Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Slow Pc , Malware


  • This topic is locked This topic is locked
17 replies to this topic

#1 BigMama

BigMama

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 23 April 2008 - 08:54 AM

Hi my pc is dead slow especially at startup windows , i got these DLL error windows\system32\ccwld16_080409.dll ,
windows\Downlo~1\e20qm6wr.dll evertime i start windows .Furthermore i got this Rootkit that never go away everyday i scan my pc i got lots of new trojan and adware and i cant get rid of them !!! pls try check for me i tried tweak and run every antispyware program but stl no diff .

This is the Hijack log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:42, on 2008-4-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\Hijack\HijackThis.exe

R3 - URLSearchHook: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B9ACAADD-FC2E-4EC4-8E02-9821735C202C} - (no file)
O2 - BHO: (no name) - {BCBD80C9-6AD7-48ed-8DF1-6963414B3649} - (no file)
O2 - BHO: (no name) - {E1CB9A2C-95B6-42A9-A58E-8F69D5E0ED38} - (no file)
O2 - BHO: (no name) - {EA2FCCA9-F44F-43DD-9724-9339950D103C} - (no file)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {FB3412B6-6D67-4650-B3B4-C2A90191A80F} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [ccwl] rundll32.exe C:\WINDOWS\system32\ccwld16_080409.dll start
O4 - HKLM\..\Policies\Explorer\Run: [e20qm6wr] rundll32 "C:\WINDOWS\Downlo~1\e20qm6wr.dll",start
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &场ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mail.rajahtann.com/iNotes6.cab
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdat...0.10-signed.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153925162750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} (MabinogiWebAvatarRenderer Class) - http://avatar.mabinogi.com:88/renderer/mab....2006.12.27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - http://download.games.yahoo.com/games/web_...outLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{964967CE-6096-4709-B068-60596131E36F}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: clic onfg (cliconfg) - Unknown owner - C:\WINDOWS\system32\cliconfg.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logical Disk Manager Amdinistrative SAlm080124 (lmoboyes) - Unknown owner - c:\root\lm8124\scvhost.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: COM+ Windows System (WinCOM) - Unknown owner - C:\WINDOWS\system32\wincom.exe (file missing)

--
End of file - 10495 bytes

BC AdBot (Login to Remove)

 


m

#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 23 April 2008 - 11:12 AM

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. :thumbsup:

Run Hijackthis again, click scan, and Put a checkmark next to each of the lines listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

O2 - BHO: (no name) - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {B9ACAADD-FC2E-4EC4-8E02-9821735C202C} - (no file)
O2 - BHO: (no name) - {BCBD80C9-6AD7-48ed-8DF1-6963414B3649} - (no file)
O2 - BHO: (no name) - {E1CB9A2C-95B6-42A9-A58E-8F69D5E0ED38} - (no file)
O2 - BHO: (no name) - {EA2FCCA9-F44F-43DD-9724-9339950D103C} - (no file)
O2 - BHO: (no name) - {FB3412B6-6D67-4650-B3B4-C2A90191A80F} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O4 - HKLM\..\Policies\Explorer\Run: [ccwl] rundll32.exe C:\WINDOWS\system32\ccwld16_080409.dll start
O4 - HKLM\..\Policies\Explorer\Run: [e20qm6wr] rundll32 "C:\WINDOWS\Downlo~1\e20qm6wr.dll",start



Reboot your computer.



Please go to this page and scroll down to step 6.
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

Follow the directions there to run DSS and then post those logs back here in your next reply.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 23 April 2008 - 08:44 PM

My windows startup is faster now and the error is gone!!
This is my Deckards Log :


Deckard's System Scanner v20071014.68
Run by HP_Owner on 2008-04-24 09:53:25
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Percentage of Memory in Use: 88% (more than 75%).
Total Physical Memory: 448 MiB (512 MiB recommended).


-- HijackThis (run as HP_Owner.exe) --------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:40, on 2008-4-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Documents and Settings\HP_Owner\My Documents\dss.exe
C:\WINDOWS\system32\conime.exe
C:\Hijack\HP_Owner.exe

R3 - URLSearchHook: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使” FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &全部使” FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &场ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mail.rajahtann.com/iNotes6.cab
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdat...0.10-signed.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153925162750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} (MabinogiWebAvatarRenderer Class) - http://avatar.mabinogi.com:88/renderer/mab....2006.12.27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - http://download.games.yahoo.com/games/web_...outLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{964967CE-6096-4709-B068-60596131E36F}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: clic onfg (cliconfg) - Unknown owner - C:\WINDOWS\system32\cliconfg.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logical Disk Manager Amdinistrative SAlm080124 (lmoboyes) - Unknown owner - c:\root\lm8124\scvhost.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: COM+ Windows System (WinCOM) - Unknown owner - C:\WINDOWS\system32\wincom.exe (file missing)

--
End of file - 9742 bytes

-- Files created between 2008-03-24 and 2008-04-24 -----------------------------

2008-04-24 09:33:48 0 d--h----- C:\$AVG8.VAULT$
2008-04-23 21:35:14 0 dr-h----- C:\Documents and Settings\HP_Owner\Recent
2008-04-23 16:29:27 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-23 16:29:26 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\AVGTOOLBAR
2008-04-23 14:40:54 0 d-------- C:\fsaua.data
2008-04-23 14:02:25 0 d-------- C:\cc
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\SendTo
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Recent
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\PrintHood
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\NetHood
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-04-23 12:35:55 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-04-23 12:35:55 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Real
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Intervideo
2008-04-23 12:35:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-04-23 12:35:54 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-04-23 12:35:54 0 d-------- C:\Documents and Settings\Administrator\Templates
2008-04-23 12:35:54 0 d-------- C:\Documents and Settings\Administrator\Start Menu
2008-04-23 12:35:52 720896 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
2008-04-23 12:20:23 0 d-------- C:\FileAssasin
2008-04-23 12:15:14 0 d-------- C:\Hijack
2008-04-23 12:14:39 0 d-------- C:\Program Files\Trend Micro
2008-04-21 12:39:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 12:39:08 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 09:58:04 0 d-------- C:\Program Files\Netcom3 Cleaner
2008-04-13 23:24:55 0 d-------- C:\Program Files\AVG
2008-04-13 23:24:53 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-07 19:58:41 182784 --a------ C:\WINDOWS\kkk.exe
2008-04-03 22:59:24 0 d-------- C:\Program Files\JavaCore
2008-04-03 22:59:24 0 d-------- C:\Program Files\InetGet2
2008-04-03 22:54:29 85504 --a------ C:\WINDOWS\tpp.exe
2008-04-03 22:54:22 0 d-------- C:\Program Files\nvcoi
2008-04-03 22:49:20 0 d-------- C:\Program Files\CPV
2008-04-03 22:49:19 0 d-------- C:\Program Files\Temporary
2008-04-03 15:30:51 0 d-------- C:\Taikou Risshiden 5
2008-04-03 13:26:48 85504 --a------ C:\WINDOWS\tp.exe
2008-04-02 14:12:25 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-04-01 15:57:57 0 d-------- C:\Program Files\eMule
2008-04-01 14:32:02 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Real
2008-04-01 12:57:07 0 dr------- C:\Documents and Settings\NetworkService\Favorites
2008-04-01 12:37:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Adobe
2008-04-01 12:22:03 5248 --a------ C:\WINDOWS\system32\drivers\d346prt.sys
2008-04-01 12:22:03 156800 --a------ C:\WINDOWS\system32\drivers\d346bus.sys
2008-04-01 12:21:59 0 d-------- C:\Program Files\D-Tools
2008-04-01 12:21:22 509440 --a------ C:\WINDOWS\daemon346.exe
2008-04-01 12:18:14 0 --a------ C:\WINDOWS\system32\dnabeser.dat
2008-04-01 12:18:14 446 --a------ C:\WINDOWS\system32\98609b50d9.dll
2008-04-01 12:17:03 0 d-------- C:\WINDOWS\system32\inf
2008-04-01 12:15:08 0 --a------ C:\WINDOWS\acdsee321.dll
2008-03-31 16:51:01 0 d-------- C:\Program Files\NOBU12PK
2008-03-30 20:26:37 61 --a------ C:\WINDOWS\system32\cdcalcfull.dll
2008-03-30 15:46:31 0 d-------- C:\Program Files\baidu
2008-03-30 15:45:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-03-30 13:22:57 0 d-------- C:\root
2008-03-30 13:14:58 0 d-------- C:\My Downloads
2008-03-29 19:44:28 0 d-------- C:\Documents and Settings\LocalService\Application Data\Real
2008-03-29 19:44:27 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-03-28 23:56:54 22 --a------ C:\WINDOWS\system32\drivers\MS8c7.sys
2008-03-28 23:56:54 0 d-------- C:\Documents and Settings\All Users\Application Data\ou
2008-03-28 23:56:51 0 d-------- C:\WINDOWS\cursor
2008-03-24 04:48:49 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2


-- Find3M Report ---------------------------------------------------------------

2008-04-24 09:53:28 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\SlimBrowser
2008-04-23 22:24:17 0 d-------- C:\Program Files\PPLive
2008-04-23 14:04:04 0 d-------- C:\Program Files\CCleaner
2008-04-21 14:04:17 0 d-------- C:\Program Files\Lavasoft
2008-04-21 12:39:08 0 d-a------ C:\Program Files\Common Files
2008-04-20 09:55:33 77368 --a------ C:\Documents and Settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-04-15 11:22:48 0 d-------- C:\Program Files\PowerArchiver
2008-04-14 00:55:46 0 d-------- C:\Program Files\MSAR3.0_Alpha
2008-04-14 00:49:54 0 d-------- C:\Program Files\Microsoft Works
2008-04-14 00:41:00 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-04-14 00:28:05 0 d-------- C:\Program Files\Globe7
2008-04-14 00:28:05 0 d-------- C:\Program Files\FlashGet
2008-04-14 00:22:37 0 d-------- C:\Program Files\blueserver
2008-04-14 00:22:37 0 d-------- C:\Program Files\BitComet
2008-04-13 23:38:56 0 d-------- C:\Program Files\DivX
2008-04-11 09:20:02 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\Adobe
2008-04-11 09:18:21 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-11 09:11:21 0 d-------- C:\Program Files\SlimBrowser
2008-04-10 20:44:08 0 d-------- C:\Program Files\Common Files\CPUSH
2008-04-10 20:35:16 29 --a------ C:\WINDOWS\system32\-612629104
2008-04-10 20:21:02 2131 --a------ C:\WINDOWS\system32\m7ci0Tk.dll
2008-04-10 13:56:21 0 d-------- C:\Program Files\Movie Maker
2008-04-07 12:05:02 26 --a------ C:\WINDOWS\system32\891a1d68
2008-04-06 01:30:15 0 d-------- C:\Program Files\Warcraft III
2008-04-04 01:35:31 95 --a------ C:\WINDOWS\9a1a1d68
2008-04-04 01:35:31 87 --a------ C:\WINDOWS\-1022629104
2008-04-03 13:22:35 86 --a------ C:\WINDOWS\-1012629104
2008-03-30 16:50:42 0 d-------- C:\Program Files\Koei
2008-03-26 18:28:21 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-23 22:07:07 0 d-------- C:\Program Files\Windows Live
2008-03-23 22:05:44 0 d-------- C:\Program Files\MSN Messenger
2008-03-23 22:03:06 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-04 15:27:45 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-03-03 16:49:43 0 d-------- C:\Program Files\Ocean Technologies & Media
2008-03-03 16:49:20 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\InstallShield
2008-02-24 10:10:43 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\Mozilla
2008-02-24 04:37:57 0 d-------- C:\Program Files\Real
2008-02-24 04:10:50 203776 --a------ C:\WINDOWS\system32\clrviddc.dll <Not Verified; Iterated Systems, Inc.; ClearVideo Decoder DLL>
2008-02-24 04:05:41 0 d-------- C:\Program Files\Common Files\xing shared
2008-02-24 04:04:49 0 d-------- C:\Program Files\Common Files\Real
2008-02-17 11:56:43 22759 --a------ C:\WINDOWS\War3Unin.dat
2008-02-17 11:31:08 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-02-17 11:31:08 126976 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-02-10 00:01:39 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-23 16:29 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-24 04:03]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 22:43]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-23 16:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-10-23 4:33:37]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-143991]
C:\WINDOWS\system32\-143991.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-867254]
C:\WINDOWS\system32\-867254.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hxgame-update]
C:\Program Files\酵砑”牁炵蹈\酵砑”牁5.0\Statistics\hxgame-update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
PTBTMACJZIGFH HWQRLDYQLLRX
NWQGVCZ IXKBXE
FQGGUNMZQP OZJUV

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
DCOMManager16


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53fdaf04-2fcb-11db-a695-0016ec362bf4}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe Bha.dll.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54be6a1c-0762-11dd-9458-0016ec362bf4}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ece6e89-2974-11db-a684-0016ec362bf4}]
Auto\command- K:\RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8278570e-31e5-11dc-aa4d-0016ec362bf4}]
Auto\command- F:\RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92a0a000-1c60-11db-a65f-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e41057a-8001-11dc-aad6-0016ec362bf4}]
Auto\command- F:\RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2cbe7e2-94cf-11db-a7ff-0016ec362bf4}]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4ca1bb0-fd14-11db-a9c6-0016ec362bf4}]
AutoRun\command- Iexplores.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcba675e-e868-11dc-ac17-0016ec362bf4}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e




-- End of Deckard's System Scanner: finished at 2008-04-24 09:54:05 ------------

Edited by BigMama, 23 April 2008 - 08:59 PM.


#4 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 23 April 2008 - 08:47 PM

This is the latest Hijack Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:57, on 2008-4-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\Hijack\HijackThis.exe

R3 - URLSearchHook: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &场ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} (MMCPlayer Class) - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://mail.rajahtann.com/iNotes6.cab
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdat...0.10-signed.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153925162750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} (MabinogiWebAvatarRenderer Class) - http://avatar.mabinogi.com:88/renderer/mab....2006.12.27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - http://download.games.yahoo.com/games/web_...outLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{964967CE-6096-4709-B068-60596131E36F}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: clic onfg (cliconfg) - Unknown owner - C:\WINDOWS\system32\cliconfg.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logical Disk Manager Amdinistrative SAlm080124 (lmoboyes) - Unknown owner - c:\root\lm8124\scvhost.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: COM+ Windows System (WinCOM) - Unknown owner - C:\WINDOWS\system32\wincom.exe (file missing)

--
End of file - 9730 bytes

Edited by BigMama, 23 April 2008 - 08:57 PM.


#5 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 24 April 2008 - 08:42 AM

You've still got some trouble showing up.

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

Folder::
C:\Program Files\nvcoi
C:\Program Files\CPV
C:\Program Files\Temporary

File::
K:\RavMonE.exe
F:\RavMonE.exe
C:\WINDOWS\system32\-143991.exe
C:\WINDOWS\system32\-867254.exe
C:\WINDOWS\kkk.exe
C:\WINDOWS\tpp.exe
C:\WINDOWS\tp.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53fdaf04-2fcb-11db-a695-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54be6a1c-0762-11dd-9458-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ece6e89-2974-11db-a684-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8278570e-31e5-11dc-aa4d-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92a0a000-1c60-11db-a65f-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e41057a-8001-11dc-aad6-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2cbe7e2-94cf-11db-a7ff-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4ca1bb0-fd14-11db-a9c6-0016ec362bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcba675e-e868-11dc-ac17-0016ec362bf4}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-143991]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-867254]

Dirlook::
C:\WINDOWS\system32\-612629104
C:\WINDOWS\system32\891a1d68
C:\WINDOWS\9a1a1d68
C:\WINDOWS\-1022629104
C:\WINDOWS\-1012629104
C:\Taikou Risshiden 5
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.


===================



Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#6 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 03:26 AM

this is the Combo fix log :

ComboFix 08-04-24.1 - HP_Owner 2008-04-26 11:41:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.1.1033.18.105 [GMT 8:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\kkk.exe
C:\WINDOWS\system32\-143991.exe
C:\WINDOWS\system32\-867254.exe
C:\WINDOWS\tp.exe
C:\WINDOWS\tpp.exe
F:\RavMonE.exe
K:\RavMonE.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\clubmember
C:\Documents and Settings\All Users\Application Data\clubmember\Cast\bfrw_3030.inf
C:\Documents and Settings\All Users\Application Data\clubmember\Cast\bfyswj.inf
C:\Documents and Settings\All Users\Application Data\clubmember\Cast\dxgdgjc.inf
C:\Documents and Settings\All Users\Application Data\clubmember\Cast\yxssj_3030.inf
C:\Documents and Settings\All Users\Application Data\microsoft\iehelper
C:\Documents and Settings\All Users\Application Data\t
C:\Documents and Settings\All Users\Application Data\t\a1677.dat
C:\Documents and Settings\All Users\Application Data\t\b1677.dat
C:\Documents and Settings\All Users\Application Data\t\k1677.dat
C:\Documents and Settings\All Users\Application Data\t\p16777.dat
C:\Documents and Settings\All Users\Application Data\t\r1677.dat
C:\Documents and Settings\HP_Owner\ravmonlog
C:\Program Files\baidu
C:\Program Files\Common Files\cpush
C:\Program Files\Common Files\cpush\Uninst.exe
C:\Program Files\CPV
C:\Program Files\inetget2
C:\Program Files\JavaCore
C:\Program Files\nvcoi
C:\Program Files\nvcoi\mst.stt
C:\Program Files\Temporary
C:\Program Files\yahoo!\assist~1
C:\WINDOWS\acdsee321.dll
C:\WINDOWS\cursor
C:\WINDOWS\cursor\MSd5.cur
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\kkk.exe
C:\WINDOWS\qmdispatch.dll
C:\windows\system32\3223csa.okc
C:\WINDOWS\system32\98609b50d9.dll
C:\WINDOWS\system32\cdcalcfull.dll
C:\WINDOWS\system32\cflInfo.nt
C:\WINDOWS\system32\d3d1caps.srg
C:\WINDOWS\system32\dnabeser.dat
C:\WINDOWS\system32\drivers\MS8c7.sys
C:\WINDOWS\system32\lylk.dat
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\system32\ms_sys.dat
C:\WINDOWS\system32\mscpx32r.det
C:\WINDOWS\system32\mshtmll.dll
C:\WINDOWS\system32\mstacim.sig
C:\WINDOWS\system32\yhbo.dll
C:\WINDOWS\Tasks.\win_update_program.job
C:\WINDOWS\tp.exe
C:\WINDOWS\tpp.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ACPIDISK
-------\Legacy_CNSMINKP
-------\Legacy_FSPROT
-------\Legacy_MOPROT
-------\Legacy_MS_2FAX
-------\Legacy_P4P_SERVICE
-------\Service_CnsMinKP


((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.

2008-04-25 01:40 . 2008-04-25 01:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-24 10:24 . 2008-04-24 10:55 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-24 09:33 . 2008-04-24 10:17 <DIR> d--h----- C:\$AVG8.VAULT$
2008-04-24 09:30 . 2008-04-24 09:30 <DIR> d-------- C:\Deckard
2008-04-23 16:29 . 2008-04-26 02:20 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-23 16:29 . 2008-04-23 16:29 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\AVGTOOLBAR
2008-04-23 16:29 . 2008-04-23 16:29 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-23 16:29 . 2008-04-23 16:29 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-23 16:29 . 2008-04-23 16:29 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-04-23 16:29 . 2008-04-23 16:29 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-23 14:40 . 2008-04-23 14:40 <DIR> d-------- C:\fsaua.data
2008-04-23 14:02 . 2008-04-23 14:03 <DIR> d-------- C:\cc
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intervideo
2008-04-23 12:35 . 2008-04-23 16:22 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-23 12:35 . 2008-04-26 11:41 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-23 12:20 . 2008-04-23 12:20 <DIR> d-------- C:\FileAssasin
2008-04-23 12:15 . 2008-04-26 11:14 <DIR> d-------- C:\Hijack
2008-04-23 12:14 . 2008-04-23 12:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-21 12:39 . 2008-04-21 12:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 12:39 . 2008-04-21 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 09:58 . 2008-04-21 12:38 <DIR> d-------- C:\Program Files\Netcom3 Cleaner
2008-04-20 15:59 . 2008-04-20 15:59 244 --ah----- C:\sqmnoopt01.sqm
2008-04-20 15:59 . 2008-04-20 15:59 232 --ah----- C:\sqmdata01.sqm
2008-04-20 10:00 . 2008-04-20 10:00 244 --ah----- C:\sqmnoopt00.sqm
2008-04-20 10:00 . 2008-04-20 10:00 232 --ah----- C:\sqmdata00.sqm
2008-04-13 23:24 . 2008-04-13 23:24 <DIR> d-------- C:\Program Files\AVG
2008-04-13 23:24 . 2008-04-23 16:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-13 02:24 . 2008-04-13 02:24 1,073,741,824 --a------ C:\pfsvoddata.bbv
2008-04-10 18:15 . 2008-04-10 20:47 17,267 --a------ C:\WINDOWS\system32\ccwl32.ini.tmp
2008-04-07 11:47 . 2008-04-07 11:51 159,744 --a------ C:\WINDOWS\AF.tmp
2008-04-03 15:37 . 2008-04-07 14:54 336 --a------ C:\tesvlog.lvr
2008-04-03 15:30 . 2008-04-03 15:33 <DIR> d-------- C:\Taikou Risshiden 5
2008-04-02 22:33 . 2008-04-10 20:36 250 --a------ C:\WINDOWS\system32\ccwl32.ini
2008-04-02 22:32 . 2008-04-10 18:13 396 --a------ C:\WINDOWS\ccwl16.ini
2008-04-01 15:57 . 2008-04-14 00:28 <DIR> d-------- C:\Program Files\eMule
2008-04-01 12:22 . 2004-03-12 22:41 156,800 --a------ C:\WINDOWS\system32\drivers\d346bus.sys
2008-04-01 12:22 . 2004-03-12 22:41 5,248 --a------ C:\WINDOWS\system32\drivers\d346prt.sys
2008-04-01 12:21 . 2008-04-01 12:22 <DIR> d-------- C:\Program Files\D-Tools
2008-04-01 12:21 . 2004-05-03 02:07 509,440 --a------ C:\WINDOWS\daemon346.exe
2008-04-01 12:17 . 2008-04-14 01:26 <DIR> d-------- C:\WINDOWS\system32\inf
2008-03-31 19:13 . 2008-04-13 00:02 236 --a------ C:\WINDOWS\system32\resiifers.ini
2008-03-31 16:51 . 2008-04-14 00:56 <DIR> d-------- C:\Program Files\NOBU12PK
2008-03-30 15:45 . 2008-04-02 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-03-30 15:32 . 2008-03-30 15:37 26 --a------ C:\system_32.ini
2008-03-30 13:22 . 2008-03-30 13:22 <DIR> d-------- C:\root
2008-03-30 13:14 . 2008-03-30 13:23 <DIR> d-------- C:\My Downloads
2008-03-28 23:56 . 2008-04-02 11:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ou
2008-03-27 14:31 . 2008-03-27 14:31 0 --a------ C:\WINDOWS\65.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-26 03:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-26 03:41 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SlimBrowser
2008-04-26 03:23 --------- d-----w C:\Program Files\PPLive
2008-04-25 17:12 --------- d-----w C:\Program Files\Warcraft III
2008-04-25 11:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-25 04:10 --------- d-----w C:\Program Files\PowerArchiver
2008-04-23 06:04 --------- d-----w C:\Program Files\CCleaner
2008-04-21 06:04 --------- d-----w C:\Program Files\Lavasoft
2008-04-20 01:55 77,368 ----a-w C:\Documents and Settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 16:55 --------- d-----w C:\Program Files\MSAR3.0_Alpha
2008-04-13 16:49 --------- d-----w C:\Program Files\Microsoft Works
2008-04-13 16:41 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-13 16:28 --------- d-----w C:\Program Files\Globe7
2008-04-13 16:28 --------- d-----w C:\Program Files\FlashGet
2008-04-13 16:22 --------- d-----w C:\Program Files\blueserver
2008-04-13 16:22 --------- d-----w C:\Program Files\BitComet
2008-04-13 15:38 --------- d-----w C:\Program Files\DivX
2008-04-11 01:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-11 01:11 --------- d-----w C:\Program Files\SlimBrowser
2008-03-30 08:50 --------- d-----w C:\Program Files\Koei
2008-03-30 07:31 3,270 ----a-w C:\WINDOWS\system32\drivers\GUPLPSCX.DLL
2008-03-26 10:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-23 20:48 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-23 14:07 --------- d-----w C:\Program Files\Windows Live
2008-03-23 14:05 --------- d-----w C:\Program Files\MSN Messenger
2008-03-23 14:03 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 13:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 08:49 --------- d-----w C:\Program Files\Ocean Technologies & Media
2008-03-03 08:49 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\InstallShield
2008-02-17 03:31 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-02-17 03:31 126,976 ----a-w C:\WINDOWS\War3Unin.exe
2006-08-01 03:26 0 ----a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2006-06-13 05:47 368,702 ----a-w C:\Program Files\Storm.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Taikou Risshiden 5 ----

2008-04-03 15:35 47906 --a------ C:\Taikou Risshiden 5\INSTALL.LOG
2006-05-19 10:36 4342668 --a------ C:\Taikou Risshiden 5\Taikou5.exe
2004-07-28 14:17 28224000 --a------ C:\Taikou Risshiden 5\cdkey.iso
2004-07-20 20:51 41472 --a------ C:\Taikou Risshiden 5\DrvMgt.dll
2004-07-20 20:51 308278 --a------ C:\Taikou Risshiden 5\00000000.256
2004-07-20 20:51 153718 --a------ C:\Taikou Risshiden 5\00000000.016
2004-07-20 20:51 12400 --a------ C:\Taikou Risshiden 5\Secdrv.sys
2004-07-20 18:17 952 --a------ C:\Taikou Risshiden 5\Event_tw\Epf20300.ts5
2004-07-20 18:17 9504 --a------ C:\Taikou Risshiden 5\Event_tw\Epf11700.ts5
2004-07-20 18:17 950 --a------ C:\Taikou Risshiden 5\Event_tw\Ef51fa00.te5
2004-07-20 18:17 942 --a------ C:\Taikou Risshiden 5\Event_tw\Epf25900.te5
2004-07-20 18:17 940 --a------ C:\Taikou Risshiden 5\Event_tw\Eff06d00.ts5
2004-07-20 18:17 9308 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01700.ts5
2004-07-20 18:17 910 --a------ C:\Taikou Risshiden 5\Event_tw\Enf00600.te5
2004-07-20 18:17 8734 --a------ C:\Taikou Risshiden 5\Event_tw\Ep111700.te5
2004-07-20 18:17 8556 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0a400.ts5
2004-07-20 18:17 850 --a------ C:\Taikou Risshiden 5\Event_tw\Epf04800.te5
2004-07-20 18:17 8436 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01d00.ts5
2004-07-20 18:17 832 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07c00.ts5
2004-07-20 18:17 816632 --a------ C:\Taikou Risshiden 5\Event_tw\Ecf00000.ts5
2004-07-20 18:17 8128 --a------ C:\Taikou Risshiden 5\Event_tw\Ef51fa00.ts5
2004-07-20 18:17 806 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02e00.te5
2004-07-20 18:17 7756 --a------ C:\Taikou Risshiden 5\Event_tw\Epf12800.ts5
2004-07-20 18:17 774 --a------ C:\Taikou Risshiden 5\Event_tw\Eff28700.te5
2004-07-20 18:17 774 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14700.te5
2004-07-20 18:17 762 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01100.te5
2004-07-20 18:17 758 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02d00.te5
2004-07-20 18:17 738 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fb00.te5
2004-07-20 18:17 7196 --a------ C:\Taikou Risshiden 5\Event_tw\Eff31100.ts5
2004-07-20 18:17 716 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07500.ts5
2004-07-20 18:17 7024 --a------ C:\Taikou Risshiden 5\Event_tw\Epf24900.ts5
2004-07-20 18:17 67768 --a------ C:\Taikou Risshiden 5\Event_tw\Eff20600.ts5
2004-07-20 18:17 6646 --a------ C:\Taikou Risshiden 5\Event_tw\Eff20500.te5
2004-07-20 18:17 6620 --a------ C:\Taikou Risshiden 5\Event_tw\Epf25900.ts5
2004-07-20 18:17 6616 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01f00.ts5
2004-07-20 18:17 642 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01f00.te5
2004-07-20 18:17 638 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fa00.te5
2004-07-20 18:17 628 --a------ C:\Taikou Risshiden 5\Event_tw\Ec500000.ts5
2004-07-20 18:17 62136 --a------ C:\Taikou Risshiden 5\Event_tw\Epf20500.ts5
2004-07-20 18:17 6152 --a------ C:\Taikou Risshiden 5\Event_tw\Eff08c00.ts5
2004-07-20 18:17 6110 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1c100.te5
2004-07-20 18:17 610 --a------ C:\Taikou Risshiden 5\Event_tw\Eff00e00.te5
2004-07-20 18:17 606 --a------ C:\Taikou Risshiden 5\Event_tw\Ep122500.te5
2004-07-20 18:17 600 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0e900.ts5
2004-07-20 18:17 59256 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07700.ts5
2004-07-20 18:17 5878 --a------ C:\Taikou Risshiden 5\Event_tw\Epf20500.te5
2004-07-20 18:17 582 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00300.te5
2004-07-20 18:17 582 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0be00.te5
2004-07-20 18:17 5778 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00400.te5
2004-07-20 18:17 570 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1d000.te5
2004-07-20 18:17 5656 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c100.ts5
2004-07-20 18:17 5652 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0bf00.ts5
2004-07-20 18:17 5512 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02300.ts5
2004-07-20 18:17 5512 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02000.ts5
2004-07-20 18:17 5506 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07700.te5
2004-07-20 18:17 54132 --a------ C:\Taikou Risshiden 5\Event_tw\Eff16700.ts5
2004-07-20 18:17 53248 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1c100.ts5
2004-07-20 18:17 5060 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02e00.ts5
2004-07-20 18:17 506 --a------ C:\Taikou Risshiden 5\Event_tw\Epf07700.te5
2004-07-20 18:17 506 --a------ C:\Taikou Risshiden 5\Event_tw\Eff06d00.te5
2004-07-20 18:17 474 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2fc00.te5
2004-07-20 18:17 470 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18600.te5
2004-07-20 18:17 46544 --a------ C:\Taikou Risshiden 5\Event_tw\Ep111700.ts5
2004-07-20 18:17 4606 --a------ C:\Taikou Risshiden 5\Event_tw\Eff20600.te5
2004-07-20 18:17 454 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0d800.te5
2004-07-20 18:17 446 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0ae00.te5
2004-07-20 18:17 44532 --a------ C:\Taikou Risshiden 5\Event_tw\Eff20500.ts5
2004-07-20 18:17 4452 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01100.ts5
2004-07-20 18:17 44212 --a------ C:\Taikou Risshiden 5\Event_tw\Epf00e00.ts5
2004-07-20 18:17 4408 --a------ C:\Taikou Risshiden 5\Event_tw\Eff18a00.ts5
2004-07-20 18:17 438 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1ca00.te5
2004-07-20 18:17 418 --a------ C:\Taikou Risshiden 5\Event_tw\Epf29100.te5
2004-07-20 18:17 418 --a------ C:\Taikou Risshiden 5\Event_tw\Ec500000.te5
2004-07-20 18:17 406 --a------ C:\Taikou Risshiden 5\Event_tw\Epf20300.te5
2004-07-20 18:17 3956 --a------ C:\Taikou Risshiden 5\Event_tw\Ef520600.ts5
2004-07-20 18:17 394 --a------ C:\Taikou Risshiden 5\Event_tw\Eff29300.te5
2004-07-20 18:17 392 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0cb00.ts5
2004-07-20 18:17 3916 --a------ C:\Taikou Risshiden 5\Event_tw\Epf04800.ts5
2004-07-20 18:17 3910 --a------ C:\Taikou Risshiden 5\Event_tw\Eff16700.te5
2004-07-20 18:17 390 --a------ C:\Taikou Risshiden 5\Event_tw\Epf16500.te5
2004-07-20 18:17 390 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0f300.te5
2004-07-20 18:17 386 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c800.te5
2004-07-20 18:17 382 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c000.te5
2004-07-20 18:17 38096 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1bf00.ts5
2004-07-20 18:17 37126 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0c300.te5
2004-07-20 18:17 3710 --a------ C:\Taikou Risshiden 5\Event_tw\Ep516900.te5
2004-07-20 18:17 370 --a------ C:\Taikou Risshiden 5\Event_tw\Epf19f00.te5
2004-07-20 18:17 370 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0e900.te5
2004-07-20 18:17 3662 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1d200.te5
2004-07-20 18:17 366 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c700.te5
2004-07-20 18:17 3658 --a------ C:\Taikou Risshiden 5\Event_tw\Epf11700.te5
2004-07-20 18:17 358 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2f700.te5
2004-07-20 18:17 358 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0a400.te5
2004-07-20 18:17 354 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1e800.te5
2004-07-20 18:17 354 --a------ C:\Taikou Risshiden 5\Event_tw\Epf02900.te5
2004-07-20 18:17 346 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0f000.te5
2004-07-20 18:17 346 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c800.te5
2004-07-20 18:17 346 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07c00.te5
2004-07-20 18:17 346 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07500.te5
2004-07-20 18:17 34504 --a------ C:\Taikou Risshiden 5\Event_tw\Eff18b00.ts5
2004-07-20 18:17 342 --a------ C:\Taikou Risshiden 5\Event_tw\Epf27e00.te5
2004-07-20 18:17 342 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18b00.te5
2004-07-20 18:17 342 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18a00.te5
2004-07-20 18:17 342 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0bd00.te5
2004-07-20 18:17 342 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0a700.te5
2004-07-20 18:17 3410 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1bf00.te5
2004-07-20 18:17 3392 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fa00.ts5
2004-07-20 18:17 3374 --a------ C:\Taikou Risshiden 5\Event_tw\Epf00e00.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf15000.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf14a00.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0cb00.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf06400.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf01900.te5
2004-07-20 18:17 334 --a------ C:\Taikou Risshiden 5\Event_tw\Epf00b00.te5
2004-07-20 18:17 33324 --a------ C:\Taikou Risshiden 5\Event_tw\Epf16900.ts5
2004-07-20 18:17 33056 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2d100.ts5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2e400.te5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2c200.te5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2c100.te5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2bd00.te5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf27c00.te5
2004-07-20 18:17 330 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1aa00.te5
2004-07-20 18:17 3282 --a------ C:\Taikou Risshiden 5\Event_tw\Epf12400.te5
2004-07-20 18:17 328 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0d800.ts5
2004-07-20 18:17 3230 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2f400.te5
2004-07-20 18:17 3218 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fc00.te5
2004-07-20 18:17 31728 --a------ C:\Taikou Risshiden 5\Event_tw\Ep516900.ts5
2004-07-20 18:17 3162 --a------ C:\Taikou Risshiden 5\Event_tw\Epf04b00.te5
2004-07-20 18:17 3134 --a------ C:\Taikou Risshiden 5\Event_tw\Ep12e400.te5
2004-07-20 18:17 3108 --a------ C:\Taikou Risshiden 5\Event_tw\Eff28700.ts5
2004-07-20 18:17 31048 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0a500.ts5
2004-07-20 18:17 3092 --a------ C:\Taikou Risshiden 5\Event_tw\Enf00600.ts5
2004-07-20 18:17 3086 --a------ C:\Taikou Risshiden 5\Event_tw\Eff18b00.te5
2004-07-20 18:17 306 --a------ C:\Taikou Risshiden 5\Event_tw\Ef520600.te5
2004-07-20 18:17 3058 --a------ C:\Taikou Risshiden 5\Event_tw\Epf16900.te5
2004-07-20 18:17 3010 --a------ C:\Taikou Risshiden 5\Event_tw\Epf17b00.te5
2004-07-20 18:17 300 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c800.ts5
2004-07-20 18:17 300 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0a700.ts5
2004-07-20 18:17 29398 --a------ C:\Taikou Risshiden 5\Event_tw\Ep124b00.te5
2004-07-20 18:17 292424 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0c300.ts5
2004-07-20 18:17 2898 --a------ C:\Taikou Risshiden 5\Event_tw\Ep12f400.te5
2004-07-20 18:17 2882 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2d100.te5
2004-07-20 18:17 28784 --a------ C:\Taikou Risshiden 5\Event_tw\Eff13b00.ts5
2004-07-20 18:17 2858 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14200.te5
2004-07-20 18:17 284 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0bd00.ts5
2004-07-20 18:17 2814 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07400.te5
2004-07-20 18:17 27776 --a------ C:\Taikou Risshiden 5\Event_tw\Ep515700.ts5
2004-07-20 18:17 2772 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0be00.ts5
2004-07-20 18:17 2758 --a------ C:\Taikou Risshiden 5\Event_tw\Eff13800.te5
2004-07-20 18:17 2750 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1e400.te5
2004-07-20 18:17 2750 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1ca00.te5
2004-07-20 18:17 2750 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0a500.te5
2004-07-20 18:17 2750 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07d00.te5
2004-07-20 18:17 2750 --a------ C:\Taikou Risshiden 5\Event_tw\Eff03600.te5
2004-07-20 18:17 2738 --a------ C:\Taikou Risshiden 5\Event_tw\Eff27c00.te5
2004-07-20 18:17 2730 --a------ C:\Taikou Risshiden 5\Event_tw\Eff12500.te5
2004-07-20 18:17 272 --a------ C:\Taikou Risshiden 5\Event_tw\Epf19f00.ts5
2004-07-20 18:17 27032 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1d200.ts5
2004-07-20 18:17 2686 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00800.te5
2004-07-20 18:17 26488 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00400.ts5
2004-07-20 18:17 264 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c700.ts5
2004-07-20 18:17 26344 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07400.ts5
2004-07-20 18:17 2614 --a------ C:\Taikou Risshiden 5\Event_tw\Eff11600.te5
2004-07-20 18:17 2562 --a------ C:\Taikou Risshiden 5\Event_tw\Epf24900.te5
2004-07-20 18:17 25504 --a------ C:\Taikou Risshiden 5\Event_tw\Epf22500.ts5
2004-07-20 18:17 2542 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2f800.te5
2004-07-20 18:17 2534 --a------ C:\Taikou Risshiden 5\Event_tw\Eff26700.te5
2004-07-20 18:17 2534 --a------ C:\Taikou Risshiden 5\Event_tw\Eff04300.te5
2004-07-20 18:17 2534 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01a00.te5
2004-07-20 18:17 2526 --a------ C:\Taikou Risshiden 5\Event_tw\Ep515700.te5
2004-07-20 18:17 2502 --a------ C:\Taikou Risshiden 5\Event_tw\Eff21800.te5
2004-07-20 18:17 24828 --a------ C:\Taikou Risshiden 5\Event_tw\Epf04b00.ts5
2004-07-20 18:17 248 --a------ C:\Taikou Risshiden 5\Event_tw\Epf16500.ts5
2004-07-20 18:17 2446 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1f300.te5
2004-07-20 18:17 244 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1aa00.ts5
2004-07-20 18:17 24200 --a------ C:\Taikou Risshiden 5\Event_tw\Epf17b00.ts5
2004-07-20 18:17 2406 --a------ C:\Taikou Risshiden 5\Event_tw\Eff17b00.te5
2004-07-20 18:17 240 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2e400.ts5
2004-07-20 18:17 23764 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fc00.ts5
2004-07-20 18:17 23624 --a------ C:\Taikou Risshiden 5\Event_tw\Eff06e00.ts5
2004-07-20 18:17 23620 --a------ C:\Taikou Risshiden 5\Event_tw\Ep12f400.ts5
2004-07-20 18:17 23400 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1ca00.ts5
2004-07-20 18:17 23364 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1e400.ts5
2004-07-20 18:17 23320 --a------ C:\Taikou Risshiden 5\Event_tw\Eff03600.ts5
2004-07-20 18:17 23268 --a------ C:\Taikou Risshiden 5\Event_tw\Eff13800.ts5
2004-07-20 18:17 23240 --a------ C:\Taikou Risshiden 5\Event_tw\Eff07d00.ts5
2004-07-20 18:17 2246 --a------ C:\Taikou Risshiden 5\Event_tw\Eff27600.te5
2004-07-20 18:17 224 --a------ C:\Taikou Risshiden 5\Event_tw\Epf27e00.ts5
2004-07-20 18:17 22328 --a------ C:\Taikou Risshiden 5\Event_tw\Eff27c00.ts5
2004-07-20 18:17 2218 --a------ C:\Taikou Risshiden 5\Event_tw\Eff13b00.te5
2004-07-20 18:17 216 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18600.ts5
2004-07-20 18:17 216 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0f300.ts5
2004-07-20 18:17 21440 --a------ C:\Taikou Risshiden 5\Event_tw\Eff21800.ts5
2004-07-20 18:17 2130 --a------ C:\Taikou Risshiden 5\Event_tw\Epf22500.te5
2004-07-20 18:17 212 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1e800.ts5
2004-07-20 18:17 2114 --a------ C:\Taikou Risshiden 5\Event_tw\Eff06e00.te5
2004-07-20 18:17 208 --a------ C:\Taikou Risshiden 5\Event_tw\Epf06400.ts5
2004-07-20 18:17 2074 --a------ C:\Taikou Risshiden 5\Event_tw\Ep52bc00.te5
2004-07-20 18:17 2066 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c300.te5
2004-07-20 18:17 2066 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0e600.te5
2004-07-20 18:17 20416 --a------ C:\Taikou Risshiden 5\Event_tw\Ep12e400.ts5
2004-07-20 18:17 20032 --a------ C:\Taikou Risshiden 5\Event_tw\Eff12500.ts5
2004-07-20 18:17 19872 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2d200.ts5
2004-07-20 18:17 1978 --a------ C:\Taikou Risshiden 5\Event_tw\Epf29300.te5
2004-07-20 18:17 1974 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2d200.te5
2004-07-20 18:17 196 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2f700.ts5
2004-07-20 18:17 196 --a------ C:\Taikou Risshiden 5\Event_tw\Epf14a00.ts5
2004-07-20 18:17 196 --a------ C:\Taikou Risshiden 5\Event_tw\Epf00b00.ts5
2004-07-20 18:17 19556 --a------ C:\Taikou Risshiden 5\Event_tw\Eff11600.ts5
2004-07-20 18:17 192 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c800.ts5
2004-07-20 18:17 19188 --a------ C:\Taikou Risshiden 5\Event_tw\Eff2f800.ts5
2004-07-20 18:17 18940 --a------ C:\Taikou Risshiden 5\Event_tw\Ep52bc00.ts5
2004-07-20 18:17 18852 --a------ C:\Taikou Risshiden 5\Event_tw\Eff26700.ts5
2004-07-20 18:17 18840 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14400.ts5
2004-07-20 18:17 18728 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01a00.ts5
2004-07-20 18:17 18720 --a------ C:\Taikou Risshiden 5\Event_tw\Ep120500.ts5
2004-07-20 18:17 18700 --a------ C:\Taikou Risshiden 5\Event_tw\Eff04300.ts5
2004-07-20 18:17 1862 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c700.te5
2004-07-20 18:17 18508 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1f300.ts5
2004-07-20 18:17 184 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0a400.ts5
2004-07-20 18:17 180 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18b00.ts5
2004-07-20 18:17 180 --a------ C:\Taikou Risshiden 5\Event_tw\Epf18a00.ts5
2004-07-20 18:17 1794 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01000.te5
2004-07-20 18:17 1786 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c100.te5
2004-07-20 18:17 1786 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0bf00.te5
2004-07-20 18:17 1780 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1ca00.ts5
2004-07-20 18:17 176428 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1fa00.ts5
2004-07-20 18:17 1762 --a------ C:\Taikou Risshiden 5\Event_tw\Eff09800.te5
2004-07-20 18:17 1728 --a------ C:\Taikou Risshiden 5\Event_tw\Ep122500.ts5
2004-07-20 18:17 172 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2bd00.ts5
2004-07-20 18:17 172 --a------ C:\Taikou Risshiden 5\Event_tw\Epf27c00.ts5
2004-07-20 18:17 172 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c000.ts5
2004-07-20 18:17 17144 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2f400.ts5
2004-07-20 18:17 17124 --a------ C:\Taikou Risshiden 5\Event_tw\Epf29300.ts5
2004-07-20 18:17 1690 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0a400.te5
2004-07-20 18:17 168 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0f000.ts5
2004-07-20 18:17 165820 --a------ C:\Taikou Risshiden 5\Event_tw\Ep124b00.ts5
2004-07-20 18:17 164 --a------ C:\Taikou Risshiden 5\Event_tw\Epf02900.ts5
2004-07-20 18:17 16308 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14200.ts5
2004-07-20 18:17 16200 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c300.ts5
2004-07-20 18:17 1620 --a------ C:\Taikou Risshiden 5\Event_tw\Epf29100.ts5
2004-07-20 18:17 16146 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1fa00.te5
2004-07-20 18:17 160 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0ae00.ts5
2004-07-20 18:17 1580 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2fc00.ts5
2004-07-20 18:17 1568 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00300.ts5
2004-07-20 18:17 156 --a------ C:\Taikou Risshiden 5\Event_tw\Epf15000.ts5
2004-07-20 18:17 152 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2c200.ts5
2004-07-20 18:17 152 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2c100.ts5
2004-07-20 18:17 15040 --a------ C:\Taikou Risshiden 5\Event_tw\Epf12400.ts5
2004-07-20 18:17 1470 --a------ C:\Taikou Risshiden 5\Event_tw\Ep120500.te5
2004-07-20 18:17 14520 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c200.ts5
2004-07-20 18:17 1406 --a------ C:\Taikou Risshiden 5\Event_tw\Eff18a00.te5
2004-07-20 18:17 140 --a------ C:\Taikou Risshiden 5\Event_tw\Epf01900.ts5
2004-07-20 18:17 13988 --a------ C:\Taikou Risshiden 5\Event_tw\Eff0e600.ts5
2004-07-20 18:17 13924 --a------ C:\Taikou Risshiden 5\Event_tw\Eff27600.ts5
2004-07-20 18:17 1350 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02300.te5
2004-07-20 18:17 1350 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02000.te5
2004-07-20 18:17 1338 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01d00.te5
2004-07-20 18:17 1318 --a------ C:\Taikou Risshiden 5\Event_tw\Epf0c200.te5
2004-07-20 18:17 1308 --a------ C:\Taikou Risshiden 5\Event_tw\Epf07700.ts5
2004-07-20 18:17 12812 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1c700.ts5
2004-07-20 18:17 12604 --a------ C:\Taikou Risshiden 5\Event_tw\Eff17b00.ts5
2004-07-20 18:17 12388 --a------ C:\Taikou Risshiden 5\Event_tw\Eff00e00.ts5
2004-07-20 18:17 1228 --a------ C:\Taikou Risshiden 5\Event_tw\Eff1d000.ts5
2004-07-20 18:17 11980 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01000.ts5
2004-07-20 18:17 11884 --a------ C:\Taikou Risshiden 5\Event_tw\Epf1fb00.ts5
2004-07-20 18:17 1176 --a------ C:\Taikou Risshiden 5\Event_tw\Eff02d00.ts5
2004-07-20 18:17 1170 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2e000.te5
2004-07-20 18:17 11680 --a------ C:\Taikou Risshiden 5\Event_tw\Ekf00800.ts5
2004-07-20 18:17 1150 --a------ C:\Taikou Risshiden 5\Event_tw\Eff31100.te5
2004-07-20 18:17 1146 --a------ C:\Taikou Risshiden 5\Event_tw\Eff01700.te5
2004-07-20 18:17 1100 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14700.ts5
2004-07-20 18:17 109138 --a------ C:\Taikou Risshiden 5\Event_tw\Ecf00000.te5
2004-07-20 18:17 1086 --a------ C:\Taikou Risshiden 5\Event_tw\Eff14400.te5
2004-07-20 18:17 10800 --a------ C:\Taikou Risshiden 5\Event_tw\Epf2e000.ts5
2004-07-20 18:17 1072 --a------ C:\Taikou Risshiden 5\Event_tw\Eff29300.ts5
2004-07-20 18:17 10484 --a------ C:\Taikou Risshiden 5\Event_tw\Eff09800.ts5
2004-07-20 18:17 1014 --a------ C:\Taikou Risshiden 5\Event_tw\Epf12800.te5
2004-07-20 18:17 1014 --a------ C:\Taikou Risshiden 5\Event_tw\Eff08c00.te5
2004-07-20 17:34 82601 --a------ C:\Taikou Risshiden 5\Tw\tr5msg15.tr5
2004-07-20 17:34 74403 --a------ C:\Taikou Risshiden 5\Tw\tr5msg09.tr5
2004-07-20 17:34 71801 --a------ C:\Taikou Risshiden 5\Tw\tr5msg12.tr5
2004-07-20 17:34 59980 --a------ C:\Taikou Risshiden 5\Tw\tr5msg22.tr5
2004-07-20 17:34 49401 --a------ C:\Taikou Risshiden 5\Tw\tr5msg03.tr5
2004-07-20 17:34 46155 --a------ C:\Taikou Risshiden 5\Tw\tr5msg02.tr5
2004-07-20 17:34 103865 --a------ C:\Taikou Risshiden 5\Tw\tr5msg14.tr5
2004-07-19 18:34 74548 --a------ C:\Taikou Risshiden 5\Tw\tr5msg07.tr5
2004-07-19 18:34 48858 --a------ C:\Taikou Risshiden 5\Tw\tr5msg01.tr5
2004-07-19 18:34 38180 --a------ C:\Taikou Risshiden 5\Tw\tr5msg08.tr5
2004-07-19 14:53 72590 --a------ C:\Taikou Risshiden 5\Tw\tr5msg13.tr5
2004-07-19 14:53 64772 --a------ C:\Taikou Risshiden 5\Tw\tr5msg16.tr5
2004-07-19 12:47 99080 --a------ C:\Taikou Risshiden 5\Tw\tr5msg06.tr5
2004-07-19 12:47 38161 --a------ C:\Taikou Risshiden 5\Tw\tr5msg05.tr5
2004-07-18 08:24 4858 --a------ C:\Taikou Risshiden 5\ReadMe.txt
2004-07-17 17:14 40722 --a------ C:\Taikou Risshiden 5\Tw\tr5msg19.tr5
2004-07-17 17:14 39319 --a------ C:\Taikou Risshiden 5\Tw\tr5msg17.tr5
2004-07-17 17:14 16824 --a------ C:\Taikou Risshiden 5\Tw\tr5msg21.tr5
2004-07-17 16:39 153323 --a------ C:\Taikou Risshiden 5\Tw\Snr5_TW.TR5
2004-07-17 16:39 153323 --a------ C:\Taikou Risshiden 5\Tw\Snr2_TW.TR5
2004-07-17 16:39 153290 --a------ C:\Taikou Risshiden 5\Tw\Snr0_TW.TR5
2004-07-17 16:39 153188 --a------ C:\Taikou Risshiden 5\Tw\Snr3_TW.TR5
2004-07-17 16:39 153101 --a------ C:\Taikou Risshiden 5\Tw\Snr4_TW.TR5
2004-07-17 15:57 153335 --a------ C:\Taikou Risshiden 5\Tw\Snr1_TW.TR5
2004-07-17 13:04 28976 --a------ C:\Taikou Risshiden 5\Tw\tr5msg23.tr5
2004-07-15 11:48 76247 --a------ C:\Taikou Risshiden 5\Tw\tr5msg10.tr5
2004-07-15 11:48 52018 --a------ C:\Taikou Risshiden 5\Tw\tr5msg20.tr5
2004-07-15 11:48 49939 --a------ C:\Taikou Risshiden 5\Tw\tr5msg00.tr5
2004-07-15 11:48 31375 --a------ C:\Taikou Risshiden 5\Tw\tr5msg04.tr5
2004-07-15 11:48 212045 --a------ C:\Taikou Risshiden 5\Tw\tr5msg11.tr5
2004-07-15 09:13 880640 --a------ C:\Taikou Risshiden 5\TR5Start.exe
2004-07-15 08:30 11352080 --a------ C:\Taikou Risshiden 5\Tw\F_FONTT.tr5
2004-07-11 09:31 32557702 --a------ C:\Taikou Risshiden 5\Tw\Evstill.tg5
2004-07-11 09:29 4480982 --a------ C:\Taikou Risshiden 5\Tw\Init.tg5
2004-07-11 09:21 7458493 --a------ C:\Taikou Risshiden 5\Tw\MiniGame.tg5
2004-07-05 15:12 391526 --a------ C:\Taikou Risshiden 5\Tw\Cwtdat.tr5
2004-07-02 17:12 653068 --a------ C:\Taikou Risshiden 5\Tw\Title.tg5
2004-06-30 13:06 114688 --a------ C:\Taikou Risshiden 5\koeids.dll
2004-06-30 13:05 204800 --a------ C:\Taikou Risshiden 5\KSndStr.dll
2004-06-24 17:09 40478 --a------ C:\Taikou Risshiden 5\Tw\tr5msg18.tr5
2004-06-16 18:28 28233732 --a------ C:\Taikou Risshiden 5\Movie\TR5OP_TW.mpg
2004-06-14 11:32 52580356 --a------ C:\Taikou Risshiden 5\Movie\TR5ED_TW.mpg
2004-05-12 11:43 889 --a------ C:\Taikou Risshiden 5\Tw\tr5msg24.tr5
2004-05-07 09:43 991901 --a------ C:\Taikou Risshiden 5\Scenario.tg5
2004-05-07 09:43 810805 --a------ C:\Taikou Risshiden 5\Tsukasa.tg5
2004-05-07 09:43 36040 --a------ C:\Taikou Risshiden 5\SpCdInit.tr5
2004-05-07 09:43 331068 --a------ C:\Taikou Risshiden 5\Testwave.wav
2004-05-07 09:43 30000 --a------ C:\Taikou Risshiden 5\SbCdInit.tr5
2004-05-07 09:43 14002750 --a------ C:\Taikou Risshiden 5\Town.tg5
2004-05-07 09:43 14 --a------ C:\Taikou Risshiden 5\Taikou5.ini
2004-05-07 09:43 109560 --a------ C:\Taikou Risshiden 5\Trade.tg5
2004-05-07 09:42 7410105 --a------ C:\Taikou Risshiden 5\Face0.tg5
2004-05-07 09:42 693872 --a------ C:\Taikou Risshiden 5\Item.tg5
2004-05-07 09:42 692840 --a------ C:\Taikou Risshiden 5\Parts_A.tg5
2004-05-07 09:42 6420164 --a------ C:\Taikou Risshiden 5\Pbgrp3.tg5
2004-05-07 09:42 6384586 --a------ C:\Taikou Risshiden 5\JapanMMap.tg5
2004-05-07 09:42 58819084 --a------ C:\Taikou Risshiden 5\Pbgrp2.tg5
2004-05-07 09:42 55812165 --a------ C:\Taikou Risshiden 5\JapanMap.tg5
2004-05-07 09:42 418019 --a------ C:\Taikou Risshiden 5\M_FSAMPLE.tg5
2004-05-07 09:42 32274 --a------ C:\Taikou Risshiden 5\MapRoute.tr5
2004-05-07 09:42 301855 --a------ C:\Taikou Risshiden 5\JmapParts_A.tg5
2004-05-07 09:42 2708186 --a------ C:\Taikou Risshiden 5\EvStillM.tg5
2004-05-07 09:42 2693769 --a------ C:\Taikou Risshiden 5\Jmapstl.tg5
2004-05-07 09:42 249441 --a------ C:\Taikou Risshiden 5\Face1.tg5
2004-05-07 09:42 246400 --a------ C:\Taikou Risshiden 5\MapLand_j.TR5
2004-05-07 09:42 2380324 --a------ C:\Taikou Risshiden 5\KyotenBtn.tg5
2004-05-07 09:42 231659 --a------ C:\Taikou Risshiden 5\MainBox.tg5
2004-05-07 09:42 21274696 --a------ C:\Taikou Risshiden 5\Fwar.tg5
2004-05-07 09:42 209384 --a------ C:\Taikou Risshiden 5\Kamon.tg5
2004-05-07 09:42 1959522 --a------ C:\Taikou Risshiden 5\M_FC00_S.tg5
2004-05-07 09:42 18206550 --a------ C:\Taikou Risshiden 5\Room.tg5
2004-05-07 09:42 18000 --a------ C:\Taikou Risshiden 5\FWarAttr.tr5
2004-05-07 09:42 1650 --a------ C:\Taikou Risshiden 5\MapLand_n.tr5
2004-05-07 09:42 16320 --a------ C:\Taikou Risshiden 5\MapFHTbl.tr5
2004-05-07 09:42 1626547 --a------ C:\Taikou Risshiden 5\JmapParts_N.tg5
2004-05-07 09:42 15750 --a------ C:\Taikou Risshiden 5\M_FC00.tr5
2004-05-07 09:42 1413616 --a------ C:\Taikou Risshiden 5\Parts_N.tg5
2004-05-07 09:42 13733969 --a------ C:\Taikou Risshiden 5\M_FC00.tg5
2004-05-07 09:41 56278408 --a------ C:\Taikou Risshiden 5\Bustup0.tg5
2004-05-07 09:41 2587009 --a------ C:\Taikou Risshiden 5\Card.tg5
2004-05-07 09:41 231970 --a------ C:\Taikou Risshiden 5\Bird.tg5
2004-05-07 09:41 1878179 --a------ C:\Taikou Risshiden 5\Bustup1.tg5
2004-05-07 09:41 13249924 --a------ C:\Taikou Risshiden 5\Cwar.tg5
2004-04-15 09:55 463587 --a------ C:\Taikou Risshiden 5\Tw\Saveload.tg5
2004-04-14 09:27 4246049 --a------ C:\Taikou Risshiden 5\Tw\Pbgrp.tg5
2004-02-12 09:11 524448 --a------ C:\Taikou Risshiden 5\Ksf\SE016.sfs
2004-02-05 10:38 524448 --a------ C:\Taikou Risshiden 5\Ksf\SE017.sfs
2004-01-20 13:01 54728 --a------ C:\Taikou Risshiden 5\Ksf\SE020.sfs
2004-01-20 13:01 27808 --a------ C:\Taikou Risshiden 5\Ksf\SE012.sfs
2004-01-20 13:01 240030 --a------ C:\Taikou Risshiden 5\Ksf\SE007.sfs
2004-01-08 09:15 96740 --a------ C:\Taikou Risshiden 5\Ksf\SE023.sfs
2004-01-08 09:15 787446 --a------ C:\Taikou Risshiden 5\Ksf\SE021.sfs
2004-01-08 09:15 60558 --a------ C:\Taikou Risshiden 5\Ksf\SE024.sfs
2004-01-08 09:15 58404 --a------ C:\Taikou Risshiden 5\Ksf\SE011.sfs
2004-01-08 09:15 343786 --a------ C:\Taikou Risshiden 5\Ksf\SE028.sfs
2004-01-08 09:15 180268 --a------ C:\Taikou Risshiden 5\Ksf\SE029.sfs
2004-01-08 09:15 177394 --a------ C:\Taikou Risshiden 5\Ksf\SE027.sfs
2004-01-08 09:15 1731060 --a------ C:\Taikou Risshiden 5\Ksf\SE026.sfs
2004-01-08 09:15 132174 --a------ C:\Taikou Risshiden 5\Ksf\SE030.sfs
2004-01-08 09:15 1136020 --a------ C:\Taikou Risshiden 5\Ksf\SE025.sfs
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\yumi_cursor.cur
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\tokugi_cursor.cur
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\oodutu_cursor.cur
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\meisyo_marker.cur
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\long_cursor.cur
2003-12-25 09:27 2238 --a------ C:\Taikou Risshiden 5\Cur\direct_cursor.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor07.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor06.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor05.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor04.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor03.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor02.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor01.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor00.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\normal_cusor.cur
2003-12-05 09:13 2238 --a------ C:\Taikou Risshiden 5\Cur\focus_cursor.cur
2003-12-05 09:13 20282 --a------ C:\Taikou Risshiden 5\Cur\wait_cusor.ani
2003-12-04 08:57 1410188 --a------ C:\Taikou Risshiden 5\Movie\KOEILOGO.mpg
2003-11-27 17:52 2238 --a------ C:\Taikou Risshiden 5\Cur\koma_cursor_1.cur
2003-11-27 08:47 990384 --a------ C:\Taikou Risshiden 5\Ksf\22_minigame.kvs
2003-11-27 08:47 974653 --a------ C:\Taikou Risshiden 5\Ksf\28_honnori.kvs
2003-11-27 08:47 963535 --a------ C:\Taikou Risshiden 5\Ksf\14_chajintaku.kvs
2003-11-27 08:47 955984 --a------ C:\Taikou Risshiden 5\Ksf\SE019.sfs
2003-11-27 08:47 948779 --a------ C:\Taikou Risshiden 5\Ksf\03_kakyuu.kvs
2003-11-27 08:47 943055 --a------ C:\Taikou Risshiden 5\Ksf\26_kiki.kvs
2003-11-27 08:47 899585 --a------ C:\Taikou Risshiden 5\Ksf\16_nanban.kvs
2003-11-27 08:47 783964 --a------ C:\Taikou Risshiden 5\Ksf\SE005.sfs
2003-11-27 08:47 733348 --a------ C:\Taikou Risshiden 5\Ksf\SE022.sfs
2003-11-27 08:47 579628 --a------ C:\Taikou Risshiden 5\Ksf\SE018.sfs
2003-11-27 08:47 271148 --a------ C:\Taikou Risshiden 5\Ksf\SE015.sfs
2003-11-27 08:47 237487 --a------ C:\Taikou Risshiden 5\Ksf\32_gameover.kvs
2003-11-27 08:47 176150 --a------ C:\Taikou Risshiden 5\Ksf\SE013.sfs
2003-11-27 08:47 1699904 --a------ C:\Taikou Risshiden 5\Ksf\05_shounin.kvs
2003-11-27 08:47 1528976 --a------ C:\Taikou Risshiden 5\Ksf\02_joukyuu.kvs
2003-11-27 08:47 1427382 --a------ C:\Taikou Risshiden 5\Ksf\19_yasen.kvs
2003-11-27 08:47 1426463 --a------ C:\Taikou Risshiden 5\Ksf\15_sakaba.kvs
2003-11-27 08:47 1407134 --a------ C:\Taikou Risshiden 5\Ksf\01_daimyou.kvs
2003-11-27 08:47 1405654 --a------ C:\Taikou Risshiden 5\Ksf\33_seiki_end.kvs
2003-11-27 08:47 1401380 --a------ C:\Taikou Risshiden 5\Ksf\35_kengou.kvs
2003-11-27 08:47 1388630 --a------ C:\Taikou Risshiden 5\Ksf\20_koujousen.kvs
2003-11-27 08:47 1387252 --a------ C:\Taikou Risshiden 5\Ksf\12_kyouto.kvs
2003-11-27 08:47 1385680 --a------ C:\Taikou Risshiden 5\Ksf\11_jitaku.kvs
2003-11-27 08:47 1384231 --a------ C:\Taikou Risshiden 5\Ksf\06_toushu.kvs
2003-11-27 08:47 1383537 --a------ C:\Taikou Risshiden 5\Ksf\04_rounin.kvs
2003-11-27 08:47 1363606 --a------ C:\Taikou Risshiden 5\Ksf\10_touryou.kvs
2003-11-27 08:47 1337334 --a------ C:\Taikou Risshiden 5\Ksf\08_kashira.kvs
2003-11-27 08:47 1315643 --a------ C:\Taikou Risshiden 5\Ksf\21_kojinsentou.kvs
2003-11-27 08:47 1290877 --a------ C:\Taikou Risshiden 5\Ksf\23_kanashii.kvs
2003-11-27 08:47 1232425 --a------ C:\Taikou Risshiden 5\Ksf\17_kaigaikyoten.kvs
2003-11-27 08:47 1229053 --a------ C:\Taikou Risshiden 5\Ksf\18_gundanidou.kvs
2003-11-27 08:47 1198036 --a------ C:\Taikou Risshiden 5\Ksf\25_ketsui.kvs
2003-11-27 08:47 1157889 --a------ C:\Taikou Risshiden 5\Ksf\13_hyoujou.kvs
2003-11-27 08:47 1134774 --a------ C:\Taikou Risshiden 5\Ksf\31_shokisettei.kvs
2003-11-27 08:47 1132082 --a------ C:\Taikou Risshiden 5\Ksf\09_kaizoku.kvs
2003-11-27 08:47 1104399 --a------ C:\Taikou Risshiden 5\Ksf\07_ninja.kvs
2003-11-27 08:47 108856 --a------ C:\Taikou Risshiden 5\Ksf\SE006.sfs
2003-11-27 08:47 1060640 --a------ C:\Taikou Risshiden 5\Ksf\34_mini_end.kvs
2003-11-27 08:47 1044880 --a------ C:\Taikou Risshiden 5\Ksf\27_honnouji.kvs
2003-11-27 08:47 1038030 --a------ C:\Taikou Risshiden 5\Ksf\24_ureshii.kvs
2003-11-19 11:22 2238 --a------ C:\Taikou Risshiden 5\Cur\koma_cursor_2.cur
2003-11-19 11:22 2238 --a------ C:\Taikou Risshiden 5\Cur\koma_cursor_0.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_07.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_06.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_05.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_04.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_03.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_02.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_01.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\scroll_cursor_00.cur
2003-11-05 08:56 2238 --a------ C:\Taikou Risshiden 5\Cur\normal_cusor_00.cur
2003-09-18 11:46 898788 --a------ C:\Taikou Risshiden 5\Ksf\SE010.sfs
2003-09-18 11:46 644580 --a------ C:\Taikou Risshiden 5\Ksf\SE008.sfs
2003-09-18 11:46 2728096 --a------ C:\Taikou Risshiden 5\Ksf\SE004.sfs
2003-09-18 11:46 219664 --a------ C:\Taikou Risshiden 5\Ksf\SE001.sfs
2003-09-18 11:46 21234 --a------ C:\Taikou Risshiden 5\Ksf\SE014.sfs
2003-09-18 11:46 179384 --a------ C:\Taikou Risshiden 5\Ksf\SE009.sfs
2003-09-18 11:46 176984 --a------ C:\Taikou Risshiden 5\Ksf\SE000.sfs
2003-09-18 11:46 1474720 --a------ C:\Taikou Risshiden 5\Ksf\SE002.sfs
2003-09-18 11:46 1441952 --a------ C:\Taikou Risshiden 5\Ksf\SE003.sfs
2001-11-05 09:30 165376 --a------ C:\Taikou Risshiden 5\Uninstall.exe

---- Directory of C:\WINDOWS\-1012629104 ----

C:\WINDOWS\-1012629104\

---- Directory of C:\WINDOWS\-1022629104 ----

C:\WINDOWS\-1022629104\

---- Directory of C:\WINDOWS\9a1a1d68 ----

C:\WINDOWS\9a1a1d68\

---- Directory of C:\WINDOWS\system32\-612629104 ----

C:\WINDOWS\system32\-612629104\

---- Directory of C:\WINDOWS\system32\891a1d68 ----

C:\WINDOWS\system32\891a1d68\


------- Sigcheck -------

2005-03-14 09:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 20:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-31 00:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-03-14 08:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2007-01-14 11:48 359808 b4e29943b4b04bd5e7381546848e6669 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-03-17 02:10 360064 ef7834c1d9ddf4c7da697d8c24a03791 C:\WINDOWS\system32\dllcache\TCPIP.SYS
2007-03-17 02:10 360064 ef7834c1d9ddf4c7da697d8c24a03791 C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-23 16:29 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-23 16:29 2051328]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-23 16:29 2051328]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-24 04:03 185896]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 22:43 81920]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-23 16:29 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-12 18:12:08 27136]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-12 18:12:08 27136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-10-23 04:33:37 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= C:\Program Files\WIZET\MapleStory\l3codeca.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hxgame-update]
C:\Program Files\酵砑蚔牁炵蹈\酵砑蚔牁5.0\Statistics\hxgame-update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\WIZET\\MapleStory\\MapleStory.exe"=
"<NO NAME>"= :
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Tuotu\\Tuotu.exe"=
"C:\\Program Files\\WIZET\\MapleStory\\Patcher.exe"=
"C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\GGclient.exe"=
"C:\\Program Files\\Real\\eMule\\emule.exe"=
"C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\Garena.exe"=
"C:\\Program Files\\PPLive\\PPLive.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13113:TCP"= 13113:TCP:*:Disabled:BitComet 13113 TCP
"13113:UDP"= 13113:UDP:*:Disabled:BitComet 13113 UDP
"12372:TCP"= 12372:TCP:NortonAV
"16036:TCP"= 16036:TCP:NortonAV
"13159:TCP"= 13159:TCP:NortonAV
"17820:TCP"= 17820:TCP:NortonAV
"13570:TCP"= 13570:TCP:NortonAV
"18305:TCP"= 18305:TCP:NortonAV
"18990:TCP"= 18990:TCP:NortonAV
"15128:TCP"= 15128:TCP:NortonAV
"17533:TCP"= 17533:TCP:NortonAV
"13172:TCP"= 13172:TCP:NortonAV
"16852:TCP"= 16852:TCP:NortonAV
"15943:TCP"= 15943:TCP:NortonAV
"17524:TCP"= 17524:TCP:NortonAV
"18411:TCP"= 18411:TCP:NortonAV
"17957:TCP"= 17957:TCP:NortonAV
"18061:TCP"= 18061:TCP:NortonAV
"18043:TCP"= 18043:TCP:NortonAV
"12431:TCP"= 12431:TCP:NortonAV
"13282:TCP"= 13282:TCP:NortonAV
"12312:TCP"= 12312:TCP:NortonAV
"18235:TCP"= 18235:TCP:NortonAV
"13963:TCP"= 13963:TCP:NortonAV
"12672:TCP"= 12672:TCP:NortonAV
"13279:TCP"= 13279:TCP:NortonAV
"18190:TCP"= 18190:TCP:NortonAV
"16609:TCP"= 16609:TCP:NortonAV
"17980:TCP"= 17980:TCP:NortonAV
"16068:TCP"= 16068:TCP:NortonAV
"18675:TCP"= 18675:TCP:NortonAV
"18518:TCP"= 18518:TCP:NortonAV
"12464:TCP"= 12464:TCP:NortonAV
"18583:TCP"= 18583:TCP:NortonAV

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-04-23 16:29]
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-23 16:29]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-23 16:29]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-23 16:29]
S2 cliconfg;clic onfg;C:\WINDOWS\system32\cliconfg.exe []
S2 DCOMManager16;DCOM Service Process Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]
S2 HWQRLDYQLLRX;NDOYEQAZBJD;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]
S2 lmoboyes;Logical Disk Manager Amdinistrative SAlm080124;c:\root\lm8124\scvhost.exe []
S2 ti7gnjw;ti7gnjw;C:\WINDOWS\system32\drivers\ti7gnjw.sys []
S2 WinCOM;COM+ Windows System;C:\WINDOWS\system32\wincom.exe []
S3 IVIresizeP8;IVIresizeP8;C:\WINDOWS\system32\drivers\IVIresizeP8.sys []
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys []
S3 XDva020;XDva020;C:\WINDOWS\system32\XDva020.sys []
S4 IXKBXE;BNTJKTH;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]
S4 OZJUV;BCFRHQXUR;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
PTBTMACJZIGFH REG_MULTI_SZ HWQRLDYQLLRX
NWQGVCZ REG_MULTI_SZ IXKBXE
FQGGUNMZQP REG_MULTI_SZ OZJUV

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
DCOMManager16

.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 03:48:54 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-04-26 03:49:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-26 11:46:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DCOMManager16]
"ServiceDll"="c:\windows\inf\pcidev32.inf"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-04-26 11:50:39 - machine was rebooted [HP_Owner]
ComboFix-quarantined-files.txt 2008-04-26 03:50:30

Pre-Run: 124,410,736,640 bytes free
Post-Run: 124,324,294,656 bytes free

805 --- E O F --- 2008-03-30 11:55:17

#7 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 03:29 AM

This is the scan log and the last Hijack log : Btw the Taikou5 is a game program

C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01072007-191343.log Object is locked skipped

C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012008042620080427\index.dat Object is locked skipped

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{FB0B7E35-1791-4838-8FCB-12BD2312AC3E}\RP1062\A0481384.exe Object is locked skipped

C:\System Volume Information\_restore{FB0B7E35-1791-4838-8FCB-12BD2312AC3E}\RP1063\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

D:\System Volume Information\_restore{FB0B7E35-1791-4838-8FCB-12BD2312AC3E}\RP1063\change.log Object is locked skipped

Scan process completed.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:01:16, on 2008-4-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\Hijack\HijackThis.exe

R3 - URLSearchHook: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &场ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} - https://mail.rajahtann.com/iNotes6.cab
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdat...0.10-signed.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153925162750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - http://avatar.mabinogi.com:88/renderer/mab....2006.12.27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - http://download.games.yahoo.com/games/web_...outLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{964967CE-6096-4709-B068-60596131E36F}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: clic onfg (cliconfg) - Unknown owner - C:\WINDOWS\system32\cliconfg.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logical Disk Manager Amdinistrative SAlm080124 (lmoboyes) - Unknown owner - c:\root\lm8124\scvhost.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: COM+ Windows System (WinCOM) - Unknown owner - C:\WINDOWS\system32\wincom.exe (file missing)

--
End of file - 9585 bytes

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 26 April 2008 - 09:06 AM

Just a little more.

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

Dirlook::
c:\windows\inf

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DCOMManager16]
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.


How is your computer working now?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#9 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 09:20 AM

My com is working SUPER no more delay and spyware problem now !!! Thank you For your help i really appreciate for eveything u done for me You're the Man Buckeye_Sam!!! :thumbsup:

#10 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 26 April 2008 - 09:23 AM

Please be sure to follow my last steps. You may not be out of the woods yet.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#11 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 09:26 AM

ComboFix 08-04-24.1 - HP_Owner 2008-04-26 22:09:24.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.1.1033.18.79 [GMT 8:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.

2008-04-26 11:56 . 2008-04-26 11:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-26 11:56 . 2008-04-26 11:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-25 01:40 . 2008-04-25 01:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-24 10:24 . 2008-04-24 10:55 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-24 09:33 . 2008-04-24 10:17 <DIR> d--h----- C:\$AVG8.VAULT$
2008-04-24 09:30 . 2008-04-24 09:30 <DIR> d-------- C:\Deckard
2008-04-23 16:29 . 2008-04-26 02:20 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-23 16:29 . 2008-04-23 16:29 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\AVGTOOLBAR
2008-04-23 16:29 . 2008-04-23 16:29 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-23 16:29 . 2008-04-23 16:29 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-23 16:29 . 2008-04-23 16:29 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-04-23 16:29 . 2008-04-23 16:29 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-23 14:40 . 2008-04-23 14:40 <DIR> d-------- C:\fsaua.data
2008-04-23 14:02 . 2008-04-23 14:03 <DIR> d-------- C:\cc
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-23 12:35 . 2006-01-13 10:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intervideo
2008-04-23 12:35 . 2008-04-23 16:22 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-23 12:35 . 2008-04-26 11:41 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-23 12:20 . 2008-04-23 12:20 <DIR> d-------- C:\FileAssasin
2008-04-23 12:15 . 2008-04-26 16:01 <DIR> d-------- C:\Hijack
2008-04-23 12:14 . 2008-04-23 12:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-21 12:39 . 2008-04-21 12:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 12:39 . 2008-04-21 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 09:58 . 2008-04-21 12:38 <DIR> d-------- C:\Program Files\Netcom3 Cleaner
2008-04-20 15:59 . 2008-04-20 15:59 244 --ah----- C:\sqmnoopt01.sqm
2008-04-20 15:59 . 2008-04-20 15:59 232 --ah----- C:\sqmdata01.sqm
2008-04-20 10:00 . 2008-04-20 10:00 244 --ah----- C:\sqmnoopt00.sqm
2008-04-20 10:00 . 2008-04-20 10:00 232 --ah----- C:\sqmdata00.sqm
2008-04-13 23:24 . 2008-04-13 23:24 <DIR> d-------- C:\Program Files\AVG
2008-04-13 23:24 . 2008-04-23 16:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-13 02:24 . 2008-04-13 02:24 1,073,741,824 --a------ C:\pfsvoddata.bbv
2008-04-10 18:15 . 2008-04-10 20:47 17,267 --a------ C:\WINDOWS\system32\ccwl32.ini.tmp
2008-04-07 11:47 . 2008-04-07 11:51 159,744 --a------ C:\WINDOWS\AF.tmp
2008-04-03 15:37 . 2008-04-07 14:54 336 --a------ C:\tesvlog.lvr
2008-04-03 15:30 . 2008-04-03 15:33 <DIR> d-------- C:\Taikou Risshiden 5
2008-04-02 22:33 . 2008-04-10 20:36 250 --a------ C:\WINDOWS\system32\ccwl32.ini
2008-04-02 22:32 . 2008-04-10 18:13 396 --a------ C:\WINDOWS\ccwl16.ini
2008-04-01 15:57 . 2008-04-14 00:28 <DIR> d-------- C:\Program Files\eMule
2008-04-01 12:22 . 2004-03-12 22:41 156,800 --a------ C:\WINDOWS\system32\drivers\d346bus.sys
2008-04-01 12:22 . 2004-03-12 22:41 5,248 --a------ C:\WINDOWS\system32\drivers\d346prt.sys
2008-04-01 12:21 . 2008-04-01 12:22 <DIR> d-------- C:\Program Files\D-Tools
2008-04-01 12:21 . 2004-05-03 02:07 509,440 --a------ C:\WINDOWS\daemon346.exe
2008-04-01 12:17 . 2008-04-14 01:26 <DIR> d-------- C:\WINDOWS\system32\inf
2008-03-31 19:13 . 2008-04-13 00:02 236 --a------ C:\WINDOWS\system32\resiifers.ini
2008-03-31 16:51 . 2008-04-14 00:56 <DIR> d-------- C:\Program Files\NOBU12PK
2008-03-30 15:45 . 2008-04-02 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-03-30 15:32 . 2008-03-30 15:37 26 --a------ C:\system_32.ini
2008-03-30 13:22 . 2008-03-30 13:22 <DIR> d-------- C:\root
2008-03-30 13:14 . 2008-03-30 13:23 <DIR> d-------- C:\My Downloads
2008-03-28 23:56 . 2008-04-02 11:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ou
2008-03-27 14:31 . 2008-03-27 14:31 0 --a------ C:\WINDOWS\65.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-26 14:12 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SlimBrowser
2008-04-26 03:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-26 03:23 --------- d-----w C:\Program Files\PPLive
2008-04-25 17:12 --------- d-----w C:\Program Files\Warcraft III
2008-04-25 11:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-25 04:10 --------- d-----w C:\Program Files\PowerArchiver
2008-04-23 06:04 --------- d-----w C:\Program Files\CCleaner
2008-04-21 06:04 --------- d-----w C:\Program Files\Lavasoft
2008-04-20 01:55 77,368 ----a-w C:\Documents and Settings\HP_Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 16:55 --------- d-----w C:\Program Files\MSAR3.0_Alpha
2008-04-13 16:49 --------- d-----w C:\Program Files\Microsoft Works
2008-04-13 16:41 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-13 16:28 --------- d-----w C:\Program Files\Globe7
2008-04-13 16:28 --------- d-----w C:\Program Files\FlashGet
2008-04-13 16:22 --------- d-----w C:\Program Files\blueserver
2008-04-13 16:22 --------- d-----w C:\Program Files\BitComet
2008-04-13 15:38 --------- d-----w C:\Program Files\DivX
2008-04-11 01:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-11 01:11 --------- d-----w C:\Program Files\SlimBrowser
2008-04-10 12:21 2,131 ----a-w C:\WINDOWS\system32\m7ci0Tk.dll
2008-03-30 08:50 --------- d-----w C:\Program Files\Koei
2008-03-30 07:31 3,270 ----a-w C:\WINDOWS\system32\drivers\GUPLPSCX.DLL
2008-03-26 10:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-23 20:48 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-23 14:07 --------- d-----w C:\Program Files\Windows Live
2008-03-23 14:05 --------- d-----w C:\Program Files\MSN Messenger
2008-03-23 14:03 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 13:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 08:49 --------- d-----w C:\Program Files\Ocean Technologies & Media
2008-03-03 08:49 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\InstallShield
2008-02-23 20:10 203,776 ----a-w C:\WINDOWS\system32\clrviddc.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-17 03:31 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-02-17 03:31 126,976 ----a-w C:\WINDOWS\War3Unin.exe
2008-02-09 16:01 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2006-08-01 03:26 0 ----a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2006-06-13 05:47 368,702 ----a-w C:\Program Files\Storm.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of c:\windows\inf ----

2008-04-25 01:37 69560 --a------ c:\windows\inf\oem2.PNF
2008-04-23 19:23 222180 --a------ c:\windows\inf\drvindex.PNF
2008-04-23 19:21 6216 --a------ c:\windows\inf\netiprip.PNF
2008-04-23 19:21 4004 --a------ c:\windows\inf\netupnp.PNF
2008-04-23 19:21 3652 --a------ c:\windows\inf\netbeac.PNF
2008-04-23 19:21 14240 --a------ c:\windows\inf\p2p.PNF
2008-04-23 19:21 10732 --a------ c:\windows\inf\nettpsmp.PNF
2008-04-23 19:21 10412 --a------ c:\windows\inf\netlpd.PNF
2008-04-23 19:20 993248 --a------ c:\windows\inf\LAYOUT.PNF
2008-04-23 19:20 9492 --a------ c:\windows\inf\msnmsn.PNF
2008-04-23 19:20 87456 --a------ c:\windows\inf\msmsgs.PNF
2008-04-23 19:20 6928 --a------ c:\windows\inf\wbemsnmp.PNF
2008-04-23 19:20 6756 --a------ c:\windows\inf\SYSOC.PNF
2008-04-23 19:20 55728 --a------ c:\windows\inf\fxsocm.PNF
2008-04-23 19:20 48316 --a------ c:\windows\inf\accessor.PNF
2008-04-23 19:20 4424 --a------ c:\windows\inf\ieaccess.PNF
2008-04-23 19:20 4408 --a------ c:\windows\inf\wmpocm.PNF
2008-04-23 19:20 4384 --a------ c:\windows\inf\oeaccess.PNF
2008-04-23 19:20 41164 --a------ c:\windows\inf\setupqry.PNF
2008-04-23 19:20 4056 --a------ c:\windows\inf\wmaccess.PNF
2008-04-23 19:20 3932 --a------ c:\windows\inf\rootau.PNF
2008-04-23 19:20 21688 --a------ c:\windows\inf\optional.PNF
2008-04-23 19:20 19900 --a------ c:\windows\inf\netsnmp.PNF
2008-04-23 19:20 17568 --a------ c:\windows\inf\fp40ext.PNF
2008-04-23 19:20 17476 --a------ c:\windows\inf\communic.PNF
2008-04-23 19:20 16656 --a------ c:\windows\inf\wordpad.PNF
2008-04-23 19:20 16448 --a------ c:\windows\inf\netoc.PNF
2008-04-23 19:20 15092 --a------ c:\windows\inf\games.PNF
2008-04-23 19:20 134788 --a------ c:\windows\inf\comnt5.PNF
2008-04-23 19:20 13260 --a------ c:\windows\inf\igames.PNF
2008-04-23 19:20 12416 --a------ c:\windows\inf\wbemoc.PNF
2008-04-23 19:20 12368 --a------ c:\windows\inf\pinball.PNF
2008-04-23 19:20 122672 --a------ c:\windows\inf\tsoc.PNF
2008-04-23 19:20 11984 --a------ c:\windows\inf\multimed.PNF
2008-04-23 19:20 105644 --a------ c:\windows\inf\startoc.PNF
2008-04-23 19:20 105040 --a------ c:\windows\inf\ims.PNF
2008-04-23 19:20 10240 --a------ c:\windows\inf\dtcnt5.PNF
2008-04-23 19:20 100544 --a------ c:\windows\inf\iis.PNF
2008-04-15 00:22 7800 --a------ c:\windows\inf\certclas.PNF
2008-04-11 12:01 4624 --a------ c:\windows\inf\GETPLUSo.PNF
2008-04-11 08:53 146476 --a------ c:\windows\inf\prtupg9x.PNF
2008-04-11 08:53 1317388 --a------ c:\windows\inf\ntprint.PNF
2008-04-10 13:56 99324 --a------ c:\windows\inf\syssetup.PNF
2008-04-04 01:35 78 --a------ c:\windows\inf\PlugsList.dat
2008-04-01 12:43 109404 --a------ c:\windows\inf\apps.PNF
2008-04-01 12:22 6068 --a------ c:\windows\inf\oem93.PNF
2008-04-01 12:22 1647160 --a------ c:\windows\inf\INFCACHE.1
2008-04-01 12:22 1255 --a------ c:\windows\inf\oem93.inf
2008-04-01 12:20 6110 --a------ c:\windows\inf\oem92.PNF
2008-04-01 12:20 2687 --a------ c:\windows\inf\oem92.inf
2008-04-01 12:20 19996 --a------ c:\windows\inf\oem90.PNF
2008-03-31 16:33 8580 --a------ c:\windows\inf\fsvga.PNF
2008-03-31 16:33 2648 --a------ c:\windows\inf\fsvgaadd.PNF
2008-03-24 15:28 0 ---h----- c:\windows\inf\oem91.inf
2008-03-02 22:56 4100 --a------ c:\windows\inf\branches.PNF
2008-02-21 06:00 424000 --a------ c:\windows\inf\intl.PNF
2008-01-06 12:19 56516 --a------ c:\windows\inf\cdrom.PNF
2008-01-06 12:02 6124 --a------ c:\windows\inf\oem89.PNF
2008-01-06 12:02 1273 --a------ c:\windows\inf\oem89.inf
2007-12-29 22:45 9644 --a------ c:\windows\inf\ccdecode.PNF
2007-12-29 22:45 9636 --a------ c:\windows\inf\nabtsfec.PNF
2007-12-29 22:45 9200 --a------ c:\windows\inf\wstcodec.PNF
2007-12-29 22:45 9196 --a------ c:\windows\inf\slip.PNF
2007-12-29 22:45 91444 --a------ c:\windows\inf\ks.PNF
2007-12-29 22:45 9096 --a------ c:\windows\inf\ndisip.PNF
2007-12-29 22:45 74356 --a------ c:\windows\inf\wdma_usb.PNF
2007-12-29 22:45 44896 --a------ c:\windows\inf\wdmaudio.PNF
2007-12-29 22:45 43544 --a------ c:\windows\inf\oem70.PNF
2007-12-29 22:45 43500 --a------ c:\windows\inf\kscaptur.PNF
2007-12-29 22:45 24640 --a------ c:\windows\inf\ksfilter.PNF
2007-12-29 22:45 11956 --a------ c:\windows\inf\streamip.PNF
2007-12-19 04:46 705 --a------ c:\windows\inf\branches.inf
2007-12-17 23:53 63112 --a------ c:\windows\inf\msmouse.PNF
2007-12-17 23:53 57268 --a------ c:\windows\inf\keyboard.PNF
2007-12-17 23:53 12720 --a------ c:\windows\inf\hidserv.PNF
2007-12-17 23:53 100124 --a------ c:\windows\inf\input.PNF
2007-12-17 23:52 44496 --a------ c:\windows\inf\usb.PNF
2007-12-12 20:06 72642 --a------ c:\windows\inf\oem73.PNF
2007-12-12 20:06 6656 --a------ c:\windows\inf\hdaudbus.PNF
2007-12-12 20:06 6356 --a------ c:\windows\inf\net1394.PNF
2007-12-12 20:06 6192 --a------ c:\windows\inf\sonypvu1.PNF
2007-12-12 20:06 61560 --a------ c:\windows\inf\oem1.PNF
2007-12-12 20:06 6018 --a------ c:\windows\inf\oem0.PNF
2007-12-12 20:06 5772 --a------ c:\windows\inf\netpsa.PNF
2007-12-12 20:06 5476 --a------ c:\windows\inf\usbprint.PNF
2007-12-12 20:06 51448 --a------ c:\windows\inf\usbport.PNF
2007-12-12 20:06 49540 --a------ c:\windows\inf\mshdc.PNF
2007-12-12 20:06 47202 --a------ c:\windows\inf\oem7.PNF
2007-12-12 20:06 39084 --a------ c:\windows\inf\msdv.PNF
2007-12-12 20:06 34070 --a------ c:\windows\inf\oem6.PNF
2007-12-12 20:06 27832 --a------ c:\windows\inf\sti.PNF
2007-12-12 20:06 23504 --a------ c:\windows\inf\netrasa.PNF
2007-12-12 20:06 231234 --a------ c:\windows\inf\oem68.PNF
2007-12-12 20:06 19836 --a------ c:\windows\inf\netrtsnt.PNF
2007-12-12 20:06 16576 --a------ c:\windows\inf\1394.PNF
2007-12-12 20:06 11468 --a------ c:\windows\inf\hal.PNF
2007-12-12 20:06 10580 --a------ c:\windows\inf\wave.PNF
2007-12-12 20:05 8480 --a------ c:\windows\inf\flpydisk.PNF
2007-12-12 20:05 7940 --a------ c:\windows\inf\fdc.PNF
2007-12-12 20:05 6168 --a------ c:\windows\inf\oem66.PNF
2007-12-12 20:05 6146 --a------ c:\windows\inf\oem8.PNF
2007-12-12 20:05 44516 --a------ c:\windows\inf\oem65.PNF
2007-12-12 20:05 33818 --a------ c:\windows\inf\oem72.PNF
2007-12-12 20:05 30232 --a------ c:\windows\inf\msports.PNF
2007-12-12 20:05 193074 --a------ c:\windows\inf\oem67.PNF
2007-12-12 20:05 192908 --a------ c:\windows\inf\oem3.PNF
2007-12-12 20:05 187380 --a------ c:\windows\inf\machine.PNF
2007-12-12 20:05 16972 --a------ c:\windows\inf\cpu.PNF
2007-12-12 20:05 14376 --a------ c:\windows\inf\oem74.PNF
2007-12-12 20:05 12512 --a------ c:\windows\inf\acpi.PNF
2007-10-21 11:12 19988 --a------ c:\windows\inf\oem88.PNF
2007-08-24 09:10 0 ---h----- c:\windows\inf\oem71.inf
2007-07-30 19:02 50726 --a------ c:\windows\inf\wuau.adm
2007-06-09 08:21 4684 --a------ c:\windows\inf\Erma.PNF
2007-05-23 05:29 0 ---h----- c:\windows\inf\oem87.inf
2007-05-08 11:33 5196 --a------ c:\windows\inf\xact2_3_x86.PNF
2007-05-08 11:33 5196 --a------ c:\windows\inf\xact2_2_x86.PNF
2007-05-08 11:33 5196 --a------ c:\windows\inf\xact2_1_x86.PNF
2007-05-08 11:33 5180 --a------ c:\windows\inf\xact_x86.PNF
2007-05-08 11:33 4860 --a------ c:\windows\inf\d3dx9_30_x86.PNF
2007-05-08 11:33 4860 --a------ c:\windows\inf\d3dx9_29_x86.PNF
2007-05-08 11:33 4860 --a------ c:\windows\inf\d3dx9_28_x86.PNF
2007-05-08 11:33 4860 --a------ c:\windows\inf\d3dx9_26_x86.PNF
2007-05-08 11:33 4860 --a------ c:\windows\inf\d3dx9_25_x86.PNF
2007-05-08 11:33 4796 --a------ c:\windows\inf\xinput9_1_0_x86.PNF
2007-05-08 11:33 4780 --a------ c:\windows\inf\xinput1_2_x86.PNF
2007-05-08 11:33 4780 --a------ c:\windows\inf\xinput1_1_x86.PNF
2007-05-08 11:32 4892 --a------ c:\windows\inf\d3dx9_24_x86.PNF
2007-02-20 12:50 35940 --a------ c:\windows\inf\oem90.inf
2007-02-02 20:29 4816 --a------ c:\windows\inf\volume.PNF
2007-02-02 20:29 37024 --a------ c:\windows\inf\usbstor.PNF
2007-02-02 20:29 12136 --a------ c:\windows\inf\disk.PNF
2007-01-30 04:45 62236 --a------ c:\windows\inf\font.PNF
2007-01-11 18:33 7698 --a------ c:\windows\inf\oem76.PNF
2007-01-11 18:33 7610 --a------ c:\windows\inf\oem79.PNF
2007-01-11 18:33 6778 --a------ c:\windows\inf\oem78.PNF
2007-01-11 18:33 6722 --a------ c:\windows\inf\oem80.PNF
2007-01-11 18:33 6688 --a------ c:\windows\inf\oem77.PNF
2007-01-11 18:33 6308 --a------ c:\windows\inf\oem85.PNF
2007-01-11 18:33 6280 --a------ c:\windows\inf\oem82.PNF
2007-01-11 18:33 6208 --a------ c:\windows\inf\oem81.PNF
2007-01-11 18:33 6160 --a------ c:\windows\inf\oem86.PNF
2007-01-11 18:33 5308 --a------ c:\windows\inf\oem83.PNF
2007-01-11 18:33 5300 --a------ c:\windows\inf\oem84.PNF
2006-12-15 14:15 6496 --a------ c:\windows\inf\pxhelp20.PNF
2006-12-03 19:06 795 --a------ c:\windows\inf\ieaccess.inf
2006-11-15 17:04 5752 --a------ c:\windows\inf\iereset.PNF
2006-10-13 12:43 35868 --a------ c:\windows\inf\oem88.inf
2006-10-03 01:43 2402550 --------- c:\windows\inf\inetres.adm
2006-09-28 14:46 44964 --a------ c:\windows\inf\printupg.PNF
2006-09-28 14:31 97298 --a------ c:\windows\inf\oem16.PNF
2006-09-28 14:31 71058 --a------ c:\windows\inf\oem15.PNF
2006-09-28 14:31 36274 --a------ c:\windows\inf\oem75.PNF
2006-09-28 14:31 23450 --a------ c:\windows\inf\oem17.PNF
2006-09-28 11:53 20044 --a------ c:\windows\inf\windowsdefender.adm
2006-09-01 07:55 37836 --------- c:\windows\inf\IEM\0409\inetset.iem
2006-09-01 07:55 13696 --------- c:\windows\inf\IEM\0409\inetcorp.iem
2006-08-13 10:38 8368 --a------ c:\windows\inf\swflash.PNF
2006-08-13 10:38 5788 --a------ c:\windows\inf\fhg.PNF
2006-08-08 03:06 4858 --a------ c:\windows\inf\d3dx9_27_x86.PNF
2006-07-28 10:19 905 --a------ c:\windows\inf\xact2_3_x86.inf
2006-07-28 10:19 783 --a------ c:\windows\inf\xinput1_2_x86.inf
2006-07-26 22:54 0 ---h----- c:\windows\inf\oem69.inf
2006-07-26 18:01 7952 --a------ c:\windows\inf\netfw.PNF
2006-07-26 18:01 3704 --a------ c:\windows\inf\msnetfw.PNF
2006-07-26 12:42 4802 --a------ c:\windows\inf\netfw.inf
2006-07-26 12:40 7412 --a------ c:\windows\inf\hpi_bmsa.PNF
2006-07-26 12:40 5448 --a------ c:\windows\inf\USBkey.PNF
2006-07-26 12:40 3988 --a------ c:\windows\inf\wmsetsdk.PNF
2006-07-26 12:40 10428 --a------ c:\windows\inf\wpdmtp.PNF
2006-06-22 11:41 5032 --a------ c:\windows\inf\swflash.inf
2006-05-31 07:31 905 --a------ c:\windows\inf\xact2_2_x86.inf
2006-03-31 12:46 905 --a------ c:\windows\inf\xact2_1_x86.inf
2006-03-31 12:46 783 --a------ c:\windows\inf\xinput1_1_x86.inf
2006-03-31 12:46 779 --a------ c:\windows\inf\d3dx9_30_x86.inf
2006-02-03 08:51 899 --a------ c:\windows\inf\xact_x86.inf
2006-02-03 08:51 779 --a------ c:\windows\inf\d3dx9_29_x86.inf
2006-01-12 19:33 8136 --a------ c:\windows\inf\ProfSec.PNF
2006-01-12 19:33 4524 --a------ c:\windows\inf\ProfSec.Inf
2006-01-12 19:03 6770 --a------ c:\windows\inf\DRM10.PNF
2006-01-12 19:03 6178 --a------ c:\windows\inf\MPPRE10.PNF
2006-01-12 19:03 22146 --a------ c:\windows\inf\WMDM10.PNF
2006-01-12 19:03 13082 --a------ c:\windows\inf\codecs10.PNF
2006-01-12 19:03 10744 --a------ c:\windows\inf\WMFSDK10.PNF
2006-01-12 19:03 10524 --a------ c:\windows\inf\WPD10.PNF
2006-01-12 18:43 8224 --a------ c:\windows\inf\oem54.PNF
2006-01-12 18:43 69810 --a------ c:\windows\inf\oem60.PNF
2006-01-12 18:43 6706 --a------ c:\windows\inf\oem56.PNF
2006-01-12 18:43 50450 --a------ c:\windows\inf\oem57.PNF
2006-01-12 18:43 45290 --a------ c:\windows\inf\oem55.PNF
2006-01-12 18:43 37786 --a------ c:\windows\inf\oem59.PNF
2006-01-12 18:43 30530 --a------ c:\windows\inf\oem62.PNF
2006-01-12 18:43 23426 --a------ c:\windows\inf\oem61.PNF
2006-01-12 18:43 20442 --a------ c:\windows\inf\oem58.PNF
2006-01-12 18:42 8602 --a------ c:\windows\inf\oem42.PNF
2006-01-12 18:42 8282 --a------ c:\windows\inf\oem48.PNF
2006-01-12 18:42 8250 --a------ c:\windows\inf\oem49.PNF
2006-01-12 18:42 8250 --a------ c:\windows\inf\oem28.PNF
2006-01-12 18:42 8234 --a------ c:\windows\inf\oem50.PNF
2006-01-12 18:42 8226 --a------ c:\windows\inf\oem52.PNF
2006-01-12 18:42 8218 --a------ c:\windows\inf\oem24.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem63.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem53.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem38.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem36.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem35.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem33.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem32.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem31.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem30.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem29.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem27.PNF
2006-01-12 18:42 8210 --a------ c:\windows\inf\oem26.PNF
2006-01-12 18:42 8208 --a------ c:\windows\inf\oem64.PNF
2006-01-12 18:42 8202 --a------ c:\windows\inf\oem37.PNF
2006-01-12 18:42 8202 --a------ c:\windows\inf\oem34.PNF
2006-01-12 18:42 8178 --a------ c:\windows\inf\oem25.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem51.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem47.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem46.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem45.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem44.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem43.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem41.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem40.PNF
2006-01-12 18:42 8162 --a------ c:\windows\inf\oem39.PNF
2006-01-12 18:42 2669 --a------ c:\windows\inf\hpi_bmsa.inf
2006-01-12 18:40 69882 --a------ c:\windows\inf\oem18.PNF
2006-01-12 18:40 67746 --a------ c:\windows\inf\oem19.PNF
2006-01-12 18:40 37522 --a------ c:\windows\inf\oem23.PNF
2006-01-12 18:40 30586 --a------ c:\windows\inf\oem22.PNF
2006-01-12 18:40 25354 --a------ c:\windows\inf\oem21.PNF
2006-01-12 18:40 23458 --a------ c:\windows\inf\oem20.PNF
2006-01-12 18:38 69882 --a------ c:\windows\inf\oem9.PNF
2006-01-12 18:38 67746 --a------ c:\windows\inf\oem10.PNF
2006-01-12 18:38 37522 --a------ c:\windows\inf\oem14.PNF
2006-01-12 18:38 30586 --a------ c:\windows\inf\oem13.PNF
2006-01-12 18:38 25354 --a------ c:\windows\inf\oem12.PNF
2006-01-12 18:38 23458 --a------ c:\windows\inf\oem11.PNF
2006-01-12 18:35 13154 --a------ c:\windows\inf\oem5.PNF
2006-01-12 18:35 13154 --a------ c:\windows\inf\oem4.PNF
2006-01-12 18:27 40524 --a------ c:\windows\inf\hdaudio.PNF
2006-01-12 18:25 6484 --a------ c:\windows\inf\skins.PNF
2006-01-12 18:22 65516 --a------ c:\windows\inf\WMP10.PNF
2006-01-12 18:22 5346 --a------ c:\windows\inf\MPSTUB10.PNF
2006-01-12 18:22 5322 --a------ c:\windows\inf\MPCD10.PNF
2006-01-12 18:22 5242 --a------ c:\windows\inf\WMSET10.PNF
2006-01-12 18:12 9960 --a------ c:\windows\inf\mxboard.PNF
2006-01-12 18:12 9952 --a------ c:\windows\inf\msinfo32.PNF
2006-01-12 18:12 9940 --a------ c:\windows\inf\netfa312.PNF
2006-01-12 18:12 9936 --a------ c:\windows\inf\xscan_xp.PNF
2006-01-12 18:12 9916 --a------ c:\windows\inf\trid3d.PNF
2006-01-12 18:12 9900 --a------ c:\windows\inf\tsbvcap.PNF
2006-01-12 18:12 9868 --a------ c:\windows\inf\netw840.PNF
2006-01-12 18:12 9864 --a------ c:\windows\inf\netf56n5.PNF
2006-01-12 18:12 9848 --a------ c:\windows\inf\netxcpq.PNF
2006-01-12 18:12 9776 --a------ c:\windows\inf\tshoot.PNF
2006-01-12 18:12 9740 --a------ c:\windows\inf\netamd.PNF
2006-01-12 18:12 9732 --a------ c:\windows\inf\netias.PNF
2006-01-12 18:12 9716 --a------ c:\windows\inf\tridkb.PNF
2006-01-12 18:12 9712 --a------ c:\windows\inf\mflm56.PNF
2006-01-12 18:12 9704 --a------ c:\windows\inf\mff56n5.PNF
2006-01-12 18:12 9684 --a------ c:\windows\inf\viafir2k.PNF
2006-01-12 18:12 9668 --a------ c:\windows\inf\nv3.PNF
2006-01-12 18:12 96400 --a------ c:\windows\inf\mdmlt3.PNF
2006-01-12 18:12 9596 --a------ c:\windows\inf\mfsocket.PNF
2006-01-12 18:12 95848 --a------ c:\windows\inf\wdma_aur.PNF
2006-01-12 18:12 9556 --a------ c:\windows\inf\netirda.PNF
2006-01-12 18:12 9460 --a------ c:\windows\inf\mfx56nf.PNF
2006-01-12 18:12 9424 --a------ c:\windows\inf\tdibth.PNF
2006-01-12 18:12 94204 --a------ c:\windows\inf\monitor6.PNF
2006-01-12 18:12 9380 --a------ c:\windows\inf\ps5333.PNF
2006-01-12 18:12 9368 --a------ c:\windows\inf\netbcm4p.PNF
2006-01-12 18:12 9332 --a------ c:\windows\inf\mdmusrf.PNF
2006-01-12 18:12 9288 --a------ c:\windows\inf\mflm.PNF
2006-01-12 18:12 9244 --a------ c:\windows\inf\netdefxa.PNF
2006-01-12 18:12 92092 --a------ c:\windows\inf\mdmmhza.PNF
2006-01-12 18:12 9204 --a------ c:\windows\inf\nettb155.PNF
2006-01-12 18:12 9172 --a------ c:\windows\inf\net656c5.PNF
2006-01-12 18:12 9068 --a------ c:\windows\inf\sis300i.PNF
2006-01-12 18:12 9068 --a------ c:\windows\inf\netcem28.PNF
2006-01-12 18:12 9044 --a------ c:\windows\inf\netcem33.PNF
2006-01-12 18:12 90232 --a------ c:\windows\inf\mdmsonyu.PNF
2006-01-12 18:12 89996 --a------ c:\windows\inf\mdmmhzk1.PNF
2006-01-12 18:12 8940 --a------ c:\windows\inf\perm3.PNF
2006-01-12 18:12 8932 --a------ c:\windows\inf\netupnph.PNF
2006-01-12 18:12 8932 --a------ c:\windows\inf\memstpci.PNF
2006-01-12 18:12 89128 --a------ c:\windows\inf\monitor3.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv5.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv4.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv3.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv2.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv1.PNF
2006-01-12 18:12 8892 --a------ c:\windows\inf\wtv0.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp8.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp7.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp6.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp5.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp3.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp2.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp1.PNF
2006-01-12 18:12 8884 --a------ c:\windows\inf\wfp0.PNF
2006-01-12 18:12 8876 --a------ c:\windows\inf\wfp4.PNF
2006-01-12 18:12 8868 --a------ c:\windows\inf\netcb102.PNF
2006-01-12 18:12 8864 --a------ c:\windows\inf\mdmmotou.PNF
2006-01-12 18:12 88208 --a------ c:\windows\inf\monitor7.PNF
2006-01-12 18:12 8812 --a------ c:\windows\inf\tgiu.PNF
2006-01-12 18:12 8812 --a------ c:\windows\inf\net3c556.PNF
2006-01-12 18:12 8776 --a------ c:\windows\inf\netbcm4u.PNF
2006-01-12 18:12 8724 --a------ c:\windows\inf\netbcm4e.PNF
2006-01-12 18:12 8720 --a------ c:\windows\inf\mtxvideo.PNF
2006-01-12 18:12 87168 --a------ c:\windows\inf\stillcam.PNF
2006-01-12 18:12 8700 --a------ c:\windows\inf\netserv.PNF
2006-01-12 18:12 86836 --a------ c:\windows\inf\monitor4.PNF
2006-01-12 18:12 8676 --a------ c:\windows\inf\s3savmx.PNF
2006-01-12 18:12 8644 --a------ c:\windows\inf\s3sav4.PNF
2006-01-12 18:12 8628 --a------ c:\windows\inf\tridxp.PNF
2006-01-12 18:12 8616 --a------ c:\windows\inf\netktc.PNF
2006-01-12 18:12 8604 --a------ c:\windows\inf\net713.PNF
2006-01-12 18:12 8572 --a------ c:\windows\inf\sgiu.PNF
2006-01-12 18:12 8532 --a------ c:\windows\inf\net5515n.PNF
2006-01-12 18:12 8512 --a------ c:\windows\inf\netdf650.PNF
2006-01-12 18:12 8508 --a------ c:\windows\inf\mwmbatam.PNF
2006-01-12 18:12 8484 --a------ c:\windows\inf\s3sav3d.PNF
2006-01-12 18:12 8452 --a------ c:\windows\inf\net559ib.PNF
2006-01-12 18:12 8428 --a------ c:\windows\inf\netrwan.PNF
2006-01-12 18:12 8412 --a------ c:\windows\inf\netpc100.PNF
2006-01-12 18:12 8408 --a------ c:\windows\inf\netrsvp.PNF
2006-01-12 18:12 8372 --a------ c:\windows\inf\mdmpbit.PNF
2006-01-12 18:12 83384 --a------ c:\windows\inf\net557.PNF
2006-01-12 18:12 8324 --a------ c:\windows\inf\netejxmp.PNF
2006-01-12 18:12 8284 --a------ c:\windows\inf\mpe.PNF
2006-01-12 18:12 8232 --a------ c:\windows\inf\netepro.PNF
2006-01-12 18:12 8224 --a------ c:\windows\inf\mdmvdot.PNF
2006-01-12 18:12 8180 --a------ c:\windows\inf\netlnev2.PNF
2006-01-12 18:12 81760 --a------ c:\windows\inf\mdmmts.PNF
2006-01-12 18:12 8172 --a------ c:\windows\inf\nettdkb.PNF
2006-01-12 18:12 80924 --a------ c:\windows\inf\mdmzyp.PNF
2006-01-12 18:12 80624 --a------ c:\windows\inf\mdmracal.PNF
2006-01-12 18:12 8020 --a------ c:\windows\inf\neo20xx.PNF
2006-01-12 18:12 8004 --a------ c:\windows\inf\stalport.PNF
2006-01-12 18:12 7988 --a------ c:\windows\inf\sis6306.PNF
2006-01-12 18:12 7980 --a------ c:\windows\inf\net650d.PNF
2006-01-12 18:12 7972 --a------ c:\windows\inf\netfa410.PNF
2006-01-12 18:12 79716 --a------ c:\windows\inf\mdmpenr.PNF
2006-01-12 18:12 7856 --a------ c:\windows\inf\mymusic.PNF
2006-01-12 18:12 7808 --a------ c:\windows\inf\sffdisk.PNF
2006-01-12 18:12 7748 --a------ c:\windows\inf\netali.PNF
2006-01-12 18:12 77168 --a------ c:\windows\inf\mdmltsft.PNF
2006-01-12 18:12 7716 --a------ c:\windows\inf\sisv6326.PNF
2006-01-12 18:12 76812 --a------ c:\windows\inf\mdmxircc.PNF
2006-01-12 18:12 7668 --a------ c:\windows\inf\netsla30.PNF
2006-01-12 18:12 7668 --a------ c:\windows\inf\mfcem28.PNF
2006-01-12 18:12 76292 --a------ c:\windows\inf\mdmltleo.PNF
2006-01-12 18:12 7616 --a------ c:\windows\inf\netfore.PNF
2006-01-12 18:12 76068 --a------ c:\windows\inf\mdmspq28.PNF
2006-01-12 18:12 7584 --a------ c:\windows\inf\netforeh.PNF
2006-01-12 18:12 7560 --a------ c:\windows\inf\netel515.PNF
2006-01-12 18:12 7540 --a------ c:\windows\inf\netsap.PNF
2006-01-12 18:12 75336 --a------ c:\windows\inf\mdmusrgl.PNF
2006-01-12 18:12 7528 --a------ c:\windows\inf\netrlw2k.PNF
2006-01-12 18:12 7472 --a------ c:\windows\inf\nettpro.PNF
2006-01-12 18:12 74536 --a------ c:\windows\inf\wdma_ali.PNF
2006-01-12 18:12 7452 --a------ c:\windows\inf\netlm.PNF
2006-01-12 18:12 7440 --a------ c:\windows\inf\netloop.PNF
2006-01-12 18:12 74344 --a------ c:\windows\inf\mdmusrk1.PNF
2006-01-12 18:12 74120 --a------ c:\windows\inf\mdmmhrtz.PNF
2006-01-12 18:12 74036 --a------ c:\windows\inf\mdmxirmp.PNF
2006-01-12 18:12 7388 --a------ c:\windows\inf\mfcem33.PNF
2006-01-12 18:12 7344 --a------ c:\windows\inf\netlm56.PNF
2006-01-12 18:12 7304 --a------ c:\windows\inf\netel5x9.PNF
2006-01-12 18:12 7300 --a------ c:\windows\inf\smi.PNF
2006-01-12 18:12 7288 --a------ c:\windows\inf\netfjvj.PNF
2006-01-12 18:12 7272 --a------ c:\windows\inf\netfjvi.PNF
2006-01-12 18:12 72136 --a------ c:\windows\inf\mdmmoto.PNF
2006-01-12 18:12 7176 --a------ c:\windows\inf\netw926.PNF
2006-01-12 18:12 7172 --a------ c:\windows\inf\ramdisk.PNF
2006-01-12 18:12 7132 --a------ c:\windows\inf\netex10.PNF
2006-01-12 18:12 71236 --a------ c:\windows\inf\mdmrock4.PNF
2006-01-12 18:12 71144 --a------ c:\windows\inf\mdmx5560.PNF
2006-01-12 18:12 7096 --a------ c:\windows\inf\ntgrip.PNF
2006-01-12 18:12 7032 --a------ c:\windows\inf\netepvcm.PNF
2006-01-12 18:12 7028 --a------ c:\windows\inf\netwzc.PNF
2006-01-12 18:12 7012 --a------ c:\windows\inf\msrio.PNF
2006-01-12 18:12 6920 --a------ c:\windows\inf\msrio8.PNF
2006-01-12 18:12 6916 --a------ c:\windows\inf\ppa3.PNF
2006-01-12 18:12 6916 --a------ c:\windows\inf\net3sr.PNF
2006-01-12 18:12 6868 --a------ c:\windows\inf\ppa.PNF
2006-01-12 18:12 68664 --a------ c:\windows\inf\mdmpctel.PNF
2006-01-12 18:12 68364 --a------ c:\windows\inf\umax.PNF
2006-01-12 18:12 6800 --a------ c:\windows\inf\netrndis.PNF
2006-01-12 18:12 6776 --a------ c:\windows\inf\mdmrisa.PNF
2006-01-12 18:12 6768 --a------ c:\windows\inf\msnike.PNF
2006-01-12 18:12 6740 --a------ c:\windows\inf\s3trio3d.PNF
2006-01-12 18:12 6688 --a------ c:\windows\inf\mscpqpa1.PNF
2006-01-12 18:12 6668 --a------ c:\windows\inf\netw940.PNF
2006-01-12 18:12 6660 --a------ c:\windows\inf\ntapm.PNF
2006-01-12 18:12 6648 --a------ c:\windows\inf\netauni.PNF
2006-01-12 18:12 6644 --a------ c:\windows\inf\wmtour.PNF
2006-01-12 18:12 6636 --a------ c:\windows\inf\mfsupra.PNF
2006-01-12 18:12 65804 --a------ c:\windows\inf\mdmtdk.PNF
2006-01-12 18:12 6568 --a------ c:\windows\inf\netambi.PNF
2006-01-12 18:12 6484 --a------ c:\windows\inf\netepvcp.PNF
2006-01-12 18:12 6464 --a------ c:\windows\inf\sbp2.PNF
2006-01-12 18:12 64544 --a------ c:\windows\inf\mdmmcom.PNF
2006-01-12 18:12 6412 --a------ c:\windows\inf\netsmc.PNF
2006-01-12 18:12 6348 --a------ c:\windows\inf\nettun.PNF
2006-01-12 18:12 63176 --a------ c:\windows\inf\mdmmct.PNF
2006-01-12 18:12 63168 --a------ c:\windows\inf\wdma_ctl.PNF
2006-01-12 18:12 6260 --a------ c:\windows\inf\netlanep.PNF
2006-01-12 18:12 6236 --a------ c:\windows\inf\net10.PNF
2006-01-12 18:12 6208 --a------ c:\windows\inf\netpschd.PNF
2006-01-12 18:12 60940 --a------ c:\windows\inf\msnetmtg.PNF
2006-01-12 18:12 6076 --a------ c:\windows\inf\mdmsgsml.PNF
2006-01-12 18:12 6056 --a------ c:\windows\inf\netnb.PNF
2006-01-12 18:12 5988 --a------ c:\windows\inf\srchasst.PNF
2006-01-12 18:12 59804 --a------ c:\windows\inf\tape.PNF
2006-01-12 18:12 5896 --a------ c:\windows\inf\netbrdgm.PNF
2006-01-12 18:12 58752 --a------ c:\windows\inf\mdmisdn.PNF
2006-01-12 18:12 5860 --a------ c:\windows\inf\ovcomp.PNF
2006-01-12 18:12 5836 --a------ c:\windows\inf\multiprt.PNF
2006-01-12 18:12 5792 --a------ c:\windows\inf\ndisuio.PNF
2006-01-12 18:12 57548 --a------ c:\windows\inf\swnt.PNF
2006-01-12 18:12 57460 --a------ c:\windows\inf\netdgdxb.PNF
2006-01-12 18:12 57224 --a------ c:\windows\inf\mdmpp.PNF
2006-01-12 18:12 56940 --a------ c:\windows\inf\wmp.PNF
2006-01-12 18:12 5592 --a------ c:\windows\inf\mf.PNF
2006-01-12 18:12 5492 --a------ c:\windows\inf\netbrdgs.PNF
2006-01-12 18:12 54848 --a------ c:\windows\inf\mwtpdsp.PNF
2006-01-12 18:12 53880 --a------ c:\windows\inf\mdmti.PNF
2006-01-12 18:12 5356 --a------ c:\windows\inf\netgpc.PNF
2006-01-12 18:12 5340 --a------ c:\windows\inf\netlanem.PNF
2006-01-12 18:12 53292 --a------ c:\windows\inf\nv4_disp.PNF
2006-01-12 18:12 53128 --a------ c:\windows\inf\mdmtosh.PNF
2006-01-12 18:12 50624 --a------ c:\windows\inf\mdmrock3.PNF
2006-01-12 18:12 4964 --a------ c:\windows\inf\volsnap.PNF
2006-01-12 18:12 49096 --a------ c:\windows\inf\mdmosi.PNF
2006-01-12 18:12 4792 --a------ c:\windows\inf\unknown.PNF
2006-01-12 18:12 46148 --a------ c:\windows\inf\mdmntstm.PNF
2006-01-12 18:12 45896 --a------ c:\windows\inf\mdmsupr3.PNF
2006-01-12 18:12 45772 --a------ c:\windows\inf\pcmcia.PNF
2006-01-12 18:12 45648 --a------ c:\windows\inf\wdma_csf.PNF
2006-01-12 18:12 45180 --a------ c:\windows\inf\netrass.PNF
2006-01-12 18:12 44908 --a------ c:\windows\inf\wdma_int.PNF
2006-01-12 18:12 44876 --a------ c:\windows\inf\mdmsier.PNF
2006-01-12 18:12 4416 --a------ c:\windows\inf\netcis.PNF
2006-01-12 18:12 4368 --a------ c:\windows\inf\vgx.PNF
2006-01-12 18:12 43672 --a------ c:\windows\inf\wdma_m2e.PNF
2006-01-12 18:12 43508 --a------ c:\windows\inf\wdma_sis.PNF
2006-01-12 18:12 42660 --a------ c:\windows\inf\mdmlasno.PNF
2006-01-12 18:12 42088 --a------ c:\windows\inf\wdma_ess.PNF
2006-01-12 18:12 41660 --a------ c:\windows\inf\wdma_csc.PNF
2006-01-12 18:12 41332 --a------ c:\windows\inf\mmopt.PNF
2006-01-12 18:12 4096 --a------ c:\windows\inf\secdrv.PNF
2006-01-12 18:12 40676 --a------ c:\windows\inf\mdmsuprv.PNF
2006-01-12 18:12 4000 --a------ c:\windows\inf\mdmsetup.PNF
2006-01-12 18:12 39416 --a------ c:\windows\inf\mdmosice.PNF
2006-01-12 18:12 38476 --a------ c:\windows\inf\shell.PNF
2006-01-12 18:12 38304 --a------ c:\windows\inf\nettcpip.PNF
2006-01-12 18:12 38256 --a------ c:\windows\inf\sceregvl.PNF
2006-01-12 18:12 38224 --a------ c:\windows\inf\mwavmdm1.PNF
2006-01-12 18:12 37528 --a------ c:\windows\inf\scsidev.PNF
2006-01-12 18:12 37312 --a------ c:\windows\inf\sdwndr2k.PNF
2006-01-12 18:12 3696 --a------ c:\windows\inf\netclass.PNF
2006-01-12 18:12 3668 --a------ c:\windows\inf\minioc.PNF
2006-01-12 18:12 36624 --a------ c:\windows\inf\wdma_ens.PNF
2006-01-12 18:12 36404 --a------ c:\windows\inf\mdmlucnt.PNF
2006-01-12 18:12 36372 --a------ c:\windows\inf\smartcrd.PNF
2006-01-12 18:12 35964 --a------ c:\windows\inf\msoe50.PNF
2006-01-12 18:12 35832 --a------ c:\windows\inf\parhmse.PNF
2006-01-12 18:12 35276 --a------ c:\windows\inf\wdma_azt.PNF
2006-01-12 18:12 34904 --a------ c:\windows\inf\netb57xp.PNF
2006-01-12 18:12 34272 --a------ c:\windows\inf\mdmsun2.PNF
2006-01-12 18:12 34060 --a------ c:\windows\inf\nvdm.PNF
2006-01-12 18:12 33516 --a------ c:\windows\inf\wdma_via.PNF
2006-01-12 18:12 31812 --a------ c:\windows\inf\wdma_cwr.PNF
2006-01-12 18:12 3164 --a------ c:\windows\inf\syscomp.PNF
2006-01-12 18:12 30644 --a------ c:\windows\inf\mplayer2.PNF
2006-01-12 18:12 306060 --a------ c:\windows\inf\mdmrpci.PNF
2006-01-12 18:12 30252 --a------ c:\windows\inf\wdma_ym2.PNF
2006-01-12 18:12 301312 --a------ c:\windows\inf\wdma10k1.PNF
2006-01-12 18:12 29708 --a------ c:\windows\inf\mdmtdkj5.PNF
2006-01-12 18:12 29420 --a------ c:\windows\inf\nete1000.PNF
2006-01-12 18:12 29140 --a------ c:\windows\inf\msmscsi.PNF
2006-01-12 18:12 27880 --a------ c:\windows\inf\netwlan.PNF
2006-01-12 18:12 27860 --a------ c:\windows\inf\mdmpace.PNF
2006-01-12 18:12 27740 --a------ c:\windows\inf\netmadge.PNF
2006-01-12 18:12 27016 --a------ c:\windows\inf\mdmtdkj2.PNF
2006-01-12 18:12 26724 --a------ c:\windows\inf\mdmvv.PNF
2006-01-12 18:12 26716 --a------ c:\windows\inf\mdmtdkj3.PNF
2006-01-12 18:12 26576 --a------ c:\windows\inf\net21x4.PNF
2006-01-12 18:12 26320 --a------ c:\windows\inf\secrecs.PNF
2006-01-12 18:12 2608 --a------ c:\windows\inf\SVCPACK.PNF
2006-01-12 18:12 25996 --a------ c:\windows\inf\MDMJF56E.PNF
2006-01-12 18:12 25888 --a------ c:\windows\inf\wdma_rip.PNF
2006-01-12 18:12 25484 --a------ c:\windows\inf\net8511.PNF
2006-01-12 18:12 24920 --a------ c:\windows\inf\usbvideo.PNF
2006-01-12 18:12 24812 --a------ c:\windows\inf\ovcam.PNF
2006-01-12 18:12 24792 --a------ c:\windows\inf\wdma_neo.PNF
2006-01-12 18:12 24516 --a------ c:\windows\inf\mdmtdkj4.PNF
2006-01-12 18:12 24424 --a------ c:\windows\inf\netirsir.PNF
2006-01-12 18:12 23852 --a------ c:\windows\inf\mdmusrg.PNF
2006-01-12 18:12 23816 --a------ c:\windows\inf\mstape.PNF
2006-01-12 18:12 23712 --a------ c:\windows\inf\mdmrock.PNF
2006-01-12 18:12 23608 --a------ c:\windows\inf\mdmsiil6.PNF
2006-01-12 18:12 23448 --a------ c:\windows\inf\netsk_fp.PNF
2006-01-12 18:12 23408 --a------ c:\windows\inf\mdmsii64.PNF
2006-01-12 18:12 23188 --a------ c:\windows\inf\mdmtron.PNF
2006-01-12 18:12 23000 --a------ c:\windows\inf\mdmsgsmu.PNF
2006-01-12 18:12 22196 --a------ c:\windows\inf\nvts.PNF
2006-01-12 18:12 22148 --a------ c:\windows\inf\nvct.PNF
2006-01-12 18:12 22004 --a------ c:\windows\inf\mdmnttd6.PNF
2006-01-12 18:12 22000 --a------ c:\windows\inf\netnf3.PNF
2006-01-12 18:12 21996 --a------ c:\windows\inf\mdmnttd2.PNF
2006-01-12 18:12 21944 --a------ c:\windows\inf\scsi.PNF
2006-01-12 18:12 21768 --a------ c:\windows\inf\wmdm.PNF
2006-01-12 18:12 21736 --a------ c:\windows\inf\netsis.PNF
2006-01-12 18:12 21352 --a------ c:\windows\inf\wab50.PNF
2006-01-12 18:12 20868 --a------ c:\windows\inf\mdmlasat.PNF
2006-01-12 18:12 20344 --a------ c:\windows\inf\netmscli.PNF
2006-01-12 18:12 20328 --a------ c:\windows\inf\mdmneuhs.PNF
2006-01-12 18:12 20260 --a------ c:\windows\inf\mdmtdkj7.PNF
2006-01-12 18:12 20228 --a------ c:\windows\inf\spx.PNF
2006-01-12 18:12 20216 --a------ c:\windows\inf\mdmnova.PNF
2006-01-12 18:12 20132 --a------ c:\windows\inf\mdmmoto1.PNF
2006-01-12 18:12 199760 --a------ c:\windows\inf\mdmmhzel.PNF
2006-01-12 18:12 19480 --a------ c:\windows\inf\netel90b.PNF
2006-01-12 18:12 19408 --a------ c:\windows\inf\netwv48.PNF
2006-01-12 18:12 19344 --a------ c:\windows\inf\netx500.PNF
2006-01-12 18:12 19268 --a------ c:\windows\inf\mdmpin.PNF
2006-01-12 18:12 19048 --a------ c:\windows\inf\mdmolic.PNF
2006-01-12 18:12 18984 --a------ c:\windows\inf\mfcem56.PNF
2006-01-12 18:12 18672 --a------ c:\windows\inf\wdma_ne2.PNF
2006-01-12 18:12 18624 --a------ c:\windows\inf\netklsi.PNF
2006-01-12 18:12 18540 --a------ c:\windows\inf\mdmmod.PNF
2006-01-12 18:12 18476 --a------ c:\windows\inf\ricoh.PNF
2006-01-12 18:12 18216 --a------ c:\windows\inf\wdma_avc.PNF
2006-01-12 18:12 18112 --a------ c:\windows\inf\wdmjoy.PNF
2006-01-12 18:12 17936 --a------ c:\windows\inf\netamd2.PNF
2006-01-12 18:12 17772 --a------ c:\windows\inf\netcpqi.PNF
2006-01-12 18:12 17712 --a------ c:\windows\inf\netibm.PNF
2006-01-12 18:12 17460 --a------ c:\windows\inf\mdmnttp2.PNF
2006-01-12 18:12 17416 --a------ c:\windows\inf\wdma_ymh.PNF
2006-01-12 18:12 17416 --a------ c:\windows\inf\mdmmega.PNF
2006-01-12 18:12 17392 --a------ c:\windows\inf\netcpqg.PNF
2006-01-12 18:12 17332 --a------ c:\windows\inf\netel99x.PNF
2006-01-12 18:12 17320 --a------ c:\windows\inf\mdmtdkj6.PNF
2006-01-12 18:12 17240 --a------ c:\windows\inf\oobe.PNF
2006-01-12 18:12 17180 --a------ c:\windows\inf\memcard.PNF
2006-01-12 18:12 16952 --a------ c:\windows\inf\pmxmcro.PNF
2006-01-12 18:12 16924 --a------ c:\windows\inf\mwremove.PNF
2006-01-12 18:12 168904 --a------ c:\windows\inf\mdmwhql0.PNF
2006-01-12 18:12 16524 --a------ c:\windows\inf\netcbe.PNF
2006-01-12 18:12 16504 --a------ c:\windows\inf\mdmmc288.PNF
2006-01-12 18:12 16416 --a------ c:\windows\inf\netan983.PNF
2006-01-12 18:12 16332 --a------ c:\windows\inf\mdmtexas.PNF
2006-01-12 18:12 16196 --a------ c:\windows\inf\mdmnttp.PNF
2006-01-12 18:12 16156 --a------ c:\windows\inf\netnwlnk.PNF
2006-01-12 18:12 15924 --a------ c:\windows\inf\mpsstln.PNF
2006-01-12 18:12 15908 --a------ c:\windows\inf\wmfsdk.PNF
2006-01-12 18:12 15840 --a------ c:\windows\inf\mdmpsion.PNF
2006-01-12 18:12 15748 --a------ c:\windows\inf\net83820.PNF
2006-01-12 18:12 15720 --a------ c:\windows\inf\shl_img.PNF
2006-01-12 18:12 15620 --a------ c:\windows\inf\wsh.PNF
2006-01-12 18:12 1536452 --a------ c:\windows\inf\mdmrpciw.PNF
2006-01-12 18:12 15364 --a------ c:\windows\inf\msmusb.PNF
2006-01-12 18:12 15196 --a------ c:\windows\inf\moviemk.PNF
2006-01-12 18:12 15124 --a------ c:\windows\inf\netcicap.PNF
2006-01-12 18:12 14892 --a------ c:\windows\inf\netvt86.PNF
2006-01-12 18:12 14812 --a------ c:\windows\inf\netcb325.PNF
2006-01-12 18:12 14768 --a------ c:\windows\inf\netnm.PNF
2006-01-12 18:12 14740 --a------ c:\windows\inf\netwlan2.PNF
2006-01-12 18:12 14720 --a------ c:\windows\inf\netsk98.PNF
2006-01-12 18:12 14696 --a------ c:\windows\inf\netosi2c.PNF
2006-01-12 18:12 14684 --a------ c:\windows\inf\netnovel.PNF
2006-01-12 18:12 14620 --a------ c:\windows\inf\netibm2.PNF
2006-01-12 18:12 14536 --a------ c:\windows\inf\mdmsmart.PNF
2006-01-12 18:12 14388 --a------ c:\windows\inf\netcem56.PNF
2006-01-12 18:12 14352 --a------ c:\windows\inf\net3c985.PNF
2006-01-12 18:12 14128 --a------ c:\windows\inf\netce3.PNF
2006-01-12 18:12 13960 --a------ c:\windows\inf\mstask.PNF
2006-01-12 18:12 139136 --a------ c:\windows\inf\sapi5.PNF
2006-01-12 18:12 13828 --a------ c:\windows\inf\phil2vid.PNF
2006-01-12 18:12 13800 --a------ c:\windows\inf\mdmntt1.PNF
2006-01-12 18:12 134964 --a------ c:\windows\inf\mdmzyxlg.PNF
2006-01-12 18:12 134308 --a------ c:\windows\inf\mdmsupra.PNF
2006-01-12 18:12 13300 --a------ c:\windows\inf\philtune.PNF
2006-01-12 18:12 13244 --a------ c:\windows\inf\mdmnokia.PNF
2006-01-12 18:12 13172 --a------ c:\windows\inf\phildec.PNF
2006-01-12 18:12 13020 --a------ c:\windows\inf\netip6.PNF
2006-01-12 18:12 129992 --a------ c:\windows\inf\mdmzoom.PNF
2006-01-12 18:12 12992 --a------ c:\windows\inf\pchealth.PNF
2006-01-12 18:12 12940 --a------ c:\windows\inf\netosi5.PNF
2006-01-12 18:12 12656 --a------ c:\windows\inf\netcpqc.PNF
2006-01-12 18:12 12644 --a------ c:\windows\inf\mdmkortx.PNF
2006-01-12 18:12 126152 --a------ c:\windows\inf\mdmomrn3.PNF
2006-01-12 18:12 12612 --a------ c:\windows\inf\netel980.PNF
2006-01-12 18:12 12604 --a------ c:\windows\inf\netbrzw.PNF
2006-01-12 18:12 12596 --a------ c:\windows\inf\phdsext.PNF
2006-01-12 18:12 125636 --a------ c:\windows\inf\mdmrock5.PNF
2006-01-12 18:12 12556 --a------ c:\windows\inf\perm2.PNF
2006-01-12 18:12 12388 --a------ c:\windows\inf\spxports.PNF
2006-01-12 18:12 12380 --a------ c:\windows\inf\ovsound.PNF
2006-01-12 18:12 123012 --a------ c:\windows\inf\wdma_es3.PNF
2006-01-12 18:12 12292 --a------ c:\windows\inf\mfosi5.PNF
2006-01-12 18:12 12224 --a------ c:\windows\inf\mxport.PNF
2006-01-12 18:12 122052 --a------ c:\windows\inf\mdmzyxel.PNF
2006-01-12 18:12 12188 --a------ c:\windows\inf\netana.PNF
2006-01-12 18:12 12104 --a------ c:\windows\inf\netrast.PNF
2006-01-12 18:12 12096 --a------ c:\windows\inf\netdlh5x.PNF
2006-01-12 18:12 120720 --a------ c:\windows\inf\monitor5.PNF
2006-01-12 18:12 12064 --a------ c:\windows\inf\sr.PNF
2006-01-12 18:12 11984 --a------ c:\windows\inf\netel90a.PNF
2006-01-12 18:12 11944 --a------ c:\windows\inf\wceusbsh.PNF
2006-01-12 18:12 11912 --a------ c:\windows\inf\netasp2k.PNF
2006-01-12 18:12 11892 --a------ c:\windows\inf\mdmke.PNF
2006-01-12 18:12 11764 --a------ c:\windows\inf\modemcsa.PNF
2006-01-12 18:12 11696 --a------ c:\windows\inf\mdmminij.PNF
2006-01-12 18:12 11660 --a------ c:\windows\inf\srusbusd.PNF
2006-01-12 18:12 11552 --a------ c:\windows\inf\net3c589.PNF
2006-01-12 18:12 11532 --a------ c:\windows\inf\nete100i.PNF
2006-01-12 18:12 11516 --a------ c:\windows\inf\mdmnttme.PNF
2006-01-12 18:12 11504 --a------ c:\windows\inf\mdmmcd.PNF
2006-01-12 18:12 11480 --a------ c:\windows\inf\mdmoptn.PNF
2006-01-12 18:12 11416 --a------ c:\windows\inf\qmgr.PNF
2006-01-12 18:12 11388 --a------ c:\windows\inf\netpwr2.PNF
2006-01-12 18:12 11340 --a------ c:\windows\inf\Mdmnis2u.PNF
2006-01-12 18:12 11312 --a------ c:\windows\inf\nettiger.PNF
2006-01-12 18:12 11292 --a------ c:\windows\inf\mdmsun1.PNF
2006-01-12 18:12 11268 --a------ c:\windows\inf\Mdmnis1u.PNF
2006-01-12 18:12 11252 --a------ c:\windows\inf\sisgr.PNF
2006-01-12 18:12 112360 --a------ c:\windows\inf\monitor8.PNF
2006-01-12 18:12 11180 --a------ c:\windows\inf\netmhzn5.PNF
2006-01-12 18:12 11132 --a------ c:\windows\inf\netel574.PNF
2006-01-12 18:12 11068 --a------ c:\windows\inf\mfmhzn5.PNF
2006-01-12 18:12 110412 --a------ c:\windows\inf\mdmmetri.PNF
2006-01-12 18:12 11016 --a------ c:\windows\inf\netx56n5.PNF
2006-01-12 18:12 10992 --a------ c:\windows\inf\umaxpp.PNF
2006-01-12 18:12 10896 --a------ c:\windows\inf\netepicn.PNF
2006-01-12 18:12 10884 --a------ c:\windows\inf\netngr.PNF
2006-01-12 18:12 10820 --a------ c:\windows\inf\net656n5.PNF
2006-01-12 18:12 108188 --a------ c:\windows\inf\monitor.PNF
2006-01-12 18:12 10700 --a------ c:\windows\inf\netrtpnt.PNF
2006-01-12 18:12 10644 --a------ c:\windows\inf\wbfirdma.PNF
2006-01-12 18:12 10632 --a------ c:\windows\inf\sdbus.PNF
2006-01-12 18:12 10620 --a------ c:\windows\inf\ptpusb.PNF
2006-01-12 18:12 10608 --a------ c:\windows\inf\netdm.PNF
2006-01-12 18:12 10588 --a------ c:\windows\inf\net575nt.PNF
2006-01-12 18:12 10572 --a------ c:\windows\inf\mdmnttte.PNF
2006-01-12 18:12 105552 --a------ c:\windows\inf\pnpscsi.PNF
2006-01-12 18:12 10484 --a------ c:\windows\inf\phil1vid.PNF
2006-01-12 18:12 10460 --a------ c:\windows\inf\netctmrk.PNF
2006-01-12 18:12 10448 --a------ c:\windows\inf\netdav.PNF
2006-01-12 18:12 10424 --a------ c:\windows\inf\mdmusrsp.PNF
2006-01-12 18:12 10424 --a------ c:\windows\inf\mdmpn1.PNF
2006-01-12 18:12 10364 --a------ c:\windows\inf\Mdmnis3t.PNF
2006-01-12 18:12 10360 --a------ c:\windows\inf\netamdhl.PNF
2006-01-12 18:12 10340 --a------ c:\windows\inf\Mdmnis5t.PNF
2006-01-12 18:12 10328 --a------ c:\windows\inf\netcpqmt.PNF
2006-01-12 18:12 10316 --a------ c:\windows\inf\netsnip.PNF
2006-01-12 18:12 10220 --a------ c:\windows\inf\netpnic.PNF
2006-01-12 18:12 101404 --a------ c:\windows\inf\wdma_es2.PNF
2006-01-12 18:12 101148 --a------ c:\windows\inf\monitor2.PNF
2006-01-12 18:12 10080 --a------ c:\windows\inf\netce2.PNF
2006-01-12 18:12 10004 --a------ c:\windows\inf\mgau.PNF
2006-01-12 18:11 99404 --a------ c:\windows\inf\mdm3mini.PNF
2006-01-12 18:11 9908 --a------ c:\windows\inf\banshee.PNF
2006-01-12 18:11 97624 --a------ c:\windows\inf\mdm3com.PNF
2006-01-12 18:11 96712 --a------ c:\windows\inf\mdmgl006.PNF
2006-01-12 18:11 9548 --a------ c:\windows\inf\avc.PNF
2006-01-12 18:11 9476 --a------ c:\windows\inf\HidDigi.PNF
2006-01-12 18:11 94532 --a------ c:\windows\inf\atiixpag.PNF
2006-01-12 18:11 9420 --a------ c:\windows\inf\atirage3.PNF
2006-01-12 18:11 93596 --a------ c:\windows\inf\mdmgl010.PNF
2006-01-12 18:11 91508 --a------ c:\windows\inf\mdmcm28.PNF
2006-01-12 18:11 9148 --a------ c:\windows\inf\irstusb.PNF
2006-01-12 18:11 8996 --a------ c:\windows\inf\i740nt5.PNF
2006-01-12 18:11 89852 --a------ c:\windows\inf\mdmgl002.PNF
2006-01-12 18:11 8948 --a------ c:\windows\inf\irmk7w2k.PNF
2006-01-12 18:11 8924 --a------ c:\windows\inf\brmfcsto.PNF
2006-01-12 18:11 8884 --a------ c:\windows\inf\irdaalif.PNF
2006-01-12 18:11 8824 --a------ c:\windows\inf\mdmairte.PNF
2006-01-12 18:11 8664 --a------ c:\windows\inf\dshowext.PNF
2006-01-12 18:11 8648 --a------ c:\windows\inf\brmfcumd.PNF
2006-01-12 18:11 8560 --a------ c:\windows\inf\mdmhaeu.PNF
2006-01-12 18:11 8428 --a------ c:\windows\inf\apcompat.PNF
2006-01-12 18:11 8384 --a------ c:\windows\inf\digiisdn.PNF
2006-01-12 18:11 83728 --a------ c:\windows\inf\ie.PNF
2006-01-12 18:11 8248 --a------ c:\windows\inf\adm_mult.PNF
2006-01-12 18:11 82384 --a------ c:\windows\inf\mdmgl005.PNF
2006-01-12 18:11 8168 --a------ c:\windows\inf\digirprt.PNF
2006-01-12 18:11 81048 --a------ c:\windows\inf\mdmbcmsm.PNF
2006-01-12 18:11 8032 --a------ c:\windows\inf\bthpan.PNF
2006-01-12 18:11 7984 --a------ c:\windows\inf\ibmvcap.PNF
2006-01-12 18:11 7964 --a------ c:\windows\inf\digirp.PNF
2006-01-12 18:11 77992 --a------ c:\windows\inf\mdmdcm5.PNF
2006-01-12 18:11 7780 --a------ c:\windows\inf\hidbth.PNF
2006-01-12 18:11 77752 --a------ c:\windows\inf\mdmati.PNF
2006-01-12 18:11 77228 --a------ c:\windows\inf\mdmgl001.PNF
2006-01-12 18:11 7256 --a------ c:\windows\inf\61883.PNF
2006-01-12 18:11 72016 --a------ c:\windows\inf\mdmgen.PNF
2006-01-12 18:11 7024 --a------ c:\windows\inf\hpdigwia.PNF
2006-01-12 18:11 69848 --a------ c:\windows\inf\mdmhay2.PNF
2006-01-12 18:11 69540 --a------ c:\windows\inf\mdmgatew.PNF
2006-01-12 18:11 69256 --a------ c:\windows\inf\biosinfo.PNF
2006-01-12 18:11 6864 --a------ c:\windows\inf\cyclom-y.PNF
2006-01-12 18:11 68340 --a------ c:\windows\inf\mdmcxsf2.PNF
2006-01-12 18:11 68016 --a------ c:\windows\inf\dot4.PNF
2006-01-12 18:11 6732 --a------ c:\windows\inf\cyclad-z.PNF
2006-01-12 18:11 66232 --a------ c:\windows\inf\brmfcmf.PNF
2006-01-12 18:11 6604 --a------ c:\windows\inf\dfrg.PNF
2006-01-12 18:11 6584 --a------ c:\windows\inf\eqnport.PNF
2006-01-12 18:11 6460 --a------ c:\windows\inf\dot4prt.PNF
2006-01-12 18:11 6452 --a------ c:\windows\inf\adm_port.PNF
2006-01-12 18:11 64292 --a------ c:\windows\inf\mdmboca.PNF
2006-01-12 18:11 6424 --a------ c:\windows\inf\digiasyn.PNF
2006-01-12 18:11 628064 --a------ c:\windows\inf\mdmcxsft.PNF
2006-01-12 18:11 62708 --a------ c:\windows\inf\mdmetech.PNF
2006-01-12 18:11 6224 --a------ c:\windows\inf\bthprint.PNF
2006-01-12 18:11 6092 --a------ c:\windows\inf\enum1394.PNF
2006-01-12 18:11 5972 --a------ c:\windows\inf\bthspp.PNF
2006-01-12 18:11 59556 --a------ c:\windows\inf\mdmhandy.PNF
2006-01-12 18:11 59372 --a------ c:\windows\inf\mdmgl003.PNF
2006-01-12 18:11 5872 --a------ c:\windows\inf\epcfw2k.PNF
2006-01-12 18:11 5856 --a------ c:\windows\inf\epstw2k.PNF
2006-01-12 18:11 5844 --a------ c:\windows\inf\genprint.PNF
2006-01-12 18:11 57572 --a------ c:\windows\inf\mdmgl008.PNF
2006-01-12 18:11 57164 --a------ c:\windows\inf\mdmdyna.PNF
2006-01-12 18:11 56852 --a------ c:\windows\inf\mdm656n5.PNF
2006-01-12 18:11 5596 --a------ c:\windows\inf\1394vdbg.PNF
2006-01-12 18:11 53980 --a------ c:\windows\inf\display.PNF
2006-01-12 18:11 5004 --a------ c:\windows\inf\fltmgr.PNF
2006-01-12 18:11 49228 --a------ c:\windows\inf\mdmess.PNF
2006-01-12 18:11 49072 --a------ c:\windows\inf\mdm3cpcm.PNF
2006-01-12 18:11 47576 --a------ c:\windows\inf\mdmcpq2.PNF
2006-01-12 18:11 47528 --a------ c:\windows\inf\brmfcmdm.PNF
2006-01-12 18:11 47316 --a------ c:\windows\inf\mdmexp.PNF
2006-01-12 18:11 45784 --a------ c:\windows\inf\atixpwdm.PNF
2006-01-12 18:11 45632 --a------ c:\windows\inf\epsnscan.PNF
2006-01-12 18:11 4428 --a------ c:\windows\inf\axant5.PNF
2006-01-12 18:11 43708 --a------ c:\windows\inf\mdm5674a.PNF
2006-01-12 18:11 43280 --a------ c:\windows\inf\ati1xwdm.PNF
2006-01-12 18:11 43240 --a------ c:\windows\inf\mdmcom1.PNF
2006-01-12 18:11 43228 --a------ c:\windows\inf\mdmarch.PNF
2006-01-12 18:11 42992 --a------ c:\windows\inf\defltwk.PNF
2006-01-12 18:11 42676 --a------ c:\windows\inf\mdmgcs.PNF
2006-01-12 18:11 41732 --a------ c:\windows\inf\atividin.PNF
2006-01-12 18:11 41668 --a------ c:\windows\inf\dgaport.PNF
2006-01-12 18:11 41068 --a------ c:\windows\inf\hpscan.PNF
2006-01-12 18:11 4084 --a------ c:\windows\inf\drm.PNF
2006-01-12 18:11 40560 --a------ c:\windows\inf\mdmbtmdm.PNF
2006-01-12 18:11 39396 --a------ c:\windows\inf\devxprop.PNF
2006-01-12 18:11 3924 --a------ c:\windows\inf\legcydrv.PNF
2006-01-12 18:11 38636 --a------ c:\windows\inf\atimpab.PNF
2006-01-12 18:11 37336 --a------ c:\windows\inf\brmfcwia.PNF
2006-01-12 18:11 34212 --a------ c:\windows\inf\mdmatt.PNF
2006-01-12 18:11 34084 --a------ c:\windows\inf\mdmdcm6.PNF
2006-01-12 18:11 33636 --a------ c:\windows\inf\divac.PNF
2006-01-12 18:11 33304 --a------ c:\windows\inf\avmisdn.PNF
2006-01-12 18:11 3260 --a------ c:\windows\inf\icminst.PNF
2006-01-12 18:11 31784 --a------ c:\windows\inf\mdmdigi.PNF
2006-01-12 18:11 31012 --a------ c:\windows\inf\corelist.PNF
2006-01-12 18:11 30748 --a------ c:\windows\inf\mdmiodat.PNF
2006-01-12 18:11 30596 --a------ c:\windows\inf\mdmeiger.PNF
2006-01-12 18:11 30280 --a------ c:\windows\inf\mchgr.PNF
2006-01-12 18:11 29512 --a------ c:\windows\inf\mdmgsm.PNF
2006-01-12 18:11 29316 --a------ c:\windows\inf\atim128.PNF
2006-01-12 18:11 29012 --a------ c:\windows\inf\atiixpaa.PNF
2006-01-12 18:11 28908 --a------ c:\windows\inf\mdminfot.PNF
2006-01-12 18:11 28828 --a------ c:\windows\inf\3dfxvs2k.PNF
2006-01-12 18:11 2856 --a------ c:\windows\inf\appmig.PNF
2006-01-12 18:11 27876 --a------ c:\windows\inf\dimaps.PNF
2006-01-12 18:11 27208 --a------ c:\windows\inf\mdmintel.PNF
2006-01-12 18:11 26872 --a------ c:\windows\inf\mdmeric2.PNF
2006-01-12 18:11 26676 --a------ c:\windows\inf\mdmaiwa5.PNF
2006-01-12 18:11 26564 --a------ c:\windows\inf\dvd.PNF
2006-01-12 18:11 2648 --a------ c:\windows\inf\fsvgadel.PNF
2006-01-12 18:11 26316 --a------ c:\windows\inf\mdmbw561.PNF
2006-01-12 18:11 26132 --a------ c:\windows\inf\irnsc.PNF
2006-01-12 18:11 25780 --a------ c:\windows\inf\bth.PNF
2006-01-12 18:11 24624 --a------ c:\windows\inf\mdmdf56F.PNF
2006-01-12 18:11 24468 --a------ c:\windows\inf\mdmcodex.PNF
2006-01-12 18:11 23988 --a------ c:\windows\inf\mdmaiwa.PNF
2006-01-12 18:11 23888 --a------ c:\windows\inf\mdmbsb.PNF
2006-01-12 18:11 23876 --a------ c:\windows\inf\fjtscan.PNF
2006-01-12 18:11 23804 --a------ c:\windows\inf\divasrv.PNF
2006-01-12 18:11 23720 --a------ c:\windows\inf\dwup.PNF
2006-01-12 18:11 2312 --a------ c:\windows\inf\mdmchipv.PNF
2006-01-12 18:11 23052 --a------ c:\windows\inf\hpojscan.PNF
2006-01-12 18:11 22804 --a------ c:\windows\inf\image.PNF
2006-01-12 18:11 22428 --a------ c:\windows\inf\mdmc26a.PNF
2006-01-12 18:11 22040 --a------ c:\windows\inf\kdk2x0.PNF
2006-01-12 18:11 21904 --a------ c:\windows\inf\dgasync.PNF
2006-01-12 18:11 21792 --a------ c:\windows\inf\cyzport.PNF
2006-01-12 18:11 21512 --a------ c:\windows\inf\ctmaport.PNF
2006-01-12 18:11 21376 --a------ c:\windows\inf\mdmaus.PNF
2006-01-12 18:11 21372 --a------ c:\windows\inf\mdmcrtix.PNF
2006-01-12 18:11 21124 --a------ c:\windows\inf\mdmfj2.PNF
2006-01-12 18:11 20368 --a------ c:\windows\inf\mdmdgden.PNF
2006-01-12 18:11 20236 --a------ c:\windows\inf\bda.PNF
2006-01-12 18:11 20192 --a------ c:\windows\inf\mdmeric.PNF
2006-01-12 18:11 20052 --a------ c:\windows\inf\mdmdgitn.PNF
2006-01-12 18:11 19568 --a------ c:\windows\inf\mdmatm2k.PNF
2006-01-12 18:11 18592 --a------ c:\windows\inf\lwusbhid.PNF
2006-01-12 18:11 18488 --a------ c:\windows\inf\mdmaiwa3.PNF
2006-01-12 18:11 18084 --a------ c:\windows\inf\i81xnt5.PNF
2006-01-12 18:11 17876 --a------ c:\windows\inf\icam4usb.PNF
2006-01-12 18:11 17572 --a------ c:\windows\inf\mdac.PNF
2006-01-12 18:11 17500 --a------ c:\windows\inf\mdmdp2.PNF
2006-01-12 18:11 17268 --a------ c:\windows\inf\camvid20.PNF
2006-01-12 18:11 17232 --a------ c:\windows\inf\agtinst.PNF
2006-01-12 18:11 169544 --a------ c:\windows\inf\mdmdsi.PNF
2006-01-12 18:11 16420 --a------ c:\windows\inf\mdmarn.PNF
2006-01-12 18:11 16384 --a------ c:\windows\inf\digimps.PNF
2006-01-12 18:11 16020 --a------ c:\windows\inf\camvid30.PNF
2006-01-12 18:11 1597336 --a------ c:\windows\inf\mdmgl004.PNF
2006-01-12 18:11 157264 --a------ c:\windows\inf\mdmgl009.PNF
2006-01-12 18:11 15528 --a------ c:\windows\inf\mdmar1.PNF
2006-01-12 18:11 15440 --a------ c:\windows\inf\irdasmc.PNF
2006-01-12 18:11 15408 --a------ c:\windows\inf\icwnt5.PNF
2006-01-12 18:11 15312 --a------ c:\windows\inf\brmfport.PNF
2006-01-12 18:11 152844 --a------ c:\windows\inf\mdmhamrw.PNF
2006-01-12 18:11 151716 --a------ c:\windows\inf\mdmgl007.PNF
2006-01-12 18:11 15036 --a------ c:\windows\inf\mdmadc.PNF
2006-01-12 18:11 14772 --a------ c:\windows\inf\au.PNF
2006-01-12 18:11 14192 --a------ c:\windows\inf\gameport.PNF
2006-01-12 18:11 13944 --a------ c:\windows\inf\lwngmadi.PNF
2006-01-12 18:11 13828 --a------ c:\windows\inf\mdmcpv.PNF
2006-01-12 18:11 13708 --a------ c:\windows\inf\icam5usb.PNF
2006-01-12 18:11 13628 --a------ c:\windows\inf\asynceqn.PNF
2006-01-12 18:11 136128 --a------ c:\windows\inf\mdmcpq.PNF
2006-01-12 18:11 13352 --a------ c:\windows\inf\cyyport.PNF
2006-01-12 18:11 13312 --a------ c:\windows\inf\battery.PNF
2006-01-12 18:11 13148 --a------ c:\windows\inf\icam3.PNF
2006-01-12 18:11 12836 --a------ c:\windows\inf\g400.PNF
2006-01-12 18:11 12544 --a------ c:\windows\inf\mdmcdp.PNF
2006-01-12 18:11 12528 --a------ c:\windows\inf\mdmcomp.PNF
2006-01-12 18:11 11884 --a------ c:\windows\inf\irtos4mo.PNF
2006-01-12 18:11 11868 --a------ c:\windows\inf\g200.PNF
2006-01-12 18:11 115112 --a------ c:\windows\inf\mdmelsa.PNF
2006-01-12 18:11 11416 --a------ c:\windows\inf\epsnmfp.PNF
2006-01-12 18:11 11404 --a------ c:\windows\inf\flash.PNF
2006-01-12 18:11 11180 --a------ c:\windows\inf\camdsh20.PNF
2006-01-12 18:11 10968 --a------ c:\windows\inf\mdmaiwat.PNF
2006-01-12 18:11 107872 --a------ c:\windows\inf\mdmirmdm.PNF
2006-01-12 18:11 10768 --a------ c:\windows\inf\agp.PNF
2006-01-12 18:11 10712 --a------ c:\windows\inf\kdkscan.PNF
2006-01-12 18:11 10516 --a------ c:\windows\inf\mdmbug3.PNF
2006-01-12 18:11 105104 --a------ c:\windows\inf\mdmaiwa4.PNF
2006-01-12 18:11 10456 --a------ c:\windows\inf\mdmcommu.PNF
2006-01-12 18:11 10284 --a------ c:\windows\inf\acerscan.PNF
2006-01-12 18:11 102152 --a------ c:\windows\inf\mdmhayes.PNF
2006-01-12 18:11 10212 --a------ c:\windows\inf\kodak.PNF
2005-12-05 18:17 791 --a------ c:\windows\inf\xinput9_1_0_x86.inf
2005-12-05 18:17 779 --a------ c:\windows\inf\d3dx9_28_x86.inf
2005-10-31 10:35 1887 --a------ c:\windows\inf\oem80.inf
2005-10-28 08:28 7704 --a------ c:\windows\inf\oem74.inf
2005-10-28 08:28 64562 --a------ c:\windows\inf\oem16.inf
2005-10-28 08:28 54641 --a------ c:\windows\inf\oem15.inf
2005-10-28 08:28 17766 --a------ c:\windows\inf\oem72.inf
2005-10-28 08:28 16021 --a------ c:\windows\inf\oem75.inf
2005-10-28 08:28 12850 --a------ c:\windows\inf\oem17.inf
2005-10-28 08:23 74678 --a------ c:\windows\inf\oem7.inf
2005-10-28 08:23 65786 --a------ c:\windows\inf\oem6.inf
2005-10-28 08:23 3420 --a------ c:\windows\inf\oem8.inf
2005-10-28 08:23 113734 --a------ c:\windows\inf\oem73.inf
2005-10-18 21:20 133116 --a------ c:\windows\inf\oem67.inf
2005-10-18 21:20 133036 --a------ c:\windows\inf\oem3.inf
2005-09-24 00:26 44878 --a------ c:\windows\inf\oem2.inf
2005-09-01 00:11 1530 --a------ c:\windows\inf\USBkey.inf
2005-08-26 20:58 37756 --a------ c:\windows\inf\oem1.inf
2005-08-09 22:36 209394 --a------ c:\windows\inf\oem68.inf
2005-07-22 20:05 779 --a------ c:\windows\inf\d3dx9_27_x86.inf
2005-06-24 02:56 47750 --a------ c:\windows\inf\oem65.inf
2005-06-02 07:33 6260 --a------ c:\windows\inf\oem54.inf
2005-06-02 07:10 50615 --a------ c:\windows\inf\oem60.inf
2005-06-02 07:10 32707 --a------ c:\windows\inf\oem57.inf
2005-06-02 07:10 24859 --a------ c:\windows\inf\oem59.inf
2005-06-02 07:10 20168 --a------ c:\windows\inf\oem62.inf
2005-06-02 07:10 12922 --a------ c:\windows\inf\oem61.inf
2005-06-02 07:10 11094 --a------ c:\windows\inf\oem58.inf
2005-05-26 15:40 779 --a------ c:\windows\inf\d3dx9_26_x86.inf
2005-05-16 23:54 92698 --a------ c:\windows\inf\oem55.inf
2005-05-16 23:54 3672 --a------ c:\windows\inf\oem56.inf
2005-03-18 17:25 779 --a------ c:\windows\inf\d3dx9_25_x86.inf
2005-03-08 23:48 50548 --a------ c:\windows\inf\oem9.inf
2005-03-08 23:48 45476 --a------ c:\windows\inf\oem10.inf
2005-03-08 23:48 24516 --a------ c:\windows\inf\oem14.inf
2005-03-08 23:48 20165 --a------ c:\windows\inf\oem13.inf
2005-03-08 23:48 13896 --a------ c:\windows\inf\oem12.inf
2005-03-08 23:48 12922 --a------ c:\windows\inf\oem11.inf
2005-03-08 22:47 50548 --a------ c:\windows\inf\oem18.inf
2005-03-08 22:47 45476 --a------ c:\windows\inf\oem19.inf
2005-03-08 22:47 24516 --a------ c:\windows\inf\oem23.inf
2005-03-08 22:47 20165 --a------ c:\windows\inf\oem22.inf
2005-03-08 22:47 13896 --a------ c:\windows\inf\oem21.inf
2005-03-08 22:47 12922 --a------ c:\windows\inf\oem20.inf
2005-03-01 12:55 3308 --a------ c:\windows\inf\oem79.inf
2005-02-28 15:15 3129 --a------ c:\windows\inf\oem64.inf
2005-01-28 13:44 892 --a------ c:\windows\inf\wmsetsdk.inf
2005-01-28 13:44 6099 --a------ c:\windows\inf\wpdmtp.inf
2005-01-28 13:44 4668 --a------ c:\windows\inf\WMFSDK10.inf
2005-01-28 13:44 4395 --a------ c:\windows\inf\codecs10.inf
2005-01-28 13:44 3954 --a------ c:\windows\inf\wpd10.inf
2005-01-28 13:44 1911 --a------ c:\windows\inf\DRM10.inf
2005-01-28 13:44 16724 --a------ c:\windows\inf\WMDM10.inf
2005-01-28 13:44 1419 --a------ c:\windows\inf\MPPRE10.inf
2005-01-26 02:03 1651 --a------ c:\windows\inf\pxhelp20.inf
2005-01-25 23:08 791 --a------ c:\windows\inf\d3dx9_24_x86.inf
2005-01-07 17:06 51914 --a------ c:\windows\inf\hdaudio.inf
2005-01-07 17:06 4866 --a------ c:\windows\inf\hdaudbus.inf
2004-12-20 23:16 1829 --a------ c:\windows\inf\oem0.inf
2004-12-15 15:14 3119 --a------ c:\windows\inf\oem63.inf
2004-12-15 15:14 3119 --a------ c:\windows\inf\oem31.inf
2004-12-03 20:59 3119 --a------ c:\windows\inf\oem33.inf
2004-12-03 20:57 3119 --a------ c:\windows\inf\oem32.inf
2004-12-03 19:59 3119 --a------ c:\windows\inf\oem30.inf
2004-12-02 10:40 3119 --a------ c:\windows\inf\oem38.inf
2004-12-02 10:40 3119 --a------ c:\windows\inf\oem35.inf
2004-11-09 18:39 2760 --a------ c:\windows\inf\iereset.inf
2004-10-26 17:14 3115 --a------ c:\windows\inf\oem34.inf
2004-10-08 19:57 30273 -ra------ c:\windows\inf\oem70.inf
2004-09-16 21:27 1681 --a------ c:\windows\inf\oem66.inf
2004-09-14 04:09 33672 --a------ c:\windows\inf\AER_1025.ADM
2004-08-11 01:45 67456 --a------ c:\windows\inf\wmplayer.adm
2004-08-11 01:45 34751 --a------ c:\windows\inf\WMP10.inf
2004-08-11 01:45 2227 --a------ c:\windows\inf\skins.inf
2004-08-11 01:45 192512 --a------ c:\windows\inf\unregmp2.exe
2004-08-11 01:45 1213 --a------ c:\windows\inf\MPSTUB10.inf
2004-08-11 01:45 1195 --a------ c:\windows\inf\MPCD10.inf
2004-08-11 01:45 1188 --a------ c:\windows\inf\WMSET10.inf
2004-08-04 19:00 9972 --a------ c:\windows\inf\mdmeric.inf
2004-08-04 19:00 9921 --a------ c:\windows\inf\bda.inf
2004-08-04 19:00 9904 --a------ c:\windows\inf\ksfilter.inf
2004-08-04 19:00 9891 --a------ c:\windows\inf\mdmtdkj6.inf
2004-08-04 19:00 9856 --a------ c:\windows\inf\spxports.inf
2004-08-04 19:00 9785 --a------ c:\windows\inf\camvid20.inf
2004-08-04 19:00 9736 --a------ c:\windows\inf\mdmdgitn.inf
2004-08-04 19:00 9614 --a------ c:\windows\inf\mdmaiwa3.inf
2004-08-04 19:00 9494 --a------ c:\windows\inf\mdmmc288.inf
2004-08-04 19:00 94336 --a------ c:\windows\inf\umax.inf
2004-08-04 19:00 9421 --a------ c:\windows\inf\mdmtexas.inf
2004-08-04 19:00 9288 --a------ c:\windows\inf\mdmdp2.inf
2004-08-04 19:00 9197 --a------ c:\windows\inf\smi.inf
2004-08-04 19:00 9074 --a------ c:\windows\inf\netoc.inf
2004-08-04 19:00 9030 --a------ c:\windows\inf\netwlan2.inf
2004-08-04 19:00 9022 --a------ c:\windows\inf\netrtsnt.inf
2004-08-04 19:00 8967 --a------ c:\windows\inf\net3c985.inf
2004-08-04 19:00 8945 --a------ c:\windows\inf\hpojscan.inf
2004-08-04 19:00 8860 --a------ c:\windows\inf\games.inf
2004-08-04 19:00 8847 --a------ c:\windows\inf\netnm.inf
2004-08-04 19:00 8842 --a------ c:\windows\inf\communic.inf
2004-08-04 19:00 8810 --a------ c:\windows\inf\netklsi.inf
2004-08-04 19:00 8728 --a------ c:\windows\inf\lwusbhid.inf
2004-08-04 19:00 86985 --a------ c:\windows\inf\wdma_aur.inf
2004-08-04 19:00 8627 --a------ c:\windows\inf\mwremove.inf
2004-08-04 19:00 8611 --a------ c:\windows\inf\mdmnttp2.inf
2004-08-04 19:00 8599 --a------ c:\windows\inf\netcbe.inf
2004-08-04 19:00 859 --a------ c:\windows\inf\rootau.inf
2004-08-04 19:00 85547 --a------ c:\windows\inf\machine.inf
2004-08-04 19:00 855 --a------ c:\windows\inf\wmpocm.inf
2004-08-04 19:00 85069 --a------ c:\windows\inf\mdmhamrw.inf
2004-08-04 19:00 849768 --a------ c:\windows\inf\intl.inf
2004-08-04 19:00 8467 --a------ c:\windows\inf\wdma_ymh.inf
2004-08-04 19:00 8463 --a------ c:\windows\inf\corelist.inf
2004-08-04 19:00 8451 --a------ c:\windows\inf\mdmmega.inf
2004-08-04 19:00 8438 --a------ c:\windows\inf\mdmolic.inf
2004-08-04 19:00 8426 --a------ c:\windows\inf\phil2vid.inf
2004-08-04 19:00 8415 --a------ c:\windows\inf\netvt86.inf
2004-08-04 19:00 839 --a------ c:\windows\inf\netupnp.inf
2004-08-04 19:00 8360 --a------ c:\windows\inf\mdmmod.inf
2004-08-04 19:00 8339 --a------ c:\windows\inf\netibm2.inf
2004-08-04 19:00 8329 --a------ c:\windows\inf\netcem56.inf
2004-08-04 19:00 8296 --a------ c:\windows\inf\wdma_ne2.inf
2004-08-04 19:00 829 --a------ c:\windows\inf\legcydrv.inf
2004-08-04 19:00 8277 --a------ c:\windows\inf\wsh.inf
2004-08-04 19:00 8244 --a------ c:\windows\inf\secrecs.inf
2004-08-04 19:00 8181 --a------ c:\windows\inf\netce3.inf
2004-08-04 19:00 81775 --a------ c:\windows\inf\comnt5.inf
2004-08-04 19:00 8167 --a------ c:\windows\inf\icwnt5.inf
2004-08-04 19:00 8151 --a------ c:\windows\inf\msmusb.inf
2004-08-04 19:00 8138 --a------ c:\windows\inf\netdlh5x.inf
2004-08-04 19:00 8134 --a------ c:\windows\inf\cpu.inf
2004-08-04 19:00 8049 --a------ c:\windows\inf\icam5usb.inf
2004-08-04 19:00 8047 --a------ c:\windows\inf\wordpad.inf
2004-08-04 19:00 8042 --a------ c:\windows\inf\Mdmnis2u.inf
2004-08-04 19:00 80419 --a------ c:\windows\inf\mdmzyxel.inf
2004-08-04 19:00 8026 --a------ c:\windows\inf\camdsh20.inf
2004-08-04 19:00 8012 --a------ c:\windows\inf\mdmnttp.inf
2004-08-04 19:00 79843 --a------ c:\windows\inf\mdmirmdm.inf
2004-08-04 19:00 7974 --a------ c:\windows\inf\Mdmnis1u.inf
2004-08-04 19:00 7946 --a------ c:\windows\inf\fp40ext.inf
2004-08-04 19:00 7919 --a------ c:\windows\inf\netosi5.inf
2004-08-04 19:00 79128 --a------ c:\windows\inf\mdmrock5.inf
2004-08-04 19:00 7895 --a------ c:\windows\inf\1394.inf
2004-08-04 19:00 787 --a------ c:\windows\inf\netbeac.inf
2004-08-04 19:00 7813 --a------ c:\windows\inf\cyzport.inf
2004-08-04 19:00 7790 --a------ c:\windows\inf\netsk98.inf
2004-08-04 19:00 7766 --a------ c:\windows\inf\agtinst.inf
2004-08-04 19:00 7761 --a------ c:\windows\inf\mdmar1.inf
2004-08-04 19:00 771 --a------ c:\windows\inf\oeaccess.inf
2004-08-04 19:00 77 --a------ c:\windows\inf\mdmchipv.inf
2004-08-04 19:00 7655 --a------ c:\windows\inf\icam3.inf
2004-08-04 19:00 76481 --a------ c:\windows\inf\mdmelsa.inf
2004-08-04 19:00 76255 --a------ c:\windows\inf\mdmgl006.inf
2004-08-04 19:00 7624 --a------ c:\windows\inf\wdmjoy.inf
2004-08-04 19:00 7619 --a------ c:\windows\inf\mdmpsion.inf
2004-08-04 19:00 7611 --a------ c:\windows\inf\mpsstln.inf
2004-08-04 19:00 76070 --a------ c:\windows\inf\wdma_es2.inf
2004-08-04 19:00 7513 --a------ c:\windows\inf\netcicap.inf
2004-08-04 19:00 750 --a------ c:\windows\inf\drm.inf
2004-08-04 19:00 7450 --a------ c:\windows\inf\asynceqn.inf
2004-08-04 19:00 7379 --a------ c:\windows\inf\moviemk.inf
2004-08-04 19:00 734 --a------ c:\windows\inf\secdrv.inf
2004-08-04 19:00 7316 --a------ c:\windows\inf\optional.inf
2004-08-04 19:00 7315 --a------ c:\windows\inf\net83820.inf
2004-08-04 19:00 72863 --a------ c:\windows\inf\mdmhayes.inf
2004-08-04 19:00 7232 --a------ c:\windows\inf\mdmarn.inf
2004-08-04 19:00 71827 --a------ c:\windows\inf\mdmmetri.inf
2004-08-04 19:00 7159 --a------ c:\windows\inf\ctmaport.inf
2004-08-04 19:00 7142 --a------ c:\windows\inf\netana.inf
2004-08-04 19:00 71404 --a------ c:\windows\inf\mdmomrn3.inf
2004-08-04 19:00 7072 --a------ c:\windows\inf\netel980.inf
2004-08-04 19:00 7072 --a------ c:\windows\inf\netel90a.inf
2004-08-04 19:00 70683 --a------ c:\windows\inf\font.inf
2004-08-04 19:00 7020 --a------ c:\windows\inf\netan983.inf
2004-08-04 19:00 7004 --a------ c:\windows\inf\lwngmadi.inf
2004-08-04 19:00 69701 --a------ c:\windows\inf\mdmcm28.inf
2004-08-04 19:00 696 --a------ c:\windows\inf\msnetfw.inf
2004-08-04 19:00 6903 --a------ c:\windows\inf\philtune.inf
2004-08-04 19:00 68786 --a------ c:\windows\inf\prtupg9x.inf
2004-08-04 19:00 6782 --a------ c:\windows\inf\camvid30.inf
2004-08-04 19:00 67816 --a------ c:\windows\inf\drvindex.inf
2004-08-04 19:00 6769 --a------ c:\windows\inf\wmfsdk.inf
2004-08-04 19:00 6742 --a------ c:\windows\inf\ndisip.inf
2004-08-04 19:00 6659 --a------ c:\windows\inf\netnovel.inf
2004-08-04 19:00 6612 --a------ c:\windows\inf\netbrzw.inf
2004-08-04 19:00 6606 --a------ c:\windows\inf\mdmsmart.inf
2004-08-04 19:00 6592 --a------ c:\windows\inf\p2p.inf
2004-08-04 19:00 65589 --a------ c:\windows\inf\net557.inf
2004-08-04 19:00 6538 --a------ c:\windows\inf\shl_img.inf
2004-08-04 19:00 6532 --a------ c:\windows\inf\mdmadc.inf
2004-08-04 19:00 6520 --a------ c:\windows\inf\nettiger.inf
2004-08-04 19:00 649 --a------ c:\windows\inf\mdmsetup.inf
2004-08-04 19:00 6464 --a------ c:\windows\inf\mstask.inf
2004-08-04 19:00 6433 --a------ c:\windows\inf\mfmhzn5.inf
2004-08-04 19:00 6351 --a------ c:\windows\inf\flash.inf
2004-08-04 19:00 6344 --a------ c:\windows\inf\oobe.inf
2004-08-04 19:00 6343 --a------ c:\windows\inf\mdmntt1.INF
2004-08-04 19:00 6337 --a------ c:\windows\inf\mfosi5.inf
2004-08-04 19:00 63294 --a------ c:\windows\inf\wdma_ali.inf
2004-08-04 19:00 6324 --a------ c:\windows\inf\igames.inf
2004-08-04 19:00 6314 --a------ c:\windows\inf\gameport.inf
2004-08-04 19:00 6308 --a------ c:\windows\inf\netpwr2.inf
2004-08-04 19:00 6268 --a------ c:\windows\inf\netcpqc.inf
2004-08-04 19:00 62517 --a------ c:\windows\inf\apps.inf
2004-08-04 19:00 624 --a------ c:\windows\inf\icminst.inf
2004-08-04 19:00 6215 --a------ c:\windows\inf\netasp2k.inf
2004-08-04 19:00 620730 --a------ c:\windows\inf\mdmcxsft.inf
2004-08-04 19:00 6151 --a------ c:\windows\inf\netip6.inf
2004-08-04 19:00 6140 --a------ c:\windows\inf\qmgr.inf
2004-08-04 19:00 6131 --a------ c:\windows\inf\perm2.inf
2004-08-04 19:00 6091 --a------ c:\windows\inf\au.inf
2004-08-04 19:00 60733 --a------ c:\windows\inf\mdmlt3.inf
2004-08-04 19:00 60593 --a------ c:\windows\inf\monitor5.inf
2004-08-04 19:00 6053 --a------ c:\windows\inf\hal.inf
2004-08-04 19:00 6045 --a------ c:\windows\inf\mdmcdp.inf
2004-08-04 19:00 60304 --a------ c:\windows\inf\atiixpag.inf
2004-08-04 19:00 6030 --a------ c:\windows\inf\netcpqmt.inf
2004-08-04 19:00 6027 --a------ c:\windows\inf\mdmcomp.inf
2004-08-04 19:00 59725 --a------ c:\windows\inf\mdmaiwa4.inf
2004-08-04 19:00 592 --a------ c:\windows\inf\minioc.inf
2004-08-04 19:00 5904 --a------ c:\windows\inf\mdmnokia.inf
2004-08-04 19:00 5892 --a------ c:\windows\inf\netrast.inf
2004-08-04 19:00 5884 --a------ c:\windows\inf\streamip.inf
2004-08-04 19:00 586 --a------ c:\windows\inf\wmaccess.inf
2004-08-04 19:00 5822 --a------ c:\windows\inf\nete100i.inf
2004-08-04 19:00 58073 --a------ c:\windows\inf\netdgdxb.inf
2004-08-04 19:00 5798 --a------ c:\windows\inf\net3c589.inf
2004-08-04 19:00 57835 --a------ c:\windows\inf\mdmmhza.inf
2004-08-04 19:00 5762 --a------ c:\windows\inf\ovsound.inf
2004-08-04 19:00 5748 --a------ c:\windows\inf\multimed.inf
2004-08-04 19:00 57364 --a------ c:\windows\inf\mdmusrgl.inf
2004-08-04 19:00 57297 --a------ c:\windows\inf\wdma_usb.inf
2004-08-04 19:00 57234 --a------ c:\windows\inf\stillcam.inf
2004-08-04 19:00 5711 --a------ c:\windows\inf\mdmkortx.inf
2004-08-04 19:00 56891 --a------ c:\windows\inf\mwtpdsp.inf
2004-08-04 19:00 5689 --a------ c:\windows\inf\mdmcpv.inf
2004-08-04 19:00 56849 --a------ c:\windows\inf\mdmmhzk1.inf
2004-08-04 19:00 55764 --a------ c:\windows\inf\mdm3mini.inf
2004-08-04 19:00 5552 --a------ c:\windows\inf\netel574.inf
2004-08-04 19:00 55506 --a------ c:\windows\inf\mdmpenr.inf
2004-08-04 19:00 55401 --a------ c:\windows\inf\mdmgl010.inf
2004-08-04 19:00 5462 --a------ c:\windows\inf\netce2.inf
2004-08-04 19:00 5445 --a------ c:\windows\inf\sisgr.inf
2004-08-04 19:00 5442 --a------ c:\windows\inf\battery.inf
2004-08-04 19:00 5417 --a------ c:\windows\inf\netamd.inf
2004-08-04 19:00 54131 --a------ c:\windows\inf\ie.inf
2004-08-04 19:00 53570 --a------ c:\windows\inf\mdmdcm5.inf
2004-08-04 19:00 53355 --a------ c:\windows\inf\mdmmts.inf
2004-08-04 19:00 5327 --a------ c:\windows\inf\disk.inf
2004-08-04 19:00 53259 --a------ c:\windows\inf\pnpscsi.inf
2004-08-04 19:00 53234 --a------ c:\windows\inf\mdm3com.inf
2004-08-04 19:00 53142 --a------ c:\windows\inf\input.inf
2004-08-04 19:00 5295 --a------ c:\windows\inf\brmfport.inf
2004-08-04 19:00 5277 --a------ c:\windows\inf\wbemoc.inf
2004-08-04 19:00 52695 --a------ c:\windows\inf\mdmati.inf
2004-08-04 19:00 52670 --a------ c:\windows\inf\monitor8.inf
2004-08-04 19:00 52556 --a------ c:\windows\inf\mdmzyp.inf
2004-08-04 19:00 5215 --a------ c:\windows\inf\srusbusd.inf
2004-08-04 19:00 52138 --a------ c:\windows\inf\mdmgl003.inf
2004-08-04 19:00 52117 --a------ c:\windows\inf\monitor.inf
2004-08-04 19:00 5199 --a------ c:\windows\inf\g400.inf
2004-08-04 19:00 51556 --a------ c:\windows\inf\mdmracal.inf
2004-08-04 19:00 51427 --a------ c:\windows\inf\msmsgs.inf
2004-08-04 19:00 5103 --a------ c:\windows\inf\mdmmcd.inf
2004-08-04 19:00 5095 --a------ c:\windows\inf\netctmrk.inf
2004-08-04 19:00 50945 --a------ c:\windows\inf\mdmhay2.inf
2004-08-04 19:00 5089 --a------ c:\windows\inf\mwmbatam.inf
2004-08-04 19:00 50680 --a------ c:\windows\inf\fxsocm.inf
2004-08-04 19:00 5038 --a------ c:\windows\inf\sr.inf
2004-08-04 19:00 5037 --a------ c:\windows\inf\netngr.inf
2004-08-04 19:00 5026 --a------ c:\windows\inf\mdmsun1.inf
2004-08-04 19:00 50067 --a------ c:\windows\inf\mdmcxsf2.inf
2004-08-04 19:00 4985 --a------ c:\windows\inf\epsnmfp.inf
2004-08-04 19:00 4980 --a------ c:\windows\inf\netw840.inf
2004-08-04 19:00 49661 --a------ c:\windows\inf\mdmusrk1.inf
2004-08-04 19:00 49556 --a------ c:\windows\inf\mdmltsft.inf
2004-08-04 19:00 4945 --a------ c:\windows\inf\netpnic.inf
2004-08-04 19:00 49397 --a------ c:\windows\inf\mdmgl002.inf
2004-08-04 19:00 49296 --a------ c:\windows\inf\mdmgen.inf
2004-08-04 19:00 4929 --a------ c:\windows\inf\net575nt.inf
2004-08-04 19:00 49212 --a------ c:\windows\inf\mdmsonyu.inf
2004-08-04 19:00 4917 --a------ c:\windows\inf\pchealth.inf
2004-08-04 19:00 48980 --a------ c:\windows\inf\mdmltleo.inf
2004-08-04 19:00 4898 --a------ c:\windows\inf\viafir2k.inf
2004-08-04 19:00 4897 --a------ c:\windows\inf\netepicn.inf
2004-08-04 19:00 48940 --a------ c:\windows\inf\mdmxircc.inf
2004-08-04 19:00 48853 --a------ c:\windows\inf\ims.inf
2004-08-04 19:00 48614 --a------ c:\windows\inf\mdmmhrtz.inf
2004-08-04 19:00 4861 --a------ c:\windows\inf\netamdhl.inf
2004-08-04 19:00 48170 --a------ c:\windows\inf\mdmbcmsm.inf
2004-08-04 19:00 48055 --a------ c:\windows\inf\brmfcmf.inf
2004-08-04 19:00 48044 --a------ c:\windows\inf\biosinfo.inf
2004-08-04 19:00 48015 --a------ c:\windows\inf\mdmmoto.inf
2004-08-04 19:00 47730 --a------ c:\windows\inf\monitor2.inf
2004-08-04 19:00 4761 --a------ c:\windows\inf\kdkscan.inf
2004-08-04 19:00 4753 --a------ c:\windows\inf\mflm56.inf
2004-08-04 19:00 4750 --a------ c:\windows\inf\mflm.inf
2004-08-04 19:00 4749 --a------ c:\windows\inf\nettpsmp.inf
2004-08-04 19:00 4727 --a------ c:\windows\inf\acpi.inf
2004-08-04 19:00 4726 --a------ c:\windows\inf\wceusbsh.inf
2004-08-04 19:00 4722 --a------ c:\windows\inf\netdefxa.inf
2004-08-04 19:00 47026 --a------ c:\windows\inf\mdmgl005.inf
2004-08-04 19:00 4701 --a------ c:\windows\inf\irmk7w2k.inf
2004-08-04 19:00 46837 --a------ c:\windows\inf\mdmxirmp.inf
2004-08-04 19:00 4673 --a------ c:\windows\inf\mfsocket.inf
2004-08-04 19:00 4671 --a------ c:\windows\inf\digirp.inf
2004-08-04 19:00 4664 --a------ c:\windows\inf\mxboard.inf
2004-08-04 19:00 4645 --a------ c:\windows\inf\netrtpnt.inf
2004-08-04 19:00 4637 --a------ c:\windows\inf\nettb155.inf
2004-08-04 19:00 46281 --a------ c:\windows\inf\msnetmtg.inf
2004-08-04 19:00 46281 --a------ c:\windows\inf\mdmgatew.inf
2004-08-04 19:00 4627 --a------ c:\windows\inf\cyyport.inf
2004-08-04 19:00 4612 --a------ c:\windows\inf\netxcpq.inf
2004-08-04 19:00 46074 --a------ c:\windows\inf\mdmmcom.inf
2004-08-04 19:00 45880 --a------ c:\windows\inf\mdmtdk.inf
2004-08-04 19:00 45673 --a------ c:\windows\inf\monitor6.inf
2004-08-04 19:00 45601 --a------ c:\windows\inf\mdmrock4.inf
2004-08-04 19:00 4557 --a------ c:\windows\inf\mdmnttme.INF
2004-08-04 19:00 4541 --a------ c:\windows\inf\mdmoptn.inf
2004-08-04 19:00 4538 --a------ c:\windows\inf\netx56n5.inf
2004-08-04 19:00 4507 --a------ c:\windows\inf\netmhzn5.inf
2004-08-04 19:00 44961 --a------ c:\windows\inf\mdmisdn.inf
2004-08-04 19:00 4475 --a------ c:\windows\inf\netfa312.inf
2004-08-04 19:00 4473 --a------ c:\windows\inf\tdibth.inf
2004-08-04 19:00 44714 --a------ c:\windows\inf\mdmgl001.inf
2004-08-04 19:00 4466 --a------ c:\windows\inf\mdmke.inf
2004-08-04 19:00 4456 --a------ c:\windows\inf\netirda.inf
2004-08-04 19:00 44439 --a------ c:\windows\inf\mdmboca.inf
2004-08-04 19:00 4443 --a------ c:\windows\inf\netdm.inf
2004-08-04 19:00 4433 --a------ c:\windows\inf\hidserv.inf
2004-08-04 19:00 4432 --a------ c:\windows\inf\umaxpp.inf
2004-08-04 19:00 4422 --a------ c:\windows\inf\perm3.inf
2004-08-04 19:00 4410 --a------ c:\windows\inf\mdmminij.inf
2004-08-04 19:00 43975 --a------ c:\windows\inf\mdmess.inf
2004-08-04 19:00 4386 --a------ c:\windows\inf\modemcsa.inf
2004-08-04 19:00 4370 --a------ c:\windows\inf\net656n5.inf
2004-08-04 19:00 43229 --a------ c:\windows\inf\setupqry.inf
2004-08-04 19:00 4317 --a------ c:\windows\inf\mdmaiwat.inf
2004-08-04 19:00 4274 --a------ c:\windows\inf\netcem28.inf
2004-08-04 19:00 4269 --a------ c:\windows\inf\avc.inf
2004-08-04 19:00 4260 --a------ c:\windows\inf\netcem33.inf
2004-08-04 19:00 42416 --a------ c:\windows\inf\dot4.inf
2004-08-04 19:00 4228 --a------ c:\windows\inf\irdaalif.inf
2004-08-04 19:00 4222 --a------ c:\windows\inf\mxport.inf
2004-08-04 19:00 4206 --a------ c:\windows\inf\mdmbug3.inf
2004-08-04 19:00 41883 --a------ c:\windows\inf\monitor3.inf
2004-08-04 19:00 4177 --a------ c:\windows\inf\nv3.inf
2004-08-04 19:00 4170 --a------ c:\windows\inf\mdmnttte.inf
2004-08-04 19:00 4152 --a------ c:\windows\inf\phil1vid.inf
2004-08-04 19:00 4130 --a------ c:\windows\inf\Mdmnis5t.inf
2004-08-04 19:00 41189 --a------ c:\windows\inf\mdmspq28.inf
2004-08-04 19:00 41011 --a------ c:\windows\inf\mdmetech.inf
2004-08-04 19:00 4100 --a------ c:\windows\inf\wbfirdma.inf
2004-08-04 19:00 410 --a------ c:\windows\inf\syscomp.inf
2004-08-04 19:00 4097 --a------ c:\windows\inf\nabtsfec.inf
2004-08-04 19:00 4091 --a------ c:\windows\inf\Mdmnis3t.inf
2004-08-04 19:00 4082 --a------ c:\windows\inf\net559ib.inf
2004-08-04 19:00 40809 --a------ c:\windows\inf\mdmrock3.inf
2004-08-04 19:00 40466 --a------ c:\windows\inf\wdma_ctl.inf
2004-08-04 19:00 4044 --a------ c:\windows\inf\tridkb.inf
2004-08-04 19:00 40439 --a------ c:\windows\inf\monitor7.inf
2004-08-04 19:00 4040 --a------ c:\windows\inf\netepro.inf
2004-08-04 19:00 404 --a------ c:\windows\inf\appmig.inf
2004-08-04 19:00 40207 --a------ c:\windows\inf\mdmgl008.inf
2004-08-04 19:00 40054 --a------ c:\windows\inf\monitor4.inf
2004-08-04 19:00 3999 --a------ c:\windows\inf\digirprt.inf
2004-08-04 19:00 3998 --a------ c:\windows\inf\netwzc.inf
2004-08-04 19:00 3976 --a------ c:\windows\inf\agp.inf
2004-08-04 19:00 39513 --a------ c:\windows\inf\devxprop.inf
2004-08-04 19:00 3936 --a------ c:\windows\inf\mff56n5.inf
2004-08-04 19:00 3928 --a------ c:\windows\inf\msnmsn.inf
2004-08-04 19:00 39025 --a------ c:\windows\inf\netrass.inf
2004-08-04 19:00 3894 --a------ c:\windows\inf\netlpd.inf
2004-08-04 19:00 3874 --a------ c:\windows\inf\g200.inf
2004-08-04 19:00 3864 --a------ c:\windows\inf\tsbvcap.inf
2004-08-04 19:00 384320 --a------ c:\windows\inf\layout.inf
2004-08-04 19:00 3843 --a------ c:\windows\inf\apcompat.inf
2004-08-04 19:00 38304 --a------ c:\windows\inf\mdmdyna.inf
2004-08-04 19:00 38179 --a------ c:\windows\inf\mdmpctel.inf
2004-08-04 19:00 3816 --a------ c:\windows\inf\dshowext.inf
2004-08-04 19:00 3808 --a------ c:\windows\inf\netdav.inf
2004-08-04 19:00 3788 --a------ c:\windows\inf\sis300i.inf
2004-08-04 19:00 3776 --a------ c:\windows\inf\ccdecode.inf
2004-08-04 19:00 37708 --a------ c:\windows\inf\mdmx5560.inf
2004-08-04 19:00 37657 --a------ c:\windows\inf\mdmpp.inf
2004-08-04 19:00 3761 --a------ c:\windows\inf\mdmcommu.inf
2004-08-04 19:00 3751 --a------ c:\windows\inf\HidDigi.inf
2004-08-04 19:00 3736 --a------ c:\windows\inf\mdmusrsp.inf
2004-08-04 19:00 3711 --a------ c:\windows\inf\irstusb.inf
2004-08-04 19:00 36992 --a------ c:\windows\inf\ks.inf
2004-08-04 19:00 3687 --a------ c:\windows\inf\netf56n5.inf
2004-08-04 19:00 3677 --a------ c:\windows\inf\msinfo32.inf
2004-08-04 19:00 3651 --a------ c:\windows\inf\fsvga.inf
2004-08-04 19:00 36375 --a------ c:\windows\inf\mdmmct.inf
2004-08-04 19:00 3637 --a------ c:\windows\inf\mymusic.inf
2004-08-04 19:00 3622 --a------ c:\windows\inf\sdbus.inf
2004-08-04 19:00 3612 --a------ c:\windows\inf\wstcodec.inf
2004-08-04 19:00 3609 --a------ c:\windows\inf\trid3d.inf
2004-08-04 19:00 3606 --a------ c:\windows\inf\net713.inf
2004-08-04 19:00 3599 --a------ c:\windows\inf\slip.inf
2004-08-04 19:00 3596 --a------ c:\windows\inf\ptpusb.inf
2004-08-04 19:00 35903 --a------ c:\windows\inf\mdmti.inf
2004-08-04 19:00 3581 --a------ c:\windows\inf\wave.inf
2004-08-04 19:00 3570 --a------ c:\windows\inf\net5515n.inf
2004-08-04 19:00 3551 --a------ c:\windows\inf\pinball.inf
2004-08-04 19:00 35450 --a------ c:\windows\inf\cdrom.inf
2004-08-04 19:00 3537 --a------ c:\windows\inf\netias.inf
2004-08-04 19:00 3512 --a------ c:\windows\inf\mfx56nf.inf
2004-08-04 19:00 3474 --a------ c:\windows\inf\netsnip.inf
2004-08-04 19:00 34685 --a------ c:\windows\inf\syssetup.inf
2004-08-04 19:00 3467 --a------ c:\windows\inf\netejxmp.inf
2004-08-04 19:00 3464 --a------ c:\windows\inf\ps5333.inf
2004-08-04 19:00 3462 --a------ c:\windows\inf\wtv2.inf
2004-08-04 19:00 3462 --a------ c:\windows\inf\wtv1.inf
2004-08-04 19:00 3460 --a------ c:\windows\inf\wfp8.inf
2004-08-04 19:00 3459 --a------ c:\windows\inf\wtv0.inf
2004-08-04 19:00 3459 --a------ c:\windows\inf\wfp5.inf
2004-08-04 19:00 3458 --a------ c:\windows\inf\wfp7.inf
2004-08-04 19:00 3458 --a------ c:\windows\inf\wfp6.inf
2004-08-04 19:00 3457 --a------ c:\windows\inf\wtv4.inf
2004-08-04 19:00 3456 --a------ c:\windows\inf\wtv3.inf
2004-08-04 19:00 3455 --a------ c:\windows\inf\wtv5.inf
2004-08-04 19:00 3455 --a------ c:\windows\inf\wfp4.inf
2004-08-04 19:00 3455 --a------ c:\windows\inf\wfp3.inf
2004-08-04 19:00 3455 --a------ c:\windows\inf\wfp0.inf
2004-08-04 19:00 3454 --a------ c:\windows\inf\wfp1.inf
2004-08-04 19:00 3453 --a------ c:\windows\inf\wfp2.inf
2004-08-04 19:00 33891 --a------ c:\windows\inf\mdmtosh.inf
2004-08-04 19:00 33702 --a------ c:\windows\inf\display.inf
2004-08-04 19:00 3359 --a------ c:\windows\inf\netserv.inf
2004-08-04 19:00 33550 --a------ c:\windows\inf\tape.inf
2004-08-04 19:00 3353 --a------ c:\windows\inf\mpe.inf
2004-08-04 19:00 33270 --a------ c:\windows\inf\mdmhandy.inf
2004-08-04 19:00 3322 --a------ c:\windows\inf\mgau.inf
2004-08-04 19:00 3302 --a------ c:\windows\inf\net656c5.inf
2004-08-04 19:00 3284 --a------ c:\windows\inf\dtcnt5.inf
2004-08-04 19:00 32807 --a------ c:\windows\inf\mdm5674a.inf
2004-08-04 19:00 32707 --a------ c:\windows\inf\epsnscan.inf
2004-08-04 19:00 3258 --a------ c:\windows\inf\s3savmx.inf
2004-08-04 19:00 3257 --a------ c:\windows\inf\netdf650.inf
2004-08-04 19:00 3246 --a------ c:\windows\inf\s3sav4.inf
2004-08-04 19:00 3243 --a------ c:\windows\inf\netupnph.inf
2004-08-04 19:00 3237 --a------ c:\windows\inf\acerscan.inf
2004-08-04 19:00 32342 --a------ c:\windows\inf\atimpab.inf
2004-08-04 19:00 3227 --a------ c:\windows\inf\netrsvp.inf
2004-08-04 19:00 3212 --a------ c:\windows\inf\xscan_xp.inf
2004-08-04 19:00 3208 --a------ c:\windows\inf\netrlw2k.inf
2004-08-04 19:00 3207 --a------ c:\windows\inf\eqnport.inf
2004-08-04 19:00 3204 --a------ c:\windows\inf\netpc100.inf
2004-08-04 19:00 3200 --a------ c:\windows\inf\net3c556.inf
2004-08-04 19:00 3187 --a------ c:\windows\inf\mdmpn1.inf
2004-08-04 19:00 31768 --a------ c:\windows\inf\msmouse.inf
2004-08-04 19:00 3167 --a------ c:\windows\inf\s3sav3d.inf
2004-08-04 19:00 3166 --a------ c:\windows\inf\sis6306.inf
2004-08-04 19:00 31555 --a------ c:\windows\inf\mdmosi.inf
2004-08-04 19:00 3154 --a------ c:\windows\inf\kodak.inf
2004-08-04 19:00 3149 --a------ c:\windows\inf\banshee.inf
2004-08-04 19:00 3146 --a------ c:\windows\inf\digiisdn.inf
2004-08-04 19:00 314 --a------ c:\windows\inf\fsvgadel.inf
2004-08-04 19:00 31321 --a------ c:\windows\inf\mdmexp.inf
2004-08-04 19:00 313 --a------ c:\windows\inf\fsvgaadd.inf
2004-08-04 19:00 31254 --a------ c:\windows\inf\keyboard.inf
2004-08-04 19:00 3121 --a------ c:\windows\inf\tridxp.inf
2004-08-04 19:00 3111 --a------ c:\windows\inf\netfore.inf
2004-08-04 19:00 31107 --a------ c:\windows\inf\msdv.inf
2004-08-04 19:00 3102 --a------ c:\windows\inf\sisv6326.inf
2004-08-04 19:00 30934 --a------ c:\windows\inf\mdm656n5.inf
2004-08-04 19:00 3092 --a------ c:\windows\inf\netforeh.inf
2004-08-04 19:00 3085 --a------ c:\windows\inf\mtxvideo.inf
2004-08-04 19:00 30835 --a------ c:\windows\inf\wdma_m2e.inf
2004-08-04 19:00 30548 --a------ c:\windows\inf\atixpwdm.inf
2004-08-04 19:00 3049 --a------ c:\windows\inf\flpydisk.inf
2004-08-04 19:00 3046 --a------ c:\windows\inf\atirage3.inf
2004-08-04 19:00 3045 --a------ c:\windows\inf\netel5x9.inf
2004-08-04 19:00 3038 --a------ c:\windows\inf\netbcm4e.inf
2004-08-04 19:00 3032 --a------ c:\windows\inf\mdmusrf.inf
2004-08-04 19:00 3031 --a------ c:\windows\inf\netfa410.inf
2004-08-04 19:00 3029 --a------ c:\windows\inf\brmfcsto.inf
2004-08-04 19:00 3027 --a------ c:\windows\inf\netel515.inf
2004-08-04 19:00 3001 --a------ c:\windows\inf\netloop.inf
2004-08-04 19:00 29998 --a------ c:\windows\inf\swnt.inf
2004-08-04 19:00 2999 --a------ c:\windows\inf\nettdkb.inf
2004-08-04 19:00 2998 --a------ c:\windows\inf\netfjvi.inf
2004-08-04 19:00 299444 --a------ c:\windows\inf\mdmrpci.inf
2004-08-04 19:00 29925 --a------ c:\windows\inf\mdmsupr3.inf
2004-08-04 19:00 29798 --a------ c:\windows\inf\atividin.inf
2004-08-04 19:00 29632 --a------ c:\windows\inf\ati1xwdm.inf
2004-08-04 19:00 2961 --a------ c:\windows\inf\netcb102.inf
2004-08-04 19:00 2950 --a------ c:\windows\inf\net650d.inf
2004-08-04 19:00 2938 --a------ c:\windows\inf\netrndis.inf
2004-08-04 19:00 29028 --a------ c:\windows\inf\mdmosice.inf
2004-08-04 19:00 2883 --a------ c:\windows\inf\sgiu.inf
2004-08-04 19:00 2883 --a------ c:\windows\inf\netfjvj.inf
2004-08-04 19:00 28806 --a------ c:\windows\inf\wmp.inf
2004-08-04 19:00 2879 --a------ c:\windows\inf\nettpro.inf
2004-08-04 19:00 28714 --a------ c:\windows\inf\hpscan.inf
2004-08-04 19:00 28644 --a------ c:\windows\inf\brmfcmdm.inf
2004-08-04 19:00 2861 --a------ c:\windows\inf\mdmairte.inf
2004-08-04 19:00 2857 --a------ c:\windows\inf\mdmmotou.inf
2004-08-04 19:00 28499 --a------ c:\windows\inf\mdmcom1.inf
2004-08-04 19:00 2849 --a------ c:\windows\inf\netktc.inf
2004-08-04 19:00 28376 --a------ c:\windows\inf\mdmcpq2.inf
2004-08-04 19:00 28128 --a------ c:\windows\inf\mdmntstm.inf
2004-08-04 19:00 2812 --a------ c:\windows\inf\tgiu.inf
2004-08-04 19:00 28113 --a------ c:\windows\inf\avmisdn.inf
2004-08-04 19:00 2805 --a------ c:\windows\inf\ibmvcap.inf
2004-08-04 19:00 27971 --a------ c:\windows\inf\mdmsuprv.inf
2004-08-04 19:00 2773 --a------ c:\windows\inf\i740nt5.inf
2004-08-04 19:00 27623 --a------ c:\windows\inf\wdma_ess.inf
2004-08-04 19:00 27604 --a------ c:\windows\inf\mshdc.inf
2004-08-04 19:00 2758 --a------ c:\windows\inf\netbcm4p.inf
2004-08-04 19:00 2694 --a------ c:\windows\inf\netlnev2.inf
2004-08-04 19:00 267903 --a------ c:\windows\inf\wdma10k1.inf
2004-08-04 19:00 26756 --a------ c:\windows\inf\mdmbtmdm.inf
2004-08-04 19:00 26729 --a------ c:\windows\inf\netb57xp.inf
2004-08-04 19:00 26660 --a------ c:\windows\inf\mdmsier.inf
2004-08-04 19:00 26407 --a------ c:\windows\inf\shell.inf
2004-08-04 19:00 2640 --a------ c:\windows\inf\sffdisk.inf
2004-08-04 19:00 2620 --a------ c:\windows\inf\adm_mult.inf
2004-08-04 19:00 2597 --a------ c:\windows\inf\netepvcm.inf
2004-08-04 19:00 25938 --a------ c:\windows\inf\mdm3cpcm.inf
2004-08-04 19:00 2592 --a------ c:\windows\inf\wbemsnmp.inf
2004-08-04 19:00 2589 --a------ c:\windows\inf\cyclom-y.inf
2004-08-04 19:00 25815 --a------ c:\windows\inf\wdma_ens.inf
2004-08-04 19:00 25815 --a------ c:\windows\inf\accessor.inf
2004-08-04 19:00 2565 --a------ c:\windows\inf\stalport.inf
2004-08-04 19:00 25634 --a------ c:\windows\inf\wdma_csf.inf
2004-08-04 19:00 25633 --a------ c:\windows\inf\atim128.inf
2004-08-04 19:00 2563 --a------ c:\windows\inf\bthpan.inf
2004-08-04 19:00 2556 --a------ c:\windows\inf\brmfcumd.inf
2004-08-04 19:00 2539 --a------ c:\windows\inf\netbcm4u.inf
2004-08-04 19:00 25366 --a------ c:\windows\inf\defltwk.inf
2004-08-04 19:00 2519 --a------ c:\windows\inf\netali.inf
2004-08-04 19:00 2515 --a------ c:\windows\inf\netrwan.inf
2004-08-04 19:00 25073 --a------ c:\windows\inf\mdmarch.inf
2004-08-04 19:00 2507 --a------ c:\windows\inf\mdmhaeu.inf
2004-08-04 19:00 2505 --a------ c:\windows\inf\61883.inf
2004-08-04 19:00 2500 --a------ c:\windows\inf\mdmpbit.inf
2004-08-04 19:00 24853 --a------ c:\windows\inf\mwavmdm1.inf
2004-08-04 19:00 2478 --a------ c:\windows\inf\netex10.inf
2004-08-04 19:00 24491 --a------ c:\windows\inf\netnf3.inf
2004-08-04 19:00 2447 --a------ c:\windows\inf\ndisuio.inf
2004-08-04 19:00 24371 --a------ c:\windows\inf\wdma_int.inf
2004-08-04 19:00 2429 --a------ c:\windows\inf\netsap.inf
2004-08-04 19:00 2423 --a------ c:\windows\inf\mdmvdot.inf
2004-08-04 19:00 24187 --a------ c:\windows\inf\nettcpip.inf
2004-08-04 19:00 2418 --a------ c:\windows\inf\cyclad-z.inf
2004-08-04 19:00 24146 --a------ c:\windows\inf\sdwndr2k.inf
2004-08-04 19:00 2402 --a------ c:\windows\inf\fdc.inf
2004-08-04 19:00 2398 --a------ c:\windows\inf\netlm.inf
2004-08-04 19:00 23978 --a------ c:\windows\inf\kscaptur.inf
2004-08-04 19:00 2394 --a------ c:\windows\inf\mfsupra.inf
2004-08-04 19:00 2391 --a------ c:\windows\inf\multiprt.inf
2004-08-04 19:00 23848 --a------ c:\windows\inf\wdma_sis.inf
2004-08-04 19:00 23714 --a------ c:\windows\inf\smartcrd.inf
2004-08-04 19:00 23708 --a------ c:\windows\inf\usbport.inf
2004-08-04 19:00 23685 --a------ c:\windows\inf\wdmaudio.inf
2004-08-04 19:00 23576 --a------ c:\windows\inf\mdmgcs.inf
2004-08-04 19:00 23444 --a------ c:\windows\inf\brmfcwia.inf
2004-08-04 19:00 2320 --a------ c:\windows\inf\netlm56.inf
2004-08-04 19:00 2317 --a------ c:\windows\inf\ntgrip.inf
2004-08-04 19:00 23090 --a------ c:\windows\inf\mdmlasno.inf
2004-08-04 19:00 23078 --a------ c:\windows\inf\irnsc.inf
2004-08-04 19:00 2300 --a------ c:\windows\inf\net1394.inf
2004-08-04 19:00 2293 --a------ c:\windows\inf\netw926.inf
2004-08-04 19:00 22776 --a------ c:\windows\inf\mdmdcm6.inf
2004-08-04 19:00 22618 --a------ c:\windows\inf\scsidev.inf
2004-08-04 19:00 2257 --a------ c:\windows\inf\memstpci.inf
2004-08-04 19:00 22554 --a------ c:\windows\inf\divasrv.inf
2004-08-04 19:00 2243 --a------ c:\windows\inf\dot4prt.inf
2004-08-04 19:00 22424 --a------ c:\windows\inf\mdmlucnt.inf
2004-08-04 19:00 22398 --a------ c:\windows\inf\net21x4.inf
2004-08-04 19:00 22319 --a------ c:\windows\inf\nete1000.inf
2004-08-04 19:00 22273 --a------ c:\windows\inf\wdma_csc.inf
2004-08-04 19:00 2224 --a------ c:\windows\inf\mfcem28.inf
2004-08-04 19:00 2219 --a------ c:\windows\inf\s3trio3d.inf
2004-08-04 19:00 22012 --a------ c:\windows\inf\mdmatt.inf
2004-08-04 19:00 21999 --a------ c:\windows\inf\netmadge.inf
2004-08-04 19:00 21964 --a------ c:\windows\inf\divac.inf
2004-08-04 19:00 2186 --a------ c:\windows\inf\certclas.inf
2004-08-04 19:00 2175 --a------ c:\windows\inf\netw940.inf
2004-08-04 19:00 2158 --a------ c:\windows\inf\netsla30.inf
2004-08-04 19:00 21547 --a------ c:\windows\inf\mdmsun2.inf
2004-08-04 19:00 2139 --a------ c:\windows\inf\dfrg.inf
2004-08-04 19:00 2134 --a------ c:\windows\inf\netepvcp.inf
2004-08-04 19:00 21295 --a------ c:\windows\inf\nv4_disp.inf
2004-08-04 19:00 2129 --a------ c:\windows\inf\netambi.inf
2004-08-04 19:00 20776 --a------ c:\windows\inf\mmopt.inf
2004-08-04 19:00 2076 --a------ c:\windows\inf\ppa3.inf
2004-08-04 19:00 2073 --a------ c:\windows\inf\mfcem33.inf
2004-08-04 19:00 20623 --a------ c:\windows\inf\usb.inf
2004-08-04 19:00 2048 --a------ c:\windows\inf\ppa.inf
2004-08-04 19:00 2038 --a------ c:\windows\inf\netsmc.inf
2004-08-04 19:00 20351 --a------ c:\windows\inf\pcmcia.inf
2004-08-04 19:00 20236 --a------ c:\windows\inf\mdminfot.inf
2004-08-04 19:00 2020 --a------ c:\windows\inf\mdmrisa.inf
2004-08-04 19:00 2016 --a------ c:\windows\inf\digiasyn.inf
2004-08-04 19:00 1997 --a------ c:\windows\inf\nettun.inf
2004-08-04 19:00 1997 --a------ c:\windows\inf\bthprint.inf
2004-08-04 19:00 1995 --a------ c:\windows\inf\hidbth.inf
2004-08-04 19:00 19904 --a------ c:\windows\inf\msmscsi.inf
2004-08-04 19:00 1955 --a------ c:\windows\inf\netnb.inf
2004-08-04 19:00 1946 --a------ c:\windows\inf\hpdigwia.inf
2004-08-04 19:00 1943 --a------ c:\windows\inf\bthspp.inf
2004-08-04 19:00 19420 --a------ c:\windows\inf\mdmgsm.inf
2004-08-04 19:00 19364 --a------ c:\windows\inf\dwup.inf
2004-08-04 19:00 1928 --a------ c:\windows\inf\msrio.inf
2004-08-04 19:00 19255 --a------ c:\windows\inf\msports.inf
2004-08-04 19:00 1925 --a------ c:\windows\inf\msrio8.inf
2004-08-04 19:00 19224 --a------ c:\windows\inf\image.inf
2004-08-04 19:00 19214 --a------ c:\windows\inf\nvdm.inf
2004-08-04 19:00 19125 --a------ c:\windows\inf\mdmdigi.inf
2004-08-04 19:00 19024 --a------ c:\windows\inf\wdma_ym2.inf
2004-08-04 19:00 1894 --a------ c:\windows\inf\ramdisk.inf
2004-08-04 19:00 18736 --a------ c:\windows\inf\wdma_via.inf
2004-08-04 19:00 1870 --a------ c:\windows\inf\netpschd.inf
2004-08-04 19:00 18680 --a------ c:\windows\inf\printupg.inf
2004-08-04 19:00 1862 --a------ c:\windows\inf\netiprip.inf
2004-08-04 19:00 1842 --a------ c:\windows\inf\msnike.inf
2004-08-04 19:00 18400 --a------ c:\windows\inf\msoe50.inf
2004-08-04 19:00 18333 --a------ c:\windows\inf\net8511.inf
2004-08-04 19:00 18322 --a------ c:\windows\inf\mdmtdkj3.inf
2004-08-04 19:00 18286 --a------ c:\windows\inf\mplayer2.inf
2004-08-04 19:00 1823 --a------ c:\windows\inf\netlanep.inf
2004-08-04 19:00 18040 --a------ c:\windows\inf\mdmtdkj5.inf
2004-08-04 19:00 1802 --a------ c:\windows\inf\mdmsgsml.inf
2004-08-04 19:00 1801 --a------ c:\windows\inf\sbp2.inf
2004-08-04 19:00 17976 --a------ c:\windows\inf\mdmpace.inf
2004-08-04 19:00 17939 --a------ c:\windows\inf\mdmeiger.inf
2004-08-04 19:00 17801 --a------ c:\windows\inf\mdmiodat.inf
2004-08-04 19:00 17766 --a------ c:\windows\inf\netsk_fp.inf
2004-08-04 19:00 17675 --a------ c:\windows\inf\3dfxvs2k.inf
2004-08-04 19:00 1761 --a------ c:\windows\inf\ntapm.inf
2004-08-04 19:00 17594 --a------ c:\windows\inf\netrasa.inf
2004-08-04 19:00 175444 --a------ c:\windows\inf\sapi5.inf
2004-08-04 19:00 17503 --a------ c:\windows\inf\netwlan.inf
2004-08-04 19:00 1747 --a------ c:\windows\inf\srchasst.inf
2004-08-04 19:00 17418 --a------ c:\windows\inf\sti.inf
2004-08-04 19:00 1739 --a------ c:\windows\inf\net3sr.inf
2004-08-04 19:00 1737 --a------ c:\windows\inf\ovcomp.inf
2004-08-04 19:00 1737 --a------ c:\windows\inf\netauni.inf
2004-08-04 19:00 17278 --a------ c:\windows\inf\sceregvl.inf
2004-08-04 19:00 17272 --a------ c:\windows\inf\wmdm.inf
2004-08-04 19:00 1701 --a------ c:\windows\inf\mscpqpa1.inf
2004-08-04 19:00 1698 --a------ c:\windows\inf\sysoc.inf
2004-08-04 19:00 16957 --a------ c:\windows\inf\mstape.inf
2004-08-04 19:00 1670 --a------ c:\windows\inf\usbprint.inf
2004-08-04 19:00 16592 --a------ c:\windows\inf\dvd.inf
2004-08-04 19:00 1641 --a------ c:\windows\inf\adm_port.inf
2004-08-04 19:00 16408 --a------ c:\windows\inf\wdma_azt.inf
2004-08-04 19:00 1633 --a------ c:\windows\inf\axant5.inf
2004-08-04 19:00 16205 --a------ c:\windows\inf\mchgr.inf
2004-08-04 19:00 16181 --a------ c:\windows\inf\mdmtdkj2.inf
2004-08-04 19:00 1616 --a------ c:\windows\inf\net10.inf
2004-08-04 19:00 15975 --a------ c:\windows\inf\wdma_cwr.inf
2004-08-04 19:00 1571002 --a------ c:\windows\inf\mdmgl004.inf
2004-08-04 19:00 15527 --a------ c:\windows\inf\mdmvv.inf
2004-08-04 19:00 15523 --a------ c:\windows\inf\mdmeric2.inf
2004-08-04 19:00 1544841 --a------ c:\windows\inf\mdmrpciw.inf
2004-08-04 19:00 1535 --a------ c:\windows\inf\enum1394.inf
2004-08-04 19:00 1533 --a------ c:\windows\inf\epcfw2k.inf
2004-08-04 19:00 15219 --a------ c:\windows\inf\netirsir.inf
2004-08-04 19:00 15158 --a------ c:\windows\inf\netamd2.inf
2004-08-04 19:00 15157 --a------ c:\windows\inf\mdmintel.inf
2004-08-04 19:00 1498946 --a------ c:\windows\inf\ntprint.inf
2004-08-04 19:00 14981 --a------ c:\windows\inf\dgasync.inf
2004-08-04 19:00 14952 --a------ c:\windows\inf\dgaport.inf
2004-08-04 19:00 1490 --a------ c:\windows\inf\sonypvu1.inf
2004-08-04 19:00 1481 --a------ c:\windows\inf\wmtour.inf
2004-08-04 19:00 14809 --a------ c:\windows\inf\ovcam.inf
2004-08-04 19:00 14782 --a------ c:\windows\inf\spx.inf
2004-08-04 19:00 14690 --a------ c:\windows\inf\wdma_rip.inf
2004-08-04 19:00 14675 --a------ c:\windows\inf\mdmbw561.INF
2004-08-04 19:00 14578 --a------ c:\windows\inf\usbstor.inf
2004-08-04 19:00 14455 --a------ c:\windows\inf\atiixpaa.inf
2004-08-04 19:00 14428 --a------ c:\windows\inf\mdmaiwa5.inf
2004-08-04 19:00 14374 --a------ c:\windows\inf\netsis.inf
2004-08-04 19:00 14340 --a------ c:\windows\inf\tshoot.inf
2004-08-04 19:00 14269 --a------ c:\windows\inf\MDMJF56E.INF
2004-08-04 19:00 1417 --a------ c:\windows\inf\epstw2k.inf
2004-08-04 19:00 1402 --a------ c:\windows\inf\genprint.inf
2004-08-04 19:00 13982 --a------ c:\windows\inf\mdmsgsmu.inf
2004-08-04 19:00 1394 --a------ c:\windows\inf\unknown.inf
2004-08-04 19:00 13934 --a------ c:\windows\inf\mdmsiil6.INF
2004-08-04 19:00 13769 --a------ c:\windows\inf\mdmsii64.INF
2004-08-04 19:00 137 --a------ c:\windows\inf\svcpack.inf
2004-08-04 19:00 13556 --a------ c:\windows\inf\mdmtron.inf
2004-08-04 19:00 1352 --a------ c:\windows\inf\1394vdbg.inf
2004-08-04 19:00 13380 --a------ c:\windows\inf\mdmaiwa.inf
2004-08-04 19:00 13358 --a------ c:\windows\inf\parhmse.inf
2004-08-04 19:00 133512 --a------ c:\windows\inf\mdmdsi.inf
2004-08-04 19:00 13275 --a------ c:\windows\inf\mdmdf56F.inf
2004-08-04 19:00 13273 --a------ c:\windows\inf\netnwlnk.inf
2004-08-04 19:00 13259 --a------ c:\windows\inf\memcard.inf
2004-08-04 19:00 1323 --a------ c:\windows\inf\netpsa.inf
2004-08-04 19:00 1322 --a------ c:\windows\inf\netbrdgm.inf
2004-08-04 19:00 13219 --a------ c:\windows\inf\mdmtdkj4.inf
2004-08-04 19:00 13178 --a------ c:\windows\inf\mdmrock.inf
2004-08-04 19:00 1316 --a------ c:\windows\inf\mf.inf
2004-08-04 19:00 13080 --a------ c:\windows\inf\netcpqg.inf
2004-08-04 19:00 130588 --a------ c:\windows\inf\mdmwhql0.inf
2004-08-04 19:00 13035 --a------ c:\windows\inf\mdmcodex.inf
2004-08-04 19:00 1302 --a------ c:\windows\inf\vgx.inf
2004-08-04 19:00 12899 --a------ c:\windows\inf\mdmc26a.INF
2004-08-04 19:00 12883 --a------ c:\windows\inf\mdmaus.inf
2004-08-04 19:00 12847 --a------ c:\windows\inf\netel90b.inf
2004-08-04 19:00 12840 --a------ c:\windows\inf\mdmtdkj7.inf
2004-08-04 19:00 1283 --a------ c:\windows\inf\netclass.inf
2004-08-04 19:00 127277 --a------ c:\windows\inf\mdmmhzel.inf
2004-08-04 19:00 12602 --a------ c:\windows\inf\netibm.inf
2004-08-04 19:00 12398 --a------ c:\windows\inf\fjtscan.inf
2004-08-04 19:00 12389 --a------ c:\windows\inf\wdma_neo.inf
2004-08-04 19:00 12357 --a------ c:\windows\inf\mdmbsb.inf
2004-08-04 19:00 12343 --a------ c:\windows\inf\mdmnttd2.inf
2004-08-04 19:00 123410 --a------ c:\windows\inf\iis.inf
2004-08-04 19:00 12323 --a------ c:\windows\inf\netx500.inf
2004-08-04 19:00 12299 --a------ c:\windows\inf\digimps.inf
2004-08-04 19:00 1224 --a------ c:\windows\inf\fltmgr.inf
2004-08-04 19:00 12221 --a------ c:\windows\inf\mdmmoto1.inf
2004-08-04 19:00 12211 --a------ c:\windows\inf\mdmusrg.inf
2004-08-04 19:00 121790 --a------ c:\windows\inf\wdma_es3.inf
2004-08-04 19:00 12166 --a------ c:\windows\inf\mdmnttd6.inf
2004-08-04 19:00 12085 --a------ c:\windows\inf\netcpqi.inf
2004-08-04 19:00 11985 --a------ c:\windows\inf\usbvideo.inf
2004-08-04 19:00 11972 --a------ c:\windows\inf\mdmcrtix.inf
2004-08-04 19:00 11927 --a------ c:\windows\inf\irdasmc.inf
2004-08-04 19:00 1190 --a------ c:\windows\inf\netlanem.inf
2004-08-04 19:00 11790 --a------ c:\windows\inf\mdac.inf
2004-08-04 19:00 11747 --a------ c:\windows\inf\netmscli.inf
2004-08-04 19:00 11718 --a------ c:\windows\inf\i81xnt5.inf
2004-08-04 19:00 11681 --a------ c:\windows\inf\bth.inf
2004-08-04 19:00 116718 --a------ c:\windows\inf\mdmsupra.inf
2004-08-04 19:00 11634 --a------ c:\windows\inf\mdmneuhs.inf
2004-08-04 19:00 11615 --a------ c:\windows\inf\mdmnova.inf
2004-08-04 19:00 11586 --a------ c:\windows\inf\netsnmp.inf
2004-08-04 19:00 11494 --a------ c:\windows\inf\nvct.inf
2004-08-04 19:00 114795 --a------ c:\windows\inf\tsoc.inf
2004-08-04 19:00 11437 --a------ c:\windows\inf\wdma_avc.inf
2004-08-04 19:00 11407 --a------ c:\windows\inf\mdmdgden.inf
2004-08-04 19:00 11373 --a------ c:\windows\inf\dimaps.inf
2004-08-04 19:00 11262 --a------ c:\windows\inf\netel99x.inf
2004-08-04 19:00 11209 --a------ c:\windows\inf\neo20xx.inf
2004-08-04 19:00 11177 --a------ c:\windows\inf\netcb325.inf
2004-08-04 19:00 11157 --a------ c:\windows\inf\pmxmcro.inf
2004-08-04 19:00 11141 --a------ c:\windows\inf\icam4usb.inf
2004-08-04 19:00 1104 --a------ c:\windows\inf\netgpc.inf
2004-08-04 19:00 11037 --a------ c:\windows\inf\mdmfj2.inf
2004-08-04 19:00 11003 --a------ c:\windows\inf\phildec.inf
2004-08-04 19:00 1096 --a------ c:\windows\inf\netbrdgs.inf
2004-08-04 19:00 1095 --a------ c:\windows\inf\volsnap.inf
2004-08-04 19:00 109098 --a------ c:\windows\inf\startoc.inf
2004-08-04 19:00 10895 --a------ c:\windows\inf\wab50.inf
2004-08-04 19:00 10865 --a------ c:\windows\inf\nvts.inf
2004-08-04 19:00 10836 --a------ c:\windows\inf\phdsext.inf
2004-08-04 19:00 10822 --a------ c:\windows\inf\scsi.inf
2004-08-04 19:00 108097 --a------ c:\windows\inf\mdmgl009.inf
2004-08-04 19:00 108001 --a------ c:\windows\inf\mdmzoom.inf
2004-08-04 19:00 10700 --a------ c:\windows\inf\kdk2x0.inf
2004-08-04 19:00 1064 --a------ c:\windows\inf\netcis.inf
2004-08-04 19:00 10619 --a------ c:\windows\inf\irtos4mo.inf
2004-08-04 19:00 10576 --a------ c:\windows\inf\mdmpin.inf
2004-08-04 19:00 10508 --a------ c:\windows\inf\mfcem56.inf
2004-08-04 19:00 104156 --a------ c:\windows\inf\mdmcpq.inf
2004-08-04 19:00 10414 --a------ c:\windows\inf\ricoh.inf
2004-08-04 19:00 103924 --a------ c:\windows\inf\mdmzyxlg.inf
2004-08-04 19:00 10336 --a------ c:\windows\inf\mdmlasat.inf
2004-08-04 19:00 102685 --a------ c:\windows\inf\mdmgl007.inf
2004-08-04 19:00 1018 --a------ c:\windows\inf\volume.inf
2004-08-04 19:00 10083 --a------ c:\windows\inf\mdmatm2k.inf
2004-08-04 19:00 10068 --a------ c:\windows\inf\netwv48.inf
2004-08-04 19:00 10008 --a------ c:\windows\inf\netosi2c.inf
2004-08-04 14:09 3119 --a------ c:\windows\inf\oem36.inf
2004-07-27 10:10 3115 --a------ c:\windows\inf\oem37.inf
2004-04-29 15:37 3116 --a------ c:\windows\inf\oem53.inf
2004-04-29 15:32 3121 --a------ c:\windows\inf\oem52.inf
2004-04-13 12:58 1007 --a------ c:\windows\inf\oem84.inf
2004-04-09 12:43 1004 --a------ c:\windows\inf\oem83.inf
2004-03-04 14:09 13334 --a------ c:\windows\inf\oem5.inf
2004-03-04 14:09 13334 --a------ c:\windows\inf\oem4.inf
2004-02-03 17:03 3116 --a------ c:\windows\inf\oem27.inf
2004-02-03 17:03 3116 --a------ c:\windows\inf\oem26.inf
2003-12-01 14:25 3116 --a------ c:\windows\inf\oem29.inf
2003-07-18 14:42 39132 --a------ c:\windows\inf\AER_1040.ADM
2003-07-18 14:37 38066 --a------ c:\windows\inf\AER_3082.ADM
2003-07-12 02:55 23748 --a------ c:\windows\inf\AER_2052.ADM
2003-07-12 02:52 26616 --a------ c:\windows\inf\AER_1042.ADM
2003-07-12 02:48 23282 --a------ c:\windows\inf\AER_1028.ADM
2003-07-12 02:43 26292 --a------ c:\windows\inf\AER_1041.ADM
2003-07-12 02:40 39516 --a------ c:\windows\inf\AER_1031.ADM
2003-05-07 10:14 3115 --a------ c:\windows\inf\oem47.inf
2003-04-03 09:57 3115 --a------ c:\windows\inf\oem46.inf
2003-04-03 09:49 3122 --a------ c:\windows\inf\oem25.inf
2003-04-01 19:33 1995 --a------ c:\windows\inf\oem78.inf
2003-03-24 16:04 3115 --a------ c:\windows\inf\oem43.inf
2003-03-14 20:35 3115 --a------ c:\windows\inf\oem44.inf
2003-01-15 12:50 3167 --a------ c:\windows\inf\oem76.inf
2003-01-13 16:11 39366 --a------ c:\windows\inf\AER_1036.ADM
2002-10-30 13:27 1408 --a------ c:\windows\inf\oem82.inf
2002-10-15 11:45 3115 --a------ c:\windows\inf\oem45.inf
2002-10-10 08:44 34066 --a------ c:\windows\inf\AER_1033.ADM
2002-09-17 13:23 1864 --a------ c:\windows\inf\oem77.inf
2002-09-11 10:16 1624 --a------ c:\windows\inf\oem85.inf
2002-05-17 15:10 3115 --a------ c:\windows\inf\oem51.inf
2002-05-09 16:55 3115 --a------ c:\windows\inf\oem41.inf
2002-05-09 16:55 3115 --a------ c:\windows\inf\oem40.inf
2002-05-09 16:55 3115 --a------ c:\windows\inf\oem39.inf
2002-03-12 15:46 3126 --a------ c:\windows\inf\oem28.inf
2002-02-01 14:47 3119 --a------ c:\windows\inf\oem24.inf
2002-01-21 10:12 1385 --a------ c:\windows\inf\oem81.inf
2002-01-03 16:39 3315 --a------ c:\windows\inf\oem42.inf
2002-01-03 16:39 3149 --a------ c:\windows\inf\oem48.inf
2002-01-03 16:39 3130 --a------ c:\windows\inf\oem49.inf
2002-01-03 16:39 3126 --a------ c:\windows\inf\oem50.inf
2001-10-04 23:53 1624 --a------ c:\windows\inf\oem86.inf
2000-04-10 17:12 1765 --a------ c:\windows\inf\fhg.inf


------- Sigcheck -------

2005-03-14 09:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 20:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-31 00:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-03-14 08:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2007-01-14 11:48 359808 b4e29943b4b04bd5e7381546848e6669 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-03-17 02:10 360064 ef7834c1d9ddf4c7da697d8c24a03791 C:\WINDOWS\system32\dllcache\TCPIP.SYS
2007-03-17 02:10 360064 ef7834c1d9ddf4c7da697d8c24a03791 C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-04-26_11.50.11.12 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-26 03:45:43 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-26 14:00:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 04:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 07:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 07:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-23 16:29 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-23 16:29 2051328]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-23 16:29 2051328]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-24 04:03 185896]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 22:43 81920]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-23 16:29 1177368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-12 18:12:08 27136]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-01-12 18:12:08 27136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-10-23 04:33:37 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= C:\Program Files\WIZET\MapleStory\l3codeca.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hxgame-update]
C:\Program Files\酵砑蚔牁炵蹈\酵砑蚔牁5.0\Statistics\hxgame-update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\WIZET\\MapleStory\\MapleStory.exe"=
"<NO NAME>"= :
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Tuotu\\Tuotu.exe"=
"C:\\Program Files\\WIZET\\MapleStory\\Patcher.exe"=
"C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\GGclient.exe"=
"C:\\Program Files\\Real\\eMule\\emule.exe"=
"C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\Garena.exe"=
"C:\\Program Files\\PPLive\\PPLive.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13113:TCP"= 13113:TCP:*:Disabled:BitComet 13113 TCP
"13113:UDP"= 13113:UDP:*:Disabled:BitComet 13113 UDP
"12372:TCP"= 12372:TCP:NortonAV
"16036:TCP"= 16036:TCP:NortonAV
"13159:TCP"= 13159:TCP:NortonAV
"17820:TCP"= 17820:TCP:NortonAV
"13570:TCP"= 13570:TCP:NortonAV
"18305:TCP"= 18305:TCP:NortonAV
"18990:TCP"= 18990:TCP:NortonAV
"15128:TCP"= 15128:TCP:NortonAV
"17533:TCP"= 17533:TCP:NortonAV
"13172:TCP"= 13172:TCP:NortonAV
"16852:TCP"= 16852:TCP:NortonAV
"15943:TCP"= 15943:TCP:NortonAV
"17524:TCP"= 17524:TCP:NortonAV
"18411:TCP"= 18411:TCP:NortonAV
"17957:TCP"= 17957:TCP:NortonAV
"18061:TCP"= 18061:TCP:NortonAV
"18043:TCP"= 18043:TCP:NortonAV
"12431:TCP"= 12431:TCP:NortonAV
"13282:TCP"= 13282:TCP:NortonAV
"12312:TCP"= 12312:TCP:NortonAV
"18235:TCP"= 18235:TCP:NortonAV
"13963:TCP"= 13963:TCP:NortonAV
"12672:TCP"= 12672:TCP:NortonAV
"13279:TCP"= 13279:TCP:NortonAV
"18190:TCP"= 18190:TCP:NortonAV
"16609:TCP"= 16609:TCP:NortonAV
"17980:TCP"= 17980:TCP:NortonAV
"16068:TCP"= 16068:TCP:NortonAV
"18675:TCP"= 18675:TCP:NortonAV
"18518:TCP"= 18518:TCP:NortonAV
"12464:TCP"= 12464:TCP:NortonAV
"18583:TCP"= 18583:TCP:NortonAV

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-04-23 16:29]
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-23 16:29]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-23 16:29]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-23 16:29]
S2 cliconfg;clic onfg;C:\WINDOWS\system32\cliconfg.exe []
S2 HWQRLDYQLLRX;NDOYEQAZBJD;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]
S2 lmoboyes;Logical Disk Manager Amdinistrative SAlm080124;c:\root\lm8124\scvhost.exe []
S2 ti7gnjw;ti7gnjw;C:\WINDOWS\system32\drivers\ti7gnjw.sys []
S2 WinCOM;COM+ Windows System;C:\WINDOWS\system32\wincom.exe []
S3 IVIresizeP8;IVIresizeP8;C:\WINDOWS\system32\drivers\IVIresizeP8.sys []
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys []
S3 XDva020;XDva020;C:\WINDOWS\system32\XDva020.sys []
S4 IXKBXE;BNTJKTH;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]
S4 OZJUV;BCFRHQXUR;C:\WINDOWS\system32\svchost.exe [2004-08-04 12:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
PTBTMACJZIGFH REG_MULTI_SZ HWQRLDYQLLRX
NWQGVCZ REG_MULTI_SZ IXKBXE
FQGGUNMZQP REG_MULTI_SZ OZJUV

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
DCOMManager16

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 14:03:50 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-04-26 14:14:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-26 22:12:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...
New log :

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DCOMManager16]
"ServiceDll"="c:\windows\inf\pcidev32.inf"
.
Completion time: 2008-04-26 22:14:39
ComboFix-quarantined-files.txt 2008-04-26 14:14:35
ComboFix2.txt 2008-04-26 03:50:40

Pre-Run: 124,278,435,840 bytes free
Post-Run: 124,271,226,880 bytes free

1937 --- E O F --- 2008-03-30 11:55:17

#12 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 26 April 2008 - 09:38 AM

Open Notepad, and copy everything in the code box below and paste it into a new notepad file. Change the "Save As Type" to "All Files". Save it as fixme.reg on your Desktop. Make sure there is NO blank line above "REGEDIT4"!

REGEDIT4

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_DCOMMANAGER16]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DCOMManager16]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_DCOMMANAGER16]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DCOMManager16]
Locate fixme.reg on your Desktop and double-click on it. When it asks if you want to merge with the registry, click YES.

Reboot your computer.


================



Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#13 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 11:24 AM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/27/2008 at 00:02 AM

Application Version : 4.0.1154

Core Rules Database Version : 3448
Trace Rules Database Version: 1440

Scan type : Complete Scan
Total Scan Time : 00:57:56

Memory items scanned : 293
Memory threats detected : 0
Registry items scanned : 5969
Registry threats detected : 11
File items scanned : 113974
File threats detected : 12

Rogue.Netcom3/SpyClean
HKU\S-1-5-21-1390448951-2275363048-3209160754-1008\Software\Netcom3 Cleaner
HKU\S-1-5-21-1390448951-2275363048-3209160754-1008\Software\SpyClean
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#Type
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#Start
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3\Security
HKLM\SYSTEM\CurrentControlSet\Services\Netcom3\Security#Security
C:\Program Files\Netcom3 Cleaner\Backup
C:\Program Files\Netcom3 Cleaner\Logs\2008_04_21.log
C:\Program Files\Netcom3 Cleaner\Logs
C:\Program Files\Netcom3 Cleaner

Rogue.Netcom3/SpyClean-Installer
C:\DOCUMENTS AND SETTINGS\HP_OWNER\MY DOCUMENTS\NETCOM3_SETUP.EXE

Adware.Tracking Cookie
C:\Documents and Settings\LocalService\Cookies\system@ad.363[2].txt
C:\Documents and Settings\LocalService\Cookies\system@ads.i2link[1].txt
C:\Documents and Settings\LocalService\Cookies\system@ebaycpc.t2click[1].txt
C:\Documents and Settings\LocalService\Cookies\system@imrworldwide[2].txt
C:\Documents and Settings\LocalService\Cookies\system@xxx.18dmm[1].txt
C:\Documents and Settings\NetworkService\Cookies\hp_owner@lstat.youku[2].txt

Trojan.Unclassified-Packed/Suspicious
C:\SYSTEM VOLUME INFORMATION\_RESTORE{FB0B7E35-1791-4838-8FCB-12BD2312AC3E}\RP1063\A0483609.DLL

#14 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:10:02 AM

Posted 26 April 2008 - 11:37 AM

Ok, that's looking better.
Please one more hijackthis log so I can get one last look.

Any problems now?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#15 BigMama

BigMama
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:02 PM

Posted 26 April 2008 - 10:30 PM

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:26:07, on 2008-4-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\antispyware\SUPERAntiSpyware.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Hijack\HijackThis.exe

R3 - URLSearchHook: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: blueserver Toolbar - {83ef376d-8874-4769-a2e7-7096480e7def} - C:\Program Files\blueserver\tbblu1.dll
O3 - Toolbar: (no name) - {F60C7D81-8471-4D40-AAFE-56D318F34C2D} - (no file)
O3 - Toolbar: Yahoo!集倍畖 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\antispyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &场ㄏノ FlashGet 更 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {05C1004E-2596-48E5-8E26-39362985EEB9} - http://p3p.sogou.com/MMCShell.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} - https://mail.rajahtann.com/iNotes6.cab
O16 - DPF: {3C38DEE8-BE1A-4DEC-B232-2C78706CC7EA} - http://ps.itv.mop.com/update/update/GUpdat...0.10-signed.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153925162750
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - http://avatar.mabinogi.com:88/renderer/mab....2006.12.27.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - http://download.games.yahoo.com/games/web_...outLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{964967CE-6096-4709-B068-60596131E36F}: NameServer = 202.188.0.133,202.188.1.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\antispyware\SASWINLO.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: clic onfg (cliconfg) - Unknown owner - C:\WINDOWS\system32\cliconfg.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logical Disk Manager Amdinistrative SAlm080124 (lmoboyes) - Unknown owner - c:\root\lm8124\scvhost.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: COM+ Windows System (WinCOM) - Unknown owner - C:\WINDOWS\system32\wincom.exe (file missing)

--
End of file - 9636 bytes


currenly looks fine , one thing the missing file in the hijack log root\lm8124\scvhost.exe (file missing) should i concern about it or fix it ?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users