problem!! help!

Hello, I'm having a lot of problems with my computer. I ran the adaware scan and the spybot but i couldnt do the kaspersky scan or the panda scan. The problem I'm having is that I can't get into my email. Also, I can't search anything on google or any other search engines. There's also a pop up problem. Here is my HijackThis log.. any help would be gladly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:28 PM, on 9/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [{5edbf857-26da-2a2d-4ca3-519e74cf546d}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\offeojxjdbht.dll" DllStub
O4 - HKLM\..\Run: [BM1790d87a] Rundll32.exe "C:\WINDOWS\system32\fpgmvagx.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3308] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5275] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5719] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7974] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6393] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8275] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1655] command /c del "C:\WINDOWS\system32\fpgmvagx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9256] cmd /c del "C:\WINDOWS\system32\fpgmvagx.dll_old"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\E_S72.tmp" /EF "HKCU"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6767] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9034] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9783] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2128] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5941] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6654] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2572] command /c del "C:\WINDOWS\system32\fpgmvagx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6767] cmd /c del "C:\WINDOWS\system32\fpgmvagx.dll_old"
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

--
End of file - 4292 bytes

Comments

  • edited September 2008
    Hello and Welcome to the forums!

    My name is Carolyn and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens.

    Please do not run any other tool untill instructed to do so!
    Please reply to this thread, do not start another!
    Please tell me about any problems that have occurred during the fix.
    Please tell me of any other symptoms you may be having as these can help also.
    Please try as much as possible not to run anything while executing a fix.


    If you follow these instructions, everything should go smoothly.


    Your log indicates that Spybot Search & Destroy will delete some files when you reboot your computer. If you have not done so already, please reboot now.



    Download and Run ComboFix (by sUBs)

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper.


    We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    2. Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New HijackThis log.
  • edited October 2008
    Hello. Thanks for getting back to me. apparently my combofix log is too long to post on here. It's a pretty long list. Here is my HJT log though. Is there any other way to send you the Combofix log?

    HJT:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:27:38 PM, on 10/1/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HHVcdV7Sys\VC7SecS.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\Rundll32.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: bambanner browser enhancer - {a209a7c6-3e7c-8276-94d1-13daf7e173bd} - C:\WINDOWS\system32\offeojxjdbht.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O4 - HKLM\..\Run: [{5edbf857-26da-2a2d-4ca3-519e74cf546d}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\offeojxjdbht.dll" DllStub
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yaboik] "C:\Documents and Settings\Compaq_Owner\My Documents\A?pPatch\?xplorer.exe"
    O4 - HKCU\..\Run: [Mpnv] C:\WINDOWS\system32\?dobe\?hkdsk.exe
    O4 - HKCU\..\Run: [EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\E_S72.tmp" /EF "HKCU"
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O20 - AppInit_DLLs: waxkfq.dll
    O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

    --
    End of file - 3986 bytes
  • edited October 2008
    Hi,

    The best way to deal with really long logs is to copy and post it in sections using more than one reply. Please let me know if you need additional instruction on how to do so.
  • edited October 2008
    here is the combofix log in parts

    ComboFix 08-10-01.02 - Compaq_Owner 2008-10-01 17:11:25.3 - NTFSx86
    Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Compaq_Owner\My Documents\APPATC~1
    C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Outerinfo
    C:\Program Files\Common Files\fnts~1
    C:\Program Files\Common Files\fnts~1\F?nts\
    C:\Program Files\Common Files\stem32~1
    C:\Program Files\GetPack
    C:\Program Files\iCheck
    C:\Program Files\outerinfo
    C:\Program Files\VirusHeat 4.3
    C:\Temp\1cb
    C:\Temp\1cb\syscheck.log
    C:\temp\tn3
    C:\WINDOWS\b116.exe
    C:\WINDOWS\BM1790d87a.txt
    C:\WINDOWS\BM1790d87a.xml
    C:\WINDOWS\faceback.exe
    C:\WINDOWS\fnts~1
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\smante~1
    C:\WINDOWS\system32\375013
    C:\WINDOWS\system32\arniwfys.dll
    C:\WINDOWS\system32\aximqj.dll
    C:\WINDOWS\system32\baqfyt.dll
    C:\WINDOWS\system32\bdfonlhj.dll
    C:\WINDOWS\system32\binxpe.dll
    C:\WINDOWS\system32\bmjbjpur.dll
    C:\WINDOWS\system32\bnfrgd.dll
    C:\WINDOWS\system32\bvsvmhpc.dll
    C:\WINDOWS\system32\cbXOGXRk.dll
    C:\WINDOWS\system32\cgulvqte.dll
    C:\WINDOWS\system32\cgveoj.dll
    C:\WINDOWS\system32\cqnjgifa.dll
    C:\WINDOWS\system32\dobe~1
    C:\WINDOWS\system32\dobe~1\?hkdsk.exe
    C:\WINDOWS\system32\drivers\rasptii.sys
    C:\WINDOWS\system32\eabktwps.dll
    C:\WINDOWS\system32\eccydbrm.dll
    C:\WINDOWS\system32\efhtqfwm.ini
    C:\WINDOWS\system32\eqcxywpv.dll
    C:\WINDOWS\system32\eyymhodc.dll
    C:\WINDOWS\system32\FfhkQqss.ini
    C:\WINDOWS\system32\FfhkQqss.ini2
    C:\WINDOWS\system32\fhgftgjc.dll
    C:\WINDOWS\system32\fifpeuis.dll
    C:\WINDOWS\system32\foxlagsr.dll
    C:\WINDOWS\system32\gnpqrtbi.ini
    C:\WINDOWS\system32\grhiiflh.dll
    C:\WINDOWS\system32\hhbrlrbn.dll
    C:\WINDOWS\system32\hiyuxggi.dll
    C:\WINDOWS\system32\hlfiihrg.ini
    C:\WINDOWS\system32\hmotvnsj.dll
    C:\WINDOWS\system32\hravbfcr.dll
    C:\WINDOWS\system32\hxnhawln.dll
    C:\WINDOWS\system32\iggxuyih.ini
    C:\WINDOWS\system32\ihscynvh.dll
    C:\WINDOWS\system32\iifggdDV.dll
    C:\WINDOWS\system32\ijmwfgfy.dll
    C:\WINDOWS\system32\impybmwj.ini
    C:\WINDOWS\system32\iqmjhmmn.ini
    C:\WINDOWS\system32\iqntiscb.dll
    C:\WINDOWS\system32\ixpospuj.dll
    C:\WINDOWS\system32\iyvtor.dll
    C:\WINDOWS\system32\jbbgjv.dll
    C:\WINDOWS\system32\jbjffbun.ini
    C:\WINDOWS\system32\jikbnlln.dll
    C:\WINDOWS\system32\jtjticgl.dll
    C:\WINDOWS\system32\kjznep.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mlJBRHYS.dll
    C:\WINDOWS\system32\mpdvghjv.dll
    C:\WINDOWS\system32\MSINET.oca
    C:\WINDOWS\system32\nirwaaey.ini
    C:\WINDOWS\system32\nllnbkij.ini
    C:\WINDOWS\system32\nubffjbj.dll
    C:\WINDOWS\system32\nzhanz.dll
    C:\WINDOWS\system32\ogkfwtnq.dll
    C:\WINDOWS\system32\opnmLCvt.dll
    C:\WINDOWS\system32\oucqmg.dll
    C:\WINDOWS\system32\oWyayJjl.ini
    C:\WINDOWS\system32\pac.txt
    C:\WINDOWS\system32\qoMgHARH.dll
    C:\WINDOWS\system32\qskiqfgr.dll
    C:\WINDOWS\system32\rAJkSvut.ini
    C:\WINDOWS\system32\rgkyfa.dll
    C:\WINDOWS\system32\rqRKCuUM.dll
    C:\WINDOWS\system32\smbols~1
    C:\WINDOWS\system32\ssqQkhfF.dll
    C:\WINDOWS\system32\ufikdryp.ini
    C:\WINDOWS\system32\umxxthbk.dll
    C:\WINDOWS\system32\urqNeDvV.dll
    C:\WINDOWS\system32\vssjdutq.dll
    C:\WINDOWS\system32\vtUmLbyA.dll
    C:\WINDOWS\system32\VuDcdccf.ini
    C:\WINDOWS\system32\VvDeNqru.ini
    C:\WINDOWS\system32\waburq.dll
    C:\WINDOWS\system32\waxkfq.dll
    C:\WINDOWS\system32\wqphjbon.dll
    C:\WINDOWS\system32\wvUnNedC.dll
    C:\WINDOWS\system32\wxtsjnwa.dll
    C:\WINDOWS\system32\xemhbsrt.dll
    C:\WINDOWS\system32\xemwxymi.dll
    C:\WINDOWS\system32\xerhhijt.ini
    C:\WINDOWS\system32\xjeknqka.dll
    C:\WINDOWS\system32\xmlleh.dll
    C:\WINDOWS\system32\yfgfwmji.ini
    C:\WINDOWS\system32\yhhnac.dll
    C:\WINDOWS\system32\ylqmxcjh.dll
    C:\WINDOWS\system32\zlsmp.dll
    C:\Program Files\Common Files\fnts~1\nopdb.exe . . . . failed to delete

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Legacy_CMDSERVICE
    \Legacy_MCHINJDRV
    \Legacy_NETWORK_MONITOR
    \Legacy_RASPTII
    \Legacy_SVCPROC
    \Legacy_TNIDRIVER
    \Legacy_VIEWPOINT_MANAGER_SERVICE
    \Service_cmdService
    \Service_rasptii
    \Service_TnIDriver
    \Service_Viewpoint Manager Service


    ((((((((((((((((((((((((( Files Created from 2008-09-02 to 2008-10-02 )))))))))))))))))))))))))))))))
    .

    2008-10-01 17:47 . 2008-10-01 17:47 <DIR> d
    C:\WINDOWS\LastGood
    2008-09-27 12:23 . 2008-09-27 12:24 <DIR> d
    C:\Documents and Settings\All Users\Application Data\WinZip
    2008-09-23 22:36 . 2008-09-23 22:36 <DIR> d
    C:\Program Files\Panda Security
    2008-09-18 01:22 . 2008-09-18 01:22 <DIR> d
    C:\Program Files\TeaTimer (Spybot - Search & Destroy)
    2008-09-18 00:16 . 2008-09-18 00:16 <DIR> d
    C:\Program Files\OINAnalytics
    2008-09-17 00:22 . 2008-09-17 00:22 <DIR> d
    C:\Documents and Settings\LocalService\Application Data\Apple Computer
    2008-09-17 00:11 . 2008-09-17 00:11 <DIR> d
    C:\Program Files\Mjcore
    2008-09-17 00:08 . 2008-09-18 18:05 <DIR> d--hs---- C:\WINDOWS\TWFyaWEgUml2ZXJh
    2008-09-17 00:08 . 2008-09-17 00:08 71,711 --a
    C:\WINDOWS\system32\zpdilktkhogz.exe
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\wp
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\RES
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\pin
    2008-09-17 00:07 . 2008-09-18 18:03 <DIR> d
    C:\WINDOWS\system32\np5
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\mC02
    2008-09-17 00:07 . 2008-09-17 00:08 <DIR> d
    C:\temp\mtc2
    2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
    C:\Program Files\iTunes
    2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
    C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-09-11 00:35 . 2008-09-11 00:35 <DIR> d
    C:\Program Files\Bonjour
    2008-09-11 00:34 . 2008-09-11 00:34 <DIR> d
    C:\Program Files\QuickTime
    2008-09-11 00:32 . 2008-09-05 22:16 1,900,544 --a
    C:\WINDOWS\system32\usbaaplrc.dll
    2008-09-11 00:32 . 2008-09-05 22:16 36,864 --a
    C:\WINDOWS\system32\drivers\usbaapl.sys
    2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a
    C:\WINDOWS\system32\QuickTimeVR.qtx
    2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a
    C:\WINDOWS\system32\QuickTime.qts
    2008-09-04 22:51 . 2008-09-04 22:53 <DIR> d
    C:\Program Files\V CAST Music with Rhapsody
    2008-09-03 23:20 . 2008-09-03 23:40 <DIR> d
    C:\WINDOWS\system32\CatRoot_bak
    2008-09-02 21:22 . 2004-07-15 10:00 16,896 --a
    C:\WINDOWS\system32\apintfnt.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-28 19:49
    d
    w C:\Program Files\Safari
    2008-09-26 20:48
    d
    w C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
    2008-09-23 04:38
    d
    w C:\Program Files\LimeWire
    2008-09-21 00:16
    d
    w C:\Program Files\Spybot - Search & Destroy
    2008-09-19 03:32
    d
    w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-09-18 15:51 28,106 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
    2008-09-18 06:41
    d
    w C:\Program Files\Java
    2008-09-11 07:37
    d
    w C:\Program Files\iPod
    2008-09-11 07:34
    d
    w C:\Program Files\Common Files\Apple
    2008-09-05 05:52
    d
    w C:\Program Files\Real
    2008-09-03 04:22
    d
    w C:\Program Files\Verizon Wireless
    2008-08-23 07:15
    d
    w C:\Program Files\Microsoft Silverlight
    2008-08-22 03:15
    d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-08-06 16:35
    d
    w C:\Program Files\Apple Software Update
    2008-07-14 19:29 88 --sha-r C:\Documents and Settings\All Users\Application Data\53D7D18ABC.sys
    2008-07-14 19:29 2,516 --sha-w C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
    2008-07-11 02:44 606,848 ----a-w C:\WINDOWS\flashax.exe
    2008-07-11 02:44 12,288 ----a-w C:\WINDOWS\impborl.dll
    2008-04-29 05:05 69,832 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\GDIPFONTCACHEV1.DAT
    2006-08-17 03:20 184,808 -c--a-w C:\Documents and Settings\Guest\Application Data\shb.dat
    2006-06-23 17:39 1,820 -c--a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
    2005-07-29 23:24 472 --sha-r C:\WINDOWS\TWFyaWEgUml2ZXJh\nqIVuqH0oA5ZtrL1.vbs
    .

    ((((((((((((((((((((((((((((( snapshot@2007-12-17_22.48.08.40 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-02-26 11:48:44 297,984 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\SP2QFE\msctf.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\updspapi.dll
    + 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
    + 2008-03-19 09:40:27 1,845,888 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
    + 2007-12-04 18:29:10 551,936 ----a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll
    + 2007-11-07 09:50:47 727,040 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
    + 2007-12-07 02:01:07 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll
    + 2007-12-19 22:57:52 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll
    + 2007-12-07 02:01:07 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll
    + 2007-12-07 02:01:07 133,120 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll
    + 2007-12-07 02:01:07 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll
    + 2007-12-06 08:34:28 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe
    + 2007-12-07 02:01:08 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll
    + 2007-12-07 02:01:08 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll
    + 2007-12-06 05:00:02 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat
    + 2007-12-07 02:01:08 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll
    + 2007-12-07 02:01:08 388,096 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll
    + 2007-12-07 02:01:10 6,067,200 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll
    + 2007-12-07 02:01:10 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll
    + 2007-12-07 02:01:11 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll
    + 2007-12-06 08:34:29 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe
    + 2007-12-06 08:34:45 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
    + 2007-12-07 02:01:11 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll
    + 2007-12-07 02:01:11 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll
    + 2007-12-07 02:01:11 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll
    + 2007-12-07 02:01:12 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll
    + 2007-12-07 02:01:12 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll
    + 2007-12-07 02:01:13 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll
    + 2007-12-07 02:01:13 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll
    + 2007-12-07 02:01:13 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll
    + 2008-01-11 05:57:26 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll
    + 2007-12-07 02:01:13 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\url.dll
    + 2007-12-07 02:01:13 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll
    + 2007-12-07 02:01:13 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll
    + 2007-12-07 02:01:13 825,344 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\updspapi.dll
    + 2008-02-20 05:19:35 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
    + 2008-02-20 18:49:36 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
    + 2007-12-18 09:38:59 179,712 ----a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll
    + 2008-05-02 13:30:08 83,968 ----a-w C:\WINDOWS\$hf_mig$\KB946648\SP2QFE\msgsc.dll
    + 2008-05-02 14:01:49 83,968 ----a-w C:\WINDOWS\$hf_mig$\KB946648\SP3GDR\msgsc.dll
    + 2008-05-02 13:42:10 83,968 ----a-w C:\WINDOWS\$hf_mig$\KB946648\SP3QFE\msgsc.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB946648\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB946648\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB946648\update\spcustom.dll
    + 2007-11-30 11:20:44 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB946648\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB946648\update\updspapi.dll
    + 2008-03-01 13:03:00 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll
    + 2008-03-01 13:03:00 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll
    + 2008-03-01 13:03:00 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll
    + 2008-03-01 13:03:00 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll
    + 2008-03-01 13:03:00 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll
    + 2008-02-22 09:39:56 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe
    + 2008-03-01 13:03:00 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll
    + 2008-03-01 13:03:00 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll
    + 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat
    + 2008-03-01 13:03:00 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll
    + 2008-03-01 13:03:00 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll
    + 2008-03-01 13:03:01 6,067,712 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll
    + 2008-03-01 13:03:01 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll
    + 2008-03-01 13:03:01 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll
    + 2008-02-22 09:39:56 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe
    + 2008-02-22 09:40:22 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
    + 2008-03-01 13:03:01 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll
    + 2008-03-01 13:03:01 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll
    + 2008-03-01 13:03:01 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll
    + 2008-03-01 13:03:01 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll
    + 2008-03-01 13:03:01 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll
    + 2008-03-01 13:03:01 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll
    + 2008-03-01 13:03:01 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll
    + 2008-03-01 13:03:01 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll
    + 2008-03-01 13:03:01 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll
    + 2008-03-01 13:03:02 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll
    + 2008-03-01 13:03:02 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll
    + 2008-03-01 13:03:02 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll
    + 2008-03-01 13:03:02 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll
    + 2008-02-20 06:52:43 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
    + 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe
    + 2007-03-06 01:23:47 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll
    + 2008-01-23 04:56:21 554,008 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll
    + 2007-12-10 12:41:11 518,944 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll
    + 2007-12-10 12:41:11 326,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
    + 2007-12-10 12:41:11 1,516,568 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll
    + 2007-12-10 12:41:11 355,112 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
    + 2008-03-27 07:39:13 151,583 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll
    + 2007-12-10 12:41:12 60,192 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll
    + 2007-12-10 12:41:12 248,608 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
    + 2007-12-10 12:41:12 219,936 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll
    + 2007-12-10 12:41:12 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
    + 2007-12-10 12:41:13 432,928 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
    + 2007-12-10 12:41:13 322,336 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
    + 2007-12-10 12:41:13 559,904 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
    + 2007-12-10 12:41:13 264,992 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll
    + 2007-12-10 12:41:13 838,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
    + 2007-12-10 12:41:14 621,344 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
    + 2007-12-10 12:41:14 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
    + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll
    + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe
    + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll
    + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll
    + 2008-04-23 03:35:35 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\advpack.dll
    + 2008-04-23 03:35:35 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\dxtmsft.dll
    + 2008-04-23 03:35:35 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\dxtrans.dll
    + 2008-04-23 03:35:35 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\extmgr.dll
    + 2008-04-23 03:35:35 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\icardie.dll
    + 2008-04-22 08:02:19 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ie4uinit.exe
    + 2008-04-23 03:35:35 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieakeng.dll
    + 2008-04-23 03:35:35 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieaksie.dll
    + 2008-04-20 05:07:38 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dat
    + 2008-04-23 03:35:35 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieapfltr.dll
    + 2008-04-23 03:35:35 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iedkcs32.dll
    + 2008-04-23 03:35:36 6,068,224 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieframe.dll
    + 2008-04-23 03:35:36 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iernonce.dll
    + 2008-04-23 03:35:36 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iertutil.dll
    + 2008-04-22 08:02:19 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\ieudinit.exe
    + 2008-04-22 08:02:46 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
    + 2008-04-23 03:35:36 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\jsproxy.dll
    + 2008-04-23 03:35:36 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\msfeeds.dll
    + 2008-04-23 03:35:36 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\msfeedsbs.dll
    + 2008-04-23 03:35:36 3,593,728 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll
    + 2008-04-23 03:35:36 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\mshtmled.dll
    + 2008-04-23 03:35:36 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\msrating.dll
    + 2008-04-23 03:35:36 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\mstime.dll
    + 2008-04-23 03:35:36 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\occache.dll
    + 2008-04-23 03:35:36 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\pngfilt.dll
    + 2008-04-23 03:35:36 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\url.dll
    + 2008-04-23 03:35:36 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\urlmon.dll
    + 2008-04-23 03:35:36 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\webcheck.dll
    + 2008-04-23 03:35:36 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB950759-IE7\update\updspapi.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB950760\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB950760\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950760\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB950760\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB950760\update\updspapi.dll
    + 2008-05-08 12:14:51 203,008 ----a-w C:\WINDOWS\$hf_mig$\KB950762\SP2QFE\rmcast.sys
    + 2008-05-08 14:02:52 203,136 ----a-w C:\WINDOWS\$hf_mig$\KB950762\SP3GDR\rmcast.sys
    + 2008-05-08 13:58:17 203,136 ----a-w C:\WINDOWS\$hf_mig$\KB950762\SP3QFE\rmcast.sys
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB950762\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB950762\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950762\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB950762\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB950762\update\updspapi.dll
    + 2008-07-07 20:06:43 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP2QFE\es.dll
    + 2008-07-07 20:26:58 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3GDR\es.dll
    + 2008-07-07 20:23:18 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
    + 2007-11-30 12:39:18 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
    + 2007-11-30 12:39:19 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
    + 2008-04-11 18:39:39 683,520 ----a-w C:\WINDOWS\$hf_mig$\KB951066\SP2QFE\inetcomm.dll
    + 2008-04-11 19:04:26 691,712 ----a-w C:\WINDOWS\$hf_mig$\KB951066\SP3GDR\inetcomm.dll
    + 2008-04-12 07:22:26 691,712 ----a-w C:\WINDOWS\$hf_mig$\KB951066\SP3QFE\inetcomm.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951066\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951066\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951066\update\spcustom.dll
    + 2007-12-03 15:25:31 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951066\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951066\update\updspapi.dll
    + 2008-07-14 11:03:00 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
    + 2008-07-11 12:42:28 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
    + 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
    + 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
    + 2008-06-13 09:52:16 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys
    + 2008-06-13 11:05:51 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys
    + 2008-06-13 11:27:43 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys
    + 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951376-v2\update\updspapi.dll
    + 2008-04-14 11:00:16 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376\SP2QFE\bthport.sys
    + 2008-04-14 12:30:49 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376\SP3GDR\bthport.sys
    + 2008-04-14 12:36:35 272,128 ----a-w C:\WINDOWS\$hf_mig$\KB951376\SP3QFE\bthport.sys
    + 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951376\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951376\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951376\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951376\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951376\update\updspapi.dll
    + 2008-05-07 04:55:40 1,288,192 ----a-w C:\WINDOWS\$hf_mig$\KB951698\SP2QFE\quartz.dll
    + 2008-05-07 05:12:40 1,288,192 ----a-w C:\WINDOWS\$hf_mig$\KB951698\SP3GDR\quartz.dll
    + 2008-05-07 05:04:15 1,288,192 ----a-w C:\WINDOWS\$hf_mig$\KB951698\SP3QFE\quartz.dll
    + 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951698\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951698\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951698\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951698\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951698\update\updspapi.dll
    + 2006-08-16 12:08:32 100,352 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\6to4svc.dll
    + 2008-06-20 10:44:08 138,368 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\afd.sys
    + 2008-06-20 17:36:11 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\dnsapi.dll
    + 2008-06-20 17:36:11 245,248 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll
    + 2008-06-20 10:44:42 360,960 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    + 2008-06-20 09:32:39 225,920 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip6.sys
    + 2008-06-20 11:40:08 138,496 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\afd.sys
    + 2008-06-20 17:46:57 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\dnsapi.dll
    + 2008-06-20 17:46:57 245,248 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll
    + 2008-06-20 11:51:12 361,600 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    + 2008-06-20 11:08:27 225,856 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip6.sys
    + 2008-06-20 11:48:03 138,496 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys
    + 2008-06-20 17:43:05 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\dnsapi.dll
    + 2008-06-20 17:43:05 245,248 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll
    + 2008-06-20 11:59:02 361,600 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    + 2008-06-20 11:16:44 225,856 ----a-w C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip6.sys
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951748\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951748\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951748\update\spcustom.dll
    + 2007-11-30 12:39:18 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951748\update\update.exe
    + 2007-11-30 12:39:19 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951748\update\updspapi.dll
    + 2008-05-01 15:04:00 331,776 ----a-w C:\WINDOWS\$hf_mig$\KB952287\SP2QFE\msadce.dll
    + 2008-05-01 14:33:02 331,776 ----a-w C:\WINDOWS\$hf_mig$\KB952287\SP3GDR\msadce.dll
    + 2008-05-01 14:38:05 331,776 ----a-w C:\WINDOWS\$hf_mig$\KB952287\SP3QFE\msadce.dll
    + 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB952287\spmsg.dll
    + 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB952287\spuninst.exe
    + 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952287\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB952287\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB952287\update\updspapi.dll
    + 2008-06-24 16:28:00 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP2QFE\mscms.dll
    + 2008-06-24 16:43:16 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3GDR\mscms.dll
    + 2008-06-24 16:53:10 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
    + 2008-06-23 16:01:38 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\advpack.dll
    + 2008-06-23 16:01:38 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\dxtmsft.dll
    + 2008-06-23 16:01:39 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\dxtrans.dll
    + 2008-06-23 16:01:39 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\extmgr.dll
    + 2008-06-23 16:01:39 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\icardie.dll
    + 2008-06-23 08:23:18 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe
    + 2008-06-23 16:01:39 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieakeng.dll
    + 2008-06-23 16:01:39 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieaksie.dll
    + 2008-06-21 05:23:53 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieakui.dll
    + 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dat
    + 2008-06-23 16:01:40 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieapfltr.dll
    + 2008-06-23 16:01:40 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iedkcs32.dll
    + 2008-06-23 16:01:43 6,068,736 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieframe.dll
    + 2008-06-23 16:01:43 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iernonce.dll
    + 2008-06-23 16:01:44 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iertutil.dll
    + 2008-06-23 08:23:18 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe
    + 2008-06-23 08:23:52 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
    + 2008-06-23 16:01:46 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\jsproxy.dll
    + 2008-06-23 16:01:46 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\msfeeds.dll
    + 2008-06-23 16:01:46 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\msfeedsbs.dll
    + 2008-06-23 16:01:49 3,594,240 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
    + 2008-06-23 16:01:49 477,696 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\mshtmled.dll
    + 2008-06-23 16:01:49 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\msrating.dll
    + 2008-06-23 16:01:50 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\mstime.dll
    + 2008-06-23 16:01:50 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\occache.dll
    + 2008-06-23 16:01:50 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\pngfilt.dll
    + 2008-06-23 16:01:50 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\url.dll
    + 2008-06-23 16:01:51 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\urlmon.dll
    + 2008-06-23 16:01:51 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\webcheck.dll
    + 2008-06-23 16:01:51 827,904 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
    + 2007-03-06 01:22:33 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\spmsg.dll
    + 2007-03-06 01:22:39 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\spuninst.exe
    + 2007-03-06 01:22:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\update\spcustom.dll
    + 2007-03-06 01:22:56 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\update\update.exe
    + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB953838-IE7\update\updspapi.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB953839\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB953839\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB953839\update\spcustom.dll
    + 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB953839\update\update.exe
    + 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB953839\update\updspapi.dll
  • edited October 2008
    + 2004-08-04 12:00:00 294,400 -c----w C:\WINDOWS\$NtUninstallKB932823-v3$\msctf.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\updspapi.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
    + 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll
    + 2007-03-08 13:47:48 1,843,584 -c----w C:\WINDOWS\$NtUninstallKB941693$\win32k.sys
    + 2007-05-17 11:28:05 549,376 -c----w C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll
    + 2006-08-17 12:28:27 721,920 -c----w C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll
    + 2006-06-26 17:37:10 148,480 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll
    + 2004-08-04 12:00:00 45,568 -c----w C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll
    + 2004-08-04 12:00:00 181,248 -c----w C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll
    + 2004-08-04 15:06:34 82,944 -c----w C:\WINDOWS\$NtUninstallKB946648$\msgsc.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB946648$\spuninst\updspapi.dll
    + 2007-06-19 13:31:19 282,112 -c----w C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll
    + 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe
    + 2007-03-06 01:23:47 371,424 -c----w C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll
    + 2004-08-04 12:00:00 561,179 -c----w C:\WINDOWS\$NtUninstallKB950749$\dao360.dll
    + 2004-08-04 12:00:00 512,029 -c----w C:\WINDOWS\$NtUninstallKB950749$\msexch40.dll
    + 2004-08-04 12:00:00 319,517 -c----w C:\WINDOWS\$NtUninstallKB950749$\msexcl40.dll
    + 2004-08-04 12:00:00 1,507,356 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjet40.dll
    + 2004-08-04 12:00:00 358,976 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjetol1.dll
    + 2004-08-04 19:00:00 358,976 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjetoledb40.dll
    + 2004-08-04 12:00:00 151,583 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjint40.dll
    + 2004-08-04 12:00:00 53,279 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjter40.dll
    + 2004-08-04 12:00:00 241,693 -c----w C:\WINDOWS\$NtUninstallKB950749$\msjtes40.dll
    + 2004-08-04 12:00:00 213,023 -c----w C:\WINDOWS\$NtUninstallKB950749$\msltus40.dll
    + 2004-08-04 12:00:00 348,189 -c----w C:\WINDOWS\$NtUninstallKB950749$\mspbde40.dll
    + 2004-08-04 12:00:00 421,919 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrd2x40.dll
    + 2004-08-04 12:00:00 315,423 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrd3x40.dll
    + 2004-08-04 12:00:00 552,989 -c----w C:\WINDOWS\$NtUninstallKB950749$\msrepl40.dll
    + 2004-08-04 12:00:00 258,077 -c----w C:\WINDOWS\$NtUninstallKB950749$\mstext40.dll
    + 2004-08-04 12:00:00 831,519 -c----w C:\WINDOWS\$NtUninstallKB950749$\mswdat10.dll
    + 2004-08-04 12:00:00 614,429 -c----w C:\WINDOWS\$NtUninstallKB950749$\mswstr10.dll
    + 2004-08-04 12:00:00 348,189 -c----w C:\WINDOWS\$NtUninstallKB950749$\msxbde40.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB950749$\spuninst\updspapi.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB950760$\spuninst\updspapi.dll
    + 2006-07-13 08:48:58 202,240 -c----w C:\WINDOWS\$NtUninstallKB950762$\rmcast.sys
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB950762$\spuninst\updspapi.dll
    + 2005-07-26 04:39:45 243,200 -c----w C:\WINDOWS\$NtUninstallKB950974$\es.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe
    + 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB950974$\spuninst\updspapi.dll
    + 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\$NtUninstallKB951066$\inetcomm.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951066$\spuninst\updspapi.dll
    + 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\updspapi.dll
    + 2007-11-13 11:31:11 60,416 -c----w C:\WINDOWS\$NtUninstallKB951072-v2$\tzchange.exe
    + 2008-04-14 11:01:02 272,128 -c----w C:\WINDOWS\$NtUninstallKB951376-v2$\bthport.sys
    + 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe
    + 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\updspapi.dll
    + 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe
    + 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB951376$\spuninst\updspapi.dll
    + 2007-10-29 22:43:03 1,287,680 -c----w C:\WINDOWS\$NtUninstallKB951698$\quartz.dll
    + 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB951698$\spuninst\updspapi.dll
    + 2004-08-04 12:00:00 138,496 -c----w C:\WINDOWS\$NtUninstallKB951748$\afd.sys
    + 2008-02-20 05:32:43 148,992 -c----w C:\WINDOWS\$NtUninstallKB951748$\dnsapi.dll
    + 2004-08-04 12:00:00 245,248 -c----w C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe
    + 2007-11-30 12:39:19 382,840 -c----w C:\WINDOWS\$NtUninstallKB951748$\spuninst\updspapi.dll
    + 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
    + 2006-08-16 09:37:30 225,664 -c----w C:\WINDOWS\$NtUninstallKB951748$\tcpip6.sys
    + 2004-08-04 12:00:00 331,776 -c----w C:\WINDOWS\$NtUninstallKB952287$\msadce.dll
    + 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe
    + 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB952287$\spuninst\updspapi.dll
    + 2005-06-29 01:46:00 74,240 -c----w C:\WINDOWS\$NtUninstallKB952954$\mscms.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe
    + 2007-11-30 12:39:22 382,840 -c----w C:\WINDOWS\$NtUninstallKB952954$\spuninst\updspapi.dll
    + 2007-11-30 12:39:22 231,288 -c----w C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe
    + 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB953839$\spuninst\updspapi.dll
    + 2008-03-19 02:38:12 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
    + 2008-03-19 02:38:12 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
    + 2008-03-19 02:38:12 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
    + 2008-03-19 02:38:05 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:06 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:07 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:07 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:08 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:09 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:09 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:10 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:11 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:13 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
    + 2008-03-19 02:38:13 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
    + 2008-03-19 02:38:13 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
    + 2008-03-19 02:38:13 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
    + 2008-03-19 02:38:14 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
    + 2008-03-19 02:38:11 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
    - 2007-12-07 04:24:44 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2008-04-12 08:07:43 69,120 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    - 2007-12-07 04:25:05 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2008-04-12 08:07:50 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    - 2007-12-07 04:25:06 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2008-04-12 08:07:27 4,444,160 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    - 2007-12-07 04:25:08 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2008-04-12 08:07:53 483,840 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    - 2007-12-07 04:25:01 2,902,016 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2008-04-12 08:07:36 3,036,160 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    - 2007-12-07 04:24:24 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2008-04-12 08:07:57 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2007-12-07 04:24:24 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2008-04-12 08:07:57 113,664 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    - 2007-12-07 04:25:20 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2008-04-12 08:07:51 261,120 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    - 2007-12-07 04:24:54 5,156,864 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2008-04-12 08:07:34 5,431,296 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    - 2007-12-07 04:24:40 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    + 2008-04-12 08:07:41 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2007-12-07 04:24:22 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2008-04-12 08:07:35 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    - 2007-12-07 04:24:34 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2008-04-12 08:07:43 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    - 2007-12-07 04:25:03 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2008-04-12 08:07:47 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    - 2007-12-07 04:25:04 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    + 2008-04-12 08:07:47 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    - 2007-12-07 04:25:04 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2008-04-12 08:07:48 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    - 2007-12-07 04:24:38 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2008-04-12 08:07:58 348,160 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    - 2007-12-07 04:24:38 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2008-04-12 08:07:59 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2007-12-07 04:24:39 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    + 2008-04-12 08:08:00 655,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    - 2007-12-07 04:24:40 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    + 2008-04-12 08:08:01 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    - 2007-12-07 04:24:37 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2008-04-12 08:07:48 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    - 2007-12-07 04:25:24 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2008-04-12 08:07:47 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2007-12-07 04:25:24 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    + 2008-04-12 08:07:46 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2007-12-07 04:24:14 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2008-04-12 08:07:53 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    - 2007-12-07 04:25:21 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2008-04-12 08:07:45 671,744 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    - 2007-12-07 04:25:25 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2008-04-12 08:07:30 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2007-12-07 04:24:19 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2008-04-12 08:07:56 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2007-12-07 04:24:16 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    + 2008-04-12 08:07:45 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2007-12-07 04:24:17 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    + 2008-04-12 08:07:44 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2007-12-07 04:25:12 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2008-04-12 08:07:49 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2007-12-07 04:24:45 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2008-04-12 08:07:50 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    - 2007-12-07 04:25:13 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2008-04-12 08:07:36 425,984 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    - 2007-12-07 04:25:09 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2008-04-12 08:07:37 741,376 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    - 2007-12-07 04:24:29 888,832 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2008-04-12 08:07:37 933,888 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    - 2007-12-07 04:25:02 5,001,216 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2008-04-12 08:08:02 5,070,848 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    - 2007-12-07 04:24:48 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2008-04-12 08:08:00 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2007-12-07 04:24:46 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2008-04-12 08:07:41 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    - 2007-12-07 04:24:50 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2008-04-12 08:07:55 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2007-12-07 04:25:18 577,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2008-04-12 08:07:31 630,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    - 2007-12-07 04:25:09 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2008-04-12 08:07:57 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    - 2007-12-07 04:25:18 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2008-04-12 08:07:54 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    - 2007-12-07 04:25:10 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2008-04-12 08:07:52 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    - 2007-12-07 04:25:11 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2008-04-12 08:07:51 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2007-12-07 04:24:42 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2008-04-12 08:07:32 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    - 2007-12-07 04:24:52 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2008-04-12 08:07:32 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    - 2007-12-07 04:25:20 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    + 2008-04-12 08:07:39 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    - 2007-12-07 04:24:55 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    + 2008-04-12 08:07:40 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    - 2007-12-07 04:24:56 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    + 2008-04-12 08:07:39 839,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2007-12-07 04:24:57 5,152,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2008-04-12 08:07:42 5,013,504 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    - 2007-12-07 04:24:58 2,027,520 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    + 2008-04-12 08:07:34 2,068,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    - 2007-12-07 04:25:16 2,940,928 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2008-04-12 08:07:38 3,076,096 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2008-04-13 01:18:32 27,136 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll
    + 2008-04-13 01:18:37 884,736 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll
    + 2008-04-13 01:18:38 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll
    + 2008-04-13 01:18:38 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe
    + 2008-04-13 01:18:41 876,544 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll
    + 2008-04-13 01:18:41 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll
    + 2008-04-13 01:18:45 1,695,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll
    + 2008-04-13 01:18:46 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll
    + 2008-04-13 01:18:49 1,740,800 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll
    + 2008-04-12 13:34:05 11,722,752 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll
    + 2008-04-13 01:18:50 1,011,712 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll
    + 2008-04-12 13:35:08 7,049,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll
    + 2008-04-13 01:18:52 1,798,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll
    + 2008-04-12 13:35:30 10,969,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll
    + 2008-04-13 01:18:54 1,224,704 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll
    + 2008-04-13 01:18:55 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll
    + 2008-04-12 13:35:33 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll
    + 2008-04-12 13:35:33 1,667,072 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll
    + 2008-04-13 01:18:56 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll
    + 2008-04-13 01:18:56 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll
    + 2008-04-13 01:18:58 733,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll
    + 2008-04-13 01:18:58 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll
    + 2008-04-13 01:19:00 679,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll
    + 2008-04-13 01:19:19 2,342,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll
    + 2008-04-13 01:19:20 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll
    + 2008-04-13 01:19:23 1,986,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll
    + 2008-04-13 01:19:16 12,509,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll
    + 2008-04-12 13:35:57 13,193,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll
    + 2008-04-12 13:36:10 5,771,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll
    + 2008-04-12 13:34:46 8,265,728 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll
    + 2007-12-20 07:47:25 38,428 ----a-w C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
    + 2008-06-13 13:10:50 272,128
    w C:\WINDOWS\Driver Cache\i386\bthport.sys
    + 2005-10-21 03:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
    - 2007-03-13 18:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
    + 2005-10-21 03:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
    + 2000-08-31 15:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
    + 2000-08-31 15:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
    + 2004-08-04 12:00:00 2,589
    w C:\WINDOWS\I386\RUNW32.BAT
    + 2007-10-10 23:55:51 124,928 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\advpack.dll
    + 2006-10-17 19:58:06 346,624 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtmsft.dll
    + 2007-10-10 23:55:51 214,528 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtrans.dll
    + 2007-10-10 23:55:51 132,608 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\extmgr.dll
    + 2007-10-10 23:55:51 63,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\icardie.dll
    + 2007-10-10 10:59:40 70,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ie4uinit.exe
    + 2007-10-10 23:55:51 153,088 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakeng.dll
    + 2007-10-10 23:55:51 230,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieaksie.dll
    + 2007-10-10 05:46:55 161,792 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakui.dll
    + 2007-10-10 23:55:52 383,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieapfltr.dll
    + 2007-10-10 23:55:52 384,512 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iedkcs32.dll
    + 2007-10-10 23:55:54 6,065,664 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieframe.dll
    + 2007-10-10 23:55:55 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iernonce.dll
    + 2007-10-10 23:55:55 267,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iertutil.dll
    + 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieudinit.exe
    + 2007-10-10 10:59:52 625,152 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
    + 2007-10-10 23:55:56 27,648 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\jsproxy.dll
    + 2007-10-10 23:55:56 459,264 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeeds.dll
    + 2007-10-10 23:55:56 52,224 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeedsbs.dll
    + 2007-10-30 23:42:28 3,590,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll
    + 2007-10-10 23:55:58 478,208 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtmled.dll
    + 2007-10-10 23:55:58 193,024 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msrating.dll
    + 2007-10-10 23:55:59 671,232 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mstime.dll
    + 2007-10-10 23:55:59 102,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\occache.dll
    + 2006-10-17 19:58:08 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\pngfilt.dll
    + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\updspapi.dll
    + 2007-10-10 23:55:59 105,984 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\url.dll
    + 2007-10-10 23:56:00 1,159,680 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\urlmon.dll
    + 2007-10-10 23:56:00 232,960 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\webcheck.dll
    + 2007-10-10 23:56:00 824,832 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
    + 2007-12-07 02:21:45 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll
    + 2007-12-19 23:01:06 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll
    + 2007-12-07 02:21:45 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll
    + 2007-12-07 02:21:45 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll
    + 2007-12-07 02:21:45 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll
    + 2007-12-06 11:00:57 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe
    + 2007-12-07 02:21:45 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll
    + 2007-12-07 02:21:45 230,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll
    + 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll
    + 2007-12-07 02:21:45 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll
    + 2007-12-07 02:21:45 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll
    + 2007-12-07 02:21:46 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll
    + 2007-12-07 02:21:46 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll
    + 2007-12-07 02:21:46 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll
    + 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe
    + 2007-12-06 11:01:25 625,664 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
    + 2007-12-07 02:21:47 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll
    + 2007-12-07 02:21:47 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll
    + 2007-12-07 02:21:47 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll
    + 2007-12-08 05:21:48 3,592,192 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll
    + 2007-12-07 02:21:47 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll
    + 2007-12-07 02:21:48 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll
    + 2007-12-07 02:21:48 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll
    + 2007-12-07 02:21:48 102,912 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll
    + 2008-01-11 05:53:32 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll
    + 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll
    + 2007-12-07 02:21:48 105,984 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll
    + 2007-12-07 02:21:48 1,159,680 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll
    + 2007-12-07 02:21:48 233,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll
    + 2007-12-07 02:21:48 824,832 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
    + 2008-03-01 13:06:20 124,928 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
    + 2008-03-01 13:06:21 347,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
    + 2008-03-01 13:06:21 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
    + 2008-03-01 13:06:21 133,120 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
    + 2008-03-01 13:06:21 63,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
    + 2008-02-29 08:55:23 70,656 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
    + 2008-03-01 13:06:21 153,088 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
    + 2008-03-01 13:06:21 230,400 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
    + 2008-02-15 05:44:25 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
    + 2008-03-01 13:06:22 383,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
    + 2008-03-01 13:06:22 384,512 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
    + 2008-03-01 13:06:24 6,066,176 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
    + 2008-03-01 13:06:24 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
    + 2008-03-01 13:06:25 267,776 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
    + 2008-02-22 10:00:51 13,824 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
    + 2008-02-29 08:55:46 625,664 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
    + 2008-03-01 13:06:25 27,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
    + 2008-03-01 13:06:26 459,264 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
    + 2008-03-01 13:06:26 52,224 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
    + 2008-03-02 01:36:30 3,591,680 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
    + 2008-03-01 13:06:28 478,208 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
    + 2008-03-01 13:06:28 193,024 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
    + 2008-03-01 13:06:29 671,232 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
    + 2008-03-01 13:06:29 102,912 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
    + 2008-03-01 13:06:29 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
    + 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
    + 2008-03-01 13:06:29 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
    + 2008-03-01 13:06:30 1,159,680 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
    + 2008-03-01 13:06:30 233,472 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
    + 2008-03-01 13:06:31 826,368 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
    + 2008-04-23 04:16:28 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
    + 2008-04-23 04:16:28 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
    + 2008-04-23 04:16:28 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
    + 2008-04-23 04:16:28 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
    + 2008-04-23 04:16:28 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
    + 2008-04-22 07:39:58 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
    + 2008-04-23 04:16:28 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
    + 2008-04-23 04:16:28 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
    + 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
    + 2008-04-23 04:16:28 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
    + 2008-04-23 04:16:28 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
    + 2008-04-23 04:16:28 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
    + 2008-04-23 04:16:28 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
    + 2008-04-23 04:16:28 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
    + 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
    + 2008-04-22 07:40:18 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
    + 2008-04-23 04:16:28 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
    + 2008-04-23 04:16:28 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
    + 2008-04-23 04:16:28 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
    + 2008-04-24 05:16:30 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
    + 2008-04-23 04:16:28 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
    + 2008-04-23 04:16:28 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
    + 2008-04-23 04:16:28 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
    + 2008-04-23 04:16:28 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
    + 2008-04-23 04:16:28 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
    + 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
    + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
    + 2008-04-23 04:16:28 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll
    + 2008-04-23 04:16:29 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
    + 2008-04-23 04:16:29 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
    + 2008-04-23 04:16:29 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
    + 2008-08-06 16:35:10 27,136 ----a-r C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
    + 2008-09-11 07:35:35 86,016 ----a-r C:\WINDOWS\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
    - 2007-01-23 06:36:39 167,936 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
    + 2008-09-18 08:40:28 167,936 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
    + 2008-09-18 08:40:29 2,560 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
    - 2007-01-23 06:36:39 34,304 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\misc.exe
    + 2008-09-18 08:40:27 34,304 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\misc.exe
    - 2007-01-23 06:36:40 8,192 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
    + 2008-09-18 08:40:29 8,192 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
    - 2007-01-23 06:36:40 3,584 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
    + 2008-09-18 08:40:29 3,584 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
    - 2007-01-23 06:36:40 114,688 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
    + 2008-09-18 08:40:29 114,688 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
    - 2007-01-23 06:36:39 16,384 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
    + 2008-09-18 08:40:28 16,384 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
    - 2007-01-23 06:36:39 30,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
    + 2008-09-18 08:40:28 30,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
    - 2007-01-23 06:36:40 22,528 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
    + 2008-09-18 08:40:30 22,528 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
    - 2007-01-23 06:36:39 45,056 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
    + 2008-09-18 08:40:27 45,056 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
    - 2007-01-23 06:36:39 90,112 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
    + 2008-09-18 08:40:27 90,112 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
    - 2006-11-19 02:56:31 12,288 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2008-08-01 00:13:05 12,288 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2006-11-19 02:56:31 135,168 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2008-08-01 00:13:05 135,168 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2006-11-19 02:56:31 11,264 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2008-08-01 00:13:05 11,264 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2006-11-19 02:56:31 27,136 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-08-01 00:13:05 27,136 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2006-11-19 02:56:31 4,096 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-08-01 00:13:05 4,096 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2006-11-19 02:56:31 794,624 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-08-01 00:13:05 794,624 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2006-11-19 02:56:31 249,856 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-08-01 00:13:05 249,856 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2006-11-19 02:56:32 23,040 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-08-01 00:13:05 23,040 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2006-11-19 02:56:30 286,720 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-08-01 00:13:05 286,720 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2006-11-19 02:56:30 409,600 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-08-01 00:13:05 409,600 ----a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-02-11 18:38:07 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
    + 2008-07-31 07:20:26 307,200 ----a-r C:\WINDOWS\Installer\{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}\SafariIco.exe
    + 2008-09-27 19:24:08 632,320 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}\IconCD95F66110.exe
    + 2008-09-27 19:24:08 29,184 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}\IconCD95F6617.exe
    + 2008-03-19 02:40:43 441,406 ----a-r C:\WINDOWS\Installer\{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}\ARPPRODUCTICON.exe
    + 2008-09-11 07:37:56 102,400 ----a-r C:\WINDOWS\Installer\{EA418519-2160-43A0-AABD-6608DDD8D87F}\iTunesIco.exe
  • edited October 2008
    + 2006-12-14 03:01:58 2,678 ----a-w C:\WINDOWS\java\Packages\Data\3P71BDN7.DAT
    + 2006-12-14 03:01:56 2,678 ----a-w C:\WINDOWS\java\Packages\Data\5Z5RZVZR.DAT
    + 2006-12-14 03:01:55 2,678 ----a-w C:\WINDOWS\java\Packages\Data\BBZDJH37.DAT
    + 2006-12-14 03:01:54 2,678 ----a-w C:\WINDOWS\java\Packages\Data\KS9VLBXJ.DAT
    + 2006-12-14 03:02:03 2,678 ----a-w C:\WINDOWS\java\Packages\Data\N1RVJ575.DAT
    + 2006-12-07 04:47:46 2,232 ----a-w C:\WINDOWS\java\Packages\Data\TZL7HRXZ.DAT
    + 2007-07-31 03:19:20 92,504 ----a-w C:\WINDOWS\LastGood\system32\cdm.dll
    + 2007-07-31 03:19:36 549,720 ----a-w C:\WINDOWS\LastGood\system32\wuapi.dll
    + 2007-07-31 03:19:16 53,080 ----a-w C:\WINDOWS\LastGood\system32\wuauclt.exe
    + 2007-07-31 03:19:42 1,712,984 ----a-w C:\WINDOWS\LastGood\system32\wuaueng.dll
    + 2007-07-31 03:19:32 325,976 ----a-w C:\WINDOWS\LastGood\system32\wucltui.dll
    + 2007-07-31 03:18:40 33,624 ----a-w C:\WINDOWS\LastGood\system32\wups.dll
    + 2007-07-31 03:19:12 43,352 ----a-w C:\WINDOWS\LastGood\system32\wups2.dll
    + 2007-07-31 03:19:28 203,096 ----a-w C:\WINDOWS\LastGood\system32\wuweb.dll
    + 2005-03-18 23:23:10 53,248 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
    + 2005-03-18 23:23:10 12,800 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
    + 2005-03-18 23:23:14 473,600 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
    + 2004-09-29 19:38:58 2,676,224 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-03-18 23:23:10 145,920 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
    + 2005-03-18 23:23:10 159,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
    + 2005-03-18 23:23:14 364,544 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
    + 2005-03-18 23:23:12 178,176 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
    + 2005-03-18 23:23:14 223,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
    + 2004-12-01 22:53:06 2,846,720 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-02-06 02:32:54 563,712 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-03-19 00:23:14 567,296 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-05-26 22:15:56 576,000 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-07-23 00:21:34 577,024 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-09-28 21:11:52 577,536 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
    + 2005-12-06 00:20:50 577,536 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
    + 2006-02-03 14:40:48 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
    + 2006-03-31 18:27:50 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
    - 2005-09-23 14:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
    + 2007-10-24 08:47:38 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
    - 2005-09-23 14:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
    + 2007-10-24 08:47:38 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll
    - 2005-09-23 14:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
    + 2007-10-24 08:47:40 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
    - 2005-09-23 14:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
    + 2007-10-24 08:47:42 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
    - 2005-09-23 14:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll
    + 2007-10-24 08:47:40 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll
    - 2005-09-23 14:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
    + 2007-10-24 08:47:38 97,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
    - 2005-09-23 14:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
    + 2007-10-24 08:47:26 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
    - 2005-09-23 14:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
    + 2007-10-24 08:47:30 145,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
    - 2005-09-23 14:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
    + 2007-10-24 08:47:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
    - 2005-09-23 14:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
    + 2007-10-24 08:47:48 193,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
    - 2005-09-23 14:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
    + 2007-10-24 08:47:20 218,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
    - 2005-09-23 14:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
    + 2007-10-24 08:47:40 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
    - 2005-09-23 14:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
    + 2007-10-24 08:47:42 147,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
    - 2005-09-23 14:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll
    + 2007-10-24 08:47:26 99,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll
    - 2007-04-13 11:21:18 58,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
    + 2007-10-24 08:47:42 59,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
    - 2005-09-23 14:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
    + 2007-10-24 08:47:22 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
    - 2007-04-13 11:20:52 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
    + 2007-10-24 08:47:22 22,024 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
    - 2007-04-13 11:20:52 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
    + 2007-10-24 08:47:22 17,928 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
    - 2007-04-13 11:20:52 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
    + 2007-10-24 08:47:22 33,288 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
    - 2007-04-13 11:20:50 75,264 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
    + 2007-10-24 08:47:22 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
    - 2005-09-23 14:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
    + 2007-10-24 08:47:22 24,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
    - 2007-04-13 11:20:52 32,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
    + 2007-10-24 08:47:22 32,776 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
    - 2005-09-23 14:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
    + 2007-10-24 08:47:22 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
    - 2007-04-13 11:20:52 33,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    + 2007-10-24 08:47:22 33,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    - 2007-04-13 11:20:52 32,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    + 2007-10-24 08:47:22 33,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    - 2007-04-13 11:20:52 507,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
    + 2007-10-24 08:47:22 507,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
    - 2005-09-23 14:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
    + 2007-10-24 08:47:40 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
    - 2007-04-13 11:21:16 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
    + 2007-10-24 08:47:40 101,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
    - 2005-09-23 14:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe
    + 2007-10-24 08:47:30 80,376 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe
    - 2005-09-23 14:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
    + 2007-10-24 08:47:30 1,162,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
    - 2005-09-23 14:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
    + 2007-10-24 08:47:30 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
    - 2005-09-23 14:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll
    + 2007-10-24 08:47:42 27,136 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll
    - 2005-09-23 14:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
    + 2007-10-24 08:47:40 69,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
    - 2005-09-23 14:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
    + 2007-10-24 08:47:30 35,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
    - 2005-09-23 14:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
    + 2007-10-24 08:47:28 66,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
    - 2007-04-13 11:20:58 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
    + 2007-10-24 08:47:28 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
    - 2005-09-23 14:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
    + 2007-10-24 08:47:54 572,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
    - 2005-09-23 14:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
    + 2007-10-24 08:47:40 798,224 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
    - 2005-09-23 14:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll
    + 2007-10-24 08:47:36 18,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll
    - 2007-04-13 11:21:16 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
    + 2007-10-24 08:47:40 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
    - 2005-09-23 14:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
    + 2007-10-24 08:47:40 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
    - 2005-09-23 14:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
    + 2007-10-24 08:47:40 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
    - 2005-09-23 14:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
    + 2007-10-24 08:47:40 6,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
    - 2007-04-13 11:21:16 228,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
    + 2007-10-24 08:47:40 230,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
    - 2007-04-13 11:21:16 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
    + 2007-10-24 08:47:40 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
    - 2005-09-23 14:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
    + 2007-10-24 08:47:40 65,032 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
    - 2005-09-23 14:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
    + 2007-10-24 08:47:40 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
    - 2005-09-23 14:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
    + 2007-10-24 08:47:34 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe
    - 2007-04-13 11:21:10 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
    + 2007-10-24 08:47:36 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
    - 2005-09-23 14:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
    + 2007-10-24 08:47:36 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
    - 2007-04-13 11:21:10 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
    + 2007-10-24 08:47:36 655,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
    - 2005-09-23 14:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
    + 2007-10-24 08:47:36 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
    - 2007-04-13 11:21:08 749,568 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
    + 2007-10-24 08:47:34 749,568 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
    - 2005-09-23 14:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2007-10-24 08:47:52 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2005-09-23 14:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
    + 2007-10-24 08:47:52 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
    - 2005-09-23 14:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
    + 2007-10-24 08:47:50 671,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
    - 2005-09-23 14:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
    + 2007-10-24 08:47:20 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
    - 2005-09-23 14:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
    + 2007-10-24 08:47:52 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
    - 2005-09-23 14:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
    + 2007-10-24 08:47:20 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
    - 2005-09-23 14:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2007-10-24 08:47:20 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2005-09-23 14:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
    + 2007-10-24 08:47:20 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
    - 2007-04-13 11:20:52 87,040 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
    + 2007-10-24 08:47:22 97,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
    - 2005-09-23 14:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
    + 2007-10-24 08:47:36 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
    - 2007-04-13 11:21:18 802,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2007-10-24 08:47:40 822,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    - 2005-09-23 14:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
    + 2007-10-24 08:47:40 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
    - 2005-09-23 14:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
    + 2007-10-24 08:47:40 308,224 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
    - 2007-04-13 11:21:16 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
    + 2007-10-24 08:47:40 47,104 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
    - 2007-04-13 11:21:16 326,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
    + 2007-10-24 08:47:40 348,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
    - 2005-09-23 14:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
    + 2007-10-24 08:47:40 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
    - 2007-04-13 11:21:16 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2007-10-24 08:47:40 4,444,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    - 2007-04-13 11:21:16 102,912 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
    + 2007-10-24 08:47:40 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
    - 2005-09-23 14:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
    + 2007-10-24 08:47:44 340,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
    - 2005-09-23 14:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
    + 2007-10-24 08:47:40 77,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
    - 2005-09-23 14:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
    + 2007-10-24 08:47:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
    - 2007-04-13 11:21:18 227,328 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
    + 2007-10-24 08:47:40 242,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
    - 2007-04-13 11:21:18 68,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    + 2007-10-24 08:47:40 70,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    - 2005-09-23 14:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
    + 2007-10-24 08:47:40 19,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
    - 2007-04-13 11:21:12 5,634,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    + 2007-10-24 08:47:36 5,814,784 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    - 2005-09-23 14:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
    + 2007-10-24 08:47:44 31,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
    - 2007-04-13 11:21:16 99,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
    + 2007-10-24 08:47:40 101,880 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
    - 2007-04-13 11:21:18 15,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll
    + 2007-10-24 08:47:40 24,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll
    - 2005-09-23 14:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
    + 2007-10-24 08:47:40 89,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
    - 2007-04-13 11:21:12 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll
    + 2007-10-24 08:47:36 144,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll
    - 2005-09-23 14:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
    + 2007-10-24 08:47:40 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
    - 2005-09-23 14:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
    + 2007-10-24 08:47:40 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
    - 2005-09-23 14:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
    + 2007-10-24 08:47:46 61,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
    - 2005-09-23 14:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
    + 2007-10-24 08:47:42 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
    - 2005-09-23 14:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
    + 2007-10-24 08:47:40 119,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
    - 2005-09-23 14:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
    + 2007-10-24 08:47:44 95,232 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
    - 2007-04-13 11:21:18 382,464 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2007-10-24 08:47:40 392,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    - 2007-04-13 11:21:18 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
    + 2007-10-24 08:47:40 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
    - 2007-04-13 11:21:18 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
    + 2007-10-24 08:47:42 425,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
    - 2005-09-23 14:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
    + 2007-10-24 08:47:40 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
    - 2007-04-13 11:21:16 2,902,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
    + 2007-10-24 08:47:40 3,036,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
    - 2007-04-13 11:21:18 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
    + 2007-10-24 08:47:40 483,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
    - 2007-04-13 11:21:18 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
    + 2007-10-24 08:47:40 741,376 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
    - 2007-04-13 11:20:58 888,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
    + 2007-10-24 08:47:28 933,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
    - 2007-04-13 11:21:16 5,001,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
    + 2007-10-24 08:47:40 5,070,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
    - 2005-09-23 14:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
    + 2007-10-24 08:47:40 401,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
    - 2007-04-13 11:21:18 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
    + 2007-10-24 08:47:40 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
    - 2007-04-13 11:21:16 2,940,928 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2007-10-24 08:47:40 3,076,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll
    - 2005-09-23 14:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
    + 2007-10-24 08:47:40 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
    - 2007-04-13 11:21:16 577,536 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
    + 2007-10-24 08:47:40 630,784 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
    - 2007-04-13 11:21:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
    + 2007-10-24 08:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
    - 2007-04-13 11:21:18 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
    + 2007-10-24 08:47:40 57,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
    - 2007-04-13 11:21:18 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
    + 2007-10-24 08:47:40 113,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
    - 2007-04-13 11:21:16 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
    + 2007-10-24 08:47:40 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
    - 2005-09-23 14:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
    + 2007-10-24 08:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
    - 2007-04-13 11:21:16 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
    + 2007-10-24 08:47:40 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
    - 2005-09-23 14:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
    + 2007-10-24 08:47:40 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
    - 2005-09-23 14:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    + 2007-10-24 08:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    - 2005-09-23 14:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
    + 2007-10-24 08:47:40 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
    - 2007-04-13 11:21:18 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
    + 2007-10-24 08:47:40 261,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
    - 2007-04-13 11:21:16 5,156,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    + 2007-10-24 08:47:40 5,431,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    - 2005-09-23 14:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
    + 2007-10-24 08:47:40 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
    - 2005-09-23 14:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
    + 2007-10-24 08:47:40 90,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
    - 2005-09-23 14:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
    + 2007-10-24 08:47:40 839,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
    - 2007-04-13 11:21:16 5,152,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
    + 2007-10-24 08:47:40 5,013,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
    - 2007-04-13 11:21:16 2,027,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
    + 2007-10-24 08:47:40 2,068,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
    - 2005-09-23 14:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
    + 2007-10-24 08:47:40 81,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
    - 2007-04-13 11:21:28 1,166,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
    + 2007-10-24 08:47:48 1,172,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe
    - 2007-04-13 11:20:50 1,330,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
    + 2007-10-24 08:47:20 1,344,000 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
    - 2007-04-13 11:20:52 406,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    + 2007-10-24 08:47:22 434,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    - 2005-09-23 14:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
    + 2007-10-24 08:47:40 37,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
    + 2000-08-31 15:00:00 28,672 ----a-w C:\WINDOWS\Nircmd.exe
    + 1995-08-01 12:44:46 212,480 ----a-w C:\WINDOWS\PCDLIB32.DLL
    + 2000-08-31 15:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
    + 2000-08-31 15:00:00 161,792 ----a-w C:\WINDOWS\SWREG.exe
    + 2000-08-31 15:00:00 136,704 ----a-w C:\WINDOWS\SWSC.exe
    + 2000-08-31 15:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
    + 2004-08-04 12:00:00 2,000 ----a-w C:\WINDOWS\system\KEYBOARD.DRV
    + 2004-08-04 12:00:00 73,376 ----a-w C:\WINDOWS\system\MCIAVI.DRV
    + 2004-08-04 12:00:00 25,264 ----a-w C:\WINDOWS\system\MCISEQ.DRV
    + 2004-08-04 12:00:00 28,160 ----a-w C:\WINDOWS\system\MCIWAVE.DRV
    + 2004-08-04 12:00:00 2,032 ----a-w C:\WINDOWS\system\MOUSE.DRV
    + 2004-08-04 12:00:00 1,744 ----a-w C:\WINDOWS\system\SOUND.DRV
    + 2004-08-04 12:00:00 3,360 ----a-w C:\WINDOWS\system\SYSTEM.DRV
    + 2004-08-04 12:00:00 4,048 ----a-w C:\WINDOWS\system\TIMER.DRV
    + 2004-08-04 12:00:00 2,176 ----a-w C:\WINDOWS\system\VGA.DRV
    + 2004-08-04 12:00:00 13,600 ----a-w C:\WINDOWS\system\WFWNET.DRV
    + 2004-08-04 12:00:00 146,432 ----a-w C:\WINDOWS\system\WINSPOOL.DRV
    - 2007-10-10 23:55:51 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
    + 2008-06-23 16:57:27 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
    + 1999-08-09 22:39:20 14,832 ----a-w C:\WINDOWS\system32\asfsipc.dll
    - 2007-07-31 03:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
    + 2008-07-19 05:10:48 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    + 2008-06-18 03:30:25 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    + 2004-08-04 12:00:00 10,544 ----a-w C:\WINDOWS\system32\comm.drv
    + 2004-11-15 19:40:37 1,731 -c--a-w C:\WINDOWS\system32\config\systemprofile\Application Data\Sonic\Update Manager\sumdb.dat
    + 2005-02-06 02:45:26 2,222,800 ----a-w C:\WINDOWS\system32\d3dx9_24.dll
    + 2005-03-19 00:19:58 2,337,488 ----a-w C:\WINDOWS\system32\d3dx9_25.dll
    + 2005-05-26 22:34:52 2,297,552 ----a-w C:\WINDOWS\system32\d3dx9_26.dll
    + 2005-07-23 02:59:04 2,319,568 ----a-w C:\WINDOWS\system32\d3dx9_27.dll
    + 2005-12-06 01:09:18 2,323,664 ----a-w C:\WINDOWS\system32\d3dx9_28.dll
    + 2006-02-03 15:43:16 2,332,368 ----a-w C:\WINDOWS\system32\d3dx9_29.dll
    + 2006-03-31 19:40:58 2,388,176 ----a-w C:\WINDOWS\system32\d3dx9_30.dll
    + 2006-09-28 23:05:20 2,414,360 ----a-w C:\WINDOWS\system32\d3dx9_31.dll
    + 2006-11-29 20:06:18 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
    + 2004-05-19 19:18:46 221,184 ----a-w C:\WINDOWS\system32\DartSock.dll
    + 2004-05-27 18:08:38 118,784 ----a-w C:\WINDOWS\system32\DartTelnet.dll
    + 2004-08-04 12:00:00 1,788 ----a-w C:\WINDOWS\system32\Dcache.bin
    + 2004-06-09 16:29:56 6,977 ----a-w C:\WINDOWS\system32\DDMI2.sys
    - 2005-09-23 14:28:38 83,456 ----a-w C:\WINDOWS\system32\dfshim.dll
    + 2007-10-24 08:47:28 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll
    + 2006-10-03 02:24:00 487,424 ----a-w C:\WINDOWS\system32\DLLAV32.dll
    - 2007-10-10 23:55:51 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
    + 2008-06-23 16:57:27 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
    - 2004-08-04 12:00:00 138,496 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys
    + 2008-06-20 10:44:38 138,368 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys
    + 2008-06-13 13:10:50 272,128 -c--a-w C:\WINDOWS\system32\dllcache\bthport.sys
    - 2007-07-31 03:19:20 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
    + 2008-07-19 05:10:48 94,920 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
    - 2004-08-04 12:00:00 561,179 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
    + 2008-03-25 04:50:25 554,008 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
    - 2006-06-26 17:37:10 148,480 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
    + 2008-06-20 17:41:10 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
    - 2004-08-04 12:00:00 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
    + 2008-02-20 05:32:43 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
    + 2004-08-04 13:07:58 2,944 -c--a-w C:\WINDOWS\system32\dllcache\drmkaud.sys
    - 2006-10-17 19:58:06 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    + 2008-06-23 16:57:27 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    - 2007-10-10 23:55:51 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    + 2008-06-23 16:57:27 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    - 2005-07-26 04:39:45 243,200 -c--a-w C:\WINDOWS\system32\dllcache\es.dll
    + 2008-07-07 20:32:22 253,952 -c--a-w C:\WINDOWS\system32\dllcache\es.dll
    - 2007-10-10 23:55:51 132,608 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    + 2008-06-23 16:57:27 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    - 2007-06-19 13:31:19 282,112 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
    + 2008-02-20 06:51:05 282,624 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
    - 2007-10-10 23:55:51 63,488 -c--a-w C:\WINDOWS\system32\dllcache\icardie.dll
    + 2008-06-23 16:57:28 63,488 -c--a-w C:\WINDOWS\system32\dllcache\icardie.dll
    - 2007-10-10 10:59:40 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
    + 2008-06-23 09:20:25 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
    - 2007-10-10 23:55:51 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
    + 2008-06-23 16:57:29 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
    - 2007-10-10 23:55:51 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
    + 2008-06-23 16:57:29 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
    - 2007-10-10 05:46:55 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
    + 2008-06-21 05:23:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
    - 2007-10-10 23:55:52 383,488 -c--a-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
    + 2008-06-23 16:57:29 383,488 -c--a-w C:\WINDOWS\system32\dllcache\ieapfltr.dll
    - 2007-10-10 23:55:52 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
    + 2008-06-23 16:57:29 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
    - 2007-10-10 23:55:54 6,065,664 -c--a-w C:\WINDOWS\system32\dllcache\ieframe.dll
    + 2008-06-23 16:57:33 6,066,176 -c--a-w C:\WINDOWS\system32\dllcache\ieframe.dll
    - 2007-10-10 23:55:55 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
    + 2008-06-23 16:57:33 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
    - 2007-10-10 23:55:55 267,776 -c--a-w C:\WINDOWS\system32\dllcache\iertutil.dll
    + 2008-06-23 16:57:34 267,776 -c--a-w C:\WINDOWS\system32\dllcache\iertutil.dll
    - 2007-10-10 10:59:40 13,824 -c--a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
    + 2008-06-23 09:20:26 13,824 -c--a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
    - 2007-10-10 10:59:52 625,152 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
    + 2008-06-23 09:20:52 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
    - 2007-08-21 06:15:44 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
    + 2008-04-11 18:50:43 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
    - 2007-10-10 23:55:56 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2008-06-23 16:57:35 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2004-08-04 12:00:00 2,000 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.drv
    - 2006-08-17 12:28:27 721,920 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
    + 2007-11-07 09:26:56 721,920 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
    + 2004-08-04 12:00:00 2,560 -c--a-w C:\WINDOWS\system32\dllcache\lz32.dll
    + 2004-08-04 12:00:00 73,376 -c--a-w C:\WINDOWS\system32\dllcache\mciavi.drv
    + 2004-08-04 12:00:00 25,264 -c--a-w C:\WINDOWS\system32\dllcache\mciseq.drv
    + 2004-08-04 12:00:00 28,160 -c--a-w C:\WINDOWS\system32\dllcache\mciwave.drv
    + 2004-08-04 12:00:00 2,032 -c--a-w C:\WINDOWS\system32\dllcache\mouse.drv
    - 2004-08-04 12:00:00 181,248 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
    + 2007-12-18 09:51:35 179,584 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
    - 2004-08-04 12:00:00 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll
    + 2008-05-01 14:30:33 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll
    - 2005-06-29 01:46:00 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll
    + 2008-06-24 16:23:05 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll
    - 2004-08-04 12:00:00 294,400 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll
    + 2008-02-26 11:59:50 294,912 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll
    - 2004-08-04 12:00:00 512,029 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
    + 2008-03-25 04:50:28 518,944 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
    - 2004-08-04 12:00:00 319,517 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
    + 2008-03-25 04:50:30 326,432 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
    - 2007-10-10 23:55:56 459,264 -c--a-w C:\WINDOWS\system32\dllcache\msfeeds.dll
    + 2008-06-23 16:57:36 459,264 -c--a-w C:\WINDOWS\system32\dllcache\msfeeds.dll
    - 2007-10-10 23:55:56 52,224 -c--a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    + 2008-06-23 16:57:36 52,224 -c--a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    - 2007-10-30 23:42:28 3,590,656 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    + 2008-06-24 17:57:40 3,592,192 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    - 2007-10-10 23:55:58 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    + 2008-06-23 16:57:39 477,696 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    - 2004-08-04 12:00:00 1,507,356 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
    + 2008-03-25 04:50:34 1,516,568 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
    - 2004-08-04 12:00:00 358,976 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
    + 2008-03-25 04:50:40 355,112 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
    - 2004-08-04 12:00:00 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    + 2008-03-27 08:12:54 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    - 2004-08-04 12:00:00 53,279 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
    + 2008-03-25 04:50:42 60,192 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
    - 2004-08-04 12:00:00 241,693 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
    + 2008-03-25 04:50:42 248,608 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
    - 2004-08-04 12:00:00 213,023 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
    + 2008-03-25 04:50:44 219,936 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
    - 2004-08-04 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
    + 2008-03-25 04:50:45 355,104 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
    - 2007-10-10 23:55:58 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
    + 2008-06-23 16:57:39 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
    - 2004-08-04 12:00:00 421,919 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
    + 2008-03-25 04:50:47 432,928 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
    - 2004-08-04 12:00:00 315,423 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
    + 2008-03-25 04:50:49 322,336 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
    - 2004-08-04 12:00:00 552,989 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
    + 2008-03-25 04:50:52 559,904 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
    - 2004-08-04 12:00:00 258,077 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
    + 2008-03-25 04:50:55 264,992 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
    - 2007-10-10 23:55:59 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
    + 2008-06-23 16:57:40 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
    - 2004-08-04 12:00:00 831,519 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
    + 2008-03-25 04:50:57 838,432 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
    - 2004-08-04 12:00:00 245,248 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll
    + 2008-06-20 17:41:10 245,248 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll
    - 2004-08-04 12:00:00 614,429 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    + 2008-03-25 04:50:58 621,344 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    - 2004-08-04 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
    + 2008-03-25 04:50:58 355,104 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
    + 2004-08-04 12:00:00 2,944 -c--a-w C:\WINDOWS\system32\dllcache\null.sys
    - 2007-10-10 23:55:59 102,400 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
    + 2008-06-23 16:57:40 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
    - 2007-05-17 11:28:05 549,376 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
    + 2007-12-04 18:38:13 550,912 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
    - 2006-10-17 19:58:08 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    + 2008-06-23 16:57:40 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    - 2007-10-29 22:43:03 1,287,680 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
    + 2008-05-07 05:18:48 1,287,680 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
    - 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
    + 2008-05-08 12:28:49 202,752 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
    + 2004-08-04 12:00:00 1,744 -c--a-w C:\WINDOWS\system32\dllcache\sound.drv
    + 2004-08-04 12:00:00 3,360 -c--a-w C:\WINDOWS\system32\dllcache\system.drv
    - 2006-04-20 11:51:50 359,808 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
    + 2008-06-20 10:45:13 360,320 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
    - 2006-08-16 09:37:30 225,664 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
    + 2008-06-20 09:52:06 225,920 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
    + 2004-08-04 12:00:00 4,048 -c--a-w C:\WINDOWS\system32\dllcache\timer.drv
    - 2007-10-10 23:55:59 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
    + 2008-06-23 16:57:40 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
    - 2007-10-10 23:56:00 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2008-06-23 16:57:40 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2004-08-04 12:00:00 2,176 -c--a-w C:\WINDOWS\system32\dllcache\vga.drv
    - 2007-10-10 23:56:00 232,960 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
    + 2008-06-23 16:57:41 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
    + 2004-08-04 12:00:00 13,600 -c--a-w C:\WINDOWS\system32\dllcache\wfwnet.drv
    - 2007-03-08 13:47:48 1,843,584 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
    + 2008-03-19 09:47:00 1,845,248 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
    - 2007-10-10 23:56:00 824,832 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2008-06-23 16:57:41 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2004-08-04 12:00:00 2,864 -c--a-w C:\WINDOWS\system32\dllcache\winsock.dll
    + 2004-08-04 12:00:00 146,432 -c--a-w C:\WINDOWS\system32\dllcache\winspool.drv
    + 2004-08-04 12:00:00 2,112 -c--a-w C:\WINDOWS\system32\dllcache\winspool.exe
    + 2004-08-04 12:00:00 2,736 -c--a-w C:\WINDOWS\system32\dllcache\wowdeb.exe
    - 2007-07-31 03:19:36 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
    + 2008-07-19 05:09:44 563,912 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
    - 2007-07-31 03:19:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
    + 2008-07-19 05:10:42 53,448 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
    - 2007-07-31 03:19:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
    + 2008-07-19 05:09:42 1,811,656 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
    - 2007-07-31 03:19:32 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
    + 2008-07-19 05:09:46 325,832 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
    - 2007-07-31 03:19:28 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
    + 2008-07-19 05:09:44 205,000 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
  • edited October 2008
    + 2003-03-14 19:33:12 114,688 ----a-w C:\WINDOWS\system32\DLLCDA32.dll
    + 2003-03-14 19:33:00 61,440 ----a-w C:\WINDOWS\system32\DLLCDF32.dll
    + 2006-10-03 02:24:00 94,208 ----a-w C:\WINDOWS\system32\DLLCPY32.dll
    + 2006-10-03 02:24:00 163,840 ----a-w C:\WINDOWS\system32\DLLDEV32.dll
    + 2003-03-14 19:32:44 32,768 ----a-w C:\WINDOWS\system32\DLLDIR32.dll
    + 2006-10-03 02:24:00 151,552 ----a-w C:\WINDOWS\system32\DLLDRV32.dll
    + 2003-03-14 19:33:02 45,056 ----a-w C:\WINDOWS\system32\DLLIMG32.dll
    + 2006-10-03 02:24:00 53,248 ----a-w C:\WINDOWS\system32\DLLIO32.dll
    + 2003-03-14 19:32:46 32,768 ----a-w C:\WINDOWS\system32\DLLISO32.dll
    + 2003-03-14 19:32:40 24,576 ----a-w C:\WINDOWS\system32\DLLIX.dll
    + 2003-03-14 19:32:42 32,768 ----a-w C:\WINDOWS\system32\DLLMSC32.dll
    + 2006-10-03 02:24:00 36,864 ----a-w C:\WINDOWS\system32\DLLPNT32.dll
    + 2003-03-14 19:32:44 49,152 ----a-w C:\WINDOWS\system32\DLLPRF32.dll
    + 2003-03-14 19:33:04 53,248 ----a-w C:\WINDOWS\system32\DLLPRJ32.dll
    + 2003-03-14 19:32:50 65,536 ----a-w C:\WINDOWS\system32\DLLPTL32.dll
    + 2003-03-14 19:35:00 40,960 ----a-w C:\WINDOWS\system32\DLLRD32.dll
    + 2006-10-03 02:24:00 188,416 ----a-w C:\WINDOWS\system32\DLLRES32.dll
    + 2003-03-14 19:32:54 57,344 ----a-w C:\WINDOWS\system32\DLLTPO32.dll
    + 2005-03-13 23:54:00 6,656 ----a-w C:\WINDOWS\system32\DLPT2.sys
    + 2008-08-29 17:18:58 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
    - 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
    + 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
    - 2004-08-04 12:00:00 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
    + 2008-02-20 05:32:43 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
    + 2008-08-29 16:53:50 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
    + 2005-02-23 22:58:56 11,776 ----a-w C:\WINDOWS\system32\drivers\afc.sys
    - 2004-08-04 12:00:00 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    + 2008-06-20 10:44:38 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    + 2007-05-30 12:10:42 10,872 ----a-w C:\WINDOWS\system32\drivers\AvgAsCln.sys
    + 2008-06-13 13:10:50 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
    + 2004-08-04 13:07:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
    - 2006-09-19 23:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
    + 2008-04-17 20:12:54 15,464 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
    + 2008-06-22 00:26:05 29,184 ----a-w C:\WINDOWS\system32\drivers\goprot51.sys
    - 2003-09-11 07:36:54 21,060 ----a-w C:\WINDOWS\system32\drivers\iviaspi.sys
    + 2005-09-21 00:27:20 10,368 ----a-w C:\WINDOWS\system32\drivers\iviaspi.sys
    - 2005-05-26 19:01:18 21,344 ----a-w C:\WINDOWS\system32\drivers\lgusbbus.sys
    + 2007-04-09 16:53:24 12,672 ----a-w C:\WINDOWS\system32\drivers\lgusbbus.sys
    - 2005-05-26 19:01:36 38,144 ----a-w C:\WINDOWS\system32\drivers\lgusbdiag.sys
    + 2007-04-09 16:56:22 21,248 ----a-w C:\WINDOWS\system32\drivers\lgusbdiag.sys
    - 2005-06-25 02:36:16 39,036 ----a-w C:\WINDOWS\system32\drivers\lgusbmodem.sys
    + 2007-04-09 16:55:08 22,912 ----a-w C:\WINDOWS\system32\drivers\lgusbmodem.sys
    - 2004-08-04 12:00:00 181,248 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
    + 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
    + 2004-08-04 12:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\null.sys
    + 2008-06-17 04:53:21 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    + 2007-04-18 03:09:28 11,032 ----a-w C:\WINDOWS\system32\drivers\regi.sys
    - 2006-07-13 08:48:58 202,240 -c--a-w C:\WINDOWS\system32\drivers\rmcast.sys
    + 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
    - 2006-04-20 11:51:50 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    + 2008-06-20 10:45:13 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    - 2006-08-16 09:37:30 225,664 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    + 2008-06-20 09:52:06 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    + 2005-01-31 19:54:52 76,672 ----a-w C:\WINDOWS\system32\drivers\vdrv7000.sys
    + 2008-04-17 20:12:54 107,368 -c--a-w C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
    + 2008-04-17 20:12:54 15,464 -c--a-w C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
    + 2007-04-05 22:04:16 17,920 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_AAA6EBF99A29B32284FBE77DCBA5A978B418DB78\motccgp.sys
    + 2007-01-24 02:03:44 7,680 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_AAA6EBF99A29B32284FBE77DCBA5A978B418DB78\motccgpfl.sys
    + 2006-12-07 00:33:54 6,400 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_AAA6EBF99A29B32284FBE77DCBA5A978B418DB78\motswch.sys
    + 2006-11-13 21:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_AAA6EBF99A29B32284FBE77DCBA5A978B418DB78\wdfcoinstaller01005.dll
    + 2007-05-04 23:54:08 22,528 -c--a-w C:\WINDOWS\system32\DRVSTORE\motmodem_73B0B439953C130D8EB59CD7FCAE8E6CAAE33C7B\motmodem.sys
    + 2006-11-13 21:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motmodem_73B0B439953C130D8EB59CD7FCAE8E6CAAE33C7B\wdfcoinstaller01005.dll
    + 2006-07-28 15:10:08 6,144 -c--a-w C:\WINDOWS\system32\DRVSTORE\motodrv_33FDC8751D718FF9BCD2F345588D4E10B502D569\mot_ci.dll
    + 2007-05-05 00:04:04 42,112 -c--a-w C:\WINDOWS\system32\DRVSTORE\motodrv_33FDC8751D718FF9BCD2F345588D4E10B502D569\motodrv.sys
    + 2007-01-24 04:36:20 6,016 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_ABB6512ACA55A7A4E2FA3DE425ED10A6DA3518DB\motfilt.sys
    + 2007-01-24 04:36:28 22,016 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_ABB6512ACA55A7A4E2FA3DE425ED10A6DA3518DB\Motousbnet.sys
    + 2006-12-07 00:33:54 6,400 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_ABB6512ACA55A7A4E2FA3DE425ED10A6DA3518DB\motswch.sys
    + 2006-11-13 21:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_ABB6512ACA55A7A4E2FA3DE425ED10A6DA3518DB\wdfcoinstaller01005.dll
    + 2007-05-04 23:54:08 22,528 -c--a-w C:\WINDOWS\system32\DRVSTORE\motport_6F4CC69E1DFD455E7B0E2326811BDD44A181D021\motport.sys
    + 2006-11-13 21:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motport_6F4CC69E1DFD455E7B0E2326811BDD44A181D021\wdfcoinstaller01005.dll
    + 2008-09-06 05:16:46 36,864 -c--a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_4BA70430CFB145AED5FAD1594679A495A188AB90\usbaapl.sys
    + 2008-09-06 05:16:46 1,900,544 -c--a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_4BA70430CFB145AED5FAD1594679A495A188AB90\usbaaplrc.dll
    + 2005-04-26 20:17:48 643,072 ----a-w C:\WINDOWS\system32\DVDProX2.dll
    - 2006-10-17 19:58:06 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    + 2008-06-23 16:57:27 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    - 2007-10-10 23:55:51 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2008-06-23 16:57:27 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2006-04-19 09:00:00 62,976 ----a-w C:\WINDOWS\system32\E_FD4BCAA.DLL
    + 2006-12-08 10:04:00 76,800 ----a-w C:\WINDOWS\system32\E_FLBCAA.DLL
    + 2006-10-31 08:10:00 51,360 ----a-w C:\WINDOWS\system32\EpPicMgr.dll
    + 2004-03-03 14:10:00 29,114 ----a-w C:\WINDOWS\system32\EPPICPattern1.dat
    + 2004-03-03 14:10:00 27,417 ----a-w C:\WINDOWS\system32\EPPICPattern121.dat
    + 2004-03-03 14:10:00 31,053 ----a-w C:\WINDOWS\system32\EPPICPattern131.dat
    + 2004-03-03 14:10:00 13,280 ----a-w C:\WINDOWS\system32\EPPICPattern2.dat
    + 2004-03-03 14:10:00 21,021 ----a-w C:\WINDOWS\system32\EPPICPattern3.dat
    + 2004-03-03 14:10:00 10,673 ----a-w C:\WINDOWS\system32\EPPICPattern4.dat
    + 2004-03-03 14:10:00 15,670 ----a-w C:\WINDOWS\system32\EPPICPattern5.dat
    + 2004-03-03 14:10:00 4,943 ----a-w C:\WINDOWS\system32\EPPICPattern6.dat
    + 2004-03-03 14:10:00 73,220 ----a-w C:\WINDOWS\system32\EPPICPrinterDB.dat
    + 2006-10-31 08:10:00 51,360 ----a-w C:\WINDOWS\system32\EpPicPrt.dll
    - 2005-07-26 04:39:45 243,200 ----a-w C:\WINDOWS\system32\es.dll
    + 2008-07-07 20:32:22 253,952 ----a-w C:\WINDOWS\system32\es.dll
    + 2006-12-28 08:00:00 208,896 ----a-w C:\WINDOWS\system32\esint7e.dll
    + 2006-12-28 08:00:00 66,560 ----a-w C:\WINDOWS\system32\eswia7e.dll
    + 2006-03-10 08:00:00 3,584 ----a-w C:\WINDOWS\system32\eswiaml.dll
    - 2007-10-10 23:55:51 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2008-06-23 16:57:27 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
    - 2007-08-01 03:13:22 207,304 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    + 2008-04-09 07:36:53 244,720 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    - 2007-06-19 13:31:19 282,112 ----a-w C:\WINDOWS\system32\gdi32.dll
    + 2008-02-20 06:51:05 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
    + 2006-04-02 23:52:08 1,851,546 ----a-w C:\WINDOWS\system32\gdql_lsa.dll
    - 2006-10-04 02:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
    + 2008-04-17 20:12:54 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
    + 2005-11-21 20:17:38 135,168 ----a-w C:\WINDOWS\system32\GoProto.dll
    + 1998-10-16 01:28:16 85,504 ----a-w C:\WINDOWS\system32\HtmlWH.dll
    - 2007-10-10 23:55:51 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
    + 2008-06-23 16:57:28 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
    - 2007-10-10 10:59:40 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
    + 2008-06-23 09:20:25 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
    - 2007-10-10 23:55:51 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
    + 2008-06-23 16:57:29 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
    - 2007-10-10 23:55:51 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
    + 2008-06-23 16:57:29 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
    - 2007-10-10 05:46:55 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
    + 2008-06-21 05:23:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
    - 2007-10-10 23:55:52 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
    + 2008-06-23 16:57:29 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
    - 2007-10-10 23:55:52 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
    + 2008-06-23 16:57:29 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
    - 2007-10-10 23:55:54 6,065,664 ----a-w C:\WINDOWS\system32\ieframe.dll
    + 2008-06-23 16:57:33 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
    - 2007-10-10 23:55:55 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
    + 2008-06-23 16:57:33 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
    - 2007-10-10 23:55:55 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
    + 2008-06-23 16:57:34 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
    - 2007-10-10 10:59:40 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
    + 2008-06-23 09:20:26 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
    - 2007-08-21 06:15:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    + 2008-04-11 18:50:43 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    - 2004-08-24 23:09:18 54,784 ----a-w C:\WINDOWS\system32\Inetwh32.dll
    + 1999-01-28 22:44:20 49,152 ----a-w C:\WINDOWS\system32\Inetwh32.dll
    - 2007-07-12 09:22:00 135,168 ----a-w C:\WINDOWS\system32\java.exe
    + 2008-06-10 08:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
    - 2007-07-12 09:22:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
    + 2008-06-10 08:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
    - 2007-07-12 10:22:38 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
    + 2008-06-10 09:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
    - 2007-10-10 23:55:56 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2008-06-23 16:57:35 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2004-08-04 12:00:00 2,000 ----a-w C:\WINDOWS\system32\keyboard.drv
    + 2004-08-04 12:00:00 221,600 ----a-w C:\WINDOWS\system32\lanman.drv
    - 2006-08-17 12:28:27 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
    + 2007-11-07 09:26:56 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
    + 2004-08-04 12:00:00 2,560 ----a-w C:\WINDOWS\system32\lz32.dll
    + 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
    + 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
    + 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
    - 2007-12-06 02:45:10 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    + 2008-04-25 01:01:39 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    + 2008-06-04 03:41:54 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    + 2008-09-10 20:59:32 32,768 ----a-w C:\WINDOWS\system32\mC02\mC022328.exe
    + 2004-08-04 12:00:00 73,376 ----a-w C:\WINDOWS\system32\mciavi.drv
    + 2004-08-04 12:00:00 25,264 ----a-w C:\WINDOWS\system32\mciseq.drv
    + 2004-08-04 12:00:00 28,160 ----a-w C:\WINDOWS\system32\mciwave.drv
    - 2002-01-05 18:48:16 974,848 ----a-w C:\WINDOWS\system32\mfc70.dll
    + 2002-01-05 21:48:16 974,848 ----a-w C:\WINDOWS\system32\mfc70.dll
    + 2007-04-17 18:56:40 663,552 ----a-w C:\WINDOWS\system32\mgxoschk.dll
    + 2008-07-31 17:24:05 49,244 ---ha-w C:\WINDOWS\system32\mlfcache.dat
    + 2006-07-28 15:10:08 6,144 ----a-w C:\WINDOWS\system32\mot_ci.dll
    + 2004-08-04 12:00:00 2,032 ----a-w C:\WINDOWS\system32\mouse.drv
    + 2001-05-11 21:18:14 420,240 ----a-w C:\WINDOWS\system32\mpg4c32.dll
    - 2007-12-02 23:00:05 18,684,536 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2008-08-26 20:28:12 16,208,504 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2004-08-04 12:00:00 20,480 ----a-w C:\WINDOWS\system32\msacm32.drv
    - 2005-06-29 01:46:00 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    + 2008-06-24 16:23:05 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
    - 2007-04-13 11:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
    + 2007-10-24 08:47:38 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll
    - 2005-09-23 14:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll
    + 2007-10-24 08:47:38 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll
    - 2005-09-23 14:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll
    + 2007-10-24 08:47:38 84,480 ----a-w C:\WINDOWS\system32\mscories.dll
    - 2004-08-04 12:00:00 294,400 ----a-w C:\WINDOWS\system32\MSCTF.dll
    + 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
    - 2004-08-04 12:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll
    + 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll
    - 2004-08-04 12:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll
    + 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll
    - 2007-10-10 23:55:56 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
    + 2008-06-23 16:57:36 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
    - 2007-10-10 23:55:56 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
    + 2008-06-23 16:57:36 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
    + 2004-08-04 12:00:00 188,416 ----a-w C:\WINDOWS\system32\msh261.drv
    + 2004-08-04 19:00:00 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
    - 2007-10-30 23:42:28 3,590,656 ----a-w C:\WINDOWS\system32\mshtml.dll
    + 2008-06-24 17:57:40 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll
    - 2007-10-10 23:55:58 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
    + 2008-06-23 16:57:39 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll
    - 2004-08-04 12:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll
    + 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll
    - 2004-08-04 19:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
    + 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
    - 2004-08-04 12:00:00 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
    + 2008-03-27 08:12:54 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
    - 2004-08-04 12:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll
    + 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll
    - 2004-08-04 12:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll
    + 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll
    - 2004-08-04 12:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll
    + 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
    - 2004-08-04 12:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll
    + 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll
    - 2007-10-10 23:55:58 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
    + 2008-06-23 16:57:39 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
    - 2004-08-04 12:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll
    + 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll
    - 2004-08-04 12:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll
    + 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll
    - 2004-08-04 12:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll
    + 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll
    - 2004-08-04 12:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll
    + 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll
    - 2007-10-10 23:55:59 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
    + 2008-06-23 16:57:40 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
    - 2002-01-05 17:40:20 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
    + 2002-01-05 19:40:18 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
    - 2003-03-19 03:14:52 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
    + 2003-03-19 06:14:52 499,712 ----a-r C:\WINDOWS\system32\msvcp71.dll
    - 2002-01-05 15:37:00 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
    + 2002-01-05 20:37:26 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
    - 2003-02-21 11:42:22 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
    + 2003-02-21 12:42:22 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
    - 2004-08-04 12:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll
    + 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll
    - 2004-08-04 12:00:00 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
    + 2008-06-20 17:41:10 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
    - 2004-08-04 12:00:00 614,429 ----a-w C:\WINDOWS\system32\mswstr10.dll
    + 2008-03-25 04:50:58 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    - 2004-08-04 12:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll
    + 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll
    + 2003-04-19 00:29:26 44,544 ----a-w C:\WINDOWS\system32\msxml4a.dll
    - 2003-04-19 06:29:26 82,432 ----a-w C:\WINDOWS\system32\msxml4r.dll
    + 2003-04-19 00:29:26 82,432 ----a-w C:\WINDOWS\system32\msxml4r.dll
    - 2006-12-22 21:02:36 6,144 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll
    + 2007-10-24 08:47:44 15,360 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll
    + 2006-03-31 23:57:40 430,080 ----a-w C:\WINDOWS\system32\MXRestore.exe
    + 2004-07-06 17:52:10 811,008 ----a-w C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
    + 2004-07-13 17:57:26 1,843,200 ----a-w C:\WINDOWS\system32\NCTAudioFile2.dll
    + 2004-07-13 17:58:10 315,392 ----a-w C:\WINDOWS\system32\NCTAudioPlayer2.dll
    - 2007-10-10 23:55:59 102,400 ----a-w C:\WINDOWS\system32\occache.dll
    + 2008-06-23 16:57:40 102,912 ----a-w C:\WINDOWS\system32\occache.dll
    + 2008-08-29 12:11:24 166,400 ----a-w C:\WINDOWS\system32\offeojxjdbht.dll
    - 2007-05-17 11:28:05 549,376 ----a-w C:\WINDOWS\system32\oleaut32.dll
    + 2007-12-04 18:38:13 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
    - 2007-12-07 04:26:44 63,016 ----a-w C:\WINDOWS\system32\perfc009.dat
    + 2008-04-12 08:08:09 64,200 ----a-w C:\WINDOWS\system32\perfc009.dat
    - 2007-12-07 04:26:44 402,406 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2008-04-12 08:08:09 407,670 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2006-10-21 00:11:04 126,976 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow.scr
    + 2004-04-10 01:19:18 294,912 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\ArtistTitle.dll
    + 2003-06-26 21:54:10 24,576 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\ArtistTitleRes.dll
    + 2006-02-10 19:27:10 167,936 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\dtype32.dll
    + 2006-02-10 19:27:10 155,648 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\dtype32x.dll
    + 2005-12-20 00:09:00 819,200 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\EzDll.dll
    + 2004-12-14 20:00:00 430,080 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\fpxlib.dll
    + 2006-01-24 18:20:00 1,645,320 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\gdiplus.dll
    + 2006-09-18 18:51:00 73,835 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\ImgCtrl.dll
    + 2006-05-30 18:46:44 245,760 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\kgl.dll
    + 2006-11-02 22:35:30 35,584 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagCore.dll
    + 2006-09-30 18:40:24 340,044 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\magengin.dll
    + 2006-09-18 18:43:00 28,672 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\magFileIO.dll
    + 2006-09-18 19:27:00 430,080 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\magFpxio.dll
    + 2005-06-20 22:38:32 98,304 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\maghelpr.dll
    + 2006-11-02 22:34:40 56,064 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagicFrame.dll
    + 2006-11-02 22:28:42 60,160 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagPCMac.dll
    + 2006-09-29 22:55:16 118,784 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\magPltfm.dll
    + 2006-09-18 18:51:00 233,472 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\magTools.dll
    + 2006-11-02 22:29:22 158,464 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagUIEngine.dll
    + 2006-11-02 22:34:54 150,272 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagUIImage.dll
    + 2006-11-02 22:30:26 88,832 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MagUIInter.dll
    + 2005-05-27 23:09:00 1,024,082 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MFC42LU.DLL
    + 2005-05-27 22:58:00 69,632 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MSLUIRT.dll
    + 2005-05-27 22:58:00 393,216 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MSLUP60.dll
    + 2005-05-27 22:58:00 249,856 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\MSLURT.dll
    + 2003-11-12 21:52:10 499,712 ----a-r C:\WINDOWS\system32\PhotoImpression Slideshow\msvcp71.dll
    + 2003-02-21 13:42:22 348,160 ----a-r C:\WINDOWS\system32\PhotoImpression Slideshow\msvcr71.dll
    + 2002-08-30 03:41:08 323,072 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\msvcrt.dll
    + 2006-07-12 17:49:16 614,481 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\RawEngine.dll
    + 2006-09-30 18:34:40 622,592 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\ToolsCtrl.dll
    + 2005-12-07 19:37:00 45,056 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uaswmf.dll
    + 2006-09-11 16:38:28 1,146,880 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uDXPubTool.dll
    + 2006-02-23 23:44:00 888,832 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uEzDll.dll
    + 2004-12-15 01:43:00 245,408 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\unicows.dll
    + 2006-10-20 18:01:44 36,864 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uScreenPlayer.dll
    + 2006-04-21 00:42:08 622,592 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uSlideShow.dll
    + 2006-08-23 00:56:12 1,785,856 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uVDibTool.dll
    + 2006-01-24 21:55:38 372,736 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uVideoLib.dll
    + 2005-03-30 23:25:00 155,648 ----a-w C:\WINDOWS\system32\PhotoImpression Slideshow\uWMVDLL.dll
    + 2006-10-20 08:10:00 108,704 ----a-w C:\WINDOWS\system32\PICEntry.dll
    + 2006-10-20 08:10:00 80,024 ----a-w C:\WINDOWS\system32\PICSDK.dll
    + 2006-10-20 08:10:00 501,912 ----a-w C:\WINDOWS\system32\PICSDK2.dll
    + 2008-09-16 21:59:18 162,834 ----a-w C:\WINDOWS\system32\pin\CONFG32I9.exe
    - 2006-10-17 19:58:08 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-06-23 16:57:40 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-06-17 04:44:58 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
    + 2008-06-17 04:52:55 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    - 2007-10-29 22:43:03 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
    + 2008-05-07 05:18:48 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
    + 2004-08-04 19:00:00 23,552 -c--a-w C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\wdmaud.drv
    + 2008-09-04 20:48:10 402,200 ----a-w C:\WINDOWS\system32\RES\comec130t.exe
    - 2004-08-24 23:09:18 1,044,480 ----a-w C:\WINDOWS\system32\roboex32.dll
    + 2003-07-25 00:01:04 1,044,480 ----a-w C:\WINDOWS\system32\ROBOEX32.DLL
    + 2006-08-01 21:01:08 438,272 ----a-w C:\WINDOWS\system32\SkinCrafter.dll
    + 2008-07-19 05:10:20 36,552 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
    + 2008-07-19 05:10:40 45,768 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.784\wups2.dll
    + 2004-08-04 12:00:00 1,744 ----a-w C:\WINDOWS\system32\sound.drv
    - 2006-09-26 00:58:48 14,640 ----a-w C:\WINDOWS\system32\spmsg.dll
    + 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\system32\spmsg.dll
    + 2007-02-03 02:57:42 202,912 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DUPA20.EXE
    + 2007-01-22 10:00:02 6,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_DUPA2E.DLL
    + 2007-03-01 13:01:00 397,824 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FABRCAA.DLL
    + 2007-03-01 13:01:00 3,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAIFCAA.DAT
    + 2007-01-22 09:02:00 138,752 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAIRCAA.DLL
    + 2006-12-20 13:00:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAMTCAA.EXE
    + 2007-03-02 13:01:00 667,136 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAPRCAA.DLL
    + 2007-01-25 13:00:00 155,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FARNCAA.EXE
    + 2006-11-13 13:00:00 129,536 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FASKCAA.DLL
    + 2007-03-06 08:01:00 454,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FASOCAA.DLL
    + 2007-03-01 13:01:00 64,512 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FASRCAA.DLL
    + 2007-03-01 13:01:00 180,736 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATICAA.EXE
    + 2006-11-13 09:00:00 23,552 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FAUDCAA.DLL
    + 2007-02-21 13:01:00 32,768 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBA6CAA.DLL
    + 2006-11-30 13:12:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBAPCAA.DLL
    + 2006-11-16 09:01:00 176,128 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBCSCAA.EXE
    + 2007-01-30 13:03:00 35,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FBL6CAA.DLL
    + 2006-11-13 12:00:00 458,752 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FCONCAA.DLL
    + 2007-04-10 12:00:00 71,680 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FDSPCAA.DLL
    + 2007-02-26 08:01:00 9,728 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FGEPCAA.DLL
    + 2006-09-21 11:04:00 18,432 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FGRCCAA.DLL
    + 2007-01-24 09:00:00 529,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHBRCAA.DLL
    + 2006-01-23 12:20:00 325,632 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHM0CAA.DLL
    + 2007-01-24 09:00:00 33,792 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHSRCAA.DLL
    + 2005-11-30 12:20:00 212,992 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHT0CAA.DLL
    + 2007-01-22 18:03:00 218,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHUTCAA.DLL
    + 2007-01-22 18:03:00 105,984 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FHUTCAA.EXE
    + 2007-01-10 12:00:00 403,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FJBCCAA.DLL
    + 2007-01-10 13:00:00 119,296 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FMAICAA.DLL
    + 2006-05-18 12:20:00 49,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FMW0CAA.DLL
    + 2005-04-19 02:10:02 258,114 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FOKACAA.DLL
    + 2006-10-31 12:00:00 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FPRECAA.EXE
    + 2006-10-31 12:00:00 626,688 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FPRUCAA.DLL
    + 2006-09-26 12:20:00 997,888 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FSR0CAA.DLL
    + 2006-12-25 15:01:00 723,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FUI1CAA.DLL
    + 2007-01-23 14:00:00 1,401,344 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FUICCAA.DLL
    + 2006-10-30 14:01:00 4,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FUIPCAA.DLL
    + 2007-01-22 15:01:00 187,392 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FUIRCAA.DLL
    + 2007-01-11 12:02:00 113,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S40RP7.EXE
    + 2006-11-30 13:12:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\EBAPI4.DLL
    + 2006-04-19 14:00:00 34,304 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\EBPBIDI.DLL
    + 2007-02-06 10:07:00 296,448 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\EPSET32.DLL
    + 2004-04-21 08:00:00 5,729 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUPDATE.DAT
    + 2006-11-01 14:18:00 723,128 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\EPUPDATE.EXE
    + 2007-02-03 02:57:42 202,912 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_DUPA20.EXE
    + 2007-01-22 10:00:02 6,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_DUPA2E.DLL
    + 2007-03-01 13:01:00 397,824 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FABRCAA.DLL
    + 2007-03-01 13:01:00 3,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FAIFCAA.DAT
    + 2007-01-22 09:02:00 138,752 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FAIRCAA.DLL
    + 2006-12-20 13:00:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FAMTCAA.EXE
    + 2007-03-02 13:01:00 667,136 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FAPRCAA.DLL
    + 2007-01-25 13:00:00 155,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FARNCAA.EXE
    + 2006-11-13 13:00:00 129,536 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FASKCAA.DLL
    + 2007-03-06 08:01:00 454,656 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FASOCAA.DLL
    + 2007-03-01 13:01:00 64,512 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FASRCAA.DLL
    + 2007-03-01 13:01:00 180,736 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FATICAA.EXE
    + 2006-11-13 08:00:00 23,552 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FAUDCAA.DLL
    + 2007-02-21 13:01:00 32,768 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FBA6CAA.DLL
    + 2006-11-30 12:12:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FBAPCAA.DLL
    + 2006-11-16 09:01:00 176,128 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FBCSCAA.EXE
    + 2007-01-30 13:03:00 35,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FBL6CAA.DLL
    + 2006-11-13 11:00:00 458,752 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FCONCAA.DLL
    + 2007-01-10 12:00:00 71,680 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FDSPCAA.DLL
    + 2007-02-26 08:01:00 9,728 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FGEPCAA.DLL
    + 2006-09-21 10:04:00 18,432 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FGRCCAA.DLL
    + 2007-01-24 08:00:00 529,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHBRCAA.DLL
    + 2006-01-23 11:20:00 325,632 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHM0CAA.DLL
    + 2007-01-24 08:00:00 33,792 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHSRCAA.DLL
    + 2005-11-30 11:20:00 212,992 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHT0CAA.DLL
    + 2007-01-22 17:03:00 218,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHUTCAA.DLL
    + 2007-01-22 17:03:00 105,984 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FHUTCAA.EXE
    + 2007-01-10 11:00:00 403,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FJBCCAA.DLL
    + 2007-01-10 12:00:00 119,296 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FMAICAA.DLL
    + 2006-05-18 11:20:00 49,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FMW0CAA.DLL
    + 2005-04-19 01:10:02 258,114 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FOKACAA.DLL
    + 2006-10-31 11:00:00 196,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FPRECAA.EXE
    + 2006-10-31 11:00:00 626,688 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FPRUCAA.DLL
    + 2006-09-26 11:20:00 997,888 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FSR0CAA.DLL
    + 2006-12-25 15:01:00 723,456 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FUI1CAA.DLL
    + 2007-01-23 13:00:00 1,401,344 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FUICCAA.DLL
    + 2006-10-30 13:01:00 4,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FUIPCAA.DLL
    + 2007-01-22 14:01:00 187,392 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_FUIRCAA.DLL
    + 2007-01-11 12:02:00 113,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\E_S40RP7.EXE
    + 2006-11-30 12:12:00 172,032 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\EBAPI4.DLL
    + 2006-04-19 13:00:00 34,304 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\EBPBIDI.DLL
    + 2007-02-06 10:07:00 296,448 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\EPSET32.DLL
    + 2004-04-21 08:00:00 5,729 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\EPUPDATE.DAT
    + 2006-11-01 13:18:00 723,128 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_cx4400f57e\EPUPDATE.EXE
    + 2004-04-21 08:00:00 5,729 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\EPUPDATE.DAT
    + 2006-11-01 14:18:00 723,128 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\EPUPDATE.EXE
  • edited October 2008
    + 2006-10-03 02:24:00 32,768 ----a-w C:\WINDOWS\system32\STRING32.dll
    + 2004-08-04 12:00:00 3,360 ----a-w C:\WINDOWS\system32\system.drv
    + 2004-08-04 12:00:00 4,048 ----a-w C:\WINDOWS\system32\timer.drv
    + 2003-03-14 19:32:54 24,576 ----a-w C:\WINDOWS\system32\TTI32.dll
    + 2003-03-14 19:32:54 24,576 ----a-w C:\WINDOWS\system32\TTIC32.dll
    - 2007-11-13 11:31:11 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
    + 2008-07-14 11:09:18 62,976 ----a-w C:\WINDOWS\system32\tzchange.exe
    - 2007-10-10 23:55:59 105,984 ----a-w C:\WINDOWS\system32\url.dll
    + 2008-06-23 16:57:40 105,984 ----a-w C:\WINDOWS\system32\url.dll
    - 2007-10-10 23:56:00 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2008-06-23 16:57:40 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2004-12-09 18:21:20 73,728 ----a-w C:\WINDOWS\system32\vc7api.dll
    + 2005-11-23 23:17:36 253,952 ----a-w C:\WINDOWS\system32\vc7comm.dll
    + 2005-06-09 22:32:14 278,528 ----a-w C:\WINDOWS\system32\vc7dlg.dll
    + 2004-10-29 15:56:26 24,064 ----a-w C:\WINDOWS\system32\VC7Env.dll
    + 2005-04-19 16:47:48 163,840 ----a-w C:\WINDOWS\system32\vc7extse.dll
    + 2005-05-20 17:30:30 53,248 ----a-w C:\WINDOWS\system32\vc7op.dll
    + 2005-03-02 20:35:06 53,248 ----a-w C:\WINDOWS\system32\vc7perm.dll
    + 2005-06-15 21:03:08 81,920 ----a-w C:\WINDOWS\system32\vc7prop.dll
    + 2005-06-13 17:43:06 77,824 ----a-w C:\WINDOWS\system32\VC7Scsi.dll
    + 2005-02-28 20:01:12 172,032 ----a-w C:\WINDOWS\system32\vc7sec.dll
    + 2004-11-02 18:56:02 49,152 ----a-w C:\WINDOWS\system32\vc7upd.dll
    + 2004-08-04 12:00:00 2,176 ----a-w C:\WINDOWS\system32\vga.drv
    + 2007-03-09 16:37:54 139,264 ----a-w C:\WINDOWS\system32\viscomqtde.dll
    + 2007-03-09 16:36:48 81,920 ----a-w C:\WINDOWS\system32\viscomwave.dll
    + 2004-08-04 19:00:00 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
    - 2007-10-10 23:56:00 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll
    + 2008-06-23 16:57:41 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
    + 2004-08-04 12:00:00 13,600 ----a-w C:\WINDOWS\system32\wfwnet.drv
    - 2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
    + 2008-03-19 09:47:00 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
    - 2007-10-10 23:56:00 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2008-06-23 16:57:41 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2004-08-04 12:00:00 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
    + 2004-08-04 12:00:00 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
    + 2004-08-04 12:00:00 2,112 ----a-w C:\WINDOWS\system32\winspool.exe
    + 1999-08-09 22:40:56 163,600 ----a-w C:\WINDOWS\system32\wmaudsdk.dll
    - 2006-10-19 05:47:20 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
    + 2008-06-25 01:12:58 295,936 ----a-w C:\WINDOWS\system32\wmpeffects.dll
    + 2001-05-17 01:54:44 309,616 ----a-w C:\WINDOWS\system32\wmv8dmod.dll
    + 2007-08-07 19:32:16 57,344 ----a-w C:\WINDOWS\system32\Wnaspint.dll
    + 2004-08-04 12:00:00 2,736 ----a-w C:\WINDOWS\system32\wowdeb.exe
    + 2008-05-05 16:16:46 127,488 ----a-w C:\WINDOWS\system32\wp\xerd2140.exe
    - 2007-07-31 03:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
    + 2008-07-19 05:09:44 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    - 2007-07-31 03:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
    + 2008-07-19 05:10:42 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    - 2007-07-31 03:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
    + 2008-07-19 05:09:42 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    - 2007-07-31 03:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
    + 2008-07-19 05:09:46 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    - 2007-07-31 03:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
    + 2008-07-19 05:09:44 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    + 2006-02-03 15:41:26 14,032 ----a-w C:\WINDOWS\system32\x3daudio1_0.dll
    + 2007-01-08 22:30:42 15,128 ----a-w C:\WINDOWS\system32\x3daudio1_1.dll
    + 2006-02-03 15:42:06 230,096 ----a-w C:\WINDOWS\system32\xactengine2_0.dll
    + 2006-03-31 19:39:48 229,584 ----a-w C:\WINDOWS\system32\xactengine2_1.dll
    + 2006-05-31 14:24:16 230,168 ----a-w C:\WINDOWS\system32\xactengine2_2.dll
    + 2006-07-28 16:30:32 236,824 ----a-w C:\WINDOWS\system32\xactengine2_3.dll
    + 2006-09-28 23:05:56 237,848 ----a-w C:\WINDOWS\system32\xactengine2_4.dll
    + 2006-12-08 19:02:00 251,672 ----a-w C:\WINDOWS\system32\xactengine2_5.dll
    + 2007-01-24 22:27:30 255,848 ----a-w C:\WINDOWS\system32\xactengine2_6.dll
    + 2006-03-31 19:39:24 62,672 ----a-w C:\WINDOWS\system32\xinput1_1.dll
    + 2006-07-28 16:30:14 62,744 ----a-w C:\WINDOWS\system32\xinput1_2.dll
    + 2006-09-28 23:04:02 68,888 ----a-w C:\WINDOWS\system32\xinput1_3.dll
    + 2005-12-06 01:07:30 61,136 ----a-w C:\WINDOWS\system32\xinput9_1_0.dll
    + 1999-12-07 10:03:00 73,216 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ade.dll
    + 1999-04-27 08:17:00 3,136 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ade001.bin
    + 2006-03-10 08:00:00 77,824 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esddc.dll
    + 2006-10-24 08:00:00 188,416 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esdevcl.dll
    + 2006-10-24 08:00:00 131,072 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esdevif.dll
    + 2006-03-08 08:00:00 49,152 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esdscl.dll
    + 2006-12-12 08:00:00 425,984 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esdtr.dll
    + 2006-08-30 08:00:00 94,208 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esdtr2.dll
    + 2006-03-06 08:00:00 172,032 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esfit.dll
    + 2005-09-27 08:00:00 53,248 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esicm.dll
    + 2006-07-05 08:00:00 561,152 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esimfl.dll
    + 2006-10-24 08:00:00 229,376 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esimgctl.dll
    + 2006-08-01 08:00:00 1,658,880 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esimgdet.dll
    + 2006-10-24 08:00:00 348,267 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esmps.dll
    + 2006-03-08 08:00:00 561,272 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esmpsres.dll
    + 2006-04-17 08:00:00 3,555,328 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esres.dll
    + 2006-12-13 08:00:00 327,680 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esscncl.dll
    + 2006-03-08 08:00:00 40,960 ----a-w C:\WINDOWS\twain_32\escndv\es007e\estwm.exe
    + 2006-10-24 08:00:00 249,856 ----a-w C:\WINDOWS\twain_32\escndv\es007e\estwpmg.dll
    + 2006-12-13 08:00:00 675,840 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esui.dll
    + 2006-03-08 08:00:00 126,976 ----a-w C:\WINDOWS\twain_32\escndv\es007e\esutwb.dll
    + 2006-05-26 08:00:00 73,728 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epbmp.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epbmpres.dll
    + 2006-02-15 08:00:00 98,304 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epipd.dll
    + 2006-06-23 08:00:00 151,552 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epjpg.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epjpgres.dll
    + 2006-10-24 08:00:00 94,208 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epmtf.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\epmtfres.dll
    + 2006-10-24 08:00:00 102,400 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppdf.dll
    + 2006-04-17 08:00:00 49,152 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppdfres.dll
    + 2006-05-26 08:00:00 86,016 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppij.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppijres.dll
    + 2006-05-26 08:00:00 86,016 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppit.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eppitres.dll
    + 2006-06-23 08:00:00 94,208 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eptif.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\eptifres.dll
    + 2005-08-29 08:00:00 143,360 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\esexf.dll
    + 2005-08-29 08:00:00 98,304 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\espimtif.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\epbmpres.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\epjpgres.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\epmtfres.dll
    + 2006-04-17 08:00:00 49,152 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\eppdfres.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\eppijres.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\eppitres.dll
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\es007e\ffmt\local\eptifres.dll
    + 2006-03-08 08:00:00 561,272 ----a-w C:\WINDOWS\twain_32\escndv\es007e\local\esmpsres.dll
    + 2006-04-17 08:00:00 3,555,328 ----a-w C:\WINDOWS\twain_32\escndv\es007e\local\esres.dll
    + 2006-03-08 08:00:00 118,784 ----a-w C:\WINDOWS\twain_32\escndv\escndv.exe
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\escndvrs.dll
    + 2006-03-08 08:00:00 40,960 ----a-w C:\WINDOWS\twain_32\escndv\estwm.exe
    + 2006-03-08 08:00:00 45,056 ----a-w C:\WINDOWS\twain_32\escndv\local\escndvrs.dll
    + 2000-08-31 15:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
    + 2008-04-12 08:07:47 8,192 ----a-w C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2005-09-23 06:49:12 95,744 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
    + 2007-10-24 08:47:56 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcm80.dll
    + 2007-10-24 08:47:56 558,080 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll
    + 2007-10-24 08:47:56 635,904 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll
    + 2006-06-05 22:14:28 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
    + 2006-06-05 22:14:28 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
    + 2006-06-05 22:14:28 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
    + 2005-09-23 08:16:02 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
    + 2005-09-23 08:16:06 1,079,808 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
    + 2005-09-23 08:16:08 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
    + 2005-09-23 08:16:10 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
    + 2005-09-23 07:58:06 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
    + 2005-09-23 07:58:06 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
    + 2005-09-23 07:58:06 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
    + 2005-09-23 07:58:06 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
    + 2005-09-23 07:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
    + 2005-09-23 07:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
    + 2005-09-23 07:58:06 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
    + 2005-09-23 07:58:06 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
    + 2005-09-23 07:58:06 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
    + 2005-09-23 08:35:10 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
    + 2008-04-15 17:54:19 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
    - 2007-12-07 04:24:24 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2008-04-12 08:07:57 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    - 2007-12-07 04:24:24 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2008-04-12 08:07:57 113,664 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    + 2000-08-31 15:00:00 68,096 ----a-w C:\WINDOWS\zip.exe
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a209a7c6-3e7c-8276-94d1-13daf7e173bd}]
    2008-08-29 05:11 166400 --a
    C:\WINDOWS\system32\offeojxjdbht.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yaboik"="C:\Documents and Settings\Compaq_Owner\My Documents\A?pPatch\?xplorer.exe" [?]
    "Mpnv"="C:\WINDOWS\system32\?dobe\?hkdsk.exe" [?]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "{5edbf857-26da-2a2d-4ca3-519e74cf546d}"="C:\WINDOWS\system32\offeojxjdbht.dll" [2008-08-29 166400]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=waxkfq.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
    backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
    backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
    backup=C:\WINDOWS\pss\Image Transfer.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Compaq Organize.lnk]
    path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Compaq Organize.lnk
    backup=C:\WINDOWS\pss\Compaq Organize.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a
    2008-09-08 23:02 289576 C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Corel\\DVD9\\WinDVD.exe"=
    "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA20.EXE"=
    "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4 Demo\\Civilization4.exe"=
    "C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    R1 vdrv7000;vdrv7000;C:\WINDOWS\system32\DRIVERS\vdrv7000.sys [2005-01-31 76672]
    R2 PSI_SVC_2;Protexis Licensing V2;C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
    R2 regi;regi;C:\WINDOWS\system32\drivers\regi.sys [2007-04-17 11032]
    R2 VC7SecS;Virtual CD v7 Management Service;C:\Program Files\HHVcdV7Sys\VC7SecS.exe [2005-11-24 106496]
    S4 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3afa4cc1-3d8d-11dc-a85b-0011d805b895}]
    \Shell\AutoRun\command - H:\system\viewer\Viewer.exe
    \Shell\View your videos\command - H:\system\viewer\Viewer.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{0FB6138D-0CA5-4EA5-A46F-86DFE700A287} - C:\WINDOWS\system32\ssqQkhfF.dll
    BHO-{1BC9B244-A35D-40D3-B181-EC778E349E0D} - (no file)
    BHO-{30EC3838-C860-463B-9211-807D5195F06E} - (no file)
    BHO-{4a96e9ff-a4cb-49c5-8975-20550fc47a6f} - C:\WINDOWS\system32\waxkfq.dll
    BHO-{5F6E5BDB-1442-45B7-B0C9-E927035A7415} - (no file)
    BHO-{68A59E49-20D8-0B5B-8C3B-5DC0705987C1} - C:\WINDOWS\system32\zlsmp.dll
    BHO-{6B221E01-F517-4959-8C41-81948E7F2F17} - (no file)
    BHO-{759B1EEC-8289-4D01-AFD5-B3ADF6728470} - (no file)
    BHO-{7CD8A910-22B6-434B-AF8A-9837ADCA1B62} - (no file)
    BHO-{8542ADAA-B3BF-454E-AAA3-CB20F764D664} - (no file)
    BHO-{9A1DB4EE-2DB6-4F12-B5DA-5DF09154D30F} - (no file)
    BHO-{AB16ED6F-5DAB-7676-AC3C-7DA296B649CA} - (no file)
    BHO-{AD10BF3E-5DF0-7826-AC3C-7DA296B518CA} - (no file)
    BHO-{AD40BB34-5CAF-7672-AC3C-7DA296B64BCB} - (no file)
    BHO-{AF41E168-01AD-792B-FF3C-7DA296B542C8} - (no file)
    BHO-{B61FC97E-8605-402C-997C-BEA9B3A6B094} - (no file)
    BHO-{BD04EB49-E758-4C2D-A1A0-3961F29374BB} - (no file)
    BHO-{c73b807f-a2cf-4156-91de-fcf58fa98b70} - (no file)
    BHO-{EF18E2FB-C141-437D-A7C0-D38B7F5A9732} - (no file)
    BHO-{FB44E06F-00AD-2D27-AA3C-7DA296B51FCE} - (no file)
    HKCU-Run-Srro - C:\PROGRA~1\COMMON~1\FNTS~1\nopdb.exe
    HKLM-Run-14a3ebe6 - C:\WINDOWS\system32\ijmwfgfy.dll
    HKLM-Run-BM1790d87a - C:\WINDOWS\system32\umxxthbk.dll
    MSConfigStartUp-AIM - C:\Program Files\AIM\aim.exe
    MSConfigStartUp-AOL Spyware Protection - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    MSConfigStartUp-AOLDialer - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    MSConfigStartUp-HostManager - C:\Program Files\Common Files\AOL\1132185535\ee\AOLHostManager.exe
    MSConfigStartUp-WT GameChannel - C:\Program Files\WildTangent\Apps\GameChannel.exe


    .
    Supplementary Scan
    .
    FireFox -: Profile - C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\hkm924et.default\
    FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
    FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
    FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-01 17:53:31
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vdrv7000]
    "ImagePath"="system32\DRIVERS\vdrv7000.sys"
    .
    Other Running Processes
    .
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    .
    **************************************************************************
    .
    Completion time: 2008-10-01 17:59:46 - machine was rebooted [Compaq_Owner]
    ComboFix-quarantined-files.txt 2008-10-02 00:59:42
    ComboFix2.txt 2007-12-21 22:26:53

    Pre-Run: 122,849,583,104 bytes free
    Post-Run: 123,729,530,880 bytes free

    2088 --- E O F --- 2008-09-11 06:54:12
  • edited October 2008
    Hello,

    P2P Warning!

    IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

    LimeWire

    P2P programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P programme is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured programme.

    This article from InfoWorld illustrates perfectly the dangers of a poorly configured P2P program.
    http://www.infoworld.com/article/07/09/06/Seattle-man-arrested-for-p-to-p-ID-theft_1.html

    Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

    When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

    Note: It is pretty much certain that if you continue to use P2P programs, then you will get infected again.

    I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

    If you wish to keep it, please do not use it until your computer is cleaned.


    Disable Spybot's TeaTimer. This is a two step process.

    Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

    First step:
    • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
    • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
    • If you have Version 1.4, Click on Exit Spybot S&D Resident
    Second step, For Either Version :
    • Open Spybot S&D
    • Click Mode, choose Advanced Mode
    • Go To the bottom of the Vertical Panel on the Left, Click Tools
    • then, also in left panel, click Resident shows a red/white shield.
    • If your firewall raises a question, say OK
    • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
    • OK any prompts.
    • Use File, Exit to terminate Spybot
    • Reboot your machine for the changes to take effect.
    Don't forget to re-enable it, when your computer is clean.


    Download and Run OTMoveIt3

    Download OTMoveIt3 by Old Timer and save it to your Desktop.
    • Double-click OTMoveIt3.exe. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
    • Copy the lines in the codebox below.
    :files
    C:\Documents and Settings\Compaq_Owner\My Documents\A?pPatch /u
    C:\WINDOWS\system32\?dobe /u
    
    :commands
    [purity]
    [emptytemp]
    
    • Return to OTMoveIt3, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.
    • Close OTMoveIt3


    Run a custom CFScript

    1. Close any open browsers.

    2. Open notepad and copy/paste the text in the quotebox below into it:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\zpdilktkhogz.exe
    C:\WINDOWS\TWFyaWEgUml2ZXJh\nqIVuqH0oA5ZtrL1.vbs
    C:\WINDOWS\system32\offeojxjdbht.dll
    C:\WINDOWS\system32\waxkfq.dll
    
    Folder::
    C:\Program Files\OINAnalytics
    C:\WINDOWS\TWFyaWEgUml2ZXJh
    C:\Program Files\Mjcore
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a209a7c6-3e7c-8276-94d1-13daf7e173bd}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yaboik"=-
    "Mpnv"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "{5edbf857-26da-2a2d-4ca3-519e74cf546d}"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    DirLook::
    C:\WINDOWS\system32\wp
    C:\WINDOWS\system32\RES
    C:\WINDOWS\system32\pin
    C:\WINDOWS\system32\np5
    C:\WINDOWS\system32\mC02
    

    Save this as CFScript.txt, in the same location as ComboFix.exe


    CFScriptB-4.gif

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at "C:\ComboFix.txt"

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall



    Please post the following:
    • The OTMoveIt3 log
    • The ComboFix log
    • A fresh HijackThis log
  • edited October 2008
    here are the logs you asked for

    moveit:
    ========== FILES ==========
    File/Folder C:\Documents and Settings\Compaq_Owner\My Documents\A?pPatch not found.
    File/Folder C:\WINDOWS\system32\?dobe not found.
    ========== COMMANDS ==========
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Java cache emptied.
    FireFox cache emptied.
    Temp folders emptied.

    OTMoveIt3 by OldTimer - Version 1.0.3.1 log created on 10032008_173531





    combofix:
    ComboFix 08-10-01.02 - Compaq_Owner 2008-10-03 17:38:39.4 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.186 [GMT -7:00]
    Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    C:\WINDOWS\system32\offeojxjdbht.dll
    C:\WINDOWS\system32\waxkfq.dll
    C:\WINDOWS\system32\zpdilktkhogz.exe
    C:\WINDOWS\TWFyaWEgUml2ZXJh\nqIVuqH0oA5ZtrL1.vbs
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\Mjcore
    C:\Program Files\OINAnalytics
    C:\WINDOWS\system32\offeojxjdbht.dll
    C:\WINDOWS\system32\zpdilktkhogz.exe
    C:\WINDOWS\TWFyaWEgUml2ZXJh
    C:\WINDOWS\TWFyaWEgUml2ZXJh\nqIVuqH0oA5ZtrL1.vbs

    .
    ((((((((((((((((((((((((( Files Created from 2008-09-04 to 2008-10-04 )))))))))))))))))))))))))))))))
    .

    2008-10-03 17:35 . 2008-10-03 17:35 <DIR> d
    C:\_OTMoveIt
    2008-10-02 17:37 . 2008-10-02 17:38 <DIR> d
    C:\Program Files\Frets on Fire
    2008-10-02 17:30 . 2008-10-02 17:30 0 --ah
    C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2008-10-02 17:30 . 2008-10-02 17:30 0 --ah
    C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
    2008-09-27 12:23 . 2008-09-27 12:24 <DIR> d
    C:\Documents and Settings\All Users\Application Data\WinZip
    2008-09-23 22:36 . 2008-09-23 22:36 <DIR> d
    C:\Program Files\Panda Security
    2008-09-18 01:22 . 2008-09-18 01:22 <DIR> d
    C:\Program Files\TeaTimer (Spybot - Search & Destroy)
    2008-09-17 00:22 . 2008-09-17 00:22 <DIR> d
    C:\Documents and Settings\LocalService\Application Data\Apple Computer
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\wp
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\RES
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\pin
    2008-09-17 00:07 . 2008-09-18 18:03 <DIR> d
    C:\WINDOWS\system32\np5
    2008-09-17 00:07 . 2008-09-17 00:07 <DIR> d
    C:\WINDOWS\system32\mC02
    2008-09-17 00:07 . 2008-09-17 00:08 <DIR> d
    C:\temp\mtc2
    2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
    C:\Program Files\iTunes
    2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
    C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-09-11 00:35 . 2008-09-11 00:35 <DIR> d
    C:\Program Files\Bonjour
    2008-09-11 00:34 . 2008-09-11 00:34 <DIR> d
    C:\Program Files\QuickTime
    2008-09-11 00:32 . 2008-09-05 22:16 1,900,544 --a
    C:\WINDOWS\system32\usbaaplrc.dll
    2008-09-11 00:32 . 2008-09-05 22:16 36,864 --a
    C:\WINDOWS\system32\drivers\usbaapl.sys
    2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a
    C:\WINDOWS\system32\QuickTimeVR.qtx
    2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a
    C:\WINDOWS\system32\QuickTime.qts
    2008-09-04 22:51 . 2008-09-04 22:53 <DIR> d
    C:\Program Files\V CAST Music with Rhapsody

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-03 08:01
    d
    w C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
    2008-09-28 19:49
    d
    w C:\Program Files\Safari
    2008-09-23 04:38
    d
    w C:\Program Files\LimeWire
    2008-09-21 00:16
    d
    w C:\Program Files\Spybot - Search & Destroy
    2008-09-19 03:32
    d
    w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-09-18 15:51 28,106 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
    2008-09-18 06:41
    d
    w C:\Program Files\Java
    2008-09-11 07:37
    d
    w C:\Program Files\iPod
    2008-09-11 07:34
    d
    w C:\Program Files\Common Files\Apple
    2008-09-05 05:52
    d
    w C:\Program Files\Real
    2008-09-03 04:22
    d
    w C:\Program Files\Verizon Wireless
    2008-08-23 07:15
    d
    w C:\Program Files\Microsoft Silverlight
    2008-08-22 03:15
    d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-08-06 16:35
    d
    w C:\Program Files\Apple Software Update
    2008-07-14 19:29 88 --sha-r C:\Documents and Settings\All Users\Application Data\53D7D18ABC.sys
    2008-07-14 19:29 2,516 --sha-w C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
    2008-07-11 02:44 606,848 ----a-w C:\WINDOWS\flashax.exe
    2008-07-11 02:44 12,288 ----a-w C:\WINDOWS\impborl.dll
    2008-04-29 05:05 69,832 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\GDIPFONTCACHEV1.DAT
    2006-08-17 03:20 184,808 -c--a-w C:\Documents and Settings\Guest\Application Data\shb.dat
    2006-06-23 17:39 1,820 -c--a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
    .

    (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    ---- Directory of C:\WINDOWS\system32\mC02 ----

    2008-09-10 13:59 32768 --a
    C:\WINDOWS\system32\mC02\mC022328.exe

    ---- Directory of C:\WINDOWS\system32\np5 ----


    ---- Directory of C:\WINDOWS\system32\pin ----

    2008-09-16 14:59 162834 --a
    C:\WINDOWS\system32\pin\CONFG32I9.exe

    ---- Directory of C:\WINDOWS\system32\RES ----

    2008-09-04 13:48 402200 --a
    C:\WINDOWS\system32\RES\comec130t.exe

    ---- Directory of C:\WINDOWS\system32\wp ----

    2008-05-05 09:16 127488 --a
    C:\WINDOWS\system32\wp\xerd2140.exe


    ((((((((((((((((((((((((((((( snapshot_2008-10-01_17.59.14.12 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2007-07-31 03:18:40 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
    + 2008-07-19 05:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
    + 2006-11-02 14:22:54 492,000
    w C:\WINDOWS\system32\drivers\wdf01000.sys
    + 2006-11-02 14:22:52 32,224
    w C:\WINDOWS\system32\drivers\wdfldr.sys
    + 2007-08-29 00:05:12 55,808 ----a-w C:\WINDOWS\system32\drivers\xusb21.sys
    - 2006-09-26 00:58:48 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
    + 2006-10-09 04:51:14 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
    + 2006-11-02 23:09:50 1,419,232 ----a-w C:\WINDOWS\system32\WdfCoInstaller01005.dll
    - 2007-07-31 03:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
    + 2008-07-19 05:10:20 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    - 2007-07-31 03:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
    + 2008-07-19 05:10:40 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
    backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
    backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
    backup=C:\WINDOWS\pss\Image Transfer.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Compaq Organize.lnk]
    path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Compaq Organize.lnk
    backup=C:\WINDOWS\pss\Compaq Organize.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
    path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a
    2008-09-08 23:02 289576 C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Corel\\DVD9\\WinDVD.exe"=
    "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA20.EXE"=
    "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4 Demo\\Civilization4.exe"=
    "C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    R1 vdrv7000;vdrv7000;C:\WINDOWS\system32\DRIVERS\vdrv7000.sys [2005-01-31 76672]
    R2 PSI_SVC_2;Protexis Licensing V2;C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
    R2 regi;regi;C:\WINDOWS\system32\drivers\regi.sys [2007-04-17 11032]
    R2 VC7SecS;Virtual CD v7 Management Service;C:\Program Files\HHVcdV7Sys\VC7SecS.exe [2005-11-24 106496]
    S4 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3afa4cc1-3d8d-11dc-a85b-0011d805b895}]
    \Shell\AutoRun\command - H:\system\viewer\Viewer.exe
    \Shell\View your videos\command - H:\system\viewer\Viewer.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-03 17:45:49
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vdrv7000]
    "ImagePath"="system32\DRIVERS\vdrv7000.sys"
    .
    Other Running Processes
    .
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\ComboFix\pv.cfexe
    .
    **************************************************************************
    .
    Completion time: 2008-10-03 17:50:42 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-10-04 00:50:40
    ComboFix2.txt 2008-10-02 00:59:47
    ComboFix3.txt 2007-12-21 22:26:53

    Pre-Run: 121,423,675,392 bytes free
    Post-Run: 121,415,663,616 bytes free

    179 --- E O F --- 2008-10-02 07:30:44






    hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:21:22 PM, on 10/4/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HHVcdV7Sys\VC7SecS.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

    --
    End of file - 3249 bytes
  • edited October 2008
    Hi,

    Please run another custom CFScript

    1. Close any open browsers.

    2. Open notepad and copy/paste the text in the quotebox below into it:
    KILLALL::
    
    Folder::
    C:\WINDOWS\system32\wp
    C:\WINDOWS\system32\RES
    C:\WINDOWS\system32\pin
    C:\WINDOWS\system32\np5
    C:\WINDOWS\system32\mC02
    C:\temp\mtc2
    

    Save this as CFScript.txt, in the same location as ComboFix.exe


    CFScriptB-4.gif

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at "C:\ComboFix.txt"

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall



    Next,

    Please go to Kaspersky website and perform an online antivirus scan.
    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
        Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
        Mail databases
      [*]Click on My Computer under Scan.
      [*]Once the scan is complete, it will display the results. Click on View Scan Report.
      [*]You will see a list of infected items there. Click on Save Report As....
      [*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
      [*]Please post this log in your next reply along with a fresh HijackThis log and a description of how your computer is behaving.
    5. edited October 2008
      My computer is actually doing a lot better. very few pop ups and the search engines are working. it's a little slow but its close to what it was before. here is the two logs you asked for

      KASPERSKY ONLINE SCANNER 7 REPORT
      Sunday, October 5, 2008
      Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
      Kaspersky Online Scanner 7 version: 7.0.25.0
      Program database last update: Sunday, October 05, 2008 22:11:22
      Records in database: 1293379

      Scan settings:
      Scan using the following database: extended
      Scan archives: yes
      Scan mail databases: yes

      Scan area - My Computer:
      C:\
      D:\
      E:\
      F:\
      G:\
      H:\
      I:\
      J:\
      K:\

      Scan statistics:
      Files scanned: 107767
      Threat name: 74
      Infected objects: 448
      Suspicious objects: 0
      Duration of the scan: 02:37:08


      File name / Threat name / Threats count
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\011F76FD.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01307EC6.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\013328C2.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\013752BF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.af 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\013A7CBB.exe Infected: Trojan.Win32.Stervis.h 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0197335D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01FE2965.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0292410C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\02F93714.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\035030C8.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03BF1D4C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\059B5A71.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\05AF504D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\05B27A49.exe Infected: Trojan-Downloader.Win32.Intexp.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\06C072AF.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\06DC7935.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07B00F9C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\087C7BAB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\08E271B2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09463F0B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\094867BA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\094D1303.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09503D00.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\095466FC.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\095710F9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\095A3AF5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\095D64F1.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09610EEE.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\096438EA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\096A0CE3.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.j 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\097160DC.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09740AD8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.n 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\098806C3.exe Infected: Trojan.Win32.Stervis.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0A8203D8.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B8153D0.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0CBB2C6D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0CE55339.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D286F5C.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D486B8D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D7F73BF.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D8E6563.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E7E43B7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E897313.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0F4F594A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0F5E0F6B.htm Infected: Exploit.HTML.Mht 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0F7E13AF.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0FB54F52.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\107D63A7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\114F3A42.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\117C339F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13056DC5.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13404B9A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13A641A2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\14722DB1.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\14D823B8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\153F19C0.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17B93889.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\188573D4.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\191E2162.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1970601E.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1A192F11.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ADF1549.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B460B50.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1CA836C7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ED00799.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F2D6256.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F367DA0.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F9D73A8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA545D0.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\200369AF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20695FB7.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20CF55BF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\22832A71.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23DC1088.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2496551A.tmp Infected: Trojan-Dropper.Win32.Agent.hl 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\24AF5D61.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\259954AF.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\25AA6B10.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26C517CC.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26D6474F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29642E3F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A614397.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2AC7399F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2B9325AE.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2BF91BB6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2C5F11BD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CBA3E3C.tmp Infected: Trojan-Dropper.Win32.Agent.hl 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CBD6838.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CD57026.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DE569C8.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2ECF4474.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\303F195F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3046320D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30A50F67.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30FA2EAE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30FB4732.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.v 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30FF712F.exe Infected: Trojan-Downloader.Win32.Intexp.e 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31054527.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31086F24.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\313A270E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31A01D16.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31C14940.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3266034E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\327A55AA.exe Infected: Trojan-Downloader.Win32.Intexp.e 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\34006E3E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.l 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35063BC3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3657759E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36BD6BA5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\372361AD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\378957B4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37914F6A.exe Infected: Trojan.Win32.Poler.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\379B4D60.exe Infected: not-a-virus:AdWare.Win32.Bestofer.d 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37B9473F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ai 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A4869EA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A4B13E6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A4F3DE3.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A5267DF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A5511DC.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A583BD8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A5C65D4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A5F0FD1.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A6239CD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A690DC6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A6F61BF.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A730BBB.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A730BBB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3AD0628D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B637E8D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BCF555E.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C354B65.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CCA630D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3DEA3DD0.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3DF73F4C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3E5B0831.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB22158.exe Infected: Trojan-Downloader.Win32.Intexp.e 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB97551.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40CF032B.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\41E7319C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\424E27A4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\42B41DAB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\431A13B3.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\438009BA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45926C5F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4595165C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45994058.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\459C6A55.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\459F1451.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A23E4D.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.e 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A23E4D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A6684A Infected: Trojan-Downloader.Win32.Small.abd 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A6684A.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.e 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A7331C.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A91246.dll Infected: Trojan-Downloader.Win32.IstBar.gen 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45A91246.exe Infected: not-a-virus:AdWare.Win32.WinAD.aw 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AB5D18.dll Infected: not-a-virus:AdWare.Win32.HotSearchBar.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AC3C43.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AC3C43.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AF663F.dll Infected: not-a-virus:AdWare.Win32.Beginto.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45AF663F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45C0382D.exe Infected: Trojan-Downloader.Win32.Intexp.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\46601E8B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\46F33A8B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4760115D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47C60764.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47EF5527.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48C11513.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4A123261.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B016BD4.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C003BCB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C0869CE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4D000BC3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4D786D9B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4DDE63A2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4DFF5BBB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E4459AA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4EAA4FB2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4EFE2BB3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F102722.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F792BB5.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FFD7BAB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\50FC4BA3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51FC1B9B.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5284768A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\52E96D9C.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\533E2D02.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ao 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\53472AF7.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\53564363.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\54515112.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5517374A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5630791E.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\563A26F2.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\565A2F83.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\596E1FA1.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59B21940.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.au 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59CB716A.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59D415A9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A7A7802.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.au 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A7E21FE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A814BFB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A8475F7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A881FF4.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A8B49F0.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A8E73EC.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A911DE9.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A9547E5.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A9871E2.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A9B1BDE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A9E45DB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AA101B8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AA26FD7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AA519D3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AA843D0.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AAB6DCC.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AAF17C9.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AB241C5.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.i 1
    6. edited October 2008
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5D3B3351.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5D504B1A.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EAB012B.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EAB012B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EAF2B28.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB25524.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB57F21.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB8291D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EBC5319.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EBF7D16.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EC22712.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EC5510F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EC97B0B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ECC2507.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ECF4F04.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ED37900.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ED622FD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ED94CF9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EDC76F5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE020F2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE34AEE.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE67F61.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE91EE7.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE91EE7.exe Infected: not-a-virus:AdWare.Win32.WinAD.bw 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EED48E4.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EED48E4.exe Infected: Trojan.Win32.Stervis.d 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60A87348.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\610E6950.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62631B83.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62D30677.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.t 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62D73073.exe Infected: Trojan.Win32.Stervis.j 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64711D16.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64986598.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\656551A7.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68CE0DDB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\693F643B.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\69D3640F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A6763E3.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A773B60.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6ADD3168.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.t 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AFB63B7.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B72490F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B8F638B.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BD83F17.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C23635F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CB76333.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6D4B6307.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6DDF62DB.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6E7362AE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6E8B1013.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6E9E0646.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70292197.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\702E622A.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\703A647D.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\708F179E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70C261FE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70F50DA6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\715661D2.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\715B03AD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71861803.dll Infected: Trojan-Downloader.Win32.Small.bpk 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71C179B5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71EA61A6.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72276FBD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\728E2636.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72915032.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72957A2E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7298242B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\729B4E27.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\729E7824.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72A22220.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72A54C1C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72A87619.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72AB2015.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72AF4A12.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72B2740E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72B51E0A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72B84807.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72BC7203.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72BF1C00.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.i 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72C66FF8.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72C66FF8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72C66FF8.tmp Infected: Trojan-Downloader.Win32.Apropo.ae 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72C919F5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.l 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73587A81.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73E25052.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73E57A4E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73E8244B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73EB4E47.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73EF7843.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73F22240.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73F54C3C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73F87639.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73FC2035.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73FF4A32.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7402742E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74051E2A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74094827.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\740C7223.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\740F1C20.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7413461C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74167018.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74191A15.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\741C4411.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74206E0E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7423180A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74264206.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74296C03.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\742D15FF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74303FFC.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\743369F8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\743613F4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\743A3DF1.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\743D67ED.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\744011EA.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74443BE6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\744765E2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\744A0FDF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\744D39DB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\745163D8.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74540DD4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\745737D0.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\745A61CD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\745E0BC9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\746135C6.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74645FC2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\746709BF.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\746B33BB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\746E5DB7.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\747107B4.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\747431B0.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74785BAD.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\747B05A9.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\747E2FA5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\748259A2.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7485039E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74882D9B.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\748B5797.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\748F0193.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74922B90.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74953FCE.dll Infected: not-a-virus:AdWare.Win32.ImiBar.h 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7495558C.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74987F89.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\749C13C7.dll Infected: not-a-virus:AdWare.Win32.ActivShopper.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\749C2985.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\749F5381.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74A27D7E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74A5277A.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74A95177.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74AC7B73.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74AF256F.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74B34F6C.exe Infected: Trojan-Downloader.Win32.Intexp.d 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74F7026C.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\75352A86.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.a 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\75943298.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.am 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7607775F.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\766D6D66.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7702050E.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\775A3679.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77C86B45.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77C86B45.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.r 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\782E614D.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78FE6B13.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A1E00D5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.t 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7AB404A4.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B7910DE.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7BB95D95.exe Infected: Trojan-Downloader.Win32.Intexp.c 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C5C149F.dll Infected: not-a-virus:AdWare.Win32.ClientMan 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C8549A5.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.u 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DB82BBB.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ah 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7E7B0875.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7FDF6EE1.tmp Infected: not-a-virus:AdWare.Win32.BetterInternet.b 1
      C:\Documents and Settings\Compaq_Owner\Desktop\Setup.exe Infected: not-a-virus:AdTool.Win32.Zango.e 1
      C:\Documents and Settings\Compaq_Owner\Incomplete\T-5745425-system of a down attack.mp3 Infected: Trojan-Downloader.WMA.Wimad.n 1
      C:\Program Files\Morpheus\morpheustoolbar.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.bm 1
      C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
      C:\qoobox\Quarantine\C\WINDOWS\faceback.exe.vir Infected: Trojan-Downloader.Win32.Agent.agcd 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\aximqj.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.efv 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\binxpe.dll.vir Infected: Trojan.Win32.Monder.pse 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\bmjbjpur.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alee 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\bvsvmhpc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alvf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\cbXOGXRk.dll.vir Infected: Trojan.Win32.Monder.oqh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\cgveoj.dll.vir Infected: Trojan.Win32.Monder.png 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\djtxporv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\DOBE~1\сhkdsk.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.jw 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\rasptii.sys.vir Infected: Rootkit.Win32.Agent.aol 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\eqcxywpv.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\eyymhodc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alvi 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ffhfkhwf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\fhgftgjc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alqn 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\fifpeuis.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\foxlagsr.dll.vir Infected: Trojan.Win32.Monder.png 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\gamtxunv.dll.vir Infected: Trojan.Win32.BHO.hj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\grhiiflh.dll.vir Infected: Trojan.Win32.Monder.qdo 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hhbrlrbn.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hiyuxggi.dll.vir Infected: Trojan.Win32.Monder.qdo 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hmotvnsj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alrx 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hmvjghvw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hravbfcr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alqn 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\hxnhawln.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ihscynvh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alqc 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\iifggdDV.dll.vir Infected: Trojan.Win32.Monder.psf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\iqntiscb.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ixpospuj.dll.vir Infected: Trojan.Win32.Monder.psg 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\jbmehdag.dll.vir Infected: Trojan.Win32.BHO.hj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\jikbnlln.dll.vir Infected: Trojan.Win32.Monder.qwn 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\jlhouldu.dll.vir Infected: Trojan.Win32.BHO.hj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\lgaahalc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\lquwpfbn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\mC02\mC022328.exe.vir Infected: Trojan-Downloader.Win32.VB.hpv 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\mlJBRHYS.dll.vir Infected: Trojan.Win32.Monder.psf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ogkfwtnq.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.efv 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\opnmLCvt.dll.vir Infected: Trojan.Win32.Monder.oqh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\qoMgHARH.dll.vir Infected: Trojan.Win32.Monder.psf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\qskiqfgr.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.efv 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\RES\comec130t.exe.vir Infected: not-a-virus:AdWare.Win32.WebHancer.f 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\RES\comec130t.exe.vir Infected: not-a-virus:AdWare.Win32.WebHancer.390 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\rgkyfa.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.efv 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\rqRKCuUM.dll.vir Infected: Trojan.Win32.Monder.psf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\sjviinbx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ssqQkhfF.dll.vir Infected: Trojan.Win32.Monder.pfy 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\ualylqiy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\umxxthbk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.alub 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\urqNeDvV.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\vssjdutq.dll.vir Infected: Trojan.Win32.Monder.qie 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\vtUmLbyA.dll.vir Infected: Trojan.Win32.Monder.psf 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\wp\xerd2140.exe.vir Infected: Trojan.Win32.Agent.lom 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\wvUnNedC.dll.vir Infected: Trojan.Win32.Monder.psh 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\xemwxymi.dll.vir Infected: Trojan.Win32.Monder.pse 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\yvbubysy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.quj 1
      C:\qoobox\Quarantine\C\WINDOWS\system32\zlsmp.dll.vir Infected: not-a-virus:AdWare.Win32.PurityScan.jv 1
      C:\qoobox\Quarantine\catchme2007-12-17_224647.79.zip Infected: not-a-virus:AdWare.Win32.Virtumonde.am 1
      C:\qoobox\Quarantine\catchme2008-10-01_175326.31.zip Infected: Trojan-Downloader.Win32.Agent.kwg 1

      The selected area was scanned.




      hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 7:20:58 PM, on 10/5/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\HHVcdV7Sys\VC7SecS.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Compaq_Owner\Local Settings\temp\jkos-Compaq_Owner\binaries\ScanningProcess.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
      O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

      --
      End of file - 3323 bytes
    7. edited October 2008
      Sorry, but I forgot to ask you to post the last ComboFix log. Please post it for my review.

      Thank you!
    8. edited October 2008
      Sorry it took so long for me to reply. I went on a little vacay. Anyway... here's the combofix log from last time

      ComboFix 08-10-01.02 - Compaq_Owner 2008-10-05 16:08:14.5 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.187 [GMT -7:00]
      Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
      Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFScript.txt
      * Created a new restore point
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\temp\mtc2
      C:\temp\mtc2\h5v.log
      C:\WINDOWS\system32\mC02
      C:\WINDOWS\system32\mC02\mC022328.exe
      C:\WINDOWS\system32\np5
      C:\WINDOWS\system32\pin
      C:\WINDOWS\system32\pin\CONFG32I9.exe
      C:\WINDOWS\system32\RES
      C:\WINDOWS\system32\RES\comec130t.exe
      C:\WINDOWS\system32\wp
      C:\WINDOWS\system32\wp\xerd2140.exe

      .
      ((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
      .

      2008-10-03 17:35 . 2008-10-03 17:35 <DIR> d
      C:\_OTMoveIt
      2008-10-02 17:37 . 2008-10-02 17:38 <DIR> d
      C:\Program Files\Frets on Fire
      2008-10-02 17:30 . 2008-10-02 17:30 0 --ah
      C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
      2008-10-02 17:30 . 2008-10-02 17:30 0 --ah
      C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
      2008-09-27 12:23 . 2008-09-27 12:24 <DIR> d
      C:\Documents and Settings\All Users\Application Data\WinZip
      2008-09-23 22:36 . 2008-09-23 22:36 <DIR> d
      C:\Program Files\Panda Security
      2008-09-18 01:22 . 2008-09-18 01:22 <DIR> d
      C:\Program Files\TeaTimer (Spybot - Search & Destroy)
      2008-09-17 00:22 . 2008-09-17 00:22 <DIR> d
      C:\Documents and Settings\LocalService\Application Data\Apple Computer
      2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
      C:\Program Files\iTunes
      2008-09-11 00:36 . 2008-09-11 00:37 <DIR> d
      C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
      2008-09-11 00:35 . 2008-09-11 00:35 <DIR> d
      C:\Program Files\Bonjour
      2008-09-11 00:34 . 2008-09-11 00:34 <DIR> d
      C:\Program Files\QuickTime
      2008-09-11 00:32 . 2008-09-05 22:16 1,900,544 --a
      C:\WINDOWS\system32\usbaaplrc.dll
      2008-09-11 00:32 . 2008-09-05 22:16 36,864 --a
      C:\WINDOWS\system32\drivers\usbaapl.sys
      2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a
      C:\WINDOWS\system32\QuickTimeVR.qtx
      2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a
      C:\WINDOWS\system32\QuickTime.qts

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-10-03 08:01
      d
      w C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire
      2008-09-28 19:49
      d
      w C:\Program Files\Safari
      2008-09-23 04:38
      d
      w C:\Program Files\LimeWire
      2008-09-21 00:16
      d
      w C:\Program Files\Spybot - Search & Destroy
      2008-09-19 03:32
      d
      w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-09-18 15:51 28,106 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
      2008-09-18 06:41
      d
      w C:\Program Files\Java
      2008-09-11 07:37
      d
      w C:\Program Files\iPod
      2008-09-11 07:34
      d
      w C:\Program Files\Common Files\Apple
      2008-09-05 05:53
      d
      w C:\Program Files\V CAST Music with Rhapsody
      2008-09-05 05:52
      d
      w C:\Program Files\Real
      2008-09-03 04:22
      d
      w C:\Program Files\Verizon Wireless
      2008-08-23 07:15
      d
      w C:\Program Files\Microsoft Silverlight
      2008-08-22 03:15
      d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
      2008-08-06 16:35
      d
      w C:\Program Files\Apple Software Update
      2008-07-14 19:29 88 --sha-r C:\Documents and Settings\All Users\Application Data\53D7D18ABC.sys
      2008-07-14 19:29 2,516 --sha-w C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
      2008-07-11 02:44 606,848 ----a-w C:\WINDOWS\flashax.exe
      2008-07-11 02:44 12,288 ----a-w C:\WINDOWS\impborl.dll
      2008-04-29 05:05 69,832 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\GDIPFONTCACHEV1.DAT
      2006-08-17 03:20 184,808 -c--a-w C:\Documents and Settings\Guest\Application Data\shb.dat
      2006-06-23 17:39 1,820 -c--a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
      .

      ((((((((((((((((((((((((((((( snapshot_2008-10-01_17.59.14.12 )))))))))))))))))))))))))))))))))))))))))
      .
      - 2007-07-31 03:18:40 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
      + 2008-07-19 05:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
      + 2006-11-02 14:22:54 492,000
      w C:\WINDOWS\system32\drivers\wdf01000.sys
      + 2006-11-02 14:22:52 32,224
      w C:\WINDOWS\system32\drivers\wdfldr.sys
      + 2007-08-29 00:05:12 55,808 ----a-w C:\WINDOWS\system32\drivers\xusb21.sys
      - 2006-09-26 00:58:48 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
      + 2006-10-09 04:51:14 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe
      + 2006-11-02 23:09:50 1,419,232 ----a-w C:\WINDOWS\system32\WdfCoInstaller01005.dll
      - 2007-07-31 03:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
      + 2008-07-19 05:10:20 36,552 ----a-w C:\WINDOWS\system32\wups.dll
      - 2007-07-31 03:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
      + 2008-07-19 05:10:40 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
      "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
      backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
      backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
      backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
      backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
      backup=C:\WINDOWS\pss\Image Transfer.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Compaq Organize.lnk]
      path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Compaq Organize.lnk
      backup=C:\WINDOWS\pss\Compaq Organize.lnkStartup

      [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
      path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
      backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
      --a
      2008-09-08 23:02 289576 C:\Program Files\iTunes\iTunesHelper.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "C:\\Program Files\\LimeWire\\LimeWire.exe"=
      "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
      "C:\\Program Files\\Corel\\DVD9\\WinDVD.exe"=
      "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_DUPA20.EXE"=
      "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4 Demo\\Civilization4.exe"=
      "C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
      "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "C:\\Program Files\\iTunes\\iTunes.exe"=

      R1 vdrv7000;vdrv7000;C:\WINDOWS\system32\DRIVERS\vdrv7000.sys [2005-01-31 76672]
      R2 PSI_SVC_2;Protexis Licensing V2;C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
      R2 regi;regi;C:\WINDOWS\system32\drivers\regi.sys [2007-04-17 11032]
      R2 VC7SecS;Virtual CD v7 Management Service;C:\Program Files\HHVcdV7Sys\VC7SecS.exe [2005-11-24 106496]
      S4 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 544768]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3afa4cc1-3d8d-11dc-a85b-0011d805b895}]
      \Shell\AutoRun\command - H:\system\viewer\Viewer.exe
      \Shell\View your videos\command - H:\system\viewer\Viewer.exe
      .
      Contents of the 'Scheduled Tasks' folder
      .

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-10-05 16:13:49
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vdrv7000]
      "ImagePath"="system32\DRIVERS\vdrv7000.sys"
      .
      Other Running Processes
      .
      C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\ComboFix\pv.cfexe
      .
      **************************************************************************
      .
      Completion time: 2008-10-05 16:19:32 - machine was rebooted
      ComboFix-quarantined-files.txt 2008-10-05 23:19:29
      ComboFix2.txt 2008-10-04 00:50:44
      ComboFix3.txt 2008-10-02 00:59:47
      ComboFix4.txt 2007-12-21 22:26:53

      Pre-Run: 121,311,961,088 bytes free
      Post-Run: 121,296,928,768 bytes free

      164 --- E O F --- 2008-10-02 07:30:44
    9. edited October 2008
      Hi,

      EMPTY NORTON QUARANTEE FOLDERS
      Go to this page and follow the directions for emptying Quarantine for your version of Norton Antivirus:Removing files from Norton AntiVirus Quarantine

      Make an uninstall list using HijackThis
      To access the Uninstall Manager you would do the following:

      1. Start HijackThis
      2. Click on the Config button
      3. Click on the Misc Tools button
      4. Click on the Open Uninstall Manager button.
      5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in your next reply.

      Please post the Unisntall List along with a fresh HijackThis log and a description of how your computer is running.
    10. edited October 2008
      This topic is now closed due to inactivity. If you wish to reopen your topic, please send a Private Message (PM) to Trogan with a link to your thread.

      If it has been 7 days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, this topic will not be reopened. If you still require help, please start a new topic and include a fresh HijackThis log and a link to this thread in your new topic.

      If you are not the user who started this thread, you must start your own Thread instead (grin)

    Sign In or Register to comment.