ComboFix 11-09-24.04 - Administrator 9/2011 Sun 18:41:44.18.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.950.886.1028.18.3070.2759 [GMT 8:00]
執行位置: C:\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Norton AntiVirus *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
.
((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\iklog.log
.
---- 早前運行的結果 -------
.
c:\windows\$NtUninstallKB27891$\32537550
c:\windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
c:\windows\system32\iklog.log
.
.
((((((((((((((((((((((((((((((((((((((( 驅動/服務 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_41a2d2ae
.
.
((((((((((((((((((((((((( 2011-08-25 至 2011-09-25 的新的檔案 )))))))))))))))))))))))))))))))
.
.
2011-09-20 10:30 . 2011-09-20 10:30 1409 ----a-w- c:\windows\QTFont.for
2011-09-18 03:58 . 2011-09-18 03:58 -------- d-----w- C:\$AVG
2011-09-18 03:10 . 2011-09-18 03:10 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
2011-09-18 02:52 . 2011-09-18 02:52 -------- d-----w- c:\documents and settings\Ken\Application Data\AVG2012
2011-09-18 02:49 . 2011-09-25 01:53 -------- d-----w- c:\windows\system32\drivers\AVG
2011-09-18 02:49 . 2011-09-18 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2011-09-17 11:38 . 2008-04-13 18:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2011-09-17 11:38 . 2008-04-13 18:46 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2011-09-17 11:38 . 2008-04-15 10:55 16384 ----a-w- c:\windows\system32\ipsink.ax
2011-09-17 11:38 . 2008-04-13 18:46 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2011-09-17 11:38 . 2008-04-13 18:46 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2011-09-17 11:38 . 2008-04-13 18:46 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2011-09-17 11:38 . 2008-04-13 18:46 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2011-09-17 11:37 . 2008-04-13 18:46 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2011-09-17 11:37 . 2008-04-15 10:54 51712 ----a-w- c:\windows\system32\vfwwdm32.dll
2011-09-17 11:37 . 2008-04-15 10:55 90112 ----a-w- c:\windows\system32\kswdmcap.ax
2011-09-17 11:37 . 2008-04-15 10:55 43008 ----a-w- c:\windows\system32\ksxbar.ax
2011-09-17 11:37 . 2008-04-15 10:55 61440 ----a-w- c:\windows\system32\kstvtune.ax
2011-09-17 11:37 . 2008-04-15 10:55 20992 ----a-w- c:\windows\system32\dshowext.ax
2011-09-16 12:55 . 2011-09-16 12:55 48016 --sha-w- c:\windows\system32\c_37243.nl_
2011-09-16 12:48 . 2011-09-17 11:25 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\NPE
2011-09-15 15:12 . 2011-09-15 15:12 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\Temp
2011-09-15 14:09 . 2011-09-15 14:09 -------- d-----w- c:\program files\Windows Sidebar
2011-09-15 14:09 . 2011-09-18 02:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2011-09-15 13:37 . 2011-09-25 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-09-14 14:51 . 2011-09-14 14:51 -------- d-----w- c:\documents and settings\Ken\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-09-14 14:38 . 2011-09-14 14:38 -------- d-----w- C:\ABC
2011-09-14 14:00 . 2011-09-14 14:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ALM
2011-09-14 13:49 . 2011-09-14 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
2011-09-14 13:41 . 2011-09-14 13:41 -------- d-----w- c:\documents and settings\Ken\Adobe Flash Builder 4.5
2011-09-14 12:22 . 2011-09-14 12:22 -------- d-----w- c:\program files\My Company Name
2011-09-13 07:31 . 2011-09-13 12:33 -------- d-----w- c:\documents and settings\Ken\Application Data\Dropbox
2011-09-13 04:12 . 2011-09-13 04:12 -------- d-----w- c:\program files\VS Revo Group
2011-09-12 15:44 . 2011-09-13 15:46 -------- d-----w- c:\windows\AutoKMS
2011-09-12 15:28 . 2011-09-12 15:28 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\PackageAware
2011-09-12 15:07 . 2011-09-13 03:31 -------- d-----w- c:\program files\Facecons
2011-09-12 13:38 . 2011-09-12 15:29 -------- d-----w- c:\program files\Microsoft.NET
2011-09-12 13:38 . 2011-09-12 13:38 -------- d-----w- c:\documents and settings\All Users\Microsoft
2011-09-12 13:33 . 2011-09-12 13:33 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-09-12 13:31 . 2011-09-12 13:31 -------- d-----r- C:\MSOCache
2011-09-11 18:37 . 2011-09-11 18:37 -------- d-----w- c:\documents and settings\Ken\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
2011-09-11 18:37 . 2011-09-11 18:37 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-09-11 17:27 . 2011-09-11 17:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Premium
2011-09-11 17:27 . 2011-09-12 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate
2011-09-11 15:40 . 2011-09-11 15:40 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\SoftGrid Client
2011-09-11 15:40 . 2011-09-11 16:32 -------- d-----w- c:\documents and settings\Ken\Application Data\SoftGrid Client
2011-09-11 15:39 . 2011-09-11 16:33 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-09-11 15:37 . 2011-09-11 15:43 -------- d-----w- c:\documents and settings\Ken\Application Data\TP
2011-09-11 15:10 . 2011-09-11 15:10 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\TechSmith
2011-09-11 15:07 . 2011-09-11 15:07 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2011-09-11 15:07 . 2011-09-11 15:08 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2011-09-11 15:07 . 2011-09-11 15:07 -------- d-----w- c:\program files\TechSmith
2011-09-11 14:32 . 2006-10-17 14:29 487479 ----a-w- c:\windows\system32\SkinMagic.dll
2011-09-11 12:23 . 2011-09-11 12:24 -------- d-----w- c:\program files\ZD Soft
2011-09-11 12:06 . 2011-09-12 15:32 -------- d-----w- c:\program files\DebugMode
2011-09-11 11:52 . 2011-09-11 11:57 -------- d-----w- c:\program files\Free Screen Recorder
2011-09-11 11:41 . 2008-04-15 10:54 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-09-11 11:41 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-09-11 11:40 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-09-08 13:33 . 2011-09-08 13:34 -------- d-----w- c:\program files\Scratch
2011-09-05 17:05 . 2011-09-05 17:05 47512 ----a-w- c:\windows\system32\AdobePDF.dll
2011-09-05 17:04 . 2011-09-05 17:04 22936 ----a-w- c:\windows\system32\AdobePDFUI.dll
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-09-03 10:17 . 2011-09-09 09:11 591872 -c----w- c:\windows\system32\dllcache\crypt32.dll
2011-09-01 16:02 . 2011-09-01 16:02 -------- d-----w- c:\documents and settings\Ken\.google
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:11 . 2004-08-12 10:00 591872 ----a-w- c:\windows\system32\crypt32.dll
2011-08-22 08:44 . 2011-07-18 01:14 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-14 06:24 . 2010-06-04 09:38 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-08-14 06:24 . 2007-07-16 01:30 128000 ----a-w- c:\windows\system32\javacpl.cpl
2011-08-07 22:08 . 2011-08-07 22:08 40016 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-07-31 07:35 . 2011-07-31 07:35 65536 ----a-w- c:\windows\system32\frapsvid.dll
2011-07-15 13:29 . 2004-08-12 10:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-10 17:14 . 2011-07-10 17:14 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-07-10 17:14 . 2011-07-10 17:14 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-07-10 17:14 . 2011-07-10 17:14 24272 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2011-07-10 17:14 . 2011-07-10 17:14 23120 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-07-10 17:14 . 2011-07-10 17:14 134608 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-07-10 17:13 . 2011-07-10 17:13 229840 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-07-10 17:13 . 2011-07-10 17:13 32464 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-07-10 10:23 . 2011-08-20 07:19 336400 ----a-w- c:\windows\system32\mltcpip32.mlp
2011-07-10 10:23 . 2011-08-20 07:19 93712 ----a-w- c:\windows\system32\mltcp32.mlp
2011-07-10 10:23 . 2011-08-20 07:19 88080 ----a-w- c:\windows\system32\mlshm32.mlp
2011-07-10 10:22 . 2011-08-20 07:19 167952 ----a-w- c:\windows\system32\mlmodule32.dll
2011-07-10 10:22 . 2011-08-20 07:19 79376 ----a-w- c:\windows\system32\mlmap32.mlp
2011-07-10 10:22 . 2011-08-20 07:19 369680 ----a-w- c:\windows\system32\ml32i3.dll
2011-07-10 10:22 . 2011-08-20 07:19 260112 ----a-w- c:\windows\system32\ml32i2.dll
2011-07-10 10:22 . 2011-08-20 07:19 253968 ----a-w- c:\windows\system32\ml32i1.dll
2011-07-08 14:02 . 2004-08-12 10:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-09-07 12:39 . 2011-05-23 13:13 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2009-12-10 16:56 . 2009-12-10 16:56 253952 ----a-w- c:\program files\mozilla firefox\components\CheckTudouVa.dll
2010-04-22 19:44 . 2010-05-07 11:57 79664 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\atapi.sys
[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
[-] 2004-08-12 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
.
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\asyncmac.sys
[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
[-] 2004-08-12 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys
.
[-] 2004-08-12 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2004-08-12 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys
.
[-] 2008-04-15 . 781A83EE8D53443539E54D4743437196 . 23296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-15 . 781A83EE8D53443539E54D4743437196 . 23296 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\kbdclass.sys
[-] 2008-04-15 . 781A83EE8D53443539E54D4743437196 . 23296 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
[-] 2004-08-12 . 8CCDD51821BBACD3DBA1AFA5E7C4D756 . 23424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys
.
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ndis.sys
[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
[-] 2004-08-12 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys
.
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ntfs.sys
[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
[-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2004-08-12 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ntfs.sys
[-] 2004-08-12 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB930916$\ntfs.sys
.
[-] 2004-08-12 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2004-08-12 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys
.
[-] 2008-04-15 . A6AF7426A3997FB41F98BC824B4AF17C . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
[-] 2008-04-15 . A6AF7426A3997FB41F98BC824B4AF17C . 77824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\browser.dll
[-] 2008-04-15 . A6AF7426A3997FB41F98BC824B4AF17C . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
[-] 2004-08-12 . 1575EF29B1918CF69A156EFFD71AA518 . 77312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\browser.dll
.
[-] 2008-04-15 . 4E09C68586CF236B9853FC7F93F69C62 . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-15 . 4E09C68586CF236B9853FC7F93F69C62 . 13312 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\lsass.exe
[-] 2008-04-15 . 4E09C68586CF236B9853FC7F93F69C62 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
[-] 2004-08-12 . 667F58ED31D0CB4D5909CF2219B7FF70 . 13312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe
.
[-] 2008-04-15 . EBE06A8BC7AF8F3FBDD987AE16056A6A . 197120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
[-] 2008-04-15 . EBE06A8BC7AF8F3FBDD987AE16056A6A . 197120 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\netman.dll
[-] 2008-04-15 . EBE06A8BC7AF8F3FBDD987AE16056A6A . 197120 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
[-] 2005-08-22 . C3BD19BE25894ABA1D824060DBA380DC . 196608 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll
[-] 2004-08-12 . 7BB4F981873F8087E3D19E2C282C1834 . 197120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netman.dll
[-] 2004-08-12 . 7BB4F981873F8087E3D19E2C282C1834 . 197120 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB905414$\netman.dll
.
[-] 2008-04-15 10:54 . DBFD3D48B295F7A3FF907B27B206EC06 . 619520 . . [2001.12.4414.700] . . c:\windows\ServicePackFiles\i386\comres.dll
[-] 2008-04-15 10:54 . DBFD3D48B295F7A3FF907B27B206EC06 . 619520 . . [2001.12.4414.700] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\comres.dll
[-] 2008-04-15 10:54 . DBFD3D48B295F7A3FF907B27B206EC06 . 619520 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
[-] 2004-08-12 10:00 . B1C69C983E63FB28B7D04A1473D6DDF8 . 619520 . . [2001.12.4414.258] . . c:\windows\$NtServicePackUninstall$\comres.dll
.
[-] 2008-04-15 . 25ADD5F84EC1E7DCAF48F9669D00F20C . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
[-] 2008-04-15 . 25ADD5F84EC1E7DCAF48F9669D00F20C . 409088 . . [6.7.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\qmgr.dll
[-] 2008-04-15 . 25ADD5F84EC1E7DCAF48F9669D00F20C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
[-] 2008-04-15 . 25ADD5F84EC1E7DCAF48F9669D00F20C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll
[-] 2004-08-12 . 75F977315C40B14B9F64F44B40E6523D . 382464 . . [6.6.2600.2180] . . c:\windows\$NtServicePackUninstall$\qmgr.dll
.
[-] 2009-02-09 . E9D71100B51AF947485C1A1D5BB96420 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2009-02-09 . E663977BFB3010FC60C47167A3B2A534 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . E663977BFB3010FC60C47167A3B2A534 . 401408 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2008-04-15 . 621AE6FE5A11D0B1AA58E7645773B1AF . 399360 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\rpcss.dll
[-] 2008-04-15 . 621AE6FE5A11D0B1AA58E7645773B1AF . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2008-04-15 . 621AE6FE5A11D0B1AA58E7645773B1AF . 399360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\rpcss.dll
[-] 2005-07-26 . 54CDADD68D7D044E56A236DDF6AB6312 . 398336 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\rpcss.dll
[-] 2005-04-28 . 58F1C1DF277BF509531100731FE0BA1D . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . C1901C996B9F603698AB8FFC903A556D . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2004-08-12 . ECC989F0C862FFF72726E9BE01A30C5C . 395776 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2004-08-12 . ECC989F0C862FFF72726E9BE01A30C5C . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
.
[-] 2009-02-09 . 03BADD2C0EEC04B91ABBD4F570569DC5 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\services.exe
[-] 2009-02-09 . 03BADD2C0EEC04B91ABBD4F570569DC5 . 110592 . . [5.1.2600.5755] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-09 . 577A24BF31050D354801BD9301CC7ACF . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-15 . 5A46FFC92E0A0632DC2CE87330E83030 . 108544 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956572$\services.exe
[-] 2008-04-15 . 5A46FFC92E0A0632DC2CE87330E83030 . 108544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\services.exe
[-] 2008-04-15 . 5A46FFC92E0A0632DC2CE87330E83030 . 108544 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\services.exe
[-] 2004-08-12 . 232C421AD4E93A1ED15B6D887FF07066 . 108032 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\services.exe
.
[-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] . . c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\spoolsv.exe
[-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] . . c:\windows\system32\dllcache\spoolsv.exe
[-] 2008-04-15 . D45799D6241DE2A68CEB2C4E708E89B0 . 57856 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2347290$\spoolsv.exe
[-] 2008-04-15 . D45799D6241DE2A68CEB2C4E708E89B0 . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-15 . D45799D6241DE2A68CEB2C4E708E89B0 . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2004-08-12 . 131268ADCC76BA28C4D425AD4B1006A5 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
.
[-] 2008-04-15 . 0D07E75030839CF4A0A0D854484A7FEF . 493568 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-15 . 0D07E75030839CF4A0A0D854484A7FEF . 493568 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\winlogon.exe
[-] 2008-04-15 . 0D07E75030839CF4A0A0D854484A7FEF . 493568 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2004-08-12 . 5A9C3615AF0188E61F25ACEDCD904C92 . 487936 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
.
[-] 2010-08-23 . 42535D25A64D5037EA9C6419FD9034FF . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2010-08-23 . 42535D25A64D5037EA9C6419FD9034FF . 617472 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[-] 2010-08-23 . 8445A2BC69AACB6E95155774BC1705A0 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[-] 2008-04-15 . 540B82F3D6304CAE3272B1926CE30E00 . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[-] 2008-04-15 . 540B82F3D6304CAE3272B1926CE30E00 . 617472 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-15 . 540B82F3D6304CAE3272B1926CE30E00 . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\comctl32.dll
[-] 2008-04-15 . 7CAFFF4FF50F0A309CF30114DE4CC4E9 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\asms\60\msft\windows\common\controls\comctl32.dll
[-] 2008-04-15 . 7CAFFF4FF50F0A309CF30114DE4CC4E9 . 1054208 . . [6.0] . . c:\windows\WinSxS\InstallTemp\3089329\comctl32.dll
[-] 2008-04-15 . 7CAFFF4FF50F0A309CF30114DE4CC4E9 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[-] 2006-08-25 . 5558401C77236AD278480DA94CE391F9 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
[-] 2004-08-12 . E56D2BC1F8C3A0C63C1901356B5A6611 . 611328 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2004-08-12 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2004-08-12 . B5FBAC2ACF5A70D6D389479008E28306 . 1050624 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
[-] 2004-08-12 . E56D2BC1F8C3A0C63C1901356B5A6611 . 611328 . . [5.82] . . c:\windows\$NtUninstallKB923191$\comctl32.dll
[-] 2004-08-12 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\InstallTemp\66369\comctl32.dll
.
[-] 2008-04-15 . 19CBC2DD23F3DF39C0BB9470EF01E5F3 . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
[-] 2008-04-15 . 19CBC2DD23F3DF39C0BB9470EF01E5F3 . 62464 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\cryptsvc.dll
[-] 2008-04-15 . 19CBC2DD23F3DF39C0BB9470EF01E5F3 . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
[-] 2004-08-12 . 222B9EE60B9106EB8C03D1C4ED59E55F . 60416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll
.
[-] 2008-07-07 20:30 . 26B6F854BC60346624448453B4064316 . 253952 . . [2001.12.4414.320] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2008-07-07 20:27 . F80DD79D05B594A0181CE14BDAAAC650 . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[-] 2008-07-07 20:27 . F80DD79D05B594A0181CE14BDAAAC650 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:27 . F80DD79D05B594A0181CE14BDAAAC650 . 253952 . . [2001.12.4414.706] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:23 . E92EF81D5E8BF37E1DB63ED1BDB9C16E . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-07-07 20:17 . CC5B380DCA33DADF7EA01FFBD5713E2A . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[-] 2008-04-15 10:54 . EF429761AC7161F38979BADAEF23C825 . 246272 . . [2001.12.4414.701] . . c:\windows\$NtUninstallKB950974$\es.dll
[-] 2008-04-15 10:54 . EF429761AC7161F38979BADAEF23C825 . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2008-04-15 10:54 . EF429761AC7161F38979BADAEF23C825 . 246272 . . [2001.12.4414.701] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\es.dll
[-] 2005-07-26 04:29 . B000463E9F02EFB28F9730F37DF873E2 . 243200 . . [2001.12.4414.308] . . c:\windows\$hf_mig$\KB902400\SP2QFE\es.dll
[-] 2004-08-12 10:00 . 93C638635BC2392511003A5DC690F6A3 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB950974_0$\es.dll
[-] 2004-08-12 04:00 . 93C638635BC2392511003A5DC690F6A3 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB902400$\es.dll
.
[-] 2008-04-15 . F74927743F8D8F58C277D37C3F0DD7CB . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-15 . F74927743F8D8F58C277D37C3F0DD7CB . 110080 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\imm32.dll
[-] 2008-04-15 . F74927743F8D8F58C277D37C3F0DD7CB . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
[-] 2004-08-12 . 36242C7F81706BA6103E7DA273CDA782 . 110080 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\imm32.dll
.
[-] 2009-03-21 . 5F545A19FED4464DA3BAA1DFB5134707 . 1156096 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . 5F545A19FED4464DA3BAA1DFB5134707 . 1156096 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . FB9C8D83863EB9442BDF54D58CBE19A5 . 1158144 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2008-04-15 . 11F9B0324BBC4E8EE90D53FBAAF788F2 . 1156096 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB959426$\kernel32.dll
[-] 2008-04-15 . 11F9B0324BBC4E8EE90D53FBAAF788F2 . 1156096 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kernel32.dll
[-] 2008-04-15 . 11F9B0324BBC4E8EE90D53FBAAF788F2 . 1156096 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\kernel32.dll
[-] 2007-04-16 . 6808E4CC97631FAD8D1EF5460FA7359F . 1152512 . . [5.1.2600.3119] . . c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[-] 2006-07-05 . 8DBDAFF18F4AB91F0EB6D02CAC9B461A . 1151488 . . [5.1.2600.2945] . . c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
[-] 2006-07-05 . A31BD5DD405AABE87C47B1039DC71DAA . 1150464 . . [5.1.2600.2945] . . c:\windows\$NtUninstallKB935839$\kernel32.dll
[-] 2004-08-12 . 9940D5F6B21DD16044AA27E12ADDAE89 . 1149952 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kernel32.dll
[-] 2004-08-12 . 9940D5F6B21DD16044AA27E12ADDAE89 . 1149952 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB917422$\kernel32.dll
.
[-] 2008-04-15 . 67C4D7D09AEE4ED5EA304C441C50B4AD . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2008-04-15 . 67C4D7D09AEE4ED5EA304C441C50B4AD . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\linkinfo.dll
[-] 2008-04-15 . 67C4D7D09AEE4ED5EA304C441C50B4AD . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
[-] 2005-09-01 . 037840BA6A992B66D31548CCEE07A55B . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2004-08-12 . 3A53CF1A8C67CB15F5D9D65F8F68536C . 18944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2004-08-12 . 3A53CF1A8C67CB15F5D9D65F8F68536C . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll
.
[-] 2008-04-15 . C552E8C7BD2837E3C5F4652DAB1D2BB4 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
[-] 2008-04-15 . C552E8C7BD2837E3C5F4652DAB1D2BB4 . 22016 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\lpk.dll
[-] 2008-04-15 . C552E8C7BD2837E3C5F4652DAB1D2BB4 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
[-] 2004-08-12 . A9D171A73D510833872D11F6B18F5982 . 22016 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lpk.dll
.
[-] 2008-04-15 . 2E32871DD344F00DDCEA1463A46F84B0 . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
[-] 2008-04-15 . 2E32871DD344F00DDCEA1463A46F84B0 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\msvcrt.dll
[-] 2008-04-15 . 2E32871DD344F00DDCEA1463A46F84B0 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[-] 2008-04-15 . AA863C1EA65F36F439A54AA9E64BA893 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\asms\70\msft\windows\mswincrt\msvcrt.dll
[-] 2008-04-15 . AA863C1EA65F36F439A54AA9E64BA893 . 343040 . . [7.0.2600.5512] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
[-] 2004-08-12 . 6D9090049387E9C0424BD7AB952DB29D . 343040 . . [7.0.2600.2180] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll
[-] 2004-08-12 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
[-] 2004-08-12 . 699EE1335F83DC786078FC4D41179E24 . 343040 . . [7.0.2600.2180] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll
.
[-] 2008-04-15 . 380F657700A117DA25AB6E4713EB8E08 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
[-] 2008-04-15 . 380F657700A117DA25AB6E4713EB8E08 . 407040 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\netlogon.dll
[-] 2008-04-15 . 380F657700A117DA25AB6E4713EB8E08 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
[-] 2004-08-12 . E1E2BA80D8CFC0C6814E5774E42B53D9 . 407040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netlogon.dll
.
[-] 2008-04-15 . FB52B1E513761A3D13FDB8D52655476F . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-15 . FB52B1E513761A3D13FDB8D52655476F . 17408 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\powrprof.dll
[-] 2008-04-15 . FB52B1E513761A3D13FDB8D52655476F . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
[-] 2004-08-12 . 890319064E4F5D60A4294AB5CDFD25D9 . 17408 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\powrprof.dll
.
[-] 2008-04-15 . 011B5C1D7D51291041B4574CD423253C . 172544 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
[-] 2008-04-15 . 011B5C1D7D51291041B4574CD423253C . 172544 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\scecli.dll
[-] 2008-04-15 . 011B5C1D7D51291041B4574CD423253C . 172544 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
[-] 2004-08-12 . 3294F364BA88EDA4A296A7FDD55653E9 . 171520 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\scecli.dll
.
[-] 2008-04-15 . 08ED70669310D136D5EC525FA92322D4 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
[-] 2008-04-15 . 08ED70669310D136D5EC525FA92322D4 . 5120 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\sfc.dll
[-] 2008-04-15 . 08ED70669310D136D5EC525FA92322D4 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
[-] 2004-08-12 . 3148EB8DBF69C8D641E231F2200CE357 . 5120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfc.dll
.
[-] 2008-04-15 . 3AECECC06B3C127F625A73BB6E01668C . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-15 . 3AECECC06B3C127F625A73BB6E01668C . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\svchost.exe
[-] 2008-04-15 . 3AECECC06B3C127F625A73BB6E01668C . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
[-] 2004-08-12 . 8AB5BC670D2B17DB59789500524E08FE . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe
.
[-] 2008-04-15 . F1A48452D018059538CD66E76261C2F4 . 247296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2008-04-15 . F1A48452D018059538CD66E76261C2F4 . 247296 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\tapisrv.dll
[-] 2008-04-15 . F1A48452D018059538CD66E76261C2F4 . 247296 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
[-] 2007-06-18 . E1E074DB9C0C158736A04EC9B6144B3F . 246784 . . [5.1.2600.3158] . . c:\windows\$hf_mig$\KB938828\SP2QFE\tapisrv.dll
[-] 2005-07-08 . 5BAB8AB739453DD356A5C137F48159F1 . 246784 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FCF84F606E86557FD0FCD2CE21F4D245 . 246784 . . [5.1.2600.2716] . . c:\windows\$NtUninstallKB938828$\tapisrv.dll
[-] 2004-08-12 . B33207375E2B018409286E9477A1B517 . 243712 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2004-08-12 . B33207375E2B018409286E9477A1B517 . 243712 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll
.
[-] 2008-04-15 . E38CF3ED0E3BD8397BBF47979FCE40F1 . 573952 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-15 . E38CF3ED0E3BD8397BBF47979FCE40F1 . 573952 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\user32.dll
[-] 2008-04-15 . E38CF3ED0E3BD8397BBF47979FCE40F1 . 573952 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-03-08 . FDEF087C4231D694376835423612A3AD . 573440 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2005-03-02 . 9848C48F99238C5224E68E335D0C0EB6 . 572416 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . 54F0524B9ABCDC6C7C6B3705133509D3 . 572416 . . [5.1.2600.2622] . . c:\windows\$NtUninstallKB925902$\user32.dll
[-] 2004-08-12 . 9F2E567CCCE96E5AA5A57A890385D2C6 . 572416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2004-08-12 . 9F2E567CCCE96E5AA5A57A890385D2C6 . 572416 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
.
[-] 2008-04-15 . A66E0579B78B8C1A62330BB124C9CD23 . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-15 . A66E0579B78B8C1A62330BB124C9CD23 . 25088 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\userinit.exe
[-] 2008-04-15 . A66E0579B78B8C1A62330BB124C9CD23 . 25088 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
[-] 2004-08-12 . 55FC3F751B389187404BA70EAF989F9D . 23552 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
.
[-] 2008-04-15 . EBF5E57B2E84FB3DB0A598364FAAE00C . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-15 . EBF5E57B2E84FB3DB0A598364FAAE00C . 82432 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ws2_32.dll
[-] 2008-04-15 . EBF5E57B2E84FB3DB0A598364FAAE00C . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-12 . 7DD840ECEA9722678BC48BDF664BB810 . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll
.
[-] 2008-04-15 . 935FC91E9E9734114431345618E756AE . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll
[-] 2008-04-15 . 935FC91E9E9734114431345618E756AE . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ws2help.dll
[-] 2008-04-15 . 935FC91E9E9734114431345618E756AE . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll
[-] 2004-08-12 . A838148A8FE49383D56B79FD87982D3D . 19968 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2help.dll
.
[-] 2008-04-15 . 88057E7B74236C11098E4D4EEAC7DF5E . 978432 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-15 . 88057E7B74236C11098E4D4EEAC7DF5E . 978432 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2008-04-15 . 88057E7B74236C11098E4D4EEAC7DF5E . 978432 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\explorer.exe
[-] 2007-06-18 . D1822278F43E2850E03EF36D29686D4F . 977920 . . [6.00.2900.3158] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2004-08-12 . 211358AE74733075C22142B3AC519A19 . 976896 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2004-08-12 . 211358AE74733075C22142B3AC519A19 . 976896 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
.
[-] 2008-04-15 . E8384D6AEC59F62727C5FFDF0703D060 . 132096 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2008-04-15 . E8384D6AEC59F62727C5FFDF0703D060 . 132096 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regedit.exe
[-] 2008-04-15 . E8384D6AEC59F62727C5FFDF0703D060 . 132096 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\regedit.exe
[-] 2004-08-12 . 50B8808A1F8D8416E77B89C30D058B0F . 132096 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regedit.exe
.
[-] 2010-07-16 . A13C0B8AB092AA99F2E51115309F2F4F . 1287680 . . [5.1.2600.6010] . . c:\windows\system32\ole32.dll
[-] 2010-07-16 . A13C0B8AB092AA99F2E51115309F2F4F . 1287680 . . [5.1.2600.6010] . . c:\windows\system32\dllcache\ole32.dll
[-] 2010-07-16 . 0102D4DA9C6DCCDEB27765FCFFAE5B6D . 1288704 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
[-] 2008-04-15 . A1AF7CC75B8105AB42FC9BA0A57A2708 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll
[-] 2008-04-15 . A1AF7CC75B8105AB42FC9BA0A57A2708 . 1287168 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll
[-] 2008-04-15 . A1AF7CC75B8105AB42FC9BA0A57A2708 . 1287168 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ole32.dll
[-] 2005-07-26 . 8409E75CF573F70BA75485E2FBB003A8 . 1285632 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
[-] 2005-04-28 . 6C4ABA088C17B30C7F4E5276B28C48CA . 1286144 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll
[-] 2005-04-28 . 0B9EA5F275BE5092EFFE1212F7A86A20 . 1284608 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\ole32.dll
[-] 2004-08-12 . 2D35307C950EDFBBF32610E40C33B9F9 . 1281024 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ole32.dll
[-] 2004-08-12 . 2D35307C950EDFBBF32610E40C33B9F9 . 1281024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391$\ole32.dll
.
[-] 2010-04-16 . AEA03754A5A3329991163D30FF90FD06 . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\usp10.dll
[-] 2010-04-16 . AEA03754A5A3329991163D30FF90FD06 . 406016 . . [1.0420.2600.5969] . . c:\windows\system32\dllcache\usp10.dll
[-] 2010-04-16 . 351DD7E2C1ABD09D0093A1A7EA49E1CB . 406016 . . [1.0420.2600.5969] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll
[-] 2008-04-15 . CC1170C5E31ED0E0006C085D31D34293 . 406016 . . [1.0420.2600.5512] . . c:\windows\$NtUninstallKB981322$\usp10.dll
[-] 2008-04-15 . CC1170C5E31ED0E0006C085D31D34293 . 406016 . . [1.0420.2600.5512] . . c:\windows\ServicePackFiles\i386\usp10.dll
[-] 2008-04-15 . CC1170C5E31ED0E0006C085D31D34293 . 406016 . . [1.0420.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\usp10.dll
[-] 2004-08-12 . 56BAEE5EEBF420D85E15E33E81F41F60 . 406528 . . [1.0420.2600.2180] . . c:\windows\$NtServicePackUninstall$\usp10.dll
.
[-] 2008-04-15 . BBAC786F11F72A7A05F4AB7A550ACBFF . 4096 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\ksuser.dll
[-] 2008-04-15 . BBAC786F11F72A7A05F4AB7A550ACBFF . 4096 . . [5.3.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ksuser.dll
[-] 2008-04-15 . BBAC786F11F72A7A05F4AB7A550ACBFF . 4096 . . [5.3.2600.5512] . . c:\windows\system32\ksuser.dll
[-] 2004-08-11 . A86FA4F0B23C0F99196043FFF56AE990 . 4096 . . [5.3.2600.2180] . . c:\windows\$NtServicePackUninstall$\ksuser.dll
.
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\srsvc.dll
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
[-] 2004-08-12 . E6A012C244684DDD584E525727806630 . 168960 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll
.
[-] 2008-04-15 . 692414395A8EE4F4871ABA6A68E996A4 . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-15 . 692414395A8EE4F4871ABA6A68E996A4 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\wscntfy.exe
[-] 2008-04-15 . 692414395A8EE4F4871ABA6A68E996A4 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
[-] 2004-08-12 . 51DB6852956183FC473A3F5A59D9E908 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe
.
[-] 2008-04-15 . 7A934888CEF098EEEDED1EEF09F6B5BF . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
[-] 2008-04-15 . 7A934888CEF098EEEDED1EEF09F6B5BF . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\xmlprov.dll
[-] 2008-04-15 . 7A934888CEF098EEEDED1EEF09F6B5BF . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
[-] 2004-08-12 . 7CCB5D4D26D43B9F8BBE9F8F1ED77274 . 129536 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\xmlprov.dll
.
[-] 2008-04-15 . 0A9FB6653A8AC115B5110C0A5C263952 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-15 . 0A9FB6653A8AC115B5110C0A5C263952 . 56320 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\eventlog.dll
[-] 2008-04-15 . 0A9FB6653A8AC115B5110C0A5C263952 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
[-] 2004-08-12 . D33069982F8DCCA36BA9B5E64188BA48 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
.
[-] 2008-04-15 . 5A500070F303F0D2B3EB428E35B8C06C . 1570816 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-15 . 5A500070F303F0D2B3EB428E35B8C06C . 1570816 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\sfcfiles.dll
[-] 2008-04-15 . 5A500070F303F0D2B3EB428E35B8C06C . 1570816 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[-] 2004-08-12 . 150428EFBC597C98DA34FA86A503CDC6 . 1546752 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll
.
[-] 2008-04-15 . 4C97CBAD0CF9E6263C49CFA57BCCAEDD . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-15 . 4C97CBAD0CF9E6263C49CFA57BCCAEDD . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ctfmon.exe
[-] 2008-04-15 . 4C97CBAD0CF9E6263C49CFA57BCCAEDD . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2004-08-12 . 0AB124F591C029952122834036F7BE30 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
[-] 2009-07-27 . 497324C1C8B865EBE080DFF33D855484 . 134144 . . [6.00.2900.5853] . . c:\windows\system32\shsvcs.dll
[-] 2009-07-27 . 497324C1C8B865EBE080DFF33D855484 . 134144 . . [6.00.2900.5853] . . c:\windows\system32\dllcache\shsvcs.dll
[-] 2009-07-27 . D5840205C511AD5D057C0C71AE144F62 . 134144 . . [6.00.2900.5853] . . c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll
[-] 2008-04-15 . B2C5CC863A5463920985553AE6D9903E . 134144 . . [6.00.2900.5512] . . c:\windows\$NtUninstallKB971029$\shsvcs.dll
[-] 2008-04-15 . B2C5CC863A5463920985553AE6D9903E . 134144 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2008-04-15 . B2C5CC863A5463920985553AE6D9903E . 134144 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\shsvcs.dll
[-] 2006-12-19 . 165A96E13698519CE0E1DD9362A441B3 . 134144 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll
[-] 2004-08-12 . 5AAC1A4B788B56F6189070B7E3DBDD13 . 133632 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
[-] 2004-08-12 . 5AAC1A4B788B56F6189070B7E3DBDD13 . 133632 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB928255$\shsvcs.dll
.
[-] 2008-04-15 . 0C84BF1BCC996AC884DE5E60829DB1F4 . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-15 . 0C84BF1BCC996AC884DE5E60829DB1F4 . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\regsvc.dll
[-] 2008-04-15 . 0C84BF1BCC996AC884DE5E60829DB1F4 . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
[-] 2004-08-12 . 4C4AF1B842C3A3BBA7E90527572F3D06 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll
.
[-] 2008-04-15 . D62CFE4CFF830F757CBDEF4FE5BF20AF . 186880 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-15 . D62CFE4CFF830F757CBDEF4FE5BF20AF . 186880 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\schedsvc.dll
[-] 2008-04-15 . D62CFE4CFF830F757CBDEF4FE5BF20AF . 186880 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
[-] 2004-08-12 . 25A63F8345E1827FCF8B3FE219942E94 . 185344 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll
.
[-] 2008-04-15 . 48102E81781864DC3700433C9FE03AA7 . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
[-] 2008-04-15 . 48102E81781864DC3700433C9FE03AA7 . 71680 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ssdpsrv.dll
[-] 2008-04-15 . 48102E81781864DC3700433C9FE03AA7 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
[-] 2004-08-12 . 0D883713E94C8CA6FFB8C2C914D38446 . 71680 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
.
[-] 2008-04-15 . F1D722FAC699F6372D020A634ADC8361 . 286208 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-15 . F1D722FAC699F6372D020A634ADC8361 . 286208 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\termsrv.dll
[-] 2008-04-15 . F1D722FAC699F6372D020A634ADC8361 . 286208 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[-] 2004-08-12 . 43B8706B6EC05301E84B349CBEC18EFF . 286208 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
.
[-] 2008-04-15 . 5728254CA2FC82AB0642A67C3A83E0BA . 333824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\hnetcfg.dll
[-] 2008-04-15 . 5728254CA2FC82AB0642A67C3A83E0BA . 333824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\hnetcfg.dll
[-] 2008-04-15 . 5728254CA2FC82AB0642A67C3A83E0BA . 333824 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
[-] 2004-08-12 . 6127406D984332FA6B79DE14A80AA70A . 333824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\hnetcfg.dll
.
[-] 2004-08-12 . 619410BE0B33801F0FA0AD994B153CB4 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys
.
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
[-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
[-] 2004-08-12 10:00 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\$NtServicePackUninstall$\aec.sys
[-] 2004-08-03 14:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\$NtUninstallKB900485$\aec.sys
.
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\agp440.sys
[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys
[-] 2004-08-03 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\agp440.sys
.
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ip6fw.sys
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
[-] 2004-08-12 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ip6fw.sys
.
[-] 2008-04-15 . BD3408588FC2489A232ADF68983A8DB5 . 29696 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\iprip.dll
[-] 2008-04-15 . BD3408588FC2489A232ADF68983A8DB5 . 29696 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\iprip.dll
[-] 2008-04-15 . BD3408588FC2489A232ADF68983A8DB5 . 29696 . . [5.1.2600.5512] . . c:\windows\system32\iprip.dll
[-] 2004-08-12 . F808C8DCDCDF0A6B3FA3FFBA21DB6FFD . 29696 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\iprip.dll
.
[-] 2010-09-18 07:18 . 7ADB2C0DDBEE245B20F370BFE2696AEA . 953856 . . [4.1.6151] . . c:\windows\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll
[-] 2010-09-18 06:52 . 5D695590EA095E468D271ABBE84E4377 . 953856 . . [4.1.6151] . . c:\windows\system32\mfc40u.dll
[-] 2010-09-18 06:52 . 5D695590EA095E468D271ABBE84E4377 . 953856 . . [4.1.6151] . . c:\windows\system32\dllcache\mfc40u.dll
[-] 2008-04-15 10:54 . 4EA819BA8083F767AE6AFDA1E1930F2A . 927504 . . [4.1.0.61] . . c:\windows\$NtUninstallKB2387149$\mfc40u.dll
[-] 2008-04-15 10:54 . 4EA819BA8083F767AE6AFDA1E1930F2A . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
[-] 2008-04-15 10:54 . 4EA819BA8083F767AE6AFDA1E1930F2A . 927504 . . [4.1.0.61] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\mfc40u.dll
[-] 2004-08-12 10:00 . 4E41965C2C3B6B069255EAE66E2B0A33 . 924432 . . [4.1.6140] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll
[-] 2004-08-12 04:00 . 4E41965C2C3B6B069255EAE66E2B0A33 . 924432 . . [4.1.6140] . . c:\windows\$NtUninstallKB924667$\mfc40u.dll
.
[-] 2008-04-15 . B79E4D171027D927BFA9687723C89A87 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-15 . B79E4D171027D927BFA9687723C89A87 . 33792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\msgsvc.dll
[-] 2008-04-15 . B79E4D171027D927BFA9687723C89A87 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
[-] 2004-08-12 . 68F8E95E2F9C8032ED425886E43F8C43 . 33792 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll
.
[-] 2006-10-18 13:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-18 13:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2005-01-28 00:53 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2005-01-28 00:53 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2004-08-12 10:00 . E69D06FDA2D25E1617117093BEBAA283 . 52224 . . [9.0.1.56] . . c:\windows\$NtServicePackUninstall$\mspmsnsv.dll
[-] 2004-08-12 04:00 . E69D06FDA2D25E1617117093BEBAA283 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
.
[-] 2010-12-09 . 24A5ECA7D2FE1764ACFC3D3DBED92532 . 2027008 . . [5.1.2600.6055] . . c:\windows\system32\ntkrnlpa.exe
[-] 2010-12-09 . D58AF27834858C916DD47129CC659251 . 2069248 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2010-12-09 . D58AF27834858C916DD47129CC659251 . 2069248 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2010-12-09 . AA9AAD51D5564331DCB0F262A12CE2FB . 2069248 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe
[-] 2010-04-28 . FA525A48D4E05A8CA09D201F0FB52022 . 2066816 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe
[-] 2010-04-28 . B6AE1E98CA5643B7BD7BD6AB5635AB38 . 2024448 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe
[-] 2010-02-16 . FDE6B370A68F937E3E0707C1A906FBDF . 2024448 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe
[-] 2010-02-16 . 7743CE017012EAFFCD518EA1331EC240 . 2066816 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe
[-] 2009-12-09 . AD6B1C9E14B57846C4A118DD7C3F5D51 . 2023936 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntkrnlpa.exe
[-] 2009-12-09 . D8DF934C9AE9B549BCEF21BE1C6938A3 . 2066048 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-08-04 . A1CB1DECFE9F8C285DA83E587CF3E84A . 2023936 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe
[-] 2009-08-04 . B5FAA1877D254D2C8A81FE178547EFEA . 2066048 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-02-09 . D427E0A9D6E646C7901D9E1E95A27104 . 2023936 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe
[-] 2009-02-09 . 1C89B423D5C9A5D303723AD462CEC93D . 2066048 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 . 9D72122B11E7638F8D3C7F9D9FDD8C9F . 2020864 . . [5.1.2600.3427] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
[-] 2008-08-14 . A915E8F1CA374043615A8AB0C88442CE . 2065920 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
[-] 2008-08-14 . 6051C2DAD7AD5722E50248A42C7C1AA1 . 2023936 . . [5.1.2600.5657] . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[-] 2008-08-14 . 2612BBB588E37A8CC5D9ED9B1BCFCB10 . 2065920 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-04-15 . E7FA03C6160E9B5F7A8789478B31C7CC . 2023936 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
[-] 2008-04-15 . 7808D5B49D30B5A0FD09C4420D97CAAB . 2065792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2008-04-15 . 7808D5B49D30B5A0FD09C4420D97CAAB . 2065792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ntkrnlpa.exe
[-] 2006-12-19 . 12D56FD8097D4BFE7310AFE064D29B91 . 2017280 . . [5.1.2600.3051] . . c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
[-] 2006-10-30 . 352B17A8C2764883DC41065331E9CCBC . 2017280 . . [5.1.2600.3023] . . c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
[-] 2005-03-30 . 0510B3733CEC32C89E023F5D0BB15800 . 2015232 . . [5.1.2600.2643] . . c:\windows\$NtUninstallKB956841_0$\ntkrnlpa.exe
[-] 2005-03-02 . ACD412243D6652EF6B86F5671ABDB159 . 2056832 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
.
[-] 2008-04-15 10:54 . 61B72B947C343400C9682CE08DD2CF98 . 429056 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-15 10:54 . 61B72B947C343400C9682CE08DD2CF98 . 429056 . . [5.1.2400.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ntmssvc.dll
[-] 2008-04-15 10:54 . 61B72B947C343400C9682CE08DD2CF98 . 429056 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
[-] 2004-08-12 10:00 . 09C11261DFE650B7D924E49EFC793431 . 429056 . . [5.1.2400.2180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll
.
[-] 2008-04-15 . 39883E6BC093DE7F36861EFFDA09CB05 . 183808 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-15 . 39883E6BC093DE7F36861EFFDA09CB05 . 183808 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\upnphost.dll
[-] 2008-04-15 . 39883E6BC093DE7F36861EFFDA09CB05 . 183808 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
[-] 2007-02-05 . FCB333B6325EC8A0177A07ABFFBFD933 . 182784 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
[-] 2004-08-12 . 4A04B09863C815B671811C726B696C68 . 182784 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\upnphost.dll
[-] 2004-08-12 . 4A04B09863C815B671811C726B696C68 . 182784 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB931261$\upnphost.dll
.
[-] 2008-04-15 . 938C17B4AC71DB743743BED20E401844 . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll
[-] 2008-04-15 . 938C17B4AC71DB743743BED20E401844 . 367616 . . [5.3.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\dsound.dll
[-] 2008-04-15 . 938C17B4AC71DB743743BED20E401844 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll
[-] 2004-08-12 . C1A715F2082A0BF74DBCF419526EB05F . 367616 . . [5.3.2600.2180] . . c:\windows\$NtServicePackUninstall$\dsound.dll
.
[-] 2008-04-15 . 61CC5C50BCEB93B66E5D63ED2EB47E3A . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll
[-] 2008-04-15 . 61CC5C50BCEB93B66E5D63ED2EB47E3A . 1689088 . . [5.03.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\d3d9.dll
[-] 2008-04-15 . 61CC5C50BCEB93B66E5D63ED2EB47E3A . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll
[-] 2004-08-12 . AB2511ABCE215E068A0A46E9BA18E0BB . 1689088 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\d3d9.dll
.
[-] 2008-04-15 . 50829DDC0AD93F155ACFA4E13F3FD636 . 279040 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll
[-] 2008-04-15 . 50829DDC0AD93F155ACFA4E13F3FD636 . 279040 . . [5.03.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ddraw.dll
[-] 2008-04-15 . 50829DDC0AD93F155ACFA4E13F3FD636 . 279040 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll
[-] 2004-08-12 . 87954EF317C3D669BCD6CE2A7150098A . 265728 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\ddraw.dll
.
[-] 2008-04-15 10:54 . 9807404DF7B007586BE953CB5CED0B5C . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll
[-] 2008-04-15 10:54 . 9807404DF7B007586BE953CB5CED0B5C . 84992 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\olepro32.dll
[-] 2008-04-15 10:54 . 9807404DF7B007586BE953CB5CED0B5C . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll
[-] 2004-08-12 10:00 . 53E89ADE97FC93576C1F17643555500C . 83456 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\olepro32.dll
.
[-] 2008-04-15 . 2961A2EA799C7F6127F1BE60B822ACD1 . 34304 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll
[-] 2008-04-15 . 2961A2EA799C7F6127F1BE60B822ACD1 . 34304 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\perfctrs.dll
[-] 2008-04-15 . 2961A2EA799C7F6127F1BE60B822ACD1 . 34304 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll
[-] 2004-08-12 . 7EF7751FF58EE3B65259829AAB75D6DD . 34304 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\perfctrs.dll
.
[-] 2008-04-15 . 485AFA4C6BD37DD49CA417278F5FE145 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\version.dll
[-] 2008-04-15 . 485AFA4C6BD37DD49CA417278F5FE145 . 18944 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\version.dll
[-] 2008-04-15 . 485AFA4C6BD37DD49CA417278F5FE145 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll
[-] 2004-08-12 . DCBA8C7A649036F9EE291DA03AC2717B . 18944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\version.dll
.
[-] 2010-12-09 . 305E9ECBCBACE7C793D103BFC8BA549B . 2192640 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe
[-] 2010-12-09 . E0B64301FFA474F0B877D5FACDD1EE70 . 2192640 . . [5.1.2600.6055] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2010-12-09 . E0B64301FFA474F0B877D5FACDD1EE70 . 2192640 . . [5.1.2600.6055] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2010-12-09 . 41ED782DAFA90F21523434047C1015DF . 2148864 . . [5.1.2600.6055] . . c:\windows\system32\ntoskrnl.exe
[-] 2010-04-28 . 17FC18EA62943E6576BE51705FD34E93 . 2146304 . . [5.1.2600.5973] . . c:\windows\$NtUninstallKB2393802$\ntoskrnl.exe
[-] 2010-04-28 . 789F1F8650263E6022F0F32FF9CE8330 . 2189952 . . [5.1.2600.5973] . . c:\windows\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe
[-] 2010-02-16 . A306837B0FA1880F98F83D2EC536F1F4 . 2146304 . . [5.1.2600.5938] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe
[-] 2010-02-16 . 2F18DA51523E9CEF07C40C3E412086CA . 2189952 . . [5.1.2600.5938] . . c:\windows\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe
[-] 2009-12-09 . 0551F7AC179945EA49CBE069DFCD2708 . 2145280 . . [5.1.2600.5913] . . c:\windows\$NtUninstallKB979683$\ntoskrnl.exe
[-] 2009-12-09 . 9CEAB5E658F5782F7A4C0A818464195B . 2189184 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-08-04 . C747A69CF3B1E3BD6476EA7B2F7D2B05 . 2145280 . . [5.1.2600.5857] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe
[-] 2009-08-04 . 82E3AE8AAFCB0E6950AD9633A438559D . 2189184 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[-] 2009-02-10 . AFF75869BDF0CA3F992411C2AC99EAE1 . 2189056 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2009-02-09 . C1FBDE0071192DB50E3C51783EF95F6F . 2145280 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe
[-] 2008-08-14 . 7CC9A57EF0D3D37DC5A3DE6BE663FE1C . 2142720 . . [5.1.2600.3427] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
[-] 2008-08-14 . 207544C19E580507DBACCF24D736A459 . 2189056 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
[-] 2008-08-14 . A87366EB762C7F1C14A99F7D2D27F9D8 . 2145280 . . [5.1.2600.5657] . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
[-] 2008-08-14 . C9ED78E4D4A2CAABADE34BB2F9EF4855 . 2189056 . . [5.1.2600.5657] . . c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-04-15 . 6A85DFB1190736B507EEA978A8D4B357 . 2188928 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2008-04-15 . 6A85DFB1190736B507EEA978A8D4B357 . 2188928 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\ntoskrnl.exe
[-] 2008-04-15 . 60E500797E35C6A2CCA2C6A01793A03E . 2145280 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
[-] 2006-12-19 . 216B17213542A959AAC3919CD3A6C010 . 2137600 . . [5.1.2600.3051] . . c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
[-] 2006-10-30 . B666655BB2E7EE9D508B13BCB397139D . 2137600 . . [5.1.2600.3023] . . c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
[-] 2005-03-30 . 0BADB66A08A243060C71AC69122DDF00 . 2135552 . . [5.1.2600.2643] . . c:\windows\$NtUninstallKB956841_0$\ntoskrnl.exe
[-] 2005-03-02 . CA5B77F8ABC95792241156CA40F26D1D . 2179456 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
.
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\srsvc.dll
[-] 2008-04-15 . B266B3F20F6E1CCCD6A0B0AA25D708B3 . 169472 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
[-] 2004-08-12 . E6A012C244684DDD584E525727806630 . 168960 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll
.
[-] 2008-04-15 . ACF8A5219A3A6E56B5C050212BC2DB24 . 183296 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\w32time.dll
[-] 2008-04-15 . ACF8A5219A3A6E56B5C050212BC2DB24 . 183296 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\w32time.dll
[-] 2008-04-15 . ACF8A5219A3A6E56B5C050212BC2DB24 . 183296 . . [5.1.2600.5512] . . c:\windows\system32\w32time.dll
[-] 2004-08-12 . 75176551C739AADB5D905B094E1AFA33 . 182784 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\w32time.dll
.
[-] 2008-04-15 . 59621C18EE8E2B79E9F0A1BC8F3D6295 . 331776 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wiaservc.dll
[-] 2008-04-15 . 59621C18EE8E2B79E9F0A1BC8F3D6295 . 331776 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\wiaservc.dll
[-] 2008-04-15 . 59621C18EE8E2B79E9F0A1BC8F3D6295 . 331776 . . [5.1.2600.5512] . . c:\windows\system32\wiaservc.dll
[-] 2006-12-19 . E7B68A07E5389AFE55FA264D9D45473A . 331776 . . [5.1.2600.3051] . . c:\windows\$hf_mig$\KB927802\SP2QFE\wiaservc.dll
[-] 2004-08-12 . D19A3700EFF7C720E0F17FF72AC14310 . 331264 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wiaservc.dll
[-] 2004-08-12 . D19A3700EFF7C720E0F17FF72AC14310 . 331264 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB927802$\wiaservc.dll
.
[-] 2008-04-15 . 411750F307ACCEFB58D01773D5DE3D31 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\midimap.dll
[-] 2008-04-15 . 411750F307ACCEFB58D01773D5DE3D31 . 18944 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\midimap.dll
[-] 2008-04-15 . 411750F307ACCEFB58D01773D5DE3D31 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\midimap.dll
[-] 2004-08-12 . 9AB01283152319C1261C6DDE5721E3EA . 18944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\midimap.dll
.
[-] 2008-04-15 . C7E193E318C5FCDC95539D413C0887C7 . 7680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rasadhlp.dll
[-] 2008-04-15 . C7E193E318C5FCDC95539D413C0887C7 . 7680 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44efa6227a0729b233508b6f95c3fb71\rasadhlp.dll
[-] 2008-04-15 . C7E193E318C5FCDC95539D413C0887C7 . 7680 . . [5.1.2600.5512] . . c:\windows\system32\rasadhlp.dll
[-] 2006-06-26 . 8F2100CC9B88B0B7D7123E5EF802B857 . 7680 . . [5.1.2600.2938] . . c:\windows\$hf_mig$\KB920683\SP2QFE\rasadhlp.dll
[-] 2004-08-12 . FC0C871278D0EF84B39693D6CFABDC52 . 8192 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\rasadhlp.dll
[-] 2004-08-12 . FC0C871278D0EF84B39693D6CFABDC52 . 8192 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB920683$\rasadhlp.dll
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{43BEAFD9-E005-483D-A367-146BA6C8A32E}]
2009-12-10 16:56 87448 ----a-w- c:\program files\Tudou\滄厒Tudou\tudouDetector.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-09-07 2401120]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-12 44544]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ken^「開始」功能表^程式集^啟動^OAhotkey.lnk]
path=c:\documents and settings\Ken\「開始」功能表\程式集\啟動\OAhotkey.lnk
backup=c:\windows\pss\OAhotkey.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ken^「開始」功能表^程式集^啟動^OpenOffice.org 3.3.lnk]
path=c:\documents and settings\Ken\「開始」功能表\程式集\啟動\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2011-09-05 17:04 2904984 ----a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-09-05 17:04 36760 ----a-w- c:\program files\Adobe\Acrobat 10.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-29 13:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2011-03-30 00:46 499608 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager]
2011-01-11 23:08 1523360 ----a-w- c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-09-04 11:57 136176 ----atw- c:\documents and settings\Ken\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPS Accelerator]
2010-02-24 03:25 214408 ----a-w- c:\progra~1\PPStream\PPSAP.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 05:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\YouBe Casual Network\\YouBe.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Thunder Network\\DS\\Ver1\\1.0.2.73\\ThunderService.exe"=
"c:\\Program Files\\Common Files\\Thunder Network\\DS\\Ver1\\1.0.2.73\\ThunderLiveUD.exe"=
"c:\\Program Files\\Common Files\\Thunder Network\\DS\\Ver1\\1.0.2.73\\XLBugReport.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\PPStream\\PPStream.exe"=
"c:\\Program Files\\PPStream\\PPSAP.exe"=
"c:\\Program Files\\Common Files\\Tencent\\QQDownload\\112\\Tencentdl.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Adobe\\Adobe Flash Builder 4.5\\FlashBuilder.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3306:TCP"= 3306:TCP:MYSQL
"13521:TCP"= 13521:TCP:BitComet 13521 TCP
"13521:UDP"= 13521:UDP:BitComet 13521 UDP
"11282:TCP"= 11282:TCP:BitComet 11282 TCP
"11282:UDP"= 11282:UDP:BitComet 11282 UDP
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"6892:TCP"= 6892:TCP:League of Legends Launcher
"6892:UDP"= 6892:UDP:League of Legends Launcher
"6954:TCP"= 6954:TCP:League of Legends Launcher
"6954:UDP"= 6954:UDP:League of Legends Launcher
"6950:TCP"= 6950:TCP:League of Legends Launcher
"6950:UDP"= 6950:UDP:League of Legends Launcher
"8382:TCP"= 8382:TCP:League of Legends Launcher
"8382:UDP"= 8382:UDP:League of Legends Launcher
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
"6965:TCP"= 6965:TCP:League of Legends Launcher
"6965:UDP"= 6965:UDP:League of Legends Launcher
"7935:TCP"= 7935:TCP:Adobe Flash Builder 4.5
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11/7/2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [11/7/2011 1:13 32464]
S0 KSRBC;KSRBC;c:\windows\system32\drivers\BC.sys [7/11/2009 0:42 24944]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11/7/2011 1:13 229840]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/7/2011 1:14 295248]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [18/2/2010 2:25 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/5/2010 2:41 67656]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [1/9/2011 6:16 5265248]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/8/2011 6:09 192776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/3/2010 13:16 130384]
S2 EraserSvc11113;Symantec Eraser Service;"c:\program files\Norton AntiVirus\Engine\19.1.0.28\ccSvcHst.exe" /h ccCommon --> c:\program files\Norton AntiVirus\Engine\19.1.0.28\ccSvcHst.exe [?]
S2 sbbotdi;sbbotdi;\??\c:\progra~1\SPEEDB~1\sbbotdi.sys --> c:\progra~1\SPEEDB~1\sbbotdi.sys [?]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11/7/2011 1:14 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11/7/2011 1:14 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [11/7/2011 1:14 16720]
S3 CENIXFMC;Cenix Digicom Digital Voice Recorder Service;c:\windows\system32\drivers\CenixFMC.sys [17/6/2008 16:08 18660]
S3 IPvE;IPvE Adapter Driver;c:\windows\system32\drivers\IPvEx86.sys [22/7/2010 17:58 17184]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/2/2010 13:37 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/3/2010 13:16 753504]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14/7/2006 23:39 642560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
‘計劃任務’ 文件夾 裡的內容
.
2011-09-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2928647282-1049154914-751282057-1006Core.job
- c:\documents and settings\Ken\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-04 11:57]
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2928647282-1049154914-751282057-1006UA.job
- c:\documents and settings\Ken\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-04 11:57]
.
.
------- 而外的掃描 -------
.
uStart Page = www.6700.cn?tn=102760
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www1.ap.dell.com/content/default.aspx?c=hk&l=zh&s=gen
IE: {{548BF84E-9665-47f9-B635-7380F8943E90} - c:\program files\Thunder Network\Thunder\Program\repairimage.htm
TCP: DhcpNameServer = 203.186.94.240 203.186.94.244 203.186.94.241
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} - hxxp://www.tvkoo.com/update/KooPlayer.ocx
FF - ProfilePath - c:\documents and settings\Ken\Application Data\Mozilla\Firefox\Profiles\a4sjxaq1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com.hk/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-ApacheTomcatMonitor7 - c:\program files\Apache Software Foundation\Tomcat 7.0\bin\Tomcat7w.exe
MSConfigStartUp-Malwarebytes' Anti-Malware - c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
MSConfigStartUp-Pando Media Booster - c:\program files\Pando Networks\Media Booster\PMB.exe
AddRemove-KB913433 - c:\windows\system32\MacroMed\Flash\genuinst.exe
AddRemove-MinGW - c:\mingw\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-25 19:02
Windows 5.1.2600 Service Pack 3 NTFS
.
掃描被隱藏的進程 ...
.
掃描被隱藏的啟動組 ...
.
掃描被隱藏的文件 ...
.
掃描完成
被隱藏的檔案: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.iksyssec]
"ImagePath"="\*"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\MenuExt\!*d*Nd]
@="res://c:\\Program Files\\YiSou\\yisou.dll/232"
.
[HKEY_LOCAL_MACHINE\software\Classes\?*PW儳t?*.*M*y*N*S*H*a*n*d*l*e*r*\Clsid]
@="{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC}"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\-NfNM|櫜.*M*y*N*S*H*a*n*d*l*e*r*\Clsid]
@="{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC}"
.
--------------------- 運行進程下的動態鏈接庫 ---------------------
.
- - - - - - - > 'winlogon.exe'(220)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
完成時間: 2011-09-25 19:08:58
ComboFix-quarantined-files.txt 2011-09-25 11:08
.
Pre-Run: 88,988,098,560 位元組可用
Post-Run: 88,964,915,200 位元組可用
.
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 972FA58592FB88B4F14238217D89B389