Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virtumonde Infection


  • This topic is locked This topic is locked
29 replies to this topic

#1 The Grog

The Grog

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 17 January 2009 - 03:55 PM

Hello again,

I was having trouble with our new most common friend, Virtumonde. Spybot found it and said it was deleted, but I was still having problems. AdAware didn't find anything, Malwarebyte did find other things but not Virtumonde. I would like somebody to check my HJT log to see if I am clean of Virtumonde as well as anything else that may be hiding that the above programs may have missed.

As always, thanks for your time. You guys are incredible and always helpful.

HJT log
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:43:49 PM, on 1/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Documents and Settings\Compaq_Owner\Desktop\PRINTKEY.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Compaq Organize.lnk = ?
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20364.www2.hp.com/CSMWeb/Customer/...DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols3beta/fscax.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe

--
End of file - 10425 bytes
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

BC AdBot (Login to Remove)

 


#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 29 January 2009 - 11:39 AM

Hi The Grog,

Welcome to BC HijackThis forum and sorry for the delay. I am farbar. I am going to assist you with your problem.

Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.
  • Tell me if you have done anything since previous post. Or you have run any other tools. Also tell me how is the current condition of your computer.

  • To get an idea about the current condition of you computer download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Set the scan files/folders to 3 mounts.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

    Note 1: If you have difficulty finding the logs, the logs are in this folder: C:\rsit

    Note 2: The tool takes not more than one minute to scan the system.
You might want to save this page on your favorites, so you can find it again when you return.

#3 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 01 February 2009 - 03:12 PM

Farbar,

Thank you so much for responding. I haven't checked for several days as you guys are so busy. The only thing that I have been doing for the most part is running Ad-Aware, Malwarebytes, and Spybot. Virtumonde.sci has come up a few times in Spybot. When it does I tell Spybot to fix it, and it says it does, but somehow it keeps getting re-infected. Is there a way to keep this pesky virus from re-attaching itself? I see from the forums that this seems to be the most copmmon problem these days.

Here is my current log.

Logfile of random's system information tool 1.05 (written by random/random)
Run by Compaq_Owner at 2009-02-01 15:06:21
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 119 GB (82%) free of 146 GB
Total RAM: 959 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:06:56 PM, on 2/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Compaq_Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Compaq_Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Compaq Organize.lnk = ?
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20364.www2.hp.com/CSMWeb/Customer/...DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols3beta/fscax.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe

--
End of file - 10264 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\mskapbho.dll [2008-10-17 247312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2008-06-20 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-11-14 150032]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-03-08 16010240]
"Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE [2005-07-23 237568]
"PCDrProfiler"= []
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2006-02-16 249856]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-02-17 49152]
"HPAIO_PrintFolderMgr"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe [2000-07-14 61440]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SSP Notifier"=C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe [2006-07-12 20480]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe [2008-04-17 9117696]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe

C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup
Compaq Organize.lnk - C:\Program Files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe
iWin Desktop Alerts.lnk - C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-02-07 61440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\iWin Games\iWinGames.exe"="C:\Program Files\iWin Games\iWinGames.exe:*:Enabled:iWin Games application."
"C:\Program Files\iWin Games\WebUpdater.exe"="C:\Program Files\iWin Games\WebUpdater.exe:*:Enabled:iWin Games updater."
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\MySpace\IM\MySpaceIM.exe"="C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 3 months======

2009-02-01 15:06:21 ----D---- C:\rsit
2009-01-17 23:33:55 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2009-01-17 22:11:33 ----D---- C:\Program Files\EA GAMES
2009-01-17 22:11:32 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
2009-01-17 15:26:25 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
2009-01-17 15:26:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-17 15:26:17 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-15 06:34:29 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-06 20:18:25 ----D---- C:\Program Files\Essentials Codec Pack
2008-12-31 10:48:41 ----D---- C:\Program Files\Disney
2008-12-30 19:50:24 ----D---- C:\WINDOWS\Cache
2008-12-30 19:50:23 ----D---- C:\Program Files\Coupons
2008-12-16 23:28:57 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
2008-12-16 23:27:50 ----D---- C:\Program Files\Mozilla Firefox
2008-12-14 00:51:09 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\MySpace
2008-12-14 00:51:01 ----D---- C:\Program Files\MySpace
2008-12-11 07:57:58 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2008-12-11 07:57:02 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-11 07:56:58 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2008-12-11 07:56:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2008-12-06 15:31:06 ----A---- C:\WINDOWS\system32\kbdkor.dll
2008-12-06 15:31:06 ----A---- C:\WINDOWS\system32\kbdjpn.dll
2008-12-06 15:31:06 ----A---- C:\WINDOWS\system32\kbd103.dll
2008-12-06 15:31:06 ----A---- C:\WINDOWS\system32\kbd101c.dll
2008-12-06 15:31:03 ----A---- C:\WINDOWS\system32\kbd101b.dll
2008-12-06 15:31:02 ----A---- C:\WINDOWS\system32\kbd106.dll
2008-11-20 21:27:32 ----D---- C:\WINDOWS\system32\dPI19
2008-11-20 21:17:19 ----A---- C:\WINDOWS\system32\zvpekucihp.exe
2008-11-20 21:17:12 ----D---- C:\WINDOWS\system32\vd2
2008-11-20 21:17:12 ----D---- C:\WINDOWS\system32\tim
2008-11-20 21:17:12 ----D---- C:\WINDOWS\system32\ap
2008-11-13 06:28:32 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-13 06:28:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-13 06:28:13 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-03 13:40:52 ----D---- C:\Program Files\iPod
2008-11-03 13:40:50 ----D---- C:\Program Files\iTunes
2008-11-03 13:40:50 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-03 13:21:00 ----D---- C:\Program Files\Safari

======List of files/folders modified in the last 3 months======

2009-02-01 15:06:29 ----D---- C:\WINDOWS\Temp
2009-02-01 15:06:02 ----D---- C:\WINDOWS\Prefetch
2009-01-31 12:53:17 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-31 12:44:48 ----D---- C:\WINDOWS\system32\Lang
2009-01-31 12:44:29 ----AD---- C:\WINDOWS
2009-01-31 12:43:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-30 18:10:07 ----D---- C:\Program Files\McAfee
2009-01-28 21:25:16 ----D---- C:\WINDOWS\system32
2009-01-28 10:07:28 ----HD---- C:\WINDOWS\inf
2009-01-28 10:07:26 ----D---- C:\WINDOWS\system32\drivers
2009-01-23 11:58:28 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
2009-01-22 06:37:04 ----SHD---- C:\WINDOWS\Installer
2009-01-22 06:37:04 ----SHD---- C:\Config.Msi
2009-01-17 22:11:33 ----D---- C:\Program Files
2009-01-15 06:34:32 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-01-15 06:33:42 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-09 20:35:28 ----A---- C:\WINDOWS\system32\MRT.exe
2008-12-22 20:29:02 ----A---- C:\WINDOWS\imsins.BAK
2008-12-22 20:08:44 ----D---- C:\WINDOWS\Help
2008-12-21 22:43:13 ----D---- C:\Program Files\iWin Games
2008-12-19 19:54:05 ----SD---- C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
2008-12-16 23:30:11 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2008-12-16 14:02:49 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-14 00:51:10 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-13 23:19:08 ----D---- C:\Temp
2008-12-13 01:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-11 07:57:41 ----D---- C:\Program Files\Internet Explorer
2008-12-08 20:51:09 ----D---- C:\WINDOWS\system32\FxsTmp
2008-12-08 20:14:19 ----D---- C:\WINDOWS\system32\Restore
2008-12-01 08:19:45 ----D---- C:\Program Files\Common Files\Adobe
2008-12-01 08:19:32 ----D---- C:\WINDOWS\WinSxS
2008-12-01 08:19:29 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-12-01 08:19:16 ----D---- C:\Program Files\Adobe
2008-11-25 15:24:21 ----D---- C:\Program Files\iWin.com
2008-11-17 22:11:51 ----SD---- C:\WINDOWS\Tasks
2008-11-10 19:44:26 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-11-03 13:41:23 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-11-03 02:39:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-02-07 1480704]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSX_DP;HSX_DP; C:\WINDOWS\system32\DRIVERS\HSX_DP.sys [2005-12-06 936448]
R3 HSXHWBS2;HSXHWBS2; C:\WINDOWS\system32\DRIVERS\HSXHWBS2.sys [2005-12-06 241664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-03-08 4246016]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-01-18 80512]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 winachsx;winachsx; C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys [2005-12-06 670208]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 catchme;catchme; \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\catchme.sys []
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-18 611664]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-02-07 405504]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 iWinGamesInstaller;iWinGamesInstaller; C:\Program Files\iWin Games\iWinGamesInstaller.exe [2008-07-17 78104]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-03-24 73728]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-12-05 206096]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-10-10 792696]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee SpamKiller Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-09-16 605512]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------


Hope you can help. :thumbup2:
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#4 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 01 February 2009 - 09:16 PM

The Grog,

You forgot to post the info.txt:

Please go to start -> Run.
  • Copy and paste the bold line in the run-box and click OK: notepad c:\rsit\info.txt
  • A text file opens, copy and paste the content to your reply.


#5 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 03 February 2009 - 06:32 AM

:thumbup2:

Thought that's what I did. Hence my sig



info.txt logfile of random's system information tool 1.05 2009-02-01 15:07:01

======Uninstall list======

-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00C6-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Alien Outbreak 2-->"C:\Program Files\HP Games\Alien Outbreak 2\Uninstall.exe"
Ancient Sudoku-->"C:\Program Files\HP Games\Ancient Sudoku\Uninstall.exe"
AnswerWorks 4.0 Runtime - English-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}\setup.exe" -l0x9 -removeonly
Apple Mobile Device Support-->MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Bejeweled 2 Deluxe-->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
Big Kahuna Reef-->"C:\Program Files\HP Games\Big Kahuna Reef\Uninstall.exe"
Blackhawk Striker 2-->"C:\Program Files\HP Games\Blackhawk Striker 2\Uninstall.exe"
Blasterball 2 Remix-->"C:\Program Files\HP Games\Blasterball 2 Remix\Uninstall.exe"
Blasterball 2 Revolution-->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Bookworm Deluxe-->"C:\Program Files\HP Games\Bookworm Deluxe\Uninstall.exe"
Bounce Symphony-->"C:\Program Files\HP Games\Bounce Symphony\Uninstall.exe"
Chuzzle Deluxe-->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
Compaq Connections (remove only)-->C:\WINDOWS\HPCPCUninstall-5577497\HPBWSetup.exe -appid 5577497 -uninstall
Compaq Organize-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}\Setup.exe" UNINSTALL
Coupon Printer for Windows-->"C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
Customer Experience Enhancement-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1033
Data Fax SoftModem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\HXFSETUP.EXE -U -ITrx200Ck.inf
Diner Dash-->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
Disney Pirates of the Caribbean Online-->C:\Program Files\Disney\Disney Online\PiratesOnline\uninst.exe
Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /remove
Fairies-->"C:\Program Files\HP Games\Fairies\Uninstall.exe"
Family Feud-->"C:\Program Files\HP Games\Family Feud\Uninstall.exe"
FATE-->"C:\Program Files\HP Games\FATE\Uninstall.exe"
Flip Words-->"C:\Program Files\HP Games\Flip Words\Uninstall.exe"
FP3 Player-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{44170B31-F47A-4FF9-9D77-382D1FE2A728}
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Boot Optimizer-->MsiExec.exe /X{1341D838-719C-4A05-B50F-49420CA1B4BB}
HP DVD Play 2.1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP Game Console-->"C:\Program Files\WildTangent\Apps\HP Game Console\Uninstall.exe"
HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OfficeJet K Series-->"C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\Uninstall\hpourn07.exe" /Path="C:\Program Files\Hewlett-Packard\HP OfficeJet K Series" /Uninstall="HP OfficeJet K Series"
HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Rhapsody-->C:\PROGRA~1\HPRHAP~1\Unwise32.exe /A C:\PROGRA~1\HPRHAP~1\install.log
HP Software Update-->MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
HP Support Overview-->"C:\WINDOWS\unins000.exe"
HP Web Helper-->regsvr32 /u /s "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll"
Insaniquarium Deluxe-->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
iTunes-->MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
iWin Games (remove only)-->"C:\Program Files\iWin Games\Uninstall.exe"
J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
Java™ 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Jewel Quest-->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
JS World Kindergarten-->C:\Program Files\Common Files\Knowledge Adventure\Uninstall\JSWorldKUn.exe
JSWorldKGMain-->C:\Program Files\InstallShield Installation Information\{A943CC79-CC0E-4F74-B613-EAB418F043AD}\setup.exe -runfromtemp -l0x0409
JSWPFCom-->MsiExec.exe /X{9A2F0A59-B202-4D2A-9343-A7E5ACE852B7}
JSWPFGradeK-->MsiExec.exe /I{B2EB23D7-8AA5-457F-82B8-4F60321A9CC7}
JumpStart World Presents Pet Playground-->C:\Program Files\Common Files\Knowledge Adventure\Uninstall\PetPlaygroundUn.exe
LimeWire 4.16.6-->"C:\Program Files\LimeWire\uninstall.exe"
Mah Jong Quest-->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Basic Edition 2003-->MsiExec.exe /I{91130409-6000-11D3-8CFE-0150048383C9}
Microsoft Streets and Trips 2004-->MsiExec.exe /I{8704D51E-25B7-4F23-81E7-AA4F54790210}
MobileMe Control Panel-->MsiExec.exe /I{924EB80F-C2BB-4B9F-8412-88BBA937393F}
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MySpaceIM-->C:\Program Files\MySpace\IM\Uninstall.exe
Mystery Case Files-->"C:\Program Files\HP Games\Mystery Case Files\Uninstall.exe"
Netscape Browser (remove only)-->"C:\Program Files\Netscape\Netscape Browser\NSUninst.exe"
Netscape Navigator (9.0.0.6)-->C:\Program Files\Netscape\Navigator 9\uninstall\helper.exe
PC-Doctor 5 for Windows-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
Poker Superstars-->"C:\Program Files\HP Games\Poker Superstars\Uninstall.exe"
Polar Bowler-->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
Polar Golfer-->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
Puzzle Play Dot-to-Dots-->C:\WINDOWS\unvise32.exe C:\Program Files\sz18103_7_1\uninstal.log
Puzzle Play Hidden Pictures-->C:\WINDOWS\unvise32.exe C:\Program Files\sz18102_7_1\uninstal.log
Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
Quicken 2006-->MsiExec.exe /X{2818095F-FB6C-42C8-827E-0A406CC9AFF5}
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Ricochet Lost Worlds-->"C:\Program Files\HP Games\Ricochet Lost Worlds\Uninstall.exe"
RollerCoaster Tycoon 3 Platinum-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\SETUP.EXE" -l0x9 -removeonly
RON Tool Netupbanner-->C:\WINDOWS\system32\zvpekucihp.exe
Safari-->MsiExec.exe /I{582D2A53-F426-4C5E-A2E6-43C1AB36B907}
SCRABBLE-->"C:\Program Files\HP Games\SCRABBLE\Uninstall.exe"
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Slingo Deluxe-->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
Snowy The Bears Adventure-->"C:\Program Files\HP Games\Snowy The Bears Adventure\Uninstall.exe"
Sonic Express Labeler-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic MyDVD Plus-->MsiExec.exe /X{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio-->MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy-->MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data-->MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager-->MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Super Granny-->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
Tennis Titans-->"C:\Program Files\HP Games\Tennis Titans\Uninstall.exe"
The Sims™ 2 Double Deluxe-->C:\Program Files\EA GAMES\The Sims 2 Double Deluxe\EAUninstall.exe
Tornado Jockey-->"C:\Program Files\HP Games\Tornado Jockey\Uninstall.exe"
Tradewinds-->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
TurboTax Deluxe 2007-->C:\Program Files\TurboTax\Deluxe 2007\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2007\Uninstall.log" -NoGui
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Verizon Online-->C:\WINDOWS\system32\VerizonUninstaller.exe
VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WildTangent Web Driver-->C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
Windows Essentials Media Codec Pack 1.0-->C:\Program Files\Essentials Codec Pack\uninst.exe
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

=====HijackThis Backups=====

O3 - Toolbar: The nssfrch - {AC9BBDB2-8FCD-49C8-96F7-CC3CF7B453CD} - C:\WINDOWS\nssfrch.dll (file missing)
O2 - BHO: MSVPS System - {077F45D5-5CC9-4FC8-A7BB-9D79836A6066} - C:\WINDOWS\movctrlnkd.dll (file missing)

======Hosts File======

127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall

System event log

Computer Name: YOUR-D0F670B45A
Event Code: 7035
Message: The Network Location Awareness (NLA) service was successfully sent a start control.

Record Number: 20159
Source Name: Service Control Manager
Time Written: 20081212081436.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: YOUR-D0F670B45A
Event Code: 7035
Message: The Fast User Switching Compatibility service was successfully sent a start control.

Record Number: 20158
Source Name: Service Control Manager
Time Written: 20081212081436.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: YOUR-D0F670B45A
Event Code: 7036
Message: The Terminal Services service entered the running state.

Record Number: 20157
Source Name: Service Control Manager
Time Written: 20081212081436.000000-300
Event Type: information
User:

Computer Name: YOUR-D0F670B45A
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
ftsata2

Record Number: 20156
Source Name: Service Control Manager
Time Written: 20081212081435.000000-300
Event Type: error
User:

Computer Name: YOUR-D0F670B45A
Event Code: 6005
Message: The Event log service was started.

Record Number: 20155
Source Name: EventLog
Time Written: 20081212081351.000000-300
Event Type: information
User:

Application event log

Computer Name: YOUR-D0F670B45A
Event Code: 0
Message:
Record Number: 678
Source Name: mcmispupdmgr
Time Written: 20071109190259.000000-300
Event Type: information
User:

Computer Name: YOUR-D0F670B45A
Event Code: 5000
Message: McShield service started.

Engine version : 5100.0194

DAT version : 5160.0000



Number of signatures in EXTRA.DAT : None

Names of threats that EXTRA.DAT can detect : None

Record Number: 677
Source Name: McLogEvent
Time Written: 20071109190242.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: YOUR-D0F670B45A
Event Code: 0
Message:
Record Number: 676
Source Name: mcmispupdmgr
Time Written: 20071109190058.000000-300
Event Type: information
User:

Computer Name: YOUR-D0F670B45A
Event Code: 0
Message:
Record Number: 675
Source Name: mcmispupdmgr
Time Written: 20071109190058.000000-300
Event Type: information
User:

Computer Name: YOUR-D0F670B45A
Event Code: 1000
Message: Faulting application iexplore.exe, version 7.0.6000.16544, faulting module msvcrt.dll, version 7.0.2600.2180, fault address 0x000372e3.

Record Number: 674
Source Name: Application Error
Time Written: 20071109182333.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0409
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip

-----------------EOF-----------------
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 03 February 2009 - 03:41 PM

This requires some patience and a cop of coffee as you have some work and some cleaning to do :thumbup2:

Your log(s) show that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world the cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."


Removal Instructions
  • You have the program Spybot S&D (Teatimer option) running on your machine. We need to disable TeaTimer so it does not interfere with the fixes we are about to do. This will only take a few seconds.
    • First disable TeaTimer:
      • Run Spybot-S&D
      • Go to the Mode menu, and make sure Advanced Mode is selected
      • On the left hand side, choose Tools -> Resident
      • Uncheck Resident TeaTimer and OK any prompts
      • Restart your computer.
      Instruction is also here: How to disable TeaTimer during HijackThis Cleanup

      Note:If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

    • Then download ResetTeaTimer.exe to your desktop. (In case you use Firefox, rightclick the link and choose "Save Link As").
      • Doubleclick ResetTeaTimer.exe and let it run.
    Note: The Teatimer should be kept disabled until I give you the clean sign.


  • I see on the log the Coupon Printer for Windows is installed on your computer:
    This program is known to be bundled with adware/spyware.

    To uninstall Coupon Printer for Windows:

    Click "start" on the taskbar and then click on the "Control Panel" icon.
    Please doubleclick the "Add or Remove Programs" icon.
    A list of programs installed will be "populated" this may take a bit of time.
    If they exist, uninstall the following by clicking on the following entries and selecting "remove":

    Coupon Printer for Windows

  • I see on the log iWin Games is installed on your computer:

    This program is known to be Adware.BHO.GEN.
    Adware.BHO.GEN is adware that use BHOs to display ads or can be used for malicious purposes like gathering info on your surfing habits. It also has the functionality to download and install further malicious files from remote servers.You may read more about iWin Games here:
    http://www.threatexpert.com/report.aspx?ui...c3-94261dd31588

    To uninstall iWin Games:

    Click "start" on the taskbar and then click on the "Control Panel" icon.
    Please doubleclick the "Add or Remove Programs" icon.
    A list of programs installed will be "populated" this may take a bit of time.
    If they exist, uninstall the following by clicking on the following entries and selecting "remove":

    iWin Games

  • Go to start > Run copy/paste the following line in the run box and click OK.

    sc stop iWinGamesInstaller
    sc delete iWinGamesInstaller


  • Please open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below (if present):

    O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe


    Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.

  • Open your Malwarebytes' Anti-Malware, first update it, run a "quick scan", let reboot if needed and copy/paste the log to your reply.

    Note: The logs are saved by default under the Logs tab. If the log did not automatically open you can obtain the latest log from there.

  • Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Information on A/V control HERE)
    • Double click on ComboFix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Posted Image


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Posted Image


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

  • Please copy and paste a fresh Hijackthis log to your reply.
Please include in your next reply:
  • The log of MBAM.
  • The Combofix log.
  • A fresh Hijackthis log.
  • Any comment or feedback about how it went.


#7 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 03 February 2009 - 09:05 PM

Farbar,

I did all that you asked. It would not get rid of the coupon printer, that froze up every time I tried to uninstall it. I just installed it recently for some rewards I had won from Coke. I do not think it's malicious but will remove it by other means if you instruct me how.

Of these

O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe

only the middle one was there. Perhaps the others weren't there because I uninstalled it from the control panel.

MBAM LOG:

Malwarebytes' Anti-Malware 1.33
Database version: 1723
Windows 5.1.2600 Service Pack 3

2009-02-03 20:47:04
mbam-log-2009-02-03 (20-47-04).txt

Scan type: Quick Scan
Objects scanned: 69724
Time elapsed: 14 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#8 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 03 February 2009 - 09:08 PM


COMBOFIX LOG:


omboFix 09-02-02.04 - Compaq_Owner 2009-02-03 20:43:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.368 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\temp\FT62
c:\temp\FT62\teTU.log
c:\windows\system32\ap
c:\windows\system32\dPI19
c:\windows\system32\tim
c:\windows\system32\tmp.reg
c:\windows\system32\vd2

.
((((((((((((((((((((((((( Files Created from 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))))))
.

2009-02-01 15:06 . 2009-02-01 15:07 <DIR> d-------- C:\rsit
2009-01-17 23:33 . 2009-01-17 23:33 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-01-17 22:11 . 2009-01-17 22:11 <DIR> d-------- c:\program files\EA GAMES
2009-01-17 22:11 . 2008-03-12 18:38 445,504 -ra------ c:\windows\system32\vp6vfw.dll
2009-01-17 15:26 . 2009-01-17 15:26 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-17 15:26 . 2009-01-17 15:26 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-01-17 15:26 . 2009-01-17 15:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-17 15:26 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-17 15:26 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-06 20:18 . 2009-01-06 20:18 <DIR> d-------- c:\program files\Essentials Codec Pack

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 01:26 --------- d-----w c:\documents and settings\All Users\Application Data\iWin Games
2009-02-04 01:19 --------- d-----w c:\program files\Coupons
2009-02-04 01:12 3,649 ----a-w c:\windows\viassary-hp.reg
2009-01-30 23:10 --------- d-----w c:\program files\McAfee
2009-01-30 19:00 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-01-23 16:58 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\LimeWire
2008-12-31 15:48 --------- d-----w c:\program files\Disney
2008-12-17 04:30 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Apple Computer
2008-12-16 19:02 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 05:51 --------- d-----w c:\program files\MySpace
2008-12-14 05:51 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\MySpace
2008-12-13 06:40 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-11-21 02:18 47,598 ----a-w c:\windows\system32\zvpekucihp.exe
2008-06-12 20:23 56,912 ----a-w c:\documents and settings\Compaq_Owner\g2mdlhlpx.exe
2008-09-14 22:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091420080915\index.dat
.

((((((((((((((((((((((((((((( snapshot@2007-10-28_19.27.10.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-03-24 04:47:44 49,152 ----a-w c:\windows\$hf_mig$\KB904942\SP2QFE\wdigest.dll
+ 2005-10-12 23:12:25 14,048 ----a-w c:\windows\$hf_mig$\KB904942\spmsg.dll
+ 2005-10-12 23:12:26 213,216 ----a-w c:\windows\$hf_mig$\KB904942\spuninst.exe
+ 2005-10-12 23:12:25 22,752 ----a-w c:\windows\$hf_mig$\KB904942\update\spcustom.dll
+ 2005-10-12 23:12:29 716,000 ----a-w c:\windows\$hf_mig$\KB904942\update\update.exe
+ 2005-10-12 23:12:34 371,424 ----a-w c:\windows\$hf_mig$\KB904942\update\updspapi.dll
+ 2008-02-26 11:48:44 297,984 ----a-w c:\windows\$hf_mig$\KB932823-v3\SP2QFE\msctf.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB932823-v3\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB932823-v3\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB932823-v3\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB932823-v3\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB932823-v3\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB938464\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB938464\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB938464\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 ----a-w c:\windows\$hf_mig$\KB938464\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB938464\update\updspapi.dll
+ 2007-10-29 22:35:13 1,287,680 ----a-w c:\windows\$hf_mig$\KB941568\SP2QFE\quartz.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB941568\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB941568\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB941568\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB941568\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB941568\update\updspapi.dll
+ 2007-10-30 16:53:32 360,832 ----a-w c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB941644\update\updspapi.dll
+ 2008-03-19 09:40:27 1,845,888 ----a-w c:\windows\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB941693\update\updspapi.dll
+ 2007-10-10 23:47:27 124,928 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\advpack.dll
+ 2007-10-10 23:47:27 214,528 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\dxtrans.dll
+ 2007-10-10 23:47:27 132,608 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\extmgr.dll
+ 2007-10-10 23:47:27 63,488 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\icardie.dll
+ 2007-10-10 08:16:47 70,656 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ie4uinit.exe
+ 2007-10-10 23:47:27 153,088 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieakeng.dll
+ 2007-10-10 23:47:27 230,400 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieaksie.dll
+ 2007-10-10 05:47:20 161,792 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dat
+ 2007-10-10 23:47:27 383,488 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dll
+ 2007-10-10 23:47:27 388,096 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iedkcs32.dll
+ 2007-10-10 23:47:27 6,067,200 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieframe.dll
+ 2007-10-10 23:47:27 44,544 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iernonce.dll
+ 2007-10-10 23:47:27 267,776 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iertutil.dll
+ 2007-10-10 08:16:47 13,824 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\ieudinit.exe
+ 2007-10-10 08:16:56 625,664 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
+ 2007-10-10 23:47:28 27,648 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\jsproxy.dll
+ 2007-10-10 23:47:28 459,264 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\msfeeds.dll
+ 2007-10-10 23:47:28 52,224 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\msfeedsbs.dll
+ 2007-10-30 23:48:49 3,593,216 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll
+ 2007-10-10 23:47:28 478,208 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\mshtmled.dll
+ 2007-10-10 23:47:28 193,024 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\msrating.dll
+ 2007-10-10 23:47:28 671,232 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\mstime.dll
+ 2007-10-10 23:47:28 102,912 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\occache.dll
+ 2007-10-10 23:47:28 105,984 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\url.dll
+ 2007-10-10 23:47:29 1,162,240 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\urlmon.dll
+ 2007-10-10 23:47:29 233,472 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\webcheck.dll
+ 2007-10-10 23:47:29 825,344 ----a-w c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB942615-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB942615-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB942615-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB942615-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB942615-IE7\update\updspapi.dll
+ 2007-11-13 11:02:46 60,416 ----a-w c:\windows\$hf_mig$\KB942763\SP2QFE\tzchange.exe
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB942763\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB942763\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB942763\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB942763\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB942763\update\updspapi.dll
+ 2007-12-04 18:29:10 551,936 ----a-w c:\windows\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB943055\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB943055\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB943055\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB943055\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB943055\update\updspapi.dll
+ 2007-11-07 09:50:47 727,040 ----a-w c:\windows\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB943485\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB943485\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB943485\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB943485\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB943485\update\updspapi.dll
+ 2007-12-07 02:01:07 124,928 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll
+ 2007-12-19 22:57:52 347,136 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll
+ 2007-12-07 02:01:07 214,528 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll
+ 2007-12-07 02:01:07 133,120 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll
+ 2007-12-07 02:01:07 63,488 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll
+ 2007-12-06 08:34:28 70,656 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe
+ 2007-12-07 02:01:08 153,088 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll
+ 2007-12-07 02:01:08 230,400 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll
+ 2007-12-06 05:00:02 161,792 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat
+ 2007-12-07 02:01:08 383,488 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll
+ 2007-12-07 02:01:08 388,096 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll
+ 2007-12-07 02:01:10 6,067,200 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll
+ 2007-12-07 02:01:10 44,544 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll
+ 2007-12-07 02:01:11 267,776 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll
+ 2007-12-06 08:34:29 13,824 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe
+ 2007-12-06 08:34:45 625,664 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
+ 2007-12-07 02:01:11 27,648 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll
+ 2007-12-07 02:01:11 459,264 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll
+ 2007-12-07 02:01:11 52,224 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll
+ 2007-12-07 02:01:12 3,593,216 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
+ 2007-12-07 02:01:12 478,208 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll
+ 2007-12-07 02:01:13 193,024 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll
+ 2007-12-07 02:01:13 671,232 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll
+ 2007-12-07 02:01:13 102,912 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll
+ 2008-01-11 05:57:26 44,544 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll
+ 2007-12-07 02:01:13 105,984 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\url.dll
+ 2007-12-07 02:01:13 1,162,752 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll
+ 2007-12-07 02:01:13 233,472 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll
+ 2007-12-07 02:01:13 825,344 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB944533-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB944533-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB944533-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB944533-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB944533-IE7\update\updspapi.dll
+ 2007-11-13 08:47:45 20,480 ----a-w c:\windows\$hf_mig$\KB944653\SP2QFE\secdrv.sys
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB944653\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB944653\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB944653\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB944653\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB944653\update\updspapi.dll
+ 2008-02-20 05:19:35 147,968 ----a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:49:36 45,568 ----a-w c:\windows\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB945553\update\updspapi.dll
+ 2007-12-18 09:38:59 179,712 ----a-w c:\windows\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB946026\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB946026\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB946026\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB946026\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB946026\update\updspapi.dll
+ 2008-05-02 13:30:08 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP2QFE\msgsc.dll
+ 2008-05-02 14:01:49 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP3GDR\msgsc.dll
+ 2008-05-02 13:42:10 83,968 ----a-w c:\windows\$hf_mig$\KB946648\SP3QFE\msgsc.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB946648\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB946648\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB946648\update\spcustom.dll
+ 2007-11-30 11:20:44 755,576 ----a-w c:\windows\$hf_mig$\KB946648\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB946648\update\updspapi.dll
+ 2008-03-01 13:03:00 124,928 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
+ 2008-03-01 13:03:00 347,136 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
+ 2008-03-01 13:03:00 214,528 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
+ 2008-03-01 13:03:00 132,608 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
+ 2008-03-01 13:03:00 63,488 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
+ 2008-02-22 09:39:56 70,656 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
+ 2008-03-01 13:03:00 153,088 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
+ 2008-03-01 13:03:00 230,400 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
+ 2008-03-01 13:03:00 383,488 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
+ 2008-03-01 13:03:00 388,608 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
+ 2008-03-01 13:03:01 6,067,712 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
+ 2008-03-01 13:03:01 44,544 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
+ 2008-03-01 13:03:01 267,776 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
+ 2008-02-22 09:39:56 13,824 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
+ 2008-02-22 09:40:22 625,664 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
+ 2008-03-01 13:03:01 27,648 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
+ 2008-03-01 13:03:01 459,264 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
+ 2008-03-01 13:03:01 52,224 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
+ 2008-03-01 13:03:01 3,593,216 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
+ 2008-03-01 13:03:01 478,208 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
+ 2008-03-01 13:03:01 193,024 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
+ 2008-03-01 13:03:01 671,232 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
+ 2008-03-01 13:03:01 102,912 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
+ 2008-03-01 13:03:01 44,544 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
+ 2008-03-01 13:03:02 105,984 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
+ 2008-03-01 13:03:02 1,162,752 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
+ 2008-03-01 13:03:02 233,472 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
+ 2008-03-01 13:03:02 827,392 ----a-w c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB947864-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB947864-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB947864-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB947864-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB947864-IE7\update\updspapi.dll
+ 2008-02-20 06:52:43 282,624 ----a-w c:\windows\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB948590\update\updspapi.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB948881\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB948881\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB948881\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB948881\update\update.exe
+ 2007-03-06 01:23:47 371,424 ----a-w c:\windows\$hf_mig$\KB948881\update\updspapi.dll
+ 2008-01-23 04:56:21 554,008 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-27 07:39:13 151,583 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-12-10 12:41:14 621,344 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 ----a-w c:\windows\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB950749\update\updspapi.dll
+ 2008-04-23 03:35:35 124,928 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\advpack.dll
+ 2008-04-23 03:35:35 347,136 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\dxtmsft.dll
+ 2008-04-23 03:35:35 214,528 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\dxtrans.dll
+ 2008-04-23 03:35:35 132,608 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\extmgr.dll
+ 2008-04-23 03:35:35 63,488 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\icardie.dll
+ 2008-04-22 08:02:19 70,656 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ie4uinit.exe
+ 2008-04-23 03:35:35 153,088 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieakeng.dll
+ 2008-04-23 03:35:35 230,400 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieaksie.dll
+ 2008-04-20 05:07:38 161,792 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dat
+ 2008-04-23 03:35:35 383,488 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dll
+ 2008-04-23 03:35:35 388,608 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iedkcs32.dll
+ 2008-04-23 03:35:36 6,068,224 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieframe.dll
+ 2008-04-23 03:35:36 44,544 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iernonce.dll
+ 2008-04-23 03:35:36 267,776 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iertutil.dll
+ 2008-04-22 08:02:19 13,824 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\ieudinit.exe
+ 2008-04-22 08:02:46 625,664 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
+ 2008-04-23 03:35:36 27,648 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\jsproxy.dll
+ 2008-04-23 03:35:36 459,264 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msfeeds.dll
+ 2008-04-23 03:35:36 52,224 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msfeedsbs.dll
+ 2008-04-23 03:35:36 3,593,728 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
+ 2008-04-23 03:35:36 478,208 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mshtmled.dll
+ 2008-04-23 03:35:36 193,024 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\msrating.dll
+ 2008-04-23 03:35:36 671,232 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\mstime.dll
+ 2008-04-23 03:35:36 102,912 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\occache.dll
+ 2008-04-23 03:35:36 44,544 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\pngfilt.dll
+ 2008-04-23 03:35:36 105,984 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\url.dll
+ 2008-04-23 03:35:36 1,162,752 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\urlmon.dll
+ 2008-04-23 03:35:36 233,472 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\webcheck.dll
+ 2008-04-23 03:35:36 827,392 ----a-w c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB950759-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB950759-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB950759-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB950759-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB950759-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950760\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950760\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950760\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB950760\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB950760\update\updspapi.dll
+ 2008-05-08 12:14:51 203,008 ----a-w c:\windows\$hf_mig$\KB950762\SP2QFE\rmcast.sys
+ 2008-05-08 14:02:52 203,136 ----a-w c:\windows\$hf_mig$\KB950762\SP3GDR\rmcast.sys
+ 2008-05-08 13:58:17 203,136 ----a-w c:\windows\$hf_mig$\KB950762\SP3QFE\rmcast.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950762\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950762\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950762\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB950762\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB950762\update\updspapi.dll
+ 2008-07-07 20:06:43 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
+ 2008-07-07 20:26:58 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
+ 2008-07-07 20:23:18 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-04-11 18:39:39 683,520 ----a-w c:\windows\$hf_mig$\KB951066\SP2QFE\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 ----a-w c:\windows\$hf_mig$\KB951066\SP3GDR\inetcomm.dll
+ 2008-04-12 04:22:26 691,712 ----a-w c:\windows\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951066\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951066\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951066\update\spcustom.dll
+ 2007-12-03 15:25:31 755,576 ----a-w c:\windows\$hf_mig$\KB951066\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951066\update\updspapi.dll
+ 2008-07-14 11:03:00 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
+ 2008-07-11 12:42:28 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
+ 2008-07-11 12:51:51 62,976 ----a-w c:\windows\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-13 09:52:16 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys
+ 2008-06-13 11:05:51 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys
+ 2008-06-13 11:27:43 272,128 ----a-w c:\windows\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951376-v2\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951376-v2\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB951376-v2\update\updspapi.dll
+ 2008-04-14 11:00:16 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP2QFE\bthport.sys
+ 2008-04-14 12:30:49 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP3GDR\bthport.sys
+ 2008-04-14 12:36:35 272,128 ----a-w c:\windows\$hf_mig$\KB951376\SP3QFE\bthport.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951376\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951376\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951376\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB951376\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB951376\update\updspapi.dll
+ 2008-05-07 04:55:40 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP2QFE\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP3GDR\quartz.dll
+ 2008-05-07 05:04:15 1,288,192 ----a-w c:\windows\$hf_mig$\KB951698\SP3QFE\quartz.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB951698\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB951698\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB951698\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB951698\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB951698\update\updspapi.dll
+ 2006-08-16 12:08:32 100,352 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\6to4svc.dll
+ 2008-06-20 10:44:08 138,368 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\afd.sys
+ 2008-06-20 17:36:11 147,968 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\dnsapi.dll
+ 2008-06-20 17:36:11 245,248 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
+ 2008-06-20 10:44:42 360,960 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
+ 2008-06-20 09:32:39 225,920 ----a-w c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip6.sys
+ 2008-06-20 11:40:08 138,496 ----a-w c:\windows\$hf_mig$\KB951748\SP3GDR\afd.sys
+ 2008-06-20 17:46:57 147,968 ----a-w c:\windows\$hf_mig$\KB951748\SP3GDR\dnsapi.dll
+ 2008-06-20 17:46:57 245,248 ----a-w c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
+ 2008-06-20 11:51:12 361,600 ----a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
+ 2008-06-20 11:08:27 225,856 ----a-w c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip6.sys
+ 2008-06-20 11:48:03 138,496 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys
+ 2008-06-20 17:43:05 147,968 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
+ 2008-06-20 17:43:05 245,248 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
+ 2008-06-20 11:59:02 361,600 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
+ 2008-06-20 11:16:44 225,856 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951748\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951748\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951748\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB951748\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB951748\update\updspapi.dll
+ 2008-05-07 09:07:23 135,168 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 ----a-w c:\windows\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w c:\windows\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w c:\windows\$hf_mig$\KB951978\update\updspapi.dll
+ 2008-05-01 15:04:00 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP2QFE\msadce.dll
+ 2008-05-01 14:33:02 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP3GDR\msadce.dll
+ 2008-05-01 14:38:05 331,776 ----a-w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB952287\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB952287\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB952287\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB952287\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB952287\update\updspapi.dll
+ 2008-06-24 16:28:00 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP2QFE\mscms.dll
+ 2008-06-24 16:43:16 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP3GDR\mscms.dll
+ 2008-06-24 16:53:10 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-06-23 16:01:38 124,928 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\advpack.dll
+ 2008-06-23 16:01:38 347,136 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtmsft.dll
+ 2008-06-23 16:01:39 214,528 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\dxtrans.dll
+ 2008-06-23 16:01:39 132,608 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\extmgr.dll
+ 2008-06-23 16:01:39 63,488 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\icardie.dll
+ 2008-06-23 08:23:18 70,656 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe
+ 2008-06-23 16:01:39 153,088 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakeng.dll
+ 2008-06-23 16:01:39 230,400 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieaksie.dll
+ 2008-06-21 05:23:53 161,792 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dat
+ 2008-06-23 16:01:40 383,488 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dll
+ 2008-06-23 16:01:40 388,608 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iedkcs32.dll
+ 2008-06-23 16:01:43 6,068,736 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieframe.dll
+ 2008-06-23 16:01:43 44,544 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iernonce.dll
+ 2008-06-23 16:01:44 267,776 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iertutil.dll
+ 2008-06-23 08:23:18 13,824 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe
+ 2008-06-23 08:23:52 625,664 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
+ 2008-06-23 16:01:46 27,648 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\jsproxy.dll
+ 2008-06-23 16:01:46 459,264 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeeds.dll
+ 2008-06-23 16:01:46 52,224 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msfeedsbs.dll
+ 2008-06-23 16:01:49 3,594,240 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
+ 2008-06-23 16:01:49 477,696 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtmled.dll
+ 2008-06-23 16:01:49 193,024 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\msrating.dll
+ 2008-06-23 16:01:50 671,232 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mstime.dll
+ 2008-06-23 16:01:50 102,912 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\occache.dll
+ 2008-06-23 16:01:50 44,544 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\pngfilt.dll
+ 2008-06-23 16:01:50 105,984 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\url.dll
+ 2008-06-23 16:01:51 1,162,752 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\urlmon.dll
+ 2008-06-23 16:01:51 233,472 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\webcheck.dll
+ 2008-06-23 16:01:51 827,904 ----a-w c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB953838-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB953838-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB953838-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB953838-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB953838-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB953839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB953839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB953839\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB953839\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB953839\update\updspapi.dll
+ 2008-09-15 12:25:27 1,846,912 ----a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954211\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954211\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954211\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB954211\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954211\update\updspapi.dll
+ 2008-09-10 01:10:56 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2008-10-03 09:49:31 247,326 ----a-w c:\windows\$hf_mig$\KB954600\SP3QFE\strmdll.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB954600\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB954600\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB954600\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB954600\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB954600\update\updspapi.dll
+ 2008-09-04 17:12:27 1,106,944 ----a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 18:08:38 382,840 ----a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-08-26 09:08:35 124,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\advpack.dll
+ 2008-08-26 09:08:36 347,136 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
+ 2008-08-26 09:08:36 214,528 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
+ 2008-08-26 09:08:36 132,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\extmgr.dll
+ 2008-08-26 09:08:36 63,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
+ 2008-08-25 08:43:21 70,656 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
+ 2008-08-26 09:08:36 153,088 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
+ 2008-08-26 09:08:36 230,400 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieaksie.dll
+ 2008-08-23 05:54:50 161,792 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
+ 2008-08-26 09:08:36 380,928 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dll
+ 2008-08-26 09:08:37 388,608 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-03 17:26:50 6,068,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
+ 2008-08-26 09:08:39 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
+ 2008-08-26 09:08:39 267,776 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
+ 2008-08-25 08:43:21 13,824 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
+ 2008-08-26 09:08:40 27,648 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
+ 2008-08-26 09:08:40 459,264 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
+ 2008-08-26 09:08:40 52,224 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
+ 2008-08-26 09:08:43 3,594,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
+ 2008-08-26 09:08:43 477,696 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
+ 2008-08-26 09:08:44 193,024 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
+ 2008-08-26 09:08:44 671,232 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
+ 2008-08-26 09:08:44 102,912 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
+ 2008-08-26 09:08:44 44,544 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
+ 2008-08-26 09:08:44 105,984 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
+ 2008-08-26 09:08:45 1,162,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
+ 2008-08-26 09:08:45 233,472 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\webcheck.dll
+ 2008-08-26 09:08:45 827,904 ----a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-08-14 10:34:26 138,496 ----a-w c:\windows\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-08-14 10:39:28 2,145,280 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe
+ 2008-08-14 19:39:46 2,066,048 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
+ 2008-08-14 10:09:44 2,023,936 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe
+ 2008-08-14 20:11:10 2,189,184 ----a-w c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB956841\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB956841\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB956841\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB956841\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956841\update\updspapi.dll
+ 2008-09-08 11:37:19 333,824 ----a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB957095\update\updspapi.dll
+ 2008-10-24 11:41:11 455,936 ----a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 13:02:04 755,576 ----a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 13:02:12 382,840 ----a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-10-16 20:24:09 124,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\advpack.dll
+ 2008-10-16 20:24:09 347,136 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtmsft.dll
+ 2008-10-16 20:24:09 214,528 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\dxtrans.dll
+ 2008-10-16 20:24:09 132,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\extmgr.dll
+ 2008-10-16 20:24:09 63,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\icardie.dll
+ 2008-10-16 12:46:08 70,656 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ie4uinit.exe
+ 2008-10-16 20:24:09 153,088 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakeng.dll
+ 2008-10-16 20:24:09 230,400 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieaksie.dll
+ 2008-10-15 06:33:26 161,792 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dat
+ 2008-10-16 20:24:09 380,928 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieapfltr.dll
+ 2008-10-16 20:24:09 388,608 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iedkcs32.dll
+ 2008-10-16 20:24:09 6,068,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieframe.dll
+ 2008-10-16 20:24:09 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iernonce.dll
+ 2008-10-16 20:24:09 267,776 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iertutil.dll
+ 2008-10-16 12:46:08 13,824 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ieudinit.exe
+ 2008-10-15 06:34:58 633,632 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
+ 2008-10-16 20:24:10 27,648 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\jsproxy.dll
+ 2008-10-16 20:24:10 459,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeeds.dll
+ 2008-10-16 20:24:10 52,224 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msfeedsbs.dll
+ 2008-10-16 20:24:10 3,595,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
+ 2008-10-16 20:24:10 477,696 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtmled.dll
+ 2008-10-16 20:24:10 193,024 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\msrating.dll
+ 2008-10-16 20:24:10 671,232 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mstime.dll
+ 2008-10-16 20:24:10 102,912 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\occache.dll
+ 2008-10-16 20:24:10 44,544 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\pngfilt.dll
+ 2008-10-16 20:24:10 105,984 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\url.dll
+ 2008-10-16 20:24:11 1,163,264 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\urlmon.dll
+ 2008-10-16 20:24:11 233,472 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\webcheck.dll
+ 2008-10-16 20:24:11 827,904 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB958215-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w c:\windows\$hf_mig$\KB958215-IE7\update\updspapi.dll
+ 2008-10-15 16:25:53 339,456 ----a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB958644\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB958644\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB958644\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958644\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958644\update\updspapi.dll
+ 2008-12-13 06:26:56 3,594,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
+ 2007-03-06 01:22:33 14,048 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 ----a-w c:\windows\$hf_mig$\KB960714-IE7\spuninst.exe
+ 2007-03-06 01:22:31 22,752 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\spcustom.dll
+ 2007-03-06 01:22:56 716,000 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\update.exe
+ 2007-03-06 01:23:47 371,424 ----a-w c:\windows\$hf_mig$\KB960714-IE7\update\updspapi.dll
+ 2004-08-04 13:10:08 53,248 -c----w c:\windows\$NtServicePackUninstall$\1394bus.sys
+ 2006-08-16 11:58:05 100,352 -c----w c:\windows\$NtServicePackUninstall$\6to4svc.dll
+ 2007-09-29 23:07:27 2,678 -c----w c:\windows\$NtServicePackUninstall$\8jdzftvn.dat
+ 2004-08-04 11:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\accwiz.exe
+ 2004-08-04 11:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll
+ 2004-08-04 11:00:00 1,852,416 -c----w c:\windows\$NtServicePackUninstall$\acgenral.dll.000
+ 2004-08-04 11:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll
+ 2004-08-04 11:00:00 450,048 -c----w c:\windows\$NtServicePackUninstall$\aclayers.dll.000
+ 2004-08-04 11:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll
+ 2004-08-04 11:00:00 137,728 -c----w c:\windows\$NtServicePackUninstall$\aclua.dll.000
+ 2004-08-04 11:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\aclui.dll
+ 2004-08-04 11:00:00 187,776 -c----w c:\windows\$NtServicePackUninstall$\acpi.sys
+ 2004-08-04 11:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll
+ 2004-08-04 11:00:00 244,736 -c----w c:\windows\$NtServicePackUninstall$\acspecfc.dll.000
+ 2004-08-04 11:00:00 194,048 -c----w c:\windows\$NtServicePackUninstall$\activeds.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\actmovie.exe
+ 2004-08-04 11:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\actxprxy.dll
+ 2004-08-04 11:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll
+ 2004-08-04 11:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\acxtrnal.dll.000
+ 2003-03-24 23:52:04 20,540 -c----w c:\windows\$NtServicePackUninstall$\admin.dll
+ 2003-03-24 23:52:04 16,439 -c----w c:\windows\$NtServicePackUninstall$\admin.exe
+ 2004-08-04 11:00:00 175,616 -c----w c:\windows\$NtServicePackUninstall$\adsldp.dll
+ 2004-08-04 11:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\adsldpc.dll
+ 2004-08-04 11:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\adsmsext.dll
+ 2004-08-04 11:00:00 263,680 -c----w c:\windows\$NtServicePackUninstall$\adsnt.dll
+ 2004-08-04 11:00:00 616,960 -c----w c:\windows\$NtServicePackUninstall$\advapi32.dll
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys
+ 2006-02-15 00:22:26 142,464 -c----w c:\windows\$NtServicePackUninstall$\aec.sys.000
+ 2008-06-20 10:44:38 138,368 -c----w c:\windows\$NtServicePackUninstall$\afd.sys
+ 2004-08-04 11:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentanm.dll
+ 2004-08-04 11:00:00 214,016 -c----w c:\windows\$NtServicePackUninstall$\agentctl.dll
+ 2006-10-12 13:54:18 42,496 -c----w c:\windows\$NtServicePackUninstall$\agentdp2.dll
+ 2007-03-09 13:58:57 57,344 -c----w c:\windows\$NtServicePackUninstall$\agentdpv.dll
+ 2004-08-04 11:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\agentmpx.dll
+ 2004-08-04 11:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agentpsh.dll
+ 2004-08-04 11:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\agentsr.dll
+ 2006-10-12 11:54:07 256,512 -c----w c:\windows\$NtServicePackUninstall$\agentsvr.exe
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0401.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0404.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0405.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0406.dll
+ 2004-08-04 11:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt0407.dll
+ 2004-08-04 11:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\agt0408.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0409.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt040b.dll
+ 2004-08-04 11:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\agt040c.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt040d.dll
+ 2004-08-04 11:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\agt040e.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0410.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0411.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0412.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0413.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0414.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0415.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0416.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0419.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041d.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt041f.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\agt0804.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\agt0816.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\agt0c0a.dll
+ 2004-08-04 11:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\agtintl.dll
+ 2004-08-04 11:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\ahui.exe
+ 2004-08-04 11:00:00 44,544 -c----w c:\windows\$NtServicePackUninstall$\alg.exe
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\alrsvc.dll
+ 2004-08-04 11:00:00 36,992 -c----w c:\windows\$NtServicePackUninstall$\amdk6.sys
+ 2004-08-04 11:00:00 37,376 -c----w c:\windows\$NtServicePackUninstall$\amdk7.sys
+ 2004-08-04 11:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\amstream.dll
+ 2004-08-04 11:00:00 126,976 -c----w c:\windows\$NtServicePackUninstall$\apphelp.dll
+ 2004-08-04 11:00:00 331,264 -c----w c:\windows\$NtServicePackUninstall$\aqueue.dll
+ 2004-08-04 11:00:00 60,800 -c----w c:\windows\$NtServicePackUninstall$\arp1394.sys
+ 2004-08-04 11:00:00 65,024 -c----w c:\windows\$NtServicePackUninstall$\asycfilt.dll
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\asyncmac.sys
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\at.exe
+ 2004-08-04 12:59:44 95,360 -c----w c:\windows\$NtServicePackUninstall$\atapi.sys
+ 2004-08-04 11:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\atl.dll
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\atmadm.exe
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\atmarpc.sys
+ 2004-08-04 11:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\atmfd.dll
+ 2004-08-04 11:00:00 55,936 -c----w c:\windows\$NtServicePackUninstall$\atmlane.sys
+ 2004-08-04 11:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\atmlib.dll
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\attrib.exe
+ 2004-08-04 11:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\audiosrv.dll
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\auditusr.exe
+ 2003-03-24 23:52:04 20,540 -c----w c:\windows\$NtServicePackUninstall$\author.dll
+ 2003-03-24 23:52:04 16,439 -c----w c:\windows\$NtServicePackUninstall$\author.exe
+ 2005-03-02 18:09:29 56,832 -c----w c:\windows\$NtServicePackUninstall$\authz.dll
+ 2004-08-04 11:00:00 588,800 -c----w c:\windows\$NtServicePackUninstall$\autochk.exe
+ 2004-08-04 11:00:00 602,624 -c----w c:\windows\$NtServicePackUninstall$\autoconv.exe
+ 2004-08-04 11:00:00 580,608 -c----w c:\windows\$NtServicePackUninstall$\autofmt.exe
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\autolfn.exe
+ 2004-08-04 11:00:00 84,992 -c----w c:\windows\$NtServicePackUninstall$\avifil32.dll
+ 2004-08-04 11:00:00 52,736 -c----w c:\windows\$NtServicePackUninstall$\basesrv.dll
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\batmeter.dll
+ 2004-08-04 11:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\batt.dll
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\bidispl.dll
+ 2004-08-04 11:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\bitsprx2.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\bitsprx3.dll
+ 2004-08-04 11:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\blastcln.exe
+ 2004-08-04 11:00:00 71,552 -c----w c:\windows\$NtServicePackUninstall$\bridge.sys
+ 2004-08-04 11:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\browselc.dll
+ 2004-08-04 11:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\browser.dll
+ 2006-09-23 16:12:50 1,022,976 -c----w c:\windows\$NtServicePackUninstall$\browseui.dll
+ 2004-08-04 11:00:00 78,336 -c----w c:\windows\$NtServicePackUninstall$\browsewm.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\bthci.dll
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\$NtServicePackUninstall$\bthport.sys.000
+ 2004-08-04 11:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\bthserv.dll
+ 2004-08-04 11:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\btpanui.dll
+ 2004-08-04 11:00:00 218,112 -c----w c:\windows\$NtServicePackUninstall$\c_g18030.dll
+ 2007-09-29 23:07:31 2,678 -c----w c:\windows\$NtServicePackUninstall$\c0r3jxzr.dat
+ 2007-09-29 23:07:27 2,678 -c----w c:\windows\$NtServicePackUninstall$\c6e88jbl.dat
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\cabinet.dll
+ 2004-08-04 11:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\cabview.dll
+ 2004-08-04 11:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\cacls.exe
+ 2004-08-04 11:00:00 385,024 -c----w c:\windows\$NtServicePackUninstall$\callcont.dll
+ 2004-08-04 11:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\camocx.dll
+ 2004-08-04 11:00:00 142,848 -c----w c:\windows\$NtServicePackUninstall$\capesnpn.dll
+ 2005-07-26 11:39:42 225,792 -c----w c:\windows\$NtServicePackUninstall$\catsrv.dll
+ 2004-08-04 11:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\catsrvps.dll
+ 2005-07-26 11:39:43 625,152 -c----w c:\windows\$NtServicePackUninstall$\catsrvut.dll
+ 2004-08-04 11:00:00 63,744 -c----w c:\windows\$NtServicePackUninstall$\cdfs.sys
+ 2006-01-10 01:01:58 151,040 -c----w c:\windows\$NtServicePackUninstall$\cdfview.dll
+ 2005-09-10 01:53:41 2,067,968 -c----w c:\windows\$NtServicePackUninstall$\cdosys.dll
+ 2004-08-04 11:00:00 49,536 -c----w c:\windows\$NtServicePackUninstall$\cdrom.sys
+ 2004-08-04 11:00:00 194,560 -c----w c:\windows\$NtServicePackUninstall$\certcli.dll
+ 2004-08-04 11:00:00 457,728 -c----w c:\windows\$NtServicePackUninstall$\certmgr.dll
+ 2004-08-04 11:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\cfgbkend.dll
+ 2004-08-04 11:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\cfgmgr32.dll
+ 2003-03-24 23:52:04 188,480 -c----w c:\windows\$NtServicePackUninstall$\cfgwiz.exe
+ 2004-08-04 11:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\cic.dll
+ 2004-08-04 11:00:00 1,352,192 -c----w c:\windows\$NtServicePackUninstall$\cimwin32.dll
+ 2006-06-22 05:06:29 69,120 -c----w c:\windows\$NtServicePackUninstall$\ciodm.dll
+ 2004-08-04 11:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\cisvc.exe
+ 2004-08-04 11:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\classpnp.sys
+ 2005-07-26 11:39:43 110,080 -c----w c:\windows\$NtServicePackUninstall$\clbcatex.dll
+ 2005-07-26 11:39:43 498,688 -c----w c:\windows\$NtServicePackUninstall$\clbcatq.dll
+ 2004-08-04 11:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\cleanmgr.exe
+ 2004-08-04 11:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\cliconfg.exe
+ 2004-08-04 11:00:00 102,912 -c----w c:\windows\$NtServicePackUninstall$\clipbrd.exe
+ 2004-08-04 11:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\clipsrv.exe
+ 2004-08-04 11:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\clusapi.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\cmcfg32.dll
+ 2004-08-04 11:00:00 388,608 -c----w c:\windows\$NtServicePackUninstall$\cmd.exe
+ 2004-08-04 11:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\cmdial32.dll
+ 2004-08-04 11:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cmdl32.exe
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmmon32.exe
+ 2004-08-04 11:00:00 185,344 -c----w c:\windows\$NtServicePackUninstall$\cmprops.dll
+ 2004-08-04 11:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\cmsetacl.dll
+ 2004-08-04 11:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cmstp.exe
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\cmutil.dll
+ 2004-08-04 11:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\cnbjmon.dll
+ 2005-07-26 11:39:43 60,416 -c----w c:\windows\$NtServicePackUninstall$\colbact.dll
+ 2004-08-04 11:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\comaddin.dll
+ 2005-07-26 11:39:44 195,072 -c----w c:\windows\$NtServicePackUninstall$\comadmin.dll
+ 2006-08-25 15:45:58 617,472 -c----w c:\windows\$NtServicePackUninstall$\comctl32.dll
+ 2004-08-04 11:00:00 276,992 -c----w c:\windows\$NtServicePackUninstall$\comdlg32.dll
+ 2004-08-04 11:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\compatui.dll
+ 2004-08-04 11:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\compstui.dll
+ 2005-07-26 11:39:44 97,792 -c----w c:\windows\$NtServicePackUninstall$\comrepl.dll
+ 2004-08-04 11:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\comrepl.exe
+ 2004-08-04 11:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\comrereg.exe
+ 2004-08-04 11:00:00 792,064 -c----w c:\windows\$NtServicePackUninstall$\comres.dll
+ 2004-08-04 11:00:00 259,584 -c----w c:\windows\$NtServicePackUninstall$\comsetup.dll
+ 2004-08-04 11:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\comsnap.dll
+ 2005-07-26 11:39:44 1,267,200 -c----w c:\windows\$NtServicePackUninstall$\comsvcs.dll
+ 2005-07-26 11:39:45 540,160 -c----w c:\windows\$NtServicePackUninstall$\comuid.dll
+ 2004-08-04 11:00:00 1,032,192 -c----w c:\windows\$NtServicePackUninstall$\conf.exe
+ 2004-08-04 11:00:00 45,056 -c----w c:\windows\$NtServicePackUninstall$\confmrsl.dll
+ 2004-08-04 11:00:00 345,600 -c----w c:\windows\$NtServicePackUninstall$\confmsp.dll
+ 2004-08-04 11:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\conime.exe
+ 2007-08-13 22:42:54 17,408 -c----w c:\windows\$NtServicePackUninstall$\corpol.dll
+ 2004-08-04 11:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\credui.dll
+ 2004-08-04 11:00:00 36,480 -c----w c:\windows\$NtServicePackUninstall$\crusoe.sys
+ 2004-08-04 11:00:00 597,504 -c----w c:\windows\$NtServicePackUninstall$\crypt32.dll
+ 2004-08-04 11:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\cryptdlg.dll
+ 2004-08-04 11:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\cryptdll.dll
+ 2004-08-04 11:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\cryptext.dll
+ 2004-08-04 11:00:00 63,488 -c----w c:\windows\$NtServicePackUninstall$\cryptnet.dll
+ 2004-08-04 11:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\cryptsvc.dll
+ 2004-08-04 11:00:00 512,512 -c----w c:\windows\$NtServicePackUninstall$\cryptui.dll
+ 2004-08-04 11:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\cscdll.dll
+ 2004-08-04 11:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\cscript.exe
+ 2004-08-04 11:00:00 326,656 -c----w c:\windows\$NtServicePackUninstall$\cscui.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\csrsrv.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\csrss.exe
+ 2004-08-04 11:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\ctfmon.exe
+ 2006-06-03 11:40:49 33,792 -c----w c:\windows\$NtServicePackUninstall$\custsat.dll
+ 2004-08-04 11:00:00 1,179,648 -c----w c:\windows\$NtServicePackUninstall$\d3d8.dll
+ 2004-08-04 11:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\d3d8thk.dll
+ 2004-08-04 11:00:00 1,689,088 -c----w c:\windows\$NtServicePackUninstall$\d3d9.dll
+ 2004-08-04 11:00:00 825,344 -c----w c:\windows\$NtServicePackUninstall$\d3dim700.dll
+ 2006-01-10 01:01:58 1,054,208 -c----w c:\windows\$NtServicePackUninstall$\danim.dll
+ 2004-08-04 11:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\dataclen.dll
+ 2004-08-04 11:00:00 152,064 -c----w c:\windows\$NtServicePackUninstall$\datime.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\davclnt.dll
+ 2004-08-04 11:00:00 640,000 -c----w c:\windows\$NtServicePackUninstall$\dbghelp.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\dbmsrpcn.dll
+ 2004-08-04 11:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\dbnetlib.dll
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dbnmpntw.dll
+ 2004-08-04 11:00:00 1,788 -c----w c:\windows\$NtServicePackUninstall$\dcache.bin
+ 2004-08-04 11:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\dcap32.dll
+ 2004-08-04 11:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\dciman32.dll
+ 2004-08-04 11:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dcomcnfg.exe
+ 2004-08-04 11:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\ddeshare.exe
+ 2004-08-04 11:00:00 266,240 -c----w c:\windows\$NtServicePackUninstall$\ddraw.dll
+ 2004-08-04 11:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\ddrawex.dll
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\defrag.exe
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\devenum.dll
+ 2004-08-04 11:00:00 282,624 -c----w c:\windows\$NtServicePackUninstall$\devmgr.dll
+ 2004-08-04 11:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dfrgfat.exe
+ 2004-08-04 11:00:00 104,960 -c----w c:\windows\$NtServicePackUninstall$\dfrgntfs.exe
+ 2004-08-04 11:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\dfrgsnap.dll
+ 2004-08-04 11:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\dfrgui.dll
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dfsshlex.dll
+ 2004-08-04 11:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\dgnet.dll
+ 2006-05-19 12:59:41 111,616 -c----w c:\windows\$NtServicePackUninstall$\dhcpcsvc.dll
+ 2004-08-04 11:00:00 370,176 -c----w c:\windows\$NtServicePackUninstall$\dhcpmon.dll
+ 2004-08-04 11:00:00 539,136 -c----w c:\windows\$NtServicePackUninstall$\dialer.exe
+ 2004-08-04 11:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\diantz.exe
+ 2004-08-04 11:00:00 68,608 -c----w c:\windows\$NtServicePackUninstall$\digest.dll
+ 2004-08-04 11:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\dinput.dll
+ 2004-08-04 11:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dinput8.dll
+ 2007-05-16 15:12:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\directdb.dll
+ 2004-08-04 11:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\disk.sys
+ 2004-08-04 11:00:00 1,501,696 -c----w c:\windows\$NtServicePackUninstall$\diskcopy.dll
+ 2004-08-04 11:00:00 14,208 -c----w c:\windows\$NtServicePackUninstall$\diskdump.sys
+ 2004-08-04 11:00:00 163,840 -c----w c:\windows\$NtServicePackUninstall$\diskpart.exe
+ 2004-08-04 11:00:00 45,083 -c----w c:\windows\$NtServicePackUninstall$\dispex.dll
+ 2004-08-04 11:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\dllhost.exe
+ 2004-08-04 11:00:00 224,768 -c----w c:\windows\$NtServicePackUninstall$\dmadmin.exe
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\dmband.dll
+ 2004-08-04 11:00:00 799,744 -c----w c:\windows\$NtServicePackUninstall$\dmboot.sys
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\dmcompos.dll
+ 2004-08-04 11:00:00 273,920 -c----w c:\windows\$NtServicePackUninstall$\dmdlgs.dll
+ 2004-08-04 11:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\dmdskmgr.dll
+ 2004-08-04 11:00:00 181,248 -c----w c:\windows\$NtServicePackUninstall$\dmime.dll
+ 2004-08-04 11:00:00 153,344 -c----w c:\windows\$NtServicePackUninstall$\dmio.sys
+ 2004-08-04 11:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\dmloader.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\dmremote.exe
+ 2004-08-04 11:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\dmscript.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dmserver.dll
+ 2004-08-04 11:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\dmstyle.dll
+ 2004-08-04 11:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\dmsynth.dll
+ 2004-08-04 11:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\dmusic.dll
+ 2004-08-04 13:07:40 52,864 -c----w c:\windows\$NtServicePackUninstall$\dmusic.sys
+ 2004-08-04 11:00:00 52,224 -c----w c:\windows\$NtServicePackUninstall$\dmutil.dll
+ 2008-06-20 17:41:10 148,992 -c----w c:\windows\$NtServicePackUninstall$\dnsapi.dll
+ 2008-02-20 05:32:43 45,568 -c----w c:\windows\$NtServicePackUninstall$\dnsrslvr.dll
+ 2004-08-04 11:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\docprop2.dll
+ 2004-08-04 02:58:30 207,360 -c----w c:\windows\$NtServicePackUninstall$\dot4.sys
+ 2004-08-04 11:00:00 97,280 -c----w c:\windows\$NtServicePackUninstall$\dpcdll.dll
+ 2004-08-04 11:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\dplaysvr.exe
+ 2004-08-04 11:00:00 229,888 -c----w c:\windows\$NtServicePackUninstall$\dplayx.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\dpmodemx.dll
+ 2004-08-04 11:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnaddr.dll
+ 2004-08-04 11:00:00 375,296 -c----w c:\windows\$NtServicePackUninstall$\dpnet.dll
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\dpnhpast.dll
+ 2004-08-04 11:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\dpnhupnp.dll
+ 2004-08-04 11:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\dpnlobby.dll
+ 2004-08-04 11:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\dpnsvr.exe
+ 2004-08-04 11:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\dpvacm.dll
+ 2004-08-04 11:00:00 212,480 -c----w c:\windows\$NtServicePackUninstall$\dpvoice.dll
+ 2004-08-04 11:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\dpvsetup.exe
+ 2004-08-04 11:00:00 116,736 -c----w c:\windows\$NtServicePackUninstall$\dpvvox.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\dpwsockx.dll
+ 2004-08-04 13:08:00 60,288 -c----w c:\windows\$NtServicePackUninstall$\drmk.sys
+ 2004-08-04 13:07:58 2,944 -c----w c:\windows\$NtServicePackUninstall$\drmkaud.sys
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\drprov.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\ds32gt.dll
+ 2004-08-04 11:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\dsdmo.dll
+ 2004-08-04 11:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\dsdmoprp.dll
+ 2004-08-04 11:00:00 92,672 -c----w c:\windows\$NtServicePackUninstall$\dskquota.dll
+ 2004-08-04 11:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\dskquoui.dll
+ 2004-08-04 11:00:00 367,616 -c----w c:\windows\$NtServicePackUninstall$\dsound.dll
+ 2004-08-04 11:00:00 1,294,336 -c----w c:\windows\$NtServicePackUninstall$\dsound3d.dll
+ 2004-08-04 11:00:00 142,336 -c----w c:\windows\$NtServicePackUninstall$\dsprop.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\dsprpres.dll
+ 2004-08-04 11:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\dsquery.dll
+ 2004-08-04 11:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\dssec.dll
+ 2004-08-04 11:00:00 137,216 -c----w c:\windows\$NtServicePackUninstall$\dssenh.dll
+ 2004-08-04 11:00:00 113,152 -c----w c:\windows\$NtServicePackUninstall$\dsuiext.dll
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\dswave.dll
+ 2004-08-04 11:00:00 10,752 -c----w c:\windows\$NtServicePackUninstall$\dumprep.exe
+ 2004-08-04 11:00:00 304,128 -c----w c:\windows\$NtServicePackUninstall$\duser.dll
+ 2004-08-04 11:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\dvdupgrd.exe
+ 2004-08-04 11:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\dwwin.exe
+ 2004-08-04 11:00:00 619,008 -c----w c:\windows\$NtServicePackUninstall$\dx7vb.dll
+ 2004-08-04 11:00:00 1,227,264 -c----w c:\windows\$NtServicePackUninstall$\dx8vb.dll
+ 2004-08-04 11:00:00 1,298,432 -c----w c:\windows\$NtServicePackUninstall$\dxdiag.exe
+ 2004-08-04 11:00:00 2,113,536 -c----w c:\windows\$NtServicePackUninstall$\dxdiagn.dll
+ 2004-08-04 11:00:00 71,040 -c----w c:\windows\$NtServicePackUninstall$\dxg.sys
+ 2006-08-22 08:05:26 498,742 -c----w c:\windows\$NtServicePackUninstall$\dxmasf.dll
+ 2004-08-04 11:00:00 183,296 -c----w c:\windows\$NtServicePackUninstall$\els.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\encapi.dll
+ 2004-08-04 11:00:00 186,368 -c----w c:\windows\$NtServicePackUninstall$\encdec.dll
+ 2004-08-04 11:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\ersvc.dll
+ 2008-07-07 20:32:22 253,952 -c----w c:\windows\$NtServicePackUninstall$\es.dll
+ 2005-10-20 22:20:03 1,082,368 -c----w c:\windows\$NtServicePackUninstall$\esent.dll
+ 2004-08-04 11:00:00 247,808 -c----w c:\windows\$NtServicePackUninstall$\esscli.dll
+ 2004-08-04 11:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\eudcedit.exe
+ 2004-08-04 11:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\eventlog.dll
+ 2004-08-04 11:00:00 101,888 -c----w c:\windows\$NtServicePackUninstall$\evntagnt.dll
+ 2004-08-04 11:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\evntcmd.exe
+ 2004-08-04 11:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\evntrprv.dll
+ 2004-08-04 11:00:00 92,160 -c----w c:\windows\$NtServicePackUninstall$\evntwin.exe
+ 2007-06-13 10:23:07 1,033,216 -c----w c:\windows\$NtServicePackUninstall$\explorer.exe
+ 2004-08-04 11:00:00 380,957 -c----w c:\windows\$NtServicePackUninstall$\expsrv.dll
+ 2004-08-04 11:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\extrac32.exe
+ 2004-08-04 11:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\exts.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\f3ahvoas.dll
+ 2004-08-04 11:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fastfat.sys
+ 2004-08-04 11:00:00 472,064 -c----w c:\windows\$NtServicePackUninstall$\fastprox.dll
+ 2004-08-04 11:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\faultrep.dll
+ 2004-08-04 11:00:00 27,392 -c----w c:\windows\$NtServicePackUninstall$\fdc.sys
+ 2004-08-04 11:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\feclient.dll
+ 2004-08-04 11:00:00 337,920 -c----w c:\windows\$NtServicePackUninstall$\filemgmt.dll
+ 2004-08-04 11:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\findstr.exe
+ 2004-08-04 11:00:00 34,944 -c----w c:\windows\$NtServicePackUninstall$\fips.sys
+ 2004-08-04 11:00:00 87,552 -c----w c:\windows\$NtServicePackUninstall$\fldrclnr.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\flpydisk.sys
+ 2006-08-21 12:21:06 16,896 -c----w c:\windows\$NtServicePackUninstall$\fltlib.dll
+ 2006-08-21 09:14:58 23,040 -c----w c:\windows\$NtServicePackUninstall$\fltmc.exe
+ 2006-08-21 09:14:58 128,896 -c----w c:\windows\$NtServicePackUninstall$\fltmgr.sys
+ 2004-08-04 11:00:00 382,976 -c----w c:\windows\$NtServicePackUninstall$\fontext.dll
+ 2005-10-18 04:14:45 80,896 -c----w c:\windows\$NtServicePackUninstall$\fontsub.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\fontview.exe
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\forcedos.exe
+ 2004-08-04 11:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\format.com
+ 2004-08-04 11:00:00 32,828 -c----w c:\windows\$NtServicePackUninstall$\fp40ext.dll
+ 2004-05-13 07:39:48 184,435 -c----w c:\windows\$NtServicePackUninstall$\fp4amsft.dll
+ 2003-03-24 23:52:04 82,035 -c----w c:\windows\$NtServicePackUninstall$\fp4anscp.dll
+ 2003-03-24 23:52:04 147,513 -c----w c:\windows\$NtServicePackUninstall$\fp4apws.dll
+ 2003-03-24 23:52:04 49,210 -c----w c:\windows\$NtServicePackUninstall$\fp4areg.dll
+ 2003-03-24 23:52:04 102,509 -c----w c:\windows\$NtServicePackUninstall$\fp4atxt.dll
+ 2003-03-24 23:52:04 618,605 -c----w c:\windows\$NtServicePackUninstall$\fp4autl.dll
+ 2003-03-24 23:52:04 41,020 -c----w c:\windows\$NtServicePackUninstall$\fp4avnb.dll
+ 2003-03-24 23:52:04 32,826 -c----w c:\windows\$NtServicePackUninstall$\fp4avss.dll
+ 2003-03-24 23:52:04 49,212 -c----w c:\windows\$NtServicePackUninstall$\fp4awebs.dll
+ 2004-05-13 07:39:48 876,653 -c----w c:\windows\$NtServicePackUninstall$\fp4awel.dll
+ 2003-03-24 23:52:04 14,608 -c----w c:\windows\$NtServicePackUninstall$\fp98sadm.exe
+ 2003-03-24 23:52:04 109,328 -c----w c:\windows\$NtServicePackUninstall$\fp98swin.exe
+ 2003-03-24 23:52:04 24,632 -c----w c:\windows\$NtServicePackUninstall$\fpadmcgi.exe
+ 2003-03-24 23:52:04 20,541 -c----w c:\windows\$NtServicePackUninstall$\fpadmdll.dll
+ 2003-03-24 23:52:04 188,494 -c----w c:\windows\$NtServicePackUninstall$\fpcount.exe
+ 2003-03-24 23:52:04 94,208 -c----w c:\windows\$NtServicePackUninstall$\fpencode.dll
+ 2003-03-24 23:52:04 20,541 -c----w c:\windows\$NtServicePackUninstall$\fpexedll.dll
+ 2004-05-13 07:39:48 598,071 -c----w c:\windows\$NtServicePackUninstall$\fpmmc.dll
+ 2003-03-24 23:52:06 208,896 -c----w c:\windows\$NtServicePackUninstall$\fpmmcsat.dll
+ 2003-03-24 23:52:04 20,538 -c----w c:\windows\$NtServicePackUninstall$\fpremadm.exe
+ 2004-08-04 11:00:00 9,344 -c----w c:\windows\$NtServicePackUninstall$\framebuf.dll
+ 2004-08-04 11:00:00 185,856 -c----w c:\windows\$NtServicePackUninstall$\framedyn.dll
+ 2004-08-04 11:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\fsquirt.exe
+ 2004-08-04 11:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\ftp.exe
+ 2004-08-04 11:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\fwcfg.dll
+ 2004-08-04 11:00:00 452,096 -c----w c:\windows\$NtServicePackUninstall$\fxsapi.dll
+ 2004-08-04 11:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\fxsclnt.exe
+ 2004-08-04 11:00:00 72,192 -c----w c:\windows\$NtServicePackUninstall$\fxscom.dll
+ 2004-08-04 11:00:00 285,184 -c----w c:\windows\$NtServicePackUninstall$\fxscomex.dll
+ 2004-08-04 11:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\fxscover.exe
+ 2004-08-04 11:00:00 27,136 -c----w c:\windows\$NtServicePackUninstall$\fxsdrv.dll
+ 2004-08-04 11:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\fxsevent.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\fxsext32.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\fxsmon.dll
+ 2004-08-04 11:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\fxsocm.dll
+ 2004-08-04 11:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\fxsperf.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\fxsres.dll
+ 2004-08-04 11:00:00 562,176 -c----w c:\windows\$NtServicePackUninstall$\fxsst.dll
+ 2004-08-04 11:00:00 267,776 -c----w c:\windows\$NtServicePackUninstall$\fxssvc.exe
+ 2004-08-04 11:00:00 246,272 -c----w c:\windows\$NtServicePackUninstall$\fxst30.dll
+ 2004-08-04 11:00:00 397,312 -c----w c:\windows\$NtServicePackUninstall$\fxstiff.dll
+ 2004-08-04 11:00:00 154,112 -c----w c:\windows\$NtServicePackUninstall$\fxsui.dll
+ 2004-08-04 11:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\fxswzrd.dll
+ 2004-08-04 11:00:00 400,384 -c----w c:\windows\$NtServicePackUninstall$\fxsxp32.dll
+ 2008-02-20 06:51:05 282,624 -c----w c:\windows\$NtServicePackUninstall$\gdi32.dll
+ 2004-08-04 11:00:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\glu32.dll
+ 2004-08-04 11:00:00 9,728 -c----w c:\windows\$NtServicePackUninstall$\gpkrsrc.dll
+ 2004-08-04 11:00:00 39,424 -c----w c:\windows\$NtServicePackUninstall$\grpconv.exe
+ 2004-08-04 11:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\guitrn.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\h323cc.dll
+ 2004-08-04 11:00:00 614,912 -c----w c:\windows\$NtServicePackUninstall$\h323msp.dll
+ 2004-08-04 12:59:14 134,400 -c----w c:\windows\$NtServicePackUninstall$\hal.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\hccoin.dll
+ 2005-01-08 07:07:18 138,752 -c----w c:\windows\$NtServicePackUninstall$\hdaudbus.sys
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\help.exe
+ 2004-08-04 11:00:00 768,512 -c----w c:\windows\$NtServicePackUninstall$\helpctr.exe
+ 2004-08-04 11:00:00 743,936 -c----w c:\windows\$NtServicePackUninstall$\helpsvc.exe
+ 2005-05-27 06:22:01 10,752 -c----w c:\windows\$NtServicePackUninstall$\hh.exe
+ 2005-05-27 09:04:27 41,472 -c----w c:\windows\$NtServicePackUninstall$\hhsetup.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\hid.dll
+ 2004-08-04 11:00:00 36,224 -c----w c:\windows\$NtServicePackUninstall$\hidclass.sys
+ 2004-08-04 11:00:00 24,960 -c----w c:\windows\$NtServicePackUninstall$\hidparse.sys
+ 2006-07-21 08:24:43 72,704 -c----w c:\windows\$NtServicePackUninstall$\hlink.dll
+ 2004-08-04 11:00:00 344,064 -c----w c:\windows\$NtServicePackUninstall$\hnetcfg.dll
+ 2004-08-04 11:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\hnetwiz.dll
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\hostmib.dll
+ 2004-08-04 11:00:00 144,896 -c----w c:\windows\$NtServicePackUninstall$\hotplug.dll
+ 2004-08-04 04:56:44 87,552 -c----w c:\windows\$NtServicePackUninstall$\hpfud50.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\hscupd.exe
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys
+ 2006-03-17 00:33:10 262,784 -c----w c:\windows\$NtServicePackUninstall$\http.sys.000
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\httpapi.dll
+ 2004-08-04 11:00:00 41,984 -c----w c:\windows\$NtServicePackUninstall$\htui.dll
+ 2004-11-18 00:41:24 347,136 -c----w c:\windows\$NtServicePackUninstall$\hypertrm.dll
+ 2004-08-04 03:14:38 52,736 -c----w c:\windows\$NtServicePackUninstall$\i8042prt.sys
+ 2004-08-04 11:00:00 119,808 -c----w c:\windows\$NtServicePackUninstall$\iasrad.dll
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\icaapi.dll
+ 2004-08-04 11:00:00 80,384 -c----w c:\windows\$NtServicePackUninstall$\iccvid.dll
+ 2005-06-29 08:46:00 254,976 -c----w c:\windows\$NtServicePackUninstall$\icm32.dll
+ 2004-08-04 11:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\icmp.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\iconlib.dll
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\icwconn.dll
+ 2004-08-04 11:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\icwconn1.exe
+ 2004-08-04 11:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\icwconn2.exe
+ 2004-08-04 11:00:00 73,728 -c----w c:\windows\$NtServicePackUninstall$\icwdial.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\icwdl.dll
+ 2004-08-04 11:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\icwhelp.dll
+ 2004-08-04 11:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\icwphbk.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\icwrmind.exe
+ 2004-08-04 11:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\icwutil.dll
+ 2004-08-04 11:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\idq.dll
+ 2007-08-13 22:45:18 78,336 -c----w c:\windows\$NtServicePackUninstall$\ieencode.dll
+ 2004-08-04 11:00:00 114,688 -c----w c:\windows\$NtServicePackUninstall$\iexpress.exe
+ 2004-08-04 11:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\ifmon.dll
+ 2004-08-04 11:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\igmpagnt.dll
+ 2004-08-04 11:00:00 505,344 -c----w c:\windows\$NtServicePackUninstall$\iis.dll
+ 2004-08-04 11:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\ils.dll
+ 2004-08-04 11:00:00 144,384 -c----w c:\windows\$NtServicePackUninstall$\imagehlp.dll
+ 2004-08-04 11:00:00 150,016 -c----w c:\windows\$NtServicePackUninstall$\imapi.exe
+ 2004-08-04 11:00:00 41,856 -c----w c:\windows\$NtServicePackUninstall$\imapi.sys
+ 2004-08-04 11:00:00 36,921 -c----w c:\windows\$NtServicePackUninstall$\imeshare.dll
+ 2004-08-04 11:00:00 110,080 -c----w c:\windows\$NtServicePackUninstall$\imm32.dll
+ 2004-08-04 11:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\imsinsnt.dll
+ 2004-08-04 11:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\inetcfg.dll
+ 2008-04-11 18:50:43 683,520 -c----w c:\windows\$NtServicePackUninstall$\inetcomm.dll
+ 2004-08-04 11:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\inetmib1.dll
+ 2004-08-04 11:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\inetpp.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\inetppui.dll
+ 2004-08-04 11:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\inetres.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\inetwiz.exe
+ 2004-08-04 11:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\initpki.dll
+ 2004-08-04 11:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\input.dll
+ 2004-08-04 12:59:42 5,504 -c----w c:\windows\$NtServicePackUninstall$\intelide.sys
+ 2004-08-04 12:59:20 36,096 -c----w c:\windows\$NtServicePackUninstall$\intelppm.sys
+ 2004-08-04 11:00:00 29,056 -c----w c:\windows\$NtServicePackUninstall$\ip6fw.sys
+ 2004-08-04 11:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\ipconfig.exe
+ 2006-05-19 12:59:41 94,720 -c----w c:\windows\$NtServicePackUninstall$\iphlpapi.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipinip.sys
+ 2004-08-04 11:00:00 154,112 -c----w c:\windows\$NtServicePackUninstall$\ipmontr.dll
+ 2004-09-29 22:28:37 134,912 -c----w c:\windows\$NtServicePackUninstall$\ipnat.sys
+ 2004-08-04 11:00:00 331,264 -c----w c:\windows\$NtServicePackUninstall$\ipnathlp.dll
+ 2004-08-04 11:00:00 330,752 -c----w c:\windows\$NtServicePackUninstall$\ippromon.dll
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\iprip.dll
+ 2004-08-04 11:00:00 169,984 -c----w c:\windows\$NtServicePackUninstall$\iprtrmgr.dll
+ 2004-08-04 11:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\ipsec.sys
+ 2004-08-04 11:00:00 349,696 -c----w c:\windows\$NtServicePackUninstall$\ipsecsnp.dll
+ 2004-08-04 11:00:00 182,784 -c----w c:\windows\$NtServicePackUninstall$\ipsecsvc.dll
+ 2004-08-04 11:00:00 384,000 -c----w c:\windows\$NtServicePackUninstall$\ipsmsnap.dll
+ 2004-08-04 11:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\ipv6.exe
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\ipv6mon.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\ipxroute.exe
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ipxwan.dll
+ 2004-08-04 11:00:00 120,320 -c----w c:\windows\$NtServicePackUninstall$\ir41_qc.dll
+ 2004-08-04 11:00:00 338,432 -c----w c:\windows\$NtServicePackUninstall$\ir41_qcx.dll
+ 2004-08-04 11:00:00 755,200 -c----w c:\windows\$NtServicePackUninstall$\ir50_32.dll
+ 2004-08-04 11:00:00 200,192 -c----w c:\windows\$NtServicePackUninstall$\ir50_qc.dll
+ 2004-08-04 11:00:00 183,808 -c----w c:\windows\$NtServicePackUninstall$\ir50_qcx.dll
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\irenum.sys
+ 2004-08-04 11:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\isapnp.sys
+ 2004-08-04 11:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\isign32.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\isrdbg32.dll
+ 2005-05-27 09:04:27 155,136 -c----w c:\windows\$NtServicePackUninstall$\itircl.dll
+ 2005-05-27 09:04:27 137,216 -c----w c:\windows\$NtServicePackUninstall$\itss.dll
+ 2004-08-04 11:00:00 192,000 -c----w c:\windows\$NtServicePackUninstall$\iuengine.dll
+ 2004-08-04 11:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\ixsso.dll
+ 2004-08-04 11:00:00 47,616 -c----w c:\windows\$NtServicePackUninstall$\iyuv_32.dll
+ 2006-06-01 18:47:07 163,840 -c----w c:\windows\$NtServicePackUninstall$\jgdw400.dll
+ 2006-06-01 18:47:07 27,648 -c----w c:\windows\$NtServicePackUninstall$\jgpl400.dll
+ 2007-08-13 22:38:04 491,520 -c----w c:\windows\$NtServicePackUninstall$\jscript.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbd101.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbd106n.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdax2.dll
+ 2004-08-04 02:58:34 24,576 -c----w c:\windows\$NtServicePackUninstall$\kbdclass.sys
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdfi1.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdibm02.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdinbe1.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinben.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdinmal.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\kbdlk41a.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdlk41j.dll
+ 2004-08-04 11:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\kbdmaori.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt47.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\kbdmlt48.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdnec.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdno1.dll
+ 2004-08-04 11:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsfi.dll
+ 2004-08-04 11:00:00 7,680 -c----w c:\windows\$NtServicePackUninstall$\kbdsmsno.dll
+ 2004-08-04 11:00:00 7,168 -c----w c:\windows\$NtServicePackUninstall$\kbdukx.dll
+ 2004-08-04 11:00:00 7,424 -c----w c:\windows\$NtServicePackUninstall$\kd1394.dll
+ 2005-06-15 17:49:30 295,936 -c----w c:\windows\$NtServicePackUninstall$\kerberos.dll
+ 2007-04-16 15:52:53 984,576 -c----w c:\windows\$NtServicePackUninstall$\kernel32.dll
+ 2004-08-04 11:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\keymgr.dll
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys
+ 2006-06-14 08:47:45 172,416 -c----w c:\windows\$NtServicePackUninstall$\kmixer.sys.000
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\krnlprov.dll
+ 2004-08-04 13:15:22 140,928 -c----w c:\windows\$NtServicePackUninstall$\ks.sys
+ 2004-08-04 11:00:00 92,032 -c----w c:\windows\$NtServicePackUninstall$\ksecdd.sys
+ 2004-08-04 14:56:44 4,096 -c----w c:\windows\$NtServicePackUninstall$\ksuser.dll
+ 2004-08-04 11:00:00 423,936 -c----w c:\windows\$NtServicePackUninstall$\licdll.dll
+ 2004-08-04 11:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\licwmi.dll
+ 2005-09-01 01:41:53 19,968 -c----w c:\windows\$NtServicePackUninstall$\linkinfo.dll
+ 2004-08-04 11:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\lmhsvc.dll
+ 2004-08-04 11:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\lmmib2.dll
+ 2004-08-04 11:00:00 399,872 -c----w c:\windows\$NtServicePackUninstall$\lmrt.dll
+ 2004-08-04 11:00:00 97,280 -c----w c:\windows\$NtServicePackUninstall$\loadperf.dll
+ 2004-08-04 11:00:00 221,696 -c----w c:\windows\$NtServicePackUninstall$\localsec.dll
+ 2004-08-04 11:00:00 341,504 -c----w c:\windows\$NtServicePackUninstall$\localspl.dll
+ 2004-08-04 11:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\localui.dll
+ 2004-08-04 11:00:00 75,264 -c----w c:\windows\$NtServicePackUninstall$\locator.exe
+ 2004-08-04 11:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\log.dll
+ 2004-08-04 11:00:00 59,392 -c----w c:\windows\$NtServicePackUninstall$\logman.exe
+ 2004-08-04 11:00:00 220,672 -c----w c:\windows\$NtServicePackUninstall$\logon.scr
+ 2004-08-04 11:00:00 514,560 -c----w c:\windows\$NtServicePackUninstall$\logonui.exe
+ 2004-08-04 11:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\lpdsvc.dll
+ 2004-08-04 11:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\lpk.dll
+ 2004-08-04 11:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\lprhelp.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\lprmon.dll
+ 2007-11-07 09:26:56 721,920 -c----w c:\windows\$NtServicePackUninstall$\lsasrv.dll
+ 2004-08-04 11:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\lsass.exe
+ 2004-08-04 11:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\magnify.exe
+ 2004-08-04 11:00:00 85,504 -c----w c:\windows\$NtServicePackUninstall$\makecab.exe
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mcastmib.dll
+ 2004-08-04 11:00:00 84,480 -c----w c:\windows\$NtServicePackUninstall$\mciavi32.dll
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\mciqtz32.dll
+ 2004-08-04 11:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\mciseq.dll
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\mciwave.dll
+ 2004-08-04 11:00:00 118,272 -c----w c:\windows\$NtServicePackUninstall$\mdminst.dll
+ 2004-08-04 11:00:00 63,744 -c----w c:\windows\$NtServicePackUninstall$\mf.sys
+ 2007-03-08 15:36:28 40,960 -c----w c:\windows\$NtServicePackUninstall$\mf3216.dll
+ 2006-11-01 19:17:45 927,504 -c----w c:\windows\$NtServicePackUninstall$\mfc40u.dll
+ 2004-08-04 11:00:00 1,028,096 -c----w c:\windows\$NtServicePackUninstall$\mfc42.dll
+ 2004-08-04 11:00:00 22,528 -c----w c:\windows\$NtServicePackUninstall$\mfcsubs.dll
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\mgmtapi.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\midimap.dll
+ 2004-08-04 11:00:00 201,216 -c----w c:\windows\$NtServicePackUninstall$\migism.dll
+ 2004-08-04 11:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\miglibnt.dll
+ 2004-08-04 11:00:00 103,424 -c----w c:\windows\$NtServicePackUninstall$\migload.exe
+ 2005-07-26 06:46:57 7,680 -c----w c:\windows\$NtServicePackUninstall$\migregdb.exe
+ 2004-08-04 11:00:00 240,128 -c----w c:\windows\$NtServicePackUninstall$\migwiz.exe
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\mimefilt.dll
+ 2004-08-04 11:00:00 586,240 -c----w c:\windows\$NtServicePackUninstall$\mlang.dll
+ 2004-08-04 11:00:00 815,104 -c----w c:\windows\$NtServicePackUninstall$\mmc.exe
+ 2004-08-04 11:00:00 70,656 -c----w c:\windows\$NtServicePackUninstall$\mmcbase.dll
+ 2004-08-04 11:00:00 1,192,960 -c----w c:\windows\$NtServicePackUninstall$\mmcndmgr.dll
+ 2004-08-04 11:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\mmcshext.dll
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\mmfutil.dll
+ 2004-08-04 11:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\mnmdd.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\mnmsrvc.exe
+ 2004-08-04 11:00:00 207,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.dll
+ 2004-08-04 11:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\mobsync.exe
+ 2004-08-04 11:00:00 30,080 -c----w c:\windows\$NtServicePackUninstall$\modem.sys
+ 2004-08-04 11:00:00 153,600 -c----w c:\windows\$NtServicePackUninstall$\modemui.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\mofcomp.exe
+ 2004-08-04 11:00:00 123,904 -c----w c:\windows\$NtServicePackUninstall$\mofd.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\more.com
+ 2004-08-04 11:00:00 216,064 -c----w c:\windows\$NtServicePackUninstall$\moricons.dll
+ 2004-08-04 11:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\mouclass.sys
+ 2004-08-04 11:00:00 42,240 -c----w c:\windows\$NtServicePackUninstall$\mountmgr.sys
+ 2004-08-04 11:00:00 3,555,328 -c----w c:\windows\$NtServicePackUninstall$\moviemk.exe
+ 2004-08-04 11:00:00 240,640 -c----w c:\windows\$NtServicePackUninstall$\mpg4dmod.dll
+ 2004-08-04 11:00:00 123,392 -c----w c:\windows\$NtServicePackUninstall$\mplay32.exe
+ 2004-08-04 11:00:00 4,639 -c----w c:\windows\$NtServicePackUninstall$\mplayer2.exe
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\mpr.dll
+ 2004-08-04 11:00:00 87,040 -c----w c:\windows\$NtServicePackUninstall$\mprapi.dll
+ 2004-08-04 11:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\mprdim.dll
+ 2007-12-18 09:51:35 179,584 -c----w c:\windows\$NtServicePackUninstall$\mrxdav.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 -c----w c:\windows\$NtServicePackUninstall$\mrxsmb.sys.000
+ 2004-08-04 11:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\msacm32.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msadcer.dll
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msadcf.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcfr.dll
+ 2006-03-23 05:44:21 143,360 -c----w c:\windows\$NtServicePackUninstall$\msadco.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msadcor.dll
+ 2004-08-04 11:00:00 53,248 -c----w c:\windows\$NtServicePackUninstall$\msadcs.dll
+ 2004-08-04 11:00:00 155,648 -c----w c:\windows\$NtServicePackUninstall$\msadds.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msaddsr.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msader15.dll
+ 2006-12-26 13:07:23 536,576 -c----w c:\windows\$NtServicePackUninstall$\msado15.dll
+ 2006-12-26 13:07:23 180,224 -c----w c:\windows\$NtServicePackUninstall$\msadomd.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msador15.dll
+ 2006-12-26 13:07:23 200,704 -c----w c:\windows\$NtServicePackUninstall$\msadox.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msadrh15.dll
+ 2004-08-04 11:00:00 3,584 -c----w c:\windows\$NtServicePackUninstall$\msafd.dll
+ 2004-08-04 11:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\msapsspc.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\msasn1.dll
+ 2004-08-04 11:00:00 220,160 -c----w c:\windows\$NtServicePackUninstall$\mscandui.dll
+ 2008-06-24 16:23:05 74,240 -c----w c:\windows\$NtServicePackUninstall$\mscms.dll
+ 2004-08-04 11:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\msconf.dll
+ 2005-09-27 07:34:26 169,984 -c----w c:\windows\$NtServicePackUninstall$\msconfig.exe
+ 2004-08-04 11:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mscpx32r.dll
+ 2004-08-04 11:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\mscpxl32.dll
+ 2008-02-26 11:59:50 294,912 -c----w c:\windows\$NtServicePackUninstall$\msctf.dll
+ 2004-08-04 11:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\msctfp.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdadc.dll
+ 2004-08-04 11:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdadiag.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaenum.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaer.dll
+ 2004-08-04 11:00:00 233,472 -c----w c:\windows\$NtServicePackUninstall$\msdaora.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaorar.dll
+ 2004-08-04 11:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\msdaosp.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaprsr.dll
+ 2004-08-04 11:00:00 200,704 -c----w c:\windows\$NtServicePackUninstall$\msdaprst.dll
+ 2004-08-04 11:00:00 204,800 -c----w c:\windows\$NtServicePackUninstall$\msdaps.dll
+ 2004-08-04 11:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\msdarem.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdaremr.dll
+ 2004-08-04 11:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\msdart.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdasc.dll
+ 2004-08-04 11:00:00 315,392 -c----w c:\windows\$NtServicePackUninstall$\msdasql.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msdasqlr.dll
+ 2004-08-04 11:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\msdatl3.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msdatt.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\msdaurl.dll
+ 2004-08-04 11:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\msdfmap.dll
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\msdmo.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\msdtc.exe
+ 2004-08-04 11:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\msdtclog.dll
+ 2006-03-01 19:42:42 426,496 -c----w c:\windows\$NtServicePackUninstall$\msdtcprx.dll
+ 2004-08-04 11:00:00 82,432 -c----w c:\windows\$NtServicePackUninstall$\msdtcstp.dll
+ 2006-03-01 19:42:42 956,416 -c----w c:\windows\$NtServicePackUninstall$\msdtctm.dll
+ 2006-03-01 19:42:42 161,280 -c----w c:\windows\$NtServicePackUninstall$\msdtcuiu.dll
+ 2004-08-04 11:00:00 4,126 -c----w c:\windows\$NtServicePackUninstall$\msdxmlc.dll
+ 2004-08-04 11:00:00 19,072 -c----w c:\windows\$NtServicePackUninstall$\msfs.sys
+ 2006-11-27 14:54:06 539,136 -c----w c:\windows\$NtServicePackUninstall$\msftedit.dll
+ 2004-08-04 11:00:00 994,304 -c----w c:\windows\$NtServicePackUninstall$\msgina.dll
+ 2004-08-04 11:00:00 35,072 -c----w c:\windows\$NtServicePackUninstall$\msgpc.sys
+ 2004-08-04 11:00:00 3,166,208 -c----w c:\windows\$NtServicePackUninstall$\msgr3en.dll
+ 2004-08-04 11:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\msgrocm.dll
+ 2004-08-04 08:06:34 180,224 -c----w c:\windows\$NtServicePackUninstall$\msgslang.dll
+ 2004-08-04 11:00:00 33,792 -c----w c:\windows\$NtServicePackUninstall$\msgsvc.dll
+ 2004-08-04 11:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\msh261.drv
+ 2004-08-04 11:00:00 294,912 -c----w c:\windows\$NtServicePackUninstall$\msh263.drv
+ 2007-04-18 16:12:23 2,854,400 -c----w c:\windows\$NtServicePackUninstall$\msi.dll
+ 2004-08-04 11:00:00 51,712 -c----w c:\windows\$NtServicePackUninstall$\msident.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\msidle.dll
+ 2004-08-04 11:00:00 248,832 -c----w c:\windows\$NtServicePackUninstall$\msieftp.dll
+ 2005-05-04 02:58:36 78,848 -c----w c:\windows\$NtServicePackUninstall$\msiexec.exe
+ 2005-05-04 02:58:36 271,360 -c----w c:\windows\$NtServicePackUninstall$\msihnd.dll
+ 2004-08-04 11:00:00 4,608 -c----w c:\windows\$NtServicePackUninstall$\msimg32.dll
+ 2004-08-04 11:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\msimn.exe
+ 2005-05-04 02:58:36 884,736 -c----w c:\windows\$NtServicePackUninstall$\msimsg.dll
+ 2004-08-04 11:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\msimtf.dll
+ 2004-08-04 11:00:00 376,320 -c----w c:\windows\$NtServicePackUninstall$\msinfo.dll
+ 2004-08-04 11:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\msiregmv.exe
+ 2005-05-04 02:58:36 15,360 -c----w c:\windows\$NtServicePackUninstall$\msisip.dll
+ 2008-03-27 08:12:54 151,583 -c----w c:\windows\$NtServicePackUninstall$\msjint40.dll
+ 2006-12-26 13:07:23 102,400 -c----w c:\windows\$NtServicePackUninstall$\msjro.dll
+ 2004-08-04 12:58:42 7,552 -c----w c:\windows\$NtServicePackUninstall$\mskssrv.sys
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mslbui.dll
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\mslwvtts.dll
+ 2004-10-13 23:24:37 1,694,208 -c----w c:\windows\$NtServicePackUninstall$\msmsgs.exe
+ 2004-08-04 11:00:00 290,816 -c----w c:\windows\$NtServicePackUninstall$\msnsspc.dll
+ 2004-08-04 11:00:00 122,368 -c----w c:\windows\$NtServicePackUninstall$\msobcomm.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\msobdl.dll
+ 2004-11-25 07:31:13 563,200 -c----w c:\windows\$NtServicePackUninstall$\msobmain.dll
+ 2004-08-04 11:00:00 30,720 -c----w c:\windows\$NtServicePackUninstall$\msobshel.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\msobweb.dll
+ 2007-05-16 15:12:08 1,314,816 -c----w c:\windows\$NtServicePackUninstall$\msoe.dll
+ 2004-08-04 11:00:00 252,928 -c----w c:\windows\$NtServicePackUninstall$\msoeacct.dll
+ 2004-08-04 11:00:00 2,479,616 -c----w c:\windows\$NtServicePackUninstall$\msoeres.dll
+ 2004-08-04 11:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\msoert2.dll
+ 2004-08-04 11:00:00 28,160 -c----w c:\windows\$NtServicePackUninstall$\msoobe.exe
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\msorc32r.dll
+ 2004-08-04 11:00:00 143,360 -c----w c:\windows\$NtServicePackUninstall$\msorcl32.dll
+ 2004-08-04 11:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\mspaint.exe
+ 2004-08-04 11:00:00 30,208 -c----w c:\windows\$NtServicePackUninstall$\mspatcha.dll
+ 2004-08-04 12:58:40 5,376 -c----w c:\windows\$NtServicePackUninstall$\mspclock.sys
+ 2004-08-04 12:58:42 4,992 -c----w c:\windows\$NtServicePackUninstall$\mspqm.sys
+ 2004-08-04 11:00:00 48,128 -c----w c:\windows\$NtServicePackUninstall$\msprivs.dll
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\msrle32.dll
+ 2004-08-04 11:00:00 134,656 -c----w c:\windows\$NtServicePackUninstall$\mssap.dll
+ 2004-08-04 11:00:00 15,488 -c----w c:\windows\$NtServicePackUninstall$\mssmbios.sys
+ 2004-08-04 11:00:00 274,432 -c----w c:\windows\$NtServicePackUninstall$\mst120.dll
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\mst123.dll
+ 2004-08-04 11:00:00 274,944 -c----w c:\windows\$NtServicePackUninstall$\mstask.dll
+ 2004-08-04 11:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\mstinit.exe
+ 2004-08-04 11:00:00 115,712 -c----w c:\windows\$NtServicePackUninstall$\mstlsapi.dll
+ 2004-08-04 11:00:00 407,552 -c----w c:\windows\$NtServicePackUninstall$\mstsc.exe
+ 2004-08-04 11:00:00 655,360 -c----w c:\windows\$NtServicePackUninstall$\mstscax.dll
+ 2004-08-04 11:00:00 195,072 -c----w c:\windows\$NtServicePackUninstall$\msutb.dll
+ 2004-08-04 11:00:00 129,536 -c----w c:\windows\$NtServicePackUninstall$\msv1_0.dll
+ 2004-08-04 11:00:00 1,392,671 -c----w c:\windows\$NtServicePackUninstall$\msvbvm60.dll
+ 2004-08-04 11:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\msvcirt.dll
+ 2004-08-04 11:00:00 413,696 -c----w c:\windows\$NtServicePackUninstall$\msvcp60.dll
+ 2004-08-04 11:00:00 343,040 -c----w c:\windows\$NtServicePackUninstall$\msvcrt.dll
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\msvcrt40.dll
+ 2004-08-04 11:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\msvfw32.dll
+ 2004-08-04 11:00:00 1,428,480 -c----w c:\windows\$NtServicePackUninstall$\msvidctl.dll
+ 2004-08-04 11:00:00 72,704 -c----w c:\windows\$NtServicePackUninstall$\msw3prt.dll
+ 2004-08-04 11:00:00 204,288 -c----w c:\windows\$NtServicePackUninstall$\mswebdvd.dll
+ 2008-06-20 17:41:10 245,248 -c----w c:\windows\$NtServicePackUninstall$\mswsock.dll
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\msxactps.dll
+ 2004-08-04 11:00:00 506,368 -c----w c:\windows\$NtServicePackUninstall$\msxml.dll
+ 2004-08-04 11:00:00 701,440 -c----w c:\windows\$NtServicePackUninstall$\msxml2.dll
+ 2007-06-26 06:08:16 1,104,896 -c----w c:\windows\$NtServicePackUninstall$\msxml3.dll
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\msyuv.dll
+ 2006-03-01 19:42:42 66,560 -c----w c:\windows\$NtServicePackUninstall$\mtxclu.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\mtxdm.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\mtxex.dll
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\mtxlegih.dll
+ 2006-03-01 19:42:42 91,136 -c----w c:\windows\$NtServicePackUninstall$\mtxoci.dll
+ 2004-08-04 11:00:00 107,904 -c----w c:\windows\$NtServicePackUninstall$\mup.sys
+ 2004-08-04 11:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\mydocs.dll
+ 2004-08-04 11:00:00 221,184 -c----w c:\windows\$NtServicePackUninstall$\nac.dll
+ 2004-08-04 11:00:00 53,760 -c----w c:\windows\$NtServicePackUninstall$\narrator.exe
+ 2004-08-04 11:00:00 36,352 -c----w c:\windows\$NtServicePackUninstall$\ncobjapi.dll
+ 2004-08-04 11:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ncprov.dll
+ 2004-08-04 11:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\nddeapi.dll
+ 2004-08-04 11:00:00 4,096 -c----w c:\windows\$NtServicePackUninstall$\nddeapir.exe
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\nddenb32.dll
+ 2004-08-04 11:00:00 182,912 -c----w c:\windows\$NtServicePackUninstall$\ndis.sys
+ 2004-08-04 11:00:00 57,344 -c----w c:\windows\$NtServicePackUninstall$\ndisnpp.dll
+ 2004-08-04 11:00:00 9,600 -c----w c:\windows\$NtServicePackUninstall$\ndistapi.sys
+ 2005-04-20 06:54:04 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys
+ 2005-04-20 06:54:04 14,592 -c----w c:\windows\$NtServicePackUninstall$\ndisuio.sys.000
+ 2004-08-04 11:00:00 91,776 -c----w c:\windows\$NtServicePackUninstall$\ndiswan.sys
+ 2004-08-04 11:00:00 38,016 -c----w c:\windows\$NtServicePackUninstall$\ndproxy.sys
+ 2004-08-04 11:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\net.exe
+ 2004-08-04 11:00:00 124,928 -c----w c:\windows\$NtServicePackUninstall$\net1.exe
+ 2006-08-17 12:28:27 332,288 -c----w c:\windows\$NtServicePackUninstall$\netapi32.dll
+ 2004-08-04 11:00:00 34,560 -c----w c:\windows\$NtServicePackUninstall$\netbios.sys
+ 2004-08-04 11:00:00 162,816 -c----w c:\windows\$NtServicePackUninstall$\netbt.sys
+ 2004-08-04 11:00:00 622,080 -c----w c:\windows\$NtServicePackUninstall$\netcfgx.dll
+ 2004-08-04 11:00:00 111,104 -c----w c:\windows\$NtServicePackUninstall$\netdde.exe
+ 2004-08-04 11:00:00 139,264 -c----w c:\windows\$NtServicePackUninstall$\netid.dll
+ 2004-08-04 11:00:00 407,040 -c----w c:\windows\$NtServicePackUninstall$\netlogon.dll
+ 2005-08-22 18:29:46 197,632 -c----w c:\windows\$NtServicePackUninstall$\netman.dll
+ 2004-08-04 11:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\netoc.dll
+ 2004-08-04 11:00:00 875,008 -c----w c:\windows\$NtServicePackUninstall$\netplwiz.dll
+ 2004-08-04 11:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\netrap.dll
+ 2004-08-04 11:00:00 329,728 -c----w c:\windows\$NtServicePackUninstall$\netsetup.exe
+ 2004-08-04 11:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\netsh.exe
+ 2005-04-21 02:21:33 1,705,472 -c----w c:\windows\$NtServicePackUninstall$\netshell.dll
+ 2004-08-04 11:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\netstat.exe
+ 2004-08-04 11:00:00 80,896 -c----w c:\windows\$NtServicePackUninstall$\netui0.dll
+ 2004-08-04 11:00:00 245,760 -c----w c:\windows\$NtServicePackUninstall$\netui1.dll
+ 2004-08-13 00:50:01 247,808 -c----w c:\windows\$NtServicePackUninstall$\newdev.dll
+ 2004-08-04 11:00:00 61,824 -c----w c:\windows\$NtServicePackUninstall$\nic1394.sys
+ 2004-08-04 11:00:00 103,936 -c----w c:\windows\$NtServicePackUninstall$\nlhtml.dll
+ 2004-08-04 11:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\nmas.dll
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmasnt.dll
+ 2004-08-04 11:00:00 81,920 -c----w c:\windows\$NtServicePackUninstall$\nmchat.dll
+ 2004-08-04 11:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\nmcom.dll
+ 2004-08-04 11:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\nmft.dll
+ 2004-08-04 11:00:00 28,672 -c----w c:\windows\$NtServicePackUninstall$\nmmkcert.dll
+ 2004-08-04 11:00:00 40,320 -c----w c:\windows\$NtServicePackUninstall$\nmnt.sys
+ 2004-08-04 11:00:00 172,032 -c----w c:\windows\$NtServicePackUninstall$\nmoldwb.dll
+ 2004-08-04 11:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\nmwb.dll
+ 2004-08-04 11:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\notepad.exe
+ 2004-08-04 11:00:00 226,816 -c----w c:\windows\$NtServicePackUninstall$\npdrmv2.dll
+ 2005-11-29 20:27:06 364,544 -c----w c:\windows\$NtServicePackUninstall$\npdsplay.dll
+ 2004-08-04 11:00:00 30,848 -c----w c:\windows\$NtServicePackUninstall$\npfs.sys
+ 2004-08-04 11:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\nppagent.exe
+ 2004-08-04 11:00:00 54,784 -c----w c:\windows\$NtServicePackUninstall$\npptools.dll
+ 2004-08-04 11:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\npwmsdrm.dll
+ 2004-08-04 11:00:00 76,800 -c----w c:\windows\$NtServicePackUninstall$\nslookup.exe
+ 2004-08-04 11:00:00 708,096 -c----w c:\windows\$NtServicePackUninstall$\ntdll.dll
+ 2004-08-04 11:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\ntdsapi.dll
+ 2004-08-04 11:00:00 212,992 -c----w c:\windows\$NtServicePackUninstall$\ntevt.dll
+ 2007-02-09 11:10:35 574,464 -c----w c:\windows\$NtServicePackUninstall$\ntfs.sys
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlmp.exe.000
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe
+ 2007-02-28 08:38:57 2,015,744 -c----w c:\windows\$NtServicePackUninstall$\ntkrpamp.exe.000
+ 2004-08-04 11:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\ntlanman.dll
+ 2004-08-04 11:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\ntlsapi.dll
+ 2004-08-04 11:00:00 118,784 -c----w c:\windows\$NtServicePackUninstall$\ntmarta.dll
+ 2004-08-04 11:00:00 40,960 -c----w c:\windows\$NtServicePackUninstall$\ntmsapi.dll
+ 2004-08-04 11:00:00 179,712 -c----w c:\windows\$NtServicePackUninstall$\ntmsdba.dll
+ 2004-08-04 11:00:00 488,448 -c----w c:\windows\$NtServicePackUninstall$\ntmsmgr.dll
+ 2004-08-04 11:00:00 435,200 -c----w c:\windows\$NtServicePackUninstall$\ntmssvc.dll
+ 2004-08-04 11:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\ntoc.dll
+ 2007-02-28 09:08:48 2,136,064 -c----w c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
+ 2004-08-04 11:00:00 91,136 -c----w c:\windows\$NtServicePackUninstall$\ntprint.dll
+ 2004-08-04 11:00:00 143,872 -c----w c:\windows\$NtServicePackUninstall$\ntshrui.dll
+ 2004-08-04 11:00:00 419,840 -c----w c:\windows\$NtServicePackUninstall$\ntvdm.exe
+ 2004-08-04 11:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\ntvdmd.dll
+ 2004-08-04 11:00:00 88,448 -c----w c:\windows\$NtServicePackUninstall$\nwlnkipx.sys
+ 2006-10-13 12:35:12 142,336 -c----w c:\windows\$NtServicePackUninstall$\nwprovau.dll
+ 2004-08-04 11:00:00 266,752 -c----w c:\windows\$NtServicePackUninstall$\oakley.dll
+ 2004-08-04 11:00:00 229,376 -c----w c:\windows\$NtServicePackUninstall$\obelog.dll
+ 2004-08-04 11:00:00 966,656 -c----w c:\windows\$NtServicePackUninstall$\obemetal.dll
+ 2004-08-04 11:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\obemtllc.dll
+ 2004-08-04 11:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\obepopc.dll
+ 2004-08-04 11:00:00 285,696 -c----w c:\windows\$NtServicePackUninstall$\objsel.dll
+ 2004-08-04 11:00:00 405,504 -c----w c:\windows\$NtServicePackUninstall$\obrb041b.dll
+ 2004-08-04 11:00:00 408,576 -c----w c:\windows\$NtServicePackUninstall$\obrb0424.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\ocgen.dll
+ 2004-08-04 11:00:00 60,928 -c----w c:\windows\$NtServicePackUninstall$\ocmanage.dll
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\ocmsn.dll
+ 2004-08-04 11:00:00 249,856 -c----w c:\windows\$NtServicePackUninstall$\odbc32.dll
+ 2004-08-04 11:00:00 16,384 -c----w c:\windows\$NtServicePackUninstall$\odbc32gt.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\odbcad32.exe
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\odbcbcp.dll
+ 2004-08-04 11:00:00 135,168 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.dll
+ 2004-08-04 11:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\odbcconf.exe
+ 2004-08-04 11:00:00 106,496 -c----w c:\windows\$NtServicePackUninstall$\odbccp32.dll
+ 2004-08-04 11:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccr32.dll
+ 2004-08-04 11:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\odbccu32.dll
+ 2004-08-04 11:00:00 94,208 -c----w c:\windows\$NtServicePackUninstall$\odbcint.dll
+ 2004-08-04 11:00:00 53,279 -c----w c:\windows\$NtServicePackUninstall$\odbcji32.dll
+ 2004-08-04 11:00:00 278,559 -c----w c:\windows\$NtServicePackUninstall$\odbcjt32.dll
+ 2004-08-04 11:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\odbcp32r.dll
+ 2004-08-04 11:00:00 147,456 -c----w c:\windows\$NtServicePackUninstall$\odbctrac.dll
+ 2004-08-04 11:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\oddbse32.dll
+ 2004-08-04 11:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odexl32.dll
+ 2004-08-04 11:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odfox32.dll
+ 2004-08-04 11:00:00 20,510 -c----w c:\windows\$NtServicePackUninstall$\odpdx32.dll
+ 2004-08-04 11:00:00 20,511 -c----w c:\windows\$NtServicePackUninstall$\odtext32.dll
+ 2004-08-04 11:00:00 104,448 -c----w c:\windows\$NtServicePackUninstall$\oeimport.dll
+ 2004-08-04 11:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\oemig50.exe
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\oemiglib.dll
+ 2004-08-04 11:00:00 120,832 -c----w c:\windows\$NtServicePackUninstall$\offfilt.dll
+ 2004-08-04 13:10:10 61,056 -c----w c:\windows\$NtServicePackUninstall$\ohci1394.sys
+ 2005-07-26 11:39:48 1,285,120 -c----w c:\windows\$NtServicePackUninstall$\ole32.dll
+ 2007-12-04 18:38:13 550,912 -c----w c:\windows\$NtServicePackUninstall$\oleaut32.dll
+ 2005-07-26 11:39:48 74,752 -c----w c:\windows\$NtServicePackUninstall$\olecli32.dll
+ 2005-07-26 11:39:49 37,888 -c----w c:\windows\$NtServicePackUninstall$\olecnv32.dll
+ 2004-08-04 11:00:00 487,424 -c----w c:\windows\$NtServicePackUninstall$\oledb32.dll
+ 2004-08-04 11:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\oledb32r.dll
+ 2006-10-16 16:15:00 122,880 -c----w c:\windows\$NtServicePackUninstall$\oledlg.dll
+ 2004-08-04 11:00:00 107,008 -c----w c:\windows\$NtServicePackUninstall$\oleprn.dll
+ 2004-08-04 11:00:00 83,456 -c----w c:\windows\$NtServicePackUninstall$\olepro32.dll
+ 2004-08-04 11:00:00 51,200 -c----w c:\windows\$NtServicePackUninstall$\oobebaln.exe
+ 2004-08-04 11:00:00 713,728 -c----w c:\windows\$NtServicePackUninstall$\opengl32.dll
+ 2004-08-04 11:00:00 215,552 -c----w c:\windows\$NtServicePackUninstall$\osk.exe
+ 2004-08-04 11:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\osuninst.dll
+ 2004-08-04 11:00:00 116,224 -c----w c:\windows\$NtServicePackUninstall$\p2p.dll
+ 2004-08-04 11:00:00 86,016 -c----w c:\windows\$NtServicePackUninstall$\p2pgasvc.dll
+ 2004-08-04 11:00:00 312,320 -c----w c:\windows\$NtServicePackUninstall$\p2pgraph.dll
+ 2004-08-04 11:00:00 88,064 -c----w c:\windows\$NtServicePackUninstall$\p2pnetsh.dll
+ 2004-08-04 11:00:00 526,848 -c----w c:\windows\$NtServicePackUninstall$\p2psvc.dll
+ 2004-08-04 11:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\p3.sys
+ 2007-09-29 23:07:28 2,678 -c----w c:\windows\$NtServicePackUninstall$\p7vf57bj.dat
+ 2004-08-04 11:00:00 58,368 -c----w c:\windows\$NtServicePackUninstall$\packager.exe
+ 2004-08-04 11:00:00 80,128 -c----w c:\windows\$NtServicePackUninstall$\parport.sys
+ 2004-08-04 11:00:00 18,688 -c----w c:\windows\$NtServicePackUninstall$\partmgr.sys
+ 2004-08-04 11:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\pautoenr.dll
+ 2004-08-04 11:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\pchshell.dll
+ 2004-08-04 11:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\pchsvc.dll
+ 2004-08-04 11:00:00 68,224 -c----w c:\windows\$NtServicePackUninstall$\pci.sys
+ 2004-08-04 12:59:42 25,088 -c----w c:\windows\$NtServicePackUninstall$\pciidex.sys
+ 2004-08-04 11:00:00 119,936 -c----w c:\windows\$NtServicePackUninstall$\pcmcia.sys
+ 2004-08-04 11:00:00 283,648 -c----w c:\windows\$NtServicePackUninstall$\pdh.dll
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\perfctrs.dll
+ 2004-08-04 11:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\perfdisk.dll
+ 2004-08-04 11:00:00 15,872 -c----w c:\windows\$NtServicePackUninstall$\perfmon.exe
+ 2004-08-04 11:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\perfnet.dll
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\perfos.dll
+ 2004-08-04 11:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\perfproc.dll
+ 2004-08-04 11:00:00 176,128 -c----w c:\windows\$NtServicePackUninstall$\photowiz.dll
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\pid.dll
+ 2004-08-04 11:00:00 24,064 -c----w c:\windows\$NtServicePackUninstall$\pidgen.dll
+ 2004-08-04 11:00:00 281,088 -c----w c:\windows\$NtServicePackUninstall$\pinball.exe
+ 2004-08-04 11:00:00 17,920 -c----w c:\windows\$NtServicePackUninstall$\ping.exe
+ 2004-08-04 11:00:00 15,360 -c----w c:\windows\$NtServicePackUninstall$\pjlmon.dll
+ 2007-09-22 03:43:56 2,232 -c----w c:\windows\$NtServicePackUninstall$\pndnnpj3.dat
+ 2004-08-04 11:00:00 48,640 -c----w c:\windows\$NtServicePackUninstall$\pnrpnsp.dll
+ 2004-08-04 11:00:00 105,472 -c----w c:\windows\$NtServicePackUninstall$\polstore.dll
+ 2004-03-17 00:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys
+ 2004-03-17 00:58:20 136,960 -c----w c:\windows\$NtServicePackUninstall$\portcls.sys.000
+ 2004-08-04 11:00:00 49,152 -c----w c:\windows\$NtServicePackUninstall$\powercfg.exe
+ 2004-08-04 11:00:00 17,408 -c----w c:\windows\$NtServicePackUninstall$\powrprof.dll
+ 2004-08-04 11:00:00 560,640 -c----w c:\windows\$NtServicePackUninstall$\printui.dll
+ 2004-08-04 11:00:00 35,328 -c----w c:\windows\$NtServicePackUninstall$\processr.sys
+ 2004-08-04 11:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\profmap.dll
+ 2004-08-04 11:00:00 109,568 -c----w c:\windows\$NtServicePackUninstall$\progman.exe
+ 2004-08-04 11:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\proquota.exe
+ 2004-08-04 11:00:00 237,056 -c----w c:\windows\$NtServicePackUninstall$\provthrd.dll
+ 2004-08-04 11:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\proxycfg.exe
+ 2004-08-04 11:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\psapi.dll
+ 2004-08-04 11:00:00 96,768 -c----w c:\windows\$NtServicePackUninstall$\psbase.dll
+ 2004-08-04 11:00:00 69,120 -c----w c:\windows\$NtServicePackUninstall$\psched.sys
+ 2004-08-04 11:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\pstorec.dll
+ 2004-08-04 11:00:00 34,304 -c----w c:\windows\$NtServicePackUninstall$\pstorsvc.dll
+ 2004-08-04 11:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\qcap.dll
+ 2004-08-04 11:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\qdv.dll
+ 2004-08-04 11:00:00 385,024 -c----w c:\windows\$NtServicePackUninstall$\qdvd.dll
+ 2004-08-04 11:00:00 562,176 -c----w c:\windows\$NtServicePackUninstall$\qedit.dll
+ 2004-08-04 11:00:00 733,696 -c----w c:\windows\$NtServicePackUninstall$\qedwipes.dll
+ 2004-08-04 11:00:00 382,464 -c----w c:\windows\$NtServicePackUninstall$\qmgr.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\qmgrprxy.dll
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\qprocess.exe
+ 2008-05-07 05:18:48 1,287,680 -c----w c:\windows\$NtServicePackUninstall$\quartz.dll
+ 2006-06-22 05:06:30 1,435,648 -c----w c:\windows\$NtServicePackUninstall$\query.dll
+ 2004-08-04 11:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\racpldlg.dll
+ 2004-08-04 11:00:00 20,736 -c----w c:\windows\$NtServicePackUninstall$\ramdisk.sys
+ 2006-06-26 17:37:10 8,192 -c----w c:\windows\$NtServicePackUninstall$\rasadhlp.dll
+ 2004-08-04 11:00:00 236,544 -c----w c:\windows\$NtServicePackUninstall$\rasapi32.dll
+ 2004-08-04 11:00:00 89,088 -c----w c:\windows\$NtServicePackUninstall$\rasauto.dll
+ 2004-08-04 11:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\raschap.dll
+ 2004-08-04 11:00:00 657,920 -c----w c:\windows\$NtServicePackUninstall$\rasdlg.dll
+ 2004-08-04 11:00:00 51,328 -c----w c:\windows\$NtServicePackUninstall$\rasl2tp.sys
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rasman.dll
+ 2006-06-22 10:47:18 181,248 -c----w c:\windows\$NtServicePackUninstall$\rasmans.dll
+ 2004-08-04 11:00:00 56,832 -c----w c:\windows\$NtServicePackUninstall$\rasphone.exe
+ 2004-08-04 11:00:00 206,336 -c----w c:\windows\$NtServicePackUninstall$\rasppp.dll
+ 2004-08-04 11:00:00 41,472 -c----w c:\windows\$NtServicePackUninstall$\raspppoe.sys
+ 2004-08-04 11:00:00 48,384 -c----w c:\windows\$NtServicePackUninstall$\raspptp.sys
+ 2004-08-04 11:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\rassapi.dll
+ 2004-08-04 11:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\rastapi.dll
+ 2004-08-04 11:00:00 112,128 -c----w c:\windows\$NtServicePackUninstall$\rastls.dll
+ 2004-08-04 11:00:00 102,400 -c----w c:\windows\$NtServicePackUninstall$\rcbdyctl.dll
+ 2004-08-04 11:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\rcimlby.exe
+ 2004-08-04 11:00:00 21,504 -c----w c:\windows\$NtServicePackUninstall$\rcp.exe
+ 2006-05-05 09:47:57 174,592 -c----w c:\windows\$NtServicePackUninstall$\rdbss.sys
+ 2004-08-04 11:00:00 147,968 -c----w c:\windows\$NtServicePackUninstall$\rdchost.dll
+ 2004-08-04 11:00:00 62,464 -c----w c:\windows\$NtServicePackUninstall$\rdpclip.exe
+ 2004-08-04 11:00:00 92,168 -c----w c:\windows\$NtServicePackUninstall$\rdpdd.dll
+ 2004-08-04 06:01:16 196,864 -c----w c:\windows\$NtServicePackUninstall$\rdpdr.sys
+ 2004-08-04 11:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\rdpsnd.dll
+ 2005-06-10 04:09:46 139,528 -c----w c:\windows\$NtServicePackUninstall$\rdpwd.sys
+ 2004-08-04 11:00:00 87,176 -c----w c:\windows\$NtServicePackUninstall$\rdpwsx.dll
+ 2004-08-04 11:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rdsaddin.exe
+ 2004-08-04 11:00:00 67,072 -c----w c:\windows\$NtServicePackUninstall$\rdshost.exe
+ 2004-08-03 21:59:38 57,472 -c----w c:\windows\$NtServicePackUninstall$\redbook.sys
+ 2004-08-04 11:00:00 50,176 -c----w c:\windows\$NtServicePackUninstall$\reg.exe
+ 2004-08-04 11:00:00 49,664 -c----w c:\windows\$NtServicePackUninstall$\regapi.dll
+ 2004-08-04 11:00:00 146,432 -c----w c:\windows\$NtServicePackUninstall$\regedit.exe
+ 2004-08-04 11:00:00 59,904 -c----w c:\windows\$NtServicePackUninstall$\regsvc.dll
+ 2004-08-04 11:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\regsvr32.exe
+ 2004-08-04 11:00:00 397,824 -c----w c:\windows\$NtServicePackUninstall$\regwizc.dll
+ 2004-08-04 11:00:00 60,416 -c----w c:\windows\$NtServicePackUninstall$\remotepg.dll
+ 2004-08-04 11:00:00 177,152 -c----w c:\windows\$NtServicePackUninstall$\repdrvfs.dll
+ 2004-08-04 11:00:00 58,880 -c----w c:\windows\$NtServicePackUninstall$\resutils.dll
+ 2004-08-04 11:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\rexec.exe
+ 2006-11-27 14:54:06 433,152 -c----w c:\windows\$NtServicePackUninstall$\riched20.dll
+ 2008-05-08 12:28:49 202,752 -c----w c:\windows\$NtServicePackUninstall$\rmcast.sys
+ 2004-08-04 11:00:00 30,080 -c----w c:\windows\$NtServicePackUninstall$\rndismp.sys
+ 2007-07-09 13:16:16 582,656 -c----w c:\windows\$NtServicePackUninstall$\rpcrt4.dll
+ 2005-07-26 11:39:49 397,824 -c----w c:\windows\$NtServicePackUninstall$\rpcss.dll
+ 2004-08-04 11:00:00 61,440 -c----w c:\windows\$NtServicePackUninstall$\rrcm.dll
+ 2004-08-04 11:00:00 152,576 -c----w c:\windows\$NtServicePackUninstall$\rsaenh.dll
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\rsh.exe
+ 2004-08-04 11:00:00 39,936 -c----w c:\windows\$NtServicePackUninstall$\rshx32.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\rsmps.dll
+ 2004-08-04 11:00:00 380,416 -c----w c:\windows\$NtServicePackUninstall$\rstrui.exe
+ 2004-08-04 11:00:00 90,112 -c----w c:\windows\$NtServicePackUninstall$\rsvpsp.dll
+ 2004-08-04 11:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\rtcshare.exe
+ 2004-08-04 11:00:00 31,744 -c----w c:\windows\$NtServicePackUninstall$\rtipxmib.dll
+ 2004-08-04 11:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\rtutils.dll
+ 2004-08-04 11:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\rundll32.exe
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\runonce.exe
+ 2004-08-04 11:00:00 24,576 -c----w c:\windows\$NtServicePackUninstall$\rw001ext.dll
+ 2004-08-04 11:00:00 26,624 -c----w c:\windows\$NtServicePackUninstall$\rw330ext.dll
+ 2004-08-04 11:00:00 43,520 -c----w c:\windows\$NtServicePackUninstall$\safrcdlg.dll
+ 2004-08-04 11:00:00 29,696 -c----w c:\windows\$NtServicePackUninstall$\safrdm.dll
+ 2004-08-04 11:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\safrslv.dll
+ 2004-08-04 11:00:00 64,000 -c----w c:\windows\$NtServicePackUninstall$\samlib.dll
+ 2004-08-04 11:00:00 415,744 -c----w c:\windows\$NtServicePackUninstall$\samsrv.dll
+ 2004-08-04 11:00:00 741,376 -c----w c:\windows\$NtServicePackUninstall$\sapi.dll
+ 2004-08-04 11:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\savedump.exe
+ 2004-08-04 11:00:00 270,848 -c----w c:\windows\$NtServicePackUninstall$\sbe.dll
+ 2004-08-04 11:00:00 159,232 -c----w c:\windows\$NtServicePackUninstall$\sbeio.dll
+ 2004-08-04 11:00:00 69,632 -c----w c:\windows\$NtServicePackUninstall$\scarddlg.dll
+ 2004-08-04 11:00:00 95,744 -c----w c:\windows\$NtServicePackUninstall$\scardsvr.exe
+ 2004-08-04 11:00:00 171,008 -c----w c:\windows\$NtServicePackUninstall$\sccsccp.dll
+ 2004-08-04 11:00:00 180,224 -c----w c:\windows\$NtServicePackUninstall$\scecli.dll
+ 2004-08-04 11:00:00 313,856 -c----w c:\windows\$NtServicePackUninstall$\scesrv.dll
+ 2007-04-25 14:21:15 144,896 -c----w c:\windows\$NtServicePackUninstall$\schannel.dll
+ 2004-08-04 11:00:00 190,976 -c----w c:\windows\$NtServicePackUninstall$\schedsvc.dll
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\sclgntfy.dll
+ 2004-08-04 11:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\scrcons.exe
+ 2004-08-04 11:00:00 202,752 -c----w c:\windows\$NtServicePackUninstall$\script.dll
+ 2004-08-04 11:00:00 9,216 -c----w c:\windows\$NtServicePackUninstall$\scrnsave.scr
+ 2004-08-04 11:00:00 159,744 -c----w c:\windows\$NtServicePackUninstall$\scrobj.dll
+ 2004-08-04 11:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\scrrun.dll
+ 2004-08-04 11:00:00 96,256 -c----w c:\windows\$NtServicePackUninstall$\scsiport.sys
+ 2004-08-04 11:00:00 77,312 -c----w c:\windows\$NtServicePackUninstall$\sdbinst.exe
+ 2004-08-04 11:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sdbus.sys
+ 2004-08-04 11:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sdhcinst.dll
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\seclogon.dll
+ 2004-08-04 11:00:00 55,808 -c----w c:\windows\$NtServicePackUninstall$\secur32.dll
+ 2004-08-04 11:00:00 5,632 -c----w c:\windows\$NtServicePackUninstall$\security.dll
+ 2004-08-04 11:00:00 29,184 -c----w c:\windows\$NtServicePackUninstall$\sendcmsg.dll
+ 2004-08-04 11:00:00 55,296 -c----w c:\windows\$NtServicePackUninstall$\sendmail.dll
+ 2004-08-04 11:00:00 38,912 -c----w c:\windows\$NtServicePackUninstall$\sens.dll
+ 2004-08-04 11:00:00 6,656 -c----w c:\windows\$NtServicePackUninstall$\sensapi.dll
+ 2004-08-04 11:00:00 15,488 -c----w c:\windows\$NtServicePackUninstall$\serenum.sys
+ 2004-08-04 11:00:00 64,896 -c----w c:\windows\$NtServicePackUninstall$\serial.sys
+ 2004-08-04 11:00:00 56,320 -c----w c:\windows\$NtServicePackUninstall$\servdeps.dll
+ 2004-08-04 11:00:00 108,032 -c----w c:\windows\$NtServicePackUninstall$\services.exe
+ 2004-08-04 11:00:00 140,800 -c----w c:\windows\$NtServicePackUninstall$\sessmgr.exe
+ 2004-08-04 11:00:00 31,232 -c----w c:\windows\$NtServicePackUninstall$\sethc.exe
+ 2004-08-04 11:00:00 23,040 -c----w c:\windows\$NtServicePackUninstall$\setup.exe
+ 2004-08-04 11:00:00 73,216 -c----w c:\windows\$NtServicePackUninstall$\setup50.exe
+ 2004-08-04 11:00:00 983,552 -c----w c:\windows\$NtServicePackUninstall$\setupapi.dll
+ 2004-08-04 11:00:00 101,376 -c----w c:\windows\$NtServicePackUninstall$\setupqry.dll
+ 2004-08-04 11:00:00 5,120 -c----w c:\windows\$NtServicePackUninstall$\sfc.dll
+ 2004-08-04 11:00:00 140,288 -c----w c:\windows\$NtServicePackUninstall$\sfc_os.dll
+ 2004-08-04 11:00:00 1,580,544 -c----w c:\windows\$NtServicePackUninstall$\sfcfiles.dll
+ 2004-08-04 11:00:00 11,136 -c----w c:\windows\$NtServicePackUninstall$\sffdisk.sys
+ 2004-08-04 11:00:00 10,240 -c----w c:\windows\$NtServicePackUninstall$\sffp_sd.sys
+ 2004-08-04 11:00:00 11,392 -c----w c:\windows\$NtServicePackUninstall$\sfloppy.sys
+ 2004-08-04 11:00:00 549,376 -c----w c:\windows\$NtServicePackUninstall$\shdoclc.dll
+ 2006-09-23 16:12:50 1,497,088 -c----w c:\windows\$NtServicePackUninstall$\shdocvw.dll
+ 2007-10-26 03:34:01 8,460,288 -c----w c:\windows\$NtServicePackUninstall$\shell32.dll
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\shfolder.dll
+ 2004-08-04 11:00:00 68,096 -c----w c:\windows\$NtServicePackUninstall$\shgina.dll
+ 2004-08-04 11:00:00 65,536 -c----w c:\windows\$NtServicePackUninstall$\shimeng.dll
+ 2004-08-04 11:00:00 438,272 -c----w c:\windows\$NtServicePackUninstall$\shimgvw.dll
+ 2006-09-23 16:12:50 474,112 -c----w c:\windows\$NtServicePackUninstall$\shlwapi.dll
+ 2004-08-04 11:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\shmedia.dll
+ 2004-08-04 11:00:00 42,496 -c----w c:\windows\$NtServicePackUninstall$\shmgrate.exe
+ 2004-08-04 11:00:00 77,824 -c----w c:\windows\$NtServicePackUninstall$\shrpubw.exe
+ 2004-08-04 11:00:00 27,648 -c----w c:\windows\$NtServicePackUninstall$\shscrap.dll
+ 2006-12-19 21:52:18 134,656 -c----w c:\windows\$NtServicePackUninstall$\shsvcs.dll
+ 2003-03-24 23:52:04 20,536 -c----w c:\windows\$NtServicePackUninstall$\shtml.dll
+ 2003-03-24 23:52:04 16,437 -c----w c:\windows\$NtServicePackUninstall$\shtml.exe
+ 2004-08-04 11:00:00 19,456 -c----w c:\windows\$NtServicePackUninstall$\shutdown.exe
+ 2004-08-04 11:00:00 13,312 -c----w c:\windows\$NtServicePackUninstall$\sigtab.dll
+ 2004-08-04 11:00:00 70,144 -c----w c:\windows\$NtServicePackUninstall$\sigverif.exe
+ 2004-08-04 11:00:00 26,112 -c----w c:\windows\$NtServicePackUninstall$\skeys.exe
+ 2004-08-04 11:00:00 25,088 -c----w c:\windows\$NtServicePackUninstall$\slayerxp.dll
+ 2004-08-04 11:00:00 98,304 -c----w c:\windows\$NtServicePackUninstall$\slbiop.dll
+ 2004-08-04 11:00:00 8,192 -c----w c:\windows\$NtServicePackUninstall$\smbinst.exe
+ 2004-08-04 11:00:00 236,544 -c----w c:\windows\$NtServicePackUninstall$\smi2smir.exe
+ 2004-08-04 11:00:00 363,008 -c----w c:\windows\$NtServicePackUninstall$\smlogcfg.dll
+ 2004-08-04 11:00:00 89,600 -c----w c:\windows\$NtServicePackUninstall$\smlogsvc.exe
+ 2004-08-04 11:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\smss.exe
+ 2004-08-04 11:00:00 456,704 -c----w c:\windows\$NtServicePackUninstall$\smtpsvc.dll
+ 2004-08-04 11:00:00 131,584 -c----w c:\windows\$NtServicePackUninstall$\sndrec32.exe
+ 2004-08-04 11:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\sniffpol.dll
+ 2004-08-04 11:00:00 32,768 -c----w c:\windows\$NtServicePackUninstall$\snmp.exe
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\snmpapi.dll
+ 2004-08-04 11:00:00 259,072 -c----w c:\windows\$NtServicePackUninstall$\snmpcl.dll
+ 2004-08-04 11:00:00 358,400 -c----w c:\windows\$NtServicePackUninstall$\snmpincl.dll
+ 2004-08-04 11:00:00 6,144 -c----w c:\windows\$NtServicePackUninstall$\snmpmib.dll
+ 2004-08-04 11:00:00 188,416 -c----w c:\windows\$NtServicePackUninstall$\snmpsmir.dll
+ 2004-08-04 11:00:00 182,272 -c----w c:\windows\$NtServicePackUninstall$\snmpsnap.dll
+ 2004-08-04 11:00:00 40,448 -c----w c:\windows\$NtServicePackUninstall$\snmpthrd.dll
+ 2004-08-04 11:00:00 8,704 -c----w c:\windows\$NtServicePackUninstall$\snmptrap.exe
+ 2004-08-04 11:00:00 130,048 -c----w c:\windows\$NtServicePackUninstall$\softkbd.dll
+ 2004-08-04 11:00:00 25,472 -c----w c:\windows\$NtServicePackUninstall$\sonydcam.sys
+ 2004-08-04 11:00:00 23,552 -c----w c:\windows\$NtServicePackUninstall$\sort.exe
+ 2004-08-04 11:00:00 62,976 -c----w c:\windows\$NtServicePackUninstall$\spgrmr.dll
+ 2004-08-04 11:00:00 538,624 -c----w c:\windows\$NtServicePackUninstall$\spider.exe
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys
+ 2006-06-14 08:47:46 6,400 -c----w c:\windows\$NtServicePackUninstall$\splitter.sys.000
+ 2004-08-04 11:00:00 11,776 -c----w c:\windows\$NtServicePackUninstall$\spnpinst.exe
+ 2004-08-04 11:00:00 74,752 -c----w c:\windows\$NtServicePackUninstall$\spoolss.dll
+ 2005-06-10 23:53:32 57,856 -c----w c:\windows\$NtServicePackUninstall$\spoolsv.exe
+ 2004-08-04 11:00:00 193,024 -c----w c:\windows\$NtServicePackUninstall$\spra041b.dll
+ 2004-08-04 11:00:00 192,512 -c----w c:\windows\$NtServicePackUninstall$\spra0424.dll
+ 2004-08-04 11:00:00 757,248 -c----w c:\windows\$NtServicePackUninstall$\sprb041b.dll
+ 2004-08-04 11:00:00 732,160 -c----w c:\windows\$NtServicePackUninstall$\sprb0424.dll
+ 2004-08-04 11:00:00 250,880 -c----w c:\windows\$NtServicePackUninstall$\sptip.dll
+ 2008-04-14 09:42:08 438,272 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spcompat.dll
+ 2007-08-11 00:46:18 231,288 -c----w c:\windows\$NtServicePackUninstall$\spuninst\spuninst.exe
+ 2007-08-11 00:46:28 382,840 -c----w c:\windows\$NtServicePackUninstall$\spuninst\updspapi.dll
+ 2004-08-04 11:00:00 151,552 -c----w c:\windows\$NtServicePackUninstall$\sqldb20.dll
+ 2004-08-04 11:00:00 528,384 -c----w c:\windows\$NtServicePackUninstall$\sqloledb.dll
+ 2004-08-04 11:00:00 462,848 -c----w c:\windows\$NtServicePackUninstall$\sqlqp20.dll
+ 2004-08-04 11:00:00 110,592 -c----w c:\windows\$NtServicePackUninstall$\sqlse20.dll
+ 2004-08-04 11:00:00 442,368 -c----w c:\windows\$NtServicePackUninstall$\sqlsrv32.dll
+ 2004-08-04 11:00:00 180,800 -c----w c:\windows\$NtServicePackUninstall$\sqlunirl.dll
+ 2004-08-04 11:00:00 217,088 -c----w c:\windows\$NtServicePackUninstall$\sqlxmlx.dll
+ 2004-08-04 11:00:00 73,472 -c----w c:\windows\$NtServicePackUninstall$\sr.sys
+ 2004-08-04 11:00:00 58,434 -c----w c:\windows\$NtServicePackUninstall$\srchctls.dll
+ 2004-08-04 11:00:00 725,566 -c----w c:\windows\$NtServicePackUninstall$\srchui.dll
+ 2004-08-04 11:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\srclient.dll
+ 2004-08-04 11:00:00 239,104 -c----w c:\windows\$NtServicePackUninstall$\srrstr.dll
+ 2004-08-04 11:00:00 170,496 -c----w c:\windows\$NtServicePackUninstall$\srsvc.dll
+ 2006-08-14 10:34:41 332,928 -c----w c:\windows\$NtServicePackUninstall$\srv.sys
+ 2004-12-07 19:32:34 96,768 -c----w c:\windows\$NtServicePackUninstall$\srvsvc.dll
+ 2004-08-04 11:00:00 704,512 -c----w c:\windows\$NtServicePackUninstall$\ss3dfo.scr
+ 2004-08-04 11:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ssbezier.scr
+ 2004-08-04 11:00:00 34,816 -c----w c:\windows\$NtServicePackUninstall$\ssdpapi.dll
+ 2004-08-04 11:00:00 71,680 -c----w c:\windows\$NtServicePackUninstall$\ssdpsrv.dll
+ 2004-08-04 11:00:00 393,216 -c----w c:\windows\$NtServicePackUninstall$\ssflwbox.scr
+ 2004-08-04 11:00:00 20,992 -c----w c:\windows\$NtServicePackUninstall$\ssmarque.scr
+ 2004-08-04 11:00:00 47,104 -c----w c:\windows\$NtServicePackUninstall$\ssmypics.scr
+ 2004-08-04 11:00:00 18,944 -c----w c:\windows\$NtServicePackUninstall$\ssmyst.scr
+ 2004-08-04 11:00:00 610,304 -c----w c:\windows\$NtServicePackUninstall$\sspipes.scr
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\ssstars.scr
+ 2004-08-04 11:00:00 679,936 -c----w c:\windows\$NtServicePackUninstall$\sstext3d.scr
+ 2004-08-04 11:00:00 33,280 -c----w c:\windows\$NtServicePackUninstall$\sstub.dll
+ 2004-08-04 11:00:00 22,016 -c----w c:\windows\$NtServicePackUninstall$\startoc.dll
+ 2004-08-04 11:00:00 54,272 -c----w c:\windows\$NtServicePackUninstall$\stclient.dll
+ 2004-08-04 11:00:00 86,528 -c----w c:\windows\$NtServicePackUninstall$\stdprov.dll
+ 2004-08-04 11:00:00 67,584 -c----w c:\windows\$NtServicePackUninstall$\sti.dll
+ 2004-08-04 11:00:00 136,704 -c----w c:\windows\$NtServicePackUninstall$\sti_ci.dll
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\stimon.exe
+ 2004-08-04 11:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\stobject.dll
+ 2004-08-03 23:56:46 74,752 -c----w c:\windows\$NtServicePackUninstall$\storprop.dll
+ 2004-08-04 13:08:04 48,640 -c----w c:\windows\$NtServicePackUninstall$\stream.sys
+ 2006-08-21 13:52:08 246,814 -c----w c:\windows\$NtServicePackUninstall$\strmdll.dll
+ 2004-08-04 11:00:00 75,776 -c----w c:\windows\$NtServicePackUninstall$\strmfilt.dll
+ 2004-08-04 11:00:00 14,336 -c----w c:\windows\$NtServicePackUninstall$\svchost.exe
+ 2004-08-04 11:00:00 4,352 -c----w c:\windows\$NtServicePackUninstall$\swenum.sys
+ 2001-08-18 04:00:52 54,272 -c----w c:\windows\$NtServicePackUninstall$\swmidi.sys
+ 2006-10-19 13:56:32 713,216 -c----w c:\windows\$NtServicePackUninstall$\sxs.dll
+ 2004-08-04 11:00:00 57,856 -c----w c:\windows\$NtServicePackUninstall$\synceng.dll
+ 2004-08-04 11:00:00 191,488 -c----w c:\windows\$NtServicePackUninstall$\syncui.dll
+ 2004-08-04 13:15:56 60,800 -c----w c:\windows\$NtServicePackUninstall$\sysaudio.sys
+ 2004-08-04 11:00:00 168,960 -c----w c:\windows\$NtServicePackUninstall$\sysmod.dll
+ 2004-08-04 11:00:00 105,984 -c----w c:\windows\$NtServicePackUninstall$\sysocmgr.exe
+ 2004-08-04 11:00:00 984,576 -c----w c:\windows\$NtServicePackUninstall$\syssetup.dll
+ 2005-10-18 04:14:46 118,272 -c----w c:\windows\$NtServicePackUninstall$\t2embed.dll
+ 2004-08-04 11:00:00 14,976 -c----w c:\windows\$NtServicePackUninstall$\tape.sys
+ 2004-08-04 11:00:00 858,624 -c----w c:\windows\$NtServicePackUninstall$\tapi3.dll
+ 2004-08-04 11:00:00 181,760 -c----w c:\windows\$NtServicePackUninstall$\tapi32.dll
+ 2005-07-08 16:27:56 249,344 -c----w c:\windows\$NtServicePackUninstall$\tapisrv.dll
+ 2004-08-04 11:00:00 135,680 -c----w c:\windows\$NtServicePackUninstall$\taskmgr.exe
+ 2008-06-20 10:45:13 360,320 -c----w c:\windows\$NtServicePackUninstall$\tcpip.sys
+ 2008-06-20 09:52:06 225,920 -c----w c:\windows\$NtServicePackUninstall$\tcpip6.sys
+ 2004-08-04 11:00:00 14,848 -c----w c:\windows\$NtServicePackUninstall$\tcpmib.dll
+ 2004-08-04 11:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmon.dll
+ 2004-08-04 11:00:00 45,568 -c----w c:\windows\$NtServicePackUninstall$\tcpmonui.dll
+ 2003-03-24 23:52:04 32,827 -c----w c:\windows\$NtServicePackUninstall$\tcptest.exe
+ 2003-03-24 23:52:06 16,384 -c----w c:\windows\$NtServicePackUninstall$\tcptsat.dll
+ 2004-08-04 11:00:00 18,560 -c----w c:\windows\$NtServicePackUninstall$\tdi.sys
+ 2004-08-04 11:00:00 12,040 -c----w c:\windows\$NtServicePackUninstall$\tdpipe.sys
+ 2004-08-04 11:00:00 21,896 -c----w c:\windows\$NtServicePackUninstall$\tdtcp.sys
+ 2005-05-10 23:45:48 75,776 -c----w c:\windows\$NtServicePackUninstall$\telnet.exe
+ 2004-08-04 08:01:08 40,840 -c----w c:\windows\$NtServicePackUninstall$\termdd.sys
+ 2004-08-04 11:00:00 358,400 -c----w c:\windows\$NtServicePackUninstall$\termmgr.dll
+ 2004-08-04 11:00:00 295,424 -c----w c:\windows\$NtServicePackUninstall$\termsrv.dll
+ 2004-08-04 11:00:00 385,536 -c----w c:\windows\$NtServicePackUninstall$\themeui.dll
+ 2004-08-04 11:00:00 347,136 -c----w c:\windows\$NtServicePackUninstall$\tourstart.exe
+ 2004-08-04 11:00:00 347,136 -c----w c:\windows\$NtServicePackUninstall$\tourstrt.exe
+ 2004-08-04 11:00:00 12,288 -c----w c:\windows\$NtServicePackUninstall$\tracert.exe
+ 2004-08-04 11:00:00 11,264 -c----w c:\windows\$NtServicePackUninstall$\tree.com
+ 2004-08-04 11:00:00 153,088 -c----w c:\windows\$NtServicePackUninstall$\triedit.dll
+ 2004-08-04 11:00:00 90,624 -c----w c:\windows\$NtServicePackUninstall$\trkwks.dll
+ 2004-08-04 11:00:00 93,696 -c----w c:\windows\$NtServicePackUninstall$\tscfgwmi.dll
+ 2004-08-04 11:00:00 12,168 -c----w c:\windows\$NtServicePackUninstall$\tsddd.dll
+ 2004-08-04 11:00:00 279,040 -c----w c:\windows\$NtServicePackUninstall$\tshoot.dll
+ 2004-08-04 11:00:00 121,856 -c----w c:\windows\$NtServicePackUninstall$\tsoc.dll
+ 2004-08-04 11:00:00 12,416 -c----w c:\windows\$NtServicePackUninstall$\tunmp.sys
+ 2004-08-04 11:00:00 50,688 -c----w c:\windows\$NtServicePackUninstall$\twain_32.dll
+ 2004-08-04 11:00:00 44,032 -c----w c:\windows\$NtServicePackUninstall$\twext.dll
+ 2005-07-26 11:39:49 101,376 -c----w c:\windows\$NtServicePackUninstall$\txflog.dll
+ 2008-07-14 11:09:18 62,976 -c----w c:\windows\$NtServicePackUninstall$\tzchange.exe
+ 2007-09-29 23:07:27 2,678 -c----w c:\windows\$NtServicePackUninstall$\uam79nnp.dat
+ 2004-08-04 11:00:00 66,176 -c----w c:\windows\$NtServicePackUninstall$\udfs.sys
+ 2004-08-04 11:00:00 25,600 -c----w c:\windows\$NtServicePackUninstall$\udhisapi.dll
+ 2004-08-04 11:00:00 275,456 -c----w c:\windows\$NtServicePackUninstall$\ulib.dll
+ 2004-08-04 11:00:00 35,840 -c----w c:\windows\$NtServicePackUninstall$\umandlg.dll
+ 2005-08-23 03:35:42 123,392 -c----w c:\windows\$NtServicePackUninstall$\umpnpmgr.dll
+ 2004-08-04 04:56:48 264,704 -c----w c:\windows\$NtServicePackUninstall$\unidrv.dll
+ 2004-08-04 04:56:48 197,120 -c----w c:\windows\$NtServicePackUninstall$\unidrvui.dll
+ 2004-08-04 11:00:00 74,240 -c----w c:\windows\$NtServicePackUninstall$\unimdmat.dll
+ 2004-08-04 11:00:00 13,824 -c----w c:\windows\$NtServicePackUninstall$\uniplat.dll
+ 2004-08-04 04:56:36 619,520 -c----w c:\windows\$NtServicePackUninstall$\unires.dll
+ 2004-08-04 11:00:00 316,416 -c----w c:\windows\$NtServicePackUninstall$\untfs.dll
+ 2007-04-23 10:32:54 364,160 -c----w c:\windows\$NtServicePackUninstall$\update.sys
+ 2004-08-04 11:00:00 150,528 -c----w c:\windows\$NtServicePackUninstall$\uploadm.exe
+ 2004-08-04 11:00:00 132,608 -c----w c:\windows\$NtServicePackUninstall$\upnp.dll
+ 2004-08-04 11:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\upnpcont.exe
+ 2007-02-05 20:17:02 185,344 -c----w c:\windows\$NtServicePackUninstall$\upnphost.dll
+ 2004-08-04 11:00:00 239,616 -c----w c:\windows\$NtServicePackUninstall$\upnpui.dll
+ 2004-08-04 11:00:00 18,432 -c----w c:\windows\$NtServicePackUninstall$\ups.exe
+ 2004-08-04 11:00:00 12,672 -c----w c:\windows\$NtServicePackUninstall$\usb8023.sys
+ 2004-08-04 11:00:00 23,808 -c----w c:\windows\$NtServicePackUninstall$\usbcamd.sys
+ 2004-08-04 11:00:00 23,936 -c----w c:\windows\$NtServicePackUninstall$\usbcamd2.sys
+ 2005-03-31 08:13:52 27,008 -c----w c:\windows\$NtServicePackUninstall$\usbehci.sys
+ 2005-03-31 08:13:52 27,008 -c----w c:\windows\$NtServicePackUninstall$\usbehci.sys.000
+ 2004-08-04 11:00:00 57,600 -c----w c:\windows\$NtServicePackUninstall$\usbhub.sys
+ 2004-08-04 11:00:00 16,000 -c----w c:\windows\$NtServicePackUninstall$\usbintel.sys
+ 2004-08-04 11:00:00 16,896 -c----w c:\windows\$NtServicePackUninstall$\usbmon.dll
+ 2004-08-04 13:08:38 17,024 -c----w c:\windows\$NtServicePackUninstall$\usbohci.sys
+ 2004-08-04 11:00:00 142,976 -c----w c:\windows\$NtServicePackUninstall$\usbport.sys
+ 2004-08-04 11:00:00 26,496 -c----w c:\windows\$NtServicePackUninstall$\usbstor.sys
+ 2004-08-04 11:00:00 20,480 -c----w c:\windows\$NtServicePackUninstall$\usbuhci.sys
+ 2004-08-03 23:56:48 74,240 -c----w c:\win

#9 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 03 February 2009 - 09:19 PM

Combofix log is too long. I keep getting error messages. Suggestions? PM me your email and I send as attachment? I don't know what to do with that.

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:49 PM, on 2/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\WINDOWS\system32\NOTEPAD.EXE
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Compaq Organize.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20364.www2.hp.com/CSMWeb/Customer/...DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols3beta/fscax.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe

--
End of file - 9238 bytes
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#10 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 04 February 2009 - 02:22 PM

Please attach the Combofix.txt to your reply. To do that when you press the ADDREPLY, under the reply window press Browse... show the path to the file on your computer:

c:\combofix.txt

Highlight the file and click Open then press the green UPLOAD button.

Edited by farbar, 04 February 2009 - 02:23 PM.


#11 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 04 February 2009 - 07:42 PM

:thumbup2:

No go. Said it was uploading file for like 20 minutes and noting happened
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#12 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 05 February 2009 - 02:25 AM

You can upload the file to the following site and give me the link to the file:
http://www.mediafire.com/

#13 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 07 February 2009 - 01:51 PM

I PM'd the link to you
Inept Computer User

I'm so happy 'cause today I found my friends in my head.....

#14 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:09 AM

Posted 08 February 2009 - 09:10 AM

Thanks for uploading the Combofix log.

  • It would not get rid of the coupon printer, that froze up every time I tried to uninstall it. I just installed it recently for some rewards I had won from Coke. I do not think it's malicious but will remove it by other means if you instruct me how.


    One of the questionable Coupons.com practices is inability of the users to uninstall its software properly via Add/Remove Programs.
    For more information please see this:
    A Closer Look at Coupons.com

    Let me know if you want to get rid of the Coupons Printer.

  • If you can not find the following file make sure that you can view all hidden and system files. Instructions on how to do this can be found here: How to see hidden files in Windows

    Click on this link--> virustotal

    Click the browse button and navigate to the file below in bold, then click Send File.

    C:\WINDOWS\system32\zvpekucihp.exe

    If the file is analyzed before click Reanalyse File Now button.

    Please copy and paste the results of the scan in your next post.

  • Please use Internet Explorer to perform a BitDefender Online Virus and Malware Scan
  • Click on I Agree.
  • If an Active X warning box will appear Click on Install.
    Note: If you got the message:"Could not load the Online Scanner! Click here for other possible fixes", it means Internet Explorer has blocked the Active X being installed. Just above the page under the Internet Explorer toolbar you see this message:
    "This website wants to install the following add-on: "Bitdefender OnlineScanner v8' from 'BITDEFENDER LLC'. If you trust the website and the add-on and want to install it, click here..."
    Click on that and select: Install Active x.
  • Now Click On Start Scan. Please wait as it might take some time.
  • If it found anything when it finished click Click here to export the scan report
  • Give the report a name and save it. The file will be a .HTML file.
  • Please attach the file to your reply.
  • To attach the file press ADDREPLY, under the reply window press Browse... show the path to the file on your computer.
  • Highlight the file and click Open then press the green UPLOAD button.


#15 The Grog

The Grog
  • Topic Starter

  • Members
  • 128 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pennsylvania
  • Local time:09:09 PM

Posted 08 February 2009 - 07:43 PM

VirusTotal


File zvpekucihp.exe received on 02.09.2009 01:39:18 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 3/39 (7.7%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.0.0.93 2009.02.09 -
AhnLab-V3 5.0.0.2 2009.02.07 -
AntiVir 7.9.0.76 2009.02.08 -
Authentium 5.1.0.4 2009.02.08 -
Avast 4.8.1335.0 2009.02.08 -
AVG 8.0.0.229 2009.02.08 -
BitDefender 7.2 2009.02.09 -
CAT-QuickHeal 10.00 2009.02.07 -
ClamAV 0.94.1 2009.02.09 -
Comodo 971 2009.02.08 -
DrWeb 4.44.0.09170 2009.02.09 -
eSafe 7.0.17.0 2009.02.08 -
eTrust-Vet 31.6.6346 2009.02.07 -
F-Prot 4.4.4.56 2009.02.08 -
F-Secure 8.0.14470.0 2009.02.09 -
Fortinet 3.117.0.0 2009.02.08 -
GData 19 2009.02.09 -
Ikarus T3.1.1.45.0 2009.02.09 -
K7AntiVirus 7.10.623 2009.02.07 -
Kaspersky 7.0.0.125 2009.02.09 -
McAfee 5520 2009.02.08 -
McAfee+Artemis 5520 2009.02.08 -
Microsoft 1.4306 2009.02.08 -
NOD32 3837 2009.02.08 -
Norman 6.00.02 2009.02.06 -
nProtect 2009.1.8.0 2009.02.08 -
Panda 9.5.1.2 2009.02.08 -
PCTools 4.4.2.0 2009.02.08 Adware.Adrotator.GEN
Prevx1 V2 2009.02.09 Cloaked Malware
Rising 21.15.50.00 2009.02.07 -
SecureWeb-Gateway 6.7.6 2009.02.09 -
Sophos 4.38.0 2009.02.08 -
Sunbelt 3.2.1847.2 2009.02.07 -
Symantec 10 2009.02.09 -
TheHacker 6.3.1.5.249 2009.02.09 Adware/AdRotator
TrendMicro 8.700.0.1004 2009.02.06 -
VBA32 3.12.8.12 2009.02.08 -
ViRobot 2009.2.6.1594 2009.02.06 -
VirusBuster 4.5.11.0 2009.02.08 -
Additional information
File size: 47598 bytes
MD5...: 9aa256298d1fda25a9b9163f1e5a9612
SHA1..: 61db76be58b5b0a82a5657107933b216707c34c2
SHA256: 2825ac7030bfd1714163551af85700301b6ba2b9a7df9374f6190fa24071b333
SHA512: 25489d1a465b580549e77c56ba6c4ebd6066302e32223e1d158e35b9922c09b7
0ab88cb0a27d3a737284057c31400c32ef2ea7cd63b84187729f0f8e581bde70
ssdeep: 768:SSup23EQCjlQRB8/ewZ1iU6nyYFxbssT/F/O71mJ5TJRn0V9RXW88Zjd7cim
Oy3z:Hu4EQalMK/ewGnh0mJ6PRXW9dh5yoMJ
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x3225
timedatestamp.....: 0x48efcdc9 (Fri Oct 10 21:48:57 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5976 0x5a00 6.47 335c19bb25cd1d02eec2b0a4eacb979c
.rdata 0x7000 0x1190 0x1200 5.18 db16645055619c0cc73276ff5c3adb75
.data 0x9000 0x1af98 0x400 4.69 59710519e577598f785044e4d95261f4
.ndata 0x24000 0xd000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x31000 0x908 0xa00 3.85 c8a7e34036e84f6de6309bd5eacecfa0

( 8 imports )
> KERNEL32.dll: CompareFileTime, SearchPathA, GetShortPathNameA, GetFullPathNameA, MoveFileA, SetCurrentDirectoryA, GetFileAttributesA, GetLastError, CreateDirectoryA, SetFileAttributesA, Sleep, GetTickCount, CreateFileA, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, ExitProcess, SetFileTime, GetTempPathA, GetCommandLineA, SetErrorMode, LoadLibraryA, lstrcpynA, GetDiskFreeSpaceA, GlobalUnlock, GlobalLock, CreateThread, CreateProcessA, RemoveDirectoryA, GetTempFileNameA, lstrlenA, lstrcatA, GetSystemDirectoryA, GetVersion, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, WaitForSingleObject, GetExitCodeProcess, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, WriteFile, ReadFile, MulDiv, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, GetWindowsDirectoryA
> USER32.dll: EndDialog, ScreenToClient, GetWindowRect, EnableMenuItem, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, RegisterClassA, TrackPopupMenu, AppendMenuA, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, OpenClipboard, ExitWindowsEx, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, ShowWindow
> GDI32.dll: SetBkColor, GetDeviceCaps, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor, SelectObject
> SHELL32.dll: SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA, SHGetSpecialFolderLocation
> ADVAPI32.dll: RegQueryValueExA, RegSetValueExA, RegEnumKeyA, RegEnumValueA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA
> COMCTL32.dll: ImageList_AddMasked, ImageList_Destroy, -, ImageList_Create
> ole32.dll: CoTaskMemFree, OleInitialize, OleUninitialize, CoCreateInstance
> VERSION.dll: GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

( 0 exports )
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=9aa256298d1fda25a9b9163f1e5a9612' target='_blank'>http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=9aa256298d1fda25a9b9163f1e5a9612</a>
Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=8BBFD997EEC3D6E0B91500CEBA529500046EB8CF' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=8BBFD997EEC3D6E0B91500CEBA529500046EB8CF</a>







Could not get bitdefender to come up as you said it would. Don't use IE much anymore, usually use firefox.

I did go use it as you suggested and went into IE's properties and disabled the pop up blocker and clicked it to prompt for active x instead of disable and still nothing came up when I clicked on the I agree button. It just redirects to same page.


Also would like to get rid of coupon.com printer

Edited by The Grog, 08 February 2009 - 08:03 PM.

Inept Computer User

I'm so happy 'cause today I found my friends in my head.....




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users