Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Aug 21 2008, 03:37 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 16 Joined: 20-August 08 Member No.: 231,686 |
Symptoms observed before manual cleanup: ============================ System originally had v6msn.exe infection as well, and I believe I removed this. - taskmgr disabled - msconfig disabled - regedit disabled - many websites blocked (including bleeping computer) - hijackthis prevented from running (runs if renamed to something else) NOTE: gpedit.msc is not disabled and will run, allowing you to manually throw DISABLE on the taskmanager blocking etc. On next reboot the DISABLE setting is ignored and must be bounced. - systempre.exe sitting in WINDOWS\system32\ - <random named exe file> sitting in WINDOWS\system32\ (examples iafxqxs.exe, ygyvosm.exe, vscnnq.exe) - <randome named exe file> sitting in \Documents and Settings\<user that was logged in when virus last deployed> - HKLM\..\Run: [System Presets] systempre.exe - HKLM\..\Run: [System Presets] <random named file>.exe "Userinit"="C:\\WINDOWS\\SYSTEM32\\Userinit.exe," changed to load <random>.exe === SDFix fails to remove as virus reinstates systempre.exe as soon as network cable is plugged in next time. Prep steps taken =========== cleanmgr - run adaware - clean spybit - cannot run because it forces an internet check, and infected box is off the net. (Plugging box into net activates virus host which deploys systempre.exe etc) Stinger - clean housecall/panda/bitdefender - not run. all require net connection. Firewall - Sygate firewall installed (windows firewall off) Updates - SP3 installed, loaded batch of 21 recent stored updates, not sure if completely updated. HJT Log ===== Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:03:53 PM, on 8/21/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\WINDOWS\system32\acs.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\TPHDEXLG.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\TpShocks.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\Program Files\ScanSoft\OmniPageSE\opware32.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1192779822406 O17 - HKLM\System\CCS\Services\Tcpip\..\{93008F3B-85B5-41D8-B1FB-9225D9F2B837}: NameServer = 208.201.224.11,208.201.224.33 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- End of file - 5813 bytes Additional Notes: =========== System originally had v6msn.exe infection as well, and I believe I removed this. Portion of SDFIX log BEFORE manual cleanup: === C:\PROGRA~1\PEAZIP\RES\LPAQ\LPAQ1.EXE - Deleted C:\WINDOWS\system32\systempre.exe - Deleted C:\WINDOWS\system32\v6msn.exe - Deleted Files with Hidden Attributes : Sun 13 Jul 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe" Thu 1 Nov 2007 59,392 ..SHR --- "C:\WINDOWS\system32\ESaudio.exe" Wed 23 Jul 2008 49,664 ..SHR --- "C:\WINDOWS\system32\msnchat6.1.7.exe" Mon 21 Jul 2008 49,664 ..SHR --- "C:\WINDOWS\system32\msnv6.1.exe" Actions Taken === ESaudio - I renamed it Picasa2\setup.exe - deleted deleted all exe's mentions removed all reg keys mentioned (run keys as well as firewall keys) Full text of SDFIX systemreport.txt ====================== System Report ************* Run on Thu 08/21/2008 at 01:24 PM Microsoft Windows XP [Version 5.1.2600] Current user is an administrator Running Processes: \SystemRoot\System32\smss.exe [1056] \??\C:\WINDOWS\system32\csrss.exe [1148] \??\C:\WINDOWS\system32\winlogon.exe [1176] C:\WINDOWS\system32\services.exe [1220] C:\WINDOWS\system32\lsass.exe [1232] C:\WINDOWS\system32\ibmpmsvc.exe [1400] C:\WINDOWS\system32\svchost.exe [1428] C:\WINDOWS\system32\svchost.exe [1472] C:\WINDOWS\System32\svchost.exe [1512] C:\Program Files\Sygate\SPF\smc.exe [1640] C:\WINDOWS\system32\svchost.exe [1744] C:\WINDOWS\system32\svchost.exe [1788] C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008] C:\WINDOWS\system32\spoolsv.exe [344] C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [388] C:\WINDOWS\system32\acs.exe [732] C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [780] C:\WINDOWS\system32\svchost.exe [904] C:\WINDOWS\System32\TPHDEXLG.exe [928] C:\WINDOWS\system32\TpKmpSVC.exe [948] C:\WINDOWS\System32\alg.exe [1600] C:\WINDOWS\system32\wbem\wmiprvse.exe [1632] C:\WINDOWS\Explorer.EXE [1928] C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2200] C:\WINDOWS\system32\igfxtray.exe [2320] C:\WINDOWS\system32\igfxpers.exe [2372] C:\Program Files\Analog Devices\Core\smax4pnp.exe [2400] C:\WINDOWS\system32\igfxsrvc.exe [2456] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2512] C:\WINDOWS\system32\rundll32.exe [2540] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2580] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2596] C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe [2624] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2636] C:\WINDOWS\system32\TpShocks.exe [2716] C:\Program Files\Lenovo\Zoom\TpScrex.exe [2740] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2760] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [2772] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2796] C:\Program Files\Logitech\QuickCam\Quickcam.exe [2808] C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe [3332] Drivers - Running: ACPI ACPIEC ADIHdAudAddService AEAudio AFD AR5211 Arp1394 atapi audstub Beep Cdfs Cdrom CmBatt Compbatt Disk e1express Fastfat Fips FltMgr Ftdisk Gpc HDAudBus HSFHWAZL HSF_DPV HTTP i8042prt ialm iastor IBMPMDRV Imapi intelppm IpNat IPSec isapnp Kbdclass kmixer KSecDD LVPr2Mon mdmxsdk mnmdd Modem Mouclass MountMgr MRxDAV MRxSmb Msfs mssmbios Mup NDIS NdisTapi Ndisuio NdisWan NDProxy NetBIOS NetBT NIC1394 Npfs Ntfs Null ohci1394 PartMgr PCI PCIIde Pcmcia PptpMiniport PSched Ptilink PxHelp20 RasAcd Rasl2tp RasPppoe Raspti Rdbss RDPCDD rdpdr redbook rimmptsk rimsptsk RimVSerPort rismxdp ROOTMODEM sdbus Secdrv Shockprf sr Srv swenum SynTP sysaudio Tcpip Teefer TermDD TPDIGIMN TPHKDRV TPPWRIF TSMAPIP Update usbehci usbhub usbuhci VgaSave VolSnap Wanarp wdmaud wg3n wg4n wg5n wg6n winachsf WmiAcpi wpsdrvnt WSIMD Drivers - Stopped: Abiosdsk abp480n5 adpu160m aec Aha154x aic78u2 aic78xx AliIde amsint asc asc3350p asc3550 AsyncMac Atdisk Atmarpc catchme cbidf2k CCDECODE cd20xrnt Cdaudio Changer CmdIde Cpqarray dac960nt dmboot dmio dmload DMusic dpti2o drmkaud Fdc Flpydisk hidusb hpn i2omgmt i2omp ini910u IntelIde Ip6Fw IpFilterDriver IpInIp IRENUM lbrtfdc LVcKap LVMVDrv LVUSBSta mouhid mraid35x MSKSSRV MSPCLOCK MSPQM MSTEE NABTSFEC NdisIP NwlnkFlt NwlnkFwd Parport ParVdm PCIDump PDCOMP PDFRAME PDRELI PDRFRAME perc2 perc2hib PID_0928 ql1080 Ql10wnt ql12160 ql1240 ql1280 RDPWD RimUsb Serial sffdisk sffp_sd Sfloppy Simbad SLIP Sparrow splitter streamip swmidi symc810 symc8xx sym_hi sym_u3 TDPIPE TDTCP TosIde Udfs UIUSys ultra usbccgp usbprint usbscan USBSTOR ViaIde vsdatant WDICA WSTCODEC Services - Running: aawservice acs ALG AudioSrv Browser CryptSvc DcomLaunch Dhcp Dnscache ERSvc Eventlog EventSystem helpsvc IBMPMSVC lanmanserver lanmanworkstation LmHosts LVCOMSer LVPrcSrv Netman Nla PlugPlay PolicyAgent ProtectedStorage RasMan RemoteRegistry RpcSs SamSs Schedule seclogon SENS SharedAccess ShellHWDetection SmcService Spooler srservice SSDPSRV stisvc TapiSrv TermService Themes TPHDEXLGSVC TpKmpSVC TrkWks W32Time WebClient winmgmt wscsvc wuauserv WZCSVC Services - Stopped: Alerter AppMgmt BITS CiSvc ClipSrv COMSysApp dmadmin dmserver Dot3svc EapHost FastUserSwitchingCompatibility gusvc HidServ hkmsvc HTTPFilter IDriverT ImapiService LVSrvLauncher Messenger mnmsrvc MSDTC MSIServer napagent NetDDE NetDDEdsdm Netlogon NtLmSsp NtmsSvc ose RasAuto RDSessMgr RemoteAccess RpcLocator RSVP SCardSvr SwPrv SysmonLog TlntSvr upnphost UPS VSS WinVNC4 WmdmPmSN Wmi WmiApSrv xmlprov Files Created/Modified - 60 Days: C:\ Aug 21 2008 12:58:20p 1,046,786,048 A.SH. "C:\hiberfil.sys" Aug 20 2008 4:52:36p 250,048 A.SHR "C:\ntldr" Aug 21 2008 12:58:02p 1,572,864,000 A.SH. "C:\pagefile.sys" Aug 20 2008 1:11:32a 244 A..H. "C:\sqmnoopt12.sqm" Aug 20 2008 1:53:58a 244 A..H. "C:\sqmnoopt13.sqm" Aug 19 2008 5:40:36p 244 A..H. "C:\sqmnoopt10.sqm" Aug 19 2008 6:24:40p 244 A..H. "C:\sqmnoopt11.sqm" Aug 20 2008 2:53:14a 244 A..H. "C:\sqmnoopt16.sqm" Aug 18 2008 9:44:20p 244 A..H. "C:\sqmnoopt17.sqm" Aug 20 2008 2:12:34a 244 A..H. "C:\sqmnoopt14.sqm" Aug 20 2008 2:15:46a 244 A..H. "C:\sqmnoopt15.sqm" Aug 19 2008 2:44:26p 244 A..H. "C:\sqmnoopt06.sqm" Aug 19 2008 3:28:28p 244 A..H. "C:\sqmnoopt07.sqm" Aug 19 2008 1:16:20p 244 A..H. "C:\sqmnoopt04.sqm" Aug 19 2008 2:00:22p 244 A..H. "C:\sqmnoopt05.sqm" Aug 18 2008 10:24:22p 244 A..H. "C:\sqmnoopt18.sqm" Aug 19 2008 9:36:04a 244 A..H. "C:\sqmnoopt19.sqm" Aug 19 2008 4:12:32p 244 A..H. "C:\sqmnoopt08.sqm" Aug 19 2008 4:56:34p 244 A..H. "C:\sqmnoopt09.sqm" Aug 19 2008 5:40:36p 232 A..H. "C:\sqmdata10.sqm" Aug 20 2008 2:12:34a 268 A..H. "C:\sqmdata14.sqm" Aug 19 2008 1:16:20p 232 A..H. "C:\sqmdata04.sqm" Aug 18 2008 10:24:22p 232 A..H. "C:\sqmdata18.sqm" Aug 19 2008 4:12:32p 232 A..H. "C:\sqmdata08.sqm" Aug 19 2008 6:24:40p 232 A..H. "C:\sqmdata11.sqm" Aug 20 2008 2:15:46a 268 A..H. "C:\sqmdata15.sqm" Aug 19 2008 2:00:22p 232 A..H. "C:\sqmdata05.sqm" Aug 19 2008 9:36:04a 232 A..H. "C:\sqmdata19.sqm" Aug 19 2008 4:56:34p 232 A..H. "C:\sqmdata09.sqm" Aug 20 2008 1:11:32a 268 A..H. "C:\sqmdata12.sqm" Aug 20 2008 2:53:14a 268 A..H. "C:\sqmdata16.sqm" Aug 19 2008 2:44:26p 232 A..H. "C:\sqmdata06.sqm" Aug 20 2008 1:53:58a 232 A..H. "C:\sqmdata13.sqm" Aug 18 2008 9:44:20p 232 A..H. "C:\sqmdata17.sqm" Aug 19 2008 3:28:28p 232 A..H. "C:\sqmdata07.sqm" Aug 19 2008 10:20:08a 232 A..H. "C:\sqmdata00.sqm" Aug 19 2008 11:04:10a 232 A..H. "C:\sqmdata01.sqm" Aug 19 2008 11:48:14a 232 A..H. "C:\sqmdata02.sqm" Aug 19 2008 12:32:16p 232 A..H. "C:\sqmdata03.sqm" Aug 19 2008 10:20:08a 244 A..H. "C:\sqmnoopt00.sqm" Aug 19 2008 11:04:10a 244 A..H. "C:\sqmnoopt01.sqm" Aug 19 2008 11:48:14a 244 A..H. "C:\sqmnoopt02.sqm" Aug 19 2008 12:32:16p 244 A..H. "C:\sqmnoopt03.sqm" Aug 21 2008 12:58:24p 3,432 A.... "C:\TPHKLOCK.TXT" C:\WINDOWS\ Aug 21 2008 12:58:44p 0 A.... "C:\WINDOWS\0.log" Aug 21 2008 12:58:22p 2,048 A.S.. "C:\WINDOWS\bootstat.dat" Jul 5 2008 10:46:48p 136 A.... "C:\WINDOWS\ChssBase.ini" Aug 20 2008 4:58:38p 373 A.... "C:\WINDOWS\cmsetacl.log" Aug 20 2008 5:40:08p 204,052 A.... "C:\WINDOWS\comsetup.log" Aug 20 2008 5:03:52p 359 A.... "C:\WINDOWS\DtcInstall.log" Aug 20 2008 5:40:08p 586,533 A.... "C:\WINDOWS\FaxSetup.log" Aug 20 2008 5:40:08p 661,066 A.... "C:\WINDOWS\iis6.log" Aug 20 2008 5:40:02p 1,374 A.... "C:\WINDOWS\imsins.BAK" Aug 20 2008 5:40:08p 1,374 A.... "C:\WINDOWS\imsins.log" Aug 20 2008 9:42:36a 4,194 A.... "C:\WINDOWS\KB944338-v2.log" Aug 20 2008 9:42:48a 3,779 A.... "C:\WINDOWS\KB950749.log" Aug 20 2008 5:38:24p 10,674 A.... "C:\WINDOWS\KB950762.log" Aug 20 2008 5:39:42p 16,060 A.... "C:\WINDOWS\KB950974.log" Aug 20 2008 5:38:10p 10,700 A.... "C:\WINDOWS\KB951066.log" Aug 20 2008 5:38:20p 29,074 A.... "C:\WINDOWS\KB951072-v2.log" Aug 20 2008 5:40:08p 11,592 A.... "C:\WINDOWS\KB951376-v2.log" Aug 20 2008 5:39:22p 15,257 A.... "C:\WINDOWS\KB951698.log" Aug 20 2008 5:35:56p 14,939 A.... "C:\WINDOWS\KB951748.log" Aug 20 2008 5:38:14p 10,443 A.... "C:\WINDOWS\KB952287.log" Aug 20 2008 5:40:02p 16,586 A.... "C:\WINDOWS\KB952954.log" Aug 20 2008 5:36:12p 16,425 A.... "C:\WINDOWS\KB953838.log" Aug 20 2008 5:39:58p 10,508 A.... "C:\WINDOWS\KB953839.log" Aug 20 2008 5:40:08p 41,523 A.... "C:\WINDOWS\MedCtrOC.log" Aug 20 2008 5:40:08p 29,380 A.... "C:\WINDOWS\msgsocm.log" Aug 20 2008 5:40:06p 184,854 A.... "C:\WINDOWS\msmqinst.log" Aug 20 2008 5:40:08p 103,183 A.... "C:\WINDOWS\netfxocm.log" Jun 23 2008 11:35:22p 395 A.... "C:\WINDOWS\nsw.log" Aug 20 2008 7:13:20p 2,237,828 A.... "C:\WINDOWS\ntbtlog.txt" Aug 20 2008 5:40:08p 121,837 A.... "C:\WINDOWS\ntdtcsetup.log" Aug 20 2008 5:40:08p 286,349 A.... "C:\WINDOWS\ocgen.log" Aug 20 2008 5:40:08p 32,510 A.... "C:\WINDOWS\ocmsn.log" Aug 21 2008 12:22:38p 376 A.... "C:\WINDOWS\ODBC.INI" Aug 20 2008 5:03:56p 1,868 A.... "C:\WINDOWS\OEWABLog.txt" Aug 10 2008 11:47:36p 1,409 A.... "C:\WINDOWS\QTFont.for" Aug 10 2008 11:47:36p 54,156 A..H. "C:\WINDOWS\QTFont.qfn" Aug 21 2008 12:57:26p 32,642 A.... "C:\WINDOWS\SchedLgU.Txt" Aug 20 2008 4:58:30p 1,281 A.... "C:\WINDOWS\sessmgr.setup.log" Aug 21 2008 12:22:38p 179,190 A.... "C:\WINDOWS\setupact.log" Aug 20 2008 11:44:46p 4,815 A.... "C:\WINDOWS\setupapi.log" Aug 20 2008 5:00:02p 1,057,463 A.... "C:\WINDOWS\setupapi.log.0.old" Aug 20 2008 5:03:18p 876,870 A.... "C:\WINDOWS\setuplog.txt" Aug 20 2008 5:04:16p 69,776 A.... "C:\WINDOWS\spupdsvc.log" Aug 20 2008 5:03:34p 187 A.... "C:\WINDOWS\spupdsvc.log.1.log" Aug 20 2008 5:01:32p 551,790 A.... "C:\WINDOWS\svcpack.log" Aug 20 2008 5:40:08p 30,331 A.... "C:\WINDOWS\tabletoc.log" Aug 20 2008 5:40:08p 271,598 A.... "C:\WINDOWS\tsoc.log" Aug 20 2008 5:40:02p 117,725 A.... "C:\WINDOWS\updspapi.log" Aug 21 2008 12:58:40p 159 A.... "C:\WINDOWS\wiadebug.log" Aug 21 2008 12:58:46p 49 A.... "C:\WINDOWS\wiaservc.log" Aug 20 2008 5:37:10p 756 A.... "C:\WINDOWS\win.ini" Aug 21 2008 12:59:26p 1,086,806 A.... "C:\WINDOWS\WindowsUpdate.log" Aug 20 2008 5:04:16p 5,073 A.... "C:\WINDOWS\wmsetup.log" Aug 20 2008 5:04:14p 316,640 A.... "C:\WINDOWS\WMSysPr9.prx" Aug 20 2008 4:50:38p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00003" Aug 20 2008 4:50:38p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00004" ... <NOTE I REMOVED A LONG LIST OF SP3 UNINSTALL FILES HERE TO SAVE SPACE> ... Aug 20 2008 4:51:20p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg02390" Aug 20 2008 5:03:54p 572 A.... "C:\WINDOWS\Debug\blastcln.log" Jun 23 2008 11:35:16p 5,733 A.... "C:\WINDOWS\Debug\NetSetup.LOG" Aug 21 2008 12:58:22p 0 A.... "C:\WINDOWS\Debug\PASSWD.LOG" Aug 20 2008 11:44:26p 4,676 A.... "C:\WINDOWS\inf\branches.PNF" Aug 20 2008 4:59:56p 25,780 A.... "C:\WINDOWS\inf\bth.PNF" Aug 20 2008 11:44:26p 6,224 A.... "C:\WINDOWS\inf\bthprint.PNF" Aug 20 2008 11:44:26p 5,972 A.... "C:\WINDOWS\inf\bthspp.PNF" Aug 20 2008 5:00:58p 134,788 A.... "C:\WINDOWS\inf\comnt5.PNF" Aug 20 2008 11:44:28p 326,568 A.... "C:\WINDOWS\inf\defltwk.PNF" Aug 20 2008 4:59:56p 222,468 A.... "C:\WINDOWS\inf\drvindex.PNF" Aug 20 2008 5:00:58p 10,240 A.... "C:\WINDOWS\inf\dtcnt5.PNF" Aug 20 2008 11:44:28p 334,564 A.... "C:\WINDOWS\inf\dwup.PNF" Aug 20 2008 11:44:28p 5,004 A.... "C:\WINDOWS\inf\fltmgr.PNF" Aug 20 2008 5:00:58p 17,568 A.... "C:\WINDOWS\inf\fp40ext.PNF" Aug 20 2008 5:00:02p 6,796 A.... "C:\WINDOWS\inf\hdaudbus.PNF" Aug 20 2008 11:44:28p 7,780 A.... "C:\WINDOWS\inf\hidbth.PNF" Aug 20 2008 11:44:28p 9,476 A.... "C:\WINDOWS\inf\HidDigi.PNF" Aug 20 2008 11:44:28p 12,720 A.... "C:\WINDOWS\inf\hidserv.PNF" Aug 20 2008 11:44:28p 83,728 A.... "C:\WINDOWS\inf\ie.PNF" Aug 20 2008 5:00:58p 4,464 A.... "C:\WINDOWS\inf\ieaccess.PNF" Aug 20 2008 5:00:58p 971,036 A.... "C:\WINDOWS\inf\iis.PNF" Aug 20 2008 5:00:58p 105,208 A.... "C:\WINDOWS\inf\ims.PNF" Aug 20 2008 11:44:38p 1,433,016 A.... "C:\WINDOWS\inf\INFCACHE.1" Aug 20 2008 11:44:28p 108,916 A.... "C:\WINDOWS\inf\input.PNF" Aug 20 2008 11:44:30p 432,252 A.... "C:\WINDOWS\inf\intl.PNF" Aug 20 2008 11:44:30p 28,188 A.... "C:\WINDOWS\inf\irbus.PNF" Aug 20 2008 11:44:30p 67,708 A.... "C:\WINDOWS\inf\keyboard.PNF" Aug 20 2008 5:00:56p 2,916 A.... "C:\WINDOWS\inf\koc.PNF" Aug 20 2008 11:44:30p 91,444 A.... "C:\WINDOWS\inf\ks.PNF" Aug 20 2008 11:44:30p 43,500 A.... "C:\WINDOWS\inf\kscaptur.PNF" Aug 20 2008 11:44:30p 24,640 A.... "C:\WINDOWS\inf\ksfilter.PNF" Aug 20 2008 4:59:54p 1,068,864 A.... "C:\WINDOWS\inf\LAYOUT.PNF" Aug 20 2008 5:00:02p 187,380 A.... "C:\WINDOWS\inf\machine.PNF" Aug 20 2008 11:44:30p 30,564 A.... "C:\WINDOWS\inf\mchgr.PNF" Aug 20 2008 11:44:32p 17,572 A.... "C:\WINDOWS\inf\mdac.PNF" Aug 20 2008 11:44:32p 40,560 A.... "C:\WINDOWS\inf\mdmbtmdm.PNF" Aug 20 2008 11:44:32p 108,224 A.... "C:\WINDOWS\inf\mdmirmdm.PNF" Aug 20 2008 11:44:32p 8,284 A.... "C:\WINDOWS\inf\mpe.PNF" Aug 20 2008 11:44:32p 49,540 A.... "C:\WINDOWS\inf\mshdc.PNF" Aug 20 2008 5:03:56p 35,964 A.... "C:\WINDOWS\inf\msoe50.PNF" Aug 20 2008 11:44:32p 23,816 A.... "C:\WINDOWS\inf\mstape.PNF" Aug 20 2008 11:44:32p 9,636 A.... "C:\WINDOWS\inf\nabtsfec.PNF" Aug 20 2008 11:44:32p 9,096 A.... "C:\WINDOWS\inf\ndisip.PNF" Aug 20 2008 5:01:00p 3,652 A.... "C:\WINDOWS\inf\netbeac.PNF" Aug 20 2008 5:03:42p 3,704 A.... "C:\WINDOWS\inf\netfw.PNF" Aug 20 2008 5:01:00p 174,876 A.... "C:\WINDOWS\inf\netfxocm.PNF" Aug 20 2008 11:44:32p 13,020 A.... "C:\WINDOWS\inf\netip6.PNF" Aug 20 2008 11:44:34p 20,344 A.... "C:\WINDOWS\inf\netmscli.PNF" Aug 20 2008 5:00:58p 16,448 A.... "C:\WINDOWS\inf\netoc.PNF" Aug 20 2008 11:44:34p 45,180 A.... "C:\WINDOWS\inf\netrass.PNF" Aug 20 2008 11:44:34p 6,800 A.... "C:\WINDOWS\inf\netrndis.PNF" Aug 20 2008 11:44:34p 39,216 A.... "C:\WINDOWS\inf\nettcpip.PNF" Aug 20 2008 11:44:34p 6,348 A.... "C:\WINDOWS\inf\nettun.PNF" Aug 20 2008 11:44:34p 8,932 A.... "C:\WINDOWS\inf\netupnph.PNF" Aug 20 2008 11:44:34p 7,028 A.... "C:\WINDOWS\inf\netwzc.PNF" Aug 20 2008 11:44:34p 1,317,388 A.... "C:\WINDOWS\inf\ntprint.PNF" Aug 20 2008 5:01:00p 4,384 A.... "C:\WINDOWS\inf\oeaccess.PNF" Aug 20 2008 3:14:02a 0 ...H. "C:\WINDOWS\inf\oem46.inf" Aug 20 2008 11:44:36p 17,240 A.... "C:\WINDOWS\inf\oobe.PNF" Aug 20 2008 5:01:00p 14,492 A.... "C:\WINDOWS\inf\p2p.PNF" Aug 20 2008 11:44:36p 105,552 A.... "C:\WINDOWS\inf\pnpscsi.PNF" Jul 18 2008 4:58:54p 6,496 A.... "C:\WINDOWS\inf\pxhelp20.PNF" Aug 20 2008 11:44:36p 11,920 A.... "C:\WINDOWS\inf\qmgr.PNF" Aug 20 2008 11:44:36p 7,172 A.... "C:\WINDOWS\inf\ramdisk.PNF" Aug 20 2008 5:03:56p 39,428 A.... "C:\WINDOWS\inf\sceregvl.PNF" Aug 20 2008 11:44:36p 21,944 A.... "C:\WINDOWS\inf\scsi.PNF" Aug 20 2008 4:59:56p 10,732 A.... "C:\WINDOWS\inf\sdbus.PNF" Aug 20 2008 11:44:36p 26,712 A.... "C:\WINDOWS\inf\secrecs.PNF" Aug 20 2008 4:59:58p 10,036 A.... "C:\WINDOWS\inf\sffdisk.PNF" Aug 20 2008 11:44:36p 38,476 A.... "C:\WINDOWS\inf\shell.PNF" Aug 20 2008 11:44:36p 15,720 A.... "C:\WINDOWS\inf\shl_img.PNF" Aug 20 2008 11:44:36p 9,196 A.... "C:\WINDOWS\inf\slip.PNF" Aug 20 2008 11:44:36p 36,372 A.... "C:\WINDOWS\inf\smartcrd.PNF" Aug 20 2008 11:44:36p 11,956 A.... "C:\WINDOWS\inf\streamip.PNF" Aug 20 2008 11:44:36p 5,724 A.... "C:\WINDOWS\inf\swflash.PNF" Aug 20 2008 5:00:56p 7,356 A.... "C:\WINDOWS\inf\SYSOC.PNF" Aug 20 2008 11:44:38p 101,276 A.... "C:\WINDOWS\inf\syssetup.PNF" Aug 20 2008 5:01:00p 558,428 A.... "C:\WINDOWS\inf\tabletpc.PNF" Aug 20 2008 11:44:38p 59,804 A.... "C:\WINDOWS\inf\tape.PNF" Aug 20 2008 11:44:38p 9,424 A.... "C:\WINDOWS\inf\tdibth.PNF" Aug 20 2008 5:00:58p 131,204 A.... "C:\WINDOWS\inf\tsoc.PNF" Aug 20 2008 11:44:38p 51,448 A.... "C:\WINDOWS\inf\usbport.PNF" Aug 20 2008 11:44:38p 20,324 A.... "C:\WINDOWS\inf\usbvideo.PNF" Aug 20 2008 5:00:56p 14,228 A.... "C:\WINDOWS\inf\wbemoc.PNF" Aug 20 2008 11:44:38p 74,520 A.... "C:\WINDOWS\inf\wdma_ali.PNF" Aug 20 2008 11:44:38p 33,508 A.... "C:\WINDOWS\inf\wdma_via.PNF" Aug 20 2008 4:59:54p 57,172 A.... "C:\WINDOWS\inf\wmp.PNF" Aug 20 2008 11:44:38p 9,200 A.... "C:\WINDOWS\inf\wstcodec.PNF" Jul 7 2008 1:26:58p 253,952 A.... "C:\WINDOWS\system32\es.dll" Aug 20 2008 5:42:52p 204,120 A.... "C:\WINDOWS\system32\FNTCACHE.DAT" Aug 20 2008 4:47:18p 1,053 A.... "C:\WINDOWS\system32\lvcoinst.log" Jun 24 2008 9:43:16a 74,240 A.... "C:\WINDOWS\system32\mscms.dll" Jun 23 2008 8:09:28a 3,067,392 A.... "C:\WINDOWS\system32\mshtml.dll" Aug 20 2008 6:31:20p 1,786 A.... "C:\WINDOWS\system32\PerfStringBackup.TMP" Jun 26 2008 1:15:30a 1,499,136 A.... "C:\WINDOWS\system32\shdocvw.dll" Aug 20 2008 5:03:32p 255 A.... "C:\WINDOWS\system32\spupdwxp.log" Aug 21 2008 11:07:20a 384 A.... "C:\WINDOWS\system32\TPAPSLOG.LOG" Aug 21 2008 12:58:42p 2,560 A.... "C:\WINDOWS\system32\TPHDLOG0.LOG" Jul 11 2008 5:42:28a 62,976 ..... "C:\WINDOWS\system32\tzchange.exe" Aug 20 2008 5:38:16p 349,202 A.... "C:\WINDOWS\system32\TZLog.log" Jun 26 2008 1:15:30a 619,520 A.... "C:\WINDOWS\system32\urlmon.dll" Jun 23 2008 8:09:28a 666,112 A.... "C:\WINDOWS\system32\wininet.dll" Aug 20 2008 11:23:08a 13,588 A.... "C:\WINDOWS\system32\wpa.bak" Aug 21 2008 12:58:44p 13,646 A.... "C:\WINDOWS\system32\wpa.dbl" Aug 21 2008 12:58:48p 302 A.... "C:\WINDOWS\Tasks\PMTask.job" Aug 21 2008 12:58:30p 6 A..H. "C:\WINDOWS\Tasks\SA.DAT" Aug 21 2008 1:19:12p 3,845 A.... "C:\WINDOWS\Temp\LVCOMSX.LOG" Aug 21 2008 1:23:38p 37,695 A.... "C:\WINDOWS\Temp\scs4.tmp" Aug 20 2008 4:58:12p 4,828 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\Service Pack 3.asms" Aug 20 2008 5:01:00p 1,161,355 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.inf" Aug 20 2008 4:51:20p 508,435 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.txt" Aug 20 2008 10:12:10a 562,784 A.... "C:\WINDOWS\Debug\Setup\UpdSh.bak" Aug 20 2008 5:01:12p 543,504 A.... "C:\WINDOWS\Debug\Setup\UpdSh.log" Jul 1 2008 9:02:24p 308,376 A.... "C:\WINDOWS\Debug\UserMode\userenv.bak" Aug 21 2008 12:58:22p 231,232 A.... "C:\WINDOWS\Debug\UserMode\userenv.log" Aug 20 2008 5:01:02p 1,056,768 A.... "C:\WINDOWS\security\Database\Service Pack 3.sdb" Aug 20 2008 5:03:52p 732 A.... "C:\WINDOWS\security\logs\scecomp.old" Aug 20 2008 5:01:02p 7,168 A.... "C:\WINDOWS\security\logs\update.log" Jul 7 2008 1:26:58p 253,952 ..... "C:\WINDOWS\system32\dllcache\es.dll" Jun 24 2008 9:43:16a 74,240 ..... "C:\WINDOWS\system32\dllcache\mscms.dll" Jun 23 2008 8:09:28a 3,067,392 ..... "C:\WINDOWS\system32\dllcache\mshtml.dll" Jun 26 2008 1:15:30a 1,499,136 ..... "C:\WINDOWS\system32\dllcache\shdocvw.dll" Jun 26 2008 1:15:30a 619,520 ..... "C:\WINDOWS\system32\dllcache\urlmon.dll" Aug 20 2008 6:19:36p 578,560 A.... "C:\WINDOWS\system32\dllcache\user32.dll" Jun 23 2008 8:09:28a 666,112 ..... "C:\WINDOWS\system32\dllcache\wininet.dll" Aug 20 2008 3:01:22a 156 A.... "C:\WINDOWS\system32\GroupPolicy\gpt.ini" Aug 20 2008 5:03:14p 3,201 A.... "C:\WINDOWS\system32\oobe\agtscrp2.js" Aug 20 2008 5:03:14p 9,607 A.... "C:\WINDOWS\system32\oobe\oobeutil.js" Aug 20 2008 5:03:14p 32,004 A.... "C:\WINDOWS\system32\oobe\updshell.htm" Aug 20 2008 4:58:12p 500 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63.Manifest" Aug 20 2008 4:58:10p 1,237 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest" Aug 20 2008 4:58:12p 1,822 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a.Manifest" Aug 20 2008 4:58:10p 1,883 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest" Aug 20 2008 4:58:10p 1,187 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest" Aug 20 2008 4:58:10p 460 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc 0.Manifest" Aug 20 2008 4:58:12p 1,862 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83.Manifest" Aug 20 2008 4:58:10p 397 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c.Manifest" Aug 20 2008 4:46:12p 0 A.... "C:\WINDOWS\Debug\Setup\Backup\HDAUDIO_Backup.bak" Aug 20 2008 4:46:12p 4 A.... "C:\WINDOWS\Debug\Setup\Backup\INTPPM_Backup.bak" Aug 20 2008 5:00:10p 14,688,256 A.... "C:\WINDOWS\pchealth\helpctr\Database\HCdata.edb" Aug 20 2008 4:59:42p 2,974,155 A.... "C:\WINDOWS\pchealth\helpctr\Indices\merged.hhk" Aug 20 2008 4:59:42p 13,328 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_2.hhk" Aug 20 2008 4:59:42p 16,703 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_3.hhk" Aug 20 2008 4:59:42p 35,565 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_4.hhk" Aug 20 2008 4:59:42p 20,016 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_5.hhk" Aug 20 2008 4:59:42p 15,646 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_6.hhk" Aug 20 2008 4:59:42p 102,895 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_7.hhk" Aug 20 2008 4:59:42p 209,095 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_8.hhk" Aug 20 2008 4:59:42p 51,061 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_9.hhk" Aug 20 2008 4:59:52p 935,163 A.... "C:\WINDOWS\pchealth\helpctr\Logs\hcupdate.log" Aug 20 2008 4:59:52p 86,327 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat" Aug 20 2008 4:59:52p 4 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\CRC_Disk" Aug 20 2008 4:58:40p 309,519 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_7.cab" Aug 20 2008 4:59:52p 68,704 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_8.cab" Aug 20 2008 4:59:52p 3,460 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin" Aug 20 2008 4:58:44p 6,150 A.... "C:\WINDOWS\pchealth\helpctr\System\Headlines.htm" Aug 20 2008 4:58:44p 5,812 A.... "C:\WINDOWS\pchealth\helpctr\System\HelpCtr.mmf" Aug 20 2008 4:58:44p 7,737 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__DESKTOP.htm" Aug 20 2008 4:58:44p 7,355 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__SERVER.htm" Aug 20 2008 6:20:24p 686 A.... "C:\WINDOWS\system32\drivers\etc\HOSTS" Aug 20 2008 1:13:42a 81 ...H. "C:\WINDOWS\system32\GroupPolicy\Adm\admfiles.ini" Aug 20 2008 3:01:22a 384 A.... "C:\WINDOWS\system32\GroupPolicy\User\Registry.pol" Aug 20 2008 2:08:06p 8,239 A.... "C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log" Aug 20 2008 5:03:14p 5,579 A.... "C:\WINDOWS\system32\oobe\setup\autoupdt.htm" Aug 20 2008 5:03:14p 13,568 A.... "C:\WINDOWS\system32\oobe\setup\au_plcy.htm" Jun 27 2008 11:34:16p 1,468 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00000.SHD" Jun 27 2008 8:40:32p 10,792 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00000.SPL" Jun 27 2008 11:34:16p 1,468 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00001.SHD" Jun 27 2008 8:41:38p 10,792 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00001.SPL" Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00002.SHD" Jul 1 2008 1:55:12p 36,544 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00002.SPL" Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00003.SHD" Jul 1 2008 1:55:20p 34,368 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00003.SPL" Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00004.SHD" Jul 1 2008 1:55:22p 34,368 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00004.SPL" Jul 13 2008 9:39:20p 1,344 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00005.SHD" Jul 13 2008 6:54:48p 5,409,320 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00005.SPL" Aug 20 2008 4:58:34p 2,775,948 A.... "C:\WINDOWS\system32\wbem\AutoRecover\26C097A9392F8C541AD42E89B7909073.mof" Aug 20 2008 4:58:32p 15,698 A.... "C:\WINDOWS\system32\wbem\AutoRecover\4DE29A3EB9A6B944E8035563044DBE7E.mof" Aug 20 2008 5:03:56p 8,820 A.... "C:\WINDOWS\system32\wbem\AutoRecover\6FFF7467A5B40765D5740A413CA8BB8A.mof" Aug 20 2008 4:58:24p 1,394 A.... "C:\WINDOWS\system32\wbem\AutoRecover\7F417E1A6D819A9B2FEB55DA6858EA0A.mof" Jun 22 2008 1:56:40p 149,398 A.... "C:\WINDOWS\system32\wbem\AutoRecover\8858F1BA0D460E5A5B27AB13DE3ACB5D.mof" Aug 20 2008 4:58:24p 8,102 A.... "C:\WINDOWS\system32\wbem\AutoRecover\903E49C444C46FEF5F2C3A189C9CEF71.mof" Aug 20 2008 4:58:34p 2,566 A.... "C:\WINDOWS\system32\wbem\AutoRecover\9AD3182A2F39A3E091E15109132EC6CC.mof" Aug 20 2008 5:03:56p 88,742 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C3A0BE17B37ACE48BE78B31580231AE9.mof" Aug 20 2008 4:58:32p 99,856 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C6300BFE37ADE6B52EC023F66124985F.mof" Aug 20 2008 4:58:12p 621 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy" Aug 20 2008 4:58:12p 623 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\7.0.2600.5512.Policy" Aug 20 2008 4:58:10p 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\5.2.2.3.Policy" Aug 20 2008 4:58:10p 605 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\1.0.2600.5512.Policy" Aug 20 2008 4:58:10p 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\5.2.2.3.Policy" Aug 20 2008 4:58:12p 644 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_x-ww_527a1c68\6.0.9792.0.Policy" Aug 20 2008 4:58:10p 625 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\5.1.2600.2000.Policy" Aug 20 2008 4:59:44p 62 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000000.query" Aug 20 2008 4:59:44p 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000001.query" Aug 20 2008 4:59:44p 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000002.query" Aug 20 2008 4:59:44p 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000004.query" Aug 20 2008 4:59:46p 266 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000100.query" ... <NOTE ALSO REMOVED LONG LIST OF LIKE FILES HERE> ... Aug 20 2008 4:59:44p 304 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000007c.query" Aug 20 2008 4:59:46p 4,312 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000017a.query" Aug 20 2008 4:59:44p 3,096 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000007a.query" Aug 20 2008 4:58:44p 2,352 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\about_support.htm" Aug 20 2008 4:58:44p 1,453 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Favorites.htm" Aug 20 2008 4:58:44p 1,740 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\ftshelp.htm" Aug 20 2008 4:58:44p 1,386 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\History.htm" Aug 20 2008 4:58:44p 1,477 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Index.htm" Aug 20 2008 4:58:44p 3,873 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\isupport.htm" Aug 20 2008 4:58:44p 1,816 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\keywordhelp.htm" Aug 20 2008 4:58:44p 1,679 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\options.htm" Aug 20 2008 4:58:44p 1,763 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchblurb.htm" Aug 20 2008 4:58:44p 10,376 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchtips.htm" Aug 20 2008 4:58:44p 1,411 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\tools.htm" Aug 20 2008 4:58:44p 360,054 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\watermark_300x.bmp" Aug 20 2008 4:58:44p 2,368 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\windows_newsgroups.htm" Aug 20 2008 4:58:44p 3,155 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\AboutCompat.htm" Aug 20 2008 4:58:50p 77,245 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatMode.htm" Aug 20 2008 4:58:44p 1,340 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatOffline.htm" Aug 20 2008 4:58:44p 2,588 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\LearnCompat.htm" Aug 20 2008 4:58:44p 1,175 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Behaviors.css" Aug 20 2008 4:58:44p 492 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Layout.css" Aug 20 2008 4:58:44p 850 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\DlgLib.js" Aug 20 2008 4:58:44p 7,523 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\Print.dlg" Aug 20 2008 4:58:44p 1,656 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.htm" Aug 20 2008 4:58:50p 1,206 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.js" Aug 20 2008 4:58:44p 9,264 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\stripe.jpg" Aug 20 2008 4:58:44p 880 A.... "C:\WINDOWS\pchealth\helpctr\System\ErrMsg\ErrorMessagesOffline.htm" Aug 20 2008 4:58:44p 1,663 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\badurl.htm" Aug 20 2008 4:58:50p 18,852 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\connection.htm" Aug 20 2008 4:58:44p 1,655 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\indexfirstlevel.htm" Aug 20 2008 4:58:44p 2,028 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\notfound.htm" Aug 20 2008 4:58:44p 775 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\offline.htm" Aug 20 2008 4:58:44p 1,728 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\redirect.htm" Aug 20 2008 4:58:44p 1,689 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\unreachable.htm" Aug 20 2008 4:58:44p 1,557 A.... "C:\WINDOWS\pchealth\helpctr\System\images\error.gif" Aug 20 2008 4:58:44p 895 A.... "C:\WINDOWS\pchealth\helpctr\System\images\feedback.gif" Aug 20 2008 4:58:44p 70 A.... "C:\WINDOWS\pchealth\helpctr\System\images\flyout_arrow.gif" Aug 20 2008 4:58:44p 1,383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\get_conn.gif" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_articles_12x.bmp" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_blank_12x.bmp" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_newwindow_12x.bmp" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_onlineinline_12x.bmp" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tours_12x.bmp" Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tutorials_12x.bmp" Aug 20 2008 4:58:44p 1,521 A.... "C:\WINDOWS\pchealth\helpctr\System\images\info.gif" Aug 20 2008 4:58:44p 2,801 A.... "C:\WINDOWS\pchealth\helpctr\System\images\progbar.gif" Aug 20 2008 4:58:44p 1,466 A.... "C:\WINDOWS\pchealth\helpctr\System\images\warning.gif" Aug 20 2008 4:58:44p 76 A.... "C:\WINDOWS\pchealth\helpctr\System\images\wrapperhelp.gif" Aug 20 2008 4:58:44p 55,709 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogs.htm" Aug 20 2008 4:58:44p 2,654 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogshelp.htm" Aug 20 2008 4:58:50p 19,520 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\AdvSearch.htm" Aug 20 2008 4:58:44p 608 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm" Aug 20 2008 4:58:44p 9,174 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Context.htm" Aug 20 2008 4:58:44p 714 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\firstpage.htm" Aug 20 2008 4:58:44p 713 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\HHWrapper.htm" Aug 20 2008 4:58:44p 4,764 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.htm" Aug 20 2008 4:58:44p 1,990 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.xml" Aug 20 2008 4:58:44p 20,832 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.htm" Aug 20 2008 4:58:44p 2,513 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.xml" Aug 20 2008 4:58:44p 4,418 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Options.htm" Aug 20 2008 4:58:44p 43,111 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\RemoteHelp.htm" Aug 20 2008 4:58:44p 4,553 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\ShareHelp.htm" Aug 20 2008 4:58:44p 5,547 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Topics.htm" Aug 20 2008 4:58:44p 2,367 A.... "C:\WINDOWS\pchealth\helpctr\System\rc\rcRequest.htm" Aug 20 2008 4:58:48p 80,856 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\ding.wav" Aug 20 2008 4:58:48p 3,907 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\helpeeaccept.htm" Aug 20 2008 4:58:50p 540 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAClientLayout.xml" Aug 20 2008 4:58:50p 666 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAHelpeeAcceptLayout.xml" Aug 20 2008 4:58:50p 587 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAIMLayout.xml" Aug 20 2008 4:58:48p 3,493 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAStartPage.htm" Aug 20 2008 4:58:50p 569 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAURA.xml" Aug 20 2008 4:58:48p 5,980 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\rcBuddy.htm" Aug 20 2008 4:58:50p 3,159 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\Common.js" Aug 20 2008 4:58:44p 4,609 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SHARED.js" Aug 20 2008 4:58:44p 3,445 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__DESKTOP.js" Aug 20 2008 4:58:44p 8,844 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SERVER.js" Aug 20 2008 4:58:44p 2,954 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\wrapperparam.js" Aug 20 2008 4:58:50p 32,141 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\commonFunc.js" Aug 20 2008 4:58:44p 26,520 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\loc_strings.xml" Aug 20 2008 4:58:44p 2,501 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.htm" Aug 20 2008 4:58:44p 371 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.xml" Aug 20 2008 4:58:44p 582 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfohss.css" Aug 20 2008 4:58:44p 56,540 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.htm" Aug 20 2008 4:58:44p 56,777 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.js" Aug 20 2008 4:58:50p 25,050 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.htm" Aug 20 2008 4:58:50p 27,910 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.js" Aug 20 2008 4:58:44p 1,323 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysConfigLaunch.htm" Aug 20 2008 4:58:44p 2,537 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysDiskTS.htm" Aug 20 2008 4:58:44p 10,312 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysEvtLogInfo.htm" Aug 20 2008 4:58:44p 13,556 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.htm" Aug 20 2008 4:58:44p 20,083 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.js" Aug 20 2008 4:58:44p 4,132 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysInfoLaunch.htm" Aug 20 2008 4:58:44p 4,150 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfomain.htm" Aug 20 2008 4:58:50p 16,097 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfosum.htm" Aug 20 2008 4:58:44p 1,864 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysRemoteInfo.htm" Aug 20 2008 4:58:44p 10,136 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysServicesInfo.htm" Aug 20 2008 4:58:50p 7,840 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.htm" Aug 20 2008 4:58:44p 9,506 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.js" Aug 20 2008 4:58:50p 14,129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\wmi_data.js" Aug 20 2008 4:58:44p 4,113 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\AboutWU.htm" Aug 20 2008 4:58:44p 2,059 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\Learn.htm" Aug 20 2008 4:58:44p 2,500 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\LearnInternet.htm" Aug 20 2008 4:58:44p 2,518 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\learnWU.htm" Aug 20 2008 4:58:44p 1,132 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\updatecenter.htm" Aug 20 2008 4:58:48p 627 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Connection.htm" Aug 20 2008 4:58:48p 682 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GArrow.gif" Aug 20 2008 4:58:48p 311 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GRect.gif" Aug 20 2008 4:58:48p 213 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Info_Icon.gif" Aug 20 2008 4:58:48p 2,722 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineOptions.htm" Aug 20 2008 4:58:48p 13,050 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineDC.htm" Aug 20 2008 4:58:48p 781 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\PSS.css" Aug 20 2008 4:58:48p 10,912 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot.xml" Aug 20 2008 4:58:48p 7,098 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-less.xml" Aug 20 2008 4:58:48p 10,755 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-wo-com.xml" Aug 20 2008 4:58:48p 30,494 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pss_getting_worldwide_help.htm" Aug 20 2008 4:58:48p 114 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c1.gif" Aug 20 2008 4:58:48p 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c2.gif" Aug 20 2008 4:58:48p 106 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c3.gif" Aug 20 2008 4:58:48p 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r3_c2.gif" Aug 20 2008 4:58:48p 43 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\spacer.gif" Aug 20 2008 4:58:48p 232 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\status_ok.gif" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_blue_normal_shadow.bmp" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_green_normal_shadow.bmp" Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\compat.bmp" Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\errmsg.bmp" Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\support.bmp" Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\tools.bmp" Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\update.bmp" Aug 20 2008 4:58:44p 600 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\warning.gif" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mousedown.bmp" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mouseover.bmp" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_normal.bmp" Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\32x32\logo.bmp" Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_generic.bmp" Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_01.bmp" Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_02.bmp" Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_03.bmp" Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_04.bmp" Aug 20 2008 4:58:44p 674 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\blue_arrow.gif" Aug 20 2008 4:58:44p 1,383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Connect.gif" Aug 20 2008 4:58:44p 1,839 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\IULogo.gif" Aug 20 2008 4:58:44p 1,525 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Uabrand.gif" Aug 20 2008 4:58:44p 139 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\collapsed.gif" Aug 20 2008 4:58:44p 136 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\endnode.gif" Aug 20 2008 4:58:44p 135 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\expanded.gif" Aug 20 2008 4:58:44p 207 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\helpdoc.gif" Aug 20 2008 4:58:44p 8,494 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Channels.htm" Aug 20 2008 4:58:44p 8,522 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Favorites.htm" Aug 20 2008 4:58:44p 5,369 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\History.htm" Aug 20 2008 4:58:44p 2,911 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Index.htm" Aug 20 2008 4:58:44p 3,465 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Options.htm" Aug 20 2008 4:58:50p 37,469 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Search.htm" Aug 20 2008 4:58:44p 6,520 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Subsite.htm" Aug 20 2008 4:58:50p 5,231 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\common.js" Aug 20 2008 4:58:48p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\ConnIssue.htm" Aug 20 2008 4:58:48p 2,151 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\constants.js" Aug 20 2008 4:58:48p 234 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_information_32x.gif" Aug 20 2008 4:58:48p 219 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_warning_32x.gif" Aug 20 2008 4:58:48p 1,633 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\LearnInternet.htm" Aug 20 2008 4:58:48p 2,317 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RAHelp.htm" Aug 20 2008 4:58:48p 2,981 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RCMoreInfo.htm" Aug 20 2008 4:58:48p 1,369 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\RAChat.css" Aug 20 2008 4:58:48p 2,442 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rc.css" Aug 20 2008 4:58:48p 1,308 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rcbuddy.css" Aug 20 2008 4:58:44p 118 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\alert.gif" Aug 20 2008 4:58:44p 674 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\BArrow.gif" Aug 20 2008 4:58:44p 162 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\card.gif" Aug 20 2008 4:58:44p 257 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\cd.gif" Aug 20 2008 4:58:44p 145 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\check.gif" Aug 20 2008 4:58:44p 102 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\chip.gif" Aug 20 2008 4:58:44p 1,498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\down.bmp" Aug 20 2008 4:58:44p 139 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\drive.gif" Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\error.gif" Aug 20 2008 4:58:44p 159 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\floppy.gif" Aug 20 2008 4:58:44p 682 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\GArrow.gif" Aug 20 2008 4:58:44p 135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\gears.gif" Aug 20 2008 4:58:44p 677 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\greendot.jpg" Aug 20 2008 4:58:44p 99 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\info.gif" Aug 20 2008 4:58:44p 129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\monitor.gif" Aug 20 2008 4:58:44p 181 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\personalizing.gif" Aug 20 2008 4:58:44p 1,135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieChart.gif" Aug 20 2008 4:58:44p 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieGrey.gif" Aug 20 2008 4:58:44p 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieWhite.gif" Aug 20 2008 4:58:44p 136 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\printer.gif" Aug 20 2008 4:58:44p 114 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c1.gif" Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c2.gif" Aug 20 2008 4:58:44p 106 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c3.gif" Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r3_c2.gif" Aug 20 2008 4:58:44p 43 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\spacer.gif" Aug 20 2008 4:58:44p 404 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\system.gif" Aug 20 2008 4:58:44p 1,135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\Untitled.gif" Aug 20 2008 4:58:44p 1,498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\up.bmp" Aug 20 2008 4:58:44p 262 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\usb.gif" Aug 20 2008 4:58:44p 569 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\windows.gif" Aug 20 2008 4:58:48p 2,843 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\confirm.htm" Aug 20 2008 4:58:50p 16,167 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm" Aug 20 2008 4:59:52p 16,167 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm" Aug 20 2008 5:03:34p 40,520 A.... "C:\WINDOWS\system32\spool\drivers\w32x86\3\HPVDJ82I.BUD" Aug 20 2008 4:58:48p 4,756 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Animation.gif" Aug 20 2008 4:58:48p 59 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\combobox_line.gif" Aug 20 2008 4:58:48p 1,094 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\connected.gif" Aug 20 2008 4:58:48p 1,024 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.gif" Aug 20 2008 4:58:48p 346 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.htm" Aug 20 2008 4:58:48p 838 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DownArrow.gif" Aug 20 2008 4:58:48p 8,969 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAChatClient.htm" Aug 20 2008 4:58:50p 45,530 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.htm" Aug 20 2008 4:58:50p 11,254 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.js" Aug 20 2008 4:58:48p 7,140 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAStatusBar.htm" Aug 20 2008 4:58:50p 11,187 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.htm" Aug 20 2008 4:58:48p 3,172 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.xml" Aug 20 2008 4:58:48p 1,290 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rcscreen6_head.htm" Aug 20 2008 4:58:50p 2,496 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rctoolScreen1.htm" Aug 20 2008 4:58:48p 6,552 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\setting.htm" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.bmp" Aug 20 2008 4:58:48p 861 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.gif" Aug 20 2008 4:58:48p 834 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\UpArrow.gif" Aug 20 2008 4:58:50p 690 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\attentioninteraction.gif" Aug 20 2008 4:58:48p 2,086 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\ErrorMsgs.htm" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.bmp" Aug 20 2008 4:58:48p 845 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.gif" Aug 20 2008 4:58:48p 379 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\hide-chat.gif" Aug 20 2008 4:58:48p 227 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\info.gif" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.bmp" Aug 20 2008 4:58:48p 713 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.gif" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.bmp" Aug 20 2008 4:58:48p 750 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.gif" Aug 20 2008 4:58:50p 15,709 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RAControl.js" Aug 20 2008 4:58:50p 30,918 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RCFileXfer.htm" Aug 20 2008 4:58:48p 1,041 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendChat.gif" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.bmp" Aug 20 2008 4:58:48p 694 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.gif" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.bmp" Aug 20 2008 4:58:48p 692 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.gif" Aug 20 2008 4:58:48p 994 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoiceOn.gif" Aug 20 2008 4:58:48p 380 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\show-chat.gif" Aug 20 2008 4:58:50p 3,226 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\voicefirewallmsg.htm" Aug 20 2008 4:58:48p 2,333 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\VOIPMsgs.htm" Aug 20 2008 4:58:48p 341 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar1.htm" Aug 20 2008 4:58:48p 353 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar2.htm" Aug 20 2008 4:58:48p 2,818 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ESC_key.gif" Aug 20 2008 4:58:48p 75 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Helpee_line.gif" Aug 20 2008 4:58:48p 8,095 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAChatServer.htm" Aug 20 2008 4:58:50p 21,049 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.htm" Aug 20 2008 4:58:50p 5,158 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.js" Aug 20 2008 4:58:50p 14,557 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServerToolBar.htm" Aug 20 2008 4:58:48p 4,797 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\SettingServer.htm" Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.bmp" Aug 20 2008 4:58:48p 640 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.gif" Aug 20 2008 4:58:48p 3,210 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\TakeControlMsgs.htm" Aug 20 2008 4:58:44p 734 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\0_chart.gif" Aug 20 2008 4:58:44p 741 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\100_chart.gif" Aug 20 2008 4:58:44p 784 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\10_chart.gif" Aug 20 2008 4:58:44p 778 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\15_chart.gif" Aug 20 2008 4:58:44p 775 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\20_chart.gif" Aug 20 2008 4:58:44p 781 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\25_chart.gif" Aug 20 2008 4:58:44p 782 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\30_chart.gif" Aug 20 2008 4:58:44p 793 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\35_chart.gif" Aug 20 2008 4:58:44p 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\40_chart.gif" Aug 20 2008 4:58:44p 785 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\45_chart.gif" Aug 20 2008 4:58:44p 762 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\50_chart.gif" Aug 20 2008 4:58:44p 777 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\55_chart.gif" Aug 20 2008 4:58:44p 773 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\5_chart.gif" Aug 20 2008 4:58:44p 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\60_chart.gif" Aug 20 2008 4:58:44p 1,199 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\65_chart.gif" Aug 20 2008 4:58:44p 1,190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\70_chart.gif" Aug 20 2008 4:58:44p 1,194 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\75_chart.gif" Aug 20 2008 4:58:44p 1,196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\80_chart.gif" Aug 20 2008 4:58:44p 1,190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\85_chart.gif" Aug 20 2008 4:58:44p 1,196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\90_chart.gif" Aug 20 2008 4:58:44p 1,207 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\95_chart.gif" Aug 20 2008 4:58:44p 1,345 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\0_chart.gif" Aug 20 2008 4:58:44p 1,358 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\100_chart.gif" Aug 20 2008 4:58:44p 1,443 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\10_chart.gif" Aug 20 2008 4:58:44p 1,435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\15_chart.gif" Aug 20 2008 4:58:44p 1,421 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\20_chart.gif" Aug 20 2008 4:58:44p 1,423 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\25_chart.gif" Aug 20 2008 4:58:44p 1,428 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\30_chart.gif" Aug 20 2008 4:58:44p 1,441 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\35_chart.gif" Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\40_chart.gif" Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\45_chart.gif" Aug 20 2008 4:58:44p 1,412 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\50_chart.gif" Aug 20 2008 4:58:44p 1,430 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\55_chart.gif" Aug 20 2008 4:58:44p 1,413 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\5_chart.gif" Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\60_chart.gif" Aug 20 2008 4:58:44p 1,445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\65_chart.gif" Aug 20 2008 4:58:44p 1,435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\70_chart.gif" Aug 20 2008 4:58:44p 1,442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\75_chart.gif" Aug 20 2008 4:58:44p 1,447 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\80_chart.gif" Aug 20 2008 4:58:44p 1,426 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\85_chart.gif" Aug 20 2008 4:58:44p 1,442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\90_chart.gif" Aug 20 2008 4:58:44p 1,445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\95_chart.gif" Aug 20 2008 4:58:50p 5,231 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\common.js" Aug 20 2008 4:58:50p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm" Aug 20 2008 4:58:48p 2,151 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\constants.js" Aug 20 2008 4:58:48p 234 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_information_32x.gif" Aug 20 2008 4:58:48p 219 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_warning_32x.gif" Aug 20 2008 4:58:48p 1,633 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\LearnInternet.htm" Aug 20 2008 4:58:48p 2,317 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RAHelp.htm" Aug 20 2008 4:58:50p 5,930 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RCMoreInfo.htm" Aug 20 2008 4:58:48p 1,369 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\RAChat.css" Aug 20 2008 4:58:48p 2,442 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rc.css" Aug 20 2008 4:58:48p 1,308 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rcbuddy.css" Aug 20 2008 4:59:52p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm" Aug 20 2008 4:59:52p 5,930 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\Common\rcmoreinfo.htm" Aug 20 2008 4:58:48p 102 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\address_book.gif" Aug 20 2008 4:58:48p 1,074 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\arrow.gif" Aug 20 2008 4:58:48p 690 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\attention.gif" Aug 20 2008 4:58:48p 384 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_offline.gif" Aug 20 2008 4:58:48p 387 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy.gif" Aug 20 2008 4:58:48p |