Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:13 PM, on 6/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///E:/September911surprise%20CTV/PirateNews-org/Homepage/index2.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
N2 - Netscape 6: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\JOHN LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\JOHN LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
O2 - BHO: (no name) - {344B7EF2-9819-299E-51CB-018EEAA2D736} - C:\WINDOWS\system32\admdsc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Common Files\Justdo\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://www.archive.org
O15 - Trusted Zone: http://tvplanner.comcast.net
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://www.disabilityforms.com
O15 - Trusted Zone: http://www.fireflyfans.net
O15 - Trusted Zone: http://www.infowars.com
O15 - Trusted Zone: http://www.infowars.net
O15 - Trusted Zone: http://*.infowars.net
O15 - Trusted Zone: http://*.myspace.com
O15 - Trusted Zone: http://ww2.nero.com
O15 - Trusted Zone: http://vhost.oddcast.com
O15 - Trusted Zone: http://flash.picturetail.com
O15 - Trusted Zone: http://www.picturetrail.com
O15 - Trusted Zone: *.picturetrail.com
O15 - Trusted Zone: www.piratenews.org
O15 - Trusted Zone: *.piratenews.org
O15 - Trusted Zone: http://*.piratenews.org
O15 - Trusted Zone: *.piratenews_supremecenter38.com
O15 - Trusted Zone: http://forums.spybot.info
O15 - Trusted Zone: *.supremecenter38.com
O15 - Trusted Zone: http://www.tallemu.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O20 - Winlogon Notify: hgnid - C:\WINDOWS\
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
--
End of file - 4501 bytes
=========================================================
ComboFix 08-06-07.3 - John Lee 2008-06-08 14:25:53.5 - NTFSx86
Running from: C:\Documents and Settings\John Lee\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\system32\183aa.exe
C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe
C:\WINDOWS\system32\drivers\Cksu78.sys
C:\WINDOWS\system32\hlnftdrlttr.nls
C:\WINDOWS\system32\hlphnttnjhr.sys
C:\WINDOWS\system32\pltllp.drv
C:\WINDOWS\system32\ptldtl.dll
C:\WINDOWS\system32\ptpdrfhlhbt.dll
C:\WINDOWS\system32\ptpdrfhlhbt_ORIGINAL.dll
C:\WINDOWS\system32\rdpthj.sys
C:\WINDOWS\system32\torapcfm.dll
C:\WINDOWS\TEMP\brfnhbjtdp.dll
C:\WINDOWS\TEMP\nntnnbrh.dll
C:\WINDOWS\TEMP\pltllp.drv
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CKSU78
-------\Service_Cksu78
-------\Service_CKSU78
((((((((((((((((((((((((( Files Created from 2008-05-08 to 2008-06-08 )))))))))))))))))))))))))))))))
.
2100-02-24 15:15 . 2001-04-02 17:30 821 --a--c--- C:\WINDOWS\Lexmark_ICM.ini
2100-02-16 17:09 . 2001-02-16 16:37 62 --a--c--- C:\WINDOWS\system32\LXASUSCI.INI
2008-06-08 03:00 . 2008-06-08 03:00 <DIR> d-------- C:\OnlineArmor
2008-06-08 01:05 . 2008-06-08 01:06 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-31 05:01 . 2008-05-31 05:15 <DIR> d-------- C:\Program Files\MediaCoder
2008-05-31 05:00 . 2008-05-31 05:00 17,352,333 --a------ C:\MediaCoder-0.6.1.4111-flv-to-mpg.exe
2008-05-30 20:47 . 2008-05-30 20:47 <DIR> d-------- C:\Program Files\MSECACHE
2008-05-30 20:43 . 2008-05-30 20:43 359,656 --a------ C:\ms-windows-installer-cleanup-remove-programs-only2.exe
2008-05-27 13:12 . 2008-05-27 13:12 2,585,872 --a------ C:\WindowsInstaller-KB893803-v2-x86.exe
2008-05-21 23:08 . 2008-06-08 14:41 <DIR> d-------- C:\Documents and Settings\John Lee\Application Data\OnlineArmor
2008-05-21 23:08 . 2008-05-21 23:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-05-21 23:07 . 2008-05-21 23:07 <DIR> d-------- C:\Program Files\Tall Emu
2008-05-21 23:07 . 2008-04-17 05:25 80,584 --a------ C:\WINDOWS\system32\drivers\OADriver.sys
2008-05-21 23:07 . 2008-04-17 05:25 32,456 --a------ C:\WINDOWS\system32\drivers\OAmon.sys
2008-05-21 23:07 . 2008-04-17 05:25 28,872 --a------ C:\WINDOWS\system32\drivers\oanet.sys
2008-05-21 11:56 . 2008-05-21 11:56 <DIR> d-------- C:\Program Files\Cmkkhknc
2008-05-21 11:56 . 2008-05-21 11:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zazodeji
2008-05-21 11:56 . 2008-05-21 11:56 110,592 --a------ C:\WINDOWS\system32\admdsc.dll
2008-05-21 11:56 . 2008-05-21 11:56 110,592 --a------ C:\Documents and Settings\All Users\Application Data\ufofsron.dll
2008-05-21 11:56 . 2008-05-21 11:56 106,496 --a------ C:\WINDOWS\system32\vmnylyrg.exe
2008-05-21 00:27 . 2004-05-04 13:19 <DIR> d-------- C:\Documents and Settings\Web Surfing\WINDOWS
2008-05-21 00:27 . 2004-05-04 13:19 <DIR> d-------- C:\Documents and Settings\Web Surfing\Application Data\Symantec
2008-05-21 00:27 . 2004-05-18 16:07 <DIR> d-------- C:\Documents and Settings\Web Surfing\Application Data\CyberLink
2008-05-21 00:27 . 2008-05-21 00:27 <DIR> d-------- C:\Documents and Settings\Web Surfing
2008-05-19 20:01 . 2008-05-19 20:01 <DIR> d-------- C:\EPSONREG
2008-05-19 20:01 . 2008-05-19 20:01 <DIR> d-------- C:\Documents and Settings\John Lee\Application Data\Leadertech
2008-05-19 19:59 . 2008-05-19 19:59 <DIR> d-------- C:\WINDOWS\system32\Import-Export
2008-05-19 19:59 . 2008-05-19 21:00 <DIR> d-------- C:\Program Files\EPSON Print CD
2008-05-19 19:59 . 2008-05-19 19:59 <DIR> d-------- C:\Program Files\EPSON
2008-05-19 19:58 . 2008-05-19 21:22 66 --a------ C:\WINDOWS\ESPR200.ini
2008-05-19 19:53 . 2003-05-29 01:01 91,648 --a------ C:\WINDOWS\system32\E_SAGSET.DLL
2008-05-19 19:53 . 2003-07-28 01:10 76,045 --a------ C:\WINDOWS\system32\EBPMON24.DLL
2008-05-19 19:53 . 2003-02-13 01:10 69,632 --a------ C:\WINDOWS\system32\EAL.EXE
2008-05-19 19:53 . 2003-05-21 02:27 64,000 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2008-05-19 19:53 . 2002-03-01 01:00 44,544 --a------ C:\WINDOWS\system32\EAL32.DLL
2008-05-19 19:53 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2008-05-19 19:53 . 2001-09-04 02:04 182 --a------ C:\WINDOWS\system32\EBPPORT4.DAT
2008-05-19 19:01 . 2008-05-19 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\dgpixcds
2008-05-19 19:01 . 2008-05-19 19:01 122,880 --a------ C:\Documents and Settings\All Users\Application Data\ubcredal.dll
2008-05-19 19:01 . 2008-05-19 19:01 4,096 --a------ C:\WINDOWS\system32\anticipator_delete_virus.dll
2008-05-19 19:00 . 2008-05-19 19:00 122,880 --a------ C:\WINDOWS\system32\strsys.dll
2008-05-19 19:00 . 2008-05-19 19:00 102,400 --a------ C:\WINDOWS\system32\puvkbohq.exe
2008-05-16 17:39 . 2008-05-16 17:39 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2008-05-09 15:20 . 2004-05-04 13:19 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-09 15:20 . 2004-05-04 13:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-05-09 15:20 . 2004-05-18 16:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-05-09 15:20 . 2008-05-09 15:20 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-09 12:38 . 2008-05-09 13:00 <DIR> d-------- C:\Program Files\worthles
2008-05-09 12:38 . 2008-05-09 12:38 <DIR> d-------- C:\Program Files\WAYBEY~1
2008-05-09 12:38 . 2008-05-09 12:58 <DIR> d-------- C:\Program Files\NEUROC~1
2008-05-09 12:38 . 2008-05-09 13:01 <DIR> d-------- C:\Program Files\MOTORC~1
2008-05-09 12:37 . 2008-05-09 12:57 <DIR> d-------- C:\Program Files\jeru
2008-05-09 12:37 . 2008-05-09 12:56 <DIR> d-------- C:\Program Files\GENERA~1
2008-05-09 12:37 . 2008-05-09 12:55 <DIR> d-------- C:\Program Files\empirest
2008-05-09 12:37 . 2008-05-09 12:37 <DIR> d-------- C:\Program Files\dodger
2008-05-09 12:37 . 2008-05-09 12:37 <DIR> d-------- C:\Program Files\dirtydoz
2008-05-09 12:36 . 2008-05-09 12:45 <DIR> d-------- C:\Program Files\cube
2008-05-09 12:36 . 2008-05-09 12:45 <DIR> d-------- C:\Program Files\creature
2008-05-09 12:36 . 2008-05-09 12:36 <DIR> d-------- C:\Program Files\crass
2008-05-09 12:36 . 2008-05-09 12:44 <DIR> d-------- C:\Program Files\crakoom
2008-05-09 12:36 . 2008-05-09 12:36 <DIR> d-------- C:\Program Files\COPPAK~1
2008-05-09 12:35 . 2008-05-09 12:35 <DIR> d-------- C:\Program Files\conca
2008-05-09 12:35 . 2008-05-09 12:35 <DIR> d-------- C:\Program Files\COLLEG~2
2008-05-09 12:35 . 2008-05-09 12:44 <DIR> d-------- C:\Program Files\COLLEG~1
2008-05-09 12:35 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\CLONEW~1
2008-05-09 12:35 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\CAPTAI~1
2008-05-09 12:34 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\BURLES~1
2008-05-09 12:33 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\BLUELI~1
2008-05-09 12:33 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\BLINDM~1
2008-05-09 12:33 . 2008-05-09 12:43 <DIR> d-------- C:\Program Files\beatmygu
2008-05-09 12:33 . 2008-05-09 12:42 <DIR> d-------- C:\Program Files\autobahn
2008-05-09 12:33 . 2008-05-09 12:42 <DIR> d-------- C:\Program Files\arnon
2008-05-09 12:33 . 2008-05-09 12:42 <DIR> d-------- C:\Program Files\ARMORP~1
2008-05-09 12:33 . 2008-05-09 12:42 <DIR> d-------- C:\Program Files\ARMAGG~1
2008-05-09 12:32 . 2008-05-09 13:01 <DIR> d-------- C:\Program Files\ANYTHI~1
2008-05-09 12:32 . 2008-05-09 12:42 <DIR> d-------- C:\Program Files\ANGRYB~1
2008-05-09 12:32 . 2008-05-09 12:41 <DIR> d-------- C:\Program Files\ANCIEN~1
2008-05-09 12:32 . 2008-05-09 12:41 <DIR> d-------- C:\Program Files\amerika
2008-05-09 12:32 . 2008-05-09 12:41 <DIR> d-------- C:\Program Files\ALIENS~1
2008-05-09 12:32 . 2008-05-09 12:32 <DIR> d-------- C:\Program Files\alien
2008-05-09 12:32 . 2008-05-09 12:32 <DIR> d-------- C:\Program Files\aldo
2008-05-09 12:31 . 2008-05-09 12:31 <DIR> d-------- C:\Program Files\ACTION~1
2008-05-09 12:30 . 2008-05-09 12:41 <DIR> d-------- C:\Program Files\ABDUCT~1
2008-05-08 12:39 . 2008-05-08 12:39 29 --a------ C:\WINDOWS\system32\auqwqdas.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 03:40 --------- d-----w C:\Program Files\Screenshot Pilot
2008-05-31 01:06 --------- d-----w C:\Documents and Settings\John Lee\Application Data\AdobeUM
2008-05-29 02:21 --------- d-----w C:\Program Files\RogueRemover FREE
2008-05-27 15:35 4,931,320 ----a-w C:\Opera_9.27_English_Setup.exe
2008-05-22 03:07 10,402,864 ----a-w C:\OnlineArmor_Setup_Free.exe
2008-05-19 23:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 03:37 --------- d-----w C:\Program Files\support.com
2008-05-13 20:41 --------- d-----w C:\Program Files\Pinnacle
2008-05-07 22:58 --------- d-----w C:\Program Files\EMPTY
2008-05-05 07:35 6,039,048 ----a-w C:\Firefox Setup 2.0.0.14.exe
2008-04-30 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\vmxkzufk
2008-04-28 15:48 98,304 ----a-w C:\Documents and Settings\All Users\Application Data\atubgxav.dll
2008-04-28 15:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\yvktobmb
2008-04-27 11:10 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\whulibwj.dll
2008-04-27 11:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\parifcpm
2008-04-25 23:25 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\wdqzcjeh.dll
2008-04-25 23:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\dunwjghm
2008-04-24 06:49 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\elitcvol.dll
2008-04-24 06:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\fmpkrczw
2008-04-23 18:42 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\qvwvklqf.dll
2008-04-23 02:56 122,880 ----a-w C:\Documents and Settings\All Users\Application Data\cfuvubgd.dll
2008-04-23 02:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\dgxwxyjw
2008-04-22 00:52 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\zqjctcjy.dll
2008-04-22 00:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\hydmhcby
2008-04-21 10:32 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\ryfktuji.dll
2008-04-21 10:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\fspmjgfy
2008-04-21 00:31 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\vqzyjyno.dll
2008-04-21 00:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\izgtgbct
2008-04-19 23:40 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\rkjovyzk.dll
2008-04-19 23:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\qtglohyd
2008-04-18 10:50 102,400 ----a-w C:\Documents and Settings\All Users\Application Data\azqteduj.dll
2008-04-18 10:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\fyvgtytu
2008-04-16 06:48 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\xmrezyho.dll
2008-04-16 06:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\dsxmtkvi
2008-04-14 20:11 131,072 ----a-w C:\Documents and Settings\All Users\Application Data\pabedoza.dll
2008-04-13 15:55 102,400 ----a-w C:\Documents and Settings\All Users\Application Data\ktobqrwd.dll
2008-04-11 04:39 122,880 ----a-w C:\Documents and Settings\All Users\Application Data\krwzmpex.dll
2008-04-11 04:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\danwhoha
2008-04-10 04:15 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\ajwvivwh.dll
2008-04-10 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\whulahat
2008-04-09 18:10 122,880 ----a-w C:\Documents and Settings\All Users\Application Data\mdcvwpqv.dll
2008-04-09 18:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\cnifshqp
2008-04-08 08:35 126,976 ----a-w C:\Documents and Settings\All Users\Application Data\ncbqjkxg.dll
2008-04-08 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\jahihoxw
2008-04-07 21:59 63,488 ----a-w C:\WINDOWS\xobglu16.dll
2008-04-07 21:59 23,552 ----a-w C:\WINDOWS\xobglu32.dll
2008-04-07 05:35 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\dojazyds.dll
2008-04-05 04:05 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\qbqfgjod.dll
2008-04-02 19:13 114,688 ----a-w C:\Documents and Settings\All Users\Application Data\kbqnmhel.dll
2008-04-02 00:32 1,676,293 ----a-w C:\vixybeta_install_1apr08.exe
2008-03-31 22:34 8,161,400 ----a-w C:\Windows-malicious-software-removal-mar08.exe
2008-03-30 21:36 1,415,095 ----a-w C:\SDFixMarch2008.exe
2008-03-30 21:35 1,603,366 ----a-w C:\ComboFixMarch2008.exe
2008-03-28 21:18 114,688 ----a-w C:\Documents and Settings\All Users\Application Data\buvobwlu.dll
2008-03-27 19:37 114,688 ----a-w C:\Documents and Settings\All Users\Application Data\gdizatqp.dll
2008-03-27 03:24 110,592 ----a-w C:\Documents and Settings\All Users\Application Data\ozmvkdqp.dll
2008-03-27 00:52 1,306,722 ----a-w C:\SmitfraudFixMarch2008.exe
2008-03-27 00:20 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\bwbcvybi.dll
2008-03-26 22:31 147,456 ----a-w C:\VundoFix.exe
2008-03-26 09:41 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\ahgtmdmv.dll
2008-03-26 03:14 114,688 ----a-w C:\Documents and Settings\All Users\Application Data\elazqfct.dll
2008-03-23 00:32 318,369 ----a-w C:\HiJackThis202.zip
2008-03-21 03:24 106,496 ----a-w C:\Documents and Settings\All Users\Application Data\klmngtet.dll
2008-03-19 23:56 15,452,536 ----a-w C:\IE7-WindowsXP-x86-enu.exe
2008-03-18 22:30 8,705,840 ----a-w C:\winamp552_full_emusic-7plus_en-us.exe
2008-03-18 22:22 6,956 -c--a-w C:\Program Files\hijackthis.log
2008-03-18 21:28 2,671,816 ----a-w C:\spywareblastersetup40.exe
2008-03-18 21:25 706,360 ----a-w C:\winpatrolsetup-ok.exe
2008-03-18 18:36 1,580,267 ----a-w C:\ComboFix_old.exe
2008-03-18 18:34 102,400 ----a-w C:\Documents and Settings\All Users\Application Data\obunarah.dll
2008-03-18 17:13 102,400 ----a-w C:\Documents and Settings\All Users\Application Data\mlqdwxef.dll
2008-03-18 04:24 98,304 ----a-w C:\Documents and Settings\All Users\Application Data\tijwncze.dll
2008-03-18 01:04 98,304 ----a-w C:\Documents and Settings\All Users\Application Data\admrgzcl.dll
2008-03-17 23:36 98,304 ----a-w C:\Documents and Settings\All Users\Application Data\pmlypovk.dll
2008-03-15 01:26 14,113,576 ----a-w C:\ewido-avg-antispyware-setup-7.5-30days.exe
2008-03-14 22:35 98,304 ----a-w C:\Documents and Settings\All Users\Application Data\ghotkrex.dll
2008-03-14 19:53 690,568 ----a-w C:\rogue-remover-free-setup.exe
2008-01-13 19:38 12,879,368 ----a-w C:\Program Files\RealPlayer10-5GOLD.exe
2007-12-21 06:09 4,398,984 -c--a-w C:\Program Files\MorphVOXPro_Install.exe
2007-12-21 06:07 1,083,064 -c--a-w C:\Program Files\SP-SpookySounds_Install.exe
2007-12-16 05:14 17,760,400 -c--a-w C:\Program Files\DivXInstaller.exe
2007-12-08 10:56 1,781,292 -c--a-w C:\Program Files\vixybeta_install.exe
2007-10-23 05:46 34,441,990 -c--a-w C:\Program Files\Second Life 1-18-2-0 Setup.exe
2007-10-11 17:21 904,984 -c--a-w C:\Program Files\cuz4_setup.exe
2007-08-12 22:05 1,035,000 -c--a-w C:\Program Files\daemon-tools-iso-SPTDinst-v150-x64.exe
2007-08-12 14:14 1,207,026 -c--a-w C:\Program Files\winrar370.exe
2007-06-08 16:01 27,917,104 -c--a-w C:\Program Files\downloadable_install_wizard.exe
2007-04-27 05:39 4,960,221 -c--a-w C:\Program Files\RivaEncoderSetup.exe
2007-04-02 08:12 1,512,927 -c--a-w C:\Program Files\LADSPA_plugins-win-0.4.15.exe
2007-04-02 08:11 2,228,534 -c--a-w C:\Program Files\audacity-win-1.2.6.exe
2007-04-02 07:57 614,943 ----a-w C:\Program Files\lame-3.96.1.zip
2007-03-16 11:07 502,941 ----a-w C:\Program Files\MPEG_Streamclip_1.1.zip
2007-02-27 19:59 23,510,720 -c--a-w C:\Program Files\dotnetfx.exe
2007-02-27 19:57 1,629,496 ----a-w C:\Program Files\VOB2MPGv2_3.zip
2007-02-27 09:48 392,984 ----a-w C:\Program Files\SmartRipper 2.41.zip
2007-01-29 11:53 3,602,120 -c--a-w C:\Program Files\SFTPMSI.exe
2007-01-16 11:58 363,800 -c--a-w C:\Program Files\download-flvplayer_setup.exe.exe
2007-01-09 10:22 20,368,912 -c--a-w C:\Program Files\GoogleEarthWinProSetup.exe
2007-01-02 07:54 55,217 ----a-w C:\Program Files\Copy of checkboxtemplate.zip
2007-01-02 07:54 55,217 ----a-w C:\Program Files\checkboxtemplate.zip
2005-07-14 19:31 27,648 -csha-w C:\WINDOWS\system32\AVSredirect.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-18_14.59.37.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-09 13:16:16 582,656 ----a-w C:\WINDOWS\$hf_mig$\KB933729\SP2QFE\rpcrt4.dll
+ 2007-06-19 07:24:36 350,720 ----a-w C:\WINDOWS\$hf_mig$\KB933729\SP2QFE\xpsp3res.dll
+ 2005-10-12 23:12:25 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB933729\spmsg.dll
+ 2005-10-12 23:12:26 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB933729\spuninst.exe
+ 2005-10-12 23:12:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB933729\update\spcustom.dll
+ 2005-10-12 23:12:28 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB933729\update\update.exe
+ 2005-10-12 23:12:33 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB933729\update\updspapi.dll
+ 2007-08-21 06:25:02 683,520 ----a-w C:\WINDOWS\$hf_mig$\KB941202\SP2QFE\inetcomm.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941202\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941202\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941202\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941202\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941202\update\updspapi.dll
+ 2007-10-29 22:35:13 1,287,680 ----a-w C:\WINDOWS\$hf_mig$\KB941568\SP2QFE\quartz.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941568\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941568\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941568\update\updspapi.dll
+ 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2007-11-13 11:02:46 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll
+ 2007-11-14 07:18:03 450,560 ----a-w C:\WINDOWS\$hf_mig$\KB942840\SP2QFE\jscript.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB942840\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB942840\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB942840\update\updspapi.dll
+ 2007-12-04 18:29:10 551,936 ----a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll
+ 2007-10-26 03:34:01 8,460,288 ----a-w C:\WINDOWS\$hf_mig$\KB943460\SP2QFE\shell32.dll
+ 2007-10-29 10:04:03 350,720 ----a-w C:\WINDOWS\$hf_mig$\KB943460\SP2QFE\xpsp3res.dll
+ 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943460\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943460\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943460\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943460\update\update.exe
+ 2007-03-06 01:23:47 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943460\update\updspapi.dll
+ 2007-11-07 09:50:47 727,040 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
+ 2007-12-07 00:44:30 1,024,000 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\browseui.dll
+ 2007-12-07 00:44:30 151,040 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\cdfview.dll
+ 2007-12-07 00:44:32 1,054,208 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\danim.dll
+ 2007-12-07 00:44:33 357,888 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\dxtmsft.dll
+ 2007-12-07 00:44:33 205,824 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\dxtrans.dll
+ 2007-12-07 00:44:33 55,808 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\extmgr.dll
+ 2007-12-06 10:05:52 18,432 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\iedw.exe
+ 2007-12-07 00:44:33 251,904 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\iepeers.dll
+ 2007-12-07 00:44:33 96,256 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\inseng.dll
+ 2007-12-07 00:44:33 16,384 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\jsproxy.dll
+ 2007-12-07 00:44:35 3,066,368 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\mshtml.dll
+ 2007-12-07 00:44:36 449,024 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\mshtmled.dll
+ 2007-12-07 00:44:36 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\msrating.dll
+ 2007-12-07 00:44:36 532,480 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\mstime.dll
+ 2007-12-07 00:44:36 39,424 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\pngfilt.dll
+ 2007-12-07 00:44:37 1,499,136 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\shdocvw.dll
+ 2007-12-07 00:44:38 474,112 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\shlwapi.dll
+ 2007-12-07 00:44:39 617,984 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\urlmon.dll
+ 2007-12-07 00:44:39 666,112 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
+ 2007-12-06 09:38:31 350,720 ----a-w C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\xpsp3res.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB944533\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB944533\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB944533\update\updspapi.dll
+ 2007-11-13 08:47:45 20,480 ----a-w C:\WINDOWS\$hf_mig$\KB944653\SP2QFE\secdrv.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB944653\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB944653\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB944653\update\updspapi.dll
+ 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
+ 2003-03-31 12:00:00 1,740 -c----w C:\WINDOWS\$NtServicePackUninstall$\dcache.bin
+ 2002-08-29 22:32:34 2,816 -c----w C:\WINDOWS\$NtServicePackUninstall$\drmkaud.sys
+ 2004-08-04 07:56:44 581,120 -c----w C:\WINDOWS\$NtUninstallKB933729$\rpcrt4.dll
+ 2005-10-12 23:12:26 213,216 -c----w C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe
+ 2005-10-12 23:12:33 371,424 -c----w C:\WINDOWS\$NtUninstallKB933729$\spuninst\updspapi.dll
+ 2007-05-16 15:12:02 683,520 -c----w C:\WINDOWS\$NtUninstallKB941202$\inetcomm.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941202$\spuninst\updspapi.dll
+ 2005-08-30 03:54:26 1,287,168 -c----w C:\WINDOWS\$NtUninstallKB941568$\quartz.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941568$\spuninst\updspapi.dll
+ 2007-10-27 20:39:36 213,216 -c----w C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe
+ 2007-10-27 20:39:46 371,424 -c----w C:\WINDOWS\$NtUninstallKB941569$\spuninst\updspapi.dll
+ 2004-09-22 22:46:12 229,376 -c----w C:\WINDOWS\$NtUninstallKB941569$\wmasf.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
+ 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst\updspapi.dll
+ 2007-07-18 12:42:22 60,416 -c----w C:\WINDOWS\$NtUninstallKB942763$\tzchange.exe
+ 2006-05-18 05:24:25 450,560 -c----w C:\WINDOWS\$NtUninstallKB942840$\jscript.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB942840$\spuninst\updspapi.dll
+ 2007-05-17 11:28:05 549,376 -c----w C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll
+ 2006-12-19 21:52:18 8,453,632 -c----w C:\WINDOWS\$NtUninstallKB943460$\shell32.dll
+ 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w C:\WINDOWS\$NtUninstallKB943460$\spuninst\updspapi.dll
+ 2006-08-17 12:28:27 721,920 -c----w C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll
+ 2007-06-14 18:09:18 1,023,488 -c----w C:\WINDOWS\$NtUninstallKB944533$\browseui.dll
+ 2007-06-14 18:09:18 151,040 -c----w C:\WINDOWS\$NtUninstallKB944533$\cdfview.dll
+ 2007-06-14 18:09:18 1,054,208 -c----w C:\WINDOWS\$NtUninstallKB944533$\danim.dll
+ 2007-06-14 18:09:18 357,888 -c----w C:\WINDOWS\$NtUninstallKB944533$\dxtmsft.dll
+ 2007-06-14 18:09:19 205,312 -c----w C:\WINDOWS\$NtUninstallKB944533$\dxtrans.dll
+ 2007-06-14 18:09:19 55,808 -c----w C:\WINDOWS\$NtUninstallKB944533$\extmgr.dll
+ 2007-06-14 14:07:24 18,432 -c----w C:\WINDOWS\$NtUninstallKB944533$\iedw.exe
+ 2007-06-14 18:09:19 251,392 -c----w C:\WINDOWS\$NtUninstallKB944533$\iepeers.dll
+ 2007-06-14 18:09:19 96,256 -c----w C:\WINDOWS\$NtUninstallKB944533$\inseng.dll
+ 2007-06-14 18:09:19 16,384 -c----w C:\WINDOWS\$NtUninstallKB944533$\jsproxy.dll
+ 2007-06-14 18:09:20 3,058,688 -c----w C:\WINDOWS\$NtUninstallKB944533$\mshtml.dll
+ 2007-06-14 18:09:19 449,024 -c----w C:\WINDOWS\$NtUninstallKB944533$\mshtmled.dll
+ 2007-06-14 18:09:19 146,432 -c----w C:\WINDOWS\$NtUninstallKB944533$\msrating.dll
+ 2007-06-14 18:09:20 532,480 -c----w C:\WINDOWS\$NtUninstallKB944533$\mstime.dll
+ 2007-06-14 18:09:20 39,424 -c----w C:\WINDOWS\$NtUninstallKB944533$\pngfilt.dll
+ 2007-06-14 18:09:20 1,494,528 -c----w C:\WINDOWS\$NtUninstallKB944533$\shdocvw.dll
+ 2007-06-14 18:09:20 474,112 -c----w C:\WINDOWS\$NtUninstallKB944533$\shlwapi.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB944533$\spuninst\updspapi.dll
+ 2007-06-14 18:09:20 615,424 -c----w C:\WINDOWS\$NtUninstallKB944533$\urlmon.dll
+ 2007-06-26 14:09:10 658,944 -c----w C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
+ 2007-06-14 13:39:54 115,712 -c----w C:\WINDOWS\$NtUninstallKB944533$\xpsp3res.dll
+ 2005-03-03 04:48:59 12,400 -c----w C:\WINDOWS\$NtUninstallKB944653$\secdrv.sys
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB944653$\spuninst\updspapi.dll
+ 2004-08-04 06:00:56 181,248 -c----w C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll
+ 2008-06-08 18:33:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2003-10-06 06:59:14 49,152 -c--a-w C:\WINDOWS\CTDCRES.DLL
+ 2006-08-11 18:55:52 10,240 ----a-w C:\WINDOWS\CTDCRES.DLL
+ 2006-08-11 18:56:02 17,920 ----a-w C:\WINDOWS\CTHELPER.EXE
+ 2006-08-11 18:56:06 3,072 ----a-w C:\WINDOWS\CTXFIRES.DLL
+ 2007-09-11 17:49:24 12,592 ----a-w C:\WINDOWS\Downloaded Program Files\LibComm.dll
+ 2007-09-11 17:49:28 38,280 ----a-w C:\WINDOWS\Downloaded Program Files\NanoInst.dll
+ 2007-09-11 17:49:30 43,824 ----a-w C:\WINDOWS\Downloaded Program Files\PSComm.dll
+ 2007-09-11 17:49:34 100,656 ----a-w C:\WINDOWS\Downloaded Program Files\PSNAdbrk.dll
- 2000-08-31 12:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 12:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-06-08 06:22:14 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-06-08 16:52:25 12,705,792 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-06-08 16:52:25 282,624 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-06-08 06:22:14 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-06-08 05:06:16 12,705,792 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-06-08 05:06:16 282,624 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2000-08-31 12:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 12:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2003-03-31 12:00:00 2,589 -c----w C:\WINDOWS\I386\RUNW32.BAT
- 2003-10-06 06:48:18 20,480 -c--a-w C:\WINDOWS\INRES.DLL
+ 2006-08-11 18:57:06 11,776 -c--a-w C:\WINDOWS\INRES.DLL
+ 2008-03-20 03:43:00 22,666 --sh--r C:\WINDOWS\Installer\{47a73001-2c42-45e0-95ee-64c647a0c7b9}\zip.dll
+ 2008-03-18 21:44:10 22,614 --sh--r C:\WINDOWS\Installer\{6ea97d2b-af03-4653-9ca0-ff61d00d5cbf}\zip.dll
+ 2008-03-18 20:10:00 22,782 ----a-w C:\WINDOWS\Installer\{d5922084-f076-4b91-abc8-9390f0f76e02}\zip.dll
+ 2008-03-18 20:09:47 22,610 --sh--r C:\WINDOWS\Installer\{ffec9829-e3c4-4c07-ae34-3eadf8b7a6bf}\zip.dll
+ 2007-09-15 09:00:26 2,678 -c--a-w C:\WINDOWS\java\Packages\Data\3FHBXBRT.DAT
+ 2007-09-15 09:00:22 2,678 -c--a-w C:\WINDOWS\java\Packages\Data\9JD7RRLZ.DAT
+ 2007-09-15 09:00:23 2,678 -c--a-w C:\WINDOWS\java\Packages\Data\L3V5NZPR.DAT
+ 2007-09-15 09:00:22 2,678 -c--a-w C:\WINDOWS\java\Packages\Data\MPNHB79J.DAT
+ 2007-09-15 09:00:22 2,678 -c--a-w C:\WINDOWS\java\Packages\Data\NNT793TB.DAT
+ 2005-12-29 05:34:27 2,232 -c--a-w C:\WINDOWS\java\Packages\Data\RJ5NXZXN.DAT
- 2003-06-20 10:13:46 49,152 -c--a-w C:\WINDOWS\MIDIDEF.EXE
+ 2006-08-11 18:42:52 25,600 ----a-w C:\WINDOWS\MIDIDEF.EXE
- 2006-12-09 20:26:25 11,402 -c--a-w C:\WINDOWS\mozver.dat
+ 2008-05-05 15:01:04 12,007 -c--a-w C:\WINDOWS\mozver.dat
- 2003-10-06 06:59:00 184,320 -c--a-w C:\WINDOWS\PSCONV.EXE
+ 2006-08-11 18:56:04 34,304 ----a-w C:\WINDOWS\PSCONV.EXE
- 2003-10-06 06:58:50 180,224 -c--a-w C:\WINDOWS\READREG.EXE
+ 2006-08-11 18:56:08 35,840 ----a-w C:\WINDOWS\READREG.EXE
+ 2000-08-31 12:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2004-08-04 08:07:21 1,788 -c----w C:\WINDOWS\ServicePackFiles\i386\dcache.bin
+ 2004-08-04 06:07:57 2,944 -c----w C:\WINDOWS\ServicePackFiles\i386\drmkaud.sys
+ 2003-03-31 12:00:00 138,752 ----a-w C:\WINDOWS\sndvol32.exe
+ 2000-08-31 12:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 12:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 12:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
- 2002-11-22 13:07:10 765,952 ----a-w C:\WINDOWS\system\crlds3d.dll
+ 2005-06-08 00:58:54 765,952 ----a-w C:\WINDOWS\system\crlds3d.dll
+ 2003-03-31 12:00:00 2,000 -c--a-w C:\WINDOWS\system\KEYBOARD.DRV
+ 2003-03-31 12:00:00 2,032 -c--a-w C:\WINDOWS\system\MOUSE.DRV
+ 1996-11-13 20:33:32 1,504 -c--a-w C:\WINDOWS\system\NPRX16.DLL
+ 1996-11-27 16:01:18 1,540 -c--a-w C:\WINDOWS\system\NSX83P16.DLL
+ 2003-03-31 12:00:00 1,744 -c--a-w C:\WINDOWS\system\SOUND.DRV
+ 2003-03-31 12:00:00 2,176 -c--a-w C:\WINDOWS\system\VGA.DRV
- 2003-10-06 06:38:06 65,536 -c--a-w C:\WINDOWS\system32\a3d.dll
+ 2006-08-11 18:56:28 33,792 ----a-w C:\WINDOWS\system32\a3d.dll
- 2003-10-06 06:55:56 53,248 -c--a-w C:\WINDOWS\system32\AC3API.DLL
+ 2006-08-11 18:56:16 26,624 -c--a-w C:\WINDOWS\system32\AC3API.DLL
+ 2008-04-24 06:49:46 126,976 ----a-w C:\WINDOWS\system32\actmnt.dll
+ 2008-04-14 20:11:50 131,072 ----a-w C:\WINDOWS\system32\admcomwin.dll
+ 2008-04-23 18:42:28 118,784 ----a-w C:\WINDOWS\system32\apismart.dll
+ 2008-04-23 02:56:01 122,880 ----a-w C:\WINDOWS\system32\aplen.dll
+ 2008-04-27 11:10:55 102,400 ----a-w C:\WINDOWS\system32\bohodqhy.exe
+ 2008-04-02 19:13:37 102,400 ----a-w C:\WINDOWS\system32\bqxgvwxo.exe
- 2007-06-14 18:09:18 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2007-12-07 01:07:12 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
- 2007-06-14 18:09:18 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2007-12-07 01:07:12 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2003-10-06 06:44:28 114,688 ----a-w C:\WINDOWS\system32\commonfx.dll
+ 2006-08-11 18:48:08 87,552 ----a-w C:\WINDOWS\system32\commonfx.dll
- 2008-03-13 16:12:41 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-02 18:43:28 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-13 16:12:41 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-02 18:43:28 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-13 16:12:41 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-02 18:43:28 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-08-11 18:45:36 200,192 ----a-w C:\WINDOWS\system32\CT_OAL.DLL
+ 2006-08-11 18:48:50 158,720 ----a-w C:\WINDOWS\system32\CT20XUT.DLL
- 2003-10-06 06:57:50 57,344 ----a-w C:\WINDOWS\system32\CTAGENT.DLL
+ 2006-08-11 18:56:02 7,168 ----a-w C:\WINDOWS\system32\CTAGENT.DLL
- 2003-11-19 02:09:46 126,976 -c--a-w C:\WINDOWS\system32\CTASIO.DLL
+ 2006-08-11 18:45:34 74,752 ----a-w C:\WINDOWS\system32\CTASIO.DLL
- 2003-11-18 07:23:50 585,728 ----a-w C:\WINDOWS\system32\ctaudfx.dll
+ 2006-08-11 18:48:12 536,576 ----a-w C:\WINDOWS\system32\ctaudfx.dll
- 2003-10-21 09:54:48 140,643 ----a-w C:\WINDOWS\system32\ctbas2w.dat
+ 2006-08-11 18:45:08 140,643 ----a-w C:\WINDOWS\system32\ctbas2w.dat
- 2003-10-21 09:50:46 112,411 -c--a-w C:\WINDOWS\system32\CTBASICW.DAT
+ 2006-08-11 18:43:20 113,221 ----a-w C:\WINDOWS\system32\CTBASICW.DAT
+ 2006-08-11 18:57:18 37,888 ----a-w C:\WINDOWS\system32\CTBURST.DLL
- 2003-10-06 06:48:30 69,632 -c--a-w C:\WINDOWS\system32\ctcoinst.dll
+ 2006-08-11 18:57:04 81,920 ----a-w C:\WINDOWS\system32\CTCOINST.DLL
- 2003-10-21 09:47:34 53,932 ----a-w C:\WINDOWS\system32\ctdaught.dat
+ 2006-08-11 18:43:04 53,932 ----a-w C:\WINDOWS\system32\ctdaught.dat
- 2003-11-27 01:35:26 327,680 ----a-w C:\WINDOWS\system32\CTDC0000.DLL
+ 2006-08-11 18:55:52 190,976 ----a-w C:\WINDOWS\system32\CTDC0000.DLL
- 2003-12-03 01:08:46 466,944 ----a-w C:\WINDOWS\system32\CTDC0001.DLL
+ 2006-08-11 18:55:52 286,208 ----a-w C:\WINDOWS\system32\CTDC0001.DLL
- 2003-10-06 06:57:12 139,264 ----a-w C:\WINDOWS\system32\CTDCIFCE.DLL
+ 2006-08-11 18:55:54 129,536 ----a-w C:\WINDOWS\system32\CTDCIFCE.DLL
- 2003-10-21 09:54:50 217,272 ----a-w C:\WINDOWS\system32\ctdlang.dat
+ 2006-08-11 18:49:24 323,640 ----a-w C:\WINDOWS\system32\ctdlang.dat
+ 2006-08-11 18:49:24 44,567 ----a-w C:\WINDOWS\system32\ctdnlstr.dat
- 2003-10-06 06:46:42 110,592 ----a-w C:\WINDOWS\system32\CTDPROXY.DLL
+ 2006-08-11 18:45:34 71,680 ----a-w C:\WINDOWS\system32\ctdproxy.dll
- 2003-10-06 06:48:42 143,360 -c--a-w C:\WINDOWS\system32\ctdvinst.dll
+ 2006-08-11 18:57:06 146,432 ----a-w C:\WINDOWS\system32\ctdvinst.dll
+ 2006-08-11 18:48:28 160,768 ----a-w C:\WINDOWS\system32\cteapsfx.dll
+ 2006-08-11 18:45:36 47,616 ----a-w C:\WINDOWS\system32\CTEDASIO.DLL
+ 2006-08-11 18:45:40 269,824 ----a-w C:\WINDOWS\system32\CTEDSPFX.DLL
+ 2006-08-11 18:45:50 115,200 ----a-w C:\WINDOWS\system32\CTEDSPIO.DLL
+ 2006-08-11 18:48:06 317,952 ----a-w C:\WINDOWS\system32\CTEDSPSY.DLL
- 2003-10-06 06:45:28 36,864 -c--a-w C:\WINDOWS\system32\CTEMUPIA.DLL
+ 2006-08-11 18:48:52 108,032 ----a-w C:\WINDOWS\system32\ctemupia.dll
+ 2006-08-11 18:48:42 1,170,432 ----a-w C:\WINDOWS\system32\CTEXFIFX.dll
+ 2006-08-11 18:48:52 61,952 ----a-w C:\WINDOWS\system32\CTHWIUT.DLL
+ 2005-06-16 22:17:16 71,680 ----a-w C:\WINDOWS\system32\CTMMACTL.DLL
- 2003-10-06 06:57:48 28,672 -c--a-w C:\WINDOWS\system32\CTMMEP.DLL
+ 2006-08-11 18:56:00 11,776 ----a-w C:\WINDOWS\system32\CTMMEP.DLL
- 2003-10-06 06:46:50 159,744 ----a-w C:\WINDOWS\system32\CTOSUSER.DLL
+ 2006-08-11 18:45:22 132,096 ----a-w C:\WINDOWS\system32\CTOSUSER.DLL
+ 2006-08-11 18:56:00 30,208 ----a-w C:\WINDOWS\system32\CTPCMCIA.DLL
+ 2006-08-11 18:55:56 9,216 ----a-w C:\WINDOWS\system32\CTPRES.DLL
- 2003-10-21 09:54:42 264,466 -c--a-w C:\WINDOWS\system32\ctsbas2w.dat
+ 2006-08-11 18:43:26 265,042 ----a-w C:\WINDOWS\system32\ctsbas2w.dat
- 2003-10-21 09:50:44 230,201 -c--a-w C:\WINDOWS\system32\CTSBASW.DAT
+ 2006-08-11 18:43:18 231,281 ----a-w C:\WINDOWS\system32\CTSBASW.DAT
- 2003-10-06 06:46:14 606,208 ----a-w C:\WINDOWS\system32\ctsblfx.dll
+ 2006-08-11 18:48:32 548,352 ----a-w C:\WINDOWS\system32\ctsblfx.dll
- 2003-10-06 06:57:20 118,784 -c--a-w C:\WINDOWS\system32\CTSCAL.DLL
+ 2006-08-11 18:55:54 75,264 ----a-w C:\WINDOWS\system32\CTSCAL.DLL
+ 2005-06-30 19:24:14 121,856 ----a-w C:\WINDOWS\system32\CTSFINST.DLL
- 2003-10-06 06:58:46 45,056 ----a-w C:\WINDOWS\system32\CTSPKHLP.DLL
+ 2006-08-11 18:56:02 23,040 ----a-w C:\WINDOWS\system32\CTSPKHLP.DLL
- 2003-10-21 09:47:40 298,971 ----a-w C:\WINDOWS\system32\ctstatic.dat
+ 2006-08-11 18:43:04 313,207 ----a-w C:\WINDOWS\system32\ctstatic.dat
- 2003-12-31 00:48:26 106,496 -c--a-w C:\WINDOWS\system32\CTTHXCAL.DLL
+ 2006-08-11 18:55:54 64,000 ----a-w C:\WINDOWS\system32\CTTHXCAL.DLL
+ 2006-08-11 18:56:06 26,112 ----a-w C:\WINDOWS\system32\CTXFIBTN.DLL
+ 2006-08-11 18:56:04 18,944 ----a-w C:\WINDOWS\system32\CTXFIHLP.EXE
+ 2006-08-11 18:53:22 42,496 ----a-w C:\WINDOWS\system32\CTXFIREG.EXE
+ 2006-08-11 18:53:22 52,224 ----a-w C:\WINDOWS\system32\CTXFISPI.DLL
+ 2006-08-11 18:53:20 733,184 ----a-w C:\WINDOWS\system32\CTXFISPI.EXE
+ 2006-08-11 18:56:06 25,088 ----a-w C:\WINDOWS\system32\CTXFISPK.DLL
- 2007-06-14 18:09:18 1,054,208 -c--a-w C:\WINDOWS\system32\danim.dll
+ 2007-12-07 01:07:12 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
- 2003-10-21 09:50:40 232,319 -c--a-w C:\WINDOWS\system32\Data\CT0060W.DAT
+ 2006-08-11 18:43:12 232,847 ----a-w C:\WINDOWS\system32\Data\CT0060W.DAT
+ 2006-08-11 18:43:04 15,899 ----a-w C:\WINDOWS\system32\Data\CTD20X.DAT
+ 2006-08-11 18:43:18 199,465 ----a-w C:\WINDOWS\system32\Data\CTEAPSW.DAT
+ 2006-08-11 18:43:40 364,754 ----a-w C:\WINDOWS\system32\Data\CTEDSP2W.DAT
+ 2006-08-11 18:43:42 339,138 ----a-w C:\WINDOWS\system32\Data\CTEDSPHW.DAT
+ 2006-08-11 18:43:40 285,488 ----a-w C:\WINDOWS\system32\Data\CTEDSPKW.DAT
+ 2006-08-11 18:43:40 285,488 ----a-w C:\WINDOWS\system32\Data\CTEDSPLW.DAT
+ 2006-08-11 18:43:42 321,378 ----a-w C:\WINDOWS\system32\Data\CTEDSPPW.DAT
+ 2006-08-11 18:43:40 261,640 ----a-w C:\WINDOWS\system32\Data\CTEDSPTW.DAT
+ 2006-08-11 18:43:42 261,640 ----a-w C:\WINDOWS\system32\Data\CTEDSPUW.DAT
+ 2006-08-11 18:43:32 364,754 ----a-w C:\WINDOWS\system32\Data\CTEDSPW.DAT
- 2003-10-21 09:50:40 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0060W.DAT
+ 2006-08-11 18:43:12 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0060W.DAT
- 2003-10-21 09:50:42 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0061W.DAT
+ 2006-08-11 18:43:14 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0061W.DAT
- 2003-10-21 09:54:40 279,288 -c--a-w C:\WINDOWS\system32\Data\CTP0070W.DAT
+ 2006-08-11 18:43:20 279,864 ----a-w C:\WINDOWS\system32\Data\CTP0070W.DAT
- 2003-10-21 09:54:40 279,288 -c--a-w C:\WINDOWS\system32\Data\CTP0073W.DAT
+ 2006-08-11 18:43:20 279,864 ----a-w C:\WINDOWS\system32\Data\CTP0073W.DAT
- 2003-10-21 09:54:40 266,617 -c--a-w C:\WINDOWS\system32\Data\CTP0090W.DAT
+ 2006-08-11 18:43:20 267,193 ----a-w C:\WINDOWS\system32\Data\CTP0090W.DAT
- 2003-10-21 09:54:42 265,048 -c--a-w C:\WINDOWS\system32\Data\CTP0091W.DAT
+ 2006-08-11 18:43:26 265,624 ----a-w C:\WINDOWS\system32\Data\CTP0091W.DAT
- 2003-10-21 09:54:42 266,617 -c--a-w C:\WINDOWS\system32\Data\CTP0092W.DAT
+ 2006-08-11 18:43:22 267,193 ----a-w C:\WINDOWS\system32\Data\CTP0092W.DAT
- 2003-10-21 09:54:42 264,466 -c--a-w C:\WINDOWS\system32\Data\CTP0095W.DAT
+ 2006-08-11 18:43:26 265,042 ----a-w C:\WINDOWS\system32\Data\CTP0095W.DAT
- 2003-10-21 09:50:40 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0100W.DAT
+ 2006-08-11 18:43:12 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0100W.DAT
- 2003-10-21 09:50:42 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0101W.DAT
+ 2006-08-11 18:43:14 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0101W.DAT
- 2003-10-21 09:50:40 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0102W.DAT
+ 2006-08-11 18:43:12 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0102W.DAT
- 2003-10-21 09:50:42 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0103W.DAT
+ 2006-08-11 18:43:14 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0103W.DAT
- 2003-10-21 09:50:42 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0105W.DAT
+ 2006-08-11 18:43:16 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0105W.DAT
- 2003-10-21 09:50:38 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP0150W.DAT
+ 2006-08-11 18:43:10 229,863 ----a-w C:\WINDOWS\system32\Data\CTP0150W.DAT
- 2003-10-21 09:54:40 265,048 -c--a-w C:\WINDOWS\system32\Data\CTP0161W.DAT
+ 2006-08-11 18:43:22 265,882 ----a-w C:\WINDOWS\system32\Data\CTP0161W.DAT
- 2003-10-21 09:54:40 266,617 -c--a-w C:\WINDOWS\system32\Data\CTP0162W.DAT
+ 2006-08-11 18:43:22 267,193 ----a-w C:\WINDOWS\system32\Data\CTP0162W.DAT
- 2003-10-21 09:50:42 232,523 -c--a-w C:\WINDOWS\system32\Data\CTP0170W.DAT
+ 2006-08-11 18:43:16 232,964 ----a-w C:\WINDOWS\system32\Data\CTP0170W.DAT
- 2003-10-21 09:50:42 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017AW.DAT
+ 2006-08-11 18:43:16 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017AW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017BW.DAT
+ 2006-08-11 18:43:16 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017BW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017CW.DAT
+ 2006-08-11 18:43:16 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017CW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017DW.DAT
+ 2006-08-11 18:43:16 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017DW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017EW.DAT
+ 2006-08-11 18:43:18 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017EW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017FW.DAT
+ 2006-08-11 18:43:18 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017FW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017GW.DAT
+ 2006-08-11 18:43:18 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017GW.DAT
- 2003-10-21 09:50:44 232,319 -c--a-w C:\WINDOWS\system32\Data\CTP017HW.DAT
+ 2006-08-11 18:43:18 232,847 ----a-w C:\WINDOWS\system32\Data\CTP017HW.DAT
- 2003-10-21 09:54:40 265,048 -c--a-w C:\WINDOWS\system32\Data\CTP0191W.DAT
+ 2006-08-11 18:43:22 265,624 ----a-w C:\WINDOWS\system32\Data\CTP0191W.DAT
- 2003-10-21 09:54:40 266,617 -c--a-w C:\WINDOWS\system32\Data\CTP0192W.DAT
+ 2006-08-11 18:43:22 267,193 ----a-w C:\WINDOWS\system32\Data\CTP0192W.DAT
- 2003-10-21 09:50:42 233,453 -c--a-w C:\WINDOWS\system32\Data\CTP0221W.DAT
+ 2006-08-11 18:43:14 233,894 ----a-w C:\WINDOWS\system32\Data\CTP0221W.DAT
- 2003-10-21 09:50:42 233,453 -c--a-w C:\WINDOWS\system32\Data\CTP0222W.DAT
+ 2006-08-11 18:43:14 233,894 ----a-w C:\WINDOWS\system32\Data\CTP0222W.DAT
- 2003-10-21 09:54:42 267,038 -c--a-w C:\WINDOWS\system32\Data\CTP0230W.DAT
+ 2006-08-11 18:43:24 267,614 ----a-w C:\WINDOWS\system32\Data\CTP0230W.DAT
- 2003-10-21 09:54:42 265,695 -c--a-w C:\WINDOWS\system32\Data\CTP0231W.DAT
+ 2006-08-11 18:43:24 266,271 ----a-w C:\WINDOWS\system32\Data\CTP0231W.DAT
- 2003-10-21 09:54:42 267,038 -c--a-w C:\WINDOWS\system32\Data\CTP0232W.DAT
+ 2006-08-11 18:43:24 267,614 ----a-w C:\WINDOWS\system32\Data\CTP0232W.DAT
- 2003-10-21 09:54:42 265,396 -c--a-w C:\WINDOWS\system32\Data\CTP0238W.DAT
+ 2006-08-11 18:43:24 265,972 ----a-w C:\WINDOWS\system32\Data\CTP0238W.DAT
- 2003-10-21 09:54:44 307,781 -c--a-w C:\WINDOWS\system32\Data\CTP0240W.DAT
+ 2006-08-11 18:43:26 309,525 ----a-w C:\WINDOWS\system32\Data\CTP0240W.DAT
- 2003-10-21 09:54:44 308,441 -c--a-w C:\WINDOWS\system32\Data\CTP0242W.DAT
+ 2006-08-11 18:43:28 310,185 ----a-w C:\WINDOWS\system32\Data\CTP0242W.DAT
- 2003-10-21 09:54:44 307,511 -c--a-w C:\WINDOWS\system32\Data\CTP0243W.DAT
+ 2006-08-11 18:43:28 309,255 ----a-w C:\WINDOWS\system32\Data\CTP0243W.DAT
- 2003-10-21 09:54:44 308,441 -c--a-w C:\WINDOWS\system32\Data\CTP0244W.DAT
+ 2006-08-11 18:43:28 310,185 ----a-w C:\WINDOWS\system32\Data\CTP0244W.DAT
- 2003-10-21 09:54:44 306,965 -c--a-w C:\WINDOWS\system32\Data\CTP0245W.DAT
+ 2006-08-11 18:43:28 308,709 ----a-w C:\WINDOWS\system32\Data\CTP0245W.DAT
+ 2006-08-11 18:43:30 310,185 ----a-w C:\WINDOWS\system32\Data\CTP0246W.DAT
- 2003-10-21 09:54:44 307,052 -c--a-w C:\WINDOWS\system32\Data\CTP0249W.DAT
+ 2006-08-11 18:43:30 308,796 ----a-w C:\WINDOWS\system32\Data\CTP0249W.DAT
- 2003-10-21 09:54:46 306,965 -c--a-w C:\WINDOWS\system32\Data\CTP0280W.DAT
+ 2006-08-11 18:43:30 308,709 ----a-w C:\WINDOWS\system32\Data\CTP0280W.DAT
- 2003-10-21 09:54:46 306,965 -c--a-w C:\WINDOWS\system32\Data\CTP0320W.DAT
+ 2006-08-11 18:43:32 308,709 ----a-w C:\WINDOWS\system32\Data\CTP0320W.DAT
- 2003-10-21 09:54:46 312,351 ----a-w C:\WINDOWS\system32\Data\CTP0350W.DAT
+ 2006-08-11 18:43:32 314,095 ----a-w C:\WINDOWS\system32\Data\CTP0350W.DAT
- 2003-10-21 09:54:46 310,240 -c--a-w C:\WINDOWS\system32\Data\CTP0352W.DAT
+ 2006-08-11 18:43:32 311,984 ----a-w C:\WINDOWS\system32\Data\CTP0352W.DAT
+ 2006-08-11 18:43:36 312,649 ----a-w C:\WINDOWS\system32\Data\CTP0355W.DAT
+ 2006-08-11 18:43:34 312,007 ----a-w C:\WINDOWS\system32\Data\CTP0358W.DAT
+ 2006-08-11 18:43:34 311,077 ----a-w C:\WINDOWS\system32\Data\CTP0359W.DAT
- 2003-10-21 09:54:46 308,787 -c--a-w C:\WINDOWS\system32\Data\CTP0360W.DAT
+ 2006-08-11 18:43:34 310,531 ----a-w C:\WINDOWS\system32\Data\CTP0360W.DAT
+ 2006-08-11 18:43:36 310,531 ----a-w C:\WINDOWS\system32\Data\CTP0380W.DAT
+ 2006-08-11 18:43:36 310,562 ----a-w C:\WINDOWS\system32\Data\CTP0400W.DAT
+ 2006-08-11 18:45:08 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0460W.DAT
+ 2006-08-11 18:45:10 244,765 ----a-w C:\WINDOWS\system32\Data\CTP0463W.DAT
+ 2006-08-11 18:45:10 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0464W.DAT
+ 2006-08-11 18:45:10 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0465W.DAT
+ 2006-08-11 18:45:08 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0466W.DAT
+ 2006-08-11 18:45:10 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0468W.DAT
+ 2006-08-11 18:45:10 245,093 ----a-w C:\WINDOWS\system32\Data\CTP0469W.DAT
+ 2006-08-11 18:45:10 244,765 ----a-w C:\WINDOWS\system32\Data\CTP046AW.DAT
+ 2006-08-11 18:45:10 244,765 ----a-w C:\WINDOWS\system32\Data\CTP046BW.DAT
+ 2006-08-11 18:45:10 244,765 ----a-w C:\WINDOWS\system32\Data\CTP046CW.DAT
+ 2006-08-11 18:44:24 222,944 ----a-w C:\WINDOWS\system32\Data\CTP0530L.DAT
+ 2006-08-11 18:43:42 312,182 ----a-w C:\WINDOWS\system32\Data\CTP0530W.DAT
+ 2006-08-11 18:45:08 222,944 ----a-w C:\WINDOWS\system32\Data\CTP0531L.DAT
+ 2006-08-11 18:44:26 312,182 ----a-w C:\WINDOWS\system32\Data\CTP0531W.DAT
+ 2006-08-11 18:45:10 245,351 ----a-w C:\WINDOWS\system32\Data\CTP0550W.DAT
+ 2006-08-11 18:45:12 245,023 ----a-w C:\WINDOWS\system32\Data\CTP055AW.DAT
+ 2006-08-11 18:43:38 310,562 ----a-w C:\WINDOWS\system32\Data\CTP0600W.DAT
+ 2006-08-11 18:43:38 310,562 ----a-w C:\WINDOWS\system32\Data\CTP0610W.DAT
+ 2006-08-11 18:43:40 310,562 ----a-w C:\WINDOWS\system32\Data\CTP0669W.DAT
+ 2006-08-11 18:45:08 326,466 ----a-w C:\WINDOWS\system32\Data\CTP0679W.DAT
+ 2006-08-11 18:45:10 245,847 ----a-w C:\WINDOWS\system32\Data\CTP0730W.DAT
+ 2006-08-11 18:45:12 245,847 ----a-w C:\WINDOWS\system32\Data\CTP073AW.DAT
- 2003-10-21 09:50:36 230,861 -c--a-w C:\WINDOWS\system32\Data\CTP1140W.DAT
+ 2006-08-11 18:43:06 231,389 ----a-w C:\WINDOWS\system32\Data\CTP1140W.DAT
- 2003-10-21 09:50:36 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4620W.DAT
+ 2006-08-11 18:43:04 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4620W.DAT
- 2003-10-21 09:50:36 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4670W.DAT
+ 2006-08-11 18:43:06 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4670W.DAT
- 2003-10-21 09:50:36 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4760W.DAT
+ 2006-08-11 18:43:04 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4760W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4780W.DAT
+ 2006-08-11 18:43:08 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4780W.DAT
- 2003-10-21 09:50:38 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP4790W.DAT
+ 2006-08-11 18:43:10 229,863 ----a-w C:\WINDOWS\system32\Data\CTP4790W.DAT
- 2003-10-21 09:54:40 257,478 -c--a-w C:\WINDOWS\system32\Data\CTP4820W.DAT
+ 2006-08-11 18:43:20 258,054 ----a-w C:\WINDOWS\system32\Data\CTP4820W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4830W.DAT
+ 2006-08-11 18:43:08 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4830W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4831W.DAT
+ 2006-08-11 18:43:08 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4831W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4832W.DAT
+ 2006-08-11 18:43:10 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4832W.DAT
- 2003-10-21 09:50:40 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP4840W.DAT
+ 2006-08-11 18:43:10 229,863 ----a-w C:\WINDOWS\system32\Data\CTP4840W.DAT
- 2003-10-21 09:50:36 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4850W.DAT
+ 2006-08-11 18:43:06 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4850W.DAT
- 2003-10-21 09:50:36 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4870W.DAT
+ 2006-08-11 18:43:06 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4870W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4871W.DAT
+ 2006-08-11 18:43:08 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4871W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4872W.DAT
+ 2006-08-11 18:43:08 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4872W.DAT
- 2003-10-21 09:50:38 230,201 -c--a-w C:\WINDOWS\system32\Data\CTP4875W.DAT
+ 2006-08-11 18:43:06 230,729 ----a-w C:\WINDOWS\system32\Data\CTP4875W.DAT
- 2003-10-21 09:50:40 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP4890W.DAT
+ 2006-08-11 18:43:10 229,863 ----a-w C:\WINDOWS\system32\Data\CTP4890W.DAT
- 2003-10-21 09:50:40 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP4891W.DAT
+ 2006-08-11 18:43:10 229,863 ----a-w C:\WINDOWS\system32\Data\CTP4891W.DAT
- 2003-10-21 09:50:40 229,335 -c--a-w C:\WINDOWS\system32\Data\CTP4893W.DAT
+ 2006-08-11 18:43:12 229,863 ----a-w C:\WINDOWS\system32\Data\CTP4893W.DAT
- 2003-10-21 09:50:40 232,319 -c--a-w C:\WINDOWS\system32\Data\CTPDXW.DAT
+ 2006-08-11 18:43:14 232,847 ----a-w C:\WINDOWS\system32\Data\CTPDXW.DAT
- 2003-10-21 09:50:36 230,861 -c--a-w C:\WINDOWS\system32\Data\CTPM002W.DAT
+ 2006-08-11 18:43:06 231,389 ----a-w C:\WINDOWS\system32\Data\CTPM002W.DAT
+ 2006-08-11 18:43:04 2,091 ----a-w C:\WINDOWS\system32\Data\CTS20X.DAT
+ 2008-04-28 15:48:15 98,304 ----a-w C:\WINDOWS\system32\dbcfg.dll
+ 2004-08-04 08:07:21 1,788 -c--a-w C:\WINDOWS\system32\dcache.bin
+ 2006-08-11 18:42:50 47,104 ----a-w C:\WINDOWS\system32\DEVREG.DLL
- 2003-10-06 06:38:06 65,536 -c--a-w C:\WINDOWS\system32\dllcache\a3d.dll
+ 2006-08-11 18:56:28 33,792 -c--a-w C:\WINDOWS\system32\dllcache\a3d.dll
- 2007-06-14 18:09:18 1,023,488 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2007-12-07 01:07:12 1,023,488 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
- 2007-06-14 18:09:18 151,040 -c----w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2007-12-07 01:07:12 151,040 -c----w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2007-06-14 18:09:18 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2007-12-07 01:07:12 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2004-08-04 06:07:58 60,288 -c--a-w C:\WINDOWS\system32\dllcache\drmk.sys
+ 2004-08-04 05:07:58 60,288 -c--a-w C:\WINDOWS\system32\dllcache\drmk.sys