تقرير أداة الـ ComboFix
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
ComboFix 08-09-20.05 - w 09/21/2008 4:28:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1025.18.1334 [GMT 3:00]
Running from: C:\Documents and Settings\w\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\w\s\w@myspace[1].txt
.
((((((((((((((((((((((((( Files Created from 2008-08-21 to 2008-09-21 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-21 01:34 --------- d-----w C:\Program Files\Common Files\Akamai
2008-09-21 01:32 8,619,552 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-21 01:32 7,784 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-21 01:32 69,468 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-21 01:32 1,654,816 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-21 01:32 --------- d-----w C:\Documents and Settings\w\Application Data\Free Download Manager
2008-09-20 22:48 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\PC Suite
2008-09-20 20:55 --------- d-----w C:\Documents and Settings\w\Application Data\Nokia
2008-09-20 20:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-09-20 20:41 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-09-20 20:41 --------- d-----w C:\Program Files\Nokia
2008-09-20 20:41 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-20 20:41 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-20 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-09-20 19:18 --------- d-----w C:\Documents and Settings\w\Application Data\PC Suite
2008-09-20 19:17 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-20 19:17 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-20 17:18 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-09-19 23:01 --------- d-----w C:\Program Files\nLite
2008-09-18 05:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-18 04:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-18 04:47 --------- d-----w C:\Program Files\Realtek
2008-09-17 23:48 --------- d-----w C:\Program Files\Driver Magician
2008-09-17 21:27 --------- d-----w C:\Program Files\FormatFactory
2008-09-17 20:45 --------- d-----w C:\Program Files\VideoLAN
2008-09-17 19:05 24,944 ----a-w C:\WINDOWS\system32\drivers\GVTDrv.sys
2008-09-17 12:52 77,824 ----a-w C:\WINDOWS\system32\drivers\jraid.sys
2008-09-17 04:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\PassMark
2008-09-17 02:05 --------- d-----w C:\Documents and Settings\w\Application Data\CyberScrub
2008-09-17 02:05 --------- d-----w C:\Documents and Settings\w\Application Data\cleaner
2008-09-15 15:45 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-09-15 13:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winferno
2008-09-15 13:37 --------- d-----w C:\Program Files\PC Wizard 2008
2008-09-15 10:25 --------- d-----w C:\Program Files\Real
2008-09-15 10:25 --------- d-----w C:\Program Files\Common Files\Real
2008-09-14 02:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-14 02:47 --------- d-----w C:\Documents and Settings\w\Application Data\cafe
2008-09-14 02:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\cafe
2008-09-12 00:39 --------- d-----w C:\Program Files\LClock
2008-09-11 07:17 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-09-11 06:40 --------- d-----w C:\Program Files\DivX
2008-09-11 04:43 --------- d-----w C:\Program Files\HighMAT CD Writing Wizard
2008-09-11 00:27 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-09-11 00:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-09-11 00:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-10 09:01 --------- d-----w C:\Documents and Settings\w\Application Data\OtakuSoftware
2008-09-10 08:44 --------- d-----w C:\Documents and Settings\w\Application Data\ViStart
2008-09-10 05:46 --------- d-----w C:\Documents and Settings\w\Application Data\TuneUp Software
2008-09-10 00:35 --------- d-----w C:\Program Files\Intel Desktop Board
2008-09-09 23:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-09 23:11 --------- d-----w C:\Program Files\VAIOXP
2008-09-09 23:11 --------- d-----w C:\Program Files\RocketDock
2008-09-09 23:11 --------- d-----w C:\Program Files\RKLauncher
2008-09-09 17:36 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-09 17:29 --------- d-----w C:\Program Files\Ringz Studio
2008-09-09 15:39 16,851,968 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-09-09 15:07 4,813,824 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-09-05 23:29 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-09-05 00:16 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-09-04 20:09 --------- d-----w C:\Program Files\Debugging Tools for Windows (x86)
2008-09-03 19:00 --------- d-----w C:\Program Files\ma-config.com
2008-09-03 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-09-02 04:00 --------- d-----w C:\Program Files\IIS
2008-09-01 21:32 --------- d-----w C:\Program Files\Marvell
2008-09-01 21:31 --------- d-----w C:\Documents and Settings\w\Application Data\TMP
2008-08-30 19:23 --------- d-----w C:\Documents and Settings\w\Application Data\Thinstall
2008-08-30 17:17 --------- d-----w C:\Program Files\Microsoft IPsec Diagnostic Tool
2008-08-30 17:16 --------- d-----w C:\Documents and Settings\w\Application Data\IPSecureLogs
2008-08-29 05:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 18:58 --------- d-----w C:\Program Files\CPUZ 147
2008-08-27 23:38 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-27 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-27 20:36 --------- d-----w C:\Documents and Settings\w\Application Data\Ahead
2008-08-25 17:25 --------- d-----w C:\Program Files\Microsoft Works
2008-08-25 17:24 --------- d-----w C:\Program Files\MSBuild
2008-08-25 16:32 --------- d-----w C:\Program Files\HP
2008-08-25 12:24 --------- d-----w C:\Program Files\XP LogonUI
2008-08-25 09:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-08-23 16:52 --------- d-----w C:\Documents and Settings\w\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-08-23 16:46 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-23 13:35 --------- d-----w C:\Program Files\Stardock
2008-08-23 11:12 --------- d-----w C:\Program Files\7-Zip
2008-08-23 04:13 --------- d-----w C:\Documents and Settings\w\Application Data\OfficeUpdate12
2008-08-21 12:59 --------- d-----w C:\Program Files\Free Download Manager
2008-08-21 12:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-08-21 10:32 --------- d-----w C:\Documents and Settings\w\Application Data\SystemRequirementsLab
2008-08-21 09:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-08-21 09:05 14,080 ----a-w C:\WINDOWS\system32\drivers\SaiMini.sys
2008-08-19 22:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-19 19:30 --------- d-----w C:\Program Files\MSECache
2008-08-19 10:26 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
2008-08-19 04:05 --------- d-----w C:\Documents and Settings\w\Application Data\Apple Computer
2008-08-19 02:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-19 02:28 --------- d-----w C:\Program Files\QuickTime
2008-08-19 02:27 --------- d-----w C:\Program Files\Apple Software Update
2008-08-19 02:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-18 17:23 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-18 17:09 --------- d-----w C:\Program Files\Windows Defender
2008-08-18 09:14 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-06-30 13:08 330,317 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\Freecell.exe
2007-06-30 13:08 330,318 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\Minesweeper.exe
2007-06-30 13:08 330,317 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\mshearts.exe
2007-06-30 13:08 330,319 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\PurblePlace.exe
2007-06-30 13:08 330,317 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\Shanghai.exe
2007-06-30 13:08 330,316 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\Solitaire.exe
2007-06-30 13:08 330,316 --sha-r C:\WINDOWS\GShellPack\Microsoft Games\Spider.exe
2007-08-21 09:15 19,550,626 --sha-r C:\WINDOWS\system32\ControlPack.exe
2007-06-20 08:31 2,167,296 --sha-r C:\WINDOWS\system32\Desk.exe
2005-10-28 18:22 732,160 --sha-r C:\WINDOWS\system32\gfc.exe
2005-10-28 17:53 997,774 --sha-r C:\WINDOWS\system32\gms.exe
2005-10-28 18:26 731,009 --sha-r C:\WINDOWS\system32\gmsv.exe
2006-02-16 11:49 890,987 --sha-r C:\WINDOWS\system32\gpack Auror.scr
2006-02-28 20:23 1,185,280 --sha-r C:\WINDOWS\system32\GPack Bubbles.scr
2005-04-27 13:39 81,408 --sha-r C:\WINDOWS\system32\GPack FieldLines.scr
2006-03-03 06:12 529,408 --sha-r C:\WINDOWS\system32\GPack Mystify.scr
2005-04-27 13:39 57,344 --sha-r C:\WINDOWS\system32\GPack Plasma.scr
2006-02-28 20:51 529,408 --sha-r C:\WINDOWS\system32\GPack Ribbons.scr
2005-04-27 13:39 69,632 --sha-r C:\WINDOWS\system32\GPack SolarWinds.scr
2005-10-28 18:24 960,385 --sha-r C:\WINDOWS\system32\gpr.exe
2005-10-28 18:25 705,422 --sha-r C:\WINDOWS\system32\gsig.exe
2005-10-28 18:00 766,832 --sha-r C:\WINDOWS\system32\gslt.exe
2005-10-28 17:56 736,129 --sha-r C:\WINDOWS\system32\gsp.exe
2006-05-28 07:37 36,864 --sha-r C:\WINDOWS\system32\VisualTaskTips.exe
2007-04-25 05:15 1,009,152 --sha-r C:\WINDOWS\system32\VisualToolTip.exe
2006-03-23 19:45 2,433,024 --sha-r C:\WINDOWS\system32\mui\
0c0a\Cursors.exe
2005-09-15 12:30 2,359,296 --sha-r C:\WINDOWS\system32\mui\
0c0a\run.exe
2007-03-29 01:35 228,525 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers0.exe
2007-03-29 01:37 172,537 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers1.exe
2007-03-29 01:41 152,909 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers10.exe
2007-03-29 01:41 210,310 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers11.exe
2007-03-29 01:41 204,410 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers12.exe
2007-03-29 01:42 220,781 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers13.exe
2007-03-29 01:42 409,400 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers14.exe
2007-03-29 01:42 485,825 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers15.exe
2007-03-29 01:43 126,803 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers16.exe
2007-03-29 01:43 90,275 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers17.exe
2007-03-29 01:43 96,042 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers18.exe
2007-03-29 10:48 232,604 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers19.exe
2007-03-29 01:37 167,807 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers2.exe
2007-06-20 15:10 189,049 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers20.exe
2007-06-20 15:10 174,231 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers21.exe
2007-06-20 15:11 156,033 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers22.exe
2007-06-20 15:14 200,503 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers23.exe
2007-06-20 15:23 222,615 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers24.exe
2007-06-20 15:23 178,552 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers25.exe
2007-06-20 15:26 312,710 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers26.exe
2007-06-20 15:26 297,352 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers27.exe
2007-06-20 15:27 268,346 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers28.exe
2007-06-20 15:27 231,000 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers29.exe
2007-03-29 01:37 236,423 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers3.exe
2007-06-20 15:28 272,014 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers30.exe
2007-06-20 15:33 211,922 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers31.exe
2007-06-20 15:28 205,414 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers32.exe
2007-06-20 15:34 195,560 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers33.exe
2007-06-20 15:35 257,213 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers34.exe
2007-06-20 15:35 240,530 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers35.exe
2007-06-20 15:35 345,679 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers36.exe
2007-06-20 15:39 233,424 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers37.exe
2007-06-20 15:39 186,406 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers38.exe
2007-06-20 15:39 179,637 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers39.exe
2007-03-29 01:38 184,489 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers4.exe
2007-03-29 01:38 280,148 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers5.exe
2007-03-29 01:39 153,250 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers6.exe
2007-03-29 01:39 117,405 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers7.exe
2007-03-29 01:40 188,106 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers8.exe
2007-03-29 01:40 164,351 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\Wallpapers9.exe
2007-03-30 01:06 139,368 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\aero\aero.exe
2007-03-30 01:07 117,435 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\RED\RED.exe
2007-03-30 01:07 116,794 --sha-r C:\WINDOWS\system32\mui\
0c0a\AutoPlay\Docs\UMBER\UMBER.exe
2007-07-01 19:01 11,179,752 --sha-w C:\WINDOWS\system32\oobe\html\iconnect\Root.exe
2007-06-21 13:35 258,048 --sha-r C:\WINDOWS\system32\smi\QTAddressBar.exe
2007-06-19 09:33 344,064 --sha-r C:\WINDOWS\system32\smi\QTTabBar.exe
.
(((((((((((((((((((((((((((((
snapshot@Thu 09-04-2008_ 5.12.40.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-30 12:39:03 752,504 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:38:55 752,504 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\update.exe
- 2007-11-30 12:39:04 380,792 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\updspapi.dll
+ 2007-11-30 12:38:55 380,792 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\updspapi.dll
+ 2007-11-30 12:39:01 231,288 -c----w C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe
+ 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB938464$\spuninst\updspapi.dll
+ 2007-11-30 12:39:01 26,488 -c----w C:\WINDOWS\$NtUninstallKB950974$\spcustom.dll
+ 2007-11-30 12:39:01 17,784 -c----w C:\WINDOWS\$NtUninstallKB950974$\spmsg.dll
+ 2007-11-30 12:39:01 231,288 -c----w C:\WINDOWS\$NtUninstallKB950974$\spuninst.exe
+ 2007-11-30 12:38:55 752,504 -c----w C:\WINDOWS\$NtUninstallKB950974$\update.exe
+ 2007-11-30 12:38:55 380,792 -c----w C:\WINDOWS\$NtUninstallKB950974$\updspapi.dll
+ 2007-11-30 12:39:01 26,488 -c----w C:\WINDOWS\$NtUninstallKB951066$\spcustom.dll
+ 2007-11-30 12:39:01 17,784 -c----w C:\WINDOWS\$NtUninstallKB951066$\spmsg.dll
+ 2007-11-30 12:39:01 231,288 -c----w C:\WINDOWS\$NtUninstallKB951066$\spuninst.exe
+ 2007-12-03 15:25:13 752,504 -c----w C:\WINDOWS\$NtUninstallKB951066$\update.exe
+ 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB951066$\updspapi.dll
+ 2007-11-30 11:18:09 26,488 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\spcustom.dll
+ 2007-11-30 11:18:09 17,784 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\spmsg.dll
+ 2007-11-30 11:18:09 231,288 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst.exe
- 2008-03-27 10:40:24 60,416 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\tzchange.exe
+ 2008-04-14 18:30:06 60,416 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\tzchange.exe
+ 2007-11-30 12:39:03 752,504 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\update.exe
+ 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\updspapi.dll
- 2007-11-30 12:39:03 752,504 -c----w C:\WINDOWS\$NtUninstallKB951748$\update.exe
+ 2007-11-30 12:38:55 752,504 -c----w C:\WINDOWS\$NtUninstallKB951748$\update.exe
- 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB951748$\updspapi.dll
+ 2007-11-30 12:38:55 380,792 -c----w C:\WINDOWS\$NtUninstallKB951748$\updspapi.dll
- 2007-11-30 12:38:55 752,504 -c----w C:\WINDOWS\$NtUninstallKB951978$\update.exe
+ 2007-11-30 12:39:03 752,504 -c----w C:\WINDOWS\$NtUninstallKB951978$\update.exe
- 2007-11-30 12:38:55 380,792 -c----w C:\WINDOWS\$NtUninstallKB951978$\updspapi.dll
+ 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB951978$\updspapi.dll
+ 2007-11-30 11:18:09 26,488 -c----w C:\WINDOWS\$NtUninstallKB952287$\spcustom.dll
+ 2007-11-30 11:18:09 17,784 -c----w C:\WINDOWS\$NtUninstallKB952287$\spmsg.dll
+ 2007-11-30 11:18:09 231,288 -c----w C:\WINDOWS\$NtUninstallKB952287$\spuninst.exe
+ 2007-11-30 11:18:13 752,504 -c----w C:\WINDOWS\$NtUninstallKB952287$\update.exe
+ 2007-11-30 11:18:13 380,792 -c----w C:\WINDOWS\$NtUninstallKB952287$\updspapi.dll
+ 2007-11-30 12:39:01 26,488 -c----w C:\WINDOWS\$NtUninstallKB952954$\spcustom.dll
+ 2007-11-30 12:39:01 17,784 -c----w C:\WINDOWS\$NtUninstallKB952954$\spmsg.dll
+ 2007-11-30 12:39:01 231,288 -c----w C:\WINDOWS\$NtUninstallKB952954$\spuninst.exe
+ 2007-11-30 12:39:03 752,504 -c----w C:\WINDOWS\$NtUninstallKB952954$\update.exe
+ 2007-11-30 12:39:04 380,792 -c----w C:\WINDOWS\$NtUninstallKB952954$\updspapi.dll
+ 2006-11-02 04:22:52 51,680 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\Kmdfcustom.dll
+ 2006-10-08 18:51:14 221,488 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe
+ 2006-10-08 18:51:14 379,184 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\updspapi.dll
+ 2008-09-09 23:11:55 126,976 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__78a0cde69b47ca25\Interop.SHDocVw.dll
+ 2008-09-09 23:11:56 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Interop.Shell32\1.0.0.0__78a0cde69b47ca25\Interop.Shell32.dll
+ 2008-09-09 23:11:54 98,304 ----a-w C:\WINDOWS\assembly\GAC_MSIL\QTAddressBar\1.0.0.0__78a0cde69b47ca25\QTAddressBar.dll
+ 2008-09-09 23:11:55 405,504 ----a-w C:\WINDOWS\assembly\GAC_MSIL\QTTabBar\1.0.0.0__78a0cde69b47ca25\QTTabBar.dll
+ 2008-06-24 05:05:12 455,744 ----a-w C:\WINDOWS\Downloaded Program Files\wlscBase.dll
- 2004-08-04 12:00:00 28,672 ----a-w C:\WINDOWS\ehome\custsat.dll
+ 2008-04-14 18:29:34 33,792 ----a-w C:\WINDOWS\ehome\custsat.dll
+ 2008-09-21 01:27:54 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\DEFAUL~1.DAT
+ 2008-04-14 18:29:46 183,296 ----a-w C:\WINDOWS\GShellPack\Backup\accwiz.exe
+ 2008-04-14 18:29:48 98,304 ----a-w C:\WINDOWS\GShellPack\Backup\ahui.exe
+ 2006-10-18 18:47:08 276,992 ----a-w C:\WINDOWS\GShellPack\Backup\Audiodev.dll
+ 2008-04-14 18:29:34 1,025,024 ----a-w C:\WINDOWS\GShellPack\Backup\browseui.dll
+ 2008-04-14 18:29:34 84,480 ----a-w C:\WINDOWS\GShellPack\Backup\cabview.dll
+ 2004-08-04 12:00:00 114,688 ----a-w C:\WINDOWS\GShellPack\Backup\calc.exe
+ 2004-08-04 12:00:00 80,384 ----a-w C:\WINDOWS\GShellPack\Backup\Charmap.exe
+ 2008-04-14 18:29:50 64,512 ----a-w C:\WINDOWS\GShellPack\Backup\cleanmgr.exe
+ 2008-04-14 18:29:50 389,120 ----a-w C:\WINDOWS\GShellPack\Backup\cmd.exe
+ 2008-04-14 18:29:34 345,600 ----a-w C:\WINDOWS\GShellPack\Backup\cmdial32.dll
+ 2008-04-14 18:29:34 184,320 ----a-w C:\WINDOWS\GShellPack\Backup\cmprops.dll
+ 2008-04-14 18:29:34 617,472 ----a-w C:\WINDOWS\GShellPack\Backup\comctl32.dll
+ 2008-04-14 18:29:34 252,928 ----a-w C:\WINDOWS\GShellPack\Backup\compatui.dll
+ 2004-08-04 12:00:00 67,072 ----a-w C:\WINDOWS\GShellPack\Backup\console.dll
+ 2008-04-14 18:29:34 260,608 ----a-w C:\WINDOWS\GShellPack\Backup\credui.dll
+ 2008-04-14 18:29:34 326,656 ----a-w C:\WINDOWS\GShellPack\Backup\cscui.dll
+ 2004-08-04 12:00:00 16,384 ----a-w C:\WINDOWS\GShellPack\Backup\deskadp.dll
+ 2004-08-04 12:00:00 16,896 ----a-w C:\WINDOWS\GShellPack\Backup\deskmon.dll
+ 2008-04-14 18:29:34 282,112 ----a-w C:\WINDOWS\GShellPack\Backup\devmgr.dll
+ 2008-04-14 18:29:36 183,296 ----a-w C:\WINDOWS\GShellPack\Backup\els.dll
+ 2008-04-14 18:29:54 1,031,168 ----a-w C:\WINDOWS\GShellPack\Backup\explorer.exe
+ 2008-04-14 18:29:36 333,312 ----a-w C:\WINDOWS\GShellPack\Backup\filemgmt.dll
+ 2008-07-03 02:02:05 307,712 ----a-w C:\WINDOWS\GShellPack\Backup\firefox.exe
+ 2008-04-14 18:29:36 381,952 ----a-w C:\WINDOWS\GShellPack\Backup\Fontext.dll
+ 2004-08-04 12:00:00 55,808 ----a-w C:\WINDOWS\GShellPack\Backup\Freecell.exe
+ 2008-04-14 18:29:54 769,024 ----a-w C:\WINDOWS\GShellPack\Backup\helpctr.exe
+ 2008-04-14 18:29:36 330,752 ----a-w C:\WINDOWS\GShellPack\Backup\hnetwiz.dll
+ 2008-04-14 18:29:36 142,848 ----a-w C:\WINDOWS\GShellPack\Backup\hotplug.dll
+ 2004-08-04 12:00:00 28,160 ----a-w C:\WINDOWS\GShellPack\Backup\hypertrm.exe
+ 2008-04-14 18:29:54 211,968 ----a-w C:\WINDOWS\GShellPack\Backup\icwconn1.exe
+ 2008-04-14 18:29:54 86,016 ----a-w C:\WINDOWS\GShellPack\Backup\icwconn2.exe
+ 2008-06-23 16:15:19 230,400 ----a-w C:\WINDOWS\GShellPack\Backup\ieaksie.dll
+ 2008-06-23 09:18:36 625,664 ----a-w C:\WINDOWS\GShellPack\Backup\iexplore.exe
+ 2004-08-04 12:00:00 110,592 ----a-w C:\WINDOWS\GShellPack\Backup\inetcplc.dll
+ 2008-04-14 18:29:38 150,016 ----a-w C:\WINDOWS\GShellPack\Backup\keymgr.dll
+ 2008-04-14 18:29:56 515,072 ----a-w C:\WINDOWS\GShellPack\Backup\logonui.exe
+ 2008-04-14 18:29:56 72,704 ----a-w C:\WINDOWS\GShellPack\Backup\magnify.exe
+ 2008-04-14 18:29:38 118,272 ----a-w C:\WINDOWS\GShellPack\Backup\mdminst.dll
+ 2008-04-14 18:29:56 103,936 ----a-w C:\WINDOWS\GShellPack\Backup\migload.exe
+ 2004-08-04 12:00:00 51,712 ----a-w C:\WINDOWS\GShellPack\Backup\migpwd.exe
+ 2008-04-14 18:29:56 243,200 ----a-w C:\WINDOWS\GShellPack\Backup\migwiz.exe
+ 2008-04-14 18:29:38 206,336 ----a-w C:\WINDOWS\GShellPack\Backup\mobsync.dll
+ 2008-04-14 18:29:58 142,848 ----a-w C:\WINDOWS\GShellPack\Backup\mobsync.exe
+ 2008-04-13 19:15:32 216,064 ----a-w C:\WINDOWS\GShellPack\Backup\moricons.dll
+ 2008-04-14 18:29:58 3,558,912 ----a-w C:\WINDOWS\GShellPack\Backup\moviemk.exe
+ 2008-04-14 18:29:58 169,984 ----a-w C:\WINDOWS\GShellPack\Backup\msconfig.exe
+ 2008-04-14 18:29:38 995,840 ----a-w C:\WINDOWS\GShellPack\Backup\msgina.dll
+ 2004-08-04 12:00:00 127,488 ----a-w C:\WINDOWS\GShellPack\Backup\Mshearts.exe
+ 2008-06-24 07:15:22 3,592,192 ----a-w C:\WINDOWS\GShellPack\Backup\mshtml.dll
+ 2008-04-14 18:29:38 2,843,136 ----a-w C:\WINDOWS\GShellPack\Backup\msi.dll
+ 2008-04-14 18:29:38 51,712 ----a-w C:\WINDOWS\GShellPack\Backup\msident.dll
+ 2008-04-14 18:29:38 247,296 ----a-w C:\WINDOWS\GShellPack\Backup\msieftp.dll
+ 2008-04-14 18:29:58 59,904 ----a-w C:\WINDOWS\GShellPack\Backup\msimn.exe
+ 2004-08-04 12:00:00 39,936 ----a-w C:\WINDOWS\GShellPack\Backup\msinfo32.exe
+ 2008-04-14 18:09:26 2,455,040 ----a-w C:\WINDOWS\GShellPack\Backup\msoeres.dll
+ 2008-04-14 18:30:00 342,016 ----a-w C:\WINDOWS\GShellPack\Backup\mspaint.exe
+ 2008-04-14 18:29:40 274,944 ----a-w C:\WINDOWS\GShellPack\Backup\mstask.dll
+ 2008-04-14 18:29:56 677,888 ----a-w C:\WINDOWS\GShellPack\Backup\mstsc.exe
+ 2008-04-14 18:29:38 2,061,824 ----a-w C:\WINDOWS\GShellPack\Backup\mstscax.dll
+ 2004-08-04 12:00:00 90,112 ----a-w C:\WINDOWS\GShellPack\Backup\mycomput.dll
+ 2008-04-14 18:29:40 90,112 ----a-w C:\WINDOWS\GShellPack\Backup\Mydocs.dll
+ 2008-04-14 18:30:00 54,272 ----a-w C:\WINDOWS\GShellPack\Backup\narrator.exe
+ 2008-04-14 18:29:40 136,192 ----a-w C:\WINDOWS\GShellPack\Backup\netid.dll
+ 2008-04-14 18:29:40 872,448 ----a-w C:\WINDOWS\GShellPack\Backup\netplwiz.dll
+ 2008-04-14 18:29:40 1,694,720 ----a-w C:\WINDOWS\GShellPack\Backup\netshell.dll
+ 2008-04-14 18:29:40 247,296 ----a-w C:\WINDOWS\GShellPack\Backup\newdev.dll
+ 2008-04-14 18:30:00 69,120 ----a-w C:\WINDOWS\GShellPack\Backup\notepad.exe
+ 2008-04-14 18:30:00 1,204,224 ----a-w C:\WINDOWS\GShellPack\Backup\ntbackup.exe
+ 2008-04-14 18:12:16 2,025,472 ----a-w C:\WINDOWS\GShellPack\Backup\ntkrnlpa.exe
+ 2008-04-14 18:12:10 2,146,816 ----a-w C:\WINDOWS\GShellPack\Backup\ntoskrnl.exe
+ 2008-04-14 18:29:42 142,848 ----a-w C:\WINDOWS\GShellPack\Backup\ntshrui.dll
+ 2008-06-23 16:15:21 102,912 ----a-w C:\WINDOWS\GShellPack\Backup\occache.dll
+ 2008-04-14 18:30:00 32,768 ----a-w C:\WINDOWS\GShellPack\Backup\odbcad32.exe
+ 2008-04-14 18:30:00 59,392 ----a-w C:\WINDOWS\GShellPack\Backup\oobebaln.exe
+ 2008-04-14 18:30:02 215,552 ----a-w C:\WINDOWS\GShellPack\Backup\osk.exe
+ 2008-04-14 18:29:42 171,520 ----a-w C:\WINDOWS\GShellPack\Backup\photowiz.dll
+ 2008-04-14 18:29:42 558,080 ----a-w C:\WINDOWS\GShellPack\Backup\printui.dll
+ 2008-04-14 18:29:42 658,944 ----a-w C:\WINDOWS\GShellPack\Backup\rasdlg.dll
+ 2008-04-14 18:30:02 56,832 ----a-w C:\WINDOWS\GShellPack\Backup\rasphone.exe
+ 2008-04-14 18:30:02 35,840 ----a-w C:\WINDOWS\GShellPack\Backup\rcimlby.exe
+ 2008-04-14 18:30:02 146,944 ----a-w C:\WINDOWS\GShellPack\Backup\regedit.exe
+ 2008-04-14 18:29:42 60,416 ----a-w C:\WINDOWS\GShellPack\Backup\remotepg.dll
+ 2008-04-14 18:30:02 385,536 ----a-w C:\WINDOWS\GShellPack\Backup\rstrui.exe
+ 2008-04-14 18:30:02 76,800 ----a-w C:\WINDOWS\GShellPack\Backup\rtcshare.exe
+ 2008-04-14 18:29:42 55,296 ----a-w C:\WINDOWS\GShellPack\Backup\sendmail.dll
+ 2008-04-14 18:29:42 984,064 ----a-w C:\WINDOWS\GShellPack\Backup\setupapi.dll
+ 2008-04-14 18:29:42 139,264 ----a-w C:\WINDOWS\GShellPack\Backup\sfc_os.dll
+ 2008-04-14 18:09:20 547,840 ----a-w C:\WINDOWS\GShellPack\Backup\shdoclc.dll
+ 2008-04-14 18:29:42 1,499,136 ----a-w C:\WINDOWS\GShellPack\Backup\shdocvw.dll
+ 2008-04-14 18:29:42 8,446,976 ----a-w C:\WINDOWS\GShellPack\Backup\shell32.dll
+ 2008-04-14 18:29:42 438,272 ----a-w C:\WINDOWS\GShellPack\Backup\shimgvw.dll
+ 2008-04-14 18:29:42 474,112 ----a-w C:\WINDOWS\GShellPack\Backup\shlwapi.dll
+ 2008-04-14 18:30:04 131,072 ----a-w C:\WINDOWS\GShellPack\Backup\sndrec32.exe
+ 2004-08-04 12:00:00 139,264 ----a-w C:\WINDOWS\GShellPack\Backup\sndvol32.exe
+ 2004-08-04 12:00:00 57,344 ----a-w C:\WINDOWS\GShellPack\Backup\sol.exe
+ 2008-04-14 18:30:04 538,624 ----a-w C:\WINDOWS\GShellPack\Backup\spider.exe
+ 2008-04-14 18:29:44 725,566 ----a-w C:\WINDOWS\GShellPack\Backup\srchui.dll
+ 2008-04-14 18:29:44 239,616 ----a-w C:\WINDOWS\GShellPack\Backup\srrstr.dll
+ 2008-04-14 18:29:44 136,192 ----a-w C:\WINDOWS\GShellPack\Backup\sti_ci.dll
+ 2008-04-14 18:29:44 121,856 ----a-w C:\WINDOWS\GShellPack\Backup\st.dll
+ 2004-08-04 12:00:00 51,200 ----a-w C:\WINDOWS\GShellPack\Backup\syncapp.exe
+ 2008-04-14 18:29:44 191,488 ----a-w C:\WINDOWS\GShellPack\Backup\syncui.dll
+ 2008-04-14 18:30:06 105,984 ----a-w C:\WINDOWS\GShellPack\Backup\sysocmgr.exe
+ 2008-04-14 18:29:44 988,160 ----a-w C:\WINDOWS\GShellPack\Backup\syssetup.dll
+ 2004-08-04 12:00:00 78,848 ----a-w C:\WINDOWS\GShellPack\Backup\tapiui.dll
+ 2008-04-14 18:30:06 139,264 ----a-w C:\WINDOWS\GShellPack\Backup\taskmgr.exe
+ 2008-04-14 18:29:44 384,000 ----a-w C:\WINDOWS\GShellPack\Backup\themeui.dll
+ 2008-04-14 18:29:44 239,104 ----a-w C:\WINDOWS\GShellPack\Backup\upnpui.dll
+ 2008-06-23 16:15:22 105,984 ----a-w C:\WINDOWS\GShellPack\Backup\url.dll
+ 2008-06-23 16:15:22 1,159,680 ----a-w C:\WINDOWS\GShellPack\Backup\urlmon.dll
+ 2008-04-14 18:29:44 578,048 ----a-w C:\WINDOWS\GShellPack\Backup\user32.dll
+ 2008-04-14 18:30:06 50,176 ----a-w C:\WINDOWS\GShellPack\Backup\utilman.exe
+ 2008-04-14 18:30:06 46,080 ----a-w C:\WINDOWS\GShellPack\Backup\wab.exe
+ 2008-04-14 18:06:14 247,808 ----a-w C:\WINDOWS\GShellPack\Backup\wab32res.dll
+ 2008-06-23 16:15:22 233,472 ----a-w C:\WINDOWS\GShellPack\Backup\webcheck.dll
+ 2008-04-14 18:30:08 431,104 ----a-w C:\WINDOWS\GShellPack\Backup\wiaacmgr.exe
+ 2008-04-14 18:29:44 462,848 ----a-w C:\WINDOWS\GShellPack\Backup\wiadefui.dll
+ 2008-04-14 18:29:44 588,288 ----a-w C:\WINDOWS\GShellPack\Backup\wiashext.dll
+ 2008-06-23 16:15:22 826,368 ----a-w C:\WINDOWS\GShellPack\Backup\wininet.dll
+ 2004-08-04 12:00:00 119,808 ----a-w C:\WINDOWS\GShellPack\Backup\winmine.exe
+ 2007-09-20 15:34:22 936,960 ----a-w C:\WINDOWS\GShellPack\Backup\WinRAR.exe
+ 2008-04-14 18:29:44 331,264 ----a-w C:\WINDOWS\GShellPack\Backup\winsrv.dll
+ 2006-12-01 09:03:08 63,488 ----a-w C:\WINDOWS\GShellPack\Backup\wmplayer.exe
+ 2008-04-14 18:30:08 214,016 ----a-w C:\WINDOWS\GShellPack\Backup\wordpad.exe
+ 2008-04-14 18:30:08 32,256 ----a-w C:\WINDOWS\GShellPack\Backup\wpabaln.exe
+ 2008-04-14 18:29:46 599,040 ----a-w C:\WINDOWS\GShellPack\Backup\wsecedit.dll
+ 2008-07-18 19:10:42 53,448 ----a-w C:\WINDOWS\GShellPack\Backup\wuauclt.exe
+ 2008-04-14 18:30:08 164,864 ----a-w C:\WINDOWS\GShellPack\Backup\wuauclt1.exe
+ 2008-04-14 18:29:46 182,784 ----a-w C:\WINDOWS\GShellPack\Backup\wuaueng1.dll
+ 2004-08-04 12:00:00 32,256 ----a-w C:\WINDOWS\GShellPack\Backup\wupdmgr.exe
+ 2008-04-13 21:05:08 186,880 ----a-w C:\WINDOWS\GShellPack\Backup\xpsp1res.dll
+ 2008-04-13 21:05:42 5,742,080 ----a-w C:\WINDOWS\GShellPack\Backup\xpsp2res.dll
+ 2008-04-14 18:29:46 338,432 ----a-w C:\WINDOWS\GShellPack\Backup\zipfldr.dll
+ 2008-09-11 10:35:22 118,803 ----a-w C:\WINDOWS\GShellPack\LoadPack.exe
+ 2008-09-11 10:34:32 11,776 ----a-w C:\WINDOWS\GShellPack\regsvr32.exe
+ 2008-04-14 18:29:56 6,501,376 ----a-w C:\WINDOWS\GShellPack\RES\logonui.exe
+ 2005-05-07 11:28:56 881,152 ----a-w C:\WINDOWS\GShellPack\RES\ResHacker.exe
+ 2007-06-07 13:01:20 16,335 ----a-w C:\WINDOWS\GShellPack\Resources\logonui.exe\1.bin
+ 2007-04-17 21:09:56 2,641 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_1.bin
+ 2007-04-17 21:09:56 3,196 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_10.bin
+ 2007-04-17 21:09:56 2,246 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_11.bin
+ 2007-04-17 21:09:56 2,761 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_4.bin
+ 2007-04-17 21:09:56 2,296 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_5.bin
+ 2007-04-17 21:09:56 1,983 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_6.bin
+ 2007-04-17 21:09:56 1,603 ----a-w C:\WINDOWS\GShellPack\Resources\wscui.cpl\Data_8.bin
+ 2008-09-11 10:35:44 57,779 ----a-w C:\WINDOWS\GShellPack\SilentLoad.exe
+ 2002-12-08 12:37:30 69,632 ----a-w C:\WINDOWS\GShellPack\Tools\MoveEx.exe
+ 2005-05-07 11:28:56 881,152 ----a-w C:\WINDOWS\GShellPack\Tools\ResHacker.exe
+ 2008-09-11 10:36:09 211,257 ----a-w C:\WINDOWS\GShellPack\uninst.exe
+ 2007-03-06 00:57:32 22,752 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spcustom.dll
+ 2007-03-06 00:57:33 14,560 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spmsg.dll
+ 2007-03-06 00:57:38 213,216 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst.exe
+ 2007-03-06 00:57:55 712,928 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\update.exe
+ 2007-03-06 00:58:46 369,376 -c----w C:\WINDOWS\ie7updates\KB938127-v2-IE7\updspapi.dll
- 2008-04-23 04:16:31 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
+ 2007-08-13 15:39:00 123,904 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
- 2008-04-23 04:16:31 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2007-08-13 15:35:46 346,624 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
- 2008-04-23 04:16:31 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
+ 2007-08-13 15:35:38 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
- 2008-04-23 04:16:31 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
+ 2007-08-13 15:54:10 131,584 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
- 2008-04-22 07:38:04 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2007-08-13 15:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
- 2008-04-23 04:16:31 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
+ 2007-08-13 15:39:26 152,064 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
- 2008-04-23 04:16:31 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
+ 2007-08-13 15:39:54 229,376 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
- 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
+ 2007-08-13 14:56:54 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
- 2008-04-23 04:16:31 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2007-08-13 15:39:50 382,976 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
- 2008-04-23 04:16:32 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
+ 2007-08-13 15:39:10 43,008 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
- 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
+ 2007-08-13 15:39:10 13,312 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
- 2008-04-22 07:38:13 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
+ 2007-08-13 15:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
- 2008-04-23 04:16:32 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
+ 2007-08-13 15:54:10 27,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
- 2008-04-23 19:16:34 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
+ 2007-08-13 15:54:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
- 2008-04-23 04:16:33 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
+ 2007-08-13 15:54:10 475,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
- 2008-04-23 04:16:33 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
+ 2007-08-13 15:44:26 192,000 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
- 2008-04-23 04:16:33 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
+ 2007-08-13 15:54:10 670,720 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
- 2008-04-23 04:16:33 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
+ 2007-08-13 15:44:06 101,376 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
- 2008-04-23 04:16:33 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-08-13 15:36:12 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 00:57:32 22,752 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spcustom.dll
+ 2007-03-06 00:57:33 14,560 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spmsg.dll
+ 2007-03-06 00:57:38 213,216 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst.exe
+ 2007-03-06 00:57:56 712,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\update.exe
+ 2007-03-06 00:58:46 369,376 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\updspapi.dll
- 2008-04-23 04:16:33 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
+ 2007-08-13 15:44:30 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
- 2008-04-23 04:16:33 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
+ 2007-08-13 15:54:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
- 2008-04-23 04:16:33 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
+ 2007-08-13 15:54:10 231,424 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
- 2008-04-23 04:16:33 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2007-08-13 15:54:10 818,688 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2006-10-26 17:55:38 138,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-10-27 12:16:36 46,864 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
- 2008-04-21 16:52:29 350,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2007-08-28 20:16:00 350,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2008-09-20 20:41:21 10,134 ----a-r C:\WINDOWS\Installer\{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}\ARPPRODUCTICON.exe
+ 2008-09-20 19:41:45 3,262 ----a-r C:\WINDOWS\Installer\{2A0A6470-FD0F-4F45-9B11-85F3167DB943}\ARPPRODUCTICON.exe
+ 2008-09-20 19:41:37 10,134 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\ARPPRODUCTICON.exe
+ 2008-09-20 19:41:37 458,752 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\NewShortcut16_F7578A24A4B240E4BA057EF931EB25B5.exe
+ 2008-09-20 19:41:37 8,854 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
+ 2008-09-20 19:41:37 458,752 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\NewShortcut20_F7578A24A4B240E4BA057EF931EB25B5.exe
+ 2008-09-20 19:41:37 8,854 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\NewShortcut21_E2CBBE559A074AF98E8596196B075190.exe
+ 2008-09-20 19:41:37 8,854 ----a-r C:\WINDOWS\Installer\{48110A46-A3A4-481E-8230-7873B7F4C696}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
+ 2008-09-11 07:17:10 25,214 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\ARPPRODUCTICON.exe
+ 2008-09-11 07:17:10 25,214 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\CPL_DTSC.exe
+ 2008-09-11 07:17:10 25,214 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\CPL_SC.exe
+ 2008-09-11 07:17:10 25,214 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\HCG_SC.exe
+ 2008-09-11 07:17:10 4,846 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\MouseUG.exe
+ 2008-09-11 07:17:10 29,926 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut1_6463554370E7436D8D6D4A721595029E.exe
+ 2008-09-11 07:17:10 29,926 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut2_6463554370E7436D8D6D4A721595029E.exe
+ 2008-09-11 07:17:10 65,536 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut3_4748AC220AD3439FA5EECE4BB6C12AAC.exe
+ 2008-09-11 07:17:10 65,536 ----a-r C:\WINDOWS\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut4_66A9D30D14644C7FB2F3507DADAF2595.exe
+ 2008-09-17 21:27:09 15,086 ----a-r C:\WINDOWS\Installer\{7D5E6E9C-0C9A-49CB-94ED-F0C8C14769BE}\controlPanelIcon.exe
+ 2008-09-17 21:27:10 10,134 ----a-r C:\WINDOWS\Installer\{7D5E6E9C-0C9A-49CB-94ED-F0C8C14769BE}\SystemFolder_msiexec.exe
- 2008-08-25 17:27:15 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-09-09 18:54:49 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-08-25 17:27:17 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-09-09 18:54:49 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-08-25 17:27:16 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-09-09 18:54:49 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-08-25 17:27:16 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-09-09 18:54:49 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-08-25 17:27:17 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-09 18:54:49 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-08-25 17:27:17 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-09-09 18:54:49 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-25 17:27:18 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-09-09 18:54:50 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-08-25 17:27:16 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-09-09 18:54:49 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-08-25 17:27:17 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-09-09 18:54:49 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-25 17:27:17 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-09-09 18:54:49 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-08-25 17:27:18 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-09-09 18:54:49 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-25 17:27:16 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-09-09 18:54:49 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-20 06:41:19 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0401-0000-0000000FF1CE}\misc.exe
+ 2008-09-14 02:51:49 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0401-0000-0000000FF1CE}\misc.exe
- 2008-08-20 06:41:30 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-09-06 14:33:07 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-09-20 20:42:13 15,086 ----a-r C:\WINDOWS\Installer\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\ARPPRODUCTICON.exe
+ 2008-09-20 19:41:59 3,262 ----a-r C:\WINDOWS\Installer\{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}\ARPPRODUCTICON.exe
- 2008-08-03 03:14:55 352,256 ---ha-w C:\WINDOWS\repair\ntuser.dat
+ 2008-09-17 17:44:48 364,544 ---ha-w C:\WINDOWS\repair\ntuser.dat
+ 2002-12-09 09:06:34 378,880 ----a-w C:\WINDOWS\Resources\Themes\Continuum\Shell\NormalColor\shellstyle.dll
+ 2008-09-12 02:07:45 729,088 ----a-w C:\WINDOWS\Resources\Themes\Contrast\Shell\normalcolor\shellstyle.dll
+ 2008-09-12 02:08:22 756,736 ----a-w C:\WINDOWS\Resources\Themes\DarkRealm\Shell\NormalColor\shellstyle.dll
+ 2002-06-02 16:09:18 376,832 ----a-w C:\WINDOWS\Resources\Themes\Evening Mist\Shell\NormalColor\shellstyle.dll
+ 2008-09-12 02:06:26 749,568 ----a-w C:\WINDOWS\Resources\Themes\llics\Shell\NormalColor\shellstyle.dll
+ 2004-08-25 13:41:34 372,736 ----a-w C:\WINDOWS\Resources\Themes\Theme_3\Royale-Theme\Shell\llic\Shellstyle.dll
+ 2004-08-25 13:41:32 372,736 ----a-w C:\WINDOWS\Resources\Themes\Theme_3\Royale-Theme\Shell\NormalColor\l_ss.dll
+ 2004-08-25 13:41:34 372,736 ----a-w C:\WINDOWS\Resources\Themes\Theme_3\RoyaleNoir-theme\Shell\llic\Shellstyle.dll
+ 2004-08-25 13:41:32 372,736 ----a-w C:\WINDOWS\Resources\Themes\Theme_3\RoyaleNoir-theme\Shell\NormalColor\l_ss.dll
+ 2007-03-21 11:45:26 1,111,358 ----a-w C:\WINDOWS\Resources\Themes\Theme_3\UXTheme Multi-Patcher 5.5.exe
+ 2007-08-05 05:30:12 1,627,136 ----a-w C:\WINDOWS\Resources\Themes\vistags\Shell\Basic\Shellstyle.dll
+ 2007-08-05 05:30:48 1,819,648 ----a-w C:\WINDOWS\Resources\Themes\vistags\Shell\ColorBasic\Shellstyle.dll
+ 2007-08-05 05:29:14 1,627,136 ----a-w C:\WINDOWS\Resources\Themes\vistags\Shell\NormalColor\Shellstyle.dll
+ 2007-10-22 03:11:09 1,262,592 ----a-w C:\WINDOWS\Resources\Themes\Vistaluna Basic\Themes\Vistaluna Basic\Shell\Alternat\Shellstyle.dll
+ 2007-10-22 03:11:09 1,262,592 ----a-w C:\WINDOWS\Resources\Themes\Vistaluna Basic\Themes\Vistaluna Basic\Shell\Alternat2\Shellstyle.dll
+ 2007-10-22 03:11:09 1,262,592 ----a-w C:\WINDOWS\Resources\Themes\Vistaluna Basic\Themes\Vistaluna Basic\Shell\Normal2\Shellstyle.dll
+ 2007-10-22 03:11:09 1,262,592 ----a-w C:\WINDOWS\Resources\Themes\Vistaluna Basic\Themes\Vistaluna Basic\Shell\NormalColor\Shellstyle.dll
+ 2002-03-15 16:58:02 756,736 ----a-w C:\WINDOWS\Resources\Themes\Windows MAX 2003\Shell\NormalColor\shellstyle.dll
+ 2002-03-15 16:58:02 774,656 ----a-w C:\WINDOWS\Resources\Themes\Windows MAX 2003\Shell\WinMAXV45\shellstyle.dll
- 2008-07-15 10:47:22 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
+ 2008-08-06 12:51:52 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
+ 2001-07-14 14:32:24 69,632 ----a-w C:\WINDOWS\setupupd\temp\wsdueng.dll
- 2004-08-04 12:00:00 68,320 ----a-w C:\WINDOWS\system\MMSYSTEM.DLL
+ 2008-02-05 09:11:14 68,320 ----a-w C:\WINDOWS\system\MMSYSTEM.DLL
+ 2008-04-14 18:29:34 43,520 ----a-w C:\WINDOWS\system32\admwprox.dll
- 2008-03-19 16:23:20 114,688 ----a-w C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
+ 2008-08-06 13:22:02 114,688 ----a-w C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
- 2008-06-17 13:23:02 202,168 ----a-w C:\WINDOWS\system32\Adobe\Director\swdir.dll
+ 2008-08-06 13:30:48 202,168 ----a-w C:\WINDOWS\system32\Adobe\Director\swdir.dll
- 2008-06-17 13:23:18 62,904 ----a-w C:\WINDOWS\system32\Adobe\Director\SwDnld.exe
+ 2008-08-06 13:31:08 67,000 ----a-w C:\WINDOWS\system32\Adobe\Director\SwDnld.exe
- 2008-03-19 16:24:02 487,424 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Control.dll
+ 2008-08-06 13:22:42 499,712 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Control.dll
- 2008-03-19 15:46:26 1,798,144 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\dirapi.dll
+ 2008-08-06 12:45:40 1,798,144 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\dirapi.dll
- 2008-03-19 16:24:04 9,216 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2008-08-06 13:22:44 9,216 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\DynaPlayer.dll
- 2008-03-19 15:36:14 754,688 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gi.dll
+ 2008-08-06 12:35:52 706,048 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gi.dll
- 2008-03-19 15:36:16 1,145,896 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gt.exe
+ 2008-08-06 12:35:52 1,145,896 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gt.exe
- 2008-03-19 15:36:14 52,288 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gtapi.dll
+ 2008-08-06 12:35:52 52,288 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gtapi.dll
- 2008-03-19 15:42:42 892,928 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\iml32.dll
+ 2008-08-06 12:42:04 892,928 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\iml32.dll
+ 2008-08-06 12:35:52 54,656 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\pccuapi.dll
- 2008-03-19 16:22:34 249,856 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Plugin.dll
+ 2008-08-06 13:21:14 266,240 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Plugin.dll
- 2008-03-19 16:25:36 442,368 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Proj.dll
+ 2008-08-06 13:24:14 446,464 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Proj.dll
+ 2008-08-06 13:30:30 447,928 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1100465.exe
- 2008-03-19 16:26:20 110,592 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwInit.exe
+ 2008-08-06 13:24:56 114,688 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwInit.exe
- 2008-03-19 16:22:22 94,208 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2008-08-06 13:21:04 94,208 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwMenu.dll
- 2008-03-19 15:36:14 50,808 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2008-08-06 12:35:52 50,808 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2008-04-14 18:29:34 290,816 ----a-w C:\WINDOWS\system32\adsiis.dll
+ 2006-10-27 09:10:48 516,832 ----a-w C:\WINDOWS\system32\CapiCom.dll
- 2008-04-20 20:03:26 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
+ 2008-09-11 11:11:55 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
- 2008-04-14 18:29:34 48,128 ----a-w C:\WINDOWS\system32\cnbjmon.dll
+ 2008-04-14 18:41:50 48,128 ----a-w C:\WINDOWS\system32\cnbjmon.dll
- 2008-08-26 18:02:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
+ 2008-09-17 17:50:50 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
- 2008-08-26 18:02:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-17 17:50:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-17 17:50:49 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091720080918\index.dat
- 2008-08-26 18:02:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
+ 2008-09-17 17:50:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
- 2008-07-16 13:05:08 53,248 ----a-w C:\WINDOWS\system32\CSVer.dll
+ 2008-05-01 13:35:20 53,248 ----a-w C:\WINDOWS\system32\CSVer.dll
+ 2006-11-10 06:25:46 319,456 ----a-w C:\WINDOWS\system32\difxapi.dll
- 2008-04-14 18:29:34 20,540 -c--a-w C:\WINDOWS\system32\dllcache\admin.dll
+ 2003-03-24 13:52:04 20,540 -c--a-w C:\WINDOWS\system32\dllcache\admin.dll
- 2008-04-14 18:29:48 16,439 -c--a-w C:\WINDOWS\system32\dllcache\admin.exe
+ 2003-03-24 13:52:04 16,439 -c--a-w C:\WINDOWS\system32\dllcache\admin.exe
- 2008-04-14 18:29:34 20,540 -c--a-w C:\WINDOWS\system32\dllcache\author.dll
+ 2003-03-24 13:52:04 20,540 -c--a-w C:\WINDOWS\system32\dllcache\author.dll
- 2008-04-14 18:29:48 16,439 -c--a-w C:\WINDOWS\system32\dllcache\author.exe
+ 2003-03-24 13:52:04 16,439 -c--a-w C:\WINDOWS\system32\dllcache\author.exe
- 2008-04-14 18:29:50 188,480 -c--a-w C:\WINDOWS\system32\dllcache\cfgwiz.exe
+ 2003-03-24 13:52:04 188,480 -c--a-w C:\WINDOWS\system32\dllcache\cfgwiz.exe
- 2004-08-04 12:00:00 53,840 -c--a-w C:\WINDOWS\system32\dllcache\dosx.exe
+ 2008-04-13 19:24:52 53,840 -c--a-w C:\WINDOWS\system32\dllcache\dosx.exe
- 2004-08-04 12:00:00 4,656 -c--a-w C:\WINDOWS\system32\dllcache\ds16gt.dll
+ 2007-04-02 16:35:22 4,656 -c--a-w C:\WINDOWS\system32\dllcache\ds16gt.dll
- 2008-04-14 18:29:36 184,435 -c--a-w C:\WINDOWS\system32\dllcache\fp4amsft.dll
+ 2004-05-12 21:39:48 184,435 -c--a-w C:\WINDOWS\system32\dllcache\fp4amsft.dll
- 2008-04-14 18:29:36 82,035 -c--a-w C:\WINDOWS\system32\dllcache\fp4anscp.dll
+ 2003-03-24 13:52:04 82,035 -c--a-w C:\WINDOWS\system32\dllcache\fp4anscp.dll
- 2008-04-14 18:29:36 147,513 -c--a-w C:\WINDOWS\system32\dllcache\fp4apws.dll
+ 2003-03-24 13:52:04 147,513 -c--a-w C:\WINDOWS\system32\dllcache\fp4apws.dll
- 2008-04-14 18:29:36 49,210 -c--a-w C:\WINDOWS\system32\dllcache\fp4areg.dll
+ 2003-03-24 13:52:04 49,210 -c--a-w C:\WINDOWS\system32\dllcache\fp4areg.dll
- 2008-04-14 18:29:36 102,509 -c--a-w C:\WINDOWS\system32\dllcache\fp4atxt.dll
+ 2003-03-24 13:52:04 102,509 -c--a-w C:\WINDOWS\system32\dllcache\fp4atxt.dll
- 2008-04-14 18:29:36 41,020 -c--a-w C:\WINDOWS\system32\dllcache\fp4avnb.dll
+ 2003-03-24 13:52:04 41,020 -c--a-w C:\WINDOWS\system32\dllcache\fp4avnb.dll
- 2008-04-14 18:29:36 32,826 -c--a-w C:\WINDOWS\system32\dllcache\fp4avss.dll
+ 2003-03-24 13:52:04 32,826 -c--a-w C:\WINDOWS\system32\dllcache\fp4avss.dll
- 2008-04-14 18:29:36 49,212 -c--a-w C:\WINDOWS\system32\dllcache\fp4awebs.dll
+ 2003-03-24 13:52:04 49,212 -c--a-w C:\WINDOWS\system32\dllcache\fp4awebs.dll
- 2008-04-14 18:29:36 876,653 -c--a-w C:\WINDOWS\system32\dllcache\fp4awel.dll
+ 2004-05-12 21:39:48 876,653 -c--a-w C:\WINDOWS\system32\dllcache\fp4awel.dll
- 2008-04-14 18:29:54 15,120 -c--a-w C:\WINDOWS\system32\dllcache\fp98sadm.exe
+ 2003-03-24 13:52:04 14,608 -c--a-w C:\WINDOWS\system32\dllcache\fp98sadm.exe
- 2008-04-14 18:29:54 109,840 -c--a-w C:\WINDOWS\system32\dllcache\fp98swin.exe
+ 2003-03-24 13:52:04 109,328 -c--a-w C:\WINDOWS\system32\dllcache\fp98swin.exe
- 2008-04-14 18:29:54 24,632 -c--a-w C:\WINDOWS\system32\dllcache\fpadmcgi.exe
+ 2003-03-24 13:52:04 24,632 -c--a-w C:\WINDOWS\system32\dllcache\fpadmcgi.exe
- 2008-04-14 18:29:36 20,541 -c--a-w C:\WINDOWS\system32\dllcache\fpadmdll.dll
+ 2003-03-24 13:52:04 20,541 -c--a-w C:\WINDOWS\system32\dllcache\fpadmdll.dll
- 2008-04-14 18:29:54 188,494 -c--a-w C:\WINDOWS\system32\dllcache\fpcount.exe
+ 2003-03-24 13:52:04 188,494 -c--a-w C:\WINDOWS\system32\dllcache\fpcount.exe
- 2008-04-14 18:29:36 94,208 -c--a-w C:\WINDOWS\system32\dllcache\fpencode.dll
+ 2003-03-24 13:52:04 94,208 -c--a-w C:\WINDOWS\system32\dllcache\fpencode.dll
- 2008-04-14 18:29:36 20,541 -c--a-w C:\WINDOWS\system32\dllcache\fpexedll.dll
+ 2003-03-24 13:52:04 20,541 -c--a-w C:\WINDOWS\system32\dllcache\fpexedll.dll
- 2008-04-14 18:29:36 598,071 -c--a-w C:\WINDOWS\system32\dllcache\fpmmc.dll
+ 2004-05-12 21:39:48 598,071 -c--a-w C:\WINDOWS\system32\dllcache\fpmmc.dll
- 2007-04-02 19:06:06 208,896 -c--a-w C:\WINDOWS\system32\dllcache\fpmmcsat.dll
+ 2003-03-24 13:52:06 208,896 -c--a-w C:\WINDOWS\system32\dllcache\fpmmcsat.dll
- 2008-04-14 18:29:54 20,538 -c--a-w C:\WINDOWS\system32\dllcache\fpremadm.exe
+ 2003-03-24 13:52:04 20,538 -c--a-w C:\WINDOWS\system32\dllcache\fpremadm.exe
- 2004-08-04 12:00:00 101,888 -c--a-w C:\WINDOWS\system32\dllcache\gpkcsp.dll
+ 2008-04-13 20:08:00 101,888 -c--a-w C:\WINDOWS\system32\dllcache\gpkcsp.dll
- 2004-08-04 12:00:00 42,537 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.sys
+ 2008-04-13 19:20:56 42,537 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.sys
- 2004-08-04 12:00:00 92,224 -c--a-w C:\WINDOWS\system32\dllcache\krnl386.exe
+ 2008-04-13 19:23:14 92,224 -c--a-w C:\WINDOWS\system32\dllcache\krnl386.exe
- 2004-08-04 12:00:00 68,320 -c--a-w C:\WINDOWS\system32\dllcache\mmsystem.dll
+ 2008-02-05 09:11:14 68,320 -c--a-w C:\WINDOWS\system32\dllcache\mmsystem.dll
- 2004-08-04 12:00:00 126,976 -c--a-w C:\WINDOWS\system32\dllcache\netfxocm.dll
+ 2008-04-13 18:39:58 126,976 -c--a-w C:\WINDOWS\system32\dllcache\netfxocm.dll
- 2004-08-04 12:00:00 33,840 -c--a-w C:\WINDOWS\system32\dllcache\ntio.sys
+ 2008-04-13 19:19:40 33,840 -c--a-w C:\WINDOWS\system32\dllcache\ntio.sys
- 2004-08-04 12:00:00 34,560 -c--a-w C:\WINDOWS\system32\dllcache\ntio404.sys
+ 2008-04-13 19:19:44 34,560 -c--a-w C:\WINDOWS\system32\dllcache\ntio404.sys
- 2004-08-04 12:00:00 35,648 -c--a-w C:\WINDOWS\system32\dllcache\ntio411.sys
+ 2008-04-13 19:19:40 35,648 -c--a-w C:\WINDOWS\system32\dllcache\ntio411.sys
- 2004-08-04 12:00:00 35,424 -c--a-w C:\WINDOWS\system32\dllcache\ntio412.sys
+ 2008-04-13 19:19:44 35,424 -c--a-w C:\WINDOWS\system32\dllcache\ntio412.sys
- 2004-08-04 12:00:00 34,560 -c--a-w C:\WINDOWS\system32\dllcache\ntio804.sys
+ 2008-04-13 19:19:42 34,560 -c--a-w C:\WINDOWS\system32\dllcache\ntio804.sys
- 2004-08-04 12:00:00 26,224 -c--a-w C:\WINDOWS\system32\dllcache\odbc16gt.dll
+ 2007-04-02 16:35:22 26,224 -c--a-w C:\WINDOWS\system32\dllcache\odbc16gt.dll
- 2004-08-04 12:00:00 3,338 -c--a-w C:\WINDOWS\system32\dllcache\redir.exe
+ 2008-04-13 19:22:30 3,338 -c--a-w C:\WINDOWS\system32\dllcache\redir.exe
- 2004-08-04 12:00:00 169,984 -c--a-w C:\WINDOWS\system32\dllcache\sccbase.dll
+ 2008-04-13 20:08:00 169,984 -c--a-w C:\WINDOWS\system32\dllcache\sccbase.dll
- 2004-08-04 12:00:00 4,569 -c--a-w C:\WINDOWS\system32\dllcache\secupd.dat
+ 2006-12-31 04:57:08 4,569 -c--a-w C:\WINDOWS\system32\dllcache\secupd.dat
- 2008-04-14 18:29:42 20,536 -c--a-w C:\WINDOWS\system32\dllcache\shtml.dll
+ 2003-03-24 13:52:04 20,536 -c--a-w C:\WINDOWS\system32\dllcache\shtml.dll
- 2008-04-14 18:30:04 16,437 -c--a-w C:\WINDOWS\system32\dllcache\shtml.exe
+ 2003-03-24 13:52:04 16,437 -c--a-w C:\WINDOWS\system32\dllcache\shtml.exe
- 2004-08-04 12:00:00 306,176 -c--a-w C:\WINDOWS\system32\dllcache\slbcsp.dll
+ 2008-04-13 20:08:00 306,176 -c--a-w C:\WINDOWS\system32\dllcache\slbcsp.dll
- 2008-04-14 18:30:06 32,827 -c--a-w C:\WINDOWS\system32\dllcache\tcptest.exe
+ 2003-03-24 13:52:04 32,827 -c--a-w C:\WINDOWS\system32\dllcache\tcptest.exe
- 2007-04-02 19:06:08 16,384 -c--a-w C:\WINDOWS\system32\dllcache\tcptsat.dll
+ 2003-03-24 13:52:06 16,384 -c--a-w C:\WINDOWS\system32\dllcache\tcptsat.dll
- 2008-04-25 16:41:40 218,624 -c--a-w C:\WINDOWS\system32\dllcache\uxtheme.dll
+ 2008-04-14 18:29:44 218,624 -c--a-w C:\WINDOWS\system32\dllcache\uxtheme.dll
- 2004-08-04 12:00:00 5,120 -c--a-w C:\WINDOWS\system32\dllcache\winnls.dll
+ 2008-04-13 19:24:48 5,120 -c--a-w C:\WINDOWS\system32\dllcache\winnls.dll
- 2004-08-04 12:00:00 173,176 -c--a-w C:\WINDOWS\system32\dllcache\xenroll.dll
+ 2006-12-31 04:07:02 173,176 -c--a-w C:\WINDOWS\system32\dllcache\xenroll.dll
- 2008-04-14 18:29:36 47,616 ----a-w C:\WINDOWS\system32\dmutil.dll
+ 2008-04-14 18:41:50 47,616 ----a-w C:\WINDOWS\system32\dmutil.dll
- 2004-08-04 12:00:00 53,840 ----a-w C:\WINDOWS\system32\dosx.exe
+ 2008-04-13 19:24:52 53,840 ----a-w C:\WINDOWS\system32\dosx.exe
+ 2006-07-30 00:37:14 121,089 ----a-w C:\WINDOWS\system32\drive\vistadrive.exe
- 2008-04-13 19:09:24 142,592 ----a-w C:\WINDOWS\system32\drivers\aec.sys
+ 2008-04-14 18:41:50 142,592 ----a-w C:\WINDOWS\system32\drivers\aec.sys
+ 2008-08-05 17:10:12 1,684,736 ----a-w C:\WINDOWS\system32\drivers\Ambfilt.sys
- 2008-04-14 18:04:14 41,088 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
+ 2008-04-14 18:41:50 41,088 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
- 2008-04-14 18:04:14 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
+ 2008-04-14 18:41:50 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
- 2008-04-13 21:21:26 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
+ 2008-04-14 18:41:50 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
- 2008-04-13 21:16:22 11,776 ----a-w C:\WINDOWS\system32\drivers\bdasup.sys
+ 2008-04-14 18:41:50 11,776 ----a-w C:\WINDOWS\system32\drivers\bdasup.sys
+ 2008-05-07 04:38:20 17,536 ----a-w C:\WINDOWS\system32\drivers\ccdcmb.sys
+ 2008-05-07 04:38:20 20,864 ----a-w C:\WINDOWS\system32\drivers\ccdcmbo.sys
- 2008-04-14 18:09:20 40,448 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
+ 2008-04-14 18:41:50 40,448 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
- 2008-04-13 21:15:14 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
+ 2008-04-14 18:41:50 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
- 2008-07-28 07:43:00 144,384 ----a-w C:\WINDOWS\system32\drivers\hdaudbus.sys
+ 2008-04-13 19:06:06 144,384 ----a-w C:\WINDOWS\system32\drivers\hdaudbus.sys
- 2006-06-01 04:43:56 43,264 ----a-r C:\WINDOWS\system32\drivers\HECI.sys
+ 2006-10-23 06:23:02 44,416 ----a-w C:\WINDOWS\system32\drivers\HECI.sys
- 2007-04-04 11:58:26 24,344 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
+ 2008-04-30 15:06:48 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
- 2008-04-13 21:15:10 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
+ 2008-04-14 18:41:50 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
- 2008-04-13 21:06:42 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys
+ 2008-04-14 18:41:50 63,744 ----a-w C:\WINDOWS\system32\drivers\mf.sys
- 2008-04-14 18:03:16 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
+ 2008-04-14 18:41:50 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
+ 2006-01-04 12:41:48 1,389,056 ----a-w C:\WINDOWS\system32\drivers\Monfilt.sys
- 2008-04-14 18:03:20 22,912 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
+ 2008-04-14 18:41:50 22,912 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
- 2008-04-13 21:16:24 15,232 ----a-w C:\WINDOWS\system32\drivers\mpe.sys
+ 2008-04-14 18:41:50 15,232 ----a-w C:\WINDOWS\system32\drivers\mpe.sys
- 2008-04-13 21:09:54 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
+ 2008-04-14 18:41:50 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
- 2008-04-13 21:09:52 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
+ 2008-04-14 18:41:50 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
- 2008-04-13 21:09:52 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
+ 2008-04-14 18:41:50 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
- 2008-04-13 21:06:48 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys
+ 2008-04-14 18:41:50 15,488 ----a-w C:\WINDOWS\system32\drivers\mssmbios.sys
- 2008-04-13 21:16:24 10,880 ----a-w C:\WINDOWS\system32\drivers\ndisip.sys
+ 2008-04-14 18:41:50 10,880 ----a-w C:\WINDOWS\system32\drivers\ndisip.sys
- 2008-04-13 21:26:00 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
+ 2008-04-14 18:41:50 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
- 2008-04-13 21:21:26 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
+ 2008-04-14 18:41:50 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
+ 2008-02-01 13:17:12 138,112 ----a-w C:\WINDOWS\system32\drivers\nmwcdnsu.sys
+ 2008-02-01 13:17:06 8,320 ----a-w C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
- 2008-04-14 18:13:16 46,464 ----a-w C:\WINDOWS\system32\drivers\p3.sys
+ 2008-04-14 18:41:50 46,464 ----a-w C:\WINDOWS\system32\drivers\p3.sys
- 2008-04-14 18:13:16 79,872 ----a-w C:\WINDOWS\system32\drivers\parport.sys
+ 2008-04-14 18:41:50 79,872 ----a-w C:\WINDOWS\system32\drivers\parport.sys
- 2007-08-20 22:13:00 21,760 ----a-w C:\WINDOWS\system32\drivers\point32.sys
+ 2008-06-10 10:04:28 31,048 ----a-w C:\WINDOWS\system32\drivers\point32.sys
- 2008-04-14 18:05:54 39,552 ----a-w C:\WINDOWS\system32\drivers\processr.sys
+ 2008-04-14 18:41:50 39,552 ----a-w C:\WINDOWS\system32\drivers\processr.sys
- 2008-04-13 21:06:36 5,888 ----a-w C:\WINDOWS\system32\drivers\smbali.sys
+ 2008-04-14 18:41:50 5,888 ----a-w C:\WINDOWS\system32\drivers\smbali.sys
- 2008-04-13 21:16:08 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
+ 2008-04-14 18:41:50 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
- 2008-04-13 21:09:54 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
+ 2008-04-14 18:41:50 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
- 2008-04-13 21:15:10 56,576 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
+ 2008-04-14 18:41:50 56,576 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
- 2008-04-13 21:45:56 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
+ 2008-04-14 18:41:50 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
- 2008-04-13 21:26:02 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
+ 2008-04-14 18:41:50 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
+ 2008-05-20 07:37:00 525,824 ----a-w C:\WINDOWS\system32\drivers\UMDF\PCCSWpdDriver.dll
- 2008-04-13 21:15:42 25,600 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys
+ 2008-04-14 18:41:50 25,600 ----a-w C:\WINDOWS\system32\drivers\usbcamd.sys
- 2008-04-13 21:15:42 25,728 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys
+ 2008-04-14 18:41:50 25,728 ----a-w C:\WINDOWS\system32\drivers\usbcamd2.sys
- 2008-04-13 21:15:44 15,872 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys
+ 2008-04-14 18:41:50 15,872 ----a-w C:\WINDOWS\system32\drivers\usbintel.sys
+ 2008-04-13 21:15:38 26,112 ----a-w C:\WINDOWS\system32\drivers\usbser.sys
+ 2008-06-06 06:24:44 8,064 ----a-w C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
+ 2008-05-07 04:38:36 8,064 ----a-w C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
+ 2006-11-02 04:22:54 492,000 ------w C:\WINDOWS\system32\drivers\wdf01000.sys
+ 2006-11-02 04:22:52 32,224 ------w C:\WINDOWS\system32\drivers\wdfldr.sys
- 2008-04-13 21:47:20 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2008-04-14 18:41:50 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2008-05-07 04:38:20 17,536 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\ccdcmb.sys
+ 2008-05-07 04:38:24 90,624 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\nmwcdcls.dll
+ 2008-05-07 04:38:34 659,968 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\nmwcdcocls.dll
+ 2008-05-07 04:39:22 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\wdfcoinstaller01005.dll
+ 2008-05-07 04:38:36 8,064 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmbcj_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\usbser_lowerfltj.sys
+ 2008-06-06 06:24:44 8,064 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmbm_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\usbser_lowerflt.sys
+ 2008-05-07 04:38:20 20,864 -c--a-w C:\WINDOWS\system32\DRVSTORE\ccdcmbo_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\ccdcmbo.sys
+ 2006-10-23 06:23:02 44,416 -c--a-w C:\WINDOWS\system32\DRVSTORE\HECI_A6423F88956C77CC436542B173C4725B23C9CD05\HECI.sys
+ 2006-10-23 06:23:06 44,800 -c--a-w C:\WINDOWS\system32\DRVSTORE\HECI_A6423F88956C77CC436542B173C4725B23C9CD05\HECI2K.sys
+ 2006-10-23 06:23:12 63,488 -c--a-w C:\WINDOWS\system32\DRVSTORE\HECI_A6423F88956C77CC436542B173C4725B23C9CD05\HECIx64.sys
+ 2008-02-01 13:17:12 138,112 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdnsu_44DA5D9994D88495A1C1116BFFF6763CF67ABD72\nmwcdnsu.sys
+ 2008-02-01 13:17:06 8,320 -c--a-w C:\WINDOWS\system32\DRVSTORE\nmwcdnsuc_44DA5D9994D88495A1C1116BFFF6763CF67ABD72\nmwcdnsuc.sys
+ 2008-05-20 07:37:00 525,824 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_66268C3E0C6968D7F539EAEAD801C68E0DB54FE9\PCCSWpdDriver.dll
+ 2008-05-20 07:32:30 831,048 -c--a-w C:\WINDOWS\system32\DRVSTORE\pccswpddri_66268C3E0C6968D7F539EAEAD801C68E0DB54FE9\WudfUpdate_01005.dll
+ 2008-06-10 10:04:28 33,352 -c--a-w C:\WINDOWS\system32\DRVSTORE\pnt32pk_10A740FB87D0ACA33593A12D9BBD5CBB5DED03D4\point32k.sys
+ 2008-06-10 10:04:28 31,048 -c--a-w C:\WINDOWS\system32\DRVSTORE\pnt32pw_81F87EB3DFFD672CD4DE30C5341B8C7F08DA9486\point32.sys
+ 2008-06-10 10:04:28 33,352 -c--a-w C:\WINDOWS\system32\DRVSTORE\pnt32uk_8477F1120BF994C8009DDB48E4DD8FA85A9039FC\point32k.sys
+ 2008-06-10 10:04:28 31,048 -c--a-w C:\WINDOWS\system32\DRVSTORE\pnt32uw_667890F3485BB5D1C47F7877D51185D7490A7A6A\point32.sys
- 2004-08-04 12:00:00 4,656 ----a-w C:\WINDOWS\system32\ds16gt.dLL
+ 2007-04-02 16:35:22 4,656 ----a-w C:\WINDOWS\system32\ds16gt.dLL
- 2008-08-03 03:12:36 24,048 ----a-w C:\WINDOWS\system32\emptyregdb.dat
+ 2008-09-17 17:41:51 24,048 ----a-w C:\WINDOWS\system32\emptyregdb.dat
+ 2008-04-14 18:29:36 14,336 ----a-w C:\WINDOWS\system32\exstrace.dll
- 2006-05-26 13:29:14 5,120 ----a-w C:\WINDOWS\system32\ff_vfw.dll
+ 2008-06-12 18:36:38 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
- 2008-08-25 17:39:52 423,816 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-09-17 17:50:15 430,984 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2004-08-04 12:00:00 6,144 ----a-w C:\WINDOWS\system32\ftpsapi2.dll
- 2004-08-04 12:00:00 101,888 ----a-w C:\WINDOWS\system32\gpkcsp.dll
+ 2008-04-13 20:08:00 101,888 ----a-w C:\WINDOWS\system32\gpkcsp.dll
+ 2007-05-29 13:13:52 920,344 ----a-w C:\WINDOWS\system32\heciudlg.exe
- 2008-04-14 18:29:36 20,992 ----a-w C:\WINDOWS\system32\hid.dll
+ 2008-04-14 18:41:50 20,992 ----a-w C:\WINDOWS\system32\hid.dll
+ 2007-09-06 18:01:42 1,536 ----a-w C:\WINDOWS\system32\hidec.exe
- 2008-04-14 18:29:36 21,504 ----a-w C:\WINDOWS\system32\hidserv.dll
+ 2008-04-14 18:41:50 21,504 ----a-w C:\WINDOWS\system32\hidserv.dll
- 2007-02-21 01:35:02 73,728 ----a-w C:\WINDOWS\system32\HPZipm12.exe
+ 2008-09-14 10:44:34 73,728 ----a-w C:\WINDOWS\system32\HPZipm12.exe
+ 2008-09-11 19:42:44 87,552 ----a-w C:\WINDOWS\system32\IECONT.DLL
+ 2008-09-11 19:45:06 22,528 ----a-w C:\WINDOWS\system32\IECONTLC.DLL
+ 2008-04-14 18:29:36 68,608 ----a-w C:\WINDOWS\system32\iisext.dll
+ 2008-04-14 18:29:36 64,000 ----a-w C:\WINDOWS\system32\iismap.dll
+ 2004-08-04 12:00:00 3,584 ----a-w C:\WINDOWS\system32\iismui.dll
+ 2004-08-04 12:00:00 14,336 ----a-w C:\WINDOWS\system32\iisreset.exe
+ 2004-08-04 12:00:00 5,632 ----a-w C:\WINDOWS\system32\iisrstap.dll
+ 2008-04-14 18:29:36 133,632 ----a-w C:\WINDOWS\system32\iisRtl.dll
+ 2004-08-04 12:00:00 19,968 ----a-w C:\WINDOWS\system32\inetsloc.dll
+ 2008-04-14 18:29:34 46,592 ----a-w C:\WINDOWS\system32\inetsrv\coadmin.dll
+ 2004-08-04 12:00:00 60,928 ----a-w C:\WINDOWS\system32\inetsrv\iisclex4.dll
+ 2008-04-14 18:29:56 30,720 ----a-w C:\WINDOWS\system32\inetsrv\iisrstas.exe
+ 2004-08-04 12:00:00 169,984 ----a-w C:\WINDOWS\system32\inetsrv\iisui.dll
+ 2008-04-14 18:29:36 829,952 ----a-w C:\WINDOWS\system32\inetsrv\inetmgr.dll
+ 2004-08-04 12:00:00 7,680 ----a-w C:\WINDOWS\system32\inetsrv\inetmgr.exe
+ 2008-04-14 18:29:38 68,608 ----a-w C:\WINDOWS\system32\inetsrv\isatq.dll
+ 2008-04-14 18:29:36 13,312 ----a-w C:\WINDOWS\system32\infoadmn.dll
+ 2007-09-07 10:50:56 2,626,920 ----a-w C:\WINDOWS\system32\Installermsx\Installer.exe
+ 2007-08-19 15:57:44 973,557 ----a-w C:\WINDOWS\system32\Installermsx\msx.exe
- 2008-04-14 18:29:38 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
+ 2008-04-14 18:41:50 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
- 2008-04-14 18:28:26 6,144 ----a-w C:\WINDOWS\system32\kbd106.dll
+ 2008-04-14 18:41:50 6,144 ----a-w C:\WINDOWS\system32\kbd106.dll
- 2004-08-04 12:00:00 42,537 ----a-w C:\WINDOWS\system32\keyboard.sys
+ 2008-04-13 19:20:56 42,537 ----a-w C:\WINDOWS\system32\keyboard.sys
- 2004-08-04 12:00:00 92,224 ----a-w C:\WINDOWS\system32\krnl386.exe
+ 2008-04-13 19:23:14 92,224 ----a-w C:\WINDOWS\system32\krnl386.exe
+ 2004-08-03 22:56:52 514,560 ----a-w C:\WINDOWS\system32\logonuiX.exe
+ 2008-09-18 05:29:18 6,656 ----a-w C:\WINDOWS\system32\lpcio.dll
- 2008-08-17 07:40:15 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-09-17 21:16:16 74,137 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-08-19 20:31:04 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-09-17 21:17:03 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
+ 3427-09-25 18:10:30 233,577 ----a-w C:\WINDOWS\system32\mainhook.dll
- 2004-08-04 12:00:00 68,320 ----a-w C:\WINDOWS\system32\mmsystem.dll
+ 2008-02-05 09:11:14 68,320 ----a-w C:\WINDOWS\system32\mmsystem.dll
- 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-08-26 20:28:12 16,208,504 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-04-14 18:30:10 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
+ 2008-04-14 18:41:50 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
- 2008-04-19 14:17:03 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
+ 2008-09-09 22:46:54 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
- 2008-04-19 14:17:03 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
+ 2008-09-09 22:46:54 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
- 2008-04-14 18:29:40 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
+ 2008-04-14 18:41:50 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
- 2007-11-29 07:32:38 48,128 ----a-w C:\WINDOWS\system32\nmwcdcls.dll
+ 2008-05-07 04:38:24 90,624 ----a-w C:\WINDOWS\system32\nmwcdcls.dll
+ 2008-05-07 04:38:34 659,968 ----a-w C:\WINDOWS\system32\nmwcdcocls.dll
- 2004-08-04 12:00:00 33,840 ----a-w C:\WINDOWS\system32\ntio.sys
+ 2008-04-13 19:19:40 33,840 ----a-w C:\WINDOWS\system32\ntio.sys
- 2004-08-04 12:00:00 34,560 ----a-w C:\WINDOWS\system32\ntio404.sys
+ 2008-04-13 19:19:44 34,560 ----a-w C:\WINDOWS\system32\ntio404.sys
- 2004-08-04 12:00:00 35,648 ----a-w C:\WINDOWS\system32\ntio411.sys
+ 2008-04-13 19:19:40 35,648 ----a-w C:\WINDOWS\system32\ntio411.sys
- 2004-08-04 12:00:00 35,424 ----a-w C:\WINDOWS\system32\ntio412.sys
+ 2008-04-13 19:19:44 35,424 ----a-w C:\WINDOWS\system32\ntio412.sys
- 2004-08-04 12:00:00 34,560 ----a-w C:\WINDOWS\system32\ntio804.sys
+ 2008-04-13 19:19:42 34,560 ----a-w C:\WINDOWS\system32\ntio804.sys
- 2008-04-14 18:12:16 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
+ 2008-04-14 18:41:50 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
- 2004-08-04 12:00:00 26,224 ----a-w C:\WINDOWS\system32\odbc16gt.dll
+ 2007-04-02 16:35:22 26,224 ----a-w C:\WINDOWS\system32\odbc16gt.dll
+ 2007-06-04 23:04:32 106,908 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\1\Control Logon.exe
+ 2007-06-04 23:05:30 101,659 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\10\Control Logon.exe
+ 2007-06-04 23:05:38 100,578 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\11\Control Logon.exe
+ 2007-06-04 23:05:42 91,307 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\12\Control Logon.exe
+ 2007-06-04 23:05:50 97,352 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\13\Control Logon.exe
+ 2007-06-04 23:05:56 102,547 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\14\Control Logon.exe
+ 2007-06-04 23:06:02 102,489 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\15\Control Logon.exe
+ 2007-06-04 23:04:38 95,571 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\2\Control Logon.exe
+ 2007-06-04 23:04:44 105,239 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\3\Control Logon.exe
+ 2007-06-04 23:04:50 101,472 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\4\Control Logon.exe
+ 2007-06-04 23:04:56 103,264 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\5\Control Logon.exe
+ 2007-06-04 23:05:02 91,150 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\6\Control Logon.exe
+ 2007-06-04 23:05:08 86,395 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\7\Control Logon.exe
+ 2007-06-04 23:05:16 100,118 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\8\Control Logon.exe
+ 2007-06-04 23:05:22 80,273 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\AutoPlay\Docs\9\Control Logon.exe
+ 2003-05-27 14:57:00 3,872 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap1.dat
+ 2007-03-29 17:42:16 8,802 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap10.dat
+ 2007-03-29 17:43:34 8,580 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap11.dat
+ 2007-07-30 15:00:26 425,317 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap12.dat
+ 2003-05-27 14:57:00 3,833 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap2.dat
+ 2006-11-12 10:09:50 19,884 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap3.dat
+ 2006-11-12 10:09:50 26,124 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap4.dat
+ 2006-11-12 10:09:50 129,580 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap5.dat
+ 2006-11-12 10:09:50 227,372 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap6.dat
+ 2006-03-23 21:18:54 3,632 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap7.dat
+ 2006-03-24 22:53:22 11,839 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap8.dat
+ 2007-03-29 17:40:36 12,106 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\dat01\ap9.dat
+ 2006-03-23 23:55:34 34,596 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ClearType\de\ClearType.exe
+ 2006-03-23 23:54:12 121,052 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ClearType\en\ClearType.exe
+ 2007-08-21 09:11:50 111,541 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ICON\de\iconlde.exe
+ 2007-08-21 09:12:06 109,468 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ICON\en\iconlen.exe
+ 2006-03-24 00:23:10 32,753 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\LClock\de\LClock.exe
+ 2006-03-24 00:22:56 32,776 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\LClock\en\LClock.exe
+ 2007-08-20 21:09:54 2,962,880 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\LOGON\ch\ControlLogon.exe
+ 2007-04-04 01:23:38 187,300 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\LOGON\de\Logon Screen.exe
+ 2007-04-04 01:23:54 33,272 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\LOGON\en\Logon Screen.exe
+ 2007-07-06 22:15:52 33,237 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\PaintDesktopVersion\de\PaintDesktopVersionde.exe
+ 2007-07-06 22:15:44 33,245 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\PaintDesktopVersion\en\PaintDesktopVersionen.exe
+ 2007-07-04 10:16:54 34,574 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\RKLauncher\de\deRKLauncher.exe
+ 2007-07-04 10:30:02 35,390 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\RKLauncher\en\enRKLauncher.exe
+ 2007-06-01 20:52:36 34,613 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\RocketDock\de\RocketDock2.exe
+ 2007-08-04 10:19:16 43,065 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\RocketDock\en\RocketDock2.exe
+ 2006-03-24 23:08:56 32,695 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ScreenSaver\de\ScreenSaver.exe
+ 2006-03-24 23:11:42 104,899 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\ScreenSaver\en\ScreenSaver.exe
+ 2007-04-28 06:58:08 35,339 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\STARTMENO\de\Vista Startde.exe
+ 2007-04-28 07:04:08 35,339 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\STARTMENO\en\VistaStarten.exe
+ 2006-03-24 00:40:36 34,609 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Top Desk\de\Top Desk.exe
+ 2006-03-24 09:33:42 42,179 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Top Desk\en\Top Desk.exe
+ 2007-07-01 18:59:12 2,080,797 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Cursors e\Vista Cursors.exe
+ 2006-03-24 00:22:30 40,794 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Cursors\de\Vista Cursors.exe
+ 2006-03-24 00:22:06 41,157 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Cursors\en\Vista Cursors.exe
+ 2006-03-25 15:05:02 32,706 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Drive\DE\Vista Drive.exe
+ 2006-03-25 15:06:22 32,686 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Drive\EN\Vista Drive.exe
+ 2006-03-25 15:28:30 43,044 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Sounds\DE\Vista Sounds.exe
+ 2007-06-01 20:53:12 43,435 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Vista Sounds\en\Vista Sounds.exe
+ 2006-03-23 23:29:44 32,387 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Style\DS\Visual Style de.exe
+ 2007-07-04 08:04:38 34,797 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Style\EN\Visual Style EN.EXE
+ 2006-03-23 23:29:00 717,419 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Style\EN\Visual Style ENbk.exe
+ 2006-03-23 23:51:48 34,603 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Task Tips\de\Visual Task Tips.exe
+ 2007-07-04 10:50:36 35,383 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Task Tips\en\Visual Task Tips.exe
+ 2007-07-04 10:36:16 35,306 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Tool tip\de\Tooltip.exe
+ 2007-07-04 10:51:40 35,393 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Visual Tool tip\en\Tooltip.exe
+ 2006-03-24 23:05:08 38,676 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\WALLPAPERS\de\Wallpapers.exe
+ 2006-03-24 23:07:24 38,678 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\WALLPAPERS\en\Wallpapers.exe
+ 2007-07-01 19:18:38 11,028,377 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\WALLPAPERS\Wallpaper.exe
+ 2007-07-30 14:35:54 35,295 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Windows Sidebar\de\Sidebarde.exe
+ 2007-08-20 22:53:56 43,550 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\conp\Docs\Windows Sidebar\en\SidebarEN.exe
+ 2007-07-30 15:03:54 2,355,200 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\Control Pack.exe
+ 2007-06-05 00:22:42 2,355,200 ----a-w C:\WINDOWS\system32\oobe\html\dslmain\Logon.exe
+ 2007-07-01 18:57:18 2,389,493 ----a-w C:\WINDOWS\system32\oobe\html\iconnect\VistaCursors.exe
- 2008-09-03 19:16:50 72,386 ----a-w C:\WINDOWS\system32\perfc001.dat
+ 2008-09-17 17:55:33 72,386 ----a-w C:\WINDOWS\system32\perfc001.dat
- 2008-09-03 19:16:50 72,040 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-09-17 17:55:33 72,040 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-09-03 19:16:50 378,788 ----a-w C:\WINDOWS\system32\perfh001.dat
+ 2008-09-17 17:55:33 378,788 ----a-w C:\WINDOWS\system32\perfh001.dat
- 2008-09-03 19:16:50 444,164 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-09-17 17:55:33 444,164 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-04-14 18:29:42 35,328 ----a-w C:\WINDOWS\system32\pid.dll
+ 2008-04-14 18:41:50 35,328 ----a-w C:\WINDOWS\system32\pid.dll
- 2008-04-14 18:29:42 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
+ 2008-04-14 18:41:50 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
- 2008-04-19 14:17:02 278,528 ----a-w C:\WINDOWS\system32\pncrt.dll
+ 2008-09-09 22:46:54 278,528 ----a-w C:\WINDOWS\system32\pncrt.dll
- 2008-04-19 14:17:03 6,656 ----a-w C:\WINDOWS\system32\pndx5016.dll
+ 2008-09-09 22:46:55 6,656 ----a-w C:\WINDOWS\system32\pndx5016.dll
- 2008-04-19 14:17:03 5,632 ----a-w C:\WINDOWS\system32\pndx5032.dll
+ 2008-09-09 22:46:55 5,632 ----a-w C:\WINDOWS\system32\pndx5032.dll
- 2008-04-14 18:29:42 363,520 ----a-w C:\WINDOWS\system32\psisdecd.dll
+ 2008-04-14 18:41:50 363,520 ----a-w C:\WINDOWS\system32\psisdecd.dll
- 2004-08-04 12:00:00 3,338 ----a-w C:\WINDOWS\system32\redir.exe
+ 2008-04-13 19:22:30 3,338 ----a-w C:\WINDOWS\system32\redir.exe
+ 2008-04-14 18:13:20 68,480 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0063\DriverFiles\i386\pci.sys
+ 2005-10-21 16:58:52 49,920 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0065\DriverFiles\drivers\dot4\Win2000\HPZid412.sys
- 2008-04-19 14:17:09 185,944 ----a-w C:\WINDOWS\system32\rmoc3260.dll
+ 2008-09-09 22:47:02 185,944 ----a-w C:\WINDOWS\system32\rmoc3260.dll
- 2004-08-04 12:00:00 169,984 ----a-w C:\WINDOWS\system32\sccbase.dll
+ 2008-04-13 20:08:00 169,984 ----a-w C:\WINDOWS\system32\sccbase.dll
- 2004-08-04 12:00:00 4,569 ----a-w C:\WINDOWS\system32\secupd.dat
+ 2006-12-31 04:57:08 4,569 ----a-w C:\WINDOWS\system32\secupd.dat
+ 2007-02-15 12:22:26 688,000 ----a-w C:\WINDOWS\system32\SelfHelpControl.DLL
- 2004-08-04 12:00:00 126,976 ----a-w C:\WINDOWS\system32\Setup\netfxocm.dll
+ 2008-04-13 18:39:58 126,976 ----a-w C:\WINDOWS\system32\Setup\netfxocm.dll
- 2004-08-04 12:00:00 306,176 ----a-w C:\WINDOWS\system32\slbcsp.dll
+ 2008-04-13 20:08:00 306,176 ----a-w C:\WINDOWS\system32\slbcsp.dll
+ 2007-05-05 19:09:26 77,824 ----a-w C:\WINDOWS\system32\smi\QTShortcutKeyEditor.exe
+ 2007-04-07 14:10:48 20,480 ----a-w C:\WINDOWS\system32\smi\Tools\OpenGroup.exe
+ 2006-09-21 18:08:58 16,384 ----a-w C:\WINDOWS\system32\smi\Tools\QTPopup.exe
+ 2007-02-02 19:12:32 40,960 ----a-w C:\WINDOWS\system32\smi\Tools\ShutDownTool.exe
- 2007-11-30 12:39:01 17,784 ------w C:\WINDOWS\system32\spmsg.dll
+ 2006-10-08 18:51:14 14,640 ------w C:\WINDOWS\system32\spmsg.dll
+ 2006-10-26 16:56:16 864,080 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2008-04-14 18:29:44 8,192 ----a-w C:\WINDOWS\system32\staxmem.dll
+ 2007-06-20 08:30:40 49,152 ----a-w C:\WINDOWS\system32\topdesk153.dll
+ 2008-09-20 23:14:15 2,286,592 ----a-w C:\WINDOWS\system32\TUKernel.exe
+ 2008-09-11 00:26:24 355,584 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
+ 2003-06-25 13:05:08 266,360 ----a-w C:\WINDOWS\system32\TweakUI.exe
- 2003-05-15 06:39:50 155,136 ----a-w C:\WINDOWS\system32\unrar.dll
+ 2007-09-04 16:56:10 164,352 ----a-w C:\WINDOWS\system32\unrar.dll
- 2008-04-14 18:29:44 73,728 ----a-w C:\WINDOWS\system32\usbui.dll
+ 2008-04-14 18:41:50 73,728 ----a-w C:\WINDOWS\system32\usbui.dll
- 2008-04-25 16:41:40 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
+ 2008-04-14 18:29:44 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
+ 2008-05-29 06:28:54 28,416 ----a-w C:\WINDOWS\system32\uxtuneup.dll
+ 2006-05-21 15:30:04 61,440 ----a-w C:\WINDOWS\system32\Vista.Emulation.dll
+ 3427-09-25 18:10:30 589,824 --sha-r C:\WINDOWS\system32\ViStart.exe
+ 2007-03-13 12:20:26 37,376 ----a-w C:\WINDOWS\system32\VisualTooltip.dll
+ 2006-05-28 07:37:06 7,680 ----a-w C:\WINDOWS\system32\VttHooks.dll
+ 2004-08-04 12:00:00 7,168 ----a-w C:\WINDOWS\system32\wamregps.dll
+ 2008-05-07 04:39:22 1,419,232 ----a-w C:\WINDOWS\system32\wdfcoinstaller01005.dll
- 2008-07-11 08:56:22 712,704 ----a-w C:\WINDOWS\system32\windowscodecs.dll
+ 2008-04-14 18:29:44 712,704 ----a-w C:\WINDOWS\system32\windowscodecs.dll
- 2008-07-11 08:56:22 347,648 ----a-w C:\WINDOWS\system32\windowscodecsext.dll
+ 2008-04-14 18:29:44 346,112 ----a-w C:\WINDOWS\system32\windowscodecsext.dll
- 2004-08-04 12:00:00 5,120 ----a-w C:\WINDOWS\system32\winnls.dll
+ 2008-04-13 19:24:48 5,120 ----a-w C:\WINDOWS\system32\winnls.dll
- 2006-10-18 18:47:20 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-24 15:12:58 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-05-20 07:32:30 831,048 ----a-w C:\WINDOWS\system32\WudfUpdate_01005.dll
- 2008-04-14 18:29:46 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
+ 2008-04-14 18:41:50 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
- 2008-04-14 18:29:46 483,840 ----a-w C:\WINDOWS\system32\wzcsvc.dll
+ 2008-04-14 18:41:50 483,840 ----a-w C:\WINDOWS\system32\wzcsvc.dll
- 2004-08-04 12:00:00 173,176 ----a-w C:\WINDOWS\system32\xenroll.dll
+ 2006-12-31 04:07:02 173,176 ----a-w C:\WINDOWS\system32\xenroll.dll
- 2008-08-21 09:26:32 121,856 ----a-w C:\WINDOWS\system32\xmllite.dll
+ 2008-04-14 18:29:46 121,856 ----a-w C:\WINDOWS\system32\xmllite.dll
- 2008-03-19 07:54:42 151,552 ----a-w C:\WINDOWS\system32\xRaidAPI.dll
+ 2008-03-19 07:54:44 151,552 ----a-w C:\WINDOWS\system32\xRaidAPI.dll
- 2006-11-01 06:52:38 765,952 ----a-w C:\WINDOWS\system32\xvidcore.dll
+ 2008-01-10 12:15:30 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll
- 2006-11-01 06:54:30 180,224 ----a-w C:\WINDOWS\system32\xvidvfw.dll
+ 2008-01-10 12:16:20 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
- 2008-08-18 07:04:00 270,336 ----a-w C:\WINDOWS\system32\ykx32mpcoinst.dll
+ 2008-09-15 10:56:56 270,336 ----a-w C:\WINDOWS\system32\ykx32mpcoinst.dll
+ 2004-01-25 16:18:44 217,088 ----a-w C:\WINDOWS\system32\yv12vfw.dll
+ 2008-04-15 17:47:48 1,724,416 ----a-w C:\WINDOWS\WinSxS\InstallTemp\4656905\GdiPlus.dll
+ 2004-08-04 12:00:00 921,088 ----a-w C:\WINDOWS\WinSxS\InstallTemp\80139\comctl32.dll
- 2005-09-23 04:29:16 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 10:40:36 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
- 2005-09-23 04:29:16 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 10:40:36 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
- 2005-09-23 04:29:16 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-10-26 10:40:36 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-22 22:35:10 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
+ 2008-04-15 17:47:48 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [09/14/2008 01:39 PM 2474031]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/12/2007 01:43 AM 1661304]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [01/22/2008 11:13 AM 152872]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [08/11/2008 08:31 AM 1124352]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" [06/17/2008 04:00 PM 1249280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/16/2008 02:01 PM 13529088]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [08/04/2004 03:00 PM 208952]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM 33648]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [06/10/2008 12:56 PM 1406024]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [05/28/2008 08:27 AM 570664]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/27/2007 06:32 PM 81920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [10/27/2007 06:28 PM 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/10/2008 01:46 AM 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM 34672]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [10/27/2007 06:30 PM 286720]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [05/16/2008 02:01 PM 86016]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [03/20/2007 02:36 PM 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [11/19/2007 11:01 AM 1970176]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05/27/2008 10:50 AM 413696]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"nwiz"="nwiz.exe" [05/16/2008 02:01 PM 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [09/09/2008 06:39 PM 16851968 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 09:29 PM 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [08/24/2007 03:18 AM 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [08/04/2004 03:00 PM 44544]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MVJP"= C:\WINDOWS\system32\mjpcodec.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\ExtraTools\\ExtraDNS\\ExtraDNS.dll"=
"C:\\Program Files\\Messenger\\Msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
"9420:TCP"= 9420:TCP:Akamai Network Manager
"5000:UDP"= 5000:UDP:Akamai Network Manager
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R2 Akamai;Akamai;C:\WINDOWS\System32\svchost.exe [04/14/2008 09:30 PM 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
R3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [08/08/2006 06:25 PM 182528]
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [04/14/2008 09:30 PM 14336]
S3 GVTDrv;GVTDrv;C:\WINDOWS\system32\Drivers\GVTDrv.sys [09/17/2008 10:05 PM 24944]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [09/02/2008 04:14 PM 191656]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [02/01/2008 04:17 PM 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [02/01/2008 04:17 PM 8320]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [09/11/2008 03:26 AM 355584]
S4 POSPerformanceCounters;Point Of Service Performance Counters;c:\Program Files\Microsoft Point Of Service\Microsoft.PointOfService.Service.exe [02/01/2007 11:14 PM 42352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
"%ProgramFiles%\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{65FFB6E3-03E8-48C4-9376-D649003738E9}]
HIDEC /W "%VAIOTOOLS%\REGTLIB" "%ProgramFiles%\Common Files\Ahead\Lib\NeroGadgetCMServer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
"%ProgramFiles%\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
HIDEC /W "%VAIOTOOLS%\REGTLIB" "%ProgramFiles%\Windows Sidebar\sidebar.exe"
.
s of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-Nokia.PCSync - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\w\Application Data\Mozilla\Firefox\Profiles\syjrufjz.default\
FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-21 04:35:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3409.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/rswin_3409.dll"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\LightSurf\Common\IconMgr.exe
C:\Program Files\LightSurf\Colorific\hgcctl95.exe
C:\Program Files\LightSurf\Color Indicator\TICIcon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\wscntfy.exe
C:\ComboFix\pv.cfexe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 09/21/2008 4:51:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-21 01:51:05
ComboFix2.txt 2008-09-04 02:13:03
Pre-Run: 45,560,152,064 bytes free
Post-Run: 46,146,539,520 bytes free
1186 --- E O F --- 2008-09-19 20:40:17
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
تقرير Hijack
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:55:29 ص, on 21/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\LightSurf\Common\IconMgr.exe
C:\Program Files\LightSurf\Colorific\hgcctl95.exe
C:\Program Files\LightSurf\Color Indicator\TICIcon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\w\سطح المكتب\Zyzoom_HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: مساعد تسجيل الدخول إلى Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIEsBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: LightSurf.lnk = C:\Program Files\LightSurf\Common\IconMgr.exe
O8 - Extra context menu item: "إضافة إلى حاجب الدعايات" - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free Download Manager تحميل الفيديو بواسطة -
Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: تحميل المحددة بفري داونلود مانيجر -
Files\Free Download Manager\dlselected.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: إرسال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: إر&سال إلى OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) -
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)
--
End of file - 11264 bytes
مع الشكر