Yomommassis
New member
+ 2004-08-10 15:00:00 212,992 ----a-w C:\WINDOWS\system32\dllcache\ntevt.dll
+ 2004-08-10 15:00:00 393,728 ----a-w C:\WINDOWS\system32\dllcache\obrb0401.dll
+ 2004-08-10 15:00:00 212,480 ----a-w C:\WINDOWS\system32\dllcache\obrb0404.dll
+ 2004-08-10 15:00:00 428,032 ----a-w C:\WINDOWS\system32\dllcache\obrb0405.dll
+ 2004-08-10 15:00:00 418,816 ----a-w C:\WINDOWS\system32\dllcache\obrb0406.dll
+ 2004-08-10 15:00:00 403,456 ----a-w C:\WINDOWS\system32\dllcache\obrb0407.dll
+ 2004-08-10 15:00:00 419,328 ----a-w C:\WINDOWS\system32\dllcache\obrb0408.dll
+ 2004-08-10 15:00:00 405,504 ----a-w C:\WINDOWS\system32\dllcache\obrb040b.dll
+ 2004-08-10 15:00:00 410,624 ----a-w C:\WINDOWS\system32\dllcache\obrb040C.dll
+ 2004-08-10 15:00:00 384,000 ----a-w C:\WINDOWS\system32\dllcache\obrb040D.dll
+ 2004-08-10 15:00:00 434,176 ----a-w C:\WINDOWS\system32\dllcache\obrb040e.dll
+ 2004-08-10 15:00:00 413,696 ----a-w C:\WINDOWS\system32\dllcache\obrb0410.dll
+ 2004-08-10 15:00:00 275,456 ----a-w C:\WINDOWS\system32\dllcache\obrb0411.dll
+ 2004-08-10 15:00:00 306,688 ----a-w C:\WINDOWS\system32\dllcache\obrb0412.dll
+ 2004-08-10 15:00:00 401,920 ----a-w C:\WINDOWS\system32\dllcache\obrb0413.dll
+ 2004-08-10 15:00:00 353,792 ----a-w C:\WINDOWS\system32\dllcache\obrb0414.dll
+ 2004-08-10 15:00:00 391,680 ----a-w C:\WINDOWS\system32\dllcache\obrb0415.dll
+ 2004-08-10 15:00:00 409,600 ----a-w C:\WINDOWS\system32\dllcache\obrb0416.dll
+ 2004-08-10 15:00:00 427,008 ----a-w C:\WINDOWS\system32\dllcache\obrb0419.dll
+ 2004-08-10 15:00:00 405,504 ----a-w C:\WINDOWS\system32\dllcache\obrb041b.dll
+ 2004-08-10 15:00:00 363,520 ----a-w C:\WINDOWS\system32\dllcache\obrb041D.dll
+ 2004-08-10 15:00:00 390,144 ----a-w C:\WINDOWS\system32\dllcache\obrb041f.dll
+ 2004-08-10 15:00:00 408,576 ----a-w C:\WINDOWS\system32\dllcache\obrb0424.dll
+ 2004-08-10 15:00:00 270,336 ----a-w C:\WINDOWS\system32\dllcache\obrb0804.dll
+ 2004-08-10 15:00:00 435,200 ----a-w C:\WINDOWS\system32\dllcache\obrb0816.dll
+ 2004-08-10 15:00:00 446,464 ----a-w C:\WINDOWS\system32\dllcache\obrb0C0A.dll
- 2007-10-10 23:55:59 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-08-26 07:24:30 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2004-08-10 15:00:00 104,448 ----a-w C:\WINDOWS\system32\dllcache\oeimport.dll
+ 2004-08-10 15:00:00 60,416 ----a-w C:\WINDOWS\system32\dllcache\oemig50.exe
+ 2004-08-10 15:00:00 35,328 ----a-w C:\WINDOWS\system32\dllcache\oemiglib.dll
+ 2004-08-10 15:00:00 82,944 ----a-w C:\WINDOWS\system32\dllcache\olecli.dll
+ 2004-08-10 15:00:00 487,424 ----a-w C:\WINDOWS\system32\dllcache\oledb32.dll
+ 2004-08-10 15:00:00 65,536 ----a-w C:\WINDOWS\system32\dllcache\oledb32r.dll
+ 2004-08-10 15:00:00 24,064 ----a-w C:\WINDOWS\system32\dllcache\olesvr.dll
+ 2004-08-10 15:00:00 51,200 ----a-w C:\WINDOWS\system32\dllcache\oobebaln.exe
+ 2006-10-11 16:24:45 153,088 ------w C:\WINDOWS\system32\dllcache\p2p.dll
+ 2006-10-11 16:24:45 104,960 ------w C:\WINDOWS\system32\dllcache\p2pgasvc.dll
+ 2006-10-11 16:24:45 313,344 ------w C:\WINDOWS\system32\dllcache\p2pgraph.dll
+ 2006-10-11 16:24:45 116,224 ------w C:\WINDOWS\system32\dllcache\p2pnetsh.dll
+ 2006-10-11 16:24:45 553,984 ------w C:\WINDOWS\system32\dllcache\p2psvc.dll
+ 2004-08-10 15:00:00 281,088 ----a-w C:\WINDOWS\system32\dllcache\pinball.exe
- 2007-08-14 02:36:12 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2006-10-11 16:24:45 58,880 ------w C:\WINDOWS\system32\dllcache\pnrpnsp.dll
+ 2004-08-10 15:00:00 92,672 ----a-w C:\WINDOWS\system32\dllcache\policman.dll
- 2007-10-29 22:35:13 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\rrcm.dll
+ 2004-08-10 15:00:00 48,706 ----a-w C:\WINDOWS\system32\dllcache\rvse.dll
+ 2004-08-10 15:00:00 42,574 ----a-w C:\WINDOWS\system32\dllcache\rvsezm.exe
+ 2004-08-10 15:00:00 741,376 ----a-w C:\WINDOWS\system32\dllcache\sapi.dll
+ 2004-08-10 15:00:00 36,864 ----a-w C:\WINDOWS\system32\dllcache\sapisvr.exe
+ 2004-08-10 15:00:00 36,864 ----a-w C:\WINDOWS\system32\dllcache\scrcons.exe
+ 2005-04-28 19:16:29 215,552 ----a-w C:\WINDOWS\system32\dllcache\script.dll
+ 2004-08-10 15:00:00 188,416 ----a-w C:\WINDOWS\system32\dllcache\script_a.dll
+ 2006-11-02 02:31:38 1,669,120 ----a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
+ 2004-08-10 15:00:00 73,216 ----a-w C:\WINDOWS\system32\dllcache\setup50.exe
+ 2004-08-10 15:00:00 5,120 ----a-w C:\WINDOWS\system32\dllcache\shell.dll
+ 2004-08-10 15:00:00 66,113 ----a-w C:\WINDOWS\system32\dllcache\shvl.dll
+ 2004-08-10 15:00:00 42,573 ----a-w C:\WINDOWS\system32\dllcache\shvlzm.exe
+ 2004-08-10 15:00:00 40,960 ----a-w C:\WINDOWS\system32\dllcache\smtpcons.dll
+ 2004-08-10 15:00:00 130,048 ----a-w C:\WINDOWS\system32\dllcache\softkbd.dll
+ 2004-08-10 15:00:00 1,744 ----a-w C:\WINDOWS\system32\dllcache\sound.drv
+ 2004-08-10 15:00:00 77,824 ----a-w C:\WINDOWS\system32\dllcache\spcommon.dll
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\spcplui.dll
+ 2004-08-10 15:00:00 62,976 ----a-w C:\WINDOWS\system32\dllcache\spgrmr.dll
+ 2004-08-10 15:00:00 186,880 ----a-w C:\WINDOWS\system32\dllcache\spra0401.dll
+ 2004-08-10 15:00:00 189,440 ----a-w C:\WINDOWS\system32\dllcache\spra0402.dll
+ 2004-08-10 15:00:00 161,280 ----a-w C:\WINDOWS\system32\dllcache\spra0404.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra0405.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0406.dll
+ 2004-08-10 15:00:00 199,680 ----a-w C:\WINDOWS\system32\dllcache\spra0407.dll
+ 2004-08-10 15:00:00 197,632 ----a-w C:\WINDOWS\system32\dllcache\spra0408.dll
+ 2004-08-10 15:00:00 186,368 ----a-w C:\WINDOWS\system32\dllcache\spra040b.dll
+ 2004-08-10 15:00:00 197,632 ----a-w C:\WINDOWS\system32\dllcache\spra040C.dll
+ 2004-08-10 15:00:00 181,760 ----a-w C:\WINDOWS\system32\dllcache\spra040D.dll
+ 2004-08-10 15:00:00 195,584 ----a-w C:\WINDOWS\system32\dllcache\spra040e.dll
+ 2004-08-10 15:00:00 195,072 ----a-w C:\WINDOWS\system32\dllcache\spra0410.dll
+ 2004-08-10 15:00:00 171,008 ----a-w C:\WINDOWS\system32\dllcache\spra0411.dll
+ 2004-08-10 15:00:00 167,936 ----a-w C:\WINDOWS\system32\dllcache\spra0412.dll
+ 2004-08-10 15:00:00 196,096 ----a-w C:\WINDOWS\system32\dllcache\spra0413.dll
+ 2004-08-10 15:00:00 189,440 ----a-w C:\WINDOWS\system32\dllcache\spra0414.dll
+ 2004-08-10 15:00:00 194,560 ----a-w C:\WINDOWS\system32\dllcache\spra0415.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0416.dll
+ 2004-08-10 15:00:00 190,464 ----a-w C:\WINDOWS\system32\dllcache\spra0418.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0419.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041a.dll
+ 2004-08-10 15:00:00 193,024 ----a-w C:\WINDOWS\system32\dllcache\spra041b.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041D.dll
+ 2004-08-10 15:00:00 188,416 ----a-w C:\WINDOWS\system32\dllcache\spra041e.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041f.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0424.dll
+ 2004-08-10 15:00:00 187,392 ----a-w C:\WINDOWS\system32\dllcache\spra0425.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra0426.dll
+ 2004-08-10 15:00:00 189,952 ----a-w C:\WINDOWS\system32\dllcache\spra0427.dll
+ 2004-08-10 15:00:00 161,280 ----a-w C:\WINDOWS\system32\dllcache\spra0804.dll
+ 2004-08-10 15:00:00 194,560 ----a-w C:\WINDOWS\system32\dllcache\spra0816.dll
+ 2004-08-10 15:00:00 196,096 ----a-w C:\WINDOWS\system32\dllcache\spra0C0A.dll
+ 2004-08-10 15:00:00 2,869,248 ----a-w C:\WINDOWS\system32\dllcache\sprb0401.dll
+ 2004-08-10 15:00:00 477,696 ----a-w C:\WINDOWS\system32\dllcache\sprb0404.dll
+ 2004-08-10 15:00:00 734,720 ----a-w C:\WINDOWS\system32\dllcache\sprb0405.dll
+ 2004-08-10 15:00:00 742,912 ----a-w C:\WINDOWS\system32\dllcache\sprb0406.dll
+ 2004-08-10 15:00:00 788,992 ----a-w C:\WINDOWS\system32\dllcache\sprb0407.dll
+ 2004-08-10 15:00:00 801,280 ----a-w C:\WINDOWS\system32\dllcache\sprb0408.dll
+ 2004-08-10 15:00:00 729,088 ----a-w C:\WINDOWS\system32\dllcache\sprb040b.dll
+ 2004-08-10 15:00:00 793,600 ----a-w C:\WINDOWS\system32\dllcache\sprb040C.dll
+ 2004-08-10 15:00:00 2,842,112 ----a-w C:\WINDOWS\system32\dllcache\sprb040D.dll
+ 2004-08-10 15:00:00 769,536 ----a-w C:\WINDOWS\system32\dllcache\sprb040e.dll
+ 2004-08-10 15:00:00 769,536 ----a-w C:\WINDOWS\system32\dllcache\sprb0410.dll
+ 2004-08-10 15:00:00 562,688 ----a-w C:\WINDOWS\system32\dllcache\sprb0411.dll
+ 2004-08-10 15:00:00 543,744 ----a-w C:\WINDOWS\system32\dllcache\sprb0412.dll
+ 2004-08-10 15:00:00 769,024 ----a-w C:\WINDOWS\system32\dllcache\sprb0413.dll
+ 2004-08-10 15:00:00 716,288 ----a-w C:\WINDOWS\system32\dllcache\sprb0414.dll
+ 2004-08-10 15:00:00 759,808 ----a-w C:\WINDOWS\system32\dllcache\sprb0415.dll
+ 2004-08-10 15:00:00 752,128 ----a-w C:\WINDOWS\system32\dllcache\sprb0416.dll
+ 2004-08-10 15:00:00 736,768 ----a-w C:\WINDOWS\system32\dllcache\sprb0419.dll
+ 2004-08-10 15:00:00 757,248 ----a-w C:\WINDOWS\system32\dllcache\sprb041b.dll
+ 2004-08-10 15:00:00 724,992 ----a-w C:\WINDOWS\system32\dllcache\sprb041D.dll
+ 2004-08-10 15:00:00 724,480 ----a-w C:\WINDOWS\system32\dllcache\sprb041f.dll
+ 2004-08-10 15:00:00 732,160 ----a-w C:\WINDOWS\system32\dllcache\sprb0424.dll
+ 2004-08-10 15:00:00 470,016 ----a-w C:\WINDOWS\system32\dllcache\sprb0804.dll
+ 2004-08-10 15:00:00 751,616 ----a-w C:\WINDOWS\system32\dllcache\sprb0816.dll
+ 2004-08-10 15:00:00 773,632 ----a-w C:\WINDOWS\system32\dllcache\sprb0C0A.dll
+ 2004-08-10 15:00:00 774,144 ----a-w C:\WINDOWS\system32\dllcache\spttseng.dll
+ 2004-08-10 15:00:00 151,552 ----a-w C:\WINDOWS\system32\dllcache\sqldb20.dll
+ 2004-08-10 15:00:00 462,848 ----a-w C:\WINDOWS\system32\dllcache\sqlqp20.dll
+ 2004-08-10 15:00:00 110,592 ----a-w C:\WINDOWS\system32\dllcache\sqlse20.dll
+ 2004-08-10 15:00:00 217,088 ----a-w C:\WINDOWS\system32\dllcache\sqlxmlx.dll
+ 2004-08-10 15:00:00 58,434 ----a-w C:\WINDOWS\system32\dllcache\srchctls.dll
+ 2004-08-10 15:00:00 725,566 ----a-w C:\WINDOWS\system32\dllcache\srchui.dll
+ 2004-08-10 15:00:00 47,104 ----a-w C:\WINDOWS\system32\dllcache\srdiag.exe
+ 2004-08-10 15:00:00 33,280 ----a-w C:\WINDOWS\system32\dllcache\sstub.dll
+ 2004-08-10 15:00:00 86,528 ----a-w C:\WINDOWS\system32\dllcache\stdprov.dll
- 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2004-08-04 06:08:04 48,640 ----a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2005-04-28 19:16:29 193,024 ----a-w C:\WINDOWS\system32\dllcache\sysmod.dll
+ 2004-08-10 15:00:00 155,648 ----a-w C:\WINDOWS\system32\dllcache\sysmod_a.dll
+ 2004-08-10 15:00:00 3,360 ----a-w C:\WINDOWS\system32\dllcache\system.drv
+ 2004-08-10 15:00:00 19,200 ----a-w C:\WINDOWS\system32\dllcache\tapi.dll
- 2007-10-30 17:20:55 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2004-08-10 15:00:00 4,048 ----a-w C:\WINDOWS\system32\dllcache\timer.drv
+ 2004-08-10 15:00:00 61,952 ----a-w C:\WINDOWS\system32\dllcache\tmplprov.dll
+ 2004-08-10 15:00:00 3,374,640 ----a-w C:\WINDOWS\system32\dllcache\tourW.exe
+ 2004-08-10 15:00:00 153,088 ----a-w C:\WINDOWS\system32\dllcache\triedit.dll
+ 2004-08-10 15:00:00 59,904 ----a-w C:\WINDOWS\system32\dllcache\trnsprov.dll
+ 2004-08-10 15:00:00 16,896 ----a-w C:\WINDOWS\system32\dllcache\unsecapp.exe
+ 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\dllcache\updprov.dll
+ 2004-08-10 15:00:00 150,528 ----a-w C:\WINDOWS\system32\dllcache\uploadm.exe
- 2007-10-10 23:55:59 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-08-26 07:24:30 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
- 2007-10-10 23:56:00 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2004-08-10 15:00:00 9,008 ----a-w C:\WINDOWS\system32\dllcache\ver.dll
+ 2004-08-10 15:00:00 2,176 ----a-w C:\WINDOWS\system32\dllcache\vga.drv
+ 2004-08-10 15:00:00 131,584 ----a-w C:\WINDOWS\system32\dllcache\viewprov.dll
+ 2004-08-10 15:00:00 46,080 ----a-w C:\WINDOWS\system32\dllcache\wab.exe
+ 2004-08-10 15:00:00 32,768 ----a-w C:\WINDOWS\system32\dllcache\wabfind.dll
+ 2004-08-10 15:00:00 30,208 ----a-w C:\WINDOWS\system32\dllcache\wabmig.exe
+ 2004-08-10 15:00:00 12,288 ----a-w C:\WINDOWS\system32\dllcache\wb32.exe
+ 2004-08-10 15:00:00 12,288 ----a-w C:\WINDOWS\system32\dllcache\wbemads.dll
+ 2004-08-10 15:00:00 196,608 ----a-w C:\WINDOWS\system32\dllcache\wbemcntl.dll
+ 2004-08-10 15:00:00 43,008 ----a-w C:\WINDOWS\system32\dllcache\wbemperf.dll
+ 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\dllcache\wbemtest.exe
+ 2004-08-10 15:00:00 197,120 ----a-w C:\WINDOWS\system32\dllcache\wbemupgd.dll
- 2007-10-10 23:56:00 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2004-08-10 15:00:00 13,600 ----a-w C:\WINDOWS\system32\dllcache\wfwnet.drv
- 2007-10-10 23:56:00 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-08-26 07:24:31 826,368 ------w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2004-08-10 15:00:00 13,312 ----a-w C:\WINDOWS\system32\dllcache\winmgmt.exe
+ 2004-08-10 15:00:00 16,384 ----a-w C:\WINDOWS\system32\dllcache\winmgmtr.dll
+ 2004-08-10 15:00:00 146,432 ----a-w C:\WINDOWS\system32\dllcache\winspool.drv
+ 2004-08-10 15:00:00 25,088 ----a-w C:\WINDOWS\system32\dllcache\wisc10.dll
+ 2004-08-10 15:00:00 6,656 ----a-w C:\WINDOWS\system32\dllcache\wmiapres.dll
+ 2004-08-10 15:00:00 89,088 ----a-w C:\WINDOWS\system32\dllcache\wmiaprpl.dll
+ 2004-08-10 15:00:00 358,912 ----a-w C:\WINDOWS\system32\dllcache\wmic.exe
+ 2004-08-10 15:00:00 60,928 ----a-w C:\WINDOWS\system32\dllcache\wmicookr.dll
+ 2004-08-10 15:00:00 140,800 ----a-w C:\WINDOWS\system32\dllcache\wmidcprv.dll
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\wmimsg.dll
+ 2004-08-10 15:00:00 132,096 ----a-w C:\WINDOWS\system32\dllcache\wmipdskq.dll
+ 2004-08-10 15:00:00 62,464 ----a-w C:\WINDOWS\system32\dllcache\wmipiprt.dll
+ 2004-08-10 15:00:00 62,976 ----a-w C:\WINDOWS\system32\dllcache\wmipjobj.dll
+ 2004-08-10 15:00:00 41,472 ----a-w C:\WINDOWS\system32\dllcache\wmipsess.dll
+ 2004-08-10 15:00:00 52,224 ----a-w C:\WINDOWS\system32\dllcache\wmitimep.dll
+ 2004-08-10 15:00:00 167,936 ----a-w C:\WINDOWS\system32\dllcache\wmm2ae.dll
+ 2004-08-10 18:47:46 9,728 ----a-w C:\WINDOWS\system32\dllcache\wmm2eres.dll
+ 2004-08-10 18:47:48 69,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2ext.dll
+ 2004-08-10 15:00:00 402,432 ----a-w C:\WINDOWS\system32\dllcache\wmm2filt.dll
+ 2004-08-10 15:00:00 502,272 ----a-w C:\WINDOWS\system32\dllcache\wmm2fxa.dll
+ 2004-08-10 15:00:00 325,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2fxb.dll
+ 2004-08-10 15:00:00 5,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2res2.dll
+ 2006-10-19 05:47:20 96,256 ----a-w C:\WINDOWS\system32\dllcache\wmpband.dll
+ 2004-08-10 15:00:00 41,029 ----a-w C:\WINDOWS\system32\dllcache\zcorem.dll
+ 2004-08-10 15:00:00 4,677 ----a-w C:\WINDOWS\system32\dllcache\zeeverm.dll
+ 2004-08-10 15:00:00 29,760 ----a-w C:\WINDOWS\system32\dllcache\znetm.dll
+ 2004-08-10 15:00:00 113,222 ----a-w C:\WINDOWS\system32\dllcache\zoneclim.dll
+ 2004-08-10 15:00:00 13,894 ----a-w C:\WINDOWS\system32\dllcache\zonelibm.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2004-08-10 15:00:00 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
- 2005-09-27 21:51:00 40,960 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
+ 2005-11-23 01:48:38 40,960 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
- 2005-09-27 22:46:00 1,345,536 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
+ 2005-11-23 02:50:52 1,410,560 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
- 2005-08-02 09:58:00 38,016 ----a-w C:\WINDOWS\system32\drivers\camc6aud.sys
+ 2005-08-02 00:58:28 38,016 ----a-w C:\WINDOWS\system32\drivers\camc6aud.sys
- 2005-08-02 10:00:00 349,312 ----a-w C:\WINDOWS\system32\drivers\camc6hal.sys
+ 2005-08-02 01:00:04 349,312 ----a-w C:\WINDOWS\system32\drivers\camc6hal.sys
- 2004-08-04 07:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
+ 2004-08-04 06:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
- 2005-06-29 07:43:36 19,200 ----a-w C:\WINDOWS\system32\drivers\hidir.sys
+ 2006-01-11 00:48:53 19,200 ----a-w C:\WINDOWS\system32\drivers\hidir.sys
- 2005-08-22 09:06:00 718,464 ----a-w C:\WINDOWS\system32\drivers\HSF_CNXT.sys
+ 2005-08-22 22:06:10 718,464 ----a-w C:\WINDOWS\system32\drivers\HSF_CNXT.sys
+ 2005-08-22 23:07:00 1,035,008 ----a-w C:\WINDOWS\system32\drivers\HSF_DPV.sys
- 2005-08-22 09:06:00 231,424 ----a-w C:\WINDOWS\system32\drivers\HSFHWATI.sys
+ 2005-08-22 22:06:14 231,424 ----a-w C:\WINDOWS\system32\drivers\HSFHWATI.sys
- 2005-06-29 07:43:40 46,592 ----a-w C:\WINDOWS\system32\drivers\irbus.sys
+ 2006-01-11 00:48:58 46,592 ----a-w C:\WINDOWS\system32\drivers\irbus.sys
- 2004-08-04 07:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2004-08-04 06:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2004-03-17 04:04:00 13,059 ----a-w C:\WINDOWS\system32\drivers\mdmxsdk.sys
+ 2004-03-17 17:04:14 13,059 ----a-w C:\WINDOWS\system32\drivers\mdmxsdk.sys
- 2006-07-13 08:48:58 202,240 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2004-08-04 06:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
- 2007-08-14 02:35:46 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-10-10 23:55:51 214,528 ------w C:\WINDOWS\system32\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 ------w C:\WINDOWS\system32\dxtrans.dll
- 2005-07-26 04:39:45 243,200 ----a-w C:\WINDOWS\system32\es.dll
+ 2008-07-07 20:32:22 253,952 ----a-w C:\WINDOWS\system32\es.dll
- 2007-10-10 23:55:51 132,608 ------w C:\WINDOWS\system32\extmgr.dll
+ 2008-08-26 07:24:28 133,120 ------w C:\WINDOWS\system32\extmgr.dll
- 2003-08-03 17:56:16 1,146,184 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-06-06 17:53:34 1,195,888 ----a-w C:\WINDOWS\system32\FM20.DLL
- 2007-08-30 01:56:33 256,656 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-18 01:33:41 256,656 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-10-10 23:55:51 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-08-26 07:24:28 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2007-10-10 10:59:40 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
- 2007-10-10 23:55:51 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
- 2007-10-10 23:55:51 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
- 2007-10-10 05:46:55 161,792 ------w C:\WINDOWS\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ------w C:\WINDOWS\system32\ieakui.dll
- 2007-10-10 23:55:52 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-08-26 07:24:28 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2007-10-10 23:55:52 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
- 2007-10-10 23:55:54 6,065,664 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-10-03 17:41:15 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2007-10-10 23:55:55 44,544 ------w C:\WINDOWS\system32\iernonce.dll
+ 2008-08-26 07:24:29 44,544 ------w C:\WINDOWS\system32\iernonce.dll
- 2007-10-10 23:55:55 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-08-26 07:24:29 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2007-10-10 10:59:40 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2005-10-29 06:49:40 151,552 ------w C:\WINDOWS\system32\ifxcardm.dll
- 2007-08-21 06:15:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2007-07-12 08:22:00 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 08:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-07-12 08:22:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 08:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-07-12 09:22:38 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 09:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2007-10-10 23:55:56 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
- 2004-08-04 08:56:44 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2004-08-04 07:56:44 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2008-03-21 01:06:36 1,480,232 ------w C:\WINDOWS\system32\LegitCheckControl.dll
- 2008-02-06 00:50:38 14,864 ----a-w C:\WINDOWS\system32\LVCOMSX.EXE
+ 2005-07-20 00:32:18 221,184 ----a-w C:\WINDOWS\system32\LVCOMSX.EXE
- 2003-06-19 00:31:48 17,920 ----a-w C:\WINDOWS\system32\mdimon.dll
+ 2007-04-09 20:23:54 28,040 ----a-w C:\WINDOWS\system32\mdimon.dll
- 2004-03-17 04:00:00 86,016 ----a-w C:\WINDOWS\system32\mdmxsdk.dll
+ 2004-03-17 17:00:32 86,016 ----a-w C:\WINDOWS\system32\mdmxsdk.dll
- 2008-01-02 18:21:36 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-10-07 19:19:42 16,721,856 ----a-w C:\WINDOWS\system32\MRT.exe
- 2005-06-29 01:46:00 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
- 2004-07-15 14:34:06 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll
+ 2005-09-23 14:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll
- 2003-02-21 10:09:14 106,496 ----a-w C:\WINDOWS\system32\mscories.dll
+ 2005-09-23 14:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll
- 2004-08-10 15:00:00 294,400 ----a-w C:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
- 2004-08-10 15:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll
- 2004-08-10 15:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll
- 2007-10-10 23:55:56 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-08-26 07:24:30 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-10-10 23:55:56 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-08-26 07:24:30 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2007-10-30 23:42:28 3,590,656 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-08-27 08:24:32 3,593,216 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-10-10 23:55:58 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2004-08-10 15:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll
- 2004-08-10 15:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
- 2004-08-10 15:00:00 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
- 2004-08-10 15:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll
- 2004-08-10 15:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll
- 2004-08-10 15:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
- 2004-08-10 15:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll
- 2007-10-10 23:55:58 193,024 ------w C:\WINDOWS\system32\msrating.dll
+ 2008-08-26 07:24:30 193,024 ------w C:\WINDOWS\system32\msrating.dll
- 2004-08-10 15:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll
- 2004-08-10 15:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll
- 2004-08-10 15:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll
- 2004-08-10 15:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll
- 2007-10-10 23:55:59 671,232 ------w C:\WINDOWS\system32\mstime.dll
+ 2008-08-26 07:24:30 671,232 ------w C:\WINDOWS\system32\mstime.dll
- 2004-08-10 15:00:00 407,552 ----a-w C:\WINDOWS\system32\mstsc.exe
+ 2006-11-07 08:06:47 600,576 ----a-w C:\WINDOWS\system32\mstsc.exe
- 2004-08-10 15:00:00 655,360 ----a-w C:\WINDOWS\system32\mstscax.dll
+ 2006-11-13 06:02:58 1,866,240 ----a-w C:\WINDOWS\system32\mstscax.dll
- 2004-08-10 15:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll
- 2004-08-10 15:00:00 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
- 2004-08-10 15:00:00 614,429 ----a-w C:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
- 2004-08-10 15:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2007-07-31 02:18:34 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
- 2007-10-10 23:55:59 102,400 ------w C:\WINDOWS\system32\occache.dll
+ 2008-08-26 07:24:30 102,912 ------w C:\WINDOWS\system32\occache.dll
- 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\p2p.dll
+ 2006-10-11 16:24:45 153,088 ----a-w C:\WINDOWS\system32\p2p.dll
- 2004-08-10 15:00:00 86,016 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
+ 2006-10-11 16:24:45 104,960 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
- 2004-08-10 15:00:00 312,320 ----a-w C:\WINDOWS\system32\p2pgraph.dll
+ 2006-10-11 16:24:45 313,344 ----a-w C:\WINDOWS\system32\p2pgraph.dll
- 2004-08-10 15:00:00 88,064 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
+ 2006-10-11 16:24:45 116,224 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
- 2004-08-10 15:00:00 526,848 ----a-w C:\WINDOWS\system32\p2psvc.dll
+ 2006-10-11 16:24:45 553,984 ----a-w C:\WINDOWS\system32\p2psvc.dll
- 2008-10-14 03:52:49 53,166 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-16 18:27:06 62,746 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-10-14 03:52:50 380,918 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-16 18:27:06 401,632 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2005-10-29 06:49:42 84,480 ------w C:\WINDOWS\system32\pintool.exe
- 2007-08-14 02:36:12 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2004-08-10 15:00:00 48,640 ----a-w C:\WINDOWS\system32\pnrpnsp.dll
+ 2006-10-11 16:24:45 58,880 ----a-w C:\WINDOWS\system32\pnrpnsp.dll
- 2007-10-29 22:35:13 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2005-09-27 21:47:00 233,472 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2cqag.dll
+ 2005-09-27 22:47:00 241,664 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2dvag.dll
+ 2005-09-27 22:42:00 39,936 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2edxx.dll
+ 2005-09-27 21:51:00 40,960 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2erec.dll
+ 2005-09-27 22:41:00 46,080 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2evxx.dll
+ 2005-09-27 22:40:00 376,832 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2evxx.exe
+ 2005-09-27 22:42:00 25,088 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\Ati2mdxx.exe
+ 2005-09-27 22:46:00 1,345,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2mtag.sys
+ 2005-09-27 22:33:00 2,430,368 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati3duag.dll
+ 2005-09-28 00:44:00 253,952 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ATIDEMGR.dll
+ 2005-09-14 10:13:00 104,376 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atiicdxx.dat
+ 2005-09-28 01:22:00 307,200 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atiiiexx.dll
+ 2005-09-27 22:15:00 147,456 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atikvmag.dll
+ 2005-09-28 00:03:00 6,680,576 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atioglx1.dll
+ 2005-09-27 23:01:00 4,841,472 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atioglxx.dll
+ 2005-09-27 21:52:00 17,408 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atitvo32.dll
+ 2005-09-27 22:27:00 602,304 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ativvaxx.dll
+ 2005-08-22 09:06:00 718,464 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSF_CNXT.sys
+ 2005-08-22 09:06:00 1,035,008 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSF_DP.sys
+ 2005-08-22 09:06:00 231,424 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSFHWATI.sys
+ 2005-08-12 08:01:00 577,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HXFSetup.exe
+ 2004-03-17 04:00:00 86,016 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\mdmxsdk.dll
+ 2004-03-17 04:04:00 13,059 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\mdmxsdk.sys
+ 2005-06-20 02:57:00 110,592 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\uci32100.dll
+ 2005-08-02 09:58:00 38,016 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\camc6aud.sys
+ 2005-08-02 10:00:00 349,312 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\camc6hal.sys
+ 2005-02-24 14:56:00 16,437 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\CAUDINST.dll
+ 2005-05-12 12:40:00 577,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\HXFSetup.exe
+ 2004-08-04 07:08:00 60,288 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\drmk.sys
+ 2004-08-04 07:15:22 140,928 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\ks.sys
+ 2004-08-04 08:56:44 4,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\ksuser.dll
+ 2005-03-22 03:43:15 145,920 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\portcls.sys
+ 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\stream.sys
+ 2004-08-10 15:00:00 23,552 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\wdmaud.drv
- 2006-09-26 01:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2003-06-19 00:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2007-04-09 20:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2003-06-19 00:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2007-04-09 20:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
- 2003-06-19 00:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2007-04-09 20:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
- 2003-06-19 00:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2007-04-09 20:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
- 2003-06-19 00:31:48 18,944 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2007-04-09 20:23:54 28,552 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
- 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2006-12-21 00:37:40 176,128 ----a-w C:\WINDOWS\system32\UCI32A16.dll
- 2007-10-10 23:55:59 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-08-26 07:24:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-10-10 23:56:00 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2005-04-27 23:15:36 17,920 ------w C:\WINDOWS\system32\usmt\cobramsg.dll
- 2004-08-10 15:00:00 123,904 ----a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2005-04-28 19:16:29 133,120 ----a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2005-04-28 19:16:29 115,200 ------w C:\WINDOWS\system32\usmt\guitrna.dll
- 2004-08-10 15:00:00 4,096 ----a-w C:\WINDOWS\system32\usmt\iconlib.dll
+ 2005-04-27 23:15:45 2,560 ----a-w C:\WINDOWS\system32\usmt\iconlib.dll
- 2004-08-10 15:00:00 19,968 ----a-w C:\WINDOWS\system32\usmt\log.dll
+ 2005-04-28 19:16:29 19,968 ----a-w C:\WINDOWS\system32\usmt\log.dll
- 2004-08-10 15:00:00 201,216 ----a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2005-04-28 19:16:29 274,432 ----a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2005-04-28 19:16:30 261,120 ------w C:\WINDOWS\system32\usmt\migisma.dll
- 2004-08-10 15:00:00 103,424 ----a-w C:\WINDOWS\system32\usmt\migload.exe
+ 2005-04-28 00:12:58 103,424 ----a-w C:\WINDOWS\system32\usmt\migload.exe
- 2004-08-10 15:00:00 240,128 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2005-04-28 00:12:57 245,248 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2005-04-28 00:12:57 241,152 ------w C:\WINDOWS\system32\usmt\migwiza.exe
- 2004-08-10 15:00:00 202,752 ----a-w C:\WINDOWS\system32\usmt\script.dll
+ 2005-04-28 19:16:29 215,552 ----a-w C:\WINDOWS\system32\usmt\script.dll
+ 2005-04-28 19:16:29 199,680 ------w C:\WINDOWS\system32\usmt\scripta.dll
- 2004-08-10 15:00:00 168,960 ----a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2005-04-28 19:16:29 193,024 ----a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2005-04-28 19:16:29 173,568 ------w C:\WINDOWS\system32\usmt\sysmoda.dll
- 2007-10-10 23:56:00 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
- 2007-10-10 23:56:00 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-08-26 07:24:31 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
- 2006-10-19 05:47:20 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-25 01:12:58 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-04-15 17:54:19 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
+ 2008-10-16 18:24:40 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-10-16 18:24:40 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5aa265c0-4404-3ff0-7ceb-9118c2e0bfd0}]
2008-09-04 04:02 350208 --a------ C:\WINDOWS\system32\nss15.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-11 67128]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-27 344064]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-20 48752]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-10-11 409600]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 368706]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MDDiskProtect.exe"="C:\Program Files\Mediafour\MacDrive\MDDiskProtect.exe" [2005-04-15 106496]
"Mediafour Mac Volume Notifications"="C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE" [2002-12-17 61440]
"DigidesignMMERefresh"="C:\Program Files\Digidesign\Drivers\MMERefresh.exe" [2006-11-14 61440]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-04-03 727288]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 5562368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-05-08 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-11 67128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave7"= Digi32.dll
"MIDI7"= diomidi.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 05:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 17:52 50736 C:\Program Files\Common Files\AOL\1168232905\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2004-10-13 17:04 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-08-13 17:04 5562368 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
--a--c--- 2004-08-24 16:09 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-11-28 22:52 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-28 11:40 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-05-14 15:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP
eer Name Resolution Protocol (PNRP)
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 16384]
R0 MDPMGRNT;MDPMGRNT;C:\WINDOWS\system32\drivers\MDPMGRNT.sys [2006-04-30 16640]
R1 MDFSYSNT;MDFSYSNT;C:\WINDOWS\system32\drivers\MDFSYSNT.sys [2006-06-16 212864]
R2 DigiNet;Digidesign Ethernet Support;C:\WINDOWS\system32\DRIVERS\diginet.sys [2006-11-13 11776]
R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 27992]
R2 Synchro Arts License Manager;Synchro Arts License Manager;C:\Program Files\Common Files\License.exe [2002-01-17 28672]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2008-01-26 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - bestbuy.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2005-05-06 04:15]
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-Mediafour Mac Volume Icons - (no file)
MSConfigStartUp-AOL Spyware Protection - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
MSConfigStartUp-My Web Search Bar Search Scope Monitor - C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 19:08:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????9?9?3?7??????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-17 19:10:45
ComboFix-quarantined-files.txt 2008-10-18 02:10:26
ComboFix2.txt 2008-10-16 11:12:46
ComboFix3.txt 2008-10-15 23:37:57
ComboFix4.txt 2008-10-15 04:02:03
ComboFix5.txt 2008-10-18 02:01:51
Pre-Run: 62,894,878,720 bytes free
Post-Run: 62,933,798,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
1498 --- E O F --- 2008-10-17 16:50:45
+ 2004-08-10 15:00:00 393,728 ----a-w C:\WINDOWS\system32\dllcache\obrb0401.dll
+ 2004-08-10 15:00:00 212,480 ----a-w C:\WINDOWS\system32\dllcache\obrb0404.dll
+ 2004-08-10 15:00:00 428,032 ----a-w C:\WINDOWS\system32\dllcache\obrb0405.dll
+ 2004-08-10 15:00:00 418,816 ----a-w C:\WINDOWS\system32\dllcache\obrb0406.dll
+ 2004-08-10 15:00:00 403,456 ----a-w C:\WINDOWS\system32\dllcache\obrb0407.dll
+ 2004-08-10 15:00:00 419,328 ----a-w C:\WINDOWS\system32\dllcache\obrb0408.dll
+ 2004-08-10 15:00:00 405,504 ----a-w C:\WINDOWS\system32\dllcache\obrb040b.dll
+ 2004-08-10 15:00:00 410,624 ----a-w C:\WINDOWS\system32\dllcache\obrb040C.dll
+ 2004-08-10 15:00:00 384,000 ----a-w C:\WINDOWS\system32\dllcache\obrb040D.dll
+ 2004-08-10 15:00:00 434,176 ----a-w C:\WINDOWS\system32\dllcache\obrb040e.dll
+ 2004-08-10 15:00:00 413,696 ----a-w C:\WINDOWS\system32\dllcache\obrb0410.dll
+ 2004-08-10 15:00:00 275,456 ----a-w C:\WINDOWS\system32\dllcache\obrb0411.dll
+ 2004-08-10 15:00:00 306,688 ----a-w C:\WINDOWS\system32\dllcache\obrb0412.dll
+ 2004-08-10 15:00:00 401,920 ----a-w C:\WINDOWS\system32\dllcache\obrb0413.dll
+ 2004-08-10 15:00:00 353,792 ----a-w C:\WINDOWS\system32\dllcache\obrb0414.dll
+ 2004-08-10 15:00:00 391,680 ----a-w C:\WINDOWS\system32\dllcache\obrb0415.dll
+ 2004-08-10 15:00:00 409,600 ----a-w C:\WINDOWS\system32\dllcache\obrb0416.dll
+ 2004-08-10 15:00:00 427,008 ----a-w C:\WINDOWS\system32\dllcache\obrb0419.dll
+ 2004-08-10 15:00:00 405,504 ----a-w C:\WINDOWS\system32\dllcache\obrb041b.dll
+ 2004-08-10 15:00:00 363,520 ----a-w C:\WINDOWS\system32\dllcache\obrb041D.dll
+ 2004-08-10 15:00:00 390,144 ----a-w C:\WINDOWS\system32\dllcache\obrb041f.dll
+ 2004-08-10 15:00:00 408,576 ----a-w C:\WINDOWS\system32\dllcache\obrb0424.dll
+ 2004-08-10 15:00:00 270,336 ----a-w C:\WINDOWS\system32\dllcache\obrb0804.dll
+ 2004-08-10 15:00:00 435,200 ----a-w C:\WINDOWS\system32\dllcache\obrb0816.dll
+ 2004-08-10 15:00:00 446,464 ----a-w C:\WINDOWS\system32\dllcache\obrb0C0A.dll
- 2007-10-10 23:55:59 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-08-26 07:24:30 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2004-08-10 15:00:00 104,448 ----a-w C:\WINDOWS\system32\dllcache\oeimport.dll
+ 2004-08-10 15:00:00 60,416 ----a-w C:\WINDOWS\system32\dllcache\oemig50.exe
+ 2004-08-10 15:00:00 35,328 ----a-w C:\WINDOWS\system32\dllcache\oemiglib.dll
+ 2004-08-10 15:00:00 82,944 ----a-w C:\WINDOWS\system32\dllcache\olecli.dll
+ 2004-08-10 15:00:00 487,424 ----a-w C:\WINDOWS\system32\dllcache\oledb32.dll
+ 2004-08-10 15:00:00 65,536 ----a-w C:\WINDOWS\system32\dllcache\oledb32r.dll
+ 2004-08-10 15:00:00 24,064 ----a-w C:\WINDOWS\system32\dllcache\olesvr.dll
+ 2004-08-10 15:00:00 51,200 ----a-w C:\WINDOWS\system32\dllcache\oobebaln.exe
+ 2006-10-11 16:24:45 153,088 ------w C:\WINDOWS\system32\dllcache\p2p.dll
+ 2006-10-11 16:24:45 104,960 ------w C:\WINDOWS\system32\dllcache\p2pgasvc.dll
+ 2006-10-11 16:24:45 313,344 ------w C:\WINDOWS\system32\dllcache\p2pgraph.dll
+ 2006-10-11 16:24:45 116,224 ------w C:\WINDOWS\system32\dllcache\p2pnetsh.dll
+ 2006-10-11 16:24:45 553,984 ------w C:\WINDOWS\system32\dllcache\p2psvc.dll
+ 2004-08-10 15:00:00 281,088 ----a-w C:\WINDOWS\system32\dllcache\pinball.exe
- 2007-08-14 02:36:12 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2006-10-11 16:24:45 58,880 ------w C:\WINDOWS\system32\dllcache\pnrpnsp.dll
+ 2004-08-10 15:00:00 92,672 ----a-w C:\WINDOWS\system32\dllcache\policman.dll
- 2007-10-29 22:35:13 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\rrcm.dll
+ 2004-08-10 15:00:00 48,706 ----a-w C:\WINDOWS\system32\dllcache\rvse.dll
+ 2004-08-10 15:00:00 42,574 ----a-w C:\WINDOWS\system32\dllcache\rvsezm.exe
+ 2004-08-10 15:00:00 741,376 ----a-w C:\WINDOWS\system32\dllcache\sapi.dll
+ 2004-08-10 15:00:00 36,864 ----a-w C:\WINDOWS\system32\dllcache\sapisvr.exe
+ 2004-08-10 15:00:00 36,864 ----a-w C:\WINDOWS\system32\dllcache\scrcons.exe
+ 2005-04-28 19:16:29 215,552 ----a-w C:\WINDOWS\system32\dllcache\script.dll
+ 2004-08-10 15:00:00 188,416 ----a-w C:\WINDOWS\system32\dllcache\script_a.dll
+ 2006-11-02 02:31:38 1,669,120 ----a-w C:\WINDOWS\system32\dllcache\setup_wm.exe
+ 2004-08-10 15:00:00 73,216 ----a-w C:\WINDOWS\system32\dllcache\setup50.exe
+ 2004-08-10 15:00:00 5,120 ----a-w C:\WINDOWS\system32\dllcache\shell.dll
+ 2004-08-10 15:00:00 66,113 ----a-w C:\WINDOWS\system32\dllcache\shvl.dll
+ 2004-08-10 15:00:00 42,573 ----a-w C:\WINDOWS\system32\dllcache\shvlzm.exe
+ 2004-08-10 15:00:00 40,960 ----a-w C:\WINDOWS\system32\dllcache\smtpcons.dll
+ 2004-08-10 15:00:00 130,048 ----a-w C:\WINDOWS\system32\dllcache\softkbd.dll
+ 2004-08-10 15:00:00 1,744 ----a-w C:\WINDOWS\system32\dllcache\sound.drv
+ 2004-08-10 15:00:00 77,824 ----a-w C:\WINDOWS\system32\dllcache\spcommon.dll
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\spcplui.dll
+ 2004-08-10 15:00:00 62,976 ----a-w C:\WINDOWS\system32\dllcache\spgrmr.dll
+ 2004-08-10 15:00:00 186,880 ----a-w C:\WINDOWS\system32\dllcache\spra0401.dll
+ 2004-08-10 15:00:00 189,440 ----a-w C:\WINDOWS\system32\dllcache\spra0402.dll
+ 2004-08-10 15:00:00 161,280 ----a-w C:\WINDOWS\system32\dllcache\spra0404.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra0405.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0406.dll
+ 2004-08-10 15:00:00 199,680 ----a-w C:\WINDOWS\system32\dllcache\spra0407.dll
+ 2004-08-10 15:00:00 197,632 ----a-w C:\WINDOWS\system32\dllcache\spra0408.dll
+ 2004-08-10 15:00:00 186,368 ----a-w C:\WINDOWS\system32\dllcache\spra040b.dll
+ 2004-08-10 15:00:00 197,632 ----a-w C:\WINDOWS\system32\dllcache\spra040C.dll
+ 2004-08-10 15:00:00 181,760 ----a-w C:\WINDOWS\system32\dllcache\spra040D.dll
+ 2004-08-10 15:00:00 195,584 ----a-w C:\WINDOWS\system32\dllcache\spra040e.dll
+ 2004-08-10 15:00:00 195,072 ----a-w C:\WINDOWS\system32\dllcache\spra0410.dll
+ 2004-08-10 15:00:00 171,008 ----a-w C:\WINDOWS\system32\dllcache\spra0411.dll
+ 2004-08-10 15:00:00 167,936 ----a-w C:\WINDOWS\system32\dllcache\spra0412.dll
+ 2004-08-10 15:00:00 196,096 ----a-w C:\WINDOWS\system32\dllcache\spra0413.dll
+ 2004-08-10 15:00:00 189,440 ----a-w C:\WINDOWS\system32\dllcache\spra0414.dll
+ 2004-08-10 15:00:00 194,560 ----a-w C:\WINDOWS\system32\dllcache\spra0415.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0416.dll
+ 2004-08-10 15:00:00 190,464 ----a-w C:\WINDOWS\system32\dllcache\spra0418.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0419.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041a.dll
+ 2004-08-10 15:00:00 193,024 ----a-w C:\WINDOWS\system32\dllcache\spra041b.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041D.dll
+ 2004-08-10 15:00:00 188,416 ----a-w C:\WINDOWS\system32\dllcache\spra041e.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra041f.dll
+ 2004-08-10 15:00:00 192,512 ----a-w C:\WINDOWS\system32\dllcache\spra0424.dll
+ 2004-08-10 15:00:00 187,392 ----a-w C:\WINDOWS\system32\dllcache\spra0425.dll
+ 2004-08-10 15:00:00 188,928 ----a-w C:\WINDOWS\system32\dllcache\spra0426.dll
+ 2004-08-10 15:00:00 189,952 ----a-w C:\WINDOWS\system32\dllcache\spra0427.dll
+ 2004-08-10 15:00:00 161,280 ----a-w C:\WINDOWS\system32\dllcache\spra0804.dll
+ 2004-08-10 15:00:00 194,560 ----a-w C:\WINDOWS\system32\dllcache\spra0816.dll
+ 2004-08-10 15:00:00 196,096 ----a-w C:\WINDOWS\system32\dllcache\spra0C0A.dll
+ 2004-08-10 15:00:00 2,869,248 ----a-w C:\WINDOWS\system32\dllcache\sprb0401.dll
+ 2004-08-10 15:00:00 477,696 ----a-w C:\WINDOWS\system32\dllcache\sprb0404.dll
+ 2004-08-10 15:00:00 734,720 ----a-w C:\WINDOWS\system32\dllcache\sprb0405.dll
+ 2004-08-10 15:00:00 742,912 ----a-w C:\WINDOWS\system32\dllcache\sprb0406.dll
+ 2004-08-10 15:00:00 788,992 ----a-w C:\WINDOWS\system32\dllcache\sprb0407.dll
+ 2004-08-10 15:00:00 801,280 ----a-w C:\WINDOWS\system32\dllcache\sprb0408.dll
+ 2004-08-10 15:00:00 729,088 ----a-w C:\WINDOWS\system32\dllcache\sprb040b.dll
+ 2004-08-10 15:00:00 793,600 ----a-w C:\WINDOWS\system32\dllcache\sprb040C.dll
+ 2004-08-10 15:00:00 2,842,112 ----a-w C:\WINDOWS\system32\dllcache\sprb040D.dll
+ 2004-08-10 15:00:00 769,536 ----a-w C:\WINDOWS\system32\dllcache\sprb040e.dll
+ 2004-08-10 15:00:00 769,536 ----a-w C:\WINDOWS\system32\dllcache\sprb0410.dll
+ 2004-08-10 15:00:00 562,688 ----a-w C:\WINDOWS\system32\dllcache\sprb0411.dll
+ 2004-08-10 15:00:00 543,744 ----a-w C:\WINDOWS\system32\dllcache\sprb0412.dll
+ 2004-08-10 15:00:00 769,024 ----a-w C:\WINDOWS\system32\dllcache\sprb0413.dll
+ 2004-08-10 15:00:00 716,288 ----a-w C:\WINDOWS\system32\dllcache\sprb0414.dll
+ 2004-08-10 15:00:00 759,808 ----a-w C:\WINDOWS\system32\dllcache\sprb0415.dll
+ 2004-08-10 15:00:00 752,128 ----a-w C:\WINDOWS\system32\dllcache\sprb0416.dll
+ 2004-08-10 15:00:00 736,768 ----a-w C:\WINDOWS\system32\dllcache\sprb0419.dll
+ 2004-08-10 15:00:00 757,248 ----a-w C:\WINDOWS\system32\dllcache\sprb041b.dll
+ 2004-08-10 15:00:00 724,992 ----a-w C:\WINDOWS\system32\dllcache\sprb041D.dll
+ 2004-08-10 15:00:00 724,480 ----a-w C:\WINDOWS\system32\dllcache\sprb041f.dll
+ 2004-08-10 15:00:00 732,160 ----a-w C:\WINDOWS\system32\dllcache\sprb0424.dll
+ 2004-08-10 15:00:00 470,016 ----a-w C:\WINDOWS\system32\dllcache\sprb0804.dll
+ 2004-08-10 15:00:00 751,616 ----a-w C:\WINDOWS\system32\dllcache\sprb0816.dll
+ 2004-08-10 15:00:00 773,632 ----a-w C:\WINDOWS\system32\dllcache\sprb0C0A.dll
+ 2004-08-10 15:00:00 774,144 ----a-w C:\WINDOWS\system32\dllcache\spttseng.dll
+ 2004-08-10 15:00:00 151,552 ----a-w C:\WINDOWS\system32\dllcache\sqldb20.dll
+ 2004-08-10 15:00:00 462,848 ----a-w C:\WINDOWS\system32\dllcache\sqlqp20.dll
+ 2004-08-10 15:00:00 110,592 ----a-w C:\WINDOWS\system32\dllcache\sqlse20.dll
+ 2004-08-10 15:00:00 217,088 ----a-w C:\WINDOWS\system32\dllcache\sqlxmlx.dll
+ 2004-08-10 15:00:00 58,434 ----a-w C:\WINDOWS\system32\dllcache\srchctls.dll
+ 2004-08-10 15:00:00 725,566 ----a-w C:\WINDOWS\system32\dllcache\srchui.dll
+ 2004-08-10 15:00:00 47,104 ----a-w C:\WINDOWS\system32\dllcache\srdiag.exe
+ 2004-08-10 15:00:00 33,280 ----a-w C:\WINDOWS\system32\dllcache\sstub.dll
+ 2004-08-10 15:00:00 86,528 ----a-w C:\WINDOWS\system32\dllcache\stdprov.dll
- 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2004-08-04 06:08:04 48,640 ----a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2005-04-28 19:16:29 193,024 ----a-w C:\WINDOWS\system32\dllcache\sysmod.dll
+ 2004-08-10 15:00:00 155,648 ----a-w C:\WINDOWS\system32\dllcache\sysmod_a.dll
+ 2004-08-10 15:00:00 3,360 ----a-w C:\WINDOWS\system32\dllcache\system.drv
+ 2004-08-10 15:00:00 19,200 ----a-w C:\WINDOWS\system32\dllcache\tapi.dll
- 2007-10-30 17:20:55 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2004-08-10 15:00:00 4,048 ----a-w C:\WINDOWS\system32\dllcache\timer.drv
+ 2004-08-10 15:00:00 61,952 ----a-w C:\WINDOWS\system32\dllcache\tmplprov.dll
+ 2004-08-10 15:00:00 3,374,640 ----a-w C:\WINDOWS\system32\dllcache\tourW.exe
+ 2004-08-10 15:00:00 153,088 ----a-w C:\WINDOWS\system32\dllcache\triedit.dll
+ 2004-08-10 15:00:00 59,904 ----a-w C:\WINDOWS\system32\dllcache\trnsprov.dll
+ 2004-08-10 15:00:00 16,896 ----a-w C:\WINDOWS\system32\dllcache\unsecapp.exe
+ 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\dllcache\updprov.dll
+ 2004-08-10 15:00:00 150,528 ----a-w C:\WINDOWS\system32\dllcache\uploadm.exe
- 2007-10-10 23:55:59 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-08-26 07:24:30 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
- 2007-10-10 23:56:00 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2004-08-10 15:00:00 9,008 ----a-w C:\WINDOWS\system32\dllcache\ver.dll
+ 2004-08-10 15:00:00 2,176 ----a-w C:\WINDOWS\system32\dllcache\vga.drv
+ 2004-08-10 15:00:00 131,584 ----a-w C:\WINDOWS\system32\dllcache\viewprov.dll
+ 2004-08-10 15:00:00 46,080 ----a-w C:\WINDOWS\system32\dllcache\wab.exe
+ 2004-08-10 15:00:00 32,768 ----a-w C:\WINDOWS\system32\dllcache\wabfind.dll
+ 2004-08-10 15:00:00 30,208 ----a-w C:\WINDOWS\system32\dllcache\wabmig.exe
+ 2004-08-10 15:00:00 12,288 ----a-w C:\WINDOWS\system32\dllcache\wb32.exe
+ 2004-08-10 15:00:00 12,288 ----a-w C:\WINDOWS\system32\dllcache\wbemads.dll
+ 2004-08-10 15:00:00 196,608 ----a-w C:\WINDOWS\system32\dllcache\wbemcntl.dll
+ 2004-08-10 15:00:00 43,008 ----a-w C:\WINDOWS\system32\dllcache\wbemperf.dll
+ 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\dllcache\wbemtest.exe
+ 2004-08-10 15:00:00 197,120 ----a-w C:\WINDOWS\system32\dllcache\wbemupgd.dll
- 2007-10-10 23:56:00 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2004-08-10 15:00:00 13,600 ----a-w C:\WINDOWS\system32\dllcache\wfwnet.drv
- 2007-10-10 23:56:00 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-08-26 07:24:31 826,368 ------w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2004-08-10 15:00:00 13,312 ----a-w C:\WINDOWS\system32\dllcache\winmgmt.exe
+ 2004-08-10 15:00:00 16,384 ----a-w C:\WINDOWS\system32\dllcache\winmgmtr.dll
+ 2004-08-10 15:00:00 146,432 ----a-w C:\WINDOWS\system32\dllcache\winspool.drv
+ 2004-08-10 15:00:00 25,088 ----a-w C:\WINDOWS\system32\dllcache\wisc10.dll
+ 2004-08-10 15:00:00 6,656 ----a-w C:\WINDOWS\system32\dllcache\wmiapres.dll
+ 2004-08-10 15:00:00 89,088 ----a-w C:\WINDOWS\system32\dllcache\wmiaprpl.dll
+ 2004-08-10 15:00:00 358,912 ----a-w C:\WINDOWS\system32\dllcache\wmic.exe
+ 2004-08-10 15:00:00 60,928 ----a-w C:\WINDOWS\system32\dllcache\wmicookr.dll
+ 2004-08-10 15:00:00 140,800 ----a-w C:\WINDOWS\system32\dllcache\wmidcprv.dll
+ 2004-08-10 15:00:00 61,440 ----a-w C:\WINDOWS\system32\dllcache\wmimsg.dll
+ 2004-08-10 15:00:00 132,096 ----a-w C:\WINDOWS\system32\dllcache\wmipdskq.dll
+ 2004-08-10 15:00:00 62,464 ----a-w C:\WINDOWS\system32\dllcache\wmipiprt.dll
+ 2004-08-10 15:00:00 62,976 ----a-w C:\WINDOWS\system32\dllcache\wmipjobj.dll
+ 2004-08-10 15:00:00 41,472 ----a-w C:\WINDOWS\system32\dllcache\wmipsess.dll
+ 2004-08-10 15:00:00 52,224 ----a-w C:\WINDOWS\system32\dllcache\wmitimep.dll
+ 2004-08-10 15:00:00 167,936 ----a-w C:\WINDOWS\system32\dllcache\wmm2ae.dll
+ 2004-08-10 18:47:46 9,728 ----a-w C:\WINDOWS\system32\dllcache\wmm2eres.dll
+ 2004-08-10 18:47:48 69,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2ext.dll
+ 2004-08-10 15:00:00 402,432 ----a-w C:\WINDOWS\system32\dllcache\wmm2filt.dll
+ 2004-08-10 15:00:00 502,272 ----a-w C:\WINDOWS\system32\dllcache\wmm2fxa.dll
+ 2004-08-10 15:00:00 325,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2fxb.dll
+ 2004-08-10 15:00:00 5,632 ----a-w C:\WINDOWS\system32\dllcache\wmm2res2.dll
+ 2006-10-19 05:47:20 96,256 ----a-w C:\WINDOWS\system32\dllcache\wmpband.dll
+ 2004-08-10 15:00:00 41,029 ----a-w C:\WINDOWS\system32\dllcache\zcorem.dll
+ 2004-08-10 15:00:00 4,677 ----a-w C:\WINDOWS\system32\dllcache\zeeverm.dll
+ 2004-08-10 15:00:00 29,760 ----a-w C:\WINDOWS\system32\dllcache\znetm.dll
+ 2004-08-10 15:00:00 113,222 ----a-w C:\WINDOWS\system32\dllcache\zoneclim.dll
+ 2004-08-10 15:00:00 13,894 ----a-w C:\WINDOWS\system32\dllcache\zonelibm.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2004-08-10 15:00:00 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
- 2005-09-27 21:51:00 40,960 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
+ 2005-11-23 01:48:38 40,960 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
- 2005-09-27 22:46:00 1,345,536 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
+ 2005-11-23 02:50:52 1,410,560 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
- 2005-08-02 09:58:00 38,016 ----a-w C:\WINDOWS\system32\drivers\camc6aud.sys
+ 2005-08-02 00:58:28 38,016 ----a-w C:\WINDOWS\system32\drivers\camc6aud.sys
- 2005-08-02 10:00:00 349,312 ----a-w C:\WINDOWS\system32\drivers\camc6hal.sys
+ 2005-08-02 01:00:04 349,312 ----a-w C:\WINDOWS\system32\drivers\camc6hal.sys
- 2004-08-04 07:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
+ 2004-08-04 06:08:00 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
- 2005-06-29 07:43:36 19,200 ----a-w C:\WINDOWS\system32\drivers\hidir.sys
+ 2006-01-11 00:48:53 19,200 ----a-w C:\WINDOWS\system32\drivers\hidir.sys
- 2005-08-22 09:06:00 718,464 ----a-w C:\WINDOWS\system32\drivers\HSF_CNXT.sys
+ 2005-08-22 22:06:10 718,464 ----a-w C:\WINDOWS\system32\drivers\HSF_CNXT.sys
+ 2005-08-22 23:07:00 1,035,008 ----a-w C:\WINDOWS\system32\drivers\HSF_DPV.sys
- 2005-08-22 09:06:00 231,424 ----a-w C:\WINDOWS\system32\drivers\HSFHWATI.sys
+ 2005-08-22 22:06:14 231,424 ----a-w C:\WINDOWS\system32\drivers\HSFHWATI.sys
- 2005-06-29 07:43:40 46,592 ----a-w C:\WINDOWS\system32\drivers\irbus.sys
+ 2006-01-11 00:48:58 46,592 ----a-w C:\WINDOWS\system32\drivers\irbus.sys
- 2004-08-04 07:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2004-08-04 06:15:22 140,928 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2004-03-17 04:04:00 13,059 ----a-w C:\WINDOWS\system32\drivers\mdmxsdk.sys
+ 2004-03-17 17:04:14 13,059 ----a-w C:\WINDOWS\system32\drivers\mdmxsdk.sys
- 2006-07-13 08:48:58 202,240 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2004-08-04 06:08:04 48,640 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
- 2007-08-14 02:35:46 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-08-26 07:24:28 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-10-10 23:55:51 214,528 ------w C:\WINDOWS\system32\dxtrans.dll
+ 2008-08-26 07:24:28 214,528 ------w C:\WINDOWS\system32\dxtrans.dll
- 2005-07-26 04:39:45 243,200 ----a-w C:\WINDOWS\system32\es.dll
+ 2008-07-07 20:32:22 253,952 ----a-w C:\WINDOWS\system32\es.dll
- 2007-10-10 23:55:51 132,608 ------w C:\WINDOWS\system32\extmgr.dll
+ 2008-08-26 07:24:28 133,120 ------w C:\WINDOWS\system32\extmgr.dll
- 2003-08-03 17:56:16 1,146,184 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-06-06 17:53:34 1,195,888 ----a-w C:\WINDOWS\system32\FM20.DLL
- 2007-08-30 01:56:33 256,656 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-18 01:33:41 256,656 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-10-10 23:55:51 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-08-26 07:24:28 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2007-10-10 10:59:40 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-08-25 08:37:59 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
- 2007-10-10 23:55:51 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
+ 2008-08-26 07:24:28 153,088 ------w C:\WINDOWS\system32\ieakeng.dll
- 2007-10-10 23:55:51 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
+ 2008-08-26 07:24:28 230,400 ------w C:\WINDOWS\system32\ieaksie.dll
- 2007-10-10 05:46:55 161,792 ------w C:\WINDOWS\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ------w C:\WINDOWS\system32\ieakui.dll
- 2007-10-10 23:55:52 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-08-26 07:24:28 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2007-10-10 23:55:52 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-08-26 07:24:29 384,512 ------w C:\WINDOWS\system32\iedkcs32.dll
- 2007-10-10 23:55:54 6,065,664 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-10-03 17:41:15 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2007-10-10 23:55:55 44,544 ------w C:\WINDOWS\system32\iernonce.dll
+ 2008-08-26 07:24:29 44,544 ------w C:\WINDOWS\system32\iernonce.dll
- 2007-10-10 23:55:55 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-08-26 07:24:29 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2007-10-10 10:59:40 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-08-25 08:38:00 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2005-10-29 06:49:40 151,552 ------w C:\WINDOWS\system32\ifxcardm.dll
- 2007-08-21 06:15:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2007-07-12 08:22:00 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 08:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-07-12 08:22:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 08:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-07-12 09:22:38 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 09:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2007-10-10 23:55:56 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
+ 2008-08-26 07:24:30 27,648 ------w C:\WINDOWS\system32\jsproxy.dll
- 2004-08-04 08:56:44 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2004-08-04 07:56:44 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
+ 2008-03-21 01:06:36 1,480,232 ------w C:\WINDOWS\system32\LegitCheckControl.dll
- 2008-02-06 00:50:38 14,864 ----a-w C:\WINDOWS\system32\LVCOMSX.EXE
+ 2005-07-20 00:32:18 221,184 ----a-w C:\WINDOWS\system32\LVCOMSX.EXE
- 2003-06-19 00:31:48 17,920 ----a-w C:\WINDOWS\system32\mdimon.dll
+ 2007-04-09 20:23:54 28,040 ----a-w C:\WINDOWS\system32\mdimon.dll
- 2004-03-17 04:00:00 86,016 ----a-w C:\WINDOWS\system32\mdmxsdk.dll
+ 2004-03-17 17:00:32 86,016 ----a-w C:\WINDOWS\system32\mdmxsdk.dll
- 2008-01-02 18:21:36 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-10-07 19:19:42 16,721,856 ----a-w C:\WINDOWS\system32\MRT.exe
- 2005-06-29 01:46:00 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
- 2004-07-15 14:34:06 16,896 ----a-w C:\WINDOWS\system32\mscorier.dll
+ 2005-09-23 14:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll
- 2003-02-21 10:09:14 106,496 ----a-w C:\WINDOWS\system32\mscories.dll
+ 2005-09-23 14:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll
- 2004-08-10 15:00:00 294,400 ----a-w C:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
- 2004-08-10 15:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll
- 2004-08-10 15:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll
- 2007-10-10 23:55:56 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-08-26 07:24:30 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-10-10 23:55:56 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-08-26 07:24:30 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2007-10-30 23:42:28 3,590,656 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-08-27 08:24:32 3,593,216 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-10-10 23:55:58 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2004-08-10 15:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll
- 2004-08-10 15:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
- 2004-08-10 15:00:00 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
- 2004-08-10 15:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll
- 2004-08-10 15:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll
- 2004-08-10 15:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
- 2004-08-10 15:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll
- 2007-10-10 23:55:58 193,024 ------w C:\WINDOWS\system32\msrating.dll
+ 2008-08-26 07:24:30 193,024 ------w C:\WINDOWS\system32\msrating.dll
- 2004-08-10 15:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll
- 2004-08-10 15:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll
- 2004-08-10 15:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll
- 2004-08-10 15:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll
- 2007-10-10 23:55:59 671,232 ------w C:\WINDOWS\system32\mstime.dll
+ 2008-08-26 07:24:30 671,232 ------w C:\WINDOWS\system32\mstime.dll
- 2004-08-10 15:00:00 407,552 ----a-w C:\WINDOWS\system32\mstsc.exe
+ 2006-11-07 08:06:47 600,576 ----a-w C:\WINDOWS\system32\mstsc.exe
- 2004-08-10 15:00:00 655,360 ----a-w C:\WINDOWS\system32\mstscax.dll
+ 2006-11-13 06:02:58 1,866,240 ----a-w C:\WINDOWS\system32\mstscax.dll
- 2004-08-10 15:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll
- 2004-08-10 15:00:00 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
- 2004-08-10 15:00:00 614,429 ----a-w C:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
- 2004-08-10 15:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2007-07-31 02:18:34 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
- 2007-10-10 23:55:59 102,400 ------w C:\WINDOWS\system32\occache.dll
+ 2008-08-26 07:24:30 102,912 ------w C:\WINDOWS\system32\occache.dll
- 2004-08-10 15:00:00 116,224 ----a-w C:\WINDOWS\system32\p2p.dll
+ 2006-10-11 16:24:45 153,088 ----a-w C:\WINDOWS\system32\p2p.dll
- 2004-08-10 15:00:00 86,016 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
+ 2006-10-11 16:24:45 104,960 ----a-w C:\WINDOWS\system32\p2pgasvc.dll
- 2004-08-10 15:00:00 312,320 ----a-w C:\WINDOWS\system32\p2pgraph.dll
+ 2006-10-11 16:24:45 313,344 ----a-w C:\WINDOWS\system32\p2pgraph.dll
- 2004-08-10 15:00:00 88,064 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
+ 2006-10-11 16:24:45 116,224 ----a-w C:\WINDOWS\system32\p2pnetsh.dll
- 2004-08-10 15:00:00 526,848 ----a-w C:\WINDOWS\system32\p2psvc.dll
+ 2006-10-11 16:24:45 553,984 ----a-w C:\WINDOWS\system32\p2psvc.dll
- 2008-10-14 03:52:49 53,166 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-16 18:27:06 62,746 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-10-14 03:52:50 380,918 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-16 18:27:06 401,632 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2005-10-29 06:49:42 84,480 ------w C:\WINDOWS\system32\pintool.exe
- 2007-08-14 02:36:12 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-08-26 07:24:30 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2004-08-10 15:00:00 48,640 ----a-w C:\WINDOWS\system32\pnrpnsp.dll
+ 2006-10-11 16:24:45 58,880 ----a-w C:\WINDOWS\system32\pnrpnsp.dll
- 2007-10-29 22:35:13 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2008-05-07 04:55:40 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2005-09-27 21:47:00 233,472 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2cqag.dll
+ 2005-09-27 22:47:00 241,664 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2dvag.dll
+ 2005-09-27 22:42:00 39,936 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2edxx.dll
+ 2005-09-27 21:51:00 40,960 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2erec.dll
+ 2005-09-27 22:41:00 46,080 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2evxx.dll
+ 2005-09-27 22:40:00 376,832 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2evxx.exe
+ 2005-09-27 22:42:00 25,088 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\Ati2mdxx.exe
+ 2005-09-27 22:46:00 1,345,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati2mtag.sys
+ 2005-09-27 22:33:00 2,430,368 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ati3duag.dll
+ 2005-09-28 00:44:00 253,952 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ATIDEMGR.dll
+ 2005-09-14 10:13:00 104,376 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atiicdxx.dat
+ 2005-09-28 01:22:00 307,200 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atiiiexx.dll
+ 2005-09-27 22:15:00 147,456 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atikvmag.dll
+ 2005-09-28 00:03:00 6,680,576 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atioglx1.dll
+ 2005-09-27 23:01:00 4,841,472 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atioglxx.dll
+ 2005-09-27 21:52:00 17,408 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\atitvo32.dll
+ 2005-09-27 22:27:00 602,304 ----a-w C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\B_27289\ativvaxx.dll
+ 2005-08-22 09:06:00 718,464 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSF_CNXT.sys
+ 2005-08-22 09:06:00 1,035,008 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSF_DP.sys
+ 2005-08-22 09:06:00 231,424 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HSFHWATI.sys
+ 2005-08-12 08:01:00 577,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\HXFSetup.exe
+ 2004-03-17 04:00:00 86,016 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\mdmxsdk.dll
+ 2004-03-17 04:04:00 13,059 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\mdmxsdk.sys
+ 2005-06-20 02:57:00 110,592 ----a-w C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\uci32100.dll
+ 2005-08-02 09:58:00 38,016 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\camc6aud.sys
+ 2005-08-02 10:00:00 349,312 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\camc6hal.sys
+ 2005-02-24 14:56:00 16,437 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\CAUDINST.dll
+ 2005-05-12 12:40:00 577,536 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\HXFSetup.exe
+ 2004-08-04 07:08:00 60,288 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\drmk.sys
+ 2004-08-04 07:15:22 140,928 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\ks.sys
+ 2004-08-04 08:56:44 4,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\ksuser.dll
+ 2005-03-22 03:43:15 145,920 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\portcls.sys
+ 2004-08-04 07:08:04 48,640 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\stream.sys
+ 2004-08-10 15:00:00 23,552 ----a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\wdmaud.drv
- 2006-09-26 01:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2003-06-19 00:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2007-04-09 20:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2003-06-19 00:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2007-04-09 20:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
- 2003-06-19 00:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2007-04-09 20:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
- 2003-06-19 00:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2007-04-09 20:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
- 2003-06-19 00:31:48 18,944 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2007-04-09 20:23:54 28,552 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
- 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2006-12-21 00:37:40 176,128 ----a-w C:\WINDOWS\system32\UCI32A16.dll
- 2007-10-10 23:55:59 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-08-26 07:24:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-10-10 23:56:00 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2005-04-27 23:15:36 17,920 ------w C:\WINDOWS\system32\usmt\cobramsg.dll
- 2004-08-10 15:00:00 123,904 ----a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2005-04-28 19:16:29 133,120 ----a-w C:\WINDOWS\system32\usmt\guitrn.dll
+ 2005-04-28 19:16:29 115,200 ------w C:\WINDOWS\system32\usmt\guitrna.dll
- 2004-08-10 15:00:00 4,096 ----a-w C:\WINDOWS\system32\usmt\iconlib.dll
+ 2005-04-27 23:15:45 2,560 ----a-w C:\WINDOWS\system32\usmt\iconlib.dll
- 2004-08-10 15:00:00 19,968 ----a-w C:\WINDOWS\system32\usmt\log.dll
+ 2005-04-28 19:16:29 19,968 ----a-w C:\WINDOWS\system32\usmt\log.dll
- 2004-08-10 15:00:00 201,216 ----a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2005-04-28 19:16:29 274,432 ----a-w C:\WINDOWS\system32\usmt\migism.dll
+ 2005-04-28 19:16:30 261,120 ------w C:\WINDOWS\system32\usmt\migisma.dll
- 2004-08-10 15:00:00 103,424 ----a-w C:\WINDOWS\system32\usmt\migload.exe
+ 2005-04-28 00:12:58 103,424 ----a-w C:\WINDOWS\system32\usmt\migload.exe
- 2004-08-10 15:00:00 240,128 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2005-04-28 00:12:57 245,248 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2005-04-28 00:12:57 241,152 ------w C:\WINDOWS\system32\usmt\migwiza.exe
- 2004-08-10 15:00:00 202,752 ----a-w C:\WINDOWS\system32\usmt\script.dll
+ 2005-04-28 19:16:29 215,552 ----a-w C:\WINDOWS\system32\usmt\script.dll
+ 2005-04-28 19:16:29 199,680 ------w C:\WINDOWS\system32\usmt\scripta.dll
- 2004-08-10 15:00:00 168,960 ----a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2005-04-28 19:16:29 193,024 ----a-w C:\WINDOWS\system32\usmt\sysmod.dll
+ 2005-04-28 19:16:29 173,568 ------w C:\WINDOWS\system32\usmt\sysmoda.dll
- 2007-10-10 23:56:00 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-08-26 07:24:31 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
- 2007-10-10 23:56:00 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-08-26 07:24:31 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
- 2006-10-19 05:47:20 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-25 01:12:58 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-04-15 17:54:19 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
+ 2008-10-16 18:24:40 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2008-10-16 18:24:40 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5aa265c0-4404-3ff0-7ceb-9118c2e0bfd0}]
2008-09-04 04:02 350208 --a------ C:\WINDOWS\system32\nss15.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-11 67128]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-27 344064]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-20 48752]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-10-11 409600]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 368706]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MDDiskProtect.exe"="C:\Program Files\Mediafour\MacDrive\MDDiskProtect.exe" [2005-04-15 106496]
"Mediafour Mac Volume Notifications"="C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE" [2002-12-17 61440]
"DigidesignMMERefresh"="C:\Program Files\Digidesign\Drivers\MMERefresh.exe" [2006-11-14 61440]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-04-03 727288]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 5562368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-05-08 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-11 67128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave7"= Digi32.dll
"MIDI7"= diomidi.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 05:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 17:52 50736 C:\Program Files\Common Files\AOL\1168232905\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2004-10-13 17:04 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-08-13 17:04 5562368 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
--a--c--- 2004-08-24 16:09 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-11-28 22:52 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-28 11:40 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-05-14 15:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 16384]
R0 MDPMGRNT;MDPMGRNT;C:\WINDOWS\system32\drivers\MDPMGRNT.sys [2006-04-30 16640]
R1 MDFSYSNT;MDFSYSNT;C:\WINDOWS\system32\drivers\MDFSYSNT.sys [2006-06-16 212864]
R2 DigiNet;Digidesign Ethernet Support;C:\WINDOWS\system32\DRIVERS\diginet.sys [2006-11-13 11776]
R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 27992]
R2 Synchro Arts License Manager;Synchro Arts License Manager;C:\Program Files\Common Files\License.exe [2002-01-17 28672]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2008-01-26 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - bestbuy.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2005-05-06 04:15]
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-Mediafour Mac Volume Icons - (no file)
MSConfigStartUp-AOL Spyware Protection - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
MSConfigStartUp-My Web Search Bar Search Scope Monitor - C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 19:08:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????9?9?3?7??????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-17 19:10:45
ComboFix-quarantined-files.txt 2008-10-18 02:10:26
ComboFix2.txt 2008-10-16 11:12:46
ComboFix3.txt 2008-10-15 23:37:57
ComboFix4.txt 2008-10-15 04:02:03
ComboFix5.txt 2008-10-18 02:01:51
Pre-Run: 62,894,878,720 bytes free
Post-Run: 62,933,798,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
1498 --- E O F --- 2008-10-17 16:50:45