This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't Remove Trojan / Adware

91 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't seem to remove spyware from my computer. After running scans I find the following:

Trojan.FakeAlert
Adware.WinFixer

After having them removed, they later reappear and my computer runs slowly no matter what.

Thank you very much for your assistance!

Here is the current Logfile:

Logfile of HijackThis v1.99.1
Scan saved at 3:50:46 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RIMDeviceManager] "C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe" -RunServer
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199839687828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

If you already have a copy, open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, continue with the scan, "option 1", below.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue…"
Press "1" and then to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Please Note: Some security programs will incorrectly identify this tool as potentially or actually malicious due to some of it's components. Although these files can be used maliciously, they are an integral part of the fix and I recommend you tell your scanner to mind it's own business this time.

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thanks so much for your reply! Below is the information requested. Thank you and I look forward to hearing from you…….. SmitFraudFix v2.305 Scan done at 10:57:09.87, Tue 03/18/2008 Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\Program Files\McAfee.com\MPS\mscifapp.exe C:\Program Files\iTunes\iTunesHelper.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wscntfy.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts hosts file corrupted ! 127.0.0.1 www.legal-at-spybot.info 127.0.0.1 legal-at-spybot.info »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri +————————————————–+ [!] Suspicious: sysvol32.dll BHO: Sysem Player - {EDB33932-35A4-4566-9FBC-5750DCAF8F89} CLSID: {EDB33932-35A4-4566-9FBC-5750DCAF8F89} AppID: {EDB33932-35A4-4566-9FBC-5750DCAF8F89} AppID: sysvol32.dll Classes: sysvol32.Video TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411} Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06} »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport DNS Server Search Order: 68.105.28.11 DNS Server Search Order: 68.105.29.11 DNS Server Search Order: 68.105.28.12 HKLM\SYSTEM\CCS\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Adobe Flash Player ActiveX Adobe Reader 6.0.1 Apple Mobile Device Support Apple Software Update BlackBerry Desktop Software 4.2.2 BlackBerry Desktop Software 4.2.2 Broadcom 440x 10/100 Integrated Controller Dell Media Experience Dell ResourceCD Full Tilt Poker Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Intel® Extreme Graphics Driver iTunes Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition McAfee Personal Firewall Plus McAfee Privacy Service McAfee SecurityCenter McAfee VirusScan Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Media Content Microsoft Office XP Small Business Microsoft User-Mode Driver Framework Feature Pack 1.0 MSXML 4.0 SP2 (KB936181) PowerDVD QuickTime Roxio Media Manager Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB946026) Sound Blaster Live! Spybot - Search & Destroy Spyware Doctor 5.5 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Windows Defender Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download Malwarebytes' Anti-Malware from here and save it to your Desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to Update Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the little window has closed, the program is up to date and this bit is done.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

5) You will need to disable Spybot's Tea Timer function, if it is running, as it may interfere with this fix. - this is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labelled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot.
6) You will need to disable Windows Defender's real-time protection, if it is running, as it may interfere with the fix. To do this,
Open Windows Defender:
  • Go to "Tools" > "General Settings"
  • Scroll down to "Real-time protection options"
  • Uncheck "Turn on real-time protection (recommended)"
  • Click Save.
Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then .
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then .
Your PC now needs to be rebooted - if this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back into Normal Mode.

3) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then .

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete…
Under Temporary Internet Files, click Delete files…

7) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop… and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

8) Empty the Recycle Bin.

9) Run MBAM - either via the shortcut on your Desktop or Start > All Programs.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

10) Reboot the computer.

Will you then post the following:
  • A new HJT log,
  • The MBAM log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
Noviciate - Thank you so much for the prompt reply and the help. I followed your instructions and have copied the logfiles below……My machine seems to still be slow….Please see below and thank you so much for the assistance!
Logfile of HijackThis v1.99.1
Scan saved at 4:56:22 PM, on 3/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RIMDeviceManager] "C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe" -RunServer
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199839687828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

Malwarebytes' Anti-Malware 1.08
Database version: 501

Scan type: Full Scan (A:\|C:\|)
Objects scanned: 59947
Time elapsed: 35 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{48d78be5-cfb9-4b66-9ac4-96d4cf21de06} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{74d46bba-5638-473a-83b6-97e7804a7411} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{edb33932-35a4-4566-9fbc-5750dcaf8f89} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{edb33932-35a4-4566-9fbc-5750dcaf8f89} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sysvol32.Video (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\sysvol32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\sysvol32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
SmitFraudFix v2.305

Scan done at 10:57:09.87, Tue 03/18/2008
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
+————————————————–+
[!] Suspicious: sysvol32.dll
BHO: Sysem Player - {EDB33932-35A4-4566-9FBC-5750DCAF8F89}
CLSID: {EDB33932-35A4-4566-9FBC-5750DCAF8F89}
AppID: {EDB33932-35A4-4566-9FBC-5750DCAF8F89}
AppID: sysvol32.dll
Classes: sysvol32.Video
TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411}
Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06}


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
DNS Server Search Order: 68.105.28.11
DNS Server Search Order: 68.105.29.11
DNS Server Search Order: 68.105.28.12

HKLM\SYSTEM\CCS\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
The following steps will serve as a spring clean for your PC. Not all of them will be of benefit to your PC as this is a general post, but the overall effect should be positive.

1) Go to Start > Control Panel > Add/Remove Programs and remove any programs that you no longer use and then reboot your PC.

2) Download ATF Cleaner by Atribune from here and save it to your Desktop.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Java Cache

The rest are optional - if you want to remove the lot, check "Select All".
Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.

If you use the Firefox or Opera browsers, you can use this program as a quick way to tidy those up as well.

When you have finished, click on the Exit button in the Main menu.

For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please Note: This program is for Windows XP and Windows 2000 only.

3) Double click My Computer.
Right click the disc drive you wish to check.
Click Properties.
In the Properties dialog box, click the Tools Tab.
Under Error-checking, click the Check Now button.
In the "Check Disc Local Disk (C:)" dialog box, check both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, and then click Start.

This will look for and attempt to repair any errors that your hard drive has.

4) Defragment your hard drive. A tutorial for disc defragmentation is available here.

5) Download and run StartUp Inspector.
This program will help you to decide exactly what programs you disable from running at startup.
The Readme.txt file included has instructions on how to use it.

Let me have a fresh HJT log once you've worked through the above, and a description of how the PC is behaving.
Thanks again for the prompt reply and assistance. My lastest HJT log is below……..my internet now seems to run slower than ever…….it takes a very long time for pages to load….I would be grateful if you have any other advice for me.

Logfile of HijackThis v1.99.1
Scan saved at 6:40:46 PM, on 3/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\MPS\mscifapp.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [RIMDeviceManager] "C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe" -RunServer
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199839687828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
Have the PC/internet speed issues only been present since the two detections that you listed in your first post made an appearance?
Hi Noviciate - The internet loading issues etc. started right after I was infected……..at first I had pop ups which lasted a long time……and are now gone……I have checked the internet line speed coming into my computer and everything is fine and very fast…….but as I said before, when using the internet….everything is very, very slow…and almost seems to be getting slower with time…thinks load very slowly…..logging into email sites takes a long time……clinking on links, such as when I receive one of your replies takes a very, very long time to load…….Thanks again for all of your assistance.
I'll take another look at things in the morning, but i'm not seeing anything that would account for it in your logs.

.I have checked the internet line speed coming into my computer

Have you used an online speed tester, or just looked at what your PC is reporting as it's connection speed?
If the speed test was an online one, then your internet speed isn't slow all the time - unless i'm misunderstanding you. Are you suffering the same symptoms on all the sites you visit, or just specific ones?
What I mean is that a website that measures the speed for the cable company (my internet provider) says my internet speed is very high……despite this, almost all sites I visit are very slow….is there anything else I can do? Thank you very much.
Download HostsXpert by FunkyToad from here and save it to your Desktop.
You will need to extract the file(s):
Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish

You should now see the HostsXpert folder - open it and double click HostsXpert.exe
  • In the top left hand corner of the new window, ensure that the button says "Make ReadOnly?"
    If it says "Make Writable?", click it and it should change to the above.
  • Click on Restore MS Hosts File.
  • In the confirmation window, click on OK.
  • Finally, click the button mentioned above to make it read "Make Writable?".

Download OTScanIt by OldTimer from here and save it to your Desktop.
Double click OTScanIt.exe and then click Extract to extract the files - a folder called OTScanIt will be created on your Desktop.
  • Close all open programs.
  • Open the OTScanIt folder and double click OTScanIt.exe to begin.
  • Click Run Scan in the top left to, well, run a scan - obvious really!
  • Once the scan has completed a Notepad window entitled OTScanIt.txt will open with the results in - a copy of the log will also be saved in the OTScanIt folder.
  • Click Format at the top and ensure that Wordwrap is unchecked - if it isn't, do so.
  • Copy and paste the log into your next reply.
  • Once you have posted your reply, check that the last line is < End of report >
    If it isn't, the post was too long for one reply and you will need to post the remaining part of the log in a separate reply.
Here is the new logfile………thank you!
WinPFind35 logfile created on: 3/23/2008 12:12:36 PM
WinPFind35U Version 1.0.5.0	 Folder = C:\Documents and Settings\Administrator\Desktop\WinPFind35u
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
510.00 Mb Total Physical Memory | 189.54 Mb Available Physical Memory | 37.16% Memory free
1.22 Gb Paging File | 0.81 Gb Available in Paging File | 66.04% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 66.99 Gb Free Space | 89.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BRAD-12F3CC08EB
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user

[Processes - Non-Microsoft Only]
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 126976 bytes | Modified Date = 6/22/2005 12:44:34 AM | Attr =	]
pcmservice.exe -> %ProgramFiles%\Dell\Media Experience\PCMService.exe -> CyberLink Corp. [Ver = 1.0.1611  | Size = 290816 bytes | Modified Date = 4/11/2004 9:15:14 PM | Attr =	]
mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> Networks Associates Technology, Inc [Ver = 4, 3, 0, 10 | Size = 245760 bytes | Modified Date = 8/27/2003 12:00:12 PM | Attr =	]
pdvddxsrv.exe -> %ProgramFiles%\CyberLink\PowerDVD DX\PDVDDXSrv.exe -> CyberLink Corp. [Ver = 4, 5, 0, 0 | Size = 118784 bytes | Modified Date = 10/20/2006 6:23:38 PM | Attr =	]
mcvsshld.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 15 | Size = 163840 bytes | Modified Date = 8/17/2003 10:50:34 PM | Attr =	]
mpftray.exe -> %ProgramFiles%\McAfee.com\Personal Firewall\MpfTray.exe -> McAfee Security [Ver = 5.0.1.5 | Size = 1380352 bytes | Modified Date = 9/2/2003 3:00:00 PM | Attr =	]
mscifapp.exe -> %ProgramFiles%\McAfee.com\MPS\mscifapp.exe -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 24 | Size = 225280 bytes | Modified Date = 7/25/2003 4:56:18 PM | Attr =	]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 1/15/2008 4:22:56 AM | Attr =	]
mcvsescn.exe -> %ProgramFiles%\McAfee.com\VSO\McVSEscn.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 20 | Size = 413753 bytes | Modified Date = 9/28/2003 2:47:00 PM | Attr =	]
pctstray.exe -> %ProgramFiles%\Spyware Doctor\pctsTray.exe -> PC Tools [Ver = 5.5.0.51 | Size = 1103752 bytes | Modified Date = 12/10/2007 3:53:46 PM | Attr =	]
rimdevicemanager.exe -> %CommonProgramFiles%\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe -> Research In Motion Limited [Ver = 4.2.2.10 (Release build by unknown) | Size = 1320472 bytes | Modified Date = 4/13/2007 6:19:52 PM | Attr =	]
googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 1, 2, 1128, 5462 | Size = 171448 bytes | Modified Date = 2/9/2008 2:57:58 AM | Attr =	]
teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 2, 16 | Size = 2097488 bytes | Modified Date = 1/28/2008 12:43:40 PM | Attr = RHS]
bbdevmgr.exe -> %CommonProgramFiles%\Research In Motion\USB Drivers\BbDevMgr.exe -> Research In Motion Limited [Ver = 3.2.0.1 | Size = 209003 bytes | Modified Date = 4/5/2007 4:11:16 PM | Attr =	]
mpfagent.exe -> %ProgramFiles%\McAfee.com\Personal Firewall\MpfAgent.exe -> McAfee Security [Ver = 4.1.0.1 | Size = 512000 bytes | Modified Date = 9/2/2003 3:00:00 PM | Attr =	]
diagent.exe -> %ProgramFiles%\Creative\SBLive\Diagnostics\diagent.exe -> Creative Technology Ltd [Ver = 1, 1, 4, 0 | Size = 135264 bytes | Modified Date = 4/3/2002 2:01:00 AM | Attr =	]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 3:09:16 PM | Attr =	]
mpfservice.exe -> %ProgramFiles%\McAfee.com\Personal Firewall\MpfService.exe -> McAfee Corporation [Ver = 4.1.0.1 | Size = 503808 bytes | Modified Date = 9/2/2003 3:00:00 PM | Attr =	]
pctsauxs.exe -> %ProgramFiles%\Spyware Doctor\pctsAuxs.exe -> PC Tools [Ver = 5.5.0.37 | Size = 747912 bytes | Modified Date = 12/10/2007 3:53:44 PM | Attr =	]
pctssvc.exe -> %ProgramFiles%\Spyware Doctor\pctsSvc.exe -> PC Tools [Ver = 5.5.0.68 | Size = 946568 bytes | Modified Date = 12/10/2007 3:53:46 PM | Attr =	]
mcvsrte.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsrte.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 12 | Size = 106496 bytes | Modified Date = 8/8/2003 7:04:38 PM | Attr =	]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 1/15/2008 4:22:44 AM | Attr =	]
mcshield.exe -> %ProgramFiles%\McAfee.com\VSO\McShield.exe ->  [Ver =  | Size = 225375 bytes | Modified Date = 3/13/2002 9:50:34 AM | Attr =	]
winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.5.0 | Size = 310272 bytes | Modified Date = 3/10/2008 2:34:14 AM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 3:09:16 PM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 3:00:00 AM | Attr =	]
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 2/9/2008 2:57:56 AM | Attr =	]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 10.50.125 | Size = 73728 bytes | Modified Date = 10/22/2004 4:24:18 AM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 1/15/2008 4:22:44 AM | Attr =	]
(McShield) McAfee.com McShield [Win32_Own | On_Demand | Running] -> %ProgramFiles%\McAfee.com\VSO\McShield.exe ->  [Ver =  | Size = 225375 bytes | Modified Date = 3/13/2002 9:50:34 AM | Attr =	]
(mcupdmgr.exe) McAfee SecurityCenter Update Manager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee.com\Agent\mcupdmgr.exe -> Networks Associates Technology, Inc [Ver = 4, 3, 0, 8 | Size = 245760 bytes | Modified Date = 8/21/2003 7:06:56 PM | Attr =	]
(MCVSRte) McAfee.com VirusScan Online Realtime Engine [Win32_Own | On_Demand | Running] -> %ProgramFiles%\McAfee.com\VSO\mcvsrte.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 12 | Size = 106496 bytes | Modified Date = 8/8/2003 7:04:38 PM | Attr =	]
(MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Personal Firewall\MpfService.exe -> McAfee Corporation [Ver = 4.1.0.1 | Size = 503808 bytes | Modified Date = 9/2/2003 3:00:00 PM | Attr =	]
(Roxio UPnP Renderer 9) Roxio UPnP Renderer 9 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe -> Sonic Solutions [Ver = 9.0.0.93 | Size = 88824 bytes | Modified Date = 4/22/2007 9:29:34 PM | Attr =	]
(Roxio Upnp Server 9) Roxio Upnp Server 9 [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Roxio\Digital Home 9\RoxioUpnpService9.exe -> Sonic Solutions [Ver = 9.1.1.53 | Size = 359160 bytes | Modified Date = 4/22/2007 9:29:32 PM | Attr =	]
(RoxLiveShare9) LiveShare P2P Server 9 [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -> Sonic Solutions [Ver = 9.1.1.55 | Size = 310008 bytes | Modified Date = 4/23/2007 12:43:54 PM | Attr =	]
(RoxMediaDB9) RoxMediaDB9 [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -> Sonic Solutions [Ver = 9.1.1.55 | Size = 1010424 bytes | Modified Date = 4/23/2007 12:43:46 PM | Attr =	]
(RoxWatch9) Roxio Hard Drive Watcher 9 [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -> Sonic Solutions [Ver = 9.1.1.55 | Size = 166648 bytes | Modified Date = 4/23/2007 12:43:54 PM | Attr =	]
(sdAuxService) PC Tools Auxiliary Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spyware Doctor\pctsAuxs.exe -> PC Tools [Ver = 5.5.0.37 | Size = 747912 bytes | Modified Date = 12/10/2007 3:53:44 PM | Attr =	]
(sdCoreService) PC Tools Security Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spyware Doctor\pctsSvc.exe -> PC Tools [Ver = 5.5.0.68 | Size = 946568 bytes | Modified Date = 12/10/2007 3:53:46 PM | Attr =	]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
 ->  -> File not found
diagent -> %ProgramFiles%\Creative\SBLive\Diagnostics\diagent.exe -> Creative Technology Ltd [Ver = 1, 1, 4, 0 | Size = 135264 bytes | Modified Date = 4/3/2002 2:01:00 AM | Attr =	]
HotKeysCmds -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 126976 bytes | Modified Date = 6/22/2005 12:44:34 AM | Attr =	]
IgfxTray -> %SystemRoot%\system32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 155648 bytes | Modified Date = 6/22/2005 12:48:18 AM | Attr =	]
ISTray -> %ProgramFiles%\Spyware Doctor\pctsTray.exe -> PC Tools [Ver = 5.5.0.51 | Size = 1103752 bytes | Modified Date = 12/10/2007 3:53:46 PM | Attr =	]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 1/15/2008 4:22:56 AM | Attr =	]
MCAgentExe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> Networks Associates Technology, Inc [Ver = 4, 3, 0, 10 | Size = 245760 bytes | Modified Date = 8/27/2003 12:00:12 PM | Attr =	]
MCUpdateExe -> %ProgramFiles%\McAfee.com\Agent\mcupdate.exe -> Networks Associates Technology, Inc [Ver = 4, 3, 0, 7 | Size = 180224 bytes | Modified Date = 8/21/2003 7:10:50 PM | Attr =	]
MPFExe -> %ProgramFiles%\McAfee.com\Personal Firewall\MpfTray.exe -> McAfee Security [Ver = 5.0.1.5 | Size = 1380352 bytes | Modified Date = 9/2/2003 3:00:00 PM | Attr =	]
MPSExe -> %ProgramFiles%\McAfee.com\MPS\mscifapp.exe -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 24 | Size = 225280 bytes | Modified Date = 7/25/2003 4:56:18 PM | Attr =	]
PCMService -> %ProgramFiles%\Dell\Media Experience\PCMService.exe -> CyberLink Corp. [Ver = 1.0.1611  | Size = 290816 bytes | Modified Date = 4/11/2004 9:15:14 PM | Attr =	]
PDVDDXSrv -> %ProgramFiles%\CyberLink\PowerDVD DX\PDVDDXSrv.exe -> CyberLink Corp. [Ver = 4, 5, 0, 0 | Size = 118784 bytes | Modified Date = 10/20/2006 6:23:38 PM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4 | Size = 385024 bytes | Modified Date = 1/10/2008 4:27:36 PM | Attr =	]
RoxWatchTray -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe -> Sonic Solutions [Ver = 9.1.1.55 | Size = 228088 bytes | Modified Date = 4/23/2007 12:43:50 PM | Attr =	]
UpdReg -> %SystemRoot%\Updreg.EXE -> Creative Technology Ltd. [Ver = 1.0.2 | Size = 90112 bytes | Modified Date = 5/11/2000 2:00:00 AM | Attr =	]
VirusScan Online -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 15 | Size = 163840 bytes | Modified Date = 8/17/2003 10:50:34 PM | Attr =	]
VSOCheckTask -> %ProgramFiles%\McAfee.com\VSO\mcmnhdlr.exe -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 12 | Size = 122880 bytes | Modified Date = 8/8/2003 7:02:10 PM | Attr =	]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> 
IMAIL-> Installed = 1 -> 
MAPI-> Installed = 1 -> 
MSFS-> Installed = 1 -> 
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
RIMDeviceManager -> %CommonProgramFiles%\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe -> Research In Motion Limited [Ver = 4.2.2.10 (Release build by unknown) | Size = 1320472 bytes | Modified Date = 4/13/2007 6:19:52 PM | Attr =	]
SpybotSD TeaTimer -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 2, 16 | Size = 2097488 bytes | Modified Date = 1/28/2008 12:43:40 PM | Attr = RHS]
swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 1, 2, 1128, 5462 | Size = 171448 bytes | Modified Date = 2/9/2008 2:57:58 AM | Attr =	]
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Desktop Manager.lnk -> %ProgramFiles%\Research In Motion\BlackBerry\DesktopMgr.exe -> Research In Motion Limited [Ver = 4.2.2.14 (Release build by absadmin) | Size = 1283608 bytes | Modified Date = 5/31/2007 3:49:06 PM | Attr =	]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 348160 bytes | Modified Date = 6/22/2005 12:44:12 AM | Attr =	]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\\ScanWithAntiVirus -> 2 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
< HOSTS File > (698 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.google.com/ -> 
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 6.0.1.2003110300 | Size = 54248 bytes | Modified Date = 11/3/2003 3:17:44 PM | Attr =	]
{227B8AA8-DAF2-4892-BD1D-73F568BCB24E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee.com\MPS\McBrHlpr.dll [McBrwHelper Class] -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 102400 bytes | Modified Date = 4/28/2003 5:38:36 PM | Attr =	]
{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 12:43:28 PM | Attr =	]
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 5904 | Size = 2403392 bytes | Modified Date = 2/9/2008 2:57:56 AM | Attr = R  ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 5904 | Size = 2403392 bytes | Modified Date = 2/9/2008 2:57:56 AM | Attr = R  ]
{BA52B914-B692-46c4-B683-905236F6F655} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee.com\VSO\mcvsshl.dll [McAfee VirusScan] -> Networks Associates Technology, Inc [Ver = 8, 0, 0, 15 | Size = 114743 bytes | Modified Date = 8/18/2003 12:19:32 PM | Attr =	]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar1.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 5904 | Size = 2403392 bytes | Modified Date = 2/9/2008 2:57:56 AM | Attr = R  ]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 12:43:28 PM | Attr =	]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{2EAFEEA1-B781-4D3F-9066-046C2408A34A} ->	(Motorola SURFboard SB5101 USB Cable Modem) -> 
{9E49E816-A0CB-4E8E-93FC-9DDF593E2D09} ->	(Broadcom 440x 10/100 Integrated Controller) -> 
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
Protocol_Catalog9\Catalog_Entries\000000000001 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000002 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000003 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000004 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000005 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000006 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000007 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000008 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000009 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000010 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000011 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000012 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000013 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000014 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000015 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000016 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000017 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000018 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000019 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000020 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000021 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000022 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000023 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000024 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000025 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000026 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000027 -> %SystemRoot%\system32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Modified Date = 4/9/2003 7:32:50 PM | Attr =	]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[] -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199839687828[WUWebControl Class] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 



[Files/Folders - Created Within 90 days]
AUTOEXEC.BAT -> %SystemDrive%\AUTOEXEC.BAT ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr =	]
boot.ini -> %SystemDrive%\boot.ini ->  [Ver =  | Size = 211 bytes | Created Date = 1/8/2008 9:00:01 AM | Attr =  HS]
CONFIG.SYS -> %SystemDrive%\CONFIG.SYS ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr =	]
DELL -> %SystemDrive%\DELL ->  [Folder | Created Date = 1/8/2008 5:10:44 PM | Attr =	]
Documents and Settings -> %SystemDrive%\Documents and Settings ->  [Folder | Created Date = 1/8/2008 9:00:45 AM | Attr =	]
Drivers -> %SystemDrive%\Drivers ->  [Folder | Created Date = 1/8/2008 5:34:52 PM | Attr =	]
IO.SYS -> %SystemDrive%\IO.SYS ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr = RHS]
MSDOS.SYS -> %SystemDrive%\MSDOS.SYS ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr = RHS]
Program Files -> %ProgramFiles% ->  [Folder | Created Date = 1/8/2008 9:01:45 AM | Attr = R  ]
RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Created Date = 1/10/2008 6:06:22 PM | Attr =  HS]
System Volume Information -> %SystemDrive%\System Volume Information ->  [Folder | Created Date = 1/8/2008 9:00:45 AM | Attr =  HS]
tmp.bat -> %SystemDrive%\tmp.bat ->  [Ver =  | Size = 51 bytes | Created Date = 2/9/2008 2:00:28 AM | Attr =	]
WINDOWS -> %SystemRoot% ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
a3d.dll -> %SystemRoot%\System32\dllcache\a3d.dll ->   [Ver = 80.0.0.3 | Size = 65536 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
big5.nls -> %SystemRoot%\System32\dllcache\big5.nls ->  [Ver =  | Size = 66728 bytes | Created Date = 1/8/2008 5:11:21 PM | Attr =	]
bopomofo.nls -> %SystemRoot%\System32\dllcache\bopomofo.nls ->  [Ver =  | Size = 82172 bytes | Created Date = 1/8/2008 5:11:21 PM | Attr =	]
cap7146.sys -> %SystemRoot%\System32\dllcache\cap7146.sys -> Philips Semiconductors GmbH [Ver = 1.00 (XPClient.010817-1148) | Size = 54528 bytes | Created Date = 1/8/2008 5:11:28 PM | Attr =	]
chtskf.dll -> %SystemRoot%\System32\dllcache\chtskf.dll ->  [Ver =  | Size = 173568 bytes | Created Date = 1/8/2008 5:11:31 PM | Attr =	]
c_10001.nls -> %SystemRoot%\System32\dllcache\c_10001.nls ->  [Ver =  | Size = 162850 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10002.nls -> %SystemRoot%\System32\dllcache\c_10002.nls ->  [Ver =  | Size = 195618 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10003.nls -> %SystemRoot%\System32\dllcache\c_10003.nls ->  [Ver =  | Size = 177698 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10004.nls -> %SystemRoot%\System32\dllcache\c_10004.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10005.nls -> %SystemRoot%\System32\dllcache\c_10005.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10006.nls -> %SystemRoot%\System32\dllcache\c_10006.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_10007.nls -> %SystemRoot%\System32\dllcache\c_10007.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
c_10008.nls -> %SystemRoot%\System32\dllcache\c_10008.nls ->  [Ver =  | Size = 173602 bytes | Created Date = 1/8/2008 5:11:22 PM | Attr =	]
c_10010.nls -> %SystemRoot%\System32\dllcache\c_10010.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_10017.nls -> %SystemRoot%\System32\dllcache\c_10017.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
c_10021.nls -> %SystemRoot%\System32\dllcache\c_10021.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_10029.nls -> %SystemRoot%\System32\dllcache\c_10029.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_10081.nls -> %SystemRoot%\System32\dllcache\c_10081.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_10082.nls -> %SystemRoot%\System32\dllcache\c_10082.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_1047.nls -> %SystemRoot%\System32\dllcache\c_1047.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1140.nls -> %SystemRoot%\System32\dllcache\c_1140.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1141.nls -> %SystemRoot%\System32\dllcache\c_1141.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1142.nls -> %SystemRoot%\System32\dllcache\c_1142.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1143.nls -> %SystemRoot%\System32\dllcache\c_1143.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1144.nls -> %SystemRoot%\System32\dllcache\c_1144.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1145.nls -> %SystemRoot%\System32\dllcache\c_1145.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1146.nls -> %SystemRoot%\System32\dllcache\c_1146.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1147.nls -> %SystemRoot%\System32\dllcache\c_1147.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1148.nls -> %SystemRoot%\System32\dllcache\c_1148.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:23 PM | Attr =	]
c_1149.nls -> %SystemRoot%\System32\dllcache\c_1149.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_1361.nls -> %SystemRoot%\System32\dllcache\c_1361.nls ->  [Ver =  | Size = 189986 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20000.nls -> %SystemRoot%\System32\dllcache\c_20000.nls ->  [Ver =  | Size = 180258 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20001.nls -> %SystemRoot%\System32\dllcache\c_20001.nls ->  [Ver =  | Size = 186402 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20002.nls -> %SystemRoot%\System32\dllcache\c_20002.nls ->  [Ver =  | Size = 173602 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20003.nls -> %SystemRoot%\System32\dllcache\c_20003.nls ->  [Ver =  | Size = 185378 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20004.nls -> %SystemRoot%\System32\dllcache\c_20004.nls ->  [Ver =  | Size = 180258 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20005.nls -> %SystemRoot%\System32\dllcache\c_20005.nls ->  [Ver =  | Size = 187938 bytes | Created Date = 1/8/2008 5:11:24 PM | Attr =	]
c_20105.nls -> %SystemRoot%\System32\dllcache\c_20105.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20106.nls -> %SystemRoot%\System32\dllcache\c_20106.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20107.nls -> %SystemRoot%\System32\dllcache\c_20107.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20108.nls -> %SystemRoot%\System32\dllcache\c_20108.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20127.nls -> %SystemRoot%\System32\dllcache\c_20127.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:36 AM | Attr =	]
c_20269.nls -> %SystemRoot%\System32\dllcache\c_20269.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20273.nls -> %SystemRoot%\System32\dllcache\c_20273.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20277.nls -> %SystemRoot%\System32\dllcache\c_20277.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20278.nls -> %SystemRoot%\System32\dllcache\c_20278.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20280.nls -> %SystemRoot%\System32\dllcache\c_20280.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20284.nls -> %SystemRoot%\System32\dllcache\c_20284.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20285.nls -> %SystemRoot%\System32\dllcache\c_20285.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20290.nls -> %SystemRoot%\System32\dllcache\c_20290.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:25 PM | Attr =	]
c_20297.nls -> %SystemRoot%\System32\dllcache\c_20297.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20420.nls -> %SystemRoot%\System32\dllcache\c_20420.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20423.nls -> %SystemRoot%\System32\dllcache\c_20423.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20424.nls -> %SystemRoot%\System32\dllcache\c_20424.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20833.nls -> %SystemRoot%\System32\dllcache\c_20833.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20838.nls -> %SystemRoot%\System32\dllcache\c_20838.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20871.nls -> %SystemRoot%\System32\dllcache\c_20871.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20880.nls -> %SystemRoot%\System32\dllcache\c_20880.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20924.nls -> %SystemRoot%\System32\dllcache\c_20924.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20932.nls -> %SystemRoot%\System32\dllcache\c_20932.nls ->  [Ver =  | Size = 180770 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20936.nls -> %SystemRoot%\System32\dllcache\c_20936.nls ->  [Ver =  | Size = 173602 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_20949.nls -> %SystemRoot%\System32\dllcache\c_20949.nls ->  [Ver =  | Size = 177698 bytes | Created Date = 1/8/2008 5:11:26 PM | Attr =	]
c_21025.nls -> %SystemRoot%\System32\dllcache\c_21025.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_21027.nls -> %SystemRoot%\System32\dllcache\c_21027.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_28594.nls -> %SystemRoot%\System32\dllcache\c_28594.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
c_28595.nls -> %SystemRoot%\System32\dllcache\c_28595.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
c_28596.nls -> %SystemRoot%\System32\dllcache\c_28596.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_28597.nls -> %SystemRoot%\System32\dllcache\c_28597.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_28599.nls -> %SystemRoot%\System32\dllcache\c_28599.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_28603.nls -> %SystemRoot%\System32\dllcache\c_28603.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:44 AM | Attr =	]
c_708.nls -> %SystemRoot%\System32\dllcache\c_708.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_720.nls -> %SystemRoot%\System32\dllcache\c_720.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_737.nls -> %SystemRoot%\System32\dllcache\c_737.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_852.nls -> %SystemRoot%\System32\dllcache\c_852.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_855.nls -> %SystemRoot%\System32\dllcache\c_855.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
c_857.nls -> %SystemRoot%\System32\dllcache\c_857.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_858.nls -> %SystemRoot%\System32\dllcache\c_858.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_862.nls -> %SystemRoot%\System32\dllcache\c_862.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 5:11:27 PM | Attr =	]
c_864.nls -> %SystemRoot%\System32\dllcache\c_864.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 5:11:28 PM | Attr =	]
c_866.nls -> %SystemRoot%\System32\dllcache\c_866.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
c_869.nls -> %SystemRoot%\System32\dllcache\c_869.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_870.nls -> %SystemRoot%\System32\dllcache\c_870.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 5:11:28 PM | Attr =	]
c_875.nls -> %SystemRoot%\System32\dllcache\c_875.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
dgrpsetu.dll -> %SystemRoot%\System32\dllcache\dgrpsetu.dll -> Digi International, Inc. [Ver = 2.3.7 | Size = 176157 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
dgsetup.dll -> %SystemRoot%\System32\dllcache\dgsetup.dll -> Digi International [Ver = v3.7.3.0 | Size = 85020 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
eqnclass.dll -> %SystemRoot%\System32\dllcache\eqnclass.dll -> Equinox Systems Inc. [Ver = 5.0u(58) | Size = 103424 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
esucmd.dll -> %SystemRoot%\System32\dllcache\esucmd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 31744 bytes | Created Date = 1/8/2008 5:11:41 PM | Attr =	]
esuimgd.dll -> %SystemRoot%\System32\dllcache\esuimgd.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 57856 bytes | Created Date = 1/8/2008 5:11:41 PM | Attr =	]
esunid.dll -> %SystemRoot%\System32\dllcache\esunid.dll -> SEIKO EPSON CORP. [Ver = 1.00 | Size = 45056 bytes | Created Date = 1/8/2008 5:11:41 PM | Attr =	]
FP4.CAT -> %SystemRoot%\System32\dllcache\FP4.CAT ->  [Ver =  | Size = 31281 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
fpencode.dll -> %SystemRoot%\System32\dllcache\fpencode.dll ->  [Ver =  | Size = 94208 bytes | Created Date = 1/8/2008 5:11:44 PM | Attr =	]
hanja.lex -> %SystemRoot%\System32\dllcache\hanja.lex ->  [Ver =  | Size = 108827 bytes | Created Date = 1/8/2008 5:11:48 PM | Attr =	]
HPCRDP.CAT -> %SystemRoot%\System32\dllcache\HPCRDP.CAT ->  [Ver =  | Size = 13472 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
htrn_jis.dll -> %SystemRoot%\System32\dllcache\htrn_jis.dll -> Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 13312 bytes | Created Date = 1/8/2008 5:06:29 PM | Attr =	]
hwxjpn.dll -> %SystemRoot%\System32\dllcache\hwxjpn.dll ->  [Ver =  | Size = 13463552 bytes | Created Date = 1/8/2008 5:11:53 PM | Attr =	]
IASNT4.CAT -> %SystemRoot%\System32\dllcache\IASNT4.CAT ->  [Ver =  | Size = 8574 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
imekr.lex -> %SystemRoot%\System32\dllcache\imekr.lex ->  [Ver =  | Size = 134339 bytes | Created Date = 1/8/2008 5:12:02 PM | Attr =	]
imjpinst.exe -> %SystemRoot%\System32\dllcache\imjpinst.exe ->  [Ver =  | Size = 196665 bytes | Created Date = 1/8/2008 5:12:04 PM | Attr =	]
IMS.CAT -> %SystemRoot%\System32\dllcache\IMS.CAT ->  [Ver =  | Size = 13753 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
imscinst.exe -> %SystemRoot%\System32\dllcache\imscinst.exe ->  [Ver =  | Size = 59392 bytes | Created Date = 1/8/2008 5:12:05 PM | Attr =	]
isrdbg32.dll -> %SystemRoot%\System32\dllcache\isrdbg32.dll -> Intel Corporation [Ver = 0.0 | Size = 32768 bytes | Created Date = 1/8/2008 5:07:43 PM | Attr =	]
korwbrkr.lex -> %SystemRoot%\System32\dllcache\korwbrkr.lex ->  [Ver =  | Size = 1158818 bytes | Created Date = 1/8/2008 5:12:12 PM | Attr =	]
ksc.nls -> %SystemRoot%\System32\dllcache\ksc.nls ->  [Ver =  | Size = 47066 bytes | Created Date = 1/8/2008 5:12:13 PM | Attr =	]
ltts1033.lxa -> %SystemRoot%\System32\dllcache\ltts1033.lxa ->  [Ver =  | Size = 643717 bytes | Created Date = 1/8/2008 9:01:46 AM | Attr =	]
MAPIMIG.CAT -> %SystemRoot%\System32\dllcache\MAPIMIG.CAT ->  [Ver =  | Size = 399645 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
mediactr.cat -> %SystemRoot%\System32\dllcache\mediactr.cat ->  [Ver =  | Size = 31965 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
mplayer2.exe -> %SystemRoot%\System32\dllcache\mplayer2.exe ->  [Ver =  | Size = 4639 bytes | Created Date = 1/8/2008 5:07:54 PM | Attr =	]
msinfo.dll -> %SystemRoot%\System32\dllcache\msinfo.dll ->  [Ver = 7, 0, 0, 0 | Size = 376320 bytes | Created Date = 1/8/2008 5:07:45 PM | Attr =	]
MSMSGS.CAT -> %SystemRoot%\System32\dllcache\MSMSGS.CAT ->  [Ver =  | Size = 9581 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
msn7.cat -> %SystemRoot%\System32\dllcache\msn7.cat ->  [Ver =  | Size = 24209 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
msn9.cat -> %SystemRoot%\System32\dllcache\msn9.cat ->  [Ver =  | Size = 11651 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
MSTSWEB.CAT -> %SystemRoot%\System32\dllcache\MSTSWEB.CAT ->  [Ver =  | Size = 7245 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
MW770.CAT -> %SystemRoot%\System32\dllcache\MW770.CAT ->  [Ver =  | Size = 37484 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
netfx.cat -> %SystemRoot%\System32\dllcache\netfx.cat ->  [Ver =  | Size = 141702 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
nls302en.lex -> %SystemRoot%\System32\dllcache\nls302en.lex ->  [Ver =  | Size = 4399505 bytes | Created Date = 1/8/2008 5:08:32 PM | Attr =	]
NT5.CAT -> %SystemRoot%\System32\dllcache\NT5.CAT ->  [Ver =  | Size = 2012670 bytes | Created Date = 1/8/2008 9:01:21 AM | Attr =	]
NT5IIS.CAT -> %SystemRoot%\System32\dllcache\NT5IIS.CAT ->  [Ver =  | Size = 797189 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
NT5INF.CAT -> %SystemRoot%\System32\dllcache\NT5INF.CAT ->  [Ver =  | Size = 502724 bytes | Created Date = 1/8/2008 9:01:21 AM | Attr =	]
NTPRINT.CAT -> %SystemRoot%\System32\dllcache\NTPRINT.CAT ->  [Ver =  | Size = 1086058 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
OEMBIOS.CAT -> %SystemRoot%\System32\dllcache\OEMBIOS.CAT ->  [Ver =  | Size = 7710 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
pinball.exe -> %SystemRoot%\System32\dllcache\pinball.exe -> Cinematronics [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 281088 bytes | Created Date = 1/8/2008 5:06:07 PM | Attr =	]
pintlcsa.dll -> %SystemRoot%\System32\dllcache\pintlcsa.dll ->  [Ver =  | Size = 175104 bytes | Created Date = 1/8/2008 5:12:35 PM | Attr =	]
prc.nls -> %SystemRoot%\System32\dllcache\prc.nls ->  [Ver =  | Size = 83748 bytes | Created Date = 1/8/2008 5:12:36 PM | Attr =	]
prcp.nls -> %SystemRoot%\System32\dllcache\prcp.nls ->  [Ver =  | Size = 83748 bytes | Created Date = 1/8/2008 5:12:36 PM | Attr =	]
r1033tts.lxa -> %SystemRoot%\System32\dllcache\r1033tts.lxa ->  [Ver =  | Size = 605050 bytes | Created Date = 1/8/2008 9:01:46 AM | Attr =	]
rw330ext.dll -> %SystemRoot%\System32\dllcache\rw330ext.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 26624 bytes | Created Date = 1/8/2008 5:12:42 PM | Attr =	]
rwia001.dll -> %SystemRoot%\System32\dllcache\rwia001.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 79872 bytes | Created Date = 1/8/2008 5:12:42 PM | Attr =	]
rwia330.dll -> %SystemRoot%\System32\dllcache\rwia330.dll -> Ricoh Co., Ltd. [Ver = 5, 0, 2419, 1 | Size = 79872 bytes | Created Date = 1/8/2008 5:12:42 PM | Attr =	]
sam.sdf -> %SystemRoot%\System32\dllcache\sam.sdf ->  [Ver =  | Size = 888 bytes | Created Date = 1/8/2008 9:01:46 AM | Attr =	]
sam.spd -> %SystemRoot%\System32\dllcache\sam.spd ->  [Ver =  | Size = 1685606 bytes | Created Date = 1/8/2008 9:01:46 AM | Attr =	]
SP2.CAT -> %SystemRoot%\System32\dllcache\SP2.CAT ->  [Ver =  | Size = 1042903 bytes | Created Date = 1/8/2008 9:01:21 AM | Attr =	]
spxcoins.dll -> %SystemRoot%\System32\dllcache\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
srframe.mmf -> %SystemRoot%\System32\dllcache\srframe.mmf ->  [Ver =  | Size = 984 bytes | Created Date = 1/8/2008 5:08:04 PM | Attr =	]
tabletpc.cat -> %SystemRoot%\System32\dllcache\tabletpc.cat ->  [Ver =  | Size = 110116 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
wmerrenu.cat -> %SystemRoot%\System32\dllcache\wmerrenu.cat ->  [Ver =  | Size = 7334 bytes | Created Date = 1/8/2008 9:01:22 AM | Attr =	]
xjis.nls -> %SystemRoot%\System32\dllcache\xjis.nls ->  [Ver =  | Size = 28288 bytes | Created Date = 1/8/2008 5:13:12 PM | Attr =	]
bcm4sbxp.sys -> %SystemRoot%\System32\drivers\bcm4sbxp.sys -> Broadcom Corporation [Ver = 3.63.0.0 built by: WinDDK | Size = 43136 bytes | Created Date = 1/8/2008 5:33:46 PM | Attr = R  ]
ctoss2k.sys -> %SystemRoot%\System32\drivers\ctoss2k.sys -> Creative Technology Ltd. [Ver = 5.12.01.0172-0.75.1810 (beta-release) | Size = 178672 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
ctsfm2k.sys -> %SystemRoot%\System32\drivers\ctsfm2k.sys -> Creative Technology Ltd [Ver = 5.12.01.0172-0.75.1810 (beta-release) | Size = 130192 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
disdn -> %SystemRoot%\System32\drivers\disdn ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
etc -> %SystemRoot%\System32\drivers\etc ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
hosts.20080209-143216.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080209-143216.backup ->  [Ver =  | Size = 734 bytes | Created Date = 2/9/2008 3:32:16 PM | Attr =	]
ialmnt5.sys -> %SystemRoot%\System32\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.4342 | Size = 807998 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ikfilesec.sys -> %SystemRoot%\System32\drivers\ikfilesec.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1038 built by: WinDDK | Size = 41864 bytes | Created Date = 2/9/2008 2:58:10 AM | Attr =	]
iksysflt.sys -> %SystemRoot%\System32\drivers\iksysflt.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1029 | Size = 66952 bytes | Created Date = 2/9/2008 2:58:10 AM | Attr =	]
iksyssec.sys -> %SystemRoot%\System32\drivers\iksyssec.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1031 | Size = 81288 bytes | Created Date = 2/9/2008 2:58:10 AM | Attr =	]
kcom.sys -> %SystemRoot%\System32\drivers\kcom.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1008 | Size = 29576 bytes | Created Date = 2/9/2008 2:58:10 AM | Attr =	]
MpFirewall.sys -> %SystemRoot%\System32\drivers\MpFirewall.sys -> McAfee Security [Ver = 5, 0, 1, 0 | Size = 79165 bytes | Created Date = 1/8/2008 6:30:44 PM | Attr =	]
NaiFiltr.sys -> %SystemRoot%\System32\drivers\NaiFiltr.sys ->  [Ver =  | Size = 23296 bytes | Created Date = 1/8/2008 6:20:00 PM | Attr =	]
NetMotCM.sys -> %SystemRoot%\System32\drivers\NetMotCM.sys -> Motorola Inc. [Ver = 2.4.5.0 | Size = 15360 bytes | Created Date = 1/8/2008 5:19:07 PM | Attr =	]
omci.sys -> %SystemRoot%\System32\drivers\omci.sys -> Dell Computer Corporation [Ver = 6, 1, 0, 242 | Size = 13632 bytes | Created Date = 1/8/2008 5:56:02 PM | Attr =	]
P16X.sys -> %SystemRoot%\System32\drivers\P16X.sys -> Creative Technology Ltd. [Ver = 5.12.01.203 | Size = 1330048 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
PFMODNT.SYS -> %SystemRoot%\System32\drivers\PFMODNT.SYS -> Creative Technology Ltd. [Ver = 3.0.0.3 | Size = 15840 bytes | Created Date = 1/8/2008 5:39:34 PM | Attr =	]
RimSerial.sys -> %SystemRoot%\System32\drivers\RimSerial.sys -> Research in Motion Ltd [Ver = 2.1.0.4 | Size = 26496 bytes | Created Date = 1/22/2008 10:05:12 AM | Attr = R  ]
UMDF -> %SystemRoot%\System32\drivers\UMDF ->  [Folder | Created Date = 1/8/2008 6:14:27 PM | Attr =	]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 6:14:30 PM | Attr =  H ]
$winnt$.inf -> %SystemRoot%\System32\$winnt$.inf ->  [Ver =  | Size = 261 bytes | Created Date = 1/8/2008 8:59:57 AM | Attr =	]
1025 -> %SystemRoot%\System32\1025 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1028 -> %SystemRoot%\System32\1028 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1031 -> %SystemRoot%\System32\1031 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1033 -> %SystemRoot%\System32\1033 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1037 -> %SystemRoot%\System32\1037 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1041 -> %SystemRoot%\System32\1041 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1042 -> %SystemRoot%\System32\1042 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
1054 -> %SystemRoot%\System32\1054 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
2052 -> %SystemRoot%\System32\2052 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
3076 -> %SystemRoot%\System32\3076 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
3com_dmi -> %SystemRoot%\System32\3com_dmi ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
A3d.dll -> %SystemRoot%\System32\A3d.dll ->   [Ver = 80.0.0.3 | Size = 65536 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
amcompat.tlb -> %SystemRoot%\System32\amcompat.tlb ->  [Ver =  | Size = 16832 bytes | Created Date = 1/8/2008 5:10:06 PM | Attr =	]
AUTOEXEC.NT -> %SystemRoot%\System32\AUTOEXEC.NT ->  [Ver =  | Size = 1688 bytes | Created Date = 1/8/2008 9:01:33 AM | Attr =	]
bopomofo.uce -> %SystemRoot%\System32\bopomofo.uce ->  [Ver =  | Size = 22984 bytes | Created Date = 1/8/2008 5:06:23 PM | Attr =	]
CatRoot -> %SystemRoot%\System32\CatRoot ->  [Folder | Created Date = 1/8/2008 9:01:10 AM | Attr =	]
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Created Date = 1/8/2008 9:01:10 AM | Attr =	]
cdplayer.exe.manifest -> %SystemRoot%\System32\cdplayer.exe.manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
Com -> %SystemRoot%\System32\Com ->  [Folder | Created Date = 1/8/2008 5:06:02 PM | Attr =	]
config -> %SystemRoot%\System32\config ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
CONFIG.NT -> %SystemRoot%\System32\CONFIG.NT ->  [Ver =  | Size = 2577 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr =	]
Ct1mgm.rom -> %SystemRoot%\System32\Ct1mgm.rom ->  [Ver =  | Size = 1048576 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
ct2mgm.sf2 -> %SystemRoot%\System32\ct2mgm.sf2 ->  [Ver =  | Size = 2167684 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
CTDevCRes.dll -> %SystemRoot%\System32\CTDevCRes.dll -> Creative Technology Ltd [Ver = 1.0.0 | Size = 24576 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
ctdevctrl.CNT -> %SystemRoot%\System32\ctdevctrl.CNT ->  [Ver =  | Size = 274 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
CTDevCtrl.cpl -> %SystemRoot%\System32\CTDevCtrl.cpl -> Creative Technology Ltd. [Ver = 1.00.01.0 | Size = 212992 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
CTDevctrl.ftg -> %SystemRoot%\System32\CTDevctrl.ftg ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
CTDevctrl.fts -> %SystemRoot%\System32\CTDevctrl.fts ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
CTDevctrl.gid -> %SystemRoot%\System32\CTDevctrl.gid ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
CTDEVCTRL.HLP -> %SystemRoot%\System32\CTDEVCTRL.HLP ->  [Ver =  | Size = 14273 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
ctzapxx.ini -> %SystemRoot%\System32\ctzapxx.ini ->  [Ver =  | Size = 26 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
c_10006.nls -> %SystemRoot%\System32\c_10006.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_10007.nls -> %SystemRoot%\System32\c_10007.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
c_10010.nls -> %SystemRoot%\System32\c_10010.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_10017.nls -> %SystemRoot%\System32\c_10017.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
c_10029.nls -> %SystemRoot%\System32\c_10029.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_10081.nls -> %SystemRoot%\System32\c_10081.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_10082.nls -> %SystemRoot%\System32\c_10082.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_20127.nls -> %SystemRoot%\System32\c_20127.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:36 AM | Attr =	]
C_28594.NLS -> %SystemRoot%\System32\C_28594.NLS ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
C_28595.NLS -> %SystemRoot%\System32\C_28595.NLS ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:41 AM | Attr =	]
C_28597.NLS -> %SystemRoot%\System32\C_28597.NLS ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_28599.nls -> %SystemRoot%\System32\c_28599.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_28603.nls -> %SystemRoot%\System32\c_28603.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:44 AM | Attr =	]
c_737.nls -> %SystemRoot%\System32\c_737.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_852.nls -> %SystemRoot%\System32\c_852.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:37 AM | Attr =	]
c_855.nls -> %SystemRoot%\System32\c_855.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
c_857.nls -> %SystemRoot%\System32\c_857.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:43 AM | Attr =	]
c_866.nls -> %SystemRoot%\System32\c_866.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:39 AM | Attr =	]
c_869.nls -> %SystemRoot%\System32\c_869.nls ->  [Ver =  | Size = 66594 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
c_875.nls -> %SystemRoot%\System32\c_875.nls ->  [Ver =  | Size = 66082 bytes | Created Date = 1/8/2008 9:01:40 AM | Attr =	]
Data -> %SystemRoot%\System32\Data ->  [Folder | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
Default.sfm -> %SystemRoot%\System32\Default.sfm ->  [Ver =  | Size = 59 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
default4.sfm -> %SystemRoot%\System32\default4.sfm ->  [Ver =  | Size = 59 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
default8.sfm -> %SystemRoot%\System32\default8.sfm ->  [Ver =  | Size = 59 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
desktop.ini -> %SystemRoot%\System32\desktop.ini ->  [Ver =  | Size = 2 bytes | Created Date = 1/8/2008 5:08:09 PM | Attr =	]
dgrpsetu.dll -> %SystemRoot%\System32\dgrpsetu.dll -> Digi International, Inc. [Ver = 2.3.7 | Size = 176157 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
dgsetup.dll -> %SystemRoot%\System32\dgsetup.dll -> Digi International [Ver = v3.7.3.0 | Size = 85020 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
dhcp -> %SystemRoot%\System32\dhcp ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
DirectX -> %SystemRoot%\System32\DirectX ->  [Folder | Created Date = 1/8/2008 5:08:26 PM | Attr =	]
dllcache -> %SystemRoot%\System32\dllcache ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr = RHS]
drivers -> %SystemRoot%\System32\drivers ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
DRVSTORE -> %SystemRoot%\System32\DRVSTORE ->  [Folder | Created Date = 1/10/2008 7:02:48 PM | Attr =	]
dumphive.exe -> %SystemRoot%\System32\dumphive.exe ->  [Ver =  | Size = 51200 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
emptyregdb.dat -> %SystemRoot%\System32\emptyregdb.dat ->  [Ver =  | Size = 21640 bytes | Created Date = 1/8/2008 5:07:07 PM | Attr =	]
en-US -> %SystemRoot%\System32\en-US ->  [Folder | Created Date = 1/12/2008 3:29:11 PM | Attr =	]
EqnClass.Dll -> %SystemRoot%\System32\EqnClass.Dll -> Equinox Systems Inc. [Ver = 5.0u(58) | Size = 103424 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
export -> %SystemRoot%\System32\export ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT ->  [Ver =  | Size = 283720 bytes | Created Date = 1/8/2008 9:00:45 AM | Attr =	]
gb2312.uce -> %SystemRoot%\System32\gb2312.uce ->  [Ver =  | Size = 24006 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
hccutils.dll -> %SystemRoot%\System32\hccutils.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 118784 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
hhactivex.dll -> %SystemRoot%\System32\hhactivex.dll -> Blue Sky Software Corporation. [Ver = 8.00.125 | Size = 446464 bytes | Created Date = 1/8/2008 5:56:06 PM | Attr = R  ]
hkcmd.exe -> %SystemRoot%\System32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 126976 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
hticons.dll -> %SystemRoot%\System32\hticons.dll -> Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Created Date = 1/8/2008 5:06:29 PM | Attr =	]
hypertrm.dll -> %SystemRoot%\System32\hypertrm.dll -> Hilgraeve, Inc. [Ver = 5.1.2600.2563 | Size = 347136 bytes | Created Date = 1/8/2008 5:06:06 PM | Attr =	]
iAlmCoIn_v4342.dll -> %SystemRoot%\System32\iAlmCoIn_v4342.dll -> Intel Corporation [Ver = 1.00.1000.1 | Size = 61440 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmdd5.dll -> %SystemRoot%\System32\ialmdd5.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 879228 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmdev5.dll -> %SystemRoot%\System32\ialmdev5.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 178844 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmdnt5.dll -> %SystemRoot%\System32\ialmdnt5.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 108157 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmgdev.dll -> %SystemRoot%\System32\ialmgdev.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 516096 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmgicd.dll -> %SystemRoot%\System32\ialmgicd.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 2289664 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmrem.dll -> %SystemRoot%\System32\ialmrem.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 49152 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ialmrnt5.dll -> %SystemRoot%\System32\ialmrnt5.dll -> Intel Corporation [Ver = 6.14.10.4342 | Size = 38016 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
ias -> %SystemRoot%\System32\ias ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
icsxml -> %SystemRoot%\System32\icsxml ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
ideograf.uce -> %SystemRoot%\System32\ideograf.uce ->  [Ver =  | Size = 60458 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> S!Ri.URZ [Ver =  | Size = 82432 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
igfxcfg.exe -> %SystemRoot%\System32\igfxcfg.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 503808 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxcpl.cpl -> %SystemRoot%\System32\igfxcpl.cpl -> Intel Corporation [Ver = 3.0.0.4342 | Size = 94208 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxdev.dll -> %SystemRoot%\System32\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 139264 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxdgps.dll -> %SystemRoot%\System32\igfxdgps.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 45056 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxdiag.exe -> %SystemRoot%\System32\igfxdiag.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 151552 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxdo.dll -> %SystemRoot%\System32\igfxdo.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 86016 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxeud.dll -> %SystemRoot%\System32\igfxeud.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 225280 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxexps.dll -> %SystemRoot%\System32\igfxexps.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 36864 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxext.exe -> %SystemRoot%\System32\igfxext.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 106496 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhchs.lhp -> %SystemRoot%\System32\igfxhchs.lhp ->  [Ver =  | Size = 58430 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhcht.lhp -> %SystemRoot%\System32\igfxhcht.lhp ->  [Ver =  | Size = 59354 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhdeu.lhp -> %SystemRoot%\System32\igfxhdeu.lhp ->  [Ver =  | Size = 62339 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhenu.lhp -> %SystemRoot%\System32\igfxhenu.lhp ->  [Ver =  | Size = 57801 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhesp.lhp -> %SystemRoot%\System32\igfxhesp.lhp ->  [Ver =  | Size = 60786 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhfra.lhp -> %SystemRoot%\System32\igfxhfra.lhp ->  [Ver =  | Size = 62454 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhita.lhp -> %SystemRoot%\System32\igfxhita.lhp ->  [Ver =  | Size = 59687 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhjpn.lhp -> %SystemRoot%\System32\igfxhjpn.lhp ->  [Ver =  | Size = 62578 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhk.dll -> %SystemRoot%\System32\igfxhk.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 126976 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhkor.lhp -> %SystemRoot%\System32\igfxhkor.lhp ->  [Ver =  | Size = 66013 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhptb.lhp -> %SystemRoot%\System32\igfxhptb.lhp ->  [Ver =  | Size = 61839 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxhtha.lhp -> %SystemRoot%\System32\igfxhtha.lhp ->  [Ver =  | Size = 62836 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxpph.dll -> %SystemRoot%\System32\igfxpph.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 225280 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrchs.lrc -> %SystemRoot%\System32\igfxrchs.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 143360 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrcht.lrc -> %SystemRoot%\System32\igfxrcht.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 143360 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrdeu.lrc -> %SystemRoot%\System32\igfxrdeu.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 167936 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrenu.lrc -> %SystemRoot%\System32\igfxrenu.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 163840 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxres.dll -> %SystemRoot%\System32\igfxres.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 163840 bytes | Created Date = 1/8/2008 5:41:55 PM | Attr =	]
igfxresp.lrc -> %SystemRoot%\System32\igfxresp.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 172032 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxress.dll -> %SystemRoot%\System32\igfxress.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 1245184 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrfra.lrc -> %SystemRoot%\System32\igfxrfra.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 167936 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrita.lrc -> %SystemRoot%\System32\igfxrita.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 167936 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrjpn.lrc -> %SystemRoot%\System32\igfxrjpn.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 151552 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrkor.lrc -> %SystemRoot%\System32\igfxrkor.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 147456 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrptb.lrc -> %SystemRoot%\System32\igfxrptb.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 167936 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxrtha.lrc -> %SystemRoot%\System32\igfxrtha.lrc -> Intel Corporation [Ver = 3.0.0.4342 | Size = 163840 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxsrvc.dll -> %SystemRoot%\System32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 348160 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxtray.exe -> %SystemRoot%\System32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 155648 bytes | Created Date = 1/8/2008 5:34:53 PM | Attr =	]
igfxzoom.exe -> %SystemRoot%\System32\igfxzoom.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 114688 bytes | Created Date = 1/8/2008 5:34:54 PM | Attr =	]
IME -> %SystemRoot%\System32\IME ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
inetsrv -> %SystemRoot%\System32\inetsrv ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
instlsp.exe -> %SystemRoot%\System32\instlsp.exe ->  [Ver =  | Size = 32768 bytes | Created Date = 1/8/2008 6:32:27 PM | Attr =	]
isrdbg32.dll -> %SystemRoot%\System32\isrdbg32.dll -> Intel Corporation [Ver = 0.0 | Size = 32768 bytes | Created Date = 1/8/2008 5:07:43 PM | Attr =	]
kanji_1.uce -> %SystemRoot%\System32\kanji_1.uce ->  [Ver =  | Size = 6948 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
kanji_2.uce -> %SystemRoot%\System32\kanji_2.uce ->  [Ver =  | Size = 8484 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
korean.uce -> %SystemRoot%\System32\korean.uce ->  [Ver =  | Size = 12876 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
LogFiles -> %SystemRoot%\System32\LogFiles ->  [Folder | Created Date = 1/8/2008 6:14:27 PM | Attr =	]
logonui.exe.manifest -> %SystemRoot%\System32\logonui.exe.manifest ->  [Ver =  | Size = 488 bytes | Created Date = 1/8/2008 5:08:54 PM | Attr = RH ]
Macromed -> %SystemRoot%\System32\Macromed ->  [Folder | Created Date = 1/8/2008 5:07:56 PM | Attr =	]
mcgdmgr.dll -> %SystemRoot%\System32\mcgdmgr.dll -> Networks Associates Technology, Inc [Ver = 1, 0, 0, 16 | Size = 270336 bytes | Created Date = 1/8/2008 6:19:35 PM | Attr =	]
mcinsctl.dll -> %SystemRoot%\System32\mcinsctl.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 0, 74 | Size = 348160 bytes | Created Date = 1/8/2008 6:19:35 PM | Attr =	]
mclsp.dll -> %SystemRoot%\System32\mclsp.dll -> Networks Associates Technology, Inc [Ver = 4, 0, 1, 20 | Size = 114688 bytes | Created Date = 1/8/2008 6:32:28 PM | Attr =	]
mclsphlr -> %SystemRoot%\System32\mclsphlr ->  [Folder | Created Date = 1/8/2008 6:32:28 PM | Attr =	]
mcrtl32.dll -> %SystemRoot%\System32\mcrtl32.dll ->  [Ver =  | Size = 65536 bytes | Created Date = 1/8/2008 6:32:27 PM | Attr =	]
Microsoft -> %SystemRoot%\System32\Microsoft ->  [Folder | Created Date = 1/8/2008 5:14:22 PM | Attr =   S]
MpfApi.dll -> %SystemRoot%\System32\MpfApi.dll ->  [Ver =  | Size = 20480 bytes | Created Date = 1/8/2008 6:30:45 PM | Attr =	]
MsDtc -> %SystemRoot%\System32\MsDtc ->  [Folder | Created Date = 1/8/2008 5:06:04 PM | Attr =	]
msdtcprf.h -> %SystemRoot%\System32\msdtcprf.h ->  [Ver =  | Size = 768 bytes | Created Date = 1/8/2008 5:06:21 PM | Attr =	]
msdtcprf.ini -> %SystemRoot%\System32\msdtcprf.ini ->  [Ver =  | Size = 1931 bytes | Created Date = 1/8/2008 5:06:21 PM | Attr =	]
mui -> %SystemRoot%\System32\mui ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
ncpa.cpl.manifest -> %SystemRoot%\System32\ncpa.cpl.manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
npp -> %SystemRoot%\System32\npp ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
nscompat.tlb -> %SystemRoot%\System32\nscompat.tlb ->  [Ver =  | Size = 23392 bytes | Created Date = 1/8/2008 5:10:06 PM | Attr =	]
nwc.cpl.manifest -> %SystemRoot%\System32\nwc.cpl.manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
Odbcjet.cnt -> %SystemRoot%\System32\Odbcjet.cnt ->  [Ver =  | Size = 7348 bytes | Created Date = 1/8/2008 5:56:05 PM | Attr =	]
Odbcjet.hlp -> %SystemRoot%\System32\Odbcjet.hlp ->  [Ver =  | Size = 171967 bytes | Created Date = 1/8/2008 5:56:05 PM | Attr =	]
oobe -> %SystemRoot%\System32\oobe ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
P16X.dll -> %SystemRoot%\System32\P16X.dll ->  [Ver = 1.0.0.15 | Size = 47616 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
P16X.ini -> %SystemRoot%\System32\P16X.ini ->  [Ver =  | Size = 2516 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
P16Xres.dll -> %SystemRoot%\System32\P16Xres.dll -> Creative Technology Ltd. [Ver = 5.12.0104 | Size = 34304 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 356302 bytes | Created Date = 1/8/2008 9:01:49 AM | Attr =	]
PFMODNT.SYS -> %SystemRoot%\System32\PFMODNT.SYS -> Creative Technology Ltd. [Ver = 2.0.0.0 | Size = 6752 bytes | Created Date = 1/8/2008 5:39:36 PM | Attr =	]
pool.bin -> %SystemRoot%\System32\pool.bin ->  [Ver =  | Size = 256 bytes | Created Date = 1/22/2008 10:15:03 AM | Attr =	]
PreInstall -> %SystemRoot%\System32\PreInstall ->  [Folder | Created Date = 1/8/2008 5:53:43 PM | Attr =	]
Process.exe -> %SystemRoot%\System32\Process.exe -> http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4 | Size = 57344 bytes | Created Date = 1/10/2008 4:27:44 PM | Attr =	]
QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4 | Size = 90112 bytes | Created Date = 1/10/2008 4:27:46 PM | Attr =	]
ras -> %SystemRoot%\System32\ras ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
RcdScan.dll -> %SystemRoot%\System32\RcdScan.dll -> Dell Computer Corporation [Ver = 1.20.00.00 | Size = 176128 bytes | Created Date = 1/8/2008 5:56:06 PM | Attr =	]
ReinstallBackups -> %SystemRoot%\System32\ReinstallBackups ->  [Folder | Created Date = 1/8/2008 5:30:16 PM | Attr =	]
Restore -> %SystemRoot%\System32\Restore ->  [Folder | Created Date = 1/8/2008 5:07:43 PM | Attr =	]
sapi.cpl.manifest -> %SystemRoot%\System32\sapi.cpl.manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
Setup -> %SystemRoot%\System32\Setup ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
sfman32.dll -> %SystemRoot%\System32\sfman32.dll -> Creative Technology Ltd [Ver = 5.12.01.0130-1.00.0000 | Size = 36864 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
sfms32.dll -> %SystemRoot%\System32\sfms32.dll -> Creative Technology Ltd [Ver = 5.12.01.0172-0.75.1810 (beta-release) | Size = 172032 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
ShellExt -> %SystemRoot%\System32\ShellExt ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
shiftjis.uce -> %SystemRoot%\System32\shiftjis.uce ->  [Ver =  | Size = 16740 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
SoftwareDistribution -> %SystemRoot%\System32\SoftwareDistribution ->  [Folder | Created Date = 1/8/2008 5:47:37 PM | Attr =	]
spool -> %SystemRoot%\System32\spool ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
spxcoins.dll -> %SystemRoot%\System32\spxcoins.dll -> Perle Systems Ltd. [Ver = 1.0.0.0007 | Size = 24661 bytes | Created Date = 1/8/2008 9:01:35 AM | Attr =	]
SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> S!Ri [Ver =  | Size = 288417 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
ssa3d30.ocx -> %SystemRoot%\System32\ssa3d30.ocx -> Sheridan Software Systems, Inc. [Ver = 3.00.0034 | Size = 328480 bytes | Created Date = 1/8/2008 5:56:06 PM | Attr =	]
Status.MPF -> %SystemRoot%\System32\Status.MPF ->  [Ver =  | Size = 37152 bytes | Created Date = 1/9/2008 4:25:19 AM | Attr =	]
subrange.uce -> %SystemRoot%\System32\subrange.uce ->  [Ver =  | Size = 93702 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
swreg.exe -> %SystemRoot%\System32\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
swsc.exe -> %SystemRoot%\System32\swsc.exe ->  [Ver =  | Size = 40960 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
tmp.reg -> %SystemRoot%\System32\tmp.reg ->  [Ver =  | Size = 3438 bytes | Created Date = 3/18/2008 10:57:33 AM | Attr =	]
tslabels.h -> %SystemRoot%\System32\tslabels.h ->  [Ver =  | Size = 3286 bytes | Created Date = 1/8/2008 5:06:22 PM | Attr =	]
tslabels.ini -> %SystemRoot%\System32\tslabels.ini ->  [Ver =  | Size = 13223 bytes | Created Date = 1/8/2008 5:06:22 PM | Attr =	]
usmt -> %SystemRoot%\System32\usmt ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
usrlogon.cmd -> %SystemRoot%\System32\usrlogon.cmd ->  [Ver =  | Size = 1161 bytes | Created Date = 1/8/2008 5:06:22 PM | Attr =	]
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> S!Ri.URZ [Ver =  | Size = 86528 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> S!Ri [Ver =  | Size = 289144 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
wbem -> %SystemRoot%\System32\wbem ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
WindowsLogon.manifest -> %SystemRoot%\System32\WindowsLogon.manifest ->  [Ver =  | Size = 488 bytes | Created Date = 1/8/2008 5:08:54 PM | Attr = RH ]
wins -> %SystemRoot%\System32\wins ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
wmimgmt.msc -> %SystemRoot%\System32\wmimgmt.msc ->  [Ver =  | Size = 63488 bytes | Created Date = 1/8/2008 5:06:16 PM | Attr =	]
WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe ->  [Ver =  | Size = 25600 bytes | Created Date = 3/18/2008 10:56:01 AM | Attr =	]
wuaucpl.cpl.manifest -> %SystemRoot%\System32\wuaucpl.cpl.manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
xircom -> %SystemRoot%\System32\xircom ->  [Folder | Created Date = 1/8/2008 5:10:59 PM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Created Date = 1/8/2008 5:10:33 PM | Attr =  H ]
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ ->  [Folder | Created Date = 1/8/2008 5:53:25 PM | Attr =  H ]
$NtServicePackUninstallIDNMitigationAPIs$ -> %SystemRoot%\$NtServicePackUninstallIDNMitigationAPIs$ ->  [Folder | Created Date = 1/12/2008 3:27:45 PM | Attr =  H ]
$NtServicePackUninstallNLSDownlevelMapping$ -> %SystemRoot%\$NtServicePackUninstallNLSDownlevelMapping$ ->  [Folder | Created Date = 1/12/2008 3:27:24 PM | Attr =  H ]
addins -> %SystemRoot%\addins ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
AppPatch -> %SystemRoot%\AppPatch ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Blue Lace 16.bmp -> %SystemRoot%\Blue Lace 16.bmp ->  [Ver =  | Size = 1272 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
bootstat.dat -> %SystemRoot%\bootstat.dat ->  [Ver =  | Size = 2048 bytes | Created Date = 1/8/2008 5:13:24 PM | Attr =   S]
Coffee Bean.bmp -> %SystemRoot%\Coffee Bean.bmp ->  [Ver =  | Size = 17062 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
Config -> %SystemRoot%\Config ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Connection Wizard -> %SystemRoot%\Connection Wizard ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
control.ini -> %SystemRoot%\control.ini ->  [Ver =  | Size = 0 bytes | Created Date = 1/8/2008 5:10:21 PM | Attr =	]
Cursors -> %SystemRoot%\Cursors ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Debug -> %SystemRoot%\Debug ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
dell -> %SystemRoot%\dell ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
desktop.ini -> %SystemRoot%\desktop.ini ->  [Ver =  | Size = 2 bytes | Created Date = 1/8/2008 5:08:09 PM | Attr =	]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Created Date = 1/8/2008 5:08:54 PM | Attr =   S]
Driver Cache -> %SystemRoot%\Driver Cache ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
ehome -> %SystemRoot%\ehome ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
FeatherTexture.bmp -> %SystemRoot%\FeatherTexture.bmp ->  [Ver =  | Size = 16730 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
Fonts -> %SystemRoot%\Fonts ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr = R S]
ftpcache -> %SystemRoot%\ftpcache ->  [Folder | Created Date = 1/16/2008 4:40:59 PM | Attr =  HS]
Gone Fishing.bmp -> %SystemRoot%\Gone Fishing.bmp ->  [Ver =  | Size = 17336 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
Greenstone.bmp -> %SystemRoot%\Greenstone.bmp ->  [Ver =  | Size = 26582 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
Help -> %SystemRoot%\Help ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
ie7 -> %SystemRoot%\ie7 ->  [Folder | Created Date = 1/12/2008 3:28:05 PM | Attr =  H ]
ie7updates -> %SystemRoot%\ie7updates ->  [Folder | Created Date = 1/12/2008 3:29:59 PM | Attr =	]
ime -> %SystemRoot%\ime ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
imsins.BAK -> %SystemRoot%\imsins.BAK ->  [Ver =  | Size = 1374 bytes | Created Date = 1/8/2008 9:01:52 AM | Attr =	]
inf -> %SystemRoot%\inf ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =  H ]
INRES.DLL -> %SystemRoot%\INRES.DLL -> Creative Technology Ltd [Ver = 1, 0, 2, 0 | Size = 20480 bytes | Created Date = 1/8/2008 5:40:21 PM | Attr =	]
Installer -> %SystemRoot%\Installer ->  [Folder | Created Date = 1/8/2008 9:01:49 AM | Attr =  HS]
java -> %SystemRoot%\java ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Live.bmp -> %SystemRoot%\Live.bmp ->  [Ver =  | Size = 3126 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
Live.ico -> %SystemRoot%\Live.ico ->  [Ver =  | Size = 4398 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
Media -> %SystemRoot%\Media ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
MIDIDEF.EXE -> %SystemRoot%\MIDIDEF.EXE -> Creative Technology Ltd [Ver = 2, 8, 3, 0 | Size = 61440 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
MIXDEF.INI -> %SystemRoot%\MIXDEF.INI ->  [Ver =  | Size = 2696 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
MIXERDEF.EXE -> %SystemRoot%\MIXERDEF.EXE -> Creative Technology Ltd [Ver = 1, 0, 0, 7 | Size = 24576 bytes | Created Date = 1/8/2008 5:40:20 PM | Attr =	]
msagent -> %SystemRoot%\msagent ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
msapps -> %SystemRoot%\msapps ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
mui -> %SystemRoot%\mui ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
network diagnostic -> %SystemRoot%\network diagnostic ->  [Folder | Created Date = 1/12/2008 3:25:50 PM | Attr =	]
nsreg.dat -> %SystemRoot%\nsreg.dat ->  [Ver =  | Size = 0 bytes | Created Date = 2/7/2008 7:55:13 PM | Attr =	]
ODBC.INI -> %SystemRoot%\ODBC.INI ->  [Ver =  | Size = 376 bytes | Created Date = 1/25/2008 10:07:26 AM | Attr =	]
ODBCINST.INI -> %SystemRoot%\ODBCINST.INI ->  [Ver =  | Size = 4161 bytes | Created Date = 1/8/2008 9:01:48 AM | Attr =	]
Offline Web Pages -> %SystemRoot%\Offline Web Pages ->  [Folder | Created Date = 1/8/2008 5:08:55 PM | Attr = R  ]
pchealth -> %SystemRoot%\pchealth ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
PeerNet -> %SystemRoot%\PeerNet ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Prairie Wind.bmp -> %SystemRoot%\Prairie Wind.bmp ->  [Ver =  | Size = 65954 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Created Date = 1/8/2008 5:14:22 PM | Attr =	]
Provisioning -> %SystemRoot%\Provisioning ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
pss -> %SystemRoot%\pss ->  [Folder | Created Date = 2/12/2008 7:05:23 PM | Attr =	]
QTFont.for -> %SystemRoot%\QTFont.for ->  [Ver =  | Size = 1409 bytes | Created Date = 1/10/2008 7:04:08 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Created Date = 1/10/2008 7:04:08 PM | Attr =  H ]
Registration -> %SystemRoot%\Registration ->  [Folder | Created Date = 1/8/2008 5:06:52 PM | Attr =	]
REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD ->  [Ver =  | Size = 8192 bytes | Created Date = 1/8/2008 5:14:10 PM | Attr =	]
repair -> %SystemRoot%\repair ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Resources -> %SystemRoot%\Resources ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Rhododendron.bmp -> %SystemRoot%\Rhododendron.bmp ->  [Ver =  | Size = 17362 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
River Sumida.bmp -> %SystemRoot%\River Sumida.bmp ->  [Ver =  | Size = 26680 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
Santa Fe Stucco.bmp -> %SystemRoot%\Santa Fe Stucco.bmp ->  [Ver =  | Size = 65832 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
SBWIN.INI -> %SystemRoot%\SBWIN.INI ->  [Ver =  | Size = 66 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
security -> %SystemRoot%\security ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
ShellNew -> %SystemRoot%\ShellNew ->  [Folder | Created Date = 1/25/2008 10:05:15 AM | Attr =	]
Soap Bubbles.bmp -> %SystemRoot%\Soap Bubbles.bmp ->  [Ver =  | Size = 65978 bytes | Created Date = 1/8/2008 5:06:24 PM | Attr =	]
SoftwareDistribution -> %SystemRoot%\SoftwareDistribution ->  [Folder | Created Date = 1/8/2008 5:14:24 PM | Attr =	]
srchasst -> %SystemRoot%\srchasst ->  [Folder | Created Date = 1/8/2008 5:07:57 PM | Attr =	]
system -> %SystemRoot%\system ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
system32 -> %SystemRoot%\system32 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Tasks -> %SystemRoot%\Tasks ->  [Folder | Created Date = 1/8/2008 5:08:00 PM | Attr =   S]
Temp -> %SystemRoot%\Temp ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
twain_32 -> %SystemRoot%\twain_32 ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
Updreg.EXE -> %SystemRoot%\Updreg.EXE -> Creative Technology Ltd. [Ver = 1.0.2 | Size = 90112 bytes | Created Date = 1/8/2008 5:40:48 PM | Attr =	]
vb.ini -> %SystemRoot%\vb.ini ->  [Ver =  | Size = 36 bytes | Created Date = 1/8/2008 5:06:56 PM | Attr =	]
vbaddin.ini -> %SystemRoot%\vbaddin.ini ->  [Ver =  | Size = 37 bytes | Created Date = 1/8/2008 5:06:56 PM | Attr =	]
WBEM -> %SystemRoot%\WBEM ->  [Folder | Created Date = 1/12/2008 3:29:13 PM | Attr =	]
Web -> %SystemRoot%\Web ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr = R  ]
WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest ->  [Ver =  | Size = 749 bytes | Created Date = 1/8/2008 5:08:48 PM | Attr = RH ]
winnt.bmp -> %SystemRoot%\winnt.bmp ->  [Ver =  | Size = 48680 bytes | Created Date = 1/8/2008 5:08:09 PM | Attr =  HS]
winnt256.bmp -> %SystemRoot%\winnt256.bmp ->  [Ver =  | Size = 48680 bytes | Created Date = 1/8/2008 5:08:09 PM | Attr =  HS]
WinSxS -> %SystemRoot%\WinSxS ->  [Folder | Created Date = 1/8/2008 8:54:22 AM | Attr =	]
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx ->  [Ver =  | Size = 316640 bytes | Created Date = 1/8/2008 5:10:05 PM | Attr =	]
Zapotec.bmp -> %SystemRoot%\Zapotec.bmp ->  [Ver =  | Size = 9522 bytes | Created Date = 1/8/2008 5:06:25 PM | Attr =	]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Created Date = 1/10/2008 7:03:00 PM | Attr =	]
desktop.ini -> %SystemRoot%\tasks\desktop.ini ->  [Ver =  | Size = 65 bytes | Created Date = 1/8/2008 5:08:00 PM | Attr = RH ]
McAfee.com Update Check (BRAD-12F3CC08EB-Administrator).job -> %SystemRoot%\tasks\McAfee.com Update Check (BRAD-12F3CC08EB-Administrator).job ->  [Ver =  | Size = 510 bytes | Created Date = 1/8/2008 6:20:27 PM | Attr =	]
MP Scheduled Scan.job -> %SystemRoot%\tasks\MP Scheduled Scan.job ->  [Ver =  | Size = 330 bytes | Created Date = 2/9/2008 10:08:58 PM | Attr =  H ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Created Date = 1/8/2008 5:14:22 PM | Attr =  H ]

[Files/Folders - Modified Within 90 days]
AUTOEXEC.BAT -> %SystemDrive%\AUTOEXEC.BAT ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr =	]
boot.ini -> %SystemDrive%\boot.ini ->  [Ver =  | Size = 211 bytes | Modified Date = 2/12/2008 7:18:18 PM | Attr =  HS]
CONFIG.SYS -> %SystemDrive%\CONFIG.SYS ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr =	]
DELL -> %SystemDrive%\DELL ->  [Folder | Modified Date = 1/8/2008 5:29:47 PM | Attr =	]
Documents and Settings -> %SystemDrive%\Documents and Settings ->  [Folder | Modified Date = 1/8/2008 5:14:46 PM | Attr =	]
Drivers -> %SystemDrive%\Drivers ->  [Folder | Modified Date = 1/8/2008 5:34:52 PM | Attr =	]
IO.SYS -> %SystemDrive%\IO.SYS ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr = RHS]
MSDOS.SYS -> %SystemDrive%\MSDOS.SYS ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr = RHS]
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 3/19/2008 3:58:02 PM | Attr = R  ]
RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Modified Date = 1/10/2008 6:06:22 PM | Attr =  HS]
System Volume Information -> %SystemDrive%\System Volume Information ->  [Folder | Modified Date = 1/8/2008 5:14:24 PM | Attr =  HS]
tmp.bat -> %SystemDrive%\tmp.bat ->  [Ver =  | Size = 51 bytes | Modified Date = 2/9/2008 2:00:28 AM | Attr =	]
WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 3/18/2008 4:46:29 PM | Attr =	]
disdn -> %SystemRoot%\System32\drivers\disdn ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
etc -> %SystemRoot%\System32\drivers\etc ->  [Folder | Modified Date = 2/9/2008 3:32:16 PM | Attr =	]
hosts -> %SystemRoot%\System32\drivers\etc\hosts ->  [Ver =  | Size = 698 bytes | Modified Date = 3/23/2008 12:06:12 PM | Attr = R  ]
UMDF -> %SystemRoot%\System32\drivers\UMDF ->  [Folder | Modified Date = 1/8/2008 6:14:53 PM | Attr =	]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 6:14:30 PM | Attr =  H ]
$winnt$.inf -> %SystemRoot%\System32\$winnt$.inf ->  [Ver =  | Size = 261 bytes | Modified Date = 1/8/2008 5:13:30 PM | Attr =	]
1025 -> %SystemRoot%\System32\1025 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1028 -> %SystemRoot%\System32\1028 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
1031 -> %SystemRoot%\System32\1031 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
1033 -> %SystemRoot%\System32\1033 ->  [Folder | Modified Date = 1/8/2008 8:55:18 AM | Attr =	]
1037 -> %SystemRoot%\System32\1037 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
1041 -> %SystemRoot%\System32\1041 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
1042 -> %SystemRoot%\System32\1042 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
1054 -> %SystemRoot%\System32\1054 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
2052 -> %SystemRoot%\System32\2052 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
3076 -> %SystemRoot%\System32\3076 ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
3com_dmi -> %SystemRoot%\System32\3com_dmi ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
amcompat.tlb -> %SystemRoot%\System32\amcompat.tlb ->  [Ver =  | Size = 16832 bytes | Modified Date = 1/8/2008 6:29:01 PM | Attr =	]
CatRoot -> %SystemRoot%\System32\CatRoot ->  [Folder | Modified Date = 1/12/2008 3:26:40 PM | Attr =	]
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 3/18/2008 3:38:18 PM | Attr =	]
cdplayer.exe.manifest -> %SystemRoot%\System32\cdplayer.exe.manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
Com -> %SystemRoot%\System32\Com ->  [Folder | Modified Date = 1/9/2008 4:08:48 AM | Attr =	]
config -> %SystemRoot%\System32\config ->  [Folder | Modified Date = 1/12/2008 3:29:17 PM | Attr =	]
CONFIG.NT -> %SystemRoot%\System32\CONFIG.NT ->  [Ver =  | Size = 2577 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr =	]
Data -> %SystemRoot%\System32\Data ->  [Folder | Modified Date = 1/8/2008 5:40:21 PM | Attr =	]
dhcp -> %SystemRoot%\System32\dhcp ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
DirectX -> %SystemRoot%\System32\DirectX ->  [Folder | Modified Date = 1/8/2008 5:08:26 PM | Attr =	]
dllcache -> %SystemRoot%\System32\dllcache ->  [Folder | Modified Date = 2/13/2008 4:02:16 AM | Attr = RHS]
drivers -> %SystemRoot%\System32\drivers ->  [Folder | Modified Date = 3/23/2008 11:40:18 AM | Attr =	]
DRVSTORE -> %SystemRoot%\System32\DRVSTORE ->  [Folder | Modified Date = 1/10/2008 7:02:48 PM | Attr =	]
emptyregdb.dat -> %SystemRoot%\System32\emptyregdb.dat ->  [Ver =  | Size = 21640 bytes | Modified Date = 1/8/2008 5:07:07 PM | Attr =	]
en-US -> %SystemRoot%\System32\en-US ->  [Folder | Modified Date = 1/12/2008 3:30:09 PM | Attr =	]
export -> %SystemRoot%\System32\export ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT ->  [Ver =  | Size = 283720 bytes | Modified Date = 2/9/2008 2:12:37 AM | Attr =	]
ias -> %SystemRoot%\System32\ias ->  [Folder | Modified Date = 1/8/2008 5:09:39 PM | Attr =	]
icsxml -> %SystemRoot%\System32\icsxml ->  [Folder | Modified Date = 1/8/2008 8:55:45 AM | Attr =	]
IEDFix.exe -> %SystemRoot%\System32\IEDFix.exe -> S!Ri.URZ [Ver =  | Size = 82432 bytes | Modified Date = 3/15/2008 5:16:49 PM | Attr =	]
IME -> %SystemRoot%\System32\IME ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
inetsrv -> %SystemRoot%\System32\inetsrv ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
LogFiles -> %SystemRoot%\System32\LogFiles ->  [Folder | Modified Date = 1/8/2008 6:14:27 PM | Attr =	]
logonui.exe.manifest -> %SystemRoot%\System32\logonui.exe.manifest ->  [Ver =  | Size = 488 bytes | Modified Date = 1/8/2008 5:08:54 PM | Attr = RH ]
Macromed -> %SystemRoot%\System32\Macromed ->  [Folder | Modified Date = 1/8/2008 5:07:56 PM | Attr =	]
mclsphlr -> %SystemRoot%\System32\mclsphlr ->  [Folder | Modified Date = 1/9/2008 4:25:19 AM | Attr =	]
Microsoft -> %SystemRoot%\System32\Microsoft ->  [Folder | Modified Date = 1/8/2008 5:14:22 PM | Attr =   S]
MsDtc -> %SystemRoot%\System32\MsDtc ->  [Folder | Modified Date = 1/8/2008 5:06:50 PM | Attr =	]
mui -> %SystemRoot%\System32\mui ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
ncpa.cpl.manifest -> %SystemRoot%\System32\ncpa.cpl.manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
npp -> %SystemRoot%\System32\npp ->  [Folder | Modified Date = 1/8/2008 8:59:13 AM | Attr =	]
nscompat.tlb -> %SystemRoot%\System32\nscompat.tlb ->  [Ver =  | Size = 23392 bytes | Modified Date = 1/8/2008 6:29:01 PM | Attr =	]
nwc.cpl.manifest -> %SystemRoot%\System32\nwc.cpl.manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
oobe -> %SystemRoot%\System32\oobe ->  [Folder | Modified Date = 1/8/2008 5:08:19 PM | Attr =	]
perfc009.dat -> %SystemRoot%\System32\perfc009.dat ->  [Ver =  | Size = 39992 bytes | Modified Date = 3/12/2008 3:19:26 PM | Attr =	]
perfh009.dat -> %SystemRoot%\System32\perfh009.dat ->  [Ver =  | Size = 311604 bytes | Modified Date = 3/12/2008 3:19:26 PM | Attr =	]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 356302 bytes | Modified Date = 3/12/2008 3:19:26 PM | Attr =	]
pool.bin -> %SystemRoot%\System32\pool.bin ->  [Ver =  | Size = 256 bytes | Modified Date = 2/8/2008 12:44:15 AM | Attr =	]
PreInstall -> %SystemRoot%\System32\PreInstall ->  [Folder | Modified Date = 1/8/2008 5:53:43 PM | Attr =	]
QuickTime.qts -> %SystemRoot%\System32\QuickTime.qts -> Apple Inc. [Ver = 7.4 | Size = 57344 bytes | Modified Date = 1/10/2008 4:27:44 PM | Attr =	]
QuickTimeVR.qtx -> %SystemRoot%\System32\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.4 | Size = 90112 bytes | Modified Date = 1/10/2008 4:27:46 PM | Attr =	]
ras -> %SystemRoot%\System32\ras ->  [Folder | Modified Date = 1/8/2008 8:56:10 AM | Attr =	]
ReinstallBackups -> %SystemRoot%\System32\ReinstallBackups ->  [Folder | Modified Date = 1/22/2008 10:05:17 AM | Attr =	]
Restore -> %SystemRoot%\System32\Restore ->  [Folder | Modified Date = 1/8/2008 5:14:23 PM | Attr =	]
sapi.cpl.manifest -> %SystemRoot%\System32\sapi.cpl.manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
Setup -> %SystemRoot%\System32\Setup ->  [Folder | Modified Date = 1/8/2008 8:59:50 AM | Attr =	]
ShellExt -> %SystemRoot%\System32\ShellExt ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
SoftwareDistribution -> %SystemRoot%\System32\SoftwareDistribution ->  [Folder | Modified Date = 1/8/2008 5:47:37 PM | Attr =	]
spool -> %SystemRoot%\System32\spool ->  [Folder | Modified Date = 1/8/2008 5:05:32 PM | Attr =	]
Status.MPF -> %SystemRoot%\System32\Status.MPF ->  [Ver =  | Size = 37152 bytes | Modified Date = 3/23/2008 11:41:27 AM | Attr =	]
tmp.reg -> %SystemRoot%\System32\tmp.reg ->  [Ver =  | Size = 3438 bytes | Modified Date = 3/18/2008 10:57:34 AM | Attr =	]
usmt -> %SystemRoot%\System32\usmt ->  [Folder | Modified Date = 1/8/2008 8:59:43 AM | Attr =	]
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> S!Ri.URZ [Ver =  | Size = 86528 bytes | Modified Date = 3/14/2008 9:09:32 AM | Attr =	]
wbem -> %SystemRoot%\System32\wbem ->  [Folder | Modified Date = 1/8/2008 5:10:59 PM | Attr =	]
WindowsLogon.manifest -> %SystemRoot%\System32\WindowsLogon.manifest ->  [Ver =  | Size = 488 bytes | Modified Date = 1/8/2008 5:08:54 PM | Attr = RH ]
wins -> %SystemRoot%\System32\wins ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl ->  [Ver =  | Size = 2206 bytes | Modified Date = 3/2/2008 3:56:08 PM | Attr =	]
wuaucpl.cpl.manifest -> %SystemRoot%\System32\wuaucpl.cpl.manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
xircom -> %SystemRoot%\System32\xircom ->  [Folder | Modified Date = 1/8/2008 5:10:59 PM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Modified Date = 2/12/2008 4:30:02 PM | Attr =  H ]
5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
$MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ ->  [Folder | Modified Date = 1/8/2008 5:53:26 PM | Attr =  H ]
$NtServicePackUninstallIDNMitigationAPIs$ -> %SystemRoot%\$NtServicePackUninstallIDNMitigationAPIs$ ->  [Folder | Modified Date = 1/12/2008 3:27:45 PM | Attr =  H ]
$NtServicePackUninstallNLSDownlevelMapping$ -> %SystemRoot%\$NtServicePackUninstallNLSDownlevelMapping$ ->  [Folder | Modified Date = 1/12/2008 3:27:24 PM | Attr =  H ]
addins -> %SystemRoot%\addins ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
AppPatch -> %SystemRoot%\AppPatch ->  [Folder | Modified Date = 1/8/2008 6:27:27 PM | Attr =	]
bootstat.dat -> %SystemRoot%\bootstat.dat ->  [Ver =  | Size = 2048 bytes | Modified Date = 3/23/2008 11:38:53 AM | Attr =   S]
Config -> %SystemRoot%\Config ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
Connection Wizard -> %SystemRoot%\Connection Wizard ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
control.ini -> %SystemRoot%\control.ini ->  [Ver =  | Size = 0 bytes | Modified Date = 1/8/2008 5:10:21 PM | Attr =	]
Cursors -> %SystemRoot%\Cursors ->  [Folder | Modified Date = 1/8/2008 5:06:34 PM | Attr =	]
Debug -> %SystemRoot%\Debug ->  [Folder | Modified Date = 1/12/2008 3:26:15 PM | Attr =	]
dell -> %SystemRoot%\dell ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Modified Date = 2/17/2008 6:26:50 PM | Attr =   S]
Driver Cache -> %SystemRoot%\Driver Cache ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
ehome -> %SystemRoot%\ehome ->  [Folder | Modified Date = 1/8/2008 8:59:31 AM | Attr =	]
Fonts -> %SystemRoot%\Fonts ->  [Folder | Modified Date = 1/25/2008 10:05:20 AM | Attr = R S]
ftpcache -> %SystemRoot%\ftpcache ->  [Folder | Modified Date = 1/16/2008 4:40:59 PM | Attr =  HS]
Help -> %SystemRoot%\Help ->  [Folder | Modified Date = 2/20/2008 12:22:54 PM | Attr =	]
ie7 -> %SystemRoot%\ie7 ->  [Folder | Modified Date = 1/12/2008 3:28:53 PM | Attr =  H ]
ie7updates -> %SystemRoot%\ie7updates ->  [Folder | Modified Date = 1/13/2008 4:00:35 AM | Attr =	]
ime -> %SystemRoot%\ime ->  [Folder | Modified Date = 1/8/2008 5:10:59 PM | Attr =	]
imsins.BAK -> %SystemRoot%\imsins.BAK ->  [Ver =  | Size = 1374 bytes | Modified Date = 2/13/2008 4:02:05 AM | Attr =	]
inf -> %SystemRoot%\inf ->  [Folder | Modified Date = 3/7/2008 7:57:59 AM | Attr =  H ]
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 2/9/2008 10:05:58 PM | Attr =  HS]
java -> %SystemRoot%\java ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
Media -> %SystemRoot%\Media ->  [Folder | Modified Date = 1/12/2008 3:29:04 PM | Attr =	]
msagent -> %SystemRoot%\msagent ->  [Folder | Modified Date = 1/9/2008 4:25:20 AM | Attr =	]
msapps -> %SystemRoot%\msapps ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
mui -> %SystemRoot%\mui ->  [Folder | Modified Date = 1/8/2008 8:59:31 AM | Attr =	]
network diagnostic -> %SystemRoot%\network diagnostic ->  [Folder | Modified Date = 1/12/2008 3:25:50 PM | Attr =	]
nsreg.dat -> %SystemRoot%\nsreg.dat ->  [Ver =  | Size = 0 bytes | Modified Date = 2/7/2008 7:55:13 PM | Attr =	]
ODBC.INI -> %SystemRoot%\ODBC.INI ->  [Ver =  | Size = 376 bytes | Modified Date = 1/25/2008 10:07:26 AM | Attr =	]
ODBCINST.INI -> %SystemRoot%\ODBCINST.INI ->  [Ver =  | Size = 4161 bytes | Modified Date = 1/8/2008 5:09:55 PM | Attr =	]
Offline Web Pages -> %SystemRoot%\Offline Web Pages ->  [Folder | Modified Date = 1/8/2008 5:08:55 PM | Attr = R  ]
pchealth -> %SystemRoot%\pchealth ->  [Folder | Modified Date = 2/9/2008 10:05:48 PM | Attr =	]
PeerNet -> %SystemRoot%\PeerNet ->  [Folder | Modified Date = 1/8/2008 8:59:22 AM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 3/23/2008 12:12:19 PM | Attr =	]
Provisioning -> %SystemRoot%\Provisioning ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
pss -> %SystemRoot%\pss ->  [Folder | Modified Date = 2/12/2008 7:05:23 PM | Attr =	]
QTFont.for -> %SystemRoot%\QTFont.for ->  [Ver =  | Size = 1409 bytes | Modified Date = 1/10/2008 7:04:24 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 3/23/2008 11:39:12 AM | Attr =  H ]
Registration -> %SystemRoot%\Registration ->  [Folder | Modified Date = 1/8/2008 5:09:51 PM | Attr =	]
REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD ->  [Ver =  | Size = 8192 bytes | Modified Date = 1/8/2008 5:14:10 PM | Attr =	]
repair -> %SystemRoot%\repair ->  [Folder | Modified Date = 1/8/2008 5:10:59 PM | Attr =	]
Resources -> %SystemRoot%\Resources ->  [Folder | Modified Date = 1/8/2008 8:54:22 AM | Attr =	]
SBWIN.INI -> %SystemRoot%\SBWIN.INI ->  [Ver =  | Size = 66 bytes | Modified Date = 1/8/2008 5:40:57 PM | Attr =	]
security -> %SystemRoot%\security ->  [Folder | Modified Date = 1/8/2008 5:41:18 PM | Attr =	]
ShellNew -> %SystemRoot%\ShellNew ->  [Folder | Modified Date = 1/25/2008 10:06:12 AM | Attr =	]
SoftwareDistribution -> %SystemRoot%\SoftwareDistribution ->  [Folder | Modified Date = 1/8/2008 5:48:12 PM | Attr =	]
srchasst -> %SystemRoot%\srchasst ->  [Folder | Modified Date = 1/8/2008 5:08:33 PM | Attr =	]
system -> %SystemRoot%\system ->  [Folder | Modified Date = 1/25/2008 10:02:19 AM | Attr =	]
system.ini -> %SystemRoot%\system.ini ->  [Ver =  | Size = 227 bytes | Modified Date = 2/12/2008 7:18:18 PM | Attr =	]
system32 -> %SystemRoot%\system32 ->  [Folder | Modified Date = 3/19/2008 3:58:02 PM | Attr =	]
Tasks -> %SystemRoot%\Tasks ->  [Folder | Modified Date = 3/23/2008 11:50:01 AM | Attr =   S]
Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 3/23/2008 12:07:35 PM | Attr =	]
twain_32 -> %SystemRoot%\twain_32 ->  [Folder | Modified Date = 1/8/2008 6:04:34 PM | Attr =	]
vb.ini -> %SystemRoot%\vb.ini ->  [Ver =  | Size = 36 bytes | Modified Date = 1/8/2008 5:06:56 PM | Attr =	]
vbaddin.ini -> %SystemRoot%\vbaddin.ini ->  [Ver =  | Size = 37 bytes | Modified Date = 1/8/2008 5:06:56 PM | Attr =	]
WBEM -> %SystemRoot%\WBEM ->  [Folder | Modified Date = 1/12/2008 3:29:13 PM | Attr =	]
Web -> %SystemRoot%\Web ->  [Folder | Modified Date = 1/8/2008 5:08:57 PM | Attr = R  ]
win.ini -> %SystemRoot%\win.ini ->  [Ver =  | Size = 603 bytes | Modified Date = 2/12/2008 7:18:18 PM | Attr =	]
WindowsShell.Manifest -> %SystemRoot%\WindowsShell.Manifest ->  [Ver =  | Size = 749 bytes | Modified Date = 1/8/2008 5:08:48 PM | Attr = RH ]
WinSxS -> %SystemRoot%\WinSxS ->  [Folder | Modified Date = 2/9/2008 10:05:49 PM | Attr =	]
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx ->  [Ver =  | Size = 316640 bytes | Modified Date = 1/8/2008 6:14:56 PM | Attr =	]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Modified Date = 3/19/2008 11:56:04 AM | Attr =	]
McAfee.com Update Check (BRAD-12F3CC08EB-Administrator).job -> %SystemRoot%\tasks\McAfee.com Update Check (BRAD-12F3CC08EB-Administrator).job ->  [Ver =  | Size = 510 bytes | Modified Date = 3/23/2008 11:50:01 AM | Attr =	]
MP Scheduled Scan.job -> %SystemRoot%\tasks\MP Scheduled Scan.job ->  [Ver =  | Size = 330 bytes | Modified Date = 3/23/2008 11:42:05 AM | Attr =  H ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 3/23/2008 11:38:55 AM | Attr =  H ]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 4232 bytes | Modified Date = 3/21/2008 12:56:54 AM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 5454 bytes | Modified Date = 3/21/2008 12:56:54 AM | Attr =	]
data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat ->  [Ver =  | Size = 3804 bytes | Modified Date = 1/25/2008 10:10:15 AM | Attr =	]

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI