poporacer
Topic Starter
My mom's computer is running extreme slow and sometimes IE explorer does not load. I downloaded DDS to the desktop and disabled Norton System Works. I ran DDS and it didn't do anything. After about 10 minutes I closed the DOS window and retried it. after a couple of times, it finally gave me the files. Here are the files:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/02 07:22
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
——————-
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x92152000 Size: 45056 File Visible: No Signed: -
Status: -
Name: dump_msahci.sys
Image Path: C:\Windows\System32\Drivers\dump_msahci.sys
Address: 0x9215D000 Size: 40960 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xB4DCA000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1204 Status: Locked to the Windows API!
SSDT
——————-
#: 013 Function Name: NtAlertResumeThread
Status: Hooked by "" at address 0x8cea9958
#: 014 Function Name: NtAlertThread
Status: Hooked by "" at address 0x8cea9a18
#: 018 Function Name: NtAllocateVirtualMemory
Status: Hooked by "" at address 0x8c32a9c0
#: 054 Function Name: NtConnectPort
Status: Hooked by "" at address 0x8cf11e80
#: 067 Function Name: NtCreateMutant
Status: Hooked by "" at address 0x8cea9708
#: 078 Function Name: NtCreateThread
Status: Hooked by "" at address 0x8c32ab08
#: 147 Function Name: NtFreeVirtualMemory
Status: Hooked by "" at address 0x8c32a820
#: 156 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "" at address 0x8cea97d8
#: 158 Function Name: NtImpersonateThread
Status: Hooked by "" at address 0x8cea9898
#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "" at address 0x8c32a740
#: 184 Function Name: NtOpenEvent
Status: Hooked by "" at address 0x8cea9648
#: 195 Function Name: NtOpenProcessToken
Status: Hooked by "" at address 0x8c32aa90
#: 202 Function Name: NtOpenThreadToken
Status: Hooked by "" at address 0x8cea9e30
#: 282 Function Name: NtResumeThread
Status: Hooked by "" at address 0x8c288ad8
#: 289 Function Name: NtSetContextThread
Status: Hooked by "" at address 0x8cea9d70
#: 305 Function Name: NtSetInformationProcess
Status: Hooked by "" at address 0x8cea9f00
#: 306 Function Name: NtSetInformationThread
Status: Hooked by "" at address 0x8cea9ca0
#: 330 Function Name: NtSuspendProcess
Status: Hooked by "" at address 0x8cea9588
#: 331 Function Name: NtSuspendThread
Status: Hooked by "" at address 0x8cea9b20
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "" at address 0x8c32a208
#: 335 Function Name: NtTerminateThread
Status: Hooked by "" at address 0x8cea9be0
#: 348 Function Name: NtUnmapViewOfSection
Status: Hooked by "" at address 0x8cea9fd0
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "" at address 0x8c32a8f0
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 7:33:27.74 on Wed 09/02/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1013.187 [GMT -7:00]
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Common Files\AOL\1189663422\ee\aolsoftware.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Mediafour\XPlay 3\XPlay.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\msiexec.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\Wilma\Desktop\RootRepeal.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Wilma\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.charter.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
BHO: Mediafour XPlay Explorer notifications: {4907c0ad-874d-44d9-b13e-7b0a4d8b9d3e} - c:\program files\mediafour\xplay 3\XPBHO.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [HostManager] c:\program files\common files\aol\1189663422\ee\AOLSoftware.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}] "c:\program files\mediafour\xplay 3\XPlay.exe"
mRun: [snp2uvc] c:\windows\vsnp2uvc.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2009-4-30 284416]
R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2009-7-31 136744]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20090826.001\IDSvix86.sys [2009-9-1 272432]
R2 M4iPodWPDService;M4iPodWPDService;c:\program files\common files\mediafour\ipod\M4iPodWPDService.exe [2009-7-6 208896]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-27 102448]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-8-3 38448]
=============== Created Last 30 ================
2009-09-02 06:53 –d—– c:\programdata\Office Genuine Advantage
2009-09-01 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-09-01 22:44 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-01 22:38 499,712 a——- c:\windows\system32\kerberos.dll
2009-09-01 22:38 213,504 a——- c:\windows\system32\msv1_0.dll
2009-09-01 22:38 175,104 a——- c:\windows\system32\wdigest.dll
2009-09-01 22:38 1,256,448 a——- c:\windows\system32\lsasrv.dll
2009-09-01 22:38 270,848 a——- c:\windows\system32\schannel.dll
2009-09-01 22:38 439,896 a——- c:\windows\system32\drivers\ksecdd.sys
2009-09-01 22:38 72,704 a——- c:\windows\system32\secur32.dll
2009-09-01 22:38 9,728 a——- c:\windows\system32\lsass.exe
2009-09-01 21:31 2,048 a——- c:\windows\system32\tzres.dll
2009-08-16 14:50 160,256 a——- c:\windows\system32\wkssvc.dll
2009-08-16 14:50 71,680 a——- c:\windows\system32\atl.dll
2009-08-16 14:50 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-08-16 14:50 91,136 a——- c:\windows\system32\avifil32.dll
2009-08-16 14:49 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-08-16 14:49 7,680 a——- c:\windows\system32\spwmp.dll
2009-08-16 14:49 4,096 a——- c:\windows\system32\dxmasf.dll
2009-08-16 14:49 4,096 a——- c:\windows\system32\msdxm.ocx
2009-08-16 14:49 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-08-16 14:48 18,432 a——- c:\windows\system32\amcompat.tlb
2009-08-16 14:48 43,520 a——- c:\windows\system32\msdxm.tlb
2009-08-08 03:02 6,103,040 a——- c:\windows\system32\chtbrkr.dll
2009-08-08 03:02 1,671,680 a——- c:\windows\system32\chsbrkr.dll
2009-08-08 03:02 184,832 a——- c:\windows\system32\SearchProtocolHost.exe
2009-08-08 03:02 1,582,592 a——- c:\windows\system32\tquery.dll
2009-08-08 03:02 1,418,240 a——- c:\windows\system32\mssrch.dll
2009-08-08 03:02 439,808 a——- c:\windows\system32\SearchIndexer.exe
2009-08-08 03:02 670,208 a——- c:\windows\system32\mssvp.dll
2009-08-08 03:02 350,208 a——- c:\windows\system32\mssph.dll
2009-08-08 03:02 203,776 a——- c:\windows\system32\mssphtb.dll
2009-08-07 17:48 891,448 a——- c:\windows\system32\drivers\tcpip.sys
2009-08-07 17:48 72,192 a——- c:\windows\system32\drivers\pacer.sys
2009-08-07 17:48 15,360 a——- c:\windows\system32\pacerprf.dll
2009-08-07 17:41 147,456 a——- c:\windows\system32\Faultrep.dll
2009-08-07 17:41 125,952 a——- c:\windows\system32\wersvc.dll
2009-08-07 17:38 565,248 a——- c:\windows\system32\emdmgmt.dll
2009-08-07 17:38 625,152 a——- c:\windows\system32\drivers\dxgkrnl.sys
2009-08-07 17:38 148,480 a——- c:\windows\system32\drivers\nwifi.sys
2009-08-07 17:38 45,056 a——- c:\windows\system32\dataclen.dll
2009-08-07 17:38 36,864 a——- c:\windows\system32\cdd.dll
2009-08-07 17:38 155,648 a——- c:\windows\system32\wscript.exe
2009-08-07 17:38 135,168 a——- c:\windows\system32\wshom.ocx
2009-08-07 17:38 90,112 a——- c:\windows\system32\wshext.dll
2009-08-07 17:38 180,224 a——- c:\windows\system32\scrobj.dll
2009-08-07 17:38 172,032 a——- c:\windows\system32\scrrun.dll
2009-08-07 17:38 135,168 a——- c:\windows\system32\cscript.exe
2009-08-03 19:07 9,892 a——- c:\windows\system32\drivers\SymRedir.cat
2009-08-03 19:07 1,356 a——- c:\windows\system32\drivers\SymRedir.inf
2009-08-03 19:07 38,448 a——- c:\windows\system32\drivers\symndisv.sys
2009-08-03 19:07 188,080 a——- c:\windows\system32\drivers\symtdi.sys
2009-08-03 19:07 145,968 a——- c:\windows\system32\drivers\symfw.sys
2009-08-03 19:07 39,856 a——- c:\windows\system32\drivers\symids.sys
2009-08-03 19:07 26,416 a——- c:\windows\system32\drivers\symredrv.sys
2009-08-03 19:07 12,720 a——- c:\windows\system32\drivers\symdns.sys
2009-08-03 15:07 403,816 a——- c:\windows\system32\OGACheckControl.dll
2009-08-03 15:07 322,928 a——- c:\windows\system32\OGAAddin.dll
2009-08-03 15:07 230,768 a——- c:\windows\system32\OGAEXEC.exe
==================== Find3M ====================
2009-08-28 05:39 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 05:38 2,153,984 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 05:38 541,696 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 05:38 459,776 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-16 22:23 143,360 a——- c:\windows\inf\infstrng.dat
2009-08-16 22:23 86,016 a——- c:\windows\inf\infstor.dat
2009-08-16 22:23 51,200 a——- c:\windows\inf\infpub.dat
2009-08-01 08:52 174 a–sh— c:\program files\desktop.ini
2009-08-01 08:28 665,600 a——- c:\windows\inf\drvindex.dat
2009-08-01 07:58 101,888 a——- c:\windows\system32\ifxcardm.dll
2009-08-01 07:57 82,432 a——- c:\windows\system32\axaltocm.dll
2009-07-31 23:48 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll
2009-07-21 14:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 14:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 14:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 13:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-06-30 15:36 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryReplaceNew.exe
2009-06-30 15:10 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryNoTravel.exe
2009-06-30 15:03 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryAccessories.exe
2009-06-30 12:44 18,184 a——- c:\windows\help\oem\scripts\HC_BatteryWeakNew.exe
2009-06-26 18:36 18,184 a——- c:\windows\help\oem\scripts\HC_BatteryUpgrade.exe
2009-06-15 08:24 156,672 a——- c:\windows\system32\t2embed.dll
2009-06-15 08:20 72,704 a——- c:\windows\system32\fontsub.dll
2009-06-15 08:20 10,240 a——- c:\windows\system32\dciman32.dll
2009-06-15 05:52 289,792 a——- c:\windows\system32\atmfd.dll
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 7:35:39.43 ===============