- 2004-08-19 13:42:28 171,008 ----a-w c:\windows\system32\srsvc.dll
+ 2008-04-14 02:18:44 171,520 ----a-w c:\windows\system32\srsvc.dll
- 2004-12-07 19:34:00 96,768 ----a-w c:\windows\system32\srvsvc.dll
+ 2008-04-14 02:18:44 96,768 ----a-w c:\windows\system32\srvsvc.dll
- 2004-08-19 13:43:24 708,608 ----a-w c:\windows\system32\ss3dfo.scr
+ 2008-04-14 02:19:18 708,608 ----a-w c:\windows\system32\ss3dfo.scr
- 2004-08-19 13:43:24 19,968 ----a-w c:\windows\system32\ssbezier.scr
+ 2008-04-14 02:19:18 19,968 ----a-w c:\windows\system32\ssbezier.scr
- 2004-08-19 13:42:28 34,816 ----a-w c:\windows\system32\ssdpapi.dll
+ 2008-04-14 02:18:44 34,816 ----a-w c:\windows\system32\ssdpapi.dll
- 2004-08-19 13:42:28 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
+ 2008-04-14 02:18:44 71,680 ----a-w c:\windows\system32\ssdpsrv.dll
- 2004-08-19 13:43:26 393,216 ----a-w c:\windows\system32\ssflwbox.scr
+ 2008-04-14 02:19:19 393,216 ----a-w c:\windows\system32\ssflwbox.scr
- 2004-08-19 13:43:26 20,992 ----a-w c:\windows\system32\ssmarque.scr
+ 2008-04-14 02:19:19 20,992 ----a-w c:\windows\system32\ssmarque.scr
- 2004-08-19 13:43:26 47,616 ----a-w c:\windows\system32\ssmypics.scr
+ 2008-04-14 02:19:19 47,616 ----a-w c:\windows\system32\ssmypics.scr
- 2004-08-19 13:43:26 18,944 ----a-w c:\windows\system32\ssmyst.scr
+ 2008-04-14 02:19:19 18,944 ----a-w c:\windows\system32\ssmyst.scr
- 2004-08-19 13:43:26 610,304 ----a-w c:\windows\system32\sspipes.scr
+ 2008-04-14 02:19:19 610,304 ----a-w c:\windows\system32\sspipes.scr
- 2004-08-19 13:43:26 14,848 ----a-w c:\windows\system32\ssstars.scr
+ 2008-04-14 02:19:19 14,848 ----a-w c:\windows\system32\ssstars.scr
- 2004-08-19 13:43:26 684,032 ----a-w c:\windows\system32\sstext3d.scr
+ 2008-04-14 02:19:19 684,032 ----a-w c:\windows\system32\sstext3d.scr
- 2002-09-10 12:00:00 54,272 ----a-w c:\windows\system32\stclient.dll
+ 2008-04-14 02:18:44 59,392 ----a-w c:\windows\system32\stclient.dll
- 2004-08-19 13:42:28 68,096 ----a-w c:\windows\system32\sti.dll
+ 2008-04-14 02:18:44 68,608 ----a-w c:\windows\system32\sti.dll
- 2004-08-19 13:42:28 137,728 ----a-w c:\windows\system32\sti_ci.dll
+ 2008-04-14 02:18:44 137,728 ----a-w c:\windows\system32\sti_ci.dll
- 2004-08-19 13:43:12 14,848 ----a-w c:\windows\system32\stimon.exe
+ 2008-04-14 02:19:12 14,848 ----a-w c:\windows\system32\stimon.exe
- 2004-08-19 13:42:28 122,368 ----a-w c:\windows\system32\stobject.dll
+ 2008-04-14 02:18:44 122,368 ----a-w c:\windows\system32\stobject.dll
- 2004-08-19 14:42:28 76,288 ----a-w c:\windows\system32\storprop.dll
+ 2008-04-14 02:18:44 76,288 ----a-w c:\windows\system32\storprop.dll
- 2006-08-24 17:19:40 246,814 ----a-w c:\windows\system32\strmdll.dll
+ 2008-04-14 02:18:44 246,814 ----a-w c:\windows\system32\strmdll.dll
- 2004-08-19 13:42:28 75,776 ----a-w c:\windows\system32\strmfilt.dll
+ 2008-04-14 02:18:44 75,776 ----a-w c:\windows\system32\strmfilt.dll
- 2004-08-19 13:43:12 14,336 ----a-w c:\windows\system32\svchost.exe
+ 2008-04-14 02:19:12 14,336 ----a-w c:\windows\system32\svchost.exe
- 2006-10-20 01:38:50 716,288 ----a-w c:\windows\system32\sxs.dll
+ 2008-04-14 02:18:44 715,776 ----a-w c:\windows\system32\sxs.dll
- 2004-08-19 13:42:28 57,856 ----a-w c:\windows\system32\synceng.dll
+ 2008-04-14 02:18:44 57,856 ----a-w c:\windows\system32\synceng.dll
- 2004-08-19 13:42:28 195,072 ----a-w c:\windows\system32\syncui.dll
+ 2008-04-14 02:18:44 195,072 ----a-w c:\windows\system32\syncui.dll
- 2004-08-19 13:43:12 107,520 ----a-w c:\windows\system32\sysocmgr.exe
+ 2008-04-14 02:19:13 107,520 ----a-w c:\windows\system32\sysocmgr.exe
- 2004-08-19 13:42:28 1,001,472 ----a-w c:\windows\system32\syssetup.dll
+ 2008-04-14 02:18:44 1,009,664 ----a-w c:\windows\system32\syssetup.dll
- 2002-09-10 12:00:00 70,144 ----a-w c:\windows\system32\systeminfo.exe
+ 2008-04-14 02:19:12 73,728 ----a-w c:\windows\system32\systeminfo.exe
- 2005-10-17 21:21:06 118,272 ----a-w c:\windows\system32\t2embed.dll
+ 2008-04-14 02:18:44 117,760 ----a-w c:\windows\system32\t2embed.dll
- 2004-08-19 13:42:28 860,160 ----a-w c:\windows\system32\tapi3.dll
+ 2008-04-14 02:18:44 860,160 ----a-w c:\windows\system32\tapi3.dll
- 2004-08-19 13:42:28 181,760 ----a-w c:\windows\system32\tapi32.dll
+ 2008-04-14 02:18:44 181,760 ----a-w c:\windows\system32\tapi32.dll
- 2005-07-08 16:29:01 249,344 ----a-w c:\windows\system32\tapisrv.dll
+ 2008-04-14 02:18:44 249,856 ----a-w c:\windows\system32\tapisrv.dll
- 2002-09-10 12:00:00 74,752 ----a-w c:\windows\system32\taskkill.exe
+ 2008-04-14 02:19:13 78,848 ----a-w c:\windows\system32\taskkill.exe
- 2002-09-10 12:00:00 74,240 ----a-w c:\windows\system32\tasklist.exe
+ 2008-04-14 02:19:13 79,872 ----a-w c:\windows\system32\tasklist.exe
- 2004-08-19 13:43:14 141,312 ----a-w c:\windows\system32\taskmgr.exe
+ 2008-04-14 02:19:13 141,312 ----a-w c:\windows\system32\taskmgr.exe
- 2004-08-19 13:42:28 14,848 ----a-w c:\windows\system32\tcpmib.dll
+ 2008-04-14 02:18:44 14,848 ----a-w c:\windows\system32\tcpmib.dll
- 2004-08-19 13:42:28 46,592 ----a-w c:\windows\system32\tcpmon.dll
+ 2008-04-14 02:18:44 46,592 ----a-w c:\windows\system32\tcpmon.dll
- 2004-08-19 13:42:28 46,592 ----a-w c:\windows\system32\tcpmonui.dll
+ 2008-04-14 02:18:44 46,592 ----a-w c:\windows\system32\tcpmonui.dll
- 2005-05-11 02:30:02 77,824 ----a-w c:\windows\system32\telnet.exe
+ 2008-04-14 02:19:13 77,824 ----a-w c:\windows\system32\telnet.exe
- 2004-08-19 13:42:28 358,912 ----a-w c:\windows\system32\termmgr.dll
+ 2008-04-14 02:18:44 358,912 ----a-w c:\windows\system32\termmgr.dll
- 2004-08-19 13:42:28 296,960 ----a-w c:\windows\system32\termsrv.dll
+ 2008-04-14 02:18:44 296,960 ----a-w c:\windows\system32\termsrv.dll
- 2004-08-19 13:42:28 390,656 ----a-w c:\windows\system32\themeui.dll
+ 2008-04-14 02:18:44 390,656 ----a-w c:\windows\system32\themeui.dll
- 2004-08-19 13:43:14 63,488 ----a-w c:\windows\system32\tlntadmn.exe
+ 2008-04-14 02:19:13 63,488 ----a-w c:\windows\system32\tlntadmn.exe
- 2004-08-19 13:43:14 79,360 ----a-w c:\windows\system32\tlntsess.exe
+ 2008-04-14 02:19:13 79,360 ----a-w c:\windows\system32\tlntsess.exe
- 2004-08-19 13:43:14 74,240 ----a-w c:\windows\system32\tlntsvr.exe
+ 2008-04-14 02:19:13 74,240 ----a-w c:\windows\system32\tlntsvr.exe
- 2004-08-19 13:42:28 7,168 ----a-w c:\windows\system32\tlntsvrp.dll
+ 2008-04-14 02:18:44 7,168 ----a-w c:\windows\system32\tlntsvrp.dll
- 2004-08-19 13:43:14 347,136 ----a-w c:\windows\system32\tourstart.exe
+ 2008-04-14 02:19:13 347,136 ----a-w c:\windows\system32\tourstart.exe
- 2004-08-19 13:43:14 260,608 ----a-w c:\windows\system32\tracerpt.exe
+ 2008-04-14 02:19:13 260,608 ----a-w c:\windows\system32\tracerpt.exe
- 2004-08-19 13:43:14 13,312 ----a-w c:\windows\system32\tracert.exe
+ 2008-04-14 02:19:14 13,312 ----a-w c:\windows\system32\tracert.exe
- 2002-09-10 12:00:00 11,264 ----a-w c:\windows\system32\tree.com
+ 2008-04-14 02:19:18 12,800 ----a-w c:\windows\system32\tree.com
- 2004-08-19 13:42:28 90,624 ----a-w c:\windows\system32\trkwks.dll
+ 2008-04-14 02:18:44 90,112 ----a-w c:\windows\system32\trkwks.dll
- 2004-08-19 13:42:28 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
+ 2008-04-14 02:18:44 93,696 ----a-w c:\windows\system32\tscfgwmi.dll
- 2004-08-19 13:43:38 12,168 ----a-w c:\windows\system32\tsddd.dll
+ 2008-04-14 02:19:43 12,168 ----a-w c:\windows\system32\tsddd.dll
+ 2008-04-14 02:18:44 53,248 ------w c:\windows\system32\tsgqec.dll
+ 2008-04-14 02:18:45 50,688 ------w c:\windows\system32\tspkg.dll
- 2004-08-19 13:42:28 44,032 ----a-w c:\windows\system32\twext.dll
+ 2008-04-14 02:18:45 57,856 ----a-w c:\windows\system32\twext.dll
- 2005-07-26 04:40:01 101,376 ----a-w c:\windows\system32\txflog.dll
+ 2008-04-14 02:18:45 101,376 ----a-w c:\windows\system32\txflog.dll
- 2008-07-14 11:09:18 62,976 ------w c:\windows\system32\tzchange.exe
+ 2008-04-14 02:19:14 60,416 ------w c:\windows\system32\tzchange.exe
- 2004-08-19 13:42:28 25,600 ----a-w c:\windows\system32\udhisapi.dll
+ 2008-04-14 02:18:45 26,624 ----a-w c:\windows\system32\udhisapi.dll
- 2004-08-19 13:42:28 310,784 ----a-w c:\windows\system32\ulib.dll
+ 2008-04-14 02:18:45 310,784 ----a-w c:\windows\system32\ulib.dll
- 2004-08-19 13:42:28 36,864 ----a-w c:\windows\system32\umandlg.dll
+ 2008-04-14 02:18:45 36,864 ----a-w c:\windows\system32\umandlg.dll
- 2005-08-23 03:39:10 124,416 ----a-w c:\windows\system32\umpnpmgr.dll
+ 2008-04-14 02:18:45 124,416 ----a-w c:\windows\system32\umpnpmgr.dll
- 2004-08-19 13:42:28 78,848 ----a-w c:\windows\system32\unimdmat.dll
+ 2008-04-14 02:18:45 78,848 ----a-w c:\windows\system32\unimdmat.dll
- 2004-08-19 13:42:28 13,824 ----a-w c:\windows\system32\uniplat.dll
+ 2008-04-14 02:18:45 13,824 ----a-w c:\windows\system32\uniplat.dll
- 2004-08-19 13:42:28 316,416 ----a-w c:\windows\system32\untfs.dll
+ 2008-04-14 02:18:45 316,416 ----a-w c:\windows\system32\untfs.dll
- 2004-08-19 13:42:28 132,608 ----a-w c:\windows\system32\upnp.dll
+ 2008-04-14 02:18:45 133,632 ----a-w c:\windows\system32\upnp.dll
- 2004-08-19 13:43:14 16,896 ----a-w c:\windows\system32\upnpcont.exe
+ 2008-04-14 02:19:14 16,896 ----a-w c:\windows\system32\upnpcont.exe
- 2007-02-05 20:18:39 185,344 ----a-w c:\windows\system32\upnphost.dll
+ 2008-04-14 02:18:45 186,368 ----a-w c:\windows\system32\upnphost.dll
- 2004-08-19 13:42:28 240,128 ----a-w c:\windows\system32\upnpui.dll
+ 2008-04-14 02:18:45 240,128 ----a-w c:\windows\system32\upnpui.dll
- 2004-08-19 13:43:14 18,432 ----a-w c:\windows\system32\ups.exe
+ 2008-04-14 02:19:14 18,432 ----a-w c:\windows\system32\ups.exe
- 2004-08-19 13:42:28 37,888 ----a-w c:\windows\system32\url.dll
+ 2007-08-13 22:44:30 105,984 ----a-w c:\windows\system32\url.dll
- 2008-06-23 15:40:08 616,960 ----a-w c:\windows\system32\urlmon.dll
+ 2007-08-13 22:54:10 1,162,240 ----a-w c:\windows\system32\urlmon.dll
- 2004-08-19 13:42:28 16,896 ----a-w c:\windows\system32\usbmon.dll
+ 2008-04-14 02:18:45 16,896 ----a-w c:\windows\system32\usbmon.dll
- 2004-08-19 14:42:28 77,824 ----a-w c:\windows\system32\usbui.dll
+ 2008-04-14 02:18:45 77,824 ----a-w c:\windows\system32\usbui.dll
- 2007-03-08 15:36:30 578,560 ----a-w c:\windows\system32\user32.dll
+ 2008-04-14 02:18:45 579,584 ----a-w c:\windows\system32\user32.dll
- 2004-08-19 13:42:28 729,600 ----a-w c:\windows\system32\userenv.dll
+ 2008-04-14 02:18:45 733,184 ----a-w c:\windows\system32\userenv.dll
- 2004-08-19 13:43:14 25,088 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-14 02:19:14 26,624 ----a-w c:\windows\system32\userinit.exe
+ 2008-04-13 16:44:16 17,920 ------w c:\windows\system32\usmt\cobramsg.dll
- 2004-08-19 13:42:10 124,928 ----a-w c:\windows\system32\usmt\guitrn.dll
+ 2008-04-14 02:18:21 134,144 ----a-w c:\windows\system32\usmt\guitrn.dll
+ 2008-04-14 02:18:21 115,712 ------w c:\windows\system32\usmt\guitrna.dll
- 2004-08-19 13:42:10 4,096 ----a-w c:\windows\system32\usmt\iconlib.dll
+ 2008-04-13 16:44:29 2,560 ----a-w c:\windows\system32\usmt\iconlib.dll
- 2004-08-19 13:42:14 19,968 ----a-w c:\windows\system32\usmt\log.dll
+ 2008-04-14 02:18:24 19,968 ----a-w c:\windows\system32\usmt\log.dll
- 2004-08-19 13:42:14 201,216 ----a-w c:\windows\system32\usmt\migism.dll
+ 2008-04-14 02:18:24 274,432 ----a-w c:\windows\system32\usmt\migism.dll
+ 2008-04-14 02:18:24 261,120 ------w c:\windows\system32\usmt\migisma.dll
- 2004-08-19 13:42:54 103,936 ----a-w c:\windows\system32\usmt\migload.exe
+ 2008-04-14 02:19:01 104,448 ----a-w c:\windows\system32\usmt\migload.exe
- 2004-08-19 13:42:54 246,272 ----a-w c:\windows\system32\usmt\migwiz.exe
+ 2008-04-14 02:19:02 251,392 ----a-w c:\windows\system32\usmt\migwiz.exe
+ 2008-04-14 02:19:02 247,296 ------w c:\windows\system32\usmt\migwiza.exe
- 2004-08-19 13:42:24 204,288 ----a-w c:\windows\system32\usmt\script.dll
+ 2008-04-14 02:18:35 217,088 ----a-w c:\windows\system32\usmt\script.dll
+ 2008-04-14 02:18:35 200,704 ------w c:\windows\system32\usmt\scripta.dll
- 2004-08-19 13:42:28 169,472 ----a-w c:\windows\system32\usmt\sysmod.dll
+ 2008-04-14 02:18:44 193,536 ----a-w c:\windows\system32\usmt\sysmod.dll
+ 2008-04-14 02:18:44 173,568 ------w c:\windows\system32\usmt\sysmoda.dll
- 2004-08-19 13:42:28 406,528 ----a-w c:\windows\system32\usp10.dll
+ 2008-04-14 02:18:45 406,016 ----a-w c:\windows\system32\usp10.dll
- 2004-08-19 13:43:14 50,176 ----a-w c:\windows\system32\utilman.exe
+ 2008-04-14 02:19:14 50,176 ----a-w c:\windows\system32\utilman.exe
- 2004-08-19 13:42:28 220,160 ----a-w c:\windows\system32\uxtheme.dll
+ 2008-04-14 02:18:45 220,160 ----a-w c:\windows\system32\uxtheme.dll
- 2004-08-19 13:42:28 30,749 ----a-w c:\windows\system32\vbajet32.dll
+ 2008-04-14 02:18:45 30,749 ----a-w c:\windows\system32\vbajet32.dll
- 2007-12-18 14:42:03 417,792 ----a-w c:\windows\system32\vbscript.dll
+ 2008-04-14 02:18:45 434,176 ----a-w c:\windows\system32\vbscript.dll
- 2004-08-19 13:42:28 26,112 ----a-w c:\windows\system32\vdmdbg.dll
+ 2008-04-14 02:18:45 26,112 ----a-w c:\windows\system32\vdmdbg.dll
- 2004-08-19 13:42:28 51,712 ----a-w c:\windows\system32\vdmredir.dll
+ 2008-04-14 02:18:45 51,712 ----a-w c:\windows\system32\vdmredir.dll
- 2006-03-17 00:38:01 28,672 ------w c:\windows\system32\verclsid.exe
+ 2008-04-14 02:19:14 28,672 ------w c:\windows\system32\verclsid.exe
- 2002-09-10 12:00:00 13,312 ----a-w c:\windows\system32\verifier.dll
+ 2008-04-14 02:18:45 26,624 ----a-w c:\windows\system32\verifier.dll
- 2004-08-19 13:42:28 18,944 ----a-w c:\windows\system32\version.dll
+ 2008-04-14 02:18:45 18,944 ----a-w c:\windows\system32\version.dll
- 2004-08-19 13:42:28 430,592 ----a-w c:\windows\system32\vssapi.dll
+ 2008-04-14 02:18:45 430,592 ----a-w c:\windows\system32\vssapi.dll
- 2004-08-19 13:43:14 293,888 ----a-w c:\windows\system32\vssvc.exe
+ 2008-04-14 02:19:14 293,888 ----a-w c:\windows\system32\vssvc.exe
- 2004-08-19 13:42:28 176,640 ----a-w c:\windows\system32\w32time.dll
+ 2008-04-14 02:18:45 177,152 ----a-w c:\windows\system32\w32time.dll
- 2004-08-19 13:42:28 15,872 ----a-w c:\windows\system32\w3ssl.dll
+ 2008-04-14 02:18:45 15,872 ----a-w c:\windows\system32\w3ssl.dll
- 2004-08-03 21:07:34 17,664 ----a-w c:\windows\system32\watchdog.sys
+ 2008-04-13 18:44:59 17,664 ----a-w c:\windows\system32\watchdog.sys
- 2002-09-10 12:00:00 208,896 ----a-w c:\windows\system32\wavemsp.dll
+ 2008-04-14 02:18:45 215,552 ----a-w c:\windows\system32\wavemsp.dll
- 2004-08-19 13:41:52 1,352,704 ----a-w c:\windows\system32\wbem\cimwin32.dll
+ 2008-04-14 02:18:20 1,359,360 ----a-w c:\windows\system32\wbem\cimwin32.dll
- 2004-08-19 13:42:08 45,568 ----a-w c:\windows\system32\wbem\CmdEvTgProv.dll
+ 2008-04-14 02:18:21 45,056 ----a-w c:\windows\system32\wbem\cmdevtgprov.dll
- 2004-08-19 13:42:08 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
+ 2008-04-14 02:18:21 247,808 ----a-w c:\windows\system32\wbem\esscli.dll
- 2004-08-19 13:42:08 22,016 ----a-w c:\windows\system32\wbem\evntrprv.dll
+ 2008-04-14 02:18:21 21,504 ----a-w c:\windows\system32\wbem\evntrprv.dll
- 2004-08-19 13:42:08 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
+ 2008-04-14 02:18:21 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll
- 2004-08-19 13:42:08 185,856 ----a-w c:\windows\system32\wbem\framedyn.dll
+ 2008-04-14 02:18:21 185,344 ----a-w c:\windows\system32\wbem\framedyn.dll
- 2004-08-19 13:42:14 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll
+ 2008-04-14 02:18:24 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll
- 2004-08-19 13:42:56 17,408 ----a-w c:\windows\system32\wbem\mofcomp.exe
+ 2008-04-14 02:19:03 17,408 ----a-w c:\windows\system32\wbem\mofcomp.exe
- 2004-08-19 13:42:16 124,928 ----a-w c:\windows\system32\wbem\mofd.dll
+ 2008-04-14 02:18:24 124,928 ----a-w c:\windows\system32\wbem\mofd.dll
- 2004-08-19 13:42:20 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
+ 2008-04-14 02:18:28 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll
- 2004-08-19 13:42:20 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll
+ 2008-04-14 02:18:28 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll
- 2004-08-19 13:42:22 92,672 ----a-w c:\windows\system32\wbem\policman.dll
+ 2008-04-14 02:18:33 92,672 ----a-w c:\windows\system32\wbem\policman.dll
- 2004-08-19 13:42:22 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll
+ 2008-04-14 02:18:33 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll
- 2004-08-19 13:42:22 177,152 ----a-w c:\windows\system32\wbem\repdrvfs.dll
+ 2008-04-14 02:18:34 178,176 ----a-w c:\windows\system32\wbem\repdrvfs.dll
- 2004-08-19 13:43:08 36,864 ----a-w c:\windows\system32\wbem\scrcons.exe
+ 2008-04-14 02:19:10 36,352 ----a-w c:\windows\system32\wbem\scrcons.exe
- 2004-08-19 13:42:28 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll
+ 2008-04-14 02:18:44 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll
- 2004-08-19 13:42:28 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
+ 2008-04-14 02:18:45 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
- 2004-08-19 13:42:30 200,192 ----a-w c:\windows\system32\wbem\wbemcntl.dll
+ 2008-04-14 02:18:45 200,192 ----a-w c:\windows\system32\wbem\wbemcntl.dll
- 2004-08-19 13:42:30 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
+ 2008-04-14 02:18:45 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
- 2004-08-19 13:42:30 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
+ 2008-04-14 02:18:46 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
- 2004-08-19 13:42:30 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll
+ 2008-04-14 02:18:46 531,968 ----a-w c:\windows\system32\wbem\wbemcore.dll
- 2004-08-19 13:42:30 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
+ 2008-04-14 02:18:46 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
- 2004-08-19 13:42:30 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
+ 2008-04-14 02:18:46 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
- 2004-08-19 13:42:30 44,032 ----a-w c:\windows\system32\wbem\wbemperf.dll
+ 2008-04-14 02:18:46 44,032 ----a-w c:\windows\system32\wbem\wbemperf.dll
- 2004-08-19 13:42:30 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
+ 2008-04-14 02:18:46 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
- 2004-08-19 13:42:30 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
+ 2008-04-14 02:18:46 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
- 2004-08-19 13:43:16 119,296 ----a-w c:\windows\system32\wbem\wbemtest.exe
+ 2008-04-14 02:19:15 119,296 ----a-w c:\windows\system32\wbem\wbemtest.exe
- 2004-08-19 13:42:30 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
+ 2008-04-14 02:18:46 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
- 2004-08-19 13:43:16 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
+ 2008-04-14 02:19:16 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
- 2004-08-19 13:41:16 7,680 ----a-w c:\windows\system32\wbem\wmiapres.dll
+ 2008-04-14 01:53:21 7,680 ----a-w c:\windows\system32\wbem\wmiapres.dll
- 2004-08-19 13:42:32 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
+ 2008-04-14 02:18:46 88,576 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
- 2004-08-19 13:43:18 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
+ 2008-04-14 02:19:16 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
- 2004-08-19 13:43:18 366,592 ----a-w c:\windows\system32\wbem\wmic.exe
+ 2008-04-14 02:19:16 366,592 ----a-w c:\windows\system32\wbem\wmic.exe
- 2004-08-19 13:42:32 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
+ 2008-04-14 02:18:46 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
- 2004-08-19 13:42:32 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
+ 2008-04-14 02:18:46 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
- 2004-08-19 13:42:32 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
+ 2008-04-14 02:18:46 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
- 2004-08-19 13:42:32 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
+ 2008-04-14 02:18:46 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
- 2004-08-19 13:42:32 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll
+ 2008-04-14 02:18:46 61,952 ----a-w c:\windows\system32\wbem\wmipiprt.dll
- 2004-08-19 13:42:32 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll
+ 2008-04-14 02:18:46 62,464 ----a-w c:\windows\system32\wbem\wmipjobj.dll
- 2004-08-19 13:42:32 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
+ 2008-04-14 02:18:46 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
- 2004-08-19 13:42:32 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
+ 2008-04-14 02:18:47 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
- 2004-08-19 13:43:18 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
+ 2008-04-14 02:19:16 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
- 2004-08-19 13:42:32 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
+ 2008-04-14 02:18:47 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
- 2004-08-19 13:42:32 145,408 ----a-w c:\windows\system32\wbem\wmisvc.dll
+ 2008-04-14 02:18:47 145,408 ----a-w c:\windows\system32\wbem\wmisvc.dll
- 2004-08-19 13:42:32 98,816 ----a-w c:\windows\system32\wbem\wmiutils.dll
+ 2008-04-14 02:18:47 98,816 ----a-w c:\windows\system32\wbem\wmiutils.dll
- 2004-08-19 13:42:30 49,152 ----a-w c:\windows\system32\wdigest.dll
+ 2008-04-14 02:18:46 49,152 ----a-w c:\windows\system32\wdigest.dll
- 2004-08-19 20:43:26 23,552 ----a-w c:\windows\system32\wdmaud.drv
+ 2008-04-14 02:19:19 23,552 ----a-w c:\windows\system32\wdmaud.drv
- 2004-08-19 13:42:30 280,576 ----a-w c:\windows\system32\webcheck.dll
+ 2007-08-13 22:54:10 231,424 ----a-w c:\windows\system32\webcheck.dll
- 2006-01-04 03:35:09 68,096 ----a-w c:\windows\system32\webclnt.dll
+ 2008-04-14 02:18:46 68,096 ----a-w c:\windows\system32\webclnt.dll
- 2004-08-19 13:42:30 136,192 ----a-w c:\windows\system32\webvw.dll
+ 2008-04-14 02:18:46 136,192 ----a-w c:\windows\system32\webvw.dll
- 2004-08-19 13:43:16 66,560 ----a-w c:\windows\system32\wextract.exe
+ 2008-04-14 02:19:15 66,560 ----a-w c:\windows\system32\wextract.exe
- 2004-08-19 13:43:16 435,200 ----a-w c:\windows\system32\wiaacmgr.exe
+ 2008-04-14 02:19:15 435,200 ----a-w c:\windows\system32\wiaacmgr.exe
- 2004-08-19 13:42:30 461,312 ----a-w c:\windows\system32\wiadefui.dll
+ 2008-04-14 02:18:46 461,312 ----a-w c:\windows\system32\wiadefui.dll
- 2004-08-19 13:42:30 124,928 ----a-w c:\windows\system32\wiadss.dll
+ 2008-04-14 02:18:46 124,928 ----a-w c:\windows\system32\wiadss.dll
- 2004-08-19 13:42:30 75,776 ----a-w c:\windows\system32\wiascr.dll
+ 2008-04-14 02:18:46 75,776 ----a-w c:\windows\system32\wiascr.dll
- 2006-12-19 18:17:15 334,336 ----a-w c:\windows\system32\wiaservc.dll
+ 2008-04-14 02:18:46 334,336 ----a-w c:\windows\system32\wiaservc.dll
- 2004-08-19 13:42:30 592,384 ----a-w c:\windows\system32\wiashext.dll
+ 2008-04-14 02:18:46 592,384 ----a-w c:\windows\system32\wiashext.dll
- 2004-08-19 13:42:30 111,104 ----a-w c:\windows\system32\wiavideo.dll
+ 2008-04-14 02:18:46 111,104 ----a-w c:\windows\system32\wiavideo.dll
- 2008-03-20 08:09:25 1,845,376 ----a-w c:\windows\system32\win32k.sys
+ 2008-04-14 01:52:22 1,845,760 ----a-w c:\windows\system32\win32k.sys
- 2004-08-19 13:42:30 102,400 ----a-w c:\windows\system32\win32spl.dll
+ 2008-04-14 02:18:46 102,912 ----a-w c:\windows\system32\win32spl.dll
- 2004-08-19 13:41:10 937,984 ----a-w c:\windows\system32\winbrand.dll
+ 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll
+ 2008-04-14 02:18:46 712,704 ------w c:\windows\system32\windowscodecs.dll
+ 2008-04-14 02:18:46 346,112 ------w c:\windows\system32\windowscodecsext.dll
+ 2007-08-13 22:45:16 206,336 ------w c:\windows\system32\WinFXDocObj.exe
- 2004-08-19 13:42:32 351,232 ----a-w c:\windows\system32\winhttp.dll
+ 2008-04-14 02:18:46 354,304 ----a-w c:\windows\system32\winhttp.dll
- 2008-06-23 15:40:09 662,016 ----a-w c:\windows\system32\wininet.dll
+ 2007-08-13 22:54:10 818,688 ----a-w c:\windows\system32\wininet.dll
- 2004-08-19 13:42:32 32,768 ----a-w c:\windows\system32\winipsec.dll
+ 2008-04-14 02:18:46 32,256 ----a-w c:\windows\system32\winipsec.dll
- 2004-08-19 13:43:16 505,344 ----a-w c:\windows\system32\winlogon.exe
+ 2008-04-14 02:19:15 510,976 ----a-w c:\windows\system32\winlogon.exe
- 2004-08-19 13:42:32 180,224 ----a-w c:\windows\system32\winmm.dll
+ 2008-04-14 02:18:46 180,224 ----a-w c:\windows\system32\winmm.dll
- 2004-08-19 13:41:14 774,144 ----a-w c:\windows\system32\winntbbu.dll
+ 2008-04-14 02:17:52 763,904 ----a-w c:\windows\system32\winntbbu.dll
- 2004-08-19 13:42:32 16,896 ----a-w c:\windows\system32\winrnr.dll
+ 2008-04-14 02:18:46 16,896 ----a-w c:\windows\system32\winrnr.dll
- 2004-08-19 13:42:32 100,352 ----a-w c:\windows\system32\winscard.dll
+ 2008-04-14 02:18:46 100,352 ----a-w c:\windows\system32\winscard.dll
- 2004-08-19 13:42:32 17,408 ----a-w c:\windows\system32\winshfhc.dll
+ 2008-04-14 02:18:46 17,408 ----a-w c:\windows\system32\winshfhc.dll
- 2004-08-19 13:43:26 146,944 ----a-w c:\windows\system32\winspool.drv
+ 2008-04-14 02:19:19 146,944 ----a-w c:\windows\system32\winspool.drv
- 2007-03-17 13:45:06 293,376 ----a-w c:\windows\system32\winsrv.dll
+ 2008-04-14 02:18:46 293,888 ----a-w c:\windows\system32\winsrv.dll
- 2004-08-19 13:42:32 53,760 ----a-w c:\windows\system32\winsta.dll
+ 2008-04-14 02:18:46 53,760 ----a-w c:\windows\system32\winsta.dll
- 2004-08-19 13:42:32 176,640 ----a-w c:\windows\system32\wintrust.dll
+ 2008-04-14 02:18:46 176,640 ----a-w c:\windows\system32\wintrust.dll
- 2004-08-19 13:43:16 5,632 ----a-w c:\windows\system32\winver.exe
+ 2008-04-14 02:19:16 5,632 ----a-w c:\windows\system32\winver.exe
- 2006-08-17 12:29:42 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2008-04-14 02:18:46 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2008-04-14 02:18:46 69,120 ------w c:\windows\system32\wlanapi.dll
- 2004-08-19 13:42:32 172,544 ----a-w c:\windows\system32\wldap32.dll
+ 2008-04-14 02:18:46 172,544 ----a-w c:\windows\system32\wldap32.dll
- 2004-08-19 13:42:32 93,696 ----a-w c:\windows\system32\wlnotify.dll
+ 2008-04-14 02:18:46 93,696 ----a-w c:\windows\system32\wlnotify.dll
- 2004-08-19 13:41:16 200,704 ----a-w c:\windows\system32\wmerror.dll
+ 2008-04-14 01:53:19 200,704 ----a-w c:\windows\system32\wmerror.dll
- 2004-08-19 13:41:16 5,632 ----a-w c:\windows\system32\wmi.dll
+ 2008-04-14 02:17:54 5,632 ----a-w c:\windows\system32\wmi.dll
- 2007-04-30 06:22:16 4,734,976 ----a-w c:\windows\system32\wmp.dll
+ 2008-04-14 02:18:47 4,874,240 ----a-w c:\windows\system32\wmp.dll
- 2004-08-19 13:42:32 114,688 ----a-w c:\windows\system32\wmpasf.dll
+ 2008-04-14 02:18:47 114,688 ----a-w c:\windows\system32\wmpasf.dll
- 2004-08-19 13:42:32 20,480 ----a-w c:\windows\system32\wmpcd.dll
+ 2008-04-14 02:18:47 20,480 ----a-w c:\windows\system32\wmpcd.dll
- 2004-08-19 13:42:32 20,480 ----a-w c:\windows\system32\wmpcore.dll
+ 2008-04-14 02:18:47 20,480 ----a-w c:\windows\system32\wmpcore.dll
- 2004-08-19 13:42:32 233,472 ----a-w c:\windows\system32\wmpdxm.dll
+ 2008-04-14 02:18:47 233,472 ----a-w c:\windows\system32\wmpdxm.dll
+ 2008-04-14 02:18:47 276,992 ------w c:\windows\system32\wmphoto.dll
- 2004-08-19 13:41:26 2,977,792 ----a-w c:\windows\system32\wmploc.dll
+ 2008-04-14 01:54:40 2,977,792 ----a-w c:\windows\system32\wmploc.dll
- 2004-08-19 13:42:32 102,400 ----a-w c:\windows\system32\wmpshell.dll
+ 2008-04-14 02:18:47 102,400 ----a-w c:\windows\system32\wmpshell.dll
- 2004-08-19 13:42:32 20,480 ----a-w c:\windows\system32\wmpui.dll
+ 2008-04-14 02:18:47 20,480 ----a-w c:\windows\system32\wmpui.dll
- 2004-08-19 13:42:32 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
+ 2008-04-14 02:18:47 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
- 2004-08-19 13:42:32 303,616 ----a-w c:\windows\system32\wmstream.dll
+ 2008-04-14 02:18:47 303,616 ----a-w c:\windows\system32\wmstream.dll
- 2004-08-19 13:42:32 265,216 ----a-w c:\windows\system32\wow32.dll
+ 2008-04-14 02:18:47 265,216 ----a-w c:\windows\system32\wow32.dll
- 2004-08-19 13:43:18 32,256 ----a-w c:\windows\system32\wpabaln.exe
+ 2008-04-14 02:19:17 32,256 ----a-w c:\windows\system32\wpabaln.exe
- 2004-08-19 13:43:18 32,768 ----a-w c:\windows\system32\wpnpinst.exe
+ 2008-04-14 02:19:17 11,776 ----a-w c:\windows\system32\wpnpinst.exe
- 2004-08-19 13:42:32 82,944 ----a-w c:\windows\system32\ws2_32.dll
+ 2008-04-14 02:18:47 82,432 ----a-w c:\windows\system32\ws2_32.dll
- 2004-08-19 13:42:32 19,968 ----a-w c:\windows\system32\ws2help.dll
+ 2008-04-14 02:18:47 19,968 ----a-w c:\windows\system32\ws2help.dll
- 2004-08-19 13:43:18 13,824 ----a-w c:\windows\system32\wscntfy.exe
+ 2008-04-14 02:19:17 13,824 ----a-w c:\windows\system32\wscntfy.exe
- 2004-08-19 13:43:18 114,688 ----a-w c:\windows\system32\wscript.exe
+ 2008-04-14 02:19:17 155,648 ----a-w c:\windows\system32\wscript.exe
- 2004-08-19 13:42:32 81,408 ----a-w c:\windows\system32\wscsvc.dll
+ 2008-04-14 02:18:47 80,896 ----a-w c:\windows\system32\wscsvc.dll
- 2004-08-19 13:42:32 611,328 ----a-w c:\windows\system32\wsecedit.dll
+ 2008-04-14 02:18:47 618,496 ----a-w c:\windows\system32\wsecedit.dll
- 2004-08-19 13:42:32 108,032 ----a-w c:\windows\system32\wshbth.dll
+ 2008-04-14 02:18:47 108,032 ----a-w c:\windows\system32\wshbth.dll
- 2004-08-19 13:42:32 28,672 ----a-w c:\windows\system32\wshcon.dll
+ 2008-04-14 02:18:47 36,864 ----a-w c:\windows\system32\wshcon.dll
- 2004-08-19 13:42:32 65,536 ----a-w c:\windows\system32\wshext.dll
+ 2008-04-14 02:18:47 90,112 ----a-w c:\windows\system32\wshext.dll
- 2004-08-19 13:42:32 14,336 ----a-w c:\windows\system32\wship6.dll
+ 2008-04-14 02:18:47 14,336 ----a-w c:\windows\system32\wship6.dll
- 2004-08-19 13:42:32 11,776 ----a-w c:\windows\system32\WshRm.dll
+ 2008-04-14 02:18:47 11,264 ----a-w c:\windows\system32\wshrm.dll
- 2004-08-19 13:42:32 19,968 ----a-w c:\windows\system32\wshtcpip.dll
+ 2008-04-14 02:18:47 19,456 ----a-w c:\windows\system32\wshtcpip.dll
- 2004-08-19 13:42:32 42,496 ----a-w c:\windows\system32\wsnmp32.dll
+ 2008-04-14 02:18:47 41,984 ----a-w c:\windows\system32\wsnmp32.dll
- 2004-08-19 13:42:32 25,600 ----a-w c:\windows\system32\wsock32.dll
+ 2008-04-14 02:18:47 25,600 ----a-w c:\windows\system32\wsock32.dll
- 2004-08-19 13:42:32 51,200 ----a-w c:\windows\system32\wstdecod.dll
+ 2008-04-14 02:18:47 51,200 ----a-w c:\windows\system32\wstdecod.dll
- 2004-08-19 13:42:32 18,432 ----a-w c:\windows\system32\wtsapi32.dll
+ 2008-04-14 02:18:47 18,432 ----a-w c:\windows\system32\wtsapi32.dll
- 2007-07-30 23:19:36 549,720 ----a-w c:\windows\system32\wuapi.dll
+ 2008-07-19 02:09:44 563,912 ----a-w c:\windows\system32\wuapi.dll
- 2007-07-30 23:19:16 53,080 ----a-w c:\windows\system32\wuauclt.exe
+ 2008-07-19 02:10:42 53,448 ----a-w c:\windows\system32\wuauclt.exe
- 2007-07-30 23:19:42 1,712,984 ----a-w c:\windows\system32\wuaueng.dll
+ 2008-07-19 02:09:42 1,811,656 ----a-w c:\windows\system32\wuaueng.dll
- 2004-08-19 13:42:34 6,656 ----a-w c:\windows\system32\wuauserv.dll
+ 2008-04-14 02:18:48 6,656 ----a-w c:\windows\system32\wuauserv.dll
- 2007-07-30 23:19:32 325,976 ----a-w c:\windows\system32\wucltui.dll
+ 2008-07-19 02:09:46 325,832 ----a-w c:\windows\system32\wucltui.dll
- 2007-07-30 23:18:40 33,624 ----a-w c:\windows\system32\wups.dll
+ 2008-07-19 02:10:20 36,552 ----a-w c:\windows\system32\wups.dll
- 2007-07-30 23:19:12 43,352 ----a-w c:\windows\system32\wups2.dll
+ 2008-07-19 02:10:40 45,768 ----a-w c:\windows\system32\wups2.dll
- 2007-07-30 23:19:28 203,096 ----a-w c:\windows\system32\wuweb.dll
+ 2008-07-19 02:09:44 205,000 ----a-w c:\windows\system32\wuweb.dll
- 2004-08-19 13:42:34 378,880 ----a-w c:\windows\system32\wzcdlg.dll
+ 2008-04-14 02:18:48 384,000 ----a-w c:\windows\system32\wzcdlg.dll
- 2004-08-19 13:56:12 51,712 ----a-w c:\windows\system32\wzcsapi.dll
+ 2008-04-14 02:18:48 52,736 ----a-w c:\windows\system32\wzcsapi.dll
- 2004-08-19 13:56:12 360,448 ----a-w c:\windows\system32\wzcsvc.dll
+ 2008-04-14 02:18:48 484,352 ----a-w c:\windows\system32\wzcsvc.dll
- 2004-08-19 13:42:34 91,648 ----a-w c:\windows\system32\xactsrv.dll
+ 2008-04-14 02:18:48 91,648 ----a-w c:\windows\system32\xactsrv.dll
- 2004-08-19 13:43:18 30,720 ----a-w c:\windows\system32\xcopy.exe
+ 2008-04-14 02:19:17 30,720 ----a-w c:\windows\system32\xcopy.exe
+ 2008-04-14 02:18:48 121,856 ------w c:\windows\system32\xmllite.dll
- 2004-08-19 13:42:34 129,536 ----a-w c:\windows\system32\xmlprov.dll
+ 2008-04-14 02:18:48 129,024 ----a-w c:\windows\system32\xmlprov.dll
- 2004-08-19 13:42:34 50,176 ----a-w c:\windows\system32\xmlprovi.dll
+ 2008-04-14 02:18:48 50,176 ----a-w c:\windows\system32\xmlprovi.dll
- 2006-03-01 19:44:00 11,776 ----a-w c:\windows\system32\xolehlp.dll
+ 2008-04-14 02:18:48 11,776 ----a-w c:\windows\system32\xolehlp.dll
- 2004-08-19 13:40:00 481,792 ----a-w c:\windows\system32\xpob2res.dll
+ 2008-04-13 18:40:26 481,792 ----a-w c:\windows\system32\xpob2res.dll
- 2004-08-19 13:40:36 196,096 ----a-w c:\windows\system32\xpsp1res.dll
+ 2008-04-13 18:35:11 196,096 ----a-w c:\windows\system32\xpsp1res.dll
- 2004-08-19 13:40:42 2,966,528 ----a-w c:\windows\system32\xpsp2res.dll
+ 2008-04-13 18:36:24 2,966,528 ----a-w c:\windows\system32\xpsp2res.dll
- 2008-07-03 09:42:31 369,152 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-04-13 18:39:11 764,416 ----a-w c:\windows\system32\xpsp3res.dll
- 2004-08-19 13:42:34 339,968 ----a-w c:\windows\system32\zipfldr.dll
+ 2008-04-14 02:18:48 340,480 ----a-w c:\windows\system32\zipfldr.dll
- 2004-08-19 13:42:28 50,688 ----a-w c:\windows\twain_32.dll
+ 2008-04-14 02:18:45 50,688 ----a-w c:\windows\twain_32.dll
- 2004-08-19 13:43:16 286,720 ----a-w c:\windows\winhlp32.exe
+ 2008-04-14 02:19:15 286,720 ----a-w c:\windows\winhlp32.exe
- 2007-01-19 12:50:55 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2008-04-14 02:16:14 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
- 2007-01-19 12:50:55 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2008-04-14 02:16:14 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2007-01-19 12:50:55 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2008-04-14 02:16:14 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
- 2007-01-19 12:50:55 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 02:16:14 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 02:16:14 1,054,208 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
+ 2008-04-14 02:16:14 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
+ 2008-04-14 02:16:15 343,040 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
+ 2008-04-14 02:16:13 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
+ 2008-04-15 17:49:33 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
- 2004-08-19 13:38:10 852,992 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 02:16:14 852,992 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
- 2004-08-19 13:38:10 993,280 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
+ 2008-04-14 02:16:14 993,280 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2004-08-19 13:38:10 136,192 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_es_858031fb\rtcres.dll
+ 2008-04-14 01:56:44 136,192 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_es_858031fb\rtcres.dll
.
-- Restablecer a la fecha actual de Snapshot --
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\archivos de programa\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Easy-PrintToolBox"="c:\archivos de programa\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-13 409600]
"AVG8_TRAY"="c:\archiv~1\AVG\AVG8\avgtray.exe" [2008-09-04 1235736]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Men£ Inicio\Programas\Inicio\
AutoCAD Startup Accelerator.lnk - c:\archivos de programa\Archivos comunes\Autodesk Shared\acstart16.exe [05/03/2005 16:18:22 10872]
Inicio r*pido de Adobe Reader.lnk - c:\archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 22:05:26 29696]
Software Kodak EasyShare.lnk - c:\archivos de programa\Kodak\Kodak EasyShare software\bin\EasyShare.exe [23/07/2004 8:26:34 757760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\aiaqdcz]
aiaqdcz.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Adg82.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Qux71.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Vyc03.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Inicio rápido de Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Reader.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon]
NULL [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinManage]
NULL [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2008-02-20 10:33 963072 c:\archivos de programa\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-13 22:18 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2004-06-04 07:33 1400944 c:\archivos de programa\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-05-11 20:52 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2008-03-31 21:54 507904 c:\archivos de programa\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-07-06 22:09 77824 c:\archivos de programa\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 14:49 36352 c:\archivos de programa\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
--a------ 2003-07-18 04:01 180224 c:\windows\system32\pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PV92TRAY]
--a------ 2003-06-25 07:47 311296 c:\windows\system32\PV92Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Archivos de programa\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Archivos de programa\\Microsoft Encarta\\Biblioteca de Consulta Encarta 2004\\EDICT.EXE"=
"c:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"c:\\Archivos de programa\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Archivos de programa\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Archivos de programa\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Archivos de programa\\AVG\\AVG8\\avgupd.exe"=
"c:\\Archivos de programa\\Ares\\Ares.exe"=
"c:\\Archivos de programa\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\livecall.exe"=
R0 Adg82;Adg82;c:\windows\system32\Drivers\Adg82.sys [23/07/2008 16:38:35 32256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [04/09/2008 21:19:36 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\archiv~1\AVG\AVG8\avgwdsvc.exe [04/09/2008 21:17:57 231704]
S0 Qux71;Qux71;c:\windows\system32\Drivers\Qux71.sys []
S0 Vyc03;Vyc03;c:\windows\system32\Drivers\Vyc03.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e5aad0d-a758-11db-b153-000b6a9b859d}]
\Shell\AutoRun\command - H:\cfdflx.com
\Shell\explore\Command - H:\cfdflx.com
\Shell\open\Command - H:\cfdflx.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5387fa46-5dc5-11dd-a93e-000b6a9b859d}]
\Shell\AutoRun\command - G:\cfdflx.com
\Shell\explore\Command - G:\cfdflx.com
\Shell\open\Command - G:\cfdflx.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58376c3c-6e58-11dd-a94c-000b6a9b859d}]
\Shell\AutoRun\command - G:\cfdflx.com
\Shell\explore\Command - G:\cfdflx.com
\Shell\open\Command - G:\cfdflx.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{812b4358-d275-11dc-a88c-000b6a9b859d}]
\Shell\AutoRun\command - G:\cfdflx.com
\Shell\explore\Command - G:\cfdflx.com
\Shell\open\Command - G:\cfdflx.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aef08416-e963-11db-b1b3-000b6a9b859d}]
\Shell\AutoRun\command - G:\cfdflx.com
\Shell\explore\Command - G:\cfdflx.com
\Shell\open\Command - G:\cfdflx.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c144148e-dbed-11dc-a89f-000b6a9b859d}]
\Shell\AutoRun\command - G:\cfdflx.com
\Shell\explore\Command - G:\cfdflx.com
\Shell\open\Command - G:\cfdflx.com
.
Contenido de carpeta 'Tareas Programadas'
2008-09-28 c:\windows\Tasks\9CD3906491C041C4.job
- c:\docume~1\temp\datosd~1\liesmu~1\LinkStopBat.exe []
2008-09-28 c:\windows\Tasks\A0222F749199DFA0.job
- c:\docume~1\manuel~1\datosd~1\liesmu~1\LinkStopBat.exe []
2008-09-28 c:\windows\Tasks\AC599C6C91E21AD0.job
- c:\docume~1\cinthia\datosd~1\liesmu~1\LinkStopBat.exe []
.
- - - - HUÉRFANOS ELIMINADOS - - - -
MSConfigStartUp-lphc52qj0et8j - c:\windows\system32\lphc52qj0et8j.exe
.
------- Análisis Suplementario -------
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE: &Clean Traces - c:\archivos de programa\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\archivos de programa\DAP\dapextie.htm
IE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZC
IE: &Winamp Search - c:\documents and settings\All Users\Datos de programa\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Download &all with DAP - c:\archivos de programa\DAP\dapextie2.htm
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\archiv~1\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\archiv~1\DAP\dapie.dll
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-27 07:45:35
Windows 5.1.2600 Service Pack 3 NTFS
escaneando procesos ocultos ...
escaneando entradas ocultas de autostart ...
escaneando archivos ocultos ...
el escaneo se completo con exito
archivos ocultos: 0
**************************************************************************
.
------------------------ Otros procesos en ejecución ------------------------
.
c:\archivos de programa\Ahead\InCD\InCDsrv.exe
c:\archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
c:\archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\system32\wdfmgr.exe
c:\archiv~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Tiempo completado: 2008-12-27 7:54:00 - Reiniciando la máquina
ComboFix-quarantined-files.txt 2008-12-27 11:53:54
ComboFix2.txt 2008-09-28 12:33:02
Pre-Run: 14,512,439,296 bytes libres
Post-Run: 14,410,645,504 bytes libres
6577 --- E O F --- 2008-12-27 11:29:02