll
+ 2008-04-13 18:45:35 17,152 -c----w c:\windows\ServicePackFiles\i386\usbohci.sys
+ 2008-04-13 18:45:36 143,872 -c----w c:\windows\ServicePackFiles\i386\usbport.sys
+ 2008-04-13 18:47:37 25,856 -c----w c:\windows\ServicePackFiles\i386\usbprint.sys
+ 2008-04-13 18:45:34 15,104 -c----w c:\windows\ServicePackFiles\i386\usbscan.sys
+ 2008-04-13 18:45:36 26,112 -c----w c:\windows\ServicePackFiles\i386\usbser.sys
+ 2008-04-13 18:45:38 26,368 -c----w c:\windows\ServicePackFiles\i386\usbstor.sys
+ 2008-04-13 18:45:35 20,608 -c----w c:\windows\ServicePackFiles\i386\usbuhci.sys
+ 2008-04-14 00:12:08 74,240 -c----w c:\windows\ServicePackFiles\i386\usbui.dll
+ 2008-04-13 18:46:20 121,984 -c----w c:\windows\ServicePackFiles\i386\usbvideo.sys
+ 2008-04-14 00:12:08 578,560 -c----w c:\windows\ServicePackFiles\i386\user32.dll
+ 2008-04-14 00:12:08 727,040 -c----w c:\windows\ServicePackFiles\i386\userenv.dll
+ 2008-04-14 00:12:38 26,112 -c----w c:\windows\ServicePackFiles\i386\userinit.exe
+ 2008-04-14 00:12:08 406,016 -c----w c:\windows\ServicePackFiles\i386\usp10.dll
+ 2008-04-14 00:12:38 50,176 -c----w c:\windows\ServicePackFiles\i386\utilman.exe
+ 2008-04-14 00:12:08 218,624 -c----w c:\windows\ServicePackFiles\i386\uxtheme.dll
+ 2008-04-14 00:12:08 30,749 -c----w c:\windows\ServicePackFiles\i386\vbajet32.dll
+ 2004-07-20 09:54:22 716,800 -c----w c:\windows\ServicePackFiles\i386\vbc.exe
+ 2004-08-04 13:12:48 126,976 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.chs.dll
+ 2004-08-04 13:12:48 126,976 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.cht.dll
+ 2004-08-04 13:12:48 126,976 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.dll
+ 2004-08-04 13:12:48 147,456 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.es.dll
+ 2004-08-04 13:12:48 151,552 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.fr.dll
+ 2004-08-04 13:12:48 151,552 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.ger.dll
+ 2004-08-04 13:12:50 147,456 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.it.dll
+ 2004-08-04 13:12:50 126,976 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.ja.dll
+ 2004-08-04 13:12:50 126,976 -c----w c:\windows\ServicePackFiles\i386\vbc7ui.kor.dll
+ 2008-04-14 00:12:08 434,176 -c----w c:\windows\ServicePackFiles\i386\vbscript.dll
+ 2008-04-14 00:12:08 11,325 -c----w c:\windows\ServicePackFiles\i386\vchnt5.dll
+ 2008-04-14 00:12:08 26,112 -c----w c:\windows\ServicePackFiles\i386\vdmdbg.dll
+ 2008-04-14 00:12:08 51,712 -c----w c:\windows\ServicePackFiles\i386\vdmredir.dll
+ 2008-04-14 00:12:38 28,672 -c----w c:\windows\ServicePackFiles\i386\verclsid.exe
+ 2008-04-14 00:12:08 26,624 -c----w c:\windows\ServicePackFiles\i386\verifier.dll
+ 2008-04-14 00:12:08 18,944 -c----w c:\windows\ServicePackFiles\i386\version.dll
+ 2008-04-14 00:12:08 53,760 -c----w c:\windows\ServicePackFiles\i386\vfwwdm32.dll
+ 2008-04-13 18:44:40 20,992 -c----w c:\windows\ServicePackFiles\i386\vga.sys
+ 2008-04-14 00:12:08 851,968 -c----w c:\windows\ServicePackFiles\i386\vgx.dll
+ 2008-04-13 18:36:40 42,240 -c----w c:\windows\ServicePackFiles\i386\viaagp.sys
+ 2008-04-13 18:40:31 5,376 -c----w c:\windows\ServicePackFiles\i386\viaide.sys
+ 2008-04-13 18:44:40 81,664 -c----w c:\windows\ServicePackFiles\i386\videoprt.sys
+ 2008-04-14 00:12:08 131,584 -c----w c:\windows\ServicePackFiles\i386\viewprov.dll
+ 2008-04-13 18:41:01 52,352 -c----w c:\windows\ServicePackFiles\i386\volsnap.sys
+ 2004-08-04 13:12:50 999,424 -c----w c:\windows\ServicePackFiles\i386\vsavb7rt.dll
+ 2008-04-14 00:12:08 430,592 -c----w c:\windows\ServicePackFiles\i386\vssapi.dll
+ 2008-04-14 00:12:38 289,792 -c----w c:\windows\ServicePackFiles\i386\vssvc.exe
+ 2008-04-14 00:12:08 175,104 -c----w c:\windows\ServicePackFiles\i386\w32time.dll
+ 2008-04-14 00:12:08 15,872 -c----w c:\windows\ServicePackFiles\i386\w3ssl.dll
+ 2008-04-14 00:12:08 364,032 -c----w c:\windows\ServicePackFiles\i386\w3svc.dll
+ 2008-04-14 00:12:08 483,840 -c----w c:\windows\ServicePackFiles\i386\w95upgnt.dll
+ 2008-04-14 00:12:38 46,080 -c----w c:\windows\ServicePackFiles\i386\wab.exe
+ 2008-04-14 00:12:08 510,976 -c----w c:\windows\ServicePackFiles\i386\wab32.dll
+ 2008-04-13 16:21:48 249,856 -c----w c:\windows\ServicePackFiles\i386\wab32res.dll
+ 2008-04-14 00:12:08 32,768 -c----w c:\windows\ServicePackFiles\i386\wabfind.dll
+ 2008-04-14 00:12:08 85,504 -c----w c:\windows\ServicePackFiles\i386\wabimp.dll
+ 2008-04-14 00:12:39 30,208 -c----w c:\windows\ServicePackFiles\i386\wabmig.exe
+ 2008-04-13 18:43:55 14,208 -c----w c:\windows\ServicePackFiles\i386\wacompen.sys
+ 2004-08-04 02:29:38 12,415 -c----w c:\windows\ServicePackFiles\i386\wadv01nt.sys
+ 2004-08-04 02:29:38 12,127 -c----w c:\windows\ServicePackFiles\i386\wadv02nt.sys
+ 2004-08-04 02:29:38 11,775 -c----w c:\windows\ServicePackFiles\i386\wadv05nt.sys
+ 2004-08-04 02:29:40 11,807 -c----w c:\windows\ServicePackFiles\i386\wadv07nt.sys
+ 2004-08-04 02:29:40 11,295 -c----w c:\windows\ServicePackFiles\i386\wadv08nt.sys
+ 2004-08-04 02:29:42 11,871 -c----w c:\windows\ServicePackFiles\i386\wadv09nt.sys
+ 2004-08-04 02:29:42 11,935 -c----w c:\windows\ServicePackFiles\i386\wadv11nt.sys
+ 2008-04-14 00:12:08 76,800 -c----w c:\windows\ServicePackFiles\i386\wam51.dll
+ 2008-04-14 00:12:08 53,248 -c----w c:\windows\ServicePackFiles\i386\wamreg51.dll
+ 2008-04-13 18:57:21 34,560 -c----w c:\windows\ServicePackFiles\i386\wanarp.sys
+ 2008-04-13 18:44:59 17,664 -c----w c:\windows\ServicePackFiles\i386\watchdog.sys
+ 2004-08-04 02:29:42 29,311 -c----w c:\windows\ServicePackFiles\i386\watv01nt.sys
+ 2004-08-04 02:29:44 19,551 -c----w c:\windows\ServicePackFiles\i386\watv02nt.sys
+ 2004-08-04 02:29:44 33,599 -c----w c:\windows\ServicePackFiles\i386\watv04nt.sys
+ 2004-08-04 02:29:46 22,271 -c----w c:\windows\ServicePackFiles\i386\watv06nt.sys
+ 2004-08-04 02:29:46 25,471 -c----w c:\windows\ServicePackFiles\i386\watv10nt.sys
+ 2008-04-14 00:12:08 215,552 -c----w c:\windows\ServicePackFiles\i386\wavemsp.dll
+ 2008-04-14 00:12:08 196,608 -c----w c:\windows\ServicePackFiles\i386\wbemcntl.dll
+ 2008-04-14 00:12:08 214,528 -c----w c:\windows\ServicePackFiles\i386\wbemcomn.dll
+ 2008-04-14 00:12:08 71,680 -c----w c:\windows\ServicePackFiles\i386\wbemcons.dll
+ 2008-04-14 00:12:08 531,456 -c----w c:\windows\ServicePackFiles\i386\wbemcore.dll
+ 2008-04-14 00:12:08 178,176 -c----w c:\windows\ServicePackFiles\i386\wbemdisp.dll
+ 2008-04-14 00:12:08 273,920 -c----w c:\windows\ServicePackFiles\i386\wbemess.dll
+ 2008-04-14 00:12:08 43,008 -c----w c:\windows\ServicePackFiles\i386\wbemperf.dll
+ 2008-04-14 00:12:08 18,944 -c----w c:\windows\ServicePackFiles\i386\wbemprox.dll
+ 2008-04-14 00:12:08 43,520 -c----w c:\windows\ServicePackFiles\i386\wbemsvc.dll
+ 2008-04-14 00:12:39 116,224 -c----w c:\windows\ServicePackFiles\i386\wbemtest.exe
+ 2008-04-14 00:12:08 197,120 -c----w c:\windows\ServicePackFiles\i386\wbemupgd.dll
+ 2008-04-13 18:45:38 31,744 -c----w c:\windows\ServicePackFiles\i386\wceusbsh.sys
+ 2004-08-04 02:29:46 23,615 -c----w c:\windows\ServicePackFiles\i386\wch7xxnt.sys
+ 2008-04-14 00:12:08 49,152 -c----w c:\windows\ServicePackFiles\i386\wdigest.dll
+ 2008-04-14 00:12:45 23,552 -c----w c:\windows\ServicePackFiles\i386\wdmaud.drv
+ 2008-04-13 19:17:18 83,072 -c----w c:\windows\ServicePackFiles\i386\wdmaud.sys
+ 2008-04-14 00:12:08 276,480 -c----w c:\windows\ServicePackFiles\i386\webcheck.dll
+ 2008-04-14 00:12:08 68,096 -c----w c:\windows\ServicePackFiles\i386\webclnt.dll
+ 2008-04-14 00:12:08 135,680 -c----w c:\windows\ServicePackFiles\i386\webvw.dll
+ 2008-04-14 00:12:39 65,024 -c----w c:\windows\ServicePackFiles\i386\wextract.exe
+ 2008-04-14 00:12:39 433,664 -c----w c:\windows\ServicePackFiles\i386\wiaacmgr.exe
+ 2008-04-14 00:12:08 463,360 -c----w c:\windows\ServicePackFiles\i386\wiadefui.dll
+ 2008-04-14 00:12:08 124,416 -c----w c:\windows\ServicePackFiles\i386\wiadss.dll
+ 2008-04-14 00:12:08 75,776 -c----w c:\windows\ServicePackFiles\i386\wiascr.dll
+ 2008-04-14 00:12:08 333,824 -c----w c:\windows\ServicePackFiles\i386\wiaservc.dll
+ 2008-04-14 00:12:08 589,312 -c----w c:\windows\ServicePackFiles\i386\wiashext.dll
+ 2008-04-14 00:12:08 111,104 -c----w c:\windows\ServicePackFiles\i386\wiavideo.dll
+ 2008-04-14 00:12:08 712,704 -c----w c:\windows\ServicePackFiles\i386\wic.dll
+ 2008-04-14 00:12:08 346,112 -c----w c:\windows\ServicePackFiles\i386\wicext.dll
+ 2008-04-13 19:30:10 1,845,632 -c----w c:\windows\ServicePackFiles\i386\win32k.sys
+ 2008-04-14 00:12:08 102,400 -c----w c:\windows\ServicePackFiles\i386\win32spl.dll
+ 2008-04-13 16:48:53 1,647,616 -c----w c:\windows\ServicePackFiles\i386\winbrand.dll
+ 2008-04-14 00:12:39 283,648 -c----w c:\windows\ServicePackFiles\i386\winhlp32.exe
+ 2008-04-14 00:12:08 354,304 -c----w c:\windows\ServicePackFiles\i386\winhttp.dll
+ 2008-04-14 00:12:08 666,112 -c----w c:\windows\ServicePackFiles\i386\wininet.dll
+ 2008-04-14 00:12:09 32,256 -c----w c:\windows\ServicePackFiles\i386\winipsec.dll
+ 2008-04-14 00:12:39 507,904 -c----w c:\windows\ServicePackFiles\i386\winlogon.exe
+ 2008-04-14 00:12:09 176,128 -c----w c:\windows\ServicePackFiles\i386\winmm.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\ServicePackFiles\i386\winnls.dll
+ 2008-04-14 00:11:11 756,224 -c----w c:\windows\ServicePackFiles\i386\winntbbu.dll
+ 2008-04-14 00:12:09 16,896 -c----w c:\windows\ServicePackFiles\i386\winrnr.dll
+ 2008-04-14 00:12:09 99,328 -c----w c:\windows\ServicePackFiles\i386\winscard.dll
+ 2008-04-14 00:12:09 17,408 -c----w c:\windows\ServicePackFiles\i386\winshfhc.dll
+ 2008-04-14 00:12:45 146,432 -c----w c:\windows\ServicePackFiles\i386\winspool.drv
+ 2008-04-14 00:12:09 293,376 -c----w c:\windows\ServicePackFiles\i386\winsrv.dll
+ 2008-04-14 00:12:09 53,760 -c----w c:\windows\ServicePackFiles\i386\winsta.dll
+ 2008-04-14 00:12:09 176,640 -c----w c:\windows\ServicePackFiles\i386\wintrust.dll
+ 2008-04-14 00:12:40 5,632 -c----w c:\windows\ServicePackFiles\i386\winver.exe
+ 2008-04-14 00:12:09 132,096 -c----w c:\windows\ServicePackFiles\i386\wkssvc.dll
+ 2008-04-14 00:12:09 69,120 -c----w c:\windows\ServicePackFiles\i386\wlanapi.dll
+ 2008-04-14 00:12:09 172,032 -c----w c:\windows\ServicePackFiles\i386\wldap32.dll
+ 2004-08-04 02:31:28 154,624 -c----w c:\windows\ServicePackFiles\i386\wlluc48.sys
+ 2008-04-14 00:12:09 92,672 -c----w c:\windows\ServicePackFiles\i386\wlnotify.dll
+ 2008-04-14 00:11:15 5,632 -c----w c:\windows\ServicePackFiles\i386\wmi.dll
+ 2008-04-13 18:36:38 8,832 -c----w c:\windows\ServicePackFiles\i386\wmiacpi.sys
+ 2008-04-14 00:12:40 196,608 -c----w c:\windows\ServicePackFiles\i386\wmiadap.exe
+ 2008-04-13 17:10:20 6,656 -c----w c:\windows\ServicePackFiles\i386\wmiapres.dll
+ 2008-04-14 00:12:09 88,576 -c----w c:\windows\ServicePackFiles\i386\wmiaprpl.dll
+ 2008-04-14 00:12:40 126,464 -c----w c:\windows\ServicePackFiles\i386\wmiapsrv.exe
+ 2008-04-14 00:12:40 358,912 -c----w c:\windows\ServicePackFiles\i386\wmic.exe
+ 2008-04-14 00:12:09 60,928 -c----w c:\windows\ServicePackFiles\i386\wmicookr.dll
+ 2008-04-14 00:12:09 140,800 -c----w c:\windows\ServicePackFiles\i386\wmidcprv.dll
+ 2008-04-14 00:12:09 156,672 -c----w c:\windows\ServicePackFiles\i386\wmipcima.dll
+ 2008-04-14 00:12:09 132,096 -c----w c:\windows\ServicePackFiles\i386\wmipdskq.dll
+ 2008-04-14 00:12:09 61,952 -c----w c:\windows\ServicePackFiles\i386\wmipiprt.dll
+ 2008-04-14 00:12:09 62,464 -c----w c:\windows\ServicePackFiles\i386\wmipjobj.dll
+ 2008-04-14 00:12:09 144,896 -c----w c:\windows\ServicePackFiles\i386\wmiprov.dll
+ 2008-04-14 00:12:09 437,248 -c----w c:\windows\ServicePackFiles\i386\wmiprvsd.dll
+ 2008-04-14 00:12:40 218,112 -c----w c:\windows\ServicePackFiles\i386\wmiprvse.exe
+ 2008-04-14 00:12:09 41,472 -c----w c:\windows\ServicePackFiles\i386\wmipsess.dll
+ 2008-04-14 00:12:09 144,896 -c----w c:\windows\ServicePackFiles\i386\wmisvc.dll
+ 2008-04-14 00:12:09 95,232 -c----w c:\windows\ServicePackFiles\i386\wmiutils.dll
+ 2008-04-14 00:12:09 167,936 -c----w c:\windows\ServicePackFiles\i386\wmm2ae.dll
+ 2008-04-14 00:12:09 4,096 -c----w c:\windows\ServicePackFiles\i386\wmm2eres.dll
+ 2008-04-14 00:12:09 7,680 -c----w c:\windows\ServicePackFiles\i386\wmm2ext.dll
+ 2008-04-14 00:12:09 402,432 -c----w c:\windows\ServicePackFiles\i386\wmm2filt.dll
+ 2008-04-14 00:12:09 502,272 -c----w c:\windows\ServicePackFiles\i386\wmm2fxa.dll
+ 2008-04-14 00:12:09 325,632 -c----w c:\windows\ServicePackFiles\i386\wmm2fxb.dll
+ 2008-04-14 00:12:09 4,256,768 -c----w c:\windows\ServicePackFiles\i386\wmm2res.dll
+ 2008-04-14 00:12:09 5,632 -c----w c:\windows\ServicePackFiles\i386\wmm2res2.dll
+ 2008-04-14 00:12:09 276,992 -c----w c:\windows\ServicePackFiles\i386\wmphoto.dll
+ 2008-04-14 00:12:40 214,528 -c----w c:\windows\ServicePackFiles\i386\wordpad.exe
+ 2008-04-14 00:12:10 264,192 -c----w c:\windows\ServicePackFiles\i386\wow32.dll
+ 2008-04-14 00:12:40 32,256 -c----w c:\windows\ServicePackFiles\i386\wpabaln.exe
+ 2008-04-14 00:12:41 11,264 -c----w c:\windows\ServicePackFiles\i386\wpnpinst.exe
+ 2008-04-14 00:12:10 82,432 -c----w c:\windows\ServicePackFiles\i386\ws2_32.dll
+ 2008-04-14 00:12:10 19,968 -c----w c:\windows\ServicePackFiles\i386\ws2help.dll
+ 2008-04-14 00:12:41 13,824 -c----w c:\windows\ServicePackFiles\i386\wscntfy.exe
+ 2008-04-14 00:12:41 155,648 -c----w c:\windows\ServicePackFiles\i386\wscript.exe
+ 2008-04-14 00:12:10 80,896 -c----w c:\windows\ServicePackFiles\i386\wscsvc.dll
+ 2008-04-14 00:12:10 604,160 -c----w c:\windows\ServicePackFiles\i386\wsecedit.dll
+ 2008-04-14 00:12:10 108,032 -c----w c:\windows\ServicePackFiles\i386\wshbth.dll
+ 2008-04-14 00:12:10 36,864 -c----w c:\windows\ServicePackFiles\i386\wshcon.dll
+ 2008-04-14 00:12:10 90,112 -c----w c:\windows\ServicePackFiles\i386\wshext.dll
+ 2008-04-14 00:12:10 14,336 -c----w c:\windows\ServicePackFiles\i386\wship6.dll
+ 2008-04-14 00:12:10 8,192 -c----w c:\windows\ServicePackFiles\i386\wshirda.dll
+ 2008-04-14 00:12:10 11,264 -c----w c:\windows\ServicePackFiles\i386\wshrm.dll
+ 2008-04-14 00:12:10 19,456 -c----w c:\windows\ServicePackFiles\i386\wshtcpip.dll
+ 2004-08-04 02:29:48 12,063 -c----w c:\windows\ServicePackFiles\i386\wsiintxx.sys
+ 2008-04-14 00:12:10 41,984 -c----w c:\windows\ServicePackFiles\i386\wsnmp32.dll
+ 2008-04-14 00:12:10 22,528 -c----w c:\windows\ServicePackFiles\i386\wsock32.dll
+ 2008-04-13 18:46:24 19,200 -c----w c:\windows\ServicePackFiles\i386\wstcodec.sys
+ 2008-04-14 00:12:10 50,688 -c----w c:\windows\ServicePackFiles\i386\wstdecod.dll
+ 2008-04-14 00:12:10 18,432 -c----w c:\windows\ServicePackFiles\i386\wtsapi32.dll
+ 2008-04-14 00:12:10 430,592 -c----w c:\windows\ServicePackFiles\i386\wuapi.dll
+ 2008-04-14 00:12:41 111,104 -c----w c:\windows\ServicePackFiles\i386\wuauclt.exe
+ 2008-04-14 00:12:41 165,888 -c----w c:\windows\ServicePackFiles\i386\wuauclt1.exe
+ 2008-04-14 00:12:11 1,135,616 -c----w c:\windows\ServicePackFiles\i386\wuaueng.dll
+ 2008-04-14 00:12:11 183,296 -c----w c:\windows\ServicePackFiles\i386\wuaueng1.dll
+ 2008-04-14 00:12:11 6,656 -c----w c:\windows\ServicePackFiles\i386\wuauserv.dll
+ 2008-04-14 00:12:11 112,640 -c----w c:\windows\ServicePackFiles\i386\wucltui.dll
+ 2008-04-14 00:12:11 32,256 -c----w c:\windows\ServicePackFiles\i386\wups.dll
+ 2008-04-14 00:12:11 120,320 -c----w c:\windows\ServicePackFiles\i386\wuweb.dll
+ 2004-08-04 02:29:50 19,455 -c----w c:\windows\ServicePackFiles\i386\wvchntxx.sys
+ 2008-04-14 00:12:11 383,488 -c----w c:\windows\ServicePackFiles\i386\wzcdlg.dll
+ 2008-04-14 00:12:11 52,736 -c----w c:\windows\ServicePackFiles\i386\wzcsapi.dll
+ 2008-04-14 00:12:11 483,840 -c----w c:\windows\ServicePackFiles\i386\wzcsvc.dll
+ 2008-04-14 00:12:11 91,648 -c----w c:\windows\ServicePackFiles\i386\xactsrv.dll
+ 2008-04-14 00:12:41 30,720 -c----w c:\windows\ServicePackFiles\i386\xcopy.exe
+ 2004-08-10 19:00:00 174,200 -c----w c:\windows\ServicePackFiles\i386\xenroll.dll
+ 2008-04-14 00:12:11 121,856 -c----w c:\windows\ServicePackFiles\i386\xmllite.dll
+ 2008-04-14 00:12:11 129,024 -c----w c:\windows\ServicePackFiles\i386\xmlprov.dll
+ 2008-04-14 00:12:11 50,176 -c----w c:\windows\ServicePackFiles\i386\xmlprovi.dll
+ 2008-04-14 00:12:11 11,776 -c----w c:\windows\ServicePackFiles\i386\xolehlp.dll
+ 2008-04-13 18:53:32 558,080 -c----w c:\windows\ServicePackFiles\i386\xpnetdg.exe
+ 2008-04-13 17:39:29 438,784 -c----w c:\windows\ServicePackFiles\i386\xpob2res.dll
+ 2008-04-13 17:39:22 187,392 -c----w c:\windows\ServicePackFiles\i386\xpsp1res.dll
+ 2008-04-13 17:39:24 2,897,920 -c----w c:\windows\ServicePackFiles\i386\xpsp2res.dll
+ 2008-04-13 17:39:26 689,152 -c----w c:\windows\ServicePackFiles\i386\xpsp3res.dll
+ 2008-04-14 00:12:11 18,944 -c----w c:\windows\ServicePackFiles\i386\xrxscnui.dll
+ 2008-04-14 00:12:11 116,224 -c----w c:\windows\ServicePackFiles\i386\xrxwiadr.dll
+ 2008-04-14 00:12:11 338,432 -c----w c:\windows\ServicePackFiles\i386\zipfldr.dll
+ 2008-04-14 00:11:51 33,792 -c----w c:\windows\ServicePackFiles\ServicePackCache\i386\custsat.dll
+ 2008-04-14 00:11:59 82,944 -c----w c:\windows\ServicePackFiles\ServicePackCache\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 -c----w c:\windows\ServicePackFiles\ServicePackCache\i386\msgslang.dll
+ 2008-04-14 00:12:28 1,695,232 -c----w c:\windows\ServicePackFiles\ServicePackCache\i386\msmsgs.exe
+ 2008-04-14 00:12:35 32,866 -c----w c:\windows\slrundll.exe
- 2004-08-10 19:00:00 3,166,208 ----a-w c:\windows\srchasst\msgr3en.dll
+ 2008-04-14 00:11:59 3,166,208 -c--a-w c:\windows\srchasst\msgr3en.dll
- 2004-08-10 19:00:00 58,434 ----a-w c:\windows\srchasst\srchctls.dll
+ 2008-04-14 00:12:06 58,434 ----a-w c:\windows\srchasst\srchctls.dll
- 2004-08-10 19:00:00 725,566 ----a-w c:\windows\srchasst\srchui.dll
+ 2008-04-14 00:12:07 726,078 ----a-w c:\windows\srchasst\srchui.dll
- 2000-08-31 12:00:00 161,792 ----a-w c:\windows\swreg.exe
+ 2000-08-31 13:00:00 161,792 -c--a-w c:\windows\swreg.exe
- 2004-08-10 19:00:00 146,432 ----a-w c:\windows\system\WINSPOOL.DRV
+ 2008-04-14 00:12:45 146,432 -c--a-w c:\windows\system\winspool.drv
- 2006-08-16 11:58:05 100,352 ----a-w c:\windows\system32\6to4svc.dll
+ 2008-04-14 00:11:48 100,352 ----a-w c:\windows\system32\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 ------w c:\windows\system32\aaclient.dll
- 2004-08-10 19:00:00 183,808 ----a-w c:\windows\system32\accwiz.exe
+ 2008-04-14 00:12:11 184,320 ----a-w c:\windows\system32\accwiz.exe
- 2004-08-10 19:00:00 114,688 ----a-w c:\windows\system32\aclui.dll
+ 2008-04-14 00:11:48 115,712 ----a-w c:\windows\system32\aclui.dll
- 2004-08-10 19:00:00 194,048 ----a-w c:\windows\system32\activeds.dll
+ 2008-04-14 00:11:48 193,536 ----a-w c:\windows\system32\activeds.dll
- 2004-08-10 19:00:00 4,096 ----a-w c:\windows\system32\actmovie.exe
+ 2008-04-14 00:12:12 4,096 ----a-w c:\windows\system32\actmovie.exe
- 2004-08-10 19:00:00 101,888 ----a-w c:\windows\system32\actxprxy.dll
+ 2008-04-14 00:11:48 98,304 ----a-w c:\windows\system32\actxprxy.dll
- 2004-08-10 19:00:00 175,616 ----a-w c:\windows\system32\adsldp.dll
+ 2008-04-14 00:11:48 175,616 ----a-w c:\windows\system32\adsldp.dll
- 2004-08-10 19:00:00 143,360 ----a-w c:\windows\system32\adsldpc.dll
+ 2008-04-14 00:11:48 143,360 ----a-w c:\windows\system32\adsldpc.dll
- 2004-08-10 19:00:00 68,096 ----a-w c:\windows\system32\adsmsext.dll
+ 2008-04-14 00:11:48 68,096 ----a-w c:\windows\system32\adsmsext.dll
- 2004-08-10 19:00:00 263,680 ----a-w c:\windows\system32\adsnt.dll
+ 2008-04-14 00:11:48 263,680 ----a-w c:\windows\system32\adsnt.dll
- 2004-08-10 19:00:00 109,568 ----a-w c:\windows\system32\adsnw.dll
+ 2008-04-14 00:11:48 123,392 ----a-w c:\windows\system32\adsnw.dll
- 2004-08-10 19:00:00 616,960 ----a-w c:\windows\system32\advapi32.dll
+ 2008-04-14 00:11:48 617,472 ----a-w c:\windows\system32\advapi32.dll
- 2008-04-23 04:16:28 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
- 2004-08-10 19:00:00 98,304 ----a-w c:\windows\system32\ahui.exe
+ 2008-04-14 00:12:12 98,304 ----a-w c:\windows\system32\ahui.exe
- 2004-08-10 19:00:00 44,544 ----a-w c:\windows\system32\alg.exe
+ 2008-04-14 00:12:12 44,544 ----a-w c:\windows\system32\alg.exe
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\alrsvc.dll
+ 2008-04-14 00:11:49 17,408 ----a-w c:\windows\system32\alrsvc.dll
- 2004-08-10 19:00:00 70,656 ----a-w c:\windows\system32\amstream.dll
+ 2008-04-14 00:11:49 70,656 ----a-w c:\windows\system32\amstream.dll
- 2004-08-10 19:00:00 126,976 ----a-w c:\windows\system32\apphelp.dll
+ 2008-04-14 00:11:49 125,952 ----a-w c:\windows\system32\apphelp.dll
- 2004-08-10 19:00:00 167,936 ----a-w c:\windows\system32\appmgmts.dll
+ 2008-04-14 00:11:49 167,936 ----a-w c:\windows\system32\appmgmts.dll
- 2004-08-10 19:00:00 295,936 ----a-w c:\windows\system32\appmgr.dll
+ 2008-04-14 00:11:49 295,936 ----a-w c:\windows\system32\appmgr.dll
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\asr_fmt.exe
+ 2008-04-14 00:12:12 30,208 ----a-w c:\windows\system32\asr_fmt.exe
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\asr_pfu.exe
+ 2008-04-14 00:12:12 32,768 ----a-w c:\windows\system32\asr_pfu.exe
- 2004-08-10 19:00:00 65,024 ----a-w c:\windows\system32\asycfilt.dll
+ 2008-04-14 00:11:49 65,024 ----a-w c:\windows\system32\asycfilt.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\at.exe
+ 2008-04-14 00:12:12 25,088 ----a-w c:\windows\system32\at.exe
+ 2008-04-14 00:11:49 229,376 ------w c:\windows\system32\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ------w c:\windows\system32\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ------w c:\windows\system32\ati2dvag.dll
+ 2008-04-14 00:11:49 870,784 ------w c:\windows\system32\ati3d1ag.dll
+ 2008-04-14 00:11:50 1,888,992 ------w c:\windows\system32\ati3duag.dll
+ 2008-04-14 00:11:50 32,768 ------w c:\windows\system32\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ------w c:\windows\system32\ativvaxx.dll
- 2004-08-10 19:00:00 58,880 ----a-w c:\windows\system32\atl.dll
+ 2008-04-14 00:11:50 58,880 ----a-w c:\windows\system32\atl.dll
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\atmadm.exe
+ 2008-04-14 00:12:12 11,264 ----a-w c:\windows\system32\atmadm.exe
- 2004-08-10 19:00:00 285,696 ----a-w c:\windows\system32\atmfd.dll
+ 2008-04-14 00:09:01 285,696 ----a-w c:\windows\system32\atmfd.dll
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\atmlib.dll
+ 2008-04-14 00:11:50 30,208 ----a-w c:\windows\system32\atmlib.dll
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\attrib.exe
+ 2008-04-14 00:12:12 12,288 ----a-w c:\windows\system32\attrib.exe
- 2004-08-10 19:00:00 42,496 ----a-w c:\windows\system32\audiosrv.dll
+ 2008-04-14 00:11:50 42,496 ----a-w c:\windows\system32\audiosrv.dll
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\auditusr.exe
+ 2008-04-14 00:12:12 14,336 ----a-w c:\windows\system32\auditusr.exe
- 2005-03-02 18:09:29 56,832 ----a-w c:\windows\system32\authz.dll
+ 2008-04-14 00:11:50 62,464 ----a-w c:\windows\system32\authz.dll
- 2004-08-10 19:00:00 588,800 ----a-w c:\windows\system32\autochk.exe
+ 2008-04-14 00:12:12 588,800 ----a-w c:\windows\system32\autochk.exe
- 2004-08-10 19:00:00 602,624 ----a-w c:\windows\system32\autoconv.exe
+ 2008-04-14 00:12:12 602,624 ----a-w c:\windows\system32\autoconv.exe
- 2004-08-10 19:00:00 580,608 ----a-w c:\windows\system32\autofmt.exe
+ 2008-04-14 00:12:13 580,608 ----a-w c:\windows\system32\autofmt.exe
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\autolfn.exe
+ 2008-04-14 00:12:13 11,264 ----a-w c:\windows\system32\autolfn.exe
- 2004-08-10 19:00:00 84,992 ----a-w c:\windows\system32\avifil32.dll
+ 2008-04-14 00:11:50 84,992 ----a-w c:\windows\system32\avifil32.dll
- 2007-05-17 15:30:48 318,976 ----a-w c:\windows\system32\avisynth.dll
+ 2006-12-31 02:16:36 313,344 ----a-w c:\windows\system32\avisynth.dll
+ 2008-04-14 00:11:50 233,472 ------w c:\windows\system32\azroles.dll
- 2004-08-10 19:00:00 52,736 ----a-w c:\windows\system32\basesrv.dll
+ 2008-04-14 00:11:50 52,736 ----a-w c:\windows\system32\basesrv.dll
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\batmeter.dll
+ 2008-04-14 00:11:50 29,184 ----a-w c:\windows\system32\batmeter.dll
- 2004-08-10 19:00:00 8,704 ----a-w c:\windows\system32\batt.dll
+ 2008-04-14 00:11:50 8,704 ----a-w c:\windows\system32\batt.dll
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\bidispl.dll
+ 2008-04-14 00:11:50 17,408 ----a-w c:\windows\system32\bidispl.dll
+ 2008-04-14 00:12:03 409,088 -c----w c:\windows\system32\bits\qmgr.dll
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\bitsprx2.dll
+ 2008-04-14 00:11:50 8,192 ----a-w c:\windows\system32\bitsprx2.dll
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ----a-w c:\windows\system32\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ------w c:\windows\system32\bitsprx4.dll
- 2004-08-10 19:00:00 71,680 ----a-w c:\windows\system32\blastcln.exe
+ 2008-04-14 00:12:13 71,680 ----a-w c:\windows\system32\blastcln.exe
- 2004-08-10 19:00:00 136,704 ----a-w c:\windows\system32\bootcfg.exe
+ 2008-04-14 00:12:13 142,848 ----a-w c:\windows\system32\bootcfg.exe
- 2004-08-10 19:00:00 63,488 ----a-w c:\windows\system32\browselc.dll
+ 2008-04-13 17:03:24 63,488 ----a-w c:\windows\system32\browselc.dll
- 2004-08-10 19:00:00 77,312 ----a-w c:\windows\system32\browser.dll
+ 2008-04-14 00:11:50 77,824 ----a-w c:\windows\system32\browser.dll
- 2007-12-07 00:44:30 1,024,000 ----a-w c:\windows\system32\browseui.dll
+ 2008-04-14 00:11:50 1,025,024 ----a-w c:\windows\system32\browseui.dll
- 2004-08-10 19:00:00 78,336 ----a-w c:\windows\system32\browsewm.dll
+ 2008-04-14 00:11:50 78,336 ----a-w c:\windows\system32\browsewm.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\bthci.dll
+ 2008-04-14 00:11:50 20,992 ----a-w c:\windows\system32\bthci.dll
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\bthserv.dll
+ 2008-04-14 00:11:50 30,208 ----a-w c:\windows\system32\bthserv.dll
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\system32\btpanui.dll
+ 2008-04-14 00:11:50 50,688 ----a-w c:\windows\system32\btpanui.dll
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\cabinet.dll
+ 2008-04-14 00:11:50 60,416 ----a-w c:\windows\system32\cabinet.dll
- 2004-08-10 19:00:00 84,480 ----a-w c:\windows\system32\cabview.dll
+ 2008-04-14 00:11:50 84,480 ----a-w c:\windows\system32\cabview.dll
- 2004-08-10 19:00:00 18,432 ----a-w c:\windows\system32\cacls.exe
+ 2008-04-14 00:12:13 19,968 ----a-w c:\windows\system32\cacls.exe
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\system32\camocx.dll
+ 2008-04-14 00:11:50 50,688 ----a-w c:\windows\system32\camocx.dll
- 2004-08-10 19:00:00 142,848 ----a-w c:\windows\system32\capesnpn.dll
+ 2008-04-14 00:11:50 150,016 ----a-w c:\windows\system32\capesnpn.dll
- 2005-07-26 04:39:42 225,792 ----a-w c:\windows\system32\catsrv.dll
+ 2008-04-14 00:11:50 226,304 ----a-w c:\windows\system32\catsrv.dll
- 2004-08-10 19:00:00 85,504 ----a-w c:\windows\system32\catsrvps.dll
+ 2008-04-14 00:11:50 85,504 ----a-w c:\windows\system32\catsrvps.dll
- 2005-07-26 04:39:43 625,152 ----a-w c:\windows\system32\catsrvut.dll
+ 2008-04-14 00:11:50 625,664 ----a-w c:\windows\system32\catsrvut.dll
- 2007-12-07 00:44:30 151,040 ----a-w c:\windows\system32\cdfview.dll
+ 2008-04-14 00:11:50 151,040 ----a-w c:\windows\system32\cdfview.dll
- 2007-07-31 00:19:20 92,504 ----a-w c:\windows\system32\cdm.dll
+ 2008-10-16 19:09:44 92,696 ----a-w c:\windows\system32\cdm.dll
- 2005-09-10 01:53:41 2,067,968 ----a-w c:\windows\system32\cdosys.dll
+ 2008-04-14 00:11:50 2,091,520 ----a-w c:\windows\system32\cdosys.dll
- 2004-08-10 19:00:00 194,560 ----a-w c:\windows\system32\certcli.dll
+ 2008-04-14 00:11:50 194,560 ----a-w c:\windows\system32\certcli.dll
- 2004-08-10 19:00:00 457,728 ----a-w c:\windows\system32\certmgr.dll
+ 2008-04-14 00:11:50 457,728 ----a-w c:\windows\system32\certmgr.dll
- 2004-08-10 19:00:00 38,912 ----a-w c:\windows\system32\cfgbkend.dll
+ 2008-04-14 00:11:50 38,912 ----a-w c:\windows\system32\cfgbkend.dll
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\cfgmgr32.dll
+ 2008-04-14 00:09:05 16,896 ----a-w c:\windows\system32\cfgmgr32.dll
- 2004-08-10 19:00:00 109,568 ----a-w c:\windows\system32\cic.dll
+ 2008-04-14 00:11:50 148,480 ----a-w c:\windows\system32\cic.dll
- 2006-06-22 05:06:29 69,120 ----a-w c:\windows\system32\ciodm.dll
+ 2008-04-14 00:11:50 69,120 ----a-w c:\windows\system32\ciodm.dll
- 2004-08-10 19:00:00 56,320 ----a-w c:\windows\system32\cipher.exe
+ 2008-04-14 00:12:14 56,832 ----a-w c:\windows\system32\cipher.exe
- 2004-08-10 19:00:00 5,632 ----a-w c:\windows\system32\cisvc.exe
+ 2008-04-14 00:12:14 5,632 ----a-w c:\windows\system32\cisvc.exe
- 2005-07-26 04:39:43 110,080 ----a-w c:\windows\system32\clbcatex.dll
+ 2008-04-14 00:11:50 110,592 ----a-w c:\windows\system32\clbcatex.dll
- 2005-07-26 04:39:43 498,688 ----a-w c:\windows\system32\clbcatq.dll
+ 2008-04-14 00:11:50 498,688 ----a-w c:\windows\system32\clbcatq.dll
- 2004-08-10 19:00:00 64,000 ----a-w c:\windows\system32\cleanmgr.exe
+ 2008-04-14 00:12:14 64,000 ----a-w c:\windows\system32\cleanmgr.exe
- 2004-08-10 19:00:00 77,824 ----a-w c:\windows\system32\cliconfg.dll
+ 2008-04-14 00:11:50 77,824 ----a-w c:\windows\system32\cliconfg.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\cliconfg.exe
+ 2008-04-14 00:12:14 20,480 ----a-w c:\windows\system32\cliconfg.exe
- 2004-08-10 19:00:00 102,912 ----a-w c:\windows\system32\clipbrd.exe
+ 2008-04-14 00:12:14 102,912 ----a-w c:\windows\system32\clipbrd.exe
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\system32\clipsrv.exe
+ 2008-04-14 00:12:14 33,280 ----a-w c:\windows\system32\clipsrv.exe
- 2004-08-10 19:00:00 57,856 ----a-w c:\windows\system32\clusapi.dll
+ 2008-04-14 00:11:50 58,368 ----a-w c:\windows\system32\clusapi.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\cmcfg32.dll
+ 2008-04-14 00:11:50 15,872 ----a-w c:\windows\system32\cmcfg32.dll
- 2004-08-10 19:00:00 388,608 ----a-w c:\windows\system32\cmd.exe
+ 2008-04-14 00:12:14 389,120 ----a-w c:\windows\system32\cmd.exe
- 2004-08-10 19:00:00 343,040 ----a-w c:\windows\system32\cmdial32.dll
+ 2008-04-14 00:11:50 344,064 ----a-w c:\windows\system32\cmdial32.dll
- 2004-08-10 19:00:00 47,104 ----a-w c:\windows\system32\cmdl32.exe
+ 2008-04-14 00:12:14 25,600 ----a-w c:\windows\system32\cmdl32.exe
+ 1998-07-06 06:00:00 33,792 ----a-w c:\windows\system32\CMDLGDE.DLL
+ 2008-09-07 19:54:24 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
- 2004-08-10 19:00:00 39,936 ----a-w c:\windows\system32\cmmon32.exe
+ 2008-04-14 00:12:15 39,936 ----a-w c:\windows\system32\cmmon32.exe
- 2004-08-10 19:00:00 185,344 ----a-w c:\windows\system32\cmprops.dll
+ 2008-04-14 00:11:50 185,344 ----a-w c:\windows\system32\cmprops.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\cmsetACL.dll
+ 2008-04-14 00:11:50 13,312 ----a-w c:\windows\system32\cmsetacl.dll
- 2004-08-10 19:00:00 63,488 ----a-w c:\windows\system32\cmstp.exe
+ 2008-04-14 00:12:15 63,488 ----a-w c:\windows\system32\cmstp.exe
- 2004-08-10 19:00:00 39,936 ----a-w c:\windows\system32\cmutil.dll
+ 2008-04-14 00:11:50 39,424 ----a-w c:\windows\system32\cmutil.dll
- 2004-08-04 00:56:42 47,104 ----a-w c:\windows\system32\cnbjmon.dll
+ 2008-04-14 00:11:50 47,104 ----a-w c:\windows\system32\cnbjmon.dll
- 2005-07-26 04:39:43 60,416 ----a-w c:\windows\system32\colbact.dll
+ 2008-04-14 00:11:51 60,416 ----a-w c:\windows\system32\colbact.dll
- 2005-07-26 04:39:44 195,072 ----a-w c:\windows\system32\Com\comadmin.dll
+ 2008-04-14 00:11:51 195,072 -c--a-w c:\windows\system32\Com\comadmin.dll
- 2004-08-10 19:00:00 9,728 ----a-w c:\windows\system32\Com\comrepl.exe
+ 2008-04-14 00:12:15 9,728 -c--a-w c:\windows\system32\Com\comrepl.exe
- 2004-08-10 19:00:00 5,120 ----a-w c:\windows\system32\Com\comrereg.exe
+ 2008-04-14 00:12:15 6,144 -c--a-w c:\windows\system32\Com\comrereg.exe
- 2004-08-10 19:00:00 25,600 ----a-w c:\windows\system32\comaddin.dll
+ 2008-04-14 00:11:51 28,160 ----a-w c:\windows\system32\comaddin.dll
- 2006-08-25 15:45:58 617,472 ----a-w c:\windows\system32\comctl32.dll
+ 2008-04-14 00:11:51 617,472 ----a-w c:\windows\system32\comctl32.dll
- 2004-08-10 19:00:00 276,992 ----a-w c:\windows\system32\comdlg32.dll
+ 2008-04-14 00:11:51 276,992 ----a-w c:\windows\system32\comdlg32.dll
- 2004-08-10 19:00:00 252,928 ----a-w c:\windows\system32\compatUI.dll
+ 2008-04-14 00:11:51 252,928 ----a-w c:\windows\system32\compatui.dll
- 2004-08-10 19:00:00 229,376 ----a-w c:\windows\system32\compstui.dll
+ 2008-04-14 00:11:51 229,376 ----a-w c:\windows\system32\compstui.dll
- 2005-07-26 04:39:44 97,792 ----a-w c:\windows\system32\comrepl.dll
+ 2008-04-14 00:11:51 97,792 ----a-w c:\windows\system32\comrepl.dll
- 2004-08-10 19:00:00 792,064 ----a-w c:\windows\system32\comres.dll
+ 2008-04-14 00:11:51 792,064 ----a-w c:\windows\system32\comres.dll
+ 2008-04-13 18:43:32 9,728 ------w c:\windows\system32\comsdupd.exe
- 2004-08-10 19:00:00 147,456 ----a-w c:\windows\system32\comsnap.dll
+ 2008-04-14 00:11:51 167,424 ----a-w c:\windows\system32\comsnap.dll
- 2005-07-26 04:39:44 1,267,200 ----a-w c:\windows\system32\comsvcs.dll
+ 2008-04-14 00:11:51 1,267,200 ----a-w c:\windows\system32\comsvcs.dll
- 2005-07-26 04:39:45 540,160 ----a-w c:\windows\system32\comuid.dll
+ 2008-04-14 00:11:51 539,648 ----a-w c:\windows\system32\comuid.dll
- 2008-04-03 06:36:24 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-16 18:07:07 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-04-03 06:36:24 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-16 18:07:07 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-03 06:36:24 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-16 18:07:07 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-10 19:00:00 345,600 ----a-w c:\windows\system32\confmsp.dll
+ 2008-04-14 00:11:51 357,888 ----a-w c:\windows\system32\confmsp.dll
- 2004-08-10 19:00:00 27,648 ----a-w c:\windows\system32\conime.exe
+ 2008-04-14 00:12:15 27,648 ----a-w c:\windows\system32\conime.exe
- 2004-08-10 19:00:00 35,328 ------w c:\windows\system32\corpol.dll
+ 2008-04-14 00:11:51 35,328 ------w c:\windows\system32\corpol.dll
+ 2008-04-14 00:11:51 12,800 ------w c:\windows\system32\credssp.dll
- 2004-08-10 19:00:00 163,840 ----a-w c:\windows\system32\credui.dll
+ 2008-04-14 00:11:51 163,840 ----a-w c:\windows\system32\credui.dll
- 2004-08-10 19:00:00 597,504 ----a-w c:\windows\system32\crypt32.dll
+ 2008-04-14 00:11:51 599,040 ----a-w c:\windows\system32\crypt32.dll
- 2004-08-10 19:00:00 74,752 ----a-w c:\windows\system32\cryptdlg.dll
+ 2008-04-14 00:11:51 74,752 ----a-w c:\windows\system32\cryptdlg.dll
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\system32\cryptdll.dll
+ 2008-04-14 00:11:51 33,280 ----a-w c:\windows\system32\cryptdll.dll
- 2004-08-10 19:00:00 53,760 ----a-w c:\windows\system32\cryptext.dll
+ 2008-04-14 00:11:51 53,760 ----a-w c:\windows\system32\cryptext.dll
- 2004-08-10 19:00:00 63,488 ----a-w c:\windows\system32\cryptnet.dll
+ 2008-04-14 00:11:51 64,512 ----a-w c:\windows\system32\cryptnet.dll
- 2004-08-10 19:00:00 60,416 ----a-w c:\windows\system32\cryptsvc.dll
+ 2008-04-14 00:11:51 62,464 ----a-w c:\windows\system32\cryptsvc.dll
- 2004-08-10 19:00:00 512,512 ----a-w c:\windows\system32\cryptui.dll
+ 2008-04-14 00:11:51 512,512 ----a-w c:\windows\system32\cryptui.dll
- 2004-08-10 19:00:00 101,888 ----a-w c:\windows\system32\cscdll.dll
+ 2008-04-14 00:11:51 101,888 ----a-w c:\windows\system32\cscdll.dll
- 2004-08-10 19:00:00 98,304 ----a-w c:\windows\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 ----a-w c:\windows\system32\cscript.exe
- 2004-08-10 19:00:00 326,656 ----a-w c:\windows\system32\cscui.dll
+ 2008-04-14 00:11:51 326,656 ----a-w c:\windows\system32\cscui.dll
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\csrsrv.dll
+ 2008-04-14 00:11:51 32,256 ----a-w c:\windows\system32\csrsrv.dll
- 2004-08-10 19:00:00 6,144 ----a-w c:\windows\system32\csrss.exe
+ 2008-04-14 00:12:15 6,144 ----a-w c:\windows\system32\csrss.exe
- 2004-08-10 19:00:00 15,360 ----a-w c:\windows\system32\ctfmon.exe
+ 2008-04-14 00:12:16 15,360 ----a-w c:\windows\system32\ctfmon.exe
- 2004-08-10 19:00:00 1,179,648 ----a-w c:\windows\system32\d3d8.dll
+ 2008-04-14 00:11:51 1,179,648 ----a-w c:\windows\system32\d3d8.dll
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\d3d8thk.dll
+ 2008-04-14 00:11:51 8,192 ----a-w c:\windows\system32\d3d8thk.dll
- 2004-08-10 19:00:00 1,689,088 ----a-w c:\windows\system32\d3d9.dll
+ 2008-04-14 00:11:51 1,689,088 ----a-w c:\windows\system32\d3d9.dll
- 2004-08-10 19:00:00 825,344 ----a-w c:\windows\system32\d3dim700.dll
+ 2008-04-14 00:11:51 824,320 ----a-w c:\windows\system32\d3dim700.dll
- 2007-12-07 00:44:32 1,054,208 ----a-w c:\windows\system32\danim.dll
+ 2008-04-14 00:11:51 1,054,208 ----a-w c:\windows\system32\danim.dll
- 2004-08-10 19:00:00 54,272 ----a-w c:\windows\system32\dataclen.dll
+ 2008-04-14 00:11:51 54,272 ----a-w c:\windows\system32\dataclen.dll
- 2004-08-10 19:00:00 152,064 ----a-w c:\windows\system32\datime.dll
+ 2008-04-14 00:11:51 165,376 ----a-w c:\windows\system32\datime.dll
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\davclnt.dll
+ 2008-04-14 00:11:51 25,088 ----a-w c:\windows\system32\davclnt.dll
- 2004-08-10 19:00:00 640,000 ----a-w c:\windows\system32\dbghelp.dll
+ 2008-04-14 00:11:51 640,000 ----a-w c:\windows\system32\dbghelp.dll
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\dbmsrpcn.dll
+ 2008-04-14 00:11:51 24,576 ----a-w c:\windows\system32\dbmsrpcn.dll
- 2004-08-10 19:00:00 110,592 ----a-w c:\windows\system32\dbnetlib.dll
+ 2008-04-14 00:11:51 110,592 ----a-w c:\windows\system32\dbnetlib.dll
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\dbnmpntw.dll
+ 2008-04-14 00:11:51 28,672 ----a-w c:\windows\system32\dbnmpntw.dll
- 2004-08-10 19:00:00 1,788 ----a-w c:\windows\system32\Dcache.bin
+ 2008-04-14 00:25:26 1,804 ----a-w c:\windows\system32\dcache.bin
- 2004-08-10 19:00:00 8,704 ----a-w c:\windows\system32\dciman32.dll
+ 2008-04-14 00:11:51 8,704 ----a-w c:\windows\system32\dciman32.dll
- 2004-08-10 19:00:00 5,120 ----a-w c:\windows\system32\dcomcnfg.exe
+ 2008-04-14 00:12:16 6,144 ----a-w c:\windows\system32\dcomcnfg.exe
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\ddeshare.exe
+ 2008-04-14 00:12:16 30,208 ----a-w c:\windows\system32\ddeshare.exe
- 2004-08-10 19:00:00 266,240 ----a-w c:\windows\system32\ddraw.dll
+ 2008-04-14 00:11:51 279,552 ----a-w c:\windows\system32\ddraw.dll
- 2004-08-10 19:00:00 27,136 ----a-w c:\windows\system32\ddrawex.dll
+ 2008-04-14 00:11:51 27,136 ----a-w c:\windows\system32\ddrawex.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\defrag.exe
+ 2008-04-14 00:12:16 25,088 ----a-w c:\windows\system32\defrag.exe
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\devenum.dll
+ 2008-04-14 00:11:51 59,904 ----a-w c:\windows\system32\devenum.dll
- 2004-02-22 08:11:08 719,872 ----a-w c:\windows\system32\devil.dll
+ 2004-05-26 12:37:34 719,872 ----a-w c:\windows\system32\devil.dll
- 2004-08-10 19:00:00 282,624 ----a-w c:\windows\system32\devmgr.dll
+ 2008-04-14 00:11:51 282,624 ----a-w c:\windows\system32\devmgr.dll
- 2004-08-10 19:00:00 82,432 ----a-w c:\windows\system32\dfrgfat.exe
+ 2008-04-14 00:12:16 82,944 ----a-w c:\windows\system32\dfrgfat.exe
- 2004-08-10 19:00:00 104,960 ----a-w c:\windows\system32\dfrgntfs.exe
+ 2008-04-14 00:12:16 105,472 ----a-w c:\windows\system32\dfrgntfs.exe
- 2004-08-10 19:00:00 38,912 ----a-w c:\windows\system32\dfrgsnap.dll
+ 2008-04-14 00:11:51 39,424 ----a-w c:\windows\system32\dfrgsnap.dll
- 2004-08-10 19:00:00 123,904 ----a-w c:\windows\system32\dfrgui.dll
+ 2008-04-14 00:11:51 124,416 ----a-w c:\windows\system32\dfrgui.dll
+ 2007-10-24 05:47:28 96,760 ----a-w c:\windows\system32\dfshim.dll
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\dfsshlex.dll
+ 2008-04-14 00:11:51 28,672 ----a-w c:\windows\system32\dfsshlex.dll
- 2004-08-10 19:00:00 111,104 ----a-w c:\windows\system32\dgnet.dll
+ 2008-04-14 00:11:51 111,104 ----a-w c:\windows\system32\dgnet.dll
- 2006-05-19 12:59:41 111,616 ----a-w c:\windows\system32\dhcpcsvc.dll
+ 2008-04-14 00:11:51 126,976 ----a-w c:\windows\system32\dhcpcsvc.dll
- 2004-08-10 19:00:00 370,176 ----a-w c:\windows\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 379,904 ----a-w c:\windows\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ------w c:\windows\system32\dhcpqec.dll
- 2004-08-10 19:00:00 85,504 ----a-w c:\windows\system32\diantz.exe
+ 2008-04-14 00:12:17 87,040 ----a-w c:\windows\system32\diantz.exe
- 2004-08-10 19:00:00 68,608 ----a-w c:\windows\system32\digest.dll
+ 2008-04-14 00:11:52 68,608 ----a-w c:\windows\system32\digest.dll
+ 2008-04-14 00:11:52 19,456 ------w c:\windows\system32\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ------w c:\windows\system32\dimsroam.dll
- 2004-08-10 19:00:00 159,232 ----a-w c:\windows\system32\dinput.dll
+ 2008-04-14 00:11:52 158,720 ----a-w c:\windows\system32\dinput.dll
- 2004-08-10 19:00:00 181,760 ----a-w c:\windows\system32\dinput8.dll
+ 2008-04-14 00:11:52 181,760 ----a-w c:\windows\system32\dinput8.dll
- 2004-08-10 19:00:00 1,501,696 ----a-w c:\windows\system32\diskcopy.dll
+ 2008-04-14 00:11:52 1,504,256 ----a-w c:\windows\system32\diskcopy.dll
- 2004-08-10 19:00:00 163,840 ----a-w c:\windows\system32\diskpart.exe
+ 2008-04-14 00:12:17 163,840 ----a-w c:\windows\system32\diskpart.exe
- 2004-08-10 19:00:00 45,083 ----a-w c:\windows\system32\dispex.dll
+ 2008-04-14 00:11:52 32,768 ----a-w c:\windows\system32\dispex.dll
- 2008-03-31 21:25:46 682,496 ----a-w c:\windows\system32\DivX.dll
+ 2007-01-03 21:51:25 637,534 ----a-w c:\windows\system32\DivX.dll
- 2008-03-31 21:25:48 823,296 ----a-w c:\windows\system32\divx_xx07.dll
+ 2007-01-03 21:51:25 806,912 ----a-w c:\windows\system32\divx_xx07.dll
- 2008-03-31 21:25:46 831,488 ----a-w c:\windows\system32\divx_xx0a.dll
+ 2008-08-05 21:58:58 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
- 2008-03-31 21:25:48 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
+ 2007-01-03 21:51:25 806,912 ----a-w c:\windows\system32\divx_xx0c.dll
- 2008-03-31 21:25:46 802,816 ----a-w c:\windows\system32\divx_xx11.dll
+ 2007-01-03 21:51:25 790,528 ----a-w c:\windows\system32\divx_xx11.dll
+ 2007-01-03 22:02:40 118,784 ----a-w c:\windows\system32\DivXCodecUpdateChecker.exe
- 2008-03-31 21:25:52 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
+ 2008-08-05 21:58:32 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
- 2008-03-21 20:30:12 524,288 ----a-w c:\windows\system32\DivXsm.exe
+ 2007-01-03 21:58:18 520,192 ----a-w c:\windows\system32\DivXsm.exe
- 2008-03-21 20:28:20 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
+ 2007-01-03 22:02:23 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
+ 2008-04-14 00:11:48 451,072 -c--a-w c:\windows\system32\dllcache\aclayers.dll
+ 2008-04-14 00:11:48 141,312 -c--a-w c:\windows\system32\dllcache\aclua.dll
+ 2008-04-14 00:11:48 116,224 -c--a-w c:\windows\system32\dllcache\acxtrnal.dll
- 2008-04-23 04:16:28 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
- 2008-06-20 10:44:38 138,368 -c----w c:\windows\system32\dllcache\afd.sys
+ 2008-08-14 10:04:36 138,496 -c----w c:\windows\system32\dllcache\afd.sys

EasyEEE
2008-12-29, 18:13
+ 2008-04-14 00:11:48 24,064 -c--a-w c:\windows\system32\dllcache\agentanm.dll
+ 2008-04-14 00:11:48 214,016 -c--a-w c:\windows\system32\dllcache\agentctl.dll
- 2007-03-09 13:58:57 57,344 -c----w c:\windows\system32\dllcache\agentdpv.dll
+ 2008-04-14 00:11:48 57,344 -c--a-w c:\windows\system32\dllcache\agentdpv.dll
+ 2008-04-14 00:11:48 49,152 -c--a-w c:\windows\system32\dllcache\agentmpx.dll
+ 2008-04-14 00:11:48 44,032 -c--a-w c:\windows\system32\dllcache\agentsr.dll
- 2006-10-12 11:09:53 256,512 -c----w c:\windows\system32\dllcache\agentsvr.exe
+ 2008-04-14 00:12:12 256,512 -c--a-w c:\windows\system32\dllcache\agentsvr.exe
+ 2007-04-02 18:25:59 19,456 -c--a-w c:\windows\system32\dllcache\agt0405.dll
+ 2007-04-02 18:25:59 19,456 -c--a-w c:\windows\system32\dllcache\agt0406.dll
+ 2007-04-02 18:26:00 21,504 -c--a-w c:\windows\system32\dllcache\agt0407.dll
+ 2007-04-02 18:26:00 22,016 -c--a-w c:\windows\system32\dllcache\agt0408.dll
+ 2008-04-13 17:32:28 19,968 -c--a-w c:\windows\system32\dllcache\agt0409.dll
+ 2007-04-02 18:26:00 19,456 -c--a-w c:\windows\system32\dllcache\agt040b.dll
+ 2007-04-02 18:26:00 21,504 -c--a-w c:\windows\system32\dllcache\agt040c.dll
+ 2007-04-02 18:26:00 19,968 -c--a-w c:\windows\system32\dllcache\agt040e.dll
+ 2007-04-02 18:26:00 20,992 -c--a-w c:\windows\system32\dllcache\agt0410.dll
+ 2007-04-02 18:26:01 20,992 -c--a-w c:\windows\system32\dllcache\agt0413.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\system32\dllcache\agt0414.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\system32\dllcache\agt0415.dll
+ 2007-04-02 18:26:01 20,480 -c--a-w c:\windows\system32\dllcache\agt0416.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\system32\dllcache\agt0419.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\system32\dllcache\agt041d.dll
+ 2007-04-02 18:26:01 19,456 -c--a-w c:\windows\system32\dllcache\agt041f.dll
+ 2007-04-02 18:26:02 20,992 -c--a-w c:\windows\system32\dllcache\agt0816.dll
+ 2007-04-02 18:26:02 20,480 -c--a-w c:\windows\system32\dllcache\agt0c0a.dll
+ 2008-04-14 00:11:49 24,064 -c--a-w c:\windows\system32\dllcache\agtintl.dll
+ 2004-08-10 19:00:00 69,584 -c--a-w c:\windows\system32\dllcache\avicap.dll
+ 2004-08-10 19:00:00 109,456 -c--a-w c:\windows\system32\dllcache\avifile.dll
+ 2004-08-10 19:00:00 82,501 -c--a-w c:\windows\system32\dllcache\bckg.dll
+ 2004-08-10 19:00:00 4,224 -c--a-w c:\windows\system32\dllcache\beep.sys
+ 2004-08-10 19:00:00 361,472 -c--a-w c:\windows\system32\dllcache\blue_ss.dll
+ 2004-08-10 19:00:00 152,576 -c--a-w c:\windows\system32\dllcache\bnts.dll
+ 2004-08-10 19:00:00 21,504 -c--a-w c:\windows\system32\dllcache\brpinfo.dll
- 2008-06-13 13:10:50 272,128 -c----w c:\windows\system32\dllcache\bthport.sys
+ 2008-06-13 11:05:51 272,128 -c----w c:\windows\system32\dllcache\bthport.sys
+ 2008-04-13 18:46:24 17,024 -c--a-w c:\windows\system32\dllcache\ccdecode.sys
+ 2001-08-17 13:52:30 18,688 -c--a-w c:\windows\system32\dllcache\cdaudio.sys
- 2007-07-31 00:19:20 92,504 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 19:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
+ 2004-08-10 19:00:00 40,515 -c--a-w c:\windows\system32\dllcache\chkr.dll
+ 2004-08-10 19:00:00 217,160 -c--a-w c:\windows\system32\dllcache\cmnclim.dll
+ 2004-08-10 19:00:00 1,039,955 -c--a-w c:\windows\system32\dllcache\cmnresm.dll
+ 2008-04-13 16:44:16 17,920 -c--a-w c:\windows\system32\dllcache\cobramsg.dll
+ 2008-04-14 00:11:51 195,072 -c--a-w c:\windows\system32\dllcache\comadmin.dll
+ 2004-08-10 19:00:00 32,816 -c--a-w c:\windows\system32\dllcache\commdlg.dll
+ 2008-04-14 00:12:15 9,728 -c--a-w c:\windows\system32\dllcache\comrepl.exe
+ 2008-04-14 00:12:15 6,144 -c--a-w c:\windows\system32\dllcache\comrereg.exe
+ 2008-05-07 09:07:23 135,168 -c----w c:\windows\system32\dllcache\cscript.exe
+ 2004-08-10 19:11:42 152,064 -c--a-w c:\windows\system32\dllcache\debugsvc.dll
- 2007-05-16 15:12:00 86,528 -c----w c:\windows\system32\dllcache\directdb.dll
+ 2008-04-14 00:11:52 86,528 -c--a-w c:\windows\system32\dllcache\directdb.dll
- 2008-06-20 17:41:10 148,992 -c--a-w c:\windows\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 -c----w c:\windows\system32\dllcache\dnsapi.dll
+ 2004-08-10 19:00:00 120,320 -c--a-w c:\windows\system32\dllcache\dsprov.dll
- 2006-08-22 09:05:26 498,742 -c----w c:\windows\system32\dllcache\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 -c----w c:\windows\system32\dllcache\dxmasf.dll
- 2008-04-23 04:16:28 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-04-23 04:16:28 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-10 19:11:48 1,370,112 -c--a-w c:\windows\system32\dllcache\ehchsime.dll
+ 2005-08-06 05:01:54 102,400 -c--a-w c:\windows\system32\dllcache\ehcir.dll
+ 2005-08-06 05:01:56 192,512 -c--a-w c:\windows\system32\dllcache\ehcommon.dll
+ 2005-08-06 05:01:56 126,976 -c--a-w c:\windows\system32\dllcache\ehepgdat.dll
+ 2004-08-10 19:11:42 35,328 -c--a-w c:\windows\system32\dllcache\ehepgdec.dll
+ 2005-08-06 05:01:56 73,728 -c--a-w c:\windows\system32\dllcache\ehiextens.dll
+ 2005-08-06 05:01:56 204,800 -c--a-w c:\windows\system32\dllcache\ehiplay.dll
+ 2005-08-06 05:01:56 389,120 -c--a-w c:\windows\system32\dllcache\ehiproxy.dll
+ 2005-08-06 05:01:56 18,944 -c--a-w c:\windows\system32\dllcache\ehiuserxp.dll
+ 2005-08-06 05:01:56 278,528 -c--a-w c:\windows\system32\dllcache\ehividctl.dll
+ 2004-08-10 19:12:46 122,880 -c--a-w c:\windows\system32\dllcache\ehiwmp.dll
+ 2005-08-06 05:01:56 45,056 -c--a-w c:\windows\system32\dllcache\ehjpnime.dll
+ 2005-08-06 05:01:56 389,120 -c--a-w c:\windows\system32\dllcache\ehrecobj.dll
+ 2008-07-07 20:26:58 253,952 -c----w c:\windows\system32\dllcache\es.dll
+ 2008-04-14 00:11:53 21,504 -c--a-w c:\windows\system32\dllcache\evntrprv.dll
+ 2008-04-14 00:11:53 45,056 -c--a-w c:\windows\system32\dllcache\evtgprov.dll
- 2008-04-23 04:16:28 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2007-03-23 00:24:58 28,160 -c----w c:\windows\system32\dllcache\FilterPipelinePrintProc.dll
+ 2008-04-14 00:11:53 618,605 -c--a-w c:\windows\system32\dllcache\fp4autl.dll
+ 2004-08-10 19:00:00 6,144 -c--a-w c:\windows\system32\dllcache\fsconins.dll
+ 2004-08-10 19:00:00 53,248 -c--a-w c:\windows\system32\dllcache\fwdprov.dll
+ 2008-04-13 16:10:32 61,440 -c--a-w c:\windows\system32\dllcache\gacutil.exe
- 2008-02-20 06:51:05 282,624 -c----w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 12:36:14 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll
+ 2008-04-14 00:11:54 133,120 -c--a-w c:\windows\system32\dllcache\guitrn.dll
+ 2008-04-14 00:11:54 115,200 -c--a-w c:\windows\system32\dllcache\guitrna.dll
+ 2004-08-10 19:00:00 99,840 -c--a-w c:\windows\system32\dllcache\helphost.exe
+ 2004-08-10 19:00:00 87,552 -c--a-w c:\windows\system32\dllcache\hhctrlui.dll
+ 2004-08-10 19:00:00 362,496 -c--a-w c:\windows\system32\dllcache\home_ss.dll
+ 2004-08-10 19:00:00 57,409 -c--a-w c:\windows\system32\dllcache\hrtz.dll
+ 2008-04-14 00:12:21 18,432 -c--a-w c:\windows\system32\dllcache\hscupd.exe
- 2008-04-23 04:16:28 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
- 2008-04-22 07:39:58 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-23 04:16:28 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
- 2008-04-23 04:16:28 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
- 2008-04-20 05:07:51 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
- 2008-04-23 04:16:28 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-04-23 04:16:28 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-23 04:16:28 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
- 2008-04-23 04:16:28 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
- 2008-04-23 04:16:28 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
- 2008-04-22 07:39:58 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
- 2008-04-22 07:40:18 625,664 -c----w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe
- 2007-08-21 06:15:44 683,520 -c----w c:\windows\system32\dllcache\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 -c----w c:\windows\system32\dllcache\inetcomm.dll
- 2007-08-13 23:38:04 491,520 -c--a-w c:\windows\system32\dllcache\jscript.dll
+ 2008-05-09 10:53:39 512,000 -c----w c:\windows\system32\dllcache\jscript.dll
- 2008-04-23 04:16:28 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-10 19:00:00 2,000 -c--a-w c:\windows\system32\dllcache\keyboard.drv
+ 2008-04-14 00:11:56 24,576 -c--a-w c:\windows\system32\dllcache\krnlprov.dll
+ 2008-04-14 00:11:56 19,968 -c--a-w c:\windows\system32\dllcache\log.dll
+ 2008-06-18 06:09:22 100,864 -c----w c:\windows\system32\dllcache\logagent.exe
+ 2004-08-10 19:00:00 9,936 -c--a-w c:\windows\system32\dllcache\lzexpand.dll
+ 2004-08-10 19:00:00 73,376 -c--a-w c:\windows\system32\dllcache\mciavi.drv
+ 2004-08-10 19:00:00 25,264 -c--a-w c:\windows\system32\dllcache\mciseq.drv
+ 2004-08-10 19:00:00 28,160 -c--a-w c:\windows\system32\dllcache\mciwave.drv
+ 2005-08-06 04:29:12 63,488 -c--a-w c:\windows\system32\dllcache\medctrro.exe
+ 2004-08-10 19:00:00 362,496 -c--a-w c:\windows\system32\dllcache\metal_ss.dll
+ 2008-04-14 00:11:57 274,432 -c--a-w c:\windows\system32\dllcache\migism.dll
+ 2008-04-14 00:11:57 261,120 -c--a-w c:\windows\system32\dllcache\migisma.dll
+ 2008-04-14 00:12:25 103,936 -c--a-w c:\windows\system32\dllcache\migload.exe
+ 2008-04-14 00:12:25 241,152 -c--a-w c:\windows\system32\dllcache\migwiza.exe
+ 2004-08-10 19:00:00 68,768 -c--a-w c:\windows\system32\dllcache\mmsystem.dll
+ 2008-04-14 00:12:26 16,384 -c--a-w c:\windows\system32\dllcache\mofcomp.exe
+ 2004-08-10 19:00:00 2,032 -c--a-w c:\windows\system32\dllcache\mouse.drv
- 2006-05-05 09:41:45 453,120 -c----w c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
+ 2008-05-01 14:33:02 331,776 -c----w c:\windows\system32\dllcache\msadce.dll
+ 2008-04-13 17:25:57 20,480 -c--a-w c:\windows\system32\dllcache\msadcer.dll
+ 2008-04-14 00:11:58 61,440 -c--a-w c:\windows\system32\dllcache\msadcf.dll
+ 2008-04-13 17:25:57 16,384 -c--a-w c:\windows\system32\dllcache\msadcfr.dll
+ 2008-04-13 17:25:57 16,384 -c--a-w c:\windows\system32\dllcache\msadcor.dll
+ 2008-04-14 00:11:58 53,248 -c--a-w c:\windows\system32\dllcache\msadcs.dll
+ 2008-04-14 00:11:58 155,648 -c--a-w c:\windows\system32\dllcache\msadds.dll
+ 2008-04-13 17:25:58 24,576 -c--a-w c:\windows\system32\dllcache\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 -c--a-w c:\windows\system32\dllcache\msader15.dll
- 2006-12-26 13:07:23 180,224 -c----w c:\windows\system32\dllcache\msadomd.dll
+ 2008-04-14 00:11:58 180,224 -c--a-w c:\windows\system32\dllcache\msadomd.dll
+ 2008-04-14 00:11:58 57,344 -c--a-w c:\windows\system32\dllcache\msador15.dll
+ 2008-04-14 00:11:58 220,160 -c--a-w c:\windows\system32\dllcache\mscandui.dll
+ 2008-06-24 16:43:16 74,240 -c----w c:\windows\system32\dllcache\mscms.dll
+ 2008-04-14 00:11:58 4,096 -c--a-w c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:11:58 4,096 -c--a-w c:\windows\system32\dllcache\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 -c--a-w c:\windows\system32\dllcache\msdaer.dll
+ 2008-04-14 00:11:58 233,472 -c--a-w c:\windows\system32\dllcache\msdaora.dll
+ 2008-04-13 17:24:14 16,384 -c--a-w c:\windows\system32\dllcache\msdaorar.dll
+ 2008-04-14 00:11:58 77,824 -c--a-w c:\windows\system32\dllcache\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 -c--a-w c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 -c--a-w c:\windows\system32\dllcache\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 -c--a-w c:\windows\system32\dllcache\msdaps.dll
+ 2008-04-14 00:11:59 118,784 -c--a-w c:\windows\system32\dllcache\msdarem.dll
+ 2008-04-13 17:25:58 16,384 -c--a-w c:\windows\system32\dllcache\msdaremr.dll
+ 2008-04-14 00:11:59 4,096 -c--a-w c:\windows\system32\dllcache\msdasc.dll
+ 2008-04-14 00:11:59 315,392 -c--a-w c:\windows\system32\dllcache\msdasql.dll
+ 2008-04-13 17:26:07 16,384 -c--a-w c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-04-14 00:11:59 94,208 -c--a-w c:\windows\system32\dllcache\msdatl3.dll
+ 2008-04-14 00:11:59 20,480 -c--a-w c:\windows\system32\dllcache\msdatt.dll
+ 2008-04-14 00:11:59 4,096 -c--a-w c:\windows\system32\dllcache\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 -c--a-w c:\windows\system32\dllcache\msdfmap.dll
- 2008-04-23 04:16:28 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
- 2008-04-23 04:16:28 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-04-14 00:11:59 3,166,208 -c--a-w c:\windows\system32\dllcache\msgr3en.dll
- 2008-04-24 02:16:30 3,591,680 -c----w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
- 2008-04-23 04:16:28 478,208 -c----w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-10 19:00:00 273,920 -c--a-w c:\windows\system32\dllcache\msiprov.dll
+ 2008-04-14 00:12:00 39,936 -c--a-w c:\windows\system32\dllcache\mslwvtts.dll
+ 2008-04-14 00:12:00 122,368 -c--a-w c:\windows\system32\dllcache\msobcomm.dll
+ 2008-04-14 00:12:00 16,384 -c--a-w c:\windows\system32\dllcache\msobdl.dll
+ 2008-04-14 00:12:00 565,248 -c--a-w c:\windows\system32\dllcache\msobmain.dll
+ 2008-04-14 00:12:00 30,720 -c--a-w c:\windows\system32\dllcache\msobshel.dll
+ 2008-04-14 00:12:00 19,456 -c--a-w c:\windows\system32\dllcache\msobweb.dll
+ 2008-04-14 00:12:28 29,184 -c--a-w c:\windows\system32\dllcache\msoobe.exe
- 2008-04-23 04:16:28 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
+ 2004-08-10 19:00:00 235,520 -c--a-w c:\windows\system32\dllcache\mssoap1.dll
+ 2004-08-10 19:00:00 23,552 -c--a-w c:\windows\system32\dllcache\mssoapr.dll
+ 2008-04-13 18:39:50 5,504 -c--a-w c:\windows\system32\dllcache\mstee.sys
- 2008-04-23 04:16:28 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
+ 2004-08-10 19:00:00 126,912 -c--a-w c:\windows\system32\dllcache\msvideo.dll
- 2008-06-20 17:41:10 245,248 -c----w c:\windows\system32\dllcache\mswsock.dll
+ 2008-06-20 17:46:57 245,248 -c----w c:\windows\system32\dllcache\mswsock.dll
+ 2008-04-14 00:12:01 24,576 -c--a-w c:\windows\system32\dllcache\msxactps.dll
- 2007-06-26 06:08:16 1,104,896 -c----w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 -c----w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-10 01:14:56 1,307,648 -c----w c:\windows\system32\dllcache\msxml6.dll
+ 2008-04-13 17:27:18 79,872 -c----w c:\windows\system32\dllcache\msxml6r.dll
+ 2008-04-14 00:12:29 90,624 -c--a-w c:\windows\system32\dllcache\muisetup.exe
+ 2008-04-13 18:46:26 85,248 -c--a-w c:\windows\system32\dllcache\nabtsfec.sys
+ 2008-04-13 18:46:22 10,880 -c--a-w c:\windows\system32\dllcache\ndisip.sys
+ 2008-04-14 00:12:01 57,344 -c--a-w c:\windows\system32\dllcache\ndisnpp.dll
- 2006-08-17 12:28:27 332,288 -c----w c:\windows\system32\dllcache\netapi32.dll
+ 2008-10-15 16:34:24 337,408 -c----w c:\windows\system32\dllcache\netapi32.dll
+ 2008-04-14 00:12:29 69,120 -c--a-w c:\windows\system32\dllcache\notepad.exe
+ 2004-08-10 19:00:00 35,328 -c--a-w c:\windows\system32\dllcache\notiflag.exe
+ 2008-04-14 00:12:29 15,360 -c--a-w c:\windows\system32\dllcache\nppagent.exe
+ 2008-04-14 00:12:02 212,992 -c--a-w c:\windows\system32\dllcache\ntevt.dll
- 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-08-14 10:09:26 2,145,280 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 -c----w c:\windows\system32\dllcache\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-08-14 09:33:16 2,023,936 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-04-13 18:40:07 393,728 -c--a-w c:\windows\system32\dllcache\obrb0401.dll
+ 2008-04-13 18:40:23 212,480 -c--a-w c:\windows\system32\dllcache\obrb0404.dll
+ 2008-04-13 18:40:24 428,032 -c--a-w c:\windows\system32\dllcache\obrb0405.dll
+ 2008-04-13 18:40:27 418,816 -c--a-w c:\windows\system32\dllcache\obrb0406.dll
+ 2008-04-13 18:40:34 403,456 -c--a-w c:\windows\system32\dllcache\obrb0407.dll
+ 2008-04-13 18:40:30 419,328 -c--a-w c:\windows\system32\dllcache\obrb0408.dll
+ 2008-04-13 18:40:32 405,504 -c--a-w c:\windows\system32\dllcache\obrb040b.dll
+ 2008-04-13 18:40:33 410,624 -c--a-w c:\windows\system32\dllcache\obrb040C.dll
+ 2008-04-13 18:40:32 384,000 -c--a-w c:\windows\system32\dllcache\obrb040D.dll
+ 2008-04-13 18:40:39 434,176 -c--a-w c:\windows\system32\dllcache\obrb040e.dll
+ 2008-04-13 18:40:39 413,696 -c--a-w c:\windows\system32\dllcache\obrb0410.dll
+ 2008-04-13 18:40:44 275,456 -c--a-w c:\windows\system32\dllcache\obrb0411.dll
+ 2008-04-13 18:40:48 306,688 -c--a-w c:\windows\system32\dllcache\obrb0412.dll
+ 2008-04-13 18:40:44 401,920 -c--a-w c:\windows\system32\dllcache\obrb0413.dll
+ 2008-04-13 18:40:44 353,792 -c--a-w c:\windows\system32\dllcache\obrb0414.dll
+ 2008-04-13 18:40:47 391,680 -c--a-w c:\windows\system32\dllcache\obrb0415.dll
+ 2008-04-13 18:40:10 409,600 -c--a-w c:\windows\system32\dllcache\obrb0416.dll
+ 2008-04-13 18:40:50 427,008 -c--a-w c:\windows\system32\dllcache\obrb0419.dll
+ 2008-04-13 18:40:52 405,504 -c--a-w c:\windows\system32\dllcache\obrb041b.dll
+ 2008-04-13 18:40:56 363,008 -c--a-w c:\windows\system32\dllcache\obrb041D.dll
+ 2008-04-13 18:41:00 390,144 -c--a-w c:\windows\system32\dllcache\obrb041f.dll
+ 2008-04-13 18:40:56 408,576 -c--a-w c:\windows\system32\dllcache\obrb0424.dll
+ 2008-04-13 18:40:24 270,336 -c--a-w c:\windows\system32\dllcache\obrb0804.dll
+ 2008-04-13 18:40:48 435,200 -c--a-w c:\windows\system32\dllcache\obrb0816.dll
+ 2008-04-13 18:40:30 446,464 -c--a-w c:\windows\system32\dllcache\obrb0C0A.dll
- 2008-04-23 04:16:28 102,912 -c----w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll
+ 2004-08-10 19:00:00 82,944 -c--a-w c:\windows\system32\dllcache\olecli.dll
+ 2004-08-10 19:00:00 24,064 -c--a-w c:\windows\system32\dllcache\olesvr.dll
+ 2008-04-14 00:12:31 51,200 -c--a-w c:\windows\system32\dllcache\oobebaln.exe
- 2008-04-23 04:16:28 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 00:12:02 92,672 -c--a-w c:\windows\system32\dllcache\policman.dll
+ 2007-03-23 00:25:42 677,376 -c----w c:\windows\system32\dllcache\PrintFilterPipelineSvc.exe
+ 2008-04-14 00:12:03 237,056 -c--a-w c:\windows\system32\dllcache\provthrd.dll
- 2008-05-07 04:55:40 1,288,192 -c----w c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 -c----w c:\windows\system32\dllcache\quartz.dll
- 2008-05-08 12:28:49 202,752 -c----w c:\windows\system32\dllcache\rmcast.sys
+ 2008-05-08 14:02:52 203,136 -c----w c:\windows\system32\dllcache\rmcast.sys
+ 2004-08-10 19:00:00 48,706 -c--a-w c:\windows\system32\dllcache\rvse.dll
+ 2008-04-14 00:12:04 741,376 -c--a-w c:\windows\system32\dllcache\sapi.dll
+ 2004-08-10 19:00:00 36,864 -c--a-w c:\windows\system32\dllcache\sapisvr.exe
+ 2008-04-14 00:12:34 36,352 -c--a-w c:\windows\system32\dllcache\scrcons.exe
+ 2008-04-14 00:12:05 215,552 -c--a-w c:\windows\system32\dllcache\script.dll
+ 2008-04-14 00:12:05 199,680 -c--a-w c:\windows\system32\dllcache\scripta.dll
+ 2008-05-09 10:53:39 180,224 -c----w c:\windows\system32\dllcache\scrobj.dll
+ 2008-05-09 10:53:40 172,032 -c----w c:\windows\system32\dllcache\scrrun.dll
+ 2008-04-14 00:12:05 221,696 -c--a-w c:\windows\system32\dllcache\seo.dll
+ 2004-08-10 19:00:00 5,120 -c--a-w c:\windows\system32\dllcache\shell.dll
+ 2004-08-10 19:00:00 66,113 -c--a-w c:\windows\system32\dllcache\shvl.dll
+ 2008-04-13 18:46:24 11,136 -c--a-w c:\windows\system32\dllcache\slip.sys
+ 2008-04-14 00:12:35 32,866 -c--a-w c:\windows\system32\dllcache\slrundll.exe
+ 2008-04-14 00:12:06 189,440 -c--a-w c:\windows\system32\dllcache\smtpadm.dll
+ 2004-08-10 19:00:00 40,960 -c--a-w c:\windows\system32\dllcache\smtpcons.dll
+ 2008-04-14 00:12:06 2,134,528 -c--a-w c:\windows\system32\dllcache\smtpsnap.dll
+ 2008-04-14 00:12:06 34,816 -c--a-w c:\windows\system32\dllcache\sniffpol.dll
+ 2008-04-14 00:12:06 130,048 -c--a-w c:\windows\system32\dllcache\softkbd.dll
+ 2004-08-10 19:00:00 1,744 -c--a-w c:\windows\system32\dllcache\sound.drv
+ 2004-08-10 19:00:00 77,824 -c--a-w c:\windows\system32\dllcache\spcommon.dll
+ 2004-08-10 19:00:00 61,440 -c--a-w c:\windows\system32\dllcache\spcplui.dll
+ 2008-04-13 16:43:18 62,976 -c--a-w c:\windows\system32\dllcache\spgrmr.dll
+ 2008-04-13 18:35:06 186,880 -c--a-w c:\windows\system32\dllcache\spra0401.dll
+ 2008-04-13 18:35:08 189,440 -c--a-w c:\windows\system32\dllcache\spra0402.dll
+ 2008-04-13 18:35:09 161,280 -c--a-w c:\windows\system32\dllcache\spra0404.dll
+ 2008-04-13 18:35:09 188,928 -c--a-w c:\windows\system32\dllcache\spra0405.dll
+ 2008-04-13 18:35:09 192,000 -c--a-w c:\windows\system32\dllcache\spra0406.dll
+ 2008-04-13 18:35:21 199,680 -c--a-w c:\windows\system32\dllcache\spra0407.dll
+ 2008-04-13 18:35:11 197,632 -c--a-w c:\windows\system32\dllcache\spra0408.dll
+ 2008-04-13 18:35:11 186,368 -c--a-w c:\windows\system32\dllcache\spra040b.dll
+ 2008-04-13 18:35:20 197,632 -c--a-w c:\windows\system32\dllcache\spra040C.dll
+ 2008-04-13 18:35:21 181,760 -c--a-w c:\windows\system32\dllcache\spra040D.dll
+ 2008-04-13 18:35:23 195,584 -c--a-w c:\windows\system32\dllcache\spra040e.dll
+ 2008-04-13 18:35:23 195,072 -c--a-w c:\windows\system32\dllcache\spra0410.dll
+ 2008-04-13 18:35:23 171,008 -c--a-w c:\windows\system32\dllcache\spra0411.dll
+ 2008-04-13 18:35:23 167,936 -c--a-w c:\windows\system32\dllcache\spra0412.dll
+ 2008-04-13 18:35:25 196,096 -c--a-w c:\windows\system32\dllcache\spra0413.dll
+ 2008-04-13 18:35:25 189,440 -c--a-w c:\windows\system32\dllcache\spra0414.dll
+ 2008-04-13 18:35:26 194,560 -c--a-w c:\windows\system32\dllcache\spra0415.dll
+ 2008-04-13 18:35:08 192,512 -c--a-w c:\windows\system32\dllcache\spra0416.dll
+ 2008-04-13 18:35:27 190,464 -c--a-w c:\windows\system32\dllcache\spra0418.dll
+ 2008-04-13 18:35:27 192,512 -c--a-w c:\windows\system32\dllcache\spra0419.dll
+ 2008-04-13 18:35:21 188,928 -c--a-w c:\windows\system32\dllcache\spra041a.dll
+ 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\dllcache\spra041b.dll
+ 2008-04-13 18:35:28 188,928 -c--a-w c:\windows\system32\dllcache\spra041D.dll
+ 2008-04-13 18:35:29 188,416 -c--a-w c:\windows\system32\dllcache\spra041e.dll
+ 2008-04-13 18:35:30 188,928 -c--a-w c:\windows\system32\dllcache\spra041f.dll
+ 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\dllcache\spra0424.dll
+ 2008-04-13 18:35:11 186,880 -c--a-w c:\windows\system32\dllcache\spra0425.dll
+ 2008-04-13 18:35:24 188,928 -c--a-w c:\windows\system32\dllcache\spra0426.dll
+ 2008-04-13 18:35:24 189,952 -c--a-w c:\windows\system32\dllcache\spra0427.dll
+ 2008-04-13 18:35:06 161,280 -c--a-w c:\windows\system32\dllcache\spra0804.dll
+ 2008-04-13 18:35:26 194,560 -c--a-w c:\windows\system32\dllcache\spra0816.dll
+ 2008-04-13 18:35:11 196,096 -c--a-w c:\windows\system32\dllcache\spra0C0A.dll
+ 2008-04-13 18:35:49 2,869,248 -c--a-w c:\windows\system32\dllcache\sprb0401.dll
+ 2008-04-13 18:36:10 477,696 -c--a-w c:\windows\system32\dllcache\sprb0404.dll
+ 2008-04-13 18:36:10 734,720 -c--a-w c:\windows\system32\dllcache\sprb0405.dll
+ 2008-04-13 18:36:10 742,912 -c--a-w c:\windows\system32\dllcache\sprb0406.dll
+ 2008-04-13 18:37:03 788,480 -c--a-w c:\windows\system32\dllcache\sprb0407.dll
+ 2008-04-13 18:36:35 801,280 -c--a-w c:\windows\system32\dllcache\sprb0408.dll
+ 2008-04-13 18:36:39 729,088 -c--a-w c:\windows\system32\dllcache\sprb040b.dll
+ 2008-04-13 18:36:55 793,088 -c--a-w c:\windows\system32\dllcache\sprb040C.dll
+ 2008-04-13 18:37:07 2,842,112 -c--a-w c:\windows\system32\dllcache\sprb040D.dll
+ 2008-04-13 18:37:22 769,536 -c--a-w c:\windows\system32\dllcache\sprb040e.dll
+ 2008-04-13 18:37:22 769,536 -c--a-w c:\windows\system32\dllcache\sprb0410.dll
+ 2008-04-13 18:37:34 562,688 -c--a-w c:\windows\system32\dllcache\sprb0411.dll
+ 2008-04-13 18:37:37 543,744 -c--a-w c:\windows\system32\dllcache\sprb0412.dll
+ 2008-04-13 18:38:00 769,024 -c--a-w c:\windows\system32\dllcache\sprb0413.dll
+ 2008-04-13 18:38:02 716,288 -c--a-w c:\windows\system32\dllcache\sprb0414.dll
+ 2008-04-13 18:38:05 759,808 -c--a-w c:\windows\system32\dllcache\sprb0415.dll
+ 2008-04-13 18:35:43 752,128 -c--a-w c:\windows\system32\dllcache\sprb0416.dll
+ 2008-04-13 18:38:28 736,768 -c--a-w c:\windows\system32\dllcache\sprb0419.dll
+ 2008-04-13 18:38:37 757,248 -c--a-w c:\windows\system32\dllcache\sprb041b.dll
+ 2008-04-13 18:38:47 724,480 -c--a-w c:\windows\system32\dllcache\sprb041D.dll
+ 2008-04-13 18:38:51 724,480 -c--a-w c:\windows\system32\dllcache\sprb041f.dll
+ 2008-04-13 18:38:36 732,160 -c--a-w c:\windows\system32\dllcache\sprb0424.dll
+ 2008-04-13 18:35:54 470,016 -c--a-w c:\windows\system32\dllcache\sprb0804.dll
+ 2008-04-13 18:38:06 751,616 -c--a-w c:\windows\system32\dllcache\sprb0816.dll
+ 2008-04-13 18:36:38 773,632 -c--a-w c:\windows\system32\dllcache\sprb0C0A.dll
+ 2008-04-13 18:39:02 656,896 -c--a-w c:\windows\system32\dllcache\sprc0401.dll
+ 2008-04-13 18:39:13 327,680 -c--a-w c:\windows\system32\dllcache\sprc0404.dll
+ 2008-04-13 18:39:02 601,088 -c--a-w c:\windows\system32\dllcache\sprc0405.dll
+ 2008-04-13 18:39:12 605,696 -c--a-w c:\windows\system32\dllcache\sprc0406.dll
+ 2008-04-13 18:39:19 663,552 -c--a-w c:\windows\system32\dllcache\sprc0407.dll
+ 2008-04-13 18:39:12 679,936 -c--a-w c:\windows\system32\dllcache\sprc0408.dll
+ 2008-04-13 18:39:17 604,672 -c--a-w c:\windows\system32\dllcache\sprc040b.dll
+ 2008-04-13 18:39:20 663,040 -c--a-w c:\windows\system32\dllcache\sprc040C.dll
+ 2008-04-13 18:39:28 620,544 -c--a-w c:\windows\system32\dllcache\sprc040D.dll
+ 2008-04-13 18:39:28 645,120 -c--a-w c:\windows\system32\dllcache\sprc040e.dll
+ 2008-04-13 18:39:28 658,432 -c--a-w c:\windows\system32\dllcache\sprc0410.dll
+ 2008-04-13 18:39:49 412,672 -c--a-w c:\windows\system32\dllcache\sprc0411.dll
+ 2008-04-13 18:39:49 392,704 -c--a-w c:\windows\system32\dllcache\sprc0412.dll
+ 2008-04-13 18:39:47 645,120 -c--a-w c:\windows\system32\dllcache\sprc0413.dll
+ 2008-04-13 18:39:48 591,872 -c--a-w c:\windows\system32\dllcache\sprc0414.dll
+ 2008-04-13 18:39:52 641,024 -c--a-w c:\windows\system32\dllcache\sprc0415.dll
+ 2008-04-13 18:38:56 620,032 -c--a-w c:\windows\system32\dllcache\sprc0416.dll
+ 2008-04-13 18:39:56 627,200 -c--a-w c:\windows\system32\dllcache\sprc0419.dll
+ 2008-04-13 18:40:04 577,536 -c--a-w c:\windows\system32\dllcache\sprc041b.dll
+ 2008-04-13 18:40:05 590,848 -c--a-w c:\windows\system32\dllcache\sprc041D.dll
+ 2008-04-13 18:40:09 592,896 -c--a-w c:\windows\system32\dllcache\sprc041f.dll
+ 2008-04-13 18:40:05 576,512 -c--a-w c:\windows\system32\dllcache\sprc0424.dll
+ 2008-04-13 18:39:03 322,560 -c--a-w c:\windows\system32\dllcache\sprc0804.dll
+ 2008-04-13 18:39:53 639,488 -c--a-w c:\windows\system32\dllcache\sprc0816.dll
+ 2008-04-13 18:39:13 648,704 -c--a-w c:\windows\system32\dllcache\sprc0C0A.dll
+ 2004-08-10 19:00:00 774,144 -c--a-w c:\windows\system32\dllcache\spttseng.dll
+ 2008-04-14 00:12:06 151,552 -c--a-w c:\windows\system32\dllcache\sqldb20.dll
+ 2008-04-14 00:12:06 462,848 -c--a-w c:\windows\system32\dllcache\sqlqp20.dll
+ 2008-04-14 00:12:06 110,592 -c--a-w c:\windows\system32\dllcache\sqlse20.dll
+ 2008-04-14 00:12:06 217,088 -c--a-w c:\windows\system32\dllcache\sqlxmlx.dll
+ 2004-08-10 19:00:00 47,104 -c--a-w c:\windows\system32\dllcache\srdiag.exe
- 2006-08-14 10:34:41 332,928 -c----w c:\windows\system32\dllcache\srv.sys
+ 2008-09-08 10:41:42 333,824 -c----w c:\windows\system32\dllcache\srv.sys
+ 2008-04-14 00:12:07 33,280 -c--a-w c:\windows\system32\dllcache\sstub.dll
+ 2008-04-14 00:12:07 86,528 -c--a-w c:\windows\system32\dllcache\stdprov.dll
+ 2008-04-13 18:46:22 15,232 -c--a-w c:\windows\system32\dllcache\streamip.sys
- 2006-08-21 14:52:08 246,814 -c----w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c----w c:\windows\system32\dllcache\strmdll.dll
+ 2008-04-14 00:12:07 193,024 -c--a-w c:\windows\system32\dllcache\sysmod.dll
+ 2008-04-14 00:12:07 173,568 -c--a-w c:\windows\system32\dllcache\sysmoda.dll
+ 2004-08-10 19:00:00 3,360 -c--a-w c:\windows\system32\dllcache\system.drv
+ 2004-08-10 19:00:00 19,200 -c--a-w c:\windows\system32\dllcache\tapi.dll
+ 2004-08-10 19:00:00 15,360 -c--a-w c:\windows\system32\dllcache\taskman.exe
- 2008-06-20 10:45:13 360,320 -c--a-w c:\windows\system32\dllcache\tcpip.sys
+ 2008-06-20 11:51:12 361,600 -c----w c:\windows\system32\dllcache\tcpip.sys
- 2008-06-20 09:52:06 225,920 -c--a-w c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 -c----w c:\windows\system32\dllcache\tcpip6.sys
+ 2008-04-15 15:17:37 295,424 -c----w c:\windows\system32\dllcache\termsrv.dll
+ 2004-08-10 19:00:00 4,048 -c--a-w c:\windows\system32\dllcache\timer.drv
+ 2004-08-10 19:00:00 61,952 -c--a-w c:\windows\system32\dllcache\tmplprov.dll
+ 2004-08-10 19:00:00 3,374,640 -c--a-w c:\windows\system32\dllcache\tourW.exe
+ 2008-04-14 00:12:07 153,088 -c--a-w c:\windows\system32\dllcache\triedit.dll
+ 2004-08-10 19:00:00 59,904 -c--a-w c:\windows\system32\dllcache\trnsprov.dll
+ 2008-04-14 00:12:07 279,040 -c--a-w c:\windows\system32\dllcache\tshoot.dll
+ 2004-08-10 19:00:00 94,784 -c--a-w c:\windows\system32\dllcache\twain.dll
+ 2004-08-10 19:00:00 49,680 -c--a-w c:\windows\system32\dllcache\twunk_16.exe
+ 2004-08-10 19:00:00 25,600 -c--a-w c:\windows\system32\dllcache\twunk_32.exe
+ 2004-08-10 19:00:00 32,339 -c--a-w c:\windows\system32\dllcache\uniansi.dll
+ 2004-08-10 19:00:00 16,896 -c--a-w c:\windows\system32\dllcache\unsecapp.exe
+ 2004-08-10 19:00:00 116,224 -c--a-w c:\windows\system32\dllcache\updprov.dll
+ 2008-04-14 00:12:38 150,528 -c--a-w c:\windows\system32\dllcache\uploadm.exe
- 2008-04-23 04:16:28 105,984 -c----w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
- 2008-04-23 04:16:29 1,159,680 -c----w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-13 18:45:12 60,032 -c--a-w c:\windows\system32\dllcache\usbaudio.sys
+ 2008-04-13 18:45:40 32,128 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
+ 2008-04-14 00:12:38 26,112 -c--a-w c:\windows\system32\dllcache\userinit.exe
- 2007-08-13 23:54:10 413,696 -c----w c:\windows\system32\dllcache\vbscript.dll
+ 2008-05-09 10:53:40 430,080 -c----w c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-10 19:00:00 9,008 -c--a-w c:\windows\system32\dllcache\ver.dll
+ 2008-04-14 00:12:08 53,760 -c--a-w c:\windows\system32\dllcache\vfwwdm32.dll
+ 2004-08-10 19:00:00 2,176 -c--a-w c:\windows\system32\dllcache\vga.drv
+ 2008-04-14 00:12:08 131,584 -c--a-w c:\windows\system32\dllcache\viewprov.dll
+ 2004-08-10 19:00:00 18,944 -c--a-w c:\windows\system32\dllcache\vmmreg32.dll
- 2007-05-16 15:12:12 510,976 -c----w c:\windows\system32\dllcache\wab32.dll
+ 2008-04-14 00:12:08 510,976 -c--a-w c:\windows\system32\dllcache\wab32.dll
+ 2008-04-13 16:21:48 249,856 -c--a-w c:\windows\system32\dllcache\wab32res.dll
+ 2004-08-10 19:00:00 12,288 -c--a-w c:\windows\system32\dllcache\wbemads.dll
+ 2008-04-14 00:12:08 196,608 -c--a-w c:\windows\system32\dllcache\wbemcntl.dll
+ 2008-04-14 00:12:08 178,176 -c--a-w c:\windows\system32\dllcache\wbemdisp.dll
+ 2008-04-14 00:12:08 43,008 -c--a-w c:\windows\system32\dllcache\wbemperf.dll
+ 2008-04-14 00:12:39 116,224 -c--a-w c:\windows\system32\dllcache\wbemtest.exe
+ 2008-04-14 00:12:08 197,120 -c--a-w c:\windows\system32\dllcache\wbemupgd.dll
- 2008-04-23 04:16:29 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-10 19:00:00 13,600 -c--a-w c:\windows\system32\dllcache\wfwnet.drv
- 2008-03-19 09:47:00 1,845,248 -c----w c:\windows\system32\dllcache\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 -c----w c:\windows\system32\dllcache\win32k.sys
+ 2004-08-10 19:00:00 256,192 -c--a-w c:\windows\system32\dllcache\winhelp.exe
- 2008-04-23 04:16:29 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
+ 2004-08-10 19:00:00 13,312 -c--a-w c:\windows\system32\dllcache\winmgmt.exe
+ 2004-08-10 19:00:00 16,384 -c--a-w c:\windows\system32\dllcache\winmgmtr.dll
+ 2008-04-14 00:12:45 146,432 -c--a-w c:\windows\system32\dllcache\winspool.drv
+ 2004-08-10 19:00:00 25,088 -c--a-w c:\windows\system32\dllcache\wisc10.dll
+ 2008-04-14 00:12:09 60,928 -c--a-w c:\windows\system32\dllcache\wmicookr.dll
+ 2008-04-14 00:12:09 140,800 -c--a-w c:\windows\system32\dllcache\wmidcprv.dll
+ 2004-08-10 19:00:00 61,440 -c--a-w c:\windows\system32\dllcache\wmimsg.dll
+ 2008-04-14 00:12:09 132,096 -c--a-w c:\windows\system32\dllcache\wmipdskq.dll
+ 2004-08-10 19:00:00 75,264 -c--a-w c:\windows\system32\dllcache\wmipicmp.dll
+ 2008-04-14 00:12:09 61,952 -c--a-w c:\windows\system32\dllcache\wmipiprt.dll
+ 2008-04-14 00:12:09 62,464 -c--a-w c:\windows\system32\dllcache\wmipjobj.dll
+ 2008-04-14 00:12:09 41,472 -c--a-w c:\windows\system32\dllcache\wmipsess.dll
+ 2004-08-10 19:00:00 52,224 -c--a-w c:\windows\system32\dllcache\wmitimep.dll
+ 2008-06-18 10:03:08 938,496 -c----w c:\windows\system32\dllcache\WMNetmgr.dll
+ 2007-06-12 03:51:12 10,834,944 -c--a-w c:\windows\system32\dllcache\wmp.dll
- 2006-10-19 01:47:22 2,450,944 -c----w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
+ 2008-05-08 11:24:44 155,648 -c----w c:\windows\system32\dllcache\wscript.exe
+ 2008-05-09 10:53:40 90,112 -c----w c:\windows\system32\dllcache\wshext.dll
+ 2008-04-13 18:46:24 19,200 -c--a-w c:\windows\system32\dllcache\wstcodec.sys
- 2007-07-31 00:19:36 549,720 -c--a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 19:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-31 00:19:16 53,080 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-31 00:19:32 325,976 -c--a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 19:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-31 00:18:40 33,624 -c--a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 19:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-31 00:19:28 203,096 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 19:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
+ 2007-03-23 10:07:54 583,504 -c----w c:\windows\system32\dllcache\XPSSHHDR.dll
+ 2007-03-23 10:07:56 1,683,280 -c----w c:\windows\system32\dllcache\XpsSvcs.dll
+ 2004-08-10 19:00:00 36,937 -c--a-w c:\windows\system32\dllcache\zclientm.exe
+ 2004-08-10 19:00:00 41,029 -c--a-w c:\windows\system32\dllcache\zcorem.dll
+ 2004-08-10 19:00:00 4,677 -c--a-w c:\windows\system32\dllcache\zeeverm.dll
+ 2004-08-10 19:00:00 29,760 -c--a-w c:\windows\system32\dllcache\znetm.dll
+ 2004-08-10 19:00:00 113,222 -c--a-w c:\windows\system32\dllcache\zoneclim.dll
+ 2004-08-10 19:00:00 13,894 -c--a-w c:\windows\system32\dllcache\zonelibm.dll
- 2004-08-10 19:00:00 5,120 ----a-w c:\windows\system32\dllhost.exe
+ 2008-04-14 00:12:17 5,120 ----a-w c:\windows\system32\dllhost.exe
- 2004-08-10 19:00:00 224,768 ----a-w c:\windows\system32\dmadmin.exe
+ 2008-04-14 00:12:17 224,768 ----a-w c:\windows\system32\dmadmin.exe
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\dmband.dll
+ 2008-04-14 00:11:52 28,672 ----a-w c:\windows\system32\dmband.dll
- 2004-08-10 19:00:00 61,440 ----a-w c:\windows\system32\dmcompos.dll
+ 2008-04-14 00:11:52 61,440 ----a-w c:\windows\system32\dmcompos.dll
- 2004-08-10 19:00:00 273,920 ----a-w c:\windows\system32\dmdlgs.dll
+ 2008-04-14 00:11:52 285,184 ----a-w c:\windows\system32\dmdlgs.dll
- 2004-08-10 19:00:00 200,704 ----a-w c:\windows\system32\dmdskmgr.dll
+ 2008-04-14 00:11:52 200,704 ----a-w c:\windows\system32\dmdskmgr.dll
- 2004-08-10 19:00:00 181,248 ----a-w c:\windows\system32\dmime.dll
+ 2008-04-14 00:11:52 181,248 ----a-w c:\windows\system32\dmime.dll
- 2004-08-10 19:00:00 35,840 ----a-w c:\windows\system32\dmloader.dll
+ 2008-04-14 00:11:52 35,840 ----a-w c:\windows\system32\dmloader.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\dmremote.exe
+ 2008-04-14 00:12:17 15,872 ----a-w c:\windows\system32\dmremote.exe
- 2004-08-10 19:00:00 82,432 ----a-w c:\windows\system32\dmscript.dll
+ 2008-04-14 00:11:52 82,432 ----a-w c:\windows\system32\dmscript.dll
- 2004-08-10 19:00:00 23,552 ----a-w c:\windows\system32\dmserver.dll
+ 2008-04-14 00:11:52 23,552 ----a-w c:\windows\system32\dmserver.dll
- 2004-08-10 19:00:00 105,984 ----a-w c:\windows\system32\dmstyle.dll
+ 2008-04-14 00:11:52 105,984 ----a-w c:\windows\system32\dmstyle.dll
- 2004-08-10 19:00:00 103,424 ----a-w c:\windows\system32\dmsynth.dll
+ 2008-04-14 00:11:52 103,424 ----a-w c:\windows\system32\dmsynth.dll
- 2004-08-10 19:00:00 104,448 ----a-w c:\windows\system32\dmusic.dll
+ 2008-04-14 00:11:52 104,448 ----a-w c:\windows\system32\dmusic.dll
- 2004-08-04 00:56:44 52,224 ----a-w c:\windows\system32\dmutil.dll
+ 2008-04-14 00:11:52 52,224 ----a-w c:\windows\system32\dmutil.dll
- 2007-07-24 19:17:08 81,920 ----a-w c:\windows\system32\dns-sd.exe
+ 2008-08-29 15:18:58 87,336 ----a-w c:\windows\system32\dns-sd.exe
- 2008-06-20 17:41:10 148,992 ----a-w c:\windows\system32\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 ----a-w c:\windows\system32\dnsapi.dll
- 2008-02-20 05:32:43 45,568 ----a-w c:\windows\system32\dnsrslvr.dll
+ 2008-04-14 00:11:52 45,568 ----a-w c:\windows\system32\dnsrslvr.dll
- 2007-07-24 19:17:08 61,440 ----a-w c:\windows\system32\dnssd.dll
+ 2008-08-29 14:53:50 61,440 ----a-w c:\windows\system32\dnssd.dll
- 2004-08-10 19:00:00 48,128 ----a-w c:\windows\system32\docprop2.dll
+ 2008-04-14 00:11:52 48,128 ----a-w c:\windows\system32\docprop2.dll
+ 2008-04-14 00:11:52 26,112 ------w c:\windows\system32\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ------w c:\windows\system32\dot3cfg.dll
+ 2008-04-14 00:11:52 9,216 ------w c:\windows\system32\dot3dlg.dll
+ 2008-04-14 00:11:52 39,936 ------w c:\windows\system32\dot3gpclnt.dll
+ 2008-04-14 00:11:52 56,320 ------w c:\windows\system32\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ------w c:\windows\system32\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ------w c:\windows\system32\dot3ui.dll
- 2004-08-10 19:00:00 96,768 ----a-w c:\windows\system32\dpcdll.dll
+ 2008-04-14 00:11:52 102,912 ----a-w c:\windows\system32\dpcdll.dll
- 2008-03-21 20:28:54 81,920 ----a-w c:\windows\system32\dpl100.dll
+ 2007-01-03 21:52:55 73,728 ----a-w c:\windows\system32\dpl100.dll
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\dplaysvr.exe
+ 2008-04-14 00:12:17 29,696 ----a-w c:\windows\system32\dplaysvr.exe
- 2004-08-10 19:00:00 229,888 ----a-w c:\windows\system32\dplayx.dll
+ 2008-04-14 00:11:52 229,888 ----a-w c:\windows\system32\dplayx.dll
- 2004-08-10 19:00:00 23,552 ----a-w c:\windows\system32\dpmodemx.dll
+ 2008-04-14 00:11:52 23,552 ----a-w c:\windows\system32\dpmodemx.dll
- 2004-08-10 19:00:00 3,584 ----a-w c:\windows\system32\dpnaddr.dll
+ 2008-04-14 00:09:19 3,072 ----a-w c:\windows\system32\dpnaddr.dll
- 2004-08-10 19:00:00 375,296 ----a-w c:\windows\system32\dpnet.dll
+ 2008-04-14 00:11:52 375,296 ----a-w c:\windows\system32\dpnet.dll
- 2004-08-10 19:00:00 35,328 ----a-w c:\windows\system32\dpnhpast.dll
+ 2008-04-14 00:11:52 35,328 ----a-w c:\windows\system32\dpnhpast.dll
- 2004-08-10 19:00:00 60,928 ----a-w c:\windows\system32\dpnhupnp.dll
+ 2008-04-14 00:11:52 60,928 ----a-w c:\windows\system32\dpnhupnp.dll
- 2004-08-10 19:00:00 3,584 ----a-w c:\windows\system32\dpnlobby.dll
+ 2008-04-14 00:09:20 3,072 ----a-w c:\windows\system32\dpnlobby.dll
- 2004-08-10 19:00:00 18,432 ----a-w c:\windows\system32\dpnsvr.exe
+ 2008-04-14 00:12:17 17,920 ----a-w c:\windows\system32\dpnsvr.exe
- 2008-03-21 20:28:50 294,912 ----a-w c:\windows\system32\dpu10.dll
+ 2007-01-03 21:51:28 294,912 ----a-w c:\windows\system32\dpu10.dll
- 2008-03-21 20:28:50 294,912 ----a-w c:\windows\system32\dpu11.dll
+ 2007-01-03 21:51:28 294,912 ----a-w c:\windows\system32\dpu11.dll
- 2008-03-21 20:28:52 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
+ 2007-01-03 21:51:29 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
- 2008-03-21 20:28:50 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
+ 2007-01-03 21:51:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
- 2008-03-21 20:28:50 344,064 ----a-w c:\windows\system32\dpus11.dll
+ 2007-01-03 21:51:28 344,064 ----a-w c:\windows\system32\dpus11.dll
- 2008-03-21 20:28:50 57,344 ----a-w c:\windows\system32\dpv11.dll
+ 2007-01-03 21:51:28 57,344 ----a-w c:\windows\system32\dpv11.dll
- 2004-08-10 19:00:00 21,504 ----a-w c:\windows\system32\dpvacm.dll
+ 2008-04-14 00:11:52 21,504 ----a-w c:\windows\system32\dpvacm.dll
- 2004-08-10 19:00:00 212,480 ----a-w c:\windows\system32\dpvoice.dll
+ 2008-04-14 00:11:52 212,480 ----a-w c:\windows\system32\dpvoice.dll
- 2004-08-10 19:00:00 83,456 ----a-w c:\windows\system32\dpvsetup.exe
+ 2008-04-14 00:12:18 83,456 ----a-w c:\windows\system32\dpvsetup.exe
- 2004-08-10 19:00:00 116,736 ----a-w c:\windows\system32\dpvvox.dll
+ 2008-04-14 00:11:52 116,736 ----a-w c:\windows\system32\dpvvox.dll
- 2004-08-10 19:00:00 57,344 ----a-w c:\windows\system32\dpwsockx.dll
+ 2008-04-14 00:11:52 57,344 ----a-w c:\windows\system32\dpwsockx.dll
- 2004-08-10 19:00:00 58,368 ----a-w c:\windows\system32\driverquery.exe
+ 2008-04-14 00:12:18 62,976 ----a-w c:\windows\system32\driverquery.exe
- 2004-08-04 07:10:08 53,248 ----a-w c:\windows\system32\drivers\1394bus.sys
+ 2008-04-13 18:46:18 53,376 ----a-w c:\windows\system32\drivers\1394bus.sys
- 2004-08-10 19:00:00 187,776 ----a-w c:\windows\system32\drivers\acpi.sys
+ 2008-04-13 18:36:35 187,776 ----a-w c:\windows\system32\drivers\acpi.sys
+ 2008-04-14 00:11:48 4,255 ------w c:\windows\system32\drivers\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ------w c:\windows\system32\drivers\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ------w c:\windows\system32\drivers\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ------w c:\windows\system32\drivers\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ------w c:\windows\system32\drivers\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ------w c:\windows\system32\drivers\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ------w c:\windows\system32\drivers\adv11nt5.dll
- 2006-02-15 00:22:26 142,464 ----a-w c:\windows\system32\drivers\aec.sys
+ 2008-04-13 16:39:23 142,592 ----a-w c:\windows\system32\drivers\aec.sys
- 2008-06-20 10:44:38 138,368 ----a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 10:04:36 138,496 ----a-w c:\windows\system32\drivers\afd.sys
- 2004-08-03 23:07:42 42,368 ----a-w c:\windows\system32\drivers\AGP440.SYS
+ 2008-04-13 18:36:38 42,368 ----a-w c:\windows\system32\drivers\agp440.sys
- 2004-08-03 23:07:44 44,928 ----a-w c:\windows\system32\drivers\AGPCPQ.SYS
+ 2008-04-13 18:36:39 44,928 ----a-w c:\windows\system32\drivers\agpcpq.sys
- 2004-08-03 23:07:42 42,752 ----a-w c:\windows\system32\drivers\ALIM1541.SYS
+ 2008-04-13 18:36:38 42,752 ----a-w c:\windows\system32\drivers\alim1541.sys
- 2004-08-03 23:07:44 43,008 ----a-w c:\windows\system32\drivers\AMDAGP.SYS
+ 2008-04-13 18:36:39 43,008 ----a-w c:\windows\system32\drivers\amdagp.sys
- 2004-08-03 22:59:20 36,992 ----a-w c:\windows\system32\drivers\amdk6.sys
+ 2008-04-13 18:31:32 37,376 ----a-w c:\windows\system32\drivers\amdk6.sys
- 2004-08-03 22:59:22 37,376 ----a-w c:\windows\system32\drivers\amdk7.sys
+ 2008-04-13 18:31:33 37,760 ----a-w c:\windows\system32\drivers\amdk7.sys
- 2004-08-03 22:58:30 60,800 ----a-w c:\windows\system32\drivers\arp1394.sys
+ 2008-04-13 18:51:25 60,800 ----a-w c:\windows\system32\drivers\arp1394.sys
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\drivers\asyncmac.sys
+ 2008-04-13 18:57:27 14,336 ----a-w c:\windows\system32\drivers\asyncmac.sys
- 2004-08-10 19:00:00 95,360 ----a-w c:\windows\system32\drivers\atapi.sys
+ 2008-04-13 18:40:30 96,512 ----a-w c:\windows\system32\drivers\atapi.sys
+ 2004-08-04 02:29:30 56,623 ------w c:\windows\system32\drivers\ati1btxx.sys
+ 2004-08-04 02:29:30 11,615 ------w c:\windows\system32\drivers\ati1mdxx.sys
+ 2004-08-04 02:29:30 12,047 ------w c:\windows\system32\drivers\ati1pdxx.sys
+ 2004-08-04 02:29:32 30,671 ------w c:\windows\system32\drivers\ati1raxx.sys
+ 2004-08-04 02:29:32 63,663 ------w c:\windows\system32\drivers\ati1rvxx.sys
+ 2004-08-04 02:29:32 26,367 ------w c:\windows\system32\drivers\ati1snxx.sys
+ 2004-08-04 02:29:32 21,343 ------w c:\windows\system32\drivers\ati1ttxx.sys
+ 2004-08-04 02:29:32 36,463 ------w c:\windows\system32\drivers\ati1tuxx.sys
+ 2004-08-04 02:29:32 29,455 ------w c:\windows\system32\drivers\ati1xbxx.sys
+ 2004-08-04 02:29:32 34,735 ------w c:\windows\system32\drivers\ati1xsxx.sys
+ 2004-08-04 02:29:28 327,040 ------w c:\windows\system32\drivers\ati2mtaa.sys
+ 2004-08-04 02:29:28 701,440 ------w c:\windows\system32\drivers\ati2mtag.sys
+ 2004-08-04 02:29:28 57,856 ------w c:\windows\system32\drivers\atinbtxx.sys
+ 2004-08-04 02:29:30 13,824 ------w c:\windows\system32\drivers\atinmdxx.sys
+ 2004-08-04 02:29:30 14,336 ------w c:\windows\system32\drivers\atinpdxx.sys
+ 2004-08-04 02:29:30 52,224 ------w c:\windows\system32\drivers\atinraxx.sys
+ 2004-08-04 02:29:32 104,960 ------w c:\windows\system32\drivers\atinrvxx.sys
+ 2004-08-04 02:29:32 28,672 ------w c:\windows\system32\drivers\atinsnxx.sys
+ 2004-08-04 02:29:32 13,824 ------w c:\windows\system32\drivers\atinttxx.sys
+ 2004-08-04 02:29:32 73,216 ------w c:\windows\system32\drivers\atintuxx.sys
+ 2004-08-04 02:29:32 31,744 ------w c:\windows\system32\drivers\atinxbxx.sys
+ 2004-08-04 02:29:32 63,488 ------w c:\windows\system32\drivers\atinxsxx.sys
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\drivers\atmarpc.sys
+ 2008-04-13 18:51:25 59,904 ----a-w c:\windows\system32\drivers\atmarpc.sys
- 2004-08-10 19:00:00 55,936 ----a-w c:\windows\system32\drivers\atmlane.sys
+ 2008-04-13 18:51:30 55,808 ----a-w c:\windows\system32\drivers\atmlane.sys
+ 2008-04-14 00:11:50 21,183 ------w c:\windows\system32\drivers\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ------w c:\windows\system32\drivers\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ------w c:\windows\system32\drivers\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ------w c:\windows\system32\drivers\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ------w c:\windows\system32\drivers\atv10nt5.dll
- 2004-08-10 19:00:00 71,552 ----a-w c:\windows\system32\drivers\bridge.sys
+ 2008-04-13 18:53:23 71,552 ----a-w c:\windows\system32\drivers\bridge.sys
+ 2008-04-13 18:46:33 17,024 ------w c:\windows\system32\drivers\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ------w c:\windows\system32\drivers\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ------w c:\windows\system32\drivers\bthpan.sys
- 2008-06-13 13:10:50 272,128 ------w c:\windows\system32\drivers\bthport.sys
+ 2008-06-13 11:05:51 272,128 ------w c:\windows\system32\drivers\bthport.sys
+ 2008-04-13 18:46:31 36,480 ------w c:\windows\system32\drivers\bthprint.sys
+ 2008-04-13 18:46:29 18,944 ------w c:\windows\system32\drivers\bthusb.sys
+ 2008-04-13 18:46:24 17,024 ----a-w c:\windows\system32\drivers\CCDECODE.sys
- 2004-08-10 19:00:00 63,744 ----a-w c:\windows\system32\drivers\cdfs.sys
+ 2008-04-13 19:14:21 63,744 ----a-w c:\windows\system32\drivers\cdfs.sys
- 2004-08-10 19:00:00 49,536 ----a-w c:\windows\system32\drivers\cdrom.sys
+ 2008-04-13 18:40:46 62,976 ----a-w c:\windows\system32\drivers\cdrom.sys
+ 2008-04-14 00:11:50 15,423 ------w c:\windows\system32\drivers\ch7xxnt5.dll
- 2004-08-10 19:00:00 49,664 ----a-w c:\windows\system32\drivers\classpnp.sys
+ 2008-04-13 19:16:22 49,536 ----a-w c:\windows\system32\drivers\classpnp.sys
- 2004-08-03 22:59:22 36,480 ----a-w c:\windows\system32\drivers\crusoe.sys
+ 2008-04-13 18:31:32 36,736 ----a-w c:\windows\system32\drivers\crusoe.sys
- 2004-08-10 19:00:00 36,352 ----a-w c:\windows\system32\drivers\disk.sys
+ 2008-04-13 18:40:47 36,352 ----a-w c:\windows\system32\drivers\disk.sys
- 2004-08-10 19:00:00 14,208 ----a-w c:\windows\system32\drivers\diskdump.sys
+ 2008-04-13 18:40:44 14,208 ----a-w c:\windows\system32\drivers\diskdump.sys
- 2004-08-10 19:00:00 799,744 ----a-w c:\windows\system32\drivers\dmboot.sys
+ 2008-04-13 18:44:48 799,744 ----a-w c:\windows\system32\drivers\dmboot.sys
- 2004-08-10 19:00:00 153,344 ----a-w c:\windows\system32\drivers\dmio.sys
+ 2008-04-13 18:44:46 153,344 ----a-w c:\windows\system32\drivers\dmio.sys
- 2004-08-04 03:07:40 52,864 ----a-w c:\windows\system32\drivers\DMusic.sys
+ 2008-04-13 18:45:01 52,864 ----a-w c:\windows\system32\drivers\dmusic.sys
- 2004-08-04 03:08:00 60,288 ----a-w c:\windows\system32\drivers\drmk.sys
+ 2008-04-13 18:45:14 60,160 ----a-w c:\windows\system32\drivers\drmk.sys
- 2004-08-04 03:07:58 2,944 ----a-w c:\windows\system32\drivers\drmkaud.sys
+ 2008-04-13 18:45:13 2,944 ----a-w c:\windows\system32\drivers\drmkaud.sys
- 2004-08-10 19:00:00 71,040 ----a-w c:\windows\system32\drivers\dxg.sys
+ 2008-04-13 18:38:29 71,168 ----a-w c:\windows\system32\drivers\dxg.sys
- 2004-08-10 19:00:00 143,360 ----a-w c:\windows\system32\drivers\fastfat.sys
+ 2008-04-13 19:14:29 143,744 ----a-w c:\windows\system32\drivers\fastfat.sys
- 2004-08-10 19:00:00 27,392 ----a-w c:\windows\system32\drivers\fdc.sys
+ 2008-04-13 18:40:25 27,392 ----a-w c:\windows\system32\drivers\fdc.sys
- 2004-08-10 19:00:00 34,944 ----a-w c:\windows\system32\drivers\fips.sys
+ 2008-04-13 18:33:28 44,544 ----a-w c:\windows\system32\drivers\fips.sys
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\drivers\flpydisk.sys
+ 2008-04-13 18:40:25 20,480 ----a-w c:\windows\system32\drivers\flpydisk.sys
- 2006-08-21 09:14:58 128,896 ----a-w c:\windows\system32\drivers\fltmgr.sys
+ 2008-04-13 18:32:59 129,792 ----a-w c:\windows\system32\drivers\fltmgr.sys
+ 2008-04-13 18:36:40 46,464 ------w c:\windows\system32\drivers\gagp30kx.sys
- 2008-01-29 16:01:28 16,168 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 18:12:54 15,464 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-12-29 14:57:49 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
- 2005-01-07 21:07:18 138,752 ------w c:\windows\system32\drivers\Hdaudbus.sys
+ 2008-04-13 16:36:05 144,384 ------w c:\windows\system32\drivers\hdaudbus.sys
+ 2008-04-13 18:46:30 25,600 ------w c:\windows\system32\drivers\hidbth.sys
- 2004-08-10 19:00:00 36,224 ----a-w c:\windows\system32\drivers\hidclass.sys
+ 2008-04-13 18:45:26 36,864 ----a-w c:\windows\system32\drivers\hidclass.sys
- 2005-06-29 06:43:35 19,200 ------w c:\windows\system32\drivers\hidir.sys
+ 2008-04-13 18:45:26 19,200 ------w c:\windows\system32\drivers\hidir.sys
- 2004-08-10 19:00:00 24,960 ----a-w c:\windows\system32\drivers\hidparse.sys
+ 2008-04-13 18:45:22 24,960 ----a-w c:\windows\system32\drivers\hidparse.sys
- 2001-08-17 22:02:20 9,600 ----a-w c:\windows\system32\drivers\hidusb.sys
+ 2008-04-13 18:45:27 10,368 ----a-w c:\windows\system32\drivers\hidusb.sys
+ 2004-08-04 02:41:48 220,032 ------w c:\windows\system32\drivers\hsfbs2s2.sys
+ 2004-08-04 02:41:50 685,056 ------w c:\windows\system32\drivers\hsfcxts2.sys
+ 2004-08-04 02:41:56 1,041,536 ------w c:\windows\system32\drivers\hsfdpsp2.sys
- 2006-03-17 00:33:10 262,784 ----a-w c:\windows\system32\drivers\http.sys
+ 2008-04-13 18:53:53 264,832 ----a-w c:\windows\system32\drivers\http.sys
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\drivers\i2omgmt.sys
+ 2008-04-13 18:41:22 8,576 ----a-w c:\windows\system32\drivers\i2omgmt.sys
- 2004-08-10 19:00:00 18,560 ----a-w c:\windows\system32\drivers\i2omp.sys
+ 2008-04-13 18:41:22 18,560 ----a-w c:\windows\system32\drivers\i2omp.sys
- 2004-08-10 19:00:00 52,736 ----a-w c:\windows\system32\drivers\i8042prt.sys
+ 2008-04-13 19:18:00 52,480 ----a-w c:\windows\system32\drivers\i8042prt.sys
- 2004-08-10 19:00:00 41,856 ----a-w c:\windows\system32\drivers\imapi.sys
+ 2008-04-13 18:40:58 42,112 ----a-w c:\windows\system32\drivers\imapi.sys
- 2004-08-10 19:00:00 5,504 ----a-w c:\windows\system32\drivers\intelide.sys
+ 2008-04-13 18:40:29 5,504 ----a-w c:\windows\system32\drivers\intelide.sys
- 2004-08-10 19:00:00 36,096 ----a-w c:\windows\system32\drivers\intelppm.sys
+ 2008-04-13 18:31:32 36,352 ----a-w c:\windows\system32\drivers\intelppm.sys
- 2004-08-10 19:00:00 29,056 ----a-w c:\windows\system32\drivers\ip6fw.sys
+ 2008-04-13 18:53:34 36,608 ----a-w c:\windows\system32\drivers\ip6fw.sys
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\drivers\ipinip.sys
+ 2008-04-13 18:57:07 20,864 ----a-w c:\windows\system32\drivers\ipinip.sys
- 2004-09-29 22:28:37 134,912 ----a-w c:\windows\system32\drivers\ipnat.sys
+ 2008-04-13 18:57:15 152,832 ----a-w c:\windows\system32\drivers\ipnat.sys
- 2004-08-10 19:00:00 74,752 ----a-w c:\windows\system32\drivers\ipsec.sys
+ 2008-04-13 19:19:42 75,264 ----a-w c:\windows\system32\drivers\ipsec.sys
- 2005-06-29 06:43:39 46,592 ------w c:\windows\system32\drivers\irbus.sys
+ 2008-04-13 18:45:34 46,592 ------w c:\windows\system32\drivers\irbus.sys
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\drivers\irenum.sys
+ 2008-04-13 18:54:28 11,264 ----a-w c:\windows\system32\drivers\irenum.sys
- 2004-08-10 19:00:00 35,840 ----a-w c:\windows\system32\drivers\isapnp.sys
+ 2008-04-13 18:36:41 37,248 ----a-w c:\windows\system32\drivers\isapnp.sys
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\drivers\kbdclass.sys
+ 2008-04-13 18:39:47 24,576 ----a-w c:\windows\system32\drivers\kbdclass.sys
- 2006-06-14 08:47:45 172,416 ----a-w c:\windows\system32\drivers\kmixer.sys
+ 2008-04-13 18:45:09 172,416 ----a-w c:\windows\system32\drivers\kmixer.sys
- 2004-08-04 03:15:22 140,928 ----a-w c:\windows\system32\drivers\ks.sys
+ 2008-04-13 19:16:36 141,056 ----a-w c:\windows\system32\drivers\ks.sys
- 2004-08-10 19:00:00 92,032 ----a-w c:\windows\system32\drivers\ksecdd.sys
+ 2008-04-13 18:31:43 92,288 ----a-w c:\windows\system32\drivers\ksecdd.sys
+ 2008-02-28 19:31:08 10,144 ----a-w c:\windows\system32\drivers\lmimirr.sys
+ 2008-03-07 17:39:50 45,848 ----a-w c:\windows\system32\drivers\LMIRfsDriver.sys
+ 2004-08-04 02:41:56 11,868 ------w c:\windows\system32\drivers\mdmxsdk.sys
- 2004-08-03 23:07:46 63,744 ----a-w c:\windows\system32\drivers\mf.sys
+ 2008-04-13 18:36:41 63,744 ----a-w c:\windows\system32\drivers\mf.sys
- 2004-08-03 23:08:06 30,080 ----a-w c:\windows\system32\drivers\modem.sys
+ 2008-04-13 19:00:19 30,080 ----a-w c:\windows\system32\drivers\modem.sys
- 2004-08-03 22:58:34 23,040 ----a-w c:\windows\system32\drivers\mouclass.sys
+ 2008-04-13 18:39:47 23,040 ----a-w c:\windows\system32\drivers\mouclass.sys
- 2004-08-10 19:00:00 42,240 ----a-w c:\windows\system32\drivers\mountmgr.sys
+ 2008-04-13 18:39:46 42,368 ----a-w c:\windows\system32\drivers\mountmgr.sys
- 2007-07-06 10:05:47 72,960 ----a-w c:\windows\system32\drivers\mqac.sys
+ 2008-04-13 18:39:44 92,544 ----a-w c:\windows\system32\drivers\mqac.sys
- 2007-12-18 09:51:35 179,584 ----a-w c:\windows\system32\drivers\mrxdav.sys
+ 2008-04-13 18:32:44 180,608 ----a-w c:\windows\system32\drivers\mrxdav.sys
- 2006-05-05 09:41:45 453,120 ----a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
- 2004-08-10 19:00:00 19,072 ----a-w c:\windows\system32\drivers\msfs.sys
+ 2008-04-13 18:32:39 19,072 ----a-w c:\windows\system32\drivers\msfs.sys
- 2004-08-10 19:00:00 35,072 ----a-w c:\windows\system32\drivers\msgpc.sys
+ 2008-04-13 18:56:32 35,072 ----a-w c:\windows\system32\drivers\msgpc.sys
- 2004-08-04 02:58:42 7,552 ----a-w c:\windows\system32\drivers\MSKSSRV.sys
+ 2008-04-13 18:39:52 7,552 ----a-w c:\windows\system32\drivers\mskssrv.sys
- 2004-08-04 02:58:40 5,376 ----a-w c:\windows\system32\drivers\MSPCLOCK.sys
+ 2008-04-13 18:39:50 5,376 ----a-w c:\windows\system32\drivers\mspclock.sys
- 2004-08-04 02:58:42 4,992 ----a-w c:\windows\system32\drivers\MSPQM.sys
+ 2008-04-13 18:39:51 4,992 ----a-w c:\windows\system32\drivers\mspqm.sys
- 2004-08-03 23:07:48 15,488 ----a-w c:\windows\system32\drivers\mssmbios.sys
+ 2008-04-13 18:36:46 15,488 ----a-w c:\windows\system32\drivers\mssmbios.sys
+ 2008-04-13 18:39:50 5,504 ----a-w c:\windows\system32\drivers\MSTEE.sys
+ 2004-08-04 02:41:40 126,686 ------w c:\windows\system32\drivers\mtlmnt5.sys
+ 2004-08-04 02:41:38 1,309,184 ------w c:\windows\system32\drivers\mtlstrm.sys

EasyEEE
2008-12-29, 18:14
+ 2004-08-04 02:29:38 452,736 ------w c:\windows\system32\drivers\mtxparhm.sys
- 2004-08-10 19:00:00 107,904 ----a-w c:\windows\system32\drivers\mup.sys
+ 2008-04-13 19:17:05 105,344 ----a-w c:\windows\system32\drivers\mup.sys
+ 2008-04-13 18:43:55 12,672 ------w c:\windows\system32\drivers\mutohpen.sys
+ 2008-04-13 18:46:26 85,248 ----a-w c:\windows\system32\drivers\NABTSFEC.sys
- 2004-08-10 19:00:00 182,912 ----a-w c:\windows\system32\drivers\ndis.sys
+ 2008-04-13 19:20:37 182,656 ----a-w c:\windows\system32\drivers\ndis.sys
+ 2008-04-13 18:46:22 10,880 ----a-w c:\windows\system32\drivers\NdisIP.sys
- 2004-08-10 19:00:00 9,600 ----a-w c:\windows\system32\drivers\ndistapi.sys
+ 2008-04-13 18:57:27 10,112 ----a-w c:\windows\system32\drivers\ndistapi.sys
- 2005-06-21 08:52:55 14,592 ----a-w c:\windows\system32\drivers\ndisuio.sys
+ 2008-04-13 18:55:58 14,592 ----a-w c:\windows\system32\drivers\ndisuio.sys
- 2004-08-10 19:00:00 91,776 ----a-w c:\windows\system32\drivers\ndiswan.sys
+ 2008-04-13 19:20:42 91,520 ----a-w c:\windows\system32\drivers\ndiswan.sys
- 2004-08-10 19:00:00 38,016 ----a-w c:\windows\system32\drivers\ndproxy.sys
+ 2008-04-13 18:57:29 40,576 ----a-w c:\windows\system32\drivers\ndproxy.sys
- 2004-08-10 19:00:00 34,560 ----a-w c:\windows\system32\drivers\netbios.sys
+ 2008-04-13 18:56:02 34,688 ----a-w c:\windows\system32\drivers\netbios.sys
- 2004-08-10 19:00:00 162,816 ----a-w c:\windows\system32\drivers\netbt.sys
+ 2008-04-13 19:21:00 162,816 ----a-w c:\windows\system32\drivers\netbt.sys
- 2004-08-03 22:58:30 61,824 ----a-w c:\windows\system32\drivers\nic1394.sys
+ 2008-04-13 18:51:25 61,824 ----a-w c:\windows\system32\drivers\nic1394.sys
- 2004-08-10 19:00:00 40,320 ----a-w c:\windows\system32\drivers\nmnt.sys
+ 2008-04-13 18:53:09 40,320 ----a-w c:\windows\system32\drivers\nmnt.sys
- 2004-08-10 19:00:00 30,848 ----a-w c:\windows\system32\drivers\npfs.sys
+ 2008-04-13 18:32:39 30,848 ----a-w c:\windows\system32\drivers\npfs.sys
- 2007-02-09 11:10:35 574,464 ----a-w c:\windows\system32\drivers\ntfs.sys
+ 2008-04-13 19:15:53 574,976 ----a-w c:\windows\system32\drivers\ntfs.sys
+ 2004-08-04 02:41:40 180,360 ------w c:\windows\system32\drivers\ntmtlfax.sys
- 2004-08-10 19:00:00 88,448 ----a-w c:\windows\system32\drivers\nwlnkipx.sys
+ 2008-04-13 18:56:06 88,320 ----a-w c:\windows\system32\drivers\nwlnkipx.sys
- 2006-10-13 10:23:15 163,584 ----a-w c:\windows\system32\drivers\nwrdr.sys
+ 2008-04-13 18:34:12 163,584 ----a-w c:\windows\system32\drivers\nwrdr.sys
+ 2008-08-04 20:22:18 33,808 ----a-w c:\windows\system32\drivers\nx6000.sys
- 2004-08-04 07:10:10 61,056 ----a-w c:\windows\system32\drivers\ohci1394.sys
+ 2008-04-13 18:46:18 61,696 ----a-w c:\windows\system32\drivers\ohci1394.sys
- 2004-08-03 22:59:20 42,496 ----a-w c:\windows\system32\drivers\p3.sys
+ 2008-04-13 18:31:31 42,752 ----a-w c:\windows\system32\drivers\p3.sys
- 2004-08-03 22:59:08 80,128 ----a-w c:\windows\system32\drivers\parport.sys
+ 2008-04-13 18:40:10 80,128 ----a-w c:\windows\system32\drivers\parport.sys
- 2004-08-10 19:00:00 18,688 ----a-w c:\windows\system32\drivers\partmgr.sys
+ 2008-04-13 18:40:49 19,712 ----a-w c:\windows\system32\drivers\partmgr.sys
- 2004-08-10 19:00:00 68,224 ----a-w c:\windows\system32\drivers\pci.sys
+ 2008-04-13 18:36:44 68,224 ----a-w c:\windows\system32\drivers\pci.sys
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\drivers\pciidex.sys
+ 2008-04-13 18:40:29 24,960 ----a-w c:\windows\system32\drivers\pciidex.sys
- 2004-08-10 19:00:00 119,936 ----a-w c:\windows\system32\drivers\pcmcia.sys
+ 2008-04-13 18:36:43 120,192 ----a-w c:\windows\system32\drivers\pcmcia.sys
- 2004-03-16 14:58:20 136,960 ----a-w c:\windows\system32\drivers\portcls.sys
+ 2008-04-13 19:19:41 146,048 ----a-w c:\windows\system32\drivers\portcls.sys
- 2004-08-03 22:59:18 35,328 ----a-w c:\windows\system32\drivers\processr.sys
+ 2008-04-13 18:31:30 35,840 ----a-w c:\windows\system32\drivers\processr.sys
- 2004-08-10 19:00:00 69,120 ----a-w c:\windows\system32\drivers\psched.sys
+ 2008-04-13 18:56:38 69,120 ----a-w c:\windows\system32\drivers\psched.sys
- 2004-08-10 19:00:00 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys
+ 2008-04-13 19:19:43 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys
- 2004-08-10 19:00:00 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys
+ 2008-04-13 18:57:32 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys
- 2004-08-10 19:00:00 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys
+ 2008-04-13 19:19:48 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys
- 2006-05-05 09:47:57 174,592 ----a-w c:\windows\system32\drivers\rdbss.sys
+ 2008-04-13 19:28:39 175,744 ----a-w c:\windows\system32\drivers\rdbss.sys
- 2004-08-03 23:01:16 196,864 ----a-w c:\windows\system32\drivers\rdpdr.sys
+ 2008-04-13 18:32:51 196,224 ----a-w c:\windows\system32\drivers\rdpdr.sys
- 2005-06-10 04:09:46 139,528 ----a-w c:\windows\system32\drivers\rdpwd.sys
+ 2008-04-14 00:13:22 139,656 ----a-w c:\windows\system32\drivers\rdpwd.sys
+ 2004-08-04 02:41:40 13,776 ------w c:\windows\system32\drivers\recagent.sys
- 2004-08-03 22:59:38 57,472 ----a-w c:\windows\system32\drivers\redbook.sys
+ 2008-04-13 18:40:27 57,600 ----a-w c:\windows\system32\drivers\redbook.sys
+ 2008-04-13 18:46:32 59,136 ------w c:\windows\system32\drivers\rfcomm.sys
- 2008-05-08 12:28:49 202,752 ----a-w c:\windows\system32\drivers\rmcast.sys
+ 2008-05-08 14:02:52 203,136 ----a-w c:\windows\system32\drivers\rmcast.sys
- 2004-08-10 19:00:00 30,080 ----a-w c:\windows\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ----a-w c:\windows\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ------w c:\windows\system32\drivers\rndismpx.sys
+ 2004-08-04 02:29:52 166,912 ------w c:\windows\system32\drivers\s3gnbm.sys
- 2004-08-10 19:00:00 96,256 ----a-w c:\windows\system32\drivers\scsiport.sys
+ 2008-04-13 18:40:30 96,384 ----a-w c:\windows\system32\drivers\scsiport.sys
- 2004-08-10 19:00:00 67,584 ----a-w c:\windows\system32\drivers\sdbus.sys
+ 2008-04-13 18:36:44 79,232 ----a-w c:\windows\system32\drivers\sdbus.sys
- 2004-08-10 19:00:00 15,488 ----a-w c:\windows\system32\drivers\serenum.sys
+ 2008-04-13 18:40:12 15,744 ----a-w c:\windows\system32\drivers\serenum.sys
- 2004-08-10 19:00:00 64,896 ----a-w c:\windows\system32\drivers\serial.sys
+ 2008-04-13 19:15:45 64,512 ----a-w c:\windows\system32\drivers\serial.sys
- 2004-08-10 19:00:00 11,136 ----a-w c:\windows\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:47 11,904 ----a-w c:\windows\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 ------w c:\windows\system32\drivers\sffp_mmc.sys
- 2004-08-10 19:00:00 10,240 ----a-w c:\windows\system32\drivers\sffp_sd.sys
+ 2008-04-13 18:40:47 11,008 ----a-w c:\windows\system32\drivers\sffp_sd.sys
- 2004-08-10 19:00:00 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys
+ 2008-04-13 18:40:48 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys
+ 2008-04-14 00:12:05 3,901 ------w c:\windows\system32\drivers\siint5.dll
- 2004-08-03 23:07:44 41,088 ----a-w c:\windows\system32\drivers\SISAGP.SYS
+ 2008-04-13 18:36:39 40,960 ----a-w c:\windows\system32\drivers\sisagp.sys
+ 2008-04-13 18:46:24 11,136 ----a-w c:\windows\system32\drivers\SLIP.sys
+ 2004-08-04 02:41:42 129,535 ------w c:\windows\system32\drivers\slnt7554.sys
+ 2004-08-04 02:41:44 404,990 ------w c:\windows\system32\drivers\slntamr.sys
+ 2004-08-04 02:41:46 95,424 ------w c:\windows\system32\drivers\slnthal.sys
+ 2004-08-04 02:41:46 13,240 ------w c:\windows\system32\drivers\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 ------w c:\windows\system32\drivers\smbali.sys
- 2004-08-03 23:09:56 25,472 ----a-w c:\windows\system32\drivers\sonydcam.sys
+ 2008-04-13 18:46:07 25,344 ----a-w c:\windows\system32\drivers\sonydcam.sys
- 2006-06-14 08:47:46 6,400 ----a-w c:\windows\system32\drivers\splitter.sys
+ 2008-04-13 18:45:07 6,272 ----a-w c:\windows\system32\drivers\splitter.sys
- 2004-08-10 19:00:00 73,472 ----a-w c:\windows\system32\drivers\sr.sys
+ 2008-04-13 18:36:52 73,472 ----a-w c:\windows\system32\drivers\sr.sys
- 2006-08-14 10:34:41 332,928 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-09-08 10:41:42 333,824 ----a-w c:\windows\system32\drivers\srv.sys
- 2004-08-04 03:08:04 48,640 ----a-w c:\windows\system32\drivers\stream.sys
+ 2008-04-13 18:45:15 49,408 ----a-w c:\windows\system32\drivers\stream.sys
+ 2008-04-13 18:46:22 15,232 ----a-w c:\windows\system32\drivers\StreamIP.sys
- 2004-08-03 22:58:42 4,352 ----a-w c:\windows\system32\drivers\swenum.sys
+ 2008-04-13 18:39:53 4,352 ----a-w c:\windows\system32\drivers\swenum.sys
- 2001-08-17 18:00:52 54,272 ----a-w c:\windows\system32\drivers\swmidi.sys
+ 2008-04-13 18:45:09 56,576 ----a-w c:\windows\system32\drivers\swmidi.sys
- 2004-08-04 03:15:56 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys
+ 2008-04-13 19:15:55 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys
- 2004-08-10 19:00:00 14,976 ----a-w c:\windows\system32\drivers\tape.sys
+ 2008-04-13 18:40:50 14,976 ----a-w c:\windows\system32\drivers\tape.sys
- 2008-06-20 10:45:13 360,320 ----a-w c:\windows\system32\drivers\tcpip.sys
+ 2008-06-20 11:51:12 361,600 ----a-w c:\windows\system32\drivers\tcpip.sys
- 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\drivers\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 ----a-w c:\windows\system32\drivers\tcpip6.sys
- 2004-08-10 19:00:00 18,560 ----a-w c:\windows\system32\drivers\tdi.sys
+ 2008-04-13 19:00:05 19,072 ----a-w c:\windows\system32\drivers\tdi.sys
- 2004-08-10 19:00:00 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys
+ 2008-04-14 00:13:20 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys
- 2004-08-10 19:00:00 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys
+ 2008-04-14 00:13:21 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys
- 2004-08-04 01:01:08 40,840 ----a-w c:\windows\system32\drivers\termdd.sys
+ 2008-04-14 00:13:20 40,840 ----a-w c:\windows\system32\drivers\termdd.sys
- 2004-08-03 23:03:18 12,416 ----a-w c:\windows\system32\drivers\tunmp.sys
+ 2008-04-13 18:56:01 12,288 ----a-w c:\windows\system32\drivers\tunmp.sys
+ 2008-04-13 18:36:40 44,672 ------w c:\windows\system32\drivers\uagp35.sys
- 2004-08-10 19:00:00 66,176 ----a-w c:\windows\system32\drivers\udfs.sys
+ 2008-04-13 18:32:36 66,048 ----a-w c:\windows\system32\drivers\udfs.sys
- 2004-08-10 19:00:00 209,408 ----a-w c:\windows\system32\drivers\update.sys
+ 2008-04-13 18:39:46 384,768 ----a-w c:\windows\system32\drivers\update.sys
- 2004-08-10 19:00:00 12,672 ----a-w c:\windows\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ----a-w c:\windows\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ------w c:\windows\system32\drivers\usb8023x.sys
+ 2008-04-13 18:45:12 60,032 ----a-w c:\windows\system32\drivers\USBAUDIO.sys
- 2001-08-17 14:03:42 23,808 ----a-w c:\windows\system32\drivers\usbcamd.sys
+ 2008-04-13 18:45:40 25,600 ----a-w c:\windows\system32\drivers\usbcamd.sys
- 2001-08-17 14:03:44 23,936 ----a-w c:\windows\system32\drivers\usbcamd2.sys
+ 2008-04-13 18:45:41 25,728 ----a-w c:\windows\system32\drivers\usbcamd2.sys
+ 2008-04-13 18:45:40 32,128 ----a-w c:\windows\system32\drivers\usbccgp.sys
- 2004-08-04 07:08:38 26,624 ----a-w c:\windows\system32\drivers\usbehci.sys
+ 2008-04-13 18:45:35 30,208 ----a-w c:\windows\system32\drivers\usbehci.sys
- 2004-08-10 19:00:00 57,600 ----a-w c:\windows\system32\drivers\usbhub.sys
+ 2008-04-13 18:45:37 59,520 ----a-w c:\windows\system32\drivers\usbhub.sys
- 2004-08-03 23:08:58 16,000 ----a-w c:\windows\system32\drivers\usbintel.sys
+ 2008-04-13 18:45:43 15,872 ----a-w c:\windows\system32\drivers\usbintel.sys
- 2004-08-04 07:08:38 17,024 ----a-w c:\windows\system32\drivers\usbohci.sys
+ 2008-04-13 18:45:35 17,152 ----a-w c:\windows\system32\drivers\usbohci.sys
- 2004-08-10 19:00:00 142,976 ----a-w c:\windows\system32\drivers\usbport.sys
+ 2008-04-13 18:45:36 143,872 ----a-w c:\windows\system32\drivers\usbport.sys
- 2004-08-10 19:00:00 26,496 ----a-w c:\windows\system32\drivers\usbstor.sys
+ 2008-04-13 18:45:38 26,368 ----a-w c:\windows\system32\drivers\usbstor.sys
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\drivers\usbuhci.sys
+ 2008-04-13 18:45:35 20,608 ----a-w c:\windows\system32\drivers\usbuhci.sys
+ 2008-04-13 18:46:20 121,984 ------w c:\windows\system32\drivers\usbvideo.sys
+ 2008-04-14 00:12:08 11,325 ------w c:\windows\system32\drivers\vchnt5.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\drivers\vga.sys
+ 2008-04-13 18:44:40 20,992 ----a-w c:\windows\system32\drivers\vga.sys
- 2004-08-03 23:07:44 42,240 ----a-w c:\windows\system32\drivers\VIAAGP.SYS
+ 2008-04-13 18:36:40 42,240 ----a-w c:\windows\system32\drivers\viaagp.sys
- 2004-08-10 19:00:00 5,376 ----a-w c:\windows\system32\drivers\viaide.sys
+ 2008-04-13 18:40:31 5,376 ----a-w c:\windows\system32\drivers\viaide.sys
- 2004-08-10 19:00:00 79,744 ----a-w c:\windows\system32\drivers\videoprt.sys
+ 2008-04-13 18:44:40 81,664 ----a-w c:\windows\system32\drivers\videoprt.sys
- 2004-08-10 19:00:00 52,352 ----a-w c:\windows\system32\drivers\volsnap.sys
+ 2008-04-13 18:41:01 52,352 ----a-w c:\windows\system32\drivers\volsnap.sys
+ 2008-04-13 18:43:55 14,208 ------w c:\windows\system32\drivers\wacompen.sys
+ 2004-08-04 02:29:40 11,807 ------w c:\windows\system32\drivers\wadv07nt.sys
+ 2004-08-04 02:29:40 11,295 ------w c:\windows\system32\drivers\wadv08nt.sys
+ 2004-08-04 02:29:42 11,871 ------w c:\windows\system32\drivers\wadv09nt.sys
+ 2004-08-04 02:29:42 11,935 ------w c:\windows\system32\drivers\wadv11nt.sys
- 2004-08-10 19:00:00 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys
+ 2008-04-13 18:57:21 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys
+ 2004-08-04 02:29:46 22,271 ------w c:\windows\system32\drivers\watv06nt.sys
+ 2004-08-04 02:29:46 25,471 ------w c:\windows\system32\drivers\watv10nt.sys
- 2006-06-14 09:00:45 82,944 ----a-w c:\windows\system32\drivers\wdmaud.sys
+ 2008-04-13 19:17:18 83,072 ----a-w c:\windows\system32\drivers\wdmaud.sys
- 2008-03-25 20:15:22 50,536 ----a-w c:\windows\system32\drivers\WpsHelper.sys
+ 2008-03-25 21:15:22 50,536 ----a-w c:\windows\system32\drivers\WpsHelper.sys
+ 2008-04-13 18:46:24 19,200 ----a-w c:\windows\system32\drivers\WSTCODEC.SYS
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\drprov.dll
+ 2008-04-14 00:11:52 14,336 ----a-w c:\windows\system32\drprov.dll
+ 2008-04-17 18:12:54 107,368 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 18:12:54 15,464 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
+ 2008-04-25 12:18:24 185,352 -c--a-w c:\windows\system32\DRVSTORE\nx6000_C7BD514BECF496356358A0FCC625B173CE5AD364\LCCoin20.dll
+ 2008-08-04 20:22:18 33,808 -c--a-w c:\windows\system32\DRVSTORE\nx6000_C7BD514BECF496356358A0FCC625B173CE5AD364\nx6000.sys
+ 2008-11-07 19:23:30 32,000 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
+ 2008-04-25 12:18:26 111,624 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\1033\VX1000.dll
+ 2008-04-25 12:18:22 189,448 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\cVX1000.dll
+ 2008-04-25 12:18:24 185,352 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\LCCoin20.dll
+ 2008-04-25 12:18:26 517,128 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\TwainUI.dll
+ 2008-04-25 12:18:26 218,120 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\vVX1000.dll
+ 2008-04-25 12:18:26 721,928 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\vVX1000.exe
+ 2008-04-25 12:18:26 1,964,424 -c--a-w c:\windows\system32\DRVSTORE\VX1000_015DD07F1C1BF6F5CFB44B5A547C0AC4225B44F6\VX1000.sys
+ 2008-04-25 12:18:26 111,624 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\1033\VX3000.dll
+ 2008-04-25 12:18:22 189,448 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\cVX3000.dll
+ 2008-04-25 12:18:26 185,352 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\LCCoin20.dll
+ 2008-04-25 12:18:26 517,128 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\TwainUI.dll
+ 2008-04-25 12:18:26 218,120 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\vVX3000.dll
+ 2008-04-25 12:18:26 721,928 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\vVX3000.exe
+ 2008-04-25 12:18:26 1,964,808 -c--a-w c:\windows\system32\DRVSTORE\VX3000_052F8D5E78E9788221E4DDC49AADB58AEBEEF337\VX3000.sys
+ 2008-04-25 12:18:26 115,720 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\1033\VX6000.dll
+ 2008-04-25 12:18:22 189,448 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\cVX6000.dll
+ 2008-04-25 12:18:26 185,352 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\LCCoin20.dll
+ 2008-04-25 12:18:26 467,976 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\vVX6000.dll
+ 2008-04-25 12:18:26 713,736 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\vVX6000.exe
+ 2008-04-25 12:18:28 2,077,832 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\VX6000Xp.sys
+ 2008-04-25 12:18:28 36,232 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\VX6KCamd.sys
+ 2008-04-25 12:18:28 513,032 -c--a-w c:\windows\system32\DRVSTORE\VX6000_B98963198176720A90285CFBB5B3EF4B30356ADE\VX6KTUI.dll
- 2004-08-10 19:00:00 16,384 ----a-w c:\windows\system32\ds32gt.dll
+ 2008-04-14 00:11:52 16,384 ----a-w c:\windows\system32\ds32gt.dll
- 2004-08-10 19:00:00 181,760 ----a-w c:\windows\system32\dsdmo.dll
+ 2008-04-14 00:11:52 181,248 ----a-w c:\windows\system32\dsdmo.dll
- 2004-08-10 19:00:00 71,680 ----a-w c:\windows\system32\dsdmoprp.dll
+ 2008-04-14 00:11:52 71,680 ----a-w c:\windows\system32\dsdmoprp.dll
- 2004-08-10 19:00:00 92,672 ----a-w c:\windows\system32\dskquota.dll
+ 2008-04-14 00:11:52 92,672 ----a-w c:\windows\system32\dskquota.dll
- 2004-08-10 19:00:00 144,384 ----a-w c:\windows\system32\dskquoui.dll
+ 2008-04-14 00:11:52 155,648 ----a-w c:\windows\system32\dskquoui.dll
- 2004-08-10 19:00:00 367,616 ----a-w c:\windows\system32\dsound.dll
+ 2008-04-14 00:11:52 367,616 ----a-w c:\windows\system32\dsound.dll
- 2004-08-10 19:00:00 1,294,336 ----a-w c:\windows\system32\dsound3d.dll
+ 2008-04-14 00:11:52 1,293,824 ----a-w c:\windows\system32\dsound3d.dll

EasyEEE
2008-12-29, 18:15
- 2004-08-10 19:00:00 142,336 ----a-w c:\windows\system32\dsprop.dll
+ 2008-04-14 00:11:52 142,848 ----a-w c:\windows\system32\dsprop.dll
- 2004-08-10 19:00:00 4,096 ----a-w c:\windows\system32\dsprpres.dll
+ 2008-04-13 17:09:30 4,096 ----a-w c:\windows\system32\dsprpres.dll
- 2004-08-10 19:00:00 239,104 ----a-w c:\windows\system32\dsquery.dll
+ 2008-04-14 00:11:52 239,104 ----a-w c:\windows\system32\dsquery.dll
- 2004-08-10 19:00:00 51,200 ----a-w c:\windows\system32\dssec.dll
+ 2008-04-14 00:11:52 51,200 ----a-w c:\windows\system32\dssec.dll
- 2004-08-10 19:00:00 137,216 ----a-w c:\windows\system32\dssenh.dll
+ 2008-04-13 17:37:57 138,752 ----a-w c:\windows\system32\dssenh.dll
- 2004-08-10 19:00:00 113,152 ----a-w c:\windows\system32\dsuiext.dll
+ 2008-04-14 00:11:52 113,152 ----a-w c:\windows\system32\dsuiext.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\system32\dswave.dll
+ 2008-04-14 00:11:52 19,456 ----a-w c:\windows\system32\dswave.dll
- 2008-03-21 20:28:54 196,608 ----a-w c:\windows\system32\dtu100.dll
+ 2007-01-03 21:52:55 196,608 ----a-w c:\windows\system32\dtu100.dll
- 2004-08-10 19:00:00 10,752 ----a-w c:\windows\system32\dumprep.exe
+ 2008-04-14 00:12:18 10,752 ----a-w c:\windows\system32\dumprep.exe
- 2004-08-10 19:00:00 304,128 ----a-w c:\windows\system32\duser.dll
+ 2008-04-14 00:11:52 304,128 ----a-w c:\windows\system32\duser.dll
- 2004-08-10 19:00:00 17,920 ----a-w c:\windows\system32\dvdupgrd.exe
+ 2008-04-14 00:12:18 17,920 ----a-w c:\windows\system32\dvdupgrd.exe
- 2004-08-10 19:00:00 180,224 ----a-w c:\windows\system32\dwwin.exe
+ 2008-04-14 00:12:18 180,224 ----a-w c:\windows\system32\dwwin.exe
- 2004-08-10 19:00:00 619,008 ----a-w c:\windows\system32\dx7vb.dll
+ 2008-04-14 00:11:52 619,008 ----a-w c:\windows\system32\dx7vb.dll
- 2004-08-10 19:00:00 1,227,264 ----a-w c:\windows\system32\dx8vb.dll
+ 2008-04-14 00:11:52 1,227,264 ----a-w c:\windows\system32\dx8vb.dll
- 2004-08-10 19:00:00 1,298,432 ----a-w c:\windows\system32\dxdiag.exe
+ 2008-04-14 00:12:18 1,298,432 ----a-w c:\windows\system32\dxdiag.exe
- 2004-08-10 19:00:00 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll
+ 2008-04-14 00:11:52 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll
- 2006-08-22 09:05:26 498,742 ----a-w c:\windows\system32\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 ----a-w c:\windows\system32\dxmasf.dll
- 2008-04-23 04:16:28 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-04-23 04:16:28 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2007-10-09 17:03:00 73,752 ----a-w c:\windows\system32\dxva2.dll
+ 2008-04-14 00:11:52 30,720 ------w c:\windows\system32\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ------w c:\windows\system32\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ------w c:\windows\system32\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ------w c:\windows\system32\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ------w c:\windows\system32\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ------w c:\windows\system32\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ------w c:\windows\system32\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ------w c:\windows\system32\eapsvc.dll
- 2004-08-10 19:00:00 26,624 ----a-w c:\windows\system32\efsadu.dll
+ 2008-04-14 00:11:52 26,624 ----a-w c:\windows\system32\efsadu.dll
- 2004-08-10 19:00:00 183,296 ----a-w c:\windows\system32\els.dll
+ 2008-04-14 00:11:53 183,296 ----a-w c:\windows\system32\els.dll
+ 2008-04-14 00:11:57 28,672 -c----w c:\windows\system32\en\microsoft.managementconsole.resources.dll
+ 2008-04-14 00:11:57 40,960 -c----w c:\windows\system32\en\mmcex.resources.dll
+ 2008-04-14 00:11:57 6,656 -c----w c:\windows\system32\en\mmcfxcommon.resources.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\encapi.dll
+ 2008-04-14 00:11:53 20,480 ----a-w c:\windows\system32\encapi.dll
- 2004-08-10 19:00:00 23,040 ----a-w c:\windows\system32\ersvc.dll
+ 2008-04-14 00:11:53 23,040 ----a-w c:\windows\system32\ersvc.dll
- 2005-07-26 04:39:45 243,200 ----a-w c:\windows\system32\es.dll
+ 2008-07-07 20:26:58 253,952 ----a-w c:\windows\system32\es.dll
- 2005-10-20 22:20:03 1,082,368 ----a-w c:\windows\system32\esent.dll
+ 2008-04-14 00:11:53 1,082,368 ----a-w c:\windows\system32\esent.dll
- 2004-08-10 19:00:00 193,024 ----a-w c:\windows\system32\eudcedit.exe
+ 2008-04-14 00:12:19 193,024 ----a-w c:\windows\system32\eudcedit.exe
- 2004-08-10 19:00:00 50,176 ----a-w c:\windows\system32\eventcreate.exe
+ 2008-04-14 00:12:19 50,688 ----a-w c:\windows\system32\eventcreate.exe
- 2004-08-10 19:00:00 55,808 ----a-w c:\windows\system32\eventlog.dll
+ 2008-04-14 00:11:53 56,320 ----a-w c:\windows\system32\eventlog.dll
- 2004-08-10 19:00:00 77,824 ----a-w c:\windows\system32\eventtriggers.exe
+ 2008-04-14 00:12:19 82,944 ----a-w c:\windows\system32\eventtriggers.exe
+ 2007-10-09 17:03:12 493,080 ----a-w c:\windows\system32\evr.dll
- 2004-08-10 19:00:00 380,957 ----a-w c:\windows\system32\expsrv.dll
+ 2008-04-14 00:11:53 380,445 ----a-w c:\windows\system32\expsrv.dll
- 2008-04-23 04:16:28 133,120 ------w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 ------w c:\windows\system32\extmgr.dll
- 2004-08-10 19:00:00 45,568 ----a-w c:\windows\system32\extrac32.exe
+ 2008-04-14 00:12:19 24,064 ----a-w c:\windows\system32\extrac32.exe
- 2004-08-10 19:00:00 121,856 ----a-w c:\windows\system32\exts.dll
+ 2008-04-14 00:11:53 125,952 ----a-w c:\windows\system32\exts.dll
- 2004-08-10 19:00:00 80,384 ----a-w c:\windows\system32\faultrep.dll
+ 2008-04-14 00:11:53 80,384 ----a-w c:\windows\system32\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ------w c:\windows\system32\faxpatch.exe
- 2004-08-10 19:00:00 117,760 ----a-w c:\windows\system32\fde.dll
+ 2008-04-14 00:11:53 124,928 ----a-w c:\windows\system32\fde.dll
- 2004-08-10 19:00:00 73,728 ----a-w c:\windows\system32\fdeploy.dll
+ 2008-04-14 00:11:53 73,728 ----a-w c:\windows\system32\fdeploy.dll
- 2004-08-10 19:00:00 21,504 ----a-w c:\windows\system32\feclient.dll
+ 2008-04-14 00:11:53 21,504 ----a-w c:\windows\system32\feclient.dll
+ 2008-08-02 02:21:18 7,680 ----a-w c:\windows\system32\ff_vfw.dll
- 2004-08-10 19:00:00 337,920 ----a-w c:\windows\system32\filemgmt.dll
+ 2008-04-14 00:11:53 337,920 ----a-w c:\windows\system32\filemgmt.dll
- 2004-08-10 19:00:00 27,136 ----a-w c:\windows\system32\findstr.exe
+ 2008-04-14 00:12:20 27,136 ----a-w c:\windows\system32\findstr.exe
- 2004-08-10 19:00:00 87,552 ----a-w c:\windows\system32\fldrclnr.dll
+ 2008-04-14 00:11:53 87,552 ----a-w c:\windows\system32\fldrclnr.dll
- 2006-08-21 12:21:06 16,896 ----a-w c:\windows\system32\fltlib.dll
+ 2008-04-14 00:11:53 16,896 ----a-w c:\windows\system32\fltlib.dll
- 2006-08-21 09:14:58 23,040 ----a-w c:\windows\system32\fltmc.exe
+ 2008-04-14 00:12:20 23,040 ----a-w c:\windows\system32\fltmc.exe
+ 1998-07-06 06:00:00 42,496 ----a-w c:\windows\system32\FLXGDDE.DLL
- 2008-07-08 21:56:50 178,648 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-11-21 03:03:06 220,040 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 19:00:00 382,976 ----a-w c:\windows\system32\fontext.dll
+ 2008-04-14 00:11:53 382,976 ----a-w c:\windows\system32\fontext.dll
- 2005-10-17 21:14:45 80,896 ----a-w c:\windows\system32\fontsub.dll
+ 2008-04-14 00:11:53 80,896 ----a-w c:\windows\system32\fontsub.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\fontview.exe
+ 2008-04-14 00:12:20 20,992 ----a-w c:\windows\system32\fontview.exe
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\forcedos.exe
+ 2008-04-14 00:12:20 7,680 ----a-w c:\windows\system32\forcedos.exe
- 2004-08-10 19:00:00 25,600 ----a-w c:\windows\system32\format.com
+ 2008-04-14 00:12:42 29,696 ----a-w c:\windows\system32\format.com
- 2004-08-10 19:00:00 9,344 ----a-w c:\windows\system32\framebuf.dll
+ 2008-04-14 00:09:33 9,344 ----a-w c:\windows\system32\framebuf.dll
- 2004-08-10 19:00:00 193,024 ----a-w c:\windows\system32\fsquirt.exe
+ 2008-04-14 00:12:20 193,024 ----a-w c:\windows\system32\fsquirt.exe
- 2004-08-10 19:00:00 42,496 ----a-w c:\windows\system32\ftp.exe
+ 2008-04-14 00:12:20 42,496 ----a-w c:\windows\system32\ftp.exe
- 2004-08-10 19:00:00 60,416 ----a-w c:\windows\system32\fwcfg.dll
+ 2008-04-14 00:11:53 60,416 ----a-w c:\windows\system32\fwcfg.dll
- 2008-02-20 06:51:05 282,624 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 12:36:14 286,720 ----a-w c:\windows\system32\gdi32.dll
- 2008-01-29 16:02:30 107,368 ----a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-17 18:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
- 2004-08-10 19:00:00 55,296 ----a-w c:\windows\system32\getmac.exe
+ 2008-04-14 00:12:21 59,904 ----a-w c:\windows\system32\getmac.exe
- 2004-08-10 19:00:00 122,880 ----a-w c:\windows\system32\glu32.dll
+ 2008-04-14 00:11:54 122,880 ----a-w c:\windows\system32\glu32.dll
- 2004-08-10 19:00:00 566,784 ----a-w c:\windows\system32\gpedit.dll
+ 2008-04-14 00:09:35 566,784 ----a-w c:\windows\system32\gpedit.dll
- 2004-08-10 19:00:00 9,728 ----a-w c:\windows\system32\gpkrsrc.dll
+ 2006-12-31 01:26:44 9,728 ----a-w c:\windows\system32\gpkrsrc.dll
- 2004-08-10 19:00:00 119,808 ----a-w c:\windows\system32\gpresult.exe
+ 2008-04-14 00:12:21 120,832 ----a-w c:\windows\system32\gpresult.exe
- 2004-08-10 19:00:00 198,656 ----a-w c:\windows\system32\gptext.dll
+ 2008-04-14 00:11:54 199,680 ----a-w c:\windows\system32\gptext.dll
- 2004-08-10 19:00:00 39,424 ----a-w c:\windows\system32\grpconv.exe
+ 2008-04-14 00:12:21 39,424 ----a-w c:\windows\system32\grpconv.exe
- 2004-08-10 19:00:00 614,912 ----a-w c:\windows\system32\h323msp.dll
+ 2008-04-14 00:11:54 614,912 ----a-w c:\windows\system32\h323msp.dll
- 2004-08-04 03:59:10 131,968 ----a-w c:\windows\system32\hal.dll
+ 2008-04-13 18:31:28 131,840 ----a-w c:\windows\system32\HAL.DLL
- 2004-08-04 08:56:44 7,168 ----a-w c:\windows\system32\hccoin.dll
+ 2008-04-14 00:11:54 7,168 ----a-w c:\windows\system32\hccoin.dll
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\help.exe
+ 2008-04-14 00:12:21 15,872 ----a-w c:\windows\system32\help.exe
- 2005-05-27 02:04:27 41,472 ----a-w c:\windows\system32\hhsetup.dll
+ 2008-04-14 00:11:54 41,472 ----a-w c:\windows\system32\hhsetup.dll
- 2004-08-04 00:56:44 20,992 ----a-w c:\windows\system32\hid.dll
+ 2008-04-14 00:11:54 20,992 ----a-w c:\windows\system32\hid.dll
- 2006-07-21 08:24:43 72,704 ----a-w c:\windows\system32\hlink.dll
+ 2008-04-14 00:11:54 72,704 ----a-w c:\windows\system32\hlink.dll
- 2004-08-10 19:00:00 344,064 ----a-w c:\windows\system32\hnetcfg.dll
+ 2008-04-14 00:11:54 344,064 ----a-w c:\windows\system32\hnetcfg.dll
- 2004-08-10 19:00:00 330,752 ----a-w c:\windows\system32\hnetwiz.dll
+ 2008-04-14 00:11:54 330,752 ----a-w c:\windows\system32\hnetwiz.dll
- 2004-08-10 19:00:00 144,896 ----a-w c:\windows\system32\hotplug.dll
+ 2008-04-14 00:11:54 144,896 ----a-w c:\windows\system32\hotplug.dll
+ 2008-04-14 00:11:54 32,285 ------w c:\windows\system32\hsfcisp2.dll
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\httpapi.dll
+ 2008-04-14 00:11:54 24,576 ----a-w c:\windows\system32\httpapi.dll
- 2004-08-10 19:00:00 41,984 ----a-w c:\windows\system32\htui.dll
+ 2008-04-14 00:11:54 41,984 ----a-w c:\windows\system32\htui.dll
- 2004-11-17 17:41:24 347,136 ----a-w c:\windows\system32\hypertrm.dll
+ 2008-04-14 00:11:54 347,136 ----a-w c:\windows\system32\hypertrm.dll
- 2004-08-10 19:00:00 119,808 ----a-w c:\windows\system32\iasrad.dll
+ 2008-04-14 00:11:54 119,808 ----a-w c:\windows\system32\iasrad.dll
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\icaapi.dll
+ 2008-04-14 00:11:54 11,264 ----a-w c:\windows\system32\icaapi.dll
+ 2007-10-11 13:55:10 579,584 ----a-w c:\windows\system32\icardagt.exe
- 2008-04-23 04:16:28 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2007-10-11 13:55:10 11,776 ----a-w c:\windows\system32\icardres.dll
- 2004-08-10 19:00:00 80,384 ----a-w c:\windows\system32\iccvid.dll
+ 2008-04-14 00:11:54 80,384 ----a-w c:\windows\system32\iccvid.dll
- 2005-06-29 01:46:00 254,976 ----a-w c:\windows\system32\icm32.dll
+ 2008-04-14 00:11:54 254,976 ----a-w c:\windows\system32\icm32.dll
- 2004-08-10 19:00:00 3,584 ----a-w c:\windows\system32\icmp.dll
+ 2008-04-14 00:09:40 3,584 ----a-w c:\windows\system32\icmp.dll
- 2004-08-10 19:00:00 73,728 ----a-w c:\windows\system32\icwdial.dll
+ 2008-04-14 00:11:54 73,728 ----a-w c:\windows\system32\icwdial.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\icwphbk.dll
+ 2008-04-14 00:11:54 65,536 ----a-w c:\windows\system32\icwphbk.dll
- 2004-08-10 19:00:00 120,832 ----a-w c:\windows\system32\idq.dll
+ 2008-04-14 00:11:54 120,832 ----a-w c:\windows\system32\idq.dll
- 2008-04-22 07:39:58 70,656 ------w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 ------w c:\windows\system32\ie4uinit.exe
- 2008-04-23 04:16:28 153,088 ------w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 ------w c:\windows\system32\ieakeng.dll
- 2008-04-23 04:16:28 230,400 ------w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 ------w c:\windows\system32\ieaksie.dll
- 2008-04-20 05:07:51 161,792 ------w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ------w c:\windows\system32\ieakui.dll
- 2008-04-23 04:16:28 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-04-23 04:16:28 384,512 ------w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 ------w c:\windows\system32\iedkcs32.dll
- 2007-08-13 23:45:18 78,336 ----a-w c:\windows\system32\ieencode.dll
+ 2008-04-14 00:11:54 81,920 ----a-w c:\windows\system32\ieencode.dll
- 2008-04-23 04:16:28 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-04-23 04:16:28 44,544 ------w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 ------w c:\windows\system32\iernonce.dll
- 2008-04-23 04:16:28 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-04-22 07:39:58 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2004-08-10 19:00:00 114,688 ----a-w c:\windows\system32\iexpress.exe
+ 2008-04-14 00:12:22 114,688 ----a-w c:\windows\system32\iexpress.exe
- 2004-08-10 19:00:00 135,680 ----a-w c:\windows\system32\ifmon.dll
+ 2008-04-14 00:11:54 135,680 ----a-w c:\windows\system32\ifmon.dll
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\igmpagnt.dll
+ 2008-04-14 00:11:54 8,192 ----a-w c:\windows\system32\igmpagnt.dll
- 2004-08-10 19:00:00 81,920 ----a-w c:\windows\system32\ils.dll
+ 2008-04-14 00:11:54 81,920 ----a-w c:\windows\system32\ils.dll
- 2004-08-10 19:00:00 144,384 ----a-w c:\windows\system32\imagehlp.dll
+ 2008-04-14 00:11:54 144,384 ----a-w c:\windows\system32\imagehlp.dll
- 2004-08-10 19:00:00 150,016 ----a-w c:\windows\system32\imapi.exe
+ 2008-04-14 00:12:22 150,528 ----a-w c:\windows\system32\imapi.exe
- 2004-08-10 19:00:00 36,921 ----a-w c:\windows\system32\imeshare.dll
+ 2008-04-14 00:11:54 36,921 ----a-w c:\windows\system32\imeshare.dll
- 2004-08-10 19:00:00 110,080 ----a-w c:\windows\system32\imm32.dll
+ 2008-04-14 00:11:54 110,080 ----a-w c:\windows\system32\imm32.dll
- 2004-08-10 19:00:00 274,432 ----a-w c:\windows\system32\inetcfg.dll
+ 2008-04-14 00:11:54 274,432 ----a-w c:\windows\system32\inetcfg.dll
- 2007-08-21 06:15:44 683,520 ----a-w c:\windows\system32\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 ----a-w c:\windows\system32\inetcomm.dll
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\system32\inetmib1.dll
+ 2008-04-14 00:11:55 32,768 ----a-w c:\windows\system32\inetmib1.dll
- 2004-08-10 19:00:00 75,264 ----a-w c:\windows\system32\inetpp.dll
+ 2008-04-14 00:11:55 75,264 ----a-w c:\windows\system32\inetpp.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\inetppui.dll
+ 2008-04-14 00:11:55 15,872 ----a-w c:\windows\system32\inetppui.dll
- 2004-08-10 19:00:00 48,128 ----a-w c:\windows\system32\inetres.dll
+ 2008-04-13 16:22:12 48,128 ----a-w c:\windows\system32\inetres.dll
+ 2008-04-14 00:12:05 221,696 -c----w c:\windows\system32\inetsrv\seo.dll
+ 2008-04-14 00:12:06 189,440 -c----w c:\windows\system32\inetsrv\smtpadm.dll
+ 2008-04-14 00:12:06 2,134,528 -c----w c:\windows\system32\inetsrv\smtpsnap.dll
+ 1999-01-28 19:44:20 49,152 ----a-w c:\windows\system32\INETWH32.dll
+ 2007-10-11 13:55:10 88,576 ----a-w c:\windows\system32\infocardapi.dll
+ 2008-04-14 00:12:38 26,112 ----a-w c:\windows\system32\init32.exe
- 2004-08-10 19:00:00 147,456 ----a-w c:\windows\system32\initpki.dll
+ 2008-04-14 00:11:55 147,456 ----a-w c:\windows\system32\initpki.dll
- 2004-08-10 19:00:00 123,392 ----a-w c:\windows\system32\input.dll
+ 2008-04-14 00:11:55 123,392 ----a-w c:\windows\system32\input.dll
- 2004-08-10 19:00:00 55,808 ----a-w c:\windows\system32\ipconfig.exe
+ 2008-04-14 00:12:22 55,808 ----a-w c:\windows\system32\ipconfig.exe
- 2006-05-19 12:59:41 94,720 ----a-w c:\windows\system32\iphlpapi.dll
+ 2008-04-14 00:11:55 94,720 ----a-w c:\windows\system32\iphlpapi.dll
- 2004-08-10 19:00:00 154,112 ----a-w c:\windows\system32\ipmontr.dll
+ 2008-04-14 00:11:55 161,280 ----a-w c:\windows\system32\ipmontr.dll
- 2004-08-10 19:00:00 331,264 ----a-w c:\windows\system32\ipnathlp.dll
+ 2008-04-14 00:11:55 331,264 ----a-w c:\windows\system32\ipnathlp.dll
- 2004-08-10 19:00:00 330,752 ----a-w c:\windows\system32\ippromon.dll
+ 2008-04-14 00:11:55 330,752 ----a-w c:\windows\system32\ippromon.dll
- 2004-08-10 19:00:00 169,984 ----a-w c:\windows\system32\iprtrmgr.dll
+ 2008-04-14 00:11:55 177,152 ----a-w c:\windows\system32\iprtrmgr.dll
- 2004-08-10 19:00:00 349,696 ----a-w c:\windows\system32\ipsecsnp.dll
+ 2008-04-14 00:11:55 349,696 ----a-w c:\windows\system32\ipsecsnp.dll
- 2004-08-10 19:00:00 182,784 ----a-w c:\windows\system32\ipsecsvc.dll
+ 2008-04-14 00:11:55 183,808 ----a-w c:\windows\system32\ipsecsvc.dll
- 2004-08-10 19:00:00 384,000 ----a-w c:\windows\system32\ipsmsnap.dll
+ 2008-04-14 00:11:55 384,000 ----a-w c:\windows\system32\ipsmsnap.dll
- 2004-08-10 19:00:00 53,248 ----a-w c:\windows\system32\ipv6.exe
+ 2008-04-14 00:12:23 53,248 ----a-w c:\windows\system32\ipv6.exe
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\ipv6mon.dll
+ 2008-04-14 00:11:55 59,904 ----a-w c:\windows\system32\ipv6mon.dll
- 2004-08-10 19:00:00 23,552 ----a-w c:\windows\system32\ipxroute.exe
+ 2008-04-14 00:12:23 23,552 ----a-w c:\windows\system32\ipxroute.exe
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\ipxwan.dll
+ 2008-04-14 00:11:55 22,016 ----a-w c:\windows\system32\ipxwan.dll
- 2004-08-10 19:00:00 120,320 ----a-w c:\windows\system32\ir41_qc.dll
+ 2008-04-14 00:11:55 120,320 ----a-w c:\windows\system32\ir41_qc.dll
- 2004-08-10 19:00:00 338,432 ----a-w c:\windows\system32\ir41_qcx.dll
+ 2008-04-14 00:11:55 338,432 ----a-w c:\windows\system32\ir41_qcx.dll
- 2004-08-10 19:00:00 755,200 ----a-w c:\windows\system32\ir50_32.dll
+ 2008-04-14 00:11:55 755,200 ----a-w c:\windows\system32\ir50_32.dll
- 2004-08-10 19:00:00 200,192 ----a-w c:\windows\system32\ir50_qc.dll
+ 2008-04-14 00:11:55 200,192 ----a-w c:\windows\system32\ir50_qc.dll
- 2004-08-10 19:00:00 183,808 ----a-w c:\windows\system32\ir50_qcx.dll
+ 2008-04-14 00:11:55 183,808 ----a-w c:\windows\system32\ir50_qcx.dll
- 2004-08-10 19:00:00 81,920 ----a-w c:\windows\system32\isign32.dll
+ 2008-04-14 00:11:55 81,920 ----a-w c:\windows\system32\isign32.dll
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\isrdbg32.dll
+ 2008-04-14 00:11:55 32,768 ----a-w c:\windows\system32\isrdbg32.dll
- 2005-05-27 02:04:27 155,136 ----a-w c:\windows\system32\itircl.dll
+ 2008-04-14 00:11:55 155,136 ----a-w c:\windows\system32\itircl.dll
- 2005-05-27 02:04:27 137,216 ----a-w c:\windows\system32\itss.dll
+ 2008-04-14 00:11:55 138,240 ----a-w c:\windows\system32\itss.dll
- 2004-08-10 19:00:00 192,000 ----a-w c:\windows\system32\iuengine.dll
+ 2008-04-14 00:11:55 191,488 ----a-w c:\windows\system32\iuengine.dll
+ 2002-11-22 07:57:24 20,480 ----a-w c:\windows\system32\IVIresize.dll
+ 2002-11-22 07:57:26 200,704 ----a-w c:\windows\system32\IVIresizeA6.dll
+ 2002-11-22 07:57:26 192,512 ----a-w c:\windows\system32\IVIresizeM6.dll
+ 2002-11-22 07:57:26 192,512 ----a-w c:\windows\system32\IVIresizeP6.dll
+ 2002-11-22 07:57:26 188,416 ----a-w c:\windows\system32\IVIresizePX.dll
+ 2002-11-22 07:57:26 204,800 ----a-w c:\windows\system32\IVIresizeW7.dll
- 2004-08-10 19:00:00 54,272 ----a-w c:\windows\system32\ixsso.dll
+ 2008-04-14 00:11:55 54,272 ----a-w c:\windows\system32\ixsso.dll
- 2004-08-04 00:56:44 47,616 ----a-w c:\windows\system32\iyuv_32.dll
+ 2008-04-14 00:11:55 47,616 ----a-w c:\windows\system32\iyuv_32.dll
- 2008-02-22 05:23:35 135,168 ----a-w c:\windows\system32\java.exe
+ 2008-06-10 05:21:01 135,168 ----a-w c:\windows\system32\java.exe
- 2008-02-22 05:23:39 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 ----a-w c:\windows\system32\javaw.exe
- 2008-02-22 06:33:32 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2008-06-10 06:32:34 139,264 ----a-w c:\windows\system32\javaws.exe
- 2006-06-01 18:47:07 163,840 ----a-w c:\windows\system32\jgdw400.dll
+ 2008-04-14 00:11:55 163,840 ----a-w c:\windows\system32\jgdw400.dll
- 2006-06-01 18:47:07 27,648 ----a-w c:\windows\system32\jgpl400.dll
+ 2008-04-14 00:11:55 27,648 ----a-w c:\windows\system32\jgpl400.dll
- 2007-08-13 23:38:04 491,520 ----a-w c:\windows\system32\jscript.dll
+ 2008-05-09 10:53:39 512,000 ----a-w c:\windows\system32\jscript.dll
- 2008-04-23 04:16:28 27,648 ------w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ------w c:\windows\system32\kbdbhc.dll
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\kbdfi1.dll
+ 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdfi1.dll
- 2004-08-10 19:00:00 6,144 ----a-w c:\windows\system32\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdinbe1.dll
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\kbdinben.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdinben.dll
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,656 ----a-w c:\windows\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 ------w c:\windows\system32\kbdiultn.dll
- 2004-08-10 19:00:00 5,632 ----a-w c:\windows\system32\kbdmaori.dll
+ 2008-04-14 00:09:55 5,632 ----a-w c:\windows\system32\kbdmaori.dll
- 2004-08-10 19:00:00 6,144 ----a-w c:\windows\system32\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdmlt47.dll
- 2004-08-10 19:00:00 6,144 ----a-w c:\windows\system32\kbdmlt48.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\kbdmlt48.dll
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\kbdnec.dll
+ 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 ------w c:\windows\system32\kbdnepr.dll
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\kbdno1.dll
+ 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 ------w c:\windows\system32\kbdpash.dll
- 2004-08-10 19:00:00 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll
- 2004-08-10 19:00:00 7,680 ----a-w c:\windows\system32\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,680 ----a-w c:\windows\system32\kbdsmsno.dll
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\kbdukx.dll
+ 2008-04-14 00:09:55 7,168 ----a-w c:\windows\system32\kbdukx.dll
- 2004-08-10 19:00:00 7,424 ----a-w c:\windows\system32\kd1394.dll
+ 2008-04-13 18:31:35 7,424 ----a-w c:\windows\system32\kd1394.dll
- 2005-06-15 17:49:30 295,936 ----a-w c:\windows\system32\kerberos.dll
+ 2008-04-14 00:11:56 299,520 ----a-w c:\windows\system32\kerberos.dll
- 2007-04-16 15:52:53 984,576 ----a-w c:\windows\system32\kernel32.dll
+ 2008-04-14 00:11:56 989,696 ----a-w c:\windows\system32\kernel32.dll
- 2004-08-10 19:00:00 150,528 ----a-w c:\windows\system32\keymgr.dll
+ 2008-04-14 00:11:56 150,528 ----a-w c:\windows\system32\keymgr.dll
+ 2008-11-02 13:05:34 2,516 --sha-w c:\windows\system32\KGyGaAvL.sys
+ 2008-04-14 00:11:56 61,440 ------w c:\windows\system32\kmsvc.dll
- 2004-08-04 04:56:44 4,096 ----a-w c:\windows\system32\ksuser.dll
+ 2008-04-14 00:11:56 4,096 ----a-w c:\windows\system32\ksuser.dll
+ 2008-04-14 00:11:56 37,376 ------w c:\windows\system32\l2gpstore.dll
+ 2008-04-25 12:18:24 185,352 ----a-w c:\windows\system32\LCCoin20.dll
- 2007-10-11 19:12:48 1,468,968 ------w c:\windows\system32\LegitCheckControl.dll
+ 2008-03-20 22:06:36 1,480,232 ------w c:\windows\system32\LegitCheckControl.dll
- 2008-03-21 20:30:00 1,044,480 ----a-w c:\windows\system32\libdivx.dll
+ 2007-01-03 21:58:03 1,044,480 ----a-w c:\windows\system32\libdivx.dll
- 2004-08-10 19:00:00 423,936 ----a-w c:\windows\system32\licdll.dll
+ 2008-04-14 09:41:58 423,936 ----a-w c:\windows\system32\licdll.dll
- 2004-08-10 19:00:00 58,880 ----a-w c:\windows\system32\licwmi.dll
+ 2008-04-14 00:11:56 58,880 ----a-w c:\windows\system32\licwmi.dll
- 2005-09-01 01:41:53 19,968 ----a-w c:\windows\system32\linkinfo.dll
+ 2008-04-14 00:11:56 19,968 ----a-w c:\windows\system32\linkinfo.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\lmhsvc.dll
+ 2008-04-14 00:11:56 13,824 ----a-w c:\windows\system32\lmhsvc.dll
+ 2008-05-28 16:32:54 87,352 ----a-w c:\windows\system32\LMIinit.dll
+ 2008-05-28 16:32:56 23,736 ----a-w c:\windows\system32\lmimirr.dll
+ 2008-05-28 16:32:58 10,040 ----a-w c:\windows\system32\lmimirr2.dll
+ 2008-05-28 16:33:00 24,608 ----a-w c:\windows\system32\LMIport.dll
+ 2008-05-28 16:33:14 83,288 ----a-w c:\windows\system32\LMIRfsClientNP.dll
- 2004-08-10 19:00:00 399,872 ----a-w c:\windows\system32\lmrt.dll
+ 2008-04-14 00:11:56 399,872 ----a-w c:\windows\system32\lmrt.dll
- 2004-08-10 19:00:00 97,280 ----a-w c:\windows\system32\loadperf.dll
+ 2008-04-14 00:11:56 97,280 ----a-w c:\windows\system32\loadperf.dll
- 2004-08-10 19:00:00 221,696 ----a-w c:\windows\system32\localsec.dll
+ 2008-04-14 00:11:56 221,696 ----a-w c:\windows\system32\localsec.dll
- 2004-08-10 19:00:00 341,504 ----a-w c:\windows\system32\localspl.dll
+ 2008-04-14 00:11:56 343,040 ----a-w c:\windows\system32\localspl.dll
- 2004-08-10 19:00:00 11,776 ----a-w c:\windows\system32\localui.dll
+ 2008-04-14 00:11:56 11,776 ----a-w c:\windows\system32\localui.dll
- 2004-08-10 19:00:00 75,264 ----a-w c:\windows\system32\locator.exe
+ 2008-04-14 00:12:24 75,264 ----a-w c:\windows\system32\locator.exe
- 2006-10-19 00:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
- 2004-08-10 19:00:00 59,392 ----a-w c:\windows\system32\logman.exe
+ 2008-04-14 00:12:24 59,392 ----a-w c:\windows\system32\logman.exe
- 2004-08-10 19:00:00 220,672 ----a-w c:\windows\system32\logon.scr
+ 2008-04-14 00:12:43 220,672 ----a-w c:\windows\system32\logon.scr
- 2004-08-10 19:00:00 514,560 ----a-w c:\windows\system32\logonui.exe
+ 2008-04-14 00:12:24 514,560 ----a-w c:\windows\system32\logonui.exe
- 2004-08-10 19:00:00 22,016 ----a-w c:\windows\system32\lpk.dll
+ 2008-04-14 00:11:56 22,016 ----a-w c:\windows\system32\lpk.dll
- 2004-08-10 19:00:00 10,240 ----a-w c:\windows\system32\lprhelp.dll
+ 2008-04-14 00:11:56 10,240 ----a-w c:\windows\system32\lprhelp.dll
- 2007-11-07 09:26:56 721,920 ----a-w c:\windows\system32\lsasrv.dll
+ 2008-04-14 00:11:56 728,064 ----a-w c:\windows\system32\lsasrv.dll
- 2004-08-10 19:00:00 13,312 ----a-w c:\windows\system32\lsass.exe
+ 2008-04-14 00:12:24 13,312 ----a-w c:\windows\system32\lsass.exe
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
- 2008-03-25 03:21:18 2,889,088 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 03:21:20 218,496 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-05 03:24:04 235,936 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2008-06-08 14:01:47 74,137 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-12-25 00:57:22 88,590 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-06-19 03:37:20 70,264 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-11-07 20:37:52 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2004-08-10 19:00:00 72,704 ----a-w c:\windows\system32\magnify.exe
+ 2008-04-14 00:12:24 72,704 ----a-w c:\windows\system32\magnify.exe
- 2004-08-10 19:00:00 85,504 ----a-w c:\windows\system32\makecab.exe
+ 2008-04-14 00:12:25 57,344 ----a-w c:\windows\system32\makecab.exe
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\mcastmib.dll
+ 2008-04-14 00:11:56 14,336 ----a-w c:\windows\system32\mcastmib.dll
- 2004-08-10 19:00:00 84,480 ----a-w c:\windows\system32\mciavi32.dll
+ 2008-04-14 00:11:56 84,480 ----a-w c:\windows\system32\mciavi32.dll
- 2004-08-10 19:00:00 35,328 ----a-w c:\windows\system32\mciqtz32.dll
+ 2008-04-14 00:11:56 35,328 ----a-w c:\windows\system32\mciqtz32.dll
- 2004-08-10 19:00:00 23,040 ----a-w c:\windows\system32\mciseq.dll
+ 2008-04-14 00:11:56 23,040 ----a-w c:\windows\system32\mciseq.dll
- 2004-08-10 19:00:00 23,552 ----a-w c:\windows\system32\mciwave.dll
+ 2008-04-14 00:11:56 23,552 ----a-w c:\windows\system32\mciwave.dll
+ 2005-06-20 14:12:00 284,240 ----a-w c:\windows\system32\MCPrintX.dll
+ 2005-03-24 15:17:02 153,168 ----a-w c:\windows\system32\MCScripX.dll
- 2004-08-10 19:00:00 118,272 ----a-w c:\windows\system32\mdminst.dll
+ 2008-04-14 00:11:56 118,272 ----a-w c:\windows\system32\mdminst.dll
+ 2008-04-14 00:11:56 86,016 ------w c:\windows\system32\mdmxsdk.dll
- 2007-03-08 15:36:28 40,960 ----a-w c:\windows\system32\mf3216.dll
+ 2008-04-14 00:11:56 40,960 ----a-w c:\windows\system32\mf3216.dll
- 2006-11-01 19:17:45 927,504 ----a-w c:\windows\system32\mfc40u.dll
+ 2008-04-14 00:11:56 927,504 ----a-w c:\windows\system32\mfc40u.dll
- 2004-08-10 19:00:00 1,028,096 ----a-w c:\windows\system32\mfc42.dll
+ 2008-04-14 00:11:56 1,028,096 ----a-w c:\windows\system32\mfc42.dll
+ 2007-08-28 16:00:00 1,101,824 ----a-w c:\windows\system32\mfc80.dll
- 2004-08-10 19:00:00 22,528 ----a-w c:\windows\system32\mfcsubs.dll
+ 2008-04-14 00:11:56 22,528 ----a-w c:\windows\system32\mfcsubs.dll
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\mgmtapi.dll
+ 2008-04-14 00:11:56 14,848 ----a-w c:\windows\system32\mgmtapi.dll
+ 2008-04-14 00:11:57 184,320 ------w c:\windows\system32\microsoft.managementconsole.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\midimap.dll
+ 2008-04-14 00:11:57 18,944 ----a-w c:\windows\system32\midimap.dll
- 2004-08-10 19:00:00 60,928 ----a-w c:\windows\system32\miglibnt.dll
+ 2008-04-14 00:11:57 60,928 ----a-w c:\windows\system32\miglibnt.dll
+ 2007-10-09 17:03:14 1,986,072 ----a-w c:\windows\system32\milcore.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\mimefilt.dll
+ 2008-04-14 00:11:57 29,696 ----a-w c:\windows\system32\mimefilt.dll
- 2004-08-10 19:00:00 586,240 ----a-w c:\windows\system32\mlang.dll
+ 2008-04-14 00:11:57 586,240 ----a-w c:\windows\system32\mlang.dll
- 2004-08-10 19:00:00 815,104 ----a-w c:\windows\system32\mmc.exe
+ 2008-04-14 00:12:25 1,414,656 ----a-w c:\windows\system32\mmc.exe
- 2004-08-10 19:00:00 70,656 ----a-w c:\windows\system32\mmcbase.dll
+ 2008-04-14 00:11:57 163,328 ----a-w c:\windows\system32\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 ------w c:\windows\system32\mmcex.dll
+ 2008-04-14 00:11:57 106,496 ------w c:\windows\system32\mmcfxcommon.dll
- 2004-08-10 19:00:00 1,192,960 ----a-w c:\windows\system32\mmcndmgr.dll
+ 2008-04-14 00:11:57 1,872,896 ----a-w c:\windows\system32\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 ------w c:\windows\system32\mmcperf.exe
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\system32\mmcshext.dll
+ 2008-04-14 00:11:57 61,440 ----a-w c:\windows\system32\mmcshext.dll
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\mmfutil.dll
+ 2008-04-14 00:11:57 17,408 ----a-w c:\windows\system32\mmfutil.dll
- 2004-08-10 19:00:00 34,560 ----a-w c:\windows\system32\mnmdd.dll
+ 2008-04-14 00:11:57 34,560 ----a-w c:\windows\system32\mnmdd.dll
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\mnmsrvc.exe
+ 2008-04-14 00:12:25 32,768 ----a-w c:\windows\system32\mnmsrvc.exe
- 2004-08-10 19:00:00 207,360 ----a-w c:\windows\system32\mobsync.dll
+ 2008-04-14 00:11:57 207,360 ----a-w c:\windows\system32\mobsync.dll
- 2004-08-10 19:00:00 143,360 ----a-w c:\windows\system32\mobsync.exe
+ 2008-04-14 00:12:26 143,360 ----a-w c:\windows\system32\mobsync.exe
- 2004-08-10 19:00:00 153,600 ----a-w c:\windows\system32\modemui.dll
+ 2008-04-14 00:11:57 153,600 ----a-w c:\windows\system32\modemui.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\more.com
+ 2008-04-14 00:12:42 16,896 ----a-w c:\windows\system32\more.com
- 2004-08-10 19:00:00 216,064 ----a-w c:\windows\system32\moricons.dll
+ 2008-04-13 16:45:30 216,064 ----a-w c:\windows\system32\moricons.dll
- 2004-08-10 19:00:00 123,392 ----a-w c:\windows\system32\mplay32.exe
+ 2008-04-14 00:12:27 123,392 ----a-w c:\windows\system32\mplay32.exe
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\mpr.dll
+ 2008-04-14 00:11:57 59,904 ----a-w c:\windows\system32\mpr.dll
- 2004-08-10 19:00:00 87,040 ----a-w c:\windows\system32\mprapi.dll
+ 2008-04-14 00:11:57 87,040 ----a-w c:\windows\system32\mprapi.dll
- 2004-08-10 19:00:00 49,152 ----a-w c:\windows\system32\mprdim.dll
+ 2008-04-14 00:11:57 53,248 ----a-w c:\windows\system32\mprdim.dll
- 2007-07-06 12:46:59 138,240 ----a-w c:\windows\system32\mqad.dll
+ 2008-04-14 00:11:57 138,240 ----a-w c:\windows\system32\mqad.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\mqbkup.exe
+ 2008-04-14 00:12:27 19,968 ----a-w c:\windows\system32\mqbkup.exe
- 2007-07-06 12:46:59 47,104 ----a-w c:\windows\system32\mqdscli.dll
+ 2008-04-14 00:11:57 47,616 ----a-w c:\windows\system32\mqdscli.dll
- 2007-07-06 12:46:59 16,896 ----a-w c:\windows\system32\mqise.dll
+ 2008-04-14 00:11:57 16,896 ----a-w c:\windows\system32\mqise.dll
- 2004-08-10 19:00:00 89,088 ----a-w c:\windows\system32\mqlogmgr.dll
+ 2008-04-14 00:11:57 89,088 ----a-w c:\windows\system32\mqlogmgr.dll
- 2004-08-10 19:00:00 225,280 ----a-w c:\windows\system32\mqoa.dll
+ 2008-04-14 00:11:57 225,280 ----a-w c:\windows\system32\mqoa.dll
- 2007-07-06 12:46:59 660,992 ----a-w c:\windows\system32\mqqm.dll
+ 2008-04-14 00:11:57 663,040 ----a-w c:\windows\system32\mqqm.dll
- 2007-07-06 12:46:59 177,152 ----a-w c:\windows\system32\mqrt.dll
+ 2008-04-14 00:11:57 177,152 ----a-w c:\windows\system32\mqrt.dll
- 2004-08-10 19:00:00 123,392 ----a-w c:\windows\system32\mqrtdep.dll
+ 2008-04-14 00:11:57 123,904 ----a-w c:\windows\system32\mqrtdep.dll
- 2007-07-06 12:46:59 95,744 ----a-w c:\windows\system32\mqsec.dll
+ 2008-04-14 00:11:57 95,744 ----a-w c:\windows\system32\mqsec.dll
- 2004-08-10 19:00:00 517,632 ----a-w c:\windows\system32\mqsnap.dll
+ 2008-04-14 00:11:58 517,632 ----a-w c:\windows\system32\mqsnap.dll
- 2004-08-10 19:00:00 4,608 ----a-w c:\windows\system32\mqsvc.exe
+ 2008-04-14 00:12:27 4,608 ----a-w c:\windows\system32\mqsvc.exe
- 2004-08-10 19:00:00 117,248 ----a-w c:\windows\system32\mqtgsvc.exe
+ 2008-04-14 00:12:27 117,248 ----a-w c:\windows\system32\mqtgsvc.exe
- 2004-08-10 19:00:00 186,880 ----a-w c:\windows\system32\mqtrig.dll
+ 2008-04-14 00:11:58 187,392 ----a-w c:\windows\system32\mqtrig.dll
- 2007-07-06 12:46:59 48,640 ----a-w c:\windows\system32\mqupgrd.dll
+ 2008-04-14 00:11:58 49,152 ----a-w c:\windows\system32\mqupgrd.dll
- 2007-07-06 12:46:59 471,552 ----a-w c:\windows\system32\mqutil.dll
+ 2008-04-14 00:11:58 471,552 ----a-w c:\windows\system32\mqutil.dll
- 2008-06-25 16:15:46 17,972,344 ----a-w c:\windows\system32\MRT.exe
+ 2008-12-09 20:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2004-08-10 19:00:00 71,680 ----a-w c:\windows\system32\msacm32.dll
+ 2008-04-14 00:11:58 71,680 ----a-w c:\windows\system32\msacm32.dll
- 2004-08-10 19:00:00 3,584 ----a-w c:\windows\system32\msafd.dll
+ 2008-04-14 00:10:06 3,584 ----a-w c:\windows\system32\msafd.dll
- 2004-08-10 19:00:00 86,016 ----a-w c:\windows\system32\msapsspc.dll
+ 2008-04-14 00:11:58 86,016 ----a-w c:\windows\system32\msapsspc.dll
- 2004-08-10 19:00:00 57,344 ----a-w c:\windows\system32\msasn1.dll
+ 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\msasn1.dll
+ 1998-07-06 06:00:00 64,512 ----a-w c:\windows\system32\MSCC2DE.DLL
+ 1998-07-06 06:00:00 158,208 ----a-w c:\windows\system32\MSCMCDE.DLL
- 2005-06-29 01:46:00 74,240 ----a-w c:\windows\system32\mscms.dll
+ 2008-06-24 16:43:16 74,240 ----a-w c:\windows\system32\mscms.dll
- 2004-08-10 19:00:00 69,632 ----a-w c:\windows\system32\msconf.dll
+ 2008-04-14 00:11:58 69,632 ----a-w c:\windows\system32\msconf.dll
- 2006-12-22 16:28:14 271,360 ----a-w c:\windows\system32\mscoree.dll
+ 2007-10-24 05:47:38 282,112 ----a-w c:\windows\system32\mscoree.dll
- 2004-07-15 14:34:06 16,896 ----a-w c:\windows\system32\mscorier.dll
+ 2007-10-24 05:47:38 158,720 ----a-w c:\windows\system32\mscorier.dll
- 2003-02-21 10:09:14 106,496 ----a-w c:\windows\system32\mscories.dll
+ 2007-10-24 05:47:38 84,480 ----a-w c:\windows\system32\mscories.dll
- 2004-08-10 19:00:00 12,288 ----a-w c:\windows\system32\mscpx32r.dLL
+ 2008-04-13 17:26:07 12,288 ----a-w c:\windows\system32\mscpx32r.dll
- 2004-08-10 19:00:00 36,864 ----a-w c:\windows\system32\mscpxl32.dLL
+ 2008-04-14 00:11:58 36,864 ----a-w c:\windows\system32\mscpxl32.dll
- 2008-02-26 11:59:50 294,912 ----a-w c:\windows\system32\msctf.dll
+ 2008-04-14 00:11:58 297,984 ----a-w c:\windows\system32\msctf.dll
- 2004-08-10 19:00:00 69,120 ----a-w c:\windows\system32\MSCTFP.dll
+ 2008-04-14 00:11:58 68,608 ----a-w c:\windows\system32\msctfp.dll
- 2004-08-10 19:00:00 118,784 ----a-w c:\windows\system32\msdadiag.dll
+ 2008-04-14 00:11:58 118,784 ----a-w c:\windows\system32\msdadiag.dll
- 2004-08-10 19:00:00 151,552 ----a-w c:\windows\system32\msdart.dll
+ 2008-04-14 00:11:59 151,552 ----a-w c:\windows\system32\msdart.dll
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\msdmo.dll
+ 2008-04-14 00:11:59 14,336 ----a-w c:\windows\system32\msdmo.dll
- 2004-08-10 19:00:00 6,144 ----a-w c:\windows\system32\msdtc.exe
+ 2008-04-14 00:12:27 6,144 ----a-w c:\windows\system32\msdtc.exe
- 2004-08-10 19:00:00 58,880 ----a-w c:\windows\system32\msdtclog.dll
+ 2008-04-14 00:11:59 58,880 ----a-w c:\windows\system32\msdtclog.dll
- 2006-03-01 19:42:42 426,496 ----a-w c:\windows\system32\msdtcprx.dll
+ 2008-04-14 00:11:59 427,008 ----a-w c:\windows\system32\msdtcprx.dll
- 2006-03-01 19:42:42 956,416 ----a-w c:\windows\system32\msdtctm.dll
+ 2008-04-14 00:11:59 956,928 ----a-w c:\windows\system32\msdtctm.dll
- 2006-03-01 19:42:42 161,280 ----a-w c:\windows\system32\msdtcuiu.dll
+ 2008-04-14 00:11:59 161,792 ----a-w c:\windows\system32\msdtcuiu.dll
- 2004-08-10 19:00:00 4,126 ----a-w c:\windows\system32\msdxmlc.dll
+ 2008-04-14 00:10:08 4,126 ----a-w c:\windows\system32\msdxmlc.dll
- 2008-04-23 04:16:28 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-04-23 04:16:28 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2006-11-27 14:54:06 539,136 ----a-w c:\windows\system32\msftedit.dll
+ 2008-04-14 00:11:59 539,136 ----a-w c:\windows\system32\msftedit.dll
- 2004-08-10 19:00:00 994,304 ----a-w c:\windows\system32\msgina.dll
+ 2008-04-14 00:11:59 997,376 ----a-w c:\windows\system32\msgina.dll
- 2004-08-10 19:00:00 33,792 ----a-w c:\windows\system32\msgsvc.dll
+ 2008-04-14 00:11:59 33,792 ----a-w c:\windows\system32\msgsvc.dll
- 2004-08-10 19:00:00 188,416 ----a-w c:\windows\system32\msh261.drv
+ 2008-04-14 00:12:45 188,416 ----a-w c:\windows\system32\msh261.drv
- 2004-08-04 00:56:58 294,912 ----a-w c:\windows\system32\msh263.drv
+ 2008-04-14 00:12:45 294,912 ----a-w c:\windows\system32\msh263.drv
- 2008-04-24 02:16:30 3,591,680 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-04-23 04:16:28 478,208 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2007-04-18 16:12:23 2,854,400 ----a-w c:\windows\system32\msi.dll
+ 2008-04-14 00:11:59 2,843,136 ----a-w c:\windows\system32\msi.dll
- 2004-08-10 19:00:00 51,712 ----a-w c:\windows\system32\msident.dll
+ 2008-04-14 00:11:59 51,712 ----a-w c:\windows\system32\msident.dll
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\msidle.dll
+ 2008-04-14 00:11:59 6,656 ----a-w c:\windows\system32\msidle.dll
- 2004-08-10 19:00:00 248,832 ----a-w c:\windows\system32\msieftp.dll
+ 2008-04-14 00:11:59 248,832 ----a-w c:\windows\system32\msieftp.dll
- 2005-05-04 19:45:36 78,848 ----a-w c:\windows\system32\msiexec.exe
+ 2008-04-14 00:12:28 78,848 ----a-w c:\windows\system32\msiexec.exe
- 2005-05-04 19:45:36 271,360 ----a-w c:\windows\system32\msihnd.dll
+ 2008-04-14 00:11:59 271,360 ----a-w c:\windows\system32\msihnd.dll
- 2004-08-10 19:00:00 4,608 ----a-w c:\windows\system32\msimg32.dll
+ 2008-04-14 00:11:59 4,608 ----a-w c:\windows\system32\msimg32.dll
- 2005-05-04 19:45:36 884,736 ----a-w c:\windows\system32\msimsg.dll
+ 2008-04-13 15:39:43 884,736 ----a-w c:\windows\system32\msimsg.dll
- 2004-08-10 19:00:00 159,232 ----a-w c:\windows\system32\MSIMTF.dll
+ 2008-04-14 00:11:59 159,232 ----a-w c:\windows\system32\msimtf.dll
- 2005-05-04 19:45:36 15,360 ----a-w c:\windows\system32\msisip.dll
+ 2008-04-14 00:11:59 15,360 ----a-w c:\windows\system32\msisip.dll
- 2008-03-27 08:12:54 151,583 ----a-w c:\windows\system32\msjint40.dll
+ 2008-04-14 00:12:00 151,583 ----a-w c:\windows\system32\msjint40.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\mslbui.dll
+ 2008-04-14 00:12:00 25,088 ----a-w c:\windows\system32\mslbui.dll
- 2004-08-10 19:00:00 290,816 ----a-w c:\windows\system32\msnsspc.dll
+ 2008-04-14 00:12:00 290,816 ----a-w c:\windows\system32\msnsspc.dll
- 2004-08-10 19:00:00 252,928 ----a-w c:\windows\system32\msoeacct.dll
+ 2008-04-14 00:12:00 252,928 ----a-w c:\windows\system32\msoeacct.dll
- 2004-08-10 19:00:00 105,984 ----a-w c:\windows\system32\msoert2.dll
+ 2008-04-14 00:12:00 105,984 ----a-w c:\windows\system32\msoert2.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\msorc32r.dll
+ 2008-04-13 17:24:14 20,480 ----a-w c:\windows\system32\msorc32r.dll
- 2004-08-10 19:00:00 143,360 ----a-w c:\windows\system32\msorcl32.dll
+ 2008-04-14 00:12:00 143,360 ----a-w c:\windows\system32\msorcl32.dll
- 2004-08-10 19:00:00 343,040 ----a-w c:\windows\system32\mspaint.exe
+ 2008-04-14 00:12:28 343,040 ----a-w c:\windows\system32\mspaint.exe
- 2004-08-10 19:00:00 30,208 ----a-w c:\windows\system32\mspatcha.dll
+ 2008-04-14 00:12:00 29,696 ----a-w c:\windows\system32\mspatcha.dll
- 2004-08-10 19:00:00 48,128 ----a-w c:\windows\system32\msprivs.dll
+ 2008-04-13 16:23:31 48,128 ----a-w c:\windows\system32\msprivs.dll
- 2008-04-23 04:16:28 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\msrle32.dll
+ 2008-04-14 00:12:00 11,264 ----a-w c:\windows\system32\msrle32.dll
- 2004-08-10 19:00:00 134,656 ----a-w c:\windows\system32\mssap.dll
+ 2008-04-14 00:12:00 134,656 ----a-w c:\windows\system32\mssap.dll
+ 2008-04-14 00:12:00 155,136 ------w c:\windows\system32\mssha.dll
+ 2008-04-13 18:14:58 76,800 ------w c:\windows\system32\msshavmsg.dll
+ 2005-08-25 23:18:16 118,784 ----a-w c:\windows\system32\MSSTDFMT.DLL
- 2004-08-10 19:00:00 274,944 ----a-w c:\windows\system32\mstask.dll
+ 2008-04-14 00:12:00 274,944 ----a-w c:\windows\system32\mstask.dll
- 2008-04-23 04:16:28 671,232 ------w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 ------w c:\windows\system32\mstime.dll
- 2004-08-10 19:00:00 12,288 ----a-w c:\windows\system32\mstinit.exe
+ 2008-04-14 00:12:29 12,288 ----a-w c:\windows\system32\mstinit.exe
- 2004-08-10 19:00:00 115,712 ----a-w c:\windows\system32\mstlsapi.dll
+ 2008-04-14 00:12:00 116,224 ----a-w c:\windows\system32\mstlsapi.dll
- 2004-08-10 19:00:00 407,552 ----a-w c:\windows\system32\mstsc.exe
+ 2008-04-14 00:12:23 677,888 ----a-w c:\windows\system32\mstsc.exe
- 2004-08-10 19:00:00 655,360 ----a-w c:\windows\system32\mstscax.dll
+ 2008-04-14 00:11:56 2,061,824 ----a-w c:\windows\system32\mstscax.dll
- 2004-08-10 19:00:00 195,072 ----a-w c:\windows\system32\msutb.dll
+ 2008-04-14 00:12:00 195,072 ----a-w c:\windows\system32\msutb.dll
- 2004-08-10 19:00:00 129,536 ----a-w c:\windows\system32\msv1_0.dll
+ 2008-04-14 00:12:00 132,608 ----a-w c:\windows\system32\msv1_0.dll
- 2004-08-10 19:00:00 1,392,671 ----a-w c:\windows\system32\msvbvm60.dll
+ 2008-04-14 00:12:00 1,384,479 ----a-w c:\windows\system32\msvbvm60.dll
- 2004-08-10 19:00:00 54,784 ----a-w c:\windows\system32\msvcirt.dll
+ 2008-04-14 00:12:01 57,344 ----a-w c:\windows\system32\msvcirt.dll
- 2004-08-10 19:00:00 413,696 ----a-w c:\windows\system32\msvcp60.dll
+ 2008-04-14 00:12:01 413,696 ----a-w c:\windows\system32\msvcp60.dll
+ 2007-08-28 16:00:00 548,864 ----a-w c:\windows\system32\msvcp80.dll
+ 2007-08-28 16:00:00 626,688 ----a-w c:\windows\system32\msvcr80.dll
- 2004-08-10 19:00:00 343,040 ----a-w c:\windows\system32\msvcrt.dll
+ 2008-04-14 00:12:01 343,040 ----a-w c:\windows\system32\msvcrt.dll
- 2004-08-10 19:00:00 61,440 ----a-w c:\windows\system32\msvcrt40.dll
+ 2008-04-13 18:30:46 61,440 ----a-w c:\windows\system32\msvcrt40.dll
- 2004-08-10 19:00:00 120,832 ----a-w c:\windows\system32\msvfw32.dll
+ 2008-04-14 00:12:01 121,344 ----a-w c:\windows\system32\msvfw32.dll
- 2004-08-10 19:00:00 72,704 ----a-w c:\windows\system32\msw3prt.dll
+ 2008-04-14 00:12:01 72,704 ----a-w c:\windows\system32\msw3prt.dll
- 2004-08-10 19:00:00 204,288 ----a-w c:\windows\system32\mswebdvd.dll
+ 2008-04-14 00:12:01 203,776 ----a-w c:\windows\system32\mswebdvd.dll
- 2008-06-20 17:41:10 245,248 ----a-w c:\windows\system32\mswsock.dll
+ 2008-06-20 17:46:57 245,248 ----a-w c:\windows\system32\mswsock.dll
- 2004-08-10 19:00:00 506,368 ----a-w c:\windows\system32\msxml.dll
+ 2008-04-14 00:12:01 506,368 ----a-w c:\windows\system32\msxml.dll
- 2004-08-10 19:00:00 701,440 ----a-w c:\windows\system32\msxml2.dll
+ 2008-04-14 00:12:01 701,440 ----a-w c:\windows\system32\msxml2.dll
- 2007-06-26 06:08:16 1,104,896 ----a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 ----a-w c:\windows\system32\msxml3.dll
- 2008-06-25 11:26:38 29,480 ----a-w c:\windows\system32\msxml3a.dll
+ 2008-07-27 00:42:40 29,480 ----a-w c:\windows\system32\msxml3a.dll
+ 2008-09-30 21:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
+ 2003-04-18 20:29:26 82,432 ----a-w c:\windows\system32\msxml4r.dll
+ 2008-09-10 01:14:56 1,307,648 ----a-w c:\windows\system32\msxml6.dll
+ 2008-04-13 17:27:18 79,872 ------w c:\windows\system32\msxml6r.dll
- 2004-08-04 00:56:46 17,408 ----a-w c:\windows\system32\msyuv.dll
+ 2008-04-14 00:12:01 16,896 ----a-w c:\windows\system32\msyuv.dll
- 2006-03-01 19:42:42 66,560 ----a-w c:\windows\system32\mtxclu.dll
+ 2008-04-14 00:12:01 66,560 ----a-w c:\windows\system32\mtxclu.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\mtxdm.dll
+ 2008-04-14 00:12:01 30,720 ----a-w c:\windows\system32\mtxdm.dll
- 2004-08-10 19:00:00 4,096 ----a-w c:\windows\system32\mtxex.dll
+ 2008-04-14 00:12:01 4,096 ----a-w c:\windows\system32\mtxex.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\mtxlegih.dll
+ 2008-04-14 00:12:01 34,304 ----a-w c:\windows\system32\mtxlegih.dll
- 2006-03-01 19:42:42 91,136 ----a-w c:\windows\system32\mtxoci.dll
+ 2008-04-14 00:12:01 91,648 ----a-w c:\windows\system32\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 ------w c:\windows\system32\mtxparhd.dll
+ 2008-10-16 19:06:48 268,648 ----a-w c:\windows\system32\mucltui.dll
- 2004-08-10 19:00:00 393,728 ----a-w c:\windows\system32\mui\0401\xpob2res.dll
+ 2008-04-13 18:40:07 393,728 -c--a-w c:\windows\system32\mui\0401\xpob2res.dll
- 2004-08-10 19:00:00 186,880 ----a-w c:\windows\system32\mui\0401\xpsp1res.dll
+ 2008-04-13 18:35:06 186,880 -c--a-w c:\windows\system32\mui\0401\xpsp1res.dll
- 2004-08-10 19:00:00 2,869,248 ----a-w c:\windows\system32\mui\0401\xpsp2res.dll
+ 2008-04-13 18:35:49 2,869,248 -c--a-w c:\windows\system32\mui\0401\xpsp2res.dll
+ 2008-04-13 18:39:02 656,896 -c----w c:\windows\system32\mui\0401\xpsp3res.dll
- 2004-08-10 19:00:00 189,440 ----a-w c:\windows\system32\mui\0402\xpsp1res.dll
+ 2008-04-13 18:35:08 189,440 -c--a-w c:\windows\system32\mui\0402\xpsp1res.dll
- 2004-08-10 19:00:00 212,480 ----a-w c:\windows\system32\mui\0404\xpob2res.dll
+ 2008-04-13 18:40:23 212,480 -c--a-w c:\windows\system32\mui\0404\xpob2res.dll
- 2004-08-10 19:00:00 161,280 ----a-w c:\windows\system32\mui\0404\xpsp1res.dll
+ 2008-04-13 18:35:09 161,280 -c--a-w c:\windows\system32\mui\0404\xpsp1res.dll
- 2004-08-10 19:00:00 477,696 ----a-w c:\windows\system32\mui\0404\xpsp2res.dll
+ 2008-04-13 18:36:10 477,696 -c--a-w c:\windows\system32\mui\0404\xpsp2res.dll
+ 2008-04-13 18:39:13 327,680 -c----w c:\windows\system32\mui\0404\xpsp3res.dll
- 2004-08-10 19:00:00 428,032 ----a-w c:\windows\system32\mui\0405\xpob2res.dll
+ 2008-04-13 18:40:24 428,032 -c--a-w c:\windows\system32\mui\0405\xpob2res.dll
- 2004-08-10 19:00:00 188,928 ----a-w c:\windows\system32\mui\0405\xpsp1res.dll
+ 2008-04-13 18:35:09 188,928 -c--a-w c:\windows\system32\mui\0405\xpsp1res.dll
- 2004-08-10 19:00:00 734,720 ----a-w c:\windows\system32\mui\0405\xpsp2res.dll
+ 2008-04-13 18:36:10 734,720 -c--a-w c:\windows\system32\mui\0405\xpsp2res.dll
+ 2008-04-13 18:39:02 601,088 -c----w c:\windows\system32\mui\0405\xpsp3res.dll
- 2004-08-10 19:00:00 418,816 ----a-w c:\windows\system32\mui\0406\xpob2res.dll
+ 2008-04-13 18:40:27 418,816 -c--a-w c:\windows\system32\mui\0406\xpob2res.dll
- 2004-08-10 19:00:00 192,512 ----a-w c:\windows\system32\mui\0406\xpsp1res.dll
+ 2008-04-13 18:35:09 192,000 -c--a-w c:\windows\system32\mui\0406\xpsp1res.dll
- 2004-08-10 19:00:00 742,912 ----a-w c:\windows\system32\mui\0406\xpsp2res.dll
+ 2008-04-13 18:36:10 742,912 -c--a-w c:\windows\system32\mui\0406\xpsp2res.dll
+ 2008-04-13 18:39:12 605,696 -c----w c:\windows\system32\mui\0406\xpsp3res.dll
- 2004-08-10 19:00:00 403,456 ----a-w c:\windows\system32\mui\0407\xpob2res.dll
+ 2008-04-13 18:40:34 403,456 -c--a-w c:\windows\system32\mui\0407\xpob2res.dll
- 2004-08-10 19:00:00 199,680 ----a-w c:\windows\system32\mui\0407\xpsp1res.dll
+ 2008-04-13 18:35:21 199,680 -c--a-w c:\windows\system32\mui\0407\xpsp1res.dll
- 2004-08-10 19:00:00 788,992 ----a-w c:\windows\system32\mui\0407\xpsp2res.dll
+ 2008-04-13 18:37:03 788,480 -c--a-w c:\windows\system32\mui\0407\xpsp2res.dll
+ 2008-04-13 18:39:19 663,552 -c----w c:\windows\system32\mui\0407\xpsp3res.dll
- 2004-08-10 19:00:00 419,328 ----a-w c:\windows\system32\mui\0408\xpob2res.dll
+ 2008-04-13 18:40:30 419,328 -c--a-w c:\windows\system32\mui\0408\xpob2res.dll
- 2004-08-10 19:00:00 197,632 ----a-w c:\windows\system32\mui\0408\xpsp1res.dll
+ 2008-04-13 18:35:11 197,632 -c--a-w c:\windows\system32\mui\0408\xpsp1res.dll
- 2004-08-10 19:00:00 801,280 ----a-w c:\windows\system32\mui\0408\xpsp2res.dll
+ 2008-04-13 18:36:35 801,280 -c--a-w c:\windows\system32\mui\0408\xpsp2res.dll
+ 2008-04-13 18:39:12 679,936 -c----w c:\windows\system32\mui\0408\xpsp3res.dll
- 2006-12-22 17:02:36 6,144 ----a-w c:\windows\system32\mui\0409\mscorees.dll
+ 2007-10-24 05:47:44 15,360 -c--a-w c:\windows\system32\mui\0409\mscorees.dll
- 2004-08-10 19:00:00 405,504 ----a-w c:\windows\system32\mui\040b\xpob2res.dll
+ 2008-04-13 18:40:32 405,504 -c--a-w c:\windows\system32\mui\040b\xpob2res.dll
- 2004-08-10 19:00:00 186,368 ----a-w c:\windows\system32\mui\040b\xpsp1res.dll
+ 2008-04-13 18:35:11 186,368 -c--a-w c:\windows\system32\mui\040b\xpsp1res.dll
- 2004-08-10 19:00:00 729,088 ----a-w c:\windows\system32\mui\040b\xpsp2res.dll
+ 2008-04-13 18:36:39 729,088 -c--a-w c:\windows\system32\mui\040b\xpsp2res.dll
+ 2008-04-13 18:39:17 604,672 -c----w c:\windows\system32\mui\040b\xpsp3res.dll
- 2004-08-10 19:00:00 410,624 ----a-w c:\windows\system32\mui\040C\xpob2res.dll
+ 2008-04-13 18:40:33 410,624 -c--a-w c:\windows\system32\mui\040C\xpob2res.dll
- 2004-08-10 19:00:00 197,632 ----a-w c:\windows\system32\mui\040C\xpsp1res.dll
+ 2008-04-13 18:35:20 197,632 -c--a-w c:\windows\system32\mui\040C\xpsp1res.dll
- 2004-08-10 19:00:00 793,600 ----a-w c:\windows\system32\mui\040C\xpsp2res.dll
+ 2008-04-13 18:36:55 793,088 -c--a-w c:\windows\system32\mui\040C\xpsp2res.dll
+ 2008-04-13 18:39:20 663,040 -c----w c:\windows\system32\mui\040C\xpsp3res.dll
- 2004-08-10 19:00:00 384,000 ----a-w c:\windows\system32\mui\040D\xpob2res.dll
+ 2008-04-13 18:40:32 384,000 -c--a-w c:\windows\system32\mui\040D\xpob2res.dll
- 2004-08-10 19:00:00 181,760 ----a-w c:\windows\system32\mui\040D\xpsp1res.dll
+ 2008-04-13 18:35:21 181,760 -c--a-w c:\windows\system32\mui\040D\xpsp1res.dll
- 2004-08-10 19:00:00 2,842,112 ----a-w c:\windows\system32\mui\040D\xpsp2res.dll
+ 2008-04-13 18:37:07 2,842,112 -c--a-w c:\windows\system32\mui\040D\xpsp2res.dll
+ 2008-04-13 18:39:28 620,544 -c----w c:\windows\system32\mui\040D\xpsp3res.dll
- 2004-08-10 19:00:00 434,176 ----a-w c:\windows\system32\mui\040e\xpob2res.dll
+ 2008-04-13 18:40:39 434,176 -c--a-w c:\windows\system32\mui\040e\xpob2res.dll
- 2004-08-10 19:00:00 195,584 ----a-w c:\windows\system32\mui\040e\xpsp1res.dll
+ 2008-04-13 18:35:23 195,584 -c--a-w c:\windows\system32\mui\040e\xpsp1res.dll
- 2004-08-10 19:00:00 769,536 ----a-w c:\windows\system32\mui\040e\xpsp2res.dll
+ 2008-04-13 18:37:22 769,536 -c--a-w c:\windows\system32\mui\040e\xpsp2res.dll
+ 2008-04-13 18:39:28 645,120 -c----w c:\windows\system32\mui\040e\xpsp3res.dll
- 2004-08-10 19:00:00 413,696 ----a-w c:\windows\system32\mui\0410\xpob2res.dll
+ 2008-04-13 18:40:39 413,696 -c--a-w c:\windows\system32\mui\0410\xpob2res.dll
- 2004-08-10 19:00:00 195,072 ----a-w c:\windows\system32\mui\0410\xpsp1res.dll
+ 2008-04-13 18:35:23 195,072 -c--a-w c:\windows\system32\mui\0410\xpsp1res.dll
- 2004-08-10 19:00:00 769,536 ----a-w c:\windows\system32\mui\0410\xpsp2res.dll
+ 2008-04-13 18:37:22 769,536 -c--a-w c:\windows\system32\mui\0410\xpsp2res.dll
+ 2008-04-13 18:39:28 658,432 -c----w c:\windows\system32\mui\0410\xpsp3res.dll
- 2004-08-10 19:00:00 275,456 ----a-w c:\windows\system32\mui\0411\xpob2res.dll
+ 2008-04-13 18:40:44 275,456 -c--a-w c:\windows\system32\mui\0411\xpob2res.dll
- 2004-08-10 19:00:00 171,008 ----a-w c:\windows\system32\mui\0411\xpsp1res.dll
+ 2008-04-13 18:35:23 171,008 -c--a-w c:\windows\system32\mui\0411\xpsp1res.dll
- 2004-08-10 19:00:00 562,688 ----a-w c:\windows\system32\mui\0411\xpsp2res.dll
+ 2008-04-13 18:37:34 562,688 -c--a-w c:\windows\system32\mui\0411\xpsp2res.dll
+ 2008-04-13 18:39:49 412,672 -c----w c:\windows\system32\mui\0411\xpsp3res.dll
- 2004-08-10 19:00:00 306,688 ----a-w c:\windows\system32\mui\0412\xpob2res.dll
+ 2008-04-13 18:40:48 306,688 -c--a-w c:\windows\system32\mui\0412\xpob2res.dll
- 2004-08-10 19:00:00 167,936 ----a-w c:\windows\system32\mui\0412\xpsp1res.dll
+ 2008-04-13 18:35:23 167,936 -c--a-w c:\windows\system32\mui\0412\xpsp1res.dll
- 2004-08-10 19:00:00 543,744 ----a-w c:\windows\system32\mui\0412\xpsp2res.dll
+ 2008-04-13 18:37:37 543,744 -c--a-w c:\windows\system32\mui\0412\xpsp2res.dll
+ 2008-04-13 18:39:49 392,704 -c----w c:\windows\system32\mui\0412\xpsp3res.dll
- 2004-08-10 19:00:00 401,920 ----a-w c:\windows\system32\mui\0413\xpob2res.dll
+ 2008-04-13 18:40:44 401,920 -c--a-w c:\windows\system32\mui\0413\xpob2res.dll
- 2004-08-10 19:00:00 196,096 ----a-w c:\windows\system32\mui\0413\xpsp1res.dll
+ 2008-04-13 18:35:25 196,096 -c--a-w c:\windows\system32\mui\0413\xpsp1res.dll
- 2004-08-10 19:00:00 769,024 ----a-w c:\windows\system32\mui\0413\xpsp2res.dll
+ 2008-04-13 18:38:00 769,024 -c--a-w c:\windows\system32\mui\0413\xpsp2res.dll
+ 2008-04-13 18:39:47 645,120 -c----w c:\windows\system32\mui\0413\xpsp3res.dll
- 2004-08-10 19:00:00 353,792 ----a-w c:\windows\system32\mui\0414\xpob2res.dll
+ 2008-04-13 18:40:44 353,792 -c--a-w c:\windows\system32\mui\0414\xpob2res.dll
- 2004-08-10 19:00:00 189,440 ----a-w c:\windows\system32\mui\0414\xpsp1res.dll
+ 2008-04-13 18:35:25 189,440 -c--a-w c:\windows\system32\mui\0414\xpsp1res.dll
- 2004-08-10 19:00:00 716,288 ----a-w c:\windows\system32\mui\0414\xpsp2res.dll
+ 2008-04-13 18:38:02 716,288 -c--a-w c:\windows\system32\mui\0414\xpsp2res.dll
+ 2008-04-13 18:39:48 591,872 -c----w c:\windows\system32\mui\0414\xpsp3res.dll
- 2004-08-10 19:00:00 391,680 ----a-w c:\windows\system32\mui\0415\xpob2res.dll
+ 2008-04-13 18:40:47 391,680 -c--a-w c:\windows\system32\mui\0415\xpob2res.dll
- 2004-08-10 19:00:00 194,560 ----a-w c:\windows\system32\mui\0415\xpsp1res.dll
+ 2008-04-13 18:35:26 194,560 -c--a-w c:\windows\system32\mui\0415\xpsp1res.dll
- 2004-08-10 19:00:00 759,808 ----a-w c:\windows\system32\mui\0415\xpsp2res.dll
+ 2008-04-13 18:38:05 759,808 -c--a-w c:\windows\system32\mui\0415\xpsp2res.dll
+ 2008-04-13 18:39:52 641,024 -c----w c:\windows\system32\mui\0415\xpsp3res.dll
- 2004-08-10 19:00:00 409,600 ----a-w c:\windows\system32\mui\0416\xpob2res.dll
+ 2008-04-13 18:40:10 409,600 -c--a-w c:\windows\system32\mui\0416\xpob2res.dll
- 2004-08-10 19:00:00 192,512 ----a-w c:\windows\system32\mui\0416\xpsp1res.dll
+ 2008-04-13 18:35:08 192,512 -c--a-w c:\windows\system32\mui\0416\xpsp1res.dll
- 2004-08-10 19:00:00 752,128 ----a-w c:\windows\system32\mui\0416\xpsp2res.dll
+ 2008-04-13 18:35:43 752,128 -c--a-w c:\windows\system32\mui\0416\xpsp2res.dll
+ 2008-04-13 18:38:56 620,032 -c----w c:\windows\system32\mui\0416\xpsp3res.dll
- 2004-08-10 19:00:00 190,464 ----a-w c:\windows\system32\mui\0418\xpsp1res.dll
+ 2008-04-13 18:35:27 190,464 -c--a-w c:\windows\system32\mui\0418\xpsp1res.dll
- 2004-08-10 19:00:00 427,008 ----a-w c:\windows\system32\mui\0419\xpob2res.dll
+ 2008-04-13 18:40:50 427,008 -c--a-w c:\windows\system32\mui\0419\xpob2res.dll
- 2004-08-10 19:00:00 192,512 ----a-w c:\windows\system32\mui\0419\xpsp1res.dll
+ 2008-04-13 18:35:27 192,512 -c--a-w c:\windows\system32\mui\0419\xpsp1res.dll
- 2004-08-10 19:00:00 736,768 ----a-w c:\windows\system32\mui\0419\xpsp2res.dll
+ 2008-04-13 18:38:28 736,768 -c--a-w c:\windows\system32\mui\0419\xpsp2res.dll
+ 2008-04-13 18:39:56 627,200 -c----w c:\windows\system32\mui\0419\xpsp3res.dll
- 2004-08-10 19:00:00 188,928 ----a-w c:\windows\system32\mui\041a\xpsp1res.dll
+ 2008-04-13 18:35:21 188,928 -c--a-w c:\windows\system32\mui\041a\xpsp1res.dll
- 2004-08-10 19:00:00 405,504 ----a-w c:\windows\system32\mui\041b\xpob2res.dll
+ 2008-04-13 18:40:52 405,504 -c--a-w c:\windows\system32\mui\041b\xpob2res.dll
- 2004-08-10 19:00:00 193,024 ----a-w c:\windows\system32\mui\041b\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\mui\041b\xpsp1res.dll
- 2004-08-10 19:00:00 757,248 ----a-w c:\windows\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:38:37 757,248 -c--a-w c:\windows\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:40:04 577,536 -c----w c:\windows\system32\mui\041b\xpsp3res.dll
- 2004-08-10 19:00:00 363,520 ----a-w c:\windows\system32\mui\041D\xpob2res.dll
+ 2008-04-13 18:40:56 363,008 -c--a-w c:\windows\system32\mui\041D\xpob2res.dll
- 2004-08-10 19:00:00 188,928 ----a-w c:\windows\system32\mui\041D\xpsp1res.dll
+ 2008-04-13 18:35:28 188,928 -c--a-w c:\windows\system32\mui\041D\xpsp1res.dll
- 2004-08-10 19:00:00 724,992 ----a-w c:\windows\system32\mui\041D\xpsp2res.dll
+ 2008-04-13 18:38:47 724,480 -c--a-w c:\windows\system32\mui\041D\xpsp2res.dll
+ 2008-04-13 18:40:05 590,848 -c----w c:\windows\system32\mui\041D\xpsp3res.dll
- 2004-08-10 19:00:00 188,416 ----a-w c:\windows\system32\mui\041e\xpsp1res.dll
+ 2008-04-13 18:35:29 188,416 -c--a-w c:\windows\system32\mui\041e\xpsp1res.dll
- 2004-08-10 19:00:00 390,144 ----a-w c:\windows\system32\mui\041f\xpob2res.dll
+ 2008-04-13 18:41:00 390,144 -c--a-w c:\windows\system32\mui\041f\xpob2res.dll
- 2004-08-10 19:00:00 188,928 ----a-w c:\windows\system32\mui\041f\xpsp1res.dll
+ 2008-04-13 18:35:30 188,928 -c--a-w c:\windows\system32\mui\041f\xpsp1res.dll
- 2004-08-10 19:00:00 724,480 ----a-w c:\windows\system32\mui\041f\xpsp2res.dll
+ 2008-04-13 18:38:51 724,480 -c--a-w c:\windows\system32\mui\041f\xpsp2res.dll
+ 2008-04-13 18:40:09 592,896 -c----w c:\windows\system32\mui\041f\xpsp3res.dll
- 2004-08-10 19:00:00 408,576 ----a-w c:\windows\system32\mui\0424\xpob2res.dll
+ 2008-04-13 18:40:56 408,576 -c--a-w c:\windows\system32\mui\0424\xpob2res.dll
- 2004-08-10 19:00:00 192,512 ----a-w c:\windows\system32\mui\0424\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 -c--a-w c:\windows\system32\mui\0424\xpsp1res.dll
- 2004-08-10 19:00:00 732,160 ----a-w c:\windows\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:38:36 732,160 -c--a-w c:\windows\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:40:05 576,512 -c----w c:\windows\system32\mui\0424\xpsp3res.dll
- 2004-08-10 19:00:00 187,392 ----a-w c:\windows\system32\mui\0425\xpsp1res.dll
+ 2008-04-13 18:35:11 186,880 -c--a-w c:\windows\system32\mui\0425\xpsp1res.dll
- 2004-08-10 19:00:00 188,928 ----a-w c:\windows\system32\mui\0426\xpsp1res.dll
+ 2008-04-13 18:35:24 188,928 -c--a-w c:\windows\system32\mui\0426\xpsp1res.dll

EasyEEE
2008-12-29, 18:15
- 2004-08-10 19:00:00 189,952 ----a-w c:\windows\system32\mui\0427\xpsp1res.dll
+ 2008-04-13 18:35:24 189,952 -c--a-w c:\windows\system32\mui\0427\xpsp1res.dll
- 2004-08-10 19:00:00 270,336 ----a-w c:\windows\system32\mui\0804\xpob2res.dll
+ 2008-04-13 18:40:24 270,336 -c--a-w c:\windows\system32\mui\0804\xpob2res.dll
- 2004-08-10 19:00:00 161,280 ----a-w c:\windows\system32\mui\0804\xpsp1res.dll
+ 2008-04-13 18:35:06 161,280 -c--a-w c:\windows\system32\mui\0804\xpsp1res.dll
- 2004-08-10 19:00:00 470,016 ----a-w c:\windows\system32\mui\0804\xpsp2res.dll
+ 2008-04-13 18:35:54 470,016 -c--a-w c:\windows\system32\mui\0804\xpsp2res.dll
+ 2008-04-13 18:39:03 322,560 -c----w c:\windows\system32\mui\0804\xpsp3res.dll
- 2004-08-10 19:00:00 435,200 ----a-w c:\windows\system32\mui\0816\xpob2res.dll
+ 2008-04-13 18:40:48 435,200 -c--a-w c:\windows\system32\mui\0816\xpob2res.dll
- 2004-08-10 19:00:00 194,560 ----a-w c:\windows\system32\mui\0816\xpsp1res.dll
+ 2008-04-13 18:35:26 194,560 -c--a-w c:\windows\system32\mui\0816\xpsp1res.dll
- 2004-08-10 19:00:00 751,616 ----a-w c:\windows\system32\mui\0816\xpsp2res.dll
+ 2008-04-13 18:38:06 751,616 -c--a-w c:\windows\system32\mui\0816\xpsp2res.dll
+ 2008-04-13 18:39:53 639,488 -c----w c:\windows\system32\mui\0816\xpsp3res.dll
- 2004-08-10 19:00:00 446,464 ----a-w c:\windows\system32\mui\0C0A\xpob2res.dll
+ 2008-04-13 18:40:30 446,464 -c--a-w c:\windows\system32\mui\0C0A\xpob2res.dll
- 2004-08-10 19:00:00 196,096 ----a-w c:\windows\system32\mui\0C0A\xpsp1res.dll
+ 2008-04-13 18:35:11 196,096 -c--a-w c:\windows\system32\mui\0C0A\xpsp1res.dll
- 2004-08-10 19:00:00 773,632 ----a-w c:\windows\system32\mui\0C0A\xpsp2res.dll
+ 2008-04-13 18:36:38 773,632 -c--a-w c:\windows\system32\mui\0C0A\xpsp2res.dll
+ 2008-04-13 18:39:13 648,704 -c----w c:\windows\system32\mui\0C0A\xpsp3res.dll
+ 2008-10-16 19:06:48 208,744 ----a-w c:\windows\system32\muweb.dll
- 2004-08-10 19:00:00 90,624 ----a-w c:\windows\system32\mydocs.dll
+ 2008-04-14 00:12:01 90,624 ----a-w c:\windows\system32\mydocs.dll
+ 2008-04-14 00:12:01 30,208 ------w c:\windows\system32\napipsec.dll
+ 2008-04-14 00:12:01 193,024 ------w c:\windows\system32\napmontr.dll
+ 2008-04-14 00:12:29 176,640 ------w c:\windows\system32\napstat.exe
- 2004-08-10 19:00:00 53,760 ----a-w c:\windows\system32\narrator.exe
+ 2008-04-14 00:12:29 53,760 ----a-w c:\windows\system32\narrator.exe
- 2004-08-10 19:00:00 36,352 ----a-w c:\windows\system32\ncobjapi.dll
+ 2008-04-14 00:12:01 36,352 ----a-w c:\windows\system32\ncobjapi.dll
- 2004-08-10 19:00:00 17,920 ----a-w c:\windows\system32\nddeapi.dll
+ 2008-04-14 00:12:01 17,920 ----a-w c:\windows\system32\nddeapi.dll
- 2004-08-10 19:00:00 4,096 ----a-w c:\windows\system32\nddeapir.exe
+ 2008-04-14 00:12:29 4,096 ----a-w c:\windows\system32\nddeapir.exe
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\nddenb32.dll
+ 2008-04-14 00:12:01 18,944 ----a-w c:\windows\system32\nddenb32.dll
- 2004-08-10 19:00:00 42,496 ----a-w c:\windows\system32\net.exe
+ 2008-04-14 00:12:29 42,496 ----a-w c:\windows\system32\net.exe
- 2004-08-10 19:00:00 124,928 ----a-w c:\windows\system32\net1.exe
+ 2008-04-14 00:12:29 124,928 ----a-w c:\windows\system32\net1.exe
- 2006-08-17 12:28:27 332,288 ----a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:34:24 337,408 ----a-w c:\windows\system32\netapi32.dll
- 2004-08-10 19:00:00 622,080 ----a-w c:\windows\system32\netcfgx.dll
+ 2008-04-14 00:12:01 622,592 ----a-w c:\windows\system32\netcfgx.dll
- 2004-08-10 19:00:00 111,104 ----a-w c:\windows\system32\netdde.exe
+ 2008-04-14 00:12:29 111,104 ----a-w c:\windows\system32\netdde.exe
- 2004-08-10 19:00:00 139,264 ----a-w c:\windows\system32\netid.dll
+ 2008-04-14 00:12:01 139,264 ----a-w c:\windows\system32\netid.dll
- 2004-08-10 19:00:00 407,040 ----a-w c:\windows\system32\netlogon.dll
+ 2008-04-14 00:12:01 407,040 ----a-w c:\windows\system32\netlogon.dll
- 2005-08-22 18:29:46 197,632 ----a-w c:\windows\system32\netman.dll
+ 2008-04-14 00:12:01 198,144 ----a-w c:\windows\system32\netman.dll
- 2004-08-10 19:00:00 875,008 ----a-w c:\windows\system32\netplwiz.dll
+ 2008-04-14 00:12:01 875,008 ----a-w c:\windows\system32\netplwiz.dll
- 2004-08-10 19:00:00 12,288 ----a-w c:\windows\system32\netrap.dll
+ 2008-04-14 00:12:01 11,776 ----a-w c:\windows\system32\netrap.dll
- 2004-08-10 19:00:00 329,728 ----a-w c:\windows\system32\netsetup.exe
+ 2008-04-14 00:16:51 329,728 ----a-w c:\windows\system32\netsetup.exe
- 2004-08-10 19:00:00 86,016 ----a-w c:\windows\system32\netsh.exe
+ 2008-04-14 00:12:29 86,016 ----a-w c:\windows\system32\netsh.exe
- 2005-06-22 05:00:18 1,705,472 ----a-w c:\windows\system32\netshell.dll
+ 2008-04-14 00:12:02 1,703,936 ----a-w c:\windows\system32\netshell.dll
- 2004-08-10 19:00:00 36,864 ----a-w c:\windows\system32\netstat.exe
+ 2008-04-14 00:12:29 36,864 ----a-w c:\windows\system32\netstat.exe
- 2004-08-10 19:00:00 80,896 ----a-w c:\windows\system32\netui0.dll
+ 2008-04-14 00:12:02 80,896 ----a-w c:\windows\system32\netui0.dll
- 2004-08-10 19:00:00 245,760 ----a-w c:\windows\system32\netui1.dll
+ 2008-04-14 00:12:02 245,760 ----a-w c:\windows\system32\netui1.dll
- 2004-08-10 19:00:00 248,832 ----a-w c:\windows\system32\newdev.dll
+ 2008-04-14 00:12:02 247,808 ----a-w c:\windows\system32\newdev.dll
- 2004-08-10 19:00:00 103,936 ----a-w c:\windows\system32\nlhtml.dll
+ 2008-04-14 00:12:02 98,304 ----a-w c:\windows\system32\nlhtml.dll
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\nmmkcert.dll
+ 2008-04-14 00:12:02 28,672 ----a-w c:\windows\system32\nmmkcert.dll
- 2004-08-10 19:00:00 69,120 ----a-w c:\windows\system32\notepad.exe
+ 2008-04-14 00:12:29 69,120 ----a-w c:\windows\system32\notepad.exe
- 2004-08-10 19:00:00 57,344 ----a-w c:\windows\system32\npp\ndisnpp.dll
+ 2008-04-14 00:12:01 57,344 -c--a-w c:\windows\system32\npp\ndisnpp.dll
- 2004-08-10 19:00:00 15,360 ----a-w c:\windows\system32\npp\nppagent.exe
+ 2008-04-14 00:12:29 15,360 -c--a-w c:\windows\system32\npp\nppagent.exe
- 2004-08-10 19:00:00 54,784 ----a-w c:\windows\system32\npptools.dll
+ 2008-04-14 00:12:02 54,784 ----a-w c:\windows\system32\npptools.dll
- 2004-08-10 19:00:00 76,800 ----a-w c:\windows\system32\nslookup.exe
+ 2008-04-14 00:12:29 76,800 ----a-w c:\windows\system32\nslookup.exe
- 2004-08-10 19:00:00 1,200,128 ----a-w c:\windows\system32\ntbackup.exe
+ 2008-04-14 00:12:30 1,200,640 ----a-w c:\windows\system32\ntbackup.exe
- 2004-08-10 19:00:00 708,096 ----a-w c:\windows\system32\ntdll.dll
+ 2008-04-14 00:11:24 706,048 ----a-w c:\windows\system32\ntdll.dll
- 2004-08-10 19:00:00 67,072 ----a-w c:\windows\system32\ntdsapi.dll
+ 2008-04-14 00:12:02 67,072 ----a-w c:\windows\system32\ntdsapi.dll
- 2007-02-28 08:38:55 2,057,600 ----a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 ----a-w c:\windows\system32\ntkrnlpa.exe
- 2004-08-10 19:00:00 43,520 ----a-w c:\windows\system32\ntlanman.dll
+ 2008-04-14 00:12:02 44,032 ----a-w c:\windows\system32\ntlanman.dll
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\ntlsapi.dll
+ 2008-04-14 00:12:02 8,192 ----a-w c:\windows\system32\ntlsapi.dll
- 2004-08-10 19:00:00 118,784 ----a-w c:\windows\system32\ntmarta.dll
+ 2008-04-14 00:12:02 118,784 ----a-w c:\windows\system32\ntmarta.dll
- 2004-08-10 19:00:00 40,960 ----a-w c:\windows\system32\ntmsapi.dll
+ 2008-04-14 00:12:02 40,960 ----a-w c:\windows\system32\ntmsapi.dll
- 2004-08-10 19:00:00 179,712 ----a-w c:\windows\system32\ntmsdba.dll
+ 2008-04-14 00:12:02 179,200 ----a-w c:\windows\system32\ntmsdba.dll
- 2004-08-10 19:00:00 488,448 ----a-w c:\windows\system32\ntmsmgr.dll
+ 2008-04-14 00:12:02 488,448 ----a-w c:\windows\system32\ntmsmgr.dll
- 2004-08-10 19:00:00 435,200 ----a-w c:\windows\system32\ntmssvc.dll
+ 2008-04-14 00:12:02 435,200 ----a-w c:\windows\system32\ntmssvc.dll
- 2007-02-28 09:10:57 2,180,352 ----a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 ----a-w c:\windows\system32\ntoskrnl.exe
- 2004-08-10 19:00:00 91,136 ----a-w c:\windows\system32\ntprint.dll
+ 2008-04-14 00:12:02 91,136 ----a-w c:\windows\system32\ntprint.dll
- 2004-08-10 19:00:00 143,872 ----a-w c:\windows\system32\ntshrui.dll
+ 2008-04-14 00:12:02 143,360 ----a-w c:\windows\system32\ntshrui.dll
- 2004-08-10 19:00:00 419,840 ----a-w c:\windows\system32\ntvdm.exe
+ 2008-04-14 00:12:30 420,864 ----a-w c:\windows\system32\ntvdm.exe
- 2004-08-10 19:00:00 13,312 ----a-w c:\windows\system32\ntvdmd.dll
+ 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\ntvdmd.dll
- 2006-10-13 12:35:12 64,000 ----a-w c:\windows\system32\nwapi32.dll
+ 2008-04-14 00:12:02 64,000 ----a-w c:\windows\system32\nwapi32.dll
- 2006-10-13 12:35:12 142,336 ----a-w c:\windows\system32\nwprovau.dll
+ 2008-04-14 00:12:02 142,336 ----a-w c:\windows\system32\nwprovau.dll
- 2006-10-13 12:35:12 65,536 ----a-w c:\windows\system32\nwwks.dll
+ 2008-04-14 00:12:02 65,536 ----a-w c:\windows\system32\nwwks.dll
- 2004-08-10 19:00:00 266,752 ----a-w c:\windows\system32\oakley.dll
+ 2008-04-14 00:12:02 270,336 ----a-w c:\windows\system32\oakley.dll
- 2004-08-10 19:00:00 285,696 ----a-w c:\windows\system32\objsel.dll
+ 2008-04-14 00:12:02 286,208 ----a-w c:\windows\system32\objsel.dll
- 2008-04-23 04:16:28 102,912 ------w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 ------w c:\windows\system32\occache.dll
- 2004-08-10 19:00:00 60,928 ----a-w c:\windows\system32\ocmanage.dll
+ 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\ocmanage.dll
- 2004-08-10 19:00:00 249,856 ----a-w c:\windows\system32\odbc32.dll
+ 2008-04-14 00:12:02 249,856 ----a-w c:\windows\system32\odbc32.dll
- 2004-08-10 19:00:00 16,384 ----a-w c:\windows\system32\odbc32gt.dll
+ 2008-04-14 00:12:02 16,384 ----a-w c:\windows\system32\odbc32gt.dll
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\odbcad32.exe
+ 2008-04-14 00:12:30 32,768 ----a-w c:\windows\system32\odbcad32.exe
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\odbcbcp.dll
+ 2008-04-14 00:12:02 24,576 ----a-w c:\windows\system32\odbcbcp.dll
- 2004-08-10 19:00:00 135,168 ----a-w c:\windows\system32\odbcconf.dll
+ 2008-04-14 00:12:02 135,168 ----a-w c:\windows\system32\odbcconf.dll
- 2004-08-10 19:00:00 69,632 ----a-w c:\windows\system32\odbcconf.exe
+ 2008-04-14 00:12:30 69,632 ----a-w c:\windows\system32\odbcconf.exe
- 2004-08-10 19:00:00 106,496 ----a-w c:\windows\system32\odbccp32.dll
+ 2008-04-14 00:12:02 106,496 ----a-w c:\windows\system32\odbccp32.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 ----a-w c:\windows\system32\odbccr32.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\odbccu32.dll
+ 2008-04-14 00:12:02 65,536 ----a-w c:\windows\system32\odbccu32.dll
- 2004-08-10 19:00:00 94,208 ----a-w c:\windows\system32\odbcint.dll
+ 2008-04-13 17:26:05 94,208 ----a-w c:\windows\system32\odbcint.dll
- 2004-08-10 19:00:00 53,279 ----a-w c:\windows\system32\odbcji32.dll
+ 2008-04-14 00:10:31 53,279 ----a-w c:\windows\system32\odbcji32.dll
- 2004-08-10 19:00:00 278,559 ----a-w c:\windows\system32\odbcjt32.dll
+ 2008-04-14 00:12:02 278,559 ----a-w c:\windows\system32\odbcjt32.dll
- 2004-08-10 19:00:00 12,288 ----a-w c:\windows\system32\odbcp32r.dll
+ 2008-04-13 17:26:05 12,288 ----a-w c:\windows\system32\odbcp32r.dll
- 2004-08-10 19:00:00 147,456 ----a-w c:\windows\system32\odbctrac.dll
+ 2008-04-14 00:12:02 147,456 ----a-w c:\windows\system32\odbctrac.dll
- 2004-08-10 19:00:00 20,511 ----a-w c:\windows\system32\oddbse32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\oddbse32.dll
- 2004-08-10 19:00:00 20,510 ----a-w c:\windows\system32\odexl32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odexl32.dll
- 2004-08-10 19:00:00 20,510 ----a-w c:\windows\system32\odfox32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odfox32.dll
- 2004-08-10 19:00:00 20,510 ----a-w c:\windows\system32\odpdx32.dll
+ 2008-04-14 00:12:02 20,510 ----a-w c:\windows\system32\odpdx32.dll
- 2004-08-10 19:00:00 20,511 ----a-w c:\windows\system32\odtext32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\odtext32.dll
- 2004-08-10 19:00:00 120,832 ----a-w c:\windows\system32\offfilt.dll
+ 2008-04-14 00:12:02 192,000 ----a-w c:\windows\system32\offfilt.dll
- 2005-07-26 04:39:48 1,285,120 ----a-w c:\windows\system32\ole32.dll
+ 2008-04-14 00:12:02 1,287,168 ----a-w c:\windows\system32\ole32.dll
- 2007-12-04 18:38:13 550,912 ----a-w c:\windows\system32\oleaut32.dll
+ 2008-04-14 00:12:02 551,936 ----a-w c:\windows\system32\oleaut32.dll
- 2005-07-26 04:39:48 74,752 ----a-w c:\windows\system32\olecli32.dll
+ 2008-04-14 00:12:02 74,752 ----a-w c:\windows\system32\olecli32.dll
- 2005-07-26 04:39:49 37,888 ----a-w c:\windows\system32\olecnv32.dll
+ 2008-04-14 00:12:02 37,376 ----a-w c:\windows\system32\olecnv32.dll
- 2006-10-16 16:15:00 122,880 ----a-w c:\windows\system32\oledlg.dll
+ 2008-04-14 00:12:02 122,880 ----a-w c:\windows\system32\oledlg.dll
- 2004-08-10 19:00:00 107,008 ----a-w c:\windows\system32\oleprn.dll
+ 2008-04-14 00:12:02 107,008 ----a-w c:\windows\system32\oleprn.dll
- 2004-08-10 19:00:00 83,456 ----a-w c:\windows\system32\olepro32.dll
+ 2008-04-14 00:12:02 84,992 ----a-w c:\windows\system32\olepro32.dll
+ 2008-04-14 00:12:02 144,384 ------w c:\windows\system32\onex.dll
- 2004-08-10 19:00:00 122,368 ----a-w c:\windows\system32\oobe\msobcomm.dll
+ 2008-04-14 00:12:00 122,368 -c--a-w c:\windows\system32\oobe\msobcomm.dll
- 2004-08-10 19:00:00 16,384 ----a-w c:\windows\system32\oobe\msobdl.dll
+ 2008-04-14 00:12:00 16,384 -c--a-w c:\windows\system32\oobe\msobdl.dll
- 2004-08-10 19:00:00 561,664 ----a-w c:\windows\system32\oobe\msobmain.dll
+ 2008-04-14 00:12:00 565,248 -c--a-w c:\windows\system32\oobe\msobmain.dll
- 2004-08-10 19:00:00 30,720 ----a-w c:\windows\system32\oobe\msobshel.dll
+ 2008-04-14 00:12:00 30,720 -c--a-w c:\windows\system32\oobe\msobshel.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\oobe\msobweb.dll
+ 2008-04-14 00:12:00 19,456 -c--a-w c:\windows\system32\oobe\msobweb.dll
- 2004-08-10 19:00:00 28,160 ----a-w c:\windows\system32\oobe\msoobe.exe
+ 2008-04-14 00:12:28 29,184 -c--a-w c:\windows\system32\oobe\msoobe.exe
- 2004-08-10 19:00:00 51,200 ----a-w c:\windows\system32\oobe\oobebaln.exe
+ 2008-04-14 00:12:31 51,200 -c--a-w c:\windows\system32\oobe\oobebaln.exe
- 2004-08-10 19:00:00 67,584 ----a-w c:\windows\system32\openfiles.exe
+ 2008-04-14 00:12:31 67,584 ----a-w c:\windows\system32\openfiles.exe
- 2004-08-10 19:00:00 713,728 ----a-w c:\windows\system32\opengl32.dll
+ 2008-04-14 00:12:02 713,728 ----a-w c:\windows\system32\opengl32.dll
- 2004-08-10 19:00:00 215,552 ----a-w c:\windows\system32\osk.exe
+ 2008-04-14 00:12:31 215,552 ----a-w c:\windows\system32\osk.exe
- 2004-08-10 19:00:00 67,584 ----a-w c:\windows\system32\osuninst.dll
+ 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\osuninst.dll
- 2004-08-10 19:00:00 116,224 ----a-w c:\windows\system32\p2p.dll
+ 2008-04-14 00:12:02 153,600 ----a-w c:\windows\system32\p2p.dll
- 2004-08-10 19:00:00 86,016 ----a-w c:\windows\system32\p2pgasvc.dll
+ 2008-04-14 00:12:02 105,472 ----a-w c:\windows\system32\p2pgasvc.dll
- 2004-08-10 19:00:00 312,320 ----a-w c:\windows\system32\p2pgraph.dll
+ 2008-04-14 00:12:02 313,856 ----a-w c:\windows\system32\p2pgraph.dll
- 2004-08-10 19:00:00 88,064 ----a-w c:\windows\system32\p2pnetsh.dll
+ 2008-04-14 00:12:02 115,712 ----a-w c:\windows\system32\p2pnetsh.dll
- 2004-08-10 19:00:00 526,848 ----a-w c:\windows\system32\p2psvc.dll
+ 2008-04-14 00:12:02 554,496 ----a-w c:\windows\system32\p2psvc.dll
- 2004-08-10 19:00:00 58,368 ----a-w c:\windows\system32\packager.exe
+ 2008-04-14 00:12:31 58,368 ----a-w c:\windows\system32\packager.exe
- 2004-08-10 19:00:00 62,976 ----a-w c:\windows\system32\pautoenr.dll
+ 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\pautoenr.dll
- 2004-08-10 19:00:00 283,648 ----a-w c:\windows\system32\pdh.dll
+ 2008-04-14 00:12:02 284,160 ----a-w c:\windows\system32\pdh.dll
- 2008-04-03 03:45:05 52,764 ----a-w c:\windows\system32\perfc009.dat
+ 2008-11-07 20:40:50 71,308 ----a-w c:\windows\system32\perfc009.dat
- 2004-08-10 19:00:00 39,936 ----a-w c:\windows\system32\perfctrs.dll
+ 2008-04-14 00:12:02 39,936 ----a-w c:\windows\system32\perfctrs.dll
- 2004-08-10 19:00:00 26,624 ----a-w c:\windows\system32\perfdisk.dll
+ 2008-04-14 00:12:02 26,624 ----a-w c:\windows\system32\perfdisk.dll
- 2008-04-03 03:45:05 380,350 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-07 20:40:50 441,624 ----a-w c:\windows\system32\perfh009.dat
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\perfmon.exe
+ 2008-04-14 00:12:31 15,872 ----a-w c:\windows\system32\perfmon.exe
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\perfnet.dll
+ 2008-04-14 00:12:02 17,920 ----a-w c:\windows\system32\perfnet.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\perfos.dll
+ 2008-04-14 00:12:02 25,088 ----a-w c:\windows\system32\perfos.dll
- 2004-08-10 19:00:00 34,816 ----a-w c:\windows\system32\perfproc.dll
+ 2008-04-14 00:12:02 34,816 ----a-w c:\windows\system32\perfproc.dll
+ 2008-04-14 00:12:02 412,160 ------w c:\windows\system32\photometadatahandler.dll
- 2004-08-10 19:00:00 176,128 ----a-w c:\windows\system32\photowiz.dll
+ 2008-04-14 00:12:02 176,128 ----a-w c:\windows\system32\photowiz.dll
- 2004-08-04 00:56:46 35,328 ----a-w c:\windows\system32\pid.dll
+ 2008-04-14 00:12:02 35,328 ----a-w c:\windows\system32\pid.dll
- 2004-08-10 19:00:00 24,064 ----a-w c:\windows\system32\pidgen.dll
+ 2008-04-14 00:11:09 24,064 ----a-w c:\windows\system32\pidgen.dll
- 2004-08-10 19:00:00 17,920 ----a-w c:\windows\system32\ping.exe
+ 2008-04-14 00:12:31 17,920 ----a-w c:\windows\system32\ping.exe
- 2004-08-04 00:56:46 15,360 ----a-w c:\windows\system32\pjlmon.dll
+ 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\pjlmon.dll
- 2008-04-23 04:16:28 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll
- 2004-08-10 19:00:00 48,640 ----a-w c:\windows\system32\pnrpnsp.dll
+ 2008-04-14 00:12:02 58,880 ----a-w c:\windows\system32\pnrpnsp.dll
- 2004-08-10 19:00:00 105,472 ----a-w c:\windows\system32\polstore.dll
+ 2008-04-14 00:12:02 105,472 ----a-w c:\windows\system32\polstore.dll
- 2004-08-10 19:00:00 49,152 ----a-w c:\windows\system32\powercfg.exe
+ 2008-04-14 00:12:31 49,152 ----a-w c:\windows\system32\powercfg.exe
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\powrprof.dll
+ 2008-04-14 00:12:03 17,408 ----a-w c:\windows\system32\powrprof.dll
+ 2007-10-09 17:03:04 106,520 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
+ 2007-10-09 17:03:08 350,744 ----a-w c:\windows\system32\PresentationHost.exe
+ 2007-10-09 17:03:02 33,304 ----a-w c:\windows\system32\PresentationHostProxy.dll
+ 2007-10-09 17:03:12 779,800 ----a-w c:\windows\system32\PresentationNative_v0300.dll
- 2004-08-10 19:00:00 560,640 ----a-w c:\windows\system32\printui.dll
+ 2008-04-14 00:12:03 560,640 ----a-w c:\windows\system32\printui.dll
+ 2007-03-23 00:25:02 124,928 ------w c:\windows\system32\prntvpt.dll
- 2004-08-10 19:00:00 27,648 ----a-w c:\windows\system32\profmap.dll
+ 2008-04-14 00:12:03 27,648 ----a-w c:\windows\system32\profmap.dll
- 2004-08-10 19:00:00 109,568 ----a-w c:\windows\system32\progman.exe
+ 2008-04-14 00:12:31 109,568 ----a-w c:\windows\system32\progman.exe
- 2004-08-10 19:00:00 50,176 ----a-w c:\windows\system32\proquota.exe
+ 2008-04-14 00:12:32 50,176 ----a-w c:\windows\system32\proquota.exe
- 2004-08-10 19:00:00 9,216 ----a-w c:\windows\system32\proxycfg.exe
+ 2008-04-14 00:12:32 9,216 ----a-w c:\windows\system32\proxycfg.exe
- 2004-08-10 19:00:00 23,040 ----a-w c:\windows\system32\psapi.dll
+ 2008-04-14 00:12:03 23,040 ----a-w c:\windows\system32\psapi.dll
- 2004-08-10 19:00:00 96,768 ----a-w c:\windows\system32\psbase.dll
+ 2008-04-14 00:12:03 96,768 ----a-w c:\windows\system32\psbase.dll
+ 2007-06-05 17:20:30 1,459,752 ----a-w c:\windows\system32\PSIKey.dll
+ 2007-06-05 17:20:32 177,704 ----a-w c:\windows\system32\PSIService.exe
- 2004-08-10 19:00:00 43,520 ----a-w c:\windows\system32\pstorec.dll
+ 2008-04-14 00:12:03 43,520 ----a-w c:\windows\system32\pstorec.dll
- 2004-08-10 19:00:00 34,304 ----a-w c:\windows\system32\pstorsvc.dll
+ 2008-04-14 00:12:03 34,304 ----a-w c:\windows\system32\pstorsvc.dll
+ 2008-01-01 04:00:00 60,273 ----a-w c:\windows\system32\pthreadGC2.dll
+ 2008-04-14 00:12:03 150,528 ------w c:\windows\system32\qagent.dll
+ 2008-04-14 00:12:03 291,328 ------w c:\windows\system32\qagentrt.dll
- 2005-08-04 09:29:52 221,184 ------w c:\windows\system32\qasf.dll
+ 2006-10-19 01:47:18 211,456 ------w c:\windows\system32\qasf.dll
- 2004-08-10 19:00:00 192,512 ----a-w c:\windows\system32\qcap.dll
+ 2008-04-14 00:12:03 192,512 ----a-w c:\windows\system32\qcap.dll
+ 2008-04-14 00:12:03 62,464 ------w c:\windows\system32\qcliprov.dll
- 2004-08-10 19:00:00 279,040 ----a-w c:\windows\system32\qdv.dll
+ 2008-04-14 00:12:03 279,040 ----a-w c:\windows\system32\qdv.dll
- 2005-06-29 08:55:07 385,024 ----a-w c:\windows\system32\qdvd.dll
+ 2008-04-14 00:12:03 386,048 ----a-w c:\windows\system32\qdvd.dll
- 2004-08-10 19:00:00 562,176 ----a-w c:\windows\system32\qedit.dll
+ 2008-04-14 00:12:03 562,176 ----a-w c:\windows\system32\qedit.dll
- 2004-08-10 19:00:00 733,696 ----a-w c:\windows\system32\qedwipes.dll
+ 2008-04-13 17:21:32 733,696 ----a-w c:\windows\system32\qedwipes.dll
- 2004-08-10 19:00:00 382,464 ----a-w c:\windows\system32\qmgr.dll
+ 2008-04-14 00:12:03 409,088 ----a-w c:\windows\system32\qmgr.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\qmgrprxy.dll
+ 2008-04-14 00:12:03 18,944 ----a-w c:\windows\system32\qmgrprxy.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\qprocess.exe
+ 2008-04-14 00:12:32 19,968 ----a-w c:\windows\system32\qprocess.exe
- 2008-03-21 20:30:08 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
+ 2007-01-03 21:58:11 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
- 2008-05-07 04:55:40 1,288,192 ----a-w c:\windows\system32\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ------w c:\windows\system32\quartz.dll
- 2006-06-22 05:06:30 1,435,648 ----a-w c:\windows\system32\query.dll
+ 2008-04-14 00:12:03 1,435,648 ----a-w c:\windows\system32\query.dll
+ 2008-04-14 00:12:03 76,800 ------w c:\windows\system32\qutil.dll
- 2004-08-10 19:00:00 43,520 ----a-w c:\windows\system32\racpldlg.dll
+ 2008-04-14 00:12:03 43,520 ----a-w c:\windows\system32\racpldlg.dll
- 2006-06-26 17:37:10 8,192 ----a-w c:\windows\system32\rasadhlp.dll
+ 2008-04-14 00:12:03 7,680 ----a-w c:\windows\system32\rasadhlp.dll
- 2004-08-10 19:00:00 236,544 ----a-w c:\windows\system32\rasapi32.dll
+ 2008-04-14 00:12:03 237,056 ----a-w c:\windows\system32\rasapi32.dll
- 2004-08-10 19:00:00 89,088 ----a-w c:\windows\system32\rasauto.dll
+ 2008-04-14 00:12:03 88,576 ----a-w c:\windows\system32\rasauto.dll
- 2004-08-10 19:00:00 69,632 ----a-w c:\windows\system32\raschap.dll
+ 2008-04-14 00:12:03 79,872 ----a-w c:\windows\system32\raschap.dll
- 2004-08-10 19:00:00 657,920 ----a-w c:\windows\system32\rasdlg.dll
+ 2008-04-14 00:12:03 658,432 ----a-w c:\windows\system32\rasdlg.dll
- 2004-08-10 19:00:00 61,440 ----a-w c:\windows\system32\rasman.dll
+ 2008-04-14 00:12:03 61,440 ----a-w c:\windows\system32\rasman.dll
- 2006-06-22 10:47:18 181,248 ----a-w c:\windows\system32\rasmans.dll
+ 2008-04-14 00:12:03 186,368 ----a-w c:\windows\system32\rasmans.dll
- 2004-08-10 19:00:00 56,832 ----a-w c:\windows\system32\rasphone.exe
+ 2008-04-14 00:12:32 56,832 ----a-w c:\windows\system32\rasphone.exe
- 2004-08-10 19:00:00 206,336 ----a-w c:\windows\system32\rasppp.dll
+ 2008-04-14 00:12:03 210,944 ----a-w c:\windows\system32\rasppp.dll
+ 2008-04-14 00:12:03 61,952 ------w c:\windows\system32\rasqec.dll
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\rassapi.dll
+ 2008-04-14 00:12:03 16,384 ----a-w c:\windows\system32\rassapi.dll
- 2004-08-10 19:00:00 58,880 ----a-w c:\windows\system32\rastapi.dll
+ 2008-04-14 00:12:03 58,368 ----a-w c:\windows\system32\rastapi.dll
- 2004-08-10 19:00:00 112,128 ----a-w c:\windows\system32\rastls.dll
+ 2008-04-14 00:12:03 150,016 ----a-w c:\windows\system32\rastls.dll
- 2004-08-10 19:00:00 102,400 ----a-w c:\windows\system32\rcbdyctl.dll
+ 2008-04-14 00:12:03 102,400 ----a-w c:\windows\system32\rcbdyctl.dll
- 2004-08-10 19:00:00 35,840 ----a-w c:\windows\system32\rcimlby.exe
+ 2008-04-14 00:12:32 35,840 ----a-w c:\windows\system32\rcimlby.exe
- 2004-08-10 19:00:00 21,504 ----a-w c:\windows\system32\rcp.exe
+ 2008-04-14 00:12:32 21,504 ----a-w c:\windows\system32\rcp.exe
- 2004-08-10 19:00:00 147,968 ----a-w c:\windows\system32\rdchost.dll
+ 2008-04-14 00:12:03 147,968 ----a-w c:\windows\system32\rdchost.dll
- 2004-08-10 19:00:00 62,464 ----a-w c:\windows\system32\rdpclip.exe
+ 2008-04-14 00:12:32 62,976 ----a-w c:\windows\system32\rdpclip.exe
- 2004-08-10 19:00:00 92,168 ----a-w c:\windows\system32\rdpdd.dll
+ 2008-04-14 00:13:22 92,424 ----a-w c:\windows\system32\rdpdd.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\rdpsnd.dll
+ 2008-04-14 00:12:04 19,968 ----a-w c:\windows\system32\rdpsnd.dll
- 2004-08-10 19:00:00 87,176 ----a-w c:\windows\system32\rdpwsx.dll
+ 2008-04-14 00:13:22 87,176 ----a-w c:\windows\system32\rdpwsx.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\rdsaddin.exe
+ 2008-04-14 00:12:32 13,824 ----a-w c:\windows\system32\rdsaddin.exe
- 2004-08-10 19:00:00 67,072 ----a-w c:\windows\system32\rdshost.exe
+ 2008-04-14 00:12:32 67,072 ----a-w c:\windows\system32\rdshost.exe
- 2004-08-10 19:00:00 50,176 ----a-w c:\windows\system32\reg.exe
+ 2008-04-14 00:12:32 50,176 ----a-w c:\windows\system32\reg.exe
- 2004-08-10 19:00:00 49,664 ----a-w c:\windows\system32\regapi.dll
+ 2008-04-14 00:12:04 49,664 ----a-w c:\windows\system32\regapi.dll
- 2004-08-10 19:00:00 59,904 ----a-w c:\windows\system32\regsvc.dll
+ 2008-04-14 00:12:04 59,904 ----a-w c:\windows\system32\regsvc.dll
- 2004-08-10 19:00:00 11,776 ----a-w c:\windows\system32\regsvr32.exe
+ 2008-04-14 00:12:32 11,776 ----a-w c:\windows\system32\regsvr32.exe
- 2004-08-10 19:00:00 397,824 ----a-w c:\windows\system32\regwizc.dll
+ 2008-04-14 00:12:04 397,824 ----a-w c:\windows\system32\regwizc.dll
+ 2004-08-03 22:59:18 35,328 -c--a-w c:\windows\system32\ReinstallBackups\0003\DriverFiles\i386\processr.sys
+ 2005-01-07 21:07:18 138,752 -c--a-w c:\windows\system32\ReinstallBackups\0004\DriverFiles\hdaudbus.sys
- 2004-08-10 19:00:00 60,416 ----a-w c:\windows\system32\remotepg.dll
+ 2008-04-14 00:12:04 60,416 ----a-w c:\windows\system32\remotepg.dll
- 2004-08-10 19:00:00 380,416 ----a-w c:\windows\system32\Restore\rstrui.exe
+ 2008-04-14 00:12:33 380,416 ----a-w c:\windows\system32\Restore\rstrui.exe
- 2004-08-10 19:00:00 58,880 ----a-w c:\windows\system32\resutils.dll
+ 2008-04-14 00:12:04 58,880 ----a-w c:\windows\system32\resutils.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\rexec.exe
+ 2008-04-14 00:12:33 13,824 ----a-w c:\windows\system32\rexec.exe
+ 2006-08-24 20:15:06 150,808 ----a-w c:\windows\system32\rgb9rast_2.dll
+ 2008-04-14 00:12:04 290,304 ------w c:\windows\system32\rhttpaa.dll
- 2006-11-27 14:54:06 433,152 ----a-w c:\windows\system32\riched20.dll
+ 2008-04-14 00:12:04 433,664 ----a-w c:\windows\system32\riched20.dll
+ 1999-10-15 16:50:10 1,056,768 ----a-w c:\windows\system32\ROBOEX32.DLL
- 2007-07-09 13:16:16 582,656 ----a-w c:\windows\system32\rpcrt4.dll
+ 2008-04-14 00:12:04 584,704 ----a-w c:\windows\system32\rpcrt4.dll
- 2005-07-26 04:39:49 397,824 ----a-w c:\windows\system32\rpcss.dll
+ 2008-04-14 00:12:04 399,360 ----a-w c:\windows\system32\rpcss.dll
- 2004-08-10 19:00:00 152,576 ----a-w c:\windows\system32\rsaenh.dll
+ 2008-04-13 17:37:57 208,384 ----a-w c:\windows\system32\rsaenh.dll
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\rsh.exe
+ 2008-04-14 00:12:33 14,848 ----a-w c:\windows\system32\rsh.exe
- 2004-08-10 19:00:00 39,936 ----a-w c:\windows\system32\rshx32.dll
+ 2008-04-14 00:12:04 39,936 ----a-w c:\windows\system32\rshx32.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\rsmps.dll
+ 2008-04-14 00:12:04 18,944 ----a-w c:\windows\system32\rsmps.dll
- 2004-08-10 19:00:00 107,520 ----a-w c:\windows\system32\rsnotify.exe
+ 2008-04-14 00:12:33 107,520 ----a-w c:\windows\system32\rsnotify.exe
- 2004-08-10 19:00:00 90,112 ----a-w c:\windows\system32\rsvpsp.dll
+ 2008-04-14 00:12:04 92,672 ----a-w c:\windows\system32\rsvpsp.dll
- 2004-08-10 19:00:00 77,312 ----a-w c:\windows\system32\rtcshare.exe
+ 2008-04-14 00:12:33 77,312 ----a-w c:\windows\system32\rtcshare.exe
- 2004-08-10 19:00:00 31,744 ----a-w c:\windows\system32\rtipxmib.dll
+ 2008-04-14 00:12:04 31,744 ----a-w c:\windows\system32\rtipxmib.dll
- 2004-08-10 19:00:00 44,032 ----a-w c:\windows\system32\rtutils.dll
+ 2008-04-14 00:12:04 44,032 ----a-w c:\windows\system32\rtutils.dll
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\system32\rundll32.exe
+ 2008-04-14 00:12:33 33,280 ----a-w c:\windows\system32\rundll32.exe
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\runonce.exe
+ 2008-04-14 00:12:33 14,336 ----a-w c:\windows\system32\runonce.exe
+ 2008-04-14 00:12:04 9,728 ------w c:\windows\system32\rwnh.dll
+ 2008-04-14 00:12:04 397,056 ------w c:\windows\system32\s3gnb.dll
- 2004-08-10 19:00:00 43,520 ----a-w c:\windows\system32\safrcdlg.dll
+ 2008-04-14 00:12:04 43,520 ----a-w c:\windows\system32\safrcdlg.dll
- 2004-08-10 19:00:00 29,696 ----a-w c:\windows\system32\safrdm.dll
+ 2008-04-14 00:12:04 29,696 ----a-w c:\windows\system32\safrdm.dll
- 2004-08-10 19:00:00 45,568 ----a-w c:\windows\system32\safrslv.dll
+ 2008-04-14 00:12:04 45,568 ----a-w c:\windows\system32\safrslv.dll
- 2004-08-10 19:00:00 64,000 ----a-w c:\windows\system32\samlib.dll
+ 2008-04-14 00:12:04 64,000 ----a-w c:\windows\system32\samlib.dll
- 2004-08-10 19:00:00 415,744 ----a-w c:\windows\system32\samsrv.dll
+ 2008-04-14 00:12:04 415,744 ----a-w c:\windows\system32\samsrv.dll
- 2004-08-10 19:00:00 13,312 ----a-w c:\windows\system32\savedump.exe
+ 2008-04-14 00:12:33 13,312 ----a-w c:\windows\system32\savedump.exe
- 2004-08-10 19:00:00 159,232 ----a-w c:\windows\system32\sbeio.dll
+ 2008-04-14 00:12:04 159,232 ----a-w c:\windows\system32\sbeio.dll
- 2004-08-10 19:00:00 69,632 ----a-w c:\windows\system32\scarddlg.dll
+ 2008-04-14 00:12:04 69,632 ----a-w c:\windows\system32\scarddlg.dll
- 2004-08-10 19:00:00 95,744 ----a-w c:\windows\system32\scardsvr.exe
+ 2008-04-14 00:12:33 95,744 ----a-w c:\windows\system32\scardsvr.exe
- 2004-08-10 19:00:00 171,008 ----a-w c:\windows\system32\sccsccp.dll
+ 2008-04-14 00:12:05 171,008 ----a-w c:\windows\system32\sccsccp.dll
- 2004-08-10 19:00:00 180,224 ----a-w c:\windows\system32\scecli.dll
+ 2008-04-14 00:12:05 181,248 ----a-w c:\windows\system32\scecli.dll
- 2004-08-10 19:00:00 313,856 ----a-w c:\windows\system32\scesrv.dll
+ 2008-04-14 00:12:05 314,880 ----a-w c:\windows\system32\scesrv.dll
- 2007-04-25 14:21:15 144,896 ----a-w c:\windows\system32\schannel.dll
+ 2008-04-14 00:12:05 144,384 ----a-w c:\windows\system32\schannel.dll
- 2004-08-10 19:00:00 190,976 ----a-w c:\windows\system32\schedsvc.dll
+ 2008-04-14 00:12:05 192,512 ----a-w c:\windows\system32\schedsvc.dll
- 2004-08-10 19:00:00 121,856 ----a-w c:\windows\system32\schtasks.exe
+ 2008-04-14 00:12:34 121,856 ----a-w c:\windows\system32\schtasks.exe
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\sclgntfy.dll
+ 2008-04-14 00:12:05 20,480 ----a-w c:\windows\system32\sclgntfy.dll
- 2004-08-10 19:00:00 9,216 ----a-w c:\windows\system32\scrnsave.scr
+ 2008-04-14 00:12:43 9,216 ----a-w c:\windows\system32\scrnsave.scr
- 2004-08-10 19:00:00 159,744 ----a-w c:\windows\system32\scrobj.dll
+ 2008-05-09 10:53:39 180,224 ----a-w c:\windows\system32\scrobj.dll
- 2004-08-10 19:00:00 151,552 ----a-w c:\windows\system32\scrrun.dll
+ 2008-05-09 10:53:40 172,032 ----a-w c:\windows\system32\scrrun.dll
- 2004-08-10 19:00:00 77,312 ----a-w c:\windows\system32\sdbinst.exe
+ 2008-04-14 00:12:34 77,312 ----a-w c:\windows\system32\sdbinst.exe
- 2004-08-10 19:00:00 29,184 ----a-w c:\windows\system32\sdhcinst.dll
+ 2008-04-14 00:12:05 29,184 ----a-w c:\windows\system32\sdhcinst.dll
- 2004-08-10 19:00:00 18,432 ----a-w c:\windows\system32\secedit.exe
+ 2008-04-14 00:12:34 18,944 ----a-w c:\windows\system32\secedit.exe
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\seclogon.dll
+ 2008-04-14 00:12:05 18,944 ----a-w c:\windows\system32\seclogon.dll
- 2004-08-10 19:00:00 55,808 ----a-w c:\windows\system32\secur32.dll
+ 2008-04-14 00:12:05 56,320 ----a-w c:\windows\system32\secur32.dll
- 2004-08-10 19:00:00 5,632 ----a-w c:\windows\system32\security.dll
+ 2008-04-14 00:12:05 5,632 ----a-w c:\windows\system32\security.dll
- 2004-08-10 19:00:00 29,184 ----a-w c:\windows\system32\sendcmsg.dll
+ 2008-04-14 00:12:05 29,184 ----a-w c:\windows\system32\sendcmsg.dll
- 2004-08-10 19:00:00 55,296 ----a-w c:\windows\system32\sendmail.dll
+ 2008-04-14 00:12:05 54,784 ----a-w c:\windows\system32\sendmail.dll
- 2004-08-10 19:00:00 38,912 ----a-w c:\windows\system32\sens.dll
+ 2008-04-14 00:12:05 39,424 ----a-w c:\windows\system32\sens.dll
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\sensapi.dll
+ 2008-04-14 00:12:05 7,168 ----a-w c:\windows\system32\sensapi.dll
- 2004-08-10 19:00:00 56,320 ----a-w c:\windows\system32\servdeps.dll
+ 2008-04-14 00:12:05 56,320 ----a-w c:\windows\system32\servdeps.dll
- 2004-08-10 19:00:00 108,032 ----a-w c:\windows\system32\services.exe
+ 2008-04-14 00:12:34 108,544 ----a-w c:\windows\system32\services.exe
- 2004-08-10 19:00:00 140,800 ----a-w c:\windows\system32\sessmgr.exe
+ 2008-04-14 00:12:34 141,312 ----a-w c:\windows\system32\sessmgr.exe
- 2004-08-10 19:00:00 31,232 ----a-w c:\windows\system32\sethc.exe
+ 2008-04-14 00:12:34 31,232 ----a-w c:\windows\system32\sethc.exe
- 2004-08-10 19:00:00 23,040 ----a-w c:\windows\system32\setup.exe
+ 2008-04-14 00:12:34 23,040 ----a-w c:\windows\system32\setup.exe
- 2004-08-10 19:00:00 259,584 ----a-w c:\windows\system32\Setup\comsetup.dll
+ 2008-04-14 00:11:51 274,944 ----a-w c:\windows\system32\Setup\comsetup.dll
- 2004-08-10 19:00:00 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll
+ 2008-04-14 00:11:53 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll
- 2004-08-10 19:00:00 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll
+ 2008-04-14 00:11:54 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll
- 2004-08-10 19:00:00 505,344 ----a-w c:\windows\system32\Setup\iis.dll
+ 2008-04-14 00:11:54 505,344 ----a-w c:\windows\system32\Setup\iis.dll
- 2004-08-10 19:00:00 115,712 ----a-w c:\windows\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:54 123,392 ----a-w c:\windows\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:56 8,192 -c--a-w c:\windows\system32\Setup\koc.dll
- 2004-08-10 19:00:00 82,432 ----a-w c:\windows\system32\Setup\msdtcstp.dll
+ 2008-04-14 00:11:59 90,112 ----a-w c:\windows\system32\Setup\msdtcstp.dll
- 2004-08-10 19:00:00 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll
+ 2008-04-14 00:11:59 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll
- 2004-08-10 19:00:00 169,984 ----a-w c:\windows\system32\Setup\msmqocm.dll
+ 2008-04-14 00:12:00 170,496 ----a-w c:\windows\system32\Setup\msmqocm.dll
- 2004-08-10 19:00:00 77,312 ----a-w c:\windows\system32\Setup\netoc.dll
+ 2008-04-14 00:12:01 77,312 ----a-w c:\windows\system32\Setup\netoc.dll
- 2004-08-10 19:00:00 62,976 ----a-w c:\windows\system32\Setup\ntoc.dll
+ 2008-04-14 00:12:02 62,976 ----a-w c:\windows\system32\Setup\ntoc.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\Setup\ocgen.dll
+ 2008-04-14 00:12:02 15,360 ----a-w c:\windows\system32\Setup\ocgen.dll
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll
+ 2008-04-14 00:12:02 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll
- 2004-08-10 19:00:00 101,376 ----a-w c:\windows\system32\Setup\setupqry.dll
+ 2008-04-14 00:12:05 101,376 ----a-w c:\windows\system32\Setup\setupqry.dll
- 2004-08-10 19:00:00 33,792 ----a-w c:\windows\system32\Setup\tabletoc.dll
+ 2008-04-14 00:12:07 33,792 ----a-w c:\windows\system32\Setup\tabletoc.dll
- 2004-08-10 19:00:00 121,856 ----a-w c:\windows\system32\Setup\tsoc.dll
+ 2008-04-14 00:12:07 130,048 ----a-w c:\windows\system32\Setup\tsoc.dll
- 2004-08-10 19:00:00 983,552 ----a-w c:\windows\system32\setupapi.dll
+ 2008-04-14 09:42:06 985,088 ----a-w c:\windows\system32\setupapi.dll
+ 2008-04-14 00:12:35 32,768 ------w c:\windows\system32\setupn.exe
- 2004-08-10 19:00:00 5,120 ----a-w c:\windows\system32\sfc.dll
+ 2008-04-14 00:12:05 5,120 ----a-w c:\windows\system32\sfc.dll
- 2004-08-10 19:00:00 140,288 ----a-w c:\windows\system32\sfc_os.dll
+ 2008-04-14 00:12:05 140,288 ----a-w c:\windows\system32\sfc_os.dll
- 2004-08-10 19:00:00 1,580,544 ----a-w c:\windows\system32\sfcfiles.dll
+ 2008-04-14 00:12:05 1,614,848 ----a-w c:\windows\system32\sfcfiles.dll
- 2004-08-10 19:00:00 549,376 ----a-w c:\windows\system32\shdoclc.dll
+ 2008-04-13 17:03:19 549,376 ----a-w c:\windows\system32\shdoclc.dll
- 2007-12-07 00:44:37 1,499,136 ----a-w c:\windows\system32\shdocvw.dll
+ 2008-04-14 00:12:05 1,499,136 ----a-w c:\windows\system32\shdocvw.dll
- 2007-10-26 03:34:01 8,460,288 ----a-w c:\windows\system32\shell32.dll
+ 2008-04-14 00:12:05 8,461,312 ----a-w c:\windows\system32\shell32.dll
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\shfolder.dll
+ 2008-04-14 00:12:05 25,088 ----a-w c:\windows\system32\shfolder.dll
- 2004-08-10 19:00:00 68,096 ----a-w c:\windows\system32\shgina.dll
+ 2008-04-14 00:12:05 68,096 ----a-w c:\windows\system32\shgina.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\shimeng.dll
+ 2008-04-14 00:12:05 65,024 ----a-w c:\windows\system32\shimeng.dll
- 2004-08-10 19:00:00 438,272 ----a-w c:\windows\system32\shimgvw.dll
+ 2008-04-14 00:12:05 438,272 ----a-w c:\windows\system32\shimgvw.dll
- 2007-12-07 00:44:38 474,112 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-04-14 00:12:05 474,112 ----a-w c:\windows\system32\shlwapi.dll
- 2004-08-10 19:00:00 151,552 ----a-w c:\windows\system32\shmedia.dll
+ 2008-04-14 00:12:05 152,064 ----a-w c:\windows\system32\shmedia.dll
- 2004-08-10 19:00:00 42,496 ----a-w c:\windows\system32\shmgrate.exe
+ 2008-04-14 00:12:35 45,056 ----a-w c:\windows\system32\shmgrate.exe
- 2004-08-10 19:00:00 77,824 ----a-w c:\windows\system32\shrpubw.exe
+ 2008-04-14 00:12:35 77,824 ----a-w c:\windows\system32\shrpubw.exe
- 2004-08-10 19:00:00 27,648 ----a-w c:\windows\system32\shscrap.dll
+ 2008-04-14 00:12:05 27,648 ----a-w c:\windows\system32\shscrap.dll
- 2006-12-19 21:52:18 134,656 ----a-w c:\windows\system32\shsvcs.dll
+ 2008-04-14 00:12:05 135,168 ----a-w c:\windows\system32\shsvcs.dll
- 2004-08-10 19:00:00 19,456 ----a-w c:\windows\system32\shutdown.exe
+ 2008-04-14 00:12:35 19,456 ----a-w c:\windows\system32\shutdown.exe
- 2004-08-10 19:00:00 13,312 ----a-w c:\windows\system32\sigtab.dll
+ 2008-04-14 00:12:05 13,312 ----a-w c:\windows\system32\sigtab.dll
- 2004-08-10 19:00:00 70,144 ----a-w c:\windows\system32\sigverif.exe
+ 2008-04-14 00:12:35 70,144 ----a-w c:\windows\system32\sigverif.exe
+ 2007-10-18 15:31:46 51,224 ----a-w c:\windows\system32\sirenacm.dll
- 2004-08-10 19:00:00 26,112 ----a-w c:\windows\system32\skeys.exe
+ 2008-04-14 00:12:35 26,112 ----a-w c:\windows\system32\skeys.exe
- 2004-08-10 19:00:00 25,088 ----a-w c:\windows\system32\slayerxp.dll
+ 2008-04-14 00:12:06 25,088 ----a-w c:\windows\system32\slayerxp.dll
- 2004-08-10 19:00:00 98,304 ----a-w c:\windows\system32\slbiop.dll
+ 2008-04-14 00:12:06 98,304 ----a-w c:\windows\system32\slbiop.dll
+ 2008-04-14 00:12:06 73,832 ------w c:\windows\system32\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 ------w c:\windows\system32\slextspk.dll

EasyEEE
2008-12-29, 18:16
+ 2008-04-14 00:12:06 188,508 ------w c:\windows\system32\slgen.dll
+ 2008-04-14 00:12:35 32,866 ------w c:\windows\system32\slrundll.exe
+ 2008-04-14 00:12:35 73,796 ------w c:\windows\system32\slserv.exe
- 2004-08-10 19:00:00 8,192 ----a-w c:\windows\system32\smbinst.exe
+ 2008-04-14 00:12:35 8,192 ----a-w c:\windows\system32\smbinst.exe
- 2004-08-10 19:00:00 363,008 ----a-w c:\windows\system32\smlogcfg.dll
+ 2008-04-14 00:12:06 362,496 ----a-w c:\windows\system32\smlogcfg.dll
- 2004-08-10 19:00:00 89,600 ----a-w c:\windows\system32\smlogsvc.exe
+ 2008-04-14 00:12:35 89,600 ----a-w c:\windows\system32\smlogsvc.exe
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\system32\smss.exe
+ 2008-04-14 00:12:36 50,688 ----a-w c:\windows\system32\smss.exe
+ 2008-04-14 00:12:06 10,752 ------w c:\windows\system32\smtpapi.dll
- 2004-08-10 19:00:00 131,584 ----a-w c:\windows\system32\sndrec32.exe
+ 2008-04-14 00:12:36 131,584 ----a-w c:\windows\system32\sndrec32.exe
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\snmpapi.dll
+ 2008-04-14 00:12:06 18,944 ----a-w c:\windows\system32\snmpapi.dll
- 2004-08-10 19:00:00 182,272 ----a-w c:\windows\system32\snmpsnap.dll
+ 2008-04-14 00:12:06 182,272 ----a-w c:\windows\system32\snmpsnap.dll
+ 2008-07-19 02:10:20 36,552 -c--a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-07-19 02:10:40 45,768 -c--a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
+ 2008-10-16 19:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2004-08-10 19:00:00 23,552 ----a-w c:\windows\system32\sort.exe
+ 2008-04-14 00:12:36 24,576 ----a-w c:\windows\system32\sort.exe
+ 2008-04-14 00:12:36 7,680 ----a-w c:\windows\system32\spdwnwxp.exe
- 2004-08-10 19:00:00 538,624 ----a-w c:\windows\system32\spider.exe
+ 2008-04-14 00:12:36 538,624 ----a-w c:\windows\system32\spider.exe
- 2004-08-10 19:00:00 12,800 ----a-w c:\windows\system32\spiisupd.exe
+ 2008-04-13 18:43:31 12,800 ----a-w c:\windows\system32\spiisupd.exe
+ 2006-06-29 17:07:36 14,048 ------w c:\windows\system32\spmsg2.dll
- 2004-08-10 19:00:00 11,776 ----a-w c:\windows\system32\spnpinst.exe
+ 2008-04-14 09:42:38 11,264 ----a-w c:\windows\system32\spnpinst.exe
+ 2008-05-28 16:33:00 33,080 ----a-w c:\windows\system32\spool\drivers\w32x86\3\LMIprinter.dll
+ 2008-05-28 16:33:04 43,320 -c--a-w c:\windows\system32\spool\drivers\w32x86\3\LMIprinterdat.dll
+ 2008-05-28 16:33:04 43,320 -c--a-w c:\windows\system32\spool\drivers\w32x86\3\LMIprinterui.dll
+ 2007-03-23 00:24:50 762,880 ----a-w c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
+ 2007-03-23 00:24:34 131,584 ----a-w c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
- 2003-05-05 20:47:20 129,024 ----a-w c:\windows\system32\spool\drivers\w32x86\3\Ps5ui.dll
+ 2008-04-14 00:12:03 728,576 ----a-w c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
- 2003-05-05 20:47:20 455,168 ----a-w c:\windows\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL
+ 2008-04-14 00:12:03 543,232 ----a-w c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
+ 2007-03-23 00:24:06 376,832 -c--a-w c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2007-03-23 01:03:54 749,568 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
+ 2007-03-23 01:03:58 761,344 ----a-w c:\windows\system32\spool\drivers\w32x86\3\unires.dll
+ 2007-03-23 10:07:56 1,683,280 -c--a-w c:\windows\system32\spool\drivers\w32x86\3\XpsSvcs.dll
+ 2008-05-28 16:33:00 33,080 -c--a-w c:\windows\system32\spool\drivers\w32x86\LMIprinter.dll
+ 2008-05-28 16:33:04 43,320 -c--a-w c:\windows\system32\spool\drivers\w32x86\LMIprinterdat.dll
+ 2008-05-28 16:33:04 43,320 -c--a-w c:\windows\system32\spool\drivers\w32x86\LMIprinterui.dll
+ 2006-10-14 20:43:18 27,648 ----a-w c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
+ 2008-05-28 16:33:06 47,416 ----a-w c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
+ 2007-03-23 00:25:42 677,376 -c----w c:\windows\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe
+ 2006-10-14 21:13:02 34,304 -c--a-w c:\windows\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
+ 2007-03-23 00:53:16 746,496 -c--a-w c:\windows\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
+ 2007-03-23 00:59:24 2,932,224 -c--a-w c:\windows\system32\spool\XPSEP\amd64\amd64\xpssvcs.dll
+ 2007-03-23 00:53:16 746,496 -c--a-w c:\windows\system32\spool\XPSEP\amd64\mxdwdrv.dll
+ 2007-03-23 00:59:24 2,932,224 -c--a-w c:\windows\system32\spool\XPSEP\amd64\xpssvcs.dll
+ 2007-03-23 00:24:50 762,880 -c--a-w c:\windows\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
+ 2007-03-23 10:07:56 1,683,280 -c--a-w c:\windows\system32\spool\XPSEP\i386\i386\xpssvcs.dll
+ 2007-03-23 00:24:50 762,880 -c--a-w c:\windows\system32\spool\XPSEP\i386\mxdwdrv.dll
+ 2007-03-23 10:07:56 1,683,280 -c--a-w c:\windows\system32\spool\XPSEP\i386\xpssvcs.dll
- 2004-08-10 19:00:00 74,752 ----a-w c:\windows\system32\spoolss.dll
+ 2008-04-14 00:12:06 75,264 ----a-w c:\windows\system32\spoolss.dll
- 2005-06-10 23:53:32 57,856 ----a-w c:\windows\system32\spoolsv.exe
+ 2008-04-14 00:12:36 57,856 ----a-w c:\windows\system32\spoolsv.exe
- 2006-09-25 21:58:48 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-08-11 00:46:18 26,488 ----a-w c:\windows\system32\spupdsvc.exe
+ 2008-04-14 00:12:36 20,992 ------w c:\windows\system32\spupdwxp.exe
- 2004-08-10 19:00:00 442,368 ----a-w c:\windows\system32\sqlsrv32.dll
+ 2008-04-14 00:12:06 442,368 ----a-w c:\windows\system32\sqlsrv32.dll
- 2004-08-10 19:00:00 180,800 ----a-w c:\windows\system32\sqlunirl.dll
+ 2008-04-14 00:12:06 180,800 ----a-w c:\windows\system32\sqlunirl.dll
- 2004-08-10 19:00:00 67,584 ----a-w c:\windows\system32\srclient.dll
+ 2008-04-14 00:12:07 67,584 ----a-w c:\windows\system32\srclient.dll
- 2004-08-10 19:00:00 239,104 ----a-w c:\windows\system32\srrstr.dll
+ 2008-04-14 00:12:07 239,104 ----a-w c:\windows\system32\srrstr.dll
- 2004-08-10 19:00:00 170,496 ----a-w c:\windows\system32\srsvc.dll
+ 2008-04-14 00:12:07 171,008 ----a-w c:\windows\system32\srsvc.dll
- 2004-12-07 19:32:34 96,768 ----a-w c:\windows\system32\srvsvc.dll
+ 2008-04-14 00:12:07 96,768 ----a-w c:\windows\system32\srvsvc.dll
- 2004-08-10 19:00:00 704,512 ----a-w c:\windows\system32\ss3dfo.scr
+ 2008-04-14 00:12:43 704,512 ----a-w c:\windows\system32\ss3dfo.scr
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\ssbezier.scr
+ 2008-04-14 00:12:43 19,968 ----a-w c:\windows\system32\ssbezier.scr
- 2004-08-10 19:00:00 34,816 ----a-w c:\windows\system32\ssdpapi.dll
+ 2008-04-14 00:12:07 34,816 ----a-w c:\windows\system32\ssdpapi.dll
- 2004-08-10 19:00:00 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
+ 2008-04-14 00:12:07 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
- 2004-08-10 19:00:00 393,216 ----a-w c:\windows\system32\ssflwbox.scr
+ 2008-04-14 00:12:43 393,216 ----a-w c:\windows\system32\ssflwbox.scr
- 2008-03-21 20:30:00 200,704 ----a-w c:\windows\system32\ssldivx.dll
+ 2007-01-03 21:58:03 200,704 ----a-w c:\windows\system32\ssldivx.dll
- 2004-08-10 19:00:00 20,992 ----a-w c:\windows\system32\ssmarque.scr
+ 2008-04-14 00:12:44 20,992 ----a-w c:\windows\system32\ssmarque.scr
- 2004-08-10 19:00:00 47,104 ----a-w c:\windows\system32\ssmypics.scr
+ 2008-04-14 00:12:44 47,104 ----a-w c:\windows\system32\ssmypics.scr
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\ssmyst.scr
+ 2008-04-14 00:12:44 18,944 ----a-w c:\windows\system32\ssmyst.scr
- 2004-08-10 19:00:00 610,304 ----a-w c:\windows\system32\sspipes.scr
+ 2008-04-14 00:12:44 610,304 ----a-w c:\windows\system32\sspipes.scr
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\ssstars.scr
+ 2008-04-14 00:12:44 14,336 ----a-w c:\windows\system32\ssstars.scr
- 2004-08-10 19:00:00 679,936 ----a-w c:\windows\system32\sstext3d.scr
+ 2008-04-14 00:12:44 679,936 ----a-w c:\windows\system32\sstext3d.scr
- 2004-08-10 19:00:00 54,272 ----a-w c:\windows\system32\stclient.dll
+ 2008-04-14 00:12:07 59,392 ----a-w c:\windows\system32\stclient.dll
- 2004-08-10 19:00:00 67,584 ----a-w c:\windows\system32\sti.dll
+ 2008-04-14 00:12:07 68,096 ----a-w c:\windows\system32\sti.dll
- 2004-08-10 19:00:00 136,704 ----a-w c:\windows\system32\sti_ci.dll
+ 2008-04-14 00:12:07 136,704 ----a-w c:\windows\system32\sti_ci.dll
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\stimon.exe
+ 2008-04-14 00:12:36 14,848 ----a-w c:\windows\system32\stimon.exe
- 2004-08-10 19:00:00 121,856 ----a-w c:\windows\system32\stobject.dll
+ 2008-04-14 00:12:07 121,856 ----a-w c:\windows\system32\stobject.dll
- 2004-08-04 00:56:46 74,752 ----a-w c:\windows\system32\storprop.dll
+ 2008-04-14 00:12:07 74,752 ----a-w c:\windows\system32\storprop.dll
- 2006-08-21 14:52:08 246,814 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:02:42 247,326 ----a-w c:\windows\system32\strmdll.dll
- 2004-08-10 19:00:00 75,776 ----a-w c:\windows\system32\strmfilt.dll
+ 2008-04-14 00:12:07 75,776 ----a-w c:\windows\system32\strmfilt.dll
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\svchost.exe
+ 2008-04-14 00:12:36 14,336 ----a-w c:\windows\system32\svchost.exe
- 2006-10-19 13:56:32 713,216 ----a-w c:\windows\system32\sxs.dll
+ 2008-04-14 00:12:07 713,216 ----a-w c:\windows\system32\sxs.dll
- 2004-08-10 19:00:00 57,856 ----a-w c:\windows\system32\synceng.dll
+ 2008-04-14 00:12:07 57,856 ----a-w c:\windows\system32\synceng.dll
- 2004-08-10 19:00:00 191,488 ----a-w c:\windows\system32\syncui.dll
+ 2008-04-14 00:12:07 191,488 ----a-w c:\windows\system32\syncui.dll
- 2004-08-10 19:00:00 105,984 ----a-w c:\windows\system32\sysocmgr.exe
+ 2008-04-14 00:12:37 106,496 ----a-w c:\windows\system32\sysocmgr.exe
- 2004-08-10 19:00:00 984,576 ----a-w c:\windows\system32\syssetup.dll
+ 2008-04-14 00:12:07 990,208 ----a-w c:\windows\system32\syssetup.dll
- 2004-08-10 19:00:00 68,096 ----a-w c:\windows\system32\systeminfo.exe
+ 2008-04-14 00:12:36 71,680 ----a-w c:\windows\system32\systeminfo.exe
- 2005-10-17 21:14:46 118,272 ----a-w c:\windows\system32\t2embed.dll
+ 2008-04-14 00:12:07 117,760 ----a-w c:\windows\system32\t2embed.dll
+ 1998-07-06 06:00:00 22,528 ----a-w c:\windows\system32\TABCTDE.DLL
- 2004-08-10 19:00:00 858,624 ----a-w c:\windows\system32\tapi3.dll
+ 2008-04-14 00:12:07 858,624 ----a-w c:\windows\system32\tapi3.dll
- 2004-08-10 19:00:00 181,760 ----a-w c:\windows\system32\tapi32.dll
+ 2008-04-14 00:12:07 181,760 ----a-w c:\windows\system32\tapi32.dll
- 2005-07-08 16:27:56 249,344 ----a-w c:\windows\system32\tapisrv.dll
+ 2008-04-14 00:12:07 249,856 ----a-w c:\windows\system32\tapisrv.dll
- 2004-08-10 19:00:00 72,192 ----a-w c:\windows\system32\taskkill.exe
+ 2008-04-14 00:12:37 76,288 ----a-w c:\windows\system32\taskkill.exe
- 2004-08-10 19:00:00 72,192 ----a-w c:\windows\system32\tasklist.exe
+ 2008-04-14 00:12:37 77,824 ----a-w c:\windows\system32\tasklist.exe
- 2004-08-10 19:00:00 135,680 ----a-w c:\windows\system32\taskmgr.exe
+ 2008-04-14 00:12:37 135,680 ----a-w c:\windows\system32\taskmgr.exe
- 2004-08-10 19:00:00 14,848 ----a-w c:\windows\system32\tcpmib.dll
+ 2008-04-14 00:12:07 14,848 ----a-w c:\windows\system32\tcpmib.dll
- 2004-08-10 19:00:00 45,568 ----a-w c:\windows\system32\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 ----a-w c:\windows\system32\tcpmon.dll
- 2004-08-10 19:00:00 45,568 ----a-w c:\windows\system32\tcpmonui.dll
+ 2008-04-14 00:12:07 45,568 ----a-w c:\windows\system32\tcpmonui.dll
- 2005-05-10 23:45:48 75,776 ----a-w c:\windows\system32\telnet.exe
+ 2008-04-14 00:12:37 75,776 ----a-w c:\windows\system32\telnet.exe
- 2004-08-10 19:00:00 358,400 ----a-w c:\windows\system32\termmgr.dll
+ 2008-04-14 00:12:07 358,400 ----a-w c:\windows\system32\termmgr.dll
- 2005-03-10 14:49:51 295,424 ----a-w c:\windows\system32\termsrv.dll
+ 2008-04-15 15:17:37 295,424 ----a-w c:\windows\system32\termsrv.dll
- 2004-08-10 19:00:00 385,536 ----a-w c:\windows\system32\themeui.dll
+ 2008-04-14 00:12:07 385,536 ----a-w c:\windows\system32\themeui.dll
- 2004-08-10 19:00:00 61,440 ----a-w c:\windows\system32\tlntadmn.exe
+ 2008-04-14 00:12:37 61,440 ----a-w c:\windows\system32\tlntadmn.exe
- 2004-08-10 19:00:00 78,336 ----a-w c:\windows\system32\tlntsess.exe
+ 2008-04-14 00:12:37 78,336 ----a-w c:\windows\system32\tlntsess.exe
- 2004-08-10 19:00:00 73,216 ----a-w c:\windows\system32\tlntsvr.exe
+ 2008-04-14 00:12:38 73,216 ----a-w c:\windows\system32\tlntsvr.exe
- 2004-08-10 19:00:00 7,168 ----a-w c:\windows\system32\tlntsvrp.dll
+ 2008-04-14 00:12:07 7,168 ----a-w c:\windows\system32\tlntsvrp.dll
- 2004-08-10 19:00:00 347,136 ----a-w c:\windows\system32\tourstart.exe
+ 2008-04-14 00:12:38 347,136 ----a-w c:\windows\system32\tourstart.exe
- 2004-08-10 19:00:00 259,584 ----a-w c:\windows\system32\tracerpt.exe
+ 2008-04-14 00:12:38 259,584 ----a-w c:\windows\system32\tracerpt.exe
- 2004-08-10 19:00:00 12,288 ----a-w c:\windows\system32\tracert.exe
+ 2008-04-14 00:12:38 12,288 ----a-w c:\windows\system32\tracert.exe
- 2004-08-10 19:00:00 11,264 ----a-w c:\windows\system32\tree.com
+ 2008-04-14 00:12:42 12,800 ----a-w c:\windows\system32\tree.com
- 2004-08-10 19:00:00 90,624 ----a-w c:\windows\system32\trkwks.dll
+ 2008-04-14 00:12:07 90,112 ----a-w c:\windows\system32\trkwks.dll
- 2004-08-10 19:00:00 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
+ 2008-04-14 00:12:07 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
- 2004-08-10 19:00:00 12,168 ----a-w c:\windows\system32\tsddd.dll
+ 2008-04-14 00:13:21 12,168 ----a-w c:\windows\system32\tsddd.dll
+ 2008-04-14 00:12:07 53,248 ------w c:\windows\system32\tsgqec.dll
+ 2008-04-14 00:12:07 50,688 ------w c:\windows\system32\tspkg.dll
+ 2007-10-09 16:58:20 16,896 ----a-w c:\windows\system32\tswpfwrp.exe
- 2004-08-10 19:00:00 44,032 ----a-w c:\windows\system32\twext.dll
+ 2008-04-14 00:12:07 57,856 ----a-w c:\windows\system32\twext.dll
- 2005-07-26 04:39:49 101,376 ----a-w c:\windows\system32\txflog.dll
+ 2008-04-14 00:12:07 101,376 ----a-w c:\windows\system32\txflog.dll
- 2007-11-13 11:31:11 60,416 ------w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 ------w c:\windows\system32\tzchange.exe
- 2004-08-10 19:00:00 25,600 ----a-w c:\windows\system32\udhisapi.dll
+ 2008-04-14 00:12:07 26,624 ----a-w c:\windows\system32\udhisapi.dll
+ 2007-10-09 17:03:08 161,304 ----a-w c:\windows\system32\UIAutomationCore.dll
- 2004-08-10 19:00:00 275,456 ----a-w c:\windows\system32\ulib.dll
+ 2008-04-14 00:12:07 275,456 ----a-w c:\windows\system32\ulib.dll
- 2004-08-10 19:00:00 35,840 ----a-w c:\windows\system32\umandlg.dll
+ 2008-04-14 00:12:07 35,840 ----a-w c:\windows\system32\umandlg.dll
- 2005-08-23 03:35:42 123,392 ----a-w c:\windows\system32\umpnpmgr.dll
+ 2008-04-14 00:12:07 123,392 ----a-w c:\windows\system32\umpnpmgr.dll
- 2004-08-10 19:00:00 74,240 ----a-w c:\windows\system32\unimdmat.dll
+ 2008-04-14 00:12:07 74,240 ----a-w c:\windows\system32\unimdmat.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\uniplat.dll
+ 2008-04-14 00:12:07 13,824 ----a-w c:\windows\system32\uniplat.dll
- 2004-08-10 19:00:00 316,416 ----a-w c:\windows\system32\untfs.dll
+ 2008-04-14 00:12:07 316,416 ----a-w c:\windows\system32\untfs.dll
- 2004-08-10 19:00:00 132,608 ----a-w c:\windows\system32\upnp.dll
+ 2008-04-14 00:12:08 133,632 ----a-w c:\windows\system32\upnp.dll
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\upnpcont.exe
+ 2008-04-14 00:12:38 16,896 ----a-w c:\windows\system32\upnpcont.exe
- 2007-02-05 20:17:02 185,344 ----a-w c:\windows\system32\upnphost.dll
+ 2008-04-14 00:12:08 185,856 ----a-w c:\windows\system32\upnphost.dll
- 2004-08-10 19:00:00 239,616 ----a-w c:\windows\system32\upnpui.dll
+ 2008-04-14 00:12:08 239,616 ----a-w c:\windows\system32\upnpui.dll
- 2004-08-10 19:00:00 18,432 ----a-w c:\windows\system32\ups.exe
+ 2008-04-14 00:12:38 18,432 ----a-w c:\windows\system32\ups.exe
- 2008-04-23 04:16:28 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
- 2008-04-23 04:16:29 1,159,680 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\usbmon.dll
+ 2008-04-14 00:12:08 16,896 ----a-w c:\windows\system32\usbmon.dll
- 2004-08-04 00:56:48 74,240 ----a-w c:\windows\system32\usbui.dll
+ 2008-04-14 00:12:08 74,240 ----a-w c:\windows\system32\usbui.dll
- 2007-03-08 15:36:28 577,536 ----a-w c:\windows\system32\user32.dll
+ 2008-04-14 00:12:08 578,560 ----a-w c:\windows\system32\user32.dll
- 2004-08-10 19:00:00 723,456 ----a-w c:\windows\system32\userenv.dll
+ 2008-04-14 00:12:08 727,040 ----a-w c:\windows\system32\userenv.dll
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-14 00:12:38 26,112 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-13 16:44:16 17,920 -c----w c:\windows\system32\usmt\cobramsg.dll
- 2004-08-10 19:00:00 123,904 ----a-w c:\windows\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 133,120 -c--a-w c:\windows\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 115,200 -c----w c:\windows\system32\usmt\guitrna.dll
- 2004-08-10 19:00:00 4,096 ----a-w c:\windows\system32\usmt\iconlib.dll
+ 2008-04-13 16:44:29 2,560 -c--a-w c:\windows\system32\usmt\iconlib.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\usmt\log.dll
+ 2008-04-14 00:11:56 19,968 -c--a-w c:\windows\system32\usmt\log.dll
- 2004-08-10 19:00:00 201,216 ----a-w c:\windows\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 274,432 -c--a-w c:\windows\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 261,120 -c----w c:\windows\system32\usmt\migisma.dll
- 2004-08-10 19:00:00 103,424 ----a-w c:\windows\system32\usmt\migload.exe
+ 2008-04-14 00:12:25 103,936 -c--a-w c:\windows\system32\usmt\migload.exe
- 2004-08-10 19:00:00 240,128 ----a-w c:\windows\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 245,248 ----a-w c:\windows\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 241,152 -c----w c:\windows\system32\usmt\migwiza.exe
- 2004-08-10 19:00:00 202,752 ----a-w c:\windows\system32\usmt\script.dll
+ 2008-04-14 00:12:05 215,552 -c--a-w c:\windows\system32\usmt\script.dll
+ 2008-04-14 00:12:05 199,680 -c----w c:\windows\system32\usmt\scripta.dll
- 2004-08-10 19:00:00 168,960 ----a-w c:\windows\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 193,024 -c--a-w c:\windows\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 173,568 -c----w c:\windows\system32\usmt\sysmoda.dll
- 2004-08-10 19:00:00 406,528 ----a-w c:\windows\system32\usp10.dll
+ 2008-04-14 00:12:08 406,016 ----a-w c:\windows\system32\usp10.dll
- 2004-08-10 19:00:00 50,176 ----a-w c:\windows\system32\utilman.exe
+ 2008-04-14 00:12:38 50,176 ----a-w c:\windows\system32\utilman.exe
- 2004-08-10 19:00:00 218,624 ----a-w c:\windows\system32\uxtheme.dll
+ 2008-04-14 00:12:08 218,624 ----a-w c:\windows\system32\uxtheme.dll
+ 1998-07-06 06:00:00 125,712 ----a-w c:\windows\system32\VB6DE.DLL
- 2004-08-10 19:00:00 30,749 ----a-w c:\windows\system32\vbajet32.dll
+ 2008-04-14 00:12:08 30,749 ----a-w c:\windows\system32\vbajet32.dll
- 2007-08-13 23:54:10 413,696 ----a-w c:\windows\system32\vbscript.dll
+ 2008-05-09 10:53:40 430,080 ----a-w c:\windows\system32\vbscript.dll
- 2004-08-10 19:00:00 26,112 ----a-w c:\windows\system32\vdmdbg.dll
+ 2008-04-14 00:12:08 26,112 ----a-w c:\windows\system32\vdmdbg.dll
- 2004-08-10 19:00:00 51,712 ----a-w c:\windows\system32\vdmredir.dll
+ 2008-04-14 00:12:08 51,712 ----a-w c:\windows\system32\vdmredir.dll
- 2006-03-17 00:38:01 28,672 ------w c:\windows\system32\verclsid.exe
+ 2008-04-14 00:12:38 28,672 ------w c:\windows\system32\verclsid.exe
- 2004-08-10 19:00:00 13,312 ----a-w c:\windows\system32\verifier.dll
+ 2008-04-14 00:12:08 26,624 ----a-w c:\windows\system32\verifier.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\version.dll
+ 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\version.dll
+ 2008-04-14 00:12:08 53,760 ----a-w c:\windows\system32\vfwwdm32.dll
- 2004-08-10 19:00:00 430,592 ----a-w c:\windows\system32\vssapi.dll
+ 2008-04-14 00:12:08 430,592 ----a-w c:\windows\system32\vssapi.dll
- 2004-08-10 19:00:00 289,792 ----a-w c:\windows\system32\vssvc.exe
+ 2008-04-14 00:12:38 289,792 ----a-w c:\windows\system32\vssvc.exe
- 2004-08-10 19:00:00 174,592 ----a-w c:\windows\system32\w32time.dll
+ 2008-04-14 00:12:08 175,104 ----a-w c:\windows\system32\w32time.dll
- 2004-08-10 19:00:00 15,872 ----a-w c:\windows\system32\w3ssl.dll
+ 2008-04-14 00:12:08 15,872 ----a-w c:\windows\system32\w3ssl.dll
- 2004-08-10 19:00:00 17,664 ----a-w c:\windows\system32\watchdog.sys
+ 2008-04-13 18:44:59 17,664 ----a-w c:\windows\system32\watchdog.sys
- 2004-08-10 19:00:00 208,896 ----a-w c:\windows\system32\wavemsp.dll
+ 2008-04-14 00:12:08 215,552 ----a-w c:\windows\system32\wavemsp.dll
- 2004-08-10 19:00:00 1,352,192 ----a-w c:\windows\system32\wbem\cimwin32.dll
+ 2008-04-14 00:11:50 1,358,848 ----a-w c:\windows\system32\wbem\cimwin32.dll
- 2004-08-10 19:00:00 45,568 ----a-w c:\windows\system32\wbem\CmdEvTgProv.dll
+ 2008-04-14 00:11:53 45,056 -c--a-w c:\windows\system32\wbem\cmdevtgprov.dll
- 2004-08-10 19:00:00 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
+ 2008-04-14 00:11:53 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
- 2004-08-10 19:00:00 22,016 ----a-w c:\windows\system32\wbem\evntrprv.dll
+ 2008-04-14 00:11:53 21,504 -c--a-w c:\windows\system32\wbem\evntrprv.dll
- 2004-08-10 19:00:00 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
+ 2008-04-14 00:11:53 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
- 2004-08-10 19:00:00 185,856 ----a-w c:\windows\system32\wbem\framedyn.dll
+ 2008-04-14 00:11:53 185,344 ----a-w c:\windows\system32\wbem\framedyn.dll
- 2004-08-10 19:00:00 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll
+ 2008-04-14 00:11:56 24,576 -c--a-w c:\windows\system32\wbem\krnlprov.dll
- 2004-08-10 19:00:00 16,384 ----a-w c:\windows\system32\wbem\mofcomp.exe
+ 2008-04-14 00:12:26 16,384 -c--a-w c:\windows\system32\wbem\mofcomp.exe
- 2004-08-10 19:00:00 123,904 ----a-w c:\windows\system32\wbem\mofd.dll
+ 2008-04-14 00:11:57 123,904 ----a-w c:\windows\system32\wbem\mofd.dll
- 2004-08-10 19:00:00 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
+ 2008-04-14 00:12:01 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
- 2004-08-10 19:00:00 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll
+ 2008-04-14 00:12:02 212,992 -c--a-w c:\windows\system32\wbem\ntevt.dll
- 2004-08-10 19:00:00 92,672 ----a-w c:\windows\system32\wbem\policman.dll
+ 2008-04-14 00:12:02 92,672 -c--a-w c:\windows\system32\wbem\policman.dll
- 2004-08-10 19:00:00 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll
+ 2008-04-14 00:12:03 237,056 -c--a-w c:\windows\system32\wbem\provthrd.dll
- 2004-08-10 19:00:00 177,152 ----a-w c:\windows\system32\wbem\repdrvfs.dll
+ 2008-04-14 00:12:04 178,176 ----a-w c:\windows\system32\wbem\repdrvfs.dll
- 2004-08-10 19:00:00 36,864 ----a-w c:\windows\system32\wbem\scrcons.exe
+ 2008-04-14 00:12:34 36,352 -c--a-w c:\windows\system32\wbem\scrcons.exe
- 2004-08-10 19:00:00 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll
+ 2008-04-14 00:12:07 86,528 -c--a-w c:\windows\system32\wbem\stdprov.dll
- 2004-08-10 19:00:00 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
+ 2008-04-14 00:12:08 131,584 -c--a-w c:\windows\system32\wbem\viewprov.dll
- 2004-08-10 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
+ 2008-04-14 00:12:08 196,608 -c--a-w c:\windows\system32\wbem\wbemcntl.dll
- 2004-08-10 19:00:00 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
+ 2008-04-14 00:12:08 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
- 2004-08-10 19:00:00 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
+ 2008-04-14 00:12:08 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
- 2004-08-10 19:00:00 530,944 ----a-w c:\windows\system32\wbem\wbemcore.dll
+ 2008-04-14 00:12:08 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll
- 2004-08-10 19:00:00 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
+ 2008-04-14 00:12:08 178,176 -c--a-w c:\windows\system32\wbem\wbemdisp.dll
- 2004-08-10 19:00:00 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
+ 2008-04-14 00:12:08 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
- 2004-08-10 19:00:00 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
+ 2008-04-14 00:12:08 43,008 -c--a-w c:\windows\system32\wbem\wbemperf.dll
- 2004-08-10 19:00:00 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
+ 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
- 2004-08-10 19:00:00 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
+ 2008-04-14 00:12:08 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
- 2004-08-10 19:00:00 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
+ 2008-04-14 00:12:39 116,224 -c--a-w c:\windows\system32\wbem\wbemtest.exe
- 2004-08-10 19:00:00 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
+ 2008-04-14 00:12:08 197,120 -c--a-w c:\windows\system32\wbem\wbemupgd.dll
- 2004-08-10 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
+ 2008-04-14 00:12:40 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
+ 2008-04-13 17:10:20 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
- 2004-08-10 19:00:00 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
+ 2008-04-14 00:12:09 88,576 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
- 2004-08-10 19:00:00 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
+ 2008-04-14 00:12:40 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
- 2004-08-10 19:00:00 358,912 ----a-w c:\windows\system32\wbem\wmic.exe
+ 2008-04-14 00:12:40 358,912 ----a-w c:\windows\system32\wbem\wmic.exe
- 2004-08-10 19:00:00 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
+ 2008-04-14 00:12:09 60,928 -c--a-w c:\windows\system32\wbem\wmicookr.dll
- 2004-08-10 19:00:00 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll

EasyEEE
2008-12-29, 18:17
+ 2008-04-14 00:12:09 140,800 -c--a-w c:\windows\system32\wbem\wmidcprv.dll
- 2004-08-10 19:00:00 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
+ 2008-04-14 00:12:09 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
- 2004-08-10 19:00:00 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
+ 2008-04-14 00:12:09 132,096 -c--a-w c:\windows\system32\wbem\wmipdskq.dll
- 2004-08-10 19:00:00 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll
+ 2008-04-14 00:12:09 61,952 -c--a-w c:\windows\system32\wbem\wmipiprt.dll
- 2004-08-10 19:00:00 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll
+ 2008-04-14 00:12:09 62,464 -c--a-w c:\windows\system32\wbem\wmipjobj.dll
- 2004-08-10 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
+ 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
- 2004-08-10 19:00:00 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
+ 2008-04-14 00:12:09 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
- 2004-08-10 19:00:00 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
+ 2008-04-14 00:12:40 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
- 2004-08-10 19:00:00 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
+ 2008-04-14 00:12:09 41,472 -c--a-w c:\windows\system32\wbem\wmipsess.dll
- 2004-08-10 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
+ 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
- 2004-08-10 19:00:00 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
+ 2008-04-14 00:12:09 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
- 2006-03-24 04:37:50 49,152 ----a-w c:\windows\system32\wdigest.dll
+ 2008-04-14 00:12:08 49,152 ----a-w c:\windows\system32\wdigest.dll
- 2004-08-04 00:56:58 23,552 ----a-w c:\windows\system32\wdmaud.drv
+ 2008-04-14 00:12:45 23,552 ----a-w c:\windows\system32\wdmaud.drv
- 2008-04-23 04:16:29 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2006-01-04 03:35:05 68,096 ----a-w c:\windows\system32\webclnt.dll
+ 2008-04-14 00:12:08 68,096 ----a-w c:\windows\system32\webclnt.dll
- 2004-08-10 19:00:00 135,680 ----a-w c:\windows\system32\webvw.dll
+ 2008-04-14 00:12:08 135,680 ----a-w c:\windows\system32\webvw.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\wextract.exe
+ 2008-04-14 00:12:39 65,024 ----a-w c:\windows\system32\wextract.exe
- 2004-08-10 19:00:00 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
+ 2008-04-14 00:12:39 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
- 2004-08-10 19:00:00 463,360 ----a-w c:\windows\system32\wiadefui.dll
+ 2008-04-14 00:12:08 463,360 ----a-w c:\windows\system32\wiadefui.dll
- 2004-08-10 19:00:00 124,416 ----a-w c:\windows\system32\wiadss.dll
+ 2008-04-14 00:12:08 124,416 ----a-w c:\windows\system32\wiadss.dll
- 2004-08-10 19:00:00 75,776 ----a-w c:\windows\system32\wiascr.dll
+ 2008-04-14 00:12:08 75,776 ----a-w c:\windows\system32\wiascr.dll
- 2006-12-19 18:16:47 333,824 ----a-w c:\windows\system32\wiaservc.dll
+ 2008-04-14 00:12:08 333,824 ----a-w c:\windows\system32\wiaservc.dll
- 2004-08-10 19:00:00 589,312 ----a-w c:\windows\system32\wiashext.dll
+ 2008-04-14 00:12:08 589,312 ----a-w c:\windows\system32\wiashext.dll
- 2004-08-10 19:00:00 111,104 ----a-w c:\windows\system32\wiavideo.dll
+ 2008-04-14 00:12:08 111,104 ----a-w c:\windows\system32\wiavideo.dll
- 2008-03-19 09:47:00 1,845,248 ----a-w c:\windows\system32\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 ----a-w c:\windows\system32\win32k.sys
- 2004-08-10 19:00:00 101,888 ----a-w c:\windows\system32\win32spl.dll
+ 2008-04-14 00:12:08 102,400 ----a-w c:\windows\system32\win32spl.dll
- 2004-08-10 19:00:00 937,984 ----a-w c:\windows\system32\winbrand.dll
+ 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll
+ 2008-04-14 00:12:08 712,704 ------w c:\windows\system32\windowscodecs.dll
+ 2008-04-14 00:12:08 346,112 ------w c:\windows\system32\windowscodecsext.dll
- 2004-08-10 19:00:00 351,232 ----a-w c:\windows\system32\winhttp.dll
+ 2008-04-14 00:12:08 354,304 ----a-w c:\windows\system32\winhttp.dll
- 2008-04-23 04:16:29 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:38:40 826,368 ----a-w c:\windows\system32\wininet.dll
- 2004-08-10 19:00:00 32,768 ----a-w c:\windows\system32\winipsec.dll
+ 2008-04-14 00:12:09 32,256 ----a-w c:\windows\system32\winipsec.dll
- 2004-08-10 19:00:00 502,272 ----a-w c:\windows\system32\winlogon.exe
+ 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\winlogon.exe
- 2004-08-10 19:00:00 176,128 ----a-w c:\windows\system32\winmm.dll
+ 2008-04-14 00:12:09 176,128 ----a-w c:\windows\system32\winmm.dll
- 2004-08-10 19:00:00 764,928 ----a-w c:\windows\system32\winntbbu.dll
+ 2008-04-14 00:11:11 756,224 ----a-w c:\windows\system32\winntbbu.dll
- 2004-08-10 19:00:00 16,896 ----a-w c:\windows\system32\winrnr.dll
+ 2008-04-14 00:12:09 16,896 ----a-w c:\windows\system32\winrnr.dll
- 2004-08-10 19:00:00 99,328 ----a-w c:\windows\system32\winscard.dll
+ 2008-04-14 00:12:09 99,328 ----a-w c:\windows\system32\winscard.dll
- 2004-08-10 19:00:00 17,408 ----a-w c:\windows\system32\winshfhc.dll
+ 2008-04-14 00:12:09 17,408 ----a-w c:\windows\system32\winshfhc.dll
- 2004-08-10 19:00:00 146,432 ----a-w c:\windows\system32\winspool.drv
+ 2008-04-14 00:12:45 146,432 ----a-w c:\windows\system32\winspool.drv
- 2007-03-17 13:43:01 292,864 ----a-w c:\windows\system32\winsrv.dll
+ 2008-04-14 00:12:09 293,376 ----a-w c:\windows\system32\winsrv.dll
- 2004-08-10 19:00:00 53,760 ----a-w c:\windows\system32\winsta.dll
+ 2008-04-14 00:12:09 53,760 ----a-w c:\windows\system32\winsta.dll
- 2004-08-10 19:00:00 176,640 ----a-w c:\windows\system32\wintrust.dll
+ 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\wintrust.dll
- 2004-08-10 19:00:00 5,632 ----a-w c:\windows\system32\winver.exe
+ 2008-04-14 00:12:40 5,632 ----a-w c:\windows\system32\winver.exe
- 2006-08-17 12:28:27 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2008-04-14 00:12:09 69,120 ------w c:\windows\system32\wlanapi.dll
- 2004-08-10 19:00:00 172,032 ----a-w c:\windows\system32\wldap32.dll
+ 2008-04-14 00:12:09 172,032 ----a-w c:\windows\system32\wldap32.dll
- 2004-08-10 19:00:00 92,672 ----a-w c:\windows\system32\wlnotify.dll
+ 2008-04-14 00:12:09 92,672 ----a-w c:\windows\system32\wlnotify.dll
- 2004-08-10 19:00:00 5,632 ----a-w c:\windows\system32\wmi.dll
+ 2008-04-14 00:11:15 5,632 ----a-w c:\windows\system32\wmi.dll
- 2006-10-19 01:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll
+ 2008-06-18 10:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\wmpcd.dll
+ 2008-04-14 00:12:09 20,480 ----a-w c:\windows\system32\wmpcd.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\wmpcore.dll
+ 2008-04-14 00:12:09 20,480 ----a-w c:\windows\system32\wmpcore.dll
- 2006-10-19 01:47:20 295,936 ------w c:\windows\system32\wmpeffects.dll
+ 2008-06-24 22:12:58 295,936 ------w c:\windows\system32\wmpeffects.dll
+ 2008-04-14 00:12:09 276,992 ------w c:\windows\system32\wmphoto.dll
- 2004-08-10 19:00:00 20,480 ----a-w c:\windows\system32\wmpui.dll
+ 2008-04-14 00:12:09 20,480 ----a-w c:\windows\system32\wmpui.dll
- 2004-08-10 19:00:00 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
+ 2008-04-14 00:12:09 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
- 2004-08-10 19:00:00 303,616 ----a-w c:\windows\system32\wmstream.dll
+ 2008-04-14 00:12:10 303,616 ----a-w c:\windows\system32\wmstream.dll
- 2006-10-19 01:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
+ 2007-08-13 18:51:04 446,464 ----a-w c:\windows\system32\wmvdmoe.dll
- 2004-08-10 19:00:00 264,192 ----a-w c:\windows\system32\wow32.dll
+ 2008-04-14 00:12:10 264,192 ----a-w c:\windows\system32\wow32.dll
- 2004-08-10 19:00:00 32,256 ----a-w c:\windows\system32\wpabaln.exe
+ 2008-04-14 00:12:40 32,256 ----a-w c:\windows\system32\wpabaln.exe
- 2004-08-10 19:00:00 32,256 ----a-w c:\windows\system32\wpnpinst.exe
+ 2008-04-14 00:12:41 11,264 ----a-w c:\windows\system32\wpnpinst.exe
- 2004-08-10 19:00:00 82,944 ----a-w c:\windows\system32\ws2_32.dll
+ 2008-04-14 00:12:10 82,432 ----a-w c:\windows\system32\ws2_32.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\ws2help.dll
+ 2008-04-14 00:12:10 19,968 ----a-w c:\windows\system32\ws2help.dll
- 2004-08-10 19:00:00 13,824 ----a-w c:\windows\system32\wscntfy.exe
+ 2008-04-14 00:12:41 13,824 ----a-w c:\windows\system32\wscntfy.exe
- 2004-08-10 19:00:00 114,688 ----a-w c:\windows\system32\wscript.exe
+ 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe
- 2004-08-10 19:00:00 81,408 ----a-w c:\windows\system32\wscsvc.dll
+ 2008-04-14 00:12:10 80,896 ----a-w c:\windows\system32\wscsvc.dll
- 2004-08-10 19:00:00 596,992 ----a-w c:\windows\system32\wsecedit.dll
+ 2008-04-14 00:12:10 604,160 ----a-w c:\windows\system32\wsecedit.dll
- 2004-08-10 19:00:00 108,032 ----a-w c:\windows\system32\wshbth.dll
+ 2008-04-14 00:12:10 108,032 ----a-w c:\windows\system32\wshbth.dll
- 2004-08-10 19:00:00 28,672 ----a-w c:\windows\system32\wshcon.dll
+ 2008-04-14 00:12:10 36,864 ----a-w c:\windows\system32\wshcon.dll
- 2004-08-10 19:00:00 65,536 ----a-w c:\windows\system32\wshext.dll
+ 2008-05-09 10:53:40 90,112 ----a-w c:\windows\system32\wshext.dll
- 2004-08-10 19:00:00 14,336 ----a-w c:\windows\system32\wship6.dll
+ 2008-04-14 00:12:10 14,336 ----a-w c:\windows\system32\wship6.dll
- 2004-08-10 19:00:00 11,776 ----a-w c:\windows\system32\WshRm.dll
+ 2008-04-14 00:12:10 11,264 ----a-w c:\windows\system32\wshrm.dll
- 2004-08-10 19:00:00 19,968 ----a-w c:\windows\system32\wshtcpip.dll
+ 2008-04-14 00:12:10 19,456 ----a-w c:\windows\system32\wshtcpip.dll
- 2004-08-10 19:00:00 42,496 ----a-w c:\windows\system32\wsnmp32.dll
+ 2008-04-14 00:12:10 41,984 ----a-w c:\windows\system32\wsnmp32.dll
- 2004-08-10 19:00:00 22,528 ----a-w c:\windows\system32\wsock32.dll
+ 2008-04-14 00:12:10 22,528 ----a-w c:\windows\system32\wsock32.dll
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\system32\wstdecod.dll
+ 2008-04-14 00:12:10 50,688 ----a-w c:\windows\system32\wstdecod.dll
- 2004-08-10 19:00:00 18,432 ----a-w c:\windows\system32\wtsapi32.dll
+ 2008-04-14 00:12:10 18,432 ----a-w c:\windows\system32\wtsapi32.dll
- 2007-07-31 00:19:36 549,720 ----a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 ----a-w c:\windows\system32\wuapi.dll
- 2007-07-31 00:19:16 53,080 ----a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 ----a-w c:\windows\system32\wuauclt.exe
- 2004-08-10 19:00:00 165,888 ----a-w c:\windows\system32\wuauclt1.exe
+ 2008-04-14 00:12:41 165,888 ----a-w c:\windows\system32\wuauclt1.exe
- 2007-07-31 00:19:42 1,712,984 ----a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
- 2004-08-10 19:00:00 183,296 ----a-w c:\windows\system32\wuaueng1.dll
+ 2008-04-14 00:12:11 183,296 ----a-w c:\windows\system32\wuaueng1.dll
- 2004-08-10 19:00:00 6,656 ----a-w c:\windows\system32\wuauserv.dll
+ 2008-04-14 00:12:11 6,656 ----a-w c:\windows\system32\wuauserv.dll
- 2007-07-31 00:19:32 325,976 ----a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 ----a-w c:\windows\system32\wucltui.dll
- 2007-07-31 00:18:40 33,624 ----a-w c:\windows\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\wups.dll
- 2007-07-31 00:19:12 43,352 ----a-w c:\windows\system32\wups2.dll
+ 2008-10-16 19:09:44 43,544 ----a-w c:\windows\system32\wups2.dll
- 2007-07-31 00:19:28 203,096 ----a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 19:13:40 202,776 ----a-w c:\windows\system32\wuweb.dll
- 2005-06-22 05:00:18 383,488 ----a-w c:\windows\system32\wzcdlg.dll
+ 2008-04-14 00:12:11 383,488 ----a-w c:\windows\system32\wzcdlg.dll
- 2005-06-22 05:00:18 52,736 ----a-w c:\windows\system32\wzcsapi.dll
+ 2008-04-14 00:12:11 52,736 ----a-w c:\windows\system32\wzcsapi.dll
- 2005-06-22 05:00:18 474,624 ----a-w c:\windows\system32\wzcsvc.dll
+ 2008-04-14 00:12:11 483,840 ----a-w c:\windows\system32\wzcsvc.dll
- 2004-08-10 19:00:00 91,648 ----a-w c:\windows\system32\xactsrv.dll
+ 2008-04-14 00:12:11 91,648 ----a-w c:\windows\system32\xactsrv.dll
- 2004-08-10 19:00:00 30,720 ----a-w c:\windows\system32\xcopy.exe
+ 2008-04-14 00:12:41 30,720 ----a-w c:\windows\system32\xcopy.exe
- 2006-07-14 15:51:51 121,856 ------w c:\windows\system32\xmllite.dll
+ 2008-04-14 00:12:11 121,856 ----a-w c:\windows\system32\xmllite.dll
- 2004-08-10 19:00:00 129,536 ----a-w c:\windows\system32\xmlprov.dll
+ 2008-04-14 00:12:11 129,024 ----a-w c:\windows\system32\xmlprov.dll
- 2004-08-10 19:00:00 50,176 ----a-w c:\windows\system32\xmlprovi.dll
+ 2008-04-14 00:12:11 50,176 ----a-w c:\windows\system32\xmlprovi.dll
- 2006-03-01 19:42:42 11,776 ----a-w c:\windows\system32\xolehlp.dll
+ 2008-04-14 00:12:11 11,776 ----a-w c:\windows\system32\xolehlp.dll
- 2004-08-10 19:00:00 438,784 ----a-w c:\windows\system32\xpob2res.dll
+ 2008-04-13 17:39:29 438,784 ----a-w c:\windows\system32\xpob2res.dll
- 2004-08-10 19:00:00 187,392 ----a-w c:\windows\system32\xpsp1res.dll
+ 2008-04-13 17:39:22 187,392 ----a-w c:\windows\system32\xpsp1res.dll
- 2004-08-10 19:00:00 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
+ 2008-04-13 17:39:24 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
- 2007-12-06 09:38:31 350,720 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-04-13 17:39:26 689,152 ----a-w c:\windows\system32\xpsp3res.dll
+ 2007-03-23 10:07:54 583,504 ------w c:\windows\system32\XPSSHHDR.dll
+ 2007-03-23 10:07:56 1,683,280 ------w c:\windows\system32\XpsSvcs.dll
+ 2007-10-09 17:03:08 308,760 ----a-w c:\windows\system32\XPSViewer\XPSViewer.exe
- 2007-06-28 22:52:18 765,952 ----a-w c:\windows\system32\xvidcore.dll
+ 2008-04-27 14:33:36 765,952 ----a-w c:\windows\system32\xvidcore.dll
- 2007-06-28 22:54:10 180,224 ----a-w c:\windows\system32\xvidvfw.dll
+ 2008-04-27 14:35:28 180,224 ----a-w c:\windows\system32\xvidvfw.dll
- 2004-08-10 19:00:00 337,920 ----a-w c:\windows\system32\zipfldr.dll
+ 2008-04-14 00:12:11 338,432 ----a-w c:\windows\system32\zipfldr.dll
+ 2008-12-29 16:27:11 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_f58.dat
- 2004-08-10 19:00:00 50,688 ----a-w c:\windows\twain_32.dll
+ 2008-04-14 00:12:07 50,688 ----a-w c:\windows\twain_32.dll
+ 2002-03-17 00:00:00 7,420 ----a-w c:\windows\UA000071.DLL
- 2004-08-10 19:00:00 283,648 ----a-w c:\windows\winhlp32.exe
+ 2008-04-14 00:12:39 283,648 ----a-w c:\windows\winhlp32.exe
+ 2008-09-11 15:21:36 8,192 -c--a-w c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2008-09-01 21:39:59 1,233,920 -c--a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
+ 2007-05-08 19:06:44 1,275,392 -c--a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
+ 2008-09-30 21:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-01 21:39:59 82,432 -c--a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
+ 2008-09-30 21:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
- 2007-01-19 20:15:24 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2008-04-14 00:12:50 74,802 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
- 2007-01-19 20:15:24 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2008-04-14 00:12:50 995,383 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2007-01-19 20:15:24 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2008-04-14 00:12:50 1,011,774 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
- 2007-01-19 20:15:24 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 00:12:50 401,462 -c--a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2005-09-23 04:49:12 95,744 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2007-10-24 05:47:56 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcm80.dll
+ 2007-10-24 05:47:56 558,080 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll
+ 2007-10-24 05:47:56 635,904 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll
+ 2005-09-23 03:48:08 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 03:48:08 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48:06 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 04:48:08 1,015,808 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_f75eb16c\msvcm80d.dll
+ 2005-09-23 04:48:08 1,028,096 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_f75eb16c\msvcp80d.dll
+ 2005-09-23 04:48:08 1,171,456 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugCRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_f75eb16c\msvcr80d.dll
+ 2005-09-23 06:16:02 2,375,680 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_c8452471\mfc80d.dll
+ 2005-09-23 06:16:06 2,379,264 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_c8452471\mfc80ud.dll
+ 2005-09-23 06:16:10 114,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_c8452471\mfcm80d.dll
+ 2005-09-23 06:16:12 102,400 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugMFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_c8452471\mfcm80ud.dll
+ 2005-09-23 06:35:10 102,400 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.DebugOpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_66b81908\vcompd.dll
+ 2005-09-23 06:16:02 1,093,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-23 06:16:06 1,079,808 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 06:16:08 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-23 06:16:10 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 05:58:06 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2005-09-23 05:58:06 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2005-09-23 05:58:06 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2005-09-23 05:58:06 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2005-09-23 05:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2005-09-23 05:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2005-09-23 05:58:06 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2005-09-23 05:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2005-09-23 05:58:06 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2005-09-23 06:35:10 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
+ 2008-09-30 23:29:22 224,768 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2008-09-30 23:29:22 568,832 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2008-09-30 23:29:22 655,872 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2008-04-14 00:12:51 1,054,208 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
+ 2008-04-14 00:12:51 57,344 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
+ 2008-04-14 00:12:51 343,040 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
+ 2008-04-14 00:12:47 1,724,416 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
+ 2008-04-15 17:47:33 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
- 2004-08-10 19:00:00 853,504 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 00:12:49 853,504 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
- 2004-08-10 19:00:00 991,232 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
+ 2008-04-14 00:12:50 991,232 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2004-08-10 19:00:00 132,096 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
+ 2008-04-13 18:26:33 132,096 -c--a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\rtcres.dll
+ 2008-09-11 15:21:40 258,048 -c--a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-09-11 15:21:40 113,664 -c--a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-02 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-10 2356088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLJ"="0 (0x0)" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"Power2GoExpress"="c:\program files\CyberLink\Power2Go\Power2GoExpress.exe" [2008-01-14 2667816]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2007-10-17 128296]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-08-06 115560]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-03-21 91432]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-14 c:\windows\RTHDCPL.EXE]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-28 11:32 87352 c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"msacm.l3codecp"= l3codecp.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Active WebCam\\WebCam.exe"=
"c:\\Program Files\\Active WebCam\\Watchdog.exe"=
"c:\\Program Files\\OpenCase\\OpenCASE Media Agent\\PandoBinaries\\NBCPandoREST.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8080:TCP"= 8080:TCP:8080
"8081:TCP"= 8081:TCP:8081
"8081:UDP"= 8081:UDP:8081
"8080:UDP"= 8080:UDP:8080
"56607:TCP"= 56607:TCP:PandoRest Listening Port

R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 16:24:04 41456]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2008-08-03 45848]
R2 OpenCASE Media Agent;OpenCASE Media Agent;"c:\program files\OpenCase\OpenCASE Media Agent\MediaAgent.exe" [2008-08-05 835208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2008-08-05 33808]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys []
S2 gupdate1c8e207f066345c;Google Update Service (gupdate1c8e207f066345c);"c:\program files\Google\Update\GoogleUpdate.exe" /svc [2008-07-09 133104]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys []
S3 ACTIVEWEBCAMWATCHDOG;Active WebCam Watchdog;c:\program files\Active WebCam\Watchdog.exe [2008-08-06 719696]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 22112]
S4 LMIRfsClientNP;LMIRfsClientNP; []

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-08-29 18:58]

2008-12-28 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 03:18]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Symantec Antvirus


.
------- Supplementary Scan -------
.
uStart Page = hxxp://news.google.com/nwshp?hl=en&tab=wn
uDefault_Search_URL = about:blank
uSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mSearch Bar = about:blank
mSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchURL = about:blank
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

c:\windows\Downloaded Program Files\GSM_codec.dll - c:\windows\Downloaded Program Files\WebCamPlayerOCX.ocx
O16 -: {66D393D5-4D80-497C-9F4F-F3839E090202}
hxxp://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
c:\windows\Downloaded Program Files\WebCamPlayerOCX.inf
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0z3hh7vs.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.google.com/nwshp?client=firefox-a&rls=org.mozilla:en-US:official&hl=en&tab=wn
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0z3hh7vs.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Lively\nplively.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 11:27:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\vsdatant]
"ImagePath"="a"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\LMIinit.dll
c:\program files\Symantec\Symantec Endpoint Protection\SnacNp.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\rundll32.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\PSIService.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
.
**************************************************************************
.
Completion time: 2008-12-29 11:30:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-29 16:30:07
ComboFix2.txt 2008-07-13 17:08:47

Pre-Run: 272,441,556,992 bytes free
Post-Run: 272,396,611,584 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

8153 --- E O F --- 2008-12-11 21:32:13

EasyEEE
2008-12-29, 18:18
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:15 AM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 14674 bytes
[/FONT]

Shaba
2008-12-29, 19:01
I'd like you to check a file for malware.

Go to VirusTotal (http://www.virustotal.com) or Jotti's (http://virusscan.jotti.org/)


c:\windows\system32\userinit.exe

Copy/Paste the first file on the list into the white Upload a file box.
Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
After a while, a window will open, with details of what the scans found.
Save the complete results in a Notepad/Word document on your desktop.
Post back results here, please.

EasyEEE
2008-12-29, 19:32
Yeah, I've noticed that file during my many scans. Even scanning/cleaning in Safe mode, to the point where that file no longer appeared infected.

http://www.virustotal.com/ would not load. Are you able to load it? Web sites have been hit and miss with this computer infected.

http://virusscan.jotti.org/ reports:

Scan taken on 29 Dec 2008 18:27:17 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

Shaba
2008-12-29, 19:36
OK, that might be clean.

A bootlog is a file where windows writes down which drivers are loaded and which not during startup.
Using Windows explorer, see if you find c:\windows\ntbtlog.txt - If it exists, delete the file.

Click Start then Run and type in msconfig in the edit box and hit Enter or click Ok
Click on the boot.ini tab and check the box that says /BOOTLOG
Click Apply & Ok and reboot the PC (may take a bit longer to boot)
After it reboots, you will get a message that msconfig has been used to change your start settings.
In msconfig, Check Normal Startup on the GENERAL tab, and on the BOOT.INI tab, Uncheck /BOOTLOG. Click Apply, OK.
When a message asks if you want to Reboot now, Click Exit Without Reboot. You don't need to.
Using Windows Explorer, locate c:\windows\ntbtlog.txt and post the content of the file.

EasyEEE
2008-12-29, 19:50
Found file, deleted, did as instructed, rebooted:

Service Pack 312 29 2008 13:42:41.500
Loaded driver \WINDOWS\system32\ntkrnlpa.exe
Loaded driver \WINDOWS\system32\hal.dll
Loaded driver \WINDOWS\system32\KDCOM.DLL
Loaded driver \WINDOWS\system32\BOOTVID.dll
Loaded driver sptd.sys
Loaded driver \WINDOWS\System32\Drivers\WMILIB.SYS
Loaded driver \WINDOWS\System32\Drivers\SCSIPORT.SYS
Loaded driver ACPI.sys
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver pciide.sys
Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Loaded driver aliide.sys
Loaded driver cmdide.sys
Loaded driver toside.sys
Loaded driver viaide.sys
Loaded driver intelide.sys
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver VolSnap.sys
Loaded driver cpqarray.sys
Loaded driver IASTOR.SYS
Loaded driver atapi.sys
Loaded driver aha154x.sys
Loaded driver sparrow.sys
Loaded driver symc810.sys
Loaded driver aic78xx.sys
Loaded driver dac960nt.sys
Loaded driver ql10wnt.sys
Loaded driver amsint.sys
Loaded driver asc.sys
Loaded driver asc3550.sys
Loaded driver mraid35x.sys
Loaded driver i2omp.sys
Loaded driver ini910u.sys
Loaded driver ql1240.sys
Loaded driver aic78u2.sys
Loaded driver symc8xx.sys
Loaded driver sym_hi.sys
Loaded driver sym_u3.sys
Loaded driver ABP480N5.SYS
Loaded driver asc3350p.sys
Loaded driver cd20xrnt.sys
Loaded driver ultra.sys
Loaded driver dpti2o.sys
Loaded driver adpu160m.sys
Loaded driver ql1080.sys
Loaded driver ql1280.sys
Loaded driver ql12160.sys
Loaded driver perc2.sys
Loaded driver perc2hib.sys
Loaded driver hpn.sys
Loaded driver cbidf2k.sys
Loaded driver dac2w2k.sys
Loaded driver nvata.sys
Loaded driver disk.sys
Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Loaded driver fltmgr.sys
Loaded driver sr.sys
Loaded driver PxHelp20.sys
Loaded driver KSecDD.sys
Loaded driver WudfPf.sys
Loaded driver Ntfs.sys
Loaded driver NDIS.sys
Loaded driver viaagp.sys
Loaded driver SysPlant.sys
Loaded driver sisagp.sys
Loaded driver ohci1394.sys
Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS
Loaded driver Mup.sys
Loaded driver agp440.sys
Loaded driver alim1541.sys
Loaded driver amdagp.sys
Loaded driver agpCPQ.sys
Loaded driver \SystemRoot\system32\DRIVERS\nic1394.sys
Loaded driver \SystemRoot\System32\Drivers\abe8js54.SYS
Loaded driver \SystemRoot\system32\DRIVERS\processr.sys
Loaded driver \SystemRoot\system32\DRIVERS\nv4_mini.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\System32\Drivers\GEARAspiWDM.sys
Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\nvnetbus.sys
Loaded driver \SystemRoot\system32\DRIVERS\serial.sys
Loaded driver \SystemRoot\system32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\parport.sys
Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\lmimirr.sys
Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\teefer2.sys
Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\update.sys
Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
Loaded driver \SystemRoot\system32\drivers\RtkHDAud.sys
Loaded driver \SystemRoot\system32\DRIVERS\NVENETFD.sys
Loaded driver \SystemRoot\system32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\system32\DRIVERS\USBSTOR.SYS
Loaded driver \SystemRoot\system32\DRIVERS\usbccgp.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouhid.sys
Loaded driver \SystemRoot\System32\Drivers\nx6000.sys
Loaded driver \SystemRoot\System32\Drivers\usbvideo.sys
Loaded driver \SystemRoot\system32\drivers\usbaudio.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Loaded driver \SystemRoot\System32\Drivers\SRTSPX.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS
Loaded driver \SystemRoot\System32\Drivers\SRTSP.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\DRIVERS\gmer.sys
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
Loaded driver \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
Loaded driver \SystemRoot\System32\Drivers\SYMTDI.SYS
Loaded driver \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\system32\DRIVERS\arp1394.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
Did not load driver \SystemRoot\system32\DRIVERS\p3.sys
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Loaded driver \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Loaded driver \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
Loaded driver \SystemRoot\System32\Drivers\Udfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \??\C:\WINDOWS\system32\drivers\WpsHelper.sys
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \??\C:\WINDOWS\system32\drivers\WpsHelper.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
Loaded driver \SystemRoot\system32\DRIVERS\SLIP.sys
Loaded driver \SystemRoot\System32\Drivers\SYMREDRV.SYS
Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
Loaded driver \??\C:\WINDOWS\system32\drivers\hardlock.sys
Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
Did not load driver \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
Loaded driver \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
Loaded driver \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl
Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \??\C:\WINDOWS\nvoclock.sys
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS
Loaded driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS
Loaded driver \SystemRoot\system32\drivers\kmixer.sys

Shaba
2008-12-29, 19:53
Upload this file to jotti and post back results, please:

c:\windows\System32\Drivers\abe8js54.SYS

EasyEEE
2008-12-29, 19:59
Service load: 0% 100%
File: abe8js54.SYS
Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 9f3a2f5aa6875c72bf062c712cfa2674
Packers detected:
-

A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

I haven't had any pop-ups since this morning. At least, I think I had some this morning. I've been shutting down the computer when not using, for obvious reasons.

Shaba
2008-12-29, 20:01
That is a good sign :)

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif)

EasyEEE
2008-12-30, 01:43
Hrm...

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, December 29, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 29, 2008 16:53:18
Records in database: 1528965
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Files scanned: 133714
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 03:14:50


File name / Threat name / Threats count
C:\QooBox\Quarantine\C\WINDOWS\system32\userinit.exe.vir Infected: Backdoor.Win32.Rbot.xec 1

The selected area was scanned.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:42:09 PM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 14640 bytes

EasyEEE
2008-12-30, 01:51
Test? It says I had the last reply, but it's not appearing.

Shaba
2008-12-30, 14:38
Yes forum has been a bit buggy lately.

Kaspersky finding is in combofix quarantine.

We will uninstall combofix later.

Still problems?

EasyEEE
2008-12-30, 16:37
No Symantec pop-ups at all since we started this. Even left computer on last night.

Only issue is randomly, a few web sites don't load. Like last night, tried to go to ign.com - and it was very sluggish loading, if it loaded at all. Loaded just fine now.

I'm not sure if those are internet related or related to traffic coming in and out of my computer from some sort of virus.

Surfing seems to be 98-99% of what it was. Maybe it's just me, maybe it is just coincidence.

Shaba
2008-12-30, 16:39
Do you they load OK via some proxy, like myproxy.ca?

EasyEEE
2008-12-30, 16:55
I didn't think of using a proxy, but did check the status of ign.com via http://downforeveryoneorjustme.com/ and it said it was up.

And it did load slowly, after a few failed connections. And ign.com is loading just fine now.

Shaba
2008-12-30, 16:58
OK, so that might be isp/connection issue.

Any other issues?

EasyEEE
2008-12-30, 17:03
No, my friend. I'm thinking I'm all set.

Last night I did re-run those virus scanners last night, including Microsoft's Windows Live OneCare safety scanner at http://safety.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt

The only thing any of them found was that Windows Live OneCare safety scanner reported combofix.exe on my desk top as infected.

But if I'm not mistaken, that happens with some scanners, correct?

Shaba
2008-12-30, 17:07
Yes some scanners report it due to its nature, it is false positive.

See below for my instructions:

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Please download JavaRa (http://sourceforge.net/project/downloading.php?groupname=javara&filename=JavaRa.zip&use_mirror=osdn) and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

Double-click on JavaRa.exe to start the program.
From the drop-down menu, choose English and click on Select.
JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
A logfile will pop up. Please save it to a convenient location.

Then download and install Java Runtime Environment (JRE) 6 Update 11 (http://java.sun.com/javase/downloads/index.jsp).

Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK

Next we remove all used tools.

Please download OTCleanIt (http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe) and save it to desktop.

Double-click OTCleanIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1644)

Malwarebytes' Anti-Malware Scanning Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1645)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

EasyEEE
2008-12-30, 17:18
Thank you very much for your time. Sincerely appreciate. Still curious what I had and how I got it. I've been very very careful, have had all these programs installed, and still got hit.

Anyway, have a great New Years!

-Brad

Shaba
2009-01-01, 10:58
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.