Noga 0 Denunciar post Postado Dezembro 25, 2008 Olá.. Estou com algum problema, e não sei identificá-lo. Meu explorer. exe fica fechando sozinho, a cada aproximadamente 10 segundos. Depois de um tempo, ele fecha e não volta mais. Aí vai o log do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:06, on 2008-12-25 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\SearchIn1Step\searchin1.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Logitech\iTouch\iTouch.exe C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\imapi.exe C:\Arquivos de programas\SearchIn1Step\searchin1.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\ARQUIV~1\DAP\SBSearch.dll R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Arquivos de programas\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\avgtoolbar.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [zBrowser Launcher] C:\Arquivos de programas\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Karin\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [NetMeter] C:\Arquivos de programas\HooTech\NetMeter\HooNetMeter.exe O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Arquivos de programas\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Acrobat Assistant.lnk = C:\Arquivos de programas\Adobe\Acrobat 6.0\Distillr\acrotray.exe O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.18\AMVConverter\grab.html O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\ARQUIV~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\Arquivos,de,programas\RelevantKnowledge\rlai.dll,C:\Arquivos,de,programas\RelevantKnowledge\rlai.dll,C:\Arquivos,de,programas\RelevantKnowledge\rlai.dll,C:\Arquivos,de,programas\RelevantKnowledge\rlai.dll,C:\Arquivos,de,programas\RelevantKnowledge\rlai.dll,avgrsstx.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SearchIn1Step Service - Unknown owner - C:\Arquivos de programas\SearchIn1Step\searchin1.exe Aguardo alguma boa alma! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Dezembro 26, 2008 Opa Noga, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar. PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO. OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Dezembro 28, 2008 Olá Jgarcia! Fiz isso e resolveu meu problema. Está funcionando direitinho. Obrigada! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Dezembro 28, 2008 Olá Jgarcia! Fiz isso e resolveu meu problema. Está funcionando direitinho. Obrigada! Sugiro que você poste o log gerado, a fim de que eu possa analisar se a infecção foi removida integralmente. ;) Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Dezembro 31, 2008 Olá Perdi o log antigo, então fiz novamente. Realmente o problema foi resolvido, o explorer.exe não está mais fechando, mas agora surgiu outro. Não consigo abrir nenhum arquivo do word ou do excel. Para arquivos do word, a mensagem é a seguinte: "O arquivo nome.doc não está disponível." E para arquivos do excel, a mensagem é a seguinte: "O arquivo não pode ser aberto porque o antivírus encontrou um problema no arquivo. Este erro poderá ocorrer porque um programa antivírus não está permitindo que o arquivo seja aberto. Essa situação pode ser causada por um dos seguintes motivos: O programa antivírus precisa ser atualizado devido a um problema de compatibilidade com este programa. (...) " Já reinstalei o Office, reinstalei o antivírus, mas o problema continua. O novo log do ComboFix é o seguinte: ComboFix 08-12-29.02 - Karin 2008-12-30 22:49:26.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1022.521 [GMT -2:00] Executando de: c:\documents and settings\Karin\Meus documentos\Downloads\ComboFix.exe * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))) . 2008-12-28 17:55 . 2008-12-28 20:24 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-12-28 17:11 . 2008-12-28 17:11 <DIR> d-------- c:\arquivos de programas\Windows Media Lite 2008-12-28 17:11 . 2008-12-28 17:11 <DIR> d-------- c:\arquivos de programas\P2P_Torrent 2008-12-28 17:10 . 2008-12-28 18:04 <DIR> d-------- c:\arquivos de programas\Ares Galaxy Turbo Booster 2008-12-28 17:04 . 2008-12-28 17:16 <DIR> d--h----- c:\windows\$hf_mig$ 2008-12-28 16:57 . 2008-12-28 16:58 <DIR> d-------- c:\arquivos de programas\LiveTV_ 2008-12-28 16:57 . 2008-12-28 16:57 <DIR> d-------- c:\arquivos de programas\Conduit 2008-12-28 16:50 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll 2008-12-28 16:44 . 2008-12-28 16:44 <DIR> d-------- c:\arquivos de programas\MSBuild 2008-12-28 16:44 . 2004-08-04 01:45 221,184 --a------ c:\windows\system32\wmpns.dll 2008-12-28 16:43 . 2008-12-28 16:43 <DIR> d-------- c:\arquivos de programas\Microsoft.NET 2008-12-28 16:38 . 2008-12-28 16:38 <DIR> d-------- c:\arquivos de programas\Microsoft Visual Studio 8 2008-12-28 16:38 . 2008-12-28 16:38 <DIR> d-------- c:\arquivos de programas\Live_TV 2008-12-28 16:31 . 2008-12-28 16:31 <DIR> dr-h----- C:\MSOCache 2008-12-28 16:10 . 2008-12-28 16:13 <DIR> d-------- c:\windows\system32\drivers\Avg 2008-12-28 16:10 . 2008-12-28 16:10 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-28 16:10 . 2008-12-28 16:10 98,440 --a------ c:\windows\system32\drivers\avgldx86.sys 2008-12-28 16:10 . 2008-12-28 16:10 90,632 --a------ c:\windows\system32\drivers\avgtdix.sys 2008-12-28 16:10 . 2008-12-28 16:10 10,520 --a------ c:\windows\system32\avgrsstx.dll 2008-12-26 10:55 . 2008-12-26 11:16 <DIR> d-------- c:\windows\system32\NtmsData 2008-12-26 00:15 . 2008-12-26 00:15 <DIR> d-------- c:\arquivos de programas\Windows Defender 2008-12-25 23:06 . 2008-12-25 23:07 <DIR> d-------- c:\arquivos de programas\Ares 2008-12-25 21:31 . 2008-12-25 21:51 <DIR> d-------- c:\windows\system32\CatRoot_bak 2008-12-25 21:06 . 2008-12-25 21:06 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-25 17:11 . 2005-07-15 06:48 40,960 -r------- c:\windows\system32\ChCfg.exe 2008-12-25 17:10 . 2006-06-20 19:40 18,796,544 -r------- c:\windows\system32\alsndmgr.cpl 2008-12-25 17:10 . 2006-06-20 19:35 10,527,744 -r------- c:\windows\system32\RTLCPL.exe 2008-12-25 17:10 . 2006-06-27 07:42 3,972,672 -r------- c:\windows\system32\drivers\alcxwdm.sys 2008-12-25 17:10 . 2006-06-20 19:42 577,536 -r------- c:\windows\soundman.exe 2008-12-25 17:10 . 2006-06-07 22:00 143,360 -r------- c:\windows\system32\RtlCPAPI.dll 2008-12-25 17:10 . 2002-02-05 03:54 141,016 -r------- c:\windows\system32\alsndmgr.wav 2008-12-25 17:09 . 2008-12-25 17:09 <DIR> d-------- c:\arquivos de programas\Realtek AC97 2008-12-25 17:09 . 2006-03-20 01:48 315,392 -r------- c:\windows\alcupd.exe 2008-12-25 17:09 . 2005-11-18 01:20 217,088 -ra------ c:\windows\Alcrmv.exe 2008-12-25 16:58 . 2008-12-25 17:02 <DIR> d-------- c:\windows\NV23442748.TMP 2008-12-25 16:56 . 2008-12-25 16:56 54,156 --ah----- c:\windows\QTFont.qfn 2008-12-25 16:56 . 2008-12-25 16:56 1,409 --a------ c:\windows\QTFont.for 2008-12-25 02:22 . 2008-12-25 02:22 665 --a------ c:\windows\wininit.ini 2008-12-25 01:53 . 2008-12-25 01:53 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\LEGO Company 2008-12-25 01:53 . 2008-12-25 01:53 101 --a------ c:\windows\system32\nocfhjfaujf 2008-12-25 01:53 . 2008-12-25 01:53 100 --a------ c:\windows\plmadfhdashd 2008-12-25 01:34 . 2008-12-25 01:36 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\TrackMania 2008-12-25 01:30 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\TmNationsForever 2008-12-25 01:02 . 2008-12-25 02:22 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-25 01:02 . 2008-12-25 01:02 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-12-25 00:59 . 2008-12-25 02:07 <DIR> d-------- c:\arquivos de programas\LEGO Company 2008-12-25 00:56 . 2008-12-25 00:56 <DIR> d-------- c:\temp\rk 2008-12-25 00:56 . 2008-12-25 01:18 <DIR> d-------- C:\temp 2008-12-25 00:53 . 2008-12-25 00:53 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\SpeedBit 2008-12-25 00:52 . 2008-12-28 17:00 <DIR> d-------- c:\arquivos de programas\AskSBar 2008-12-25 00:48 . 2008-12-25 00:48 <DIR> d-------- c:\arquivos de programas\LogyxPack 2008-12-25 00:45 . 2008-12-25 02:19 <DIR> d-------- c:\arquivos de programas\Extreme Tux Racer 2008-12-25 00:43 . 2008-12-25 00:43 30,601 --a------ c:\documents and settings\Karin\x.exe 2008-12-25 00:38 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\Enigma 2008-12-25 00:36 . 2008-12-25 00:53 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-12-25 00:36 . 2008-12-26 01:09 <DIR> d-------- c:\arquivos de programas\DAP 2008-12-25 00:36 . 2008-12-25 00:36 479,298 --a------ c:\windows\system32\wbocx.ocx 2008-12-25 00:36 . 2008-12-25 00:36 172,032 --a------ c:\windows\system32\AniGIF.ocx 2008-12-25 00:36 . 2008-12-25 00:36 50,688 --a------ c:\windows\system32\wbhelp2.dll 2008-12-25 00:32 . 2008-12-25 02:20 <DIR> d-------- c:\arquivos de programas\AbcPuzzles 2008-12-25 00:23 . 2008-12-25 00:23 <DIR> d-------- c:\arquivos de programas\Lavasoft 2008-12-24 14:42 . 2008-12-28 17:15 1,393 --a------ c:\windows\imsins.BAK 2008-12-24 01:27 . 2008-12-24 01:27 45,056 --a------ c:\windows\system32\opnmMeBt.dll 2008-12-24 00:48 . 2008-12-24 00:48 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\HTNetMeter 2008-12-24 00:48 . 2008-12-24 00:48 <DIR> d-------- c:\arquivos de programas\HooTech 2008-12-24 00:05 . 2007-08-24 19:45 101,120 -ra------ c:\windows\system32\drivers\ewusbmdm.sys 2008-12-24 00:05 . 2007-08-24 19:45 24,448 -ra------ c:\windows\system32\drivers\ewdcsc.sys 2008-12-24 00:04 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\TIM Web Banda Larga 2008-12-23 00:52 . 2008-12-23 00:52 <DIR> d-------- c:\windows\MVScreenSaver 2008-12-23 00:52 . 2008-12-23 00:51 686,111 --a------ c:\windows\unins000.exe 2008-12-23 00:52 . 2008-12-23 00:52 1,037 --a------ c:\windows\unins000.dat 2008-12-23 00:52 . 2008-01-19 17:18 62 --a------ c:\windows\MVSCREENSAVER.INI 2008-12-23 00:15 . 2008-12-23 00:15 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbser6k.sys 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbnmea.sys 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbmdm6k.sys 2008-12-21 18:13 . 2008-12-21 18:13 <DIR> d-------- c:\arquivos de programas\Microsoft 2008-12-21 18:12 . 2008-12-21 18:12 <DIR> d-------- c:\arquivos de programas\Windows Live SkyDrive 2008-12-16 22:48 . 2008-12-16 22:48 <DIR> d-------- C:\OdontoPlus 2008-12-04 12:16 . 2008-12-04 13:18 <DIR> d-------- c:\arquivos de programas\Zero Assumption Digital Image Recovery 2008-12-02 22:37 . 2008-12-02 22:37 49,480 --a------ c:\windows\system32\sirenacm.dll 2008-11-30 00:07 . 2008-11-30 23:34 <DIR> d-------- c:\documents and settings\Karin\amsn 2008-11-23 15:51 . 2007-08-11 23:07 <DIR> d--h----- c:\documents and settings\Convidado\Modelos 2008-11-23 15:51 . 2008-11-23 15:52 <DIR> dr------- c:\documents and settings\Convidado\Meus documentos 2008-11-23 15:51 . 2007-08-11 20:02 <DIR> dr------- c:\documents and settings\Convidado\Menu Iniciar 2008-11-23 15:51 . 2008-11-23 15:52 <DIR> dr------- c:\documents and settings\Convidado\Favoritos 2008-11-23 15:51 . 2008-11-23 15:52 <DIR> dr-h----- c:\documents and settings\Convidado\Dados de aplicativos 2008-11-23 15:51 . 2008-12-30 22:51 <DIR> d--h----- c:\documents and settings\Convidado\Configurações locais 2008-11-23 15:51 . 2007-08-11 20:02 <DIR> d--h----- c:\documents and settings\Convidado\Ambiente de rede 2008-11-23 15:51 . 2007-08-11 20:02 <DIR> d--h----- c:\documents and settings\Convidado\Ambiente de impressão 2008-11-23 15:51 . 2008-12-28 16:11 <DIR> d-------- c:\documents and settings\Convidado . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-31 00:48 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP 2008-12-28 19:16 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help 2008-12-28 16:47 --------- d-----w c:\arquivos de programas\MediaMonkey 2008-12-28 16:39 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\WildTangent 2008-12-26 02:15 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\AdobeUM 2008-12-26 01:02 --------- d-----w c:\arquivos de programas\eMule 2008-12-25 19:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-12-25 04:04 --------- d-----w c:\arquivos de programas\Readiris10 2008-12-25 04:01 --------- d-----w c:\arquivos de programas\Secret Maryo Chronicles 2008-12-25 04:00 --------- d-----w c:\arquivos de programas\Smart Projects 2008-12-25 03:00 --------- d-----w c:\arquivos de programas\GameTop.com 2008-12-24 11:48 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2008-12-23 02:15 --------- d-----w c:\arquivos de programas\Java 2008-12-21 22:28 --------- d-----w c:\arquivos de programas\Windows Live 2008-12-18 00:44 --------- d-----w c:\arquivos de programas\SearchIn1Step 2008-12-04 15:18 --------- d-----w c:\arquivos de programas\SmarThru 4 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll 2008-10-13 03:25 219,648 ----a-w c:\windows\system32\uxtheme.dll 2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys 2008-09-04 16:45 1,106,944 ----a-w c:\windows\system32\msxml3.dll 2008-09-03 02:24 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-09-03 02:24 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-09-03 02:24 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-09-03 02:24 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-09-03 02:24 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-25_21.26.34.62 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-28 18:45:01 110,592 ----a-w c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll + 2008-12-28 18:44:57 65,536 ----a-w c:\windows\assembly\GAC\dao\10.0.4504.0__31bf3856ad364e35\DAO.DLL + 2008-12-28 18:45:02 4,608 ----a-w c:\windows\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll + 2008-12-28 18:44:56 1,215,328 ----a-w c:\windows\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll + 2008-12-28 18:44:57 82,784 ----a-w c:\windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll + 2008-12-28 18:44:40 31,560 ----a-w c:\windows\assembly\GAC\ipdmctrl\11.0.0.0__71e9bce111e9429c\IPDMCTRL.DLL + 2008-12-28 18:45:00 8,007,680 ----a-w c:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll + 2008-12-28 18:44:40 16,712 ----a-w c:\windows\assembly\GAC\Microsoft.Office.InfoPath.Permission\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Permission.dll + 2008-12-28 18:43:10 80,696 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll + 2008-12-28 18:43:46 1,612,592 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Access.dll + 2008-12-28 18:43:46 1,276,720 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll + 2008-12-28 18:43:47 150,320 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll + 2008-12-28 18:44:42 404,296 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.SemiTrust\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.SemiTrust.dll + 2008-12-28 18:43:52 88,896 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll + 2008-12-28 18:43:50 146,232 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll + 2008-12-28 18:44:21 17,208 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll + 2008-12-28 18:43:48 920,376 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll + 2008-12-28 18:43:49 35,648 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll + 2008-12-28 19:04:07 250,928 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll + 2008-12-28 18:43:49 232,248 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Publisher.dll + 2008-12-28 18:43:48 20,280 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll + 2008-12-28 18:45:23 783,744 ----a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll + 2008-12-28 18:44:58 13,312 ----a-w c:\windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll + 2008-12-28 18:43:47 371,496 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll + 2008-12-28 18:43:50 64,288 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll + 2008-12-28 18:44:58 229,376 ----a-w c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL + 2008-12-28 18:45:01 4,096 ----a-w c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll + 2008-12-28 18:43:48 416,544 ----a-w c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL + 2008-12-28 18:43:10 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Access\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Access.dll + 2008-12-28 18:43:11 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll + 2008-12-28 18:44:00 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll + 2008-12-28 18:44:43 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.Xml.dll + 2008-12-28 18:44:42 12,616 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.InfoPath\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.InfoPath.dll + 2008-12-28 18:44:24 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll + 2008-12-28 18:44:22 12,632 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll + 2008-12-28 18:44:24 12,112 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll + 2008-12-28 18:44:36 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Publisher\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Publisher.dll + 2008-12-28 18:44:19 12,104 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll + 2008-12-28 18:44:38 12,096 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll + 2008-12-28 18:44:19 12,080 ----a-w c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll + 2008-12-28 18:44:19 11,544 ----a-w c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll + 2008-12-28 18:44:58 16,384 ----a-w c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll + 2008-12-28 18:45:31 120,408 ----a-w c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll + 2008-12-28 18:45:05 367,400 ----a-w c:\windows\assembly\GAC_32\Microsoft.VisualStudio.Tools.Applications.InteropAdapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.InteropAdapter.dll + 2008-12-28 18:45:31 611,392 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll + 2008-12-28 18:44:41 43,840 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.FormControl\12.0.0.0__71e9bce111e9429c\microsoft.office.infopath.formcontrol.dll + 2008-12-28 18:44:42 39,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Vsta\12.0.0.0__71e9bce111e9429c\Microsoft.Office.InfoPath.Vsta.dll + 2008-12-28 18:44:41 60,200 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Office.InfoPath\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.dll + 2008-12-28 18:38:32 4,608 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter.resources\8.0.0.0_pt-BR_b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.resources.dll + 2008-12-28 18:44:53 211,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Adapter\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Adapter.dll + 2008-12-28 18:38:31 5,632 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager.resources\8.0.0.0_pt-BR_b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.resources.dll + 2008-12-28 18:44:54 105,248 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.AddInManager\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.AddInManager.dll + 2008-12-28 18:44:46 330,520 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Blueprints\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Blueprints.dll + 2008-12-28 18:38:31 4,096 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.resources\8.0.0.0_pt-BR_b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.resources.dll + 2008-12-28 18:44:54 39,712 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.ComRPCChannel.dll + 2008-12-28 18:44:55 39,704 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.Contract\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.Contract.dll + 2008-12-28 18:44:48 72,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualStudio.Tools.Applications.DesignTime\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.Tools.Applications.DesignTime.dll + 2008-12-28 18:44:55 47,832 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll + 2008-12-28 18:44:55 39,624 ----a-w c:\windows\assembly\GAC_MSIL\System.AddIn\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.dll - 2006-05-05 09:41:45 453,120 ------w c:\windows\Driver Cache\i386\mrxsmb.sys + 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys - 2007-02-28 16:02:20 2,140,160 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2008-08-14 13:45:20 2,140,160 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe - 2007-02-28 16:02:34 2,061,824 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe + 2008-08-14 13:45:24 2,061,952 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe - 2007-02-28 16:02:18 2,019,840 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe + 2008-08-14 13:45:20 2,019,840 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe - 2007-02-28 16:02:28 2,184,576 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-08-14 13:45:25 2,184,576 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe + 2006-10-26 21:49:48 1,011,488 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109010061400000000000F01FEC\12.0.4518\MSDAIPP.DLL + 2006-10-26 21:49:46 970,528 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109010061400000000000F01FEC\12.0.4518\MSONSEXT.DLL + 2006-10-27 18:00:10 576,376 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL + 2006-10-27 00:18:12 162,616 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL + 2006-10-27 18:00:12 1,751,904 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL + 2006-10-27 18:00:10 576,376 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL + 2006-10-27 18:00:06 47,976 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL + 2006-10-27 18:00:08 191,360 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL + 2006-10-26 23:13:34 338,800 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL + 2006-10-26 23:13:44 629,616 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL + 2006-10-26 23:13:28 207,736 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL + 2006-10-26 23:13:32 279,352 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL + 2006-10-26 23:13:08 15,160 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL + 2006-10-26 23:13:08 15,160 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL + 2006-10-26 23:13:08 15,160 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL + 2006-10-26 23:13:12 15,160 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL + 2006-10-27 18:00:06 387,960 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL + 2006-10-26 23:13:38 392,048 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL + 2006-10-26 23:13:30 260,976 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL + 2006-10-26 23:13:32 289,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL + 2006-10-26 23:13:20 56,120 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL + 2006-10-26 23:13:38 551,800 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL + 2006-10-26 23:13:30 224,104 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL + 2006-10-27 18:40:34 208,760 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL + 2006-10-26 23:13:34 371,568 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL + 2006-10-27 18:41:04 399,640 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL + 2006-10-26 22:59:24 205,616 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE + 2006-10-26 23:12:52 189,760 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL + 2006-10-26 22:48:14 439,568 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL + 2006-10-26 17:10:08 1,190,688 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL + 2006-10-26 17:04:58 75,576 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL + 2006-10-26 22:21:24 1,682,232 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL + 2006-10-27 18:09:36 983,376 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL + 2006-10-26 23:02:12 2,526,520 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE + 2006-10-26 23:12:52 173,328 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL + 2006-10-27 18:10:10 5,281,592 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL + 2006-10-26 22:58:24 793,392 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MDIGRAPH.DLL + 2006-10-26 22:58:18 274,776 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MDIINK.DLL + 2006-10-26 22:55:10 828,704 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL + 2006-10-27 18:01:34 10,371,880 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE + 2006-10-27 00:18:06 66,880 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL + 2006-10-26 16:58:14 117,552 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL + 2006-10-27 17:59:06 161,080 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL + 2006-10-26 22:48:12 14,664 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL + 2006-10-26 23:12:58 428,816 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL + 2006-10-27 00:13:36 26,936 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL + 2006-10-26 23:00:08 6,635,320 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL + 2006-10-26 16:56:36 436,520 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL + 2006-10-26 22:58:26 1,057,632 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPCORE.DLL + 2006-10-26 22:58:22 772,944 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSPFILT.DLL + 2006-10-26 22:50:04 672,024 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE + 2006-10-26 16:56:40 505,136 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL + 2006-10-26 22:55:12 832,800 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE + 2006-10-26 22:55:06 538,904 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL + 2006-10-26 23:12:30 65,824 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL + 2006-10-27 18:14:34 14,151,456 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL + 2006-10-26 23:06:54 232,816 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE + 2006-10-26 23:14:06 7,033,152 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL + 2006-10-27 18:18:36 1,658,152 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL + 2006-10-26 23:00:08 274,744 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE + 2006-10-26 23:00:12 998,208 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL + 2006-10-26 23:00:10 285,008 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL + 2006-10-26 16:58:40 540,008 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORGCHART.EXE + 2006-10-26 23:07:04 6,536,992 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL + 2006-07-26 21:53:56 459,080 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL + 2006-10-27 00:30:44 482,088 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL + 2006-10-27 18:04:06 465,200 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE + 2006-10-27 18:04:06 7,980,848 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL + 2006-10-26 22:52:10 2,012,480 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE + 2006-10-26 17:05:00 77,144 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL + 2006-10-27 00:13:38 38,168 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL + 2006-10-26 17:04:44 19,784 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL + 2006-10-26 23:13:00 503,624 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE + 2006-10-26 23:06:58 439,600 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE + 2006-10-27 00:18:16 502,608 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL + 2006-10-27 17:57:08 2,330,968 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL + 2006-10-26 17:04:48 29,976 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL + 2006-10-26 17:05:04 126,784 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL + 2006-10-26 17:05:02 86,840 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL + 2006-10-26 17:04:56 58,168 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL + 2006-10-26 17:04:48 27,456 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL + 2006-10-26 17:04:54 51,008 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL + 2006-10-26 17:04:44 19,784 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL + 2006-10-26 17:04:58 76,624 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL + 2006-09-30 03:42:56 2,583,344 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL + 2006-10-27 01:58:38 3,732,792 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL + 2006-10-26 17:05:08 1,181,520 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL + 2006-10-26 17:05:08 530,760 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL + 2007-09-14 23:45:58 16,901,168 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL + 2007-08-29 02:19:24 1,654,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL + 2007-08-29 01:06:16 467,840 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE + 2007-08-29 01:06:44 7,990,144 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL + 2008-12-28 18:45:54 251,272 ----a-r c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTPIA.DLL + 2008-12-26 04:42:01 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe - 2008-07-28 00:05:21 1,165,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe + 2008-12-28 19:16:27 1,165,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe - 2008-07-28 00:05:22 20,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe + 2008-12-28 19:16:28 20,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe - 2008-07-28 00:05:21 159,504 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe + 2008-12-28 19:16:28 159,504 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe - 2008-07-28 00:05:21 184,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe + 2008-12-28 19:16:28 184,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe - 2008-07-28 00:05:22 217,864 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe + 2008-12-28 19:16:28 217,864 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe - 2008-07-28 00:05:22 18,704 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe + 2008-12-28 19:16:29 18,704 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe - 2008-07-28 00:05:22 35,088 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe + 2008-12-28 19:16:29 35,088 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe - 2008-07-28 00:05:22 845,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe + 2008-12-28 19:16:28 845,584 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe - 2008-07-28 00:05:22 922,384 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe + 2008-12-28 19:16:28 922,384 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe - 2008-07-28 00:05:22 272,648 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe + 2008-12-28 19:16:28 272,648 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe - 2008-07-28 00:05:22 888,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe + 2008-12-28 19:16:29 888,080 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe - 2008-07-28 00:05:21 1,172,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe + 2008-12-28 19:16:28 1,172,240 ----a-r c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe - 2007-08-12 01:44:21 217,864 ----a-r c:\windows\Installer\{90120000-006E-0416-0000-0000000FF1CE}\misc.exe + 2008-12-26 04:45:32 217,864 ----a-r c:\windows\Installer\{90120000-006E-0416-0000-0000000FF1CE}\misc.exe - 2006-11-03 02:24:36 7,168 ----a-w c:\windows\system32\asferror.dll + 2006-11-03 01:24:36 7,168 ----a-w c:\windows\system32\asferror.dll - 2006-10-19 00:47:08 284,672 ----a-w c:\windows\system32\audiodev.dll + 2006-10-18 23:47:08 276,992 ----a-w c:\windows\system32\audiodev.dll - 2008-04-21 07:02:31 1,024,000 ----a-w c:\windows\system32\browseui.dll Aguardo e desde já agradeço. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Dezembro 31, 2008 Esqueci outro problema. O iexplorer tb está com problemas. Esporadicamente, aparece uma mensagem que ele não pode ser aberto, e precisa ser fechado. :S Oh my god! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Dezembro 31, 2008 Opa Noga, 1. Baixe o BankerFix 3.0. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM. 4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado. 5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos. 6. Terminado o scan, leia a mensagem na tela e aperte Enter. 7. Habilite o seu anti-vírus. 8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Dezembro 31, 2008 BankerFix 3.0 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2008-12-30 - 23:19 ------------------------------------------------------- Lista de Definição: 2008-12-14-1 | CORE: 2008-12-14-1 ======================================================= ----- Fim ------------------------- :D Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Janeiro 6, 2009 O problema ainda continua. Só consigo abrir arquivos word e excel se estiver sem o AVG instalado. Alguma idéia? Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Janeiro 9, 2009 Opa Noga, Poste um novo log do ComboFix. PS.: Desculpe a demora, pois cheguei de viagem hoje. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Janeiro 22, 2009 Oiee... ok.. tb estive fora.. entao.. resolvi o problema tirando o AVG do meu pc... agora estou com o Avast..mas o problema do explorer voltou. As vezes da uma mensagem que o windows explores precisa ser fechado, e uma vez fechado, ele nao volta mais. Nao mais mais o q fazer. Vai aí o log do combofix.. ComboFix 09-01-21.02 - Karin 2009-01-22 1:11:01.3 - NTFSx86 Executando de: c:\documents and settings\Karin\Desktop\ComboFix.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2008-12-22 to 2009-01-22 )))))))))))))))))))))))))))) . 2009-01-22 01:09 . 2009-01-22 01:10 <DIR> d-------- C:\32788R22FWJFW 2009-01-21 22:27 . 2009-01-21 22:27 <DIR> d-------- c:\arquivos de programas\AVIConverter 2009-01-21 01:19 . 2009-01-21 01:19 <DIR> d--h----- c:\windows\$hf_mig$ 2009-01-19 23:54 . 2009-01-20 01:43 <DIR> d-------- C:\OdontoPlus 2009-01-09 09:56 . 2009-01-09 09:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SlySoft 2009-01-07 23:38 . 2009-01-07 23:38 <DIR> d-------- c:\arquivos de programas\SlySoft 2009-01-07 00:24 . 2003-06-25 19:38 14,848 --a------ c:\arquivos de programas\aida32.exe 2009-01-05 22:47 . 2009-01-05 22:47 <DIR> d-------- c:\arquivos de programas\Alwil Software 2009-01-04 12:12 . 2009-01-04 12:12 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack 2009-01-04 12:12 . 2008-09-19 19:57 3,596,288 --a------ c:\windows\system32\qt-dx331.dll 2009-01-04 12:12 . 2008-09-24 16:41 839,680 --a------ c:\windows\system32\lameACM.acm 2009-01-04 12:12 . 2008-12-07 16:08 795,648 --a------ c:\windows\system32\xvidcore.dll 2009-01-04 12:12 . 2008-10-28 20:35 684,032 --a------ c:\windows\system32\divx.dll 2009-01-04 12:12 . 2004-01-25 14:18 217,088 --a------ c:\windows\system32\yv12vfw.dll 2009-01-04 12:12 . 2008-12-07 16:08 130,048 --a------ c:\windows\system32\xvidvfw.dll 2009-01-04 12:12 . 2007-09-20 22:52 118,784 --a------ c:\windows\system32\ac3acm.acm 2009-01-04 12:12 . 2008-09-25 06:03 81,920 --a------ c:\windows\system32\dpl100.dll 2009-01-04 12:12 . 2008-12-08 09:53 57,344 --a------ c:\windows\system32\ff_vfw.dll 2009-01-04 12:12 . 2007-07-10 14:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest 2009-01-04 12:12 . 2008-10-03 10:30 414 --a------ c:\windows\system32\lame_acm.xml 2009-01-04 12:12 . 2008-07-30 17:09 38 --a------ c:\windows\avisplitter.ini 2009-01-04 11:06 . 2009-01-21 21:58 41 --a------ c:\windows\system32\Filzip.ini 2009-01-04 11:01 . 2009-01-04 11:02 1,303,128 ---hs---- c:\windows\system32\eyupifuv.ini 2009-01-01 20:36 . 2009-01-01 20:36 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\xing shared 2009-01-01 20:35 . 2009-01-01 20:36 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Real 2009-01-01 14:19 . 2009-01-20 01:23 41 --a------ c:\windows\Filzip.ini 2009-01-01 14:18 . 2009-01-01 14:58 <DIR> d-------- c:\arquivos de programas\Filzip 2009-01-01 14:08 . 1999-03-23 09:12 299,520 --a------ c:\windows\uninst.exe 2008-12-31 23:20 . 2008-12-31 23:20 33,832 --a------ c:\windows\system32\xlxtwcrn.exe 2008-12-31 23:20 . 2008-12-31 23:20 33,832 --a------ c:\windows\system32\lwhdjvsp.exe 2008-12-31 23:12 . 2008-12-31 23:12 33,832 --a------ c:\windows\system32\znagoswz.exe 2008-12-31 23:06 . 2008-12-31 23:06 1,303,128 ---hs---- c:\windows\system32\imabatup.ini 2008-12-31 11:59 . 2008-12-31 11:59 24,872 --a------ c:\windows\system32\drivers\ElbyCDIO.sys 2008-12-30 23:19 . 2009-01-20 01:13 <DIR> d-------- C:\LinhaDefensiva 2008-12-30 21:53 . 2008-12-30 21:53 103,360 --a------ c:\windows\system32\drivers\AnyDVD.sys 2008-12-28 17:55 . 2009-01-02 10:13 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-12-28 17:11 . 2008-12-28 17:11 <DIR> d-------- c:\arquivos de programas\Windows Media Lite 2008-12-28 17:11 . 2008-12-28 17:11 <DIR> d-------- c:\arquivos de programas\P2P_Torrent 2008-12-28 17:10 . 2008-12-28 18:04 <DIR> d-------- c:\arquivos de programas\Ares Galaxy Turbo Booster 2008-12-28 16:57 . 2008-12-28 16:58 <DIR> d-------- c:\arquivos de programas\LiveTV_ 2008-12-28 16:57 . 2008-12-28 16:57 <DIR> d-------- c:\arquivos de programas\Conduit 2008-12-28 16:50 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll 2008-12-28 16:44 . 2008-12-28 16:44 <DIR> d-------- c:\arquivos de programas\MSBuild 2008-12-28 16:44 . 2004-08-04 01:45 221,184 --a------ c:\windows\system32\wmpns.dll 2008-12-28 16:43 . 2008-12-28 16:43 <DIR> d-------- c:\arquivos de programas\Microsoft.NET 2008-12-28 16:38 . 2008-12-28 16:38 <DIR> d-------- c:\arquivos de programas\Microsoft Visual Studio 8 2008-12-28 16:38 . 2008-12-28 16:38 <DIR> d-------- c:\arquivos de programas\Live_TV 2008-12-28 16:31 . 2008-12-28 16:31 <DIR> dr-h----- C:\MSOCache 2008-12-28 16:10 . 2009-01-05 22:06 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-26 10:55 . 2008-12-26 11:16 <DIR> d-------- c:\windows\system32\NtmsData 2008-12-26 00:15 . 2008-12-26 00:15 <DIR> d-------- c:\arquivos de programas\Windows Defender 2008-12-25 23:06 . 2008-12-25 23:07 <DIR> d-------- c:\arquivos de programas\Ares 2008-12-25 21:31 . 2009-01-21 22:13 <DIR> d-------- c:\windows\system32\CatRoot_bak 2008-12-25 21:06 . 2008-12-25 21:06 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-25 17:11 . 2005-07-15 06:48 40,960 -r------- c:\windows\system32\ChCfg.exe 2008-12-25 17:10 . 2006-06-20 19:40 18,796,544 -r------- c:\windows\system32\alsndmgr.cpl 2008-12-25 17:10 . 2006-06-20 19:35 10,527,744 -r------- c:\windows\system32\RTLCPL.exe 2008-12-25 17:10 . 2006-06-27 07:42 3,972,672 -r------- c:\windows\system32\drivers\alcxwdm.sys 2008-12-25 17:10 . 2006-06-20 19:42 577,536 -r------- c:\windows\soundman.exe 2008-12-25 17:10 . 2006-06-07 22:00 143,360 -r------- c:\windows\system32\RtlCPAPI.dll 2008-12-25 17:10 . 2002-02-05 03:54 141,016 -r------- c:\windows\system32\alsndmgr.wav 2008-12-25 17:09 . 2008-12-25 17:09 <DIR> d-------- c:\arquivos de programas\Realtek AC97 2008-12-25 17:09 . 2006-03-20 01:48 315,392 -r------- c:\windows\alcupd.exe 2008-12-25 17:09 . 2005-11-18 01:20 217,088 -ra------ c:\windows\Alcrmv.exe 2008-12-25 16:58 . 2008-12-25 17:02 <DIR> d-------- c:\windows\NV23442748.TMP 2008-12-25 02:22 . 2008-12-25 02:22 665 --a------ c:\windows\wininit.ini 2008-12-25 01:53 . 2008-12-25 01:53 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\LEGO Company 2008-12-25 01:53 . 2008-12-25 01:53 101 --a------ c:\windows\system32\nocfhjfaujf 2008-12-25 01:53 . 2008-12-25 01:53 100 --a------ c:\windows\plmadfhdashd 2008-12-25 01:34 . 2008-12-25 01:36 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\TrackMania 2008-12-25 01:30 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\TmNationsForever 2008-12-25 01:02 . 2008-12-31 21:58 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-25 01:02 . 2008-12-31 21:57 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-12-25 00:59 . 2008-12-25 02:07 <DIR> d-------- c:\arquivos de programas\LEGO Company 2008-12-25 00:56 . 2008-12-25 00:56 <DIR> d-------- c:\temp\rk 2008-12-25 00:56 . 2008-12-25 01:18 <DIR> d-------- C:\temp 2008-12-25 00:53 . 2008-12-25 00:53 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\SpeedBit 2008-12-25 00:52 . 2008-12-28 17:00 <DIR> d-------- c:\arquivos de programas\AskSBar 2008-12-25 00:48 . 2008-12-25 00:48 <DIR> d-------- c:\arquivos de programas\LogyxPack 2008-12-25 00:45 . 2008-12-25 02:19 <DIR> d-------- c:\arquivos de programas\Extreme Tux Racer 2008-12-25 00:43 . 2008-12-25 00:43 30,601 --a------ c:\documents and settings\Karin\x.exe 2008-12-25 00:38 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\Enigma 2008-12-25 00:36 . 2008-12-25 00:53 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-12-25 00:36 . 2008-12-26 01:09 <DIR> d-------- c:\arquivos de programas\DAP 2008-12-25 00:36 . 2008-12-25 00:36 479,298 --a------ c:\windows\system32\wbocx.ocx 2008-12-25 00:36 . 2008-12-25 00:36 172,032 --a------ c:\windows\system32\AniGIF.ocx 2008-12-25 00:36 . 2008-12-25 00:36 50,688 --a------ c:\windows\system32\wbhelp2.dll 2008-12-25 00:32 . 2008-12-25 02:20 <DIR> d-------- c:\arquivos de programas\AbcPuzzles 2008-12-25 00:23 . 2008-12-25 00:23 <DIR> d-------- c:\arquivos de programas\Lavasoft 2008-12-24 14:42 . 2008-12-30 23:07 4,625 --a------ c:\windows\imsins.BAK 2008-12-24 00:48 . 2008-12-24 00:48 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\HTNetMeter 2008-12-24 00:48 . 2008-12-24 00:48 <DIR> d-------- c:\arquivos de programas\HooTech 2008-12-24 00:05 . 2007-08-24 19:45 101,120 -ra------ c:\windows\system32\drivers\ewusbmdm.sys 2008-12-24 00:05 . 2007-08-24 19:45 24,448 -ra------ c:\windows\system32\drivers\ewdcsc.sys 2008-12-24 00:04 . 2008-12-25 01:52 <DIR> d-------- c:\arquivos de programas\TIM Web Banda Larga 2008-12-23 00:52 . 2008-12-23 00:52 <DIR> d-------- c:\windows\MVScreenSaver 2008-12-23 00:52 . 2008-12-23 00:51 686,111 --a------ c:\windows\unins000.exe 2008-12-23 00:52 . 2008-12-23 00:52 1,037 --a------ c:\windows\unins000.dat 2008-12-23 00:52 . 2008-01-19 17:18 62 --a------ c:\windows\MVSCREENSAVER.INI 2008-12-23 00:15 . 2008-12-23 00:15 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbser6k.sys 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbnmea.sys 2008-12-22 23:36 . 2008-03-21 10:16 104,960 --a------ c:\windows\system32\drivers\ZTEusbmdm6k.sys . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-22 03:16 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP 2009-01-22 02:48 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink 2009-01-21 03:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help 2009-01-18 17:47 --------- d-----w c:\arquivos de programas\eMule 2009-01-18 15:04 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\AdobeUM 2009-01-07 03:09 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-01-06 00:07 --------- d-s---w c:\documents and settings\Usuário\Dados de aplicativos\Microsoft 2009-01-02 12:13 --------- d-----w c:\arquivos de programas\SearchIn1Step 2008-12-28 16:47 --------- d-----w c:\arquivos de programas\MediaMonkey 2008-12-28 16:39 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\WildTangent 2008-12-25 19:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-12-25 04:04 --------- d-----w c:\arquivos de programas\Readiris10 2008-12-25 04:01 --------- d-----w c:\arquivos de programas\Secret Maryo Chronicles 2008-12-25 04:00 --------- d-----w c:\arquivos de programas\Smart Projects 2008-12-25 03:00 --------- d-----w c:\arquivos de programas\GameTop.com 2008-12-24 11:48 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2008-12-23 02:15 --------- d-----w c:\arquivos de programas\Java 2008-12-21 22:28 --------- d-----w c:\arquivos de programas\Windows Live 2008-12-21 20:13 --------- d-----w c:\arquivos de programas\Microsoft 2008-12-21 20:12 --------- d-----w c:\arquivos de programas\Windows Live SkyDrive 2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys 2008-12-04 15:18 --------- d-----w c:\arquivos de programas\Zero Assumption Digital Image Recovery 2008-12-04 15:18 --------- d-----w c:\arquivos de programas\SmarThru 4 2008-12-03 00:37 49,480 ----a-w c:\windows\system32\sirenacm.dll 2008-11-19 17:21 93,128 ----a-w c:\windows\system32\ElbyCDIO.dll 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-09-03 02:24 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-09-03 02:24 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-09-03 02:24 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-09-03 02:24 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-09-03 02:24 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . ------- Sigcheck ------- 2007-06-13 11:21 1697280 07a1a28907a5f2a251b3b2564884d730 c:\windows\explorer.exe 2008-04-14 00:20 1035776 064ec7ff5f58b928c3e119402977fa6d c:\windows\SoftwareDistribution\Download\0bd93937a84337966dcbb1c34e8c1b2f\explorer.exe 2007-06-13 11:21 1697280 07a1a28907a5f2a251b3b2564884d730 c:\windows\system32\dllcache\explorer.exe 2007-06-13 11:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 c:\windows\XPize Darkside\Backup\explorer.exe 2008-04-14 00:20 15360 4e486adfe3a0b9ed0eb0639902e9f64f c:\windows\SoftwareDistribution\Download\0bd93937a84337966dcbb1c34e8c1b2f\ctfmon.exe 2004-08-04 01:45 30208 c44b39505116f6961988b8681793e572 c:\windows\system32\ctfmon.exe 2004-08-04 01:45 30208 c44b39505116f6961988b8681793e572 c:\windows\system32\dllcache\ctfmon.exe 2004-08-04 01:45 15360 f40bc97996b8e53799eef1d63996674b c:\windows\XPize Darkside\Backup\ctfmon.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{F4F10C1D-87C7-404A-B4B3-000000000000}"= "c:\arquiv~1\DAP\SBSearch.dll" [2008-12-25 38384] "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\arquivos de programas\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-12-25 66912] [HKEY_CLASSES_ROOT\clsid\{f4f10c1d-87c7-404a-b4b3-000000000000}] [HKEY_CLASSES_ROOT\SearchHook.SrchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}] [HKEY_CLASSES_ROOT\SearchHook.SrchHook] [HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}] 2008-12-25 00:52 66912 --a------ c:\arquivos de programas\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59385f95-c52f-4a84-b674-4a4206b17218}] 2008-12-19 01:32 1878040 --a------ c:\arquivos de programas\LiveTV_\tbLive.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bc4be15d-6a34-4356-9e97-79e43da32b1d}] 2008-11-23 23:03 1784856 --a------ c:\arquivos de programas\P2P_Torrent\tbP2P_.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{59385f95-c52f-4a84-b674-4a4206b17218}"= "c:\arquivos de programas\LiveTV_\tbLive.dll" [2008-12-19 1878040] "{bc4be15d-6a34-4356-9e97-79e43da32b1d}"= "c:\arquivos de programas\P2P_Torrent\tbP2P_.dll" [2008-11-23 1784856] [HKEY_CLASSES_ROOT\clsid\{59385f95-c52f-4a84-b674-4a4206b17218}] [HKEY_CLASSES_ROOT\clsid\{bc4be15d-6a34-4356-9e97-79e43da32b1d}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{59385F95-C52F-4A84-B674-4A4206B17218}"= "c:\arquivos de programas\LiveTV_\tbLive.dll" [2008-12-19 1878040] "{BC4BE15D-6A34-4356-9E97-79E43DA32B1D}"= "c:\arquivos de programas\P2P_Torrent\tbP2P_.dll" [2008-11-23 1784856] [HKEY_CLASSES_ROOT\clsid\{59385f95-c52f-4a84-b674-4a4206b17218}] [HKEY_CLASSES_ROOT\clsid\{bc4be15d-6a34-4356-9e97-79e43da32b1d}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 30208] "DownloadAccelerator"="c:\arquivos de programas\DAP\DAP.EXE" [2008-12-26 3134976] "ares"="c:\arquivos de programas\Ares\Ares.exe" [2008-12-25 893440] "AnyDVD"="c:\arquivos de programas\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-12-31 2489280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2007-04-27 282624] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2009-01-01 185872] "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-08-16 503808] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2004-08-04 541696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 30208] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^InterVideo WinCinema Manager.lnk] backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM5babd069 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rebobalisu [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] --a------ 2008-12-25 22:40 893440 c:\arquivos de programas\Ares\Ares.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] --a------ 2004-08-04 01:45 30208 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] --a------ 2008-12-26 01:03 3134976 c:\arquivos de programas\DAP\DAP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2008-12-02 22:30 3882312 c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetMeter] --a------ 2008-10-06 23:18 577536 c:\arquivos de programas\HooTech\NetMeter\HooNetMeter.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-08-11 11:43 7630848 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-08-11 11:43 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-04-27 10:41 282624 c:\arquivos de programas\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr] --a------ 2006-08-16 01:10 503808 c:\windows\Samsung\PanelMgr\SSMMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] --------- 2008-07-07 09:42 2156368 c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2009-01-01 20:35 185872 c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher] --a------ 2004-03-18 10:33 892928 c:\arquivos de programas\Logitech\iTouch\iTouch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-08-11 11:43 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] -r------- 2006-06-20 19:42 577536 c:\windows\soundman.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "d:\\Karin Noga\\Jogos\\Jogos\\Battlefield 1942\\BF1942.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Arquivos de programas\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\TmNationsForever\\TmForever.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "c:\\Arquivos de programas\\Arquivos comuns\\Microsoft Shared\\DW\\DW20.EXE"= S1 aswSP;avast! Self Protection; [x] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560] S2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [2006-11-03 13592] S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\lccfltr.sys [2004-03-03 14095] --- --- *Deregistered* - Aavmker4 *Deregistered* - aawservice *Deregistered* - AFD *Deregistered* - ALG *Deregistered* - aswFsBlk *Deregistered* - aswMon2 *Deregistered* - aswRdr *Deregistered* - aswSP *Deregistered* - aswTdi *Deregistered* - aswUpdSv *Deregistered* - atirage3 *Deregistered* - AudioSrv *Deregistered* - audstub *Deregistered* - avast! Antivirus *Deregistered* - avast! Mail Scanner *Deregistered* - avast! Web Scanner *Deregistered* - Beep *Deregistered* - BITS *Deregistered* - Browser *Deregistered* - Cdfs *Deregistered* - CryptSvc *Deregistered* - DcomLaunch *Deregistered* - DgiVecp *Deregistered* - Dhcp *Deregistered* - dmio *Deregistered* - dmload *Deregistered* - dmserver *Deregistered* - Dnscache *Deregistered* - ElbyCDIO *Deregistered* - ERSvc *Deregistered* - EventSystem *Deregistered* - FastUserSwitchingCompatibility *Deregistered* - Fips *Deregistered* - FltMgr *Deregistered* - Ftdisk *Deregistered* - Gpc *Deregistered* - helpsvc *Deregistered* - HidServ *Deregistered* - HTTP *Deregistered* - ImapiService *Deregistered* - IpNat *Deregistered* - IPSec *Deregistered* - JavaQuickStarterService *Deregistered* - Kbdclass *Deregistered* - KSecDD *Deregistered* - lanmanserver *Deregistered* - lanmanworkstation *Deregistered* - LmHosts *Deregistered* - MDM *Deregistered* - mnmdd *Deregistered* - MountMgr *Deregistered* - MRxDAV *Deregistered* - MRxSmb *Deregistered* - Msfs *Deregistered* - mssmbios *Deregistered* - Mup *Deregistered* - NDIS *Deregistered* - NdisTapi *Deregistered* - Ndisuio *Deregistered* - NdisWan *Deregistered* - NDProxy *Deregistered* - NetBIOS *Deregistered* - NetBT *Deregistered* - Netman *Deregistered* - Nla *Deregistered* - Npfs *Deregistered* - Ntfs *Deregistered* - Null *Deregistered* - NVSvc *Deregistered* - PartMgr *Deregistered* - ParVdm *Deregistered* - PolicyAgent *Deregistered* - PptpMiniport *Deregistered* - ProtectedStorage *Deregistered* - PSched *Deregistered* - RasAcd *Deregistered* - Rasl2tp *Deregistered* - RasMan *Deregistered* - RasPppoe *Deregistered* - Raspti *Deregistered* - Rdbss *Deregistered* - RDPCDD *Deregistered* - rdpdr *Deregistered* - RpcSs *Deregistered* - SamSs *Deregistered* - Schedule *Deregistered* - Secdrv *Deregistered* - seclogon *Deregistered* - SENS *Deregistered* - SharedAccess *Deregistered* - ShellHWDetection *Deregistered* - Spooler *Deregistered* - sr *Deregistered* - srservice *Deregistered* - Srv *Deregistered* - SSDPSRV *Deregistered* - stisvc *Deregistered* - swenum *Deregistered* - TapiSrv *Deregistered* - Tcpip *Deregistered* - TermDD *Deregistered* - TermService *Deregistered* - Themes *Deregistered* - TrkWks *Deregistered* - Udfs *Deregistered* - Update *Deregistered* - upnphost *Deregistered* - VgaSave *Deregistered* - VolSnap *Deregistered* - W32Time *Deregistered* - Wanarp *Deregistered* - WebClient *Deregistered* - WinDefend *Deregistered* - winmgmt *Deregistered* - WmiApSrv *Deregistered* - wscsvc *Deregistered* - wuauserv *Deregistered* - WZCSVC [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2609aed3-d15f-11dd-9ccd-0017315b5fb6}] \Shell\AutoRun\command - G:\AutoRun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4932ea7-89b4-11dc-99d2-0017315b5fb6}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1c4eba5-c761-11dc-9ab5-0017315b5fb6}] \Shell\Auto\command - MicrosoftPowerPoint.exe \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df7293dc-596e-11dc-999d-0017315b5fb6}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe . Conteúdo da pasta 'Tarefas Agendadas' 2008-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2007-01-10 16:42] 2009-01-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1614895754-725345543-1003.job - c:\documents and settings\Karin\Configura [] 2009-01-22 c:\windows\Tasks\MP Scheduled Scan.job - c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 19:20] 2009-01-22 c:\windows\Tasks\ycxwlgvb.job - c:\windows\system32\opnmMeBt.dll [] . - - - - ORFÃOS REMOVIDOS - - - - BHO-{11dc5af3-abb9-4fa5-b2ad-84d43a741582} - (no file) HKCU-Run-Google Update - c:\documents and settings\Karin\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe . ------- Scan Suplementar ------- . uStart Page = hxxp://search.speedbit.com/ IE: &Clean Traces - c:\arquivos de programas\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\arquivos de programas\DAP\dapextie.htm IE: Add to AMV Converter... - c:\arquivos de programas\MP3 Player Utilities 4.18\AMVConverter\grab.html IE: Download &all with DAP - c:\arquivos de programas\DAP\dapextie2.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {6A7723BF-ABF2-4E7E-94B2-942BB0374B59} = 189.40.224.5 10.223.246.102 Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll FF - ProfilePath - . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-22 01:16:03 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... c:\docume~1\Karin\CONFIG~1\Temp\BIT3.tmp 0 bytes Varredura completada com sucesso arquivos/ficheiros ocultos: 1 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(692) c:\windows\system32\cscui.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe c:\arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe c:\arquivos de programas\Alwil Software\Avast4\ashServ.exe c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe c:\windows\system32\nvsvc32.exe c:\arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe c:\arquivos de programas\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\rundll32.exe c:\arquivos de programas\Adobe\Acrobat 6.0\Distillr\acrotray.exe . ************************************************************************** . Tempo para conclusão: 2009-01-22 1:19:09 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-01-22 03:18:53 ComboFix2.txt 2008-12-31 00:52:58 PrÚ-execuþÒo: 16 pasta(s) 80.568.483.840 bytes dispon¡veis P¾s execuþÒo: 16 pasta(s) 80,683,610,112 bytes dispon¡veis 450 --- E O F --- 2009-01-21 03:19:54 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Janeiro 28, 2009 Opa Noga, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1614895754-725345543-1003.job c:\docume~1\Karin\CONFIG~1\Temp\BIT3.tmp c:\windows\system32\eyupifuv.ini c:\windows\system32\imabatup.ini c:\windows\system32\xlxtwcrn.exe c:\windows\system32\lwhdjvsp.exe c:\windows\system32\znagoswz.exe c:\documents and settings\Karin\x.exe c:\arquivos de programas\GameTop.com c:\windows\system32\opnmMeBt.dll c:\windows\Tasks\ycxwlgvb.job c:\windows\MVSCREENSAVER.INI c:\windows\NV23442748.TMP c:\windows\imsins.BAK G:\AutoRun.exe Folder:: c:\documents and settings\Karin\Configura c:\arquivos de programas\AskSBar c:\windows\system32\nocfhjfaujf c:\windows\plmadfhdashd C:\32788R22FWJFW Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{F4F10C1D-87C7-404A-B4B3-000000000000}"=- "{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=- [-HKEY_CLASSES_ROOT\clsid\{f4f10c1d-87c7-404a-b4b3-000000000000}] [-HKEY_CLASSES_ROOT\SearchHook.SrchHook.1] [-HKEY_CLASSES_ROOT\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}] [-HKEY_CLASSES_ROOT\SearchHook.SrchHook] [-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}] [-HKEY_CLASSES_ROOT\clsid\{59385f95-c52f-4a84-b674-4a4206b17218}] [-HKEY_CLASSES_ROOT\clsid\{bc4be15d-6a34-4356-9e97-79e43da32b1d}] [-HKEY_CLASSES_ROOT\clsid\{59385f95-c52f-4a84-b674-4a4206b17218}] [-HKEY_CLASSES_ROOT\clsid\{bc4be15d-6a34-4356-9e97-79e43da32b1d}] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000000 [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2609aed3-d15f-11dd-9ccd-0017315b5fb6}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4932ea7-89b4-11dc-99d2-0017315b5fb6}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1c4eba5-c761-11dc-9ab5-0017315b5fb6}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df7293dc-596e-11dc-999d-0017315b5fb6}] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. PS.: Execute a ação com o seu pendrive conectado ao PC. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 Olá Ai vai o log do ComboFix ComboFix 08-12-24.01 - Karin 2009-02-05 19:55:05.4 - NTFSx86 Running from: d:\karin noga\Downloads\ComboFix.exe Command switches used :: d:\karin noga\Downloads\CFScript.txt . - REDUCED FUNCTIONALITY MODE - FILE :: c:\arquivos de programas\GameTop.com c:\docume~1\Karin\CONFIG~1\Temp\BIT3.tmp c:\documents and settings\Karin\x.exe c:\windows\imsins.BAK c:\windows\MVSCREENSAVER.INI c:\windows\NV23442748.TMP c:\windows\system32\eyupifuv.ini c:\windows\system32\imabatup.ini c:\windows\system32\lwhdjvsp.exe c:\windows\system32\opnmMeBt.dll c:\windows\system32\xlxtwcrn.exe c:\windows\system32\znagoswz.exe c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1614895754-725345543-1003.job c:\windows\Tasks\ycxwlgvb.job G:\AutoRun.exe . ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\32788R22FWJFW c:\arquivos de programas\AskSBar c:\arquivos de programas\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL c:\documents and settings\Karin\x.exe c:\windows\imsins.BAK c:\windows\MVSCREENSAVER.INI c:\windows\plmadfhdashd\ c:\windows\system32\eyupifuv.ini c:\windows\system32\imabatup.ini c:\windows\system32\lwhdjvsp.exe c:\windows\system32\nocfhjfaujf\ c:\windows\system32\xlxtwcrn.exe c:\windows\system32\znagoswz.exe c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-1614895754-725345543-1003.job c:\windows\Tasks\ycxwlgvb.job . ((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 ))))))))))))))))))))))))))))))) . 2009-02-05 19:52 . 2009-02-05 19:52 400,896 --a------ c:\windows\system32\CF18441.exe 2009-02-05 02:00 . 2009-02-05 02:00 <DIR> d-------- c:\arquivos de programas\Real 2009-02-05 02:00 . 2009-02-05 02:00 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\xing shared 2009-02-05 01:58 . 2009-02-05 11:41 <DIR> d-------- c:\arquivos de programas\RelevantKnowledge 2009-02-03 23:10 . 2009-02-03 23:10 <DIR> d-------- C:\Downloads 2009-02-03 22:47 . 2009-02-05 13:23 <DIR> d-------- C:\Across the Universe[2007]DvDrip[Eng]-FXG 2009-02-03 22:37 . 2008-11-06 14:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll 2009-02-03 22:37 . 2008-12-07 16:08 795,648 --a------ c:\windows\system32\xvidcore.dll 2009-02-03 22:37 . 2008-11-06 14:33 684,032 --a------ c:\windows\system32\divx.dll 2009-02-03 22:37 . 2004-01-25 14:18 217,088 --a------ c:\windows\system32\yv12vfw.dll 2009-02-03 22:37 . 2008-12-07 16:08 130,048 --a------ c:\windows\system32\xvidvfw.dll 2009-02-03 22:37 . 2008-12-10 22:33 86,016 --a------ c:\windows\system32\dpl100.dll 2009-02-03 22:37 . 2008-10-03 10:30 414 --a------ c:\windows\system32\lame_acm.xml 2009-02-03 22:33 . 2009-02-05 01:57 <DIR> d-------- c:\arquivos de programas\ffdshow 2009-02-03 22:33 . 2008-06-08 22:58 60,273 --a------ c:\windows\system32\pthreadGC2.dll 2009-02-03 22:33 . 2008-12-08 12:53 57,344 --a------ c:\windows\system32\ff_vfw.dll 2009-02-03 22:33 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest 2009-02-03 01:08 . 2009-02-05 19:51 <DIR> d-------- c:\documents and settings\Karin\Dados de aplicativos\uTorrent 2009-02-03 01:08 . 2009-02-03 01:08 <DIR> d-------- c:\arquivos de programas\uTorrent 2009-01-22 23:50 . 2008-10-15 23:02 1,499,136 -----c--- c:\windows\system32\dllcache\shdocvw.dll 2009-01-22 23:50 . 2008-10-15 23:02 668,160 -----c--- c:\windows\system32\dllcache\wininet.dll 2009-01-22 23:50 . 2008-10-15 23:02 619,520 -----c--- c:\windows\system32\dllcache\urlmon.dll 2009-01-22 23:50 . 2008-05-09 08:55 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll 2009-01-22 23:50 . 2008-05-09 08:55 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll 2009-01-22 23:50 . 2008-05-09 08:55 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll 2009-01-22 23:50 . 2008-05-08 09:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe 2009-01-22 23:50 . 2008-05-09 06:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe 2009-01-22 23:50 . 2008-05-09 08:55 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll 2009-01-22 23:49 . 2008-08-14 11:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2009-01-22 23:49 . 2008-08-14 11:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-01-22 23:49 . 2008-08-14 11:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-01-22 23:49 . 2008-08-14 11:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2009-01-22 23:49 . 2008-09-15 13:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys 2009-01-22 22:01 . 2008-12-12 15:02 3,088,896 -----c--- c:\windows\system32\dllcache\mshtml.dll 2009-01-22 21:51 . 2008-06-14 15:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys 2009-01-22 17:12 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2009-01-22 17:12 . 2008-05-08 12:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys 2009-01-22 17:11 . 2008-04-11 17:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll 2009-01-22 17:11 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll 2009-01-22 15:38 . 2009-01-22 15:38 <DIR> d-------- c:\windows\system32\pt-br 2009-01-22 15:38 . 2009-01-22 15:38 <DIR> d-------- c:\windows\system32\bits 2009-01-22 15:38 . 2009-01-22 15:38 <DIR> d-------- c:\windows\l2schemas 2009-01-22 15:36 . 2009-01-22 15:38 <DIR> d-------- c:\windows\ServicePackFiles 2009-01-22 14:51 . 2009-01-22 14:51 <DIR> d-------- c:\windows\Samsung 2009-01-22 01:21 . 2009-01-22 01:21 <DIR> d-------- C:\DVD2 2009-01-21 22:27 . 2009-01-21 22:27 <DIR> d-------- c:\arquivos de programas\AVIConverter 2009-01-21 22:11 . 2008-04-14 00:20 1,888,992 --------- c:\windows\system32\ati3duag.dll 2009-01-21 01:19 . 2009-01-23 01:36 <DIR> d--h----- c:\windows\$hf_mig$ 2009-01-20 23:11 . 2008-12-11 08:57 333,952 -----c--- c:\windows\system32\dllcache\srv.sys 2009-01-19 23:54 . 2009-01-22 01:18 <DIR> d-------- C:\OdontoPlus 2009-01-09 09:56 . 2009-01-09 09:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SlySoft 2009-01-07 23:38 . 2009-02-03 21:25 <DIR> d-------- c:\arquivos de programas\SlySoft 2009-01-07 00:24 . 2003-06-25 19:38 14,848 --a------ c:\arquivos de programas\aida32.exe 2009-01-05 22:47 . 2009-01-05 22:47 <DIR> d-------- c:\arquivos de programas\Alwil Software . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-05 12:47 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP 2009-02-05 04:00 --------- d-----w c:\arquivos de programas\Arquivos comuns\Real 2009-02-05 01:32 --------- d-----w c:\arquivos de programas\K-Lite Codec Pack 2009-02-03 23:56 --------- d-----w c:\arquivos de programas\HooTech 2009-02-03 23:35 --------- d-----w c:\arquivos de programas\Google 2009-02-03 23:27 --------- d-----w c:\arquivos de programas\Yahoo! 2009-02-03 22:40 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\AdobeUM 2009-02-03 16:21 286,720 ------w c:\windows\Setup1.exe 2009-02-03 14:42 --------- d-----w c:\arquivos de programas\Live_TV 2009-02-03 03:07 --------- d-----w c:\arquivos de programas\eMule 2009-02-03 02:44 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\Skype 2009-02-02 22:15 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2009-01-22 02:48 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink 2009-01-21 03:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help 2009-01-07 03:09 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-01-06 00:06 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8 2009-01-02 12:13 --------- d-----w c:\arquivos de programas\SearchIn1Step 2009-01-01 16:58 --------- d-----w c:\arquivos de programas\Filzip 2008-12-31 23:58 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-31 23:57 --------- d-----w c:\arquivos de programas\Spybot - Search & Destroy 2008-12-31 13:59 24,872 ----a-w c:\windows\system32\drivers\ElbyCDIO.sys 2008-12-28 20:04 --------- d-----w c:\arquivos de programas\Ares Galaxy Turbo Booster 2008-12-28 19:11 --------- d-----w c:\arquivos de programas\Windows Media Lite 2008-12-28 18:44 --------- d-----w c:\arquivos de programas\MSBuild 2008-12-28 18:43 --------- d-----w c:\arquivos de programas\Microsoft.NET 2008-12-28 18:38 --------- d-----w c:\arquivos de programas\Microsoft Visual Studio 8 2008-12-28 16:47 --------- d-----w c:\arquivos de programas\MediaMonkey 2008-12-28 16:39 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\WildTangent 2008-12-26 03:09 --------- d-----w c:\arquivos de programas\DAP 2008-12-26 02:15 --------- d-----w c:\arquivos de programas\Windows Defender 2008-12-26 01:07 --------- d-----w c:\arquivos de programas\Ares 2008-12-25 23:06 --------- d-----w c:\arquivos de programas\Trend Micro 2008-12-25 19:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-12-25 19:09 --------- d-----w c:\arquivos de programas\Realtek AC97 2008-12-25 04:20 --------- d-----w c:\arquivos de programas\AbcPuzzles 2008-12-25 04:19 --------- d-----w c:\arquivos de programas\Extreme Tux Racer 2008-12-25 04:07 --------- d-----w c:\arquivos de programas\LEGO Company 2008-12-25 04:04 --------- d-----w c:\arquivos de programas\Readiris10 2008-12-25 04:01 --------- d-----w c:\arquivos de programas\Secret Maryo Chronicles 2008-12-25 04:00 --------- d-----w c:\arquivos de programas\Smart Projects 2008-12-25 03:53 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\LEGO Company 2008-12-25 03:52 --------- d-----w c:\arquivos de programas\TmNationsForever 2008-12-25 03:52 --------- d-----w c:\arquivos de programas\TIM Web Banda Larga 2008-12-25 03:52 --------- d-----w c:\arquivos de programas\Enigma 2008-12-25 03:36 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TrackMania 2008-12-25 03:00 --------- d-----w c:\arquivos de programas\GameTop.com 2008-12-25 02:53 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\SpeedBit 2008-12-25 02:53 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-12-25 02:48 --------- d-----w c:\arquivos de programas\LogyxPack 2008-12-25 02:36 50,688 ----a-w c:\windows\system32\wbhelp2.dll 2008-12-25 02:23 --------- d-----w c:\arquivos de programas\Lavasoft 2008-12-24 02:48 --------- d-----w c:\documents and settings\Karin\Dados de aplicativos\HTNetMeter 2008-12-23 02:51 686,111 ----a-w c:\windows\unins000.exe 2008-12-23 02:15 410,984 ----a-w c:\windows\system32\deploytk.dll 2008-12-23 02:15 --------- d-----w c:\arquivos de programas\Java 2008-12-21 22:28 --------- d-----w c:\arquivos de programas\Windows Live 2008-12-21 20:13 --------- d-----w c:\arquivos de programas\Microsoft 2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys 2008-12-03 00:37 49,480 ----a-w c:\windows\system32\sirenacm.dll 2008-11-19 17:21 93,128 ----a-w c:\windows\system32\ElbyCDIO.dll 2008-09-03 02:24 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-09-03 02:24 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-09-03 02:24 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-09-03 02:24 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-09-03 02:24 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot@2009-01-22_ 1.17.59.42 ))))))))))))))))))))))))))))))))))))))))) . + 2008-07-07 20:25:26 253,952 ----a-w c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll + 2007-11-30 12:39:04 18,296 ----a-w c:\windows\$hf_mig$\KB950974\spmsg.dll + 2007-11-30 12:39:04 233,336 ----a-w c:\windows\$hf_mig$\KB950974\spuninst.exe + 2007-11-30 12:39:04 26,488 ----a-w c:\windows\$hf_mig$\KB950974\update\spcustom.dll + 2007-11-30 12:38:57 760,696 ----a-w c:\windows\$hf_mig$\KB950974\update\update.exe + 2007-11-30 12:38:57 395,128 ----a-w c:\windows\$hf_mig$\KB950974\update\updspapi.dll + 2008-05-07 05:04:43 1,292,800 ----a-w c:\windows\$hf_mig$\KB951698\SP3QFE\quartz.dll + 2007-11-30 11:18:16 18,296 ----a-w c:\windows\$hf_mig$\KB951698\spmsg.dll + 2007-11-30 11:18:16 233,336 ----a-w c:\windows\$hf_mig$\KB951698\spuninst.exe + 2007-11-30 11:18:16 26,488 ----a-w c:\windows\$hf_mig$\KB951698\update\spcustom.dll + 2007-11-30 12:39:05 760,696 ----a-w c:\windows\$hf_mig$\KB951698\update\update.exe + 2007-11-30 12:39:05 395,128 ----a-w c:\windows\$hf_mig$\KB951698\update\updspapi.dll + 2008-06-20 11:48:03 138,496 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\afd.sys + 2008-06-20 17:44:42 147,968 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\dnsapi.dll + 2008-06-20 17:44:42 247,808 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll + 2008-06-20 11:59:02 361,600 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys + 2008-06-20 11:16:44 225,856 ----a-w c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip6.sys + 2007-11-30 12:39:04 18,296 ----a-w c:\windows\$hf_mig$\KB951748\spmsg.dll + 2007-11-30 12:39:04 233,336 ----a-w c:\windows\$hf_mig$\KB951748\spuninst.exe + 2007-11-30 12:39:04 26,488 ----a-w c:\windows\$hf_mig$\KB951748\update\spcustom.dll + 2007-11-30 12:38:57 760,696 ----a-w c:\windows\$hf_mig$\KB951748\update\update.exe + 2007-11-30 12:38:57 395,128 ----a-w c:\windows\$hf_mig$\KB951748\update\updspapi.dll + 2008-06-24 16:53:55 74,240 ----a-w c:\windows\$hf_mig$\KB952954\SP3QFE\mscms.dll + 2007-11-30 12:39:04 18,296 ----a-w c:\windows\$hf_mig$\KB952954\spmsg.dll + 2007-11-30 12:39:04 233,336 ----a-w c:\windows\$hf_mig$\KB952954\spuninst.exe + 2007-11-30 12:39:04 26,488 ----a-w c:\windows\$hf_mig$\KB952954\update\spcustom.dll + 2007-11-30 12:39:05 760,696 ----a-w c:\windows\$hf_mig$\KB952954\update\update.exe + 2007-11-30 12:39:05 395,128 ----a-w c:\windows\$hf_mig$\KB952954\update\updspapi.dll + 2008-09-10 01:12:17 1,379,840 ----a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll + 2007-11-30 12:39:04 18,296 ----a-w c:\windows\$hf_mig$\KB954459\spmsg.dll + 2007-11-30 12:39:04 233,336 ----a-w c:\windows\$hf_mig$\KB954459\spuninst.exe + 2007-11-30 12:39:04 26,488 ----a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll + 2007-11-30 12:39:05 760,696 ----a-w c:\windows\$hf_mig$\KB954459\update\update.exe + 2007-11-30 12:39:05 395,128 ----a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll + 2008-10-23 12:44:38 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll + 2008-07-08 12:58:40 18,296 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll + 2008-07-08 12:58:41 233,336 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe + 2008-07-08 12:58:40 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll + 2008-07-09 07:34:54 760,696 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe + 2008-07-09 07:35:02 395,128 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll - 2008-08-28 10:04:17 333,056 -c----w c:\windows\$NtUninstallKB958687$\srv.sys - 2006-10-04 14:05:26 39,424 ------w c:\windows\AppPatch\acadproc.dll + 2008-04-14 02:20:22 39,424 ----a-w c:\windows\AppPatch\acadproc.dll - 2004-08-04 03:45:22 1,852,416 ----a-w c:\windows\AppPatch\AcGenral.dll + 2008-04-14 02:20:23 1,852,928 ----a-w c:\windows\AppPatch\acgenral.dll - 2004-08-04 03:45:22 450,048 ----a-w c:\windows\AppPatch\AcLayers.dll + 2008-04-14 02:20:23 451,072 ----a-w c:\windows\AppPatch\aclayers.dll - 2004-08-04 03:45:22 137,728 ----a-w c:\windows\AppPatch\AcLua.dll + 2008-04-14 02:20:23 141,312 ----a-w c:\windows\AppPatch\aclua.dll - 2004-08-04 03:45:22 244,736 ----a-w c:\windows\AppPatch\AcSpecfc.dll + 2008-04-14 02:20:23 245,248 ----a-w c:\windows\AppPatch\acspecfc.dll - 2004-08-04 03:45:22 116,224 ----a-w c:\windows\AppPatch\AcXtrnal.dll + 2008-04-14 02:20:23 116,224 ----a-w c:\windows\AppPatch\acxtrnal.dll - 2008-06-14 17:59:51 272,384 ------w c:\windows\Driver Cache\i386\bthport.sys + 2008-06-14 17:34:41 272,384 ------w c:\windows\Driver Cache\i386\bthport.sys - 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys + 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys - 2008-08-14 13:45:20 2,140,160 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe + 2008-08-14 13:24:43 2,149,376 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe - 2008-08-14 13:45:24 2,061,952 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe + 2008-08-14 13:24:46 2,070,272 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe - 2008-08-14 13:45:20 2,019,840 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe + 2008-08-14 13:24:42 2,028,032 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe - 2008-08-14 13:45:25 2,184,576 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-08-14 13:24:45 2,193,408 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe + 2008-04-14 02:21:05 58,368 ------w c:\windows\ehome\medctrro.exe - 2007-06-13 13:21:56 1,697,280 ----a-w c:\windows\explorer.exe + 2008-04-14 02:20:58 1,035,776 ----a-w c:\windows\explorer.exe - 2004-08-04 03:45:28 34,816 ----a-w c:\windows\Help\sniffpol.dll + 2008-04-14 02:20:40 34,816 ----a-w c:\windows\Help\sniffpol.dll - 2004-08-04 03:45:28 33,280 ----a-w c:\windows\Help\sstub.dll + 2008-04-14 02:20:40 33,280 ----a-w c:\windows\Help\sstub.dll - 2004-08-04 03:45:28 279,040 ----a-w c:\windows\Help\tshoot.dll + 2008-04-14 02:20:40 279,040 ----a-w c:\windows\Help\tshoot.dll - 2005-05-26 23:22:01 143,872 ----a-w c:\windows\hh.exe + 2008-04-14 02:21:00 10,752 ----a-w c:\windows\hh.exe - 2004-08-04 03:45:24 220,160 ----a-w c:\windows\ime\mscandui.dll + 2008-04-14 02:20:32 220,160 ----a-w c:\windows\ime\mscandui.dll - 2004-08-04 03:45:28 130,048 ----a-w c:\windows\ime\SOFTKBD.DLL + 2008-04-14 02:20:40 130,048 ----a-w c:\windows\ime\softkbd.dll - 2004-08-04 03:44:52 62,976 ----a-w c:\windows\ime\SPGRMR.dll + 2008-04-13 16:43:18 62,976 ----a-w c:\windows\ime\spgrmr.dll - 2004-08-04 03:45:28 271,872 ----a-w c:\windows\ime\SPTIP.dll + 2008-04-14 02:20:40 271,872 ----a-w c:\windows\ime\sptip.dll + 2009-02-03 23:38:54 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe + 2009-02-03 23:38:54 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-03 23:38:54 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-03 23:38:54 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-03 23:38:54 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-03 23:38:54 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe - 2008-12-21 20:14:14 80,395 ----a-r c:\windows\Installer\{C8DD4EAD-674B-461B-94D5-4C80CCFB8401}\MsblIco.Exe + 2009-01-22 18:57:18 80,395 ----a-r c:\windows\Installer\{C8DD4EAD-674B-461B-94D5-4C80CCFB8401}\MsblIco.Exe + 2008-01-18 15:13:09 2,247 ------w c:\windows\Installer\tsclientmsitrans\tscdsbl.bat + 2007-12-12 10:33:51 18,917 ------w c:\windows\Installer\tsclientmsitrans\tscinst.vbs + 2007-10-30 10:06:46 13,801 ------w c:\windows\Installer\tsclientmsitrans\tscuinst.vbs + 2008-04-14 02:20:11 25,600 ------w c:\windows\Installer\tsclientmsitrans\tscupdc.dll - 2004-08-04 03:45:22 24,064 ----a-w c:\windows\msagent\agentanm.dll + 2008-04-14 02:20:23 24,064 ----a-w c:\windows\msagent\agentanm.dll - 2004-08-04 03:45:22 214,016 ----a-w c:\windows\msagent\agentctl.dll + 2008-04-14 02:20:23 214,016 ----a-w c:\windows\msagent\agentctl.dll - 2006-10-12 14:04:05 42,496 ----a-w c:\windows\msagent\agentdp2.dll + 2008-04-14 02:20:23 42,496 ----a-w c:\windows\msagent\agentdp2.dll - 2007-03-09 13:46:24 57,344 ----a-w c:\windows\msagent\agentdpv.dll + 2008-04-14 02:20:23 57,344 ----a-w c:\windows\msagent\agentdpv.dll - 2004-08-04 03:45:22 49,152 ----a-w c:\windows\msagent\agentmpx.dll + 2008-04-14 02:20:23 49,152 ----a-w c:\windows\msagent\agentmpx.dll - 2004-08-04 03:45:22 24,064 ----a-w c:\windows\msagent\agentpsh.dll + 2008-04-14 02:20:23 24,064 ----a-w c:\windows\msagent\agentpsh.dll - 2004-08-04 03:45:22 44,032 ----a-w c:\windows\msagent\agentsr.dll + 2008-04-14 02:20:23 44,032 ----a-w c:\windows\msagent\agentsr.dll - 2006-10-12 11:09:53 256,512 ----a-w c:\windows\msagent\agentsvr.exe + 2008-04-14 02:20:46 256,512 ----a-w c:\windows\msagent\agentsvr.exe - 2004-08-04 03:45:22 24,064 ----a-w c:\windows\msagent\agtintl.dll + 2008-04-14 02:20:23 24,064 ----a-w c:\windows\msagent\agtintl.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0405.dll + 2007-04-02 18:25:59 19,456 ----a-w c:\windows\msagent\intl\agt0405.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0406.dll + 2007-04-02 18:25:59 19,456 ----a-w c:\windows\msagent\intl\agt0406.dll - 2001-10-28 15:06:06 21,504 ----a-w c:\windows\msagent\intl\agt0407.dll + 2007-04-02 18:26:00 21,504 ----a-w c:\windows\msagent\intl\agt0407.dll - 2001-10-28 15:06:06 22,016 ----a-w c:\windows\msagent\intl\agt0408.dll + 2007-04-02 18:26:00 22,016 ----a-w c:\windows\msagent\intl\agt0408.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0409.dll + 2008-04-13 17:32:28 19,968 ----a-w c:\windows\msagent\intl\agt0409.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt040b.dll + 2007-04-02 18:26:00 19,456 ----a-w c:\windows\msagent\intl\agt040b.dll - 2001-10-28 15:06:06 21,504 ----a-w c:\windows\msagent\intl\agt040c.dll + 2007-04-02 18:26:00 21,504 ----a-w c:\windows\msagent\intl\agt040c.dll - 2001-10-28 15:06:06 19,968 ----a-w c:\windows\msagent\intl\agt040e.dll + 2007-04-02 18:26:00 19,968 ----a-w c:\windows\msagent\intl\agt040e.dll - 2001-10-28 15:06:06 20,992 ----a-w c:\windows\msagent\intl\agt0410.dll + 2007-04-02 18:26:00 20,992 ----a-w c:\windows\msagent\intl\agt0410.dll - 2001-10-28 15:06:06 20,992 ----a-w c:\windows\msagent\intl\agt0413.dll + 2007-04-02 18:26:01 20,992 ----a-w c:\windows\msagent\intl\agt0413.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0414.dll + 2007-04-02 18:26:01 19,456 ----a-w c:\windows\msagent\intl\agt0414.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0415.dll + 2007-04-02 18:26:01 19,456 ----a-w c:\windows\msagent\intl\agt0415.dll - 2001-10-28 15:06:06 20,480 ----a-w c:\windows\msagent\intl\agt0416.dll + 2007-04-02 18:26:01 20,480 ----a-w c:\windows\msagent\intl\agt0416.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt0419.dll + 2007-04-02 18:26:01 19,456 ----a-w c:\windows\msagent\intl\agt0419.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt041d.dll + 2007-04-02 18:26:01 19,456 ----a-w c:\windows\msagent\intl\agt041d.dll - 2001-10-28 15:06:06 19,456 ----a-w c:\windows\msagent\intl\agt041f.dll + 2007-04-02 18:26:01 19,456 ----a-w c:\windows\msagent\intl\agt041f.dll - 2001-10-28 15:06:06 20,992 ----a-w c:\windows\msagent\intl\agt0816.dll + 2007-04-02 18:26:02 20,992 ----a-w c:\windows\msagent\intl\agt0816.dll - 2001-10-28 15:06:06 20,480 ----a-w c:\windows\msagent\intl\agt0c0a.dll + 2007-04-02 18:26:02 20,480 ----a-w c:\windows\msagent\intl\agt0c0a.dll - 2004-08-04 03:45:26 39,936 ----a-w c:\windows\msagent\mslwvtts.dll + 2008-04-14 02:20:34 39,936 ----a-w c:\windows\msagent\mslwvtts.dll + 2008-04-14 02:20:24 33,792 ------w c:\windows\network diagnostic\custsat.dll + 2008-04-13 18:53:32 558,080 ------w c:\windows\network diagnostic\xpnetdiag.exe - 2000-08-31 10:00:00 29,696 ----a-w c:\windows\NIRCMD.exe + 2000-08-31 10:00:00 28,672 ----a-w c:\windows\NIRCMD.exe - 2004-08-04 03:45:40 70,144 ----a-w c:\windows\NOTEPAD.EXE + 2008-04-14 02:21:12 70,144 ----a-w c:\windows\notepad.exe - 2004-08-04 03:45:36 768,512 ----a-w c:\windows\pchealth\helpctr\binaries\helpctr.exe + 2008-04-14 02:21:00 769,024 ----a-w c:\windows\pchealth\helpctr\binaries\helpctr.exe - 2004-08-04 03:45:36 743,936 ----a-w c:\windows\pchealth\helpctr\binaries\HelpSvc.exe + 2008-04-14 02:21:00 744,448 ----a-w c:\windows\pchealth\helpctr\binaries\helpsvc.exe - 2004-08-04 03:45:36 18,944 ----a-w c:\windows\pchealth\helpctr\binaries\HscUpd.exe + 2008-04-14 02:21:00 18,432 ----a-w c:\windows\pchealth\helpctr\binaries\hscupd.exe - 2004-08-04 03:45:40 173,568 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe + 2008-04-14 02:21:09 171,520 ----a-w c:\windows\pchealth\helpctr\binaries\msconfig.exe - 2004-08-04 03:45:24 380,928 ----a-w c:\windows\pchealth\helpctr\binaries\msinfo.dll + 2008-04-14 02:20:34 381,440 ----a-w c:\windows\pchealth\helpctr\binaries\msinfo.dll - 2004-08-04 03:45:26 102,400 ----a-w c:\windows\pchealth\helpctr\binaries\pchshell.dll + 2008-04-14 02:20:37 102,912 ----a-w c:\windows\pchealth\helpctr\binaries\pchshell.dll - 2004-08-04 03:45:26 38,912 ----a-w c:\windows\pchealth\helpctr\binaries\pchsvc.dll + 2008-04-14 02:20:37 38,400 ----a-w c:\windows\pchealth\helpctr\binaries\pchsvc.dll - 2004-08-04 03:45:46 151,040 ----a-w c:\windows\pchealth\UploadLB\Binaries\UploadM.exe + 2008-04-14 02:21:21 151,040 ----a-w c:\windows\pchealth\UploadLB\Binaries\uploadm.exe - 2004-08-04 03:45:28 151,552 ----a-w c:\windows\PeerNet\sqldb20.dll + 2008-04-14 02:20:40 151,552 ----a-w c:\windows\PeerNet\sqldb20.dll - 2004-08-04 03:45:28 462,848 ----a-w c:\windows\PeerNet\sqlqp20.dll + 2008-04-14 02:20:40 462,848 ----a-w c:\windows\PeerNet\sqlqp20.dll - 2004-08-04 03:45:28 110,592 ----a-w c:\windows\PeerNet\sqlse20.dll + 2008-04-14 02:20:40 110,592 ----a-w c:\windows\PeerNet\sqlse20.dll - 2004-08-04 03:45:42 428,032 ----a-w c:\windows\regedit.exe + 2008-04-14 02:21:16 150,528 ----a-w c:\windows\regedit.exe + 2008-04-13 18:46:18 53,376 ------w c:\windows\ServicePackFiles\i386\1394bus.sys + 2008-04-13 18:40:50 12,288 ------w c:\windows\ServicePackFiles\i386\4mmdat.sys + 2008-04-13 18:46:20 48,128 ------w c:\windows\ServicePackFiles\i386\61883.sys + 2008-04-14 02:20:22 100,352 ------w c:\windows\ServicePackFiles\i386\6to4svc.dll + 2008-04-14 02:20:22 136,192 ------w c:\windows\ServicePackFiles\i386\aaclient.dll + 2004-08-04 00:32:22 231,552 ------w c:\windows\ServicePackFiles\i386\ac97ali.sys + 2004-08-04 00:32:32 84,480 ------w c:\windows\ServicePackFiles\i386\ac97via.sys + 2008-04-14 02:20:22 39,424 ------w c:\windows\ServicePackFiles\i386\acadproc.dll + 2008-04-14 02:20:46 188,416 ------w c:\windows\ServicePackFiles\i386\accwiz.exe + 2008-04-14 02:20:23 1,852,928 ------w c:\windows\ServicePackFiles\i386\acgenral.dll + 2008-04-14 02:20:23 451,072 ------w c:\windows\ServicePackFiles\i386\aclayers.dll + 2008-04-14 02:20:23 141,312 ------w c:\windows\ServicePackFiles\i386\aclua.dll + 2008-04-14 02:20:23 116,736 ------w c:\windows\ServicePackFiles\i386\aclui.dll + 2008-04-14 01:50:05 188,416 ------w c:\windows\ServicePackFiles\i386\acpi.sys + 2008-04-14 02:20:23 245,248 ------w c:\windows\ServicePackFiles\i386\acspecfc.dll + 2008-04-14 02:20:23 193,536 ------w c:\windows\ServicePackFiles\i386\activeds.dll + 2008-04-14 02:20:46 4,096 ------w c:\windows\ServicePackFiles\i386\actmovie.exe + 2008-04-14 02:20:23 98,304 ------w c:\windows\ServicePackFiles\i386\actxprxy.dll + 2008-04-14 02:20:23 116,224 ------w c:\windows\ServicePackFiles\i386\acxtrnal.dll + 2008-04-14 02:20:23 29,696 ------w c:\windows\ServicePackFiles\i386\admexs.dll + 2008-04-14 02:20:23 20,540 ------w c:\windows\ServicePackFiles\i386\admin.dll + 2008-04-14 02:20:46 16,439 ------w c:\windows\ServicePackFiles\i386\admin.exe + 2004-08-04 00:32:24 10,880 ------w c:\windows\ServicePackFiles\i386\admjoy.sys + 2008-04-14 02:20:23 61,440 ------w c:\windows\ServicePackFiles\i386\admparse.dll + 2008-04-14 02:20:23 43,520 ------w c:\windows\ServicePackFiles\i386\admwprox.dll + 2008-04-14 02:20:23 290,816 ------w c:\windows\ServicePackFiles\i386\adsiis51.dll + 2008-04-14 02:20:23 175,616 ------w c:\windows\ServicePackFiles\i386\adsldp.dll + 2008-04-14 02:20:23 143,360 ------w c:\windows\ServicePackFiles\i386\adsldpc.dll + 2008-04-14 02:20:23 68,096 ------w c:\windows\ServicePackFiles\i386\adsmsext.dll + 2008-04-14 02:20:23 263,680 ------w c:\windows\ServicePackFiles\i386\adsnt.dll + 2008-04-14 02:20:23 123,392 ------w c:\windows\ServicePackFiles\i386\adsnw.dll + 2007-04-02 13:10:44 85,813 ------w c:\windows\ServicePackFiles\i386\adsutil.vbs + 2008-04-14 02:20:23 4,255 ------w c:\windows\ServicePackFiles\i386\adv01nt5.dll + 2008-04-14 02:20:23 3,967 ------w c:\windows\ServicePackFiles\i386\adv02nt5.dll + 2008-04-14 02:20:23 3,615 ------w c:\windows\ServicePackFiles\i386\adv05nt5.dll + 2008-04-14 02:20:23 3,647 ------w c:\windows\ServicePackFiles\i386\adv07nt5.dll + 2008-04-14 02:20:23 3,135 ------w c:\windows\ServicePackFiles\i386\adv08nt5.dll + 2008-04-14 02:20:23 3,711 ------w c:\windows\ServicePackFiles\i386\adv09nt5.dll + 2008-04-14 02:20:23 3,775 ------w c:\windows\ServicePackFiles\i386\adv11nt5.dll + 2008-04-14 02:20:23 683,520 ------w c:\windows\ServicePackFiles\i386\advapi32.dll + 2008-04-14 02:20:23 101,376 ------w c:\windows\ServicePackFiles\i386\advpack.dll + 2008-04-13 16:39:23 142,592 ------w c:\windows\ServicePackFiles\i386\aec.sys + 2008-04-13 19:19:23 138,112 ------w c:\windows\ServicePackFiles\i386\afd.sys + 2008-04-14 02:20:23 24,064 ------w c:\windows\ServicePackFiles\i386\agentanm.dll + 2008-04-14 02:20:23 214,016 ------w c:\windows\ServicePackFiles\i386\agentctl.dll + 2008-04-14 02:20:23 42,496 ------w c:\windows\ServicePackFiles\i386\agentdp2.dll + 2008-04-14 02:20:23 57,344 ------w c:\windows\ServicePackFiles\i386\agentdpv.dll + 2008-04-14 02:20:23 49,152 ------w c:\windows\ServicePackFiles\i386\agentmpx.dll + 2008-04-14 02:20:23 24,064 ------w c:\windows\ServicePackFiles\i386\agentpsh.dll + 2008-04-14 02:20:23 44,032 ------w c:\windows\ServicePackFiles\i386\agentsr.dll + 2008-04-14 02:20:46 256,512 ------w c:\windows\ServicePackFiles\i386\agentsvr.exe + 2008-04-13 18:36:38 42,368 ------w c:\windows\ServicePackFiles\i386\agp440.sys + 2008-04-13 18:36:39 44,928 ------w c:\windows\ServicePackFiles\i386\agpcpq.sys + 2007-04-02 18:25:59 19,456 ------w c:\windows\ServicePackFiles\i386\agt0401.dll + 2007-04-02 18:25:59 19,456 ------w c:\windows\ServicePackFiles\i386\agt0404.dll + 2007-04-02 18:25:59 19,456 ------w c:\windows\ServicePackFiles\i386\agt0405.dll + 2007-04-02 18:25:59 19,456 ------w c:\windows\ServicePackFiles\i386\agt0406.dll + 2007-04-02 18:26:00 21,504 ------w c:\windows\ServicePackFiles\i386\agt0407.dll + 2007-04-02 18:26:00 22,016 ------w c:\windows\ServicePackFiles\i386\agt0408.dll + 2008-04-13 17:32:28 19,968 ------w c:\windows\ServicePackFiles\i386\agt0409.dll + 2007-04-02 18:26:00 19,456 ------w c:\windows\ServicePackFiles\i386\agt040b.dll + 2007-04-02 18:26:00 21,504 ------w c:\windows\ServicePackFiles\i386\agt040c.dll + 2007-04-02 18:26:00 19,456 ------w c:\windows\ServicePackFiles\i386\agt040d.dll + 2007-04-02 18:26:00 19,968 ------w c:\windows\ServicePackFiles\i386\agt040e.dll + 2007-04-02 18:26:00 20,992 ------w c:\windows\ServicePackFiles\i386\agt0410.dll + 2007-04-02 18:26:00 19,456 ------w c:\windows\ServicePackFiles\i386\agt0411.dll + 2007-04-02 18:26:00 19,456 ------w c:\windows\ServicePackFiles\i386\agt0412.dll + 2007-04-02 18:26:01 20,992 ------w c:\windows\ServicePackFiles\i386\agt0413.dll + 2007-04-02 18:26:01 19,456 ------w c:\windows\ServicePackFiles\i386\agt0414.dll + 2007-04-02 18:26:01 19,456 ------w c:\windows\ServicePackFiles\i386\agt0415.dll + 2007-04-02 18:26:01 20,480 ------w c:\windows\ServicePackFiles\i386\agt0416.dll + 2007-04-02 18:26:01 19,456 ------w c:\windows\ServicePackFiles\i386\agt0419.dll + 2007-04-02 18:26:01 19,456 ------w c:\windows\ServicePackFiles\i386\agt041d.dll + 2007-04-02 18:26:01 19,456 ------w c:\windows\ServicePackFiles\i386\agt041f.dll + 2007-04-02 18:26:02 19,456 ------w c:\windows\ServicePackFiles\i386\agt0804.dll + 2007-04-02 18:26:02 20,992 ------w c:\windows\ServicePackFiles\i386\agt0816.dll + 2007-04-02 18:26:02 20,480 ------w c:\windows\ServicePackFiles\i386\agt0c0a.dll + 2008-04-14 02:20:23 24,064 ------w c:\windows\ServicePackFiles\i386\agtintl.dll + 2008-04-14 02:20:46 98,304 ------w c:\windows\ServicePackFiles\i386\ahui.exe + 2008-04-14 02:20:46 44,544 ------w c:\windows\ServicePackFiles\i386\alg.exe + 2008-04-13 18:36:38 42,752 ------w c:\windows\ServicePackFiles\i386\alim1541.sys + 2008-04-14 02:20:23 17,408 ------w c:\windows\ServicePackFiles\i386\alrsvc.dll + 2008-04-13 18:36:39 43,008 ------w c:\windows\ServicePackFiles\i386\amdagp.sys + 2008-04-14 01:51:11 41,472 ------w c:\windows\ServicePackFiles\i386\amdk6.sys + 2008-04-14 01:51:12 41,856 ------w c:\windows\ServicePackFiles\i386\amdk7.sys + 2008-04-14 02:20:23 70,656 ------w c:\windows\ServicePackFiles\i386\amstream.dll + 2004-08-04 00:31:20 36,224 ------w c:\windows\ServicePackFiles\i386\an983.sys + 2008-04-14 02:20:23 109,568 ------w c:\windows\ServicePackFiles\i386\appconf.dll + 2008-04-14 02:20:23 125,952 ------w c:\windows\ServicePackFiles\i386\apphelp.dll + 2008-04-14 02:20:23 172,032 ------w c:\windows\ServicePackFiles\i386\appmgmts.dll + 2008-04-14 02:20:23 297,984 ------w c:\windows\ServicePackFiles\i386\appmgr.dll + 2008-04-14 02:20:23 332,800 ------w c:\windows\ServicePackFiles\i386\aqueue.dll + 2008-04-13 18:51:25 60,800 ------w c:\windows\ServicePackFiles\i386\arp1394.sys + 2008-04-14 02:20:23 374,784 ------w c:\windows\ServicePackFiles\i386\asp51.dll + 2008-04-13 16:09:58 20,480 ------w c:\windows\ServicePackFiles\i386\aspnet_filter.dll + 2008-04-13 16:09:59 200,704 ------w c:\windows\ServicePackFiles\i386\aspnet_isapi.dll + 2008-04-13 16:10:01 24,576 ------w c:\windows\ServicePackFiles\i386\aspnet_regiis.exe + 2008-04-13 16:10:01 32,768 ------w c:\windows\ServicePackFiles\i386\aspnet_state.exe + 2008-04-13 16:10:01 32,768 ------w c:\windows\ServicePackFiles\i386\aspnet_wp.exe + 2008-04-14 02:20:46 30,208 ------w c:\windows\ServicePackFiles\i386\asr_fmt.exe + 2008-04-14 02:20:46 32,768 ------w c:\windows\ServicePackFiles\i386\asr_pfu.exe + 2008-04-14 02:20:23 65,024 ------w c:\windows\ServicePackFiles\i386\asycfilt.dll + 2008-04-13 18:57:27 14,336 ------w c:\windows\ServicePackFiles\i386\asyncmac.sys + 2008-04-14 02:20:46 25,600 ------w c:\windows\ServicePackFiles\i386\at.exe + 2008-04-13 18:40:30 96,512 ------w c:\windows\ServicePackFiles\i386\atapi.sys + 2004-08-04 00:29:30 56,623 ------w c:\windows\ServicePackFiles\i386\ati1btxx.sys + 2004-08-04 00:29:30 11,615 ------w c:\windows\ServicePackFiles\i386\ati1mdxx.sys + 2004-08-04 00:29:30 12,047 ------w c:\windows\ServicePackFiles\i386\ati1pdxx.sys + 2004-08-04 00:29:32 30,671 ------w c:\windows\ServicePackFiles\i386\ati1raxx.sys + 2004-08-04 00:29:32 63,663 ------w c:\windows\ServicePackFiles\i386\ati1rvxx.sys + 2004-08-04 00:29:32 26,367 ------w c:\windows\ServicePackFiles\i386\ati1snxx.sys + 2004-08-04 00:29:32 21,343 ------w c:\windows\ServicePackFiles\i386\ati1ttxx.sys + 2004-08-04 00:29:32 36,463 ------w c:\windows\ServicePackFiles\i386\ati1tuxx.sys + 2004-08-04 00:29:32 29,455 ------w c:\windows\ServicePackFiles\i386\ati1xbxx.sys + 2004-08-04 00:29:32 34,735 ------w c:\windows\ServicePackFiles\i386\ati1xsxx.sys + 2008-04-14 02:20:23 229,376 ------w c:\windows\ServicePackFiles\i386\ati2cqag.dll + 2008-04-14 02:20:23 377,984 ------w c:\windows\ServicePackFiles\i386\ati2dvaa.dll + 2008-04-14 02:20:24 201,728 ------w c:\windows\ServicePackFiles\i386\ati2dvag.dll + 2004-08-04 02:36:02 327,040 ------w c:\windows\ServicePackFiles\i386\ati2mtaa.sys + 2004-08-04 02:36:02 701,440 ------w c:\windows\ServicePackFiles\i386\ati2mtag.sys + 2008-04-14 02:20:24 870,784 ------w c:\windows\ServicePackFiles\i386\ati3d1ag.dll + 2008-04-14 02:20:24 1,057,760 ------w c:\windows\ServicePackFiles\i386\ati3d2ag.dll + 2008-04-14 02:20:24 1,888,992 ------w c:\windows\ServicePackFiles\i386\ati3duag.dll + 2004-08-04 00:29:28 57,856 ------w c:\windows\ServicePackFiles\i386\atinbtxx.sys + 2004-08-04 00:29:30 13,824 ------w c:\windows\ServicePackFiles\i386\atinmdxx.sys + 2004-08-04 00:29:30 14,336 ------w c:\windows\ServicePackFiles\i386\atinpdxx.sys + 2004-08-04 00:29:30 52,224 ------w c:\windows\ServicePackFiles\i386\atinraxx.sys + 2004-08-04 00:29:32 104,960 ------w c:\windows\ServicePackFiles\i386\atinrvxx.sys + 2004-08-04 00:29:32 28,672 ------w c:\windows\ServicePackFiles\i386\atinsnxx.sys + 2004-08-04 00:29:32 13,824 ------w c:\windows\ServicePackFiles\i386\atinttxx.sys + 2004-08-04 00:29:32 73,216 ------w c:\windows\ServicePackFiles\i386\atintuxx.sys + 2004-08-04 00:29:32 31,744 ------w c:\windows\ServicePackFiles\i386\atinxbxx.sys + 2004-08-04 00:29:32 63,488 ------w c:\windows\ServicePackFiles\i386\atinxsxx.sys + 2008-04-14 02:20:24 32,768 ------w c:\windows\ServicePackFiles\i386\ativtmxx.dll + 2008-04-14 02:20:24 516,768 ------w c:\windows\ServicePackFiles\i386\ativvaxx.dll + 2008-04-14 02:20:24 58,880 ------w c:\windows\ServicePackFiles\i386\atl.dll + 2008-04-14 02:20:46 11,776 ------w c:\windows\ServicePackFiles\i386\atmadm.exe + 2008-04-13 18:51:25 59,904 ------w c:\windows\ServicePackFiles\i386\atmarpc.sys + 2008-04-14 02:18:02 285,696 ------w c:\windows\ServicePackFiles\i386\atmfd.dll + 2008-04-13 18:51:30 55,808 ------w c:\windows\ServicePackFiles\i386\atmlane.sys + 2008-04-14 02:20:24 30,208 ------w c:\windows\ServicePackFiles\i386\atmlib.dll + 2008-04-14 02:20:47 12,288 ------w c:\windows\ServicePackFiles\i386\attrib.exe + 2008-04-14 02:20:24 21,183 ------w c:\windows\ServicePackFiles\i386\atv01nt5.dll + 2008-04-14 02:20:24 11,359 ------w c:\windows\ServicePackFiles\i386\atv02nt5.dll + 2008-04-14 02:20:24 25,471 ------w c:\windows\ServicePackFiles\i386\atv04nt5.dll + 2008-04-14 02:20:24 14,143 ------w c:\windows\ServicePackFiles\i386\atv06nt5.dll + 2008-04-14 02:20:24 17,279 ------w c:\windows\ServicePackFiles\i386\atv10nt5.dll + 2008-04-14 02:20:24 42,496 ------w c:\windows\ServicePackFiles\i386\audiosrv.dll + 2008-04-14 02:20:47 14,336 ------w c:\windows\ServicePackFiles\i386\auditusr.exe + 2008-04-14 02:20:24 20,540 ------w c:\windows\ServicePackFiles\i386\author.dll + 2008-04-14 02:20:47 16,439 ------w c:\windows\ServicePackFiles\i386\author.exe + 2008-04-14 02:20:24 62,464 ------w c:\windows\ServicePackFiles\i386\authz.dll + 2008-04-14 02:20:47 616,960 ------w c:\windows\ServicePackFiles\i386\autochk.exe + 2008-04-14 02:20:48 630,784 ------w c:\windows\ServicePackFiles\i386\autoconv.exe + 2008-04-14 02:20:48 608,768 ------w c:\windows\ServicePackFiles\i386\autofmt.exe + 2008-04-14 02:20:48 11,264 ------w c:\windows\ServicePackFiles\i386\autolfn.exe + 2008-04-13 18:46:20 38,912 ------w c:\windows\ServicePackFiles\i386\avc.sys + 2008-04-13 18:46:07 13,696 ------w c:\windows\ServicePackFiles\i386\avcstrm.sys + 2008-04-14 02:20:24 85,504 ------w c:\windows\ServicePackFiles\i386\avifil32.dll + 2008-04-14 02:20:24 233,472 ------w c:\windows\ServicePackFiles\i386\azroles.dll + 2008-04-14 02:20:24 52,736 ------w c:\windows\ServicePackFiles\i386\basesrv.dll + 2008-04-14 02:20:24 29,184 ------w c:\windows\ServicePackFiles\i386\batmeter.dll + 2008-04-14 02:20:24 8,704 ------w c:\windows\ServicePackFiles\i386\batt.dll + 2008-04-13 18:36:32 14,208 ------w c:\windows\ServicePackFiles\i386\battc.sys + 2008-04-13 18:46:21 11,776 ------w c:\windows\ServicePackFiles\i386\bdasup.sys + 2008-04-14 02:20:24 17,408 ------w c:\windows\ServicePackFiles\i386\bidispl.dll + 2008-04-14 02:20:24 8,192 ------w c:\windows\ServicePackFiles\i386\bitsprx2.dll + 2008-04-14 02:20:24 7,168 ------w c:\windows\ServicePackFiles\i386\bitsprx3.dll + 2008-04-14 02:20:24 7,168 ------w c:\windows\ServicePackFiles\i386\bitsprx4.dll + 2008-04-14 02:20:50 71,680 ------w c:\windows\ServicePackFiles\i386\blastcln.exe + 2008-04-14 02:20:50 153,600 ------w c:\windows\ServicePackFiles\i386\bootcfg.exe + 2008-04-13 18:53:23 71,552 ------w c:\windows\ServicePackFiles\i386\bridge.sys + 2008-04-14 01:53:30 67,584 ------w c:\windows\ServicePackFiles\i386\browselc.dll + 2008-04-14 02:20:24 77,824 ------w c:\windows\ServicePackFiles\i386\browser.dll + 2008-04-14 02:20:24 1,025,536 ------w c:\windows\ServicePackFiles\i386\browseui.dll + 2008-04-14 02:20:24 78,336 ------w c:\windows\ServicePackFiles\i386\browsewm.dll + 2008-04-14 02:20:24 20,992 ------w c:\windows\ServicePackFiles\i386\bthci.dll + 2008-04-13 18:46:33 17,024 ------w c:\windows\ServicePackFiles\i386\bthenum.sys + 2008-04-13 18:46:33 37,888 ------w c:\windows\ServicePackFiles\i386\bthmodem.sys + 2008-04-13 18:51:34 101,120 ------w c:\windows\ServicePackFiles\i386\bthpan.sys + 2008-04-14 01:53:47 273,280 ------w c:\windows\ServicePackFiles\i386\bthport.sys + 2008-04-13 18:46:31 36,480 ------w c:\windows\ServicePackFiles\i386\bthprint.sys + 2008-04-14 02:20:24 30,208 ------w c:\windows\ServicePackFiles\i386\bthserv.dll + 2008-04-13 18:46:29 18,944 ------w c:\windows\ServicePackFiles\i386\bthusb.sys + 2008-04-14 02:20:24 50,688 ------w c:\windows\ServicePackFiles\i386\btpanui.dll + 2008-04-14 02:20:24 218,112 ------w c:\windows\ServicePackFiles\i386\c_g18030.dll + 2008-04-14 02:20:24 60,416 ------w c:\windows\ServicePackFiles\i386\cabinet.dll + 2008-04-14 02:20:24 84,992 ------w c:\windows\ServicePackFiles\i386\cabview.dll + 2008-04-14 02:20:50 20,480 ------w c:\windows\ServicePackFiles\i386\cacls.exe + 2008-04-14 02:20:24 385,024 ------w c:\windows\ServicePackFiles\i386\callcont.dll + 2008-04-14 02:20:24 121,856 ------w c:\windows\ServicePackFiles\i386\camext30.dll + 2008-04-14 02:20:24 50,688 ------w c:\windows\ServicePackFiles\i386\camocx.dll + 2008-04-14 02:20:24 152,576 ------w c:\windows\ServicePackFiles\i386\capesnpn.dll + 2007-06-27 12:53:18 94,208 ------w c:\windows\ServicePackFiles\i386\caspol.exe + 2008-04-14 02:20:24 226,304 ------w c:\windows\ServicePackFiles\i386\catsrv.dll + 2008-04-14 02:20:24 85,504 ------w c:\windows\ServicePackFiles\i386\catsrvps.dll + 2008-04-14 02:20:24 625,664 ------w c:\windows\ServicePackFiles\i386\catsrvut.dll + 2008-04-13 18:46:23 17,024 ------w c:\windows\ServicePackFiles\i386\ccdecode.sys + 2008-04-13 19:14:21 63,744 ------w c:\windows\ServicePackFiles\i386\cdfs.sys + 2008-04-14 02:20:24 151,552 ------w c:\windows\ServicePackFiles\i386\cdfview.dll + 2008-04-14 02:20:24 66,560 ------w c:\windows\ServicePackFiles\i386\cdm.dll + 2008-04-14 02:20:24 2,091,520 ------w c:\windows\ServicePackFiles\i386\cdosys.dll + 2008-04-13 18:40:46 62,976 ------w c:\windows\ServicePackFiles\i386\cdrom.sys + 2008-04-14 02:20:24 199,680 ------w c:\windows\ServicePackFiles\i386\certcli.dll + 2008-04-14 02:20:24 464,384 ------w c:\windows\ServicePackFiles\i386\certmgr.dll + 2008-04-14 02:20:24 39,424 ------w c:\windows\ServicePackFiles\i386\cfgbkend.dll + 2008-04-14 02:18:05 16,896 ------w c:\windows\ServicePackFiles\i386\cfgmgr32.dll + 2008-04-14 02:20:50 188,480 ------w c:\windows\ServicePackFiles\i386\cfgwiz.exe + 2008-04-14 02:20:24 15,423 ------w c:\windows\ServicePackFiles\i386\ch7xxnt5.dll + 2008-04-13 18:40:58 8,192 ------w c:\windows\ServicePackFiles\i386\changer.sys + 2008-04-14 02:20:24 148,480 ------w c:\windows\ServicePackFiles\i386\cic.dll + 2008-04-14 02:20:24 1,359,360 ------w c:\windows\ServicePackFiles\i386\cimwin32.dll + 2008-04-14 02:20:24 69,120 ------w c:\windows\ServicePackFiles\i386\ciodm.dll + 2008-04-14 02:20:50 57,856 ------w c:\windows\ServicePackFiles\i386\cipher.exe + 2008-04-14 02:20:51 5,632 ------w c:\windows\ServicePackFiles\i386\cisvc.exe + 2008-04-13 19:16:22 49,536 ------w c:\windows\ServicePackFiles\i386\classpnp.sys + 2008-04-14 02:20:24 110,592 ------w c:\windows\ServicePackFiles\i386\clbcatex.dll + 2008-04-14 02:20:24 498,688 ------w c:\windows\ServicePackFiles\i386\clbcatq.dll + 2008-04-14 02:20:51 64,512 ------w c:\windows\ServicePackFiles\i386\cleanmgr.exe + 2008-04-14 02:20:24 77,824 ------w c:\windows\ServicePackFiles\i386\cliconfg.dll + 2008-04-14 02:20:51 20,480 ------w c:\windows\ServicePackFiles\i386\cliconfg.exe + 2008-04-14 02:20:51 104,960 ------w c:\windows\ServicePackFiles\i386\clipbrd.exe + 2008-04-14 02:20:51 33,280 ------w c:\windows\ServicePackFiles\i386\clipsrv.exe + 2008-04-14 02:20:24 58,368 ------w c:\windows\ServicePackFiles\i386\clusapi.dll + 2008-04-13 18:36:37 13,952 ------w c:\windows\ServicePackFiles\i386\cmbatt.sys + 2008-04-14 02:20:24 15,872 ------w c:\windows\ServicePackFiles\i386\cmcfg32.dll + 2008-04-14 02:20:52 400,896 ------w c:\windows\ServicePackFiles\i386\cmd.exe + 2008-04-14 02:20:24 348,672 ------w c:\windows\ServicePackFiles\i386\cmdial32.dll + 2008-04-14 02:20:52 25,600 ------w c:\windows\ServicePackFiles\i386\cmdl32.exe + 2008-04-14 02:20:52 39,936 ------w c:\windows\ServicePackFiles\i386\cmmon32.exe + 2008-04-14 02:20:24 188,928 ------w c:\windows\ServicePackFiles\i386\cmprops.dll + 2008-04-14 02:20:24 13,312 ------w c:\windows\ServicePackFiles\i386\cmsetacl.dll + 2008-04-14 02:20:52 65,024 ------w c:\windows\ServicePackFiles\i386\cmstp.exe + 2008-04-14 02:20:24 40,960 ------w c:\windows\ServicePackFiles\i386\cmutil.dll + 2008-04-14 02:20:24 49,152 ------w c:\windows\ServicePackFiles\i386\cnbjmon.dll + 2008-04-14 02:20:24 81,920 ------w c:\windows\ServicePackFiles\i386\cnbjmon2.dll + 2008-04-14 02:20:24 47,104 ------w c:\windows\ServicePackFiles\i386\coadmin.dll + 2008-04-13 16:44:16 17,920 ------w c:\windows\ServicePackFiles\i386\cobramsg.dll + 2008-04-14 02:20:24 60,416 ------w c:\windows\ServicePackFiles\i386\colbact.dll + 2008-04-14 02:20:24 28,160 ------w c:\windows\ServicePackFiles\i386\comaddin.dll + 2008-04-14 02:20:24 195,072 ------w c:\windows\ServicePackFiles\i386\comadmin.dll + 2008-04-14 02:20:24 617,472 ------w c:\windows\ServicePackFiles\i386\comctl32.dll + 2008-04-14 02:20:24 275,968 ------w c:\windows\ServicePackFiles\i386\comdlg32.dll + 2008-04-14 02:20:24 253,440 ------w c:\windows\ServicePackFiles\i386\compatui.dll + 2008-04-13 18:36:37 10,240 ------w c:\windows\ServicePackFiles\i386\compbatt.sys + 2008-04-14 02:20:24 24,064 ------w c:\windows\ServicePackFiles\i386\compfilt.dll + 2008-04-14 02:20:24 230,400 ------w c:\windows\ServicePackFiles\i386\compstui.dll + 2008-04-14 02:20:24 97,792 ------w c:\windows\ServicePackFiles\i386\comrepl.dll + 2008-04-14 02:20:52 9,728 ------w c:\windows\ServicePackFiles\i386\comrepl.exe + 2008-04-14 02:20:52 6,144 ------w c:\windows\ServicePackFiles\i386\comrereg.exe + 2008-04-14 02:20:24 821,760 ------w c:\windows\ServicePackFiles\i386\comres.dll + 2008-04-13 18:43:32 9,728 ------w c:\windows\ServicePackFiles\i386\comsdupd.exe + 2008-04-14 02:20:24 274,944 ------w c:\windows\ServicePackFiles\i386\comsetup.dll + 2008-04-14 02:20:24 167,424 ------w c:\windows\ServicePackFiles\i386\comsnap.dll + 2008-04-14 02:20:24 1,267,200 ------w c:\windows\ServicePackFiles\i386\comsvcs.dll + 2008-04-14 02:20:24 539,648 ------w c:\windows\ServicePackFiles\i386\comuid.dll + 2008-04-14 02:20:53 1,040,384 ------w c:\windows\ServicePackFiles\i386\conf.exe + 2008-04-14 02:20:24 45,056 ------w c:\windows\ServicePackFiles\i386\confmrsl.dll + 2008-04-14 02:20:24 358,400 ------w c:\windows\ServicePackFiles\i386\confmsp.dll + 2008-04-14 02:20:53 27,648 ------w c:\windows\ServicePackFiles\i386\conime.exe + 2008-04-13 16:10:05 69,632 ------w c:\windows\ServicePackFiles\i386\corperfmonext.dll + 2008-04-14 02:20:24 35,328 ------w c:\windows\ServicePackFiles\i386\corpol.dll + 2008-04-14 02:20:24 12,800 ------w c:\windows\ServicePackFiles\i386\credssp.dll + 2008-04-14 02:20:24 164,352 ------w c:\windows\ServicePackFiles\i386\credui.dll + 2008-04-14 01:57:17 40,832 ------w c:\windows\ServicePackFiles\i386\crusoe.sys + 2008-04-14 02:20:24 605,184 ------w c:\windows\ServicePackFiles\i386\crypt32.dll + 2008-04-14 02:20:24 75,264 ------w c:\windows\ServicePackFiles\i386\cryptdlg.dll + 2008-04-14 02:20:24 33,280 ------w c:\windows\ServicePackFiles\i386\cryptdll.dll + 2008-04-14 02:20:24 54,784 ------w c:\windows\ServicePackFiles\i386\cryptext.dll + 2008-04-14 02:20:24 64,512 ------w c:\windows\ServicePackFiles\i386\cryptnet.dll + 2008-04-14 02:20:24 62,464 ------w c:\windows\ServicePackFiles\i386\cryptsvc.dll + 2008-04-14 02:20:24 528,384 ------w c:\windows\ServicePackFiles\i386\cryptui.dll + 2008-04-13 16:10:13 49,152 ------w c:\windows\ServicePackFiles\i386\csc.exe + 2008-04-14 02:20:24 102,400 ------w c:\windows\ServicePackFiles\i386\cscdll.dll + 2007-06-27 12:53:47 589,824 ------w c:\windows\ServicePackFiles\i386\cscomp.dll + 2008-04-14 02:20:53 139,264 ------w c:\windows\ServicePackFiles\i386\cscript.exe + 2008-04-14 02:20:24 331,776 ------w c:\windows\ServicePackFiles\i386\cscui.dll + 2008-04-14 02:20:24 32,256 ------w c:\windows\ServicePackFiles\i386\csrsrv.dll + 2008-04-14 02:20:53 6,144 ------w c:\windows\ServicePackFiles\i386\csrss.exe + 2008-04-14 02:20:54 15,360 ------w c:\windows\ServicePackFiles\i386\ctfmon.exe + 2008-04-14 02:20:24 251,904 ------w c:\windows\ServicePackFiles\i386\ctmasetp.dll + 2008-04-14 02:20:24 33,792 ------w c:\windows\ServicePackFiles\i386\custsat.dll + 2004-08-04 00:32:26 48,640 ------w c:\windows\ServicePackFiles\i386\cwrwdm.sys + 2008-04-14 02:20:24 1,179,648 ------w c:\windows\ServicePackFiles\i386\d3d8.dll + 2008-04-14 02:20:24 8,192 ------w c:\windows\ServicePackFiles\i386\d3d8thk.dll + 2008-04-14 02:20:24 1,689,088 ------w c:\windows\ServicePackFiles\i386\d3d9.dll + 2008-04-14 02:20:24 824,320 ------w c:\windows\ServicePackFiles\i386\d3dim700.dll + 2008-04-14 02:20:24 1,055,744 ------w c:\windows\ServicePackFiles\i386\danim.dll + 2008-03-25 04:50:25 554,008 ------w c:\windows\ServicePackFiles\i386\dao360.dll + 2008-04-14 02:20:24 54,784 ------w c:\windows\ServicePackFiles\i386\dataclen.dll + 2008-04-14 02:20:24 165,376 ------w c:\windows\ServicePackFiles\i386\datime.dll + 2008-04-14 02:20:54 42,496 ------w c:\windows\ServicePackFiles\i386\davcdata.exe + 2008-04-14 02:20:24 25,600 ------w c:\windows\ServicePackFiles\i386\davclnt.dll + 2008-04-14 02:20:24 640,000 ------w c:\windows\ServicePackFiles\i386\dbghelp.dll + 2008-04-14 02:20:24 24,576 ------w c:\windows\ServicePackFiles\i386\dbmsrpcn.dll + 2008-04-14 02:20:24 110,592 ------w c:\windows\ServicePackFiles\i386\dbnetlib.dll + 2008-04-14 02:20:24 28,672 ------w c:\windows\ServicePackFiles\i386\dbnmpntw.dll + 2008-04-14 02:37:12 1,804 ------w c:\windows\ServicePackFiles\i386\dcache.bin + 2008-04-14 02:20:24 40,960 ------w c:\windows\ServicePackFiles\i386\dcap32.dll + 2008-04-14 02:20:24 8,704 ------w c:\windows\ServicePackFiles\i386\dciman32.dll + 2008-04-14 02:20:54 6,144 ------w c:\windows\ServicePackFiles\i386\dcomcnfg.exe + 2008-04-14 02:20:54 32,256 ------w c:\windows\ServicePackFiles\i386\ddeshare.exe + 2008-04-14 02:20:24 279,552 ------w c:\windows\ServicePackFiles\i386\ddraw.dll + 2008-04-14 02:20:24 27,136 ------w c:\windows\ServicePackFiles\i386\ddrawex.dll + 2008-04-14 02:20:54 25,088 ------w c:\windows\ServicePackFiles\i386\defrag.exe + 2008-04-14 02:20:24 59,904 ------w c:\windows\ServicePackFiles\i386\devenum.dll + 2008-04-14 02:20:24 288,768 ------w c:\windows\ServicePackFiles\i386\devmgr.dll + 2008-04-14 02:20:54 82,944 ------w c:\windows\ServicePackFiles\i386\dfrgfat.exe + 2008-04-14 02:20:54 105,472 ------w c:\windows\ServicePackFiles\i386\dfrgntfs.exe + 2008-04-14 02:20:24 39,424 ------w c:\windows\ServicePackFiles\i386\dfrgsnap.dll + 2008-04-14 02:20:24 124,416 ------w c:\windows\ServicePackFiles\i386\dfrgui.dll + 2008-04-14 02:20:24 28,672 ------w c:\windows\ServicePackFiles\i386\dfsshlex.dll + 2008-04-14 02:20:24 113,152 ------w c:\windows\ServicePackFiles\i386\dgnet.dll + 2008-04-14 02:20:24 126,976 ------w c:\windows\ServicePackFiles\i386\dhcpcsvc.dll + 2008-04-14 02:20:25 400,896 ------w c:\windows\ServicePackFiles\i386\dhcpmon.dll + 2008-04-14 02:20:25 48,640 ------w c:\windows\ServicePackFiles\i386\dhcpqec.dll + 2008-04-14 02:20:55 545,280 ------w c:\windows\ServicePackFiles\i386\dialer.exe + 2008-04-14 02:20:55 87,040 ------w c:\windows\ServicePackFiles\i386\diantz.exe + 2008-04-14 02:20:25 68,608 ------w c:\windows\ServicePackFiles\i386\digest.dll + 2008-04-14 02:20:25 19,456 ------w c:\windows\ServicePackFiles\i386\dimsntfy.dll + 2008-04-14 02:20:25 39,936 ------w c:\windows\ServicePackFiles\i386\dimsroam.dll + 2008-04-14 02:20:25 166,912 ------w c:\windows\ServicePackFiles\i386\dinput.dll + 2008-04-14 02:20:25 189,952 ------w c:\windows\ServicePackFiles\i386\dinput8.dll + 2008-04-14 02:20:25 86,528 ------w c:\windows\ServicePackFiles\i386\directdb.dll + 2008-04-13 18:40:47 36,352 ------w c:\windows\ServicePackFiles\i386\disk.sys + 2008-04-14 02:20:25 1,504,768 ------w c:\windows\ServicePackFiles\i386\diskcopy.dll + 2008-04-13 18:40:44 14,208 ------w c:\windows\ServicePackFiles\i386\diskdump.sys + 2008-04-14 02:20:55 165,376 ------w c:\windows\ServicePackFiles\i386\diskpart.exe + 2008-04-14 02:20:25 32,768 ------w c:\windows\ServicePackFiles\i386\dispex.dll + 2008-04-14 02:20:55 5,120 ------w c:\windows\ServicePackFiles\i386\dllhost.exe + 2008-04-13 18:40:51 8,320 ------w c:\windows\ServicePackFiles\i386\dlttape.sys + 2008-04-14 02:20:56 225,280 ------w c:\windows\ServicePackFiles\i386\dmadmin.exe + 2008-04-14 02:20:25 28,672 ------w c:\windows\ServicePackFiles\i386\dmband.dll + 2008-04-14 01:59:00 800,000 ------w c:\windows\ServicePackFiles\i386\dmboot.sys + 2008-04-14 02:20:25 61,440 ------w c:\windows\ServicePackFiles\i386\dmcompos.dll + 2008-04-14 02:20:25 285,184 ------w c:\windows\ServicePackFiles\i386\dmdlgs.dll + 2008-04-14 02:20:25 200,704 ------w c:\windows\ServicePackFiles\i386\dmdskmgr.dll + 2008-04-14 02:20:25 181,248 ------w c:\windows\ServicePackFiles\i386\dmime.dll + 2008-04-14 01:59:07 153,984 ------w c:\windows\ServicePackFiles\i386\dmio.sys + 2008-04-14 02:20:25 35,840 ------w c:\windows\ServicePackFiles\i386\dmloader.dll + 2008-04-14 02:20:56 15,872 ------w c:\windows\ServicePackFiles\i386\dmremote.exe + 2008-04-14 02:20:25 82,432 ------w c:\windows\ServicePackFiles\i386\dmscript.dll + 2008-04-14 02:20:25 23,552 ------w c:\windows\ServicePackFiles\i386\dmserver.dll + 2008-04-14 02:20:25 105,984 ------w c:\windows\ServicePackFiles\i386\dmstyle.dll + 2008-04-14 02:20:25 103,424 ------w c:\windows\ServicePackFiles\i386\dmsynth.dll + 2008-04-14 02:20:25 104,448 ------w c:\windows\ServicePackFiles\i386\dmusic.dll + 2008-04-13 18:45:01 52,864 ------w c:\windows\ServicePackFiles\i386\dmusic.sys + 2008-04-14 02:20:25 55,296 ------w c:\windows\ServicePackFiles\i386\dmutil.dll + 2008-04-14 02:20:25 147,968 ------w c:\windows\ServicePackFiles\i386\dnsapi.dll + 2008-04-14 02:20:25 45,568 ------w c:\windows\ServicePackFiles\i386\dnsrslvr.dll + 2008-04-14 02:20:25 48,640 ------w c:\windows\ServicePackFiles\i386\docprop2.dll + 2004-08-04 01:51:26 54,048 ------w c:\windows\ServicePackFiles\i386\dosx.exe + 2008-04-14 02:20:25 26,112 ------w c:\windows\ServicePackFiles\i386\dot3api.dll + 2008-04-14 02:20:25 59,392 ------w c:\windows\ServicePackFiles\i386\dot3cfg.dll + 2008-04-14 02:20:25 39,936 ------w c:\windows\ServicePackFiles\i386\dot3clnt.dll + 2008-04-14 02:20:25 9,216 ------w c:\windows\ServicePackFiles\i386\dot3dlg.dll + 2008-04-14 02:20:25 56,832 ------w c:\windows\ServicePackFiles\i386\dot3msm.dll + 2008-04-14 02:20:25 133,120 ------w c:\windows\ServicePackFiles\i386\dot3svc.dll + 2008-04-14 02:20:25 651,264 ------w c:\windows\ServicePackFiles\i386\dot3ui.dll + 2008-04-13 18:39:46 206,976 ------w c:\windows\ServicePackFiles\i386\dot4.sys + 2008-04-14 02:20:25 102,912 ------w c:\windows\ServicePackFiles\i386\dpcdll.dll + 2008-04-14 02:20:56 29,696 ------w c:\windows\ServicePackFiles\i386\dplaysvr.exe + 2008-04-14 02:20:25 229,888 ------w c:\windows\ServicePackFiles\i386\dplayx.dll + 2008-04-14 02:20:25 24,064 ------w c:\windows\ServicePackFiles\i386\dpmodemx.dll + 2008-04-14 02:18:18 3,072 ------w c:\windows\ServicePackFiles\i386\dpnaddr.dll + 2008-04-14 02:20:26 375,296 ------w c:\windows\ServicePackFiles\i386\dpnet.dll + 2008-04-14 02:20:26 35,328 ------w c:\windows\ServicePackFiles\i386\dpnhpast.dll + 2008-04-14 02:20:26 60,928 ------w c:\windows\ServicePackFiles\i386\dpnhupnp.dll + 2008-04-14 02:18:18 3,072 ------w c:\windows\ServicePackFiles\i386\dpnlobby.dll + 2008-04-14 02:20:56 17,920 ------w c:\windows\ServicePackFiles\i386\dpnsvr.exe + 2008-04-14 02:20:26 21,504 ------w c:\windows\ServicePackFiles\i386\dpvacm.dll + 2008-04-14 02:20:26 212,992 ------w c:\windows\ServicePackFiles\i386\dpvoice.dll + 2008-04-14 02:20:56 83,456 ------w c:\windows\ServicePackFiles\i386\dpvsetup.exe + 2008-04-14 02:20:26 116,736 ------w c:\windows\ServicePackFiles\i386\dpvvox.dll + 2008-04-14 02:20:26 57,856 ------w c:\windows\ServicePackFiles\i386\dpwsockx.dll + 2008-04-13 18:45:14 60,160 ------w c:\windows\ServicePackFiles\i386\drmk.sys + 2008-04-13 18:45:13 2,944 ------w c:\windows\ServicePackFiles\i386\drmkaud.sys + 2008-04-14 02:20:26 14,336 ------w c:\windows\ServicePackFiles\i386\drprov.dll + 2008-04-14 02:20:56 64,512 ------w c:\windows\ServicePackFiles\i386\drvqry.exe + 2004-07-17 14:36:44 4,656 ------w c:\windows\ServicePackFiles\i386\ds16gt.dll + 2008-04-14 02:20:26 16,384 ------w c:\windows\ServicePackFiles\i386\ds32gt.dll + 2008-04-14 02:20:26 181,248 ------w c:\windows\ServicePackFiles\i386\dsdmo.dll + 2008-04-14 02:20:26 71,680 ------w c:\windows\ServicePackFiles\i386\dsdmoprp.dll + 2008-04-14 02:20:26 93,184 ------w c:\windows\ServicePackFiles\i386\dskquota.dll + 2008-04-14 02:20:26 158,208 ------w c:\windows\ServicePackFiles\i386\dskquoui.dll + 2008-04-14 02:20:26 367,616 ------w c:\windows\ServicePackFiles\i386\dsound.dll + 2008-04-14 02:20:26 1,293,824 ------w c:\windows\ServicePackFiles\i386\dsound3d.dll + 2008-04-14 02:20:26 144,384 ------w c:\windows\ServicePackFiles\i386\dsprop.dll + 2008-04-14 02:00:13 4,096 ------w c:\windows\ServicePackFiles\i386\dsprpres.dll + 2008-04-14 02:20:26 240,128 ------w c:\windows\ServicePackFiles\i386\dsquery.dll + 2008-04-14 02:20:26 51,712 ------w c:\windows\ServicePackFiles\i386\dssec.dll + 2008-04-13 17:37:57 138,752 ------w c:\windows\ServicePackFiles\i386\dssenh.dll + 2008-04-14 02:20:26 113,664 ------w c:\windows\ServicePackFiles\i386\dsuiext.dll + 2008-04-14 02:20:26 19,456 ------w c:\windows\ServicePackFiles\i386\dswave.dll + 2008-04-14 02:20:56 10,752 ------w c:\windows\ServicePackFiles\i386\dumprep.exe + 2008-04-14 02:20:26 304,128 ------w c:\windows\ServicePackFiles\i386\duser.dll + 2008-04-14 02:20:56 17,920 ------w c:\windows\ServicePackFiles\i386\dvdupgrd.exe + 2004-07-17 14:39:20 56,032 ------w c:\windows\ServicePackFiles\i386\dwil1046.dll + 2008-04-14 02:20:56 180,224 ------w c:\windows\ServicePackFiles\i386\dwwin.exe + 2008-04-14 02:20:26 619,008 ------w c:\windows\ServicePackFiles\i386\dx7vb.dll + 2008-04-14 02:20:26 1,227,264 ------w c:\windows\ServicePackFiles\i386\dx8vb.dll + 2008-04-14 02:20:56 1,298,432 ------w c:\windows\ServicePackFiles\i386\dxdiag.exe + 2008-04-14 02:20:26 2,113,536 ------w c:\windows\ServicePackFiles\i386\dxdiagn.dll + 2008-04-13 18:38:29 71,168 ------w c:\windows\ServicePackFiles\i386\dxg.sys + 2008-04-14 02:20:26 357,888 ------w c:\windows\ServicePackFiles\i386\dxtmsft.dll + 2008-04-14 02:20:26 205,312 ------w c:\windows\ServicePackFiles\i386\dxtrans.dll + 2008-04-14 02:20:26 30,720 ------w c:\windows\ServicePackFiles\i386\eapolqec.dll + 2008-04-14 02:20:26 184,832 ------w c:\windows\ServicePackFiles\i386\eapp3hst.dll + 2008-04-14 02:20:26 126,976 ------w c:\windows\ServicePackFiles\i386\eappcfg.dll + 2008-04-14 02:20:26 94,720 ------w c:\windows\ServicePackFiles\i386\eappgnui.dll + 2008-04-14 02:20:26 180,224 ------w c:\windows\ServicePackFiles\i386\eapphost.dll + 2008-04-14 02:20:26 40,960 ------w c:\windows\ServicePackFiles\i386\eappprxy.dll + 2008-04-14 02:20:26 59,392 ------w c:\windows\ServicePackFiles\i386\eapqec.dll + 2008-04-14 02:20:26 33,792 ------w c:\windows\ServicePackFiles\i386\eapsvc.dll + 2008-04-14 02:20:26 27,136 ------w c:\windows\ServicePackFiles\i386\efsadu.dll + 2008-04-14 02:20:26 185,344 ------w c:\windows\ServicePackFiles\i386\els.dll + 2008-04-14 02:20:26 20,480 ------w c:\windows\ServicePackFiles\i386\encapi.dll + 2008-04-14 02:20:26 186,880 ------w c:\windows\ServicePackFiles\i386\encdec.dll + 2008-04-14 01:51:50 40,960 ------w c:\windows\ServicePackFiles\i386\ep9res.dll + 2004-08-04 02:35:16 121,344 ------w c:\windows\ServicePackFiles\i386\epcl5res.dll + 2008-04-14 02:20:26 23,040 ------w c:\windows\ServicePackFiles\i386\ersvc.dll + 2008-04-14 02:20:26 246,272 ------w c:\windows\ServicePackFiles\i386\es.dll + 2008-04-14 02:20:26 1,092,096 ------w c:\windows\ServicePackFiles\i386\esent.dll + 2008-04-14 02:20:26 247,808 ------w c:\windows\ServicePackFiles\i386\esscli.dll + 2004-08-04 00:32:28 137,088 ------w c:\windows\ServicePackFiles\i386\essm2e.sys + 2008-04-14 02:20:57 194,560 ------w c:\windows\ServicePackFiles\i386\eudcedit.exe + 2008-04-14 02:20:57 52,224 ------w c:\windows\ServicePackFiles\i386\evcreate.exe + 2008-04-14 02:20:26 56,320 ------w c:\windows\ServicePackFiles\i386\eventlog.dll + 2007-06-27 12:54:17 798,720 ------w c:\windows\ServicePackFiles\i386\eventlogmessages.dll + 2008-04-14 02:20:26 106,496 ------w c:\windows\ServicePackFiles\i386\evntagnt.dll + 2008-04-14 02:20:58 24,576 ------w c:\windows\ServicePackFiles\i386\evntcmd.exe + 2008-04-14 02:20:26 21,504 ------w c:\windows\ServicePackFiles\i386\evntrprv.dll + 2008-04-14 02:20:58 93,696 ------w c:\windows\ServicePackFiles\i386\evntwin.exe + 2008-04-14 02:20:26 45,056 ------w c:\windows\ServicePackFiles\i386\evtgprov.dll + 2008-04-14 02:20:58 84,992 ------w c:\windows\ServicePackFiles\i386\evtrig.exe + 2008-04-14 02:20:58 1,035,776 ------w c:\windows\ServicePackFiles\i386\explorer.exe + 2008-04-14 02:20:26 380,445 ------w c:\windows\ServicePackFiles\i386\expsrv.dll + 2008-04-14 02:20:26 14,336 ------w c:\windows\ServicePackFiles\i386\exstrace.dll + 2008-04-14 02:20:26 55,808 ------w c:\windows\ServicePackFiles\i386\extmgr.dll + 2008-04-14 02:20:58 24,064 ------w c:\windows\ServicePackFiles\i386\extrac32.exe + 2008-04-14 02:20:26 125,952 ------w c:\windows\ServicePackFiles\i386\exts.dll + 2008-04-14 02:18:25 7,168 ------w c:\windows\ServicePackFiles\i386\f3ahvoas.dll + 2008-04-13 19:14:29 143,744 ------w c:\windows\ServicePackFiles\i386\fastfat.sys + 2008-04-14 02:20:26 472,064 ------w c:\windows\ServicePackFiles\i386\fastprox.dll + 2008-04-14 02:20:26 80,896 ------w c:\windows\ServicePackFiles\i386\faultrep.dll + 2008-04-14 02:20:58 20,992 ------w c:\windows\ServicePackFiles\i386\faxpatch.exe + 2008-04-13 18:40:25 27,392 ------w c:\windows\ServicePackFiles\i386\fdc.sys + 2008-04-14 02:20:26 125,952 ------w c:\windows\ServicePackFiles\i386\fde.dll + 2008-04-14 02:20:26 75,264 ------w c:\windows\ServicePackFiles\i386\fdeploy.dll + 2008-04-14 02:20:26 21,504 ------w c:\windows\ServicePackFiles\i386\feclient.dll + 2008-04-14 02:20:26 342,528 ------w c:\windows\ServicePackFiles\i386\filemgmt.dll + 2008-04-14 02:20:58 28,672 ------w c:\windows\ServicePackFiles\i386\findstr.exe + 2008-04-14 01:52:42 44,672 ------w c:\windows\ServicePackFiles\i386\fips.sys + 2008-04-14 02:20:26 88,576 ------w c:\windows\ServicePackFiles\i386\fldrclnr.dll + 2008-04-13 18:40:25 20,480 ------w c:\windows\ServicePackFiles\i386\flpydisk.sys + 2008-04-14 02:20:26 16,896 ------w c:\windows\ServicePackFiles\i386\fltlib.dll + 2008-04-14 02:20:58 23,040 ------w c:\windows\ServicePackFiles\i386\fltmc.exe + 2008-04-13 18:32:59 129,792 ------w c:\windows\ServicePackFiles\i386\fltmgr.sys + 2008-04-14 02:20:26 384,512 ------w c:\windows\ServicePackFiles\i386\fontext.dll + 2008-04-14 02:20:26 80,896 ------w c:\windows\ServicePackFiles\i386\fontsub.dll + 2008-04-14 02:20:58 21,504 ------w c:\windows\ServicePackFiles\i386\fontview.exe + 2008-04-14 02:20:58 7,680 ------w c:\windows\ServicePackFiles\i386\forcedos.exe + 2004-08-04 00:31:24 34,173 ------w c:\windows\ServicePackFiles\i386\forehe.sys + 2008-04-14 02:21:25 29,696 ------w c:\windows\ServicePackFiles\i386\format.com + 2008-04-14 02:20:26 32,828 ------w c:\windows\ServicePackFiles\i386\fp40ext.dll + 2008-04-14 02:20:26 184,435 ------w c:\windows\ServicePackFiles\i386\fp4amsft.dll + 2008-04-14 02:20:26 82,035 ------w c:\windows\ServicePackFiles\i386\fp4anscp.dll + 2008-04-14 02:20:26 147,513 ------w c:\windows\ServicePackFiles\i386\fp4apws.dll + 2008-04-14 02:20:26 49,210 ------w c:\windows\ServicePackFiles\i386\fp4areg.dll + 2008-04-14 02:20:26 102,509 ------w c:\windows\ServicePackFiles\i386\fp4atxt.dll + 2008-04-14 02:20:26 618,605 ------w c:\windows\ServicePackFiles\i386\fp4autl.dll + 2008-04-14 02:20:26 41,020 ------w c:\windows\ServicePackFiles\i386\fp4avnb.dll + 2008-04-14 02:20:26 32,826 ------w c:\windows\ServicePackFiles\i386\fp4avss.dll + 2008-04-14 02:20:26 49,212 ------w c:\windows\ServicePackFiles\i386\fp4awebs.dll + 2008-04-14 02:20:26 876,653 ------w c:\windows\ServicePackFiles\i386\fp4awel.dll + 2008-04-14 02:20:58 15,120 ------w c:\windows\ServicePackFiles\i386\fp98sadm.exe + 2008-04-14 02:20:58 109,840 ------w c:\windows\ServicePackFiles\i386\fp98swin.exe + 2008-04-14 02:20:58 24,632 ------w c:\windows\ServicePackFiles\i386\fpadmcgi.exe + 2008-04-14 02:20:26 20,541 ------w c:\windows\ServicePackFiles\i386\fpadmdll.dll + 2008-04-14 02:20:59 188,494 ------w c:\windows\ServicePackFiles\i386\fpcount.exe + 2008-04-14 02:20:26 94,208 ------w c:\windows\ServicePackFiles\i386\fpencode.dll + 2008-04-14 02:20:26 20,541 ------w c:\windows\ServicePackFiles\i386\fpexedll.dll + 2008-04-14 02:20:26 598,071 ------w c:\windows\ServicePackFiles\i386\fpmmc.dll + 2003-04-14 23:54:06 217,088 ------w c:\windows\ServicePackFiles\i386\fpmmcsat.dll + 2008-04-14 02:20:59 20,538 ------w c:\windows\ServicePackFiles\i386\fpremadm.exe + 2008-04-14 02:20:59 28,728 ------w c:\windows\ServicePackFiles\i386\fpsrvadm.exe + 2008-04-14 02:18:27 9,344 ------w c:\windows\ServicePackFiles\i386\framebuf.dll + 2008-04-14 02:20:26 185,344 ------w c:\windows\ServicePackFiles\i386\framedyn.dll + 2008-04-14 02:20:59 193,024 ------w c:\windows\ServicePackFiles\i386\fsquirt.exe + 2008-04-14 02:20:59 45,056 ------w c:\windows\ServicePackFiles\i386\ftp.exe + 2008-04-14 02:20:26 6,144 ------w c:\windows\ServicePackFiles\i386\ftpmib.dll + 2008-04-14 02:20:26 127,488 ------w c:\windows\ServicePackFiles\i386\ftpsv251.dll + 2007-06-27 12:54:17 233,472 ------w c:\windows\ServicePackFiles\i386\fusion.dll + 2008-04-14 02:20:27 60,416 ------w c:\windows\ServicePackFiles\i386\fwcfg.dll + 2008-04-14 02:20:27 451,584 ------w c:\windows\ServicePackFiles\i386\fxsapi.dll + 2008-04-14 02:20:59 142,848 ------w c:\windows\ServicePackFiles\i386\fxsclnt.exe + 2008-04-14 02:20:27 72,192 ------w c:\windows\ServicePackFiles\i386\fxscom.dll + 2008-04-14 02:20:27 285,184 ------w c:\windows\ServicePackFiles\i386\fxscomex.dll + 2008-04-14 02:20:59 234,496 ------w c:\windows\ServicePackFiles\i386\fxscover.exe + 2008-04-14 02:20:27 26,624 ------w c:\windows\ServicePackFiles\i386\fxsdrv.dll + 2008-04-14 02:20:27 60,416 ------w c:\windows\ServicePackFiles\i386\fxsevent.dll + 2008-04-14 02:20:27 23,552 ------w c:\windows\ServicePackFiles\i386\fxsext32.dll + 2008-04-14 02:20:27 23,552 ------w c:\windows\ServicePackFiles\i386\fxsmon.dll + 2008-04-14 02:20:27 132,608 ------w c:\windows\ServicePackFiles\i386\fxsocm.dll + 2008-04-14 02:20:27 8,704 ------w c:\windows\ServicePackFiles\i386\fxsperf.dll + 2008-04-14 02:18:28 6,656 ------w c:\windows\ServicePackFiles\i386\fxsres.dll + 2008-04-14 02:20:27 562,688 ------w c:\windows\ServicePackFiles\i386\fxsst.dll + 2008-04-14 02:21:00 268,288 ------w c:\windows\ServicePackFiles\i386\fxssvc.exe + 2008-04-14 02:20:27 246,272 ------w c:\windows\ServicePackFiles\i386\fxst30.dll + 2008-04-14 02:20:27 397,312 ------w c:\windows\ServicePackFiles\i386\fxstiff.dll + 2008-04-14 02:20:27 155,136 ------w c:\windows\ServicePackFiles\i386\fxsui.dll + 2008-04-14 02:20:27 195,072 ------w c:\windows\ServicePackFiles\i386\fxswzrd.dll + 2008-04-14 02:20:27 400,896 ------w c:\windows\ServicePackFiles\i386\fxsxp32.dll + 2008-04-13 18:36:40 46,464 ------w c:\windows\ServicePackFiles\i386\gagp30kx.sys + 2008-04-13 18:45:29 10,624 ------w c:\windows\ServicePackFiles\i386\gameenum.sys + 2008-04-13 18:45:32 59,136 ------w c:\windows\ServicePackFiles\i386\gckernel.sys + 2008-04-14 02:20:27 285,184 ------w c:\windows\ServicePackFiles\i386\gdi32.dll + 2008-04-14 02:21:00 61,440 ------w c:\windows\ServicePackFiles\i386\getmac.exe + 2008-04-14 02:20:27 123,904 ------w c:\windows\ServicePackFiles\i386\glu32.dll + 2008-04-14 02:18:30 572,928 ------w c:\windows\ServicePackFiles\i386\gpedit.dll + 2004-08-04 01:31:44 101,888 ------w c:\windows\ServicePackFiles\i386\gpkcsp.dll + 2008-04-14 01:54:04 10,240 ------w c:\windows\ServicePackFiles\i386\gpkrsrc.dll + 2008-04-14 02:21:00 123,392 ------w c:\windows\ServicePackFiles\i386\gprslt.exe + 2008-04-14 02:20:27 201,216 ------w c:\windows\ServicePackFiles\i386\gptext.dll + 2008-04-14 02:21:00 39,424 ------w c:\windows\ServicePackFiles\i386\grpconv.exe + 2008-04-14 01:54:08 28,544 ------w c:\windows\ServicePackFiles\i386\grserial.sys + 2008-04-14 02:20:27 134,144 ------w c:\windows\ServicePackFiles\i386\guitrn.dll + 2008-04-14 02:20:27 115,200 ------w c:\windows\ServicePackFiles\i386\guitrna.dll + 2008-04-14 02:20:27 32,256 ------w c:\windows\ServicePackFiles\i386\gzip.dll + 2008-04-14 02:20:27 57,344 ------w c:\windows\ServicePackFiles\i386\h323cc.dll + 2008-04-14 02:20:27 614,912 ------w c:\windows\ServicePackFiles\i386\h323msp.dll + 2008-04-13 18:31:32 105,344 ------w c:\windows\ServicePackFiles\i386\hal.dll + 2008-04-13 18:31:28 131,840 ------w c:\windows\ServicePackFiles\i386\halaacpi.dll + 2008-04-13 18:31:27 81,152 ------w c:\windows\ServicePackFiles\i386\halacpi.dll + 2008-04-13 18:31:28 150,528 ------w c:\windows\ServicePackFiles\i386\halapic.dll + 2008-04-13 18:31:28 134,400 ------w c:\windows\ServicePackFiles\i386\halmacpi.dll + 2008-04-13 18:31:32 152,576 ------w c:\windows\ServicePackFiles\i386\halmps.dll + 2008-04-13 18:31:31 77,696 ------w c:\windows\ServicePackFiles\i386\halsp.dll + 2008-04-14 02:20:27 7,168 ------w c:\windows\ServicePackFiles\i386\hccoin.dll + 2008-04-13 16:36:05 144,384 ------w c:\windows\ServicePackFiles\i386\hdaudbus.sys + 2008-04-14 02:21:00 16,384 ------w c:\windows\ServicePackFiles\i386\help.exe + 2008-04-14 02:21:00 769,024 ------w c:\windows\ServicePackFiles\i386\helpctr.exe + 2008-04-14 02:21:00 744,448 ------w c:\windows\ServicePackFiles\i386\helpsvc.exe + 2008-04-14 02:21:00 10,752 ------w c:\windows\ServicePackFiles\i386\hh.exe + 2008-04-14 02:20:27 41,472 ------w c:\windows\ServicePackFiles\i386\hhsetup.dll + 2008-04-14 02:20:27 20,992 ------w c:\windows\ServicePackFiles\i386\hid.dll + 2008-04-13 18:36:38 20,352 ------w c:\windows\ServicePackFiles\i386\hidbatt.sys + 2008-04-14 01:54:34 25,728 ------w c:\windows\ServicePackFiles\i386\hidbth.sys + 2008-04-13 18:45:26 36,864 ------w c:\windows\ServicePackFiles\i386\hidclass.sys + 2008-04-13 18:45:26 19,200 ------w c:\windows\ServicePackFiles\i386\hidir.sys + 2008-04-13 18:45:22 24,960 ------w c:\windows\ServicePackFiles\i386\hidparse.sys + 2008-04-14 02:20:28 21,504 ------w c:\windows\ServicePackFiles\i386\hidserv.dll + 2008-04-13 18:45:27 10,368 ------w c:\windows\ServicePackFiles\i386\hidusb.sys + 2008-04-14 02:20:28 72,704 ------w c:\windows\ServicePackFiles\i386\hlink.dll + 2008-04-14 02:20:28 38,912 ------w c:\windows\ServicePackFiles\i386\hmmapi.dll + 2008-04-14 02:20:28 346,624 ------w c:\windows\ServicePackFiles\i386\hnetcfg.dll + 2008-04-14 02:20:28 334,848 ------w c:\windows\ServicePackFiles\i386\hnetwiz.dll + 2008-04-14 02:20:28 39,936 ------w c:\windows\ServicePackFiles\i386\hostmib.dll + 2008-04-14 02:20:28 146,432 ------w c:\windows\ServicePackFiles\i386\hotplug.dll + 2008-04-14 02:20:28 10,752 ------w c:\windows\ServicePackFiles\i386\hpcjrr.dll + 2008-04-14 02:20:28 10,240 ------w c:\windows\ServicePackFiles\i386\hpcjrrps.dll + 2008-04-14 02:20:28 87,552 ------w c:\windows\ServicePackFiles\i386\hpfud50.dll + 2008-04-14 02:21:00 18,432 ------w c:\windows\ServicePackFiles\i386\hscupd.exe + 2004-08-04 00:41:48 220,032 ------w c:\windows\ServicePackFiles\i386\hsfbs2s2.sys + 2008-04-14 02:20:28 32,285 ------w c:\windows\ServicePackFiles\i386\hsfcisp2.dll + 2004-08-04 00:41:50 685,056 ------w c:\windows\ServicePackFiles\i386\hsfcxts2.sys + 2004-08-04 00:41:56 1,041,536 ------w c:\windows\ServicePackFiles\i386\hsfdpsp2.sys + 2008-04-13 18:53:53 264,832 ------w c:\windows\ServicePackFiles\i386\http.sys + 2008-04-14 02:20:28 24,576 ------w c:\windows\ServicePackFiles\i386\httpapi.dll + 2008-04-14 02:20:28 268,288 ------w c:\windows\ServicePackFiles\i386\httpext.dll + 2008-04-14 02:20:28 8,192 ------w c:\windows\ServicePackFiles\i386\httpmb51.dll + 2008-04-14 02:20:28 61,952 ------w c:\windows\ServicePackFiles\i386\httpod51.dll + 2008-04-14 02:20:28 42,496 ------w c:\windows\ServicePackFiles\i386\htui.dll + 2008-04-14 02:20:28 352,768 ------w c:\windows\ServicePackFiles\i386\hypertrm.dll + 2008-04-13 18:41:22 8,576 ------w c:\windows\ServicePackFiles\i386\i2omgmt.sys + 2008-04-13 18:41:22 18,560 ------w c:\windows\ServicePackFiles\i386\i2omp.sys + 2008-04-14 01:55:19 53,504 ------w c:\windows\ServicePackFiles\i386\i8042prt.sys + 2008-04-14 02:20:28 702,845 ------w c:\windows\ServicePackFiles\i386\i81xdnt5.dll + 2004-08-04 00:29:38 161,020 ------w c:\windows\ServicePackFiles\i386\i81xnt5.sys + 2008-04-14 02:20:28 119,808 ------w c:\windows\ServicePackFiles\i386\iasrad.dll + 2008-04-14 02:20:28 11,264 ------w c:\windows\ServicePackFiles\i386\icaapi.dll + 2008-04-14 02:20:28 80,384 ------w c:\windows\ServicePackFiles\i386\iccvid.dll + 2008-04-14 02:20:28 254,976 ------w c:\windows\ServicePackFiles\i386\icm32.dll + 2008-04-14 02:18:33 3,584 ------w c:\windows\ServicePackFiles\i386\icmp.dll + 2008-04-13 16:44:29 2,560 ------w c:\windows\ServicePackFiles\i386\iconlib.dll + 2008-04-14 02:20:28 61,440 ------w c:\windows\ServicePackFiles\i386\icwconn.dll + 2008-04-14 02:21:01 217,600 ------w c:\windows\ServicePackFiles\i386\icwconn1.exe + 2008-04-14 02:21:01 86,016 ------w c:\windows\ServicePackFiles\i386\icwconn2.exe + 2008-04-14 02:20:28 73,728 ------w c:\windows\ServicePackFiles\i386\icwdial.dll + 2008-04-14 02:20:28 32,768 ------w c:\windows\ServicePackFiles\i386\icwdl.dll + 2008-04-14 02:20:28 176,128 ------w c:\windows\ServicePackFiles\i386\icwhelp.dll + 2008-04-14 02:20:28 65,536 ------w c:\windows\ServicePackFiles\i386\icwphbk.dll + 2008-04-14 02:21:01 24,576 ------w c:\windows\ServicePackFiles\i386\icwrmind.exe + 2008-04-14 02:20:28 49,152 ------w c:\windows\ServicePackFiles\i386\icwutil.dll + 2008-04-14 02:20:28 121,344 ------w c:\windows\ServicePackFiles\i386\idq.dll + 2008-04-14 02:21:01 34,304 ------w c:\windows\ServicePackFiles\i386\ie4uinit.exe + 2008-04-14 02:20:28 143,360 ------w c:\windows\ServicePackFiles\i386\ieakeng.dll + 2008-04-14 02:20:28 220,160 ------w c:\windows\ServicePackFiles\i386\ieaksie.dll + 2008-04-14 02:20:28 323,584 ------w c:\windows\ServicePackFiles\i386\iedkcs32.dll + 2008-04-14 02:21:01 18,432 ------w c:\windows\ServicePackFiles\i386\iedw.exe + 2008-04-14 02:20:28 81,920 ------w c:\windows\ServicePackFiles\i386\ieencode.dll + 2007-12-17 11:58:35 8,192 ------w c:\windows\ServicePackFiles\i386\ieexec.exe + 2007-06-27 12:54:23 7,168 ------w c:\windows\ServicePackFiles\i386\ieexecremote.dll + 2007-06-27 12:54:23 32,768 ------w c:\windows\ServicePackFiles\i386\iehost.dll + 2008-04-14 02:20:28 251,904 ------w c:\windows\ServicePackFiles\i386\iepeers.dll + 2008-04-14 02:20:28 48,640 ------w c:\windows\ServicePackFiles\i386\iernonce.dll + 2008-04-14 02:20:28 63,488 ------w c:\windows\ServicePackFiles\i386\iesetup.dll + 2008-04-14 02:21:01 93,184 ------w c:\windows\ServicePackFiles\i386\iexplore.exe + 2008-04-14 02:21:02 114,688 ------w c:\windows\ServicePackFiles\i386\iexpress.exe + 2008-04-14 02:20:28 137,728 ------w c:\windows\ServicePackFiles\i386\ifmon.dll + 2008-04-14 02:20:28 8,192 ------w c:\windows\ServicePackFiles\i386\igmpagnt.dll + 2008-04-14 02:20:28 507,392 ------w c:\windows\ServicePackFiles\i386\iis.dll + 2008-04-14 02:20:28 25,088 ------w c:\windows\ServicePackFiles\i386\iisadmin.dll + 2008-04-14 02:20:28 145,408 ------w c:\windows\ServicePackFiles\i386\iische51.dll Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 continuando 1: + 2008-04-14 02:20:28 68,608 ------w c:\windows\ServicePackFiles\i386\iisext51.dll + 2008-04-14 02:20:28 7,168 ------w c:\windows\ServicePackFiles\i386\iisfecnv.dll + 2008-04-14 02:20:28 79,872 ------w c:\windows\ServicePackFiles\i386\iislog51.dll + 2008-04-14 02:20:28 64,512 ------w c:\windows\ServicePackFiles\i386\iismap.dll + 2008-04-14 02:21:02 31,232 ------w c:\windows\ServicePackFiles\i386\iisrstas.exe + 2008-04-14 02:20:28 133,632 ------w c:\windows\ServicePackFiles\i386\iisrtl.dll + 2008-04-13 16:10:32 184,320 ------w c:\windows\ServicePackFiles\i386\ilasm.exe + 2008-04-14 02:20:28 81,920 ------w c:\windows\ServicePackFiles\i386\ils.dll + 2008-04-14 02:20:28 144,384 ------w c:\windows\ServicePackFiles\i386\imagehlp.dll + 2008-04-14 02:21:02 150,528 ------w c:\windows\ServicePackFiles\i386\imapi.exe + 2008-04-13 18:40:58 42,112 ------w c:\windows\ServicePackFiles\i386\imapi.sys + 2008-04-14 02:20:28 36,921 ------w c:\windows\ServicePackFiles\i386\imeshare.dll + 2008-04-14 02:20:28 35,840 ------w c:\windows\ServicePackFiles\i386\imgutil.dll + 2008-04-14 02:20:28 110,080 ------w c:\windows\ServicePackFiles\i386\imm32.dll + 2008-04-14 02:20:28 125,440 ------w c:\windows\ServicePackFiles\i386\imsinsnt.dll + 2008-04-14 02:20:28 278,528 ------w c:\windows\ServicePackFiles\i386\inetcfg.dll + 2008-04-14 02:20:28 691,712 ------w c:\windows\ServicePackFiles\i386\inetcomm.dll + 2008-04-14 02:21:02 15,872 ------w c:\windows\ServicePackFiles\i386\inetin51.exe + 2008-04-14 02:20:28 837,120 ------w c:\windows\ServicePackFiles\i386\inetmgr.dll + 2008-04-14 02:20:28 32,768 ------w c:\windows\ServicePackFiles\i386\inetmib1.dll + 2008-04-14 02:20:28 75,264 ------w c:\windows\ServicePackFiles\i386\inetpp.dll + 2008-04-14 02:20:28 15,872 ------w c:\windows\ServicePackFiles\i386\inetppui.dll + 2008-04-14 01:56:50 49,664 ------w c:\windows\ServicePackFiles\i386\inetres.dll + 2008-04-14 02:21:02 20,480 ------w c:\windows\ServicePackFiles\i386\inetwiz.exe + 2008-04-14 02:20:28 13,312 ------w c:\windows\ServicePackFiles\i386\infoadmn.dll + 2008-04-14 02:20:28 257,024 ------w c:\windows\ServicePackFiles\i386\infocomm.dll + 2008-04-14 02:20:28 147,456 ------w c:\windows\ServicePackFiles\i386\initpki.dll + 2008-04-14 02:20:28 125,440 ------w c:\windows\ServicePackFiles\i386\input.dll + 2008-04-14 02:20:28 96,768 ------w c:\windows\ServicePackFiles\i386\inseng.dll + 2007-06-27 12:54:28 24,576 ------w c:\windows\ServicePackFiles\i386\installutil.exe + 2008-04-14 01:57:12 5,632 ------w c:\windows\ServicePackFiles\i386\intelide.sys + 2008-04-14 01:57:13 40,448 ------w c:\windows\ServicePackFiles\i386\intelppm.sys + 2008-04-13 18:53:34 36,608 ------w c:\windows\ServicePackFiles\i386\ip6fw.sys + 2008-04-14 02:21:02 56,832 ------w c:\windows\ServicePackFiles\i386\ipconfig.exe + 2008-04-14 02:18:25 103,424 ------w c:\windows\ServicePackFiles\i386\ipevldpc.dll + 2008-04-14 02:18:21 24,064 ------w c:\windows\ServicePackFiles\i386\ipevlpid.dll + 2008-04-14 02:20:28 95,744 ------w c:\windows\ServicePackFiles\i386\iphlpapi.dll + 2008-04-13 18:57:07 20,864 ------w c:\windows\ServicePackFiles\i386\ipinip.sys + 2008-04-14 02:20:28 165,888 ------w c:\windows\ServicePackFiles\i386\ipmontr.dll + 2008-04-13 18:57:15 152,832 ------w c:\windows\ServicePackFiles\i386\ipnat.sys + 2008-04-14 02:20:28 331,264 ------w c:\windows\ServicePackFiles\i386\ipnathlp.dll + 2008-04-14 02:20:28 348,160 ------w c:\windows\ServicePackFiles\i386\ippromon.dll + 2008-04-14 02:20:28 35,840 ------w c:\windows\ServicePackFiles\i386\iprip.dll + 2008-04-14 02:20:28 177,152 ------w c:\windows\ServicePackFiles\i386\iprtrmgr.dll + 2008-04-13 19:19:42 75,264 ------w c:\windows\ServicePackFiles\i386\ipsec.sys + 2008-04-14 02:20:28 357,376 ------w c:\windows\ServicePackFiles\i386\ipsecsnp.dll + 2008-04-14 02:20:28 184,320 ------w c:\windows\ServicePackFiles\i386\ipsecsvc.dll + 2008-04-14 02:19:29 102,912 ------w c:\windows\ServicePackFiles\i386\ipseldpc.dll + 2008-04-14 02:18:21 24,064 ------w c:\windows\ServicePackFiles\i386\ipselpid.dll + 2008-04-14 02:20:28 386,560 ------w c:\windows\ServicePackFiles\i386\ipsmsnap.dll + 2008-04-14 02:21:02 53,760 ------w c:\windows\ServicePackFiles\i386\ipv6.exe + 2008-04-14 02:20:28 59,904 ------w c:\windows\ServicePackFiles\i386\ipv6mon.dll + 2008-04-14 02:21:02 24,064 ------w c:\windows\ServicePackFiles\i386\ipxroute.exe + 2008-04-14 02:20:28 22,016 ------w c:\windows\ServicePackFiles\i386\ipxwan.dll + 2008-04-14 02:20:28 120,320 ------w c:\windows\ServicePackFiles\i386\ir41_qc.dll + 2008-04-14 02:20:28 338,432 ------w c:\windows\ServicePackFiles\i386\ir41_qcx.dll + 2008-04-14 02:20:28 755,200 ------w c:\windows\ServicePackFiles\i386\ir50_32.dll + 2008-04-14 02:20:29 200,192 ------w c:\windows\ServicePackFiles\i386\ir50_qc.dll + 2008-04-14 02:20:29 183,808 ------w c:\windows\ServicePackFiles\i386\ir50_qcx.dll + 2008-04-13 18:45:34 46,592 ------w c:\windows\ServicePackFiles\i386\irbus.sys + 2008-04-13 18:54:36 88,192 ------w c:\windows\ServicePackFiles\i386\irda.sys + 2008-04-13 18:54:28 11,264 ------w c:\windows\ServicePackFiles\i386\irenum.sys + 2008-04-14 02:21:03 152,576 ------w c:\windows\ServicePackFiles\i386\irftp.exe + 2008-04-14 02:20:29 28,672 ------w c:\windows\ServicePackFiles\i386\irmon.dll + 2008-04-14 01:58:03 37,632 ------w c:\windows\ServicePackFiles\i386\isapnp.sys + 2008-04-14 02:20:29 68,608 ------w c:\windows\ServicePackFiles\i386\isatq.dll + 2008-04-14 02:20:29 27,136 ------w c:\windows\ServicePackFiles\i386\iscomlog.dll + 2008-04-14 02:19:19 105,984 ------w c:\windows\ServicePackFiles\i386\isdpc.dll + 2008-04-14 02:19:41 105,984 ------w c:\windows\ServicePackFiles\i386\isendpc.dll + 2008-04-14 02:19:41 24,064 ------w c:\windows\ServicePackFiles\i386\isenpid.dll + 2008-04-14 02:20:29 86,016 ------w c:\windows\ServicePackFiles\i386\isign32.dll + 2008-04-14 02:19:19 24,064 ------w c:\windows\ServicePackFiles\i386\ispid.dll + 2008-04-14 02:20:29 32,768 ------w c:\windows\ServicePackFiles\i386\isrdbg32.dll + 2008-04-14 02:20:29 155,136 ------w c:\windows\ServicePackFiles\i386\itircl.dll + 2008-04-14 02:20:29 138,240 ------w c:\windows\ServicePackFiles\i386\itss.dll + 2008-04-14 02:20:29 191,488 ------w c:\windows\ServicePackFiles\i386\iuengine.dll + 2008-04-14 02:20:29 54,784 ------w c:\windows\ServicePackFiles\i386\ixsso.dll + 2008-04-14 02:20:29 47,616 ------w c:\windows\ServicePackFiles\i386\iyuv_32.dll + 2008-04-14 02:20:29 163,840 ------w c:\windows\ServicePackFiles\i386\jgdw400.dll + 2008-04-14 02:20:29 27,648 ------w c:\windows\ServicePackFiles\i386\jgpl400.dll + 2007-06-27 12:54:35 40,960 ------w c:\windows\ServicePackFiles\i386\jsc.exe + 2008-04-14 02:20:29 512,000 ------w c:\windows\ServicePackFiles\i386\jscript.dll + 2008-04-14 02:20:29 15,872 ------w c:\windows\ServicePackFiles\i386\jsproxy.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbd101.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbd106.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbd106n.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdax2.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdbhc.dll + 2008-04-14 01:58:35 25,088 ------w c:\windows\ServicePackFiles\i386\kbdclass.sys + 2008-04-14 02:18:43 7,168 ------w c:\windows\ServicePackFiles\i386\kbdfi1.dll + 2008-04-14 01:58:36 14,720 ------w c:\windows\ServicePackFiles\i386\kbdhid.sys + 2008-04-14 02:18:43 7,168 ------w c:\windows\ServicePackFiles\i386\kbdibm02.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdinbe1.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdinben.dll + 2008-04-14 02:18:43 6,656 ------w c:\windows\ServicePackFiles\i386\kbdinmal.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdiultn.dll + 2008-04-14 02:18:43 6,656 ------w c:\windows\ServicePackFiles\i386\kbdlk41a.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdlk41j.dll + 2008-04-14 02:18:43 5,632 ------w c:\windows\ServicePackFiles\i386\kbdmaori.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdmlt47.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdmlt48.dll + 2008-04-14 02:18:43 7,168 ------w c:\windows\ServicePackFiles\i386\kbdnec.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdnepr.dll + 2008-04-14 02:18:43 7,168 ------w c:\windows\ServicePackFiles\i386\kbdno1.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\ServicePackFiles\i386\kbdpash.dll + 2008-04-14 02:18:43 7,680 ------w c:\windows\ServicePackFiles\i386\kbdsmsfi.dll + 2008-04-14 02:18:43 7,680 ------w c:\windows\ServicePackFiles\i386\kbdsmsno.dll + 2008-04-14 02:18:43 7,168 ------w c:\windows\ServicePackFiles\i386\kbdukx.dll + 2008-04-13 18:31:35 7,424 ------w c:\windows\ServicePackFiles\i386\kd1394.dll + 2008-04-14 02:20:29 185,856 ------w c:\windows\ServicePackFiles\i386\kdcsvc.dll + 2008-04-14 02:20:29 49,152 ------w c:\windows\ServicePackFiles\i386\kdsui.dll + 2008-04-14 02:20:29 254,464 ------w c:\windows\ServicePackFiles\i386\kdsusd.dll + 2008-04-14 02:20:29 299,520 ------w c:\windows\ServicePackFiles\i386\kerberos.dll + 2008-04-14 02:20:29 1,028,608 ------w c:\windows\ServicePackFiles\i386\kernel32.dll + 2004-08-04 01:46:56 42,537 ------w c:\windows\ServicePackFiles\i386\keyboard.sys + 2008-04-14 02:20:30 152,576 ------w c:\windows\ServicePackFiles\i386\keymgr.dll + 2008-04-13 18:45:09 172,416 ------w c:\windows\ServicePackFiles\i386\kmixer.sys + 2008-04-14 02:20:30 61,440 ------w c:\windows\ServicePackFiles\i386\kmsvc.dll + 2008-04-14 02:18:44 102,912 ------w c:\windows\ServicePackFiles\i386\knperdpc.dll + 2008-04-14 02:18:44 24,064 ------w c:\windows\ServicePackFiles\i386\knperpid.dll + 2008-04-14 02:18:45 102,912 ------w c:\windows\ServicePackFiles\i386\knprodpc.dll + 2008-04-14 02:18:45 24,576 ------w c:\windows\ServicePackFiles\i386\knpropid.dll + 2008-04-14 02:20:30 8,192 ------w c:\windows\ServicePackFiles\i386\koc.dll + 2008-04-14 02:18:44 102,912 ------w c:\windows\ServicePackFiles\i386\kperdpc.dll + 2008-04-14 02:18:44 24,064 ------w c:\windows\ServicePackFiles\i386\kperpid.dll + 2008-04-14 02:18:44 102,912 ------w c:\windows\ServicePackFiles\i386\kprodpc.dll + 2008-04-14 02:18:44 24,576 ------w c:\windows\ServicePackFiles\i386\kpropid.dll + 2004-08-04 01:49:46 92,544 ------w c:\windows\ServicePackFiles\i386\krnl386.exe + 2008-04-14 02:20:30 24,576 ------w c:\windows\ServicePackFiles\i386\krnlprov.dll + 2008-04-13 19:16:36 141,056 ------w c:\windows\ServicePackFiles\i386\ks.sys + 2008-04-13 18:31:43 92,288 ------w c:\windows\ServicePackFiles\i386\ksecdd.sys + 2008-04-14 02:20:30 4,096 ------w c:\windows\ServicePackFiles\i386\ksuser.dll + 2008-04-14 02:20:30 37,376 ------w c:\windows\ServicePackFiles\i386\l2store.dll + 2008-04-14 02:18:05 97,792 ------w c:\windows\ServicePackFiles\i386\lang\chtmbx.dll + 2008-04-14 02:18:05 56,320 ------w c:\windows\ServicePackFiles\i386\lang\chtskdic.dll + 2008-04-14 02:18:05 173,568 ------w c:\windows\ServicePackFiles\i386\lang\chtskf.dll + 2008-04-14 02:18:06 198,656 ------w c:\windows\ServicePackFiles\i386\lang\cintime.dll + 2004-08-04 01:31:56 480,256 ------w c:\windows\ServicePackFiles\i386\lang\cintsetp.exe + 2004-08-04 01:31:40 57,399 ------w c:\windows\ServicePackFiles\i386\lang\cplexe.exe + 2008-04-14 02:18:32 13,463,552 ------w c:\windows\ServicePackFiles\i386\lang\hwxjpn.dll + 2008-04-14 02:18:35 106,496 ------w c:\windows\ServicePackFiles\i386\lang\imekrcic.dll + 2008-04-14 02:18:35 86,016 ------w c:\windows\ServicePackFiles\i386\lang\imekrmbx.dll + 2008-04-14 02:18:35 811,064 ------w c:\windows\ServicePackFiles\i386\lang\imjp81k.dll + 2008-04-14 02:18:35 368,696 ------w c:\windows\ServicePackFiles\i386\lang\imjpcic.dll + 2008-04-14 02:18:35 716,856 ------w c:\windows\ServicePackFiles\i386\lang\imjpcus.dll + 2008-04-14 02:18:35 81,976 ------w c:\windows\ServicePackFiles\i386\lang\imjpdct.dll + 2004-08-04 01:31:54 307,257 ------w c:\windows\ServicePackFiles\i386\lang\imjpdct.exe + 2004-08-04 01:31:56 155,705 ------w c:\windows\ServicePackFiles\i386\lang\imjpdsvr.exe + 2004-08-04 01:31:58 196,665 ------w c:\windows\ServicePackFiles\i386\lang\imjpinst.exe + 2004-08-04 01:32:00 208,952 ------w c:\windows\ServicePackFiles\i386\lang\imjpmig.exe + 2004-08-04 01:32:12 233,527 ------w c:\windows\ServicePackFiles\i386\lang\imjprw.exe + 2004-08-04 01:32:16 262,200 ------w c:\windows\ServicePackFiles\i386\lang\imjputy.exe + 2008-04-14 02:18:36 274,489 ------w c:\windows\ServicePackFiles\i386\lang\imjputyc.dll + 2008-04-14 02:18:36 102,456 ------w c:\windows\ServicePackFiles\i386\lang\imlang.dll + 2004-08-04 01:31:50 59,392 ------w c:\windows\ServicePackFiles\i386\lang\imscinst.exe + 2008-04-14 02:18:36 315,455 ------w c:\windows\ServicePackFiles\i386\lang\imskf.dll + 2008-04-14 02:19:20 15,872 ------w c:\windows\ServicePackFiles\i386\lang\padrs404.dll + 2008-04-14 02:19:20 15,360 ------w c:\windows\ServicePackFiles\i386\lang\padrs804.dll + 2008-04-14 02:19:21 175,104 ------w c:\windows\ServicePackFiles\i386\lang\pintlcsa.dll + 2008-04-14 02:19:21 53,760 ------w c:\windows\ServicePackFiles\i386\lang\pintlcsd.dll + 2008-04-13 16:43:36 70,144 ------w c:\windows\ServicePackFiles\i386\lang\pintlphr.exe + 2008-04-14 02:19:21 67,584 ------w c:\windows\ServicePackFiles\i386\lang\pmigrate.dll + 2004-08-04 01:32:16 44,032 ------w c:\windows\ServicePackFiles\i386\lang\tintlphr.exe + 2004-08-04 01:32:16 455,168 ------w c:\windows\ServicePackFiles\i386\lang\tintsetp.exe + 2008-04-14 02:19:45 10,240 ------w c:\windows\ServicePackFiles\i386\lang\tmigrate.dll + 2008-04-14 02:19:46 76,288 ------w c:\windows\ServicePackFiles\i386\lang\uniime.dll + 2008-04-14 02:19:48 426,041 ------w c:\windows\ServicePackFiles\i386\lang\voicepad.dll + 2008-04-14 02:19:48 86,073 ------w c:\windows\ServicePackFiles\i386\lang\voicesub.dll + 2008-04-13 18:40:26 34,688 ------w c:\windows\ServicePackFiles\i386\lbrtfdc.sys + 2008-04-14 02:21:04 677,888 ------w c:\windows\ServicePackFiles\i386\lhmstsc.exe + 2008-04-14 02:20:30 2,061,824 ------w c:\windows\ServicePackFiles\i386\lhmstscx.dll + 2008-04-13 21:20:32 424,448 ------w c:\windows\ServicePackFiles\i386\licdll.dll + 2008-04-14 02:20:30 22,016 ------w c:\windows\ServicePackFiles\i386\licmgr10.dll + 2008-04-14 02:20:30 58,880 ------w c:\windows\ServicePackFiles\i386\licwmi.dll + 2008-04-14 02:20:30 19,968 ------w c:\windows\ServicePackFiles\i386\linkinfo.dll + 2008-04-14 02:20:30 13,824 ------w c:\windows\ServicePackFiles\i386\lmhsvc.dll + 2008-04-14 02:20:30 33,792 ------w c:\windows\ServicePackFiles\i386\lmmib2.dll + 2008-04-14 02:20:30 399,872 ------w c:\windows\ServicePackFiles\i386\lmrt.dll + 2008-04-14 02:20:30 100,352 ------w c:\windows\ServicePackFiles\i386\loadperf.dll + 2008-04-14 02:20:30 221,696 ------w c:\windows\ServicePackFiles\i386\localsec.dll + 2008-04-14 02:20:30 344,576 ------w c:\windows\ServicePackFiles\i386\localspl.dll + 2008-04-14 02:20:30 11,776 ------w c:\windows\ServicePackFiles\i386\localui.dll + 2008-04-14 02:21:04 75,264 ------w c:\windows\ServicePackFiles\i386\locator.exe + 2008-04-14 02:20:30 19,968 ------w c:\windows\ServicePackFiles\i386\log.dll + 2008-04-14 02:21:04 60,928 ------w c:\windows\ServicePackFiles\i386\logman.exe + 2008-04-14 02:21:25 220,672 ------w c:\windows\ServicePackFiles\i386\logon.scr + 2008-04-14 02:21:05 515,072 ------w c:\windows\ServicePackFiles\i386\logonui.exe + 2008-04-14 02:20:30 13,312 ------w c:\windows\ServicePackFiles\i386\lonsint.dll + 2008-04-14 02:20:30 23,040 ------w c:\windows\ServicePackFiles\i386\lpdsvc.dll + 2008-04-14 02:20:30 22,016 ------w c:\windows\ServicePackFiles\i386\lpk.dll + 2008-04-14 02:20:30 10,240 ------w c:\windows\ServicePackFiles\i386\lprhelp.dll + 2008-04-14 02:20:30 19,456 ------w c:\windows\ServicePackFiles\i386\lprmon.dll + 2008-04-14 02:20:30 730,624 ------w c:\windows\ServicePackFiles\i386\lsasrv.dll + 2008-04-14 02:21:05 13,312 ------w c:\windows\ServicePackFiles\i386\lsass.exe + 2004-08-04 03:40:02 607,196 ------w c:\windows\ServicePackFiles\i386\ltmdmnt.sys + 2004-08-04 02:40:04 422,016 ------w c:\windows\ServicePackFiles\i386\ltmdmntt.sys + 2008-04-13 18:40:52 7,040 ------w c:\windows\ServicePackFiles\i386\ltotape.sys + 2004-08-04 00:39:32 20,864 ------w c:\windows\ServicePackFiles\i386\lwadihid.sys + 2008-04-14 02:21:05 72,192 ------w c:\windows\ServicePackFiles\i386\magnify.exe + 2008-04-14 02:21:05 57,344 ------w c:\windows\ServicePackFiles\i386\makecab.exe + 2008-04-14 02:20:30 14,336 ------w c:\windows\ServicePackFiles\i386\mcastmib.dll + 2008-04-14 02:20:30 85,504 ------w c:\windows\ServicePackFiles\i386\mciavi32.dll + 2008-04-14 02:20:30 35,328 ------w c:\windows\ServicePackFiles\i386\mciqtz32.dll + 2008-04-14 02:20:30 23,040 ------w c:\windows\ServicePackFiles\i386\mciseq.dll + 2008-04-14 02:20:30 23,552 ------w c:\windows\ServicePackFiles\i386\mciwave.dll + 2008-04-14 02:20:30 37,888 ------w c:\windows\ServicePackFiles\i386\md5filt.dll + 2008-04-14 02:20:30 118,784 ------w c:\windows\ServicePackFiles\i386\mdminst.dll + 2008-04-14 02:20:30 86,016 ------w c:\windows\ServicePackFiles\i386\mdmxsdk.dll + 2004-08-04 00:41:56 11,868 ------w c:\windows\ServicePackFiles\i386\mdmxsdk.sys + 2008-04-14 02:20:30 16,896 ------w c:\windows\ServicePackFiles\i386\medctroc.dll + 2008-04-13 18:41:21 26,112 ------w c:\windows\ServicePackFiles\i386\memstpci.sys + 2008-04-14 02:20:30 86,016 ------w c:\windows\ServicePackFiles\i386\metada51.dll + 2008-04-13 18:36:41 63,744 ------w c:\windows\ServicePackFiles\i386\mf.sys + 2008-04-14 02:20:30 40,960 ------w c:\windows\ServicePackFiles\i386\mf3216.dll + 2008-04-14 02:20:31 927,504 ------w c:\windows\ServicePackFiles\i386\mfc40u.dll + 2008-04-14 02:20:31 1,028,096 ------w c:\windows\ServicePackFiles\i386\mfc42.dll + 2006-10-14 08:13:25 981,760 ------w c:\windows\ServicePackFiles\i386\mfc42u.dll + 2008-04-14 02:20:31 22,528 ------w c:\windows\ServicePackFiles\i386\mfcsubs.dll + 2008-04-14 02:20:31 14,848 ------w c:\windows\ServicePackFiles\i386\mgmtapi.dll + 2007-06-27 12:54:42 712,704 ------w c:\windows\ServicePackFiles\i386\microsoft.jscript.dll + 2007-06-27 12:54:48 286,720 ------w c:\windows\ServicePackFiles\i386\microsoft.visualbasic.dll + 2008-04-14 02:20:31 18,944 ------w c:\windows\ServicePackFiles\i386\midimap.dll + 2008-04-14 02:20:31 274,432 ------w c:\windows\ServicePackFiles\i386\migism.dll + 2008-04-14 02:20:31 261,120 ------w c:\windows\ServicePackFiles\i386\migisma.dll + 2008-04-14 02:20:31 60,928 ------w c:\windows\ServicePackFiles\i386\miglibnt.dll + 2008-04-14 02:21:05 104,448 ------w c:\windows\ServicePackFiles\i386\migload.exe + 2008-04-14 02:21:06 7,680 ------w c:\windows\ServicePackFiles\i386\migregdb.exe + 2008-04-14 02:21:06 250,368 ------w c:\windows\ServicePackFiles\i386\migwiz.exe + 2008-04-14 02:21:06 241,152 ------w c:\windows\ServicePackFiles\i386\migwiza.exe + 2008-04-14 02:20:31 29,696 ------w c:\windows\ServicePackFiles\i386\mimefilt.dll + 2008-04-14 02:20:31 586,240 ------w c:\windows\ServicePackFiles\i386\mlang.dll + 2008-04-14 02:21:06 1,415,168 ------w c:\windows\ServicePackFiles\i386\mmc.exe + 2008-04-14 02:20:31 184,320 ------w c:\windows\ServicePackFiles\i386\mmc30.dll + 2008-04-14 02:20:31 16,384 ------w c:\windows\ServicePackFiles\i386\mmc30r.dll + 2008-04-14 02:20:31 166,912 ------w c:\windows\ServicePackFiles\i386\mmcbase.dll + 2008-04-14 02:20:31 397,312 ------w c:\windows\ServicePackFiles\i386\mmcex.dll + 2008-04-14 02:20:31 36,864 ------w c:\windows\ServicePackFiles\i386\mmcexr.dll + 2008-04-14 02:20:32 106,496 ------w c:\windows\ServicePackFiles\i386\mmcfxc.dll + 2008-04-14 02:20:32 5,120 ------w c:\windows\ServicePackFiles\i386\mmcfxcr.dll + 2008-04-14 02:20:32 1,876,992 ------w c:\windows\ServicePackFiles\i386\mmcndmgr.dll + 2008-04-14 02:21:07 34,304 ------w c:\windows\ServicePackFiles\i386\mmcperf.exe + 2008-04-14 02:20:32 61,440 ------w c:\windows\ServicePackFiles\i386\mmcshext.dll + 2008-04-14 02:20:32 17,920 ------w c:\windows\ServicePackFiles\i386\mmfutil.dll + 2004-08-04 03:35:00 70,080 ------w c:\windows\ServicePackFiles\i386\mmsystem.dll + 2008-04-14 02:20:32 34,560 ------w c:\windows\ServicePackFiles\i386\mnmdd.dll + 2008-04-14 02:21:07 32,768 ------w c:\windows\ServicePackFiles\i386\mnmsrvc.exe + 2008-04-14 02:20:32 208,896 ------w c:\windows\ServicePackFiles\i386\mobsync.dll + 2008-04-14 02:21:07 143,872 ------w c:\windows\ServicePackFiles\i386\mobsync.exe + 2008-04-14 01:50:05 30,336 ------w c:\windows\ServicePackFiles\i386\modem.sys + 2008-04-14 02:20:32 155,136 ------w c:\windows\ServicePackFiles\i386\modemui.dll + 2008-04-14 02:21:07 16,384 ------w c:\windows\ServicePackFiles\i386\mofcomp.exe + 2008-04-14 02:20:32 124,416 ------w c:\windows\ServicePackFiles\i386\mofd.dll + 2008-04-14 02:21:25 16,896 ------w c:\windows\ServicePackFiles\i386\more.com + 2008-04-13 16:45:30 216,064 ------w c:\windows\ServicePackFiles\i386\moricons.dll + 2008-04-14 01:50:10 23,552 ------w c:\windows\ServicePackFiles\i386\mouclass.sys + 2008-04-13 18:39:46 42,368 ------w c:\windows\ServicePackFiles\i386\mountmgr.sys + 2008-04-14 02:21:08 3,558,912 ------w c:\windows\ServicePackFiles\i386\moviemk.exe + 2008-04-13 18:46:22 15,232 ------w c:\windows\ServicePackFiles\i386\mpe.sys + 2008-04-14 02:21:08 124,416 ------w c:\windows\ServicePackFiles\i386\mplay32.exe + 2008-04-14 02:20:32 59,904 ------w c:\windows\ServicePackFiles\i386\mpr.dll + 2008-04-14 02:20:32 87,040 ------w c:\windows\ServicePackFiles\i386\mprapi.dll + 2008-04-14 02:20:32 53,248 ------w c:\windows\ServicePackFiles\i386\mprdim.dll + 2008-04-13 18:39:44 92,544 ------w c:\windows\ServicePackFiles\i386\mqac.sys + 2008-04-14 02:20:32 138,240 ------w c:\windows\ServicePackFiles\i386\mqad.dll + 2008-04-14 02:21:09 19,968 ------w c:\windows\ServicePackFiles\i386\mqbkup.exe + 2008-04-14 02:20:32 47,616 ------w c:\windows\ServicePackFiles\i386\mqdscli.dll + 2008-04-14 02:20:32 16,896 ------w c:\windows\ServicePackFiles\i386\mqise.dll + 2008-04-14 02:20:32 89,088 ------w c:\windows\ServicePackFiles\i386\mqlogmgr.dll + 2008-04-14 02:20:32 225,280 ------w c:\windows\ServicePackFiles\i386\mqoa.dll + 2008-04-14 02:20:32 663,040 ------w c:\windows\ServicePackFiles\i386\mqqm.dll + 2008-04-14 02:20:32 177,152 ------w c:\windows\ServicePackFiles\i386\mqrt.dll + 2008-04-14 02:20:32 123,904 ------w c:\windows\ServicePackFiles\i386\mqrtdep.dll + 2008-04-14 02:20:32 95,744 ------w c:\windows\ServicePackFiles\i386\mqsec.dll + 2008-04-14 02:20:32 517,632 ------w c:\windows\ServicePackFiles\i386\mqsnap.dll + 2008-04-14 02:21:09 4,608 ------w c:\windows\ServicePackFiles\i386\mqsvc.exe + 2008-04-14 02:21:09 117,248 ------w c:\windows\ServicePackFiles\i386\mqtgsvc.exe + 2008-04-14 02:20:32 187,392 ------w c:\windows\ServicePackFiles\i386\mqtrig.dll + 2008-04-14 02:20:32 49,152 ------w c:\windows\ServicePackFiles\i386\mqupgrd.dll + 2008-04-14 02:20:32 523,776 ------w c:\windows\ServicePackFiles\i386\mqutil.dll + 2008-04-13 18:32:44 180,608 ------w c:\windows\ServicePackFiles\i386\mrxdav.sys + 2008-04-13 19:17:01 456,576 ------w c:\windows\ServicePackFiles\i386\mrxsmb.sys + 2008-04-14 02:20:32 71,680 ------w c:\windows\ServicePackFiles\i386\msacm32.dll + 2008-04-14 02:20:32 331,776 ------w c:\windows\ServicePackFiles\i386\msadce.dll + 2007-03-28 12:54:09 20,480 ------w c:\windows\ServicePackFiles\i386\msadcer.dll + 2008-04-14 02:20:32 61,440 ------w c:\windows\ServicePackFiles\i386\msadcf.dll + 2007-03-28 12:54:09 16,384 ------w c:\windows\ServicePackFiles\i386\msadcfr.dll + 2008-04-14 02:20:32 143,360 ------w c:\windows\ServicePackFiles\i386\msadco.dll + 2007-03-28 12:54:09 16,384 ------w c:\windows\ServicePackFiles\i386\msadcor.dll + 2008-04-14 02:20:32 53,248 ------w c:\windows\ServicePackFiles\i386\msadcs.dll + 2008-04-14 02:20:32 155,648 ------w c:\windows\ServicePackFiles\i386\msadds.dll + 2007-03-28 12:54:10 24,576 ------w c:\windows\ServicePackFiles\i386\msaddsr.dll + 2007-03-28 12:54:11 28,672 ------w c:\windows\ServicePackFiles\i386\msader15.dll + 2008-04-14 02:20:32 536,576 ------w c:\windows\ServicePackFiles\i386\msado15.dll + 2008-04-14 02:20:32 180,224 ------w c:\windows\ServicePackFiles\i386\msadomd.dll + 2008-04-14 02:20:32 57,344 ------w c:\windows\ServicePackFiles\i386\msador15.dll + 2008-04-14 02:20:32 200,704 ------w c:\windows\ServicePackFiles\i386\msadox.dll + 2008-04-14 02:20:32 57,344 ------w c:\windows\ServicePackFiles\i386\msadrh15.dll + 2008-04-14 02:18:52 3,584 ------w c:\windows\ServicePackFiles\i386\msafd.dll + 2008-04-14 02:20:32 86,016 ------w c:\windows\ServicePackFiles\i386\msapsspc.dll + 2008-04-14 02:20:32 57,344 ------w c:\windows\ServicePackFiles\i386\msasn1.dll + 2008-04-14 02:20:32 220,160 ------w c:\windows\ServicePackFiles\i386\mscandui.dll + 2008-04-14 02:20:32 73,728 ------w c:\windows\ServicePackFiles\i386\mscms.dll + 2008-04-14 02:20:32 69,632 ------w c:\windows\ServicePackFiles\i386\msconf.dll + 2008-04-14 02:21:09 171,520 ------w c:\windows\ServicePackFiles\i386\msconfig.exe + 2007-04-02 20:01:06 116,288 ------w c:\windows\ServicePackFiles\i386\msconv97.dll + 2007-06-27 12:54:57 1,564,672 ------w c:\windows\ServicePackFiles\i386\mscorcfg.dll + 2008-04-13 16:10:41 69,632 ------w c:\windows\ServicePackFiles\i386\mscordbc.dll + 2008-04-13 16:10:42 221,184 ------w c:\windows\ServicePackFiles\i386\mscordbi.dll + 2007-06-27 12:55:10 131,072 ------w c:\windows\ServicePackFiles\i386\mscoree.dll + 2008-04-13 16:10:45 73,728 ------w c:\windows\ServicePackFiles\i386\mscorie.dll + 2007-06-27 12:55:20 303,104 ------w c:\windows\ServicePackFiles\i386\mscorjit.dll + 2008-04-13 16:10:49 86,016 ------w c:\windows\ServicePackFiles\i386\mscorld.dll + 2007-12-17 11:58:42 1,998,848 ------w c:\windows\ServicePackFiles\i386\mscorlib.dll + 2008-04-13 16:10:53 94,208 ------w c:\windows\ServicePackFiles\i386\mscorpe.dll + 2008-04-13 16:10:53 143,360 ------w c:\windows\ServicePackFiles\i386\mscorrc.chs.dll + 2008-04-13 16:10:54 143,360 ------w c:\windows\ServicePackFiles\i386\mscorrc.cht.dll + 2008-04-13 16:10:54 143,360 ------w c:\windows\ServicePackFiles\i386\mscorrc.dll + 2008-04-13 16:10:54 172,032 ------w c:\windows\ServicePackFiles\i386\mscorrc.es.dll + 2008-04-13 16:10:54 172,032 ------w c:\windows\ServicePackFiles\i386\mscorrc.fr.dll + 2008-04-13 16:10:55 167,936 ------w c:\windows\ServicePackFiles\i386\mscorrc.ger.dll + 2008-04-13 16:10:55 167,936 ------w c:\windows\ServicePackFiles\i386\mscorrc.it.dll + 2008-04-13 16:10:55 143,360 ------w c:\windows\ServicePackFiles\i386\mscorrc.ja.dll + 2008-04-13 16:10:55 143,360 ------w c:\windows\ServicePackFiles\i386\mscorrc.kor.dll + 2008-04-13 16:10:55 46,592 ------w c:\windows\ServicePackFiles\i386\mscorsec.dll + 2008-04-13 16:10:55 69,632 ------w c:\windows\ServicePackFiles\i386\mscorsn.dll + 2007-12-17 11:58:53 2,273,280 ------w c:\windows\ServicePackFiles\i386\mscorsvr.dll + 2008-04-13 16:10:58 8,704 ------w c:\windows\ServicePackFiles\i386\mscortim.dll + 2007-12-17 11:59:26 2,281,472 ------w c:\windows\ServicePackFiles\i386\mscorwks.dll + 2008-04-13 17:26:07 12,288 ------w c:\windows\ServicePackFiles\i386\mscpx32r.dll + 2008-04-14 02:20:32 36,864 ------w c:\windows\ServicePackFiles\i386\mscpxl32.dll + 2008-04-14 02:20:32 297,984 ------w c:\windows\ServicePackFiles\i386\msctf.dll + 2008-04-14 02:20:32 68,608 ------w c:\windows\ServicePackFiles\i386\msctfp.dll + 2008-04-14 02:20:32 4,096 ------w c:\windows\ServicePackFiles\i386\msdadc.dll + 2008-04-14 02:20:32 118,784 ------w c:\windows\ServicePackFiles\i386\msdadiag.dll + 2008-04-14 02:20:32 4,096 ------w c:\windows\ServicePackFiles\i386\msdaenum.dll + 2008-04-14 02:20:32 4,096 ------w c:\windows\ServicePackFiles\i386\msdaer.dll + 2008-04-14 02:20:33 532,480 ------w c:\windows\ServicePackFiles\i386\msdaipp.dll + 2008-04-14 02:20:33 233,472 ------w c:\windows\ServicePackFiles\i386\msdaora.dll + 2007-03-28 12:54:12 20,480 ------w c:\windows\ServicePackFiles\i386\msdaorar.dll + 2008-04-14 02:20:33 77,824 ------w c:\windows\ServicePackFiles\i386\msdaosp.dll + 2007-03-28 12:54:12 16,384 ------w c:\windows\ServicePackFiles\i386\msdaprsr.dll + 2008-04-14 02:20:33 200,704 ------w c:\windows\ServicePackFiles\i386\msdaprst.dll + 2008-04-14 02:20:33 204,800 ------w c:\windows\ServicePackFiles\i386\msdaps.dll + 2008-04-14 02:20:33 118,784 ------w c:\windows\ServicePackFiles\i386\msdarem.dll + 2007-03-28 12:54:12 16,384 ------w c:\windows\ServicePackFiles\i386\msdaremr.dll + 2008-04-14 02:20:33 151,552 ------w c:\windows\ServicePackFiles\i386\msdart.dll + 2008-04-14 02:20:33 4,096 ------w c:\windows\ServicePackFiles\i386\msdasc.dll + 2008-04-14 02:20:33 315,392 ------w c:\windows\ServicePackFiles\i386\msdasql.dll + 2007-03-28 12:54:13 16,384 ------w c:\windows\ServicePackFiles\i386\msdasqlr.dll + 2008-04-14 02:20:33 94,208 ------w c:\windows\ServicePackFiles\i386\msdatl3.dll + 2008-04-14 02:20:33 20,480 ------w c:\windows\ServicePackFiles\i386\msdatt.dll + 2008-04-14 02:20:33 4,096 ------w c:\windows\ServicePackFiles\i386\msdaurl.dll + 2008-04-14 02:20:33 36,864 ------w c:\windows\ServicePackFiles\i386\msdfmap.dll + 2008-04-14 02:20:33 14,336 ------w c:\windows\ServicePackFiles\i386\msdmo.dll + 2008-04-14 02:21:09 6,144 ------w c:\windows\ServicePackFiles\i386\msdtc.exe + 2008-04-14 02:20:33 58,880 ------w c:\windows\ServicePackFiles\i386\msdtclog.dll + 2008-04-14 02:20:33 427,008 ------w c:\windows\ServicePackFiles\i386\msdtcprx.dll + 2008-04-14 02:20:33 90,112 ------w c:\windows\ServicePackFiles\i386\msdtcstp.dll + 2008-04-14 02:20:33 956,928 ------w c:\windows\ServicePackFiles\i386\msdtctm.dll + 2008-04-14 02:20:33 161,792 ------w c:\windows\ServicePackFiles\i386\msdtcuiu.dll + 2008-04-13 18:46:09 51,200 ------w c:\windows\ServicePackFiles\i386\msdv.sys + 2008-03-25 04:50:28 518,944 ------w c:\windows\ServicePackFiles\i386\msexch40.dll + 2008-03-25 04:50:30 326,432 ------w c:\windows\ServicePackFiles\i386\msexcl40.dll + 2008-04-13 18:32:39 19,072 ------w c:\windows\ServicePackFiles\i386\msfs.sys + 2008-04-14 02:20:33 539,136 ------w c:\windows\ServicePackFiles\i386\msftedit.dll + 2008-04-14 02:20:33 1,000,960 ------w c:\windows\ServicePackFiles\i386\msgina.dll + 2008-04-13 18:56:32 35,072 ------w c:\windows\ServicePackFiles\i386\msgpc.sys + 2008-04-14 02:20:33 3,166,208 ------w c:\windows\ServicePackFiles\i386\msgr3en.dll + 2008-04-14 02:20:33 15,360 ------w c:\windows\ServicePackFiles\i386\msgrocm.dll + 2008-04-14 02:20:33 82,944 ------w c:\windows\ServicePackFiles\i386\msgsc.dll + 2008-04-13 17:30:28 180,224 ------w c:\windows\ServicePackFiles\i386\msgslang.dll + 2008-04-14 02:20:34 33,792 ------w c:\windows\ServicePackFiles\i386\msgsvc.dll + 2008-04-14 02:21:27 188,416 ------w c:\windows\ServicePackFiles\i386\msh261.drv + 2008-04-14 02:21:27 294,912 ------w c:\windows\ServicePackFiles\i386\msh263.drv + 2008-04-14 02:21:09 29,184 ------w c:\windows\ServicePackFiles\i386\mshta.exe + 2008-04-14 02:20:34 3,066,880 ------w c:\windows\ServicePackFiles\i386\mshtml.dll + 2008-04-14 02:20:34 449,024 ------w c:\windows\ServicePackFiles\i386\mshtmled.dll + 2008-04-14 01:52:32 57,344 ------w c:\windows\ServicePackFiles\i386\mshtmler.dll + 2008-04-14 02:20:34 2,843,136 ------w c:\windows\ServicePackFiles\i386\msi.dll + 2008-04-14 02:20:34 51,712 ------w c:\windows\ServicePackFiles\i386\msident.dll + 2008-04-14 02:20:34 6,656 ------w c:\windows\ServicePackFiles\i386\msidle.dll + 2008-04-14 02:20:34 250,368 ------w c:\windows\ServicePackFiles\i386\msieftp.dll + 2008-04-14 02:21:09 78,848 ------w c:\windows\ServicePackFiles\i386\msiexec.exe + 2008-04-14 02:20:34 271,360 ------w c:\windows\ServicePackFiles\i386\msihnd.dll + 2008-04-14 02:20:34 4,608 ------w c:\windows\ServicePackFiles\i386\msimg32.dll + 2008-04-14 02:21:10 60,416 ------w c:\windows\ServicePackFiles\i386\msimn.exe + 2008-04-13 15:39:43 884,736 ------w c:\windows\ServicePackFiles\i386\msimsg.dll + 2008-04-14 02:20:34 159,232 ------w c:\windows\ServicePackFiles\i386\msimtf.dll + 2008-04-14 02:20:34 381,440 ------w c:\windows\ServicePackFiles\i386\msinfo.dll + 2008-04-13 18:54:28 22,016 ------w c:\windows\ServicePackFiles\i386\msircomm.sys + 2008-04-14 02:21:10 40,960 ------w c:\windows\ServicePackFiles\i386\msiregmv.exe + 2008-04-14 02:20:34 15,360 ------w c:\windows\ServicePackFiles\i386\msisip.dll + 2008-03-25 04:50:34 1,516,568 ------w c:\windows\ServicePackFiles\i386\msjet40.dll + 2008-03-25 04:50:40 355,112 ------w c:\windows\ServicePackFiles\i386\msjetol1.dll + 2008-03-25 04:49:45 183,072 ------w c:\windows\ServicePackFiles\i386\msjint40.dll + 2008-04-14 02:20:34 102,400 ------w c:\windows\ServicePackFiles\i386\msjro.dll + 2008-03-25 04:50:42 60,192 ------w c:\windows\ServicePackFiles\i386\msjter40.dll + 2008-03-25 04:50:42 248,608 ------w c:\windows\ServicePackFiles\i386\msjtes40.dll + 2008-04-13 18:39:52 7,552 ------w c:\windows\ServicePackFiles\i386\mskssrv.sys + 2008-04-14 02:20:34 25,088 ------w c:\windows\ServicePackFiles\i386\mslbui.dll + 2008-03-25 04:50:44 219,936 ------w c:\windows\ServicePackFiles\i386\msltus40.dll + 2008-04-14 02:20:34 39,936 ------w c:\windows\ServicePackFiles\i386\mslwvtts.dll + 2008-04-14 02:20:34 170,496 ------w c:\windows\ServicePackFiles\i386\msmqocm.dll + 2008-04-14 02:21:10 1,695,232 ------w c:\windows\ServicePackFiles\i386\msmsgs.exe + 2008-04-14 02:20:34 290,816 ------w c:\windows\ServicePackFiles\i386\msnsspc.dll + 2008-04-14 02:20:34 122,368 ------w c:\windows\ServicePackFiles\i386\msobcomm.dll + 2008-04-14 02:20:34 16,384 ------w c:\windows\ServicePackFiles\i386\msobdl.dll + 2008-04-14 02:20:34 566,272 ------w c:\windows\ServicePackFiles\i386\msobmain.dll + 2008-04-14 02:20:34 30,720 ------w c:\windows\ServicePackFiles\i386\msobshel.dll + 2008-04-14 02:20:34 19,456 ------w c:\windows\ServicePackFiles\i386\msobweb.dll + 2008-04-14 02:20:34 1,314,816 ------w c:\windows\ServicePackFiles\i386\msoe.dll + 2008-04-14 02:20:34 252,928 ------w c:\windows\ServicePackFiles\i386\msoeacct.dll + 2008-04-14 01:56:51 2,512,896 ------w c:\windows\ServicePackFiles\i386\msoeres.dll + 2008-04-14 02:20:34 105,984 ------w c:\windows\ServicePackFiles\i386\msoert2.dll + 2008-04-14 02:21:10 29,184 ------w c:\windows\ServicePackFiles\i386\msoobe.exe + 2007-03-28 12:54:14 24,576 ------w c:\windows\ServicePackFiles\i386\msorc32r.dll + 2008-04-14 02:20:34 143,360 ------w c:\windows\ServicePackFiles\i386\msorcl32.dll + 2008-04-14 02:21:11 345,600 ------w c:\windows\ServicePackFiles\i386\mspaint.exe + 2008-04-14 02:20:34 29,696 ------w c:\windows\ServicePackFiles\i386\mspatcha.dll + 2008-03-25 04:50:45 355,104 ------w c:\windows\ServicePackFiles\i386\mspbde40.dll + 2008-04-13 18:39:50 5,376 ------w c:\windows\ServicePackFiles\i386\mspclock.sys + 2008-04-13 18:39:51 4,992 ------w c:\windows\ServicePackFiles\i386\mspqm.sys + 2008-04-13 16:23:31 48,128 ------w c:\windows\ServicePackFiles\i386\msprivs.dll + 2008-04-14 02:20:34 146,432 ------w c:\windows\ServicePackFiles\i386\msrating.dll + 2008-03-25 04:50:47 432,928 ------w c:\windows\ServicePackFiles\i386\msrd2x40.dll + 2008-03-25 04:50:49 322,336 ------w c:\windows\ServicePackFiles\i386\msrd3x40.dll + 2008-03-25 04:50:52 559,904 ------w c:\windows\ServicePackFiles\i386\msrepl40.dll + 2008-04-14 02:20:34 11,264 ------w c:\windows\ServicePackFiles\i386\msrle32.dll + 2008-04-14 02:20:34 134,656 ------w c:\windows\ServicePackFiles\i386\mssap.dll + 2008-04-14 02:20:34 155,136 ------w c:\windows\ServicePackFiles\i386\mssha.dll + 2008-04-14 01:57:16 80,896 ------w c:\windows\ServicePackFiles\i386\msshamsg.dll + 2008-04-13 18:36:46 15,488 ------w c:\windows\ServicePackFiles\i386\mssmbios.sys + 2008-04-14 02:20:34 274,432 ------w c:\windows\ServicePackFiles\i386\mst120.dll + 2008-04-14 02:20:34 57,344 ------w c:\windows\ServicePackFiles\i386\mst123.dll + 2008-04-13 18:46:08 49,024 ------w c:\windows\ServicePackFiles\i386\mstape.sys + 2008-04-14 02:20:34 278,528 ------w c:\windows\ServicePackFiles\i386\mstask.dll + 2008-04-13 18:39:50 5,504 ------w c:\windows\ServicePackFiles\i386\mstee.sys + 2008-03-25 04:50:55 264,992 ------w c:\windows\ServicePackFiles\i386\mstext40.dll + 2008-04-14 02:20:34 532,480 ------w c:\windows\ServicePackFiles\i386\mstime.dll + 2008-04-14 02:21:11 12,288 ------w c:\windows\ServicePackFiles\i386\mstinit.exe + 2008-04-14 02:20:34 116,224 ------w c:\windows\ServicePackFiles\i386\mstlsapi.dll + 2008-04-14 02:20:34 199,168 ------w c:\windows\ServicePackFiles\i386\msutb.dll + 2008-04-14 02:20:34 132,608 ------w c:\windows\ServicePackFiles\i386\msv1_0.dll + 2008-04-14 02:20:34 1,384,479 ------w c:\windows\ServicePackFiles\i386\msvbvm60.dll + 2008-04-14 02:20:34 57,344 ------w c:\windows\ServicePackFiles\i386\msvcirt.dll + 2008-04-14 02:20:34 413,696 ------w c:\windows\ServicePackFiles\i386\msvcp60.dll + 2008-04-14 02:20:34 343,040 ------w c:\windows\ServicePackFiles\i386\msvcrt.dll + 2008-04-13 18:30:46 61,440 ------w c:\windows\ServicePackFiles\i386\msvcrt40.dll + 2008-04-14 02:20:34 122,368 ------w c:\windows\ServicePackFiles\i386\msvfw32.dll + 2008-04-14 02:20:34 1,433,600 ------w c:\windows\ServicePackFiles\i386\msvidctl.dll + 2008-04-14 02:20:34 72,704 ------w c:\windows\ServicePackFiles\i386\msw3prt.dll + 2008-03-25 04:50:57 838,432 ------w c:\windows\ServicePackFiles\i386\mswdat10.dll + 2008-04-14 02:20:34 204,288 ------w c:\windows\ServicePackFiles\i386\mswebdvd.dll + 2008-04-14 02:20:34 247,808 ------w c:\windows\ServicePackFiles\i386\mswsock.dll + 2008-03-25 04:49:46 621,344 ------w c:\windows\ServicePackFiles\i386\mswstr10.dll + 2008-04-14 02:20:34 24,576 ------w c:\windows\ServicePackFiles\i386\msxactps.dll + 2008-03-25 04:50:58 355,104 ------w c:\windows\ServicePackFiles\i386\msxbde40.dll + 2008-04-14 02:20:34 506,368 ------w c:\windows\ServicePackFiles\i386\msxml.dll + 2008-04-14 02:20:34 701,440 ------w c:\windows\ServicePackFiles\i386\msxml2.dll + 2008-04-14 02:20:34 1,104,896 ------w c:\windows\ServicePackFiles\i386\msxml3.dll + 2008-04-14 02:20:34 16,896 ------w c:\windows\ServicePackFiles\i386\msyuv.dll + 2004-08-04 00:41:40 126,686 ------w c:\windows\ServicePackFiles\i386\mtlmnt5.sys + 2004-08-04 00:41:38 1,309,184 ------w c:\windows\ServicePackFiles\i386\mtlstrm.sys + 2008-04-14 02:21:11 119,808 ------w c:\windows\ServicePackFiles\i386\mtstocom.exe + 2008-04-14 02:20:34 66,560 ------w c:\windows\ServicePackFiles\i386\mtxclu.dll + 2008-04-14 02:20:34 30,720 ------w c:\windows\ServicePackFiles\i386\mtxdm.dll + 2008-04-14 02:20:34 4,096 ------w c:\windows\ServicePackFiles\i386\mtxex.dll + 2008-04-14 02:20:34 34,304 ------w c:\windows\ServicePackFiles\i386\mtxlegih.dll + 2008-04-14 02:20:34 91,648 ------w c:\windows\ServicePackFiles\i386\mtxoci.dll + 2008-04-14 02:20:34 1,737,856 ------w c:\windows\ServicePackFiles\i386\mtxparhd.dll + 2004-08-04 00:29:38 452,736 ------w c:\windows\ServicePackFiles\i386\mtxparhm.sys + 2008-04-13 19:17:05 105,344 ------w c:\windows\ServicePackFiles\i386\mup.sys + 2008-04-13 18:43:55 12,672 ------w c:\windows\ServicePackFiles\i386\mutohpen.sys + 2008-04-14 02:20:34 90,624 ------w c:\windows\ServicePackFiles\i386\mydocs.dll + 2008-04-13 18:46:25 85,248 ------w c:\windows\ServicePackFiles\i386\nabtsfec.sys + 2008-04-14 02:20:34 221,184 ------w c:\windows\ServicePackFiles\i386\nac.dll + 2008-04-14 02:20:34 30,208 ------w c:\windows\ServicePackFiles\i386\napipsec.dll + 2008-04-14 02:20:34 198,656 ------w c:\windows\ServicePackFiles\i386\napmontr.dll + 2008-04-14 02:21:11 176,640 ------w c:\windows\ServicePackFiles\i386\napstat.exe + 2008-04-14 02:21:11 53,760 ------w c:\windows\ServicePackFiles\i386\narrator.exe + 2008-04-14 02:20:34 36,352 ------w c:\windows\ServicePackFiles\i386\ncobjapi.dll + 2008-04-14 02:20:34 47,104 ------w c:\windows\ServicePackFiles\i386\ncprov.dll + 2008-04-14 02:20:34 9,728 ------w c:\windows\ServicePackFiles\i386\ncpsres.dll + 2008-04-14 02:20:34 18,432 ------w c:\windows\ServicePackFiles\i386\nddeapi.dll + 2008-04-14 02:21:11 4,096 ------w c:\windows\ServicePackFiles\i386\nddeapir.exe + 2008-04-14 02:20:34 19,456 ------w c:\windows\ServicePackFiles\i386\nddenb32.dll + 2008-04-13 19:20:37 182,656 ------w c:\windows\ServicePackFiles\i386\ndis.sys + 2008-04-13 18:46:22 10,880 ------w c:\windows\ServicePackFiles\i386\ndisip.sys + 2008-04-14 02:20:34 57,344 ------w c:\windows\ServicePackFiles\i386\ndisnpp.dll + 2008-04-13 18:57:27 10,112 ------w c:\windows\ServicePackFiles\i386\ndistapi.sys + 2008-04-13 18:55:58 14,592 ------w c:\windows\ServicePackFiles\i386\ndisuio.sys + 2008-04-13 19:20:42 91,520 ------w c:\windows\ServicePackFiles\i386\ndiswan.sys + 2008-04-13 18:57:29 40,576 ------w c:\windows\ServicePackFiles\i386\ndproxy.sys + 2008-04-14 02:21:11 42,496 ------w c:\windows\ServicePackFiles\i386\net.exe + 2008-04-14 02:21:11 124,928 ------w c:\windows\ServicePackFiles\i386\net1.exe + 2008-04-14 02:20:34 337,408 ------w c:\windows\ServicePackFiles\i386\netapi32.dll + 2008-04-13 18:56:02 34,688 ------w c:\windows\ServicePackFiles\i386\netbios.sys + 2008-04-13 19:21:00 162,816 ------w c:\windows\ServicePackFiles\i386\netbt.sys + 2008-04-14 02:20:34 629,760 ------w c:\windows\ServicePackFiles\i386\netcfgx.dll + 2008-04-14 02:21:11 113,664 ------w c:\windows\ServicePackFiles\i386\netdde.exe + 2004-08-04 01:10:58 126,976 ------w c:\windows\ServicePackFiles\i386\netfxocm.dll + 2007-12-17 11:59:53 82,976 ------w c:\windows\ServicePackFiles\i386\netfxupdate.exe + 2008-04-14 02:20:34 141,824 ------w c:\windows\ServicePackFiles\i386\netid.dll + 2008-04-14 02:20:34 407,040 ------w c:\windows\ServicePackFiles\i386\netlogon.dll + 2008-04-14 02:20:34 198,144 ------w c:\windows\ServicePackFiles\i386\netman.dll + 2008-04-14 02:20:34 77,824 ------w c:\windows\ServicePackFiles\i386\netoc.dll + 2008-04-14 02:20:34 879,616 ------w c:\windows\ServicePackFiles\i386\netplwiz.dll + 2008-04-14 02:20:34 11,776 ------w c:\windows\ServicePackFiles\i386\netrap.dll + 2008-04-14 02:24:30 332,800 ------w c:\windows\ServicePackFiles\i386\netsetup.exe + 2008-04-14 02:21:11 87,040 ------w c:\windows\ServicePackFiles\i386\netsh.exe + 2008-04-14 02:20:36 1,710,592 ------w c:\windows\ServicePackFiles\i386\netshell.dll + 2008-04-14 02:21:12 37,376 ------w c:\windows\ServicePackFiles\i386\netstat.exe + 2008-04-14 02:20:36 81,920 ------w c:\windows\ServicePackFiles\i386\netui0.dll + 2008-04-14 02:20:36 245,760 ------w c:\windows\ServicePackFiles\i386\netui1.dll + 2004-08-04 02:39:38 132,695 ------w c:\windows\ServicePackFiles\i386\netwlan5.sys + 2008-04-14 02:20:36 249,344 ------w c:\windows\ServicePackFiles\i386\newdev.dll + 2008-04-13 16:11:06 147,456 ------w c:\windows\ServicePackFiles\i386\ngen.exe + 2008-04-13 18:51:25 61,824 ------w c:\windows\ServicePackFiles\i386\nic1394.sys + 2008-04-14 02:20:36 98,304 ------w c:\windows\ServicePackFiles\i386\nlhtml.dll + 2008-04-14 02:20:36 229,376 ------w c:\windows\ServicePackFiles\i386\nmas.dll + 2008-04-14 02:20:36 28,672 ------w c:\windows\ServicePackFiles\i386\nmasnt.dll + 2008-04-14 02:20:36 81,920 ------w c:\windows\ServicePackFiles\i386\nmchat.dll + 2008-04-14 02:20:36 77,824 ------w c:\windows\ServicePackFiles\i386\nmcom.dll + 2008-04-14 02:20:36 155,648 ------w c:\windows\ServicePackFiles\i386\nmft.dll + 2008-04-14 02:20:36 28,672 ------w c:\windows\ServicePackFiles\i386\nmmkcert.dll + 2008-04-13 18:53:09 40,320 ------w c:\windows\ServicePackFiles\i386\nmnt.sys + 2008-04-14 02:20:36 172,032 ------w c:\windows\ServicePackFiles\i386\nmoldwb.dll + 2008-04-14 02:20:36 192,512 ------w c:\windows\ServicePackFiles\i386\nmwb.dll + 2008-04-14 02:21:12 70,144 ------w c:\windows\ServicePackFiles\i386\notepad.exe + 2008-04-13 18:32:39 30,848 ------w c:\windows\ServicePackFiles\i386\npfs.sys + 2008-04-14 02:21:12 15,360 ------w c:\windows\ServicePackFiles\i386\nppagent.exe + 2008-04-14 02:20:36 55,296 ------w c:\windows\ServicePackFiles\i386\npptools.dll + 2008-04-13 18:54:36 28,672 ------w c:\windows\ServicePackFiles\i386\nscirda.sys + 2008-04-14 02:20:36 45,056 ------w c:\windows\ServicePackFiles\i386\nsepm.dll + 2008-04-14 02:21:12 79,360 ------w c:\windows\ServicePackFiles\i386\nslookup.exe + 2008-04-14 02:21:13 1,219,072 ------w c:\windows\ServicePackFiles\i386\ntbackup.exe + 2004-08-04 01:38:34 47,564 ------w c:\windows\ServicePackFiles\i386\ntdetect.com + 2008-04-14 02:20:06 721,920 ------w c:\windows\ServicePackFiles\i386\ntdll.dll + 2008-04-14 02:20:37 67,072 ------w c:\windows\ServicePackFiles\i386\ntdsapi.dll + 2008-04-14 02:20:37 212,992 ------w c:\windows\ServicePackFiles\i386\ntevt.dll + 2008-04-13 19:15:53 574,976 ------w c:\windows\ServicePackFiles\i386\ntfs.sys + 2004-08-04 01:45:20 33,984 ------w c:\windows\ServicePackFiles\i386\ntio.sys + 2004-08-04 01:45:16 34,560 ------w c:\windows\ServicePackFiles\i386\ntio404.sys + 2004-08-04 01:45:12 35,648 ------w c:\windows\ServicePackFiles\i386\ntio411.sys + 2004-08-04 01:45:16 35,424 ------w c:\windows\ServicePackFiles\i386\ntio412.sys + 2004-08-04 01:45:14 34,560 ------w c:\windows\ServicePackFiles\i386\ntio804.sys + 2008-04-14 02:00:35 2,149,376 ------w c:\windows\ServicePackFiles\i386\ntkrnlmp.exe + 2008-04-14 02:00:43 2,070,144 ------w c:\windows\ServicePackFiles\i386\ntkrnlpa.exe + 2008-04-14 02:00:50 2,028,032 ------w c:\windows\ServicePackFiles\i386\ntkrpamp.exe + 2008-04-14 02:20:37 44,032 ------w c:\windows\ServicePackFiles\i386\ntlanman.dll + 2008-04-14 02:20:37 8,192 ------w c:\windows\ServicePackFiles\i386\ntlsapi.dll + 2008-04-14 02:20:37 119,296 ------w c:\windows\ServicePackFiles\i386\ntmarta.dll + 2008-04-14 02:20:37 40,960 ------w c:\windows\ServicePackFiles\i386\ntmsapi.dll + 2008-04-14 02:20:37 180,224 ------w c:\windows\ServicePackFiles\i386\ntmsdba.dll + 2008-04-14 02:20:37 493,056 ------w c:\windows\ServicePackFiles\i386\ntmsmgr.dll + 2008-04-14 02:20:37 437,248 ------w c:\windows\ServicePackFiles\i386\ntmssvc.dll + 2004-08-04 00:41:40 180,360 ------w c:\windows\ServicePackFiles\i386\ntmtlfax.sys + 2008-04-14 02:20:37 63,488 ------w c:\windows\ServicePackFiles\i386\ntoc.dll + 2008-04-14 02:01:13 2,193,280 ------w c:\windows\ServicePackFiles\i386\ntoskrnl.exe + 2008-04-14 02:20:37 91,648 ------w c:\windows\ServicePackFiles\i386\ntprint.dll + 2008-04-14 02:20:37 145,408 ------w c:\windows\ServicePackFiles\i386\ntshrui.dll + 2008-04-14 02:21:13 421,376 ------w c:\windows\ServicePackFiles\i386\ntvdm.exe + 2008-04-14 02:20:37 15,360 ------w c:\windows\ServicePackFiles\i386\ntvdmd.dll + 2008-04-14 02:20:37 4,274,816 ------w c:\windows\ServicePackFiles\i386\nv4_disp.dll + 2004-08-04 00:29:56 1,897,408 ------w c:\windows\ServicePackFiles\i386\nv4_mini.sys + 2008-04-14 02:20:37 64,000 ------w c:\windows\ServicePackFiles\i386\nwapi32.dll + 2008-04-13 18:56:06 88,320 ------w c:\windows\ServicePackFiles\i386\nwlnkipx.sys + 2008-04-14 02:20:37 143,360 ------w c:\windows\ServicePackFiles\i386\nwprovau.dll + 2008-04-13 18:34:12 163,584 ------w c:\windows\ServicePackFiles\i386\nwrdr.sys + 2008-04-14 02:20:37 65,536 ------w c:\windows\ServicePackFiles\i386\nwwks.dll + 2008-04-14 02:20:37 271,360 ------w c:\windows\ServicePackFiles\i386\oakley.dll + 2008-04-14 02:20:37 287,232 ------w c:\windows\ServicePackFiles\i386\objsel.dll + 2008-04-13 18:40:07 444,928 ------w c:\windows\ServicePackFiles\i386\obrs0416.dll + 2008-04-14 02:20:37 97,280 ------w c:\windows\ServicePackFiles\i386\occache.dll + 2008-04-14 02:20:37 15,872 ------w c:\windows\ServicePackFiles\i386\ocgen.dll + 2008-04-14 02:20:37 69,120 ------w c:\windows\ServicePackFiles\i386\ocmanage.dll + 2008-04-14 02:20:37 17,408 ------w c:\windows\ServicePackFiles\i386\ocmsn.dll + 2004-07-17 14:36:44 26,224 ------w c:\windows\ServicePackFiles\i386\odbc16gt.dll + 2008-04-14 02:20:37 249,856 ------w c:\windows\ServicePackFiles\i386\odbc32.dll + 2008-04-14 02:20:37 16,384 ------w c:\windows\ServicePackFiles\i386\odbc32gt.dll + 2008-04-14 02:21:13 32,768 ------w c:\windows\ServicePackFiles\i386\odbcad32.exe + 2008-04-14 02:20:37 24,576 ------w c:\windows\ServicePackFiles\i386\odbcbcp.dll + 2008-04-14 02:20:37 135,168 ------w c:\windows\ServicePackFiles\i386\odbcconf.dll + 2008-04-14 02:21:13 69,632 ------w c:\windows\ServicePackFiles\i386\odbcconf.exe + 2008-04-14 02:20:37 106,496 ------w c:\windows\ServicePackFiles\i386\odbccp32.dll + 2008-04-14 02:20:37 65,536 ------w c:\windows\ServicePackFiles\i386\odbccr32.dll + 2008-04-14 02:20:37 65,536 ------w c:\windows\ServicePackFiles\i386\odbccu32.dll + 2007-03-28 12:54:29 98,304 ------w c:\windows\ServicePackFiles\i386\odbcint.dll + 2008-04-14 02:19:17 57,375 ------w c:\windows\ServicePackFiles\i386\odbcji32.dll + 2008-04-14 02:20:37 278,559 ------w c:\windows\ServicePackFiles\i386\odbcjt32.dll + 2008-04-13 17:26:05 12,288 ------w c:\windows\ServicePackFiles\i386\odbcp32r.dll + 2008-04-14 02:20:37 147,456 ------w c:\windows\ServicePackFiles\i386\odbctrac.dll + 2008-04-14 02:20:37 20,511 ------w c:\windows\ServicePackFiles\i386\oddbse32.dll + 2008-04-14 02:20:37 20,510 ------w c:\windows\ServicePackFiles\i386\odexl32.dll + 2008-04-14 02:20:37 20,510 ------w c:\windows\ServicePackFiles\i386\odfox32.dll + 2008-04-14 02:20:37 20,510 ------w c:\windows\ServicePackFiles\i386\odpdx32.dll + 2008-04-14 02:20:37 20,511 ------w c:\windows\ServicePackFiles\i386\odtext32.dll + 2008-04-14 02:20:37 104,448 ------w c:\windows\ServicePackFiles\i386\oeimport.dll + 2008-04-14 02:21:13 60,928 ------w c:\windows\ServicePackFiles\i386\oemig50.exe + 2008-04-14 02:20:37 35,328 ------w c:\windows\ServicePackFiles\i386\oemiglib.dll + 2008-04-14 02:20:37 192,000 ------w c:\windows\ServicePackFiles\i386\offfilt.dll + 2008-04-13 18:46:18 61,696 ------w c:\windows\ServicePackFiles\i386\ohci1394.sys + 2008-04-14 02:20:37 1,287,168 ------w c:\windows\ServicePackFiles\i386\ole32.dll + 2008-04-14 02:20:37 551,936 ------w c:\windows\ServicePackFiles\i386\oleaut32.dll + 2008-04-14 02:20:37 75,264 ------w c:\windows\ServicePackFiles\i386\olecli32.dll + 2008-04-14 02:20:37 37,376 ------w c:\windows\ServicePackFiles\i386\olecnv32.dll + 2008-04-14 02:20:37 487,424 ------w c:\windows\ServicePackFiles\i386\oledb32.dll + 2008-04-14 02:20:37 69,632 ------w c:\windows\ServicePackFiles\i386\oledb32r.dll + 2008-04-14 02:20:37 123,904 ------w c:\windows\ServicePackFiles\i386\oledlg.dll + 2008-04-14 02:20:37 109,056 ------w c:\windows\ServicePackFiles\i386\oleprn.dll + 2008-04-14 02:20:37 84,992 ------w c:\windows\ServicePackFiles\i386\olepro32.dll + 2008-04-14 02:20:37 144,896 ------w c:\windows\ServicePackFiles\i386\onex.dll + 2008-04-14 02:21:13 51,712 ------w c:\windows\ServicePackFiles\i386\oobebaln.exe + 2008-04-14 02:20:37 713,728 ------w c:\windows\ServicePackFiles\i386\opengl32.dll + 2008-04-14 02:21:13 70,144 ------w c:\windows\ServicePackFiles\i386\opnfiles.exe + 2008-04-13 18:32:32 166,912 ------w c:\windows\ServicePackFiles\i386\oschoice.exe + 2008-04-14 02:21:14 216,064 ------w c:\windows\ServicePackFiles\i386\osk.exe + 2008-04-13 18:31:43 231,936 ------w c:\windows\ServicePackFiles\i386\osloader.exe + 2008-04-14 02:20:37 67,584 ------w c:\windows\ServicePackFiles\i386\osuninst.dll + 2008-04-14 02:20:37 153,600 ------w c:\windows\ServicePackFiles\i386\p2p.dll + 2008-04-14 02:20:37 105,472 ------w c:\windows\ServicePackFiles\i386\p2pgasvc.dll + 2008-04-14 02:20:37 313,856 ------w c:\windows\ServicePackFiles\i386\p2pgraph.dll + 2008-04-14 02:20:37 115,712 ------w c:\windows\ServicePackFiles\i386\p2pnetsh.dll + 2008-04-14 02:20:37 554,496 ------w c:\windows\ServicePackFiles\i386\p2psvc.dll + 2008-04-14 02:02:22 46,848 ------w c:\windows\ServicePackFiles\i386\p3.sys + 2008-04-14 02:21:14 58,880 ------w c:\windows\ServicePackFiles\i386\packager.exe + 2008-04-14 02:02:24 80,384 ------w c:\windows\ServicePackFiles\i386\parport.sys + 2008-04-13 18:40:49 19,712 ------w c:\windows\ServicePackFiles\i386\partmgr.sys + 2008-04-14 02:20:37 68,608 ------w c:\windows\ServicePackFiles\i386\pautoenr.dll + 2004-08-04 00:31:24 29,502 ------w c:\windows\ServicePackFiles\i386\pca200e.sys + 2008-04-14 02:20:37 102,912 ------w c:\windows\ServicePackFiles\i386\pchshell.dll + 2008-04-14 02:20:37 38,400 ------w c:\windows\ServicePackFiles\i386\pchsvc.dll + 2008-04-14 02:02:29 68,992 ------w c:\windows\ServicePackFiles\i386\pci.sys + 2008-04-13 18:40:29 24,960 ------w c:\windows\ServicePackFiles\i386\pciidex.sys + 2007-05-15 08:08:11 288,768 ------w c:\windows\ServicePackFiles\i386\pcl4res.dll + 2007-05-15 08:08:13 1,058,816 ------w c:\windows\ServicePackFiles\i386\pcl5eres.dll + 2007-05-15 08:08:14 1,057,280 ------w c:\windows\ServicePackFiles\i386\pcl5ures.dll + 2007-05-15 08:08:14 207,872 ------w c:\windows\ServicePackFiles\i386\pclxl.dll + 2008-04-14 02:02:31 120,320 ------w c:\windows\ServicePackFiles\i386\pcmcia.sys + 2004-08-04 00:06:18 169,984 ------w c:\windows\ServicePackFiles\i386\pcx500.sys + 2008-04-14 02:20:37 286,208 ------w c:\windows\ServicePackFiles\i386\pdh.dll + 2008-04-13 16:11:06 20,480 ------w c:\windows\ServicePackFiles\i386\perfcounter.dll + 2008-04-14 02:20:37 40,960 ------w c:\windows\ServicePackFiles\i386\perfctrs.dll + 2008-04-14 02:20:37 27,136 ------w c:\windows\ServicePackFiles\i386\perfdisk.dll + 2008-04-14 02:21:14 15,872 ------w c:\windows\ServicePackFiles\i386\perfmon.exe + 2008-04-14 02:20:37 18,432 ------w c:\windows\ServicePackFiles\i386\perfnet.dll + 2008-04-14 02:20:37 26,112 ------w c:\windows\ServicePackFiles\i386\perfos.dll + 2008-04-14 02:20:37 35,328 ------w c:\windows\ServicePackFiles\i386\perfproc.dll + 2008-04-13 18:44:29 27,904 ------w c:\windows\ServicePackFiles\i386\perm2.sys + 2008-04-14 02:19:20 211,584 ------w c:\windows\ServicePackFiles\i386\perm2dll.dll + 2008-04-13 18:44:30 28,032 ------w c:\windows\ServicePackFiles\i386\perm3.sys + 2008-04-14 02:19:20 259,328 ------w c:\windows\ServicePackFiles\i386\perm3dd.dll + 2008-04-14 02:20:37 172,032 ------w c:\windows\ServicePackFiles\i386\photowiz.dll + 2008-04-14 02:20:37 35,328 ------w c:\windows\ServicePackFiles\i386\pid.dll + 2008-04-14 02:19:52 24,064 ------w c:\windows\ServicePackFiles\i386\pidgen.dll + 2008-04-14 02:21:14 283,648 ------w c:\windows\ServicePackFiles\i386\pinball.exe + 2008-04-14 02:21:14 19,456 ------w c:\windows\ServicePackFiles\i386\ping.exe + 2008-04-14 02:20:37 15,360 ------w c:\windows\ServicePackFiles\i386\pjlmon.dll Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 continuando 2: + 2008-04-14 02:20:37 44,544 ------w c:\windows\ServicePackFiles\i386\plotter.dll + 2008-04-14 02:20:37 53,760 ------w c:\windows\ServicePackFiles\i386\plotui.dll + 2008-04-14 02:20:37 412,160 ------w c:\windows\ServicePackFiles\i386\pmh.dll + 2008-04-14 02:20:37 39,424 ------w c:\windows\ServicePackFiles\i386\pngfilt.dll + 2008-04-14 02:20:37 58,880 ------w c:\windows\ServicePackFiles\i386\pnrpnsp.dll + 2008-04-14 02:20:37 92,672 ------w c:\windows\ServicePackFiles\i386\policman.dll + 2008-04-14 02:20:37 105,984 ------w c:\windows\ServicePackFiles\i386\polstore.dll + 2008-04-13 19:19:41 146,048 ------w c:\windows\ServicePackFiles\i386\portcls.sys + 2008-04-14 02:21:14 49,152 ------w c:\windows\ServicePackFiles\i386\powercfg.exe + 2008-04-13 18:40:56 8,832 ------w c:\windows\ServicePackFiles\i386\powerfil.sys + 2008-04-14 02:20:37 17,408 ------w c:\windows\ServicePackFiles\i386\powrprof.dll + 2008-04-13 18:41:00 17,664 ------w c:\windows\ServicePackFiles\i386\ppa3.sys + 2008-04-14 02:20:37 572,928 ------w c:\windows\ServicePackFiles\i386\printui.dll + 2008-04-14 01:51:47 39,936 ------w c:\windows\ServicePackFiles\i386\processr.sys + 2008-04-14 02:20:37 27,648 ------w c:\windows\ServicePackFiles\i386\profmap.dll + 2008-04-14 02:21:15 109,568 ------w c:\windows\ServicePackFiles\i386\progman.exe + 2008-04-14 02:21:15 50,688 ------w c:\windows\ServicePackFiles\i386\proquota.exe + 2008-04-14 02:20:37 237,056 ------w c:\windows\ServicePackFiles\i386\provthrd.dll + 2008-04-14 02:21:15 9,728 ------w c:\windows\ServicePackFiles\i386\proxycfg.exe + 2008-04-14 02:20:37 728,576 ------w c:\windows\ServicePackFiles\i386\ps5ui.dll + 2008-04-14 02:20:37 23,040 ------w c:\windows\ServicePackFiles\i386\psapi.dll + 2008-04-14 02:20:37 97,280 ------w c:\windows\ServicePackFiles\i386\psbase.dll + 2008-04-13 18:56:38 69,120 ------w c:\windows\ServicePackFiles\i386\psched.sys + 2008-04-14 02:20:37 543,232 ------w c:\windows\ServicePackFiles\i386\pscript5.dll + 2008-04-14 02:20:37 363,520 ------w c:\windows\ServicePackFiles\i386\psisdecd.dll + 2008-04-14 02:20:37 43,520 ------w c:\windows\ServicePackFiles\i386\pstorec.dll + 2008-04-14 02:20:37 34,304 ------w c:\windows\ServicePackFiles\i386\pstorsvc.dll + 2008-04-14 02:20:37 159,232 ------w c:\windows\ServicePackFiles\i386\ptpusd.dll + 2008-04-14 02:20:37 7,680 ------w c:\windows\ServicePackFiles\i386\pwsdata.dll + 2008-04-14 02:20:37 150,528 ------w c:\windows\ServicePackFiles\i386\qagent.dll + 2008-04-14 02:20:37 292,864 ------w c:\windows\ServicePackFiles\i386\qagentrt.dll + 2008-04-14 02:20:37 237,568 ------w c:\windows\ServicePackFiles\i386\qasf.dll + 2008-04-14 02:20:37 192,512 ------w c:\windows\ServicePackFiles\i386\qcap.dll + 2008-04-14 02:20:37 62,464 ------w c:\windows\ServicePackFiles\i386\qcliprov.dll + 2008-04-14 02:20:37 279,040 ------w c:\windows\ServicePackFiles\i386\qdv.dll + 2008-04-14 02:20:37 386,560 ------w c:\windows\ServicePackFiles\i386\qdvd.dll + 2008-04-14 02:20:37 563,200 ------w c:\windows\ServicePackFiles\i386\qedit.dll + 2008-04-13 17:21:32 733,696 ------w c:\windows\ServicePackFiles\i386\qedwipes.dll + 2008-04-13 18:40:52 6,016 ------w c:\windows\ServicePackFiles\i386\qic157.sys + 2008-04-14 02:20:37 409,088 ------w c:\windows\ServicePackFiles\i386\qmgr.dll + 2008-04-14 02:20:37 18,944 ------w c:\windows\ServicePackFiles\i386\qmgrprxy.dll + 2008-04-14 02:21:15 20,480 ------w c:\windows\ServicePackFiles\i386\qprocess.exe + 2008-04-14 02:20:37 1,292,800 ------w c:\windows\ServicePackFiles\i386\quartz.dll + 2008-04-14 02:20:37 1,439,744 ------w c:\windows\ServicePackFiles\i386\query.dll + 2008-04-14 02:20:37 76,800 ------w c:\windows\ServicePackFiles\i386\qutil.dll + 2008-04-14 02:20:37 43,520 ------w c:\windows\ServicePackFiles\i386\racpldlg.dll + 2008-04-13 18:41:23 20,736 ------w c:\windows\ServicePackFiles\i386\ramdisk.sys + 2008-04-14 02:20:37 7,680 ------w c:\windows\ServicePackFiles\i386\rasadhlp.dll + 2008-04-14 02:20:37 237,056 ------w c:\windows\ServicePackFiles\i386\rasapi32.dll + 2008-04-14 02:20:37 88,576 ------w c:\windows\ServicePackFiles\i386\rasauto.dll + 2008-04-14 02:20:38 79,872 ------w c:\windows\ServicePackFiles\i386\raschap.dll + 2008-04-14 02:20:38 673,280 ------w c:\windows\ServicePackFiles\i386\rasdlg.dll + 2008-04-13 19:19:43 51,328 ------w c:\windows\ServicePackFiles\i386\rasl2tp.sys + 2008-04-14 02:20:38 61,440 ------w c:\windows\ServicePackFiles\i386\rasman.dll + 2008-04-14 02:20:38 186,368 ------w c:\windows\ServicePackFiles\i386\rasmans.dll + 2008-04-14 02:21:15 57,344 ------w c:\windows\ServicePackFiles\i386\rasphone.exe + 2008-04-14 02:20:38 210,944 ------w c:\windows\ServicePackFiles\i386\rasppp.dll + 2008-04-13 18:57:32 41,472 ------w c:\windows\ServicePackFiles\i386\raspppoe.sys + 2008-04-13 19:19:48 48,384 ------w c:\windows\ServicePackFiles\i386\raspptp.sys + 2008-04-14 02:20:38 61,952 ------w c:\windows\ServicePackFiles\i386\rasqec.dll + 2008-04-14 02:20:38 16,384 ------w c:\windows\ServicePackFiles\i386\rassapi.dll + 2008-04-14 02:20:38 58,368 ------w c:\windows\ServicePackFiles\i386\rastapi.dll + 2008-04-14 02:20:38 150,528 ------w c:\windows\ServicePackFiles\i386\rastls.dll + 2008-04-14 02:20:38 102,912 ------w c:\windows\ServicePackFiles\i386\rcbdyctl.dll + 2008-04-14 02:21:15 35,840 ------w c:\windows\ServicePackFiles\i386\rcimlby.exe + 2008-04-14 02:21:15 23,040 ------w c:\windows\ServicePackFiles\i386\rcp.exe + 2008-04-13 19:28:39 175,744 ------w c:\windows\ServicePackFiles\i386\rdbss.sys + 2008-04-14 02:20:38 147,968 ------w c:\windows\ServicePackFiles\i386\rdchost.dll + 2008-04-14 02:21:16 62,976 ------w c:\windows\ServicePackFiles\i386\rdpclip.exe + 2008-04-14 02:21:50 92,424 ------w c:\windows\ServicePackFiles\i386\rdpdd.dll + 2008-04-13 18:32:51 196,224 ------w c:\windows\ServicePackFiles\i386\rdpdr.sys + 2008-04-14 02:20:38 19,968 ------w c:\windows\ServicePackFiles\i386\rdpsnd.dll + 2008-04-14 02:21:50 139,656 ------w c:\windows\ServicePackFiles\i386\rdpwd.sys + 2008-04-14 02:21:51 87,176 ------w c:\windows\ServicePackFiles\i386\rdpwsx.dll + 2008-04-14 02:21:16 13,824 ------w c:\windows\ServicePackFiles\i386\rdsaddin.exe + 2008-04-14 02:21:16 67,072 ------w c:\windows\ServicePackFiles\i386\rdshost.exe + 2004-08-04 00:41:40 13,776 ------w c:\windows\ServicePackFiles\i386\recagent.sys + 2008-04-14 01:53:17 58,240 ------w c:\windows\ServicePackFiles\i386\redbook.sys + 2004-08-04 01:48:46 3,346 ------w c:\windows\ServicePackFiles\i386\redir.exe + 2008-04-14 02:21:16 51,200 ------w c:\windows\ServicePackFiles\i386\reg.exe + 2008-04-14 02:20:38 49,664 ------w c:\windows\ServicePackFiles\i386\regapi.dll + 2007-06-27 12:57:33 28,672 ------w c:\windows\ServicePackFiles\i386\regasm.exe + 2007-06-27 12:57:36 32,768 ------w c:\windows\ServicePackFiles\i386\regcode.dll + 2008-04-14 02:21:16 150,528 ------w c:\windows\ServicePackFiles\i386\regedit.exe + 2008-04-14 02:20:38 59,904 ------w c:\windows\ServicePackFiles\i386\regsvc.dll + 2007-06-27 12:57:41 11,264 ------w c:\windows\ServicePackFiles\i386\regsvcs.exe + 2008-04-14 02:21:16 11,776 ------w c:\windows\ServicePackFiles\i386\regsvr32.exe + 2008-04-14 02:20:38 399,360 ------w c:\windows\ServicePackFiles\i386\regwizc.dll + 2008-04-14 02:20:39 61,440 ------w c:\windows\ServicePackFiles\i386\remotepg.dll + 2008-04-14 02:20:39 178,176 ------w c:\windows\ServicePackFiles\i386\repdrvfs.dll + 2008-04-14 02:20:39 58,880 ------w c:\windows\ServicePackFiles\i386\resutils.dll + 2008-04-14 02:21:16 14,848 ------w c:\windows\ServicePackFiles\i386\rexec.exe + 2008-04-13 18:46:32 59,136 ------w c:\windows\ServicePackFiles\i386\rfcomm.sys + 2008-04-14 02:20:39 290,304 ------w c:\windows\ServicePackFiles\i386\rhttpaa.dll + 2008-04-14 02:20:39 124,416 ------w c:\windows\ServicePackFiles\i386\riafres.dll + 2008-04-14 02:20:39 12,288 ------w c:\windows\ServicePackFiles\i386\riafui1.dll + 2008-04-14 02:20:39 12,288 ------w c:\windows\ServicePackFiles\i386\riafui2.dll + 2008-04-14 02:20:39 433,664 ------w c:\windows\ServicePackFiles\i386\riched20.dll + 2008-04-13 18:55:08 202,624 ------w c:\windows\ServicePackFiles\i386\rmcast.sys + 2008-04-13 18:56:49 30,592 ------w c:\windows\ServicePackFiles\i386\rndismp.sys + 2008-04-13 18:56:49 30,592 ------w c:\windows\ServicePackFiles\i386\rndismpx.sys + 2008-04-14 01:54:05 79,360 ------w c:\windows\ServicePackFiles\i386\rocket.sys + 2008-04-14 02:20:39 4,096 ------w c:\windows\ServicePackFiles\i386\rpcref.dll + 2008-04-14 02:20:39 584,704 ------w c:\windows\ServicePackFiles\i386\rpcrt4.dll + 2008-04-14 02:20:39 399,360 ------w c:\windows\ServicePackFiles\i386\rpcss.dll + 2008-04-14 02:20:39 61,440 ------w c:\windows\ServicePackFiles\i386\rrcm.dll + 2008-04-13 17:37:57 208,384 ------w c:\windows\ServicePackFiles\i386\rsaenh.dll + 2008-04-14 02:21:16 15,872 ------w c:\windows\ServicePackFiles\i386\rsh.exe + 2008-04-14 02:20:39 39,936 ------w c:\windows\ServicePackFiles\i386\rshx32.dll + 2008-04-14 02:20:39 18,944 ------w c:\windows\ServicePackFiles\i386\rsmps.dll + 2008-04-14 02:21:16 107,520 ------w c:\windows\ServicePackFiles\i386\rsnotify.exe + 2008-04-14 02:21:17 382,976 ------w c:\windows\ServicePackFiles\i386\rstrui.exe + 2008-04-14 02:20:39 92,672 ------w c:\windows\ServicePackFiles\i386\rsvpsp.dll + 2008-04-14 02:21:17 78,336 ------w c:\windows\ServicePackFiles\i386\rtcshare.exe + 2008-04-14 02:20:39 31,744 ------w c:\windows\ServicePackFiles\i386\rtipxmib.dll + 2004-08-04 00:31:34 20,992 ------w c:\windows\ServicePackFiles\i386\rtl8139.sys + 2008-04-14 02:20:39 44,032 ------w c:\windows\ServicePackFiles\i386\rtutils.dll + 2008-04-14 02:21:17 33,280 ------w c:\windows\ServicePackFiles\i386\rundll32.exe + 2008-04-14 02:21:17 14,336 ------w c:\windows\ServicePackFiles\i386\runonce.exe + 2008-04-14 02:20:39 28,160 ------w c:\windows\ServicePackFiles\i386\rw001ext.dll + 2008-04-14 02:20:39 29,184 ------w c:\windows\ServicePackFiles\i386\rw330ext.dll + 2008-04-14 02:20:39 28,160 ------w c:\windows\ServicePackFiles\i386\rw430ext.dll + 2008-04-14 02:20:39 29,696 ------w c:\windows\ServicePackFiles\i386\rw450ext.dll + 2008-04-14 02:20:39 9,728 ------w c:\windows\ServicePackFiles\i386\rwnh.dll + 2008-04-14 02:20:39 397,056 ------w c:\windows\ServicePackFiles\i386\s3gnb.dll + 2004-08-04 00:29:52 166,912 ------w c:\windows\ServicePackFiles\i386\s3gnbm.sys + 2008-04-14 02:20:39 43,520 ------w c:\windows\ServicePackFiles\i386\safrcdlg.dll + 2008-04-14 02:20:39 29,696 ------w c:\windows\ServicePackFiles\i386\safrdm.dll + 2008-04-14 02:20:39 45,568 ------w c:\windows\ServicePackFiles\i386\safrslv.dll + 2008-04-14 02:20:39 64,000 ------w c:\windows\ServicePackFiles\i386\samlib.dll + 2008-04-14 02:20:40 428,032 ------w c:\windows\ServicePackFiles\i386\samsrv.dll + 2008-04-14 02:20:40 741,376 ------w c:\windows\ServicePackFiles\i386\sapi.dll + 2008-04-14 02:21:17 13,824 ------w c:\windows\ServicePackFiles\i386\savedump.exe + 2008-04-14 02:20:40 270,848 ------w c:\windows\ServicePackFiles\i386\sbe.dll + 2008-04-14 02:20:40 159,232 ------w c:\windows\ServicePackFiles\i386\sbeio.dll + 2008-04-13 18:40:48 43,904 ------w c:\windows\ServicePackFiles\i386\sbp2port.sys + 2008-04-14 02:20:40 69,632 ------w c:\windows\ServicePackFiles\i386\scarddlg.dll + 2008-04-14 02:21:17 99,328 ------w c:\windows\ServicePackFiles\i386\scardsvr.exe + 2004-08-04 01:31:44 169,984 ------w c:\windows\ServicePackFiles\i386\sccbase.dll + 2008-04-14 02:20:40 171,008 ------w c:\windows\ServicePackFiles\i386\sccsccp.dll + 2008-04-14 02:20:40 184,832 ------w c:\windows\ServicePackFiles\i386\scecli.dll + 2008-04-14 02:20:40 320,512 ------w c:\windows\ServicePackFiles\i386\scesrv.dll + 2008-04-14 02:20:40 144,384 ------w c:\windows\ServicePackFiles\i386\schannel.dll + 2008-04-14 02:20:40 193,536 ------w c:\windows\ServicePackFiles\i386\schedsvc.dll + 2008-04-14 02:20:40 21,504 ------w c:\windows\ServicePackFiles\i386\sclgntfy.dll + 2008-04-14 02:21:17 36,352 ------w c:\windows\ServicePackFiles\i386\scrcons.exe + 2008-04-14 02:20:40 216,576 ------w c:\windows\ServicePackFiles\i386\script.dll + 2008-04-14 02:20:40 199,680 ------w c:\windows\ServicePackFiles\i386\scripta.dll + 2008-04-14 02:21:26 9,216 ------w c:\windows\ServicePackFiles\i386\scrnsave.scr + 2008-04-14 02:20:40 180,224 ------w c:\windows\ServicePackFiles\i386\scrobj.dll + 2008-04-14 02:20:40 172,032 ------w c:\windows\ServicePackFiles\i386\scrrun.dll + 2008-04-13 18:40:30 96,384 ------w c:\windows\ServicePackFiles\i386\scsiport.sys + 2008-04-13 18:45:33 11,520 ------w c:\windows\ServicePackFiles\i386\scsiscan.sys + 2008-04-14 02:21:17 126,976 ------w c:\windows\ServicePackFiles\i386\sctasks.exe + 2008-04-14 02:21:17 77,824 ------w c:\windows\ServicePackFiles\i386\sdbinst.exe + 2008-04-13 18:36:44 79,232 ------w c:\windows\ServicePackFiles\i386\sdbus.sys + 2008-04-14 02:20:40 29,184 ------w c:\windows\ServicePackFiles\i386\sdhcinst.dll + 2007-11-13 10:25:56 20,480 ------w c:\windows\ServicePackFiles\i386\secdrv.sys + 2008-04-14 02:21:17 19,456 ------w c:\windows\ServicePackFiles\i386\secedit.exe + 2008-04-14 02:20:40 18,944 ------w c:\windows\ServicePackFiles\i386\seclogon.dll + 2006-12-30 21:27:08 4,569 ------w c:\windows\ServicePackFiles\i386\secupd.dat + 2008-04-14 02:20:40 56,320 ------w c:\windows\ServicePackFiles\i386\secur32.dll + 2008-04-14 02:20:40 5,632 ------w c:\windows\ServicePackFiles\i386\security.dll + 2008-04-14 02:20:40 29,696 ------w c:\windows\ServicePackFiles\i386\sendcmsg.dll + 2008-04-14 02:20:40 55,296 ------w c:\windows\ServicePackFiles\i386\sendmail.dll + 2008-04-14 02:20:40 39,424 ------w c:\windows\ServicePackFiles\i386\sens.dll + 2008-04-14 02:20:40 7,168 ------w c:\windows\ServicePackFiles\i386\sensapi.dll + 2008-04-14 02:20:40 221,696 ------w c:\windows\ServicePackFiles\i386\seo.dll + 2008-04-13 18:40:12 15,744 ------w c:\windows\ServicePackFiles\i386\serenum.sys + 2008-04-14 01:55:20 65,536 ------w c:\windows\ServicePackFiles\i386\serial.sys + 2008-04-14 02:20:40 56,320 ------w c:\windows\ServicePackFiles\i386\servdeps.dll + 2008-04-14 02:21:17 109,056 ------w c:\windows\ServicePackFiles\i386\services.exe + 2008-04-14 02:21:17 142,848 ------w c:\windows\ServicePackFiles\i386\sessmgr.exe + 2008-04-14 02:21:17 32,768 ------w c:\windows\ServicePackFiles\i386\sethc.exe + 2007-12-17 11:59:54 66,592 ------w c:\windows\ServicePackFiles\i386\setregni.exe + 2008-04-14 02:21:17 23,040 ------w c:\windows\ServicePackFiles\i386\setup.exe + 2008-04-14 02:21:17 73,728 ------w c:\windows\ServicePackFiles\i386\setup50.exe + 2008-04-13 21:20:42 995,328 ------w c:\windows\ServicePackFiles\i386\setupapi.dll + 2008-04-14 02:21:18 32,768 ------w c:\windows\ServicePackFiles\i386\setupn.exe + 2008-04-14 02:20:40 101,888 ------w c:\windows\ServicePackFiles\i386\setupqry.dll + 2008-04-14 02:20:40 5,120 ------w c:\windows\ServicePackFiles\i386\sfc.dll + 2008-04-14 02:20:40 141,312 ------w c:\windows\ServicePackFiles\i386\sfc_os.dll + 2008-04-14 02:20:40 1,571,840 ------w c:\windows\ServicePackFiles\i386\sfcfiles.dll + 2008-04-13 18:40:47 11,904 ------w c:\windows\ServicePackFiles\i386\sffdisk.sys + 2008-04-13 18:40:48 10,240 ------w c:\windows\ServicePackFiles\i386\sffp_mmc.sys + 2008-04-13 18:40:47 11,008 ------w c:\windows\ServicePackFiles\i386\sffp_sd.sys + 2008-04-13 18:40:48 11,392 ------w c:\windows\ServicePackFiles\i386\sfloppy.sys + 2008-04-14 01:55:59 563,712 ------w c:\windows\ServicePackFiles\i386\shdoclc.dll + 2008-04-14 02:20:40 1,499,136 ------w c:\windows\ServicePackFiles\i386\shdocvw.dll + 2008-04-14 02:20:40 8,491,008 ------w c:\windows\ServicePackFiles\i386\shell32.dll + 2008-04-14 02:20:40 25,088 ------w c:\windows\ServicePackFiles\i386\shfolder.dll + 2008-04-14 02:20:40 68,096 ------w c:\windows\ServicePackFiles\i386\shgina.dll + 2008-04-14 02:20:40 65,024 ------w c:\windows\ServicePackFiles\i386\shimeng.dll + 2008-04-14 02:20:40 439,296 ------w c:\windows\ServicePackFiles\i386\shimgvw.dll + 2008-04-14 02:20:40 474,112 ------w c:\windows\ServicePackFiles\i386\shlwapi.dll + 2008-04-14 02:21:18 45,056 ------w c:\windows\ServicePackFiles\i386\shmgrate.exe + 2008-04-14 02:21:18 78,336 ------w c:\windows\ServicePackFiles\i386\shrpubw.exe + 2008-04-14 02:20:40 27,648 ------w c:\windows\ServicePackFiles\i386\shscrap.dll + 2008-04-14 02:20:40 135,168 ------w c:\windows\ServicePackFiles\i386\shsvcs.dll + 2008-04-14 02:20:40 20,536 ------w c:\windows\ServicePackFiles\i386\shtml.dll + 2008-04-14 02:21:18 16,437 ------w c:\windows\ServicePackFiles\i386\shtml.exe + 2008-04-14 02:21:18 20,480 ------w c:\windows\ServicePackFiles\i386\shutdown.exe + 2008-04-14 02:20:40 13,824 ------w c:\windows\ServicePackFiles\i386\sigtab.dll + 2008-04-14 02:21:18 71,168 ------w c:\windows\ServicePackFiles\i386\sigverif.exe + 2008-04-14 02:20:40 3,901 ------w c:\windows\ServicePackFiles\i386\siint5.dll + 2008-04-13 18:36:39 40,960 ------w c:\windows\ServicePackFiles\i386\sisagp.sys + 2004-08-04 00:31:36 32,768 ------w c:\windows\ServicePackFiles\i386\sisnic.sys + 2008-04-14 02:21:18 26,112 ------w c:\windows\ServicePackFiles\i386\skeys.exe + 2004-08-04 00:31:42 63,547 ------w c:\windows\ServicePackFiles\i386\sla30nd5.sys + 2008-04-14 02:20:40 25,600 ------w c:\windows\ServicePackFiles\i386\slayerxp.dll + 2004-08-04 01:31:44 306,176 ------w c:\windows\ServicePackFiles\i386\slbcsp.dll + 2008-04-14 02:20:40 98,304 ------w c:\windows\ServicePackFiles\i386\slbiop.dll + 2008-04-14 02:20:40 73,832 ------w c:\windows\ServicePackFiles\i386\slcoinst.dll + 2008-04-14 02:20:40 286,792 ------w c:\windows\ServicePackFiles\i386\slextspk.dll + 2008-04-14 02:20:40 188,508 ------w c:\windows\ServicePackFiles\i386\slgen.dll + 2008-04-13 18:46:23 11,136 ------w c:\windows\ServicePackFiles\i386\slip.sys + 2004-08-04 00:41:42 129,535 ------w c:\windows\ServicePackFiles\i386\slnt7554.sys + 2004-08-04 00:41:44 404,990 ------w c:\windows\ServicePackFiles\i386\slntamr.sys + 2004-08-04 00:41:46 95,424 ------w c:\windows\ServicePackFiles\i386\slnthal.sys + 2008-04-14 02:21:18 32,866 ------w c:\windows\ServicePackFiles\i386\slrundll.exe + 2008-04-14 02:21:18 73,796 ------w c:\windows\ServicePackFiles\i386\slserv.exe + 2004-08-04 00:41:46 13,240 ------w c:\windows\ServicePackFiles\i386\slwdmsup.sys + 2008-04-13 18:36:34 5,888 ------w c:\windows\ServicePackFiles\i386\smbali.sys + 2008-04-13 18:36:33 16,000 ------w c:\windows\ServicePackFiles\i386\smbbatt.sys + 2008-04-13 18:36:33 6,912 ------w c:\windows\ServicePackFiles\i386\smbclass.sys + 2008-04-14 02:21:18 8,192 ------w c:\windows\ServicePackFiles\i386\smbinst.exe + 2008-04-14 02:21:18 236,544 ------w c:\windows\ServicePackFiles\i386\smi2smir.exe + 2008-04-14 02:20:40 366,592 ------w c:\windows\ServicePackFiles\i386\smlogcfg.dll + 2008-04-14 02:21:18 90,624 ------w c:\windows\ServicePackFiles\i386\smlogsvc.exe + 2008-04-14 02:21:19 50,688 ------w c:\windows\ServicePackFiles\i386\smss.exe + 2008-04-14 02:20:40 189,952 ------w c:\windows\ServicePackFiles\i386\smtpadm.dll + 2008-04-14 02:20:40 10,752 ------w c:\windows\ServicePackFiles\i386\smtpapi.dll + 2008-04-14 02:20:40 2,134,528 ------w c:\windows\ServicePackFiles\i386\smtpsnap.dll + 2008-04-14 02:20:40 463,360 ------w c:\windows\ServicePackFiles\i386\smtpsvc.dll + 2008-04-14 02:21:19 132,608 ------w c:\windows\ServicePackFiles\i386\sndrec32.exe + 2008-04-14 02:20:40 34,816 ------w c:\windows\ServicePackFiles\i386\sniffpol.dll + 2008-04-14 02:21:19 33,280 ------w c:\windows\ServicePackFiles\i386\snmp.exe + 2008-04-14 02:20:40 18,944 ------w c:\windows\ServicePackFiles\i386\snmpapi.dll + 2008-04-14 02:20:40 259,072 ------w c:\windows\ServicePackFiles\i386\snmpcl.dll + 2008-04-14 02:20:40 358,400 ------w c:\windows\ServicePackFiles\i386\snmpincl.dll + 2008-04-14 02:20:40 6,144 ------w c:\windows\ServicePackFiles\i386\snmpmib.dll + 2008-04-14 02:20:40 188,416 ------w c:\windows\ServicePackFiles\i386\snmpsmir.dll + 2008-04-14 02:20:40 183,296 ------w c:\windows\ServicePackFiles\i386\snmpsnap.dll + 2008-04-14 02:20:40 39,936 ------w c:\windows\ServicePackFiles\i386\snmpthrd.dll + 2008-04-14 02:21:19 8,704 ------w c:\windows\ServicePackFiles\i386\snmptrap.exe + 2008-04-14 02:20:40 130,048 ------w c:\windows\ServicePackFiles\i386\softkbd.dll + 2008-04-13 18:40:52 7,552 ------w c:\windows\ServicePackFiles\i386\sonyait.sys + 2008-04-13 18:46:07 25,344 ------w c:\windows\ServicePackFiles\i386\sonydcam.sys + 2008-04-14 02:21:19 25,600 ------w c:\windows\ServicePackFiles\i386\sort.exe + 2008-04-14 02:21:19 7,680 ------w c:\windows\ServicePackFiles\i386\spdwnwxp.exe + 2008-04-13 16:43:18 62,976 ------w c:\windows\ServicePackFiles\i386\spgrmr.dll + 2008-04-14 02:21:19 539,136 ------w c:\windows\ServicePackFiles\i386\spider.exe + 2008-04-13 18:43:31 12,800 ------w c:\windows\ServicePackFiles\i386\spiisupd.exe + 2008-04-13 18:45:07 6,272 ------w c:\windows\ServicePackFiles\i386\splitter.sys + 2008-04-13 21:21:20 11,264 ------w c:\windows\ServicePackFiles\i386\spnpinst.exe + 2008-04-14 02:20:40 75,264 ------w c:\windows\ServicePackFiles\i386\spoolss.dll + 2008-04-14 02:21:19 57,856 ------w c:\windows\ServicePackFiles\i386\spoolsv.exe + 2008-04-13 18:35:08 192,512 ------w c:\windows\ServicePackFiles\i386\sprs0416.dll + 2008-04-13 18:35:38 2,945,536 ------w c:\windows\ServicePackFiles\i386\sprt0416.dll + 2008-04-13 18:38:54 736,256 ------w c:\windows\ServicePackFiles\i386\spru0416.dll + 2008-04-14 02:20:40 271,872 ------w c:\windows\ServicePackFiles\i386\sptip.dll + 2008-04-14 02:21:19 20,992 ------w c:\windows\ServicePackFiles\i386\spupdwxp.exe + 2008-04-14 02:20:40 151,552 ------w c:\windows\ServicePackFiles\i386\sqldb20.dll + 2008-04-14 02:20:40 528,384 ------w c:\windows\ServicePackFiles\i386\sqloledb.dll + 2008-04-14 02:20:40 462,848 ------w c:\windows\ServicePackFiles\i386\sqlqp20.dll + 2008-04-14 02:20:40 110,592 ------w c:\windows\ServicePackFiles\i386\sqlse20.dll + 2008-04-14 02:20:40 442,368 ------w c:\windows\ServicePackFiles\i386\sqlsrv32.dll + 2008-04-14 02:20:40 180,800 ------w c:\windows\ServicePackFiles\i386\sqlunirl.dll + 2008-04-14 02:20:40 217,088 ------w c:\windows\ServicePackFiles\i386\sqlxmlx.dll + 2008-04-14 02:02:36 73,472 ------w c:\windows\ServicePackFiles\i386\sr.sys + 2008-04-14 02:20:40 58,434 ------w c:\windows\ServicePackFiles\i386\srchctls.dll + 2008-04-14 02:20:40 727,102 ------w c:\windows\ServicePackFiles\i386\srchui.dll + 2008-04-14 02:20:40 67,584 ------w c:\windows\ServicePackFiles\i386\srclient.dll + 2008-04-14 02:20:40 240,640 ------w c:\windows\ServicePackFiles\i386\srrstr.dll + 2008-04-14 02:20:40 171,520 ------w c:\windows\ServicePackFiles\i386\srsvc.dll + 2008-04-13 19:15:11 334,848 ------w c:\windows\ServicePackFiles\i386\srv.sys + 2008-04-14 02:20:40 96,768 ------w c:\windows\ServicePackFiles\i386\srvsvc.dll + 2008-04-14 02:21:26 708,608 ------w c:\windows\ServicePackFiles\i386\ss3dfo.scr + 2008-04-14 02:21:26 19,968 ------w c:\windows\ServicePackFiles\i386\ssbezier.scr + 2008-04-14 02:20:40 34,816 ------w c:\windows\ServicePackFiles\i386\ssdpapi.dll + 2008-04-14 02:20:40 71,680 ------w c:\windows\ServicePackFiles\i386\ssdpsrv.dll + 2008-04-14 02:21:26 393,216 ------w c:\windows\ServicePackFiles\i386\ssflwbox.scr + 2008-04-14 02:20:40 45,056 ------w c:\windows\ServicePackFiles\i386\ssinc51.dll + 2008-04-14 02:21:26 20,992 ------w c:\windows\ServicePackFiles\i386\ssmarque.scr + 2008-04-14 02:21:26 47,104 ------w c:\windows\ServicePackFiles\i386\ssmypics.scr + 2008-04-14 02:21:27 18,944 ------w c:\windows\ServicePackFiles\i386\ssmyst.scr + 2008-04-14 02:20:40 46,592 ------w c:\windows\ServicePackFiles\i386\sspifilt.dll + 2008-04-14 02:21:27 610,304 ------w c:\windows\ServicePackFiles\i386\sspipes.scr + 2008-04-14 02:21:27 14,336 ------w c:\windows\ServicePackFiles\i386\ssstars.scr + 2008-04-14 02:21:27 684,032 ------w c:\windows\ServicePackFiles\i386\sstext3d.scr + 2008-04-14 02:20:40 33,280 ------w c:\windows\ServicePackFiles\i386\sstub.dll + 2008-04-14 02:20:40 8,192 ------w c:\windows\ServicePackFiles\i386\staxmem.dll + 2008-04-14 02:20:40 59,392 ------w c:\windows\ServicePackFiles\i386\stclient.dll + 2008-04-14 02:20:40 86,528 ------w c:\windows\ServicePackFiles\i386\stdprov.dll + 2008-04-14 02:20:40 68,608 ------w c:\windows\ServicePackFiles\i386\sti.dll + 2008-04-14 02:20:40 137,216 ------w c:\windows\ServicePackFiles\i386\sti_ci.dll + 2008-04-14 02:21:19 14,848 ------w c:\windows\ServicePackFiles\i386\stimon.exe + 2008-04-14 02:20:40 122,368 ------w c:\windows\ServicePackFiles\i386\stobject.dll + 2008-04-14 02:20:40 75,776 ------w c:\windows\ServicePackFiles\i386\storprop.dll + 2008-04-13 18:45:15 49,408 ------w c:\windows\ServicePackFiles\i386\stream.sys + 2008-04-13 18:46:21 15,232 ------w c:\windows\ServicePackFiles\i386\streamip.sys + 2008-04-14 02:20:40 75,776 ------w c:\windows\ServicePackFiles\i386\strmfilt.dll + 2008-04-14 02:21:20 16,449 ------w c:\windows\ServicePackFiles\i386\stub_fpsrvadm.exe + 2008-04-14 02:21:20 65,601 ------w c:\windows\ServicePackFiles\i386\stub_fpsrvwin.exe + 2008-04-14 02:20:40 46,592 ------w c:\windows\ServicePackFiles\i386\svcext51.dll + 2008-04-14 02:21:20 14,336 ------w c:\windows\ServicePackFiles\i386\svchost.exe + 2008-04-13 18:39:53 4,352 ------w c:\windows\ServicePackFiles\i386\swenum.sys + 2008-04-13 18:45:09 56,576 ------w c:\windows\ServicePackFiles\i386\swmidi.sys + 2008-04-14 02:20:40 714,752 ------w c:\windows\ServicePackFiles\i386\sxs.dll + 2007-12-17 11:59:56 1,179,648 ------w c:\windows\ServicePackFiles\i386\sy52106.dll + 2008-04-14 02:20:40 57,856 ------w c:\windows\ServicePackFiles\i386\synceng.dll + 2008-04-14 02:20:40 194,560 ------w c:\windows\ServicePackFiles\i386\syncui.dll + 2008-04-13 19:15:55 60,800 ------w c:\windows\ServicePackFiles\i386\sysaudio.sys + 2008-04-14 02:21:20 73,216 ------w c:\windows\ServicePackFiles\i386\sysinfo.exe + 2008-04-14 02:20:40 193,536 ------w c:\windows\ServicePackFiles\i386\sysmod.dll + 2008-04-14 02:20:40 173,568 ------w c:\windows\ServicePackFiles\i386\sysmoda.dll + 2008-04-14 02:21:20 107,008 ------w c:\windows\ServicePackFiles\i386\sysocmgr.exe + 2008-04-14 02:20:40 1,003,008 ------w c:\windows\ServicePackFiles\i386\syssetup.dll + 2007-06-27 12:57:55 77,824 ------w c:\windows\ServicePackFiles\i386\system.configuration.install.dll + 2007-06-27 12:58:00 1,179,648 ------w c:\windows\ServicePackFiles\i386\system.data.dll + 2007-06-27 12:58:10 1,695,744 ------w c:\windows\ServicePackFiles\i386\system.design.dll + 2007-06-27 12:58:18 86,016 ------w c:\windows\ServicePackFiles\i386\system.directoryservices.dll + 2007-06-27 12:58:21 65,536 ------w c:\windows\ServicePackFiles\i386\system.drawing.design.dll + 2007-06-27 12:58:26 462,848 ------w c:\windows\ServicePackFiles\i386\system.drawing.dll + 2007-06-27 12:58:31 212,992 ------w c:\windows\ServicePackFiles\i386\system.enterpriseservices.dll + 2008-04-13 16:11:22 48,640 ------w c:\windows\ServicePackFiles\i386\system.enterpriseservices.thunk.dll + 2007-06-27 12:58:39 352,256 ------w c:\windows\ServicePackFiles\i386\system.management.dll + 2007-06-27 12:58:43 241,664 ------w c:\windows\ServicePackFiles\i386\system.messaging.dll + 2007-06-27 12:58:55 311,296 ------w c:\windows\ServicePackFiles\i386\system.runtime.remoting.dll + 2007-06-27 12:59:02 131,072 ------w c:\windows\ServicePackFiles\i386\system.runtime.serialization.formatters.soap.dll + 2007-06-27 12:59:05 77,824 ------w c:\windows\ServicePackFiles\i386\system.security.dll + 2007-06-27 12:59:10 126,976 ------w c:\windows\ServicePackFiles\i386\system.serviceprocess.dll + 2007-12-17 12:00:01 1,200,128 ------w c:\windows\ServicePackFiles\i386\system.web.dll + 2007-06-27 12:59:21 61,440 ------w c:\windows\ServicePackFiles\i386\system.web.regularexpressions.dll + 2007-06-27 12:59:25 507,904 ------w c:\windows\ServicePackFiles\i386\system.web.services.dll + 2007-06-27 12:59:34 2,002,944 ------w c:\windows\ServicePackFiles\i386\system.windows.forms.dll + 2007-06-27 12:59:48 1,302,528 ------w c:\windows\ServicePackFiles\i386\system.xml.dll + 2008-04-14 02:20:40 117,760 ------w c:\windows\ServicePackFiles\i386\t2embed.dll + 2008-04-14 02:20:40 34,304 ------w c:\windows\ServicePackFiles\i386\tabletoc.dll + 2008-04-13 18:40:50 14,976 ------w c:\windows\ServicePackFiles\i386\tape.sys + 2008-04-14 02:20:40 859,648 ------w c:\windows\ServicePackFiles\i386\tapi3.dll + 2008-04-14 02:20:40 181,760 ------w c:\windows\ServicePackFiles\i386\tapi32.dll + 2008-04-14 02:20:40 249,856 ------w c:\windows\ServicePackFiles\i386\tapisrv.dll + 2008-04-14 02:21:20 77,824 ------w c:\windows\ServicePackFiles\i386\taskkill.exe + 2008-04-14 02:21:20 78,848 ------w c:\windows\ServicePackFiles\i386\tasklist.exe + 2008-04-14 02:21:20 141,312 ------w c:\windows\ServicePackFiles\i386\taskmgr.exe + 2008-04-13 19:20:16 361,344 ------w c:\windows\ServicePackFiles\i386\tcpip.sys + 2008-04-13 19:00:02 225,664 ------w c:\windows\ServicePackFiles\i386\tcpip6.sys + 2008-04-14 02:20:40 14,848 ------w c:\windows\ServicePackFiles\i386\tcpmib.dll + 2008-04-14 02:20:40 46,080 ------w c:\windows\ServicePackFiles\i386\tcpmon.dll + 2008-04-14 02:20:40 46,592 ------w c:\windows\ServicePackFiles\i386\tcpmonui.dll + 2008-04-14 02:21:20 32,827 ------w c:\windows\ServicePackFiles\i386\tcptest.exe + 2003-04-14 23:54:06 16,384 ------w c:\windows\ServicePackFiles\i386\tcptsat.dll + 2008-04-13 19:00:05 19,072 ------w c:\windows\ServicePackFiles\i386\tdi.sys + 2008-04-14 02:21:49 12,040 ------w c:\windows\ServicePackFiles\i386\tdpipe.sys + 2008-04-14 02:21:49 21,896 ------w c:\windows\ServicePackFiles\i386\tdtcp.sys + 2008-04-14 02:21:20 77,312 ------w c:\windows\ServicePackFiles\i386\telnet.exe + 2008-04-14 02:21:48 40,840 ------w c:\windows\ServicePackFiles\i386\termdd.sys + 2008-04-14 02:20:40 358,912 ------w c:\windows\ServicePackFiles\i386\termmgr.dll + 2008-04-14 02:20:40 296,960 ------w c:\windows\ServicePackFiles\i386\termsrv.dll + 2008-04-13 18:40:50 149,376 ------w c:\windows\ServicePackFiles\i386\tffsport.sys + 2008-04-14 02:20:40 388,608 ------w c:\windows\ServicePackFiles\i386\themeui.dll + 2008-04-14 02:21:20 62,976 ------w c:\windows\ServicePackFiles\i386\tlntadmn.exe + 2008-04-14 02:21:20 78,848 ------w c:\windows\ServicePackFiles\i386\tlntsess.exe + 2008-04-14 02:21:21 73,728 ------w c:\windows\ServicePackFiles\i386\tlntsvr.exe + 2008-04-14 02:20:40 7,168 ------w c:\windows\ServicePackFiles\i386\tlntsvrp.dll + 2007-12-17 12:00:05 66,592 ------w c:\windows\ServicePackFiles\i386\togac.exe + 2008-04-14 02:20:40 33,792 ------w c:\windows\ServicePackFiles\i386\tools.dll + 2008-04-14 02:21:21 347,136 ------w c:\windows\ServicePackFiles\i386\tourstrt.exe + 2008-04-14 02:21:21 82,944 ------w c:\windows\ServicePackFiles\i386\tp4mon.exe + 2008-04-14 02:21:21 260,096 ------w c:\windows\ServicePackFiles\i386\tracerpt.exe + 2008-04-14 02:21:21 12,800 ------w c:\windows\ServicePackFiles\i386\tracert.exe + 2008-04-14 02:21:25 12,800 ------w c:\windows\ServicePackFiles\i386\tree.com + 2008-04-14 02:20:40 153,088 ------w c:\windows\ServicePackFiles\i386\triedit.dll + 2008-04-14 02:20:40 90,112 ------w c:\windows\ServicePackFiles\i386\trkwks.dll + 2008-01-18 15:13:09 2,247 ------w c:\windows\ServicePackFiles\i386\tscdsbl.bat + 2008-04-14 02:20:40 93,696 ------w c:\windows\ServicePackFiles\i386\tscfgwmi.dll + 2007-12-12 10:33:51 18,917 ------w c:\windows\ServicePackFiles\i386\tscinst.vbs + 2007-10-30 10:06:46 13,801 ------w c:\windows\ServicePackFiles\i386\tscuinst.vbs + 2008-04-14 02:20:11 25,600 ------w c:\windows\ServicePackFiles\i386\tscupdc.dll + 2008-04-14 02:21:50 12,168 ------w c:\windows\ServicePackFiles\i386\tsddd.dll + 2008-04-14 02:20:40 53,248 ------w c:\windows\ServicePackFiles\i386\tsgqec.dll + 2008-04-14 02:20:40 279,040 ------w c:\windows\ServicePackFiles\i386\tshoot.dll + 2008-04-14 02:20:40 131,584 ------w c:\windows\ServicePackFiles\i386\tsoc.dll + 2008-04-14 02:20:40 50,688 ------w c:\windows\ServicePackFiles\i386\tspkg.dll + 2008-04-14 02:20:40 8,704 ------w c:\windows\ServicePackFiles\i386\tty.dll + 2008-04-14 01:51:20 39,936 ------w c:\windows\ServicePackFiles\i386\ttyres.dll + 2008-04-14 02:20:40 16,384 ------w c:\windows\ServicePackFiles\i386\ttyui.dll + 2008-04-13 18:56:01 12,288 ------w c:\windows\ServicePackFiles\i386\tunmp.sys + 2008-04-14 02:20:40 50,688 ------w c:\windows\ServicePackFiles\i386\twain_32.dll + 2008-04-14 02:20:40 57,856 ------w c:\windows\ServicePackFiles\i386\twext.dll + 2008-04-14 02:20:40 101,376 ------w c:\windows\ServicePackFiles\i386\txflog.dll + 2008-04-14 02:21:21 60,416 ------w c:\windows\ServicePackFiles\i386\tzchange.exe + 2008-04-13 18:36:40 44,672 ------w c:\windows\ServicePackFiles\i386\uagp35.sys + 2008-04-13 18:32:36 66,048 ------w c:\windows\ServicePackFiles\i386\udfs.sys + 2008-04-14 02:20:40 26,624 ------w c:\windows\ServicePackFiles\i386\udhisapi.dll + 2008-04-14 02:20:40 103,936 ------w c:\windows\ServicePackFiles\i386\uihelper.dll + 2008-04-14 02:20:40 303,616 ------w c:\windows\ServicePackFiles\i386\ulib.dll + 2008-04-14 02:20:40 36,864 ------w c:\windows\ServicePackFiles\i386\umandlg.dll + 2008-04-14 02:20:40 124,416 ------w c:\windows\ServicePackFiles\i386\umpnpmgr.dll + 2008-04-14 02:20:40 373,248 ------w c:\windows\ServicePackFiles\i386\unidrv.dll + 2008-04-14 02:20:40 744,448 ------w c:\windows\ServicePackFiles\i386\unidrvui.dll + 2008-04-14 02:20:40 77,824 ------w c:\windows\ServicePackFiles\i386\unimdmat.dll + 2008-04-14 02:20:40 13,824 ------w c:\windows\ServicePackFiles\i386\uniplat.dll + 2007-05-15 08:08:53 761,344 ------w c:\windows\ServicePackFiles\i386\unires.dll + 2008-04-14 02:20:40 316,416 ------w c:\windows\ServicePackFiles\i386\untfs.dll + 2008-04-13 18:39:46 384,768 ------w c:\windows\ServicePackFiles\i386\update.sys + 2008-04-14 02:21:21 151,040 ------w c:\windows\ServicePackFiles\i386\uploadm.exe + 2008-04-14 02:20:40 133,632 ------w c:\windows\ServicePackFiles\i386\upnp.dll + 2008-04-14 02:21:21 16,896 ------w c:\windows\ServicePackFiles\i386\upnpcont.exe + 2008-04-14 02:20:40 186,368 ------w c:\windows\ServicePackFiles\i386\upnphost.dll + 2008-04-14 02:20:40 239,616 ------w c:\windows\ServicePackFiles\i386\upnpui.dll + 2008-04-14 02:21:21 18,432 ------w c:\windows\ServicePackFiles\i386\ups.exe + 2008-04-14 02:20:40 37,888 ------w c:\windows\ServicePackFiles\i386\url.dll + 2008-04-14 02:20:40 620,544 ------w c:\windows\ServicePackFiles\i386\urlmon.dll + 2004-08-04 02:37:02 32,384 ------w c:\windows\ServicePackFiles\i386\usb101et.sys + 2008-04-13 18:56:49 12,800 ------w c:\windows\ServicePackFiles\i386\usb8023.sys + 2008-04-13 18:56:49 12,800 ------w c:\windows\ServicePackFiles\i386\usb8023x.sys + 2008-04-13 18:45:12 60,032 ------w c:\windows\ServicePackFiles\i386\usbaudio.sys + 2008-04-13 18:45:40 25,600 ------w c:\windows\ServicePackFiles\i386\usbcamd.sys + 2008-04-13 18:45:41 25,728 ------w c:\windows\ServicePackFiles\i386\usbcamd2.sys + 2008-04-13 18:45:39 32,128 ------w c:\windows\ServicePackFiles\i386\usbccgp.sys + 2008-04-13 18:45:35 30,208 ------w c:\windows\ServicePackFiles\i386\usbehci.sys + 2008-04-13 18:45:37 59,520 ------w c:\windows\ServicePackFiles\i386\usbhub.sys + 2008-04-13 18:45:43 15,872 ------w c:\windows\ServicePackFiles\i386\usbintel.sys + 2008-04-14 02:20:40 16,896 ------w c:\windows\ServicePackFiles\i386\usbmon.dll + 2008-04-13 18:45:35 17,152 ------w c:\windows\ServicePackFiles\i386\usbohci.sys + 2008-04-13 18:45:36 143,872 ------w c:\windows\ServicePackFiles\i386\usbport.sys + 2008-04-13 18:47:37 25,856 ------w c:\windows\ServicePackFiles\i386\usbprint.sys + 2008-04-13 18:45:34 15,104 ------w c:\windows\ServicePackFiles\i386\usbscan.sys + 2008-04-13 18:45:36 26,112 ------w c:\windows\ServicePackFiles\i386\usbser.sys + 2008-04-13 18:45:38 26,368 ------w c:\windows\ServicePackFiles\i386\usbstor.sys + 2008-04-13 18:45:35 20,608 ------w c:\windows\ServicePackFiles\i386\usbuhci.sys + 2008-04-14 02:20:40 76,288 ------w c:\windows\ServicePackFiles\i386\usbui.dll + 2008-04-13 18:46:20 121,984 ------w c:\windows\ServicePackFiles\i386\usbvideo.sys + 2008-04-14 02:20:40 579,072 ------w c:\windows\ServicePackFiles\i386\user32.dll + 2008-04-14 02:20:40 732,160 ------w c:\windows\ServicePackFiles\i386\userenv.dll + 2008-04-14 02:21:21 26,112 ------w c:\windows\ServicePackFiles\i386\userinit.exe + 2008-04-14 02:20:40 406,016 ------w c:\windows\ServicePackFiles\i386\usp10.dll + 2008-04-14 02:21:22 50,176 ------w c:\windows\ServicePackFiles\i386\utilman.exe + 2008-04-14 02:20:40 219,648 ------w c:\windows\ServicePackFiles\i386\uxtheme.dll + 2008-04-14 02:20:40 30,749 ------w c:\windows\ServicePackFiles\i386\vbajet32.dll + 2007-06-27 12:59:58 716,800 ------w c:\windows\ServicePackFiles\i386\vbc.exe + 2008-04-13 16:11:44 126,976 ------w c:\windows\ServicePackFiles\i386\vbc7ui.chs.dll + 2008-04-13 16:11:45 126,976 ------w c:\windows\ServicePackFiles\i386\vbc7ui.cht.dll + 2008-04-13 16:11:45 126,976 ------w c:\windows\ServicePackFiles\i386\vbc7ui.dll + 2008-04-13 16:11:45 147,456 ------w c:\windows\ServicePackFiles\i386\vbc7ui.es.dll + 2008-04-13 16:11:45 151,552 ------w c:\windows\ServicePackFiles\i386\vbc7ui.fr.dll + 2008-04-13 16:11:45 151,552 ------w c:\windows\ServicePackFiles\i386\vbc7ui.ger.dll + 2008-04-13 16:11:45 147,456 ------w c:\windows\ServicePackFiles\i386\vbc7ui.it.dll + 2008-04-13 16:11:45 126,976 ------w c:\windows\ServicePackFiles\i386\vbc7ui.ja.dll + 2008-04-13 16:11:45 126,976 ------w c:\windows\ServicePackFiles\i386\vbc7ui.kor.dll + 2008-04-14 02:20:40 434,176 ------w c:\windows\ServicePackFiles\i386\vbscript.dll + 2008-04-14 02:20:40 11,325 ------w c:\windows\ServicePackFiles\i386\vchnt5.dll + 2008-04-14 02:20:40 26,112 ------w c:\windows\ServicePackFiles\i386\vdmdbg.dll + 2008-04-14 02:20:40 51,712 ------w c:\windows\ServicePackFiles\i386\vdmredir.dll + 2008-04-14 02:21:22 28,672 ------w c:\windows\ServicePackFiles\i386\verclsid.exe + 2008-04-14 02:20:40 26,624 ------w c:\windows\ServicePackFiles\i386\verifier.dll + 2008-04-14 02:20:40 18,944 ------w c:\windows\ServicePackFiles\i386\version.dll + 2008-04-14 02:20:40 54,784 ------w c:\windows\ServicePackFiles\i386\vfwwdm32.dll + 2008-04-13 18:44:40 20,992 ------w c:\windows\ServicePackFiles\i386\vga.sys + 2008-04-14 02:20:40 851,968 ------w c:\windows\ServicePackFiles\i386\vgx.dll + 2008-04-13 18:36:40 42,240 ------w c:\windows\ServicePackFiles\i386\viaagp.sys + 2008-04-13 18:40:31 5,376 ------w c:\windows\ServicePackFiles\i386\viaide.sys + 2008-04-13 18:44:40 81,664 ------w c:\windows\ServicePackFiles\i386\videoprt.sys + 2008-04-14 02:20:40 131,584 ------w c:\windows\ServicePackFiles\i386\viewprov.dll + 2008-04-14 01:53:00 53,248 ------w c:\windows\ServicePackFiles\i386\volsnap.sys + 2008-04-13 16:11:47 999,424 ------w c:\windows\ServicePackFiles\i386\vsavb7rt.dll + 2008-04-14 02:20:41 430,592 ------w c:\windows\ServicePackFiles\i386\vssapi.dll + 2008-04-14 02:21:22 292,864 ------w c:\windows\ServicePackFiles\i386\vssvc.exe + 2008-04-14 02:20:41 176,128 ------w c:\windows\ServicePackFiles\i386\w32time.dll + 2008-04-14 02:20:41 15,872 ------w c:\windows\ServicePackFiles\i386\w3ssl.dll + 2008-04-14 02:20:41 368,128 ------w c:\windows\ServicePackFiles\i386\w3svc.dll + 2008-04-14 02:20:41 492,032 ------w c:\windows\ServicePackFiles\i386\w95upgnt.dll + 2008-04-14 02:21:22 46,080 ------w c:\windows\ServicePackFiles\i386\wab.exe + 2008-04-14 02:20:41 510,976 ------w c:\windows\ServicePackFiles\i386\wab32.dll + 2008-04-14 01:53:14 260,608 ------w c:\windows\ServicePackFiles\i386\wab32res.dll + 2008-04-14 02:20:41 32,768 ------w c:\windows\ServicePackFiles\i386\wabfind.dll + 2008-04-14 02:20:41 85,504 ------w c:\windows\ServicePackFiles\i386\wabimp.dll + 2008-04-14 02:21:22 30,208 ------w c:\windows\ServicePackFiles\i386\wabmig.exe + 2008-04-13 18:43:55 14,208 ------w c:\windows\ServicePackFiles\i386\wacompen.sys + 2004-08-04 00:29:38 12,415 ------w c:\windows\ServicePackFiles\i386\wadv01nt.sys + 2004-08-04 00:29:38 12,127 ------w c:\windows\ServicePackFiles\i386\wadv02nt.sys + 2004-08-04 00:29:38 11,775 ------w c:\windows\ServicePackFiles\i386\wadv05nt.sys + 2004-08-04 00:29:40 11,807 ------w c:\windows\ServicePackFiles\i386\wadv07nt.sys + 2004-08-04 00:29:40 11,295 ------w c:\windows\ServicePackFiles\i386\wadv08nt.sys + 2004-08-04 00:29:42 11,871 ------w c:\windows\ServicePackFiles\i386\wadv09nt.sys + 2004-08-04 00:29:42 11,935 ------w c:\windows\ServicePackFiles\i386\wadv11nt.sys + 2008-04-14 02:20:41 78,336 ------w c:\windows\ServicePackFiles\i386\wam51.dll + 2008-04-14 02:20:41 53,248 ------w c:\windows\ServicePackFiles\i386\wamreg51.dll + 2008-04-13 18:57:21 34,560 ------w c:\windows\ServicePackFiles\i386\wanarp.sys + 2008-04-13 18:44:59 17,664 ------w c:\windows\ServicePackFiles\i386\watchdog.sys + 2004-08-04 00:29:42 29,311 ------w c:\windows\ServicePackFiles\i386\watv01nt.sys + 2004-08-04 00:29:44 19,551 ------w c:\windows\ServicePackFiles\i386\watv02nt.sys + 2004-08-04 00:29:44 33,599 ------w c:\windows\ServicePackFiles\i386\watv04nt.sys + 2004-08-04 00:29:46 22,271 ------w c:\windows\ServicePackFiles\i386\watv06nt.sys + 2004-08-04 00:29:46 25,471 ------w c:\windows\ServicePackFiles\i386\watv10nt.sys + 2008-04-14 02:20:41 215,552 ------w c:\windows\ServicePackFiles\i386\wavemsp.dll + 2008-04-14 02:20:41 199,168 ------w c:\windows\ServicePackFiles\i386\wbemcntl.dll + 2008-04-14 02:20:41 214,528 ------w c:\windows\ServicePackFiles\i386\wbemcomn.dll + 2008-04-14 02:20:41 71,680 ------w c:\windows\ServicePackFiles\i386\wbemcons.dll + 2008-04-14 02:20:41 531,968 ------w c:\windows\ServicePackFiles\i386\wbemcore.dll + 2008-04-14 02:20:41 178,176 ------w c:\windows\ServicePackFiles\i386\wbemdisp.dll + 2008-04-14 02:20:41 273,920 ------w c:\windows\ServicePackFiles\i386\wbemess.dll + 2008-04-14 02:20:41 43,520 ------w c:\windows\ServicePackFiles\i386\wbemperf.dll + 2008-04-14 02:20:41 18,944 ------w c:\windows\ServicePackFiles\i386\wbemprox.dll + 2008-04-14 02:20:41 43,520 ------w c:\windows\ServicePackFiles\i386\wbemsvc.dll + 2008-04-14 02:21:22 118,784 ------w c:\windows\ServicePackFiles\i386\wbemtest.exe + 2008-04-14 02:20:41 197,120 ------w c:\windows\ServicePackFiles\i386\wbemupgd.dll + 2008-04-14 01:53:46 32,000 ------w c:\windows\ServicePackFiles\i386\wceusbsh.sys + 2004-08-04 00:29:46 23,615 ------w c:\windows\ServicePackFiles\i386\wch7xxnt.sys + 2008-04-14 02:20:41 49,152 ------w c:\windows\ServicePackFiles\i386\wdigest.dll + 2008-04-14 02:21:27 23,552 ------w c:\windows\ServicePackFiles\i386\wdmaud.drv + 2008-04-13 19:17:18 83,072 ------w c:\windows\ServicePackFiles\i386\wdmaud.sys + 2008-04-14 02:20:41 278,528 ------w c:\windows\ServicePackFiles\i386\webcheck.dll + 2008-04-14 02:20:41 68,096 ------w c:\windows\ServicePackFiles\i386\webclnt.dll + 2008-04-14 02:20:41 136,192 ------w c:\windows\ServicePackFiles\i386\webvw.dll + 2008-04-14 02:21:22 66,048 ------w c:\windows\ServicePackFiles\i386\wextract.exe + 2008-04-14 02:21:23 434,688 ------w c:\windows\ServicePackFiles\i386\wiaacmgr.exe + 2008-04-14 02:20:41 464,384 ------w c:\windows\ServicePackFiles\i386\wiadefui.dll + 2008-04-14 02:20:42 124,928 ------w c:\windows\ServicePackFiles\i386\wiadss.dll + 2008-04-14 02:20:42 75,776 ------w c:\windows\ServicePackFiles\i386\wiascr.dll + 2008-04-14 02:20:42 334,336 ------w c:\windows\ServicePackFiles\i386\wiaservc.dll + 2008-04-14 02:20:42 591,872 ------w c:\windows\ServicePackFiles\i386\wiashext.dll + 2008-04-14 02:20:42 111,104 ------w c:\windows\ServicePackFiles\i386\wiavideo.dll + 2008-04-14 02:20:42 712,704 ------w c:\windows\ServicePackFiles\i386\wic.dll + 2008-04-14 02:20:42 346,112 ------w c:\windows\ServicePackFiles\i386\wicext.dll + 2008-04-14 01:54:20 1,845,760 ------w c:\windows\ServicePackFiles\i386\win32k.sys + 2008-04-14 02:20:42 102,912 ------w c:\windows\ServicePackFiles\i386\win32spl.dll + 2008-04-13 16:48:53 1,647,616 ------w c:\windows\ServicePackFiles\i386\winbrand.dll + 2008-04-14 02:21:23 287,744 ------w c:\windows\ServicePackFiles\i386\winhlp32.exe + 2008-04-14 02:20:42 354,304 ------w c:\windows\ServicePackFiles\i386\winhttp.dll + 2008-04-14 02:20:42 668,160 ------w c:\windows\ServicePackFiles\i386\wininet.dll + 2008-04-14 02:20:42 32,256 ------w c:\windows\ServicePackFiles\i386\winipsec.dll + 2008-04-14 02:21:23 509,952 ------w c:\windows\ServicePackFiles\i386\winlogon.exe + 2008-04-14 02:20:42 179,200 ------w c:\windows\ServicePackFiles\i386\winmm.dll + 2004-08-04 01:51:20 5,120 ------w c:\windows\ServicePackFiles\i386\winnls.dll + 2008-04-14 02:19:54 763,392 ------w c:\windows\ServicePackFiles\i386\winntbbu.dll + 2008-04-14 02:20:42 16,896 ------w c:\windows\ServicePackFiles\i386\winrnr.dll + 2008-04-14 02:20:42 99,840 ------w c:\windows\ServicePackFiles\i386\winscard.dll + 2008-04-14 02:20:42 17,408 ------w c:\windows\ServicePackFiles\i386\winshfhc.dll + 2008-04-14 02:21:27 146,944 ------w c:\windows\ServicePackFiles\i386\winspool.drv + 2008-04-14 02:20:42 293,888 ------w c:\windows\ServicePackFiles\i386\winsrv.dll + 2008-04-14 02:20:42 53,760 ------w c:\windows\ServicePackFiles\i386\winsta.dll + 2008-04-14 02:20:42 176,640 ------w c:\windows\ServicePackFiles\i386\wintrust.dll + 2008-04-14 02:21:23 5,632 ------w c:\windows\ServicePackFiles\i386\winver.exe + 2008-04-14 02:20:42 132,096 ------w c:\windows\ServicePackFiles\i386\wkssvc.dll + 2008-04-14 02:20:42 69,120 ------w c:\windows\ServicePackFiles\i386\wlanapi.dll + 2008-04-14 02:20:42 172,544 ------w c:\windows\ServicePackFiles\i386\wldap32.dll + 2004-08-04 00:31:28 154,624 ------w c:\windows\ServicePackFiles\i386\wlluc48.sys + 2008-04-14 02:20:43 93,184 ------w c:\windows\ServicePackFiles\i386\wlnotify.dll + 2008-04-14 02:19:55 5,632 ------w c:\windows\ServicePackFiles\i386\wmi.dll + 2008-04-13 18:36:38 8,832 ------w c:\windows\ServicePackFiles\i386\wmiacpi.sys + 2008-04-14 02:21:23 196,608 ------w c:\windows\ServicePackFiles\i386\wmiadap.exe + 2008-04-14 01:55:31 7,168 ------w c:\windows\ServicePackFiles\i386\wmiapres.dll + 2008-04-14 02:20:43 88,576 ------w c:\windows\ServicePackFiles\i386\wmiaprpl.dll + 2008-04-14 02:21:24 126,464 ------w c:\windows\ServicePackFiles\i386\wmiapsrv.exe + 2008-04-14 02:21:24 365,056 ------w c:\windows\ServicePackFiles\i386\wmic.exe + 2008-04-14 02:20:43 60,928 ------w c:\windows\ServicePackFiles\i386\wmicookr.dll + 2008-04-14 02:20:43 140,800 ------w c:\windows\ServicePackFiles\i386\wmidcprv.dll + 2008-04-14 02:20:43 156,672 ------w c:\windows\ServicePackFiles\i386\wmipcima.dll + 2008-04-14 02:20:43 132,096 ------w c:\windows\ServicePackFiles\i386\wmipdskq.dll + 2008-04-14 02:20:43 61,952 ------w c:\windows\ServicePackFiles\i386\wmipiprt.dll + 2008-04-14 02:20:43 62,464 ------w c:\windows\ServicePackFiles\i386\wmipjobj.dll + 2008-04-14 02:20:43 144,896 ------w c:\windows\ServicePackFiles\i386\wmiprov.dll + 2008-04-14 02:20:43 437,248 ------w c:\windows\ServicePackFiles\i386\wmiprvsd.dll + 2008-04-14 02:21:24 218,112 ------w c:\windows\ServicePackFiles\i386\wmiprvse.exe + 2008-04-14 02:20:43 41,472 ------w c:\windows\ServicePackFiles\i386\wmipsess.dll + 2008-04-14 02:20:43 145,408 ------w c:\windows\ServicePackFiles\i386\wmisvc.dll + 2008-04-14 02:20:43 97,792 ------w c:\windows\ServicePackFiles\i386\wmiutils.dll + 2008-04-14 02:20:43 167,936 ------w c:\windows\ServicePackFiles\i386\wmm2ae.dll + 2008-04-14 02:20:43 4,096 ------w c:\windows\ServicePackFiles\i386\wmm2eres.dll + 2008-04-14 02:20:43 7,680 ------w c:\windows\ServicePackFiles\i386\wmm2ext.dll + 2008-04-14 02:20:43 402,432 ------w c:\windows\ServicePackFiles\i386\wmm2filt.dll + 2008-04-14 02:20:43 502,272 ------w c:\windows\ServicePackFiles\i386\wmm2fxa.dll + 2008-04-14 02:20:43 325,632 ------w c:\windows\ServicePackFiles\i386\wmm2fxb.dll + 2008-04-14 02:20:43 4,274,176 ------w c:\windows\ServicePackFiles\i386\wmm2res.dll + 2008-04-14 02:20:43 5,632 ------w c:\windows\ServicePackFiles\i386\wmm2res2.dll + 2008-04-14 02:20:43 276,992 ------w c:\windows\ServicePackFiles\i386\wmphoto.dll + 2008-04-14 02:21:24 215,040 ------w c:\windows\ServicePackFiles\i386\wordpad.exe + 2008-04-14 02:20:44 264,704 ------w c:\windows\ServicePackFiles\i386\wow32.dll + 2008-04-14 02:21:24 32,256 ------w c:\windows\ServicePackFiles\i386\wpabaln.exe + 2008-04-14 02:21:24 11,776 ------w c:\windows\ServicePackFiles\i386\wpnpinst.exe + 2008-04-14 02:20:44 82,432 ------w c:\windows\ServicePackFiles\i386\ws2_32.dll + 2008-04-14 02:20:44 19,968 ------w c:\windows\ServicePackFiles\i386\ws2help.dll + 2008-04-14 02:21:24 13,824 ------w c:\windows\ServicePackFiles\i386\wscntfy.exe + 2008-04-14 02:21:24 155,648 ------w c:\windows\ServicePackFiles\i386\wscript.exe + 2008-04-14 02:20:44 80,896 ------w c:\windows\ServicePackFiles\i386\wscsvc.dll + 2008-04-14 02:20:44 614,912 ------w c:\windows\ServicePackFiles\i386\wsecedit.dll + 2008-04-14 02:20:44 108,032 ------w c:\windows\ServicePackFiles\i386\wshbth.dll + 2008-04-14 02:20:44 36,864 ------w c:\windows\ServicePackFiles\i386\wshcon.dll + 2008-04-14 02:20:44 90,112 ------w c:\windows\ServicePackFiles\i386\wshext.dll + 2008-04-14 02:20:44 14,336 ------w c:\windows\ServicePackFiles\i386\wship6.dll + 2008-04-14 02:20:44 8,192 ------w c:\windows\ServicePackFiles\i386\wshirda.dll + 2008-04-14 02:20:44 11,264 ------w c:\windows\ServicePackFiles\i386\wshrm.dll + 2008-04-14 02:20:44 19,456 ------w c:\windows\ServicePackFiles\i386\wshtcpip.dll + 2004-08-04 00:29:48 12,063 ------w c:\windows\ServicePackFiles\i386\wsiintxx.sys + 2008-04-14 02:20:44 41,984 ------w c:\windows\ServicePackFiles\i386\wsnmp32.dll + 2008-04-14 02:20:44 25,088 ------w c:\windows\ServicePackFiles\i386\wsock32.dll + 2008-04-13 18:46:24 19,200 ------w c:\windows\ServicePackFiles\i386\wstcodec.sys + 2008-04-14 02:20:44 51,200 ------w c:\windows\ServicePackFiles\i386\wstdecod.dll + 2008-04-14 02:20:44 18,432 ------w c:\windows\ServicePackFiles\i386\wtsapi32.dll + 2008-04-14 02:20:44 431,616 ------w c:\windows\ServicePackFiles\i386\wuapi.dll + 2008-04-14 02:21:24 111,616 ------w c:\windows\ServicePackFiles\i386\wuauclt.exe + 2008-04-14 02:21:25 167,936 ------w c:\windows\ServicePackFiles\i386\wuauclt1.exe + 2008-04-14 02:20:45 1,135,616 ------w c:\windows\ServicePackFiles\i386\wuaueng.dll + 2008-04-14 02:20:45 183,808 ------w c:\windows\ServicePackFiles\i386\wuaueng1.dll + 2008-04-14 02:20:45 6,656 ------w c:\windows\ServicePackFiles\i386\wuauserv.dll + 2008-04-14 02:20:46 113,152 ------w c:\windows\ServicePackFiles\i386\wucltui.dll + 2008-04-14 02:20:46 32,256 ------w c:\windows\ServicePackFiles\i386\wups.dll + 2008-04-14 02:20:46 120,320 ------w c:\windows\ServicePackFiles\i386\wuweb.dll + 2004-08-04 00:29:50 19,455 ------w c:\windows\ServicePackFiles\i386\wvchntxx.sys + 2008-04-14 02:20:46 383,488 ------w c:\windows\ServicePackFiles\i386\wzcdlg.dll + 2008-04-14 02:20:46 52,736 ------w c:\windows\ServicePackFiles\i386\wzcsapi.dll + 2008-04-14 02:20:46 483,840 ------w c:\windows\ServicePackFiles\i386\wzcsvc.dll + 2008-04-14 02:20:46 91,648 ------w c:\windows\ServicePackFiles\i386\xactsrv.dll + 2008-04-14 02:21:25 30,720 ------w c:\windows\ServicePackFiles\i386\xcopy.exe + 2004-07-17 14:38:58 176,760 ------w c:\windows\ServicePackFiles\i386\xenroll.dll + 2008-04-14 02:20:46 121,856 ------w c:\windows\ServicePackFiles\i386\xmllite.dll + 2008-04-14 02:20:46 129,024 ------w c:\windows\ServicePackFiles\i386\xmlprov.dll + 2008-04-14 02:20:46 50,176 ------w c:\windows\ServicePackFiles\i386\xmlprovi.dll + 2008-04-14 02:20:46 11,776 ------w c:\windows\ServicePackFiles\i386\xolehlp.dll + 2008-04-13 18:53:32 558,080 ------w c:\windows\ServicePackFiles\i386\xpnetdg.exe + 2008-04-14 02:20:46 18,944 ------w c:\windows\ServicePackFiles\i386\xrxscnui.dll + 2008-04-14 02:20:46 116,224 ------w c:\windows\ServicePackFiles\i386\xrxwiadr.dll + 2008-04-14 02:20:46 339,456 ------w c:\windows\ServicePackFiles\i386\zipfldr.dll + 2008-04-14 02:20:24 33,792 ------w c:\windows\ServicePackFiles\ServicePackCache\i386\custsat.dll + 2008-04-14 02:20:33 82,944 ------w c:\windows\ServicePackFiles\ServicePackCache\i386\msgsc.dll + 2008-04-13 17:30:28 180,224 ------w c:\windows\ServicePackFiles\ServicePackCache\i386\msgslang.dll + 2008-04-14 02:21:10 1,695,232 ------w c:\windows\ServicePackFiles\ServicePackCache\i386\msmsgs.exe + 2008-04-14 02:21:18 32,866 ------w c:\windows\slrundll.exe - 2004-08-04 03:45:24 3,166,208 ----a-w c:\windows\srchasst\msgr3en.dll + 2008-04-14 02:20:33 3,166,208 ----a-w c:\windows\srchasst\msgr3en.dll - 2004-08-04 03:45:28 58,434 ----a-w c:\windows\srchasst\srchctls.dll + 2008-04-14 02:20:40 58,434 ----a-w c:\windows\srchasst\srchctls.dll - 2004-08-04 03:45:28 726,590 ----a-w c:\windows\srchasst\srchui.dll + 2008-04-14 02:20:40 727,102 ----a-w c:\windows\srchasst\srchui.dll - 2004-08-04 03:45:48 146,944 ----a-w c:\windows\system\WINSPOOL.DRV + 2008-04-14 02:21:27 146,944 ----a-w c:\windows\system\winspool.drv - 2006-08-16 11:59:24 100,352 ----a-w c:\windows\system32\6to4svc.dll + 2008-04-14 02:20:22 100,352 ----a-w c:\windows\system32\6to4svc.dll + 2008-04-14 02:20:22 136,192 ------w c:\windows\system32\aaclient.dll - 2004-08-04 03:45:30 516,096 ----a-w c:\windows\system32\accwiz.exe + 2008-04-14 02:20:46 188,416 ----a-w c:\windows\system32\accwiz.exe - 2004-08-04 03:45:22 115,712 ----a-w c:\windows\system32\aclui.dll + 2008-04-14 02:20:23 116,736 ----a-w c:\windows\system32\aclui.dll - 2004-08-04 03:45:22 194,048 ----a-w c:\windows\system32\activeds.dll + 2008-04-14 02:20:23 193,536 ----a-w c:\windows\system32\activeds.dll - 2004-08-04 03:45:30 4,096 ----a-w c:\windows\system32\actmovie.exe + 2008-04-14 02:20:46 4,096 ----a-w c:\windows\system32\actmovie.exe - 2004-08-04 03:45:22 101,888 ----a-w c:\windows\system32\actxprxy.dll + 2008-04-14 02:20:23 98,304 ----a-w c:\windows\system32\actxprxy.dll - 2004-08-04 03:45:22 61,440 ----a-w c:\windows\system32\admparse.dll + 2008-04-14 02:20:23 61,440 ----a-w c:\windows\system32\admparse.dll - 2004-08-04 03:45:22 175,616 ----a-w c:\windows\system32\adsldp.dll + 2008-04-14 02:20:23 175,616 ----a-w c:\windows\system32\adsldp.dll - 2004-08-04 03:45:22 143,360 ----a-w c:\windows\system32\adsldpc.dll + 2008-04-14 02:20:23 143,360 ----a-w c:\windows\system32\adsldpc.dll - 2004-08-04 03:45:22 68,096 ----a-w c:\windows\system32\adsmsext.dll + 2008-04-14 02:20:23 68,096 ----a-w c:\windows\system32\adsmsext.dll - 2004-08-04 03:45:22 263,680 ----a-w c:\windows\system32\adsnt.dll + 2008-04-14 02:20:23 263,680 ----a-w c:\windows\system32\adsnt.dll - 2001-10-28 15:06:06 109,568 ----a-w c:\windows\system32\adsnw.dll + 2008-04-14 02:20:23 123,392 ----a-w c:\windows\system32\adsnw.dll - 2004-08-04 03:45:22 683,008 ----a-w c:\windows\system32\advapi32.dll + 2008-04-14 02:20:23 683,520 ----a-w c:\windows\system32\advapi32.dll - 2004-08-04 03:45:22 101,376 ----a-w c:\windows\system32\advpack.dll + 2008-04-14 02:20:23 101,376 ----a-w c:\windows\system32\advpack.dll - 2004-08-04 03:45:30 98,304 ----a-w c:\windows\system32\ahui.exe + 2008-04-14 02:20:46 98,304 ----a-w c:\windows\system32\ahui.exe - 2004-08-04 03:45:30 44,544 ----a-w c:\windows\system32\alg.exe + 2008-04-14 02:20:46 44,544 ----a-w c:\windows\system32\alg.exe - 2004-08-04 03:45:22 17,408 ----a-w c:\windows\system32\alrsvc.dll + 2008-04-14 02:20:23 17,408 ----a-w c:\windows\system32\alrsvc.dll - 2004-08-04 03:45:22 70,656 ----a-w c:\windows\system32\amstream.dll + 2008-04-14 02:20:23 70,656 ----a-w c:\windows\system32\amstream.dll - 2004-08-04 03:45:22 126,976 ----a-w c:\windows\system32\apphelp.dll + 2008-04-14 02:20:23 125,952 ----a-w c:\windows\system32\apphelp.dll - 2004-08-04 03:45:22 172,032 ----a-w c:\windows\system32\appmgmts.dll + 2008-04-14 02:20:23 172,032 ----a-w c:\windows\system32\appmgmts.dll - 2004-08-04 03:45:22 297,984 ----a-w c:\windows\system32\appmgr.dll + 2008-04-14 02:20:23 297,984 ----a-w c:\windows\system32\appmgr.dll - 2004-08-04 03:45:30 30,208 ----a-w c:\windows\system32\asr_fmt.exe + 2008-04-14 02:20:46 30,208 ----a-w c:\windows\system32\asr_fmt.exe - 2004-08-04 03:45:30 32,768 ----a-w c:\windows\system32\asr_pfu.exe + 2008-04-14 02:20:46 32,768 ----a-w c:\windows\system32\asr_pfu.exe - 2004-08-04 03:45:22 65,024 ----a-w c:\windows\system32\asycfilt.dll + 2008-04-14 02:20:23 65,024 ----a-w c:\windows\system32\asycfilt.dll - 2004-08-04 03:45:30 25,600 ----a-w c:\windows\system32\at.exe + 2008-04-14 02:20:46 25,600 ----a-w c:\windows\system32\at.exe + 2008-04-14 02:20:23 229,376 ------w c:\windows\system32\ati2cqag.dll + 2008-04-14 02:20:23 377,984 ------w c:\windows\system32\ati2dvaa.dll + 2008-04-14 02:20:24 201,728 ------w c:\windows\system32\ati2dvag.dll + 2008-04-14 02:20:24 870,784 ------w c:\windows\system32\ati3d1ag.dll + 2008-04-14 02:20:24 32,768 ------w c:\windows\system32\ativtmxx.dll + 2008-04-14 02:20:24 516,768 ------w c:\windows\system32\ativvaxx.dll - 2004-08-04 03:45:22 58,880 ----a-w c:\windows\system32\atl.dll + 2008-04-14 02:20:24 58,880 ----a-w c:\windows\system32\atl.dll - 2004-08-04 03:45:30 11,776 ----a-w c:\windows\system32\atmadm.exe + 2008-04-14 02:20:46 11,776 ----a-w c:\windows\system32\atmadm.exe - 2004-08-04 03:44:08 285,696 ----a-w c:\windows\system32\atmfd.dll + 2008-04-14 02:18:02 285,696 ----a-w c:\windows\system32\atmfd.dll - 2004-08-04 03:45:22 30,208 ----a-w c:\windows\system32\atmlib.dll + 2008-04-14 02:20:24 30,208 ----a-w c:\windows\system32\atmlib.dll - 2001-10-28 15:06:10 11,264 ----a-w c:\windows\system32\attrib.exe + 2008-04-14 02:20:47 12,288 ----a-w c:\windows\system32\attrib.exe - 2004-08-04 03:45:22 42,496 ----a-w c:\windows\system32\audiosrv.dll + 2008-04-14 02:20:24 42,496 ----a-w c:\windows\system32\audiosrv.dll - 2004-08-04 03:45:30 14,336 ----a-w c:\windows\system32\auditusr.exe + 2008-04-14 02:20:47 14,336 ----a-w c:\windows\system32\auditusr.exe - 2005-03-02 18:18:26 56,832 ----a-w c:\windows\system32\authz.dll + 2008-04-14 02:20:24 62,464 ----a-w c:\windows\system32\authz.dll - 2004-08-04 03:45:30 616,960 ----a-w c:\windows\system32\autochk.exe + 2008-04-14 02:20:47 616,960 ----a-w c:\windows\system32\autochk.exe - 2004-08-04 03:45:30 630,784 ----a-w c:\windows\system32\autoconv.exe + 2008-04-14 02:20:48 630,784 ----a-w c:\windows\system32\autoconv.exe - 2004-08-04 03:45:30 608,768 ----a-w c:\windows\system32\autofmt.exe + 2008-04-14 02:20:48 608,768 ----a-w c:\windows\system32\autofmt.exe - 2004-08-04 03:45:30 11,264 ----a-w c:\windows\system32\autolfn.exe + 2008-04-14 02:20:48 11,264 ----a-w c:\windows\system32\autolfn.exe - 2004-08-04 03:45:22 85,504 ----a-w c:\windows\system32\avifil32.dll + 2008-04-14 02:20:24 85,504 ----a-w c:\windows\system32\avifil32.dll + 2008-04-14 02:20:24 233,472 ------w c:\windows\system32\azroles.dll - 2004-08-04 03:45:22 52,736 ----a-w c:\windows\system32\basesrv.dll + 2008-04-14 02:20:24 52,736 ----a-w c:\windows\system32\basesrv.dll - 2004-08-04 03:45:22 30,720 ----a-w c:\windows\system32\batmeter.dll + 2008-04-14 02:20:24 29,184 ----a-w c:\windows\system32\batmeter.dll - 2004-08-04 03:45:22 13,312 ----a-w c:\windows\system32\batt.dll + 2008-04-14 02:20:24 8,704 ----a-w c:\windows\system32\batt.dll - 2004-08-04 03:45:22 17,408 ----a-w c:\windows\system32\bidispl.dll + 2008-04-14 02:20:24 17,408 ----a-w c:\windows\system32\bidispl.dll + 2008-04-14 02:20:37 409,088 ------w c:\windows\system32\bits\qmgr.dll - 2004-08-04 03:45:22 8,192 ----a-w c:\windows\system32\bitsprx2.dll + 2008-04-14 02:20:24 8,192 ----a-w c:\windows\system32\bitsprx2.dll - 2004-08-04 03:45:22 7,168 ----a-w c:\windows\system32\bitsprx3.dll + 2008-04-14 02:20:24 7,168 ----a-w c:\windows\system32\bitsprx3.dll + 2008-04-14 02:20:24 7,168 ------w c:\windows\system32\bitsprx4.dll - 2004-08-04 03:45:30 71,680 ----a-w c:\windows\system32\blastcln.exe + 2008-04-14 02:20:50 71,680 ----a-w c:\windows\system32\blastcln.exe - 2001-10-28 15:06:10 147,456 ----a-w c:\windows\system32\bootcfg.exe + 2008-04-14 02:20:50 153,600 ----a-w c:\windows\system32\bootcfg.exe - 2004-08-04 03:44:08 67,584 ----a-w c:\windows\system32\browselc.dll + 2008-04-14 01:53:30 67,584 ----a-w c:\windows\system32\browselc.dll - 2004-08-04 03:45:22 77,312 ----a-w c:\windows\system32\browser.dll + 2008-04-14 02:20:24 77,824 ----a-w c:\windows\system32\browser.dll - 2008-10-16 10:39:09 1,024,000 ----a-w c:\windows\system32\browseui.dll + 2008-04-14 02:20:24 1,025,536 ----a-w c:\windows\system32\browseui.dll - 2004-08-04 03:45:22 78,336 ----a-w c:\windows\system32\browsewm.dll + 2008-04-14 02:20:24 78,336 ----a-w c:\windows\system32\browsewm.dll - 2004-08-04 03:45:22 20,992 ----a-w c:\windows\system32\bthci.dll + 2008-04-14 02:20:24 20,992 ----a-w c:\windows\system32\bthci.dll - 2004-08-04 03:45:22 30,208 ----a-w c:\windows\system32\bthserv.dll + 2008-04-14 02:20:24 30,208 ----a-w c:\windows\system32\bthserv.dll - 2004-08-04 03:45:22 50,688 ----a-w c:\windows\system32\btpanui.dll + 2008-04-14 02:20:24 50,688 ----a-w c:\windows\system32\btpanui.dll - 2004-08-04 03:45:22 59,904 ----a-w c:\windows\system32\cabinet.dll + 2008-04-14 02:20:24 60,416 ----a-w c:\windows\system32\cabinet.dll - 2004-08-04 03:45:22 84,992 ----a-w c:\windows\system32\cabview.dll + 2008-04-14 02:20:24 84,992 ----a-w c:\windows\system32\cabview.dll - 2001-10-28 15:06:10 18,944 ----a-w c:\windows\system32\cacls.exe + 2008-04-14 02:20:50 20,480 ----a-w c:\windows\system32\cacls.exe - 2004-08-04 03:45:22 50,688 ----a-w c:\windows\system32\camocx.dll + 2008-04-14 02:20:24 50,688 ----a-w c:\windows\system32\camocx.dll - 2001-10-28 15:06:10 145,408 ----a-w c:\windows\system32\capesnpn.dll + 2008-04-14 02:20:24 152,576 ----a-w c:\windows\system32\capesnpn.dll - 2005-07-26 04:40:27 225,792 ----a-w c:\windows\system32\catsrv.dll + 2008-04-14 02:20:24 226,304 ----a-w c:\windows\system32\catsrv.dll - 2004-08-04 03:45:22 85,504 ----a-w c:\windows\system32\catsrvps.dll + 2008-04-14 02:20:24 85,504 ----a-w c:\windows\system32\catsrvps.dll - 2005-07-26 04:40:28 625,152 ----a-w c:\windows\system32\catsrvut.dll + 2008-04-14 02:20:24 625,664 ----a-w c:\windows\system32\catsrvut.dll - 2008-10-16 10:39:07 151,552 ----a-w c:\windows\system32\cdfview.dll + 2008-04-14 02:20:24 151,552 ----a-w c:\windows\system32\cdfview.dll - 2005-09-10 01:55:12 2,067,968 ----a-w c:\windows\system32\cdosys.dll + 2008-04-14 02:20:24 2,091,520 ----a-w c:\windows\system32\cdosys.dll - 2004-08-04 03:45:22 199,680 ----a-w c:\windows\system32\certcli.dll + 2008-04-14 02:20:24 199,680 ----a-w c:\windows\system32\certcli.dll - 2004-08-04 03:45:22 825,856 ----a-w c:\windows\system32\certmgr.dll + 2008-04-14 02:20:24 464,384 ----a-w c:\windows\system32\certmgr.dll - 2004-08-04 03:45:22 39,424 ----a-w c:\windows\system32\cfgbkend.dll + 2008-04-14 02:20:24 39,424 ----a-w c:\windows\system32\cfgbkend.dll - 2004-08-04 03:44:08 16,896 ----a-w c:\windows\system32\cfgmgr32.dll + 2008-04-14 02:18:05 16,896 ----a-w c:\windows\system32\cfgmgr32.dll - 2001-10-28 15:06:12 109,568 ----a-w c:\windows\system32\cic.dll + 2008-04-14 02:20:24 148,480 ----a-w c:\windows\system32\cic.dll - 2006-06-22 05:17:15 69,120 ----a-w c:\windows\system32\ciodm.dll + 2008-04-14 02:20:24 69,120 ----a-w c:\windows\system32\ciodm.dll - 2004-08-04 03:45:30 57,344 ----a-w c:\windows\system32\cipher.exe + 2008-04-14 02:20:50 57,856 ----a-w c:\windows\system32\cipher.exe - 2004-08-04 03:45:30 5,632 ----a-w c:\windows\system32\cisvc.exe + 2008-04-14 02:20:51 5,632 ----a-w c:\windows\system32\cisvc.exe - 2005-07-26 04:40:28 110,080 ----a-w c:\windows\system32\clbcatex.dll + 2008-04-14 02:20:24 110,592 ----a-w c:\windows\system32\clbcatex.dll - 2005-07-26 04:40:29 498,688 ----a-w c:\windows\system32\clbcatq.dll + 2008-04-14 02:20:24 498,688 ----a-w c:\windows\system32\clbcatq.dll - 2004-08-04 03:45:30 80,384 ----a-w c:\windows\system32\cleanmgr.exe + 2008-04-14 02:20:51 64,512 ----a-w c:\windows\system32\cleanmgr.exe - 2004-08-04 03:45:22 77,824 ----a-w c:\windows\system32\cliconfg.dll + 2008-04-14 02:20:24 77,824 ----a-w c:\windows\system32\cliconfg.dll - 2004-08-04 03:45:30 20,480 ----a-w c:\windows\system32\cliconfg.exe + 2008-04-14 02:20:51 20,480 ----a-w c:\windows\system32\cliconfg.exe - 2004-08-04 03:45:32 109,568 ----a-w c:\windows\system32\clipbrd.exe + 2008-04-14 02:20:51 104,960 ----a-w c:\windows\system32\clipbrd.exe - 2004-08-04 03:45:32 48,128 ----a-w c:\windows\system32\clipsrv.exe + 2008-04-14 02:20:51 33,280 ----a-w c:\windows\system32\clipsrv.exe - 2004-08-04 03:45:22 57,856 ----a-w c:\windows\system32\clusapi.dll + 2008-04-14 02:20:24 58,368 ----a-w c:\windows\system32\clusapi.dll - 2004-08-04 03:45:22 15,872 ----a-w c:\windows\system32\cmcfg32.dll + 2008-04-14 02:20:24 15,872 ----a-w c:\windows\system32\cmcfg32.dll - 2004-08-04 03:45:32 514,560 ----a-w c:\windows\system32\cmd.exe + 2008-04-14 02:20:52 400,896 ----a-w c:\windows\system32\cmd.exe - 2004-08-04 03:45:22 518,144 ----a-w c:\windows\system32\cmdial32.dll + 2008-04-14 02:20:24 348,672 ----a-w c:\windows\system32\cmdial32.dll - 2004-08-04 03:45:32 61,440 ----a-w c:\windows\system32\cmdl32.exe + 2008-04-14 02:20:52 25,600 ----a-w c:\windows\system32\cmdl32.exe - 2004-08-04 03:45:32 39,936 ----a-w c:\windows\system32\cmmon32.exe + 2008-04-14 02:20:52 39,936 ----a-w c:\windows\system32\cmmon32.exe - 2004-08-04 03:45:22 188,928 ----a-w c:\windows\system32\cmprops.dll + 2008-04-14 02:20:24 188,928 ----a-w c:\windows\system32\cmprops.dll - 2004-08-04 03:45:22 13,824 ----a-w c:\windows\system32\cmsetACL.dll + 2008-04-14 02:20:24 13,312 ----a-w c:\windows\system32\cmsetacl.dll - 2004-08-04 03:45:32 79,360 ----a-w c:\windows\system32\cmstp.exe + 2008-04-14 02:20:52 65,024 ----a-w c:\windows\system32\cmstp.exe - 2004-08-04 03:45:22 40,960 ----a-w c:\windows\system32\cmutil.dll + 2008-04-14 02:20:24 40,960 ----a-w c:\windows\system32\cmutil.dll - 2004-08-04 03:55:42 49,152 ----a-w c:\windows\system32\cnbjmon.dll + 2008-04-14 02:20:24 49,152 ----a-w c:\windows\system32\cnbjmon.dll - 2005-07-26 04:40:29 60,416 ----a-w c:\windows\system32\colbact.dll + 2008-04-14 02:20:24 60,416 ----a-w c:\windows\system32\colbact.dll - 2005-07-26 04:40:29 195,072 ----a-w c:\windows\system32\Com\comadmin.dll + 2008-04-14 02:20:24 195,072 ----a-w c:\windows\system32\Com\comadmin.dll - 2004-08-04 03:45:32 9,728 ----a-w c:\windows\system32\Com\comrepl.exe + 2008-04-14 02:20:52 9,728 ----a-w c:\windows\system32\Com\comrepl.exe - 2001-10-28 15:06:16 5,120 ----a-w c:\windows\system32\Com\comrereg.exe + 2008-04-14 02:20:52 6,144 ----a-w c:\windows\system32\Com\comrereg.exe - 2001-10-28 15:06:12 25,600 ----a-w c:\windows\system32\comaddin.dll + 2008-04-14 02:20:24 28,160 ----a-w c:\windows\system32\comaddin.dll - 2006-08-25 15:49:12 617,472 ----a-w c:\windows\system32\comctl32.dll + 2008-04-14 02:20:24 617,472 ----a-w c:\windows\system32\comctl32.dll - 2004-08-04 03:45:22 325,120 ----a-w c:\windows\system32\comdlg32.dll + 2008-04-14 02:20:24 275,968 ----a-w c:\windows\system32\comdlg32.dll - 2004-08-04 03:45:22 253,440 ----a-w c:\windows\system32\compatUI.dll + 2008-04-14 02:20:24 253,440 ----a-w c:\windows\system32\compatui.dll - 2004-08-04 03:45:22 230,400 ----a-w c:\windows\system32\compstui.dll + 2008-04-14 02:20:24 230,400 ----a-w c:\windows\system32\compstui.dll - 2005-07-26 04:40:29 97,792 ----a-w c:\windows\system32\comrepl.dll + 2008-04-14 02:20:24 97,792 ----a-w c:\windows\system32\comrepl.dll - 2004-08-04 03:45:22 832,000 ----a-w c:\windows\system32\comres.dll + 2008-04-14 02:20:24 821,760 ----a-w c:\windows\system32\comres.dll + 2008-04-13 18:43:32 9,728 ------w c:\windows\system32\comsdupd.exe - 2001-10-28 15:06:16 147,456 ----a-w c:\windows\system32\comsnap.dll + 2008-04-14 02:20:24 167,424 ----a-w c:\windows\system32\comsnap.dll - 2005-07-26 04:40:30 1,267,200 ----a-w c:\windows\system32\comsvcs.dll + 2008-04-14 02:20:24 1,267,200 ----a-w c:\windows\system32\comsvcs.dll - 2005-07-26 04:40:30 540,160 ----a-w c:\windows\system32\comuid.dll + 2008-04-14 02:20:24 539,648 ----a-w c:\windows\system32\comuid.dll - 2008-12-26 00:01:19 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat + 2009-01-22 18:54:38 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat + 2009-01-22 18:54:36 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012009012220090123\index.dat - 2008-12-26 00:01:19 49,152 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat + 2009-01-22 18:54:38 49,152 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat - 2008-12-26 00:01:19 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat + 2009-01-22 18:54:38 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat - 2001-10-28 15:06:16 346,112 ----a-w c:\windows\system32\confmsp.dll + 2008-04-14 02:20:24 358,400 ----a-w c:\windows\system32\confmsp.dll - 2004-08-04 03:45:32 41,472 ----a-w c:\windows\system32\conime.exe + 2008-04-14 02:20:53 27,648 ----a-w c:\windows\system32\conime.exe - 2004-08-04 03:45:22 35,328 ----a-w c:\windows\system32\corpol.dll + 2008-04-14 02:20:24 35,328 ----a-w c:\windows\system32\corpol.dll + 2008-04-14 02:20:24 12,800 ------w c:\windows\system32\credssp.dll - 2004-08-04 03:45:22 205,312 ----a-w c:\windows\system32\credui.dll + 2008-04-14 02:20:24 164,352 ----a-w c:\windows\system32\credui.dll - 2004-08-04 03:45:22 603,648 ----a-w c:\windows\system32\crypt32.dll + 2008-04-14 02:20:24 605,184 ----a-w c:\windows\system32\crypt32.dll - 2004-08-04 03:45:22 75,264 ----a-w c:\windows\system32\cryptdlg.dll + 2008-04-14 02:20:24 75,264 ----a-w c:\windows\system32\cryptdlg.dll - 2004-08-04 03:45:22 33,280 ----a-w c:\windows\system32\cryptdll.dll + 2008-04-14 02:20:24 33,280 ----a-w c:\windows\system32\cryptdll.dll - 2004-08-04 03:45:22 54,784 ----a-w c:\windows\system32\cryptext.dll + 2008-04-14 02:20:24 54,784 ----a-w c:\windows\system32\cryptext.dll - 2004-08-04 03:45:22 63,488 ----a-w c:\windows\system32\cryptnet.dll + 2008-04-14 02:20:24 64,512 ----a-w c:\windows\system32\cryptnet.dll - 2004-08-04 03:45:22 60,416 ----a-w c:\windows\system32\cryptsvc.dll + 2008-04-14 02:20:24 62,464 ----a-w c:\windows\system32\cryptsvc.dll - 2004-08-04 03:45:22 583,168 ----a-w c:\windows\system32\cryptui.dll + 2008-04-14 02:20:24 528,384 ----a-w c:\windows\system32\cryptui.dll - 2004-08-04 03:45:22 102,400 ----a-w c:\windows\system32\cscdll.dll + 2008-04-14 02:20:24 102,400 ----a-w c:\windows\system32\cscdll.dll - 2004-08-04 03:45:22 780,800 ----a-w c:\windows\system32\cscui.dll + 2008-04-14 02:20:24 331,776 ----a-w c:\windows\system32\cscui.dll - 2004-08-04 03:45:22 32,768 ----a-w c:\windows\system32\csrsrv.dll + 2008-04-14 02:20:24 32,256 ----a-w c:\windows\system32\csrsrv.dll - 2004-08-04 03:45:32 6,144 ----a-w c:\windows\system32\csrss.exe + 2008-04-14 02:20:53 6,144 ----a-w c:\windows\system32\csrss.exe - 2004-08-04 03:45:32 30,208 ----a-w c:\windows\system32\ctfmon.exe + 2008-04-14 02:20:54 15,360 ----a-w c:\windows\system32\ctfmon.exe - 2004-08-04 03:45:22 1,179,648 ----a-w c:\windows\system32\d3d8.dll + 2008-04-14 02:20:24 1,179,648 ----a-w c:\windows\system32\d3d8.dll - 2004-08-04 03:45:22 8,192 ----a-w c:\windows\system32\d3d8thk.dll + 2008-04-14 02:20:24 8,192 ----a-w c:\windows\system32\d3d8thk.dll - 2004-08-04 03:45:22 1,689,088 ----a-w c:\windows\system32\d3d9.dll + 2008-04-14 02:20:24 1,689,088 ----a-w c:\windows\system32\d3d9.dll - 2004-08-04 03:45:22 825,344 ----a-w c:\windows\system32\d3dim700.dll + 2008-04-14 02:20:24 824,320 ----a-w c:\windows\system32\d3dim700.dll - 2008-10-16 10:39:07 1,055,744 ----a-w c:\windows\system32\danim.dll + 2008-04-14 02:20:24 1,055,744 ----a-w c:\windows\system32\danim.dll - 2004-08-04 03:45:22 54,784 ----a-w c:\windows\system32\dataclen.dll + 2008-04-14 02:20:24 54,784 ----a-w c:\windows\system32\dataclen.dll - 2001-10-28 15:06:18 152,064 ----a-w c:\windows\system32\datime.dll + 2008-04-14 02:20:24 165,376 ----a-w c:\windows\system32\datime.dll - 2004-08-04 03:45:22 25,088 ----a-w c:\windows\system32\davclnt.dll + 2008-04-14 02:20:24 25,600 ----a-w c:\windows\system32\davclnt.dll - 2004-08-04 03:45:22 640,000 ----a-w c:\windows\system32\dbghelp.dll + 2008-04-14 02:20:24 640,000 ----a-w c:\windows\system32\dbghelp.dll - 2004-08-04 03:45:22 24,576 ----a-w c:\windows\system32\dbmsrpcn.dll + 2008-04-14 02:20:24 24,576 ----a-w c:\windows\system32\dbmsrpcn.dll - 2004-08-04 03:45:22 110,592 ----a-w c:\windows\system32\dbnetlib.dll + 2008-04-14 02:20:24 110,592 ----a-w c:\windows\system32\dbnetlib.dll - 2004-08-04 03:45:22 28,672 ----a-w c:\windows\system32\dbnmpntw.dll + 2008-04-14 02:20:24 28,672 ----a-w c:\windows\system32\dbnmpntw.dll - 2004-08-04 03:57:52 1,788 ----a-w c:\windows\system32\Dcache.bin + 2008-04-14 02:37:12 1,804 ----a-w c:\windows\system32\dcache.bin - 2004-08-04 03:45:22 8,704 ----a-w c:\windows\system32\dciman32.dll + 2008-04-14 02:20:24 8,704 ----a-w c:\windows\system32\dciman32.dll - 2001-10-28 15:06:18 5,120 ----a-w c:\windows\system32\dcomcnfg.exe + 2008-04-14 02:20:54 6,144 ----a-w c:\windows\system32\dcomcnfg.exe - 2004-08-04 03:45:32 32,256 ----a-w c:\windows\system32\ddeshare.exe + 2008-04-14 02:20:54 32,256 ----a-w c:\windows\system32\ddeshare.exe - 2004-08-04 03:45:22 266,240 ----a-w c:\windows\system32\ddraw.dll + 2008-04-14 02:20:24 279,552 ----a-w c:\windows\system32\ddraw.dll - 2004-08-04 03:45:22 27,136 ----a-w c:\windows\system32\ddrawex.dll + 2008-04-14 02:20:24 27,136 ----a-w c:\windows\system32\ddrawex.dll - 2004-08-04 03:45:32 25,088 ----a-w c:\windows\system32\defrag.exe + 2008-04-14 02:20:54 25,088 ----a-w c:\windows\system32\defrag.exe - 2004-08-04 03:45:22 59,904 ----a-w c:\windows\system32\devenum.dll + 2008-04-14 02:20:24 59,904 ----a-w c:\windows\system32\devenum.dll - 2004-08-04 03:45:22 432,128 ----a-w c:\windows\system32\devmgr.dll + 2008-04-14 02:20:24 288,768 ----a-w c:\windows\system32\devmgr.dll - 2004-08-04 03:45:32 82,432 ----a-w c:\windows\system32\dfrgfat.exe + 2008-04-14 02:20:54 82,944 ----a-w c:\windows\system32\dfrgfat.exe - 2004-08-04 03:45:32 104,960 ----a-w c:\windows\system32\dfrgntfs.exe + 2008-04-14 02:20:54 105,472 ----a-w c:\windows\system32\dfrgntfs.exe - 2004-08-04 03:45:22 38,912 ----a-w c:\windows\system32\dfrgsnap.dll + 2008-04-14 02:20:24 39,424 ----a-w c:\windows\system32\dfrgsnap.dll - 2004-08-04 03:45:22 123,904 ----a-w c:\windows\system32\dfrgui.dll + 2008-04-14 02:20:24 124,416 ----a-w c:\windows\system32\dfrgui.dll - 2004-08-04 03:45:22 28,672 ----a-w c:\windows\system32\dfsshlex.dll + 2008-04-14 02:20:24 28,672 ----a-w c:\windows\system32\dfsshlex.dll - 2004-08-04 03:45:22 113,152 ----a-w c:\windows\system32\dgnet.dll + 2008-04-14 02:20:24 113,152 ----a-w c:\windows\system32\dgnet.dll - 2006-05-19 13:23:33 111,616 ----a-w c:\windows\system32\dhcpcsvc.dll + 2008-04-14 02:20:24 126,976 ----a-w c:\windows\system32\dhcpcsvc.dll - 2001-10-28 15:06:18 391,168 ----a-w c:\windows\system32\dhcpmon.dll + 2008-04-14 02:20:25 400,896 ----a-w c:\windows\system32\dhcpmon.dll + 2008-04-14 02:20:25 48,640 ------w c:\windows\system32\dhcpqec.dll - 2004-08-04 03:45:32 85,504 ----a-w c:\windows\system32\diantz.exe + 2008-04-14 02:20:55 87,040 ----a-w c:\windows\system32\diantz.exe - 2004-08-04 03:45:22 68,608 ----a-w c:\windows\system32\digest.dll + 2008-04-14 02:20:25 68,608 ----a-w c:\windows\system32\digest.dll + 2008-04-14 02:20:25 19,456 ------w c:\windows\system32\dimsntfy.dll + 2008-04-14 02:20:25 39,936 ------w c:\windows\system32\dimsroam.dll - 2004-08-04 03:45:22 166,912 ----a-w c:\windows\system32\dinput.dll + 2008-04-14 02:20:25 166,912 ----a-w c:\windows\system32\dinput.dll - 2004-08-04 03:45:22 189,952 ----a-w c:\windows\system32\dinput8.dll + 2008-04-14 02:20:25 189,952 ----a-w c:\windows\system32\dinput8.dll - 2001-10-28 15:06:18 1,506,304 ----a-w c:\windows\system32\diskcopy.dll + 2008-04-14 02:20:25 1,504,768 ----a-w c:\windows\system32\diskcopy.dll - 2004-08-04 03:45:32 165,376 ----a-w c:\windows\system32\diskpart.exe + 2008-04-14 02:20:55 165,376 ----a-w c:\windows\system32\diskpart.exe - 2001-10-28 15:06:18 45,083 ----a-w c:\windows\system32\dispex.dll + 2008-04-14 02:20:25 32,768 ----a-w c:\windows\system32\dispex.dll - 2008-08-14 09:51:43 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys + 2008-08-14 10:04:36 138,496 -c----w c:\windows\system32\dllcache\afd.sys - 2004-08-04 01:31:52 97,792 -c--a-w c:\windows\system32\dllcache\chtmbx.dll + 2008-04-14 02:18:05 97,792 -c--a-w c:\windows\system32\dllcache\chtmbx.dll - 2004-08-04 01:31:54 56,320 -c--a-w c:\windows\system32\dllcache\chtskdic.dll + 2008-04-14 02:18:05 56,320 -c--a-w c:\windows\system32\dllcache\chtskdic.dll - 2004-08-04 01:31:54 173,568 -c--a-w c:\windows\system32\dllcache\chtskf.dll + 2008-04-14 02:18:05 173,568 -c--a-w c:\windows\system32\dllcache\chtskf.dll - 2004-08-04 01:31:54 198,656 -c--a-w c:\windows\system32\dllcache\cintime.dll + 2008-04-14 02:18:06 198,656 -c--a-w c:\windows\system32\dllcache\cintime.dll - 2004-08-04 03:45:22 28,672 -c--a-w c:\windows\system32\dllcache\custsat.dll + 2008-04-14 02:20:24 33,792 -c--a-w c:\windows\system32\dllcache\custsat.dll - 2008-06-20 17:41:07 148,992 -c--a-w c:\windows\system32\dllcache\dnsapi.dll + 2008-06-20 17:48:21 147,968 -c----w c:\windows\system32\dllcache\dnsapi.dll - 2004-08-04 03:44:50 96,768 -c--a-w c:\windows\system32\dllcache\dpcdll.dll + 2008-04-14 02:19:29 102,912 -c----w c:\windows\system32\dllcache\dpcdll.dll - 2004-08-04 03:45:52 299,520 -c--a-w c:\windows\system32\dllcache\drmclien.dll + 2008-04-14 02:21:35 299,520 -c--a-w c:\windows\system32\dllcache\drmclien.dll - 2004-08-04 03:45:22 87,040 -c--a-w c:\windows\system32\dllcache\drmstor.dll + 2008-04-14 02:20:26 87,040 -c--a-w c:\windows\system32\dllcache\drmstor.dll - 2006-08-24 16:18:32 632,886 -c--a-w c:\windows\system32\dllcache\dxmasf.dll + 2008-04-14 02:20:26 499,766 -c--a-w c:\windows\system32\dllcache\dxmasf.dll - 2008-07-07 20:31:58 253,952 -c--a-w c:\windows\system32\dllcache\es.dll + 2008-07-07 20:28:46 253,952 -c----w c:\windows\system32\dllcache\es.dll - 2004-08-04 03:45:22 380,957 -c--a-w c:\windows\system32\dllcache\expsrv.dll + 2008-04-14 02:20:26 380,445 -c--a-w c:\windows\system32\dllcache\expsrv.dll - 2008-10-23 13:00:11 283,648 -c--a-w c:\windows\system32\dllcache\gdi32.dll + 2008-10-23 12:37:45 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll - 2004-08-04 02:08:20 36,224 -c--a-w c:\windows\system32\dllcache\hidclass.sys + 2008-04-13 18:45:26 36,864 -c--a-w c:\windows\system32\dllcache\hidclass.sys - 2004-08-04 02:08:18 24,960 -c--a-w c:\windows\system32\dllcache\hidparse.sys + 2008-04-13 18:45:22 24,960 -c--a-w c:\windows\system32\dllcache\hidparse.sys - 2001-08-18 01:02:20 9,600 -c--a-w c:\windows\system32\dllcache\hidusb.sys + 2008-04-13 18:45:28 10,368 -c--a-w c:\windows\system32\dllcache\hidusb.sys - 2001-10-28 15:06:44 13,463,552 -c--a-w c:\windows\system32\dllcache\hwxjpn.dll + 2008-04-14 02:18:32 13,463,552 -c--a-w c:\windows\system32\dllcache\hwxjpn.dll - 2004-08-04 02:04:38 106,496 -c--a-w c:\windows\system32\dllcache\imekrcic.dll + 2008-04-14 02:18:35 106,496 -c--a-w c:\windows\system32\dllcache\imekrcic.dll - 2004-08-04 02:04:34 86,016 -c--a-w c:\windows\system32\dllcache\imekrmbx.dll + 2008-04-14 02:18:35 86,016 -c--a-w c:\windows\system32\dllcache\imekrmbx.dll - 2004-08-04 01:31:50 811,064 -c--a-w c:\windows\system32\dllcache\imjp81k.dll + 2008-04-14 02:18:35 811,064 -c--a-w c:\windows\system32\dllcache\imjp81k.dll - 2004-08-04 01:31:52 368,696 -c--a-w c:\windows\system32\dllcache\imjpcic.dll + 2008-04-14 02:18:35 368,696 -c--a-w c:\windows\system32\dllcache\imjpcic.dll - 2004-08-04 01:31:52 716,856 -c--a-w c:\windows\system32\dllcache\imjpcus.dll + 2008-04-14 02:18:35 716,856 -c--a-w c:\windows\system32\dllcache\imjpcus.dll - 2004-08-04 01:31:54 81,976 -c--a-w c:\windows\system32\dllcache\imjpdct.dll + 2008-04-14 02:18:35 81,976 -c--a-w c:\windows\system32\dllcache\imjpdct.dll - 2004-08-04 01:32:16 274,489 -c--a-w c:\windows\system32\dllcache\imjputyc.dll + 2008-04-14 02:18:36 274,489 -c--a-w c:\windows\system32\dllcache\imjputyc.dll - 2004-08-04 01:32:28 102,456 -c--a-w c:\windows\system32\dllcache\imlang.dll + 2008-04-14 02:18:36 102,456 -c--a-w c:\windows\system32\dllcache\imlang.dll - 2001-10-28 15:06:50 315,452 -c--a-w c:\windows\system32\dllcache\imskf.dll + 2008-04-14 02:18:36 315,455 -c--a-w c:\windows\system32\dllcache\imskf.dll - 2004-08-04 03:39:20 25,088 -c--a-w c:\windows\system32\dllcache\kbdclass.sys + 2008-04-14 01:58:36 25,088 -c--a-w c:\windows\system32\dllcache\kbdclass.sys - 2004-08-04 03:39:20 14,848 -c--a-w c:\windows\system32\dllcache\kbdhid.sys + 2008-04-14 01:58:36 14,720 -c--a-w c:\windows\system32\dllcache\kbdhid.sys - 2004-08-04 03:45:40 124,416 -c--a-w c:\windows\system32\dllcache\mplay32.exe + 2008-04-14 02:21:08 124,416 -c--a-w c:\windows\system32\dllcache\mplay32.exe - 2004-08-04 03:45:40 18,463 -c--a-w c:\windows\system32\dllcache\mplayer2.exe + 2008-04-14 02:21:08 4,639 -c--a-w c:\windows\system32\dllcache\mplayer2.exe - 2008-05-01 14:32:24 331,776 -c--a-w c:\windows\system32\dllcache\msadce.dll + 2008-05-01 14:36:56 331,776 -c--a-w c:\windows\system32\dllcache\msadce.dll - 2008-06-24 16:24:13 74,240 -c--a-w c:\windows\system32\dllcache\mscms.dll + 2008-06-24 16:43:36 74,240 -c----w c:\windows\system32\dllcache\mscms.dll - 2004-08-04 03:44:28 4,126 -c--a-w c:\windows\system32\dllcache\msdxmlc.dll + 2008-04-14 02:18:55 4,126 -c--a-w c:\windows\system32\dllcache\msdxmlc.dll - 2008-06-20 17:41:07 247,808 -c--a-w c:\windows\system32\dllcache\mswsock.dll + 2008-06-20 17:48:21 247,808 -c----w c:\windows\system32\dllcache\mswsock.dll + 2008-09-10 01:15:24 1,307,648 -c----w c:\windows\system32\dllcache\msxml6.dll + 2008-04-14 01:58:05 86,016 -c----w c:\windows\system32\dllcache\msxml6r.dll - 2004-08-04 03:45:50 226,816 -c--a-w c:\windows\system32\dllcache\npdrmv2.dll + 2008-04-14 02:21:32 226,816 -c--a-w c:\windows\system32\dllcache\npdrmv2.dll - 2005-11-29 19:27:06 364,544 -c--a-w c:\windows\system32\dllcache\npdsplay.dll + 2008-04-14 02:20:36 364,544 -c--a-w c:\windows\system32\dllcache\npdsplay.dll - 2004-08-04 03:45:26 10,240 -c--a-w c:\windows\system32\dllcache\npwmsdrm.dll + 2008-04-14 02:20:36 10,240 -c--a-w c:\windows\system32\dllcache\npwmsdrm.dll - 2004-08-04 01:32:12 15,872 -c--a-w c:\windows\system32\dllcache\padrs404.dll + 2008-04-14 02:19:20 15,872 -c--a-w c:\windows\system32\dllcache\padrs404.dll - 2004-08-04 01:31:50 15,360 -c--a-w c:\windows\system32\dllcache\padrs804.dll + 2008-04-14 02:19:20 15,360 -c--a-w c:\windows\system32\dllcache\padrs804.dll - 2004-08-04 03:44:12 24,064 -c--a-w c:\windows\system32\dllcache\pidgen.dll + 2008-04-14 02:18:21 24,064 -c----w c:\windows\system32\dllcache\pidgen.dll - 2004-08-04 01:31:50 175,104 -c--a-w c:\windows\system32\dllcache\pintlcsa.dll + 2008-04-14 02:19:21 175,104 -c--a-w c:\windows\system32\dllcache\pintlcsa.dll - 2004-08-04 01:31:50 53,760 -c--a-w c:\windows\system32\dllcache\pintlcsd.dll + 2008-04-14 02:19:21 53,760 -c--a-w c:\windows\system32\dllcache\pintlcsd.dll - 2004-08-04 01:31:50 70,144 -c--a-w c:\windows\system32\dllcache\pintlphr.exe + 2008-04-13 16:43:36 70,144 -c--a-w c:\windows\system32\dllcache\pintlphr.exe - 2004-08-04 01:31:50 67,584 -c--a-w c:\windows\system32\dllcache\pmigrate.dll + 2008-04-14 02:19:21 67,584 -c--a-w c:\windows\system32\dllcache\pmigrate.dll - 2008-05-07 05:15:38 2,660,864 -c--a-w c:\windows\system32\dllcache\quartz.dll + 2008-05-07 05:11:33 1,292,800 -c----w c:\windows\system32\dllcache\quartz.dll - 2004-08-04 03:45:28 151,552 -c--a-w c:\windows\system32\dllcache\scrrun.dll + 2008-05-09 10:55:05 172,032 -c--a-w c:\windows\system32\dllcache\scrrun.dll - 2004-08-04 03:45:28 152,576 -c--a-w c:\windows\system32\dllcache\shmedia.dll + 2008-04-14 02:20:40 153,088 -c--a-w c:\windows\system32\dllcache\shmedia.dll - 2008-06-20 10:45:13 360,320 -c--a-w c:\windows\system32\dllcache\tcpip.sys + 2008-06-20 11:51:12 361,600 -c----w c:\windows\system32\dllcache\tcpip.sys - 2008-06-20 09:52:06 225,920 -c--a-w c:\windows\system32\dllcache\tcpip6.sys + 2008-06-20 11:08:27 225,856 -c----w c:\windows\system32\dllcache\tcpip6.sys - 2004-08-04 01:32:14 10,240 -c--a-w c:\windows\system32\dllcache\tmigrate.dll + 2008-04-14 02:19:45 10,240 -c--a-w c:\windows\system32\dllcache\tmigrate.dll - 2004-08-04 02:04:12 76,288 -c--a-w c:\windows\system32\dllcache\uniime.dll + 2008-04-14 02:19:46 76,288 -c--a-w c:\windows\system32\dllcache\uniime.dll - 2004-08-04 03:45:28 30,749 -c--a-w c:\windows\system32\dllcache\vbajet32.dll + 2008-04-14 02:20:40 30,749 -c--a-w c:\windows\system32\dllcache\vbajet32.dll - 2004-08-04 01:32:36 426,041 -c--a-w c:\windows\system32\dllcache\voicepad.dll + 2008-04-14 02:19:48 426,041 -c--a-w c:\windows\system32\dllcache\voicepad.dll - 2004-08-04 01:32:36 86,073 -c--a-w c:\windows\system32\dllcache\voicesub.dll + 2008-04-14 02:19:48 86,073 -c--a-w c:\windows\system32\dllcache\voicesub.dll - 2004-08-04 03:45:28 20,480 -c--a-w c:\windows\system32\dllcache\wmpcd.dll + 2008-04-14 02:20:43 20,480 -c--a-w c:\windows\system32\dllcache\wmpcd.dll - 2004-08-04 03:45:28 20,480 -c--a-w c:\windows\system32\dllcache\wmpcore.dll + 2008-04-14 02:20:43 20,480 -c--a-w c:\windows\system32\dllcache\wmpcore.dll - 2004-08-04 03:45:28 20,480 -c--a-w c:\windows\system32\dllcache\wmpui.dll + 2008-04-14 02:20:43 20,480 -c--a-w c:\windows\system32\dllcache\wmpui.dll - 2004-08-04 03:45:28 115,200 -c--a-w c:\windows\system32\dllcache\wmsdmoe.dll + 2008-04-14 02:20:43 115,200 -c--a-w c:\windows\system32\dllcache\wmsdmoe.dll - 2004-08-04 03:45:28 303,616 -c--a-w c:\windows\system32\dllcache\wmstream.dll + 2008-04-14 02:20:43 303,616 -c--a-w c:\windows\system32\dllcache\wmstream.dll - 2004-08-04 03:45:32 5,120 ----a-w c:\windows\system32\dllhost.exe + 2008-04-14 02:20:55 5,120 ----a-w c:\windows\system32\dllhost.exe - 2004-08-04 03:45:32 225,280 ----a-w c:\windows\system32\dmadmin.exe + 2008-04-14 02:20:56 225,280 ----a-w c:\windows\system32\dmadmin.exe - 2004-08-04 03:45:22 28,672 ----a-w c:\windows\system32\dmband.dll + 2008-04-14 02:20:25 28,672 ----a-w c:\windows\system32\dmband.dll - 2004-08-04 03:45:22 61,440 ----a-w c:\windows\system32\dmcompos.dll + 2008-04-14 02:20:25 61,440 ----a-w c:\windows\system32\dmcompos.dll - 2001-10-28 15:06:18 797,696 ----a-w c:\windows\system32\dmdlgs.dll + 2008-04-14 02:20:25 285,184 ----a-w c:\windows\system32\dmdlgs.dll - 2004-08-04 03:45:22 200,704 ----a-w c:\windows\system32\dmdskmgr.dll + 2008-04-14 02:20:25 200,704 ----a-w c:\windows\system32\dmdskmgr.dll - 2004-08-04 03:45:22 181,248 ----a-w c:\windows\system32\dmime.dll + 2008-04-14 02:20:25 181,248 ----a-w c:\windows\system32\dmime.dll - 2004-08-04 03:45:22 35,840 ----a-w c:\windows\system32\dmloader.dll + 2008-04-14 02:20:25 35,840 ----a-w c:\windows\system32\dmloader.dll - 2004-08-04 03:45:32 15,872 ----a-w c:\windows\system32\dmremote.exe + 2008-04-14 02:20:56 15,872 ----a-w c:\windows\system32\dmremote.exe - 2004-08-04 03:45:22 82,432 ----a-w c:\windows\system32\dmscript.dll + 2008-04-14 02:20:25 82,432 ----a-w c:\windows\system32\dmscript.dll - 2004-08-04 03:45:22 23,552 ----a-w c:\windows\system32\dmserver.dll + 2008-04-14 02:20:25 23,552 ----a-w c:\windows\system32\dmserver.dll - 2004-08-04 03:45:22 105,984 ----a-w c:\windows\system32\dmstyle.dll + 2008-04-14 02:20:25 105,984 ----a-w c:\windows\system32\dmstyle.dll - 2004-08-04 03:45:22 103,424 ----a-w c:\windows\system32\dmsynth.dll + 2008-04-14 02:20:25 103,424 ----a-w c:\windows\system32\dmsynth.dll - 2004-08-04 03:45:22 104,448 ----a-w c:\windows\system32\dmusic.dll + 2008-04-14 02:20:25 104,448 ----a-w c:\windows\system32\dmusic.dll - 2004-08-04 03:55:42 55,296 ----a-w c:\windows\system32\dmutil.dll + 2008-04-14 02:20:25 55,296 ----a-w c:\windows\system32\dmutil.dll - 2008-06-20 17:41:07 148,992 ----a-w c:\windows\system32\dnsapi.dll + 2008-06-20 17:48:21 147,968 ----a-w c:\windows\system32\dnsapi.dll - 2008-02-20 05:37:59 45,568 ----a-w c:\windows\system32\dnsrslvr.dll + 2008-04-14 02:20:25 45,568 ----a-w c:\windows\system32\dnsrslvr.dll - 2004-08-04 03:45:22 48,640 ----a-w c:\windows\system32\docprop2.dll + 2008-04-14 02:20:25 48,640 ----a-w c:\windows\system32\docprop2.dll + 2008-04-14 02:20:25 26,112 ------w c:\windows\system32\dot3api.dll + 2008-04-14 02:20:25 59,392 ------w c:\windows\system32\dot3cfg.dll + 2008-04-14 02:20:25 9,216 ------w c:\windows\system32\dot3dlg.dll + 2008-04-14 02:20:25 39,936 ------w c:\windows\system32\dot3gpclnt.dll + 2008-04-14 02:20:25 56,832 ------w c:\windows\system32\dot3msm.dll + 2008-04-14 02:20:25 133,120 ------w c:\windows\system32\dot3svc.dll + 2008-04-14 02:20:25 651,264 ------w c:\windows\system32\dot3ui.dll Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 continuando 3: - 2004-08-04 03:44:50 96,768 ----a-w c:\windows\system32\dpcdll.dll + 2008-04-14 02:19:29 102,912 ----a-w c:\windows\system32\dpcdll.dll - 2004-08-04 03:45:32 30,208 ----a-w c:\windows\system32\dplaysvr.exe + 2008-04-14 02:20:56 29,696 ----a-w c:\windows\system32\dplaysvr.exe - 2004-08-04 03:45:22 229,888 ----a-w c:\windows\system32\dplayx.dll + 2008-04-14 02:20:25 229,888 ----a-w c:\windows\system32\dplayx.dll - 2004-08-04 03:45:22 24,064 ----a-w c:\windows\system32\dpmodemx.dll + 2008-04-14 02:20:25 24,064 ----a-w c:\windows\system32\dpmodemx.dll - 2004-08-04 03:44:10 3,584 ----a-w c:\windows\system32\dpnaddr.dll + 2008-04-14 02:18:18 3,072 ----a-w c:\windows\system32\dpnaddr.dll - 2004-08-04 03:45:22 375,296 ----a-w c:\windows\system32\dpnet.dll + 2008-04-14 02:20:26 375,296 ----a-w c:\windows\system32\dpnet.dll - 2004-08-04 03:45:22 35,328 ----a-w c:\windows\system32\dpnhpast.dll + 2008-04-14 02:20:26 35,328 ----a-w c:\windows\system32\dpnhpast.dll - 2004-08-04 03:45:22 60,928 ----a-w c:\windows\system32\dpnhupnp.dll + 2008-04-14 02:20:26 60,928 ----a-w c:\windows\system32\dpnhupnp.dll - 2004-08-04 03:44:10 3,584 ----a-w c:\windows\system32\dpnlobby.dll + 2008-04-14 02:18:18 3,072 ----a-w c:\windows\system32\dpnlobby.dll - 2004-08-04 03:45:32 18,432 ----a-w c:\windows\system32\dpnsvr.exe + 2008-04-14 02:20:56 17,920 ----a-w c:\windows\system32\dpnsvr.exe - 2004-08-04 03:45:22 21,504 ----a-w c:\windows\system32\dpvacm.dll + 2008-04-14 02:20:26 21,504 ----a-w c:\windows\system32\dpvacm.dll - 2004-08-04 03:45:22 484,352 ----a-w c:\windows\system32\dpvoice.dll + 2008-04-14 02:20:26 212,992 ----a-w c:\windows\system32\dpvoice.dll - 2004-08-04 03:45:32 83,456 ----a-w c:\windows\system32\dpvsetup.exe + 2008-04-14 02:20:56 83,456 ----a-w c:\windows\system32\dpvsetup.exe - 2004-08-04 03:45:22 116,736 ----a-w c:\windows\system32\dpvvox.dll + 2008-04-14 02:20:26 116,736 ----a-w c:\windows\system32\dpvvox.dll - 2004-08-04 03:45:22 57,856 ----a-w c:\windows\system32\dpwsockx.dll + 2008-04-14 02:20:26 57,856 ----a-w c:\windows\system32\dpwsockx.dll - 2001-10-28 15:06:30 59,904 ----a-w c:\windows\system32\driverquery.exe + 2008-04-14 02:20:56 64,512 ----a-w c:\windows\system32\driverquery.exe - 2004-08-04 03:35:08 188,416 ----a-w c:\windows\system32\drivers\acpi.sys + 2008-04-14 01:50:05 188,416 ----a-w c:\windows\system32\drivers\acpi.sys + 2008-04-14 02:20:23 4,255 ------w c:\windows\system32\drivers\adv01nt5.dll + 2008-04-14 02:20:23 3,967 ------w c:\windows\system32\drivers\adv02nt5.dll + 2008-04-14 02:20:23 3,615 ------w c:\windows\system32\drivers\adv05nt5.dll + 2008-04-14 02:20:23 3,647 ------w c:\windows\system32\drivers\adv07nt5.dll + 2008-04-14 02:20:23 3,135 ------w c:\windows\system32\drivers\adv08nt5.dll + 2008-04-14 02:20:23 3,711 ------w c:\windows\system32\drivers\adv09nt5.dll + 2008-04-14 02:20:23 3,775 ------w c:\windows\system32\drivers\adv11nt5.dll - 2006-02-15 00:22:26 142,464 ----a-w c:\windows\system32\drivers\aec.sys + 2008-04-13 16:39:23 142,592 ----a-w c:\windows\system32\drivers\aec.sys - 2008-08-14 09:51:43 138,368 ----a-w c:\windows\system32\drivers\afd.sys + 2008-08-14 10:04:36 138,496 ----a-w c:\windows\system32\drivers\afd.sys + 2008-04-13 18:36:38 42,368 ------w c:\windows\system32\drivers\agp440.sys + 2008-04-13 18:36:39 44,928 ------w c:\windows\system32\drivers\agpcpq.sys + 2008-04-13 18:36:38 42,752 ------w c:\windows\system32\drivers\alim1541.sys + 2008-04-13 18:36:39 43,008 ------w c:\windows\system32\drivers\amdagp.sys - 2004-08-04 03:55:42 41,088 ----a-w c:\windows\system32\drivers\amdk6.sys + 2008-04-14 01:51:11 41,472 ----a-w c:\windows\system32\drivers\amdk6.sys - 2004-08-04 03:55:42 41,472 ----a-w c:\windows\system32\drivers\amdk7.sys + 2008-04-14 01:51:12 41,856 ----a-w c:\windows\system32\drivers\amdk7.sys - 2004-08-04 03:55:42 60,800 ----a-w c:\windows\system32\drivers\arp1394.sys + 2008-04-13 18:51:25 60,800 ----a-w c:\windows\system32\drivers\arp1394.sys - 2004-08-04 02:05:04 14,336 ----a-w c:\windows\system32\drivers\asyncmac.sys + 2008-04-13 18:57:27 14,336 ----a-w c:\windows\system32\drivers\asyncmac.sys - 2004-08-04 01:59:44 95,360 ----a-w c:\windows\system32\drivers\atapi.sys + 2008-04-13 18:40:30 96,512 ----a-w c:\windows\system32\drivers\atapi.sys + 2004-08-04 00:29:30 56,623 ------w c:\windows\system32\drivers\ati1btxx.sys + 2004-08-04 00:29:30 11,615 ------w c:\windows\system32\drivers\ati1mdxx.sys + 2004-08-04 00:29:30 12,047 ------w c:\windows\system32\drivers\ati1pdxx.sys + 2004-08-04 00:29:32 30,671 ------w c:\windows\system32\drivers\ati1raxx.sys + 2004-08-04 00:29:32 63,663 ------w c:\windows\system32\drivers\ati1rvxx.sys + 2004-08-04 00:29:32 26,367 ------w c:\windows\system32\drivers\ati1snxx.sys + 2004-08-04 00:29:32 21,343 ------w c:\windows\system32\drivers\ati1ttxx.sys + 2004-08-04 00:29:32 36,463 ------w c:\windows\system32\drivers\ati1tuxx.sys + 2004-08-04 00:29:32 29,455 ------w c:\windows\system32\drivers\ati1xbxx.sys + 2004-08-04 00:29:32 34,735 ------w c:\windows\system32\drivers\ati1xsxx.sys + 2004-08-04 02:36:02 327,040 ------w c:\windows\system32\drivers\ati2mtaa.sys + 2004-08-04 02:36:02 701,440 ------w c:\windows\system32\drivers\ati2mtag.sys + 2004-08-04 00:29:28 57,856 ------w c:\windows\system32\drivers\atinbtxx.sys + 2004-08-04 00:29:30 13,824 ------w c:\windows\system32\drivers\atinmdxx.sys + 2004-08-04 00:29:30 14,336 ------w c:\windows\system32\drivers\atinpdxx.sys + 2004-08-04 00:29:30 52,224 ------w c:\windows\system32\drivers\atinraxx.sys + 2004-08-04 00:29:32 104,960 ------w c:\windows\system32\drivers\atinrvxx.sys + 2004-08-04 00:29:32 28,672 ------w c:\windows\system32\drivers\atinsnxx.sys + 2004-08-04 00:29:32 13,824 ------w c:\windows\system32\drivers\atinttxx.sys + 2004-08-04 00:29:32 73,216 ------w c:\windows\system32\drivers\atintuxx.sys + 2004-08-04 00:29:32 31,744 ------w c:\windows\system32\drivers\atinxbxx.sys + 2004-08-04 00:29:32 63,488 ------w c:\windows\system32\drivers\atinxsxx.sys - 2004-08-04 01:58:32 59,904 ----a-w c:\windows\system32\drivers\atmarpc.sys + 2008-04-13 18:51:25 59,904 ----a-w c:\windows\system32\drivers\atmarpc.sys - 2004-08-04 01:58:36 55,936 ----a-w c:\windows\system32\drivers\atmlane.sys + 2008-04-13 18:51:30 55,808 ----a-w c:\windows\system32\drivers\atmlane.sys + 2008-04-14 02:20:24 21,183 ------w c:\windows\system32\drivers\atv01nt5.dll + 2008-04-14 02:20:24 11,359 ------w c:\windows\system32\drivers\atv02nt5.dll + 2008-04-14 02:20:24 25,471 ------w c:\windows\system32\drivers\atv04nt5.dll + 2008-04-14 02:20:24 14,143 ------w c:\windows\system32\drivers\atv06nt5.dll + 2008-04-14 02:20:24 17,279 ------w c:\windows\system32\drivers\atv10nt5.dll - 2004-08-04 01:59:58 71,552 ----a-w c:\windows\system32\drivers\bridge.sys + 2008-04-13 18:53:23 71,552 ----a-w c:\windows\system32\drivers\bridge.sys + 2008-04-13 18:46:33 17,024 ------w c:\windows\system32\drivers\bthenum.sys + 2008-04-13 18:46:33 37,888 ------w c:\windows\system32\drivers\bthmodem.sys + 2008-04-13 18:51:34 101,120 ------w c:\windows\system32\drivers\bthpan.sys - 2008-06-14 17:59:51 272,384 ------w c:\windows\system32\drivers\bthport.sys + 2008-06-14 17:34:41 272,384 ------w c:\windows\system32\drivers\bthport.sys + 2008-04-13 18:46:31 36,480 ------w c:\windows\system32\drivers\bthprint.sys + 2008-04-13 18:46:29 18,944 ------w c:\windows\system32\drivers\bthusb.sys - 2004-08-04 02:14:12 63,744 ----a-w c:\windows\system32\drivers\cdfs.sys + 2008-04-13 19:14:21 63,744 ----a-w c:\windows\system32\drivers\cdfs.sys - 2004-08-04 01:59:54 49,536 ----a-w c:\windows\system32\drivers\cdrom.sys + 2008-04-13 18:40:46 62,976 ----a-w c:\windows\system32\drivers\cdrom.sys + 2008-04-14 02:20:24 15,423 ------w c:\windows\system32\drivers\ch7xxnt5.dll - 2004-08-04 02:14:28 49,664 ----a-w c:\windows\system32\drivers\classpnp.sys + 2008-04-13 19:16:22 49,536 ----a-w c:\windows\system32\drivers\classpnp.sys - 2004-08-04 03:55:42 40,576 ----a-w c:\windows\system32\drivers\crusoe.sys + 2008-04-14 01:57:17 40,832 ----a-w c:\windows\system32\drivers\crusoe.sys - 2004-08-04 01:59:56 36,352 ----a-w c:\windows\system32\drivers\disk.sys + 2008-04-13 18:40:47 36,352 ----a-w c:\windows\system32\drivers\disk.sys - 2004-08-04 01:59:54 14,208 ----a-w c:\windows\system32\drivers\diskdump.sys + 2008-04-13 18:40:44 14,208 ----a-w c:\windows\system32\drivers\diskdump.sys - 2004-08-04 03:39:24 800,000 ----a-w c:\windows\system32\drivers\dmboot.sys + 2008-04-14 01:59:00 800,000 ----a-w c:\windows\system32\drivers\dmboot.sys - 2004-08-04 03:39:26 153,984 ----a-w c:\windows\system32\drivers\dmio.sys + 2008-04-14 01:59:07 153,984 ----a-w c:\windows\system32\drivers\dmio.sys - 2004-08-04 02:07:40 52,864 ----a-w c:\windows\system32\drivers\DMusic.sys + 2008-04-13 18:45:01 52,864 ----a-w c:\windows\system32\drivers\dmusic.sys - 2004-08-04 01:08:00 60,288 ----a-w c:\windows\system32\drivers\drmk.sys + 2008-04-13 18:45:14 60,160 ----a-w c:\windows\system32\drivers\drmk.sys - 2004-08-04 02:07:58 2,944 ----a-w c:\windows\system32\drivers\drmkaud.sys + 2008-04-13 18:45:13 2,944 ----a-w c:\windows\system32\drivers\drmkaud.sys - 2004-08-04 02:00:56 71,040 ----a-w c:\windows\system32\drivers\dxg.sys + 2008-04-13 18:38:29 71,168 ----a-w c:\windows\system32\drivers\dxg.sys - 2004-08-04 02:14:18 143,360 ----a-w c:\windows\system32\drivers\fastfat.sys + 2008-04-13 19:14:29 143,744 ----a-w c:\windows\system32\drivers\fastfat.sys - 2004-08-04 01:59:28 27,392 ----a-w c:\windows\system32\drivers\fdc.sys + 2008-04-13 18:40:25 27,392 ----a-w c:\windows\system32\drivers\fdc.sys - 2001-10-28 15:06:32 35,072 ----a-w c:\windows\system32\drivers\fips.sys + 2008-04-14 01:52:42 44,672 ----a-w c:\windows\system32\drivers\fips.sys - 2004-08-04 01:59:28 20,480 ----a-w c:\windows\system32\drivers\flpydisk.sys + 2008-04-13 18:40:25 20,480 ----a-w c:\windows\system32\drivers\flpydisk.sys - 2006-08-21 09:14:58 128,896 ----a-w c:\windows\system32\drivers\fltmgr.sys + 2008-04-13 18:32:59 129,792 ----a-w c:\windows\system32\drivers\fltmgr.sys + 2008-04-13 18:36:40 46,464 ------w c:\windows\system32\drivers\gagp30kx.sys + 2008-04-13 16:36:05 144,384 ------w c:\windows\system32\drivers\hdaudbus.sys + 2008-04-14 01:54:34 25,728 ------w c:\windows\system32\drivers\hidbth.sys - 2004-08-04 02:08:20 36,224 ----a-w c:\windows\system32\drivers\hidclass.sys + 2008-04-13 18:45:26 36,864 ----a-w c:\windows\system32\drivers\hidclass.sys + 2008-04-13 18:45:26 19,200 ------w c:\windows\system32\drivers\hidir.sys - 2004-08-04 02:08:18 24,960 ----a-w c:\windows\system32\drivers\hidparse.sys + 2008-04-13 18:45:22 24,960 ----a-w c:\windows\system32\drivers\hidparse.sys - 2001-08-18 01:02:20 9,600 ----a-w c:\windows\system32\drivers\hidusb.sys + 2008-04-13 18:45:28 10,368 ----a-w c:\windows\system32\drivers\hidusb.sys + 2004-08-04 00:41:48 220,032 ------w c:\windows\system32\drivers\hsfbs2s2.sys + 2004-08-04 00:41:50 685,056 ------w c:\windows\system32\drivers\hsfcxts2.sys + 2004-08-04 00:41:56 1,041,536 ------w c:\windows\system32\drivers\hsfdpsp2.sys - 2006-03-17 00:33:10 262,784 ----a-w c:\windows\system32\drivers\http.sys + 2008-04-13 18:53:53 264,832 ----a-w c:\windows\system32\drivers\http.sys - 2004-08-04 03:37:16 53,760 ----a-w c:\windows\system32\drivers\i8042prt.sys + 2008-04-14 01:55:19 53,504 ----a-w c:\windows\system32\drivers\i8042prt.sys - 2004-08-04 02:00:16 41,856 ----a-w c:\windows\system32\drivers\imapi.sys + 2008-04-13 18:40:58 42,112 ----a-w c:\windows\system32\drivers\imapi.sys - 2004-08-04 03:38:28 40,192 ----a-w c:\windows\system32\drivers\intelppm.sys + 2008-04-14 01:57:13 40,448 ----a-w c:\windows\system32\drivers\intelppm.sys - 2004-08-04 02:00:08 29,056 ----a-w c:\windows\system32\drivers\ip6fw.sys + 2008-04-13 18:53:34 36,608 ----a-w c:\windows\system32\drivers\ip6fw.sys - 2004-08-04 02:04:46 20,992 ----a-w c:\windows\system32\drivers\ipinip.sys + 2008-04-13 18:57:07 20,864 ----a-w c:\windows\system32\drivers\ipinip.sys - 2004-09-29 22:28:37 134,912 ----a-w c:\windows\system32\drivers\ipnat.sys + 2008-04-13 18:57:15 152,832 ----a-w c:\windows\system32\drivers\ipnat.sys - 2004-08-04 02:14:30 74,752 ----a-w c:\windows\system32\drivers\ipsec.sys + 2008-04-13 19:19:42 75,264 ----a-w c:\windows\system32\drivers\ipsec.sys + 2008-04-13 18:45:34 46,592 ------w c:\windows\system32\drivers\irbus.sys - 2004-08-04 02:00:48 11,264 ----a-w c:\windows\system32\drivers\irenum.sys + 2008-04-13 18:54:28 11,264 ----a-w c:\windows\system32\drivers\irenum.sys - 2001-10-28 15:06:40 36,224 ----a-w c:\windows\system32\drivers\isapnp.sys + 2008-04-14 01:58:03 37,632 ----a-w c:\windows\system32\drivers\isapnp.sys - 2004-08-04 03:39:20 25,088 ----a-w c:\windows\system32\drivers\kbdclass.sys + 2008-04-14 01:58:36 25,088 ----a-w c:\windows\system32\drivers\kbdclass.sys - 2004-08-04 03:39:20 14,848 ----a-w c:\windows\system32\drivers\kbdhid.sys + 2008-04-14 01:58:36 14,720 ----a-w c:\windows\system32\drivers\kbdhid.sys - 2006-06-14 08:47:45 172,416 ----a-w c:\windows\system32\drivers\kmixer.sys + 2008-04-13 18:45:09 172,416 ----a-w c:\windows\system32\drivers\kmixer.sys - 2004-08-04 01:15:22 140,928 ----a-w c:\windows\system32\drivers\ks.sys + 2008-04-13 19:16:36 141,056 ----a-w c:\windows\system32\drivers\ks.sys - 2004-08-04 01:59:48 92,032 ----a-w c:\windows\system32\drivers\ksecdd.sys + 2008-04-13 18:31:43 92,288 ----a-w c:\windows\system32\drivers\ksecdd.sys + 2004-08-04 00:41:56 11,868 ------w c:\windows\system32\drivers\mdmxsdk.sys - 2004-08-04 03:55:42 63,744 ----a-w c:\windows\system32\drivers\mf.sys + 2008-04-13 18:36:41 63,744 ----a-w c:\windows\system32\drivers\mf.sys - 2004-08-04 03:55:42 30,336 ----a-w c:\windows\system32\drivers\modem.sys + 2008-04-14 01:50:05 30,336 ----a-w c:\windows\system32\drivers\modem.sys - 2004-08-04 03:55:42 23,552 ----a-w c:\windows\system32\drivers\mouclass.sys + 2008-04-14 01:50:10 23,552 ----a-w c:\windows\system32\drivers\mouclass.sys - 2004-08-04 01:58:32 42,240 ----a-w c:\windows\system32\drivers\mountmgr.sys + 2008-04-13 18:39:46 42,368 ----a-w c:\windows\system32\drivers\mountmgr.sys - 2007-07-06 10:05:47 72,960 ----a-w c:\windows\system32\drivers\mqac.sys + 2008-04-13 18:39:44 92,544 ----a-w c:\windows\system32\drivers\mqac.sys - 2007-12-18 09:51:35 179,584 ----a-w c:\windows\system32\drivers\mrxdav.sys + 2008-04-13 18:32:44 180,608 ----a-w c:\windows\system32\drivers\mrxdav.sys - 2008-10-24 11:10:42 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys + 2008-10-24 11:21:09 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys - 2004-08-04 02:00:42 19,072 ----a-w c:\windows\system32\drivers\msfs.sys + 2008-04-13 18:32:39 19,072 ----a-w c:\windows\system32\drivers\msfs.sys - 2004-08-04 02:04:14 35,072 ----a-w c:\windows\system32\drivers\msgpc.sys + 2008-04-13 18:56:32 35,072 ----a-w c:\windows\system32\drivers\msgpc.sys - 2004-08-04 01:58:42 7,552 ----a-w c:\windows\system32\drivers\MSKSSRV.sys + 2008-04-13 18:39:52 7,552 ----a-w c:\windows\system32\drivers\mskssrv.sys - 2004-08-04 01:58:40 5,376 ----a-w c:\windows\system32\drivers\MSPCLOCK.sys + 2008-04-13 18:39:50 5,376 ----a-w c:\windows\system32\drivers\mspclock.sys - 2004-08-04 01:58:42 4,992 ----a-w c:\windows\system32\drivers\MSPQM.sys + 2008-04-13 18:39:51 4,992 ----a-w c:\windows\system32\drivers\mspqm.sys - 2004-08-04 03:55:42 15,488 ----a-w c:\windows\system32\drivers\mssmbios.sys + 2008-04-13 18:36:46 15,488 ----a-w c:\windows\system32\drivers\mssmbios.sys + 2004-08-04 00:41:40 126,686 ------w c:\windows\system32\drivers\mtlmnt5.sys + 2004-08-04 00:41:38 1,309,184 ------w c:\windows\system32\drivers\mtlstrm.sys + 2004-08-04 00:29:38 452,736 ------w c:\windows\system32\drivers\mtxparhm.sys - 2004-08-04 02:15:22 107,904 ----a-w c:\windows\system32\drivers\mup.sys + 2008-04-13 19:17:05 105,344 ----a-w c:\windows\system32\drivers\mup.sys + 2008-04-13 18:43:55 12,672 ------w c:\windows\system32\drivers\mutohpen.sys - 2004-08-04 02:14:30 182,912 ----a-w c:\windows\system32\drivers\ndis.sys + 2008-04-13 19:20:37 182,656 ----a-w c:\windows\system32\drivers\ndis.sys - 2001-10-28 15:07:06 9,600 ----a-w c:\windows\system32\drivers\ndistapi.sys + 2008-04-13 18:57:27 10,112 ----a-w c:\windows\system32\drivers\ndistapi.sys - 2004-08-04 03:55:42 12,928 ----a-w c:\windows\system32\drivers\ndisuio.sys + 2008-04-13 18:55:58 14,592 ----a-w c:\windows\system32\drivers\ndisuio.sys - 2004-08-04 02:14:32 91,776 ----a-w c:\windows\system32\drivers\ndiswan.sys + 2008-04-13 19:20:42 91,520 ----a-w c:\windows\system32\drivers\ndiswan.sys - 2001-10-28 15:07:06 38,016 ----a-w c:\windows\system32\drivers\ndproxy.sys + 2008-04-13 18:57:29 40,576 ----a-w c:\windows\system32\drivers\ndproxy.sys - 2004-08-04 02:03:22 34,560 ----a-w c:\windows\system32\drivers\netbios.sys + 2008-04-13 18:56:02 34,688 ----a-w c:\windows\system32\drivers\netbios.sys - 2004-08-04 02:14:38 162,816 ----a-w c:\windows\system32\drivers\netbt.sys + 2008-04-13 19:21:00 162,816 ----a-w c:\windows\system32\drivers\netbt.sys - 2004-08-04 03:55:42 61,824 ----a-w c:\windows\system32\drivers\nic1394.sys + 2008-04-13 18:51:25 61,824 ----a-w c:\windows\system32\drivers\nic1394.sys - 2004-08-04 01:59:52 40,320 ----a-w c:\windows\system32\drivers\nmnt.sys + 2008-04-13 18:53:09 40,320 ----a-w c:\windows\system32\drivers\nmnt.sys - 2004-08-04 02:00:44 30,848 ----a-w c:\windows\system32\drivers\npfs.sys + 2008-04-13 18:32:39 30,848 ----a-w c:\windows\system32\drivers\npfs.sys - 2007-02-09 11:10:35 574,464 ----a-w c:\windows\system32\drivers\ntfs.sys + 2008-04-13 19:15:53 574,976 ----a-w c:\windows\system32\drivers\ntfs.sys + 2004-08-04 00:41:40 180,360 ------w c:\windows\system32\drivers\ntmtlfax.sys - 2004-08-04 02:03:36 88,448 ----a-w c:\windows\system32\drivers\nwlnkipx.sys + 2008-04-13 18:56:06 88,320 ----a-w c:\windows\system32\drivers\nwlnkipx.sys - 2006-10-13 10:23:15 163,584 ----a-w c:\windows\system32\drivers\nwrdr.sys + 2008-04-13 18:34:12 163,584 ----a-w c:\windows\system32\drivers\nwrdr.sys - 2004-08-04 03:55:42 46,592 ----a-w c:\windows\system32\drivers\p3.sys + 2008-04-14 02:02:22 46,848 ----a-w c:\windows\system32\drivers\p3.sys - 2004-08-04 03:55:42 80,384 ----a-w c:\windows\system32\drivers\parport.sys + 2008-04-14 02:02:24 80,384 ----a-w c:\windows\system32\drivers\parport.sys - 2001-10-28 15:07:16 18,688 ----a-w c:\windows\system32\drivers\partmgr.sys + 2008-04-13 18:40:49 19,712 ----a-w c:\windows\system32\drivers\partmgr.sys - 2004-08-04 03:35:08 68,992 ----a-w c:\windows\system32\drivers\pci.sys + 2008-04-14 02:02:29 68,992 ----a-w c:\windows\system32\drivers\pci.sys - 2004-08-04 01:59:42 25,088 ----a-w c:\windows\system32\drivers\pciidex.sys + 2008-04-13 18:40:29 24,960 ----a-w c:\windows\system32\drivers\pciidex.sys - 2004-08-04 03:35:10 120,064 ----a-w c:\windows\system32\drivers\pcmcia.sys + 2008-04-14 02:02:31 120,320 ----a-w c:\windows\system32\drivers\pcmcia.sys - 2004-08-04 01:15:50 145,792 ----a-w c:\windows\system32\drivers\portcls.sys + 2008-04-13 19:19:41 146,048 ----a-w c:\windows\system32\drivers\portcls.sys - 2004-08-04 03:55:42 39,424 ----a-w c:\windows\system32\drivers\processr.sys + 2008-04-14 01:51:47 39,936 ----a-w c:\windows\system32\drivers\processr.sys - 2004-08-04 02:04:20 69,120 ----a-w c:\windows\system32\drivers\psched.sys + 2008-04-13 18:56:38 69,120 ----a-w c:\windows\system32\drivers\psched.sys - 2004-08-04 02:14:24 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys + 2008-04-13 19:19:43 51,328 ----a-w c:\windows\system32\drivers\rasl2tp.sys - 2004-08-04 02:05:08 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys + 2008-04-13 18:57:32 41,472 ----a-w c:\windows\system32\drivers\raspppoe.sys - 2004-08-04 02:14:28 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys + 2008-04-13 19:19:48 48,384 ----a-w c:\windows\system32\drivers\raspptp.sys - 2006-05-05 09:47:57 174,592 ----a-w c:\windows\system32\drivers\rdbss.sys + 2008-04-13 19:28:39 175,744 ----a-w c:\windows\system32\drivers\rdbss.sys - 2004-08-04 02:01:16 196,864 ----a-w c:\windows\system32\drivers\rdpdr.sys + 2008-04-13 18:32:51 196,224 ----a-w c:\windows\system32\drivers\rdpdr.sys - 2005-06-10 04:11:19 139,528 ----a-w c:\windows\system32\drivers\rdpwd.sys + 2008-04-14 02:21:50 139,656 ----a-w c:\windows\system32\drivers\rdpwd.sys + 2004-08-04 00:41:40 13,776 ------w c:\windows\system32\drivers\recagent.sys - 2004-08-04 00:36:32 57,984 ----a-w c:\windows\system32\drivers\redbook.sys + 2008-04-14 01:53:17 58,240 ----a-w c:\windows\system32\drivers\redbook.sys + 2008-04-13 18:46:32 59,136 ------w c:\windows\system32\drivers\rfcomm.sys - 2008-05-08 12:28:49 202,752 ----a-w c:\windows\system32\drivers\rmcast.sys + 2008-05-08 14:02:52 203,136 ----a-w c:\windows\system32\drivers\rmcast.sys - 2004-08-04 02:04:32 30,080 ----a-w c:\windows\system32\drivers\rndismp.sys + 2008-04-13 18:56:49 30,592 ----a-w c:\windows\system32\drivers\rndismp.sys + 2008-04-13 18:56:49 30,592 ------w c:\windows\system32\drivers\rndismpx.sys + 2004-08-04 00:29:52 166,912 ------w c:\windows\system32\drivers\s3gnbm.sys - 2004-08-04 01:59:42 96,256 ----a-w c:\windows\system32\drivers\scsiport.sys + 2008-04-13 18:40:30 96,384 ----a-w c:\windows\system32\drivers\scsiport.sys - 2004-08-04 02:07:48 67,584 ----a-w c:\windows\system32\drivers\sdbus.sys + 2008-04-13 18:36:44 79,232 ----a-w c:\windows\system32\drivers\sdbus.sys - 2004-08-04 01:59:08 15,488 ----a-w c:\windows\system32\drivers\serenum.sys + 2008-04-13 18:40:12 15,744 ----a-w c:\windows\system32\drivers\serenum.sys - 2004-08-04 03:37:42 65,920 ----a-w c:\windows\system32\drivers\serial.sys + 2008-04-14 01:55:20 65,536 ----a-w c:\windows\system32\drivers\serial.sys - 2004-08-04 01:59:56 11,136 ----a-w c:\windows\system32\drivers\sffdisk.sys + 2008-04-13 18:40:47 11,904 ----a-w c:\windows\system32\drivers\sffdisk.sys + 2008-04-13 18:40:48 10,240 ------w c:\windows\system32\drivers\sffp_mmc.sys - 2004-08-04 01:59:56 10,240 ----a-w c:\windows\system32\drivers\sffp_sd.sys + 2008-04-13 18:40:47 11,008 ----a-w c:\windows\system32\drivers\sffp_sd.sys - 2004-08-04 01:59:56 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys + 2008-04-13 18:40:48 11,392 ----a-w c:\windows\system32\drivers\sfloppy.sys + 2008-04-14 02:20:40 3,901 ------w c:\windows\system32\drivers\siint5.dll + 2008-04-13 18:36:39 40,960 ------w c:\windows\system32\drivers\sisagp.sys + 2004-08-04 00:41:42 129,535 ------w c:\windows\system32\drivers\slnt7554.sys + 2004-08-04 00:41:44 404,990 ------w c:\windows\system32\drivers\slntamr.sys + 2004-08-04 00:41:46 95,424 ------w c:\windows\system32\drivers\slnthal.sys + 2004-08-04 00:41:46 13,240 ------w c:\windows\system32\drivers\slwdmsup.sys + 2008-04-13 18:36:34 5,888 ------w c:\windows\system32\drivers\smbali.sys - 2004-08-04 03:55:42 25,472 ----a-w c:\windows\system32\drivers\sonydcam.sys + 2008-04-13 18:46:07 25,344 ----a-w c:\windows\system32\drivers\sonydcam.sys - 2006-06-14 08:47:46 6,400 ----a-w c:\windows\system32\drivers\splitter.sys + 2008-04-13 18:45:07 6,272 ----a-w c:\windows\system32\drivers\splitter.sys - 2004-08-04 03:41:04 73,472 ----a-w c:\windows\system32\drivers\sr.sys + 2008-04-14 02:02:36 73,472 ----a-w c:\windows\system32\drivers\sr.sys - 2004-08-04 01:08:04 48,640 ----a-w c:\windows\system32\drivers\stream.sys + 2008-04-13 18:45:15 49,408 ----a-w c:\windows\system32\drivers\stream.sys - 2004-08-04 03:55:42 4,352 ----a-w c:\windows\system32\drivers\swenum.sys + 2008-04-13 18:39:53 4,352 ----a-w c:\windows\system32\drivers\swenum.sys - 2001-08-18 01:00:52 54,272 ----a-w c:\windows\system32\drivers\swmidi.sys + 2008-04-13 18:45:09 56,576 ----a-w c:\windows\system32\drivers\swmidi.sys - 2004-08-04 02:15:56 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys + 2008-04-13 19:15:55 60,800 ----a-w c:\windows\system32\drivers\sysaudio.sys - 2004-08-04 02:00:00 14,976 ----a-w c:\windows\system32\drivers\tape.sys + 2008-04-13 18:40:50 14,976 ----a-w c:\windows\system32\drivers\tape.sys - 2008-06-20 10:45:13 360,320 ----a-w c:\windows\system32\drivers\tcpip.sys + 2008-06-20 11:51:12 361,600 ----a-w c:\windows\system32\drivers\tcpip.sys - 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\drivers\tcpip6.sys + 2008-06-20 11:08:27 225,856 ----a-w c:\windows\system32\drivers\tcpip6.sys - 2004-08-04 02:07:50 18,560 ----a-w c:\windows\system32\drivers\tdi.sys + 2008-04-13 19:00:05 19,072 ----a-w c:\windows\system32\drivers\tdi.sys - 2004-08-04 03:45:56 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys + 2008-04-14 02:21:49 12,040 ----a-w c:\windows\system32\drivers\tdpipe.sys - 2004-08-04 03:45:56 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys + 2008-04-14 02:21:49 21,896 ----a-w c:\windows\system32\drivers\tdtcp.sys - 2004-08-04 03:45:54 40,840 ----a-w c:\windows\system32\drivers\termdd.sys + 2008-04-14 02:21:48 40,840 ----a-w c:\windows\system32\drivers\termdd.sys - 2004-08-04 03:55:42 12,416 ----a-w c:\windows\system32\drivers\tunmp.sys + 2008-04-13 18:56:01 12,288 ----a-w c:\windows\system32\drivers\tunmp.sys + 2008-04-13 18:36:40 44,672 ------w c:\windows\system32\drivers\uagp35.sys - 2004-08-04 02:00:32 66,176 ----a-w c:\windows\system32\drivers\udfs.sys + 2008-04-13 18:32:36 66,048 ----a-w c:\windows\system32\drivers\udfs.sys - 2004-08-04 01:58:34 209,408 ----a-w c:\windows\system32\drivers\update.sys + 2008-04-13 18:39:46 384,768 ----a-w c:\windows\system32\drivers\update.sys - 2004-08-04 02:04:34 12,672 ----a-w c:\windows\system32\drivers\usb8023.sys + 2008-04-13 18:56:49 12,800 ----a-w c:\windows\system32\drivers\usb8023.sys + 2008-04-13 18:56:49 12,800 ------w c:\windows\system32\drivers\usb8023x.sys - 2001-10-28 15:06:30 23,808 ----a-w c:\windows\system32\drivers\usbcamd.sys + 2008-04-13 18:45:40 25,600 ----a-w c:\windows\system32\drivers\usbcamd.sys - 2001-10-28 15:06:30 23,936 ----a-w c:\windows\system32\drivers\usbcamd2.sys + 2008-04-13 18:45:41 25,728 ----a-w c:\windows\system32\drivers\usbcamd2.sys - 2004-08-04 02:08:48 31,616 ----a-w c:\windows\system32\drivers\usbccgp.sys + 2008-04-13 18:45:39 32,128 ----a-w c:\windows\system32\drivers\usbccgp.sys - 2004-08-04 02:08:38 26,624 ----a-w c:\windows\system32\drivers\usbehci.sys + 2008-04-13 18:45:35 30,208 ----a-w c:\windows\system32\drivers\usbehci.sys - 2004-08-04 02:08:44 57,600 ----a-w c:\windows\system32\drivers\usbhub.sys + 2008-04-13 18:45:37 59,520 ----a-w c:\windows\system32\drivers\usbhub.sys - 2004-08-04 03:55:42 16,000 ----a-w c:\windows\system32\drivers\usbintel.sys + 2008-04-13 18:45:43 15,872 ----a-w c:\windows\system32\drivers\usbintel.sys - 2004-08-04 02:08:38 17,024 ----a-w c:\windows\system32\drivers\usbohci.sys + 2008-04-13 18:45:35 17,152 ----a-w c:\windows\system32\drivers\usbohci.sys - 2004-08-04 02:08:44 142,976 ----a-w c:\windows\system32\drivers\usbport.sys + 2008-04-13 18:45:36 143,872 ----a-w c:\windows\system32\drivers\usbport.sys - 2004-08-04 02:01:26 25,856 ----a-w c:\windows\system32\drivers\usbprint.sys + 2008-04-13 18:47:37 25,856 ----a-w c:\windows\system32\drivers\usbprint.sys - 2004-08-04 01:58:46 15,104 ----a-w c:\windows\system32\drivers\usbscan.sys + 2008-04-13 18:45:34 15,104 ----a-w c:\windows\system32\drivers\usbscan.sys - 2004-08-04 02:08:48 26,496 ----a-w c:\windows\system32\drivers\USBSTOR.SYS + 2008-04-13 18:45:38 26,368 ----a-w c:\windows\system32\drivers\usbstor.sys + 2008-04-13 18:46:20 121,984 ------w c:\windows\system32\drivers\usbvideo.sys + 2008-04-14 02:20:40 11,325 ------w c:\windows\system32\drivers\vchnt5.dll - 2004-08-04 02:07:08 20,992 ----a-w c:\windows\system32\drivers\vga.sys + 2008-04-13 18:44:40 20,992 ----a-w c:\windows\system32\drivers\vga.sys + 2008-04-13 18:36:40 42,240 ------w c:\windows\system32\drivers\viaagp.sys - 2004-08-04 02:07:06 79,744 ----a-w c:\windows\system32\drivers\videoprt.sys + 2008-04-13 18:44:40 81,664 ----a-w c:\windows\system32\drivers\videoprt.sys - 2004-08-04 03:37:30 53,248 ----a-w c:\windows\system32\drivers\volsnap.sys + 2008-04-14 01:53:00 53,248 ----a-w c:\windows\system32\drivers\volsnap.sys + 2008-04-13 18:43:55 14,208 ------w c:\windows\system32\drivers\wacompen.sys + 2004-08-04 00:29:40 11,807 ------w c:\windows\system32\drivers\wadv07nt.sys + 2004-08-04 00:29:40 11,295 ------w c:\windows\system32\drivers\wadv08nt.sys + 2004-08-04 00:29:42 11,871 ------w c:\windows\system32\drivers\wadv09nt.sys + 2004-08-04 00:29:42 11,935 ------w c:\windows\system32\drivers\wadv11nt.sys - 2004-08-04 02:04:58 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys + 2008-04-13 18:57:21 34,560 ----a-w c:\windows\system32\drivers\wanarp.sys + 2004-08-04 00:29:46 22,271 ------w c:\windows\system32\drivers\watv06nt.sys + 2004-08-04 00:29:46 25,471 ------w c:\windows\system32\drivers\watv10nt.sys - 2006-06-14 09:00:45 82,944 ----a-w c:\windows\system32\drivers\wdmaud.sys + 2008-04-13 19:17:18 83,072 ----a-w c:\windows\system32\drivers\wdmaud.sys - 2004-08-04 03:45:52 299,520 ----a-w c:\windows\system32\drmclien.dll + 2008-04-14 02:21:35 299,520 ----a-w c:\windows\system32\drmclien.dll - 2004-08-04 03:45:22 87,040 ----a-w c:\windows\system32\drmstor.dll + 2008-04-14 02:20:26 87,040 ----a-w c:\windows\system32\drmstor.dll - 2004-08-04 03:45:22 14,336 ----a-w c:\windows\system32\drprov.dll + 2008-04-14 02:20:26 14,336 ----a-w c:\windows\system32\drprov.dll - 2004-08-04 03:45:22 16,384 ----a-w c:\windows\system32\ds32gt.dll + 2008-04-14 02:20:26 16,384 ----a-w c:\windows\system32\ds32gt.dll - 2004-08-04 03:45:22 181,760 ----a-w c:\windows\system32\dsdmo.dll + 2008-04-14 02:20:26 181,248 ----a-w c:\windows\system32\dsdmo.dll - 2004-08-04 03:45:22 71,680 ----a-w c:\windows\system32\dsdmoprp.dll + 2008-04-14 02:20:26 71,680 ----a-w c:\windows\system32\dsdmoprp.dll - 2004-08-04 03:45:22 93,184 ----a-w c:\windows\system32\dskquota.dll + 2008-04-14 02:20:26 93,184 ----a-w c:\windows\system32\dskquota.dll - 2001-10-28 15:06:30 171,520 ----a-w c:\windows\system32\dskquoui.dll + 2008-04-14 02:20:26 158,208 ----a-w c:\windows\system32\dskquoui.dll - 2004-08-04 03:45:22 367,616 ----a-w c:\windows\system32\dsound.dll + 2008-04-14 02:20:26 367,616 ----a-w c:\windows\system32\dsound.dll - 2004-08-04 03:45:22 1,294,336 ----a-w c:\windows\system32\dsound3d.dll + 2008-04-14 02:20:26 1,293,824 ----a-w c:\windows\system32\dsound3d.dll - 2004-08-04 03:45:22 143,872 ----a-w c:\windows\system32\dsprop.dll + 2008-04-14 02:20:26 144,384 ----a-w c:\windows\system32\dsprop.dll - 2004-08-04 03:44:10 4,096 ----a-w c:\windows\system32\dsprpres.dll + 2008-04-14 02:00:13 4,096 ----a-w c:\windows\system32\dsprpres.dll - 2004-08-04 03:45:22 196,096 ----a-w c:\windows\system32\dsquery.dll + 2008-04-14 02:20:26 240,128 ----a-w c:\windows\system32\dsquery.dll - 2004-08-04 03:45:22 51,712 ----a-w c:\windows\system32\dssec.dll + 2008-04-14 02:20:26 51,712 ----a-w c:\windows\system32\dssec.dll - 2004-08-04 01:31:44 137,216 ----a-w c:\windows\system32\dssenh.dll + 2008-04-13 17:37:57 138,752 ----a-w c:\windows\system32\dssenh.dll - 2004-08-04 03:45:22 228,864 ----a-w c:\windows\system32\dsuiext.dll + 2008-04-14 02:20:26 113,664 ----a-w c:\windows\system32\dsuiext.dll - 2004-08-04 03:45:22 19,456 ----a-w c:\windows\system32\dswave.dll + 2008-04-14 02:20:26 19,456 ----a-w c:\windows\system32\dswave.dll - 2004-08-04 03:45:32 10,752 ----a-w c:\windows\system32\dumprep.exe + 2008-04-14 02:20:56 10,752 ----a-w c:\windows\system32\dumprep.exe - 2004-08-04 03:45:22 304,128 ----a-w c:\windows\system32\duser.dll + 2008-04-14 02:20:26 304,128 ----a-w c:\windows\system32\duser.dll - 2004-08-04 03:45:32 17,920 ----a-w c:\windows\system32\dvdupgrd.exe + 2008-04-14 02:20:56 17,920 ----a-w c:\windows\system32\dvdupgrd.exe - 2004-08-04 03:45:32 180,224 ----a-w c:\windows\system32\dwwin.exe + 2008-04-14 02:20:56 180,224 ----a-w c:\windows\system32\dwwin.exe - 2004-08-04 03:45:22 619,008 ----a-w c:\windows\system32\dx7vb.dll + 2008-04-14 02:20:26 619,008 ----a-w c:\windows\system32\dx7vb.dll - 2004-08-04 03:45:22 1,227,264 ----a-w c:\windows\system32\dx8vb.dll + 2008-04-14 02:20:26 1,227,264 ----a-w c:\windows\system32\dx8vb.dll - 2004-08-04 03:45:32 1,298,432 ----a-w c:\windows\system32\dxdiag.exe + 2008-04-14 02:20:56 1,298,432 ----a-w c:\windows\system32\dxdiag.exe - 2004-08-04 03:45:22 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll + 2008-04-14 02:20:26 2,113,536 ----a-w c:\windows\system32\dxdiagn.dll - 2006-08-24 16:18:32 632,886 ----a-w c:\windows\system32\dxmasf.dll + 2008-04-14 02:20:26 499,766 ----a-w c:\windows\system32\dxmasf.dll - 2008-10-16 10:39:07 357,888 ----a-w c:\windows\system32\dxtmsft.dll + 2008-04-14 02:20:26 357,888 ----a-w c:\windows\system32\dxtmsft.dll - 2008-10-16 10:39:07 205,312 ----a-w c:\windows\system32\dxtrans.dll + 2008-04-14 02:20:26 205,312 ----a-w c:\windows\system32\dxtrans.dll + 2008-04-14 02:20:26 30,720 ------w c:\windows\system32\eapolqec.dll + 2008-04-14 02:20:26 184,832 ------w c:\windows\system32\eapp3hst.dll + 2008-04-14 02:20:26 126,976 ------w c:\windows\system32\eappcfg.dll + 2008-04-14 02:20:26 94,720 ------w c:\windows\system32\eappgnui.dll + 2008-04-14 02:20:26 180,224 ------w c:\windows\system32\eapphost.dll + 2008-04-14 02:20:26 40,960 ------w c:\windows\system32\eappprxy.dll + 2008-04-14 02:20:26 59,392 ------w c:\windows\system32\eapqec.dll + 2008-04-14 02:20:26 33,792 ------w c:\windows\system32\eapsvc.dll - 2004-08-04 03:45:22 27,136 ----a-w c:\windows\system32\efsadu.dll + 2008-04-14 02:20:26 27,136 ----a-w c:\windows\system32\efsadu.dll - 2004-08-04 03:45:22 322,560 ----a-w c:\windows\system32\els.dll + 2008-04-14 02:20:26 185,344 ----a-w c:\windows\system32\els.dll - 2004-08-04 03:45:22 20,480 ----a-w c:\windows\system32\encapi.dll + 2008-04-14 02:20:26 20,480 ----a-w c:\windows\system32\encapi.dll - 2004-08-04 03:45:22 186,368 ----a-w c:\windows\system32\encdec.dll + 2008-04-14 02:20:26 186,880 ----a-w c:\windows\system32\encdec.dll - 2004-08-04 03:45:22 23,040 ----a-w c:\windows\system32\ersvc.dll + 2008-04-14 02:20:26 23,040 ----a-w c:\windows\system32\ersvc.dll - 2008-07-07 20:31:58 253,952 ----a-w c:\windows\system32\es.dll + 2008-07-07 20:28:46 253,952 ----a-w c:\windows\system32\es.dll - 2005-10-20 22:25:15 1,092,096 ----a-w c:\windows\system32\esent.dll + 2008-04-14 02:20:26 1,092,096 ----a-w c:\windows\system32\esent.dll - 2004-08-04 03:45:34 194,560 ----a-w c:\windows\system32\eudcedit.exe + 2008-04-14 02:20:57 194,560 ----a-w c:\windows\system32\eudcedit.exe - 2004-08-04 03:45:34 51,712 ----a-w c:\windows\system32\eventcreate.exe + 2008-04-14 02:20:57 52,224 ----a-w c:\windows\system32\eventcreate.exe - 2004-08-04 03:45:22 55,808 ----a-w c:\windows\system32\eventlog.dll + 2008-04-14 02:20:26 56,320 ----a-w c:\windows\system32\eventlog.dll - 2001-10-28 15:06:32 79,872 ----a-w c:\windows\system32\eventtriggers.exe + 2008-04-14 02:20:58 84,992 ----a-w c:\windows\system32\eventtriggers.exe - 2004-08-04 03:45:22 380,957 ----a-w c:\windows\system32\expsrv.dll + 2008-04-14 02:20:26 380,445 ----a-w c:\windows\system32\expsrv.dll - 2008-10-16 10:39:07 55,808 ----a-w c:\windows\system32\extmgr.dll + 2008-04-14 02:20:26 55,808 ----a-w c:\windows\system32\extmgr.dll - 2004-08-04 03:45:34 45,568 ----a-w c:\windows\system32\extrac32.exe + 2008-04-14 02:20:58 24,064 ----a-w c:\windows\system32\extrac32.exe - 2001-10-28 15:06:32 121,856 ----a-w c:\windows\system32\exts.dll + 2008-04-14 02:20:26 125,952 ----a-w c:\windows\system32\exts.dll - 2004-08-04 03:45:22 80,896 ----a-w c:\windows\system32\faultrep.dll + 2008-04-14 02:20:26 80,896 ----a-w c:\windows\system32\faultrep.dll + 2008-04-14 02:20:58 20,992 ------w c:\windows\system32\faxpatch.exe - 2001-10-28 15:06:32 118,784 ----a-w c:\windows\system32\fde.dll + 2008-04-14 02:20:26 125,952 ----a-w c:\windows\system32\fde.dll - 2004-08-04 03:45:22 75,264 ----a-w c:\windows\system32\fdeploy.dll + 2008-04-14 02:20:26 75,264 ----a-w c:\windows\system32\fdeploy.dll - 2004-08-04 03:45:22 21,504 ----a-w c:\windows\system32\feclient.dll + 2008-04-14 02:20:26 21,504 ----a-w c:\windows\system32\feclient.dll - 2004-08-04 03:45:22 369,152 ----a-w c:\windows\system32\filemgmt.dll + 2008-04-14 02:20:26 342,528 ----a-w c:\windows\system32\filemgmt.dll - 2004-08-04 03:45:34 28,672 ----a-w c:\windows\system32\findstr.exe + 2008-04-14 02:20:58 28,672 ----a-w c:\windows\system32\findstr.exe - 2004-08-04 03:45:22 222,208 ----a-w c:\windows\system32\fldrclnr.dll + 2008-04-14 02:20:26 88,576 ----a-w c:\windows\system32\fldrclnr.dll - 2006-08-21 12:27:07 16,896 ----a-w c:\windows\system32\fltlib.dll + 2008-04-14 02:20:26 16,896 ----a-w c:\windows\system32\fltlib.dll - 2006-08-21 09:14:58 23,040 ----a-w c:\windows\system32\fltmc.exe + 2008-04-14 02:20:58 23,040 ----a-w c:\windows\system32\fltmc.exe - 2008-12-28 20:36:43 627,592 ----a-w c:\windows\system32\FNTCACHE.DAT + 2009-01-23 22:43:42 628,392 ----a-w c:\windows\system32\FNTCACHE.DAT - 2004-08-04 03:45:22 1,181,696 ----a-w c:\windows\system32\fontext.dll + 2008-04-14 02:20:26 384,512 ----a-w c:\windows\system32\fontext.dll - 2005-10-17 21:21:02 80,896 ----a-w c:\windows\system32\fontsub.dll + 2008-04-14 02:20:26 80,896 ----a-w c:\windows\system32\fontsub.dll - 2004-08-04 03:45:34 21,504 ----a-w c:\windows\system32\fontview.exe + 2008-04-14 02:20:58 21,504 ----a-w c:\windows\system32\fontview.exe - 2001-10-28 15:06:32 7,168 ----a-w c:\windows\system32\forcedos.exe + 2008-04-14 02:20:58 7,680 ----a-w c:\windows\system32\forcedos.exe - 2001-10-28 15:06:32 25,600 ----a-w c:\windows\system32\format.com + 2008-04-14 02:21:25 29,696 ----a-w c:\windows\system32\format.com - 2004-08-04 03:44:16 9,344 ----a-w c:\windows\system32\framebuf.dll + 2008-04-14 02:18:27 9,344 ----a-w c:\windows\system32\framebuf.dll - 2004-08-04 03:45:34 399,360 ----a-w c:\windows\system32\fsquirt.exe + 2008-04-14 02:20:59 193,024 ----a-w c:\windows\system32\fsquirt.exe - 2004-08-04 03:45:34 45,056 ----a-w c:\windows\system32\ftp.exe + 2008-04-14 02:20:59 45,056 ----a-w c:\windows\system32\ftp.exe - 2004-08-04 03:45:22 60,416 ----a-w c:\windows\system32\fwcfg.dll + 2008-04-14 02:20:27 60,416 ----a-w c:\windows\system32\fwcfg.dll - 2008-10-23 13:00:11 283,648 ----a-w c:\windows\system32\gdi32.dll + 2008-10-23 12:37:45 286,720 ----a-w c:\windows\system32\gdi32.dll - 2001-10-28 15:06:34 56,832 ----a-w c:\windows\system32\getmac.exe + 2008-04-14 02:21:00 61,440 ----a-w c:\windows\system32\getmac.exe - 2004-08-04 03:45:24 123,904 ----a-w c:\windows\system32\glu32.dll + 2008-04-14 02:20:27 123,904 ----a-w c:\windows\system32\glu32.dll - 2004-08-04 03:44:18 585,728 ----a-w c:\windows\system32\gpedit.dll + 2008-04-14 02:18:30 572,928 ----a-w c:\windows\system32\gpedit.dll - 2004-08-04 03:44:18 10,240 ----a-w c:\windows\system32\gpkrsrc.dll + 2008-04-14 01:54:04 10,240 ----a-w c:\windows\system32\gpkrsrc.dll - 2004-08-04 03:45:36 122,368 ----a-w c:\windows\system32\gpresult.exe + 2008-04-14 02:21:00 123,392 ----a-w c:\windows\system32\gpresult.exe - 2004-08-04 03:45:24 200,192 ----a-w c:\windows\system32\gptext.dll + 2008-04-14 02:20:27 201,216 ----a-w c:\windows\system32\gptext.dll - 2004-08-04 03:45:36 39,424 ----a-w c:\windows\system32\grpconv.exe + 2008-04-14 02:21:00 39,424 ----a-w c:\windows\system32\grpconv.exe - 2004-08-04 03:45:24 614,912 ----a-w c:\windows\system32\h323msp.dll + 2008-04-14 02:20:27 614,912 ----a-w c:\windows\system32\h323msp.dll - 2004-08-04 01:59:10 131,968 ----a-w c:\windows\system32\hal.dll + 2008-04-13 18:31:28 131,840 ----a-w c:\windows\system32\HAL.DLL - 2004-08-04 03:45:24 7,168 ----a-w c:\windows\system32\hccoin.dll + 2008-04-14 02:20:27 7,168 ----a-w c:\windows\system32\hccoin.dll - 2001-10-28 15:06:34 15,360 ----a-w c:\windows\system32\help.exe + 2008-04-14 02:21:00 16,384 ----a-w c:\windows\system32\help.exe - 2005-05-27 02:07:52 41,472 ----a-w c:\windows\system32\hhsetup.dll + 2008-04-14 02:20:27 41,472 ----a-w c:\windows\system32\hhsetup.dll - 2004-08-04 03:55:42 20,992 ----a-w c:\windows\system32\hid.dll + 2008-04-14 02:20:27 20,992 ----a-w c:\windows\system32\hid.dll - 2004-08-04 03:45:24 21,504 ----a-w c:\windows\system32\hidserv.dll + 2008-04-14 02:20:28 21,504 ----a-w c:\windows\system32\hidserv.dll - 2006-07-21 08:28:16 72,704 ----a-w c:\windows\system32\hlink.dll + 2008-04-14 02:20:28 72,704 ----a-w c:\windows\system32\hlink.dll - 2004-08-04 03:45:24 346,624 ----a-w c:\windows\system32\hnetcfg.dll + 2008-04-14 02:20:28 346,624 ----a-w c:\windows\system32\hnetcfg.dll - 2004-08-04 03:45:24 740,352 ----a-w c:\windows\system32\hnetwiz.dll + 2008-04-14 02:20:28 334,848 ----a-w c:\windows\system32\hnetwiz.dll - 2004-08-04 03:45:24 168,960 ----a-w c:\windows\system32\hotplug.dll + 2008-04-14 02:20:28 146,432 ----a-w c:\windows\system32\hotplug.dll + 2008-04-14 02:20:28 32,285 ------w c:\windows\system32\hsfcisp2.dll - 2004-08-04 03:45:24 24,576 ----a-w c:\windows\system32\httpapi.dll + 2008-04-14 02:20:28 24,576 ----a-w c:\windows\system32\httpapi.dll - 2004-08-04 03:45:24 42,496 ----a-w c:\windows\system32\htui.dll + 2008-04-14 02:20:28 42,496 ----a-w c:\windows\system32\htui.dll - 2004-11-17 17:43:08 352,768 ----a-w c:\windows\system32\hypertrm.dll + 2008-04-14 02:20:28 352,768 ----a-w c:\windows\system32\hypertrm.dll - 2004-08-04 03:45:24 119,808 ----a-w c:\windows\system32\iasrad.dll + 2008-04-14 02:20:28 119,808 ----a-w c:\windows\system32\iasrad.dll - 2004-08-04 03:45:24 11,264 ----a-w c:\windows\system32\icaapi.dll + 2008-04-14 02:20:28 11,264 ----a-w c:\windows\system32\icaapi.dll - 2004-08-04 03:45:24 80,384 ----a-w c:\windows\system32\iccvid.dll + 2008-04-14 02:20:28 80,384 ----a-w c:\windows\system32\iccvid.dll - 2005-06-29 01:49:48 254,976 ----a-w c:\windows\system32\icm32.dll + 2008-04-14 02:20:28 254,976 ----a-w c:\windows\system32\icm32.dll - 2004-08-04 03:44:20 3,584 ----a-w c:\windows\system32\icmp.dll + 2008-04-14 02:18:33 3,584 ----a-w c:\windows\system32\icmp.dll - 2004-08-04 03:45:24 73,728 ----a-w c:\windows\system32\icwdial.dll + 2008-04-14 02:20:28 73,728 ----a-w c:\windows\system32\icwdial.dll - 2004-08-04 03:45:24 65,536 ----a-w c:\windows\system32\icwphbk.dll + 2008-04-14 02:20:28 65,536 ----a-w c:\windows\system32\icwphbk.dll - 2004-08-04 03:45:24 121,344 ----a-w c:\windows\system32\idq.dll + 2008-04-14 02:20:28 121,344 ----a-w c:\windows\system32\idq.dll - 2004-08-04 03:45:36 34,304 ----a-w c:\windows\system32\ie4uinit.exe + 2008-04-14 02:21:01 34,304 ----a-w c:\windows\system32\ie4uinit.exe - 2004-08-04 03:45:24 139,264 ----a-w c:\windows\system32\ieakeng.dll + 2008-04-14 02:20:28 143,360 ----a-w c:\windows\system32\ieakeng.dll - 2004-08-04 03:45:24 220,160 ----a-w c:\windows\system32\ieaksie.dll + 2008-04-14 02:20:28 220,160 ----a-w c:\windows\system32\ieaksie.dll - 2004-08-04 03:45:24 323,584 ----a-w c:\windows\system32\iedkcs32.dll + 2008-04-14 02:20:28 323,584 ----a-w c:\windows\system32\iedkcs32.dll - 2004-08-04 03:45:24 81,920 ----a-w c:\windows\system32\ieencode.dll + 2008-04-14 02:20:28 81,920 ----a-w c:\windows\system32\ieencode.dll - 2008-10-16 10:39:07 251,392 ----a-w c:\windows\system32\iepeers.dll + 2008-04-14 02:20:28 251,904 ----a-w c:\windows\system32\iepeers.dll - 2004-08-04 03:45:24 48,640 ----a-w c:\windows\system32\iernonce.dll + 2008-04-14 02:20:28 48,640 ----a-w c:\windows\system32\iernonce.dll - 2004-08-04 03:45:24 63,488 ----a-w c:\windows\system32\iesetup.dll + 2008-04-14 02:20:28 63,488 ----a-w c:\windows\system32\iesetup.dll - 2004-08-04 03:45:36 204,800 ----a-w c:\windows\system32\iexpress.exe + 2008-04-14 02:21:02 114,688 ----a-w c:\windows\system32\iexpress.exe - 2004-08-04 03:45:24 137,728 ----a-w c:\windows\system32\ifmon.dll + 2008-04-14 02:20:28 137,728 ----a-w c:\windows\system32\ifmon.dll - 2004-08-04 03:45:24 8,192 ----a-w c:\windows\system32\igmpagnt.dll + 2008-04-14 02:20:28 8,192 ----a-w c:\windows\system32\igmpagnt.dll - 2004-08-04 03:45:24 81,920 ----a-w c:\windows\system32\ils.dll + 2008-04-14 02:20:28 81,920 ----a-w c:\windows\system32\ils.dll - 2004-08-04 03:45:24 144,384 ----a-w c:\windows\system32\imagehlp.dll + 2008-04-14 02:20:28 144,384 ----a-w c:\windows\system32\imagehlp.dll - 2004-08-04 03:45:36 150,016 ----a-w c:\windows\system32\imapi.exe + 2008-04-14 02:21:02 150,528 ----a-w c:\windows\system32\imapi.exe - 2004-08-04 03:45:24 36,921 ----a-w c:\windows\system32\imeshare.dll + 2008-04-14 02:20:28 36,921 ----a-w c:\windows\system32\imeshare.dll - 2004-08-04 03:45:24 35,840 ----a-w c:\windows\system32\imgutil.dll + 2008-04-14 02:20:28 35,840 ----a-w c:\windows\system32\imgutil.dll - 2004-08-04 03:45:24 110,080 ----a-w c:\windows\system32\imm32.dll + 2008-04-14 02:20:28 110,080 ----a-w c:\windows\system32\imm32.dll - 2004-08-04 03:45:24 278,528 ----a-w c:\windows\system32\inetcfg.dll + 2008-04-14 02:20:28 278,528 ----a-w c:\windows\system32\inetcfg.dll - 2008-04-11 18:51:08 683,520 ----a-w c:\windows\system32\inetcomm.dll + 2008-04-11 19:05:45 691,712 ----a-w c:\windows\system32\inetcomm.dll - 2004-08-04 03:45:24 33,280 ----a-w c:\windows\system32\inetmib1.dll + 2008-04-14 02:20:28 32,768 ----a-w c:\windows\system32\inetmib1.dll - 2004-08-04 03:45:24 75,264 ----a-w c:\windows\system32\inetpp.dll + 2008-04-14 02:20:28 75,264 ----a-w c:\windows\system32\inetpp.dll - 2004-08-04 03:45:24 15,872 ----a-w c:\windows\system32\inetppui.dll + 2008-04-14 02:20:28 15,872 ----a-w c:\windows\system32\inetppui.dll - 2004-08-04 03:44:20 57,344 ----a-w c:\windows\system32\inetres.dll + 2008-04-14 01:56:50 49,664 ----a-w c:\windows\system32\inetres.dll + 2008-04-14 02:20:40 221,696 ------w c:\windows\system32\inetsrv\seo.dll + 2008-04-14 02:20:40 189,952 ------w c:\windows\system32\inetsrv\smtpadm.dll + 2008-04-14 02:20:40 2,134,528 ------w c:\windows\system32\inetsrv\smtpsnap.dll - 2004-08-04 03:45:24 147,456 ----a-w c:\windows\system32\initpki.dll + 2008-04-14 02:20:28 147,456 ----a-w c:\windows\system32\initpki.dll - 2004-08-04 03:45:24 126,464 ----a-w c:\windows\system32\input.dll + 2008-04-14 02:20:28 125,440 ----a-w c:\windows\system32\input.dll - 2008-10-16 10:39:07 96,768 ----a-w c:\windows\system32\inseng.dll + 2008-04-14 02:20:28 96,768 ----a-w c:\windows\system32\inseng.dll - 2004-08-04 03:45:36 56,832 ----a-w c:\windows\system32\ipconfig.exe + 2008-04-14 02:21:02 56,832 ----a-w c:\windows\system32\ipconfig.exe - 2006-05-19 13:23:33 95,744 ----a-w c:\windows\system32\iphlpapi.dll + 2008-04-14 02:20:28 95,744 ----a-w c:\windows\system32\iphlpapi.dll - 2001-10-28 15:06:38 158,720 ----a-w c:\windows\system32\ipmontr.dll + 2008-04-14 02:20:28 165,888 ----a-w c:\windows\system32\ipmontr.dll - 2004-08-04 03:45:24 331,264 ----a-w c:\windows\system32\ipnathlp.dll + 2008-04-14 02:20:28 331,264 ----a-w c:\windows\system32\ipnathlp.dll - 2004-08-04 03:45:24 348,160 ----a-w c:\windows\system32\ippromon.dll + 2008-04-14 02:20:28 348,160 ----a-w c:\windows\system32\ippromon.dll - 2001-10-28 15:06:38 169,984 ----a-w c:\windows\system32\iprtrmgr.dll + 2008-04-14 02:20:28 177,152 ----a-w c:\windows\system32\iprtrmgr.dll - 2004-08-04 03:45:24 357,376 ----a-w c:\windows\system32\ipsecsnp.dll + 2008-04-14 02:20:28 357,376 ----a-w c:\windows\system32\ipsecsnp.dll - 2004-08-04 03:45:24 183,296 ----a-w c:\windows\system32\ipsecsvc.dll + 2008-04-14 02:20:28 184,320 ----a-w c:\windows\system32\ipsecsvc.dll - 2004-08-04 03:45:24 386,560 ----a-w c:\windows\system32\ipsmsnap.dll + 2008-04-14 02:20:28 386,560 ----a-w c:\windows\system32\ipsmsnap.dll - 2004-08-04 03:45:36 53,760 ----a-w c:\windows\system32\ipv6.exe + 2008-04-14 02:21:02 53,760 ----a-w c:\windows\system32\ipv6.exe - 2004-08-04 03:45:24 60,416 ----a-w c:\windows\system32\ipv6mon.dll + 2008-04-14 02:20:28 59,904 ----a-w c:\windows\system32\ipv6mon.dll - 2004-08-04 03:45:36 24,064 ----a-w c:\windows\system32\ipxroute.exe + 2008-04-14 02:21:02 24,064 ----a-w c:\windows\system32\ipxroute.exe - 2001-10-28 15:06:38 20,992 ----a-w c:\windows\system32\ipxwan.dll + 2008-04-14 02:20:28 22,016 ----a-w c:\windows\system32\ipxwan.dll - 2004-08-04 03:45:24 120,320 ----a-w c:\windows\system32\ir41_qc.dll + 2008-04-14 02:20:28 120,320 ----a-w c:\windows\system32\ir41_qc.dll - 2004-08-04 03:45:24 338,432 ----a-w c:\windows\system32\ir41_qcx.dll + 2008-04-14 02:20:28 338,432 ----a-w c:\windows\system32\ir41_qcx.dll - 2004-08-04 03:45:24 755,200 ----a-w c:\windows\system32\ir50_32.dll + 2008-04-14 02:20:28 755,200 ----a-w c:\windows\system32\ir50_32.dll - 2004-08-04 03:45:24 200,192 ----a-w c:\windows\system32\ir50_qc.dll + 2008-04-14 02:20:29 200,192 ----a-w c:\windows\system32\ir50_qc.dll - 2004-08-04 03:45:24 183,808 ----a-w c:\windows\system32\ir50_qcx.dll + 2008-04-14 02:20:29 183,808 ----a-w c:\windows\system32\ir50_qcx.dll - 2004-08-04 03:45:24 86,016 ----a-w c:\windows\system32\isign32.dll + 2008-04-14 02:20:29 86,016 ----a-w c:\windows\system32\isign32.dll - 2004-08-04 03:45:24 32,768 ----a-w c:\windows\system32\isrdbg32.dll + 2008-04-14 02:20:29 32,768 ----a-w c:\windows\system32\isrdbg32.dll - 2005-05-27 02:07:52 155,136 ----a-w c:\windows\system32\itircl.dll + 2008-04-14 02:20:29 155,136 ----a-w c:\windows\system32\itircl.dll - 2005-05-27 02:07:53 137,216 ----a-w c:\windows\system32\itss.dll + 2008-04-14 02:20:29 138,240 ----a-w c:\windows\system32\itss.dll - 2004-08-04 03:45:24 192,000 ----a-w c:\windows\system32\iuengine.dll + 2008-04-14 02:20:29 191,488 ----a-w c:\windows\system32\iuengine.dll - 2004-08-04 03:45:24 54,784 ----a-w c:\windows\system32\ixsso.dll + 2008-04-14 02:20:29 54,784 ----a-w c:\windows\system32\ixsso.dll - 2004-08-04 03:55:42 47,616 ----a-w c:\windows\system32\iyuv_32.dll + 2008-04-14 02:20:29 47,616 ----a-w c:\windows\system32\iyuv_32.dll - 2006-06-01 18:48:50 163,840 ----a-w c:\windows\system32\jgdw400.dll + 2008-04-14 02:20:29 163,840 ----a-w c:\windows\system32\jgdw400.dll - 2006-06-01 18:48:50 27,648 ----a-w c:\windows\system32\jgpl400.dll + 2008-04-14 02:20:29 27,648 ----a-w c:\windows\system32\jgpl400.dll - 2007-12-18 14:42:09 450,560 ----a-w c:\windows\system32\jscript.dll + 2008-05-09 10:55:05 512,000 ----a-w c:\windows\system32\jscript.dll - 2008-10-16 10:39:08 16,384 ----a-w c:\windows\system32\jsproxy.dll + 2008-04-14 02:20:29 15,872 ----a-w c:\windows\system32\jsproxy.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\system32\kbdbhc.dll - 2004-08-04 03:44:24 7,168 ----a-w c:\windows\system32\kbdfi1.dll + 2008-04-14 02:18:43 7,168 ----a-w c:\windows\system32\kbdfi1.dll - 2004-08-04 03:44:24 6,144 ----a-w c:\windows\system32\kbdinbe1.dll + 2008-04-14 02:18:43 6,144 ----a-w c:\windows\system32\kbdinbe1.dll - 2004-08-04 03:44:24 6,656 ----a-w c:\windows\system32\kbdinben.dll + 2008-04-14 02:18:43 6,144 ----a-w c:\windows\system32\kbdinben.dll - 2004-08-04 03:44:24 6,656 ----a-w c:\windows\system32\kbdinmal.dll + 2008-04-14 02:18:43 6,656 ----a-w c:\windows\system32\kbdinmal.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\system32\kbdiultn.dll - 2004-08-04 03:44:24 5,632 ----a-w c:\windows\system32\kbdmaori.dll + 2008-04-14 02:18:43 5,632 ----a-w c:\windows\system32\kbdmaori.dll - 2004-08-04 03:44:24 6,144 ----a-w c:\windows\system32\kbdmlt47.dll + 2008-04-14 02:18:43 6,144 ----a-w c:\windows\system32\kbdmlt47.dll - 2004-08-04 03:44:24 6,144 ----a-w c:\windows\system32\kbdmlt48.dll + 2008-04-14 02:18:43 6,144 ----a-w c:\windows\system32\kbdmlt48.dll - 2001-10-28 15:06:40 7,168 ----a-w c:\windows\system32\kbdnec.dll + 2008-04-14 02:18:43 7,168 ----a-w c:\windows\system32\kbdnec.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\system32\kbdnepr.dll - 2004-08-04 03:44:24 7,168 ----a-w c:\windows\system32\kbdno1.dll + 2008-04-14 02:18:43 7,168 ----a-w c:\windows\system32\kbdno1.dll + 2008-04-14 02:18:43 6,144 ------w c:\windows\system32\kbdpash.dll - 2004-08-04 03:44:24 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll + 2008-04-14 02:18:43 7,680 ----a-w c:\windows\system32\kbdsmsfi.dll - 2004-08-04 03:44:24 7,680 ----a-w c:\windows\system32\kbdsmsno.dll + 2008-04-14 02:18:43 7,680 ----a-w c:\windows\system32\kbdsmsno.dll - 2004-08-04 03:44:24 7,168 ----a-w c:\windows\system32\kbdukx.dll + 2008-04-14 02:18:43 7,168 ----a-w c:\windows\system32\kbdukx.dll - 2004-08-04 01:59:24 7,424 ----a-w c:\windows\system32\kd1394.dll + 2008-04-13 18:31:35 7,424 ----a-w c:\windows\system32\kd1394.dll - 2005-06-15 17:50:49 295,936 ----a-w c:\windows\system32\kerberos.dll + 2008-04-14 02:20:29 299,520 ----a-w c:\windows\system32\kerberos.dll - 2007-04-16 15:53:09 1,023,488 ----a-w c:\windows\system32\kernel32.dll + 2008-04-14 02:20:29 1,028,608 ----a-w c:\windows\system32\kernel32.dll - 2004-08-04 03:45:24 408,064 ----a-w c:\windows\system32\keymgr.dll + 2008-04-14 02:20:30 152,576 ----a-w c:\windows\system32\keymgr.dll + 2008-04-14 02:20:30 61,440 ------w c:\windows\system32\kmsvc.dll - 2004-08-04 02:45:24 4,096 ----a-w c:\windows\system32\ksuser.dll + 2008-04-14 02:20:30 4,096 ----a-w c:\windows\system32\ksuser.dll + 2008-04-14 02:20:30 37,376 ------w c:\windows\system32\l2gpstore.dll + 2009-02-03 16:22:50 24,576 ----a-w c:\windows\system32\lfavi10N.dll + 2009-02-03 16:22:50 34,304 ----a-w c:\windows\system32\lfbmp10N.dll + 2009-02-03 16:22:50 271,360 ----a-w c:\windows\system32\Lfcmp10n.dll + 2009-02-03 16:22:50 78,336 ----a-w c:\windows\system32\lffax10N.dll + 2009-02-03 16:22:50 31,744 ----a-w c:\windows\system32\lflmb10N.dll + 2009-02-03 16:22:50 31,744 ----a-w c:\windows\system32\lfpct10N.dll + 2009-02-03 16:22:50 33,280 ----a-w c:\windows\system32\lfpcx10N.dll + 2009-02-03 16:22:50 134,144 ----a-w c:\windows\system32\lfpng10N.dll + 2009-02-03 16:22:50 26,112 ----a-w c:\windows\system32\lfras10N.dll + 2009-02-03 16:22:50 27,648 ----a-w c:\windows\system32\lftga10N.dll + 2009-02-03 16:22:50 122,880 ----a-w c:\windows\system32\lftif10N.dll + 2009-02-03 16:22:50 58,880 ----a-w c:\windows\system32\lfwmf10N.dll - 2004-08-04 03:45:24 424,448 ----a-w c:\windows\system32\licdll.dll + 2008-04-13 21:20:32 424,448 ----a-w c:\windows\system32\licdll.dll - 2004-08-04 03:45:24 22,016 ----a-w c:\windows\system32\licmgr10.dll + 2008-04-14 02:20:30 22,016 ----a-w c:\windows\system32\licmgr10.dll - 2004-08-04 03:45:24 58,880 ----a-w c:\windows\system32\licwmi.dll + 2008-04-14 02:20:30 58,880 ----a-w c:\windows\system32\licwmi.dll - 2005-09-01 01:43:35 19,968 ----a-w c:\windows\system32\linkinfo.dll + 2008-04-14 02:20:30 19,968 ----a-w c:\windows\system32\linkinfo.dll - 2004-08-04 03:45:24 13,824 ----a-w c:\windows\system32\lmhsvc.dll + 2008-04-14 02:20:30 13,824 ----a-w c:\windows\system32\lmhsvc.dll - 2004-08-04 03:45:24 399,872 ----a-w c:\windows\system32\lmrt.dll + 2008-04-14 02:20:30 399,872 ----a-w c:\windows\system32\lmrt.dll - 2004-08-04 03:45:24 100,352 ----a-w c:\windows\system32\loadperf.dll + 2008-04-14 02:20:30 100,352 ----a-w c:\windows\system32\loadperf.dll - 2004-08-04 03:45:24 221,696 ----a-w c:\windows\system32\localsec.dll + 2008-04-14 02:20:30 221,696 ----a-w c:\windows\system32\localsec.dll - 2004-08-04 03:45:24 343,040 ----a-w c:\windows\system32\localspl.dll + 2008-04-14 02:20:30 344,576 ----a-w c:\windows\system32\localspl.dll - 2004-08-04 03:45:24 11,776 ----a-w c:\windows\system32\localui.dll + 2008-04-14 02:20:30 11,776 ----a-w c:\windows\system32\localui.dll - 2004-08-04 03:45:36 75,264 ----a-w c:\windows\system32\locator.exe + 2008-04-14 02:21:04 75,264 ----a-w c:\windows\system32\locator.exe - 2004-08-04 03:45:36 60,928 ----a-w c:\windows\system32\logman.exe + 2008-04-14 02:21:04 60,928 ----a-w c:\windows\system32\logman.exe - 2004-08-04 03:45:48 220,672 ----a-w c:\windows\system32\logon.scr + 2008-04-14 02:21:25 220,672 ----a-w c:\windows\system32\logon.scr - 2004-08-04 03:45:36 515,072 ----a-w c:\windows\system32\logonui.exe + 2008-04-14 02:21:05 515,072 ----a-w c:\windows\system32\logonui.exe - 2004-08-04 03:45:24 22,016 ----a-w c:\windows\system32\lpk.dll + 2008-04-14 02:20:30 22,016 ----a-w c:\windows\system32\lpk.dll - 2004-08-04 03:45:24 10,240 ----a-w c:\windows\system32\lprhelp.dll + 2008-04-14 02:20:30 10,240 ----a-w c:\windows\system32\lprhelp.dll - 2007-11-07 09:28:43 724,480 ----a-w c:\windows\system32\lsasrv.dll + 2008-04-14 02:20:30 730,624 ----a-w c:\windows\system32\lsasrv.dll - 2004-08-04 03:45:36 13,312 ----a-w c:\windows\system32\lsass.exe + 2008-04-14 02:21:05 13,312 ----a-w c:\windows\system32\lsass.exe + 2009-02-03 16:22:50 229,888 ----a-w c:\windows\system32\LTDIS10N.dll + 2009-02-03 16:22:51 265,728 ----a-w c:\windows\system32\ltdlg10N.dll + 2009-02-03 16:22:51 221,184 ----a-w c:\windows\system32\ltefx10N.dll + 2009-02-03 16:22:51 107,520 ----a-w c:\windows\system32\ltfil10N.DLL + 2009-02-03 16:22:51 114,176 ----a-w c:\windows\system32\ltimg10N.dll + 2009-02-03 16:22:51 297,984 ----a-w c:\windows\system32\ltkrn10N.dll + 2009-02-03 16:22:51 3,824 ----a-w c:\windows\system32\ltthk10w.dll + 2009-02-03 16:22:51 35,840 ----a-w c:\windows\system32\lttwn10N.dll + 2009-02-03 16:22:51 45,936 ----a-w c:\windows\system32\ltvdd10w.drv - 2004-08-04 03:45:36 72,192 ----a-w c:\windows\system32\magnify.exe + 2008-04-14 02:21:05 72,192 ----a-w c:\windows\system32\magnify.exe - 2004-08-04 03:45:36 85,504 ----a-w c:\windows\system32\makecab.exe + 2008-04-14 02:21:05 57,344 ----a-w c:\windows\system32\makecab.exe - 2004-08-04 03:45:24 14,848 ----a-w c:\windows\system32\mcastmib.dll + 2008-04-14 02:20:30 14,336 ----a-w c:\windows\system32\mcastmib.dll - 2004-08-04 03:45:24 85,504 ----a-w c:\windows\system32\mciavi32.dll + 2008-04-14 02:20:30 85,504 ----a-w c:\windows\system32\mciavi32.dll - 2004-08-04 03:45:24 35,328 ----a-w c:\windows\system32\mciqtz32.dll + 2008-04-14 02:20:30 35,328 ----a-w c:\windows\system32\mciqtz32.dll - 2004-08-04 03:45:24 23,040 ----a-w c:\windows\system32\mciseq.dll + 2008-04-14 02:20:30 23,040 ----a-w c:\windows\system32\mciseq.dll - 2004-08-04 03:45:24 23,552 ----a-w c:\windows\system32\mciwave.dll + 2008-04-14 02:20:30 23,552 ----a-w c:\windows\system32\mciwave.dll - 2004-08-04 03:45:24 201,728 ----a-w c:\windows\system32\mdminst.dll + 2008-04-14 02:20:30 118,784 ----a-w c:\windows\system32\mdminst.dll + 2008-04-14 02:20:30 86,016 ------w c:\windows\system32\mdmxsdk.dll - 2007-03-08 15:36:54 40,960 ----a-w c:\windows\system32\mf3216.dll + 2008-04-14 02:20:30 40,960 ----a-w c:\windows\system32\mf3216.dll - 2006-11-01 19:18:30 927,504 ----a-w c:\windows\system32\mfc40u.dll + 2008-04-14 02:20:31 927,504 ----a-w c:\windows\system32\mfc40u.dll - 2004-08-04 03:45:24 1,028,096 ----a-w c:\windows\system32\mfc42.dll + 2008-04-14 02:20:31 1,028,096 ----a-w c:\windows\system32\mfc42.dll - 2004-08-04 03:45:24 22,528 ----a-w c:\windows\system32\mfcsubs.dll + 2008-04-14 02:20:31 22,528 ----a-w c:\windows\system32\mfcsubs.dll - 2004-08-04 03:45:24 14,848 ----a-w c:\windows\system32\mgmtapi.dll + 2008-04-14 02:20:31 14,848 ----a-w c:\windows\system32\mgmtapi.dll + 2008-04-14 02:20:31 184,320 ------w c:\windows\system32\microsoft.managementconsole.dll - 2004-08-04 03:45:24 18,944 ----a-w c:\windows\system32\midimap.dll + 2008-04-14 02:20:31 18,944 ----a-w c:\windows\system32\midimap.dll - 2004-08-04 03:45:24 60,928 ----a-w c:\windows\system32\miglibnt.dll + 2008-04-14 02:20:31 60,928 ----a-w c:\windows\system32\miglibnt.dll - 2001-10-28 15:06:58 18,944 ----a-w c:\windows\system32\mimefilt.dll + 2008-04-14 02:20:31 29,696 ----a-w c:\windows\system32\mimefilt.dll - 2004-08-04 03:45:24 586,240 ----a-w c:\windows\system32\mlang.dll + 2008-04-14 02:20:31 586,240 ----a-w c:\windows\system32\mlang.dll - 2004-08-04 03:45:38 849,920 ----a-w c:\windows\system32\mmc.exe + 2008-04-14 02:21:06 1,415,168 ----a-w c:\windows\system32\mmc.exe - 2004-08-04 03:45:24 75,264 ----a-w c:\windows\system32\mmcbase.dll + 2008-04-14 02:20:31 166,912 ----a-w c:\windows\system32\mmcbase.dll + 2008-04-14 02:20:31 397,312 ------w c:\windows\system32\mmcex.dll + 2008-04-14 02:20:32 106,496 ------w c:\windows\system32\mmcfxcommon.dll - 2004-08-04 03:45:24 1,197,056 ----a-w c:\windows\system32\mmcndmgr.dll + 2008-04-14 02:20:32 1,876,992 ----a-w c:\windows\system32\mmcndmgr.dll + 2008-04-14 02:21:07 34,304 ------w c:\windows\system32\mmcperf.exe - 2004-08-04 03:45:24 65,024 ----a-w c:\windows\system32\mmcshext.dll + 2008-04-14 02:20:32 61,440 ----a-w c:\windows\system32\mmcshext.dll - 2004-08-04 03:45:24 17,920 ----a-w c:\windows\system32\mmfutil.dll + 2008-04-14 02:20:32 17,920 ----a-w c:\windows\system32\mmfutil.dll - 2004-08-04 03:45:24 34,560 ----a-w c:\windows\system32\mnmdd.dll + 2008-04-14 02:20:32 34,560 ----a-w c:\windows\system32\mnmdd.dll - 2004-08-04 03:45:38 32,768 ----a-w c:\windows\system32\mnmsrvc.exe + 2008-04-14 02:21:07 32,768 ----a-w c:\windows\system32\mnmsrvc.exe - 2004-08-04 03:45:24 208,896 ----a-w c:\windows\system32\mobsync.dll + 2008-04-14 02:20:32 208,896 ----a-w c:\windows\system32\mobsync.dll - 2004-08-04 03:45:38 324,096 ----a-w c:\windows\system32\mobsync.exe + 2008-04-14 02:21:07 143,872 ----a-w c:\windows\system32\mobsync.exe - 2004-08-04 03:45:24 155,136 ----a-w c:\windows\system32\modemui.dll + 2008-04-14 02:20:32 155,136 ----a-w c:\windows\system32\modemui.dll - 2001-10-28 15:07:00 15,872 ----a-w c:\windows\system32\more.com + 2008-04-14 02:21:25 16,896 ----a-w c:\windows\system32\more.com - 2004-08-04 03:44:26 216,064 ----a-w c:\windows\system32\moricons.dll + 2008-04-13 16:45:30 216,064 ----a-w c:\windows\system32\moricons.dll - 2004-08-04 03:45:40 124,416 ----a-w c:\windows\system32\mplay32.exe + 2008-04-14 02:21:08 124,416 ----a-w c:\windows\system32\mplay32.exe - 2004-08-04 03:45:24 59,904 ----a-w c:\windows\system32\mpr.dll + 2008-04-14 02:20:32 59,904 ----a-w c:\windows\system32\mpr.dll - 2004-08-04 03:45:24 87,040 ----a-w c:\windows\system32\mprapi.dll + 2008-04-14 02:20:32 87,040 ----a-w c:\windows\system32\mprapi.dll - 2001-10-28 15:07:00 49,152 ----a-w c:\windows\system32\mprdim.dll + 2008-04-14 02:20:32 53,248 ----a-w c:\windows\system32\mprdim.dll - 2007-07-06 12:51:36 138,240 ----a-w c:\windows\system32\mqad.dll + 2008-04-14 02:20:32 138,240 ----a-w c:\windows\system32\mqad.dll - 2004-08-04 03:45:40 19,968 ----a-w c:\windows\system32\mqbkup.exe + 2008-04-14 02:21:09 19,968 ----a-w c:\windows\system32\mqbkup.exe - 2007-07-06 12:51:36 47,104 ----a-w c:\windows\system32\mqdscli.dll + 2008-04-14 02:20:32 47,616 ----a-w c:\windows\system32\mqdscli.dll - 2007-07-06 12:51:36 16,896 ----a-w c:\windows\system32\mqise.dll + 2008-04-14 02:20:32 16,896 ----a-w c:\windows\system32\mqise.dll - 2004-08-04 03:45:24 89,088 ----a-w c:\windows\system32\mqlogmgr.dll + 2008-04-14 02:20:32 89,088 ----a-w c:\windows\system32\mqlogmgr.dll - 2004-08-04 03:45:24 225,280 ----a-w c:\windows\system32\mqoa.dll + 2008-04-14 02:20:32 225,280 ----a-w c:\windows\system32\mqoa.dll - 2007-07-06 12:51:36 660,992 ----a-w c:\windows\system32\mqqm.dll + 2008-04-14 02:20:32 663,040 ----a-w c:\windows\system32\mqqm.dll - 2007-07-06 12:51:36 177,152 ----a-w c:\windows\system32\mqrt.dll + 2008-04-14 02:20:32 177,152 ----a-w c:\windows\system32\mqrt.dll - 2004-08-04 03:45:24 123,392 ----a-w c:\windows\system32\mqrtdep.dll + 2008-04-14 02:20:32 123,904 ----a-w c:\windows\system32\mqrtdep.dll - 2007-07-06 12:51:36 95,744 ----a-w c:\windows\system32\mqsec.dll + 2008-04-14 02:20:32 95,744 ----a-w c:\windows\system32\mqsec.dll - 2004-08-04 03:45:24 517,632 ----a-w c:\windows\system32\mqsnap.dll + 2008-04-14 02:20:32 517,632 ----a-w c:\windows\system32\mqsnap.dll - 2004-08-04 03:45:40 4,608 ----a-w c:\windows\system32\mqsvc.exe + 2008-04-14 02:21:09 4,608 ----a-w c:\windows\system32\mqsvc.exe - 2004-08-04 03:45:40 117,248 ----a-w c:\windows\system32\mqtgsvc.exe + 2008-04-14 02:21:09 117,248 ----a-w c:\windows\system32\mqtgsvc.exe - 2004-08-04 03:45:24 186,880 ----a-w c:\windows\system32\mqtrig.dll + 2008-04-14 02:20:32 187,392 ----a-w c:\windows\system32\mqtrig.dll - 2007-07-06 12:51:36 48,640 ----a-w c:\windows\system32\mqupgrd.dll + 2008-04-14 02:20:32 49,152 ----a-w c:\windows\system32\mqupgrd.dll - 2007-07-06 12:51:36 523,776 ----a-w c:\windows\system32\mqutil.dll + 2008-04-14 02:20:32 523,776 ----a-w c:\windows\system32\mqutil.dll - 2004-08-04 03:45:24 71,680 ----a-w c:\windows\system32\msacm32.dll + 2008-04-14 02:20:32 71,680 ----a-w c:\windows\system32\msacm32.dll - 2004-08-04 03:44:28 3,584 ----a-w c:\windows\system32\msafd.dll + 2008-04-14 02:18:52 3,584 ----a-w c:\windows\system32\msafd.dll - 2004-08-04 03:45:24 86,016 ----a-w c:\windows\system32\msapsspc.dll + 2008-04-14 02:20:32 86,016 ----a-w c:\windows\system32\msapsspc.dll - 2004-08-04 03:45:24 57,344 ----a-w c:\windows\system32\msasn1.dll + 2008-04-14 02:20:32 57,344 ----a-w c:\windows\system32\msasn1.dll - 2008-06-24 16:24:13 74,240 ----a-w c:\windows\system32\mscms.dll + 2008-06-24 16:43:36 74,240 ----a-w c:\windows\system32\mscms.dll - 2004-08-04 03:45:24 69,632 ----a-w c:\windows\system32\msconf.dll + 2008-04-14 02:20:32 69,632 ----a-w c:\windows\system32\msconf.dll - 2004-08-04 03:44:28 12,288 ----a-w c:\windows\system32\mscpx32r.dLL + 2008-04-13 17:26:07 12,288 ----a-w c:\windows\system32\mscpx32r.dll - 2004-08-04 03:45:24 36,864 ----a-w c:\windows\system32\mscpxl32.dLL + 2008-04-14 02:20:32 36,864 ----a-w c:\windows\system32\mscpxl32.dll - 2004-08-04 03:45:24 294,400 ----a-w c:\windows\system32\MSCTF.dll + 2008-04-14 02:20:32 297,984 ----a-w c:\windows\system32\msctf.dll - 2004-08-04 03:45:24 69,120 ----a-w c:\windows\system32\MSCTFP.dll + 2008-04-14 02:20:32 68,608 ----a-w c:\windows\system32\msctfp.dll - 2004-08-04 03:45:24 118,784 ----a-w c:\windows\system32\msdadiag.dll + 2008-04-14 02:20:32 118,784 ----a-w c:\windows\system32\msdadiag.dll - 2004-08-04 03:45:24 151,552 ----a-w c:\windows\system32\msdart.dll + 2008-04-14 02:20:33 151,552 ----a-w c:\windows\system32\msdart.dll - 2004-08-04 03:45:24 14,336 ----a-w c:\windows\system32\msdmo.dll + 2008-04-14 02:20:33 14,336 ----a-w c:\windows\system32\msdmo.dll - 2004-08-04 03:45:40 20,480 ----a-w c:\windows\system32\msdtc.exe + 2008-04-14 02:21:09 6,144 ----a-w c:\windows\system32\msdtc.exe - 2004-08-04 03:45:24 58,880 ----a-w c:\windows\system32\msdtclog.dll + 2008-04-14 02:20:33 58,880 ----a-w c:\windows\system32\msdtclog.dll - 2006-03-01 19:44:01 426,496 ----a-w c:\windows\system32\msdtcprx.dll + 2008-04-14 02:20:33 427,008 ----a-w c:\windows\system32\msdtcprx.dll - 2006-03-01 19:44:01 956,416 ----a-w c:\windows\system32\msdtctm.dll + 2008-04-14 02:20:33 956,928 ----a-w c:\windows\system32\msdtctm.dll - 2006-03-01 19:44:01 161,280 ----a-w c:\windows\system32\msdtcuiu.dll + 2008-04-14 02:20:33 161,792 ----a-w c:\windows\system32\msdtcuiu.dll - 2004-08-04 03:44:28 4,126 ----a-w c:\windows\system32\msdxmlc.dll + 2008-04-14 02:18:55 4,126 ----a-w c:\windows\system32\msdxmlc.dll - 2006-11-27 14:55:29 539,136 ----a-w c:\windows\system32\msftedit.dll + 2008-04-14 02:20:33 539,136 ----a-w c:\windows\system32\msftedit.dll - 2004-08-04 03:45:24 1,501,696 ----a-w c:\windows\system32\msgina.dll + 2008-04-14 02:20:33 1,000,960 ----a-w c:\windows\system32\msgina.dll - 2004-08-04 03:45:24 33,792 ----a-w c:\windows\system32\msgsvc.dll + 2008-04-14 02:20:34 33,792 ----a-w c:\windows\system32\msgsvc.dll - 2004-08-04 03:45:48 188,416 ----a-w c:\windows\system32\msh261.drv + 2008-04-14 02:21:27 188,416 ----a-w c:\windows\system32\msh261.drv - 2004-08-04 03:55:42 294,912 ----a-w c:\windows\system32\msh263.drv + 2008-04-14 02:21:27 294,912 ----a-w c:\windows\system32\msh263.drv - 2004-08-04 03:45:40 29,184 ----a-w c:\windows\system32\mshta.exe + 2008-04-14 02:21:09 29,184 ----a-w c:\windows\system32\mshta.exe - 2008-12-12 17:35:12 3,081,216 ----a-w c:\windows\system32\mshtml.dll + 2008-12-12 17:02:14 3,088,896 ----a-w c:\windows\system32\mshtml.dll - 2008-10-16 10:39:08 449,024 ----a-w c:\windows\system32\mshtmled.dll + 2008-04-14 02:20:34 449,024 ----a-w c:\windows\system32\mshtmled.dll - 2004-08-04 03:44:30 57,344 ----a-w c:\windows\system32\mshtmler.dll + 2008-04-14 01:52:32 57,344 ----a-w c:\windows\system32\mshtmler.dll - 2007-04-18 16:13:00 2,854,400 ----a-w c:\windows\system32\msi.dll + 2008-04-14 02:20:34 2,843,136 ----a-w c:\windows\system32\msi.dll - 2004-08-04 03:45:24 55,296 ----a-w c:\windows\system32\msident.dll + 2008-04-14 02:20:34 51,712 ----a-w c:\windows\system32\msident.dll - 2004-08-04 03:45:24 6,656 ----a-w c:\windows\system32\msidle.dll + 2008-04-14 02:20:34 6,656 ----a-w c:\windows\system32\msidle.dll - 2004-08-04 03:45:24 363,008 ----a-w c:\windows\system32\msieftp.dll + 2008-04-14 02:20:34 250,368 ----a-w c:\windows\system32\msieftp.dll - 2005-05-04 17:45:36 211,968 ----a-w c:\windows\system32\msiexec.exe + 2008-04-14 02:21:09 78,848 ----a-w c:\windows\system32\msiexec.exe - 2005-05-04 17:45:36 271,360 ----a-w c:\windows\system32\msihnd.dll + 2008-04-14 02:20:34 271,360 ----a-w c:\windows\system32\msihnd.dll - 2004-08-04 03:45:24 4,608 ----a-w c:\windows\system32\msimg32.dll + 2008-04-14 02:20:34 4,608 ----a-w c:\windows\system32\msimg32.dll - 2005-05-04 17:45:36 884,736 ----a-w c:\windows\system32\msimsg.dll + 2008-04-13 15:39:43 884,736 ----a-w c:\windows\system32\msimsg.dll - 2004-08-04 03:45:24 159,232 ----a-w c:\windows\system32\MSIMTF.dll + 2008-04-14 02:20:34 159,232 ----a-w c:\windows\system32\msimtf.dll - 2005-05-04 17:45:36 15,360 ----a-w c:\windows\system32\msisip.dll + 2008-04-14 02:20:34 15,360 ----a-w c:\windows\system32\msisip.dll - 1999-09-28 23:42:48 1,034,752 ----a-w c:\windows\system32\MSJet35.dll + 2000-06-08 19:00:00 1,064,960 ----a-w c:\windows\system32\MSJET35.DLL - 1998-06-01 16:37:00 139,264 ----a-w c:\windows\system32\MSJInt35.dll + 1998-04-24 02:00:00 123,664 ----a-w c:\windows\system32\MSJINT35.DLL - 1997-06-23 15:06:50 24,848 ----a-w c:\windows\system32\MSJtEr35.dll + 1998-04-24 02:00:00 24,848 ----a-w c:\windows\system32\MSJTER35.DLL - 2004-08-04 03:45:26 25,600 ----a-w c:\windows\system32\mslbui.dll + 2008-04-14 02:20:34 25,088 ----a-w c:\windows\system32\mslbui.dll - 2004-08-04 03:45:26 290,816 ----a-w c:\windows\system32\msnsspc.dll + 2008-04-14 02:20:34 290,816 ----a-w c:\windows\system32\msnsspc.dll - 2004-08-04 03:45:26 252,928 ----a-w c:\windows\system32\msoeacct.dll + 2008-04-14 02:20:34 252,928 ----a-w c:\windows\system32\msoeacct.dll - 2004-08-04 03:45:26 105,984 ----a-w c:\windows\system32\msoert2.dll + 2008-04-14 02:20:34 105,984 ----a-w c:\windows\system32\msoert2.dll - 2004-08-04 03:44:38 24,576 ----a-w c:\windows\system32\msorc32r.dll + 2007-03-28 12:54:14 24,576 ----a-w c:\windows\system32\msorc32r.dll - 2004-08-04 03:45:26 143,360 ----a-w c:\windows\system32\msorcl32.dll + 2008-04-14 02:20:34 143,360 ----a-w c:\windows\system32\msorcl32.dll - 2004-08-04 03:45:40 506,368 ----a-w c:\windows\system32\mspaint.exe + 2008-04-14 02:21:11 345,600 ----a-w c:\windows\system32\mspaint.exe - 2004-08-04 03:45:26 30,208 ----a-w c:\windows\system32\mspatcha.dll + 2008-04-14 02:20:34 29,696 ----a-w c:\windows\system32\mspatcha.dll - 2004-08-04 03:44:40 48,128 ----a-w c:\windows\system32\msprivs.dll + 2008-04-13 16:23:31 48,128 ----a-w c:\windows\system32\msprivs.dll - 2008-10-16 10:39:08 146,432 ----a-w c:\windows\system32\msrating.dll + 2008-04-14 02:20:34 146,432 ----a-w c:\windows\system32\msrating.dll + 1998-04-24 02:00:00 252,176 ----a-w c:\windows\system32\MSRD2X35.DLL - 1999-08-25 16:57:26 177,664 ----a-w c:\windows\system32\MSRepl35.dll + 2000-06-08 19:00:00 430,080 ----a-w c:\windows\system32\MSREPL35.DLL - 2004-08-04 03:45:26 11,264 ----a-w c:\windows\system32\msrle32.dll + 2008-04-14 02:20:34 11,264 ----a-w c:\windows\system32\msrle32.dll - 2004-08-04 03:45:26 134,656 ----a-w c:\windows\system32\mssap.dll + 2008-04-14 02:20:34 134,656 ----a-w c:\windows\system32\mssap.dll + 2008-04-14 02:20:34 155,136 ------w c:\windows\system32\mssha.dll + 2008-04-14 01:57:16 80,896 ------w c:\windows\system32\msshavmsg.dll - 2004-02-23 03:00:00 119,808 ----a-w c:\windows\system32\MSSTDFMT.DLL + 1998-08-09 20:07:32 118,784 ----a-w c:\windows\system32\MSSTDFMT.DLL - 2004-08-04 03:45:26 400,384 ----a-w c:\windows\system32\mstask.dll + 2008-04-14 02:20:34 278,528 ----a-w c:\windows\system32\mstask.dll - 2008-10-16 10:39:08 532,480 ----a-w c:\windows\system32\mstime.dll + 2008-04-14 02:20:34 532,480 ----a-w c:\windows\system32\mstime.dll - 2004-08-04 03:45:40 12,288 ----a-w c:\windows\system32\mstinit.exe + 2008-04-14 02:21:11 12,288 ----a-w c:\windows\system32\mstinit.exe - 2004-08-04 03:45:26 115,712 ----a-w c:\windows\system32\mstlsapi.dll + 2008-04-14 02:20:34 116,224 ----a-w c:\windows\system32\mstlsapi.dll - 2004-08-04 03:34:20 419,840 ----a-w c:\windows\system32\mstsc.exe + 2008-04-14 02:21:04 677,888 ----a-w c:\windows\system32\mstsc.exe - 2004-08-04 01:59:44 655,360 ----a-w c:\windows\system32\mstscax.dll + 2008-04-14 02:20:30 2,061,824 ----a-w c:\windows\system32\mstscax.dll - 2004-08-04 03:45:26 199,168 ----a-w c:\windows\system32\msutb.dll + 2008-04-14 02:20:34 199,168 ----a-w c:\windows\system32\msutb.dll - 2004-08-04 03:45:26 129,536 ----a-w c:\windows\system32\msv1_0.dll + 2008-04-14 02:20:34 132,608 ----a-w c:\windows\system32\msv1_0.dll - 2004-02-23 03:00:00 1,386,496 ----a-w c:\windows\system32\msvbvm60.dll + 2008-04-14 02:20:34 1,384,479 ----a-w c:\windows\system32\msvbvm60.dll - 2004-08-04 03:45:26 54,784 ----a-w c:\windows\system32\msvcirt.dll + 2008-04-14 02:20:34 57,344 ----a-w c:\windows\system32\msvcirt.dll - 2004-08-04 03:45:26 413,696 ----a-w c:\windows\system32\msvcp60.dll + 2008-04-14 02:20:34 413,696 ----a-w c:\windows\system32\msvcp60.dll - 2004-08-04 03:45:26 343,040 ------w c:\windows\system32\msvcrt.dll + 2008-04-14 02:20:34 343,040 ----a-w c:\windows\system32\msvcrt.dll - 2004-08-04 01:58:26 61,440 ----a-w c:\windows\system32\msvcrt40.dll + 2008-04-13 18:30:46 61,440 ----a-w c:\windows\system32\msvcrt40.dll - 2004-08-04 03:45:26 121,856 ----a-w c:\windows\system32\msvfw32.dll + 2008-04-14 02:20:34 122,368 ----a-w c:\windows\system32\msvfw32.dll - 2004-08-04 03:45:26 1,433,088 ----a-w c:\windows\system32\msvidctl.dll + 2008-04-14 02:20:34 1,433,600 ----a-w c:\windows\system32\msvidctl.dll - 2004-08-04 03:45:26 72,704 ----a-w c:\windows\system32\msw3prt.dll + 2008-04-14 02:20:34 72,704 ----a-w c:\windows\system32\msw3prt.dll - 2004-08-04 03:45:26 204,288 ----a-w c:\windows\system32\mswebdvd.dll + 2008-04-14 02:20:34 204,288 ----a-w c:\windows\system32\mswebdvd.dll - 2008-06-20 17:41:07 247,808 ----a-w c:\windows\system32\mswsock.dll + 2008-06-20 17:48:21 247,808 ----a-w c:\windows\system32\mswsock.dll - 2004-08-04 03:45:26 506,368 ----a-w c:\windows\system32\msxml.dll + 2008-04-14 02:20:34 506,368 ----a-w c:\windows\system32\msxml.dll - 2004-08-04 03:45:26 701,440 ----a-w c:\windows\system32\msxml2.dll + 2008-04-14 02:20:34 701,440 ----a-w c:\windows\system32\msxml2.dll + 2008-09-10 01:15:24 1,307,648 ------w c:\windows\system32\msxml6.dll + 2008-04-14 01:58:05 86,016 ------w c:\windows\system32\msxml6r.dll - 2004-08-04 03:55:42 17,408 ----a-w c:\windows\system32\msyuv.dll + 2008-04-14 02:20:34 16,896 ----a-w c:\windows\system32\msyuv.dll - 2006-03-01 19:44:01 66,560 ----a-w c:\windows\system32\mtxclu.dll + 2008-04-14 02:20:34 66,560 ----a-w c:\windows\system32\mtxclu.dll - 2001-10-28 15:07:06 20,480 ----a-w c:\windows\system32\mtxdm.dll + 2008-04-14 02:20:34 30,720 ----a-w c:\windows\system32\mtxdm.dll - 2001-10-28 15:07:06 4,096 ----a-w c:\windows\system32\mtxex.dll + 2008-04-14 02:20:34 4,096 ----a-w c:\windows\system32\mtxex.dll - 2001-10-28 15:07:06 25,088 ----a-w c:\windows\system32\mtxlegih.dll + 2008-04-14 02:20:34 34,304 ----a-w c:\windows\system32\mtxlegih.dll - 2006-03-01 19:44:01 91,136 ----a-w c:\windows\system32\mtxoci.dll + 2008-04-14 02:20:34 91,648 ----a-w c:\windows\system32\mtxoci.dll + 2008-04-14 02:20:34 1,737,856 ------w c:\windows\system32\mtxparhd.dll - 2004-08-04 03:45:26 310,784 ----a-w c:\windows\system32\mydocs.dll + 2008-04-14 02:20:34 90,624 ----a-w c:\windows\system32\mydocs.dll + 2008-04-14 02:20:34 30,208 ------w c:\windows\system32\napipsec.dll + 2008-04-14 02:20:34 198,656 ------w c:\windows\system32\napmontr.dll + 2008-04-14 02:21:11 176,640 ------w c:\windows\system32\napstat.exe - 2004-08-04 03:45:40 53,760 ----a-w c:\windows\system32\narrator.exe + 2008-04-14 02:21:11 53,760 ----a-w c:\windows\system32\narrator.exe - 2004-08-04 03:45:26 36,352 ----a-w c:\windows\system32\ncobjapi.dll + 2008-04-14 02:20:34 36,352 ----a-w c:\windows\system32\ncobjapi.dll - 2004-08-04 03:45:26 18,432 ----a-w c:\windows\system32\nddeapi.dll + 2008-04-14 02:20:34 18,432 ----a-w c:\windows\system32\nddeapi.dll - 2004-08-04 03:45:40 4,096 ----a-w c:\windows\system32\nddeapir.exe + 2008-04-14 02:21:11 4,096 ----a-w c:\windows\system32\nddeapir.exe - 2004-08-04 03:45:26 19,456 ----a-w c:\windows\system32\nddenb32.dll + 2008-04-14 02:20:34 19,456 ----a-w c:\windows\system32\nddenb32.dll - 2004-08-04 03:45:40 42,496 ----a-w c:\windows\system32\net.exe + 2008-04-14 02:21:11 42,496 ----a-w c:\windows\system32\net.exe - 2004-08-04 03:45:40 124,928 ----a-w c:\windows\system32\net1.exe + 2008-04-14 02:21:11 124,928 ----a-w c:\windows\system32\net1.exe - 2008-10-15 16:59:29 332,800 ----a-w c:\windows\system32\netapi32.dll + 2008-10-15 16:36:42 337,408 ----a-w c:\windows\system32\netapi32.dll - 2004-08-04 03:45:26 629,248 ----a-w c:\windows\system32\netcfgx.dll + 2008-04-14 02:20:34 629,760 ----a-w c:\windows\system32\netcfgx.dll - 2004-08-04 03:45:40 113,664 ----a-w c:\windows\system32\netdde.exe + 2008-04-14 02:21:11 113,664 ----a-w c:\windows\system32\netdde.exe - 2004-08-04 03:45:26 141,824 ----a-w c:\windows\system32\netid.dll + 2008-04-14 02:20:34 141,824 ----a-w c:\windows\system32\netid.dll - 2004-08-04 03:45:26 407,040 ----a-w c:\windows\system32\netlogon.dll + 2008-04-14 02:20:34 407,040 ----a-w c:\windows\system32\netlogon.dll - 2005-08-22 18:34:58 197,632 ----a-w c:\windows\system32\netman.dll + 2008-04-14 02:20:34 198,144 ----a-w c:\windows\system32\netman.dll - 2004-08-04 03:45:26 2,028,544 ----a-w c:\windows\system32\netplwiz.dll + 2008-04-14 02:20:34 879,616 ----a-w c:\windows\system32\netplwiz.dll - 2004-08-04 03:45:26 12,288 ----a-w c:\windows\system32\netrap.dll + 2008-04-14 02:20:34 11,776 ----a-w c:\windows\system32\netrap.dll - 2004-08-04 03:48:08 332,800 ----a-w c:\windows\system32\netsetup.exe + 2008-04-14 02:24:30 332,800 ----a-w c:\windows\system32\netsetup.exe - 2004-08-04 03:45:40 87,040 ----a-w c:\windows\system32\netsh.exe + 2008-04-14 02:21:11 87,040 ----a-w c:\windows\system32\netsh.exe - 2004-08-04 03:45:26 2,318,336 ----a-w c:\windows\system32\netshell.dll + 2008-04-14 02:20:36 1,710,592 ----a-w c:\windows\system32\netshell.dll - 2004-08-04 03:45:40 37,376 ----a-w c:\windows\system32\netstat.exe + 2008-04-14 02:21:12 37,376 ----a-w c:\windows\system32\netstat.exe - 2004-08-04 03:45:26 81,920 ----a-w c:\windows\system32\netui0.dll + 2008-04-14 02:20:36 81,920 ----a-w c:\windows\system32\netui0.dll - 2004-08-04 03:45:26 245,760 ----a-w c:\windows\system32\netui1.dll + 2008-04-14 02:20:36 245,760 ----a-w c:\windows\system32\netui1.dll - 2004-08-04 03:45:26 700,928 ----a-w c:\windows\system32\newdev.dll + 2008-04-14 02:20:36 249,344 ----a-w c:\windows\system32\newdev.dll - 2004-08-04 03:45:26 103,936 ----a-w c:\windows\system32\nlhtml.dll + 2008-04-14 02:20:36 98,304 ----a-w c:\windows\system32\nlhtml.dll - 2004-08-04 03:45:26 28,672 ----a-w c:\windows\system32\nmmkcert.dll + 2008-04-14 02:20:36 28,672 ----a-w c:\windows\system32\nmmkcert.dll - 2004-08-04 03:45:40 182,784 ----a-w c:\windows\system32\notepad.exe + 2008-04-14 02:21:12 70,144 ----a-w c:\windows\system32\notepad.exe - 2004-08-04 03:45:26 57,344 ----a-w c:\windows\system32\npp\ndisnpp.dll + 2008-04-14 02:20:34 57,344 ----a-w c:\windows\system32\npp\ndisnpp.dll - 2004-08-04 03:45:40 15,360 ----a-w c:\windows\system32\npp\nppagent.exe + 2008-04-14 02:21:12 15,360 ----a-w c:\windows\system32\npp\nppagent.exe - 2004-08-04 03:45:26 55,296 ----a-w c:\windows\system32\npptools.dll + 2008-04-14 02:20:36 55,296 ----a-w c:\windows\system32\npptools.dll - 2004-08-04 03:45:40 93,696 ----a-w c:\windows\system32\nslookup.exe + 2008-04-14 02:21:12 79,360 ----a-w c:\windows\system32\nslookup.exe - 2004-08-04 03:45:40 1,530,880 ----a-w c:\windows\system32\ntbackup.exe + 2008-04-14 02:21:13 1,219,072 ----a-w c:\windows\system32\ntbackup.exe - 2004-08-04 03:45:18 723,968 ----a-w c:\windows\system32\ntdll.dll + 2008-04-14 02:20:06 721,920 ----a-w c:\windows\system32\ntdll.dll - 2004-08-04 03:45:26 67,072 ----a-w c:\windows\system32\ntdsapi.dll + 2008-04-14 02:20:37 67,072 ----a-w c:\windows\system32\ntdsapi.dll - 2008-08-14 13:45:24 2,061,952 ----a-w c:\windows\system32\ntkrnlpa.exe + 2008-08-14 13:24:46 2,070,272 ----a-w c:\windows\system32\ntkrnlpa.exe - 2004-08-04 03:45:26 43,520 ----a-w c:\windows\system32\ntlanman.dll + 2008-04-14 02:20:37 44,032 ----a-w c:\windows\system32\ntlanman.dll - 2004-08-04 03:45:26 8,192 ----a-w c:\windows\system32\ntlsapi.dll + 2008-04-14 02:20:37 8,192 ----a-w c:\windows\system32\ntlsapi.dll - 2004-08-04 03:45:26 119,296 ----a-w c:\windows\system32\ntmarta.dll + 2008-04-14 02:20:37 119,296 ----a-w c:\windows\system32\ntmarta.dll - 2004-08-04 03:45:26 40,960 ----a-w c:\windows\system32\ntmsapi.dll + 2008-04-14 02:20:37 40,960 ----a-w c:\windows\system32\ntmsapi.dll - 2004-08-04 03:45:26 180,224 ----a-w c:\windows\system32\ntmsdba.dll + 2008-04-14 02:20:37 180,224 ----a-w c:\windows\system32\ntmsdba.dll - 2004-08-04 03:45:26 493,056 ----a-w c:\windows\system32\ntmsmgr.dll + 2008-04-14 02:20:37 493,056 ----a-w c:\windows\system32\ntmsmgr.dll - 2004-08-04 03:45:26 437,248 ----a-w c:\windows\system32\ntmssvc.dll + 2008-04-14 02:20:37 437,248 ----a-w c:\windows\system32\ntmssvc.dll - 2008-08-14 13:45:25 2,184,576 ----a-w c:\windows\system32\ntoskrnl.exe + 2008-08-14 13:24:45 2,193,408 ----a-w c:\windows\system32\ntoskrnl.exe - 2004-08-04 03:45:26 91,648 ----a-w c:\windows\system32\ntprint.dll + 2008-04-14 02:20:37 91,648 ----a-w c:\windows\system32\ntprint.dll - 2004-08-04 03:45:26 145,408 ----a-w c:\windows\system32\ntshrui.dll + 2008-04-14 02:20:37 145,408 ----a-w c:\windows\system32\ntshrui.dll Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 continuando 4: - 2004-08-04 03:45:40 420,352 ----a-w c:\windows\system32\ntvdm.exe + 2008-04-14 02:21:13 421,376 ----a-w c:\windows\system32\ntvdm.exe - 2001-10-28 15:07:12 13,312 ----a-w c:\windows\system32\ntvdmd.dll + 2008-04-14 02:20:37 15,360 ----a-w c:\windows\system32\ntvdmd.dll - 2006-10-13 12:36:57 64,000 ----a-w c:\windows\system32\nwapi32.dll + 2008-04-14 02:20:37 64,000 ----a-w c:\windows\system32\nwapi32.dll - 2006-10-13 12:36:57 143,360 ----a-w c:\windows\system32\nwprovau.dll + 2008-04-14 02:20:37 143,360 ----a-w c:\windows\system32\nwprovau.dll - 2006-10-13 12:36:57 65,536 ----a-w c:\windows\system32\nwwks.dll + 2008-04-14 02:20:37 65,536 ----a-w c:\windows\system32\nwwks.dll - 2004-08-04 03:45:26 267,776 ----a-w c:\windows\system32\oakley.dll + 2008-04-14 02:20:37 271,360 ----a-w c:\windows\system32\oakley.dll - 2004-08-04 03:45:26 286,720 ----a-w c:\windows\system32\objsel.dll + 2008-04-14 02:20:37 287,232 ----a-w c:\windows\system32\objsel.dll - 2004-08-04 03:45:26 97,280 ----a-w c:\windows\system32\occache.dll + 2008-04-14 02:20:37 97,280 ----a-w c:\windows\system32\occache.dll - 2001-10-28 15:07:14 62,464 ----a-w c:\windows\system32\ocmanage.dll + 2008-04-14 02:20:37 69,120 ----a-w c:\windows\system32\ocmanage.dll - 2004-08-04 03:45:26 249,856 ----a-w c:\windows\system32\odbc32.dll + 2008-04-14 02:20:37 249,856 ----a-w c:\windows\system32\odbc32.dll - 2004-08-04 03:45:26 16,384 ----a-w c:\windows\system32\odbc32gt.dll + 2008-04-14 02:20:37 16,384 ----a-w c:\windows\system32\odbc32gt.dll - 2004-08-04 03:45:40 32,768 ----a-w c:\windows\system32\odbcad32.exe + 2008-04-14 02:21:13 32,768 ----a-w c:\windows\system32\odbcad32.exe - 2004-08-04 03:45:26 24,576 ----a-w c:\windows\system32\odbcbcp.dll + 2008-04-14 02:20:37 24,576 ----a-w c:\windows\system32\odbcbcp.dll - 2004-08-04 03:45:26 135,168 ----a-w c:\windows\system32\odbcconf.dll + 2008-04-14 02:20:37 135,168 ----a-w c:\windows\system32\odbcconf.dll - 2004-08-04 03:45:40 69,632 ----a-w c:\windows\system32\odbcconf.exe + 2008-04-14 02:21:13 69,632 ----a-w c:\windows\system32\odbcconf.exe - 2004-08-04 03:45:26 106,496 ----a-w c:\windows\system32\odbccp32.dll + 2008-04-14 02:20:37 106,496 ----a-w c:\windows\system32\odbccp32.dll - 2004-08-04 03:45:26 65,536 ----a-w c:\windows\system32\odbccr32.dll + 2008-04-14 02:20:37 65,536 ----a-w c:\windows\system32\odbccr32.dll - 2004-08-04 03:45:26 65,536 ----a-w c:\windows\system32\odbccu32.dll + 2008-04-14 02:20:37 65,536 ----a-w c:\windows\system32\odbccu32.dll - 2004-08-04 03:44:44 102,400 ----a-w c:\windows\system32\odbcint.dll + 2007-03-28 12:54:29 98,304 ----a-w c:\windows\system32\odbcint.dll - 2004-08-04 03:44:44 57,616 ----a-w c:\windows\system32\odbcji32.dll + 2008-04-14 02:19:17 57,375 ----a-w c:\windows\system32\odbcji32.dll - 2004-08-04 03:45:26 278,559 ----a-w c:\windows\system32\odbcjt32.dll + 2008-04-14 02:20:37 278,559 ----a-w c:\windows\system32\odbcjt32.dll - 2004-08-04 03:44:44 12,288 ----a-w c:\windows\system32\odbcp32r.dll + 2008-04-13 17:26:05 12,288 ----a-w c:\windows\system32\odbcp32r.dll - 2004-08-04 03:45:26 147,456 ----a-w c:\windows\system32\odbctrac.dll + 2008-04-14 02:20:37 147,456 ----a-w c:\windows\system32\odbctrac.dll - 2004-08-04 03:45:26 20,511 ----a-w c:\windows\system32\oddbse32.dll + 2008-04-14 02:20:37 20,511 ----a-w c:\windows\system32\oddbse32.dll - 2004-08-04 03:45:26 20,510 ----a-w c:\windows\system32\odexl32.dll + 2008-04-14 02:20:37 20,510 ----a-w c:\windows\system32\odexl32.dll - 2004-08-04 03:45:26 20,510 ----a-w c:\windows\system32\odfox32.dll + 2008-04-14 02:20:37 20,510 ----a-w c:\windows\system32\odfox32.dll - 2004-08-04 03:45:26 20,510 ----a-w c:\windows\system32\odpdx32.dll + 2008-04-14 02:20:37 20,510 ----a-w c:\windows\system32\odpdx32.dll - 2004-08-04 03:45:26 20,511 ----a-w c:\windows\system32\odtext32.dll + 2008-04-14 02:20:37 20,511 ----a-w c:\windows\system32\odtext32.dll - 2004-08-04 03:45:26 120,832 ----a-w c:\windows\system32\offfilt.dll + 2008-04-14 02:20:37 192,000 ----a-w c:\windows\system32\offfilt.dll - 2005-07-26 04:40:32 1,284,608 ----a-w c:\windows\system32\ole32.dll + 2008-04-14 02:20:37 1,287,168 ----a-w c:\windows\system32\ole32.dll - 2007-12-04 18:41:03 550,912 ----a-w c:\windows\system32\oleaut32.dll + 2008-04-14 02:20:37 551,936 ----a-w c:\windows\system32\oleaut32.dll - 2005-07-26 04:40:32 75,264 ----a-w c:\windows\system32\olecli32.dll + 2008-04-14 02:20:37 75,264 ----a-w c:\windows\system32\olecli32.dll - 2005-07-26 04:40:32 37,888 ----a-w c:\windows\system32\olecnv32.dll + 2008-04-14 02:20:37 37,376 ----a-w c:\windows\system32\olecnv32.dll - 2006-10-16 16:15:45 123,904 ----a-w c:\windows\system32\oledlg.dll + 2008-04-14 02:20:37 123,904 ----a-w c:\windows\system32\oledlg.dll - 2004-08-04 03:45:26 109,056 ----a-w c:\windows\system32\oleprn.dll + 2008-04-14 02:20:37 109,056 ----a-w c:\windows\system32\oleprn.dll - 2004-08-04 03:45:26 83,456 ----a-w c:\windows\system32\olepro32.dll + 2008-04-14 02:20:37 84,992 ----a-w c:\windows\system32\olepro32.dll + 2008-04-14 02:20:37 144,896 ------w c:\windows\system32\onex.dll - 2004-08-04 03:45:26 122,368 ----a-w c:\windows\system32\oobe\msobcomm.dll + 2008-04-14 02:20:34 122,368 ----a-w c:\windows\system32\oobe\msobcomm.dll - 2004-08-04 03:45:26 16,384 ----a-w c:\windows\system32\oobe\msobdl.dll + 2008-04-14 02:20:34 16,384 ----a-w c:\windows\system32\oobe\msobdl.dll - 2004-08-04 03:45:26 562,176 ----a-w c:\windows\system32\oobe\msobmain.dll + 2008-04-14 02:20:34 566,272 ----a-w c:\windows\system32\oobe\msobmain.dll - 2004-08-04 03:45:26 31,232 ----a-w c:\windows\system32\oobe\msobshel.dll + 2008-04-14 02:20:34 30,720 ----a-w c:\windows\system32\oobe\msobshel.dll - 2004-08-04 03:45:26 18,944 ----a-w c:\windows\system32\oobe\msobweb.dll + 2008-04-14 02:20:34 19,456 ----a-w c:\windows\system32\oobe\msobweb.dll - 2001-10-28 15:07:04 28,160 ----a-w c:\windows\system32\oobe\msoobe.exe + 2008-04-14 02:21:10 29,184 ----a-w c:\windows\system32\oobe\msoobe.exe - 2004-08-04 03:45:40 51,712 ----a-w c:\windows\system32\oobe\oobebaln.exe + 2008-04-14 02:21:13 51,712 ----a-w c:\windows\system32\oobe\oobebaln.exe - 2004-08-04 03:45:40 70,144 ----a-w c:\windows\system32\openfiles.exe + 2008-04-14 02:21:13 70,144 ----a-w c:\windows\system32\openfiles.exe - 2004-08-04 03:45:26 713,728 ----a-w c:\windows\system32\opengl32.dll + 2008-04-14 02:20:37 713,728 ----a-w c:\windows\system32\opengl32.dll - 2004-08-04 03:45:40 216,064 ----a-w c:\windows\system32\osk.exe + 2008-04-14 02:21:14 216,064 ----a-w c:\windows\system32\osk.exe - 2004-08-04 03:45:26 67,584 ----a-w c:\windows\system32\osuninst.dll + 2008-04-14 02:20:37 67,584 ----a-w c:\windows\system32\osuninst.dll - 2004-08-04 03:45:26 116,224 ----a-w c:\windows\system32\p2p.dll + 2008-04-14 02:20:37 153,600 ----a-w c:\windows\system32\p2p.dll - 2004-08-04 03:45:26 86,016 ----a-w c:\windows\system32\p2pgasvc.dll + 2008-04-14 02:20:37 105,472 ----a-w c:\windows\system32\p2pgasvc.dll - 2004-08-04 03:45:26 312,320 ----a-w c:\windows\system32\p2pgraph.dll + 2008-04-14 02:20:37 313,856 ----a-w c:\windows\system32\p2pgraph.dll - 2004-08-04 03:45:26 88,064 ----a-w c:\windows\system32\p2pnetsh.dll + 2008-04-14 02:20:37 115,712 ----a-w c:\windows\system32\p2pnetsh.dll - 2004-08-04 03:45:26 526,848 ----a-w c:\windows\system32\p2psvc.dll + 2008-04-14 02:20:37 554,496 ----a-w c:\windows\system32\p2psvc.dll - 2004-08-04 03:45:40 58,880 ----a-w c:\windows\system32\packager.exe + 2008-04-14 02:21:14 58,880 ----a-w c:\windows\system32\packager.exe - 2004-08-04 03:45:26 64,000 ----a-w c:\windows\system32\pautoenr.dll + 2008-04-14 02:20:37 68,608 ----a-w c:\windows\system32\pautoenr.dll - 2004-08-04 03:45:26 285,696 ----a-w c:\windows\system32\pdh.dll + 2008-04-14 02:20:37 286,208 ----a-w c:\windows\system32\pdh.dll - 2009-01-13 18:49:19 64,372 ----a-w c:\windows\system32\perfc009.dat + 2009-01-22 18:56:50 64,372 ----a-w c:\windows\system32\perfc009.dat - 2009-01-13 18:49:19 73,122 ----a-w c:\windows\system32\perfc016.dat + 2009-01-22 18:56:50 73,122 ----a-w c:\windows\system32\perfc016.dat - 2004-08-04 03:45:26 40,960 ----a-w c:\windows\system32\perfctrs.dll + 2008-04-14 02:20:37 40,960 ----a-w c:\windows\system32\perfctrs.dll - 2004-08-04 03:45:26 27,136 ----a-w c:\windows\system32\perfdisk.dll + 2008-04-14 02:20:37 27,136 ----a-w c:\windows\system32\perfdisk.dll - 2009-01-13 18:49:19 409,232 ----a-w c:\windows\system32\perfh009.dat + 2009-01-22 18:56:50 409,232 ----a-w c:\windows\system32\perfh009.dat - 2009-01-13 18:49:19 442,018 ----a-w c:\windows\system32\perfh016.dat + 2009-01-22 18:56:51 442,018 ----a-w c:\windows\system32\perfh016.dat - 2004-08-04 03:45:40 29,696 ----a-w c:\windows\system32\perfmon.exe + 2008-04-14 02:21:14 15,872 ----a-w c:\windows\system32\perfmon.exe - 2001-10-28 15:07:18 17,408 ----a-w c:\windows\system32\perfnet.dll + 2008-04-14 02:20:37 18,432 ----a-w c:\windows\system32\perfnet.dll - 2004-08-04 03:45:26 26,112 ----a-w c:\windows\system32\perfos.dll + 2008-04-14 02:20:37 26,112 ----a-w c:\windows\system32\perfos.dll - 2004-08-04 03:45:26 35,328 ----a-w c:\windows\system32\perfproc.dll + 2008-04-14 02:20:37 35,328 ----a-w c:\windows\system32\perfproc.dll + 2008-04-14 02:20:37 412,160 ------w c:\windows\system32\photometadatahandler.dll - 2004-08-04 03:45:26 480,768 ----a-w c:\windows\system32\photowiz.dll + 2008-04-14 02:20:37 172,032 ----a-w c:\windows\system32\photowiz.dll - 2004-08-04 03:55:42 35,328 ----a-w c:\windows\system32\pid.dll + 2008-04-14 02:20:37 35,328 ----a-w c:\windows\system32\pid.dll - 2004-08-04 03:44:12 24,064 ----a-w c:\windows\system32\pidgen.dll + 2008-04-14 02:18:21 24,064 ----a-w c:\windows\system32\pidgen.dll - 2004-08-04 03:45:40 19,456 ----a-w c:\windows\system32\ping.exe + 2008-04-14 02:21:14 19,456 ----a-w c:\windows\system32\ping.exe - 2004-08-04 03:55:42 15,360 ----a-w c:\windows\system32\pjlmon.dll + 2008-04-14 02:20:37 15,360 ----a-w c:\windows\system32\pjlmon.dll - 2009-01-01 22:36:00 278,528 ----a-w c:\windows\system32\pncrt.dll + 2009-02-05 04:00:25 278,528 ----a-w c:\windows\system32\pncrt.dll - 2009-01-01 22:36:08 6,656 ----a-w c:\windows\system32\pndx5016.dll + 2009-02-05 04:00:26 6,656 ----a-w c:\windows\system32\pndx5016.dll - 2009-01-01 22:36:08 5,632 ----a-w c:\windows\system32\pndx5032.dll + 2009-02-05 04:00:26 5,632 ----a-w c:\windows\system32\pndx5032.dll - 2008-10-16 10:39:08 39,424 ----a-w c:\windows\system32\pngfilt.dll + 2008-04-14 02:20:37 39,424 ----a-w c:\windows\system32\pngfilt.dll - 2004-08-04 03:45:26 48,640 ----a-w c:\windows\system32\pnrpnsp.dll + 2008-04-14 02:20:37 58,880 ----a-w c:\windows\system32\pnrpnsp.dll - 2004-08-04 03:45:26 105,984 ----a-w c:\windows\system32\polstore.dll + 2008-04-14 02:20:37 105,984 ----a-w c:\windows\system32\polstore.dll - 2004-08-04 03:45:40 49,152 ----a-w c:\windows\system32\powercfg.exe + 2008-04-14 02:21:14 49,152 ----a-w c:\windows\system32\powercfg.exe - 2004-08-04 03:45:26 17,408 ----a-w c:\windows\system32\powrprof.dll + 2008-04-14 02:20:37 17,408 ----a-w c:\windows\system32\powrprof.dll - 2004-08-04 03:45:26 901,632 ----a-w c:\windows\system32\printui.dll + 2008-04-14 02:20:37 572,928 ----a-w c:\windows\system32\printui.dll - 2004-08-04 03:45:26 27,648 ----a-w c:\windows\system32\profmap.dll + 2008-04-14 02:20:37 27,648 ----a-w c:\windows\system32\profmap.dll - 2004-08-04 03:45:40 109,568 ----a-w c:\windows\system32\progman.exe + 2008-04-14 02:21:15 109,568 ----a-w c:\windows\system32\progman.exe - 2004-08-04 03:45:40 50,688 ----a-w c:\windows\system32\proquota.exe + 2008-04-14 02:21:15 50,688 ----a-w c:\windows\system32\proquota.exe - 2004-08-04 03:45:40 9,728 ----a-w c:\windows\system32\proxycfg.exe + 2008-04-14 02:21:15 9,728 ----a-w c:\windows\system32\proxycfg.exe - 2004-08-04 03:45:26 23,040 ----a-w c:\windows\system32\psapi.dll + 2008-04-14 02:20:37 23,040 ----a-w c:\windows\system32\psapi.dll - 2004-08-04 03:45:26 97,280 ----a-w c:\windows\system32\psbase.dll + 2008-04-14 02:20:37 97,280 ----a-w c:\windows\system32\psbase.dll - 2004-08-04 03:45:26 43,520 ----a-w c:\windows\system32\pstorec.dll + 2008-04-14 02:20:37 43,520 ----a-w c:\windows\system32\pstorec.dll - 2004-08-04 03:45:26 34,304 ----a-w c:\windows\system32\pstorsvc.dll + 2008-04-14 02:20:37 34,304 ----a-w c:\windows\system32\pstorsvc.dll + 2008-04-14 02:20:31 16,384 ------w c:\windows\system32\pt-br\microsoft.managementconsole.resources.dll + 2008-04-14 02:20:31 36,864 ------w c:\windows\system32\pt-br\mmcex.resources.dll + 2008-04-14 02:20:32 5,120 ------w c:\windows\system32\pt-br\mmcfxcommon.resources.dll + 2008-04-14 02:20:37 150,528 ------w c:\windows\system32\qagent.dll + 2008-04-14 02:20:37 292,864 ------w c:\windows\system32\qagentrt.dll - 2004-08-04 03:45:26 192,512 ----a-w c:\windows\system32\qcap.dll + 2008-04-14 02:20:37 192,512 ----a-w c:\windows\system32\qcap.dll + 2008-04-14 02:20:37 62,464 ------w c:\windows\system32\qcliprov.dll - 2004-08-04 03:45:26 279,040 ----a-w c:\windows\system32\qdv.dll + 2008-04-14 02:20:37 279,040 ----a-w c:\windows\system32\qdv.dll - 2004-08-04 03:45:26 385,536 ----a-w c:\windows\system32\qdvd.dll + 2008-04-14 02:20:37 386,560 ----a-w c:\windows\system32\qdvd.dll - 2004-08-04 03:45:26 563,200 ----a-w c:\windows\system32\qedit.dll + 2008-04-14 02:20:37 563,200 ----a-w c:\windows\system32\qedit.dll - 2004-08-04 03:44:46 733,696 ----a-w c:\windows\system32\qedwipes.dll + 2008-04-13 17:21:32 733,696 ----a-w c:\windows\system32\qedwipes.dll - 2004-08-04 03:45:26 382,464 ----a-w c:\windows\system32\qmgr.dll + 2008-04-14 02:20:37 409,088 ----a-w c:\windows\system32\qmgr.dll - 2004-08-04 03:45:26 18,944 ----a-w c:\windows\system32\qmgrprxy.dll + 2008-04-14 02:20:37 18,944 ----a-w c:\windows\system32\qmgrprxy.dll - 2004-08-04 03:45:40 20,480 ----a-w c:\windows\system32\qprocess.exe + 2008-04-14 02:21:15 20,480 ----a-w c:\windows\system32\qprocess.exe - 2008-05-07 05:15:38 2,660,864 ----a-w c:\windows\system32\quartz.dll + 2008-05-07 05:11:33 1,292,800 ----a-w c:\windows\system32\quartz.dll - 2006-06-22 05:17:16 1,439,744 ----a-w c:\windows\system32\query.dll + 2008-04-14 02:20:37 1,439,744 ----a-w c:\windows\system32\query.dll + 2008-04-14 02:20:37 76,800 ------w c:\windows\system32\qutil.dll - 2004-08-04 03:45:26 43,520 ----a-w c:\windows\system32\racpldlg.dll + 2008-04-14 02:20:37 43,520 ----a-w c:\windows\system32\racpldlg.dll - 2006-06-26 17:41:41 8,192 ----a-w c:\windows\system32\rasadhlp.dll + 2008-04-14 02:20:37 7,680 ----a-w c:\windows\system32\rasadhlp.dll - 2004-08-04 03:45:26 236,544 ----a-w c:\windows\system32\rasapi32.dll + 2008-04-14 02:20:37 237,056 ----a-w c:\windows\system32\rasapi32.dll - 2004-08-04 03:45:26 89,088 ----a-w c:\windows\system32\rasauto.dll + 2008-04-14 02:20:37 88,576 ----a-w c:\windows\system32\rasauto.dll - 2004-08-04 03:45:26 69,632 ----a-w c:\windows\system32\raschap.dll + 2008-04-14 02:20:38 79,872 ----a-w c:\windows\system32\raschap.dll - 2004-08-04 03:45:26 1,001,984 ----a-w c:\windows\system32\rasdlg.dll + 2008-04-14 02:20:38 673,280 ----a-w c:\windows\system32\rasdlg.dll - 2004-08-04 03:45:26 61,440 ----a-w c:\windows\system32\rasman.dll + 2008-04-14 02:20:38 61,440 ----a-w c:\windows\system32\rasman.dll - 2006-06-22 10:48:30 181,248 ----a-w c:\windows\system32\rasmans.dll + 2008-04-14 02:20:38 186,368 ----a-w c:\windows\system32\rasmans.dll - 2004-08-04 03:45:40 57,344 ----a-w c:\windows\system32\rasphone.exe + 2008-04-14 02:21:15 57,344 ----a-w c:\windows\system32\rasphone.exe - 2004-08-04 03:45:26 206,336 ----a-w c:\windows\system32\rasppp.dll + 2008-04-14 02:20:38 210,944 ----a-w c:\windows\system32\rasppp.dll + 2008-04-14 02:20:38 61,952 ------w c:\windows\system32\rasqec.dll - 2004-08-04 03:45:26 16,896 ----a-w c:\windows\system32\rassapi.dll + 2008-04-14 02:20:38 16,384 ----a-w c:\windows\system32\rassapi.dll - 2004-08-04 03:45:26 58,880 ----a-w c:\windows\system32\rastapi.dll + 2008-04-14 02:20:38 58,368 ----a-w c:\windows\system32\rastapi.dll - 2004-08-04 03:45:26 112,640 ----a-w c:\windows\system32\rastls.dll + 2008-04-14 02:20:38 150,528 ----a-w c:\windows\system32\rastls.dll - 2004-08-04 03:45:26 102,912 ----a-w c:\windows\system32\rcbdyctl.dll + 2008-04-14 02:20:38 102,912 ----a-w c:\windows\system32\rcbdyctl.dll - 2004-08-04 03:45:40 35,840 ----a-w c:\windows\system32\rcimlby.exe + 2008-04-14 02:21:15 35,840 ----a-w c:\windows\system32\rcimlby.exe - 2004-08-04 03:45:40 23,040 ----a-w c:\windows\system32\rcp.exe + 2008-04-14 02:21:15 23,040 ----a-w c:\windows\system32\rcp.exe - 2004-08-04 03:45:26 147,968 ----a-w c:\windows\system32\rdchost.dll + 2008-04-14 02:20:38 147,968 ----a-w c:\windows\system32\rdchost.dll - 2004-08-04 03:45:42 62,464 ----a-w c:\windows\system32\rdpclip.exe + 2008-04-14 02:21:16 62,976 ----a-w c:\windows\system32\rdpclip.exe - 2004-08-04 03:45:56 92,168 ----a-w c:\windows\system32\rdpdd.dll + 2008-04-14 02:21:50 92,424 ----a-w c:\windows\system32\rdpdd.dll - 2004-08-04 03:45:26 19,968 ----a-w c:\windows\system32\rdpsnd.dll + 2008-04-14 02:20:38 19,968 ----a-w c:\windows\system32\rdpsnd.dll - 2004-08-04 03:45:56 87,176 ----a-w c:\windows\system32\rdpwsx.dll + 2008-04-14 02:21:51 87,176 ----a-w c:\windows\system32\rdpwsx.dll - 2004-08-04 03:45:42 13,824 ----a-w c:\windows\system32\rdsaddin.exe + 2008-04-14 02:21:16 13,824 ----a-w c:\windows\system32\rdsaddin.exe - 2004-08-04 03:45:42 67,072 ----a-w c:\windows\system32\rdshost.exe + 2008-04-14 02:21:16 67,072 ----a-w c:\windows\system32\rdshost.exe - 2004-08-04 03:45:42 51,200 ----a-w c:\windows\system32\reg.exe + 2008-04-14 02:21:16 51,200 ----a-w c:\windows\system32\reg.exe - 2004-08-04 03:45:26 49,664 ----a-w c:\windows\system32\regapi.dll + 2008-04-14 02:20:38 49,664 ----a-w c:\windows\system32\regapi.dll - 2004-08-04 03:45:26 59,904 ----a-w c:\windows\system32\regsvc.dll + 2008-04-14 02:20:38 59,904 ----a-w c:\windows\system32\regsvc.dll - 2004-08-04 03:45:42 11,776 ----a-w c:\windows\system32\regsvr32.exe + 2008-04-14 02:21:16 11,776 ----a-w c:\windows\system32\regsvr32.exe - 2004-08-04 03:45:26 399,360 ----a-w c:\windows\system32\regwizc.dll + 2008-04-14 02:20:38 399,360 ----a-w c:\windows\system32\regwizc.dll + 2008-04-14 02:20:27 20,992 ----a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\hid.dll + 2008-04-13 18:45:26 36,864 ----a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\hidclass.sys + 2008-04-13 18:45:22 24,960 ----a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\hidparse.sys + 2008-04-13 18:45:28 10,368 ----a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\hidusb.sys + 2008-04-14 01:58:36 25,088 ----a-w c:\windows\system32\ReinstallBackups\0011\DriverFiles\i386\kbdclass.sys + 2008-04-14 01:58:36 14,720 ----a-w c:\windows\system32\ReinstallBackups\0011\DriverFiles\i386\kbdhid.sys + 2008-04-14 02:20:27 20,992 ----a-w c:\windows\system32\ReinstallBackups\0012\DriverFiles\i386\hid.dll + 2008-04-13 18:45:26 36,864 ----a-w c:\windows\system32\ReinstallBackups\0012\DriverFiles\i386\hidclass.sys + 2008-04-13 18:45:22 24,960 ----a-w c:\windows\system32\ReinstallBackups\0012\DriverFiles\i386\hidparse.sys + 2008-04-13 18:45:28 10,368 ----a-w c:\windows\system32\ReinstallBackups\0012\DriverFiles\i386\hidusb.sys - 2004-08-04 03:45:26 82,944 ----a-w c:\windows\system32\remotepg.dll + 2008-04-14 02:20:39 61,440 ----a-w c:\windows\system32\remotepg.dll - 2004-08-04 03:45:42 506,368 ----a-w c:\windows\system32\Restore\rstrui.exe + 2008-04-14 02:21:17 382,976 ----a-w c:\windows\system32\Restore\rstrui.exe - 2004-08-04 03:45:26 58,880 ----a-w c:\windows\system32\resutils.dll + 2008-04-14 02:20:39 58,880 ----a-w c:\windows\system32\resutils.dll - 2004-08-04 03:45:42 14,848 ----a-w c:\windows\system32\rexec.exe + 2008-04-14 02:21:16 14,848 ----a-w c:\windows\system32\rexec.exe + 2008-04-14 02:20:39 290,304 ------w c:\windows\system32\rhttpaa.dll - 2006-11-27 14:55:29 433,152 ----a-w c:\windows\system32\riched20.dll + 2008-04-14 02:20:39 433,664 ----a-w c:\windows\system32\riched20.dll - 2009-01-01 22:36:27 185,920 ----a-w c:\windows\system32\rmoc3260.dll + 2009-02-05 04:00:35 185,920 ----a-w c:\windows\system32\rmoc3260.dll - 2007-07-09 13:09:42 584,192 ----a-w c:\windows\system32\rpcrt4.dll + 2008-04-14 02:20:39 584,704 ----a-w c:\windows\system32\rpcrt4.dll - 2005-07-26 04:40:33 397,824 ----a-w c:\windows\system32\rpcss.dll + 2008-04-14 02:20:39 399,360 ----a-w c:\windows\system32\rpcss.dll - 2004-08-04 01:31:44 152,576 ----a-w c:\windows\system32\rsaenh.dll + 2008-04-13 17:37:57 208,384 ----a-w c:\windows\system32\rsaenh.dll - 2004-08-04 03:45:42 15,872 ----a-w c:\windows\system32\rsh.exe + 2008-04-14 02:21:16 15,872 ----a-w c:\windows\system32\rsh.exe - 2004-08-04 03:45:26 39,936 ----a-w c:\windows\system32\rshx32.dll + 2008-04-14 02:20:39 39,936 ----a-w c:\windows\system32\rshx32.dll - 2004-08-04 03:45:26 18,944 ----a-w c:\windows\system32\rsmps.dll + 2008-04-14 02:20:39 18,944 ----a-w c:\windows\system32\rsmps.dll - 2004-08-04 03:45:42 107,520 ----a-w c:\windows\system32\rsnotify.exe + 2008-04-14 02:21:16 107,520 ----a-w c:\windows\system32\rsnotify.exe - 2001-10-28 15:07:24 90,112 ----a-w c:\windows\system32\rsvpsp.dll + 2008-04-14 02:20:39 92,672 ----a-w c:\windows\system32\rsvpsp.dll - 2004-08-04 03:45:42 78,336 ----a-w c:\windows\system32\rtcshare.exe + 2008-04-14 02:21:17 78,336 ----a-w c:\windows\system32\rtcshare.exe - 2004-08-04 03:45:26 31,744 ----a-w c:\windows\system32\rtipxmib.dll + 2008-04-14 02:20:39 31,744 ----a-w c:\windows\system32\rtipxmib.dll - 2004-08-04 03:45:26 44,032 ----a-w c:\windows\system32\rtutils.dll + 2008-04-14 02:20:39 44,032 ----a-w c:\windows\system32\rtutils.dll - 2004-08-04 03:45:42 33,280 ----a-w c:\windows\system32\rundll32.exe + 2008-04-14 02:21:17 33,280 ----a-w c:\windows\system32\rundll32.exe - 2004-08-04 03:45:42 28,672 ----a-w c:\windows\system32\runonce.exe + 2008-04-14 02:21:17 14,336 ----a-w c:\windows\system32\runonce.exe + 2008-04-14 02:20:39 9,728 ------w c:\windows\system32\rwnh.dll + 2008-04-14 02:20:39 397,056 ------w c:\windows\system32\s3gnb.dll - 2004-08-04 03:45:26 43,520 ----a-w c:\windows\system32\safrcdlg.dll + 2008-04-14 02:20:39 43,520 ----a-w c:\windows\system32\safrcdlg.dll - 2004-08-04 03:45:26 29,696 ----a-w c:\windows\system32\safrdm.dll + 2008-04-14 02:20:39 29,696 ----a-w c:\windows\system32\safrdm.dll - 2004-08-04 03:45:26 45,568 ----a-w c:\windows\system32\safrslv.dll + 2008-04-14 02:20:39 45,568 ----a-w c:\windows\system32\safrslv.dll - 2004-08-04 03:45:26 64,000 ----a-w c:\windows\system32\samlib.dll + 2008-04-14 02:20:39 64,000 ----a-w c:\windows\system32\samlib.dll - 2004-08-04 03:45:26 428,032 ----a-w c:\windows\system32\samsrv.dll + 2008-04-14 02:20:40 428,032 ----a-w c:\windows\system32\samsrv.dll - 2004-08-04 03:45:42 13,824 ----a-w c:\windows\system32\savedump.exe + 2008-04-14 02:21:17 13,824 ----a-w c:\windows\system32\savedump.exe - 2004-08-04 03:45:26 270,848 ----a-w c:\windows\system32\sbe.dll + 2008-04-14 02:20:40 270,848 ----a-w c:\windows\system32\sbe.dll - 2004-08-04 03:45:26 159,232 ----a-w c:\windows\system32\sbeio.dll + 2008-04-14 02:20:40 159,232 ----a-w c:\windows\system32\sbeio.dll - 2004-08-04 03:45:26 69,632 ----a-w c:\windows\system32\scarddlg.dll + 2008-04-14 02:20:40 69,632 ----a-w c:\windows\system32\scarddlg.dll - 2004-08-04 03:45:42 99,328 ----a-w c:\windows\system32\scardsvr.exe + 2008-04-14 02:21:17 99,328 ----a-w c:\windows\system32\scardsvr.exe - 2004-08-04 03:45:26 171,008 ----a-w c:\windows\system32\sccsccp.dll + 2008-04-14 02:20:40 171,008 ----a-w c:\windows\system32\sccsccp.dll - 2004-08-04 03:45:26 183,808 ----a-w c:\windows\system32\scecli.dll + 2008-04-14 02:20:40 184,832 ----a-w c:\windows\system32\scecli.dll - 2004-08-04 03:45:26 319,488 ----a-w c:\windows\system32\scesrv.dll + 2008-04-14 02:20:40 320,512 ----a-w c:\windows\system32\scesrv.dll - 2007-04-25 14:22:27 144,896 ----a-w c:\windows\system32\schannel.dll + 2008-04-14 02:20:40 144,384 ----a-w c:\windows\system32\schannel.dll - 2004-08-04 03:45:26 192,000 ----a-w c:\windows\system32\schedsvc.dll + 2008-04-14 02:20:40 193,536 ----a-w c:\windows\system32\schedsvc.dll - 2004-08-04 03:45:42 126,976 ----a-w c:\windows\system32\schtasks.exe + 2008-04-14 02:21:17 126,976 ----a-w c:\windows\system32\schtasks.exe - 2004-08-04 03:45:26 21,504 ----a-w c:\windows\system32\sclgntfy.dll + 2008-04-14 02:20:40 21,504 ----a-w c:\windows\system32\sclgntfy.dll - 2004-08-04 03:45:48 9,216 ----a-w c:\windows\system32\scrnsave.scr + 2008-04-14 02:21:26 9,216 ----a-w c:\windows\system32\scrnsave.scr - 2004-08-04 03:45:28 163,840 ----a-w c:\windows\system32\scrobj.dll + 2008-05-09 10:55:05 180,224 ----a-w c:\windows\system32\scrobj.dll - 2004-08-04 03:45:28 151,552 ----a-w c:\windows\system32\scrrun.dll + 2008-05-09 10:55:05 172,032 ----a-w c:\windows\system32\scrrun.dll - 2004-08-04 03:45:42 77,824 ----a-w c:\windows\system32\sdbinst.exe + 2008-04-14 02:21:17 77,824 ----a-w c:\windows\system32\sdbinst.exe - 2004-08-04 03:45:28 29,184 ----a-w c:\windows\system32\sdhcinst.dll + 2008-04-14 02:20:40 29,184 ----a-w c:\windows\system32\sdhcinst.dll - 2004-08-04 03:45:42 18,944 ----a-w c:\windows\system32\secedit.exe + 2008-04-14 02:21:17 19,456 ----a-w c:\windows\system32\secedit.exe - 2004-08-04 03:45:28 18,944 ----a-w c:\windows\system32\seclogon.dll + 2008-04-14 02:20:40 18,944 ----a-w c:\windows\system32\seclogon.dll - 2004-08-04 03:45:28 55,808 ----a-w c:\windows\system32\secur32.dll + 2008-04-14 02:20:40 56,320 ----a-w c:\windows\system32\secur32.dll - 2004-08-04 03:45:28 5,632 ----a-w c:\windows\system32\security.dll + 2008-04-14 02:20:40 5,632 ----a-w c:\windows\system32\security.dll - 2004-08-04 03:45:28 29,696 ----a-w c:\windows\system32\sendcmsg.dll + 2008-04-14 02:20:40 29,696 ----a-w c:\windows\system32\sendcmsg.dll - 2004-08-04 03:45:28 55,296 ----a-w c:\windows\system32\sendmail.dll + 2008-04-14 02:20:40 55,296 ----a-w c:\windows\system32\sendmail.dll - 2004-08-04 03:45:28 38,912 ----a-w c:\windows\system32\sens.dll + 2008-04-14 02:20:40 39,424 ----a-w c:\windows\system32\sens.dll - 2004-08-04 03:45:28 6,656 ----a-w c:\windows\system32\sensapi.dll + 2008-04-14 02:20:40 7,168 ----a-w c:\windows\system32\sensapi.dll - 2004-08-04 03:45:28 56,320 ----a-w c:\windows\system32\servdeps.dll + 2008-04-14 02:20:40 56,320 ----a-w c:\windows\system32\servdeps.dll - 2004-08-04 03:45:42 108,544 ----a-w c:\windows\system32\services.exe + 2008-04-14 02:21:17 109,056 ----a-w c:\windows\system32\services.exe - 2004-08-04 03:45:42 142,336 ----a-w c:\windows\system32\sessmgr.exe + 2008-04-14 02:21:17 142,848 ----a-w c:\windows\system32\sessmgr.exe - 2004-08-04 03:45:42 32,768 ----a-w c:\windows\system32\sethc.exe + 2008-04-14 02:21:17 32,768 ----a-w c:\windows\system32\sethc.exe - 2004-08-04 03:45:42 23,040 ----a-w c:\windows\system32\setup.exe + 2008-04-14 02:21:17 23,040 ----a-w c:\windows\system32\setup.exe - 2001-10-28 15:06:16 259,584 ----a-w c:\windows\system32\Setup\comsetup.dll + 2008-04-14 02:20:24 274,944 ----a-w c:\windows\system32\Setup\comsetup.dll - 2004-08-04 03:45:22 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll + 2008-04-14 02:20:26 32,828 ----a-w c:\windows\system32\Setup\fp40ext.dll - 2004-08-04 03:45:24 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll + 2008-04-14 02:20:27 132,608 ----a-w c:\windows\system32\Setup\fxsocm.dll - 2004-08-04 03:45:24 507,392 ----a-w c:\windows\system32\Setup\iis.dll + 2008-04-14 02:20:28 507,392 ----a-w c:\windows\system32\Setup\iis.dll - 2001-10-28 15:06:38 117,760 ----a-w c:\windows\system32\Setup\imsinsnt.dll + 2008-04-14 02:20:28 125,440 ----a-w c:\windows\system32\Setup\imsinsnt.dll + 2008-04-14 02:20:30 8,192 ----a-w c:\windows\system32\Setup\koc.dll - 2004-08-04 03:45:24 16,896 ----a-w c:\windows\system32\Setup\medctroc.dll + 2008-04-14 02:20:30 16,896 ----a-w c:\windows\system32\Setup\medctroc.dll - 2001-10-28 15:07:02 82,432 ----a-w c:\windows\system32\Setup\msdtcstp.dll + 2008-04-14 02:20:33 90,112 ----a-w c:\windows\system32\Setup\msdtcstp.dll - 2004-08-04 03:45:24 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll + 2008-04-14 02:20:33 15,360 ----a-w c:\windows\system32\Setup\msgrocm.dll - 2004-08-04 03:45:26 169,984 ----a-w c:\windows\system32\Setup\msmqocm.dll + 2008-04-14 02:20:34 170,496 ----a-w c:\windows\system32\Setup\msmqocm.dll - 2004-08-04 03:45:26 77,824 ----a-w c:\windows\system32\Setup\netoc.dll + 2008-04-14 02:20:34 77,824 ----a-w c:\windows\system32\Setup\netoc.dll - 2004-08-04 03:45:26 63,488 ----a-w c:\windows\system32\Setup\ntoc.dll + 2008-04-14 02:20:37 63,488 ----a-w c:\windows\system32\Setup\ntoc.dll - 2004-08-04 03:45:26 15,872 ----a-w c:\windows\system32\Setup\ocgen.dll + 2008-04-14 02:20:37 15,872 ----a-w c:\windows\system32\Setup\ocgen.dll - 2004-08-04 03:45:26 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll + 2008-04-14 02:20:37 17,408 ----a-w c:\windows\system32\Setup\ocmsn.dll - 2004-08-04 03:45:28 101,888 ----a-w c:\windows\system32\Setup\setupqry.dll + 2008-04-14 02:20:40 101,888 ----a-w c:\windows\system32\Setup\setupqry.dll - 2004-08-04 03:45:28 34,304 ----a-w c:\windows\system32\Setup\tabletoc.dll + 2008-04-14 02:20:40 34,304 ----a-w c:\windows\system32\Setup\tabletoc.dll - 2004-08-04 03:45:28 123,392 ----a-w c:\windows\system32\Setup\tsoc.dll + 2008-04-14 02:20:40 131,584 ----a-w c:\windows\system32\Setup\tsoc.dll - 2004-08-04 03:45:28 1,429,504 ----a-w c:\windows\system32\setupapi.dll + 2008-04-13 21:20:42 995,328 ----a-w c:\windows\system32\setupapi.dll + 2008-04-14 02:21:18 32,768 ------w c:\windows\system32\setupn.exe - 2004-08-04 03:45:28 5,120 ----a-w c:\windows\system32\sfc.dll + 2008-04-14 02:20:40 5,120 ----a-w c:\windows\system32\sfc.dll - 2004-08-04 03:45:28 141,312 ----a-w c:\windows\system32\sfc_os.dll + 2008-04-14 02:20:40 141,312 ----a-w c:\windows\system32\sfc_os.dll - 2004-08-04 03:45:28 1,548,288 ----a-w c:\windows\system32\sfcfiles.dll + 2008-04-14 02:20:40 1,571,840 ----a-w c:\windows\system32\sfcfiles.dll - 2004-08-04 03:44:52 821,760 ----a-w c:\windows\system32\shdoclc.dll + 2008-04-14 01:55:59 563,712 ----a-w c:\windows\system32\shdoclc.dll - 2008-10-16 10:39:08 1,494,528 ----a-w c:\windows\system32\shdocvw.dll + 2008-10-16 01:02:11 1,499,136 ----a-w c:\windows\system32\shdocvw.dll - 2007-10-25 16:57:15 22,446,080 ----a-w c:\windows\system32\shell32.dll + 2008-04-14 02:20:40 8,491,008 ----a-w c:\windows\system32\shell32.dll - 2004-08-04 03:45:28 25,088 ----a-w c:\windows\system32\shfolder.dll + 2008-04-14 02:20:40 25,088 ----a-w c:\windows\system32\shfolder.dll - 2004-08-04 03:45:28 68,096 ----a-w c:\windows\system32\shgina.dll + 2008-04-14 02:20:40 68,096 ----a-w c:\windows\system32\shgina.dll - 2004-08-04 03:45:28 65,536 ----a-w c:\windows\system32\shimeng.dll + 2008-04-14 02:20:40 65,024 ----a-w c:\windows\system32\shimeng.dll - 2004-08-04 03:45:28 1,242,624 ----a-w c:\windows\system32\shimgvw.dll + 2008-04-14 02:20:40 439,296 ----a-w c:\windows\system32\shimgvw.dll - 2008-10-16 10:39:08 474,112 ----a-w c:\windows\system32\shlwapi.dll + 2008-04-14 02:20:40 474,112 ----a-w c:\windows\system32\shlwapi.dll - 2004-08-04 03:45:28 152,576 ----a-w c:\windows\system32\shmedia.dll + 2008-04-14 02:20:40 153,088 ----a-w c:\windows\system32\shmedia.dll - 2004-08-04 03:45:42 42,496 ----a-w c:\windows\system32\shmgrate.exe + 2008-04-14 02:21:18 45,056 ----a-w c:\windows\system32\shmgrate.exe - 2004-08-04 03:45:42 257,536 ----a-w c:\windows\system32\shrpubw.exe + 2008-04-14 02:21:18 78,336 ----a-w c:\windows\system32\shrpubw.exe - 2004-08-04 03:45:28 41,984 ----a-w c:\windows\system32\shscrap.dll + 2008-04-14 02:20:40 27,648 ----a-w c:\windows\system32\shscrap.dll - 2006-12-19 21:50:36 134,656 ----a-w c:\windows\system32\shsvcs.dll + 2008-04-14 02:20:40 135,168 ----a-w c:\windows\system32\shsvcs.dll - 2004-08-04 03:45:42 20,480 ----a-w c:\windows\system32\shutdown.exe + 2008-04-14 02:21:18 20,480 ----a-w c:\windows\system32\shutdown.exe - 2004-08-04 03:45:28 13,824 ----a-w c:\windows\system32\sigtab.dll + 2008-04-14 02:20:40 13,824 ----a-w c:\windows\system32\sigtab.dll - 2004-08-04 03:45:42 130,048 ----a-w c:\windows\system32\sigverif.exe + 2008-04-14 02:21:18 71,168 ----a-w c:\windows\system32\sigverif.exe - 2004-08-04 03:45:42 26,112 ----a-w c:\windows\system32\skeys.exe + 2008-04-14 02:21:18 26,112 ----a-w c:\windows\system32\skeys.exe - 2004-08-04 03:45:28 25,600 ----a-w c:\windows\system32\slayerxp.dll + 2008-04-14 02:20:40 25,600 ----a-w c:\windows\system32\slayerxp.dll - 2004-08-04 03:45:28 98,304 ----a-w c:\windows\system32\slbiop.dll + 2008-04-14 02:20:40 98,304 ----a-w c:\windows\system32\slbiop.dll + 2008-04-14 02:20:40 73,832 ------w c:\windows\system32\slcoinst.dll + 2008-04-14 02:20:40 286,792 ------w c:\windows\system32\slextspk.dll + 2008-04-14 02:20:40 188,508 ------w c:\windows\system32\slgen.dll + 2008-04-14 02:21:18 32,866 ------w c:\windows\system32\slrundll.exe + 2008-04-14 02:21:18 73,796 ------w c:\windows\system32\slserv.exe - 2004-08-04 03:45:42 8,192 ----a-w c:\windows\system32\smbinst.exe + 2008-04-14 02:21:18 8,192 ----a-w c:\windows\system32\smbinst.exe - 2004-08-04 03:45:28 367,104 ----a-w c:\windows\system32\smlogcfg.dll + 2008-04-14 02:20:40 366,592 ----a-w c:\windows\system32\smlogcfg.dll - 2004-08-04 03:45:44 90,624 ----a-w c:\windows\system32\smlogsvc.exe + 2008-04-14 02:21:18 90,624 ----a-w c:\windows\system32\smlogsvc.exe - 2004-08-04 03:45:44 50,688 ----a-w c:\windows\system32\smss.exe + 2008-04-14 02:21:19 50,688 ----a-w c:\windows\system32\smss.exe + 2008-04-14 02:20:40 10,752 ------w c:\windows\system32\smtpapi.dll - 2004-08-04 03:45:44 147,968 ----a-w c:\windows\system32\sndrec32.exe + 2008-04-14 02:21:19 132,608 ----a-w c:\windows\system32\sndrec32.exe - 2004-08-04 03:45:28 18,944 ----a-w c:\windows\system32\snmpapi.dll + 2008-04-14 02:20:40 18,944 ----a-w c:\windows\system32\snmpapi.dll - 2004-08-04 03:45:28 183,296 ----a-w c:\windows\system32\snmpsnap.dll + 2008-04-14 02:20:40 183,296 ----a-w c:\windows\system32\snmpsnap.dll - 2001-10-28 15:07:28 24,576 ----a-w c:\windows\system32\sort.exe + 2008-04-14 02:21:19 25,600 ----a-w c:\windows\system32\sort.exe + 2008-04-14 02:21:19 7,680 ----a-w c:\windows\system32\spdwnwxp.exe - 2004-08-04 03:45:44 539,136 ----a-w c:\windows\system32\spider.exe + 2008-04-14 02:21:19 539,136 ----a-w c:\windows\system32\spider.exe - 2004-08-04 01:59:36 12,800 ----a-w c:\windows\system32\spiisupd.exe + 2008-04-13 18:43:31 12,800 ----a-w c:\windows\system32\spiisupd.exe - 2007-11-30 12:39:04 18,296 ------w c:\windows\system32\spmsg.dll + 2007-11-30 11:18:16 18,296 ------w c:\windows\system32\spmsg.dll - 2004-08-04 03:45:44 11,776 ----a-w c:\windows\system32\spnpinst.exe + 2008-04-13 21:21:20 11,264 ----a-w c:\windows\system32\spnpinst.exe - 2002-10-06 21:11:48 129,024 ----a-w c:\windows\system32\spool\drivers\w32x86\3\Ps5ui.dll + 2008-04-14 02:20:37 728,576 ----a-w c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll - 2002-10-06 21:11:48 455,168 ----a-w c:\windows\system32\spool\drivers\w32x86\3\PSCRIPT5.DLL + 2008-04-14 02:20:37 543,232 ----a-w c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll - 2004-08-04 03:45:28 74,752 ----a-w c:\windows\system32\spoolss.dll + 2008-04-14 02:20:40 75,264 ----a-w c:\windows\system32\spoolss.dll - 2005-06-10 23:53:32 57,856 ----a-w c:\windows\system32\spoolsv.exe + 2008-04-14 02:21:19 57,856 ----a-w c:\windows\system32\spoolsv.exe - 2006-10-09 00:53:36 23,856 ----a-w c:\windows\system32\spupdsvc.exe + 2007-08-10 10:12:46 26,488 ----a-w c:\windows\system32\spupdsvc.exe + 2008-04-14 02:21:19 20,992 ------w c:\windows\system32\spupdwxp.exe - 2004-08-04 03:45:28 442,368 ----a-w c:\windows\system32\sqlsrv32.dll + 2008-04-14 02:20:40 442,368 ----a-w c:\windows\system32\sqlsrv32.dll - 2004-08-04 03:45:28 180,800 ----a-w c:\windows\system32\sqlunirl.dll + 2008-04-14 02:20:40 180,800 ----a-w c:\windows\system32\sqlunirl.dll - 2004-08-04 03:45:28 67,584 ----a-w c:\windows\system32\srclient.dll + 2008-04-14 02:20:40 67,584 ----a-w c:\windows\system32\srclient.dll - 2004-08-04 03:45:28 236,544 ----a-w c:\windows\system32\srrstr.dll + 2008-04-14 02:20:40 240,640 ----a-w c:\windows\system32\srrstr.dll - 2004-08-04 03:45:28 171,008 ----a-w c:\windows\system32\srsvc.dll + 2008-04-14 02:20:40 171,520 ----a-w c:\windows\system32\srsvc.dll - 2004-12-07 19:34:12 96,768 ----a-w c:\windows\system32\srvsvc.dll + 2008-04-14 02:20:40 96,768 ----a-w c:\windows\system32\srvsvc.dll - 2004-08-04 03:45:48 708,608 ----a-w c:\windows\system32\ss3dfo.scr + 2008-04-14 02:21:26 708,608 ----a-w c:\windows\system32\ss3dfo.scr - 2004-08-04 03:45:48 19,968 ----a-w c:\windows\system32\ssbezier.scr + 2008-04-14 02:21:26 19,968 ----a-w c:\windows\system32\ssbezier.scr - 2004-08-04 03:45:28 34,816 ----a-w c:\windows\system32\ssdpapi.dll + 2008-04-14 02:20:40 34,816 ----a-w c:\windows\system32\ssdpapi.dll - 2004-08-04 03:45:28 71,680 ----a-w c:\windows\system32\ssdpsrv.dll + 2008-04-14 02:20:40 71,680 ----a-w c:\windows\system32\ssdpsrv.dll - 2004-08-04 03:45:48 393,216 ----a-w c:\windows\system32\ssflwbox.scr + 2008-04-14 02:21:26 393,216 ----a-w c:\windows\system32\ssflwbox.scr - 2004-08-04 03:45:48 20,992 ----a-w c:\windows\system32\ssmarque.scr + 2008-04-14 02:21:26 20,992 ----a-w c:\windows\system32\ssmarque.scr - 2004-08-04 03:45:48 47,104 ----a-w c:\windows\system32\ssmypics.scr + 2008-04-14 02:21:26 47,104 ----a-w c:\windows\system32\ssmypics.scr - 2004-08-04 03:45:48 18,944 ----a-w c:\windows\system32\ssmyst.scr + 2008-04-14 02:21:27 18,944 ----a-w c:\windows\system32\ssmyst.scr - 2004-08-04 03:45:48 610,304 ----a-w c:\windows\system32\sspipes.scr + 2008-04-14 02:21:27 610,304 ----a-w c:\windows\system32\sspipes.scr - 2004-08-04 03:45:48 14,336 ----a-w c:\windows\system32\ssstars.scr + 2008-04-14 02:21:27 14,336 ----a-w c:\windows\system32\ssstars.scr - 2004-08-04 03:45:48 684,032 ----a-w c:\windows\system32\sstext3d.scr + 2008-04-14 02:21:27 684,032 ----a-w c:\windows\system32\sstext3d.scr - 2001-10-28 15:07:30 54,272 ----a-w c:\windows\system32\stclient.dll + 2008-04-14 02:20:40 59,392 ----a-w c:\windows\system32\stclient.dll - 2004-08-04 03:45:28 68,096 ----a-w c:\windows\system32\sti.dll + 2008-04-14 02:20:40 68,608 ----a-w c:\windows\system32\sti.dll - 2004-08-04 03:45:28 541,696 ----a-w c:\windows\system32\sti_ci.dll + 2008-04-14 02:20:40 137,216 ----a-w c:\windows\system32\sti_ci.dll - 2004-08-04 03:45:44 14,848 ----a-w c:\windows\system32\stimon.exe + 2008-04-14 02:21:19 14,848 ----a-w c:\windows\system32\stimon.exe - 2004-08-04 03:45:28 126,464 ----a-w c:\windows\system32\stobject.dll + 2008-04-14 02:20:40 122,368 ----a-w c:\windows\system32\stobject.dll - 2004-08-04 00:45:28 75,776 ----a-w c:\windows\system32\storprop.dll + 2008-04-14 02:20:40 75,776 ----a-w c:\windows\system32\storprop.dll - 2004-08-04 03:45:28 75,776 ----a-w c:\windows\system32\strmfilt.dll + 2008-04-14 02:20:40 75,776 ----a-w c:\windows\system32\strmfilt.dll - 2004-08-04 03:45:44 14,336 ----a-w c:\windows\system32\svchost.exe + 2008-04-14 02:21:20 14,336 ----a-w c:\windows\system32\svchost.exe - 2006-10-20 01:38:48 724,480 ----a-w c:\windows\system32\sxs.dll + 2008-04-14 02:20:40 714,752 ----a-w c:\windows\system32\sxs.dll - 2004-08-04 03:45:28 57,856 ----a-w c:\windows\system32\synceng.dll + 2008-04-14 02:20:40 57,856 ----a-w c:\windows\system32\synceng.dll - 2004-08-04 03:45:28 379,392 ----a-w c:\windows\system32\syncui.dll + 2008-04-14 02:20:40 194,560 ----a-w c:\windows\system32\syncui.dll - 2004-08-04 03:45:44 417,792 ----a-w c:\windows\system32\sysocmgr.exe + 2008-04-14 02:21:20 107,008 ----a-w c:\windows\system32\sysocmgr.exe - 2004-08-04 03:45:28 994,816 ----a-w c:\windows\system32\syssetup.dll + 2008-04-14 02:20:40 1,003,008 ----a-w c:\windows\system32\syssetup.dll - 2001-10-28 15:07:30 69,632 ----a-w c:\windows\system32\systeminfo.exe + 2008-04-14 02:21:20 73,216 ----a-w c:\windows\system32\systeminfo.exe - 2005-10-17 21:21:02 118,272 ----a-w c:\windows\system32\t2embed.dll + 2008-04-14 02:20:40 117,760 ----a-w c:\windows\system32\t2embed.dll - 2004-08-04 03:45:28 859,648 ----a-w c:\windows\system32\tapi3.dll + 2008-04-14 02:20:40 859,648 ----a-w c:\windows\system32\tapi3.dll - 2004-08-04 03:45:28 181,760 ----a-w c:\windows\system32\tapi32.dll + 2008-04-14 02:20:40 181,760 ----a-w c:\windows\system32\tapi32.dll - 2005-07-08 16:29:17 249,344 ----a-w c:\windows\system32\tapisrv.dll + 2008-04-14 02:20:40 249,856 ----a-w c:\windows\system32\tapisrv.dll - 2001-10-28 15:07:30 73,728 ----a-w c:\windows\system32\taskkill.exe + 2008-04-14 02:21:20 77,824 ----a-w c:\windows\system32\taskkill.exe - 2001-10-28 15:07:30 73,216 ----a-w c:\windows\system32\tasklist.exe + 2008-04-14 02:21:20 78,848 ----a-w c:\windows\system32\tasklist.exe - 2004-08-04 03:45:44 174,080 ----a-w c:\windows\system32\taskmgr.exe + 2008-04-14 02:21:20 141,312 ----a-w c:\windows\system32\taskmgr.exe - 2004-08-04 03:45:28 14,848 ----a-w c:\windows\system32\tcpmib.dll + 2008-04-14 02:20:40 14,848 ----a-w c:\windows\system32\tcpmib.dll - 2004-08-04 03:45:28 46,080 ----a-w c:\windows\system32\tcpmon.dll + 2008-04-14 02:20:40 46,080 ----a-w c:\windows\system32\tcpmon.dll - 2004-08-04 03:45:28 203,776 ----a-w c:\windows\system32\tcpmonui.dll + 2008-04-14 02:20:40 46,592 ----a-w c:\windows\system32\tcpmonui.dll - 2005-05-11 02:30:02 91,136 ----a-w c:\windows\system32\telnet.exe + 2008-04-14 02:21:20 77,312 ----a-w c:\windows\system32\telnet.exe - 2004-08-04 03:45:28 358,912 ----a-w c:\windows\system32\termmgr.dll + 2008-04-14 02:20:40 358,912 ----a-w c:\windows\system32\termmgr.dll - 2004-08-04 03:45:28 296,960 ----a-w c:\windows\system32\termsrv.dll + 2008-04-14 02:20:40 296,960 ----a-w c:\windows\system32\termsrv.dll - 2004-08-04 03:45:28 449,536 ----a-w c:\windows\system32\themeui.dll + 2008-04-14 02:20:40 388,608 ----a-w c:\windows\system32\themeui.dll - 2004-08-04 03:45:44 62,976 ----a-w c:\windows\system32\tlntadmn.exe + 2008-04-14 02:21:20 62,976 ----a-w c:\windows\system32\tlntadmn.exe - 2004-08-04 03:45:44 78,848 ----a-w c:\windows\system32\tlntsess.exe + 2008-04-14 02:21:20 78,848 ----a-w c:\windows\system32\tlntsess.exe - 2004-08-04 03:45:44 73,728 ----a-w c:\windows\system32\tlntsvr.exe + 2008-04-14 02:21:21 73,728 ----a-w c:\windows\system32\tlntsvr.exe - 2004-08-04 03:45:28 7,168 ----a-w c:\windows\system32\tlntsvrp.dll + 2008-04-14 02:20:40 7,168 ----a-w c:\windows\system32\tlntsvrp.dll - 2004-08-04 03:45:44 347,136 ----a-w c:\windows\system32\tourstart.exe + 2008-04-14 02:21:21 347,136 ----a-w c:\windows\system32\tourstart.exe - 2004-08-04 03:45:44 260,096 ----a-w c:\windows\system32\tracerpt.exe + 2008-04-14 02:21:21 260,096 ----a-w c:\windows\system32\tracerpt.exe - 2004-08-04 03:45:44 12,800 ----a-w c:\windows\system32\tracert.exe + 2008-04-14 02:21:21 12,800 ----a-w c:\windows\system32\tracert.exe - 2001-10-28 15:07:32 11,264 ----a-w c:\windows\system32\tree.com + 2008-04-14 02:21:25 12,800 ----a-w c:\windows\system32\tree.com - 2004-08-04 03:45:28 90,624 ----a-w c:\windows\system32\trkwks.dll + 2008-04-14 02:20:40 90,112 ----a-w c:\windows\system32\trkwks.dll - 2004-08-04 03:45:28 93,696 ----a-w c:\windows\system32\tscfgwmi.dll + 2008-04-14 02:20:40 93,696 ----a-w c:\windows\system32\tscfgwmi.dll - 2004-08-04 03:45:56 12,168 ----a-w c:\windows\system32\tsddd.dll + 2008-04-14 02:21:50 12,168 ----a-w c:\windows\system32\tsddd.dll + 2008-04-14 02:20:40 53,248 ------w c:\windows\system32\tsgqec.dll + 2008-04-14 02:20:40 50,688 ------w c:\windows\system32\tspkg.dll - 2004-08-04 03:45:28 44,032 ----a-w c:\windows\system32\twext.dll + 2008-04-14 02:20:40 57,856 ----a-w c:\windows\system32\twext.dll - 2005-07-26 04:40:33 101,376 ----a-w c:\windows\system32\txflog.dll + 2008-04-14 02:20:40 101,376 ----a-w c:\windows\system32\txflog.dll - 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe + 2008-04-14 02:21:21 60,416 ------w c:\windows\system32\tzchange.exe - 2004-08-04 03:45:28 25,600 ----a-w c:\windows\system32\udhisapi.dll + 2008-04-14 02:20:40 26,624 ----a-w c:\windows\system32\udhisapi.dll - 2004-08-04 03:45:28 303,616 ----a-w c:\windows\system32\ulib.dll + 2008-04-14 02:20:40 303,616 ----a-w c:\windows\system32\ulib.dll - 2004-08-04 03:45:28 36,864 ----a-w c:\windows\system32\umandlg.dll + 2008-04-14 02:20:40 36,864 ----a-w c:\windows\system32\umandlg.dll - 2005-08-23 03:39:53 124,416 ----a-w c:\windows\system32\umpnpmgr.dll + 2008-04-14 02:20:40 124,416 ----a-w c:\windows\system32\umpnpmgr.dll - 2004-08-04 03:45:28 77,824 ----a-w c:\windows\system32\unimdmat.dll + 2008-04-14 02:20:40 77,824 ----a-w c:\windows\system32\unimdmat.dll - 2004-08-04 03:45:28 13,824 ----a-w c:\windows\system32\uniplat.dll + 2008-04-14 02:20:40 13,824 ----a-w c:\windows\system32\uniplat.dll - 2004-08-04 03:45:28 316,416 ----a-w c:\windows\system32\untfs.dll + 2008-04-14 02:20:40 316,416 ----a-w c:\windows\system32\untfs.dll - 2004-08-04 03:45:28 132,608 ----a-w c:\windows\system32\upnp.dll + 2008-04-14 02:20:40 133,632 ----a-w c:\windows\system32\upnp.dll - 2004-08-04 03:45:46 16,896 ----a-w c:\windows\system32\upnpcont.exe + 2008-04-14 02:21:21 16,896 ----a-w c:\windows\system32\upnpcont.exe - 2007-02-05 20:18:57 185,344 ----a-w c:\windows\system32\upnphost.dll + 2008-04-14 02:20:40 186,368 ----a-w c:\windows\system32\upnphost.dll - 2004-08-04 03:45:28 239,616 ----a-w c:\windows\system32\upnpui.dll + 2008-04-14 02:20:40 239,616 ----a-w c:\windows\system32\upnpui.dll - 2004-08-04 03:45:46 18,432 ----a-w c:\windows\system32\ups.exe + 2008-04-14 02:21:21 18,432 ----a-w c:\windows\system32\ups.exe - 2004-08-04 03:45:28 37,888 ----a-w c:\windows\system32\url.dll + 2008-04-14 02:20:40 37,888 ----a-w c:\windows\system32\url.dll - 2008-10-16 10:39:09 616,960 ----a-w c:\windows\system32\urlmon.dll + 2008-10-16 01:02:11 619,520 ----a-w c:\windows\system32\urlmon.dll - 2004-08-04 03:45:28 16,896 ----a-w c:\windows\system32\usbmon.dll + 2008-04-14 02:20:40 16,896 ----a-w c:\windows\system32\usbmon.dll - 2004-08-04 00:45:28 76,288 ----a-w c:\windows\system32\usbui.dll + 2008-04-14 02:20:40 76,288 ----a-w c:\windows\system32\usbui.dll - 2007-03-08 15:36:54 578,048 ----a-w c:\windows\system32\user32.dll + 2008-04-14 02:20:40 579,072 ----a-w c:\windows\system32\user32.dll - 2004-08-04 03:45:28 728,576 ----a-w c:\windows\system32\userenv.dll + 2008-04-14 02:20:40 732,160 ----a-w c:\windows\system32\userenv.dll - 2004-08-04 03:45:46 24,576 ----a-w c:\windows\system32\userinit.exe + 2008-04-14 02:21:21 26,112 ----a-w c:\windows\system32\userinit.exe + 2008-04-13 16:44:16 17,920 ------w c:\windows\system32\usmt\cobramsg.dll - 2004-08-04 03:45:24 124,928 ----a-w c:\windows\system32\usmt\guitrn.dll + 2008-04-14 02:20:27 134,144 ----a-w c:\windows\system32\usmt\guitrn.dll + 2008-04-14 02:20:27 115,200 ------w c:\windows\system32\usmt\guitrna.dll - 2004-08-04 03:45:24 4,096 ----a-w c:\windows\system32\usmt\iconlib.dll + 2008-04-13 16:44:29 2,560 ----a-w c:\windows\system32\usmt\iconlib.dll - 2004-08-04 03:45:24 19,968 ----a-w c:\windows\system32\usmt\log.dll + 2008-04-14 02:20:30 19,968 ----a-w c:\windows\system32\usmt\log.dll - 2004-08-04 03:45:24 201,216 ----a-w c:\windows\system32\usmt\migism.dll + 2008-04-14 02:20:31 274,432 ----a-w c:\windows\system32\usmt\migism.dll + 2008-04-14 02:20:31 261,120 ------w c:\windows\system32\usmt\migisma.dll - 2004-08-04 03:45:36 103,936 ----a-w c:\windows\system32\usmt\migload.exe + 2008-04-14 02:21:05 104,448 ----a-w c:\windows\system32\usmt\migload.exe - 2004-08-04 03:45:38 701,440 ----a-w c:\windows\system32\usmt\migwiz.exe + 2008-04-14 02:21:06 250,368 ----a-w c:\windows\system32\usmt\migwiz.exe + 2008-04-14 02:21:06 241,152 ------w c:\windows\system32\usmt\migwiza.exe - 2004-08-04 03:45:28 203,776 ----a-w c:\windows\system32\usmt\script.dll + 2008-04-14 02:20:40 216,576 ----a-w c:\windows\system32\usmt\script.dll + 2008-04-14 02:20:40 199,680 ------w c:\windows\system32\usmt\scripta.dll - 2004-08-04 03:45:28 169,472 ----a-w c:\windows\system32\usmt\sysmod.dll + 2008-04-14 02:20:40 193,536 ----a-w c:\windows\system32\usmt\sysmod.dll + 2008-04-14 02:20:40 173,568 ------w c:\windows\system32\usmt\sysmoda.dll - 2004-08-04 03:45:28 406,528 ----a-w c:\windows\system32\usp10.dll + 2008-04-14 02:20:40 406,016 ----a-w c:\windows\system32\usp10.dll - 2004-08-04 03:45:46 50,176 ----a-w c:\windows\system32\utilman.exe + 2008-04-14 02:21:22 50,176 ----a-w c:\windows\system32\utilman.exe - 2008-10-13 03:25:36 219,648 ----a-w c:\windows\system32\uxtheme.dll + 2008-04-14 02:20:40 219,648 ----a-w c:\windows\system32\uxtheme.dll - 1998-06-18 03:00:00 89,360 ----a-w c:\windows\system32\VB5DB.DLL + 1998-06-18 02:00:00 89,360 ----a-w c:\windows\system32\VB5DB.DLL - 2004-08-04 03:45:28 30,749 ----a-w c:\windows\system32\vbajet32.dll + 2008-04-14 02:20:40 30,749 ----a-w c:\windows\system32\vbajet32.dll - 2007-12-18 14:42:09 417,792 ----a-w c:\windows\system32\vbscript.dll + 2008-05-09 10:55:06 430,080 ----a-w c:\windows\system32\vbscript.dll - 2004-08-04 03:45:28 26,112 ----a-w c:\windows\system32\vdmdbg.dll + 2008-04-14 02:20:40 26,112 ----a-w c:\windows\system32\vdmdbg.dll - 2004-08-04 03:45:28 51,712 ----a-w c:\windows\system32\vdmredir.dll + 2008-04-14 02:20:40 51,712 ----a-w c:\windows\system32\vdmredir.dll - 2006-03-17 00:38:01 28,672 ------w c:\windows\system32\verclsid.exe + 2008-04-14 02:21:22 28,672 ------w c:\windows\system32\verclsid.exe - 2001-10-28 15:07:34 13,312 ----a-w c:\windows\system32\verifier.dll + 2008-04-14 02:20:40 26,624 ----a-w c:\windows\system32\verifier.dll - 2004-08-04 03:45:28 18,944 ----a-w c:\windows\system32\version.dll + 2008-04-14 02:20:40 18,944 ----a-w c:\windows\system32\version.dll - 2004-08-04 03:45:28 430,592 ----a-w c:\windows\system32\vssapi.dll + 2008-04-14 02:20:41 430,592 ----a-w c:\windows\system32\vssapi.dll - 2004-08-04 03:45:46 292,864 ----a-w c:\windows\system32\vssvc.exe + 2008-04-14 02:21:22 292,864 ----a-w c:\windows\system32\vssvc.exe - 2004-08-04 03:45:28 175,616 ----a-w c:\windows\system32\w32time.dll + 2008-04-14 02:20:41 176,128 ----a-w c:\windows\system32\w32time.dll - 2004-08-04 03:45:28 15,872 ----a-w c:\windows\system32\w3ssl.dll + 2008-04-14 02:20:41 15,872 ----a-w c:\windows\system32\w3ssl.dll - 2004-08-04 02:07:34 17,664 ----a-w c:\windows\system32\watchdog.sys + 2008-04-13 18:44:59 17,664 ----a-w c:\windows\system32\watchdog.sys - 2001-10-28 15:07:36 208,896 ----a-w c:\windows\system32\wavemsp.dll + 2008-04-14 02:20:41 215,552 ----a-w c:\windows\system32\wavemsp.dll - 2004-08-04 03:45:22 1,352,704 ----a-w c:\windows\system32\wbem\cimwin32.dll + 2008-04-14 02:20:24 1,359,360 ----a-w c:\windows\system32\wbem\cimwin32.dll - 2004-08-04 03:45:22 45,568 ----a-w c:\windows\system32\wbem\CmdEvTgProv.dll + 2008-04-14 02:20:26 45,056 ----a-w c:\windows\system32\wbem\cmdevtgprov.dll - 2004-08-04 03:45:22 247,808 ----a-w c:\windows\system32\wbem\esscli.dll + 2008-04-14 02:20:26 247,808 ----a-w c:\windows\system32\wbem\esscli.dll - 2004-08-04 03:45:22 22,016 ----a-w c:\windows\system32\wbem\evntrprv.dll + 2008-04-14 02:20:26 21,504 ----a-w c:\windows\system32\wbem\evntrprv.dll - 2004-08-04 03:45:22 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll + 2008-04-14 02:20:26 472,064 ----a-w c:\windows\system32\wbem\fastprox.dll - 2004-08-04 03:45:22 185,856 ----a-w c:\windows\system32\wbem\framedyn.dll + 2008-04-14 02:20:26 185,344 ----a-w c:\windows\system32\wbem\framedyn.dll - 2004-08-04 03:45:24 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll + 2008-04-14 02:20:30 24,576 ----a-w c:\windows\system32\wbem\krnlprov.dll - 2004-08-04 03:45:38 16,384 ----a-w c:\windows\system32\wbem\mofcomp.exe + 2008-04-14 02:21:07 16,384 ----a-w c:\windows\system32\wbem\mofcomp.exe - 2004-08-04 03:45:24 124,416 ----a-w c:\windows\system32\wbem\mofd.dll + 2008-04-14 02:20:32 124,416 ----a-w c:\windows\system32\wbem\mofd.dll - 2004-08-04 03:45:26 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll + 2008-04-14 02:20:34 47,104 ----a-w c:\windows\system32\wbem\ncprov.dll - 2004-08-04 03:45:26 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll + 2008-04-14 02:20:37 212,992 ----a-w c:\windows\system32\wbem\ntevt.dll - 2004-08-04 03:45:26 92,672 ----a-w c:\windows\system32\wbem\policman.dll + 2008-04-14 02:20:37 92,672 ----a-w c:\windows\system32\wbem\policman.dll - 2004-08-04 03:45:26 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll + 2008-04-14 02:20:37 237,056 ----a-w c:\windows\system32\wbem\provthrd.dll - 2004-08-04 03:45:26 177,152 ----a-w c:\windows\system32\wbem\repdrvfs.dll + 2008-04-14 02:20:39 178,176 ----a-w c:\windows\system32\wbem\repdrvfs.dll - 2004-08-04 03:45:42 36,864 ----a-w c:\windows\system32\wbem\scrcons.exe + 2008-04-14 02:21:17 36,352 ----a-w c:\windows\system32\wbem\scrcons.exe - 2004-08-04 03:45:28 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll + 2008-04-14 02:20:40 86,528 ----a-w c:\windows\system32\wbem\stdprov.dll - 2004-08-04 03:45:28 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll + 2008-04-14 02:20:40 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll - 2004-08-04 03:45:28 199,168 ----a-w c:\windows\system32\wbem\wbemcntl.dll + 2008-04-14 02:20:41 199,168 ----a-w c:\windows\system32\wbem\wbemcntl.dll - 2004-08-04 03:45:28 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll + 2008-04-14 02:20:41 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll - 2004-08-04 03:45:28 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll + 2008-04-14 02:20:41 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll - 2004-08-04 03:45:28 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll + 2008-04-14 02:20:41 531,968 ----a-w c:\windows\system32\wbem\wbemcore.dll - 2004-08-04 03:45:28 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll + 2008-04-14 02:20:41 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll - 2004-08-04 03:45:28 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll + 2008-04-14 02:20:41 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll - 2004-08-04 03:45:28 43,520 ----a-w c:\windows\system32\wbem\wbemperf.dll + 2008-04-14 02:20:41 43,520 ----a-w c:\windows\system32\wbem\wbemperf.dll - 2004-08-04 03:45:28 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll + 2008-04-14 02:20:41 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll - 2004-08-04 03:45:28 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll + 2008-04-14 02:20:41 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll - 2004-08-04 03:45:46 118,784 ----a-w c:\windows\system32\wbem\wbemtest.exe + 2008-04-14 02:21:22 118,784 ----a-w c:\windows\system32\wbem\wbemtest.exe - 2004-08-04 03:45:28 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll + 2008-04-14 02:20:41 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll - 2004-08-04 03:45:46 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe + 2008-04-14 02:21:23 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe - 2004-08-04 03:45:14 7,168 ----a-w c:\windows\system32\wbem\wmiapres.dll + 2008-04-14 01:55:31 7,168 ----a-w c:\windows\system32\wbem\wmiapres.dll - 2004-08-04 03:45:28 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll + 2008-04-14 02:20:43 88,576 ----a-w c:\windows\system32\wbem\wmiaprpl.dll - 2004-08-04 03:45:46 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe + 2008-04-14 02:21:24 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe - 2004-08-04 03:45:46 365,056 ----a-w c:\windows\system32\wbem\wmic.exe + 2008-04-14 02:21:24 365,056 ----a-w c:\windows\system32\wbem\wmic.exe - 2004-08-04 03:45:28 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll + 2008-04-14 02:20:43 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll - 2004-08-04 03:45:28 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll + 2008-04-14 02:20:43 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll - 2004-08-04 03:45:28 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll + 2008-04-14 02:20:43 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll - 2004-08-04 03:45:28 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll + 2008-04-14 02:20:43 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll - 2004-08-04 03:45:28 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll + 2008-04-14 02:20:43 61,952 ----a-w c:\windows\system32\wbem\wmipiprt.dll - 2004-08-04 03:45:28 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll + 2008-04-14 02:20:43 62,464 ----a-w c:\windows\system32\wbem\wmipjobj.dll - 2004-08-04 03:45:28 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll + 2008-04-14 02:20:43 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll - 2004-08-04 03:45:28 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll + 2008-04-14 02:20:43 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll - 2004-08-04 03:45:46 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe + 2008-04-14 02:21:24 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe - 2004-08-04 03:45:28 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll + 2008-04-14 02:20:43 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll - 2004-08-04 03:45:28 145,408 ----a-w c:\windows\system32\wbem\wmisvc.dll + 2008-04-14 02:20:43 145,408 ----a-w c:\windows\system32\wbem\wmisvc.dll - 2004-08-04 03:45:28 97,792 ----a-w c:\windows\system32\wbem\wmiutils.dll + 2008-04-14 02:20:43 97,792 ----a-w c:\windows\system32\wbem\wmiutils.dll - 2004-08-04 03:45:28 49,152 ----a-w c:\windows\system32\wdigest.dll + 2008-04-14 02:20:41 49,152 ----a-w c:\windows\system32\wdigest.dll - 2004-08-04 02:45:48 23,552 ----a-w c:\windows\system32\wdmaud.drv + 2008-04-14 02:21:27 23,552 ----a-w c:\windows\system32\wdmaud.drv - 2004-08-04 03:45:28 442,368 ----a-w c:\windows\system32\webcheck.dll + 2008-04-14 02:20:41 278,528 ----a-w c:\windows\system32\webcheck.dll - 2006-01-04 03:35:30 68,096 ----a-w c:\windows\system32\webclnt.dll + 2008-04-14 02:20:41 68,096 ----a-w c:\windows\system32\webclnt.dll - 2004-08-04 03:45:28 136,192 ----a-w c:\windows\system32\webvw.dll + 2008-04-14 02:20:41 136,192 ----a-w c:\windows\system32\webvw.dll - 2004-08-04 03:45:46 66,048 ----a-w c:\windows\system32\wextract.exe + 2008-04-14 02:21:22 66,048 ----a-w c:\windows\system32\wextract.exe - 2004-08-04 03:45:46 1,366,528 ----a-w c:\windows\system32\wiaacmgr.exe + 2008-04-14 02:21:23 434,688 ----a-w c:\windows\system32\wiaacmgr.exe - 2004-08-04 03:45:28 497,664 ----a-w c:\windows\system32\wiadefui.dll + 2008-04-14 02:20:41 464,384 ----a-w c:\windows\system32\wiadefui.dll - 2004-08-04 03:45:28 124,928 ----a-w c:\windows\system32\wiadss.dll + 2008-04-14 02:20:42 124,928 ----a-w c:\windows\system32\wiadss.dll - 2004-08-04 03:45:28 75,776 ----a-w c:\windows\system32\wiascr.dll + 2008-04-14 02:20:42 75,776 ----a-w c:\windows\system32\wiascr.dll - 2006-12-19 18:18:06 334,336 ----a-w c:\windows\system32\wiaservc.dll + 2008-04-14 02:20:42 334,336 ----a-w c:\windows\system32\wiaservc.dll - 2004-08-04 03:45:28 704,000 ----a-w c:\windows\system32\wiashext.dll + 2008-04-14 02:20:42 591,872 ----a-w c:\windows\system32\wiashext.dll - 2004-08-04 03:45:28 111,104 ----a-w c:\windows\system32\wiavideo.dll + 2008-04-14 02:20:42 111,104 ----a-w c:\windows\system32\wiavideo.dll - 2008-09-15 15:40:06 1,846,144 ----a-w c:\windows\system32\win32k.sys + 2008-09-15 15:26:10 1,846,528 ----a-w c:\windows\system32\win32k.sys - 2004-08-04 03:45:28 102,400 ----a-w c:\windows\system32\win32spl.dll + 2008-04-14 02:20:42 102,912 ----a-w c:\windows\system32\win32spl.dll - 2004-08-04 03:45:10 983,040 ----a-w c:\windows\system32\winbrand.dll + 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll + 2008-04-14 02:20:42 712,704 ------w c:\windows\system32\windowscodecs.dll + 2008-04-14 02:20:42 346,112 ------w c:\windows\system32\windowscodecsext.dll - 2004-08-04 03:45:28 351,232 ----a-w c:\windows\system32\winhttp.dll + 2008-04-14 02:20:42 354,304 ----a-w c:\windows\system32\winhttp.dll - 2008-10-16 10:39:08 661,504 ----a-w c:\windows\system32\wininet.dll + 2008-10-16 01:02:11 668,160 ----a-w c:\windows\system32\wininet.dll - 2004-08-04 03:45:28 32,768 ----a-w c:\windows\system32\winipsec.dll + 2008-04-14 02:20:42 32,256 ----a-w c:\windows\system32\winipsec.dll - 2004-08-04 03:45:46 504,320 ----a-w c:\windows\system32\winlogon.exe + 2008-04-14 02:21:23 509,952 ----a-w c:\windows\system32\winlogon.exe - 2004-08-04 03:45:28 179,200 ----a-w c:\windows\system32\winmm.dll + 2008-04-14 02:20:42 179,200 ----a-w c:\windows\system32\winmm.dll - 2004-08-04 03:45:12 773,120 ----a-w c:\windows\system32\winntbbu.dll + 2008-04-14 02:19:54 763,392 ----a-w c:\windows\system32\winntbbu.dll - 2004-08-04 03:45:28 16,896 ----a-w c:\windows\system32\winrnr.dll + 2008-04-14 02:20:42 16,896 ----a-w c:\windows\system32\winrnr.dll - 2004-08-04 03:45:28 99,840 ----a-w c:\windows\system32\winscard.dll + 2008-04-14 02:20:42 99,840 ----a-w c:\windows\system32\winscard.dll - 2004-08-04 03:45:28 17,408 ----a-w c:\windows\system32\winshfhc.dll + 2008-04-14 02:20:42 17,408 ----a-w c:\windows\system32\winshfhc.dll - 2004-08-04 03:45:48 146,944 ----a-w c:\windows\system32\winspool.drv + 2008-04-14 02:21:27 146,944 ----a-w c:\windows\system32\winspool.drv - 2007-03-17 13:44:49 293,376 ----a-w c:\windows\system32\winsrv.dll + 2008-04-14 02:20:42 293,888 ----a-w c:\windows\system32\winsrv.dll - 2004-08-04 03:45:28 53,760 ----a-w c:\windows\system32\winsta.dll + 2008-04-14 02:20:42 53,760 ----a-w c:\windows\system32\winsta.dll - 2004-08-04 03:45:28 176,640 ----a-w c:\windows\system32\wintrust.dll + 2008-04-14 02:20:42 176,640 ----a-w c:\windows\system32\wintrust.dll - 2004-08-04 03:45:46 5,632 ----a-w c:\windows\system32\winver.exe + 2008-04-14 02:21:23 5,632 ----a-w c:\windows\system32\winver.exe - 2006-08-17 12:28:32 132,096 ----a-w c:\windows\system32\wkssvc.dll + 2008-04-14 02:20:42 132,096 ----a-w c:\windows\system32\wkssvc.dll + 2008-04-14 02:20:42 69,120 ------w c:\windows\system32\wlanapi.dll - 2004-08-04 03:45:28 173,056 ----a-w c:\windows\system32\wldap32.dll + 2008-04-14 02:20:42 172,544 ----a-w c:\windows\system32\wldap32.dll - 2004-08-04 03:45:28 93,184 ----a-w c:\windows\system32\wlnotify.dll + 2008-04-14 02:20:43 93,184 ----a-w c:\windows\system32\wlnotify.dll - 2004-08-04 03:45:14 5,632 ----a-w c:\windows\system32\wmi.dll + 2008-04-14 02:19:55 5,632 ----a-w c:\windows\system32\wmi.dll - 2004-08-04 03:45:28 20,480 ----a-w c:\windows\system32\wmpcd.dll + 2008-04-14 02:20:43 20,480 ----a-w c:\windows\system32\wmpcd.dll - 2004-08-04 03:45:28 20,480 ----a-w c:\windows\system32\wmpcore.dll + 2008-04-14 02:20:43 20,480 ----a-w c:\windows\system32\wmpcore.dll + 2008-04-14 02:20:43 276,992 ------w c:\windows\system32\wmphoto.dll - 2004-08-04 03:45:28 20,480 ----a-w c:\windows\system32\wmpui.dll + 2008-04-14 02:20:43 20,480 ----a-w c:\windows\system32\wmpui.dll - 2004-08-04 03:45:28 115,200 ----a-w c:\windows\system32\wmsdmoe.dll + 2008-04-14 02:20:43 115,200 ----a-w c:\windows\system32\wmsdmoe.dll - 2004-08-04 03:45:28 303,616 ----a-w c:\windows\system32\wmstream.dll + 2008-04-14 02:20:43 303,616 ----a-w c:\windows\system32\wmstream.dll - 2004-08-04 03:45:30 264,704 ----a-w c:\windows\system32\wow32.dll + 2008-04-14 02:20:44 264,704 ----a-w c:\windows\system32\wow32.dll - 2004-08-04 03:45:46 32,256 ----a-w c:\windows\system32\wpabaln.exe + 2008-04-14 02:21:24 32,256 ----a-w c:\windows\system32\wpabaln.exe - 2004-08-04 03:45:46 32,768 ----a-w c:\windows\system32\wpnpinst.exe + 2008-04-14 02:21:24 11,776 ----a-w c:\windows\system32\wpnpinst.exe - 2004-08-04 03:45:30 82,944 ----a-w c:\windows\system32\ws2_32.dll + 2008-04-14 02:20:44 82,432 ----a-w c:\windows\system32\ws2_32.dll - 2004-08-04 03:45:30 19,968 ----a-w c:\windows\system32\ws2help.dll + 2008-04-14 02:20:44 19,968 ----a-w c:\windows\system32\ws2help.dll - 2004-08-04 03:45:46 13,824 ----a-w c:\windows\system32\wscntfy.exe + 2008-04-14 02:21:24 13,824 ----a-w c:\windows\system32\wscntfy.exe - 2004-08-04 03:45:46 405,504 ----a-w c:\windows\system32\wscript.exe + 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe - 2004-08-04 03:45:30 81,408 ----a-w c:\windows\system32\wscsvc.dll + 2008-04-14 02:20:44 80,896 ----a-w c:\windows\system32\wscsvc.dll - 2004-08-04 03:45:30 643,584 ----a-w c:\windows\system32\wsecedit.dll + 2008-04-14 02:20:44 614,912 ----a-w c:\windows\system32\wsecedit.dll - 2004-08-04 03:45:30 108,032 ----a-w c:\windows\system32\wshbth.dll + 2008-04-14 02:20:44 108,032 ----a-w c:\windows\system32\wshbth.dll - 2004-08-04 03:45:30 28,672 ----a-w c:\windows\system32\wshcon.dll + 2008-04-14 02:20:44 36,864 ----a-w c:\windows\system32\wshcon.dll - 2004-08-04 03:45:30 65,536 ----a-w c:\windows\system32\wshext.dll + 2008-05-09 10:55:06 90,112 ----a-w c:\windows\system32\wshext.dll - 2004-08-04 03:45:30 14,336 ----a-w c:\windows\system32\wship6.dll + 2008-04-14 02:20:44 14,336 ----a-w c:\windows\system32\wship6.dll - 2004-08-04 03:45:30 11,776 ----a-w c:\windows\system32\WshRm.dll + 2008-04-14 02:20:44 11,264 ----a-w c:\windows\system32\wshrm.dll - 2004-08-04 03:45:30 19,968 ----a-w c:\windows\system32\wshtcpip.dll + 2008-04-14 02:20:44 19,456 ----a-w c:\windows\system32\wshtcpip.dll - 2004-08-04 03:45:30 42,496 ----a-w c:\windows\system32\wsnmp32.dll + 2008-04-14 02:20:44 41,984 ----a-w c:\windows\system32\wsnmp32.dll - 2004-08-04 03:45:30 25,088 ----a-w c:\windows\system32\wsock32.dll + 2008-04-14 02:20:44 25,088 ----a-w c:\windows\system32\wsock32.dll - 2004-08-04 03:45:30 51,200 ----a-w c:\windows\system32\wstdecod.dll + 2008-04-14 02:20:44 51,200 ----a-w c:\windows\system32\wstdecod.dll - 2004-08-04 03:45:30 18,432 ----a-w c:\windows\system32\wtsapi32.dll + 2008-04-14 02:20:44 18,432 ----a-w c:\windows\system32\wtsapi32.dll - 2004-08-04 03:45:46 167,936 ----a-w c:\windows\system32\wuauclt1.exe + 2008-04-14 02:21:25 167,936 ----a-w c:\windows\system32\wuauclt1.exe - 2004-08-04 03:45:30 183,808 ----a-w c:\windows\system32\wuaueng1.dll + 2008-04-14 02:20:45 183,808 ----a-w c:\windows\system32\wuaueng1.dll - 2004-08-04 03:45:30 6,656 ----a-w c:\windows\system32\wuauserv.dll + 2008-04-14 02:20:45 6,656 ----a-w c:\windows\system32\wuauserv.dll - 2004-08-04 03:45:30 378,368 ----a-w c:\windows\system32\wzcdlg.dll + 2008-04-14 02:20:46 383,488 ----a-w c:\windows\system32\wzcdlg.dll - 2004-08-04 03:55:42 51,712 ----a-w c:\windows\system32\wzcsapi.dll + 2008-04-14 02:20:46 52,736 ----a-w c:\windows\system32\wzcsapi.dll - 2004-08-04 03:55:42 359,936 ----a-w c:\windows\system32\wzcsvc.dll + 2008-04-14 02:20:46 483,840 ----a-w c:\windows\system32\wzcsvc.dll - 2004-08-04 03:45:30 91,648 ----a-w c:\windows\system32\xactsrv.dll + 2008-04-14 02:20:46 91,648 ----a-w c:\windows\system32\xactsrv.dll - 2004-08-04 03:45:46 30,720 ----a-w c:\windows\system32\xcopy.exe + 2008-04-14 02:21:25 30,720 ----a-w c:\windows\system32\xcopy.exe + 2008-04-14 02:20:46 121,856 ------w c:\windows\system32\xmllite.dll - 2004-08-04 03:45:30 129,536 ----a-w c:\windows\system32\xmlprov.dll + 2008-04-14 02:20:46 129,024 ----a-w c:\windows\system32\xmlprov.dll - 2004-08-04 03:45:30 50,176 ----a-w c:\windows\system32\xmlprovi.dll + 2008-04-14 02:20:46 50,176 ----a-w c:\windows\system32\xmlprovi.dll - 2006-03-01 19:44:01 11,776 ----a-w c:\windows\system32\xolehlp.dll + 2008-04-14 02:20:46 11,776 ----a-w c:\windows\system32\xolehlp.dll - 2004-08-04 03:44:44 444,928 ----a-w c:\windows\system32\xpob2res.dll + 2008-04-13 18:40:07 444,928 ----a-w c:\windows\system32\xpob2res.dll - 2004-08-04 03:44:54 192,512 ----a-w c:\windows\system32\xpsp1res.dll + 2008-04-13 18:35:08 192,512 ----a-w c:\windows\system32\xpsp1res.dll - 2004-08-04 03:45:02 3,786,752 ----a-w c:\windows\system32\xpsp2res.dll + 2008-04-13 18:35:38 2,945,536 ----a-w c:\windows\system32\xpsp2res.dll - 2008-10-15 22:05:16 360,448 ----a-w c:\windows\system32\xpsp3res.dll + 2008-04-13 18:38:54 736,256 ----a-w c:\windows\system32\xpsp3res.dll - 2004-08-04 03:45:30 940,032 ----a-w c:\windows\system32\zipfldr.dll + 2008-04-14 02:20:46 339,456 ----a-w c:\windows\system32\zipfldr.dll + 2009-02-05 12:47:46 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_63c.dat + 2009-02-05 12:47:53 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_7d0.dat + 2009-02-05 12:48:03 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_8d4.dat - 2004-08-04 03:45:28 50,688 ----a-w c:\windows\twain_32.dll + 2008-04-14 02:20:40 50,688 ----a-w c:\windows\twain_32.dll - 2006-08-16 01:41:39 21,078 ----a-r c:\windows\twain_32\Samsung\SCX4200\OEMUIbp.dat + 2009-01-22 16:59:06 21,081 ----a-w c:\windows\twain_32\Samsung\SCX4200\OEMUIbp.dat - 2004-08-04 03:45:46 287,744 ----a-w c:\windows\winhlp32.exe + 2008-04-14 02:21:23 287,744 ----a-w c:\windows\winhlp32.exe - 2007-01-19 12:51:03 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll + 2008-04-14 02:17:55 74,802 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll - 2007-01-19 12:51:04 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll + 2008-04-14 02:17:56 995,383 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll - 2007-01-19 12:51:04 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll + 2008-04-14 02:17:56 1,011,774 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll - 2007-01-19 12:51:04 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll + 2008-04-14 02:17:56 401,462 ----a-w c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll + 2008-04-14 02:17:56 1,054,208 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll + 2008-04-14 02:17:56 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcirt.dll + 2008-04-14 02:17:56 343,040 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll + 2008-04-14 02:17:55 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll - 2004-08-04 03:44:04 852,992 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll + 2008-04-14 02:17:55 852,992 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\dxmrtp.dll - 2004-08-04 03:44:04 992,768 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll + 2008-04-14 02:17:55 992,768 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\rtcdll.dll - 2004-08-04 03:44:04 135,680 ----a-r c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_pt-BR_467e4fd0\rtcres.dll + 2008-04-14 02:00:20 135,680 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_pt-BR_467e4fd0\rtcres.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312] "DownloadAccelerator"="c:\arquivos de programas\DAP\DAP.EXE" [2008-12-26 3134976] "ares"="c:\arquivos de programas\Ares\Ares.exe" [2008-12-25 893440] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000] "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-08-16 503808] "zBrowser Launcher"="c:\arquivos de programas\Logitech\iTouch\iTouch.exe" [2004-03-18 892928] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2009-02-05 185872] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00 [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^InterVideo WinCinema Manager.lnk] backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] --a------ 2008-12-25 22:40 893440 c:\arquivos de programas\Ares\Ares.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] --a------ 2008-04-14 00:20 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] --a------ 2008-12-26 01:03 3134976 c:\arquivos de programas\DAP\DAP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2008-12-02 22:30 3882312 c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-08-11 11:43 7630848 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-08-11 11:43 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr] --a------ 2006-08-16 01:10 503808 c:\windows\Samsung\PanelMgr\SSMMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] --------- 2008-07-07 09:42 2156368 c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2009-02-05 02:00 185872 c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher] --a------ 2004-03-18 09:33 892928 c:\arquivos de programas\Logitech\iTouch\iTouch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-08-11 11:43 1519616 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] -r------- 2006-06-20 19:42 577536 c:\windows\soundman.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "d:\\Karin Noga\\Jogos\\Jogos\\Battlefield 1942\\BF1942.exe"= "c:\\Arquivos de programas\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Arquivos de programas\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Arquivos de programas\\TmNationsForever\\TmForever.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "c:\\Arquivos de programas\\Arquivos comuns\\Microsoft Shared\\DW\\DW20.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\arquivos de programas\\relevantknowledge\\rlvknlg.exe"= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2609aed4-d15f-11dd-9ccd-0017315b5fb6}] \Shell\AutoRun\command - G:\AutoRun.exe *Newly Created Service* - CATCHME . Contents of the 'Scheduled Tasks' folder 2008-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2007-01-10 16:42] 2009-02-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-03 21:12] 2009-02-05 c:\windows\Tasks\MP Scheduled Scan.job - c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 19:20] . - - - - ORPHANS REMOVED - - - - MSConfigStartUp-NetMeter - c:\arquivos de programas\HooTech\NetMeter\HooNetMeter.exe MSConfigStartUp-QuickTime Task - c:\arquivos de programas\QuickTime\qttask.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://search.speedbit.com/ IE: &Clean Traces - c:\arquivos de programas\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\arquivos de programas\DAP\dapextie.htm IE: Add to AMV Converter... - c:\arquivos de programas\MP3 Player Utilities 4.18\AMVConverter\grab.html IE: Download &all with DAP - c:\arquivos de programas\DAP\dapextie2.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll FF - ProfilePath - c:\documents and settings\Karin\Dados de aplicativos\Mozilla\Firefox\Profiles\vp0z73w6.default\ FF - prefs.js: browser.startup.homepage - hxxp://search.speedbit.com/ FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q= FF - component: c:\arquiv~1\MOZILL~1\extensions\{41697025-CA0B-4687-99DE-ABC82C5A630B}\components\NOWImaging_Moz.dll FF - component: c:\arquiv~1\MOZILL~1\extensions\{9d613b03-9b7c-4fa0-b2f8-32f7cc24873f}\components\SDIIntegrator.dll FF - component: c:\arquivos de programas\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\arquivos de programas\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll FF - component: c:\documents and settings\Karin\Dados de aplicativos\Mozilla\Firefox\Profiles\vp0z73w6.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886D}\components\GbMzhCef.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-05 19:55:29 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-02-05 19:56:41 ComboFix-quarantined-files.txt 2009-02-05 21:56:16 ComboFix2.txt 2009-01-22 03:19:11 ComboFix3.txt 2008-12-31 00:52:58 Pre-Run: 20 pasta(s) 58.636.947.456 bytes disponíveis Post-Run: 19 pasta(s) 58,696,568,832 bytes disponíveis 5015 --- E O F --- 2009-02-02 23:44:53 Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 5, 2009 continuando 5: (Ufaaaaaaaaaaa!!!) E aqui o log do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:00:10, on 05/02/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Google\Update\GoogleUpdate.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Logitech\iTouch\iTouch.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Ares\Ares.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\arquivos de programas\relevantknowledge\rlvknlg.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Documents and Settings\Karin\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\WISPTIS.EXE C:\Arquivos de programas\uTorrent\uTorrent.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\ARQUIV~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file) O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun O4 - HKLM\..\Run: [zBrowser Launcher] C:\Arquivos de programas\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Arquivos de programas\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Acrobat Assistant.lnk = C:\Arquivos de programas\Adobe\Acrobat 6.0\Distillr\acrotray.exe O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.18\AMVConverter\grab.html O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\ARQUIV~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Update Service (gupdate1c98654ea637532) (gupdate1c98654ea637532) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 8622 bytes Está tudo OK? é normal gerar um log tao extenso?? Obrigada (muito obrigada!) Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 13, 2009 Está tudo OK? é normal gerar um log tao extenso?? Isto não é comum... Bem, o Malwarebytes AntiMalware é um produto relativamente novo, porém com grande eficácia na remoção de infecções comuns. O programa é pequeno, gratuito e em português. A sua instalação é o primeiro passo para a limpeza de um sistema operacional infectado. Neste tutorial você aprenderá a instalá-lo e executá-lo. 1) Primeiramente faça o download do programa: http://www.malwarebytes.org/mbam/program/mbam-setup.exe 2) Agora proceda a instalação do programa, conforme segue: Execute o programa de instalação: Logo após a execução do arquivo de instalação, será exibida a seguinte tela: Agora, clique em Instalar para concluir: Ao término da instalação deixe marcadas as opções de Atualização e Execução: Será exibida então a tela de atualização do programa: 3) Essa é a tela inicial do programa. Marque a opção Verificação Completa e clique no botão Verificar. Aguarde até o final da verificação: Ao concluir a verificação, será exibida essa mensagem: O resultado da verificação será exibido, com o nome dos arquivos e malwares encontrados. Para efetivar a limpeza, clique em Remover selecionados: Para concluir a limpeza haverá a necessidade da reinicialização do computador: O programa guarda os logs das verificações feitas na pasta C:\Documents and Settings\Seu nome de Usuario\Dados de aplicativos\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa. Retorne com o resultado da varredura. Créditos: Fabio Assolini. Link para a postagem original: aqui. Compartilhar este post Link para o post Compartilhar em outros sites
Noga 0 Denunciar post Postado Fevereiro 15, 2009 Aqui vai o log: Malwarebytes' Anti-Malware 1.34 Versão do banco de dados: 1763 Windows 5.1.2600 Service Pack 3 15/02/2009 11:53:17 mbam-log-2009-02-15 (11-53-17).txt Tipo de Verificação: Completa (C:\|D:\|E:\|) Objetos verificados: 204700 Tempo decorrido: 54 minute(s), 51 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 2 Valores do Registro infectados: 2 Ítens do Registro infectados: 0 Pastas infectadas: 2 Arquivos infectados: 6 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. Valores do Registro infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: C:\Arquivos de programas\Live_TV (Adware.Agent) -> Quarantined and deleted successfully. C:\Arquivos de programas\RelevantKnowledge (Spyware.Marketscore) -> Quarantined and deleted successfully. Arquivos infectados: C:\System Volume Information\_restore{16FA3266-7419-4931-B080-1ECC8573A09D}\RP55\A0032061.exe (Adware.NetPumper) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{16FA3266-7419-4931-B080-1ECC8573A09D}\RP55\A0032064.exe (Adware.NetPumper) -> Quarantined and deleted successfully. D:\Karin Noga\Downloads\NERO 2005\Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Arquivos de programas\RelevantKnowledge\rlls.dll (Spyware.Marketscore) -> Quarantined and deleted successfully. C:\Arquivos de programas\RelevantKnowledge\rlservice.exe (Spyware.Marketscore) -> Quarantined and deleted successfully. C:\Arquivos de programas\RelevantKnowledge\rlvknlg.exe (Spyware.Marketscore) -> Quarantined and deleted successfully. Compartilhar este post Link para o post Compartilhar em outros sites