1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Multiple problems after clicking on BHO toolbar

Discussion in 'Malware and Virus Removal Archive' started by TamoNeko, 2010/08/09.

Thread Status:
Not open for further replies.
  1. 2010/08/09
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    [Inactive] Multiple problems after clicking on BHO toolbar

    Hello
    I've recently after years of using PC clicked on some .exe malware and now I have several problems :

    1.Very slow user/admin login to windows,and very slow first refreshing of desktop icons(was way faster before)
    2.Can not access anti malware sites and microsoft
    3.Some processes fail to start even though they are pointed at the right system files.
    4.Noticed that process svchost.exe trying to access internet.


    at first I wasn't able to start antimalware programs as some "gremlins" were killing them then I ran combofix which worked like a charm many times before but not this time.

    thanks in advance

    p.s.exe was called bho toolbar as I recall

    op.sys: windows xp sp3
     
    Last edited: 2010/08/09
  2. 2010/08/09
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2010/08/09
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    ok, I was confused as the DDS said to wait for direction to post logs
    here are the logs:

    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Woolfer at 1:10:39.53 on uto 10.08.2010
    Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.363 [GMT 2:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\system32\svchost -k rpcss
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
    C:\WINDOWS\SYSTEM32\astsrv.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe
    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    C:\Program Files\Di recnik\Di.exe
    C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
    C:\Program Files\ProxyFirewall\ProxyFirewall.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe
    C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\root.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Woolfer\Desktop\dds.scr
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = about:blank
    uInternet Settings,ProxyServer = 218.29.234.50:3128
    uInternet Settings,ProxyOverride = 127.0.0.1
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
    uRun: [ProxyFirewall] c:\program files\proxyfirewall\ProxyFirewall.exe
    uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
    mRun: [C-Media Mixer] Mixer.exe /startup
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [TWCU] "c:\program files\tp-link\tp-link wireless client utility\TWCU.exe" -nogui
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [nwiz] nwiz.exe /install
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [SW24] c:\windows\system32\sw24.exe
    mRun: [SW20] c:\windows\system32\sw20.exe
    mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
    mRun: [Di dictionary] "c:\program files\di recnik\Di.exe "
    mRun: [BtTray] "c:\program files\ivt corporation\bluesoleil\BtTray.exe "
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe "
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    dRun: [ctfmon.exe] c:\windows\system32\CTFMON.EXE
    StartupFolder: c:\docume~1\woolfer\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\woolfer\startm~1\programs\startup\shortc~1.lnk - c:\documents and settings\woolfer\desktop\folders\netoverbt\new folder\hiisi1.6.3\pihatonttu\Pihatonttu.cmd
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tssins~1.lnk - c:\program files\common files\nokia\tss\instrument api\bin\tray.exe
    IE: + Offline &Explorer: Download the link - file://c:\program files\offline explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\offline explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: Prevedi sa Di recnikom - c:\program files\di recnik\diie.htm
    IE: Send by Bluetooth - c:\program files\ivt corporation\bluesoleil\transsend\ie\tsinfo.htm
    IE: Send via &Message... - c:\program files\ivt corporation\bluesoleil\transsend\ie\tssms.htm
    IE: Translate with Di dictionary -
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://dcode.support.microsoft.com/Dcode/ActiveX/MSDcode.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1277499972140
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} -
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\windows\system32\skype4com.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\woolfer\applic~1\mozilla\firefox\profiles\wgw1e5f5.default\
    FF - prefs.js: browser.search.selectedEngine - eBay
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.http - 218.29.234.50
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: c:\documents and settings\woolfer\local settings\application data\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\documents and settings\woolfer\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);

    ============= SERVICES / DRIVERS ===============

    R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2010-4-6 20744]
    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\abbyy finereader 9.0\NetworkLicenseServer.exe [2007-9-24 566560]
    R2 BsMobileCS;BsMobileCS;c:\program files\ivt corporation\bluesoleil\BsMobileCS.exe [2009-2-27 143467]
    R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [2010-4-22 10454]
    R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2010-3-6 1668352]
    R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2010-4-6 30088]
    R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2010-4-6 26248]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [2008-7-2 418832]
    S2 CachemanService;Cacheman Service;c:\program files\cacheman\cachemanserv.exe --> c:\program files\cacheman\CachemanServ.exe [?]
    S2 nxfgt;Image System;c:\windows\system32\svchost.exe -k netsvcs [2008-11-27 14336]
    S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\drivers\btcomport.sys --> c:\windows\system32\drivers\btcomport.sys [?]
    S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\drivers\btcombus.sys --> c:\windows\system32\drivers\btcombus.sys [?]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-5-31 136704]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-5-31 8320]

    =============== Created Last 30 ================

    2010-08-09 15:10:33 0 d-----w- c:\program files\DAEMON Tools Lite
    2010-08-09 11:21:01 0 d-----w- C:\xpsp3
    2010-08-08 12:44:58 49664 ----a-w- c:\windows\unvise32.exe
    2010-08-08 12:44:47 0 d-----w- c:\program files\Active Ports
    2010-08-08 10:59:49 0 d-----w- c:\program files\Trend Micro
    2010-08-08 10:37:34 0 d-----w- c:\docume~1\woolfer\applic~1\Malwarebytes
    2010-08-08 10:36:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-08 10:36:17 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-08-08 10:36:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-08 10:36:15 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-08 03:06:47 0 d-----w- C:\ComboFix
    2010-08-06 22:19:25 0 d-sha-r- C:\cmdcons
    2010-07-30 13:08:36 0 d-----w- c:\program files\Gish
    2010-07-30 00:36:07 7 ----a-w- c:\windows\Winset.drv
    2010-07-30 00:36:07 0 ----a-w- c:\windows\winkey.drv
    2010-07-30 00:14:26 438976 ----a-w- c:\windows\system32\MSHFLXGD.OCX
    2010-07-30 00:09:51 0 d-----w- c:\program files\World of Wisdom
    2010-07-29 23:55:40 0 d-----w- c:\program files\Kundli for Windows
    2010-07-22 18:47:36 0 ------w- C:\sudo make wlunload to unload wireless modules
    2010-07-20 01:12:15 0 d-----w- c:\program files\mIRC
    2010-07-20 01:12:15 0 d-----w- c:\docume~1\woolfer\applic~1\mIRC
    2010-07-15 12:17:23 342016 ----a-w- c:\windows\system32\eswiaud.dll
    2010-07-15 12:17:23 15872 ----a-w- c:\windows\system32\escdev.dll
    2010-07-15 12:17:23 128392 ----a-w- c:\windows\system32\esdevapp.exe
    2010-07-13 21:57:01 8704 --sha-w- c:\windows\Thumbs.db
    2010-07-13 12:00:42 0 d-----w- c:\docume~1\woolfer\applic~1\Stardock
    2010-07-13 11:19:13 0 d-----w- c:\program files\RocketDock
    2010-07-12 23:50:39 0 d-----w- c:\windows\system32\ivtMobCache
    2010-07-12 15:58:12 0 d-----w- c:\program files\AveIconifier2


    ==================== Find3M ====================

    2010-08-09 15:30:18 21504 ----a-w- c:\windows\system32\hidserv.dll
    2010-08-09 15:06:25 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
    2010-06-29 17:00:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2008-11-27 03:45:08 164746 --sha-r- c:\windows\system32\wmrqdl.dll

    ============= FINISH: 1:11:43.79 ===============

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2/22/2009 12:03:38 AM
    System Uptime: 8/9/2010 11:16:12 PM (2 hours ago)

    Motherboard: MICRO-STAR INC. | | MS-6704
    Processor: Intel(R) Celeron(R) CPU 1.70GHz | FC-478 | 1703/100mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 112 GiB total, 12.591 GiB free.
    D: is CDROM ()
    E: is FIXED (NTFS) - 75 GiB total, 0.995 GiB free.
    G: is CDROM ()
    H: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP115: 8/9/2010 6:00:44 PM - System Checkpoint

    ==== Installed Programs ======================

    ABBYY FineReader 6.0 Sprint
    ABBYY FineReader 9.0 Professional Edition
    Acoustica Effects Pack
    Active Ports
    Adobe Bridge 1.0
    Adobe Common File Installer
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Help Center 1.0
    Adobe Media Player
    Adobe Photoshop CS2
    Adobe Reader 8.2.3
    Adobe Stock Photos 1.0
    AdriaROUTE 3.00 NT
    Anonymity 4 Proxy version 2.8
    Aquastart
    µTorrent
    Beyond Compare Version 3.1.11
    Bloboats
    Bluesoleil 6.4.249.0
    Bukvar
    C-Media PCI Audio Device
    Calendar Upgrade
    Canon Camera Access Library
    Canon Camera Support Core Library
    Canon G.726 WMP-Decoder
    Demolition Racer
    DFX for Winamp
    Di reenik, v1.0.0.58
    Diamond Drop
    Discover Painting for Kids Version 1.0
    Dream Aquarium
    DVB Dream version 1.4i
    DVBViewer Technisat Edition
    Elite Proxy Switcher 1.08
    eMule
    EPSON Scan
    EPSON SX110 Series Printer Uninstall
    FocalPoint 1.0
    Ford Racing 2
    FuzzyLogicIV
    Garmin MapSource
    Garmin USB Drivers
    Genuine Fractals 5.0
    Gish
    Google Earth
    Gravity
    Hard Truck 18 Wheels of Steel
    Hello Kitty Dream Carnival
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Windows XP (KB954550-v5)
    IBS
    Intellihance Pro 4.2
    IrfanView (remove only)
    JAF Setup
    Java Auto Updater
    Java(TM) 6 Update 20
    K-Lite Codec Pack 6.0.4 (Full)
    Kundli for Windows v4.5 (Demo)
    L&H TTS3000 British English
    Magic ISO Maker v5.5 (build 0274)
    MainConcept DTV Decoder Standard
    Malwarebytes' Anti-Malware
    Mask Pro 4.1
    MetaProducts Offline Explorer Enterprise
    Metric Converter
    Microcat for Ford Europe 01.2008
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Easy Assist v2
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    Microsoft Midtown Madness 2
    Microsoft Office Professional Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.7
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Windows Media Video 9 VCM
    Microsoft XML Parser
    MiG-29 Fulcrum
    Mini-stream Ripper 3.0.1.1 2008.11.23
    mIRC
    Mjuice Media Support for Winamp
    Motorola SM56 Speakerphone Modem
    Mozilla Firefox (3.6.8)
    MSVC80_x86
    MSVC80_x86_v2
    MSXML 6.0 Parser (KB933579)
    Need for Speedâ„¢ Carbon
    Nero 6 Demo
    Network Stumbler 0.4.0 (remove only)
    Nokia Connectivity Cable Driver
    Nokia Firmware RM-356 LTA
    Nokia Service Tool Drivers
    NVIDIA Drivers
    PC Connectivity Solution
    PCI Audio Driver
    Phoenix Service Software
    Phoenix Service Software 2009.20.010.39068
    PhotoFrame Pro 3.1
    PhotoTools 1.0.3 Professional Edition
    Plan Plus 2003 Pirate Edition (Serbian Only) 1.0
    Pro Pinball - Timeshock!
    Pro Pinball : Big Race USA
    Pro Pinball : Fantastic Journey
    ProgDVB
    ProxyFirewall 1.0.4 Beta
    R.C. Cars
    Rage of Mages
    RocketDock 1.3.5
    SCG Route 2.20 NT
    Serials 2000
    Sony Noise Reduction Plug-In 2.0h
    Sony Sound Forge 9.0
    Spelling Dictionaries Support For Adobe Reader 8
    Spin It Again
    SpongeBob SquarePants - Battle for Bikini Bottom
    SqrSoft® Advanced Crossfading (remove only)
    Subtitle Workshop 2.51
    TechniSat DVB-PC TV Star
    Technisat DVB-VC80 Redistributable Modules
    Toy Story 2
    TP-LINK Wireless Client Utility
    Universal Extractor 1.6.1
    VisiPics V1.30
    WebFldrs XP
    Winamp
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Support Tools
    WinRAR archiver
    WirelessMon V3.1
    WOW
    WOW Love

    ==== Event Viewer Messages From Past Week ========

    8/9/2010 6:45:57 PM, error: Service Control Manager [7023] - The Image System service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    8/9/2010 6:00:23 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments " " in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    8/9/2010 3:15:15 PM, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
    8/9/2010 2:55:09 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\ could not be copied into the DLL cache. The specific error code is 0x00000000 [The operation completed successfully. ]. This file is necessary to maintain system stability.
    8/9/2010 2:54:19 PM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\servsupp\fp4amsft.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/9/2010 12:01:04 AM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\isapi\_vti_adm\admin.dll could not be copied into the DLL cache. The specific error code is 0x000003e3 [The I/O operation has been aborted because of either a thread exit or an application request. ]. This file is necessary to maintain system stability.
    8/9/2010 1:34:51 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\admwprox.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/9/2010 1:34:48 PM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\_vti_bin\_vti_adm\admin.exe could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/9/2010 1:34:14 PM, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is Woolfer.
    8/9/2010 1:34:13 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsrv\certmap.ocx could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/9/2010 1:34:03 PM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\isapi\_vti_adm\admin.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
    8/9/2010 1:24:03 PM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\isapi\_vti_aut\author.dll could not be copied into the DLL cache. The specific error code is 0x000005b4 [This operation returned because the timeout period expired. ]. This file is necessary to maintain system stability.
    8/8/2010 8:30:16 PM, error: Service Control Manager [7000] - The lirsgt service failed to start due to the following error: The system cannot find the file specified.
    8/8/2010 8:30:16 PM, error: Service Control Manager [7000] - The atksgt service failed to start due to the following error: The system cannot find the file specified.
    8/8/2010 3:12:43 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:12:39 PM, error: Service Control Manager [7034] - The BsHelpCS service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:12:11 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:12:11 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
    8/8/2010 3:11:05 PM, error: Service Control Manager [7034] - The AST Service service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:10:55 PM, error: Service Control Manager [7034] - The ABBYY FineReader 9.0 Licensing Service service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:10:41 PM, error: Service Control Manager [7034] - The Canon Camera Access Library 8 service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:09:48 PM, error: Service Control Manager [7034] - The BsMobileCS service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:09:44 PM, error: Service Control Manager [7034] - The BlueSoleilCS service terminated unexpectedly. It has done this 1 time(s).
    8/8/2010 3:09:37 PM, error: Service Control Manager [7031] - The Universal Plug and Play Device Host service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
    8/8/2010 12:01:30 PM, error: Service Control Manager [7000] - The Cacheman Service service failed to start due to the following error: The system cannot find the file specified.
    8/8/2010 11:27:16 PM, information: Windows File Protection [64021] - The system file c:\program files\common files\microsoft shared\web server extensions\40\bin\cfgwiz.exe could not be copied into the DLL cache. The specific error code is 0x000005b4 [This operation returned because the timeout period expired. ]. This file is necessary to maintain system stability.
    8/8/2010 11:27:16 PM, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is .
    8/8/2010 11:18:30 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started.
    8/7/2010 12:52:42 AM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
    8/7/2010 11:02:37 PM, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.
    8/6/2010 12:43:20 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    8/6/2010 12:28:20 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    8/6/2010 1:13:20 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    8/5/2010 6:56:12 PM, error: Service Control Manager [7000] - The adfs service failed to start due to the following error: The system cannot find the file specified.
    8/5/2010 6:52:12 PM, error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    8/5/2010 6:52:00 PM, error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:51:49 PM, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
    8/5/2010 6:51:42 PM, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:51:42 PM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:51:42 PM, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:51:18 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:43:53 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BsHelpCS with arguments "-Service" in order to run the server: {1CE3EB56-16B9-40A0-8110-284EF53ACF04}
    8/5/2010 6:43:53 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BlueSoleilCS with arguments "-Service" in order to run the server: {DC22CE61-F0A5-415C-986E-4DF78C2D1029}
    8/5/2010 6:42:21 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied.
    8/5/2010 6:17:35 PM, error: Service Control Manager [7034] - The Cacheman Service service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:17:16 PM, error: Service Control Manager [7031] - The Remote Procedure Call (RPC) service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
    8/5/2010 6:17:00 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:13:01 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    8/5/2010 6:04:55 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D.
    8/5/2010 5:56:46 PM, error: sfsync02 [12] -
    8/5/2010 5:28:17 PM, error: PlugPlayManager [12] - The device 'Virtual Serial Bus Enumerator' (Root\SYSTEM\0003) disappeared from the system without first being prepared for removal.
    8/5/2010 5:28:17 PM, error: PlugPlayManager [12] - The device 'Plug and Play Software Device Enumerator' (Root\SYSTEM\0000) disappeared from the system without first being prepared for removal.
    8/5/2010 5:28:17 PM, error: PlugPlayManager [12] - The device 'Microsoft System Management BIOS Driver' (Root\SYSTEM\0002) disappeared from the system without first being prepared for removal.
    8/5/2010 5:28:17 PM, error: PlugPlayManager [12] - The device 'Microcode Update Device' (Root\SYSTEM\0001) disappeared from the system without first being prepared for removal.
    8/4/2010 6:02:39 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The class is configured to run as a security id different from the caller
    8/4/2010 6:02:27 PM, error: Service Control Manager [7034] - The TP-LINK Configuration Service service terminated unexpectedly. It has done this 1 time(s).

    ==== End Of File ===========================
     
  5. 2010/08/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    STEP 1. Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


    STEP 2. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    Do NOT use the computer while GMER is running!
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    IMPORTANT! If for some reason GMER refuses to run, try again.
    If it still fails, try to UN-check "Devices" in right pane.
    If still no joy, try to run it from Safe Mode.


    STEP 3. Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.



    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2010/08/10
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    I can access anti-malware sites now...still slow login
    1.MBAM
    ----------
    WHILE SCANNING WITH MALWAREBYTES' :
    An error has occured. Please report this error code to our support team
    MBAM_ERROR_FILE_SCAN (0, 5)
    c:\program Files\windows NT\hypertrm.exe

    /

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4412

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 6.0.2900.5512

    10.8.2010 13:25:31
    mbam-log-2010-08-10 (13-25-31).txt

    Scan type: Quick scan
    Objects scanned: 140854
    Time elapsed: 13 minute(s), 0 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\wmrqdl.dll (Worm.Conficker) -> Delete on reboot.
    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\81ANIJA1\aedjo[1].gif (Worm.Conficker) -> Quarantined and deleted successfully.



    2.GMER
    -------------------------------------------------------------------------
    Gmer reported error like this I've uploaded a picture as system gets BSOD and restarts too fast


    [​IMG]

    Uploaded with ImageShack.us

    [​IMG]

    Uploaded with ImageShack.us

    LOG JUST BEFORE BSOD:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-08-10 22:08:15
    Windows 5.1.2600 Service Pack 3
    Running: ww6pyhe9.exe; Driver: C:\DOCUME~1\Woolfer\LOCALS~1\Temp\pwrdqpoc.sys


    ---- System - GMER 1.0.15 ----

    SSDT sprk.sys ZwCreateKey [0xF748E0E0]
    SSDT sprk.sys ZwEnumerateKey [0xF74ACCA2]
    SSDT sprk.sys ZwEnumerateValueKey [0xF74AD030]
    SSDT sprk.sys ZwOpenKey [0xF748E0C0]
    SSDT sprk.sys ZwQueryKey [0xF74AD108]
    SSDT sprk.sys ZwQueryValueKey [0xF74ACF88]
    SSDT sprk.sys ZwSetValueKey [0xF74AD19A]

    INT 0x62 ? 83F6DBF8
    INT 0x63 ? 83D2BBF8
    INT 0x73 ? 83F70BF8
    INT 0x82 ? 83F6DBF8
    INT 0x94 ? 83D2BBF8
    INT 0xA4 ? 83D2BBF8
    INT 0xB4 ? 83D2BBF8

    ---- Kernel code sections - GMER 1.0.15 ----

    ? sprk.sys The system cannot find the file specified. !
    .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6861360, 0x20598D, 0xE8000020]
    .text USBPORT.SYS!DllUnload F68418AC 5 Bytes JMP 83D2B1D8
    .text aaf32zp1.SYS F56CB384 1 Byte [20]
    .text aaf32zp1.SYS F56CB384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
    .text aaf32zp1.SYS F56CB3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
    .text aaf32zp1.SYS F56CB3C4 3 Bytes [00, 00, 00]
    .text aaf32zp1.SYS F56CB3C9 1 Byte [00]
    .text ...
    ? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\Explorer.EXE[236] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\Explorer.EXE[236] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 01431000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\Explorer.EXE[236] WS2_32.dll!send 71AB4C27 6 Bytes JMP 01432300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\spoolsv.exe[372] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\spoolsv.exe[372] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00BC1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\spoolsv.exe[372] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00BC2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Canon\CAL\CALMAIN.exe[508] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Canon\CAL\CALMAIN.exe[508] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Canon\CAL\CALMAIN.exe[508] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe[560] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe[560] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 010D1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe[560] WS2_32.dll!send 71AB4C27 6 Bytes JMP 010D2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe[596] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe[596] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 010A1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe[596] WS2_32.dll!send 71AB4C27 6 Bytes JMP 010A2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\Mixer.exe[628] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\Mixer.exe[628] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 023B1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\Mixer.exe[628] WS2_32.dll!send 71AB4C27 6 Bytes JMP 023B2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[644] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[644] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[644] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe[668] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe[668] ws2_32.dll!connect 71AB4A07 6 Bytes JMP 02E11000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe[668] ws2_32.dll!send 71AB4C27 6 Bytes JMP 02E12300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe[720] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe[720] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 011F1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe[720] WS2_32.dll!send 71AB4C27 6 Bytes JMP 011F2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\csrss.exe[820] KERNEL32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\csrss.exe[820] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\csrss.exe[820] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\winlogon.exe[852] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\winlogon.exe[852] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\winlogon.exe[852] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\SYSTEM32\astsrv.exe[864] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\SYSTEM32\astsrv.exe[864] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\SYSTEM32\astsrv.exe[864] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe[896] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe[896] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00CB1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe[896] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00CB2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\alg.exe[924] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\System32\alg.exe[924] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\alg.exe[924] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe[988] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe[988] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00E51000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe[988] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00E52300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\svchost.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\System32\svchost.exe[996] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\svchost.exe[996] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[1048] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
    .text C:\Program Files\Mozilla Firefox\firefox.exe[1048] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Mozilla Firefox\firefox.exe[1048] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
    .text C:\Program Files\Mozilla Firefox\firefox.exe[1048] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00EB1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[1048] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00EB2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Java\jre6\bin\jqs.exe[1096] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Java\jre6\bin\jqs.exe[1096] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Java\jre6\bin\jqs.exe[1096] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\nvsvc32.exe[1132] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\nvsvc32.exe[1132] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\nvsvc32.exe[1132] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\services.exe[1184] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\services.exe[1184] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\services.exe[1184] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\lsass.exe[1196] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\lsass.exe[1196] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\lsass.exe[1196] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1356] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1356] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1416] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1416] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1416] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Di recnik\Di.exe[1452] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Di recnik\Di.exe[1452] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Di recnik\Di.exe[1452] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1484] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1484] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1484] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe[1564] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe[1564] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe[1564] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\svchost.exe[1588] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\System32\svchost.exe[1588] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\System32\svchost.exe[1588] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\DAEMON Tools Lite\daemon.exe[1624] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\DAEMON Tools Lite\daemon.exe[1624] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 013E1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\DAEMON Tools Lite\daemon.exe[1624] WS2_32.dll!send 71AB4C27 6 Bytes JMP 013E2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1628] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1628] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1628] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1728] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1728] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1728] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\svchost.exe[1768] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\svchost.exe[1768] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe[1940] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe[1940] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00DC1000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe[1940] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00DC2300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\wscntfy.exe[1944] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\wscntfy.exe[1944] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\wscntfy.exe[1944] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\rundll32.exe[1952] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\WINDOWS\system32\rundll32.exe[1952] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\WINDOWS\system32\rundll32.exe[1952] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2028] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2028] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe[2028] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\root.exe[2316] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\root.exe[2316] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 00A61000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\root.exe[2316] WS2_32.dll!send 71AB4C27 6 Bytes JMP 00A62300 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Documents and Settings\Woolfer\Desktop\ww6pyhe9.exe[2944] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F070F5A
    .text C:\Documents and Settings\Woolfer\Desktop\ww6pyhe9.exe[2944] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
    .text C:\Documents and Settings\Woolfer\Desktop\ww6pyhe9.exe[2944] WS2_32.dll!connect 71AB4A07 6 Bytes JMP 10001000 C:\Program Files\ProxyFirewall\PFW.dll
    .text C:\Documents and Settings\Woolfer\Desktop\ww6pyhe9.exe[2944] WS2_32.dll!send 71AB4C27 6 Bytes JMP 10002300 C:\Program Files\ProxyFirewall\PFW.dll

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 83F702D8
    IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74BFC4C] sprk.sys
    IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74BFCA0] sprk.sys
    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F748F040] sprk.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F748F13C] sprk.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F748F0BE] sprk.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F748F7FC] sprk.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F748F6D2] sprk.sys
    IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 83D2B2D8
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlInitUnicodeString] 000000A5
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!swprintf] 000000E5
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeSetEvent] 000000F1
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000071
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000D8
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00000031
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmFreeMappingAddress] 00000015
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000004
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 000000C7
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmUnmapIoSpace] 00000023
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 000000C3
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IofCompleteRequest] 00000018
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 00000096
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IofCallDriver] 00000005
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0000009A
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000007
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000012
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoDetachDevice] 00000080
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeWaitForSingleObject] 000000E2
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInitializeEvent] 000000EB
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeCancelTimer] 00000027
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000B2
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000075
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000009
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoQueueWorkItem] 00000083
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmMapIoSpace] 0000002C
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0000001A
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoReportDetectedDevice] 0000001B
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0000006E
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 0000005A
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!NlsMbCodePageTag] 000000A0
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!PoRequestPowerIrp] 00000052
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 0000003B
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 000000D6
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!sprintf] 000000B3
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00000029
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ObfDereferenceObject] 000000E3
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0000002F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000084
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ZwClose] 00000053
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 000000D1
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000000
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 000000ED
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 00000020
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoCreateDevice] 000000FC
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B1
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0000005B
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000006A
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ZwOpenKey] 000000CB
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 000000BE
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoStartTimer] 00000039
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInitializeTimer] 0000004A
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoInitializeTimer] 0000004C
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInitializeDpc] 00000058
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInitializeSpinLock] 000000CF
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoInitializeIrp] 000000D0
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ZwCreateKey] 000000EF
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AA
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 000000FB
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ZwSetValueKey] 00000043
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeInsertQueueDpc] 0000004D
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000033
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoStartPacket] 00000085
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000045
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000F9
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoFreeMdl] 00000002
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmUnlockPages] 0000007F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 00000050
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 0000003C
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 0000009F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000A8
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000051
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoStartNextPacket] 000000A3
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeBugCheckEx] 00000040
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeSetTimer] 00000092
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!_allmul] 0000009D
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000038
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!_except_handler3] 000000F5
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!PoSetPowerState] 000000BC
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000B6
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000DA
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000021
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!_aulldiv] 00000010
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!strstr] 000000FF
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!_strupr] 000000F3
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000D2
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CD
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!KeTickCount] 0000000C
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000013
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoDeleteDevice] 000000EC
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000005F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000097
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAllocateIrp] 00000044
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoAllocateMdl] 00000017
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000C4
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000A7
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000007E
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 0000003D
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!ExFreePoolWithTag] 00000064
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoFreeIrp] 0000005D
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!IoFreeWorkItem] 00000019
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!RtlCompareMemory] 00000060
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!PoCallDriver] 00000081
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!memmove] 0000004F
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000DC
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KfRaiseIrql] 000000AF
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KfLowerIrql] 0000009C
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!HalGetInterruptVector] 000000A4
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!HalTranslateBusAddress] 00000072
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!READ_PORT_USHORT] 00000093
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
    IAT \SystemRoot\System32\Drivers\aaf32zp1.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC
     
  7. 2010/08/10
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 83FD91F8
    Device \FileSystem\Fastfat \FatCdrom 83B8C500
    Device \Driver\usbuhci \Device\USBPDO-0 83D261F8
    Device \Driver\PCI_PNP6766 \Device\00000051 sprk.sys
    Device \Driver\dmio \Device\DmControl\DmIoDaemon 83FDB1F8
    Device \Driver\dmio \Device\DmControl\DmConfig 83FDB1F8
    Device \Driver\dmio \Device\DmControl\DmPnP 83FDB1F8
    Device \Driver\dmio \Device\DmControl\DmInfo 83FDB1F8
    Device \Driver\usbuhci \Device\USBPDO-1 83D261F8
    Device \Driver\NetBT \Device\NetBT_Tcpip_{0F71A83A-2192-4CC0-B833-911CB3746CBB} 838B9500
    Device \Driver\usbuhci \Device\USBPDO-2 83D261F8
    Device \Driver\usbehci \Device\USBPDO-3 83D041F8
    Device \Driver\Ftdisk \Device\HarddiskVolume1 83F6E1F8
    Device \Driver\Ftdisk \Device\HarddiskVolume2 83F6E1F8
    Device \Driver\Cdrom \Device\CdRom0 839EC1F8
    Device \Driver\Cdrom \Device\CdRom1 839EC1F8
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F73E2B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdePort0 [F73E2B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdePort1 [F73E2B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F73E2B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\NetBT \Device\NetBt_Wins_Export 838B9500
    Device \Driver\USBSTOR \Device\00000077 83BCB1F8
    Device \Driver\USBSTOR \Device\00000077 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\NetBT \Device\NetbiosSmb 838B9500
    Device \Driver\NetBT \Device\NetBT_Tcpip_{C16C01F7-A271-4B91-AC32-2E868B9355B3} 838B9500
    Device \Driver\usbuhci \Device\USBFDO-0 83D261F8
    Device \Driver\usbuhci \Device\USBFDO-1 83D261F8
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8356B1F8
    Device \Driver\usbuhci \Device\USBFDO-2 83D261F8
    Device \FileSystem\MRxSmb \Device\LanmanRedirector 8356B1F8
    Device \Driver\usbehci \Device\USBFDO-3 83D041F8
    Device \Driver\sptd \Device\3370623016 sprk.sys
    Device \Driver\USBSTOR \Device\0000007d 83BCB1F8
    Device \Driver\USBSTOR \Device\0000007d sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\Ftdisk \Device\FtControl 83F6E1F8
    Device \Driver\fasttx2k \Device\Scsi\fasttx2k1 83FDA1F8
    Device \Driver\fasttx2k \Device\Scsi\fasttx2k1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\aaf32zp1 \Device\Scsi\aaf32zp11 839DF1F8
    Device \Driver\aaf32zp1 \Device\Scsi\aaf32zp11 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\fasttx2k \Device\Scsi\fasttx2k1Port2Path0Target1Lun0 83FDA1F8
    Device \Driver\fasttx2k \Device\Scsi\fasttx2k1Port2Path0Target1Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \Driver\aaf32zp1 \Device\Scsi\aaf32zp11Port3Path0Target0Lun0 839DF1F8
    Device \Driver\aaf32zp1 \Device\Scsi\aaf32zp11Port3Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
    Device \FileSystem\Fastfat \Fat 83B8C500
    Device \FileSystem\Cdfs \Cdfs 83A563E8

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] nxfgt <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001167d6b6a5 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001167d6b6a5@c8979f5b48db 0x69 0x98 0x62 0xE7 ...
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8C 0x93 0x24 0x0B ...
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x09 0x18 0xE9 0x5D ...
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC2 0x7A 0xD8 0x02 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001167d6b6a5
    Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001167d6b6a5@c8979f5b48db 0x69 0x98 0x62 0xE7 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@DisplayName Image System
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@Type 32
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@Start 2
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@ErrorControl 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@ObjectName LocalSystem
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt@Description Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt\Parameters
    Reg HKLM\SYSTEM\CurrentControlSet\Services\nxfgt\Parameters@ServiceDll C:\WINDOWS\system32\wmrqdl.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8C 0x93 0x24 0x0B ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x09 0x18 0xE9 0x5D ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x6D 0x3A 0xE0 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001167d6b6a5 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001167d6b6a5@c8979f5b48db 0x69 0x98 0x62 0xE7 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@DisplayName Image System
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@Type 32
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@Start 2
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@ErrorControl 0
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@ObjectName LocalSystem
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt@Description Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt\Parameters (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\nxfgt\Parameters@ServiceDll C:\WINDOWS\system32\wmrqdl.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8C 0x93 0x24 0x0B ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x09 0x18 0xE9 0x5D ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xCE 0x6D 0x3A 0xE0 ...
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_Dlls C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll


    3.)

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x000000dc

    Kernel Drivers (total 141):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x806EE000 \WINDOWS\system32\hal.dll
    0xF7AAE000 \WINDOWS\system32\KDCOM.DLL
    0xF79BE000 \WINDOWS\system32\BOOTVID.dll
    0xF748D000 spmy.sys
    0xF7AB0000 \WINDOWS\System32\Drivers\WMILIB.SYS
    0xF7475000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
    0xF7447000 ACPI.sys
    0xF7436000 pci.sys
    0xF75AE000 ohci1394.sys
    0xF75BE000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xF75CE000 isapnp.sys
    0xF7B76000 PCIIde.sys
    0xF782E000 \WINDOWS\System32\Drivers\PCIIDEX.SYS
    0xF7AB2000 intelide.sys
    0xF75DE000 MountMgr.sys
    0xF7417000 ftdisk.sys
    0xF7AB4000 dmload.sys
    0xF73F1000 dmio.sys
    0xF7836000 PartMgr.sys
    0xF783E000 sfsync02.sys
    0xF75EE000 VolSnap.sys
    0xF73D9000 atapi.sys
    0xF73B8000 fasttx2k.sys
    0xF75FE000 disk.sys
    0xF760E000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF7398000 fltMgr.sys
    0xF7386000 sr.sys
    0xF761E000 PxHelp20.sys
    0xF736F000 KSecDD.sys
    0xF735C000 WudfPf.sys
    0xF72CF000 Ntfs.sys
    0xF72A2000 NDIS.sys
    0xF7846000 sfhlp02.sys
    0xF7291000 sfdrv01.sys
    0xF7277000 Mup.sys
    0xF79C2000 BtHidBus.sys
    0xF762E000 agp440.sys
    0xF76FE000 \SystemRoot\system32\DRIVERS\processr.sys
    0xF6861000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
    0xF684D000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xF78A6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xF6829000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF78AE000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF67C1000 \SystemRoot\system32\DRIVERS\SkyNET.SYS
    0xF66D0000 \SystemRoot\system32\DRIVERS\smserial.sys
    0xF78B6000 \SystemRoot\System32\Drivers\Modem.SYS
    0xF770E000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xF6673000 \SystemRoot\system32\drivers\cmaudio.sys
    0xF664F000 \SystemRoot\system32\drivers\portcls.sys
    0xF6C51000 \SystemRoot\system32\drivers\drmk.sys
    0xF5744000 \SystemRoot\system32\drivers\ks.sys
    0xF78C6000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xF6C41000 \SystemRoot\system32\DRIVERS\serial.sys
    0xF6D5C000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xF5730000 \SystemRoot\system32\DRIVERS\parport.sys
    0xF6C31000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF6C21000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xF6C11000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xF56AA000 \SystemRoot\System32\Drivers\atgfmwv7.SYS
    0xF795E000 \SystemRoot\System32\Drivers\btnetBus.sys
    0xF7966000 \SystemRoot\System32\Drivers\VcommMgr.sys
    0xF796E000 \SystemRoot\System32\Drivers\IvtBtBus.sys
    0xF7CC8000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xF776E000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xF7AA6000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xF554C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xF777E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xF778E000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xF7976000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xF549B000 \SystemRoot\system32\DRIVERS\psched.sys
    0xF779E000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF3B7E000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF47EA000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xF0523000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xF0C13000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF790E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xF3B6E000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF7B1C000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xF04C5000 \SystemRoot\system32\DRIVERS\update.sys
    0xF720F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xF6D54000 \SystemRoot\system32\DRIVERS\vsb.sys
    0xF0C03000 \SystemRoot\system32\DRIVERS\wsimd.sys
    0xF0BA3000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF0B63000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xF7B40000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xF7A66000 \SystemRoot\system32\drivers\MODEMCSA.sys
    0xF7ACC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7BFF000 \SystemRoot\System32\Drivers\Null.SYS
    0xF7AC2000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF0C4B000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xF0C53000 \SystemRoot\System32\drivers\vga.sys
    0xF7AC0000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF7AB8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xED65B000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xED653000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xEDD91000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xED07D000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xED024000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xECFFC000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xECFDA000 \SystemRoot\System32\drivers\afd.sys
    0xF775E000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xECF3E000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xECECE000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xF77FE000 \SystemRoot\System32\Drivers\Fips.SYS
    0xECE77000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xF76DE000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xF765E000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xED4F9000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xEC5D1000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xEC407000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xEC3F7000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xEBD8A000 \SystemRoot\System32\Drivers\btcusb.sys
    0xEBD82000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xEB29F000 \SystemRoot\system32\DRIVERS\athuw.sys
    0xEC5C9000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xEBD72000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
    0xEC3E7000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
    0xEB22E000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
    0xEBC8C000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xEBC78000 \SystemRoot\System32\Drivers\dump_diskdump.sys
    0xEB18F000 \SystemRoot\System32\Drivers\dump_fasttx2k.sys
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xEB9CF000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF79A6000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF2038000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\nv4_disp.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xECE19000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xB9473000 \SystemRoot\System32\Drivers\Fastfat.SYS
    0xB9446000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xEB445000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xB938D000 \SystemRoot\System32\Drivers\HTTP.sys
    0xB942A000 \??\C:\WINDOWS\system32\drivers\parldr2k.sys
    0xB9313000 \SystemRoot\system32\DRIVERS\srv.sys
    0xEB5A4000 \SystemRoot\system32\DRIVERS\secdrv.sys
    0xB90CE000 \SystemRoot\system32\drivers\wdmaud.sys
    0xF54CC000 \SystemRoot\system32\drivers\sysaudio.sys
    0xF1FE1000 \??\C:\WINDOWS\system32\Drivers\mchInjDrv.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 39):
    0 System Idle Process
    4 System
    684 C:\WINDOWS\system32\smss.exe
    792 C:\WINDOWS\system32\csrss.exe
    1132 C:\WINDOWS\system32\winlogon.exe
    1180 C:\WINDOWS\system32\services.exe
    1192 C:\WINDOWS\system32\lsass.exe
    1348 C:\WINDOWS\system32\svchost.exe
    1408 C:\WINDOWS\system32\svchost.exe
    1572 C:\WINDOWS\system32\svchost.exe
    1624 C:\WINDOWS\system32\svchost.exe
    1716 C:\WINDOWS\system32\svchost.exe
    1764 C:\WINDOWS\system32\svchost.exe
    368 C:\WINDOWS\system32\spoolsv.exe
    660 C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
    748 C:\WINDOWS\system32\ASTSRV.EXE
    760 C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
    800 C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
    940 C:\Program Files\Java\jre6\bin\jqs.exe
    996 C:\WINDOWS\system32\nvsvc32.exe
    1620 C:\WINDOWS\system32\svchost.exe
    2016 C:\Program Files\Canon\CAL\CALMAIN.exe
    200 C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
    1296 C:\WINDOWS\system32\alg.exe
    1240 C:\WINDOWS\system32\svchost.exe
    2052 C:\WINDOWS\explorer.exe
    2100 C:\WINDOWS\system32\wscntfy.exe
    2132 C:\WINDOWS\mixer.exe
    2140 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    2148 C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe
    2236 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
    2260 C:\Program Files\Di recnik\Di.exe
    2268 C:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
    2348 C:\Program Files\ProxyFirewall\ProxyFirewall.exe
    2372 C:\Program Files\DAEMON Tools Lite\daemon.exe
    2400 C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe
    2812 C:\Program Files\Common Files\Nokia\Tss\Instrument API\bin\root.exe
    2944 C:\WINDOWS\system32\notepad.exe
    3240 C:\Documents and Settings\Woolfer\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
    \\.\E: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive1 Model Number: Promise1+0 Stripe/RAID0, Rev: 1.10
    PhysicalDrive0 Model Number: WDCWD800BB-00DKA0, Rev: 77.07W77

    Size Device Name MBR Status
    --------------------------------------------
    111 GB \\.\PhysicalDrive1 RE: Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    74 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
     
    Last edited: 2010/08/10
  8. 2010/08/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK, we have a rootkit.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.pif
    * Rkill.exe


    • * Double-click on the Rkill desktop icon to run the tool.
      * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
      * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
      * If not, delete the file, then download and use the one provided in Link 2.
      * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
      * Do not reboot until instructed.
      * If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run then try to immediately run the following.

    Now download and run exeHelper.


    • * Please download exeHelper from Raktor to your desktop.
      * Double-click on exeHelper.com to run the fix.
      * A black window should pop up, press any key to close once the fix is completed.
      * A log file named log.txt will be created in the directory where you ran exeHelper.com
      * Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file ", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    ==============================================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  9. 2010/08/11
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    :) here goes:

    exeHelper by Raktor
    Build 20100414
    Run at 11:27:12 on 08/11/10
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--
    -------------------------------------------------------------------
    -------------------------------------------------------------------
    ComboFix 10-08-10.05 - Woolfer 11.08.2010 11:37:03.8.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.526 [GMT 2:00]
    Running from: c:\documents and settings\Woolfer\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((( Files Created from 2010-07-11 to 2010-08-11 )))))))))))))))))))))))))))))))
    .

    2010-08-10 11:07 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-10 11:07 . 2010-08-10 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-10 11:07 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-09 15:10 . 2010-08-09 15:10 -------- d-----w- c:\program files\DAEMON Tools Lite
    2010-08-09 11:21 . 2010-08-09 11:21 -------- d-----w- C:\xpsp3
    2010-08-08 12:44 . 1999-12-17 08:13 49664 ----a-w- c:\windows\unvise32.exe
    2010-08-08 12:44 . 2010-08-08 12:44 -------- d-----w- c:\program files\Active Ports
    2010-08-08 10:59 . 2010-08-08 10:59 -------- d-----w- c:\program files\Trend Micro
    2010-08-08 10:37 . 2010-08-08 10:37 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Malwarebytes
    2010-08-08 10:36 . 2010-08-08 10:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-08-02 23:01 . 2010-08-02 23:01 503808 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\msvcp71.dll
    2010-08-02 23:01 . 2010-08-02 23:01 499712 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\jmc.dll
    2010-08-02 23:01 . 2010-08-02 23:01 348160 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\msvcr71.dll
    2010-08-02 23:01 . 2010-08-02 23:01 61440 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1cef6c9b-n\decora-sse.dll
    2010-08-02 23:01 . 2010-08-02 23:01 12800 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1cef6c9b-n\decora-d3d.dll
    2010-07-30 16:02 . 2010-07-30 16:02 -------- d-----w- c:\program files\Google
    2010-07-30 13:08 . 2010-07-31 08:32 -------- d-----w- c:\program files\Gish
    2010-07-30 00:36 . 2010-07-30 00:36 7 ----a-w- c:\windows\Winset.drv
    2010-07-30 00:36 . 2010-07-30 00:36 0 ----a-w- c:\windows\winkey.drv
    2010-07-30 00:09 . 2010-07-30 00:13 -------- d-----w- c:\program files\World of Wisdom
    2010-07-29 23:55 . 2010-07-30 00:02 -------- d-----w- c:\program files\Kundli for Windows
    2010-07-20 01:12 . 2010-07-20 01:37 -------- d-----w- c:\documents and settings\Woolfer\Application Data\mIRC
    2010-07-20 01:12 . 2010-07-20 01:31 -------- d-----w- c:\program files\mIRC
    2010-07-15 12:17 . 2009-04-30 22:00 15872 ----a-w- c:\windows\system32\escdev.dll
    2010-07-15 12:17 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
    2010-07-15 12:17 . 2008-11-16 22:00 342016 ----a-w- c:\windows\system32\eswiaud.dll
    2010-07-15 10:50 . 2007-12-17 02:00 143872 ----a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
    2010-07-15 10:50 . 2007-01-11 02:02 113664 ----a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
    2010-07-13 13:11 . 2010-07-13 13:11 -------- d-----w- c:\documents and settings\Woolfer\Local Settings\Application Data\Stardock
    2010-07-13 13:10 . 2010-07-13 13:10 -------- d-----w- c:\documents and settings\Woolfer\Local Settings\Application Data\PackageAware
    2010-07-13 12:00 . 2010-07-13 12:00 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Stardock
    2010-07-13 11:19 . 2010-07-13 11:19 -------- d-----w- c:\program files\RocketDock
    2010-07-13 00:09 . 2010-07-13 01:07 -------- d-----w- c:\documents and settings\Woolfer\Local Settings\Application Data\SISContents
    2010-07-12 23:50 . 2010-07-12 23:50 -------- d-----w- c:\windows\system32\ivtMobCache
    2010-07-12 15:58 . 2010-07-13 01:42 -------- d-----w- c:\program files\AveIconifier2

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-08-11 09:23 . 2010-07-05 13:19 -------- d-----w- c:\program files\ProxyFirewall
    2010-08-09 15:30 . 2008-05-16 13:51 21504 ----a-w- c:\windows\system32\hidserv.dll
    2010-08-09 15:09 . 2009-03-20 03:23 -------- d-----w- c:\program files\Di recnik
    2010-08-09 15:06 . 2009-02-26 21:08 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
    2010-08-08 17:01 . 2009-03-10 10:43 -------- d-----w- c:\program files\Kaspersky Lab
    2010-08-08 17:01 . 2009-03-10 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2010-08-08 03:07 . 2010-06-29 01:06 -------- d-----w- c:\program files\Cacheman
    2010-08-07 10:44 . 2010-05-22 18:21 146 ----a-w- c:\windows\DelMR.bat
    2010-08-05 16:00 . 2009-02-22 10:24 45864 ----a-w- c:\documents and settings\Woolfer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-30 00:14 . 2009-03-03 21:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-07-22 01:16 . 2009-04-10 02:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-13 13:39 . 2009-03-18 13:16 -------- d-----w- c:\program files\Planplus
    2010-07-12 23:01 . 2010-01-08 16:30 1324 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-07-06 21:49 . 2010-07-06 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\PassMark
    2010-07-06 21:49 . 2010-07-06 21:49 -------- d-----w- c:\program files\WirelessMon
    2010-07-06 01:35 . 2010-07-04 23:36 -------- d-----w- c:\documents and settings\All Users\Application Data\EPS
    2010-07-04 23:42 . 2010-07-04 23:33 -------- d-----w- c:\program files\My-Proxy
    2010-07-04 23:42 . 2010-07-04 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\SPC
    2010-07-03 13:52 . 2010-07-03 13:51 -------- d-----w- c:\program files\Bukvar
    2010-07-03 00:36 . 2010-07-03 00:36 -------- d-----w- c:\documents and settings\Woolfer\Application Data\VitySoft
    2010-07-02 18:30 . 2010-06-29 16:59 -------- d-----w- c:\program files\Common Files\Real
    2010-07-02 13:51 . 2010-07-02 13:41 -------- d-----w- c:\program files\A4Proxy
    2010-06-29 17:00 . 2006-07-11 17:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2010-06-29 16:45 . 2010-06-29 16:45 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-06-29 02:50 . 2010-06-29 02:50 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\uninst_s2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\serial2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 10134 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\ARPPRODUCTICON.exe
    2010-06-26 00:00 . 2009-04-09 14:03 -------- d-----w- c:\documents and settings\Woolfer\Application Data\uTorrent
    2010-06-25 23:12 . 2010-06-25 23:12 -------- d-----w- c:\program files\Support Tools
    2010-06-19 14:04 . 2010-06-19 14:01 -------- d-----w- c:\program files\Gravity
    2010-06-19 10:14 . 2010-06-19 10:13 -------- d-----w- c:\program files\Bloboats
    2010-06-18 15:19 . 2010-06-18 15:18 -------- d-----w- c:\program files\K-Lite Codec Pack
    2010-06-14 12:21 . 2010-06-14 12:21 -------- d-----w- c:\program files\VisiPics
    2010-06-13 20:12 . 2010-06-11 01:30 -------- d-----w- c:\program files\Ontrack
    2010-06-07 17:18 . 2010-06-07 17:18 1892 ----a-w- c:\documents and settings\All Users\Application Data\xml4D.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 13757 ----a-w- c:\documents and settings\All Users\Application Data\xml4C.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 9521 ----a-w- c:\documents and settings\All Users\Application Data\xml4B.tmp
    2010-05-31 19:13 . 2010-05-31 19:13 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
    2010-05-31 19:13 . 2010-05-31 19:13 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
    2010-05-31 19:10 . 2010-05-31 19:13 34399664 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_eng.exe
    2010-05-24 23:01 . 2010-05-24 23:01 503808 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcp71.dll
    2010-05-24 23:01 . 2010-05-24 23:01 499712 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\jmc.dll
    2010-05-24 23:01 . 2010-05-24 23:01 12800 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-d3d.dll
    2010-05-24 23:01 . 2010-05-24 23:01 61440 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-sse.dll
    2010-05-24 23:01 . 2010-05-24 23:01 348160 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcr71.dll
    .

    ------- Sigcheck -------

    [-] 2009-02-21 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((( SnapShot_2010-08-06_22.54.30 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-08-11 09:32 . 2010-08-11 09:32 16384 c:\windows\temp\Perflib_Perfdata_3f0.dat
    + 2010-08-11 09:32 . 2010-08-11 09:32 16384 c:\windows\temp\Perflib_Perfdata_2c0.dat
    + 2009-03-16 00:11 . 2001-08-17 20:36 23040 c:\windows\system32\dllcache\xrxwbtmp.dll
    - 2009-03-16 00:11 . 2001-08-17 21:36 23040 c:\windows\system32\dllcache\xrxwbtmp.dll
    - 2009-03-16 00:11 . 2008-04-14 04:42 18944 c:\windows\system32\dllcache\xrxscnui.dll
    + 2009-03-16 00:11 . 2008-04-14 03:42 18944 c:\windows\system32\dllcache\xrxscnui.dll
    + 2009-03-16 00:11 . 2001-08-17 20:37 27648 c:\windows\system32\dllcache\xrxftplt.exe
    - 2009-03-16 00:11 . 2001-08-17 21:37 27648 c:\windows\system32\dllcache\xrxftplt.exe
    + 2009-03-16 00:10 . 2001-08-17 20:37 99865 c:\windows\system32\dllcache\xlog.exe
    - 2009-03-16 00:10 . 2001-08-17 21:37 99865 c:\windows\system32\dllcache\xlog.exe
    + 2009-03-16 00:10 . 2001-08-17 10:11 16970 c:\windows\system32\dllcache\xem336n5.sys
    - 2009-03-16 00:10 . 2001-08-17 11:11 16970 c:\windows\system32\dllcache\xem336n5.sys
    - 2009-03-16 00:10 . 2008-04-13 21:04 19455 c:\windows\system32\dllcache\wvchntxx.sys
    + 2009-03-16 00:10 . 2008-04-13 20:04 19455 c:\windows\system32\dllcache\wvchntxx.sys
    - 2009-03-16 00:10 . 2008-04-13 21:04 12063 c:\windows\system32\dllcache\wsiintxx.sys
    + 2009-03-16 00:10 . 2008-04-13 20:04 12063 c:\windows\system32\dllcache\wsiintxx.sys
    - 2009-03-16 00:09 . 2001-08-17 11:12 34890 c:\windows\system32\dllcache\wlandrv2.sys
    + 2009-03-16 00:09 . 2001-08-17 10:12 34890 c:\windows\system32\dllcache\wlandrv2.sys
    + 2009-03-16 00:09 . 2001-08-17 20:36 53760 c:\windows\system32\dllcache\wiamsmud.dll
    - 2009-03-16 00:09 . 2001-08-17 21:36 53760 c:\windows\system32\dllcache\wiamsmud.dll
    - 2009-03-16 00:09 . 2001-08-17 21:36 87040 c:\windows\system32\dllcache\wiafbdrv.dll
    + 2009-03-16 00:09 . 2001-08-17 20:36 87040 c:\windows\system32\dllcache\wiafbdrv.dll
    + 2009-03-16 00:09 . 2008-04-13 20:04 23615 c:\windows\system32\dllcache\wch7xxnt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 23615 c:\windows\system32\dllcache\wch7xxnt.sys
    + 2009-03-16 00:09 . 2008-04-13 22:15 31744 c:\windows\system32\dllcache\wceusbsh.sys
    - 2009-03-16 00:09 . 2008-04-13 23:15 31744 c:\windows\system32\dllcache\wceusbsh.sys
    - 2009-03-16 00:09 . 2001-08-17 11:10 35871 c:\windows\system32\dllcache\wbfirdma.sys
    + 2009-03-16 00:09 . 2001-08-17 10:10 35871 c:\windows\system32\dllcache\wbfirdma.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 25471 c:\windows\system32\dllcache\watv10nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 25471 c:\windows\system32\dllcache\watv10nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 22271 c:\windows\system32\dllcache\watv06nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 22271 c:\windows\system32\dllcache\watv06nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 33599 c:\windows\system32\dllcache\watv04nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 33599 c:\windows\system32\dllcache\watv04nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 19551 c:\windows\system32\dllcache\watv02nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 19551 c:\windows\system32\dllcache\watv02nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 29311 c:\windows\system32\dllcache\watv01nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 29311 c:\windows\system32\dllcache\watv01nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 11935 c:\windows\system32\dllcache\wadv11nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 11935 c:\windows\system32\dllcache\wadv11nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 11871 c:\windows\system32\dllcache\wadv09nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 11871 c:\windows\system32\dllcache\wadv09nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 11295 c:\windows\system32\dllcache\wadv08nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 11295 c:\windows\system32\dllcache\wadv08nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 11807 c:\windows\system32\dllcache\wadv07nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 11807 c:\windows\system32\dllcache\wadv07nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 11775 c:\windows\system32\dllcache\wadv05nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 11775 c:\windows\system32\dllcache\wadv05nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 12127 c:\windows\system32\dllcache\wadv02nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 12127 c:\windows\system32\dllcache\wadv02nt.sys
    + 2009-03-16 00:09 . 2008-04-13 20:04 12415 c:\windows\system32\dllcache\wadv01nt.sys
    - 2009-03-16 00:09 . 2008-04-13 21:04 12415 c:\windows\system32\dllcache\wadv01nt.sys
    + 2009-03-16 00:09 . 2008-04-13 22:13 14208 c:\windows\system32\dllcache\wacompen.sys
    - 2009-03-16 00:09 . 2008-04-13 23:13 14208 c:\windows\system32\dllcache\wacompen.sys
    + 2009-03-16 00:09 . 2001-08-17 10:13 16925 c:\windows\system32\dllcache\w940nd.sys
    - 2009-03-16 00:09 . 2001-08-17 11:13 16925 c:\windows\system32\dllcache\w940nd.sys
    - 2009-03-16 00:09 . 2001-08-17 11:13 19016 c:\windows\system32\dllcache\w926nd.sys
    + 2009-03-16 00:09 . 2001-08-17 10:13 19016 c:\windows\system32\dllcache\w926nd.sys
    - 2009-03-16 00:09 . 2001-08-17 11:13 19528 c:\windows\system32\dllcache\w840nd.sys
    + 2009-03-16 00:09 . 2001-08-17 10:13 19528 c:\windows\system32\dllcache\w840nd.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 64605 c:\windows\system32\dllcache\vvoice.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 64605 c:\windows\system32\dllcache\vvoice.sys
    + 2009-03-16 00:08 . 2001-08-17 11:49 24576 c:\windows\system32\dllcache\viairda.sys
    - 2009-03-16 00:08 . 2001-08-17 12:49 24576 c:\windows\system32\dllcache\viairda.sys
    - 2009-03-16 00:08 . 2008-04-13 23:06 42240 c:\windows\system32\dllcache\viaagp.sys
    + 2009-03-16 00:08 . 2008-04-13 22:06 42240 c:\windows\system32\dllcache\viaagp.sys
    - 2009-03-16 00:08 . 2008-04-14 04:42 11325 c:\windows\system32\dllcache\vchnt5.dll
    + 2009-03-16 00:08 . 2008-04-14 03:42 11325 c:\windows\system32\dllcache\vchnt5.dll
    - 2009-03-16 00:08 . 2008-04-13 23:15 17152 c:\windows\system32\dllcache\usbohci.sys
    + 2009-03-16 00:08 . 2008-04-13 22:15 17152 c:\windows\system32\dllcache\usbohci.sys
    - 2009-03-16 00:08 . 2008-04-13 23:15 60032 c:\windows\system32\dllcache\usbaudio.sys
    + 2009-03-16 00:08 . 2008-04-13 22:15 60032 c:\windows\system32\dllcache\usbaudio.sys
    - 2009-03-16 00:08 . 2008-04-13 23:26 12800 c:\windows\system32\dllcache\usb8023x.sys
    + 2009-03-16 00:08 . 2008-04-13 22:26 12800 c:\windows\system32\dllcache\usb8023x.sys
    + 2009-03-16 00:08 . 2008-04-13 20:05 32384 c:\windows\system32\dllcache\usb101et.sys
    - 2009-03-16 00:08 . 2008-04-13 21:05 32384 c:\windows\system32\dllcache\usb101et.sys
    - 2009-03-16 00:08 . 2001-08-17 21:36 94720 c:\windows\system32\dllcache\umaxud32.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 94720 c:\windows\system32\dllcache\umaxud32.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 28160 c:\windows\system32\dllcache\umaxu40.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 28160 c:\windows\system32\dllcache\umaxu40.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 26624 c:\windows\system32\dllcache\umaxu22.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 26624 c:\windows\system32\dllcache\umaxu22.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 69632 c:\windows\system32\dllcache\umaxu12.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 69632 c:\windows\system32\dllcache\umaxu12.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 50688 c:\windows\system32\dllcache\umaxscan.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 50688 c:\windows\system32\dllcache\umaxscan.dll
    + 2009-03-16 00:08 . 2001-08-17 11:58 22912 c:\windows\system32\dllcache\umaxpcls.sys
    - 2009-03-16 00:08 . 2001-08-17 12:58 22912 c:\windows\system32\dllcache\umaxpcls.sys
    - 2009-03-16 00:08 . 2001-08-17 21:36 50176 c:\windows\system32\dllcache\umaxp60.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 50176 c:\windows\system32\dllcache\umaxp60.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 47616 c:\windows\system32\dllcache\umaxcam.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 47616 c:\windows\system32\dllcache\umaxcam.dll
    - 2009-03-16 00:08 . 2001-08-17 12:52 36736 c:\windows\system32\dllcache\ultra.sys
    + 2009-03-16 00:08 . 2001-08-17 11:52 36736 c:\windows\system32\dllcache\ultra.sys
    - 2009-03-16 00:07 . 2008-04-13 23:06 44672 c:\windows\system32\dllcache\uagp35.sys
    + 2009-03-16 00:07 . 2008-04-13 22:06 44672 c:\windows\system32\dllcache\uagp35.sys
    + 2009-03-16 00:07 . 2001-08-17 11:48 11520 c:\windows\system32\dllcache\twotrack.sys
    - 2009-03-16 00:07 . 2001-08-17 12:48 11520 c:\windows\system32\dllcache\twotrack.sys
    - 2009-03-16 00:07 . 2001-08-17 11:12 34375 c:\windows\system32\dllcache\tpro4.sys
    + 2009-03-16 00:07 . 2001-08-17 10:12 34375 c:\windows\system32\dllcache\tpro4.sys
    - 2009-03-16 00:07 . 2001-08-17 21:35 42496 c:\windows\system32\dllcache\tp4res.dll
    + 2009-03-16 00:07 . 2001-08-17 20:35 42496 c:\windows\system32\dllcache\tp4res.dll
    - 2009-03-16 00:07 . 2008-04-14 04:42 82944 c:\windows\system32\dllcache\tp4mon.exe
    + 2009-03-16 00:07 . 2008-04-14 03:42 82944 c:\windows\system32\dllcache\tp4mon.exe
    - 2009-03-16 00:07 . 2001-08-17 21:36 31744 c:\windows\system32\dllcache\tp4.dll
    + 2009-03-16 00:07 . 2001-08-17 20:36 31744 c:\windows\system32\dllcache\tp4.dll
    + 2009-03-16 00:07 . 2001-08-17 10:10 28232 c:\windows\system32\dllcache\tos4mo.sys
    - 2009-03-16 00:07 . 2001-08-17 11:10 28232 c:\windows\system32\dllcache\tos4mo.sys
    - 2009-03-16 00:07 . 2001-08-17 13:56 81408 c:\windows\system32\dllcache\tgiul50.dll
    + 2009-03-16 00:07 . 2001-08-17 12:56 81408 c:\windows\system32\dllcache\tgiul50.dll
    + 2009-03-16 00:07 . 2001-08-17 10:13 17129 c:\windows\system32\dllcache\tdkcd31.sys
    - 2009-03-16 00:07 . 2001-08-17 11:13 17129 c:\windows\system32\dllcache\tdkcd31.sys
    - 2009-03-16 00:07 . 2001-08-17 11:13 37961 c:\windows\system32\dllcache\tdk100b.sys
    + 2009-03-16 00:07 . 2001-08-17 10:13 37961 c:\windows\system32\dllcache\tdk100b.sys
    - 2009-02-21 23:00 . 2003-03-24 15:52 16384 c:\windows\system32\dllcache\tcptsat.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 16384 c:\windows\system32\dllcache\tcptsat.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 32827 c:\windows\system32\dllcache\tcptest.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 32827 c:\windows\system32\dllcache\tcptest.exe
    + 2009-03-16 00:07 . 2001-08-17 11:49 30464 c:\windows\system32\dllcache\tbatm155.sys
    - 2009-03-16 00:07 . 2001-08-17 12:49 30464 c:\windows\system32\dllcache\tbatm155.sys
    + 2009-03-16 00:07 . 2001-08-17 10:50 36640 c:\windows\system32\dllcache\t2r4mini.sys
    - 2009-03-16 00:07 . 2001-08-17 11:50 36640 c:\windows\system32\dllcache\t2r4mini.sys
    + 2009-03-16 00:07 . 2001-08-17 12:07 32640 c:\windows\system32\dllcache\symc8xx.sys
    - 2009-03-16 00:07 . 2001-08-17 13:07 32640 c:\windows\system32\dllcache\symc8xx.sys
    - 2009-03-16 00:07 . 2001-08-17 13:07 16256 c:\windows\system32\dllcache\symc810.sys
    + 2009-03-16 00:07 . 2001-08-17 12:07 16256 c:\windows\system32\dllcache\symc810.sys
    - 2009-03-16 00:07 . 2001-08-17 13:07 30688 c:\windows\system32\dllcache\sym_u3.sys
    + 2009-03-16 00:07 . 2001-08-17 12:07 30688 c:\windows\system32\dllcache\sym_u3.sys
    - 2009-03-16 00:07 . 2001-08-17 13:07 28384 c:\windows\system32\dllcache\sym_hi.sys
    + 2009-03-16 00:07 . 2001-08-17 12:07 28384 c:\windows\system32\dllcache\sym_hi.sys
    - 2009-03-16 00:07 . 2001-08-17 21:36 94293 c:\windows\system32\dllcache\sxports.dll
    + 2009-03-16 00:07 . 2001-08-17 20:36 94293 c:\windows\system32\dllcache\sxports.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 10240 c:\windows\system32\dllcache\swpidflt.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 10240 c:\windows\system32\dllcache\swpidflt.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 10240 c:\windows\system32\dllcache\swpdflt2.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 10240 c:\windows\system32\dllcache\swpdflt2.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 53760 c:\windows\system32\dllcache\sw_wheel.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 53760 c:\windows\system32\dllcache\sw_wheel.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 41472 c:\windows\system32\dllcache\sw_effct.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 41472 c:\windows\system32\dllcache\sw_effct.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 53248 c:\windows\system32\dllcache\stlncoin.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 53248 c:\windows\system32\dllcache\stlncoin.dll
    + 2009-03-16 00:06 . 2001-08-17 11:51 16896 c:\windows\system32\dllcache\stcusb.sys
    - 2009-03-16 00:06 . 2001-08-17 12:51 16896 c:\windows\system32\dllcache\stcusb.sys
    + 2009-03-16 00:06 . 2001-08-17 10:11 48736 c:\windows\system32\dllcache\srwlnd5.sys
    - 2009-03-16 00:06 . 2001-08-17 11:11 48736 c:\windows\system32\dllcache\srwlnd5.sys
    - 2009-03-16 00:06 . 2001-08-17 21:36 99328 c:\windows\system32\dllcache\srusd.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 99328 c:\windows\system32\dllcache\srusd.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 24660 c:\windows\system32\dllcache\spxupchk.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 24660 c:\windows\system32\dllcache\spxupchk.dll
    - 2009-03-16 00:06 . 2001-08-17 12:51 61824 c:\windows\system32\dllcache\speed.sys
    + 2009-03-16 00:06 . 2001-08-17 11:51 61824 c:\windows\system32\dllcache\speed.sys
    - 2009-03-16 00:06 . 2001-08-17 13:07 19072 c:\windows\system32\dllcache\sparrow.sys
    + 2009-03-16 00:06 . 2001-08-17 12:07 19072 c:\windows\system32\dllcache\sparrow.sys
    - 2009-03-16 00:06 . 2001-08-17 11:51 37040 c:\windows\system32\dllcache\sonypi.sys
    + 2009-03-16 00:06 . 2001-08-17 10:51 37040 c:\windows\system32\dllcache\sonypi.sys
    + 2009-03-16 00:06 . 2001-08-17 10:51 20752 c:\windows\system32\dllcache\sonync.sys
    - 2009-03-16 00:06 . 2001-08-17 11:51 20752 c:\windows\system32\dllcache\sonync.sys
    + 2009-03-16 00:05 . 2001-08-17 10:51 58368 c:\windows\system32\dllcache\smiminib.sys
    - 2009-03-16 00:05 . 2001-08-17 11:51 58368 c:\windows\system32\dllcache\smiminib.sys
    + 2009-03-16 00:05 . 2001-08-17 10:12 25034 c:\windows\system32\dllcache\smcpwr2n.sys
    - 2009-03-16 00:05 . 2001-08-17 11:12 25034 c:\windows\system32\dllcache\smcpwr2n.sys
    + 2009-03-16 00:05 . 2001-08-17 10:10 35913 c:\windows\system32\dllcache\smcirda.sys
    - 2009-03-16 00:05 . 2001-08-17 11:10 35913 c:\windows\system32\dllcache\smcirda.sys
    + 2009-03-16 00:05 . 2001-08-17 10:12 24576 c:\windows\system32\dllcache\smc8000n.sys
    - 2009-03-16 00:05 . 2001-08-17 11:12 24576 c:\windows\system32\dllcache\smc8000n.sys
    + 2009-03-16 00:05 . 2008-04-13 22:06 16000 c:\windows\system32\dllcache\smbbatt.sys
    - 2009-03-16 00:05 . 2008-04-13 23:06 16000 c:\windows\system32\dllcache\smbbatt.sys
    - 2009-03-16 00:05 . 2001-08-17 21:36 45568 c:\windows\system32\dllcache\smb3w.dll
    + 2009-03-16 00:05 . 2001-08-17 20:36 45568 c:\windows\system32\dllcache\smb3w.dll
    + 2009-03-16 00:05 . 2001-08-17 20:36 33792 c:\windows\system32\dllcache\smb0w.dll
    - 2009-03-16 00:05 . 2001-08-17 21:36 33792 c:\windows\system32\dllcache\smb0w.dll
    - 2009-03-16 00:05 . 2001-08-17 21:36 28672 c:\windows\system32\dllcache\sma0w.dll
    + 2009-03-16 00:05 . 2001-08-17 20:36 28672 c:\windows\system32\dllcache\sma0w.dll
    - 2009-03-16 00:05 . 2001-08-17 21:36 28160 c:\windows\system32\dllcache\sm91w.dll
    + 2009-03-16 00:05 . 2001-08-17 20:36 28160 c:\windows\system32\dllcache\sm91w.dll
    - 2009-03-16 00:05 . 2008-04-13 22:53 13240 c:\windows\system32\dllcache\slwdmsup.sys
    + 2009-03-16 00:05 . 2008-04-13 21:53 13240 c:\windows\system32\dllcache\slwdmsup.sys
    - 2009-03-16 00:05 . 2008-04-14 04:42 73796 c:\windows\system32\dllcache\slserv.exe
    + 2009-03-16 00:05 . 2008-04-14 03:42 73796 c:\windows\system32\dllcache\slserv.exe
    - 2009-03-16 00:05 . 2008-04-14 04:42 32866 c:\windows\system32\dllcache\slrundll.exe
    + 2009-03-16 00:05 . 2008-04-14 03:42 32866 c:\windows\system32\dllcache\slrundll.exe
    - 2009-03-16 00:05 . 2008-04-13 22:53 95424 c:\windows\system32\dllcache\slnthal.sys
    + 2009-03-16 00:05 . 2008-04-13 21:53 95424 c:\windows\system32\dllcache\slnthal.sys
    - 2009-03-16 00:05 . 2008-04-14 04:42 73832 c:\windows\system32\dllcache\slcoinst.dll
    + 2009-03-16 00:05 . 2008-04-14 03:42 73832 c:\windows\system32\dllcache\slcoinst.dll
    - 2009-03-16 00:05 . 2008-04-13 21:05 63547 c:\windows\system32\dllcache\sla30nd5.sys
    + 2009-03-16 00:05 . 2008-04-13 20:05 63547 c:\windows\system32\dllcache\sla30nd5.sys
    + 2009-03-16 00:05 . 2001-08-17 10:12 91294 c:\windows\system32\dllcache\skfpwin.sys
    - 2009-03-16 00:05 . 2001-08-17 11:12 91294 c:\windows\system32\dllcache\skfpwin.sys
    + 2009-03-16 00:05 . 2001-08-17 10:12 94698 c:\windows\system32\dllcache\sk98xwin.sys
    - 2009-03-16 00:05 . 2001-08-17 11:12 94698 c:\windows\system32\dllcache\sk98xwin.sys
    - 2009-03-16 00:05 . 2001-08-17 11:50 50432 c:\windows\system32\dllcache\sisv.sys
    + 2009-03-16 00:05 . 2001-08-17 10:50 50432 c:\windows\system32\dllcache\sisv.sys
    - 2009-03-16 00:05 . 2008-04-13 21:05 32768 c:\windows\system32\dllcache\sisnic.sys
    + 2009-03-16 00:05 . 2008-04-13 20:05 32768 c:\windows\system32\dllcache\sisnic.sys
    - 2009-03-16 00:05 . 2008-04-13 23:06 40960 c:\windows\system32\dllcache\sisagp.sys
    + 2009-03-16 00:05 . 2008-04-13 22:06 40960 c:\windows\system32\dllcache\sisagp.sys
    + 2009-03-16 00:05 . 2001-08-17 10:50 68608 c:\windows\system32\dllcache\sis6306p.sys
    - 2009-03-16 00:05 . 2001-08-17 11:50 68608 c:\windows\system32\dllcache\sis6306p.sys
    + 2009-02-21 23:00 . 2003-03-24 14:52 16437 c:\windows\system32\dllcache\shtml.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 16437 c:\windows\system32\dllcache\shtml.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 20536 c:\windows\system32\dllcache\shtml.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 20536 c:\windows\system32\dllcache\shtml.dll
    + 2009-03-16 00:04 . 2001-07-21 12:29 18400 c:\windows\system32\dllcache\sgsmld.sys
    - 2009-03-16 00:04 . 2001-07-21 13:29 18400 c:\windows\system32\dllcache\sgsmld.sys
    + 2009-03-16 00:04 . 2001-08-17 10:51 98080 c:\windows\system32\dllcache\sgiulnt5.sys
    - 2009-03-16 00:04 . 2001-08-17 11:51 98080 c:\windows\system32\dllcache\sgiulnt5.sys
    + 2009-03-16 00:04 . 2001-08-17 10:19 36480 c:\windows\system32\dllcache\sfmanm.sys
    - 2009-03-16 00:04 . 2001-08-17 11:19 36480 c:\windows\system32\dllcache\sfmanm.sys
    - 2009-03-16 00:04 . 2001-08-17 12:48 17664 c:\windows\system32\dllcache\sermouse.sys
    + 2009-03-16 00:04 . 2001-08-17 11:48 17664 c:\windows\system32\dllcache\sermouse.sys
    - 2009-03-16 00:04 . 2008-04-13 23:15 11520 c:\windows\system32\dllcache\scsiscan.sys
    + 2009-03-16 00:04 . 2008-04-13 22:15 11520 c:\windows\system32\dllcache\scsiscan.sys
    - 2009-03-16 00:04 . 2001-08-17 12:52 11648 c:\windows\system32\dllcache\scsiprnt.sys
    + 2009-03-16 00:04 . 2001-08-17 11:52 11648 c:\windows\system32\dllcache\scsiprnt.sys
    + 2009-03-16 00:04 . 2001-08-17 11:51 17280 c:\windows\system32\dllcache\scr111.sys
    - 2009-03-16 00:04 . 2001-08-17 12:51 17280 c:\windows\system32\dllcache\scr111.sys
    + 2009-03-16 00:04 . 2001-08-17 11:51 16640 c:\windows\system32\dllcache\scmstcs.sys
    - 2009-03-16 00:04 . 2001-08-17 12:51 16640 c:\windows\system32\dllcache\scmstcs.sys
    - 2009-03-16 00:04 . 2001-08-17 12:51 23936 c:\windows\system32\dllcache\sccmusbm.sys
    + 2009-03-16 00:04 . 2001-08-17 11:51 23936 c:\windows\system32\dllcache\sccmusbm.sys
    + 2009-03-16 00:04 . 2001-08-17 11:51 23936 c:\windows\system32\dllcache\sccmn50m.sys
    - 2009-03-16 00:04 . 2001-08-17 12:51 23936 c:\windows\system32\dllcache\sccmn50m.sys
    + 2009-03-16 00:04 . 2008-04-13 22:10 43904 c:\windows\system32\dllcache\sbp2port.sys
    - 2009-03-16 00:04 . 2008-04-13 23:10 43904 c:\windows\system32\dllcache\sbp2port.sys
    + 2009-03-16 00:04 . 2001-08-17 10:50 75392 c:\windows\system32\dllcache\s3savmxm.sys
    - 2009-03-16 00:04 . 2001-08-17 11:50 75392 c:\windows\system32\dllcache\s3savmxm.sys
    - 2009-03-16 00:04 . 2001-08-17 11:50 77824 c:\windows\system32\dllcache\s3sav4m.sys
    + 2009-03-16 00:04 . 2001-08-17 10:50 77824 c:\windows\system32\dllcache\s3sav4m.sys
    + 2009-03-16 00:04 . 2001-08-17 10:50 61504 c:\windows\system32\dllcache\s3sav3dm.sys
    - 2009-03-16 00:04 . 2001-08-17 11:50 61504 c:\windows\system32\dllcache\s3sav3dm.sys
    + 2009-03-16 00:04 . 2001-08-17 20:36 62496 c:\windows\system32\dllcache\s3mtrio.dll
    - 2009-03-16 00:04 . 2001-08-17 21:36 62496 c:\windows\system32\dllcache\s3mtrio.dll
    + 2009-03-16 00:04 . 2001-08-17 10:50 41216 c:\windows\system32\dllcache\s3mt3d.sys
    - 2009-03-16 00:04 . 2001-08-17 11:50 41216 c:\windows\system32\dllcache\s3mt3d.sys
    - 2009-03-16 00:04 . 2001-08-17 12:57 65664 c:\windows\system32\dllcache\s3legacy.sys
    + 2009-03-16 00:04 . 2001-08-17 11:57 65664 c:\windows\system32\dllcache\s3legacy.sys
    - 2009-03-15 23:45 . 2001-08-17 13:56 66048 c:\windows\system32\dllcache\s3legacy.dll
    + 2009-03-15 23:45 . 2001-08-17 12:56 66048 c:\windows\system32\dllcache\s3legacy.dll
    - 2009-03-16 00:04 . 2001-08-17 21:36 82432 c:\windows\system32\dllcache\rwia450.dll
    + 2009-03-16 00:04 . 2001-08-17 20:36 82432 c:\windows\system32\dllcache\rwia450.dll
    - 2009-03-16 00:04 . 2001-08-17 21:36 79872 c:\windows\system32\dllcache\rwia430.dll
    + 2009-03-16 00:04 . 2001-08-17 20:36 79872 c:\windows\system32\dllcache\rwia430.dll
    + 2009-03-16 00:04 . 2008-04-14 03:42 29696 c:\windows\system32\dllcache\rw450ext.dll
    - 2009-03-16 00:04 . 2008-04-14 04:42 29696 c:\windows\system32\dllcache\rw450ext.dll
    + 2009-03-16 00:04 . 2008-04-14 03:42 27648 c:\windows\system32\dllcache\rw430ext.dll
    - 2009-03-16 00:04 . 2008-04-14 04:42 27648 c:\windows\system32\dllcache\rw430ext.dll
    - 2009-03-16 00:04 . 2008-04-13 21:05 20992 c:\windows\system32\dllcache\rtl8139.sys
    + 2009-03-16 00:04 . 2008-04-13 20:05 20992 c:\windows\system32\dllcache\rtl8139.sys
    - 2009-03-16 00:04 . 2001-08-17 11:12 19017 c:\windows\system32\dllcache\rtl8029.sys
    + 2009-03-16 00:04 . 2001-08-17 10:12 19017 c:\windows\system32\dllcache\rtl8029.sys
    - 2009-03-16 00:04 . 2001-08-17 11:19 30720 c:\windows\system32\dllcache\rthwcls.sys
    + 2009-03-16 00:04 . 2001-08-17 10:19 30720 c:\windows\system32\dllcache\rthwcls.sys
    + 2009-03-16 00:03 . 2008-04-13 22:10 79104 c:\windows\system32\dllcache\rocket.sys
    - 2009-03-16 00:03 . 2008-04-13 23:10 79104 c:\windows\system32\dllcache\rocket.sys
    + 2009-03-16 00:03 . 2008-04-13 22:26 30592 c:\windows\system32\dllcache\rndismpx.sys
    - 2009-03-16 00:03 . 2008-04-13 23:26 30592 c:\windows\system32\dllcache\rndismpx.sys
    - 2009-03-16 00:03 . 2001-08-17 11:12 37563 c:\windows\system32\dllcache\rlnet5.sys
    + 2009-03-16 00:03 . 2001-08-17 10:12 37563 c:\windows\system32\dllcache\rlnet5.sys
    - 2009-03-16 00:03 . 2001-08-17 21:36 86097 c:\windows\system32\dllcache\reslog32.dll
    + 2009-03-16 00:03 . 2001-08-17 20:36 86097 c:\windows\system32\dllcache\reslog32.dll
    - 2009-03-16 00:03 . 2008-04-13 22:53 13776 c:\windows\system32\dllcache\recagent.sys
    + 2009-03-16 00:03 . 2008-04-13 21:53 13776 c:\windows\system32\dllcache\recagent.sys
    + 2009-03-16 00:03 . 2001-08-17 11:51 19584 c:\windows\system32\dllcache\rasirda.sys
    - 2009-03-16 00:03 . 2001-08-17 12:51 19584 c:\windows\system32\dllcache\rasirda.sys
    - 2009-03-16 00:03 . 2001-08-17 21:36 41472 c:\windows\system32\dllcache\qvusd.dll
    + 2009-03-16 00:03 . 2001-08-17 20:36 41472 c:\windows\system32\dllcache\qvusd.dll
    - 2009-03-16 00:03 . 2001-08-17 12:52 49024 c:\windows\system32\dllcache\ql1280.sys
    + 2009-03-16 00:03 . 2001-08-17 11:52 49024 c:\windows\system32\dllcache\ql1280.sys
    - 2009-03-16 00:03 . 2001-08-17 12:52 40448 c:\windows\system32\dllcache\ql1240.sys
    + 2009-03-16 00:03 . 2001-08-17 11:52 40448 c:\windows\system32\dllcache\ql1240.sys
    - 2009-03-16 00:03 . 2001-08-17 12:52 45312 c:\windows\system32\dllcache\ql12160.sys
    + 2009-03-16 00:03 . 2001-08-17 11:52 45312 c:\windows\system32\dllcache\ql12160.sys
    - 2009-03-16 00:03 . 2001-08-17 12:52 33152 c:\windows\system32\dllcache\ql10wnt.sys
    + 2009-03-16 00:03 . 2001-08-17 11:52 33152 c:\windows\system32\dllcache\ql10wnt.sys
    + 2009-03-16 00:03 . 2001-08-17 11:52 40320 c:\windows\system32\dllcache\ql1080.sys
    - 2009-03-16 00:03 . 2001-08-17 12:52 40320 c:\windows\system32\dllcache\ql1080.sys
    + 2009-03-16 00:03 . 2001-08-17 20:36 35328 c:\windows\system32\dllcache\psisload.dll
    - 2009-03-16 00:03 . 2001-08-17 21:36 35328 c:\windows\system32\dllcache\psisload.dll
    - 2009-03-16 00:03 . 2001-08-17 12:51 16128 c:\windows\system32\dllcache\pscr.sys
    + 2009-03-16 00:03 . 2001-08-17 11:51 16128 c:\windows\system32\dllcache\pscr.sys
    - 2009-03-16 00:02 . 2008-04-13 23:11 17664 c:\windows\system32\dllcache\ppa3.sys
    + 2009-03-16 00:02 . 2008-04-13 22:11 17664 c:\windows\system32\dllcache\ppa3.sys
    - 2009-03-16 00:02 . 2001-08-17 12:53 17792 c:\windows\system32\dllcache\ppa.sys
    + 2009-03-16 00:02 . 2001-08-17 11:53 17792 c:\windows\system32\dllcache\ppa.sys
    - 2009-03-16 00:02 . 2001-08-17 13:07 19840 c:\windows\system32\dllcache\philtune.sys
    + 2009-03-16 00:02 . 2001-08-17 12:07 19840 c:\windows\system32\dllcache\philtune.sys
    + 2009-03-16 00:02 . 2001-08-17 12:04 92416 c:\windows\system32\dllcache\phildec.sys
    - 2009-03-16 00:02 . 2001-08-17 13:04 92416 c:\windows\system32\dllcache\phildec.sys
    - 2009-03-16 00:02 . 2001-08-17 13:04 75776 c:\windows\system32\dllcache\philcam1.sys
    + 2009-03-16 00:02 . 2001-08-17 12:04 75776 c:\windows\system32\dllcache\philcam1.sys
    + 2009-03-16 00:02 . 2001-08-17 20:36 16384 c:\windows\system32\dllcache\philcam1.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 16384 c:\windows\system32\dllcache\philcam1.dll
    - 2009-03-16 00:02 . 2008-04-13 23:14 28032 c:\windows\system32\dllcache\perm3.sys
    + 2009-03-16 00:02 . 2008-04-13 22:14 28032 c:\windows\system32\dllcache\perm3.sys
    + 2009-03-16 00:02 . 2008-04-13 22:14 27904 c:\windows\system32\dllcache\perm2.sys
    - 2009-03-16 00:02 . 2008-04-13 23:14 27904 c:\windows\system32\dllcache\perm2.sys
    - 2009-03-16 00:02 . 2001-08-17 13:07 27296 c:\windows\system32\dllcache\perc2.sys
    + 2009-03-16 00:02 . 2001-08-17 12:07 27296 c:\windows\system32\dllcache\perc2.sys
    - 2009-03-16 00:02 . 2001-08-17 21:36 86016 c:\windows\system32\dllcache\pctspk.exe
    + 2009-03-16 00:02 . 2001-08-17 20:36 86016 c:\windows\system32\dllcache\pctspk.exe
    + 2009-03-16 00:02 . 2001-08-17 10:11 35328 c:\windows\system32\dllcache\pcntpci5.sys
    - 2009-03-16 00:02 . 2001-08-17 11:11 35328 c:\windows\system32\dllcache\pcntpci5.sys
    + 2009-03-16 00:02 . 2001-08-17 10:11 29769 c:\windows\system32\dllcache\pcntn5m.sys
    - 2009-03-16 00:02 . 2001-08-17 11:11 29769 c:\windows\system32\dllcache\pcntn5m.sys
    + 2009-03-16 00:02 . 2001-08-17 10:11 30282 c:\windows\system32\dllcache\pcntn5hl.sys
    - 2009-03-16 00:02 . 2001-08-17 11:11 30282 c:\windows\system32\dllcache\pcntn5hl.sys
    + 2009-03-16 00:02 . 2001-08-17 10:12 26153 c:\windows\system32\dllcache\pcmlm56.sys
    - 2009-03-16 00:02 . 2001-08-17 11:12 26153 c:\windows\system32\dllcache\pcmlm56.sys
    + 2009-03-16 00:02 . 2008-04-13 20:05 29502 c:\windows\system32\dllcache\pca200e.sys
    - 2009-03-16 00:02 . 2008-04-13 21:05 29502 c:\windows\system32\dllcache\pca200e.sys
    + 2009-03-16 00:02 . 2001-08-17 10:12 30495 c:\windows\system32\dllcache\pc100nds.sys
    - 2009-03-16 00:02 . 2001-08-17 11:12 30495 c:\windows\system32\dllcache\pc100nds.sys
    + 2009-03-16 00:02 . 2001-08-17 20:36 41984 c:\windows\system32\dllcache\ovui2rc.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 41984 c:\windows\system32\dllcache\ovui2rc.dll
    + 2009-03-16 00:02 . 2001-08-17 20:36 44544 c:\windows\system32\dllcache\ovui2.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 44544 c:\windows\system32\dllcache\ovui2.dll
    - 2009-03-16 00:02 . 2001-08-17 13:05 25216 c:\windows\system32\dllcache\ovsound2.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 25216 c:\windows\system32\dllcache\ovsound2.sys
    + 2009-03-16 00:02 . 2001-08-17 20:36 39424 c:\windows\system32\dllcache\ovcoms.exe
    - 2009-03-16 00:02 . 2001-08-17 21:36 39424 c:\windows\system32\dllcache\ovcoms.exe
    + 2009-03-16 00:02 . 2001-08-17 20:36 20480 c:\windows\system32\dllcache\ovcomc.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 20480 c:\windows\system32\dllcache\ovcomc.dll
    - 2009-03-16 00:02 . 2001-08-17 13:05 31872 c:\windows\system32\dllcache\ovce.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 31872 c:\windows\system32\dllcache\ovce.sys
    - 2009-03-16 00:02 . 2001-08-17 13:05 28032 c:\windows\system32\dllcache\ovcd.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 28032 c:\windows\system32\dllcache\ovcd.sys
    - 2009-03-16 00:02 . 2001-08-17 13:05 48000 c:\windows\system32\dllcache\ovcam2.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 48000 c:\windows\system32\dllcache\ovcam2.sys
    - 2009-03-16 00:02 . 2001-08-17 13:05 25088 c:\windows\system32\dllcache\ovca.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 25088 c:\windows\system32\dllcache\ovca.sys
    - 2009-03-16 00:02 . 2001-08-17 12:28 54186 c:\windows\system32\dllcache\otcsercb.sys
    + 2009-03-16 00:02 . 2001-08-17 11:28 54186 c:\windows\system32\dllcache\otcsercb.sys
    + 2009-03-16 00:02 . 2001-08-17 10:12 43689 c:\windows\system32\dllcache\otceth5.sys
    - 2009-03-16 00:02 . 2001-08-17 11:12 43689 c:\windows\system32\dllcache\otceth5.sys
    - 2009-03-16 00:02 . 2001-08-17 11:12 27209 c:\windows\system32\dllcache\otc06x5.sys
    + 2009-03-16 00:02 . 2001-08-17 10:12 27209 c:\windows\system32\dllcache\otc06x5.sys
    + 2009-03-16 00:01 . 2001-08-17 10:20 54528 c:\windows\system32\dllcache\opl3sax.sys
    - 2009-03-16 00:01 . 2001-08-17 11:20 54528 c:\windows\system32\dllcache\opl3sax.sys
    + 2009-03-16 00:01 . 2001-08-17 10:49 51552 c:\windows\system32\dllcache\ntgrip.sys
    - 2009-03-16 00:01 . 2001-08-17 11:49 51552 c:\windows\system32\dllcache\ntgrip.sys
    - 2009-03-16 00:01 . 2008-04-13 23:24 28672 c:\windows\system32\dllcache\nscirda.sys
    + 2009-03-16 00:01 . 2008-04-13 22:24 28672 c:\windows\system32\dllcache\nscirda.sys
    + 2009-03-16 00:01 . 2001-08-17 10:20 87040 c:\windows\system32\dllcache\nm6wdm.sys
    - 2009-03-16 00:01 . 2001-08-17 11:20 87040 c:\windows\system32\dllcache\nm6wdm.sys
    + 2009-03-16 00:01 . 2001-08-17 10:12 32840 c:\windows\system32\dllcache\ngrpci.sys
    - 2009-03-16 00:01 . 2001-08-17 11:12 32840 c:\windows\system32\dllcache\ngrpci.sys
    + 2009-03-16 00:01 . 2001-08-17 10:11 65278 c:\windows\system32\dllcache\netflx3.sys
    - 2009-03-16 00:01 . 2001-08-17 11:11 65278 c:\windows\system32\dllcache\netflx3.sys
    + 2009-03-16 00:01 . 2001-08-17 10:50 39264 c:\windows\system32\dllcache\neo20xx.sys
    - 2009-03-16 00:01 . 2001-08-17 11:50 39264 c:\windows\system32\dllcache\neo20xx.sys
    - 2009-03-16 00:01 . 2001-08-17 21:36 60480 c:\windows\system32\dllcache\neo20xx.dll
    + 2009-03-16 00:01 . 2001-08-17 20:36 60480 c:\windows\system32\dllcache\neo20xx.dll
    - 2009-03-16 00:01 . 2001-08-17 12:49 15872 c:\windows\system32\dllcache\ne2000.sys
    + 2009-03-16 00:01 . 2001-08-17 11:49 15872 c:\windows\system32\dllcache\ne2000.sys
    - 2009-03-16 00:01 . 2001-08-17 13:56 91488 c:\windows\system32\dllcache\n9i3disp.dll
    + 2009-03-16 00:01 . 2001-08-17 12:56 91488 c:\windows\system32\dllcache\n9i3disp.dll
    + 2009-03-16 00:01 . 2001-08-17 10:50 27936 c:\windows\system32\dllcache\n9i3d.sys
    - 2009-03-16 00:01 . 2001-08-17 11:50 27936 c:\windows\system32\dllcache\n9i3d.sys
    - 2009-03-16 00:01 . 2001-08-17 11:50 33088 c:\windows\system32\dllcache\n9i128v2.sys
    + 2009-03-16 00:01 . 2001-08-17 10:50 33088 c:\windows\system32\dllcache\n9i128v2.sys
    - 2009-03-16 00:01 . 2001-08-17 21:36 59104 c:\windows\system32\dllcache\n9i128v2.dll
    + 2009-03-16 00:01 . 2001-08-17 20:36 59104 c:\windows\system32\dllcache\n9i128v2.dll
    - 2009-03-16 00:01 . 2001-08-17 11:50 13664 c:\windows\system32\dllcache\n9i128.sys
    + 2009-03-16 00:01 . 2001-08-17 10:50 13664 c:\windows\system32\dllcache\n9i128.sys
    - 2009-03-16 00:01 . 2001-08-17 13:56 35392 c:\windows\system32\dllcache\n9i128.dll
    + 2009-03-16 00:01 . 2001-08-17 12:56 35392 c:\windows\system32\dllcache\n9i128.dll
    + 2009-03-16 00:01 . 2001-08-17 10:11 52255 c:\windows\system32\dllcache\n1000nt5.sys
    - 2009-03-16 00:01 . 2001-08-17 11:11 52255 c:\windows\system32\dllcache\n1000nt5.sys
    + 2009-03-16 00:01 . 2001-08-17 11:50 75520 c:\windows\system32\dllcache\mxport.sys
    - 2009-03-16 00:01 . 2001-08-17 12:50 75520 c:\windows\system32\dllcache\mxport.sys
    + 2009-03-16 00:00 . 2001-08-17 11:49 19968 c:\windows\system32\dllcache\mxnic.sys
    - 2009-03-16 00:00 . 2001-08-17 12:49 19968 c:\windows\system32\dllcache\mxnic.sys
     
  10. 2010/08/11
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    + 2009-03-16 00:00 . 2001-08-17 20:36 19968 c:\windows\system32\dllcache\mxicfg.dll
    - 2009-03-16 00:00 . 2001-08-17 21:36 19968 c:\windows\system32\dllcache\mxicfg.dll
    + 2009-03-16 00:00 . 2001-08-17 11:50 21888 c:\windows\system32\dllcache\mxcard.sys
    - 2009-03-16 00:00 . 2001-08-17 12:50 21888 c:\windows\system32\dllcache\mxcard.sys
    + 2009-03-16 00:00 . 2008-04-13 22:13 12672 c:\windows\system32\dllcache\mutohpen.sys
    - 2009-03-16 00:00 . 2008-04-13 23:13 12672 c:\windows\system32\dllcache\mutohpen.sys
    - 2009-03-16 00:00 . 2008-04-13 23:16 49024 c:\windows\system32\dllcache\mstape.sys
    + 2009-03-16 00:00 . 2008-04-13 22:16 49024 c:\windows\system32\dllcache\mstape.sys
    + 2009-03-16 00:00 . 2001-08-17 11:48 12416 c:\windows\system32\dllcache\msriffwv.sys
    - 2009-03-16 00:00 . 2001-08-17 12:48 12416 c:\windows\system32\dllcache\msriffwv.sys
    - 2009-03-16 00:00 . 2008-04-13 23:24 22016 c:\windows\system32\dllcache\msircomm.sys
    + 2009-03-16 00:00 . 2008-04-13 22:24 22016 c:\windows\system32\dllcache\msircomm.sys
    + 2009-03-16 00:00 . 2001-08-17 12:02 35200 c:\windows\system32\dllcache\msgame.sys
    - 2009-03-16 00:00 . 2001-08-17 13:02 35200 c:\windows\system32\dllcache\msgame.sys
    + 2009-03-16 00:00 . 2001-08-17 11:52 17280 c:\windows\system32\dllcache\mraid35x.sys
    - 2009-03-16 00:00 . 2001-08-17 12:52 17280 c:\windows\system32\dllcache\mraid35x.sys
    + 2009-03-15 23:59 . 2008-04-13 22:16 15232 c:\windows\system32\dllcache\mpe.sys
    - 2009-03-15 23:59 . 2008-04-13 23:16 15232 c:\windows\system32\dllcache\mpe.sys
    + 2009-03-15 23:59 . 2008-04-13 22:11 26112 c:\windows\system32\dllcache\memstpci.sys
    - 2009-03-15 23:59 . 2008-04-13 23:11 26112 c:\windows\system32\dllcache\memstpci.sys
    + 2009-03-15 23:59 . 2001-08-17 20:36 47616 c:\windows\system32\dllcache\memgrp.dll
    - 2009-03-15 23:59 . 2001-08-17 21:36 47616 c:\windows\system32\dllcache\memgrp.dll
    - 2009-03-15 23:59 . 2001-08-17 11:19 48768 c:\windows\system32\dllcache\maestro.sys
    + 2009-03-15 23:59 . 2001-08-17 10:19 48768 c:\windows\system32\dllcache\maestro.sys
    - 2009-03-15 23:59 . 2001-08-17 21:36 58880 c:\windows\system32\dllcache\m3092dc.dll
    + 2009-03-15 23:59 . 2001-08-17 20:36 58880 c:\windows\system32\dllcache\m3092dc.dll
    - 2009-03-15 23:59 . 2001-08-17 21:36 58368 c:\windows\system32\dllcache\m3091dc.dll
    + 2009-03-15 23:59 . 2001-08-17 20:36 58368 c:\windows\system32\dllcache\m3091dc.dll
    + 2009-03-15 23:59 . 2001-08-17 10:49 22848 c:\windows\system32\dllcache\lwusbhid.sys
    - 2009-03-15 23:59 . 2001-08-17 11:49 22848 c:\windows\system32\dllcache\lwusbhid.sys
    - 2009-03-15 23:59 . 2008-04-13 21:09 20864 c:\windows\system32\dllcache\lwadihid.sys
    + 2009-03-15 23:59 . 2008-04-13 20:09 20864 c:\windows\system32\dllcache\lwadihid.sys
    + 2009-03-15 23:59 . 2001-08-17 10:12 70730 c:\windows\system32\dllcache\lne100tx.sys
    - 2009-03-15 23:59 . 2001-08-17 11:12 70730 c:\windows\system32\dllcache\lne100tx.sys
    - 2009-03-15 23:59 . 2001-08-17 11:12 20573 c:\windows\system32\dllcache\lne100.sys
    + 2009-03-15 23:59 . 2001-08-17 10:12 20573 c:\windows\system32\dllcache\lne100.sys
    + 2009-03-15 23:59 . 2001-08-17 10:11 25065 c:\windows\system32\dllcache\lmndis3.sys
    - 2009-03-15 23:59 . 2001-08-17 11:11 25065 c:\windows\system32\dllcache\lmndis3.sys
    + 2009-03-15 23:59 . 2001-08-17 11:51 15744 c:\windows\system32\dllcache\lit220p.sys
    - 2009-03-15 23:59 . 2001-08-17 12:51 15744 c:\windows\system32\dllcache\lit220p.sys
    + 2009-03-15 23:58 . 2008-04-13 22:10 34688 c:\windows\system32\dllcache\lbrtfdc.sys
    - 2009-03-15 23:58 . 2008-04-13 23:10 34688 c:\windows\system32\dllcache\lbrtfdc.sys
    - 2009-03-15 23:58 . 2001-08-17 11:12 26442 c:\windows\system32\dllcache\lanepic5.sys
    + 2009-03-15 23:58 . 2001-08-17 10:12 26442 c:\windows\system32\dllcache\lanepic5.sys
    + 2009-03-15 23:58 . 2001-08-17 10:12 19016 c:\windows\system32\dllcache\ktc111.sys
    - 2009-03-15 23:58 . 2001-08-17 11:12 19016 c:\windows\system32\dllcache\ktc111.sys
    + 2009-03-15 23:58 . 2001-08-17 20:36 37376 c:\windows\system32\dllcache\kousd.dll
    - 2009-03-15 23:58 . 2001-08-17 21:36 37376 c:\windows\system32\dllcache\kousd.dll
    - 2009-03-15 23:58 . 2008-04-14 04:41 48640 c:\windows\system32\dllcache\kdsui.dll
    + 2009-03-15 23:58 . 2008-04-14 03:41 48640 c:\windows\system32\dllcache\kdsui.dll
    + 2009-03-15 23:57 . 2001-08-17 11:49 26624 c:\windows\system32\dllcache\irstusb.sys
    - 2009-03-15 23:57 . 2001-08-17 12:49 26624 c:\windows\system32\dllcache\irstusb.sys
    - 2009-03-15 23:57 . 2001-08-17 12:51 18688 c:\windows\system32\dllcache\irsir.sys
    + 2009-03-15 23:57 . 2001-08-17 11:51 18688 c:\windows\system32\dllcache\irsir.sys
    + 2009-03-15 23:57 . 2001-08-17 11:49 23552 c:\windows\system32\dllcache\irmk7.sys
    - 2009-03-15 23:57 . 2001-08-17 12:49 23552 c:\windows\system32\dllcache\irmk7.sys
    + 2009-03-15 23:57 . 2008-04-13 22:24 88192 c:\windows\system32\dllcache\irda.sys
    - 2009-03-15 23:57 . 2008-04-13 23:24 88192 c:\windows\system32\dllcache\irda.sys
    - 2009-03-15 23:57 . 2008-04-13 23:15 46592 c:\windows\system32\dllcache\irbus.sys
    + 2009-03-15 23:57 . 2008-04-13 22:15 46592 c:\windows\system32\dllcache\irbus.sys
    - 2009-03-15 23:57 . 2001-08-17 11:12 45632 c:\windows\system32\dllcache\ip5515.sys
    + 2009-03-15 23:57 . 2001-08-17 10:12 45632 c:\windows\system32\dllcache\ip5515.sys
    - 2009-03-15 23:57 . 2001-08-17 21:36 90200 c:\windows\system32\dllcache\io8ports.dll
    + 2009-03-15 23:57 . 2001-08-17 20:36 90200 c:\windows\system32\dllcache\io8ports.dll
    - 2009-03-15 23:57 . 2001-08-17 12:50 38784 c:\windows\system32\dllcache\io8.sys
    + 2009-03-15 23:57 . 2001-08-17 11:50 38784 c:\windows\system32\dllcache\io8.sys
    + 2009-03-15 23:57 . 2001-08-17 11:47 13056 c:\windows\system32\dllcache\inport.sys
    - 2009-03-15 23:57 . 2001-08-17 12:47 13056 c:\windows\system32\dllcache\inport.sys
    - 2009-03-15 23:57 . 2001-08-17 12:52 16000 c:\windows\system32\dllcache\ini910u.sys
    + 2009-03-15 23:57 . 2001-08-17 11:52 16000 c:\windows\system32\dllcache\ini910u.sys
    - 2009-03-15 23:56 . 2001-08-17 21:36 20480 c:\windows\system32\dllcache\icam5ext.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 20480 c:\windows\system32\dllcache\icam5ext.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 45056 c:\windows\system32\dllcache\icam5com.dll
    - 2009-03-15 23:56 . 2001-08-17 21:36 45056 c:\windows\system32\dllcache\icam5com.dll
    - 2009-03-15 23:56 . 2001-08-17 21:36 61952 c:\windows\system32\dllcache\icam4ext.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 61952 c:\windows\system32\dllcache\icam4ext.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 91136 c:\windows\system32\dllcache\icam4com.dll
    - 2009-03-15 23:56 . 2001-08-17 21:36 91136 c:\windows\system32\dllcache\icam4com.dll
    - 2009-03-15 23:56 . 2001-08-17 21:36 26624 c:\windows\system32\dllcache\icam3ext.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 26624 c:\windows\system32\dllcache\icam3ext.dll
    - 2009-03-15 23:56 . 2001-08-17 13:06 38528 c:\windows\system32\dllcache\ibmvcap.sys
    + 2009-03-15 23:56 . 2001-08-17 12:06 38528 c:\windows\system32\dllcache\ibmvcap.sys
    + 2009-03-15 23:56 . 2001-08-17 10:11 28700 c:\windows\system32\dllcache\ibmexmp.sys
    - 2009-03-15 23:56 . 2001-08-17 11:11 28700 c:\windows\system32\dllcache\ibmexmp.sys
    - 2009-03-15 23:56 . 2001-08-17 11:49 58592 c:\windows\system32\dllcache\i740nt5.sys
    + 2009-03-15 23:56 . 2001-08-17 10:49 58592 c:\windows\system32\dllcache\i740nt5.sys
    - 2009-03-15 23:56 . 2008-04-13 23:11 18560 c:\windows\system32\dllcache\i2omp.sys
    + 2009-03-15 23:56 . 2008-04-13 22:11 18560 c:\windows\system32\dllcache\i2omp.sys
    + 2009-03-15 23:56 . 2008-04-14 03:41 32285 c:\windows\system32\dllcache\hsfcisp2.dll
    - 2009-03-15 23:56 . 2008-04-14 04:41 32285 c:\windows\system32\dllcache\hsfcisp2.dll
    - 2009-03-15 23:56 . 2001-08-17 12:28 50751 c:\windows\system32\dllcache\hsf_tone.sys
    + 2009-03-15 23:56 . 2001-08-17 11:28 50751 c:\windows\system32\dllcache\hsf_tone.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 73279 c:\windows\system32\dllcache\hsf_spkp.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 73279 c:\windows\system32\dllcache\hsf_spkp.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 44863 c:\windows\system32\dllcache\hsf_soar.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 44863 c:\windows\system32\dllcache\hsf_soar.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 57471 c:\windows\system32\dllcache\hsf_samp.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 57471 c:\windows\system32\dllcache\hsf_samp.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 67167 c:\windows\system32\dllcache\hsf_bsc2.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 67167 c:\windows\system32\dllcache\hsf_bsc2.sys
    + 2009-03-15 23:55 . 2001-08-17 20:36 19456 c:\windows\system32\dllcache\hr1w.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 19456 c:\windows\system32\dllcache\hr1w.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 13312 c:\windows\system32\dllcache\hpsjmcro.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 13312 c:\windows\system32\dllcache\hpsjmcro.dll
    - 2009-03-15 23:55 . 2001-08-17 13:07 25952 c:\windows\system32\dllcache\hpn.sys
    + 2009-03-15 23:55 . 2001-08-17 12:07 25952 c:\windows\system32\dllcache\hpn.sys
    + 2009-03-15 23:55 . 2001-08-17 20:36 32768 c:\windows\system32\dllcache\hpgtmcro.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 32768 c:\windows\system32\dllcache\hpgtmcro.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 68608 c:\windows\system32\dllcache\hpgt53tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 68608 c:\windows\system32\dllcache\hpgt53tk.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 31232 c:\windows\system32\dllcache\hpgt42tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 31232 c:\windows\system32\dllcache\hpgt42tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 93696 c:\windows\system32\dllcache\hpgt42.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 93696 c:\windows\system32\dllcache\hpgt42.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 48128 c:\windows\system32\dllcache\hpgt33tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 48128 c:\windows\system32\dllcache\hpgt33tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 89088 c:\windows\system32\dllcache\hpgt33.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 89088 c:\windows\system32\dllcache\hpgt33.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 83968 c:\windows\system32\dllcache\hpgt21.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 83968 c:\windows\system32\dllcache\hpgt21.dll
    + 2008-05-16 13:51 . 2010-08-09 15:30 21504 c:\windows\system32\dllcache\hidserv.dll
    - 2008-05-16 13:51 . 2008-04-14 03:41 21504 c:\windows\system32\dllcache\hidserv.dll
    + 2009-03-15 23:55 . 2008-04-13 22:15 19200 c:\windows\system32\dllcache\hidir.sys
    - 2009-03-15 23:55 . 2008-04-13 23:15 19200 c:\windows\system32\dllcache\hidir.sys
    + 2009-03-15 23:55 . 2008-04-13 22:16 25600 c:\windows\system32\dllcache\hidbth.sys
    - 2009-03-15 23:55 . 2008-04-13 23:16 25600 c:\windows\system32\dllcache\hidbth.sys
    - 2009-03-15 23:55 . 2008-04-13 23:06 20352 c:\windows\system32\dllcache\hidbatt.sys
    + 2009-03-15 23:55 . 2008-04-13 22:06 20352 c:\windows\system32\dllcache\hidbatt.sys
    - 2009-03-15 23:55 . 2008-04-13 23:10 28288 c:\windows\system32\dllcache\grserial.sys
    + 2009-03-15 23:55 . 2008-04-13 22:10 28288 c:\windows\system32\dllcache\grserial.sys
    + 2009-03-15 23:55 . 2001-08-17 11:51 82304 c:\windows\system32\dllcache\grclass.sys
    - 2009-03-15 23:55 . 2001-08-17 12:51 82304 c:\windows\system32\dllcache\grclass.sys
    + 2009-03-15 23:55 . 2001-08-17 11:51 17408 c:\windows\system32\dllcache\gpr400.sys
    - 2009-03-15 23:55 . 2001-08-17 12:51 17408 c:\windows\system32\dllcache\gpr400.sys
    + 2009-03-15 23:55 . 2008-04-13 22:15 59136 c:\windows\system32\dllcache\gckernel.sys
    - 2009-03-15 23:55 . 2008-04-13 23:15 59136 c:\windows\system32\dllcache\gckernel.sys
    + 2009-03-15 23:55 . 2008-04-13 22:15 10624 c:\windows\system32\dllcache\gameenum.sys
    - 2009-03-15 23:55 . 2008-04-13 23:15 10624 c:\windows\system32\dllcache\gameenum.sys
    + 2009-03-15 23:55 . 2008-04-13 22:06 46464 c:\windows\system32\dllcache\gagp30kx.sys
    - 2009-03-15 23:55 . 2008-04-13 23:06 46464 c:\windows\system32\dllcache\gagp30kx.sys
    + 2009-03-15 23:54 . 2001-08-17 20:36 92160 c:\windows\system32\dllcache\fuusd.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 92160 c:\windows\system32\dllcache\fuusd.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 20538 c:\windows\system32\dllcache\fpremadm.exe
    + 2009-02-21 23:00 . 2003-03-24 14:52 20538 c:\windows\system32\dllcache\fpremadm.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 20541 c:\windows\system32\dllcache\fpexedll.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 20541 c:\windows\system32\dllcache\fpexedll.dll
    + 2009-02-21 23:01 . 2003-03-24 14:52 94208 c:\windows\system32\dllcache\fpencode.dll
    - 2009-02-21 23:01 . 2003-03-24 15:52 94208 c:\windows\system32\dllcache\fpencode.dll
    + 2009-02-21 23:01 . 2003-03-24 14:52 20541 c:\windows\system32\dllcache\fpadmdll.dll
    - 2009-02-21 23:01 . 2003-03-24 15:52 20541 c:\windows\system32\dllcache\fpadmdll.dll
    - 2009-02-21 23:01 . 2003-03-24 15:52 24632 c:\windows\system32\dllcache\fpadmcgi.exe
    + 2009-02-21 23:01 . 2003-03-24 14:52 24632 c:\windows\system32\dllcache\fpadmcgi.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 14608 c:\windows\system32\dllcache\fp98sadm.exe
    + 2009-02-21 23:00 . 2003-03-24 14:52 14608 c:\windows\system32\dllcache\fp98sadm.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 49212 c:\windows\system32\dllcache\fp4awebs.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 49212 c:\windows\system32\dllcache\fp4awebs.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 32826 c:\windows\system32\dllcache\fp4avss.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 32826 c:\windows\system32\dllcache\fp4avss.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 41020 c:\windows\system32\dllcache\fp4avnb.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 41020 c:\windows\system32\dllcache\fp4avnb.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 49210 c:\windows\system32\dllcache\fp4areg.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 49210 c:\windows\system32\dllcache\fp4areg.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 82035 c:\windows\system32\dllcache\fp4anscp.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 82035 c:\windows\system32\dllcache\fp4anscp.dll
    - 2009-03-15 23:54 . 2008-04-13 21:05 34173 c:\windows\system32\dllcache\forehe.sys
    + 2009-03-15 23:54 . 2008-04-13 20:05 34173 c:\windows\system32\dllcache\forehe.sys
    + 2009-03-15 23:54 . 2001-08-17 20:36 71680 c:\windows\system32\dllcache\fnfilter.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 71680 c:\windows\system32\dllcache\fnfilter.dll
    + 2009-03-15 23:54 . 2001-08-17 10:13 27165 c:\windows\system32\dllcache\fetnd5.sys
    - 2009-03-15 23:54 . 2001-08-17 11:13 27165 c:\windows\system32\dllcache\fetnd5.sys
    - 2009-03-15 23:54 . 2001-08-17 11:10 22090 c:\windows\system32\dllcache\fem556n5.sys
    + 2009-03-15 23:54 . 2001-08-17 10:10 22090 c:\windows\system32\dllcache\fem556n5.sys
    + 2009-03-15 23:54 . 2001-08-17 10:12 24618 c:\windows\system32\dllcache\fa410nd5.sys
    - 2009-03-15 23:54 . 2001-08-17 11:12 24618 c:\windows\system32\dllcache\fa410nd5.sys
    + 2009-03-15 23:54 . 2001-08-17 10:12 16074 c:\windows\system32\dllcache\fa312nd5.sys
    - 2009-03-15 23:54 . 2001-08-17 11:12 16074 c:\windows\system32\dllcache\fa312nd5.sys
    - 2009-03-15 23:54 . 2001-08-17 11:11 11850 c:\windows\system32\dllcache\f3ab18xj.sys
    + 2009-03-15 23:54 . 2001-08-17 10:11 11850 c:\windows\system32\dllcache\f3ab18xj.sys
    - 2009-03-15 23:54 . 2001-08-17 11:11 12362 c:\windows\system32\dllcache\f3ab18xi.sys
    + 2009-03-15 23:54 . 2001-08-17 10:11 12362 c:\windows\system32\dllcache\f3ab18xi.sys
    - 2009-02-21 23:02 . 2001-08-17 21:36 12288 c:\windows\system32\dllcache\EXCH_smtpctrs.dll
    + 2009-02-21 23:02 . 2001-08-17 20:36 12288 c:\windows\system32\dllcache\EXCH_smtpctrs.dll
    + 2009-02-21 23:02 . 2001-08-17 20:36 26112 c:\windows\system32\dllcache\EXCH_seos.dll
    - 2009-02-21 23:02 . 2001-08-17 21:36 26112 c:\windows\system32\dllcache\EXCH_seos.dll
    - 2009-02-21 23:02 . 2001-08-17 21:36 57856 c:\windows\system32\dllcache\EXCH_scripto.dll
    + 2009-02-21 23:02 . 2001-08-17 20:36 57856 c:\windows\system32\dllcache\EXCH_scripto.dll
    - 2009-02-21 23:02 . 2001-08-17 21:36 23040 c:\windows\system32\dllcache\EXCH_regtrace.exe
    + 2009-02-21 23:02 . 2001-08-17 20:36 23040 c:\windows\system32\dllcache\EXCH_regtrace.exe
    - 2009-02-21 23:02 . 2001-08-17 21:36 38912 c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
    + 2009-02-21 23:02 . 2001-08-17 20:36 38912 c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
    + 2009-02-21 23:02 . 2001-08-17 20:36 65536 c:\windows\system32\dllcache\EXCH_mailmsg.dll
    - 2009-02-21 23:02 . 2001-08-17 21:36 65536 c:\windows\system32\dllcache\EXCH_mailmsg.dll
    - 2009-02-21 23:01 . 2001-08-17 21:36 43520 c:\windows\system32\dllcache\EXCH_fcachdll.dll
    + 2009-02-21 23:01 . 2001-08-17 20:36 43520 c:\windows\system32\dllcache\EXCH_fcachdll.dll
    - 2009-02-21 23:00 . 2001-08-17 21:36 45056 c:\windows\system32\dllcache\EXCH_aqadmin.dll
    + 2009-02-21 23:00 . 2001-08-17 20:36 45056 c:\windows\system32\dllcache\EXCH_aqadmin.dll
    + 2009-03-15 23:54 . 2001-08-17 10:12 16998 c:\windows\system32\dllcache\ex10.sys
    - 2009-03-15 23:54 . 2001-08-17 11:12 16998 c:\windows\system32\dllcache\ex10.sys
    + 2009-03-15 23:54 . 2001-08-17 20:36 45568 c:\windows\system32\dllcache\esunib.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 45568 c:\windows\system32\dllcache\esunib.dll
    + 2009-03-15 23:54 . 2001-08-17 20:36 45568 c:\windows\system32\dllcache\esuni.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 45568 c:\windows\system32\dllcache\esuni.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 34816 c:\windows\system32\dllcache\esuimg.dll
    + 2009-03-15 23:54 . 2001-08-17 20:36 34816 c:\windows\system32\dllcache\esuimg.dll
    - 2009-03-15 23:54 . 2001-08-17 21:36 43008 c:\windows\system32\dllcache\esucm.dll
    + 2009-03-15 23:54 . 2001-08-17 20:36 43008 c:\windows\system32\dllcache\esucm.dll
    + 2009-03-15 23:54 . 2001-08-17 10:19 63360 c:\windows\system32\dllcache\ess.sys
    - 2009-03-15 23:54 . 2001-08-17 11:19 63360 c:\windows\system32\dllcache\ess.sys
    + 2009-03-15 23:53 . 2001-08-17 10:19 72192 c:\windows\system32\dllcache\es1969.sys
    - 2009-03-15 23:53 . 2001-08-17 11:19 72192 c:\windows\system32\dllcache\es1969.sys
    + 2009-03-15 23:53 . 2001-08-17 10:19 40704 c:\windows\system32\dllcache\es1371mp.sys
    - 2009-03-15 23:53 . 2001-08-17 11:19 40704 c:\windows\system32\dllcache\es1371mp.sys
    - 2009-03-15 23:53 . 2001-08-17 11:19 37120 c:\windows\system32\dllcache\es1370mp.sys
    + 2009-03-15 23:53 . 2001-08-17 10:19 37120 c:\windows\system32\dllcache\es1370mp.sys
    - 2009-03-15 23:53 . 2001-08-17 21:36 61952 c:\windows\system32\dllcache\eqnloop.exe
    + 2009-03-15 23:53 . 2001-08-17 20:36 61952 c:\windows\system32\dllcache\eqnloop.exe
    + 2009-03-15 23:53 . 2001-08-17 20:36 51200 c:\windows\system32\dllcache\eqnlogr.exe
    - 2009-03-15 23:53 . 2001-08-17 21:36 51200 c:\windows\system32\dllcache\eqnlogr.exe
    + 2009-03-15 23:53 . 2001-08-17 20:36 53248 c:\windows\system32\dllcache\eqndiag.exe
    - 2009-03-15 23:53 . 2001-08-17 21:36 53248 c:\windows\system32\dllcache\eqndiag.exe
    + 2009-03-15 23:53 . 2001-08-17 10:12 18503 c:\windows\system32\dllcache\epro4.sys
    - 2009-03-15 23:53 . 2001-08-17 11:12 18503 c:\windows\system32\dllcache\epro4.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 19996 c:\windows\system32\dllcache\em556n4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 19996 c:\windows\system32\dllcache\em556n4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 25159 c:\windows\system32\dllcache\elnk3.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 25159 c:\windows\system32\dllcache\elnk3.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 70174 c:\windows\system32\dllcache\el98xn5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 70174 c:\windows\system32\dllcache\el98xn5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 66591 c:\windows\system32\dllcache\el90xbc5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 66591 c:\windows\system32\dllcache\el90xbc5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 77386 c:\windows\system32\dllcache\el656nd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 77386 c:\windows\system32\dllcache\el656nd5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 69194 c:\windows\system32\dllcache\el656cd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 69194 c:\windows\system32\dllcache\el656cd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 26141 c:\windows\system32\dllcache\el589nd5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 26141 c:\windows\system32\dllcache\el589nd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 69692 c:\windows\system32\dllcache\el575nd5.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 69692 c:\windows\system32\dllcache\el575nd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 24653 c:\windows\system32\dllcache\el574nd4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 24653 c:\windows\system32\dllcache\el574nd4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 55999 c:\windows\system32\dllcache\el556nd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 55999 c:\windows\system32\dllcache\el556nd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:10 44103 c:\windows\system32\dllcache\el515.sys
    + 2009-03-15 23:53 . 2001-08-17 10:10 44103 c:\windows\system32\dllcache\el515.sys
    - 2009-03-15 23:53 . 2001-08-17 11:12 19594 c:\windows\system32\dllcache\e100isa4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:12 19594 c:\windows\system32\dllcache\e100isa4.sys
    + 2009-03-15 23:53 . 2001-08-17 10:12 50719 c:\windows\system32\dllcache\e1000nt5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:12 50719 c:\windows\system32\dllcache\e1000nt5.sys
    + 2009-03-15 23:53 . 2001-08-17 12:07 20192 c:\windows\system32\dllcache\dpti2o.sys
    - 2009-03-15 23:53 . 2001-08-17 13:07 20192 c:\windows\system32\dllcache\dpti2o.sys
    - 2009-03-15 23:53 . 2001-08-17 11:12 28062 c:\windows\system32\dllcache\dp83820.sys
    + 2009-03-15 23:53 . 2001-08-17 10:12 28062 c:\windows\system32\dllcache\dp83820.sys
    - 2009-03-15 23:53 . 2001-08-17 12:47 23808 c:\windows\system32\dllcache\dot4usb.sys
    + 2009-03-15 23:53 . 2001-08-17 11:47 23808 c:\windows\system32\dllcache\dot4usb.sys
    - 2009-03-15 23:53 . 2001-08-17 12:47 12928 c:\windows\system32\dllcache\dot4prt.sys
    + 2009-03-15 23:53 . 2001-08-17 11:47 12928 c:\windows\system32\dllcache\dot4prt.sys
    - 2009-03-15 23:52 . 2001-08-17 11:11 29696 c:\windows\system32\dllcache\dm9pci5.sys
    + 2009-03-15 23:52 . 2001-08-17 10:11 29696 c:\windows\system32\dllcache\dm9pci5.sys
    - 2009-03-15 23:52 . 2001-08-17 11:11 26698 c:\windows\system32\dllcache\dlh5xnd5.sys
    + 2009-03-15 23:52 . 2001-08-17 10:11 26698 c:\windows\system32\dllcache\dlh5xnd5.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 29768 c:\windows\system32\dllcache\divasu.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 29768 c:\windows\system32\dllcache\divasu.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 37962 c:\windows\system32\dllcache\divaprop.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 37962 c:\windows\system32\dllcache\divaprop.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 38985 c:\windows\system32\dllcache\disrvsu.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 38985 c:\windows\system32\dllcache\disrvsu.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 31305 c:\windows\system32\dllcache\disrvpp.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 31305 c:\windows\system32\dllcache\disrvpp.dll
    + 2009-03-15 23:52 . 2001-08-17 10:13 91305 c:\windows\system32\dllcache\dimaint.sys
    - 2009-03-15 23:52 . 2001-08-17 11:13 91305 c:\windows\system32\dllcache\dimaint.sys
    - 2009-03-15 23:52 . 2001-08-17 11:17 42432 c:\windows\system32\dllcache\digirlpt.sys
    + 2009-03-15 23:52 . 2001-08-17 10:17 42432 c:\windows\system32\dllcache\digirlpt.sys
    + 2009-03-15 23:52 . 2001-08-17 10:14 21606 c:\windows\system32\dllcache\digiisdn.sys
    - 2009-03-15 23:52 . 2001-08-17 11:14 21606 c:\windows\system32\dllcache\digiisdn.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 41046 c:\windows\system32\dllcache\digiisdn.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 41046 c:\windows\system32\dllcache\digiisdn.dll
    + 2009-03-15 23:52 . 2001-08-17 10:17 90525 c:\windows\system32\dllcache\digifep5.sys
    - 2009-03-15 23:52 . 2001-08-17 11:17 90525 c:\windows\system32\dllcache\digifep5.sys
    - 2009-03-15 23:52 . 2001-08-17 11:13 37735 c:\windows\system32\dllcache\digiasyn.sys
    + 2009-03-15 23:52 . 2001-08-17 10:13 37735 c:\windows\system32\dllcache\digiasyn.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 65622 c:\windows\system32\dllcache\digiasyn.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 65622 c:\windows\system32\dllcache\digiasyn.dll
    + 2009-03-15 23:50 . 2001-08-17 20:36 32256 c:\windows\system32\dllcache\diapi2NT.dll
    - 2009-03-15 23:50 . 2001-08-17 21:36 32256 c:\windows\system32\dllcache\diapi2NT.dll
    + 2009-03-15 23:52 . 2001-08-17 10:17 29531 c:\windows\system32\dllcache\dgapci.sys
    - 2009-03-15 23:52 . 2001-08-17 11:17 29531 c:\windows\system32\dllcache\dgapci.sys
    - 2009-03-15 23:52 . 2001-08-17 11:11 24649 c:\windows\system32\dllcache\dfe650d.sys
    + 2009-03-15 23:52 . 2001-08-17 10:11 24649 c:\windows\system32\dllcache\dfe650d.sys
    - 2009-03-15 23:52 . 2001-08-17 11:11 24648 c:\windows\system32\dllcache\dfe650.sys
    + 2009-03-15 23:52 . 2001-08-17 10:11 24648 c:\windows\system32\dllcache\dfe650.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 24064 c:\windows\system32\dllcache\devldr32.exe
    - 2009-03-15 23:52 . 2001-08-17 21:36 24064 c:\windows\system32\dllcache\devldr32.exe
    - 2009-03-15 23:52 . 2001-08-17 11:11 20928 c:\windows\system32\dllcache\defpa.sys
    + 2009-03-15 23:52 . 2001-08-17 10:11 20928 c:\windows\system32\dllcache\defpa.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 86016 c:\windows\system32\dllcache\dc240usd.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 86016 c:\windows\system32\dllcache\dc240usd.dll
    - 2009-03-15 23:52 . 2001-08-17 11:12 63208 c:\windows\system32\dllcache\dc21x4.sys
    + 2009-03-15 23:52 . 2001-08-17 10:12 63208 c:\windows\system32\dllcache\dc21x4.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 80896 c:\windows\system32\dllcache\dc210usd.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 80896 c:\windows\system32\dllcache\dc210usd.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 25600 c:\windows\system32\dllcache\dc210_32.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 25600 c:\windows\system32\dllcache\dc210_32.dll
    - 2009-03-15 23:52 . 2001-08-17 12:52 14720 c:\windows\system32\dllcache\dac960nt.sys
    + 2009-03-15 23:52 . 2001-08-17 11:52 14720 c:\windows\system32\dllcache\dac960nt.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 27648 c:\windows\system32\dllcache\cyzports.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 27648 c:\windows\system32\dllcache\cyzports.dll
    + 2009-03-15 23:52 . 2001-08-17 11:50 49792 c:\windows\system32\dllcache\cyzport.sys
    - 2009-03-15 23:52 . 2001-08-17 12:50 49792 c:\windows\system32\dllcache\cyzport.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 27136 c:\windows\system32\dllcache\cyzcoins.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 27136 c:\windows\system32\dllcache\cyzcoins.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 27648 c:\windows\system32\dllcache\cyyports.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 27648 c:\windows\system32\dllcache\cyyports.dll
    - 2009-03-15 23:52 . 2001-08-17 12:50 50176 c:\windows\system32\dllcache\cyyport.sys
    + 2009-03-15 23:52 . 2001-08-17 11:50 50176 c:\windows\system32\dllcache\cyyport.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 28672 c:\windows\system32\dllcache\cyycoins.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 28672 c:\windows\system32\dllcache\cyycoins.dll
    + 2009-03-15 23:52 . 2001-08-17 11:50 14848 c:\windows\system32\dllcache\cyclom-y.sys
    - 2009-03-15 23:52 . 2001-08-17 12:50 14848 c:\windows\system32\dllcache\cyclom-y.sys
    + 2009-03-15 23:52 . 2001-08-17 11:50 17152 c:\windows\system32\dllcache\cyclad-z.sys
    - 2009-03-15 23:52 . 2001-08-17 12:50 17152 c:\windows\system32\dllcache\cyclad-z.sys
    - 2009-03-15 23:52 . 2008-04-13 21:06 48640 c:\windows\system32\dllcache\cwrwdm.sys
    + 2009-03-15 23:52 . 2008-04-13 20:06 48640 c:\windows\system32\dllcache\cwrwdm.sys
    - 2009-03-15 23:52 . 2001-08-17 11:19 93952 c:\windows\system32\dllcache\cwcwdm.sys
    + 2009-03-15 23:52 . 2001-08-17 10:19 93952 c:\windows\system32\dllcache\cwcwdm.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 72832 c:\windows\system32\dllcache\cwbwdm.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 72832 c:\windows\system32\dllcache\cwbwdm.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 96256 c:\windows\system32\dllcache\ctlsb16.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 96256 c:\windows\system32\dllcache\ctlsb16.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 42112 c:\windows\system32\dllcache\crtaud.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 42112 c:\windows\system32\dllcache\crtaud.sys
    - 2009-03-15 23:51 . 2001-08-17 11:11 60970 c:\windows\system32\dllcache\cpqtrnd5.sys
    + 2009-03-15 23:51 . 2001-08-17 10:11 60970 c:\windows\system32\dllcache\cpqtrnd5.sys
    - 2009-03-15 23:51 . 2001-08-17 11:13 21533 c:\windows\system32\dllcache\cpqndis5.sys
    + 2009-03-15 23:51 . 2001-08-17 10:13 21533 c:\windows\system32\dllcache\cpqndis5.sys
    + 2009-03-15 23:51 . 2001-08-17 11:52 14976 c:\windows\system32\dllcache\cpqarray.sys
    - 2009-03-15 23:51 . 2001-08-17 12:52 14976 c:\windows\system32\dllcache\cpqarray.sys
    + 2009-03-15 23:51 . 2008-04-13 22:06 10240 c:\windows\system32\dllcache\compbatt.sys
    - 2009-03-15 23:51 . 2008-04-13 23:06 10240 c:\windows\system32\dllcache\compbatt.sys
    - 2009-03-15 23:51 . 2001-08-17 11:11 39936 c:\windows\system32\dllcache\cnxt1803.sys
    + 2009-03-15 23:51 . 2001-08-17 10:11 39936 c:\windows\system32\dllcache\cnxt1803.sys
    - 2009-03-15 23:51 . 2001-08-17 21:36 44032 c:\windows\system32\dllcache\cnusd.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 44032 c:\windows\system32\dllcache\cnusd.dll
    + 2009-03-15 23:51 . 2001-08-17 11:51 20736 c:\windows\system32\dllcache\cmbp0wdm.sys
    - 2009-03-15 23:51 . 2001-08-17 12:51 20736 c:\windows\system32\dllcache\cmbp0wdm.sys
    - 2009-03-15 23:51 . 2008-04-13 23:06 13952 c:\windows\system32\dllcache\cmbatt.sys
    + 2009-03-15 23:51 . 2008-04-13 22:06 13952 c:\windows\system32\dllcache\cmbatt.sys
    - 2009-03-15 23:51 . 2001-08-17 12:57 45696 c:\windows\system32\dllcache\cirrus.sys
    + 2009-03-15 23:51 . 2001-08-17 11:57 45696 c:\windows\system32\dllcache\cirrus.sys
    + 2009-03-15 23:51 . 2001-08-17 12:56 91264 c:\windows\system32\dllcache\cirrus.dll
    - 2009-03-15 23:51 . 2001-08-17 13:56 91264 c:\windows\system32\dllcache\cirrus.dll
    + 2009-03-15 23:51 . 2008-04-14 03:41 15423 c:\windows\system32\dllcache\ch7xxnt5.dll
    - 2009-03-15 23:51 . 2008-04-14 04:41 15423 c:\windows\system32\dllcache\ch7xxnt5.dll
    + 2009-03-15 23:51 . 2001-08-17 10:13 49182 c:\windows\system32\dllcache\cem56n5.sys
    - 2009-03-15 23:51 . 2001-08-17 11:13 49182 c:\windows\system32\dllcache\cem56n5.sys
    - 2009-03-15 23:51 . 2001-08-17 11:13 22044 c:\windows\system32\dllcache\cem33n5.sys
    + 2009-03-15 23:51 . 2001-08-17 10:13 22044 c:\windows\system32\dllcache\cem33n5.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 22044 c:\windows\system32\dllcache\cem28n5.sys
    + 2009-03-15 23:50 . 2001-08-17 10:13 22044 c:\windows\system32\dllcache\cem28n5.sys
    + 2009-03-15 23:50 . 2001-08-17 10:13 27164 c:\windows\system32\dllcache\ce3n5.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 27164 c:\windows\system32\dllcache\ce3n5.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 21530 c:\windows\system32\dllcache\ce2n5.sys
    + 2009-03-15 23:50 . 2001-08-17 10:13 21530 c:\windows\system32\dllcache\ce2n5.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 46108 c:\windows\system32\dllcache\cben5.sys
    + 2009-03-15 23:50 . 2001-08-17 10:13 46108 c:\windows\system32\dllcache\cben5.sys
    + 2009-03-15 23:50 . 2001-08-17 10:12 39680 c:\windows\system32\dllcache\cb325.sys
    - 2009-03-15 23:50 . 2001-08-17 11:12 39680 c:\windows\system32\dllcache\cb325.sys
    + 2009-03-15 23:50 . 2001-08-17 10:12 37916 c:\windows\system32\dllcache\cb102.sys
    - 2009-03-15 23:50 . 2001-08-17 11:12 37916 c:\windows\system32\dllcache\cb102.sys
    + 2009-03-15 23:50 . 2001-08-17 20:36 74240 c:\windows\system32\dllcache\camexo20.dll
    - 2009-03-15 23:50 . 2001-08-17 21:36 74240 c:\windows\system32\dllcache\camexo20.dll
    + 2009-03-15 23:49 . 2001-08-17 11:51 13824 c:\windows\system32\dllcache\bulltlp3.sys
    - 2009-03-15 23:49 . 2001-08-17 12:51 13824 c:\windows\system32\dllcache\bulltlp3.sys
    - 2009-03-15 23:49 . 2008-04-13 23:16 36480 c:\windows\system32\dllcache\bthprint.sys
    + 2009-03-15 23:49 . 2008-04-13 22:16 36480 c:\windows\system32\dllcache\bthprint.sys
    + 2009-03-15 23:49 . 2001-08-17 10:11 31529 c:\windows\system32\dllcache\brzwlan.sys
    - 2009-03-15 23:49 . 2001-08-17 11:11 31529 c:\windows\system32\dllcache\brzwlan.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 10368 c:\windows\system32\dllcache\brusbscn.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 10368 c:\windows\system32\dllcache\brusbscn.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 11008 c:\windows\system32\dllcache\brusbmdm.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 11008 c:\windows\system32\dllcache\brusbmdm.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 60416 c:\windows\system32\dllcache\brserwdm.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 60416 c:\windows\system32\dllcache\brserwdm.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 39552 c:\windows\system32\dllcache\brparwdm.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 39552 c:\windows\system32\dllcache\brparwdm.sys
    - 2009-03-15 23:49 . 2001-08-17 21:36 41472 c:\windows\system32\dllcache\brmfusb.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 41472 c:\windows\system32\dllcache\brmfusb.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 32256 c:\windows\system32\dllcache\brmfrsmg.exe
    + 2009-03-15 23:49 . 2001-08-17 20:36 32256 c:\windows\system32\dllcache\brmfrsmg.exe
    - 2009-03-15 23:49 . 2001-08-17 21:36 29696 c:\windows\system32\dllcache\brmflpt.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 29696 c:\windows\system32\dllcache\brmflpt.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 81408 c:\windows\system32\dllcache\brmfcwia.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 81408 c:\windows\system32\dllcache\brmfcwia.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 15360 c:\windows\system32\dllcache\brmfbidi.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 15360 c:\windows\system32\dllcache\brmfbidi.dll
    - 2009-03-15 23:49 . 2001-08-17 12:12 12160 c:\windows\system32\dllcache\brfiltlo.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 12160 c:\windows\system32\dllcache\brfiltlo.sys
    - 2009-03-15 23:49 . 2001-08-17 21:36 12800 c:\windows\system32\dllcache\brevif.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 12800 c:\windows\system32\dllcache\brevif.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 19456 c:\windows\system32\dllcache\brbidiif.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 19456 c:\windows\system32\dllcache\brbidiif.dll
    - 2009-03-15 23:49 . 2008-04-13 23:16 11776 c:\windows\system32\dllcache\bdasup.sys
    + 2009-03-15 23:49 . 2008-04-13 22:16 11776 c:\windows\system32\dllcache\bdasup.sys
    - 2009-03-15 23:49 . 2001-08-17 11:11 26568 c:\windows\system32\dllcache\bcm4e5.sys
    + 2009-03-15 23:49 . 2001-08-17 10:11 26568 c:\windows\system32\dllcache\bcm4e5.sys
    + 2009-03-15 23:49 . 2001-08-17 10:11 54271 c:\windows\system32\dllcache\bcm42xx5.sys
    - 2009-03-15 23:49 . 2001-08-17 11:11 54271 c:\windows\system32\dllcache\bcm42xx5.sys
    - 2009-03-15 23:49 . 2001-08-17 11:11 66557 c:\windows\system32\dllcache\bcm42u.sys
    + 2009-03-15 23:49 . 2001-08-17 10:11 66557 c:\windows\system32\dllcache\bcm42u.sys
    - 2009-03-15 23:48 . 2008-04-13 23:06 14208 c:\windows\system32\dllcache\battc.sys
    + 2009-03-15 23:48 . 2008-04-13 22:06 14208 c:\windows\system32\dllcache\battc.sys
    - 2009-03-15 23:48 . 2001-08-17 11:48 36128 c:\windows\system32\dllcache\banshee.sys
    + 2009-03-15 23:48 . 2001-08-17 10:48 36128 c:\windows\system32\dllcache\banshee.sys
    - 2009-03-15 23:48 . 2001-08-17 11:11 96640 c:\windows\system32\dllcache\b57xp32.sys
    + 2009-03-15 23:48 . 2001-08-17 10:11 96640 c:\windows\system32\dllcache\b57xp32.sys
    + 2009-03-15 23:48 . 2001-08-17 10:13 89952 c:\windows\system32\dllcache\b1cbase.sys
    - 2009-03-15 23:48 . 2001-08-17 11:13 89952 c:\windows\system32\dllcache\b1cbase.sys
    + 2009-03-15 23:48 . 2001-08-17 10:19 36992 c:\windows\system32\dllcache\aztw2320.sys
    - 2009-03-15 23:48 . 2001-08-17 11:19 36992 c:\windows\system32\dllcache\aztw2320.sys
    + 2009-03-15 23:48 . 2001-08-17 10:13 37568 c:\windows\system32\dllcache\avmwan.sys
    - 2009-03-15 23:48 . 2001-08-17 11:13 37568 c:\windows\system32\dllcache\avmwan.sys
    + 2009-03-15 23:48 . 2001-08-17 20:36 87552 c:\windows\system32\dllcache\avmcoxp.dll
    - 2009-03-15 23:48 . 2001-08-17 21:36 87552 c:\windows\system32\dllcache\avmcoxp.dll
    + 2009-03-15 23:48 . 2008-04-13 22:16 13696 c:\windows\system32\dllcache\avcstrm.sys
    - 2009-03-15 23:48 . 2008-04-13 23:16 13696 c:\windows\system32\dllcache\avcstrm.sys
    + 2009-03-15 23:48 . 2001-08-17 12:01 36096 c:\windows\system32\dllcache\avcaudio.sys
    - 2009-03-15 23:48 . 2001-08-17 13:01 36096 c:\windows\system32\dllcache\avcaudio.sys
    - 2009-02-21 23:00 . 2003-03-24 15:52 16439 c:\windows\system32\dllcache\author.exe
    + 2009-02-21 23:00 . 2003-03-24 14:52 16439 c:\windows\system32\dllcache\author.exe
    + 2009-02-21 23:00 . 2003-03-24 14:52 20540 c:\windows\system32\dllcache\author.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 20540 c:\windows\system32\dllcache\author.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 17279 c:\windows\system32\dllcache\atv10nt5.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 17279 c:\windows\system32\dllcache\atv10nt5.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 14143 c:\windows\system32\dllcache\atv06nt5.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 14143 c:\windows\system32\dllcache\atv06nt5.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 25471 c:\windows\system32\dllcache\atv04nt5.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 25471 c:\windows\system32\dllcache\atv04nt5.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 11359 c:\windows\system32\dllcache\atv02nt5.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 11359 c:\windows\system32\dllcache\atv02nt5.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 21183 c:\windows\system32\dllcache\atv01nt5.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 21183 c:\windows\system32\dllcache\atv01nt5.dll
    - 2009-03-15 23:48 . 2001-08-17 11:49 23552 c:\windows\system32\dllcache\atixbar.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 23552 c:\windows\system32\dllcache\atixbar.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 26624 c:\windows\system32\dllcache\ativxbar.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 26624 c:\windows\system32\dllcache\ativxbar.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 19456 c:\windows\system32\dllcache\ativttxx.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 19456 c:\windows\system32\dllcache\ativttxx.sys
    + 2009-03-15 23:48 . 2008-04-14 03:41 32768 c:\windows\system32\dllcache\ativtmxx.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 32768 c:\windows\system32\dllcache\ativtmxx.dll
    - 2009-03-15 23:48 . 2001-08-17 11:49 17152 c:\windows\system32\dllcache\atitvsnd.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 17152 c:\windows\system32\dllcache\atitvsnd.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 17152 c:\windows\system32\dllcache\atitunep.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 17152 c:\windows\system32\dllcache\atitunep.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 26880 c:\windows\system32\dllcache\atirtsnd.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 26880 c:\windows\system32\dllcache\atirtsnd.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 49920 c:\windows\system32\dllcache\atirtcap.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 49920 c:\windows\system32\dllcache\atirtcap.sys
    + 2009-03-15 23:48 . 2001-08-17 10:48 70528 c:\windows\system32\dllcache\atiragem.sys
    - 2009-03-15 23:48 . 2001-08-17 11:48 70528 c:\windows\system32\dllcache\atiragem.sys
    - 2009-03-15 23:48 . 2001-08-17 11:49 10240 c:\windows\system32\dllcache\atipcxxx.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 10240 c:\windows\system32\dllcache\atipcxxx.sys
    + 2009-03-15 23:48 . 2008-04-13 20:04 63488 c:\windows\system32\dllcache\atinxsxx.sys
    - 2009-03-15 23:48 . 2008-04-13 21:04 63488 c:\windows\system32\dllcache\atinxsxx.sys
    - 2009-03-15 23:48 . 2008-04-13 21:04 31744 c:\windows\system32\dllcache\atinxbxx.sys
    + 2009-03-15 23:48 . 2008-04-13 20:04 31744 c:\windows\system32\dllcache\atinxbxx.sys
    - 2009-03-15 23:48 . 2008-04-13 21:04 73216 c:\windows\system32\dllcache\atintuxx.sys
    + 2009-03-15 23:48 . 2008-04-13 20:04 73216 c:\windows\system32\dllcache\atintuxx.sys
    - 2009-03-15 23:48 . 2008-04-13 21:04 13824 c:\windows\system32\dllcache\atinttxx.sys
    + 2009-03-15 23:48 . 2008-04-13 20:04 13824 c:\windows\system32\dllcache\atinttxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 28672 c:\windows\system32\dllcache\atinsnxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 28672 c:\windows\system32\dllcache\atinsnxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 52224 c:\windows\system32\dllcache\atinraxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 52224 c:\windows\system32\dllcache\atinraxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 14336 c:\windows\system32\dllcache\atinpdxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 14336 c:\windows\system32\dllcache\atinpdxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 13824 c:\windows\system32\dllcache\atinmdxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 13824 c:\windows\system32\dllcache\atinmdxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 57856 c:\windows\system32\dllcache\atinbtxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 57856 c:\windows\system32\dllcache\atinbtxx.sys
    - 2009-03-15 23:47 . 2001-08-17 11:49 75136 c:\windows\system32\dllcache\atimpae.sys
    + 2009-03-15 23:47 . 2001-08-17 10:49 75136 c:\windows\system32\dllcache\atimpae.sys
    - 2009-03-15 23:47 . 2001-08-17 21:36 37376 c:\windows\system32\dllcache\atievxx.exe
    + 2009-03-15 23:47 . 2001-08-17 20:36 37376 c:\windows\system32\dllcache\atievxx.exe
    + 2009-03-15 23:47 . 2001-08-17 10:49 46464 c:\windows\system32\dllcache\atibt829.sys
    - 2009-03-15 23:47 . 2001-08-17 11:49 46464 c:\windows\system32\dllcache\atibt829.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 34735 c:\windows\system32\dllcache\ati1xsxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 34735 c:\windows\system32\dllcache\ati1xsxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 29455 c:\windows\system32\dllcache\ati1xbxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 29455 c:\windows\system32\dllcache\ati1xbxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 36463 c:\windows\system32\dllcache\ati1tuxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 36463 c:\windows\system32\dllcache\ati1tuxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 21343 c:\windows\system32\dllcache\ati1ttxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 21343 c:\windows\system32\dllcache\ati1ttxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 26367 c:\windows\system32\dllcache\ati1snxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 26367 c:\windows\system32\dllcache\ati1snxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 63663 c:\windows\system32\dllcache\ati1rvxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 63663 c:\windows\system32\dllcache\ati1rvxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 30671 c:\windows\system32\dllcache\ati1raxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 30671 c:\windows\system32\dllcache\ati1raxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 12047 c:\windows\system32\dllcache\ati1pdxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 12047 c:\windows\system32\dllcache\ati1pdxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 11615 c:\windows\system32\dllcache\ati1mdxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 11615 c:\windows\system32\dllcache\ati1mdxx.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 56623 c:\windows\system32\dllcache\ati1btxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 56623 c:\windows\system32\dllcache\ati1btxx.sys
    - 2009-03-15 23:47 . 2001-08-17 12:57 77568 c:\windows\system32\dllcache\ati.sys
    + 2009-03-15 23:47 . 2001-08-17 11:57 77568 c:\windows\system32\dllcache\ati.sys
    - 2009-03-15 23:47 . 2001-08-17 13:55 96128 c:\windows\system32\dllcache\ati.dll
    + 2009-03-15 23:47 . 2001-08-17 12:55 96128 c:\windows\system32\dllcache\ati.dll
    + 2009-03-15 23:47 . 2001-08-17 10:12 97354 c:\windows\system32\dllcache\aspndis3.sys
    - 2009-03-15 23:47 . 2001-08-17 11:12 97354 c:\windows\system32\dllcache\aspndis3.sys
    + 2009-03-15 23:47 . 2001-08-17 11:51 14848 c:\windows\system32\dllcache\asc3550.sys
    - 2009-03-15 23:47 . 2001-08-17 12:51 14848 c:\windows\system32\dllcache\asc3550.sys
    + 2009-03-15 23:47 . 2001-08-17 11:52 22400 c:\windows\system32\dllcache\asc3350p.sys
    - 2009-03-15 23:47 . 2001-08-17 12:52 22400 c:\windows\system32\dllcache\asc3350p.sys
    + 2009-03-15 23:47 . 2001-08-17 11:52 26496 c:\windows\system32\dllcache\asc.sys
    - 2009-03-15 23:47 . 2001-08-17 12:52 26496 c:\windows\system32\dllcache\asc.sys
    + 2009-03-15 23:47 . 2008-04-13 20:05 36224 c:\windows\system32\dllcache\an983.sys
    - 2009-03-15 23:47 . 2008-04-13 21:05 36224 c:\windows\system32\dllcache\an983.sys
    - 2009-03-15 23:46 . 2001-08-17 12:52 12032 c:\windows\system32\dllcache\amsint.sys
    + 2009-03-15 23:46 . 2001-08-17 11:52 12032 c:\windows\system32\dllcache\amsint.sys
    + 2009-03-15 23:46 . 2008-04-13 22:06 43008 c:\windows\system32\dllcache\amdagp.sys
    - 2009-03-15 23:46 . 2008-04-13 23:06 43008 c:\windows\system32\dllcache\amdagp.sys
    - 2009-03-15 23:46 . 2001-08-17 11:11 16969 c:\windows\system32\dllcache\amb8002.sys
    + 2009-03-15 23:46 . 2001-08-17 10:11 16969 c:\windows\system32\dllcache\amb8002.sys
    + 2009-03-15 23:46 . 2008-04-13 22:06 42752 c:\windows\system32\dllcache\alim1541.sys
    - 2009-03-15 23:46 . 2008-04-13 23:06 42752 c:\windows\system32\dllcache\alim1541.sys
    + 2009-03-15 23:46 . 2001-08-17 11:49 26624 c:\windows\system32\dllcache\alifir.sys
    - 2009-03-15 23:46 . 2001-08-17 12:49 26624 c:\windows\system32\dllcache\alifir.sys
    + 2009-03-15 23:46 . 2001-08-17 10:11 27678 c:\windows\system32\dllcache\ali5261.sys
     
  11. 2010/08/11
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    - 2009-03-15 23:46 . 2001-08-17 11:11 27678 c:\windows\system32\dllcache\ali5261.sys
    + 2009-03-15 23:46 . 2001-08-17 12:07 56960 c:\windows\system32\dllcache\aic78xx.sys
    - 2009-03-15 23:46 . 2001-08-17 13:07 56960 c:\windows\system32\dllcache\aic78xx.sys
    + 2009-03-15 23:46 . 2001-08-17 12:07 55168 c:\windows\system32\dllcache\aic78u2.sys
    - 2009-03-15 23:46 . 2001-08-17 13:07 55168 c:\windows\system32\dllcache\aic78u2.sys
    + 2009-03-15 23:46 . 2001-08-17 11:52 12800 c:\windows\system32\dllcache\aha154x.sys
    - 2009-03-15 23:46 . 2001-08-17 12:52 12800 c:\windows\system32\dllcache\aha154x.sys
    + 2009-03-15 23:46 . 2008-04-13 22:06 44928 c:\windows\system32\dllcache\agpcpq.sys
    - 2009-03-15 23:46 . 2008-04-13 23:06 44928 c:\windows\system32\dllcache\agpcpq.sys
    + 2009-03-15 23:46 . 2001-08-17 10:11 46112 c:\windows\system32\dllcache\adptsf50.sys
    - 2009-03-15 23:46 . 2001-08-17 11:11 46112 c:\windows\system32\dllcache\adptsf50.sys
    + 2009-03-15 23:46 . 2008-04-13 20:06 10880 c:\windows\system32\dllcache\admjoy.sys
    - 2009-03-15 23:46 . 2008-04-13 21:06 10880 c:\windows\system32\dllcache\admjoy.sys
    + 2009-02-21 23:00 . 2003-03-24 14:52 16439 c:\windows\system32\dllcache\admin.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 16439 c:\windows\system32\dllcache\admin.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 20540 c:\windows\system32\dllcache\admin.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 20540 c:\windows\system32\dllcache\admin.dll
    + 2009-03-15 23:46 . 2001-08-17 10:11 20160 c:\windows\system32\dllcache\adm8511.sys
    - 2009-03-15 23:46 . 2001-08-17 11:11 20160 c:\windows\system32\dllcache\adm8511.sys
    + 2009-03-15 23:46 . 2001-08-17 20:36 61440 c:\windows\system32\dllcache\acerscad.dll
    - 2009-03-15 23:46 . 2001-08-17 21:36 61440 c:\windows\system32\dllcache\acerscad.dll
    + 2009-03-15 23:46 . 2008-04-13 20:06 84480 c:\windows\system32\dllcache\ac97via.sys
    - 2009-03-15 23:46 . 2008-04-13 21:06 84480 c:\windows\system32\dllcache\ac97via.sys
    - 2009-03-15 23:46 . 2001-08-17 11:20 96256 c:\windows\system32\dllcache\ac97intc.sys
    + 2009-03-15 23:46 . 2001-08-17 10:20 96256 c:\windows\system32\dllcache\ac97intc.sys
    - 2009-03-15 23:45 . 2001-08-17 12:52 23552 c:\windows\system32\dllcache\abp480n5.sys
    + 2009-03-15 23:45 . 2001-08-17 11:52 23552 c:\windows\system32\dllcache\abp480n5.sys
    - 2009-03-15 23:45 . 2001-08-17 13:55 38400 c:\windows\system32\dllcache\8514a.dll
    + 2009-03-15 23:45 . 2001-08-17 12:55 38400 c:\windows\system32\dllcache\8514a.dll
    + 2009-03-15 23:45 . 2008-04-13 22:10 12288 c:\windows\system32\dllcache\4mmdat.sys
    - 2009-03-15 23:45 . 2008-04-13 23:10 12288 c:\windows\system32\dllcache\4mmdat.sys
    - 2009-03-15 23:45 . 2001-08-17 13:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
    + 2009-03-15 23:45 . 2001-08-17 12:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
    - 2009-03-16 00:11 . 2001-08-17 21:37 4608 c:\windows\system32\dllcache\xrxflnch.exe
    + 2009-03-16 00:11 . 2001-08-17 20:37 4608 c:\windows\system32\dllcache\xrxflnch.exe
    - 2009-03-16 00:09 . 2008-04-13 23:06 8832 c:\windows\system32\dllcache\wmiacpi.sys
    + 2009-03-16 00:09 . 2008-04-13 22:06 8832 c:\windows\system32\dllcache\wmiacpi.sys
    - 2009-03-16 00:08 . 2008-04-13 23:10 5376 c:\windows\system32\dllcache\viaide.sys
    + 2009-03-16 00:08 . 2008-04-13 22:10 5376 c:\windows\system32\dllcache\viaide.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 7556 c:\windows\system32\dllcache\usroslba.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 7556 c:\windows\system32\dllcache\usroslba.sys
    - 2009-03-16 00:07 . 2001-08-17 12:51 4992 c:\windows\system32\dllcache\toside.sys
    + 2009-03-16 00:07 . 2001-08-17 11:51 4992 c:\windows\system32\dllcache\toside.sys
    - 2009-03-16 00:07 . 2001-08-17 12:52 7040 c:\windows\system32\dllcache\tandqic.sys
    + 2009-03-16 00:07 . 2001-08-17 11:52 7040 c:\windows\system32\dllcache\tandqic.sys
    + 2009-03-16 00:06 . 2001-08-17 12:02 3968 c:\windows\system32\dllcache\swusbflt.sys
    - 2009-03-16 00:06 . 2001-08-17 13:02 3968 c:\windows\system32\dllcache\swusbflt.sys
    + 2009-03-16 00:06 . 2001-08-17 11:56 7552 c:\windows\system32\dllcache\sonypvu1.sys
    - 2009-03-16 00:06 . 2001-08-17 12:56 7552 c:\windows\system32\dllcache\sonypvu1.sys
    + 2009-03-16 00:06 . 2001-08-17 11:53 9600 c:\windows\system32\dllcache\sonymc.sys
    - 2009-03-16 00:06 . 2001-08-17 12:53 9600 c:\windows\system32\dllcache\sonymc.sys
    - 2009-03-16 00:06 . 2008-04-13 23:10 7552 c:\windows\system32\dllcache\sonyait.sys
    + 2009-03-16 00:06 . 2008-04-13 22:10 7552 c:\windows\system32\dllcache\sonyait.sys
    - 2009-03-16 00:06 . 2001-08-17 12:53 7040 c:\windows\system32\dllcache\snyaitmc.sys
    + 2009-03-16 00:06 . 2001-08-17 11:53 7040 c:\windows\system32\dllcache\snyaitmc.sys
    - 2009-03-16 00:05 . 2001-08-17 12:57 6784 c:\windows\system32\dllcache\smbhc.sys
    + 2009-03-16 00:05 . 2001-08-17 11:57 6784 c:\windows\system32\dllcache\smbhc.sys
    + 2009-03-16 00:05 . 2008-04-13 22:06 6912 c:\windows\system32\dllcache\smbclass.sys
    - 2009-03-16 00:05 . 2008-04-13 23:06 6912 c:\windows\system32\dllcache\smbclass.sys
    - 2009-03-16 00:05 . 2008-04-13 23:06 5888 c:\windows\system32\dllcache\smbali.sys
    + 2009-03-16 00:05 . 2008-04-13 22:06 5888 c:\windows\system32\dllcache\smbali.sys
    + 2009-03-16 00:05 . 2008-04-14 03:42 3901 c:\windows\system32\dllcache\siint5.dll
    - 2009-03-16 00:05 . 2008-04-14 04:42 3901 c:\windows\system32\dllcache\siint5.dll
    + 2009-03-16 00:04 . 2001-08-17 11:53 6784 c:\windows\system32\dllcache\serscan.sys
    - 2009-03-16 00:04 . 2001-08-17 12:53 6784 c:\windows\system32\dllcache\serscan.sys
    + 2009-03-16 00:04 . 2001-08-17 11:53 6912 c:\windows\system32\dllcache\seaddsmc.sys
    - 2009-03-16 00:04 . 2001-08-17 12:53 6912 c:\windows\system32\dllcache\seaddsmc.sys
    + 2009-03-16 00:03 . 2001-08-17 20:36 9216 c:\windows\system32\dllcache\rsmgrstr.dll
    - 2009-03-16 00:03 . 2001-08-17 21:36 9216 c:\windows\system32\dllcache\rsmgrstr.dll
    - 2009-03-16 00:03 . 2001-08-17 11:19 3840 c:\windows\system32\dllcache\rpfun.sys
    + 2009-03-16 00:03 . 2001-08-17 10:19 3840 c:\windows\system32\dllcache\rpfun.sys
    - 2009-03-16 00:03 . 2001-08-17 12:53 3328 c:\windows\system32\dllcache\qv2kux.sys
    + 2009-03-16 00:03 . 2001-08-17 11:53 3328 c:\windows\system32\dllcache\qv2kux.sys
    + 2009-03-16 00:03 . 2008-04-13 22:10 6016 c:\windows\system32\dllcache\qic157.sys
    - 2009-03-16 00:03 . 2008-04-13 23:10 6016 c:\windows\system32\dllcache\qic157.sys
    + 2009-03-16 00:03 . 2001-08-17 20:36 5632 c:\windows\system32\dllcache\ptpusb.dll
    - 2009-03-16 00:03 . 2001-08-17 21:36 5632 c:\windows\system32\dllcache\ptpusb.dll
    - 2009-03-16 00:02 . 2008-04-13 23:10 8832 c:\windows\system32\dllcache\powerfil.sys
    + 2009-03-16 00:02 . 2008-04-13 22:10 8832 c:\windows\system32\dllcache\powerfil.sys
    + 2009-03-16 00:02 . 2001-08-17 11:53 7168 c:\windows\system32\dllcache\pnrmc.sys
    - 2009-03-16 00:02 . 2001-08-17 12:53 7168 c:\windows\system32\dllcache\pnrmc.sys
    + 2009-03-16 00:02 . 2001-08-17 12:07 5504 c:\windows\system32\dllcache\perc2hib.sys
    - 2009-03-16 00:02 . 2001-08-17 13:07 5504 c:\windows\system32\dllcache\perc2hib.sys
    - 2009-03-16 00:01 . 2001-08-17 12:47 9344 c:\windows\system32\dllcache\ntapm.sys
    + 2009-03-16 00:01 . 2001-08-17 11:47 9344 c:\windows\system32\dllcache\ntapm.sys
    + 2009-03-16 00:01 . 2001-08-17 11:53 7552 c:\windows\system32\dllcache\nsmmc.sys
    - 2009-03-16 00:01 . 2001-08-17 12:53 7552 c:\windows\system32\dllcache\nsmmc.sys
    - 2009-03-16 00:01 . 2001-08-17 21:36 7168 c:\windows\system32\dllcache\mxport.dll
    + 2009-03-16 00:01 . 2001-08-17 20:36 7168 c:\windows\system32\dllcache\mxport.dll
    + 2009-03-16 00:00 . 2001-08-17 12:00 2944 c:\windows\system32\dllcache\msmpu401.sys
    - 2009-03-16 00:00 . 2001-08-17 13:00 2944 c:\windows\system32\dllcache\msmpu401.sys
    - 2009-03-16 00:00 . 2001-08-17 12:48 6016 c:\windows\system32\dllcache\msfsio.sys
    + 2009-03-16 00:00 . 2001-08-17 11:48 6016 c:\windows\system32\dllcache\msfsio.sys
    - 2009-03-15 23:59 . 2001-08-17 12:52 6528 c:\windows\system32\dllcache\miniqic.sys
    + 2009-03-15 23:59 . 2001-08-17 11:52 6528 c:\windows\system32\dllcache\miniqic.sys
    + 2009-03-15 23:59 . 2001-08-17 11:58 8320 c:\windows\system32\dllcache\memcard.sys
    - 2009-03-15 23:59 . 2001-08-17 12:58 8320 c:\windows\system32\dllcache\memcard.sys
    - 2009-03-15 23:59 . 2001-08-17 12:52 7424 c:\windows\system32\dllcache\mammoth.sys
    + 2009-03-15 23:59 . 2001-08-17 11:52 7424 c:\windows\system32\dllcache\mammoth.sys
    - 2009-03-15 23:59 . 2008-04-13 23:10 7040 c:\windows\system32\dllcache\ltotape.sys
    + 2009-03-15 23:59 . 2008-04-13 22:10 7040 c:\windows\system32\dllcache\ltotape.sys
    + 2009-03-15 23:59 . 2001-08-17 11:53 4992 c:\windows\system32\dllcache\loop.sys
    - 2009-03-15 23:59 . 2001-08-17 12:53 4992 c:\windows\system32\dllcache\loop.sys
    + 2009-03-15 23:58 . 2001-08-17 20:36 8192 c:\windows\system32\dllcache\kbdkor.dll
    - 2009-03-15 23:58 . 2001-08-17 21:36 8192 c:\windows\system32\dllcache\kbdkor.dll
    - 2009-03-15 23:58 . 2001-08-17 21:36 8704 c:\windows\system32\dllcache\kbdjpn.dll
    + 2009-03-15 23:58 . 2001-08-17 20:36 8704 c:\windows\system32\dllcache\kbdjpn.dll
    + 2009-03-15 23:58 . 2008-04-14 03:39 6144 c:\windows\system32\dllcache\kbd106.dll
    - 2009-03-15 23:58 . 2008-04-14 04:39 6144 c:\windows\system32\dllcache\kbd106.dll
    - 2009-03-15 23:58 . 2001-08-17 13:55 5632 c:\windows\system32\dllcache\kbd103.dll
    + 2009-03-15 23:58 . 2001-08-17 12:55 5632 c:\windows\system32\dllcache\kbd103.dll
    - 2009-03-15 23:58 . 2001-08-17 13:55 6144 c:\windows\system32\dllcache\kbd101c.dll
    + 2009-03-15 23:58 . 2001-08-17 12:55 6144 c:\windows\system32\dllcache\kbd101c.dll
    - 2009-03-15 23:57 . 2001-08-17 13:55 6144 c:\windows\system32\dllcache\kbd101b.dll
    + 2009-03-15 23:57 . 2001-08-17 12:55 6144 c:\windows\system32\dllcache\kbd101b.dll
    + 2009-03-15 23:56 . 2001-08-17 20:34 9216 c:\windows\system32\dllcache\ibmsgnet.dll
    - 2009-03-15 23:56 . 2001-08-17 21:34 9216 c:\windows\system32\dllcache\ibmsgnet.dll
    - 2009-03-15 23:56 . 2008-04-13 23:11 8576 c:\windows\system32\dllcache\i2omgmt.sys
    + 2009-03-15 23:56 . 2008-04-13 22:11 8576 c:\windows\system32\dllcache\i2omgmt.sys
    - 2009-03-15 23:55 . 2001-08-17 21:36 9759 c:\windows\system32\dllcache\hsf_inst.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 9759 c:\windows\system32\dllcache\hsf_inst.dll
    - 2009-03-15 23:55 . 2001-08-17 12:52 5760 c:\windows\system32\dllcache\hpt4qic.sys
    + 2009-03-15 23:55 . 2001-08-17 11:52 5760 c:\windows\system32\dllcache\hpt4qic.sys
    + 2009-03-15 23:55 . 2001-08-17 12:02 2688 c:\windows\system32\dllcache\hidswvd.sys
    - 2009-03-15 23:55 . 2001-08-17 13:02 2688 c:\windows\system32\dllcache\hidswvd.sys
    + 2009-03-15 23:55 . 2001-08-17 12:02 8576 c:\windows\system32\dllcache\hidgame.sys
    - 2009-03-15 23:55 . 2001-08-17 13:02 8576 c:\windows\system32\dllcache\hidgame.sys
    + 2009-02-21 23:03 . 2001-08-17 20:36 7168 c:\windows\system32\dllcache\EXCH_snprfdll.dll
    - 2009-02-21 23:03 . 2001-08-17 21:36 7168 c:\windows\system32\dllcache\EXCH_snprfdll.dll
    + 2009-02-21 23:00 . 2001-08-17 20:36 5632 c:\windows\system32\dllcache\EXCH_adsiisex.dll
    - 2009-02-21 23:00 . 2001-08-17 21:36 5632 c:\windows\system32\dllcache\EXCH_adsiisex.dll
    - 2009-03-15 23:54 . 2001-08-17 12:52 7040 c:\windows\system32\dllcache\exabyte2.sys
    + 2009-03-15 23:54 . 2001-08-17 11:52 7040 c:\windows\system32\dllcache\exabyte2.sys
    + 2009-03-15 23:53 . 2001-08-17 11:53 7296 c:\windows\system32\dllcache\elmsmc.sys
    - 2009-03-15 23:53 . 2001-08-17 12:53 7296 c:\windows\system32\dllcache\elmsmc.sys
    - 2009-03-15 23:53 . 2001-08-17 12:47 8704 c:\windows\system32\dllcache\dot4scan.sys
    + 2009-03-15 23:53 . 2001-08-17 11:47 8704 c:\windows\system32\dllcache\dot4scan.sys
    - 2009-03-15 23:52 . 2008-04-13 23:10 8320 c:\windows\system32\dllcache\dlttape.sys
    + 2009-03-15 23:52 . 2008-04-13 22:10 8320 c:\windows\system32\dllcache\dlttape.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 6216 c:\windows\system32\dllcache\divaci.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 6216 c:\windows\system32\dllcache\divaci.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 6729 c:\windows\system32\dllcache\disrvci.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 6729 c:\windows\system32\dllcache\disrvci.dll
    + 2009-03-15 23:52 . 2001-08-17 11:52 7424 c:\windows\system32\dllcache\ddsmc.sys
    - 2009-03-15 23:52 . 2001-08-17 12:52 7424 c:\windows\system32\dllcache\ddsmc.sys
    - 2009-03-15 23:52 . 2001-08-17 11:19 3584 c:\windows\system32\dllcache\cwcosnt5.sys
    + 2009-03-15 23:52 . 2001-08-17 10:19 3584 c:\windows\system32\dllcache\cwcosnt5.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 3072 c:\windows\system32\dllcache\cwbmidi.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 3072 c:\windows\system32\dllcache\cwbmidi.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 3072 c:\windows\system32\dllcache\cwbase.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 3072 c:\windows\system32\dllcache\cwbase.sys
    - 2009-03-15 23:51 . 2001-08-17 21:36 4096 c:\windows\system32\dllcache\ctwdm32.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 4096 c:\windows\system32\dllcache\ctwdm32.dll
    + 2009-03-15 23:51 . 2001-08-17 10:19 3712 c:\windows\system32\dllcache\ctljystk.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 3712 c:\windows\system32\dllcache\ctljystk.sys
    - 2009-03-15 23:51 . 2001-08-17 11:19 6912 c:\windows\system32\dllcache\ctlfacem.sys
    + 2009-03-15 23:51 . 2001-08-17 10:19 6912 c:\windows\system32\dllcache\ctlfacem.sys
    - 2009-03-15 23:51 . 2001-08-17 12:51 6656 c:\windows\system32\dllcache\cmdide.sys
    + 2009-03-15 23:51 . 2001-08-17 11:51 6656 c:\windows\system32\dllcache\cmdide.sys
    + 2009-03-15 23:51 . 2008-04-13 22:11 8192 c:\windows\system32\dllcache\changer.sys
    - 2009-03-15 23:51 . 2008-04-13 23:11 8192 c:\windows\system32\dllcache\changer.sys
    - 2009-03-15 23:50 . 2001-08-17 12:52 7680 c:\windows\system32\dllcache\cd20xrnt.sys
    + 2009-03-15 23:50 . 2001-08-17 11:52 7680 c:\windows\system32\dllcache\cd20xrnt.sys
    + 2009-03-15 23:49 . 2001-08-17 20:36 9728 c:\windows\system32\dllcache\brserif.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 9728 c:\windows\system32\dllcache\brserif.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 5120 c:\windows\system32\dllcache\brscnrsm.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 5120 c:\windows\system32\dllcache\brscnrsm.dll
    + 2009-03-15 23:49 . 2001-08-17 11:12 3168 c:\windows\system32\dllcache\brparimg.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 3168 c:\windows\system32\dllcache\brparimg.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 3968 c:\windows\system32\dllcache\brfiltup.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 3968 c:\windows\system32\dllcache\brfiltup.sys
    - 2009-03-15 23:49 . 2001-08-17 12:12 2944 c:\windows\system32\dllcache\brfilt.sys
    + 2009-03-15 23:49 . 2001-08-17 11:12 2944 c:\windows\system32\dllcache\brfilt.sys
    - 2009-03-15 23:49 . 2001-08-17 21:36 9728 c:\windows\system32\dllcache\brcoinst.dll
    + 2009-03-15 23:49 . 2001-08-17 20:36 9728 c:\windows\system32\dllcache\brcoinst.dll
    - 2009-03-15 23:48 . 2001-08-17 11:49 9472 c:\windows\system32\dllcache\ativmdcd.sys
    + 2009-03-15 23:48 . 2001-08-17 10:49 9472 c:\windows\system32\dllcache\ativmdcd.sys
    - 2009-03-15 23:47 . 2001-08-17 12:47 6272 c:\windows\system32\dllcache\apmbatt.sys
    + 2009-03-15 23:47 . 2001-08-17 11:47 6272 c:\windows\system32\dllcache\apmbatt.sys
    + 2009-03-15 23:46 . 2001-08-17 11:51 5248 c:\windows\system32\dllcache\aliide.sys
    - 2009-03-15 23:46 . 2001-08-17 12:51 5248 c:\windows\system32\dllcache\aliide.sys
    + 2009-03-15 23:46 . 2008-04-14 03:41 3775 c:\windows\system32\dllcache\adv11nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3775 c:\windows\system32\dllcache\adv11nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 3711 c:\windows\system32\dllcache\adv09nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3711 c:\windows\system32\dllcache\adv09nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 3135 c:\windows\system32\dllcache\adv08nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3135 c:\windows\system32\dllcache\adv08nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3647 c:\windows\system32\dllcache\adv07nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 3647 c:\windows\system32\dllcache\adv07nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 3615 c:\windows\system32\dllcache\adv05nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3615 c:\windows\system32\dllcache\adv05nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 3967 c:\windows\system32\dllcache\adv02nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 3967 c:\windows\system32\dllcache\adv02nt5.dll
    + 2009-03-15 23:46 . 2008-04-14 03:41 4255 c:\windows\system32\dllcache\adv01nt5.dll
    - 2009-03-15 23:46 . 2008-04-14 04:41 4255 c:\windows\system32\dllcache\adv01nt5.dll
    - 2009-03-15 23:46 . 2001-08-17 12:53 7424 c:\windows\system32\dllcache\adicvls.sys
    + 2009-03-15 23:46 . 2001-08-17 11:53 7424 c:\windows\system32\dllcache\adicvls.sys
    + 2009-03-16 00:11 . 2008-04-14 03:42 116224 c:\windows\system32\dllcache\xrxwiadr.dll
    - 2009-03-16 00:11 . 2008-04-14 04:42 116224 c:\windows\system32\dllcache\xrxwiadr.dll
    - 2009-03-16 00:09 . 2008-04-13 21:05 154624 c:\windows\system32\dllcache\wlluc48.sys
    + 2009-03-16 00:09 . 2008-04-13 20:05 154624 c:\windows\system32\dllcache\wlluc48.sys
    - 2009-03-16 00:09 . 2001-08-17 12:28 771581 c:\windows\system32\dllcache\winacisa.sys
    + 2009-03-16 00:09 . 2001-08-17 11:28 771581 c:\windows\system32\dllcache\winacisa.sys
    + 2009-03-16 00:09 . 2001-08-17 11:28 701386 c:\windows\system32\dllcache\wdhaalba.sys
    - 2009-03-16 00:09 . 2001-08-17 12:28 701386 c:\windows\system32\dllcache\wdhaalba.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 397502 c:\windows\system32\dllcache\vpctcom.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 397502 c:\windows\system32\dllcache\vpctcom.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 604253 c:\windows\system32\dllcache\vmodem.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 604253 c:\windows\system32\dllcache\vmodem.sys
    + 2009-03-16 00:08 . 2001-08-17 10:14 249402 c:\windows\system32\dllcache\vinwm.sys
    - 2009-03-16 00:08 . 2001-08-17 11:14 249402 c:\windows\system32\dllcache\vinwm.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 687999 c:\windows\system32\dllcache\usrwdxjs.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 687999 c:\windows\system32\dllcache\usrwdxjs.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 765884 c:\windows\system32\dllcache\usrti.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 765884 c:\windows\system32\dllcache\usrti.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 113762 c:\windows\system32\dllcache\usrpda.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 113762 c:\windows\system32\dllcache\usrpda.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 224802 c:\windows\system32\dllcache\usr1807a.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 224802 c:\windows\system32\dllcache\usr1807a.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 794399 c:\windows\system32\dllcache\usr1806v.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 794399 c:\windows\system32\dllcache\usr1806v.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 793598 c:\windows\system32\dllcache\usr1806.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 793598 c:\windows\system32\dllcache\usr1806.sys
    + 2009-03-16 00:08 . 2001-08-17 11:28 794654 c:\windows\system32\dllcache\usr1801.sys
    - 2009-03-16 00:08 . 2001-08-17 12:28 794654 c:\windows\system32\dllcache\usr1801.sys
    - 2009-03-16 00:08 . 2008-04-13 23:16 121984 c:\windows\system32\dllcache\usbvideo.sys
    + 2009-03-16 00:08 . 2008-04-13 22:16 121984 c:\windows\system32\dllcache\usbvideo.sys
    + 2009-03-16 00:08 . 2001-08-17 20:36 211968 c:\windows\system32\dllcache\um54scan.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 211968 c:\windows\system32\dllcache\um54scan.dll
    + 2009-03-16 00:08 . 2001-08-17 20:36 216064 c:\windows\system32\dllcache\um34scan.dll
    - 2009-03-16 00:08 . 2001-08-17 21:36 216064 c:\windows\system32\dllcache\um34scan.dll
    + 2009-03-16 00:07 . 2001-08-17 10:51 166784 c:\windows\system32\dllcache\tridxpm.sys
    - 2009-03-16 00:07 . 2001-08-17 11:51 166784 c:\windows\system32\dllcache\tridxpm.sys
    + 2009-03-16 00:07 . 2001-08-17 20:36 525568 c:\windows\system32\dllcache\tridxp.dll
    - 2009-03-16 00:07 . 2001-08-17 21:36 525568 c:\windows\system32\dllcache\tridxp.dll
    + 2009-03-16 00:07 . 2001-08-17 10:51 159232 c:\windows\system32\dllcache\tridkbm.sys
    - 2009-03-16 00:07 . 2001-08-17 11:51 159232 c:\windows\system32\dllcache\tridkbm.sys
    + 2009-03-16 00:07 . 2001-08-17 12:56 440576 c:\windows\system32\dllcache\tridkb.dll
    - 2009-03-16 00:07 . 2001-08-17 13:56 440576 c:\windows\system32\dllcache\tridkb.dll
    - 2009-03-16 00:07 . 2001-08-17 11:51 222336 c:\windows\system32\dllcache\trid3dm.sys
    + 2009-03-16 00:07 . 2001-08-17 10:51 222336 c:\windows\system32\dllcache\trid3dm.sys
    + 2009-03-16 00:07 . 2001-08-17 12:56 315520 c:\windows\system32\dllcache\trid3d.dll
    - 2009-03-16 00:07 . 2001-08-17 13:56 315520 c:\windows\system32\dllcache\trid3d.dll
    + 2009-03-16 00:07 . 2001-08-17 12:02 230912 c:\windows\system32\dllcache\tosdvd03.sys
    - 2009-03-16 00:07 . 2001-08-17 13:02 230912 c:\windows\system32\dllcache\tosdvd03.sys
    + 2009-03-16 00:07 . 2001-08-17 12:01 241664 c:\windows\system32\dllcache\tosdvd02.sys
    - 2009-03-16 00:07 . 2001-08-17 13:01 241664 c:\windows\system32\dllcache\tosdvd02.sys
    - 2009-03-16 00:07 . 2001-08-17 11:14 123995 c:\windows\system32\dllcache\tjisdn.sys
    + 2009-03-16 00:07 . 2001-08-17 10:14 123995 c:\windows\system32\dllcache\tjisdn.sys
    + 2009-03-16 00:07 . 2001-08-17 10:51 138528 c:\windows\system32\dllcache\tgiulnt5.sys
    - 2009-03-16 00:07 . 2001-08-17 11:51 138528 c:\windows\system32\dllcache\tgiulnt5.sys
    - 2009-03-16 00:07 . 2008-04-13 23:10 149376 c:\windows\system32\dllcache\tffsport.sys
    + 2009-03-16 00:07 . 2008-04-13 22:10 149376 c:\windows\system32\dllcache\tffsport.sys
    - 2009-03-16 00:07 . 2001-08-17 13:56 172768 c:\windows\system32\dllcache\t2r4disp.dll
    + 2009-03-16 00:07 . 2001-08-17 12:56 172768 c:\windows\system32\dllcache\t2r4disp.dll
    + 2009-03-16 00:06 . 2001-08-17 11:50 103936 c:\windows\system32\dllcache\sx.sys
    - 2009-03-16 00:06 . 2001-08-17 12:50 103936 c:\windows\system32\dllcache\sx.sys
    - 2009-03-16 00:06 . 2001-08-17 21:36 155648 c:\windows\system32\dllcache\stlnprop.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 155648 c:\windows\system32\dllcache\stlnprop.dll
    + 2009-03-16 00:06 . 2001-08-17 10:18 285760 c:\windows\system32\dllcache\stlnata.sys
    - 2009-03-16 00:06 . 2001-08-17 11:18 285760 c:\windows\system32\dllcache\stlnata.sys
    + 2009-03-16 00:06 . 2001-08-17 20:36 106584 c:\windows\system32\dllcache\spdports.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 106584 c:\windows\system32\dllcache\spdports.dll
    + 2009-03-16 00:06 . 2001-08-17 20:36 114688 c:\windows\system32\dllcache\sonypi.dll
    - 2009-03-16 00:06 . 2001-08-17 21:36 114688 c:\windows\system32\dllcache\sonypi.dll
    - 2009-03-16 00:05 . 2001-08-17 13:56 147200 c:\windows\system32\dllcache\smidispb.dll
    + 2009-03-16 00:05 . 2001-08-17 12:56 147200 c:\windows\system32\dllcache\smidispb.dll
    + 2009-03-16 00:05 . 2008-04-13 21:53 404990 c:\windows\system32\dllcache\slntamr.sys
    - 2009-03-16 00:05 . 2008-04-13 22:53 404990 c:\windows\system32\dllcache\slntamr.sys
    + 2009-03-16 00:05 . 2008-04-13 21:53 129535 c:\windows\system32\dllcache\slnt7554.sys
    - 2009-03-16 00:05 . 2008-04-13 22:53 129535 c:\windows\system32\dllcache\slnt7554.sys
    + 2009-03-16 00:05 . 2008-04-14 03:42 188508 c:\windows\system32\dllcache\slgen.dll
    - 2009-03-16 00:05 . 2008-04-14 04:42 188508 c:\windows\system32\dllcache\slgen.dll
    + 2009-03-16 00:05 . 2008-04-14 03:42 286792 c:\windows\system32\dllcache\slextspk.dll
    - 2009-03-16 00:05 . 2008-04-14 04:42 286792 c:\windows\system32\dllcache\slextspk.dll
    - 2009-03-16 00:05 . 2001-08-17 13:56 157696 c:\windows\system32\dllcache\sisv256.dll
    + 2009-03-16 00:05 . 2001-08-17 12:56 157696 c:\windows\system32\dllcache\sisv256.dll
    - 2009-03-16 00:05 . 2001-08-17 21:36 238592 c:\windows\system32\dllcache\sisgrv.dll
    + 2009-03-16 00:05 . 2001-08-17 20:36 238592 c:\windows\system32\dllcache\sisgrv.dll
    - 2009-03-16 00:05 . 2001-08-17 11:50 104064 c:\windows\system32\dllcache\sisgrp.sys
    + 2009-03-16 00:05 . 2001-08-17 10:50 104064 c:\windows\system32\dllcache\sisgrp.sys
    + 2009-03-16 00:05 . 2001-08-17 12:56 150144 c:\windows\system32\dllcache\sis6306v.dll
    - 2009-03-16 00:05 . 2001-08-17 13:56 150144 c:\windows\system32\dllcache\sis6306v.dll
    - 2009-03-16 00:05 . 2001-08-17 13:56 252032 c:\windows\system32\dllcache\sis300iv.dll
    + 2009-03-16 00:05 . 2001-08-17 12:56 252032 c:\windows\system32\dllcache\sis300iv.dll
    + 2009-03-16 00:05 . 2001-08-17 10:50 101760 c:\windows\system32\dllcache\sis300ip.sys
    - 2009-03-16 00:05 . 2001-08-17 11:50 101760 c:\windows\system32\dllcache\sis300ip.sys
    + 2009-03-16 00:04 . 2001-07-21 12:29 161568 c:\windows\system32\dllcache\sgsmusb.sys
    - 2009-03-16 00:04 . 2001-07-21 13:29 161568 c:\windows\system32\dllcache\sgsmusb.sys
    - 2009-03-16 00:04 . 2001-08-17 21:36 386560 c:\windows\system32\dllcache\sgiul50.dll
    + 2009-03-16 00:04 . 2001-08-17 20:36 386560 c:\windows\system32\dllcache\sgiul50.dll
    - 2009-03-16 00:04 . 2001-08-17 21:36 495616 c:\windows\system32\dllcache\sblfx.dll
    + 2009-03-16 00:04 . 2001-08-17 20:36 495616 c:\windows\system32\dllcache\sblfx.dll
    - 2009-03-16 00:04 . 2001-08-17 13:56 245632 c:\windows\system32\dllcache\s3savmx.dll
    + 2009-03-16 00:04 . 2001-08-17 12:56 245632 c:\windows\system32\dllcache\s3savmx.dll
    - 2009-03-16 00:04 . 2001-08-17 13:56 198400 c:\windows\system32\dllcache\s3sav4.dll
    + 2009-03-16 00:04 . 2001-08-17 12:56 198400 c:\windows\system32\dllcache\s3sav4.dll
    - 2009-03-16 00:04 . 2001-08-17 13:56 179264 c:\windows\system32\dllcache\s3sav3d.dll
    + 2009-03-16 00:04 . 2001-08-17 12:56 179264 c:\windows\system32\dllcache\s3sav3d.dll
    - 2009-03-16 00:04 . 2001-08-17 13:56 210496 c:\windows\system32\dllcache\s3mvirge.dll
    + 2009-03-16 00:04 . 2001-08-17 12:56 210496 c:\windows\system32\dllcache\s3mvirge.dll
    + 2009-03-16 00:04 . 2001-08-17 12:56 182272 c:\windows\system32\dllcache\s3mt3d.dll
    - 2009-03-16 00:04 . 2001-08-17 13:56 182272 c:\windows\system32\dllcache\s3mt3d.dll
    + 2009-03-16 00:04 . 2001-08-17 10:50 166720 c:\windows\system32\dllcache\s3m.sys
    - 2009-03-16 00:04 . 2001-08-17 11:50 166720 c:\windows\system32\dllcache\s3m.sys
    + 2009-03-16 00:04 . 2008-04-13 20:04 166912 c:\windows\system32\dllcache\s3gnbm.sys
    - 2009-03-16 00:04 . 2008-04-13 21:04 166912 c:\windows\system32\dllcache\s3gnbm.sys
    - 2009-03-16 00:04 . 2008-04-14 04:42 397056 c:\windows\system32\dllcache\s3gnb.dll
    + 2009-03-16 00:04 . 2008-04-14 03:42 397056 c:\windows\system32\dllcache\s3gnb.dll
    - 2009-03-16 00:03 . 2001-08-17 12:28 714762 c:\windows\system32\dllcache\r2mdmkxx.sys
    + 2009-03-16 00:03 . 2001-08-17 11:28 714762 c:\windows\system32\dllcache\r2mdmkxx.sys
    + 2009-03-16 00:03 . 2001-08-17 11:28 899146 c:\windows\system32\dllcache\r2mdkxga.sys
    - 2009-03-16 00:03 . 2001-08-17 12:28 899146 c:\windows\system32\dllcache\r2mdkxga.sys
    + 2009-03-16 00:03 . 2001-08-17 11:28 130942 c:\windows\system32\dllcache\ptserlv.sys
    - 2009-03-16 00:03 . 2001-08-17 12:28 130942 c:\windows\system32\dllcache\ptserlv.sys
    - 2009-03-16 00:03 . 2001-08-17 12:28 112574 c:\windows\system32\dllcache\ptserlp.sys
    + 2009-03-16 00:03 . 2001-08-17 11:28 112574 c:\windows\system32\dllcache\ptserlp.sys
    - 2009-03-16 00:03 . 2001-08-17 12:28 128286 c:\windows\system32\dllcache\ptserli.sys
    + 2009-03-16 00:03 . 2001-08-17 11:28 128286 c:\windows\system32\dllcache\ptserli.sys
    + 2009-03-16 00:03 . 2008-04-14 03:42 159232 c:\windows\system32\dllcache\ptpusd.dll
    - 2009-03-16 00:03 . 2008-04-14 04:42 159232 c:\windows\system32\dllcache\ptpusd.dll
    + 2009-03-16 00:03 . 2008-04-14 03:42 363520 c:\windows\system32\dllcache\psisdecd.dll
    - 2009-03-16 00:03 . 2008-04-14 04:42 363520 c:\windows\system32\dllcache\psisdecd.dll
    + 2009-03-16 00:02 . 2001-08-17 20:36 121344 c:\windows\system32\dllcache\phvfwext.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 121344 c:\windows\system32\dllcache\phvfwext.dll
    - 2009-03-16 00:02 . 2001-08-17 13:04 173696 c:\windows\system32\dllcache\philcam2.sys
    + 2009-03-16 00:02 . 2001-08-17 12:04 173696 c:\windows\system32\dllcache\philcam2.sys
    - 2009-03-16 00:02 . 2008-04-14 04:40 259328 c:\windows\system32\dllcache\perm3dd.dll
    + 2009-03-16 00:02 . 2008-04-14 03:40 259328 c:\windows\system32\dllcache\perm3dd.dll
    - 2009-03-16 00:02 . 2008-04-14 04:40 211584 c:\windows\system32\dllcache\perm2dll.dll
    + 2009-03-16 00:02 . 2008-04-14 03:40 211584 c:\windows\system32\dllcache\perm2dll.dll
    - 2009-03-16 00:02 . 2008-04-13 20:42 169984 c:\windows\system32\dllcache\pcx500.sys
    + 2009-03-16 00:02 . 2008-04-13 19:42 169984 c:\windows\system32\dllcache\pcx500.sys
    + 2009-03-16 00:02 . 2001-08-17 12:05 351616 c:\windows\system32\dllcache\ovcodek2.sys
    - 2009-03-16 00:02 . 2001-08-17 13:05 351616 c:\windows\system32\dllcache\ovcodek2.sys
    + 2009-03-16 00:02 . 2001-08-17 20:36 116736 c:\windows\system32\dllcache\ovcodec2.dll
    - 2009-03-16 00:02 . 2001-08-17 21:36 116736 c:\windows\system32\dllcache\ovcodec2.dll
    - 2009-03-16 00:01 . 2001-08-17 11:50 198144 c:\windows\system32\dllcache\nv3.sys
    + 2009-03-16 00:01 . 2001-08-17 10:50 198144 c:\windows\system32\dllcache\nv3.sys
    + 2009-03-16 00:01 . 2001-08-17 20:36 123776 c:\windows\system32\dllcache\nv3.dll
    - 2009-03-16 00:01 . 2001-08-17 21:36 123776 c:\windows\system32\dllcache\nv3.dll
    + 2009-03-16 00:01 . 2008-04-13 21:53 180360 c:\windows\system32\dllcache\ntmtlfax.sys
    - 2009-03-16 00:01 . 2008-04-13 22:53 180360 c:\windows\system32\dllcache\ntmtlfax.sys
    + 2009-03-16 00:01 . 2001-08-17 10:20 126080 c:\windows\system32\dllcache\nm5a2wdm.sys
    - 2009-03-16 00:01 . 2001-08-17 11:20 126080 c:\windows\system32\dllcache\nm5a2wdm.sys
    - 2009-03-16 00:01 . 2008-04-13 21:05 132695 c:\windows\system32\dllcache\netwlan5.sys
    + 2009-03-16 00:01 . 2008-04-13 20:05 132695 c:\windows\system32\dllcache\netwlan5.sys
    - 2009-03-16 00:01 . 2001-08-17 11:11 128000 c:\windows\system32\dllcache\n100325.sys
    + 2009-03-16 00:01 . 2001-08-17 10:11 128000 c:\windows\system32\dllcache\n100325.sys
    - 2009-03-16 00:00 . 2001-08-17 11:50 103296 c:\windows\system32\dllcache\mtxvideo.sys
    + 2009-03-16 00:00 . 2001-08-17 10:50 103296 c:\windows\system32\dllcache\mtxvideo.sys
    + 2009-03-16 00:00 . 2008-04-13 20:04 452736 c:\windows\system32\dllcache\mtxparhm.sys
    - 2009-03-16 00:00 . 2008-04-13 21:04 452736 c:\windows\system32\dllcache\mtxparhm.sys
    - 2009-03-16 00:00 . 2008-04-13 22:53 126686 c:\windows\system32\dllcache\mtlmnt5.sys
    + 2009-03-16 00:00 . 2008-04-13 21:53 126686 c:\windows\system32\dllcache\mtlmnt5.sys
    - 2009-03-15 23:59 . 2001-08-17 11:50 320384 c:\windows\system32\dllcache\mgaum.sys
    + 2009-03-15 23:59 . 2001-08-17 10:50 320384 c:\windows\system32\dllcache\mgaum.sys
    + 2009-03-15 23:59 . 2001-08-17 12:56 235648 c:\windows\system32\dllcache\mgaud.dll
    - 2009-03-15 23:59 . 2001-08-17 13:56 235648 c:\windows\system32\dllcache\mgaud.dll
    + 2009-03-15 23:59 . 2001-08-17 10:12 164586 c:\windows\system32\dllcache\mdgndis5.sys
    - 2009-03-15 23:59 . 2001-08-17 11:12 164586 c:\windows\system32\dllcache\mdgndis5.sys
    + 2009-03-15 23:59 . 2001-08-17 11:28 797500 c:\windows\system32\dllcache\ltsmt.sys
    - 2009-03-15 23:59 . 2001-08-17 12:28 797500 c:\windows\system32\dllcache\ltsmt.sys
    + 2009-03-15 23:59 . 2001-08-17 11:28 802683 c:\windows\system32\dllcache\ltsm.sys
    - 2009-03-15 23:59 . 2001-08-17 12:28 802683 c:\windows\system32\dllcache\ltsm.sys
    - 2009-03-15 23:59 . 2008-04-13 22:53 420992 c:\windows\system32\dllcache\ltmdmntt.sys
    + 2009-03-15 23:59 . 2008-04-13 21:53 420992 c:\windows\system32\dllcache\ltmdmntt.sys
    + 2009-03-15 23:59 . 2001-08-17 11:28 576746 c:\windows\system32\dllcache\ltmdmntl.sys
    - 2009-03-15 23:59 . 2001-08-17 12:28 576746 c:\windows\system32\dllcache\ltmdmntl.sys
    + 2009-03-15 23:59 . 2008-04-13 21:53 606684 c:\windows\system32\dllcache\ltmdmnt.sys
    - 2009-03-15 23:59 . 2008-04-13 22:53 606684 c:\windows\system32\dllcache\ltmdmnt.sys
    - 2009-03-15 23:59 . 2001-08-17 12:28 727786 c:\windows\system32\dllcache\ltck000c.sys
    + 2009-03-15 23:59 . 2001-08-17 11:28 727786 c:\windows\system32\dllcache\ltck000c.sys
    + 2009-03-15 23:58 . 2008-04-14 03:41 253952 c:\windows\system32\dllcache\kdsusd.dll
    - 2009-03-15 23:58 . 2008-04-14 04:41 253952 c:\windows\system32\dllcache\kdsusd.dll
    + 2009-03-15 23:56 . 2001-08-17 20:36 372824 c:\windows\system32\dllcache\iconf32.dll
    - 2009-03-15 23:56 . 2001-08-17 21:36 372824 c:\windows\system32\dllcache\iconf32.dll
    - 2009-03-15 23:56 . 2001-08-17 13:06 100992 c:\windows\system32\dllcache\icam5usb.sys
    + 2009-03-15 23:56 . 2001-08-17 12:06 100992 c:\windows\system32\dllcache\icam5usb.sys
    - 2009-03-15 23:56 . 2001-08-17 13:06 154496 c:\windows\system32\dllcache\icam4usb.sys
    + 2009-03-15 23:56 . 2001-08-17 12:06 154496 c:\windows\system32\dllcache\icam4usb.sys
    + 2009-03-15 23:56 . 2001-08-17 12:05 141056 c:\windows\system32\dllcache\icam3.sys
    - 2009-03-15 23:56 . 2001-08-17 13:05 141056 c:\windows\system32\dllcache\icam3.sys
    - 2009-03-15 23:56 . 2001-08-17 11:12 109085 c:\windows\system32\dllcache\ibmtrp.sys
    + 2009-03-15 23:56 . 2001-08-17 10:12 109085 c:\windows\system32\dllcache\ibmtrp.sys
    - 2009-03-15 23:56 . 2001-08-17 11:12 100936 c:\windows\system32\dllcache\ibmtok.sys
    + 2009-03-15 23:56 . 2001-08-17 10:12 100936 c:\windows\system32\dllcache\ibmtok.sys
    - 2009-03-15 23:56 . 2008-04-13 21:04 161020 c:\windows\system32\dllcache\i81xnt5.sys
    + 2009-03-15 23:56 . 2008-04-13 20:04 161020 c:\windows\system32\dllcache\i81xnt5.sys
    - 2009-03-15 23:56 . 2008-04-14 04:41 702845 c:\windows\system32\dllcache\i81xdnt5.dll
    + 2009-03-15 23:56 . 2008-04-14 03:41 702845 c:\windows\system32\dllcache\i81xdnt5.dll
    - 2009-03-15 23:56 . 2001-08-17 13:56 353184 c:\windows\system32\dllcache\i740dnt5.dll
    + 2009-03-15 23:56 . 2001-08-17 12:56 353184 c:\windows\system32\dllcache\i740dnt5.dll
    - 2009-03-15 23:56 . 2008-04-13 22:53 685056 c:\windows\system32\dllcache\hsfcxts2.sys
    + 2009-03-15 23:56 . 2008-04-13 21:53 685056 c:\windows\system32\dllcache\hsfcxts2.sys
    - 2009-03-15 23:56 . 2008-04-13 22:53 220032 c:\windows\system32\dllcache\hsfbs2s2.sys
    + 2009-03-15 23:56 . 2008-04-13 21:53 220032 c:\windows\system32\dllcache\hsfbs2s2.sys
    + 2009-03-15 23:56 . 2001-08-17 11:28 488383 c:\windows\system32\dllcache\hsf_v124.sys
    - 2009-03-15 23:56 . 2001-08-17 12:28 488383 c:\windows\system32\dllcache\hsf_v124.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 542879 c:\windows\system32\dllcache\hsf_msft.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 542879 c:\windows\system32\dllcache\hsf_msft.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 391199 c:\windows\system32\dllcache\hsf_k56k.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 391199 c:\windows\system32\dllcache\hsf_k56k.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 115807 c:\windows\system32\dllcache\hsf_fsks.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 115807 c:\windows\system32\dllcache\hsf_fsks.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 199711 c:\windows\system32\dllcache\hsf_faxx.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 199711 c:\windows\system32\dllcache\hsf_faxx.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 289887 c:\windows\system32\dllcache\hsf_fall.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 289887 c:\windows\system32\dllcache\hsf_fall.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 150239 c:\windows\system32\dllcache\hsf_amos.sys
    - 2009-03-15 23:55 . 2001-08-17 12:28 150239 c:\windows\system32\dllcache\hsf_amos.sys
    - 2009-03-15 23:55 . 2001-08-17 21:36 324608 c:\windows\system32\dllcache\hpojwia.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 324608 c:\windows\system32\dllcache\hpojwia.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 165888 c:\windows\system32\dllcache\hpgt53.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 165888 c:\windows\system32\dllcache\hpgt53.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 126976 c:\windows\system32\dllcache\hpgt34tk.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 126976 c:\windows\system32\dllcache\hpgt34tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 101376 c:\windows\system32\dllcache\hpgt34.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 101376 c:\windows\system32\dllcache\hpgt34.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 123392 c:\windows\system32\dllcache\hpgt21tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 123392 c:\windows\system32\dllcache\hpgt21tk.dll
    - 2009-03-15 23:55 . 2001-08-17 21:36 119296 c:\windows\system32\dllcache\hpdigwia.dll
    + 2009-03-15 23:55 . 2001-08-17 20:36 119296 c:\windows\system32\dllcache\hpdigwia.dll
    - 2009-03-15 23:55 . 2001-08-17 12:28 907456 c:\windows\system32\dllcache\hcf_msft.sys
    + 2009-03-15 23:55 . 2001-08-17 11:28 907456 c:\windows\system32\dllcache\hcf_msft.sys
    - 2009-03-15 23:55 . 2001-08-17 11:49 322432 c:\windows\system32\dllcache\g400m.sys
    + 2009-03-15 23:55 . 2001-08-17 10:49 322432 c:\windows\system32\dllcache\g400m.sys
    + 2009-03-15 23:55 . 2001-08-17 10:49 320384 c:\windows\system32\dllcache\g200m.sys
    - 2009-03-15 23:55 . 2001-08-17 11:49 320384 c:\windows\system32\dllcache\g200m.sys
    + 2009-03-15 23:55 . 2001-08-17 12:56 470144 c:\windows\system32\dllcache\g200d.dll
    - 2009-03-15 23:55 . 2001-08-17 13:56 470144 c:\windows\system32\dllcache\g200d.dll
    + 2009-03-15 23:55 . 2001-08-17 10:15 454912 c:\windows\system32\dllcache\fxusbase.sys
    - 2009-03-15 23:55 . 2001-08-17 11:15 454912 c:\windows\system32\dllcache\fxusbase.sys
    - 2009-03-15 23:54 . 2001-08-17 11:15 455296 c:\windows\system32\dllcache\fusbbase.sys
    + 2009-03-15 23:54 . 2001-08-17 10:15 455296 c:\windows\system32\dllcache\fusbbase.sys
    - 2009-03-15 23:54 . 2001-08-17 11:15 455680 c:\windows\system32\dllcache\fus2base.sys
    + 2009-03-15 23:54 . 2001-08-17 10:15 455680 c:\windows\system32\dllcache\fus2base.sys
    + 2009-03-15 23:54 . 2001-08-17 10:15 442240 c:\windows\system32\dllcache\fpnpbase.sys
    - 2009-03-15 23:54 . 2001-08-17 11:15 442240 c:\windows\system32\dllcache\fpnpbase.sys
    - 2009-02-21 23:00 . 2003-03-24 15:52 208896 c:\windows\system32\dllcache\fpmmcsat.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 208896 c:\windows\system32\dllcache\fpmmcsat.dll
    + 2009-02-21 23:00 . 2004-05-12 22:39 598071 c:\windows\system32\dllcache\fpmmc.dll
    - 2009-02-21 23:00 . 2004-05-12 23:39 598071 c:\windows\system32\dllcache\fpmmc.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 188494 c:\windows\system32\dllcache\fpcount.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 188494 c:\windows\system32\dllcache\fpcount.exe
    - 2009-03-15 23:54 . 2001-08-17 11:14 441728 c:\windows\system32\dllcache\fpcmbase.sys
    + 2009-03-15 23:54 . 2001-08-17 10:14 441728 c:\windows\system32\dllcache\fpcmbase.sys
    - 2009-03-15 23:54 . 2001-08-17 11:14 444416 c:\windows\system32\dllcache\fpcibase.sys
    + 2009-03-15 23:54 . 2001-08-17 10:14 444416 c:\windows\system32\dllcache\fpcibase.sys
    + 2009-02-21 23:00 . 2003-03-24 14:52 109328 c:\windows\system32\dllcache\fp98swin.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 109328 c:\windows\system32\dllcache\fp98swin.exe
    + 2009-02-21 23:00 . 2004-05-12 22:39 876653 c:\windows\system32\dllcache\fp4awel.dll
    - 2009-02-21 23:00 . 2004-05-12 23:39 876653 c:\windows\system32\dllcache\fp4awel.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 102509 c:\windows\system32\dllcache\fp4atxt.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 102509 c:\windows\system32\dllcache\fp4atxt.dll
    - 2009-02-21 23:00 . 2003-03-24 15:52 147513 c:\windows\system32\dllcache\fp4apws.dll
    + 2009-02-21 23:00 . 2003-03-24 14:52 147513 c:\windows\system32\dllcache\fp4apws.dll
    - 2009-02-21 23:00 . 2004-05-12 23:39 184435 c:\windows\system32\dllcache\fp4amsft.dll
    + 2009-02-21 23:00 . 2004-05-12 22:39 184435 c:\windows\system32\dllcache\fp4amsft.dll
    + 2009-03-15 23:54 . 2008-04-13 20:06 137088 c:\windows\system32\dllcache\essm2e.sys
    - 2009-03-15 23:54 . 2008-04-13 21:06 137088 c:\windows\system32\dllcache\essm2e.sys
    + 2009-03-15 23:54 . 2001-08-17 11:28 347550 c:\windows\system32\dllcache\es56tpi.sys
    - 2009-03-15 23:54 . 2001-08-17 12:28 347550 c:\windows\system32\dllcache\es56tpi.sys
    - 2009-03-15 23:53 . 2001-08-17 12:28 594238 c:\windows\system32\dllcache\es56hpi.sys
    + 2009-03-15 23:53 . 2001-08-17 11:28 594238 c:\windows\system32\dllcache\es56hpi.sys
    - 2009-03-15 23:53 . 2001-08-17 12:28 595647 c:\windows\system32\dllcache\es56cvmp.sys
    + 2009-03-15 23:53 . 2001-08-17 11:28 595647 c:\windows\system32\dllcache\es56cvmp.sys
    + 2009-03-15 23:53 . 2001-08-17 10:19 174464 c:\windows\system32\dllcache\es198x.sys
    - 2009-03-15 23:53 . 2001-08-17 11:19 174464 c:\windows\system32\dllcache\es198x.sys
    - 2009-03-15 23:53 . 2001-08-17 11:17 629952 c:\windows\system32\dllcache\eqn.sys
    + 2009-03-15 23:53 . 2001-08-17 10:17 629952 c:\windows\system32\dllcache\eqn.sys
    + 2009-03-15 23:53 . 2001-08-17 11:50 114944 c:\windows\system32\dllcache\epstw2k.sys
    - 2009-03-15 23:53 . 2001-08-17 12:50 114944 c:\windows\system32\dllcache\epstw2k.sys
    - 2009-03-15 23:53 . 2001-08-17 12:50 144896 c:\windows\system32\dllcache\epcfw2k.sys
    + 2009-03-15 23:53 . 2001-08-17 11:50 144896 c:\windows\system32\dllcache\epcfw2k.sys
    + 2009-03-15 23:53 . 2001-08-17 10:19 283904 c:\windows\system32\dllcache\emu10k1m.sys
    - 2009-03-15 23:53 . 2001-08-17 11:19 283904 c:\windows\system32\dllcache\emu10k1m.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 171520 c:\windows\system32\dllcache\el99xn51.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 171520 c:\windows\system32\dllcache\el99xn51.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 455199 c:\windows\system32\dllcache\el985n51.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 455199 c:\windows\system32\dllcache\el985n51.sys
    + 2009-03-15 23:53 . 2001-08-17 10:11 153631 c:\windows\system32\dllcache\el90xnd5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:11 153631 c:\windows\system32\dllcache\el90xnd5.sys
    + 2009-03-15 23:53 . 2001-08-17 11:28 241206 c:\windows\system32\dllcache\el656se5.sys
    - 2009-03-15 23:53 . 2001-08-17 12:28 241206 c:\windows\system32\dllcache\el656se5.sys
    - 2009-03-15 23:53 . 2001-08-17 12:28 634134 c:\windows\system32\dllcache\el656ct5.sys
    + 2009-03-15 23:53 . 2001-08-17 11:28 634134 c:\windows\system32\dllcache\el656ct5.sys
    - 2009-03-15 23:53 . 2001-08-17 11:12 117760 c:\windows\system32\dllcache\e100b325.sys
    + 2009-03-15 23:53 . 2001-08-17 10:12 117760 c:\windows\system32\dllcache\e100b325.sys
    - 2009-03-15 23:53 . 2001-08-17 11:20 334208 c:\windows\system32\dllcache\ds1wdm.sys
    + 2009-03-15 23:53 . 2001-08-17 10:20 334208 c:\windows\system32\dllcache\ds1wdm.sys
    + 2009-03-15 23:53 . 2008-04-13 22:09 206976 c:\windows\system32\dllcache\dot4.sys
    - 2009-03-15 23:53 . 2008-04-13 23:09 206976 c:\windows\system32\dllcache\dot4.sys
    + 2009-03-15 23:52 . 2001-08-17 10:14 952007 c:\windows\system32\dllcache\diwan.sys
    - 2009-03-15 23:52 . 2001-08-17 11:14 952007 c:\windows\system32\dllcache\diwan.sys
    - 2009-03-15 23:52 . 2001-08-17 21:36 236060 c:\windows\system32\dllcache\ditrace.exe
    + 2009-03-15 23:52 . 2001-08-17 20:36 236060 c:\windows\system32\dllcache\ditrace.exe
    + 2009-03-15 23:52 . 2001-08-17 20:36 614429 c:\windows\system32\dllcache\digiview.exe
    - 2009-03-15 23:52 . 2001-08-17 21:36 614429 c:\windows\system32\dllcache\digiview.exe
    - 2009-03-15 23:52 . 2001-08-17 21:36 110621 c:\windows\system32\dllcache\digirlpt.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 110621 c:\windows\system32\dllcache\digirlpt.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 102484 c:\windows\system32\dllcache\digiinf.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 102484 c:\windows\system32\dllcache\digiinf.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 159828 c:\windows\system32\dllcache\digihlc.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 159828 c:\windows\system32\dllcache\digihlc.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 229462 c:\windows\system32\dllcache\digifwrk.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 229462 c:\windows\system32\dllcache\digifwrk.dll
    + 2009-03-15 23:52 . 2001-08-17 10:13 103044 c:\windows\system32\dllcache\digidxb.sys
    - 2009-03-15 23:52 . 2001-08-17 11:13 103044 c:\windows\system32\dllcache\digidxb.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 131156 c:\windows\system32\dllcache\digidbp.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 131156 c:\windows\system32\dllcache\digidbp.dll
    + 2009-03-15 23:50 . 2001-08-17 10:13 164923 c:\windows\system32\dllcache\diapi2.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 164923 c:\windows\system32\dllcache\diapi2.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 419357 c:\windows\system32\dllcache\dgconfig.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 419357 c:\windows\system32\dllcache\dgconfig.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 256512 c:\windows\system32\dllcache\devcon32.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 256512 c:\windows\system32\dllcache\devcon32.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 110592 c:\windows\system32\dllcache\dc260usd.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 110592 c:\windows\system32\dllcache\dc260usd.dll
    + 2009-03-15 23:52 . 2001-08-17 11:52 179584 c:\windows\system32\dllcache\dac2w2k.sys
    - 2009-03-15 23:52 . 2001-08-17 12:52 179584 c:\windows\system32\dllcache\dac2w2k.sys
    - 2009-03-15 23:52 . 2001-08-17 11:12 117760 c:\windows\system32\dllcache\d100ib5.sys
    + 2009-03-15 23:52 . 2001-08-17 10:12 117760 c:\windows\system32\dllcache\d100ib5.sys
    - 2009-03-15 23:52 . 2001-08-17 11:19 111872 c:\windows\system32\dllcache\cwcspud.sys
    + 2009-03-15 23:52 . 2001-08-17 10:19 111872 c:\windows\system32\dllcache\cwcspud.sys
    - 2009-03-15 23:51 . 2008-04-14 04:41 249856 c:\windows\system32\dllcache\ctmasetp.dll
    + 2009-03-15 23:51 . 2008-04-14 03:41 249856 c:\windows\system32\dllcache\ctmasetp.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 175104 c:\windows\system32\dllcache\csamsp.dll
    - 2009-03-15 23:51 . 2001-08-17 21:36 175104 c:\windows\system32\dllcache\csamsp.dll
    - 2009-03-15 23:51 . 2001-08-17 21:36 216064 c:\windows\system32\dllcache\cpscan.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 216064 c:\windows\system32\dllcache\cpscan.dll
    - 2009-03-15 23:51 . 2001-08-17 12:57 248064 c:\windows\system32\dllcache\cl546xm.sys
     
  12. 2010/08/11
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    + 2009-03-15 23:51 . 2001-08-17 11:57 248064 c:\windows\system32\dllcache\cl546xm.sys
    - 2009-03-15 23:51 . 2001-08-17 13:56 170880 c:\windows\system32\dllcache\cl546x.dll
    + 2009-03-15 23:51 . 2001-08-17 12:56 170880 c:\windows\system32\dllcache\cl546x.dll
    + 2009-03-15 23:51 . 2001-08-17 12:56 111232 c:\windows\system32\dllcache\cl5465.dll
    - 2009-03-15 23:51 . 2001-08-17 13:56 111232 c:\windows\system32\dllcache\cl5465.dll
    + 2009-03-15 23:51 . 2001-08-17 12:02 272640 c:\windows\system32\dllcache\cinemclc.sys
    - 2009-03-15 23:51 . 2001-08-17 13:02 272640 c:\windows\system32\dllcache\cinemclc.sys
    + 2009-03-15 23:51 . 2001-08-17 10:13 980034 c:\windows\system32\dllcache\cicap.sys
    - 2009-03-15 23:51 . 2001-08-17 11:13 980034 c:\windows\system32\dllcache\cicap.sys
    + 2009-02-21 23:00 . 2003-03-24 14:52 188480 c:\windows\system32\dllcache\cfgwiz.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 188480 c:\windows\system32\dllcache\cfgwiz.exe
    + 2009-03-15 23:50 . 2001-08-17 11:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys
    - 2009-03-15 23:50 . 2001-08-17 12:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys
    - 2009-03-15 23:50 . 2008-04-14 04:41 121856 c:\windows\system32\dllcache\camext30.dll
    + 2009-03-15 23:50 . 2008-04-14 03:41 121856 c:\windows\system32\dllcache\camext30.dll
    - 2009-03-15 23:50 . 2001-08-17 21:36 236032 c:\windows\system32\dllcache\camext20.dll
    + 2009-03-15 23:50 . 2001-08-17 20:36 236032 c:\windows\system32\dllcache\camext20.dll
    + 2009-03-15 23:50 . 2001-08-17 12:04 171264 c:\windows\system32\dllcache\camdrv30.sys
    - 2009-03-15 23:50 . 2001-08-17 13:04 171264 c:\windows\system32\dllcache\camdrv30.sys
    - 2009-03-15 23:50 . 2001-08-17 13:04 223232 c:\windows\system32\dllcache\camdrv21.sys
    + 2009-03-15 23:50 . 2001-08-17 12:04 223232 c:\windows\system32\dllcache\camdrv21.sys
    - 2009-03-15 23:50 . 2001-08-17 13:05 314752 c:\windows\system32\dllcache\camdro21.sys
    + 2009-03-15 23:50 . 2001-08-17 12:05 314752 c:\windows\system32\dllcache\camdro21.sys
    + 2009-03-15 23:49 . 2001-08-17 20:36 102400 c:\windows\system32\dllcache\binlsvc.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 102400 c:\windows\system32\dllcache\binlsvc.dll
    + 2009-03-15 23:49 . 2001-08-17 11:28 871388 c:\windows\system32\dllcache\bcmdm.sys
    - 2009-03-15 23:49 . 2001-08-17 12:28 871388 c:\windows\system32\dllcache\bcmdm.sys
    \system32\dllcache\digiview.exe
    - 2009-03-15 23:52 . 2001-08-17 21:36 110621 c:\windows\system32\dllcache\digirlpt.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 110621 c:\windows\system32\dllcache\digirlpt.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 102484 c:\windows\system32\dllcache\digiinf.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 102484 c:\windows\system32\dllcache\digiinf.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 159828 c:\windows\system32\dllcache\digihlc.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 159828 c:\windows\system32\dllcache\digihlc.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 229462 c:\windows\system32\dllcache\digifwrk.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 229462 c:\windows\system32\dllcache\digifwrk.dll
    + 2009-03-15 23:52 . 2001-08-17 10:13 103044 c:\windows\system32\dllcache\digidxb.sys
    - 2009-03-15 23:52 . 2001-08-17 11:13 103044 c:\windows\system32\dllcache\digidxb.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 131156 c:\windows\system32\dllcache\digidbp.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 131156 c:\windows\system32\dllcache\digidbp.dll
    + 2009-03-15 23:50 . 2001-08-17 10:13 164923 c:\windows\system32\dllcache\diapi2.sys
    - 2009-03-15 23:50 . 2001-08-17 11:13 164923 c:\windows\system32\dllcache\diapi2.sys
    + 2009-03-15 23:52 . 2001-08-17 20:36 419357 c:\windows\system32\dllcache\dgconfig.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 419357 c:\windows\system32\dllcache\dgconfig.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 256512 c:\windows\system32\dllcache\devcon32.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 256512 c:\windows\system32\dllcache\devcon32.dll
    + 2009-03-15 23:52 . 2001-08-17 20:36 110592 c:\windows\system32\dllcache\dc260usd.dll
    - 2009-03-15 23:52 . 2001-08-17 21:36 110592 c:\windows\system32\dllcache\dc260usd.dll
    + 2009-03-15 23:52 . 2001-08-17 11:52 179584 c:\windows\system32\dllcache\dac2w2k.sys
    - 2009-03-15 23:52 . 2001-08-17 12:52 179584 c:\windows\system32\dllcache\dac2w2k.sys
    - 2009-03-15 23:52 . 2001-08-17 11:12 117760 c:\windows\system32\dllcache\d100ib5.sys
    + 2009-03-15 23:52 . 2001-08-17 10:12 117760 c:\windows\system32\dllcache\d100ib5.sys
    - 2009-03-15 23:52 . 2001-08-17 11:19 111872 c:\windows\system32\dllcache\cwcspud.sys
    + 2009-03-15 23:52 . 2001-08-17 10:19 111872 c:\windows\system32\dllcache\cwcspud.sys
    - 2009-03-15 23:51 . 2008-04-14 04:41 249856 c:\windows\system32\dllcache\ctmasetp.dll
    + 2009-03-15 23:51 . 2008-04-14 03:41 249856 c:\windows\system32\dllcache\ctmasetp.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 175104 c:\windows\system32\dllcache\csamsp.dll
    - 2009-03-15 23:51 . 2001-08-17 21:36 175104 c:\windows\system32\dllcache\csamsp.dll
    - 2009-03-15 23:51 . 2001-08-17 21:36 216064 c:\windows\system32\dllcache\cpscan.dll
    + 2009-03-15 23:51 . 2001-08-17 20:36 216064 c:\windows\system32\dllcache\cpscan.dll
    - 2009-03-15 23:51 . 2001-08-17 12:57 248064 c:\windows\system32\dllcache\cl546xm.sys
    + 2009-03-15 23:51 . 2001-08-17 11:57 248064 c:\windows\system32\dllcache\cl546xm.sys
    - 2009-03-15 23:51 . 2001-08-17 13:56 170880 c:\windows\system32\dllcache\cl546x.dll
    + 2009-03-15 23:51 . 2001-08-17 12:56 170880 c:\windows\system32\dllcache\cl546x.dll
    + 2009-03-15 23:51 . 2001-08-17 12:56 111232 c:\windows\system32\dllcache\cl5465.dll
    - 2009-03-15 23:51 . 2001-08-17 13:56 111232 c:\windows\system32\dllcache\cl5465.dll
    + 2009-03-15 23:51 . 2001-08-17 12:02 272640 c:\windows\system32\dllcache\cinemclc.sys
    - 2009-03-15 23:51 . 2001-08-17 13:02 272640 c:\windows\system32\dllcache\cinemclc.sys
    + 2009-03-15 23:51 . 2001-08-17 10:13 980034 c:\windows\system32\dllcache\cicap.sys
    - 2009-03-15 23:51 . 2001-08-17 11:13 980034 c:\windows\system32\dllcache\cicap.sys
    + 2009-02-21 23:00 . 2003-03-24 14:52 188480 c:\windows\system32\dllcache\cfgwiz.exe
    - 2009-02-21 23:00 . 2003-03-24 15:52 188480 c:\windows\system32\dllcache\cfgwiz.exe
    + 2009-03-15 23:50 . 2001-08-17 11:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys
    - 2009-03-15 23:50 . 2001-08-17 12:28 714698 c:\windows\system32\dllcache\cbmdmkxx.sys
    - 2009-03-15 23:50 . 2008-04-14 04:41 121856 c:\windows\system32\dllcache\camext30.dll
    + 2009-03-15 23:50 . 2008-04-14 03:41 121856 c:\windows\system32\dllcache\camext30.dll
    - 2009-03-15 23:50 . 2001-08-17 21:36 236032 c:\windows\system32\dllcache\camext20.dll
    + 2009-03-15 23:50 . 2001-08-17 20:36 236032 c:\windows\system32\dllcache\camext20.dll
    + 2009-03-15 23:50 . 2001-08-17 12:04 171264 c:\windows\system32\dllcache\camdrv30.sys
    - 2009-03-15 23:50 . 2001-08-17 13:04 171264 c:\windows\system32\dllcache\camdrv30.sys
    - 2009-03-15 23:50 . 2001-08-17 13:04 223232 c:\windows\system32\dllcache\camdrv21.sys
    + 2009-03-15 23:50 . 2001-08-17 12:04 223232 c:\windows\system32\dllcache\camdrv21.sys
    - 2009-03-15 23:50 . 2001-08-17 13:05 314752 c:\windows\system32\dllcache\camdro21.sys
    + 2009-03-15 23:50 . 2001-08-17 12:05 314752 c:\windows\system32\dllcache\camdro21.sys
    + 2009-03-15 23:49 . 2001-08-17 20:36 102400 c:\windows\system32\dllcache\binlsvc.dll
    - 2009-03-15 23:49 . 2001-08-17 21:36 102400 c:\windows\system32\dllcache\binlsvc.dll
    + 2009-03-15 23:49 . 2001-08-17 11:28 871388 c:\windows\system32\dllcache\bcmdm.sys
    - 2009-03-15 23:49 . 2001-08-17 12:28 871388 c:\windows\system32\dllcache\bcmdm.sys

    + 2009-03-15 23:48 . 2001-08-17 12:56 342336 c:\windows\system32\dllcache\banshee.dll
    - 2009-03-15 23:48 . 2001-08-17 13:56 342336 c:\windows\system32\dllcache\banshee.dll
    + 2009-03-15 23:48 . 2001-08-17 20:36 144384 c:\windows\system32\dllcache\avmenum.dll
    - 2009-03-15 23:48 . 2001-08-17 21:36 144384 c:\windows\system32\dllcache\avmenum.dll
    + 2009-03-15 23:48 . 2008-04-14 03:41 516768 c:\windows\system32\dllcache\ativvaxx.dll
    - 2009-03-15 23:48 . 2008-04-14 04:41 516768 c:\windows\system32\dllcache\ativvaxx.dll
    - 2009-03-15 23:48 . 2001-08-17 13:56 104832 c:\windows\system32\dllcache\atiraged.dll
    + 2009-03-15 23:48 . 2001-08-17 12:56 104832 c:\windows\system32\dllcache\atiraged.dll
    - 2009-03-15 23:47 . 2008-04-13 21:04 104960 c:\windows\system32\dllcache\atinrvxx.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 104960 c:\windows\system32\dllcache\atinrvxx.sys
    + 2009-03-15 23:47 . 2001-08-17 10:48 281600 c:\windows\system32\dllcache\atimtai.sys
    - 2009-03-15 23:47 . 2001-08-17 11:48 281600 c:\windows\system32\dllcache\atimtai.sys
    - 2009-03-15 23:47 . 2001-08-17 11:48 289664 c:\windows\system32\dllcache\atimpab.sys
    + 2009-03-15 23:47 . 2001-08-17 10:48 289664 c:\windows\system32\dllcache\atimpab.sys
    - 2009-03-15 23:47 . 2001-08-17 13:56 268160 c:\windows\system32\dllcache\atidvai.dll
    + 2009-03-15 23:47 . 2001-08-17 12:56 268160 c:\windows\system32\dllcache\atidvai.dll
    - 2009-03-15 23:47 . 2001-08-17 13:56 137216 c:\windows\system32\dllcache\atidrae.dll
    + 2009-03-15 23:47 . 2001-08-17 12:56 137216 c:\windows\system32\dllcache\atidrae.dll
    - 2009-03-15 23:47 . 2001-08-17 13:55 382592 c:\windows\system32\dllcache\atidrab.dll
    + 2009-03-15 23:47 . 2001-08-17 12:55 382592 c:\windows\system32\dllcache\atidrab.dll
    + 2009-03-15 23:47 . 2008-04-14 03:41 870784 c:\windows\system32\dllcache\ati3d1ag.dll
    - 2009-03-15 23:47 . 2008-04-14 04:41 870784 c:\windows\system32\dllcache\ati3d1ag.dll
    - 2009-03-15 23:47 . 2008-04-13 21:04 701440 c:\windows\system32\dllcache\ati2mtag.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 701440 c:\windows\system32\dllcache\ati2mtag.sys
    - 2009-03-15 23:47 . 2008-04-13 21:04 327040 c:\windows\system32\dllcache\ati2mtaa.sys
    + 2009-03-15 23:47 . 2008-04-13 20:04 327040 c:\windows\system32\dllcache\ati2mtaa.sys
    + 2009-03-15 23:47 . 2008-04-14 03:41 201728 c:\windows\system32\dllcache\ati2dvag.dll
    - 2009-03-15 23:47 . 2008-04-14 04:41 201728 c:\windows\system32\dllcache\ati2dvag.dll
    - 2009-03-15 23:47 . 2008-04-14 04:41 377984 c:\windows\system32\dllcache\ati2dvaa.dll
    + 2009-03-15 23:47 . 2008-04-14 03:41 377984 c:\windows\system32\dllcache\ati2dvaa.dll
    + 2009-03-15 23:47 . 2008-04-14 03:41 229376 c:\windows\system32\dllcache\ati2cqag.dll
    - 2009-03-15 23:47 . 2008-04-14 04:41 229376 c:\windows\system32\dllcache\ati2cqag.dll
    + 2009-03-15 23:46 . 2001-08-17 12:07 101888 c:\windows\system32\dllcache\adpu160m.sys
    - 2009-03-15 23:46 . 2001-08-17 13:07 101888 c:\windows\system32\dllcache\adpu160m.sys
    + 2009-03-15 23:46 . 2001-08-17 10:19 747392 c:\windows\system32\dllcache\adm8830.sys
    - 2009-03-15 23:46 . 2001-08-17 11:19 747392 c:\windows\system32\dllcache\adm8830.sys
    - 2009-03-15 23:46 . 2001-08-17 11:19 553984 c:\windows\system32\dllcache\adm8820.sys
    + 2009-03-15 23:46 . 2001-08-17 10:19 553984 c:\windows\system32\dllcache\adm8820.sys
    - 2009-03-15 23:46 . 2001-08-17 11:19 584448 c:\windows\system32\dllcache\adm8810.sys
    + 2009-03-15 23:46 . 2001-08-17 10:19 584448 c:\windows\system32\dllcache\adm8810.sys
    - 2009-03-15 23:46 . 2001-08-17 11:20 297728 c:\windows\system32\dllcache\ac97sis.sys
    + 2009-03-15 23:46 . 2001-08-17 10:20 297728 c:\windows\system32\dllcache\ac97sis.sys
    + 2009-03-15 23:45 . 2008-04-13 20:06 231552 c:\windows\system32\dllcache\ac97ali.sys
    - 2009-03-15 23:45 . 2008-04-13 21:06 231552 c:\windows\system32\dllcache\ac97ali.sys
    - 2009-03-15 23:45 . 2001-08-17 21:36 462848 c:\windows\system32\dllcache\a3dapi.dll
    + 2009-03-15 23:45 . 2001-08-17 20:36 462848 c:\windows\system32\dllcache\a3dapi.dll
    - 2009-03-15 23:45 . 2001-08-17 11:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys
    + 2009-03-15 23:45 . 2001-08-17 10:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys
    + 2009-03-15 23:45 . 2001-08-17 12:55 689216 c:\windows\system32\dllcache\3dfxvs.dll
    - 2009-03-15 23:45 . 2001-08-17 13:55 689216 c:\windows\system32\dllcache\3dfxvs.dll
    + 2009-03-15 23:45 . 2001-08-17 11:28 762780 c:\windows\system32\dllcache\3cwmcru.sys
    - 2009-03-15 23:45 . 2001-08-17 12:28 762780 c:\windows\system32\dllcache\3cwmcru.sys
    + 2009-03-16 00:01 . 2008-04-13 22:01 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
    - 2009-03-16 00:01 . 2008-04-13 23:01 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
    + 2009-03-15 23:44 . 2008-04-13 22:54 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
    - 2009-03-15 23:44 . 2008-04-13 23:54 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
    + 2009-03-16 00:00 . 2008-04-14 03:42 1737856 c:\windows\system32\dllcache\mtxparhd.dll
    - 2009-03-16 00:00 . 2008-04-14 04:42 1737856 c:\windows\system32\dllcache\mtxparhd.dll
    - 2009-03-16 00:00 . 2008-04-13 22:53 1309184 c:\windows\system32\dllcache\mtlstrm.sys
    + 2009-03-16 00:00 . 2008-04-13 21:53 1309184 c:\windows\system32\dllcache\mtlstrm.sys
    - 2009-03-15 23:56 . 2008-04-13 22:53 1041536 c:\windows\system32\dllcache\hsfdpsp2.sys
    + 2009-03-15 23:56 . 2008-04-13 21:53 1041536 c:\windows\system32\dllcache\hsfdpsp2.sys
    + 2009-03-15 23:55 . 2001-08-17 12:56 1733120 c:\windows\system32\dllcache\g400d.dll
    - 2009-03-15 23:55 . 2001-08-17 13:56 1733120 c:\windows\system32\dllcache\g400d.dll
    - 2009-03-15 23:47 . 2008-04-14 04:41 1888992 c:\windows\system32\dllcache\ati3duag.dll
    + 2009-03-15 23:47 . 2008-04-14 03:41 1888992 c:\windows\system32\dllcache\ati3duag.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ProxyFirewall "= "c:\program files\ProxyFirewall\ProxyFirewall.exe" [2006-03-26 431104]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "C-Media Mixer "= "Mixer.exe" [2003-03-20 1855488]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "TWCU "= "c:\program files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe" [2009-08-14 569427]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
    "nwiz "= "nwiz.exe" [2005-12-10 1519616]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
    "SW24 "= "c:\windows\system32\sw24.exe" [2006-04-04 69632]
    "SW20 "= "c:\windows\system32\sw20.exe" [2006-04-04 208896]
    "SMSERIAL "= "c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
    "Di dictionary "= "c:\program files\Di recnik\Di.exe" [2007-03-16 518656]
    "BtTray "= "c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\CTFMON.EXE" [2008-11-27 15360]

    c:\documents and settings\Woolfer\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
    Shortcut to Pihatonttu.lnk - c:\documents and settings\Woolfer\Desktop\Folders\netoverbt\New Folder\Hiisi1.6.3\Pihatonttu\Pihatonttu.cmd [2010-5-22 112]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    TSS Instrument API Tray Utility.lnk - c:\program files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe [2007-12-7 77824]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @= "Driver "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "vsmon "=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Nokia\\Tss\\Instrument API\\bin\\root.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "c:\\Program Files\\seba14mods\\µtorrent 1.8.2 (build 14458) Leecher Pack\\utorrent 1.8.2 (14458)_stealth.exe "=
    "c:\\Program Files\\A4Proxy\\A4Proxy.exe "=
    "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe "=
    "c:\\Program Files\\ODEON\\JAF\\JCOP.EXE "=
    "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\WINDOWS\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DVBViewerTE\\ts_winlirc.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5232:TCP "= 5232:TCP:zgveo

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [4/6/2010 6:32 PM 20744]
    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [9/24/2007 7:11 PM 566560]
    R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2/27/2009 4:40 PM 143467]
    R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [4/22/2010 12:34 AM 10454]
    R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [3/6/2010 12:07 AM 1668352]
    R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [4/6/2010 6:33 PM 30088]
    R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [4/6/2010 6:32 PM 26248]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [7/2/2008 12:15 AM 418832]
    S2 CachemanService;Cacheman Service;c:\program files\Cacheman\CachemanServ.exe --> c:\program files\Cacheman\CachemanServ.exe [?]
    S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys --> c:\windows\system32\DRIVERS\btcomport.sys [?]
    S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys --> c:\windows\system32\Drivers\btcombus.sys [?]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5/31/2010 9:16 PM 136704]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5/31/2010 9:16 PM 8320]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/26/2009 11:08 PM 717296]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    nxfgt
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-08 c:\windows\Tasks\shutdown.job
    - c:\documents and settings\Woolfer\Desktop\shutdown.lnk [2008-07-02 19:03]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uInternet Settings,ProxyServer = 218.29.234.50:3128
    uInternet Settings,ProxyOverride = 127.0.0.1
    IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
    IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} -
    FF - ProfilePath - c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\
    FF - prefs.js: browser.search.selectedEngine - eBay
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.http - 218.29.234.50
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-08-11 11:45
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    ProxyFirewall = c:\program files\ProxyFirewall\ProxyFirewall.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nxfgt]
    "ServiceDll "= "c:\windows\system32\wmrqdl.dll "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-854245398-1383384898-1644491937-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1116)
    c:\windows\system32\athgina.dll
    .
    Completion time: 2010-08-11 11:50:12
    ComboFix-quarantined-files.txt 2010-08-11 09:50
    ComboFix2.txt 2010-08-07 20:13
    ComboFix3.txt 2010-08-06 23:54
    ComboFix4.txt 2010-08-06 23:12
    ComboFix5.txt 2010-08-11 09:33

    Pre-Run: 13.449.412.608 bytes free
    Post-Run: 13.433.872.384 bytes free

    - - End Of File - - 8821DB6C8FAABDEC845E5F17F0D933E9
     
  13. 2010/08/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I can see, you ran Combofix on your own (which is not good) several times.
    I'd like to see ComboFix5.txt located in C:\Qoobox folder
     
  14. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    This will be long post...previus logs (before combofix5) were much shorter...
    ComboFix 09-07-09.08 - Woolfer 11.07.2009 22:46.1.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.505 [GMT 2:00]
    Running from: c:\documents and settings\Woolfer\Desktop\ComboFix.exe
    AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\docume~1\Woolfer\LOCALS~1\Temp\tmp2.tmp

    .
    ((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
    .

    2009-06-20 11:22 . 2009-06-20 19:30 -------- d-----w- c:\program files\ProgDVB
    2009-06-17 22:56 . 2009-06-17 22:56 -------- d-----w- c:\program files\Monte Cristo

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-07-11 21:39 . 2009-03-10 10:43 54627360 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2009-07-11 21:38 . 2009-03-20 03:23 -------- d-----w- c:\program files\Di recnik
    2009-07-11 21:37 . 2009-03-10 10:43 2141472 --sha-w- c:\windows\system32\drivers\fidbox2.dat
    2009-07-11 21:03 . 2009-03-10 10:43 735704 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2009-07-11 21:03 . 2009-03-10 10:43 204896 --sha-w- c:\windows\system32\drivers\fidbox2.idx
    2009-07-11 19:42 . 2009-03-10 10:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
    2009-07-11 11:57 . 2009-05-26 11:54 -------- d-----w- c:\documents and settings\Woolfer\Application Data\ZoomBrowser EX
    2009-07-09 10:18 . 2009-03-18 13:16 -------- d-----w- c:\program files\Planplus
    2009-07-06 21:22 . 2009-05-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-06-21 14:36 . 2009-06-10 15:30 -------- d-----w- c:\program files\IrfanView
    2009-06-10 20:23 . 2009-04-17 00:19 -------- d-----w- c:\documents and settings\Woolfer\Application Data\onOne Software
    2009-06-10 15:28 . 2009-06-10 15:28 -------- d-----w- c:\program files\ACD Systems
    2009-06-10 14:09 . 2009-06-10 14:09 -------- d-----w- c:\documents and settings\Woolfer\Application Data\ACD Systems
    2009-06-09 21:21 . 2009-02-22 10:24 42560 ----a-w- c:\documents and settings\Woolfer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-06-08 18:05 . 2009-06-08 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\ABBYY
    2009-06-08 18:04 . 2009-06-08 18:04 -------- d-----w- c:\documents and settings\Woolfer\Application Data\ABBYY
    2009-06-08 18:03 . 2009-06-08 17:57 -------- d-----w- c:\program files\ABBYY FineReader 9.0
    2009-06-08 17:16 . 2009-06-08 17:16 -------- d-----w- c:\program files\Microsoft ActiveSync
    2009-06-08 17:11 . 2009-06-08 17:11 -------- d-----w- c:\program files\Microsoft.NET
    2009-06-07 21:20 . 2009-03-23 11:57 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Offline Explorer
    2009-06-06 10:01 . 2009-06-06 10:00 -------- d-----w- c:\program files\Acoustica Spin It Again
    2009-06-06 10:00 . 2009-06-06 10:00 -------- d-----w- c:\program files\Acoustica Shared Effects
    2009-06-05 18:02 . 2009-06-05 18:02 -------- d-----w- c:\program files\VibrateGameDeviceDriver
    2009-05-30 18:05 . 2009-05-30 18:05 -------- d-----w- c:\program files\Electronic Arts
    2009-05-29 20:53 . 2009-05-29 20:53 -------- d-----w- c:\program files\THQ
    2009-05-29 20:53 . 2009-03-03 21:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-05-29 14:26 . 2009-05-29 14:25 -------- d-----w- c:\program files\Hard Truck 18 Wheels
    2009-05-29 14:25 . 2009-02-27 12:17 -------- d-----w- c:\program files\Common Files\InstallShield
    2009-05-28 23:45 . 2009-05-28 23:45 -------- d-----w- c:\program files\Whiptail Interactive
    2009-05-27 17:23 . 2009-05-27 17:23 -------- d-----w- c:\program files\Empire Interactive
    2009-05-27 14:28 . 2009-05-27 14:28 -------- d-----w- c:\program files\Microsoft Games
    2009-05-26 11:50 . 2009-05-26 11:49 -------- d-----w- c:\program files\Canon
    2009-05-26 11:46 . 2009-05-26 11:46 -------- d-----w- c:\program files\Common Files\Canon
    2009-05-17 10:46 . 2009-05-17 10:46 -------- d--h--r- c:\documents and settings\Woolfer\Application Data\SecuROM
    2009-05-17 10:46 . 2009-05-17 10:46 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
    2009-05-17 10:24 . 2009-05-17 10:24 -------- d-----w- c:\program files\Atari
    2009-05-16 17:42 . 2009-05-16 17:40 -------- d-----w- c:\program files\Hunting Unlimited 2009
    2009-05-15 19:17 . 2009-05-15 19:17 -------- d-----w- c:\program files\Diamond Drop
    2009-05-15 19:17 . 2009-05-15 19:17 -------- d-----w- c:\program files\ReflexiveArcade
    2009-05-15 17:40 . 2009-05-15 17:40 0 ----a-w- c:\windows\popcreg.dat
    2009-05-15 17:40 . 2009-05-15 17:40 0 ----a-w- c:\windows\popcinfot.dat
    2009-05-14 22:46 . 2009-05-14 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
    2009-05-13 13:41 . 2009-05-13 13:41 4608 ----a-w- c:\windows\system32\w95inf32.dll
    2009-05-13 13:41 . 2009-05-13 13:41 2272 ----a-w- c:\windows\system32\w95inf16.dll
    2009-05-13 13:41 . 2009-05-13 13:41 -------- d-----w- c:\program files\Disney Interactive
    .

    ------- Sigcheck -------

    [-] 2009-02-21 19:33 1614848 362BC5AF8EAF712832C58CC13AE05750 c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-11-27 15360]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SMSERIAL "= "c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
    "SW20 "= "c:\windows\system32\sw20.exe" [2006-04-04 208896]
    "SW24 "= "c:\windows\system32\sw24.exe" [2006-04-04 69632]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
    "Di dictionary "= "c:\program files\Di recnik\Di.exe" [2007-03-16 518656]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
    "RTBatteryMeter "= "c:\program files\VibrateGameDeviceDriver\RFPIcon.exe" [2003-01-16 49152]
    "nwiz "= "nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
    "C-Media Mixer "= "Mixer.exe" - c:\windows\mixer.exe [2003-03-20 1855488]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\CTFMON.EXE" [2008-11-27 15360]

    c:\documents and settings\Woolfer\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Server4PC.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Server4PC.lnk
    backup=c:\windows\pss\Server4PC.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DVBViewerTE\\ts_winlirc.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\seba14mods\\µtorrent 1.8.2 (build 14458) Leecher Pack\\utorrent 1.8.2 (14458)_stealth.exe "=

    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [9/24/2007 7:11 PM 566560]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [12/13/2007 2:28 PM 24592]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [7/2/2008 12:15 AM 418832]
    S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [11/7/2007 7:15 PM 12928]
    S3 PCAlertDriver;PCAlertDriver;c:\program files\MSI\FuzzyLogic4\Ntglm7x.sys [4/29/2009 1:31 AM 19543]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-08 c:\windows\Tasks\shutdown.job
    - c:\documents and settings\Woolfer\Desktop\shutdown.lnk [2008-07-02 01:20]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-HostManager - c:\program files\Common Files\AOL\1237160791\ee\AOLSoftware.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uInternet Settings,ProxyOverride = 127.0.0.1
    IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Prevedi sa Di recnikom - c:\program files\Di recnik\diie.htm
    IE: Translate with Di dictionary -
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
    FF - ProfilePath - c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-11 23:38
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1116)
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
    c:\windows\system32\klogon.dll

    - - - - - - - > 'lsass.exe'(1176)
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll

    - - - - - - - > 'explorer.exe'(2352)
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
    c:\windows\system32\msi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ASTSRV.EXE
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\rundll32.exe
    c:\program files\IrfanView\i_view32.exe
    .
    **************************************************************************
    .
    Completion time: 2009-07-11 23:46 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-07-11 21:46

    Pre-Run: 25.377.292.288 bytes free
    Post-Run: 25.375.952.896 bytes free

    176
    ComboFix 09-07-09.08 - Woolfer 03.01.2010 18:09.2.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.468 [GMT 1:00]
    Running from: c:\documents and settings\Woolfer\Desktop\ComboFix.exe
    AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
    FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    - REDUCED FUNCTIONALITY MODE -
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2009-12-03 to 2010-01-03 )))))))))))))))))))))))))))))))
    .

    No new files created in this timespan

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-01-03 17:11 . 2009-03-10 10:43 56842272 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2010-01-03 15:21 . 2009-03-10 10:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
    2010-01-03 15:20 . 2009-03-10 10:43 2241056 --sha-w- c:\windows\system32\drivers\fidbox2.dat
    2010-01-02 22:48 . 2009-03-10 10:43 765152 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2010-01-02 22:48 . 2009-03-10 10:43 214280 --sha-w- c:\windows\system32\drivers\fidbox2.idx
    2009-12-27 20:00 . 2009-05-26 11:54 -------- d-----w- c:\documents and settings\Woolfer\Application Data\ZoomBrowser EX
    2009-12-27 19:43 . 2009-05-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
    2009-11-17 21:26 . 2009-03-20 03:23 -------- d-----w- c:\program files\Di recnik
    .

    ------- Sigcheck -------

    [-] 2009-02-21 19:33 1614848 362BC5AF8EAF712832C58CC13AE05750 c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((( SnapShot@2009-07-11_21.38.46 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0C0A\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0816\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0809\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0427\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0426\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0425\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0422\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\041F\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\041D\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\041B\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0419\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0418\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0415\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0414\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0413\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0410\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\040E\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\040C\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\040B\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0409\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0408\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0407\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0406\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0405\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\local\0401\escndvrs.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\estwm.exe
    + 2009-10-19 21:44 . 2008-11-29 22:00 32768 c:\windows\twain_32\escndv\escndvrs.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0C0A\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0816\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0809\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0427\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0426\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0425\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0422\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\041F\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\041D\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\041B\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0419\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0418\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0415\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0414\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0413\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0410\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\040E\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\040C\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\040B\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0409\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0408\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0407\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0406\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0405\esmpsres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\local\0401\esmpsres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 40960 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0C0A\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0816\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0809\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0427\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0426\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0425\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0422\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041F\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041D\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\041B\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0419\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0418\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0415\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0414\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0413\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 40960 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0410\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040E\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 40960 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040C\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\040B\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0409\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 40960 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0408\epbmpres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\eptifres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\eppitres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\eppijres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 40960 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\eppdfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\epmtfres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\epjpgres.dll
    + 2009-10-24 11:10 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0407\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0406\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0405\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\eppijres.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\eppdfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\epjpgres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\local\0401\epbmpres.dll
    + 2009-10-19 21:30 . 2005-08-28 22:00 98304 c:\windows\twain_32\escndv\es0099\ffmt\espimtif.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\eptifres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 94208 c:\windows\twain_32\escndv\es0099\ffmt\eptif.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\eppitres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 90112 c:\windows\twain_32\escndv\es0099\ffmt\eppit.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\eppijres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 94208 c:\windows\twain_32\escndv\es0099\ffmt\eppij.dll
    + 2009-10-19 21:44 . 2008-12-17 22:00 36864 c:\windows\twain_32\escndv\es0099\ffmt\eppdfres.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\epmtfres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 94208 c:\windows\twain_32\escndv\es0099\ffmt\epmtf.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\epjpgres.dll
    + 2009-10-19 21:44 . 2008-11-26 22:00 32768 c:\windows\twain_32\escndv\es0099\ffmt\epbmpres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 77824 c:\windows\twain_32\escndv\es0099\ffmt\epbmp.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\es0099\estwm.exe
    + 2009-10-19 21:44 . 2008-11-26 22:00 73728 c:\windows\twain_32\escndv\es0099\esmpsres.dll
    + 2009-10-19 21:30 . 2008-04-10 22:00 53248 c:\windows\twain_32\escndv\es0099\esicm.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 36864 c:\windows\twain_32\escndv\es0099\esdscl.dll
    + 2009-10-19 21:30 . 2008-07-15 22:00 94208 c:\windows\twain_32\escndv\es0099\esdde.dll
    + 2009-10-19 21:30 . 2006-11-01 22:00 90112 c:\windows\twain_32\escndv\es0099\esddc.dll
    + 2010-01-03 15:20 . 2010-01-03 15:20 16384 c:\windows\Temp\Perflib_Perfdata_2e0.dat
    + 2008-05-16 15:00 . 2006-10-08 19:51 23856 c:\windows\system32\spupdsvc.exe
    + 2009-10-19 21:44 . 2007-12-07 23:06 45056 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\EBPBIDI.DLL
    + 2009-10-19 21:44 . 2008-03-05 22:00 19456 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FREDFBE.DLL
    + 2009-10-19 21:44 . 2006-05-18 21:20 49664 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FMW0FBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 18:00 33280 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHSRFBE.DLL
    + 2009-10-19 21:44 . 2008-04-24 20:06 23040 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FGRCFBE.DLL
    + 2009-10-19 21:44 . 2008-10-23 18:03 16384 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FGEPFBE.DLL
    + 2009-10-19 21:44 . 2008-07-28 22:00 94208 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FDSPFBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 23:06 45056 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FBL6FBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 23:03 42496 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FBA6FBE.DLL
    + 2009-10-19 21:44 . 2006-11-13 18:00 23552 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAUDFBE.DLL
    + 2009-10-19 21:44 . 2008-12-03 23:00 49664 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FASRFBE.DLL
    + 2009-10-19 21:44 . 2007-09-01 02:32 75776 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAREFBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 23:06 45056 c:\windows\system32\spool\drivers\w32x86\3\EBPBIDI.DLL
    + 2009-10-19 21:44 . 2008-03-05 22:00 19456 c:\windows\system32\spool\drivers\w32x86\3\E_FREDFBE.DLL
    + 2009-10-19 21:44 . 2006-05-18 21:20 49664 c:\windows\system32\spool\drivers\w32x86\3\E_FMW0FBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 18:00 33280 c:\windows\system32\spool\drivers\w32x86\3\E_FHSRFBE.DLL
    + 2009-10-19 21:44 . 2008-04-24 20:06 23040 c:\windows\system32\spool\drivers\w32x86\3\E_FGRCFBE.DLL
    + 2009-10-19 21:44 . 2008-10-23 18:03 16384 c:\windows\system32\spool\drivers\w32x86\3\E_FGEPFBE.DLL
    + 2009-10-19 21:44 . 2008-07-28 22:00 94208 c:\windows\system32\spool\drivers\w32x86\3\E_FDSPFBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 23:06 45056 c:\windows\system32\spool\drivers\w32x86\3\E_FBL6FBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 23:03 42496 c:\windows\system32\spool\drivers\w32x86\3\E_FBA6FBE.DLL
    + 2009-10-19 21:44 . 2006-11-13 18:00 23552 c:\windows\system32\spool\drivers\w32x86\3\E_FAUDFBE.DLL
    + 2009-10-19 21:44 . 2008-12-03 23:00 49664 c:\windows\system32\spool\drivers\w32x86\3\E_FASRFBE.DLL
    + 2009-10-19 21:44 . 2007-09-01 02:32 75776 c:\windows\system32\spool\drivers\w32x86\3\E_FAREFBE.DLL
    + 2008-05-16 15:01 . 2006-10-08 19:51 14640 c:\windows\system32\spmsg.dll
    + 2008-05-16 15:03 . 2007-08-31 19:15 18856 c:\windows\system32\ReinstallBackups\0007\DriverFiles\nuidfltr.sys
    + 2008-05-16 15:03 . 2008-04-14 03:41 21504 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\hidserv.dll
    + 2008-05-16 15:03 . 2001-08-17 11:48 12160 c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\mouhid.sys
    + 2008-05-16 15:03 . 2008-11-27 03:45 23040 c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\mouclass.sys
    + 2008-05-16 15:03 . 2007-08-31 19:15 18856 c:\windows\system32\ReinstallBackups\0004\DriverFiles\nuidfltr.sys
    + 2008-05-16 15:03 . 2008-04-14 03:41 21504 c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\hidserv.dll
    + 2008-05-16 14:59 . 2008-04-13 22:09 14592 c:\windows\system32\ReinstallBackups\0003\DriverFiles\i386\kbdhid.sys
    + 2008-05-16 14:59 . 2008-11-27 03:45 24576 c:\windows\system32\ReinstallBackups\0003\DriverFiles\i386\kbdclass.sys
    + 2009-10-19 21:33 . 2006-10-19 22:10 80024 c:\windows\system32\PICSDK.dll
    + 2008-11-27 03:45 . 2009-11-19 07:43 59576 c:\windows\system32\perfc009.dat
    - 2008-11-27 03:45 . 2009-06-22 16:56 59576 c:\windows\system32\perfc009.dat
    + 2008-05-16 13:51 . 2008-04-14 03:41 21504 c:\windows\system32\hidserv.dll
    + 2009-10-19 21:32 . 2004-03-03 04:10 21390 c:\windows\system32\EPPICPattern5.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 11811 c:\windows\system32\EPPICPattern4.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 24903 c:\windows\system32\EPPICPattern3.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 20148 c:\windows\system32\EPPICPattern2.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 31053 c:\windows\system32\EPPICPattern131.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 27417 c:\windows\system32\EPPICPattern121.dat
    + 2009-10-19 21:32 . 2004-03-03 04:10 26154 c:\windows\system32\EPPICPattern1.dat
    + 2009-10-19 21:32 . 2006-10-30 22:10 71840 c:\windows\system32\EPPicMgr.dll
    + 2009-10-19 21:44 . 2008-08-08 19:09 86528 c:\windows\system32\E_FLBFBE.DLL
    + 2009-10-19 21:44 . 2007-12-07 19:01 78848 c:\windows\system32\E_FD4BFBE.DLL
    + 2008-05-16 15:03 . 2007-08-21 08:12 21760 c:\windows\system32\DRVSTORE\pnt32uw_760685142BE30506C264465948FA6BF3F83F6BA0\point32.sys
    + 2008-05-16 15:03 . 2007-08-21 08:13 24064 c:\windows\system32\DRVSTORE\pnt32uk_D8ABC581DD7826E63C34865005655841F42B07B3\point32k.sys
    + 2008-05-16 15:03 . 2007-08-21 08:12 21760 c:\windows\system32\DRVSTORE\pnt32pw_3628C8B45C5ED7121207F0966284A33181948AB6\point32.sys
    + 2008-05-16 15:03 . 2007-08-21 08:13 24064 c:\windows\system32\DRVSTORE\pnt32pk_B14517A010FFCFA2D7F73FBF37EC5E0C83C37769\point32k.sys
    + 2008-05-16 14:59 . 2007-08-31 19:15 18856 c:\windows\system32\DRVSTORE\nuidfltr_E8F8C714821A786671DE95508EA821EFC993B9E1\NuidFltr.sys
    + 2009-10-19 21:31 . 2007-11-28 18:15 58285 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\SAGENT4.EXE
    + 2009-10-19 21:31 . 2008-10-18 03:50 64928 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPUTY287.EXE
    + 2009-10-19 21:31 . 2008-12-12 17:00 52066 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPUPDATE.DAT
    + 2009-10-19 21:31 . 2008-04-24 20:06 11281 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPIPGI20.DLL
    + 2009-10-19 21:31 . 2007-12-07 19:01 40850 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\ECBTEGB.DLL
    + 2009-10-19 21:31 . 2003-05-21 19:27 29535 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\ECBTEG.DLL
    + 2009-10-19 21:31 . 2006-11-22 18:05 37624 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPSHRE4.DLL
    + 2009-10-19 21:31 . 2008-08-08 19:09 38997 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPMONB.DLL
    + 2009-10-19 21:31 . 2007-11-28 22:13 42757 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPMON25.DLL
    + 2009-10-19 21:31 . 2007-11-28 22:08 89231 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPLPT5.DLL
    + 2009-10-19 21:31 . 2000-06-07 18:01 13417 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPCHP.DLL
    + 2009-10-19 21:31 . 2007-12-07 23:06 23215 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPBIDI6.DLL
    + 2009-10-19 21:31 . 2007-12-07 23:06 23214 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBPBIDI.DLL
    + 2009-10-19 21:31 . 2007-12-07 23:03 20200 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBAPI6.DLL
    + 2009-10-19 21:31 . 2007-11-28 22:15 78160 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBAPI5.DLL
    + 2009-10-19 21:31 . 2007-11-28 22:15 78160 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EBAPI4.DLL
    + 2009-10-19 21:31 . 2008-09-12 22:02 68830 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SKU327.DLL
    + 2009-10-19 21:31 . 2007-12-17 18:03 83689 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SIACS7.EXE
    + 2009-10-19 21:31 . 2008-12-03 23:00 11044 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SBE0B7.DLL
    + 2009-10-19 21:31 . 2008-11-12 23:00 43441 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SBB0B5.DLL
    + 2009-10-19 21:31 . 2006-04-24 19:00 49752 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SAGSET.DLL
    + 2009-10-19 21:31 . 2007-12-17 21:00 74008 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_S40ST7.EXE
    + 2009-10-19 21:31 . 2007-01-11 21:02 59293 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_S40RP7.EXE
    + 2009-10-19 21:31 . 2008-10-27 22:05 88778 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_S40RN7.EXE
    + 2009-10-19 21:31 . 2007-11-15 22:02 88688 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_S40MT7.EXE
    + 2009-10-19 21:31 . 2008-09-30 18:00 89462 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_H5UIR7.DLL
    + 2009-10-19 21:31 . 2006-05-18 21:20 29073 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DUMWF5.DLL
    + 2009-10-19 21:31 . 2008-09-08 22:00 79529 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DMAI30.DLL
    + 2009-10-19 21:31 . 2008-09-29 18:00 68364
     
  15. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DLMW01.DLL
    + 2009-10-19 21:31 . 2008-10-30 01:01 70173 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DIX0RE.DLL
    + 2009-10-19 21:31 . 2008-12-20 01:01 30335 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DI0FBE.DLL
    + 2009-10-19 21:31 . 2005-11-30 21:20 87332 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DHA730.DLL
    + 2009-10-19 21:31 . 2008-07-28 22:00 50124 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DDSP30.DLL
    + 2009-10-19 21:31 . 2006-11-13 18:00 12334 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DAUDF1.DLL
    + 2009-10-19 21:31 . 2007-09-01 02:32 49825 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DARED1.DLL
    + 2006-11-02 05:22 . 2006-11-02 05:22 32224 c:\windows\system32\drivers\wdfldr.sys
    + 2009-10-19 21:44 . 2008-04-13 22:17 25856 c:\windows\system32\drivers\usbprint.sys
    + 2008-05-16 15:03 . 2007-08-21 08:12 21760 c:\windows\system32\drivers\point32.sys
    + 2008-05-16 14:59 . 2007-08-31 19:15 18856 c:\windows\system32\drivers\nuidfltr.sys
    + 2008-05-16 13:51 . 2001-08-17 11:48 12160 c:\windows\system32\drivers\mouhid.sys
    - 2008-04-14 00:09 . 2008-11-27 03:45 23040 c:\windows\system32\drivers\mouclass.sys
    + 2008-04-14 00:09 . 2008-04-13 22:09 23040 c:\windows\system32\drivers\mouclass.sys
    + 2008-05-16 13:51 . 2008-04-13 22:09 14592 c:\windows\system32\drivers\kbdhid.sys
    - 2008-11-27 03:45 . 2008-11-27 03:45 24576 c:\windows\system32\drivers\kbdclass.sys
    + 2008-11-27 03:45 . 2008-04-13 22:09 24576 c:\windows\system32\drivers\kbdclass.sys
    + 2008-05-16 14:59 . 2008-04-14 03:41 21504 c:\windows\system32\drivers\hidserv.dll
    - 2009-03-16 00:08 . 2008-04-13 23:17 25856 c:\windows\system32\dllcache\usbprint.sys
    + 2009-10-19 21:44 . 2008-04-13 22:17 25856 c:\windows\system32\dllcache\usbprint.sys
    + 2008-05-16 13:51 . 2001-08-17 11:48 12160 c:\windows\system32\dllcache\mouhid.sys
    - 2009-03-15 23:59 . 2001-08-17 12:48 12160 c:\windows\system32\dllcache\mouhid.sys
    - 2008-04-14 00:09 . 2008-11-27 03:45 23040 c:\windows\system32\dllcache\mouclass.sys
    + 2008-04-14 00:09 . 2008-04-13 22:09 23040 c:\windows\system32\dllcache\mouclass.sys
    + 2008-05-16 13:51 . 2008-04-13 22:09 14592 c:\windows\system32\dllcache\kbdhid.sys
    - 2009-03-15 23:58 . 2008-04-13 23:09 14592 c:\windows\system32\dllcache\kbdhid.sys
    + 2008-11-27 03:45 . 2008-04-13 22:09 24576 c:\windows\system32\dllcache\kbdclass.sys
    - 2008-11-27 03:45 . 2008-11-27 03:45 24576 c:\windows\system32\dllcache\kbdclass.sys
    - 2009-03-15 23:55 . 2008-04-14 04:41 21504 c:\windows\system32\dllcache\hidserv.dll
    + 2008-05-16 13:51 . 2008-04-14 03:41 21504 c:\windows\system32\dllcache\hidserv.dll
    + 2009-10-19 21:36 . 2009-10-19 21:36 69632 c:\windows\Installer\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}\ARPPRODUCTICON.exe
    + 2009-10-19 21:36 . 2009-10-19 21:36 69632 c:\windows\Installer\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}\_SHCT_Sprint.exe.exe
    + 2009-10-03 10:54 . 2009-10-03 10:54 40960 c:\windows\Installer\{900B84AB-6A80-49EE-B236-67F211190597}\NewShortcut5_900B84AB6A8049EEB23667F211190597.exe
    + 2009-10-03 10:54 . 2009-10-03 10:54 40960 c:\windows\Installer\{900B84AB-6A80-49EE-B236-67F211190597}\NewShortcut1_900B84AB6A8049EEB23667F211190597.exe
    + 2009-10-03 10:54 . 2009-10-03 10:54 40960 c:\windows\Installer\{900B84AB-6A80-49EE-B236-67F211190597}\ARPPRODUCTICON.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 65536 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut3_4748AC220AD3439FA5EECE4BB6C12AAC.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut2_6463554370E7436D8D6D4A721595029E.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut1_6463554370E7436D8D6D4A721595029E.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 25214 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\HCG_SC.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 25214 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\CPL_SC.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 25214 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\CPL_DTSC.exe
    + 2008-05-16 15:03 . 2008-05-16 15:03 25214 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\ARPPRODUCTICON.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 25214 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\PGM_CPL.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 65536 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut3_31DD6897EF244CA395831874C052777A.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut2_5D5B9E6A344C497695ABABBDC648E5DA.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut1_5D5B9E6A344C497695ABABBDC648E5DA.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 25214 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\ITP_HCG.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 25214 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\DS_CPL.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 25214 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\ARPPRODUCTICON.exe
    + 2009-10-19 21:38 . 2002-07-25 15:13 24576 c:\windows\Downloaded Program Files\dwusplay.dll
    + 2008-05-16 15:00 . 2006-11-02 05:22 51680 c:\windows\$NtUninstallWdf01005$\spuninst\Kmdfcustom.dll
    + 2009-10-19 21:44 . 2008-11-12 23:00 3804 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAIFFBE.DAT
    + 2009-10-19 21:44 . 2008-10-15 20:02 7168 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_DUPA3E.DLL
    + 2009-10-19 21:44 . 2008-11-12 23:00 3804 c:\windows\system32\spool\drivers\w32x86\3\E_FAIFFBE.DAT
    + 2009-10-19 21:44 . 2008-10-15 20:02 7168 c:\windows\system32\spool\drivers\w32x86\3\E_DUPA3E.DLL
    + 2009-10-19 21:30 . 2006-08-25 17:00 9216 c:\windows\system32\escdev.dll
    + 2009-10-19 21:32 . 2004-03-03 04:10 4943 c:\windows\system32\EPPICPattern6.dat
    + 2009-10-19 21:44 . 2007-04-10 18:06 8192 c:\windows\system32\E_DCINST.DLL
    + 2009-10-19 21:31 . 2008-11-12 18:00 6360 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_HBE0B7.DLL
    + 2009-10-19 21:31 . 2008-10-15 20:02 1959 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DUPA3E.DLL
    + 2009-10-19 21:31 . 2008-03-05 22:00 9587 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DRED08.DLL
    + 2009-10-19 21:31 . 2008-10-23 18:03 7510 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DGE321.DLL
    + 2009-10-19 21:31 . 2007-04-10 18:06 3707 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DCINST.DLL
    + 2008-05-16 15:03 . 2008-05-16 15:03 4846 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\MouseUG.exe
    + 2008-05-16 14:59 . 2008-05-16 14:59 4846 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\ITP_KeyboardUG.exe
    + 2009-10-19 21:30 . 2008-11-29 22:00 143360 c:\windows\twain_32\escndv\escndv.exe
    + 2009-10-24 11:10 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0C0A\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 139264 c:\windows\twain_32\escndv\es0099\local\0816\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0809\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0427\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0426\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0425\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0422\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\041F\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\041D\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\041B\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0419\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0418\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0415\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0414\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\0413\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 139264 c:\windows\twain_32\escndv\es0099\local\0410\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 135168 c:\windows\twain_32\escndv\es0099\local\040E\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 139264 c:\windows\twain_32\escndv\es0099\local\040C\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\040B\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0409\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 139264 c:\windows\twain_32\escndv\es0099\local\0408\esres.dll
    + 2009-10-24 11:10 . 2008-11-28 22:00 143360 c:\windows\twain_32\escndv\es0099\local\0407\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0406\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0405\esres.dll
    + 2009-10-19 21:30 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\local\0401\esres.dll
    + 2009-10-19 21:30 . 2008-06-19 22:00 622592 c:\windows\twain_32\escndv\es0099\ffmt\pdflib.dll
    + 2009-10-19 21:30 . 2008-07-06 22:00 180224 c:\windows\twain_32\escndv\es0099\ffmt\pdffile.dll
    + 2009-10-19 21:30 . 2005-08-28 22:00 143360 c:\windows\twain_32\escndv\es0099\ffmt\esexf.dll
    + 2009-10-19 21:30 . 2008-12-17 22:00 126976 c:\windows\twain_32\escndv\es0099\ffmt\eppdf.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 143360 c:\windows\twain_32\escndv\es0099\ffmt\epjpg.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 122880 c:\windows\twain_32\escndv\es0099\esutwb.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 262144 c:\windows\twain_32\escndv\es0099\estwpmg.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 462848 c:\windows\twain_32\escndv\es0099\esscncl.dll
    + 2009-10-19 21:44 . 2008-11-28 22:00 131072 c:\windows\twain_32\escndv\es0099\esres.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 356461 c:\windows\twain_32\escndv\es0099\esmps.dll
    + 2009-10-19 21:30 . 2008-07-07 22:00 323584 c:\windows\twain_32\escndv\es0099\esimgdet.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 217088 c:\windows\twain_32\escndv\es0099\esimgctl.dll
    + 2009-10-19 21:30 . 2008-11-13 22:00 626688 c:\windows\twain_32\escndv\es0099\esimfl.dll
    + 2009-10-19 21:30 . 2008-02-03 22:00 188416 c:\windows\twain_32\escndv\es0099\esfit.dll
    + 2009-10-19 21:30 . 2008-10-09 22:00 454656 c:\windows\twain_32\escndv\es0099\esdtr2.dll
    + 2009-10-19 21:30 . 2007-11-27 22:00 425984 c:\windows\twain_32\escndv\es0099\esdtr.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 122880 c:\windows\twain_32\escndv\es0099\esdevif.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 188416 c:\windows\twain_32\escndv\es0099\esdevcl.dll
    + 2009-10-19 21:44 . 2008-10-23 19:01 513952 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\EREGISTR.EXE
    + 2009-10-19 21:44 . 2008-07-15 20:17 295424 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\EPSET32.DLL
    + 2009-10-19 21:44 . 2007-11-28 22:15 172032 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\EBAPI4.DLL
    + 2009-10-19 21:44 . 2007-12-17 21:00 143872 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_S40ST7.EXE
    + 2009-10-19 21:44 . 2007-01-11 21:02 113664 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_S40RP7.EXE
    + 2009-10-19 21:44 . 2008-10-30 01:01 296448 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FUIXFBE.DLL
    + 2009-10-19 21:44 . 2008-12-20 01:01 209920 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FUIRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-03 01:01 995840 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FUI1FBE.DLL
    + 2009-10-19 21:44 . 2008-12-17 21:20 982528 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FSR0FBE.DLL
    + 2009-10-19 21:44 . 2008-09-08 21:00 626688 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FPRUFBE.DLL
    + 2009-10-19 21:44 . 2008-09-08 21:00 204800 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FPREFBE.EXE
    + 2009-10-19 21:44 . 2008-09-08 22:00 142336 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FMAIFBE.DLL
    + 2009-10-19 21:44 . 2008-09-29 18:00 138240 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FLMWFBE.DLL
    + 2009-10-19 21:44 . 2008-11-25 21:00 659968 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FJBCFBE.DLL
    + 2009-10-19 21:44 . 2008-10-23 00:05 804784 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FINSFBE.EXE
    + 2009-10-19 21:44 . 2006-11-03 00:21 319456 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FINSFBE.DLL
    + 2009-10-19 21:44 . 2008-12-12 17:00 309560 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FINSFBE.DAT
    + 2009-10-19 21:44 . 2008-10-18 03:50 136192 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHUTFBE.EXE
    + 2009-10-19 21:44 . 2008-10-18 03:50 285696 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHUTFBE.DLL
    + 2009-10-19 21:44 . 2005-11-30 21:20 212992 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHT0FBE.DLL
    + 2009-10-19 21:44 . 2007-03-09 21:20 328192 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHM0FBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 18:00 432128 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FHBRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-29 21:02 381440 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FCONFBE.DLL
    + 2009-10-19 21:44 . 2007-12-17 18:03 177152 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FBCSFBE.EXE
    + 2009-10-19 21:44 . 2007-11-28 22:15 172032 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FBAPFBE.DLL
    + 2009-10-19 21:44 . 2008-09-26 23:00 199680 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FATIFBE.EXE
    + 2009-10-19 21:44 . 2008-12-03 18:24 643072 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FASOFBE.DLL
    + 2009-10-19 21:44 . 2008-09-12 22:02 131584 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FASKFBE.DLL
    + 2009-10-19 21:44 . 2008-10-27 22:05 171008 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FARNFBE.EXE
    + 2009-10-19 21:44 . 2008-12-03 23:00 725504 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAPRFBE.DLL
    + 2009-10-19 21:44 . 2007-11-15 22:02 175616 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAMTFBE.EXE
    + 2009-10-19 21:44 . 2008-09-30 18:00 166400 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FAIRFBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 23:00 476672 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FABRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-15 12:44 309144 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_DUPA30.EXE
    + 2009-10-19 21:44 . 2008-10-23 19:01 513952 c:\windows\system32\spool\drivers\w32x86\3\EREGISTR.EXE
    + 2009-10-19 21:44 . 2008-07-15 20:17 295424 c:\windows\system32\spool\drivers\w32x86\3\EPSET32.DLL
    + 2009-10-19 21:44 . 2007-11-28 22:15 172032 c:\windows\system32\spool\drivers\w32x86\3\EBAPI4.DLL
    + 2009-10-19 21:44 . 2007-12-17 21:00 143872 c:\windows\system32\spool\drivers\w32x86\3\E_S40ST7.EXE
    + 2009-10-19 21:44 . 2007-01-11 21:02 113664 c:\windows\system32\spool\drivers\w32x86\3\E_S40RP7.EXE
    + 2009-10-19 21:44 . 2008-10-30 01:01 296448 c:\windows\system32\spool\drivers\w32x86\3\E_FUIXFBE.DLL
    + 2009-10-19 21:44 . 2008-12-20 01:01 209920 c:\windows\system32\spool\drivers\w32x86\3\E_FUIRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-03 01:01 995840 c:\windows\system32\spool\drivers\w32x86\3\E_FUI1FBE.DLL
    + 2009-10-19 21:44 . 2008-12-17 21:20 982528 c:\windows\system32\spool\drivers\w32x86\3\E_FSR0FBE.DLL
    + 2009-10-19 21:44 . 2008-09-08 21:00 626688 c:\windows\system32\spool\drivers\w32x86\3\E_FPRUFBE.DLL
    + 2009-10-19 21:44 . 2008-09-08 21:00 204800 c:\windows\system32\spool\drivers\w32x86\3\E_FPREFBE.EXE
    + 2009-10-19 21:44 . 2008-09-08 22:00 142336 c:\windows\system32\spool\drivers\w32x86\3\E_FMAIFBE.DLL
    + 2009-10-19 21:44 . 2008-09-29 18:00 138240 c:\windows\system32\spool\drivers\w32x86\3\E_FLMWFBE.DLL
    + 2009-10-19 21:44 . 2008-11-25 21:00 659968 c:\windows\system32\spool\drivers\w32x86\3\E_FJBCFBE.DLL
    + 2009-10-19 21:44 . 2008-10-23 00:05 804784 c:\windows\system32\spool\drivers\w32x86\3\E_FINSFBE.EXE
    + 2009-10-19 21:44 . 2006-11-03 00:21 319456 c:\windows\system32\spool\drivers\w32x86\3\E_FINSFBE.DLL
    + 2009-10-19 21:44 . 2008-12-12 17:00 309560 c:\windows\system32\spool\drivers\w32x86\3\E_FINSFBE.DAT
    + 2009-10-19 21:44 . 2008-10-18 03:50 136192 c:\windows\system32\spool\drivers\w32x86\3\E_FHUTFBE.EXE
    + 2009-10-19 21:44 . 2008-10-18 03:50 285696 c:\windows\system32\spool\drivers\w32x86\3\E_FHUTFBE.DLL
    + 2009-10-19 21:44 . 2005-11-30 21:20 212992 c:\windows\system32\spool\drivers\w32x86\3\E_FHT0FBE.DLL
    + 2009-10-19 21:44 . 2007-03-09 21:20 328192 c:\windows\system32\spool\drivers\w32x86\3\E_FHM0FBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 18:00 432128 c:\windows\system32\spool\drivers\w32x86\3\E_FHBRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-29 21:02 381440 c:\windows\system32\spool\drivers\w32x86\3\E_FCONFBE.DLL
    + 2009-10-19 21:44 . 2007-12-17 18:03 177152 c:\windows\system32\spool\drivers\w32x86\3\E_FBCSFBE.EXE
    + 2009-10-19 21:44 . 2007-11-28 22:15 172032 c:\windows\system32\spool\drivers\w32x86\3\E_FBAPFBE.DLL
    + 2009-10-19 21:44 . 2008-09-26 23:00 199680 c:\windows\system32\spool\drivers\w32x86\3\E_FATIFBE.EXE
    + 2009-10-19 21:44 . 2008-12-03 18:24 643072 c:\windows\system32\spool\drivers\w32x86\3\E_FASOFBE.DLL
    + 2009-10-19 21:44 . 2008-09-12 22:02 131584 c:\windows\system32\spool\drivers\w32x86\3\E_FASKFBE.DLL
    + 2009-10-19 21:44 . 2008-10-27 22:05 171008 c:\windows\system32\spool\drivers\w32x86\3\E_FARNFBE.EXE
    + 2009-10-19 21:44 . 2008-12-03 23:00 725504 c:\windows\system32\spool\drivers\w32x86\3\E_FAPRFBE.DLL
    + 2009-10-19 21:44 . 2007-11-15 22:02 175616 c:\windows\system32\spool\drivers\w32x86\3\E_FAMTFBE.EXE
    + 2009-10-19 21:44 . 2008-09-30 18:00 166400 c:\windows\system32\spool\drivers\w32x86\3\E_FAIRFBE.DLL
    + 2009-10-19 21:44 . 2008-11-12 23:00 476672 c:\windows\system32\spool\drivers\w32x86\3\E_FABRFBE.DLL
    + 2009-10-19 21:44 . 2008-10-15 12:44 309144 c:\windows\system32\spool\drivers\w32x86\3\E_DUPA30.EXE
    + 2009-10-19 21:33 . 2007-06-21 22:10 501912 c:\windows\system32\PICSDK2.dll
    + 2009-10-19 21:32 . 2006-10-19 22:10 108704 c:\windows\system32\PICEntry.dll
    + 2008-11-27 03:45 . 2009-11-19 07:43 395336 c:\windows\system32\perfh009.dat
    - 2008-11-27 03:45 . 2009-06-22 16:56 395336 c:\windows\system32\perfh009.dat
    + 2009-10-19 21:30 . 2008-11-16 22:00 342016 c:\windows\system32\eswiaud.dll
    + 2009-10-19 21:32 . 2006-10-30 22:10 120992 c:\windows\system32\EpPicPrt.dll
    + 2009-10-19 21:32 . 2005-05-31 22:20 111932 c:\windows\system32\EPPICPrinterDB.dat
    + 2009-10-19 21:31 . 2008-10-23 19:01 236445 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EREGISTR.EXE
    + 2009-10-19 21:31 . 2008-10-18 03:50 147220 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPUTY287.DLL
    + 2009-10-19 21:31 . 2008-10-23 00:05 359301 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPUPDATE.EXE
    + 2009-10-19 21:31 . 2008-07-15 20:17 119347 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\EPSET32.DLL
    + 2009-10-19 21:31 . 2008-09-26 23:00 100905 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SBI0B7.EXE
    + 2009-10-19 21:31 . 2008-12-03 23:00 337662 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_SB90B7.DLL
    + 2009-10-19 21:31 . 2008-12-03 18:24 296608 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_S40SO7.DLL
    + 2009-10-19 21:31 . 2008-11-12 18:00 112395 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_HBB0B5.DLL
    + 2009-10-19 21:31 . 2008-10-15 12:44 148829 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DUPA30.EXE
    + 2009-10-19 21:31 . 2008-12-19 23:00 602213 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DU3FAE.DLL
    + 2009-10-19 21:31 . 2008-12-17 21:20 931410 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DSF0BE.DLL
    + 2009-10-19 21:31 . 2008-09-08 21:00 267374 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DPUI07.DLL
    + 2009-10-19 21:31 . 2008-09-08 21:00 100673 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DPPE06.EXE
    + 2009-10-19 21:31 . 2008-11-25 21:00 346908 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DJB726.DLL
    + 2009-10-19 21:31 . 2006-11-03 00:21 151161 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DIFX01.DLL
    + 2009-10-19 21:31 . 2008-10-03 01:01 484452 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DI1FAE.DLL
    + 2009-10-19 21:31 . 2007-03-09 21:20 283458 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DHMM6A.DLL
    + 2009-10-19 21:31 . 2008-10-29 21:02 160702 c:\windows\system32\DRVSTORE\E_DF1FBE_6F6526A63F718619507CA479B9F6E8384D3223C1\WINVISTA_XP_2K\E_DCON04.DLL
    + 2006-11-02 05:22 . 2006-11-02 05:22 492000 c:\windows\system32\drivers\wdf01000.sys
    + 2006-07-23 22:25 . 2006-07-23 22:25 243712 c:\windows\Installer\5acc5.msi
    + 2008-05-16 15:02 . 2008-05-16 15:02 301056 c:\windows\Installer\3dcab2.msi
    + 2009-10-19 21:38 . 2002-07-25 15:05 172032 c:\windows\Downloaded Program Files\isusweb.dll
    + 2009-10-19 21:38 . 2002-07-25 15:13 196608 c:\windows\Downloaded Program Files\dwusplay.exe
    + 2008-05-16 15:00 . 2006-10-08 19:51 379184 c:\windows\$NtUninstallWdf01005$\spuninst\updspapi.dll
    + 2008-05-16 15:00 . 2006-10-08 19:51 221488 c:\windows\$NtUninstallWdf01005$\spuninst\spuninst.exe
    + 2009-10-19 21:44 . 2008-11-30 22:00 1060864 c:\windows\twain_32\escndv\es009a\Esui.dll
    + 2009-10-19 21:30 . 2008-11-30 22:00 1060864 c:\windows\twain_32\escndv\es0099\Esui.dll
    + 2009-10-19 21:30 . 2008-11-26 22:00 3571712 c:\windows\twain_32\escndv\es0099\escires.dll
    + 2009-10-19 21:44 . 2008-11-30 22:00 1060864 c:\windows\twain_32\escndv\es0098\Esui.dll
    + 2008-05-16 14:59 . 2007-08-31 19:13 1421736 c:\windows\system32\wdfcoinstaller01005.dll
    + 2009-10-19 21:44 . 2008-12-19 23:00 1422848 c:\windows\system32\spool\drivers\w32x86\epsonepson_stylus_sx89ab\E_FUICFBE.DLL
    + 2009-10-19 21:44 . 2008-12-19 23:00 1422848 c:\windows\system32\spool\drivers\w32x86\3\E_FUICFBE.DLL
    + 2008-05-16 15:03 . 2007-08-31 19:13 1421736 c:\windows\system32\ReinstallBackups\0007\DriverFiles\wdfcoinstaller01005.dll
    + 2008-05-16 15:03 . 2007-08-31 19:13 1421736 c:\windows\system32\ReinstallBackups\0004\DriverFiles\wdfcoinstaller01005.dll
    + 2009-02-21 23:43 . 2008-05-17 16:58 2254048 c:\windows\system32\FNTCACHE.DAT
    + 2008-05-16 14:59 . 2007-08-31 19:13 1421736 c:\windows\system32\DRVSTORE\nuidfltr_E8F8C714821A786671DE95508EA821EFC993B9E1\wdfcoinstaller01005.dll
    + 2009-10-19 21:36 . 2009-10-19 21:36 1590784 c:\windows\Installer\96222b.msi
    + 2008-05-16 15:03 . 2008-05-16 15:03 4429824 c:\windows\Installer\3dcaba.msi
    + 2008-05-16 14:59 . 2008-05-16 14:59 4657664 c:\windows\Installer\3dcaaa.msi
    + 2009-10-03 10:54 . 2009-10-03 10:54 3213824 c:\windows\Installer\38cf2.msi
    + 2009-10-03 10:53 . 2009-10-03 10:52 17213440 c:\windows\Downloaded Installations\{0DC74181-910C-4D63-93F2-22FD58B1F67B}\Hello Kitty Dream Carnival.msi
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-11-27 15360]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
    "EPSON SX110 Series "= "c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIFBE.EXE" [2008-09-26 199680]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SMSERIAL "= "c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
    "SW20 "= "c:\windows\system32\sw20.exe" [2006-04-04 208896]
    "SW24 "= "c:\windows\system32\sw24.exe" [2006-04-04 69632]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
    "Di dictionary "= "c:\program files\Di recnik\Di.exe" [2007-03-16 518656]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
    "RTBatteryMeter "= "c:\program files\VibrateGameDeviceDriver\RFPIcon.exe" [2003-01-16 49152]
    "itype "= "c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
    "IntelliPoint "= "c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
    "nwiz "= "nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
    "C-Media Mixer "= "Mixer.exe" - c:\windows\mixer.exe [2003-03-20 1855488]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\CTFMON.EXE" [2008-11-27 15360]

    c:\documents and settings\Woolfer\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Server4PC.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Server4PC.lnk
    backup=c:\windows\pss\Server4PC.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DVBViewerTE\\ts_winlirc.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\seba14mods\\µtorrent 1.8.2 (build 14458) Leecher Pack\\utorrent 1.8.2 (14458)_stealth.exe "=

    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [9/24/2007 6:11 PM 566560]
    R3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [11/7/2007 6:15 PM 12928]
    R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [12/13/2007 1:28 PM 24592]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [7/1/2008 11:15 PM 418832]
    S3 AVPsys;AVPsys;c:\windows\system32\drivers\cdaudio.sys [8/17/2001 2:52 PM 18688]
    S3 PCAlertDriver;PCAlertDriver;c:\program files\MSI\FuzzyLogic4\Ntglm7x.sys [4/29/2009 12:31 AM 19543]
    .
    Contents of the 'Scheduled Tasks' folder

    2008-05-16 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
    - c:\program files\Microsoft IntelliType Pro\itype.exe [2007-08-31 19:13]

    2009-04-08 c:\windows\Tasks\shutdown.job
    - c:\documents and settings\Woolfer\Desktop\shutdown.lnk [2008-07-02 01:20]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uInternet Settings,ProxyOverride = 127.0.0.1
    IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Prevedi sa Di recnikom - c:\program files\Di recnik\diie.htm
    IE: Translate with Di dictionary -
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
    FF - ProfilePath - c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-01-03 18:11
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1108)
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
    c:\windows\system32\klogon.dll

    - - - - - - - > 'lsass.exe'(1168)
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
    c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
    .
    Completion time: 2010-01-03 18:17
    ComboFix-quarantined-files.txt 2010-01-03 17:17
    ComboFix2.txt 2009-07-11 21:47

    Pre-Run: 15.506.567.168 bytes free
    Post-Run: 15.484.710.912 bytes free

    685
    ComboFix 10-07-01.02 - Woolfer 03.07.2010 0:21.4.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.484 [GMT 2:00]
    Running from: c:\documents and settings\Woolfer\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\Downloaded Program Files\ODCTOOLS
    c:\windows\Downloaded Program Files\ODCTOOLS\ef6b26db-344d-4ad3-ba24-aca0bdaa999a.cab
    c:\windows\Downloaded Program Files\ODCTOOLS\f04d289f-c60a-422b-8396-6c372047042e.cab
    .
    ---- Previous Run -------
    .
    C:\a.txt
    c:\documents and settings\Woolfer\Application Data\ACD Systems\ACDSee\ImageDB.ddf
    C:\Win
    c:\win\names.txt
    c:\windows\system32\winsys.exe
    c:\windows\wc98pp.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_AVPsys
    -------\Service_npf


    ((((((((((((((((((((((((( Files Created from 2010-06-02 to 2010-07-02 )))))))))))))))))))))))))))))))
    .

    2010-07-02 18:41 . 2010-07-02 18:51 4212 ---h--w- c:\windows\system32\zllictbl.dat
    2010-07-02 18:40 . 2010-07-02 22:05 -------- d-----w- c:\windows\Internet Logs
    2010-07-02 13:41 . 2010-07-02 13:51 -------- d-----w- c:\program files\A4Proxy
    2010-06-29 16:59 . 2010-07-02 18:30 -------- d-----w- c:\program files\Common Files\Real
    2010-06-29 16:45 . 2010-06-29 16:45 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-06-29 02:50 . 2010-06-29 02:50 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2010-06-29 02:15 . 2010-06-29 02:17 -------- d-----w- c:\windows\nview
    2010-06-29 02:15 . 2005-12-10 01:06 180224 ----a-w- c:\windows\system32\nvudisp.exe
    2010-06-29 02:15 . 2005-12-10 02:16 180224 ----a-w- c:\windows\system32\NVUNINST.EXE
    2010-06-29 01:06 . 2010-06-29 01:06 -------- d-----w- c:\program files\Cacheman
    2010-06-26 02:10 . 2010-07-02 13:41 188152 ----a-w- c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\FlashGot.exe
    2010-06-25 23:12 . 2010-06-25 23:12 -------- d-----w- c:\program files\Support Tools
    2010-06-25 21:11 . 2009-08-06 17:24 44768 ----a-w- c:\windows\system32\wups2.dll
    2010-06-25 21:06 . 2010-06-25 21:06 -------- d-s---w- c:\documents and settings\Woolfer\UserData
    2010-06-19 19:49 . 2010-06-19 19:49 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
    2010-06-19 19:48 . 2010-06-19 19:48 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
    2010-06-19 14:01 . 2010-06-19 14:04 -------- d-----w- c:\program files\Gravity
    2010-06-19 10:13 . 2010-06-19 10:14 -------- d-----w- c:\program files\Bloboats
    2010-06-18 15:18 . 2010-03-15 09:31 165376 ----a-w- c:\windows\system32\unrar.dll
    2010-06-18 15:18 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
    2010-06-18 15:18 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
    2010-06-18 15:18 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
    2010-06-18 15:18 . 2010-06-02 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
    2010-06-18 15:18 . 2010-06-18 15:19 -------- d-----w- c:\program files\K-Lite Codec Pack
    2010-06-14 12:21 . 2010-06-14 12:21 -------- d-----w- c:\program files\VisiPics
    2010-06-14 09:27 . 2010-07-02 17:05 -------- d-----w- c:\documents and settings\Woolfer\Local Settings\Application Data\Temp
    2010-06-14 08:54 . 2010-06-29 02:15 -------- d-----w- C:\NVIDIA
    2010-06-11 02:29 . 2010-06-11 08:35 -------- d-----w- c:\program files\DDR - Digital Camera Recovery(Demo)
    2010-06-11 02:29 . 2009-12-16 01:30 65776 ----a-w- c:\windows\UnDeploy.exe
    2010-06-11 01:30 . 2010-06-13 20:12 -------- d-----w- c:\program files\Ontrack
    2010-06-09 23:12 . 2010-06-09 23:12 -------- d-----w- c:\documents and settings\Woolfer\Local Settings\Application Data\bluesoleil
    2010-06-09 10:13 . 2010-07-02 22:51 -------- d-----w- C:\mRouterDebug
    2010-06-09 08:06 . 2010-06-09 08:06 976832 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\8.2\ARM\237\AdobeARM.exe
    2010-06-09 08:06 . 2010-06-09 08:06 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\8.2\ARM\237\AdobeExtractFiles.dll
    2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\8.2\ARM\237\ReaderUpdater.exe
    2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\8.2\ARM\237\AcrobatUpdater.exe
    2010-06-08 23:32 . 2010-06-08 23:32 -------- d-----w- c:\program files\Intuwave
    2010-06-07 19:48 . 2007-01-29 18:22 196608 ----a-r- c:\windows\system32\sm56co6a.dll
    2010-06-07 19:48 . 2007-01-29 18:26 984832 ----a-r- c:\windows\system32\drivers\smserial.sys
    2010-06-07 19:48 . 2010-06-07 19:48 -------- d-----w- c:\program files\Motorola
    2010-06-07 17:02 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
    2010-06-07 17:02 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
    2010-06-07 17:02 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
    2010-06-07 17:02 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
    2010-06-07 16:35 . 2010-06-07 16:35 -------- d-----w- c:\windows\Logs
    2010-06-06 21:05 . 2010-06-06 21:05 -------- d-----w- c:\program files\Microsoft Easy Assist
    2010-06-06 21:05 . 2010-06-06 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Applications
    2010-06-06 14:18 . 2010-06-06 14:18 -------- d-----w- c:\program files\AnalogX

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-02 22:51 . 2009-03-20 03:23 -------- d-----w- c:\program files\Di recnik
    2010-06-29 17:00 . 2006-07-11 17:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2010-06-29 02:13 . 2010-01-08 16:30 1324 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\uninst_s2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\serial2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 10134 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\ARPPRODUCTICON.exe
    2010-06-26 00:00 . 2009-04-09 14:03 -------- d-----w- c:\documents and settings\Woolfer\Application Data\uTorrent
    2010-06-23 02:05 . 2009-03-10 10:43 -------- d-----w- c:\program files\Kaspersky Lab
    2010-06-23 02:05 . 2009-03-10 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2010-06-13 20:16 . 2009-03-03 21:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-06-10 17:23 . 2009-10-19 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
    2010-06-10 17:19 . 2009-10-19 21:30 -------- d-----w- c:\program files\epson
    2010-06-10 16:49 . 2009-05-26 11:49 -------- d-----w- c:\program files\Canon
    2010-06-08 23:05 . 2010-05-22 18:21 146 ----a-w- c:\windows\DelMR.bat
    2010-06-07 17:58 . 2010-02-28 13:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
    2010-06-07 17:18 . 2010-06-07 17:18 1892 ----a-w- c:\documents and settings\All Users\Application Data\xml4D.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 13757 ----a-w- c:\documents and settings\All Users\Application Data\xml4C.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 9521 ----a-w- c:\documents and settings\All Users\Application Data\xml4B.tmp
    2010-06-07 12:25 . 2010-02-28 11:18 -------- d-----w- c:\program files\Common Files\Nokia
    2010-06-01 10:35 . 2010-06-01 10:35 -------- d-----w- c:\program files\Universal Extractor
    2010-06-01 00:19 . 2009-02-22 10:24 42952 ----a-w- c:\documents and settings\Woolfer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-05-31 19:29 . 2010-05-31 19:26 -------- d-----w- c:\documents and settings\Woolfer\Application Data\PC Suite
    2010-05-31 19:29 . 2010-05-31 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
    2010-05-31 19:17 . 2010-02-28 11:15 -------- d-----w- c:\program files\Nokia
    2010-05-31 19:17 . 2010-05-31 19:17 -------- d-----w- c:\program files\PC Connectivity Solution
    2010-05-31 19:13 . 2010-05-31 19:13 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
    2010-05-31 19:13 . 2010-05-31 19:13 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
    2010-05-31 19:10 . 2010-05-31 19:13 34399664 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_eng.exe
    2010-05-28 22:11 . 2009-04-05 17:55 -------- d-----w- c:\program files\Java
    2010-05-25 18:27 . 2010-05-24 21:48 -------- d-----w- c:\program files\Microsoft IntelliType Pro
    2010-05-25 10:17 . 2010-05-25 10:17 -------- d-----w- c:\program files\IVT Corporation
    2010-05-24 23:01 . 2010-05-24 23:01 503808 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcp71.dll
    2010-05-24 23:01 . 2010-05-24 23:01 499712 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\jmc.dll
    2010-05-24 23:01 . 2010-05-24 23:01 12800 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-d3d.dll
    2010-05-24 23:01 . 2010-05-24 23:01 61440 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-sse.dll
    2010-05-24 23:01 . 2010-05-24 23:01 348160 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcr71.dll
    2010-05-24 20:29 . 2010-05-24 20:29 389120 ----a-w- c:\windows\system32\CF25867.exe
    2010-05-22 15:13 . 2010-05-22 15:13 -------- d-----w- c:\documents and settings\Woolfer\Application Data\BluetoothDriverInstaller
    2010-05-22 13:50 . 2010-02-28 11:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
    2010-05-11 14:42 . 2009-03-23 11:57 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Offline Explorer
    2010-05-10 23:47 . 2010-05-10 16:26 -------- d-----w- c:\documents and settings\Woolfer\Application Data\GARMIN
    2010-05-10 16:34 . 2010-02-28 11:15 -------- d-----w- c:\program files\DIFX
    2010-05-10 16:34 . 2010-05-10 16:34 -------- d-----w- c:\program files\Garmin
    2010-05-10 16:26 . 2010-05-10 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\GARMIN
    2010-05-09 00:51 . 2010-05-08 23:56 -------- d-----w- c:\program files\TC UP
    2010-05-09 00:02 . 2010-05-09 00:02 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Scooter Software
    2010-05-09 00:02 . 2010-05-09 00:02 -------- d-----w- c:\program files\Beyond Compare 3
    2010-05-06 21:09 . 2009-05-26 11:54 -------- d-----w- c:\documents and settings\Woolfer\Application Data\ZoomBrowser EX
    2010-04-21 22:34 . 2010-04-21 22:34 10454 ----a-w- c:\windows\system32\drivers\parldr2k.sys
    2010-04-15 21:56 . 2010-02-28 11:10 357344 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2010-04-12 15:29 . 2010-05-28 22:12 411368 ----a-w- c:\windows\system32\deployJava1.dll
    .

    ------- Sigcheck -------

    [-] 2009-02-21 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((( SnapShot_2010-01-03_17.12.03 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-12-01 22:46 . 2006-12-01 22:46 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
    - 2006-12-01 23:46 . 2006-12-01 23:46 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
    + 2009-07-11 18:54 . 2009-07-11 18:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
    + 2009-07-11 18:32 . 2009-07-11 18:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
    + 2009-07-11 23:07 . 2009-07-11 23:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
    + 2009-07-11 23:19 . 2009-07-11 23:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
    + 2009-07-11 17:41 . 2009-07-11 17:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
    + 2010-07-02 22:31 . 2010-07-02 22:31 16384 c:\windows\Temp\Perflib_Perfdata_c34.dat
    + 2010-07-02 22:06 . 2010-07-02 22:06 16384 c:\windows\Temp\Perflib_Perfdata_c2c.dat
    + 2010-07-02 22:31 . 2010-07-02 22:31 16384 c:\windows\Temp\Perflib_Perfdata_6bc.dat
    + 2010-06-07 17:01 . 2009-09-04 15:44 69464 c:\windows\system32\XAPOFX1_3.dll
    + 2010-06-07 17:01 . 2008-10-27 08:04 70992 c:\windows\system32\XAPOFX1_2.dll
    + 2010-06-07 17:01 . 2008-07-31 08:41 68616 c:\windows\system32\XAPOFX1_1.dll
    + 2010-06-07 17:01 . 2008-05-30 12:17 65032 c:\windows\system32\XAPOFX1_0.dll
    + 2010-06-07 17:01 . 2009-03-16 12:18 22360 c:\windows\system32\X3DAudio1_6.dll
    + 2010-06-07 17:01 . 2008-10-27 08:04 23376 c:\windows\system32\X3DAudio1_5.dll
    + 2010-06-07 17:01 . 2008-05-30 12:17 25608 c:\windows\system32\X3DAudio1_4.dll
    + 2009-02-21 22:57 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll
    + 2006-09-28 17:56 . 2008-01-18 23:37 55296 c:\windows\system32\WudfSvc.dll
    + 2006-09-28 19:13 . 2008-01-18 23:37 87552 c:\windows\system32\WUDFCoinstaller.dll
    + 2009-02-21 22:57 . 2009-08-06 17:24 53472 c:\windows\system32\wuauclt.exe
    + 2010-03-05 22:07 . 2009-08-14 09:10 58208 c:\windows\system32\wsimd.sys
    + 2006-10-18 20:47 . 2006-10-18 19:47 38400 c:\windows\system32\wpdshextres.dll
    + 2006-10-18 19:00 . 2006-10-18 19:00 17408 c:\windows\system32\wpdshextautoplay.exe
    + 2006-10-18 20:47 . 2006-10-18 20:47 63488 c:\windows\system32\wpdmtpus.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 35840 c:\windows\system32\wpdconns.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 99840 c:\windows\system32\wmpshell.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 37376 c:\windows\system32\wmdmps.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 33792 c:\windows\system32\wmdmlog.dll
    + 2010-03-05 22:07 . 2009-08-14 12:53 77824 c:\windows\system32\wgapiloc.dll
    + 2008-07-29 20:10 . 2008-07-29 20:10 26112 c:\windows\system32\TsWpfWrp.exe
    + 2008-05-16 15:00 . 2008-11-07 16:55 26144 c:\windows\system32\spupdsvc.exe
    + 2010-02-28 11:08 . 2008-07-06 12:06 89088 c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    + 2010-03-23 20:25 . 2008-11-07 16:55 16928 c:\windows\system32\spmsgXP_2k3.dll
    - 2008-05-16 15:01 . 2006-10-08 19:51 14640 c:\windows\system32\spmsg.dll
    + 2010-06-29 16:46 . 2006-09-25 15:58 14640 c:\windows\system32\spmsg.dll
    + 2010-06-25 21:11 . 2009-08-06 17:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
    + 2007-09-03 13:49 . 2007-09-03 13:49 41049 c:\windows\system32\skypeagent.dll
    + 2010-05-24 21:41 . 2009-01-07 15:57 27784 c:\windows\system32\ReinstallBackups\0010\DriverFiles\point32.sys
    + 2010-05-24 21:41 . 2001-08-17 11:48 12160 c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\mouhid.sys
    + 2010-05-24 21:41 . 2008-04-13 22:09 23040 c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\mouclass.sys
    + 2010-01-10 10:43 . 2008-04-14 04:41 21504 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\hidserv.dll
    + 2010-03-07 14:16 . 2007-06-24 20:56 38920 c:\windows\system32\ReinstallBackups\0007\DriverFiles\btcusb.sys
    + 2010-05-26 20:19 . 2009-01-03 14:40 39304 c:\windows\system32\ReinstallBackups\0006\DriverFiles\btcusb.sys
    + 2010-05-25 18:26 . 2008-04-13 22:09 14592 c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\kbdhid.sys
    + 2010-05-25 18:26 . 2008-04-13 22:09 24576 c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\kbdclass.sys
    + 2010-01-10 10:43 . 2008-04-14 04:41 21504 c:\windows\system32\ReinstallBackups\0003\DriverFiles\i386\hidserv.dll
    + 2008-07-29 18:59 . 2008-07-29 18:59 43544 c:\windows\system32\PresentationHostProxy.dll
    + 2009-02-27 14:41 . 2009-02-27 14:41 28766 c:\windows\system32\PlayerCtrl.dll
    + 2008-11-27 03:45 . 2010-05-31 18:34 68544 c:\windows\system32\perfc009.dat
    + 2005-12-10 01:06 . 2005-12-10 01:06 81920 c:\windows\system32\nvwddi.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 81920 c:\windows\system32\nvwddi.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 86016 c:\windows\system32\nvmctray.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 86016 c:\windows\system32\nvmctray.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 45056 c:\windows\system32\nvmccsrs.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 45056 c:\windows\system32\nvmccsrs.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 35840
     
  16. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    c:\windows\system32\nvcodins.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 35840 c:\windows\system32\nvcod.dll
    + 2004-03-24 02:49 . 2004-03-24 02:49 94208 c:\windows\system32\nsndis50.dll
    + 2004-03-24 02:12 . 2004-03-24 02:12 17280 c:\windows\system32\nsndis5.sys
    + 2010-05-31 19:15 . 2009-10-06 09:52 91136 c:\windows\system32\nmwcdcls.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 15360 c:\windows\system32\mui\0409\mscorees.dll
    + 2003-04-18 14:29 . 2003-04-18 14:29 82432 c:\windows\system32\msxml4r.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 27136 c:\windows\system32\mspmsnsv.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 83968 c:\windows\system32\mscories.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 11264 c:\windows\system32\LAPRXY.dll
    + 2010-05-22 15:14 . 2008-04-14 03:41 28160 c:\windows\system32\irmon.dll
    + 1996-10-15 07:53 . 1996-10-15 07:53 78848 c:\windows\system32\INLOADER.DLL
    + 2008-07-29 18:24 . 2008-07-29 18:24 97800 c:\windows\system32\infocardapi.dll
    + 2008-07-29 18:24 . 2008-07-29 18:24 11264 c:\windows\system32\icardres.dll
    + 2009-02-27 14:44 . 2009-02-27 14:44 53248 c:\windows\system32\HtmPrintHelper.dll
    + 1996-10-15 07:53 . 1996-10-15 07:53 14160 c:\windows\system32\HLINKPRX.DLL
    + 2002-07-10 21:03 . 2002-07-10 21:03 45056 c:\windows\system32\EagleAPI.dll
    + 2009-10-19 21:44 . 2007-12-07 17:01 78848 c:\windows\system32\E_FD4BFBE.DLL
    - 2009-10-19 21:44 . 2007-12-07 19:01 78848 c:\windows\system32\E_FD4BFBE.DLL
    + 2008-07-29 20:10 . 2008-07-29 20:10 73720 c:\windows\system32\dxva2.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 82017 c:\windows\system32\dsaNac.dll
    + 2010-05-31 19:17 . 2008-08-26 07:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
    + 2010-05-23 23:30 . 2009-01-07 15:57 18856 c:\windows\system32\DRVSTORE\nuidfltr_4A2DD497F80BEBAFF2971F4BEDF4026E50D4DE51\NuidFltr.sys
    + 2010-05-10 16:34 . 2009-04-17 13:48 18304 c:\windows\system32\DRVSTORE\grmnusb_8E661E05CC789A6D1B8ABAA087CF60EDD72AC35D\I386\grmngen.sys
    + 2010-04-21 22:32 . 2008-03-10 13:32 26368 c:\windows\system32\DRVSTORE\fpsxx_usb_17EDE44B22398B6099FF055B5826FE9350A74460\fpsxx_usb.sys
    + 2010-04-21 22:32 . 2007-04-11 11:44 29184 c:\windows\system32\DRVSTORE\CU-4_BE39028141C25611A698EB678FC8CB41DEB64815\cu4usb.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 22016 c:\windows\system32\DRVSTORE\ccdcmbo_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\ccdcmbo.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 91136 c:\windows\system32\DRVSTORE\ccdcmb_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\nmwcdcls.dll
    + 2010-05-31 19:16 . 2009-10-06 09:52 17664 c:\windows\system32\DRVSTORE\ccdcmb_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\ccdcmb.sys
    + 2006-09-28 18:00 . 2008-01-18 21:53 83328 c:\windows\system32\drivers\WudfRd.sys
    + 2006-09-28 17:55 . 2008-01-18 21:52 77696 c:\windows\system32\drivers\WudfPf.sys
    + 2010-03-05 22:07 . 2009-08-14 09:10 58208 c:\windows\system32\drivers\wsimd.sys
    + 2006-10-18 19:00 . 2006-10-18 19:00 38528 c:\windows\system32\drivers\wpdusb.sys
    + 2006-11-02 05:22 . 2009-07-14 08:35 37608 c:\windows\system32\drivers\wdfldr.sys
    + 2008-07-23 22:29 . 2008-07-23 22:29 47744 c:\windows\system32\drivers\vserial.sys
    + 2008-07-23 22:29 . 2008-07-23 22:29 15264 c:\windows\system32\drivers\vsb.sys
    + 2008-12-22 11:18 . 2008-12-22 11:18 17416 c:\windows\system32\drivers\VHIDMini.sys
    + 2009-01-08 00:20 . 2009-01-08 00:20 31880 c:\windows\system32\drivers\VcommMgr.sys
    + 2008-01-21 17:27 . 2008-01-21 17:27 14856 c:\windows\system32\drivers\VComm.sys
    + 2010-04-15 21:27 . 2008-04-13 22:15 26112 c:\windows\system32\drivers\usbser.sys
    - 2008-04-14 00:15 . 2008-04-13 22:15 49408 c:\windows\system32\drivers\stream.sys
    + 2008-04-14 00:15 . 2008-04-13 23:15 49408 c:\windows\system32\drivers\stream.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 12424 c:\windows\system32\drivers\s125whnt.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 12424 c:\windows\system32\drivers\s125wh.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 98696 c:\windows\system32\drivers\s125obex.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 15112 c:\windows\system32\drivers\s125mdfl.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 12424 c:\windows\system32\drivers\s125cmnt.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 12424 c:\windows\system32\drivers\s125cm.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 83336 c:\windows\system32\drivers\s125bus.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 59136 c:\windows\system32\drivers\rfcomm.sys
    + 2010-05-31 19:17 . 2008-08-26 07:26 18816 c:\windows\system32\drivers\pccsmcfd.sys
    - 2008-05-16 14:59 . 2007-08-31 19:15 18856 c:\windows\system32\drivers\nuidfltr.sys
    + 2010-05-23 23:30 . 2009-01-07 16:45 18856 c:\windows\system32\drivers\nuidfltr.sys
    - 2008-05-16 13:51 . 2008-04-13 22:09 14592 c:\windows\system32\drivers\kbdhid.sys
    + 2010-05-24 21:48 . 2008-04-13 22:09 14592 c:\windows\system32\drivers\kbdhid.sys
    + 2010-04-06 16:32 . 2008-07-02 12:58 26248 c:\windows\system32\drivers\IvtBtBus.sys
    - 2009-02-21 23:45 . 2008-04-13 22:15 60160 c:\windows\system32\drivers\drmk.sys
    + 2009-02-21 23:45 . 2008-04-13 23:15 60160 c:\windows\system32\drivers\drmk.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 22016 c:\windows\system32\drivers\ccdcmbo.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 17664 c:\windows\system32\drivers\ccdcmb.sys
    + 2006-11-22 11:41 . 2006-11-22 11:41 22416 c:\windows\system32\drivers\BTNetFilter.sys
    + 2008-12-07 10:44 . 2008-12-07 10:44 14088 c:\windows\system32\drivers\btnetdrv.sys
    + 2010-04-06 16:33 . 2008-12-07 10:44 30088 c:\windows\system32\drivers\btnetBus.sys
    + 2010-05-22 15:13 . 2008-04-13 22:16 18944 c:\windows\system32\drivers\BTHUSB.SYS
    + 2010-05-22 15:41 . 2008-04-13 22:16 37888 c:\windows\system32\drivers\bthmodem.sys
    + 2010-04-06 16:32 . 2009-01-07 21:39 20744 c:\windows\system32\drivers\BtHidBus.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 17024 c:\windows\system32\drivers\bthenum.sys
    + 2009-01-03 14:40 . 2009-01-03 14:40 39304 c:\windows\system32\drivers\btcusb.sys
    + 2008-11-25 13:23 . 2008-11-25 13:23 27528 c:\windows\system32\drivers\BlueletSCOAudio.sys
    + 2008-11-25 13:23 . 2008-11-25 13:23 33800 c:\windows\system32\drivers\blueletaudio.sys
    + 2009-02-21 22:57 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll
    + 2009-02-21 22:57 . 2009-08-06 17:24 53472 c:\windows\system32\dllcache\wuauclt.exe
    + 2008-11-27 03:45 . 2006-10-18 19:47 99840 c:\windows\system32\dllcache\wmpshell.dll
    + 2009-02-21 22:57 . 2006-10-18 19:46 64000 c:\windows\system32\dllcache\wmplayer.exe
    + 2009-02-21 22:57 . 2006-10-18 19:47 96256 c:\windows\system32\dllcache\wmpband.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 37376 c:\windows\system32\dllcache\wmdmps.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 33792 c:\windows\system32\dllcache\wmdmlog.dll
    - 2009-03-16 00:08 . 2008-04-13 23:15 26112 c:\windows\system32\dllcache\usbser.sys
    + 2010-04-15 21:27 . 2008-04-13 22:15 26112 c:\windows\system32\dllcache\usbser.sys
    - 2008-04-14 00:15 . 2008-04-13 22:15 49408 c:\windows\system32\dllcache\stream.sys
    + 2008-04-14 00:15 . 2008-04-13 23:15 49408 c:\windows\system32\dllcache\stream.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 59136 c:\windows\system32\dllcache\rfcomm.sys
    - 2009-03-16 00:03 . 2008-04-13 23:16 59136 c:\windows\system32\dllcache\rfcomm.sys
    + 2008-11-27 03:45 . 2006-10-18 20:47 27136 c:\windows\system32\dllcache\mspmsnsv.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 11264 c:\windows\system32\dllcache\LAPRXY.dll
    + 2010-05-24 21:48 . 2008-04-13 22:09 14592 c:\windows\system32\dllcache\kbdhid.sys
    - 2008-05-16 13:51 . 2008-04-13 22:09 14592 c:\windows\system32\dllcache\kbdhid.sys
    - 2009-03-15 23:57 . 2008-04-14 04:41 28160 c:\windows\system32\dllcache\irmon.dll
    + 2010-05-22 15:14 . 2008-04-14 03:41 28160 c:\windows\system32\dllcache\irmon.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 89088 c:\windows\system32\dllcache\filterpipelineprintproc.dll
    + 2009-02-21 23:45 . 2008-04-13 23:15 60160 c:\windows\system32\dllcache\drmk.sys
    - 2009-02-21 23:45 . 2008-04-13 22:15 60160 c:\windows\system32\dllcache\drmk.sys
    + 2008-11-27 03:45 . 2009-08-06 17:24 96480 c:\windows\system32\dllcache\cdm.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 26112 c:\windows\system32\dllcache\cache\userinit.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 14336 c:\windows\system32\dllcache\cache\svchost.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 17408 c:\windows\system32\dllcache\cache\powrprof.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 13312 c:\windows\system32\dllcache\cache\lsass.exe
    + 2009-07-11 21:40 . 2008-04-13 22:09 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
    + 2009-07-11 21:40 . 2008-11-27 03:45 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
    + 2009-07-11 21:40 . 2008-11-27 03:45 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
    + 2010-05-22 15:13 . 2008-04-13 22:16 18944 c:\windows\system32\dllcache\bthusb.sys
    - 2009-03-15 23:49 . 2008-04-13 23:16 18944 c:\windows\system32\dllcache\bthusb.sys
    - 2009-03-15 23:49 . 2008-04-13 23:16 37888 c:\windows\system32\dllcache\bthmodem.sys
    + 2010-05-22 15:41 . 2008-04-13 22:16 37888 c:\windows\system32\dllcache\bthmodem.sys
    - 2009-03-15 23:49 . 2008-04-13 23:16 17024 c:\windows\system32\dllcache\bthenum.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 17024 c:\windows\system32\dllcache\bthenum.sys
    + 2008-07-25 10:16 . 2008-07-25 10:16 96760 c:\windows\system32\dfshim.dll
    - 2009-02-21 23:12 . 2009-02-21 23:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2009-02-21 23:12 . 2010-05-26 16:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2009-02-21 23:12 . 2010-05-26 16:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2009-02-21 23:12 . 2009-02-21 23:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2009-02-21 23:12 . 2009-02-21 23:12 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-02-21 23:12 . 2010-05-26 16:09 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2008-11-27 03:45 . 2009-08-06 17:24 96480 c:\windows\system32\cdm.dll
    + 2009-01-03 14:40 . 2009-01-03 14:40 15368 c:\windows\system32\btinstall.dll
    + 2009-02-27 14:45 . 2009-02-27 14:45 57430 c:\windows\system32\btfunc.dll
    + 2008-10-22 13:30 . 2008-10-22 13:30 81920 c:\windows\system32\BsVistaCommon.dll
    + 2009-02-27 14:40 . 2009-02-27 14:40 28760 c:\windows\system32\BsTrace.dll
    + 2009-02-27 14:45 . 2009-02-27 14:45 18432 c:\windows\system32\BsMonSvr.dll
    + 2009-02-27 14:40 . 2009-02-27 14:40 28672 c:\windows\system32\BsMobileCSps.dll
    + 2009-02-27 14:43 . 2009-02-27 14:43 94314 c:\windows\system32\BsHelpCSps.dll
    + 2009-02-27 14:41 . 2009-02-27 14:41 98403 c:\windows\system32\Bs2Res.dll
    + 2006-07-11 17:07 . 2006-07-11 17:07 89600 c:\windows\system32\atl71.dll
    + 2010-03-05 22:09 . 2009-08-14 09:09 73800 c:\windows\system32\athgina.dll
    + 2009-08-06 17:24 . 2009-08-06 17:24 44768 c:\windows\SoftwareDistribution\SelfUpdate\wups2.dll
    + 2009-08-06 17:24 . 2009-08-06 17:24 35552 c:\windows\SoftwareDistribution\SelfUpdate\wups.dll
    + 2009-08-06 17:24 . 2009-08-06 17:24 53472 c:\windows\SoftwareDistribution\SelfUpdate\wuauclt.exe
    + 2009-08-06 17:24 . 2009-08-06 17:24 96480 c:\windows\SoftwareDistribution\SelfUpdate\cdm.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 70648 c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 91136 c:\windows\Microsoft.NET\Framework\v3.5\MSBuild.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.VisualC.STLCLR.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 40960 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Data.Entity.Build.Tasks.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 89080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2052.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 92664 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1042.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 95224 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1041.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 89592 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1028.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 84480 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2052.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 94720 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1042.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 97792 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1041.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 84992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1028.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 97280 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 95224 c:\windows\Microsoft.NET\Framework\v3.5\EdmGen.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 78856 c:\windows\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 41984 c:\windows\Microsoft.NET\Framework\v3.5\AddInUtil.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 41992 c:\windows\Microsoft.NET\Framework\v3.5\AddInProcess.exe
    + 2008-07-29 20:10 . 2008-07-29 20:10 46104 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
    + 2008-07-29 18:59 . 2008-07-29 18:59 32768 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
    + 2008-07-29 20:10 . 2008-07-29 20:10 71160 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
    + 2008-07-29 18:32 . 2008-07-29 18:32 17448 c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
    + 2008-07-29 18:16 . 2008-07-29 18:16 32768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 73728 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 20504 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 11280 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 37896 c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 81400 c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL
    + 2008-07-25 10:17 . 2008-07-25 10:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 57392 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 95232 c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 16896 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 61952 c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
    - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
    - 2005-09-23 06:28 . 2005-09-23 06:28 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 88584 c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 24584 c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 31744 c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 19456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 18944 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 77312 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 94208 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 46592 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 83456 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 69632 c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 97792 c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 12800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 32768 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 72192 c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 65032 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
    - 2005-09-23 06:28 . 2005-09-23 06:28 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 18936 c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 62968 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 35320 c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 27136 c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 80376 c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 89608 c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 33792 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 34312 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 33288 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 24576 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 84480 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 33800 c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 17416 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 22024 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 58880 c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 98808 c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 13824 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 96768 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 16896 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 16896 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 16896 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 82944 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
    + 2008-08-26 06:09 . 2008-08-26 06:09 23040 c:\windows\Installer\e88c5.msp
    + 2010-02-28 11:06 . 2010-02-28 11:06 88576 c:\windows\Installer\9138d.msi
    - 2008-05-16 15:03 . 2008-05-16 15:03 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut2_6463554370E7436D8D6D4A721595029E.exe
    + 2008-05-16 15:03 . 2010-01-10 10:42 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut2_6463554370E7436D8D6D4A721595029E.exe
    - 2008-05-16 15:03 . 2008-05-16 15:03 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut1_6463554370E7436D8D6D4A721595029E.exe
    + 2008-05-16 15:03 . 2010-01-10 10:42 29926 c:\windows\Installer\{8C5FAD77-F678-4758-A296-C12F08D179E0}\NewShortcut1_6463554370E7436D8D6D4A721595029E.exe
    + 2010-05-31 19:17 . 2010-05-31 19:17 10134 c:\windows\Installer\{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}\ARPPRODUCTICON.exe
    + 2010-04-21 22:45 . 2010-04-21 22:45 40960 c:\windows\Installer\{5A32C25A-7E99-4A77-B419-B47DA290DD67}\NewShortcut3_DABD3D3B83CC411A8B6B456C8FCA7B81.exe
    + 2010-04-21 22:45 . 2010-04-21 22:45 45056 c:\windows\Installer\{5A32C25A-7E99-4A77-B419-B47DA290DD67}\NewShortcut2_DABD3D3B83CC411A8B6B456C8FCA7B81.exe
    + 2010-04-21 22:45 . 2010-04-21 22:45 45056 c:\windows\Installer\{5A32C25A-7E99-4A77-B419-B47DA290DD67}\NewShortcut1_DABD3D3B83CC411A8B6B456C8FCA7B81.exe
    + 2010-04-21 22:45 . 2010-04-21 22:45 40960 c:\windows\Installer\{5A32C25A-7E99-4A77-B419-B47DA290DD67}\NewShortcut1_1.17B8F41E_E645_4C81_BE59_DFF1C52F66EF.exe
    + 2010-04-21 22:45 . 2010-04-21 22:45 10134 c:\windows\Installer\{5A32C25A-7E99-4A77-B419-B47DA290DD67}\ARPPRODUCTICON.exe
    + 2010-04-21 22:32 . 2010-04-21 22:32 10134 c:\windows\Installer\{3DAD83B9-4C8B-4AC6-BF5E-B9FB181CCBE8}\ARPPRODUCTICON.exe
    + 2010-02-28 14:16 . 2010-02-28 14:16 45056 c:\windows\Installer\{3A56CA23-F10D-4755-BD25-57578CBFD59C}\BsolStartupShortcut_5F4A9C5DDE4741A284DAEED5CA08428B.exe
    - 2008-05-16 14:59 . 2008-05-16 14:59 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut2_5D5B9E6A344C497695ABABBDC648E5DA.exe
    + 2008-05-16 14:59 . 2010-05-24 21:48 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut2_5D5B9E6A344C497695ABABBDC648E5DA.exe
    + 2008-05-16 14:59 . 2010-05-24 21:48 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut1_5D5B9E6A344C497695ABABBDC648E5DA.exe
    - 2008-05-16 14:59 . 2008-05-16 14:59 29926 c:\windows\Installer\{345112D9-0930-4A68-AB71-A831BA5DE7AA}\NewShortcut1_5D5B9E6A344C497695ABABBDC648E5DA.exe
    + 2009-12-18 03:05 . 2009-12-18 03:05 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\ViewerPS.dll
    + 2009-12-18 06:58 . 2009-12-18 06:58 40368 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\reader_sl.exe
    + 2009-12-18 03:05 . 2009-12-18 03:05 67016 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\PDFPrevHndlrShim.exe
    + 2009-12-18 03:04 . 2009-12-18 03:04 83376 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\PDFPrevHndlr.dll
    + 2009-12-18 00:43 . 2009-12-18 00:43 95672 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\nppdf32.dll
    + 2009-12-18 00:57 . 2009-12-18 00:57 13752 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32Info.exe
    + 2009-12-18 00:16 . 2009-12-18 00:16 65536 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\Acrofx32.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 89088 c:\windows\Driver Cache\i386\filterpipelineprintproc.dll
    + 2010-02-28 11:31 . 2010-02-28 11:31 60928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\8f5c0e1b77c840d99a68897898317b79\UIAutomationProvider.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\b5a285233229bb4f9d9831ebf27fe9ac\System.Windows.Presentation.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\17e2a7113434da494a846a8f4e4ac5e9\System.Web.DynamicData.Design.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\a8e047504bdad9ec14efd483574b0dd5\System.ComponentModel.DataAnnotations.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f2b48eab657b4ef1d19dac11bdf0c913\System.AddIn.Contract.ni.dll
    + 2010-02-28 11:18 . 2010-02-28 11:18 47104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\9469981a17c01dd154c540127e678b35\PresentationFontCache.ni.exe
    + 2010-02-28 11:16 . 2010-02-28 11:16 39424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\487c1bc20f6e73e8e79503898d17d102\PresentationCFFRasterizer.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\28ea74096df47800fe2c78bb2b9a4f2a\Microsoft.Vsa.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 74752 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\66359457e427c0d547750a79f754f9ba\Microsoft.Build.Framework.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 65024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\36dbc4689f7c51e393504230004c9dec\Microsoft.Build.Framework.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 14336 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\a2865dcec9c5d3cc9c55f026cbad6fcc\dfsvc.ni.exe
    + 2010-02-28 12:09 . 2010-02-28 12:09 25600 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\c2af7cfbb47c077029a2645930b4eeac\Accessibility.ni.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 94208 c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 98304 c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 40960 c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 12288 c:\windows\assembly\GAC_MSIL\System.Windows.Presentation\3.5.0.0__b77a5c561934e089\System.Windows.Presentation.dll
    + 2010-02-28 11:11 . 2010-02-28 11:11 61440 c:\windows\assembly\GAC_MSIL\System.Web.Routing\3.5.0.0__31bf3856ad364e35\System.Web.Routing.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 32768 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData.Design\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 77824 c:\windows\assembly\GAC_MSIL\System.Web.Abstractions\3.5.0.0__31bf3856ad364e35\System.Web.Abstractions.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 32768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 73728 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 53248 c:\windows\assembly\GAC_MSIL\System.Data.DataSetExtensions\3.5.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 57344 c:\windows\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\3.5.0.0__31bf3856ad364e35\System.ComponentModel.DataAnnotations.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 45056 c:\windows\assembly\GAC_MSIL\System.AddIn.Contract\2.0.0.0__b03f5f7f11d50a3a\System.AddIn.Contract.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 46104 c:\windows\assembly\GAC_MSIL\PresentationFontCache\3.0.0.0__31bf3856ad364e35\PresentationFontCache.exe
    + 2010-02-28 11:09 . 2010-02-28 11:09 32768 c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 41984 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\1.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.STLCLR.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 94208 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.v3.5.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
    + 2010-02-28 13:12 . 2006-09-15 22:30 55296 c:\windows\$NtUninstallWudf01007$\wudfsvc.dll
    + 2010-02-28 13:12 . 2006-09-15 21:30 82688 c:\windows\$NtUninstallWudf01007$\wudfrd.sys
    + 2010-02-28 13:12 . 2006-09-15 21:29 76544 c:\windows\$NtUninstallWudf01007$\wudfpf.sys
    + 2010-02-28 13:12 . 2006-09-15 22:30 87040 c:\windows\$NtUninstallWudf01007$\wudfcoinstaller.dll
    + 2010-02-28 13:12 . 2008-01-18 21:53 72704 c:\windows\$NtUninstallWudf01007$\spuninst\WudfCustom.dll
    + 2010-02-28 11:56 . 2006-09-28 17:56 55808 c:\windows\$NtUninstallWudf01005$\wudfsvc.dll
    + 2010-02-28 11:56 . 2006-09-28 18:00 82944 c:\windows\$NtUninstallWudf01005$\wudfrd.sys
    + 2010-02-28 11:56 . 2006-09-28 17:55 77568 c:\windows\$NtUninstallWudf01005$\wudfpf.sys
    + 2010-02-28 11:56 . 2006-09-28 19:13 95344 c:\windows\$NtUninstallWudf01005$\wudfcoinstaller.dll
    + 2010-02-28 11:56 . 2006-09-15 21:30 70656 c:\windows\$NtUninstallWudf01005$\spuninst\WudfCustom.dll
    + 2010-02-28 11:13 . 2006-09-28 18:01 58368 c:\windows\$NtUninstallWudf01000$\spuninst\WudfCustom.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 23552 c:\windows\$NtUninstallWMFDist11$\wmdmps.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 27136 c:\windows\$NtUninstallWMFDist11$\wmdmlog.dll
    + 2010-02-28 11:14 . 2006-11-02 10:46 13312 c:\windows\$NtUninstallWMFDist11$\spuninst\wpdinstallutil.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 52224 c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
    + 2010-04-17 11:30 . 2008-03-27 15:27 35040 c:\windows\$NtUninstallWdf01009$\wdfldr.sys
    + 2010-04-17 11:30 . 2009-07-13 14:49 47104 c:\windows\$NtUninstallWdf01009$\spuninst\KmdfCustom.dll
    + 2010-03-23 20:25 . 2006-11-02 05:22 32224 c:\windows\$NtUninstallWdf01007$\wdfldr.sys
    + 2010-02-28 11:06 . 2010-02-28 11:06 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
    + 2010-05-22 15:14 . 2008-04-14 03:42 8192 c:\windows\system32\wshirda.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\wmvdmoe2.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\wmvdmod.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 4096 c:\windows\system32\WMVADVE.DLL
    + 2006-10-18 20:47 . 2006-10-18 20:47 4096 c:\windows\system32\WMVADVD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\wmsdmoe2.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\wmsdmod.dll
    + 2006-10-18 20:58 . 2006-10-18 20:58 8704 c:\windows\system32\wdfmgr.exe
    + 2006-10-18 20:47 . 2006-10-18 20:47 4096 c:\windows\system32\wdfapi.dll
    + 2006-10-18 20:58 . 2006-10-18 20:58 8704 c:\windows\system32\uwdf.exe
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\MPG4DMOD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\MP4SDMOD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\MP43DMOD.dll
    + 2009-02-21 23:45 . 2008-04-14 04:41 4096 c:\windows\system32\ksuser.dll
    - 2009-02-21 23:45 . 2008-04-14 03:41 4096 c:\windows\system32\ksuser.dll
    + 2009-10-19 21:44 . 2007-04-10 16:06 8192 c:\windows\system32\E_DCINST.DLL
    - 2009-10-19 21:44 . 2007-04-10 18:06 8192 c:\windows\system32\E_DCINST.DLL
    + 2010-05-31 19:16 . 2009-10-06 09:56 8320 c:\windows\system32\DRVSTORE\nmwcdnsuc_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\nmwcdnsuc.sys
    + 2010-05-10 16:34 . 2009-04-17 13:48 9344 c:\windows\system32\DRVSTORE\grmnusb_8E661E05CC789A6D1B8ABAA087CF60EDD72AC35D\I386\grmnusb.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 7936 c:\windows\system32\DRVSTORE\ccdcmbm_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\usbser_lowerflt.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 7936 c:\windows\system32\DRVSTORE\ccdcmbcj_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\usbser_lowerfltj.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 7936 c:\windows\system32\drivers\usbser_lowerfltj.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 7936 c:\windows\system32\drivers\usbser_lowerflt.sys
    + 2010-05-31 19:16 . 2009-10-06 09:56 8320 c:\windows\system32\drivers\nmwcdnsuc.sys
    + 2010-05-22 15:14 . 2008-04-14 03:42 8192 c:\windows\system32\dllcache\wshirda.dll
    - 2009-03-16 00:10 . 2008-04-14 04:42 8192 c:\windows\system32\dllcache\wshirda.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\wmvdmoe2.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\wmvdmod.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\wmsdmoe2.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\wmsdmod.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\MPG4DMOD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\MP4SDMOD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 4096 c:\windows\system32\dllcache\MP43DMOD.dll
    - 2009-02-21 23:45 . 2008-04-14 03:41 4096 c:\windows\system32\dllcache\ksuser.dll
    + 2009-02-21 23:45 . 2008-04-14 04:41 4096 c:\windows\system32\dllcache\ksuser.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 7168 c:\windows\system32\dllcache\asferror.dll
    + 2009-02-27 14:45 . 2009-02-27 14:45 9728 c:\windows\system32\BsMonUI.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 7168 c:\windows\system32\asferror.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 5632 c:\windows\Microsoft.NET\Framework\v3.5\Sentinel.v3.5Client.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 7168 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
    - 2005-09-23 06:29 . 2005-09-23 06:29 5632 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 6656 c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 9728 c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 5120 c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
    + 2010-05-31 19:16 . 2010-05-31 19:16 3262 c:\windows\Installer\{C50EF365-2898-489A-B6C7-30DAA466E9A2}\ARPPRODUCTICON.exe
    + 2010-06-09 23:09 . 2010-06-09 23:09 3638 c:\windows\Installer\{C0A871F9-D580-4404-9A69-A02CF3078C87}\ARPPRODUCTICON.exe
    + 2010-02-03 19:43 . 2010-02-03 19:43 5430 c:\windows\Installer\{345CDDCB-8241-4E76-9D3B-155F2FD6F07E}\NewShortcut3_515FF21B9D144F16ACB5BA3C3F6305EE.exe
    + 2010-02-28 11:10 . 2010-02-28 11:10 5632 c:\windows\assembly\GAC_MSIL\Sentinel.v3.5Client\3.5.0.0__b03f5f7f11d50a3a\Sentinel.v3.5Client.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 6656 c:\windows\$NtUninstallWMFDist11$\laprxy.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
    + 2007-11-07 01:19 . 2007-11-07 01:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
    + 2007-11-07 01:19 . 2007-11-07 01:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
    + 2007-11-06 20:23 . 2007-11-06 20:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
    + 2009-07-11 23:12 . 2009-07-11 23:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
    + 2009-07-11 23:09 . 2009-07-11 23:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
    + 2009-07-11 23:08 . 2009-07-11 23:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 635904 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 558080 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcp80.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcm80.dll
    - 2006-06-05 13:14 . 2006-06-05 13:14 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
    + 2006-06-05 12:14 . 2006-06-05 12:14 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
    + 2006-06-05 12:14 . 2006-06-05 12:14 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
    - 2006-06-05 13:14 . 2006-06-05 13:14 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
    + 2006-06-05 12:14 . 2006-06-05 12:14 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
    - 2006-06-05 13:14 . 2006-06-05 13:14 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
    + 2008-07-29 20:26 . 2008-07-29 20:26 301568 c:\windows\system32\XPSViewer\XPSViewer.exe
    + 2010-02-28 11:08 . 2008-07-06 12:06 575488 c:\windows\system32\xpsshhdr.dll
    + 2010-06-07 17:01 . 2009-09-04 15:44 515416 c:\windows\system32\XAudio2_5.dll
    + 2010-06-07 17:01 . 2009-03-16 12:18 517448 c:\windows\system32\XAudio2_4.dll
    + 2010-06-07 17:01 . 2008-10-27 08:04 514384 c:\windows\system32\XAudio2_3.dll
    + 2010-06-07 17:01 . 2008-07-31 08:40 509448 c:\windows\system32\XAudio2_2.dll
    + 2010-06-07 17:01 . 2008-05-30 12:19 507400 c:\windows\system32\XAudio2_1.dll
    + 2010-06-07 17:01 . 2009-09-04 15:44 238936 c:\windows\system32\xactengine3_5.dll
    + 2010-06-07 17:01 . 2009-03-16 12:18 235352 c:\windows\system32\xactengine3_4.dll
    + 2010-06-07 17:01 . 2008-10-27 08:04 235856 c:\windows\system32\xactengine3_3.dll
    + 2010-06-07 17:01 . 2008-07-31 08:41 238088 c:\windows\system32\xactengine3_2.dll
    + 2010-06-07 17:01 . 2008-05-30 12:18 238088 c:\windows\system32\xactengine3_1.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 209624 c:\windows\system32\wuweb.dll
    + 2006-09-28 17:56 . 2008-01-18 23:37 305152 c:\windows\system32\WUDFx.dll
    + 2006-09-28 17:56 . 2008-01-18 21:52 163840 c:\windows\system32\WudfPlatform.dll
    + 2006-09-28 17:56 . 2008-01-18 23:33 142336 c:\windows\system32\WudfHost.exe
    + 2009-02-21 22:57 . 2009-08-06 17:24 327896 c:\windows\system32\wucltui.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 575704 c:\windows\system32\wuapi.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 249924 c:\windows\system32\wsimd.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 254022 c:\windows\system32\wsfwDS.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 356352 c:\windows\system32\wpdsp.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 133632 c:\windows\system32\WPDShServiceObj.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 154624 c:\windows\system32\wpdmtp.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 629760 c:\windows\system32\wpd_ci.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 656896 c:\windows\system32\WMVXENCD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 767488 c:\windows\system32\WMVSENCD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 603648 c:\windows\system32\WMSPDMOD.dll
    + 2006-10-18 19:47 . 2006-10-18 19:47 204288 c:\windows\system32\wmpsrcwp.dll
    + 2006-10-18 19:47 . 2006-10-18 19:47 130048 c:\windows\system32\wmpps.dll
    + 2006-10-18 19:47 . 2006-10-18 19:47 613376 c:\windows\system32\wmpmde.dll
    + 2006-10-18 19:47 . 2006-10-18 19:47 295936 c:\windows\system32\wmpeffects.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 314880 c:\windows\system32\wmpdxm.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 242688 c:\windows\system32\wmpasf.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 937984 c:\windows\system32\WMNetMgr.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 157184 c:\windows\system32\wmidx.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 227328 c:\windows\system32\wmerror.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 535040 c:\windows\system32\wmdrmsdk.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 348672 c:\windows\system32\wmdrmnet.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 429056 c:\windows\system32\wmdrmdev.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 222208 c:\windows\system32\WMASF.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 757248 c:\windows\system32\WMADMOD.dll
    + 2010-03-05 22:07 . 2009-08-14 12:50 421973 c:\windows\system32\wgapi.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 356443 c:\windows\system32\wcapiU.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 405504 c:\windows\system32\wcapi.dll
    + 2009-02-27 14:44 . 2009-02-27 14:44 114774 c:\windows\system32\versit.dll
     
  17. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    + 2008-07-29 18:59 . 2008-07-29 18:59 161296 c:\windows\system32\UIAutomationCore.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\mxdwdrv.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 765440 c:\windows\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\mxdwdrv.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 748032 c:\windows\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 147456 c:\windows\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
    + 2010-02-28 11:08 . 2008-07-06 10:50 597504 c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
    + 2009-04-04 15:57 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\unires.dll
    - 2009-04-04 15:57 . 2007-05-15 11:38 761344 c:\windows\system32\spool\drivers\w32x86\3\UNIRES.DLL
    + 2009-04-04 15:57 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
    + 2009-04-04 15:57 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\unidrv.dll
    - 2009-04-04 15:57 . 2008-04-14 03:42 373248 c:\windows\system32\spool\drivers\w32x86\3\UNIDRV.DLL
    + 2010-02-28 11:08 . 2008-07-06 12:06 198656 c:\windows\system32\spool\drivers\w32x86\3\mxdwdui.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll
    + 2010-06-25 21:11 . 2009-08-06 17:23 575704 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wuapi.dll\7.4.7600.226\wuapi.dll
    + 2006-08-24 15:15 . 2006-08-24 15:15 150808 c:\windows\system32\rgb9rast_2.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 211456 c:\windows\system32\qasf.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 117760 c:\windows\system32\prntvpt.dll
    + 2008-07-29 18:59 . 2008-07-29 18:59 781344 c:\windows\system32\PresentationNative_v0300.dll
    + 2008-07-29 19:35 . 2008-07-29 19:35 326160 c:\windows\system32\PresentationHost.exe
    + 2008-07-29 18:59 . 2008-07-29 18:59 105016 c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 199168 c:\windows\system32\PortableDeviceWMDRM.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 132096 c:\windows\system32\PortableDeviceWiaCompat.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 166912 c:\windows\system32\PortableDeviceTypes.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 101888 c:\windows\system32\PortableDeviceClassExtension.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 284160 c:\windows\system32\PortableDeviceApi.dll
    + 2008-11-27 03:45 . 2010-05-31 18:34 435840 c:\windows\system32\perfh009.dat
    + 2009-02-27 14:44 . 2009-02-27 14:44 278647 c:\windows\system32\outlookAddin.dll
    + 1998-12-03 16:51 . 1998-12-03 16:51 372736 c:\windows\system32\ogc7050r.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 167936 c:\windows\system32\nvwrszht.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 167936 c:\windows\system32\nvwrszht.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 163840 c:\windows\system32\nvwrszhc.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 163840 c:\windows\system32\nvwrszhc.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 303104 c:\windows\system32\nvwrstr.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 303104 c:\windows\system32\nvwrstr.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 294912 c:\windows\system32\nvwrssv.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 294912 c:\windows\system32\nvwrssv.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 303104 c:\windows\system32\nvwrssl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 303104 c:\windows\system32\nvwrssl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 299008 c:\windows\system32\nvwrssk.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 299008 c:\windows\system32\nvwrssk.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 315392 c:\windows\system32\nvwrsru.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 315392 c:\windows\system32\nvwrsru.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 319488 c:\windows\system32\nvwrsptb.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 319488 c:\windows\system32\nvwrsptb.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 323584 c:\windows\system32\nvwrspt.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 323584 c:\windows\system32\nvwrspt.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 294912 c:\windows\system32\nvwrspl.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 294912 c:\windows\system32\nvwrspl.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 299008 c:\windows\system32\nvwrsno.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 299008 c:\windows\system32\nvwrsno.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 319488 c:\windows\system32\nvwrsnl.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 319488 c:\windows\system32\nvwrsnl.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 196608 c:\windows\system32\nvwrsko.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 196608 c:\windows\system32\nvwrsko.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 212992 c:\windows\system32\nvwrsja.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 212992 c:\windows\system32\nvwrsja.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 323584 c:\windows\system32\nvwrsit.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 323584 c:\windows\system32\nvwrsit.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 315392 c:\windows\system32\nvwrshu.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 315392 c:\windows\system32\nvwrshu.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 278528 c:\windows\system32\nvwrshe.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 278528 c:\windows\system32\nvwrshe.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 327680 c:\windows\system32\nvwrsfr.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 327680 c:\windows\system32\nvwrsfr.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 303104 c:\windows\system32\nvwrsfi.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 303104 c:\windows\system32\nvwrsfi.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 327680 c:\windows\system32\nvwrsesm.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 327680 c:\windows\system32\nvwrsesm.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 335872 c:\windows\system32\nvwrses.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 335872 c:\windows\system32\nvwrses.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 286720 c:\windows\system32\nvwrseng.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 286720 c:\windows\system32\nvwrseng.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 335872 c:\windows\system32\nvwrsel.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 335872 c:\windows\system32\nvwrsel.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 311296 c:\windows\system32\nvwrsde.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 311296 c:\windows\system32\nvwrsde.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 294912 c:\windows\system32\nvwrsda.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 294912 c:\windows\system32\nvwrsda.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 286720 c:\windows\system32\nvwrscs.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 286720 c:\windows\system32\nvwrscs.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 282624 c:\windows\system32\nvwrsar.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 282624 c:\windows\system32\nvwrsar.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 131139 c:\windows\system32\nvsvc32.exe
    - 2009-02-27 14:22 . 2008-05-16 13:01 466944 c:\windows\system32\nvshell.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 466944 c:\windows\system32\nvshell.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 118784 c:\windows\system32\nvrszht.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 217088 c:\windows\system32\nvrszhc.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 249856 c:\windows\system32\nvrstr.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 245760 c:\windows\system32\nvrssv.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 249856 c:\windows\system32\nvrssl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 249856 c:\windows\system32\nvrssk.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 262144 c:\windows\system32\nvrsru.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 262144 c:\windows\system32\nvrsptb.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 266240 c:\windows\system32\nvrspt.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 249856 c:\windows\system32\nvrspl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 249856 c:\windows\system32\nvrsno.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 266240 c:\windows\system32\nvrsnl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 253952 c:\windows\system32\nvrsko.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 258048 c:\windows\system32\nvrsja.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 274432 c:\windows\system32\nvrsit.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 253952 c:\windows\system32\nvrshu.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 319488 c:\windows\system32\nvrshe.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 278528 c:\windows\system32\nvrsfr.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 241664 c:\windows\system32\nvrsfi.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 266240 c:\windows\system32\nvrsesm.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 274432 c:\windows\system32\nvrses.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 241664 c:\windows\system32\nvrseng.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 274432 c:\windows\system32\nvrsel.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 270336 c:\windows\system32\nvrsde.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 245760 c:\windows\system32\nvrsda.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 241664 c:\windows\system32\nvrscs.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 319488 c:\windows\system32\nvrsar.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 286720 c:\windows\system32\nvnt4cpl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 286720 c:\windows\system32\nvnt4cpl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 229376 c:\windows\system32\nvmccs.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 229376 c:\windows\system32\nvmccs.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 573440 c:\windows\system32\nvhwvid.dll
    - 2009-02-27 14:22 . 2006-03-17 12:16 573440 c:\windows\system32\nvhwvid.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 147456 c:\windows\system32\nvcolor.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 147456 c:\windows\system32\nvcolor.exe
    - 2009-02-27 14:22 . 2008-05-16 13:01 442368 c:\windows\system32\nvappbar.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 442368 c:\windows\system32\nvappbar.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 110592 c:\windows\system32\nvapi.dll
    + 2010-05-31 19:16 . 2009-10-06 09:52 660480 c:\windows\system32\nmwcdcocls.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 321536 c:\windows\system32\mswmdm.dll
    + 2006-07-11 17:35 . 2006-07-11 17:35 503808 c:\windows\system32\msvcp71.dll
    + 2002-01-05 01:40 . 2002-01-05 01:40 487424 c:\windows\system32\msvcp70.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 414208 c:\windows\system32\msscp.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 175616 c:\windows\system32\mspmsp.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 179712 c:\windows\system32\msnetobj.dll
    + 2006-10-02 13:28 . 2006-10-02 13:28 312128 c:\windows\system32\msdelta.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 158720 c:\windows\system32\mscorier.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 282112 c:\windows\system32\mscoree.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 259072 c:\windows\system32\MPG4DECD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 317440 c:\windows\system32\MP4SDECD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 259072 c:\windows\system32\MP43DECD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 212992 c:\windows\system32\MFPLAT.dll
    + 2010-06-19 06:39 . 2010-06-22 22:29 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe
    + 2008-11-27 03:45 . 2006-10-18 19:03 100864 c:\windows\system32\logagent.exe
    - 2009-02-27 14:22 . 2008-05-16 13:01 425984 c:\windows\system32\keystone.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 425984 c:\windows\system32\keystone.exe
    + 2010-05-28 22:12 . 2010-04-12 15:29 153376 c:\windows\system32\javaws.exe
    + 2010-05-28 22:12 . 2010-04-12 15:29 145184 c:\windows\system32\javaw.exe
    + 2010-05-28 22:12 . 2010-04-12 15:29 145184 c:\windows\system32\java.exe
    + 2010-05-22 15:14 . 2008-04-14 03:42 151552 c:\windows\system32\irftp.exe
    + 2010-03-05 22:08 . 2009-08-14 09:09 262216 c:\windows\system32\IPTests.dll
    + 2008-07-29 18:24 . 2008-07-29 18:24 622080 c:\windows\system32\icardagt.exe
    + 2008-11-27 03:45 . 2008-04-14 03:42 193024 c:\windows\system32\fsquirt.exe
    - 2008-11-27 03:45 . 2008-11-27 03:45 193024 c:\windows\system32\fsquirt.exe
    + 2008-07-29 20:10 . 2008-07-29 20:10 493048 c:\windows\system32\evr.dll
    + 2003-10-06 17:50 . 2003-10-06 17:50 131072 c:\windows\system32\dzip32.dll
    + 2002-03-13 00:57 . 2002-03-13 00:57 110592 c:\windows\system32\dunzip32.dll
    + 2010-05-31 19:17 . 2009-05-11 10:30 547840 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\PCCSWpdDriver.dll
    + 2010-05-31 19:16 . 2009-10-06 09:56 136704 c:\windows\system32\DRVSTORE\nmwcdnsu_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\nmwcdnsu.sys
    + 2010-05-31 19:16 . 2009-10-06 09:52 660480 c:\windows\system32\DRVSTORE\ccdcmb_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\nmwcdcocls.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 991744 c:\windows\system32\drmv2clt.dll
    + 2006-10-18 19:00 . 2006-10-18 19:00 249856 c:\windows\system32\drmupgds.exe
    + 2006-11-02 05:22 . 2009-07-14 08:35 444136 c:\windows\system32\drivers\wdf01000.sys
    + 2006-10-18 20:47 . 2006-10-18 20:47 671232 c:\windows\system32\drivers\UMDF\wpdmtpdr.dll
    + 2009-05-11 10:30 . 2009-05-11 10:30 547840 c:\windows\system32\drivers\UMDF\PCCSWpdDriver.dll
    + 2010-02-03 19:46 . 2007-04-24 10:33 100488 c:\windows\system32\drivers\s125mgmt.sys
    + 2010-02-03 19:46 . 2007-04-24 10:33 108680 c:\windows\system32\drivers\s125mdm.sys
    - 2009-02-21 23:45 . 2008-04-13 22:49 146048 c:\windows\system32\drivers\portcls.sys
    + 2009-02-21 23:45 . 2008-04-13 23:49 146048 c:\windows\system32\drivers\portcls.sys
    + 2010-05-31 19:16 . 2009-10-06 09:56 136704 c:\windows\system32\drivers\nmwcdnsu.sys
    - 2008-04-14 00:46 . 2008-04-13 22:46 141056 c:\windows\system32\drivers\ks.sys
    + 2008-04-14 00:46 . 2008-04-13 23:46 141056 c:\windows\system32\drivers\ks.sys
    + 2007-03-19 08:59 . 2007-03-19 08:59 116021 c:\windows\system32\drivers\fw203x.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 273024 c:\windows\system32\drivers\bthport.sys
    + 2010-05-22 15:15 . 2008-04-13 22:21 101120 c:\windows\system32\drivers\bthpan.sys
    + 2007-03-19 08:59 . 2007-03-19 08:59 148830 c:\windows\system32\drivers\bcbthub.sys
    + 2010-02-28 11:08 . 2008-07-06 12:06 575488 c:\windows\system32\dllcache\xpsshhdr.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 209624 c:\windows\system32\dllcache\wuweb.dll
    + 2009-02-21 22:57 . 2009-08-06 17:24 327896 c:\windows\system32\dllcache\wucltui.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 575704 c:\windows\system32\dllcache\wuapi.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 603648 c:\windows\system32\dllcache\WMSPDMOD.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 314880 c:\windows\system32\dllcache\wmpdxm.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 242688 c:\windows\system32\dllcache\wmpasf.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 937984 c:\windows\system32\dllcache\WMNetMgr.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 157184 c:\windows\system32\dllcache\wmidx.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 227328 c:\windows\system32\dllcache\wmerror.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 222208 c:\windows\system32\dllcache\WMASF.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 757248 c:\windows\system32\dllcache\WMADMOD.dll
    + 2008-11-27 03:45 . 2006-11-01 16:31 315904 c:\windows\system32\dllcache\unregmp2.exe
    + 2008-11-27 03:45 . 2006-10-18 20:47 211456 c:\windows\system32\dllcache\qasf.dll
    + 2010-02-28 11:08 . 2008-07-06 10:50 597504 c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    + 2009-02-21 23:45 . 2008-04-13 23:49 146048 c:\windows\system32\dllcache\portcls.sys
    - 2009-02-21 23:45 . 2008-04-13 22:49 146048 c:\windows\system32\dllcache\portcls.sys
    + 2008-11-27 03:45 . 2006-10-18 20:47 321536 c:\windows\system32\dllcache\mswmdm.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 414208 c:\windows\system32\dllcache\msscp.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 175616 c:\windows\system32\dllcache\mspmsp.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 179712 c:\windows\system32\dllcache\msnetobj.dll
    + 2009-02-21 22:57 . 2006-10-18 19:47 243712 c:\windows\system32\dllcache\mpvis.dll
    + 2008-11-27 03:45 . 2006-10-18 19:03 100864 c:\windows\system32\dllcache\logagent.exe
    + 2008-04-14 00:46 . 2008-04-13 23:46 141056 c:\windows\system32\dllcache\ks.sys
    - 2008-04-14 00:46 . 2008-04-13 22:46 141056 c:\windows\system32\dllcache\ks.sys
    + 2010-05-22 15:14 . 2008-04-14 03:42 151552 c:\windows\system32\dllcache\irftp.exe
    - 2009-03-15 23:57 . 2008-04-14 04:42 151552 c:\windows\system32\dllcache\irftp.exe
    - 2008-11-27 03:45 . 2008-11-27 03:45 193024 c:\windows\system32\dllcache\fsquirt.exe
    + 2008-11-27 03:45 . 2008-04-14 03:42 193024 c:\windows\system32\dllcache\fsquirt.exe
    + 2008-11-27 03:45 . 2006-10-18 20:47 991744 c:\windows\system32\dllcache\drmv2clt.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 229376 c:\windows\system32\dllcache\cewmdm.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 111104 c:\windows\system32\dllcache\cache\wuauclt.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 507904 c:\windows\system32\dllcache\cache\winlogon.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 666112 c:\windows\system32\dllcache\cache\wininet.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 578560 c:\windows\system32\dllcache\cache\user32.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 295424 c:\windows\system32\dllcache\cache\termsrv.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 361344 c:\windows\system32\dllcache\cache\tcpip.sys
    + 2009-07-11 21:40 . 2008-11-27 03:45 108544 c:\windows\system32\dllcache\cache\services.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 182656 c:\windows\system32\dllcache\cache\ndis.sys
    + 2009-07-11 21:40 . 2008-11-27 03:45 989696 c:\windows\system32\dllcache\cache\kernel32.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 110080 c:\windows\system32\dllcache\cache\imm32.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
    - 2009-03-15 23:49 . 2008-04-13 23:16 273024 c:\windows\system32\dllcache\bthport.sys
    + 2010-05-22 15:14 . 2008-04-13 22:16 273024 c:\windows\system32\dllcache\bthport.sys
    - 2009-03-15 23:49 . 2008-04-13 23:21 101120 c:\windows\system32\dllcache\bthpan.sys
    + 2010-05-22 15:15 . 2008-04-13 22:21 101120 c:\windows\system32\dllcache\bthpan.sys
    + 2008-11-27 03:45 . 2006-10-18 20:47 542720 c:\windows\system32\dllcache\blackbox.dll
    + 2001-08-29 12:11 . 2001-08-29 12:11 398848 c:\windows\system32\DK2WIN32.DLL
    + 2010-06-07 17:01 . 2009-09-04 15:29 235344 c:\windows\system32\d3dx11_42.dll
    + 2010-06-07 17:01 . 2009-09-04 15:29 453456 c:\windows\system32\d3dx10_42.dll
    + 2010-06-07 17:01 . 2009-03-09 13:27 453456 c:\windows\system32\d3dx10_41.dll
    + 2010-06-07 17:01 . 2008-10-10 02:52 452440 c:\windows\system32\d3dx10_40.dll
    + 2010-06-07 17:01 . 2008-07-10 09:01 467984 c:\windows\system32\d3dx10_39.dll
    + 2010-06-07 17:01 . 2008-05-30 12:11 467984 c:\windows\system32\d3dx10_38.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 229376 c:\windows\system32\cewmdm.dll
    + 2009-02-27 14:45 . 2009-02-27 14:45 405589 c:\windows\system32\BsUI.dll
    + 2009-02-27 14:44 . 2009-02-27 14:44 622693 c:\windows\system32\BSShell.dll
    + 2009-02-27 14:41 . 2009-02-27 14:41 241748 c:\windows\system32\BsSDK.dll
    + 2009-02-27 14:43 . 2009-02-27 14:43 114788 c:\windows\system32\BsProfileFunc.dll
    + 2009-02-27 14:41 . 2009-02-27 14:41 122976 c:\windows\system32\BsMobileSDK.dll
    + 2009-02-27 14:43 . 2009-02-27 14:43 151642 c:\windows\system32\BsCommon.dll
    + 2009-02-27 14:43 . 2009-02-27 14:43 557142 c:\windows\system32\Bscdlg.dll
    + 2009-02-27 14:43 . 2009-02-27 14:43 553075 c:\windows\system32\BlueSoleilCSps.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 542720 c:\windows\system32\blackbox.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 276992 c:\windows\system32\audiodev.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 311390 c:\windows\system32\athcfg20U.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 127079 c:\windows\system32\athcfg20resU.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 127053 c:\windows\system32\athcfg20res.dll
    + 2010-03-05 22:07 . 2009-08-14 09:09 237568 c:\windows\system32\athcfg20.dll
    + 2010-03-05 22:08 . 2009-08-14 09:09 495700 c:\windows\system32\acs.exe
    + 2009-08-06 17:24 . 2009-08-06 17:24 209632 c:\windows\SoftwareDistribution\SelfUpdate\wuweb.dll
    + 2009-08-06 17:24 . 2009-08-06 17:24 327896 c:\windows\SoftwareDistribution\SelfUpdate\wucltui.dll
    + 2009-08-06 17:23 . 2009-08-06 17:23 575704 c:\windows\SoftwareDistribution\SelfUpdate\wuapi.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 196104 c:\windows\Microsoft.NET\Framework\v3.5\WFServicesReg.exe
    + 2008-07-29 22:40 . 2008-07-29 22:40 802816 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft.Build.Tasks.v3.5.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 984056 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapUI.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.3082.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.2070.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1055.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 105976 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1053.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 107000 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1049.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 107512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1046.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 109048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1045.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1044.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1043.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 110072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1040.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 111096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1038.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 101368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1037.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 112120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1036.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 106488 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1035.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 113656 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1032.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 111608 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1031.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1030.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 108536 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1029.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 102904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\WapRes.1025.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 689152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsscenario.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 413184 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vsbasereqs.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 632320 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs70uimgr.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 652800 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.msi
    + 2008-07-29 17:47 . 2008-07-29 17:47 110080 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 131584 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.3082.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 131072 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.2070.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1055.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 121344 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1053.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 123904 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1049.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 122880 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1046.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1045.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 121856 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1044.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 129024 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1043.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 128512 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1040.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 132096 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1038.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 111104 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1037.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 133120 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1036.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 122368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1035.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 137728 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1032.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 130048 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1031.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 126464 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1030.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 125440 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1029.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 113152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setupres.1025.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 269304 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
    + 2008-07-29 17:47 . 2008-07-29 17:47 177152 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\HtmlLite.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 276984 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\dlmgr.dll
    + 2008-07-29 22:15 . 2008-07-29 22:15 225490 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\baseline.dat
    + 2008-07-29 22:40 . 2008-07-29 22:40 233976 c:\windows\Microsoft.NET\Framework\v3.5\1033\vbc7ui.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 168448 c:\windows\Microsoft.NET\Framework\v3.5\1033\cscompui.dll
    + 2008-07-29 19:35 . 2008-07-29 19:35 864256 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
    + 2008-07-29 18:59 . 2008-07-29 18:59 132120 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
    + 2008-07-29 20:10 . 2008-07-29 20:10 806928 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NaturalLanguage6.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 152576 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
    + 2008-07-29 18:16 . 2008-07-29 18:16 966656 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 132096 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
    + 2008-07-29 18:16 . 2008-07-29 18:16 110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 156688 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
    + 2008-07-29 18:16 . 2008-07-29 18:16 163840 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 397312 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
    + 2008-07-29 18:24 . 2008-07-29 18:24 881664 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    + 2008-07-29 18:16 . 2008-07-29 18:16 168968 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 438272 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 261632 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 114688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 131072 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 303104 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 113664 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 626688 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 401408 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 970752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 745472 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 486400 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 425984 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 392184 c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 118784 c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 143360 c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 100856 c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 230912 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 345600 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 114176 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 367104 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 308224 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 998408 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 659456 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
    - 2005-09-23 06:29 . 2005-09-23 06:29 372736 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
    - 2005-09-23 06:29 . 2005-09-23 06:29 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 749568 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 655360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 348160 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 230904 c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 798224 c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 575496 c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
    - 2005-09-23 06:28 . 2005-09-23 06:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll
    - 2005-09-23 06:28 . 2005-09-23 06:28 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
    + 2008-07-25 10:16 . 2008-07-25 10:16 106496 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 147968 c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 218112 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 193016 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 145408 c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll
    + 2008-08-26 06:09 . 2008-08-26 06:09 250880 c:\windows\Installer\e88ce.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 278016 c:\windows\Installer\e88cc.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 291840 c:\windows\Installer\e88ca.msp
    + 2010-02-28 11:09 . 2010-02-28 11:09 137728 c:\windows\Installer\e88c4.msi
    + 2008-08-26 06:09 . 2008-08-26 06:09 553472 c:\windows\Installer\91392.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 506368 c:\windows\Installer\91390.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 911360 c:\windows\Installer\9138f.msp
    + 2010-05-24 21:47 . 2010-05-24 21:47 301056 c:\windows\Installer\5feee.msi
    + 2010-05-10 16:34 . 2010-05-10 16:34 406016 c:\windows\Installer\5ee1583.msi
    + 2010-02-28 13:04 . 2010-02-28 13:04 163840 c:\windows\Installer\5aedac.msi
    + 2010-05-31 19:17 . 2010-05-31 19:17 496128 c:\windows\Installer\44e4b5.msi
    + 2010-05-31 19:16 . 2010-05-31 19:16 331776 c:\windows\Installer\44e4af.msi
    + 2010-05-31 19:15 . 2010-05-31 19:15 215552 c:\windows\Installer\44e49d.msi
    + 2010-06-06 21:05 . 2010-06-06 21:05 158720 c:\windows\Installer\3137fbf.msi
    + 2010-06-25 23:12 . 2010-06-25 23:12 219136 c:\windows\Installer\26871c.msi
    + 2010-04-21 22:32 . 2010-04-21 22:32 840192 c:\windows\Installer\1e9cfd.msi
    + 2010-04-21 22:30 . 2010-04-21 22:30 331264 c:\windows\Installer\1e9cf0.msi
    + 2010-04-17 10:02 . 2010-04-17 10:02 424960 c:\windows\Installer\1ac81e.msi
    + 2010-03-05 22:09 . 2010-03-05 22:09 156672 c:\windows\Installer\153e80.msi
    + 2010-04-01 21:07 . 2010-04-01 21:07 180224 c:\windows\Installer\1029811.msi
    + 2010-02-28 11:21 . 2010-02-28 11:21 871424 c:\windows\Installer\10143d.msi
    + 2010-02-28 11:11 . 2010-02-28 11:11 648192 c:\windows\Installer\1013ed.msi
    + 2010-04-04 10:28 . 2010-07-01 14:55 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A82000000003}\SC_Reader.exe
    + 2009-12-18 00:51 . 2009-12-18 00:51 372736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\pdfshell.dll
    + 2009-11-09 20:34 . 2009-11-09 20:34 448512 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\JP2KLib.dll
    + 2009-12-18 00:14 . 2009-12-18 00:14 140728 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AdobeUpdateCheck.exe
    + 2009-12-18 02:55 . 2009-12-18 02:55 738776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AdobeCollabSync.exe
    + 2009-12-18 01:21 . 2009-12-18 01:21 112048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRdIF.dll
    + 2009-12-18 06:58 . 2009-12-18 06:58 345520 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32.exe
    + 2009-12-18 00:17 . 2009-12-18 00:17 632240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroPDF.dll
    + 2008-11-27 03:45 . 2006-11-01 16:31 315904 c:\windows\inf\unregmp2.exe
    + 2010-02-28 11:08 . 2008-03-13 04:52 761344 c:\windows\Driver Cache\i386\unires.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 744960 c:\windows\Driver Cache\i386\unidrvui.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 373248 c:\windows\Driver Cache\i386\unidrv.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 198656 c:\windows\Driver Cache\i386\mxdwdui.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 765440 c:\windows\Driver Cache\i386\mxdwdrv.dll
    + 2009-05-12 11:26 . 2009-05-12 11:26 560544 c:\windows\Downloaded Program Files\MSDcode.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 321024 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\7d2a3adbdcb675f872eb2dbf21f73596\WsatConfig.ni.exe
    + 2010-02-28 11:31 . 2010-02-28 11:31 239616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a18dff8832712a0f6cccaaefbcc45861\WindowsFormsIntegration.ni.dll
    + 2010-02-28 11:31 . 2010-02-28 11:31 187904 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\dbb2fcd246efaf3df823410597cd1677\UIAutomationTypes.ni.dll
    + 2010-02-28 11:30 . 2010-02-28 11:30 447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\d255ab525d10d8fefe5df9ba092b2df8\UIAutomationClient.ni.dll
    + 2010-02-28 12:15 . 2010-02-28 12:15 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\8c0d96269480bdd3de8a825f0215308d\System.Xml.Linq.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\18e1acd6761195389db42bab83169fd2\System.Web.Routing.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\70764208219715962d310336b5959dfa\System.Web.RegularExpressions.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 858112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f288f2cb75465c0f45154079365af9e8\System.Web.Extensions.Design.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\bbdc5cb2f2f92fd610de7331d748193a\System.Web.Entity.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ca1ce755bb49324c7d275c426188a28f\System.Web.Entity.Design.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 542720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\aff5e0fa23e49ee75e458408c1f66da2\System.Web.DynamicData.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\fbe60d84b9f1ab74e396fb1507f69615\System.Web.Abstractions.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\12903c3843fe923d1977801ffa3cf26c\System.Transactions.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\a9e71dda6389403be4db7b567592e3b8\System.ServiceProcess.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\0418eb6dbffe9b46aa4c989153d6a3b5\System.Security.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\01dc643b54310ebc5ab7e4696df426bc\System.Runtime.Serialization.Formatters.Soap.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 620032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\eabe1915c13467e1e66e2b073bcb842f\System.Net.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 997888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\894d87c08a9a5b5923e7104055a616d2\System.Management.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\1db9deebde7c96b2874b4ffccac2f48e\System.Management.Instrumentation.ni.dll
    + 2010-02-28 12:07 . 2010-02-28 12:07 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\bcfccfa22245d2223a764611c61a7cb9\System.IO.Log.ni.dll
    + 2010-02-28 12:07 . 2010-02-28 12:07 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\be8c7482f1e78a3b4984af9082d455a7\System.IdentityModel.Selectors.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5f9cd5bfebcb94175d440ebab3aa412f\System.EnterpriseServices.Wrapper.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\5f9cd5bfebcb94175d440ebab3aa412f\System.EnterpriseServices.ni.dll
    + 2010-02-28 11:27 . 2010-02-28 11:27 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\5f5d64dd0e7991aaaad2d98ee52afe42\System.Drawing.Design.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c205bbbb88bfa4bd5e274f43ea0013cb\System.DirectoryServices.AccountManagement.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\44de75caba2b9711b3d9030a30767f8b\System.DirectoryServices.Protocols.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 939520 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\d3aed340a6562196ca40978556fb29d1\System.Data.Services.Client.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\3cb9c5203e50cb6af99b163522e9357c\System.Data.Services.Design.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 755200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\9867484f25281882e61f61066fa651a3\System.Data.Entity.Design.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\4f4ddae492a4a4ce4a2961f3d72d9399\System.Data.DataSetExtensions.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 970752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb4cb21d14767292e079366a5d3d76cd\System.Configuration.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 140800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\22a1629a4dcdd493bbd8be40cc122e94\System.Configuration.Install.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 632832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\b01721205312c6c18df033cc47b60e5c\System.AddIn.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 365056 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\b9c1a29e684bc02e49226ff1e9eec253\SMSvcHost.ni.exe
    + 2010-02-28 12:09 . 2010-02-28 12:09 255488 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\2e19ccefc30d7b827bab3f7d8dcc0ab9\SMDiagnostics.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\6781b87c8d3b55e6120b1e86bea6e040\ServiceModelReg.ni.exe
    + 2010-02-28 11:22 . 2010-02-28 11:22 224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ef1a93d10c3a91b728745dbfcc79c2c7\PresentationFramework.Classic.ni.dll
    + 2010-02-28 11:22 . 2010-02-28 11:22 539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b4dc4bd8534d90fbb7430926ad990cd9\PresentationFramework.Luna.ni.dll
    + 2010-02-28 11:21 . 2010-02-28 11:21 368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9e71fd0d299c5668c96a54e4a63479fa\PresentationFramework.Aero.ni.dll
    + 2010-02-28 11:22 . 2010-02-28 11:22 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\79c2fd29b1e46c943960278051b4e1b9\PresentationFramework.Royale.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\87c84ffaaad81d8d106a9aa9d68b5926\MSBuild.ni.exe
    + 2010-02-28 12:09 . 2010-02-28 12:09 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\539e297cc9bc67fbf2fbdc9dc5fcd0f1\Microsoft.Transactions.Bridge.Dtc.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\43dceeb2d0601d79af40752fb20283c2\Microsoft.Build.Utilities.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\28eede53267524df58362a75a668cf86\Microsoft.Build.Utilities.v3.5.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 838656 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\daf5ff5e06c80eefa80c6fcc79aec963\Microsoft.Build.Engine.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c5c4db4f9bc7a454e9cfc2548a9d45a5\Microsoft.Build.Conversion.v3.5.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\e148983beeb0f30918b0564849a16456\CustomMarshalers.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 409600 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\19b50dd470540911fc5cc65331a769e4\ComSvcConfig.ni.exe
    + 2010-02-28 12:09 . 2010-02-28 12:09 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c7ffd8c23e8de4018a88185b3b60631e\AspNetMMCExt.ni.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 385024 c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 167936 c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
     
  18. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    + 2010-02-28 11:10 . 2010-02-28 11:10 139264 c:\windows\assembly\GAC_MSIL\System.Xml.Linq\3.5.0.0__b77a5c561934e089\System.Xml.Linq.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 507904 c:\windows\assembly\GAC_MSIL\System.WorkflowServices\3.5.0.0__31bf3856ad364e35\System.WorkflowServices.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 540672 c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
    + 2010-02-28 11:11 . 2010-02-28 11:11 335872 c:\windows\assembly\GAC_MSIL\System.Web.Extensions.Design\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 139264 c:\windows\assembly\GAC_MSIL\System.Web.Entity\3.5.0.0__b77a5c561934e089\System.Web.Entity.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 131072 c:\windows\assembly\GAC_MSIL\System.Web.Entity.Design\3.5.0.0__b77a5c561934e089\System.Web.Entity.Design.dll
    + 2010-02-28 11:11 . 2010-02-28 11:11 225280 c:\windows\assembly\GAC_MSIL\System.Web.DynamicData\3.5.0.0__31bf3856ad364e35\System.Web.DynamicData.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 688128 c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 569344 c:\windows\assembly\GAC_MSIL\System.ServiceModel.Web\3.5.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 966656 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 233472 c:\windows\assembly\GAC_MSIL\System.Net\3.5.0.0__b03f5f7f11d50a3a\System.Net.dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 143360 c:\windows\assembly\GAC_MSIL\System.Management.Instrumentation\3.5.0.0__b77a5c561934e089\System.Management.Instrumentation.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 131072 c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 430080 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 126976 c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 286720 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\3.5.0.0__b77a5c561934e089\System.DirectoryServices.AccountManagement.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 442368 c:\windows\assembly\GAC_MSIL\System.Data.Services\3.5.0.0__b77a5c561934e089\System.Data.Services.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 114688 c:\windows\assembly\GAC_MSIL\System.Data.Services.Design\3.5.0.0__b77a5c561934e089\System.Data.Services.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 294912 c:\windows\assembly\GAC_MSIL\System.Data.Services.Client\3.5.0.0__b77a5c561934e089\System.Data.Services.Client.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 684032 c:\windows\assembly\GAC_MSIL\System.Data.Linq\3.5.0.0__b77a5c561934e089\System.Data.Linq.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 229376 c:\windows\assembly\GAC_MSIL\System.Data.Entity.Design\3.5.0.0__b77a5c561934e089\System.Data.Entity.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 667648 c:\windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 163840 c:\windows\assembly\GAC_MSIL\System.AddIn\3.5.0.0__b77a5c561934e089\System.AddIn.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 528384 c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 864256 c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 163840 c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 397312 c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 139264 c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 196608 c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 598016 c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
    - 2009-03-11 11:35 . 2009-03-11 11:35 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 397312 c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 802816 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.v3.5.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 733184 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 106496 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Conversion.v3.5\3.5.0.0__b03f5f7f11d50a3a\Microsoft.Build.Conversion.v3.5.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    - 2009-03-11 11:34 . 2009-03-11 11:34 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
    + 2010-02-28 13:12 . 2006-09-15 22:30 308224 c:\windows\$NtUninstallWudf01007$\wudfx.dll
    + 2010-02-28 13:12 . 2006-09-15 21:29 163840 c:\windows\$NtUninstallWudf01007$\wudfplatform.dll
    + 2010-02-28 13:12 . 2006-09-15 22:30 142848 c:\windows\$NtUninstallWudf01007$\wudfhost.exe
    + 2010-02-28 13:12 . 2008-03-21 12:57 379184 c:\windows\$NtUninstallWudf01007$\spuninst\updspapi.dll
    + 2010-02-28 13:12 . 2008-03-21 12:57 221488 c:\windows\$NtUninstallWudf01007$\spuninst\spuninst.exe
    + 2010-02-28 11:56 . 2006-09-28 17:56 316416 c:\windows\$NtUninstallWudf01005$\wudfx.dll
    + 2010-02-28 11:56 . 2006-09-28 17:56 165376 c:\windows\$NtUninstallWudf01005$\wudfplatform.dll
    + 2010-02-28 11:56 . 2006-09-28 17:56 146432 c:\windows\$NtUninstallWudf01005$\wudfhost.exe
    + 2010-02-28 11:56 . 2006-09-16 02:02 379184 c:\windows\$NtUninstallWudf01005$\spuninst\updspapi.dll
    + 2010-02-28 11:56 . 2006-09-16 02:02 221488 c:\windows\$NtUninstallWudf01005$\spuninst\spuninst.exe
    + 2010-02-28 11:13 . 2006-09-16 00:05 379184 c:\windows\$NtUninstallWudf01000$\spuninst\updspapi.dll
    + 2010-02-28 11:13 . 2006-09-16 00:05 221488 c:\windows\$NtUninstallWudf01000$\spuninst\spuninst.exe
    + 2010-02-28 11:14 . 2008-11-27 03:45 809984 c:\windows\$NtUninstallWMFDist11$\wmvdmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 897024 c:\windows\$NtUninstallWMFDist11$\wmspdmoe.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 485376 c:\windows\$NtUninstallWMFDist11$\wmspdmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 759296 c:\windows\$NtUninstallWMFDist11$\wmsdmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 151552 c:\windows\$NtUninstallWMFDist11$\wmidx.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 230912 c:\windows\$NtUninstallWMFDist11$\wmasf.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 670720 c:\windows\$NtUninstallWMFDist11$\wmadmoe.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 408064 c:\windows\$NtUninstallWMFDist11$\wmadmod.dll
    + 2010-02-28 11:14 . 2006-05-16 17:11 371424 c:\windows\$NtUninstallWMFDist11$\spuninst\updspapi.dll
    + 2010-02-28 11:14 . 2006-05-16 17:11 213216 c:\windows\$NtUninstallWMFDist11$\spuninst\spuninst.exe
    + 2010-02-28 11:14 . 2008-11-27 03:45 237568 c:\windows\$NtUninstallWMFDist11$\qasf.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 245760 c:\windows\$NtUninstallWMFDist11$\mswmdm.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 356352 c:\windows\$NtUninstallWMFDist11$\msscp.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 201728 c:\windows\$NtUninstallWMFDist11$\mspmsp.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 259072 c:\windows\$NtUninstallWMFDist11$\msnetobj.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 240640 c:\windows\$NtUninstallWMFDist11$\mpg4dmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 384512 c:\windows\$NtUninstallWMFDist11$\mp4sdmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 310272 c:\windows\$NtUninstallWMFDist11$\mp43dmod.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 103936 c:\windows\$NtUninstallWMFDist11$\logagent.exe
    + 2010-02-28 11:14 . 2008-11-27 03:45 695808 c:\windows\$NtUninstallWMFDist11$\drmv2clt.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 159232 c:\windows\$NtUninstallWMFDist11$\cewmdm.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 286720 c:\windows\$NtUninstallWMFDist11$\blackbox.dll
    + 2010-04-17 11:30 . 2008-03-27 15:27 503008 c:\windows\$NtUninstallWdf01009$\wdf01000.sys
    + 2010-04-17 11:30 . 2008-11-07 16:55 382496 c:\windows\$NtUninstallWdf01009$\spuninst\updspapi.dll
    + 2010-04-17 11:30 . 2008-11-07 16:55 231456 c:\windows\$NtUninstallWdf01009$\spuninst\spuninst.exe
    + 2010-03-23 20:25 . 2006-11-02 05:22 492000 c:\windows\$NtUninstallWdf01007$\wdf01000.sys
    + 2010-03-23 20:25 . 2008-03-21 12:57 379184 c:\windows\$NtUninstallWdf01007$\spuninst\updspapi.dll
    + 2010-03-23 20:25 . 2008-03-21 12:57 221488 c:\windows\$NtUninstallWdf01007$\spuninst\spuninst.exe
    + 2009-07-11 18:46 . 2009-07-11 18:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
    + 2009-07-11 18:46 . 2009-07-11 18:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
    + 2010-04-21 22:37 . 2010-04-21 22:37 1233920 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9818.0_x-ww_8ff50c5d\msxml4.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 1676288 c:\windows\system32\xpssvcs.dll
    + 2009-05-11 09:47 . 2009-05-11 09:47 1302600 c:\windows\system32\WUDFUpdate_01007.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 1929952 c:\windows\system32\wuaueng.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 2603008 c:\windows\system32\WpdShext.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 1382912 c:\windows\system32\WMVSDECD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 1574912 c:\windows\system32\WMVENCOD.dll
    + 2006-10-18 20:47 . 2006-10-18 20:47 1543680 c:\windows\system32\WMVDECOD.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 2450944 c:\windows\system32\wmvcore.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 1329152 c:\windows\system32\WMSPDMOE.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 8231936 c:\windows\system32\wmploc.dll
    + 2006-10-18 19:47 . 2006-10-18 19:47 1661440 c:\windows\system32\wmpencen.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 1117696 c:\windows\system32\WMADMOE.dll
    + 2010-05-31 19:16 . 2009-10-06 09:55 1112288 c:\windows\system32\wdfcoinstaller01007.dll
    + 2010-05-23 23:30 . 2009-01-07 15:57 1421736 c:\windows\system32\wdfcoinstaller01005.dll
    - 2008-05-16 14:59 . 2007-08-31 19:13 1421736 c:\windows\system32\wdfcoinstaller01005.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\XPSEP\i386\xpssvcs.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\XPSEP\i386\i386\xpssvcs.dll
    + 2010-02-28 11:08 . 2008-07-06 16:36 2936832 c:\windows\system32\spool\XPSEP\amd64\xpssvcs.dll
    + 2010-02-28 11:08 . 2008-07-06 16:36 2936832 c:\windows\system32\spool\XPSEP\amd64\amd64\xpssvcs.dll
    + 2010-02-28 11:08 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\drivers\w32x86\3\XpsSvcs.dll
    + 2007-08-27 11:37 . 2007-08-27 11:37 1717848 c:\windows\system32\skype4com.dll
    + 2010-01-10 10:43 . 2007-08-31 19:13 1421736 c:\windows\system32\ReinstallBackups\0008\DriverFiles\wdfcoinstaller01005.dll
    + 2010-01-10 10:43 . 2007-08-31 19:13 1421736 c:\windows\system32\ReinstallBackups\0003\DriverFiles\wdfcoinstaller01005.dll
    + 1998-11-25 13:52 . 1998-11-25 13:52 1675264 c:\windows\system32\og70nodbas.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 1519616 c:\windows\system32\nwiz.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 1019904 c:\windows\system32\nvwimg.dll
    - 2009-02-27 14:22 . 2008-05-16 13:01 1019904 c:\windows\system32\nvwimg.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 1662976 c:\windows\system32\nvwdmcpl.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 5402624 c:\windows\system32\nvoglnt.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 1466368 c:\windows\system32\nview.dll
    + 2005-12-10 01:06 . 2005-12-10 01:06 1339392 c:\windows\system32\nvdspsch.exe
    - 2009-02-27 14:22 . 2008-05-16 13:01 1339392 c:\windows\system32\nvdspsch.exe
    + 2005-12-10 01:06 . 2005-12-10 01:06 7311360 c:\windows\system32\nvcpl.dll
    + 2009-02-21 23:47 . 2005-12-10 01:06 3955456 c:\windows\system32\nv4_disp.dll
    + 2003-04-18 14:46 . 2003-04-18 14:46 1233920 c:\windows\system32\msxml4.dll
    + 2006-07-11 18:02 . 2006-07-11 18:02 1053184 c:\windows\system32\mfc71u.dll
    + 2006-07-11 17:43 . 2006-07-11 17:43 1060864 c:\windows\system32\mfc71.dll
    - 2009-04-10 14:30 . 2003-03-19 05:19 1060864 c:\windows\system32\MFC71.DLL
    + 2010-01-27 01:07 . 2010-06-22 22:29 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2009-03-28 10:55 . 2009-03-28 10:55 1571817 c:\windows\system32\libeay32.dll
    + 2009-02-21 23:43 . 2010-06-01 12:50 2254192 c:\windows\system32\FNTCACHE.DAT
    + 2010-03-05 22:07 . 2009-08-14 09:09 1269854 c:\windows\system32\dsa.dll
    + 2010-05-31 19:17 . 2009-05-11 09:47 1302600 c:\windows\system32\DRVSTORE\pccswpddri_1C34ED6F4888FC93BE68C7A31A24834F522D3CBF\WUDFUpdate_01007.dll
    + 2010-05-23 23:30 . 2009-01-07 15:57 1421736 c:\windows\system32\DRVSTORE\nuidfltr_4A2DD497F80BEBAFF2971F4BEDF4026E50D4DE51\wdfcoinstaller01005.dll
    + 2010-04-21 22:32 . 2006-11-02 06:09 1419232 c:\windows\system32\DRVSTORE\fpsxx_usb_17EDE44B22398B6099FF055B5826FE9350A74460\wdfcoinstaller01005.dll
    + 2010-05-31 19:16 . 2009-10-06 09:55 1112288 c:\windows\system32\DRVSTORE\ccdcmb_40BC39A62FCDF7FB9E872CE08AFC5F75B82C3181\wdfcoinstaller01007.dll
    + 2009-02-21 23:47 . 2005-12-10 01:06 3536768 c:\windows\system32\drivers\nv4_mini.sys
    + 2010-03-05 22:07 . 2009-08-14 09:10 1668352 c:\windows\system32\drivers\athuw.sys
    + 2010-02-28 11:08 . 2008-07-06 12:06 1676288 c:\windows\system32\dllcache\xpssvcs.dll
    + 2009-02-21 22:57 . 2009-08-06 17:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 2450944 c:\windows\system32\dllcache\wmvcore.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 1329152 c:\windows\system32\dllcache\WMSPDMOE.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 8231936 c:\windows\system32\dllcache\wmploc.dll
    + 2008-11-27 03:45 . 2006-10-18 20:47 1117696 c:\windows\system32\dllcache\WMADMOE.dll
    + 2009-02-21 22:57 . 2006-11-01 16:31 1669120 c:\windows\system32\dllcache\setup_wm.exe
    + 2009-02-21 23:47 . 2005-12-10 01:06 3536768 c:\windows\system32\dllcache\nv4_mini.sys
    + 2009-02-21 23:47 . 2005-12-10 01:06 3955456 c:\windows\system32\dllcache\nv4_disp.dll
    + 2009-07-11 21:40 . 2008-11-27 03:45 2188928 c:\windows\system32\dllcache\cache\ntoskrnl.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 2065792 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
    + 2009-07-11 21:40 . 2008-11-27 03:45 1033728 c:\windows\system32\dllcache\cache\explorer.exe
    + 2010-06-07 17:01 . 2009-09-04 15:29 1892184 c:\windows\system32\D3DX9_42.dll
    + 2010-06-07 17:01 . 2009-03-09 13:27 4178264 c:\windows\system32\D3DX9_41.dll
    + 2010-06-07 17:01 . 2008-10-10 02:52 4379984 c:\windows\system32\D3DX9_40.dll
    + 2010-06-07 17:01 . 2008-07-10 09:00 3851784 c:\windows\system32\D3DX9_39.dll
    + 2010-06-07 17:01 . 2008-05-30 12:11 3850760 c:\windows\system32\D3DX9_38.dll
    + 2010-06-07 17:01 . 2009-09-04 15:29 5501792 c:\windows\system32\d3dcsx_42.dll
    + 2010-06-07 17:01 . 2009-09-04 15:29 1974616 c:\windows\system32\D3DCompiler_42.dll
    + 2010-06-07 17:01 . 2009-03-09 13:27 1846632 c:\windows\system32\D3DCompiler_41.dll
    + 2010-06-07 17:01 . 2008-10-10 02:52 2036576 c:\windows\system32\D3DCompiler_40.dll
    + 2010-06-07 17:01 . 2008-07-10 09:00 1493528 c:\windows\system32\D3DCompiler_39.dll
    + 2010-06-07 17:01 . 2008-05-30 12:11 1491992 c:\windows\system32\D3DCompiler_38.dll
    + 2010-03-05 22:07 . 2009-08-14 09:10 1668352 c:\windows\system32\athuw.sys
    + 2010-03-05 22:07 . 2009-08-14 09:10 1334784 c:\windows\system32\athur.sys
    + 2009-08-06 17:23 . 2009-08-06 17:23 1929952 c:\windows\SoftwareDistribution\SelfUpdate\wuaueng.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 1720824 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
    + 2008-07-29 17:47 . 2008-07-29 17:47 1054208 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 1364992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\SITSetup.dll
    + 2008-07-29 17:47 . 2008-07-29 17:47 1064448 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\gencomp.dll
    + 2008-07-29 22:40 . 2008-07-29 22:40 1548280 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
    + 2008-07-29 18:59 . 2008-07-29 18:59 1738760 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
    + 2008-07-29 20:10 . 2008-07-29 20:10 2637840 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsLexicons0009.dll
    + 2008-07-29 20:10 . 2008-07-29 20:10 4883464 c:\windows\Microsoft.NET\Framework\v3.0\WPF\NlsData0009.dll
    + 2008-07-29 18:16 . 2008-07-29 18:16 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 1344000 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 1172472 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
    + 2008-07-25 10:17 . 2008-07-25 10:17 2048000 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 5238784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 3149824 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 5062656 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 2933248 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 5815296 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
    + 2008-07-25 10:17 . 2008-07-25 10:17 4546560 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
    + 2008-07-25 10:16 . 2008-07-25 10:16 1163768 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
    + 2008-08-26 06:09 . 2008-08-26 06:09 1043456 c:\windows\Installer\e88cd.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 2679808 c:\windows\Installer\e88cb.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 3697664 c:\windows\Installer\e88c9.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 1448448 c:\windows\Installer\e88c8.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 4137984 c:\windows\Installer\e88c7.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 3376640 c:\windows\Installer\e88c6.msp
    + 2010-06-17 08:25 . 2010-06-17 08:25 3906560 c:\windows\Installer\9a75f3.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 2543616 c:\windows\Installer\91396.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 2926080 c:\windows\Installer\91395.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 6487040 c:\windows\Installer\91394.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 3403264 c:\windows\Installer\91393.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 1013248 c:\windows\Installer\91391.msp
    + 2008-08-26 06:09 . 2008-08-26 06:09 6083072 c:\windows\Installer\9138e.msp
    + 2010-05-10 23:09 . 2010-05-10 23:09 1048064 c:\windows\Installer\886a48.msi
    + 2010-04-04 10:28 . 2010-04-04 10:28 4272128 c:\windows\Installer\84a6eb.msi
    + 2007-08-31 19:14 . 2007-08-31 19:14 4657664 c:\windows\Installer\5feef.msi
    + 2010-05-10 16:34 . 2010-05-10 16:34 1091072 c:\windows\Installer\5ee1560.msi
    + 2010-05-10 16:26 . 2010-05-10 16:26 1017856 c:\windows\Installer\5ee155a.msi
    + 2010-04-02 18:53 . 2010-04-02 18:53 7220736 c:\windows\Installer\1eba6af.msp
    + 2010-04-21 22:45 . 2010-04-21 22:45 7898112 c:\windows\Installer\1e9d04.msi
    + 2010-06-09 23:09 . 2010-06-09 23:09 1511936 c:\windows\Installer\101060b.msi
    + 2010-02-03 19:44 . 2010-02-03 19:44 3395584 c:\windows\Installer\{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}\Sony Ericsson Drivers.msi
    + 2009-12-18 00:16 . 2009-12-18 00:16 1949696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\rt3d.dll
    + 2010-02-28 11:17 . 2010-02-28 11:17 3311104 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\df20e56b59b1b1a595af305ddc0777ba\WindowsBase.ni.dll
    + 2010-02-28 11:31 . 2010-02-28 11:31 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\8698f073a59ef0db10a3258b1f1deaee\UIAutomationClientsideProviders.ni.dll
    + 2010-02-28 11:15 . 2010-02-28 11:15 7867392 c:\windows\assembly\NativeImages_v2.0.50727_32\System\aa7926460a336408c8041330ad90929d\System.ni.dll
    + 2010-02-28 11:30 . 2010-02-28 11:30 5449728 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\36f3953f24d4f0b767bf172331ad6f3e\System.Xml.ni.dll
    + 2010-02-28 12:15 . 2010-02-28 12:15 1355264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\43911ac4e29949c57560eee5cb7b76c2\System.WorkflowServices.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 1904128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6d0966370023925610756f368140b947\System.Workflow.Runtime.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 4510720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\9de33f5786cd15e220f47b916c5a15e9\System.Workflow.ComponentModel.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 2989568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\d6cc33db5d526553ffbbfd1d372a8493\System.Workflow.Activities.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 1840128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1dad08772eb89d48a8a0cfe9b0467eb0\System.Web.Services.ni.dll
    + 2010-02-28 12:14 . 2010-02-28 12:14 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\e5995a34d44ad5af7d9f335075bded4d\System.Web.Mobile.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 2400256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6a20b64ad8e2aaa2f40d67ff01fcc708\System.Web.Extensions.ni.dll
    + 2010-02-28 11:28 . 2010-02-28 11:28 1912832 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2e7a6c977ac9f8d46ebe2982697a0c8d\System.Speech.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\a3adabee8e63dc76f65710a9c32175fc\System.ServiceModel.Web.ni.dll
    + 2010-02-28 12:07 . 2010-02-28 12:07 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\bb748f8ef8c98eb5c7f79b8faee95397\System.Runtime.Serialization.ni.dll
    + 2010-02-28 11:28 . 2010-02-28 11:28 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\db428f231a2ccaf490ae219efd2edc69\System.Printing.ni.dll
    + 2010-02-28 12:07 . 2010-02-28 12:07 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\94b2ca600c860c76e387f8bd317bd4c3\System.IdentityModel.ni.dll
    + 2010-02-28 11:27 . 2010-02-28 11:27 1587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6978f2e90f13bc720d57fa6895c911e2\System.Drawing.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6bcc481030a56c24d5990d199812c594\System.DirectoryServices.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 1800704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\df1efcbac5973454c608890f72eb994d\System.Deployment.ni.dll
    + 2010-02-28 11:23 . 2010-02-28 11:23 6614016 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\0b40341027c01716cec1dd97592698e0\System.Data.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 2508800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0ec1b690c5ee057fa92ecff78de1457c\System.Data.SqlXml.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 1326080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\6f298259c87cc6c7318d931f52f053c5\System.Data.Services.ni.dll
    + 2010-02-28 11:24 . 2010-02-28 11:24 2510848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\fa206c73f39721cd2c55829b9853de44\System.Data.Linq.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 9903104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\8c050147d7031f912f6ca2b15550173f\System.Data.Entity.ni.dll
    + 2010-02-28 11:23 . 2010-02-28 11:23 2294784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\6c69930d05c557da70144bcc0add7065\System.Core.ni.dll
    + 2010-02-28 11:23 . 2010-02-28 11:23 2125824 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\5c59991df60164cae10fd81b88a8e5b1\ReachFramework.ni.dll
    + 2010-02-28 11:23 . 2010-02-28 11:23 1656832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\87fb973e4ab6a21fd00e45656fa7c115\PresentationUI.ni.dll
    + 2010-02-28 11:16 . 2010-02-28 11:16 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b6bfb51dec7f8cc42c21c5928470c773\PresentationBuildTasks.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 1711104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\5b3d048d8c003d743ea5e72caf07773a\Microsoft.VisualBasic.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 1092608 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\21bb6244c91b6207fbcb038884a641ef\Microsoft.Transactions.Bridge.ni.dll
    + 2010-02-28 12:12 . 2010-02-28 12:12 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\7d61e63dea85f4f77ea4c13df7651ec7\Microsoft.JScript.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 1965568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\cd6eeb3d7ea1f65c28a43e665db38644\Microsoft.Build.Tasks.v3.5.ni.dll
    + 2010-02-28 12:10 . 2010-02-28 12:10 1620480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\152cf75db013f0523933ac45177b4217\Microsoft.Build.Tasks.ni.dll
    + 2010-02-28 12:09 . 2010-02-28 12:09 1886208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\ce984d7bbd9a6d5d3cca28c4e5038020\Microsoft.Build.Engine.ni.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 1245184 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 3149824 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 1630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 1138688 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
    + 2010-02-28 11:11 . 2010-02-28 11:11 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
    + 2010-02-28 11:10 . 2010-02-28 11:10 2879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 5238784 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
    + 2010-02-28 11:09 . 2010-02-28 11:09 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
    + 2010-02-28 11:06 . 2010-02-28 11:06 4546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 1001472 c:\windows\$NtUninstallWMFDist11$\wmvdmoe2.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 2109440 c:\windows\$NtUninstallWMFDist11$\wmvcore.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 1119744 c:\windows\$NtUninstallWMFDist11$\wmsdmoe2.dll
    + 2010-02-28 11:14 . 2008-11-27 03:45 1053184 c:\windows\$NtUninstallWMFDist11$\wmnetmgr.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 10834432 c:\windows\system32\wmp.dll
    + 2008-11-27 03:45 . 2006-10-18 19:47 10834432 c:\windows\system32\dllcache\wmp.dll
    + 2008-03-07 11:54 . 2008-03-07 11:54 17907824 c:\windows\system32\BsLangInDepRes.dll
    + 2009-12-18 06:30 . 2009-12-18 06:30 13313464 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A0200000030\8.2.0\AcroRd32.dll
    + 2010-02-28 11:30 . 2010-02-28 11:30 12428800 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\9a254c455892c02355ab0ab0f0727c5b\System.Windows.Forms.ni.dll
    + 2010-02-28 12:13 . 2010-02-28 12:13 11791360 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\50ea744ffc3cb7f09b027fd6c5c93b2b\System.Web.ni.dll
    + 2010-02-28 12:08 . 2010-02-28 12:08 17313792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\d85d9535e91da842fded56869d57790a\System.ServiceModel.ni.dll
    + 2010-02-28 11:27 . 2010-02-28 11:27 10681344 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\204db7071fb26343b0fd3f3d140c0bf8\System.Design.ni.dll
    + 2010-02-28 11:21 . 2010-02-28 11:21 14320128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9519494798a88867406b5755e1dbded6\PresentationFramework.ni.dll
    + 2010-02-28 11:18 . 2010-02-28 11:18 12213248 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\12dcb10b76012416357bdbb010fdaa97\PresentationCore.ni.dll
    + 2010-02-28 11:14 . 2010-02-28 11:14 11485184 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9adb89fa22fd5b4ce433b5aca7fb1b07\mscorlib.ni.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
    "mRouterConfig "= "c:\program files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" [2006-03-02 290816]
    "Google Update "= "c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-06-14 136176]
    "CachemanTray "= "c:\program files\Cacheman\CachemanTray.exe" [2010-06-05 317696]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SW20 "= "c:\windows\system32\sw20.exe" [2006-04-04 208896]
    "SW24 "= "c:\windows\system32\sw24.exe" [2006-04-04 69632]
    "Di dictionary "= "c:\program files\Di recnik\Di.exe" [2007-03-16 518656]
    "C-Media Mixer "= "Mixer.exe" [2003-03-20 1855488]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "TWCU "= "c:\program files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe" [2009-08-14 569427]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "SMSERIAL "= "c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
    "BtTray "= "c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
    "nwiz "= "nwiz.exe" [2005-12-10 1519616]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\CTFMON.EXE" [2008-11-27 15360]

    c:\documents and settings\Woolfer\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
    Shortcut to Pihatonttu.lnk - c:\documents and settings\Woolfer\Desktop\netoverbt\New Folder\Hiisi1.6.3\Pihatonttu\Pihatonttu.cmd [2010-5-22 112]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2009-3-3 338448]
    TSS Instrument API Tray Utility.lnk - c:\program files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe [2007-12-7 77824]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @= "Driver "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "vsmon "=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Nokia\\Tss\\Instrument API\\bin\\root.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "c:\\Program Files\\seba14mods\\µtorrent 1.8.2 (build 14458) Leecher Pack\\utorrent 1.8.2 (14458)_stealth.exe "=
    "c:\\Program Files\\A4Proxy\\A4Proxy.exe "=
    "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe "=
    "c:\\Program Files\\ODEON\\JAF\\JCOP.EXE "=
    "c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe "=
    "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\WINDOWS\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DVBViewerTE\\ts_winlirc.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [4/6/2010 6:32 PM 20744]
    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [9/24/2007 7:11 PM 566560]
    R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2/27/2009 4:40 PM 143467]
    R2 CachemanService;Cacheman Service;c:\program files\Cacheman\CachemanServ.exe [6/5/2010 1:31 AM 205056]
    R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [4/22/2010 12:34 AM 10454]
    R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [3/6/2010 12:07 AM 1668352]
    R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [4/6/2010 6:33 PM 30088]
    R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [4/6/2010 6:32 PM 26248]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [7/2/2008 12:15 AM 418832]
    S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys --> c:\windows\system32\DRIVERS\btcomport.sys [?]
    S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys --> c:\windows\system32\Drivers\btcombus.sys [?]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5/31/2010 9:16 PM 136704]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5/31/2010 9:16 PM 8320]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/26/2009 11:08 PM 717296]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1383384898-1644491937-1003Core.job
    - c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-06-14 09:27]

    2010-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1383384898-1644491937-1003UA.job
    - c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-06-14 09:27]

    2009-04-08 c:\windows\Tasks\shutdown.job
    - c:\documents and settings\Woolfer\Desktop\shutdown.lnk [2008-07-02 19:03]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uInternet Settings,ProxyOverride = 127.0.0.1
    uInternet Settings,ProxyServer = 127.0.0.1:80
    IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Prevedi sa Di recnikom - c:\program files\Di recnik\diie.htm
    IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
    IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
    IE: Translate with Di dictionary -
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} -
    FF - ProfilePath - c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\
    FF - prefs.js: browser.search.selectedEngine - Creative Commons
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.ftp - 127.0.0.1
    FF - prefs.js: network.proxy.ftp_port - 80
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 80
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-Nokia FastStart - c:\program files\Nokia\Nokia Music\NokiaMusic.exe
    AddRemove-EPSON SX110 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_FINSFBE.EXE



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-03 00:51
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-854245398-1383384898-1644491937-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1128)
    c:\windows\system32\athgina.dll

    - - - - - - - > 'explorer.exe'(1380)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\BsMobileSDK.dll
    c:\windows\system32\BsLangInDepRes.dll
    c:\windows\system32\Bs2Res.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\acs.exe
    c:\windows\SYSTEM32\astsrv.exe
    c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Canon\CAL\CALMAIN.exe
    c:\program files\IVT Corporation\BlueSoleil\BsHelpCS.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\Mixer.exe
    c:\program files\Common Files\Nokia\Tss\Instrument API\bin\root.exe
    .
    **************************************************************************
    .
    Completion time: 2010-07-03 00:56:50 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-07-02 22:56
    ComboFix2.txt 2010-01-03 17:17
    ComboFix3.txt 2009-07-11 21:47

    Pre-Run: 14.303.768.576 bytes free
    Post-Run: 14.316.580.864 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    - - End Of File - - 5B9A1E16C8B3C7CB1ECB14B1DFBB3A76
     
  19. 2010/08/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\wmrqdl.dll
    
    DDS::
    uInternet Settings,ProxyServer = 218.29.234.50:3128
    uInternet Settings,ProxyOverride = 127.0.0.1
    
    NetSvc::
    nxfgt
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
     "EnableFirewall "=dword:00000001
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nxfgt]
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  20. 2010/08/12
    TamoNeko

    TamoNeko Inactive Thread Starter

    Joined:
    2010/08/09
    Messages:
    18
    Likes Received:
    0
    ComboFix 10-08-10.05 - Woolfer 13.08.2010 2:23.9.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.767.468 [GMT 2:00]
    Running from: c:\documents and settings\Woolfer\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Woolfer\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    "c:\windows\system32\wmrqdl.dll "
    .

    ((((((((((((((((((((((((( Files Created from 2010-07-13 to 2010-08-13 )))))))))))))))))))))))))))))))
    .

    2010-08-10 11:07 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-10 11:07 . 2010-08-10 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-10 11:07 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-09 15:10 . 2010-08-09 15:10 -------- d-----w- c:\program files\DAEMON Tools Lite
    2010-08-09 11:21 . 2010-08-09 11:21 -------- d-----w- C:\xpsp3
    2010-08-08 12:44 . 1999-12-17 08:13 49664 ----a-w- c:\windows\unvise32.exe
    2010-08-08 12:44 . 2010-08-08 12:44 -------- d-----w- c:\program files\Active Ports
    2010-08-08 10:59 . 2010-08-08 10:59 -------- d-----w- c:\program files\Trend Micro
    2010-08-08 10:37 . 2010-08-08 10:37 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Malwarebytes
    2010-08-08 10:36 . 2010-08-08 10:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-08-02 23:01 . 2010-08-02 23:01 503808 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\msvcp71.dll
    2010-08-02 23:01 . 2010-08-02 23:01 499712 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\jmc.dll
    2010-08-02 23:01 . 2010-08-02 23:01 348160 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3425b7c5-n\msvcr71.dll
    2010-08-02 23:01 . 2010-08-02 23:01 61440 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1cef6c9b-n\decora-sse.dll
    2010-08-02 23:01 . 2010-08-02 23:01 12800 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1cef6c9b-n\decora-d3d.dll
    2010-07-30 16:02 . 2010-07-30 16:02 -------- d-----w- c:\program files\Google
    2010-07-30 13:08 . 2010-07-31 08:32 -------- d-----w- c:\program files\Gish
    2010-07-30 00:36 . 2010-07-30 00:36 7 ----a-w- c:\windows\Winset.drv
    2010-07-30 00:36 . 2010-07-30 00:36 0 ----a-w- c:\windows\winkey.drv
    2010-07-30 00:09 . 2010-07-30 00:13 -------- d-----w- c:\program files\World of Wisdom
    2010-07-29 23:55 . 2010-07-30 00:02 -------- d-----w- c:\program files\Kundli for Windows
    2010-07-20 01:12 . 2010-07-20 01:37 -------- d-----w- c:\documents and settings\Woolfer\Application Data\mIRC
    2010-07-20 01:12 . 2010-07-20 01:31 -------- d-----w- c:\program files\mIRC
    2010-07-15 12:17 . 2009-04-30 22:00 15872 ----a-w- c:\windows\system32\escdev.dll
    2010-07-15 12:17 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
    2010-07-15 12:17 . 2008-11-16 22:00 342016 ----a-w- c:\windows\system32\eswiaud.dll
    2010-07-15 10:50 . 2007-12-17 02:00 143872 ----a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
    2010-07-15 10:50 . 2007-01-11 02:02 113664 ----a-w- c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-08-12 20:49 . 2010-07-05 13:19 -------- d-----w- c:\program files\ProxyFirewall
    2010-08-09 15:30 . 2008-05-16 13:51 21504 ----a-w- c:\windows\system32\hidserv.dll
    2010-08-09 15:09 . 2009-03-20 03:23 -------- d-----w- c:\program files\Di recnik
    2010-08-09 15:06 . 2009-02-26 21:08 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
    2010-08-08 17:01 . 2009-03-10 10:43 -------- d-----w- c:\program files\Kaspersky Lab
    2010-08-08 17:01 . 2009-03-10 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2010-08-08 03:07 . 2010-06-29 01:06 -------- d-----w- c:\program files\Cacheman
    2010-08-07 10:44 . 2010-05-22 18:21 146 ----a-w- c:\windows\DelMR.bat
    2010-08-05 16:00 . 2009-02-22 10:24 45864 ----a-w- c:\documents and settings\Woolfer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-30 00:14 . 2009-03-03 21:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-07-22 01:16 . 2009-04-10 02:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-07-13 13:39 . 2009-03-18 13:16 -------- d-----w- c:\program files\Planplus
    2010-07-13 12:00 . 2010-07-13 12:00 -------- d-----w- c:\documents and settings\Woolfer\Application Data\Stardock
    2010-07-13 11:19 . 2010-07-13 11:19 -------- d-----w- c:\program files\RocketDock
    2010-07-13 01:42 . 2010-07-12 15:58 -------- d-----w- c:\program files\AveIconifier2
    2010-07-12 23:01 . 2010-01-08 16:30 1324 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-07-06 21:49 . 2010-07-06 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\PassMark
    2010-07-06 21:49 . 2010-07-06 21:49 -------- d-----w- c:\program files\WirelessMon
    2010-07-06 01:35 . 2010-07-04 23:36 -------- d-----w- c:\documents and settings\All Users\Application Data\EPS
    2010-07-04 23:42 . 2010-07-04 23:33 -------- d-----w- c:\program files\My-Proxy
    2010-07-04 23:42 . 2010-07-04 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\SPC
    2010-07-03 13:52 . 2010-07-03 13:51 -------- d-----w- c:\program files\Bukvar
    2010-07-03 00:36 . 2010-07-03 00:36 -------- d-----w- c:\documents and settings\Woolfer\Application Data\VitySoft
    2010-07-02 18:30 . 2010-06-29 16:59 -------- d-----w- c:\program files\Common Files\Real
    2010-07-02 13:51 . 2010-07-02 13:41 -------- d-----w- c:\program files\A4Proxy
    2010-06-29 17:00 . 2006-07-11 17:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2010-06-29 16:45 . 2010-06-29 16:45 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-06-29 02:50 . 2010-06-29 02:50 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\uninst_s2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 40960 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\serial2k.exe_AA64977EBEC84BDD81E8775F9F2FA2FF.exe
    2010-06-26 19:36 . 2009-03-18 15:09 10134 ----a-r- c:\documents and settings\Woolfer\Application Data\Microsoft\Installer\{AA64977E-BEC8-4BDD-81E8-775F9F2FA2FF}\ARPPRODUCTICON.exe
    2010-06-26 00:00 . 2009-04-09 14:03 -------- d-----w- c:\documents and settings\Woolfer\Application Data\uTorrent
    2010-06-25 23:12 . 2010-06-25 23:12 -------- d-----w- c:\program files\Support Tools
    2010-06-19 14:04 . 2010-06-19 14:01 -------- d-----w- c:\program files\Gravity
    2010-06-19 10:14 . 2010-06-19 10:13 -------- d-----w- c:\program files\Bloboats
    2010-06-18 15:19 . 2010-06-18 15:18 -------- d-----w- c:\program files\K-Lite Codec Pack
    2010-06-14 12:21 . 2010-06-14 12:21 -------- d-----w- c:\program files\VisiPics
    2010-06-07 17:18 . 2010-06-07 17:18 1892 ----a-w- c:\documents and settings\All Users\Application Data\xml4D.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 13757 ----a-w- c:\documents and settings\All Users\Application Data\xml4C.tmp
    2010-06-07 17:18 . 2010-06-07 17:18 9521 ----a-w- c:\documents and settings\All Users\Application Data\xml4B.tmp
    2010-05-31 19:13 . 2010-05-31 19:13 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
    2010-05-31 19:13 . 2010-05-31 19:13 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
    2010-05-31 19:13 . 2010-05-31 19:13 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
    2010-05-31 19:10 . 2010-05-31 19:13 34399664 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_eng.exe
    2010-05-24 23:01 . 2010-05-24 23:01 503808 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcp71.dll
    2010-05-24 23:01 . 2010-05-24 23:01 499712 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\jmc.dll
    2010-05-24 23:01 . 2010-05-24 23:01 12800 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-d3d.dll
    2010-05-24 23:01 . 2010-05-24 23:01 61440 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4ba5100c-n\decora-sse.dll
    2010-05-24 23:01 . 2010-05-24 23:01 348160 ----a-w- c:\documents and settings\Woolfer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e2a3905-n\msvcr71.dll
    .

    ------- Sigcheck -------

    [-] 2009-02-21 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
    .
    ((((((((((((((((((((((((((((( SnapShot_2010-08-11_09.45.49 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-08-12 20:45 . 2010-08-12 20:45 16384 c:\windows\temp\Perflib_Perfdata_80c.dat
    + 2010-08-12 20:45 . 2010-08-12 20:45 16384 c:\windows\temp\Perflib_Perfdata_408.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ProxyFirewall "= "c:\program files\ProxyFirewall\ProxyFirewall.exe" [2006-03-26 431104]
    "DAEMON Tools Lite "= "c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "C-Media Mixer "= "Mixer.exe" [2003-03-20 1855488]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "TWCU "= "c:\program files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe" [2009-08-14 569427]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
    "nwiz "= "nwiz.exe" [2005-12-10 1519616]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
    "SW24 "= "c:\windows\system32\sw24.exe" [2006-04-04 69632]
    "SW20 "= "c:\windows\system32\sw20.exe" [2006-04-04 208896]
    "SMSERIAL "= "c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-29 638976]
    "Di dictionary "= "c:\program files\Di recnik\Di.exe" [2007-03-16 518656]
    "BtTray "= "c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
    "BluetoothAuthenticationAgent "= "bthprops.cpl" [2008-04-14 110592]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\CTFMON.EXE" [2008-11-27 15360]

    c:\documents and settings\Woolfer\Start Menu\Programs\Startup\
    Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
    Shortcut to Pihatonttu.lnk - c:\documents and settings\Woolfer\Desktop\Folders\netoverbt\New Folder\Hiisi1.6.3\Pihatonttu\Pihatonttu.cmd [2010-5-22 112]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    TSS Instrument API Tray Utility.lnk - c:\program files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe [2007-12-7 77824]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @= "Driver "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "vsmon "=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Nokia\\Tss\\Instrument API\\bin\\root.exe "=
    "c:\\Program Files\\uTorrent\\uTorrent.exe "=
    "c:\\Program Files\\seba14mods\\µtorrent 1.8.2 (build 14458) Leecher Pack\\utorrent 1.8.2 (14458)_stealth.exe "=
    "c:\\Program Files\\A4Proxy\\A4Proxy.exe "=
    "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe "=
    "c:\\Program Files\\ODEON\\JAF\\JCOP.EXE "=
    "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\WINDOWS\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DVBViewerTE\\ts_winlirc.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5232:TCP "= 5232:TCP:zgveo

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest "= 1 (0x1)

    R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [4/6/2010 6:32 PM 20744]
    R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 Licensing Service;c:\program files\ABBYY FineReader 9.0\NetworkLicenseServer.exe [9/24/2007 7:11 PM 566560]
    R2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2/27/2009 4:40 PM 143467]
    R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [4/22/2010 12:34 AM 10454]
    R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [4/6/2010 6:33 PM 30088]
    R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [4/6/2010 6:32 PM 26248]
    R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\drivers\SkyNET.sys [7/2/2008 12:15 AM 418832]
    S2 CachemanService;Cacheman Service;c:\program files\Cacheman\CachemanServ.exe --> c:\program files\Cacheman\CachemanServ.exe [?]
    S2 nxfgt;Image System;c:\windows\system32\svchost.exe -k netsvcs [11/27/2008 5:45 AM 14336]
    S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [3/6/2010 12:07 AM 1668352]
    S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys --> c:\windows\system32\DRIVERS\btcomport.sys [?]
    S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys --> c:\windows\system32\Drivers\btcombus.sys [?]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5/31/2010 9:16 PM 136704]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5/31/2010 9:16 PM 8320]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/26/2009 11:08 PM 717296]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - mchInjDrv
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-08 c:\windows\Tasks\shutdown.job
    - c:\documents and settings\Woolfer\Desktop\shutdown.lnk [2008-07-02 19:03]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    IE: + Offline &Explorer: Download the link - file://c:\program files\Offline Explorer\Add_UrlO.htm
    IE: + Offline E&xplorer: Download the current page - file://c:\program files\Offline Explorer\Add_AllO.htm
    IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Prevedi sa Di recnikom - c:\program files\Di recnik\diie.htm
    IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
    IE: Send via &Message... - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
    IE: Translate with Di dictionary -
    Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} -
    FF - ProfilePath - c:\documents and settings\Woolfer\Application Data\Mozilla\Firefox\Profiles\wgw1e5f5.default\
    FF - prefs.js: browser.search.selectedEngine - eBay
    FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:eek:fficial
    FF - prefs.js: network.proxy.http - 218.29.234.50
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: c:\documents and settings\Woolfer\Local Settings\Application Data\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-08-13 02:33
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    ProxyFirewall = c:\program files\ProxyFirewall\ProxyFirewall.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nxfgt]
    "ServiceDll "= "c:\windows\system32\wmrqdl.dll "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-854245398-1383384898-1644491937-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1120)
    c:\windows\system32\athgina.dll

    - - - - - - - > 'explorer.exe'(3312)
    c:\windows\system32\BsMobileSDK.dll
    c:\windows\system32\BsLangInDepRes.dll
    c:\windows\system32\Bs2Res.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\BsHelpCSps.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\windows\system32\BlueSoleilCSps.dll
    c:\windows\system32\BsMobileCSps.dll
    .
    Completion time: 2010-08-13 02:37:36
    ComboFix-quarantined-files.txt 2010-08-13 00:37
    ComboFix2.txt 2010-08-11 09:50
    ComboFix3.txt 2010-08-07 20:13
    ComboFix4.txt 2010-08-06 23:54
    ComboFix5.txt 2010-08-13 00:22

    Pre-Run: 13.376.065.536 bytes free
    Post-Run: 13.357.858.816 bytes free

    - - End Of File - - 2084AEFA2D5F952D641F2A095C87D797
     
  21. 2010/08/12
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\wmrqdl.dll
    
    Driver::
    nxfgt
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\nxfgt]
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.