Can't Stop Virus Apparently Attempting To Send Emails

EasyEEE

New member
No idea what or when I downloaded something that could have possibly given me this virus.

I use the latest Spybot, Spyware Blaster, SpywareGuard, Norton's Endpoint, and even scan with Lavasoft's Ad-aware.

All of a sudden today, I keep getting pop-ups from Symantec Email Proxy saying, "Your email message was unable to be sent because your mail server rejected the message: 451 4.3.2 Please try again later"

And

554 5.1.1 WARNING: Your email was not delivered because it appears to be spam. Questions? Contact ithelp@ucdavis.edu or (530) 754-HELP.

I don't use Outlook or Outlook Express.

I only use Gmail. Although, I recently downloaded Yahoo Messenger from their web site. I logged in, but later, I couldn't log in to the application, while I could log in to the web site version. I changed password several times, and never could again log into the application version of messenger. I just say that in case maybe something is related. Also, I had to actually re-install Messenger as it wasn't appearing in the uninstall list. It did finally appear, and I've uninstalled it.

I've also booted up in Safe Mode and ran all the above programs (except Norton's, I couldn't get their anti-virus to run in safe mode.)

Would appreciate any help. Since I started writing this, I've received 20+ Symantec Email Proxy winders. None of it making sense.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:33 PM, on 12/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 15186 bytes
 
Hi EasyEEE

Download gmer.zip and save to your desktop.
alternate download site 1
alternate download site 2

  • Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.
  • When you have done this, disconnect from the Internet and close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program.
  • Allow the gmer.sys driver to load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Click on "Settings", then check the first five settings:
    *System Protection and Tracing
    *Processes
    *Save created processes to the log
    *Drivers
    *Save loaded drivers to the log
  • You will be prompted to restart your computer. Please do so.

Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE"
Important! Please do not select the "Show all" checkbox during the scan..
 
Here is the requested file. Appreciate your time.

1. The text that you have entered is too long (230280 characters). Please shorten it to 64000 characters long.

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-29 10:21:57
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.14 ----

SSDT 8A88CDD0 ZwAlertResumeThread
SSDT 8A854E70 ZwAlertThread
SSDT 8A2346E8 ZwAllocateVirtualMemory
SSDT 8A8C3990 ZwConnectPort
SSDT sptd.sys ZwCreateKey [0xB9EBE0D0]
SSDT 8A23D6E8 ZwCreateMutant
SSDT 8A6D3C30 ZwCreateThread
SSDT sptd.sys ZwEnumerateKey [0xB9EC3FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xB9EC4340]
SSDT 8A2496E8 ZwFreeVirtualMemory
SSDT 8A828858 ZwImpersonateAnonymousToken
SSDT 8A8904C8 ZwImpersonateThread
SSDT 8A6D3E78 ZwMapViewOfSection
SSDT 8A6A3108 ZwOpenEvent
SSDT sptd.sys ZwOpenKey [0xB9EBE0B0]
SSDT 8A7230F8 ZwOpenProcessToken
SSDT 8A2366E8 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xB8BA5240]
SSDT SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation) ZwQueryDefaultLocale [0xB9BA9790]
SSDT sptd.sys ZwQueryKey [0xB9EC4418]
SSDT sptd.sys ZwQueryValueKey [0xB9EC4298]
SSDT 8A6D3BF0 ZwResumeThread
SSDT 8A7006D8 ZwSetContextThread
SSDT 8A2486E8 ZwSetInformationProcess
SSDT 8A2676E8 ZwSetInformationThread
SSDT sptd.sys ZwSetValueKey [0xB9EC44AA]
SSDT 8A7CB988 ZwSuspendProcess
SSDT 8A7E3DF8 ZwSuspendThread
SSDT 8A65E5E0 ZwTerminateProcess
SSDT 8A86DDF8 ZwTerminateThread
SSDT 8A6B4C70 ZwUnmapViewOfSection
SSDT 8A2356E8 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.14 ----

.text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + AFD 8053D631 5 Bytes JMP B9BAAAD0 SysPlant.sys (Symantec CMC Firewall SysPlant/Symantec Corporation)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? System32\Drivers\awdnpolt.SYS The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B84138AC 5 Bytes JMP 8AE4E770
.text ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4
.text ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E
.text ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648
.text ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682
.text ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC
.text ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6
.text ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730
.text ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A
.text ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE

---- User code sections - GMER 1.0.14 ----

.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\userinit.exe[280] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[368] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\Explorer.EXE[616] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Update\GoogleUpdate.exe[624] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehmsas.exe[636] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[644] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Bonjour\mDNSResponder.exe[788] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[888] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\CTsvcCDA.exe[932] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\winlogon.exe[984] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\services.exe[1032] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\lsass.exe[1044] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehRecvr.exe[1048] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1244] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\svchost.exe[1300] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1344] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
 
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\eHome\ehSched.exe[1436] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\ehtray.exe[1444] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\RUNDLL32.EXE[1488] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe[1496] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[1504] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1548] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe[1660] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1852] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe[2056] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2064] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[2072] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\RTHDCPL.EXE[2084] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Symantec Shared\ccApp.exe[2092] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe[2128] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Cyberlink\Shared Files\brs.exe[2152] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2236] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
 
.text C:\Program Files\iTunes\iTunesHelper.exe[2248] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[2260] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[2336] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe[2344] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2720] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgmain.exe[2824] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Microsoft LifeCam\MSCamS32.exe[2844] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\SpywareGuard\sgbhp.exe[2888] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe[2900] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe[3032] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe[3048] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\nvsvc32.exe[3056] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe[3132] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3188] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrA.exe[3296] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PnkBstrB.exe[3308] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\PSIService.exe[3336] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\CyberLink\Shared Files\RichVideo.exe[3376] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3408] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
 
.text C:\WINDOWS\system32\svchost.exe[3420] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe[3468] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe[3516] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\ehome\mcrdsvc.exe[3544] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\System32\alg.exe[3928] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\dllhost.exe[3936] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[4024] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4072] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\WINDOWS\system32\wuauclt.exe[4996] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateFile + 5 7C90D095 5 Bytes JMP 6F025560 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateKey + 5 7C90D0D5 5 Bytes JMP 6F02559A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtSetValueKey + 5 7C90DDB5 5 Bytes JMP 6F0257A4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe[5356] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtCreateThread + 5 7C90D195 5 Bytes JMP 6F0255D4 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtDeleteFile + 5 7C90D225 5 Bytes JMP 6F02560E C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtDeleteValueKey + 5 7C90D255 5 Bytes JMP 6F025648 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtMapViewOfSection + 5 7C90D505 5 Bytes JMP 6F025682 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtOpenFile + 5 7C90D585 5 Bytes JMP 6F0256BC C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtOpenKey + 5 7C90D5B5 5 Bytes JMP 6F0256F6 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtRenameKey + 5 7C90DA45 5 Bytes JMP 6F025730 C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtSetInformationFile + 5 7C90DC45 5 Bytes JMP 6F02576A C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)
.text C:\Gmer\gmer.exe[5480] ntdll.dll!NtTerminateProcess + 5 7C90DE55 5 Bytes JMP 6F0257DE C:\WINDOWS\SYSTEM32\SYSFER.DLL (Symantec CMC Firewall sysfer/Symantec Corporation)

---- Kernel IAT/EAT - GMER 1.0.14 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EBEAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EBEC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EBEB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EBF748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EBF61E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9ED429A] sptd.sys

---- Devices - GMER 1.0.14 ----

Device \FileSystem\Ntfs \Ntfs 8AFF61E8
Device \FileSystem\Fastfat \FatCdrom 8A6E8790
Device \FileSystem\Udfs \UdfsCdRom 8A6F4790
Device \FileSystem\Udfs \UdfsDisk 8A6F4790

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\usbohci \Device\USBPDO-0 8AD945C0
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmConfig 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmPnP 8B07F1E8
Device \Driver\dmio \Device\DmControl\DmInfo 8B07F1E8
Device \Driver\usbehci \Device\USBPDO-1 8AD8B790

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\nvata \Device\000000a1 8AFF81E8
Device \Driver\nvata \Device\000000a2 8AFF81E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8B0151E8
Device \Driver\Cdrom \Device\CdRom0 8AE3A790
Device \Driver\usbstor \Device\000000b0 89BBB1E8
Device \Driver\Cdrom \Device\CdRom1 8AE3A790
Device \Driver\usbstor \Device\000000b1 89BBB1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A705428
Device \Driver\NetBT \Device\NetbiosSmb 8A705428

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)

Device \Driver\usbohci \Device\USBFDO-0 8AD945C0
Device \Driver\usbstor \Device\000000ab 89BBB1E8
Device \Driver\nvata \Device\NvAta0 8AFF81E8
Device \Driver\usbehci \Device\USBFDO-1 8AD8B790
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A70D3C8
Device \Driver\NetBT \Device\NetBT_Tcpip_{3FE5131D-2573-40B6-A366-9EE7F9CDA625} 8A705428
Device \Driver\usbstor \Device\000000ae 89BBB1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A70D3C8
Device \Driver\usbstor \Device\000000af 89BBB1E8
Device \Driver\Ftdisk \Device\FtControl 8B0151E8
Device \Driver\PCI_NTPNP4120 \Device\0000007e sptd.sys
Device \Driver\PCI_NTPNP4120 \Device\0000007f sptd.sys
Device \Driver\awdnpolt \Device\Scsi\awdnpolt1 8AE5B568
Device \FileSystem\Fastfat \Fat 8A6E8790

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 8A6EC790

---- Registry - GMER 1.0.14 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x3D 0x04 0xE4 0x1D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x53 0x53 0x02 0xC4 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xEB 0x0B 0x1B 0xF6 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA1 0xC8 0xD1 0xC3 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x59 0xA5 0x12 0x55 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x8A 0xA0 0x97 0xFA ...

---- EOF - GMER 1.0.14 ----
 
That appears to be ok.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
 
- That's it. "SHOW ALL" was UN-CHECKED and greyed out. Still looks like a lot of data.

Attached is a screen shot of all the pop-ups.

Again, thanks for your time.
 
Logfile of random's system information tool 1.05 (written by random/random)
Run by Owner at 2008-12-29 10:43:52
Microsoft Windows XP Professional Service Pack 3
System drive C: has 260 GB (54%) free of 477 GB
Total RAM: 3070 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:39 AM, on 12/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Documents and Settings\Owner\Desktop\Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/nwshp?hl=en&tab=wn
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} (PlayerOCX Control) - http://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Active WebCam Watchdog (ACTIVEWEBCAMWATCHDOG) - PY Software - C:\Program Files\Active WebCam\Watchdog.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c8e207f066345c) (gupdate1c8e207f066345c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 14803 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\Norton Security Scan for Owner.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2}]
SpywareGuardDLBLOCK.CBrowserHelper - C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-02 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-04-02 2554944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-17 652784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2007-05-10 321120]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-12-05 8523776]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-12-05 81920]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"Power2GoExpress"=C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe [2008-01-14 2667816]
"CLJ"=0 []
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2007-10-17 128296]
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [2008-01-11 623992]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-09-14 14820864]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2007-08-06 115560]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2008-03-21 91432]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2008-08-04 160800]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-02 68856]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"Power2GoExpress"=NA []
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-09-04 81920]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
"CTSyncU.exe"=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2007-07-17 868352]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2008-11-10 2356088]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2008-05-28 87352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=C:\Program Files\SpywareGuard\spywareguard.dll [2003-08-02 126976]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccEvtMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ccSetMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmcService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Symantec Antivirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Symantec Antvirus]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2"
"C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe"="C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2 Update"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\CyberLink\PowerDirector\PDR.exe"="C:\Program Files\CyberLink\PowerDirector\PDR.exe:*:Enabled:CyberLink PowerDirector"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe"="C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service"
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE"="C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service"
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Active WebCam\WebCam.exe"="C:\Program Files\Active WebCam\WebCam.exe:*:Enabled:Active WebCam"
"C:\Program Files\Active WebCam\Watchdog.exe"="C:\Program Files\Active WebCam\Watchdog.exe:*:Enabled:Watchdog"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe"="C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:*:Enabled:PandoRest Application Name"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======List of files/folders created in the last 1 months======

2008-12-29 10:43:52 ----D---- C:\rsit
2008-12-29 09:57:50 ----A---- C:\WINDOWS\gmer.ini
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer.exe
2008-12-29 09:57:49 ----A---- C:\WINDOWS\gmer.dll
2008-12-29 09:55:34 ----D---- C:\Gmer
2008-12-26 16:50:48 ----D---- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-12-26 16:50:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-26 16:50:42 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-26 16:39:25 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-26 13:15:45 ----D---- C:\Program Files\Malware Removal Tool
2008-12-26 13:14:42 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-26 13:14:22 ----D---- C:\Program Files\CleanUp!
2008-12-26 13:11:52 ----D---- C:\Program Files\CCleaner
2008-12-22 00:24:29 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-12-22 00:24:25 ----D---- C:\Program Files\Yahoo!
2008-12-12 21:52:23 ----D---- C:\Documents and Settings\Owner\Application Data\RToolDS
2008-12-12 21:52:20 ----D---- C:\Program Files\RToolDS
2008-12-12 20:16:11 ----D---- C:\Sarah's DS
2008-12-11 21:37:39 ----D---- C:\WINDOWS\Minidump
2008-12-11 19:19:02 ----D---- C:\Music
2008-12-11 16:35:43 ----D---- C:\Program Files\iPod
2008-12-11 16:35:40 ----D---- C:\Program Files\iTunes
2008-12-11 16:35:40 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:35:08 ----D---- C:\Program Files\Bonjour
2008-12-11 16:33:04 ----D---- C:\Program Files\Apple Software Update
2008-12-10 03:01:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2008-12-10 03:00:30 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-10 03:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2008-12-10 03:00:17 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2008-12-06 17:11:30 ----D---- C:\Program Files\ABC Amber LIT Converter
2008-12-04 22:55:58 ----D---- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache

======List of files/folders modified in the last 1 months======

2008-12-29 10:33:55 ----D---- C:\WINDOWS\Temp
2008-12-29 10:26:35 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-12-29 10:23:52 ----D---- C:\Program Files\Mozilla Firefox
2008-12-29 10:07:38 ----D---- C:\WINDOWS\Registration
2008-12-29 10:06:45 ----D---- C:\WINDOWS
2008-12-29 10:06:38 ----D---- C:\WINDOWS\system32\Lang
2008-12-29 09:57:49 ----D---- C:\WINDOWS\system32\drivers
2008-12-29 01:11:26 ----D---- C:\Documents and Settings\Owner\Application Data\NewsBin
2008-12-28 18:00:01 ----D---- C:\Program Files\Norton Security Scan
2008-12-28 13:26:00 ----D---- C:\WINDOWS\Prefetch
2008-12-28 13:21:52 ----D---- C:\Program Files\Active WebCam
2008-12-28 10:19:02 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-28 09:46:56 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-28 09:46:53 ----D---- C:\Program Files\SpywareBlaster
2008-12-27 07:18:18 ----D---- C:\Voyager
2008-12-26 16:57:08 ----D---- C:\WINDOWS\system32
2008-12-26 16:50:42 ----RD---- C:\Program Files
2008-12-26 13:48:40 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-26 13:15:23 ----D---- C:\WINDOWS\Debug
2008-12-26 13:05:22 ----D---- C:\WINDOWS\system32\config
2008-12-25 15:42:53 ----D---- C:\NDS
2008-12-24 12:47:00 ----SHD---- C:\WINDOWS\Installer
2008-12-24 12:46:54 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-12-23 20:14:03 ----D---- C:\Program Files\SpywareGuard
2008-12-23 19:20:19 ----RASH---- C:\WINDOWS\system32\userinit.exe
2008-12-23 10:05:16 ----D---- C:\Program Files\eMule
2008-12-17 13:44:47 ----HD---- C:\WINDOWS\inf
2008-12-17 13:44:42 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-17 13:44:29 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-13 23:49:30 ----D---- C:\SYSPREP
2008-12-13 09:36:20 ----D---- C:\NDS_DPG
2008-12-13 01:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-12 23:10:49 ----D---- C:\NDS Roms Full
2008-12-11 21:15:21 ----D---- C:\Program Files\QuickTime
2008-12-11 16:35:55 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-12-11 16:35:42 ----D---- C:\Program Files\Common Files\Apple
2008-12-11 16:33:07 ----SD---- C:\WINDOWS\Tasks
2008-12-10 03:00:55 ----D---- C:\Program Files\Internet Explorer
2008-12-09 15:24:38 ----A---- C:\WINDOWS\system32\MRT.exe
2008-12-04 23:05:58 ----D---- C:\Program Files\Hospital Hustle
2008-12-03 16:09:38 ----A---- C:\WINDOWS\AviSplitter.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2008-12-29 85969]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2007-08-14 250416]
R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2007-08-14 25136]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2007-01-09 191544]
R1 WPS;WPS; \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys []
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-14 3856896]
R3 lmimirr;lmimirr; C:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-02-28 10144]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2008-08-04 33808]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVENG.SYS []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081228.020\NAVEX15.SYS []
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-12-05 7435392]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2007-01-09 27576]
R3 Teefer2;Teefer2 Miniport; C:\WINDOWS\system32\DRIVERS\teefer2.sys [2007-08-06 49024]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 WpsHelper;WpsHelper; \??\C:\WINDOWS\system32\drivers\WpsHelper.sys []
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 42752]
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys []
S3 awdnpolt;awdnpolt; C:\WINDOWS\system32\drivers\awdnpolt.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys []
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\system32\DRIVERS\mxnic.sys [2001-08-17 19968]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2007-08-14 277040]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
S4 vsdatant;vsdatant; a []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-07-13 611664]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 Capture Device Service;Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [2006-08-11 200704]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-08-06 108392]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2007-08-06 108392]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-02-17 20543]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-17 168432]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-08-22 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2008-08-04 164896]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-02-17 61503]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-09-04 131072]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-12-05 155716]
R2 OpenCASE Media Agent;OpenCASE Media Agent; C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-05 835208]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-04-19 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-04-19 107832]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-04-07 241734]
R2 SmcService;Symantec Management Client; C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe [2007-09-07 2532736]
R2 Symantec AntiVirus;Symantec Endpoint Protection; C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe [2007-09-06 2177464]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2007-01-18 67056]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-04-03 654848]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S2 gupdate1c8e207f066345c;Google Update Service (gupdate1c8e207f066345c); C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-29 133104]
S3 ACTIVEWEBCAMWATCHDOG;Active WebCam Watchdog; C:\Program Files\Active WebCam\Watchdog.exe [2008-07-27 719696]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-08-11 3093872]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 SNAC;Symantec Network Access Control; C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE [2007-09-07 234888]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-06-14 74656]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------
 
info.txt logfile of random's system information tool 1.05 2008-12-29 10:44:40

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\InstallShield Installation Information\{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}\setup.exe" --u:{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABC Amber LIT Converter-->C:\PROGRA~1\ABCAMB~1\UNWISE.EXE C:\PROGRA~1\ABCAMB~1\INSTALL.LOG
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Active WebCam-->"C:\Program Files\Active WebCam\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 8.1.2 Professional-->msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced PDF Repair v1.1-->C:\PROGRA~1\APDFR\UNWISE.EXE C:\PROGRA~1\APDFR\INSTALL.LOG
Advanced Word Repair v1.2-->C:\PROGRA~1\AWR\UNWISE.EXE C:\PROGRA~1\AWR\INSTALL.LOG
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
Avi2Dvd 0.4.5 beta-->C:\Program Files\Avi2Dvd\uninst.exe
AviScript 2.9 (Lite Version)-->"C:\Program Files\AviScript 2.9 (Lite Version)\unins000.exe"
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Beach Party Craze-->C:\PROGRA~1\GAMEHO~1\BEACHP~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\BEACHP~1\INSTALL.LOG
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Cinema Craft Encoder SP-->C:\PROGRA~1\CUSTOM~1\CINEMA~1\uinst.exe
CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
CoffeeCup HTML Editor 2008-->C:\PROGRA~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\INSTALL.LOG
Cooking Academy-->C:\PROGRA~1\GAMEHO~1\COOKIN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\COOKIN~1\INSTALL.LOG
Corel Paint Shop Pro Photo X2-->MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
CyberLink PhotoNow-->"C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DocRepair-->C:\PROGRA~1\Jufsoft\DOCREP~1\UNWISE.EXE C:\PROGRA~1\Jufsoft\DOCREP~1\INSTALL.LOG
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVD-lab PRO 2.5-->"C:\Program Files\DVDlabPro2\unins000.exe"
EA Download Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
EasyRecovery Professional-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{268723B7-A994-4286-9F85-B974D5CAFC7B} /l1033
eMule-->"C:\Program Files\eMule\Uninstall.exe"
ffdshow [rev 2060] [2008-08-01]-->"C:\Program Files\ffdshow\unins000.exe"
FileZilla Client 3.1.0.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
GameHouse Solitaire Challenge-->C:\PROGRA~1\GAMEHO~1\GAMEHO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\GAMEHO~1\INSTALL.LOG
Golden Eagle FlightPrep 2007 SP1-->C:\Program Files\InstallShield Installation Information\{B4AC94AE-A5CE-4BB5-897C-E45E558F3277}\setup.exe -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Update-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hidden Wonders of the Depths-->C:\PROGRA~1\GAMEHO~1\HIDDEN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\HIDDEN~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB895961-v4)-->"C:\WINDOWS\$NtUninstallKB895961-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HTML-Kit-->"C:\Program Files\Chami\HTML-Kit\unins000.exe"
InterVideo DeviceService-->MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jojo's Fashion Show 2-->C:\PROGRA~1\GAMEHO~1\JOJO'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\JOJO'S~1\INSTALL.LOG
Kaspersky Online Scanner-->C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
KissYouTube.com Offline Version 1.1 Freeware-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\kiss\ST6UNST.LOG"
LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
LightScribe Template Designs - Art Pack 1-->MsiExec.exe /X{2CDB2DCD-1153-4ED4-9D0A-606231CEFE9A}
LightScribe Template Designs - Fantasy Pack 1-->MsiExec.exe /X{DE72186D-A4A5-4504-839C-B14FC3432DA1}
LightScribe Template Designs - Holiday Pack 1-->MsiExec.exe /X{CEF736FF-8133-42F3-8E18-BDFE293B87FF}
LightScribe Template Designs - Special Occasion Pack 1-->MsiExec.exe /X{B6C766E9-B26D-4D54-A22B-A52B069C6C14}
LightScribe Template Designs - Sports Pack 1-->MsiExec.exe /X{725F0ABA-808A-4256-885C-1E60245521D0}
LightScribe Template Designs - Tattoo Pack 1-->MsiExec.exe /X{E35A1183-F6D8-4DCA-A111-296AFFA00A5C}
LightScribe Template Designs - Urban Pack 1-->MsiExec.exe /X{85548764-32DC-43ED-BAA5-5386FDB2500A}
LightScribe Template Designs - Wedding Pack 1-->MsiExec.exe /X{15B6EAD9-E83D-458F-AF6F-B8F865FA4F28}
LightScribeTemplateLabeler-->MsiExec.exe /X{305D4B08-5807-4475-B1C8-D54685534864}
Lively by Google-->MsiExec.exe /X{2DE38C17-DD7E-41BA-88BC-0A2387D29657}
LiveUpdate 3.3 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lucy's Expedition-->C:\PROGRA~1\GAMEHO~1\LUCY'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\LUCY'S~1\INSTALL.LOG
Malware Removal Tool-->"C:\Program Files\Malware Removal Tool\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaMonkey 3.0-->"C:\Program Files\MediaMonkey\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Corporation-->MsiExec.exe /I{7B08D306-7266-4647-A926-2F78817ED1E0}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft LifeCam-->MsiExec.exe /X{6BCB7EAA-598C-4836-B7EA-3642E41AA222}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Monopoly by Parker Brothers-->C:\PROGRA~1\GAMEHO~1\MONOPO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MONOPO~1\INSTALL.LOG
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 Audio Editor v6.6-->"C:\Program Files\Mp3 Audio Editor\unins000.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Mysteryville-->C:\PROGRA~1\GAMEHO~1\MYSTER~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MYSTER~1\INSTALL.LOG
NBC Direct Beta-->MsiExec.exe /I{7A647B7A-9FE7-44A2-9041-C04528D44EB9}
NewsBin Pro-->C:\Program Files\NewsBin\uninst.exe
No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
Norton Security Scan (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe" /X
Norton Security Scan-->MsiExec.exe /X{3FADAA19-E595-44CA-A072-58B6B0851768}
Nucleus Kernel Word Demo ver 4.03-->"C:\Program Files\Nucleus Kernel Word Demo\unins000.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
OpenCASE Media Agent-->MsiExec.exe /I{1771FDC8-D846-4B77-996A-C80DAD42C03F}
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RichFLV-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall de.benz.RichFLV 452D2865B2D5CE6F34BBFAC997E63D0882A4858D.1
RichFLV-->MsiExec.exe /I{46B62454-F462-E952-0EA3-3FB1CDF552A9}
Ricochet Lost Worlds Recharged-->C:\PROGRA~1\GAMEHO~1\RICOCH~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\RICOCH~1\INSTALL.LOG
RToolDS v0.3.1382-->C:\Program Files\RToolDS\uninst.exe
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\setup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2-->"C:\Program Files\SpywareGuard\unins000.exe"
SureThing CD Labeler LightScribe 5.0.581.0-->"C:\Program Files\SureThing CD Labeler 5\unins000.exe"
Symantec Endpoint Protection-->MsiExec.exe /I{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TBS WMP Plug-in-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{13515135-48BB-4184-8C1F-2FAE0138E200}
TMPGEnc Plus 2.5-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A1E27FF-BE53-45B4-950F-060236E98E3D}
Tom Clancy's Rainbow Six Vegas 2-->"C:\Program Files\InstallShield Installation Information\{FD416706-875C-4B0B-A23A-9E740DAE029E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Ulead DVD MovieFactory 6 TBYB-->C:\Program Files\InstallShield Installation Information\{CCC4E428-411E-4605-B515-317D50ABD477}\setup.exe -runfromtemp -l0x0409
Ulead GIF Animator 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\Setup.exe"
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Vuze-->C:\Program Files\Vuze\uninstall.exe
Wedding Dash 2 Rings Around the World-->MsiExec.exe /X{851A0AB9-E984-47B8-9194-96CE096FB7C9}
Wheel of Fortune 2-->C:\PROGRA~1\GAMEHO~1\WHEELO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\WHEELO~1\INSTALL.LOG
Wii Max Media Manager Pro-->"C:\Program Files\Datel\Wii Max Media Manager Pro\unins000.exe"
Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail-->MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WMPCDText 1.0-->"C:\Program Files\WMPCDText\unins000.exe"
Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009

======Hosts File======

127.0.0.1 localhost
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 a9rhiwa.cn #[Google.Warning]
127.0.0.1 www.a9rhiwa.cn
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net

======Security center information======

AV: Symantec Endpoint Protection
FW: Symantec Endpoint Protection

System event log

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12609
Source Name: Service Control Manager
Time Written: 20081117185700.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12608
Source Name: Service Control Manager
Time Written: 20081117175650.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12607
Source Name: Service Control Manager
Time Written: 20081117165641.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12606
Source Name: Service Control Manager
Time Written: 20081117155631.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12605
Source Name: Service Control Manager
Time Written: 20081117145621.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000109fb.

Record Number: 3309
Source Name: Application Error
Time Written: 20081222123438.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3308
Source Name: Application Error
Time Written: 20081222103234.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3307
Source Name: Application Error
Time Written: 20081222103232.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3306
Source Name: Application Error
Time Written: 20081222093158.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3305
Source Name: Application Error
Time Written: 20081222092812.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 55 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=3702
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------
 
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

eMule
Vuze


I'd like you to read the this thread.

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Delete info.txt from c:\rsit folder.

Please run a new RSIT scan when finished and post the log back here.
 
Thanks. I knew about eMule. Tried to send video of son's birthday to his older brother. Not sure about Vuze. Here's the info.txt

info.txt logfile of random's system information tool 1.05 2008-12-29 11:08:49

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\InstallShield Installation Information\{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}\setup.exe" --u:{BB8AE808-F003-4C7F-B56B-8C80EEAFFE23}
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABC Amber LIT Converter-->C:\PROGRA~1\ABCAMB~1\UNWISE.EXE C:\PROGRA~1\ABCAMB~1\INSTALL.LOG
AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
Active WebCam-->"C:\Program Files\Active WebCam\PY_UNINSTAL.EXE" SOFTWARE\PySoft\Act_WebCam
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 8.1.2 Professional-->msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Advanced PDF Repair v1.1-->C:\PROGRA~1\APDFR\UNWISE.EXE C:\PROGRA~1\APDFR\INSTALL.LOG
Advanced Word Repair v1.2-->C:\PROGRA~1\AWR\UNWISE.EXE C:\PROGRA~1\AWR\INSTALL.LOG
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
Avi2Dvd 0.4.5 beta-->C:\Program Files\Avi2Dvd\uninst.exe
AviScript 2.9 (Lite Version)-->"C:\Program Files\AviScript 2.9 (Lite Version)\unins000.exe"
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Beach Party Craze-->C:\PROGRA~1\GAMEHO~1\BEACHP~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\BEACHP~1\INSTALL.LOG
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Cinema Craft Encoder SP-->C:\PROGRA~1\CUSTOM~1\CINEMA~1\uinst.exe
CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
CoffeeCup HTML Editor 2008-->C:\PROGRA~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\INSTALL.LOG
Cooking Academy-->C:\PROGRA~1\GAMEHO~1\COOKIN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\COOKIN~1\INSTALL.LOG
Corel Paint Shop Pro Photo X2-->MsiExec.exe /X{64E72FB1-2343-4977-B4A8-262CD53D0BD3}
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\setup.exe" -l0x9 /remove
CyberLink PhotoNow-->"C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DocRepair-->C:\PROGRA~1\Jufsoft\DOCREP~1\UNWISE.EXE C:\PROGRA~1\Jufsoft\DOCREP~1\INSTALL.LOG
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
DVD-lab PRO 2.5-->"C:\Program Files\DVDlabPro2\unins000.exe"
EA Download Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
EasyRecovery Professional-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{268723B7-A994-4286-9F85-B974D5CAFC7B} /l1033
ffdshow [rev 2060] [2008-08-01]-->"C:\Program Files\ffdshow\unins000.exe"
FileZilla Client 3.1.0.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
GameHouse Solitaire Challenge-->C:\PROGRA~1\GAMEHO~1\GAMEHO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\GAMEHO~1\INSTALL.LOG
Golden Eagle FlightPrep 2007 SP1-->C:\Program Files\InstallShield Installation Information\{B4AC94AE-A5CE-4BB5-897C-E45E558F3277}\setup.exe -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Update-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hidden Wonders of the Depths-->C:\PROGRA~1\GAMEHO~1\HIDDEN~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\HIDDEN~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB895961-v4)-->"C:\WINDOWS\$NtUninstallKB895961-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HTML-Kit-->"C:\Program Files\Chami\HTML-Kit\unins000.exe"
InterVideo DeviceService-->MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jojo's Fashion Show 2-->C:\PROGRA~1\GAMEHO~1\JOJO'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\JOJO'S~1\INSTALL.LOG
Kaspersky Online Scanner-->C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
KissYouTube.com Offline Version 1.1 Freeware-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\kiss\ST6UNST.LOG"
LightScribe System Software 1.14.25.1-->MsiExec.exe /X{DA9DAC64-C947-47BA-B411-8A1959B177CF}
LightScribe Template Designs - Art Pack 1-->MsiExec.exe /X{2CDB2DCD-1153-4ED4-9D0A-606231CEFE9A}
LightScribe Template Designs - Fantasy Pack 1-->MsiExec.exe /X{DE72186D-A4A5-4504-839C-B14FC3432DA1}
LightScribe Template Designs - Holiday Pack 1-->MsiExec.exe /X{CEF736FF-8133-42F3-8E18-BDFE293B87FF}
LightScribe Template Designs - Special Occasion Pack 1-->MsiExec.exe /X{B6C766E9-B26D-4D54-A22B-A52B069C6C14}
LightScribe Template Designs - Sports Pack 1-->MsiExec.exe /X{725F0ABA-808A-4256-885C-1E60245521D0}
LightScribe Template Designs - Tattoo Pack 1-->MsiExec.exe /X{E35A1183-F6D8-4DCA-A111-296AFFA00A5C}
LightScribe Template Designs - Urban Pack 1-->MsiExec.exe /X{85548764-32DC-43ED-BAA5-5386FDB2500A}
LightScribe Template Designs - Wedding Pack 1-->MsiExec.exe /X{15B6EAD9-E83D-458F-AF6F-B8F865FA4F28}
LightScribeTemplateLabeler-->MsiExec.exe /X{305D4B08-5807-4475-B1C8-D54685534864}
Lively by Google-->MsiExec.exe /X{2DE38C17-DD7E-41BA-88BC-0A2387D29657}
LiveUpdate 3.3 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lucy's Expedition-->C:\PROGRA~1\GAMEHO~1\LUCY'S~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\LUCY'S~1\INSTALL.LOG
Malware Removal Tool-->"C:\Program Files\Malware Removal Tool\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaMonkey 3.0-->"C:\Program Files\MediaMonkey\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Corporation-->MsiExec.exe /I{7B08D306-7266-4647-A926-2F78817ED1E0}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft LifeCam-->MsiExec.exe /X{6BCB7EAA-598C-4836-B7EA-3642E41AA222}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Monopoly by Parker Brothers-->C:\PROGRA~1\GAMEHO~1\MONOPO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MONOPO~1\INSTALL.LOG
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 Audio Editor v6.6-->"C:\Program Files\Mp3 Audio Editor\unins000.exe"
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
Mysteryville-->C:\PROGRA~1\GAMEHO~1\MYSTER~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\MYSTER~1\INSTALL.LOG
NBC Direct Beta-->MsiExec.exe /I{7A647B7A-9FE7-44A2-9041-C04528D44EB9}
NewsBin Pro-->C:\Program Files\NewsBin\uninst.exe
No-IP.com DUC (remove only)-->"C:\Program Files\No-IP\DUC20.exe" -uninstall
Norton Security Scan (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe" /X
Norton Security Scan-->MsiExec.exe /X{3FADAA19-E595-44CA-A072-58B6B0851768}
Nucleus Kernel Word Demo ver 4.03-->"C:\Program Files\Nucleus Kernel Word Demo\unins000.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
OpenCASE Media Agent-->MsiExec.exe /I{1771FDC8-D846-4B77-996A-C80DAD42C03F}
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RichFLV-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall de.benz.RichFLV 452D2865B2D5CE6F34BBFAC997E63D0882A4858D.1
RichFLV-->MsiExec.exe /I{46B62454-F462-E952-0EA3-3FB1CDF552A9}
Ricochet Lost Worlds Recharged-->C:\PROGRA~1\GAMEHO~1\RICOCH~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\RICOCH~1\INSTALL.LOG
RToolDS v0.3.1382-->C:\Program Files\RToolDS\uninst.exe
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\setup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2-->"C:\Program Files\SpywareGuard\unins000.exe"
SureThing CD Labeler LightScribe 5.0.581.0-->"C:\Program Files\SureThing CD Labeler 5\unins000.exe"
Symantec Endpoint Protection-->MsiExec.exe /I{FB8A4E30-9915-4814-ADF9-42E00D9FDC3D}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TBS WMP Plug-in-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{13515135-48BB-4184-8C1F-2FAE0138E200}
TMPGEnc Plus 2.5-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A1E27FF-BE53-45B4-950F-060236E98E3D}
Tom Clancy's Rainbow Six Vegas 2-->"C:\Program Files\InstallShield Installation Information\{FD416706-875C-4B0B-A23A-9E740DAE029E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Ulead DVD MovieFactory 6 TBYB-->C:\Program Files\InstallShield Installation Information\{CCC4E428-411E-4605-B515-317D50ABD477}\setup.exe -runfromtemp -l0x0409
Ulead GIF Animator 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AF3E926-ED59-11D4-A44B-0000E86D2305}\Setup.exe"
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Wedding Dash 2 Rings Around the World-->MsiExec.exe /X{851A0AB9-E984-47B8-9194-96CE096FB7C9}
Wheel of Fortune 2-->C:\PROGRA~1\GAMEHO~1\WHEELO~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\WHEELO~1\INSTALL.LOG
Wii Max Media Manager Pro-->"C:\Program Files\Datel\Wii Max Media Manager Pro\unins000.exe"
Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail-->MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WMPCDText 1.0-->"C:\Program Files\WMPCDText\unins000.exe"
Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009

======Hosts File======

127.0.0.1 localhost
127.0.0.1 ad.a8.net
127.0.0.1 asy.a8ww.net
127.0.0.1 a9rhiwa.cn #[Google.Warning]
127.0.0.1 www.a9rhiwa.cn
127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
127.0.0.1 phpadsnew.abac.com
127.0.0.1 a.abnad.net

======Security center information======

AV: Symantec Endpoint Protection
FW: Symantec Endpoint Protection

System event log

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12612
Source Name: Service Control Manager
Time Written: 20081117215729.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12611
Source Name: Service Control Manager
Time Written: 20081117205720.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12610
Source Name: Service Control Manager
Time Written: 20081117195710.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12609
Source Name: Service Control Manager
Time Written: 20081117185700.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: BRAD
Event Code: 7035
Message: The COH_Mon service was successfully sent a start control.

Record Number: 12608
Source Name: Service Control Manager
Time Written: 20081117175650.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Application event log

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x000109fb.

Record Number: 3309
Source Name: Application Error
Time Written: 20081222123438.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3308
Source Name: Application Error
Time Written: 20081222103234.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3307
Source Name: Application Error
Time Written: 20081222103232.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1001
Message: Fault bucket 523498321.

Record Number: 3306
Source Name: Application Error
Time Written: 20081222093158.000000-300
Event Type: error
User:

Computer Name: BRAD
Event Code: 1000
Message: Faulting application COH32.exe, version 6.1.2.54, faulting module COH32.exe, version 6.1.2.54, fault address 0x000bdab1.

Record Number: 3305
Source Name: Application Error
Time Written: 20081222092812.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 55 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=3702
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------
 
Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
 
ComboFix 08-12-28.04 - Owner 2008-12-29 11:22:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2303 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
FW: Symantec Endpoint Protection *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASC3550P


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-29 10:43 . 2008-12-29 11:08 <DIR> d-------- C:\rsit
2008-12-29 09:57 . 2008-12-29 10:08 345 --a------ c:\windows\gmer.ini
2008-12-29 09:55 . 2008-12-29 09:55 <DIR> d-------- C:\Gmer
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-26 16:50 . 2008-12-26 16:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-26 16:50 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-26 16:50 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-26 13:15 . 2008-12-26 13:15 <DIR> d-------- c:\program files\Malware Removal Tool
2008-12-26 13:14 . 2008-12-26 13:14 <DIR> d-------- c:\program files\CleanUp!
2008-12-26 13:11 . 2008-12-26 13:11 <DIR> d-------- c:\program files\CCleaner
2008-12-22 00:24 . 2008-12-24 19:58 <DIR> d-------- c:\program files\Yahoo!
2008-12-22 00:24 . 2008-12-24 19:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-12 21:52 . 2008-12-12 21:52 <DIR> d-------- c:\program files\RToolDS
2008-12-12 21:52 . 2008-12-25 15:46 <DIR> d-------- c:\documents and settings\Owner\Application Data\RToolDS
2008-12-12 20:16 . 2008-12-12 20:16 <DIR> d-------- C:\Sarah's DS
2008-12-11 19:19 . 2008-12-13 23:49 <DIR> d-------- C:\Music
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\iTunes
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\iPod
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\program files\Bonjour
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:33 . 2008-12-11 16:33 <DIR> d-------- c:\program files\Apple Software Update
2008-12-08 21:47 . 2008-12-08 21:47 244 --ah----- C:\sqmnoopt06.sqm
2008-12-08 21:47 . 2008-12-08 21:47 232 --ah----- C:\sqmdata06.sqm
2008-12-06 17:11 . 2008-12-06 21:09 <DIR> d-------- c:\program files\ABC Amber LIT Converter
2008-12-04 22:55 . 2008-12-04 22:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\BigFishGamesCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 16:20 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-29 16:06 --------- d-----w c:\program files\eMule
2008-12-29 15:26 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-29 06:11 --------- d-----w c:\documents and settings\Owner\Application Data\NewsBin
2008-12-28 23:00 --------- d-----w c:\program files\Norton Security Scan
2008-12-28 18:21 --------- d-----w c:\program files\Active WebCam
2008-12-28 14:46 --------- d-----w c:\program files\SpywareBlaster
2008-12-26 18:48 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-24 17:46 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-24 01:14 --------- d-----w c:\program files\SpywareGuard
2008-12-12 02:15 --------- d-----w c:\program files\QuickTime
2008-12-11 21:35 --------- d-----w c:\program files\Common Files\Apple
2008-12-05 04:05 --------- d-----w c:\program files\Hospital Hustle
2008-11-29 12:37 1,140 ----a-w C:\drmHeader.bin
2008-11-28 19:53 --------- d-----w c:\documents and settings\Owner\Application Data\GameInvest
2008-11-28 19:52 --------- d-----w c:\documents and settings\Owner\Application Data\SpinTop
2008-11-27 20:18 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-21 16:34 --------- d-----w c:\program files\GameHouse
2008-11-21 16:34 --------- d-----w c:\documents and settings\Owner\Application Data\GameHouse
2008-11-21 16:34 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-21 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-11-20 18:16 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org
2008-11-20 18:15 --------- d-----w c:\program files\OpenOffice.org 3
2008-11-20 18:15 --------- d-----w c:\program files\JRE
2008-11-20 18:14 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-11-20 18:10 149,286,272 ----a-w C:\OOo_3.0.0_Win32Intel_install_wJRE_en-US.exe
2008-11-20 18:03 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2008-11-17 04:40 --------- d-----w c:\documents and settings\Owner\Application Data\BeachPartyCraze
2008-11-16 03:49 --------- d-----w c:\program files\DVDlabPro2
2008-11-16 00:26 --------- d-----w c:\documents and settings\Owner\Application Data\Ulead Systems
2008-11-15 22:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-15 22:19 --------- d-----w c:\program files\DivX
2008-11-15 22:19 --------- d-----w c:\program files\Common Files\InterVideo
2008-11-15 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\InterVideo
2008-11-15 22:18 --------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2008-11-15 22:17 --------- d-----w c:\program files\Ulead Systems
2008-11-15 22:17 --------- d-----w c:\program files\Common Files\Ulead Systems
2008-11-15 20:24 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-15 20:23 --------- d-----w c:\program files\DVD Shrink
2008-11-14 20:36 --------- d-----w c:\program files\WorldOfGoo
2008-11-14 20:36 --------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2008-04-19 18:46 22,328 ----a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2008-07-14 00:37 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071320080714\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-07-13_13.08.25.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-02 13:42:10 83,968 -c--a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 -c--a-w c:\windows\$hf_mig$\KB946648\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
+ 2008-07-07 20:23:18 253,952 -c--a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 -c--a-w c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:19 382,840 -c--a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-04-12 04:22:26 691,712 -c--a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
+ 2007-12-03 15:25:31 755,576 -c--a-w c:\windows\$hf_mig$\KB951066\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
+ 2008-07-11 12:51:51 62,976 -c--a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 -c--a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 -c--a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-05-07 09:07:23 135,168 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 -c--a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 -c--a-w c:\windows\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 -c--a-w c:\windows\$hf_mig$\KB951978\update\updspapi.dll
+ 2008-05-01 14:38:05 331,776 -c--a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2007-11-30 11:18:51 17,272 -c--a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2007-11-30 11:18:51 231,288 -c--a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2007-11-30 11:18:51 26,488 -c--a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 -c--a-w c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2007-11-30 11:18:51 382,840 -c--a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2008-06-24 16:53:10 74,240 -c--a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 -c--a-w c:\windows\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:22 382,840 -c--a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-06-23 16:01:38 124,928 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\advpack.dll
+ 2008-06-23 16:01:38 347,136 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtmsft.dll
+ 2008-06-23 16:01:39 214,528 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtrans.dll
+ 2008-06-23 16:01:39 132,608 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\extmgr.dll
+ 2008-06-23 16:01:39 63,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\icardie.dll
+ 2008-06-23 08:23:18 70,656 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe
+ 2008-06-23 16:01:39 153,088 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakeng.dll
+ 2008-06-23 16:01:39 230,400 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieaksie.dll
+ 2008-06-21 05:23:53 161,792 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dat
+ 2008-06-23 16:01:40 383,488 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dll
+ 2008-06-23 16:01:40 388,608 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iedkcs32.dll
+ 2008-06-23 16:01:43 6,068,736 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieframe.dll
+ 2008-06-23 16:01:43 44,544 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iernonce.dll
+ 2008-06-23 16:01:44 267,776 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iertutil.dll
+ 2008-06-23 08:23:18 13,824 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe
+ 2008-06-23 08:23:52 625,664 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
+ 2008-06-23 16:01:46 27,648 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\jsproxy.dll
+ 2008-06-23 16:01:46 459,264 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeeds.dll
+ 2008-06-23 16:01:46 52,224 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeedsbs.dll
+ 2008-06-23 16:01:49 3,594,240 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
+ 2008-06-23 16:01:49 477,696 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtmled.dll
+ 2008-06-23 16:01:49 193,024 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msrating.dll
+ 2008-06-23 16:01:50 671,232 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mstime.dll
+ 2008-06-23 16:01:50 102,912 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\occache.dll
+ 2008-06-23 16:01:50 44,544 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\pngfilt.dll
+ 2008-06-23 16:01:50 105,984 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\url.dll
+ 2008-06-23 16:01:51 1,162,752 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\urlmon.dll
+ 2008-06-23 16:01:51 233,472 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\webcheck.dll
+ 2008-06-23 16:01:51 827,904 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 -c--a-w c:\windows\$hf_mig$\KB953838-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 -c--a-w c:\windows\$hf_mig$\KB953839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c--a-w c:\windows\$hf_mig$\KB953839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 -c--a-w c:\windows\$hf_mig$\KB953839\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 -c--a-w c:\windows\$hf_mig$\KB953839\update\update.exe
+ 2007-11-30 11:18:51 382,840 -c--a-w c:\windows\$hf_mig$\KB953839\update\updspapi.dll
+ 2008-09-15 12:25:27 1,846,912 ----a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB954211\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
+ 2008-09-10 01:10:56 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2008-09-04 17:12:27 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 18:08:38 382,840 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-08-26 09:08:35 124,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\advpack.dll
+ 2008-08-26 09:08:36 347,136 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
+ 2008-08-26 09:08:36 214,528 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
+ 2008-08-26 09:08:36 132,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\extmgr.dll
+ 2008-08-26 09:08:36 63,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
+ 2008-08-25 08:43:21 70,656 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
+ 2008-08-26 09:08:36 153,088 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
+ 2008-08-26 09:08:36 230,400 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieaksie.dll
+ 2008-08-23 05:54:50 161,792 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
+ 2008-08-26 09:08:36 380,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dll
+ 2008-08-26 09:08:37 388,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-03 17:26:50 6,068,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
+ 2008-08-26 09:08:39 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
+ 2008-08-26 09:08:39 267,776 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
+ 2008-08-25 08:43:21 13,824 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
+ 2008-08-26 09:08:40 27,648 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
+ 2008-08-26 09:08:40 459,264 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
+ 2008-08-26 09:08:40 52,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
+ 2008-08-26 09:08:43 3,594,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
+ 2008-08-26 09:08:43 477,696 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
+ 2008-08-26 09:08:44 193,024 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
+ 2008-08-26 09:08:44 671,232 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
+ 2008-08-26 09:08:44 102,912 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
+ 2008-08-26 09:08:44 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
+ 2008-08-26 09:08:44 105,984 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
+ 2008-08-26 09:08:45 1,162,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
+ 2008-08-26 09:08:45 233,472 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\webcheck.dll
+ 2008-08-26 09:08:45 827,904 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-08-14 10:34:26 138,496 ----a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-08-14 10:39:28 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
+ 2008-08-14 19:39:46 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
+ 2008-08-14 10:09:44 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
+ 2008-08-14 20:11:10 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956841\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
+ 2008-09-08 11:37:19 333,824 ----a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
+ 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 13:02:04 755,576 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 13:02:12 382,840 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-10-15 16:25:53 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2004-08-04 07:10:08 53,248 -c----w c:\windows\$NtServicePackUninstall$\1394bus.sys
+ 2006-08-16 11:58:05 100,352 -c----w c:\windows\$NtServicePackUninstall$\6to4svc.dll
+ 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll
+ 2006-10-04 14:05:26 39,424 -c----w c:\windows\$NtServicePackUninstall$\acadproc.dll.000
+ 2004-08-10 19:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\accwiz.exe
+ 2004-08-10 19:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll
+ 2004-08-10 19:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll.000
+ 2004-08-10 19:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll
+ 2004-08-10 19:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll.000
+ 2004-08-10 19:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll
+ 2004-08-10 19:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll.000
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\aclui.dll
+ 2004-08-10 19:00:00 187,776 -c----w c:\windows\$NtServicePackUninstall$\acpi.sys
+ 2004-08-10 19:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll
+ 2004-08-10 19:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll.000
+ 2004-08-10 19:00:00 194,048 -c----w c:\windows\$NtServicePackUninstall$\activeds.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\actmovie.exe
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\actxprxy.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll.000
+ 2004-08-10 19:00:00 175,616 -c----w c:\windows\$NtServicePackUninstall$\adsldp.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\adsldpc.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\adsmsext.dll
+ 2004-08-10 19:00:00 263,680 -c----w c:\windows\$NtServicePackUninstall$\adsnt.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\adsnw.dll
+ 2004-08-10 19:00:00 616,960 -c----w c:\windows\$NtServicePackUninstall$\advapi32.dll
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys.000
+ 2008-06-20 10:44:38 138,368 -c----w c:\windows\$NtServicePackUninstall$\afd.sys
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentanm.dll
+ 2004-08-10 19:00:00 214,016 -c----w c:\windows\$NtServicePackUninstall$\agentctl.dll
+ 2006-10-12 14:02:52 42,496 -c----w c:\windows\$NtServicePackUninstall$\agentdp2.dll
+ 2007-03-09 13:58:57 57,344 -c----w c:\windows\$NtServicePackUninstall$\agentdpv.dll
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\agentmpx.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentpsh.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\agentsr.dll
+ 2006-10-12 11:09:53 256,512 -c----w c:\windows\$NtServicePackUninstall$\agentsvr.exe
+ 2004-08-03 23:07:42 42,368 -c----w c:\windows\$NtServicePackUninstall$\agp440.sys
+ 2004-08-03 23:07:44 44,928 -c----w c:\windows\$NtServicePackUninstall$\agpcpq.sys
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0405.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0406.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt0407.dll
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\agt0408.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0409.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt040b.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt040c.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\agt040e.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0410.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0413.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0414.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0415.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0416.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0419.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041d.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041f.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0816.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0c0a.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agtintl.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\ahui.exe
+ 2004-08-10 19:00:00 44,544 -c----w c:\windows\$NtServicePackUninstall$\alg.exe
+ 2004-08-03 23:07:42 42,752 -c----w c:\windows\$NtServicePackUninstall$\alim1541.sys
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\alrsvc.dll
+ 2004-08-03 23:07:44 43,008 -c----w c:\windows\$NtServicePackUninstall$\amdagp.sys
+ 2004-08-03 22:59:20 36,992 -c----w c:\windows\$NtServicePackUninstall$\amdk6.sys
+ 2004-08-03 22:59:22 37,376 -c----w c:\windows\$NtServicePackUninstall$\amdk7.sys
+ 2004-08-10 19:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\amstream.dll
+ 2004-08-10 19:00:00 126,976 -c----w c:\windows\$NtServicePackUninstall$\apphelp.dll
+ 2004-08-10 19:00:00 167,936 -c----w c:\windows\$NtServicePackUninstall$\appmgmts.dll
+ 2004-08-10 19:00:00 295,936 -c----w c:\windows\$NtServicePackUninstall$\appmgr.dll
+ 2004-08-03 22:58:30 60,800 -c----w c:\windows\$NtServicePackUninstall$\arp1394.sys
+ 2002-06-22 08:31:20 20,480 -c----w c:\windows\$NtServicePackUninstall$\aspnet_filter.dll
+ 2007-01-02 21:34:04 200,704 -c----w c:\windows\$NtServicePackUninstall$\aspnet_isapi.dll
+ 2004-08-04 13:11:06 24,576 -c----w c:\windows\$NtServicePackUninstall$\aspnet_regiis.exe
+ 2002-06-22 08:31:22 32,768 -c----w c:\windows\$NtServicePackUninstall$\aspnet_state.exe
+ 2007-01-02 21:34:04 32,768 -c----w c:\windows\$NtServicePackUninstall$\aspnet_wp.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\asr_fmt.exe
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\asr_pfu.exe
+ 2004-08-10 19:00:00 65,024 -c----w c:\windows\$NtServicePackUninstall$\asycfilt.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\asyncmac.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\at.exe
+ 2004-08-10 19:00:00 95,360 -c----w c:\windows\$NtServicePackUninstall$\atapi.sys
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\atl.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\atmadm.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\atmarpc.sys
+ 2004-08-10 19:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\atmfd.dll
+ 2004-08-10 19:00:00 55,936 -c----w c:\windows\$NtServicePackUninstall$\atmlane.sys
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\atmlib.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\attrib.exe
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\audiosrv.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\auditusr.exe
+ 2005-03-02 18:09:29 56,832 -c----w c:\windows\$NtServicePackUninstall$\authz.dll
+ 2004-08-10 19:00:00 588,800 -c----w c:\windows\$NtServicePackUninstall$\autochk.exe
+ 2004-08-10 19:00:00 602,624 -c----w c:\windows\$NtServicePackUninstall$\autoconv.exe
+ 2004-08-10 19:00:00 580,608 -c----w c:\windows\$NtServicePackUninstall$\autofmt.exe
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\autolfn.exe
+ 2004-08-10 19:00:00 84,992 -c----w c:\windows\$NtServicePackUninstall$\avifil32.dll
+ 2004-08-10 19:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\basesrv.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\batmeter.dll
+ 2004-08-10 19:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\batt.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\bidispl.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\bitsprx2.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\bitsprx3.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\blastcln.exe
+ 2004-08-10 19:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\bootcfg.exe
+ 2004-08-10 19:00:00 71,552 -c----w c:\windows\$NtServicePackUninstall$\bridge.sys
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\browselc.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\browser.dll
+ 2007-12-07 00:44:30 1,024,000 -c----w c:\windows\$NtServicePackUninstall$\browseui.dll
+ 2004-08-10 19:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\browsewm.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\bthci.dll
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys.000
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\bthserv.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\btpanui.dll
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\cabinet.dll
+ 2004-08-10 19:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\cabview.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\cacls.exe
+ 2004-08-10 19:00:00 385,024 -c----w c:\windows\$NtServicePackUninstall$\callcont.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\camocx.dll
+ 2004-08-10 19:00:00 142,848 -c----w c:\windows\$NtServicePackUninstall$\capesnpn.dll
+ 2005-07-26 04:39:42 225,792 -c----w c:\windows\$NtServicePackUninstall$\catsrv.dll
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\catsrvps.dll
+ 2005-07-26 04:39:43 625,152 -c----w c:\windows\$NtServicePackUninstall$\catsrvut.dll
+ 2004-08-10 19:00:00 63,744 -c----w c:\windows\$NtServicePackUninstall$\cdfs.sys
+ 2007-12-07 00:44:30 151,040 -c----w c:\windows\$NtServicePackUninstall$\cdfview.dll
+ 2005-09-10 01:53:41 2,067,968 -c----w c:\windows\$NtServicePackUninstall$\cdosys.dll
+ 2004-08-10 19:00:00 49,536 -c----w c:\windows\$NtServicePackUninstall$\cdrom.sys
+ 2004-08-10 19:00:00 194,560 -c----w c:\windows\$NtServicePackUninstall$\certcli.dll
+ 2004-08-10 19:00:00 457,728 -c----w c:\windows\$NtServicePackUninstall$\certmgr.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\cfgbkend.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\cfgmgr32.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\cic.dll
+ 2004-08-10 19:00:00 1,352,192 -c----w c:\windows\$NtServicePackUninstall$\cimwin32.dll
+ 2006-06-22 05:06:29 69,120 -c----w c:\windows\$NtServicePackUninstall$\ciodm.dll
+ 2004-08-10 19:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\cipher.exe
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\cisvc.exe
+ 2004-08-10 19:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\classpnp.sys
+ 2005-07-26 04:39:43 110,080 -c----w c:\windows\$NtServicePackUninstall$\clbcatex.dll
+ 2005-07-26 04:39:43 498,688 -c----w c:\windows\$NtServicePackUninstall$\clbcatq.dll
+ 2004-08-10 19:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\cleanmgr.exe
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.exe
+ 2004-08-10 19:00:00 102,912 -c----w c:\windows\$NtServicePackUninstall$\clipbrd.exe
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\clipsrv.exe
+ 2004-08-10 19:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\clusapi.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\cmcfg32.dll
+ 2004-08-10 19:00:00 388,608 -c----w c:\windows\$NtServicePackUninstall$\cmd.exe
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\cmdevtgprov.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\cmdial32.dll
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cmdl32.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmmon32.exe
+ 2004-08-10 19:00:00 185,344 -c----w c:\windows\$NtServicePackUninstall$\cmprops.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\cmsetacl.dll
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cmstp.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmutil.dll
+ 2004-08-04 00:56:42 47,104 -c----w c:\windows\$NtServicePackUninstall$\cnbjmon.dll
+ 2005-07-26 04:39:43 60,416 -c----w c:\windows\$NtServicePackUninstall$\colbact.dll
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\comaddin.dll
+ 2005-07-26 04:39:44 195,072 -c----w c:\windows\$NtServicePackUninstall$\comadmin.dll
+ 2006-08-25 15:45:58 617,472 -c----w c:\windows\$NtServicePackUninstall$\comctl32.dll
+ 2004-08-10 19:00:00 276,992 -c----w c:\windows\$NtServicePackUninstall$\comdlg32.dll
+ 2004-08-10 19:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\compatui.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\compstui.dll
+ 2005-07-26 04:39:44 97,792 -c----w c:\windows\$NtServicePackUninstall$\comrepl.dll
+ 2004-08-10 19:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\comrepl.exe
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\comrereg.exe
+ 2004-08-10 19:00:00 792,064 -c----w c:\windows\$NtServicePackUninstall$\comres.dll
+ 2004-08-10 19:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\comsetup.dll
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\comsnap.dll
+ 2005-07-26 04:39:44 1,267,200 -c----w c:\windows\$NtServicePackUninstall$\comsvcs.dll
+ 2005-07-26 04:39:45 540,160 -c----w c:\windows\$NtServicePackUninstall$\comuid.dll
+ 2004-08-10 19:00:00 1,032,192 -c----w c:\windows\$NtServicePackUninstall$\conf.exe
+ 2004-08-10 19:00:00 45,056 -c----w c:\windows\$NtServicePackUninstall$\confmrsl.dll
+ 2004-08-10 19:00:00 345,600 -c----w c:\windows\$NtServicePackUninstall$\confmsp.dll
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\conime.exe
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\corpol.dll
+ 2004-08-10 19:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\credui.dll
+ 2004-08-03 22:59:22 36,480 -c----w c:\windows\$NtServicePackUninstall$\crusoe.sys
+ 2004-08-10 19:00:00 597,504 -c----w c:\windows\$NtServicePackUninstall$\crypt32.dll
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\cryptdlg.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\cryptdll.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\cryptext.dll
+ 2004-08-10 19:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cryptnet.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\cryptsvc.dll
+ 2004-08-10 19:00:00 512,512 -c----w c:\windows\$NtServicePackUninstall$\cryptui.dll
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\cscdll.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\cscript.exe
+ 2004-08-10 19:00:00 326,656 -c----w c:\windows\$NtServicePackUninstall$\cscui.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\csrsrv.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\csrss.exe
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\ctfmon.exe
+ 2006-06-03 11:40:49 33,792 -c----w c:\windows\$NtServicePackUninstall$\custsat.dll
+ 2004-08-10 19:00:00 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\d3d8.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\d3d8thk.dll
+ 2004-08-10 19:00:00 1,689,088 -c----w c:\windows\$NtServicePackUninstall$\d3d9.dll
+ 2004-08-10 19:00:00 825,344 -c----w c:\windows\$NtServicePackUninstall$\d3dim700.dll
+ 2007-12-07 00:44:32 1,054,208 -c----w c:\windows\$NtServicePackUninstall$\danim.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\dataclen.dll
+ 2004-08-10 19:00:00 152,064 -c----w c:\windows\$NtServicePackUninstall$\datime.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\davclnt.dll
+ 2004-08-10 19:00:00 640,000 -c----w c:\windows\$NtServicePackUninstall$\dbghelp.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\dbmsrpcn.dll
+ 2004-08-10 19:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\dbnetlib.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dbnmpntw.dll
+ 2004-08-10 19:00:00 1,788 -c----w c:\windows\$NtServicePackUninstall$\dcache.bin
+ 2004-08-10 19:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\dcap32.dll
+ 2004-08-10 19:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\dciman32.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dcomcnfg.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\ddeshare.exe
+ 2004-08-10 19:00:00 266,240 -c----w c:\windows\$NtServicePackUninstall$\ddraw.dll
+ 2004-08-10 19:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\ddrawex.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\defrag.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\devenum.dll
+ 2004-08-10 19:00:00 282,624 -c----w c:\windows\$NtServicePackUninstall$\devmgr.dll
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dfrgfat.exe
+ 2004-08-10 19:00:00 104,960 -c----w c:\windows\$NtServicePackUninstall$\dfrgntfs.exe
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\dfrgsnap.dll
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\dfrgui.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dfsshlex.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\dgnet.dll
+ 2006-05-19 12:59:41 111,616 -c----w c:\windows\$NtServicePackUninstall$\dhcpcsvc.dll
+ 2004-08-10 19:00:00 370,176 -c----w c:\windows\$NtServicePackUninstall$\dhcpmon.dll
+ 2004-08-10 19:00:00 539,136 -c----w c:\windows\$NtServicePackUninstall$\dialer.exe
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\diantz.exe
+ 2004-08-10 19:00:00 68,608 -c----w c:\windows\$NtServicePackUninstall$\digest.dll
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\dinput.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dinput8.dll
+ 2007-05-16 15:12:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\directdb.dll
+ 2004-08-10 19:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\disk.sys
+ 2004-08-10 19:00:00 1,501,696 -c----w c:\windows\$NtServicePackUninstall$\diskcopy.dll
+ 2004-08-10 19:00:00 14,208 -c----w c:\windows\$NtServicePackUninstall$\diskdump.sys
+ 2004-08-10 19:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\diskpart.exe
+ 2004-08-10 19:00:00 45,083 -c----w c:\windows\$NtServicePackUninstall$\dispex.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dllhost.exe
+ 2004-08-10 19:00:00 224,768 -c----w c:\windows\$NtServicePackUninstall$\dmadmin.exe
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dmband.dll
+ 2004-08-10 19:00:00 799,744 -c----w c:\windows\$NtServicePackUninstall$\dmboot.sys
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\dmcompos.dll
+ 2004-08-10 19:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\dmdlgs.dll
+ 2004-08-10 19:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\dmdskmgr.dll
+ 2004-08-10 19:00:00 181,248 -c----w c:\windows\$NtServicePackUninstall$\dmime.dll
+ 2004-08-10 19:00:00 153,344 -c----w c:\windows\$NtServicePackUninstall$\dmio.sys
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\dmloader.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\dmremote.exe
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dmscript.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dmserver.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\dmstyle.dll
+ 2004-08-10 19:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\dmsynth.dll
+ 2004-08-10 19:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\dmusic.dll
+ 2004-08-04 03:07:40 52,864 -c----w c:\windows\$NtServicePackUninstall$\dmusic.sys
+ 2004-08-04 00:56:44 52,224 -c----w c:\windows\$NtServicePackUninstall$\dmutil.dll
+ 2008-06-20 17:41:10 148,992 -c----w c:\windows\$NtServicePackUninstall$\dnsapi.dll
+ 2008-02-20 05:32:43 45,568 -c----w c:\windows\$NtServicePackUninstall$\dnsrslvr.dll
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\docprop2.dll
+ 2004-08-10 19:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\dpcdll.dll
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\dplaysvr.exe
+ 2004-08-10 19:00:00 229,888 -c----w c:\windows\$NtServicePackUninstall$\dplayx.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dpmodemx.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnaddr.dll
+ 2004-08-10 19:00:00 375,296 -c----w c:\windows\$NtServicePackUninstall$\dpnet.dll
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\dpnhpast.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\dpnhupnp.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnlobby.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\dpnsvr.exe
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\dpvacm.dll
+ 2004-08-10 19:00:00 212,480 -c----w c:\windows\$NtServicePackUninstall$\dpvoice.dll
+ 2004-08-10 19:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\dpvsetup.exe
+ 2004-08-10 19:00:00 116,736 -c----w c:\windows\$NtServicePackUninstall$\dpvvox.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\dpwsockx.dll
+ 2004-08-10 19:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\driverquery.exe
+ 2004-08-04 03:08:00 60,288 -c----w c:\windows\$NtServicePackUninstall$\drmk.sys
+ 2004-08-04 03:07:58 2,944 -c----w c:\windows\$NtServicePackUninstall$\drmkaud.sys
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\drprov.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\ds32gt.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dsdmo.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\dsdmoprp.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\dskquota.dll
+ 2004-08-10 19:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\dskquoui.dll
+ 2004-08-10 19:00:00 367,616 -c----w c:\windows\$NtServicePackUninstall$\dsound.dll
+ 2004-08-10 19:00:00 1,294,336 -c----w c:\windows\$NtServicePackUninstall$\dsound3d.dll
+ 2004-08-10 19:00:00 142,336 -c----w c:\windows\$NtServicePackUninstall$\dsprop.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\dsprpres.dll
+ 2004-08-10 19:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\dsquery.dll
+ 2004-08-10 19:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\dssec.dll
+ 2004-08-10 19:00:00 137,216 -c----w c:\windows\$NtServicePackUninstall$\dssenh.dll
+ 2004-08-10 19:00:00 113,152 -c----w c:\windows\$NtServicePackUninstall$\dsuiext.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\dswave.dll
+ 2004-08-10 19:00:00 10,752 -c----w c:\windows\$NtServicePackUninstall$\dumprep.exe
+ 2004-08-10 19:00:00 304,128 -c----w c:\windows\$NtServicePackUninstall$\duser.dll
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\dvdupgrd.exe
+ 2004-08-10 19:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\dwwin.exe
+ 2004-08-10 19:00:00 619,008 -c----w c:\windows\$NtServicePackUninstall$\dx7vb.dll
+ 2004-08-10 19:00:00 1,227,264 -c----w c:\windows\$NtServicePackUninstall$\dx8vb.dll
+ 2004-08-10 19:00:00 1,298,432 -c----w c:\windows\$NtServicePackUninstall$\dxdiag.exe
+ 2004-08-10 19:00:00 2,113,536 -c----w c:\windows\$NtServicePackUninstall$\dxdiagn.dll
+ 2004-08-10 19:00:00 71,040 -c----w c:\windows\$NtServicePackUninstall$\dxg.sys
+ 2006-08-22 09:05:26 498,742 -c----w c:\windows\$NtServicePackUninstall$\dxmasf.dll
+ 2004-08-10 19:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\efsadu.dll
+ 2004-08-10 19:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\els.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\encapi.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\ersvc.dll
+ 2005-07-26 04:39:45 243,200 -c----w c:\windows\$NtServicePackUninstall$\es.dll
+ 2005-10-20 22:20:03 1,082,368 -c----w c:\windows\$NtServicePackUninstall$\esent.dll
+ 2004-08-10 19:00:00 247,808 -c----w c:\windows\$NtServicePackUninstall$\esscli.dll
+ 2004-08-10 19:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\eudcedit.exe
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\eventcreate.exe
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\eventlog.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\eventtriggers.exe
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\evntrprv.dll
+ 2007-06-13 10:23:07 1,033,216 -c----w c:\windows\$NtServicePackUninstall$\explorer.exe
+ 2004-08-10 19:00:00 380,957 -c----w c:\windows\$NtServicePackUninstall$\expsrv.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\extrac32.exe
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\exts.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fastfat.sys
+ 2004-08-10 19:00:00 472,064 -c----w c:\windows\$NtServicePackUninstall$\fastprox.dll
+ 2004-08-10 19:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\faultrep.dll
+ 2004-08-10 19:00:00 27,392 -c----w c:\windows\$NtServicePackUninstall$\fdc.sys
+ 2004-08-10 19:00:00 117,760 -c----w c:\windows\$NtServicePackUninstall$\fde.dll
+ 2004-08-10 19:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\fdeploy.dll
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\feclient.dll
+ 2004-08-10 19:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\filemgmt.dll
+ 2004-08-10 19:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\findstr.exe
+ 2004-08-10 19:00:00 34,944 -c----w c:\windows\$NtServicePackUninstall$\fips.sys
+ 2004-08-10 19:00:00 87,552 -c----w c:\windows\$NtServicePackUninstall$\fldrclnr.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\flpydisk.sys
+ 2006-08-21 12:21:06 16,896 -c----w c:\windows\$NtServicePackUninstall$\fltlib.dll
+ 2006-08-21 09:14:58 23,040 -c----w c:\windows\$NtServicePackUninstall$\fltmc.exe
+ 2006-08-21 09:14:58 128,896 -c----w c:\windows\$NtServicePackUninstall$\fltmgr.sys
+ 2004-08-10 19:00:00 382,976 -c----w c:\windows\$NtServicePackUninstall$\fontext.dll
+ 2005-10-17 21:14:45 80,896 -c----w c:\windows\$NtServicePackUninstall$\fontsub.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\fontview.exe
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\forcedos.exe
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\format.com
+ 2004-08-10 19:00:00 32,828 -c----w c:\windows\$NtServicePackUninstall$\fp40ext.dll
+ 2003-03-25 07:52:04 618,605 -c----w c:\windows\$NtServicePackUninstall$\fp4autl.dll
+ 2004-08-10 19:00:00 9,344 -c----w c:\windows\$NtServicePackUninstall$\framebuf.dll
+ 2004-08-10 19:00:00 185,856 -c----w c:\windows\$NtServicePackUninstall$\framedyn.dll
+ 2004-08-10 19:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\fsquirt.exe
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\ftp.exe
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\fwcfg.dll
+ 2004-08-10 19:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\fxsocm.dll
+ 2007-01-15 21:10:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\gacutil.exe
+ 2008-02-20 06:51:05 282,624 -c----w c:\windows\$NtServicePackUninstall$\gdi32.dll
+ 2004-08-10 19:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\getmac.exe
+ 2004-08-10 19:00:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\glu32.dll
+ 2004-08-10 19:00:00 566,784 -c----w c:\windows\$NtServicePackUninstall$\gpedit.dll
+ 2004-08-10 19:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\gpkrsrc.dll
+ 2004-08-10 19:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\gpresult.exe
+ 2004-08-10 19:00:00 198,656 -c----w c:\windows\$NtServicePackUninstall$\gptext.dll
+ 2004-08-10 19:00:00 39,424 -c----w c:\windows\$NtServicePackUninstall$\grpconv.exe
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\guitrn.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\h323cc.dll
+ 2004-08-10 19:00:00 614,912 -c----w c:\windows\$NtServicePackUninstall$\h323msp.dll
+ 2004-08-04 03:59:10 131,968 -c----w c:\windows\$NtServicePackUninstall$\hal.dll
+ 2004-08-04 08:56:44 7,168 -c----w c:\windows\$NtServicePackUninstall$\hccoin.dll
+ 2005-01-07 21:07:18 138,752 -c----w c:\windows\$NtServicePackUninstall$\hdaudbus.sys
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\help.exe
+ 2004-08-10 19:00:00 768,512 -c----w c:\windows\$NtServicePackUninstall$\helpctr.exe
+ 2004-08-10 19:00:00 743,936 -c----w c:\windows\$NtServicePackUninstall$\helpsvc.exe
+ 2005-05-26 23:22:01 10,752 -c----w c:\windows\$NtServicePackUninstall$\hh.exe
+ 2005-05-27 02:04:27 41,472 -c----w c:\windows\$NtServicePackUninstall$\hhsetup.dll
+ 2004-08-04 00:56:44 20,992 -c----w c:\windows\$NtServicePackUninstall$\hid.dll
+ 2004-08-10 19:00:00 36,224 -c----w c:\windows\$NtServicePackUninstall$\hidclass.sys
+ 2005-06-29 06:43:35 19,200 -c----w c:\windows\$NtServicePackUninstall$\hidir.sys
+ 2005-06-29 06:43:35 19,200 -c----w c:\windows\$NtServicePackUninstall$\hidir.sys.000
+ 2004-08-10 19:00:00 24,960 -c----w c:\windows\$NtServicePackUninstall$\hidparse.sys
+ 2001-08-17 22:02:20 9,600 -c----w c:\windows\$NtServicePackUninstall$\hidusb.sys
+ 2006-07-21 08:24:43 72,704 -c----w c:\windows\$NtServicePackUninstall$\hlink.dll
+ 2004-08-10 19:00:00 344,064 -c----w c:\windows\$NtServicePackUninstall$\hnetcfg.dll
+ 2004-08-10 19:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\hnetwiz.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\hotplug.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\hscupd.exe
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys.000
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\httpapi.dll
+ 2004-08-10 19:00:00 41,984 -c----w c:\windows\$NtServicePackUninstall$\htui.dll
+ 2004-11-17 17:41:24 347,136 -c----w c:\windows\$NtServicePackUninstall$\hypertrm.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\i2omgmt.sys
+ 2004-08-10 19:00:00 18,560 -c----w c:\windows\$NtServicePackUninstall$\i2omp.sys
+ 2004-08-10 19:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\i8042prt.sys
+ 2004-08-10 19:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\iasrad.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\icaapi.dll
+ 2004-08-10 19:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\iccvid.dll
+ 2005-06-29 01:46:00 254,976 -c----w c:\windows\$NtServicePackUninstall$\icm32.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\icmp.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\iconlib.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\icwconn.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\icwconn1.exe
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\icwconn2.exe
+ 2004-08-10 19:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\icwdial.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\icwdl.dll
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\icwhelp.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\icwphbk.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\icwrmind.exe
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\icwutil.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\idq.dll
+ 2007-08-13 23:45:18 78,336 -c----w c:\windows\$NtServicePackUninstall$\ieencode.dll
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\iexpress.exe
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\ifmon.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\igmpagnt.dll
+ 2004-08-10 19:00:00 505,344 -c----w c:\windows\$NtServicePackUninstall$\iis.dll
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\ils.dll
+ 2004-08-10 19:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\imagehlp.dll
+ 2004-08-10 19:00:00 150,016 -c----w c:\windows\$NtServicePackUninstall$\imapi.exe
+ 2004-08-10 19:00:00 41,856 -c----w c:\windows\$NtServicePackUninstall$\imapi.sys
+ 2004-08-10 19:00:00 36,921 -c----w c:\windows\$NtServicePackUninstall$\imeshare.dll
+ 2004-08-10 19:00:00 110,080 -c----w c:\windows\$NtServicePackUninstall$\imm32.dll
+ 2004-08-10 19:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\imsinsnt.dll
+ 2004-08-10 19:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\inetcfg.dll
+ 2007-08-21 06:15:44 683,520 -c----w c:\windows\$NtServicePackUninstall$\inetcomm.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\inetmib1.dll
+ 2004-08-10 19:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\inetpp.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\inetppui.dll
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\inetres.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\inetwiz.exe
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\initpki.dll
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\input.dll
+ 2004-08-10 19:00:00 5,504 -c----w c:\windows\$NtServicePackUninstall$\intelide.sys
+ 2004-08-10 19:00:00 36,096 -c----w c:\windows\$NtServicePackUninstall$\intelppm.sys
+ 2004-08-10 19:00:00 29,056 -c----w c:\windows\$NtServicePackUninstall$\ip6fw.sys
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\ipconfig.exe
+ 2006-05-19 12:59:41 94,720 -c----w c:\windows\$NtServicePackUninstall$\iphlpapi.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipinip.sys
+ 2004-08-10 19:00:00 154,112 -c----w c:\windows\$NtServicePackUninstall$\ipmontr.dll
+ 2004-09-29 22:28:37 134,912 -c----w c:\windows\$NtServicePackUninstall$\ipnat.sys
+ 2004-08-10 19:00:00 331,264 -c----w c:\windows\$NtServicePackUninstall$\ipnathlp.dll
+ 2004-08-10 19:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\ippromon.dll
+ 2004-08-10 19:00:00 169,984 -c----w c:\windows\$NtServicePackUninstall$\iprtrmgr.dll
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\ipsec.sys
+ 2004-08-10 19:00:00 349,696 -c----w c:\windows\$NtServicePackUninstall$\ipsecsnp.dll
+ 2004-08-10 19:00:00 182,784 -c----w c:\windows\$NtServicePackUninstall$\ipsecsvc.dll
+ 2004-08-10 19:00:00 384,000 -c----w c:\windows\$NtServicePackUninstall$\ipsmsnap.dll
+ 2004-08-10 19:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\ipv6.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\ipv6mon.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\ipxroute.exe
 
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipxwan.dll
+ 2004-08-10 19:00:00 120,320 -c----w c:\windows\$NtServicePackUninstall$\ir41_qc.dll
+ 2004-08-10 19:00:00 338,432 -c----w c:\windows\$NtServicePackUninstall$\ir41_qcx.dll
+ 2004-08-10 19:00:00 755,200 -c----w c:\windows\$NtServicePackUninstall$\ir50_32.dll
+ 2004-08-10 19:00:00 200,192 -c----w c:\windows\$NtServicePackUninstall$\ir50_qc.dll
+ 2004-08-10 19:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\ir50_qcx.dll
+ 2005-06-29 06:43:39 46,592 -c----w c:\windows\$NtServicePackUninstall$\irbus.sys
+ 2005-06-29 06:43:39 46,592 -c----w c:\windows\$NtServicePackUninstall$\irbus.sys.000
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\irenum.sys
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\isapnp.sys
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\isign32.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\isrdbg32.dll
+ 2005-05-27 02:04:27 155,136 -c----w c:\windows\$NtServicePackUninstall$\itircl.dll
+ 2005-05-27 02:04:27 137,216 -c----w c:\windows\$NtServicePackUninstall$\itss.dll
+ 2004-08-10 19:00:00 192,000 -c----w c:\windows\$NtServicePackUninstall$\iuengine.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\ixsso.dll
+ 2004-08-04 00:56:44 47,616 -c----w c:\windows\$NtServicePackUninstall$\iyuv_32.dll
+ 2006-06-01 18:47:07 163,840 -c----w c:\windows\$NtServicePackUninstall$\jgdw400.dll
+ 2006-06-01 18:47:07 27,648 -c----w c:\windows\$NtServicePackUninstall$\jgpl400.dll
+ 2007-08-13 23:38:04 491,520 -c----w c:\windows\$NtServicePackUninstall$\jscript.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\kbdclass.sys
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdfi1.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdinbe1.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinben.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinmal.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\kbdmaori.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt47.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt48.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdnec.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdno1.dll
+ 2004-08-10 19:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsfi.dll
+ 2004-08-10 19:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsno.dll
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdukx.dll
+ 2004-08-10 19:00:00 7,424 -c----w c:\windows\$NtServicePackUninstall$\kd1394.dll
+ 2005-06-15 17:49:30 295,936 -c----w c:\windows\$NtServicePackUninstall$\kerberos.dll
+ 2007-04-16 15:52:53 984,576 -c----w c:\windows\$NtServicePackUninstall$\kernel32.dll
+ 2004-08-10 19:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\keymgr.dll
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys.000
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\krnlprov.dll
+ 2004-08-04 03:15:22 140,928 -c----w c:\windows\$NtServicePackUninstall$\ks.sys
+ 2004-08-10 19:00:00 92,032 -c----w c:\windows\$NtServicePackUninstall$\ksecdd.sys
+ 2004-08-04 04:56:44 4,096 -c----w c:\windows\$NtServicePackUninstall$\ksuser.dll
+ 2004-08-10 19:00:00 423,936 -c----w c:\windows\$NtServicePackUninstall$\licdll.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\licwmi.dll
+ 2005-09-01 01:41:53 19,968 -c----w c:\windows\$NtServicePackUninstall$\linkinfo.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\lmhsvc.dll
+ 2004-08-10 19:00:00 399,872 -c----w c:\windows\$NtServicePackUninstall$\lmrt.dll
+ 2004-08-10 19:00:00 97,280 -c----w c:\windows\$NtServicePackUninstall$\loadperf.dll
+ 2004-08-10 19:00:00 221,696 -c----w c:\windows\$NtServicePackUninstall$\localsec.dll
+ 2004-08-10 19:00:00 341,504 -c----w c:\windows\$NtServicePackUninstall$\localspl.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\localui.dll
+ 2004-08-10 19:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\locator.exe
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\log.dll
+ 2004-08-10 19:00:00 59,392 -c----w c:\windows\$NtServicePackUninstall$\logman.exe
+ 2004-08-10 19:00:00 220,672 -c----w c:\windows\$NtServicePackUninstall$\logon.scr
+ 2004-08-10 19:00:00 514,560 -c----w c:\windows\$NtServicePackUninstall$\logonui.exe
+ 2004-08-10 19:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\lpk.dll
+ 2004-08-10 19:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\lprhelp.dll
+ 2007-11-07 09:26:56 721,920 -c----w c:\windows\$NtServicePackUninstall$\lsasrv.dll
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\lsass.exe
+ 2004-08-10 19:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\magnify.exe
+ 2004-08-10 19:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\makecab.exe
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mcastmib.dll
+ 2004-08-10 19:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\mciavi32.dll
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\mciqtz32.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\mciseq.dll
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\mciwave.dll
+ 2004-08-10 19:00:00 118,272 -c----w c:\windows\$NtServicePackUninstall$\mdminst.dll
+ 2004-08-03 23:07:46 63,744 -c----w c:\windows\$NtServicePackUninstall$\mf.sys
+ 2007-03-08 15:36:28 40,960 -c----w c:\windows\$NtServicePackUninstall$\mf3216.dll
+ 2006-11-01 19:17:45 927,504 -c----w c:\windows\$NtServicePackUninstall$\mfc40u.dll
+ 2004-08-10 19:00:00 1,028,096 -c----w c:\windows\$NtServicePackUninstall$\mfc42.dll
+ 2004-08-10 19:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\mfcsubs.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mgmtapi.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\midimap.dll
+ 2004-08-10 19:00:00 201,216 -c----w c:\windows\$NtServicePackUninstall$\migism.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\miglibnt.dll
+ 2004-08-10 19:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\migload.exe
+ 2004-08-10 19:00:00 240,128 -c----w c:\windows\$NtServicePackUninstall$\migwiz.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\mimefilt.dll
+ 2004-08-10 19:00:00 586,240 -c----w c:\windows\$NtServicePackUninstall$\mlang.dll
+ 2004-08-10 19:00:00 815,104 -c----w c:\windows\$NtServicePackUninstall$\mmc.exe
+ 2004-08-10 19:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\mmcbase.dll
+ 2004-08-10 19:00:00 1,192,960 -c----w c:\windows\$NtServicePackUninstall$\mmcndmgr.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\mmcshext.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\mmfutil.dll
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\mnmdd.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\mnmsrvc.exe
+ 2004-08-10 19:00:00 207,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.exe
+ 2004-08-03 23:08:06 30,080 -c----w c:\windows\$NtServicePackUninstall$\modem.sys
+ 2004-08-10 19:00:00 153,600 -c----w c:\windows\$NtServicePackUninstall$\modemui.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\mofcomp.exe
+ 2004-08-10 19:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\mofd.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\more.com
+ 2004-08-10 19:00:00 216,064 -c----w c:\windows\$NtServicePackUninstall$\moricons.dll
+ 2004-08-03 22:58:34 23,040 -c----w c:\windows\$NtServicePackUninstall$\mouclass.sys
+ 2004-08-10 19:00:00 42,240 -c----w c:\windows\$NtServicePackUninstall$\mountmgr.sys
+ 2004-08-10 19:00:00 3,555,328 -c----w c:\windows\$NtServicePackUninstall$\moviemk.exe
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\mplay32.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\mpr.dll
+ 2004-08-10 19:00:00 87,040 -c----w c:\windows\$NtServicePackUninstall$\mprapi.dll
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\mprdim.dll
+ 2007-07-06 10:05:47 72,960 -c----w c:\windows\$NtServicePackUninstall$\mqac.sys
+ 2007-07-06 12:46:59 138,240 -c----w c:\windows\$NtServicePackUninstall$\mqad.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\mqbkup.exe
+ 2007-07-06 12:46:59 47,104 -c----w c:\windows\$NtServicePackUninstall$\mqdscli.dll
+ 2007-07-06 12:46:59 16,896 -c----w c:\windows\$NtServicePackUninstall$\mqise.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\mqlogmgr.dll
+ 2004-08-10 19:00:00 225,280 -c----w c:\windows\$NtServicePackUninstall$\mqoa.dll
+ 2007-07-06 12:46:59 660,992 -c----w c:\windows\$NtServicePackUninstall$\mqqm.dll
+ 2007-07-06 12:46:59 177,152 -c----w c:\windows\$NtServicePackUninstall$\mqrt.dll
+ 2004-08-10 19:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\mqrtdep.dll
+ 2007-07-06 12:46:59 95,744 -c----w c:\windows\$NtServicePackUninstall$\mqsec.dll
+ 2004-08-10 19:00:00 517,632 -c----w c:\windows\$NtServicePackUninstall$\mqsnap.dll
+ 2004-08-10 19:00:00 4,608 -c----w c:\windows\$NtServicePackUninstall$\mqsvc.exe
+ 2004-08-10 19:00:00 117,248 -c----w c:\windows\$NtServicePackUninstall$\mqtgsvc.exe
+ 2004-08-10 19:00:00 186,880 -c----w c:\windows\$NtServicePackUninstall$\mqtrig.dll
+ 2007-07-06 12:46:59 48,640 -c----w c:\windows\$NtServicePackUninstall$\mqupgrd.dll
+ 2007-07-06 12:46:59 471,552 -c----w c:\windows\$NtServicePackUninstall$\mqutil.dll
+ 2007-12-18 09:51:35 179,584 -c----w c:\windows\$NtServicePackUninstall$\mrxdav.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys.000
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\msacm32.dll
+ 2004-08-10 19:00:00 331,776 -c----w c:\windows\$NtServicePackUninstall$\msadce.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msadcer.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msadcf.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcfr.dll
+ 2006-03-23 05:44:21 143,360 -c----w c:\windows\$NtServicePackUninstall$\msadco.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcor.dll
+ 2004-08-10 19:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\msadcs.dll
+ 2004-08-10 19:00:00 155,648 -c----w c:\windows\$NtServicePackUninstall$\msadds.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msaddsr.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msader15.dll
+ 2006-12-26 13:07:23 536,576 -c----w c:\windows\$NtServicePackUninstall$\msado15.dll
+ 2006-12-26 13:07:23 180,224 -c----w c:\windows\$NtServicePackUninstall$\msadomd.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msador15.dll
+ 2006-12-26 13:07:23 200,704 -c----w c:\windows\$NtServicePackUninstall$\msadox.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msadrh15.dll
+ 2004-08-10 19:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\msafd.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\msapsspc.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msasn1.dll
+ 2004-08-10 19:00:00 220,160 -c----w c:\windows\$NtServicePackUninstall$\mscandui.dll
+ 2005-06-29 01:46:00 74,240 -c----w c:\windows\$NtServicePackUninstall$\mscms.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\msconf.dll
+ 2004-08-10 19:00:00 158,208 -c----w c:\windows\$NtServicePackUninstall$\msconfig.exe
+ 2007-01-02 21:28:28 2,273,280 -c----w c:\windows\$NtServicePackUninstall$\mscorsvr.dll
+ 2007-01-02 21:28:46 2,281,472 -c----w c:\windows\$NtServicePackUninstall$\mscorwks.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mscpx32r.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\mscpxl32.dll
+ 2008-02-26 11:59:50 294,912 -c----w c:\windows\$NtServicePackUninstall$\msctf.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\msctfp.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdadc.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdadiag.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaenum.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaer.dll
+ 2002-05-25 03:22:16 532,480 -c----w c:\windows\$NtServicePackUninstall$\msdaipp.dll
+ 2004-08-10 19:00:00 233,472 -c----w c:\windows\$NtServicePackUninstall$\msdaora.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaorar.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\msdaosp.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaprsr.dll
+ 2004-08-10 19:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\msdaprst.dll
+ 2004-08-10 19:00:00 204,800 -c----w c:\windows\$NtServicePackUninstall$\msdaps.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdarem.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaremr.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\msdart.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdasc.dll
+ 2004-08-10 19:00:00 315,392 -c----w c:\windows\$NtServicePackUninstall$\msdasql.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdasqlr.dll
+ 2004-08-10 19:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\msdatl3.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msdatt.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaurl.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\msdfmap.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\msdmo.dll
+ 2004-08-10 19:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\msdtc.exe
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\msdtclog.dll
+ 2006-03-01 19:42:42 426,496 -c----w c:\windows\$NtServicePackUninstall$\msdtcprx.dll
+ 2004-08-10 19:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\msdtcstp.dll
+ 2006-03-01 19:42:42 956,416 -c----w c:\windows\$NtServicePackUninstall$\msdtctm.dll
+ 2006-03-01 19:42:42 161,280 -c----w c:\windows\$NtServicePackUninstall$\msdtcuiu.dll
+ 2004-08-10 19:00:00 4,126 -c----w c:\windows\$NtServicePackUninstall$\msdxmlc.dll
+ 2004-08-10 19:00:00 19,072 -c----w c:\windows\$NtServicePackUninstall$\msfs.sys
+ 2006-11-27 14:54:06 539,136 -c----w c:\windows\$NtServicePackUninstall$\msftedit.dll
+ 2004-08-10 19:00:00 994,304 -c----w c:\windows\$NtServicePackUninstall$\msgina.dll
+ 2004-08-10 19:00:00 35,072 -c----w c:\windows\$NtServicePackUninstall$\msgpc.sys
+ 2004-08-10 19:00:00 3,166,208 -c----w c:\windows\$NtServicePackUninstall$\msgr3en.dll
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\msgrocm.dll
+ 2004-08-04 16:06:34 82,944 -c----w c:\windows\$NtServicePackUninstall$\msgsc.dll
+ 2004-08-04 16:06:34 180,224 -c----w c:\windows\$NtServicePackUninstall$\msgslang.dll
+ 2004-08-10 19:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\msgsvc.dll
+ 2004-08-10 19:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\msh261.drv
+ 2004-08-04 00:56:58 294,912 -c----w c:\windows\$NtServicePackUninstall$\msh263.drv
+ 2007-04-18 16:12:23 2,854,400 -c----w c:\windows\$NtServicePackUninstall$\msi.dll
+ 2004-08-10 19:00:00 51,712 -c----w c:\windows\$NtServicePackUninstall$\msident.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\msidle.dll
+ 2004-08-10 19:00:00 248,832 -c----w c:\windows\$NtServicePackUninstall$\msieftp.dll
+ 2005-05-04 19:45:36 78,848 -c----w c:\windows\$NtServicePackUninstall$\msiexec.exe
+ 2005-05-04 19:45:36 271,360 -c----w c:\windows\$NtServicePackUninstall$\msihnd.dll
+ 2004-08-10 19:00:00 4,608 -c----w c:\windows\$NtServicePackUninstall$\msimg32.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\msimn.exe
+ 2005-05-04 19:45:36 884,736 -c----w c:\windows\$NtServicePackUninstall$\msimsg.dll
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\msimtf.dll
+ 2004-08-10 19:00:00 376,320 -c----w c:\windows\$NtServicePackUninstall$\msinfo.dll
+ 2005-05-04 19:45:36 15,360 -c----w c:\windows\$NtServicePackUninstall$\msisip.dll
+ 2008-03-27 08:12:54 151,583 -c----w c:\windows\$NtServicePackUninstall$\msjint40.dll
+ 2006-12-26 13:07:23 102,400 -c----w c:\windows\$NtServicePackUninstall$\msjro.dll
+ 2004-08-04 02:58:42 7,552 -c----w c:\windows\$NtServicePackUninstall$\mskssrv.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mslbui.dll
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\mslwvtts.dll
+ 2004-08-10 19:00:00 169,984 -c----w c:\windows\$NtServicePackUninstall$\msmqocm.dll
+ 2004-10-13 23:24:37 1,694,208 -c----w c:\windows\$NtServicePackUninstall$\msmsgs.exe
+ 2004-08-10 19:00:00 290,816 -c----w c:\windows\$NtServicePackUninstall$\msnsspc.dll
+ 2004-08-10 19:00:00 122,368 -c----w c:\windows\$NtServicePackUninstall$\msobcomm.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msobdl.dll
+ 2004-08-10 19:00:00 561,664 -c----w c:\windows\$NtServicePackUninstall$\msobmain.dll
+ 2004-08-10 19:00:00 30,720 -c----w c:\windows\$NtServicePackUninstall$\msobshel.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\msobweb.dll
+ 2007-05-16 15:12:08 1,314,816 -c----w c:\windows\$NtServicePackUninstall$\msoe.dll
+ 2004-08-10 19:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\msoeacct.dll
+ 2004-08-10 19:00:00 2,479,616 -c----w c:\windows\$NtServicePackUninstall$\msoeres.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\msoert2.dll
+ 2004-08-10 19:00:00 28,160 -c----w c:\windows\$NtServicePackUninstall$\msoobe.exe
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msorc32r.dll
+ 2004-08-10 19:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\msorcl32.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\mspaint.exe
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\mspatcha.dll
+ 2004-08-04 02:58:40 5,376 -c----w c:\windows\$NtServicePackUninstall$\mspclock.sys
+ 2004-08-04 02:58:42 4,992 -c----w c:\windows\$NtServicePackUninstall$\mspqm.sys
+ 2004-08-10 19:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\msprivs.dll
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\msrle32.dll
+ 2004-08-10 19:00:00 134,656 -c----w c:\windows\$NtServicePackUninstall$\mssap.dll
+ 2004-08-03 23:07:48 15,488 -c----w c:\windows\$NtServicePackUninstall$\mssmbios.sys
+ 2004-08-10 19:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\mst120.dll
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\mst123.dll
+ 2004-08-10 19:00:00 274,944 -c----w c:\windows\$NtServicePackUninstall$\mstask.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mstinit.exe
+ 2004-08-10 19:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\mstlsapi.dll
+ 2004-08-10 19:00:00 407,552 -c----w c:\windows\$NtServicePackUninstall$\mstsc.exe
+ 2004-08-10 19:00:00 655,360 -c----w c:\windows\$NtServicePackUninstall$\mstscax.dll
+ 2004-08-10 19:00:00 195,072 -c----w c:\windows\$NtServicePackUninstall$\msutb.dll
+ 2004-08-10 19:00:00 129,536 -c----w c:\windows\$NtServicePackUninstall$\msv1_0.dll
+ 2004-08-10 19:00:00 1,392,671 -c----w c:\windows\$NtServicePackUninstall$\msvbvm60.dll
+ 2004-08-10 19:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\msvcirt.dll
+ 2004-08-10 19:00:00 413,696 -c----w c:\windows\$NtServicePackUninstall$\msvcp60.dll
+ 2004-08-10 19:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\msvcrt.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msvcrt40.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\msvfw32.dll
+ 2004-08-10 19:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\msw3prt.dll
+ 2004-08-10 19:00:00 204,288 -c----w c:\windows\$NtServicePackUninstall$\mswebdvd.dll
+ 2008-06-20 17:41:10 245,248 -c----w c:\windows\$NtServicePackUninstall$\mswsock.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msxactps.dll
+ 2004-08-10 19:00:00 506,368 -c----w c:\windows\$NtServicePackUninstall$\msxml.dll
+ 2004-08-10 19:00:00 701,440 -c----w c:\windows\$NtServicePackUninstall$\msxml2.dll
+ 2007-06-26 06:08:16 1,104,896 -c----w c:\windows\$NtServicePackUninstall$\msxml3.dll
+ 2004-08-04 00:56:46 17,408 -c----w c:\windows\$NtServicePackUninstall$\msyuv.dll
+ 2006-03-01 19:42:42 66,560 -c----w c:\windows\$NtServicePackUninstall$\mtxclu.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\mtxdm.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\mtxex.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mtxlegih.dll
+ 2006-03-01 19:42:42 91,136 -c----w c:\windows\$NtServicePackUninstall$\mtxoci.dll
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\muisetup.exe
+ 2004-08-10 19:00:00 107,904 -c----w c:\windows\$NtServicePackUninstall$\mup.sys
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\mydocs.dll
+ 2004-08-10 19:00:00 221,184 -c----w c:\windows\$NtServicePackUninstall$\nac.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\narrator.exe
+ 2004-08-10 19:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\ncobjapi.dll
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ncprov.dll
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\nddeapi.dll
+ 2004-08-10 19:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\nddeapir.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\nddenb32.dll
+ 2004-08-10 19:00:00 182,912 -c----w c:\windows\$NtServicePackUninstall$\ndis.sys
+ 2004-08-10 19:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\ndisnpp.dll
+ 2004-08-10 19:00:00 9,600 -c----w c:\windows\$NtServicePackUninstall$\ndistapi.sys
+ 2005-06-21 08:52:55 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys
+ 2005-06-21 08:52:55 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys.000
+ 2004-08-10 19:00:00 91,776 -c----w c:\windows\$NtServicePackUninstall$\ndiswan.sys
+ 2004-08-10 19:00:00 38,016 -c----w c:\windows\$NtServicePackUninstall$\ndproxy.sys
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\net.exe
+ 2004-08-10 19:00:00 124,928 -c----w c:\windows\$NtServicePackUninstall$\net1.exe
+ 2006-08-17 12:28:27 332,288 -c----w c:\windows\$NtServicePackUninstall$\netapi32.dll
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\netbios.sys
+ 2004-08-10 19:00:00 162,816 -c----w c:\windows\$NtServicePackUninstall$\netbt.sys
+ 2004-08-10 19:00:00 622,080 -c----w c:\windows\$NtServicePackUninstall$\netcfgx.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\netdde.exe
+ 2007-01-15 21:11:26 73,728 -c----w c:\windows\$NtServicePackUninstall$\netfxupdate.exe
+ 2004-08-10 19:00:00 139,264 -c----w c:\windows\$NtServicePackUninstall$\netid.dll
+ 2004-08-10 19:00:00 407,040 -c----w c:\windows\$NtServicePackUninstall$\netlogon.dll
+ 2005-08-22 18:29:46 197,632 -c----w c:\windows\$NtServicePackUninstall$\netman.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\netoc.dll
+ 2004-08-10 19:00:00 875,008 -c----w c:\windows\$NtServicePackUninstall$\netplwiz.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\netrap.dll
+ 2004-08-10 19:00:00 329,728 -c----w c:\windows\$NtServicePackUninstall$\netsetup.exe
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\netsh.exe
+ 2005-06-22 05:00:18 1,705,472 -c----w c:\windows\$NtServicePackUninstall$\netshell.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\netstat.exe
+ 2004-08-10 19:00:00 80,896 -c----w c:\windows\$NtServicePackUninstall$\netui0.dll
+ 2004-08-10 19:00:00 245,760 -c----w c:\windows\$NtServicePackUninstall$\netui1.dll
+ 2004-08-10 19:00:00 248,832 -c----w c:\windows\$NtServicePackUninstall$\newdev.dll
+ 2004-08-03 22:58:30 61,824 -c----w c:\windows\$NtServicePackUninstall$\nic1394.sys
+ 2004-08-10 19:00:00 103,936 -c----w c:\windows\$NtServicePackUninstall$\nlhtml.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\nmas.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmasnt.dll
+ 2004-08-10 19:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\nmchat.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\nmcom.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\nmft.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmmkcert.dll
+ 2004-08-10 19:00:00 40,320 -c----w c:\windows\$NtServicePackUninstall$\nmnt.sys
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\nmoldwb.dll
+ 2004-08-10 19:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\nmwb.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\notepad.exe
+ 2004-08-10 19:00:00 30,848 -c----w c:\windows\$NtServicePackUninstall$\npfs.sys
+ 2004-08-10 19:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\nppagent.exe
+ 2004-08-10 19:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\npptools.dll
+ 2004-08-10 19:00:00 76,800 -c----w c:\windows\$NtServicePackUninstall$\nslookup.exe
+ 2004-08-10 19:00:00 1,200,128 -c----w c:\windows\$NtServicePackUninstall$\ntbackup.exe
+ 2004-08-10 19:00:00 708,096 -c----w c:\windows\$NtServicePackUninstall$\ntdll.dll
+ 2004-08-10 19:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\ntdsapi.dll
+ 2004-08-10 19:00:00 212,992 -c----w c:\windows\$NtServicePackUninstall$\ntevt.dll
+ 2007-02-09 11:10:35 574,464 -c----w c:\windows\$NtServicePackUninstall$\ntfs.sys
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe.000
+ 2007-02-28 08:38:55 2,057,600 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
+ 2007-02-28 08:38:55 2,057,600 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe.000
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe.000
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\ntlanman.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\ntlsapi.dll
+ 2004-08-10 19:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\ntmarta.dll
+ 2004-08-10 19:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\ntmsapi.dll
+ 2004-08-10 19:00:00 179,712 -c----w c:\windows\$NtServicePackUninstall$\ntmsdba.dll
+ 2004-08-10 19:00:00 488,448 -c----w c:\windows\$NtServicePackUninstall$\ntmsmgr.dll
+ 2004-08-10 19:00:00 435,200 -c----w c:\windows\$NtServicePackUninstall$\ntmssvc.dll
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\ntoc.dll
+ 2007-02-28 09:10:57 2,180,352 -c----w c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
+ 2007-02-28 09:10:57 2,180,352 -c----w c:\windows\$NtServicePackUninstall$\ntoskrnl.exe.000
+ 2004-08-10 19:00:00 91,136 -c----w c:\windows\$NtServicePackUninstall$\ntprint.dll
+ 2004-08-10 19:00:00 143,872 -c----w c:\windows\$NtServicePackUninstall$\ntshrui.dll
+ 2004-08-10 19:00:00 419,840 -c----w c:\windows\$NtServicePackUninstall$\ntvdm.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\ntvdmd.dll
+ 2006-10-13 12:35:12 64,000 -c----w c:\windows\$NtServicePackUninstall$\nwapi32.dll
+ 2004-08-10 19:00:00 88,448 -c----w c:\windows\$NtServicePackUninstall$\nwlnkipx.sys
+ 2006-10-13 12:35:12 142,336 -c----w c:\windows\$NtServicePackUninstall$\nwprovau.dll
+ 2006-10-13 10:23:15 163,584 -c----w c:\windows\$NtServicePackUninstall$\nwrdr.sys
+ 2006-10-13 12:35:12 65,536 -c----w c:\windows\$NtServicePackUninstall$\nwwks.dll
+ 2004-08-10 19:00:00 266,752 -c----w c:\windows\$NtServicePackUninstall$\oakley.dll
+ 2004-08-10 19:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\obelog.dll
+ 2004-08-10 19:00:00 966,656 -c----w c:\windows\$NtServicePackUninstall$\obemetal.dll
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\obemtllc.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\obepopc.dll
+ 2004-08-10 19:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\objsel.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\ocgen.dll
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\ocmanage.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\ocmsn.dll
+ 2004-08-10 19:00:00 249,856 -c----w c:\windows\$NtServicePackUninstall$\odbc32.dll
+ 2004-08-10 19:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\odbc32gt.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\odbcad32.exe
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\odbcbcp.dll
+ 2004-08-10 19:00:00 135,168 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.exe
+ 2004-08-10 19:00:00 106,496 -c----w c:\windows\$NtServicePackUninstall$\odbccp32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccr32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccu32.dll
+ 2004-08-10 19:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\odbcint.dll
+ 2004-08-10 19:00:00 53,279 -c----w c:\windows\$NtServicePackUninstall$\odbcji32.dll
+ 2004-08-10 19:00:00 278,559 -c----w c:\windows\$NtServicePackUninstall$\odbcjt32.dll
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\odbcp32r.dll
+ 2004-08-10 19:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\odbctrac.dll
+ 2004-08-10 19:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\oddbse32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odexl32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odfox32.dll
+ 2004-08-10 19:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odpdx32.dll
+ 2004-08-10 19:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\odtext32.dll
+ 2004-08-10 19:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\oeimport.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\oemig50.exe
+ 2004-08-10 19:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\oemiglib.dll
+ 2004-08-10 19:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\offfilt.dll
+ 2004-08-04 07:10:10 61,056 -c----w c:\windows\$NtServicePackUninstall$\ohci1394.sys
+ 2005-07-26 04:39:48 1,285,120 -c----w c:\windows\$NtServicePackUninstall$\ole32.dll
+ 2007-12-04 18:38:13 550,912 -c----w c:\windows\$NtServicePackUninstall$\oleaut32.dll
+ 2005-07-26 04:39:48 74,752 -c----w c:\windows\$NtServicePackUninstall$\olecli32.dll
+ 2005-07-26 04:39:49 37,888 -c----w c:\windows\$NtServicePackUninstall$\olecnv32.dll
+ 2004-08-10 19:00:00 487,424 -c----w c:\windows\$NtServicePackUninstall$\oledb32.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\oledb32r.dll
+ 2006-10-16 16:15:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\oledlg.dll
+ 2004-08-10 19:00:00 107,008 -c----w c:\windows\$NtServicePackUninstall$\oleprn.dll
+ 2004-08-10 19:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\olepro32.dll
+ 2004-08-10 19:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\oobebaln.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\openfiles.exe
+ 2004-08-10 19:00:00 713,728 -c----w c:\windows\$NtServicePackUninstall$\opengl32.dll
+ 2004-08-10 19:00:00 215,552 -c----w c:\windows\$NtServicePackUninstall$\osk.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\osuninst.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\p2p.dll
+ 2004-08-10 19:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\p2pgasvc.dll
+ 2004-08-10 19:00:00 312,320 -c----w c:\windows\$NtServicePackUninstall$\p2pgraph.dll
+ 2004-08-10 19:00:00 88,064 -c----w c:\windows\$NtServicePackUninstall$\p2pnetsh.dll
+ 2004-08-10 19:00:00 526,848 -c----w c:\windows\$NtServicePackUninstall$\p2psvc.dll
+ 2004-08-03 22:59:20 42,496 -c----w c:\windows\$NtServicePackUninstall$\p3.sys
+ 2004-08-10 19:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\packager.exe
+ 2004-08-03 22:59:08 80,128 -c----w c:\windows\$NtServicePackUninstall$\parport.sys
+ 2004-08-10 19:00:00 18,688 -c----w c:\windows\$NtServicePackUninstall$\partmgr.sys
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\pautoenr.dll
+ 2004-08-10 19:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\pchshell.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\pchsvc.dll
+ 2004-08-10 19:00:00 68,224 -c----w c:\windows\$NtServicePackUninstall$\pci.sys
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\pciidex.sys
+ 2004-08-10 19:00:00 119,936 -c----w c:\windows\$NtServicePackUninstall$\pcmcia.sys
+ 2004-08-10 19:00:00 283,648 -c----w c:\windows\$NtServicePackUninstall$\pdh.dll
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\perfctrs.dll
+ 2004-08-10 19:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\perfdisk.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\perfmon.exe
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\perfnet.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\perfos.dll
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\perfproc.dll
+ 2004-08-10 19:00:00 176,128 -c----w c:\windows\$NtServicePackUninstall$\photowiz.dll
+ 2004-08-04 00:56:46 35,328 -c----w c:\windows\$NtServicePackUninstall$\pid.dll
+ 2004-08-10 19:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\pidgen.dll
+ 2004-08-10 19:00:00 281,088 -c----w c:\windows\$NtServicePackUninstall$\pinball.exe
+ 2004-08-10 19:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\ping.exe
+ 2004-08-04 00:56:46 15,360 -c----w c:\windows\$NtServicePackUninstall$\pjlmon.dll
+ 2004-08-10 19:00:00 48,640 -c----w c:\windows\$NtServicePackUninstall$\pnrpnsp.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\policman.dll
+ 2004-08-10 19:00:00 105,472 -c----w c:\windows\$NtServicePackUninstall$\polstore.dll
+ 2004-03-16 14:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys
+ 2004-03-16 14:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys.000
+ 2004-08-10 19:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\powercfg.exe
+ 2005-06-25 06:47:40 8,832 -c----w c:\windows\$NtServicePackUninstall$\powerfil.sys
+ 2005-06-25 06:47:40 8,832 -c----w c:\windows\$NtServicePackUninstall$\powerfil.sys.000
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\powrprof.dll
+ 2004-08-10 19:00:00 560,640 -c----w c:\windows\$NtServicePackUninstall$\printui.dll
+ 2004-08-03 22:59:18 35,328 -c----w c:\windows\$NtServicePackUninstall$\processr.sys
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\profmap.dll
+ 2004-08-10 19:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\progman.exe
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\proquota.exe
+ 2004-08-10 19:00:00 237,056 -c----w c:\windows\$NtServicePackUninstall$\provthrd.dll
+ 2004-08-10 19:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\proxycfg.exe
+ 2003-05-05 20:47:20 129,024 -c----w c:\windows\$NtServicePackUninstall$\ps5ui.dll
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\psapi.dll
+ 2004-08-10 19:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\psbase.dll
+ 2004-08-10 19:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\psched.sys
+ 2003-05-05 20:47:20 455,168 -c----w c:\windows\$NtServicePackUninstall$\pscript5.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\pstorec.dll
+ 2004-08-10 19:00:00 34,304 -c----w c:\windows\$NtServicePackUninstall$\pstorsvc.dll
+ 2004-08-10 19:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\qcap.dll
+ 2004-08-10 19:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\qdv.dll
+ 2005-06-29 08:55:07 385,024 -c----w c:\windows\$NtServicePackUninstall$\qdvd.dll
+ 2004-08-10 19:00:00 562,176 -c----w c:\windows\$NtServicePackUninstall$\qedit.dll
+ 2004-08-10 19:00:00 733,696 -c----w c:\windows\$NtServicePackUninstall$\qedwipes.dll
+ 2004-08-10 19:00:00 382,464 -c----w c:\windows\$NtServicePackUninstall$\qmgr.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\qmgrprxy.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\qprocess.exe
+ 2008-05-07 04:55:40 1,288,192 -c----w c:\windows\$NtServicePackUninstall$\quartz.dll
+ 2006-06-22 05:06:30 1,435,648 -c----w c:\windows\$NtServicePackUninstall$\query.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\racpldlg.dll
+ 2006-06-26 17:37:10 8,192 -c----w c:\windows\$NtServicePackUninstall$\rasadhlp.dll
+ 2004-08-10 19:00:00 236,544 -c----w c:\windows\$NtServicePackUninstall$\rasapi32.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\rasauto.dll
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\raschap.dll
+ 2004-08-10 19:00:00 657,920 -c----w c:\windows\$NtServicePackUninstall$\rasdlg.dll
+ 2004-08-10 19:00:00 51,328 -c----w c:\windows\$NtServicePackUninstall$\rasl2tp.sys
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rasman.dll
+ 2006-06-22 10:47:18 181,248 -c----w c:\windows\$NtServicePackUninstall$\rasmans.dll
+ 2004-08-10 19:00:00 56,832 -c----w c:\windows\$NtServicePackUninstall$\rasphone.exe
+ 2004-08-10 19:00:00 206,336 -c----w c:\windows\$NtServicePackUninstall$\rasppp.dll
+ 2004-08-10 19:00:00 41,472 -c----w c:\windows\$NtServicePackUninstall$\raspppoe.sys
+ 2004-08-10 19:00:00 48,384 -c----w c:\windows\$NtServicePackUninstall$\raspptp.sys
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\rassapi.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\rastapi.dll
+ 2004-08-10 19:00:00 112,128 -c----w c:\windows\$NtServicePackUninstall$\rastls.dll
+ 2004-08-10 19:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\rcbdyctl.dll
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\rcimlby.exe
+ 2004-08-10 19:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\rcp.exe
+ 2006-05-05 09:47:57 174,592 -c----w c:\windows\$NtServicePackUninstall$\rdbss.sys
+ 2004-08-10 19:00:00 147,968 -c----w c:\windows\$NtServicePackUninstall$\rdchost.dll
+ 2004-08-10 19:00:00 62,464 -c----w c:\windows\$NtServicePackUninstall$\rdpclip.exe
+ 2004-08-10 19:00:00 92,168 -c----w c:\windows\$NtServicePackUninstall$\rdpdd.dll
+ 2004-08-03 23:01:16 196,864 -c----w c:\windows\$NtServicePackUninstall$\rdpdr.sys
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\rdpsnd.dll
+ 2005-06-10 04:09:46 139,528 -c----w c:\windows\$NtServicePackUninstall$\rdpwd.sys
+ 2004-08-10 19:00:00 87,176 -c----w c:\windows\$NtServicePackUninstall$\rdpwsx.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rdsaddin.exe
+ 2004-08-10 19:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\rdshost.exe
+ 2004-08-03 22:59:38 57,472 -c----w c:\windows\$NtServicePackUninstall$\redbook.sys
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\reg.exe
+ 2004-08-10 19:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\regapi.dll
+ 2004-08-10 19:00:00 146,432 -c----w c:\windows\$NtServicePackUninstall$\regedit.exe
+ 2004-08-10 19:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\regsvc.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\regsvr32.exe
+ 2004-08-10 19:00:00 397,824 -c----w c:\windows\$NtServicePackUninstall$\regwizc.dll
+ 2004-08-10 19:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\remotepg.dll
+ 2004-08-10 19:00:00 177,152 -c----w c:\windows\$NtServicePackUninstall$\repdrvfs.dll
+ 2004-08-10 19:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\resutils.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rexec.exe
+ 2006-11-27 14:54:06 433,152 -c----w c:\windows\$NtServicePackUninstall$\riched20.dll
+ 2008-05-08 12:28:49 202,752 -c----w c:\windows\$NtServicePackUninstall$\rmcast.sys
+ 2004-08-10 19:00:00 30,080 -c----w c:\windows\$NtServicePackUninstall$\rndismp.sys
+ 2007-07-09 13:16:16 582,656 -c----w c:\windows\$NtServicePackUninstall$\rpcrt4.dll
+ 2005-07-26 04:39:49 397,824 -c----w c:\windows\$NtServicePackUninstall$\rpcss.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rrcm.dll
+ 2004-08-10 19:00:00 152,576 -c----w c:\windows\$NtServicePackUninstall$\rsaenh.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\rsh.exe
+ 2004-08-10 19:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\rshx32.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\rsmps.dll
+ 2004-08-10 19:00:00 107,520 -c----w c:\windows\$NtServicePackUninstall$\rsnotify.exe
+ 2004-08-10 19:00:00 380,416 -c----w c:\windows\$NtServicePackUninstall$\rstrui.exe
+ 2004-08-10 19:00:00 90,112 -c----w c:\windows\$NtServicePackUninstall$\rsvpsp.dll
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\rtcshare.exe
+ 2004-08-10 19:00:00 31,744 -c----w c:\windows\$NtServicePackUninstall$\rtipxmib.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\rtutils.dll
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\rundll32.exe
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\runonce.exe
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\safrcdlg.dll
+ 2004-08-10 19:00:00 29,696 -c----w c:\windows\$NtServicePackUninstall$\safrdm.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\safrslv.dll
+ 2004-08-10 19:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\samlib.dll
+ 2004-08-10 19:00:00 415,744 -c----w c:\windows\$NtServicePackUninstall$\samsrv.dll
+ 2004-08-10 19:00:00 741,376 -c----w c:\windows\$NtServicePackUninstall$\sapi.dll
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\savedump.exe
+ 2004-08-10 19:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\sbeio.dll
+ 2005-06-01 06:46:29 43,264 -c----w c:\windows\$NtServicePackUninstall$\sbp2port.sys
+ 2005-06-01 06:46:29 43,264 -c----w c:\windows\$NtServicePackUninstall$\sbp2port.sys.000
+ 2004-08-10 19:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\scarddlg.dll
+ 2004-08-10 19:00:00 95,744 -c----w c:\windows\$NtServicePackUninstall$\scardsvr.exe
+ 2004-08-10 19:00:00 171,008 -c----w c:\windows\$NtServicePackUninstall$\sccsccp.dll
+ 2004-08-10 19:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\scecli.dll
+ 2004-08-10 19:00:00 313,856 -c----w c:\windows\$NtServicePackUninstall$\scesrv.dll
+ 2007-04-25 14:21:15 144,896 -c----w c:\windows\$NtServicePackUninstall$\schannel.dll
+ 2004-08-10 19:00:00 190,976 -c----w c:\windows\$NtServicePackUninstall$\schedsvc.dll
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\schtasks.exe
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\sclgntfy.dll
+ 2004-08-10 19:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\scrcons.exe
+ 2004-08-10 19:00:00 202,752 -c----w c:\windows\$NtServicePackUninstall$\script.dll
+ 2004-08-10 19:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\scrnsave.scr
+ 2004-08-10 19:00:00 159,744 -c----w c:\windows\$NtServicePackUninstall$\scrobj.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\scrrun.dll
+ 2004-08-10 19:00:00 96,256 -c----w c:\windows\$NtServicePackUninstall$\scsiport.sys
+ 2004-08-10 19:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\sdbinst.exe
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sdbus.sys
+ 2004-08-10 19:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sdhcinst.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\secedit.exe
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\seclogon.dll
+ 2004-08-10 19:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\secur32.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\security.dll
+ 2004-08-10 19:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sendcmsg.dll
+ 2004-08-10 19:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\sendmail.dll
+ 2004-08-10 19:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\sens.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\sensapi.dll
+ 2004-08-10 19:00:00 15,488 -c----w c:\windows\$NtServicePackUninstall$\serenum.sys
+ 2004-08-10 19:00:00 64,896 -c----w c:\windows\$NtServicePackUninstall$\serial.sys
+ 2004-08-10 19:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\servdeps.dll
+ 2004-08-10 19:00:00 108,032 -c----w c:\windows\$NtServicePackUninstall$\services.exe
+ 2004-08-10 19:00:00 140,800 -c----w c:\windows\$NtServicePackUninstall$\sessmgr.exe
+ 2004-08-10 19:00:00 31,232 -c----w c:\windows\$NtServicePackUninstall$\sethc.exe
+ 2007-01-15 21:11:30 57,344 -c----w c:\windows\$NtServicePackUninstall$\setregni.exe
+ 2004-08-10 19:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\setup.exe
+ 2004-08-10 19:00:00 73,216 -c----w c:\windows\$NtServicePackUninstall$\setup50.exe
+ 2004-08-10 19:00:00 983,552 -c----w c:\windows\$NtServicePackUninstall$\setupapi.dll
+ 2004-08-10 19:00:00 101,376 -c----w c:\windows\$NtServicePackUninstall$\setupqry.dll
+ 2004-08-10 19:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\sfc.dll
+ 2004-08-10 19:00:00 140,288 -c----w c:\windows\$NtServicePackUninstall$\sfc_os.dll
+ 2004-08-10 19:00:00 1,580,544 -c----w c:\windows\$NtServicePackUninstall$\sfcfiles.dll
+ 2004-08-10 19:00:00 11,136 -c----w c:\windows\$NtServicePackUninstall$\sffdisk.sys
+ 2004-08-10 19:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\sffp_sd.sys
+ 2004-08-10 19:00:00 11,392 -c----w c:\windows\$NtServicePackUninstall$\sfloppy.sys
+ 2004-08-10 19:00:00 549,376 -c----w c:\windows\$NtServicePackUninstall$\shdoclc.dll
+ 2007-12-07 00:44:37 1,499,136 -c----w c:\windows\$NtServicePackUninstall$\shdocvw.dll
+ 2007-10-26 03:34:01 8,460,288 -c----w c:\windows\$NtServicePackUninstall$\shell32.dll
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\shfolder.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\shgina.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\shimeng.dll
+ 2004-08-10 19:00:00 438,272 -c----w c:\windows\$NtServicePackUninstall$\shimgvw.dll
+ 2007-12-07 00:44:38 474,112 -c----w c:\windows\$NtServicePackUninstall$\shlwapi.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\shmedia.dll
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\shmgrate.exe
+ 2004-08-10 19:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\shrpubw.exe
+ 2004-08-10 19:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\shscrap.dll
+ 2006-12-19 21:52:18 134,656 -c----w c:\windows\$NtServicePackUninstall$\shsvcs.dll
+ 2004-08-10 19:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\shutdown.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\sigtab.dll
+ 2004-08-10 19:00:00 70,144 -c----w c:\windows\$NtServicePackUninstall$\sigverif.exe
+ 2004-08-03 23:07:44 41,088 -c----w c:\windows\$NtServicePackUninstall$\sisagp.sys
+ 2004-08-10 19:00:00 26,112 -c----w c:\windows\$NtServicePackUninstall$\skeys.exe
+ 2004-08-10 19:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\slayerxp.dll
+ 2004-08-10 19:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\slbiop.dll
+ 2004-08-10 19:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\smbinst.exe
+ 2004-08-10 19:00:00 363,008 -c----w c:\windows\$NtServicePackUninstall$\smlogcfg.dll
+ 2004-08-10 19:00:00 89,600 -c----w c:\windows\$NtServicePackUninstall$\smlogsvc.exe
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\smss.exe
+ 2004-08-10 19:00:00 131,584 -c----w c:\windows\$NtServicePackUninstall$\sndrec32.exe
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\sniffpol.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\snmpapi.dll
+ 2004-08-10 19:00:00 182,272 -c----w c:\windows\$NtServicePackUninstall$\snmpsnap.dll
+ 2004-08-10 19:00:00 130,048 -c----w c:\windows\$NtServicePackUninstall$\softkbd.dll
+ 2004-08-03 23:09:56 25,472 -c----w c:\windows\$NtServicePackUninstall$\sonydcam.sys
+ 2004-08-10 19:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\sort.exe
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\spgrmr.dll
+ 2004-08-10 19:00:00 538,624 -c----w c:\windows\$NtServicePackUninstall$\spider.exe
+ 2004-08-10 19:00:00 12,800 -c----w c:\windows\$NtServicePackUninstall$\spiisupd.exe
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys.000
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\spnpinst.exe
+ 2004-08-10 19:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\spoolss.dll
+ 2005-06-10 23:53:32 57,856 -c----w c:\windows\$NtServicePackUninstall$\spoolsv.exe
+ 2004-08-10 19:00:00 250,880 -c----w c:\windows\$NtServicePackUninstall$\sptip.dll
+ 2008-04-14 09:42:08 438,272 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spcompat.dll
+ 2007-08-11 00:46:18 231,288 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe
+ 2007-08-11 00:46:28 382,840 -c----w c:\windows\$NtServicePackUninstall$\spuninst\updspapi.dll
+ 2004-08-10 19:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\sqldb20.dll
+ 2004-08-10 19:00:00 528,384 -c----w c:\windows\$NtServicePackUninstall$\sqloledb.dll
+ 2004-08-10 19:00:00 462,848 -c----w c:\windows\$NtServicePackUninstall$\sqlqp20.dll
+ 2004-08-10 19:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\sqlse20.dll
+ 2004-08-10 19:00:00 442,368 -c----w c:\windows\$NtServicePackUninstall$\sqlsrv32.dll
+ 2004-08-10 19:00:00 180,800 -c----w c:\windows\$NtServicePackUninstall$\sqlunirl.dll
+ 2004-08-10 19:00:00 217,088 -c----w c:\windows\$NtServicePackUninstall$\sqlxmlx.dll
+ 2004-08-10 19:00:00 73,472 -c----w c:\windows\$NtServicePackUninstall$\sr.sys
+ 2004-08-10 19:00:00 58,434 -c----w c:\windows\$NtServicePackUninstall$\srchctls.dll
+ 2004-08-10 19:00:00 725,566 -c----w c:\windows\$NtServicePackUninstall$\srchui.dll
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\srclient.dll
+ 2004-08-10 19:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\srrstr.dll
+ 2004-08-10 19:00:00 170,496 -c----w c:\windows\$NtServicePackUninstall$\srsvc.dll
+ 2006-08-14 10:34:41 332,928 -c----w c:\windows\$NtServicePackUninstall$\srv.sys
+ 2004-12-07 19:32:34 96,768 -c----w c:\windows\$NtServicePackUninstall$\srvsvc.dll
+ 2004-08-10 19:00:00 704,512 -c----w c:\windows\$NtServicePackUninstall$\ss3dfo.scr
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ssbezier.scr
+ 2004-08-10 19:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\ssdpapi.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
+ 2004-08-10 19:00:00 393,216 -c----w c:\windows\$NtServicePackUninstall$\ssflwbox.scr
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ssmarque.scr
+ 2004-08-10 19:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ssmypics.scr
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\ssmyst.scr
+ 2004-08-10 19:00:00 610,304 -c----w c:\windows\$NtServicePackUninstall$\sspipes.scr
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\ssstars.scr
+ 2004-08-10 19:00:00 679,936 -c----w c:\windows\$NtServicePackUninstall$\sstext3d.scr
+ 2004-08-10 19:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\sstub.dll
+ 2004-08-10 19:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\stclient.dll
+ 2004-08-10 19:00:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\stdprov.dll
+ 2004-08-10 19:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sti.dll
+ 2004-08-10 19:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\sti_ci.dll
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\stimon.exe
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\stobject.dll
+ 2004-08-04 00:56:46 74,752 -c----w c:\windows\$NtServicePackUninstall$\storprop.dll
+ 2004-08-04 03:08:04 48,640 -c----w c:\windows\$NtServicePackUninstall$\stream.sys
+ 2006-08-21 14:52:08 246,814 -c----w c:\windows\$NtServicePackUninstall$\strmdll.dll
+ 2004-08-10 19:00:00 75,776 -c----w c:\windows\$NtServicePackUninstall$\strmfilt.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\svchost.exe
+ 2004-08-03 22:58:42 4,352 -c----w c:\windows\$NtServicePackUninstall$\swenum.sys
+ 2001-08-17 18:00:52 54,272 -c----w c:\windows\$NtServicePackUninstall$\swmidi.sys
+ 2006-10-19 13:56:32 713,216 -c----w c:\windows\$NtServicePackUninstall$\sxs.dll
+ 2004-08-10 19:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\synceng.dll
+ 2004-08-10 19:00:00 191,488 -c----w c:\windows\$NtServicePackUninstall$\syncui.dll
+ 2004-08-04 03:15:56 60,800 -c----w c:\windows\$NtServicePackUninstall$\sysaudio.sys
+ 2004-08-10 19:00:00 168,960 -c----w c:\windows\$NtServicePackUninstall$\sysmod.dll
+ 2004-08-10 19:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\sysocmgr.exe
+ 2004-08-10 19:00:00 984,576 -c----w c:\windows\$NtServicePackUninstall$\syssetup.dll
+ 2004-07-20 09:54:18 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\system.dll
+ 2004-08-10 19:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\systeminfo.exe
+ 2005-10-17 21:14:46 118,272 -c----w c:\windows\$NtServicePackUninstall$\t2embed.dll
+ 2004-08-10 19:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\tabletoc.dll
+ 2004-08-10 19:00:00 14,976 -c----w c:\windows\$NtServicePackUninstall$\tape.sys
+ 2004-08-10 19:00:00 858,624 -c----w c:\windows\$NtServicePackUninstall$\tapi3.dll
+ 2004-08-10 19:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\tapi32.dll
+ 2005-07-08 16:27:56 249,344 -c----w c:\windows\$NtServicePackUninstall$\tapisrv.dll
+ 2004-08-10 19:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\taskkill.exe
+ 2004-08-10 19:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\tasklist.exe
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\taskmgr.exe
+ 2008-06-20 10:45:13 360,320 -c----w c:\windows\$NtServicePackUninstall$\tcpip.sys
+ 2008-06-20 09:52:06 225,920 -c----w c:\windows\$NtServicePackUninstall$\tcpip6.sys
+ 2004-08-10 19:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\tcpmib.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmon.dll
+ 2004-08-10 19:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmonui.dll
+ 2004-08-10 19:00:00 18,560 -c----w c:\windows\$NtServicePackUninstall$\tdi.sys
+ 2004-08-10 19:00:00 12,040 -c----w c:\windows\$NtServicePackUninstall$\tdpipe.sys
+ 2004-08-10 19:00:00 21,896 -c----w c:\windows\$NtServicePackUninstall$\tdtcp.sys
+ 2005-05-10 23:45:48 75,776 -c----w c:\windows\$NtServicePackUninstall$\telnet.exe
+ 2004-08-04 01:01:08 40,840 -c----w c:\windows\$NtServicePackUninstall$\termdd.sys
+ 2004-08-10 19:00:00 358,400 -c----w c:\windows\$NtServicePackUninstall$\termmgr.dll
+ 2005-03-10 14:49:51 295,424 -c----w c:\windows\$NtServicePackUninstall$\termsrv.dll
+ 2004-08-10 19:00:00 385,536 -c----w c:\windows\$NtServicePackUninstall$\themeui.dll
+ 2004-08-10 19:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\tlntadmn.exe
+ 2004-08-10 19:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\tlntsess.exe
+ 2004-08-10 19:00:00 73,216 -c----w c:\windows\$NtServicePackUninstall$\tlntsvr.exe
+ 2004-08-10 19:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\tlntsvrp.dll
+ 2007-01-15 21:11:30 57,344 -c----w c:\windows\$NtServicePackUninstall$\togac.exe
+ 2004-08-10 19:00:00 347,136 -c----w c:\windows\$NtServicePackUninstall$\tourstart.exe
+ 2004-08-10 19:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\tracerpt.exe
+ 2004-08-10 19:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\tracert.exe
+ 2004-08-10 19:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\tree.com
+ 2004-08-10 19:00:00 153,088 -c----w c:\windows\$NtServicePackUninstall$\triedit.dll
+ 2004-08-10 19:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\trkwks.dll
+ 2004-08-10 19:00:00 93,696 -c----w c:\windows\$NtServicePackUninstall$\tscfgwmi.dll
+ 2004-08-10 19:00:00 12,168 -c----w c:\windows\$NtServicePackUninstall$\tsddd.dll
+ 2004-08-10 19:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\tshoot.dll
+ 2004-08-10 19:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\tsoc.dll
+ 2004-08-03 23:03:18 12,416 -c----w c:\windows\$NtServicePackUninstall$\tunmp.sys
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\twain_32.dll
+ 2004-08-10 19:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\twext.dll
+ 2005-07-26 04:39:49 101,376 -c----w c:\windows\$NtServicePackUninstall$\txflog.dll
+ 2007-11-13 11:31:11 60,416 -c----w c:\windows\$NtServicePackUninstall$\tzchange.exe
+ 2004-08-10 19:00:00 66,176 -c----w c:\windows\$NtServicePackUninstall$\udfs.sys
+ 2004-08-10 19:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\udhisapi.dll
+ 2004-08-10 19:00:00 275,456 -c----w c:\windows\$NtServicePackUninstall$\ulib.dll
+ 2004-08-10 19:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\umandlg.dll
+ 2005-08-23 03:35:42 123,392 -c----w c:\windows\$NtServicePackUninstall$\umpnpmgr.dll
+ 2004-08-10 19:00:00 74,240 -c----w c:\windows\$NtServicePackUninstall$\unimdmat.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\uniplat.dll
+ 2004-08-10 19:00:00 316,416 -c----w c:\windows\$NtServicePackUninstall$\untfs.dll
+ 2004-08-10 19:00:00 209,408 -c----w c:\windows\$NtServicePackUninstall$\update.sys
+ 2004-08-10 19:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\uploadm.exe
+ 2004-08-10 19:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\upnp.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\upnpcont.exe
+ 2007-02-05 20:17:02 185,344 -c----w c:\windows\$NtServicePackUninstall$\upnphost.dll
+ 2004-08-10 19:00:00 239,616 -c----w c:\windows\$NtServicePackUninstall$\upnpui.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\ups.exe
+ 2004-08-10 19:00:00 12,672 -c----w c:\windows\$NtServicePackUninstall$\usb8023.sys
+ 2001-08-17 14:03:42 23,808 -c----w c:\windows\$NtServicePackUninstall$\usbcamd.sys
+ 2001-08-17 14:03:44 23,936 -c----w c:\windows\$NtServicePackUninstall$\usbcamd2.sys
+ 2004-08-04 07:08:38 26,624 -c----w c:\windows\$NtServicePackUninstall$\usbehci.sys
+ 2004-08-10 19:00:00 57,600 -c----w c:\windows\$NtServicePackUninstall$\usbhub.sys
+ 2004-08-03 23:08:58 16,000 -c----w c:\windows\$NtServicePackUninstall$\usbintel.sys
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\usbmon.dll
+ 2004-08-04 07:08:38 17,024 -c----w c:\windows\$NtServicePackUninstall$\usbohci.sys
+ 2004-08-10 19:00:00 142,976 -c----w c:\windows\$NtServicePackUninstall$\usbport.sys
+ 2004-08-10 19:00:00 26,496 -c----w c:\windows\$NtServicePackUninstall$\usbstor.sys
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\usbuhci.sys
+ 2004-08-04 00:56:48 74,240 -c----w c:\windows\$NtServicePackUninstall$\usbui.dll
+ 2007-03-08 15:36:28 577,536 -c----w c:\windows\$NtServicePackUninstall$\user32.dll
+ 2004-08-10 19:00:00 723,456 -c----w c:\windows\$NtServicePackUninstall$\userenv.dll
+ 2004-08-10 19:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\userinit.exe
 
+ 2004-08-10 19:00:00 406,528 -c----w c:\windows\$NtServicePackUninstall$\usp10.dll
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\utilman.exe
+ 2004-08-10 19:00:00 218,624 -c----w c:\windows\$NtServicePackUninstall$\uxtheme.dll
+ 2004-08-10 19:00:00 30,749 -c----w c:\windows\$NtServicePackUninstall$\vbajet32.dll
+ 2007-08-13 23:54:10 413,696 -c----w c:\windows\$NtServicePackUninstall$\vbscript.dll
+ 2004-08-10 19:00:00 26,112 -c----w c:\windows\$NtServicePackUninstall$\vdmdbg.dll
+ 2004-08-10 19:00:00 51,712 -c----w c:\windows\$NtServicePackUninstall$\vdmredir.dll
+ 2006-03-17 00:38:01 28,672 -c----w c:\windows\$NtServicePackUninstall$\verclsid.exe
+ 2004-08-10 19:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\verifier.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\version.dll
+ 2004-08-10 19:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\vga.sys
+ 2004-08-03 23:07:44 42,240 -c----w c:\windows\$NtServicePackUninstall$\viaagp.sys
+ 2004-08-10 19:00:00 5,376 -c----w c:\windows\$NtServicePackUninstall$\viaide.sys
+ 2004-08-10 19:00:00 79,744 -c----w c:\windows\$NtServicePackUninstall$\videoprt.sys
+ 2004-08-10 19:00:00 131,584 -c----w c:\windows\$NtServicePackUninstall$\viewprov.dll
+ 2004-08-10 19:00:00 52,352 -c----w c:\windows\$NtServicePackUninstall$\volsnap.sys
+ 2004-08-10 19:00:00 430,592 -c----w c:\windows\$NtServicePackUninstall$\vssapi.dll
+ 2004-08-10 19:00:00 289,792 -c----w c:\windows\$NtServicePackUninstall$\vssvc.exe
+ 2004-08-10 19:00:00 174,592 -c----w c:\windows\$NtServicePackUninstall$\w32time.dll
+ 2004-08-10 19:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\w3ssl.dll
+ 2004-08-10 19:00:00 46,080 -c----w c:\windows\$NtServicePackUninstall$\wab.exe
+ 2007-05-16 15:12:12 510,976 -c----w c:\windows\$NtServicePackUninstall$\wab32.dll
+ 2004-08-10 19:00:00 249,856 -c----w c:\windows\$NtServicePackUninstall$\wab32res.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\wabfind.dll
+ 2007-05-16 15:12:15 85,504 -c----w c:\windows\$NtServicePackUninstall$\wabimp.dll
+ 2004-08-10 19:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\wabmig.exe
+ 2004-08-10 19:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\wanarp.sys
+ 2004-08-10 19:00:00 17,664 -c----w c:\windows\$NtServicePackUninstall$\watchdog.sys
+ 2004-08-10 19:00:00 208,896 -c----w c:\windows\$NtServicePackUninstall$\wavemsp.dll
+ 2004-08-10 19:00:00 196,608 -c----w c:\windows\$NtServicePackUninstall$\wbemcntl.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\wbemcomn.dll
+ 2004-08-10 19:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\wbemcons.dll
+ 2004-08-10 19:00:00 530,944 -c----w c:\windows\$NtServicePackUninstall$\wbemcore.dll
+ 2004-08-10 19:00:00 178,176 -c----w c:\windows\$NtServicePackUninstall$\wbemdisp.dll
+ 2004-08-10 19:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\wbemess.dll
+ 2004-08-10 19:00:00 43,008 -c----w c:\windows\$NtServicePackUninstall$\wbemperf.dll
+ 2004-08-10 19:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\wbemprox.dll
+ 2004-08-10 19:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\wbemsvc.dll
+ 2004-08-10 19:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\wbemtest.exe
+ 2004-08-10 19:00:00 197,120 -c----w c:\windows\$NtServicePackUninstall$\wbemupgd.dll
+ 2006-03-24 04:37:50 49,152 -c----w c:\windows\$NtServicePackUninstall$\wdigest.dll
+ 2004-08-04 00:56:58 23,552 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.drv
+ 2006-06-14 09:00:45 82,944 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.sys
+ 2006-06-14 09:00:45 82,944 -c----w c:\windows\$NtServicePackUninstall$\wdmaud.sys.000
+ 2006-01-04 03:35:05 68,096 -c----w c:\windows\$NtServicePackUninstall$\webclnt.dll
+ 2004-08-10 19:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\webvw.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\wextract.exe
+ 2004-08-10 19:00:00 433,664 -c----w c:\windows\$NtServicePackUninstall$\wiaacmgr.exe
+ 2004-08-10 19:00:00 463,360 -c----w c:\windows\$NtServicePackUninstall$\wiadefui.dll
+ 2004-08-10 19:00:00 124,416 -c----w c:\windows\$NtServicePackUninstall$\wiadss.dll
+ 2004-08-10 19:00:00 75,776 -c----w c:\windows\$NtServicePackUninstall$\wiascr.dll
+ 2006-12-19 18:16:47 333,824 -c----w c:\windows\$NtServicePackUninstall$\wiaservc.dll
+ 2004-08-10 19:00:00 589,312 -c----w c:\windows\$NtServicePackUninstall$\wiashext.dll
+ 2004-08-10 19:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\wiavideo.dll
+ 2008-03-19 09:47:00 1,845,248 -c----w c:\windows\$NtServicePackUninstall$\win32k.sys
+ 2004-08-10 19:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\win32spl.dll
+ 2004-08-10 19:00:00 937,984 -c----w c:\windows\$NtServicePackUninstall$\winbrand.dll
+ 2004-08-10 19:00:00 283,648 -c----w c:\windows\$NtServicePackUninstall$\winhlp32.exe
+ 2004-08-10 19:00:00 351,232 -c----w c:\windows\$NtServicePackUninstall$\winhttp.dll
+ 2004-08-10 19:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\winipsec.dll
+ 2004-08-10 19:00:00 502,272 -c----w c:\windows\$NtServicePackUninstall$\winlogon.exe
+ 2004-08-10 19:00:00 176,128 -c----w c:\windows\$NtServicePackUninstall$\winmm.dll
+ 2004-08-10 19:00:00 764,928 -c----w c:\windows\$NtServicePackUninstall$\winntbbu.dll
+ 2004-08-10 19:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\winrnr.dll
+ 2004-08-10 19:00:00 99,328 -c----w c:\windows\$NtServicePackUninstall$\winscard.dll
+ 2004-08-10 19:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\winshfhc.dll
+ 2004-08-10 19:00:00 146,432 -c----w c:\windows\$NtServicePackUninstall$\winspool.drv
+ 2007-03-17 13:43:01 292,864 -c----w c:\windows\$NtServicePackUninstall$\winsrv.dll
+ 2004-08-10 19:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\winsta.dll
+ 2004-08-10 19:00:00 176,640 -c----w c:\windows\$NtServicePackUninstall$\wintrust.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\winver.exe
+ 2006-08-17 12:28:27 132,096 -c----w c:\windows\$NtServicePackUninstall$\wkssvc.dll
+ 2004-08-10 19:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\wldap32.dll
+ 2004-08-10 19:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\wlnotify.dll
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\wmi.dll
+ 2004-08-10 19:00:00 196,608 -c----w c:\windows\$NtServicePackUninstall$\wmiadap.exe
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\wmiapres.dll
+ 2004-08-10 19:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\wmiaprpl.dll
+ 2004-08-10 19:00:00 126,464 -c----w c:\windows\$NtServicePackUninstall$\wmiapsrv.exe
+ 2004-08-10 19:00:00 358,912 -c----w c:\windows\$NtServicePackUninstall$\wmic.exe
+ 2004-08-10 19:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\wmicookr.dll
+ 2004-08-10 19:00:00 140,800 -c----w c:\windows\$NtServicePackUninstall$\wmidcprv.dll
+ 2004-08-10 19:00:00 156,672 -c----w c:\windows\$NtServicePackUninstall$\wmipcima.dll
+ 2004-08-10 19:00:00 132,096 -c----w c:\windows\$NtServicePackUninstall$\wmipdskq.dll
+ 2004-08-10 19:00:00 62,464 -c----w c:\windows\$NtServicePackUninstall$\wmipiprt.dll
+ 2004-08-10 19:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\wmipjobj.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\wmiprov.dll
+ 2004-08-10 19:00:00 437,248 -c----w c:\windows\$NtServicePackUninstall$\wmiprvsd.dll
+ 2004-08-10 19:00:00 218,112 -c----w c:\windows\$NtServicePackUninstall$\wmiprvse.exe
+ 2004-08-10 19:00:00 41,472 -c----w c:\windows\$NtServicePackUninstall$\wmipsess.dll
+ 2004-08-10 19:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\wmisvc.dll
+ 2004-08-10 19:00:00 95,232 -c----w c:\windows\$NtServicePackUninstall$\wmiutils.dll
+ 2004-08-10 19:00:00 167,936 -c----w c:\windows\$NtServicePackUninstall$\wmm2ae.dll
+ 2004-08-10 19:00:00 402,432 -c----w c:\windows\$NtServicePackUninstall$\wmm2filt.dll
+ 2004-08-10 19:00:00 502,272 -c----w c:\windows\$NtServicePackUninstall$\wmm2fxa.dll
+ 2004-08-10 19:00:00 325,632 -c----w c:\windows\$NtServicePackUninstall$\wmm2fxb.dll
+ 2004-08-10 19:00:00 4,256,768 -c----w c:\windows\$NtServicePackUninstall$\wmm2res.dll
 
+ 2004-08-10 19:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\wmm2res2.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpcd.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpcore.dll
+ 2004-08-10 19:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\wmpui.dll
+ 2004-08-10 19:00:00 115,200 -c----w c:\windows\$NtServicePackUninstall$\wmsdmoe.dll
+ 2004-08-10 19:00:00 303,616 -c----w c:\windows\$NtServicePackUninstall$\wmstream.dll
+ 2004-08-10 19:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\wordpad.exe
+ 2004-08-10 19:00:00 264,192 -c----w c:\windows\$NtServicePackUninstall$\wow32.dll
+ 2004-08-10 19:00:00 32,256 -c----w c:\windows\$NtServicePackUninstall$\wpabaln.exe
+ 2004-08-10 19:00:00 32,256 -c----w c:\windows\$NtServicePackUninstall$\wpnpinst.exe
+ 2004-08-10 19:00:00 82,944 -c----w c:\windows\$NtServicePackUninstall$\ws2_32.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ws2help.dll
+ 2004-08-10 19:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\wscntfy.exe
+ 2004-08-10 19:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\wscript.exe
+ 2004-08-10 19:00:00 81,408 -c----w c:\windows\$NtServicePackUninstall$\wscsvc.dll
+ 2004-08-10 19:00:00 596,992 -c----w c:\windows\$NtServicePackUninstall$\wsecedit.dll
+ 2004-08-10 19:00:00 108,032 -c----w c:\windows\$NtServicePackUninstall$\wshbth.dll
+ 2004-08-10 19:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\wshcon.dll
+ 2004-08-10 19:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\wshext.dll
+ 2004-08-10 19:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\wship6.dll
+ 2004-08-10 19:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\wshrm.dll
+ 2004-08-10 19:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\wshtcpip.dll
+ 2004-08-10 19:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\wsnmp32.dll
+ 2004-08-10 19:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\wsock32.dll
+ 2004-08-10 19:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\wstdecod.dll
+ 2004-08-10 19:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\wtsapi32.dll
+ 2004-08-10 19:00:00 165,888 -c----w c:\windows\$NtServicePackUninstall$\wuauclt1.exe
+ 2004-08-10 19:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\wuaueng1.dll
+ 2004-08-10 19:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\wuauserv.dll
+ 2005-06-22 05:00:18 383,488 -c----w c:\windows\$NtServicePackUninstall$\wzcdlg.dll
+ 2005-06-22 05:00:18 52,736 -c----w c:\windows\$NtServicePackUninstall$\wzcsapi.dll
+ 2005-06-22 05:00:18 52,736 -c----w c:\windows\$NtServicePackUninstall$\wzcsapi.dll.000
+ 2005-06-22 05:00:18 474,624 -c----w c:\windows\$NtServicePackUninstall$\wzcsvc.dll
+ 2005-06-22 05:00:18 474,624 -c----w c:\windows\$NtServicePackUninstall$\wzcsvc.dll.000
+ 2004-08-10 19:00:00 91,648 -c----w c:\windows\$NtServicePackUninstall$\xactsrv.dll
+ 2004-08-10 19:00:00 30,720 -c----w c:\windows\$NtServicePackUninstall$\xcopy.exe
+ 2006-07-14 15:51:51 121,856 -c----w c:\windows\$NtServicePackUninstall$\xmllite.dll
+ 2004-08-10 19:00:00 129,536 -c----w c:\windows\$NtServicePackUninstall$\xmlprov.dll
+ 2004-08-10 19:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\xmlprovi.dll
+ 2006-03-01 19:42:42 11,776 -c----w c:\windows\$NtServicePackUninstall$\xolehlp.dll
+ 2006-10-10 12:44:50 557,568 -c----w c:\windows\$NtServicePackUninstall$\xpnetdiag.exe
+ 2004-08-10 19:00:00 438,784 -c----w c:\windows\$NtServicePackUninstall$\xpob2res.dll
+ 2004-08-10 19:00:00 187,392 -c----w c:\windows\$NtServicePackUninstall$\xpsp1res.dll
+ 2004-08-10 19:00:00 187,392 -c----w c:\windows\$NtServicePackUninstall$\xpsp1res.dll.026
+ 2004-08-10 19:00:00 2,897,920 -c----w c:\windows\$NtServicePackUninstall$\xpsp2res.dll
+ 2007-12-06 09:38:31 350,720 -c----w c:\windows\$NtServicePackUninstall$\xpsp3res.dll
+ 2004-08-10 19:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\zipfldr.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB895961-v4$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB895961-v4$\spuninst\updspapi.dll
+ 2008-04-14 00:12:07 295,424 -c----w c:\windows\$NtUninstallKB895961-v4$\termsrv.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB938464$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB938464$\spuninst\updspapi.dll
+ 2008-04-14 00:11:59 82,944 -c----w c:\windows\$NtUninstallKB946648$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB946648$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB946648$\spuninst\updspapi.dll
- 2006-07-13 08:48:58 202,240 -c----w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2008-04-13 18:55:08 202,624 -c----w c:\windows\$NtUninstallKB950762$\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c----w c:\windows\$NtUninstallKB950762_0$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB950762_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB950762_0$\spuninst\updspapi.dll
+ 2008-04-14 00:11:53 246,272 -c----w c:\windows\$NtUninstallKB950974$\es.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB950974$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB950974$\spuninst\updspapi.dll
+ 2008-04-14 00:11:54 691,712 -c----w c:\windows\$NtUninstallKB951066$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951066$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951066$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951072-v2$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951072-v2$\spuninst\updspapi.dll
+ 2008-04-14 00:12:38 60,416 -c----w c:\windows\$NtUninstallKB951072-v2$\tzchange.exe
- 2008-04-14 11:01:02 272,128 -c----w c:\windows\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 12:30:49 272,128 -c----w c:\windows\$NtUninstallKB951376-v2$\bthport.sys
+ 2008-04-14 11:01:02 272,128 -c----w c:\windows\$NtUninstallKB951376-v2_0$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951376-v2_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB951376-v2_0$\spuninst\updspapi.dll
+ 2008-04-13 18:46:32 273,024 -c----w c:\windows\$NtUninstallKB951376$\bthport.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951376_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB951376_0$\spuninst\updspapi.dll
- 2007-10-29 22:35:13 1,287,680 -c----w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2008-04-14 00:12:03 1,288,192 -c----w c:\windows\$NtUninstallKB951698$\quartz.dll
+ 2007-10-29 22:35:13 1,287,680 -c----w c:\windows\$NtUninstallKB951698_0$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB951698_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB951698_0$\spuninst\updspapi.dll
- 2004-08-10 19:00:00 138,496 -c----w c:\windows\$NtUninstallKB951748$\afd.sys
+ 2008-04-13 19:19:23 138,112 -c----w c:\windows\$NtUninstallKB951748$\afd.sys
- 2008-02-20 05:32:43 148,992 -c----w c:\windows\$NtUninstallKB951748$\dnsapi.dll
+ 2008-04-14 00:11:52 147,968 -c----w c:\windows\$NtUninstallKB951748$\dnsapi.dll
- 2004-08-10 19:00:00 245,248 -c----w c:\windows\$NtUninstallKB951748$\mswsock.dll
+ 2008-04-14 00:12:01 245,248 -c----w c:\windows\$NtUninstallKB951748$\mswsock.dll
- 2007-10-30 17:20:55 360,064 -c----w c:\windows\$NtUninstallKB951748$\tcpip.sys
+ 2008-04-13 19:20:16 361,344 -c----w c:\windows\$NtUninstallKB951748$\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c----w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2008-04-13 19:00:02 225,664 -c----w c:\windows\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-10 19:00:00 138,496 -c----w c:\windows\$NtUninstallKB951748_0$\afd.sys
+ 2008-02-20 05:32:43 148,992 -c----w c:\windows\$NtUninstallKB951748_0$\dnsapi.dll
+ 2004-08-10 19:00:00 245,248 -c----w c:\windows\$NtUninstallKB951748_0$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951748_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB951748_0$\spuninst\updspapi.dll
+ 2007-10-30 17:20:55 360,064 -c----w c:\windows\$NtUninstallKB951748_0$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c----w c:\windows\$NtUninstallKB951748_0$\tcpip6.sys
+ 2008-04-14 00:12:15 139,264 -c----w c:\windows\$NtUninstallKB951978$\cscript.exe
+ 2008-04-14 00:11:56 512,000 -c----w c:\windows\$NtUninstallKB951978$\jscript.dll
+ 2008-04-14 00:12:05 180,224 -c----w c:\windows\$NtUninstallKB951978$\scrobj.dll
+ 2008-04-14 00:12:05 172,032 -c----w c:\windows\$NtUninstallKB951978$\scrrun.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB951978$\spuninst\spuninst.exe
+ 2007-11-30 12:39:19 382,840 -c----w c:\windows\$NtUninstallKB951978$\spuninst\updspapi.dll
+ 2008-04-14 00:12:08 434,176 -c----w c:\windows\$NtUninstallKB951978$\vbscript.dll
+ 2008-04-14 00:12:41 155,648 -c----w c:\windows\$NtUninstallKB951978$\wscript.exe
+ 2008-04-14 00:12:10 90,112 -c----w c:\windows\$NtUninstallKB951978$\wshext.dll
+ 2008-04-14 00:11:58 331,776 -c----w c:\windows\$NtUninstallKB952287$\msadce.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB952287$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB952287$\spuninst\updspapi.dll
+ 2008-04-14 00:11:58 73,728 -c----w c:\windows\$NtUninstallKB952954$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB952954$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB952954$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB953839$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB953839$\spuninst\updspapi.dll
+ 2007-07-27 14:41:48 231,288 -c----w c:\windows\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe
+ 2007-07-27 14:41:48 382,840 -c----w c:\windows\$NtUninstallKB954154_WM11$\spuninst\updspapi.dll
+ 2006-10-19 01:47:20 295,936 -c----w c:\windows\$NtUninstallKB954154_WM11$\wmpeffects.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB954211$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB954211$\spuninst\updspapi.dll
 
+ 2008-04-13 19:30:10 1,845,632 -c----w c:\windows\$NtUninstallKB954211$\win32k.sys
+ 2008-04-14 00:12:01 1,306,624 -c----w c:\windows\$NtUninstallKB954459$\msxml6.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB954459$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB954459$\spuninst\updspapi.dll
+ 2008-04-14 00:12:01 1,104,896 -c----w c:\windows\$NtUninstallKB955069$\msxml3.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe
+ 2008-07-09 18:08:38 382,840 -c----w c:\windows\$NtUninstallKB955069$\spuninst\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB956391$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\$NtUninstallKB956391$\spuninst\updspapi.dll
+ 2008-06-20 11:40:08 138,496 -c----w c:\windows\$NtUninstallKB956803$\afd.sys
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956803$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB956803$\spuninst\updspapi.dll
+ 2008-04-13 18:31:21 2,065,792 -c----w c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
+ 2008-04-13 19:27:53 2,188,928 -c----w c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB956841$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c----w c:\windows\$NtUninstallKB956841$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB957095$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB957095$\spuninst\updspapi.dll
+ 2008-04-13 19:15:11 334,848 -c----w c:\windows\$NtUninstallKB957095$\srv.sys
+ 2008-04-13 19:17:01 456,576 -c----w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
+ 2008-07-08 13:02:02 231,288 -c----w c:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe
+ 2008-07-08 13:02:12 382,840 -c----w c:\windows\$NtUninstallKB957097$\spuninst\updspapi.dll
+ 2008-04-14 00:12:01 337,408 -c----w c:\windows\$NtUninstallKB958644$\netapi32.dll
+ 2007-11-30 11:18:51 231,288 -c----w c:\windows\$NtUninstallKB958644$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958644$\spuninst\updspapi.dll
- 2006-10-04 14:05:26 39,424 ------w c:\windows\AppPatch\acadproc.dll
+ 2008-04-14 00:11:48 39,424 ----a-w c:\windows\AppPatch\acadproc.dll
- 2004-08-10 19:00:00 1,852,416 ----a-w c:\windows\AppPatch\AcGenral.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w c:\windows\AppPatch\acgenral.dll
- 2004-08-10 19:00:00 450,048 ----a-w c:\windows\AppPatch\AcLayers.dll
+ 2008-04-14 00:11:48 451,072 -c--a-w c:\windows\AppPatch\aclayers.dll
- 2004-08-10 19:00:00 137,728 ----a-w c:\windows\AppPatch\AcLua.dll
+ 2008-04-14 00:11:48 141,312 -c--a-w c:\windows\AppPatch\aclua.dll
- 2004-08-10 19:00:00 244,736 ----a-w c:\windows\AppPatch\AcSpecfc.dll
+ 2008-04-14 00:11:48 245,248 ----a-w c:\windows\AppPatch\acspecfc.dll
- 2004-08-10 19:00:00 116,224 ----a-w c:\windows\AppPatch\AcXtrnal.dll
+ 2008-04-14 00:11:48 116,224 -c--a-w c:\windows\AppPatch\acxtrnal.dll
- 2005-01-10 01:08:31 8,704 ----a-w c:\windows\assembly\GAC\Accessibility\1.0.3300.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-07-14 00:33:10 8,704 -c--a-w c:\windows\assembly\GAC\Accessibility\1.0.3300.0__b03f5f7f11d50a3a\Accessibility.dll
- 2005-01-10 01:38:39 117,248 ----a-w c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
+ 2008-07-14 00:40:50 117,248 ----a-w c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
- 2005-01-10 01:08:31 12,288 ----a-w c:\windows\assembly\GAC\cscompmgd\7.0.3300.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-07-14 00:33:09 12,288 -c--a-w c:\windows\assembly\GAC\cscompmgd\7.0.3300.0__b03f5f7f11d50a3a\cscompmgd.dll
- 2005-01-10 01:08:31 34,816 ----a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-07-14 00:33:10 34,816 -c--a-w c:\windows\assembly\GAC\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- 2005-01-10 01:38:38 102,400 ----a-w c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
+ 2008-07-14 00:40:49 102,400 ----a-w c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
- 2008-04-21 15:59:14 1,863,680 ----a-w c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\ehcm.dll
+ 2008-07-14 00:40:50 1,863,680 ----a-w c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\EhCM.dll
- 2005-01-10 01:38:39 192,512 ----a-w c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
+ 2008-07-14 00:40:50 192,512 ----a-w c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
- 2008-04-21 15:59:14 868,352 ----a-w c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2008-07-14 00:40:50 868,352 ----a-w c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
- 2005-01-10 01:38:38 126,976 ----a-w c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
+ 2008-07-14 00:40:50 126,976 ----a-w c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
- 2005-01-10 01:38:40 110,592 ----a-w c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
+ 2008-07-14 00:40:50 110,592 -c--a-w c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
- 2005-01-10 01:38:38 8,192 ----a-w c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
+ 2008-07-14 00:40:49 8,192 ----a-w c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
- 2005-01-10 01:38:38 73,728 ----a-w c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
+ 2008-07-14 00:40:49 73,728 ----a-w c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
- 2005-01-10 01:38:39 167,936 ----a-w c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
+ 2008-07-14 00:40:50 167,936 -c--a-w c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
- 2008-04-21 15:59:15 204,800 ----a-w c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiplay.dll
+ 2008-07-14 00:40:50 204,800 ----a-w c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
- 2005-01-10 01:38:39 389,120 ----a-w c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
+ 2008-07-14 00:40:50 389,120 ----a-w c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
- 2005-01-10 01:38:39 18,944 ----a-w c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
+ 2008-07-14 00:40:50 18,944 ----a-w c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
- 2005-01-10 01:38:39 278,528 ----a-w c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
+ 2008-07-14 00:40:50 278,528 -c--a-w c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
- 2005-01-10 01:38:38 122,880 ----a-w c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
+ 2008-07-14 00:40:49 122,880 -c--a-w c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
- 2005-01-10 01:38:39 53,248 ----a-w c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
+ 2008-07-14 00:40:50 53,248 ----a-w c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
- 2005-01-10 01:38:38 389,120 ----a-w c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
+ 2008-07-14 00:40:49 389,120 ----a-w c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
- 2005-01-10 01:08:32 7,168 ----a-w c:\windows\assembly\GAC\IEExecRemote\1.0.3300.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-07-14 00:33:12 7,168 -c--a-w c:\windows\assembly\GAC\IEExecRemote\1.0.3300.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2005-01-10 01:08:32 32,768 ----a-w c:\windows\assembly\GAC\IEHost\1.0.3300.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-07-14 00:33:12 32,768 -c--a-w c:\windows\assembly\GAC\IEHost\1.0.3300.0__b03f5f7f11d50a3a\IEHost.dll
- 2005-01-10 01:08:32 4,096 ----a-w c:\windows\assembly\GAC\IIEHost\1.0.3300.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-07-14 00:33:13 4,096 -c--a-w c:\windows\assembly\GAC\IIEHost\1.0.3300.0__b03f5f7f11d50a3a\IIEHost.dll
- 2005-01-10 01:08:32 27,136 ----a-w c:\windows\assembly\GAC\ISymWrapper\1.0.3300.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-07-14 00:33:13 27,136 -c--a-w c:\windows\assembly\GAC\ISymWrapper\1.0.3300.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2005-01-10 01:08:31 712,704 ----a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-07-14 00:33:09 712,704 -c--a-w c:\windows\assembly\GAC\Microsoft.JScript\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2005-01-10 01:38:39 45,056 ----a-w c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
+ 2008-07-14 00:40:50 45,056 ----a-w c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
+ 2008-08-24 02:48:53 8,011,400 -c--a-w c:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
- 2005-01-10 01:08:31 28,672 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-07-14 00:33:09 28,672 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- 2005-01-10 01:08:31 286,720 ----a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-07-14 00:33:10 286,720 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2005-01-10 01:08:31 5,632 ----a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2008-07-14 00:33:10 5,632 -c--a-w c:\windows\assembly\GAC\Microsoft.VisualC\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
- 2005-01-10 01:08:31 11,264 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-07-14 00:33:08 11,264 -c--a-w c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2005-01-10 01:08:31 18,944 ----a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-07-14 00:33:09 18,944 -c--a-w c:\windows\assembly\GAC\Microsoft.Vsa\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2005-01-10 01:08:31 6,656 ----a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.3300.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-07-14 00:33:08 6,656 -c--a-w c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.3300.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2005-01-10 01:08:32 1,564,672 ----a-w c:\windows\assembly\GAC\mscorcfg\1.0.3300.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2008-07-14 00:33:13 1,564,672 -c--a-w c:\windows\assembly\GAC\mscorcfg\1.0.3300.0__b03f5f7f11d50a3a\mscorcfg.dll
- 2005-01-10 01:08:31 32,768 ----a-w c:\windows\assembly\GAC\Regcode\1.0.3300.0__b03f5f7f11d50a3a\RegCode.dll
+ 2008-07-14 00:33:10 32,768 -c--a-w c:\windows\assembly\GAC\Regcode\1.0.3300.0__b03f5f7f11d50a3a\RegCode.dll
- 2005-01-10 01:38:39 77,824 ----a-w c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
+ 2008-07-14 00:40:50 77,824 -c--a-w c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
- 2005-01-10 01:08:31 77,824 ----a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.3300.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-07-14 00:33:11 77,824 -c--a-w c:\windows\assembly\GAC\System.Configuration.Install\1.0.3300.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- 2005-01-10 01:08:31 1,179,648 ----a-w c:\windows\assembly\GAC\System.Data\1.0.3300.0__b77a5c561934e089\System.Data.dll
+ 2008-07-14 00:33:12 1,179,648 -c--a-w c:\windows\assembly\GAC\System.Data\1.0.3300.0__b77a5c561934e089\System.Data.dll
- 2005-01-10 01:08:31 1,695,744 ----a-w c:\windows\assembly\GAC\System.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-07-14 00:33:12 1,695,744 -c--a-w c:\windows\assembly\GAC\System.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Design.dll
- 2005-01-10 01:08:31 86,016 ----a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.3300.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-07-14 00:33:11 86,016 -c--a-w c:\windows\assembly\GAC\System.DirectoryServices\1.0.3300.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2005-01-10 01:08:31 65,536 ----a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-07-14 00:33:11 65,536 -c--a-w c:\windows\assembly\GAC\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2005-01-10 01:08:32 462,848 ----a-w c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-07-14 00:33:12 462,848 -c--a-w c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2005-01-10 01:08:31 212,992 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-07-14 00:33:10 212,992 -c--a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2005-01-10 01:08:31 48,640 ----a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2008-07-14 00:33:10 48,640 -c--a-w c:\windows\assembly\GAC\System.EnterpriseServices\1.0.3300.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
- 2005-01-10 01:08:32 352,256 ----a-w c:\windows\assembly\GAC\System.Management\1.0.3300.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-07-14 00:33:13 352,256 -c--a-w c:\windows\assembly\GAC\System.Management\1.0.3300.0__b03f5f7f11d50a3a\System.Management.dll
- 2005-01-10 01:08:32 241,664 ----a-w c:\windows\assembly\GAC\System.Messaging\1.0.3300.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-07-14 00:33:12 241,664 -c--a-w c:\windows\assembly\GAC\System.Messaging\1.0.3300.0__b03f5f7f11d50a3a\System.Messaging.dll
- 2005-01-10 01:08:32 311,296 ----a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.3300.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-07-14 00:33:13 311,296 -c--a-w c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.3300.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2005-01-10 01:08:32 131,072 ----a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.3300.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-07-14 00:33:13 131,072 -c--a-w c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.3300.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2005-01-10 01:08:31 77,824 ----a-w c:\windows\assembly\GAC\System.Security\1.0.3300.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-07-14 00:33:10 77,824 -c--a-w c:\windows\assembly\GAC\System.Security\1.0.3300.0__b03f5f7f11d50a3a\System.Security.dll
- 2005-01-10 01:08:31 126,976 ----a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.3300.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-07-14 00:33:11 126,976 -c--a-w c:\windows\assembly\GAC\System.ServiceProcess\1.0.3300.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2005-01-10 01:08:31 61,440 ----a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.3300.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-07-14 00:33:11 61,440 -c--a-w c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.3300.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2005-01-10 01:08:31 507,904 ----a-w c:\windows\assembly\GAC\System.Web.Services\1.0.3300.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-07-14 00:33:11 507,904 -c--a-w c:\windows\assembly\GAC\System.Web.Services\1.0.3300.0__b03f5f7f11d50a3a\System.Web.Services.dll
 
- 2008-04-03 03:03:06 1,200,128 ----a-w c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-07-14 00:33:11 1,200,128 -c--a-w c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2005-01-10 01:08:31 2,002,944 ----a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-07-14 00:33:11 2,002,944 -c--a-w c:\windows\assembly\GAC\System.Windows.Forms\1.0.3300.0__b77a5c561934e089\System.Windows.Forms.dll
- 2005-01-10 01:08:31 1,302,528 ----a-w c:\windows\assembly\GAC\System.Xml\1.0.3300.0__b77a5c561934e089\System.Xml.dll
+ 2008-07-14 00:33:12 1,302,528 -c--a-w c:\windows\assembly\GAC\System.Xml\1.0.3300.0__b77a5c561934e089\System.Xml.dll
- 2005-01-10 01:08:32 1,179,648 ----a-w c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
+ 2008-07-14 00:33:12 1,179,648 -c--a-w c:\windows\assembly\GAC\System\1.0.3300.0__b77a5c561934e089\System.dll
+ 2008-11-20 18:15:27 60,928 ----a-w c:\windows\assembly\GAC_32\cli_cppuhelper\1.0.14.0__ce2cb7e279207b9e\cli_cppuhelper.dll
+ 2008-08-24 02:48:14 106,120 ----a-w c:\windows\assembly\GAC_32\CSMInterface\5.3.1.1__6cba14bfb4f12ba0\CSMInterface.dll
+ 2008-08-24 02:48:14 45,056 ----a-w c:\windows\assembly\GAC_32\CSMRemotable\5.3.1.1__93c818616a5c6d1f\CSMRemotable.dll
+ 2008-09-11 15:21:35 69,120 -c--a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2008-09-11 15:21:38 72,192 -c--a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2008-09-11 15:23:35 151,552 -c--a-w c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-09-11 15:21:27 4,444,160 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2008-11-20 18:15:33 3,072 ----a-w c:\windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\14.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_cppuhelper.dll
+ 2008-09-11 15:23:40 4,174,336 ----a-w c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2008-09-11 15:21:38 483,840 -c--a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2008-09-11 15:21:32 3,036,160 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2008-09-11 15:21:40 258,048 -c--a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2008-09-11 15:21:40 113,664 -c--a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2008-09-11 15:23:39 346,624 -c--a-w c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2008-09-11 15:21:38 261,120 -c--a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2008-09-11 15:21:31 5,431,296 -c--a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-09-11 15:21:33 10,752 -c--a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2008-09-11 15:21:31 507,904 -c--a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2008-11-20 18:15:04 11,264 ----a-w c:\windows\assembly\GAC_MSIL\cli_basetypes\1.0.11.0__ce2cb7e279207b9e\cli_basetypes.dll
+ 2008-11-20 18:15:28 823,296 ----a-w c:\windows\assembly\GAC_MSIL\cli_oootypes\1.0.0.0__ce2cb7e279207b9e\cli_oootypes.dll
+ 2008-11-20 18:15:04 7,680 ----a-w c:\windows\assembly\GAC_MSIL\cli_ure\1.0.14.0__ce2cb7e279207b9e\cli_ure.dll
+ 2008-11-20 18:15:04 114,688 ----a-w c:\windows\assembly\GAC_MSIL\cli_uretypes\1.0.0.0__ce2cb7e279207b9e\cli_uretypes.dll
+ 2008-09-11 15:21:35 13,312 -c--a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2008-09-11 15:21:36 8,192 -c--a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2008-09-11 15:21:37 77,824 -c--a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
+ 2008-09-11 15:21:37 6,656 -c--a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2008-08-24 02:48:13 130,696 -c--a-w c:\windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__6cba14bfb4f12ba0\Interop.SHDocVw.dll
+ 2008-09-11 15:21:40 348,160 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2008-09-11 15:21:40 36,864 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2008-09-11 15:21:41 655,360 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2008-09-11 15:21:41 77,824 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
+ 2008-09-11 15:21:37 749,568 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2008-09-11 18:24:17 87,072 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.LifeCam.Framework\2.4.542.0__31bf3856ad364e35\Microsoft.LifeCam.Framework.dll
+ 2008-09-11 18:24:17 46,112 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.LifeCam.Interfaces\2.4.542.0__31bf3856ad364e35\Microsoft.LifeCam.Interfaces.dll
+ 2008-09-11 15:23:35 397,312 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2008-09-11 15:21:36 110,592 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2008-09-11 15:21:36 372,736 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2008-09-11 15:21:39 28,672 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2008-09-11 15:21:36 671,744 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2008-09-11 15:21:29 5,632 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2008-09-11 15:21:39 12,800 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2008-09-11 15:21:35 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2008-09-11 15:21:35 7,168 -c--a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_basetypes\11.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_basetypes.dll
+ 2008-11-20 18:15:33 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_oootypes\1.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_oootypes.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_ure\14.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_ure.dll
+ 2008-11-20 18:15:05 3,072 ----a-w c:\windows\assembly\GAC_MSIL\policy.1.0.cli_uretypes\1.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_uretypes.dll
+ 2008-09-11 15:23:33 602,112 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2008-09-11 15:23:40 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2008-09-11 15:23:38 184,320 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2008-09-11 15:23:38 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2008-09-11 15:23:38 376,832 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2008-09-11 15:23:38 151,552 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2008-09-11 15:23:37 5,210,112 ----a-w c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2008-09-11 15:23:37 897,024 -c--a-w c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2008-09-11 15:23:39 528,384 -c--a-w c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2008-09-11 15:23:35 102,400 -c--a-w c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2008-09-11 15:21:37 110,592 -c--a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2008-09-11 15:21:37 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2008-09-11 15:21:31 425,984 -c--a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2008-09-11 15:21:32 741,376 -c--a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2008-09-11 15:21:32 933,888 -c--a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2008-09-11 15:21:42 5,070,848 -c--a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2008-09-11 15:21:41 188,416 -c--a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2008-09-11 15:21:34 401,408 -c--a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2008-09-11 15:21:39 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2008-09-11 15:21:29 630,784 -c--a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2008-09-11 15:23:41 126,976 -c--a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2008-09-11 15:23:41 430,080 -c--a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2008-09-11 15:23:35 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2008-09-11 15:21:40 372,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2008-09-11 15:21:39 258,048 -c--a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2008-09-11 15:21:38 299,008 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2008-09-11 15:21:38 131,072 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2008-09-11 15:23:35 929,792 -c--a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2008-09-11 15:21:30 258,048 -c--a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2008-09-11 15:23:33 159,744 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2008-09-11 15:23:33 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2008-09-11 15:23:34 5,971,968 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2008-09-11 15:21:30 114,688 -c--a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2008-09-11 15:23:33 688,128 -c--a-w c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2008-09-11 15:21:33 884,736 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2008-09-11 15:21:33 90,112 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2008-09-11 15:21:33 839,680 -c--a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2008-09-11 15:21:34 5,013,504 -c--a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2008-09-11 15:23:41 1,152,040 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2008-09-11 15:23:40 1,635,376 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2008-09-11 15:23:40 578,592 -c--a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2008-09-11 15:21:30 2,068,480 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2008-09-11 15:21:32 3,076,096 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2008-09-11 15:23:32 163,840 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2008-09-11 15:23:32 372,736 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2008-09-11 15:23:39 32,768 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2008-09-11 15:23:39 86,016 -c--a-w c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2008-09-11 15:23:39 1,204,224 ----a-w c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2008-09-11 15:23:32 81,920 -c--a-w c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2008-08-06 15:34:22 26,624 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\052b01d5f41165c75040614d03e64545\Accessibility.ni.dll
+ 2008-09-11 15:26:49 27,136 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll
+ 2008-08-06 15:34:24 888,832 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\52e6f71030afecf866e37de57592535e\AspNetMMCExt.ni.dll
+ 2008-09-11 15:31:49 884,736 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll
+ 2008-08-06 15:34:48 499,712 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\baa716dbee42118add871bd21d5ab9fc\ComSvcConfig.ni.exe
+ 2008-09-11 15:32:23 503,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\bb3c2f59a821abc54f420f3a9e051d6a\ComSvcConfig.ni.exe
+ 2008-09-11 15:32:30 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll
+ 2008-08-06 15:36:06 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c67b101d9842e334154243a5e4da0aa3\CustomMarshalers.ni.dll
+ 2008-09-11 15:32:22 15,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe
+ 2008-08-06 15:34:48 15,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\eb54a996a7fe35fb2b4e4ef98f02a4ed\dfsvc.ni.exe
+ 2008-08-06 15:36:07 880,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5f50f3da9811bfaa72382173ee82d1dd\Microsoft.Build.Engine.ni.dll
+ 2008-09-11 15:32:31 876,544 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll
+ 2008-08-06 15:36:07 81,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\613b88256a517b5b3af9f922267e19b0\Microsoft.Build.Framework.ni.dll
+ 2008-09-11 15:32:32 81,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll
+ 2008-09-11 15:32:34 1,695,744 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll
+ 2008-08-06 15:36:09 1,687,552 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\8004ef004a54b4c2e0d05ed5e8335219\Microsoft.Build.Tasks.ni.dll
+ 2008-09-11 15:32:35 167,936 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll
+ 2008-08-06 15:36:09 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\bfcffe6e05507159e93263c5242e22a1\Microsoft.Build.Utilities.ni.dll
+ 2008-08-06 15:34:50 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\2882820964bda08740ebd2fd3afe45ab\Microsoft.Transactions.Bridge.ni.dll
+ 2008-08-06 15:34:51 405,504 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\d1a80d409e6595eecefe926e1f7a05a4\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2008-09-11 15:32:25 1,232,896 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\e3dce636e798c53ec2b44d1d4aadb850\Microsoft.Transactions.Bridge.ni.dll
+ 2008-09-11 15:32:26 401,408 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f3902a808549b40d648206c9303f2788\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2008-09-11 15:32:37 1,740,800 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll
+ 2008-08-06 15:36:11 1,720,320 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c5d3c0594e7f7d5ea8c9888f0e14c2f9\Microsoft.VisualBasic.ni.dll
+ 2008-08-06 15:35:02 17,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\b7f503038312fbdb46d541be8767dc0b\Microsoft.VisualC.ni.dll
+ 2008-09-11 15:26:50 17,920 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\cd0730694ba5927a6efd32129783e1b4\Microsoft.VisualC.ni.dll
+ 2008-09-11 15:25:09 11,722,752 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll
+ 2008-08-06 14:49:48 11,304,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3d2a91a6c545200f624700ac2ae86375\mscorlib.ni.dll
+ 2008-08-06 15:36:13 1,568,768 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\53efd2da70401b56c4a9877fab797aee\PresentationBuildTasks.ni.dll
+ 2008-09-11 15:32:39 1,581,056 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\ab2b2664932688ae7c8e0bd9d10448ef\PresentationBuildTasks.ni.dll
+ 2008-08-06 15:36:05 40,448 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\2af82cbb3977e66a69fae5b83ebdd35f\PresentationCFFRasterizer.ni.dll
+ 2008-09-11 15:27:11 40,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3df824565150953afd560ca20237b881\PresentationCFFRasterizer.ni.dll
+ 2008-09-11 15:27:10 12,570,624 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\011f8e31d197b4ccb6a61c2267a38e5c\PresentationCore.ni.dll
+ 2008-08-06 15:35:42 11,984,896 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\46dc43af4b8173a8761b4c9ee1b3f039\PresentationCore.ni.dll
+ 2008-08-06 15:34:53 48,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\26f9d960635bfc56e0312f6d3446d7bc\PresentationFontCache.ni.exe
+ 2008-09-11 15:26:11 48,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\4ce7fd62d4107fbe996ab305eb21ee6a\PresentationFontCache.ni.exe
+ 2008-08-06 15:48:24 14,680,064 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\06c18ef796aea6f5e9fa845e8a25dd80\PresentationFramework.ni.dll
+ 2008-09-11 15:28:25 393,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\36c6cfd5d4e80d5c548f823b2bbf5457\PresentationFramework.Aero.ni.dll
+ 2008-09-11 15:28:28 552,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3f18bff5107c9a8accae6c248fdf3c2e\PresentationFramework.Luna.ni.dll
+ 2008-08-06 15:48:41 393,216 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\43a7f7d305d55c956d459aafff07f871\PresentationFramework.Aero.ni.dll
+ 2008-09-11 15:27:37 15,036,416 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60421dda88800b14dc101ed9dca422fe\PresentationFramework.ni.dll
+ 2008-08-06 15:48:46 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6880aea2c464caf8759ac13f1b2a61ae\PresentationFramework.Classic.ni.dll
+ 2008-09-11 15:28:30 274,432 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\81d2540bc1c18190d0431d9a61bee65b\PresentationFramework.Royale.ni.dll
+ 2008-09-11 15:28:27 245,760 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9df61ec7aad39fe0bac82139cd84e5e5\PresentationFramework.Classic.ni.dll
+ 2008-08-06 15:48:51 548,864 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f5f05fc603c6ed0d66f6f6c6bc4a3c3f\PresentationFramework.Luna.ni.dll
+ 2008-08-06 15:48:55 270,336 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\fec099bb1b7ad687d034df56c1e87b84\PresentationFramework.Royale.ni.dll
+ 2008-09-11 15:27:39 2,035,712 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6d2716a55eb8ce6fc4cbf83f3ab329e3\PresentationUI.ni.dll
+ 2008-08-06 15:48:32 1,982,464 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\8ab7eb8fe1cba4ab55caf5b012ce94e5\PresentationUI.ni.dll
+ 2008-08-06 15:48:39 2,396,160 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\4dae59b5c525bc0c6ba738dfc13f66ef\ReachFramework.ni.dll
+ 2008-09-11 15:27:43 2,416,640 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\840c64bba900a6ed333ca39e63a9ca3b\ReachFramework.ni.dll
+ 2008-08-06 15:34:51 135,168 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\3ac95d73de52011ee0f7edd5a6d3730b\ServiceModelReg.ni.exe
+ 2008-09-11 15:32:27 139,264 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\feac66e81309d67b48f7a9f4cb98f7c8\ServiceModelReg.ni.exe
+ 2008-09-11 15:32:27 299,008 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\169ba2fe1a4d87ede3ab8dd3d44d867e\SMDiagnostics.ni.dll
+ 2008-08-06 15:34:52 286,720 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\d4b9cf1f94a59870fe4c96e1e9c5d041\SMDiagnostics.ni.dll
+ 2008-08-06 15:34:52 323,584 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\3eee8f72df72d4b86b812d2eef31096d\SMSvcHost.ni.exe
+ 2008-09-11 15:32:28 323,584 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\a098c66aa40d958878f3f5344e6ae1a4\SMSvcHost.ni.exe
+ 2008-09-11 15:32:48 262,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\6a075eb8e0f13de87d1278aa8562d51e\sysglobl.ni.dll
+ 2008-08-06 15:49:15 262,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\f1291e1269ca53fda5d9c2f85bddfb28\sysglobl.ni.dll
+ 2008-08-06 15:34:59 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\331f31454e9328cfd4adad646ae07f57\System.Configuration.Install.ni.dll
+ 2008-09-11 15:26:34 163,840 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\c46625ea87db53ccf6194fe17ee05c19\System.Configuration.Install.ni.dll
+ 2008-08-06 15:34:55 1,003,520 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\ec99be9da6a99bd8d655b71e1ab340ca\System.Configuration.ni.dll
+ 2008-09-11 15:26:19 1,011,712 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll
+ 2008-09-11 15:28:22 1,183,744 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\1abdb47765d0696a2fc0a1095bac0249\System.Data.OracleClient.ni.dll
+ 2008-08-06 15:36:03 1,179,648 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f26873ac98747631a7726745e89b223c\System.Data.OracleClient.ni.dll
+ 2008-08-06 15:34:58 2,695,168 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\b2f4ae6f29d5a3078f344c92b54bca02\System.Data.SqlXml.ni.dll
+ 2008-09-11 15:26:32 2,756,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e59504af41afab5e04681af951d9b302\System.Data.SqlXml.ni.dll
+ 2008-08-06 14:50:49 6,676,480 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\280871d92ac03759dcfd7078f76887d6\System.Data.ni.dll
+ 2008-09-11 15:27:53 7,049,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll
+ 2008-08-06 15:35:01 1,724,416 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\06305b5a0a0dd6b25225704887c66e13\System.Deployment.ni.dll
+ 2008-09-11 15:26:50 1,798,144 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll
+ 2008-08-06 14:51:15 10,702,848 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\a60b40f4a220b217c807966d3a2a4592\System.Design.ni.dll
+ 2008-09-11 15:28:20 10,969,088 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll
+ 2008-09-11 15:27:46 1,224,704 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll
+ 2008-08-06 15:36:04 512,000 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\bb5362bc478cd680b3413c70630efabc\System.DirectoryServices.Protocols.ni.dll
+ 2008-09-11 15:28:23 512,000 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll
+ 2008-08-06 15:35:45 1,216,512 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f9dd15355dd9047c3c371714bf985bef\System.DirectoryServices.ni.dll
+ 2008-08-06 14:51:18 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\02160e0e625f78d5830d9b563e100331\System.Drawing.Design.ni.dll
+ 2008-09-11 15:28:20 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll
+ 2008-09-11 15:26:36 1,667,072 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll
+ 2008-08-06 14:51:17 1,601,536 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ccb5d6542f8954915f9964b17b46bd7c\System.Drawing.ni.dll
+ 2008-09-11 15:27:55 659,456 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll
+ 2008-09-11 15:27:55 294,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll
+ 2008-08-06 15:35:44 659,456 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2db2e33c3ff91993737b98a47ba5e99\System.EnterpriseServices.ni.dll
+ 2008-08-06 15:35:44 294,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\f2db2e33c3ff91993737b98a47ba5e99\System.EnterpriseServices.Wrapper.dll
+ 2008-08-06 15:34:25 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\26b0767aafa118512edcb09b4007bbaf\System.IdentityModel.Selectors.ni.dll
+ 2008-09-11 15:31:51 241,664 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\492d16599426c7ab35ad2c499a9d4ae6\System.IdentityModel.Selectors.ni.dll
+ 2008-09-11 15:31:51 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\bdd94a4c46e4424787dfed9381196cb3\System.IdentityModel.ni.dll
+ 2008-08-06 15:34:25 987,136 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\f8f516e657a16c1770cf77749aae9540\System.IdentityModel.ni.dll
+ 2008-08-06 15:34:26 421,888 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\a66fada0648afd51c59029cd58d5ae7e\System.IO.Log.ni.dll
+ 2008-09-11 15:31:52 417,792 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e1e6aa5272543f1d9dad98be897b693e\System.IO.Log.ni.dll
+ 2008-09-11 15:33:05 655,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\00e3750e478bac4913ee7a6c3b7cd392\System.Messaging.ni.dll
+ 2008-08-06 15:49:36 655,360 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\ed190de5880e259667ae7dc60c3aa3ff\System.Messaging.ni.dll
+ 2008-08-06 15:48:40 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\454f85e8d514523698d295500e659cef\System.Printing.ni.dll
+ 2008-09-11 15:27:45 1,134,592 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\f94fbbe7d7c6e76d02cd9fb94ee8d910\System.Printing.ni.dll
+ 2008-09-11 15:27:57 815,104 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll
+ 2008-08-06 15:35:46 815,104 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\ecb6e302ca6264f422d77e40f8976c55\System.Runtime.Remoting.ni.dll
+ 2008-09-11 15:26:34 339,968 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1f5cf8178029f5b959a9af75cb8cfedb\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-08-06 15:34:29 2,363,392 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\7bf1b63ce7872a0a968825a5b98f68fd\System.Runtime.Serialization.ni.dll
+ 2008-08-06 15:35:00 339,968 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a33827fda63dcbbc207985eb4f1a9cef\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-09-11 15:31:56 2,445,312 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\e27527e67611d8acc0d8dff6d286af23\System.Runtime.Serialization.ni.dll
+ 2008-09-11 15:26:33 733,184 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll
+ 2008-08-06 15:34:59 729,088 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\779aee6971d8dac0a75bf00fa2b01740\System.Security.ni.dll
+ 2008-08-06 15:34:47 17,534,976 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\02ad21fb5d0fdd242895be699763de66\System.ServiceModel.ni.dll
+ 2008-09-11 15:32:20 18,071,552 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\350903c091629396c08742c996c1caba\System.ServiceModel.ni.dll
+ 2008-09-11 15:26:15 233,472 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll
+ 2008-08-06 15:34:53 229,376 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\389b18e556e6a5f1e09650d06002cf76\System.ServiceProcess.ni.dll
 
+ 2008-08-06 15:49:14 2,031,616 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\18ae104b9705a3bdf68cfe6fa8d61832\System.Speech.ni.dll
+ 2008-09-11 15:32:48 2,039,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\d4147c99010667b5c547fcfc56ed7bd5\System.Speech.ni.dll
+ 2008-09-11 15:27:54 679,936 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll
+ 2008-08-06 15:35:43 684,032 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\e88c997aa1c8a48e48f43fd6cbd0e03f\System.Transactions.ni.dll
+ 2008-08-06 15:49:18 2,306,048 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\0e4ce5082b36961bcc4b9191c1e8e798\System.Web.Mobile.ni.dll
+ 2008-09-11 15:32:51 2,342,912 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll
+ 2008-08-06 15:36:04 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\55cd271d60f6f2adcb5d54ba5d82865e\System.Web.RegularExpressions.ni.dll
+ 2008-09-11 15:28:23 237,568 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll
+ 2008-09-11 15:28:11 1,986,560 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll
+ 2008-08-06 15:36:02 1,941,504 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\80cd7c9e54415f07b1ad767be9795dc5\System.Web.Services.ni.dll
+ 2008-09-11 15:28:08 12,509,184 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll
+ 2008-08-06 15:35:59 12,185,600 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\f9476232b313bcdad5b484ac91b37cf9\System.Web.ni.dll
+ 2008-09-11 15:26:48 13,193,216 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll
+ 2008-08-06 14:51:31 13,107,200 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6afdd8862913a1788c068c5e8d59f4e8\System.Windows.Forms.ni.dll
+ 2008-08-06 15:49:22 2,994,176 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\3acfa0050500b276ac5a98d09c6fb4a3\System.Workflow.Activities.ni.dll
+ 2008-09-11 15:32:56 3,084,288 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\9798b3ba448ba7d5f1dd70a8a1fb7562\System.Workflow.Activities.ni.dll
+ 2008-09-11 15:33:01 4,579,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\575dad1c0dc9d035acbab10846802ce0\System.Workflow.ComponentModel.ni.dll
+ 2008-08-06 15:49:28 4,587,520 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\db1187eb1adaac7bdd7e8a4904954627\System.Workflow.ComponentModel.ni.dll
+ 2008-09-11 15:33:04 2,088,960 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\9d89b57d703aefe4938b45f8b398d378\System.Workflow.Runtime.ni.dll
+ 2008-08-06 15:49:34 2,101,248 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\bc074f562df871499f1b36f545ab1aa3\System.Workflow.Runtime.ni.dll
+ 2008-09-11 15:26:28 5,771,264 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll
+ 2008-08-06 14:51:37 5,623,808 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\e4fc736d0feeee9e0c9a0bea73237236\System.Xml.ni.dll
+ 2008-08-06 14:50:11 8,130,560 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\55f79c8f77fdcc590f75307fe36f0c5c\System.ni.dll
+ 2008-09-11 15:26:10 8,265,728 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll
+ 2008-08-06 15:49:44 483,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\5f49138e9421ea25db46ca4ed4b88337\UIAutomationClient.ni.dll
+ 2008-09-11 15:33:07 483,328 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\c2e5aa36c753a605bdefb97ab83e8806\UIAutomationClient.ni.dll
+ 2008-08-06 15:49:49 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\7b3705542d3e9d844e2548318b4154de\UIAutomationClientsideProviders.ni.dll
+ 2008-09-11 15:33:09 1,118,208 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\ae395b4b568f0d71fec35e3902a46a99\UIAutomationClientsideProviders.ni.dll
+ 2008-08-06 15:36:05 50,688 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\4281d4028d407c149249fcb8f4c5e3ed\UIAutomationProvider.ni.dll
+ 2008-09-11 15:27:10 50,688 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\9e249f5c0ef3e391c5aec1f9da805519\UIAutomationProvider.ni.dll
+ 2008-09-11 15:27:11 196,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\46e3ec015dd7b25d5ddc185534458122\UIAutomationTypes.ni.dll
+ 2008-08-06 15:36:05 196,608 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\8d337259cd6341dd0c6604008320733a\UIAutomationTypes.ni.dll
+ 2008-09-11 15:26:54 3,395,584 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\0703021437c2ec71213a6b701771be86\WindowsBase.ni.dll
+ 2008-08-06 15:35:10 3,272,704 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\ebac3191ed25ac642d2d7100a40530da\WindowsBase.ni.dll
+ 2008-08-06 15:49:58 274,432 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\8254771659c96404746d3103a2b934be\WindowsFormsIntegration.ni.dll
+ 2008-09-11 15:33:12 270,336 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b7c202147607f93463ead99e743c78b9\WindowsFormsIntegration.ni.dll
+ 2008-09-11 15:32:29 380,928 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\13f498f606b7cb97c086eea149b8c872\WsatConfig.ni.exe
+ 2008-08-06 15:34:53 380,928 -c--a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\74d81b9484635f801be67c0b9680254b\WsatConfig.ni.exe
+ 2008-07-14 00:32:34 1,855,488 -c--a-w c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_9b2c904d\System.dll
+ 2008-07-14 00:39:50 258,048 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\BDATunePIA\6.0.3000.0__31bf3856ad364e35_0c06c066\BDATunePIA.dll
+ 2008-07-14 00:39:13 159,744 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehCIR\6.0.3000.0__31bf3856ad364e35_ec9fd77f\ehCIR.dll
+ 2008-07-14 00:39:47 2,326,528 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\EhCM\6.0.3000.0__31bf3856ad364e35_f0ff3687\EhCM.dll
+ 2008-07-14 00:39:49 299,008 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehcommon\6.0.3000.0__31bf3856ad364e35_c90aafd6\ehcommon.dll
+ 2008-07-14 00:39:39 1,306,624 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehepg\6.0.3000.0__31bf3856ad364e35_bd8f3664\ehepg.dll
+ 2008-07-14 00:39:22 167,936 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehepgdat\6.0.3000.0__31bf3856ad364e35_1ca833c8\ehepgdat.dll
+ 2008-07-14 00:40:18 167,936 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehExtCOM\6.0.3000.0__31bf3856ad364e35_45509c73\ehExtCOM.dll
+ 2008-07-14 00:40:41 155,648 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehExtHost\6.0.3000.0__31bf3856ad364e35_0e3517d1\ehExtHost.exe
+ 2008-07-14 00:39:06 10,752 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiExtCOM\6.0.3000.0__31bf3856ad364e35_d7f5b581\ehiExtCOM.dll
+ 2008-07-14 00:39:07 102,400 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiExtens\6.0.3000.0__31bf3856ad364e35_0ae249af\ehiExtens.dll
+ 2008-07-14 00:39:33 266,240 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiMsgr\6.0.3000.0__31bf3856ad364e35_f497e71d\ehiMsgr.dll
+ 2008-07-14 00:39:25 380,928 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiPlay\6.0.3000.0__31bf3856ad364e35_37939819\ehiPlay.dll
+ 2008-07-14 00:39:28 565,248 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiProxy\6.0.3000.0__31bf3856ad364e35_bff8b29d\ehiProxy.dll
+ 2008-07-14 00:39:29 40,960 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiUserXp\6.0.3000.0__31bf3856ad364e35_7ea28c0d\ehiUserXp.dll
+ 2008-07-14 00:39:31 458,752 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiVidCtl\6.0.3000.0__31bf3856ad364e35_41728c4a\ehiVidCtl.dll
+ 2008-07-14 00:39:05 180,224 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiwmp\6.0.3000.0__31bf3856ad364e35_8a1592ca\ehiwmp.dll
+ 2008-07-14 00:39:51 69,632 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehiWUapi\6.0.3000.0__31bf3856ad364e35_3fb292ce\ehiWUapi.dll
+ 2008-07-14 00:39:11 684,032 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehRecObj\6.0.3000.0__31bf3856ad364e35_417cfdb5\ehRecObj.dll
+ 2008-07-14 00:40:49 6,336,512 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\ehshell\6.0.3000.0__31bf3856ad364e35_842d3c99\ehshell.exe
+ 2008-07-14 00:39:54 65,536 ----a-w c:\windows\assembly\NativeImages1_v1.1.4322\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35_d32d0e7f\Microsoft.MediaCenter.dll
+ 2008-07-14 00:40:10 20,480 -c--a-w c:\windows\assembly\NativeImages1_v1.1.4322\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0_78cc1837\SonicMCEBurnEngine.dll
+ 2003-11-16 04:28:28 129,024 ----a-w c:\windows\Downloaded Program Files\GSM_codec.dll
+ 2007-01-25 01:24:24 299,432 ----a-w c:\windows\Downloaded Program Files\StProxy.dll
- 2008-06-13 13:10:50 272,128 ------w c:\windows\Driver Cache\i386\bthport.sys
+ 2008-06-13 11:05:51 272,128 -c----w c:\windows\Driver Cache\i386\bthport.sys
- 2006-05-05 09:41:45 453,120 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
- 2007-02-28 09:08:48 2,136,064 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 10:09:26 2,145,280 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2007-02-28 08:38:55 2,057,600 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2007-02-28 08:38:57 2,015,744 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:33:16 2,023,936 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2007-02-28 09:10:57 2,180,352 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2005-10-21 00:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
- 2007-06-13 10:23:07 1,033,216 ----a-w c:\windows\explorer.exe
+ 2008-04-14 00:12:19 1,033,728 ----a-w c:\windows\explorer.exe
+ 2008-12-29 14:57:49 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-18 02:13:02 811,008 ----a-w c:\windows\gmer.exe
- 2004-08-10 19:00:00 34,816 ----a-w c:\windows\Help\sniffpol.dll
+ 2008-04-14 00:12:06 34,816 -c--a-w c:\windows\Help\sniffpol.dll
- 2004-08-10 19:00:00 33,280 ----a-w c:\windows\Help\sstub.dll
+ 2008-04-14 00:12:07 33,280 -c--a-w c:\windows\Help\sstub.dll
- 2004-08-10 19:00:00 279,040 ----a-w c:\windows\Help\tshoot.dll
+ 2008-04-14 00:12:07 279,040 -c--a-w c:\windows\Help\tshoot.dll
- 2005-05-26 23:22:01 10,752 ----a-w c:\windows\hh.exe
+ 2008-04-14 00:12:21 10,752 ----a-w c:\windows\hh.exe
+ 2008-04-23 04:16:28 124,928 -c----w c:\windows\ie7updates\KB953838-IE7\advpack.dll
+ 2008-04-23 04:16:28 347,136 -c----w c:\windows\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2008-04-23 04:16:28 214,528 -c----w c:\windows\ie7updates\KB953838-IE7\dxtrans.dll
+ 2008-04-23 04:16:28 133,120 -c----w c:\windows\ie7updates\KB953838-IE7\extmgr.dll
+ 2008-04-23 04:16:28 63,488 -c----w c:\windows\ie7updates\KB953838-IE7\icardie.dll
+ 2008-04-22 07:39:58 70,656 -c----w c:\windows\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2008-04-23 04:16:28 153,088 -c----w c:\windows\ie7updates\KB953838-IE7\ieakeng.dll
+ 2008-04-23 04:16:28 230,400 -c----w c:\windows\ie7updates\KB953838-IE7\ieaksie.dll
+ 2008-04-20 05:07:51 161,792 -c----w c:\windows\ie7updates\KB953838-IE7\ieakui.dll
+ 2008-04-23 04:16:28 383,488 -c----w c:\windows\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2008-04-23 04:16:28 384,512 -c----w c:\windows\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2008-04-23 04:16:28 6,066,176 -c----w c:\windows\ie7updates\KB953838-IE7\ieframe.dll
 
Back
Top