Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post.

- BleepingComputer Management

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

2 Pages V   1 2 >  
Closed TopicStart new topic
> Infected With "systempre.exe" And Some Hidden Morphing Installer, connecting to internet activates installer, which deploys systempre
dcarwin
post Aug 21 2008, 03:37 PM
Post #1


Member
**

Group: Members
Posts: 16
Joined: 20-August 08
Member No.: 231,686



Lenovo T60 has a hidden (I can't find it) systempre deployer. I have done manual cleanup (using SDFix and HJT) and the system appears clean/normal right now. However if I were to plug in the network cable, the deployer would install and run systempre.exe, close all "admin" apps and also create two new randomly-named executables which are also deployed.


Symptoms observed before manual cleanup:
============================
System originally had v6msn.exe infection as well, and I believe I removed this.

- taskmgr disabled
- msconfig disabled
- regedit disabled
- many websites blocked (including bleeping computer)
- hijackthis prevented from running (runs if renamed to something else)

NOTE: gpedit.msc is not disabled and will run, allowing you to manually throw DISABLE on the taskmanager blocking etc.
On next reboot the DISABLE setting is ignored and must be bounced.

- systempre.exe sitting in WINDOWS\system32\
- <random named exe file> sitting in WINDOWS\system32\ (examples iafxqxs.exe, ygyvosm.exe, vscnnq.exe)
- <randome named exe file> sitting in \Documents and Settings\<user that was logged in when virus last deployed>

- HKLM\..\Run: [System Presets] systempre.exe
- HKLM\..\Run: [System Presets] <random named file>.exe

"Userinit"="C:\\WINDOWS\\SYSTEM32\\Userinit.exe," changed to load <random>.exe
===

SDFix fails to remove as virus reinstates systempre.exe as soon as network cable is plugged in next time.

Prep steps taken
===========
cleanmgr - run
adaware - clean
spybit - cannot run because it forces an internet check, and infected box is off the net. (Plugging box into net activates virus host which deploys systempre.exe etc)
Stinger - clean
housecall/panda/bitdefender - not run. all require net connection.
Firewall - Sygate firewall installed (windows firewall off)
Updates - SP3 installed, loaded batch of 21 recent stored updates, not sure if completely updated.

HJT Log
=====
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:53 PM, on 8/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1192779822406
O17 - HKLM\System\CCS\Services\Tcpip\..\{93008F3B-85B5-41D8-B1FB-9225D9F2B837}: NameServer = 208.201.224.11,208.201.224.33
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 5813 bytes



Additional Notes:
===========
System originally had v6msn.exe infection as well, and I believe I removed this.

Portion of SDFIX log BEFORE manual cleanup:
===
C:\PROGRA~1\PEAZIP\RES\LPAQ\LPAQ1.EXE - Deleted
C:\WINDOWS\system32\systempre.exe - Deleted
C:\WINDOWS\system32\v6msn.exe - Deleted


Files with Hidden Attributes :

Sun 13 Jul 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Thu 1 Nov 2007 59,392 ..SHR --- "C:\WINDOWS\system32\ESaudio.exe"
Wed 23 Jul 2008 49,664 ..SHR --- "C:\WINDOWS\system32\msnchat6.1.7.exe"
Mon 21 Jul 2008 49,664 ..SHR --- "C:\WINDOWS\system32\msnv6.1.exe"

Actions Taken
===
ESaudio - I renamed it
Picasa2\setup.exe - deleted
deleted all exe's mentions
removed all reg keys mentioned (run keys as well as firewall keys)

Full text of SDFIX systemreport.txt
======================

System Report
*************

Run on Thu 08/21/2008 at 01:24 PM

Microsoft Windows XP [Version 5.1.2600]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [1056]
\??\C:\WINDOWS\system32\csrss.exe [1148]
\??\C:\WINDOWS\system32\winlogon.exe [1176]
C:\WINDOWS\system32\services.exe [1220]
C:\WINDOWS\system32\lsass.exe [1232]
C:\WINDOWS\system32\ibmpmsvc.exe [1400]
C:\WINDOWS\system32\svchost.exe [1428]
C:\WINDOWS\system32\svchost.exe [1472]
C:\WINDOWS\System32\svchost.exe [1512]
C:\Program Files\Sygate\SPF\smc.exe [1640]
C:\WINDOWS\system32\svchost.exe [1744]
C:\WINDOWS\system32\svchost.exe [1788]
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008]
C:\WINDOWS\system32\spoolsv.exe [344]
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [388]
C:\WINDOWS\system32\acs.exe [732]
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [780]
C:\WINDOWS\system32\svchost.exe [904]
C:\WINDOWS\System32\TPHDEXLG.exe [928]
C:\WINDOWS\system32\TpKmpSVC.exe [948]
C:\WINDOWS\System32\alg.exe [1600]
C:\WINDOWS\system32\wbem\wmiprvse.exe [1632]
C:\WINDOWS\Explorer.EXE [1928]
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2200]
C:\WINDOWS\system32\igfxtray.exe [2320]
C:\WINDOWS\system32\igfxpers.exe [2372]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2400]
C:\WINDOWS\system32\igfxsrvc.exe [2456]
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2512]
C:\WINDOWS\system32\rundll32.exe [2540]
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe [2580]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2596]
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe [2624]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2636]
C:\WINDOWS\system32\TpShocks.exe [2716]
C:\Program Files\Lenovo\Zoom\TpScrex.exe [2740]
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2760]
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe [2772]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2796]
C:\Program Files\Logitech\QuickCam\Quickcam.exe [2808]
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe [3332]


Drivers - Running:

ACPI
ACPIEC
ADIHdAudAddService
AEAudio
AFD
AR5211
Arp1394
atapi
audstub
Beep
Cdfs
Cdrom
CmBatt
Compbatt
Disk
e1express
Fastfat
Fips
FltMgr
Ftdisk
Gpc
HDAudBus
HSFHWAZL
HSF_DPV
HTTP
i8042prt
ialm
iastor
IBMPMDRV
Imapi
intelppm
IpNat
IPSec
isapnp
Kbdclass
kmixer
KSecDD
LVPr2Mon
mdmxsdk
mnmdd
Modem
Mouclass
MountMgr
MRxDAV
MRxSmb
Msfs
mssmbios
Mup
NDIS
NdisTapi
Ndisuio
NdisWan
NDProxy
NetBIOS
NetBT
NIC1394
Npfs
Ntfs
Null
ohci1394
PartMgr
PCI
PCIIde
Pcmcia
PptpMiniport
PSched
Ptilink
PxHelp20
RasAcd
Rasl2tp
RasPppoe
Raspti
Rdbss
RDPCDD
rdpdr
redbook
rimmptsk
rimsptsk
RimVSerPort
rismxdp
ROOTMODEM
sdbus
Secdrv
Shockprf
sr
Srv
swenum
SynTP
sysaudio
Tcpip
Teefer
TermDD
TPDIGIMN
TPHKDRV
TPPWRIF
TSMAPIP
Update
usbehci
usbhub
usbuhci
VgaSave
VolSnap
Wanarp
wdmaud
wg3n
wg4n
wg5n
wg6n
winachsf
WmiAcpi
wpsdrvnt
WSIMD


Drivers - Stopped:

Abiosdsk
abp480n5
adpu160m
aec
Aha154x
aic78u2
aic78xx
AliIde
amsint
asc
asc3350p
asc3550
AsyncMac
Atdisk
Atmarpc
catchme
cbidf2k
CCDECODE
cd20xrnt
Cdaudio
Changer
CmdIde
Cpqarray
dac960nt
dmboot
dmio
dmload
DMusic
dpti2o
drmkaud
Fdc
Flpydisk
hidusb
hpn
i2omgmt
i2omp
ini910u
IntelIde
Ip6Fw
IpFilterDriver
IpInIp
IRENUM
lbrtfdc
LVcKap
LVMVDrv
LVUSBSta
mouhid
mraid35x
MSKSSRV
MSPCLOCK
MSPQM
MSTEE
NABTSFEC
NdisIP
NwlnkFlt
NwlnkFwd
Parport
ParVdm
PCIDump
PDCOMP
PDFRAME
PDRELI
PDRFRAME
perc2
perc2hib
PID_0928
ql1080
Ql10wnt
ql12160
ql1240
ql1280
RDPWD
RimUsb
Serial
sffdisk
sffp_sd
Sfloppy
Simbad
SLIP
Sparrow
splitter
streamip
swmidi
symc810
symc8xx
sym_hi
sym_u3
TDPIPE
TDTCP
TosIde
Udfs
UIUSys
ultra
usbccgp
usbprint
usbscan
USBSTOR
ViaIde
vsdatant
WDICA
WSTCODEC


Services - Running:

aawservice
acs
ALG
AudioSrv
Browser
CryptSvc
DcomLaunch
Dhcp
Dnscache
ERSvc
Eventlog
EventSystem
helpsvc
IBMPMSVC
lanmanserver
lanmanworkstation
LmHosts
LVCOMSer
LVPrcSrv
Netman
Nla
PlugPlay
PolicyAgent
ProtectedStorage
RasMan
RemoteRegistry
RpcSs
SamSs
Schedule
seclogon
SENS
SharedAccess
ShellHWDetection
SmcService
Spooler
srservice
SSDPSRV
stisvc
TapiSrv
TermService
Themes
TPHDEXLGSVC
TpKmpSVC
TrkWks
W32Time
WebClient
winmgmt
wscsvc
wuauserv
WZCSVC


Services - Stopped:

Alerter
AppMgmt
BITS
CiSvc
ClipSrv
COMSysApp
dmadmin
dmserver
Dot3svc
EapHost
FastUserSwitchingCompatibility
gusvc
HidServ
hkmsvc
HTTPFilter
IDriverT
ImapiService
LVSrvLauncher
Messenger
mnmsrvc
MSDTC
MSIServer
napagent
NetDDE
NetDDEdsdm
Netlogon
NtLmSsp
NtmsSvc
ose
RasAuto
RDSessMgr
RemoteAccess
RpcLocator
RSVP
SCardSvr
SwPrv
SysmonLog
TlntSvr
upnphost
UPS
VSS
WinVNC4
WmdmPmSN
Wmi
WmiApSrv
xmlprov


Files Created/Modified - 60 Days:


C:\

Aug 21 2008 12:58:20p 1,046,786,048 A.SH. "C:\hiberfil.sys"
Aug 20 2008 4:52:36p 250,048 A.SHR "C:\ntldr"
Aug 21 2008 12:58:02p 1,572,864,000 A.SH. "C:\pagefile.sys"
Aug 20 2008 1:11:32a 244 A..H. "C:\sqmnoopt12.sqm"
Aug 20 2008 1:53:58a 244 A..H. "C:\sqmnoopt13.sqm"
Aug 19 2008 5:40:36p 244 A..H. "C:\sqmnoopt10.sqm"
Aug 19 2008 6:24:40p 244 A..H. "C:\sqmnoopt11.sqm"
Aug 20 2008 2:53:14a 244 A..H. "C:\sqmnoopt16.sqm"
Aug 18 2008 9:44:20p 244 A..H. "C:\sqmnoopt17.sqm"
Aug 20 2008 2:12:34a 244 A..H. "C:\sqmnoopt14.sqm"
Aug 20 2008 2:15:46a 244 A..H. "C:\sqmnoopt15.sqm"
Aug 19 2008 2:44:26p 244 A..H. "C:\sqmnoopt06.sqm"
Aug 19 2008 3:28:28p 244 A..H. "C:\sqmnoopt07.sqm"
Aug 19 2008 1:16:20p 244 A..H. "C:\sqmnoopt04.sqm"
Aug 19 2008 2:00:22p 244 A..H. "C:\sqmnoopt05.sqm"
Aug 18 2008 10:24:22p 244 A..H. "C:\sqmnoopt18.sqm"
Aug 19 2008 9:36:04a 244 A..H. "C:\sqmnoopt19.sqm"
Aug 19 2008 4:12:32p 244 A..H. "C:\sqmnoopt08.sqm"
Aug 19 2008 4:56:34p 244 A..H. "C:\sqmnoopt09.sqm"
Aug 19 2008 5:40:36p 232 A..H. "C:\sqmdata10.sqm"
Aug 20 2008 2:12:34a 268 A..H. "C:\sqmdata14.sqm"
Aug 19 2008 1:16:20p 232 A..H. "C:\sqmdata04.sqm"
Aug 18 2008 10:24:22p 232 A..H. "C:\sqmdata18.sqm"
Aug 19 2008 4:12:32p 232 A..H. "C:\sqmdata08.sqm"
Aug 19 2008 6:24:40p 232 A..H. "C:\sqmdata11.sqm"
Aug 20 2008 2:15:46a 268 A..H. "C:\sqmdata15.sqm"
Aug 19 2008 2:00:22p 232 A..H. "C:\sqmdata05.sqm"
Aug 19 2008 9:36:04a 232 A..H. "C:\sqmdata19.sqm"
Aug 19 2008 4:56:34p 232 A..H. "C:\sqmdata09.sqm"
Aug 20 2008 1:11:32a 268 A..H. "C:\sqmdata12.sqm"
Aug 20 2008 2:53:14a 268 A..H. "C:\sqmdata16.sqm"
Aug 19 2008 2:44:26p 232 A..H. "C:\sqmdata06.sqm"
Aug 20 2008 1:53:58a 232 A..H. "C:\sqmdata13.sqm"
Aug 18 2008 9:44:20p 232 A..H. "C:\sqmdata17.sqm"
Aug 19 2008 3:28:28p 232 A..H. "C:\sqmdata07.sqm"
Aug 19 2008 10:20:08a 232 A..H. "C:\sqmdata00.sqm"
Aug 19 2008 11:04:10a 232 A..H. "C:\sqmdata01.sqm"
Aug 19 2008 11:48:14a 232 A..H. "C:\sqmdata02.sqm"
Aug 19 2008 12:32:16p 232 A..H. "C:\sqmdata03.sqm"
Aug 19 2008 10:20:08a 244 A..H. "C:\sqmnoopt00.sqm"
Aug 19 2008 11:04:10a 244 A..H. "C:\sqmnoopt01.sqm"
Aug 19 2008 11:48:14a 244 A..H. "C:\sqmnoopt02.sqm"
Aug 19 2008 12:32:16p 244 A..H. "C:\sqmnoopt03.sqm"
Aug 21 2008 12:58:24p 3,432 A.... "C:\TPHKLOCK.TXT"


C:\WINDOWS\

Aug 21 2008 12:58:44p 0 A.... "C:\WINDOWS\0.log"
Aug 21 2008 12:58:22p 2,048 A.S.. "C:\WINDOWS\bootstat.dat"
Jul 5 2008 10:46:48p 136 A.... "C:\WINDOWS\ChssBase.ini"
Aug 20 2008 4:58:38p 373 A.... "C:\WINDOWS\cmsetacl.log"
Aug 20 2008 5:40:08p 204,052 A.... "C:\WINDOWS\comsetup.log"
Aug 20 2008 5:03:52p 359 A.... "C:\WINDOWS\DtcInstall.log"
Aug 20 2008 5:40:08p 586,533 A.... "C:\WINDOWS\FaxSetup.log"
Aug 20 2008 5:40:08p 661,066 A.... "C:\WINDOWS\iis6.log"
Aug 20 2008 5:40:02p 1,374 A.... "C:\WINDOWS\imsins.BAK"
Aug 20 2008 5:40:08p 1,374 A.... "C:\WINDOWS\imsins.log"
Aug 20 2008 9:42:36a 4,194 A.... "C:\WINDOWS\KB944338-v2.log"
Aug 20 2008 9:42:48a 3,779 A.... "C:\WINDOWS\KB950749.log"
Aug 20 2008 5:38:24p 10,674 A.... "C:\WINDOWS\KB950762.log"
Aug 20 2008 5:39:42p 16,060 A.... "C:\WINDOWS\KB950974.log"
Aug 20 2008 5:38:10p 10,700 A.... "C:\WINDOWS\KB951066.log"
Aug 20 2008 5:38:20p 29,074 A.... "C:\WINDOWS\KB951072-v2.log"
Aug 20 2008 5:40:08p 11,592 A.... "C:\WINDOWS\KB951376-v2.log"
Aug 20 2008 5:39:22p 15,257 A.... "C:\WINDOWS\KB951698.log"
Aug 20 2008 5:35:56p 14,939 A.... "C:\WINDOWS\KB951748.log"
Aug 20 2008 5:38:14p 10,443 A.... "C:\WINDOWS\KB952287.log"
Aug 20 2008 5:40:02p 16,586 A.... "C:\WINDOWS\KB952954.log"
Aug 20 2008 5:36:12p 16,425 A.... "C:\WINDOWS\KB953838.log"
Aug 20 2008 5:39:58p 10,508 A.... "C:\WINDOWS\KB953839.log"
Aug 20 2008 5:40:08p 41,523 A.... "C:\WINDOWS\MedCtrOC.log"
Aug 20 2008 5:40:08p 29,380 A.... "C:\WINDOWS\msgsocm.log"
Aug 20 2008 5:40:06p 184,854 A.... "C:\WINDOWS\msmqinst.log"
Aug 20 2008 5:40:08p 103,183 A.... "C:\WINDOWS\netfxocm.log"
Jun 23 2008 11:35:22p 395 A.... "C:\WINDOWS\nsw.log"
Aug 20 2008 7:13:20p 2,237,828 A.... "C:\WINDOWS\ntbtlog.txt"
Aug 20 2008 5:40:08p 121,837 A.... "C:\WINDOWS\ntdtcsetup.log"
Aug 20 2008 5:40:08p 286,349 A.... "C:\WINDOWS\ocgen.log"
Aug 20 2008 5:40:08p 32,510 A.... "C:\WINDOWS\ocmsn.log"
Aug 21 2008 12:22:38p 376 A.... "C:\WINDOWS\ODBC.INI"
Aug 20 2008 5:03:56p 1,868 A.... "C:\WINDOWS\OEWABLog.txt"
Aug 10 2008 11:47:36p 1,409 A.... "C:\WINDOWS\QTFont.for"
Aug 10 2008 11:47:36p 54,156 A..H. "C:\WINDOWS\QTFont.qfn"
Aug 21 2008 12:57:26p 32,642 A.... "C:\WINDOWS\SchedLgU.Txt"
Aug 20 2008 4:58:30p 1,281 A.... "C:\WINDOWS\sessmgr.setup.log"
Aug 21 2008 12:22:38p 179,190 A.... "C:\WINDOWS\setupact.log"
Aug 20 2008 11:44:46p 4,815 A.... "C:\WINDOWS\setupapi.log"
Aug 20 2008 5:00:02p 1,057,463 A.... "C:\WINDOWS\setupapi.log.0.old"
Aug 20 2008 5:03:18p 876,870 A.... "C:\WINDOWS\setuplog.txt"
Aug 20 2008 5:04:16p 69,776 A.... "C:\WINDOWS\spupdsvc.log"
Aug 20 2008 5:03:34p 187 A.... "C:\WINDOWS\spupdsvc.log.1.log"
Aug 20 2008 5:01:32p 551,790 A.... "C:\WINDOWS\svcpack.log"
Aug 20 2008 5:40:08p 30,331 A.... "C:\WINDOWS\tabletoc.log"
Aug 20 2008 5:40:08p 271,598 A.... "C:\WINDOWS\tsoc.log"
Aug 20 2008 5:40:02p 117,725 A.... "C:\WINDOWS\updspapi.log"
Aug 21 2008 12:58:40p 159 A.... "C:\WINDOWS\wiadebug.log"
Aug 21 2008 12:58:46p 49 A.... "C:\WINDOWS\wiaservc.log"
Aug 20 2008 5:37:10p 756 A.... "C:\WINDOWS\win.ini"
Aug 21 2008 12:59:26p 1,086,806 A.... "C:\WINDOWS\WindowsUpdate.log"
Aug 20 2008 5:04:16p 5,073 A.... "C:\WINDOWS\wmsetup.log"
Aug 20 2008 5:04:14p 316,640 A.... "C:\WINDOWS\WMSysPr9.prx"
Aug 20 2008 4:50:38p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00003"
Aug 20 2008 4:50:38p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00004"
...
<NOTE I REMOVED A LONG LIST OF SP3 UNINSTALL FILES HERE TO SAVE SPACE>
...
Aug 20 2008 4:51:20p 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg02390"
Aug 20 2008 5:03:54p 572 A.... "C:\WINDOWS\Debug\blastcln.log"
Jun 23 2008 11:35:16p 5,733 A.... "C:\WINDOWS\Debug\NetSetup.LOG"
Aug 21 2008 12:58:22p 0 A.... "C:\WINDOWS\Debug\PASSWD.LOG"
Aug 20 2008 11:44:26p 4,676 A.... "C:\WINDOWS\inf\branches.PNF"
Aug 20 2008 4:59:56p 25,780 A.... "C:\WINDOWS\inf\bth.PNF"
Aug 20 2008 11:44:26p 6,224 A.... "C:\WINDOWS\inf\bthprint.PNF"
Aug 20 2008 11:44:26p 5,972 A.... "C:\WINDOWS\inf\bthspp.PNF"
Aug 20 2008 5:00:58p 134,788 A.... "C:\WINDOWS\inf\comnt5.PNF"
Aug 20 2008 11:44:28p 326,568 A.... "C:\WINDOWS\inf\defltwk.PNF"
Aug 20 2008 4:59:56p 222,468 A.... "C:\WINDOWS\inf\drvindex.PNF"
Aug 20 2008 5:00:58p 10,240 A.... "C:\WINDOWS\inf\dtcnt5.PNF"
Aug 20 2008 11:44:28p 334,564 A.... "C:\WINDOWS\inf\dwup.PNF"
Aug 20 2008 11:44:28p 5,004 A.... "C:\WINDOWS\inf\fltmgr.PNF"
Aug 20 2008 5:00:58p 17,568 A.... "C:\WINDOWS\inf\fp40ext.PNF"
Aug 20 2008 5:00:02p 6,796 A.... "C:\WINDOWS\inf\hdaudbus.PNF"
Aug 20 2008 11:44:28p 7,780 A.... "C:\WINDOWS\inf\hidbth.PNF"
Aug 20 2008 11:44:28p 9,476 A.... "C:\WINDOWS\inf\HidDigi.PNF"
Aug 20 2008 11:44:28p 12,720 A.... "C:\WINDOWS\inf\hidserv.PNF"
Aug 20 2008 11:44:28p 83,728 A.... "C:\WINDOWS\inf\ie.PNF"
Aug 20 2008 5:00:58p 4,464 A.... "C:\WINDOWS\inf\ieaccess.PNF"
Aug 20 2008 5:00:58p 971,036 A.... "C:\WINDOWS\inf\iis.PNF"
Aug 20 2008 5:00:58p 105,208 A.... "C:\WINDOWS\inf\ims.PNF"
Aug 20 2008 11:44:38p 1,433,016 A.... "C:\WINDOWS\inf\INFCACHE.1"
Aug 20 2008 11:44:28p 108,916 A.... "C:\WINDOWS\inf\input.PNF"
Aug 20 2008 11:44:30p 432,252 A.... "C:\WINDOWS\inf\intl.PNF"
Aug 20 2008 11:44:30p 28,188 A.... "C:\WINDOWS\inf\irbus.PNF"
Aug 20 2008 11:44:30p 67,708 A.... "C:\WINDOWS\inf\keyboard.PNF"
Aug 20 2008 5:00:56p 2,916 A.... "C:\WINDOWS\inf\koc.PNF"
Aug 20 2008 11:44:30p 91,444 A.... "C:\WINDOWS\inf\ks.PNF"
Aug 20 2008 11:44:30p 43,500 A.... "C:\WINDOWS\inf\kscaptur.PNF"
Aug 20 2008 11:44:30p 24,640 A.... "C:\WINDOWS\inf\ksfilter.PNF"
Aug 20 2008 4:59:54p 1,068,864 A.... "C:\WINDOWS\inf\LAYOUT.PNF"
Aug 20 2008 5:00:02p 187,380 A.... "C:\WINDOWS\inf\machine.PNF"
Aug 20 2008 11:44:30p 30,564 A.... "C:\WINDOWS\inf\mchgr.PNF"
Aug 20 2008 11:44:32p 17,572 A.... "C:\WINDOWS\inf\mdac.PNF"
Aug 20 2008 11:44:32p 40,560 A.... "C:\WINDOWS\inf\mdmbtmdm.PNF"
Aug 20 2008 11:44:32p 108,224 A.... "C:\WINDOWS\inf\mdmirmdm.PNF"
Aug 20 2008 11:44:32p 8,284 A.... "C:\WINDOWS\inf\mpe.PNF"
Aug 20 2008 11:44:32p 49,540 A.... "C:\WINDOWS\inf\mshdc.PNF"
Aug 20 2008 5:03:56p 35,964 A.... "C:\WINDOWS\inf\msoe50.PNF"
Aug 20 2008 11:44:32p 23,816 A.... "C:\WINDOWS\inf\mstape.PNF"
Aug 20 2008 11:44:32p 9,636 A.... "C:\WINDOWS\inf\nabtsfec.PNF"
Aug 20 2008 11:44:32p 9,096 A.... "C:\WINDOWS\inf\ndisip.PNF"
Aug 20 2008 5:01:00p 3,652 A.... "C:\WINDOWS\inf\netbeac.PNF"
Aug 20 2008 5:03:42p 3,704 A.... "C:\WINDOWS\inf\netfw.PNF"
Aug 20 2008 5:01:00p 174,876 A.... "C:\WINDOWS\inf\netfxocm.PNF"
Aug 20 2008 11:44:32p 13,020 A.... "C:\WINDOWS\inf\netip6.PNF"
Aug 20 2008 11:44:34p 20,344 A.... "C:\WINDOWS\inf\netmscli.PNF"
Aug 20 2008 5:00:58p 16,448 A.... "C:\WINDOWS\inf\netoc.PNF"
Aug 20 2008 11:44:34p 45,180 A.... "C:\WINDOWS\inf\netrass.PNF"
Aug 20 2008 11:44:34p 6,800 A.... "C:\WINDOWS\inf\netrndis.PNF"
Aug 20 2008 11:44:34p 39,216 A.... "C:\WINDOWS\inf\nettcpip.PNF"
Aug 20 2008 11:44:34p 6,348 A.... "C:\WINDOWS\inf\nettun.PNF"
Aug 20 2008 11:44:34p 8,932 A.... "C:\WINDOWS\inf\netupnph.PNF"
Aug 20 2008 11:44:34p 7,028 A.... "C:\WINDOWS\inf\netwzc.PNF"
Aug 20 2008 11:44:34p 1,317,388 A.... "C:\WINDOWS\inf\ntprint.PNF"
Aug 20 2008 5:01:00p 4,384 A.... "C:\WINDOWS\inf\oeaccess.PNF"
Aug 20 2008 3:14:02a 0 ...H. "C:\WINDOWS\inf\oem46.inf"
Aug 20 2008 11:44:36p 17,240 A.... "C:\WINDOWS\inf\oobe.PNF"
Aug 20 2008 5:01:00p 14,492 A.... "C:\WINDOWS\inf\p2p.PNF"
Aug 20 2008 11:44:36p 105,552 A.... "C:\WINDOWS\inf\pnpscsi.PNF"
Jul 18 2008 4:58:54p 6,496 A.... "C:\WINDOWS\inf\pxhelp20.PNF"
Aug 20 2008 11:44:36p 11,920 A.... "C:\WINDOWS\inf\qmgr.PNF"
Aug 20 2008 11:44:36p 7,172 A.... "C:\WINDOWS\inf\ramdisk.PNF"
Aug 20 2008 5:03:56p 39,428 A.... "C:\WINDOWS\inf\sceregvl.PNF"
Aug 20 2008 11:44:36p 21,944 A.... "C:\WINDOWS\inf\scsi.PNF"
Aug 20 2008 4:59:56p 10,732 A.... "C:\WINDOWS\inf\sdbus.PNF"
Aug 20 2008 11:44:36p 26,712 A.... "C:\WINDOWS\inf\secrecs.PNF"
Aug 20 2008 4:59:58p 10,036 A.... "C:\WINDOWS\inf\sffdisk.PNF"
Aug 20 2008 11:44:36p 38,476 A.... "C:\WINDOWS\inf\shell.PNF"
Aug 20 2008 11:44:36p 15,720 A.... "C:\WINDOWS\inf\shl_img.PNF"
Aug 20 2008 11:44:36p 9,196 A.... "C:\WINDOWS\inf\slip.PNF"
Aug 20 2008 11:44:36p 36,372 A.... "C:\WINDOWS\inf\smartcrd.PNF"
Aug 20 2008 11:44:36p 11,956 A.... "C:\WINDOWS\inf\streamip.PNF"
Aug 20 2008 11:44:36p 5,724 A.... "C:\WINDOWS\inf\swflash.PNF"
Aug 20 2008 5:00:56p 7,356 A.... "C:\WINDOWS\inf\SYSOC.PNF"
Aug 20 2008 11:44:38p 101,276 A.... "C:\WINDOWS\inf\syssetup.PNF"
Aug 20 2008 5:01:00p 558,428 A.... "C:\WINDOWS\inf\tabletpc.PNF"
Aug 20 2008 11:44:38p 59,804 A.... "C:\WINDOWS\inf\tape.PNF"
Aug 20 2008 11:44:38p 9,424 A.... "C:\WINDOWS\inf\tdibth.PNF"
Aug 20 2008 5:00:58p 131,204 A.... "C:\WINDOWS\inf\tsoc.PNF"
Aug 20 2008 11:44:38p 51,448 A.... "C:\WINDOWS\inf\usbport.PNF"
Aug 20 2008 11:44:38p 20,324 A.... "C:\WINDOWS\inf\usbvideo.PNF"
Aug 20 2008 5:00:56p 14,228 A.... "C:\WINDOWS\inf\wbemoc.PNF"
Aug 20 2008 11:44:38p 74,520 A.... "C:\WINDOWS\inf\wdma_ali.PNF"
Aug 20 2008 11:44:38p 33,508 A.... "C:\WINDOWS\inf\wdma_via.PNF"
Aug 20 2008 4:59:54p 57,172 A.... "C:\WINDOWS\inf\wmp.PNF"
Aug 20 2008 11:44:38p 9,200 A.... "C:\WINDOWS\inf\wstcodec.PNF"
Jul 7 2008 1:26:58p 253,952 A.... "C:\WINDOWS\system32\es.dll"
Aug 20 2008 5:42:52p 204,120 A.... "C:\WINDOWS\system32\FNTCACHE.DAT"
Aug 20 2008 4:47:18p 1,053 A.... "C:\WINDOWS\system32\lvcoinst.log"
Jun 24 2008 9:43:16a 74,240 A.... "C:\WINDOWS\system32\mscms.dll"
Jun 23 2008 8:09:28a 3,067,392 A.... "C:\WINDOWS\system32\mshtml.dll"
Aug 20 2008 6:31:20p 1,786 A.... "C:\WINDOWS\system32\PerfStringBackup.TMP"
Jun 26 2008 1:15:30a 1,499,136 A.... "C:\WINDOWS\system32\shdocvw.dll"
Aug 20 2008 5:03:32p 255 A.... "C:\WINDOWS\system32\spupdwxp.log"
Aug 21 2008 11:07:20a 384 A.... "C:\WINDOWS\system32\TPAPSLOG.LOG"
Aug 21 2008 12:58:42p 2,560 A.... "C:\WINDOWS\system32\TPHDLOG0.LOG"
Jul 11 2008 5:42:28a 62,976 ..... "C:\WINDOWS\system32\tzchange.exe"
Aug 20 2008 5:38:16p 349,202 A.... "C:\WINDOWS\system32\TZLog.log"
Jun 26 2008 1:15:30a 619,520 A.... "C:\WINDOWS\system32\urlmon.dll"
Jun 23 2008 8:09:28a 666,112 A.... "C:\WINDOWS\system32\wininet.dll"
Aug 20 2008 11:23:08a 13,588 A.... "C:\WINDOWS\system32\wpa.bak"
Aug 21 2008 12:58:44p 13,646 A.... "C:\WINDOWS\system32\wpa.dbl"
Aug 21 2008 12:58:48p 302 A.... "C:\WINDOWS\Tasks\PMTask.job"
Aug 21 2008 12:58:30p 6 A..H. "C:\WINDOWS\Tasks\SA.DAT"
Aug 21 2008 1:19:12p 3,845 A.... "C:\WINDOWS\Temp\LVCOMSX.LOG"
Aug 21 2008 1:23:38p 37,695 A.... "C:\WINDOWS\Temp\scs4.tmp"
Aug 20 2008 4:58:12p 4,828 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\Service Pack 3.asms"
Aug 20 2008 5:01:00p 1,161,355 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.inf"
Aug 20 2008 4:51:20p 508,435 A.... "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.txt"
Aug 20 2008 10:12:10a 562,784 A.... "C:\WINDOWS\Debug\Setup\UpdSh.bak"
Aug 20 2008 5:01:12p 543,504 A.... "C:\WINDOWS\Debug\Setup\UpdSh.log"
Jul 1 2008 9:02:24p 308,376 A.... "C:\WINDOWS\Debug\UserMode\userenv.bak"
Aug 21 2008 12:58:22p 231,232 A.... "C:\WINDOWS\Debug\UserMode\userenv.log"
Aug 20 2008 5:01:02p 1,056,768 A.... "C:\WINDOWS\security\Database\Service Pack 3.sdb"
Aug 20 2008 5:03:52p 732 A.... "C:\WINDOWS\security\logs\scecomp.old"
Aug 20 2008 5:01:02p 7,168 A.... "C:\WINDOWS\security\logs\update.log"
Jul 7 2008 1:26:58p 253,952 ..... "C:\WINDOWS\system32\dllcache\es.dll"
Jun 24 2008 9:43:16a 74,240 ..... "C:\WINDOWS\system32\dllcache\mscms.dll"
Jun 23 2008 8:09:28a 3,067,392 ..... "C:\WINDOWS\system32\dllcache\mshtml.dll"
Jun 26 2008 1:15:30a 1,499,136 ..... "C:\WINDOWS\system32\dllcache\shdocvw.dll"
Jun 26 2008 1:15:30a 619,520 ..... "C:\WINDOWS\system32\dllcache\urlmon.dll"
Aug 20 2008 6:19:36p 578,560 A.... "C:\WINDOWS\system32\dllcache\user32.dll"
Jun 23 2008 8:09:28a 666,112 ..... "C:\WINDOWS\system32\dllcache\wininet.dll"
Aug 20 2008 3:01:22a 156 A.... "C:\WINDOWS\system32\GroupPolicy\gpt.ini"
Aug 20 2008 5:03:14p 3,201 A.... "C:\WINDOWS\system32\oobe\agtscrp2.js"
Aug 20 2008 5:03:14p 9,607 A.... "C:\WINDOWS\system32\oobe\oobeutil.js"
Aug 20 2008 5:03:14p 32,004 A.... "C:\WINDOWS\system32\oobe\updshell.htm"
Aug 20 2008 4:58:12p 500 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63.Manifest"
Aug 20 2008 4:58:10p 1,237 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.SystemCompatible_6595b64144ccf1df_5.1.2600.2000_x-ww_bcc9a281.Manifest"
Aug 20 2008 4:58:12p 1,822 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a.Manifest"
Aug 20 2008 4:58:10p 1,883 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7.Manifest"
Aug 20 2008 4:58:10p 1,187 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95.Manifest"
Aug 20 2008 4:58:10p 460 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc
0.Manifest"
Aug 20 2008 4:58:12p 1,862 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83.Manifest"
Aug 20 2008 4:58:10p 397 A.... "C:\WINDOWS\WinSxS\Manifests\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c.Manifest"
Aug 20 2008 4:46:12p 0 A.... "C:\WINDOWS\Debug\Setup\Backup\HDAUDIO_Backup.bak"
Aug 20 2008 4:46:12p 4 A.... "C:\WINDOWS\Debug\Setup\Backup\INTPPM_Backup.bak"
Aug 20 2008 5:00:10p 14,688,256 A.... "C:\WINDOWS\pchealth\helpctr\Database\HCdata.edb"
Aug 20 2008 4:59:42p 2,974,155 A.... "C:\WINDOWS\pchealth\helpctr\Indices\merged.hhk"
Aug 20 2008 4:59:42p 13,328 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_2.hhk"
Aug 20 2008 4:59:42p 16,703 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_3.hhk"
Aug 20 2008 4:59:42p 35,565 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_4.hhk"
Aug 20 2008 4:59:42p 20,016 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_5.hhk"
Aug 20 2008 4:59:42p 15,646 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_6.hhk"
Aug 20 2008 4:59:42p 102,895 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_7.hhk"
Aug 20 2008 4:59:42p 209,095 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_8.hhk"
Aug 20 2008 4:59:42p 51,061 A.... "C:\WINDOWS\pchealth\helpctr\Indices\scoped_9.hhk"
Aug 20 2008 4:59:52p 935,163 A.... "C:\WINDOWS\pchealth\helpctr\Logs\hcupdate.log"
Aug 20 2008 4:59:52p 86,327 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat"
Aug 20 2008 4:59:52p 4 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\CRC_Disk"
Aug 20 2008 4:58:40p 309,519 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_7.cab"
Aug 20 2008 4:59:52p 68,704 ..SHR "C:\WINDOWS\pchealth\helpctr\PackageStore\package_8.cab"
Aug 20 2008 4:59:52p 3,460 A.... "C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin"
Aug 20 2008 4:58:44p 6,150 A.... "C:\WINDOWS\pchealth\helpctr\System\Headlines.htm"
Aug 20 2008 4:58:44p 5,812 A.... "C:\WINDOWS\pchealth\helpctr\System\HelpCtr.mmf"
Aug 20 2008 4:58:44p 7,737 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__DESKTOP.htm"
Aug 20 2008 4:58:44p 7,355 A.... "C:\WINDOWS\pchealth\helpctr\System\HomePage__SERVER.htm"
Aug 20 2008 6:20:24p 686 A.... "C:\WINDOWS\system32\drivers\etc\HOSTS"
Aug 20 2008 1:13:42a 81 ...H. "C:\WINDOWS\system32\GroupPolicy\Adm\admfiles.ini"
Aug 20 2008 3:01:22a 384 A.... "C:\WINDOWS\system32\GroupPolicy\User\Registry.pol"
Aug 20 2008 2:08:06p 8,239 A.... "C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log"
Aug 20 2008 5:03:14p 5,579 A.... "C:\WINDOWS\system32\oobe\setup\autoupdt.htm"
Aug 20 2008 5:03:14p 13,568 A.... "C:\WINDOWS\system32\oobe\setup\au_plcy.htm"
Jun 27 2008 11:34:16p 1,468 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00000.SHD"
Jun 27 2008 8:40:32p 10,792 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00000.SPL"
Jun 27 2008 11:34:16p 1,468 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00001.SHD"
Jun 27 2008 8:41:38p 10,792 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00001.SPL"
Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00002.SHD"
Jul 1 2008 1:55:12p 36,544 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00002.SPL"
Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00003.SHD"
Jul 1 2008 1:55:20p 34,368 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00003.SPL"
Jul 1 2008 2:00:40p 1,396 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00004.SHD"
Jul 1 2008 1:55:22p 34,368 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00004.SPL"
Jul 13 2008 9:39:20p 1,344 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00005.SHD"
Jul 13 2008 6:54:48p 5,409,320 A.... "C:\WINDOWS\system32\spool\PRINTERS\FP00005.SPL"
Aug 20 2008 4:58:34p 2,775,948 A.... "C:\WINDOWS\system32\wbem\AutoRecover\26C097A9392F8C541AD42E89B7909073.mof"
Aug 20 2008 4:58:32p 15,698 A.... "C:\WINDOWS\system32\wbem\AutoRecover\4DE29A3EB9A6B944E8035563044DBE7E.mof"
Aug 20 2008 5:03:56p 8,820 A.... "C:\WINDOWS\system32\wbem\AutoRecover\6FFF7467A5B40765D5740A413CA8BB8A.mof"
Aug 20 2008 4:58:24p 1,394 A.... "C:\WINDOWS\system32\wbem\AutoRecover\7F417E1A6D819A9B2FEB55DA6858EA0A.mof"
Jun 22 2008 1:56:40p 149,398 A.... "C:\WINDOWS\system32\wbem\AutoRecover\8858F1BA0D460E5A5B27AB13DE3ACB5D.mof"
Aug 20 2008 4:58:24p 8,102 A.... "C:\WINDOWS\system32\wbem\AutoRecover\903E49C444C46FEF5F2C3A189C9CEF71.mof"
Aug 20 2008 4:58:34p 2,566 A.... "C:\WINDOWS\system32\wbem\AutoRecover\9AD3182A2F39A3E091E15109132EC6CC.mof"
Aug 20 2008 5:03:56p 88,742 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C3A0BE17B37ACE48BE78B31580231AE9.mof"
Aug 20 2008 4:58:32p 99,856 A.... "C:\WINDOWS\system32\wbem\AutoRecover\C6300BFE37ADE6B52EC023F66124985F.mof"
Aug 20 2008 4:58:12p 621 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\6.0.2600.5512.Policy"
Aug 20 2008 4:58:12p 623 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\7.0.2600.5512.Policy"
Aug 20 2008 4:58:10p 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\5.2.2.3.Policy"
Aug 20 2008 4:58:10p 605 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\1.0.2600.5512.Policy"
Aug 20 2008 4:58:10p 641 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\5.2.2.3.Policy"
Aug 20 2008 4:58:12p 644 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_x-ww_527a1c68\6.0.9792.0.Policy"
Aug 20 2008 4:58:10p 625 A.... "C:\WINDOWS\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\5.1.2600.2000.Policy"
Aug 20 2008 4:59:44p 62 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000000.query"
Aug 20 2008 4:59:44p 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000001.query"
Aug 20 2008 4:59:44p 752 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000002.query"
Aug 20 2008 4:59:44p 194 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000004.query"
Aug 20 2008 4:59:46p 266 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\00000100.query"
...
<NOTE ALSO REMOVED LONG LIST OF LIKE FILES HERE>
...
Aug 20 2008 4:59:44p 304 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000007c.query"
Aug 20 2008 4:59:46p 4,312 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000017a.query"
Aug 20 2008 4:59:44p 3,096 A.... "C:\WINDOWS\pchealth\helpctr\OfflineCache\Professional_32#0409\0000007a.query"
Aug 20 2008 4:58:44p 2,352 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\about_support.htm"
Aug 20 2008 4:58:44p 1,453 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Favorites.htm"
Aug 20 2008 4:58:44p 1,740 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\ftshelp.htm"
Aug 20 2008 4:58:44p 1,386 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\History.htm"
Aug 20 2008 4:58:44p 1,477 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\Index.htm"
Aug 20 2008 4:58:44p 3,873 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\isupport.htm"
Aug 20 2008 4:58:44p 1,816 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\keywordhelp.htm"
Aug 20 2008 4:58:44p 1,679 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\options.htm"
Aug 20 2008 4:58:44p 1,763 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchblurb.htm"
Aug 20 2008 4:58:44p 10,376 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\searchtips.htm"
Aug 20 2008 4:58:44p 1,411 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\tools.htm"
Aug 20 2008 4:58:44p 360,054 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\watermark_300x.bmp"
Aug 20 2008 4:58:44p 2,368 A.... "C:\WINDOWS\pchealth\helpctr\System\blurbs\windows_newsgroups.htm"
Aug 20 2008 4:58:44p 3,155 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\AboutCompat.htm"
Aug 20 2008 4:58:50p 77,245 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatMode.htm"
Aug 20 2008 4:58:44p 1,340 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\CompatOffline.htm"
Aug 20 2008 4:58:44p 2,588 A.... "C:\WINDOWS\pchealth\helpctr\System\CompatCtr\LearnCompat.htm"
Aug 20 2008 4:58:44p 1,175 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Behaviors.css"
Aug 20 2008 4:58:44p 492 A.... "C:\WINDOWS\pchealth\helpctr\System\css\Layout.css"
Aug 20 2008 4:58:44p 850 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\DlgLib.js"
Aug 20 2008 4:58:44p 7,523 A.... "C:\WINDOWS\pchealth\helpctr\System\dialogs\Print.dlg"
Aug 20 2008 4:58:44p 1,656 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.htm"
Aug 20 2008 4:58:50p 1,206 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\dvdupgrd.js"
Aug 20 2008 4:58:44p 9,264 A.... "C:\WINDOWS\pchealth\helpctr\System\DVDUpgrd\stripe.jpg"
Aug 20 2008 4:58:44p 880 A.... "C:\WINDOWS\pchealth\helpctr\System\ErrMsg\ErrorMessagesOffline.htm"
Aug 20 2008 4:58:44p 1,663 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\badurl.htm"
Aug 20 2008 4:58:50p 18,852 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\connection.htm"
Aug 20 2008 4:58:44p 1,655 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\indexfirstlevel.htm"
Aug 20 2008 4:58:44p 2,028 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\notfound.htm"
Aug 20 2008 4:58:44p 775 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\offline.htm"
Aug 20 2008 4:58:44p 1,728 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\redirect.htm"
Aug 20 2008 4:58:44p 1,689 A.... "C:\WINDOWS\pchealth\helpctr\System\errors\unreachable.htm"
Aug 20 2008 4:58:44p 1,557 A.... "C:\WINDOWS\pchealth\helpctr\System\images\error.gif"
Aug 20 2008 4:58:44p 895 A.... "C:\WINDOWS\pchealth\helpctr\System\images\feedback.gif"
Aug 20 2008 4:58:44p 70 A.... "C:\WINDOWS\pchealth\helpctr\System\images\flyout_arrow.gif"
Aug 20 2008 4:58:44p 1,383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\get_conn.gif"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_articles_12x.bmp"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_blank_12x.bmp"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_newwindow_12x.bmp"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_onlineinline_12x.bmp"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tours_12x.bmp"
Aug 20 2008 4:58:44p 630 A.... "C:\WINDOWS\pchealth\helpctr\System\images\icon_tutorials_12x.bmp"
Aug 20 2008 4:58:44p 1,521 A.... "C:\WINDOWS\pchealth\helpctr\System\images\info.gif"
Aug 20 2008 4:58:44p 2,801 A.... "C:\WINDOWS\pchealth\helpctr\System\images\progbar.gif"
Aug 20 2008 4:58:44p 1,466 A.... "C:\WINDOWS\pchealth\helpctr\System\images\warning.gif"
Aug 20 2008 4:58:44p 76 A.... "C:\WINDOWS\pchealth\helpctr\System\images\wrapperhelp.gif"
Aug 20 2008 4:58:44p 55,709 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogs.htm"
Aug 20 2008 4:58:44p 2,654 A.... "C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogshelp.htm"
Aug 20 2008 4:58:50p 19,520 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\AdvSearch.htm"
Aug 20 2008 4:58:44p 608 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm"
Aug 20 2008 4:58:44p 9,174 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Context.htm"
Aug 20 2008 4:58:44p 714 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\firstpage.htm"
Aug 20 2008 4:58:44p 713 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\HHWrapper.htm"
Aug 20 2008 4:58:44p 4,764 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.htm"
Aug 20 2008 4:58:44p 1,990 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\MiniNavBar.xml"
Aug 20 2008 4:58:44p 20,832 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.htm"
Aug 20 2008 4:58:44p 2,513 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\NavBar.xml"
Aug 20 2008 4:58:44p 4,418 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Options.htm"
Aug 20 2008 4:58:44p 43,111 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\RemoteHelp.htm"
Aug 20 2008 4:58:44p 4,553 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\ShareHelp.htm"
Aug 20 2008 4:58:44p 5,547 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\Topics.htm"
Aug 20 2008 4:58:44p 2,367 A.... "C:\WINDOWS\pchealth\helpctr\System\rc\rcRequest.htm"
Aug 20 2008 4:58:48p 80,856 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\ding.wav"
Aug 20 2008 4:58:48p 3,907 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\helpeeaccept.htm"
Aug 20 2008 4:58:50p 540 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAClientLayout.xml"
Aug 20 2008 4:58:50p 666 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAHelpeeAcceptLayout.xml"
Aug 20 2008 4:58:50p 587 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAIMLayout.xml"
Aug 20 2008 4:58:48p 3,493 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAStartPage.htm"
Aug 20 2008 4:58:50p 569 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\RAURA.xml"
Aug 20 2008 4:58:48p 5,980 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\rcBuddy.htm"
Aug 20 2008 4:58:50p 3,159 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\Common.js"
Aug 20 2008 4:58:44p 4,609 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SHARED.js"
Aug 20 2008 4:58:44p 3,445 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__DESKTOP.js"
Aug 20 2008 4:58:44p 8,844 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\HomePage__SERVER.js"
Aug 20 2008 4:58:44p 2,954 A.... "C:\WINDOWS\pchealth\helpctr\System\scripts\wrapperparam.js"
Aug 20 2008 4:58:50p 32,141 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\commonFunc.js"
Aug 20 2008 4:58:44p 26,520 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\loc_strings.xml"
Aug 20 2008 4:58:44p 2,501 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.htm"
Aug 20 2008 4:58:44p 371 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfo.xml"
Aug 20 2008 4:58:44p 582 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\msinfohss.css"
Aug 20 2008 4:58:44p 56,540 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.htm"
Aug 20 2008 4:58:44p 56,777 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\RSoP.js"
Aug 20 2008 4:58:50p 25,050 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.htm"
Aug 20 2008 4:58:50p 27,910 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysComponentInfo.js"
Aug 20 2008 4:58:44p 1,323 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysConfigLaunch.htm"
Aug 20 2008 4:58:44p 2,537 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysDiskTS.htm"
Aug 20 2008 4:58:44p 10,312 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysEvtLogInfo.htm"
Aug 20 2008 4:58:44p 13,556 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.htm"
Aug 20 2008 4:58:44p 20,083 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysHealthInfo.js"
Aug 20 2008 4:58:44p 4,132 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysInfoLaunch.htm"
Aug 20 2008 4:58:44p 4,150 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfomain.htm"
Aug 20 2008 4:58:50p 16,097 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysinfosum.htm"
Aug 20 2008 4:58:44p 1,864 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysRemoteInfo.htm"
Aug 20 2008 4:58:44p 10,136 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysServicesInfo.htm"
Aug 20 2008 4:58:50p 7,840 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.htm"
Aug 20 2008 4:58:44p 9,506 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\sysSoftwareInfo.js"
Aug 20 2008 4:58:50p 14,129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\wmi_data.js"
Aug 20 2008 4:58:44p 4,113 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\AboutWU.htm"
Aug 20 2008 4:58:44p 2,059 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\Learn.htm"
Aug 20 2008 4:58:44p 2,500 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\LearnInternet.htm"
Aug 20 2008 4:58:44p 2,518 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\learnWU.htm"
Aug 20 2008 4:58:44p 1,132 A.... "C:\WINDOWS\pchealth\helpctr\System\UpdateCtr\updatecenter.htm"
Aug 20 2008 4:58:48p 627 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Connection.htm"
Aug 20 2008 4:58:48p 682 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GArrow.gif"
Aug 20 2008 4:58:48p 311 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GRect.gif"
Aug 20 2008 4:58:48p 213 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Info_Icon.gif"
Aug 20 2008 4:58:48p 2,722 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineOptions.htm"
Aug 20 2008 4:58:48p 13,050 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineDC.htm"
Aug 20 2008 4:58:48p 781 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\PSS.css"
Aug 20 2008 4:58:48p 10,912 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot.xml"
Aug 20 2008 4:58:48p 7,098 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-less.xml"
Aug 20 2008 4:58:48p 10,755 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pssmachinesnapshot-wo-com.xml"
Aug 20 2008 4:58:48p 30,494 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\pss_getting_worldwide_help.htm"
Aug 20 2008 4:58:48p 114 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c1.gif"
Aug 20 2008 4:58:48p 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c2.gif"
Aug 20 2008 4:58:48p 106 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c3.gif"
Aug 20 2008 4:58:48p 107 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r3_c2.gif"
Aug 20 2008 4:58:48p 43 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\spacer.gif"
Aug 20 2008 4:58:48p 232 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\status_ok.gif"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_blue_normal_shadow.bmp"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\arrow_green_normal_shadow.bmp"
Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\compat.bmp"
Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\errmsg.bmp"
Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\support.bmp"
Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\tools.bmp"
Aug 20 2008 4:58:44p 1,078 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\update.bmp"
Aug 20 2008 4:58:44p 600 A.... "C:\WINDOWS\pchealth\helpctr\System\images\16x16\warning.gif"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mousedown.bmp"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_mouseover.bmp"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\24x24\arrow_green_normal.bmp"
Aug 20 2008 4:58:44p 2,358 A.... "C:\WINDOWS\pchealth\helpctr\System\images\32x32\logo.bmp"
Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_generic.bmp"
Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_01.bmp"
Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_02.bmp"
Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_03.bmp"
Aug 20 2008 4:58:44p 9,270 A.... "C:\WINDOWS\pchealth\helpctr\System\images\48x48\desktop_icon_04.bmp"
Aug 20 2008 4:58:44p 674 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\blue_arrow.gif"
Aug 20 2008 4:58:44p 1,383 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Connect.gif"
Aug 20 2008 4:58:44p 1,839 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\IULogo.gif"
Aug 20 2008 4:58:44p 1,525 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Centers\Uabrand.gif"
Aug 20 2008 4:58:44p 139 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\collapsed.gif"
Aug 20 2008 4:58:44p 136 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\endnode.gif"
Aug 20 2008 4:58:44p 135 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\expanded.gif"
Aug 20 2008 4:58:44p 207 A.... "C:\WINDOWS\pchealth\helpctr\System\images\Expando\helpdoc.gif"
Aug 20 2008 4:58:44p 8,494 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Channels.htm"
Aug 20 2008 4:58:44p 8,522 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Favorites.htm"
Aug 20 2008 4:58:44p 5,369 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\History.htm"
Aug 20 2008 4:58:44p 2,911 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Index.htm"
Aug 20 2008 4:58:44p 3,465 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Options.htm"
Aug 20 2008 4:58:50p 37,469 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Search.htm"
Aug 20 2008 4:58:44p 6,520 A.... "C:\WINDOWS\pchealth\helpctr\System\panels\subpanels\Subsite.htm"
Aug 20 2008 4:58:50p 5,231 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\common.js"
Aug 20 2008 4:58:48p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\ConnIssue.htm"
Aug 20 2008 4:58:48p 2,151 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\constants.js"
Aug 20 2008 4:58:48p 234 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_information_32x.gif"
Aug 20 2008 4:58:48p 219 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\icon_warning_32x.gif"
Aug 20 2008 4:58:48p 1,633 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\LearnInternet.htm"
Aug 20 2008 4:58:48p 2,317 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RAHelp.htm"
Aug 20 2008 4:58:48p 2,981 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Common\RCMoreInfo.htm"
Aug 20 2008 4:58:48p 1,369 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\RAChat.css"
Aug 20 2008 4:58:48p 2,442 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rc.css"
Aug 20 2008 4:58:48p 1,308 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Css\rcbuddy.css"
Aug 20 2008 4:58:44p 118 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\alert.gif"
Aug 20 2008 4:58:44p 674 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\BArrow.gif"
Aug 20 2008 4:58:44p 162 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\card.gif"
Aug 20 2008 4:58:44p 257 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\cd.gif"
Aug 20 2008 4:58:44p 145 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\check.gif"
Aug 20 2008 4:58:44p 102 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\chip.gif"
Aug 20 2008 4:58:44p 1,498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\down.bmp"
Aug 20 2008 4:58:44p 139 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\drive.gif"
Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\error.gif"
Aug 20 2008 4:58:44p 159 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\floppy.gif"
Aug 20 2008 4:58:44p 682 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\GArrow.gif"
Aug 20 2008 4:58:44p 135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\gears.gif"
Aug 20 2008 4:58:44p 677 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\greendot.jpg"
Aug 20 2008 4:58:44p 99 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\info.gif"
Aug 20 2008 4:58:44p 129 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\monitor.gif"
Aug 20 2008 4:58:44p 181 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\personalizing.gif"
Aug 20 2008 4:58:44p 1,135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieChart.gif"
Aug 20 2008 4:58:44p 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieGrey.gif"
Aug 20 2008 4:58:44p 67 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\PieWhite.gif"
Aug 20 2008 4:58:44p 136 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\printer.gif"
Aug 20 2008 4:58:44p 114 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c1.gif"
Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c2.gif"
Aug 20 2008 4:58:44p 106 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r1_c3.gif"
Aug 20 2008 4:58:44p 107 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\r3_c2.gif"
Aug 20 2008 4:58:44p 43 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\spacer.gif"
Aug 20 2008 4:58:44p 404 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\system.gif"
Aug 20 2008 4:58:44p 1,135 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\Untitled.gif"
Aug 20 2008 4:58:44p 1,498 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\up.bmp"
Aug 20 2008 4:58:44p 262 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\usb.gif"
Aug 20 2008 4:58:44p 569 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\windows.gif"
Aug 20 2008 4:58:48p 2,843 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\confirm.htm"
Aug 20 2008 4:58:50p 16,167 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm"
Aug 20 2008 4:59:52p 16,167 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm"
Aug 20 2008 5:03:34p 40,520 A.... "C:\WINDOWS\system32\spool\drivers\w32x86\3\HPVDJ82I.BUD"
Aug 20 2008 4:58:48p 4,756 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Animation.gif"
Aug 20 2008 4:58:48p 59 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\combobox_line.gif"
Aug 20 2008 4:58:48p 1,094 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\connected.gif"
Aug 20 2008 4:58:48p 1,024 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.gif"
Aug 20 2008 4:58:48p 346 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DividerBar.htm"
Aug 20 2008 4:58:48p 838 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DownArrow.gif"
Aug 20 2008 4:58:48p 8,969 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAChatClient.htm"
Aug 20 2008 4:58:50p 45,530 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.htm"
Aug 20 2008 4:58:50p 11,254 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAClient.js"
Aug 20 2008 4:58:48p 7,140 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAStatusBar.htm"
Aug 20 2008 4:58:50p 11,187 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.htm"
Aug 20 2008 4:58:48p 3,172 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\RAToolBar.xml"
Aug 20 2008 4:58:48p 1,290 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rcscreen6_head.htm"
Aug 20 2008 4:58:50p 2,496 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\rctoolScreen1.htm"
Aug 20 2008 4:58:48p 6,552 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\setting.htm"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.bmp"
Aug 20 2008 4:58:48p 861 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.gif"
Aug 20 2008 4:58:48p 834 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Client\UpArrow.gif"
Aug 20 2008 4:58:50p 690 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\attentioninteraction.gif"
Aug 20 2008 4:58:48p 2,086 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\ErrorMsgs.htm"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.bmp"
Aug 20 2008 4:58:48p 845 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.gif"
Aug 20 2008 4:58:48p 379 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\hide-chat.gif"
Aug 20 2008 4:58:48p 227 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\info.gif"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.bmp"
Aug 20 2008 4:58:48p 713 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.gif"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.bmp"
Aug 20 2008 4:58:48p 750 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.gif"
Aug 20 2008 4:58:50p 15,709 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RAControl.js"
Aug 20 2008 4:58:50p 30,918 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\RCFileXfer.htm"
Aug 20 2008 4:58:48p 1,041 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendChat.gif"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.bmp"
Aug 20 2008 4:58:48p 694 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.gif"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.bmp"
Aug 20 2008 4:58:48p 692 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.gif"
Aug 20 2008 4:58:48p 994 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoiceOn.gif"
Aug 20 2008 4:58:48p 380 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\show-chat.gif"
Aug 20 2008 4:58:50p 3,226 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\voicefirewallmsg.htm"
Aug 20 2008 4:58:48p 2,333 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Common\VOIPMsgs.htm"
Aug 20 2008 4:58:48p 341 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar1.htm"
Aug 20 2008 4:58:48p 353 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\DividerBar2.htm"
Aug 20 2008 4:58:48p 2,818 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ESC_key.gif"
Aug 20 2008 4:58:48p 75 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Helpee_line.gif"
Aug 20 2008 4:58:48p 8,095 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAChatServer.htm"
Aug 20 2008 4:58:50p 21,049 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.htm"
Aug 20 2008 4:58:50p 5,158 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServer.js"
Aug 20 2008 4:58:50p 14,557 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\RAServerToolBar.htm"
Aug 20 2008 4:58:48p 4,797 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\SettingServer.htm"
Aug 20 2008 4:58:48p 3,898 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.bmp"
Aug 20 2008 4:58:48p 640 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.gif"
Aug 20 2008 4:58:48p 3,210 A.... "C:\WINDOWS\pchealth\helpctr\System\Remote Assistance\Interaction\Server\TakeControlMsgs.htm"
Aug 20 2008 4:58:44p 734 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\0_chart.gif"
Aug 20 2008 4:58:44p 741 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\100_chart.gif"
Aug 20 2008 4:58:44p 784 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\10_chart.gif"
Aug 20 2008 4:58:44p 778 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\15_chart.gif"
Aug 20 2008 4:58:44p 775 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\20_chart.gif"
Aug 20 2008 4:58:44p 781 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\25_chart.gif"
Aug 20 2008 4:58:44p 782 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\30_chart.gif"
Aug 20 2008 4:58:44p 793 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\35_chart.gif"
Aug 20 2008 4:58:44p 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\40_chart.gif"
Aug 20 2008 4:58:44p 785 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\45_chart.gif"
Aug 20 2008 4:58:44p 762 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\50_chart.gif"
Aug 20 2008 4:58:44p 777 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\55_chart.gif"
Aug 20 2008 4:58:44p 773 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\5_chart.gif"
Aug 20 2008 4:58:44p 789 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\60_chart.gif"
Aug 20 2008 4:58:44p 1,199 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\65_chart.gif"
Aug 20 2008 4:58:44p 1,190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\70_chart.gif"
Aug 20 2008 4:58:44p 1,194 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\75_chart.gif"
Aug 20 2008 4:58:44p 1,196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\80_chart.gif"
Aug 20 2008 4:58:44p 1,190 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\85_chart.gif"
Aug 20 2008 4:58:44p 1,196 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\90_chart.gif"
Aug 20 2008 4:58:44p 1,207 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\33x16pie\95_chart.gif"
Aug 20 2008 4:58:44p 1,345 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\0_chart.gif"
Aug 20 2008 4:58:44p 1,358 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\100_chart.gif"
Aug 20 2008 4:58:44p 1,443 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\10_chart.gif"
Aug 20 2008 4:58:44p 1,435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\15_chart.gif"
Aug 20 2008 4:58:44p 1,421 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\20_chart.gif"
Aug 20 2008 4:58:44p 1,423 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\25_chart.gif"
Aug 20 2008 4:58:44p 1,428 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\30_chart.gif"
Aug 20 2008 4:58:44p 1,441 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\35_chart.gif"
Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\40_chart.gif"
Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\45_chart.gif"
Aug 20 2008 4:58:44p 1,412 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\50_chart.gif"
Aug 20 2008 4:58:44p 1,430 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\55_chart.gif"
Aug 20 2008 4:58:44p 1,413 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\5_chart.gif"
Aug 20 2008 4:58:44p 1,446 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\60_chart.gif"
Aug 20 2008 4:58:44p 1,445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\65_chart.gif"
Aug 20 2008 4:58:44p 1,435 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\70_chart.gif"
Aug 20 2008 4:58:44p 1,442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\75_chart.gif"
Aug 20 2008 4:58:44p 1,447 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\80_chart.gif"
Aug 20 2008 4:58:44p 1,426 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\85_chart.gif"
Aug 20 2008 4:58:44p 1,442 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\90_chart.gif"
Aug 20 2008 4:58:44p 1,445 A.... "C:\WINDOWS\pchealth\helpctr\System\sysinfo\graphics\47x24pie\95_chart.gif"
Aug 20 2008 4:58:50p 5,231 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\common.js"
Aug 20 2008 4:58:50p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm"
Aug 20 2008 4:58:48p 2,151 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\constants.js"
Aug 20 2008 4:58:48p 234 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_information_32x.gif"
Aug 20 2008 4:58:48p 219 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_warning_32x.gif"
Aug 20 2008 4:58:48p 1,633 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\LearnInternet.htm"
Aug 20 2008 4:58:48p 2,317 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RAHelp.htm"
Aug 20 2008 4:58:50p 5,930 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RCMoreInfo.htm"
Aug 20 2008 4:58:48p 1,369 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\RAChat.css"
Aug 20 2008 4:58:48p 2,442 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rc.css"
Aug 20 2008 4:58:48p 1,308 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\rcbuddy.css"
Aug 20 2008 4:59:52p 5,403 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm"
Aug 20 2008 4:59:52p 5,930 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Windows Component Publisher,L=Redmond,S=Washington,C=US\Remote Assistance\Common\rcmoreinfo.htm"
Aug 20 2008 4:58:48p 102 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\address_book.gif"
Aug 20 2008 4:58:48p 1,074 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\arrow.gif"
Aug 20 2008 4:58:48p 690 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\attention.gif"
Aug 20 2008 4:58:48p 384 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_offline.gif"
Aug 20 2008 4:58:48p 387 A.... "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy.gif"
Aug 20 2008 4:58:48p