This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unwanted IE popups

139 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have had the Geek Squad come twice to clean out a series of pop ups, with Internet Explorer header and offers to download software to get rid of virus. I also have a window, in bottom right corner(yellow triangle with ! mark), that continually pop ups with "System performance monitor: Warning -talking about black door …or Spyware found… versions of PSW.x-Vir…

The Best Buy Geek Squad has come twice, once to delete some files but could not find the source of the popup, and leaving me to buy SpySweeper, which I had a hard time loading. The second time back (two days later because Sweeper failed to get rid of it) with lots of cleaning and Restarting, the pop up kept coming back. His comment is to store our files and wipe our the operating system and reformat. Apparently this is a new polymorphic program that rebuilds itself everytime you restart your PC. Help!

Log information:
Logfile of HijackThis v1.99.1
Scan saved at 9:53:30 PM, on 10/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\qnonogul.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: IKatzu Class - {EA5159DF-E413-4878-8AE2-D921D41BB942} - C:\WINDOWS\system32\bkinopuv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qnonogul.dll
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm161YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: qnonogul - C:\WINDOWS\SYSTEM32\qnonogul.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qavuwunc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

——————
Output after doing the suggested diagnostic from helper on this topic;
a. After the Geek Squad failed to get rid of popups, I added Spy Sweeper with Anti-Virus
b. I switched to Firefox, thinking the popups came off of Internet Explorer infestation, along with tool bar that would not go away
c. I bought a external hard drive with the intention of backing up my documents and re-install the operating system
d. for now I have the combofix.txt here
ComboFix 07-10-23.1 - Glenn 2007-10-23 22:52:47.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.133 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\Application Data.\salesmonitor
C:\Documents and Settings\Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\update.log
C:\Documents and Settings\Glenn\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Glenn\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Glenn\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Owner\err.log
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Patricia\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Patricia\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Patricia\Favorites\Online Security Guide.lnk
C:\Program Files\BestsellerAntivirus
C:\Program Files\BestsellerAntivirus\Engines\AWBase\database\enemies.dat
C:\Program Files\BestsellerAntivirus\Engines\AWBase\vbpv.dat
C:\Program Files\BestsellerAntivirus\history.db
C:\Program Files\BestsellerAntivirus\ResErrors.log
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\004DEC6C.dat
C:\Program Files\Messenger\rteprejyc.html
C:\UGA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahedxntp.exe
C:\WINDOWS\system32\ahwnovyu.exe
C:\WINDOWS\system32\ajoeuyfj.exe
C:\WINDOWS\system32\anigjgjc.exe
C:\WINDOWS\system32\atudbbce.exe
C:\WINDOWS\system32\axopckrk.exe
C:\WINDOWS\system32\aypehwux.ini
C:\WINDOWS\system32\bfukszby.dll
C:\WINDOWS\system32\blqhirtg.exe
C:\WINDOWS\system32\chffbpuv.exe
C:\WINDOWS\system32\cjrotwmu.exe
C:\WINDOWS\system32\crlubbii.exe
C:\WINDOWS\system32\djovrool.exe
C:\WINDOWS\system32\dlbwfbqi.exe
C:\WINDOWS\system32\dnghkccz.dll
C:\WINDOWS\system32\dqpfuiyv.exe
C:\WINDOWS\system32\dvkkrbdp.exe
C:\WINDOWS\system32\ecgkcggx.exe
C:\WINDOWS\system32\efokluex.dll
C:\WINDOWS\system32\eleazqmy.dll
C:\WINDOWS\system32\euirtcgn.exe
C:\WINDOWS\system32\fbbyrbpx.dll
C:\WINDOWS\system32\fpdgosxl.ini
C:\WINDOWS\system32\frcaifcg.exe
C:\WINDOWS\system32\fwifiply.exe
C:\WINDOWS\system32\gmjcxyfk.ini
C:\WINDOWS\system32\gulgjrdk.exe
C:\WINDOWS\system32\gyfqmbon.exe
C:\WINDOWS\system32\gylsbvbr.exe
C:\WINDOWS\system32\h1
C:\WINDOWS\system32\htdjirfc.dll
C:\WINDOWS\system32\hvgrrrrv.dll
C:\WINDOWS\system32\hwquiosr.exe
C:\WINDOWS\system32\hxwtkqhk.exe
C:\WINDOWS\system32\ihwhpubu.dll
C:\WINDOWS\system32\jojgowsg.exe
C:\WINDOWS\system32\jowchanj.exe
C:\WINDOWS\system32\jpsecvve.dll
C:\WINDOWS\system32\jynkmgjy.dll
C:\WINDOWS\system32\kcclbmyi.exe
C:\WINDOWS\system32\kfyxcjmg.dll
C:\WINDOWS\system32\kmllm.bak1
C:\WINDOWS\system32\kmllm.bak2
C:\WINDOWS\system32\kmllm.ini
C:\WINDOWS\system32\kmllm.ini2
C:\WINDOWS\system32\kmllm.tmp
C:\WINDOWS\system32\ksfghnqc.dll
C:\WINDOWS\system32\ksknxuta.exe
C:\WINDOWS\system32\lduagcfq.dll
C:\WINDOWS\system32\lidciqlx.exe
C:\WINDOWS\system32\lkvrwlyv.dll
C:\WINDOWS\system32\lokrtdqj.exe
C:\WINDOWS\system32\lwxplxth.exe
C:\WINDOWS\system32\lxsogdpf.dll
C:\WINDOWS\system32\mgtzinua.dll
C:\WINDOWS\system32\mjcwsxgr.exe
C:\WINDOWS\system32\msuongwh.exe
C:\WINDOWS\system32\nddtlkcy.exe
C:\WINDOWS\system32\nkpuoqbc.dll
C:\WINDOWS\system32\nvelevmp.exe
C:\WINDOWS\system32\nyisxfmw.dll
C:\WINDOWS\system32\oapbjcrr.ini
C:\WINDOWS\system32\obwhxguu.dll
C:\WINDOWS\system32\ojqwixcj.exe
C:\WINDOWS\system32\p1
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pcrxzxjj.dll
C:\WINDOWS\system32\polskcuh.dll
C:\WINDOWS\system32\ptwsirtv.dll
C:\WINDOWS\system32\q21
C:\WINDOWS\system32\qagfcppl.exe
C:\WINDOWS\system32\qdavyxje.exe
C:\WINDOWS\system32\qdcqaupe.exe
C:\WINDOWS\system32\qfcgaudl.ini
C:\WINDOWS\system32\qfmgaukb.exe
C:\WINDOWS\system32\qnonogul.dll
C:\WINDOWS\system32\qnonogul.dllbox
C:\WINDOWS\system32\qodvzpmd.dll
C:\WINDOWS\system32\rdakfmss.dll
C:\WINDOWS\system32\rgmulpyv.exe
C:\WINDOWS\system32\rmehyaya.exe
C:\WINDOWS\system32\rrcjbpao.dll
C:\WINDOWS\system32\rvkeuded.dll
C:\WINDOWS\system32\sewhbnww.dll
C:\WINDOWS\system32\sqdctunx.dll
C:\WINDOWS\system32\sqtmqkrj.exe
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tcuiiycg.exe
C:\WINDOWS\system32\vMW02a
C:\WINDOWS\system32\vtriswtp.ini
C:\WINDOWS\system32\wcqalbfu.exe
C:\WINDOWS\system32\wwnbhwes.ini
C:\WINDOWS\system32\xahgyutm.exe
C:\WINDOWS\system32\xgsuycgd.exe
C:\WINDOWS\system32\xlmdwhce.dll
C:\WINDOWS\system32\xuwhepya.dll
C:\WINDOWS\system32\xzpqqjvq.dll
C:\WINDOWS\system32\yiuhlpid.dll
C:\WINDOWS\system32\yquvhyiy.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NETWORK_MONITOR
——-\ApiMon
——-\DomainService


((((((((((((((((((((((((( Files Created from 202.-02-28 to 202.0.481. )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-05-03 16:31 3,716 —-a-w C:\Program Files\INSTALL.LOG
2005-11-17 01:19 389,632 -c–a-w C:\Documents and Settings\Owner\remote.exe
2005-04-03 04:47 9,701,419 -c–a-w C:\Program Files\VSH_9_0_10_EN-GB.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2007-10-17 23:03 66912 –a—— C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5159DF-E413-4878-8AE2-D921D41BB942}]
2007-10-17 22:40 421888 –a—— C:\WINDOWS\system32\bkinopuv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-10-17 23:03 267592 –a—— C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-10-17 23:03 267592]

[HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-10-17 23:03 267592]

[HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51]
"ArtChk"="C:\WINDOWS\system32\artchker.exe" [2007-10-11 16:03]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\Glenn\Start Menu\Programs\Startup\
V CAST Music Monitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe [2005-11-30 11:32:10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Thomas Kinkade Screen Saver.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Thomas Kinkade Screen Saver.lnk
backup=C:\WINDOWS\pss\Thomas Kinkade Screen Saver.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OCRAWARE.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OCRAWARE.lnk
backup=C:\WINDOWS\pss\OCRAWARE.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=C:\WINDOWS\pss\spamsubtract.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoLoadersFou1YdUcMaM]
"C:\WINDOWS\System32\caldat10.exe" /PC="CP.IST" /ShowLegalNote="nonbranded" /UninstallName="CtxPls"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
"c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
"C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"C:\Program Files\Common Files\AOL\1142305703\ee\AOLSoftware.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
C:\WINDOWS\System32\hphmon04.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\System32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04]
"C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
"c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
LTMSG.exe 7

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mciavi32]
C:\WINDOWS\System32\mciavi32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
"C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MISAggregator]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFTray]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
"C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
"C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe "C:\WINDOWS\system32\xuwhepya.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
"C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNM]
C:\Program Files\SpyNoMore\SNM.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ss7S3sg]
caldat10.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
"C:\Program Files\Multimedia Card Reader\shwicon2k.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\Program Files\AWS\WeatherBug\Weather.exe 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
"C:\Program Files\WildTangent\Apps\GameChannel.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)

R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys

.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 23:00:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-23 23:02:19 - machine was rebooted
.
— E O F —
Hello and welcome to the forum

Did the Geek Squad leave you without an Anti-Virus program? :o
Ask for a refund.

I don't see a anti-virus program running. Get this free one.

Click HERE and Save, Install, Update and run a full scan.


After the above:

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
The information requested was added by editing the original forum submit. I am slowly learning how to respond. I still need to run thewhatthetech diagnostic. Bugfr3
Log from recent Hijackthis - following Combofix
Pop ups occured during the combofix analysis.
I don't see them if I am using Firefox.
Bugfr3

Logfile of HijackThis v1.99.1
Scan saved at 11:28:25 PM, on 10/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\WillowRd\WillowRd.exe
C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: IKatzu Class - {EA5159DF-E413-4878-8AE2-D921D41BB942} - C:\WINDOWS\system32\bkinopuv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [ArtChk] C:\WINDOWS\system32\artchker.exe
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe
O4 - Global Startup: Thomas Kinkade Screen Saver.lnk = C:\Program Files\WillowRd\WillowRd.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm161YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

When finished, it shall produce a log for you, combofix.txt.

Can you post the C:\combofix.txt file?

Also:

I don't see a anti-virus program running. Get this free one.

Click HERE and Save, Install, Update and run a full scan.


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment
The Geek that left us after two tries of fixing the popups, still with the pop ups coming on the screen and wanting us to back up our files so we can reinstall the operating system, said that our Spy Sweeper was loaded on, along with the AntiVirus that came with the CD. So I am surprised that you don't see an Anti-Virus on my machine.

The antiVirus you had me click to came up with this error:
Not Found

The requested URL /softw/70free/setup/avg75free_446a965.exe was not found on this server.
Apache Server at free3.grisoft.cz Port 80Not Found

The machine is not slow to start up as in the past, he did get rid of some files that were found by Spy Sweeper, The pop ups come if I use IE, Firefox they don't. When I did the comboFix the pop ups came alive. I don't see the yellow triangle at the bottom, so long as I use Firefox.

Combofix. txt (it was in earlier section of this - I just did not know how to add it before (assuming I do now).
ComboFix 07-10-23.1 - Glenn 2007-10-23 22:52:47.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.133 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\Application Data.\salesmonitor
C:\Documents and Settings\Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\Glenn\Application Data\BestsellerAntivirus\Logs\update.log
C:\Documents and Settings\Glenn\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Glenn\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Glenn\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Owner\err.log
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Patricia\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Patricia\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Patricia\Favorites\Online Security Guide.lnk
C:\Program Files\BestsellerAntivirus
C:\Program Files\BestsellerAntivirus\Engines\AWBase\database\enemies.dat
C:\Program Files\BestsellerAntivirus\Engines\AWBase\vbpv.dat
C:\Program Files\BestsellerAntivirus\history.db
C:\Program Files\BestsellerAntivirus\ResErrors.log
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\004DEC6C.dat
C:\Program Files\Messenger\rteprejyc.html
C:\UGA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahedxntp.exe
C:\WINDOWS\system32\ahwnovyu.exe
C:\WINDOWS\system32\ajoeuyfj.exe
C:\WINDOWS\system32\anigjgjc.exe
C:\WINDOWS\system32\atudbbce.exe
C:\WINDOWS\system32\axopckrk.exe
C:\WINDOWS\system32\aypehwux.ini
C:\WINDOWS\system32\bfukszby.dll
C:\WINDOWS\system32\blqhirtg.exe
C:\WINDOWS\system32\chffbpuv.exe
C:\WINDOWS\system32\cjrotwmu.exe
C:\WINDOWS\system32\crlubbii.exe
C:\WINDOWS\system32\djovrool.exe
C:\WINDOWS\system32\dlbwfbqi.exe
C:\WINDOWS\system32\dnghkccz.dll
C:\WINDOWS\system32\dqpfuiyv.exe
C:\WINDOWS\system32\dvkkrbdp.exe
C:\WINDOWS\system32\ecgkcggx.exe
C:\WINDOWS\system32\efokluex.dll
C:\WINDOWS\system32\eleazqmy.dll
C:\WINDOWS\system32\euirtcgn.exe
C:\WINDOWS\system32\fbbyrbpx.dll
C:\WINDOWS\system32\fpdgosxl.ini
C:\WINDOWS\system32\frcaifcg.exe
C:\WINDOWS\system32\fwifiply.exe
C:\WINDOWS\system32\gmjcxyfk.ini
C:\WINDOWS\system32\gulgjrdk.exe
C:\WINDOWS\system32\gyfqmbon.exe
C:\WINDOWS\system32\gylsbvbr.exe
C:\WINDOWS\system32\h1
C:\WINDOWS\system32\htdjirfc.dll
C:\WINDOWS\system32\hvgrrrrv.dll
C:\WINDOWS\system32\hwquiosr.exe
C:\WINDOWS\system32\hxwtkqhk.exe
C:\WINDOWS\system32\ihwhpubu.dll
C:\WINDOWS\system32\jojgowsg.exe
C:\WINDOWS\system32\jowchanj.exe
C:\WINDOWS\system32\jpsecvve.dll
C:\WINDOWS\system32\jynkmgjy.dll
C:\WINDOWS\system32\kcclbmyi.exe
C:\WINDOWS\system32\kfyxcjmg.dll
C:\WINDOWS\system32\kmllm.bak1
C:\WINDOWS\system32\kmllm.bak2
C:\WINDOWS\system32\kmllm.ini
C:\WINDOWS\system32\kmllm.ini2
C:\WINDOWS\system32\kmllm.tmp
C:\WINDOWS\system32\ksfghnqc.dll
C:\WINDOWS\system32\ksknxuta.exe
C:\WINDOWS\system32\lduagcfq.dll
C:\WINDOWS\system32\lidciqlx.exe
C:\WINDOWS\system32\lkvrwlyv.dll
C:\WINDOWS\system32\lokrtdqj.exe
C:\WINDOWS\system32\lwxplxth.exe
C:\WINDOWS\system32\lxsogdpf.dll
C:\WINDOWS\system32\mgtzinua.dll
C:\WINDOWS\system32\mjcwsxgr.exe
C:\WINDOWS\system32\msuongwh.exe
C:\WINDOWS\system32\nddtlkcy.exe
C:\WINDOWS\system32\nkpuoqbc.dll
C:\WINDOWS\system32\nvelevmp.exe
C:\WINDOWS\system32\nyisxfmw.dll
C:\WINDOWS\system32\oapbjcrr.ini
C:\WINDOWS\system32\obwhxguu.dll
C:\WINDOWS\system32\ojqwixcj.exe
C:\WINDOWS\system32\p1
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pcrxzxjj.dll
C:\WINDOWS\system32\polskcuh.dll
C:\WINDOWS\system32\ptwsirtv.dll
C:\WINDOWS\system32\q21
C:\WINDOWS\system32\qagfcppl.exe
C:\WINDOWS\system32\qdavyxje.exe
C:\WINDOWS\system32\qdcqaupe.exe
C:\WINDOWS\system32\qfcgaudl.ini
C:\WINDOWS\system32\qfmgaukb.exe
C:\WINDOWS\system32\qnonogul.dll
C:\WINDOWS\system32\qnonogul.dllbox
C:\WINDOWS\system32\qodvzpmd.dll
C:\WINDOWS\system32\rdakfmss.dll
C:\WINDOWS\system32\rgmulpyv.exe
C:\WINDOWS\system32\rmehyaya.exe
C:\WINDOWS\system32\rrcjbpao.dll
C:\WINDOWS\system32\rvkeuded.dll
C:\WINDOWS\system32\sewhbnww.dll
C:\WINDOWS\system32\sqdctunx.dll
C:\WINDOWS\system32\sqtmqkrj.exe
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tcuiiycg.exe
C:\WINDOWS\system32\vMW02a
C:\WINDOWS\system32\vtriswtp.ini
C:\WINDOWS\system32\wcqalbfu.exe
C:\WINDOWS\system32\wwnbhwes.ini
C:\WINDOWS\system32\xahgyutm.exe
C:\WINDOWS\system32\xgsuycgd.exe
C:\WINDOWS\system32\xlmdwhce.dll
C:\WINDOWS\system32\xuwhepya.dll
C:\WINDOWS\system32\xzpqqjvq.dll
C:\WINDOWS\system32\yiuhlpid.dll
C:\WINDOWS\system32\yquvhyiy.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NETWORK_MONITOR
——-\ApiMon
——-\DomainService


((((((((((((((((((((((((( Files Created from 202.-02-28 to 202.0.481. )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-05-03 16:31 3,716 —-a-w C:\Program Files\INSTALL.LOG
2005-11-17 01:19 389,632 -c–a-w C:\Documents and Settings\Owner\remote.exe
2005-04-03 04:47 9,701,419 -c–a-w C:\Program Files\VSH_9_0_10_EN-GB.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2007-10-17 23:03 66912 –a—— C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5159DF-E413-4878-8AE2-D921D41BB942}]
2007-10-17 22:40 421888 –a—— C:\WINDOWS\system32\bkinopuv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-10-17 23:03 267592 –a—— C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-10-17 23:03 267592]

[HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-10-17 23:03 267592]

[HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 17:51]
"ArtChk"="C:\WINDOWS\system32\artchker.exe" [2007-10-11 16:03]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\Glenn\Start Menu\Programs\Startup\
V CAST Music Monitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe [2005-11-30 11:32:10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Thomas Kinkade Screen Saver.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Thomas Kinkade Screen Saver.lnk
backup=C:\WINDOWS\pss\Thomas Kinkade Screen Saver.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OCRAWARE.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OCRAWARE.lnk
backup=C:\WINDOWS\pss\OCRAWARE.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=C:\WINDOWS\pss\spamsubtract.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoLoadersFou1YdUcMaM]
"C:\WINDOWS\System32\caldat10.exe" /PC="CP.IST" /ShowLegalNote="nonbranded" /UninstallName="CtxPls"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
"c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
"C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"C:\Program Files\Common Files\AOL\1142305703\ee\AOLSoftware.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
C:\WINDOWS\System32\hphmon04.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\System32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04]
"C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
"c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
"C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
LTMSG.exe 7

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mciavi32]
C:\WINDOWS\System32\mciavi32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
"C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MISAggregator]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFTray]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsgCenterExe]
"C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
"C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe "C:\WINDOWS\system32\xuwhepya.dll",sitypnow

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
"C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNM]
C:\Program Files\SpyNoMore\SNM.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ss7S3sg]
caldat10.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
"C:\Program Files\Multimedia Card Reader\shwicon2k.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\Program Files\AWS\WeatherBug\Weather.exe 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
"C:\Program Files\WildTangent\Apps\GameChannel.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)

R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys

.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 23:00:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-23 23:02:19 - machine was rebooted
.
— E O F –
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\bkinopuv.dll
C:\WINDOWS\system32\artchker.exe
c:\ALCXMNTR.EXE
C:\WINDOWS\System32\caldat10.exe
C:\WINDOWS\system32\xuwhepya.dll

Folder::
C:\Program Files\AskSBar
C:\PROGRA~1\MYWEBS~1\bar
C:\Program Files\AWS
C:\Program Files\WildTangent

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5159DF-E413-4878-8AE2-D921D41BB942}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}"=-
[-HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"=-
[-HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ArtChk"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoLoadersFou1YdUcMaM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ss7S3sg]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
I ran the scan you had me add to combo.exe - The output is too big to add into this site. There is a long series of "Wildtangent/Apps", how would you want me to edit this .txt file be able to cut/paste into here? There were no hidden files after the analysis. Bugfr3

I ran the scan you had me add to combo.exe - The output is too big to add into this site. There is a long series of "Wildtangent/Apps", how would you want me to edit this .txt file be able to cut/paste into here?
There were no hidden files after the analysis.
Bugfr3

Can you copy / paste 1/2 of it at a a time?
I still need help, but I have been fighting to be able to login into Whatthetech. For whatever reason it would not take my password. I have gone through my email link and logged in, go figure. I will cut and paste the log you wanted in pieces. Bugfr3 returns
Sheet one of : ComboFix 07-10-23.1 - Glenn 2007-10-30 21:52:32.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.160 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-31 ))))))))))))))))))))))))))))))) . 2007-10-27 00:18 d——– C:\Documents and Settings\Glenn\Application Data\Apple Computer 2007-10-25 05:26 d——– C:\Documents and Settings\Patricia\Application Data\Webroot 2007-10-24 21:35 d——– C:\Documents and Settings\LocalService\Application Data\Webroot 2007-10-24 21:35 1,526,072 –a—— C:\WINDOWS\WRSetup.dll 2007-10-24 21:35 20,280 –a—— C:\WINDOWS\system32\drivers\SSFS0BB9.sys 2007-10-23 22:51 51,200 –a—— C:\WINDOWS\NirCmd.exe 2007-10-23 22:18 d——– C:\Program Files\WillowRd 2007-10-23 22:18 297,472 –a—— C:\WINDOWS\system32\ltkrn10N.dll 2007-10-23 22:18 266,752 –a—— C:\WINDOWS\system32\Lfcmp10n.dll 2007-10-23 22:18 231,424 –a—— C:\WINDOWS\system32\LTDIS10N.dll 2007-10-23 22:18 221,696 –a—— C:\WINDOWS\system32\ltefx10N.dll 2007-10-23 22:18 103,424 –a—— C:\WINDOWS\system32\ltfil10N.DLL 2007-10-23 22:18 69,632 –a—— C:\WINDOWS\system32\Sswillow.scr 2007-10-23 22:18 34,304 –a—— C:\WINDOWS\system32\lfbmp10N.dll 2007-10-21 18:38 1,156 –a—— C:\WINDOWS\mozver.dat 2007-10-19 15:24 1,152 –a—— C:\WINDOWS\system32\windrv.sys 2007-10-19 15:20 d——– C:\Program Files\Common Files\Download Manager 2007-10-19 14:19 d——– C:\Documents and Settings\NetworkService\Application Data\Webroot 2007-10-19 14:19 163,640 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys 2007-10-19 14:19 21,816 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys 2007-10-19 14:19 20,544 –a—— C:\WINDOWS\system32\drivers\SSFS0509.sys 2007-10-19 14:18 d——– C:\Program Files\Webroot 2007-10-19 14:18 d——– C:\Documents and Settings\Administrator\Application Data\Webroot 2007-10-18 01:14 d——– C:\Documents and Settings\Glenn\Application Data\Webroot 2007-10-17 23:41 d——– C:\Documents and Settings\Owner\Application Data\Webroot 2007-10-17 23:04 23,864 –a—— C:\WINDOWS\system32\drivers\sskbfd.sys 2007-10-17 22:57 164 –a—— C:\install.dat 2007-10-17 21:41 d——– C:\WINDOWS\pss 2007-10-17 20:32 d——– C:\Documents and Settings\Administrator\WINDOWS 2007-10-17 20:32 d——– C:\Documents and Settings\Administrator\Application Data\Symantec 2007-10-17 20:32 d——– C:\Documents and Settings\Administrator\Application Data\Sonic 2007-10-17 20:32 d——– C:\Documents and Settings\Administrator\Application Data\SampleView 2007-10-17 20:32 d——– C:\Documents and Settings\Administrator\Application Data\interMute 2007-10-14 08:48 d——– C:\Documents and Settings\Patricia\Application Data\OLYMPUS 2007-10-11 16:03 d——– C:\WINDOWS\system32\kat1 2007-10-11 16:03 d——– C:\WINDOWS\system32\ipd2 2007-10-11 16:03 45,056 –a—— C:\WINDOWS\system32\katzppd.exe 2007-10-11 16:03 45,056 –a—— C:\WINDOWS\system32\katzpoeoj.exe 2007-10-11 16:03 44,922 –a—— C:\WINDOWS\system32\IKatzuUninstall.exe 2007-10-07 21:56 d——– C:\Documents and Settings\Glenn\Application Data\OLYMPUS 2007-10-01 20:00 d——– C:\Documents and Settings\Patricia\Application Data\Apple Computer 2007-09-16 16:02 d——– C:\Documents and Settings\Glenn\Application Data\Kensington 2007-09-16 15:57 d——– C:\Program Files\Kensington 2007-09-16 15:47 21,504 –a—— C:\WINDOWS\system32\hidserv.dll 2007-09-16 15:47 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll 2007-09-16 15:47 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys 2007-09-16 15:47 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys 2007-09-15 16:51 d——– C:\Documents and Settings\Owner\Application Data\Logitech 2007-09-12 13:41 d——– C:\Documents and Settings\Patricia\Application Data\Logitech 2007-09-08 22:21 d——– C:\Documents and Settings\Glenn\Application Data\Logitech 2007-09-08 22:19 1,419,024 –a—— C:\WINDOWS\system32\WdfCoInstaller01005.dll 2007-09-08 22:19 79,376 –a—— C:\WINDOWS\system32\drivers\LMouKE.Sys 2007-09-08 22:19 63,248 –a—— C:\WINDOWS\system32\drivers\L8042mou.Sys 2007-09-08 22:19 56,080 –a—— C:\WINDOWS\KHALMNPR.Exe 2007-09-08 22:19 36,112 –a—— C:\WINDOWS\system32\drivers\LMouFilt.Sys 2007-09-08 22:19 34,832 –a—— C:\WINDOWS\system32\drivers\LHidFilt.Sys 2007-09-08 22:19 20,496 –a—— C:\WINDOWS\system32\drivers\L8042Kbd.sys 2007-09-08 22:18 d——– C:\Program Files\Logitech 2007-09-08 22:18 d——– C:\Program Files\Common Files\Logitech 2007-09-08 22:18 d——– C:\Documents and Settings\Glenn\Application Data\InstallShield 2007-09-08 22:18 163,840 –a—— C:\WINDOWS\system32\kemutb.dll 2007-09-08 22:18 135,168 –a—— C:\WINDOWS\system32\KemUtil.dll 2007-09-08 22:18 110,592 –a—— C:\WINDOWS\system32\KemWnd.dll 2007-09-08 22:18 69,632 –a—— C:\WINDOWS\system32\KemXML.dll 2007-09-08 21:50 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys 2007-09-08 21:50 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys 2007-09-08 21:50 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys 2007-09-08 21:50 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys 2007-09-08 21:50 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys 2007-09-08 21:50 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys 2007-09-04 09:28 d——– C:\Documents and Settings\Patricia\Application Data\Share-to-Web Upload Folder 2007-09-04 09:27 d——– C:\Documents and Settings\Patricia\WINDOWS 2007-09-04 09:27 d——– C:\Documents and Settings\Patricia\Application Data\Symantec 2007-09-04 09:27 d——– C:\Documents and Settings\Patricia\Application Data\Sonic 2007-09-04 09:27 d——– C:\Documents and Settings\Patricia\Application Data\SampleView 2007-09-04 09:27 d——– C:\Documents and Settings\Patricia\Application Data\interMute 2007-09-03 17:12 d——– C:\Program Files\iTunes 2007-09-03 17:12 d——– C:\Program Files\iPod 2007-09-03 17:09 d—-c— C:\WINDOWS\system32\DRVSTORE 2007-09-03 17:09 d——– C:\Program Files\Common Files\Apple
Sheet two:
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-18 03:39 ——— d—–w C:\Program Files\Symantec
2007-10-18 03:39 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-18 03:07 ——— d—–w C:\Program Files\NewSoft
2007-10-18 03:02 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-18 02:58 ——— d—–w C:\Program Files\interMute
2007-10-18 02:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\interMute
2007-10-14 20:56 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-14 13:28 ——— d—–w C:\Program Files\Easy Internet signup
2007-10-14 04:14 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-14 04:14 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-11 21:03 24,576 —-a-w C:\WINDOWS\system32\msxml3a.dll
2007-10-03 02:07 ——— d—–w C:\Program Files\Google
2007-09-09 03:20 0 -c-ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-09-09 03:20 0 -c-ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-09-04 14:28 ——— d—–w C:\Program Files\Web Publish
2007-09-03 22:11 ——— d—–w C:\Program Files\QuickTime
2007-09-03 21:57 ——— d—–w C:\Program Files\Apple Software Update
2007-09-03 14:22 ——— d—–w C:\Program Files\Common Files\SysProtect
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-31 00:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 00:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 00:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 00:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 00:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 00:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 00:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 00:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-09 13:16 582,656 —-a-w C:\WINDOWS\system32\rpcrt4.dll
2007-05-03 16:31 3,716 —-a-w C:\Program Files\INSTALL.LOG
2005-11-17 01:19 389,632 -c–a-w C:\Documents and Settings\Owner\remote.exe
2005-04-03 04:47 9,701,419 -c–a-w C:\Program Files\VSH_9_0_10_EN-GB.EXE
2006-05-17 10:21:31 818,621 -csh–w C:\WINDOWS\system32\cccdd.bak1
2006-07-08 14:30:33 925,805 -csh–w C:\WINDOWS\system32\cccdd.bak2
2006-07-08 14:54:56 929,582 -csh–w C:\WINDOWS\system32\cccdd.ini2
.

((((((((((((((((((((((((((((( snapshot_2007-10-25_23.35.12.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2002-08-29 12:00:00 74,802 -c—-w C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\ATL.DLL
+ 2002-08-29 12:00:00 995,383 -c—-w C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MFC42.DLL
+ 2002-08-29 12:00:00 995,384 -c—-w C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MFC42U.DLL
+ 2002-08-29 12:00:00 401,462 -c—-w C:\WINDOWS\I386\ASMS\6000\MSFT\VCRTL\MSVCP60.DLL
+ 2002-08-29 12:00:00 921,088 -c—-w C:\WINDOWS\I386\ASMS\6000\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DLL
+ 2002-08-29 12:00:00 50,688 -c—-w C:\WINDOWS\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCIRT.DLL
+ 2002-08-29 12:00:00 322,560 -c—-w C:\WINDOWS\I386\ASMS\7000\MSFT\WINDOWS\MSWINCRT\MSVCRT.DLL
+ 2002-08-29 12:00:00 55,632 -c—-w C:\WINDOWS\I386\DRW\1033\DWINTL.DLL
+ 2002-08-29 12:00:00 162,128 -c—-w C:\WINDOWS\I386\DRW\DWWIN.EXE
+ 2002-08-29 12:00:00 28,672 -c—-w C:\WINDOWS\I386\DRW\FAULTH.DLL
+ 2002-08-29 12:00:00 668,672 -c—-w C:\WINDOWS\I386\SYSTEM32\NTDLL.DLL
+ 2002-08-29 12:00:00 470,016 -c—-w C:\WINDOWS\I386\SYSTEM32\SMSS.EXE
+ 2002-08-29 12:00:00 12,288 -c—-w C:\WINDOWS\I386\WINNTUPG\APMUPGRD.DLL
+ 2002-08-29 12:00:00 6,656 -c—-w C:\WINDOWS\I386\WINNTUPG\BOSCOMP.DLL
+ 2002-08-29 12:00:00 58,128 -c—-w C:\WINDOWS\I386\WINNTUPG\CFGMGR32.DLL
+ 2002-08-29 12:00:00 40,960 -c—-w C:\WINDOWS\I386\WINNTUPG\CLUSCOMP.DLL
+ 2002-08-29 12:00:00 5,120 -c—-w C:\WINDOWS\I386\WINNTUPG\FSFILTER.DLL
+ 2002-08-29 12:00:00 6,656 -c—-w C:\WINDOWS\I386\WINNTUPG\FTCOMP.DLL
+ 2002-08-29 12:00:00 5,632 -c—-w C:\WINDOWS\I386\WINNTUPG\INPUPGRD.DLL
+ 2002-08-29 12:00:00 5,632 -c—-w C:\WINDOWS\I386\WINNTUPG\MS\MODEMSHR\MDMSHRUP.DLL
+ 2002-08-29 12:00:00 30,748 -c—-w C:\WINDOWS\I386\WINNTUPG\MS\SNA\IBMMGUG.DLL
+ 2002-08-29 12:00:00 38,941 -c—-w C:\WINDOWS\I386\WINNTUPG\MS\SNA\NTSNAUPG.DLL
+ 2002-08-29 12:00:00 28,701 -c—-w C:\WINDOWS\I386\WINNTUPG\MS\SNA\SNADLCUG.DLL
+ 2002-08-29 12:00:00 5,632 -c—-w C:\WINDOWS\I386\WINNTUPG\MSMQCOMP.DLL
+ 2002-08-29 12:00:00 112,128 -c—-w C:\WINDOWS\I386\WINNTUPG\NETUPGRD.DLL
+ 2002-08-29 12:00:00 11,264 -c—-w C:\WINDOWS\I386\WINNTUPG\NTDSUPG.DLL
+ 2002-08-29 12:00:00 9,756 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ASYNC\DGUPGRD.DLL
+ 2002-08-29 12:00:00 72,732 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ISDN\BRI\DIGIUPG.DLL
+ 2002-08-29 12:00:00 28,701 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\ISDN\PRI\DIGPRIUP.DLL
+ 2002-08-29 12:00:00 11,292 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\DIGI\REALPORT\DGRPUPG.DLL
+ 2002-08-29 12:00:00 114,717 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\EQN\EQNUPGRD.DLL
+ 2002-08-29 12:00:00 31,744 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\SPX\MPS\SPXUPGRD.DLL
+ 2002-08-29 12:00:00 33,792 -c—-w C:\WINDOWS\I386\WINNTUPG\OEM\TIGERJET\TJUPG.DLL
+ 2002-08-29 12:00:00 323,344 -c—-w C:\WINDOWS\I386\WINNTUPG\SETUPAPI.DLL
+ 2002-08-29 12:00:00 4,608 -c—-w C:\WINDOWS\I386\WINNTUPG\TSCOMP.DLL
+ 2002-08-29 12:00:00 11,776 -c—-w C:\WINDOWS\I386\WINNTUPG\VIDUPGRD.DLL
+ 2004-08-04 07:56:41 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 07:56:41 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 07:56:41 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2006-06-03 11:40:49 33,792 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-01-04 13:36:36 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-01-04 13:36:36 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-01-04 13:36:37 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 07:56:42 38,912 -c–a-w C:\WINDOWS\ie7\hmmapi.dll
+ 2004-08-04 07:56:50 34,304 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 07:56:42 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 07:56:42 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2002-08-29 12:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 07:56:42 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-01-04 10:36:30 18,432 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 07:56:42 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-01-04 13:36:37 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 07:56:42 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 07:56:42 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 07:56:50 93,184 -c–a-w C:\WINDOWS\ie7\iexplore.exe
+ 2004-08-04 07:56:42 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-01-04 13:36:38 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-01-04 13:36:38 16,384 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 07:56:42 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 07:56:53 29,184 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-01-04 13:36:48 3,056,640 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-01-04 13:36:51 448,512 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 07:56:14 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2002-08-29 12:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-01-04 13:36:52 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-01-04 13:36:54 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 07:56:44 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2007-01-04 13:36:54 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2006-11-08 02:04:18 31,856 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2006-11-08 02:01:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 21:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-06 21:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 07:56:46 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2007-01-25 12:48:49 615,424 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 07:56:46 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2006-12-19 18:08:07 852,480 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 07:56:46 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-01-04 13:37:08 658,944 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2006-11-07 08:26:24 123,904 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\advpack.dll
+ 2006-11-08 02:03:36 131,584 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\extmgr.dll
+ 2006-11-07 08:26:28 54,784 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ie4uinit.exe
+ 2006-11-07 08:26:56 152,064 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieakeng.dll
+ 2006-11-07 08:27:02 229,376 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieaksie.dll
+ 2006-11-07 08:25:14 161,792 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieakui.dll
+ 2006-09-06 04:01:26 2,451,824 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieapfltr.dat
+ 2006-10-17 16:27:56 380,928 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieapfltr.dll
+ 2006-11-07 08:27:10 382,976 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\iedkcs32.dll
+ 2006-11-08 02:03:36 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieframe.dll
+ 2006-11-07 08:26:28 43,008 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\iernonce.dll
+ 2006-10-17 16:57:20 266,752 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\iertutil.dll
+ 2006-11-07 08:26:32 13,312 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\ieudinit.exe
+ 2006-10-17 17:04:40 622,080 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
+ 2006-11-08 02:03:36 27,136 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\jsproxy.dll
+ 2006-11-08 02:03:36 458,752 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\msfeeds.dll
+ 2006-11-08 02:03:36 50,688 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\msfeedsbs.dll
+ 2006-11-08 02:03:36 3,577,856 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\mshtml.dll
+ 2006-11-08 02:03:36 475,648 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\mshtmled.dll
+ 2006-10-17 17:05:10 192,000 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\msrating.dll
+ 2006-11-08 02:03:36 670,720 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\mstime.dll
+ 2006-10-17 17:04:46 101,376 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\occache.dll
+ 2006-01-19 19:29:19 213,216 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\updspapi.dll
+ 2006-10-17 17:05:22 105,984 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\url.dll
+ 2006-11-08 02:03:36 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\urlmon.dll
+ 2006-11-08 02:03:36 231,424 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\webcheck.dll
+ 2006-11-08 02:03:36 818,688 -c—-w C:\WINDOWS\ie7updates\KB931768-IE7\wininet.dll
+ 2007-03-07 17:45:14 124,928 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\advpack.dll
+ 2007-03-07 17:45:15 132,608 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\extmgr.dll
+ 2007-03-07 08:28:17 56,832 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ie4uinit.exe
+ 2007-03-07 17:45:15 153,088 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieakeng.dll
+ 2007-03-07 17:45:15 230,400 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieaksie.dll
+ 2007-02-21 08:00:53 161,792 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieakui.dll
+ 2007-04-03 04:36:20 2,453,952 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieapfltr.dat
+ 2007-04-03 14:46:37 383,488 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieapfltr.dll
+ 2007-03-07 17:45:15 384,000 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\iedkcs32.dll
+ 2007-03-07 17:45:16 6,054,400 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieframe.dll
+ 2007-03-07 17:45:16 44,544 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\iernonce.dll
+ 2007-03-07 17:45:16 266,752 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\iertutil.dll
+ 2007-02-27 08:20:47 13,824 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\ieudinit.exe
+ 2007-02-21 08:00:58 623,616 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
+ 2007-03-07 17:45:16 27,136 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\jsproxy.dll
+ 2007-03-07 17:45:16 458,752 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\msfeeds.dll
+ 2007-03-07 17:45:16 51,712 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\msfeedsbs.dll
+ 2007-03-07 17:45:17 3,581,952 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\mshtml.dll
+ 2007-03-07 17:45:17 477,696 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\mshtmled.dll
+ 2007-03-07 17:45:17 193,024 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\msrating.dll
+ 2007-03-07 17:45:17 670,720 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\mstime.dll
+ 2007-03-07 17:45:17 102,400 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\occache.dll
+ 2006-01-19 19:29:19 213,216 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe
+ 2006-01-19 19:29:19 371,424 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\updspapi.dll
+ 2007-03-07 17:45:17 105,984 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\url.dll
+ 2007-03-07 17:45:18 1,150,464 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\urlmon.dll
+ 2007-03-07 17:45:18 232,960 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\webcheck.dll
+ 2007-03-07 17:45:18 822,784 -c—-w C:\WINDOWS\ie7updates\KB933566-IE7\wininet.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2006-12-22 15:49:12 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-04-25 08:41:08 124,928 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2006-10-17 16:57:50 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-04-25 08:41:09 132,608 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2006-10-17 16:58:20 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-04-24 14:26:20 56,832 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-04-25 08:41:09 153,088 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-04-25 08:41:10 230,400 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-04-24 07:30:38 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-04-25 08:41:10 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-04-25 08:41:10 384,512 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-04-25 08:41:11 6,058,496 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-04-25 08:41:11 44,544 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-04-25 08:41:11 267,776 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-04-24 14:26:20 13,824 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-04-24 14:26:26 625,152 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-04-25 08:41:13 27,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-04-25 08:41:13 459,264 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-04-25 08:41:13 52,224 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-05-08 09:24:35 3,583,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-04-25 08:41:15 477,696 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-04-25 08:41:15 193,024 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-04-25 08:41:15 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-04-25 08:41:15 102,400 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-04-25 08:41:15 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-04-25 08:41:16 1,152,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-04-25 08:41:17 232,960 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-04-25 08:41:17 822,784 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2004-08-04 07:56:42 220,160 -c–a-w C:\WINDOWS\ime\mscandui.dll
+ 2004-08-04 07:56:45 130,048 -c–a-w C:\WINDOWS\ime\softkbd.dll
+ 2004-08-04 07:56:29 62,976 -c–a-w C:\WINDOWS\ime\spgrmr.dll
+ 2004-08-04 07:56:45 250,880 -c–a-w C:\WINDOWS\ime\sptip.dll
+ 2007-06-27 03:10:26 317,440 —-a-w C:\WINDOWS\inf\unregmp2.exe
+ 2004-01-21 04:10:42 9,638 -c–a-r C:\WINDOWS\Installer\{0613467F-A45E-4CB1-9ECE-1F3DD79FB927}\ARPPRODUCTICON.exe
+ 2004-07-28 04:55:57 45,056 -c–a-r C:\WINDOWS\Installer\{0D396571-7BBD-44CE-ABB3-518BF86B72F7}\_73A08744BE78_4C68_91E8_AE13955031AE.exe
+ 2004-01-21 03:40:24 81,920 -c–a-r C:\WINDOWS\Installer\{1D643CD7-4DD6-11D7-A4E0-000874180BB3}\MnyIco.exe
+ 2004-07-18 02:01:32 22,486 -c–a-r C:\WINDOWS\Installer\{21DBBDD6-93A5-4326-9A04-C9A5C9148502}\ARPPRODUCTICON.exe
+ 2004-01-21 02:31:28 8,854 -c–a-r C:\WINDOWS\Installer\{29B39FB2-5ADF-4F94-BC82-13942871DD0D}\Unload_sm.exe
+ 2004-07-01 18:01:14 4,150 -c–a-r C:\WINDOWS\Installer\{2E132061-C78A-48D4-A899-1D13B9D189FA}\HewlettPackard_0002ICON.exe
+ 2007-07-29 23:19:32 29,926 -c–a-r C:\WINDOWS\Installer\{3249FD43-B24B-413F-B786-F8FEA32FA747}\ARPPRODUCTICON.exe
+ 2007-07-29 23:19:32 69,632 -c–a-r C:\WINDOWS\Installer\{3249FD43-B24B-413F-B786-F8FEA32FA747}\NewShortcut1_3249FD43B24B413FB786F8FEA32FA747.exe
+ 2007-07-29 23:19:32 29,926 -c–a-r C:\WINDOWS\Installer\{3249FD43-B24B-413F-B786-F8FEA32FA747}\NewShortcut3_3249FD43B24B413FB786F8FEA32FA747.exe
+ 2004-01-21 01:20:24 166,912 -c–a-r C:\WINDOWS\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
+ 2004-09-12 00:09:14 25,214 -c–a-r C:\WINDOWS\Installer\{369B36BE-3D64-4641-9AEA-808D436FE130}\PI_2003.exe
+ 2004-09-12 00:09:14 25,214 -c–a-r C:\WINDOWS\Installer\{369B36BE-3D64-4641-9AEA-808D436FE130}\PI2_2003.exe
+ 2004-09-12 00:09:14 25,214 -c–a-r C:\WINDOWS\Installer\{369B36BE-3D64-4641-9AEA-808D436FE130}\PIE_2003.exe
+ 2004-09-12 00:09:14 25,214 -c–a-r C:\WINDOWS\Installer\{369B36BE-3D64-4641-9AEA-808D436FE130}\PIL_2003.exe
+ 2006-12-17 19:19:39 32,768 -c–a-r C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\icon.exe
+ 2004-07-19 03:50:26 21,630 -c–a-r C:\WINDOWS\Installer\{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}\ARPPRODUCTICON.exe
+ 2004-07-19 03:50:26 21,630 -c–a-r C:\WINDOWS\Installer\{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}\Quicken_1.exe
+ 2004-01-21 02:34:54 40,960 -c–a-r C:\WINDOWS\Installer\{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}\NewShortcut11_1.9ABF444C_1773_4CB6_8B8C_D4E755C19A8B.exe
+ 2004-01-21 02:34:54 40,960 -c–a-r C:\WINDOWS\Installer\{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}\NewShortcut9_1.9ABF444C_1773_4CB6_8B8C_D4E755C19A8B.exe
+ 2004-01-21 03:39:06 167,936 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\_31E17DA65B49_4890_8278_D9E0E69C669C.exe
+ 2004-01-21 03:39:06 65,536 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\_44791D757700_41C1_A9EF_F044CC7CAAE8.exe
+ 2004-01-21 03:39:06 65,536 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\_69D0AC841342_4703_A9E3_FCC61E10EE52.exe
+ 2004-01-21 03:39:06 17,534 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\gtngstrtd.exe
+ 2004-01-21 03:39:06 4,710 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\Win2Kico.exe
+ 2004-01-21 03:39:06 4,710 -c–a-r C:\WINDOWS\Installer\{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}\WSBico.exe
+ 2004-01-21 02:33:40 40,960 -c–a-r C:\WINDOWS\Installer\{81DD5688-695A-4c1d-AE7D-368BF857725A}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
+ 2004-01-21 03:39:23 81,920 -c–a-r C:\WINDOWS\Installer\{8C64E145-54BA-11D6-91B1-00500462BE80}\MnyIco.exe
+ 2004-04-07 12:33:51 593,920 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2004-04-07 12:33:51 12,288 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2004-04-07 12:33:51 135,168 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2004-04-07 12:33:51 11,264 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2004-04-07 12:33:51 27,136 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2004-04-07 12:33:51 4,096 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-04-07 12:33:51 794,624 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2004-04-07 12:33:51 249,856 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2004-04-07 12:33:51 61,440 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2004-04-07 12:33:51 23,040 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2004-04-07 12:33:51 286,720 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2004-04-07 12:33:51 409,600 -c–a-r C:\WINDOWS\Installer\{91110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2004-01-21 03:42:00 12,288 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2004-01-21 03:42:00 135,168 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2004-01-21 03:42:00 11,264 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2004-01-21 03:42:00 27,136 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2004-01-21 03:42:00 4,096 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-01-21 03:42:00 794,624 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2004-01-21 03:42:00 249,856 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2004-01-21 03:42:00 23,040 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2004-01-21 03:42:00 286,720 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2004-01-21 03:42:00 409,600 -c–a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2004-01-21 03:20:51 147,456 -c–a-r C:\WINDOWS\Installer\{9541FED0-327F-4DF0-8B96-EF57EF622F19}\RecordNow.exe
+ 2007-10-27 05:19:04 102,400 —-a-r C:\WINDOWS\Installer\{974C05A0-C76C-4724-A9A2-11D5D1355729}\iTunesIco.exe
+ 2007-03-04 03:53:54 61,440 -c–a-r C:\WINDOWS\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\EasyShareDesktopShortcut.exe
+ 2007-03-04 03:53:54 176,128 -c–a-r C:\WINDOWS\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\EasyShareStartMenu.exe
+ 2007-03-04 03:53:54 176,128 -c–a-r C:\WINDOWS\Installer\{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}\EasyShareStartupShortcut.exe
+ 2006-11-22 04:51:52 24,064 -c–a-r C:\WINDOWS\Installer\{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}\AppleSoftwareUpdateIco.exe
+ 2004-09-12 00:08:21 22,798 -c–a-r C:\WINDOWS\Installer\{ABEB838C-A1A7-4C5D-B7E1-8B4314B00544}\MsblIco.Exe
+ 2005-08-11 03:47:46 25,214 -c–a-r C:\WINDOWS\Installer\{AC76BA86-0000-7EC8-7489-000000000702}\ARPPRODUCTICON.exe
+ 2005-08-11 03:48:50 25,214 -c–a-r C:\WINDOWS\Installer\{AC76BA86-0000-7EC8-7489-000000000703}\ARPPRODUCTICON.exe
+ 2007-08-17 21:29:42 295,606 -c–a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81000000003}\SC_Reader.exe
+ 2005-07-20 02:28:15 25,214 -c–a-r C:\WINDOWS\Installer\{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}\Endissrv.exe
+ 2004-11-16 04:24:30 131,072 -c–a-r C:\WINDOWS\Installer\{BE20E2F5-1903-4AAE-B1AF-2046E586C925}\NewShortcut4_8C3BCD70236347B8A53EEE8A82FD5C78.exe
+ 2007-10-12 11:44:27 32,768 —-a-r C:\WINDOWS\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}\icon.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\Alarm.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\AnalogRecorder.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\AudioConverter.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\CDPrint.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\Dancer.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\MP3Pack.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\PartyMode.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\PhotoStory.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\SyncAndGo.exe
+ 2004-01-21 03:44:20 65,536 -c–a-r C:\WINDOWS\Installer\{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}\Tour.exe
+ 2007-08-07 20:08:43 25,214 -c–a-r C:\WINDOWS\Installer\{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}\ARPPRODUCTICON.exe
+ 2007-08-07 20:08:43 25,214 -c–a-r C:\WINDOWS\Installer\{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}\VerboseShortcut_7C49EA425647405184C2E6404F25A931.exe
+ 2007-08-07 20:08:43 25,214 -c–a-r C:\WINDOWS\Installer\{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}\YMJDesktopShortcut_7C49EA425647405184C2E6404F25A931.exe
+ 2007-08-07 20:08:43 25,214 -c–a-r C:\WINDOWS\Installer\{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}\YMJProgramsShortcu_7C49EA425647405184C2E6404F25A931.exe
+ 2004-04-07 06:05:56 25,214 -c–a-r C:\WINDOWS\Installer\{EF9967D8-1999-4260-ACC2-86901AA36650}\ARPPRODUCTICON.exe
- 1998-10-29 22:45:06 306,688 -c–a-w C:\WINDOWS\IsUninst.exe
+ 1998-10-29 21:45:06 306,688 —-a-w C:\WINDOWS\IsUninst.exe
+ 2003-02-21 10:09:46 57,344 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_diasymreader.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_iehost.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
+ 2002-05-15 00:42:38 5,632 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscordbi.dll
+ 2002-07-20 02:52:48 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorrc.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_mscorsec.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.configuration.install.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.data.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
+ 2002-06-28 03:45:32 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_VsaVb7rt.dll
+ 2002-05-15 00:42:38 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbs_wminet_utils.dll
+ 2003-02-21 10:09:32 5,120 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
+ 2003-02-21 09:43:50 131,072 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
+ 2003-02-21 17:59:44 16,896 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2003-02-21 18:55:06 94,208 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2002-02-13 02:55:52 54,688 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\dwintl.dll
+ 2003-02-21 18:02:16 131,072 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2003-03-19 14:38:52 122,880 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\vjscui.dll
+ 2003-03-19 14:36:12 102,400 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\vjslibui.dll
+ 2003-02-21 20:04:20 155,648 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 22:24:08 7,680 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2003-02-21 20:00:36 98,304 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-21 10:19:42 24,576 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2007-04-14 02:30:52 258,048 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 10:19:22 40,960 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2004-07-15 06:49:18 20,480 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2004-07-15 06:49:26 32,768 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2007-04-14 02:30:52 32,768 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2002-07-30 02:11:50 219,136 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-21 22:24:10 94,208 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-21 22:24:32 49,152 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2007-04-14 01:57:52 81,920 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2004-07-15 16:23:28 49,152 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2004-07-15 16:23:44 626,688 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2003-02-21 22:24:34 12,288 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-21 22:24:36 33,792 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-21 19:12:24 28,672 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-22 01:21:40 524,288 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2002-05-31 17:15:48 186,696 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\dw15.exe
+ 2003-02-21 10:16:32 798,720 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2004-07-15 05:24:30 282,624 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-10-08 19:30:14 81,920 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe
+ 2003-02-21 22:24:38 7,680 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2004-07-15 19:31:00 8,192 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2004-07-15 19:31:04 32,768 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-21 22:24:40 4,608 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2004-07-15 05:35:30 196,608 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-21 22:24:42 15,872 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-21 10:22:24 40,960 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-21 22:24:44 26,112 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-21 22:24:52 40,960 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2004-07-15 19:28:58 720,896 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 19:28:56 299,008 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-21 22:24:54 28,672 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-21 22:25:02 6,144 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-21 22:24:58 32,768 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-21 22:25:06 11,264 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-21 22:25:02 6,656 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2004-07-15 19:28:50 49,152 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2004-07-15 19:28:50 49,152 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-21 22:25:06 1,564,672 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2004-07-15 05:32:44 86,016 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2004-07-15 05:32:46 233,472 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2007-04-14 01:57:58 86,016 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-14 01:56:30 315,392 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-14 01:58:00 102,400 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 01:50:46 2,142,208 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 09:43:52 131,072 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-21 10:06:34 65,536 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2004-07-15 05:33:22 143,360 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2004-07-15 05:33:24 81,920 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2007-04-14 01:58:02 77,824 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-14 01:57:00 2,523,136 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-21 10:09:24 9,216 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2007-04-14 01:57:28 2,514,944 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-21 19:42:22 348,160 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-21 10:18:34 20,480 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-21 09:43:36 22,528 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2007-01-15 21:11:26 73,728 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-21 10:09:46 73,728 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2004-07-15 05:34:50 94,208 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-21 22:25:24 28,672 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2004-07-15 19:28:48 32,768 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-21 22:25:30 12,288 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2004-07-15 06:49:16 258,048 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_aspnet_isapi.dll
+ 2004-07-15 05:32:22 81,920 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_CORPerfMonExt.dll
+ 2004-07-15 05:24:30 282,624 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_fusion.dll
+ 2004-07-15 05:25:06 315,392 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_mscorjit.dll
+ 2004-07-15 19:29:02 2,138,112 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_mscorlib.dll
+ 2003-02-21 10:09:18 77,824 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_mscorsn.dll
+ 2004-07-15 05:26:52 2,510,848 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_mscorsvr.dll
+ 2004-07-15 05:28:34 2,502,656 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_mscorwks.dll
+ 2003-02-21 19:42:22 348,160 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_msvcr71.dll
+ 2004-07-15 05:34:50 94,208 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW1564\_PerfCounter.dll
+ 2003-02-21 10:09:34 253,952 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-21 10:09:34 122,880 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2004-07-15 05:35:04 319,488 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-21 22:26:38 77,824 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2004-07-15 19:32:00 1,294,336 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 19:31:14 303,104 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 19:29:02 1,703,936 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 19:28:54 90,112 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2007-04-14 02:35:38 1,232,896 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-21 22:26:48 65,536 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2004-07-15 19:28:58 466,944 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 19:28:56 241,664 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-15 05:35:12 66,560 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2004-07-15 19:31:58 372,736 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 19:31:12 241,664 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 19:28:58 323,584 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2004-07-15 19:31:54 131,072 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2004-07-15 19:28:52 77,824 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2004-07-15 19:28:54 126,976 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2007-04-14 02:35:46 1,265,664 —-a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 19:28:58 819,200 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2004-07-15 19:28:52 57,344 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2004-07-15 19:31:16 573,440 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2004-07-15 19:32:02 2,052,096 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 19:29:00 1,339,392 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-06-22 18:51:38 53,248 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2004-07-15 16:23:20 737,280 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2003-03-19 14:43:50 19,968 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjc.exe
+ 2003-03-19 14:43:46 1,613,824 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjsc.dll
+ 2003-03-19 16:52:02 8,704 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjscor.dll
+ 2003-03-19 16:50:02 57,344 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\VJSharpCodeProvider.DLL
+ 2003-03-19 16:52:06 3,739,648 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjslib.dll
+ 2003-03-19 16:52:08 32,768 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjslibcw.dll
+ 2003-03-19 14:30:08 266,240 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjsnativ.dll
+ 2003-03-19 16:52:10 3,399,680 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjswfc.dll
+ 2003-03-19 16:52:12 8,704 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\VJSWfcBrowserStubLib.dll
+ 2003-03-19 16:52:14 189,952 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjswfccw.dll
+ 2003-03-19 16:50:14 1,105,920 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vjswfchtml.dll
+ 2004-07-15 13:15:14 1,032,192 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-15 07:11:56 31,744 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2003-03-19 14:43:52 69,632 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\VJSharp\VJSharpSxS10.dll
+ 2003-03-19 14:38:44 110,592 -c–a-w C:\WINDOWS\Microsoft.NET\Framework\VJSharp\VJSWfcHost.dll
+ 2004-08-04 07:56:41 24,064 -c–a-w C:\WINDOWS\msagent\agentanm.dll
+ 2004-08-04 07:56:41 214,016 -c–a-w C:\WINDOWS\msagent\agentctl.dll
+ 2006-10-12 14:02:52 42,496 -c–a-w C:\WINDOWS\msagent\agentdp2.dll
+ 2007-03-09 13:58:57 57,344 -c–a-w C:\WINDOWS\msagent\agentdpv.dll
+ 2004-08-04 07:56:41 49,152 -c–a-w C:\WINDOWS\msagent\agentmpx.dll
+ 2004-08-04 07:56:41 24,064 -c–a-w C:\WINDOWS\msagent\agentpsh.dll
+ 2004-08-04 07:56:41 44,032 -c–a-w C:\WINDOWS\msagent\agentsr.dll
+ 2006-10-12 11:09:53 256,512 -c–a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2004-08-04 07:56:41 24,064 -c–a-w C:\WINDOWS\msagent\agtintl.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0405.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0406.dll
+ 2002-08-29 12:00:00 21,504 -c–a-w C:\WINDOWS\msagent\intl\agt0407.dll
+ 2002-08-29 12:00:00 22,016 -c–a-w C:\WINDOWS\msagent\intl\agt0408.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0409.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt040b.dll
+ 2002-08-29 12:00:00 21,504 -c–a-w C:\WINDOWS\msagent\intl\agt040c.dll
+ 2002-08-29 12:00:00 19,968 -c–a-w C:\WINDOWS\msagent\intl\agt040e.dll
+ 2002-08-29 12:00:00 20,992 -c–a-w C:\WINDOWS\msagent\intl\agt0410.dll
+ 2002-08-29 12:00:00 20,992 -c–a-w C:\WINDOWS\msagent\intl\agt0413.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0414.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0415.dll
+ 2002-08-29 12:00:00 20,480 -c–a-w C:\WINDOWS\msagent\intl\agt0416.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt0419.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt041d.dll
+ 2002-08-29 12:00:00 19,456 -c–a-w C:\WINDOWS\msagent\intl\agt041f.dll
+ 2002-08-29 12:00:00 20,992 -c–a-w C:\WINDOWS\msagent\intl\agt0816.dll
+ 2002-08-29 12:00:00 20,480 -c–a-w C:\WINDOWS\msagent\intl\agt0c0a.dll
+ 2004-08-04 07:56:43 39,936 -c–a-w C:\WINDOWS\msagent\mslwvtts.dll
+ 2003-02-20 08:34:02 131,072 -c–a-w C:\WINDOWS\MSBN\_setup.exe
+ 2002-07-15 13:41:12 51,712 -c–a-w C:\WINDOWS\MSBN\Drivers\MSWUSB51.sys
+ 2003-02-20 08:13:54 178,536 -c–a-w C:\WINDOWS\MSBN\Framd.exe
+ 2003-02-20 08:13:58 65,536 -c–a-w C:\WINDOWS\MSBN\MSBN.Exe
+ 2003-02-06 11:19:32 53,248 -c–a-w C:\WINDOWS\MSBN\MSBN_CoInst_HP.dll
+ 2003-02-20 08:34:02 2,015,232 -c–a-w C:\WINDOWS\MSBN\MSBNRes.dll
+ 2003-02-23 04:12:32 65,536 -c–a-w C:\WINDOWS\MSBN\setup.exe
+ 2006-06-03 11:40:49 33,792 -c—-w C:\WINDOWS\network diagnostic\custsat.dll
+ 2006-10-10 12:44:50 557,568 ——w C:\WINDOWS\network diagnostic\xpnetdiag.exe
+ 2002-08-29 12:00:00 21,504 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\brpinfo.dll
+ 2002-08-29 12:00:00 6,656 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\HCAppRes.dll
+ 2004-08-04 07:56:49 768,512 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe
+ 2002-08-29 12:00:00 99,840 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
+ 2004-08-04 07:56:50 743,936 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpsvc.exe
+ 2004-08-04 07:56:50 18,944 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\hscupd.exe
+ 2004-08-04 07:56:53 158,208 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msconfig.exe
+ 2004-08-04 07:56:43 376,320 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msinfo.dll
+ 2002-08-29 12:00:00 35,328 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\notiflag.exe
+ 2004-08-04 07:56:44 102,400 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchshell.dll
+ 2004-08-04 07:56:44 38,912 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
+ 2005-06-26 17:23:21 9,546 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Config\Cntstore.bin
+ 2005-06-26 17:24:17 80,795 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat
+ 2005-06-26 17:24:17 17,124 —-a-w C:\WINDOWS\PCHealth\HelpCtr\PackageStore\SkuStore.bin
+ 2004-01-21 04:03:01 139,264 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\ContentUpdater.exe
+ 2004-01-21 04:03:01 77,824 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\FDIWrapper.dll
+ 2004-01-21 04:03:00 344,064 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\api.dll
+ 2004-01-21 04:02:57 114,688 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\asst_ui.dll
+ 2004-01-21 04:03:26 356,352 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\client_motkt.dll
+ 2004-01-21 04:03:28 282,624 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\clientutil52.dll
+ 2004-01-21 04:03:50 36,864 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\gnu.dll
+ 2004-01-21 04:03:02 5,632 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\GUI.dll
+ 2004-01-21 04:03:18 49,152 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\hwinv.dll
+ 2004-01-21 04:03:05 26,572 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\INV16.dll
+ 2004-01-21 04:03:12 212,992 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\jsharpinterp.dll
+ 2004-01-21 04:03:21 434,176 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\motivede.dll
+ 2004-01-21 04:02:59 69,632 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\msxmlwrapper.dll
+ 2004-01-21 04:03:20 24,576 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\pcdapi.dll
+ 2004-01-21 04:03:48 32,768 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\pchapi.dll
+ 2004-01-21 04:03:49 3,072 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\pchealthde.exe
+ 2004-01-21 04:02:59 315,392 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\pchmsxml.dll
+ 2004-01-21 04:03:49 45,056 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\util.dll
+ 2004-01-21 04:03:42 114,688 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\jsharpde\ZipLib.dll
+ 2004-01-21 04:03:03 69,632 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\msxmlwrapper.dll
+ 2004-01-21 04:02:58 159,744 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\PCHButton.exe
+ 2004-01-21 04:03:08 307,200 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\pchealthplugin.dll
+ 2004-01-21 04:03:21 49,152 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\PCHI18N.dll
+ 2004-01-21 04:03:01 315,392 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\pchmsxml.dll
+ 2004-01-21 04:02:59 307,200 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\pchnotify.exe
+ 2004-01-21 04:03:46 98,304 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\PluginCtrl.dll
+ 2004-01-21 04:03:07 122,880 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\SearchCtrl.dll
+ 2004-01-21 04:03:33 77,824 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\WinVerifyTrust.dll
+ 2004-01-21 04:03:24 4,096 -c–a-w C:\WINDOWS\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Pavilion\XPHNABP4EN\plugin\bin\winverifytrustwrapper.dll
+ 2004-08-04 07:56:57 150,528 -c–a-w C:\WINDOWS\PCHealth\UploadLB\Binaries\uploadm.exe
+ 2004-08-04 07:56:45 151,552 -c—-w C:\WINDOWS\peernet\sqldb20.dll
+ 2004-08-04 07:56:45 462,848 -c—-w C:\WINDOWS\peernet\sqlqp20.dll
+ 2004-08-04 07:56:45 110,592 -c—-w C:\WINDOWS\peernet\sqlse20.dll
+ 2004-08-04 07:56:41 159,232 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\cewmdm.dll
+ 2004-08-04 07:56:43 52,224 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
+ 2004-08-04 07:56:43 201,728 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSP.dll
+ 2004-08-04 07:57:01 356,352 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSSCP.dll
+ 2004-08-04 07:56:44 245,760 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MSWMDM.dll
+ 2004-08-04 07:56:46 27,136 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMLOG.dll
+ 2004-08-04 07:56:46 23,552 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\WMDMPS.dll
+ 2005-01-28 18:44:28 164,864 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\cewmdm.dll
+ 2005-01-28 18:44:28 25,088 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
+ 2005-01-28 18:44:28 173,568 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSP.dll
+ 2005-01-28 18:44:28 364,784 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSSCP.dll
+ 2005-01-28 18:44:28 315,904 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MSWMDM.dll
+ 2005-01-28 18:44:28 28,160 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMLOG.dll
+ 2005-01-28 18:44:28 33,792 -c–a-w C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDMPS.dll
+ 2002-12-12 15:14:32 64,512 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\amstream.dll
+ 2002-12-12 15:14:32 1,177,600 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8.dll
+ 2002-12-12 15:14:32 8,192 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3d8thk.dll
+ 2003-05-31 00:00:02 797,184 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\d3dim700.dll
+ 2002-12-12 15:14:32 284,160 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
+ 2002-12-12 15:14:32 24,064 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddrawex.dll
+ 2003-05-31 00:00:02 132,608 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\devenum.dll
+ 2002-12-12 15:14:32 27,136 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmband.dll
+ 2002-12-12 15:14:32 58,368 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmcompos.dll
+ 2002-12-12 15:14:32 171,520 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmime.dll
+ 2002-12-12 15:14:32 33,280 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmloader.dll
+ 2002-12-12 15:14:32 76,800 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmscript.dll
+ 2002-12-12 15:14:32 98,816 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmstyle.dll
+ 2002-12-12 15:14:32 100,864 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmsynth.dll
+ 2002-12-12 15:14:32 116,736 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dmusic.dll
+ 2002-12-12 15:14:32 28,160 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplaysvr.exe
+ 2002-12-12 15:14:32 217,600 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dplayx.dll
+ 2002-12-12 15:14:32 77,824 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpmodemx.dll
+ 2002-12-12 15:14:32 3,072 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnaddr.dll
+ 2002-12-12 15:14:32 723,968 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnet.dll
+ 2003-03-25 00:00:02 32,768 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhpast.dll
+ 2003-03-25 00:00:02 68,096 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnhupnp.dll
+ 2002-12-12 15:14:32 3,072 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnlobby.dll
+ 2002-12-12 15:14:32 16,896 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpnsvr.exe
+ 2002-12-12 15:14:32 19,968 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvacm.dll
+ 2002-12-12 15:14:32 381,952 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvoice.dll
+ 2002-12-12 15:14:32 80,896 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvsetup.exe
+ 2002-12-12 15:14:32 112,128 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpvvox.dll
+ 2002-12-12 15:14:32 76,800 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dpwsockx.dll
+ 2002-12-12 15:14:32 186,880 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmo.dll
+ 2002-12-12 15:14:32 491,520 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsdmoprp.dll
+ 2002-12-12 15:14:32 355,328 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
+ 2002-12-12 15:14:32 1,294,336 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound3d.dll
+ 2002-12-12 15:14:32 18,432 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dswave.dll
+ 2002-12-12 15:14:32 602,624 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx7vb.dll
+ 2003-05-31 00:00:02 1,189,888 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dx8vb.dll
+ 2003-05-31 00:00:02 937,984 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdiag.exe
+ 2002-12-12 15:14:32 44,544 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dxdllreg.exe
+ 2002-12-12 15:14:32 18,944 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\encapi.dll
+ 2002-12-12 15:14:32 130,304 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ks.sys
+ 2002-12-12 15:14:32 4,096 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ksuser.dll
+ 2002-12-12 15:14:32 34,304 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mciqtz32.dll
+ 2002-12-12 15:14:32 13,312 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\msdmo.dll
+ 2002-12-12 15:14:32 7,424 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mskssrv.sys
+ 2002-12-12 15:14:32 5,248 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspclock.sys
+ 2001-08-23 20:00:00 4,608 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mspqm.sys
+ 2002-12-12 15:14:32 5,504 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mstee.sys
+ 2002-12-12 15:14:32 324,096 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\mswebdvd.dll
+ 2002-12-12 15:14:32 173,056 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qasf.dll
+ 2002-12-12 15:14:32 257,024 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qcap.dll
+ 2002-12-12 15:14:32 311,808 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdv.dll
+ 2003-05-31 00:00:02 449,024 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qdvd.dll
+ 2002-12-12 15:14:32 1,798,144 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedit.dll
+ 2002-12-12 15:14:32 733,184 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\qedwipes.dll
+ 2003-05-31 00:00:02 1,962,496 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\quartz.dll
+ 2002-12-12 15:14:32 45,696 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\stream.sys
+ 2002-12-12 15:14:32 4,096 -c–a-w C:\WINDOWS\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\swenum.sys
+ 2002-12-21 04:06:00 3,366,912 -c–a-w C:\WINDOWS\RegisteredPackages\{60BFF50D-FB2C-4498-A577-C9548C390BB9}\moviemk.exe
+ 2004-08-11 06:45:04 47,104 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\uwdf.exe
+ 2004-08-11 06:45:04 15,872 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wdfapi.dll
+ 2004-08-11 06:45:04 38,912 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wdfmgr.exe
+ 2004-08-11 06:45:06 38,912 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpd_ci.dll
+ 2004-08-11 06:45:06 61,952 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdconns.dll
+ 2004-08-11 06:45:06 114,176 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdmtp.dll
+ 2004-08-11 06:45:06 331,776 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdmtpdr.dll
+ 2004-08-11 06:45:06 66,560 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdmtpus.dll
+ 2004-08-11 06:45:06 327,680 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdsp.dll
+ 2004-08-11 06:45:06 10,752 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdtrace.dll
+ 2004-08-11 06:45:06 18,944 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}$BACKUP$\System\wpdusb.sys
+ 2005-01-28 18:44:28 47,104 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\uwdf.exe
+ 2005-01-28 18:44:28 15,872 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfapi.dll
+ 2005-01-28 18:44:28 38,912 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wdfmgr.exe
+ 2005-01-28 18:44:28 38,912 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpd_ci.dll
+ 2005-01-28 18:44:28 61,952 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdconns.dll
+ 2005-01-28 18:44:28 114,176 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtp.dll
+ 2005-01-28 18:44:28 331,776 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpdr.dll
+ 2005-01-28 18:44:28 66,560 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdmtpus.dll
+ 2005-01-28 18:44:28 331,264 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdsp.dll
+ 2005-01-28 18:44:28 10,752 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdtrace.dll
+ 2005-01-28 18:44:28 18,944 -c–a-w C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpdusb.sys
+ 2004-08-04 07:56:46 408,064 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmadmod.dll
+ 2004-08-04 07:56:46 759,296 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmsdmod.dll
+ 2004-08-04 07:56:46 484,864 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmspdmod.dll
+ 2004-08-11 06:45:06 1,181,944 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmvadvd.dll
+ 2004-08-04 07:56:46 809,984 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}$BACKUP$\System\wmvdmod.dll
+ 2005-01-28 18:44:28 396,528 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmadmod.dll
+ 2005-01-28 18:44:28 774,904 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmsdmod.dll
+ 2005-01-28 18:44:28 413,944 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmspdmod.dll
+ 2005-01-28 18:44:28 1,218,808 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvadvd.dll
+ 2005-01-28 18:44:28 895,736 -c–a-w C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\wmvdmod.dll
+ 2003-02-18 01:16:26 11,392 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\bdasup.sys
+ 2003-02-18 01:16:26 16,384 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ccdecode.sys
+ 2003-02-18 01:16:26 15,104 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\mpe.sys
+ 2003-02-18 01:16:28 1,230,336 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msvidctl.dll
+ 2003-02-18 01:16:28 16,896 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\msyuv.dll
+ 2003-02-18 01:16:28 83,968 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\nabtsfec.sys
+ 2003-02-18 01:16:28 10,112 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\ndisip.sys
+ 2003-02-18 01:16:28 354,816 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\psisdecd.dll
+ 2003-02-18 01:16:28 10,880 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\slip.sys
+ 2003-02-18 01:16:28 14,976 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\streamip.sys
+ 2003-02-18 01:16:32 18,688 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstcodec.sys
+ 2003-02-18 01:16:32 47,104 -c–a-w C:\WINDOWS\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704}\wstdecod.dll
+ 2004-08-04 07:56:42 6,656 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\laprxy.dll
+ 2004-08-04 07:56:50 103,936 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\logagent.exe
+ 2004-08-04 07:56:44 237,568 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\qasf.dll
+ 2004-08-04 07:56:46 670,720 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmadmoe.dll
+ 2004-08-04 07:56:46 230,400 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmasf.dll
+ 2004-08-11 06:45:04 344,064 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\WMDRMdev.dll
+ 2004-08-11 06:45:04 290,816 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\WMDRMNet.dll
+ 2004-08-04 07:56:46 151,552 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmidx.dll
+ 2004-08-04 07:56:46 1,050,624 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmnetmgr.dll
+ 2004-08-04 07:56:46 1,119,744 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmsdmoe2.dll
+ 2004-08-04 07:56:46 896,512 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmspdmoe.dll
+ 2004-08-11 06:45:06 1,509,376 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\WMVADVE.DLL
+ 2004-08-04 07:57:02 2,105,344 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvcore.dll
+ 2004-08-04 07:56:46 1,001,472 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}$BACKUP$\System\wmvdmoe2.dll
+ 2005-01-28 18:44:28 6,656 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\laprxy.dll
+ 2005-01-28 18:44:28 96,768 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\logagent.exe
+ 2005-01-28 18:44:28 221,184 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\qasf.dll
+ 2005-01-28 18:44:28 716,288 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmadmoe.dll
+ 2005-01-28 18:44:28 224,768 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmasf.dll
+ 2005-01-28 18:44:28 335,872 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMdev.dll
+ 2005-01-28 18:44:28 290,816 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMDRMNet.dll
+ 2005-01-28 18:44:28 150,016 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmidx.dll
+ 2005-01-28 18:44:28 1,027,072 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmnetmgr.dll
+ 2005-01-28 18:44:28 1,119,744 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmsdmoe2.dll
+ 2005-01-28 18:44:28 940,544 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmspdmoe.dll
+ 2005-01-28 18:44:28 1,512,448 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMVADVE.DLL
+ 2005-01-28 18:44:28 2,370,296 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvcore.dll
+ 2005-01-28 18:44:28 1,003,008 -c–a-w C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmvdmoe2.dll
+ 2002-12-19 19:06:54 1,129,472 -c–a-w C:\WINDOWS\RegisteredPackages\{C53A407B-397A-4EEC-812F-E951673CDE7F}\$BACKUP$\msxml3.dll
+ 2003-05-21 16:18:26 44,032 -c–a-w C:\WINDOWS\RegisteredPackages\{C53A407B-397A-4EEC-812F-E951673CDE7F}\$BACKUP$\msxml3r.dll
+ 2002-12-19 19:06:54 1,129,472 -c–a-w C:\WINDOWS\RegisteredPackages\{C53A407B-397A-4EEC-812F-E951673CDE7F}\msxml3.dll
+ 2003-05-21 16:18:26 44,032 -c–a-w C:\WINDOWS\RegisteredPackages\{C53A407B-397A-4EEC-812F-E951673CDE7F}\msxml3r.dll
+ 2004-08-04 07:56:41 286,208 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\blackbox.dll
+ 2004-08-04 07:57:04 299,520 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmclien.dll
+ 2004-08-04 07:56:42 87,040 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmstor.dll
+ 2004-08-04 07:57:02 695,296 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\drmv2clt.dll
+ 2004-08-04 07:57:01 259,072 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}$BACKUP$\System\msnetobj.dll
+ 2005-01-28 18:44:28 294,912 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\blackbox.dll
+ 2005-01-28 18:44:28 258,296 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmclien.dll
+ 2005-01-28 18:44:28 96,768 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmstor.dll
+ 2005-01-28 18:44:28 502,272 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drmv2clt.dll
+ 2005-01-28 18:44:28 142,336 -c–a-w C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\msnetobj.dll
+ 2004-01-21 01:16:47 233,472 -c-ha-w C:\WINDOWS\repair\ntuser.dat
+ 2002-08-29 19:00:00 362,496 -c–a-w C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead\shellstyle.dll
+ 2002-08-29 19:00:00 362,496 -c–a-w C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic\shellstyle.dll
+ 2002-08-29 19:00:00 361,472 —-a-w C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor\shellstyle.dll
Sheet three: + 2004-08-04 06:10:06 53,248 -c—-w C:\WINDOWS\ServicePackFiles\i386\1394bus.sys + 2004-08-04 06:00:03 12,288 -c—-w C:\WINDOWS\ServicePackFiles\i386\4mmdat.sys + 2004-08-04 06:10:10 48,128 -c—-w C:\WINDOWS\ServicePackFiles\i386\61883.sys + 2004-08-04 07:56:41 100,352 -c—-w C:\WINDOWS\ServicePackFiles\i386\6to4svc.dll + 2002-08-29 04:00:48 231,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\ac97ali.sys + 2002-08-29 04:00:56 84,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\ac97via.sys + 2004-08-04 07:56:47 183,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\accwiz.exe + 2004-08-04 07:56:41 1,852,416 -c—-w C:\WINDOWS\ServicePackFiles\i386\acgenral.dll + 2004-08-04 07:56:41 450,048 -c—-w C:\WINDOWS\ServicePackFiles\i386\aclayers.dll + 2004-08-04 07:56:41 137,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\aclua.dll + 2004-08-04 07:56:41 114,688 -c—-w C:\WINDOWS\ServicePackFiles\i386\aclui.dll + 2004-08-04 06:07:38 187,776 -c—-w C:\WINDOWS\ServicePackFiles\i386\acpi.sys + 2004-08-04 07:56:41 244,736 -c—-w C:\WINDOWS\ServicePackFiles\i386\acspecfc.dll + 2004-08-04 07:56:41 194,048 -c—-w C:\WINDOWS\ServicePackFiles\i386\activeds.dll + 2004-08-04 07:56:47 4,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\actmovie.exe + 2004-08-04 07:56:41 101,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\actxprxy.dll + 2004-08-04 07:56:41 116,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\acxtrnal.dll + 2004-08-04 07:56:41 20,540 -c—-w C:\WINDOWS\ServicePackFiles\i386\admin.dll + 2004-08-04 07:56:47 16,439 -c—-w C:\WINDOWS\ServicePackFiles\i386\admin.exe + 2002-08-29 04:00:48 10,880 -c—-w C:\WINDOWS\ServicePackFiles\i386\admjoy.sys + 2004-08-04 07:56:41 61,440 -c—-w C:\WINDOWS\ServicePackFiles\i386\admparse.dll + 2004-08-04 07:56:41 175,616 -c—-w C:\WINDOWS\ServicePackFiles\i386\adsldp.dll + 2004-08-04 07:56:41 143,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\adsldpc.dll + 2004-08-04 07:56:41 68,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\adsmsext.dll + 2004-08-04 07:56:41 263,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\adsnt.dll + 2004-08-04 07:56:41 4,255 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv01nt5.dll + 2004-08-04 07:56:41 3,967 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv02nt5.dll + 2004-08-04 07:56:41 3,615 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv05nt5.dll + 2004-08-04 07:56:41 3,647 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv07nt5.dll + 2004-08-04 07:56:41 3,135 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv08nt5.dll + 2004-08-04 07:56:41 3,711 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv09nt5.dll + 2004-08-04 07:56:41 3,775 -c—-w C:\WINDOWS\ServicePackFiles\i386\adv11nt5.dll + 2004-08-04 07:56:41 616,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\advapi32.dll + 2004-08-04 07:56:41 99,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\advpack.dll + 2004-08-04 05:39:36 142,464 -c—-w C:\WINDOWS\ServicePackFiles\i386\aec.sys + 2004-08-04 06:14:14 138,496 -c—-w C:\WINDOWS\ServicePackFiles\i386\afd.sys + 2004-08-04 07:56:41 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentanm.dll + 2004-08-04 07:56:41 214,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentctl.dll + 2004-08-04 07:56:41 41,984 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentdp2.dll + 2004-08-04 07:56:41 58,880 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentdpv.dll + 2004-08-04 07:56:41 49,152 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentmpx.dll + 2004-08-04 07:56:41 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentpsh.dll + 2004-08-04 07:56:41 44,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentsr.dll + 2004-08-04 07:56:47 256,512 -c—-w C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe + 2004-08-04 06:07:41 42,368 -c—-w C:\WINDOWS\ServicePackFiles\i386\agp440.sys + 2004-08-04 06:07:42 44,928 -c—-w C:\WINDOWS\ServicePackFiles\i386\agpcpq.sys + 2004-08-04 07:56:41 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\agtintl.dll + 2004-08-04 07:56:47 98,304 -c—-w C:\WINDOWS\ServicePackFiles\i386\ahui.exe + 2004-08-04 07:56:47 44,544 -c—-w C:\WINDOWS\ServicePackFiles\i386\alg.exe + 2004-08-04 06:07:41 42,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\alim1541.sys + 2004-08-04 07:56:41 17,408 -c—-w C:\WINDOWS\ServicePackFiles\i386\alrsvc.dll + 2004-08-04 06:07:42 43,008 -c—-w C:\WINDOWS\ServicePackFiles\i386\amdagp.sys + 2004-08-04 05:59:19 36,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\amdk6.sys + 2004-08-04 05:59:20 37,376 -c—-w C:\WINDOWS\ServicePackFiles\i386\amdk7.sys + 2004-08-04 07:56:41 70,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\amstream.dll + 2002-08-29 03:59:12 36,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\an983.sys + 2004-08-04 07:56:41 126,976 -c—-w C:\WINDOWS\ServicePackFiles\i386\apphelp.dll + 2004-08-04 07:56:41 331,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\aqueue.dll + 2004-08-04 05:58:29 60,800 -c—-w C:\WINDOWS\ServicePackFiles\i386\arp1394.sys + 2004-08-04 07:55:59 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\asferror.dll + 2004-08-04 07:56:41 65,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\asycfilt.dll + 2004-08-04 06:05:03 14,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\asyncmac.sys + 2004-08-04 07:56:47 25,088 -c—-w C:\WINDOWS\ServicePackFiles\i386\at.exe + 2004-08-04 05:59:42 95,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\atapi.sys + 2004-08-04 05:29:29 56,623 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1btxx.sys + 2004-08-04 05:29:29 11,615 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1mdxx.sys + 2004-08-04 05:29:29 12,047 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1pdxx.sys + 2004-08-04 05:29:30 30,671 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1raxx.sys + 2004-08-04 05:29:30 63,663 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1rvxx.sys + 2004-08-04 05:29:31 26,367 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1snxx.sys + 2004-08-04 05:29:31 21,343 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1ttxx.sys + 2004-08-04 05:29:31 36,463 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1tuxx.sys + 2004-08-04 05:29:31 29,455 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1xbxx.sys + 2004-08-04 05:29:31 34,735 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati1xsxx.sys + 2004-08-04 07:56:41 229,376 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati2cqag.dll + 2004-08-04 07:56:41 377,984 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati2dvaa.dll + 2004-08-04 07:56:41 201,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati2dvag.dll + 2004-08-04 05:29:26 327,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati2mtaa.sys + 2004-08-04 05:29:26 701,440 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati2mtag.sys + 2004-08-04 07:56:41 870,784 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati3d1ag.dll + 2004-08-04 07:56:41 1,057,760 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati3d2ag.dll + 2004-08-04 07:56:41 1,888,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\ati3duag.dll + 2004-08-04 05:29:27 57,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinbtxx.sys + 2004-08-04 05:29:28 13,824 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinmdxx.sys + 2004-08-04 05:29:29 14,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinpdxx.sys + 2004-08-04 05:29:29 52,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinraxx.sys + 2004-08-04 05:29:30 104,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinrvxx.sys + 2004-08-04 05:29:30 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinsnxx.sys + 2004-08-04 05:29:30 13,824 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinttxx.sys + 2004-08-04 05:29:31 73,216 -c—-w C:\WINDOWS\ServicePackFiles\i386\atintuxx.sys + 2004-08-04 05:29:31 31,744 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinxbxx.sys + 2004-08-04 05:29:31 63,488 -c—-w C:\WINDOWS\ServicePackFiles\i386\atinxsxx.sys + 2004-08-04 07:56:41 32,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\ativtmxx.dll + 2004-08-04 07:56:41 516,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\ativvaxx.dll + 2004-08-04 07:56:41 58,880 -c—-w C:\WINDOWS\ServicePackFiles\i386\atl.dll + 2004-08-04 07:56:47 11,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\atmadm.exe + 2004-08-04 05:58:30 59,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\atmarpc.sys + 2004-08-04 07:55:59 285,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\atmfd.dll + 2004-08-04 05:58:34 55,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\atmlane.sys + 2004-08-04 07:56:41 30,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\atmlib.dll + 2004-08-04 07:56:41 21,183 -c—-w C:\WINDOWS\ServicePackFiles\i386\atv01nt5.dll + 2004-08-04 07:56:41 11,359 -c—-w C:\WINDOWS\ServicePackFiles\i386\atv02nt5.dll + 2004-08-04 07:56:41 25,471 -c—-w C:\WINDOWS\ServicePackFiles\i386\atv04nt5.dll + 2004-08-04 07:56:41 14,143 -c—-w C:\WINDOWS\ServicePackFiles\i386\atv06nt5.dll + 2004-08-04 07:56:41 17,279 -c—-w C:\WINDOWS\ServicePackFiles\i386\atv10nt5.dll + 2004-08-04 07:56:41 42,496 -c—-w C:\WINDOWS\ServicePackFiles\i386\audiosrv.dll + 2004-08-04 07:56:47 14,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\auditusr.exe + 2004-08-04 07:56:41 20,540 -c—-w C:\WINDOWS\ServicePackFiles\i386\author.dll + 2004-08-04 07:56:47 16,439 -c—-w C:\WINDOWS\ServicePackFiles\i386\author.exe + 2004-08-04 07:56:41 56,832 -c—-w C:\WINDOWS\ServicePackFiles\i386\authz.dll + 2004-08-04 07:56:47 588,800 -c—-w C:\WINDOWS\ServicePackFiles\i386\autochk.exe + 2004-08-04 07:56:47 602,624 -c—-w C:\WINDOWS\ServicePackFiles\i386\autoconv.exe + 2004-08-04 07:56:47 580,608 -c—-w C:\WINDOWS\ServicePackFiles\i386\autofmt.exe + 2004-08-04 07:56:47 11,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\autolfn.exe + 2004-08-04 06:10:10 38,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\avc.sys + 2004-08-04 06:09:58 13,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\avcstrm.sys + 2004-08-04 07:56:41 84,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\avifil32.dll + 2004-08-04 07:56:41 52,736 -c—-w C:\WINDOWS\ServicePackFiles\i386\basesrv.dll + 2004-08-04 07:56:41 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\batmeter.dll + 2004-08-04 07:56:41 8,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\batt.dll + 2004-08-04 06:10:12 11,776 -c—-w C:\WINDOWS\ServicePackFiles\i386\bdasup.sys + 2004-08-04 07:56:41 17,408 -c—-w C:\WINDOWS\ServicePackFiles\i386\bidispl.dll + 2004-08-04 07:56:41 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\bitsprx2.dll + 2004-08-04 07:56:41 7,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\bitsprx3.dll + 2004-08-04 07:56:41 286,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\blackbox.dll + 2004-08-04 07:56:47 71,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\blastcln.exe + 2004-08-04 05:59:57 71,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\bridge.sys + 2004-08-04 07:55:59 63,488 -c—-w C:\WINDOWS\ServicePackFiles\i386\browselc.dll + 2004-08-04 07:56:41 77,312 -c—-w C:\WINDOWS\ServicePackFiles\i386\browser.dll + 2004-08-04 07:56:41 1,016,832 -c—-w C:\WINDOWS\ServicePackFiles\i386\browseui.dll + 2004-08-04 07:56:41 78,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\browsewm.dll + 2004-08-04 07:56:41 20,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthci.dll + 2004-08-04 06:10:38 17,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthenum.sys + 2004-08-04 06:10:38 38,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthmodem.sys + 2004-08-04 05:58:38 100,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthpan.sys + 2004-08-04 06:10:37 274,304 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthport.sys + 2004-08-04 06:10:37 35,456 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthprint.sys + 2004-08-04 07:56:41 30,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthserv.dll + 2004-08-04 06:10:34 18,944 -c—-w C:\WINDOWS\ServicePackFiles\i386\bthusb.sys + 2004-08-04 07:56:41 50,688 -c—-w C:\WINDOWS\ServicePackFiles\i386\btpanui.dll + 2004-08-04 07:56:41 59,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\cabinet.dll + 2004-08-04 07:56:41 84,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\cabview.dll + 2004-08-04 07:56:41 385,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\callcont.dll + 2004-08-04 07:56:41 50,688 -c—-w C:\WINDOWS\ServicePackFiles\i386\camocx.dll + 2004-08-04 07:56:41 229,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\catsrv.dll + 2004-08-04 07:56:41 85,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\catsrvps.dll + 2004-08-04 07:56:41 628,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\catsrvut.dll + 2004-08-04 06:10:16 17,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\ccdecode.sys + 2004-08-04 06:14:10 63,744 -c—-w C:\WINDOWS\ServicePackFiles\i386\cdfs.sys + 2004-08-04 07:56:41 150,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\cdfview.dll + 2004-08-04 07:56:41 66,560 -c—-w C:\WINDOWS\ServicePackFiles\i386\cdm.dll + 2004-08-04 07:56:41 2,067,968 -c—-w C:\WINDOWS\ServicePackFiles\i386\cdosys.dll + 2004-08-04 05:59:52 49,536 -c—-w C:\WINDOWS\ServicePackFiles\i386\cdrom.sys + 2004-08-04 07:56:41 194,560 -c—-w C:\WINDOWS\ServicePackFiles\i386\certcli.dll + 2004-08-04 07:56:41 457,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\certmgr.dll + 2004-08-04 07:56:41 159,232 -c—-w C:\WINDOWS\ServicePackFiles\i386\cewmdm.dll + 2004-08-04 07:56:41 38,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\cfgbkend.dll + 2004-08-04 07:56:00 16,896 -c—-w C:\WINDOWS\ServicePackFiles\i386\cfgmgr32.dll + 2004-08-04 07:56:47 188,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe + 2004-08-04 07:56:41 15,423 -c—-w C:\WINDOWS\ServicePackFiles\i386\ch7xxnt5.dll + 2004-08-04 06:00:12 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\changer.sys + 2004-08-04 07:56:41 1,352,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\cimwin32.dll + 2004-08-04 07:56:41 69,120 -c—-w C:\WINDOWS\ServicePackFiles\i386\ciodm.dll + 2004-08-04 07:56:47 5,632 -c—-w C:\WINDOWS\ServicePackFiles\i386\cisvc.exe + 2004-08-04 06:14:26 49,664 -c—-w C:\WINDOWS\ServicePackFiles\i386\classpnp.sys + 2004-08-04 07:56:41 110,080 -c—-w C:\WINDOWS\ServicePackFiles\i386\clbcatex.dll + 2004-08-04 07:56:41 501,248 -c—-w C:\WINDOWS\ServicePackFiles\i386\clbcatq.dll + 2004-08-04 07:56:47 64,000 -c—-w C:\WINDOWS\ServicePackFiles\i386\cleanmgr.exe + 2004-08-04 07:56:41 77,824 -c—-w C:\WINDOWS\ServicePackFiles\i386\cliconfg.dll + 2004-08-04 07:56:47 20,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\cliconfg.exe + 2004-08-04 07:56:47 102,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\clipbrd.exe + 2004-08-04 07:56:47 33,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\clipsrv.exe + 2004-08-04 07:56:41 57,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\clusapi.dll + 2004-08-04 06:07:39 14,080 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmbatt.sys + 2004-08-04 07:56:41 15,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmcfg32.dll + 2004-08-04 07:56:48 388,608 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmd.exe + 2004-08-04 07:56:41 343,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmdial32.dll + 2004-08-04 07:56:48 47,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmdl32.exe + 2004-08-04 07:56:48 39,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmmon32.exe + 2004-08-04 07:56:41 185,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmprops.dll + 2004-08-04 07:56:41 13,824 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmsetacl.dll + 2004-08-04 07:56:48 63,488 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmstp.exe + 2004-08-04 07:56:41 39,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\cmutil.dll + 2004-08-04 07:56:41 47,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\cnbjmon.dll + 2004-08-04 07:56:41 79,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\cnbjmon2.dll + 2004-08-04 07:56:41 62,464 -c—-w C:\WINDOWS\ServicePackFiles\i386\colbact.dll + 2004-08-04 07:56:41 195,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\comadmin.dll + 2004-08-04 07:56:41 611,328 -c—-w C:\WINDOWS\ServicePackFiles\i386\comctl32.dll + 2004-08-04 07:56:41 276,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\comdlg32.dll + 2004-08-04 07:56:41 252,928 -c—-w C:\WINDOWS\ServicePackFiles\i386\compatui.dll + 2004-08-04 07:56:41 229,376 -c—-w C:\WINDOWS\ServicePackFiles\i386\compstui.dll + 2004-08-04 07:56:48 9,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\comrepl.exe + 2004-08-04 07:56:41 792,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\comres.dll + 2004-08-04 07:56:41 1,251,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\comsvcs.dll + 2004-08-04 07:56:41 540,160 -c—-w C:\WINDOWS\ServicePackFiles\i386\comuid.dll + 2004-08-04 07:56:48 1,032,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\conf.exe + 2004-08-04 07:56:41 45,056 -c—-w C:\WINDOWS\ServicePackFiles\i386\confmrsl.dll + 2004-08-04 07:56:48 27,648 -c—-w C:\WINDOWS\ServicePackFiles\i386\conime.exe + 2004-08-04 07:56:41 35,328 -c—-w C:\WINDOWS\ServicePackFiles\i386\corpol.dll + 2004-08-04 07:56:41 163,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\credui.dll + 2004-08-04 05:59:20 36,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\crusoe.sys + 2004-08-04 07:56:41 597,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\crypt32.dll + 2004-08-04 07:56:41 74,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptdlg.dll + 2004-08-04 07:56:41 33,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptdll.dll + 2004-08-04 07:56:41 53,760 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptext.dll + 2004-08-04 07:56:41 63,488 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptnet.dll + 2004-08-04 07:56:41 60,416 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll + 2004-08-04 07:56:41 512,512 -c—-w C:\WINDOWS\ServicePackFiles\i386\cryptui.dll + 2004-08-04 07:56:41 101,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\cscdll.dll + 2004-08-04 07:56:48 98,304 -c—-w C:\WINDOWS\ServicePackFiles\i386\cscript.exe + 2004-08-04 07:56:41 326,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\cscui.dll + 2004-08-04 07:56:41 32,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\csrsrv.dll + 2004-08-04 07:56:48 6,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\csrss.exe + 2004-08-04 07:56:48 15,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe + 2004-08-04 07:56:41 249,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\ctmasetp.dll + 2004-08-04 07:56:41 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\custsat.dll + 2004-08-04 05:32:25 48,640 -c—-w C:\WINDOWS\ServicePackFiles\i386\cwrwdm.sys + 2004-08-04 07:56:41 1,179,648 -c—-w C:\WINDOWS\ServicePackFiles\i386\d3d8.dll + 2004-08-04 07:56:41 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\d3d8thk.dll + 2004-08-04 07:56:41 1,689,088 -c—-w C:\WINDOWS\ServicePackFiles\i386\d3d9.dll + 2004-08-04 07:56:41 825,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\d3dim700.dll + 2004-08-04 07:56:41 1,053,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\danim.dll + 2004-08-04 07:56:42 561,179 -c—-w C:\WINDOWS\ServicePackFiles\i386\dao360.dll + 2004-08-04 07:56:42 54,272 -c—-w C:\WINDOWS\ServicePackFiles\i386\dataclen.dll + 2004-08-04 07:56:42 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\davclnt.dll + 2004-08-04 07:56:42 640,000 -c—-w C:\WINDOWS\ServicePackFiles\i386\dbghelp.dll + 2004-08-04 07:56:42 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\dbmsrpcn.dll + 2004-08-04 07:56:42 110,592 -c—-w C:\WINDOWS\ServicePackFiles\i386\dbnetlib.dll + 2004-08-04 07:56:42 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\dbnmpntw.dll + 2004-08-04 07:56:42 40,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\dcap32.dll + 2004-08-04 07:56:42 8,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\dciman32.dll + 2004-08-04 07:56:48 30,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\ddeshare.exe + 2004-08-04 07:56:42 266,240 -c—-w C:\WINDOWS\ServicePackFiles\i386\ddraw.dll + 2004-08-04 07:56:42 27,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\ddrawex.dll + 2004-08-04 07:56:48 25,088 -c—-w C:\WINDOWS\ServicePackFiles\i386\defrag.exe + 2004-08-04 07:56:42 59,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\devenum.dll + 2004-08-04 07:56:42 282,624 -c—-w C:\WINDOWS\ServicePackFiles\i386\devmgr.dll + 2004-08-04 07:56:48 82,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\dfrgfat.exe + 2004-08-04 07:56:48 104,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\dfrgntfs.exe + 2004-08-04 07:56:42 38,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\dfrgsnap.dll + 2004-08-04 07:56:42 123,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\dfrgui.dll + 2004-08-04 07:56:42 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\dfsshlex.dll + 2004-08-04 07:56:42 111,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\dgnet.dll + 2004-08-04 07:56:42 111,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\dhcpcsvc.dll + 2004-08-04 07:56:48 539,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\dialer.exe + 2004-08-04 07:56:48 85,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\diantz.exe + 2004-08-04 07:56:42 68,608 -c—-w C:\WINDOWS\ServicePackFiles\i386\digest.dll + 2004-08-04 07:56:42 159,232 -c—-w C:\WINDOWS\ServicePackFiles\i386\dinput.dll + 2004-08-04 07:56:42 181,760 -c—-w C:\WINDOWS\ServicePackFiles\i386\dinput8.dll + 2004-08-04 07:56:42 81,408 -c—-w C:\WINDOWS\ServicePackFiles\i386\directdb.dll + 2004-08-04 05:59:54 36,352 -c—-w C:\WINDOWS\ServicePackFiles\i386\disk.sys + 2004-08-04 05:59:52 14,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\diskdump.sys + 2004-08-04 07:56:48 163,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\diskpart.exe + 2004-08-04 07:56:48 294,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\dlimport.exe + 2004-08-04 07:56:48 5,120 -c—-w C:\WINDOWS\ServicePackFiles\i386\dllhost.exe + 2004-08-04 06:00:04 8,320 -c—-w C:\WINDOWS\ServicePackFiles\i386\dlttape.sys + 2004-08-04 07:56:48 224,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe + 2004-08-04 07:56:42 28,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmband.dll + 2004-08-04 06:07:17 799,744 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmboot.sys + 2004-08-04 07:56:42 61,440 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmcompos.dll + 2004-08-04 07:56:42 200,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmdskmgr.dll + 2004-08-04 07:56:42 181,248 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmime.dll + 2004-08-04 06:07:16 153,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmio.sys + 2004-08-04 07:56:42 35,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmloader.dll + 2004-08-04 07:56:48 15,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmremote.exe + 2004-08-04 07:56:42 82,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmscript.dll + 2004-08-04 07:56:42 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmserver.dll + 2004-08-04 07:56:42 105,984 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmstyle.dll + 2004-08-04 07:56:42 103,424 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmsynth.dll + 2004-08-04 07:56:42 104,448 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmusic.dll + 2004-08-04 06:07:38 52,864 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmusic.sys + 2004-08-04 07:56:42 52,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\dmutil.dll + 2004-08-04 07:56:42 148,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\dnsapi.dll + 2004-08-04 07:56:42 45,568 -c—-w C:\WINDOWS\ServicePackFiles\i386\dnsrslvr.dll + 2004-08-04 07:56:42 48,128 -c—-w C:\WINDOWS\ServicePackFiles\i386\docprop2.dll + 2004-08-04 05:51:21 53,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\dosx.exe + 2004-08-04 05:58:29 207,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\dot4.sys + 2004-08-04 06:13:53 97,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpcdll.dll + 2004-08-04 07:56:48 30,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\dplaysvr.exe + 2004-08-04 07:56:42 229,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\dplayx.dll + 2004-08-04 07:56:42 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpmodemx.dll + 2004-08-04 07:56:03 3,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnaddr.dll + 2004-08-04 07:56:42 375,296 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnet.dll + 2004-08-04 07:56:42 35,328 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnhpast.dll + 2004-08-04 07:56:42 60,928 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnhupnp.dll + 2004-08-04 07:56:03 3,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnlobby.dll + 2004-08-04 07:56:48 18,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpnsvr.exe + 2004-08-04 07:56:42 21,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpvacm.dll + 2004-08-04 07:56:42 212,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpvoice.dll + 2004-08-04 07:56:48 83,456 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpvsetup.exe + 2004-08-04 07:56:42 116,736 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpvvox.dll + 2004-08-04 07:56:42 57,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\dpwsockx.dll + 2004-08-04 07:57:04 299,520 -c—-w C:\WINDOWS\ServicePackFiles\i386\drmclien.dll + 2004-08-04 06:07:58 60,288 -c—-w C:\WINDOWS\ServicePackFiles\i386\drmk.sys + 2004-08-04 07:56:42 87,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\drmstor.dll + 2004-08-04 07:57:02 695,296 -c—-w C:\WINDOWS\ServicePackFiles\i386\drmv2clt.dll + 2004-08-04 07:56:42 14,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\drprov.dll + 2002-08-29 12:00:00 4,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\ds16gt.dll + 2004-08-04 07:56:42 16,384 -c—-w C:\WINDOWS\ServicePackFiles\i386\ds32gt.dll + 2004-08-04 07:56:42 181,760 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsdmo.dll + 2004-08-04 07:56:42 71,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsdmoprp.dll + 2004-08-04 07:56:42 92,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\dskquota.dll + 2004-08-04 07:56:42 367,616 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsound.dll + 2004-08-04 07:56:42 1,294,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsound3d.dll + 2004-08-04 07:56:42 142,336 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsprop.dll + 2004-08-04 07:56:04 4,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsprpres.dll + 2004-08-04 07:56:42 239,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsquery.dll + 2004-08-04 07:56:42 51,200 -c—-w C:\WINDOWS\ServicePackFiles\i386\dssec.dll + 2004-08-04 05:31:43 137,216 -c—-w C:\WINDOWS\ServicePackFiles\i386\dssenh.dll + 2004-08-04 07:56:42 113,152 -c—-w C:\WINDOWS\ServicePackFiles\i386\dsuiext.dll + 2004-08-04 07:56:42 19,456 -c—-w C:\WINDOWS\ServicePackFiles\i386\dswave.dll + 2004-08-04 07:56:48 10,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\dumprep.exe + 2004-08-04 07:56:42 304,128 -c—-w C:\WINDOWS\ServicePackFiles\i386\duser.dll + 2004-08-04 07:56:48 17,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\dvdupgrd.exe + 2004-08-04 07:56:48 180,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\dwwin.exe + 2004-08-04 07:56:42 619,008 -c—-w C:\WINDOWS\ServicePackFiles\i386\dx7vb.dll + 2004-08-04 07:56:42 1,227,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\dx8vb.dll + 2004-08-04 07:56:48 1,298,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxdiag.exe + 2004-08-04 07:56:42 2,113,536 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxdiagn.dll + 2004-08-04 06:00:54 71,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxg.sys + 2004-08-04 07:56:42 498,205 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxmasf.dll + 2004-08-04 07:56:42 357,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxtmsft.dll + 2004-08-04 07:56:42 201,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\dxtrans.dll + 2004-08-04 07:56:42 183,296 -c—-w C:\WINDOWS\ServicePackFiles\i386\els.dll + 2004-08-04 07:56:42 20,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\encapi.dll + 2004-08-04 07:56:42 186,368 -c—-w C:\WINDOWS\ServicePackFiles\i386\encdec.dll + 2004-08-04 07:56:05 40,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\ep9res.dll + 2004-07-17 18:39:35 120,320 -c—-w C:\WINDOWS\ServicePackFiles\i386\epcl5res.dll + 2004-08-04 07:56:42 23,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\ersvc.dll + 2004-08-04 07:56:42 243,200 -c—-w C:\WINDOWS\ServicePackFiles\i386\es.dll + 2004-08-04 07:56:42 1,082,368 -c—-w C:\WINDOWS\ServicePackFiles\i386\esent.dll + 2004-08-04 07:56:42 247,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\esscli.dll + 2002-08-29 04:00:54 137,088 -c—-w C:\WINDOWS\ServicePackFiles\i386\essm2e.sys + 2004-08-04 07:56:49 193,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\eudcedit.exe + 2004-08-04 07:56:42 55,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\eventlog.dll + 2004-08-04 07:56:42 101,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\evntagnt.dll + 2004-08-04 07:56:49 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\evntcmd.exe + 2004-08-04 07:56:42 22,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\evntrprv.dll + 2004-08-04 07:56:49 92,160 -c—-w C:\WINDOWS\ServicePackFiles\i386\evntwin.exe + 2004-08-04 07:56:49 1,032,192 ——w C:\WINDOWS\ServicePackFiles\i386\explorer.exe + 2004-08-04 07:56:42 380,957 -c—-w C:\WINDOWS\ServicePackFiles\i386\expsrv.dll + 2004-08-04 07:56:42 55,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\extmgr.dll + 2004-08-04 07:56:49 45,568 -c—-w C:\WINDOWS\ServicePackFiles\i386\extrac32.exe + 2004-08-04 06:14:16 143,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\fastfat.sys + 2004-08-04 07:56:42 472,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\fastprox.dll + 2004-08-04 07:56:42 80,384 -c—-w C:\WINDOWS\ServicePackFiles\i386\faultrep.dll + 2004-08-04 07:56:49 20,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\faxpatch.exe + 2004-08-04 05:59:27 27,392 -c—-w C:\WINDOWS\ServicePackFiles\i386\fdc.sys + 2004-08-04 07:56:42 21,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\feclient.dll + 2004-08-04 07:56:42 337,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\filemgmt.dll + 2004-08-04 07:56:49 27,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\findstr.exe + 2004-08-04 07:56:42 87,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\fldrclnr.dll + 2004-08-04 05:59:27 20,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\flpydisk.sys + 2004-08-04 07:56:42 16,896 -c—-w C:\WINDOWS\ServicePackFiles\i386\fltlib.dll + 2004-08-04 07:56:49 22,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\fltmc.exe + 2004-08-04 06:01:19 124,800 -c—-w C:\WINDOWS\ServicePackFiles\i386\fltmgr.sys + 2004-08-04 07:56:42 382,976 -c—-w C:\WINDOWS\ServicePackFiles\i386\fontext.dll + 2004-08-04 07:56:49 20,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\fontview.exe + 2004-08-04 05:31:22 34,173 -c—-w C:\WINDOWS\ServicePackFiles\i386\forehe.sys + 2004-08-04 07:56:42 32,828 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp40ext.dll + 2004-08-04 07:56:42 184,435 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4amsft.dll + 2004-08-04 07:56:42 82,035 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4anscp.dll + 2004-08-04 07:56:42 147,513 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4apws.dll + 2004-08-04 07:56:42 49,210 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4areg.dll + 2004-08-04 07:56:42 102,509 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4atxt.dll + 2004-08-04 07:56:42 618,605 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4autl.dll + 2004-08-04 07:56:42 41,020 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4avnb.dll + 2004-08-04 07:56:42 32,826 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4avss.dll + 2004-08-04 07:56:42 49,212 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4awebs.dll + 2004-08-04 07:56:42 876,653 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp4awel.dll + 2004-08-04 07:56:49 15,120 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp98sadm.exe + 2004-08-04 07:56:49 109,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe + 2004-08-04 07:56:49 24,632 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpadmcgi.exe + 2004-08-04 07:56:42 20,541 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpadmdll.dll + 2004-08-04 07:56:49 188,494 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpcount.exe + 2004-08-04 07:56:42 94,208 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpencode.dll + 2004-08-04 07:56:42 20,541 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpexedll.dll + 2004-08-04 07:56:42 598,071 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpmmc.dll + 2004-08-04 07:56:06 208,896 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpmmcsat.dll + 2004-08-04 07:56:49 20,538 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpremadm.exe + 2004-08-04 07:56:49 28,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe + 2004-08-04 07:56:06 9,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\framebuf.dll + 2004-08-04 07:56:42 185,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\framedyn.dll + 2004-08-04 07:56:49 193,024 -c—-w C:\WINDOWS\ServicePackFiles\i386\fsquirt.exe + 2004-08-04 07:56:49 42,496 -c—-w C:\WINDOWS\ServicePackFiles\i386\ftp.exe + 2004-08-04 07:56:42 60,416 -c—-w C:\WINDOWS\ServicePackFiles\i386\fwcfg.dll + 2004-08-04 07:56:42 452,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsapi.dll + 2004-08-04 07:56:49 143,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsclnt.exe + 2004-08-04 07:56:42 72,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxscom.dll + 2004-08-04 07:56:42 285,184 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxscomex.dll + 2004-08-04 07:56:49 229,376 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxscover.exe + 2004-08-04 07:56:42 27,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsdrv.dll + 2004-08-04 07:56:42 55,296 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsevent.dll + 2004-08-04 07:56:42 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsext32.dll + 2004-08-04 07:56:42 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsmon.dll + 2004-08-04 07:56:42 132,608 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsocm.dll + 2004-08-04 07:56:42 8,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsperf.dll + 2004-08-04 07:56:06 6,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsres.dll + 2004-08-04 07:56:42 562,176 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsst.dll + 2004-08-04 07:56:49 267,776 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxssvc.exe + 2004-08-04 07:56:42 246,272 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxst30.dll + 2004-08-04 07:56:42 397,312 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxstiff.dll + 2004-08-04 07:56:42 154,112 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsui.dll + 2004-08-04 07:56:42 192,512 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxswzrd.dll + 2004-08-04 07:56:42 400,384 -c—-w C:\WINDOWS\ServicePackFiles\i386\fxsxp32.dll + 2004-08-04 06:07:43 46,464 -c—-w C:\WINDOWS\ServicePackFiles\i386\gagp30kx.sys + 2004-08-04 06:08:21 10,624 -c—-w C:\WINDOWS\ServicePackFiles\i386\gameenum.sys + 2004-08-04 06:08:29 59,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\gckernel.sys + 2004-08-04 07:56:42 278,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\gdi32.dll + 2004-08-04 07:56:42 122,880 -c—-w C:\WINDOWS\ServicePackFiles\i386\glu32.dll + 2002-08-29 12:00:00 101,888 -c—-w C:\WINDOWS\ServicePackFiles\i386\gpkcsp.dll + 2004-08-04 07:56:07 9,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\gpkrsrc.dll + 2004-08-04 07:56:49 39,424 -c—-w C:\WINDOWS\ServicePackFiles\i386\grpconv.exe + 2004-08-04 05:59:19 28,288 -c—-w C:\WINDOWS\ServicePackFiles\i386\grserial.sys + 2004-08-04 07:56:42 123,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\guitrn.dll + 2004-08-04 07:56:42 108,544 -c—-w C:\WINDOWS\ServicePackFiles\i386\guitrn_a.dll + 2004-08-04 07:56:42 57,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\h323cc.dll + 2004-08-04 07:56:42 614,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\h323msp.dll + 2004-08-04 05:59:19 105,472 -c—-w C:\WINDOWS\ServicePackFiles\i386\hal.dll + 2004-08-04 05:59:09 131,968 -c—-w C:\WINDOWS\ServicePackFiles\i386\halaacpi.dll + 2004-08-04 05:59:06 81,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\halacpi.dll + 2004-08-04 05:59:13 150,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\halapic.dll + 2004-08-04 05:59:12 134,400 -c—-w C:\WINDOWS\ServicePackFiles\i386\halmacpi.dll + 2004-08-04 05:59:18 152,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\halmps.dll + 2004-08-04 05:59:19 77,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\halsp.dll + 2004-08-04 07:56:42 7,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\hccoin.dll + 2004-08-04 07:56:49 768,512 -c—-w C:\WINDOWS\ServicePackFiles\i386\helpctr.exe + 2004-08-04 07:56:50 743,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe + 2004-08-04 07:56:50 10,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\hh.exe + 2004-08-04 07:56:42 38,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\hhsetup.dll + 2004-08-04 07:56:42 20,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\hid.dll + 2004-08-04 06:10:36 25,600 -c—-w C:\WINDOWS\ServicePackFiles\i386\hidbth.sys + 2004-08-04 06:08:19 36,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\hidclass.sys + 2004-08-04 06:08:18 15,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\hidir.sys + 2004-08-04 06:08:16 24,960 -c—-w C:\WINDOWS\ServicePackFiles\i386\hidparse.sys + 2004-08-04 07:56:42 21,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\hidserv.dll + 2004-08-04 07:56:42 38,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\hmmapi.dll + 2004-08-04 07:56:42 344,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\hnetcfg.dll + 2004-08-04 07:56:42 330,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\hnetwiz.dll + 2004-08-04 07:56:42 39,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\hostmib.dll + 2004-08-04 07:56:42 144,896 -c—-w C:\WINDOWS\ServicePackFiles\i386\hotplug.dll + 2004-08-04 07:56:42 10,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\hpcjrr.dll + 2004-08-04 07:56:42 10,240 -c—-w C:\WINDOWS\ServicePackFiles\i386\hpcjrrps.dll + 2004-08-04 07:56:42 87,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\hpfud50.dll + 2004-08-04 07:56:50 18,944 -c—-w C:\WINDOWS\ServicePackFiles\i386\hscupd.exe + 2004-08-04 05:41:46 220,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\hsfbs2s2.sys + 2004-08-04 07:56:42 32,285 -c—-w C:\WINDOWS\ServicePackFiles\i386\hsfcisp2.dll + 2004-08-04 05:41:48 685,056 -c—-w C:\WINDOWS\ServicePackFiles\i386\hsfcxts2.sys + 2004-08-04 05:41:54 1,041,536 -c—-w C:\WINDOWS\ServicePackFiles\i386\hsfdpsp2.sys + 2004-08-04 06:00:13 263,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\http.sys + 2004-08-04 07:56:42 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\httpapi.dll + 2004-08-04 07:56:42 41,984 -c—-w C:\WINDOWS\ServicePackFiles\i386\htui.dll + 2004-08-04 07:56:42 345,088 -c—-w C:\WINDOWS\ServicePackFiles\i386\hypertrm.dll + 2004-08-04 06:00:50 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\i2omgmt.sys + 2004-08-04 06:00:50 18,560 -c—-w C:\WINDOWS\ServicePackFiles\i386\i2omp.sys + 2004-08-04 06:14:36 52,736 -c—-w C:\WINDOWS\ServicePackFiles\i386\i8042prt.sys + 2004-08-04 07:56:42 702,845 -c—-w C:\WINDOWS\ServicePackFiles\i386\i81xdnt5.dll + 2004-08-04 05:29:36 161,020 -c—-w C:\WINDOWS\ServicePackFiles\i386\i81xnt5.sys + 2004-08-04 07:56:42 119,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\iasrad.dll + 2004-08-04 07:56:42 11,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\icaapi.dll + 2004-08-04 07:56:42 80,384 -c—-w C:\WINDOWS\ServicePackFiles\i386\iccvid.dll + 2004-08-04 07:56:42 253,952 -c—-w C:\WINDOWS\ServicePackFiles\i386\icm32.dll + 2004-08-04 07:56:07 3,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\icmp.dll + 2004-08-04 07:56:42 4,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\iconlib.dll + 2004-08-04 07:56:42 61,440 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwconn.dll + 2004-08-04 07:56:50 214,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwconn1.exe + 2004-08-04 07:56:50 86,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwconn2.exe + 2004-08-04 07:56:42 73,728 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwdial.dll + 2004-08-04 07:56:42 32,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwdl.dll + 2004-08-04 07:56:42 172,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwhelp.dll + 2004-08-04 07:56:42 65,536 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwphbk.dll + 2004-08-04 07:56:50 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwrmind.exe + 2004-08-04 07:56:42 49,152 -c—-w C:\WINDOWS\ServicePackFiles\i386\icwutil.dll + 2004-08-04 07:56:42 120,832 -c—-w C:\WINDOWS\ServicePackFiles\i386\idq.dll + 2004-08-04 07:56:50 34,304 -c—-w C:\WINDOWS\ServicePackFiles\i386\ie4uinit.exe + 2004-08-04 07:56:42 139,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\ieakeng.dll + 2004-08-04 07:56:42 216,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\ieaksie.dll + 2004-08-04 07:56:42 323,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\iedkcs32.dll + 2004-08-04 07:56:50 18,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\iedw.exe + 2004-08-04 07:56:42 81,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\ieencode.dll + 2004-08-04 07:56:42 249,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\iepeers.dll + 2004-08-04 07:56:42 48,640 -c—-w C:\WINDOWS\ServicePackFiles\i386\iernonce.dll + 2004-08-04 07:56:42 62,976 -c—-w C:\WINDOWS\ServicePackFiles\i386\iesetup.dll + 2004-08-04 07:56:50 93,184 -c—-w C:\WINDOWS\ServicePackFiles\i386\iexplore.exe + 2004-08-04 07:56:50 114,688 -c—-w C:\WINDOWS\ServicePackFiles\i386\iexpress.exe + 2004-08-04 07:56:42 135,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\ifmon.dll + 2004-08-04 07:56:42 8,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\igmpagnt.dll + 2004-08-04 07:56:42 505,344 -c—-w C:\WINDOWS\ServicePackFiles\i386\iis.dll + 2004-08-04 07:56:42 81,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\ils.dll + 2004-08-04 07:56:42 144,384 -c—-w C:\WINDOWS\ServicePackFiles\i386\imagehlp.dll + 2004-08-04 07:56:50 150,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\imapi.exe + 2004-08-04 06:00:15 41,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\imapi.sys + 2004-08-04 07:56:42 36,921 -c—-w C:\WINDOWS\ServicePackFiles\i386\imeshare.dll + 2004-08-04 07:56:42 35,840 -c—-w C:\WINDOWS\ServicePackFiles\i386\imgutil.dll + 2004-08-04 07:56:42 110,080 -c—-w C:\WINDOWS\ServicePackFiles\i386\imm32.dll + 2004-08-04 07:56:42 274,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetcfg.dll + 2004-08-04 07:56:42 678,400 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetcomm.dll + 2004-08-04 07:56:42 33,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetmib1.dll + 2004-08-04 07:56:42 75,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetpp.dll + 2004-08-04 07:56:42 15,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetppui.dll + 2004-08-04 07:56:08 48,128 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetres.dll + 2004-08-04 07:56:50 20,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\inetwiz.exe + 2004-08-04 07:56:42 147,456 -c—-w C:\WINDOWS\ServicePackFiles\i386\initpki.dll + 2004-08-04 07:56:42 123,392 -c—-w C:\WINDOWS\ServicePackFiles\i386\input.dll + 2004-08-04 07:56:42 96,256 -c—-w C:\WINDOWS\ServicePackFiles\i386\inseng.dll + 2004-08-04 05:59:41 5,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\intelide.sys + 2004-08-04 05:59:19 36,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\intelppm.sys + 2004-08-04 06:00:06 29,056 -c—-w C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys + 2004-08-04 07:56:50 55,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipconfig.exe + 2004-08-04 07:56:05 97,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipevldpc.dll + 2004-08-04 07:56:04 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipevlpid.dll + 2004-08-04 07:56:42 94,720 -c—-w C:\WINDOWS\ServicePackFiles\i386\iphlpapi.dll + 2004-08-04 06:04:45 20,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipinip.sys + 2004-08-04 07:56:11 96,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipmntdpc.dll + 2004-08-04 06:04:50 134,912 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipnat.sys + 2004-08-04 07:56:42 331,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipnathlp.dll + 2004-08-04 07:56:42 330,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\ippromon.dll + 2004-08-04 07:56:42 35,328 -c—-w C:\WINDOWS\ServicePackFiles\i386\iprip.dll + 2004-08-04 06:14:28 74,752 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipsec.sys + 2004-08-04 07:56:42 349,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipsecsnp.dll + 2004-08-04 07:56:42 182,784 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipsecsvc.dll + 2004-08-04 07:56:26 96,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipseldpc.dll + 2004-08-04 07:56:04 24,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipselpid.dll + 2004-08-04 07:56:42 384,000 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipsmsnap.dll + 2004-08-04 07:56:50 53,248 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipv6.exe + 2004-08-04 07:56:42 59,904 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipv6mon.dll + 2004-08-04 07:56:50 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\ipxroute.exe + 2004-08-04 07:56:42 120,320 -c—-w C:\WINDOWS\ServicePackFiles\i386\ir41_qc.dll + 2004-08-04 07:56:42 338,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\ir41_qcx.dll + 2004-08-04 07:56:42 755,200 -c—-w C:\WINDOWS\ServicePackFiles\i386\ir50_32.dll + 2004-08-04 07:56:42 200,192 -c—-w C:\WINDOWS\ServicePackFiles\i386\ir50_qc.dll + 2004-08-04 07:56:42 183,808 -c—-w C:\WINDOWS\ServicePackFiles\i386\ir50_qcx.dll + 2004-08-04 06:00:53 87,424 -c—-w C:\WINDOWS\ServicePackFiles\i386\irda.sys + 2004-08-04 06:00:46 11,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\irenum.sys + 2004-08-04 07:56:50 152,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\irftp.exe + 2004-08-04 07:56:42 27,136 -c—-w C:\WINDOWS\ServicePackFiles\i386\irmon.dll + 2004-08-04 07:56:42 81,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\isign32.dll + 2004-08-04 07:56:42 32,768 -c—-w C:\WINDOWS\ServicePackFiles\i386\isrdbg32.dll + 2004-08-04 07:56:42 143,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\itircl.dll + 2004-08-04 07:56:42 134,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\itss.dll + 2004-08-04 07:56:42 192,000 -c—-w C:\WINDOWS\ServicePackFiles\i386\iuengine.dll + 2004-08-04 07:56:42 54,272 -c—-w C:\WINDOWS\ServicePackFiles\i386\ixsso.dll + 2004-08-04 07:56:42 47,616 -c—-w C:\WINDOWS\ServicePackFiles\i386\iyuv_32.dll + 2004-08-04 07:56:42 450,560 -c—-w C:\WINDOWS\ServicePackFiles\i386\jscript.dll + 2004-08-04 07:56:42 15,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\jsproxy.dll + 2004-08-04 05:58:32 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdclass.sys + 2004-08-04 07:56:10 7,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdfi1.dll + 2004-08-04 05:58:34 14,848 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdhid.sys + 2004-08-04 07:56:10 6,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdinbe1.dll + 2004-08-04 07:56:10 6,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdinben.dll + 2004-08-04 07:56:10 6,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdinmal.dll + 2004-08-04 07:56:10 5,632 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdmaori.dll + 2004-08-04 07:56:10 6,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdmlt47.dll + 2004-08-04 07:56:10 6,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdmlt48.dll + 2004-08-04 07:56:10 7,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdno1.dll + 2004-08-04 07:56:10 7,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdsmsfi.dll + 2004-08-04 07:56:10 7,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdsmsno.dll + 2004-08-04 07:56:10 7,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\kbdukx.dll + 2004-08-04 05:59:23 7,424 -c—-w C:\WINDOWS\ServicePackFiles\i386\kd1394.dll + 2004-08-04 07:56:42 294,400 -c—-w C:\WINDOWS\ServicePackFiles\i386\kerberos.dll + 2004-08-04 07:56:42 983,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\kernel32.dll + 2002-08-29 12:00:00 42,537 -c—-w C:\WINDOWS\ServicePackFiles\i386\keyboard.sys + 2004-08-04 07:56:42 150,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\keymgr.dll + 2004-08-04 06:07:48 171,776 -c—-w C:\WINDOWS\ServicePackFiles\i386\kmixer.sys + 2004-08-04 05:49:32 92,224 -c—-w C:\WINDOWS\ServicePackFiles\i386\krnl386.exe + 2004-08-04 07:56:42 24,576 -c—-w C:\WINDOWS\ServicePackFiles\i386\krnlprov.dll + 2004-08-04 06:15:21 140,928 -c—-w C:\WINDOWS\ServicePackFiles\i386\ks.sys + 2004-08-04 05:59:47 92,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\ksecdd.sys + 2004-08-04 07:56:42 4,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\ksuser.dll + 2002-08-29 02:39:42 97,792 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\chtmbx.dll + 2002-08-29 02:39:42 56,320 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\chtskdic.dll + 2002-08-29 02:39:42 173,568 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\chtskf.dll + 2004-08-04 05:31:52 198,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\cintime.dll + 2004-08-04 05:31:54 480,256 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\cintsetp.exe + 2004-08-04 05:31:38 57,399 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\cplexe.exe + 2004-08-04 06:04:36 106,496 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imekrcic.dll + 2004-08-04 06:04:32 86,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imekrmbx.dll + 2004-08-04 05:31:48 811,064 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjp81k.dll + 2004-08-04 05:31:50 368,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpcic.dll + 2004-08-04 05:31:51 716,856 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpcus.dll + 2004-08-04 05:31:52 81,976 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.dll + 2004-08-04 05:31:53 307,257 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.exe + 2004-08-04 05:31:54 155,705 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpdsvr.exe + 2004-08-04 05:31:57 196,665 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpinst.exe + 2004-08-04 05:31:59 208,952 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjpmig.exe + 2004-08-04 05:32:11 233,527 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjprw.exe + 2004-08-04 05:32:14 262,200 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjputy.exe + 2004-08-04 05:32:15 274,489 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imjputyc.dll + 2002-08-29 02:39:02 102,456 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imlang.dll + 2002-08-29 02:39:06 59,392 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\imscinst.exe + 2002-08-29 02:39:46 15,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\padrs404.dll + 2002-08-29 02:39:08 15,360 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\padrs804.dll + 2002-08-29 02:39:08 175,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\pintlcsa.dll + 2002-08-29 02:39:08 53,760 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\pintlcsd.dll + 2002-08-29 02:39:06 70,144 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\pintlphr.exe + 2002-08-29 02:39:08 67,584 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\pmigrate.dll + 2002-08-29 02:39:50 44,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\tintlphr.exe + 2002-08-29 02:39:50 455,168 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\tintsetp.exe + 2002-08-29 02:39:48 10,240 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\tmigrate.dll + 2004-08-04 06:04:11 76,288 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\uniime.dll + 2004-08-04 05:32:34 426,041 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\voicepad.dll + 2004-08-04 05:32:35 86,073 -c—-w C:\WINDOWS\ServicePackFiles\i386\lang\voicesub.dll + 2004-08-04 07:56:42 6,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\laprxy.dll + 2004-08-04 05:59:32 34,688 -c—-w C:\WINDOWS\ServicePackFiles\i386\lbrtfdc.sys + 2004-08-04 05:56:44 423,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\licdll.dll + 2004-08-04 07:56:42 22,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\licmgr10.dll + 2004-08-04 07:56:42 58,880 -c—-w C:\WINDOWS\ServicePackFiles\i386\licwmi.dll + 2004-08-04 07:56:42 18,944 -c—-w C:\WINDOWS\ServicePackFiles\i386\linkinfo.dll + 2004-08-04 07:56:42 13,824 -c—-w C:\WINDOWS\ServicePackFiles\i386\lmhsvc.dll + 2004-08-04 07:56:42 33,792 -c—-w C:\WINDOWS\ServicePackFiles\i386\lmmib2.dll + 2004-08-04 07:56:42 399,872 -c—-w C:\WINDOWS\ServicePackFiles\i386\lmrt.dll + 2004-08-04 07:56:42 97,280 -c—-w C:\WINDOWS\ServicePackFiles\i386\loadperf.dll + 2004-08-04 07:56:42 221,696 -c—-w C:\WINDOWS\ServicePackFiles\i386\localsec.dll + 2004-08-04 07:56:42 341,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\localspl.dll + 2004-08-04 07:56:42 11,776 -c—-w C:\WINDOWS\ServicePackFiles\i386\localui.dll + 2004-08-04 07:56:50 75,264 -c—-w C:\WINDOWS\ServicePackFiles\i386\locator.exe + 2004-08-04 07:56:42 19,968 -c—-w C:\WINDOWS\ServicePackFiles\i386\log.dll + 2004-08-04 07:56:50 103,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\logagent.exe + 2004-08-04 07:56:50 59,392 -c—-w C:\WINDOWS\ServicePackFiles\i386\logman.exe + 2004-08-04 07:56:57 220,672 -c—-w C:\WINDOWS\ServicePackFiles\i386\logon.scr + 2004-08-04 07:56:50 514,560 -c—-w C:\WINDOWS\ServicePackFiles\i386\logonui.exe + 2004-08-04 07:56:42 22,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\lpdsvc.dll + 2004-08-04 07:56:42 22,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\lpk.dll + 2004-08-04 07:56:42 10,240 -c—-w C:\WINDOWS\ServicePackFiles\i386\lprhelp.dll + 2004-08-04 07:56:42 18,944 -c—-w C:\WINDOWS\ServicePackFiles\i386\lprmon.dll + 2004-08-04 07:56:42 721,920 -c—-w C:\WINDOWS\ServicePackFiles\i386\lsasrv.dll + 2004-08-04 07:56:50 13,312 -c—-w C:\WINDOWS\ServicePackFiles\i386\lsass.exe + 2004-08-04 05:41:35 606,684 -c—-w C:\WINDOWS\ServicePackFiles\i386\ltmdmnt.sys + 2002-08-29 04:34:38 420,992 -c—-w C:\WINDOWS\ServicePackFiles\i386\ltmdmntt.sys + 2004-08-04 06:00:06 7,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\ltotape.sys + 2002-08-29 04:16:22 20,864 -c—-w C:\WINDOWS\ServicePackFiles\i386\lwadihid.sys + 2004-08-04 07:56:50 72,704 -c—-w C:\WINDOWS\ServicePackFiles\i386\magnify.exe + 2004-08-04 07:56:50 85,504 -c—-w C:\WINDOWS\ServicePackFiles\i386\makecab.exe + 2004-08-04 07:56:42 14,848 -c—-w C:\WINDOWS\ServicePackFiles\i386\mcastmib.dll + 2004-08-04 07:56:42 84,480 -c—-w C:\WINDOWS\ServicePackFiles\i386\mciavi32.dll + 2004-08-04 07:56:42 35,328 -c—-w C:\WINDOWS\ServicePackFiles\i386\mciqtz32.dll + 2004-08-04 07:56:42 23,040 -c—-w C:\WINDOWS\ServicePackFiles\i386\mciseq.dll + 2004-08-04 07:56:42 23,552 -c—-w C:\WINDOWS\ServicePackFiles\i386\mciwave.dll + 2004-08-04 07:56:42 118,272 -c—-w C:\WINDOWS\ServicePackFiles\i386\mdminst.dll + 2004-08-04 07:56:42 86,016 -c—-w C:\WINDOWS\ServicePackFiles\i386\mdmxsdk.dll + 2004-08-04 05:41:55 11,868 -c—-w C:\WINDOWS\ServicePackFiles\i386\mdmxsdk.sys + 2004-08-04 06:00:49 26,112 -c—-w C:\WINDOWS\ServicePackFiles\i386\memstpci.sys + 2004-08-04 06:07:44 63,744 -c—-w C:\WINDOWS\ServicePackFiles\i386\mf.sys + 2004-08-04 07:56:42 39,936 -c—-w C:\WINDOWS\ServicePackFiles\i386\mf3216.dll + 2004-08-04 07:56:42 1,028,096 -c—-w C:\WINDOWS\ServicePackFiles\i386\mfc42.dll + 2004-08-04 07:56:42 1,024,000 -c—-w C:\WINDOWS\ServicePackFiles\i386\mfc42u.dll + 2004-08-04 07:56:42 22,528 -c—-w C:\WINDOWS\ServicePackFiles\i386\mfcsubs.dll + 2004-08-04 07:56:42 14,848 -c—-w C:\WINDOWS\ServicePackFiles\i386\mgmtapi.dll + 2004-08-04 07:56:42 18,944 -c—-w C:\WINDOWS\ServicePackFiles\i386\midimap.dll + 2004-08-04 07:56:42 201,216 -c—-w C:\WINDOWS\ServicePackFiles\i386\migism.dll + 2004-08-04 07:56:42 192,512 -c—-w C:\WINDOWS\ServicePackFiles\i386\migism_a.dll + 2004-08-04 07:56:42 60,928 -c—-w C:\WINDOWS\ServicePackFiles\i386\miglibnt.dll + 2004-08-04 07:56:50 103,424 -c—-w C:\WINDOWS\ServicePackFiles\i386\migload.exe + 2004-08-04 07:56:51 786,432 -c—-w C:\WINDOWS\ServicePackFiles\i386\migrate.exe + 2004-08-04 07:56:51 7,680 -c—-w C:\WINDOWS\ServicePackFiles\i386\migregdb.exe + 2004-08-04 07:56:51 240,128 -c—-w C:\WINDOWS\ServicePackFiles\i386\migwiz.exe + 2004-08-04 07:56:51 236,032 -c—-w C:\WINDOWS\ServicePackFiles\i386\migwiz_a.exe + 2004-08-04 07:56:42 586,240 -c—-w C:\WINDOWS\ServicePackFiles\i386\mlang.dll + 2004-08-04 07:56:51 815,104 -c—-w C:\WINDOWS\ServicePackFiles\i386\mmc.exe + 2004-08-04 07:56:42 70,656 -c—-w C:\WINDOWS\ServicePackFiles\i386\mmcbase.dll

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI