part 3
LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-748032383-1639382996-22249522-1007\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CurVer]
@="BDATuner.コンポーネント.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\「0・、0・ケ0ネ0・・n0ミ0テ0ッ0「0テ0ラ0 *、0・・ク0]
@="{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}"
"Description"="このバージョンの Windows をアンインストールして前のオペレーティング システムに戻る場合は、これらのファイルが必要です。"
"Display"="前のオペレーティング システムのバックアップ ファイル"
"IconPath"=expand:"%SystemRoot%\\system32\\osuninst.EXE,0"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpertLandMarkDLL]
"LandMarkPath"="c:\\Program Files\\ExpWin32\\"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpertMapDLL]
"MapBasePath"="c:\\Program Files\\ExpWin32\\Map\\"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpLibDLL]
"knbFilePath"="c:\\Program Files\\ExpWin32\\Knb\\"
"knbFileName"="JPWIN"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\VESWinlogon.dll
c:\windows\system32\imjp9.ime
c:\windows\system32\imjp9k.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\conime.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\PAStiSvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
.
**************************************************************************
.
Completion time: 2009-02-18 13:02:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-18 11:02:17
ComboFix2.txt 2009-02-17 22:37:14
ComboFix3.txt 2009-02-17 21:50:53
ComboFix4.txt 2008-09-10 23:40:11
Pre-Run: 5,700,055,040 バイトの空き領域
Post-Run: 5,729,632,256 バイトの空き領域
340 --- E O F --- 2009-02-11 14:21:06
And the latest log
ComboFix 09-02-19.01 - AQA 2009-02-20 23:54:00.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.932.1.1041.18.1526.1031 [GMT 2:00]
Running from: c:\documents and settings\AQA\デスクトップ\ComboFix.exe
Command switches used :: c:\documents and settings\AQA\デスクトップ\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090220-0] *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\config\systemprofile\.exe
c:\windows\system32\Drivers\ati0pwxx.sys
c:\windows\system32\Drivers\ati7hoxx.sys
c:\windows\system32\samsvc.exe
C:\wtlh.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-20 to 2009-02-20 )))))))))))))))))))))))))))))))
.
2009-02-18 23:49 . 2009-02-18 23:49 <DIR> d-------- c:\windows\system32\Adobe
2009-02-18 12:40 . 2009-02-18 12:40 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-18 12:39 . 2009-02-18 12:39 <DIR> d-------- c:\program files\Common Files\Adobe
2009-02-16 15:33 . 2009-02-16 15:33 <DIR> d-------- c:\program files\BigfishGames
2009-02-13 04:30 . 2009-02-13 04:30 <DIR> d-------- c:\windows\Forgotten Lands The First Colony
2009-02-13 04:30 . 2009-02-13 04:30 <DIR> d-------- c:\documents and settings\AQA\Application Data\FirstColony
2009-02-12 02:52 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-02-12 02:43 . 2009-02-12 02:52 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-12 02:43 . 2009-02-12 02:43 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-12 02:43 . 2009-02-12 02:43 <DIR> d-------- c:\program files\MSBuild
2009-02-12 02:42 . 2009-02-12 02:43 <DIR> d-------- C:\0039984b666857c681
2009-02-12 02:42 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-12 02:42 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-12 02:42 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-12 02:42 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-12 02:42 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-12 02:42 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-12 02:42 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-01-31 16:42 . 2009-01-31 16:43 <DIR> d-------- c:\program files\ERUNT
2009-01-29 07:38 . 2009-01-29 07:38 <DIR> d-------- c:\documents and settings\AQA\Application Data\Aveyond I
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 12:04 --------- d-----w c:\documents and settings\NetworkService\Application Data\Sony Corporation
2009-02-14 05:09 --------- d-----w c:\program files\ExpWin32
2009-02-14 05:03 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-11 12:36 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-02-11 12:36 --------- d-----w c:\program files\Java
2009-02-03 16:04 --------- d-----w c:\documents and settings\AQA\Application Data\PlayFirst
2009-02-03 16:04 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2009-01-30 03:30 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-30 03:21 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-24 14:02 --------- d-----w c:\documents and settings\AQA\Application Data\DivX
2009-01-10 17:59 114,048 ----a-w c:\windows\system32\drivers\snapman.sys
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-02-17_23.49.27.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\ERDNT.EXE
+ 2009-02-17 22:50:59 9,441,280 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\Users\00000001\NTUSER.DAT
+ 2009-02-17 22:51:00 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\Users\00000002\UsrClass.dat
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\ERDNT.EXE
+ 2009-02-19 08:35:05 9,449,472 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\Users\00000001\NTUSER.DAT
+ 2009-02-19 08:35:05 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\Users\00000002\UsrClass.dat
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\ERDNT.EXE
+ 2009-02-20 08:51:58 9,449,472 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\Users\00000001\NTUSER.DAT
+ 2009-02-20 08:51:58 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\Users\00000002\UsrClass.dat
+ 2007-12-12 13:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
+ 2009-02-18 10:45:21 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-5760-0000-900000000003}\ARPPRODUCTICON.exe
+ 2001-07-14 15:32:24 69,632 ----a-w c:\windows\setupupd\temp\wsdueng.dll
+ 2009-01-16 17:17:04 114,688 ----a-w c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-01-16 17:25:34 202,168 ----a-w c:\windows\system32\Adobe\Director\SwDir.dll
+ 2009-01-16 17:17:42 499,712 ----a-w c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-01-16 16:58:24 1,798,144 ----a-w c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-01-16 17:17:46 9,216 ----a-w c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-01-16 16:45:12 703,488 ----a-w c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-01-16 16:45:12 52,288 ----a-w c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-01-16 16:54:42 892,928 ----a-w c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2009-01-16 17:16:22 266,240 ----a-w c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-01-16 17:18:16 446,464 ----a-w c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-01-16 17:25:14 460,216 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwHelper_1103472.exe
+ 2009-01-16 17:16:08 114,688 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-01-16 17:16:06 94,208 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-01-16 16:45:12 58,736 ----a-w c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 1999-06-25 08:55:30 149,504 ----a-w c:\windows\system32\Adobe\Shockwave 11\UNWISE.EXE
- 2008-11-07 11:55:27 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-18 21:06:17 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-20 21:39:52 16,384 ----atw c:\windows\temp\Perflib_Perfdata_540.dat
+ 2009-02-20 21:39:42 16,384 ----atw c:\windows\temp\Perflib_Perfdata_63c.dat
+ 2009-02-20 21:39:48 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6bc.dat
+ 2006-12-01 20:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
-- Snapshot reset to current date --
LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-748032383-1639382996-22249522-1007\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CurVer]
@="BDATuner.コンポーネント.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\「0・、0・ケ0ネ0・・n0ミ0テ0ッ0「0テ0ラ0 *、0・・ク0]
@="{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}"
"Description"="このバージョンの Windows をアンインストールして前のオペレーティング システムに戻る場合は、これらのファイルが必要です。"
"Display"="前のオペレーティング システムのバックアップ ファイル"
"IconPath"=expand:"%SystemRoot%\\system32\\osuninst.EXE,0"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpertLandMarkDLL]
"LandMarkPath"="c:\\Program Files\\ExpWin32\\"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpertMapDLL]
"MapBasePath"="c:\\Program Files\\ExpWin32\\Map\\"
[HKEY_LOCAL_MACHINE\software\VAL Laboratory\ナ兀0q0B0h0W*i*n*\ExpLibDLL]
"knbFilePath"="c:\\Program Files\\ExpWin32\\Knb\\"
"knbFileName"="JPWIN"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\VESWinlogon.dll
c:\windows\system32\imjp9.ime
c:\windows\system32\imjp9k.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\conime.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\PAStiSvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
.
**************************************************************************
.
Completion time: 2009-02-18 13:02:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-18 11:02:17
ComboFix2.txt 2009-02-17 22:37:14
ComboFix3.txt 2009-02-17 21:50:53
ComboFix4.txt 2008-09-10 23:40:11
Pre-Run: 5,700,055,040 バイトの空き領域
Post-Run: 5,729,632,256 バイトの空き領域
340 --- E O F --- 2009-02-11 14:21:06
And the latest log
ComboFix 09-02-19.01 - AQA 2009-02-20 23:54:00.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.932.1.1041.18.1526.1031 [GMT 2:00]
Running from: c:\documents and settings\AQA\デスクトップ\ComboFix.exe
Command switches used :: c:\documents and settings\AQA\デスクトップ\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090220-0] *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\config\systemprofile\.exe
c:\windows\system32\Drivers\ati0pwxx.sys
c:\windows\system32\Drivers\ati7hoxx.sys
c:\windows\system32\samsvc.exe
C:\wtlh.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-20 to 2009-02-20 )))))))))))))))))))))))))))))))
.
2009-02-18 23:49 . 2009-02-18 23:49 <DIR> d-------- c:\windows\system32\Adobe
2009-02-18 12:40 . 2009-02-18 12:40 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-18 12:39 . 2009-02-18 12:39 <DIR> d-------- c:\program files\Common Files\Adobe
2009-02-16 15:33 . 2009-02-16 15:33 <DIR> d-------- c:\program files\BigfishGames
2009-02-13 04:30 . 2009-02-13 04:30 <DIR> d-------- c:\windows\Forgotten Lands The First Colony
2009-02-13 04:30 . 2009-02-13 04:30 <DIR> d-------- c:\documents and settings\AQA\Application Data\FirstColony
2009-02-12 02:52 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-02-12 02:43 . 2009-02-12 02:52 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-12 02:43 . 2009-02-12 02:43 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-12 02:43 . 2009-02-12 02:43 <DIR> d-------- c:\program files\MSBuild
2009-02-12 02:42 . 2009-02-12 02:43 <DIR> d-------- C:\0039984b666857c681
2009-02-12 02:42 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-12 02:42 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-12 02:42 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-12 02:42 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-12 02:42 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-12 02:42 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-12 02:42 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-01-31 16:42 . 2009-01-31 16:43 <DIR> d-------- c:\program files\ERUNT
2009-01-29 07:38 . 2009-01-29 07:38 <DIR> d-------- c:\documents and settings\AQA\Application Data\Aveyond I
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 12:04 --------- d-----w c:\documents and settings\NetworkService\Application Data\Sony Corporation
2009-02-14 05:09 --------- d-----w c:\program files\ExpWin32
2009-02-14 05:03 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-11 12:36 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-02-11 12:36 --------- d-----w c:\program files\Java
2009-02-03 16:04 --------- d-----w c:\documents and settings\AQA\Application Data\PlayFirst
2009-02-03 16:04 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2009-01-30 03:30 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-30 03:21 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-24 14:02 --------- d-----w c:\documents and settings\AQA\Application Data\DivX
2009-01-10 17:59 114,048 ----a-w c:\windows\system32\drivers\snapman.sys
2008-12-20 22:31 826,368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-02-17_23.49.27.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\ERDNT.EXE
+ 2009-02-17 22:50:59 9,441,280 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\Users\00000001\NTUSER.DAT
+ 2009-02-17 22:51:00 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-18\Users\00000002\UsrClass.dat
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\ERDNT.EXE
+ 2009-02-19 08:35:05 9,449,472 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\Users\00000001\NTUSER.DAT
+ 2009-02-19 08:35:05 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-19\Users\00000002\UsrClass.dat
+ 2005-10-20 10:02:28 163,328 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\ERDNT.EXE
+ 2009-02-20 08:51:58 9,449,472 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\Users\00000001\NTUSER.DAT
+ 2009-02-20 08:51:58 172,032 ----a-w c:\windows\erdnt\AutoBackup\2009-02-20\Users\00000002\UsrClass.dat
+ 2007-12-12 13:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
+ 2009-02-18 10:45:21 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-5760-0000-900000000003}\ARPPRODUCTICON.exe
+ 2001-07-14 15:32:24 69,632 ----a-w c:\windows\setupupd\temp\wsdueng.dll
+ 2009-01-16 17:17:04 114,688 ----a-w c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-01-16 17:25:34 202,168 ----a-w c:\windows\system32\Adobe\Director\SwDir.dll
+ 2009-01-16 17:17:42 499,712 ----a-w c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-01-16 16:58:24 1,798,144 ----a-w c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-01-16 17:17:46 9,216 ----a-w c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-01-16 16:45:12 703,488 ----a-w c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-01-16 16:45:12 52,288 ----a-w c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-01-16 16:54:42 892,928 ----a-w c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2009-01-16 17:16:22 266,240 ----a-w c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-01-16 17:18:16 446,464 ----a-w c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-01-16 17:25:14 460,216 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwHelper_1103472.exe
+ 2009-01-16 17:16:08 114,688 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-01-16 17:16:06 94,208 ----a-w c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-01-16 16:45:12 58,736 ----a-w c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 1999-06-25 08:55:30 149,504 ----a-w c:\windows\system32\Adobe\Shockwave 11\UNWISE.EXE
- 2008-11-07 11:55:27 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-18 21:06:17 84,661 ----a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-20 21:39:52 16,384 ----atw c:\windows\temp\Perflib_Perfdata_540.dat
+ 2009-02-20 21:39:42 16,384 ----atw c:\windows\temp\Perflib_Perfdata_63c.dat
+ 2009-02-20 21:39:48 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6bc.dat
+ 2006-12-01 20:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
-- Snapshot reset to current date --