This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Wierd Trojans popping up despite several MBAM+Spybot r

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear experts,

I am in quite a predicament. I have latest version of MBAM + Spybot S&D + Teamtimer + WinPatrol + MVP HOSTS + Trojan Antivirus. Normally, i have become pretty savvy (thanks to What_the_tech) regarding when to grant certain entries access to registry changes and when not to. However, since yesterday, i have been getting wierd IE 7.0 pop-ups. After performing MBAM scans, and countless reboots, the type of "trojans" + "malware" detected keeps changing. Attached below is the latest OTListIt2 and HJT logs. I hope you can help me narrow down the problem source.

Thank you in advance :-)

OTListIt2 Log
===========
OTListIt logfile created on: 2/28/2009 1:27:05 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.3.0 Folder = D:\Data\Downloads\Malware Removal
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.80 Gb Available in Paging File | 95.07% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 4.07 Gb Free Space | 20.81% Space Free | Partition Type: NTFS
Drive D: | 54.99 Gb Total Space | 7.23 Gb Free Space | 13.14% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USMMAN8C
Current User Name: vm092543
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINNT\System32\WLTRYSVC.EXE ()
PRC - C:\WINNT\System32\bcmwltry.exe (Dell Inc.)
PRC - C:\Program Files\AccessManager\Client\AMBroker.exe (MCI, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINNT\System32\MCSvc.exe (© 2005 - 2008 Siemens AG)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\OfficeScan NT\ntrtscan.exe (Trend Micro Inc.)
PRC - C:\WINNT\system32\SvcLncher.exe (SIS GO GIO DS PSU6)
PRC - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe (Smartpipes, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe (SigmaTel, Inc.)
PRC - C:\WINNT\system32\Suss.exe (Microsoft Corporation)
PRC - C:\Program Files\AccessManager\Client\sygman.exe (MCI, Inc.)
PRC - C:\Program Files\OfficeScan NT\tmlisten.exe (Trend Micro Inc.)
PRC - C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\WINNT\TEMP\AB3FA4.EXE (Trend Micro Inc.)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\OfficeScan NT\TmPfw.exe (Trend Micro Inc.)
PRC - C:\WINNT\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\OfficeScan NT\pccntmon.exe (Trend Micro Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\WINNT\stsystra.exe (SigmaTel, Inc.)
PRC - C:\WINNT\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINNT\system32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\AccessManager\Client\AccessMgr.exe (MCI, Inc.)
PRC - C:\WINNT\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINNT\system32\WLTRAY.exe (Dell Inc.)
PRC - C:\WINNT\system32\taskswitch.exe ()
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\WINNT\Managed\MCDesk.exe (© 2005 - 2008 Siemens AG)
PRC - C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Spybot\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe (Copernic Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\interwise\Participant\pull.exe (AT&T Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe ()
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe ()
PRC - C:\Program Files\OfficeScan NT\CNTAoSMgr.exe (Trend Micro Inc.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - D:\Data\Downloads\Malware Removal\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINNT\system32\HPZinw12.exe (HP)

========== Win32 Services (SafeList) ==========

SRV - (6to4 [Disabled | Stopped]) – C:\WINNT\system32\6to4v32.dll ()
SRV - (AMBroker [Auto | Running]) – C:\Program Files\AccessManager\Client\AMBroker.exe (MCI, Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CcmExec [Unknown | Running]) – C:\WINNT\system32\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DAPlugin [On_Demand | Stopped]) – C:\Program Files\AccessManager\Client\DAPlugin.exe (MCI, Inc.)
SRV - (defaultlib [Disabled | Stopped]) – C:\WINNT\system32\u52856226.dll ()
SRV - (DMService [On_Demand | Stopped]) – C:\WINNT\DOWNLO~1\DMService.exe ()
SRV - (eBOSS [Auto | Stopped]) – C:\WINNT\System32\eboss.exe (Siemens Business Services)
SRV - (ExtranetAccess [On_Demand | Stopped]) – C:\Program Files\IP VPN Remote Services\Extranet_serv.exe (Nortel Networks NA, Inc.)
SRV - (FLEXnet Licensing Service [On_Demand | Running]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINNT\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (HTTP Poster [Auto | Stopped]) – C:\WINNT\system32\HTTP_Poster.exe (Nokia)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPassConnectEngine [On_Demand | Stopped]) – C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateApp [On_Demand | Running]) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService [Auto | Running]) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (MCsvc [Auto | Running]) – C:\WINNT\System32\MCSvc.exe (© 2005 - 2008 Siemens AG)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ntrtscan [Auto | Running]) – C:\Program Files\OfficeScan NT\ntrtscan.exe (Trend Micro Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Unknown | Stopped]) – C:\WINNT\system32\HPZipm12.exe (HP)
SRV - (rpcapd [On_Demand | Stopped]) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (Service Launcher [Unknown | Running]) – C:\WINNT\system32\SvcLncher.exe (SIS GO GIO DS PSU6)
SRV - (ServiceLayer [On_Demand | Running]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (softyinforwow1 [Disabled | Stopped]) – C:\WINNT\system32\200924030.dll ()
SRV - (sopidkc [Disabled | Stopped]) – C:\WINNT\system32\sopidkc.exe ()
SRV - (SP Software Installer [Auto | Running]) – C:\Program Files\AccessManager\PMAC\sp_SWIns.exe (Smartpipes, Inc.)
SRV - (sp_spi_da [On_Demand | Stopped]) – C:\Program Files\AccessManager\SMOC\spi_da.exe (Smartpipes, Inc.)
SRV - (STacSV [Auto | Running]) – C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe (SigmaTel, Inc.)
SRV - (SU [Auto | Running]) – C:\WINNT\system32\Suss.exe (Microsoft Corporation)
SRV - (Sygman [Auto | Running]) – C:\Program Files\AccessManager\Client\sygman.exe (MCI, Inc.)
SRV - (tmlisten [Auto | Running]) – C:\Program Files\OfficeScan NT\tmlisten.exe (Trend Micro Inc.)
SRV - (TmPfw [On_Demand | Running]) – C:\Program Files\OfficeScan NT\TmPfw.exe (Trend Micro Inc.)
SRV - (TmProxy [On_Demand | Stopped]) – C:\Program Files\OfficeScan NT\TmProxy.exe (Trend Micro Inc.)
SRV - (wltrysvc [Auto | Running]) – C:\WINNT\System32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (Wuser32 [Unknown | Running]) – C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ApfiltrService [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (CSRBC [On_Demand | Stopped]) – C:\WINNT\System32\Drivers\csrbcxp.sys (CSR, plc)
DRV - (Eacfilt [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\eacfilt.sys (Nortel Networks)
DRV - (el575nd5 [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\el575nd5.sys (3Com Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (idisw2km [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\idisw2km.sys (Microsoft Corporation)
DRV - (iPassP [Auto | Running]) – C:\WINNT\system32\DRIVERS\iPassP.sys (Cisco Systems, Inc.)
DRV - (IPSECEXT [Auto | Stopped]) – C:\WINNT\system32\DRIVERS\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (IPSECSHM [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\ipsecw2k.sys (Nortel Networks NA, Inc.)
DRV - (kbstuff [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\kbstuff5.sys (Microsoft Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINNT\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NbtDet [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\nbtdet.sys (written by © Markus Treinen 2000 - 2005 for Siemens Business Services)
DRV - (nm [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\NMnt.sys (Microsoft Corporation)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINNT\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcdnsu [On_Demand | Stopped]) – C:\WINNT\system32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc [On_Demand | Stopped]) – C:\WINNT\system32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (NPF [Auto | Running]) – C:\WINNT\system32\drivers\npf.sys (CACE Technologies)
DRV - (pccsmcfd [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (pcistub [On_Demand | Stopped]) – C:\WINNT\system32\pcistub.sys ()
DRV - (prepdrvr [On_Demand | Stopped]) – C:\WINNT\system32\CCM\prepdrv.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINNT\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (STHDA [On_Demand | Running]) – C:\WINNT\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (StillCam [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (tmcfw [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINNT\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (TmFilter [Auto | Running]) – C:\Program Files\OfficeScan NT\TmXPFlt.sys (Trend Micro Inc.)
DRV - (TmPreFilter [Auto | Running]) – C:\Program Files\OfficeScan NT\TmPreFlt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINNT\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (toshidpt [On_Demand | Stopped]) – C:\WINNT\system32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosporte [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\tosporte.sys (TOSHIBA Corporation)
DRV - (tosrfbd [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (tosrfbnp [On_Demand | Stopped]) – C:\WINNT\System32\Drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom [System | Running]) – C:\WINNT\System32\Drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfnds [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (upperdev [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (USBCCID [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\usbccid.sys (Microsoft Corporation)
DRV - (usbser [On_Demand | Stopped]) – C:\WINNT\system32\drivers\usbser.sys (Microsoft Corporation)
DRV - (UsbserFilt [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (VSApiNt [Auto | Running]) – C:\Program Files\OfficeScan NT\VSApiNt.sys (Trend Micro Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com/
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

FF - prefs.js..extensions.enabledItems: [removed]:0.7.2
FF - prefs.js..extensions.enabledItems: {83D65D9A-9CCA-439B-9E4A-EC1FE481B443}:[removed]
FF - prefs.js..extensions.enabledItems: {C947A5EF-A041-443B-AE55-4CC7C15A9C9A}:[removed]
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.685
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.4.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.7pre.080917
FF - prefs.js..extensions.enabledItems: ilab@intuit:1.5.1
FF - prefs.js..extensions.enabledItems: {DADCCB2D-0301-478E-811B-C2FF82D7762F}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC [C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\] -> [2009/01/08 18:33:17 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2008/11/26 12:35:51 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINNT\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/02/06 02:50:20 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\NOKIA\OVI MAPS\MOZILLA FIREFOX PLUGIN\XPI [C:\PROGRAM FILES\NOKIA\OVI MAPS\MOZILLA FIREFOX PLUGIN\XPI] -> [2009/02/22 13:22:18 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/02/18 14:51:10 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/02/06 20:58:13 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Extensions [2008/09/18 08:17:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Extensions [2008/09/18 08:17:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/09/18 08:17:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/09/18 08:17:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\eclipse\extensions [2008/10/21 15:40:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\eclipse\extensions [2008/10/21 15:40:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions [2009/02/28 00:04:44 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions [2009/02/28 00:04:44 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} [2009/02/28 00:04:44 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} [2009/02/28 00:04:44 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} [2008/11/22 10:33:54 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} [2008/11/22 10:33:54 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2009/02/08 20:01:54 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9} [2009/02/08 20:01:54 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{dc572301-7619-498c-a57d-39143191b318} [2008/09/18 13:22:18 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\{dc572301-7619-498c-a57d-39143191b318} [2008/09/18 13:22:18 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/12/11 20:33:28 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/12/11 20:33:28 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/09/18 08:32:58 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/09/18 08:32:58 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\ilab@intuit [2008/09/18 08:32:59 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\ilab@intuit [2008/09/18 08:32:59 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/09/28 09:32:25 00,000,000 | —D | M]
FF - C:\Documents and Settings\vm092543\Application Data\mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed] [2008/09/28 09:32:25 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/02/28 00:00:41 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2009/02/28 00:00:41 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/02/06 20:58:07 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/02/06 20:58:07 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2008/09/29 09:38:52 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [2008/09/29 09:38:52 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [2008/11/26 12:36:07 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} [2008/11/26 12:36:07 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/01/23 10:21:27 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [2009/01/23 10:21:27 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{DADCCB2D-0301-478E-811B-C2FF82D7762F} [2009/02/26 23:00:11 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{DADCCB2D-0301-478E-811B-C2FF82D7762F} [2009/02/26 23:00:11 00,000,000 | —D | M]

O1 HOSTS File: (610711 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 a9rhiwa.cn #[Google.Warning]
O1 - Hosts: 127.0.0.1 www.a9rhiwa.cn
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtb19.acecounter.com
O1 - Hosts: 16252 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Copernic Desktop Search - Home Toolbar) - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll (Copernic Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..\Toolbar\WebBrowser: (no name) - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll (Copernic Inc.)
O3 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..\Toolbar\WebBrowser: (no name) - {968631B6-4729-440D-9BF4-251F5593EC9A} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe (MCI, Inc.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe ()
O4 - HKLM..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [MCDesk] %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini File not found
O4 - HKLM..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow (Trend Micro Inc.)
O4 - HKLM..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Synchronization Manager] mobsync.exe /logon (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot (BillP Studios)
O4 - HKLM..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O4 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe" /tray (Copernic Inc.)
O4 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray (Nokia)
O4 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe (AT&T Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Download present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoOnlinePrintsWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: nointernetopenwith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Media = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_PrintPreview = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Media = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_PrintPreview = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnforceShellExtensionSecurity = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Back = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Forward = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Stop = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Refresh = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Home = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_History = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Favorites = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Media = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Folders = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Fullscreen = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Tools = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_MailNews = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Size = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Print = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Edit = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Discussions = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Cut = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Copy = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Paste = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Encoding = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_PrintPreview = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetConnectDisconnect = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConnectHomeDirToRoot = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Download present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Persistence present
O7 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra Button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm ()
O9 - Extra 'Tools' menuitem : Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Sites: abatos.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: acuson.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: adb.be ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: anfdata.cz ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: any4swat.net ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: ardentek.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: atea.be ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: audioservice.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: bbcom-hh.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: cerberus.ch ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: click2procure.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.ae ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.id ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.id ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.il ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.in ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.in ([*.sisl] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.in ([*.spcnl] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.ir ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.jp ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.kr ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.ma ([*.sbs] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.ma ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.nz ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.ro ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.th ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.uk ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.uk ([*.siemenscomms] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.uk ([*.sni] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.yu ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: co.za ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ar ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ar ([*.siemensvdo] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.au ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.bd ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.bh ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.bn ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.br ([*.icotron] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.br ([*.infineon] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.br ([*.osram] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.br ([*.sbt] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.br ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.cn ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.cn ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.co ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ec ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.eg ([*.egti] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.eg ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.hk ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.kw ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.lb ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.mx ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.my ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ng ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.om ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.pe ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ph ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.pk ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.sa ([*.iscosa] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.sa ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.sg ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.sg ([*.siemenswestinghouse] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.tn ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.tr ([*.sbs] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.tr ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.tr ([*.simko] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.tw ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ua ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.uz ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Domains: com.ve ([*.siemens] * is out of zone range - 6)
O15 - HKLM\..Trusted Sites: comneon.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: dell.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: dematic.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: dematic.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: dnb.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: efficient.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: elmo-vacuum.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: emcom.ro ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: empros.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: entex.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: epos-d.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: e-travel.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: eupec.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: eupec.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: e-utile.it ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: fueruns-shop.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: gepas.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: gepas.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: gskv.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: harrisdirect.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: hewitt.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: hewittfs.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: hspkoeln.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: hubspan.net ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: ibmsecu.org ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: imagex.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: ind.br ([*.cvl] * is out of zone range - 6)
O15 - HKLM\..Trusted Sites: infineon.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: infineon.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: italdata.it ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: kordoba.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: landisgyr.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: landisstaefa.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: lanxtra.com ([mfa] * is out of zone range - 6)
O15 - HKLM\..Trusted Sites: microsoft.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Sites: milltronics.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: mobile-travel.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: mobisphere.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: mymeetings.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: my-siemens.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: netautor.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: netglearning.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: nokia.com ([*.ext] * is out of zone range - 6)
O15 - HKLM\..Trusted Sites: nokiasiemensnetworks.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: opentext.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: osram-os.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: osram-os.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: peopleclick.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Sites: placeware.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Sites: presswatch.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: rolm.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: rxs.fr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: salesforce.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sap.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Sites: sap-ag.de ([]* in Trusted sites)
O15 - HKLM\..Trusted Sites: sbi-jena.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbk.org ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.at ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.be ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.com ([]* in Local intranet)
O15 - HKLM\..Trusted Sites: sbs.de ([]* in Local intranet)
O15 - HKLM\..Trusted Sites: sbs.fr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.pl ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.ru ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbs.sk ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbsitalia.it ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sbt.com.br ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sgpvt.at ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: shi.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: shs-online.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sibt.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sicad.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.at ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.be ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.bg ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.ca ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.ch ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.cl ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: siemens.com ([autoconfigie.icm] http is out of zone range - 5)
O15 - HKLM\..Trusted Domains: siemens.com ([mp-reporting.icm] https is out of zone range - 6)
O15 - HKLM\..Trusted Domains: siemens.com ([project] https in Trusted sites)
O15 - HKLM\..Trusted Sites: siemens.cz ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.de ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: siemens.de ([communication-market1] http in Trusted sites)
O15 - HKLM\..Trusted Domains: siemens.de ([csc-sbs.pdb] http is out of zone range - 5)
O15 - HKLM\..Trusted Domains: siemens.de ([icm-km.erlm] http in Trusted sites)
O15 - HKLM\..Trusted Domains: siemens.de ([icm-km1.erlm] http in Trusted sites)
O15 - HKLM\..Trusted Domains: siemens.de ([icm-km2.erlm] http in Trusted sites)
O15 - HKLM\..Trusted Domains: siemens.de ([icm-km3.erlm] http in Trusted sites)
O15 - HKLM\..Trusted Domains: siemens.de ([icm-km4.erlm] http in Trusted sites)
O15 - HKLM\..Trusted Sites: siemens.dk ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.es ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.fi ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.fr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.gr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.hr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.hu ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.ie ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.it ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: siemens.it ([ikuddq.icn] http in Trusted sites)
O15 - HKLM\..Trusted Sites: siemens.kz ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.lt ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.lu ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.net ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: siemens.net ([esp.sip] https is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.nl ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.no ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.pl ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.pt ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.ro ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.ru ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.se ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.si ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.sk ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens.sn ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensauto.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemenscom.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-d-m.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-emis.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensenterprise.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensibc.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensmedical.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-mobile.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-mobile.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemenspro.at ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-psc.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-real-estate.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-sbs.ch ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-scg.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemens-sharenet.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensvdo.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensvdo.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensvdo.fr ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemensvdo.ro ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: siemenswelt.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sietec.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sim-immobilien.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: simit.de ([]* in Local intranet)
O15 - HKLM\..Trusted Sites: sitest.net ([]* in Local intranet)
O15 - HKLM\..Trusted Sites: smsocs.com ([]* in Local intranet)
O15 - HKLM\..Trusted Sites: sni.at ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.fi ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.it ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.nl ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.no ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sni.se ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: s-partners.net ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: spls.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sri.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sri-online.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sta-augsburg.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: swh.sk ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sykatec.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: sysdata.hu ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: teleplan.com ([*.tpw] * is out of zone range - 6)
O15 - HKLM\..Trusted Sites: trangosoft.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: vdogrp.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: vodafone.com ([virtualtrainingroom] * in Trusted sites)
O15 - HKLM\..Trusted Sites: vvk.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: weissgmbh.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: whiteoaksemi.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: wts-ag.de ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Sites: xtremelearning.com ([]* is out of zone range - 6)
O15 - HKLM\..Trusted Domains: 94 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Sites: abatos.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: acuson.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: adb.be ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: anfdata.cz ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: any4swat.net ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: ardentek.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: atea.be ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: audioservice.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: bbcom-hh.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: cerberus.ch ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.ae ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.id ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.id ([*.siemens-hearing] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.il ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.in ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.in ([*.sisl] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.in ([*.spcnl] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.ir ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.jp ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.kr ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.ma ([*.sbs] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.ma ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.nz ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.ro ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.th ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.uk ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.uk ([*.siemenscomms] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.uk ([*.sni] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.yu ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: co.za ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ar ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ar ([*.siemensvdo] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.au ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.bd ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.bh ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.bn ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.br ([*.icotron] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.br ([*.infineon] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.br ([*.osram] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.br ([*.sbt] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.br ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.cn ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.cn ([*.siemens-hearing] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.co ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ec ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.eg ([*.egti] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.eg ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.hk ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.kw ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.lb ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.mx ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.my ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ng ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.om ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.pe ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ph ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.pk ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.sa ([*.iscosa] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.sa ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.sg ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.sg ([*.siemenswestinghouse] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.tn ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.tr ([*.sbs] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.tr ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.tr ([*.simko] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.tw ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ua ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.uz ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: com.ve ([*.siemens] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: comneon.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: dematic.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: dematic.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: efficient.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: elmo-vacuum.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: emcom.ro ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: empros.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: entex.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: epos-d.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: eupec.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: eupec.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: e-utile.it ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: fueruns-shop.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: gepas.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: gepas.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: gskv.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: hspkoeln.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: ind.br ([*.cvl] * in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: infineon.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: infineon.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: italdata.it ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: kordoba.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: landisgyr.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: landisstaefa.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: microsoft.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Sites: milltronics.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: mobile-travel.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: mobisphere.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: my-siemens.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: osram-os.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: osram-os.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: rolm.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: rxs.fr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sap.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Sites: sap-ag.de ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Sites: sbi-jena.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbk.org ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.at ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.be ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.fr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.pl ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.ru ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbs.sk ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sbsitalia.it ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sgpvt.at ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: shs-online.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sibt.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sicad.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.at ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.be ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.bg ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.ca ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.ch ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.cl ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: siemens.com ([autoconfigie.icm] http is out of zone range - 5)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.cz ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.dk ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.es ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.fi ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.fr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.gr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.hr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.hu ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.ie ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.it ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.kz ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.lt ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.lu ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.net ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.nl ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.no ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.pl ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.pt ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.ro ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.ru ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.se ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.si ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.sk ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens.sn ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensauto.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemenscom.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-d-m.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-emis.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensibc.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensmedical.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-mobile.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-mobile.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemenspro.at ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-psc.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-real-estate.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-sbs.ch ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-scg.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemens-sharenet.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensvdo.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensvdo.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensvdo.fr ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemensvdo.ro ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: siemenswelt.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sietec.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sim-immobilien.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: simit.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sitest.net ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: smsocs.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.at ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.fi ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.it ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.no ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sni.se ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: s-partners.net ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: spls.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sri.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sri-online.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sta-augsburg.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: swh.sk ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sykatec.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: sysdata.hu ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: trangosoft.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: vdogrp.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: vvk.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: weissgmbh.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: whiteoaksemi.com ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Sites: wts-ag.de ([]* in Local intranet)
O15 - HKU\.DEFAULT\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Sites: abatos.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: acuson.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: adb.be ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: anfdata.cz ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: any4swat.net ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: ardentek.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: atea.be ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: audioservice.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: bbcom-hh.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: cerberus.ch ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.ae ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.id ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.id ([*.siemens-hearing] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.il ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.in ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.in ([*.sisl] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.in ([*.spcnl] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.ir ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.jp ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.kr ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.ma ([*.sbs] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.ma ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.nz ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.ro ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.th ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.uk ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.uk ([*.siemenscomms] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.uk ([*.sni] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.yu ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: co.za ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ar ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ar ([*.siemensvdo] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.au ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.bd ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.bh ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.bn ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.br ([*.icotron] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.br ([*.infineon] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.br ([*.osram] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.br ([*.sbt] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.br ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.cn ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.cn ([*.siemens-hearing] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.co ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ec ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.eg ([*.egti] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.eg ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.hk ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.kw ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.lb ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.mx ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.my ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ng ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.om ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.pe ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ph ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.pk ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.sa ([*.iscosa] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.sa ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.sg ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.sg ([*.siemenswestinghouse] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.tn ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.tr ([*.sbs] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.tr ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.tr ([*.simko] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.tw ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ua ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.uz ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: com.ve ([*.siemens] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: comneon.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: dematic.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: dematic.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: efficient.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: elmo-vacuum.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: emcom.ro ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: empros.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: entex.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: epos-d.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: eupec.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: eupec.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: e-utile.it ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: fueruns-shop.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: gepas.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: gepas.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: gskv.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: hspkoeln.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: ind.br ([*.cvl] * in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: infineon.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: infineon.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: italdata.it ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: kordoba.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: landisgyr.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: landisstaefa.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Sites: milltronics.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: mobile-travel.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: mobisphere.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: my-siemens.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: osram-os.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: osram-os.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: rolm.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: rxs.fr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sap.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Sites: sap-ag.de ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Sites: sbi-jena.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbk.org ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.at ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.be ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.fr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.pl ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.ru ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbs.sk ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sbsitalia.it ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sgpvt.at ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: shs-online.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sibt.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sicad.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.at ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.be ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.bg ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.ca ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.ch ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.cl ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: siemens.com ([autoconfigie.icm] http is out of zone range - 5)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.cz ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.dk ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.es ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.fi ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.fr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.gr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.hr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.hu ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.ie ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.it ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.kz ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.lt ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.lu ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.net ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.nl ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.no ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.pl ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.pt ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.ro ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.ru ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.se ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.si ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.sk ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens.sn ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensauto.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemenscom.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-d-m.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-emis.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensibc.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensmedical.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-mobile.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-mobile.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemenspro.at ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-psc.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-real-estate.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-sbs.ch ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-scg.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemens-sharenet.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensvdo.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensvdo.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensvdo.fr ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemensvdo.ro ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: siemenswelt.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sietec.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sim-immobilien.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: simit.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sitest.net ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: smsocs.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.at ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.fi ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.it ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.no ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sni.se ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: s-partners.net ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: spls.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sri.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sri-online.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sta-augsburg.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: swh.sk ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sykatec.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: sysdata.hu ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: trangosoft.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: vdogrp.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: vvk.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: weissgmbh.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: whiteoaksemi.com ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Sites: wts-ag.de ([]* in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Sites: abatos.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: acuson.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: adb.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: anfdata.cz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: any4swat.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: ardentek.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: atea.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: audioservice.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: bbcom-hh.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: cerberus.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: click2procure.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.ae ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.id ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.id ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.il ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.in ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.in ([*.sisl] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.in ([*.spcnl] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.ir ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.jp ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.kr ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.ma ([*.sbs] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.ma ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.nz ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.ro ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.th ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.uk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.uk ([*.siemenscomms] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.uk ([*.sni] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.yu ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: co.za ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ar ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ar ([*.siemensvdo] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.au ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.bd ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.bh ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.bn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.br ([*.icotron] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.br ([*.infineon] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.br ([*.osram] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.br ([*.sbt] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.br ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.cn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.cn ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.co ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ec ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.eg ([*.egti] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.eg ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.hk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.kw ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.lb ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.mx ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.my ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ng ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.om ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.pe ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ph ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.pk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.sa ([*.iscosa] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.sa ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.sg ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.sg ([*.siemenswestinghouse] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.tn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.tr ([*.sbs] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.tr ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.tr ([*.simko] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.tw ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ua ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.uz ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: com.ve ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: comneon.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: dell.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: dematic.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: dematic.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: dnb.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: efficient.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: elmo-vacuum.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: emcom.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: empros.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: entex.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: epos-d.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: e-travel.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: eupec.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: eupec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: e-utile.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: fueruns-shop.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: gepas.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: gepas.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: gskv.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: harrisdirect.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: hewitt.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: hewittfs.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: hspkoeln.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: hubspan.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: ibmsecu.org ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: imagex.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: ind.br ([*.cvl] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: infineon.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: infineon.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: italdata.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: kordoba.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: landisgyr.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: landisstaefa.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: lanxtra.com ([mfa] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: milltronics.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: mobile-travel.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: mobisphere.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: mymeetings.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: my-siemens.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: netautor.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: netglearning.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: nokia.com ([*.ext] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: nokiasiemensnetworks.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: opentext.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: osram-os.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: osram-os.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: peopleclick.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: placeware.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: presswatch.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: rolm.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: rxs.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: salesforce.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sap.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: sap-ag.de ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: sbi-jena.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbk.org ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.com ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.de ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.pl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.ru ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbs.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbsitalia.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sbt.com.br ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sgpvt.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: shi.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: shs-online.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sibt.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sicad.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.bg ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.ca ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.cl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.com ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.com ([autoconfigie.icm] http is out of zone range - 5)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.com ([mp-reporting.icm] https is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.com ([project] https in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.cz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.de ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([communication-market1] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([csc-sbs.pdb] http is out of zone range - 5)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([icm-km.erlm] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([icm-km1.erlm] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([icm-km2.erlm] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([icm-km3.erlm] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.de ([icm-km4.erlm] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.dk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.es ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.fi ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.gr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.hr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.hu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.ie ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.it ([ikuddq.icn] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.kz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.lt ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.lu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.net ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Domains: siemens.net ([esp.sip] https is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.nl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.no ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.pl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.pt ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.ru ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.se ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.si ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens.sn ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensauto.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemenscom.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-d-m.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-emis.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensenterprise.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensibc.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensmedical.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-mobile.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-mobile.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemenspro.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-psc.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-real-estate.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-sbs.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-scg.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemens-sharenet.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensvdo.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensvdo.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensvdo.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemensvdo.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: siemenswelt.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sietec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sim-immobilien.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: simit.de ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Sites: sitest.net ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Sites: smsocs.com ([]* in Local intranet)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.fi ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.nl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.no ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sni.se ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: s-partners.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: spls.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sri.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sri-online.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sta-augsburg.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: swh.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sykatec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: sysdata.hu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: teleplan.com ([*.tpw] * is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: trangosoft.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: vdogrp.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: vodafone.com ([virtualtrainingroom] * in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Sites: vvk.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: weissgmbh.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: whiteoaksemi.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: wts-ag.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Sites: xtremelearning.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-19\..Trusted Domains: 47 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: abatos.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: acuson.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: adb.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: anfdata.cz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: any4swat.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: ardentek.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: atea.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: audioservice.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: bbcom-hh.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: cerberus.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: cgintl.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: cgintl.com ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: click2procure.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.ae ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.id ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.id ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.il ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.in ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.in ([*.sisl] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.in ([*.spcnl] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.ir ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.jp ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.kr ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.ma ([*.sbs] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.ma ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.nz ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.ro ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.th ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.uk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.uk ([*.siemenscomms] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.uk ([*.sni] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.yu ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: co.za ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ar ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ar ([*.siemensvdo] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.au ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.bd ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.bh ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.bn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.br ([*.icotron] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.br ([*.infineon] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.br ([*.osram] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.br ([*.sbt] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.br ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.cn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.cn ([*.siemens-hearing] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.co ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ec ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.eg ([*.egti] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.eg ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.hk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.kw ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.lb ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.mx ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.my ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ng ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.om ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.pe ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ph ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.pk ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.sa ([*.iscosa] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.sa ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.sg ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.sg ([*.siemenswestinghouse] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.tn ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.tr ([*.sbs] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.tr ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.tr ([*.simko] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.tw ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ua ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.uz ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: com.ve ([*.siemens] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: comneon.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: dell.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: dematic.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: dematic.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: dnb.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: efficient.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: elmo-vacuum.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: emcom.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: empros.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: entex.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: epos-d.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: e-travel.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: eupec.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: eupec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: e-utile.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: fueruns-shop.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: fujitsupc.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: fujitsupc.com ([*.ebiz] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: gepas.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: gepas.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: gskv.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: harrisdirect.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: hewitt.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: hewittfs.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: hspkoeln.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: hubspan.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: ibmsecu.org ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: imagex.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: ind.br ([*.cvl] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: infineon.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: infineon.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: italdata.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: kordoba.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: landisgyr.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: landisstaefa.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: lanxtra.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: lanxtra.com ([*.mfa] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: lanxtra.com ([mfa] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: milltronics.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: mobile-travel.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: mobisphere.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: mosaic-services.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: mymeetings.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: my-siemens.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: netautor.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: netglearning.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: newark.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: newark.com ([*.secure] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: nokia.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: nokia.com ([*.ext] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: nokiasiemensnetworks.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: nokiasiemensnetworks.com ([*.inside] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: nsn-intra.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: opentext.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: osram-os.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: osram-os.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: pcconnection.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: pcconnection.com ([*.ep] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: pcconnection.com ([*.it] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: peopleclick.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: placeware.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: presswatch.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: rbc.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: rcashasp.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: remedy.com ([]* in Internet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: remedy.com ([*.supportweb] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: rolm.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: rxs.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: salesforce.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sap.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sap-ag.de ([]* in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbi-jena.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbk.org ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.com ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.de ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.pl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.ru ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbs.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbsitalia.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sbt.com.br ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sgpvt.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: shi.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: shs-online.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sibt.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sicad.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.be ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.bg ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.ca ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.cl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.com ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.com ([autoconfigie.icm] http is out of zone range - 5)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.com ([mp-reporting.icm] https is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.com ([project] https in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.cz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.de ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([communication-market1] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([csc-sbs.pdb] http is out of zone range - 5)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([icm-km.erlm] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([icm-km1.erlm] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([icm-km2.erlm] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([icm-km3.erlm] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.de ([icm-km4.erlm] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.dk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.es ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.fi ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.gr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.hr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.hu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.ie ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.it ([ikuddq.icn] http in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.kz ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.lt ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.lu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.net ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: siemens.net ([esp.sip] https is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.nl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.no ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.pl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.pt ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.ru ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.se ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.si ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens.sn ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensauto.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemenscom.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-d-m.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-emis.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensenterprise.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensibc.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensmedical.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-mobile.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-mobile.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemenspro.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-psc.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-real-estate.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-sbs.ch ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-scg.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemens-sharenet.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensvdo.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensvdo.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensvdo.fr ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemensvdo.ro ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: siemenswelt.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sietec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sim-immobilien.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: simit.de ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sitest.net ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: smsocs.com ([]* in Local intranet)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.at ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.fi ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.it ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.nl ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.no ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sni.se ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: s-partners.net ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: spls.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sri.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sri-online.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sta-augsburg.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: swh.sk ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sykatec.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: sysdata.hu ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: teleplan.com ([*.tpw] * is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: trangosoft.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: vdogrp.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: visualwebcaster.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: vodafone.com ([virtualtrainingroom] * in Trusted sites)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: vvk.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: weissgmbh.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: whiteoaksemi.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: wts-ag.de ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Sites: xtremelearning.com ([]* is out of zone range - 6)
O15 - HKU\S-1-5-21-1593251271-2640304127-1825641215-227304\..Trusted Domains: 91 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} http://www.webattend.com/components/wt0523.cab (WebTrain.ctlWebTrain)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230590012390 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1230592905812 (MUWebControl Class)
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab (JNILoader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab (Whale Client Components)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB (Xerox_Services_Portal.XrxPrinter_Inst)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://apertio.webex.com/client/T27L/webex/ieatgpc.cab (GpcContainer Class)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) - C:\WINNT\system32\userinit.exe ()
O20 - HKLM Winlogon: GinaDLL - (amgina.dll) - C:\WINNT\system32\amgina.dll (MCI, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINNT\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Antivirus-ashDisp.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\Antivirus-ashserv.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\Antivirus-ashSimpl.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\avesvc.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\bdmcon.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\bdnagent.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\bdswitch.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O27 - HKLM IFEO\DefWatch.exe: Debugger - C:\WINDOWS\system32\alg.exe File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 0
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINNT\System32\*.tmp files]
[1 C:\WINNT\*.tmp files]
[2009/02/28 13:22:51 | 00,008,192 | —- | C] () – C:\WINNT\System32\srbt.dll
[2009/02/28 13:04:05 | 00,001,740 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\HijackThis.lnk
[2009/02/28 13:04:05 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/28 11:03:09 | 00,000,000 | —D | C] – C:\WINNT\System32\3361
[2009/02/28 11:03:06 | 00,108,336 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MSWINSCK.OCX
[2009/02/28 06:43:14 | 00,000,090 | —- | C] () – C:\WINNT\System32\work.ini
[2009/02/28 05:40:36 | 00,000,227 | —- | C] () – C:\WINNT\System32\hgset.ini
[2009/02/28 05:40:31 | 00,090,112 | —- | C] () – C:\WINNT\System32\200924030.dll
[2009/02/28 05:40:26 | 00,077,824 | —- | C] () – C:\WINNT\System32\u52856226.dll
[2009/02/28 05:40:19 | 00,676,352 | —- | C] (Borland Software Corporation) – C:\WINNT\System32\rtl60.bpl
[2009/02/28 05:40:07 | 00,000,198 | —- | C] () – C:\WINNT\System32\xcchit32.ini
[2009/02/28 05:39:23 | 00,000,600 | —- | C] () – C:\WINNT\xccwinsys.ini
[2009/02/28 05:39:23 | 00,000,000 | —D | C] – C:\WINNT\System32\inf
[2009/02/28 05:39:21 | 00,155,175 | —- | C] () – C:\WINNT\System32\icv.exe
[2009/02/28 05:14:22 | 00,000,529 | —- | C] () – C:\WINNT\System32\winlogon2.exe
[2009/02/28 00:40:20 | 00,000,115 | —- | C] () – C:\WINNT\System32\win32hlp.cnf
[2009/02/28 00:40:06 | 00,000,001 | —- | C] () – C:\WINNT\System32\uniq.tll
[2009/02/26 23:00:10 | 00,047,742 | —- | C] () – C:\WINNT\System32\jkkLBsRl_8ac.VIR
[2009/02/26 13:52:27 | 00,280,064 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\VZ+LTE+Commercialization+Wkshp+Dec6+2007v1.ppt
[2009/02/26 12:55:24 | 02,896,384 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\IMS_Instructions_for_ordering_V1.1_IUS.ppt
[2009/02/26 11:01:43 | 00,000,000 | —D | C] – C:\Documents and Settings\vm092543\Local Settings\Application Data\Copernic
[2009/02/26 08:31:41 | 00,000,000 | —D | C] – C:\Program Files\Sequence Chart Studio
[2009/02/23 21:39:41 | 00,000,000 | —D | C] – C:\Program Files\Psiloc Wireless Presenter Desktop
[2009/02/23 21:23:22 | 00,000,000 | —D | C] – C:\Program Files\Psiloc
[2009/02/22 01:49:37 | 00,151,552 | —- | C] () – C:\Documents and Settings\vm092543\Local Settings\Application Data\filesync.metadata
[2009/02/22 01:47:41 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2009/02/21 22:31:07 | 01,684,791 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\Sinfoni presentations.zip
[2009/02/21 21:16:20 | 09,724,928 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\MGW_Overview_&_Architecture_description.ppt
[2009/02/20 09:43:32 | 00,000,000 | —D | C] – C:\Program Files\Copernic Desktop Search
[2009/02/18 20:20:53 | 00,008,320 | —- | C] (Nokia) – C:\WINNT\System32\drivers\nmwcdnsuc.sys
[2009/02/18 20:20:52 | 00,138,112 | —- | C] (Nokia) – C:\WINNT\System32\drivers\nmwcdnsu.sys
[2009/02/18 13:14:57 | 00,000,000 | -H-D | C] – C:\WINNT\PIF
[2009/02/18 13:12:37 | 00,000,000 | —D | C] – C:\Documents and Settings\vm092543\Application Data\Windows Search
[2009/02/18 13:12:16 | 00,000,000 | —D | C] – C:\Documents and Settings\vm092543\Local Settings\Application Data\Identities
[2009/02/18 13:11:00 | 00,000,000 | —D | C] – C:\Program Files\Windows Desktop Search
[2009/02/16 22:08:47 | 02,931,712 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\IMS-Basic-UserGuide.ppt
[2009/02/12 08:22:31 | 00,821,248 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\DataQ+Service+report+application.ppt
[2009/02/07 14:44:52 | 04,432,896 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\VoIP70_Delta_training_20090128.ppt
[2009/02/07 14:44:37 | 11,596,350 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\CBVoIP_Delta_final.vcm
[2009/02/07 14:43:19 | 02,913,280 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\OSS_for_Core_Migration.ppt
[2009/02/07 14:43:08 | 03,816,960 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\OSS_solution_for_Rel4.ppt
[2009/02/07 14:43:02 | 11,576,328 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\OSS Soln for R4.zip
[2009/02/07 14:40:55 | 07,379,712 | —- | C] () – C:\Documents and Settings\vm092543\Desktop\OSS for Core Migration Plans.zip
[2009/02/06 02:48:04 | 00,000,000 | —D | C] – C:\WINNT\System32\XPSViewer
[2009/02/06 02:47:46 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/02/06 02:47:40 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/02/06 02:46:55 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpssvcs.dll
[2009/02/06 02:46:55 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpssvcs.dll
[2009/02/06 02:46:55 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\printfilterpipelinesvc.exe
[2009/02/06 02:46:55 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\xpsshhdr.dll
[2009/02/06 02:46:55 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\xpsshhdr.dll
[2009/02/06 02:46:55 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\prntvpt.dll
[2009/02/06 02:46:55 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\dllcache\filterpipelineprintproc.dll
[2009/01/30 08:50:47 | 00,000,000 | —D | C] – C:\WINNT\System32\%APPDATA%

========== Files - Modified Within 30 Days ==========

[1 C:\WINNT\System32\*.tmp files]
[1 C:\WINNT\*.tmp files]
[2009/02/28 13:25:20 | 00,000,985 | —- | M] () – C:\WINNT\win.ini
[2009/02/28 13:23:54 | 00,000,115 | —- | M] () – C:\WINNT\System32\win32hlp.cnf
[2009/02/28 13:23:10 | 00,000,424 | —- | M] () – C:\WINNT\SMSCFG.ini
[2009/02/28 13:22:51 | 00,008,192 | —- | M] () – C:\WINNT\System32\srbt.dll
[2009/02/28 13:22:28 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/02/28 13:22:27 | 00,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2009/02/28 13:04:05 | 00,001,740 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\HijackThis.lnk
[2009/02/28 12:29:38 | 00,000,277 | RHS- | M] () – C:\boot.ini
[2009/02/28 12:29:38 | 00,000,254 | —- | M] () – C:\WINNT\system.ini
[2009/02/28 12:27:04 | 00,000,600 | —- | M] () – C:\WINNT\xccwinsys.ini
[2009/02/28 12:02:44 | 00,000,198 | —- | M] () – C:\WINNT\System32\xcchit32.ini
[2009/02/28 11:12:19 | 00,000,938 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
[2009/02/28 11:03:07 | 00,108,336 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\MSWINSCK.OCX
[2009/02/28 10:43:13 | 00,000,227 | —- | M] () – C:\WINNT\System32\hgset.ini
[2009/02/28 10:43:13 | 00,000,090 | —- | M] () – C:\WINNT\System32\work.ini
[2009/02/28 05:59:28 | 00,000,529 | —- | M] () – C:\WINNT\System32\winlogon2.exe
[2009/02/28 05:40:31 | 00,090,112 | —- | M] () – C:\WINNT\System32\200924030.dll
[2009/02/28 05:40:27 | 00,077,824 | —- | M] () – C:\WINNT\System32\u52856226.dll
[2009/02/28 05:39:23 | 00,155,175 | —- | M] () – C:\WINNT\System32\icv.exe
[2009/02/28 00:40:09 | 00,104,960 | —- | M] () – C:\WINNT\System32\userinit.exe
[2009/02/28 00:40:09 | 00,104,960 | —- | M] () – C:\WINNT\System32\dllcache\userinit.exe
[2009/02/28 00:40:06 | 00,000,001 | —- | M] () – C:\WINNT\System32\uniq.tll
[2009/02/27 23:29:07 | 02,896,384 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\IMS_Instructions_for_ordering_V1.1_IUS.ppt
[2009/02/27 23:18:31 | 00,014,715 | —- | M] () – C:\WINNT\cfgall.ini
[2009/02/27 22:30:01 | 00,000,600 | —- | M] () – C:\Documents and Settings\vm092543\Application Data\winscp.rnd
[2009/02/26 23:00:10 | 00,047,742 | —- | M] () – C:\WINNT\System32\jkkLBsRl_8ac.VIR
[2009/02/26 13:52:30 | 00,280,064 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\VZ+LTE+Commercialization+Wkshp+Dec6+2007v1.ppt
[2009/02/26 10:55:00 | 00,002,206 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2009/02/23 21:37:55 | 00,000,097 | —- | M] () – C:\WINNT\WirelessFTP.INI
[2009/02/22 01:49:37 | 00,151,552 | —- | M] () – C:\Documents and Settings\vm092543\Local Settings\Application Data\filesync.metadata
[2009/02/21 23:11:01 | 00,000,284 | —- | M] () – C:\WINNT\tasks\AppleSoftwareUpdate.job
[2009/02/21 22:31:07 | 01,684,791 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\Sinfoni presentations.zip
[2009/02/21 21:19:23 | 09,724,928 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\MGW_Overview_&_Architecture_description.ppt
[2009/02/20 09:40:29 | 00,440,032 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2009/02/20 09:40:29 | 00,070,650 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2009/02/19 12:17:10 | 00,389,120 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\Meeting Minutes.doc
[2009/02/18 13:11:17 | 00,001,809 | —- | M] () – C:\WINNT\imsins.BAK
[2009/02/18 13:11:07 | 00,541,988 | —- | M] () – C:\WINNT\System32\PerfStringBackup.INI
[2009/02/16 22:09:38 | 02,931,712 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\IMS-Basic-UserGuide.ppt
[2009/02/12 08:22:48 | 00,821,248 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\DataQ+Service+report+application.ppt
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINNT\System32\drivers\mbam.sys
[2009/02/11 01:29:44 | 00,610,711 | —- | M] () – C:\WINNT\System32\drivers\etc\HOSTS
[2009/02/08 20:33:44 | 00,000,069 | —- | M] () – C:\WINNT\NeroDigital.ini
[2009/02/08 20:33:38 | 00,028,672 | —- | M] () – C:\Documents and Settings\vm092543\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/07 14:48:12 | 11,596,350 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\CBVoIP_Delta_final.vcm
[2009/02/07 14:46:28 | 11,576,328 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\OSS Soln for R4.zip
[2009/02/07 14:46:03 | 04,432,896 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\VoIP70_Delta_training_20090128.ppt
[2009/02/07 14:44:20 | 03,816,960 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\OSS_solution_for_Rel4.ppt
[2009/02/07 14:44:16 | 02,913,280 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\OSS_for_Core_Migration.ppt
[2009/02/07 14:42:49 | 07,379,712 | —- | M] () – C:\Documents and Settings\vm092543\Desktop\OSS for Core Migration Plans.zip
[2009/02/06 20:15:18 | 00,205,712 | —- | M] () – C:\WINNT\System32\FNTCACHE.DAT
[2009/02/06 09:32:24 | 00,047,144 | —- | M] () – C:\Documents and Settings\vm092543\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

========== LOP Check ==========

[2008/10/21 15:36:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data
[2008/05/13 08:58:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2008/05/13 09:00:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\HP
[2007/09/26 13:54:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Identities
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Lotus
[2008/06/19 08:27:42 | 00,000,000 | –SD | M] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2008/12/17 20:26:28 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/17 20:27:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007/10/05 23:55:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/10/31 07:54:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Altova
[2008/04/05 11:37:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/08/03 01:30:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007/10/06 18:06:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2008/07/15 17:41:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/01/23 07:27:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/02/16 18:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2009/02/18 20:20:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/01/27 16:06:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iPass
[2008/10/21 15:34:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lotus
[2008/12/09 13:45:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/20 09:40:37 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/12/03 22:07:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2008/07/13 01:00:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/02/28 13:23:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/04/05 11:42:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SqueezeCenter
[2008/07/06 19:29:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/10/05 23:39:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/10/21 15:36:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\CCFCliSvcAcct&\Application Data
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\CCFCliSvcAcct&\Application Data\Lotus
[2007/09/26 16:04:21 | 00,000,000 | –SD | M] – C:\Documents and Settings\CCFCliSvcAcct&\Application Data\Microsoft
[2008/10/21 15:36:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Default User\Application Data
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Lotus
[2007/09/26 14:58:33 | 00,000,000 | –SD | M] – C:\Documents and Settings\Default User\Application Data\Microsoft
[2008/10/21 15:36:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\instboca00\Application Data
[2007/09/27 08:17:08 | 00,000,000 | —D | M] – C:\Documents and Settings\instboca00\Application Data\Identities
[2007/09/27 08:33:16 | 00,000,000 | —D | M] – C:\Documents and Settings\instboca00\Application Data\InstallShield
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\instboca00\Application Data\Lotus
[2007/09/27 08:23:53 | 00,000,000 | –SD | M] – C:\Documents and Settings\instboca00\Application Data\Microsoft
[2007/09/27 08:18:36 | 00,000,000 | —D | M] – C:\Documents and Settings\instboca00\Application Data\Sun
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data
[2008/05/13 23:20:10 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Identities
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Lotus
[2007/09/26 14:59:06 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/08/01 08:09:51 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Lotus
[2007/09/26 13:53:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\SMSCCMBootAcct&\Application Data
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\SMSCCMBootAcct&\Application Data\Lotus
[2008/10/21 15:36:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\SMSCliSvcAcct&\Application Data
[2008/10/21 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\SMSCliSvcAcct&\Application Data\Lotus
[2007/09/26 14:58:33 | 00,000,000 | –SD | M] – C:\Documents and Settings\SMSCliSvcAcct&\Application Data\Microsoft
[2009/02/20 09:40:37 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data
[2009/02/27 14:03:26 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\.purple
[2008/01/25 22:20:34 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Adobe
[2008/07/31 21:02:24 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Ahead
[2008/08/03 01:30:06 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Apple Computer
[2007/10/15 08:04:55 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\CatPC
[2009/02/20 09:43:09 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Copernic
[2009/01/08 12:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Creative
[2009/01/29 20:53:58 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\dvdcss
[2008/03/15 18:43:29 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\GSplit
[2008/11/12 15:00:30 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Helios
[2007/10/09 09:18:18 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\HP
[2007/09/27 08:45:20 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\InstallShield
[2007/11/17 17:41:17 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\InterVideo
[2008/11/14 22:12:26 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Interwise
[2008/12/02 16:34:41 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\iPass
[2008/02/28 14:28:12 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Kensington
[2008/09/25 22:13:39 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Lavasoft
[2008/10/21 15:32:47 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Lotus
[2008/02/29 20:42:37 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Macromedia
[2008/12/09 13:46:01 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Malwarebytes
[2007/11/15 15:11:30 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\MathWorks
[2009/02/16 13:57:56 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Microsoft
[2008/12/11 17:43:28 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Move Networks
[2008/10/21 15:40:55 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Mozilla
[2008/07/24 13:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\MySpace
[2009/02/23 20:35:52 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Nokia
[2008/12/11 15:41:30 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\PC Suite
[2009/02/27 18:45:02 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\RipIt4Me
[2007/09/26 16:04:37 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Sun
[2008/11/02 00:32:14 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\uTorrent
[2008/01/28 19:31:45 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\VanDyke
[2008/07/08 21:30:03 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\vlc
[2009/02/25 20:56:12 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\webex
[2009/02/18 13:12:37 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Windows Search
[2008/12/11 00:10:13 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\WinPatrol
[2007/12/07 15:39:33 | 00,000,000 | —D | M] – C:\Documents and Settings\vm092543\Application Data\Wireshark
[2009/02/21 23:11:01 | 00,000,284 | —- | M] () – C:\WINNT\Tasks\AppleSoftwareUpdate.job
[2001/08/23 07:00:00 | 00,000,065 | RH– | M] () – C:\WINNT\Tasks\desktop.ini
[2009/02/28 11:12:19 | 00,000,938 | —- | M] () – C:\WINNT\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
[2009/02/28 13:22:28 | 00,000,006 | -H– | M] () – C:\WINNT\Tasks\SA.DAT

========== Purity Check ==========

< End of report >


HJTLog
======
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:33:48 PM, on 2/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\AB3FA4.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINNT\system32\msiexec.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\WINNT\Explorer.EXE
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\igfxsrvc.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\WinPatrol\winpatrol.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINNT\Managed\MCDesk.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINNT\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconf.glb.nsn-net.net/proxy.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [MCDesk] %MgmtFolder%\MCDesk.exe %MgmtFolder%\MCDesk.ini
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe" /tray
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.placeware.com
O15 - Trusted Zone: *.sap-ag.de
O15 - Trusted Zone: *.sap.com
O15 - Trusted Zone: http://communication-market1.siemens.de
O15 - Trusted Zone: http://icm-km.erlm.siemens.de
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de
O15 - Trusted Zone: http://ikuddq.icn.siemens.it
O15 - Trusted Zone: virtualtrainingroom.vodafone.com
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.placeware.com (HKLM)
O15 - Trusted Zone: *.sap-ag.de (HKLM)
O15 - Trusted Zone: *.sap.com (HKLM)
O15 - Trusted Zone: http://communication-market1.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://ikuddq.icn.siemens.it (HKLM)
O15 - Trusted Zone: virtualtrainingroom.vodafone.com (HKLM)
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webattend.com/components/wt0523.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1230590012390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230592905812
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://apertio.webex.com/client/T27L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: eBOSS Helper (eBOSS) - Nortel Networks - (no file)
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE

–
End of file - 16480 bytes
Hi calvin_hobbes,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk,

Many thanks for investigating my problem. Please find below the JavaRa and ComboFix log as requested.

JavaRa Log
==========
JavaRa 1.13 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Thu Mar 05 07:51:58 2009

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: C:\Program Files\Java\jre1.6.0_04

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_04.b12\

————————————

Finished reporting.


ComboFix Log
============
ComboFix 09-03-04.01 - vm092543 2009-03-05 7:59:42.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2242 [GMT -5:00]
Running from: d:\data\Downloads\Malware Removal\ComboFix.exe
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated)
FW: Trend Micro Personal Firewall *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\winnt\Install.txt
c:\winnt\system32\inf\rundll33.exe
c:\winnt\system32\init32.exe
c:\winnt\system32\uniq.tll
c:\winnt\system32\win32hlp.cnf
c:\winnt\system32\winlogon2.exe
c:\winnt\system32\xcchit32.ini
c:\winnt\xccwinsys.ini

—– BITS: Possible infected sites —–

hxxp://USRTSMO001.nsn-intra.net:80
c:\winnt\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_6TO4
——-\Legacy_AFISICX
——-\Legacy_DEFAULTLIB
——-\Legacy_MABIDWE
——-\Legacy_SOFTYINFORWOW1
——-\Service_6to4
——-\Service_seneka
——-\Service_softyinforwow1


((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.

2009-03-05 08:06 . 2009-03-05 08:06 8,192 –a—— c:\winnt\system32\srbt.dll
2009-02-28 13:04 . 2009-02-28 13:04 d——– c:\program files\Trend Micro
2009-02-28 11:03 . 2009-02-28 12:24 d——– c:\winnt\system32\3361
2009-02-28 11:03 . 2009-02-28 11:03 108,336 –a—— c:\winnt\system32\MSWINSCK.OCX
2009-02-28 06:43 . 2009-02-28 10:43 90 –a—— c:\winnt\system32\work.ini
2009-02-28 05:40 . 2002-02-15 14:02 676,352 –a—— c:\winnt\system32\rtl60.bpl
2009-02-28 05:40 . 2009-02-28 05:40 90,240 –a—— c:\winnt\system32\200924030_232c.VIR
2009-02-28 05:40 . 2009-02-28 05:40 77,952 –a—— c:\winnt\system32\U52856226_2348.VIR
2009-02-28 05:40 . 2009-02-28 10:43 227 –a—— c:\winnt\system32\hgset.ini
2009-02-28 05:39 . 2009-03-05 08:01 d——– c:\winnt\system32\inf
2009-02-28 05:39 . 2009-02-28 05:39 155,175 –a—— c:\winnt\system32\icv.exe
2009-02-26 23:00 . 2009-02-26 23:00 47,742 –a—— c:\winnt\system32\jkkLBsRl_8ac.VIR
2009-02-26 08:31 . 2009-02-26 08:31 d——– c:\program files\Sequence Chart Studio
2009-02-23 21:39 . 2009-02-23 21:43 d——– c:\program files\Psiloc Wireless Presenter Desktop
2009-02-23 21:23 . 2009-02-23 21:26 d——– c:\program files\Psiloc
2009-02-22 01:47 . 2009-02-22 01:47 d——– c:\program files\Microsoft Sync Framework
2009-02-20 09:43 . 2009-02-20 09:43 d——– c:\program files\Copernic Desktop Search
2009-02-18 20:20 . 2008-02-01 15:17 138,112 –a—— c:\winnt\system32\drivers\nmwcdnsu.sys
2009-02-18 20:20 . 2008-02-01 15:17 8,320 –a—— c:\winnt\system32\drivers\nmwcdnsuc.sys
2009-02-18 13:14 . 2009-02-18 13:14 d–h—– c:\winnt\PIF
2009-02-18 13:12 . 2009-02-18 13:12 d——– c:\documents and settings\vm092543\Application Data\Windows Search
2009-02-18 13:11 . 2009-02-20 13:29 d——– c:\program files\Windows Desktop Search
2009-02-06 02:48 . 2009-02-06 02:48 d——– c:\winnt\system32\XPSViewer
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\Reference Assemblies
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\MSBuild
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 ——— c:\winnt\system32\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 —–c— c:\winnt\system32\dllcache\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 05:50 597,504 —–c— c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-02-06 02:46 . 2008-07-06 07:06 575,488 ——— c:\winnt\system32\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 575,488 —–c— c:\winnt\system32\dllcache\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 117,760 ——— c:\winnt\system32\prntvpt.dll
2009-02-06 02:46 . 2008-07-06 07:06 89,088 —–c— c:\winnt\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 13:08 ——— d—–w c:\program files\OfficeScan NT
2009-03-05 12:56 ——— d—–w c:\documents and settings\vm092543\Application Data\.purple
2009-03-05 12:52 ——— d—–w c:\program files\Java
2009-03-05 12:46 ——— d—–w c:\program files\IP VPN Remote Services
2009-03-04 14:49 ——— d—–w c:\documents and settings\vm092543\Application Data\webex
2009-02-28 18:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-28 18:22 ——— d—–w c:\program files\Spybot
2009-02-28 17:28 ——— d—–w c:\program files\Malwarebytes
2009-02-28 00:44 ——— d—–w c:\program files\Password Safe
2009-02-27 23:45 ——— d—–w c:\documents and settings\vm092543\Application Data\RipIt4Me
2009-02-25 05:41 ——— d—–w c:\program files\Migration
2009-02-24 01:35 ——— d—–w c:\documents and settings\vm092543\Application Data\Nokia
2009-02-22 18:22 ——— d—–w c:\program files\NOKIA
2009-02-22 06:48 ——— d—–w c:\program files\SyncToy
2009-02-20 14:43 ——— d—–w c:\documents and settings\vm092543\Application Data\Copernic
2009-02-19 01:20 ——— d—–w c:\program files\Common Files\Nokia
2009-02-19 01:20 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-02-13 14:28 ——— d—–w c:\program files\MCollect
2009-02-11 15:19 38,496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-01-30 01:53 ——— d—–w c:\documents and settings\vm092543\Application Data\dvdcss
2009-01-27 21:06 ——— d—–w c:\documents and settings\All Users\Application Data\iPass
2009-01-24 02:42 ——— d—–w c:\program files\Pidgin
2009-01-24 02:42 ——— d—–w c:\program files\Aspell
2009-01-24 02:38 ——— d—–w c:\program files\Common Files\GTK
2009-01-23 12:27 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 09:12 142,992 —-a-w c:\winnt\system32\drivers\tmcomm.sys
2009-01-15 09:11 76,304 —-a-w c:\winnt\system32\drivers\tmtdi.sys
2009-01-15 09:11 338,448 —-a-w c:\winnt\system32\drivers\TM_CFW.sys
2009-01-15 00:06 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 17:45 ——— d—–w c:\program files\WebEx
2009-01-08 23:33 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-08 23:32 ——— d—–w c:\program files\PC Connectivity Solution
2009-01-08 23:26 ——— d—–w c:\program files\Creative
2009-01-08 23:21 ——— d—–w c:\program files\BlackBerry Connect Desktop for Nokia
2009-01-08 17:04 ——— d—–w c:\documents and settings\vm092543\Application Data\Creative
2009-01-06 00:50 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-19 18:02 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-11-19 18:02 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-11-19 18:03 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-11-19 18:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2005-04-26 13:48 57,344 —-a-w c:\program files\internet explorer\plugins\PluginWrapper.dll
.

——- Sigcheck ——-

2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\userinit.exe
2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-03 15360]
"Google Update"="c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-01-26 2144088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search\DesktopSearchService.exe" [2008-12-11 1588224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\OfficeScan NT\pccntmon.exe" [2009-01-15 718120]
"WinZip Quick Pick"="c:\program files\WinZip\WZQKPICK.EXE" [2004-03-04 106560]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\winnt\system32\igfxpers.exe" [2007-05-16 138008]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-08-05 786432]
"Broadcom Wireless Manager UI"="c:\winnt\system32\WLTRAY.exe" [2007-03-16 1392640]
"CoolSwitch"="c:\winnt\system32\taskswitch.exe" [2002-03-19 45632]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Synchronization Manager"="mobsync.exe" [2004-08-03 c:\winnt\system32\mobsync.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\winnt\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-05-09 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-09-27 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Push Client.LNK - c:\program files\interwise\Participant\pull.exe [2008-11-14 886000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoThumbnailCache"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=CBEShutdown.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addlocaladm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
"Script"=EnfAdminV3.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1060284298-1450960922-725345543-500\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\1\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\0\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\1\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-136749\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-55867\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\winnt\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\winnt\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^xccstart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\xccstart.lnk
backup=c:\winnt\pss\xccstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vm092543^Start Menu^Programs^Startup^Infotriever.lnk]
path=c:\documents and settings\vm092543\Start Menu\Programs\Startup\Infotriever.lnk
backup=c:\winnt\pss\Infotriever.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-10-08 09:00 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2006-10-09 10:28 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DirXconnect settings]
–a—— 2000-03-21 08:39 106561 c:\progra~1\Siemens\DIRXDI~1\dxdSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIECACST]
–a—— 2006-10-05 10:18 69632 c:\program files\Siemens\Card API\bin\siecacst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Firefly Media Server"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%systemroot%\\PCHEALTH\\HELPCTR\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
"24881:TCP"= 24881:TCP:Trend Micro OfficeScan Listener

R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [2004-08-05 77824]
R2 MCsvc;Managed Client Service;c:\winnt\system32\MCSvc.exe [2008-09-15 69632]
R2 NPF;NetGroup Packet Filter Driver;c:\winnt\system32\drivers\npf.sys [2007-06-28 42512]
R2 Service Launcher;Service Launcher;c:\winnt\system32\SvcLncher.exe [2008-03-06 229376]
R2 SU;SU Service;c:\winnt\system32\Suss.exe [2007-09-26 12048]
R2 Sygman;SSA Integration Manager;c:\program files\AccessManager\Client\sygman.exe [2004-08-05 126976]
R2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\tmxpflt.sys [2006-09-06 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\tmpreflt.sys [2006-09-06 36368]
R3 Eacfilt;Eacfilt Miniport;c:\winnt\system32\drivers\eacfilt.sys [2007-09-27 9817]
R3 tmcfw;Trend Micro Common Firewall Service;c:\winnt\system32\drivers\TM_CFW.sys [2006-12-22 338448]
R3 TmPfw;OfficeScanNT Personal Firewall;c:\program files\OfficeScan NT\TmPfw.exe [2008-05-13 488768]
S2 eBOSS;eBOSS Helper; [x]
S2 HTTP Poster;HTTP Poster Service;c:\winnt\system32\HTTP_Poster.exe [2008-10-21 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\winnt\system32\drivers\ipsecw2k.sys [2007-09-27 117760]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-08-05 81920]
S3 DMService;Whale Component Manager;c:\winnt\DOWNLO~1\DMService.exe [2008-08-07 423576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\winnt\system32\drivers\el575ND5.sys [2007-09-26 69692]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\IP VPN Remote Services\Extranet_serv.exe [2007-09-27 643072]
S3 NbtDet;NetBoot PCI Detection Service;c:\winnt\system32\drivers\nbtdet.sys [2008-09-15 4992]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\winnt\system32\drivers\nmwcdnsu.sys [2009-02-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\winnt\system32\drivers\nmwcdnsuc.sys [2009-02-18 8320]
S3 pcistub;pcistub;c:\winnt\system32\pcistub.sys [2007-09-26 2176]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [2003-04-17 81920]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\OfficeScan NT\TmProxy.exe [2008-05-13 652552]
S4 sopidkc;sopidkc Service;c:\winnt\system32\sopidkc.exe –> c:\winnt\system32\sopidkc.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
c:\winnt\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}]
c:\winnt\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
.
Contents of the 'Scheduled Tasks' folder

2009-02-22 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-04 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
- c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:48]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MCDesk - %MgmtFolder%\MCDesk.exe
MSConfigStartUp-FireflyShell - c:\program files\Firefly Media Server\FireflyShell.exe


.
——- Supplementary Scan ——-
.
uStart Page = https://inside.nokiasiemensnetworks.com
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Edit with Altova X&MLSpy - c:\program files\Altova\XMLSpy2008\spy.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} - hxxp://www.webattend.com/components/wt0523.cab
DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} - hxxps://xesp-nsnst004.inside.nokiasiemensnetworks.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} - hxxps://office.services.xerox.com/XeroxServicesManager/UI/FindPrinter/PrnInst/Xerox_Services_Portal_Pref.CAB
FF - ProfilePath - c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\
FF - component: c:\program files\Copernic Desktop Search\FirefoxConnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\Copernic Desktop Search\Toolbar\FirefoxContainer\components\CCLCXPCOMBridge.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Nokia\Ovi maps\Mozilla Firefox plugin\XPI\plugins\npNMapG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 08:07:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\eBOSS]
"ImagePath"=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1688)
c:\winnt\system32\amgina.dll
c:\winnt\system32\amginar.dll
.
———————— Other Running Processes ————————
.
c:\winnt\system32\WLTRYSVC.EXE
c:\winnt\system32\BCMWLTRY.EXE
c:\winnt\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\OfficeScan NT\NTRtScan.exe
c:\program files\AccessManager\PMAC\sp_SWIns.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\program files\OfficeScan NT\TmListen.exe
c:\winnt\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\winnt\system32\CCM\CcmExec.exe
c:\winnt\Temp\UE8FFD.EXE
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\winnt\system32\msiexec.exe
c:\winnt\system32\igfxsrvc.exe
c:\winnt\Managed\MCDesk.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\OfficeScan NT\CNTAoSMgr.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclToBTSrv.exe
c:\winnt\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2009-03-05 8:14:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-05 13:14:19

Pre-Run: 4,499,984,384 bytes free
Post-Run: 4,572,659,712 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
440
calvin_hobbes,

Well. You've got a rather eclectic bunch of garbage on there. Porn dialers, email worms, trojans, game password stealers, etc. There appear to have many custom scripts having to do with online chatting including some that appear to give others access to your computer while in chat rooms. Some of these appear to facilitate file transfer, some literally can turn control of your computer over to someone else. Some just appear to hide open ports from your firewall. To me, all of that sounds pretty scary when it also appears that you have your computer store your passwords. The scenario that scares me is that it appears that you could log into a chat room and someone else would be able to take control of your computer. It further appears that they could simply download the file where you have stored your passwords. I suggest that you take the following warning very seriously:

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\winnt\system32\srbt.dll
    c:\winnt\system32\200924030_232c.VIR
    c:\winnt\system32\U52856226_2348.VIR
    c:\winnt\system32\hgset.ini
    c:\winnt\system32\icv.exe
    c:\winnt\system32\jkkLBsRl_8ac.VIR
    c:\winnt\system32\pcistub.sys
    c:\winnt\system32\sopidkc.exe
    
    Driver::
    eBOSS
    pcistub
    sopidkc
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Next

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tomk,

Thanks for the warning and heads-up. Eclectic it is indeed. I used to frequent yahoo chat rooms, perhaps that is where i caught these trojans from. Nonetheless, i have decided NOT to reformat the computer at this time. I will however, using an uninfected computer, change passwords on all my accounts. Please find, as requested, logs from ComboFix + Kapersky

ComboFix
========
ComboFix 09-03-04.01 - vm092543 2009-03-05 10:31:26.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2201 [GMT -5:00]
Running from: d:\data\Downloads\Malware Removal\ComboFix.exe
Command switches used :: d:\data\Downloads\Malware Removal\CFScript.txt
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point

FILE ::
c:\winnt\system32\200924030_232c.VIR
c:\winnt\system32\hgset.ini
c:\winnt\system32\icv.exe
c:\winnt\system32\jkkLBsRl_8ac.VIR
c:\winnt\system32\pcistub.sys
c:\winnt\system32\sopidkc.exe
c:\winnt\system32\srbt.dll
c:\winnt\system32\U52856226_2348.VIR
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\winnt\system32\200924030_232c.VIR
c:\winnt\system32\hgset.ini
c:\winnt\system32\icv.exe
c:\winnt\system32\jkkLBsRl_8ac.VIR
c:\winnt\system32\pcistub.sys
c:\winnt\system32\srbt.dll
c:\winnt\system32\U52856226_2348.VIR

—– BITS: Possible infected sites —–

hxxp://USRTSMO001.nsn-intra.net:80
c:\winnt\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_EBOSS
——-\Legacy_PCISTUB
——-\Legacy_SOPIDKC
——-\Service_eBOSS
——-\Service_pcistub
——-\Service_sopidkc


((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.

2009-02-28 13:04 . 2009-02-28 13:04 d——– c:\program files\Trend Micro
2009-02-28 11:03 . 2009-02-28 12:24 d——– c:\winnt\system32\3361
2009-02-28 11:03 . 2009-02-28 11:03 108,336 –a—— c:\winnt\system32\MSWINSCK.OCX
2009-02-28 06:43 . 2009-02-28 10:43 90 –a—— c:\winnt\system32\work.ini
2009-02-28 05:40 . 2002-02-15 14:02 676,352 –a—— c:\winnt\system32\rtl60.bpl
2009-02-28 05:39 . 2009-03-05 08:01 d——– c:\winnt\system32\inf
2009-02-26 08:31 . 2009-02-26 08:31 d——– c:\program files\Sequence Chart Studio
2009-02-23 21:39 . 2009-02-23 21:43 d——– c:\program files\Psiloc Wireless Presenter Desktop
2009-02-23 21:23 . 2009-02-23 21:26 d——– c:\program files\Psiloc
2009-02-22 01:47 . 2009-02-22 01:47 d——– c:\program files\Microsoft Sync Framework
2009-02-20 09:43 . 2009-02-20 09:43 d——– c:\program files\Copernic Desktop Search
2009-02-18 20:20 . 2008-02-01 15:17 138,112 –a—— c:\winnt\system32\drivers\nmwcdnsu.sys
2009-02-18 20:20 . 2008-02-01 15:17 8,320 –a—— c:\winnt\system32\drivers\nmwcdnsuc.sys
2009-02-18 13:14 . 2009-02-18 13:14 d–h—– c:\winnt\PIF
2009-02-18 13:12 . 2009-02-18 13:12 d——– c:\documents and settings\vm092543\Application Data\Windows Search
2009-02-18 13:11 . 2009-02-20 13:29 d——– c:\program files\Windows Desktop Search
2009-02-06 02:48 . 2009-02-06 02:48 d——– c:\winnt\system32\XPSViewer
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\Reference Assemblies
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\MSBuild
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 ——— c:\winnt\system32\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 —–c— c:\winnt\system32\dllcache\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 05:50 597,504 —–c— c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-02-06 02:46 . 2008-07-06 07:06 575,488 ——— c:\winnt\system32\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 575,488 —–c— c:\winnt\system32\dllcache\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 117,760 ——— c:\winnt\system32\prntvpt.dll
2009-02-06 02:46 . 2008-07-06 07:06 89,088 —–c— c:\winnt\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 15:36 ——— d—–w c:\program files\OfficeScan NT
2009-03-05 13:16 ——— d—–w c:\program files\IP VPN Remote Services
2009-03-05 12:56 ——— d—–w c:\documents and settings\vm092543\Application Data\.purple
2009-03-05 12:52 ——— d—–w c:\program files\Java
2009-03-04 14:49 ——— d—–w c:\documents and settings\vm092543\Application Data\webex
2009-02-28 18:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-28 18:22 ——— d—–w c:\program files\Spybot
2009-02-28 17:28 ——— d—–w c:\program files\Malwarebytes
2009-02-28 00:44 ——— d—–w c:\program files\Password Safe
2009-02-27 23:45 ——— d—–w c:\documents and settings\vm092543\Application Data\RipIt4Me
2009-02-25 05:41 ——— d—–w c:\program files\Migration
2009-02-24 01:35 ——— d—–w c:\documents and settings\vm092543\Application Data\Nokia
2009-02-22 18:22 ——— d—–w c:\program files\NOKIA
2009-02-22 06:48 ——— d—–w c:\program files\SyncToy
2009-02-20 14:43 ——— d—–w c:\documents and settings\vm092543\Application Data\Copernic
2009-02-19 01:20 ——— d—–w c:\program files\Common Files\Nokia
2009-02-19 01:20 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-02-13 14:28 ——— d—–w c:\program files\MCollect
2009-02-11 15:19 38,496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-01-30 01:53 ——— d—–w c:\documents and settings\vm092543\Application Data\dvdcss
2009-01-27 21:06 ——— d—–w c:\documents and settings\All Users\Application Data\iPass
2009-01-24 02:42 ——— d—–w c:\program files\Pidgin
2009-01-24 02:42 ——— d—–w c:\program files\Aspell
2009-01-24 02:38 ——— d—–w c:\program files\Common Files\GTK
2009-01-23 12:27 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 09:12 142,992 —-a-w c:\winnt\system32\drivers\tmcomm.sys
2009-01-15 09:11 76,304 —-a-w c:\winnt\system32\drivers\tmtdi.sys
2009-01-15 09:11 338,448 —-a-w c:\winnt\system32\drivers\TM_CFW.sys
2009-01-15 00:06 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 17:45 ——— d—–w c:\program files\WebEx
2009-01-08 23:33 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-08 23:32 ——— d—–w c:\program files\PC Connectivity Solution
2009-01-08 23:26 ——— d—–w c:\program files\Creative
2009-01-08 23:21 ——— d—–w c:\program files\BlackBerry Connect Desktop for Nokia
2009-01-08 17:04 ——— d—–w c:\documents and settings\vm092543\Application Data\Creative
2009-01-06 00:50 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-19 18:02 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-11-19 18:02 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-11-19 18:03 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-11-19 18:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2005-04-26 13:48 57,344 —-a-w c:\program files\internet explorer\plugins\PluginWrapper.dll
.

——- Sigcheck ——-

2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\userinit.exe
2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_ 8.13.07.90 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-05 13:05:48 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
+ 2009-03-05 15:34:24 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
+ 2009-03-05 15:35:31 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_71c.dat
+ 2009-01-15 09:12:02 296,224 —-a-w c:\winnt\Temp\WZ13FC.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-03 15360]
"Google Update"="c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-01-26 2144088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search\DesktopSearchService.exe" [2008-12-11 1588224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\OfficeScan NT\pccntmon.exe" [2009-01-15 718120]
"WinZip Quick Pick"="c:\program files\WinZip\WZQKPICK.EXE" [2004-03-04 106560]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\winnt\system32\igfxpers.exe" [2007-05-16 138008]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-08-05 786432]
"Broadcom Wireless Manager UI"="c:\winnt\system32\WLTRAY.exe" [2007-03-16 1392640]
"CoolSwitch"="c:\winnt\system32\taskswitch.exe" [2002-03-19 45632]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Synchronization Manager"="mobsync.exe" [2004-08-03 c:\winnt\system32\mobsync.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\winnt\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-05-09 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-09-27 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Push Client.LNK - c:\program files\interwise\Participant\pull.exe [2008-11-14 886000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoThumbnailCache"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=CBEShutdown.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addlocaladm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
"Script"=EnfAdminV3.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1060284298-1450960922-725345543-500\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\1\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\0\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\1\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-136749\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-55867\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\winnt\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\winnt\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^xccstart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\xccstart.lnk
backup=c:\winnt\pss\xccstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vm092543^Start Menu^Programs^Startup^Infotriever.lnk]
path=c:\documents and settings\vm092543\Start Menu\Programs\Startup\Infotriever.lnk
backup=c:\winnt\pss\Infotriever.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-10-08 09:00 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2006-10-09 10:28 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DirXconnect settings]
–a—— 2000-03-21 08:39 106561 c:\progra~1\Siemens\DIRXDI~1\dxdSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIECACST]
–a—— 2006-10-05 10:18 69632 c:\program files\Siemens\Card API\bin\siecacst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Firefly Media Server"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%systemroot%\\PCHEALTH\\HELPCTR\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
"24881:TCP"= 24881:TCP:Trend Micro OfficeScan Listener

R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [2004-08-05 77824]
R2 MCsvc;Managed Client Service;c:\winnt\system32\MCSvc.exe [2008-09-15 69632]
R2 NPF;NetGroup Packet Filter Driver;c:\winnt\system32\drivers\npf.sys [2007-06-28 42512]
R2 Service Launcher;Service Launcher;c:\winnt\system32\SvcLncher.exe [2008-03-06 229376]
R2 SU;SU Service;c:\winnt\system32\Suss.exe [2007-09-26 12048]
R2 Sygman;SSA Integration Manager;c:\program files\AccessManager\Client\sygman.exe [2004-08-05 126976]
R2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\tmxpflt.sys [2006-09-06 205328]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\tmpreflt.sys [2006-09-06 36368]
R3 Eacfilt;Eacfilt Miniport;c:\winnt\system32\drivers\eacfilt.sys [2007-09-27 9817]
R3 tmcfw;Trend Micro Common Firewall Service;c:\winnt\system32\drivers\TM_CFW.sys [2006-12-22 338448]
R3 TmPfw;OfficeScanNT Personal Firewall;c:\program files\OfficeScan NT\TmPfw.exe [2008-05-13 488768]
S2 HTTP Poster;HTTP Poster Service;c:\winnt\system32\HTTP_Poster.exe [2008-10-21 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\winnt\system32\drivers\ipsecw2k.sys [2007-09-27 117760]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-08-05 81920]
S3 DMService;Whale Component Manager;c:\winnt\DOWNLO~1\DMService.exe [2008-08-07 423576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\winnt\system32\drivers\el575ND5.sys [2007-09-26 69692]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\IP VPN Remote Services\Extranet_serv.exe [2007-09-27 643072]
S3 NbtDet;NetBoot PCI Detection Service;c:\winnt\system32\drivers\nbtdet.sys [2008-09-15 4992]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\winnt\system32\drivers\nmwcdnsu.sys [2009-02-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\winnt\system32\drivers\nmwcdnsuc.sys [2009-02-18 8320]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [2003-04-17 81920]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\OfficeScan NT\TmProxy.exe [2008-05-13 652552]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
c:\winnt\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}]
c:\winnt\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
.
Contents of the 'Scheduled Tasks' folder

2009-02-22 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-04 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
- c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:48]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://inside.nokiasiemensnetworks.com
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Edit with Altova X&MLSpy; - c:\program files\Altova\XMLSpy2008\spy.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} - hxxp://www.webattend.com/components/wt0523.cab
DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} - hxxps://xesp-nsnst004.inside.nokiasiemensnetworks.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} - hxxps://office.services.xerox.com/XeroxServicesManager/UI/FindPrinter/PrnInst/Xerox_Services_Portal_Pref.CAB
FF - ProfilePath - c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\
FF - prefs.js: network.proxy.http - usbocdns01.rt.nsn-intra.net
FF - prefs.js: network.proxy.http_port - 81
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Copernic Desktop Search\FirefoxConnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\Copernic Desktop Search\Toolbar\FirefoxContainer\components\CCLCXPCOMBridge.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Nokia\Ovi maps\Mozilla Firefox plugin\XPI\plugins\npNMapG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 10:35:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1692)
c:\winnt\system32\amgina.dll
c:\winnt\system32\amginar.dll
.
———————— Other Running Processes ————————
.
c:\winnt\system32\WLTRYSVC.EXE
c:\winnt\system32\BCMWLTRY.EXE
c:\winnt\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\OfficeScan NT\NTRtScan.exe
c:\program files\AccessManager\PMAC\sp_SWIns.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\program files\OfficeScan NT\TmListen.exe
c:\winnt\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\winnt\system32\CCM\CcmExec.exe
c:\winnt\Temp\WZ13FC.EXE
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\winnt\system32\msiexec.exe
c:\winnt\system32\igfxsrvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\program files\OfficeScan NT\CNTAoSMgr.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclToBTSrv.exe
c:\winnt\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2009-03-05 10:41:58 - machine was rebooted [vm092543]
ComboFix-quarantined-files.txt 2009-03-05 15:41:54

Pre-Run: 4,431,196,160 bytes free
Post-Run: 4,411,154,432 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
443


Kaspersky Log
============
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, March 5, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, March 05, 2009 15:56:48
Records in database: 1870933
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 72692
Threat name: 10
Infected objects: 13
Suspicious objects: 0
Duration of the scan: 05:25:02


File name / Threat name / Threats count
C:\CF1 Customer Files\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.e 1
C:\Program Files\emwprof\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.1101 1
C:\Qoobox\Quarantine\C\WINNT\system32\200924030_232c.VIR.vir Infected: Trojan-GameThief.Win32.WOW.fqh 1
C:\Qoobox\Quarantine\C\WINNT\system32\jkkLBsRl_8ac.VIR.vir Infected: Trojan.Win32.Monderb.alcl 1
C:\Qoobox\Quarantine\C\WINNT\system32\U52856226_2348.VIR.vir Infected: Trojan-GameThief.Win32.OnLineGames.bkvv 1
C:\WINNT\Installer\255ea.msi Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\WINNT\Installer\255fc.msi Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3DD0Y4RA\chinappi[1]_18bc.VIR Infected: Trojan-GameThief.Win32.WOW.fqg 1
C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR Infected: Trojan.Win32.Agent.bsud 2
C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR Infected: Trojan.Win32.Agent2.eng 1
C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR Infected: Trojan.Win32.Agent2.enz 1
C:\WINNT\system32\SOPIDKC_640.VIR Infected: Trojan.Win32.Agent2.enz 1

The scan was stopped by the user.

Note, i stopped the scan while it was searching through my data drive (D:). No programs are installed on this drive, just documents like .ppt, .doc etc.
calvin_hobbes,

A few more password stealers. You can tell from the names that a couple of them target WOW accounts.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\WINNT\Installer\255ea.msi
    C:\WINNT\Installer\255fc.msi
    C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3DD0Y4RA\chinappi[1]_18bc.VIR
    C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR
    C:\WINNT\system32\SOPIDKC_640.VIR
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Also please provide a new HijackThis log.
Tomk,

Thanks once again for the prompt reply. Please find below the requested information.

ComboFix Log (didn't reboot this time around)
============
ComboFix 09-03-04.01 - vm092543 2009-03-05 20:37:58.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2228 [GMT -5:00]
Running from: d:\data\Downloads\Malware Removal\ComboFix.exe
Command switches used :: d:\data\Downloads\Malware Removal\CFScript.txt
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point

FILE ::
c:\winnt\Installer\255ea.msi
c:\winnt\Installer\255fc.msi
c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3DD0Y4RA\chinappi[1]_18bc.VIR
c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR
c:\winnt\system32\SOPIDKC_640.VIR
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\winnt\Installer\255ea.msi
c:\winnt\Installer\255fc.msi
c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3DD0Y4RA\chinappi[1]_18bc.VIR
c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR
c:\winnt\system32\SOPIDKC_640.VIR

—– BITS: Possible infected sites —–

hxxp://USRTSMO001.nsn-intra.net:80
c:\winnt\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-02-28 13:04 . 2009-02-28 13:04 d——– c:\program files\Trend Micro
2009-02-28 11:03 . 2009-02-28 12:24 d——– c:\winnt\system32\3361
2009-02-28 11:03 . 2009-02-28 11:03 108,336 –a—— c:\winnt\system32\MSWINSCK.OCX
2009-02-28 06:43 . 2009-02-28 10:43 90 –a—— c:\winnt\system32\work.ini
2009-02-28 05:40 . 2002-02-15 14:02 676,352 –a—— c:\winnt\system32\rtl60.bpl
2009-02-28 05:39 . 2009-03-05 08:01 d——– c:\winnt\system32\inf
2009-02-26 08:31 . 2009-02-26 08:31 d——– c:\program files\Sequence Chart Studio
2009-02-23 21:39 . 2009-02-23 21:43 d——– c:\program files\Psiloc Wireless Presenter Desktop
2009-02-23 21:23 . 2009-02-23 21:26 d——– c:\program files\Psiloc
2009-02-22 01:47 . 2009-02-22 01:47 d——– c:\program files\Microsoft Sync Framework
2009-02-20 09:43 . 2009-02-20 09:43 d——– c:\program files\Copernic Desktop Search
2009-02-18 20:20 . 2008-02-01 15:17 138,112 –a—— c:\winnt\system32\drivers\nmwcdnsu.sys
2009-02-18 20:20 . 2008-02-01 15:17 8,320 –a—— c:\winnt\system32\drivers\nmwcdnsuc.sys
2009-02-18 13:14 . 2009-02-18 13:14 d–h—– c:\winnt\PIF
2009-02-18 13:12 . 2009-02-18 13:12 d——– c:\documents and settings\vm092543\Application Data\Windows Search
2009-02-18 13:11 . 2009-02-20 13:29 d——– c:\program files\Windows Desktop Search
2009-02-06 02:48 . 2009-02-06 02:48 d——– c:\winnt\system32\XPSViewer
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\Reference Assemblies
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\MSBuild
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 ——— c:\winnt\system32\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 —–c— c:\winnt\system32\dllcache\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 05:50 597,504 —–c— c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-02-06 02:46 . 2008-07-06 07:06 575,488 ——— c:\winnt\system32\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 575,488 —–c— c:\winnt\system32\dllcache\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 117,760 ——— c:\winnt\system32\prntvpt.dll
2009-02-06 02:46 . 2008-07-06 07:06 89,088 —–c— c:\winnt\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 01:36 ——— d—–w c:\program files\OfficeScan NT
2009-03-06 01:00 ——— d—–w c:\program files\Password Safe
2009-03-05 21:44 ——— d—–w c:\program files\IP VPN Remote Services
2009-03-05 17:23 ——— d—–w c:\documents and settings\vm092543\Application Data\RipIt4Me
2009-03-05 12:56 ——— d—–w c:\documents and settings\vm092543\Application Data\.purple
2009-03-05 12:52 ——— d—–w c:\program files\Java
2009-03-04 14:49 ——— d—–w c:\documents and settings\vm092543\Application Data\webex
2009-03-02 14:03 206,848 —-a-w c:\winnt\system32\SetupSvc.exe
2009-02-28 18:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-28 18:22 ——— d—–w c:\program files\Spybot
2009-02-28 17:28 ——— d—–w c:\program files\Malwarebytes
2009-02-28 05:40 104,960 —-a-w c:\winnt\system32\userinit.exe
2009-02-26 01:21 229,376 —-a-w c:\winnt\system32\SvcLncher.exe
2009-02-25 05:41 ——— d—–w c:\program files\Migration
2009-02-24 01:35 ——— d—–w c:\documents and settings\vm092543\Application Data\Nokia
2009-02-22 18:22 ——— d—–w c:\program files\NOKIA
2009-02-22 06:48 ——— d—–w c:\program files\SyncToy
2009-02-20 14:43 ——— d—–w c:\documents and settings\vm092543\Application Data\Copernic
2009-02-19 01:20 ——— d—–w c:\program files\Common Files\Nokia
2009-02-19 01:20 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-02-13 14:28 ——— d—–w c:\program files\MCollect
2009-02-11 15:19 38,496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-01-30 01:53 ——— d—–w c:\documents and settings\vm092543\Application Data\dvdcss
2009-01-27 21:06 ——— d—–w c:\documents and settings\All Users\Application Data\iPass
2009-01-24 02:42 ——— d—–w c:\program files\Pidgin
2009-01-24 02:42 ——— d—–w c:\program files\Aspell
2009-01-24 02:38 ——— d—–w c:\program files\Common Files\GTK
2009-01-23 12:27 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 09:12 142,992 —-a-w c:\winnt\system32\drivers\tmcomm.sys
2009-01-15 09:11 76,304 —-a-w c:\winnt\system32\drivers\tmtdi.sys
2009-01-15 09:11 338,448 —-a-w c:\winnt\system32\drivers\TM_CFW.sys
2009-01-15 00:06 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 17:45 ——— d—–w c:\program files\WebEx
2009-01-08 23:33 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-08 23:32 ——— d—–w c:\program files\PC Connectivity Solution
2009-01-08 23:26 ——— d—–w c:\program files\Creative
2009-01-08 23:21 ——— d—–w c:\program files\BlackBerry Connect Desktop for Nokia
2009-01-08 17:04 ——— d—–w c:\documents and settings\vm092543\Application Data\Creative
2009-01-06 00:50 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-19 18:02 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-11-19 18:02 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-11-19 18:03 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-11-19 18:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2005-04-26 13:48 57,344 —-a-w c:\program files\internet explorer\plugins\PluginWrapper.dll
.

——- Sigcheck ——-

2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\userinit.exe
2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_ 8.13.07.90 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-05 13:05:48 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
+ 2009-03-05 15:34:24 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-03 15360]
"Google Update"="c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-01-26 2144088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search\DesktopSearchService.exe" [2008-12-11 1588224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\OfficeScan NT\pccntmon.exe" [2009-01-15 718120]
"WinZip Quick Pick"="c:\program files\WinZip\WZQKPICK.EXE" [2004-03-04 106560]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\winnt\system32\igfxpers.exe" [2007-05-16 138008]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-08-05 786432]
"Broadcom Wireless Manager UI"="c:\winnt\system32\WLTRAY.exe" [2007-03-16 1392640]
"CoolSwitch"="c:\winnt\system32\taskswitch.exe" [2002-03-19 45632]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Synchronization Manager"="mobsync.exe" [2004-08-03 c:\winnt\system32\mobsync.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\winnt\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-05-09 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-09-27 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Push Client.LNK - c:\program files\interwise\Participant\pull.exe [2008-11-14 886000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoThumbnailCache"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=CBEShutdown.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addlocaladm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
"Script"=EnfAdminV3.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1060284298-1450960922-725345543-500\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\1\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\0\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\1\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-136749\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-55867\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\winnt\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\winnt\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^xccstart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\xccstart.lnk
backup=c:\winnt\pss\xccstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vm092543^Start Menu^Programs^Startup^Infotriever.lnk]
path=c:\documents and settings\vm092543\Start Menu\Programs\Startup\Infotriever.lnk
backup=c:\winnt\pss\Infotriever.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-10-08 09:00 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2006-10-09 10:28 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DirXconnect settings]
–a—— 2000-03-21 08:39 106561 c:\progra~1\Siemens\DIRXDI~1\dxdSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIECACST]
–a—— 2006-10-05 10:18 69632 c:\program files\Siemens\Card API\bin\siecacst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Firefly Media Server"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%systemroot%\\PCHEALTH\\HELPCTR\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)

R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [2004-08-05 77824]
R2 MCsvc;Managed Client Service;c:\winnt\system32\MCSvc.exe [2008-09-15 69632]
R2 NPF;NetGroup Packet Filter Driver;c:\winnt\system32\drivers\npf.sys [2007-06-28 42512]
R2 Service Launcher;Service Launcher;c:\winnt\system32\SvcLncher.exe [2008-03-06 229376]
R2 SU;SU Service;c:\winnt\system32\Suss.exe [2007-09-26 12048]
R2 Sygman;SSA Integration Manager;c:\program files\AccessManager\Client\sygman.exe [2004-08-05 126976]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\tmpreflt.sys [2006-09-06 36368]
R3 Eacfilt;Eacfilt Miniport;c:\winnt\system32\drivers\eacfilt.sys [2007-09-27 9817]
R3 tmcfw;Trend Micro Common Firewall Service;c:\winnt\system32\drivers\TM_CFW.sys [2006-12-22 338448]
S2 HTTP Poster;HTTP Poster Service;c:\winnt\system32\HTTP_Poster.exe [2008-10-21 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\winnt\system32\drivers\ipsecw2k.sys [2007-09-27 117760]
S2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\tmxpflt.sys [2006-09-06 205328]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-08-05 81920]
S3 DMService;Whale Component Manager;c:\winnt\DOWNLO~1\DMService.exe [2008-08-07 423576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\winnt\system32\drivers\el575ND5.sys [2007-09-26 69692]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\IP VPN Remote Services\Extranet_serv.exe [2007-09-27 643072]
S3 NbtDet;NetBoot PCI Detection Service;c:\winnt\system32\drivers\nbtdet.sys [2008-09-15 4992]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\winnt\system32\drivers\nmwcdnsu.sys [2009-02-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\winnt\system32\drivers\nmwcdnsuc.sys [2009-02-18 8320]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [2003-04-17 81920]
S3 TmPfw;OfficeScanNT Personal Firewall;c:\program files\OfficeScan NT\TmPfw.exe [2008-05-13 488768]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\OfficeScan NT\TmProxy.exe [2008-05-13 652552]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
c:\winnt\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}]
c:\winnt\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
.
Contents of the 'Scheduled Tasks' folder

2009-02-22 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-05 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
- c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:48]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://inside.nokiasiemensnetworks.com
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Edit with Altova X&MLSpy - c:\program files\Altova\XMLSpy2008\spy.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} - hxxp://www.webattend.com/components/wt0523.cab
DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} - hxxps://xesp-nsnst004.inside.nokiasiemensnetworks.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} - hxxps://office.services.xerox.com/XeroxServicesManager/UI/FindPrinter/PrnInst/Xerox_Services_Portal_Pref.CAB
FF - ProfilePath - c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\
FF - component: c:\program files\Copernic Desktop Search\FirefoxConnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\Copernic Desktop Search\Toolbar\FirefoxContainer\components\CCLCXPCOMBridge.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Nokia\Ovi maps\Mozilla Firefox plugin\XPI\plugins\npNMapG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 20:40:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1692)
c:\winnt\system32\amgina.dll
c:\winnt\system32\amginar.dll
c:\winnt\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1748)
c:\program files\Bonjour\mdnsNSP.dll
.
Completion time: 2009-03-05 20:43:41
ComboFix-quarantined-files.txt 2009-03-06 01:42:48

Pre-Run: 4,357,259,264 bytes free
Post-Run: 4,397,809,664 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
391


Rooter Log
========
Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel® Core™2 Duo CPU T7100 @ 1.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
USER : vm092543 ( Not Administrator ! )
BOOT : Normal boot

Antivirus : Trend Micro OfficeScan Antivirus 8.0 (Not Activated)
Firewall : Trend Micro Personal Firewall 5.3 (Not Activated)

C:\ (Local Disk) - NTFS - Total:19 Go (Free:4 Go)
D:\ (Local Disk) - NTFS - Total:54 Go (Free:6 Go)
E:\ (CD or DVD)

2009-03-05|20:56

———————-\\ Search..

———————-\\ ROOTKIT !!

Rootkit Seneka ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\seneka]


1 - "C:\Rooter$\Rooter_1.txt" - 2009-03-05|20:57

———————-\\ Scan completed at 20:57


HJT
====
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:58, on 2009-03-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxsrvc.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\WINNT\system32\HPZinw12.exe
C:\Program Files\MCollect\MPCMon.exe
C:\PROGRA~1\COPERN~2\DESKTO~1.EXE
C:\Program Files\Password Safe\pwsafe.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconf.glb.nsn-net.net/proxy.pac
F2 - REG:system.ini: UserInit=C:\WINNT\explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe" /tray
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.placeware.com
O15 - Trusted Zone: *.sap-ag.de
O15 - Trusted Zone: *.sap.com
O15 - Trusted Zone: http://communication-market1.siemens.de
O15 - Trusted Zone: http://icm-km.erlm.siemens.de
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de
O15 - Trusted Zone: http://ikuddq.icn.siemens.it
O15 - Trusted Zone: virtualtrainingroom.vodafone.com
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.placeware.com (HKLM)
O15 - Trusted Zone: *.sap-ag.de (HKLM)
O15 - Trusted Zone: *.sap.com (HKLM)
O15 - Trusted Zone: http://communication-market1.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://ikuddq.icn.siemens.it (HKLM)
O15 - Trusted Zone: virtualtrainingroom.vodafone.com (HKLM)
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webattend.com/components/wt0523.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1230590012390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230592905812
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://apertio.webex.com/client/T27L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = nsn-intra.net
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE

–
End of file - 15883 bytes


The interesting part is that prior to submitting the original log to you, i had scanned my laptop w/ F-secure blacklight rootkit detection software but nothing had turned up!
calvin_hobbes,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    DDS::
    IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\seneka]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Next

AVENGER

  • Download The Avenger by Swandog46 from here.
  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that both the box next to Scan for rootkits and the box next to Automatically disable any rootkits found both have ticks in them.
  • Click the Execute button.
  • You will be asked No script has been entered. Do you want to execute a rootkit scan only?.
  • Click Yes.
  • You will now be asked First step completed — The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If The Avenger finds a hidden rootkit driver, then The Avenger will require two reboots to complete its operation.
  • If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
  • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
  • Please post this log, along with a new HijackThis log in your next reply.
Hi Tomk,

Thanks once again for the prompt reply. Please find the requested logs

ComboFix
========
ComboFix 09-03-04.01 - vm092543 2009-03-06 8:15:52.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2033 [GMT -5:00]
Running from: d:\data\Downloads\Malware Removal\ComboFix.exe
Command switches used :: d:\data\Downloads\Malware Removal\CFScript.txt
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\winnt\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-03-06 08:02 . 2009-03-06 08:02 8,192 –a—— c:\winnt\system32\srbt.dll
2009-03-05 20:56 . 2009-03-05 20:57 d——– C:\Rooter$
2009-02-28 13:04 . 2009-02-28 13:04 d——– c:\program files\Trend Micro
2009-02-28 11:03 . 2009-02-28 12:24 d——– c:\winnt\system32\3361
2009-02-28 11:03 . 2009-02-28 11:03 108,336 –a—— c:\winnt\system32\MSWINSCK.OCX
2009-02-28 06:43 . 2009-02-28 10:43 90 –a—— c:\winnt\system32\work.ini
2009-02-28 05:40 . 2002-02-15 14:02 676,352 –a—— c:\winnt\system32\rtl60.bpl
2009-02-28 05:39 . 2009-03-05 08:01 d——– c:\winnt\system32\inf
2009-02-26 08:31 . 2009-02-26 08:31 d——– c:\program files\Sequence Chart Studio
2009-02-23 21:39 . 2009-02-23 21:43 d——– c:\program files\Psiloc Wireless Presenter Desktop
2009-02-23 21:23 . 2009-02-23 21:26 d——– c:\program files\Psiloc
2009-02-22 01:47 . 2009-02-22 01:47 d——– c:\program files\Microsoft Sync Framework
2009-02-20 09:43 . 2009-02-20 09:43 d——– c:\program files\Copernic Desktop Search
2009-02-18 20:20 . 2008-02-01 15:17 138,112 –a—— c:\winnt\system32\drivers\nmwcdnsu.sys
2009-02-18 20:20 . 2008-02-01 15:17 8,320 –a—— c:\winnt\system32\drivers\nmwcdnsuc.sys
2009-02-18 13:14 . 2009-02-18 13:14 d–h—– c:\winnt\PIF
2009-02-18 13:12 . 2009-02-18 13:12 d——– c:\documents and settings\vm092543\Application Data\Windows Search
2009-02-18 13:11 . 2009-02-20 13:29 d——– c:\program files\Windows Desktop Search
2009-02-06 02:48 . 2009-02-06 02:48 d——– c:\winnt\system32\XPSViewer
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\Reference Assemblies
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\MSBuild
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 ——— c:\winnt\system32\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 —–c— c:\winnt\system32\dllcache\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 05:50 597,504 —–c— c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-02-06 02:46 . 2008-07-06 07:06 575,488 ——— c:\winnt\system32\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 575,488 —–c— c:\winnt\system32\dllcache\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 117,760 ——— c:\winnt\system32\prntvpt.dll
2009-02-06 02:46 . 2008-07-06 07:06 89,088 —–c— c:\winnt\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 13:14 ——— d—–w c:\program files\OfficeScan NT
2009-03-06 02:02 ——— d—–w c:\program files\IP VPN Remote Services
2009-03-06 01:00 ——— d—–w c:\program files\Password Safe
2009-03-05 17:23 ——— d—–w c:\documents and settings\vm092543\Application Data\RipIt4Me
2009-03-05 12:56 ——— d—–w c:\documents and settings\vm092543\Application Data\.purple
2009-03-05 12:52 ——— d—–w c:\program files\Java
2009-03-04 14:49 ——— d—–w c:\documents and settings\vm092543\Application Data\webex
2009-03-02 14:03 206,848 —-a-w c:\winnt\system32\SetupSvc.exe
2009-02-28 18:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-28 18:22 ——— d—–w c:\program files\Spybot
2009-02-28 17:28 ——— d—–w c:\program files\Malwarebytes
2009-02-28 05:40 104,960 —-a-w c:\winnt\system32\userinit.exe
2009-02-26 01:21 229,376 —-a-w c:\winnt\system32\SvcLncher.exe
2009-02-25 05:41 ——— d—–w c:\program files\Migration
2009-02-24 01:35 ——— d—–w c:\documents and settings\vm092543\Application Data\Nokia
2009-02-22 18:22 ——— d—–w c:\program files\NOKIA
2009-02-22 06:48 ——— d—–w c:\program files\SyncToy
2009-02-20 14:43 ——— d—–w c:\documents and settings\vm092543\Application Data\Copernic
2009-02-19 01:20 ——— d—–w c:\program files\Common Files\Nokia
2009-02-19 01:20 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-02-13 14:28 ——— d—–w c:\program files\MCollect
2009-02-11 15:19 38,496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-01-30 01:53 ——— d—–w c:\documents and settings\vm092543\Application Data\dvdcss
2009-01-27 21:06 ——— d—–w c:\documents and settings\All Users\Application Data\iPass
2009-01-24 02:42 ——— d—–w c:\program files\Pidgin
2009-01-24 02:42 ——— d—–w c:\program files\Aspell
2009-01-24 02:38 ——— d—–w c:\program files\Common Files\GTK
2009-01-23 12:27 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 09:12 142,992 —-a-w c:\winnt\system32\drivers\tmcomm.sys
2009-01-15 09:11 76,304 —-a-w c:\winnt\system32\drivers\tmtdi.sys
2009-01-15 09:11 338,448 —-a-w c:\winnt\system32\drivers\TM_CFW.sys
2009-01-15 00:06 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 17:45 ——— d—–w c:\program files\WebEx
2009-01-08 23:33 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-08 23:32 ——— d—–w c:\program files\PC Connectivity Solution
2009-01-08 23:26 ——— d—–w c:\program files\Creative
2009-01-08 23:21 ——— d—–w c:\program files\BlackBerry Connect Desktop for Nokia
2009-01-08 17:04 ——— d—–w c:\documents and settings\vm092543\Application Data\Creative
2009-01-06 00:50 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-19 18:02 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-11-19 18:02 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-11-19 18:03 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-11-19 18:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2005-04-26 13:48 57,344 —-a-w c:\program files\internet explorer\plugins\PluginWrapper.dll
.

——- Sigcheck ——-

2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\userinit.exe
2009-02-28 00:40 104960 567bb443315b1d533f41f02bbf9c4413 c:\winnt\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_ 8.13.07.90 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-06 13:15:24 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_1a60.dat
- 2009-03-05 13:05:48 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
+ 2009-03-05 15:34:24 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_570.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-03 15360]
"Google Update"="c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-01-26 2144088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search\DesktopSearchService.exe" [2008-12-11 1588224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\OfficeScan NT\pccntmon.exe" [2009-01-15 718120]
"WinZip Quick Pick"="c:\program files\WinZip\WZQKPICK.EXE" [2004-03-04 106560]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\winnt\system32\igfxpers.exe" [2007-05-16 138008]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-08-05 786432]
"Broadcom Wireless Manager UI"="c:\winnt\system32\WLTRAY.exe" [2007-03-16 1392640]
"CoolSwitch"="c:\winnt\system32\taskswitch.exe" [2002-03-19 45632]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Synchronization Manager"="mobsync.exe" [2004-08-03 c:\winnt\system32\mobsync.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\winnt\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-05-09 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-09-27 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Push Client.LNK - c:\program files\interwise\Participant\pull.exe [2008-11-14 886000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoThumbnailCache"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\winnt\explorer.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=CBEShutdown.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addlocaladm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
"Script"=EnfAdminV3.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1060284298-1450960922-725345543-500\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\1\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\0\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\1\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-136749\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-55867\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\winnt\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\winnt\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^xccstart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\xccstart.lnk
backup=c:\winnt\pss\xccstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vm092543^Start Menu^Programs^Startup^Infotriever.lnk]
path=c:\documents and settings\vm092543\Start Menu\Programs\Startup\Infotriever.lnk
backup=c:\winnt\pss\Infotriever.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-10-08 09:00 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2006-10-09 10:28 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DirXconnect settings]
–a—— 2000-03-21 08:39 106561 c:\progra~1\Siemens\DIRXDI~1\dxdSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIECACST]
–a—— 2006-10-05 10:18 69632 c:\program files\Siemens\Card API\bin\siecacst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Firefly Media Server"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%systemroot%\\PCHEALTH\\HELPCTR\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)

R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [2004-08-05 77824]
R2 MCsvc;Managed Client Service;c:\winnt\system32\MCSvc.exe [2008-09-15 69632]
R2 NPF;NetGroup Packet Filter Driver;c:\winnt\system32\drivers\npf.sys [2007-06-28 42512]
R2 Service Launcher;Service Launcher;c:\winnt\system32\SvcLncher.exe [2008-03-06 229376]
R2 SU;SU Service;c:\winnt\system32\Suss.exe [2007-09-26 12048]
R2 Sygman;SSA Integration Manager;c:\program files\AccessManager\Client\sygman.exe [2004-08-05 126976]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\tmpreflt.sys [2006-09-06 36368]
R3 Eacfilt;Eacfilt Miniport;c:\winnt\system32\drivers\eacfilt.sys [2007-09-27 9817]
R3 tmcfw;Trend Micro Common Firewall Service;c:\winnt\system32\drivers\TM_CFW.sys [2006-12-22 338448]
S2 HTTP Poster;HTTP Poster Service;c:\winnt\system32\HTTP_Poster.exe [2008-10-21 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\winnt\system32\drivers\ipsecw2k.sys [2007-09-27 117760]
S2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\tmxpflt.sys [2006-09-06 205328]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-08-05 81920]
S3 DMService;Whale Component Manager;c:\winnt\DOWNLO~1\DMService.exe [2008-08-07 423576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\winnt\system32\drivers\el575ND5.sys [2007-09-26 69692]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\IP VPN Remote Services\Extranet_serv.exe [2007-09-27 643072]
S3 NbtDet;NetBoot PCI Detection Service;c:\winnt\system32\drivers\nbtdet.sys [2008-09-15 4992]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\winnt\system32\drivers\nmwcdnsu.sys [2009-02-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\winnt\system32\drivers\nmwcdnsuc.sys [2009-02-18 8320]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [2003-04-17 81920]
S3 TmPfw;OfficeScanNT Personal Firewall;c:\program files\OfficeScan NT\TmPfw.exe [2008-05-13 488768]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\OfficeScan NT\TmProxy.exe [2008-05-13 652552]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
c:\winnt\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}]
c:\winnt\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
.
Contents of the 'Scheduled Tasks' folder

2009-02-22 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-06 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
- c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:48]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://inside.nokiasiemensnetworks.com
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Edit with Altova X&MLSpy - c:\program files\Altova\XMLSpy2008\spy.htm
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} - hxxp://www.webattend.com/components/wt0523.cab
DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} - hxxps://xesp-nsnst004.inside.nokiasiemensnetworks.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} - hxxps://office.services.xerox.com/XeroxServicesManager/UI/FindPrinter/PrnInst/Xerox_Services_Portal_Pref.CAB
FF - ProfilePath - c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\
FF - component: c:\program files\Copernic Desktop Search\FirefoxConnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\Copernic Desktop Search\Toolbar\FirefoxContainer\components\CCLCXPCOMBridge.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Nokia\Ovi maps\Mozilla Firefox plugin\XPI\plugins\npNMapG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 08:17:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1692)
c:\winnt\system32\amgina.dll
c:\winnt\system32\amginar.dll
c:\winnt\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1748)
c:\program files\Bonjour\mdnsNSP.dll
.
Completion time: 2009-03-06 8:19:58
ComboFix-quarantined-files.txt 2009-03-06 13:19:49
ComboFix2.txt 2009-03-06 01:43:43

Pre-Run: 4,299,194,368 bytes free
Post-Run: 4,306,440,192 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
380

Avenger (no root kit found)
=======
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Completed script processing.

*******************

Finished! Terminate.


HJT
====
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:33, on 2009-03-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\WINNT\system32\HPZipm12.exe
C:\WINNT\system32\SvcLncher.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\TF9E8.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINNT\system32\msiexec.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\WINNT\explorer.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\igfxsrvc.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\WinPatrol\winpatrol.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\WINNT\system32\HPZinw12.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\HP\Digital Imaging\bin\hpqdirec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqdstcp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconf.glb.nsn-net.net/proxy.pac
F2 - REG:system.ini: UserInit=C:\WINNT\explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe" /tray
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.placeware.com
O15 - Trusted Zone: *.sap-ag.de
O15 - Trusted Zone: *.sap.com
O15 - Trusted Zone: http://communication-market1.siemens.de
O15 - Trusted Zone: http://icm-km.erlm.siemens.de
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de
O15 - Trusted Zone: http://ikuddq.icn.siemens.it
O15 - Trusted Zone: virtualtrainingroom.vodafone.com
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.placeware.com (HKLM)
O15 - Trusted Zone: *.sap-ag.de (HKLM)
O15 - Trusted Zone: *.sap.com (HKLM)
O15 - Trusted Zone: http://communication-market1.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km1.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km2.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km3.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://icm-km4.erlm.siemens.de (HKLM)
O15 - Trusted Zone: http://ikuddq.icn.siemens.it (HKLM)
O15 - Trusted Zone: virtualtrainingroom.vodafone.com (HKLM)
O16 - DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} (WebTrain.ctlWebTrain) - http://www.webattend.com/components/wt0523.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1230590012390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230592905812
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://apertio.webex.com/client/T27L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = nsn-intra.net
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE

–
End of file - 16794 bytes
calvin_hobbes, Looking much better. :woot: Now we need to get the userinit.exe replaced. Please go to microsoft's website and perform all critical updates. After all updates are done, please run Combofix again and post the report here.
Hi Tomk,

Thanks once again. Laptop updated to Windows XP SP3.

ComboFix
========
ComboFix 09-03-04.01 - vm092543 2009-03-06 18:56:11.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2463 [GMT -5:00]
Running from: d:\data\Downloads\Malware Removal\ComboFix.exe
AV: Trend Micro OfficeScan Antivirus *On-access scanning disabled* (Outdated)
FW: Trend Micro Personal Firewall *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://USRTSMO001:80
.
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.

2009-03-06 18:51 . 2009-03-06 18:51 8,192 –a—— c:\winnt\system32\srbt.dll
2009-03-06 15:16 . 2009-01-09 14:19 1,089,593 —–c— c:\winnt\system32\dllcache\ntprint.cat
2009-03-06 14:51 . 2008-05-01 09:33 331,776 —–c— c:\winnt\system32\dllcache\msadce.dll
2009-03-06 14:48 . 2009-03-06 14:48 d——– c:\winnt\LastGood
2009-03-06 13:07 . 2009-03-06 13:07 d——– c:\winnt\system32\scripting
2009-03-06 13:07 . 2009-03-06 13:07 d——– c:\winnt\system32\en
2009-03-06 13:07 . 2009-03-06 13:07 d——– c:\winnt\system32\bits
2009-03-06 13:07 . 2009-03-06 13:07 d——– c:\winnt\l2schemas
2009-03-06 12:58 . 2009-03-06 13:09 d——– c:\winnt\ServicePackFiles
2009-03-06 12:42 . 2008-04-13 19:12 69,120 ——— c:\winnt\system32\wlanapi.dll
2009-03-06 12:42 . 2004-08-03 22:29 25,471 ——— c:\winnt\system32\drivers\watv10nt.sys
2009-03-06 12:42 . 2004-08-03 22:29 22,271 ——— c:\winnt\system32\drivers\watv06nt.sys
2009-03-06 12:42 . 2008-04-13 13:43 14,208 ——— c:\winnt\system32\drivers\wacompen.sys
2009-03-06 12:42 . 2004-08-03 22:29 11,935 ——— c:\winnt\system32\drivers\wadv11nt.sys
2009-03-06 12:42 . 2004-08-03 22:29 11,871 ——— c:\winnt\system32\drivers\wadv09nt.sys
2009-03-06 12:42 . 2004-08-03 22:29 11,807 ——— c:\winnt\system32\drivers\wadv07nt.sys
2009-03-06 12:42 . 2004-08-03 22:29 11,295 ——— c:\winnt\system32\drivers\wadv08nt.sys
2009-03-06 12:40 . 2008-04-13 19:11 136,192 ——— c:\winnt\system32\aaclient.dll
2009-03-06 11:42 . 2008-10-16 14:07 23,576 –a—— c:\winnt\system32\wuapi.dll.mui
2009-03-05 20:56 . 2009-03-05 20:57 d——– C:\Rooter$
2009-02-28 13:04 . 2009-02-28 13:04 d——– c:\program files\Trend Micro
2009-02-28 11:03 . 2009-02-28 12:24 d——– c:\winnt\system32\3361
2009-02-28 11:03 . 2009-02-28 11:03 108,336 –a—— c:\winnt\system32\MSWINSCK.OCX
2009-02-28 06:43 . 2009-02-28 10:43 90 –a—— c:\winnt\system32\work.ini
2009-02-28 05:40 . 2002-02-15 14:02 676,352 –a—— c:\winnt\system32\rtl60.bpl
2009-02-28 05:39 . 2009-03-05 08:01 d——– c:\winnt\system32\inf
2009-02-26 08:31 . 2009-02-26 08:31 d——– c:\program files\Sequence Chart Studio
2009-02-23 21:39 . 2009-02-23 21:43 d——– c:\program files\Psiloc Wireless Presenter Desktop
2009-02-23 21:23 . 2009-02-23 21:26 d——– c:\program files\Psiloc
2009-02-22 01:47 . 2009-02-22 01:47 d——– c:\program files\Microsoft Sync Framework
2009-02-20 09:43 . 2009-02-20 09:43 d——– c:\program files\Copernic Desktop Search
2009-02-18 20:20 . 2008-02-01 15:17 138,112 –a—— c:\winnt\system32\drivers\nmwcdnsu.sys
2009-02-18 20:20 . 2008-02-01 15:17 8,320 –a—— c:\winnt\system32\drivers\nmwcdnsuc.sys
2009-02-18 13:14 . 2009-02-18 13:14 d–h—– c:\winnt\PIF
2009-02-18 13:12 . 2009-02-18 13:12 d——– c:\documents and settings\vm092543\Application Data\Windows Search
2009-02-18 13:11 . 2009-02-20 13:29 d——– c:\program files\Windows Desktop Search
2009-02-06 02:48 . 2009-02-06 02:48 d——– c:\winnt\system32\XPSViewer
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\Reference Assemblies
2009-02-06 02:47 . 2009-02-06 02:47 d——– c:\program files\MSBuild
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 ——— c:\winnt\system32\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 07:06 1,676,288 —–c— c:\winnt\system32\dllcache\xpssvcs.dll
2009-02-06 02:46 . 2008-07-06 05:50 597,504 —–c— c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-02-06 02:46 . 2008-07-06 07:06 575,488 ——— c:\winnt\system32\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 575,488 —–c— c:\winnt\system32\dllcache\xpsshhdr.dll
2009-02-06 02:46 . 2008-07-06 07:06 117,760 ——— c:\winnt\system32\prntvpt.dll
2009-02-06 02:46 . 2008-07-06 07:06 89,088 —–c— c:\winnt\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-06 23:55 ——— d—–w c:\program files\OfficeScan NT
2009-03-06 23:50 ——— d—–w c:\program files\Microsoft Silverlight
2009-03-06 22:37 ——— d—–w c:\program files\Password Safe
2009-03-06 18:46 ——— d—–w c:\program files\IP VPN Remote Services
2009-03-06 17:36 ——— d—–w c:\documents and settings\vm092543\Application Data\.purple
2009-03-06 13:52 ——— d—–w c:\documents and settings\vm092543\Application Data\webex
2009-03-05 17:23 ——— d—–w c:\documents and settings\vm092543\Application Data\RipIt4Me
2009-03-05 12:52 ——— d—–w c:\program files\Java
2009-03-02 14:03 206,848 —-a-w c:\winnt\system32\SetupSvc.exe
2009-02-28 18:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-28 18:22 ——— d—–w c:\program files\Spybot
2009-02-28 17:28 ——— d—–w c:\program files\Malwarebytes
2009-02-26 01:21 229,376 —-a-w c:\winnt\system32\SvcLncher.exe
2009-02-25 05:41 ——— d—–w c:\program files\Migration
2009-02-24 01:35 ——— d—–w c:\documents and settings\vm092543\Application Data\Nokia
2009-02-22 18:22 ——— d—–w c:\program files\NOKIA
2009-02-22 06:48 ——— d—–w c:\program files\SyncToy
2009-02-20 14:43 ——— d—–w c:\documents and settings\vm092543\Application Data\Copernic
2009-02-19 01:20 ——— d—–w c:\program files\Common Files\Nokia
2009-02-19 01:20 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-02-13 14:28 ——— d—–w c:\program files\MCollect
2009-02-11 15:19 38,496 —-a-w c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\winnt\system32\drivers\mbam.sys
2009-01-30 01:53 ——— d—–w c:\documents and settings\vm092543\Application Data\dvdcss
2009-01-27 21:06 ——— d—–w c:\documents and settings\All Users\Application Data\iPass
2009-01-24 02:42 ——— d—–w c:\program files\Pidgin
2009-01-24 02:42 ——— d—–w c:\program files\Aspell
2009-01-24 02:38 ——— d—–w c:\program files\Common Files\GTK
2009-01-23 12:27 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 09:12 142,992 —-a-w c:\winnt\system32\drivers\tmcomm.sys
2009-01-15 09:11 76,304 —-a-w c:\winnt\system32\drivers\tmtdi.sys
2009-01-15 09:11 338,448 —-a-w c:\winnt\system32\drivers\TM_CFW.sys
2009-01-15 00:06 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 17:45 ——— d—–w c:\program files\WebEx
2009-01-08 23:33 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-08 23:32 ——— d—–w c:\program files\PC Connectivity Solution
2009-01-08 23:26 ——— d—–w c:\program files\Creative
2009-01-08 23:21 ——— d—–w c:\program files\BlackBerry Connect Desktop for Nokia
2009-01-08 17:04 ——— d—–w c:\documents and settings\vm092543\Application Data\Creative
2008-12-20 23:15 826,368 —-a-w c:\winnt\system32\wininet.dll
2008-11-19 18:02 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-11-19 18:02 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-11-19 18:03 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-11-19 18:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2005-04-26 13:48 57,344 —-a-w c:\program files\internet explorer\plugins\PluginWrapper.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-03-05_ 8.13.07.90 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-08-23 12:00:00 18,944 -c—-w c:\winnt\$NtUninstallKB915800-v4$\mimefilt.dll
- 2004-08-03 22:56:46 103,936 -c—-w c:\winnt\$NtUninstallKB915800-v4$\nlhtml.dll
- 2004-08-03 22:56:46 120,832 -c—-w c:\winnt\$NtUninstallKB915800-v4$\offfilt.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB938464_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB938464_0$\spuninst\updspapi.dll
- 2004-08-04 05:06:34 82,944 -c—-w c:\winnt\$NtUninstallKB946648$\msgsc.dll
+ 2004-08-04 05:06:34 82,944 -c—-w c:\winnt\$NtUninstallKB946648_0$\msgsc.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB946648_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB946648_0$\spuninst\updspapi.dll
- 2006-07-13 08:48:58 202,240 -c—-w c:\winnt\$NtUninstallKB950762$\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c—-w c:\winnt\$NtUninstallKB950762_0$\rmcast.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB950762_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB950762_0$\spuninst\updspapi.dll
- 2005-07-26 04:39:45 243,200 -c—-w c:\winnt\$NtUninstallKB950974$\es.dll
+ 2005-07-26 04:39:45 243,200 -c—-w c:\winnt\$NtUninstallKB950974_0$\es.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB950974_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB950974_0$\spuninst\updspapi.dll
- 2007-08-21 06:15:44 683,520 -c—-w c:\winnt\$NtUninstallKB951066$\inetcomm.dll
+ 2007-08-21 06:15:44 683,520 -c—-w c:\winnt\$NtUninstallKB951066_0$\inetcomm.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB951066_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB951066_0$\spuninst\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB951376-v2_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB951376-v2_0$\spuninst\updspapi.dll
- 2007-10-29 22:43:03 1,287,680 -c—-w c:\winnt\$NtUninstallKB951698$\quartz.dll
+ 2007-10-29 22:43:03 1,287,680 -c—-w c:\winnt\$NtUninstallKB951698_0$\quartz.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB951698_0$\spuninst\spuninst.exe
+ 2007-12-04 00:55:32 382,840 -c—-w c:\winnt\$NtUninstallKB951698_0$\spuninst\updspapi.dll
- 2004-08-03 21:14:16 138,496 -c—-w c:\winnt\$NtUninstallKB951748$\afd.sys
- 2006-06-26 17:37:10 148,480 -c—-w c:\winnt\$NtUninstallKB951748$\dnsapi.dll
- 2004-08-03 22:56:46 245,248 -c—-w c:\winnt\$NtUninstallKB951748$\mswsock.dll
- 2006-04-20 11:51:50 359,808 -c—-w c:\winnt\$NtUninstallKB951748$\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c—-w c:\winnt\$NtUninstallKB951748$\tcpip6.sys
+ 2004-08-03 21:14:16 138,496 -c—-w c:\winnt\$NtUninstallKB951748_0$\afd.sys
+ 2006-06-26 17:37:10 148,480 -c—-w c:\winnt\$NtUninstallKB951748_0$\dnsapi.dll
+ 2004-08-03 22:56:46 245,248 -c—-w c:\winnt\$NtUninstallKB951748_0$\mswsock.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB951748_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB951748_0$\spuninst\updspapi.dll
+ 2006-04-20 11:51:50 359,808 -c—-w c:\winnt\$NtUninstallKB951748_0$\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c—-w c:\winnt\$NtUninstallKB951748_0$\tcpip6.sys
- 2005-06-29 01:46:00 74,240 -c—-w c:\winnt\$NtUninstallKB952954$\mscms.dll
+ 2005-06-29 01:46:00 74,240 -c—-w c:\winnt\$NtUninstallKB952954_0$\mscms.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB952954_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB952954_0$\spuninst\updspapi.dll
- 2008-03-19 09:47:00 1,845,248 -c—-w c:\winnt\$NtUninstallKB954211$\win32k.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB954211_0$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\winnt\$NtUninstallKB954211_0$\spuninst\updspapi.dll
+ 2008-03-19 09:47:00 1,845,248 -c—-w c:\winnt\$NtUninstallKB954211_0$\win32k.sys
- 2006-08-21 13:52:08 246,814 -c—-w c:\winnt\$NtUninstallKB954600$\strmdll.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB954600_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB954600_0$\spuninst\updspapi.dll
+ 2006-08-21 13:52:08 246,814 -c—-w c:\winnt\$NtUninstallKB954600_0$\strmdll.dll
- 2007-06-26 06:08:16 1,104,896 -c—-w c:\winnt\$NtUninstallKB955069$\msxml3.dll
+ 2007-06-26 06:08:16 1,104,896 -c—-w c:\winnt\$NtUninstallKB955069_0$\msxml3.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB955069_0$\spuninst\spuninst.exe
+ 2008-07-09 18:08:38 382,840 -c—-w c:\winnt\$NtUninstallKB955069_0$\spuninst\updspapi.dll
- 2008-02-20 06:51:05 282,624 -c—-w c:\winnt\$NtUninstallKB956802$\gdi32.dll
+ 2008-02-20 06:51:05 282,624 -c—-w c:\winnt\$NtUninstallKB956802_0$\gdi32.dll
+ 2008-07-08 13:02:02 231,288 -c—-w c:\winnt\$NtUninstallKB956802_0$\spuninst\spuninst.exe
+ 2008-07-08 13:02:12 382,840 -c—-w c:\winnt\$NtUninstallKB956802_0$\spuninst\updspapi.dll
- 2008-06-20 10:44:38 138,368 -c—-w c:\winnt\$NtUninstallKB956803$\afd.sys
+ 2008-06-20 10:44:38 138,368 -c—-w c:\winnt\$NtUninstallKB956803_0$\afd.sys
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB956803_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB956803_0$\spuninst\updspapi.dll
- 2007-02-28 09:15:59 2,017,280 -c—-w c:\winnt\$NtUninstallKB956841$\ntkrnlpa.exe
- 2007-02-28 09:53:04 2,137,600 -c—-w c:\winnt\$NtUninstallKB956841$\ntoskrnl.exe
+ 2007-02-28 09:53:04 2,137,600 -c—-w c:\winnt\$NtUninstallKB956841_0$\ntkrnlmp.exe
+ 2007-02-28 09:15:59 2,017,280 -c—-w c:\winnt\$NtUninstallKB956841_0$\ntkrnlpa.exe
+ 2007-02-28 09:15:59 2,017,280 -c—-w c:\winnt\$NtUninstallKB956841_0$\ntkrpamp.exe
+ 2007-02-28 09:53:04 2,137,600 -c—-w c:\winnt\$NtUninstallKB956841_0$\ntoskrnl.exe
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB956841_0$\spuninst\spuninst.exe
+ 2008-07-09 07:38:37 382,840 -c—-w c:\winnt\$NtUninstallKB956841_0$\spuninst\updspapi.dll
- 2006-08-14 10:34:41 332,928 -c—-w c:\winnt\$NtUninstallKB957095$\srv.sys
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB957095_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB957095_0$\spuninst\updspapi.dll
+ 2006-08-14 10:34:41 332,928 -c—-w c:\winnt\$NtUninstallKB957095_0$\srv.sys
- 2006-05-05 09:41:45 453,120 -c—-w c:\winnt\$NtUninstallKB957097$\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 -c—-w c:\winnt\$NtUninstallKB957097_0$\mrxsmb.sys
+ 2008-07-08 13:02:02 231,288 -c—-w c:\winnt\$NtUninstallKB957097_0$\spuninst\spuninst.exe
+ 2008-07-08 13:02:12 382,840 -c—-w c:\winnt\$NtUninstallKB957097_0$\spuninst\updspapi.dll
- 2006-08-17 12:37:49 337,408 -c—-w c:\winnt\$NtUninstallKB958644$\netapi32.dll
+ 2006-08-17 12:37:49 337,408 -c—-w c:\winnt\$NtUninstallKB958644_0$\netapi32.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\winnt\$NtUninstallKB958644_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB958644_0$\spuninst\updspapi.dll
- 2008-08-28 10:04:17 333,056 -c—-w c:\winnt\$NtUninstallKB958687$\srv.sys
+ 2007-11-30 12:39:22 231,288 -c—-w c:\winnt\$NtUninstallKB958687_0$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c—-w c:\winnt\$NtUninstallKB958687_0$\spuninst\updspapi.dll
+ 2008-08-28 10:04:17 333,056 -c—-w c:\winnt\$NtUninstallKB958687_0$\srv.sys
- 2006-10-04 14:05:26 39,424 ——w c:\winnt\AppPatch\acadproc.dll
+ 2008-04-14 00:11:48 39,424 —-a-w c:\winnt\AppPatch\acadproc.dll
- 2004-08-03 22:56:42 1,852,416 —-a-w c:\winnt\AppPatch\AcGenral.dll
+ 2008-04-14 00:11:48 1,852,928 —-a-w c:\winnt\AppPatch\acgenral.dll
- 2004-08-03 22:56:42 450,048 —-a-w c:\winnt\AppPatch\AcLayers.dll
+ 2008-04-14 00:11:48 451,072 —-a-w c:\winnt\AppPatch\aclayers.dll
- 2004-08-03 22:56:42 137,728 —-a-w c:\winnt\AppPatch\AcLua.dll
+ 2008-04-14 00:11:48 141,312 —-a-w c:\winnt\AppPatch\aclua.dll
- 2004-08-03 22:56:42 244,736 —-a-w c:\winnt\AppPatch\AcSpecfc.dll
+ 2008-04-14 00:11:48 245,248 —-a-w c:\winnt\AppPatch\acspecfc.dll
- 2004-08-03 22:56:42 116,224 —-a-w c:\winnt\AppPatch\AcXtrnal.dll
+ 2008-04-14 00:11:48 116,224 —-a-w c:\winnt\AppPatch\acxtrnal.dll
- 2007-09-26 20:44:50 20,080 —-a-w c:\winnt\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-03-06 20:34:18 22,928 —-a-w c:\winnt\assembly\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
- 2007-09-26 20:44:50 371,296 —-a-w c:\winnt\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2009-03-06 20:34:09 374,152 —-a-w c:\winnt\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
- 2007-09-26 20:44:51 64,088 —-a-w c:\winnt\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-03-06 20:34:29 66,936 —-a-w c:\winnt\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2007-09-26 20:44:51 223,800 —-a-w c:\winnt\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-03-06 20:34:19 226,656 —-a-w c:\winnt\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
- 2008-06-13 13:10:50 272,128 ——w c:\winnt\Driver Cache\i386\bthport.sys
+ 2008-06-13 11:05:51 272,128 ——w c:\winnt\Driver Cache\i386\bthport.sys
- 2008-10-24 11:10:42 453,632 ——w c:\winnt\Driver Cache\i386\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 ——w c:\winnt\Driver Cache\i386\mrxsmb.sys
- 2008-08-14 09:55:01 2,142,720 —-a-w c:\winnt\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 10:09:26 2,145,280 ——w c:\winnt\Driver Cache\i386\ntkrnlmp.exe
- 2008-08-14 09:18:44 2,062,976 —-a-w c:\winnt\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 ——w c:\winnt\Driver Cache\i386\ntkrnlpa.exe
- 2008-08-14 09:18:46 2,020,864 —-a-w c:\winnt\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 09:33:16 2,023,936 ——w c:\winnt\Driver Cache\i386\ntkrpamp.exe
- 2008-08-14 09:57:20 2,185,984 —-a-w c:\winnt\Driver Cache\i386\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 ——w c:\winnt\Driver Cache\i386\ntoskrnl.exe
- 2004-08-03 22:56:50 1,032,192 —-a-w c:\winnt\explorer.exe
+ 2008-04-14 00:12:19 1,033,728 —-a-w c:\winnt\explorer.exe
- 2004-08-03 22:56:46 34,816 —-a-w c:\winnt\Help\sniffpol.dll
+ 2008-04-14 00:12:06 34,816 —-a-w c:\winnt\Help\sniffpol.dll
- 2004-08-03 22:56:46 33,280 —-a-w c:\winnt\Help\sstub.dll
+ 2008-04-14 00:12:07 33,280 —-a-w c:\winnt\Help\sstub.dll
- 2004-08-03 22:56:48 279,040 —-a-w c:\winnt\Help\tshoot.dll
+ 2008-04-14 00:12:07 279,040 —-a-w c:\winnt\Help\tshoot.dll
- 2005-05-26 23:22:01 10,752 —-a-w c:\winnt\hh.exe
+ 2008-04-14 00:12:21 10,752 —-a-w c:\winnt\hh.exe
+ 2007-03-06 01:22:39 213,216 -c—-w c:\winnt\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w c:\winnt\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:54:10 765,952 -c—-w c:\winnt\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2008-10-16 20:38:34 124,928 -c—-w c:\winnt\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c—-w c:\winnt\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w c:\winnt\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w c:\winnt\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c—-w c:\winnt\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c—-w c:\winnt\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c—-w c:\winnt\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c—-w c:\winnt\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c—-w c:\winnt\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c—-w c:\winnt\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c—-w c:\winnt\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c—-w c:\winnt\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c—-w c:\winnt\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c—-w c:\winnt\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w c:\winnt\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w c:\winnt\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c—-w c:\winnt\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w c:\winnt\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c—-w c:\winnt\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w c:\winnt\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\winnt\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\winnt\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c—-w c:\winnt\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w c:\winnt\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c—-w c:\winnt\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c—-w c:\winnt\ie7updates\KB961260-IE7\wininet.dll
- 2004-08-03 22:56:44 220,160 —-a-w c:\winnt\ime\mscandui.dll
+ 2008-04-14 00:11:58 220,160 —-a-w c:\winnt\ime\mscandui.dll
- 2004-08-03 22:56:46 130,048 —-a-w c:\winnt\ime\SOFTKBD.DLL
+ 2008-04-14 00:12:06 130,048 —-a-w c:\winnt\ime\softkbd.dll
- 2004-08-03 22:56:30 62,976 —-a-w c:\winnt\ime\SPGRMR.dll
+ 2008-04-13 16:43:18 62,976 —-a-w c:\winnt\ime\spgrmr.dll
- 2004-08-03 22:56:46 250,880 —-a-w c:\winnt\ime\SPTIP.dll
+ 2008-04-14 00:12:06 250,368 —-a-w c:\winnt\ime\sptip.dll
- 2006-11-01 23:31:34 315,904 —-a-w c:\winnt\inf\unregmp2.exe
+ 2007-06-27 03:10:26 317,440 —-a-w c:\winnt\inf\unregmp2.exe
+ 2006-10-27 00:12:58 396,592 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\MOC.EXE
+ 2006-10-27 19:26:40 16,870,712 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 00:42:36 8,423,224 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\OARTCONV.DLL
+ 2006-10-27 19:18:36 1,658,152 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-27 01:08:00 1,764,112 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\PPCNV.DLL
+ 2006-10-27 01:07:50 67,920 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\PXBCOM.EXE
+ 2006-10-27 19:11:38 4,235,560 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 19:11:36 21,264 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2006-10-27 01:13:08 14,674,216 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2007-09-15 02:45:58 16,901,168 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 05:19:24 1,654,648 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-24 10:00:34 1,767,768 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\PPCNV.DLL
+ 2007-08-24 10:00:48 72,096 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\PXBCOM.EXE
+ 2007-09-06 23:03:02 4,280,176 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\WRD12CNV.DLL
+ 2007-08-29 05:07:58 24,928 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\WRD12EXE.EXE
+ 2007-10-03 01:00:06 14,708,760 —-a-r c:\winnt\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\XL12CNV.EXE
+ 2003-07-14 21:57:14 124,480 —-a-r c:\winnt\Installer\$PatchCache$\Managed\7040E10900063D11C8EF10054038389C\11.0.5614\MSB1CORE.DLL
+ 2003-07-14 22:12:22 47,872 —-a-r c:\winnt\Installer\$PatchCache$\Managed\7040E10900063D11C8EF10054038389C\11.0.5614\MSB1XTOR.DLL
+ 2003-08-16 10:29:36 846,440 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\AEC.DLL
+ 2003-08-16 10:28:34 434,752 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\AECUTILS.DLL
+ 2003-07-14 21:57:34 38,968 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\AUTHZAX.DLL
+ 2003-07-14 21:53:06 94,768 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\AW.DLL
+ 2003-08-16 10:26:42 132,216 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\BRTVIEW.DLL
+ 2003-08-16 10:29:04 567,928 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\BSTORM.DLL
+ 2003-08-16 10:27:06 173,688 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\CMAX20.DLL
+ 2003-08-16 10:26:32 65,600 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\CODEEDIT.DLL
+ 2003-08-16 10:27:38 309,888 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DATAGATH.DLL
+ 2003-08-16 10:30:04 916,088 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DBENGR.DLL
+ 2003-08-16 10:26:32 83,064 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DBSHARE.DLL
+ 2003-08-16 10:29:12 668,216 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DBWIZ.DLL
+ 2003-07-14 21:56:54 14,904 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DSITF.DLL
+ 2003-07-14 21:57:14 98,360 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DSSM.EXE
+ 2003-08-16 10:26:52 150,648 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DWGCNV.DLL
+ 2003-08-16 10:31:04 2,089,592 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\DWGDP.DLL
+ 2003-08-16 10:26:20 49,720 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\EDITOR.EXE
+ 2003-08-16 10:26:46 148,600 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\EDITORS.DLL
+ 2003-08-16 10:27:08 178,304 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ELEMENTS.DLL
+ 2003-08-16 10:26:46 110,208 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ELEMUTIL.DLL
+ 2003-08-16 10:27:34 258,168 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\EXTRACT.DLL
+ 2003-08-16 10:30:34 1,106,560 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\FACILITY.DLL
+ 2007-09-26 20:44:50 371,296 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\FORMSPIA.DLL
+ 2003-08-16 10:30:34 1,142,840 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\GANTT.DLL
+ 2003-08-16 10:27:36 307,768 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\HVAC.DLL
+ 2003-08-16 10:28:38 533,632 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\IMCOMMON.DLL
+ 2003-08-16 10:26:58 143,480 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\IMUTIL.DLL
+ 2003-08-16 10:27:04 175,736 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\IMWDD.DLL
+ 2003-08-16 10:26:08 21,624 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\IMWIZ.DLL
+ 2003-08-16 10:27:14 208,504 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\IXUTIL.DLL
+ 2003-08-16 10:28:06 339,000 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\LGND.DLL
+ 2003-08-16 10:29:06 740,992 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\LOGELEMS.DLL
+ 2003-08-16 10:28:04 348,792 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\LOGVIEW.DLL
+ 2003-08-16 10:28:36 477,312 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MODELENG.DLL
+ 2003-08-16 10:26:54 159,288 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MPXINT.DLL
+ 2003-07-14 21:51:44 87,104 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSENCODE.DLL
+ 2003-07-14 21:52:52 17,464 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSMH.DLL
+ 2003-07-14 21:57:16 120,888 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOAUTH.DLL
+ 2003-07-14 21:52:52 27,704 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSODCW.DLL
+ 2003-07-14 21:44:06 25,144 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOEURO.DLL
+ 2003-07-14 21:52:56 55,360 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOHTMED.EXE
+ 2003-07-11 01:15:48 1,292,872 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSONSEXT.DLL
+ 2003-07-15 02:18:52 376,888 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSORUN.DLL
+ 2003-07-14 21:52:54 28,224 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOSTYLE.DLL
+ 2003-08-16 10:26:36 93,304 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOUTLS.DLL
+ 2003-07-14 21:46:16 42,040 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOXEV.DLL
+ 2003-07-14 21:45:12 55,360 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOXMLED.EXE
+ 2003-07-14 21:45:12 39,488 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSOXMLMF.DLL
+ 2003-07-14 21:52:58 41,528 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSSH.DLL
+ 2007-09-26 20:44:50 20,080 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\MSTAGPIA.DLL
+ 2003-07-14 21:56:52 13,888 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\NPOFFICE.DLL
+ 2007-09-26 20:44:51 223,800 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\OFFICE.DLL
+ 2003-08-16 10:30:04 923,776 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ORGCHART.DLL
+ 2003-08-16 10:28:34 461,952 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ORGCHWIZ.DLL
+ 2003-08-16 10:26:18 48,184 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ORGWIZ.EXE
+ 2003-08-16 10:27:40 333,952 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\ORMELEMS.DLL
+ 2003-08-16 10:27:38 326,776 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PDSBASE.DLL
+ 2003-08-16 10:29:36 850,024 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PE.DLL
+ 2003-08-16 10:26:24 56,896 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PROJIMPT.EXE
+ 2003-08-16 10:27:02 156,224 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PROJMODL.DLL
+ 2003-08-16 10:26:24 56,440 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PROPMGR.DLL
+ 2003-08-16 10:29:06 754,232 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\PROPRPT.DLL
+ 2003-05-08 20:54:00 77,824 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\REFEDIT.DLL
+ 2003-07-14 21:57:08 40,512 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\REFIEBAR.DLL
+ 2003-08-16 10:27:04 163,960 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\REPORT.DLL
+ 2003-08-16 10:28:34 434,304 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SAVASWEB.DLL
+ 2003-08-16 10:27:38 313,912 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SAVWBHF.DLL
+ 2003-08-16 10:27:34 266,816 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SAVWBRAS.DLL
+ 2003-08-16 10:27:34 263,744 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SAVWBVML.DLL
+ 2003-07-14 21:57:18 349,248 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SELFCERT.EXE
+ 2003-07-14 21:57:08 58,944 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SEQCHK10.DLL
+ 2003-08-16 10:31:34 2,641,456 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SG.DLL
+ 2003-08-16 10:27:10 191,032 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SHAPNUM.DLL
+ 2003-08-16 10:27:04 162,432 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SMIGRATE.DLL
+ 2003-08-16 10:27:16 240,192 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SOLUTILS.DLL
+ 2003-08-16 10:27:06 181,376 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SQLSHARE.DLL
+ 2003-08-16 10:26:40 92,800 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\STYLEMGR.DLL
+ 2003-08-16 10:26:26 61,560 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\SUMINFO.DLL
+ 2003-08-16 10:29:36 873,088 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\TIMESOLN.DLL
+ 2003-08-16 10:26:20 47,160 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\TLIMPT.EXE
+ 2003-08-16 10:31:04 1,497,136 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\UML.DLL
+ 2003-08-16 10:29:10 550,456 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\UMLSYS.DLL
+ 2003-08-16 10:28:08 373,304 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\UMLVB.DLL
+ 2003-08-16 10:28:04 341,560 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\UMLVC60.DLL
+ 2003-08-16 10:28:06 394,296 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\UMLVS.DLL
+ 2003-08-16 10:26:36 93,752 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VAOSOLX.DLL
+ 2007-09-26 20:44:51 64,088 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VBIDEPIA.DLL
+ 2003-08-16 10:26:54 126,592 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VERBWIND.DLL
+ 2003-08-16 10:26:38 86,080 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VIEWMODL.DLL
+ 2003-08-16 10:31:34 7,799,864 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISBRGR.DLL
+ 2003-08-16 10:27:14 242,816 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISCOLOR.DLL
+ 2003-08-16 10:26:50 148,088 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISDLGU.DLL
+ 2003-08-16 10:31:34 2,271,800 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISFILT.DLL
+ 2003-08-16 10:27:36 308,856 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISGRF.DLL
+ 2003-08-16 10:27:12 186,936 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISIO.EXE
+ 2003-08-16 10:32:04 8,304,248 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISLIB.DLL
+ 2003-08-16 10:26:36 99,384 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISOCX.DLL
+ 2003-08-16 10:26:34 91,200 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISPRX32.DLL
+ 2003-08-16 10:29:34 785,464 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISSHE.DLL
+ 2003-08-16 10:29:04 583,224 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISSUPP.DLL
+ 2003-08-16 10:28:10 413,248 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISUTILS.DLL
+ 2003-08-16 10:30:04 998,520 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISWEB.DLL
+ 2003-08-16 10:26:22 53,888 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\VISXDATA.DLL
+ 2003-08-16 10:28:36 524,344 —-a-r c:\winnt\Installer\$PatchCache$\Managed\9040150900063D11C8EF10054038389C\11.0.3216\XFUNC.DLL
- 2007-09-26 20:53:35 35,600 —-a-r c:\winnt\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-03-06 21:52:08 35,600 —-a-r c:\winnt\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2007-09-26 20:52:47 135,168 —-a-r c:\winnt\Installer\{901E0407-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-03-06 20:32:36 135,168 —-a-r c:\winnt\Installer\{901E0407-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-10-06 04:46:07 12,288 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-03-06 20:34:40 12,288 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2007-10-06 04:46:07 135,168 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-03-06 20:34:40 135,168 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-10-06 04:46:07 4,096 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-03-06 20:34:40 4,096 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2007-10-06 04:46:07 176,128 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\visicon.exe
+ 2009-03-06 20:34:40 176,128 —-a-r c:\winnt\Installer\{90510409-6000-11D3-8CFE-0150048383C9}\visicon.exe
+ 2008-01-18 15:13:09 2,247 ——w c:\winnt\Installer\tsclientmsitrans\tscdsbl.bat
+ 2007-12-12 10:33:51 18,917 ——w c:\winnt\Installer\tsclientmsitrans\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 ——w c:\winnt\Installer\tsclientmsitrans\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 ——w c:\winnt\Installer\tsclientmsitrans\tscupdc.dll
- 2004-08-03 22:56:42 24,064 —-a-w c:\winnt\msagent\agentanm.dll
+ 2008-04-14 00:11:48 24,064 —-a-w c:\winnt\msagent\agentanm.dll
- 2004-08-03 22:56:42 214,016 —-a-w c:\winnt\msagent\agentctl.dll
+ 2008-04-14 00:11:48 214,016 —-a-w c:\winnt\msagent\agentctl.dll
- 2006-10-12 13:54:18 42,496 —-a-w c:\winnt\msagent\agentdp2.dll
+ 2008-04-14 00:11:48 42,496 —-a-w c:\winnt\msagent\agentdp2.dll
- 2007-03-09 13:58:57 57,344 —-a-w c:\winnt\msagent\agentdpv.dll
+ 2008-04-14 00:11:48 57,344 —-a-w c:\winnt\msagent\agentdpv.dll
- 2004-08-03 22:56:42 49,152 —-a-w c:\winnt\msagent\agentmpx.dll
+ 2008-04-14 00:11:48 49,152 —-a-w c:\winnt\msagent\agentmpx.dll
- 2004-08-03 22:56:42 24,064 —-a-w c:\winnt\msagent\agentpsh.dll
+ 2008-04-14 00:11:48 24,064 —-a-w c:\winnt\msagent\agentpsh.dll
- 2004-08-03 22:56:42 44,032 —-a-w c:\winnt\msagent\agentsr.dll
+ 2008-04-14 00:11:48 44,032 —-a-w c:\winnt\msagent\agentsr.dll
- 2006-10-12 11:54:07 256,512 —-a-w c:\winnt\msagent\agentsvr.exe
+ 2008-04-14 00:12:12 256,512 —-a-w c:\winnt\msagent\agentsvr.exe
- 2004-08-03 22:56:42 24,064 —-a-w c:\winnt\msagent\agtintl.dll
+ 2008-04-14 00:11:49 24,064 —-a-w c:\winnt\msagent\agtintl.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0405.dll
+ 2007-04-02 18:25:59 19,456 —-a-w c:\winnt\msagent\intl\agt0405.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0406.dll
+ 2007-04-02 18:25:59 19,456 —-a-w c:\winnt\msagent\intl\agt0406.dll
- 2001-08-23 12:00:00 21,504 —-a-w c:\winnt\msagent\intl\agt0407.dll
+ 2007-04-02 18:26:00 21,504 —-a-w c:\winnt\msagent\intl\agt0407.dll
- 2001-08-23 12:00:00 22,016 —-a-w c:\winnt\msagent\intl\agt0408.dll
+ 2007-04-02 18:26:00 22,016 —-a-w c:\winnt\msagent\intl\agt0408.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0409.dll
+ 2008-04-13 17:32:28 19,968 —-a-w c:\winnt\msagent\intl\agt0409.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt040b.dll
+ 2007-04-02 18:26:00 19,456 —-a-w c:\winnt\msagent\intl\agt040b.dll
- 2001-08-23 12:00:00 21,504 —-a-w c:\winnt\msagent\intl\agt040c.dll
+ 2007-04-02 18:26:00 21,504 —-a-w c:\winnt\msagent\intl\agt040c.dll
- 2001-08-23 12:00:00 19,968 —-a-w c:\winnt\msagent\intl\agt040e.dll
+ 2007-04-02 18:26:00 19,968 —-a-w c:\winnt\msagent\intl\agt040e.dll
- 2001-08-23 12:00:00 20,992 —-a-w c:\winnt\msagent\intl\agt0410.dll
+ 2007-04-02 18:26:00 20,992 —-a-w c:\winnt\msagent\intl\agt0410.dll
- 2001-08-23 12:00:00 20,992 —-a-w c:\winnt\msagent\intl\agt0413.dll
+ 2007-04-02 18:26:01 20,992 —-a-w c:\winnt\msagent\intl\agt0413.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0414.dll
+ 2007-04-02 18:26:01 19,456 —-a-w c:\winnt\msagent\intl\agt0414.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0415.dll
+ 2007-04-02 18:26:01 19,456 —-a-w c:\winnt\msagent\intl\agt0415.dll
- 2001-08-23 12:00:00 20,480 —-a-w c:\winnt\msagent\intl\agt0416.dll
+ 2007-04-02 18:26:01 20,480 —-a-w c:\winnt\msagent\intl\agt0416.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt0419.dll
+ 2007-04-02 18:26:01 19,456 —-a-w c:\winnt\msagent\intl\agt0419.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt041d.dll
+ 2007-04-02 18:26:01 19,456 —-a-w c:\winnt\msagent\intl\agt041d.dll
- 2001-08-23 12:00:00 19,456 —-a-w c:\winnt\msagent\intl\agt041f.dll
+ 2007-04-02 18:26:01 19,456 —-a-w c:\winnt\msagent\intl\agt041f.dll
- 2001-08-23 12:00:00 20,992 —-a-w c:\winnt\msagent\intl\agt0816.dll
+ 2007-04-02 18:26:02 20,992 —-a-w c:\winnt\msagent\intl\agt0816.dll
- 2001-08-23 12:00:00 20,480 —-a-w c:\winnt\msagent\intl\agt0c0a.dll
+ 2007-04-02 18:26:02 20,480 —-a-w c:\winnt\msagent\intl\agt0c0a.dll
- 2004-08-03 22:56:44 39,936 —-a-w c:\winnt\msagent\mslwvtts.dll
+ 2008-04-14 00:12:00 39,936 —-a-w c:\winnt\msagent\mslwvtts.dll
- 2004-08-03 22:56:54 90,624 —-a-w c:\winnt\mui\muisetup.exe
+ 2008-04-14 00:12:29 90,624 —-a-w c:\winnt\mui\muisetup.exe
+ 2008-04-14 00:11:51 33,792 ——w c:\winnt\network diagnostic\custsat.dll
+ 2008-04-13 18:53:32 558,080 ——w c:\winnt\network diagnostic\xpnetdiag.exe
- 2004-08-03 22:56:56 69,120 —-a-w c:\winnt\NOTEPAD.EXE
+ 2008-04-14 00:12:29 69,120 —-a-w c:\winnt\notepad.exe
- 2004-08-03 22:56:50 768,512 —-a-w c:\winnt\pchealth\helpctr\binaries\HelpCtr.exe
+ 2008-04-14 00:12:21 769,024 —-a-w c:\winnt\pchealth\helpctr\binaries\helpctr.exe
- 2004-08-03 22:56:52 743,936 —-a-w c:\winnt\pchealth\helpctr\binaries\HelpSvc.exe
+ 2008-04-14 00:12:21 744,448 —-a-w c:\winnt\pchealth\helpctr\binaries\helpsvc.exe
- 2004-08-03 22:56:52 18,944 —-a-w c:\winnt\pchealth\helpctr\binaries\HscUpd.exe
+ 2008-04-14 00:12:21 18,432 —-a-w c:\winnt\pchealth\helpctr\binaries\hscupd.exe
- 2004-08-03 22:56:54 158,208 —-a-w c:\winnt\pchealth\helpctr\binaries\msconfig.exe
+ 2008-04-14 00:12:27 169,984 —-a-w c:\winnt\pchealth\helpctr\binaries\msconfig.exe
- 2004-08-03 22:56:44 376,320 —-a-w c:\winnt\pchealth\helpctr\binaries\msinfo.dll
+ 2008-04-14 00:11:59 376,832 —-a-w c:\winnt\pchealth\helpctr\binaries\msinfo.dll
- 2004-08-03 22:56:46 102,400 —-a-w c:\winnt\pchealth\helpctr\binaries\pchshell.dll
+ 2008-04-14 00:12:02 102,912 —-a-w c:\winnt\pchealth\helpctr\binaries\pchshell.dll
- 2004-08-03 22:56:46 38,912 —-a-w c:\winnt\pchealth\helpctr\binaries\pchsvc.dll
+ 2008-04-14 00:12:02 38,400 —-a-w c:\winnt\pchealth\helpctr\binaries\pchsvc.dll
- 2007-09-26 19:58:26 86,315 —-a-w c:\winnt\pchealth\helpctr\OfflineCache\index.dat
+ 2009-03-06 18:18:28 86,315 —-a-w c:\winnt\pchealth\helpctr\OfflineCache\index.dat
- 2007-09-26 19:58:26 2,698 —-a-w c:\winnt\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2009-03-06 18:18:29 3,436 —-a-w c:\winnt\pchealth\helpctr\PackageStore\SkuStore.bin
- 2004-08-03 22:56:58 150,528 —-a-w c:\winnt\pchealth\UploadLB\Binaries\UploadM.exe
+ 2008-04-14 00:12:38 150,528 —-a-w c:\winnt\pchealth\UploadLB\Binaries\uploadm.exe
- 2004-08-03 22:56:46 151,552 —-a-w c:\winnt\PeerNet\sqldb20.dll
+ 2008-04-14 00:12:06 151,552 —-a-w c:\winnt\PeerNet\sqldb20.dll
- 2004-08-03 22:56:46 462,848 —-a-w c:\winnt\PeerNet\sqlqp20.dll
+ 2008-04-14 00:12:06 462,848 —-a-w c:\winnt\PeerNet\sqlqp20.dll
- 2004-08-03 22:56:46 110,592 —-a-w c:\winnt\PeerNet\sqlse20.dll
+ 2008-04-14 00:12:06 110,592 —-a-w c:\winnt\PeerNet\sqlse20.dll
- 2004-08-03 22:56:56 146,432 —-a-w c:\winnt\regedit.exe
+ 2008-04-14 00:12:32 146,432 —-a-w c:\winnt\regedit.exe
+ 2008-04-13 18:46:18 53,376 ——w c:\winnt\ServicePackFiles\i386\1394bus.sys
+ 2008-04-13 18:40:50 12,288 ——w c:\winnt\ServicePackFiles\i386\4mmdat.sys
+ 2008-04-13 18:46:20 48,128 ——w c:\winnt\ServicePackFiles\i386\61883.sys
+ 2008-04-14 00:11:48 100,352 ——w c:\winnt\ServicePackFiles\i386\6to4svc.dll
+ 2008-04-14 00:11:48 136,192 ——w c:\winnt\ServicePackFiles\i386\aaclient.dll
+ 2004-08-04 03:32:22 231,552 ——w c:\winnt\ServicePackFiles\i386\ac97ali.sys
+ 2004-08-04 03:32:32 84,480 ——w c:\winnt\ServicePackFiles\i386\ac97via.sys
+ 2008-04-14 00:11:48 39,424 ——w c:\winnt\ServicePackFiles\i386\acadproc.dll
+ 2008-04-14 00:12:11 184,320 ——w c:\winnt\ServicePackFiles\i386\accwiz.exe
+ 2008-04-14 00:11:48 1,852,928 ——w c:\winnt\ServicePackFiles\i386\acgenral.dll
+ 2008-04-14 00:11:48 451,072 ——w c:\winnt\ServicePackFiles\i386\aclayers.dll
+ 2008-04-14 00:11:48 141,312 ——w c:\winnt\ServicePackFiles\i386\aclua.dll
+ 2008-04-14 00:11:48 115,712 ——w c:\winnt\ServicePackFiles\i386\aclui.dll
+ 2008-04-13 18:36:35 187,776 ——w c:\winnt\ServicePackFiles\i386\acpi.sys
+ 2008-04-14 00:11:48 245,248 ——w c:\winnt\ServicePackFiles\i386\acspecfc.dll
+ 2008-04-14 00:11:48 193,536 ——w c:\winnt\ServicePackFiles\i386\activeds.dll
+ 2008-04-14 00:12:12 4,096 ——w c:\winnt\ServicePackFiles\i386\actmovie.exe
+ 2008-04-14 00:11:48 98,304 ——w c:\winnt\ServicePackFiles\i386\actxprxy.dll
+ 2008-04-14 00:11:48 116,224 ——w c:\winnt\ServicePackFiles\i386\acxtrnal.dll
+ 2008-04-14 00:11:48 29,696 ——w c:\winnt\ServicePackFiles\i386\admexs.dll
+ 2008-04-14 00:11:48 20,540 ——w c:\winnt\ServicePackFiles\i386\admin.dll
+ 2008-04-14 00:12:12 16,439 ——w c:\winnt\ServicePackFiles\i386\admin.exe
+ 2004-08-04 03:32:24 10,880 ——w c:\winnt\ServicePackFiles\i386\admjoy.sys
+ 2008-04-14 00:11:48 61,440 ——w c:\winnt\ServicePackFiles\i386\admparse.dll
+ 2008-04-14 00:11:48 43,520 ——w c:\winnt\ServicePackFiles\i386\admwprox.dll
+ 2008-04-14 00:11:48 290,816 ——w c:\winnt\ServicePackFiles\i386\adsiis51.dll
+ 2008-04-14 00:11:48 175,616 ——w c:\winnt\ServicePackFiles\i386\adsldp.dll
+ 2008-04-14 00:11:48 143,360 ——w c:\winnt\ServicePackFiles\i386\adsldpc.dll
+ 2008-04-14 00:11:48 68,096 ——w c:\winnt\ServicePackFiles\i386\adsmsext.dll
+ 2008-04-14 00:11:48 263,680 ——w c:\winnt\ServicePackFiles\i386\adsnt.dll
+ 2008-04-14 00:11:48 123,392 ——w c:\winnt\ServicePackFiles\i386\adsnw.dll
+ 2007-04-02 13:10:44 85,813 ——w c:\winnt\ServicePackFiles\i386\adsutil.vbs
+ 2008-04-14 00:11:48 4,255 ——w c:\winnt\ServicePackFiles\i386\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ——w c:\winnt\ServicePackFiles\i386\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ——w c:\winnt\ServicePackFiles\i386\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ——w c:\winnt\ServicePackFiles\i386\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ——w c:\winnt\ServicePackFiles\i386\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ——w c:\winnt\ServicePackFiles\i386\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ——w c:\winnt\ServicePackFiles\i386\adv11nt5.dll
+ 2008-04-14 00:11:48 617,472 ——w c:\winnt\ServicePackFiles\i386\advapi32.dll
+ 2008-04-14 00:11:48 99,840 ——w c:\winnt\ServicePackFiles\i386\advpack.dll
+ 2008-04-13 16:39:23 142,592 ——w c:\winnt\ServicePackFiles\i386\aec.sys
+ 2008-04-13 19:19:23 138,112 ——w c:\winnt\ServicePackFiles\i386\afd.sys
+ 2008-04-14 00:11:48 24,064 ——w c:\winnt\ServicePackFiles\i386\agentanm.dll
+ 2008-04-14 00:11:48 214,016 ——w c:\winnt\ServicePackFiles\i386\agentctl.dll
+ 2008-04-14 00:11:48 42,496 ——w c:\winnt\ServicePackFiles\i386\agentdp2.dll
+ 2008-04-14 00:11:48 57,344 ——w c:\winnt\ServicePackFiles\i386\agentdpv.dll
+ 2008-04-14 00:11:48 49,152 ——w c:\winnt\ServicePackFiles\i386\agentmpx.dll
+ 2008-04-14 00:11:48 24,064 ——w c:\winnt\ServicePackFiles\i386\agentpsh.dll
+ 2008-04-14 00:11:48 44,032 ——w c:\winnt\ServicePackFiles\i386\agentsr.dll
+ 2008-04-14 00:12:12 256,512 ——w c:\winnt\ServicePackFiles\i386\agentsvr.exe
+ 2008-04-13 18:36:38 42,368 ——w c:\winnt\ServicePackFiles\i386\agp440.sys
+ 2008-04-13 18:36:39 44,928 ——w c:\winnt\ServicePackFiles\i386\agpcpq.sys
+ 2007-04-02 18:25:59 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0401.dll
+ 2007-04-02 18:25:59 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0404.dll
+ 2007-04-02 18:25:59 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0405.dll
+ 2007-04-02 18:25:59 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0406.dll
+ 2007-04-02 18:26:00 21,504 ——w c:\winnt\ServicePackFiles\i386\agt0407.dll
+ 2007-04-02 18:26:00 22,016 ——w c:\winnt\ServicePackFiles\i386\agt0408.dll
+ 2008-04-13 17:32:28 19,968 ——w c:\winnt\ServicePackFiles\i386\agt0409.dll
+ 2007-04-02 18:26:00 19,456 ——w c:\winnt\ServicePackFiles\i386\agt040b.dll
+ 2007-04-02 18:26:00 21,504 ——w c:\winnt\ServicePackFiles\i386\agt040c.dll
+ 2007-04-02 18:26:00 19,456 ——w c:\winnt\ServicePackFiles\i386\agt040d.dll
+ 2007-04-02 18:26:00 19,968 ——w c:\winnt\ServicePackFiles\i386\agt040e.dll
+ 2007-04-02 18:26:00 20,992 ——w c:\winnt\ServicePackFiles\i386\agt0410.dll
+ 2007-04-02 18:26:00 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0411.dll
+ 2007-04-02 18:26:00 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0412.dll
+ 2007-04-02 18:26:01 20,992 ——w c:\winnt\ServicePackFiles\i386\agt0413.dll
+ 2007-04-02 18:26:01 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0414.dll
+ 2007-04-02 18:26:01 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0415.dll
+ 2007-04-02 18:26:01 20,480 ——w c:\winnt\ServicePackFiles\i386\agt0416.dll
+ 2007-04-02 18:26:01 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0419.dll
+ 2007-04-02 18:26:01 19,456 ——w c:\winnt\ServicePackFiles\i386\agt041d.dll
+ 2007-04-02 18:26:01 19,456 ——w c:\winnt\ServicePackFiles\i386\agt041f.dll
+ 2007-04-02 18:26:02 19,456 ——w c:\winnt\ServicePackFiles\i386\agt0804.dll
+ 2007-04-02 18:26:02 20,992 ——w c:\winnt\ServicePackFiles\i386\agt0816.dll
+ 2007-04-02 18:26:02 20,480 ——w c:\winnt\ServicePackFiles\i386\agt0c0a.dll
+ 2008-04-14 00:11:49 24,064 ——w c:\winnt\ServicePackFiles\i386\agtintl.dll
+ 2008-04-14 00:12:12 98,304 ——w c:\winnt\ServicePackFiles\i386\ahui.exe
+ 2008-04-14 00:12:12 44,544 ——w c:\winnt\ServicePackFiles\i386\alg.exe
+ 2008-04-13 18:36:38 42,752 ——w c:\winnt\ServicePackFiles\i386\alim1541.sys
+ 2008-04-14 00:11:49 17,408 ——w c:\winnt\ServicePackFiles\i386\alrsvc.dll
+ 2008-04-13 18:36:39 43,008 ——w c:\winnt\ServicePackFiles\i386\amdagp.sys
+ 2008-04-13 18:31:32 37,376 ——w c:\winnt\ServicePackFiles\i386\amdk6.sys
+ 2008-04-13 18:31:33 37,760 ——w c:\winnt\ServicePackFiles\i386\amdk7.sys
+ 2008-04-14 00:11:49 70,656 ——w c:\winnt\ServicePackFiles\i386\amstream.dll
+ 2004-08-04 03:31:20 36,224 ——w c:\winnt\ServicePackFiles\i386\an983.sys
+ 2008-04-14 00:11:49 108,544 ——w c:\winnt\ServicePackFiles\i386\appconf.dll
+ 2008-04-14 00:11:49 125,952 ——w c:\winnt\ServicePackFiles\i386\apphelp.dll
+ 2008-04-14 00:11:49 167,936 ——w c:\winnt\ServicePackFiles\i386\appmgmts.dll
+ 2008-04-14 00:11:49 295,936 ——w c:\winnt\ServicePackFiles\i386\appmgr.dll
+ 2008-04-14 00:11:49 331,264 ——w c:\winnt\ServicePackFiles\i386\aqueue.dll
+ 2008-04-13 18:51:25 60,800 ——w c:\winnt\ServicePackFiles\i386\arp1394.sys
+ 2008-04-14 00:11:49 369,664 ——w c:\winnt\ServicePackFiles\i386\asp51.dll
+ 2008-04-13 16:09:58 20,480 ——w c:\winnt\ServicePackFiles\i386\aspnet_filter.dll
+ 2008-04-13 16:09:59 200,704 ——w c:\winnt\ServicePackFiles\i386\aspnet_isapi.dll
+ 2008-04-13 16:10:01 24,576 ——w c:\winnt\ServicePackFiles\i386\aspnet_regiis.exe
+ 2008-04-13 16:10:01 32,768 ——w c:\winnt\ServicePackFiles\i386\aspnet_state.exe
+ 2008-04-13 16:10:01 32,768 ——w c:\winnt\ServicePackFiles\i386\aspnet_wp.exe
+ 2008-04-14 00:12:12 30,208 ——w c:\winnt\ServicePackFiles\i386\asr_fmt.exe
+ 2008-04-14 00:12:12 32,768 ——w c:\winnt\ServicePackFiles\i386\asr_pfu.exe
+ 2008-04-14 00:11:49 65,024 ——w c:\winnt\ServicePackFiles\i386\asycfilt.dll
+ 2008-04-13 18:57:27 14,336 ——w c:\winnt\ServicePackFiles\i386\asyncmac.sys
+ 2008-04-14 00:12:12 25,088 ——w c:\winnt\ServicePackFiles\i386\at.exe
+ 2008-04-13 18:40:30 96,512 ——w c:\winnt\ServicePackFiles\i386\atapi.sys
+ 2004-08-04 03:29:30 56,623 ——w c:\winnt\ServicePackFiles\i386\ati1btxx.sys
+ 2004-08-04 03:29:30 11,615 ——w c:\winnt\ServicePackFiles\i386\ati1mdxx.sys
+ 2004-08-04 03:29:30 12,047 ——w c:\winnt\ServicePackFiles\i386\ati1pdxx.sys
+ 2004-08-04 03:29:32 30,671 ——w c:\winnt\ServicePackFiles\i386\ati1raxx.sys
+ 2004-08-04 03:29:32 63,663 ——w c:\winnt\ServicePackFiles\i386\ati1rvxx.sys
+ 2004-08-04 03:29:32 26,367 ——w c:\winnt\ServicePackFiles\i386\ati1snxx.sys
+ 2004-08-04 03:29:32 21,343 ——w c:\winnt\ServicePackFiles\i386\ati1ttxx.sys
+ 2004-08-04 03:29:32 36,463 ——w c:\winnt\ServicePackFiles\i386\ati1tuxx.sys
+ 2004-08-04 03:29:32 29,455 ——w c:\winnt\ServicePackFiles\i386\ati1xbxx.sys
+ 2004-08-04 03:29:32 34,735 ——w c:\winnt\ServicePackFiles\i386\ati1xsxx.sys
+ 2008-04-14 00:11:49 229,376 ——w c:\winnt\ServicePackFiles\i386\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ——w c:\winnt\ServicePackFiles\i386\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ——w c:\winnt\ServicePackFiles\i386\ati2dvag.dll
+ 2004-08-04 03:29:28 327,040 ——w c:\winnt\ServicePackFiles\i386\ati2mtaa.sys
+ 2004-08-04 03:29:28 701,440 ——w c:\winnt\ServicePackFiles\i386\ati2mtag.sys
+ 2008-04-14 00:11:49 870,784 ——w c:\winnt\ServicePackFiles\i386\ati3d1ag.dll
+ 2008-04-14 00:11:49 1,057,760 ——w c:\winnt\ServicePackFiles\i386\ati3d2ag.dll
+ 2008-04-14 00:11:50 1,888,992 ——w c:\winnt\ServicePackFiles\i386\ati3duag.dll
+ 2004-08-04 03:29:28 57,856 ——w c:\winnt\ServicePackFiles\i386\atinbtxx.sys
+ 2004-08-04 03:29:30 13,824 ——w c:\winnt\ServicePackFiles\i386\atinmdxx.sys
+ 2004-08-04 03:29:30 14,336 ——w c:\winnt\ServicePackFiles\i386\atinpdxx.sys
+ 2004-08-04 03:29:30 52,224 ——w c:\winnt\ServicePackFiles\i386\atinraxx.sys
+ 2004-08-04 03:29:32 104,960 ——w c:\winnt\ServicePackFiles\i386\atinrvxx.sys
+ 2004-08-04 03:29:32 28,672 ——w c:\winnt\ServicePackFiles\i386\atinsnxx.sys
+ 2004-08-04 03:29:32 13,824 ——w c:\winnt\ServicePackFiles\i386\atinttxx.sys
+ 2004-08-04 03:29:32 73,216 ——w c:\winnt\ServicePackFiles\i386\atintuxx.sys
+ 2004-08-04 03:29:32 31,744 ——w c:\winnt\ServicePackFiles\i386\atinxbxx.sys
+ 2004-08-04 03:29:32 63,488 ——w c:\winnt\ServicePackFiles\i386\atinxsxx.sys
+ 2008-04-14 00:11:50 32,768 ——w c:\winnt\ServicePackFiles\i386\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ——w c:\winnt\ServicePackFiles\i386\ativvaxx.dll
+ 2008-04-14 00:11:50 58,880 ——w c:\winnt\ServicePackFiles\i386\atl.dll
+ 2008-04-14 00:12:12 11,264 ——w c:\winnt\ServicePackFiles\i386\atmadm.exe
+ 2008-04-13 18:51:25 59,904 ——w c:\winnt\ServicePackFiles\i386\atmarpc.sys
+ 2008-04-14 00:09:01 285,696 ——w c:\winnt\ServicePackFiles\i386\atmfd.dll
+ 2008-04-13 18:51:30 55,808 ——w c:\winnt\ServicePackFiles\i386\atmlane.sys
+ 2008-04-14 00:11:50 30,208 ——w c:\winnt\ServicePackFiles\i386\atmlib.dll
+ 2008-04-14 00:12:12 12,288 ——w c:\winnt\ServicePackFiles\i386\attrib.exe
+ 2008-04-14 00:11:50 21,183 ——w c:\winnt\ServicePackFiles\i386\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ——w c:\winnt\ServicePackFiles\i386\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ——w c:\winnt\ServicePackFiles\i386\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ——w c:\winnt\ServicePackFiles\i386\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ——w c:\winnt\ServicePackFiles\i386\atv10nt5.dll
+ 2008-04-14 00:11:50 42,496 ——w c:\winnt\ServicePackFiles\i386\audiosrv.dll
+ 2008-04-14 00:12:12 14,336 ——w c:\winnt\ServicePackFiles\i386\auditusr.exe
+ 2008-04-14 00:11:50 20,540 ——w c:\winnt\ServicePackFiles\i386\author.dll
+ 2008-04-14 00:12:12 16,439 ——w c:\winnt\ServicePackFiles\i386\author.exe
+ 2008-04-14 00:11:50 62,464 ——w c:\winnt\ServicePackFiles\i386\authz.dll
+ 2008-04-14 00:12:12 588,800 ——w c:\winnt\ServicePackFiles\i386\autochk.exe
+ 2008-04-14 00:12:12 602,624 ——w c:\winnt\ServicePackFiles\i386\autoconv.exe
+ 2008-04-14 00:12:13 580,608 ——w c:\winnt\ServicePackFiles\i386\autofmt.exe
+ 2008-04-14 00:12:13 11,264 ——w c:\winnt\ServicePackFiles\i386\autolfn.exe
+ 2008-04-13 18:46:20 38,912 ——w c:\winnt\ServicePackFiles\i386\avc.sys
+ 2008-04-13 18:46:07 13,696 ——w c:\winnt\ServicePackFiles\i386\avcstrm.sys
+ 2008-04-14 00:11:50 84,992 ——w c:\winnt\ServicePackFiles\i386\avifil32.dll
+ 2008-04-14 00:11:50 233,472 ——w c:\winnt\ServicePackFiles\i386\azroles.dll
+ 2008-04-14 00:11:50 52,736 ——w c:\winnt\ServicePackFiles\i386\basesrv.dll
+ 2008-04-14 00:11:50 29,184 ——w c:\winnt\ServicePackFiles\i386\batmeter.dll
+ 2008-04-14 00:11:50 8,704 ——w c:\winnt\ServicePackFiles\i386\batt.dll
+ 2008-04-13 18:36:32 14,208 ——w c:\winnt\ServicePackFiles\i386\battc.sys
+ 2008-04-13 18:46:21 11,776 ——w c:\winnt\ServicePackFiles\i386\bdasup.sys
+ 2008-04-14 00:11:50 17,408 ——w c:\winnt\ServicePackFiles\i386\bidispl.dll
+ 2008-04-14 00:11:50 8,192 ——w c:\winnt\ServicePackFiles\i386\bitsprx2.dll
+ 2008-04-14 00:11:50 7,168 ——w c:\winnt\ServicePackFiles\i386\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ——w c:\winnt\ServicePackFiles\i386\bitsprx4.dll
+ 2008-04-14 00:12:13 71,680 ——w c:\winnt\ServicePackFiles\i386\blastcln.exe
+ 2008-04-14 00:12:13 142,848 ——w c:\winnt\ServicePackFiles\i386\bootcfg.exe
+ 2008-04-13 18:53:23 71,552 ——w c:\winnt\ServicePackFiles\i386\bridge.sys
+ 2008-04-13 17:03:24 63,488 ——w c:\winnt\ServicePackFiles\i386\browselc.dll
+ 2008-04-14 00:11:50 77,824 ——w c:\winnt\ServicePackFiles\i386\browser.dll
+ 2008-04-14 00:11:50 1,025,024 ——w c:\winnt\ServicePackFiles\i386\browseui.dll
+ 2008-04-14 00:11:50 78,336 ——w c:\winnt\ServicePackFiles\i386\browsewm.dll
+ 2008-04-14 00:11:50 20,992 ——w c:\winnt\ServicePackFiles\i386\bthci.dll
+ 2008-04-13 18:46:33 17,024 ——w c:\winnt\ServicePackFiles\i386\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ——w c:\winnt\ServicePackFiles\i386\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ——w c:\winnt\ServicePackFiles\i386\bthpan.sys
+ 2008-04-13 18:46:32 273,024 ——w c:\winnt\ServicePackFiles\i386\bthport.sys
+ 2008-04-13 18:46:31 36,480 ——w c:\winnt\ServicePackFiles\i386\bthprint.sys
+ 2008-04-14 00:11:50 30,208 ——w c:\winnt\ServicePackFiles\i386\bthserv.dll
+ 2008-04-13 18:46:29 18,944 ——w c:\winnt\ServicePackFiles\i386\bthusb.sys
+ 2008-04-14 00:11:50 50,688 ——w c:\winnt\ServicePackFiles\i386\btpanui.dll
+ 2008-04-14 00:11:50 218,112 ——w c:\winnt\ServicePackFiles\i386\c_g18030.dll
+ 2008-04-14 00:11:50 60,416 ——w c:\winnt\ServicePackFiles\i386\cabinet.dll
+ 2008-04-14 00:11:50 84,480 ——w c:\winnt\ServicePackFiles\i386\cabview.dll
+ 2008-04-14 00:12:13 19,968 ——w c:\winnt\ServicePackFiles\i386\cacls.exe
+ 2008-04-14 00:11:50 385,024 ——w c:\winnt\ServicePackFiles\i386\callcont.dll
+ 2008-04-14 00:11:50 121,856 ——w c:\winnt\ServicePackFiles\i386\camext30.dll
+ 2008-04-14 00:11:50 50,688 ——w c:\winnt\ServicePackFiles\i386\camocx.dll
+ 2008-04-14 00:11:50 150,016 ——w c:\winnt\ServicePackFiles\i386\capesnpn.dll
+ 2004-07-15 15:05:24 94,208 ——w c:\winnt\ServicePackFiles\i386\caspol.exe
+ 2008-04-14 00:11:50 226,304 ——w c:\winnt\ServicePackFiles\i386\catsrv.dll
+ 2008-04-14 00:11:50 85,504 ——w c:\winnt\ServicePackFiles\i386\catsrvps.dll
+ 2008-04-14 00:11:50 625,664 ——w c:\winnt\ServicePackFiles\i386\catsrvut.dll
+ 2008-04-13 18:46:23 17,024 ——w c:\winnt\ServicePackFiles\i386\ccdecode.sys
+ 2008-04-13 19:14:21 63,744 ——w c:\winnt\ServicePackFiles\i386\cdfs.sys
+ 2008-04-14 00:11:50 151,040 ——w c:\winnt\ServicePackFiles\i386\cdfview.dll
+ 2008-04-14 00:11:50 66,560 ——w c:\winnt\ServicePackFiles\i386\cdm.dll
+ 2008-04-14 00:11:50 2,091,520 ——w c:\winnt\ServicePackFiles\i386\cdosys.dll
+ 2008-04-13 18:40:46 62,976 ——w c:\winnt\ServicePackFiles\i386\cdrom.sys
+ 2008-04-14 00:11:50 194,560 ——w c:\winnt\ServicePackFiles\i386\certcli.dll
+ 2008-04-14 00:11:50 457,728 ——w c:\winnt\ServicePackFiles\i386\certmgr.dll
+ 2008-04-14 00:11:50 38,912 ——w c:\winnt\ServicePackFiles\i386\cfgbkend.dll
+ 2008-04-14 00:09:05 16,896 ——w c:\winnt\ServicePackFiles\i386\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 ——w c:\winnt\ServicePackFiles\i386\cfgwiz.exe
+ 2008-04-14 00:11:50 15,423 ——w c:\winnt\ServicePackFiles\i386\ch7xxnt5.dll
+ 2008-04-13 18:40:58 8,192 ——w c:\winnt\ServicePackFiles\i386\changer.sys
+ 2008-04-14 00:11:50 148,480 ——w c:\winnt\ServicePackFiles\i386\cic.dll
+ 2008-04-14 00:11:50 1,358,848 ——w c:\winnt\ServicePackFiles\i386\cimwin32.dll
+ 2008-04-14 00:11:50 69,120 ——w c:\winnt\ServicePackFiles\i386\ciodm.dll
+ 2008-04-14 00:12:14 56,832 ——w c:\winnt\ServicePackFiles\i386\cipher.exe
+ 2008-04-14 00:12:14 5,632 ——w c:\winnt\ServicePackFiles\i386\cisvc.exe
+ 2008-04-13 19:16:22 49,536 ——w c:\winnt\ServicePackFiles\i386\classpnp.sys
+ 2008-04-14 00:11:50 110,592 ——w c:\winnt\ServicePackFiles\i386\clbcatex.dll
+ 2008-04-14 00:11:50 498,688 ——w c:\winnt\ServicePackFiles\i386\clbcatq.dll
+ 2008-04-14 00:12:14 64,000 ——w c:\winnt\ServicePackFiles\i386\cleanmgr.exe
+ 2008-04-14 00:11:50 77,824 ——w c:\winnt\ServicePackFiles\i386\cliconfg.dll
+ 2008-04-14 00:12:14 20,480 ——w c:\winnt\ServicePackFiles\i386\cliconfg.exe
+ 2008-04-14 00:12:14 102,912 ——w c:\winnt\ServicePackFiles\i386\clipbrd.exe
+ 2008-04-14 00:12:14 33,280 ——w c:\winnt\ServicePackFiles\i386\clipsrv.exe
+ 2008-04-14 00:11:50 58,368 ——w c:\winnt\ServicePackFiles\i386\clusapi.dll
+ 2008-04-13 18:36:37 13,952 ——w c:\winnt\ServicePackFiles\i386\cmbatt.sys
+ 2008-04-14 00:11:50 15,872 ——w c:\winnt\ServicePackFiles\i386\cmcfg32.dll
+ 2008-04-14 00:12:14 389,120 ——w c:\winnt\ServicePackFiles\i386\cmd.exe
+ 2008-04-14 00:11:50 344,064 ——w c:\winnt\ServicePackFiles\i386\cmdial32.dll
+ 2008-04-14 00:12:14 25,600 ——w c:\winnt\ServicePackFiles\i386\cmdl32.exe
+ 2008-04-14 00:12:15 39,936 ——w c:\winnt\ServicePackFiles\i386\cmmon32.exe
+ 2008-04-14 00:11:50 185,344 ——w c:\winnt\ServicePackFiles\i386\cmprops.dll
+ 2008-04-14 00:11:50 13,312 ——w c:\winnt\ServicePackFiles\i386\cmsetacl.dll
+ 2008-04-14 00:12:15 63,488 ——w c:\winnt\ServicePackFiles\i386\cmstp.exe
+ 2008-04-14 00:11:50 39,424 ——w c:\winnt\ServicePackFiles\i386\cmutil.dll
+ 2008-04-14 00:11:50 47,104 ——w c:\winnt\ServicePackFiles\i386\cnbjmon.dll
+ 2008-04-14 00:11:50 79,360 ——w c:\winnt\ServicePackFiles\i386\cnbjmon2.dll
+ 2008-04-14 00:11:51 46,592 ——w c:\winnt\ServicePackFiles\i386\coadmin.dll
+ 2008-04-13 16:44:16 17,920 ——w c:\winnt\ServicePackFiles\i386\cobramsg.dll
+ 2008-04-14 00:11:51 60,416 ——w c:\winnt\ServicePackFiles\i386\colbact.dll
+ 2008-04-14 00:11:51 28,160 ——w c:\winnt\ServicePackFiles\i386\comaddin.dll
+ 2008-04-14 00:11:51 195,072 ——w c:\winnt\ServicePackFiles\i386\comadmin.dll
+ 2008-04-14 00:11:51 617,472 ——w c:\winnt\ServicePackFiles\i386\comctl32.dll
+ 2008-04-14 00:11:51 276,992 ——w c:\winnt\ServicePackFiles\i386\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 ——w c:\winnt\ServicePackFiles\i386\compatui.dll
+ 2008-04-13 18:36:37 10,240 ——w c:\winnt\ServicePackFiles\i386\compbatt.sys
+ 2008-04-14 00:11:51 24,064 ——w c:\winnt\ServicePackFiles\i386\compfilt.dll
+ 2008-04-14 00:11:51 229,376 ——w c:\winnt\ServicePackFiles\i386\compstui.dll
+ 2008-04-14 00:11:51 97,792 ——w c:\winnt\ServicePackFiles\i386\comrepl.dll
+ 2008-04-14 00:12:15 9,728 ——w c:\winnt\ServicePackFiles\i386\comrepl.exe
+ 2008-04-14 00:12:15 6,144 ——w c:\winnt\ServicePackFiles\i386\comrereg.exe
+ 2008-04-14 00:11:51 792,064 ——w c:\winnt\ServicePackFiles\i386\comres.dll
+ 2008-04-13 18:43:32 9,728 ——w c:\winnt\ServicePackFiles\i386\comsdupd.exe
+ 2008-04-14 00:11:51 274,944 ——w c:\winnt\ServicePackFiles\i386\comsetup.dll
+ 2008-04-14 00:11:51 167,424 ——w c:\winnt\ServicePackFiles\i386\comsnap.dll
+ 2008-04-14 00:11:51 1,267,200 ——w c:\winnt\ServicePackFiles\i386\comsvcs.dll
+ 2008-04-14 00:11:51 539,648 ——w c:\winnt\ServicePackFiles\i386\comuid.dll
+ 2008-04-14 00:12:15 1,032,192 ——w c:\winnt\ServicePackFiles\i386\conf.exe
+ 2008-04-14 00:11:51 45,056 ——w c:\winnt\ServicePackFiles\i386\confmrsl.dll
+ 2008-04-14 00:11:51 357,888 ——w c:\winnt\ServicePackFiles\i386\confmsp.dll
+ 2008-04-14 00:12:15 27,648 ——w c:\winnt\ServicePackFiles\i386\conime.exe
+ 2004-07-15 02:50:22 69,632 ——w c:\winnt\ServicePackFiles\i386\corperfmonext.dll
+ 2008-04-14 00:11:51 35,328 ——w c:\winnt\ServicePackFiles\i386\corpol.dll
+ 2008-04-14 00:11:51 12,800 ——w c:\winnt\ServicePackFiles\i386\credssp.dll
+ 2008-04-14 00:11:51 163,840 ——w c:\winnt\ServicePackFiles\i386\credui.dll
+ 2008-04-13 18:31:32 36,736 ——w c:\winnt\ServicePackFiles\i386\crusoe.sys
+ 2008-04-14 00:11:51 599,040 ——w c:\winnt\ServicePackFiles\i386\crypt32.dll
+ 2008-04-14 00:11:51 74,752 ——w c:\winnt\ServicePackFiles\i386\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 ——w c:\winnt\ServicePackFiles\i386\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 ——w c:\winnt\ServicePackFiles\i386\cryptext.dll
+ 2008-04-14 00:11:51 64,512 ——w c:\winnt\ServicePackFiles\i386\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 ——w c:\winnt\ServicePackFiles\i386\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 ——w c:\winnt\ServicePackFiles\i386\cryptui.dll
+ 2008-04-13 16:10:13 49,152 ——w c:\winnt\ServicePackFiles\i386\csc.exe
+ 2008-04-14 00:11:51 101,888 ——w c:\winnt\ServicePackFiles\i386\cscdll.dll
+ 2007-06-27 12:53:47 589,824 ——w c:\winnt\ServicePackFiles\i386\cscomp.dll
+ 2008-04-14 00:12:15 139,264 ——w c:\winnt\ServicePackFiles\i386\cscript.exe
+ 2008-04-14 00:11:51 326,656 ——w c:\winnt\ServicePackFiles\i386\cscui.dll
+ 2008-04-14 00:11:51 32,256 ——w c:\winnt\ServicePackFiles\i386\csrsrv.dll
+ 2008-04-14 00:12:15 6,144 ——w c:\winnt\ServicePackFiles\i386\csrss.exe
+ 2008-04-14 00:12:16 15,360 ——w c:\winnt\ServicePackFiles\i386\ctfmon.exe
+ 2008-04-14 00:11:51 249,856 ——w c:\winnt\ServicePackFiles\i386\ctmasetp.dll
+ 2008-04-14 00:11:51 33,792 ——w c:\winnt\ServicePackFiles\i386\custsat.dll
+ 2004-08-04 03:32:26 48,640 ——w c:\winnt\ServicePackFiles\i386\cwrwdm.sys
+ 2008-04-14 00:11:51 1,179,648 ——w c:\winnt\ServicePackFiles\i386\d3d8.dll
+ 2008-04-14 00:11:51 8,192 ——w c:\winnt\ServicePackFiles\i386\d3d8thk.dll
+ 2008-04-14 00:11:51 1,689,088 ——w c:\winnt\ServicePackFiles\i386\d3d9.dll
+ 2008-04-14 00:11:51 824,320 ——w c:\winnt\ServicePackFiles\i386\d3dim700.dll
+ 2008-04-14 00:11:51 1,054,208 ——w c:\winnt\ServicePackFiles\i386\danim.dll
+ 2008-03-25 04:50:25 554,008 ——w c:\winnt\ServicePackFiles\i386\dao360.dll
+ 2008-04-14 00:11:51 54,272 ——w c:\winnt\ServicePackFiles\i386\dataclen.dll
+ 2008-04-14 00:11:51 165,376 ——w c:\winnt\ServicePackFiles\i386\datime.dll
+ 2008-04-14 00:12:16 42,496 ——w c:\winnt\ServicePackFiles\i386\davcdata.exe
+ 2008-04-14 00:11:51 25,088 ——w c:\winnt\ServicePackFiles\i386\davclnt.dll
+ 2008-04-14 00:11:51 640,000 ——w c:\winnt\ServicePackFiles\i386\dbghelp.dll
+ 2008-04-14 00:11:51 24,576 ——w c:\winnt\ServicePackFiles\i386\dbmsrpcn.dll
+ 2008-04-14 00:11:51 110,592 ——w c:\winnt\ServicePackFiles\i386\dbnetlib.dll
+ 2008-04-14 00:11:51 28,672 ——w c:\winnt\ServicePackFiles\i386\dbnmpntw.dll
+ 2008-04-14 00:25:26 1,804 ——w c:\winnt\ServicePackFiles\i386\dcache.bin
+ 2008-04-14 00:11:51 40,960 ——w c:\winnt\ServicePackFiles\i386\dcap32.dll
+ 2008-04-14 00:11:51 8,704 ——w c:\winnt\ServicePackFiles\i386\dciman32.dll
+ 2008-04-14 00:12:16 6,144 ——w c:\winnt\ServicePackFiles\i386\dcomcnfg.exe
+ 2008-04-14 00:12:16 30,208 ——w c:\winnt\ServicePackFiles\i386\ddeshare.exe
+ 2008-04-14 00:11:51 279,552 ——w c:\winnt\ServicePackFiles\i386\ddraw.dll
+ 2008-04-14 00:11:51 27,136 ——w c:\winnt\ServicePackFiles\i386\ddrawex.dll
+ 2008-04-14 00:12:16 25,088 ——w c:\winnt\ServicePackFiles\i386\defrag.exe
+ 2008-04-14 00:11:51 59,904 ——w c:\winnt\ServicePackFiles\i386\devenum.dll
+ 2008-04-14 00:11:51 282,624 ——w c:\winnt\ServicePackFiles\i386\devmgr.dll
+ 2008-04-14 00:12:16 82,944 ——w c:\winnt\ServicePackFiles\i386\dfrgfat.exe
+ 2008-04-14 00:12:16 105,472 ——w c:\winnt\ServicePackFiles\i386\dfrgntfs.exe
+ 2008-04-14 00:11:51 39,424 ——w c:\winnt\ServicePackFiles\i386\dfrgsnap.dll
+ 2008-04-14 00:11:51 124,416 ——w c:\winnt\ServicePackFiles\i386\dfrgui.dll
+ 2008-04-14 00:11:51 28,672 ——w c:\winnt\ServicePackFiles\i386\dfsshlex.dll
+ 2008-04-14 00:11:51 111,104 ——w c:\winnt\ServicePackFiles\i386\dgnet.dll
+ 2008-04-14 00:11:51 126,976 ——w c:\winnt\ServicePackFiles\i386\dhcpcsvc.dll
+ 2008-04-14 00:11:52 379,904 ——w c:\winnt\ServicePackFiles\i386\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ——w c:\winnt\ServicePackFiles\i386\dhcpqec.dll
+ 2008-04-14 00:12:17 539,136 ——w c:\winnt\ServicePackFiles\i386\dialer.exe
+ 2008-04-14 00:12:17 87,040 ——w c:\winnt\ServicePackFiles\i386\diantz.exe
+ 2007-04-02 18:34:11 884,712 ——w c:\winnt\ServicePackFiles\i386\digcore.exe
+ 2008-04-14 00:11:52 68,608 ——w c:\winnt\ServicePackFiles\i386\digest.dll
+ 2008-04-14 00:11:52 19,456 ——w c:\winnt\ServicePackFiles\i386\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ——w c:\winnt\ServicePackFiles\i386\dimsroam.dll
+ 2008-04-14 00:11:52 158,720 ——w c:\winnt\ServicePackFiles\i386\dinput.dll
+ 2008-04-14 00:11:52 181,760 ——w c:\winnt\ServicePackFiles\i386\dinput8.dll
+ 2008-04-14 00:11:52 86,528 ——w c:\winnt\ServicePackFiles\i386\directdb.dll
+ 2008-04-13 18:40:47 36,352 ——w c:\winnt\ServicePackFiles\i386\disk.sys
+ 2008-04-14 00:11:52 1,504,256 ——w c:\winnt\ServicePackFiles\i386\diskcopy.dll
+ 2008-04-13 18:40:44 14,208 ——w c:\winnt\ServicePackFiles\i386\diskdump.sys
+ 2008-04-14 00:12:17 163,840 ——w c:\winnt\ServicePackFiles\i386\diskpart.exe
+ 2008-04-14 00:11:52 32,768 ——w c:\winnt\ServicePackFiles\i386\dispex.dll
+ 2008-04-14 00:12:17 5,120 ——w c:\winnt\ServicePackFiles\i386\dllhost.exe
+ 2008-04-13 18:40:51 8,320 ——w c:\winnt\ServicePackFiles\i386\dlttape.sys
+ 2008-04-14 00:12:17 224,768 ——w c:\winnt\ServicePackFiles\i386\dmadmin.exe
+ 2008-04-14 00:11:52 28,672 ——w c:\winnt\ServicePackFiles\i386\dmband.dll
+ 2008-04-13 18:44:48 799,744 ——w c:\winnt\ServicePackFiles\i386\dmboot.sys
+ 2008-04-14 00:11:52 61,440 ——w c:\winnt\ServicePackFiles\i386\dmcompos.dll
+ 2008-04-14 00:11:52 285,184 ——w c:\winnt\ServicePackFiles\i386\dmdlgs.dll
+ 2008-04-14 00:11:52 200,704 ——w c:\winnt\ServicePackFiles\i386\dmdskmgr.dll
+ 2008-04-14 00:11:52 181,248 ——w c:\winnt\ServicePackFiles\i386\dmime.dll
+ 2008-04-13 18:44:46 153,344 ——w c:\winnt\ServicePackFiles\i386\dmio.sys
+ 2008-04-14 00:11:52 35,840 ——w c:\winnt\ServicePackFiles\i386\dmloader.dll
+ 2008-04-14 00:12:17 15,872 ——w c:\winnt\ServicePackFiles\i386\dmremote.exe
+ 2008-04-14 00:11:52 82,432 ——w c:\winnt\ServicePackFiles\i386\dmscript.dll
+ 2008-04-14 00:11:52 23,552 ——w c:\winnt\ServicePackFiles\i386\dmserver.dll
+ 2008-04-14 00:11:52 105,984 ——w c:\winnt\ServicePackFiles\i386\dmstyle.dll
+ 2008-04-14 00:11:52 103,424 ——w c:\winnt\ServicePackFiles\i386\dmsynth.dll
+ 2008-04-14 00:11:52 104,448 ——w c:\winnt\ServicePackFiles\i386\dmusic.dll
+ 2008-04-13 18:45:01 52,864 ——w c:\winnt\ServicePackFiles\i386\dmusic.sys
+ 2008-04-14 00:11:52 52,224 ——w c:\winnt\ServicePackFiles\i386\dmutil.dll
+ 2008-04-14 00:11:52 147,968 ——w c:\winnt\ServicePackFiles\i386\dnsapi.dll
+ 2008-04-14 00:11:52 45,568 ——w c:\winnt\ServicePackFiles\i386\dnsrslvr.dll
+ 2008-04-14 00:11:52 48,128 ——w c:\winnt\ServicePackFiles\i386\docprop2.dll
+ 2004-08-03 20:51:22 53,840 ——w c:\winnt\ServicePackFiles\i386\dosx.exe
+ 2008-04-14 00:11:52 26,112 ——w c:\winnt\ServicePackFiles\i386\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ——w c:\winnt\ServicePackFiles\i386\dot3cfg.dll
+ 2008-04-14 00:11:52 39,936 ——w c:\winnt\ServicePackFiles\i386\dot3clnt.dll
+ 2008-04-14 00:11:52 9,216 ——w c:\winnt\ServicePackFiles\i386\dot3dlg.dll
+ 2008-04-14 00:11:52 56,320 ——w c:\winnt\ServicePackFiles\i386\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ——w c:\winnt\ServicePackFiles\i386\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ——w c:\winnt\ServicePackFiles\i386\dot3ui.dll
+ 2008-04-13 18:39:46 206,976 ——w c:\winnt\ServicePackFiles\i386\dot4.sys
+ 2008-04-14 00:11:52 102,912 ——w c:\winnt\ServicePackFiles\i386\dpcdll.dll
+ 2008-04-14 00:12:17 29,696 ——w c:\winnt\ServicePackFiles\i386\dplaysvr.exe
+ 2008-04-14 00:11:52 229,888 ——w c:\winnt\ServicePackFiles\i386\dplayx.dll
+ 2008-04-14 00:11:52 23,552 ——w c:\winnt\ServicePackFiles\i386\dpmodemx.dll
+ 2008-04-14 00:09:19 3,072 ——w c:\winnt\ServicePackFiles\i386\dpnaddr.dll
+ 2008-04-14 00:11:52 375,296 ——w c:\winnt\ServicePackFiles\i386\dpnet.dll
+ 2008-04-14 00:11:52 35,328 ——w c:\winnt\ServicePackFiles\i386\dpnhpast.dll
+ 2008-04-14 00:11:52 60,928 ——w c:\winnt\ServicePackFiles\i386\dpnhupnp.dll
+ 2008-04-14 00:09:20 3,072 ——w c:\winnt\ServicePackFiles\i386\dpnlobby.dll
+ 2008-04-14 00:12:17 17,920 ——w c:\winnt\ServicePackFiles\i386\dpnsvr.exe
+ 2008-04-14 00:11:52 21,504 ——w c:\winnt\ServicePackFiles\i386\dpvacm.dll
+ 2008-04-14 00:11:52 212,480 ——w c:\winnt\ServicePackFiles\i386\dpvoice.dll
+ 2008-04-14 00:12:18 83,456 ——w c:\winnt\ServicePackFiles\i386\dpvsetup.exe
+ 2008-04-14 00:11:52 116,736 ——w c:\winnt\ServicePackFiles\i386\dpvvox.dll
+ 2008-04-14 00:11:52 57,344 ——w c:\winnt\ServicePackFiles\i386\dpwsockx.dll
+ 2008-04-13 18:45:14 60,160 ——w c:\winnt\ServicePackFiles\i386\drmk.sys
+ 2008-04-13 18:45:13 2,944 ——w c:\winnt\ServicePackFiles\i386\drmkaud.sys
+ 2008-04-14 00:11:52 14,336 ——w c:\winnt\ServicePackFiles\i386\drprov.dll
+ 2008-04-14 00:12:18 62,976 ——w c:\winnt\ServicePackFiles\i386\drvqry.exe
+ 2004-07-17 09:36:44 4,656 ——w c:\winnt\ServicePackFiles\i386\ds16gt.dll
+ 2008-04-14 00:11:52 16,384 ——w c:\winnt\ServicePackFiles\i386\ds32gt.dll
+ 2008-04-14 00:11:52 181,248 ——w c:\winnt\ServicePackFiles\i386\dsdmo.dll
+ 2008-04-14 00:11:52 71,680 ——w c:\winnt\ServicePackFiles\i386\dsdmoprp.dll
+ 2008-04-14 00:11:52 92,672 ——w c:\winnt\ServicePackFiles\i386\dskquota.dll
+ 2008-04-14 00:11:52 155,648 ——w c:\winnt\ServicePackFiles\i386\dskquoui.dll
+ 2008-04-14 00:11:52 367,616 ——w c:\winnt\ServicePackFiles\i386\dsound.dll
+ 2008-04-14 00:11:52 1,293,824 ——w c:\winnt\ServicePackFiles\i386\dsound3d.dll
+ 2008-04-14 00:11:52 142,848 ——w c:\winnt\ServicePackFiles\i386\dsprop.dll
+ 2008-04-13 17:09:30 4,096 ——w c:\winnt\ServicePackFiles\i386\dsprpres.dll
+ 2008-04-14 00:11:52 239,104 ——w c:\winnt\ServicePackFiles\i386\dsquery.dll
+ 2008-04-14 00:11:52 51,200 ——w c:\winnt\ServicePackFiles\i386\dssec.dll
+ 2008-04-13 17:37:57 138,752 ——w c:\winnt\ServicePackFiles\i386\dssenh.dll
+ 2008-04-14 00:11:52 113,152 ——w c:\winnt\ServicePackFiles\i386\dsuiext.dll
+ 2008-04-14 00:11:52 19,456 ——w c:\winnt\ServicePackFiles\i386\dswave.dll
+ 2008-04-14 00:12:18 10,752 ——w c:\winnt\ServicePackFiles\i386\dumprep.exe
+ 2008-04-14 00:11:52 304,128 ——w c:\winnt\ServicePackFiles\i386\duser.dll
+ 2008-04-14 00:12:18 17,920 ——w c:\winnt\ServicePackFiles\i386\dvdupgrd.exe
+ 2008-04-14 00:12:18 180,224 ——w c:\winnt\ServicePackFiles\i386\dwwin.exe
+ 2008-04-14 00:11:52 619,008 ——w c:\winnt\ServicePackFiles\i386\dx7vb.dll
+ 2008-04-14 00:11:52 1,227,264 ——w c:\winnt\ServicePackFiles\i386\dx8vb.dll
+ 2008-04-14 00:12:18 1,298,432 ——w c:\winnt\ServicePackFiles\i386\dxdiag.exe
+ 2008-04-14 00:11:52 2,113,536 ——w c:\winnt\ServicePackFiles\i386\dxdiagn.dll
+ 2008-04-13 18:38:29 71,168 ——w c:\winnt\ServicePackFiles\i386\dxg.sys
+ 2008-04-14 00:11:52 357,888 ——w c:\winnt\ServicePackFiles\i386\dxtmsft.dll
+ 2008-04-14 00:11:52 205,312 ——w c:\winnt\ServicePackFiles\i386\dxtrans.dll
+ 2008-04-14 00:11:52 30,720 ——w c:\winnt\ServicePackFiles\i386\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ——w c:\winnt\ServicePackFiles\i386\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ——w c:\winnt\ServicePackFiles\i386\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ——w c:\winnt\ServicePackFiles\i386\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ——w c:\winnt\ServicePackFiles\i386\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ——w c:\winnt\ServicePackFiles\i386\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ——w c:\winnt\ServicePackFiles\i386\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ——w c:\winnt\ServicePackFiles\i386\eapsvc.dll
+ 2008-04-14 00:11:52 26,624 ——w c:\winnt\ServicePackFiles\i386\efsadu.dll
+ 2008-04-14 00:11:53 183,296 ——w c:\winnt\ServicePackFiles\i386\els.dll
+ 2008-04-14 00:11:53 20,480 ——w c:\winnt\ServicePackFiles\i386\encapi.dll
+ 2008-04-14 00:11:53 186,880 ——w c:\winnt\ServicePackFiles\i386\encdec.dll
+ 2008-04-13 16:26:02 40,960 ——w c:\winnt\ServicePackFiles\i386\ep9res.dll
+ 2004-07-17 16:39:36 120,320 ——w c:\winnt\ServicePackFiles\i386\epcl5res.dll
+ 2008-04-14 00:11:53 23,040 ——w c:\winnt\ServicePackFiles\i386\ersvc.dll
+ 2008-04-14 00:11:53 246,272 ——w c:\winnt\ServicePackFiles\i386\es.dll
+ 2008-04-14 00:11:53 1,082,368 ——w c:\winnt\ServicePackFiles\i386\esent.dll
+ 2008-04-14 00:11:53 247,808 ——w c:\winnt\ServicePackFiles\i386\esscli.dll
+ 2004-08-04 03:32:28 137,088 ——w c:\winnt\ServicePackFiles\i386\essm2e.sys
+ 2008-04-14 00:12:19 193,024 ——w c:\winnt\ServicePackFiles\i386\eudcedit.exe
+ 2008-04-14 00:12:19 50,688 ——w c:\winnt\ServicePackFiles\i386\evcreate.exe
+ 2008-04-14 00:11:53 56,320 ——w c:\winnt\ServicePackFiles\i386\eventlog.dll
+ 2007-06-27 12:54:17 798,720 ——w c:\winnt\ServicePackFiles\i386\eventlogmessages.dll
+ 2008-04-14 00:11:53 101,888 ——w c:\winnt\ServicePackFiles\i386\evntagnt.dll
+ 2008-04-14 00:12:19 24,064 ——w c:\winnt\ServicePackFiles\i386\evntcmd.exe
+ 2008-04-14 00:11:53 21,504 ——w c:\winnt\ServicePackFiles\i386\evntrprv.dll
+ 2008-04-14 00:12:19 92,160 ——w c:\winnt\ServicePackFiles\i386\evntwin.exe
+ 2008-04-14 00:11:53 45,056 ——w c:\winnt\ServicePackFiles\i386\evtgprov.dll
+ 2008-04-14 00:12:19 82,944 ——w c:\winnt\ServicePackFiles\i386\evtrig.exe
+ 2008-04-14 00:12:19 1,033,728 ——w c:\winnt\ServicePackFiles\i386\explorer.exe
+ 2008-04-14 00:11:53 380,445 ——w c:\winnt\ServicePackFiles\i386\expsrv.dll
+ 2008-04-14 00:11:53 14,336 ——w c:\winnt\ServicePackFiles\i386\exstrace.dll
+ 2008-04-14 00:11:53 55,808 ——w c:\winnt\ServicePackFiles\i386\extmgr.dll
+ 2008-04-14 00:12:19 24,064 ——w c:\winnt\ServicePackFiles\i386\extrac32.exe
+ 2008-04-14 00:11:53 125,952 ——w c:\winnt\ServicePackFiles\i386\exts.dll
+ 2008-04-14 00:09:30 7,168 ——w c:\winnt\ServicePackFiles\i386\f3ahvoas.dll
+ 2008-04-13 19:14:29 143,744 ——w c:\winnt\ServicePackFiles\i386\fastfat.sys
+ 2008-04-14 00:11:53 472,064 ——w c:\winnt\ServicePackFiles\i386\fastprox.dll
+ 2008-04-14 00:11:53 80,384 ——w c:\winnt\ServicePackFiles\i386\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ——w c:\winnt\ServicePackFiles\i386\faxpatch.exe
+ 2008-04-13 18:40:25 27,392 ——w c:\winnt\ServicePackFiles\i386\fdc.sys
+ 2008-04-14 00:11:53 124,928 ——w c:\winnt\ServicePackFiles\i386\fde.dll
+ 2008-04-14 00:11:53 73,728 ——w c:\winnt\ServicePackFiles\i386\fdeploy.dll
+ 2008-04-14 00:11:53 21,504 ——w c:\winnt\ServicePackFiles\i386\feclient.dll
+ 2008-04-14 00:11:53 337,920 ——w c:\winnt\ServicePackFiles\i386\filemgmt.dll
+ 2008-04-14 00:12:20 27,136 ——w c:\winnt\ServicePackFiles\i386\findstr.exe
+ 2008-04-13 18:33:28 44,544 ——w c:\winnt\ServicePackFiles\i386\fips.sys
+ 2008-04-14 00:11:53 87,552 ——w c:\winnt\ServicePackFiles\i386\fldrclnr.dll
+ 2008-04-13 18:40:25 20,480 ——w c:\winnt\ServicePackFiles\i386\flpydisk.sys
+ 2008-04-14 00:11:53 16,896 ——w c:\winnt\ServicePackFiles\i386\fltlib.dll
+ 2008-04-14 00:12:20 23,040 ——w c:\winnt\ServicePackFiles\i386\fltmc.exe
+ 2008-04-13 18:32:59 129,792 ——w c:\winnt\ServicePackFiles\i386\fltmgr.sys
+ 2008-04-14 00:11:53 382,976 ——w c:\winnt\ServicePackFiles\i386\fontext.dll
+ 2008-04-14 00:11:53 80,896 ——w c:\winnt\ServicePackFiles\i386\fontsub.dll
+ 2008-04-14 00:12:20 20,992 ——w c:\winnt\ServicePackFiles\i386\fontview.exe
+ 2008-04-14 00:12:20 7,680 ——w c:\winnt\ServicePackFiles\i386\forcedos.exe
+ 2004-08-04 03:31:24 34,173 ——w c:\winnt\ServicePackFiles\i386\forehe.sys
+ 2008-04-14 00:12:42 29,696 ——w c:\winnt\ServicePackFiles\i386\format.com
+ 2008-04-14 00:11:53 32,828 ——w c:\winnt\ServicePackFiles\i386\fp40ext.dll
+ 2008-04-14 00:11:53 184,435 ——w c:\winnt\ServicePackFiles\i386\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 ——w c:\winnt\ServicePackFiles\i386\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 ——w c:\winnt\ServicePackFiles\i386\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 ——w c:\winnt\ServicePackFiles\i386\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 ——w c:\winnt\ServicePackFiles\i386\fp4atxt.dll
+ 2008-04-14 00:11:53 618,605 ——w c:\winnt\ServicePackFiles\i386\fp4autl.dll
+ 2008-04-14 00:11:53 41,020 ——w c:\winnt\ServicePackFiles\i386\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 ——w c:\winnt\ServicePackFiles\i386\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 ——w c:\winnt\ServicePackFiles\i386\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 ——w c:\winnt\ServicePackFiles\i386\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 ——w c:\winnt\ServicePackFiles\i386\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 ——w c:\winnt\ServicePackFiles\i386\fp98swin.exe
+ 2008-04-14 00:12:20 24,632 ——w c:\winnt\ServicePackFiles\i386\fpadmcgi.exe
+ 2008-04-14 00:11:53 20,541 ——w c:\winnt\ServicePackFiles\i386\fpadmdll.dll
+ 2008-04-14 00:12:20 188,494 ——w c:\winnt\ServicePackFiles\i386\fpcount.exe
+ 2008-04-14 00:11:53 94,208 ——w c:\winnt\ServicePackFiles\i386\fpencode.dll
+ 2008-04-14 00:11:53 20,541 ——w c:\winnt\ServicePackFiles\i386\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 ——w c:\winnt\ServicePackFiles\i386\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 ——w c:\winnt\ServicePackFiles\i386\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 ——w c:\winnt\ServicePackFiles\i386\fpremadm.exe
+ 2008-04-14 00:12:20 28,728 ——w c:\winnt\ServicePackFiles\i386\fpsrvadm.exe
+ 2008-04-14 00:09:33 9,344 ——w c:\winnt\ServicePackFiles\i386\framebuf.dll
+ 2008-04-14 00:11:53 185,344 ——w c:\winnt\ServicePackFiles\i386\framedyn.dll
+ 2008-04-14 00:12:20 193,024 ——w c:\winnt\ServicePackFiles\i386\fsquirt.exe
+ 2008-04-14 00:12:20 42,496 ——w c:\winnt\ServicePackFiles\i386\ftp.exe
+ 2008-04-14 00:11:53 6,144 ——w c:\winnt\ServicePackFiles\i386\ftpmib.dll
+ 2008-04-14 00:11:53 125,952 ——w c:\winnt\ServicePackFiles\i386\ftpsv251.dll
+ 2004-07-15 02:48:20 233,472 ——w c:\winnt\ServicePackFiles\i386\fusion.dll
+ 2008-04-14 00:11:53 60,416 ——w c:\winnt\ServicePackFiles\i386\fwcfg.dll
+ 2008-04-14 00:11:53 451,584 ——w c:\winnt\ServicePackFiles\i386\fxsapi.dll
+ 2008-04-14 00:12:21 142,848 ——w c:\winnt\ServicePackFiles\i386\fxsclnt.exe
+ 2008-04-14 00:11:54 72,192 ——w c:\winnt\ServicePackFiles\i386\fxscom.dll
+ 2008-04-14 00:11:54 285,184 ——w c:\winnt\ServicePackFiles\i386\fxscomex.dll
+ 2008-04-14 00:12:21 229,376 ——w c:\winnt\ServicePackFiles\i386\fxscover.exe
+ 2008-04-14 00:11:54 26,624 ——w c:\winnt\ServicePackFiles\i386\fxsdrv.dll
+ 2008-04-14 00:11:54 55,296 ——w c:\winnt\ServicePackFiles\i386\fxsevent.dll
+ 2008-04-14 00:11:54 23,552 ——w c:\winnt\ServicePackFiles\i386\fxsext32.dll
+ 2008-04-14 00:11:54 23,552 ——w c:\winnt\ServicePackFiles\i386\fxsmon.dll
+ 2008-04-14 00:11:54 132,608 ——w c:\winnt\ServicePackFiles\i386\fxsocm.dll
+ 2008-04-14 00:11:54 8,704 ——w c:\winnt\ServicePackFiles\i386\fxsperf.dll
+ 2008-04-14 00:09:33 6,656 ——w c:\winnt\ServicePackFiles\i386\fxsres.dll
+ 2008-04-14 00:11:54 562,176 ——w c:\winnt\ServicePackFiles\i386\fxsst.dll
+ 2008-04-14 00:12:21 267,776 ——w c:\winnt\ServicePackFiles\i386\fxssvc.exe
+ 2008-04-14 00:11:54 246,272 ——w c:\winnt\ServicePackFiles\i386\fxst30.dll
+ 2008-04-14 00:11:54 397,312 ——w c:\winnt\ServicePackFiles\i386\fxstiff.dll
+ 2008-04-14 00:11:54 154,112 ——w c:\winnt\ServicePackFiles\i386\fxsui.dll
+ 2008-04-14 00:11:54 192,512 ——w c:\winnt\ServicePackFiles\i386\fxswzrd.dll
+ 2008-04-14 00:11:54 400,384 ——w c:\winnt\ServicePackFiles\i386\fxsxp32.dll
+ 2008-04-13 18:36:40 46,464 ——w c:\winnt\ServicePackFiles\i386\gagp30kx.sys
+ 2008-04-13 18:45:29 10,624 ——w c:\winnt\ServicePackFiles\i386\gameenum.sys
+ 2008-04-13 18:45:32 59,136 ——w c:\winnt\ServicePackFiles\i386\gckernel.sys
+ 2008-04-14 00:11:54 285,184 ——w c:\winnt\ServicePackFiles\i386\gdi32.dll
+ 2008-04-14 00:12:21 59,904 ——w c:\winnt\ServicePackFiles\i386\getmac.exe
+ 2008-04-14 00:11:54 122,880 ——w c:\winnt\ServicePackFiles\i386\glu32.dll
+ 2008-04-14 00:09:35 566,784 ——w c:\winnt\ServicePackFiles\i386\gpedit.dll
+ 2004-08-03 20:31:44 101,888 ——w c:\winnt\ServicePackFiles\i386\gpkcsp.dll
+ 2006-12-31 01:26:44 9,728 ——w c:\winnt\ServicePackFiles\i386\gpkrsrc.dll
+ 2008-04-14 00:12:21 120,832 ——w c:\winnt\ServicePackFiles\i386\gprslt.exe
+ 2008-04-14 00:11:54 199,680 ——w c:\winnt\ServicePackFiles\i386\gptext.dll
+ 2008-04-14 00:12:21 39,424 ——w c:\winnt\ServicePackFiles\i386\grpconv.exe
+ 2008-04-13 18:40:21 28,288 ——w c:\winnt\ServicePackFiles\i386\grserial.sys
+ 2008-04-14 00:11:54 133,120 ——w c:\winnt\ServicePackFiles\i386\guitrn.dll
+ 2008-04-14 00:11:54 115,200 ——w c:\winnt\ServicePackFiles\i386\guitrna.dll
+ 2008-04-14 00:11:54 32,256 ——w c:\winnt\ServicePackFiles\i386\gzip.dll
+ 2008-04-14 00:11:54 57,344 ——w c:\winnt\ServicePackFiles\i386\h323cc.dll
+ 2008-04-14 00:11:54 614,912 ——w c:\winnt\ServicePackFiles\i386\h323msp.dll
+ 2008-04-13 18:31:32 105,344 ——w c:\winnt\ServicePackFiles\i386\hal.dll
+ 2008-04-13 18:31:28 131,840 ——w c:\winnt\ServicePackFiles\i386\halaacpi.dll
+ 2008-04-13 18:31:27 81,152 ——w c:\winnt\ServicePackFiles\i386\halacpi.dll
+ 2008-04-13 18:31:28 150,528 ——w c:\winnt\ServicePackFiles\i386\halapic.dll
+ 2008-04-13 18:31:28 134,400 ——w c:\winnt\ServicePackFiles\i386\halmacpi.dll
+ 2008-04-13 18:31:32 152,576 ——w c:\winnt\ServicePackFiles\i386\halmps.dll
+ 2008-04-13 18:31:31 77,696 ——w c:\winnt\ServicePackFiles\i386\halsp.dll
+ 2008-04-14 00:11:54 7,168 ——w c:\winnt\ServicePackFiles\i386\hccoin.dll
+ 2008-04-13 16:36:05 144,384 ——w c:\winnt\ServicePackFiles\i386\hdaudbus.sys
+ 2008-04-14 00:12:21 15,872 ——w c:\winnt\ServicePackFiles\i386\help.exe
+ 2008-04-14 00:12:21 769,024 ——w c:\winnt\ServicePackFiles\i386\helpctr.exe
+ 2008-04-14 00:12:21 744,448 ——w c:\winnt\ServicePackFiles\i386\helpsvc.exe
+ 2008-04-14 00:12:21 10,752 ——w c:\winnt\ServicePackFiles\i386\hh.exe
+ 2008-04-14 00:11:54 41,472 ——w c:\winnt\ServicePackFiles\i386\hhsetup.dll
+ 2008-04-14 00:11:54 20,992 ——w c:\winnt\ServicePackFiles\i386\hid.dll
+ 2008-04-13 18:36:38 20,352 ——w c:\winnt\ServicePackFiles\i386\hidbatt.sys
+ 2008-04-13 18:46:30 25,600 ——w c:\winnt\ServicePackFiles\i386\hidbth.sys
+ 2008-04-13 18:45:26 36,864 ——w c:\winnt\ServicePackFiles\i386\hidclass.sys
+ 2008-04-13 18:45:26 19,200 ——w c:\winnt\ServicePackFiles\i386\hidir.sys
+ 2008-04-13 18:45:22 24,960 ——w c:\winnt\ServicePackFiles\i386\hidparse.sys
+ 2008-04-14 00:11:54 21,504 ——w c:\winnt\ServicePackFiles\i386\hidserv.dll
+ 2008-04-13 18:45:27 10,368 ——w c:\winnt\ServicePackFiles\i386\hidusb.sys
+ 2008-04-14 00:11:54 72,704 ——w c:\winnt\ServicePackFiles\i386\hlink.dll
+ 2008-04-14 00:11:54 38,912 ——w c:\winnt\ServicePackFiles\i386\hmmapi.dll
+ 2008-04-14 00:11:54 344,064 ——w c:\winnt\ServicePackFiles\i386\hnetcfg.dll
+ 2008-04-14 00:11:54 330,752 ——w c:\winnt\ServicePackFiles\i386\hnetwiz.dll
+ 2008-04-14 00:11:54 39,936 ——w c:\winnt\ServicePackFiles\i386\hostmib.dll
+ 2008-04-14 00:11:54 144,896 ——w c:\winnt\ServicePackFiles\i386\hotplug.dll
+ 2008-04-14 00:11:54 10,752 ——w c:\winnt\ServicePackFiles\i386\hpcjrr.dll
+ 2008-04-14 00:11:54 10,240 ——w c:\winnt\ServicePackFiles\i386\hpcjrrps.dll
+ 2008-04-14 00:11:54 87,552 ——w c:\winnt\ServicePackFiles\i386\hpfud50.dll
+ 2008-04-14 00:12:21 18,432 ——w c:\winnt\ServicePackFiles\i386\hscupd.exe
+ 2004-08-04 03:41:48 220,032 ——w c:\winnt\ServicePackFiles\i386\hsfbs2s2.sys
+ 2008-04-14 00:11:54 32,285 ——w c:\winnt\ServicePackFiles\i386\hsfcisp2.dll
+ 2004-08-04 03:41:50 685,056 ——w c:\winnt\ServicePackFiles\i386\hsfcxts2.sys
+ 2004-08-04 03:41:56 1,041,536 ——w c:\winnt\ServicePackFiles\i386\hsfdpsp2.sys
+ 2008-04-13 18:53:53 264,832 ——w c:\winnt\ServicePackFiles\i386\http.sys
+ 2008-04-14 00:11:54 24,576 ——w c:\winnt\ServicePackFiles\i386\httpapi.dll
+ 2008-04-14 00:11:54 268,288 ——w c:\winnt\ServicePackFiles\i386\httpext.dll
+ 2008-04-14 00:11:54 8,192 ——w c:\winnt\ServicePackFiles\i386\httpmb51.dll
+ 2008-04-14 00:11:54 61,440 ——w c:\winnt\ServicePackFiles\i386\httpod51.dll
+ 2008-04-14 00:11:54 41,984 ——w c:\winnt\ServicePackFiles\i386\htui.dll
+ 2008-04-14 00:11:54 347,136 ——w c:\winnt\ServicePackFiles\i386\hypertrm.dll
+ 2008-04-13 18:41:22 8,576 ——w c:\winnt\ServicePackFiles\i386\i2omgmt.sys
+ 2008-04-13 18:41:22 18,560 ——w c:\winnt\ServicePackFiles\i386\i2omp.sys
+ 2008-04-13 19:18:00 52,480 ——w c:\winnt\ServicePackFiles\i386\i8042prt.sys
+ 2008-04-14 00:11:54 702,845 ——w c:\winnt\ServicePackFiles\i386\i81xdnt5.dll
+ 2004-08-04 03:29:38 161,020 ——w c:\winnt\ServicePackFiles\i386\i81xnt5.sys
+ 2008-04-14 00:11:54 119,808 ——w c:\winnt\ServicePackFiles\i386\iasrad.dll
+ 2008-04-14 00:11:54 11,264 ——w c:\winnt\ServicePackFiles\i386\icaapi.dll
+ 2008-04-14 00:11:54 80,384 ——w c:\winnt\ServicePackFiles\i386\iccvid.dll
+ 2008-04-14 00:11:54 254,976 ——w c:\winnt\ServicePackFiles\i386\icm32.dll
+ 2008-04-14 00:09:40 3,584 ——w c:\winnt\ServicePackFiles\i386\icmp.dll
+ 2008-04-13 16:44:29 2,560 ——w c:\winnt\ServicePackFiles\i386\iconlib.dll
+ 2008-04-14 00:11:54 61,440 ——w c:\winnt\ServicePackFiles\i386\icwconn.dll
+ 2008-04-14 00:12:22 214,528 ——w c:\winnt\ServicePackFiles\i386\icwconn1.exe
+ 2008-04-14 00:12:22 86,016 ——w c:\winnt\ServicePackFiles\i386\icwconn2.exe
+ 2008-04-14 00:11:54 73,728 ——w c:\winnt\ServicePackFiles\i386\icwdial.dll
+ 2008-04-14 00:11:54 32,768 ——w c:\winnt\ServicePackFiles\i386\icwdl.dll
+ 2008-04-14 00:11:54 172,032 ——w c:\winnt\ServicePackFiles\i386\icwhelp.dll
+ 2008-04-14 00:11:54 65,536 ——w c:\winnt\ServicePackFiles\i386\icwphbk.dll
+ 2008-04-14 00:12:22 24,576 ——w c:\winnt\ServicePackFiles\i386\icwrmind.exe
+ 2008-04-14 00:11:54 49,152 ——w c:\winnt\ServicePackFiles\i386\icwutil.dll
+ 2008-04-14 00:11:54 120,832 ——w c:\winnt\ServicePackFiles\i386\idq.dll
+ 2008-04-14 00:12:22 34,304 ——w c:\winnt\ServicePackFiles\i386\ie4uinit.exe
+ 2008-04-14 00:11:54 143,360 ——w c:\winnt\ServicePackFiles\i386\ieakeng.dll
+ 2008-04-14 00:11:54 216,576 ——w c:\winnt\ServicePackFiles\i386\ieaksie.dll
+ 2008-04-14 00:11:54 323,584 ——w c:\winnt\ServicePackFiles\i386\iedkcs32.dll
+ 2008-04-14 00:12:22 18,432 ——w c:\winnt\ServicePackFiles\i386\iedw.exe
+ 2008-04-14 00:11:54 81,920 ——w c:\winnt\ServicePackFiles\i386\ieencode.dll
+ 2007-01-02 20:29:28 8,192 ——w c:\winnt\ServicePackFiles\i386\ieexec.exe
+ 2007-09-26 19:59:47 7,168 ——w c:\winnt\ServicePackFiles\i386\ieexecremote.dll
+ 2007-09-26 19:59:48 32,768 ——w c:\winnt\ServicePackFiles\i386\iehost.dll
+ 2008-04-14 00:11:54 251,904 ——w c:\winnt\ServicePackFiles\i386\iepeers.dll
+ 2008-04-14 00:11:54 48,640 ——w c:\winnt\ServicePackFiles\i386\iernonce.dll
+ 2008-04-14 00:11:54 62,976 ——w c:\winnt\ServicePackFiles\i386\iesetup.dll
+ 2008-04-14 00:12:22 93,184 ——w c:\winnt\ServicePackFiles\i386\iexplore.exe
+ 2008-04-14 00:12:22 114,688 ——w c:\winnt\ServicePackFiles\i386\iexpress.exe
+ 2008-04-14 00:11:54 135,680 ——w c:\winnt\ServicePackFiles\i386\ifmon.dll
+ 2008-04-14 00:11:54 8,192 ——w c:\winnt\ServicePackFiles\i386\igmpagnt.dll
+ 2008-04-14 00:11:54 505,344 ——w c:\winnt\ServicePackFiles\i386\iis.dll
+ 2008-04-14 00:11:54 25,088 ——w c:\winnt\ServicePackFiles\i386\iisadmin.dll
+ 2008-04-14 00:11:54 145,408 ——w c:\winnt\ServicePackFiles\i386\iische51.dll
+ 2008-04-14 00:11:54 68,608 ——w c:\winnt\ServicePackFiles\i386\iisext51.dll
+ 2008-04-14 00:11:54 7,168 ——w c:\winnt\ServicePackFiles\i386\iisfecnv.dll
+ 2008-04-14 00:11:54 79,872 ——w c:\winnt\ServicePackFiles\i386\iislog51.dll
+ 2008-04-14 00:11:54 64,512 ——w c:\winnt\ServicePackFiles\i386\iismap.dll
+ 2008-04-14 00:12:22 30,720 ——w c:\winnt\ServicePackFiles\i386\iisrstas.exe
+ 2008-04-14 00:11:54 133,632 ——w c:\winnt\ServicePackFiles\i386\iisrtl.dll
+ 2004-07-15 02:50:54 184,320 ——w c:\winnt\ServicePackFiles\i386\ilasm.exe
+ 2008-04-14 00:11:54 81,920 ——w c:\winnt\ServicePackFiles\i386\ils.dll
+ 2008-04-14 00:11:54 144,384 ——w c:\winnt\ServicePackFiles\i386\imagehlp.dll
+ 2008-04-14 00:12:22 150,528 ——w c:\winnt\ServicePackFiles\i386\imapi.exe
+ 2008-04-13 18:40:58 42,112 ——w c:\winnt\ServicePackFiles\i386\imapi.sys
+ 2008-04-14 00:11:54 36,921 ——w c:\winnt\ServicePackFiles\i386\imeshare.dll
+ 2008-04-14 00:11:54 35,840 ——w c:\winnt\ServicePackFiles\i386\imgutil.dll
+ 2008-04-14 00:11:54 110,080 ——w c:\winnt\ServicePackFiles\i386\imm32.dll
+ 2008-04-14 00:11:54 123,392 ——w c:\winnt\ServicePackFiles\i386\imsinsnt.dll
+ 2008-04-14 00:11:54 274,432 ——w c:\winnt\ServicePackFiles\i386\inetcfg.dll
+ 2008-04-14 00:11:54 691,712 ——w c:\winnt\ServicePackFiles\i386\inetcomm.dll
+ 2008-04-14 00:12:22 15,360 ——w c:\winnt\ServicePackFiles\i386\inetin51.exe
+ 2008-04-14 00:11:55 829,440 ——w c:\winnt\ServicePackFiles\i386\inetmgr.dll
+ 2008-04-14 00:11:55 32,768 ——w c:\winnt\ServicePackFiles\i386\inetmib1.dll
+ 2008-04-14 00:11:55 75,264 ——w c:\winnt\ServicePackFiles\i386\inetpp.dll
+ 2008-04-14 00:11:55 15,872 ——w c:\winnt\ServicePackFiles\i386\inetppui.dll
+ 2008-04-13 16:22:12 48,128 ——w c:\winnt\ServicePackFiles\i386\inetres.dll
+ 2008-04-14 00:12:22 20,480 ——w c:\winnt\ServicePackFiles\i386\inetwiz.exe
+ 2008-04-14 00:11:55 13,312 ——w c:\winnt\ServicePackFiles\i386\infoadmn.dll
+ 2008-04-14 00:11:55 257,024 ——w c:\winnt\ServicePackFiles\i386\infocomm.dll
+ 2008-04-14 00:11:55 147,456 ——w c:\winnt\ServicePackFiles\i386\initpki.dll
+ 2008-04-14 00:11:55 123,392 ——w c:\winnt\ServicePackFiles\i386\input.dll
+ 2008-04-14 00:11:55 96,256 ——w c:\winnt\ServicePackFiles\i386\inseng.dll
+ 2004-07-15 15:05:28 24,576 ——w c:\winnt\ServicePackFiles\i386\installutil.exe
+ 2008-04-13 18:40:29 5,504 ——w c:\winnt\ServicePackFiles\i386\intelide.sys
+ 2008-04-13 18:31:32 36,352 ——w c:\winnt\ServicePackFiles\i386\intelppm.sys
+ 2008-04-13 18:53:34 36,608 ——w c:\winnt\ServicePackFiles\i386\ip6fw.sys
+ 2008-04-14 00:12:22 55,808 ——w c:\winnt\ServicePackFiles\i386\ipconfig.exe
+ 2008-04-14 00:09:30 103,424 ——w c:\winnt\ServicePackFiles\i386\ipevldpc.dll
+ 2008-04-14 00:09:23 24,064 ——w c:\winnt\ServicePackFiles\i386\ipevlpid.dll
+ 2008-04-14 00:11:55 94,720 ——w c:\winnt\ServicePackFiles\i386\iphlpapi.dll
+ 2008-04-13 18:57:07 20,864 ——w c:\winnt\ServicePackFiles\i386\ipinip.sys
+ 2008-04-14 00:11:55 161,280 ——w c:\winnt\ServicePackFiles\i386\ipmontr.dll
+ 2008-04-13 18:57:15 152,832 ——w c:\winnt\ServicePackFiles\i386\ipnat.sys
+ 2008-04-14 00:11:55 331,264 ——w c:\winnt\ServicePackFiles\i386\ipnathlp.dll
+ 2008-04-14 00:11:55 330,752 ——w c:\winnt\ServicePackFiles\i386\ippromon.dll
+ 2008-04-14 00:11:55 35,328 ——w c:\winnt\ServicePackFiles\i386\iprip.dll
+ 2008-04-14 00:11:55 177,152 ——w c:\winnt\ServicePackFiles\i386\iprtrmgr.dll
+ 2008-04-13 19:19:42 75,264 ——w c:\winnt\ServicePackFiles\i386\ipsec.sys
+ 2008-04-14 00:11:55 349,696 ——w c:\winnt\ServicePackFiles\i386\ipsecsnp.dll
+ 2008-04-14 00:11:55 183,808 ——w c:\winnt\ServicePackFiles\i386\ipsecsvc.dll
+ 2008-04-14 00:10:45 102,912 ——w c:\winnt\ServicePackFiles\i386\ipseldpc.dll
+ 2008-04-14 00:09:24 24,064 ——w c:\winnt\ServicePackFiles\i386\ipselpid.dll
+ 2008-04-14 00:11:55 384,000 ——w c:\winnt\ServicePackFiles\i386\ipsmsnap.dll
+ 2008-04-14 00:12:23 53,248 ——w c:\winnt\ServicePackFiles\i386\ipv6.exe
+ 2008-04-14 00:11:55 59,904 ——w c:\winnt\ServicePackFiles\i386\ipv6mon.dll
+ 2008-04-14 00:12:23 23,552 ——w c:\winnt\ServicePackFiles\i386\ipxroute.exe
+ 2008-04-14 00:11:55 22,016 ——w c:\winnt\ServicePackFiles\i386\ipxwan.dll
+ 2008-04-14 00:11:55 120,320 ——w c:\winnt\ServicePackFiles\i386\ir41_qc.dll
+ 2008-04-14 00:11:55 338,432 ——w c:\winnt\ServicePackFiles\i386\ir41_qcx.dll
+ 2008-04-14 00:11:55 755,200 ——w c:\winnt\ServicePackFiles\i386\ir50_32.dll
+ 2008-04-14 00:11:55 200,192 ——w c:\winnt\ServicePackFiles\i386\ir50_qc.dll
+ 2008-04-14 00:11:55 183,808 ——w c:\winnt\ServicePackFiles\i386\ir50_qcx.dll
+ 2008-04-13 18:45:34 46,592 ——w c:\winnt\ServicePackFiles\i386\irbus.sys
+ 2008-04-13 18:54:36 88,192 ——w c:\winnt\ServicePackFiles\i386\irda.sys
+ 2008-04-13 18:54:28 11,264 ——w c:\winnt\ServicePackFiles\i386\irenum.sys
+ 2008-04-14 00:12:23 151,552 ——w c:\winnt\ServicePackFiles\i386\irftp.exe
+ 2008-04-14 00:11:55 28,160 ——w c:\winnt\ServicePackFiles\i386\irmon.dll
+ 2008-04-13 18:36:41 37,248 ——w c:\winnt\ServicePackFiles\i386\isapnp.sys
+ 2008-04-14 00:11:55 68,608 ——w c:\winnt\ServicePackFiles\i386\isatq.dll
+ 2008-04-14 00:11:55 26,624 ——w c:\winnt\ServicePackFiles\i386\iscomlog.dll
+ 2008-04-14 00:10:32 105,984 ——w c:\winnt\ServicePackFiles\i386\isdpc.dll
+ 2008-04-14 00:10:55 105,984 ——w c:\winnt\ServicePackFiles\i386\isendpc.dll
+ 2008-04-14 00:10:55 24,064 ——w c:\winnt\ServicePackFiles\i386\isenpid.dll
+ 2008-04-14 00:11:55 81,920 ——w c:\winnt\ServicePackFiles\i386\isign32.dll
+ 2008-04-14 00:10:32 24,064 ——w c:\winnt\ServicePackFiles\i386\ispid.dll
+ 2008-04-14 00:11:55 32,768 ——w c:\winnt\ServicePackFiles\i386\isrdbg32.dll
+ 2008-04-14 00:11:55 155,136 ——w c:\winnt\ServicePackFiles\i386\itircl.dll
+ 2008-04-14 00:11:55 138,240 ——w c:\winnt\ServicePackFiles\i386\itss.dll
+ 2008-04-14 00:11:55 191,488 ——w c:\winnt\ServicePackFiles\i386\iuengine.dll
+ 2008-04-14 00:11:55 54,272 ——w c:\winnt\ServicePackFiles\i386\ixsso.dll
+ 2008-04-14 00:11:55 47,616 ——w c:\winnt\ServicePackFiles\i386\iyuv_32.dll
+ 2008-04-14 00:11:55 163,840 ——w c:\winnt\ServicePackFiles\i386\jgdw400.dll
+ 2008-04-14 00:11:55 27,648 ——w c:\winnt\ServicePackFiles\i386\jgpl400.dll
+ 2004-07-15 15:05:00 40,960 ——w c:\winnt\ServicePackFiles\i386\jsc.exe
+ 2008-04-14 00:11:56 512,000 ——w c:\winnt\ServicePackFiles\i386\jscript.dll
+ 2008-04-14 00:11:56 15,872 ——w c:\winnt\ServicePackFiles\i386\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbd101.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbd106.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbd106n.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdax2.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdbhc.dll
+ 2008-04-13 18:39:47 24,576 ——w c:\winnt\ServicePackFiles\i386\kbdclass.sys
+ 2008-04-14 00:09:55 7,168 ——w c:\winnt\ServicePackFiles\i386\kbdfi1.dll
+ 2008-04-13 18:39:48 14,592 ——w c:\winnt\ServicePackFiles\i386\kbdhid.sys
+ 2008-04-14 00:09:55 7,168 ——w c:\winnt\ServicePackFiles\i386\kbdibm02.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdinben.dll
+ 2008-04-14 00:09:55 6,656 ——w c:\winnt\ServicePackFiles\i386\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdiultn.dll
+ 2008-04-14 00:09:55 6,656 ——w c:\winnt\ServicePackFiles\i386\kbdlk41a.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdlk41j.dll
+ 2008-04-14 00:09:55 5,632 ——w c:\winnt\ServicePackFiles\i386\kbdmaori.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdmlt48.dll
+ 2008-04-14 00:09:55 7,168 ——w c:\winnt\ServicePackFiles\i386\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdnepr.dll
+ 2008-04-14 00:09:55 7,168 ——w c:\winnt\ServicePackFiles\i386\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\ServicePackFiles\i386\kbdpash.dll
+ 2008-04-14 00:09:55 7,680 ——w c:\winnt\ServicePackFiles\i386\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 ——w c:\winnt\ServicePackFiles\i386\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,168 ——w c:\winnt\ServicePackFiles\i386\kbdukx.dll
+ 2008-04-13 18:31:35 7,424 ——w c:\winnt\ServicePackFiles\i386\kd1394.dll
+ 2008-04-14 00:11:56 184,832 ——w c:\winnt\ServicePackFiles\i386\kdcsvc.dll
+ 2008-04-14 00:11:56 48,640 ——w c:\winnt\ServicePackFiles\i386\kdsui.dll
+ 2008-04-14 00:11:56 253,952 ——w c:\winnt\ServicePackFiles\i386\kdsusd.dll
+ 2008-04-14 00:11:56 299,520 ——w c:\winnt\ServicePackFiles\i386\kerberos.dll
+ 2008-04-14 00:11:56 989,696 ——w c:\winnt\ServicePackFiles\i386\kernel32.dll
+ 2004-08-03 20:46:56 42,537 ——w c:\winnt\ServicePackFiles\i386\keyboard.sys
+ 2008-04-14 00:11:56 150,528 ——w c:\winnt\ServicePackFiles\i386\keymgr.dll
+ 2008-04-13 18:45:09 172,416 ——w c:\winnt\ServicePackFiles\i386\kmixer.sys
+ 2008-04-14 00:11:56 61,440 ——w c:\winnt\ServicePackFiles\i386\kmsvc.dll
+ 2008-04-14 00:09:56 102,912 ——w c:\winnt\ServicePackFiles\i386\knperdpc.dll
+ 2008-04-14 00:09:56 24,064 ——w c:\winnt\ServicePackFiles\i386\knperpid.dll
+ 2008-04-14 00:09:56 102,912 ——w c:\winnt\ServicePackFiles\i386\knprodpc.dll
+ 2008-04-14 00:09:56 24,576 ——w c:\winnt\ServicePackFiles\i386\knpropid.dll
+ 2008-04-14 00:11:56 8,192 ——w c:\winnt\ServicePackFiles\i386\koc.dll
+ 2008-04-14 00:09:56 102,912 ——w c:\winnt\ServicePackFiles\i386\kperdpc.dll
+ 2008-04-14 00:09:56 24,064 ——w c:\winnt\ServicePackFiles\i386\kperpid.dll
+ 2008-04-14 00:09:56 102,912 ——w c:\winnt\ServicePackFiles\i386\kprodpc.dll
+ 2008-04-14 00:09:56 24,576 ——w c:\winnt\ServicePackFiles\i386\kpropid.dll
+ 2004-08-03 20:49:34 92,224 ——w c:\winnt\ServicePackFiles\i386\krnl386.exe
+ 2008-04-14 00:11:56 24,576 ——w c:\winnt\ServicePackFiles\i386\krnlprov.dll
+ 2008-04-13 19:16:36 141,056 ——w c:\winnt\ServicePackFiles\i386\ks.sys
+ 2008-04-13 18:31:43 92,288 ——w c:\winnt\ServicePackFiles\i386\ksecdd.sys
+ 2008-04-14 00:11:56 4,096 ——w c:\winnt\ServicePackFiles\i386\ksuser.dll
+ 2008-04-14 00:11:56 37,376 ——w c:\winnt\ServicePackFiles\i386\l2store.dll
+ 2008-04-14 00:09:05 97,792 ——w c:\winnt\ServicePackFiles\i386\lang\chtmbx.dll
+ 2008-04-14 00:09:05 56,320 ——w c:\winnt\ServicePackFiles\i386\lang\chtskdic.dll
+ 2008-04-14 00:09:05 173,568 ——w c:\winnt\ServicePackFiles\i386\lang\chtskf.dll
+ 2008-04-14 00:09:06 198,656 ——w c:\winnt\ServicePackFiles\i386\lang\cintime.dll
+ 2008-04-13 16:43:39 480,256 ——w c:\winnt\ServicePackFiles\i386\lang\cintsetp.exe
+ 2008-04-13 16:43:33 57,399 ——w c:\winnt\ServicePackFiles\i386\lang\cplexe.exe
+ 2008-04-14 00:09:39 13,463,552 ——w c:\winnt\ServicePackFiles\i386\lang\hwxjpn.dll
+ 2008-04-14 00:09:43 106,496 ——w c:\winnt\ServicePackFiles\i386\lang\imekrcic.dll
+ 2008-04-14 00:09:43 86,016 ——w c:\winnt\ServicePackFiles\i386\lang\imekrmbx.dll
+ 2008-04-14 00:09:44 811,064 ——w c:\winnt\ServicePackFiles\i386\lang\imjp81k.dll
+ 2008-04-14 00:09:45 368,696 ——w c:\winnt\ServicePackFiles\i386\lang\imjpcic.dll
+ 2008-04-14 00:09:45 716,856 ——w c:\winnt\ServicePackFiles\i386\lang\imjpcus.dll
+ 2008-04-14 00:09:45 81,976 ——w c:\winnt\ServicePackFiles\i386\lang\imjpdct.dll
+ 2008-04-13 16:43:45 307,257 ——w c:\winnt\ServicePackFiles\i386\lang\imjpdct.exe
+ 2008-04-13 16:43:46 155,705 ——w c:\winnt\ServicePackFiles\i386\lang\imjpdsvr.exe
+ 2008-04-13 16:43:48 196,665 ——w c:\winnt\ServicePackFiles\i386\lang\imjpinst.exe
+ 2008-04-13 16:43:51 208,952 ——w c:\winnt\ServicePackFiles\i386\lang\imjpmig.exe
+ 2008-04-13 16:43:58 233,527 ——w c:\winnt\ServicePackFiles\i386\lang\imjprw.exe
+ 2008-04-13 16:44:01 262,200 ——w c:\winnt\ServicePackFiles\i386\lang\imjputy.exe
+ 2008-04-14 00:09:46 274,489 ——w c:\winnt\ServicePackFiles\i386\lang\imjputyc.dll
+ 2008-04-14 00:09:46 102,456 ——w c:\winnt\ServicePackFiles\i386\lang\imlang.dll
+ 2008-04-13 16:43:36 59,392 ——w c:\winnt\ServicePackFiles\i386\lang\imscinst.exe
+ 2008-04-14 00:09:47 315,455 ——w c:\winnt\ServicePackFiles\i386\lang\imskf.dll
+ 2008-04-14 00:10:33 15,872 ——w c:\winnt\ServicePackFiles\i386\lang\padrs404.dll
+ 2008-04-14 00:10:33 15,360 ——w c:\winnt\ServicePackFiles\i386\lang\padrs804.dll
+ 2008-04-14 00:10:34 175,104 ——w c:\winnt\ServicePackFiles\i386\lang\pintlcsa.dll
+ 2008-04-14 00:10:34 53,760 ——w c:\winnt\ServicePackFiles\i386\lang\pintlcsd.dll
+ 2008-04-13 16:43:36 70,144 ——w c:\winnt\ServicePackFiles\i386\lang\pintlphr.exe
+ 2008-04-14 00:10:34 67,584 ——w c:\winnt\ServicePackFiles\i386\lang\pmigrate.dll
+ 2008-04-13 16:43:50 44,032 ——w c:\winnt\ServicePackFiles\i386\lang\tintlphr.exe
+ 2008-04-13 16:43:52 455,168 ——w c:\winnt\ServicePackFiles\i386\lang\tintsetp.exe
+ 2008-04-14 00:10:59 10,240 ——w c:\winnt\ServicePackFiles\i386\lang\tmigrate.dll
+ 2008-04-14 00:11:01 76,288 ——w c:\winnt\ServicePackFiles\i386\lang\uniime.dll
+ 2008-04-14 00:11:04 426,041 ——w c:\winnt\ServicePackFiles\i386\lang\voicepad.dll
+ 2008-04-14 00:11:04 86,073 ——w c:\winnt\ServicePackFiles\i386\lang\voicesub.dll
+ 2008-04-13 18:40:26 34,688 ——w c:\winnt\ServicePackFiles\i386\lbrtfdc.sys
+ 2008-04-14 00:12:23 677,888 ——w c:\winnt\ServicePackFiles\i386\lhmstsc.exe
+ 2008-04-14 00:11:56 2,061,824 ——w c:\winnt\ServicePackFiles\i386\lhmstscx.dll
+ 2008-04-14 10:41:58 423,936 ——w c:\winnt\ServicePackFiles\i386\licdll.dll
+ 2008-04-14 00:11:56 22,016 ——w c:\winnt\ServicePackFiles\i386\licmgr10.dll
+ 2008-04-14 00:11:56 58,880 ——w c:\winnt\ServicePackFiles\i386\licwmi.dll
+ 2008-04-14 00:11:56 19,968 ——w c:\winnt\ServicePackFiles\i386\linkinfo.dll
+ 2008-04-14 00:11:56 13,824 ——w c:\winnt\ServicePackFiles\i386\lmhsvc.dll
+ 2008-04-14 00:11:56 33,792 ——w c:\winnt\ServicePackFiles\i386\lmmib2.dll
+ 2008-04-14 00:11:56 399,872 ——w c:\winnt\ServicePackFiles\i386\lmrt.dll
+ 2008-04-14 00:11:56 97,280 ——w c:\winnt\ServicePackFiles\i386\loadperf.dll
+ 2008-04-14 00:11:56 221,696 ——w c:\winnt\ServicePackFiles\i386\localsec.dll
+ 2008-04-14 00:11:56 343,040 ——w c:\winnt\ServicePackFiles\i386\localspl.dll
+ 2008-04-14 00:11:56 11,776 ——w c:\winnt\ServicePackFiles\i386\localui.dll
+ 2008-04-14 00:12:24 75,264 ——w c:\winnt\ServicePackFiles\i386\locator.exe
+ 2008-04-14 00:11:56 19,968 ——w c:\winnt\ServicePackFiles\i386\log.dll
+ 2008-04-14 00:12:24 59,392 ——w c:\winnt\ServicePackFiles\i386\logman.exe
+ 2008-04-14 00:12:43 220,672 ——w c:\winnt\ServicePackFiles\i386\logon.scr
+ 2008-04-14 00:12:24 514,560 ——w c:\winnt\ServicePackFiles\i386\logonui.exe
+ 2008-04-14 00:11:56 13,312 ——w c:\winnt\ServicePackFiles\i386\lonsint.dll
+ 2008-04-14 00:11:56 22,528 ——w c:\winnt\ServicePackFiles\i386\lpdsvc.dll
+ 2008-04-14 00:11:56 22,016 ——w c:\winnt\ServicePackFiles\i386\lpk.dll
+ 2008-04-14 00:11:56 10,240 ——w c:\winnt\ServicePackFiles\i386\lprhelp.dll
+ 2008-04-14 00:11:56 18,944 ——w c:\winnt\ServicePackFiles\i386\lprmon.dll
+ 2008-04-14 00:11:56 728,064 ——w c:\winnt\ServicePackFiles\i386\lsasrv.dll
+ 2008-04-14 00:12:24 13,312 ——w c:\winnt\ServicePackFiles\i386\lsass.exe
+ 2004-08-04 03:41:36 606,684 ——w c:\winnt\ServicePackFiles\i386\ltmdmnt.sys
+ 2004-08-04 03:41:38 420,992 ——w c:\winnt\ServicePackFiles\i386\ltmdmntt.sys
+ 2008-04-13 18:40:52 7,040 ——w c:\winnt\ServicePackFiles\i386\ltotape.sys
+ 2004-08-04 03:39:32 20,864 ——w c:\winnt\ServicePackFiles\i386\lwadihid.sys
+ 2008-04-14 00:12:24 72,704 ——w c:\winnt\ServicePackFiles\i386\magnify.exe
+ 2008-04-14 00:12:25 57,344 ——w c:\winnt\ServicePackFiles\i386\makecab.exe
+ 2008-04-14 00:11:56 14,336 ——w c:\winnt\ServicePackFiles\i386\mcastmib.dll
+ 2008-04-14 00:11:56 84,480 ——w c:\winnt\ServicePackFiles\i386\mciavi32.dll
+ 2008-04-14 00:11:56 35,328 ——w c:\winnt\ServicePackFiles\i386\mciqtz32.dll
+ 2008-04-14 00:11:56 23,040 ——w c:\winnt\ServicePackFiles\i386\mciseq.dll
+ 2008-04-14 00:11:56 23,552 ——w c:\winnt\ServicePackFiles\i386\mciwave.dll
+ 2008-04-14 00:11:56 37,888 ——w c:\winnt\ServicePackFiles\i386\md5filt.dll
+ 2008-04-14 00:11:56 118,272 ——w c:\winnt\ServicePackFiles\i386\mdminst.dll
+ 2008-04-14 00:11:56 86,016 ——w c:\winnt\ServicePackFiles\i386\mdmxsdk.dll
+ 2004-08-04 03:41:56 11,868 ——w c:\winnt\ServicePackFiles\i386\mdmxsdk.sys
+ 2008-04-14 00:11:56 16,896 ——w c:\winnt\ServicePackFiles\i386\medctroc.dll
+ 2008-04-13 18:41:21 26,112 ——w c:\winnt\ServicePackFiles\i386\memstpci.sys
+ 2008-04-14 00:11:56 85,504 ——w c:\winnt\ServicePackFiles\i386\metada51.dll
+ 2008-04-13 18:36:41 63,744 ——w c:\winnt\ServicePackFiles\i386\mf.sys
+ 2008-04-14 00:11:56 40,960 ——w c:\winnt\ServicePackFiles\i386\mf3216.dll
+ 2008-04-14 00:11:56 927,504 ——w c:\winnt\ServicePackFiles\i386\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 ——w c:\winnt\ServicePackFiles\i386\mfc42.dll
+ 2006-12-14 13:45:53 981,760 ——w c:\winnt\ServicePackFiles\i386\mfc42u.dll
+ 2008-04-14 00:11:56 22,528 ——w c:\winnt\ServicePackFiles\i386\mfcsubs.dll
+ 2008-04-14 00:11:56 14,848 ——w c:\winnt\ServicePackFiles\i386\mgmtapi.dll
+ 2007-09-26 19:59:53 712,704 ——w c:\winnt\ServicePackFiles\i386\microsoft.jscript.dll
+ 2007-09-26 19:59:49 286,720 ——w c:\winnt\ServicePackFiles\i386\microsoft.visualbasic.dll
+ 2008-04-14 00:11:57 18,944 ——w c:\winnt\ServicePackFiles\i386\midimap.dll
+ 2008-04-14 00:11:57 274,432 ——w c:\winnt\ServicePackFiles\i386\migism.dll
+ 2008-04-14 00:11:57 261,120 ——w c:\winnt\ServicePackFiles\i386\migisma.dll
+ 2008-04-14 00:11:57 60,928 ——w c:\winnt\ServicePackFiles\i386\miglibnt.dll
+ 2008-04-14 00:12:25 103,936 ——w c:\winnt\ServicePackFiles\i386\migload.exe
+ 2008-04-14 00:12:25 7,680 ——w c:\winnt\ServicePackFiles\i386\migregdb.exe
+ 2008-04-14 00:12:25 245,248 ——w c:\winnt\ServicePackFiles\i386\migwiz.exe
+ 2008-04-14 00:12:25 241,152 ——w c:\winnt\ServicePackFiles\i386\migwiza.exe
+ 2008-04-14 00:11:57 29,696 ——w c:\winnt\ServicePackFiles\i386\mimefilt.dll
+ 2008-04-14 00:11:57 586,240 ——w c:\winnt\ServicePackFiles\i386\mlang.dll
+ 2008-04-14 00:12:25 1,414,656 ——w c:\winnt\ServicePackFiles\i386\mmc.exe
+ 2008-04-14 00:11:57 184,320 ——w c:\winnt\ServicePackFiles\i386\mmc30.dll
+ 2008-04-14 00:11:57 28,672 ——w c:\winnt\ServicePackFiles\i386\mmc30r.dll
+ 2008-04-14 00:11:57 163,328 ——w c:\winnt\ServicePackFiles\i386\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 ——w c:\winnt\ServicePackFiles\i386\mmcex.dll
+ 2008-04-14 00:11:57 40,960 ——w c:\winnt\ServicePackFiles\i386\mmcexr.dll
+ 2008-04-14 00:11:57 106,496 ——w c:\winnt\ServicePackFiles\i386\mmcfxc.dll
+ 2008-04-14 00:11:57 6,656 ——w c:\winnt\ServicePackFiles\i386\mmcfxcr.dll
+ 2008-04-14 00:11:57 1,872,896 ——w c:\winnt\ServicePackFiles\i386\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 ——w c:\winnt\ServicePackFiles\i386\mmcperf.exe
+ 2008-04-14 00:11:57 61,440 ——w c:\winnt\ServicePackFiles\i386\mmcshext.dll
+ 2008-04-14 00:11:57 17,408 ——w c:\winnt\ServicePackFiles\i386\mmfutil.dll
+ 2004-08-03 20:51:12 68,768 ——w c:\winnt\ServicePackFiles\i386\mmsystem.dll
+ 2008-04-14 00:11:57 34,560 ——w c:\winnt\ServicePackFiles\i386\mnmdd.dll
+ 2008-04-14 00:12:25 32,768 ——w c:\winnt\ServicePackFiles\i386\mnmsrvc.exe
+ 2008-04-14 00:11:57 207,360 ——w c:\winnt\ServicePackFiles\i386\mobsync.dll
+ 2008-04-14 00:12:26 143,360 ——w c:\winnt\ServicePackFiles\i386\mobsync.exe
+ 2008-04-13 19:00:19 30,080 ——w c:\winnt\ServicePackFiles\i386\modem.sys
+ 2008-04-14 00:11:57 153,600 ——w c:\winnt\ServicePackFiles\i386\modemui.dll
+ 2008-04-14 00:12:26 16,384 ——w c:\winnt\ServicePackFiles\i386\mofcomp.exe
+ 2008-04-14 00:11:57 123,904 ——w c:\winnt\ServicePackFiles\i386\mofd.dll
+ 2008-04-14 00:12:42 16,896 ——w c:\winnt\ServicePackFiles\i386\more.com
+ 2008-04-13 16:45:30 216,064 ——w c:\winnt\ServicePackFiles\i386\moricons.dll
+ 2008-04-13 18:39:47 23,040 ——w c:\winnt\ServicePackFiles\i386\mouclass.sys
+ 2008-04-13 18:39:46 42,368 ——w c:\winnt\ServicePackFiles\i386\mountmgr.sys
+ 2008-04-14 00:12:27 3,558,912 ——w c:\winnt\ServicePackFiles\i386\moviemk.exe
+ 2008-04-13 18:46:22 15,232 ——w c:\winnt\ServicePackFiles\i386\mpe.sys
+ 2008-04-14 00:12:27 123,392 ——w c:\winnt\ServicePackFiles\i386\mplay32.exe
+ 2008-04-14 00:11:57 59,904 ——w c:\winnt\ServicePackFiles\i386\mpr.dll
+ 2008-04-14 00:11:57 87,040 ——w c:\winnt\ServicePackFiles\i386\mprapi.dll
+ 2008-04-14 00:11:57 53,248 ——w c:\winnt\ServicePackFiles\i386\mprdim.dll
+ 2008-04-13 18:39:44 92,544 ——w c:\winnt\ServicePackFiles\i386\mqac.sys
+ 2008-04-14 00:11:57 138,240 ——w c:\winnt\ServicePackFiles\i386\mqad.dll
+ 2008-04-14 00:12:27 19,968 ——w c:\winnt\ServicePackFiles\i386\mqbkup.exe
+ 2008-04-14 00:11:57 47,616 ——w c:\winnt\ServicePackFiles\i386\mqdscli.dll
+ 2008-04-14 00:11:57 16,896 ——w c:\winnt\ServicePackFiles\i386\mqise.dll
+ 2008-04-14 00:11:57 89,088 ——w c:\winnt\ServicePackFiles\i386\mqlogmgr.dll
+ 2008-04-14 00:11:57 225,280 ——w c:\winnt\ServicePackFiles\i386\mqoa.dll
+ 2008-04-14 00:11:57 663,040 ——w c:\winnt\ServicePackFiles\i386\mqqm.dll
+ 2008-04-14 00:11:57 177,152 ——w c:\winnt\ServicePackFiles\i386\mqrt.dll
+ 2008-04-14 00:11:57 123,904 ——w c:\winnt\ServicePackFiles\i386\mqrtdep.dll
+ 2008-04-14 00:11:57 95,744 ——w c:\winnt\ServicePackFiles\i386\mqsec.dll
+ 2008-04-14 00:11:58 517,632 ——w c:\winnt\ServicePackFiles\i386\mqsnap.dll
+ 2008-04-14 00:12:27 4,608 ——w c:\winnt\ServicePackFiles\i386\mqsvc.exe
+ 2008-04-14 00:12:27 117,248 ——w c:\winnt\ServicePackFiles\i386\mqtgsvc.exe
+ 2008-04-14 00:11:58 187,392 ——w c:\winnt\ServicePackFiles\i386\mqtrig.dll
+ 2008-04-14 00:11:58 49,152 ——w c:\winnt\ServicePackFiles\i386\mqupgrd.dll
+ 2008-04-14 00:11:58 471,552 ——w c:\winnt\ServicePackFiles\i386\mqutil.dll
+ 2008-04-13 18:32:44 180,608 ——w c:\winnt\ServicePackFiles\i386\mrxdav.sys
+ 2008-04-13 19:17:01 456,576 ——w c:\winnt\ServicePackFiles\i386\mrxsmb.sys
+ 2008-04-14 00:11:58 71,680 ——w c:\winnt\ServicePackFiles\i386\msacm32.dll
+ 2008-04-14 00:11:58 331,776 ——w c:\winnt\ServicePackFiles\i386\msadce.dll
+ 2008-04-13 17:25:57 20,480 ——w c:\winnt\ServicePackFiles\i386\msadcer.dll
+ 2008-04-14 00:11:58 61,440 ——w c:\winnt\ServicePackFiles\i386\msadcf.dll
+ 2008-04-13 17:25:57 16,384 ——w c:\winnt\ServicePackFiles\i386\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 ——w c:\winnt\ServicePackFiles\i386\msadco.dll
+ 2008-04-13 17:25:57 16,384 ——w c:\winnt\ServicePackFiles\i386\msadcor.dll
+ 2008-04-14 00:11:58 53,248 ——w c:\winnt\ServicePackFiles\i386\msadcs.dll
+ 2008-04-14 00:11:58 155,648 ——w c:\winnt\ServicePackFiles\i386\msadds.dll
+ 2008-04-13 17:25:58 24,576 ——w c:\winnt\ServicePackFiles\i386\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 ——w c:\winnt\ServicePackFiles\i386\msader15.dll
+ 2008-04-14 00:11:58 536,576 ——w c:\winnt\ServicePackFiles\i386\msado15.dll
+ 2008-04-14 00:11:58 180,224 ——w c:\winnt\ServicePackFiles\i386\msadomd.dll
+ 2008-04-14 00:11:58 57,344 ——w c:\winnt\ServicePackFiles\i386\msador15.dll
+ 2008-04-14 00:11:58 200,704 ——w c:\winnt\ServicePackFiles\i386\msadox.dll
+ 2008-04-14 00:11:58 57,344 ——w c:\winnt\ServicePackFiles\i386\msadrh15.dll
+ 2008-04-14 00:10:06 3,584 ——w c:\winnt\ServicePackFiles\i386\msafd.dll
+ 2008-04-14 00:11:58 86,016 ——w c:\winnt\ServicePackFiles\i386\msapsspc.dll
+ 2008-04-14 00:11:58 57,344 ——w c:\winnt\ServicePackFiles\i386\msasn1.dll
+ 2008-04-14 00:11:58 220,160 ——w c:\winnt\ServicePackFiles\i386\mscandui.dll
+ 2008-04-14 00:11:58 73,728 ——w c:\winnt\ServicePackFiles\i386\mscms.dll
+ 2008-04-14 00:11:58 69,632 ——w c:\winnt\ServicePackFiles\i386\msconf.dll
+ 2008-04-14 00:12:27 169,984 ——w c:\winnt\ServicePackFiles\i386\msconfig.exe
+ 2007-04-02 20:01:06 116,288 ——w c:\winnt\ServicePackFiles\i386\msconv97.dll
+ 2007-09-26 19:59:53 1,564,672 ——w c:\winnt\ServicePackFiles\i386\mscorcfg.dll
+ 2004-07-15 02:50:28 69,632 ——w c:\winnt\ServicePackFiles\i386\mscordbc.dll
+ 2004-07-15 02:50:28 221,184 ——w c:\winnt\ServicePackFiles\i386\mscordbi.dll
+ 2007-06-27 12:55:10 131,072 ——w c:\winnt\ServicePackFiles\i386\mscoree.dll
+ 2007-01-02 20:29:12 73,728 ——w c:\winnt\ServicePackFiles\i386\mscorie.dll
+ 2004-07-15 02:48:28 303,104 ——w c:\winnt\ServicePackFiles\i386\mscorjit.dll
+ 2007-01-02 20:29:12 86,016 ——w c:\winnt\ServicePackFiles\i386\mscorld.dll
+ 2007-01-02 20:21:20 1,998,848 ——w c:\winnt\ServicePackFiles\i386\mscorlib.dll
+ 2004-07-15 02:50:32 94,208 ——w c:\winnt\ServicePackFiles\i386\mscorpe.dll
+ 2008-04-13 16:10:53 143,360 ——w c:\winnt\ServicePackFiles\i386\mscorrc.chs.dll
+ 2008-04-13 16:10:54 143,360 ——w c:\winnt\ServicePackFiles\i386\mscorrc.cht.dll
+ 2004-07-15 02:50:32 143,360 ——w c:\winnt\ServicePackFiles\i386\mscorrc.dll
+ 2008-04-13 16:10:54 172,032 ——w c:\winnt\ServicePackFiles\i386\mscorrc.es.dll
+ 2008-04-13 16:10:54 172,032 ——w c:\winnt\ServicePackFiles\i386\mscorrc.fr.dll
+ 2008-04-13 16:10:55 167,936 ——w c:\winnt\ServicePackFiles\i386\mscorrc.ger.dll
+ 2008-04-13 16:10:55 167,936 ——w c:\winnt\ServicePackFiles\i386\mscorrc.it.dll
+ 2008-04-13 16:10:55 143,360 ——w c:\winnt\ServicePackFiles\i386\mscorrc.ja.dll
+ 2008-04-13 16:10:55 143,360 ——w c:\winnt\ServicePackFiles\i386\mscorrc.kor.dll
+ 2004-07-15 02:50:34 46,592 ——w c:\winnt\ServicePackFiles\i386\mscorsec.dll
+ 2004-07-15 02:50:34 69,632 ——w c:\winnt\ServicePackFiles\i386\mscorsn.dll
+ 2007-12-17 11:58:53 2,273,280 ——w c:\winnt\ServicePackFiles\i386\mscorsvr.dll
+ 2004-07-15 02:50:40 8,704 ——w c:\winnt\ServicePackFiles\i386\mscortim.dll
+ 2007-12-17 11:59:26 2,281,472 ——w c:\winnt\ServicePackFiles\i386\mscorwks.dll
+ 2008-04-13 17:26:07 12,288 ——w c:\winnt\ServicePackFiles\i386\mscpx32r.dll
+ 2008-04-14 00:11:58 36,864 ——w c:\winnt\ServicePackFiles\i386\mscpxl32.dll
+ 2008-04-14 00:11:58 297,984 ——w c:\winnt\ServicePackFiles\i386\msctf.dll
+ 2008-04-14 00:11:58 68,608 ——w c:\winnt\ServicePackFiles\i386\msctfp.dll
+ 2008-04-14 00:11:58 4,096 ——w c:\winnt\ServicePackFiles\i386\msdadc.dll
+ 2008-04-14 00:11:58 118,784 ——w c:\winnt\ServicePackFiles\i386\msdadiag.dll
+ 2008-04-14 00:11:58 4,096 ——w c:\winnt\ServicePackFiles\i386\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 ——w c:\winnt\ServicePackFiles\i386\msdaer.dll
+ 2008-04-14 00:11:58 532,480 ——w c:\winnt\ServicePackFiles\i386\msdaipp.dll
+ 2008-04-14 00:11:58 233,472 ——w c:\winnt\ServicePackFiles\i386\msdaora.dll
+ 2008-04-13 17:24:14 16,384 ——w c:\winnt\ServicePackFiles\i386\msdaorar.dll
+ 2008-04-14 00:11:58 77,824 ——w c:\winnt\ServicePackFiles\i386\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 ——w c:\winnt\ServicePackFiles\i386\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 ——w c:\winnt\ServicePackFiles\i386\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 ——w c:\winnt\ServicePackFiles\i386\msdaps.dll
+ 2008-04-14 00:11:59 118,784 ——w c:\winnt\ServicePackFiles\i386\msdarem.dll
+ 2008-04-13 17:25:58 16,384 ——w c:\winnt\ServicePackFiles\i386\msdaremr.dll
+ 2008-04-14 00:11:59 151,552 ——w c:\winnt\ServicePackFiles\i386\msdart.dll
+ 2008-04-14 00:11:59 4,096 ——w c:\winnt\ServicePackFiles\i386\msdasc.dll
+ 2008-04-14 00:11:59 315,392 ——w c:\winnt\ServicePackFiles\i386\msdasql.dll
+ 2008-04-13 17:26:07 16,384 ——w c:\winnt\ServicePackFiles\i386\msdasqlr.dll
+ 2008-04-14 00:11:59 94,208 ——w c:\winnt\ServicePackFiles\i386\msdatl3.dll
+ 2008-04-14 00:11:59 20,480 ——w c:\winnt\ServicePackFiles\i386\msdatt.dll
+ 2008-04-14 00:11:59 4,096 ——w c:\winnt\ServicePackFiles\i386\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 ——w c:\winnt\ServicePackFiles\i386\msdfmap.dll
+ 2008-04-14 00:11:59 14,336 ——w c:\winnt\ServicePackFiles\i386\msdmo.dll
+ 2008-04-14 00:12:27 6,144 ——w c:\winnt\ServicePackFiles\i386\msdtc.exe
+ 2008-04-14 00:11:59 58,880 ——w c:\winnt\ServicePackFiles\i386\msdtclog.dll
+ 2008-04-14 00:11:59 427,008 ——w c:\winnt\ServicePackFiles\i386\msdtcprx.dll
+ 2008-04-14 00:11:59 90,112 ——w c:\winnt\ServicePackFiles\i386\msdtcstp.dll
+ 2008-04-14 00:11:59 956,928 ——w c:\winnt\ServicePackFiles\i386\msdtctm.dll
+ 2008-04-14 00:11:59 161,792 ——w c:\winnt\ServicePackFiles\i386\msdtcuiu.dll
+ 2008-04-13 18:46:09 51,200 ——w c:\winnt\ServicePackFiles\i386\msdv.sys
+ 2008-03-25 04:50:28 518,944 ——w c:\winnt\ServicePackFiles\i386\msexch40.dll
+ 2008-03-25 04:50:30 326,432 ——w c:\winnt\ServicePackFiles\i386\msexcl40.dll
+ 2008-04-13 18:32:39 19,072 ——w c:\winnt\ServicePackFiles\i386\msfs.sys
+ 2008-04-14 00:11:59 539,136 ——w c:\winnt\ServicePackFiles\i386\msftedit.dll
+ 2008-04-14 00:11:59 997,376 ——w c:\winnt\ServicePackFiles\i386\msgina.dll
+ 2008-04-13 18:56:32 35,072 ——w c:\winnt\ServicePackFiles\i386\msgpc.sys
+ 2008-04-14 00:11:59 3,166,208 ——w c:\winnt\ServicePackFiles\i386\msgr3en.dll
+ 2008-04-14 00:11:59 15,360 ——w c:\winnt\ServicePackFiles\i386\msgrocm.dll
+ 2008-04-14 00:11:59 82,944 ——w c:\winnt\ServicePackFiles\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 ——w c:\winnt\ServicePackFiles\i386\msgslang.dll
+ 2008-04-14 00:11:59 33,792 ——w c:\winnt\ServicePackFiles\i386\msgsvc.dll
+ 2008-04-14 00:12:45 188,416 ——w c:\winnt\ServicePackFiles\i386\msh261.drv
+ 2008-04-14 00:12:45 294,912 ——w c:\winnt\ServicePackFiles\i386\msh263.drv
+ 2008-04-14 00:12:27 29,184 ——w c:\winnt\ServicePackFiles\i386\mshta.exe
+ 2008-04-14 00:11:59 3,066,880 ——w c:\winnt\ServicePackFiles\i386\mshtml.dll
+ 2008-04-14 00:11:59 449,024 ——w c:\winnt\ServicePackFiles\i386\mshtmled.dll
+ 2008-04-13 16:26:26 56,832 ——w c:\winnt\ServicePackFiles\i386\mshtmler.dll
+ 2008-04-14 00:11:59 2,843,136 ——w c:\winnt\ServicePackFiles\i386\msi.dll
+ 2008-04-14 00:11:59 51,712 ——w c:\winnt\ServicePackFiles\i386\msident.dll
+ 2008-04-14 00:11:59 6,656 ——w c:\winnt\ServicePackFiles\i386\msidle.dll
+ 2008-04-14 00:11:59 248,832 ——w c:\winnt\ServicePackFiles\i386\msieftp.dll
+ 2008-04-14 00:12:28 78,848 ——w c:\winnt\ServicePackFiles\i386\msiexec.exe
+ 2008-04-14 00:11:59 271,360 ——w c:\winnt\ServicePackFiles\i386\msihnd.dll
+ 2008-04-14 00:11:59 4,608 ——w c:\winnt\ServicePackFiles\i386\msimg32.dll
+ 2008-04-14 00:12:28 60,416 ——w c:\winnt\ServicePackFiles\i386\msimn.exe
+ 2008-04-13 15:39:43 884,736 ——w c:\winnt\ServicePackFiles\i386\msimsg.dll
+ 2008-04-14 00:11:59 159,232 ——w c:\winnt\ServicePackFiles\i386\msimtf.dll
+ 2008-04-14 00:11:59 376,832 ——w c:\winnt\ServicePackFiles\i386\msinfo.dll
+ 2008-04-13 18:54:28 22,016 ——w c:\winnt\ServicePackFiles\i386\msircomm.sys
+ 2008-04-14 00:12:28 40,960 ——w c:\winnt\ServicePackFiles\i386\msiregmv.exe
+ 2008-04-14 00:11:59 15,360 ——w c:\winnt\ServicePackFiles\i386\msisip.dll
+ 2008-03-25 04:50:34 1,516,568 ——w c:\winnt\ServicePackFiles\i386\msjet40.dll
+ 2008-03-25 04:50:40 355,112 ——w c:\winnt\ServicePackFiles\i386\msjetol1.dll
+ 2008-04-14 00:12:00 151,583 ——w c:\winnt\ServicePackFiles\i386\msjint40.dll
+ 2008-04-14 00:12:00 102,400 ——w c:\winnt\ServicePackFiles\i386\msjro.dll
+ 2008-03-25 04:50:42 60,192 ——w c:\winnt\ServicePackFiles\i386\msjter40.dll
+ 2008-03-25 04:50:42 248,608 ——w c:\winnt\ServicePackFiles\i386\msjtes40.dll
+ 2008-04-13 18:39:52 7,552 ——w c:\winnt\ServicePackFiles\i386\mskssrv.sys
+ 2008-04-14 00:12:00 25,088 ——w c:\winnt\ServicePackFiles\i386\mslbui.dll
+ 2008-03-25 14:20:46 219,936 ——w c:\winnt\ServicePackFiles\i386\msltus40.dll
+ 2008-04-14 00:12:00 39,936 ——w c:\winnt\ServicePackFiles\i386\mslwvtts.dll
+ 2008-04-14 00:12:00 170,496 ——w c:\winnt\ServicePackFiles\i386\msmqocm.dll
+ 2008-04-14 00:12:28 1,695,232 ——w c:\winnt\ServicePackFiles\i386\msmsgs.exe
+ 2007-04-02 18:39:43 11,053,008 ——w c:\winnt\ServicePackFiles\i386\msncli.exe
+ 2008-04-14 00:12:00 290,816 ——w c:\winnt\ServicePackFiles\i386\msnsspc.dll
+ 2007-04-02 18:42:37 1,327,320 ——w c:\winnt\ServicePackFiles\i386\msnsusii.exe
+ 2008-04-14 00:12:00 122,368 ——w c:\winnt\ServicePackFiles\i386\msobcomm.dll
+ 2008-04-14 00:12:00 16,384 ——w c:\winnt\ServicePackFiles\i386\msobdl.dll
+ 2008-04-14 00:12:00 565,248 ——w c:\winnt\ServicePackFiles\i386\msobmain.dll
+ 2008-04-14 00:12:00 30,720 ——w c:\winnt\ServicePackFiles\i386\msobshel.dll
+ 2008-04-14 00:12:00 19,456 ——w c:\winnt\ServicePackFiles\i386\msobweb.dll
+ 2008-04-14 00:12:00 1,314,816 ——w c:\winnt\ServicePackFiles\i386\msoe.dll
+ 2008-04-14 00:12:00 252,928 ——w c:\winnt\ServicePackFiles\i386\msoeacct.dll
+ 2008-04-13 16:23:54 2,479,616 ——w c:\winnt\ServicePackFiles\i386\msoeres.dll
+ 2008-04-14 00:12:00 105,984 ——w c:\winnt\ServicePackFiles\i386\msoert2.dll
+ 2008-04-14 00:12:28 29,184 ——w c:\winnt\ServicePackFiles\i386\msoobe.exe
+ 2008-04-13 17:24:14 20,480 ——w c:\winnt\ServicePackFiles\i386\msorc32r.dll
+ 2008-04-14 00:12:00 143,360 ——w c:\winnt\ServicePackFiles\i386\msorcl32.dll
+ 2008-04-14 00:12:28 343,040 ——w c:\winnt\ServicePackFiles\i386\mspaint.exe
+ 2008-04-14 00:12:00 29,696 ——w c:\winnt\ServicePackFiles\i386\mspatcha.dll
+ 2008-03-25 04:50:45 355,104 ——w c:\winnt\ServicePackFiles\i386\mspbde40.dll
+ 2008-04-13 18:39:50 5,376 ——w c:\winnt\ServicePackFiles\i386\mspclock.sys
+ 2008-04-13 18:39:51 4,992 ——w c:\winnt\ServicePackFiles\i386\mspqm.sys
+ 2008-04-13 16:23:31 48,128 ——w c:\winnt\ServicePackFiles\i386\msprivs.dll
+ 2008-04-14 00:12:00 146,432 ——w c:\winnt\ServicePackFiles\i386\msrating.dll
+ 2008-03-25 04:50:47 432,928 ——w c:\winnt\ServicePackFiles\i386\msrd2x40.dll
+ 2008-03-25 04:50:49 322,336 ——w c:\winnt\ServicePackFiles\i386\msrd3x40.dll
+ 2008-03-25 04:50:52 559,904 ——w c:\winnt\ServicePackFiles\i386\msrepl40.dll
+ 2008-04-14 00:12:00 11,264 ——w c:\winnt\ServicePackFiles\i386\msrle32.dll
+ 2008-04-14 00:12:00 134,656 ——w c:\winnt\ServicePackFiles\i386\mssap.dll
+ 2008-04-14 00:12:00 155,136 ——w c:\winnt\ServicePackFiles\i386\mssha.dll
+ 2008-04-13 18:14:58 76,800 ——w c:\winnt\ServicePackFiles\i386\msshamsg.dll
+ 2008-04-13 18:36:46 15,488 ——w c:\winnt\ServicePackFiles\i386\mssmbios.sys
+ 2008-04-14 00:12:00 274,432 ——w c:\winnt\ServicePackFiles\i386\mst120.dll
+ 2008-04-14 00:12:00 57,344 ——w c:\winnt\ServicePackFiles\i386\mst123.dll
+ 2008-04-13 18:46:08 49,024 ——w c:\winnt\ServicePackFiles\i386\mstape.sys
+ 2008-04-14 00:12:00 274,944 ——w c:\winnt\ServicePackFiles\i386\mstask.dll
+ 2008-04-13 18:39:50 5,504 ——w c:\winnt\ServicePackFiles\i386\mstee.sys
+ 2008-03-25 04:50:55 264,992 ——w c:\winnt\ServicePackFiles\i386\mstext40.dll
+ 2008-04-14 00:12:00 532,480 ——w c:\winnt\ServicePackFiles\i386\mstime.dll
+ 2008-04-14 00:12:29 12,288 ——w c:\winnt\ServicePackFiles\i386\mstinit.exe
+ 2008-04-14 00:12:00 116,224 ——w c:\winnt\ServicePackFiles\i386\mstlsapi.dll
+ 2008-04-14 00:12:00 195,072 ——w c:\winnt\ServicePackFiles\i386\msutb.dll
+ 2008-04-14 00:12:00 132,608 ——w c:\winnt\ServicePackFiles\i386\msv1_0.dll
+ 2008-04-14 00:12:00 1,384,479 ——w c:\winnt\ServicePackFiles\i386\msvbvm60.dll
+ 2008-04-14 00:12:01 57,344 ——w c:\winnt\ServicePackFiles\i386\msvcirt.dll
+ 2008-04-14 00:12:01 413,696 ——w c:\winnt\ServicePackFiles\i386\msvcp60.dll
+ 2008-04-14 00:12:01 343,040 ——w c:\winnt\ServicePackFiles\i386\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 ——w c:\winnt\ServicePackFiles\i386\msvcrt40.dll
+ 2008-04-14 00:12:01 121,344 ——w c:\winnt\ServicePackFiles\i386\msvfw32.dll
+ 2008-04-14 00:12:01 1,428,992 ——w c:\winnt\ServicePackFiles\i386\msvidctl.dll
+ 2008-04-14 00:12:01 72,704 ——w c:\winnt\ServicePackFiles\i386\msw3prt.dll
+ 2008-03-25 04:50:57 838,432 ——w c:\winnt\ServicePackFiles\i386\mswdat10.dll
+ 2008-04-14 00:12:01 203,776 ——w c:\winnt\ServicePackFiles\i386\mswebdvd.dll
+ 2008-04-14 00:12:01 245,248 ——w c:\winnt\ServicePackFiles\i386\mswsock.dll
+ 2008-03-25 04:50:58 621,344 ——w c:\winnt\ServicePackFiles\i386\mswstr10.dll
+ 2008-04-14 00:12:01 24,576 ——w c:\winnt\ServicePackFiles\i386\msxactps.dll
+ 2008-03-25 04:50:58 355,104 ——w c:\winnt\ServicePackFiles\i386\msxbde40.dll
+ 2008-04-14 00:12:01 506,368 ——w c:\winnt\ServicePackFiles\i386\msxml.dll
+ 2008-04-14 00:12:01 701,440 ——w c:\winnt\ServicePackFiles\i386\msxml2.dll
+ 2008-04-14 00:12:01 1,104,896 ——w c:\winnt\ServicePackFiles\i386\msxml3.dll
+ 2008-04-14 00:12:01 16,896 ——w c:\winnt\ServicePackFiles\i386\msyuv.dll
+ 2004-08-04 03:41:40 126,686 ——w c:\winnt\ServicePackFiles\i386\mtlmnt5.sys
+ 2004-08-04 03:41:38 1,309,184 ——w c:\winnt\ServicePackFiles\i386\mtlstrm.sys
+ 2008-04-14 00:12:29 119,808 ——w c:\winnt\ServicePackFiles\i386\mtstocom.exe
+ 2008-04-14 00:12:01 66,560 ——w c:\winnt\ServicePackFiles\i386\mtxclu.dll
+ 2008-04-14 00:12:01 30,720 ——w c:\winnt\ServicePackFiles\i386\mtxdm.dll
+ 2008-04-14 00:12:01 4,096 ——w c:\winnt\ServicePackFiles\i386\mtxex.dll
+ 2008-04-14 00:12:01 34,304 ——w c:\winnt\ServicePackFiles\i386\mtxlegih.dll
+ 2008-04-14 00:12:01 91,648 ——w c:\winnt\ServicePackFiles\i386\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 ——w c:\winnt\ServicePackFiles\i386\mtxparhd.dll
+ 2004-08-04 03:29:38 452,736 ——w c:\winnt\ServicePackFiles\i386\mtxparhm.sys
+ 2008-04-14 00:12:29 90,624 ——w c:\winnt\ServicePackFiles\i386\muisetup.exe
+ 2008-04-13 19:17:05 105,344 ——w c:\winnt\ServicePackFiles\i386\mup.sys
+ 2008-04-13 18:43:55 12,672 ——w c:\winnt\ServicePackFiles\i386\mutohpen.sys
+ 2008-04-14 00:12:01 90,624 ——w c:\winnt\ServicePackFiles\i386\mydocs.dll
+ 2008-04-13 18:46:25 85,248 ——w c:\winnt\ServicePackFiles\i386\nabtsfec.sys
+ 2008-04-14 00:12:01 221,184 ——w c:\winnt\ServicePackFiles\i386\nac.dll
+ 2008-04-14 00:12:01 30,208 ——w c:\winnt\ServicePackFiles\i386\napipsec.dll
+ 2008-04-14 00:12:01 193,024 ——w c:\winnt\ServicePackFiles\i386\napmontr.dll
+ 2008-04-14 00:12:29 176,640 ——w c:\winnt\ServicePackFiles\i386\napstat.exe
+ 2008-04-14 00:12:29 53,760 ——w c:\winnt\ServicePackFiles\i386\narrator.exe
+ 2008-04-14 00:12:01 36,352 ——w c:\winnt\ServicePackFiles\i386\ncobjapi.dll
+ 2008-04-14 00:12:01 47,104 ——w c:\winnt\ServicePackFiles\i386\ncprov.dll
+ 2008-04-14 00:12:01 9,728 ——w c:\winnt\ServicePackFiles\i386\ncpsres.dll
+ 2008-04-14 00:12:01 17,920 ——w c:\winnt\ServicePackFiles\i386\nddeapi.dll
+ 2008-04-14 00:12:29 4,096 ——w c:\winnt\ServicePackFiles\i386\nddeapir.exe
+ 2008-04-14 00:12:01 18,944 ——w c:\winnt\ServicePackFiles\i386\nddenb32.dll
+ 2008-04-13 19:20:37 182,656 ——w c:\winnt\ServicePackFiles\i386\ndis.sys
+ 2008-04-13 18:46:22 10,880 ——w c:\winnt\ServicePackFiles\i386\ndisip.sys
+ 2008-04-14 00:12:01 57,344 ——w c:\winnt\ServicePackFiles\i386\ndisnpp.dll
+ 2008-04-13 18:57:27 10,112 ——w c:\winnt\ServicePackFiles\i386\ndistapi.sys
+ 2008-04-13 18:55:58 14,592 ——w c:\winnt\ServicePackFiles\i386\ndisuio.sys
+ 2008-04-13 19:20:42 91,520 ——w c:\winnt\ServicePackFiles\i386\ndiswan.sys
+ 2008-04-13 18:57:29 40,576 ——w c:\winnt\ServicePackFiles\i386\ndproxy.sys
+ 2008-04-14 00:12:29 42,496 ——w c:\winnt\ServicePackFiles\i386\net.exe
+ 2008-04-14 00:12:29 124,928 ——w c:\winnt\ServicePackFiles\i386\net1.exe
+ 2008-04-14 00:12:01 337,408 ——w c:\winnt\ServicePackFiles\i386\netapi32.dll
+ 2008-04-13 18:56:02 34,688 ——w c:\winnt\ServicePackFiles\i386\netbios.sys
+ 2008-04-13 19:21:00 162,816 ——w c:\winnt\ServicePackFiles\i386\netbt.sys
+ 2008-04-14 00:12:01 622,592 ——w c:\winnt\ServicePackFiles\i386\netcfgx.dll
+ 2008-04-14 00:12:29 111,104 ——w c:\winnt\ServicePackFiles\i386\netdde.exe
+ 2004-08-03 20:10:58 126,976 ——w c:\winnt\ServicePackFiles\i386\netfxocm.dll
+ 2007-12-17 11:59:53 82,976 ——w c:\winnt\ServicePackFiles\i386\netfxupdate.exe
+ 2008-04-14 00:12:01 139,264 ——w c:\winnt\ServicePackFiles\i386\netid.dll
+ 2008-04-14 00:12:01 407,040 ——w c:\winnt\ServicePackFiles\i386\netlogon.dll
+ 2008-04-14 00:12:01 198,144 ——w c:\winnt\ServicePackFiles\i386\netman.dll
+ 2008-04-14 00:12:01 77,312 ——w c:\winnt\ServicePackFiles\i386\netoc.dll
+ 2008-04-14 00:12:01 875,008 ——w c:\winnt\ServicePackFiles\i386\netplwiz.dll
+ 2008-04-14 00:12:01 11,776 ——w c:\winnt\ServicePackFiles\i386\netrap.dll
+ 2008-04-14 00:16:51 329,728 ——w c:\winnt\ServicePackFiles\i386\netsetup.exe
+ 2008-04-14 00:12:29 86,016 ——w c:\winnt\ServicePackFiles\i386\netsh.exe
+ 2008-04-14 00:12:02 1,703,936 ——w c:\winnt\ServicePackFiles\i386\netshell.dll
+ 2008-04-14 00:12:29 36,864 ——w c:\winnt\ServicePackFiles\i386\netstat.exe
+ 2008-04-14 00:12:02 80,896 ——w c:\winnt\ServicePackFiles\i386\netui0.dll
+ 2008-04-14 00:12:02 245,760 ——w c:\winnt\ServicePackFiles\i386\netui1.dll
+ 2004-08-04 03:31:42 132,695 ——w c:\winnt\ServicePackFiles\i386\netwlan5.sys
+ 2008-04-14 00:12:02 247,808 ——w c:\winnt\ServicePackFiles\i386\newdev.dll
+ 2004-07-15 02:50:58 147,456 ——w c:\winnt\ServicePackFiles\i386\ngen.exe
+ 2008-04-13 18:51:25 61,824 ——w c:\winnt\ServicePackFiles\i386\nic1394.sys
+ 2008-04-14 00:12:02 98,304 ——w c:\winnt\ServicePackFiles\i386\nlhtml.dll
+ 2008-04-14 00:12:02 229,376 ——w c:\winnt\ServicePackFiles\i386\nmas.dll
+ 2008-04-14 00:12:02 28,672 ——w c:\winnt\ServicePackFiles\i386\nmasnt.dll
+ 2008-04-14 00:12:02 81,920 ——w c:\winnt\ServicePackFiles\i386\nmchat.dll
+ 2008-04-14 00:12:02 77,824 ——w c:\winnt\ServicePackFiles\i386\nmcom.dll
+ 2008-04-14 00:12:02 151,552 ——w c:\winnt\ServicePackFiles\i386\nmft.dll
+ 2008-04-14 00:12:02 28,672 ——w c:\winnt\ServicePackFiles\i386\nmmkcert.dll
+ 2008-04-13 18:53:09 40,320 ——w c:\winnt\ServicePackFiles\i386\nmnt.sys
+ 2008-04-14 00:12:02 172,032 ——w c:\winnt\ServicePackFiles\i386\nmoldwb.dll
+ 2008-04-14 00:12:02 188,416 ——w c:\winnt\ServicePackFiles\i386\nmwb.dll
+ 2008-04-14 00:12:29 69,120 ——w c:\winnt\ServicePackFiles\i386\notepad.exe
+ 2008-04-13 18:32:39 30,848 ——w c:\winnt\ServicePackFiles\i386\npfs.sys
+ 2008-04-14 00:12:29 15,360 ——w c:\winnt\ServicePackFiles\i386\nppagent.exe
+ 2008-04-14 00:12:02 54,784 ——w c:\winnt\ServicePackFiles\i386\npptools.dll
+ 2008-04-13 18:54:36 28,672 ——w c:\winnt\ServicePackFiles\i386\nscirda.sys
+ 2008-04-14 00:12:02 44,544 ——w c:\winnt\ServicePackFiles\i386\nsepm.dll
+ 2008-04-14 00:12:29 76,800 ——w c:\winnt\ServicePackFiles\i386\nslookup.exe
+ 2008-04-14 00:12:30 1,200,640 ——w c:\winnt\ServicePackFiles\i386\ntbackup.exe
+ 2004-08-03 20:38:34 47,564 ——w c:\winnt\ServicePackFiles\i386\ntdetect.com
+ 2008-04-14 00:11:24 706,048 ——w c:\winnt\ServicePackFiles\i386\ntdll.dll
+ 2008-04-14 00:12:02 67,072 ——w c:\winnt\ServicePackFiles\i386\ntdsapi.dll
+ 2008-04-14 00:12:02 212,992 ——w c:\winnt\ServicePackFiles\i386\ntevt.dll
+ 2008-04-13 19:15:53 574,976 ——w c:\winnt\ServicePackFiles\i386\ntfs.sys
+ 2004-08-03 20:45:10 33,840 ——w c:\winnt\ServicePackFiles\i386\ntio.sys
+ 2004-08-03 20:45:16 34,560 ——w c:\winnt\ServicePackFiles\i386\ntio404.sys
+ 2004-08-03 20:45:12 35,648 ——w c:\winnt\ServicePackFiles\i386\ntio411.sys
+ 2004-08-03 20:45:16 35,424 ——w c:\winnt\ServicePackFiles\i386\ntio412.sys
+ 2004-08-03 20:45:14 34,560 ——w c:\winnt\ServicePackFiles\i386\ntio804.sys
+ 2008-04-13 19:24:37 2,145,280 ——w c:\winnt\ServicePackFiles\i386\ntkrnlmp.exe
+ 2008-04-13 18:31:21 2,065,792 ——w c:\winnt\ServicePackFiles\i386\ntkrnlpa.exe
+ 2008-04-13 18:31:21 2,023,936 ——w c:\winnt\ServicePackFiles\i386\ntkrpamp.exe
+ 2008-04-14 00:12:02 44,032 ——w c:\winnt\ServicePackFiles\i386\ntlanman.dll
+ 2008-04-14 00:12:02 8,192 ——w c:\winnt\ServicePackFiles\i386\ntlsapi.dll
+ 2008-04-14 00:12:02 118,784 ——w c:\winnt\ServicePackFiles\i386\ntmarta.dll
+ 2008-04-14 00:12:02 40,960 ——w c:\winnt\ServicePackFiles\i386\ntmsapi.dll
+ 2008-04-14 00:12:02 179,200 ——w c:\winnt\ServicePackFiles\i386\ntmsdba.dll
+ 2008-04-14 00:12:02 488,448 ——w c:\winnt\ServicePackFiles\i386\ntmsmgr.dll
+ 2008-04-14 00:12:02 435,200 ——w c:\winnt\ServicePackFiles\i386\ntmssvc.dll
+ 2004-08-04 03:41:40 180,360 ——w c:\winnt\ServicePackFiles\i386\ntmtlfax.sys
+ 2008-04-14 00:12:02 62,976 ——w c:\winnt\ServicePackFiles\i386\ntoc.dll
+ 2008-04-13 19:27:53 2,188,928 ——w c:\winnt\ServicePackFiles\i386\ntoskrnl.exe
+ 2008-04-14 00:12:02 91,136 ——w c:\winnt\ServicePackFiles\i386\ntprint.dll
+ 2008-04-14 00:12:02 143,360 ——w c:\winnt\ServicePackFiles\i386\ntshrui.dll
+ 2008-04-14 00:12:30 420,864 ——w c:\winnt\ServicePackFiles\i386\ntvdm.exe
+ 2008-04-14 00:12:02 15,360 ——w c:\winnt\ServicePackFiles\i386\ntvdmd.dll
+ 2008-04-14 00:12:02 4,274,816 ——w c:\winnt\ServicePackFiles\i386\nv4_disp.dll
+ 2004-08-04 03:29:56 1,897,408 ——w c:\winnt\ServicePackFiles\i386\nv4_mini.sys
+ 2008-04-14 00:12:02 64,000 ——w c:\winnt\ServicePackFiles\i386\nwapi32.dll
+ 2008-04-13 18:56:06 88,320 ——w c:\winnt\ServicePackFiles\i386\nwlnkipx.sys
+ 2008-04-14 00:12:02 142,336 ——w c:\winnt\ServicePackFiles\i386\nwprovau.dll
+ 2008-04-13 18:34:12 163,584 ——w c:\winnt\ServicePackFiles\i386\nwrdr.sys
+ 2008-04-14 00:12:02 65,536 ——w c:\winnt\ServicePackFiles\i386\nwwks.dll
+ 2008-04-14 00:12:02 270,336 ——w c:\winnt\ServicePackFiles\i386\oakley.dll
+ 2008-04-14 00:10:30 229,376 ——w c:\winnt\ServicePackFiles\i386\obelog.dll
+ 2008-04-14 00:10:30 966,656 ——w c:\winnt\ServicePackFiles\i386\obemetal.dll
+ 2007-04-02 18:44:11 77,824 ——w c:\winnt\ServicePackFiles\i386\obemtllc.dll
+ 2008-04-14 00:10:30 86,016 ——w c:\winnt\ServicePackFiles\i386\obepopc.dll
+ 2008-04-14 00:12:02 286,208 ——w c:\winnt\ServicePackFiles\i386\objsel.dll
+ 2008-04-13 18:40:07 393,728 ——w c:\winnt\ServicePackFiles\i386\obrb0401.dll
+ 2008-04-13 18:40:23 212,480 ——w c:\winnt\ServicePackFiles\i386\obrb0404.dll
+ 2008-04-13 18:40:24 428,032 ——w c:\winnt\ServicePackFiles\i386\obrb0405.dll
+ 2008-04-13 18:40:27 418,816 ——w c:\winnt\ServicePackFiles\i386\obrb0406.dll
+ 2008-04-13 18:40:34 403,456 ——w c:\winnt\ServicePackFiles\i386\obrb0407.dll
+ 2008-04-13 18:40:30 419,328 ——w c:\winnt\ServicePackFiles\i386\obrb0408.dll
+ 2008-04-13 18:40:32 405,504 ——w c:\winnt\ServicePackFiles\i386\obrb040b.dll
+ 2008-04-13 18:40:33 410,624 ——w c:\winnt\ServicePackFiles\i386\obrb040c.dll
+ 2008-04-13 18:40:32 384,000 ——w c:\winnt\ServicePackFiles\i386\obrb040d.dll
+ 2008-04-13 18:40:39 434,176 ——w c:\winnt\ServicePackFiles\i386\obrb040e.dll
+ 2008-04-13 18:40:39 413,696 ——w c:\winnt\ServicePackFiles\i386\obrb0410.dll
+ 2008-04-13 18:40:44 275,456 ——w c:\winnt\ServicePackFiles\i386\obrb0411.dll
+ 2008-04-13 18:40:48 306,688 ——w c:\winnt\ServicePackFiles\i386\obrb0412.dll
+ 2008-04-13 18:40:44 401,920 ——w c:\winnt\ServicePackFiles\i386\obrb0413.dll
+ 2008-04-13 18:40:44 353,792 ——w c:\winnt\ServicePackFiles\i386\obrb0414.dll
+ 2008-04-13 18:40:47 391,680 ——w c:\winnt\ServicePackFiles\i386\obrb0415.dll
+ 2008-04-13 18:40:10 409,600 ——w c:\winnt\ServicePackFiles\i386\obrb0416.dll
+ 2008-04-13 18:40:50 427,008 ——w c:\winnt\ServicePackFiles\i386\obrb0419.dll
+ 2008-04-13 18:40:52 405,504 ——w c:\winnt\ServicePackFiles\i386\obrb041b.dll
+ 2008-04-13 18:40:56 363,008 ——w c:\winnt\ServicePackFiles\i386\obrb041d.dll
+ 2008-04-13 18:41:00 390,144 ——w c:\winnt\ServicePackFiles\i386\obrb041f.dll
+ 2008-04-13 18:40:56 408,576 ——w c:\winnt\ServicePackFiles\i386\obrb0424.dll
+ 2008-04-13 18:40:24 270,336 ——w c:\winnt\ServicePackFiles\i386\obrb0804.dll
+ 2008-04-13 18:40:48 435,200 ——w c:\winnt\ServicePackFiles\i386\obrb0816.dll
+ 2008-04-13 18:40:30 446,464 ——w c:\winnt\ServicePackFiles\i386\obrb0c0a.dll
+ 2008-04-14 00:12:02 96,256 ——w c:\winnt\ServicePackFiles\i386\occache.dll
+ 2008-04-14 00:12:02 15,360 ——w c:\winnt\ServicePackFiles\i386\ocgen.dll
+ 2008-04-14 00:12:02 67,584 ——w c:\winnt\ServicePackFiles\i386\ocmanage.dll
+ 2008-04-14 00:12:02 17,408 ——w c:\winnt\ServicePackFiles\i386\ocmsn.dll
+ 2004-07-17 09:36:44 26,224 ——w c:\winnt\ServicePackFiles\i386\odbc16gt.dll
+ 2008-04-14 00:12:02 249,856 ——w c:\winnt\ServicePackFiles\i386\odbc32.dll
+ 2008-04-14 00:12:02 16,384 ——w c:\winnt\ServicePackFiles\i386\odbc32gt.dll
+ 2008-04-14 00:12:30 32,768 ——w c:\winnt\ServicePackFiles\i386\odbcad32.exe
+ 2008-04-14 00:12:02 24,576 ——w c:\winnt\ServicePackFiles\i386\odbcbcp.dll
+ 2008-04-14 00:12:02 135,168 ——w c:\winnt\ServicePackFiles\i386\odbcconf.dll
+ 2008-04-14 00:12:30 69,632 ——w c:\winnt\ServicePackFiles\i386\odbcconf.exe
+ 2008-04-14 00:12:02 106,496 ——w c:\winnt\ServicePackFiles\i386\odbccp32.dll
+ 2008-04-14 00:12:02 65,536 ——w c:\winnt\ServicePackFiles\i386\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 ——w c:\winnt\ServicePackFiles\i386\odbccu32.dll
+ 2008-04-13 17:26:05 94,208 ——w c:\winnt\ServicePackFiles\i386\odbcint.dll
+ 2008-04-14 00:10:31 53,279 ——w c:\winnt\ServicePackFiles\i386\odbcji32.dll
+ 2008-04-14 00:12:02 278,559 ——w c:\winnt\ServicePackFiles\i386\odbcjt32.dll
+ 2008-04-13 17:26:05 12,288 ——w c:\winnt\ServicePackFiles\i386\odbcp32r.dll
+ 2008-04-14 00:12:02 147,456 ——w c:\winnt\ServicePackFiles\i386\odbctrac.dll
+ 2008-04-14 00:12:02 20,511 ——w c:\winnt\ServicePackFiles\i386\oddbse32.dll
+ 2008-04-14 00:12:02 20,510 ——w c:\winnt\ServicePackFiles\i386\odexl32.dll
+ 2008-04-14 00:12:02 20,510 ——w c:\winnt\ServicePackFiles\i386\odfox32.dll
+ 2008-04-14 00:12:02 20,510 ——w c:\winnt\ServicePackFiles\i386\odpdx32.dll
+ 2008-04-14 00:12:02 20,511 ——w c:\winnt\ServicePackFiles\i386\odtext32.dll
+ 2008-04-14 00:12:02 104,448 ——w c:\winnt\ServicePackFiles\i386\oeimport.dll
+ 2008-04-14 00:12:30 60,416 ——w c:\winnt\ServicePackFiles\i386\oemig50.exe
+ 2008-04-14 00:12:02 35,328 ——w c:\winnt\ServicePackFiles\i386\oemiglib.dll
+ 2008-04-14 00:12:02 192,000 ——w c:\winnt\ServicePackFiles\i386\offfilt.dll
+ 2008-04-13 18:46:18 61,696 ——w c:\winnt\ServicePackFiles\i386\ohci1394.sys
+ 2008-04-14 00:12:02 1,287,168 ——w c:\winnt\ServicePackFiles\i386\ole32.dll
+ 2008-04-14 00:12:02 551,936 ——w c:\winnt\ServicePackFiles\i386\oleaut32.dll
+ 2008-04-14 00:12:02 74,752 ——w c:\winnt\ServicePackFiles\i386\olecli32.dll
+ 2008-04-14 00:12:02 37,376 ——w c:\winnt\ServicePackFiles\i386\olecnv32.dll
+ 2008-04-14 00:12:02 487,424 ——w c:\winnt\ServicePackFiles\i386\oledb32.dll
+ 2008-04-14 00:12:02 65,536 ——w c:\winnt\ServicePackFiles\i386\oledb32r.dll
+ 2008-04-14 00:12:02 122,880 ——w c:\winnt\ServicePackFiles\i386\oledlg.dll
+ 2008-04-14 00:12:02 107,008 ——w c:\winnt\ServicePackFiles\i386\oleprn.dll
+ 2008-04-14 00:12:02 84,992 ——w c:\winnt\ServicePackFiles\i386\olepro32.dll
+ 2008-04-14 00:12:02 144,384 ——w c:\winnt\ServicePackFiles\i386\onex.dll
+ 2008-04-14 00:12:31 51,200 ——w c:\winnt\ServicePackFiles\i386\oobebaln.exe
+ 2008-04-14 00:12:02 713,728 ——w c:\winnt\ServicePackFiles\i386\opengl32.dll
+ 2008-04-14 00:12:31 67,584 ——w c:\winnt\ServicePackFiles\i386\opnfiles.exe
+ 2008-04-13 18:32:32 166,912 ——w c:\winnt\ServicePackFiles\i386\oschoice.exe
+ 2008-04-14 00:12:31 215,552 ——w c:\winnt\ServicePackFiles\i386\osk.exe
+ 2008-04-13 18:31:43 230,400 ——w c:\winnt\ServicePackFiles\i386\osloader.exe
+ 2008-04-14 00:12:02 67,584 ——w c:\winnt\ServicePackFiles\i386\osuninst.dll
+ 2008-04-14 00:12:02 153,600 ——w c:\winnt\ServicePackFiles\i386\p2p.dll
+ 2008-04-14 00:12:02 105,472 ——w c:\winnt\ServicePackFiles\i386\p2pgasvc.dll
+ 2008-04-14 00:12:02 313,856 ——w c:\winnt\ServicePackFiles\i386\p2pgraph.dll
+ 2008-04-14 00:12:02 115,712 ——w c:\winnt\ServicePackFiles\i386\p2pnetsh.dll
+ 2008-04-14 00:12:02 554,496 ——w c:\winnt\ServicePackFiles\i386\p2psvc.dll
+ 2008-04-13 18:31:31 42,752 ——w c:\winnt\ServicePackFiles\i386\p3.sys
+ 2008-04-14 00:12:31 58,368 ——w c:\winnt\ServicePackFiles\i386\packager.exe
+ 2008-04-13 18:40:10 80,128 ——w c:\winnt\ServicePackFiles\i386\parport.sys
+ 2008-04-13 18:40:49 19,712 ——w c:\winnt\ServicePackFiles\i386\partmgr.sys
+ 2008-04-14 00:12:02 67,584 ——w c:\winnt\ServicePackFiles\i386\pautoenr.dll
+ 2004-08-04 03:31:24 29,502 ——w c:\winnt\ServicePackFiles\i386\pca200e.sys
+ 2008-04-14 00:12:02 102,912 ——w c:\winnt\ServicePackFiles\i386\pchshell.dll
+ 2008-04-14 00:12:02 38,400 ——w c:\winnt\ServicePackFiles\i386\pchsvc.dll
+ 2008-04-13 18:36:44 68,224 ——w c:\winnt\ServicePackFiles\i386\pci.sys
+ 2008-04-13 18:40:29 24,960 ——w c:\winnt\ServicePackFiles\i386\pciidex.sys
+ 2007-05-15 08:08:11 288,768 ——w c:\winnt\ServicePackFiles\i386\pcl4res.dll
+ 2007-05-15 08:08:13 1,058,816 ——w c:\winnt\ServicePackFiles\i386\pcl5eres.dll
+ 2007-05-15 08:08:14 1,057,280 ——w c:\winnt\ServicePackFiles\i386\pcl5ures.dll
+ 2007-05-15 08:08:14 207,872 ——w c:\winnt\ServicePackFiles\i386\pclxl.dll
+ 2008-04-13 18:36:43 120,192 ——w c:\winnt\ServicePackFiles\i386\pcmcia.sys
+ 2004-08-04 03:06:18 169,984 ——w c:\winnt\ServicePackFiles\i386\pcx500.sys
+ 2008-04-14 00:12:02 284,160 ——w c:\winnt\ServicePackFiles\i386\pdh.dll
+ 2008-04-13 16:11:06 20,480 ——w c:\winnt\ServicePackFiles\i386\perfcounter.dll
+ 2008-04-14 00:12:02 39,936 ——w c:\winnt\ServicePackFiles\i386\perfctrs.dll
+ 2008-04-14 00:12:02 26,624 ——w c:\winnt\ServicePackFiles\i386\perfdisk.dll
+ 2008-04-14 00:12:31 15,872 ——w c:\winnt\ServicePackFiles\i386\perfmon.exe
+ 2008-04-14 00:12:02 17,920 ——w c:\winnt\ServicePackFiles\i386\perfnet.dll
+ 2008-04-14 00:12:02 25,088 ——w c:\winnt\ServicePackFiles\i386\perfos.dll
+ 2008-04-14 00:12:02 34,816 ——w c:\winnt\ServicePackFiles\i386\perfproc.dll
+ 2008-04-13 18:44:29 27,904 ——w c:\winnt\ServicePackFiles\i386\perm2.sys
+ 2008-04-14 00:10:34 211,584 ——w c:\winnt\ServicePackFiles\i386\perm2dll.dll
+ 2008-04-13 18:44:30 28,032 ——w c:\winnt\ServicePackFiles\i386\perm3.sys
+ 2008-04-14 00:10:34 259,328 ——w c:\winnt\ServicePackFiles\i386\perm3dd.dll
+ 2008-04-14 00:12:02 176,128 ——w c:\winnt\ServicePackFiles\i386\photowiz.dll
+ 2008-04-14 00:12:02 35,328 ——w c:\winnt\ServicePackFiles\i386\pid.dll
+ 2008-04-14 00:11:09 24,064 ——w c:\winnt\ServicePackFiles\i386\pidgen.dll
+ 2008-04-14 00:12:31 281,088 ——w c:\winnt\ServicePackFiles\i386\pinball.exe
+ 2008-04-14 00:12:31 17,920 ——w c:\winnt\ServicePackFiles\i386\ping.exe
+ 2008-04-14 00:12:02 15,360 ——w c:\winnt\ServicePackFiles\i386\pjlmon.dll
+ 2008-04-14 00:12:02 44,544 ——w c:\winnt\ServicePackFiles\i386\plotter.dll
+ 2008-04-14 00:12:02 52,736 ——w c:\winnt\ServicePackFiles\i386\plotui.dll
+ 2008-04-14 00:12:02 412,160 ——w c:\winnt\ServicePackFiles\i386\pmh.dll
+ 2008-04-14 00:12:02 39,424 ——w c:\winnt\ServicePackFiles\i386\pngfilt.dll
+ 2008-04-14 00:12:02 58,880 ——w c:\winnt\ServicePackFiles\i386\pnrpnsp.dll
+ 2008-04-14 00:12:02 92,672 ——w c:\winnt\ServicePackFiles\i386\policman.dll
+ 2008-04-14 00:12:02 105,472 ——w c:\winnt\ServicePackFiles\i386\polstore.dll
+ 2008-04-13 19:19:41 146,048 ——w c:\winnt\ServicePackFiles\i386\portcls.sys
+ 2008-04-14 00:12:31 49,152 ——w c:\winnt\ServicePackFiles\i386\powercfg.exe
+ 2008-04-13 18:40:56 8,832 ——w c:\winnt\ServicePackFiles\i386\powerfil.sys
+ 2008-04-14 00:12:03 17,408 ——w c:\winnt\ServicePackFiles\i386\powrprof.dll
+ 2008-04-13 18:41:00 17,664 ——w c:\winnt\ServicePackFiles\i386\ppa3.sys
+ 2008-04-14 00:12:03 560,640 ——w c:\winnt\ServicePackFiles\i386\printui.dll
+ 2008-04-13 18:31:30 35,840 ——w c:\winnt\ServicePackFiles\i386\processr.sys
+ 2008-04-14 00:12:03 27,648 ——w c:\winnt\ServicePackFiles\i386\profmap.dll
+ 2008-04-14 00:12:31 109,568 ——w c:\winnt\ServicePackFiles\i386\progman.exe
+ 2008-04-14 00:12:32 50,176 ——w c:\winnt\ServicePackFiles\i386\proquota.exe
+ 2008-04-14 00:12:03 237,056 ——w c:\winnt\ServicePackFiles\i386\provthrd.dll
+ 2008-04-14 00:12:32 9,216 ——w c:\winnt\ServicePackFiles\i386\proxycfg.exe
+ 2008-04-14 00:12:03 728,576 ——w c:\winnt\ServicePackFiles\i386\ps5ui.dll
+ 2008-04-14 00:12:03 23,040 ——w c:\winnt\ServicePackFiles\i386\psapi.dll
+ 2008-04-14 00:12:03 96,768 ——w c:\winnt\ServicePackFiles\i386\psbase.dll
+ 2008-04-13 18:56:38 69,120 ——w c:\winnt\ServicePackFiles\i386\psched.sys
+ 2008-04-14 00:12:03 543,232 ——w c:\winnt\ServicePackFiles\i386\pscript5.dll
+ 2008-04-14 00:12:03 363,520 ——w c:\winnt\ServicePackFiles\i386\psisdecd.dll
+ 2008-04-14 00:12:03 43,520 ——w c:\winnt\ServicePackFiles\i386\pstorec.dll
+ 2008-04-14 00:12:03 34,304 ——w c:\winnt\ServicePackFiles\i386\pstorsvc.dll
+ 2008-04-14 00:12:03 159,232 ——w c:\winnt\ServicePackFiles\i386\ptpusd.dll
+ 2008-04-14 00:12:03 7,680 ——w c:\winnt\ServicePackFiles\i386\pwsdata.dll
+ 2008-04-14 00:12:03 150,528 ——w c:\winnt\ServicePackFiles\i386\qagent.dll
+ 2008-04-14 00:12:03 291,328 ——w c:\winnt\ServicePackFiles\i386\qagentrt.dll
+ 2008-04-14 00:12:03 237,568 ——w c:\winnt\ServicePackFiles\i386\qasf.dll
+ 2008-04-14 00:12:03 192,512 ——w c:\winnt\ServicePackFiles\i386\qcap.dll
+ 2008-04-14 00:12:03 62,464 ——w c:\winnt\ServicePackFiles\i386\qcliprov.dll
+ 2008-04-14 00:12:03 279,040 ——w c:\winnt\ServicePackFiles\i386\qdv.dll
+ 2008-04-14 00:12:03 386,048 ——w c:\winnt\ServicePackFiles\i386\qdvd.dll
+ 2008-04-14 00:12:03 562,176 ——w c:\winnt\ServicePackFiles\i386\qedit.dll
+ 2008-04-13 17:21:32 733,696 ——w c:\winnt\ServicePackFiles\i386\qedwipes.dll
+ 2008-04-13 18:40:52 6,016 ——w c:\winnt\ServicePackFiles\i386\qic157.sys
+ 2008-04-14 00:12:03 409,088 ——w c:\winnt\ServicePackFiles\i386\qmgr.dll
+ 2008-04-14 00:12:03 18,944 ——w c:\winnt\ServicePackFiles\i386\qmgrprxy.dll
+ 2008-04-14 00:12:32 19,968 ——w c:\winnt\ServicePackFiles\i386\qprocess.exe
+ 2008-04-14 00:12:03 1,288,192 ——w c:\winnt\ServicePackFiles\i386\quartz.dll
+ 2008-04-14 00:12:03 1,435,648 ——w c:\winnt\ServicePackFiles\i386\query.dll
+ 2008-04-14 00:12:03 76,800 ——w c:\winnt\ServicePackFiles\i386\qutil.dll
+ 2008-04-14 00:12:03 43,520 ——w c:\winnt\ServicePackFiles\i386\racpldlg.dll
+ 2008-04-13 18:41:23 20,736 ——w c:\winnt\ServicePackFiles\i386\ramdisk.sys
+ 2008-04-14 00:12:03 7,680 ——w c:\winnt\ServicePackFiles\i386\rasadhlp.dll
+ 2008-04-14 00:12:03 237,056 ——w c:\winnt\ServicePackFiles\i386\rasapi32.dll
+ 2008-04-14 00:12:03 88,576 ——w c:\winnt\ServicePackFiles\i386\rasauto.dll
+ 2008-04-14 00:12:03 79,872 ——w c:\winnt\ServicePackFiles\i386\raschap.dll
+ 2008-04-14 00:12:03 658,432 ——w c:\winnt\ServicePackFiles\i386\rasdlg.dll
+ 2008-04-13 19:19:43 51,328 ——w c:\winnt\ServicePackFiles\i386\rasl2tp.sys
+ 2008-04-14 00:12:03 61,440 ——w c:\winnt\ServicePackFiles\i386\rasman.dll
+ 2008-04-14 00:12:03 186,368 ——w c:\winnt\ServicePackFiles\i386\rasmans.dll
+ 2008-04-14 00:12:32 56,832 ——w c:\winnt\ServicePackFiles\i386\rasphone.exe
+ 2008-04-14 00:12:03 210,944 ——w c:\winnt\ServicePackFiles\i386\rasppp.dll
+ 2008-04-13 18:57:32 41,472 ——w c:\winnt\ServicePackFiles\i386\raspppoe.sys
+ 2008-04-13 19:19:48 48,384 ——w c:\winnt\ServicePackFiles\i386\raspptp.sys
+ 2008-04-14 00:12:03 61,952 ——w c:\winnt\ServicePackFiles\i386\rasqec.dll
+ 2008-04-14 00:12:03 16,384 ——w c:\winnt\ServicePackFiles\i386\rassapi.dll
+ 2008-04-14 00:12:03 58,368 ——w c:\winnt\ServicePackFiles\i386\rastapi.dll
+ 2008-04-14 00:12:03 150,016 ——w c:\winnt\ServicePackFiles\i386\rastls.dll
+ 2008-04-14 00:12:03 102,400 ——w c:\winnt\ServicePackFiles\i386\rcbdyctl.dll
+ 2008-04-14 00:12:32 35,840 ——w c:\winnt\ServicePackFiles\i386\rcimlby.exe
+ 2008-04-14 00:12:32 21,504 ——w c:\winnt\ServicePackFiles\i386\rcp.exe
+ 2008-04-13 19:28:39 175,744 ——w c:\winnt\ServicePackFiles\i386\rdbss.sys
+ 2008-04-14 00:12:03 147,968 ——w c:\winnt\ServicePackFiles\i386\rdchost.dll
+ 2008-04-14 00:12:32 62,976 ——w c:\winnt\ServicePackFiles\i386\rdpclip.exe
+ 2008-04-14 00:13:22 92,424 ——w c:\winnt\ServicePackFiles\i386\rdpdd.dll
+ 2008-04-13 18:32:51 196,224 ——w c:\winnt\ServicePackFiles\i386\rdpdr.sys
+ 2008-04-14 00:12:04 19,968 ——w c:\winnt\ServicePackFiles\i386\rdpsnd.dll
+ 2008-04-14 00:13:22 139,656 ——w c:\winnt\ServicePackFiles\i386\rdpwd.sys
+ 2008-04-14 00:13:22 87,176 ——w c:\winnt\ServicePackFiles\i386\rdpwsx.dll
+ 2008-04-14 00:12:32 13,824 ——w c:\winnt\ServicePackFiles\i386\rdsaddin.exe
+ 2008-04-14 00:12:32 67,072 ——w c:\winnt\ServicePackFiles\i386\rdshost.exe
+ 2004-08-04 03:41:40 13,776 ——w c:\winnt\ServicePackFiles\i386\recagent.sys
+ 2008-04-13 18:40:27 57,600 ——w c:\winnt\ServicePackFiles\i386\redbook.sys
+ 2004-08-03 20:48:46 3,338 ——w c:\winnt\ServicePackFiles\i386\redir.exe
+ 2008-04-14 00:12:32 50,176 ——w c:\winnt\ServicePackFiles\i386\reg.exe
+ 2008-04-14 00:12:04 49,664 ——w c:\winnt\ServicePackFiles\i386\regapi.dll
+ 2004-07-15 15:05:12 28,672 ——w c:\winnt\ServicePackFiles\i386\regasm.exe
+ 2007-09-26 19:59:52 32,768 ——w c:\winnt\ServicePackFiles\i386\regcode.dll
+ 2008-04-14 00:12:32 146,432 ——w c:\winnt\ServicePackFiles\i386\regedit.exe
+ 2008-04-14 00:12:04 59,904 ——w c:\winnt\ServicePackFiles\i386\regsvc.dll
+ 2004-07-15 15:04:12 11,264 ——w c:\winnt\ServicePackFiles\i386\regsvcs.exe
+ 2008-04-14 00:12:32 11,776 ——w c:\winnt\ServicePackFiles\i386\regsvr32.exe
+ 2008-04-14 00:12:04 397,824 ——w c:\winnt\ServicePackFiles\i386\regwizc.dll
+ 2008-04-14 00:12:04 60,416 ——w c:\winnt\ServicePackFiles\i386\remotepg.dll
+ 2008-04-14 00:12:04 178,176 ——w c:\winnt\ServicePackFiles\i386\repdrvfs.dll
+ 2008-04-14 00:12:04 58,880 ——w c:\winnt\ServicePackFiles\i386\resutils.dll
+ 2008-04-14 00:12:33 13,824 ——w c:\winnt\ServicePackFiles\i386\rexec.exe
+ 2008-04-13 18:46:32 59,136 ——w c:\winnt\ServicePackFiles\i386\rfcomm.sys
+ 2008-04-14 00:12:04 290,304 ——w c:\winnt\ServicePackFiles\i386\rhttpaa.dll
+ 2008-04-14 00:12:04 123,392 ——w c:\winnt\ServicePackFiles\i386\riafres.dll
+ 2008-04-14 00:12:04 11,776 ——w c:\winnt\ServicePackFiles\i386\riafui1.dll
+ 2008-04-14 00:12:04 11,776 ——w c:\winnt\ServicePackFiles\i386\riafui2.dll
+ 2008-04-14 00:12:04 433,664 ——w c:\winnt\ServicePackFiles\i386\riched20.dll
+ 2008-04-13 18:55:08 202,624 ——w c:\winnt\ServicePackFiles\i386\rmcast.sys
+ 2008-04-13 18:56:49 30,592 ——w c:\winnt\ServicePackFiles\i386\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ——w c:\winnt\ServicePackFiles\i386\rndismpx.sys
+ 2008-04-13 18:40:14 79,104 ——w c:\winnt\ServicePackFiles\i386\rocket.sys
+ 2008-04-14 00:12:04 4,096 ——w c:\winnt\ServicePackFiles\i386\rpcref.dll
+ 2008-04-14 00:12:04 584,704 ——w c:\winnt\ServicePackFiles\i386\rpcrt4.dll
+ 2008-04-14 00:12:04 399,360 ——w c:\winnt\ServicePackFiles\i386\rpcss.dll
+ 2008-04-14 00:12:04 61,440 ——w c:\winnt\ServicePackFiles\i386\rrcm.dll
+ 2008-04-13 17:37:57 208,384 ——w c:\winnt\ServicePackFiles\i386\rsaenh.dll
+ 2008-04-14 00:12:33 14,848 ——w c:\winnt\ServicePackFiles\i386\rsh.exe
+ 2008-04-14 00:12:04 39,936 ——w c:\winnt\ServicePackFiles\i386\rshx32.dll
+ 2008-04-14 00:12:04 18,944 ——w c:\winnt\ServicePackFiles\i386\rsmps.dll
+ 2008-04-14 00:12:33 107,520 ——w c:\winnt\ServicePackFiles\i386\rsnotify.exe
+ 2008-04-14 00:12:33 380,416 ——w c:\winnt\ServicePackFiles\i386\rstrui.exe
+ 2008-04-14 00:12:04 92,672 ——w c:\winnt\ServicePackFiles\i386\rsvpsp.dll
+ 2008-04-14 00:12:33 77,312 ——w c:\winnt\ServicePackFiles\i386\rtcshare.exe
+ 2008-04-14 00:12:04 31,744 ——w c:\winnt\ServicePackFiles\i386\rtipxmib.dll
+ 2004-08-04 03:31:34 20,992 ——w c:\winnt\ServicePackFiles\i386\rtl8139.sys
+ 2008-04-14 00:12:04 44,032 ——w c:\winnt\ServicePackFiles\i386\rtutils.dll
+ 2008-04-14 00:12:33 33,280 ——w c:\winnt\ServicePackFiles\i386\rundll32.exe
+ 2008-04-14 00:12:33 14,336 ——w c:\winnt\ServicePackFiles\i386\runonce.exe
+ 2008-04-14 00:12:04 27,648 ——w c:\winnt\ServicePackFiles\i386\rw001ext.dll
+ 2008-04-14 00:12:04 29,184 ——w c:\winnt\ServicePackFiles\i386\rw330ext.dll
+ 2008-04-14 00:12:04 27,648 ——w c:\winnt\ServicePackFiles\i386\rw430ext.dll
+ 2008-04-14 00:12:04 29,696 ——w c:\winnt\ServicePackFiles\i386\rw450ext.dll
+ 2008-04-14 00:12:04 9,728 ——w c:\winnt\ServicePackFiles\i386\rwnh.dll
+ 2008-04-14 00:12:04 397,056 ——w c:\winnt\ServicePackFiles\i386\s3gnb.dll
+ 2004-08-04 03:29:52 166,912 ——w c:\winnt\ServicePackFiles\i386\s3gnbm.sys
+ 2008-04-14 00:12:04 43,520 ——w c:\winnt\ServicePackFiles\i386\safrcdlg.dll
+ 2008-04-14 00:12:04 29,696 ——w c:\winnt\ServicePackFiles\i386\safrdm.dll
+ 2008-04-14 00:12:04 45,568 ——w c:\winnt\ServicePackFiles\i386\safrslv.dll
+ 2008-04-14 00:12:04 64,000 ——w c:\winnt\ServicePackFiles\i386\samlib.dll
+ 2008-04-14 00:12:04 415,744 ——w c:\winnt\ServicePackFiles\i386\samsrv.dll
+ 2008-04-14 00:12:04 741,376 ——w c:\winnt\ServicePackFiles\i386\sapi.dll
+ 2008-04-14 00:12:33 13,312 ——w c:\winnt\ServicePackFiles\i386\savedump.exe
+ 2008-04-14 00:12:04 270,848 ——w c:\winnt\ServicePackFiles\i386\sbe.dll
+ 2008-04-14 00:12:04 159,232 ——w c:\winnt\ServicePackFiles\i386\sbeio.dll
+ 2008-04-13 18:40:48 43,904 ——w c:\winnt\ServicePackFiles\i386\sbp2port.sys
+ 2008-04-14 00:12:04 69,632 ——w c:\winnt\ServicePackFiles\i386\scarddlg.dll
+ 2008-04-14 00:12:33 95,744 ——w c:\winnt\ServicePackFiles\i386\scardsvr.exe
+ 2004-08-03 20:31:44 169,984 ——w c:\winnt\ServicePackFiles\i386\sccbase.dll
+ 2008-04-14 00:12:05 171,008 ——w c:\winnt\ServicePackFiles\i386\sccsccp.dll
+ 2008-04-14 00:12:05 181,248 ——w c:\winnt\ServicePackFiles\i386\scecli.dll
+ 2008-04-14 00:12:05 314,880 ——w c:\winnt\ServicePackFiles\i386\scesrv.dll
+ 2008-04-14 00:12:05 144,384 ——w c:\winnt\ServicePackFiles\i386\schannel.dll
+ 2008-04-14 00:12:05 192,512 ——w c:\winnt\ServicePackFiles\i386\schedsvc.dll
+ 2008-04-14 00:12:05 20,480 ——w c:\winnt\ServicePackFiles\i386\sclgntfy.dll
+ 2008-04-14 00:12:34 36,352 ——w c:\winnt\ServicePackFiles\i386\scrcons.exe
+ 2008-04-14 00:12:05 215,552 ——w c:\winnt\ServicePackFiles\i386\script.dll
+ 2008-04-14 00:12:05 199,680 ——w c:\winnt\ServicePackFiles\i386\scripta.dll
+ 2008-04-14 00:12:43 9,216 ——w c:\winnt\ServicePackFiles\i386\scrnsave.scr
+ 2008-04-14 00:12:05 180,224 ——w c:\winnt\ServicePackFiles\i386\scrobj.dll
+ 2008-04-14 00:12:05 172,032 ——w c:\winnt\ServicePackFiles\i386\scrrun.dll
+ 2008-04-13 18:40:30 96,384 ——w c:\winnt\ServicePackFiles\i386\scsiport.sys
+ 2008-04-13 18:45:33 11,520 ——w c:\winnt\ServicePackFiles\i386\scsiscan.sys
+ 2008-04-14 00:12:34 121,856 ——w c:\winnt\ServicePackFiles\i386\sctasks.exe
+ 2008-04-14 00:12:34 77,312 ——w c:\winnt\ServicePackFiles\i386\sdbinst.exe
+ 2008-04-13 18:36:44 79,232 ——w c:\winnt\ServicePackFiles\i386\sdbus.sys
+ 2008-04-14 00:12:05 29,184 ——w c:\winnt\ServicePackFiles\i386\sdhcinst.dll
+ 2007-11-13 10:25:53 20,480 ——w c:\winnt\ServicePackFiles\i386\secdrv.sys
+ 2008-04-14 00:12:34 18,944 ——w c:\winnt\ServicePackFiles\i386\secedit.exe
+ 2008-04-14 00:12:05 18,944 ——w c:\winnt\ServicePackFiles\i386\seclogon.dll
+ 2006-12-31 12:57:08 4,569 ——w c:\winnt\ServicePackFiles\i386\secupd.dat
+ 2008-04-14 00:12:05 56,320 ——w c:\winnt\ServicePackFiles\i386\secur32.dll
+ 2008-04-14 00:12:05 5,632 ——w c:\winnt\ServicePackFiles\i386\security.dll
+ 2008-04-14 00:12:05 29,184 ——w c:\winnt\ServicePackFiles\i386\sendcmsg.dll
+ 2008-04-14 00:12:05 54,784 ——w c:\winnt\ServicePackFiles\i386\sendmail.dll
+ 2008-04-14 00:12:05 39,424 ——w c:\winnt\ServicePackFiles\i386\sens.dll
+ 2008-04-14 00:12:05 7,168 ——w c:\winnt\ServicePackFiles\i386\sensapi.dll
+ 2008-04-14 00:12:05 221,696 ——w c:\winnt\ServicePackFiles\i386\seo.dll
+ 2008-04-13 18:40:12 15,744 ——w c:\winnt\ServicePackFiles\i386\serenum.sys
+ 2008-04-13 19:15:45 64,512 ——w c:\winnt\ServicePackFiles\i386\serial.sys
+ 2008-04-14 00:12:05 56,320 ——w c:\winnt\ServicePackFiles\i386\servdeps.dll
+ 2008-04-14 00:12:34 108,544 ——w c:\winnt\ServicePackFiles\i386\services.exe
+ 2008-04-14 00:12:34 141,312 ——w c:\winnt\ServicePackFiles\i386\sessmgr.exe
+ 2008-04-14 00:12:34 31,232 ——w c:\winnt\ServicePackFiles\i386\sethc.exe
+ 2007-12-17 11:59:54 66,592 ——w c:\winnt\ServicePackFiles\i386\setregni.exe
+ 2008-04-14 00:12:34 23,040 ——w c:\winnt\ServicePackFiles\i386\setup.exe
+ 2008-04-14 00:12:34 73,216 ——w c:\winnt\ServicePackFiles\i386\setup50.exe
+ 2008-04-14 10:42:06 985,088 ——w c:\winnt\ServicePackFiles\i386\setupapi.dll
+ 2008-04-14 00:12:35 32,768 ——w c:\winnt\ServicePackFiles\i386\setupn.exe
+ 2008-04-14 00:12:05 101,376 ——w c:\winnt\ServicePackFiles\i386\setupqry.dll
+ 2008-04-14 00:12:05 5,120 ——w c:\winnt\ServicePackFiles\i386\sfc.dll
+ 2008-04-14 00:12:05 140,288 ——w c:\winnt\ServicePackFiles\i386\sfc_os.dll
+ 2008-04-14 00:12:05 1,614,848 ——w c:\winnt\ServicePackFiles\i386\sfcfiles.dll
+ 2008-04-13 18:40:47 11,904 ——w c:\winnt\ServicePackFiles\i386\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 ——w c:\winnt\ServicePackFiles\i386\sffp_mmc.sys
+ 2008-04-13 18:40:47 11,008 ——w c:\winnt\ServicePackFiles\i386\sffp_sd.sys
+ 2008-04-13 18:40:48 11,392 ——w c:\winnt\ServicePackFiles\i386\sfloppy.sys
+ 2008-04-13 17:03:19 549,376 ——w c:\winnt\ServicePackFiles\i386\shdoclc.dll
+ 2008-04-14 00:12:05 1,499,136 ——w c:\winnt\ServicePackFiles\i386\shdocvw.dll
+ 2008-04-14 00:12:05 8,461,312 ——w c:\winnt\ServicePackFiles\i386\shell32.dll
+ 2008-04-14 00:12:05 25,088 ——w c:\winnt\ServicePackFiles\i386\shfolder.dll
+ 2008-04-14 00:12:05 68,096 ——w c:\winnt\ServicePackFiles\i386\shgina.dll
+ 2008-04-14 00:12:05 65,024 ——w c:\winnt\ServicePackFiles\i386\shimeng.dll
+ 2008-04-14 00:12:05 438,272 ——w c:\winnt\ServicePackFiles\i386\shimgvw.dll
+ 2008-04-14 00:12:05 474,112 ——w c:\winnt\ServicePackFiles\i386\shlwapi.dll
+ 2008-04-14 00:12:35 45,056 ——w c:\winnt\ServicePackFiles\i386\shmgrate.exe
+ 2008-04-14 00:12:35 77,824 ——w c:\winnt\ServicePackFiles\i386\shrpubw.exe
+ 2008-04-14 00:12:05 27,648 ——w c:\winnt\ServicePackFiles\i386\shscrap.dll
+ 2008-04-14 00:12:05 135,168 ——w c:\winnt\ServicePackFiles\i386\shsvcs.dll
+ 2008-04-14 00:12:05 20,536 ——w c:\winnt\ServicePackFiles\i386\shtml.dll
+ 2008-04-14 00:12:35 16,437 ——w c:\winnt\ServicePackFiles\i386\shtml.exe
+ 2008-04-14 00:12:35 19,456 ——w c:\winnt\ServicePackFiles\i386\shutdown.exe
+ 2008-04-14 00:12:05 13,312 ——w c:\winnt\ServicePackFiles\i386\sigtab.dll
+ 2008-04-14 00:12:35 70,144 ——w c:\winnt\ServicePackFiles\i386\sigverif.exe
+ 2008-04-14 00:12:05 3,901 ——w c:\winnt\ServicePackFiles\i386\siint5.dll
+ 2008-04-13 18:36:39 40,960 ——w c:\winnt\ServicePackFiles\i386\sisagp.sys
+ 2004-08-04 03:31:36 32,768 ——w c:\winnt\ServicePackFiles\i386\sisnic.sys
+ 2008-04-14 00:12:35 26,112 ——w c:\winnt\ServicePackFiles\i386\skeys.exe
+ 2004-08-04 03:31:42 63,547 ——w c:\winnt\ServicePackFiles\i386\sla30nd5.sys
+ 2008-04-14 00:12:06 25,088 ——w c:\winnt\ServicePackFiles\i386\slayerxp.dll
+ 2004-08-03 20:31:44 306,176 ——w c:\winnt\ServicePackFiles\i386\slbcsp.dll
+ 2008-04-14 00:12:06 98,304 ——w c:\winnt\ServicePackFiles\i386\slbiop.dll
+ 2008-04-14 00:12:06 73,832 ——w c:\winnt\ServicePackFiles\i386\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 ——w c:\winnt\ServicePackFiles\i386\slextspk.dll
+ 2008-04-14 00:12:06 188,508 ——w c:\winnt\ServicePackFiles\i386\slgen.dll
+ 2008-04-13 18:46:23 11,136 ——w c:\winnt\ServicePackFiles\i386\slip.sys
+ 2004-08-04 03:41:42 129,535 ——w c:\winnt\ServicePackFiles\i386\slnt7554.sys
+ 2004-08-04 03:41:44 404,990 ——w c:\winnt\ServicePackFiles\i386\slntamr.sys
+ 2004-08-04 03:41:46 95,424 ——w c:\winnt\ServicePackFiles\i386\slnthal.sys
+ 2008-04-14 00:12:35 32,866 ——w c:\winnt\ServicePackFiles\i386\slrundll.exe
+ 2008-04-14 00:12:35 73,796 ——w c:\winnt\ServicePackFiles\i386\slserv.exe
+ 2004-08-04 03:41:46 13,240 ——w c:\winnt\ServicePackFiles\i386\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 ——w c:\winnt\ServicePackFiles\i386\smbali.sys
+ 2008-04-13 18:36:33 16,000 ——w c:\winnt\ServicePackFiles\i386\smbbatt.sys
+ 2008-04-13 18:36:33 6,912 ——w c:\winnt\ServicePackFiles\i386\smbclass.sys
+ 2008-04-14 00:12:35 8,192 ——w c:\winnt\ServicePackFiles\i386\smbinst.exe
+ 2008-04-14 00:12:35 236,544 ——w c:\winnt\ServicePackFiles\i386\smi2smir.exe
+ 2008-04-14 00:12:06 362,496 ——w c:\winnt\ServicePackFiles\i386\smlogcfg.dll
+ 2008-04-14 00:12:35 89,600 ——w c:\winnt\ServicePackFiles\i386\smlogsvc.exe
+ 2008-04-14 00:12:36 50,688 ——w c:\winnt\ServicePackFiles\i386\smss.exe
+ 2008-04-14 00:12:06 189,440 ——w c:\winnt\ServicePackFiles\i386\smtpadm.dll
+ 2008-04-14 00:12:06 10,752 ——w c:\winnt\ServicePackFiles\i386\smtpapi.dll
+ 2008-04-14 00:12:06 2,134,528 ——w c:\winnt\ServicePackFiles\i386\smtpsnap.dll
+ 2008-04-14 00:12:06 456,192 ——w c:\winnt\ServicePackFiles\i386\smtpsvc.dll
+ 2008-04-14 00:12:36 131,584 ——w c:\winnt\ServicePackFiles\i386\sndrec32.exe
+ 2008-04-14 00:12:06 34,816 ——w c:\winnt\ServicePackFiles\i386\sniffpol.dll
+ 2008-04-14 00:12:36 33,280 ——w c:\winnt\ServicePackFiles\i386\snmp.exe
+ 2008-04-14 00:12:06 18,944 ——w c:\winnt\ServicePackFiles\i386\snmpapi.dll
+ 2008-04-14 00:12:06 259,072 ——w c:\winnt\ServicePackFiles\i386\snmpcl.dll
+ 2008-04-14 00:12:06 358,400 ——w c:\winnt\ServicePackFiles\i386\snmpincl.dll
+ 2008-04-14 00:12:06 6,144 ——w c:\winnt\ServicePackFiles\i386\snmpmib.dll
+ 2008-04-14 00:12:06 188,416 ——w c:\winnt\ServicePackFiles\i386\snmpsmir.dll
+ 2008-04-14 00:12:06 182,272 ——w c:\winnt\ServicePackFiles\i386\snmpsnap.dll
+ 2008-04-14 00:12:06 39,936 ——w c:\winnt\ServicePackFiles\i386\snmpthrd.dll
+ 2008-04-14 00:12:36 8,704 ——w c:\winnt\ServicePackFiles\i386\snmptrap.exe
+ 2008-04-14 00:12:06 130,048 ——w c:\winnt\ServicePackFiles\i386\softkbd.dll
+ 2008-04-13 18:40:52 7,552 ——w c:\winnt\ServicePackFiles\i386\sonyait.sys
+ 2008-04-13 18:46:07 25,344 ——w c:\winnt\ServicePackFiles\i386\sonydcam.sys
+ 2008-04-14 00:12:36 24,576 ——w c:\winnt\ServicePackFiles\i386\sort.exe
+ 2008-04-14 00:12:36 7,680 ——w c:\winnt\ServicePackFiles\i386\spdwnwxp.exe
+ 2008-04-13 16:43:18 62,976 ——w c:\winnt\ServicePackFiles\i386\spgrmr.dll
+ 2008-04-14 00:12:36 538,624 ——w c:\winnt\ServicePackFiles\i386\spider.exe
+ 2008-04-13 18:43:31 12,800 ——w c:\winnt\ServicePackFiles\i386\spiisupd.exe
+ 2008-04-13 18:45:07 6,272 ——w c:\winnt\ServicePackFiles\i386\splitter.sys
+ 2008-04-14 10:42:38 11,264 ——w c:\winnt\ServicePackFiles\i386\spnpinst.exe
+ 2008-04-14 00:12:06 75,264 ——w c:\winnt\ServicePackFiles\i386\spoolss.dll
+ 2008-04-14 00:12:36 57,856 ——w c:\winnt\ServicePackFiles\i386\spoolsv.exe
+ 2008-04-13 18:35:06 186,880 ——w c:\winnt\ServicePackFiles\i386\spra0401.dll
+ 2008-04-13 18:35:08 189,440 ——w c:\winnt\ServicePackFiles\i386\spra0402.dll
+ 2008-04-13 18:35:09 161,280 ——w c:\winnt\ServicePackFiles\i386\spra0404.dll
+ 2008-04-13 18:35:09 188,928 ——w c:\winnt\ServicePackFiles\i386\spra0405.dll
+ 2008-04-13 18:35:09 192,000 ——w c:\winnt\ServicePackFiles\i386\spra0406.dll
+ 2008-04-13 18:35:21 199,680 ——w c:\winnt\ServicePackFiles\i386\spra0407.dll
+ 2008-04-13 18:35:11 197,632 ——w c:\winnt\ServicePackFiles\i386\spra0408.dll
+ 2008-04-13 18:35:11 186,368 ——w c:\winnt\ServicePackFiles\i386\spra040b.dll
+ 2008-04-13 18:35:20 197,632 ——w c:\winnt\ServicePackFiles\i386\spra040c.dll
+ 2008-04-13 18:35:21 181,760 ——w c:\winnt\ServicePackFiles\i386\spra040d.dll
+ 2008-04-13 18:35:23 195,584 ——w c:\winnt\ServicePackFiles\i386\spra040e.dll
+ 2008-04-13 18:35:23 195,072 ——w c:\winnt\ServicePackFiles\i386\spra0410.dll
+ 2008-04-13 18:35:23 171,008 ——w c:\winnt\ServicePackFiles\i386\spra0411.dll
+ 2008-04-13 18:35:23 167,936 ——w c:\winnt\ServicePackFiles\i386\spra0412.dll
+ 2008-04-13 18:35:25 196,096 ——w c:\winnt\ServicePackFiles\i386\spra0413.dll
+ 2008-04-13 18:35:25 189,440 ——w c:\winnt\ServicePackFiles\i386\spra0414.dll
+ 2008-04-13 18:35:26 194,560 ——w c:\winnt\ServicePackFiles\i386\spra0415.dll
+ 2008-04-13 18:35:08 192,512 ——w c:\winnt\ServicePackFiles\i386\spra0416.dll
+ 2008-04-13 18:35:27 190,464 ——w c:\winnt\ServicePackFiles\i386\spra0418.dll
+ 2008-04-13 18:35:27 192,512 ——w c:\winnt\ServicePackFiles\i386\spra0419.dll
+ 2008-04-13 18:35:21 188,928 ——w c:\winnt\ServicePackFiles\i386\spra041a.dll
+ 2008-04-13 18:35:28 192,512 ——w c:\winnt\ServicePackFiles\i386\spra041b.dll
+ 2008-04-13 18:35:28 188,928 ——w c:\winnt\ServicePackFiles\i386\spra041d.dll
+ 2008-04-13 18:35:29 188,416 ——w c:\winnt\ServicePackFiles\i386\spra041e.dll
+ 2008-04-13 18:35:30 188,928 ——w c:\winnt\ServicePackFiles\i386\spra041f.dll
+ 2008-04-13 18:35:28 192,512 ——w c:\winnt\ServicePackFiles\i386\spra0424.dll
+ 2008-04-13 18:35:11 186,880 ——w c:\winnt\ServicePackFiles\i386\spra0425.dll
+ 2008-04-13 18:35:24 188,928 ——w c:\winnt\ServicePackFiles\i386\spra0426.dll
+ 2008-04-13 18:35:24 189,952 ——w c:\winnt\ServicePackFiles\i386\spra0427.dll
+ 2008-04-13 18:35:06 161,280 ——w c:\winnt\ServicePackFiles\i386\spra0804.dll
+ 2008-04-13 18:35:26 194,560 ——w c:\winnt\ServicePackFiles\i386\spra0816.dll
+ 2008-04-13 18:35:11 196,096 ——w c:\winnt\ServicePackFiles\i386\spra0c0a.dll
+ 2008-04-13 18:35:49 2,869,248 ——w c:\winnt\ServicePackFiles\i386\sprb0401.dll
+ 2008-04-13 18:36:10 477,696 ——w c:\winnt\ServicePackFiles\i386\sprb0404.dll
+ 2008-04-13 18:36:10 734,720 ——w c:\winnt\ServicePackFiles\i386\sprb0405.dll
+ 2008-04-13 18:36:10 742,912 ——w c:\winnt\ServicePackFiles\i386\sprb0406.dll
+ 2008-04-13 18:37:03 788,480 ——w c:\winnt\ServicePackFiles\i386\sprb0407.dll
+ 2008-04-13 18:36:35 801,280 ——w c:\winnt\ServicePackFiles\i386\sprb0408.dll
+ 2008-04-13 18:36:39 729,088 ——w c:\winnt\ServicePackFiles\i386\sprb040b.dll
+ 2008-04-13 18:36:55 793,088 ——w c:\winnt\ServicePackFiles\i386\sprb040c.dll
+ 2008-04-13 18:37:07 2,842,112 ——w c:\winnt\ServicePackFiles\i386\sprb040d.dll
+ 2008-04-13 18:37:22 769,536 ——w c:\winnt\ServicePackFiles\i386\sprb040e.dll
+ 2008-04-13 18:37:22 769,536 ——w c:\winnt\ServicePackFiles\i386\sprb0410.dll
+ 2008-04-13 18:37:34 562,688 ——w c:\winnt\ServicePackFiles\i386\sprb0411.dll
+ 2008-04-13 18:37:37 543,744 ——w c:\winnt\ServicePackFiles\i386\sprb0412.dll
+ 2008-04-13 18:38:00 769,024 ——w c:\winnt\ServicePackFiles\i386\sprb0413.dll
+ 2008-04-13 18:38:02 716,288 ——w c:\winnt\ServicePackFiles\i386\sprb0414.dll
+ 2008-04-13 18:38:05 759,808 ——w c:\winnt\ServicePackFiles\i386\sprb0415.dll
+ 2008-04-13 18:35:43 752,128 ——w c:\winnt\ServicePackFiles\i386\sprb0416.dll
+ 2008-04-13 18:38:28 736,768 ——w c:\winnt\ServicePackFiles\i386\sprb0419.dll
+ 2008-04-13 18:38:37 757,248 ——w c:\winnt\ServicePackFiles\i386\sprb041b.dll
+ 2008-04-13 18:38:47 724,480 ——w c:\winnt\ServicePackFiles\i386\sprb041d.dll
+ 2008-04-13 18:38:51 724,480 ——w c:\winnt\ServicePackFiles\i386\sprb041f.dll
+ 2008-04-13 18:38:36 732,160 ——w c:\winnt\ServicePackFiles\i386\sprb0424.dll
+ 2008-04-13 18:35:54 470,016 ——w c:\winnt\ServicePackFiles\i386\sprb0804.dll
+ 2008-04-13 18:38:06 751,616 ——w c:\winnt\ServicePackFiles\i386\sprb0816.dll
+ 2008-04-13 18:36:38 773,632 ——w c:\winnt\ServicePackFiles\i386\sprb0c0a.dll
+ 2008-04-13 18:39:02 656,896 ——w c:\winnt\ServicePackFiles\i386\sprc0401.dll
+ 2008-04-13 18:39:13 327,680 ——w c:\winnt\ServicePackFiles\i386\sprc0404.dll
+ 2008-04-13 18:39:02 601,088 ——w c:\winnt\ServicePackFiles\i386\sprc0405.dll
+ 2008-04-13 18:39:12 605,696 ——w c:\winnt\ServicePackFiles\i386\sprc0406.dll
+ 2008-04-13 18:39:19 663,552 ——w c:\winnt\ServicePackFiles\i386\sprc0407.dll
+ 2008-04-13 18:39:12 679,936 ——w c:\winnt\ServicePackFiles\i386\sprc0408.dll
+ 2008-04-13 18:39:17 604,672 ——w c:\winnt\ServicePackFiles\i386\sprc040b.dll
+ 2008-04-13 18:39:20 663,040 ——w c:\winnt\ServicePackFiles\i386\sprc040c.dll
+ 2008-04-13 18:39:28 620,544 ——w c:\winnt\ServicePackFiles\i386\sprc040d.dll
+ 2008-04-13 18:39:28 645,120 ——w c:\winnt\ServicePackFiles\i386\sprc040e.dll
+ 2008-04-13 18:39:28 658,432 ——w c:\winnt\ServicePackFiles\i386\sprc0410.dll
+ 2008-04-13 18:39:49 412,672 ——w c:\winnt\ServicePackFiles\i386\sprc0411.dll
+ 2008-04-13 18:39:49 392,704 ——w c:\winnt\ServicePackFiles\i386\sprc0412.dll
+ 2008-04-13 18:39:47 645,120 ——w c:\winnt\ServicePackFiles\i386\sprc0413.dll
+ 2008-04-13 18:39:48 591,872 ——w c:\winnt\ServicePackFiles\i386\sprc0414.dll
+ 2008-04-13 18:39:52 641,024 ——w c:\winnt\ServicePackFiles\i386\sprc0415.dll
+ 2008-04-13 18:38:56 620,032 ——w c:\winnt\ServicePackFiles\i386\sprc0416.dll
+ 2008-04-13 18:39:56 627,200 ——w c:\winnt\ServicePackFiles\i386\sprc0419.dll
+ 2008-04-13 18:40:04 577,536 ——w c:\winnt\ServicePackFiles\i386\sprc041b.dll
+ 2008-04-13 18:40:05 590,848 ——w c:\winnt\ServicePackFiles\i386\sprc041d.dll
+ 2008-04-13 18:40:09 592,896 ——w c:\winnt\ServicePackFiles\i386\sprc041f.dll
+ 2008-04-13 18:40:05 576,512 ——w c:\winnt\ServicePackFiles\i386\sprc0424.dll
+ 2008-04-13 18:39:03 322,560 ——w c:\winnt\ServicePackFiles\i386\sprc0804.dll
+ 2008-04-13 18:39:53 639,488 ——w c:\winnt\ServicePackFiles\i386\sprc0816.dll
+ 2008-04-13 18:39:13 648,704 ——w c:\winnt\ServicePackFiles\i386\sprc0c0a.dll
+ 2008-04-14 00:12:06 250,368 ——w c:\winnt\ServicePackFiles\i386\sptip.dll
+ 2008-04-14 00:12:36 20,992 ——w c:\winnt\ServicePackFiles\i386\spupdwxp.exe
+ 2008-04-14 00:12:06 151,552 ——w c:\winnt\ServicePackFiles\i386\sqldb20.dll
+ 2008-04-14 00:12:06 528,384 ——w c:\winnt\ServicePackFiles\i386\sqloledb.dll
+ 2008-04-14 00:12:06 462,848 ——w c:\winnt\ServicePackFiles\i386\sqlqp20.dll
+ 2008-04-14 00:12:06 110,592 ——w c:\winnt\ServicePackFiles\i386\sqlse20.dll
+ 2008-04-14 00:12:06 442,368 ——w c:\winnt\ServicePackFiles\i386\sqlsrv32.dll
+ 2008-04-14 00:12:06 180,800 ——w c:\winnt\ServicePackFiles\i386\sqlunirl.dll
+ 2008-04-14 00:12:06 217,088 ——w c:\winnt\ServicePackFiles\i386\sqlxmlx.dll
+ 2008-04-13 18:36:52 73,472 ——w c:\winnt\ServicePackFiles\i386\sr.sys
+ 2008-04-14 00:12:06 58,434 ——w c:\winnt\ServicePackFiles\i386\srchctls.dll
+ 2008-04-14 00:12:07 726,078 ——w c:\winnt\ServicePackFiles\i386\srchui.dll
+ 2008-04-14 00:12:07 67,584 ——w c:\winnt\ServicePackFiles\i386\srclient.dll
+ 2008-04-14 00:12:07 239,104 ——w c:\winnt\ServicePackFiles\i386\srrstr.dll
+ 2008-04-14 00:12:07 171,008 ——w c:\winnt\ServicePackFiles\i386\srsvc.dll
+ 2008-04-13 19:15:11 334,848 ——w c:\winnt\ServicePackFiles\i386\srv.sys
+ 2008-04-14 00:12:07 96,768 ——w c:\winnt\ServicePackFiles\i386\srvsvc.dll
+ 2008-04-14 00:12:43 704,512 ——w c:\winnt\ServicePackFiles\i386\ss3dfo.scr
+ 2008-04-14 00:12:43 19,968 ——w c:\winnt\ServicePackFiles\i386\ssbezier.scr
+ 2008-04-14 00:12:07 34,816 ——w c:\winnt\ServicePackFiles\i386\ssdpapi.dll
+ 2008-04-14 00:12:07 71,680 ——w c:\winnt\ServicePackFiles\i386\ssdpsrv.dll
+ 2008-04-14 00:12:43 393,216 ——w c:\winnt\ServicePackFiles\i386\ssflwbox.scr
+ 2008-04-14 00:12:07 45,056 ——w c:\winnt\ServicePackFiles\i386\ssinc51.dll
+ 2008-04-14 00:12:44 20,992 ——w c:\winnt\ServicePackFiles\i386\ssmarque.scr
+ 2008-04-14 00:12:44 47,104 ——w c:\winnt\ServicePackFiles\i386\ssmypics.scr
+ 2008-04-14 00:12:44 18,944 ——w c:\winnt\ServicePackFiles\i386\ssmyst.scr
+ 2008-04-14 00:12:07 46,592 ——w c:\winnt\ServicePackFiles\i386\sspifilt.dll
+ 2008-04-14 00:12:44 610,304 ——w c:\winnt\ServicePackFiles\i386\sspipes.scr
+ 2008-04-14 00:12:44 14,336 ——w c:\winnt\ServicePackFiles\i386\ssstars.scr
+ 2008-04-14 00:12:44 679,936 ——w c:\winnt\ServicePackFiles\i386\sstext3d.scr
+ 2008-04-14 00:12:07 33,280 ——w c:\winnt\ServicePackFiles\i386\sstub.dll
+ 2008-04-14 00:12:07 8,192 ——w c:\winnt\ServicePackFiles\i386\staxmem.dll
+ 2008-04-14 00:12:07 59,392 ——w c:\winnt\ServicePackFiles\i386\stclient.dll
+ 2008-04-14 00:12:07 86,528 ——w c:\winnt\ServicePackFiles\i386\stdprov.dll
+ 2008-04-14 00:12:07 68,096 ——w c:\winnt\ServicePackFiles\i386\sti.dll
+ 2008-04-14 00:12:07 136,704 ——w c:\winnt\ServicePackFiles\i386\sti_ci.dll
+ 2008-04-14 00:12:36 14,848 ——w c:\winnt\ServicePackFiles\i386\stimon.exe
+ 2008-04-14 00:12:07 121,856 ——w c:\winnt\ServicePackFiles\i386\stobject.dll
+ 2008-04-14 00:12:07 74,752 ——w c:\winnt\ServicePackFiles\i386\storprop.dll
+ 2008-04-13 18:45:15 49,408 ——w c:\winnt\ServicePackFiles\i386\stream.sys
+ 2008-04-13 18:46:21 15,232 ——w c:\winnt\ServicePackFiles\i386\streamip.sys
+ 2008-04-14 00:12:07 75,776 ——w c:\winnt\ServicePackFiles\i386\strmfilt.dll
+ 2008-04-14 00:12:36 16,449 ——w c:\winnt\ServicePackFiles\i386\stub_fpsrvadm.exe
+ 2008-04-14 00:12:36 65,601 ——w c:\winnt\ServicePackFiles\i386\stub_fpsrvwin.exe
+ 2008-04-14 00:12:07 46,592 ——w c:\winnt\ServicePackFiles\i386\svcext51.dll
+ 2008-04-14 00:12:36 14,336 ——w c:\winnt\ServicePackFiles\i386\svchost.exe
+ 2008-04-13 18:39:53 4,352 ——w c:\winnt\ServicePackFiles\i386\swenum.sys
+ 2008-04-13 18:45:09 56,576 ——w c:\winnt\ServicePackFiles\i386\swmidi.sys
+ 2008-04-14 00:12:07 713,216 ——w c:\winnt\ServicePackFiles\i386\sxs.dll
+ 2007-12-17 11:59:56 1,179,648 ——w c:\winnt\ServicePackFiles\i386\sy52106.dll
+ 2008-04-14 00:12:07 57,856 ——w c:\winnt\ServicePackFiles\i386\synceng.dll
+ 2008-04-14 00:12:07 191,488 ——w c:\winnt\ServicePackFiles\i386\syncui.dll
+ 2008-04-13 19:15:55 60,800 ——w c:\winnt\ServicePackFiles\i386\sysaudio.sys
+ 2008-04-14 00:12:36 71,680 ——w c:\winnt\ServicePackFiles\i386\sysinfo.exe
+ 2008-04-14 00:12:07 193,024 ——w c:\winnt\ServicePackFiles\i386\sysmod.dll
+ 2008-04-14 00:12:07 173,568 ——w c:\winnt\ServicePackFiles\i386\sysmoda.dll
+ 2008-04-14 00:12:37 106,496 ——w c:\winnt\ServicePackFiles\i386\sysocmgr.exe
+ 2008-04-14 00:12:07 990,208 ——w c:\winnt\ServicePackFiles\i386\syssetup.dll
+ 2007-09-26 19:59:50 77,824 ——w c:\winnt\ServicePackFiles\i386\system.configuration.install.dll
+ 2007-09-26 19:59:52 1,179,648 ——w c:\winnt\ServicePackFiles\i386\system.data.dll
+ 2007-09-26 19:59:48 1,695,744 ——w c:\winnt\ServicePackFiles\i386\system.design.dll
+ 2007-09-26 19:59:53 86,016 ——w c:\winnt\ServicePackFiles\i386\system.directoryservices.dll
+ 2007-09-26 19:59:54 65,536 ——w c:\winnt\ServicePackFiles\i386\system.drawing.design.dll
+ 2007-09-26 19:59:52 462,848 ——w c:\winnt\ServicePackFiles\i386\system.drawing.dll
+ 2007-09-26 19:59:49 212,992 ——w c:\winnt\ServicePackFiles\i386\system.enterpriseservices.dll
+ 2007-09-26 19:59:49 48,640 ——w c:\winnt\ServicePackFiles\i386\system.enterpriseservices.thunk.dll
+ 2007-09-26 19:59:51 352,256 ——w c:\winnt\ServicePackFiles\i386\system.management.dll
+ 2007-09-26 19:59:54 241,664 ——w c:\winnt\ServicePackFiles\i386\system.messaging.dll
+ 2007-09-26 19:59:51 311,296 ——w c:\winnt\ServicePackFiles\i386\system.runtime.remoting.dll
+ 2007-09-26 19:59:49 131,072 ——w c:\winnt\ServicePackFiles\i386\system.runtime.serialization.formatters.soap.dll
+ 2007-09-26 19:59:50 77,824 ——w c:\winnt\ServicePackFiles\i386\system.security.dll
+ 2007-09-26 19:59:52 126,976 ——w c:\winnt\ServicePackFiles\i386\system.serviceprocess.dll
+ 2007-09-26 20:34:40 1,200,128 ——w c:\winnt\ServicePackFiles\i386\system.web.dll
+ 2007-09-26 19:59:49 61,440 ——w c:\winnt\ServicePackFiles\i386\system.web.regularexpressions.dll
+ 2007-09-26 19:59:48 507,904 ——w c:\winnt\ServicePackFiles\i386\system.web.services.dll
+ 2007-09-26 19:59:50 2,002,944 ——w c:\winnt\ServicePackFiles\i386\system.windows.forms.dll
+ 2007-09-26 19:59:51 1,302,528 ——w c:\winnt\ServicePackFiles\i386\system.xml.dll
+ 2008-04-14 00:12:07 117,760 ——w c:\winnt\ServicePackFiles\i386\t2embed.dll
+ 2008-04-14 00:12:07 33,792 ——w c:\winnt\ServicePackFiles\i386\tabletoc.dll
+ 2008-04-13 18:40:50 14,976 ——w c:\winnt\ServicePackFiles\i386\tape.sys
+ 2008-04-14 00:12:07 858,624 ——w c:\winnt\ServicePackFiles\i386\tapi3.dll
+ 2008-04-14 00:12:07 181,760 ——w c:\winnt\ServicePackFiles\i386\tapi32.dll
+ 2008-04-14 00:12:07 249,856 ——w c:\winnt\ServicePackFiles\i386\tapisrv.dll
+ 2008-04-14 00:12:37 76,288 ——w c:\winnt\ServicePackFiles\i386\taskkill.exe
+ 2008-04-14 00:12:37 77,824 ——w c:\winnt\ServicePackFiles\i386\tasklist.exe
+ 2008-04-14 00:12:37 135,680 ——w c:\winnt\ServicePackFiles\i386\taskmgr.exe
+ 2008-04-13 19:20:16 361,344 ——w c:\winnt\ServicePackFiles\i386\tcpip.sys
+ 2008-04-13 19:00:02 225,664 ——w c:\winnt\ServicePackFiles\i386\tcpip6.sys
+ 2008-04-14 00:12:07 14,848 ——w c:\winnt\ServicePackFiles\i386\tcpmib.dll
+ 2008-04-14 00:12:07 45,568 ——w c:\winnt\ServicePackFiles\i386\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 ——w c:\winnt\ServicePackFiles\i386\tcpmonui.dll
+ 2008-04-14 00:12:37 32,827 ——w c:\winnt\ServicePackFiles\i386\tcptest.exe
+ 2007-04-02 16:36:07 16,384 ——w c:\winnt\ServicePackFiles\i386\tcptsat.dll
+ 2008-04-13 19:00:05 19,072 ——w c:\winnt\ServicePackFiles\i386\tdi.sys
+ 2008-04-14 00:13:20 12,040 ——w c:\winnt\ServicePackFiles\i386\tdpipe.sys
+ 2008-04-14 00:13:21 21,896 ——w c:\winnt\ServicePackFiles\i386\tdtcp.sys
+ 2008-04-14 00:12:37 75,776 ——w c:\winnt\ServicePackFiles\i386\telnet.exe
+ 2008-04-14 00:13:20 40,840 ——w c:\winnt\ServicePackFiles\i386\termdd.sys
+ 2008-04-14 00:12:07 358,400 ——w c:\winnt\ServicePackFiles\i386\termmgr.dll
+ 2008-04-14 00:12:07 295,424 ——w c:\winnt\ServicePackFiles\i386\termsrv.dll
+ 2008-04-13 18:40:50 149,376 ——w c:\winnt\ServicePackFiles\i386\tffsport.sys
+ 2008-04-14 00:12:07 385,536 ——w c:\winnt\ServicePackFiles\i386\themeui.dll
+ 2008-04-14 00:12:37 61,440 ——w c:\winnt\ServicePackFiles\i386\tlntadmn.exe
+ 2008-04-14 00:12:37 78,336 ——w c:\winnt\ServicePackFiles\i386\tlntsess.exe
+ 2008-04-14 00:12:38 73,216 ——w c:\winnt\ServicePackFiles\i386\tlntsvr.exe
+ 2008-04-14 00:12:07 7,168 ——w c:\winnt\ServicePackFiles\i386\tlntsvrp.dll
+ 2007-12-17 12:00:05 66,592 ——w c:\winnt\ServicePackFiles\i386\togac.exe
+ 2008-04-14 00:12:07 33,792 ——w c:\winnt\ServicePackFiles\i386\tools.dll
+ 2008-04-14 00:12:38 347,136 ——w c:\winnt\ServicePackFiles\i386\tourstrt.exe
+ 2008-04-14 00:12:38 82,944 ——w c:\winnt\ServicePackFiles\i386\tp4mon.exe
+ 2008-04-14 00:12:38 259,584 ——w c:\winnt\ServicePackFiles\i386\tracerpt.exe
+ 2008-04-14 00:12:38 12,288 ——w c:\winnt\ServicePackFiles\i386\tracert.exe
+ 2008-04-14 00:12:42 12,800 ——w c:\winnt\ServicePackFiles\i386\tree.com
+ 2008-04-14 00:12:07 153,088 ——w c:\winnt\ServicePackFiles\i386\triedit.dll
+ 2008-04-14 00:12:07 90,112 ——w c:\winnt\ServicePackFiles\i386\trkwks.dll
+ 2008-01-18 15:13:09 2,247 ——w c:\winnt\ServicePackFiles\i386\tscdsbl.bat
+ 2008-04-14 00:12:07 93,696 ——w c:\winnt\ServicePackFiles\i386\tscfgwmi.dll
+ 2007-12-12 10:33:51 18,917 ——w c:\winnt\ServicePackFiles\i386\tscinst.vbs
+ 2007-10-30 10:06:46 13,801 ——w c:\winnt\ServicePackFiles\i386\tscuinst.vbs
+ 2008-04-14 00:11:31 25,600 ——w c:\winnt\ServicePackFiles\i386\tscupdc.dll
+ 2008-04-14 00:13:21 12,168 ——w c:\winnt\ServicePackFiles\i386\tsddd.dll
+ 2008-04-14 00:12:07 53,248 ——w c:\winnt\ServicePackFiles\i386\tsgqec.dll
+ 2008-04-14 00:12:07 279,040 ——w c:\winnt\ServicePackFiles\i386\tshoot.dll
+ 2008-04-14 00:12:07 130,048 ——w c:\winnt\ServicePackFiles\i386\tsoc.dll
+ 2008-04-14 00:12:07 50,688 ——w c:\winnt\ServicePackFiles\i386\tspkg.dll
+ 2008-04-14 00:12:07 8,704 ——w c:\winnt\ServicePackFiles\i386\tty.dll
+ 2007-04-02 15:31:00 39,936 ——w c:\winnt\ServicePackFiles\i386\ttyres.dll
+ 2008-04-14 00:12:07 16,384 ——w c:\winnt\ServicePackFiles\i386\ttyui.dll
+ 2008-04-13 18:56:01 12,288 ——w c:\winnt\ServicePackFiles\i386\tunmp.sys
+ 2008-04-14 00:12:07 50,688 ——w c:\winnt\ServicePackFiles\i386\twain_32.dll
+ 2008-04-14 00:12:07 57,856 ——w c:\winnt\ServicePackFiles\i386\twext.dll
+ 2008-04-14 00:12:07 101,376 ——w c:\winnt\ServicePackFiles\i386\txflog.dll
+ 2008-04-14 00:12:38 60,416 ——w c:\winnt\ServicePackFiles\i386\tzchange.exe
+ 2008-04-13 18:36:40 44,672 ——w c:\winnt\ServicePackFiles\i386\uagp35.sys
+ 2008-04-13 18:32:36 66,048 ——w c:\winnt\ServicePackFiles\i386\udfs.sys
+ 2008-04-14 00:12:07 26,624 ——w c:\winnt\ServicePackFiles\i386\udhisapi.dll
+ 2008-04-14 00:12:07 103,424 ——w c:\winnt\ServicePackFiles\i386\uihelper.dll
+ 2008-04-14 00:12:07 275,456 ——w c:\winnt\ServicePackFiles\i386\ulib.dll
+ 2008-04-14 00:12:07 35,840 ——w c:\winnt\ServicePackFiles\i386\umandlg.dll
+ 2008-04-14 00:12:07 123,392 ——w c:\winnt\ServicePackFiles\i386\umpnpmgr.dll
+ 2008-04-14 00:12:07 373,248 ——w c:\winnt\ServicePackFiles\i386\unidrv.dll
+ 2008-04-14 00:12:07 744,448 ——w c:\winnt\ServicePackFiles\i386\unidrvui.dll
+ 2008-04-14 00:12:07 74,240 ——w c:\winnt\ServicePackFiles\i386\unimdmat.dll
+ 2008-04-14 00:12:07 13,824 ——w c:\winnt\ServicePackFiles\i386\uniplat.dll
+ 2007-05-15 08:08:53 761,344 ——w c:\winnt\ServicePackFiles\i386\unires.dll
+ 2008-04-14 00:12:07 316,416 ——w c:\winnt\ServicePackFiles\i386\untfs.dll
+ 2008-04-13 18:39:46 384,768 ——w c:\winnt\ServicePackFiles\i386\update.sys
+ 2008-04-14 00:12:38 150,528 ——w c:\winnt\ServicePackFiles\i386\uploadm.exe
+ 2008-04-14 00:12:08 133,632 ——w c:\winnt\ServicePackFiles\i386\upnp.dll
+ 2008-04-14 00:12:38 16,896 ——w c:\winnt\ServicePackFiles\i386\upnpcont.exe
+ 2008-04-14 00:12:08 185,856 ——w c:\winnt\ServicePackFiles\i386\upnphost.dll
+ 2008-04-14 00:12:08 239,616 ——w c:\winnt\ServicePackFiles\i386\upnpui.dll
+ 2008-04-14 00:12:38 18,432 ——w c:\winnt\ServicePackFiles\i386\ups.exe
+ 2008-04-14 00:12:08 37,888 ——w c:\winnt\ServicePackFiles\i386\url.dll
+ 2008-04-14 00:12:08 619,520 ——w c:\winnt\ServicePackFiles\i386\urlmon.dll
+ 2004-08-04 03:31:26 32,384 ——w c:\winnt\ServicePackFiles\i386\usb101et.sys
+ 2008-04-13 18:56:49 12,800 ——w c:\winnt\ServicePackFiles\i386\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ——w c:\winnt\ServicePackFiles\i386\usb8023x.sys
+ 2008-04-13 18:45:12 60,032 ——w c:\winnt\ServicePackFiles\i386\usbaudio.sys
+ 2008-04-13 18:45:40 25,600 ——w c:\winnt\ServicePackFiles\i386\usbcamd.sys
+ 2008-04-13 18:45:41 25,728 ——w c:\winnt\ServicePackFiles\i386\usbcamd2.sys
+ 2008-04-13 18:45:39 32,128 ——w c:\winnt\ServicePackFiles\i386\usbccgp.sys
+ 2008-04-13 18:45:35 30,208 ——w c:\winnt\ServicePackFiles\i386\usbehci.sys
+ 2008-04-13 18:45:37 59,520 ——w c:\winnt\ServicePackFiles\i386\usbhub.sys
+ 2008-04-13 18:45:43 15,872 ——w c:\winnt\ServicePackFiles\i386\usbintel.sys
+ 2008-04-14 00:12:08 16,896 ——w c:\winnt\ServicePackFiles\i386\usbmon.dll
+ 2008-04-13 18:45:35 17,152 ——w c:\winnt\ServicePackFiles\i386\usbohci.sys
+ 2008-04-13 18:45:36 143,872 ——w c:\winnt\ServicePackFiles\i386\usbport.sys
+ 2008-04-13 18:47:37 25,856 ——w c:\winnt\ServicePackFiles\i386\usbprint.sys
+ 2008-04-13 18:45:34 15,104 ——w c:\winnt\ServicePackFiles\i386\usbscan.sys
+ 2008-04-13 18:45:36 26,112 ——w c:\winnt\ServicePackFiles\i386\usbser.sys
+ 2008-04-13 18:45:38 26,368 ——w c:\winnt\ServicePackFiles\i386\usbstor.sys
+ 2008-04-13 18:45:35 20,608 ——w c:\winnt\ServicePackFiles\i386\usbuhci.sys
+ 2008-04-14 00:12:08 74,240 ——w c:\winnt\ServicePackFiles\i386\usbui.dll
+ 2008-04-13 18:46:20 121,984 ——w c:\winnt\ServicePackFiles\i386\usbvideo.sys
+ 2008-04-14 00:12:08 578,560 ——w c:\winnt\ServicePackFiles\i386\user32.dll
+ 2008-04-14 00:12:08 727,040 ——w c:\winnt\ServicePackFiles\i386\userenv.dll
+ 2008-04-14 00:12:38 26,112 ——w c:\winnt\ServicePackFiles\i386\userinit.exe
+ 2008-04-14 00:12:08 406,016 ——w c:\winnt\ServicePackFiles\i386\usp10.dll
+ 2008-04-14 00:12:38 50,176 ——w c:\winnt\ServicePackFiles\i386\utilman.exe
+ 2008-04-14 00:12:08 218,624 ——w c:\winnt\ServicePackFiles\i386\uxtheme.dll
+ 2008-04-14 00:12:08 30,749 ——w c:\winnt\ServicePackFiles\i386\vbajet32.dll
+ 2007-06-27 12:59:58 716,800 ——w c:\winnt\ServicePackFiles\i386\vbc.exe
+ 2008-04-13 16:11:44 126,976 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.chs.dll
+ 2008-04-13 16:11:45 126,976 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.cht.dll
+ 2008-04-13 16:11:45 126,976 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.dll
+ 2008-04-13 16:11:45 147,456 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.es.dll
+ 2008-04-13 16:11:45 151,552 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.fr.dll
+ 2008-04-13 16:11:45 151,552 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.ger.dll
+ 2008-04-13 16:11:45 147,456 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.it.dll
+ 2008-04-13 16:11:45 126,976 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.ja.dll
+ 2008-04-13 16:11:45 126,976 ——w c:\winnt\ServicePackFiles\i386\vbc7ui.kor.dll
+ 2008-04-14 00:12:08 434,176 ——w c:\winnt\ServicePackFiles\i386\vbscript.dll
+ 2008-04-14 00:12:08 11,325 ——w c:\winnt\ServicePackFiles\i386\vchnt5.dll
+ 2008-04-14 00:12:08 26,112 ——w c:\winnt\ServicePackFiles\i386\vdmdbg.dll
+ 2008-04-14 00:12:08 51,712 ——w c:\winnt\ServicePackFiles\i386\vdmredir.dll
+ 2008-04-14 00:12:38 28,672 ——w c:\winnt\ServicePackFiles\i386\verclsid.exe
+ 2008-04-14 00:12:08 26,624 ——w c:\winnt\ServicePackFiles\i386\verifier.dll
+ 2008-04-14 00:12:08 18,944 ——w c:\winnt\ServicePackFiles\i386\version.dll
+ 2008-04-14 00:12:08 53,760 ——w c:\winnt\ServicePackFiles\i386\vfwwdm32.dll
+ 2008-04-13 18:44:40 20,992 ——w c:\winnt\ServicePackFiles\i386\vga.sys
+ 2008-04-14 00:12:08 851,968 ——w c:\winnt\ServicePackFiles\i386\vgx.dll
+ 2008-04-13 18:36:40 42,240 ——w c:\winnt\ServicePackFiles\i386\viaagp.sys
+ 2008-04-13 18:40:31 5,376 ——w c:\winnt\ServicePackFiles\i386\viaide.sys
+ 2008-04-13 18:44:40 81,664 ——w c:\winnt\ServicePackFiles\i386\videoprt.sys
+ 2008-04-14 00:12:08 131,584 ——w c:\winnt\ServicePackFiles\i386\viewprov.dll
+ 2008-04-13 18:41:01 52,352 ——w c:\winnt\ServicePackFiles\i386\volsnap.sys
+ 2008-04-13 16:11:47 999,424 ——w c:\winnt\ServicePackFiles\i386\vsavb7rt.dll
+ 2008-04-14 00:12:08 430,592 ——w c:\winnt\ServicePackFiles\i386\vssapi.dll
+ 2008-04-14 00:12:38 289,792 ——w c:\winnt\ServicePackFiles\i386\vssvc.exe
+ 2008-04-14 00:12:08 175,104 ——w c:\winnt\ServicePackFiles\i386\w32time.dll
+ 2008-04-14 00:12:08 15,872 ——w c:\winnt\ServicePackFiles\i386\w3ssl.dll
+ 2008-04-14 00:12:08 364,032 ——w c:\winnt\ServicePackFiles\i386\w3svc.dll
+ 2008-04-14 00:12:08 483,840 ——w c:\winnt\ServicePackFiles\i386\w95upgnt.dll
+ 2008-04-14 00:12:38 46,080 ——w c:\winnt\ServicePackFiles\i386\wab.exe
+ 2008-04-14 00:12:08 510,976 ——w c:\winnt\ServicePackFiles\i386\wab32.dll
+ 2008-04-13 16:21:48 249,856 ——w c:\winnt\ServicePackFiles\i386\wab32res.dll
+ 2008-04-14 00:12:08 32,768 ——w c:\winnt\ServicePackFiles\i386\wabfind.dll
+ 2008-04-14 00:12:08 85,504 ——w c:\winnt\ServicePackFiles\i386\wabimp.dll
+ 2008-04-14 00:12:39 30,208 ——w c:\winnt\ServicePackFiles\i386\wabmig.exe
+ 2008-04-13 18:43:55 14,208 ——w c:\winnt\ServicePackFiles\i386\wacompen.sys
+ 2004-08-04 03:29:38 12,415 ——w c:\winnt\ServicePackFiles\i386\wadv01nt.sys
+ 2004-08-04 03:29:38 12,127 ——w c:\winnt\ServicePackFiles\i386\wadv02nt.sys
+ 2004-08-04 03:29:38 11,775 ——w c:\winnt\ServicePackFiles\i386\wadv05nt.sys
+ 2004-08-04 03:29:40 11,807 ——w c:\winnt\ServicePackFiles\i386\wadv07nt.sys
+ 2004-08-04 03:29:40 11,295 ——w c:\winnt\ServicePackFiles\i386\wadv08nt.sys
+ 2004-08-04 03:29:42 11,871 ——w c:\winnt\ServicePackFiles\i386\wadv09nt.sys
+ 2004-08-04 03:29:42 11,935 ——w c:\winnt\ServicePackFiles\i386\wadv11nt.sys
+ 2008-04-14 00:12:08 76,800 ——w c:\winnt\ServicePackFiles\i386\wam51.dll
+ 2008-04-14 00:12:08 53,248 ——w c:\winnt\ServicePackFiles\i386\wamreg51.dll
+ 2008-04-13 18:57:21 34,560 ——w c:\winnt\ServicePackFiles\i386\wanarp.sys
+ 2008-04-13 18:44:59 17,664 ——w c:\winnt\ServicePackFiles\i386\watchdog.sys
+ 2004-08-04 03:29:42 29,311 ——w c:\winnt\ServicePackFiles\i386\watv01nt.sys
+ 2004-08-04 03:29:44 19,551 ——w c:\winnt\ServicePackFiles\i386\watv02nt.sys
+ 2004-08-04 03:29:44 33,599 ——w c:\winnt\ServicePackFiles\i386\watv04nt.sys
+ 2004-08-04 03:29:46 22,271 ——w c:\winnt\ServicePackFiles\i386\watv06nt.sys
+ 2004-08-04 03:29:46 25,471 ——w c:\winnt\ServicePackFiles\i386\watv10nt.sys
+ 2008-04-14 00:12:08 215,552 ——w c:\winnt\ServicePackFiles\i386\wavemsp.dll
+ 2008-04-14 00:12:08 196,608 ——w c:\winnt\ServicePackFiles\i386\wbemcntl.dll
+ 2008-04-14 00:12:08 214,528 ——w c:\winnt\ServicePackFiles\i386\wbemcomn.dll
+ 2008-04-14 00:12:08 71,680 ——w c:\winnt\ServicePackFiles\i386\wbemcons.dll
+ 2008-04-14 00:12:08 531,456 ——w c:\winnt\ServicePackFiles\i386\wbemcore.dll
+ 2008-04-14 00:12:08 178,176 ——w c:\winnt\ServicePackFiles\i386\wbemdisp.dll
+ 2008-04-14 00:12:08 273,920 ——w c:\winnt\ServicePackFiles\i386\wbemess.dll
+ 2008-04-14 00:12:08 43,008 ——w c:\winnt\ServicePackFiles\i386\wbemperf.dll
+ 2008-04-14 00:12:08 18,944 ——w c:\winnt\ServicePackFiles\i386\wbemprox.dll
+ 2008-04-14 00:12:08 43,520 ——w c:\winnt\ServicePackFiles\i386\wbemsvc.dll
+ 2008-04-14 00:12:39 116,224 ——w c:\winnt\ServicePackFiles\i386\wbemtest.exe
+ 2008-04-14 00:12:08 197,120 ——w c:\winnt\ServicePackFiles\i386\wbemupgd.dll
+ 2008-04-13 18:45:38 31,744 ——w c:\winnt\ServicePackFiles\i386\wceusbsh.sys
+ 2004-08-04 03:29:46 23,615 ——w c:\winnt\ServicePackFiles\i386\wch7xxnt.sys
+ 2008-04-14 00:12:08 49,152 ——w c:\winnt\ServicePackFiles\i386\wdigest.dll
+ 2008-04-14 00:12:45 23,552 ——w c:\winnt\ServicePackFiles\i386\wdmaud.drv
+ 2008-04-13 19:17:18 83,072 ——w c:\winnt\ServicePackFiles\i386\wdmaud.sys
+ 2008-04-14 00:12:08 276,480 ——w c:\winnt\ServicePackFiles\i386\webcheck.dll
+ 2008-04-14 00:12:08 68,096 ——w c:\winnt\ServicePackFiles\i386\webclnt.dll
+ 2008-04-14 00:12:08 135,680 ——w c:\winnt\ServicePackFiles\i386\webvw.dll
+ 2008-04-14 00:12:39 65,024 ——w c:\winnt\ServicePackFiles\i386\wextract.exe
+ 2008-04-14 00:12:39 433,664 ——w c:\winnt\ServicePackFiles\i386\wiaacmgr.exe
+ 2008-04-14 00:12:08 463,360 ——w c:\winnt\ServicePackFiles\i386\wiadefui.dll
+ 2008-04-14 00:12:08 124,416 ——w c:\winnt\ServicePackFiles\i386\wiadss.dll
+ 2008-04-14 00:12:08 75,776 ——w c:\winnt\ServicePackFiles\i386\wiascr.dll
+ 2008-04-14 00:12:08 333,824 ——w c:\winnt\ServicePackFiles\i386\wiaservc.dll
+ 2008-04-14 00:12:08 589,312 ——w c:\winnt\ServicePackFiles\i386\wiashext.dll
+ 2008-04-14 00:12:08 111,104 ——w c:\winnt\ServicePackFiles\i386\wiavideo.dll
+ 2008-04-14 00:12:08 712,704 ——w c:\winnt\ServicePackFiles\i386\wic.dll
+ 2008-04-14 00:12:08 346,112 ——w c:\winnt\ServicePackFiles\i386\wicext.dll
+ 2008-04-13 19:30:10 1,845,632 ——w c:\winnt\ServicePackFiles\i386\win32k.sys
+ 2008-04-14 00:12:08 102,400 ——w c:\winnt\ServicePackFiles\i386\win32spl.dll
+ 2008-04-13 16:48:53 1,647,616 ——w c:\winnt\ServicePackFiles\i386\winbrand.dll
+ 2008-04-14 00:12:39 283,648 ——w c:\winnt\ServicePackFiles\i386\winhlp32.exe
+ 2008-04-14 00:12:08 354,304 ——w c:\winnt\ServicePackFiles\i386\winhttp.dll
+ 2008-04-14 00:12:08 666,112 ——w c:\winnt\ServicePackFiles\i386\wininet.dll
+ 2008-04-14 00:12:09 32,256 ——w c:\winnt\ServicePackFiles\i386\winipsec.dll
+ 2008-04-14 00:12:39 507,904 ——w c:\winnt\ServicePackFiles\i386\winlogon.exe
+ 2008-04-14 00:12:09 176,128 ——w c:\winnt\ServicePackFiles\i386\winmm.dll
+ 2004-08-03 20:51:20 5,120 ——w c:\winnt\ServicePackFiles\i386\winnls.dll
+ 2008-04-14 00:11:11 756,224 ——w c:\winnt\ServicePackFiles\i386\winntbbu.dll
+ 2008-04-14 00:12:09 16,896 ——w c:\winnt\ServicePackFiles\i386\winrnr.dll
+ 2008-04-14 00:12:09 99,328 ——w c:\winnt\ServicePackFiles\i386\winscard.dll
+ 2008-04-14 00:12:09 17,408 ——w c:\winnt\ServicePackFiles\i386\winshfhc.dll
+ 2008-04-14 00:12:45 146,432 ——w c:\winnt\ServicePackFiles\i386\winspool.drv
+ 2008-04-14 00:12:09 293,376 ——w c:\winnt\ServicePackFiles\i386\winsrv.dll
+ 2008-04-14 00:12:09 53,760 ——w c:\winnt\ServicePackFiles\i386\winsta.dll
+ 2008-04-14 00:12:09 176,640 ——w c:\winnt\ServicePackFiles\i386\wintrust.dll
+ 2008-04-14 00:12:40 5,632 ——w c:\winnt\ServicePackFiles\i386\winver.exe
+ 2008-04-14 00:12:09 132,096 ——w c:\winnt\ServicePackFiles\i386\wkssvc.dll
+ 2008-04-14 00:12:09 69,120 ——w c:\winnt\ServicePackFiles\i386\wlanapi.dll
+ 2008-04-14 00:12:09 172,032 ——w c:\winnt\ServicePackFiles\i386\wldap32.dll
+ 2004-08-04 03:31:28 154,624 ——w c:\winnt\ServicePackFiles\i386\wlluc48.sys
+ 2008-04-14 00:12:09 92,672 ——w c:\winnt\ServicePackFiles\i386\wlnotify.dll
+ 2008-04-14 00:11:15 5,632 ——w c:\winnt\ServicePackFiles\i386\wmi.dll
+ 2008-04-13 18:36:38 8,832 ——w c:\winnt\ServicePackFiles\i386\wmiacpi.sys
+ 2008-04-14 00:12:40 196,608 ——w c:\winnt\ServicePackFiles\i386\wmiadap.exe
+ 2008-04-13 17:10:20 6,656 ——w c:\winnt\ServicePackFiles\i386\wmiapres.dll
+ 2008-04-14 00:12:09 88,576 ——w c:\winnt\ServicePackFiles\i386\wmiaprpl.dll
+ 2008-04-14 00:12:40 126,464 ——w c:\winnt\ServicePackFiles\i386\wmiapsrv.exe
+ 2008-04-14 00:12:40 358,912 ——w c:\winnt\ServicePackFiles\i386\wmic.exe
+ 2008-04-14 00:12:09 60,928 ——w c:\winnt\ServicePackFiles\i386\wmicookr.dll
+ 2008-04-14 00:12:09 140,800 ——w c:\winnt\ServicePackFiles\i386\wmidcprv.dll
+ 2008-04-14 00:12:09 156,672 ——w c:\winnt\ServicePackFiles\i386\wmipcima.dll
+ 2008-04-14 00:12:09 132,096 ——w c:\winnt\ServicePackFiles\i386\wmipdskq.dll
+ 2008-04-14 00:12:09 61,952 ——w c:\winnt\ServicePackFiles\i386\wmipiprt.dll
+ 2008-04-14 00:12:09 62,464 ——w c:\winnt\ServicePackFiles\i386\wmipjobj.dll
+ 2008-04-14 00:12:09 144,896 ——w c:\winnt\ServicePackFiles\i386\wmiprov.dll
+ 2008-04-14 00:12:09 437,248 ——w c:\winnt\ServicePackFiles\i386\wmiprvsd.dll
+ 2008-04-14 00:12:40 218,112 ——w c:\winnt\ServicePackFiles\i386\wmiprvse.exe
+ 2008-04-14 00:12:09 41,472 ——w c:\winnt\ServicePackFiles\i386\wmipsess.dll
+ 2008-04-14 00:12:09 144,896 ——w c:\winnt\ServicePackFiles\i386\wmisvc.dll
+ 2008-04-14 00:12:09 95,232 ——w c:\winnt\ServicePackFiles\i386\wmiutils.dll
+ 2008-04-14 00:12:09 167,936 ——w c:\winnt\ServicePackFiles\i386\wmm2ae.dll
+ 2008-04-14 00:12:09 4,096 ——w c:\winnt\ServicePackFiles\i386\wmm2eres.dll
+ 2008-04-14 00:12:09 7,680 ——w c:\winnt\ServicePackFiles\i386\wmm2ext.dll
+ 2008-04-14 00:12:09 402,432 ——w c:\winnt\ServicePackFiles\i386\wmm2filt.dll
+ 2008-04-14 00:12:09 502,272 ——w c:\winnt\ServicePackFiles\i386\wmm2fxa.dll
+ 2008-04-14 00:12:09 325,632 ——w c:\winnt\ServicePackFiles\i386\wmm2fxb.dll
+ 2008-04-14 00:12:09 4,256,768 ——w c:\winnt\ServicePackFiles\i386\wmm2res.dll
+ 2008-04-14 00:12:09 5,632 ——w c:\winnt\ServicePackFiles\i386\wmm2res2.dll
+ 2008-04-14 00:12:09 276,992 ——w c:\winnt\ServicePackFiles\i386\wmphoto.dll
+ 2008-04-14 00:12:40 214,528 ——w c:\winnt\ServicePackFiles\i386\wordpad.exe
+ 2008-04-14 00:12:10 264,192 ——w c:\winnt\ServicePackFiles\i386\wow32.dll
+ 2008-04-14 00:12:40 32,256 ——w c:\winnt\ServicePackFiles\i386\wpabaln.exe
+ 2008-04-14 00:12:41 11,264 ——w c:\winnt\ServicePackFiles\i386\wpnpinst.exe
+ 2008-04-14 00:12:10 82,432 ——w c:\winnt\ServicePackFiles\i386\ws2_32.dll
+ 2008-04-14 00:12:10 19,968 ——w c:\winnt\ServicePackFiles\i386\ws2help.dll
+ 2008-04-14 00:12:41 13,824 ——w c:\winnt\ServicePackFiles\i386\wscntfy.exe
+ 2008-04-14 00:12:41 155,648 ——w c:\winnt\ServicePackFiles\i386\wscript.exe
+ 2008-04-14 00:12:10 80,896 ——w c:\winnt\ServicePackFiles\i386\wscsvc.dll
+ 2008-04-14 00:12:10 604,160 ——w c:\winnt\ServicePackFiles\i386\wsecedit.dll
+ 2008-04-14 00:12:10 108,032 ——w c:\winnt\ServicePackFiles\i386\wshbth.dll
+ 2008-04-14 00:12:10 36,864 ——w c:\winnt\ServicePackFiles\i386\wshcon.dll
+ 2008-04-14 00:12:10 90,112 ——w c:\winnt\ServicePackFiles\i386\wshext.dll
+ 2008-04-14 00:12:10 14,336 ——w c:\winnt\ServicePackFiles\i386\wship6.dll
+ 2008-04-14 00:12:10 8,192 ——w c:\winnt\ServicePackFiles\i386\wshirda.dll
+ 2008-04-14 00:12:10 11,264 ——w c:\winnt\ServicePackFiles\i386\wshrm.dll
+ 2008-04-14 00:12:10 19,456 ——w c:\winnt\ServicePackFiles\i386\wshtcpip.dll
+ 2004-08-04 03:29:48 12,063 ——w c:\winnt\ServicePackFiles\i386\wsiintxx.sys
+ 2008-04-14 00:12:10 41,984 ——w c:\winnt\ServicePackFiles\i386\wsnmp32.dll
+ 2008-04-14 00:12:10 22,528 ——w c:\winnt\ServicePackFiles\i386\wsock32.dll
+ 2008-04-13 18:46:24 19,200 ——w c:\winnt\ServicePackFiles\i386\wstcodec.sys
+ 2008-04-14 00:12:10 50,688 ——w c:\winnt\ServicePackFiles\i386\wstdecod.dll
+ 2008-04-14 00:12:10 18,432 ——w c:\winnt\ServicePackFiles\i386\wtsapi32.dll
+ 2008-04-14 00:12:10 430,592 ——w c:\winnt\ServicePackFiles\i386\wuapi.dll
+ 2008-04-14 00:12:41 111,104 ——w c:\winnt\ServicePackFiles\i386\wuauclt.exe
+ 2008-04-14 00:12:41 165,888 ——w c:\winnt\ServicePackFiles\i386\wuauclt1.exe
+ 2008-04-14 00:12:11 1,135,616 ——w c:\winnt\ServicePackFiles\i386\wuaueng.dll
+ 2008-04-14 00:12:11 183,296 ——w c:\winnt\ServicePackFiles\i386\wuaueng1.dll
+ 2008-04-14 00:12:11 6,656 ——w c:\winnt\ServicePackFiles\i386\wuauserv.dll
+ 2008-04-14 00:12:11 112,640 ——w c:\winnt\ServicePackFiles\i386\wucltui.dll
+ 2008-04-14 00:12:11 32,256 ——w c:\winnt\ServicePackFiles\i386\wups.dll
+ 2008-04-14 00:12:11 120,320 ——w c:\winnt\ServicePackFiles\i386\wuweb.dll
+ 2004-08-04 03:29:50 19,455 ——w c:\winnt\ServicePackFiles\i386\wvchntxx.sys
+ 2008-04-14 00:12:11 383,488 ——w c:\winnt\ServicePackFiles\i386\wzcdlg.dll
+ 2008-04-14 00:12:11 52,736 ——w c:\winnt\ServicePackFiles\i386\wzcsapi.dll
+ 2008-04-14 00:12:11 483,840 ——w c:\winnt\ServicePackFiles\i386\wzcsvc.dll
+ 2008-04-14 00:12:11 91,648 ——w c:\winnt\ServicePackFiles\i386\xactsrv.dll
+ 2008-04-14 00:12:41 30,720 ——w c:\winnt\ServicePackFiles\i386\xcopy.exe
+ 2004-07-17 09:39:16 174,200 ——w c:\winnt\ServicePackFiles\i386\xenroll.dll
+ 2008-04-14 00:12:11 121,856 ——w c:\winnt\ServicePackFiles\i386\xmllite.dll
+ 2008-04-14 00:12:11 129,024 ——w c:\winnt\ServicePackFiles\i386\xmlprov.dll
+ 2008-04-14 00:12:11 50,176 ——w c:\winnt\ServicePackFiles\i386\xmlprovi.dll
+ 2008-04-14 00:12:11 11,776 ——w c:\winnt\ServicePackFiles\i386\xolehlp.dll
+ 2008-04-13 18:53:32 558,080 ——w c:\winnt\ServicePackFiles\i386\xpnetdg.exe
+ 2008-04-13 17:39:29 438,784 ——w c:\winnt\ServicePackFiles\i386\xpob2res.dll
+ 2008-04-13 17:39:22 187,392 ——w c:\winnt\ServicePackFiles\i386\xpsp1res.dll
+ 2008-04-13 17:39:24 2,897,920 ——w c:\winnt\ServicePackFiles\i386\xpsp2res.dll
+ 2008-04-13 17:39:26 689,152 ——w c:\winnt\ServicePackFiles\i386\xpsp3res.dll
+ 2008-04-14 00:12:11 18,944 ——w c:\winnt\ServicePackFiles\i386\xrxscnui.dll
+ 2008-04-14 00:12:11 116,224 ——w c:\winnt\ServicePackFiles\i386\xrxwiadr.dll
+ 2008-04-14 00:12:11 338,432 ——w c:\winnt\ServicePackFiles\i386\zipfldr.dll
+ 2008-04-14 00:11:51 33,792 ——w c:\winnt\ServicePackFiles\ServicePackCache\i386\custsat.dll
+ 2008-04-14 00:11:59 82,944 ——w c:\winnt\ServicePackFiles\ServicePackCache\i386\msgsc.dll
+ 2008-04-13 17:30:28 180,224 ——w c:\winnt\ServicePackFiles\ServicePackCache\i386\msgslang.dll
+ 2008-04-14 00:12:28 1,695,232 ——w c:\winnt\ServicePackFiles\ServicePackCache\i386\msmsgs.exe
+ 2008-04-14 00:12:35 32,866 ——w c:\winnt\slrundll.exe
+ 2009-03-06 23:37:41 4,326 —-a-w c:\winnt\SoftwareDistribution\EventCache\{40BEECEB-1866-4BD1-9F06-37467D0270FD}.bin
- 2004-08-03 22:56:44 3,166,208 —-a-w c:\winnt\srchasst\msgr3en.dll
+ 2008-04-14 00:11:59 3,166,208 —-a-w c:\winnt\srchasst\msgr3en.dll
- 2004-08-03 22:56:46 58,434 —-a-w c:\winnt\srchasst\srchctls.dll
+ 2008-04-14 00:12:06 58,434 —-a-w c:\winnt\srchasst\srchctls.dll
- 2004-08-03 22:56:46 725,566 —-a-w c:\winnt\srchasst\srchui.dll
+ 2008-04-14 00:12:07 726,078 —-a-w c:\winnt\srchasst\srchui.dll
- 2004-08-03 22:56:58 146,432 —-a-w c:\winnt\system\WINSPOOL.DRV
+ 2008-04-14 00:12:45 146,432 —-a-w c:\winnt\system\winspool.drv
- 2006-08-16 11:58:05 100,352 —-a-w c:\winnt\system32\6to4svc.dll
+ 2008-04-14 00:11:48 100,352 —-a-w c:\winnt\system32\6to4svc.dll
- 2004-08-03 22:56:48 183,808 —-a-w c:\winnt\system32\accwiz.exe
+ 2008-04-14 00:12:11 184,320 —-a-w c:\winnt\system32\accwiz.exe
- 2004-08-03 22:56:42 114,688 —-a-w c:\winnt\system32\aclui.dll
+ 2008-04-14 00:11:48 115,712 —-a-w c:\winnt\system32\aclui.dll
- 2004-08-03 22:56:42 194,048 —-a-w c:\winnt\system32\activeds.dll
+ 2008-04-14 00:11:48 193,536 —-a-w c:\winnt\system32\activeds.dll
- 2004-08-03 22:56:48 4,096 —-a-w c:\winnt\system32\actmovie.exe
+ 2008-04-14 00:12:12 4,096 —-a-w c:\winnt\system32\actmovie.exe
- 2004-08-03 22:56:42 101,888 —-a-w c:\winnt\system32\actxprxy.dll
+ 2008-04-14 00:11:48 98,304 —-a-w c:\winnt\system32\actxprxy.dll
- 2004-08-03 22:56:42 175,616 —-a-w c:\winnt\system32\adsldp.dll
+ 2008-04-14 00:11:48 175,616 —-a-w c:\winnt\system32\adsldp.dll
- 2004-08-03 22:56:42 143,360 —-a-w c:\winnt\system32\adsldpc.dll
+ 2008-04-14 00:11:48 143,360 —-a-w c:\winnt\system32\adsldpc.dll
- 2004-08-03 22:56:42 68,096 —-a-w c:\winnt\system32\adsmsext.dll
+ 2008-04-14 00:11:48 68,096 —-a-w c:\winnt\system32\adsmsext.dll
- 2004-08-03 22:56:42 263,680 —-a-w c:\winnt\system32\adsnt.dll
+ 2008-04-14 00:11:48 263,680 —-a-w c:\winnt\system32\adsnt.dll
- 2001-08-23 12:00:00 109,568 —-a-w c:\winnt\system32\adsnw.dll
+ 2008-04-14 00:11:48 123,392 —-a-w c:\winnt\system32\adsnw.dll
- 2004-08-03 22:56:42 616,960 —-a-w c:\winnt\system32\advapi32.dll
+ 2008-04-14 00:11:48 617,472 —-a-w c:\winnt\system32\advapi32.dll
- 2008-10-16 20:38:34 124,928 —-a-w c:\winnt\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w c:\winnt\system32\advpack.dll
- 2004-08-03 22:56:48 98,304 —-a-w c:\winnt\system32\ahui.exe
+ 2008-04-14 00:12:12 98,304 —-a-w c:\winnt\system32\ahui.exe
- 2004-08-03 22:56:48 44,544 —-a-w c:\winnt\system32\alg.exe
+ 2008-04-14 00:12:12 44,544 —-a-w c:\winnt\system32\alg.exe
- 2004-08-03 22:56:42 17,408 —-a-w c:\winnt\system32\alrsvc.dll
+ 2008-04-14 00:11:49 17,408 —-a-w c:\winnt\system32\alrsvc.dll
- 2004-08-03 22:56:42 70,656 —-a-w c:\winnt\system32\amstream.dll
+ 2008-04-14 00:11:49 70,656 —-a-w c:\winnt\system32\amstream.dll
- 2004-08-03 22:56:42 126,976 —-a-w c:\winnt\system32\apphelp.dll
+ 2008-04-14 00:11:49 125,952 —-a-w c:\winnt\system32\apphelp.dll
- 2004-08-03 22:56:42 167,936 —-a-w c:\winnt\system32\appmgmts.dll
+ 2008-04-14 00:11:49 167,936 —-a-w c:\winnt\system32\appmgmts.dll
- 2004-08-03 22:56:42 295,936 —-a-w c:\winnt\system32\appmgr.dll
+ 2008-04-14 00:11:49 295,936 —-a-w c:\winnt\system32\appmgr.dll
- 2004-08-03 22:56:48 30,208 —-a-w c:\winnt\system32\asr_fmt.exe
+ 2008-04-14 00:12:12 30,208 —-a-w c:\winnt\system32\asr_fmt.exe
- 2004-08-03 22:56:48 32,768 —-a-w c:\winnt\system32\asr_pfu.exe
+ 2008-04-14 00:12:12 32,768 —-a-w c:\winnt\system32\asr_pfu.exe
- 2004-08-03 22:56:42 65,024 —-a-w c:\winnt\system32\asycfilt.dll
+ 2008-04-14 00:11:49 65,024 —-a-w c:\winnt\system32\asycfilt.dll
- 2004-08-03 22:56:48 25,088 —-a-w c:\winnt\system32\at.exe
+ 2008-04-14 00:12:12 25,088 —-a-w c:\winnt\system32\at.exe
+ 2008-04-14 00:11:49 229,376 ——w c:\winnt\system32\ati2cqag.dll
+ 2008-04-14 00:11:49 377,984 ——w c:\winnt\system32\ati2dvaa.dll
+ 2008-04-14 00:11:49 201,728 ——w c:\winnt\system32\ati2dvag.dll
+ 2008-04-14 00:11:49 870,784 ——w c:\winnt\system32\ati3d1ag.dll
+ 2008-04-14 00:11:50 1,888,992 ——w c:\winnt\system32\ati3duag.dll
+ 2008-04-14 00:11:50 32,768 ——w c:\winnt\system32\ativtmxx.dll
+ 2008-04-14 00:11:50 516,768 ——w c:\winnt\system32\ativvaxx.dll
- 2004-08-03 22:56:42 58,880 —-a-w c:\winnt\system32\atl.dll
+ 2008-04-14 00:11:50 58,880 —-a-w c:\winnt\system32\atl.dll
- 2004-08-03 22:56:48 11,264 —-a-w c:\winnt\system32\atmadm.exe
+ 2008-04-14 00:12:12 11,264 —-a-w c:\winnt\system32\atmadm.exe
- 2004-08-03 22:56:00 285,696 —-a-w c:\winnt\system32\atmfd.dll
+ 2008-04-14 00:09:01 285,696 —-a-w c:\winnt\system32\atmfd.dll
- 2004-08-03 22:56:42 30,208 —-a-w c:\winnt\system32\atmlib.dll
+ 2008-04-14 00:11:50 30,208 —-a-w c:\winnt\system32\atmlib.dll
- 2001-08-23 12:00:00 11,264 —-a-w c:\winnt\system32\attrib.exe
+ 2008-04-14 00:12:12 12,288 —-a-w c:\winnt\system32\attrib.exe
- 2004-08-03 22:56:42 42,496 —-a-w c:\winnt\system32\audiosrv.dll
+ 2008-04-14 00:11:50 42,496 —-a-w c:\winnt\system32\audiosrv.dll
- 2004-08-03 22:56:48 14,336 —-a-w c:\winnt\system32\auditusr.exe
+ 2008-04-14 00:12:12 14,336 —-a-w c:\winnt\system32\auditusr.exe
- 2005-03-02 18:09:29 56,832 —-a-w c:\winnt\system32\authz.dll
+ 2008-04-14 00:11:50 62,464 —-a-w c:\winnt\system32\authz.dll
- 2004-08-03 22:56:48 588,800 —-a-w c:\winnt\system32\autochk.exe
+ 2008-04-14 00:12:12 588,800 —-a-w c:\winnt\system32\autochk.exe
- 2004-08-03 22:56:48 602,624 —-a-w c:\winnt\system32\autoconv.exe
+ 2008-04-14 00:12:12 602,624 —-a-w c:\winnt\system32\autoconv.exe
- 2004-08-03 22:56:48 580,608 —-a-w c:\winnt\system32\autofmt.exe
+ 2008-04-14 00:12:13 580,608 —-a-w c:\winnt\system32\autofmt.exe
- 2004-08-03 22:56:48 11,264 —-a-w c:\winnt\system32\autolfn.exe
+ 2008-04-14 00:12:13 11,264 —-a-w c:\winnt\system32\autolfn.exe
- 2004-08-03 22:56:42 84,992 —-a-w c:\winnt\system32\avifil32.dll
+ 2008-04-14 00:11:50 84,992 —-a-w c:\winnt\system32\avifil32.dll
+ 2008-04-14 00:11:50 233,472 ——w c:\winnt\system32\azroles.dll
- 2004-08-03 22:56:42 52,736 —-a-w c:\winnt\system32\basesrv.dll
+ 2008-04-14 00:11:50 52,736 —-a-w c:\winnt\system32\basesrv.dll
- 2004-08-03 22:56:42 28,672 —-a-w c:\winnt\system32\batmeter.dll
+ 2008-04-14 00:11:50 29,184 —-a-w c:\winnt\system32\batmeter.dll
- 2004-08-03 22:56:42 8,704 —-a-w c:\winnt\system32\batt.dll
+ 2008-04-14 00:11:50 8,704 —-a-w c:\winnt\system32\batt.dll
- 2004-08-03 22:56:42 17,408 —-a-w c:\winnt\system32\bidispl.dll
+ 2008-04-14 00:11:50 17,408 —-a-w c:\winnt\system32\bidispl.dll
+ 2008-04-14 00:12:03 409,088 ——w c:\winnt\system32\bits\qmgr.dll
- 2004-08-03 22:56:42 8,192 —-a-w c:\winnt\system32\bitsprx2.dll
+ 2008-04-14 00:11:50 8,192 —-a-w c:\winnt\system32\bitsprx2.dll
- 2004-08-03 22:56:42 7,168 —-a-w c:\winnt\system32\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 —-a-w c:\winnt\system32\bitsprx3.dll
+ 2008-04-14 00:11:50 7,168 ——w c:\winnt\system32\bitsprx4.dll
- 2004-08-03 22:56:48 71,680 —-a-w c:\winnt\system32\blastcln.exe
+ 2008-04-14 00:12:13 71,680 —-a-w c:\winnt\system32\blastcln.exe
- 2001-08-23 12:00:00 136,704 —-a-w c:\winnt\system32\bootcfg.exe
+ 2008-04-14 00:12:13 142,848 —-a-w c:\winnt\system32\bootcfg.exe
- 2004-08-03 22:56:00 63,488 —-a-w c:\winnt\system32\browselc.dll
+ 2008-04-13 17:03:24 63,488 —-a-w c:\winnt\system32\browselc.dll
- 2004-08-03 22:56:42 77,312 —-a-w c:\winnt\system32\browser.dll
+ 2008-04-14 00:11:50 77,824 —-a-w c:\winnt\system32\browser.dll
- 2008-10-16 10:20:52 1,024,000 —-a-w c:\winnt\system32\browseui.dll
+ 2008-04-14 00:11:50 1,025,024 —-a-w c:\winnt\system32\browseui.dll
- 2004-08-03 22:56:42 78,336 —-a-w c:\winnt\system32\browsewm.dll
+ 2008-04-14 00:11:50 78,336 —-a-w c:\winnt\system32\browsewm.dll
- 2004-08-03 23:05:44 20,992 —-a-w c:\winnt\system32\bthci.dll
+ 2008-04-14 00:11:50 20,992 —-a-w c:\winnt\system32\bthci.dll
- 2004-08-03 23:05:44 30,208 —-a-w c:\winnt\system32\bthserv.dll
+ 2008-04-14 00:11:50 30,208 —-a-w c:\winnt\system32\bthserv.dll
- 2004-08-03 22:56:42 50,688 —-a-w c:\winnt\system32\btpanui.dll
+ 2008-04-14 00:11:50 50,688 —-a-w c:\winnt\system32\btpanui.dll
- 2004-08-03 22:56:42 59,904 —-a-w c:\winnt\system32\cabinet.dll
+ 2008-04-14 00:11:50 60,416 —-a-w c:\winnt\system32\cabinet.dll
- 2004-08-03 22:56:42 84,480 —-a-w c:\winnt\system32\cabview.dll
+ 2008-04-14 00:11:50 84,480 —-a-w c:\winnt\system32\cabview.dll
- 2001-08-23 12:00:00 18,432 —-a-w c:\winnt\system32\cacls.exe
+ 2008-04-14 00:12:13 19,968 —-a-w c:\winnt\system32\cacls.exe
- 2004-08-03 22:56:42 50,688 —-a-w c:\winnt\system32\camocx.dll
+ 2008-04-14 00:11:50 50,688 —-a-w c:\winnt\system32\camocx.dll
- 2001-08-23 12:00:00 142,848 —-a-w c:\winnt\system32\capesnpn.dll
+ 2008-04-14 00:11:50 150,016 —-a-w c:\winnt\system32\capesnpn.dll
- 2005-07-26 04:39:42 225,792 —-a-w c:\winnt\system32\catsrv.dll
+ 2008-04-14 00:11:50 226,304 —-a-w c:\winnt\system32\catsrv.dll
- 2004-08-03 22:56:42 85,504 —-a-w c:\winnt\system32\catsrvps.dll
+ 2008-04-14 00:11:50 85,504 —-a-w c:\winnt\system32\catsrvps.dll
- 2005-07-26 04:39:43 625,152 —-a-w c:\winnt\system32\catsrvut.dll
+ 2008-04-14 00:11:50 625,664 —-a-w c:\winnt\system32\catsrvut.dll
- 2008-10-16 10:20:42 151,040 —-a-w c:\winnt\system32\cdfview.dll
+ 2008-04-14 00:11:50 151,040 —-a-w c:\winnt\system32\cdfview.dll
- 2008-07-19 02:10:48 94,920 —-a-w c:\winnt\system32\cdm.dll
+ 2008-10-16 19:09:44 92,696 —-a-w c:\winnt\system32\cdm.dll
- 2005-09-10 01:53:41 2,067,968 —-a-w c:\winnt\system32\cdosys.dll
+ 2008-04-14 00:11:50 2,091,520 —-a-w c:\winnt\system32\cdosys.dll
- 2004-08-03 22:56:42 194,560 —-a-w c:\winnt\system32\certcli.dll
+ 2008-04-14 00:11:50 194,560 —-a-w c:\winnt\system32\certcli.dll
- 2004-08-03 22:56:42 457,728 —-a-w c:\winnt\system32\certmgr.dll
+ 2008-04-14 00:11:50 457,728 —-a-w c:\winnt\system32\certmgr.dll
- 2004-08-03 22:56:42 38,912 —-a-w c:\winnt\system32\cfgbkend.dll
+ 2008-04-14 00:11:50 38,912 —-a-w c:\winnt\system32\cfgbkend.dll
- 2004-08-03 22:56:02 16,896 —-a-w c:\winnt\system32\cfgmgr32.dll
+ 2008-04-14 00:09:05 16,896 —-a-w c:\winnt\system32\cfgmgr32.dll
- 2001-08-23 12:00:00 109,568 —-a-w c:\winnt\system32\cic.dll
+ 2008-04-14 00:11:50 148,480 —-a-w c:\winnt\system32\cic.dll
- 2006-06-22 05:06:29 69,120 —-a-w c:\winnt\system32\ciodm.dll
+ 2008-04-14 00:11:50 69,120 —-a-w c:\winnt\system32\ciodm.dll
- 2005-12-30 01:03:29 56,320 —-a-w c:\winnt\system32\cipher.exe
+ 2008-04-14 00:12:14 56,832 —-a-w c:\winnt\system32\cipher.exe
- 2004-08-03 22:56:48 5,632 —-a-w c:\winnt\system32\cisvc.exe
+ 2008-04-14 00:12:14 5,632 —-a-w c:\winnt\system32\cisvc.exe
- 2005-07-26 04:39:43 110,080 —-a-w c:\winnt\system32\clbcatex.dll
+ 2008-04-14 00:11:50 110,592 —-a-w c:\winnt\system32\clbcatex.dll
- 2005-07-26 04:39:43 498,688 —-a-w c:\winnt\system32\clbcatq.dll
+ 2008-04-14 00:11:50 498,688 —-a-w c:\winnt\system32\clbcatq.dll
- 2004-08-03 22:56:48 64,000 —-a-w c:\winnt\system32\cleanmgr.exe
+ 2008-04-14 00:12:14 64,000 —-a-w c:\winnt\system32\cleanmgr.exe
- 2004-08-03 22:56:42 77,824 —-a-w c:\winnt\system32\cliconfg.dll
+ 2008-04-14 00:11:50 77,824 —-a-w c:\winnt\system32\cliconfg.dll
- 2004-08-03 22:56:48 20,480 —-a-w c:\winnt\system32\cliconfg.exe
+ 2008-04-14 00:12:14 20,480 —-a-w c:\winnt\system32\cliconfg.exe
- 2004-08-03 22:56:48 102,912 —-a-w c:\winnt\system32\clipbrd.exe
+ 2008-04-14 00:12:14 102,912 —-a-w c:\winnt\system32\clipbrd.exe
- 2004-08-03 22:56:48 33,280 —-a-w c:\winnt\system32\clipsrv.exe
+ 2008-04-14 00:12:14 33,280 —-a-w c:\winnt\system32\clipsrv.exe
- 2004-08-03 22:56:42 57,856 —-a-w c:\winnt\system32\clusapi.dll
+ 2008-04-14 00:11:50 58,368 —-a-w c:\winnt\system32\clusapi.dll
- 2004-08-03 22:56:42 15,872 —-a-w c:\winnt\system32\cmcfg32.dll
+ 2008-04-14 00:11:50 15,872 —-a-w c:\winnt\system32\cmcfg32.dll
- 2004-08-03 22:56:50 388,608 —-a-w c:\winnt\system32\cmd.exe
+ 2008-04-14 00:12:14 389,120 —-a-w c:\winnt\system32\cmd.exe
- 2004-08-03 22:56:42 343,040 —-a-w c:\winnt\system32\cmdial32.dll
+ 2008-04-14 00:11:50 344,064 —-a-w c:\winnt\system32\cmdial32.dll
- 2004-08-03 22:56:50 47,104 —-a-w c:\winnt\system32\cmdl32.exe
+ 2008-04-14 00:12:14 25,600 —-a-w c:\winnt\system32\cmdl32.exe
- 2004-08-03 22:56:50 39,936 —-a-w c:\winnt\system32\cmmon32.exe
+ 2008-04-14 00:12:15 39,936 —-a-w c:\winnt\system32\cmmon32.exe
- 2004-08-03 22:56:42 185,344 —-a-w c:\winnt\system32\cmprops.dll
+ 2008-04-14 00:11:50 185,344 —-a-w c:\winnt\system32\cmprops.dll
- 2004-08-03 22:56:42 13,824 —-a-w c:\winnt\system32\cmsetACL.dll
+ 2008-04-14 00:11:50 13,312 —-a-w c:\winnt\system32\cmsetacl.dll
- 2004-08-03 22:56:50 63,488 —-a-w c:\winnt\system32\cmstp.exe
+ 2008-04-14 00:12:15 63,488 —-a-w c:\winnt\system32\cmstp.exe
- 2004-08-03 22:56:42 39,936 —-a-w c:\winnt\system32\cmutil.dll
+ 2008-04-14 00:11:50 39,424 —-a-w c:\winnt\system32\cmutil.dll
- 2004-08-03 23:05:44 47,104 —-a-w c:\winnt\system32\cnbjmon.dll
+ 2008-04-14 00:11:50 47,104 —-a-w c:\winnt\system32\cnbjmon.dll
- 2005-07-26 04:39:43 60,416 —-a-w c:\winnt\system32\colbact.dll
+ 2008-04-14 00:11:51 60,416 —-a-w c:\winnt\system32\colbact.dll
- 2005-07-26 04:39:44 195,072 —-a-w c:\winnt\system32\Com\comadmin.dll
+ 2008-04-14 00:11:51 195,072 —-a-w c:\winnt\system32\Com\comadmin.dll
- 2004-08-03 22:56:50 9,728 —-a-w c:\winnt\system32\Com\comrepl.exe
+ 2008-04-14 00:12:15 9,728 —-a-w c:\winnt\system32\Com\comrepl.exe
- 2001-08-23 12:00:00 5,120 —-a-w c:\winnt\system32\Com\comrereg.exe
+ 2008-04-14 00:12:15 6,144 —-a-w c:\winnt\system32\Com\comrereg.exe
- 2001-08-23 12:00:00 25,600 —-a-w c:\winnt\system32\comaddin.dll
+ 2008-04-14 00:11:51 28,160 —-a-w c:\winnt\system32\comaddin.dll
- 2006-08-25 15:45:58 617,472 —-a-w c:\winnt\system32\comctl32.dll
+ 2008-04-14 00:11:51 617,472 —-a-w c:\winnt\system32\comctl32.dll
- 2004-08-03 22:56:42 276,992 —-a-w c:\winnt\system32\comdlg32.dll
+ 2008-04-14 00:11:51 276,992 —-a-w c:\winnt\system32\comdlg32.dll
- 2004-08-03 22:56:42 252,928 —-a-w c:\winnt\system32\compatUI.dll
+ 2008-04-14 00:11:51 252,928 —-a-w c:\winnt\system32\compatui.dll
- 2004-08-03 22:56:42 229,376 —-a-w c:\winnt\system32\compstui.dll
+ 2008-04-14 00:11:51 229,376 —-a-w c:\winnt\system32\compstui.dll
- 2005-07-26 04:39:44 97,792 —-a-w c:\winnt\system32\comrepl.dll
+ 2008-04-14 00:11:51 97,792 —-a-w c:\winnt\system32\comrepl.dll
- 2004-08-03 22:56:42 792,064 —-a-w c:\winnt\system32\comres.dll
+ 2008-04-14 00:11:51 792,064 —-a-w c:\winnt\system32\comres.dll
+ 2008-04-13 18:43:32 9,728 ——w c:\winnt\system32\comsdupd.exe
- 2001-08-23 12:00:00 147,456 —-a-w c:\winnt\system32\comsnap.dll
+ 2008-04-14 00:11:51 167,424 —-a-w c:\winnt\system32\comsnap.dll
- 2005-07-26 04:39:44 1,267,200 —-a-w c:\winnt\system32\comsvcs.dll
+ 2008-04-14 00:11:51 1,267,200 —-a-w c:\winnt\system32\comsvcs.dll
- 2005-07-26 04:39:45 540,160 —-a-w c:\winnt\system32\comuid.dll
+ 2008-04-14 00:11:51 539,648 —-a-w c:\winnt\system32\comuid.dll
- 2009-02-28 17:24:57 32,768 —-a-w c:\winnt\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-06 18:29:32 32,768 —-a-w c:\winnt\system32\config\systemprofile\Cookies\index.dat
- 2009-02-28 17:24:57 32,768 —-a-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-06 18:29:32 32,768 —-a-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-06 18:29:21 32,768 –sha-w c:\winnt\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009030620090307\index.dat
- 2009-02-28 17:24:57 131,072 —-a-w c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 18:29:32 131,072 —-a-w c:\winnt\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2001-08-23 12:00:00 345,600 —-a-w c:\winnt\system32\confmsp.dll
+ 2008-04-14 00:11:51 357,888 —-a-w c:\winnt\system32\confmsp.dll
- 2004-08-03 22:56:50 27,648 —-a-w c:\winnt\system32\conime.exe
+ 2008-04-14 00:12:15 27,648 —-a-w c:\winnt\system32\conime.exe
- 2007-08-13 23:42:54 17,408 —-a-w c:\winnt\system32\corpol.dll
+ 2008-04-14 00:11:51 35,328 —-a-w c:\winnt\system32\corpol.dll
+ 2008-04-14 00:11:51 12,800 ——w c:\winnt\system32\credssp.dll
- 2004-08-03 22:56:42 163,840 —-a-w c:\winnt\system32\credui.dll
+ 2008-04-14 00:11:51 163,840 —-a-w c:\winnt\system32\credui.dll
- 2004-08-03 22:56:42 597,504 —-a-w c:\winnt\system32\crypt32.dll
+ 2008-04-14 00:11:51 599,040 —-a-w c:\winnt\system32\crypt32.dll
- 2004-08-03 22:56:42 74,752 —-a-w c:\winnt\system32\cryptdlg.dll
+ 2008-04-14 00:11:51 74,752 —-a-w c:\winnt\system32\cryptdlg.dll
- 2004-08-03 22:56:42 33,280 —-a-w c:\winnt\system32\cryptdll.dll
+ 2008-04-14 00:11:51 33,280 —-a-w c:\winnt\system32\cryptdll.dll
- 2004-08-03 22:56:42 53,760 —-a-w c:\winnt\system32\cryptext.dll
+ 2008-04-14 00:11:51 53,760 —-a-w c:\winnt\system32\cryptext.dll
- 2004-08-03 22:56:42 63,488 —-a-w c:\winnt\system32\cryptnet.dll
+ 2008-04-14 00:11:51 64,512 —-a-w c:\winnt\system32\cryptnet.dll
- 2004-08-03 22:56:42 60,416 —-a-w c:\winnt\system32\cryptsvc.dll
+ 2008-04-14 00:11:51 62,464 —-a-w c:\winnt\system32\cryptsvc.dll
- 2004-08-03 22:56:42 512,512 —-a-w c:\winnt\system32\cryptui.dll
+ 2008-04-14 00:11:51 512,512 —-a-w c:\winnt\system32\cryptui.dll
- 2004-08-03 22:56:42 101,888 —-a-w c:\winnt\system32\cscdll.dll
+ 2008-04-14 00:11:51 101,888 —-a-w c:\winnt\system32\cscdll.dll
- 2004-08-03 22:56:50 98,304 —-a-w c:\winnt\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 —-a-w c:\winnt\system32\cscript.exe
- 2004-08-03 22:56:42 326,656 —-a-w c:\winnt\system32\cscui.dll
+ 2008-04-14 00:11:51 326,656 —-a-w c:\winnt\system32\cscui.dll
- 2004-08-03 22:56:42 32,768 —-a-w c:\winnt\system32\csrsrv.dll
+ 2008-04-14 00:11:51 32,256 —-a-w c:\winnt\system32\csrsrv.dll
- 2004-08-03 22:56:50 6,144 —-a-w c:\winnt\system32\csrss.exe
+ 2008-04-14 00:12:15 6,144 —-a-w c:\winnt\system32\csrss.exe
- 2004-08-03 22:56:50 15,360 —-a-w c:\winnt\system32\ctfmon.exe
+ 2008-04-14 00:12:16 15,360 —-a-w c:\winnt\system32\ctfmon.exe
- 2004-08-03 22:56:42 1,179,648 —-a-w c:\winnt\system32\d3d8.dll
+ 2008-04-14 00:11:51 1,179,648 —-a-w c:\winnt\system32\d3d8.dll
- 2004-08-03 22:56:42 8,192 —-a-w c:\winnt\system32\d3d8thk.dll
+ 2008-04-14 00:11:51 8,192 —-a-w c:\winnt\system32\d3d8thk.dll
- 2004-08-03 22:56:42 1,689,088 —-a-w c:\winnt\system32\d3d9.dll
+ 2008-04-14 00:11:51 1,689,088 —-a-w c:\winnt\system32\d3d9.dll
- 2004-08-03 22:56:42 825,344 —-a-w c:\winnt\system32\d3dim700.dll
+ 2008-04-14 00:11:51 824,320 —-a-w c:\winnt\system32\d3dim700.dll
- 2008-10-16 10:20:45 1,054,208 —-a-w c:\winnt\system32\danim.dll
+ 2008-04-14 00:11:51 1,054,208 —-a-w c:\winnt\system32\danim.dll
- 2004-08-03 22:56:44 54,272 —-a-w c:\winnt\system32\dataclen.dll
+ 2008-04-14 00:11:51 54,272 —-a-w c:\winnt\system32\dataclen.dll
- 2001-08-23 12:00:00 152,064 —-a-w c:\winnt\system32\datime.dll
+ 2008-04-14 00:11:51 165,376 —-a-w c:\winnt\system32\datime.dll
- 2004-08-03 22:56:44 24,576 —-a-w c:\winnt\system32\davclnt.dll
+ 2008-04-14 00:11:51 25,088 —-a-w c:\winnt\system32\davclnt.dll
- 2004-08-03 22:56:44 640,000 —-a-w c:\winnt\system32\dbghelp.dll
+ 2008-04-14 00:11:51 640,000 —-a-w c:\winnt\system32\dbghelp.dll
- 2004-08-03 22:56:44 24,576 —-a-w c:\winnt\system32\dbmsrpcn.dll
+ 2008-04-14 00:11:51 24,576 —-a-w c:\winnt\system32\dbmsrpcn.dll
- 2004-08-03 22:56:44 110,592 —-a-w c:\winnt\system32\dbnetlib.dll
+ 2008-04-14 00:11:51 110,592 —-a-w c:\winnt\system32\dbnetlib.dll
- 2004-08-03 22:56:44 28,672 —-a-w c:\winnt\system32\dbnmpntw.dll
+ 2008-04-14 00:11:51 28,672 —-a-w c:\winnt\system32\dbnmpntw.dll
- 2004-08-03 23:07:22 1,788 —-a-w c:\winnt\system32\Dcache.bin
+ 2008-04-14 00:25:26 1,804 —-a-w c:\winnt\system32\dcache.bin
- 2004-08-03 22:56:44 8,704 —-a-w c:\winnt\system32\dciman32.dll
+ 2008-04-14 00:11:51 8,704 —-a-w c:\winnt\system32\dciman32.dll
- 2001-08-23 12:00:00 5,120 —-a-w c:\winnt\system32\dcomcnfg.exe
+ 2008-04-14 00:12:16 6,144 —-a-w c:\winnt\system32\dcomcnfg.exe
- 2004-08-03 22:56:50 30,208 —-a-w c:\winnt\system32\ddeshare.exe
+ 2008-04-14 00:12:16 30,208 —-a-w c:\winnt\system32\ddeshare.exe
- 2004-08-03 22:56:44 266,240 —-a-w c:\winnt\system32\ddraw.dll
+ 2008-04-14 00:11:51 279,552 —-a-w c:\winnt\system32\ddraw.dll
- 2004-08-03 22:56:44 27,136 —-a-w c:\winnt\system32\ddrawex.dll
+ 2008-04-14 00:11:51 27,136 —-a-w c:\winnt\system32\ddrawex.dll
- 2004-08-03 22:56:50 25,088 —-a-w c:\winnt\system32\defrag.exe
+ 2008-04-14 00:12:16 25,088 —-a-w c:\winnt\system32\defrag.exe
- 2004-08-03 22:56:44 59,904 —-a-w c:\winnt\system32\devenum.dll
+ 2008-04-14 00:11:51 59,904 —-a-w c:\winnt\system32\devenum.dll
- 2004-08-03 22:56:44 282,624 —-a-w c:\winnt\system32\devmgr.dll
+ 2008-04-14 00:11:51 282,624 —-a-w c:\winnt\system32\devmgr.dll
- 2004-08-03 22:56:50 82,432 —-a-w c:\winnt\system32\dfrgfat.exe
+ 2008-04-14 00:12:16 82,944 —-a-w c:\winnt\system32\dfrgfat.exe
- 2004-08-03 22:56:50 104,960 —-a-w c:\winnt\system32\dfrgntfs.exe
+ 2008-04-14 00:12:16 105,472 —-a-w c:\winnt\system32\dfrgntfs.exe
- 2004-08-03 22:56:44 38,912 —-a-w c:\winnt\system32\dfrgsnap.dll
+ 2008-04-14 00:11:51 39,424 —-a-w c:\winnt\system32\dfrgsnap.dll
- 2004-08-03 22:56:44 123,904 —-a-w c:\winnt\system32\dfrgui.dll
+ 2008-04-14 00:11:51 124,416 —-a-w c:\winnt\system32\dfrgui.dll
- 2004-08-03 22:56:44 28,672 —-a-w c:\winnt\system32\dfsshlex.dll
+ 2008-04-14 00:11:51 28,672 —-a-w c:\winnt\system32\dfsshlex.dll
- 2004-08-03 22:56:44 111,104 —-a-w c:\winnt\system32\dgnet.dll
+ 2008-04-14 00:11:51 111,104 —-a-w c:\winnt\system32\dgnet.dll
- 2006-05-19 12:59:41 111,616 —-a-w c:\winnt\system32\dhcpcsvc.dll
+ 2008-04-14 00:11:51 126,976 —-a-w c:\winnt\system32\dhcpcsvc.dll
- 2001-08-23 12:00:00 370,176 —-a-w c:\winnt\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 379,904 —-a-w c:\winnt\system32\dhcpmon.dll
+ 2008-04-14 00:11:52 48,640 ——w c:\winnt\system32\dhcpqec.dll
- 2004-08-03 22:56:50 85,504 —-a-w c:\winnt\system32\diantz.exe
+ 2008-04-14 00:12:17 87,040 —-a-w c:\winnt\system32\diantz.exe
- 2004-08-03 22:56:44 68,608 —-a-w c:\winnt\system32\digest.dll
+ 2008-04-14 00:11:52 68,608 —-a-w c:\winnt\system32\digest.dll
+ 2008-04-14 00:11:52 19,456 ——w c:\winnt\system32\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ——w c:\winnt\system32\dimsroam.dll
- 2004-08-03 22:56:44 159,232 —-a-w c:\winnt\system32\dinput.dll
+ 2008-04-14 00:11:52 158,720 —-a-w c:\winnt\system32\dinput.dll
- 2004-08-03 22:56:44 181,760 —-a-w c:\winnt\system32\dinput8.dll
+ 2008-04-14 00:11:52 181,760 —-a-w c:\winnt\system32\dinput8.dll
- 2001-08-23 12:00:00 1,501,696 —-a-w c:\winnt\system32\diskcopy.dll
+ 2008-04-14 00:11:52 1,504,256 —-a-w c:\winnt\system32\diskcopy.dll
- 2004-08-03 22:56:50 163,840 —-a-w c:\winnt\system32\diskpart.exe
+ 2008-04-14 00:12:17 163,840 —-a-w c:\winnt\system32\diskpart.exe
- 2001-08-23 12:00:00 45,083 —-a-w c:\winnt\system32\dispex.dll
+ 2008-04-14 00:11:52 32,768 —-a-w c:\winnt\system32\dispex.dll
- 2008-10-16 20:38:34 124,928 -c–a-w c:\winnt\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 -c–a-w c:\winnt\system32\dllcache\advpack.dll
- 2008-08-14 09:51:43 138,368 -c–a-w c:\winnt\system32\dllcache\afd.sys
+ 2008-08-14 10:04:36 138,496 -c—-w c:\winnt\system32\dllcache\afd.sys
- 2008-06-13 13:10:50 272,128 -c—-w c:\winnt\system32\dllcache\bthport.sys
+ 2008-06-13 11:05:51 272,128 -c—-w c:\winnt\system32\dllcache\bthport.sys
- 2008-07-19 02:10:48 94,920 -c–a-w c:\winnt\system32\dllcache\cdm.dll
+ 2008-10-16 19:09:44 92,696 -c–a-w c:\winnt\system32\dllcache\cdm.dll
- 2004-08-03 22:56:50 98,304 -c–a-w c:\winnt\system32\dllcache\cscript.exe
+ 2008-05-07 09:07:23 135,168 -c—-w c:\winnt\system32\dllcache\cscript.exe
- 2008-06-21 03:11:12 148,992 -c–a-w c:\winnt\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 -c—-w c:\winnt\system32\dllcache\dnsapi.dll
- 2004-08-03 22:56:28 96,768 -c–a-w c:\winnt\system32\dllcache\dpcdll.dll
+ 2008-04-14 00:10:45 102,912 -c—-w c:\winnt\system32\dllcache\dpcdll.dll
- 2004-08-03 22:57:06 299,520 -c–a-w c:\winnt\system32\dllcache\drmclien.dll
+ 2008-04-14 00:13:00 299,520 -c–a-w c:\winnt\system32\dllcache\drmclien.dll
- 2004-08-03 22:56:44 87,040 -c–a-w c:\winnt\system32\dllcache\drmstor.dll
+ 2008-04-14 00:11:52 87,040 -c–a-w c:\winnt\system32\dllcache\drmstor.dll
- 2006-08-22 08:05:26 498,742 -c–a-w c:\winnt\system32\dllcache\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 -c–a-w c:\winnt\system32\dllcache\dxmasf.dll
- 2008-10-16 20:38:34 347,136 -c–a-w c:\winnt\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 -c–a-w c:\winnt\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 -c–a-w c:\winnt\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 -c–a-w c:\winnt\system32\dllcache\dxtrans.dll
- 2008-07-07 20:32:22 253,952 -c–a-w c:\winnt\system32\dllcache\es.dll
+ 2008-07-07 20:26:58 253,952 -c—-w c:\winnt\system32\dllcache\es.dll
- 2008-10-16 20:38:35 133,120 -c–a-w c:\winnt\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 -c–a-w c:\winnt\system32\dllcache\extmgr.dll
- 2008-10-23 13:01:36 283,648 -c–a-w c:\winnt\system32\dllcache\gdi32.dll
+ 2008-10-23 12:36:14 286,720 -c—-w c:\winnt\system32\dllcache\gdi32.dll
- 2008-10-16 20:38:35 63,488 -c—-w c:\winnt\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 -c—-w c:\winnt\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 -c–a-w c:\winnt\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 -c–a-w c:\winnt\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 -c–a-w c:\winnt\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 -c–a-w c:\winnt\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 -c–a-w c:\winnt\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 -c–a-w c:\winnt\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c–a-w c:\winnt\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 -c–a-w c:\winnt\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 -c—-w c:\winnt\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 -c—-w c:\winnt\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 -c–a-w c:\winnt\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 -c–a-w c:\winnt\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 -c—-w c:\winnt\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 -c—-w c:\winnt\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 -c–a-w c:\winnt\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 -c–a-w c:\winnt\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 -c—-w c:\winnt\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 -c—-w c:\winnt\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 -c—-w c:\winnt\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 -c—-w c:\winnt\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 -c–a-w c:\winnt\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 -c–a-w c:\winnt\system32\dllcache\iexplore.exe
- 2008-04-11 18:50:43 683,520 -c–a-w c:\winnt\system32\dllcache\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 -c—-w c:\winnt\system32\dllcache\inetcomm.dll
- 2007-08-13 23:38:04 491,520 -c–a-w c:\winnt\system32\dllcache\jscript.dll
+ 2008-05-09 10:53:39 512,000 -c—-w c:\winnt\system32\dllcache\jscript.dll
- 2008-10-16 20:38:37 27,648 -c–a-w c:\winnt\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 -c–a-w c:\winnt\system32\dllcache\jsproxy.dll
- 2008-03-07 16:56:41 29,696 -c–a-w c:\winnt\system32\dllcache\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 -c–a-w c:\winnt\system32\dllcache\mimefilt.dll
- 2004-08-03 22:56:54 123,392 -c–a-w c:\winnt\system32\dllcache\mplay32.exe
+ 2008-04-14 00:12:27 123,392 -c–a-w c:\winnt\system32\dllcache\mplay32.exe
- 2004-08-03 22:56:54 4,639 -c–a-w c:\winnt\system32\dllcache\mplayer2.exe
+ 2008-04-14 00:12:27 4,639 -c–a-w c:\winnt\system32\dllcache\mplayer2.exe
- 2008-10-24 11:10:42 453,632 -c—-w c:\winnt\system32\dllcache\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 -c—-w c:\winnt\system32\dllcache\mrxsmb.sys
- 2008-06-24 16:23:05 74,240 -c–a-w c:\winnt\system32\dllcache\mscms.dll
+ 2008-06-24 16:43:16 74,240 -c—-w c:\winnt\system32\dllcache\mscms.dll
- 2004-08-03 22:56:14 4,126 -c–a-w c:\winnt\system32\dllcache\msdxmlc.dll
+ 2008-04-14 00:10:08 4,126 -c–a-w c:\winnt\system32\dllcache\msdxmlc.dll
- 2008-10-16 20:38:37 459,264 -c—-w c:\winnt\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 -c—-w c:\winnt\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 -c—-w c:\winnt\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 -c—-w c:\winnt\system32\dllcache\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 -c–a-w c:\winnt\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 -c–a-w c:\winnt\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 -c–a-w c:\winnt\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 -c–a-w c:\winnt\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 -c–a-w c:\winnt\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 -c–a-w c:\winnt\system32\dllcache\msrating.dll
- 2006-10-19 02:47:16 414,208 -c–a-w c:\winnt\system32\dllcache\msscp.dll
+ 2006-12-04 21:21:50 414,720 -c–a-w c:\winnt\system32\dllcache\msscp.dll
- 2008-10-16 20:38:39 671,232 -c–a-w c:\winnt\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 -c–a-w c:\winnt\system32\dllcache\mstime.dll
- 2008-06-20 17:41:10 245,248 -c–a-w c:\winnt\system32\dllcache\mswsock.dll
+ 2008-06-20 17:46:57 245,248 -c—-w c:\winnt\system32\dllcache\mswsock.dll
- 2008-09-04 16:42:02 1,106,944 -c–a-w c:\winnt\system32\dllcache\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 -c–a-w c:\winnt\system32\dllcache\msxml3.dll
+ 2008-04-14 00:12:01 1,306,624 -c—-w c:\winnt\system32\dllcache\msxml6.dll
+ 2008-04-13 17:27:18 79,872 -c—-w c:\winnt\system32\dllcache\msxml6r.dll
- 2008-10-15 16:53:28 339,456 -c–a-w c:\winnt\system32\dllcache\netapi32.dll
+ 2008-10-15 16:34:24 337,408 -c—-w c:\winnt\system32\dllcache\netapi32.dll
- 2008-03-07 16:56:41 98,304 -c–a-w c:\winnt\system32\dllcache\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 -c–a-w c:\winnt\system32\dllcache\nlhtml.dll
- 2004-08-03 22:57:02 226,816 -c–a-w c:\winnt\system32\dllcache\npdrmv2.dll
+ 2008-04-14 00:12:56 226,816 -c–a-w c:\winnt\system32\dllcache\npdrmv2.dll
- 2004-08-03 22:56:46 364,544 -c–a-w c:\winnt\system32\dllcache\npdsplay.dll
+ 2008-04-14 00:12:02 364,544 -c–a-w c:\winnt\system32\dllcache\npdsplay.dll
- 2004-08-03 22:56:46 10,240 -c–a-w c:\winnt\system32\dllcache\npwmsdrm.dll
+ 2008-04-14 00:12:02 10,240 -c–a-w c:\winnt\system32\dllcache\npwmsdrm.dll
- 2008-08-14 09:55:01 2,142,720 -c—-w c:\winnt\system32\dllcache\ntkrnlmp.exe
+ 2008-08-14 10:09:26 2,145,280 -c—-w c:\winnt\system32\dllcache\ntkrnlmp.exe
- 2008-08-14 09:18:44 2,062,976 -c—-w c:\winnt\system32\dllcache\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 -c—-w c:\winnt\system32\dllcache\ntkrnlpa.exe
- 2008-08-14 09:18:46 2,020,864 -c—-w c:\winnt\system32\dllcache\ntkrpamp.exe
+ 2008-08-14 09:33:16 2,023,936 -c—-w c:\winnt\system32\dllcache\ntkrpamp.exe
- 2008-08-14 09:57:20 2,185,984 -c—-w c:\winnt\system32\dllcache\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 -c—-w c:\winnt\system32\dllcache\ntoskrnl.exe
- 2008-10-16 20:38:39 102,912 -c–a-w c:\winnt\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 -c–a-w c:\winnt\system32\dllcache\occache.dll
- 2008-03-07 16:56:41 192,000 -c–a-w c:\winnt\system32\dllcache\offfilt.dll
+ 2008-03-07 17:02:08 192,000 -c–a-w c:\winnt\system32\dllcache\offfilt.dll
- 2004-08-03 22:56:06 24,064 -c–a-w c:\winnt\system32\dllcache\pidgen.dll
+ 2008-04-14 00:09:24 24,064 -c—-w c:\winnt\system32\dllcache\pidgen.dll
- 2008-10-16 20:38:39 44,544 -c–a-w c:\winnt\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 -c–a-w c:\winnt\system32\dllcache\pngfilt.dll
- 2008-05-07 05:18:48 1,287,680 -c–a-w c:\winnt\system32\dllcache\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 -c—-w c:\winnt\system32\dllcache\quartz.dll
- 2008-05-08 12:28:49 202,752 -c–a-w c:\winnt\system32\dllcache\rmcast.sys
+ 2008-05-08 14:02:52 203,136 -c—-w c:\winnt\system32\dllcache\rmcast.sys
- 2004-08-03 22:56:46 159,744 -c–a-w c:\winnt\system32\dllcache\scrobj.dll
+ 2008-05-09 10:53:39 180,224 -c—-w c:\winnt\system32\dllcache\scrobj.dll
- 2004-08-03 22:56:46 151,552 -c–a-w c:\winnt\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53:40 172,032 -c—-w c:\winnt\system32\dllcache\scrrun.dll
- 2007-10-26 03:34:01 8,460,288 -c–a-w c:\winnt\system32\dllcache\shell32.dll
+ 2008-06-17 19:02:19 8,461,312 -c—-w c:\winnt\system32\dllcache\shell32.dll
- 2004-08-03 22:56:46 151,552 -c–a-w c:\winnt\system32\dllcache\shmedia.dll
+ 2008-04-14 00:12:05 152,064 -c–a-w c:\winnt\system32\dllcache\shmedia.dll
- 2008-12-11 11:57:21 333,184 -c–a-w c:\winnt\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c—-w c:\winnt\system32\dllcache\srv.sys
- 2008-10-03 10:15:47 247,326 -c–a-w c:\winnt\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c–a-w c:\winnt\system32\dllcache\strmdll.dll
- 2008-06-20 10:45:13 360,320 -c–a-w c:\winnt\system32\dllcache\tcpip.sys
+ 2008-06-20 11:51:12 361,600 -c—-w c:\winnt\system32\dllcache\tcpip.sys
- 2008-06-20 19:22:08 225,920 -c–a-w c:\winnt\system32\dllcache\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 -c—-w c:\winnt\system32\dllcache\tcpip6.sys
- 2006-11-01 23:31:34 315,904 -c–a-w c:\winnt\system32\dllcache\unregmp2.exe
+ 2007-06-27 03:10:26 317,440 -c–a-w c:\winnt\system32\dllcache\unregmp2.exe
- 2008-10-16 20:38:39 105,984 -c–a-w c:\winnt\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 -c–a-w c:\winnt\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 -c–a-w c:\winnt\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 -c–a-w c:\winnt\system32\dllcache\urlmon.dll
- 2007-08-13 23:54:10 413,696 -c–a-w c:\winnt\system32\dllcache\vbscript.dll
+ 2008-05-09 10:53:40 430,080 -c—-w c:\winnt\system32\dllcache\vbscript.dll
- 2007-08-13 23:54:10 765,952 -c–a-w c:\winnt\system32\dllcache\VGX.dll
+ 2008-05-27 17:23:58 765,952 -c–a-w c:\winnt\system32\dllcache\vgx.dll
- 2008-10-16 20:38:39 233,472 -c–a-w c:\winnt\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 -c–a-w c:\winnt\system32\dllcache\webcheck.dll
+ 2008-09-06 04:30:42 241,704 -c—-w c:\winnt\system32\dllcache\wgaLogon.dll
+ 2008-09-06 04:29:58 917,032 -c—-w c:\winnt\system32\dllcache\WgaTray.exe
- 2008-09-15 11:57:41 1,846,016 -c–a-w c:\winnt\system32\dllcache\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 -c—-w c:\winnt\system32\dllcache\win32k.sys
- 2008-10-16 20:38:40 826,368 -c–a-w c:\winnt\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 -c–a-w c:\winnt\system32\dllcache\wininet.dll
- 2004-08-03 22:56:48 20,480 -c–a-w c:\winnt\system32\dllcache\wmpcd.dll
+ 2008-04-14 00:12:09 20,480 -c–a-w c:\winnt\system32\dllcache\wmpcd.dll
- 2004-08-03 22:56:48 20,480 -c–a-w c:\winnt\system32\dllcache\wmpcore.dll
+ 2008-04-14 00:12:09 20,480 -c–a-w c:\winnt\system32\dllcache\wmpcore.dll
- 2004-08-03 22:56:48 20,480 -c–a-w c:\winnt\system32\dllcache\wmpui.dll
+ 2008-04-14 00:12:09 20,480 -c–a-w c:\winnt\system32\dllcache\wmpui.dll
- 2004-08-03 22:56:48 115,200 -c–a-w c:\winnt\system32\dllcache\wmsdmoe.dll
+ 2008-04-14 00:12:09 115,200 -c–a-w c:\winnt\system32\dllcache\wmsdmoe.dll
- 2004-08-03 22:56:48 303,616 -c–a-w c:\winnt\system32\dllcache\wmstream.dll
+ 2008-04-14 00:12:10 303,616 -c–a-w c:\winnt\system32\dllcache\wmstream.dll
- 2004-08-03 22:56:58 114,688 -c–a-w c:\winnt\system32\dllcache\wscript.exe
+ 2008-05-08 11:24:44 155,648 -c—-w c:\winnt\system32\dllcache\wscript.exe
- 2004-08-03 22:56:48 65,536 -c–a-w c:\winnt\system32\dllcache\wshext.dll
+ 2008-05-09 10:53:40 90,112 -c—-w c:\winnt\system32\dllcache\wshext.dll
- 2008-07-19 02:09:44 563,912 -c–a-w c:\winnt\system32\dllcache\wuapi.dll
+ 2008-10-16 19:12:20 561,688 -c–a-w c:\winnt\system32\dllcache\wuapi.dll
- 2008-07-19 02:10:42 53,448 -c–a-w c:\winnt\system32\dllcache\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 -c–a-w c:\winnt\system32\dllcache\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 -c–a-w c:\winnt\system32\dllcache\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 -c–a-w c:\winnt\system32\dllcache\wuaueng.dll
- 2008-07-19 02:09:46 325,832 -c–a-w c:\winnt\system32\dllcache\wucltui.dll
+ 2008-10-16 19:12:22 323,608 -c–a-w c:\winnt\system32\dllcache\wucltui.dll
- 2008-07-19 02:10:20 36,552 -c–a-w c:\winnt\system32\dllcache\wups.dll
+ 2008-10-16 19:08:58 34,328 -c–a-w c:\winnt\system32\dllcache\wups.dll
- 2004-08-03 22:56:50 5,120 —-a-w c:\winnt\system32\dllhost.exe
+ 2008-04-14 00:12:17 5,120 —-a-w c:\winnt\system32\dllhost.exe
- 2004-08-03 22:56:50 224,768 —-a-w c:\winnt\system32\dmadmin.exe
+ 2008-04-14 00:12:17 224,768 —-a-w c:\winnt\system32\dmadmin.exe
- 2004-08-03 22:56:44 28,672 —-a-w c:\winnt\system32\dmband.dll
+ 2008-04-14 00:11:52 28,672 —-a-w c:\winnt\system32\dmband.dll
- 2004-08-03 22:56:44 61,440 —-a-w c:\winnt\system32\dmcompos.dll
+ 2008-04-14 00:11:52 61,440 —-a-w c:\winnt\system32\dmcompos.dll
- 2001-08-23 12:00:00 273,920 —-a-w c:\winnt\system32\dmdlgs.dll
+ 2008-04-14 00:11:52 285,184 —-a-w c:\winnt\system32\dmdlgs.dll
- 2004-08-03 22:56:44 200,704 —-a-w c:\winnt\system32\dmdskmgr.dll
+ 2008-04-14 00:11:52 200,704 —-a-w c:\winnt\system32\dmdskmgr.dll
- 2004-08-03 22:56:44 181,248 —-a-w c:\winnt\system32\dmime.dll
+ 2008-04-14 00:11:52 181,248 —-a-w c:\winnt\system32\dmime.dll
- 2004-08-03 22:56:44 35,840 —-a-w c:\winnt\system32\dmloader.dll
+ 2008-04-14 00:11:52 35,840 —-a-w c:\winnt\system32\dmloader.dll
- 2004-08-03 22:56:50 15,872 —-a-w c:\winnt\system32\dmremote.exe
+ 2008-04-14 00:12:17 15,872 —-a-w c:\winnt\system32\dmremote.exe
- 2004-08-03 22:56:44 82,432 —-a-w c:\winnt\system32\dmscript.dll
+ 2008-04-14 00:11:52 82,432 —-a-w c:\winnt\system32\dmscript.dll
- 2004-08-03 22:56:44 23,552 —-a-w c:\winnt\system32\dmserver.dll
+ 2008-04-14 00:11:52 23,552 —-a-w c:\winnt\system32\dmserver.dll
- 2004-08-03 22:56:44 105,984 —-a-w c:\winnt\system32\dmstyle.dll
+ 2008-04-14 00:11:52 105,984 —-a-w c:\winnt\system32\dmstyle.dll
- 2004-08-03 22:56:44 103,424 —-a-w c:\winnt\system32\dmsynth.dll
+ 2008-04-14 00:11:52 103,424 —-a-w c:\winnt\system32\dmsynth.dll
- 2004-08-03 22:56:44 104,448 —-a-w c:\winnt\system32\dmusic.dll
+ 2008-04-14 00:11:52 104,448 —-a-w c:\winnt\system32\dmusic.dll
- 2004-08-03 23:05:44 52,224 —-a-w c:\winnt\system32\dmutil.dll
+ 2008-04-14 00:11:52 52,224 —-a-w c:\winnt\system32\dmutil.dll
- 2008-06-21 03:11:12 148,992 —-a-w c:\winnt\system32\dnsapi.dll
+ 2008-06-20 17:46:57 147,968 —-a-w c:\winnt\system32\dnsapi.dll
- 2008-02-20 05:32:43 45,568 —-a-w c:\winnt\system32\dnsrslvr.dll
+ 2008-04-14 00:11:52 45,568 —-a-w c:\winnt\system32\dnsrslvr.dll
- 2004-08-03 22:56:44 48,128 —-a-w c:\winnt\system32\docprop2.dll
+ 2008-04-14 00:11:52 48,128 —-a-w c:\winnt\system32\docprop2.dll
+ 2008-04-14 00:11:52 26,112 ——w c:\winnt\system32\dot3api.dll
+ 2008-04-14 00:11:52 57,856 ——w c:\winnt\system32\dot3cfg.dll
+ 2008-04-14 00:11:52 9,216 ——w c:\winnt\system32\dot3dlg.dll
+ 2008-04-14 00:11:52 39,936 ——w c:\winnt\system32\dot3gpclnt.dll
+ 2008-04-14 00:11:52 56,320 ——w c:\winnt\system32\dot3msm.dll
+ 2008-04-14 00:11:52 132,096 ——w c:\winnt\system32\dot3svc.dll
+ 2008-04-14 00:11:52 650,752 ——w c:\winnt\system32\dot3ui.dll
- 2004-08-03 22:56:28 96,768 —-a-w c:\winnt\system32\dpcdll.dll
+ 2008-04-14 00:10:45 102,912 —-a-w c:\winnt\system32\dpcdll.dll
- 2004-08-03 22:56:50 30,208 —-a-w c:\winnt\system32\dplaysvr.exe
+ 2008-04-14 00:12:17 29,696 —-a-w c:\winnt\system32\dplaysvr.exe
- 2004-08-03 22:56:44 229,888 —-a-w c:\winnt\system32\dplayx.dll
+ 2008-04-14 00:11:52 229,888 —-a-w c:\winnt\system32\dplayx.dll
- 2004-08-03 22:56:44 23,552 —-a-w c:\winnt\system32\dpmodemx.dll
+ 2008-04-14 00:11:52 23,552 —-a-w c:\winnt\system32\dpmodemx.dll
- 2004-08-03 22:56:04 3,584 —-a-w c:\winnt\system32\dpnaddr.dll
+ 2008-04-14 00:09:19 3,072 —-a-w c:\winnt\system32\dpnaddr.dll
- 2004-08-03 22:56:44 375,296 —-a-w c:\winnt\system32\dpnet.dll
+ 2008-04-14 00:11:52 375,296 —-a-w c:\winnt\system32\dpnet.dll
- 2004-08-03 22:56:44 35,328 —-a-w c:\winnt\system32\dpnhpast.dll
+ 2008-04-14 00:11:52 35,328 —-a-w c:\winnt\system32\dpnhpast.dll
- 2004-08-03 22:56:44 60,928 —-a-w c:\winnt\system32\dpnhupnp.dll
+ 2008-04-14 00:11:52 60,928 —-a-w c:\winnt\system32\dpnhupnp.dll
- 2004-08-03 22:56:04 3,584 —-a-w c:\winnt\system32\dpnlobby.dll
+ 2008-04-14 00:09:20 3,072 —-a-w c:\winnt\system32\dpnlobby.dll
- 2004-08-03 22:56:50 18,432 —-a-w c:\winnt\system32\dpnsvr.exe
+ 2008-04-14 00:12:17 17,920 —-a-w c:\winnt\system32\dpnsvr.exe
- 2004-08-03 22:56:44 21,504 —-a-w c:\winnt\system32\dpvacm.dll
+ 2008-04-14 00:11:52 21,504 —-a-w c:\winnt\system32\dpvacm.dll
- 2004-08-03 22:56:44 212,480 —-a-w c:\winnt\system32\dpvoice.dll
+ 2008-04-14 00:11:52 212,480 —-a-w c:\winnt\system32\dpvoice.dll
- 2004-08-03 22:56:50 83,456 —-a-w c:\winnt\system32\dpvsetup.exe
+ 2008-04-14 00:12:18 83,456 —-a-w c:\winnt\system32\dpvsetup.exe
- 2004-08-03 22:56:44 116,736 —-a-w c:\winnt\system32\dpvvox.dll
+ 2008-04-14 00:11:52 116,736 —-a-w c:\winnt\system32\dpvvox.dll
- 2004-08-03 22:56:44 57,344 —-a-w c:\winnt\system32\dpwsockx.dll
+ 2008-04-14 00:11:52 57,344 —-a-w c:\winnt\system32\dpwsockx.dll
- 2001-08-23 12:00:00 58,368 —-a-w c:\winnt\system32\driverquery.exe
+ 2008-04-14 00:12:18 62,976 —-a-w c:\winnt\system32\driverquery.exe
- 2004-08-03 23:05:44 53,248 —-a-w c:\winnt\system32\drivers\1394bus.sys
+ 2008-04-13 18:46:18 53,376 —-a-w c:\winnt\system32\drivers\1394bus.sys
- 2004-08-03 23:05:44 187,776 —-a-w c:\winnt\system32\drivers\acpi.sys
+ 2008-04-13 18:36:35 187,776 —-a-w c:\winnt\system32\drivers\acpi.sys
+ 2008-04-14 00:11:48 4,255 ——w c:\winnt\system32\drivers\adv01nt5.dll
+ 2008-04-14 00:11:48 3,967 ——w c:\winnt\system32\drivers\adv02nt5.dll
+ 2008-04-14 00:11:48 3,615 ——w c:\winnt\system32\drivers\adv05nt5.dll
+ 2008-04-14 00:11:48 3,647 ——w c:\winnt\system32\drivers\adv07nt5.dll
+ 2008-04-14 00:11:48 3,135 ——w c:\winnt\system32\drivers\adv08nt5.dll
+ 2008-04-14 00:11:48 3,711 ——w c:\winnt\system32\drivers\adv09nt5.dll
+ 2008-04-14 00:11:48 3,775 ——w c:\winnt\system32\drivers\adv11nt5.dll
- 2004-08-04 02:39:38 142,464 —-a-w c:\winnt\system32\drivers\aec.sys
+ 2008-04-13 16:39:23 142,592 —-a-w c:\winnt\system32\drivers\aec.sys
- 2008-08-14 09:51:43 138,368 —-a-w c:\winnt\system32\drivers\afd.sys
+ 2008-08-14 10:04:36 138,496 —-a-w c:\winnt\system32\drivers\afd.sys
+ 2008-04-13 18:36:38 42,368 ——w c:\winnt\system32\drivers\agp440.sys
+ 2008-04-13 18:36:39 44,928 ——w c:\winnt\system32\drivers\agpcpq.sys
+ 2008-04-13 18:36:38 42,752 ——w c:\winnt\system32\drivers\alim1541.sys
+ 2008-04-13 18:36:39 43,008 ——w c:\winnt\system32\drivers\amdagp.sys
- 2004-08-03 23:05:44 36,992 —-a-w c:\winnt\system32\drivers\amdk6.sys
+ 2008-04-13 18:31:32 37,376 —-a-w c:\winnt\system32\drivers\amdk6.sys
- 2004-08-03 23:05:44 37,376 —-a-w c:\winnt\system32\drivers\amdk7.sys
+ 2008-04-13 18:31:33 37,760 —-a-w c:\winnt\system32\drivers\amdk7.sys
- 2004-08-03 23:05:44 60,800 —-a-w c:\winnt\system32\drivers\arp1394.sys
+ 2008-04-13 18:51:25 60,800 —-a-w c:\winnt\system32\drivers\arp1394.sys
- 2004-08-03 21:05:04 14,336 —-a-w c:\winnt\system32\drivers\asyncmac.sys
+ 2008-04-13 18:57:27 14,336 —-a-w c:\winnt\system32\drivers\asyncmac.sys
- 2004-08-04 02:59:44 95,360 —-a-w c:\winnt\system32\drivers\atapi.sys
+ 2008-04-13 18:40:30 96,512 —-a-w c:\winnt\system32\drivers\atapi.sys
+ 2004-08-04 03:29:30 56,623 ——w c:\winnt\system32\drivers\ati1btxx.sys
+ 2004-08-04 03:29:30 11,615 ——w c:\winnt\system32\drivers\ati1mdxx.sys
+ 2004-08-04 03:29:30 12,047 ——w c:\winnt\system32\drivers\ati1pdxx.sys
+ 2004-08-04 03:29:32 30,671 ——w c:\winnt\system32\drivers\ati1raxx.sys
+ 2004-08-04 03:29:32 63,663 ——w c:\winnt\system32\drivers\ati1rvxx.sys
+ 2004-08-04 03:29:32 26,367 ——w c:\winnt\system32\drivers\ati1snxx.sys
+ 2004-08-04 03:29:32 21,343 ——w c:\winnt\system32\drivers\ati1ttxx.sys
+ 2004-08-04 03:29:32 36,463 ——w c:\winnt\system32\drivers\ati1tuxx.sys
+ 2004-08-04 03:29:32 29,455 ——w c:\winnt\system32\drivers\ati1xbxx.sys
+ 2004-08-04 03:29:32 34,735 ——w c:\winnt\system32\drivers\ati1xsxx.sys
+ 2004-08-04 03:29:28 327,040 ——w c:\winnt\system32\drivers\ati2mtaa.sys
+ 2004-08-04 03:29:28 701,440 ——w c:\winnt\system32\drivers\ati2mtag.sys
+ 2004-08-04 03:29:28 57,856 ——w c:\winnt\system32\drivers\atinbtxx.sys
+ 2004-08-04 03:29:30 13,824 ——w c:\winnt\system32\drivers\atinmdxx.sys
+ 2004-08-04 03:29:30 14,336 ——w c:\winnt\system32\drivers\atinpdxx.sys
+ 2004-08-04 03:29:30 52,224 ——w c:\winnt\system32\drivers\atinraxx.sys
+ 2004-08-04 03:29:32 104,960 ——w c:\winnt\system32\drivers\atinrvxx.sys
+ 2004-08-04 03:29:32 28,672 ——w c:\winnt\system32\drivers\atinsnxx.sys
+ 2004-08-04 03:29:32 13,824 ——w c:\winnt\system32\drivers\atinttxx.sys
+ 2004-08-04 03:29:32 73,216 ——w c:\winnt\system32\drivers\atintuxx.sys
+ 2004-08-04 03:29:32 31,744 ——w c:\winnt\system32\drivers\atinxbxx.sys
+ 2004-08-04 03:29:32 63,488 ——w c:\winnt\system32\drivers\atinxsxx.sys
- 2004-08-03 20:58:32 59,904 —-a-w c:\winnt\system32\drivers\atmarpc.sys
+ 2008-04-13 18:51:25 59,904 —-a-w c:\winnt\system32\drivers\atmarpc.sys
- 2004-08-03 20:58:36 55,936 —-a-w c:\winnt\system32\drivers\atmlane.sys
+ 2008-04-13 18:51:30 55,808 —-a-w c:\winnt\system32\drivers\atmlane.sys
+ 2008-04-14 00:11:50 21,183 ——w c:\winnt\system32\drivers\atv01nt5.dll
+ 2008-04-14 00:11:50 11,359 ——w c:\winnt\system32\drivers\atv02nt5.dll
+ 2008-04-14 00:11:50 25,471 ——w c:\winnt\system32\drivers\atv04nt5.dll
+ 2008-04-14 00:11:50 14,143 ——w c:\winnt\system32\drivers\atv06nt5.dll
+ 2008-04-14 00:11:50 17,279 ——w c:\winnt\system32\drivers\atv10nt5.dll
- 2001-08-17 13:57:54 14,080 —-a-w c:\winnt\system32\drivers\battc.sys
+ 2008-04-13 18:36:32 14,208 —-a-w c:\winnt\system32\drivers\battc.sys
- 2004-08-03 20:59:58 71,552 —-a-w c:\winnt\system32\drivers\bridge.sys
+ 2008-04-13 18:53:23 71,552 —-a-w c:\winnt\system32\drivers\bridge.sys
+ 2008-04-13 18:46:33 17,024 ——w c:\winnt\system32\drivers\bthenum.sys
+ 2008-04-13 18:46:33 37,888 ——w c:\winnt\system32\drivers\bthmodem.sys
+ 2008-04-13 18:51:34 101,120 ——w c:\winnt\system32\drivers\bthpan.sys
- 2008-06-13 13:10:50 272,128 ——w c:\winnt\system32\drivers\bthport.sys
+ 2008-06-13 11:05:51 272,128 ——w c:\winnt\system32\drivers\bthport.sys
+ 2008-04-13 18:46:31 36,480 ——w c:\winnt\system32\drivers\bthprint.sys
+ 2008-04-13 18:46:29 18,944 ——w c:\winnt\system32\drivers\bthusb.sys
- 2004-08-03 21:14:12 63,744 —-a-w c:\winnt\system32\drivers\cdfs.sys
+ 2008-04-13 19:14:21 63,744 —-a-w c:\winnt\system32\drivers\cdfs.sys
- 2004-08-03 23:05:44 49,536 —-a-w c:\winnt\system32\drivers\cdrom.sys
+ 2008-04-13 18:40:46 62,976 —-a-w c:\winnt\system32\drivers\cdrom.sys
+ 2008-04-14 00:11:50 15,423 ——w c:\winnt\system32\drivers\ch7xxnt5.dll
- 2004-08-03 21:14:28 49,664 —-a-w c:\winnt\system32\drivers\classpnp.sys
+ 2008-04-13 19:16:22 49,536 —-a-w c:\winnt\system32\drivers\classpnp.sys
- 2004-08-03 23:07:40 14,080 —-a-w c:\winnt\system32\drivers\CmBatt.sys
+ 2008-04-13 18:36:37 13,952 —-a-w c:\winnt\system32\drivers\cmbatt.sys
- 2001-08-17 13:58:00 9,344 —-a-w c:\winnt\system32\drivers\compbatt.sys
+ 2008-04-13 18:36:37 10,240 —-a-w c:\winnt\system32\drivers\compbatt.sys
- 2004-08-03 23:05:44 36,480 —-a-w c:\winnt\system32\drivers\crusoe.sys
+ 2008-04-13 18:31:32 36,736 —-a-w c:\winnt\system32\drivers\crusoe.sys
- 2004-08-03 23:05:44 36,352 —-a-w c:\winnt\system32\drivers\disk.sys
+ 2008-04-13 18:40:47 36,352 —-a-w c:\winnt\system32\drivers\disk.sys
- 2004-08-03 20:59:54 14,208 —-a-w c:\winnt\system32\drivers\diskdump.sys
+ 2008-04-13 18:40:44 14,208 —-a-w c:\winnt\system32\drivers\diskdump.sys
- 2004-08-03 21:07:18 799,744 —-a-w c:\winnt\system32\drivers\dmboot.sys
+ 2008-04-13 18:44:48 799,744 —-a-w c:\winnt\system32\drivers\dmboot.sys
- 2004-08-03 21:07:18 153,344 —-a-w c:\winnt\system32\drivers\dmio.sys
+ 2008-04-13 18:44:46 153,344 —-a-w c:\winnt\system32\drivers\dmio.sys
- 2004-08-04 03:07:40 52,864 —-a-w c:\winnt\system32\drivers\DMusic.sys
+ 2008-04-13 18:45:01 52,864 —-a-w c:\winnt\system32\drivers\dmusic.sys
- 2004-08-04 03:08:00 60,288 —-a-w c:\winnt\system32\drivers\drmk.sys
+ 2008-04-13 18:45:14 60,160 —-a-w c:\winnt\system32\drivers\drmk.sys
- 2004-08-04 03:07:58 2,944 —-a-w c:\winnt\system32\drivers\drmkaud.sys
+ 2008-04-13 18:45:13 2,944 —-a-w c:\winnt\system32\drivers\drmkaud.sys
- 2004-08-03 23:05:44 71,040 —-a-w c:\winnt\system32\drivers\dxg.sys
+ 2008-04-13 18:38:29 71,168 —-a-w c:\winnt\system32\drivers\dxg.sys
- 2004-08-03 21:14:18 143,360 —-a-w c:\winnt\system32\drivers\fastfat.sys
+ 2008-04-13 19:14:29 143,744 —-a-w c:\winnt\system32\drivers\fastfat.sys
- 2004-08-03 23:05:44 27,392 —-a-w c:\winnt\system32\drivers\fdc.sys
+ 2008-04-13 18:40:25 27,392 —-a-w c:\winnt\system32\drivers\fdc.sys
- 2001-08-23 12:00:00 34,944 —-a-w c:\winnt\system32\drivers\fips.sys
+ 2008-04-13 18:33:28 44,544 —-a-w c:\winnt\system32\drivers\fips.sys
- 2004-08-03 23:05:44 20,480 —-a-w c:\winnt\system32\drivers\flpydisk.sys
+ 2008-04-13 18:40:25 20,480 —-a-w c:\winnt\system32\drivers\flpydisk.sys
- 2004-08-03 21:01:20 124,800 —-a-w c:\winnt\system32\drivers\fltMgr.sys
+ 2008-04-13 18:32:59 129,792 —-a-w c:\winnt\system32\drivers\fltmgr.sys
+ 2008-04-13 18:36:40 46,464 ——w c:\winnt\system32\drivers\gagp30kx.sys
- 2005-01-07 21:07:18 138,752 —-a-w c:\winnt\system32\drivers\Hdaudbus.sys
+ 2008-04-13 16:36:05 144,384 —-a-w c:\winnt\system32\drivers\hdaudbus.sys
+ 2008-04-13 18:46:30 25,600 ——w c:\winnt\system32\drivers\hidbth.sys
- 2004-08-03 23:05:44 36,224 —-a-w c:\winnt\system32\drivers\hidclass.sys
+ 2008-04-13 18:45:26 36,864 —-a-w c:\winnt\system32\drivers\hidclass.sys
+ 2008-04-13 18:45:26 19,200 ——w c:\winnt\system32\drivers\hidir.sys
- 2004-08-03 23:05:44 24,960 —-a-w c:\winnt\system32\drivers\hidparse.sys
+ 2008-04-13 18:45:22 24,960 —-a-w c:\winnt\system32\drivers\hidparse.sys
- 2001-08-17 18:02:20 9,600 —-a-w c:\winnt\system32\drivers\hidusb.sys
+ 2008-04-13 18:45:27 10,368 —-a-w c:\winnt\system32\drivers\hidusb.sys
+ 2004-08-04 03:41:48 220,032 ——w c:\winnt\system32\drivers\hsfbs2s2.sys
+ 2004-08-04 03:41:50 685,056 ——w c:\winnt\system32\drivers\hsfcxts2.sys
+ 2004-08-04 03:41:56 1,041,536 ——w c:\winnt\system32\drivers\hsfdpsp2.sys
- 2004-08-03 23:05:44 263,040 —-a-w c:\winnt\system32\drivers\http.sys
+ 2008-04-13 18:53:53 264,832 —-a-w c:\winnt\system32\drivers\http.sys
- 2004-08-04 04:14:38 52,736 —-a-w c:\winnt\system32\drivers\i8042prt.sys
+ 2008-04-13 19:18:00 52,480 —-a-w c:\winnt\system32\drivers\i8042prt.sys
- 2004-08-03 23:05:44 41,856 —-a-w c:\winnt\system32\drivers\imapi.sys
+ 2008-04-13 18:40:58 42,112 —-a-w c:\winnt\system32\drivers\imapi.sys
- 2004-08-03 23:05:44 36,096 —-a-w c:\winnt\system32\drivers\intelppm.sys
+ 2008-04-13 18:31:32 36,352 —-a-w c:\winnt\system32\drivers\intelppm.sys
- 2004-08-03 21:00:08 29,056 —-a-w c:\winnt\system32\drivers\ip6fw.sys
+ 2008-04-13 18:53:34 36,608 —-a-w c:\winnt\system32\drivers\ip6fw.sys
- 2004-08-03 21:04:46 20,992 —-a-w c:\winnt\system32\drivers\ipinip.sys
+ 2008-04-13 18:57:07 20,864 —-a-w c:\winnt\system32\drivers\ipinip.sys
- 2004-09-29 22:28:37 134,912 —-a-w c:\winnt\system32\drivers\ipnat.sys
+ 2008-04-13 18:57:15 152,832 —-a-w c:\winnt\system32\drivers\ipnat.sys
- 2004-08-03 21:14:30 74,752 —-a-w c:\winnt\system32\drivers\ipsec.sys
+ 2008-04-13 19:19:42 75,264 —-a-w c:\winnt\system32\drivers\ipsec.sys
+ 2008-04-13 18:45:34 46,592 ——w c:\winnt\system32\drivers\irbus.sys
- 2004-08-03 21:00:48 11,264 —-a-w c:\winnt\system32\drivers\irenum.sys
+ 2008-04-13 18:54:28 11,264 —-a-w c:\winnt\system32\drivers\irenum.sys
- 2001-08-17 17:58:02 35,840 —-a-w c:\winnt\system32\drivers\isapnp.sys
+ 2008-04-13 18:36:41 37,248 —-a-w c:\winnt\system32\drivers\isapnp.sys
- 2004-08-03 23:05:44 24,576 —-a-w c:\winnt\system32\drivers\kbdclass.sys
+ 2008-04-13 18:39:47 24,576 —-a-w c:\winnt\system32\drivers\kbdclass.sys
- 2004-08-04 02:58:36 14,848 —-a-w c:\winnt\system32\drivers\kbdhid.sys
+ 2008-04-13 18:39:48 14,592 —-a-w c:\winnt\system32\drivers\kbdhid.sys
- 2004-08-04 03:07:50 171,776 —-a-w c:\winnt\system32\drivers\kmixer.sys
+ 2008-04-13 18:45:09 172,416 —-a-w c:\winnt\system32\drivers\kmixer.sys
- 2004-08-04 03:15:22 140,928 —-a-w c:\winnt\system32\drivers\ks.sys
+ 2008-04-13 19:16:36 141,056 —-a-w c:\winnt\system32\drivers\ks.sys
- 2004-08-03 20:59:48 92,032 —-a-w c:\winnt\system32\drivers\ksecdd.sys
+ 2008-04-13 18:31:43 92,288 —-a-w c:\winnt\system32\drivers\ksecdd.sys
- 2004-08-03 23:05:44 63,744 —-a-w c:\winnt\system32\drivers\mf.sys
+ 2008-04-13 18:36:41 63,744 —-a-w c:\winnt\system32\drivers\mf.sys
- 2004-08-03 23:05:44 30,080 —-a-w c:\winnt\system32\drivers\modem.sys
+ 2008-04-13 19:00:19 30,080 —-a-w c:\winnt\system32\drivers\modem.sys
- 2004-08-04 03:58:34 23,040 —-a-w c:\winnt\system32\drivers\mouclass.sys
+ 2008-04-13 18:39:47 23,040 —-a-w c:\winnt\system32\drivers\mouclass.sys
- 2004-08-03 20:58:32 42,240 —-a-w c:\winnt\system32\drivers\mountmgr.sys
+ 2008-04-13 18:39:46 42,368 —-a-w c:\winnt\system32\drivers\mountmgr.sys
- 2007-07-06 10:05:47 72,960 —-a-w c:\winnt\system32\drivers\mqac.sys
+ 2008-04-13 18:39:44 92,544 —-a-w c:\winnt\system32\drivers\mqac.sys
- 2007-12-18 09:51:35 179,584 —-a-w c:\winnt\system32\drivers\mrxdav.sys
+ 2008-04-13 18:32:44 180,608 —-a-w c:\winnt\system32\drivers\mrxdav.sys
- 2008-10-24 11:10:42 453,632 —-a-w c:\winnt\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 —-a-w c:\winnt\system32\drivers\mrxsmb.sys
- 2004-08-03 21:00:42 19,072 —-a-w c:\winnt\system32\drivers\msfs.sys
+ 2008-04-13 18:32:39 19,072 —-a-w c:\winnt\system32\drivers\msfs.sys
- 2004-08-03 21:04:14 35,072 —-a-w c:\winnt\system32\drivers\msgpc.sys
+ 2008-04-13 18:56:32 35,072 —-a-w c:\winnt\system32\drivers\msgpc.sys
- 2004-08-04 02:58:42 7,552 —-a-w c:\winnt\system32\drivers\MSKSSRV.sys
+ 2008-04-13 18:39:52 7,552 —-a-w c:\winnt\system32\drivers\mskssrv.sys
- 2004-08-04 02:58:40 5,376 —-a-w c:\winnt\system32\drivers\MSPCLOCK.sys
+ 2008-04-13 18:39:50 5,376 —-a-w c:\winnt\system32\drivers\mspclock.sys
- 2004-08-04 02:58:42 4,992 —-a-w c:\winnt\system32\drivers\MSPQM.sys
+ 2008-04-13 18:39:51 4,992 —-a-w c:\winnt\system32\drivers\mspqm.sys
- 2004-08-03 23:05:44 15,488 —-a-w c:\winnt\system32\drivers\mssmbios.sys
+ 2008-04-13 18:36:46 15,488 —-a-w c:\winnt\system32\drivers\mssmbios.sys
+ 2004-08-04 03:41:40 126,686 ——w c:\winnt\system32\drivers\mtlmnt5.sys
+ 2004-08-04 03:41:38 1,309,184 ——w c:\winnt\system32\drivers\mtlstrm.sys
+ 2004-08-04 03:29:38 452,736 ——w c:\winnt\system32\drivers\mtxparhm.sys
- 2004-08-03 21:15:22 107,904 —-a-w c:\winnt\system32\drivers\mup.sys
+ 2008-04-13 19:17:05 105,344 —-a-w c:\winnt\system32\drivers\mup.sys
+ 2008-04-13 18:43:55 12,672 ——w c:\winnt\system32\drivers\mutohpen.sys
- 2004-08-03 21:14:30 182,912 —-a-w c:\winnt\system32\drivers\ndis.sys
+ 2008-04-13 19:20:37 182,656 —-a-w c:\winnt\system32\drivers\ndis.sys
- 2001-08-23 12:00:00 9,600 —-a-w c:\winnt\system32\drivers\ndistapi.sys
+ 2008-04-13 18:57:27 10,112 —-a-w c:\winnt\system32\drivers\ndistapi.sys
- 2006-08-18 09:36:45 14,592 —-a-w c:\winnt\system32\drivers\ndisuio.sys
+ 2008-04-13 18:55:58 14,592 —-a-w c:\winnt\system32\drivers\ndisuio.sys
- 2004-08-03 21:14:32 91,776 —-a-w c:\winnt\system32\drivers\ndiswan.sys
+ 2008-04-13 19:20:42 91,520 —-a-w c:\winnt\system32\drivers\ndiswan.sys
- 2001-08-23 12:00:00 38,016 —-a-w c:\winnt\system32\drivers\ndproxy.sys
+ 2008-04-13 18:57:29 40,576 —-a-w c:\winnt\system32\drivers\ndproxy.sys
- 2004-08-03 21:03:22 34,560 —-a-w c:\winnt\system32\drivers\netbios.sys
+ 2008-04-13 18:56:02 34,688 —-a-w c:\winnt\system32\drivers\netbios.sys
- 2004-08-03 21:14:38 162,816 —-a-w c:\winnt\system32\drivers\netbt.sys
+ 2008-04-13 19:21:00 162,816 —-a-w c:\winnt\system32\drivers\netbt.sys
- 2004-08-03 23:05:44 61,824 —-a-w c:\winnt\system32\drivers\nic1394.sys
+ 2008-04-13 18:51:25 61,824 —-a-w c:\winnt\system32\drivers\nic1394.sys
- 2004-08-03 20:59:52 40,320 —-a-w c:\winnt\system32\drivers\nmnt.sys
+ 2008-04-13 18:53:09 40,320 —-a-w c:\winnt\system32\drivers\nmnt.sys
- 2004-08-03 21:00:44 30,848 —-a-w c:\winnt\system32\drivers\npfs.sys
+ 2008-04-13 18:32:39 30,848 —-a-w c:\winnt\system32\drivers\npfs.sys
- 2004-08-03 21:15:10 574,592 —-a-w c:\winnt\system32\drivers\ntfs.sys
+ 2008-04-13 19:15:53 574,976 —-a-w c:\winnt\system32\drivers\ntfs.sys
+ 2004-08-04 03:41:40 180,360 ——w c:\winnt\system32\drivers\ntmtlfax.sys
+ 2004-08-04 03:29:56 1,897,408 ——w c:\winnt\system32\drivers\nv4_mini.sys
- 2004-08-03 21:03:36 88,448 —-a-w c:\winnt\system32\drivers\nwlnkipx.sys
+ 2008-04-13 18:56:06 88,320 —-a-w c:\winnt\system32\drivers\nwlnkipx.sys
- 2006-10-13 10:23:15 163,584 —-a-w c:\winnt\system32\drivers\nwrdr.sys
+ 2008-04-13 18:34:12 163,584 —-a-w c:\winnt\system32\drivers\nwrdr.sys
- 2004-08-03 23:05:44 61,056 —-a-w c:\winnt\system32\drivers\ohci1394.sys
+ 2008-04-13 18:46:18 61,696 —-a-w c:\winnt\system32\drivers\ohci1394.sys
- 2004-08-03 23:05:44 42,496 —-a-w c:\winnt\system32\drivers\p3.sys
+ 2008-04-13 18:31:31 42,752 —-a-w c:\winnt\system32\drivers\p3.sys
- 2004-08-03 23:05:44 80,128 —-a-w c:\winnt\system32\drivers\parport.sys
+ 2008-04-13 18:40:10 80,128 —-a-w c:\winnt\system32\drivers\parport.sys
- 2001-08-23 12:00:00 18,688 —-a-w c:\winnt\system32\drivers\partmgr.sys
+ 2008-04-13 18:40:49 19,712 —-a-w c:\winnt\system32\drivers\partmgr.sys
- 2004-08-04 03:07:48 68,224 —-a-w c:\winnt\system32\drivers\pci.sys
+ 2008-04-13 18:36:44 68,224 —-a-w c:\winnt\system32\drivers\pci.sys
- 2004-08-04 02:59:42 25,088 —-a-w c:\winnt\system32\drivers\pciidex.sys
+ 2008-04-13 18:40:29 24,960 —-a-w c:\winnt\system32\drivers\pciidex.sys
- 2004-08-03 23:07:48 119,936 —-a-w c:\winnt\system32\drivers\pcmcia.sys
+ 2008-04-13 18:36:43 120,192 —-a-w c:\winnt\system32\drivers\pcmcia.sys
- 2004-03-16 14:58:20 136,960 —-a-w c:\winnt\system32\drivers\portcls.sys
+ 2008-04-13 19:19:41 146,048 —-a-w c:\winnt\system32\drivers\portcls.sys
- 2004-08-03 23:05:44 35,328 —-a-w c:\winnt\system32\drivers\processr.sys
+ 2008-04-13 18:31:30 35,840 —-a-w c:\winnt\system32\drivers\processr.sys
- 2004-08-03 21:04:20 69,120 —-a-w c:\winnt\system32\drivers\psched.sys
+ 2008-04-13 18:56:38 69,120 —-a-w c:\winnt\system32\drivers\psched.sys
- 2004-08-03 21:14:24 51,328 —-a-w c:\winnt\system32\drivers\rasl2tp.sys
+ 2008-04-13 19:19:43 51,328 —-a-w c:\winnt\system32\drivers\rasl2tp.sys
- 2004-08-03 21:05:08 41,472 —-a-w c:\winnt\system32\drivers\raspppoe.sys
+ 2008-04-13 18:57:32 41,472 —-a-w c:\winnt\system32\drivers\raspppoe.sys
- 2004-08-03 21:14:28 48,384 —-a-w c:\winnt\system32\drivers\raspptp.sys
+ 2008-04-13 19:19:48 48,384 —-a-w c:\winnt\system32\drivers\raspptp.sys
- 2006-05-05 09:47:57 174,592 —-a-w c:\winnt\system32\drivers\rdbss.sys
+ 2008-04-13 19:28:39 175,744 —-a-w c:\winnt\system32\drivers\rdbss.sys
- 2004-08-04 03:01:16 196,864 —-a-w c:\winnt\system32\drivers\rdpdr.sys
+ 2008-04-13 18:32:51 196,224 —-a-w c:\winnt\system32\drivers\rdpdr.sys
- 2005-06-10 04:09:46 139,528 —-a-w c:\winnt\system32\drivers\rdpwd.sys
+ 2008-04-14 00:13:22 139,656 —-a-w c:\winnt\system32\drivers\rdpwd.sys
+ 2004-08-04 03:41:40 13,776 ——w c:\winnt\system32\drivers\recagent.sys
- 2004-08-03 22:59:38 57,472 —-a-w c:\winnt\system32\drivers\redbook.sys
+ 2008-04-13 18:40:27 57,600 —-a-w c:\winnt\system32\drivers\redbook.sys
+ 2008-04-13 18:46:32 59,136 ——w c:\winnt\system32\drivers\rfcomm.sys
- 2008-05-08 12:28:49 202,752 —-a-w c:\winnt\system32\drivers\rmcast.sys
+ 2008-05-08 14:02:52 203,136 —-a-w c:\winnt\system32\drivers\rmcast.sys
- 2004-08-03 21:04:32 30,080 —-a-w c:\winnt\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 —-a-w c:\winnt\system32\drivers\rndismp.sys
+ 2008-04-13 18:56:49 30,592 ——w c:\winnt\system32\drivers\rndismpx.sys
+ 2004-08-04 03:29:52 166,912 ——w c:\winnt\system32\drivers\s3gnbm.sys
- 2004-08-03 23:05:44 96,256 —-a-w c:\winnt\system32\drivers\scsiport.sys
+ 2008-04-13 18:40:30 96,384 —-a-w c:\winnt\system32\drivers\scsiport.sys
- 2004-08-03 23:05:44 67,584 —-a-w c:\winnt\system32\drivers\sdbus.sys
+ 2008-04-13 18:36:44 79,232 —-a-w c:\winnt\system32\drivers\sdbus.sys
- 2004-08-03 23:05:44 15,488 —-a-w c:\winnt\system32\drivers\serenum.sys
+ 2008-04-13 18:40:12 15,744 —-a-w c:\winnt\system32\drivers\serenum.sys
- 2004-08-03 23:05:44 64,896 —-a-w c:\winnt\system32\drivers\serial.sys
+ 2008-04-13 19:15:45 64,512 —-a-w c:\winnt\system32\drivers\serial.sys
- 2004-08-03 23:05:44 11,136 —-a-w c:\winnt\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:47 11,904 —-a-w c:\winnt\system32\drivers\sffdisk.sys
+ 2008-04-13 18:40:48 10,240 ——w c:\winnt\system32\drivers\sffp_mmc.sys
- 2004-08-03 23:05:44 10,240 —-a-w c:\winnt\system32\drivers\sffp_sd.sys
+ 2008-04-13 18:40:47 11,008 —-a-w c:\winnt\system32\drivers\sffp_sd.sys
- 2004-08-03 23:05:44 11,392 —-a-w c:\winnt\system32\drivers\sfloppy.sys
+ 2008-04-13 18:40:48 11,392 —-a-w c:\winnt\system32\drivers\sfloppy.sys
+ 2008-04-14 00:12:05 3,901 ——w c:\winnt\system32\drivers\siint5.dll
+ 2008-04-13 18:36:39 40,960 ——w c:\winnt\system32\drivers\sisagp.sys
+ 2004-08-04 03:41:42 129,535 ——w c:\winnt\system32\drivers\slnt7554.sys
+ 2004-08-04 03:41:44 404,990 ——w c:\winnt\system32\drivers\slntamr.sys
+ 2004-08-04 03:41:46 95,424 ——w c:\winnt\system32\drivers\slnthal.sys
+ 2004-08-04 03:41:46 13,240 ——w c:\winnt\system32\drivers\slwdmsup.sys
+ 2008-04-13 18:36:34 5,888 ——w c:\winnt\system32\drivers\smbali.sys
- 2004-08-03 23:05:44 25,472 —-a-w c:\winnt\system32\drivers\sonydcam.sys
+ 2008-04-13 18:46:07 25,344 —-a-w c:\winnt\system32\drivers\sonydcam.sys
- 2004-08-04 03:07:48 6,400 —-a-w c:\winnt\system32\drivers\splitter.sys
+ 2008-04-13 18:45:07 6,272 —-a-w c:\winnt\system32\drivers\splitter.sys
- 2004-08-03 21:06:26 73,472 —-a-w c:\winnt\system32\drivers\sr.sys
+ 2008-04-13 18:36:52 73,472 —-a-w c:\winnt\system32\drivers\sr.sys
- 2008-12-11 11:57:21 333,184 —-a-w c:\winnt\system32\drivers\srv.sys
+ 2008-12-11 10:57:09 333,952 —-a-w c:\winnt\system32\drivers\srv.sys
- 2004-08-04 03:08:04 48,640 —-a-w c:\winnt\system32\drivers\stream.sys
+ 2008-04-13 18:45:15 49,408 —-a-w c:\winnt\system32\drivers\stream.sys
- 2004-08-03 23:05:44 4,352 —-a-w c:\winnt\system32\drivers\swenum.sys
+ 2008-04-13 18:39:53 4,352 —-a-w c:\winnt\system32\drivers\swenum.sys
- 2001-08-17 18:00:52 54,272 —-a-w c:\winnt\system32\drivers\swmidi.sys
+ 2008-04-13 18:45:09 56,576 —-a-w c:\winnt\system32\drivers\swmidi.sys
- 2004-08-04 03:15:56 60,800 —-a-w c:\winnt\system32\drivers\sysaudio.sys
+ 2008-04-13 19:15:55 60,800 —-a-w c:\winnt\system32\drivers\sysaudio.sys
- 2004-08-03 21:00:00 14,976 —-a-w c:\winnt\system32\drivers\tape.sys
+ 2008-04-13 18:40:50 14,976 —-a-w c:\winnt\system32\drivers\tape.sys
- 2008-06-20 10:45:13 360,320 —-a-w c:\winnt\system32\drivers\tcpip.sys
+ 2008-06-20 11:51:12 361,600 —-a-w c:\winnt\system32\drivers\tcpip.sys
- 2008-06-20 19:22:08 225,920 —-a-w c:\winnt\system32\drivers\tcpip6.sys
+ 2008-06-20 11:08:27 225,856 —-a-w c:\winnt\system32\drivers\tcpip6.sys
- 2004-08-03 21:07:50 18,560 —-a-w c:\winnt\system32\drivers\tdi.sys
+ 2008-04-13 19:00:05 19,072 —-a-w c:\winnt\system32\drivers\tdi.sys
- 2004-08-03 23:01:08 12,040 —-a-w c:\winnt\system32\drivers\tdpipe.sys
+ 2008-04-14 00:13:20 12,040 —-a-w c:\winnt\system32\drivers\tdpipe.sys
- 2004-08-03 23:01:08 21,896 —-a-w c:\winnt\system32\drivers\tdtcp.sys
+ 2008-04-14 00:13:21 21,896 —-a-w c:\winnt\system32\drivers\tdtcp.sys
- 2004-08-04 05:01:08 40,840 —-a-w c:\winnt\system32\drivers\termdd.sys
+ 2008-04-14 00:13:20 40,840 —-a-w c:\winnt\system32\drivers\termdd.sys
- 2004-08-03 23:05:44 12,416 —-a-w c:\winnt\system32\drivers\tunmp.sys
+ 2008-04-13 18:56:01 12,288 —-a-w c:\winnt\system32\drivers\tunmp.sys
+ 2008-04-13 18:36:40 44,672 ——w c:\winnt\system32\drivers\uagp35.sys
- 2004-08-03 21:00:32 66,176 —-a-w c:\winnt\system32\drivers\udfs.sys
+ 2008-04-13 18:32:36 66,048 —-a-w c:\winnt\system32\drivers\udfs.sys
- 2004-08-03 20:58:34 209,408 —-a-w c:\winnt\system32\drivers\update.sys
+ 2008-04-13 18:39:46 384,768 —-a-w c:\winnt\system32\drivers\update.sys
- 2004-08-03 21:04:34 12,672 —-a-w c:\winnt\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 —-a-w c:\winnt\system32\drivers\usb8023.sys
+ 2008-04-13 18:56:49 12,800 ——w c:\winnt\system32\drivers\usb8023x.sys
- 2004-08-04 04:07:56 59,264 —-a-w c:\winnt\system32\drivers\usbaudio.sys
+ 2008-04-13 18:45:12 60,032 —-a-w c:\winnt\system32\drivers\usbaudio.sys
- 2001-08-23 12:00:00 23,808 —-a-w c:\winnt\system32\drivers\usbcamd.sys
+ 2008-04-13 18:45:40 25,600 —-a-w c:\winnt\system32\drivers\usbcamd.sys
- 2001-08-23 12:00:00 23,936 —-a-w c:\winnt\system32\drivers\usbcamd2.sys
+ 2008-04-13 18:45:41 25,728 —-a-w c:\winnt\system32\drivers\usbcamd2.sys
- 2004-08-04 03:08:48 31,616 —-a-w c:\winnt\system32\drivers\usbccgp.sys
+ 2008-04-13 18:45:39 32,128 —-a-w c:\winnt\system32\drivers\usbccgp.sys
- 2005-03-31 01:13:52 27,008 —-a-w c:\winnt\system32\drivers\usbehci.sys
+ 2008-04-13 18:45:35 30,208 —-a-w c:\winnt\system32\drivers\usbehci.sys
- 2004-08-04 03:08:44 57,600 —-a-w c:\winnt\system32\drivers\usbhub.sys
+ 2008-04-13 18:45:37 59,520 —-a-w c:\winnt\system32\drivers\usbhub.sys
- 2004-08-03 23:05:44 16,000 —-a-w c:\winnt\system32\drivers\usbintel.sys
+ 2008-04-13 18:45:43 15,872 —-a-w c:\winnt\system32\drivers\usbintel.sys
- 2004-08-04 03:08:44 142,976 —-a-w c:\winnt\system32\drivers\usbport.sys
+ 2008-04-13 18:45:36 143,872 —-a-w c:\winnt\system32\drivers\usbport.sys
- 2004-08-04 03:01:26 25,856 —-a-w c:\winnt\system32\drivers\usbprint.sys
+ 2008-04-13 18:47:37 25,856 —-a-w c:\winnt\system32\drivers\usbprint.sys
- 2004-08-04 02:58:46 15,104 —-a-w c:\winnt\system32\drivers\usbscan.sys
+ 2008-04-13 18:45:34 15,104 —-a-w c:\winnt\system32\drivers\usbscan.sys
- 2004-08-04 03:08:44 25,600 —-a-w c:\winnt\system32\drivers\usbser.sys
+ 2008-04-13 18:45:36 26,112 —-a-w c:\winnt\system32\drivers\usbser.sys
- 2004-08-04 03:08:48 26,496 —-a-w c:\winnt\system32\drivers\USBSTOR.SYS
+ 2008-04-13 18:45:38 26,368 —-a-w c:\winnt\system32\drivers\usbstor.sys
- 2004-08-04 03:08:38 20,480 —-a-w c:\winnt\system32\drivers\usbuhci.sys
+ 2008-04-13 18:45:35 20,608 —-a-w c:\winnt\system32\drivers\usbuhci.sys
+ 2008-04-13 18:46:20 121,984 ——w c:\winnt\system32\drivers\usbvideo.sys
+ 2008-04-14 00:12:08 11,325 ——w c:\winnt\system32\drivers\vchnt5.dll
- 2004-08-03 21:07:08 20,992 —-a-w c:\winnt\system32\drivers\vga.sys
+ 2008-04-13 18:44:40 20,992 —-a-w c:\winnt\system32\drivers\vga.sys
+ 2008-04-13 18:36:40 42,240 ——w c:\winnt\system32\drivers\viaagp.sys
- 2004-08-03 21:07:06 79,744 —-a-w c:\winnt\system32\drivers\videoprt.sys
+ 2008-04-13 18:44:40 81,664 —-a-w c:\winnt\system32\drivers\videoprt.sys
- 2004-08-03 21:00:18 52,352 —-a-w c:\winnt\system32\drivers\volsnap.sys
+ 2008-04-13 18:41:01 52,352 —-a-w c:\winnt\system32\drivers\volsnap.sys
- 2004-08-03 21:04:58 34,560 —-a-w c:\winnt\system32\drivers\wanarp.sys
+ 2008-04-13 18:57:21 34,560 —-a-w c:\winnt\system32\drivers\wanarp.sys
- 2004-08-04 03:15:06 82,944 —-a-w c:\winnt\system32\drivers\wdmaud.sys
+ 2008-04-13 19:17:18 83,072 —-a-w c:\winnt\system32\drivers\wdmaud.sys
- 2004-08-03 23:07:42 8,832 —-a-w c:\winnt\system32\drivers\wmiacpi.sys
+ 2008-04-13 18:36:38 8,832 —-a-w c:\winnt\system32\drivers\wmiacpi.sys
- 2004-08-03 22:57:06 299,520 —-a-w c:\winnt\system32\drmclien.dll
+ 2008-04-14 00:13:00 299,520 —-a-w c:\winnt\system32\drmclien.dll
- 2004-08-03 22:56:44 87,040 —-a-w c:\winnt\system32\drmstor.dll
+ 2008-04-14 00:11:52 87,040 —-a-w c:\winnt\system32\drmstor.dll
- 2004-08-03 22:56:44 14,336 —-a-w c:\winnt\system32\drprov.dll
+ 2008-04-14 00:11:52 14,336 —-a-w c:\winnt\system32\drprov.dll
- 2004-08-03 22:56:44 16,384 —-a-w c:\winnt\system32\ds32gt.dll
+ 2008-04-14 00:11:52 16,384 —-a-w c:\winnt\system32\ds32gt.dll
- 2004-08-03 22:56:44 181,760 —-a-w c:\winnt\system32\dsdmo.dll
+ 2008-04-14 00:11:52 181,248 —-a-w c:\winnt\system32\dsdmo.dll
- 2004-08-03 22:56:44 71,680 —-a-w c:\winnt\system32\dsdmoprp.dll
+ 2008-04-14 00:11:52 71,680 —-a-w c:\winnt\system32\dsdmoprp.dll
- 2004-08-03 22:56:44 92,672 —-a-w c:\winnt\system32\dskquota.dll
+ 2008-04-14 00:11:52 92,672 —-a-w c:\winnt\system32\dskquota.dll
- 2001-08-23 12:00:00 144,384 —-a-w c:\winnt\system32\dskquoui.dll
+ 2008-04-14 00:11:52 155,648 —-a-w c:\winnt\system32\dskquoui.dll
- 2004-08-03 22:56:44 367,616 —-a-w c:\winnt\system32\dsound.dll
+ 2008-04-14 00:11:52 367,616 —-a-w c:\winnt\system32\dsound.dll
- 2004-08-03 22:56:44 1,294,336 —-a-w c:\winnt\system32\dsound3d.dll
+ 2008-04-14 00:11:52 1,293,824 —-a-w c:\winnt\system32\dsound3d.dll
- 2004-08-03 22:56:44 142,336 —-a-w c:\winnt\system32\dsprop.dll
+ 2008-04-14 00:11:52 142,848 —-a-w c:\winnt\system32\dsprop.dll
- 2004-08-03 22:56:06 4,096 —-a-w c:\winnt\system32\dsprpres.dll
+ 2008-04-13 17:09:30 4,096 —-a-w c:\winnt\system32\dsprpres.dll
- 2004-08-03 22:56:44 239,104 —-a-w c:\winnt\system32\dsquery.dll
+ 2008-04-14 00:11:52 239,104 —-a-w c:\winnt\system32\dsquery.dll
- 2004-08-03 22:56:44 51,200 —-a-w c:\winnt\system32\dssec.dll
+ 2008-04-14 00:11:52 51,200 —-a-w c:\winnt\system32\dssec.dll
- 2004-08-03 20:31:44 137,216 —-a-w c:\winnt\system32\dssenh.dll
+ 2008-04-13 17:37:57 138,752 —-a-w c:\winnt\system32\dssenh.dll
- 2004-08-03 22:56:44 113,152 —-a-w c:\winnt\system32\dsuiext.dll
+ 2008-04-14 00:11:52 113,152 —-a-w c:\winnt\system32\dsuiext.dll
- 2004-08-03 22:56:44 19,456 —-a-w c:\winnt\system32\dswave.dll
+ 2008-04-14 00:11:52 19,456 —-a-w c:\winnt\system32\dswave.dll
- 2004-08-03 22:56:50 10,752 —-a-w c:\winnt\system32\dumprep.exe
+ 2008-04-14 00:12:18 10,752 —-a-w c:\winnt\system32\dumprep.exe
- 2004-08-03 22:56:44 304,128 —-a-w c:\winnt\system32\duser.dll
+ 2008-04-14 00:11:52 304,128 —-a-w c:\winnt\system32\duser.dll
- 2004-08-03 22:56:50 17,920 —-a-w c:\winnt\system32\dvdupgrd.exe
+ 2008-04-14 00:12:18 17,920 —-a-w c:\winnt\system32\dvdupgrd.exe
- 2004-08-03 22:56:50 180,224 —-a-w c:\winnt\system32\dwwin.exe
+ 2008-04-14 00:12:18 180,224 —-a-w c:\winnt\system32\dwwin.exe
- 2004-08-03 22:56:44 619,008 —-a-w c:\winnt\system32\dx7vb.dll
+ 2008-04-14 00:11:52 619,008 —-a-w c:\winnt\system32\dx7vb.dll
- 2004-08-03 22:56:44 1,227,264 —-a-w c:\winnt\system32\dx8vb.dll
+ 2008-04-14 00:11:52 1,227,264 —-a-w c:\winnt\system32\dx8vb.dll
- 2004-08-03 22:56:50 1,298,432 —-a-w c:\winnt\system32\dxdiag.exe
+ 2008-04-14 00:12:18 1,298,432 —-a-w c:\winnt\system32\dxdiag.exe
- 2004-08-03 22:56:44 2,113,536 —-a-w c:\winnt\system32\dxdiagn.dll
+ 2008-04-14 00:11:52 2,113,536 —-a-w c:\winnt\system32\dxdiagn.dll
- 2006-08-22 08:05:26 498,742 —-a-w c:\winnt\system32\dxmasf.dll
+ 2008-04-14 00:11:52 498,742 —-a-w c:\winnt\system32\dxmasf.dll
- 2008-10-16 20:38:34 347,136 —-a-w c:\winnt\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\winnt\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 —-a-w c:\winnt\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 —-a-w c:\winnt\system32\dxtrans.dll
+ 2008-04-14 00:11:52 30,720 ——w c:\winnt\system32\eapolqec.dll
+ 2008-04-14 00:11:52 184,832 ——w c:\winnt\system32\eapp3hst.dll
+ 2008-04-14 00:11:52 126,976 ——w c:\winnt\system32\eappcfg.dll
+ 2008-04-14 00:11:52 94,208 ——w c:\winnt\system32\eappgnui.dll
+ 2008-04-14 00:11:52 180,224 ——w c:\winnt\system32\eapphost.dll
+ 2008-04-14 00:11:52 40,960 ——w c:\winnt\system32\eappprxy.dll
+ 2008-04-14 00:11:52 59,392 ——w c:\winnt\system32\eapqec.dll
+ 2008-04-14 00:11:52 33,792 ——w c:\winnt\system32\eapsvc.dll
- 2004-08-03 22:56:44 26,624 —-a-w c:\winnt\system32\efsadu.dll
+ 2008-04-14 00:11:52 26,624 —-a-w c:\winnt\system32\efsadu.dll
- 2004-08-03 22:56:44 183,296 —-a-w c:\winnt\system32\els.dll
+ 2008-04-14 00:11:53 183,296 —-a-w c:\winnt\system32\els.dll
+ 2008-04-14 00:11:57 28,672 ——w c:\winnt\system32\en\microsoft.managementconsole.resources.dll
+ 2008-04-14 00:11:57 40,960 ——w c:\winnt\system32\en\mmcex.resources.dll
+ 2008-04-14 00:11:57 6,656 ——w c:\winnt\system32\en\mmcfxcommon.resources.dll
- 2004-08-03 22:56:44 20,480 —-a-w c:\winnt\system32\encapi.dll
+ 2008-04-14 00:11:53 20,480 —-a-w c:\winnt\system32\encapi.dll
- 2004-08-03 22:56:44 186,368 —-a-w c:\winnt\system32\encdec.dll
+ 2008-04-14 00:11:53 186,880 —-a-w c:\winnt\system32\encdec.dll
- 2004-08-03 22:56:44 23,040 —-a-w c:\winnt\system32\ersvc.dll
+ 2008-04-14 00:11:53 23,040 —-a-w c:\winnt\system32\ersvc.dll
- 2008-07-07 20:32:22 253,952 —-a-w c:\winnt\system32\es.dll
+ 2008-07-07 20:26:58 253,952 —-a-w c:\winnt\system32\es.dll
- 2004-08-03 22:56:44 1,082,368 —-a-w c:\winnt\system32\esent.dll
+ 2008-04-14 00:11:53 1,082,368 —-a-w c:\winnt\system32\esent.dll
- 2004-08-03 22:56:50 193,024 —-a-w c:\winnt\system32\eudcedit.exe
+ 2008-04-14 00:12:19 193,024 —-a-w c:\winnt\system32\eudcedit.exe
- 2004-08-03 22:56:50 50,176 —-a-w c:\winnt\system32\eventcreate.exe
+ 2008-04-14 00:12:19 50,688 —-a-w c:\winnt\system32\eventcreate.exe
- 2004-08-03 22:56:44 55,808 —-a-w c:\winnt\system32\eventlog.dll
+ 2008-04-14 00:11:53 56,320 —-a-w c:\winnt\system32\eventlog.dll
- 2001-08-23 12:00:00 77,824 —-a-w c:\winnt\system32\eventtriggers.exe
+ 2008-04-14 00:12:19 82,944 —-a-w c:\winnt\system32\eventtriggers.exe
- 2004-08-03 22:56:44 380,957 —-a-w c:\winnt\system32\expsrv.dll
+ 2008-04-14 00:11:53 380,445 —-a-w c:\winnt\system32\expsrv.dll
- 2008-10-16 20:38:35 133,120 —-a-w c:\winnt\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 —-a-w c:\winnt\system32\extmgr.dll
- 2004-08-03 22:56:50 45,568 —-a-w c:\winnt\system32\extrac32.exe
+ 2008-04-14 00:12:19 24,064 —-a-w c:\winnt\system32\extrac32.exe
- 2001-08-23 12:00:00 121,856 —-a-w c:\winnt\system32\exts.dll
+ 2008-04-14 00:11:53 125,952 —-a-w c:\winnt\system32\exts.dll
- 2004-08-03 22:56:44 80,384 —-a-w c:\winnt\system32\faultrep.dll
+ 2008-04-14 00:11:53 80,384 —-a-w c:\winnt\system32\faultrep.dll
+ 2008-04-14 00:12:20 20,992 ——w c:\winnt\system32\faxpatch.exe
- 2001-08-23 12:00:00 117,760 —-a-w c:\winnt\system32\fde.dll
+ 2008-04-14 00:11:53 124,928 —-a-w c:\winnt\system32\fde.dll
- 2004-08-03 22:56:44 73,728 —-a-w c:\winnt\system32\fdeploy.dll
+ 2008-04-14 00:11:53 73,728 —-a-w c:\winnt\system32\fdeploy.dll
- 2004-08-03 22:56:44 21,504 —-a-w c:\winnt\system32\feclient.dll
+ 2008-04-14 00:11:53 21,504 —-a-w c:\winnt\system32\feclient.dll
- 2004-08-03 22:56:44 337,920 —-a-w c:\winnt\system32\filemgmt.dll
+ 2008-04-14 00:11:53 337,920 —-a-w c:\winnt\system32\filemgmt.dll
- 2004-08-03 22:56:50 27,136 —-a-w c:\winnt\system32\findstr.exe
+ 2008-04-14 00:12:20 27,136 —-a-w c:\winnt\system32\findstr.exe
- 2004-08-03 22:56:44 87,552 —-a-w c:\winnt\system32\fldrclnr.dll
+ 2008-04-14 00:11:53 87,552 —-a-w c:\winnt\system32\fldrclnr.dll
- 2004-08-03 22:56:44 16,896 —-a-w c:\winnt\system32\fltlib.dll
+ 2008-04-14 00:11:53 16,896 —-a-w c:\winnt\system32\fltlib.dll
- 2004-08-03 22:56:50 22,528 —-a-w c:\winnt\system32\fltMc.exe
+ 2008-04-14 00:12:20 23,040 —-a-w c:\winnt\system32\fltmc.exe
- 2005-03-17 18:39:58 1,146,320 —-a-w c:\winnt\system32\FM20.DLL
+ 2007-06-06 15:53:34 1,195,888 —-a-w c:\winnt\system32\FM20.DLL
- 2003-07-23 20:39:58 36,680 —-a-w c:\winnt\system32\FM20DEU.DLL
+ 2007-04-12 15:05:12 48,864 —-a-w c:\winnt\system32\FM20DEU.DLL
- 2003-07-14 21:57:04 32,584 —-a-w c:\winnt\system32\FM20ENU.DLL
+ 2007-03-23 00:17:04 35,440 —-a-w c:\winnt\system32\FM20ENU.DLL
- 2009-02-07 01:15:18 205,712 —-a-w c:\winnt\system32\FNTCACHE.DAT
+ 2009-03-06 18:28:56 205,712 —-a-w c:\winnt\system32\FNTCACHE.DAT
- 2004-08-03 22:56:44 382,976 —-a-w c:\winnt\system32\fontext.dll
+ 2008-04-14 00:11:53 382,976 —-a-w c:\winnt\system32\fontext.dll
- 2005-10-17 21:14:45 80,896 —-a-w c:\winnt\system32\fontsub.dll
+ 2008-04-14 00:11:53 80,896 —-a-w c:\winnt\system32\fontsub.dll
- 2004-08-03 22:56:50 20,992 —-a-w c:\winnt\system32\fontview.exe
+ 2008-04-14 00:12:20 20,992 —-a-w c:\winnt\system32\fontview.exe
- 2001-08-23 12:00:00 7,168 —-a-w c:\winnt\system32\forcedos.exe
+ 2008-04-14 00:12:20 7,680 —-a-w c:\winnt\system32\forcedos.exe
- 2001-08-23 12:00:00 25,600 —-a-w c:\winnt\system32\format.com
+ 2008-04-14 00:12:42 29,696 —-a-w c:\winnt\system32\format.com
- 2004-08-03 22:56:08 9,344 —-a-w c:\winnt\system32\framebuf.dll
+ 2008-04-14 00:09:33 9,344 —-a-w c:\winnt\system32\framebuf.dll
- 2004-08-03 23:05:44 193,024 —-a-w c:\winnt\system32\fsquirt.exe
+ 2008-04-14 00:12:20 193,024 —-a-w c:\winnt\system32\fsquirt.exe
- 2004-08-03 22:56:50 42,496 —-a-w c:\winnt\system32\ftp.exe
+ 2008-04-14 00:12:20 42,496 —-a-w c:\winnt\system32\ftp.exe
- 2004-08-03 22:56:44 60,416 —-a-w c:\winnt\system32\fwcfg.dll
+ 2008-04-14 00:11:53 60,416 —-a-w c:\winnt\system32\fwcfg.dll
- 2008-10-23 13:01:36 283,648 —-a-w c:\winnt\system32\gdi32.dll
+ 2008-10-23 12:36:14 286,720 —-a-w c:\winnt\system32\gdi32.dll
- 2001-08-23 12:00:00 55,296 —-a-w c:\winnt\system32\getmac.exe
+ 2008-04-14 00:12:21 59,904 —-a-w c:\winnt\system32\getmac.exe
- 2004-08-03 22:56:44 122,880 —-a-w c:\winnt\system32\glu32.dll
+ 2008-04-14 00:11:54 122,880 —-a-w c:\winnt\system32\glu32.dll
- 2004-08-03 22:56:08 566,784 —-a-w c:\winnt\system32\gpedit.dll
+ 2008-04-14 00:09:35 566,784 —-a-w c:\winnt\system32\gpedit.dll
- 2004-08-03 22:56:08 9,728 —-a-w c:\winnt\system32\gpkrsrc.dll
+ 2006-12-31 01:26:44 9,728 —-a-w c:\winnt\system32\gpkrsrc.dll
- 2004-08-03 22:56:50 119,808 —-a-w c:\winnt\system32\gpresult.exe
+ 2008-04-14 00:12:21 120,832 —-a-w c:\winnt\system32\gpresult.exe
- 2004-08-03 22:56:44 198,656 —-a-w c:\winnt\system32\gptext.dll
+ 2008-04-14 00:11:54 199,680 —-a-w c:\winnt\system32\gptext.dll
- 2004-08-03 22:56:50 39,424 —-a-w c:\winnt\system32\grpconv.exe
+ 2008-04-14 00:12:21 39,424 —-a-w c:\winnt\system32\grpconv.exe
- 2004-08-03 22:56:44 614,912 —-a-w c:\winnt\system32\h323msp.dll
+ 2008-04-14 00:11:54 614,912 —-a-w c:\winnt\system32\h323msp.dll
- 2005-09-28 23:35:25 134,272 —-a-w c:\winnt\system32\HAL.DLL
+ 2008-04-13 18:31:28 134,400 —-a-w c:\winnt\system32\HAL.DLL
- 2004-08-03 23:05:44 7,168 —-a-w c:\winnt\system32\hccoin.dll
+ 2008-04-14 00:11:54 7,168 —-a-w c:\winnt\system32\hccoin.dll
- 2001-08-23 12:00:00 14,848 —-a-w c:\winnt\system32\help.exe
+ 2008-04-14 00:12:21 15,872 —-a-w c:\winnt\system32\help.exe
- 2005-05-27 02:04:27 41,472 —-a-w c:\winnt\system32\hhsetup.dll
+ 2008-04-14 00:11:54 41,472 —-a-w c:\winnt\system32\hhsetup.dll
- 2004-08-03 23:05:44 20,992 —-a-w c:\winnt\system32\hid.dll
+ 2008-04-14 00:11:54 20,992 —-a-w c:\winnt\system32\hid.dll
- 2004-08-04 04:56:44 21,504 —-a-w c:\winnt\system32\hidserv.dll
+ 2008-04-14 00:11:54 21,504 —-a-w c:\winnt\system32\hidserv.dll
- 2006-07-21 08:24:43 72,704 —-a-w c:\winnt\system32\hlink.dll
+ 2008-04-14 00:11:54 72,704 —-a-w c:\winnt\system32\hlink.dll
- 2004-08-03 22:56:44 344,064 —-a-w c:\winnt\system32\hnetcfg.dll
+ 2008-04-14 00:11:54 344,064 —-a-w c:\winnt\system32\hnetcfg.dll
- 2004-08-03 22:56:44 330,752 —-a-w c:\winnt\system32\hnetwiz.dll
+ 2008-04-14 00:11:54 330,752 —-a-w c:\winnt\system32\hnetwiz.dll
- 2004-08-03 22:56:44 144,896 —-a-w c:\winnt\system32\hotplug.dll
+ 2008-04-14 00:11:54 144,896 —-a-w c:\winnt\system32\hotplug.dll
+ 2008-04-14 00:11:54 32,285 ——w c:\winnt\system32\hsfcisp2.dll
- 2004-08-03 22:56:44 24,576 —-a-w c:\winnt\system32\httpapi.dll
+ 2008-04-14 00:11:54 24,576 —-a-w c:\winnt\system32\httpapi.dll
- 2004-08-03 22:56:44 41,984 —-a-w c:\winnt\system32\htui.dll
+ 2008-04-14 00:11:54 41,984 —-a-w c:\winnt\system32\htui.dll
- 2004-11-17 17:41:24 347,136 —-a-w c:\winnt\system32\hypertrm.dll
+ 2008-04-14 00:11:54 347,136 —-a-w c:\winnt\system32\hypertrm.dll
- 2004-08-03 22:56:44 119,808 —-a-w c:\winnt\system32\iasrad.dll
+ 2008-04-14 00:11:54 119,808 —-a-w c:\winnt\system32\iasrad.dll
- 2004-08-03 22:56:44 11,264 —-a-w c:\winnt\system32\icaapi.dll
+ 2008-04-14 00:11:54 11,264 —-a-w c:\winnt\system32\icaapi.dll
- 2008-10-16 20:38:35 63,488 —-a-w c:\winnt\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w c:\winnt\system32\icardie.dll
- 2004-08-03 22:56:44 80,384 —-a-w c:\winnt\system32\iccvid.dll
+ 2008-04-14 00:11:54 80,384 —-a-w c:\winnt\system32\iccvid.dll
- 2005-06-29 01:46:00 254,976 —-a-w c:\winnt\system32\icm32.dll
+ 2008-04-14 00:11:54 254,976 —-a-w c:\winnt\system32\icm32.dll
- 2004-08-03 22:56:08 3,584 —-a-w c:\winnt\system32\icmp.dll
+ 2008-04-14 00:09:40 3,584 —-a-w c:\winnt\system32\icmp.dll
- 2004-08-03 22:56:44 73,728 —-a-w c:\winnt\system32\icwdial.dll
+ 2008-04-14 00:11:54 73,728 —-a-w c:\winnt\system32\icwdial.dll
- 2004-08-03 22:56:44 65,536 —-a-w c:\winnt\system32\icwphbk.dll
+ 2008-04-14 00:11:54 65,536 —-a-w c:\winnt\system32\icwphbk.dll
- 2004-08-03 22:56:44 120,832 —-a-w c:\winnt\system32\idq.dll
+ 2008-04-14 00:11:54 120,832 —-a-w c:\winnt\system32\idq.dll
- 2008-10-16 13:11:09 70,656 —-a-w c:\winnt\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 —-a-w c:\winnt\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 —-a-w c:\winnt\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\winnt\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 —-a-w c:\winnt\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\winnt\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 —-a-w c:\winnt\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\winnt\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 —-a-w c:\winnt\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w c:\winnt\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 —-a-w c:\winnt\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\winnt\system32\iedkcs32.dll
- 2007-08-13 23:45:18 78,336 —-a-w c:\winnt\system32\ieencode.dll
+ 2008-04-14 00:11:54 81,920 —-a-w c:\winnt\system32\ieencode.dll
- 2008-10-16 20:38:37 6,066,176 —-a-w c:\winnt\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w c:\winnt\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 —-a-w c:\winnt\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 —-a-w c:\winnt\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 —-a-w c:\winnt\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\winnt\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 —-a-w c:\winnt\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w c:\winnt\system32\ieudinit.exe
- 2004-08-03 22:56:52 114,688 —-a-w c:\winnt\system32\iexpress.exe
+ 2008-04-14 00:12:22 114,688 —-a-w c:\winnt\system32\iexpress.exe
- 2004-08-03 22:56:44 135,680 —-a-w c:\winnt\system32\ifmon.dll
+ 2008-04-14 00:11:54 135,680 —-a-w c:\winnt\system32\ifmon.dll
- 2004-08-03 22:56:44 8,192 —-a-w c:\winnt\system32\igmpagnt.dll
+ 2008-04-14 00:11:54 8,192 —-a-w c:\winnt\system32\igmpagnt.dll
- 2004-08-03 22:56:44 81,920 —-a-w c:\winnt\system32\ils.dll
+ 2008-04-14 00:11:54 81,920 —-a-w c:\winnt\system32\ils.dll
- 2004-08-03 22:56:44 144,384 —-a-w c:\winnt\system32\imagehlp.dll
+ 2008-04-14 00:11:54 144,384 —-a-w c:\winnt\system32\imagehlp.dll
- 2004-08-03 22:56:52 150,016 —-a-w c:\winnt\system32\imapi.exe
+ 2008-04-14 00:12:22 150,528 —-a-w c:\winnt\system32\imapi.exe
- 2004-08-03 22:56:44 36,921 —-a-w c:\winnt\system32\imeshare.dll
+ 2008-04-14 00:11:54 36,921 —-a-w c:\winnt\system32\imeshare.dll
- 2004-08-03 22:56:44 110,080 —-a-w c:\winnt\system32\imm32.dll
+ 2008-04-14 00:11:54 110,080 —-a-w c:\winnt\system32\imm32.dll
- 2004-08-03 22:56:44 274,432 —-a-w c:\winnt\system32\inetcfg.dll
+ 2008-04-14 00:11:54 274,432 —-a-w c:\winnt\system32\inetcfg.dll
- 2008-04-11 18:50:43 683,520 —-a-w c:\winnt\system32\inetcomm.dll
+ 2008-04-11 19:04:26 691,712 —-a-w c:\winnt\system32\inetcomm.dll
- 2004-08-03 22:56:44 33,280 —-a-w c:\winnt\system32\inetmib1.dll
+ 2008-04-14 00:11:55 32,768 —-a-w c:\winnt\system32\inetmib1.dll
- 2004-08-03 22:56:44 75,264 —-a-w c:\winnt\system32\inetpp.dll
+ 2008-04-14 00:11:55 75,264 —-a-w c:\winnt\system32\inetpp.dll
- 2004-08-03 22:56:44 15,872 —-a-w c:\winnt\system32\inetppui.dll
+ 2008-04-14 00:11:55 15,872 —-a-w c:\winnt\system32\inetppui.dll
- 2004-08-03 22:56:10 48,128 —-a-w c:\winnt\system32\inetres.dll
+ 2008-04-13 16:22:12 48,128 —-a-w c:\winnt\system32\inetres.dll
- 2004-08-03 22:56:42 29,696 —-a-w c:\winnt\system32\inetsrv\admexs.dll
+ 2008-04-14 00:11:48 29,696 —-a-w c:\winnt\system32\inetsrv\admexs.dll
- 2004-08-03 22:56:42 108,544 —-a-w c:\winnt\system32\inetsrv\AppConf.dll
+ 2008-04-14 00:11:49 108,544 —-a-w c:\winnt\system32\inetsrv\appconf.dll
- 2004-08-03 22:56:50 42,496 —-a-w c:\winnt\system32\inetsrv\davcdata.exe
+ 2008-04-14 00:12:16 42,496 —-a-w c:\winnt\system32\inetsrv\davcdata.exe
- 2004-08-03 22:56:44 268,288 —-a-w c:\winnt\system32\inetsrv\httpext.dll
+ 2008-04-14 00:11:54 268,288 —-a-w c:\winnt\system32\inetsrv\httpext.dll
- 2004-08-03 22:56:44 25,088 —-a-w c:\winnt\system32\inetsrv\iisadmin.dll
+ 2008-04-14 00:11:54 25,088 —-a-w c:\winnt\system32\inetsrv\iisadmin.dll
- 2004-08-03 22:56:44 145,408 —-a-w c:\winnt\system32\inetsrv\iischema.dll
+ 2008-04-14 00:11:54 145,408 —-a-w c:\winnt\system32\inetsrv\iischema.dll
- 2004-08-03 22:56:44 7,168 —-a-w c:\winnt\system32\inetsrv\iisfecnv.dll
+ 2008-04-14 00:11:54 7,168 —-a-w c:\winnt\system32\inetsrv\iisfecnv.dll
- 2004-08-03 22:56:44 79,872 —-a-w c:\winnt\system32\inetsrv\iislog.dll
+ 2008-04-14 00:11:54 79,872 —-a-w c:\winnt\system32\inetsrv\iislog.dll
- 2004-08-03 22:56:52 15,872 —-a-w c:\winnt\system32\inetsrv\inetinfo.exe
+ 2008-04-14 00:12:22 15,360 —-a-w c:\winnt\system32\inetsrv\inetinfo.exe
- 2004-08-03 22:56:44 257,024 —-a-w c:\winnt\system32\inetsrv\infocomm.dll
+ 2008-04-14 00:11:55 257,024 —-a-w c:\winnt\system32\inetsrv\infocomm.dll
- 2004-08-03 22:56:44 26,624 —-a-w c:\winnt\system32\inetsrv\iscomlog.dll
+ 2008-04-14 00:11:55 26,624 —-a-w c:\winnt\system32\inetsrv\iscomlog.dll
- 2004-08-03 22:56:44 13,312 —-a-w c:\winnt\system32\inetsrv\lonsint.dll
+ 2008-04-14 00:11:56 13,312 —-a-w c:\winnt\system32\inetsrv\lonsint.dll
- 2004-08-03 22:56:44 85,504 —-a-w c:\winnt\system32\inetsrv\metadata.dll
+ 2008-04-14 00:11:56 85,504 —-a-w c:\winnt\system32\inetsrv\metadata.dll
- 2004-08-03 22:56:46 44,544 —-a-w c:\winnt\system32\inetsrv\nsepm.dll
+ 2008-04-14 00:12:02 44,544 —-a-w c:\winnt\system32\inetsrv\nsepm.dll
- 2004-08-03 22:56:46 4,096 —-a-w c:\winnt\system32\inetsrv\rpcref.dll
+ 2008-04-14 00:12:04 4,096 —-a-w c:\winnt\system32\inetsrv\rpcref.dll
+ 2008-04-14 00:12:05 221,696 ——w c:\winnt\system32\inetsrv\seo.dll
+ 2008-04-14 00:12:06 189,440 ——w c:\winnt\system32\inetsrv\smtpadm.dll
+ 2008-04-14 00:12:06 2,134,528 ——w c:\winnt\system32\inetsrv\smtpsnap.dll
- 2004-08-03 22:56:48 103,424 —-a-w c:\winnt\system32\inetsrv\uihelper.dll
+ 2008-04-14 00:12:07 103,424 —-a-w c:\winnt\system32\inetsrv\uihelper.dll
- 2004-08-03 22:56:44 147,456 —-a-w c:\winnt\system32\initpki.dll
+ 2008-04-14 00:11:55 147,456 —-a-w c:\winnt\system32\initpki.dll
- 2004-08-03 22:56:44 123,392 —-a-w c:\winnt\system32\input.dll
+ 2008-04-14 00:11:55 123,392 —-a-w c:\winnt\system32\input.dll
- 2004-08-03 22:56:52 55,808 —-a-w c:\winnt\system32\ipconfig.exe
+ 2008-04-14 00:12:22 55,808 —-a-w c:\winnt\system32\ipconfig.exe
- 2006-05-19 12:59:41 94,720 —-a-w c:\winnt\system32\iphlpapi.dll
+ 2008-04-14 00:11:55 94,720 —-a-w c:\winnt\system32\iphlpapi.dll
- 2001-08-23 12:00:00 154,112 —-a-w c:\winnt\system32\ipmontr.dll
+ 2008-04-14 00:11:55 161,280 —-a-w c:\winnt\system32\ipmontr.dll
- 2004-08-03 22:56:44 331,264 —-a-w c:\winnt\system32\ipnathlp.dll
+ 2008-04-14 00:11:55 331,264 —-a-w c:\winnt\system32\ipnathlp.dll
- 2004-08-03 22:56:44 330,752 —-a-w c:\winnt\system32\ippromon.dll
+ 2008-04-14 00:11:55 330,752 —-a-w c:\winnt\system32\ippromon.dll
- 2001-08-23 12:00:00 169,984 —-a-w c:\winnt\system32\iprtrmgr.dll
+ 2008-04-14 00:11:55 177,152 —-a-w c:\winnt\system32\iprtrmgr.dll
- 2004-08-03 22:56:44 349,696 —-a-w c:\winnt\system32\ipsecsnp.dll
+ 2008-04-14 00:11:55 349,696 —-a-w c:\winnt\system32\ipsecsnp.dll
- 2004-08-03 22:56:44 182,784 —-a-w c:\winnt\system32\ipsecsvc.dll
+ 2008-04-14 00:11:55 183,808 —-a-w c:\winnt\system32\ipsecsvc.dll
- 2004-08-03 22:56:44 384,000 —-a-w c:\winnt\system32\ipsmsnap.dll
+ 2008-04-14 00:11:55 384,000 —-a-w c:\winnt\system32\ipsmsnap.dll
- 2004-08-03 22:56:52 53,248 —-a-w c:\winnt\system32\ipv6.exe
+ 2008-04-14 00:12:23 53,248 —-a-w c:\winnt\system32\ipv6.exe
- 2004-08-03 22:56:44 59,904 —-a-w c:\winnt\system32\ipv6mon.dll
+ 2008-04-14 00:11:55 59,904 —-a-w c:\winnt\system32\ipv6mon.dll
- 2004-08-03 22:56:52 23,552 —-a-w c:\winnt\system32\ipxroute.exe
+ 2008-04-14 00:12:23 23,552 —-a-w c:\winnt\system32\ipxroute.exe
- 2001-08-23 12:00:00 20,992 —-a-w c:\winnt\system32\ipxwan.dll
+ 2008-04-14 00:11:55 22,016 —-a-w c:\winnt\system32\ipxwan.dll
- 2004-08-03 22:56:44 120,320 —-a-w c:\winnt\system32\ir41_qc.dll
+ 2008-04-14 00:11:55 120,320 —-a-w c:\winnt\system32\ir41_qc.dll
- 2004-08-03 22:56:44 338,432 —-a-w c:\winnt\system32\ir41_qcx.dll
+ 2008-04-14 00:11:55 338,432 —-a-w c:\winnt\system32\ir41_qcx.dll
- 2004-08-03 22:56:44 755,200 —-a-w c:\winnt\system32\ir50_32.dll
+ 2008-04-14 00:11:55 755,200 —-a-w c:\winnt\system32\ir50_32.dll
- 2004-08-03 22:56:44 200,192 —-a-w c:\winnt\system32\ir50_qc.dll
+ 2008-04-14 00:11:55 200,192 —-a-w c:\winnt\system32\ir50_qc.dll
- 2004-08-03 22:56:44 183,808 —-a-w c:\winnt\system32\ir50_qcx.dll
+ 2008-04-14 00:11:55 183,808 —-a-w c:\winnt\system32\ir50_qcx.dll
- 2004-08-03 22:56:44 81,920 —-a-w c:\winnt\system32\isign32.dll
+ 2008-04-14 00:11:55 81,920 —-a-w c:\winnt\system32\isign32.dll
- 2004-08-03 22:56:44 32,768 —-a-w c:\winnt\system32\isrdbg32.dll
+ 2008-04-14 00:11:55 32,768 —-a-w c:\winnt\system32\isrdbg32.dll
- 2005-05-27 02:04:27 155,136 —-a-w c:\winnt\system32\itircl.dll
+ 2008-04-14 00:11:55 155,136 —-a-w c:\winnt\system32\itircl.dll
- 2005-05-27 02:04:27 137,216 —-a-w c:\winnt\system32\itss.dll
+ 2008-04-14 00:11:55 138,240 —-a-w c:\winnt\system32\itss.dll
- 2004-08-03 22:56:44 54,272 —-a-w c:\winnt\system32\ixsso.dll
+ 2008-04-14 00:11:55 54,272 —-a-w c:\winnt\system32\ixsso.dll
- 2004-08-03 23:05:44 47,616 —-a-w c:\winnt\system32\iyuv_32.dll
+ 2008-04-14 00:11:55 47,616 —-a-w c:\winnt\system32\iyuv_32.dll
- 2006-06-01 18:47:07 163,840 —-a-w c:\winnt\system32\jgdw400.dll
+ 2008-04-14 00:11:55 163,840 —-a-w c:\winnt\system32\jgdw400.dll
- 2006-06-01 18:47:07 27,648 —-a-w c:\winnt\system32\jgpl400.dll
+ 2008-04-14 00:11:55 27,648 —-a-w c:\winnt\system32\jgpl400.dll
- 2007-08-13 23:38:04 491,520 —-a-w c:\winnt\system32\jscript.dll
+ 2008-05-09 10:53:39 512,000 —-a-w c:\winnt\system32\jscript.dll
- 2008-10-16 20:38:37 27,648 —-a-w c:\winnt\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 —-a-w c:\winnt\system32\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\system32\kbdbhc.dll
- 2004-08-03 22:56:12 7,168 —-a-w c:\winnt\system32\kbdfi1.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\winnt\system32\kbdfi1.dll
- 2004-08-03 22:56:12 6,144 —-a-w c:\winnt\system32\kbdinbe1.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\winnt\system32\kbdinbe1.dll
- 2004-08-03 22:56:12 6,656 —-a-w c:\winnt\system32\kbdinben.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\winnt\system32\kbdinben.dll
- 2004-08-03 22:56:12 6,656 —-a-w c:\winnt\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,656 —-a-w c:\winnt\system32\kbdinmal.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\system32\kbdiultn.dll
- 2004-08-03 22:56:12 5,632 —-a-w c:\winnt\system32\kbdmaori.dll
+ 2008-04-14 00:09:55 5,632 —-a-w c:\winnt\system32\kbdmaori.dll
- 2004-08-03 22:56:12 6,144 —-a-w c:\winnt\system32\kbdmlt47.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\winnt\system32\kbdmlt47.dll
- 2004-08-03 22:56:12 6,144 —-a-w c:\winnt\system32\kbdmlt48.dll
+ 2008-04-14 00:09:55 6,144 —-a-w c:\winnt\system32\kbdmlt48.dll
- 2001-08-23 12:00:00 7,168 —-a-w c:\winnt\system32\kbdnec.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\winnt\system32\kbdnec.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\system32\kbdnepr.dll
- 2004-08-03 22:56:12 7,168 —-a-w c:\winnt\system32\kbdno1.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\winnt\system32\kbdno1.dll
+ 2008-04-14 00:09:55 6,144 ——w c:\winnt\system32\kbdpash.dll
- 2004-08-03 22:56:12 7,680 —-a-w c:\winnt\system32\kbdsmsfi.dll
+ 2008-04-14 00:09:55 7,680 —-a-w c:\winnt\system32\kbdsmsfi.dll
- 2004-08-03 22:56:12 7,680 —-a-w c:\winnt\system32\kbdsmsno.dll
+ 2008-04-14 00:09:55 7,680 —-a-w c:\winnt\system32\kbdsmsno.dll
- 2004-08-03 22:56:12 7,168 —-a-w c:\winnt\system32\kbdukx.dll
+ 2008-04-14 00:09:55 7,168 —-a-w c:\winnt\system32\kbdukx.dll
- 2004-08-03 20:59:24 7,424 —-a-w c:\winnt\system32\kd1394.dll
+ 2008-04-13 18:31:35 7,424 —-a-w c:\winnt\system32\kd1394.dll
- 2005-06-15 17:49:30 295,936 —-a-w c:\winnt\system32\kerberos.dll
+ 2008-04-14 00:11:56 299,520 —-a-w c:\winnt\system32\kerberos.dll
- 2007-04-16 15:52:53 984,576 —-a-w c:\winnt\system32\kernel32.dll
+ 2008-04-14 00:11:56 989,696 —-a-w c:\winnt\system32\kernel32.dll
- 2004-08-03 22:56:44 150,528 —-a-w c:\winnt\system32\keymgr.dll
+ 2008-04-14 00:11:56 150,528 —-a-w c:\winnt\system32\keymgr.dll
+ 2008-04-14 00:11:56 61,440 ——w c:\winnt\system32\kmsvc.dll
- 2004-08-04 04:56:44 4,096 —-a-w c:\winnt\system32\ksuser.dll
+ 2008-04-14 00:11:56 4,096 —-a-w c:\winnt\system32\ksuser.dll
+ 2008-04-14 00:11:56 37,376 ——w c:\winnt\system32\l2gpstore.dll
+ 2008-09-06 04:30:06 1,480,232 —-a-w c:\winnt\system32\LegitCheckControl.dll
- 2004-08-03 22:56:44 423,936 —-a-w c:\winnt\system32\licdll.dll
+ 2008-04-14 10:41:58 423,936 —-a-w c:\winnt\system32\licdll.dll
- 2004-08-03 22:56:44 58,880 —-a-w c:\winnt\system32\licwmi.dll
+ 2008-04-14 00:11:56 58,880 —-a-w c:\winnt\system32\licwmi.dll
- 2005-09-01 01:41:53 19,968 —-a-w c:\winnt\system32\linkinfo.dll
+ 2008-04-14 00:11:56 19,968 —-a-w c:\winnt\system32\linkinfo.dll
- 2004-08-03 22:56:44 13,824 —-a-w c:\winnt\system32\lmhsvc.dll
+ 2008-04-14 00:11:56 13,824 —-a-w c:\winnt\system32\lmhsvc.dll
- 2004-08-03 22:56:44 399,872 —-a-w c:\winnt\system32\lmrt.dll
+ 2008-04-14 00:11:56 399,872 —-a-w c:\winnt\system32\lmrt.dll
- 2004-08-03 22:56:44 97,280 —-a-w c:\winnt\system32\loadperf.dll
+ 2008-04-14 00:11:56 97,280 —-a-w c:\winnt\system32\loadperf.dll
- 2004-08-03 22:56:44 221,696 —-a-w c:\winnt\system32\localsec.dll
+ 2008-04-14 00:11:56 221,696 —-a-w c:\winnt\system32\localsec.dll
- 2004-08-03 22:56:44 341,504 —-a-w c:\winnt\system32\localspl.dll
+ 2008-04-14 00:11:56 343,040 —-a-w c:\winnt\system32\localspl.dll
- 2004-08-03 22:56:44 11,776 —-a-w c:\winnt\system32\localui.dll
+ 2008-04-14 00:11:56 11,776 —-a-w c:\winnt\system32\localui.dll
- 2004-08-03 22:56:52 75,264 —-a-w c:\winnt\system32\locator.exe
+ 2008-04-14 00:12:24 75,264 —-a-w c:\winnt\system32\locator.exe
- 2004-08-03 22:56:52 59,392 —-a-w c:\winnt\system32\logman.exe
+ 2008-04-14 00:12:24 59,392 —-a-w c:\winnt\system32\logman.exe
- 2004-08-03 22:56:58 220,672 —-a-w c:\winnt\system32\logon.scr
+ 2008-04-14 00:12:43 220,672 —-a-w c:\winnt\system32\logon.scr
- 2004-08-03 22:56:52 514,560 —-a-w c:\winnt\system32\logonui.exe
+ 2008-04-14 00:12:24 514,560 —-a-w c:\winnt\system32\logonui.exe
- 2004-08-03 22:56:44 22,016 —-a-w c:\winnt\system32\lpk.dll
+ 2008-04-14 00:11:56 22,016 —-a-w c:\winnt\system32\lpk.dll
- 2004-08-03 22:56:44 10,240 —-a-w c:\winnt\system32\lprhelp.dll
+ 2008-04-14 00:11:56 10,240 —-a-w c:\winnt\system32\lprhelp.dll
- 2007-11-07 09:50:47 727,040 —-a-w c:\winnt\system32\lsasrv.dll
+ 2008-04-14 00:11:56 728,064 —-a-w c:\winnt\system32\lsasrv.dll
- 2004-08-03 22:56:52 13,312 —-a-w c:\winnt\system32\lsass.exe
+ 2008-04-14 00:12:24 13,312 —-a-w c:\winnt\system32\lsass.exe
- 2004-08-03 22:56:52 72,704 —-a-w c:\winnt\system32\magnify.exe
+ 2008-04-14 00:12:24 72,704 —-a-w c:\winnt\system32\magnify.exe
- 2004-08-03 22:56:52 85,504 —-a-w c:\winnt\system32\makecab.exe
+ 2008-04-14 00:12:25 57,344 —-a-w c:\winnt\system32\makecab.exe
- 2004-08-03 22:56:44 14,848 —-a-w c:\winnt\system32\mcastmib.dll
+ 2008-04-14 00:11:56 14,336 —-a-w c:\winnt\system32\mcastmib.dll
- 2004-08-03 22:56:44 84,480 —-a-w c:\winnt\system32\mciavi32.dll
+ 2008-04-14 00:11:56 84,480 —-a-w c:\winnt\system32\mciavi32.dll
- 2004-08-03 22:56:44 35,328 —-a-w c:\winnt\system32\mciqtz32.dll
+ 2008-04-14 00:11:56 35,328 —-a-w c:\winnt\system32\mciqtz32.dll
- 2004-08-03 22:56:44 23,040 —-a-w c:\winnt\system32\mciseq.dll
+ 2008-04-14 00:11:56 23,040 —-a-w c:\winnt\system32\mciseq.dll
- 2004-08-03 22:56:44 23,552 —-a-w c:\winnt\system32\mciwave.dll
+ 2008-04-14 00:11:56 23,552 —-a-w c:\winnt\system32\mciwave.dll
- 2004-08-03 22:56:44 118,272 —-a-w c:\winnt\system32\mdminst.dll
+ 2008-04-14 00:11:56 118,272 —-a-w c:\winnt\system32\mdminst.dll
- 2007-03-08 15:36:28 40,960 —-a-w c:\winnt\system32\mf3216.dll
+ 2008-04-14 00:11:56 40,960 —-a-w c:\winnt\system32\mf3216.dll
- 2006-11-01 19:17:45 927,504 —-a-w c:\winnt\system32\mfc40u.dll
+ 2008-04-14 00:11:56 927,504 —-a-w c:\winnt\system32\mfc40u.dll
- 2004-08-03 22:56:44 1,028,096 —-a-w c:\winnt\system32\mfc42.dll
+ 2008-04-14 00:11:56 1,028,096 —-a-w c:\winnt\system32\mfc42.dll
- 2004-08-03 22:56:44 22,528 —-a-w c:\winnt\system32\mfcsubs.dll
+ 2008-04-14 00:11:56 22,528 —-a-w c:\winnt\system32\mfcsubs.dll
- 2004-08-03 22:56:44 14,848 —-a-w c:\winnt\system32\mgmtapi.dll
+ 2008-04-14 00:11:56 14,848 —-a-w c:\winnt\system32\mgmtapi.dll
+ 2008-04-14 00:11:57 184,320 ——w c:\winnt\system32\microsoft.managementconsole.dll
- 2004-08-03 22:56:44 18,944 —-a-w c:\winnt\system32\midimap.dll
+ 2008-04-14 00:11:57 18,944 —-a-w c:\winnt\system32\midimap.dll
- 2004-08-03 22:56:44 60,928 —-a-w c:\winnt\system32\miglibnt.dll
+ 2008-04-14 00:11:57 60,928 —-a-w c:\winnt\system32\miglibnt.dll
- 2008-03-07 16:56:41 29,696 —-a-w c:\winnt\system32\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 —-a-w c:\winnt\system32\mimefilt.dll
- 2004-08-03 22:56:44 586,240 —-a-w c:\winnt\system32\mlang.dll
+ 2008-04-14 00:11:57 586,240 —-a-w c:\winnt\system32\mlang.dll
- 2004-08-03 22:56:52 815,104 —-a-w c:\winnt\system32\mmc.exe
+ 2008-04-14 00:12:25 1,414,656 —-a-w c:\winnt\system32\mmc.exe
- 2004-08-03 22:56:44 70,656 —-a-w c:\winnt\system32\mmcbase.dll
+ 2008-04-14 00:11:57 163,328 —-a-w c:\winnt\system32\mmcbase.dll
+ 2008-04-14 00:11:57 397,312 ——w c:\winnt\system32\mmcex.dll
+ 2008-04-14 00:11:57 106,496 ——w c:\winnt\system32\mmcfxcommon.dll
- 2004-08-03 22:56:44 1,192,960 —-a-w c:\winnt\system32\mmcndmgr.dll
+ 2008-04-14 00:11:57 1,872,896 —-a-w c:\winnt\system32\mmcndmgr.dll
+ 2008-04-14 00:12:25 33,792 ——w c:\winnt\system32\mmcperf.exe
- 2004-08-03 22:56:44 50,688 —-a-w c:\winnt\system32\mmcshext.dll
+ 2008-04-14 00:11:57 61,440 —-a-w c:\winnt\system32\mmcshext.dll
- 2004-08-03 22:56:44 17,408 —-a-w c:\winnt\system32\mmfutil.dll
+ 2008-04-14 00:11:57 17,408 —-a-w c:\winnt\system32\mmfutil.dll
- 2004-08-03 22:56:44 34,560 —-a-w c:\winnt\system32\mnmdd.dll
+ 2008-04-14 00:11:57 34,560 —-a-w c:\winnt\system32\mnmdd.dll
- 2004-08-03 22:56:52 32,768 —-a-w c:\winnt\system32\mnmsrvc.exe
+ 2008-04-14 00:12:25 32,768 —-a-w c:\winnt\system32\mnmsrvc.exe
- 2004-08-03 22:56:44 207,360 —-a-w c:\winnt\system32\mobsync.dll
+ 2008-04-14 00:11:57 207,360 —-a-w c:\winnt\system32\mobsync.dll
- 2004-08-03 22:56:52 143,360 —-a-w c:\winnt\system32\mobsync.exe
+ 2008-04-14 00:12:26 143,360 —-a-w c:\winnt\system32\mobsync.exe
- 2004-08-03 22:56:44 153,600 —-a-w c:\winnt\system32\modemui.dll
+ 2008-04-14 00:11:57 153,600 —-a-w c:\winnt\system32\modemui.dll
- 2001-08-23 12:00:00 15,872 —-a-w c:\winnt\system32\more.com
+ 2008-04-14 00:12:42 16,896 —-a-w c:\winnt\system32\more.com
- 2004-08-03 22:56:12 216,064 —-a-w c:\winnt\system32\moricons.dll
+ 2008-04-13 16:45:30 216,064 —-a-w c:\winnt\system32\moricons.dll
- 2004-08-03 22:56:54 123,392 —-a-w c:\winnt\system32\mplay32.exe
+ 2008-04-14 00:12:27 123,392 —-a-w c:\winnt\system32\mplay32.exe
- 2004-08-03 22:56:44 59,904 —-a-w c:\winnt\system32\mpr.dll
+ 2008-04-14 00:11:57 59,904 —-a-w c:\winnt\system32\mpr.dll
- 2004-08-03 22:56:44 87,040 —-a-w c:\winnt\system32\mprapi.dll
+ 2008-04-14 00:11:57 87,040 —-a-w c:\winnt\system32\mprapi.dll
- 2001-08-23 12:00:00 49,152 —-a-w c:\winnt\system32\mprdim.dll
+ 2008-04-14 00:11:57 53,248 —-a-w c:\winnt\system32\mprdim.dll
- 2007-07-06 12:46:59 138,240 —-a-w c:\winnt\system32\mqad.dll
+ 2008-04-14 00:11:57 138,240 —-a-w c:\winnt\system32\mqad.dll
- 2004-08-03 22:56:54 19,968 —-a-w c:\winnt\system32\mqbkup.exe
+ 2008-04-14 00:12:27 19,968 —-a-w c:\winnt\system32\mqbkup.exe
- 2007-07-06 12:46:59 47,104 —-a-w c:\winnt\system32\mqdscli.dll
+ 2008-04-14 00:11:57 47,616 —-a-w c:\winnt\system32\mqdscli.dll
- 2007-07-06 12:46:59 16,896 —-a-w c:\winnt\system32\mqise.dll
+ 2008-04-14 00:11:57 16,896 —-a-w c:\winnt\system32\mqise.dll
- 2004-08-03 22:56:44 89,088 —-a-w c:\winnt\system32\mqlogmgr.dll
+ 2008-04-14 00:11:57 89,088 —-a-w c:\winnt\system32\mqlogmgr.dll
- 2004-08-03 22:56:44 225,280 —-a-w c:\winnt\system32\mqoa.dll
+ 2008-04-14 00:11:57 225,280 —-a-w c:\winnt\system32\mqoa.dll
- 2007-07-06 12:46:59 660,992 —-a-w c:\winnt\system32\mqqm.dll
+ 2008-04-14 00:11:57 663,040 —-a-w c:\winnt\system32\mqqm.dll
- 2007-07-06 12:46:59 177,152 —-a-w c:\winnt\system32\mqrt.dll
+ 2008-04-14 00:11:57 177,152 —-a-w c:\winnt\system32\mqrt.dll
- 2004-08-03 22:56:44 123,392 —-a-w c:\winnt\system32\mqrtdep.dll
+ 2008-04-14 00:11:57 123,904 —-a-w c:\winnt\system32\mqrtdep.dll
- 2007-07-06 12:46:59 95,744 —-a-w c:\winnt\system32\mqsec.dll
+ 2008-04-14 00:11:57 95,744 —-a-w c:\winnt\system32\mqsec.dll
- 2004-08-03 22:56:44 517,632 —-a-w c:\winnt\system32\mqsnap.dll
+ 2008-04-14 00:11:58 517,632 —-a-w c:\winnt\system32\mqsnap.dll
- 2004-08-03 22:56:54 4,608 —-a-w c:\winnt\system32\mqsvc.exe
+ 2008-04-14 00:12:27 4,608 —-a-w c:\winnt\system32\mqsvc.exe
- 2004-08-03 22:56:54 117,248 —-a-w c:\winnt\system32\mqtgsvc.exe
+ 2008-04-14 00:12:27 117,248 —-a-w c:\winnt\system32\mqtgsvc.exe
- 2004-08-03 22:56:44 186,880 —-a-w c:\winnt\system32\mqtrig.dll
+ 2008-04-14 00:11:58 187,392 —-a-w c:\winnt\system32\mqtrig.dll
- 2007-07-06 12:46:59 48,640 —-a-w c:\winnt\system32\mqupgrd.dll
+ 2008-04-14 00:11:58 49,152 —-a-w c:\winnt\system32\mqupgrd.dll
- 2007-07-06 12:46:59 471,552 —-a-w c:\winnt\system32\mqutil.dll
+ 2008-04-14 00:11:58 471,552 —-a-w c:\winnt\system32\mqutil.dll
+ 2009-02-12 01:56:18 21,244,872 —-a-w c:\winnt\system32\MRT.exe
- 2004-08-03 22:56:44 71,680 —-a-w c:\winnt\system32\msacm32.dll
+ 2008-04-14 00:11:58 71,680 —-a-w c:\winnt\system32\msacm32.dll
- 2004-08-03 22:56:14 3,584 —-a-w c:\winnt\system32\msafd.dll
+ 2008-04-14 00:10:06 3,584 —-a-w c:\winnt\system32\msafd.dll
- 2004-08-03 22:56:44 86,016 —-a-w c:\winnt\system32\msapsspc.dll
+ 2008-04-14 00:11:58 86,016 —-a-w c:\winnt\system32\msapsspc.dll
- 2004-08-03 22:56:44 57,344 —-a-w c:\winnt\system32\msasn1.dll
+ 2008-04-14 00:11:58 57,344 —-a-w c:\winnt\system32\msasn1.dll
- 2008-06-24 16:23:05 74,240 —-a-w c:\winnt\system32\mscms.dll
+ 2008-06-24 16:43:16 74,240 —-a-w c:\winnt\system32\mscms.dll
- 2004-08-03 22:56:44 69,632 —-a-w c:\winnt\system32\msconf.dll
+ 2008-04-14 00:11:58 69,632 —-a-w c:\winnt\system32\msconf.dll
- 2004-08-03 22:56:14 12,288 —-a-w c:\winnt\system32\mscpx32r.dLL
+ 2008-04-13 17:26:07 12,288 —-a-w c:\winnt\system32\mscpx32r.dll
- 2004-08-03 22:56:44 36,864 —-a-w c:\winnt\system32\mscpxl32.dLL
+ 2008-04-14 00:11:58 36,864 —-a-w c:\winnt\system32\mscpxl32.dll
- 2004-08-03 22:56:44 294,400 —-a-w c:\winnt\system32\MSCTF.dll
+ 2008-04-14 00:11:58 297,984 —-a-w c:\winnt\system32\msctf.dll
- 2004-08-03 22:56:44 69,120 —-a-w c:\winnt\system32\MSCTFP.dll
+ 2008-04-14 00:11:58 68,608 —-a-w c:\winnt\system32\msctfp.dll
- 2004-08-03 22:56:44 118,784 —-a-w c:\winnt\system32\msdadiag.dll
+ 2008-04-14 00:11:58 118,784 —-a-w c:\winnt\system32\msdadiag.dll
- 2004-08-03 22:56:44 151,552 —-a-w c:\winnt\system32\msdart.dll
+ 2008-04-14 00:11:59 151,552 —-a-w c:\winnt\system32\msdart.dll
- 2004-08-03 22:56:44 14,336 —-a-w c:\winnt\system32\msdmo.dll
+ 2008-04-14 00:11:59 14,336 —-a-w c:\winnt\system32\msdmo.dll
- 2004-08-03 22:56:54 6,144 —-a-w c:\winnt\system32\msdtc.exe
+ 2008-04-14 00:12:27 6,144 —-a-w c:\winnt\system32\msdtc.exe
- 2004-08-03 22:56:44 58,880 —-a-w c:\winnt\system32\msdtclog.dll
+ 2008-04-14 00:11:59 58,880 —-a-w c:\winnt\system32\msdtclog.dll
- 2006-03-01 19:42:42 426,496 —-a-w c:\winnt\system32\msdtcprx.dll
+ 2008-04-14 00:11:59 427,008 —-a-w c:\winnt\system32\msdtcprx.dll
- 2006-03-01 19:42:42 956,416 —-a-w c:\winnt\system32\msdtctm.dll
+ 2008-04-14 00:11:59 956,928 —-a-w c:\winnt\system32\msdtctm.dll
- 2006-03-01 19:42:42 161,280 —-a-w c:\winnt\system32\msdtcuiu.dll
+ 2008-04-14 00:11:59 161,792 —-a-w c:\winnt\system32\msdtcuiu.dll
- 2004-08-03 22:56:14 4,126 —-a-w c:\winnt\system32\msdxmlc.dll
+ 2008-04-14 00:10:08 4,126 —-a-w c:\winnt\system32\msdxmlc.dll
- 2008-10-16 20:38:37 459,264 —-a-w c:\winnt\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w c:\winnt\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 —-a-w c:\winnt\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\winnt\system32\msfeedsbs.dll
- 2006-11-27 14:54:06 539,136 —-a-w c:\winnt\system32\msftedit.dll
+ 2008-04-14 00:11:59 539,136 —-a-w c:\winnt\system32\msftedit.dll
- 2004-08-03 22:56:44 994,304 —-a-w c:\winnt\system32\msgina.dll
+ 2008-04-14 00:11:59 997,376 —-a-w c:\winnt\system32\msgina.dll
- 2004-08-03 22:56:44 33,792 —-a-w c:\winnt\system32\msgsvc.dll
+ 2008-04-14 00:11:59 33,792 —-a-w c:\winnt\system32\msgsvc.dll
- 2004-08-03 22:56:58 188,416 —-a-w c:\winnt\system32\msh261.drv
+ 2008-04-14 00:12:45 188,416 —-a-w c:\winnt\system32\msh261.drv
- 2004-08-03 23:05:44 294,912 —-a-w c:\winnt\system32\msh263.drv
+ 2008-04-14 00:12:45 294,912 —-a-w c:\winnt\system32\msh263.drv
- 2008-12-13 06:40:02 3,593,216 —-a-w c:\winnt\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w c:\winnt\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 —-a-w c:\winnt\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\winnt\system32\mshtmled.dll
- 2007-06-26 05:53:38 2,854,912 —-a-w c:\winnt\system32\msi.dll
+ 2008-04-14 00:11:59 2,843,136 —-a-w c:\winnt\system32\msi.dll
- 2004-08-03 22:56:44 51,712 —-a-w c:\winnt\system32\msident.dll
+ 2008-04-14 00:11:59 51,712 —-a-w c:\winnt\system32\msident.dll
- 2004-08-03 22:56:44 6,656 —-a-w c:\winnt\system32\msidle.dll
+ 2008-04-14 00:11:59 6,656 —-a-w c:\winnt\system32\msidle.dll
- 2004-08-03 22:56:44 248,832 —-a-w c:\winnt\system32\msieftp.dll
+ 2008-04-14 00:11:59 248,832 —-a-w c:\winnt\system32\msieftp.dll
- 2005-05-03 16:58:36 78,848 —-a-w c:\winnt\system32\msiexec.exe
+ 2008-04-14 00:12:28 78,848 —-a-w c:\winnt\system32\msiexec.exe
- 2005-05-03 16:58:36 271,360 —-a-w c:\winnt\system32\msihnd.dll
+ 2008-04-14 00:11:59 271,360 —-a-w c:\winnt\system32\msihnd.dll
- 2004-08-03 22:56:44 4,608 —-a-w c:\winnt\system32\msimg32.dll
+ 2008-04-14 00:11:59 4,608 —-a-w c:\winnt\system32\msimg32.dll
- 2005-05-03 16:58:36 884,736 —-a-w c:\winnt\system32\msimsg.dll
+ 2008-04-13 15:39:43 884,736 —-a-w c:\winnt\system32\msimsg.dll
- 2004-08-03 22:56:44 159,232 —-a-w c:\winnt\system32\MSIMTF.dll
+ 2008-04-14 00:11:59 159,232 —-a-w c:\winnt\system32\msimtf.dll
- 2005-05-03 16:58:36 15,360 —-a-w c:\winnt\system32\msisip.dll
+ 2008-04-14 00:11:59 15,360 —-a-w c:\winnt\system32\msisip.dll
- 2008-03-26 08:09:15 151,583 —-a-w c:\winnt\system32\msjint40.dll
+ 2008-04-14 00:12:00 151,583 —-a-w c:\winnt\system32\msjint40.dll
- 2004-08-03 22:56:44 25,088 —-a-w c:\winnt\system32\mslbui.dll
+ 2008-04-14 00:12:00 25,088 —-a-w c:\winnt\system32\mslbui.dll
- 2004-08-03 22:56:44 290,816 —-a-w c:\winnt\system32\msnsspc.dll
+ 2008-04-14 00:12:00 290,816 —-a-w c:\winnt\system32\msnsspc.dll
- 2004-08-03 22:56:44 252,928 —-a-w c:\winnt\system32\msoeacct.dll
+ 2008-04-14 00:12:00 252,928 —-a-w c:\winnt\system32\msoeacct.dll
- 2004-08-03 22:56:44 105,984 —-a-w c:\winnt\system32\msoert2.dll
+ 2008-04-14 00:12:00 105,984 —-a-w c:\winnt\system32\msoert2.dll
- 2004-08-03 22:56:20 20,480 —-a-w c:\winnt\system32\msorc32r.dll
+ 2008-04-13 17:24:14 20,480 —-a-w c:\winnt\system32\msorc32r.dll
- 2004-08-03 22:56:44 143,360 —-a-w c:\winnt\system32\msorcl32.dll
+ 2008-04-14 00:12:00 143,360 —-a-w c:\winnt\system32\msorcl32.dll
- 2004-08-03 22:56:54 343,040 —-a-w c:\winnt\system32\mspaint.exe
+ 2008-04-14 00:12:28 343,040 —-a-w c:\winnt\system32\mspaint.exe
- 2004-08-03 22:56:44 30,208 —-a-w c:\winnt\system32\mspatcha.dll
+ 2008-04-14 00:12:00 29,696 —-a-w c:\winnt\system32\mspatcha.dll
- 2004-08-03 22:56:20 48,128 —-a-w c:\winnt\system32\msprivs.dll
+ 2008-04-13 16:23:31 48,128 —-a-w c:\winnt\system32\msprivs.dll
- 2008-10-16 20:38:38 193,024 —-a-w c:\winnt\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 —-a-w c:\winnt\system32\msrating.dll
- 2004-08-03 22:56:44 11,264 —-a-w c:\winnt\system32\msrle32.dll
+ 2008-04-14 00:12:00 11,264 —-a-w c:\winnt\system32\msrle32.dll
- 2004-08-03 22:56:44 134,656 —-a-w c:\winnt\system32\mssap.dll
+ 2008-04-14 00:12:00 134,656 —-a-w c:\winnt\system32\mssap.dll
- 2006-10-19 02:47:16 414,208 —-a-w c:\winnt\system32\msscp.dll
+ 2006-12-04 21:21:50 414,720 —-a-w c:\winnt\system32\msscp.dll
+ 2008-04-14 00:12:00 155,136 ——w c:\winnt\system32\mssha.dll
+ 2008-04-13 18:14:58 76,800 ——w c:\winnt\system32\msshavmsg.dll
- 2004-08-03 22:56:44 274,944 —-a-w c:\winnt\system32\mstask.dll
+ 2008-04-14 00:12:00 274,944 —-a-w c:\winnt\system32\mstask.dll
- 2008-10-16 20:38:39 671,232 —-a-w c:\winnt\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\winnt\system32\mstime.dll
- 2004-08-03 22:56:54 12,288 —-a-w c:\winnt\system32\mstinit.exe
+ 2008-04-14 00:12:29 12,288 —-a-w c:\winnt\system32\mstinit.exe
- 2004-08-03 22:56:44 115,712 —-a-w c:\winnt\system32\mstlsapi.dll
+ 2008-04-14 00:12:00 116,224 —-a-w c:\winnt\system32\mstlsapi.dll
- 2004-08-03 20:59:42 407,552 —-a-w c:\winnt\system32\mstsc.exe
+ 2008-04-14 00:12:23 677,888 —-a-w c:\winnt\system32\mstsc.exe
- 2004-08-03 20:59:44 655,360 —-a-w c:\winnt\system32\mstscax.dll
+ 2008-04-14 00:11:56 2,061,824 —-a-w c:\winnt\system32\mstscax.dll
- 2004-08-03 22:56:44 195,072 —-a-w c:\winnt\system32\msutb.dll
+ 2008-04-14 00:12:00 195,072 —-a-w c:\winnt\system32\msutb.dll
- 2004-08-03 22:56:44 129,536 —-a-w c:\winnt\system32\msv1_0.dll
+ 2008-04-14 00:12:00 132,608 —-a-w c:\winnt\system32\msv1_0.dll
- 2004-08-03 22:56:44 1,392,671 —-a-w c:\winnt\system32\msvbvm60.dll
+ 2008-04-14 00:12:00 1,384,479 —-a-w c:\winnt\system32\msvbvm60.dll
- 2004-08-03 22:56:44 54,784 —-a-w c:\winnt\system32\msvcirt.dll
+ 2008-04-14 00:12:01 57,344 —-a-w c:\winnt\system32\msvcirt.dll
- 2004-08-03 22:56:44 413,696 —-a-w c:\winnt\system32\msvcp60.dll
+ 2008-04-14 00:12:01 413,696 —-a-w c:\winnt\system32\msvcp60.dll
- 2004-08-03 22:56:44 343,040 —-a-w c:\winnt\system32\msvcrt.dll
+ 2008-04-14 00:12:01 343,040 —-a-w c:\winnt\system32\msvcrt.dll
- 2004-08-03 20:58:26 61,440 —-a-w c:\winnt\system32\msvcrt40.dll
+ 2008-04-13 18:30:46 61,440 —-a-w c:\winnt\system32\msvcrt40.dll
- 2004-08-03 22:56:44 120,832 —-a-w c:\winnt\system32\msvfw32.dll
+ 2008-04-14 00:12:01 121,344 —-a-w c:\winnt\system32\msvfw32.dll
- 2004-08-03 22:56:44 1,428,480 —-a-w c:\winnt\system32\msvidctl.dll
+ 2008-04-14 00:12:01 1,428,992 —-a-w c:\winnt\system32\msvidctl.dll
- 2004-08-03 22:56:44 72,704 —-a-w c:\winnt\system32\msw3prt.dll
+ 2008-04-14 00:12:01 72,704 —-a-w c:\winnt\system32\msw3prt.dll
- 2004-08-03 22:56:46 204,288 —-a-w c:\winnt\system32\mswebdvd.dll
+ 2008-04-14 00:12:01 203,776 —-a-w c:\winnt\system32\mswebdvd.dll
- 2008-06-20 17:41:10 245,248 —-a-w c:\winnt\system32\mswsock.dll
+ 2008-06-20 17:46:57 245,248 —-a-w c:\winnt\system32\mswsock.dll
- 2004-08-03 22:56:46 506,368 —-a-w c:\winnt\system32\msxml.dll
+ 2008-04-14 00:12:01 506,368 —-a-w c:\winnt\system32\msxml.dll
- 2004-08-03 22:56:46 701,440 —-a-w c:\winnt\system32\msxml2.dll
+ 2008-04-14 00:12:01 701,440 —-a-w c:\winnt\system32\msxml2.dll
- 2008-09-04 16:42:02 1,106,944 —-a-w c:\winnt\system32\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 —-a-w c:\winnt\system32\msxml3.dll
- 2006-10-19 17:33:20 86,728 —-a-w c:\winnt\system32\msxml6r.dll
+ 2008-04-13 17:27:18 79,872 —-a-w c:\winnt\system32\msxml6r.dll
- 2004-08-03 23:05:44 17,408 —-a-w c:\winnt\system32\msyuv.dll
+ 2008-04-14 00:12:01 16,896 —-a-w c:\winnt\system32\msyuv.dll
- 2006-03-01 19:42:42 66,560 —-a-w c:\winnt\system32\mtxclu.dll
+ 2008-04-14 00:12:01 66,560 —-a-w c:\winnt\system32\mtxclu.dll
- 2001-08-23 12:00:00 20,480 —-a-w c:\winnt\system32\mtxdm.dll
+ 2008-04-14 00:12:01 30,720 —-a-w c:\winnt\system32\mtxdm.dll
- 2001-08-23 12:00:00 4,096 —-a-w c:\winnt\system32\mtxex.dll
+ 2008-04-14 00:12:01 4,096 —-a-w c:\winnt\system32\mtxex.dll
- 2001-08-23 12:00:00 25,088 —-a-w c:\winnt\system32\mtxlegih.dll
+ 2008-04-14 00:12:01 34,304 —-a-w c:\winnt\system32\mtxlegih.dll
- 2006-03-01 19:42:42 91,136 —-a-w c:\winnt\system32\mtxoci.dll
+ 2008-04-14 00:12:01 91,648 —-a-w c:\winnt\system32\mtxoci.dll
+ 2008-04-14 00:12:01 1,737,856 ——w c:\winnt\system32\mtxparhd.dll
- 2004-08-03 22:56:22 393,728 —-a-w c:\winnt\system32\mui\0401\xpob2res.dll
+ 2008-04-13 18:40:07 393,728 —-a-w c:\winnt\system32\mui\0401\xpob2res.dll
- 2004-08-03 22:56:30 186,880 —-a-w c:\winnt\system32\mui\0401\xpsp1res.dll
+ 2008-04-13 18:35:06 186,880 —-a-w c:\winnt\system32\mui\0401\xpsp1res.dll
- 2004-08-03 22:56:30 2,869,248 —-a-w c:\winnt\system32\mui\0401\xpsp2res.dll
+ 2008-04-13 18:35:49 2,869,248 —-a-w c:\winnt\system32\mui\0401\xpsp2res.dll
+ 2008-04-13 18:39:02 656,896 ——w c:\winnt\system32\mui\0401\xpsp3res.dll
- 2004-08-03 22:56:30 189,440 —-a-w c:\winnt\system32\mui\0402\xpsp1res.dll
+ 2008-04-13 18:35:08 189,440 —-a-w c:\winnt\system32\mui\0402\xpsp1res.dll
- 2004-08-03 22:56:22 212,480 —-a-w c:\winnt\system32\mui\0404\xpob2res.dll
+ 2008-04-13 18:40:23 212,480 —-a-w c:\winnt\system32\mui\0404\xpob2res.dll
- 2004-08-03 22:56:30 161,280 —-a-w c:\winnt\system32\mui\0404\xpsp1res.dll
+ 2008-04-13 18:35:09 161,280 —-a-w c:\winnt\system32\mui\0404\xpsp1res.dll
- 2004-08-03 22:56:30 477,696 —-a-w c:\winnt\system32\mui\0404\xpsp2res.dll
+ 2008-04-13 18:36:10 477,696 —-a-w c:\winnt\system32\mui\0404\xpsp2res.dll
+ 2008-04-13 18:39:13 327,680 ——w c:\winnt\system32\mui\0404\xpsp3res.dll
- 2004-08-03 22:56:22 428,032 —-a-w c:\winnt\system32\mui\0405\xpob2res.dll
+ 2008-04-13 18:40:24 428,032 —-a-w c:\winnt\system32\mui\0405\xpob2res.dll
- 2004-08-03 22:56:30 188,928 —-a-w c:\winnt\system32\mui\0405\xpsp1res.dll
+ 2008-04-13 18:35:09 188,928 —-a-w c:\winnt\system32\mui\0405\xpsp1res.dll
- 2004-08-03 22:56:30 734,720 —-a-w c:\winnt\system32\mui\0405\xpsp2res.dll
+ 2008-04-13 18:36:10 734,720 —-a-w c:\winnt\system32\mui\0405\xpsp2res.dll
+ 2008-04-13 18:39:02 601,088 ——w c:\winnt\system32\mui\0405\xpsp3res.dll
- 2004-08-03 22:56:22 418,816 —-a-w c:\winnt\system32\mui\0406\xpob2res.dll
+ 2008-04-13 18:40:27 418,816 —-a-w c:\winnt\system32\mui\0406\xpob2res.dll
- 2004-08-03 22:56:30 192,512 —-a-w c:\winnt\system32\mui\0406\xpsp1res.dll
+ 2008-04-13 18:35:09 192,000 —-a-w c:\winnt\system32\mui\0406\xpsp1res.dll
- 2004-08-03 22:56:30 742,912 —-a-w c:\winnt\system32\mui\0406\xpsp2res.dll
+ 2008-04-13 18:36:10 742,912 —-a-w c:\winnt\system32\mui\0406\xpsp2res.dll
+ 2008-04-13 18:39:12 605,696 ——w c:\winnt\system32\mui\0406\xpsp3res.dll
- 2004-08-03 22:56:22 403,456 —-a-w c:\winnt\system32\mui\0407\xpob2res.dll
+ 2008-04-13 18:40:34 403,456 —-a-w c:\winnt\system32\mui\0407\xpob2res.dll
- 2004-08-03 22:56:30 199,680 —-a-w c:\winnt\system32\mui\0407\xpsp1res.dll
+ 2008-04-13 18:35:21 199,680 —-a-w c:\winnt\system32\mui\0407\xpsp1res.dll
- 2004-08-03 22:56:30 788,992 —-a-w c:\winnt\system32\mui\0407\xpsp2res.dll
+ 2008-04-13 18:37:03 788,480 —-a-w c:\winnt\system32\mui\0407\xpsp2res.dll
+ 2008-04-13 18:39:19 663,552 ——w c:\winnt\system32\mui\0407\xpsp3res.dll
- 2004-08-03 22:56:22 419,328 —-a-w c:\winnt\system32\mui\0408\xpob2res.dll
+ 2008-04-13 18:40:30 419,328 —-a-w c:\winnt\system32\mui\0408\xpob2res.dll
- 2004-08-03 22:56:30 197,632 —-a-w c:\winnt\system32\mui\0408\xpsp1res.dll
+ 2008-04-13 18:35:11 197,632 —-a-w c:\winnt\system32\mui\0408\xpsp1res.dll
- 2004-08-03 22:56:30 801,280 —-a-w c:\winnt\system32\mui\0408\xpsp2res.dll
+ 2008-04-13 18:36:35 801,280 —-a-w c:\winnt\system32\mui\0408\xpsp2res.dll
+ 2008-04-13 18:39:12 679,936 ——w c:\winnt\system32\mui\0408\xpsp3res.dll
- 2004-08-03 22:56:22 405,504 —-a-w c:\winnt\system32\mui\040b\xpob2res.dll
+ 2008-04-13 18:40:32 405,504 —-a-w c:\winnt\system32\mui\040b\xpob2res.dll
- 2004-08-03 22:56:30 186,368 —-a-w c:\winnt\system32\mui\040b\xpsp1res.dll
+ 2008-04-13 18:35:11 186,368 —-a-w c:\winnt\system32\mui\040b\xpsp1res.dll
- 2004-08-03 22:56:30 729,088 —-a-w c:\winnt\system32\mui\040b\xpsp2res.dll
+ 2008-04-13 18:36:39 729,088 —-a-w c:\winnt\system32\mui\040b\xpsp2res.dll
+ 2008-04-13 18:39:17 604,672 ——w c:\winnt\system32\mui\040b\xpsp3res.dll
- 2004-08-03 22:56:24 410,624 —-a-w c:\winnt\system32\mui\040C\xpob2res.dll
+ 2008-04-13 18:40:33 410,624 —-a-w c:\winnt\system32\mui\040C\xpob2res.dll
- 2004-08-03 22:56:30 197,632 —-a-w c:\winnt\system32\mui\040C\xpsp1res.dll
+ 2008-04-13 18:35:20 197,632 —-a-w c:\winnt\system32\mui\040C\xpsp1res.dll
- 2004-08-03 22:56:30 793,600 —-a-w c:\winnt\system32\mui\040C\xpsp2res.dll
+ 2008-04-13 18:36:55 793,088 —-a-w c:\winnt\system32\mui\040C\xpsp2res.dll
+ 2008-04-13 18:39:20 663,040 ——w c:\winnt\system32\mui\040C\xpsp3res.dll
- 2004-08-03 22:56:24 384,000 —-a-w c:\winnt\system32\mui\040D\xpob2res.dll
+ 2008-04-13 18:40:32 384,000 —-a-w c:\winnt\system32\mui\040D\xpob2res.dll
- 2004-08-03 22:56:30 181,760 —-a-w c:\winnt\system32\mui\040D\xpsp1res.dll
+ 2008-04-13 18:35:21 181,760 —-a-w c:\winnt\system32\mui\040D\xpsp1res.dll
- 2005-09-28 09:33:06 2,842,112 —-a-w c:\winnt\system32\mui\040D\xpsp2res.dll
+ 2008-04-13 18:37:07 2,842,112 —-a-w c:\winnt\system32\mui\040D\xpsp2res.dll
+ 2008-04-13 18:39:28 620,544 ——w c:\winnt\system32\mui\040D\xpsp3res.dll
- 2004-08-03 22:56:24 434,176 —-a-w c:\winnt\system32\mui\040e\xpob2res.dll
+ 2008-04-13 18:40:39 434,176 —-a-w c:\winnt\system32\mui\040e\xpob2res.dll
- 2004-08-03 22:56:30 195,584 —-a-w c:\winnt\system32\mui\040e\xpsp1res.dll
+ 2008-04-13 18:35:23 195,584 —-a-w c:\winnt\system32\mui\040e\xpsp1res.dll
- 2004-08-03 22:56:30 769,536 —-a-w c:\winnt\system32\mui\040e\xpsp2res.dll
+ 2008-04-13 18:37:22 769,536 —-a-w c:\winnt\system32\mui\040e\xpsp2res.dll
+ 2008-04-13 18:39:28 645,120 ——w c:\winnt\system32\mui\040e\xpsp3res.dll
- 2004-08-03 22:56:24 413,696 —-a-w c:\winnt\system32\mui\0410\xpob2res.dll
+ 2008-04-13 18:40:39 413,696 —-a-w c:\winnt\system32\mui\0410\xpob2res.dll
- 2004-08-03 22:56:30 195,072 —-a-w c:\winnt\system32\mui\0410\xpsp1res.dll
+ 2008-04-13 18:35:23 195,072 —-a-w c:\winnt\system32\mui\0410\xpsp1res.dll
- 2004-08-03 22:56:30 769,536 —-a-w c:\winnt\system32\mui\0410\xpsp2res.dll
+ 2008-04-13 18:37:22 769,536 —-a-w c:\winnt\system32\mui\0410\xpsp2res.dll
+ 2008-04-13 18:39:28 658,432 ——w c:\winnt\system32\mui\0410\xpsp3res.dll
- 2004-08-03 22:56:24 275,456 —-a-w c:\winnt\system32\mui\0411\xpob2res.dll
+ 2008-04-13 18:40:44 275,456 —-a-w c:\winnt\system32\mui\0411\xpob2res.dll
- 2004-08-03 22:56:30 171,008 —-a-w c:\winnt\system32\mui\0411\xpsp1res.dll
+ 2008-04-13 18:35:23 171,008 —-a-w c:\winnt\system32\mui\0411\xpsp1res.dll
- 2004-08-03 22:56:30 562,688 —-a-w c:\winnt\system32\mui\0411\xpsp2res.dll
+ 2008-04-13 18:37:34 562,688 —-a-w c:\winnt\system32\mui\0411\xpsp2res.dll
+ 2008-04-13 18:39:49 412,672 ——w c:\winnt\system32\mui\0411\xpsp3res.dll
- 2004-08-03 22:56:24 306,688 —-a-w c:\winnt\system32\mui\0412\xpob2res.dll
+ 2008-04-13 18:40:48 306,688 —-a-w c:\winnt\system32\mui\0412\xpob2res.dll
- 2004-08-03 22:56:30 167,936 —-a-w c:\winnt\system32\mui\0412\xpsp1res.dll
+ 2008-04-13 18:35:23 167,936 —-a-w c:\winnt\system32\mui\0412\xpsp1res.dll
- 2004-08-03 22:56:30 543,744 —-a-w c:\winnt\system32\mui\0412\xpsp2res.dll
+ 2008-04-13 18:37:37 543,744 —-a-w c:\winnt\system32\mui\0412\xpsp2res.dll
+ 2008-04-13 18:39:49 392,704 ——w c:\winnt\system32\mui\0412\xpsp3res.dll
- 2004-08-03 22:56:24 401,920 —-a-w c:\winnt\system32\mui\0413\xpob2res.dll
+ 2008-04-13 18:40:44 401,920 —-a-w c:\winnt\system32\mui\0413\xpob2res.dll
- 2004-08-03 22:56:30 196,096 —-a-w c:\winnt\system32\mui\0413\xpsp1res.dll
+ 2008-04-13 18:35:25 196,096 —-a-w c:\winnt\system32\mui\0413\xpsp1res.dll
- 2004-08-03 22:56:30 769,024 —-a-w c:\winnt\system32\mui\0413\xpsp2res.dll
+ 2008-04-13 18:38:00 769,024 —-a-w c:\winnt\system32\mui\0413\xpsp2res.dll
+ 2008-04-13 18:39:47 645,120 ——w c:\winnt\system32\mui\0413\xpsp3res.dll
- 2004-08-03 22:56:24 353,792 —-a-w c:\winnt\system32\mui\0414\xpob2res.dll
+ 2008-04-13 18:40:44 353,792 —-a-w c:\winnt\system32\mui\0414\xpob2res.dll
- 2004-08-03 22:56:30 189,440 —-a-w c:\winnt\system32\mui\0414\xpsp1res.dll
+ 2008-04-13 18:35:25 189,440 —-a-w c:\winnt\system32\mui\0414\xpsp1res.dll
- 2004-08-03 22:56:30 716,288 —-a-w c:\winnt\system32\mui\0414\xpsp2res.dll
+ 2008-04-13 18:38:02 716,288 —-a-w c:\winnt\system32\mui\0414\xpsp2res.dll
+ 2008-04-13 18:39:48 591,872 ——w c:\winnt\system32\mui\0414\xpsp3res.dll
- 2004-08-03 22:56:24 391,680 —-a-w c:\winnt\system32\mui\0415\xpob2res.dll
+ 2008-04-13 18:40:47 391,680 —-a-w c:\winnt\system32\mui\0415\xpob2res.dll
- 2004-08-03 22:56:30 194,560 —-a-w c:\winnt\system32\mui\0415\xpsp1res.dll
+ 2008-04-13 18:35:26 194,560 —-a-w c:\winnt\system32\mui\0415\xpsp1res.dll
- 2004-08-03 22:56:30 759,808 —-a-w c:\winnt\system32\mui\0415\xpsp2res.dll
+ 2008-04-13 18:38:05 759,808 —-a-w c:\winnt\system32\mui\0415\xpsp2res.dll
+ 2008-04-13 18:39:52 641,024 ——w c:\winnt\system32\mui\0415\xpsp3res.dll
- 2004-08-03 22:56:24 409,600 —-a-w c:\winnt\system32\mui\0416\xpob2res.dll
+ 2008-04-13 18:40:10 409,600 —-a-w c:\winnt\system32\mui\0416\xpob2res.dll
- 2004-08-03 22:56:30 192,512 —-a-w c:\winnt\system32\mui\0416\xpsp1res.dll
+ 2008-04-13 18:35:08 192,512 —-a-w c:\winnt\system32\mui\0416\xpsp1res.dll
- 2004-08-03 22:56:30 752,128 —-a-w c:\winnt\system32\mui\0416\xpsp2res.dll
+ 2008-04-13 18:35:43 752,128 —-a-w c:\winnt\system32\mui\0416\xpsp2res.dll
+ 2008-04-13 18:38:56 620,032 ——w c:\winnt\system32\mui\0416\xpsp3res.dll
- 2004-08-03 22:56:30 190,464 —-a-w c:\winnt\system32\mui\0418\xpsp1res.dll
+ 2008-04-13 18:35:27 190,464 —-a-w c:\winnt\system32\mui\0418\xpsp1res.dll
- 2004-08-03 22:56:24 427,008 —-a-w c:\winnt\system32\mui\0419\xpob2res.dll
+ 2008-04-13 18:40:50 427,008 —-a-w c:\winnt\system32\mui\0419\xpob2res.dll
- 2004-08-03 22:56:30 192,512 —-a-w c:\winnt\system32\mui\0419\xpsp1res.dll
+ 2008-04-13 18:35:27 192,512 —-a-w c:\winnt\system32\mui\0419\xpsp1res.dll
- 2004-08-03 22:56:30 736,768 —-a-w c:\winnt\system32\mui\0419\xpsp2res.dll
+ 2008-04-13 18:38:28 736,768 —-a-w c:\winnt\system32\mui\0419\xpsp2res.dll
+ 2008-04-13 18:39:56 627,200 ——w c:\winnt\system32\mui\0419\xpsp3res.dll
- 2004-08-03 22:56:30 188,928 —-a-w c:\winnt\system32\mui\041a\xpsp1res.dll
+ 2008-04-13 18:35:21 188,928 —-a-w c:\winnt\system32\mui\041a\xpsp1res.dll
- 2004-08-03 22:56:24 405,504 —-a-w c:\winnt\system32\mui\041b\xpob2res.dll
+ 2008-04-13 18:40:52 405,504 —-a-w c:\winnt\system32\mui\041b\xpob2res.dll
- 2004-08-03 22:56:30 193,024 —-a-w c:\winnt\system32\mui\041b\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 —-a-w c:\winnt\system32\mui\041b\xpsp1res.dll
- 2004-08-03 22:56:30 757,248 —-a-w c:\winnt\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:38:37 757,248 —-a-w c:\winnt\system32\mui\041b\xpsp2res.dll
+ 2008-04-13 18:40:04 577,536 ——w c:\winnt\system32\mui\041b\xpsp3res.dll
- 2004-08-03 22:56:24 363,520 —-a-w c:\winnt\system32\mui\041D\xpob2res.dll
+ 2008-04-13 18:40:56 363,008 —-a-w c:\winnt\system32\mui\041D\xpob2res.dll
- 2004-08-03 22:56:30 188,928 —-a-w c:\winnt\system32\mui\041D\xpsp1res.dll
+ 2008-04-13 18:35:28 188,928 —-a-w c:\winnt\system32\mui\041D\xpsp1res.dll
- 2004-08-03 22:56:30 724,992 —-a-w c:\winnt\system32\mui\041D\xpsp2res.dll
+ 2008-04-13 18:38:47 724,480 —-a-w c:\winnt\system32\mui\041D\xpsp2res.dll
+ 2008-04-13 18:40:05 590,848 ——w c:\winnt\system32\mui\041D\xpsp3res.dll
- 2004-08-03 22:56:30 188,416 —-a-w c:\winnt\system32\mui\041e\xpsp1res.dll
+ 2008-04-13 18:35:29 188,416 —-a-w c:\winnt\system32\mui\041e\xpsp1res.dll
- 2004-08-03 22:56:24 390,144 —-a-w c:\winnt\system32\mui\041f\xpob2res.dll
+ 2008-04-13 18:41:00 390,144 —-a-w c:\winnt\system32\mui\041f\xpob2res.dll
- 2004-08-03 22:56:30 188,928 —-a-w c:\winnt\system32\mui\041f\xpsp1res.dll
+ 2008-04-13 18:35:30 188,928 —-a-w c:\winnt\system32\mui\041f\xpsp1res.dll
- 2004-08-03 22:56:32 724,480 —-a-w c:\winnt\system32\mui\041f\xpsp2res.dll
+ 2008-04-13 18:38:51 724,480 —-a-w c:\winnt\system32\mui\041f\xpsp2res.dll
+ 2008-04-13 18:40:09 592,896 ——w c:\winnt\system32\mui\041f\xpsp3res.dll
- 2004-08-03 22:56:24 408,576 —-a-w c:\winnt\system32\mui\0424\xpob2res.dll
+ 2008-04-13 18:40:56 408,576 —-a-w c:\winnt\system32\mui\0424\xpob2res.dll
- 2004-08-03 22:56:30 192,512 —-a-w c:\winnt\system32\mui\0424\xpsp1res.dll
+ 2008-04-13 18:35:28 192,512 —-a-w c:\winnt\system32\mui\0424\xpsp1res.dll
- 2004-08-03 22:56:32 732,160 —-a-w c:\winnt\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:38:36 732,160 —-a-w c:\winnt\system32\mui\0424\xpsp2res.dll
+ 2008-04-13 18:40:05 576,512 ——w c:\winnt\system32\mui\0424\xpsp3res.dll
- 2004-08-03 22:56:30 187,392 —-a-w c:\winnt\system32\mui\0425\xpsp1res.dll
+ 2008-04-13 18:35:11 186,880 —-a-w c:\winnt\system32\mui\0425\xpsp1res.dll
- 2004-08-03 22:56:30 188,928 —-a-w c:\winnt\system32\mui\0426\xpsp1res.dll
+ 2008-04-13 18:35:24 188,928 —-a-w c:\winnt\system32\mui\0426\xpsp1res.dll
- 2004-08-03 22:56:30 189,952 —-a-w c:\winnt\system32\mui\0427\xpsp1res.dll
+ 2008-04-13 18:35:24 189,952 —-a-w c:\winnt\system32\mui\0427\xpsp1res.dll
- 2004-08-03 22:56:24 270,336 —-a-w c:\winnt\system32\mui\0804\xpob2res.dll
+ 2008-04-13 18:40:24 270,336 —-a-w c:\winnt\system32\mui\0804\xpob2res.dll
- 2004-08-03 22:56:30 161,280 —-a-w c:\winnt\system32\mui\0804\xpsp1res.dll
+ 2008-04-13 18:35:06 161,280 —-a-w c:\winnt\system32\mui\0804\xpsp1res.dll
- 2004-08-03 22:56:32 470,016 —-a-w c:\winnt\system32\mui\0804\xpsp2res.dll
+ 2008-04-13 18:35:54 470,016 —-a-w c:\winnt\system32\mui\0804\xpsp2res.dll
+ 2008-04-13 18:39:03 322,560 ——w c:\winnt\system32\mui\0804\xpsp3res.dll
- 2004-08-03 22:56:24 435,200 —-a-w c:\winnt\system32\mui\0816\xpob2res.dll
+ 2008-04-13 18:40:48 435,200 —-a-w c:\winnt\system32\mui\0816\xpob2res.dll
- 2004-08-03 22:56:30 194,560 —-a-w c:\winnt\system32\mui\0816\xpsp1res.dll
+ 2008-04-13 18:35:26 194,560 —-a-w c:\winnt\system32\mui\0816\xpsp1res.dll
- 2004-08-03 22:56:32 751,616 —-a-w c:\winnt\system32\mui\0816\xpsp2res.dll
+ 2008-04-13 18:38:06 751,616 —-a-w c:\winnt\system32\mui\0816\xpsp2res.dll
+ 2008-04-13 18:39:53 639,488 ——w c:\winnt\system32\mui\0816\xpsp3res.dll
- 2004-08-03 22:56:24 446,464 —-a-w c:\winnt\system32\mui\0C0A\xpob2res.dll
+ 2008-04-13 18:40:30 446,464 —-a-w c:\winnt\system32\mui\0C0A\xpob2res.dll
- 2004-08-03 22:56:30 196,096 —-a-w c:\winnt\system32\mui\0C0A\xpsp1res.dll
+ 2008-04-13 18:35:11 196,096 —-a-w c:\winnt\system32\mui\0C0A\xpsp1res.dll
- 2004-08-03 22:56:32 773,632 —-a-w c:\winnt\system32\mui\0C0A\xpsp2res.dll
+ 2008-04-13 18:36:38 773,632 —-a-w c:\winnt\system32\mui\0C0A\xpsp2res.dll
+ 2008-04-13 18:39:13 648,704 ——w c:\winnt\system32\mui\0C0A\xpsp3res.dll
- 2004-08-03 22:56:46 90,624 —-a-w c:\winnt\system32\mydocs.dll
+ 2008-04-14 00:12:01 90,624 —-a-w c:\winnt\system32\mydocs.dll
+ 2008-04-14 00:12:01 30,208 ——w c:\winnt\system32\napipsec.dll
+ 2008-04-14 00:12:01 193,024 ——w c:\winnt\system32\napmontr.dll
+ 2008-04-14 00:12:29 176,640 ——w c:\winnt\system32\napstat.exe
- 2004-08-03 22:56:56 53,760 —-a-w c:\winnt\system32\narrator.exe
+ 2008-04-14 00:12:29 53,760 —-a-w c:\winnt\system32\narrator.exe
- 2004-08-03 22:56:46 36,352 —-a-w c:\winnt\system32\ncobjapi.dll
+ 2008-04-14 00:12:01 36,352 —-a-w c:\winnt\system32\ncobjapi.dll
- 2004-08-03 22:56:46 17,920 —-a-w c:\winnt\system32\nddeapi.dll
+ 2008-04-14 00:12:01 17,920 —-a-w c:\winnt\system32\nddeapi.dll
- 2004-08-03 22:56:56 4,096 —-a-w c:\winnt\system32\nddeapir.exe
+ 2008-04-14 00:12:29 4,096 —-a-w c:\winnt\system32\nddeapir.exe
- 2004-08-03 22:56:46 18,944 —-a-w c:\winnt\system32\nddenb32.dll
+ 2008-04-14 00:12:01 18,944 —-a-w c:\winnt\system32\nddenb32.dll
- 2004-08-03 22:56:56 42,496 —-a-w c:\winnt\system32\net.exe
+ 2008-04-14 00:12:29 42,496 —-a-w c:\winnt\system32\net.exe
- 2004-08-03 22:56:56 124,928 —-a-w c:\winnt\system32\net1.exe
+ 2008-04-14 00:12:29 124,928 —-a-w c:\winnt\system32\net1.exe
- 2008-10-15 16:53:28 339,456 —-a-w c:\winnt\system32\netapi32.dll
+ 2008-10-15 16:34:24 337,408 —-a-w c:\winnt\system32\netapi32.dll
- 2004-08-03 22:56:46 622,080 —-a-w c:\winnt\system32\netcfgx.dll
+ 2008-04-14 00:12:01 622,592 —-a-w c:\winnt\system32\netcfgx.dll
- 2004-08-03 22:56:56 111,104 —-a-w c:\winnt\system32\netdde.exe
+ 2008-04-14 00:12:29 111,104 —-a-w c:\winnt\system32\netdde.exe
- 2004-08-03 22:56:46 139,264 —-a-w c:\winnt\system32\netid.dll
+ 2008-04-14 00:12:01 139,264 —-a-w c:\winnt\system32\netid.dll
- 2004-08-03 22:56:46 407,040 —-a-w c:\winnt\system32\netlogon.dll
+ 2008-04-14 00:12:01 407,040 —-a-w c:\winnt\system32\netlogon.dll
- 2005-08-22 18:29:46 197,632 —-a-w c:\winnt\system32\netman.dll
+ 2008-04-14 00:12:01 198,144 —-a-w c:\winnt\system32\netman.dll
- 2004-08-03 22:56:46 875,008 —-a-w c:\winnt\system32\netplwiz.dll
+ 2008-04-14 00:12:01 875,008 —-a-w c:\winnt\system32\netplwiz.dll
- 2004-08-03 22:56:46 12,288 —-a-w c:\winnt\system32\netrap.dll
+ 2008-04-14 00:12:01 11,776 —-a-w c:\winnt\system32\netrap.dll
- 2004-08-03 23:02:46 329,728 —-a-w c:\winnt\system32\netsetup.exe
+ 2008-04-14 00:16:51 329,728 —-a-w c:\winnt\system32\netsetup.exe
- 2004-08-03 22:56:56 86,016 —-a-w c:\winnt\system32\netsh.exe
+ 2008-04-14 00:12:29 86,016 —-a-w c:\winnt\system32\netsh.exe
- 2006-08-18 12:37:56 1,705,472 —-a-w c:\winnt\system32\netshell.dll
+ 2008-04-14 00:12:02 1,703,936 —-a-w c:\winnt\system32\netshell.dll
- 2004-08-03 22:56:56 36,864 —-a-w c:\winnt\system32\netstat.exe
+ 2008-04-14 00:12:29 36,864 —-a-w c:\winnt\system32\netstat.exe
- 2004-08-03 22:56:46 80,896 —-a-w c:\winnt\system32\netui0.dll
+ 2008-04-14 00:12:02 80,896 —-a-w c:\winnt\system32\netui0.dll
- 2004-08-03 22:56:46 245,760 —-a-w c:\winnt\system32\netui1.dll
+ 2008-04-14 00:12:02 245,760 —-a-w c:\winnt\system32\netui1.dll
- 2004-08-03 22:56:46 248,832 —-a-w c:\winnt\system32\newdev.dll
+ 2008-04-14 00:12:02 247,808 —-a-w c:\winnt\system32\newdev.dll
- 2008-03-07 16:56:41 98,304 —-a-w c:\winnt\system32\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 —-a-w c:\winnt\system32\nlhtml.dll
- 2004-08-03 22:56:46 28,672 —-a-w c:\winnt\system32\nmmkcert.dll
+ 2008-04-14 00:12:02 28,672 —-a-w c:\winnt\system32\nmmkcert.dll
- 2004-08-03 22:56:56 69,120 —-a-w c:\winnt\system32\notepad.exe
+ 2008-04-14 00:12:29 69,120 —-a-w c:\winnt\system32\notepad.exe
- 2004-08-03 22:56:46 57,344 —-a-w c:\winnt\system32\npp\ndisnpp.dll
+ 2008-04-14 00:12:01 57,344 —-a-w c:\winnt\system32\npp\ndisnpp.dll
- 2004-08-03 22:56:56 15,360 —-a-w c:\winnt\system32\npp\nppagent.exe
+ 2008-04-14 00:12:29 15,360 —-a-w c:\winnt\system32\npp\nppagent.exe
- 2004-08-03 22:56:46 54,784 —-a-w c:\winnt\system32\npptools.dll
+ 2008-04-14 00:12:02 54,784 —-a-w c:\winnt\system32\npptools.dll
- 2004-08-03 22:56:56 76,800 —-a-w c:\winnt\system32\nslookup.exe
+ 2008-04-14 00:12:29 76,800 —-a-w c:\winnt\system32\nslookup.exe
- 2004-08-03 22:56:56 1,200,128 —-a-w c:\winnt\system32\ntbackup.exe
+ 2008-04-14 00:12:30 1,200,640 —-a-w c:\winnt\system32\ntbackup.exe
- 2004-08-03 22:56:38 708,096 —-a-w c:\winnt\system32\ntdll.dll
+ 2008-04-14 00:11:24 706,048 —-a-w c:\winnt\system32\ntdll.dll
- 2004-08-03 22:56:46 67,072 —-a-w c:\winnt\system32\ntdsapi.dll
+ 2008-04-14 00:12:02 67,072 —-a-w c:\winnt\system32\ntdsapi.dll
- 2008-08-14 09:18:46 2,020,864 —-a-w c:\winnt\system32\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,023,936 —-a-w c:\winnt\system32\ntkrnlpa.exe
- 2004-08-03 22:56:46 43,520 —-a-w c:\winnt\system32\ntlanman.dll
+ 2008-04-14 00:12:02 44,032 —-a-w c:\winnt\system32\ntlanman.dll
- 2004-08-03 22:56:46 8,192 —-a-w c:\winnt\system32\ntlsapi.dll
+ 2008-04-14 00:12:02 8,192 —-a-w c:\winnt\system32\ntlsapi.dll
- 2004-08-03 22:56:46 118,784 —-a-w c:\winnt\system32\ntmarta.dll
+ 2008-04-14 00:12:02 118,784 —-a-w c:\winnt\system32\ntmarta.dll
- 2004-08-03 22:56:46 40,960 —-a-w c:\winnt\system32\ntmsapi.dll
+ 2008-04-14 00:12:02 40,960 —-a-w c:\winnt\system32\ntmsapi.dll
- 2004-08-03 22:56:46 179,712 —-a-w c:\winnt\system32\ntmsdba.dll
+ 2008-04-14 00:12:02 179,200 —-a-w c:\winnt\system32\ntmsdba.dll
- 2004-08-03 22:56:46 488,448 —-a-w c:\winnt\system32\ntmsmgr.dll
+ 2008-04-14 00:12:02 488,448 —-a-w c:\winnt\system32\ntmsmgr.dll
- 2004-08-03 22:56:46 435,200 —-a-w c:\winnt\system32\ntmssvc.dll
+ 2008-04-14 00:12:02 435,200 —-a-w c:\winnt\system32\ntmssvc.dll
- 2008-08-14 09:55:01 2,142,720 —-a-w c:\winnt\system32\ntoskrnl.exe
+ 2008-08-14 10:09:26 2,145,280 —-a-w c:\winnt\system32\ntoskrnl.exe
- 2004-08-03 22:56:46 91,136 —-a-w c:\winnt\system32\ntprint.dll
+ 2008-04-14 00:12:02 91,136 —-a-w c:\winnt\system32\ntprint.dll
- 2004-08-03 22:56:46 143,872 —-a-w c:\winnt\system32\ntshrui.dll
+ 2008-04-14 00:12:02 143,360 —-a-w c:\winnt\system32\ntshrui.dll
- 2004-08-03 22:56:56 419,840 —-a-w c:\winnt\system32\ntvdm.exe
+ 2008-04-14 00:12:30 420,864 —-a-w c:\winnt\system32\ntvdm.exe
- 2001-08-23 12:00:00 13,312 —-a-w c:\winnt\system32\ntvdmd.dll
+ 2008-04-14 00:12:02 15,360 —-a-w c:\winnt\system32\ntvdmd.dll
+ 2008-04-14 00:12:02 4,274,816 ——w c:\winnt\system32\nv4_disp.dll
- 2006-10-13 12:35:12 64,000 —-a-w c:\winnt\system32\nwapi32.dll
+ 2008-04-14 00:12:02 64,000 —-a-w c:\winnt\system32\nwapi32.dll
- 2006-10-13 12:35:12 142,336 —-a-w c:\winnt\system32\nwprovau.dll
+ 2008-04-14 00:12:02 142,336 —-a-w c:\winnt\system32\nwprovau.dll
- 2006-10-13 12:35:12 65,536 —-a-w c:\winnt\system32\nwwks.dll
+ 2008-04-14 00:12:02 65,536 —-a-w c:\winnt\system32\nwwks.dll
- 2004-08-03 22:56:46 266,752 —-a-w c:\winnt\system32\oakley.dll
+ 2008-04-14 00:12:02 270,336 —-a-w c:\winnt\system32\oakley.dll
- 2004-08-03 22:56:46 285,696 —-a-w c:\winnt\system32\objsel.dll
+ 2008-04-14 00:12:02 286,208 —-a-w c:\winnt\system32\objsel.dll
- 2008-10-16 20:38:39 102,912 —-a-w c:\winnt\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\winnt\system32\occache.dll
- 2001-08-23 12:00:00 60,928 —-a-w c:\winnt\system32\ocmanage.dll
+ 2008-04-14 00:12:02 67,584 —-a-w c:\winnt\system32\ocmanage.dll
- 2004-08-03 22:56:46 249,856 —-a-w c:\winnt\system32\odbc32.dll
+ 2008-04-14 00:12:02 249,856 —-a-w c:\winnt\system32\odbc32.dll
- 2004-08-03 22:56:46 16,384 —-a-w c:\winnt\system32\odbc32gt.dll
+ 2008-04-14 00:12:02 16,384 —-a-w c:\winnt\system32\odbc32gt.dll
- 2004-08-03 22:56:56 32,768 —-a-w c:\winnt\system32\odbcad32.exe
+ 2008-04-14 00:12:30 32,768 —-a-w c:\winnt\system32\odbcad32.exe
- 2004-08-03 22:56:46 24,576 —-a-w c:\winnt\system32\odbcbcp.dll
+ 2008-04-14 00:12:02 24,576 —-a-w c:\winnt\system32\odbcbcp.dll
- 2004-08-03 22:56:46 135,168 —-a-w c:\winnt\system32\odbcconf.dll
+ 2008-04-14 00:12:02 135,168 —-a-w c:\winnt\system32\odbcconf.dll
- 2004-08-03 22:56:56 69,632 —-a-w c:\winnt\system32\odbcconf.exe
+ 2008-04-14 00:12:30 69,632 —-a-w c:\winnt\system32\odbcconf.exe
- 2004-08-03 22:56:46 106,496 —-a-w c:\winnt\system32\odbccp32.dll
+ 2008-04-14 00:12:02 106,496 —-a-w c:\winnt\system32\odbccp32.dll
- 2004-08-03 22:56:46 65,536 —-a-w c:\winnt\system32\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 —-a-w c:\winnt\system32\odbccr32.dll
- 2004-08-03 22:56:46 65,536 —-a-w c:\winnt\system32\odbccu32.dll
+ 2008-04-14 00:12:02 65,536 —-a-w c:\winnt\system32\odbccu32.dll
- 2004-08-03 22:56:24 94,208 —-a-w c:\winnt\system32\odbcint.dll
+ 2008-04-13 17:26:05 94,208 —-a-w c:\winnt\system32\odbcint.dll
- 2004-08-03 22:56:24 53,279 —-a-w c:\winnt\system32\odbcji32.dll
+ 2008-04-14 00:10:31 53,279 —-a-w c:\winnt\system32\odbcji32.dll
- 2004-08-03 22:56:46 278,559 —-a-w c:\winnt\system32\odbcjt32.dll
+ 2008-04-14 00:12:02 278,559 —-a-w c:\winnt\system32\odbcjt32.dll
- 2004-08-03 22:56:24 12,288 —-a-w c:\winnt\system32\odbcp32r.dll
+ 2008-04-13 17:26:05 12,288 —-a-w c:\winnt\system32\odbcp32r.dll
- 2004-08-03 22:56:46 147,456 —-a-w c:\winnt\system32\odbctrac.dll
+ 2008-04-14 00:12:02 147,456 —-a-w c:\winnt\system32\odbctrac.dll
- 2004-08-03 22:56:46 20,511 —-a-w c:\winnt\system32\oddbse32.dll
+ 2008-04-14 00:12:02 20,511 —-a-w c:\winnt\system32\oddbse32.dll
- 2004-08-03 22:56:46 20,510 —-a-w c:\winnt\system32\odexl32.dll
+ 2008-04-14 00:12:02 20,510 —-a-w c:\winnt\system32\odexl32.dll
- 2004-08-03 22:56:46 20,510 —-a-w c:\winnt\system32\odfox32.dll
+ 2008-04-14 00:12:02 20,510 —-a-w c:\winnt\system32\odfox32.dll
- 2004-08-03 22:56:46 20,510 —-a-w c:\winnt\system32\odpdx32.dll
+ 2008-04-14 00:12:02 20,510 —-a-w c:\winnt\system32\odpdx32.dll
- 2004-08-03 22:56:46 20,511 —-a-w c:\winnt\system32\odtext32.dll
+ 2008-04-14 00:12:02 20,511 —-a-w c:\winnt\system32\odtext32.dll
- 2008-03-07 16:56:41 192,000 —-a-w c:\winnt\system32\offfilt.dll
+ 2008-03-07 17:02:08 192,000 —-a-w c:\winnt\system32\offfilt.dll
- 2005-07-26 04:39:48 1,285,120 —-a-w c:\winnt\system32\ole32.dll
+ 2008-04-14 00:12:02 1,287,168 —-a-w c:\winnt\system32\ole32.dll
- 2007-12-04 18:38:13 550,912 —-a-w c:\winnt\system32\oleaut32.dll
+ 2008-04-14 00:12:02 551,936 —-a-w c:\winnt\system32\oleaut32.dll
- 2005-07-26 04:39:48 74,752 —-a-w c:\winnt\system32\olecli32.dll
+ 2008-04-14 00:12:02 74,752 —-a-w c:\winnt\system32\olecli32.dll
- 2005-07-26 04:39:49 37,888 —-a-w c:\winnt\system32\olecnv32.dll
+ 2008-04-14 00:12:02 37,376 —-a-w c:\winnt\system32\olecnv32.dll
- 2006-10-16 16:15:00 122,880 —-a-w c:\winnt\system32\oledlg.dll
+ 2008-04-14 00:12:02 122,880 —-a-w c:\winnt\system32\oledlg.dll
- 2004-08-03 22:56:46 107,008 —-a-w c:\winnt\system32\oleprn.dll
+ 2008-04-14 00:12:02 107,008 —-a-w c:\winnt\system32\oleprn.dll
- 2004-08-03 22:56:46 83,456 —-a-w c:\winnt\system32\olepro32.dll
+ 2008-04-14 00:12:02 84,992 —-a-w c:\winnt\system32\olepro32.dll
+ 2008-04-14 00:12:02 144,384 ——w c:\winnt\system32\onex.dll
- 2004-08-03 22:56:44 122,368 —-a-w c:\winnt\system32\oobe\msobcomm.dll
+ 2008-04-14 00:12:00 122,368 —-a-w c:\winnt\system32\oobe\msobcomm.dll
- 2004-08-03 22:56:44 16,384 —-a-w c:\winnt\system32\oobe\msobdl.dll
+ 2008-04-14 00:12:00 16,384 —-a-w c:\winnt\system32\oobe\msobdl.dll
- 2004-08-03 22:56:44 561,664 —-a-w c:\winnt\system32\oobe\msobmain.dll
+ 2008-04-14 00:12:00 565,248 —-a-w c:\winnt\system32\oobe\msobmain.dll
- 2004-08-03 22:56:44 30,720 —-a-w c:\winnt\system32\oobe\msobshel.dll
+ 2008-04-14 00:12:00 30,720 —-a-w c:\winnt\system32\oobe\msobshel.dll
- 2004-08-03 22:56:44 18,944 —-a-w c:\winnt\system32\oobe\msobweb.dll
+ 2008-04-14 00:12:00 19,456 —-a-w c:\winnt\system32\oobe\msobweb.dll
- 2001-08-23 12:00:00 28,160 —-a-w c:\winnt\system32\oobe\msoobe.exe
+ 2008-04-14 00:12:28 29,184 —-a-w c:\winnt\system32\oobe\msoobe.exe
- 2004-08-03 22:56:56 51,200 —-a-w c:\winnt\system32\oobe\oobebaln.exe
+ 2008-04-14 00:12:31 51,200 —-a-w c:\winnt\system32\oobe\oobebaln.exe
- 2004-08-03 22:56:56 67,584 —-a-w c:\winnt\system32\openfiles.exe
+ 2008-04-14 00:12:31 67,584 —-a-w c:\winnt\system32\openfiles.exe
- 2004-08-03 22:56:46 713,728 —-a-w c:\winnt\system32\opengl32.dll
+ 2008-04-14 00:12:02 713,728 —-a-w c:\winnt\system32\opengl32.dll
- 2004-08-03 22:56:56 215,552 —-a-w c:\winnt\system32\osk.exe
+ 2008-04-14 00:12:31 215,552 —-a-w c:\winnt\system32\osk.exe
- 2004-08-03 22:56:46 67,584 —-a-w c:\winnt\system32\osuninst.dll
+ 2008-04-14 00:12:02 67,584 —-a-w c:\winnt\system32\osuninst.dll
- 2004-08-03 22:56:46 116,224 —-a-w c:\winnt\system32\p2p.dll
+ 2008-04-14 00:12:02 153,600 —-a-w c:\winnt\system32\p2p.dll
- 2004-08-03 22:56:46 86,016 —-a-w c:\winnt\system32\p2pgasvc.dll
+ 2008-04-14 00:12:02 105,472 —-a-w c:\winnt\system32\p2pgasvc.dll
- 2004-08-03 22:56:46 312,320 —-a-w c:\winnt\system32\p2pgraph.dll
+ 2008-04-14 00:12:02 313,856 —-a-w c:\winnt\system32\p2pgraph.dll
- 2004-08-03 22:56:46 88,064 —-a-w c:\winnt\system32\p2pnetsh.dll
+ 2008-04-14 00:12:02 115,712 —-a-w c:\winnt\system32\p2pnetsh.dll
- 2004-08-03 22:56:46 526,848 —-a-w c:\winnt\system32\p2psvc.dll
+ 2008-04-14 00:12:02 554,496 —-a-w c:\winnt\system32\p2psvc.dll
- 2004-08-03 22:56:56 58,368 —-a-w c:\winnt\system32\packager.exe
+ 2008-04-14 00:12:31 58,368 —-a-w c:\winnt\system32\packager.exe
- 2004-08-03 22:56:46 62,976 —-a-w c:\winnt\system32\pautoenr.dll
+ 2008-04-14 00:12:02 67,584 —-a-w c:\winnt\system32\pautoenr.dll
- 2004-08-03 22:56:46 283,648 —-a-w c:\winnt\system32\pdh.dll
+ 2008-04-14 00:12:02 284,160 —-a-w c:\winnt\system32\pdh.dll
- 2009-02-20 14:40:29 70,650 —-a-w c:\winnt\system32\perfc009.dat
+ 2009-03-06 18:33:09 70,650 —-a-w c:\winnt\system32\perfc009.dat
- 2004-08-03 22:56:46 39,936 —-a-w c:\winnt\system32\perfctrs.dll
+ 2008-04-14 00:12:02 39,936 —-a-w c:\winnt\system32\perfctrs.dll
- 2004-08-03 22:56:46 26,624 —-a-w c:\winnt\system32\perfdisk.dll
+ 2008-04-14 00:12:02 26,624 —-a-w c:\winnt\system32\perfdisk.dll
- 2009-02-20 14:40:29 440,032 —-a-w c:\winnt\system32\perfh009.dat
+ 2009-03-06 18:33:09 440,032 —-a-w c:\winnt\system32\perfh009.dat
- 2004-08-03 22:56:56 15,872 —-a-w c:\winnt\system32\perfmon.exe
+ 2008-04-14 00:12:31 15,872 —-a-w c:\winnt\system32\perfmon.exe
- 2001-08-23 12:00:00 16,896 —-a-w c:\winnt\system32\perfnet.dll
+ 2008-04-14 00:12:02 17,920 —-a-w c:\winnt\system32\perfnet.dll
- 2004-08-03 22:56:46 25,088 —-a-w c:\winnt\system32\perfos.dll
+ 2008-04-14 00:12:02 25,088 —-a-w c:\winnt\system32\perfos.dll
- 2004-08-03 22:56:46 34,816 —-a-w c:\winnt\system32\perfproc.dll
+ 2008-04-14 00:12:02 34,816 —-a-w c:\winnt\system32\perfproc.dll
- 2006-10-24 17:30:20 412,160 ——w c:\winnt\system32\photometadatahandler.dll
+ 2008-04-14 00:12:02 412,160 ——w c:\winnt\system32\photometadatahandler.dll
- 2004-08-03 22:56:46 176,128 —-a-w c:\winnt\system32\photowiz.dll
+ 2008-04-14 00:12:02 176,128 —-a-w c:\winnt\system32\photowiz.dll
- 2004-08-03 23:05:44 35,328 —-a-w c:\winnt\system32\pid.dll
+ 2008-04-14 00:12:02 35,328 —-a-w c:\winnt\system32\pid.dll
- 2004-08-03 22:56:06 24,064 —-a-w c:\winnt\system32\pidgen.dll
+ 2008-04-14 00:09:24 24,064 —-a-w c:\winnt\system32\pidgen.dll
- 2004-08-03 22:56:56 17,920 —-a-w c:\winnt\system32\ping.exe
+ 2008-04-14 00:12:31 17,920 —-a-w c:\winnt\system32\ping.exe
- 2004-08-03 23:05:44 15,360 —-a-w c:\winnt\system32\pjlmon.dll
+ 2008-04-14 00:12:02 15,360 —-a-w c:\winnt\system32\pjlmon.dll
- 2008-10-16 20:38:39 44,544 —-a-w c:\winnt\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\winnt\system32\pngfilt.dll
- 2004-08-03 22:56:46 48,640 —-a-w c:\winnt\system32\pnrpnsp.dll
+ 2008-04-14 00:12:02 58,880 —-a-w c:\winnt\system32\pnrpnsp.dll
- 2004-08-03 22:56:46 105,472 —-a-w c:\winnt\system32\polstore.dll
+ 2008-04-14 00:12:02 105,472 —-a-w c:\winnt\system32\polstore.dll
- 2004-08-03 22:56:56 49,152 —-a-w c:\winnt\system32\powercfg.exe
+ 2008-04-14 00:12:31 49,152 —-a-w c:\winnt\system32\powercfg.exe
- 2004-08-03 22:56:46 17,408 —-a-w c:\winnt\system32\powrprof.dll
+ 2008-04-14 00:12:03 17,408 —-a-w c:\winnt\system32\powrprof.dll
- 2004-08-03 22:56:46 560,640 —-a-w c:\winnt\system32\printui.dll
+ 2008-04-14 00:12:03 560,640 —-a-w c:\winnt\system32\printui.dll
- 2004-08-03 22:56:46 27,648 —-a-w c:\winnt\system32\profmap.dll
+ 2008-04-14 00:12:03 27,648 —-a-w c:\winnt\system32\profmap.dll
- 2004-08-03 22:56:56 109,568 —-a-w c:\winnt\system32\progman.exe
+ 2008-04-14 00:12:31 109,568 —-a-w c:\winnt\system32\progman.exe
- 2004-08-03 22:56:56 50,176 —-a-w c:\winnt\system32\proquota.exe
+ 2008-04-14 00:12:32 50,176 —-a-w c:\winnt\system32\proquota.exe
- 2004-08-03 22:56:56 9,216 —-a-w c:\winnt\system32\proxycfg.exe
+ 2008-04-14 00:12:32 9,216 —-a-w c:\winnt\system32\proxycfg.exe
- 2004-08-03 22:56:46 23,040 —-a-w c:\winnt\system32\psapi.dll
+ 2008-04-14 00:12:03 23,040 —-a-w c:\winnt\system32\psapi.dll
- 2004-08-03 22:56:46 96,768 —-a-w c:\winnt\system32\psbase.dll
+ 2008-04-14 00:12:03 96,768 —-a-w c:\winnt\system32\psbase.dll
- 2004-08-03 22:56:46 43,520 —-a-w c:\winnt\system32\pstorec.dll
+ 2008-04-14 00:12:03 43,520 —-a-w c:\winnt\system32\pstorec.dll
- 2004-08-03 22:56:46 34,304 —-a-w c:\winnt\system32\pstorsvc.dll
+ 2008-04-14 00:12:03 34,304 —-a-w c:\winnt\system32\pstorsvc.dll
+ 2008-04-14 00:12:03 150,528 ——w c:\winnt\system32\qagent.dll
+ 2008-04-14 00:12:03 291,328 ——w c:\winnt\system32\qagentrt.dll
- 2004-08-03 22:56:46 192,512 —-a-w c:\winnt\system32\qcap.dll
+ 2008-04-14 00:12:03 192,512 —-a-w c:\winnt\system32\qcap.dll
+ 2008-04-14 00:12:03 62,464 ——w c:\winnt\system32\qcliprov.dll
- 2004-08-03 22:56:46 279,040 —-a-w c:\winnt\system32\qdv.dll
+ 2008-04-14 00:12:03 279,040 —-a-w c:\winnt\system32\qdv.dll
- 2004-08-03 22:56:46 385,024 —-a-w c:\winnt\system32\qdvd.dll
+ 2008-04-14 00:12:03 386,048 —-a-w c:\winnt\system32\qdvd.dll
- 2004-08-03 22:56:46 562,176 —-a-w c:\winnt\system32\qedit.dll
+ 2008-04-14 00:12:03 562,176 —-a-w c:\winnt\system32\qedit.dll
- 2004-08-03 22:56:26 733,696 —-a-w c:\winnt\system32\qedwipes.dll
+ 2008-04-13 17:21:32 733,696 —-a-w c:\winnt\system32\qedwipes.dll
- 2004-08-03 22:56:46 382,464 —-a-w c:\winnt\system32\qmgr.dll
+ 2008-04-14 00:12:03 409,088 —-a-w c:\winnt\system32\qmgr.dll
- 2004-08-03 22:56:46 18,944 —-a-w c:\winnt\system32\qmgrprxy.dll
+ 2008-04-14 00:12:03 18,944 —-a-w c:\winnt\system32\qmgrprxy.dll
- 2004-08-03 22:56:56 20,480 —-a-w c:\winnt\system32\qprocess.exe
+ 2008-04-14 00:12:32 19,968 —-a-w c:\winnt\system32\qprocess.exe
- 2008-05-07 05:18:48 1,287,680 —-a-w c:\winnt\system32\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 —-a-w c:\winnt\system32\quartz.dll
- 2006-06-22 05:06:30 1,435,648 —-a-w c:\winnt\system32\query.dll
+ 2008-04-14 00:12:03 1,435,648 —-a-w c:\winnt\system32\query.dll
+ 2008-04-14 00:12:03 76,800 ——w c:\winnt\system32\qutil.dll
- 2004-08-03 22:56:46 43,520 —-a-w c:\winnt\system32\racpldlg.dll
+ 2008-04-14 00:12:03 43,520 —-a-w c:\winnt\system32\racpldlg.dll
- 2006-06-26 17:37:10 8,192 —-a-w c:\winnt\system32\rasadhlp.dll
+ 2008-04-14 00:12:03 7,680 —-a-w c:\winnt\system32\rasadhlp.dll
- 2004-08-03 22:56:46 236,544 —-a-w c:\winnt\system32\rasapi32.dll
+ 2008-04-14 00:12:03 237,056 —-a-w c:\winnt\system32\rasapi32.dll
- 2004-08-03 22:56:46 89,088 —-a-w c:\winnt\system32\rasauto.dll
+ 2008-04-14 00:12:03 88,576 —-a-w c:\winnt\system32\rasauto.dll
- 2004-08-03 22:56:46 69,632 —-a-w c:\winnt\system32\raschap.dll
+ 2008-04-14 00:12:03 79,872 —-a-w c:\winnt\system32\raschap.dll
- 2004-08-03 22:56:46 657,920 —-a-w c:\winnt\system32\rasdlg.dll
+ 2008-04-14 00:12:03 658,432 —-a-w c:\winnt\system32\rasdlg.dll
- 2004-08-03 22:56:46 61,440 —-a-w c:\winnt\system32\rasman.dll
+ 2008-04-14 00:12:03 61,440 —-a-w c:\winnt\system32\rasman.dll
- 2006-06-22 10:47:18 181,248 —-a-w c:\winnt\system32\rasmans.dll
+ 2008-04-14 00:12:03 186,368 —-a-w c:\winnt\system32\rasmans.dll
- 2004-08-03 22:56:56 56,832 —-a-w c:\winnt\system32\rasphone.exe
+ 2008-04-14 00:12:32 56,832 —-a-w c:\winnt\system32\rasphone.exe
- 2004-08-03 22:56:46 206,336 —-a-w c:\winnt\system32\rasppp.dll
+ 2008-04-14 00:12:03 210,944 —-a-w c:\winnt\system32\rasppp.dll
+ 2008-04-14 00:12:03 61,952 ——w c:\winnt\system32\rasqec.dll
- 2004-08-03 22:56:46 16,896 —-a-w c:\winnt\system32\rassapi.dll
+ 2008-04-14 00:12:03 16,384 —-a-w c:\winnt\system32\rassapi.dll
- 2004-08-03 22:56:46 58,880 —-a-w c:\winnt\system32\rastapi.dll
+ 2008-04-14 00:12:03 58,368 —-a-w c:\winnt\system32\rastapi.dll
- 2004-12-30 01:14:12 112,640 —-a-w c:\winnt\system32\rastls.dll
+ 2008-04-14 00:12:03 150,016 —-a-w c:\winnt\system32\rastls.dll
- 2004-08-03 22:56:46 102,400 —-a-w c:\winnt\system32\rcbdyctl.dll
+ 2008-04-14 00:12:03 102,400 —-a-w c:\winnt\system32\rcbdyctl.dll
- 2004-08-03 22:56:56 35,840 —-a-w c:\winnt\system32\rcimlby.exe
+ 2008-04-14 00:12:32 35,840 —-a-w c:\winnt\system32\rcimlby.exe
- 2004-08-03 22:56:56 21,504 —-a-w c:\winnt\system32\rcp.exe
+ 2008-04-14 00:12:32 21,504 —-a-w c:\winnt\system32\rcp.exe
- 2004-08-03 22:56:46 147,968 —-a-w c:\winnt\system32\rdchost.dll
+ 2008-04-14 00:12:03 147,968 —-a-w c:\winnt\system32\rdchost.dll
- 2004-08-03 22:56:56 62,464 —-a-w c:\winnt\system32\rdpclip.exe
+ 2008-04-14 00:12:32 62,976 —-a-w c:\winnt\system32\rdpclip.exe
- 2004-08-03 23:01:08 92,168 —-a-w c:\winnt\system32\rdpdd.dll
+ 2008-04-14 00:13:22 92,424 —-a-w c:\winnt\system32\rdpdd.dll
- 2004-08-03 22:56:46 19,968 —-a-w c:\winnt\system32\rdpsnd.dll
+ 2008-04-14 00:12:04 19,968 —-a-w c:\winnt\system32\rdpsnd.dll
- 2004-08-03 23:01:10 87,176 —-a-w c:\winnt\system32\rdpwsx.dll
+ 2008-04-14 00:13:22 87,176 —-a-w c:\winnt\system32\rdpwsx.dll
- 2004-08-03 22:56:56 13,824 —-a-w c:\winnt\system32\rdsaddin.exe
+ 2008-04-14 00:12:32 13,824 —-a-w c:\winnt\system32\rdsaddin.exe
- 2004-08-03 22:56:56 67,072 —-a-w c:\winnt\system32\rdshost.exe
+ 2008-04-14 00:12:32 67,072 —-a-w c:\winnt\system32\rdshost.exe
- 2004-08-03 22:56:56 50,176 —-a-w c:\winnt\system32\reg.exe
+ 2008-04-14 00:12:32 50,176 —-a-w c:\winnt\system32\reg.exe
- 2004-08-03 22:56:46 49,664 —-a-w c:\winnt\system32\regapi.dll
+ 2008-04-14 00:12:04 49,664 —-a-w c:\winnt\system32\regapi.dll
- 2004-08-03 22:56:46 59,904 —-a-w c:\winnt\system32\regsvc.dll
+ 2008-04-14 00:12:04 59,904 —-a-w c:\winnt\system32\regsvc.dll
- 2004-08-03 22:56:56 11,776 —-a-w c:\winnt\system32\regsvr32.exe
+ 2008-04-14 00:12:32 11,776 —-a-w c:\winnt\system32\regsvr32.exe
- 2004-08-03 22:56:46 397,824 —-a-w c:\winnt\system32\regwizc.dll
+ 2008-04-14 00:12:04 397,824 —-a-w c:\winnt\system32\regwizc.dll
+ 2004-08-03 23:05:44 36,096 —-a-w c:\winnt\system32\ReinstallBackups\0016\DriverFiles\i386\intelppm.sys
+ 2004-08-03 23:05:44 36,096 —-a-w c:\winnt\system32\ReinstallBackups\0018\DriverFiles\i386\intelppm.sys
+ 2005-01-07 21:07:18 138,752 —-a-w c:\winnt\system32\ReinstallBackups\0019\DriverFiles\hdaudbus.sys
- 2004-08-03 22:56:46 60,416 —-a-w c:\winnt\system32\remotepg.dll
+ 2008-04-14 00:12:04 60,416 —-a-w c:\winnt\system32\remotepg.dll
- 2004-08-03 22:56:56 380,416 —-a-w c:\winnt\system32\Restore\rstrui.exe
+ 2008-04-14 00:12:33 380,416 —-a-w c:\winnt\system32\Restore\rstrui.exe
- 2004-08-03 22:56:46 58,880 —-a-w c:\winnt\system32\resutils.dll
+ 2008-04-14 00:12:04 58,880 —-a-w c:\winnt\system32\resutils.dll
- 2004-08-03 22:56:56 13,824 —-a-w c:\winnt\system32\rexec.exe
+ 2008-04-14 00:12:33 13,824 —-a-w c:\winnt\system32\rexec.exe
+ 2008-04-14 00:12:04 290,304 ——w c:\winnt\system32\rhttpaa.dll
- 2006-11-27 14:54:06 433,152 —-a-w c:\winnt\system32\riched20.dll
+ 2008-04-14 00:12:04 433,664 —-a-w c:\winnt\system32\riched20.dll
- 2007-07-09 13:09:42 584,192 —-a-w c:\winnt\system32\rpcrt4.dll
+ 2008-04-14 00:12:04 584,704 —-a-w c:\winnt\system32\rpcrt4.dll
- 2005-07-26 04:39:49 397,824 —-a-w c:\winnt\system32\rpcss.dll
+ 2008-04-14 00:12:04 399,360 —-a-w c:\winnt\system32\rpcss.dll
- 2004-08-03 20:31:44 152,576 —-a-w c:\winnt\system32\rsaenh.dll
+ 2008-04-13 17:37:57 208,384 —-a-w c:\winnt\system32\rsaenh.dll
- 2004-08-03 22:56:56 14,848 —-a-w c:\winnt\system32\rsh.exe
+ 2008-04-14 00:12:33 14,848 —-a-w c:\winnt\system32\rsh.exe
- 2004-08-03 22:56:46 39,936 —-a-w c:\winnt\system32\rshx32.dll
+ 2008-04-14 00:12:04 39,936 —-a-w c:\winnt\system32\rshx32.dll
- 2004-08-03 22:56:46 18,944 —-a-w c:\winnt\system32\rsmps.dll
+ 2008-04-14 00:12:04 18,944 —-a-w c:\winnt\system32\rsmps.dll
- 2004-08-03 22:56:56 107,520 —-a-w c:\winnt\system32\rsnotify.exe
+ 2008-04-14 00:12:33 107,520 —-a-w c:\winnt\system32\rsnotify.exe
- 2001-08-23 12:00:00 90,112 —-a-w c:\winnt\system32\rsvpsp.dll
+ 2008-04-14 00:12:04 92,672 —-a-w c:\winnt\system32\rsvpsp.dll
- 2004-08-03 22:56:56 77,312 —-a-w c:\winnt\system32\rtcshare.exe
+ 2008-04-14 00:12:33 77,312 —-a-w c:\winnt\system32\rtcshare.exe
- 2004-08-03 22:56:46 31,744 —-a-w c:\winnt\system32\rtipxmib.dll
+ 2008-04-14 00:12:04 31,744 —-a-w c:\winnt\system32\rtipxmib.dll
- 2004-08-03 22:56:46 44,032 —-a-w c:\winnt\system32\rtutils.dll
+ 2008-04-14 00:12:04 44,032 —-a-w c:\winnt\system32\rtutils.dll
- 2004-08-03 22:56:56 33,280 —-a-w c:\winnt\system32\rundll32.exe
+ 2008-04-14 00:12:33 33,280 —-a-w c:\winnt\system32\rundll32.exe
- 2004-08-03 22:56:56 14,336 —-a-w c:\winnt\system32\runonce.exe
+ 2008-04-14 00:12:33 14,336 —-a-w c:\winnt\system32\runonce.exe
+ 2008-04-14 00:12:04 9,728 ——w c:\winnt\system32\rwnh.dll
+ 2008-04-14 00:12:04 397,056 ——w c:\winnt\system32\s3gnb.dll
- 2004-08-03 22:56:46 43,520 —-a-w c:\winnt\system32\safrcdlg.dll
+ 2008-04-14 00:12:04 43,520 —-a-w c:\winnt\system32\safrcdlg.dll
- 2004-08-03 22:56:46 29,696 —-a-w c:\winnt\system32\safrdm.dll
+ 2008-04-14 00:12:04 29,696 —-a-w c:\winnt\system32\safrdm.dll
- 2004-08-03 22:56:46 45,568 —-a-w c:\winnt\system32\safrslv.dll
+ 2008-04-14 00:12:04 45,568 —-a-w c:\winnt\system32\safrslv.dll
- 2004-08-03 22:56:46 64,000 —-a-w c:\winnt\system32\samlib.dll
+ 2008-04-14 00:12:04 64,000 —-a-w c:\winnt\system32\samlib.dll
- 2004-08-03 22:56:46 415,744 —-a-w c:\winnt\system32\samsrv.dll
+ 2008-04-14 00:12:04 415,744 —-a-w c:\winnt\system32\samsrv.dll
- 2004-08-03 22:56:56 13,312 —-a-w c:\winnt\system32\savedump.exe
+ 2008-04-14 00:12:33 13,312 —-a-w c:\winnt\system32\savedump.exe
- 2004-08-03 22:56:46 270,848 —-a-w c:\winnt\system32\sbe.dll
+ 2008-04-14 00:12:04 270,848 —-a-w c:\winnt\system32\sbe.dll
- 2004-08-03 22:56:46 159,232 —-a-w c:\winnt\system32\sbeio.dll
+ 2008-04-14 00:12:04 159,232 —-a-w c:\winnt\system32\sbeio.dll
- 2004-08-03 22:56:46 69,632 —-a-w c:\winnt\system32\scarddlg.dll
+ 2008-04-14 00:12:04 69,632 —-a-w c:\winnt\system32\scarddlg.dll
- 2004-08-03 22:56:56 95,744 —-a-w c:\winnt\system32\scardsvr.exe
+ 2008-04-14 00:12:33 95,744 —-a-w c:\winnt\system32\scardsvr.exe
- 2004-08-03 22:56:46 171,008 —-a-w c:\winnt\system32\sccsccp.dll
+ 2008-04-14 00:12:05 171,008 —-a-w c:\winnt\system32\sccsccp.dll
- 2004-08-03 22:56:46 180,224 —-a-w c:\winnt\system32\scecli.dll
+ 2008-04-14 00:12:05 181,248 —-a-w c:\winnt\system32\scecli.dll
- 2004-08-03 22:56:46 313,856 —-a-w c:\winnt\system32\scesrv.dll
+ 2008-04-14 00:12:05 314,880 —-a-w c:\winnt\system32\scesrv.dll
- 2007-04-25 14:21:15 144,896 —-a-w c:\winnt\system32\schannel.dll
+ 2008-04-14 00:12:05 144,384 —-a-w c:\winnt\system32\schannel.dll
- 2004-08-03 22:56:46 190,976 —-a-w c:\winnt\system32\schedsvc.dll
+ 2008-04-14 00:12:05 192,512 —-a-w c:\winnt\system32\schedsvc.dll
- 2004-08-03 22:56:56 121,856 —-a-w c:\winnt\system32\schtasks.exe
+ 2008-04-14 00:12:34 121,856 —-a-w c:\winnt\system32\schtasks.exe
- 2004-08-03 22:56:46 20,992 —-a-w c:\winnt\system32\sclgntfy.dll
+ 2008-04-14 00:12:05 20,480 —-a-w c:\winnt\system32\sclgntfy.dll
- 2004-08-03 22:56:58 9,216 —-a-w c:\winnt\system32\scrnsave.scr
+ 2008-04-14 00:12:43 9,216 —-a-w c:\winnt\system32\scrnsave.scr
- 2004-08-03 22:56:46 159,744 —-a-w c:\winnt\system32\scrobj.dll
+ 2008-05-09 10:53:39 180,224 —-a-w c:\winnt\system32\scrobj.dll
- 2004-08-03 22:56:46 151,552 —-a-w c:\winnt\system32\scrrun.dll
+ 2008-05-09 10:53:40 172,032 —-a-w c:\winnt\system32\scrrun.dll
- 2004-08-03 22:56:56 77,312 —-a-w c:\winnt\system32\sdbinst.exe
+ 2008-04-14 00:12:34 77,312 —-a-w c:\winnt\system32\sdbinst.exe
- 2004-08-03 23:05:44 29,184 —-a-w c:\winnt\system32\sdhcinst.dll
+ 2008-04-14 00:12:05 29,184 —-a-w c:\winnt\system32\sdhcinst.dll
- 2004-08-03 22:56:56 18,432 —-a-w c:\winnt\system32\secedit.exe
+ 2008-04-14 00:12:34 18,944 —-a-w c:\winnt\system32\secedit.exe
- 2004-08-03 22:56:46 18,944 —-a-w c:\winnt\system32\seclogon.dll
+ 2008-04-14 00:12:05 18,944 —-a-w c:\winnt\system32\seclogon.dll
- 2004-08-03 22:56:46 55,808 —-a-w c:\winnt\system32\secur32.dll
+ 2008-04-14 00:12:05 56,320 —-a-w c:\winnt\system32\secur32.dll
- 2004-08-03 22:56:46 5,632 —-a-w c:\winnt\system32\security.dll
+ 2008-04-14 00:12:05 5,632 —-a-w c:\winnt\system32\security.dll
- 2004-08-03 22:56:46 29,184 —-a-w c:\winnt\system32\sendcmsg.dll
+ 2008-04-14 00:12:05 29,184 —-a-w c:\winnt\system32\sendcmsg.dll
- 2004-08-03 22:56:46 55,296 —-a-w c:\winnt\system32\sendmail.dll
+ 2008-04-14 00:12:05 54,784 —-a-w c:\winnt\system32\sendmail.dll
- 2004-08-03 22:56:46 38,912 —-a-w c:\winnt\system32\sens.dll
+ 2008-04-14 00:12:05 39,424 —-a-w c:\winnt\system32\sens.dll
- 2004-08-03 22:56:46 6,656 —-a-w c:\winnt\system32\sensapi.dll
+ 2008-04-14 00:12:05 7,168 —-a-w c:\winnt\system32\sensapi.dll
- 2004-08-03 22:56:46 56,320 —-a-w c:\winnt\system32\servdeps.dll
+ 2008-04-14 00:12:05 56,320 —-a-w c:\winnt\system32\servdeps.dll
- 2004-08-03 22:56:56 108,032 —-a-w c:\winnt\system32\services.exe
+ 2008-04-14 00:12:34 108,544 —-a-w c:\winnt\system32\services.exe
- 2004-08-03 22:56:58 140,800 —-a-w c:\winnt\system32\sessmgr.exe
+ 2008-04-14 00:12:34 141,312 —-a-w c:\winnt\system32\sessmgr.exe
- 2004-08-03 22:56:58 31,232 —-a-w c:\winnt\system32\sethc.exe
+ 2008-04-14 00:12:34 31,232 —-a-w c:\winnt\system32\sethc.exe
- 2004-08-03 22:56:58 23,040 —-a-w c:\winnt\system32\setup.exe
+ 2008-04-14 00:12:34 23,040 —-a-w c:\winnt\system32\setup.exe
- 2001-08-23 12:00:00 259,584 —-a-w c:\winnt\system32\Setup\comsetup.dll
+ 2008-04-14 00:11:51 274,944 —-a-w c:\winnt\system32\Setup\comsetup.dll
- 2004-08-03 22:56:44 32,828 —-a-w c:\winnt\system32\Setup\fp40ext.dll
+ 2008-04-14 00:11:53 32,828 —-a-w c:\winnt\system32\Setup\fp40ext.dll
- 2004-08-03 22:56:44 132,608 —-a-w c:\winnt\system32\Setup\fxsocm.dll
+ 2008-04-14 00:11:54 132,608 —-a-w c:\winnt\system32\Setup\fxsocm.dll
- 2004-08-03 22:56:44 505,344 —-a-w c:\winnt\system32\Setup\iis.dll
+ 2008-04-14 00:11:54 505,344 —-a-w c:\winnt\system32\Setup\iis.dll
- 2001-08-23 12:00:00 115,712 —-a-w c:\winnt\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:54 123,392 —-a-w c:\winnt\system32\Setup\imsinsnt.dll
+ 2008-04-14 00:11:56 8,192 —-a-w c:\winnt\system32\Setup\koc.dll
- 2004-08-03 22:56:44 16,896 —-a-w c:\winnt\system32\Setup\medctroc.dll
+ 2008-04-14 00:11:56 16,896 —-a-w c:\winnt\system32\Setup\medctroc.dll
- 2001-08-23 12:00:00 82,432 —-a-w c:\winnt\system32\Setup\msdtcstp.dll
+ 2008-04-14 00:11:59 90,112 —-a-w c:\winnt\system32\Setup\msdtcstp.dll
- 2004-08-03 22:56:44 15,360 —-a-w c:\winnt\system32\Setup\msgrocm.dll
+ 2008-04-14 00:11:59 15,360 —-a-w c:\winnt\system32\Setup\msgrocm.dll
- 2004-08-03 22:56:44 169,984 —-a-w c:\winnt\system32\Setup\msmqocm.dll
+ 2008-04-14 00:12:00 170,496 —-a-w c:\winnt\system32\Setup\msmqocm.dll
- 2004-08-03 22:56:46 77,312 —-a-w c:\winnt\system32\Setup\netoc.dll
+ 2008-04-14 00:12:01 77,312 —-a-w c:\winnt\system32\Setup\netoc.dll
- 2004-08-03 22:56:46 62,976 —-a-w c:\winnt\system32\Setup\ntoc.dll
+ 2008-04-14 00:12:02 62,976 —-a-w c:\winnt\system32\Setup\ntoc.dll
- 2004-08-03 22:56:46 15,872 —-a-w c:\winnt\system32\Setup\ocgen.dll
+ 2008-04-14 00:12:02 15,360 —-a-w c:\winnt\system32\Setup\ocgen.dll
- 2004-08-03 22:56:46 17,408 —-a-w c:\winnt\system32\Setup\ocmsn.dll
+ 2008-04-14 00:12:02 17,408 —-a-w c:\winnt\system32\Setup\ocmsn.dll
- 2004-08-03 22:56:46 101,376 —-a-w c:\winnt\system32\Setup\setupqry.dll
+ 2008-04-14 00:12:05 101,376 —-a-w c:\winnt\system32\Setup\setupqry.dll
- 2004-08-03 22:56:48 33,792 —-a-w c:\winnt\system32\Setup\tabletoc.dll
+ 2008-04-14 00:12:07 33,792 —-a-w c:\winnt\system32\Setup\tabletoc.dll
- 2004-08-03 22:56:48 121,856 —-a-w c:\winnt\system32\Setup\tsoc.dll
+ 2008-04-14 00:12:07 130,048 —-a-w c:\winnt\system32\Setup\tsoc.dll
- 2004-08-03 22:56:46 983,552 —-a-w c:\winnt\system32\setupapi.dll
+ 2008-04-14 10:42:06 985,088 —-a-w c:\winnt\system32\setupapi.dll
+ 2008-04-14 00:12:35 32,768 ——w c:\winnt\system32\setupn.exe
- 2004-08-03 22:56:46 5,120 —-a-w c:\winnt\system32\sfc.dll
+ 2008-04-14 00:12:05 5,120 —-a-w c:\winnt\system32\sfc.dll
- 2004-08-03 22:56:46 140,288 —-a-w c:\winnt\system32\sfc_os.dll
+ 2008-04-14 00:12:05 140,288 —-a-w c:\winnt\system32\sfc_os.dll
- 2004-08-03 22:56:46 1,580,544 —-a-w c:\winnt\system32\sfcfiles.dll
+ 2008-04-14 00:12:05 1,614,848 —-a-w c:\winnt\system32\sfcfiles.dll
- 2004-08-03 22:56:28 549,376 —-a-w c:\winnt\system32\shdoclc.dll
+ 2008-04-13 17:03:19 549,376 —-a-w c:\winnt\system32\shdoclc.dll
- 2008-10-16 10:20:48 1,499,136 —-a-w c:\winnt\system32\shdocvw.dll
+ 2008-04-14 00:12:05 1,499,136 —-a-w c:\winnt\system32\shdocvw.dll
- 2007-10-26 03:34:01 8,460,288 —-a-w c:\winnt\system32\shell32.dll
+ 2008-06-17 19:02:19 8,461,312 —-a-w c:\winnt\system32\shell32.dll
- 2004-08-03 22:56:46 25,088 —-a-w c:\winnt\system32\shfolder.dll
+ 2008-04-14 00:12:05 25,088 —-a-w c:\winnt\system32\shfolder.dll
- 2004-08-03 22:56:46 68,096 —-a-w c:\winnt\system32\shgina.dll
+ 2008-04-14 00:12:05 68,096 —-a-w c:\winnt\system32\shgina.dll
- 2004-08-03 22:56:46 65,536 —-a-w c:\winnt\system32\shimeng.dll
+ 2008-04-14 00:12:05 65,024 —-a-w c:\winnt\system32\shimeng.dll
- 2004-08-03 22:56:46 438,272 —-a-w c:\winnt\system32\shimgvw.dll
+ 2008-04-14 00:12:05 438,272 —-a-w c:\winnt\system32\shimgvw.dll
- 2008-10-16 10:20:51 474,112 —-a-w c:\winnt\system32\shlwapi.dll
+ 2008-04-14 00:12:05 474,112 —-a-w c:\winnt\system32\shlwapi.dll
- 2004-08-03 22:56:46 151,552 —-a-w c:\winnt\system32\shmedia.dll
+ 2008-04-14 00:12:05 152,064 —-a-w c:\winnt\system32\shmedia.dll
- 2004-08-03 22:56:58 42,496 —-a-w c:\winnt\system32\shmgrate.exe
+ 2008-04-14 00:12:35 45,056 —-a-w c:\winnt\system32\shmgrate.exe
- 2004-08-03 22:56:58 77,824 —-a-w c:\winnt\system32\shrpubw.exe
+ 2008-04-14 00:12:35 77,824 —-a-w c:\winnt\system32\shrpubw.exe
- 2004-08-03 22:56:46 27,648 —-a-w c:\winnt\system32\shscrap.dll
+ 2008-04-14 00:12:05 27,648 —-a-w c:\winnt\system32\shscrap.dll
- 2006-12-19 21:50:10 135,168 —-a-w c:\winnt\system32\shsvcs.dll
+ 2008-04-14 00:12:05 135,168 —-a-w c:\winnt\system32\shsvcs.dll
- 2004-08-03 22:56:58 19,456 —-a-w c:\winnt\system32\shutdown.exe
+ 2008-04-14 00:12:35 19,456 —-a-w c:\winnt\system32\shutdown.exe
- 2004-08-03 22:56:46 13,312 —-a-w c:\winnt\system32\sigtab.dll
+ 2008-04-14 00:12:05 13,312 —-a-w c:\winnt\system32\sigtab.dll
- 2004-08-03 22:56:58 70,144 —-a-w c:\winnt\system32\sigverif.exe
+ 2008-04-14 00:12:35 70,144 —-a-w c:\winnt\system32\sigverif.exe
- 2004-08-03 22:56:58 26,112 —-a-w c:\winnt\system32\skeys.exe
+ 2008-04-14 00:12:35 26,112 —-a-w c:\winnt\system32\skeys.exe
- 2004-08-03 22:56:46 25,088 —-a-w c:\winnt\system32\slayerxp.dll
+ 2008-04-14 00:12:06 25,088 —-a-w c:\winnt\system32\slayerxp.dll
- 2004-08-03 22:56:46 98,304 —-a-w c:\winnt\system32\slbiop.dll
+ 2008-04-14 00:12:06 98,304 —-a-w c:\winnt\system32\slbiop.dll
+ 2008-04-14 00:12:06 73,832 ——w c:\winnt\system32\slcoinst.dll
+ 2008-04-14 00:12:06 286,792 ——w c:\winnt\system32\slextspk.dll
+ 2008-04-14 00:12:06 188,508 ——w c:\winnt\system32\slgen.dll
+ 2008-04-14 00:12:35 32,866 ——w c:\winnt\system32\slrundll.exe
+ 2008-04-14 00:12:35 73,796 ——w c:\winnt\system32\slserv.exe
- 2004-08-03 22:56:58 8,192 —-a-w c:\winnt\system32\smbinst.exe
+ 2008-04-14 00:12:35 8,192 —-a-w c:\winnt\system32\smbinst.exe
- 2004-08-03 22:56:46 363,008 —-a-w c:\winnt\system32\smlogcfg.dll
+ 2008-04-14 00:12:06 362,496 —-a-w c:\winnt\system32\smlogcfg.dll
- 2004-08-03 22:56:58 89,600 —-a-w c:\winnt\system32\smlogsvc.exe
+ 2008-04-14 00:12:35 89,600 —-a-w c:\winnt\system32\smlogsvc.exe
- 2004-08-03 22:56:58 50,688 —-a-w c:\winnt\system32\smss.exe
+ 2008-04-14 00:12:36 50,688 —-a-w c:\winnt\system32\smss.exe
+ 2008-04-14 00:12:06 10,752 ——w c:\winnt\system32\smtpapi.dll
- 2004-08-03 22:56:58 131,584 —-a-w c:\winnt\system32\sndrec32.exe
+ 2008-04-14 00:12:36 131,584 —-a-w c:\winnt\system32\sndrec32.exe
- 2004-08-03 22:56:46 18,944 —-a-w c:\winnt\system32\snmpapi.dll
+ 2008-04-14 00:12:06 18,944 —-a-w c:\winnt\system32\snmpapi.dll
- 2004-08-03 22:56:46 182,272 —-a-w c:\winnt\system32\snmpsnap.dll
+ 2008-04-14 00:12:06 182,272 —-a-w c:\winnt\system32\snmpsnap.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\winnt\system32\SoftwareDistribution\Setup\ServiceStartup\wuapi.dll\7.2.6001.788\wuapi.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\winnt\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\winnt\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2001-08-23 12:00:00 23,552 —-a-w c:\winnt\system32\sort.exe
+ 2008-04-14 00:12:36 24,576 —-a-w c:\winnt\system32\sort.exe
+ 2008-04-14 00:12:36 7,680 —-a-w c:\winnt\system32\spdwnwxp.exe
- 2004-08-03 20:59:36 12,800 —-a-w c:\winnt\system32\spiisupd.exe
+ 2008-04-13 18:43:31 12,800 —-a-w c:\winnt\system32\spiisupd.exe
- 2007-11-30 12:39:22 17,272 ——w c:\winnt\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w c:\winnt\system32\spmsg.dll
- 2004-08-03 22:56:58 11,776 —-a-w c:\winnt\system32\spnpinst.exe
+ 2008-04-14 10:42:38 11,264 —-a-w c:\winnt\system32\spnpinst.exe
- 2007-10-16 10:31:16 728,576 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\PS5UI.DLL
+ 2008-04-14 00:12:03 728,576 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\ps5ui.dll
- 2007-10-16 10:31:16 543,232 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL
+ 2008-04-14 00:12:03 543,232 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\pscript5.dll
- 2008-07-06 12:06:10 373,248 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\unidrv.dll
+ 2008-04-14 00:12:07 373,248 —-a-w c:\winnt\system32\spool\drivers\w32x86\3\unidrv.dll
- 2004-08-03 22:56:46 74,752 —-a-w c:\winnt\system32\spoolss.dll
+ 2008-04-14 00:12:06 75,264 —-a-w c:\winnt\system32\spoolss.dll
- 2005-06-10 23:53:32 57,856 —-a-w c:\winnt\system32\spoolsv.exe
+ 2008-04-14 00:12:36 57,856 —-a-w c:\winnt\system32\spoolsv.exe
- 2007-11-30 11:18:51 26,488 —-a-w c:\winnt\system32\spupdsvc.exe
+ 2007-08-11 01:46:18 26,488 —-a-w c:\winnt\system32\spupdsvc.exe
+ 2008-04-14 00:12:36 20,992 ——w c:\winnt\system32\spupdwxp.exe
- 2004-08-03 22:56:46 442,368 —-a-w c:\winnt\system32\sqlsrv32.dll
+ 2008-04-14 00:12:06 442,368 —-a-w c:\winnt\system32\sqlsrv32.dll
- 2004-08-03 22:56:46 180,800 —-a-w c:\winnt\system32\sqlunirl.dll
+ 2008-04-14 00:12:06 180,800 —-a-w c:\winnt\system32\sqlunirl.dll
- 2004-08-03 22:56:46 67,584 —-a-w c:\winnt\system32\srclient.dll
+ 2008-04-14 00:12:07 67,584 —-a-w c:\winnt\system32\srclient.dll
- 2004-08-03 22:56:46 239,104 —-a-w c:\winnt\system32\srrstr.dll
+ 2008-04-14 00:12:07 239,104 —-a-w c:\winnt\system32\srrstr.dll
- 2004-08-03 22:56:46 170,496 —-a-w c:\winnt\system32\srsvc.dll
+ 2008-04-14 00:12:07 171,008 —-a-w c:\winnt\system32\srsvc.dll
- 2004-12-07 19:32:34 96,768 —-a-w c:\winnt\system32\srvsvc.dll
+ 2008-04-14 00:12:07 96,768 —-a-w c:\winnt\system32\srvsvc.dll
- 2004-08-03 22:56:58 704,512 —-a-w c:\winnt\system32\ss3dfo.scr
+ 2008-04-14 00:12:43 704,512 —-a-w c:\winnt\system32\ss3dfo.scr
- 2004-08-03 22:56:58 19,968 —-a-w c:\winnt\system32\ssbezier.scr
+ 2008-04-14 00:12:43 19,968 —-a-w c:\winnt\system32\ssbezier.scr
- 2004-08-03 22:56:46 34,816 —-a-w c:\winnt\system32\ssdpapi.dll
+ 2008-04-14 00:12:07 34,816 —-a-w c:\winnt\system32\ssdpapi.dll
- 2004-08-03 22:56:46 71,680 —-a-w c:\winnt\system32\ssdpsrv.dll
+ 2008-04-14 00:12:07 71,680 —-a-w c:\winnt\system32\ssdpsrv.dll
- 2004-08-03 22:56:58 393,216 —-a-w c:\winnt\system32\ssflwbox.scr
+ 2008-04-14 00:12:43 393,216 —-a-w c:\winnt\system32\ssflwbox.scr
- 2004-08-03 22:56:58 20,992 —-a-w c:\winnt\system32\ssmarque.scr
+ 2008-04-14 00:12:44 20,992 —-a-w c:\winnt\system32\ssmarque.scr
- 2004-08-03 22:56:58 47,104 —-a-w c:\winnt\system32\ssmypics.scr
+ 2008-04-14 00:12:44 47,104 —-a-w c:\winnt\system32\ssmypics.scr
- 2004-08-03 22:56:58 18,944 —-a-w c:\winnt\system32\ssmyst.scr
+ 2008-04-14 00:12:44 18,944 —-a-w c:\winnt\system32\ssmyst.scr
- 2004-08-03 22:56:58 610,304 —-a-w c:\winnt\system32\sspipes.scr
+ 2008-04-14 00:12:44 610,304 —-a-w c:\winnt\system32\sspipes.scr
- 2004-08-03 22:56:58 14,336 —-a-w c:\winnt\system32\ssstars.scr
+ 2008-04-14 00:12:44 14,336 —-a-w c:\winnt\system32\ssstars.scr
- 2004-08-03 22:56:58 679,936 —-a-w c:\winnt\system32\sstext3d.scr
+ 2008-04-14 00:12:44 679,936 —-a-w c:\winnt\system32\sstext3d.scr
- 2004-08-03 22:56:46 8,192 —-a-w c:\winnt\system32\staxmem.dll
+ 2008-04-14 00:12:07 8,192 —-a-w c:\winnt\system32\staxmem.dll
- 2001-08-23 12:00:00 54,272 —-a-w c:\winnt\system32\stclient.dll
+ 2008-04-14 00:12:07 59,392 —-a-w c:\winnt\system32\stclient.dll
- 2004-08-03 22:56:46 67,584 —-a-w c:\winnt\system32\sti.dll
+ 2008-04-14 00:12:07 68,096 —-a-w c:\winnt\system32\sti.dll
- 2004-08-03 22:56:46 136,704 —-a-w c:\winnt\system32\sti_ci.dll
+ 2008-04-14 00:12:07 136,704 —-a-w c:\winnt\system32\sti_ci.dll
- 2004-08-03 22:56:58 14,848 —-a-w c:\winnt\system32\stimon.exe
+ 2008-04-14 00:12:36 14,848 —-a-w c:\winnt\system32\stimon.exe
- 2004-08-03 22:56:46 121,856 —-a-w c:\winnt\system32\stobject.dll
+ 2008-04-14 00:12:07 121,856 —-a-w c:\winnt\system32\stobject.dll
- 2004-08-04 00:56:46 74,752 —-a-w c:\winnt\system32\storprop.dll
+ 2008-04-14 00:12:07 74,752 —-a-w c:\winnt\system32\storprop.dll
- 2008-10-03 10:15:47 247,326 —-a-w c:\winnt\system32\strmdll.dll
+ 2008-10-03 10:02:42 247,326 —-a-w c:\winnt\system32\strmdll.dll
- 2004-08-03 22:56:46 75,776 —-a-w c:\winnt\system32\strmfilt.dll
+ 2008-04-14 00:12:07 75,776 —-a-w c:\winnt\system32\strmfilt.dll
- 2004-08-03 22:56:58 14,336 —-a-w c:\winnt\system32\svchost.exe
+ 2008-04-14 00:12:36 14,336 —-a-w c:\winnt\system32\svchost.exe
- 2006-10-19 13:56:32 713,216 —-a-w c:\winnt\system32\sxs.dll
+ 2008-04-14 00:12:07 713,216 —-a-w c:\winnt\system32\sxs.dll
- 2004-08-03 22:56:48 57,856 —-a-w c:\winnt\system32\synceng.dll
+ 2008-04-14 00:12:07 57,856 —-a-w c:\winnt\system32\synceng.dll
- 2004-08-03 22:56:48 191,488 —-a-w c:\winnt\system32\syncui.dll
+ 2008-04-14 00:12:07 191,488 —-a-w c:\winnt\system32\syncui.dll
- 2004-08-03 22:56:58 105,984 —-a-w c:\winnt\system32\sysocmgr.exe
+ 2008-04-14 00:12:37 106,496 —-a-w c:\winnt\system32\sysocmgr.exe
- 2004-08-03 22:56:48 984,576 —-a-w c:\winnt\system32\syssetup.dll
+ 2008-04-14 00:12:07 990,208 —-a-w c:\winnt\system32\syssetup.dll
- 2001-08-23 12:00:00 68,096 —-a-w c:\winnt\system32\systeminfo.exe
+ 2008-04-14 00:12:36 71,680 —-a-w c:\winnt\system32\systeminfo.exe
- 2005-10-17 21:14:46 118,272 —-a-w c:\winnt\system32\t2embed.dll
+ 2008-04-14 00:12:07 117,760 —-a-w c:\winnt\system32\t2embed.dll
- 2004-08-03 22:56:48 858,624 —-a-w c:\winnt\system32\tapi3.dll
+ 2008-04-14 00:12:07 858,624 —-a-w c:\winnt\system32\tapi3.dll
- 2004-08-03 22:56:48 181,760 —-a-w c:\winnt\system32\tapi32.dll
+ 2008-04-14 00:12:07 181,760 —-a-w c:\winnt\system32\tapi32.dll
- 2005-07-08 16:27:56 249,344 —-a-w c:\winnt\system32\tapisrv.dll
+ 2008-04-14 00:12:07 249,856 —-a-w c:\winnt\system32\tapisrv.dll
- 2001-08-23 12:00:00 72,192 —-a-w c:\winnt\system32\taskkill.exe
+ 2008-04-14 00:12:37 76,288 —-a-w c:\winnt\system32\taskkill.exe
- 2001-08-23 12:00:00 72,192 —-a-w c:\winnt\system32\tasklist.exe
+ 2008-04-14 00:12:37 77,824 —-a-w c:\winnt\system32\tasklist.exe
- 2004-08-03 22:56:58 135,680 —-a-w c:\winnt\system32\taskmgr.exe
+ 2008-04-14 00:12:37 135,680 —-a-w c:\winnt\system32\taskmgr.exe
- 2004-08-03 22:56:48 14,848 —-a-w c:\winnt\system32\tcpmib.dll
+ 2008-04-14 00:12:07 14,848 —-a-w c:\winnt\system32\tcpmib.dll
- 2004-08-03 22:56:48 45,568 —-a-w c:\winnt\system32\tcpmon.dll
+ 2008-04-14 00:12:07 45,568 —-a-w c:\winnt\system32\tcpmon.dll
- 2004-08-03 22:56:48 45,568 —-a-w c:\winnt\system32\tcpmonui.dll
+ 2008-04-14 00:12:07 45,568 —-a-w c:\winnt\system32\tcpmonui.dll
- 2005-05-10 23:45:48 75,776 —-a-w c:\winnt\system32\telnet.exe
+ 2008-04-14 00:12:37 75,776 —-a-w c:\winnt\system32\telnet.exe
- 2004-08-03 22:56:48 358,400 —-a-w c:\winnt\system32\termmgr.dll
+ 2008-04-14 00:12:07 358,400 —-a-w c:\winnt\system32\termmgr.dll
- 2004-08-03 22:56:48 295,424 —-a-w c:\winnt\system32\termsrv.dll
+ 2008-04-14 00:12:07 295,424 —-a-w c:\winnt\system32\termsrv.dll
- 2004-08-03 22:56:48 385,536 —-a-w c:\winnt\system32\themeui.dll
+ 2008-04-14 00:12:07 385,536 —-a-w c:\winnt\system32\themeui.dll
- 2004-08-03 22:56:58 61,440 —-a-w c:\winnt\system32\tlntadmn.exe
+ 2008-04-14 00:12:37 61,440 —-a-w c:\winnt\system32\tlntadmn.exe
- 2004-08-03 22:56:58 78,336 —-a-w c:\winnt\system32\tlntsess.exe
+ 2008-04-14 00:12:37 78,336 —-a-w c:\winnt\system32\tlntsess.exe
- 2004-08-03 22:56:58 73,216 —-a-w c:\winnt\system32\tlntsvr.exe
+ 2008-04-14 00:12:38 73,216 —-a-w c:\winnt\system32\tlntsvr.exe
- 2004-08-03 22:56:48 7,168 —-a-w c:\winnt\system32\tlntsvrp.dll
+ 2008-04-14 00:12:07 7,168 —-a-w c:\winnt\system32\tlntsvrp.dll
- 2004-08-03 22:56:58 347,136 —-a-w c:\winnt\system32\tourstart.exe
+ 2008-04-14 00:12:38 347,136 —-a-w c:\winnt\system32\tourstart.exe
- 2004-08-03 22:56:58 259,584 —-a-w c:\winnt\system32\tracerpt.exe
+ 2008-04-14 00:12:38 259,584 —-a-w c:\winnt\system32\tracerpt.exe
- 2004-08-03 22:56:58 12,288 —-a-w c:\winnt\system32\tracert.exe
+ 2008-04-14 00:12:38 12,288 —-a-w c:\winnt\system32\tracert.exe
- 2001-08-23 12:00:00 11,264 —-a-w c:\winnt\system32\tree.com
+ 2008-04-14 00:12:42 12,800 —-a-w c:\winnt\system32\tree.com
- 2004-08-03 22:56:48 90,624 —-a-w c:\winnt\system32\trkwks.dll
+ 2008-04-14 00:12:07 90,112 —-a-w c:\winnt\system32\trkwks.dll
- 2004-08-03 22:56:48 93,696 —-a-w c:\winnt\system32\tscfgwmi.dll
+ 2008-04-14 00:12:07 93,696 —-a-w c:\winnt\system32\tscfgwmi.dll
- 2004-08-03 23:01:08 12,168 —-a-w c:\winnt\system32\tsddd.dll
+ 2008-04-14 00:13:21 12,168 —-a-w c:\winnt\system32\tsddd.dll
+ 2008-04-14 00:12:07 53,248 ——w c:\winnt\system32\tsgqec.dll
+ 2008-04-14 00:12:07 50,688 ——w c:\winnt\system32\tspkg.dll
- 2004-08-03 22:56:48 44,032 —-a-w c:\winnt\system32\twext.dll
+ 2008-04-14 00:12:07 57,856 —-a-w c:\winnt\system32\twext.dll
- 2005-07-26 04:39:49 101,376 —-a-w c:\winnt\system32\txflog.dll
+ 2008-04-14 00:12:07 101,376 —-a-w c:\winnt\system32\txflog.dll
- 2008-10-22 09:47:07 62,976 ——w c:\winnt\system32\tzchange.exe
+ 2008-04-14 00:12:38 60,416 ——w c:\winnt\system32\tzchange.exe
- 2004-08-03 22:56:48 25,600 —-a-w c:\winnt\system32\udhisapi.dll
+ 2008-04-14 00:12:07 26,624 —-a-w c:\winnt\system32\udhisapi.dll
- 2004-08-03 22:56:48 275,456 —-a-w c:\winnt\system32\ulib.dll
+ 2008-04-14 00:12:07 275,456 —-a-w c:\winnt\system32\ulib.dll
- 2004-08-03 22:56:48 35,840 —-a-w c:\winnt\system32\umandlg.dll
+ 2008-04-14 00:12:07 35,840 —-a-w c:\winnt\system32\umandlg.dll
- 2005-08-23 03:35:42 123,392 —-a-w c:\winnt\system32\umpnpmgr.dll
+ 2008-04-14 00:12:07 123,392 —-a-w c:\winnt\system32\umpnpmgr.dll
- 2004-08-03 22:56:48 74,240 —-a-w c:\winnt\system32\unimdmat.dll
+ 2008-04-14 00:12:07 74,240 —-a-w c:\winnt\system32\unimdmat.dll
- 2004-08-03 22:56:48 13,824 —-a-w c:\winnt\system32\uniplat.dll
+ 2008-04-14 00:12:07 13,824 —-a-w c:\winnt\system32\uniplat.dll
- 2004-08-03 22:56:48 316,416 —-a-w c:\winnt\system32\untfs.dll
+ 2008-04-14 00:12:07 316,416 —-a-w c:\winnt\system32\untfs.dll
- 2004-08-03 22:56:48 132,608 —-a-w c:\winnt\system32\upnp.dll
+ 2008-04-14 00:12:08 133,632 —-a-w c:\winnt\system32\upnp.dll
- 2004-08-03 22:56:58 16,896 —-a-w c:\winnt\system32\upnpcont.exe
+ 2008-04-14 00:12:38 16,896 —-a-w c:\winnt\system32\upnpcont.exe
- 2007-02-05 20:17:02 185,344 —-a-w c:\winnt\system32\upnphost.dll
+ 2008-04-14 00:12:08 185,856 —-a-w c:\winnt\system32\upnphost.dll
- 2004-08-03 22:56:48 239,616 —-a-w c:\winnt\system32\upnpui.dll
+ 2008-04-14 00:12:08 239,616 —-a-w c:\winnt\system32\upnpui.dll
- 2004-08-03 22:56:58 18,432 —-a-w c:\winnt\system32\ups.exe
+ 2008-04-14 00:12:38 18,432 —-a-w c:\winnt\system32\ups.exe
- 2008-10-16 20:38:39 105,984 —-a-w c:\winnt\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w c:\winnt\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 —-a-w c:\winnt\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\winnt\system32\urlmon.dll
- 2004-08-03 22:56:48 16,896 —-a-w c:\winnt\system32\usbmon.dll
+ 2008-04-14 00:12:08 16,896 —-a-w c:\winnt\system32\usbmon.dll
- 2004-08-04 04:56:48 74,240 —-a-w c:\winnt\system32\usbui.dll
+ 2008-04-14 00:12:08 74,240 —-a-w c:\winnt\system32\usbui.dll
- 2007-03-08 15:36:28 577,536 —-a-w c:\winnt\system32\user32.dll
+ 2008-04-14 00:12:08 578,560 —-a-w c:\winnt\system32\user32.dll
- 2004-08-03 22:56:48 723,456 —-a-w c:\winnt\system32\userenv.dll
+ 2008-04-14 00:12:08 727,040 —-a-w c:\winnt\system32\userenv.dll
- 2009-02-28 05:40:09 104,960 —-a-w c:\winnt\system32\userinit.exe
+ 2008-04-14 00:12:38 26,112 —-a-w c:\winnt\system32\userinit.exe
+ 2008-04-13 16:44:16 17,920 ——w c:\winnt\system32\usmt\cobramsg.dll
- 2004-08-03 22:56:44 123,904 —-a-w c:\winnt\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 133,120 —-a-w c:\winnt\system32\usmt\guitrn.dll
+ 2008-04-14 00:11:54 115,200 ——w c:\winnt\system32\usmt\guitrna.dll
- 2004-08-03 22:56:44 4,096 —-a-w c:\winnt\system32\usmt\iconlib.dll
+ 2008-04-13 16:44:29 2,560 —-a-w c:\winnt\system32\usmt\iconlib.dll
- 2004-08-03 22:56:44 19,968 —-a-w c:\winnt\system32\usmt\log.dll
+ 2008-04-14 00:11:56 19,968 —-a-w c:\winnt\system32\usmt\log.dll
- 2004-08-03 22:56:44 201,216 —-a-w c:\winnt\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 274,432 —-a-w c:\winnt\system32\usmt\migism.dll
+ 2008-04-14 00:11:57 261,120 ——w c:\winnt\system32\usmt\migisma.dll
- 2004-08-03 22:56:52 103,424 —-a-w c:\winnt\system32\usmt\migload.exe
+ 2008-04-14 00:12:25 103,936 —-a-w c:\winnt\system32\usmt\migload.exe
- 2004-08-03 22:56:52 240,128 —-a-w c:\winnt\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 245,248 —-a-w c:\winnt\system32\usmt\migwiz.exe
+ 2008-04-14 00:12:25 241,152 ——w c:\winnt\system32\usmt\migwiza.exe
- 2004-08-03 22:56:46 202,752 —-a-w c:\winnt\system32\usmt\script.dll
+ 2008-04-14 00:12:05 215,552 —-a-w c:\winnt\system32\usmt\script.dll
+ 2008-04-14 00:12:05 199,680 ——w c:\winnt\system32\usmt\scripta.dll
- 2004-08-03 22:56:48 168,960 —-a-w c:\winnt\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 193,024 —-a-w c:\winnt\system32\usmt\sysmod.dll
+ 2008-04-14 00:12:07 173,568 ——w c:\winnt\system32\usmt\sysmoda.dll
- 2004-08-03 22:56:48 406,528 —-a-w c:\winnt\system32\usp10.dll
+ 2008-04-14 00:12:08 406,016 —-a-w c:\winnt\system32\usp10.dll
- 2004-08-03 22:56:58 50,176 —-a-w c:\winnt\system32\utilman.exe
+ 2008-04-14 00:12:38 50,176 —-a-w c:\winnt\system32\utilman.exe
- 2004-08-03 22:56:48 218,624 —-a-w c:\winnt\system32\uxtheme.dll
+ 2008-04-14 00:12:08 218,624 —-a-w c:\winnt\system32\uxtheme.dll
- 2004-08-03 22:56:48 30,749 —-a-w c:\winnt\system32\vbajet32.dll
+ 2008-04-14 00:12:08 30,749 —-a-w c:\winnt\system32\vbajet32.dll
- 2007-08-13 23:54:10 413,696 —-a-w c:\winnt\system32\vbscript.dll
+ 2008-05-09 10:53:40 430,080 —-a-w c:\winnt\system32\vbscript.dll
- 2004-08-03 22:56:48 26,112 —-a-w c:\winnt\system32\vdmdbg.dll
+ 2008-04-14 00:12:08 26,112 —-a-w c:\winnt\system32\vdmdbg.dll
- 2004-08-03 22:56:48 51,712 —-a-w c:\winnt\system32\vdmredir.dll
+ 2008-04-14 00:12:08 51,712 —-a-w c:\winnt\system32\vdmredir.dll
- 2006-03-17 01:05:35 28,672 ——w c:\winnt\system32\verclsid.exe
+ 2008-04-14 00:12:38 28,672 ——w c:\winnt\system32\verclsid.exe
- 2001-08-23 12:00:00 13,312 —-a-w c:\winnt\system32\verifier.dll
+ 2008-04-14 00:12:08 26,624 —-a-w c:\winnt\system32\verifier.dll
- 2004-08-03 22:56:48 18,944 —-a-w c:\winnt\system32\version.dll
+ 2008-04-14 00:12:08 18,944 —-a-w c:\winnt\system32\version.dll
- 2004-08-04 05:56:48 53,760 —-a-w c:\winnt\system32\vfwwdm32.dll
+ 2008-04-14 00:12:08 53,760 —-a-w c:\winnt\system32\vfwwdm32.dll
- 2004-08-03 22:56:48 430,592 —-a-w c:\winnt\system32\vssapi.dll
+ 2008-04-14 00:12:08 430,592 —-a-w c:\winnt\system32\vssapi.dll
- 2004-08-03 22:56:58 289,792 —-a-w c:\winnt\system32\vssvc.exe
+ 2008-04-14 00:12:38 289,792 —-a-w c:\winnt\system32\vssvc.exe
- 2004-08-03 22:56:48 174,592 —-a-w c:\winnt\system32\w32time.dll
+ 2008-04-14 00:12:08 175,104 —-a-w c:\winnt\system32\w32time.dll
- 2004-08-03 22:56:48 15,872 —-a-w c:\winnt\system32\w3ssl.dll
+ 2008-04-14 00:12:08 15,872 —-a-w c:\winnt\system32\w3ssl.dll
- 2004-08-03 21:07:34 17,664 —-a-w c:\winnt\system32\watchdog.sys
+ 2008-04-13 18:44:59 17,664 —-a-w c:\winnt\system32\watchdog.sys
- 2001-08-23 12:00:00 208,896 —-a-w c:\winnt\system32\wavemsp.dll
+ 2008-04-14 00:12:08 215,552 —-a-w c:\winnt\system32\wavemsp.dll
- 2006-03-09 05:14:53 1,353,216 —-a-w c:\winnt\system32\wbem\cimwin32.dll
+ 2008-04-14 00:11:50 1,358,848 —-a-w c:\winnt\system32\wbem\cimwin32.dll
- 2004-08-03 22:56:44 45,568 —-a-w c:\winnt\system32\wbem\CmdEvTgProv.dll
+ 2008-04-14 00:11:53 45,056 —-a-w c:\winnt\system32\wbem\cmdevtgprov.dll
- 2004-08-03 22:56:44 247,808 —-a-w c:\winnt\system32\wbem\esscli.dll
+ 2008-04-14 00:11:53 247,808 —-a-w c:\winnt\system32\wbem\esscli.dll
- 2004-08-03 22:56:44 22,016 —-a-w c:\winnt\system32\wbem\evntrprv.dll
+ 2008-04-14 00:11:53 21,504 —-a-w c:\winnt\system32\wbem\evntrprv.dll
- 2004-08-03 22:56:44 472,064 —-a-w c:\winnt\system32\wbem\fastprox.dll
+ 2008-04-14 00:11:53 472,064 —-a-w c:\winnt\system32\wbem\fastprox.dll
- 2004-08-03 22:56:44 185,856 —-a-w c:\winnt\system32\wbem\framedyn.dll
+ 2008-04-14 00:11:53 185,344 —-a-w c:\winnt\system32\wbem\framedyn.dll
- 2004-08-03 22:56:44 24,576 —-a-w c:\winnt\system32\wbem\krnlprov.dll
+ 2008-04-14 00:11:56 24,576 —-a-w c:\winnt\system32\wbem\krnlprov.dll
- 2004-08-03 22:56:52 16,384 —-a-w c:\winnt\system32\wbem\mofcomp.exe
+ 2008-04-14 00:12:26 16,384 —-a-w c:\winnt\system32\wbem\mofcomp.exe
- 2004-08-03 22:56:44 123,904 —-a-w c:\winnt\system32\wbem\mofd.dll
+ 2008-04-14 00:11:57 123,904 —-a-w c:\winnt\system32\wbem\mofd.dll
- 2004-08-03 22:56:46 47,104 —-a-w c:\winnt\system32\wbem\ncprov.dll
+ 2008-04-14 00:12:01 47,104 —-a-w c:\winnt\system32\wbem\ncprov.dll
- 2004-08-03 22:56:46 212,992 —-a-w c:\winnt\system32\wbem\ntevt.dll
+ 2008-04-14 00:12:02 212,992 —-a-w c:\winnt\system32\wbem\ntevt.dll
- 2004-08-03 22:56:46 92,672 —-a-w c:\winnt\system32\wbem\policman.dll
+ 2008-04-14 00:12:02 92,672 —-a-w c:\winnt\system32\wbem\policman.dll
- 2004-08-03 22:56:46 237,056 —-a-w c:\winnt\system32\wbem\provthrd.dll
+ 2008-04-14 00:12:03 237,056 —-a-w c:\winnt\system32\wbem\provthrd.dll
- 2007-05-14 12:51:32 178,176 —-a-w c:\winnt\system32\wbem\repdrvfs.dll
+ 2008-04-14 00:12:04 178,176 —-a-w c:\winnt\system32\wbem\repdrvfs.dll
- 2004-08-03 22:56:56 36,864 —-a-w c:\winnt\system32\wbem\scrcons.exe
+ 2008-04-14 00:12:34 36,352 —-a-w c:\winnt\system32\wbem\scrcons.exe
- 2004-08-03 22:56:46 86,528 —-a-w c:\winnt\system32\wbem\stdprov.dll
+ 2008-04-14 00:12:07 86,528 —-a-w c:\winnt\system32\wbem\stdprov.dll
- 2004-08-03 22:56:48 131,584 —-a-w c:\winnt\system32\wbem\viewprov.dll
+ 2008-04-14 00:12:08 131,584 —-a-w c:\winnt\system32\wbem\viewprov.dll
- 2004-08-03 22:56:48 196,608 —-a-w c:\winnt\system32\wbem\wbemcntl.dll
+ 2008-04-14 00:12:08 196,608 —-a-w c:\winnt\system32\wbem\wbemcntl.dll
- 2004-08-03 22:56:48 214,528 —-a-w c:\winnt\system32\wbem\wbemcomn.dll
+ 2008-04-14 00:12:08 214,528 —-a-w c:\winnt\system32\wbem\wbemcomn.dll
- 2004-08-03 22:56:48 71,680 —-a-w c:\winnt\system32\wbem\wbemcons.dll
+ 2008-04-14 00:12:08 71,680 —-a-w c:\winnt\system32\wbem\wbemcons.dll
- 2004-08-03 22:56:48 530,944 —-a-w c:\winnt\system32\wbem\wbemcore.dll
+ 2008-04-14 00:12:08 531,456 —-a-w c:\winnt\system32\wbem\wbemcore.dll
- 2004-08-03 22:56:48 178,176 —-a-w c:\winnt\system32\wbem\wbemdisp.dll
+ 2008-04-14 00:12:08 178,176 —-a-w c:\winnt\system32\wbem\wbemdisp.dll
- 2004-08-03 22:56:48 273,920 —-a-w c:\winnt\system32\wbem\wbemess.dll
+ 2008-04-14 00:12:08 273,920 —-a-w c:\winnt\system32\wbem\wbemess.dll
- 2004-08-03 22:56:48 43,008 —-a-w c:\winnt\system32\wbem\wbemperf.dll
+ 2008-04-14 00:12:08 43,008 —-a-w c:\winnt\system32\wbem\wbemperf.dll
- 2004-08-03 22:56:48 18,944 —-a-w c:\winnt\system32\wbem\wbemprox.dll
+ 2008-04-14 00:12:08 18,944 —-a-w c:\winnt\system32\wbem\wbemprox.dll
- 2004-08-03 22:56:48 43,520 —-a-w c:\winnt\system32\wbem\wbemsvc.dll
+ 2008-04-14 00:12:08 43,520 —-a-w c:\winnt\system32\wbem\wbemsvc.dll
- 2004-08-03 22:56:58 116,224 —-a-w c:\winnt\system32\wbem\wbemtest.exe
+ 2008-04-14 00:12:39 116,224 —-a-w c:\winnt\system32\wbem\wbemtest.exe
- 2004-08-03 22:56:48 197,120 —-a-w c:\winnt\system32\wbem\wbemupgd.dll
+ 2008-04-14 00:12:08 197,120 —-a-w c:\winnt\system32\wbem\wbemupgd.dll
- 2004-08-03 22:56:58 196,608 —-a-w c:\winnt\system32\wbem\wmiadap.exe
+ 2008-04-14 00:12:40 196,608 —-a-w c:\winnt\system32\wbem\wmiadap.exe
- 2004-08-03 22:56:36 6,656 —-a-w c:\winnt\system32\wbem\wmiapres.dll
+ 2008-04-13 17:10:20 6,656 —-a-w c:\winnt\system32\wbem\wmiapres.dll
- 2004-08-03 22:56:48 89,088 —-a-w c:\winnt\system32\wbem\wmiaprpl.dll
+ 2008-04-14 00:12:09 88,576 —-a-w c:\winnt\system32\wbem\wmiaprpl.dll
- 2004-08-03 22:56:58 126,464 —-a-w c:\winnt\system32\wbem\wmiapsrv.exe
+ 2008-04-14 00:12:40 126,464 —-a-w c:\winnt\system32\wbem\wmiapsrv.exe
- 2004-08-03 22:56:58 358,912 —-a-w c:\winnt\system32\wbem\wmic.exe
+ 2008-04-14 00:12:40 358,912 —-a-w c:\winnt\system32\wbem\wmic.exe
- 2004-08-03 22:56:48 60,928 —-a-w c:\winnt\system32\wbem\wmicookr.dll
+ 2008-04-14 00:12:09 60,928 —-a-w c:\winnt\system32\wbem\wmicookr.dll
- 2004-08-03 22:56:48 140,800 —-a-w c:\winnt\system32\wbem\wmidcprv.dll
+ 2008-04-14 00:12:09 140,800 —-a-w c:\winnt\system32\wbem\wmidcprv.dll
- 2004-08-03 22:56:48 156,672 —-a-w c:\winnt\system32\wbem\wmipcima.dll
+ 2008-04-14 00:12:09 156,672 —-a-w c:\winnt\system32\wbem\wmipcima.dll
- 2004-08-03 22:56:48 132,096 —-a-w c:\winnt\system32\wbem\wmipdskq.dll
+ 2008-04-14 00:12:09 132,096 —-a-w c:\winnt\system32\wbem\wmipdskq.dll
- 2004-08-03 22:56:48 62,464 —-a-w c:\winnt\system32\wbem\wmipiprt.dll
+ 2008-04-14 00:12:09 61,952 —-a-w c:\winnt\system32\wbem\wmipiprt.dll
- 2004-08-03 22:56:48 62,976 —-a-w c:\winnt\system32\wbem\wmipjobj.dll
+ 2008-04-14 00:12:09 62,464 —-a-w c:\winnt\system32\wbem\wmipjobj.dll
- 2004-08-03 22:56:48 144,896 —-a-w c:\winnt\system32\wbem\wmiprov.dll
+ 2008-04-14 00:12:09 144,896 —-a-w c:\winnt\system32\wbem\wmiprov.dll
- 2004-08-03 22:56:48 437,248 —-a-w c:\winnt\system32\wbem\wmiprvsd.dll
+ 2008-04-14 00:12:09 437,248 —-a-w c:\winnt\system32\wbem\wmiprvsd.dll
- 2004-08-03 22:56:58 218,112 —-a-w c:\winnt\system32\wbem\wmiprvse.exe
+ 2008-04-14 00:12:40 218,112 —-a-w c:\winnt\system32\wbem\wmiprvse.exe
- 2004-08-03 22:56:48 41,472 —-a-w c:\winnt\system32\wbem\wmipsess.dll
+ 2008-04-14 00:12:09 41,472 —-a-w c:\winnt\system32\wbem\wmipsess.dll
- 2004-08-03 22:56:48 144,896 —-a-w c:\winnt\system32\wbem\wmisvc.dll
+ 2008-04-14 00:12:09 144,896 —-a-w c:\winnt\system32\wbem\wmisvc.dll
- 2004-08-03 22:56:48 95,232 —-a-w c:\winnt\system32\wbem\wmiutils.dll
+ 2008-04-14 00:12:09 95,232 —-a-w c:\winnt\system32\wbem\wmiutils.dll
- 2004-08-03 22:56:48 49,152 —-a-w c:\winnt\system32\wdigest.dll
+ 2008-04-14 00:12:08 49,152 —-a-w c:\winnt\system32\wdigest.dll
- 2004-08-04 04:56:58 23,552 —-a-w c:\winnt\system32\wdmaud.drv
+ 2008-04-14 00:12:45 23,552 —-a-w c:\winnt\system32\wdmaud.drv
- 2008-10-16 20:38:39 233,472 —-a-w c:\winnt\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\winnt\system32\webcheck.dll
- 2006-01-04 03:35:05 68,096 —-a-w c:\winnt\system32\webclnt.dll
+ 2008-04-14 00:12:08 68,096 —-a-w c:\winnt\system32\webclnt.dll
- 2004-08-03 22:56:48 135,680 —-a-w c:\winnt\system32\webvw.dll
+ 2008-04-14 00:12:08 135,680 —-a-w c:\winnt\system32\webvw.dll
- 2004-08-03 22:56:58 65,536 —-a-w c:\winnt\system32\wextract.exe
+ 2008-04-14 00:12:39 65,024 —-a-w c:\winnt\system32\wextract.exe
+ 2008-09-06 04:30:42 241,704 ——w c:\winnt\system32\WgaLogon.dll
+ 2008-09-06 04:29:58 917,032 ——w c:\winnt\system32\WgaTray.exe
- 2004-08-03 22:56:58 433,664 —-a-w c:\winnt\system32\wiaacmgr.exe
+ 2008-04-14 00:12:39 433,664 —-a-w c:\winnt\system32\wiaacmgr.exe
- 2004-08-03 22:56:48 463,360 —-a-w c:\winnt\system32\wiadefui.dll
+ 2008-04-14 00:12:08 463,360 —-a-w c:\winnt\system32\wiadefui.dll
- 2004-08-03 22:56:48 124,416 —-a-w c:\winnt\system32\wiadss.dll
+ 2008-04-14 00:12:08 124,416 —-a-w c:\winnt\system32\wiadss.dll
- 2004-08-03 22:56:48 75,776 —-a-w c:\winnt\system32\wiascr.dll
+ 2008-04-14 00:12:08 75,776 —-a-w c:\winnt\system32\wiascr.dll
- 2006-12-19 18:16:47 333,824 —-a-w c:\winnt\system32\wiaservc.dll
+ 2008-04-14 00:12:08 333,824 —-a-w c:\winnt\system32\wiaservc.dll
- 2004-08-03 22:56:48 589,312 —-a-w c:\winnt\system32\wiashext.dll
+ 2008-04-14 00:12:08 589,312 —-a-w c:\winnt\system32\wiashext.dll
- 2004-08-03 22:56:48 111,104 —-a-w c:\winnt\system32\wiavideo.dll
+ 2008-04-14 00:12:08 111,104 —-a-w c:\winnt\system32\wiavideo.dll
- 2008-09-15 11:57:41 1,846,016 —-a-w c:\winnt\system32\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 —-a-w c:\winnt\system32\win32k.sys
- 2004-08-03 22:56:48 101,888 —-a-w c:\winnt\system32\win32spl.dll
+ 2008-04-14 00:12:08 102,400 —-a-w c:\winnt\system32\win32spl.dll
- 2004-08-03 22:56:36 937,984 —-a-w c:\winnt\system32\winbrand.dll
+ 2008-04-13 16:48:53 1,647,616 —-a-w c:\winnt\system32\winbrand.dll
- 2006-10-24 17:30:06 716,288 ——w c:\winnt\system32\WindowsCodecs.dll
+ 2008-04-14 00:12:08 712,704 ——w c:\winnt\system32\windowscodecs.dll
- 2006-10-24 17:29:50 352,256 ——w c:\winnt\system32\WindowsCodecsExt.dll
+ 2008-04-14 00:12:08 346,112 ——w c:\winnt\system32\windowscodecsext.dll
- 2004-08-03 22:56:48 351,232 —-a-w c:\winnt\system32\winhttp.dll
+ 2008-04-14 00:12:08 354,304 —-a-w c:\winnt\system32\winhttp.dll
- 2004-08-03 22:56:48 32,768 —-a-w c:\winnt\system32\winipsec.dll
+ 2008-04-14 00:12:09 32,256 —-a-w c:\winnt\system32\winipsec.dll
- 2004-08-03 22:56:58 502,272 —-a-w c:\winnt\system32\winlogon.exe
+ 2008-04-14 00:12:39 507,904 —-a-w c:\winnt\system32\winlogon.exe
- 2004-08-03 22:56:48 176,128 —-a-w c:\winnt\system32\winmm.dll
+ 2008-04-14 00:12:09 176,128 —-a-w c:\winnt\system32\winmm.dll
- 2004-08-03 22:56:36 764,928 —-a-w c:\winnt\system32\winntbbu.dll
+ 2008-04-14 00:11:11 756,224 —-a-w c:\winnt\system32\winntbbu.dll
- 2004-08-03 22:56:48 16,896 —-a-w c:\winnt\system32\winrnr.dll
+ 2008-04-14 00:12:09 16,896 —-a-w c:\winnt\system32\winrnr.dll
- 2004-08-03 22:56:48 99,328 —-a-w c:\winnt\system32\winscard.dll
+ 2008-04-14 00:12:09 99,328 —-a-w c:\winnt\system32\winscard.dll
- 2004-08-03 22:56:48 17,408 —-a-w c:\winnt\system32\winshfhc.dll
+ 2008-04-14 00:12:09 17,408 —-a-w c:\winnt\system32\winshfhc.dll
- 2004-08-03 22:56:58 146,432 —-a-w c:\winnt\system32\winspool.drv
+ 2008-04-14 00:12:45 146,432 —-a-w c:\winnt\system32\winspool.drv
- 2007-03-17 13:43:01 292,864 —-a-w c:\winnt\system32\winsrv.dll
+ 2008-04-14 00:12:09 293,376 —-a-w c:\winnt\system32\winsrv.dll
- 2004-08-03 22:56:48 53,760 —-a-w c:\winnt\system32\winsta.dll
+ 2008-04-14 00:12:09 53,760 —-a-w c:\winnt\system32\winsta.dll
- 2004-08-03 22:56:48 176,640 —-a-w c:\winnt\system32\wintrust.dll
+ 2008-04-14 00:12:09 176,640 —-a-w c:\winnt\system32\wintrust.dll
- 2004-08-03 22:56:58 5,632 —-a-w c:\winnt\system32\winver.exe
+ 2008-04-14 00:12:40 5,632 —-a-w c:\winnt\system32\winver.exe
- 2006-08-17 12:37:49 132,096 —-a-w c:\winnt\system32\wkssvc.dll
+ 2008-04-14 00:12:09 132,096 —-a-w c:\winnt\system32\wkssvc.dll
- 2004-08-03 22:56:48 172,032 —-a-w c:\winnt\system32\wldap32.dll
+ 2008-04-14 00:12:09 172,032 —-a-w c:\winnt\system32\wldap32.dll
- 2004-08-03 22:56:48 92,672 —-a-w c:\winnt\system32\wlnotify.dll
+ 2008-04-14 00:12:09 92,672 —-a-w c:\winnt\system32\wlnotify.dll
- 2004-08-03 22:56:36 5,632 —-a-w c:\winnt\system32\wmi.dll
+ 2008-04-14 00:11:15 5,632 —-a-w c:\winnt\system32\wmi.dll
- 2004-08-03 22:56:48 20,480 —-a-w c:\winnt\system32\wmpcd.dll
+ 2008-04-14 00:12:09 20,480 —-a-w c:\winnt\system32\wmpcd.dll
- 2004-08-03 22:56:48 20,480 —-a-w c:\winnt\system32\wmpcore.dll
+ 2008-04-14 00:12:09 20,480 —-a-w c:\winnt\system32\wmpcore.dll
- 2006-10-19 02:47:20 295,936 ——w c:\winnt\system32\wmpeffects.dll
+ 2008-06-24 23:12:58 295,936 ——w c:\winnt\system32\wmpeffects.dll
- 2006-10-24 17:30:00 276,992 ——w c:\winnt\system32\WMPhoto.dll
+ 2008-04-14 00:12:09 276,992 ——w c:\winnt\system32\wmphoto.dll
- 2004-08-03 22:56:48 20,480 —-a-w c:\winnt\system32\wmpui.dll
+ 2008-04-14 00:12:09 20,480 —-a-w c:\winnt\system32\wmpui.dll
- 2004-08-03 22:56:48 115,200 —-a-w c:\winnt\system32\wmsdmoe.dll
+ 2008-04-14 00:12:09 115,200 —-a-w c:\winnt\system32\wmsdmoe.dll
- 2004-08-03 22:56:48 303,616 —-a-w c:\winnt\system32\wmstream.dll
+ 2008-04-14 00:12:10 303,616 —-a-w c:\winnt\system32\wmstream.dll
- 2004-08-03 22:56:48 264,192 —-a-w c:\winnt\system32\wow32.dll
+ 2008-04-14 00:12:10 264,192 —-a-w c:\winnt\system32\wow32.dll
- 2004-08-03 22:56:58 32,256 —-a-w c:\winnt\system32\wpabaln.exe
+ 2008-04-14 00:12:40 32,256 —-a-w c:\winnt\system32\wpabaln.exe
- 2004-08-03 22:56:58 32,256 —-a-w c:\winnt\system32\wpnpinst.exe
+ 2008-04-14 00:12:41 11,264 —-a-w c:\winnt\system32\wpnpinst.exe
- 2004-08-03 22:56:48 82,944 —-a-w c:\winnt\system32\ws2_32.dll
+ 2008-04-14 00:12:10 82,432 —-a-w c:\winnt\system32\ws2_32.dll
- 2004-08-03 22:56:48 19,968 —-a-w c:\winnt\system32\ws2help.dll
+ 2008-04-14 00:12:10 19,968 —-a-w c:\winnt\system32\ws2help.dll
- 2004-08-03 22:56:58 13,824 —-a-w c:\winnt\system32\wscntfy.exe
+ 2008-04-14 00:12:41 13,824 —-a-w c:\winnt\system32\wscntfy.exe
- 2004-08-03 22:56:58 114,688 —-a-w c:\winnt\system32\wscript.exe
+ 2008-05-08 11:24:44 155,648 —-a-w c:\winnt\system32\wscript.exe
- 2004-08-03 22:56:48 81,408 —-a-w c:\winnt\system32\wscsvc.dll
+ 2008-04-14 00:12:10 80,896 —-a-w c:\winnt\system32\wscsvc.dll
- 2004-08-03 22:56:48 596,992 —-a-w c:\winnt\system32\wsecedit.dll
+ 2008-04-14 00:12:10 604,160 —-a-w c:\winnt\system32\wsecedit.dll
- 2004-08-03 23:05:44 108,032 —-a-w c:\winnt\system32\wshbth.dll
+ 2008-04-14 00:12:10 108,032 —-a-w c:\winnt\system32\wshbth.dll
- 2004-08-03 22:56:48 28,672 —-a-w c:\winnt\system32\wshcon.dll
+ 2008-04-14 00:12:10 36,864 —-a-w c:\winnt\system32\wshcon.dll
- 2004-08-03 22:56:48 65,536 —-a-w c:\winnt\system32\wshext.dll
+ 2008-05-09 10:53:40 90,112 —-a-w c:\winnt\system32\wshext.dll
- 2004-08-03 22:56:48 14,336 —-a-w c:\winnt\system32\wship6.dll
+ 2008-04-14 00:12:10 14,336 —-a-w c:\winnt\system32\wship6.dll
- 2004-08-03 22:56:48 11,776 —-a-w c:\winnt\system32\WshRm.dll
+ 2008-04-14 00:12:10 11,264 —-a-w c:\winnt\system32\wshrm.dll
- 2004-08-03 22:56:48 19,968 —-a-w c:\winnt\system32\wshtcpip.dll
+ 2008-04-14 00:12:10 19,456 —-a-w c:\winnt\system32\wshtcpip.dll
- 2004-08-03 22:56:48 42,496 —-a-w c:\winnt\system32\wsnmp32.dll
+ 2008-04-14 00:12:10 41,984 —-a-w c:\winnt\system32\wsnmp32.dll
- 2004-08-03 22:56:48 22,528 —-a-w c:\winnt\system32\wsock32.dll
+ 2008-04-14 00:12:10 22,528 —-a-w c:\winnt\system32\wsock32.dll
- 2004-08-03 22:56:48 50,688 —-a-w c:\winnt\system32\wstdecod.dll
+ 2008-04-14 00:12:10 50,688 —-a-w c:\winnt\system32\wstdecod.dll
- 2004-08-03 22:56:48 18,432 —-a-w c:\winnt\system32\wtsapi32.dll
+ 2008-04-14 00:12:10 18,432 —-a-w c:\winnt\system32\wtsapi32.dll
- 2008-07-19 02:09:44 563,912 —-a-w c:\winnt\system32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\winnt\system32\wuapi.dll
- 2008-07-19 02:10:42 53,448 —-a-w c:\winnt\system32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 —-a-w c:\winnt\system32\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 —-a-w c:\winnt\system32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 —-a-w c:\winnt\system32\wuaueng.dll
- 2004-08-03 22:56:48 6,656 —-a-w c:\winnt\system32\wuauserv.dll
+ 2008-04-14 00:12:11 6,656 —-a-w c:\winnt\system32\wuauserv.dll
- 2008-07-19 02:09:46 325,832 —-a-w c:\winnt\system32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 —-a-w c:\winnt\system32\wucltui.dll
- 2008-07-19 02:10:20 36,552 —-a-w c:\winnt\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\winnt\system32\wups.dll
- 2008-07-19 02:10:40 45,768 —-a-w c:\winnt\system32\wups2.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\winnt\system32\wups2.dll
- 2006-08-18 12:37:56 383,488 —-a-w c:\winnt\system32\wzcdlg.dll
+ 2008-04-14 00:12:11 383,488 —-a-w c:\winnt\system32\wzcdlg.dll
- 2006-08-18 12:37:56 52,736 —-a-w c:\winnt\system32\wzcsapi.dll
+ 2008-04-14 00:12:11 52,736 —-a-w c:\winnt\system32\wzcsapi.dll
- 2006-08-18 12:37:56 476,160 —-a-w c:\winnt\system32\wzcsvc.dll
+ 2008-04-14 00:12:11 483,840 —-a-w c:\winnt\system32\wzcsvc.dll
- 2004-08-03 22:56:48 91,648 —-a-w c:\winnt\system32\xactsrv.dll
+ 2008-04-14 00:12:11 91,648 —-a-w c:\winnt\system32\xactsrv.dll
- 2004-08-03 22:56:58 30,720 —-a-w c:\winnt\system32\xcopy.exe
+ 2008-04-14 00:12:41 30,720 —-a-w c:\winnt\system32\xcopy.exe
- 2006-07-14 15:51:51 121,856 ——w c:\winnt\system32\xmllite.dll
+ 2008-04-14 00:12:11 121,856 —-a-w c:\winnt\system32\xmllite.dll
- 2004-08-03 22:56:48 129,536 —-a-w c:\winnt\system32\xmlprov.dll
+ 2008-04-14 00:12:11 129,024 —-a-w c:\winnt\system32\xmlprov.dll
- 2004-08-03 22:56:48 50,176 —-a-w c:\winnt\system32\xmlprovi.dll
+ 2008-04-14 00:12:11 50,176 —-a-w c:\winnt\system32\xmlprovi.dll
- 2006-03-01 19:42:42 11,776 —-a-w c:\winnt\system32\xolehlp.dll
+ 2008-04-14 00:12:11 11,776 —-a-w c:\winnt\system32\xolehlp.dll
- 2004-08-03 22:56:38 438,784 —-a-w c:\winnt\system32\xpob2res.dll
+ 2008-04-13 17:39:29 438,784 —-a-w c:\winnt\system32\xpob2res.dll
- 2004-08-03 22:56:38 187,392 —-a-w c:\winnt\system32\xpsp1res.dll
+ 2008-04-13 17:39:22 187,392 —-a-w c:\winnt\system32\xpsp1res.dll
- 2004-08-03 22:56:38 2,897,920 —-a-w c:\winnt\system32\xpsp2res.dll
+ 2008-04-13 17:39:24 2,897,920 —-a-w c:\winnt\system32\xpsp2res.dll
- 2008-10-15 14:00:41 351,744 —-a-w c:\winnt\system32\xpsp3res.dll
+ 2008-04-13 17:39:26 689,152 —-a-w c:\winnt\system32\xpsp3res.dll
- 2004-08-03 22:56:48 337,920 —-a-w c:\winnt\system32\zipfldr.dll
+ 2008-04-14 00:12:11 338,432 —-a-w c:\winnt\system32\zipfldr.dll
+ 2009-03-06 23:50:37 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_534.dat
+ 2009-03-06 23:52:53 16,384 —-atw c:\winnt\Temp\Perflib_Perfdata_8ec.dat
- 2004-08-03 22:56:48 50,688 —-a-w c:\winnt\twain_32.dll
+ 2008-04-14 00:12:07 50,688 —-a-w c:\winnt\twain_32.dll
- 2004-08-03 22:56:58 283,648 —-a-w c:\winnt\winhlp32.exe
+ 2008-04-14 00:12:39 283,648 —-a-w c:\winnt\winhlp32.exe
- 2007-01-19 20:15:24 74,802 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2008-04-14 00:12:50 74,802 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
- 2007-01-19 20:15:24 995,383 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2008-04-14 00:12:50 995,383 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2007-01-19 20:15:24 1,011,774 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2008-04-14 00:12:50 1,011,774 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
- 2007-01-19 20:15:24 401,462 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 00:12:50 401,462 —-a-w c:\winnt\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2008-04-14 00:12:51 1,054,208 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
+ 2008-04-14 00:12:51 57,344 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll
+ 2008-04-14 00:12:51 343,040 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
+ 2008-04-14 00:12:47 1,724,416 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll
- 2004-08-03 22:57:00 853,504 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
+ 2008-04-14 00:12:49 853,504 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll
- 2004-08-03 22:57:00 991,232 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
+ 2008-04-14 00:12:50 991,232 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll
- 2004-08-03 22:55:58 132,096 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc
0\rtcres.dll
+ 2008-04-13 18:26:33 132,096 —-a-w c:\winnt\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc
0\rtcres.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-01-26 2144088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search\DesktopSearchService.exe" [2008-12-11 1588224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\OfficeScan NT\pccntmon.exe" [2009-01-15 718120]
"WinZip Quick Pick"="c:\program files\WinZip\WZQKPICK.EXE" [2004-03-04 106560]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\winnt\system32\igfxpers.exe" [2007-05-16 138008]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-08-05 786432]
"Broadcom Wireless Manager UI"="c:\winnt\system32\WLTRAY.exe" [2007-03-16 1392640]
"CoolSwitch"="c:\winnt\system32\taskswitch.exe" [2002-03-19 45632]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Synchronization Manager"="mobsync.exe" [2008-04-13 c:\winnt\system32\mobsync.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\winnt\stsystra.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader - Schnellstart.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-05-09 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-09-27 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Push Client.LNK - c:\program files\interwise\Participant\pull.exe [2008-11-14 886000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
"NoOnlinePrintsWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoThumbnailCache"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=CBEShutdown.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addlocaladm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=nsn_svclaunch.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
"Script"=EnfAdminV3.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1060284298-1450960922-725345543-500\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logoff\1\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\0\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1593251271-2640304127-1825641215-227304\Scripts\Logon\1\0]
"Script"=GPOLogon-V2.6.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-136749\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1935655697-1965331169-839522115-55867\Scripts\Logoff\0\0]
"Script"=CBELogoff.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\winnt\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\winnt\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^xccstart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\xccstart.lnk
backup=c:\winnt\pss\xccstart.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vm092543^Start Menu^Programs^Startup^Infotriever.lnk]
path=c:\documents and settings\vm092543\Start Menu\Programs\Startup\Infotriever.lnk
backup=c:\winnt\pss\Infotriever.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-10-08 09:00 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2006-10-09 10:28 139264 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DirXconnect settings]
–a—— 2000-03-21 08:39 106561 c:\progra~1\Siemens\DIRXDI~1\dxdSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 01:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIECACST]
–a—— 2006-10-05 10:18 69632 c:\program files\Siemens\Card API\bin\siecacst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Firefly Media Server"=2 (0x2)
"Bonjour Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%systemroot%\\PCHEALTH\\HELPCTR\\Binaries\\helpsvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)

R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [2004-08-05 77824]
R2 MCsvc;Managed Client Service;c:\winnt\system32\MCSvc.exe [2008-09-15 69632]
R2 NPF;NetGroup Packet Filter Driver;c:\winnt\system32\drivers\npf.sys [2007-06-28 42512]
R2 Service Launcher;Service Launcher;c:\winnt\system32\SvcLncher.exe [2008-03-06 229376]
R2 SU;SU Service;c:\winnt\system32\Suss.exe [2007-09-26 12048]
R2 Sygman;SSA Integration Manager;c:\program files\AccessManager\Client\sygman.exe [2004-08-05 126976]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\OfficeScan NT\tmpreflt.sys [2006-09-06 36368]
R3 Eacfilt;Eacfilt Miniport;c:\winnt\system32\drivers\eacfilt.sys [2007-09-27 9817]
R3 tmcfw;Trend Micro Common Firewall Service;c:\winnt\system32\drivers\TM_CFW.sys [2006-12-22 338448]
S2 HTTP Poster;HTTP Poster Service;c:\winnt\system32\HTTP_Poster.exe [2008-10-21 45056]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\winnt\system32\drivers\ipsecw2k.sys [2007-09-27 117760]
S2 TmFilter;Trend Micro Filter;c:\program files\OfficeScan NT\tmxpflt.sys [2006-09-06 205328]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-08-05 81920]
S3 DMService;Whale Component Manager;c:\winnt\DOWNLO~1\DMService.exe [2008-08-07 423576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\winnt\system32\drivers\el575ND5.sys [2007-09-26 69692]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\IP VPN Remote Services\Extranet_serv.exe [2007-09-27 643072]
S3 NbtDet;NetBoot PCI Detection Service;c:\winnt\system32\drivers\nbtdet.sys [2008-09-15 4992]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\winnt\system32\drivers\nmwcdnsu.sys [2009-02-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\winnt\system32\drivers\nmwcdnsuc.sys [2009-02-18 8320]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [2003-04-17 81920]
S3 TmPfw;OfficeScanNT Personal Firewall;c:\program files\OfficeScan NT\TmPfw.exe [2008-05-13 488768]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\OfficeScan NT\TmProxy.exe [2008-05-13 652552]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5084F01D-458E-45EB-A6FD-692D4C9D2789}]
c:\winnt\system32\msiexec.exe /qn /fpu {5084F01D-458E-45EB-A6FD-692D4C9D2789}

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}]
c:\winnt\system32\msiexec.exe /qn /fpu {A9E4F13B-7EEA-4C83-85DF-0F447BF4DE7B}
.
Contents of the 'Scheduled Tasks' folder

2009-02-22 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-06 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-1593251271-2640304127-1825641215-227304.job
- c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:48]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://inside.nokiasiemensnetworks.com
uInternet Settings,ProxyOverride =
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Edit with Altova X&MLSpy - c:\program files\Altova\XMLSpy2008\spy.htm
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
Trusted Zone: microsoft.com
Trusted Zone: peopleclick.com
Trusted Zone: placeware.com
Trusted Zone: sap-ag.de
Trusted Zone: sap.com
Trusted Zone: siemens.com\project
Trusted Zone: siemens.de\communication-market1
Trusted Zone: siemens.de\icm-km.erlm
Trusted Zone: siemens.de\icm-km1.erlm
Trusted Zone: siemens.de\icm-km2.erlm
Trusted Zone: siemens.de\icm-km3.erlm
Trusted Zone: siemens.de\icm-km4.erlm
Trusted Zone: siemens.it\ikuddq.icn
Trusted Zone: vodafone.com\virtualtrainingroom
DPF: {21C6245C-9408-11D7-BF3B-00E09876DF26} - hxxp://www.webattend.com/components/wt0523.cab
DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} - hxxps://xesp-nsnst004.inside.nokiasiemensnetworks.com/sametime/stmeetingroomclient/STJNILoader.cab
DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} - hxxps://office.services.xerox.com/XeroxServicesManager/UI/FindPrinter/PrnInst/Xerox_Services_Portal_Pref.CAB
FF - ProfilePath - c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\
FF - component: c:\program files\Copernic Desktop Search\FirefoxConnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\Copernic Desktop Search\Toolbar\FirefoxContainer\components\CCLCXPCOMBridge.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\vm092543\Application Data\Mozilla\Firefox\Profiles\rrxtafk7.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\vm092543\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Nokia\Ovi maps\Mozilla Firefox plugin\XPI\plugins\npNMapG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 18:59:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1688)
c:\winnt\system32\amgina.dll
c:\winnt\system32\amginar.dll
.
Completion time: 2009-03-06 19:02:51
ComboFix-quarantined-files.txt 2009-03-07 00:01:34
ComboFix2.txt 2009-03-06 13:20:00
ComboFix3.txt 2009-03-06 01:43:43

Pre-Run: 1,815,277,568 bytes free
Post-Run: 1,811,820,544 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,5
5718 — E O F — 2009-03-06 23:55:11
calvin_hobbes,


Then please run a new Kaspersky scan. Let it run to completion this time. I realize it takes forever but, start it tonight and let it run while you sleep. Then post to me tommorrow.
Hi Tomk, Once again thanks for your patience and prompt support. Please find below the requested logs. Kaspersky ======== ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Sunday, March 8, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, March 07, 2009 23:14:07 Records in database: 1878614 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - Folder: C:\ Scan statistics: Files scanned: 78764 Threat name: 12 Infected objects: 15 Suspicious objects: 0 Duration of the scan: 02:11:56 File name / Threat name / Threats count C:\CF1 Customer Files\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.e 1 C:\Program Files\emwprof\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.1101 1 C:\Qoobox\Quarantine\C\WINNT\Installer\255ea.msi.vir Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\Qoobox\Quarantine\C\WINNT\Installer\255fc.msi.vir Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\Qoobox\Quarantine\C\WINNT\system32\200924030_232c.VIR.vir Infected: Trojan-GameThief.Win32.WOW.fqh 1 C:\Qoobox\Quarantine\C\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3DD0Y4RA\chinappi[1]_18bc.VIR.vir Infected: Trojan-GameThief.Win32.WOW.fqg 1 C:\Qoobox\Quarantine\C\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR.vir Infected: Trojan.Win32.Agent.bsud 2 C:\Qoobox\Quarantine\C\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR.vir Infected: Trojan.Win32.Agent2.eng 1 C:\Qoobox\Quarantine\C\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UL5ZJ820\bb021908[1]_2048.VIR.vir Infected: Trojan.Win32.Agent2.enz 1 C:\Qoobox\Quarantine\C\WINNT\system32\icv.exe.vir Infected: Trojan.Win32.Buzus.aocw 1 C:\Qoobox\Quarantine\C\WINNT\system32\jkkLBsRl_8ac.VIR.vir Infected: Trojan.Win32.Monderb.alcl 1 C:\Qoobox\Quarantine\C\WINNT\system32\SOPIDKC_640.VIR.vir Infected: Trojan.Win32.Agent2.enz 1 C:\Qoobox\Quarantine\C\WINNT\system32\U52856226_2348.VIR.vir Infected: Trojan-GameThief.Win32.OnLineGames.bkvv 1 C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\BLJJX0MW\zha[1].exe Infected: Trojan.Win32.Agent.btpk 1 The selected area was scanned.
calvin_hobbes,

Download HostsXpert v4.3 and unzip it to your computer, somewhere where you can find it.
  • Double click on HostsXpert.exe to launch the program.
  • Click on Restore MS Hosts File to restore your Hosts file to its default condition.
  • Click on Make ReadOnly to secure it against further infection.
  • Exit the program.
Visit the Website for more information.

Then

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next

Please give me a new HijackThis log and let me know how it's running.
Hi Tom,

I normally maintain a most up-to-date MVPS host file, however the HostXpert program has overwritten it with a single entry and made it read-only. Should i restore the host file from MVPS, and make it read-only or leave it as-is replaced by HostXpert?

HJT
===
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:49:01 PM, on 03/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\MCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Suss.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\WINNT\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\TEMP\SEE9C9.EXE
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\OfficeScan NT\TmPfw.exe
C:\WINNT\explorer.exe
C:\Program Files\OfficeScan NT\pccntmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\stsystra.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\WINNT\system32\igfxsrvc.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\WINNT\system32\WLTRAY.exe
C:\WINNT\system32\taskswitch.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WinPatrol\winpatrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\interwise\Participant\pull.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\OfficeScan NT\CNTAoSMgr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\WINNT\system32\SvcLncher.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINNT\system32\HPZinw12.exe
C:\WINNT\system32\HPZipm12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconf.glb.nsn-net.net/proxy.pac
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinZip Quick Pick] C:\Program Files\WinZip\WZQKPICK.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINNT\system32\WLTRAY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINNT\system32\taskswitch.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\vm092543\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search\DesktopSearchService.exe" /tray
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\Participant\pull.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2008\spy.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://inside.nokiasiemensnetworks.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1230590012390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230592905812
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://xesp-nsnst004.inside.nokiasiemensne…STJNILoader.cab
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} (Whale Client Components) - https://bpsn.inside.nokiasiemensnetworks.co…/WhlCompMgr.cab
O16 - DPF: {D3E01836-60CD-480D-BBDB-19D5A7D23128} (Xerox_Services_Portal.XrxPrinter_Inst) - https://office.services.xerox.com/XeroxServ…Portal_Pref.CAB
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://apertio.webex.com/client/T27L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\Software\..\Telephony: DomainName = nsn-intra.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = nsn-intra.net
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\IP VPN Remote Services\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: HTTP Poster Service (HTTP Poster) - Nokia - C:\WINNT\system32\HTTP_Poster.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Managed Client Service (MCsvc) - © 2005 - 2008 Siemens AG - C:\WINNT\System32\MCSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Service Launcher - SIS GO GIO DS PSU6 - C:\WINNT\system32\SvcLncher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScanNT Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINNT\System32\WLTRYSVC.EXE

–
End of file - 14952 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI