Dienst "Automatische Updates" deaktiviert |
||
---|---|---|
#0
| ||
19.05.2008, 18:36
Member
Beiträge: 31 |
||
|
||
19.05.2008, 19:30
Ehrenmitglied
Beiträge: 29434 |
#2
Hallo,
wende cleaner an , lösche die temp-Dateien http://www.ccleaner.de/?protecus.de lade combofix, klicke die Warnmeldung weg + poste den report http://virus-protect.org/artikel/tools/combofix.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
19.05.2008, 20:12
Member
Themenstarter Beiträge: 31 |
#3
Hier das LOG von combofix
ComboFix 08-05-15.3 - Robert 2008-05-19 19:52:00.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.474 [GMT 2:00] ausgeführt von:: C:\Download\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt * Resident AV is active [color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color] . (((((((((((((((((((((((((((((((((((( Weitere L”schungen )))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\edvtkmst.ini C:\WINDOWS\system32\IkmprBeg.ini C:\WINDOWS\system32\IkmprBeg.ini2 . ((((((((((((((((((((((( Dateien erstellt von 2008-04-19 bis 2008-05-19 )))))))))))))))))))))))))))))) . 2008-05-19 19:40 . 2008-05-19 19:40 <DIR> d-------- C:\Programme\CCleaner 2008-05-19 17:35 . 2008-05-19 17:35 <DIR> d-------- C:\Programme\Trend Micro 2008-05-19 15:56 . 2008-05-19 15:56 114,688 --a------ C:\WINDOWS\system32\tsmktvde.dll 2008-05-19 14:37 . 2008-05-19 14:37 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-05-19 14:37 . 2008-05-19 14:37 1,409 --a------ C:\WINDOWS\QTFont.for 2008-05-19 12:57 . 2008-05-19 12:57 371,712 --a------ C:\WINDOWS\system32\geBrpmkI.dll 2008-05-19 09:15 . 2008-05-19 09:15 58,368 --a------ C:\WINDOWS\system32\wvUoLeFu.dll 2008-05-19 00:54 . 2008-05-19 00:54 58,368 --a------ C:\WINDOWS\system32\mljjKDVL.dll 2008-05-19 00:53 . 2008-05-19 00:53 58,368 --a------ C:\WINDOWS\system32\ssQgeccA.dll . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-19 18:02 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon 2008-05-19 17:45 --------- d-----w C:\Programme\GetRight 2008-05-19 17:00 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP 2008-05-19 16:09 --------- d-----w C:\Programme\Microsoft Works 2008-05-19 15:53 --------- d-----w C:\Programme\Bytescout Movies Extractor Scout 2008-05-19 12:50 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\AdobeUM 2008-05-19 11:37 --------- d-----w C:\Programme\Gemeinsame Dateien\Adobe 2008-05-18 23:01 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help 2008-04-10 19:50 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE 2008-04-10 19:50 253,952 ------w C:\WINDOWS\Setup1.exe 2008-04-09 10:58 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Skype 2008-04-03 18:19 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Good Keywords v2 2008-04-03 14:14 --------- d-----w C:\Programme\Softnik Technologies 2008-04-02 15:05 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\MegauploadToolbar 2008-04-02 15:02 --------- d-----w C:\Programme\MegauploadToolbar 2008-04-02 15:02 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Megaupload 2008-04-02 15:01 --------- d--h--w C:\Programme\InstallShield Installation Information 2008-04-02 15:01 --------- d-----w C:\Programme\Megaupload 2008-04-02 08:41 --------- d-----w C:\Programme\ITSolution 2008-03-29 17:52 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\BitTorrent 2008-03-20 15:25 --------- d-----w C:\Programme\ImTOO 2008-03-20 11:01 --------- d-----w C:\Programme\Motorola Phone Tools 2008-03-09 21:53 1,880 ----a-w C:\WINDOWS\AUTOLNCH.REG 2008-01-13 20:38 49,958 ----a-w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\wklnhst.dat 2007-04-12 20:05 25,600 ----a-w C:\Dokumente und Einstellungen\Robert\usbsermptxp.sys 2007-04-12 20:05 22,768 ----a-w C:\Dokumente und Einstellungen\Robert\usbsermpt.sys 2007-01-08 09:44 774,144 ----a-w C:\Programme\RngInterstitial.dll 2006-04-25 19:39 46 ----a-w C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\wklnhst.dat 2007-04-09 20:09 278,528 ----a-w C:\Programme\internet explorer\plugins\PanoViewer.dll 2007-04-09 20:09 98,304 ----a-w C:\Programme\internet explorer\plugins\UPjpeg.dll 2007-07-01 20:42 23 --sha-w C:\WINDOWS\system32\daed_r.dll . ((((((((((((((((((((((((((((( snapshot@2007-11-15_15.47.55.84 ))))))))))))))))))))))))))))))))))))))))) . + 2007-07-06 09:52:38 72,960 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqac.sys + 2007-07-06 13:08:15 138,240 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqad.dll + 2007-07-06 13:08:15 47,104 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqdscli.dll + 2007-07-06 13:08:15 16,896 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqise.dll + 2007-07-06 13:08:15 660,992 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqqm.dll + 2007-07-06 13:08:15 177,152 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqrt.dll + 2007-07-06 13:08:15 95,744 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqsec.dll + 2007-07-06 13:08:15 48,640 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqupgrd.dll + 2007-07-06 13:08:15 533,504 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqutil.dll + 2005-10-12 23:11:08 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\spmsg.dll + 2005-10-12 23:11:08 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\spuninst.exe + 2005-10-12 23:11:04 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\update\spcustom.dll + 2005-10-12 23:11:11 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\update\update.exe + 2005-10-12 23:11:17 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB937894\update\updspapi.dll + 2007-10-29 22:35:36 1,293,312 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\SP2QFE\quartz.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB941568\update\updspapi.dll + 2007-10-30 16:53:32 360,832 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll + 2008-03-20 07:56:37 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys + 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll + 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe + 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll + 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe + 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll + 2007-10-10 23:20:34 124,928 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\advpack.dll + 2007-10-10 23:20:34 214,528 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\dxtrans.dll + 2007-10-10 23:20:34 132,608 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\extmgr.dll + 2007-10-10 23:20:34 63,488 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\icardie.dll + 2007-10-10 08:16:47 70,656 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ie4uinit.exe + 2007-10-10 23:20:34 153,088 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakeng.dll + 2007-10-10 23:20:34 230,400 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieaksie.dll + 2007-10-10 05:47:20 161,792 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieakui.dll + 2007-04-17 09:32:38 2,455,488 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dat + 2007-10-10 23:20:34 383,488 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieapfltr.dll + 2007-10-10 23:20:35 388,096 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iedkcs32.dll + 2007-10-10 23:20:37 6,067,200 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieframe.dll + 2007-10-10 23:20:37 44,544 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iernonce.dll + 2007-10-10 23:20:37 267,776 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iertutil.dll + 2007-10-10 08:16:47 13,824 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\ieudinit.exe + 2007-10-10 08:16:56 625,664 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe + 2007-10-10 23:20:37 27,648 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\jsproxy.dll + 2007-10-10 23:20:37 459,264 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeeds.dll + 2007-10-10 23:20:37 52,224 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msfeedsbs.dll + 2007-10-30 23:39:03 3,593,216 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll + 2007-10-10 23:20:40 478,208 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtmled.dll + 2007-10-10 23:20:40 193,024 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\msrating.dll + 2007-10-10 23:20:41 671,232 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mstime.dll + 2007-10-10 23:20:41 102,912 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\occache.dll + 2007-10-10 23:20:41 105,984 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\url.dll + 2007-10-10 23:20:41 1,162,240 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\urlmon.dll + 2007-10-10 23:20:42 233,472 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\webcheck.dll + 2007-10-10 23:20:42 825,344 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB942615-IE7\update\updspapi.dll + 2007-11-13 11:02:46 60,416 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll + 2008-01-10 18:37:11 375,296 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\SP2QFE\asp51.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB942830\update\updspapi.dll + 2008-01-10 05:09:53 257,024 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\SP2QFE\infocomm.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB942831\update\updspapi.dll + 2007-12-04 18:29:30 551,936 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\SP2QFE\oleaut32.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB943055\update\updspapi.dll + 2007-11-07 09:49:17 734,720 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll + 2007-12-07 01:41:41 124,928 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\advpack.dll + 2007-12-19 22:18:03 347,136 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtmsft.dll + 2007-12-07 01:41:42 214,528 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\dxtrans.dll + 2007-12-07 01:41:42 133,120 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\extmgr.dll + 2007-12-07 01:41:42 63,488 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\icardie.dll + 2007-12-06 08:34:28 70,656 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ie4uinit.exe + 2007-12-07 01:41:42 153,088 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakeng.dll + 2007-12-07 01:41:42 230,400 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieaksie.dll + 2007-12-06 05:00:02 161,792 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieakui.dll + 2007-04-17 09:32:38 2,455,488 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dat + 2007-12-07 01:41:42 383,488 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieapfltr.dll + 2007-12-07 01:41:42 388,096 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iedkcs32.dll + 2007-12-07 01:41:44 6,067,200 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieframe.dll + 2007-12-07 01:41:44 44,544 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iernonce.dll + 2007-12-07 01:41:44 267,776 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iertutil.dll + 2007-12-06 08:34:29 13,824 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\ieudinit.exe + 2007-12-06 08:34:45 625,664 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe + 2007-12-07 01:41:44 27,648 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\jsproxy.dll + 2007-12-07 01:41:44 459,264 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeeds.dll + 2007-12-07 01:41:44 52,224 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msfeedsbs.dll + 2007-12-07 01:41:46 3,593,216 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll + 2007-12-07 01:41:47 478,208 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtmled.dll + 2007-12-07 01:41:47 193,024 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\msrating.dll + 2007-12-07 01:41:47 671,232 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mstime.dll + 2007-12-07 01:41:47 102,912 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\occache.dll + 2008-01-11 05:49:55 44,544 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\pngfilt.dll + 2007-12-07 01:41:48 105,984 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\url.dll + 2007-12-07 01:41:48 1,162,752 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\urlmon.dll + 2007-12-07 01:41:48 233,472 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\webcheck.dll + 2007-12-07 01:41:49 825,344 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB944533-IE7\update\updspapi.dll + 2007-11-13 08:47:44 20,480 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\SP2QFE\secdrv.sys + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB944653\update\updspapi.dll + 2008-02-20 05:20:09 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll + 2008-02-20 18:50:10 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll + 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll + 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe + 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll + 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe + 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll + 2007-12-18 09:38:59 179,712 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys + 2007-03-06 01:14:12 15,584 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\spmsg.dll + 2007-03-06 01:14:17 217,312 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\spuninst.exe + 2007-03-06 01:14:11 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\update\spcustom.dll + 2007-03-06 01:14:35 725,728 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\update\update.exe + 2007-03-06 01:15:25 377,568 -c--a-w C:\WINDOWS\$hf_mig$\KB946026\update\updspapi.dll + 2008-03-01 12:33:31 124,928 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\advpack.dll + 2008-03-01 12:33:31 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtmsft.dll + 2008-03-01 12:33:31 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\dxtrans.dll + 2008-03-01 12:33:31 132,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\extmgr.dll + 2008-03-01 12:33:31 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\icardie.dll + 2008-02-22 09:39:56 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ie4uinit.exe + 2008-03-01 12:33:32 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakeng.dll + 2008-03-01 12:33:32 230,400 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieaksie.dll + 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieakui.dll + 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dat + 2008-03-01 12:33:32 383,488 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieapfltr.dll + 2008-03-01 12:33:32 388,608 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iedkcs32.dll + 2008-03-01 12:33:34 6,067,712 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieframe.dll + 2008-03-01 12:33:34 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iernonce.dll + 2008-03-01 12:33:35 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iertutil.dll + 2008-02-22 09:39:56 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\ieudinit.exe + 2008-02-22 09:40:22 625,664 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe + 2008-03-01 12:33:35 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\jsproxy.dll + 2008-03-01 12:33:36 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeeds.dll + 2008-03-01 12:33:36 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msfeedsbs.dll + 2008-03-01 12:33:37 3,593,216 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll + 2008-03-01 12:33:37 478,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtmled.dll + 2008-03-01 12:33:38 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\msrating.dll + 2008-03-01 12:33:38 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mstime.dll + 2008-03-01 12:33:38 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\occache.dll + 2008-03-01 12:33:38 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\pngfilt.dll + 2008-03-01 12:33:38 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\url.dll + 2008-03-01 12:33:41 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\urlmon.dll + 2008-03-01 12:33:41 233,472 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\webcheck.dll + 2008-03-01 12:33:41 827,392 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll + 2007-03-06 01:14:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spmsg.dll + 2007-03-06 01:14:13 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\spuninst.exe + 2007-03-06 01:14:07 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\spcustom.dll + 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe + 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB947864-IE7\update\updspapi.dll + 2008-02-20 06:52:36 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll + 2007-03-06 01:14:12 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll + 2007-03-06 01:14:17 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe + 2007-03-06 01:14:11 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll + 2007-03-06 01:14:35 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe + 2007-03-06 01:15:25 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll + 2007-03-06 01:14:08 15,584 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spmsg.dll + 2007-03-06 01:14:13 217,312 ----a-w C:\WINDOWS\$hf_mig$\KB948881\spuninst.exe + 2007-03-06 01:14:07 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\spcustom.dll + 2007-03-06 01:14:30 725,728 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\update.exe + 2007-03-06 01:15:22 377,568 ----a-w C:\WINDOWS\$hf_mig$\KB948881\update\updspapi.dll + 2006-11-02 06:22:52 51,680 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\Kmdfcustom.dll + 2006-10-08 20:51:14 221,488 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe + 2006-10-08 20:51:14 379,184 -c----w C:\WINDOWS\$NtUninstallWdf01005$\spuninst\updspapi.dll - 2007-02-10 09:20:20 248,632 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll + 2007-12-14 17:02:20 251,272 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll - 2007-02-10 09:20:21 781,104 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll + 2007-12-14 17:01:19 783,744 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll - 2007-07-11 08:18:37 68,608 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2008-05-18 23:04:47 69,120 ----a-w C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll - 2007-07-11 08:18:56 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll + 2008-05-18 23:04:55 72,192 ----a-w C:\WINDOWS\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll - 2007-02-10 09:20:57 118,112 ----a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll + 2007-12-14 17:01:50 120,408 ----a-w C:\WINDOWS\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll - 2007-07-11 08:18:58 4,308,992 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2008-05-18 23:04:25 4,444,160 ----a-w C:\WINDOWS\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll - 2007-07-11 08:19:01 482,304 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2008-05-18 23:04:58 483,840 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll - 2007-07-11 08:18:53 2,902,016 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2008-05-18 23:04:36 3,036,160 ----a-w C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll - 2007-07-11 08:18:26 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll + 2008-05-18 23:05:03 258,048 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll - 2007-07-11 08:18:26 114,176 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2008-05-18 23:05:03 113,664 ----a-w C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll - 2007-07-11 08:19:05 260,096 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2008-05-18 23:04:56 261,120 ----a-w C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll - 2007-07-11 08:18:44 5,156,864 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll + 2008-05-18 23:04:33 5,431,296 ----a-w C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll - 2007-07-11 08:18:36 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2008-05-18 23:04:43 10,752 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll - 2007-07-11 08:18:26 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2008-05-18 23:04:34 507,904 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll - 2007-07-11 08:18:30 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2008-05-18 23:04:46 13,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll - 2007-07-11 08:18:55 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll + 2008-05-18 23:04:50 8,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll - 2007-07-11 08:18:56 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll + 2008-05-18 23:04:52 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll - 2007-07-11 08:18:56 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2008-05-18 23:04:52 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll - 2007-07-11 08:18:32 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2008-05-18 23:05:04 348,160 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll - 2007-07-11 08:18:33 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2008-05-18 23:05:05 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll - 2007-07-11 08:18:34 647,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll + 2008-05-18 23:05:06 655,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll - 2007-07-11 08:18:35 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2008-05-18 23:05:07 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll - 2007-07-11 08:18:31 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2008-05-18 23:04:53 749,568 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll - 2007-02-10 09:20:57 609,104 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll + 2007-12-14 17:01:48 611,392 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Office.InfoPath.Client.Internal.Host\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.dll - 2007-07-11 08:19:13 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2008-05-18 23:04:51 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll - 2007-07-11 08:19:12 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2008-05-18 23:04:50 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll - 2007-07-11 08:18:21 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2008-05-18 23:04:59 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll - 2007-07-11 08:19:08 667,648 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2008-05-18 23:04:49 671,744 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll - 2007-07-11 08:19:14 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll + 2008-05-18 23:04:29 5,632 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll - 2007-07-11 08:18:25 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2008-05-18 23:05:01 12,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll - 2007-07-11 08:18:22 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2008-05-18 23:04:48 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll - 2007-07-11 08:18:25 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2008-05-18 23:04:48 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll - 2007-07-11 08:19:03 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2008-05-18 23:04:54 110,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll - 2007-07-11 08:18:38 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2008-05-18 23:04:54 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll - 2007-07-11 08:19:03 413,696 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2008-05-18 23:04:35 425,984 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll - 2007-07-11 08:19:01 716,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2008-05-18 23:04:37 741,376 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll - 2007-07-11 08:18:27 888,832 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2008-05-18 23:04:38 933,888 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll - 2007-07-11 08:18:55 5,001,216 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2008-05-18 23:05:08 5,070,848 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll - 2007-07-11 08:18:40 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2008-05-18 23:05:05 188,416 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll - 2007-07-11 08:18:38 397,312 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2008-05-18 23:04:44 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll - 2007-07-11 08:18:41 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2008-05-18 23:05:00 81,920 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll - 2007-07-11 08:19:04 577,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll + 2008-05-18 23:04:30 630,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll - 2007-07-11 08:19:02 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2008-05-18 23:05:02 372,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll - 2007-07-11 08:19:04 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2008-05-18 23:05:00 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll - 2007-07-11 08:19:02 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll + 2008-05-18 23:04:57 299,008 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - 2007-07-11 08:19:02 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll + 2008-05-18 23:04:56 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll - 2007-07-11 08:18:36 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2008-05-18 23:04:30 258,048 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll - 2007-07-11 08:18:42 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2008-05-18 23:04:31 114,688 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll - 2007-07-11 08:19:06 835,584 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll + 2008-05-18 23:04:42 884,736 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll - 2007-07-11 08:18:46 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2008-05-18 23:04:43 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll - 2007-07-11 08:18:46 823,296 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2008-05-18 23:04:41 839,680 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll - 2007-07-11 08:18:47 5,152,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2008-05-18 23:04:45 5,013,504 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll - 2007-07-11 08:18:49 2,027,520 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2008-05-18 23:04:32 2,068,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll - 2007-07-11 08:19:03 2,940,928 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2008-05-18 23:04:39 3,076,096 ----a-w C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2008-05-19 07:36:18 27,136 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\c6772fd12a581ad3be49e3f2a80b5622\Accessibility.ni.dll + 2008-05-19 07:37:08 884,736 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\a1d353edc300e3aff0784202f68a657b\AspNetMMCExt.ni.dll + 2008-05-19 07:37:49 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c10ec9b4de2b366236ec83237dc31281\CustomMarshalers.ni.dll + 2008-05-19 07:37:29 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\837fe02bdcf637d5bf1e5ffb935ebb80\dfsvc.ni.exe + 2008-05-19 07:38:07 876,544 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\9710a3c0d11dd264c3a6b88977699e9b\Microsoft.Build.Engine.ni.dll + 2008-05-19 07:38:19 81,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\e2858a45971fb30b0c0523dbb52c1d4e\Microsoft.Build.Framework.ni.dll + 2008-05-19 07:38:51 1,695,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\63d69ffdf3c640d2d104a4b74e8115f8\Microsoft.Build.Tasks.ni.dll + 2008-05-19 07:39:01 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\11cb5418c06e30100616fbf205588489\Microsoft.Build.Utilities.ni.dll + 2008-05-19 07:46:03 249,856 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\c851efbcdb133ac214b09ae51ff54b55\Microsoft.NetEnterpriseServers.ExceptionMessageBox.ni.dll + 2008-05-19 07:46:42 94,208 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.NetEnterp#\df614699b80fb6de5378b8fa864a0564\microsoft.netenterpriseservers.exceptionmessagebox.resources.ni.dll + 2008-05-19 07:48:45 561,152 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\057d6ab1c1f71152ad954bb83ad6b59a\Microsoft.SqlServer.GridControl.ni.dll + 2008-05-19 07:48:02 90,112 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\13256fee4d650a2b1533c00ce04871a0\Microsoft.SqlServer.CustomControls.ni.dll + 2008-05-19 07:52:38 1,028,096 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\87fc9687f3a26c1f9650b2d0fcac3d0e\Microsoft.SqlServer.WizardFrameworkLite.ni.dll + 2008-05-19 07:50:42 376,832 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\8a623038cabd22378ae860620f61bc8f\Microsoft.SqlServer.Setup.ni.dll + 2008-05-19 07:49:23 20,992 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\afe805396c4dc967cd1f1b13e826d133\microsoft.sqlserver.gridcontrol.resources.ni.dll + 2008-05-19 07:51:19 77,824 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\f18eb2de8518f2bac489b5d9e7bce375\microsoft.sqlserver.setup.resources.ni.dll + 2008-05-19 07:53:16 360,448 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\fa68f408b4be39122ac1f2c1ed244e26\microsoft.sqlserver.wizardframeworklite.resources.ni.dll + 2008-05-19 07:53:45 1,740,800 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll + 2008-05-18 23:06:41 11,722,752 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll + 2008-05-19 07:54:00 1,011,712 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll + 2008-05-19 07:10:20 7,049,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll + 2008-05-19 07:54:14 1,798,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\c7dea4895e1fa33d65e448c03de48d26\System.Deployment.ni.dll + 2008-05-19 07:10:48 10,969,088 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\c1e16b40e30a05c39be8aee46311841c\System.Design.ni.dll + 2008-05-19 07:54:28 1,224,704 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\914668b240550f529e54bb772c6fc881\System.DirectoryServices.ni.dll + 2008-05-19 08:00:35 512,000 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f11bc82c09955cb8438d3885a99c297d\System.DirectoryServices.Protocols.ni.dll + 2008-05-19 07:10:53 229,376 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\b974f6c17d17a533adf6e7710c5a62fa\System.Drawing.Design.ni.dll + 2008-05-19 07:10:51 1,667,072 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll + 2008-05-19 08:00:50 659,456 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.ni.dll + 2008-05-19 08:00:50 294,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\646131eda5f21f4e6216733d49c22c56\System.EnterpriseServices.Wrapper.dll + 2008-05-19 08:00:59 733,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\2b5994269cc5b996231c9b21afea9a91\System.Security.ni.dll + 2008-05-19 08:01:16 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll + 2008-05-19 08:01:29 679,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll + 2008-05-19 08:02:34 2,342,912 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\37d87b3cab1c66ec4430ebb2abeaa570\System.Web.Mobile.ni.dll + 2008-05-19 08:02:39 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5b81faf46fc63c20d5339b36edd02fa\System.Web.RegularExpressions.ni.dll + 2008-05-19 08:02:51 1,986,560 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\38991368499e2109ea4099a0fe29c5a3\System.Web.Services.ni.dll + 2008-05-19 08:02:20 12,509,184 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll + 2008-05-19 07:11:15 13,193,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll + 2008-05-19 07:11:24 5,771,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll + 2008-05-18 23:07:33 8,265,728 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll + 2008-05-19 18:00:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE - 2007-03-13 09:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE + 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe - 2005-08-25 11:09:02 492,544 ----a-w C:\WINDOWS\fpuninst.exe + 2007-11-29 16:39:20 649,216 ----a-w C:\WINDOWS\fpuninst.exe + 2000-08-31 06:00:00 80,412 ----a-w C:\WINDOWS\grep.exe + 2004-08-04 11:00:00 2,589 ----a-w C:\WINDOWS\I386\RUNW32.BAT + 2007-08-20 09:55:27 124,928 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll + 2007-08-20 09:55:28 214,528 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\dxtrans.dll + 2007-08-20 09:55:28 132,608 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\extmgr.dll + 2007-08-20 09:55:28 63,488 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\icardie.dll + 2007-08-17 10:19:56 63,488 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe + 2007-08-20 09:55:28 153,088 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll + 2007-08-20 09:55:29 230,400 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll + 2007-08-17 07:34:25 161,792 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll + 2007-08-20 09:55:29 383,488 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dll + 2007-08-20 09:55:29 384,512 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll + 2007-08-20 09:55:31 6,058,496 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieframe.dll + 2007-08-20 09:55:31 44,544 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll + 2007-08-20 09:55:31 267,776 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iertutil.dll + 2007-08-17 10:19:56 13,824 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\ieudinit.exe + 2007-08-17 10:20:22 625,152 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe + 2007-08-20 09:55:31 27,648 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\jsproxy.dll + 2007-08-20 09:55:32 459,264 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeeds.dll + 2007-08-20 09:55:32 52,224 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msfeedsbs.dll + 2007-08-20 09:55:33 3,584,512 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtml.dll + 2007-08-20 09:55:33 477,696 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mshtmled.dll + 2007-08-20 09:55:33 193,024 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\msrating.dll + 2007-08-20 09:55:34 671,232 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\mstime.dll + 2007-08-20 09:55:34 102,400 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll + 2007-03-06 01:14:17 217,312 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe + 2007-03-06 01:15:25 377,568 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\updspapi.dll + 2007-08-20 09:55:34 105,984 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll + 2007-08-20 09:55:34 1,152,000 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\urlmon.dll + 2007-08-20 09:55:34 232,960 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll + 2007-08-20 09:55:34 824,832 -c----w C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll + 2007-10-10 23:46:47 124,928 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\advpack.dll + 2006-10-17 11:58:06 346,624 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtmsft.dll + 2007-10-10 23:46:47 214,528 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\dxtrans.dll + 2007-10-10 23:46:47 132,608 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\extmgr.dll + 2007-10-10 23:46:47 63,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\icardie.dll + 2007-10-10 10:59:01 70,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ie4uinit.exe + 2007-10-10 23:46:47 153,088 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakeng.dll + 2007-10-10 23:46:47 230,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieaksie.dll + 2007-10-10 05:46:55 161,792 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieakui.dll + 2007-10-10 23:46:47 383,488 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieapfltr.dll + 2007-10-10 23:46:47 384,512 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iedkcs32.dll + 2007-10-10 23:46:49 6,065,664 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieframe.dll + 2007-10-10 23:46:49 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iernonce.dll + 2007-10-10 23:46:49 267,776 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iertutil.dll + 2007-10-10 10:59:40 13,824 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\ieudinit.exe + 2007-10-10 10:59:13 625,152 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe + 2007-10-10 23:46:49 27,648 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\jsproxy.dll + 2007-10-10 23:46:49 459,264 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeeds.dll + 2007-10-10 23:46:49 52,224 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msfeedsbs.dll + 2007-10-30 23:19:46 3,590,656 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll + 2007-10-10 23:46:50 478,208 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mshtmled.dll + 2007-10-10 23:46:50 193,024 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\msrating.dll + 2007-10-10 23:46:51 671,232 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\mstime.dll + 2007-10-10 23:46:51 102,400 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\occache.dll + 2006-10-17 11:58:08 44,544 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\pngfilt.dll + 2007-03-06 01:14:17 217,312 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe + 2007-03-06 01:15:25 377,568 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\updspapi.dll + 2007-10-10 23:46:51 105,984 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\url.dll + 2007-10-10 23:46:52 1,159,680 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\urlmon.dll + 2007-10-10 23:46:52 232,960 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\webcheck.dll + 2007-10-10 23:46:52 824,832 -c----w C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll + 2007-12-07 02:04:44 124,928 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\advpack.dll + 2007-12-19 22:48:07 347,136 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtmsft.dll + 2007-12-07 02:04:44 214,528 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\dxtrans.dll + 2007-12-07 02:04:44 133,120 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\extmgr.dll + 2007-12-07 02:04:44 63,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\icardie.dll + 2007-12-06 11:00:26 70,656 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ie4uinit.exe + 2007-12-07 02:04:44 153,088 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakeng.dll + 2007-12-07 02:04:44 230,400 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieaksie.dll + 2007-12-06 04:59:51 161,792 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieakui.dll + 2007-12-07 02:04:44 383,488 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieapfltr.dll + 2007-12-07 02:04:45 384,512 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iedkcs32.dll + 2007-12-07 02:04:46 6,066,176 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieframe.dll + 2007-12-07 02:04:46 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iernonce.dll + 2007-12-07 02:04:46 267,776 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iertutil.dll + 2007-12-06 11:00:58 13,824 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\ieudinit.exe + 2007-12-06 11:00:51 625,664 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe + 2007-12-07 02:04:47 27,648 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\jsproxy.dll + 2007-12-07 02:04:47 459,264 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeeds.dll + 2007-12-07 02:04:47 52,224 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msfeedsbs.dll + 2007-12-08 05:04:50 3,592,192 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll + 2007-12-07 02:04:48 478,208 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mshtmled.dll + 2007-12-07 02:04:48 193,024 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\msrating.dll + 2007-12-07 02:04:49 671,232 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\mstime.dll + 2007-12-07 02:04:49 102,912 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\occache.dll + 2008-01-11 05:32:59 44,544 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\pngfilt.dll + 2007-03-06 01:14:13 217,312 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe + 2007-03-06 01:15:25 377,568 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\updspapi.dll + 2007-12-07 02:04:49 105,984 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\url.dll + 2007-12-07 02:04:49 1,159,680 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\urlmon.dll + 2007-12-07 02:04:49 233,472 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\webcheck.dll + 2007-12-07 02:04:49 824,832 -c----w C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll + 2006-10-26 18:49:48 1,011,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010070400000000000F01FEC\12.0.4518\MSDAIPP.DLL + 2006-10-26 18:49:46 970,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109010070400000000000F01FEC\12.0.4518\MSONSEXT.DLL + 2006-10-27 14:00:10 576,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACACEDAO.DLL + 2006-10-26 19:18:12 162,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACCWIZ.DLL + 2006-10-27 14:00:12 1,751,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECORE.DLL + 2006-10-27 14:00:10 576,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEDAO.DLL + 2006-10-27 14:00:06 47,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEERR.DLL + 2006-10-27 14:00:08 191,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEES.DLL + 2006-10-26 19:13:34 338,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCH.DLL + 2006-10-26 19:13:44 629,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEEXCL.DLL + 2006-10-26 19:13:28 207,736 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACELTS.DLL + 2006-10-26 19:13:32 279,352 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODBC.DLL + 2006-10-26 19:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODDBS.DLL + 2006-10-26 19:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODEXL.DLL + 2006-10-26 19:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODPDX.DLL + 2006-10-26 19:13:12 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEODTXT.DLL + 2006-10-27 14:00:06 387,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL + 2006-10-26 19:13:38 392,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEPDE.DLL + 2006-10-26 19:13:30 260,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER2X.DLL + 2006-10-26 19:13:32 289,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACER3X.DLL + 2006-10-26 19:13:20 56,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACERCLR.DLL + 2006-10-26 19:13:38 551,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEREP.DLL + 2006-10-26 19:13:30 224,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACETXT.DLL + 2006-10-27 14:40:34 208,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEWSS.DLL + 2006-10-26 19:13:34 371,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACEXBE.DLL + 2006-10-27 14:41:04 399,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CDLMSO.DLL + 2006-10-26 18:59:24 205,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CLVIEW.EXE + 2006-10-26 20:30:42 65,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\COLLIMP.DLL + 2006-10-27 14:16:36 133,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTAB32.DLL + 2006-10-26 19:12:52 189,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL + 2006-10-26 19:55:32 87,344 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DLGSETP.DLL + 2006-10-26 23:48:08 234,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DRAT.EXE + 2006-10-26 18:48:14 439,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\DWDCW20.DLL + 2006-10-26 13:10:08 1,190,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FM20.DLL + 2006-10-26 13:04:58 75,576 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FORM.DLL + 2006-10-26 18:21:24 1,682,232 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL + 2006-10-27 14:09:36 983,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FPWEC.DLL + 2006-10-26 19:02:12 2,526,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GRAPH.EXE + 2006-10-27 14:37:44 338,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVE.EXE + 2006-10-27 14:38:02 6,191,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEACCOUNTMGR.DLL + 2006-10-27 14:37:44 284,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDIO.DLL + 2006-10-26 23:47:54 65,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUDITSERVICE.EXE + 2006-10-27 14:37:40 34,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEAUTOPROXY.DLL + 2006-10-27 14:37:44 300,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECALENDARTOOL.DLL + 2006-10-26 23:47:44 33,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECLEAN.EXE + 2006-10-27 14:37:56 2,689,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMONCOMPONENTS.DLL + 2006-10-27 14:38:00 3,508,544 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSERVICES.DLL + 2006-10-27 14:37:40 117,584 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL + 2006-10-27 14:37:50 768,304 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECOMPONENTMGR.DLL + 2006-10-27 14:37:52 1,359,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVECRYPTO.DLL + 2006-10-26 23:48:24 377,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDATAVIEWERTOOL.DLL + 2006-10-27 14:37:58 3,071,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEDOCUMENTSHARETOOL.DLL + 2006-10-27 14:37:44 284,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEFETCHSERVICES.DLL + 2006-10-26 23:48:00 197,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEGAMES.DLL + 2006-10-26 23:48:18 317,736 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMIGRATOR.EXE + 2006-10-26 23:48:40 1,555,232 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMISC.DLL + 2006-10-26 23:47:42 31,016 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEMONITOR.EXE + 2006-10-26 23:47:40 22,808 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVENEW.DLL + 2006-10-26 23:48:02 224,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEPROJECTTOOLSET.DLL + 2006-10-27 14:38:04 7,053,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVERESOURCE.DLL + 2006-10-26 23:48:42 2,210,608 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESHELLEXTENSIONS.DLL + 2006-10-26 23:48:18 363,304 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESKETCHTOOL.DLL + 2006-10-26 23:47:40 16,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTDURLLAUNCHER.EXE + 2006-10-27 14:37:56 2,738,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESTORAGEMGR.DLL + 2006-10-27 14:37:38 35,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMMODE.DLL + 2006-10-26 23:48:02 222,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVESYSTEMSERVICES.DLL + 2006-10-27 14:37:50 1,163,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETEXTTOOLS.DLL + 2006-10-27 14:38:00 4,746,536 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVETRANSCEIVER.DLL + 2006-10-27 14:37:54 1,396,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUIFRAMEWORK.DLL + 2006-10-26 23:48:34 955,680 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEUTIL.DLL + 2006-10-27 14:37:40 268,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBBROWSERTOOL2.DLL + 2006-10-26 23:48:26 572,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBPLATFORMSERVICES.DLL + 2006-10-27 14:37:48 631,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\GROOVEWEBSERVICES.DLL + 2006-10-26 19:12:52 173,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IEAWSDC.DLL + 2006-10-27 14:10:08 1,439,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\INFOPATH.EXE + 2006-10-27 14:10:10 5,456,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPDESIGN.DLL + 2006-10-27 14:10:10 5,281,592 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPEDITOR.DLL + 2006-10-26 20:42:00 176,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOLK.DLL + 2007-02-10 09:20:57 609,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMHOST.DLL + 2007-02-10 09:20:57 118,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\IPOMINT.DLL + 2006-10-26 18:55:10 828,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDCAT.DLL + 2006-10-26 19:55:48 340,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MIMEDIR.DLL + 2006-10-27 14:04:08 497,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL + 2006-10-27 14:01:34 10,371,880 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSACCESS.EXE + 2006-10-26 20:18:06 66,880 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSAEXP30.DLL + 2006-10-26 11:58:14 117,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSCONV97.DLL + 2006-10-27 13:59:06 161,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCF.DLL + 2006-10-26 18:48:12 14,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOCFU.DLL + 2006-10-26 19:12:58 428,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSODCW.DLL + 2006-10-26 20:13:36 26,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSOEURO.DLL + 2006-10-26 19:00:08 6,635,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORES.DLL + 2006-10-26 12:56:36 436,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSORUN.DLL + 2006-10-26 18:50:04 672,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSQRY32.EXE + 2006-10-26 12:56:40 505,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSSOAP30.DLL + 2006-10-26 18:55:12 832,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORDB.EXE + 2006-10-26 18:55:06 538,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MSTORES.DLL + 2006-10-26 19:12:30 65,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\NAME.DLL + 2006-10-27 14:14:34 14,151,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OART.DLL + 2006-10-26 19:06:54 232,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ODEPLOY.EXE + 2006-10-26 19:14:06 7,033,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OFFOWC.DLL + 2006-10-27 14:18:36 1,658,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OGL.DLL + 2006-10-26 19:00:08 274,744 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OIS.EXE + 2006-10-26 19:00:12 998,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISAPP.DLL + 2006-10-26 19:00:10 285,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OISGRAPH.DLL + 2006-10-26 19:34:12 660,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSMAIN.DLL + 2006-10-26 19:34:10 192,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OMSXP32.DLL + 2006-10-26 19:32:42 604,000 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL + 2006-10-27 14:39:36 687,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL + 2006-10-27 14:03:04 1,018,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTE.EXE + 2006-10-26 19:24:54 98,632 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONENOTEM.EXE + 2006-10-26 19:24:50 72,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONFILTER.DLL + 2006-10-26 19:24:58 1,165,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONLIBS.DLL + 2006-10-27 14:03:06 6,579,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONMAIN.DLL + 2006-10-26 19:23:00 782,720 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL + 2006-10-26 19:07:04 6,536,992 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OSETUP.DLL + 2006-07-26 17:53:56 459,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL + 2006-10-27 14:16:44 594,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLMIME.DLL + 2006-10-27 14:16:40 176,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OUTLPH.DLL + 2006-10-26 20:30:44 482,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PORTCONN.DLL + 2006-10-27 14:04:06 465,200 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\POWERPNT.EXE + 2006-10-27 14:04:06 7,980,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPCORE.DLL + 2007-02-10 09:20:20 248,632 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTPIA.DLL + 2006-10-26 18:52:10 2,012,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PPTVIEW.EXE + 2006-10-26 19:09:36 136,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL + 2006-10-26 13:05:00 77,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSOM.DLL + 2006-10-26 19:55:54 413,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSTPRX32.DLL + 2006-10-27 14:04:06 624,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL + 2006-10-26 20:13:38 38,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REFEDIT.DLL + 2006-10-26 20:42:12 744,808 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REGFORM.EXE + 2006-10-26 13:04:44 19,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\REVERSE.DLL + 2006-10-26 19:13:00 503,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SELFCERT.EXE + 2006-10-26 19:06:58 439,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SETUP.EXE + 2006-10-26 20:18:16 502,608 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOA.DLL + 2006-07-28 14:21:58 277,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SSGEN.DLL + 2006-10-27 13:57:08 2,330,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\STSLIST.DLL + 2006-10-26 13:04:48 29,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\THOCRAPI.DLL + 2006-10-26 13:05:04 126,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL + 2006-10-26 13:05:02 86,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL + 2006-10-26 13:04:56 58,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWLAY32.DLL + 2006-10-26 13:04:48 27,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWORIENT.DLL + 2006-10-26 13:04:54 51,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECE.DLL + 2006-10-26 13:04:44 19,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWRECS.DLL + 2006-10-26 13:04:58 76,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL + 2006-09-29 23:42:56 2,583,344 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VBE6.DLL + 2006-10-26 22:00:12 1,841,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL + 2006-10-26 21:58:38 3,732,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VVIEWER.DLL + 2006-10-27 14:23:04 347,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE + 2007-02-10 09:20:21 781,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\WORDPIA.DLL + 2006-10-26 13:05:08 1,181,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL + 2006-10-26 20:17:08 11,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XLCALL32.DLL + 2006-10-26 13:05:08 530,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\XPAGE3C.DLL + 2007-08-28 22:22:36 579,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACACEDAO.DLL + 2007-08-24 04:17:04 165,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACCWIZ.DLL + 2007-08-28 22:22:30 1,754,536 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACECORE.DLL + 2007-08-28 22:22:36 579,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEDAO.DLL + 2007-08-28 22:22:38 50,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEERR.DLL + 2007-08-28 22:22:40 193,992 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEES.DLL + 2007-08-24 02:46:10 341,440 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEEXCH.DLL + 2007-08-24 02:46:14 632,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEEXCL.DLL + 2007-08-24 02:46:16 210,368 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACELTS.DLL + 2007-08-24 02:46:18 281,992 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEODBC.DLL + 2007-08-24 02:46:20 17,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEODDBS.DLL + 2007-08-24 02:46:22 17,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEODEXL.DLL + 2007-08-24 02:46:22 17,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEODPDX.DLL + 2007-08-24 02:46:22 17,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEODTXT.DLL + 2007-08-28 22:22:44 390,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEOLEDB.DLL + 2007-08-24 02:46:28 394,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEPDE.DLL + 2007-08-24 02:46:30 263,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACER2X.DLL + 2007-08-24 02:46:32 292,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACER3X.DLL + 2007-08-24 02:46:34 58,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACERCLR.DLL + 2007-08-24 02:46:38 554,440 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEREP.DLL + 2007-08-24 02:46:40 226,744 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACETXT.DLL + 2007-08-28 23:52:12 201,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEWSS.DLL + 2007-08-24 02:46:44 374,200 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ACEXBE.DLL + 2007-08-28 23:53:12 402,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\CDLMSO.DLL + 2007-08-24 02:45:50 208,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\CLVIEW.EXE + 2007-08-24 04:38:36 67,952 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\COLLIMP.DLL + 2007-08-28 22:19:32 136,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\CONTAB32.DLL + 2007-08-24 02:36:26 192,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\CONTACTPICKER.DLL + 2007-08-24 03:49:12 89,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\DLGSETP.DLL + 2007-08-24 05:58:50 237,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\DRAT.EXE + 2007-08-24 02:18:14 442,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\DWDCW20.DLL + 2007-08-24 02:18:18 437,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\DWTRIG20.EXE + 2007-10-05 19:37:38 17,927,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\EXCEL.EXE + 2007-08-23 00:03:38 1,195,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\FM20.DLL + 2007-08-23 00:19:06 78,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\FORM.DLL + 2007-08-25 18:11:44 1,685,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\FPSRVUTL.DLL + 2007-08-28 22:45:00 985,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\FPWEC.DLL + 2007-10-02 18:45:34 2,530,864 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GRAPH.EXE + 2007-08-28 23:23:36 340,856 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVE.EXE + 2007-08-28 23:23:52 6,192,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEACCOUNTMGR.DLL + 2007-08-28 23:24:06 286,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEAUDIO.DLL + 2007-08-24 05:59:20 68,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEAUDITSERVICE.EXE + 2007-08-28 23:24:08 36,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEAUTOPROXY.DLL + 2007-08-28 23:24:10 301,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECALENDARTOOL.DLL + 2007-08-24 05:59:26 36,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECLEAN.EXE + 2007-08-28 23:24:24 2,690,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECOMMONCOMPONENTS.DLL + 2007-08-28 23:24:52 3,514,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECOMMUNICATIONSSERVICES.DLL + 2007-08-28 23:25:00 118,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECOMMUNICATIONSSTATUSANDCONTROL.DLL + 2007-08-28 23:25:02 769,400 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECOMPONENTMGR.DLL + 2007-08-28 23:25:10 1,362,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVECRYPTO.DLL + 2007-08-24 06:00:16 378,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEDATAVIEWERTOOL.DLL + 2007-08-28 23:25:22 3,073,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEDOCUMENTSHARETOOL.DLL + 2007-08-28 23:25:32 287,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEFETCHSERVICES.DLL + 2007-08-24 06:00:36 200,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEGAMES.DLL + 2007-08-24 06:00:40 320,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEMIGRATOR.EXE + 2007-08-24 06:00:46 1,562,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEMISC.DLL + 2007-08-24 06:00:48 33,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEMONITOR.EXE + 2007-08-24 06:00:50 25,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVENEW.DLL + 2007-08-24 06:00:52 225,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEPROJECTTOOLSET.DLL + 2007-08-28 23:25:54 7,053,680 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVERESOURCE.DLL + 2007-08-24 06:01:22 2,212,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESHELLEXTENSIONS.DLL + 2007-08-24 06:01:28 364,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESKETCHTOOL.DLL + 2007-08-24 06:01:30 19,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESTDURLLAUNCHER.EXE + 2007-08-28 23:26:12 2,740,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESTORAGEMGR.DLL + 2007-08-28 23:26:18 36,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESYSTEMMODE.DLL + 2007-08-24 06:01:46 224,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVESYSTEMSERVICES.DLL + 2007-08-28 23:26:22 1,165,176 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVETEXTTOOLS.DLL + 2007-08-28 23:26:34 4,747,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVETRANSCEIVER.DLL + 2007-08-28 23:26:44 1,398,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEUIFRAMEWORK.DLL + 2007-08-24 06:02:24 959,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEUTIL.DLL + 2007-08-28 23:26:48 269,184 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEWEBBROWSERTOOL2.DLL + 2007-08-24 06:02:34 573,832 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEWEBPLATFORMSERVICES.DLL + 2007-08-28 23:26:54 632,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\GROOVEWEBSERVICES.DLL + 2007-08-24 02:36:58 175,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\IEAWSDC.DLL + 2007-10-05 19:30:22 1,443,880 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\INFOPATH.EXE + 2007-10-05 19:30:40 5,460,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\IPDESIGN.DLL + 2007-10-05 19:31:06 5,287,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\IPEDITOR.DLL + 2007-08-24 04:43:06 179,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\IPOLK.DLL + 2007-08-28 23:45:54 831,856 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MEDCAT.DLL + 2007-08-24 03:49:40 342,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MIMEDIR.DLL + 2007-08-28 22:38:10 500,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MORPH9.DLL + 2007-08-28 22:13:52 10,367,352 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSACCESS.EXE + 2007-08-24 04:17:48 69,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSAEXP30.DLL + 2007-08-28 23:52:02 120,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSCONV97.DLL + 2007-09-14 20:45:58 16,901,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSO.DLL + 2007-08-28 22:20:06 163,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSOCF.DLL + 2007-08-28 22:20:12 17,304 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSOCFU.DLL + 2007-09-06 16:55:08 431,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSODCW.DLL + 2007-08-24 04:50:10 29,576 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSOEURO.DLL + 2007-08-27 19:20:14 6,637,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSORES.DLL + 2007-08-28 23:18:20 439,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSORUN.DLL + 2007-08-28 22:38:46 9,584,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSPUB.EXE + 2007-08-24 02:40:16 674,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSQRY32.EXE + 2007-08-23 00:12:20 507,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSSOAP30.DLL + 2007-08-28 23:45:58 835,952 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSTORDB.EXE + 2007-08-28 23:46:06 542,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\MSTORES.DLL + 2007-08-24 02:37:50 68,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\NAME.DLL + 2007-10-05 19:44:24 14,168,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OART.DLL + 2007-10-02 18:51:22 8,436,776 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OARTCONV.DLL + 2007-09-02 00:55:16 235,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ODEPLOY.EXE + 2007-08-28 23:37:40 7,039,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OFFOWC.DLL + 2007-08-28 23:19:24 1,654,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OGL.DLL + 2007-08-24 03:06:28 277,384 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OIS.EXE + 2007-08-24 03:06:32 1,000,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OISAPP.DLL + 2007-08-24 03:06:38 288,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OISGRAPH.DLL + 2007-08-28 22:20:20 2,949,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OLMAPI32.DLL + 2007-08-24 04:42:40 663,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OMSMAIN.DLL + 2007-08-24 04:42:44 195,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OMSXP32.DLL + 2007-08-28 23:49:28 606,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONBTTNIE.DLL + 2007-08-28 23:49:34 667,544 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONBTTNOL.DLL + 2007-08-28 22:43:30 1,022,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONENOTE.EXE + 2007-08-24 03:45:42 101,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONENOTEM.EXE + 2007-08-24 03:45:42 75,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONFILTER.DLL + 2007-08-24 03:45:46 1,167,744 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONLIBS.DLL + 2007-10-12 20:08:52 6,588,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONMAIN.DLL + 2007-08-28 23:31:42 785,352 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\ONSYNCPC.DLL + 2007-09-02 00:55:54 6,540,656 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OSETUP.DLL + 2007-06-07 18:51:00 465,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OUTLFLTR.DLL + 2007-08-28 22:20:44 600,992 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OUTLMIME.DLL + 2007-09-06 17:01:10 12,836,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OUTLOOK.EXE + 2007-08-28 22:22:04 180,128 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\OUTLPH.DLL + 2007-09-06 16:50:34 485,232 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PORTCONN.DLL + 2007-08-28 22:06:16 467,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE + 2007-08-28 22:06:44 7,990,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL + 2007-08-28 23:38:22 2,016,656 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTVIEW.EXE + 2007-08-24 02:43:28 138,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PRTF9.DLL + 2007-08-23 00:19:06 79,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PSOM.DLL + 2007-08-24 03:51:48 416,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PSTPRX32.DLL + 2007-08-28 22:39:14 625,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PTXT9.DLL + 2007-08-24 02:43:36 593,296 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PUBCONV.DLL + 2007-08-24 04:50:10 41,832 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\REFEDIT.DLL + 2007-08-24 04:43:20 747,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\REGFORM.EXE + 2007-08-23 00:19:08 22,416 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\REVERSE.DLL + 2007-08-24 03:52:08 266,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SCNPST32.DLL + 2007-08-24 03:52:10 275,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SCNPST64.DLL + 2007-09-06 16:55:22 505,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SELFCERT.EXE + 2007-09-02 00:55:34 442,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SETUP.EXE + 2007-08-24 04:17:54 505,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SOA.DLL + 2007-06-07 18:51:00 125,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\SSGEN.DLL + 2007-08-28 22:28:26 2,330,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\STSLIST.DLL + 2007-08-23 00:19:08 32,608 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\THOCRAPI.DLL + 2007-08-23 00:19:08 129,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWCUTCHR.DLL + 2007-08-23 00:19:10 90,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWCUTLIN.DLL + 2007-08-23 00:19:10 60,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWLAY32.DLL + 2007-08-23 00:19:12 30,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWORIENT.DLL + 2007-08-23 00:19:14 54,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWRECE.DLL + 2007-08-23 00:19:14 22,416 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWRECS.DLL + 2007-08-23 00:19:16 79,776 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\TWSTRUCT.DLL + 2007-06-27 19:58:12 2,585,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\VBE6.DLL + 2007-08-24 06:10:14 1,846,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\VVIEWDWG.DLL + 2007-08-24 06:10:28 3,735,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\VVIEWER.DLL + 2007-08-28 22:16:00 350,064 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WINWORD.EXE + 2007-09-06 17:03:02 4,280,176 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WRD12CNV.DLL + 2007-08-28 23:07:58 24,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WRD12EXE.EXE + 2007-09-06 16:56:32 17,490,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\WWLIB.DLL + 2007-08-23 00:19:18 1,198,496 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XIMAGE3B.DLL + 2007-10-02 19:00:06 14,708,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XL12CNV.EXE + 2007-08-24 04:14:14 13,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XLCALL32.DLL + 2007-08-23 00:19:20 535,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\XPAGE3C.DLL - 2007-11-14 11:19:41 65,536 ----a-r C:\WINDOWS\Installer\{44025BD7-AD10-4769-99AE-6378FD0303D6}\DWARPPRODUCTICON.exe + 2008-05-19 10:21:08 65,536 ----a-r C:\WINDOWS\Installer\{44025BD7-AD10-4769-99AE-6378FD0303D6}\DWARPPRODUCTICON.exe + 2008-05-19 07:20:26 10,134 ----a-r C:\WINDOWS\Installer\{86A6E235-C08F-4A14-B14C-793C7D8844A0}\callmsi.exe + 2008-05-19 07:20:26 136,448 ----a-r C:\WINDOWS\Installer\{86A6E235-C08F-4A14-B14C-793C7D8844A0}\egui.exe - 2007-11-14 07:13:04 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe + 2008-05-18 23:01:47 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe - 2007-11-14 07:13:05 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe + 2008-05-18 23:01:47 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe - 2007-11-14 07:13:04 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe + 2008-05-18 23:01:47 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe - 2007-11-14 07:13:04 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe + 2008-05-18 23:01:47 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe - 2007-11-14 07:13:04 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe + 2008-05-18 23:01:47 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe - 2007-11-14 07:13:05 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe + 2008-05-18 23:01:47 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe - 2007-11-14 07:13:05 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe + 2008-05-18 23:01:47 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe - 2007-11-14 07:13:04 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe + 2008-05-18 23:01:47 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe - 2007-11-14 07:13:04 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe + 2008-05-18 23:01:47 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe - 2007-11-14 07:13:04 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe + 2008-05-18 23:01:47 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe - 2007-11-14 07:13:05 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe + 2008-05-18 23:01:47 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe - 2007-11-14 07:13:04 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe + 2008-05-18 23:01:47 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe - 2007-06-12 15:30:14 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0407-0000-0000000FF1CE}\misc.exe + 2007-12-14 17:07:56 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0407-0000-0000000FF1CE}\misc.exe - 2007-11-10 09:12:49 65,536 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\PM_Designer.exe + 2008-05-19 11:49:41 65,536 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\PM_Designer.exe - 2007-11-10 09:12:49 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe + 2008-05-19 11:49:40 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe - 2007-11-10 09:12:49 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat_Standard.exe + 2008-05-19 11:49:41 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat_Standard.exe - 2007-11-10 09:12:49 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Distiller.exe + 2008-05-19 11:49:41 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Distiller.exe - 2007-11-10 09:12:49 7,278 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_ELEMENTS_DT.exe + 2008-05-19 11:49:41 7,278 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_ELEMENTS_DT.exe - 2007-11-13 15:50:00 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ARPPRODUCTICON.exe + 2008-01-17 12:06:06 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ARPPRODUCTICON.exe - 2007-11-13 15:50:00 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_FineReader.exe + 2008-01-17 12:06:06 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_FineReader.exe - 2007-11-13 15:50:00 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_ScreenshotReader.exe + 2008-01-17 12:06:06 25,214 ----a-r C:\WINDOWS\Installer\{F9000000-0001-0000-0000-074957833700}\ICON_ScreenshotReader.exe + 2006-06-02 19:27:14 2,678 ----a-w C:\WINDOWS\java\Packages\Data\7FDRDJ1B.DAT + 2006-06-02 19:27:13 2,678 ----a-w C:\WINDOWS\java\Packages\Data\LZDV9J1N.DAT + 2006-06-02 19:27:18 2,678 ----a-w C:\WINDOWS\java\Packages\Data\U7RL73DJ.DAT + 2006-06-02 19:27:13 2,678 ----a-w C:\WINDOWS\java\Packages\Data\X3TFTJXZ.DAT + 2006-06-02 19:27:14 2,678 ----a-w C:\WINDOWS\java\Packages\Data\XBJNDZJP.DAT + 2006-04-12 08:47:22 217,073 -c--a-w C:\WINDOWS\meta4.exe - 2005-09-23 05:28:52 72,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe + 2007-10-23 23:47:38 82,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe - 2005-09-23 05:28:52 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll + 2007-10-23 23:47:38 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp10.dll - 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll + 2007-10-23 23:47:40 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_mscorwks.dll - 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll + 2007-10-23 23:47:42 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\sbscmp20_perfcounter.dll - 2005-09-23 05:28:56 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll + 2007-10-23 23:47:40 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\SharedReg12.dll - 2005-09-23 05:28:52 86,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll + 2007-10-23 23:47:38 97,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll - 2005-09-23 05:28:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll + 2007-10-23 23:47:26 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll - 2005-09-23 05:28:42 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll + 2007-10-23 23:47:30 145,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll - 2005-09-23 05:28:44 4,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll + 2007-10-23 23:47:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll - 2005-09-23 05:29:04 183,808 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll + 2007-10-23 23:47:48 193,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll - 2005-09-23 05:28:28 208,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll + 2007-10-23 23:47:20 218,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll - 2005-09-23 05:28:56 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll + 2007-10-23 23:47:40 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll - 2005-09-23 05:28:58 138,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll + 2007-10-23 23:47:42 147,968 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll - 2005-09-23 05:28:36 87,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll + 2007-10-23 23:47:26 99,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\alink.dll - 2007-04-13 01:21:18 58,712 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe + 2007-10-23 23:47:42 59,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe - 2005-09-23 05:28:32 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe + 2007-10-23 23:47:22 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe - 2007-04-13 01:20:52 10,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll + 2007-10-23 23:47:22 22,024 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll - 2007-04-13 01:20:52 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll + 2007-10-23 23:47:22 17,928 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll - 2007-04-13 01:20:52 23,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll + 2007-10-23 23:47:22 33,288 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll - 2007-04-13 01:20:50 75,264 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll + 2007-10-23 23:47:22 84,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll - 2005-09-23 05:28:32 13,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe + 2007-10-23 23:47:22 24,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe - 2007-04-13 01:20:52 32,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe + 2007-10-23 23:47:22 32,776 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe - 2005-09-23 05:28:32 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe + 2007-10-23 23:47:22 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe - 2007-04-13 01:20:52 33,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe + 2007-10-23 23:47:22 33,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe - 2007-04-13 01:20:52 32,600 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2007-10-23 23:47:22 33,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe - 2007-04-13 01:20:52 507,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll + 2007-10-23 23:47:22 507,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll - 2005-09-23 05:28:56 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe + 2007-10-23 23:47:40 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe - 2007-04-13 01:21:16 88,576 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll + 2007-10-23 23:47:40 101,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll - 2005-09-23 05:28:42 76,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe + 2007-10-23 23:47:30 80,376 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\csc.exe - 2005-09-23 05:28:42 1,144,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll + 2007-10-23 23:47:30 1,162,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscomp.dll - 2005-09-23 05:28:42 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll + 2007-10-23 23:47:30 13,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll - 2005-09-23 05:28:58 17,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll + 2007-10-23 23:47:42 27,136 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll - 2005-09-23 05:28:56 68,608 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll + 2007-10-23 23:47:40 69,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll - 2005-09-23 05:28:44 31,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe + 2007-10-23 23:47:30 35,320 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\cvtres.exe - 2005-09-23 05:28:38 52,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll + 2007-10-23 23:47:28 66,552 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll - 2007-04-13 01:20:58 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe + 2007-10-23 23:47:28 5,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe - 2005-09-23 05:29:12 547,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll + 2007-10-23 23:47:54 572,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll - 2005-09-23 05:28:56 788,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll + 2007-10-23 23:47:40 798,224 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll - 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll + 2007-10-23 23:47:36 18,936 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\fusion.dll - 2007-04-13 01:21:16 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe + 2007-10-23 23:47:40 9,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExec.exe - 2005-09-23 05:28:56 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll + 2007-10-23 23:47:40 8,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll - 2005-09-23 05:28:56 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll + 2007-10-23 23:47:40 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IEHost.dll - 2005-09-23 05:28:56 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll + 2007-10-23 23:47:40 6,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll - 2007-04-13 01:21:16 228,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe + 2007-10-23 23:47:40 230,904 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ilasm.exe - 2007-04-13 01:21:16 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe + 2007-10-23 23:47:40 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe - 2005-09-23 05:28:56 55,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll + 2007-10-23 23:47:40 65,032 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll - 2005-09-23 05:28:56 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll + 2007-10-23 23:47:40 72,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll - 2005-09-23 05:28:48 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe + 2007-10-23 23:47:34 40,960 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe - 2007-04-13 01:21:10 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll + 2007-10-23 23:47:36 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll - 2005-09-23 05:28:48 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll + 2007-10-23 23:47:36 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll - 2007-04-13 01:21:10 647,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll + 2007-10-23 23:47:36 655,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll - 2005-09-23 05:28:48 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll + 2007-10-23 23:47:36 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll - 2007-04-13 01:21:08 749,568 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll + 2007-10-23 23:47:34 749,568 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll - 2005-09-23 05:29:10 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll + 2007-10-23 23:47:52 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll - 2005-09-23 05:29:10 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll + 2007-10-23 23:47:52 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll - 2005-09-23 05:29:08 667,648 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll + 2007-10-23 23:47:50 671,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll - 2005-09-23 05:28:30 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll + 2007-10-23 23:47:20 28,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll - 2005-09-23 05:29:10 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll + 2007-10-23 23:47:52 5,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll - 2005-09-23 05:28:30 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll + 2007-10-23 23:47:20 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll - 2005-09-23 05:28:30 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2007-10-23 23:47:20 12,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll - 2005-09-23 05:28:30 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll + 2007-10-23 23:47:20 7,168 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll - 2007-04-13 01:20:52 87,040 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll + 2007-10-23 23:47:22 97,792 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll - 2005-09-23 05:28:48 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe + 2007-10-23 23:47:36 69,632 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe - 2007-04-13 01:21:18 802,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2007-10-23 23:47:40 822,280 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll - 2005-09-23 05:28:56 73,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll + 2007-10-23 23:47:40 83,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll - 2005-09-23 05:28:56 288,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll + 2007-10-23 23:47:40 308,224 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll - 2007-04-13 01:21:16 36,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll + 2007-10-23 23:47:40 47,104 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll - 2007-04-13 01:21:16 326,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2007-10-23 23:47:40 348,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll - 2005-09-23 05:28:56 81,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll + 2007-10-23 23:47:40 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorld.dll - 2007-04-13 01:21:16 4,308,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2007-10-23 23:47:40 4,444,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll - 2007-04-13 01:21:16 102,912 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll + 2007-10-23 23:47:40 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll - 2005-09-23 05:29:00 330,752 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll + 2007-10-23 23:47:44 340,992 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll - 2005-09-23 05:28:56 67,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll + 2007-10-23 23:47:40 77,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll - 2005-09-23 05:28:50 9,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll + 2007-10-23 23:47:36 18,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll - 2007-04-13 01:21:18 227,328 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll + 2007-10-23 23:47:40 242,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll - 2007-04-13 01:21:18 68,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe + 2007-10-23 23:47:40 70,144 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - 2005-09-23 05:28:56 10,240 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll + 2007-10-23 23:47:40 19,456 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscortim.dll - 2007-04-13 01:21:12 5,634,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll + 2007-10-23 23:47:36 5,814,784 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - 2005-09-23 05:29:00 22,528 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll + 2007-10-23 23:47:44 31,744 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll - 2007-04-13 01:21:16 99,152 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe + 2007-10-23 23:47:40 101,880 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe - 2007-04-13 01:21:18 15,360 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll + 2007-10-23 23:47:40 24,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\normalization.dll - 2005-09-23 05:28:56 78,336 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll + 2007-10-23 23:47:40 89,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll - 2007-04-13 01:21:12 136,192 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll + 2007-10-23 23:47:36 144,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\peverify.dll - 2005-09-23 05:28:56 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe + 2007-10-23 23:47:40 53,248 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe - 2005-09-23 05:28:56 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe + 2007-10-23 23:47:40 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe - 2005-09-23 05:29:02 59,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe + 2007-10-23 23:47:46 61,952 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe - 2005-09-23 05:28:58 7,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll + 2007-10-23 23:47:42 16,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll - 2005-09-23 05:28:56 107,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll + 2007-10-23 23:47:40 119,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\shfusion.dll - 2005-09-23 05:29:00 85,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll + 2007-10-23 23:47:44 95,232 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll - 2007-04-13 01:21:18 382,464 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll + 2007-10-23 23:47:40 392,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\SOS.dll - 2007-04-13 01:21:18 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll + 2007-10-23 23:47:40 110,592 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll - 2007-04-13 01:21:18 413,696 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll + 2007-10-23 23:47:42 425,984 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll - 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll + 2007-10-23 23:47:40 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll - 2007-04-13 01:21:16 2,902,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll + 2007-10-23 23:47:40 3,036,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.dll - 2007-04-13 01:21:18 482,304 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll + 2007-10-23 23:47:40 483,840 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll - 2007-04-13 01:21:18 716,800 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll + 2007-10-23 23:47:40 741,376 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll - 2007-04-13 01:20:58 888,832 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll + 2007-10-23 23:47:28 933,888 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll - 2007-04-13 01:21:16 5,001,216 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll + 2007-10-23 23:47:40 5,070,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Design.dll - 2005-09-23 05:28:56 397,312 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll + 2007-10-23 23:47:40 401,408 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll - 2007-04-13 01:21:18 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll + 2007-10-23 23:47:40 188,416 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll - 2007-04-13 01:21:16 2,940,928 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll + 2007-10-23 23:47:40 3,076,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.dll - 2005-09-23 05:28:56 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll + 2007-10-23 23:47:40 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll - 2007-04-13 01:21:16 577,536 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll + 2007-10-23 23:47:40 630,784 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll - 2007-04-13 01:21:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll + 2007-10-23 23:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll - 2007-04-13 01:21:18 47,616 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll + 2007-10-23 23:47:40 57,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll - 2007-04-13 01:21:18 114,176 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll + 2007-10-23 23:47:40 113,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll - 2007-04-13 01:21:16 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll + 2007-10-23 23:47:40 372,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Management.dll - 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll + 2007-10-23 23:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll - 2007-04-13 01:21:16 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll + 2007-10-23 23:47:40 299,008 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll - 2005-09-23 05:28:56 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll + 2007-10-23 23:47:40 131,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll - 2005-09-23 05:28:56 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll + 2007-10-23 23:47:40 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Security.dll - 2005-09-23 05:28:56 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll + 2007-10-23 23:47:40 114,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll - 2007-04-13 01:21:18 260,096 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll + 2007-10-23 23:47:40 261,120 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll - 2007-04-13 01:21:16 5,156,864 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2007-10-23 23:47:40 5,431,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.dll - 2005-09-23 05:28:56 835,584 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll + 2007-10-23 23:47:40 884,736 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll - 2005-09-23 05:28:56 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll + 2007-10-23 23:47:40 90,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll - 2005-09-23 05:28:56 823,296 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll + 2007-10-23 23:47:40 839,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll - 2007-04-13 01:21:16 5,152,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll + 2007-10-23 23:47:40 5,013,504 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll - 2007-04-13 01:21:16 2,027,520 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll + 2007-10-23 23:47:40 2,068,480 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.XML.dll - 2005-09-23 05:28:56 71,680 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL + 2007-10-23 23:47:40 81,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL - 2007-04-13 01:21:28 1,166,672 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe + 2007-10-23 23:47:48 1,172,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\vbc.exe - 2007-04-13 01:20:50 1,330,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll + 2007-10-23 23:47:20 1,344,000 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll - 2007-04-13 01:20:52 406,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2007-10-23 23:47:22 434,688 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll - 2005-09-23 05:28:56 28,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll + 2007-10-23 23:47:40 37,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll + 2006-04-05 07:09:16 66,560 -c--a-w C:\WINDOWS\MOTA113.exe + 2006-04-27 09:23:36 2,909 ----a-w C:\WINDOWS\mozver.dat - 2007-06-16 23:11:58 51,200 ----a-w C:\WINDOWS\NirCmd.exe + 2000-08-31 06:00:00 28,160 -c--a-w C:\WINDOWS\NirCmd.exe + 2006-11-05 11:09:08 3,014 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin + 2000-08-31 06:00:00 98,816 ----a-w C:\WINDOWS\sed.exe + 2007-10-11 10:24:00 85,952 -c--a-w C:\WINDOWS\sleen1664.sys + 2006-11-19 15:45:55 2,268 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{AD79946E-DDBE-406F-8B4F-C27892D9A964}.bin + 2007-08-25 16:41:44 100,864 -c--a-w C:\WINDOWS\step1.exe + 2006-07-24 20:22:00 86,016 -c--a-w C:\WINDOWS\step2.exe + 2000-08-31 06:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe + 2000-08-31 06:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe + 2000-08-31 06:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe + 2004-08-04 11:00:00 2,000 ----a-w C:\WINDOWS\system\KEYBOARD.DRV + 2006-07-17 00:00:00 73,760 ----a-w C:\WINDOWS\system\MCIAVI.DRV + 2006-07-17 00:00:00 25,296 ----a-w C:\WINDOWS\system\MCISEQ.DRV + 2006-07-17 00:00:00 28,160 ----a-w C:\WINDOWS\system\MCIWAVE.DRV + 2004-08-04 11:00:00 2,032 ----a-w C:\WINDOWS\system\MOUSE.DRV + 2004-08-04 11:00:00 1,744 ----a-w C:\WINDOWS\system\SOUND.DRV + 2004-08-04 11:00:00 3,360 ----a-w C:\WINDOWS\system\SYSTEM.DRV + 2004-08-04 11:00:00 4,048 ----a-w C:\WINDOWS\system\TIMER.DRV + 2004-08-04 11:00:00 2,176 ----a-w C:\WINDOWS\system\VGA.DRV + 2004-08-04 11:00:00 13,600 ----a-w C:\WINDOWS\system\WFWNET.DRV + 2004-08-04 11:00:00 146,944 ----a-w C:\WINDOWS\system\WINSPOOL.DRV - 2007-08-20 09:55:27 124,928 ----a-w C:\WINDOWS\system32\advpack.dll + 2008-03-01 12:53:51 124,928 ----a-w C:\WINDOWS\system32\advpack.dll - 2007-02-19 09:48:00 790,528 ----a-w C:\WINDOWS\system32\asignp11.dll + 2007-11-08 10:34:48 831,488 ----a-w C:\WINDOWS\system32\asignp11.dll + 2007-05-17 16:30:48 318,976 ----a-w C:\WINDOWS\system32\avisynth.dll + 2005-07-14 11:31:20 27,648 ----a-w C:\WINDOWS\system32\AVSredirect.dll - 2007-09-19 12:21:37 9,728 ----a-w C:\WINDOWS\system32\BASSMOD.dll + 2007-12-04 21:52:57 34,308 ----a-w C:\WINDOWS\system32\BASSMOD.dll + 2007-12-18 11:26:46 153,448 ----a-w C:\WINDOWS\system32\cjeca32.dll - 2007-01-30 08:38:08 47,616 ------w C:\WINDOWS\system32\cjKbBase.dll + 2007-05-31 06:38:14 47,616 ----a-w C:\WINDOWS\system32\cjKbBase.dll - 2007-03-04 20:26:16 593,920 ----a-w C:\WINDOWS\system32\cjpcsc.exe + 2008-01-07 11:19:04 652,592 ----a-w C:\WINDOWS\system32\cjpcsc.exe - 2007-03-04 20:25:36 413,696 ----a-w C:\WINDOWS\system32\cjpcsc32.dll + 2008-01-07 11:19:10 427,312 ----a-w C:\WINDOWS\system32\cjpcsc32.dll - 2007-03-04 20:25:24 638,976 ----a-w C:\WINDOWS\system32\cjpcscui.exe + 2008-01-07 11:19:12 648,496 ----a-w C:\WINDOWS\system32\cjpcscui.exe - 2007-02-18 18:38:00 147,456 ------w C:\WINDOWS\system32\cjppa32.dll + 2007-05-31 06:38:14 147,456 ----a-w C:\WINDOWS\system32\cjppa32.dll - 2004-03-09 07:40:58 53,248 ------w C:\WINDOWS\system32\cjtrm.dll + 2007-05-31 06:38:00 53,248 ----a-w C:\WINDOWS\system32\cjtrm.dll + 2006-07-17 00:00:00 10,544 ----a-w C:\WINDOWS\system32\comm.drv - 2007-03-04 20:25:52 303,104 ----a-w C:\WINDOWS\system32\ctrsct32.dll + 2008-01-07 11:19:06 308,528 ----a-w C:\WINDOWS\system32\ctrsct32.dll + 2006-07-17 00:00:00 1,788 ----a-w C:\WINDOWS\system32\Dcache.bin + 2004-02-22 09:11:08 719,872 ----a-w C:\WINDOWS\system32\devil.dll - 2005-09-23 05:28:38 83,456 ----a-w C:\WINDOWS\system32\dfshim.dll + 2007-10-23 23:47:28 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll - 2007-02-01 04:56:04 639,066 ----a-w C:\WINDOWS\system32\DivX.dll + 2007-12-04 01:33:16 682,496 ----a-w C:\WINDOWS\system32\DivX.dll - 2007-02-01 04:56:06 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll + 2007-12-04 01:33:18 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll - 2007-02-01 04:56:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll + 2007-12-04 01:33:18 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll - 2007-02-01 04:56:05 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll + 2007-12-04 01:33:18 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll + 2007-11-28 21:55:18 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe - 2007-01-31 21:27:01 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe + 2007-11-29 22:30:42 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe - 2006-12-12 16:24:42 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll + 2007-11-28 21:52:32 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll - 2007-08-20 09:55:27 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll + 2008-03-01 12:53:51 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll - 2006-07-17 00:00:00 375,296 -c--a-w C:\WINDOWS\system32\dllcache\asp51.dll + 2008-01-10 18:44:48 375,296 -c--a-w C:\WINDOWS\system32\dllcache\asp51.dll - 2006-06-26 17:40:34 148,480 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll + 2008-02-20 05:33:54 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll - 2006-07-17 00:00:00 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll + 2008-02-20 05:33:54 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll - 2006-10-17 11:58:06 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll + 2008-03-01 12:53:51 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll - 2007-08-20 09:55:28 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2008-03-01 12:53:52 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2007-08-20 09:55:28 132,608 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2008-03-01 12:53:52 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll - 2007-06-19 13:31:19 282,112 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll + 2008-02-20 06:50:29 282,624 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll - 2007-08-20 09:55:28 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll + 2008-03-01 12:53:52 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll - 2007-08-17 10:19:56 63,488 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe + 2008-02-29 08:54:43 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe - 2007-08-20 09:55:28 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll + 2008-03-01 12:53:52 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll - 2007-08-20 09:55:29 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll + 2008-03-01 12:53:52 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll - 2007-08-17 07:34:25 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll + 2008-02-15 05:44:25 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll - 2007-08-20 09:55:29 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll + 2008-03-01 12:53:52 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll - 2007-08-20 09:55:29 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll + 2008-03-01 12:53:53 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll - 2007-08-20 09:55:31 6,058,496 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll + 2008-03-01 12:53:56 6,066,176 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll - 2007-08-20 09:55:31 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll + 2008-03-01 12:53:57 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll - 2007-08-20 09:55:31 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll + 2008-03-01 12:53:57 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll - 2007-08-17 10:19:56 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe + 2008-02-22 10:00:51 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe - 2007-08-17 10:20:22 625,152 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe + 2008-02-29 08:55:08 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe - 2006-07-17 00:00:00 257,024 -c--a-w C:\WINDOWS\system32\dllcache\infocomm.dll + 2008-01-10 05:21:41 257,024 -c--a-w C:\WINDOWS\system32\dllcache\infocomm.dll - 2007-08-20 09:55:31 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2008-03-01 12:53:58 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2006-07-17 00:00:00 2,000 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.drv - 2006-08-17 12:28:44 729,600 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll + 2007-11-07 09:27:10 729,600 -c--a-w C:\WINDOWS\system32\dllcache\lsasrv.dll + 2006-07-17 00:00:00 2,560 -c--a-w C:\WINDOWS\system32\dllcache\lz32.dll + 2006-07-17 00:00:00 73,760 -c--a-w C:\WINDOWS\system32\dllcache\mciavi.drv + 2006-07-17 00:00:00 25,296 -c--a-w C:\WINDOWS\system32\dllcache\mciseq.drv + 2006-07-17 00:00:00 28,160 -c--a-w C:\WINDOWS\system32\dllcache\mciwave.drv + 2006-07-17 00:00:00 2,032 -c--a-w C:\WINDOWS\system32\dllcache\mouse.drv - 2006-07-17 00:00:00 72,960 -c--a-w C:\WINDOWS\system32\dllcache\mqac.sys + 2007-07-06 10:05:47 72,960 -c--a-w C:\WINDOWS\system32\dllcache\mqac.sys - 2006-07-17 00:00:00 138,240 -c--a-w C:\WINDOWS\system32\dllcache\mqad.dll + 2007-07-06 12:49:58 138,240 -c--a-w C:\WINDOWS\system32\dllcache\mqad.dll - 2006-07-17 00:00:00 47,104 -c--a-w C:\WINDOWS\system32\dllcache\mqdscli.dll + 2007-07-06 12:49:58 47,104 -c--a-w C:\WINDOWS\system32\dllcache\mqdscli.dll - 2006-07-17 00:00:00 16,896 -c--a-w C:\WINDOWS\system32\dllcache\mqise.dll + 2007-07-06 12:49:58 16,896 -c--a-w C:\WINDOWS\system32\dllcache\mqise.dll - 2006-07-17 00:00:00 660,992 -c--a-w C:\WINDOWS\system32\dllcache\mqqm.dll + 2007-07-06 12:49:58 660,992 -c--a-w C:\WINDOWS\system32\dllcache\mqqm.dll - 2006-07-17 00:00:00 177,152 -c--a-w C:\WINDOWS\system32\dllcache\mqrt.dll + 2007-07-06 12:49:58 177,152 -c--a-w C:\WINDOWS\system32\dllcache\mqrt.dll - 2006-07-17 00:00:00 95,744 -c--a-w C:\WINDOWS\system32\dllcache\mqsec.dll + 2007-07-06 12:49:58 95,744 -c--a-w C:\WINDOWS\system32\dllcache\mqsec.dll - 2006-07-17 00:00:00 48,640 -c--a-w C:\WINDOWS\system32\dllcache\mqupgrd.dll + 2007-07-06 12:49:58 48,640 -c--a-w C:\WINDOWS\system32\dllcache\mqupgrd.dll - 2006-07-17 00:00:00 533,504 -c--a-w C:\WINDOWS\system32\dllcache\mqutil.dll + 2007-07-06 12:49:58 533,504 -c--a-w C:\WINDOWS\system32\dllcache\mqutil.dll - 2006-07-17 00:00:00 181,248 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys + 2007-12-18 09:51:35 179,584 -c--a-w C:\WINDOWS\system32\dllcache\mrxdav.sys - 2007-08-20 09:55:32 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll + 2008-03-01 12:53:59 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll - 2007-08-20 09:55:32 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll + 2008-03-01 12:53:59 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll - 2007-08-20 09:55:33 3,584,512 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll + 2008-03-01 16:24:04 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll - 2007-08-20 09:55:33 477,696 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2008-03-01 12:54:02 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2007-08-20 09:55:33 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2008-03-01 12:54:03 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2007-08-20 09:55:34 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2008-03-01 12:54:03 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2006-07-17 00:00:00 2,944 -c--a-w C:\WINDOWS\system32\dllcache\null.sys - 2007-08-20 09:55:34 102,400 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll + 2008-03-01 12:54:03 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll - 2007-05-17 11:28:50 549,376 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll + 2007-12-04 18:40:03 550,912 -c--a-w C:\WINDOWS\system32\dllcache\oleaut32.dll - 2006-10-17 11:58:08 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll + 2008-03-01 12:54:04 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll - 2006-07-17 00:00:00 1,292,800 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll + 2007-10-29 22:42:30 1,293,312 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll + 2006-07-17 00:00:00 1,744 -c--a-w C:\WINDOWS\system32\dllcache\sound.drv + 2006-07-17 00:00:00 3,360 -c--a-w C:\WINDOWS\system32\dllcache\system.drv - 2006-07-17 00:00:00 359,808 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys + 2007-10-30 17:20:55 360,064 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys + 2006-07-17 00:00:00 4,048 -c--a-w C:\WINDOWS\system32\dllcache\timer.drv - 2007-08-20 09:55:34 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll + 2008-03-01 12:54:04 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll - 2007-08-20 09:55:34 1,152,000 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2008-03-01 12:54:04 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2006-07-17 00:00:00 2,176 -c--a-w C:\WINDOWS\system32\dllcache\vga.drv - 2007-08-20 09:55:34 232,960 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll + 2008-03-01 12:54:05 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll + 2006-07-17 00:00:00 13,600 -c--a-w C:\WINDOWS\system32\dllcache\wfwnet.drv - 2007-03-08 15:32:24 1,843,712 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys + 2008-03-20 08:03:19 1,845,376 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys - 2007-08-20 09:55:34 824,832 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2008-03-01 12:54:05 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2006-07-17 00:00:00 2,864 -c--a-w C:\WINDOWS\system32\dllcache\winsock.dll + 2006-07-17 00:00:00 146,944 -c--a-w C:\WINDOWS\system32\dllcache\winspool.drv + 2006-07-17 00:00:00 2,112 -c--a-w C:\WINDOWS\system32\dllcache\winspool.exe - 2006-10-18 20:47:18 222,208 -c--a-w C:\WINDOWS\system32\dllcache\WMASF.dll + 2007-10-25 08:28:30 222,720 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll + 2006-07-17 00:00:00 2,736 -c--a-w C:\WINDOWS\system32\dllcache\wowdeb.exe - 2006-06-26 17:40:34 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll + 2008-02-20 05:33:54 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll - 2006-07-17 00:00:00 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll + 2008-02-20 05:33:54 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll - 2007-01-30 04:56:56 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll + 2007-11-29 22:28:24 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll - 2007-01-26 01:13:44 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll + 2007-11-28 21:53:18 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll - 2007-01-26 01:13:44 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll + 2007-11-28 21:53:18 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll - 2007-01-26 01:13:45 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll + 2007-11-28 21:53:18 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll - 2007-01-26 01:13:44 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll + 2007-11-28 21:53:18 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll - 2007-01-26 01:13:44 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll + 2007-11-28 21:53:18 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll - 2007-01-26 01:13:44 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll + 2007-11-28 21:53:18 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll - 2006-01-28 12:58:48 14,949 ------w C:\WINDOWS\system32\drivers\bizVSerialNT.sys + 2007-05-31 06:38:16 14,949 ----a-w C:\WINDOWS\system32\drivers\bizVSerialNT.sys + 2006-08-28 19:48:26 2,432 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys + 2006-08-28 19:48:26 2,560 ----a-w C:\WINDOWS\system32\drivers\cdralw2k.sys - 2006-06-14 12:37:04 23,040 ----a-w C:\WINDOWS\system32\drivers\cjusb.sys + 2007-05-31 06:38:18 23,040 ----a-w C:\WINDOWS\system32\drivers\cjusb.sys + 2006-07-17 00:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys - 2007-09-21 07:15:26 33,288 ----a-w C:\WINDOWS\system32\drivers\eamon.sys + 2008-03-13 14:43:42 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys - 2007-09-21 07:15:52 25,096 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys + 2008-03-13 14:44:36 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys - 2007-09-21 07:17:14 28,680 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys + 2008-03-13 14:52:18 33,800 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys + 2007-11-02 13:36:10 18,176 ----a-w C:\WINDOWS\system32\drivers\motccgp.sys + 2007-01-22 18:33:00 7,680 ----a-w C:\WINDOWS\system32\drivers\motccgpfl.sys + 2007-06-18 14:18:26 23,680 ----a-w C:\WINDOWS\system32\drivers\motmodem.sys + 2007-11-02 13:51:28 6,400 ----a-w C:\WINDOWS\system32\drivers\motswch.sys - 2006-07-17 00:00:00 72,960 ----a-w C:\WINDOWS\system32\drivers\mqac.sys + 2007-07-06 10:05:47 72,960 ----a-w C:\WINDOWS\system32\drivers\mqac.sys - 2006-07-17 00:00:00 181,248 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys + 2007-12-18 09:51:35 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys + 2006-07-17 00:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\null.sys - 2006-07-17 00:00:00 27,440 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys + 2007-11-13 10:25:53 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys + 2007-10-11 10:24:00 79,104 ----a-w C:\WINDOWS\system32\drivers\sleen16.sys - 2006-07-17 00:00:00 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys + 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys + 2006-11-02 06:22:54 492,000 ------w C:\WINDOWS\system32\drivers\wdf01000.sys + 2006-11-02 06:22:52 32,224 ------w C:\WINDOWS\system32\drivers\wdfldr.sys + 2007-05-31 06:38:18 23,040 -c--a-w C:\WINDOWS\system32\DRVSTORE\cjusbxp_087D072C161AA8B8DE1BF13728E5B7B238633E7F\cjusb.sys + 2007-11-02 13:36:10 18,176 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_BE790352925446F864D655FAFE9970C67FAF936A\motccgp.sys + 2007-01-23 18:03:44 7,680 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_BE790352925446F864D655FAFE9970C67FAF936A\motccgpfl.sys + 2007-11-02 13:51:28 6,400 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_BE790352925446F864D655FAFE9970C67FAF936A\motswch.sys + 2006-11-13 13:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motccgp_BE790352925446F864D655FAFE9970C67FAF936A\wdfcoinstaller01005.dll + 2007-06-18 13:18:26 23,680 -c--a-w C:\WINDOWS\system32\DRVSTORE\motmodem_6069CEC8E9C5F2AEEF321872E395929E2ECB977C\motmodem.sys + 2006-11-13 13:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motmodem_6069CEC8E9C5F2AEEF321872E395929E2ECB977C\wdfcoinstaller01005.dll + 2006-07-28 06:10:08 6,144 -c--a-w C:\WINDOWS\system32\DRVSTORE\motodrv_22341B72FCC8DC598935CF00122CD189BE8E0E3B\mot_ci.dll + 2007-10-10 15:41:50 42,112 -c--a-w C:\WINDOWS\system32\DRVSTORE\motodrv_22341B72FCC8DC598935CF00122CD189BE8E0E3B\motodrv.sys + 2007-01-23 20:36:20 6,016 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_F1F6B8D0B008E23D15C7FB6A13B8CAA12F1AA650\motfilt.sys + 2007-11-02 13:41:06 22,272 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_F1F6B8D0B008E23D15C7FB6A13B8CAA12F1AA650\Motousbnet.sys + 2007-11-02 13:51:28 6,400 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_F1F6B8D0B008E23D15C7FB6A13B8CAA12F1AA650\motswch.sys + 2006-11-13 13:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motousbnet_F1F6B8D0B008E23D15C7FB6A13B8CAA12F1AA650\wdfcoinstaller01005.dll + 2007-06-18 13:18:26 23,680 -c--a-w C:\WINDOWS\system32\DRVSTORE\motport_971CE3EB0BFA971A641FCBEF7FB91FA0762A6404\motport.sys + 2006-11-13 13:45:54 1,419,232 -c--a-w C:\WINDOWS\system32\DRVSTORE\motport_971CE3EB0BFA971A641FCBEF7FB91FA0762A6404\wdfcoinstaller01005.dll - 2007-01-26 01:13:45 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll + 2007-11-29 22:28:24 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll - 2006-10-17 11:58:06 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll + 2008-03-01 12:53:51 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll - 2007-08-20 09:55:28 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll + 2008-03-01 12:53:52 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll - 2007-08-20 09:55:28 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll + 2008-03-01 12:53:52 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll - 2006-10-26 13:10:08 1,190,688 ----a-w C:\WINDOWS\system32\FM20.DLL + 2007-08-23 00:03:38 1,195,888 ----a-w C:\WINDOWS\system32\FM20.DLL - 2007-06-12 19:44:25 331,480 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2008-04-10 01:22:34 331,480 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT - 2007-06-19 13:31:19 282,112 ----a-w C:\WINDOWS\system32\gdi32.dll + 2008-02-20 06:50:29 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll - 2002-06-27 14:17:12 200,704 ------w C:\WINDOWS\system32\gkapi.dll + 2008-01-07 11:09:56 274,432 ----a-w C:\WINDOWS\system32\gkapi.dll + 2004-01-24 23:00:00 70,656 ----a-w C:\WINDOWS\system32\i420vfw.dll - 2007-08-20 09:55:28 63,488 ----a-w C:\WINDOWS\system32\icardie.dll + 2008-03-01 12:53:52 63,488 ----a-w C:\WINDOWS\system32\icardie.dll - 2007-08-17 10:19:56 63,488 ----a-w C:\WINDOWS\system32\ie4uinit.exe + 2008-02-29 08:54:43 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe - 2007-08-20 09:55:28 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll + 2008-03-01 12:53:52 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll - 2007-08-20 09:55:29 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll + 2008-03-01 12:53:52 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll - 2007-08-17 07:34:25 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll + 2008-02-15 05:44:25 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll - 2007-08-20 09:55:29 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll + 2008-03-01 12:53:52 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll - 2007-08-20 09:55:29 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll + 2008-03-01 12:53:53 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll - 2007-08-20 09:55:31 6,058,496 ----a-w C:\WINDOWS\system32\ieframe.dll + 2008-03-01 12:53:56 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll - 2007-08-20 09:55:31 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll + 2008-03-01 12:53:57 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll - 2007-08-20 09:55:31 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll + 2008-03-01 12:53:57 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll - 2007-08-17 10:19:56 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe + 2008-02-22 10:00:51 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe - 2006-07-17 00:00:00 375,296 ----a-w C:\WINDOWS\system32\inetsrv\asp.dll + 2008-01-10 18:44:48 375,296 ----a-w C:\WINDOWS\system32\inetsrv\asp.dll - 2006-07-17 00:00:00 257,024 ----a-w C:\WINDOWS\system32\inetsrv\infocomm.dll + 2008-01-10 05:21:41 257,024 ----a-w C:\WINDOWS\system32\inetsrv\infocomm.dll - 2007-11-15 14:45:16 224,623 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin + 2008-05-19 18:03:33 224,605 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin - 2007-08-20 09:55:31 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2008-03-01 12:53:58 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2006-07-17 00:00:00 2,000 ----a-w C:\WINDOWS\system32\keyboard.drv + 2006-07-17 00:00:00 226,064 ----a-w C:\WINDOWS\system32\lanman.drv - 2007-01-26 01:18:54 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll + 2007-11-29 22:30:16 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll - 2006-08-17 12:28:44 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll + 2007-11-07 09:27:10 729,600 ----a-w C:\WINDOWS\system32\lsasrv.dll + 2006-07-17 00:00:00 2,560 ----a-w C:\WINDOWS\system32\lz32.dll - 2007-08-07 16:20:44 182,248 ----a-w C:\WINDOWS\system32\Macromed\Director\SwDir.dll + 2008-01-07 10:26:46 181,672 ----a-w C:\WINDOWS\system32\Macromed\Director\SwDir.dll + 2007-11-21 00:04:14 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe - 2007-08-07 12:35:56 585,728 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll + 2008-01-03 17:19:34 581,632 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll - 2007-08-07 12:19:40 1,490,944 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\dirapi.dll + 2008-01-03 17:01:46 1,490,944 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\dirapi.dll - 2007-08-07 12:36:32 24,576 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\DynaPlayer.dll + 2008-01-03 17:20:14 24,576 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\DynaPlayer.dll - 2007-08-07 15:52:32 1,113,600 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gi.dll + 2008-01-03 17:39:06 1,113,600 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gi.dll - 2007-08-07 12:08:48 52,288 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gtapi.dll + 2008-01-03 16:46:46 52,288 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gtapi.dll - 2007-08-07 12:17:24 606,208 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\iml32.dll + 2008-01-03 16:59:14 606,208 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\iml32.dll - 2007-08-07 12:35:22 339,968 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Plugin.dll + 2008-01-03 17:18:56 339,968 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Plugin.dll - 2007-08-07 12:35:32 483,328 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PluginPing.dll + 2008-01-03 17:19:06 475,136 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PluginPing.dll - 2007-08-07 12:28:38 180,224 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Proj.dll + 2008-01-03 17:11:48 180,224 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Proj.dll + 2008-01-07 10:26:28 390,568 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwHelper_1030024.exe - 2007-08-07 12:37:56 77,824 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe + 2008-01-03 17:22:06 77,824 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe - 2007-08-07 12:35:18 86,016 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwMenu.dll + 2008-01-03 17:18:50 86,016 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwMenu.dll - 2007-08-07 12:37:58 98,304 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwOnce.dll + 2008-01-03 17:22:08 98,304 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwOnce.dll - 2007-08-07 12:08:46 50,808 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SYMCCHECKER.DLL + 2008-01-03 16:46:44 50,808 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SYMCCHECKER.DLL + 2006-07-17 00:00:00 73,760 ----a-w C:\WINDOWS\system32\mciavi.drv + 2006-07-17 00:00:00 25,296 ----a-w C:\WINDOWS\system32\mciseq.drv + 2006-07-17 00:00:00 28,160 ----a-w C:\WINDOWS\system32\mciwave.drv + 2006-07-28 07:10:08 6,144 ----a-w C:\WINDOWS\system32\mot_ci.dll + 2006-07-17 00:00:00 2,032 ----a-w C:\WINDOWS\system32\mouse.drv - 2006-07-17 00:00:00 138,240 ----a-w C:\WINDOWS\system32\mqad.dll + 2007-07-06 12:49:58 138,240 ----a-w C:\WINDOWS\system32\mqad.dll - 2006-07-17 00:00:00 47,104 ----a-w C:\WINDOWS\system32\mqdscli.dll + 2007-07-06 12:49:58 47,104 ----a-w C:\WINDOWS\system32\mqdscli.dll - 2006-07-17 00:00:00 16,896 ----a-w C:\WINDOWS\system32\mqise.dll + 2007-07-06 12:49:58 16,896 ----a-w C:\WINDOWS\system32\mqise.dll - 2006-07-17 00:00:00 660,992 ----a-w C:\WINDOWS\system32\mqqm.dll + 2007-07-06 12:49:58 660,992 ----a-w C:\WINDOWS\system32\mqqm.dll - 2006-07-17 00:00:00 177,152 ----a-w C:\WINDOWS\system32\mqrt.dll + 2007-07-06 12:49:58 177,152 ----a-w C:\WINDOWS\system32\mqrt.dll - 2006-07-17 00:00:00 95,744 ----a-w C:\WINDOWS\system32\mqsec.dll + 2007-07-06 12:49:58 95,744 ----a-w C:\WINDOWS\system32\mqsec.dll - 2006-07-17 00:00:00 48,640 ----a-w C:\WINDOWS\system32\mqupgrd.dll + 2007-07-06 12:49:58 48,640 ----a-w C:\WINDOWS\system32\mqupgrd.dll - 2006-07-17 00:00:00 533,504 ----a-w C:\WINDOWS\system32\mqutil.dll + 2007-07-06 12:49:58 533,504 ----a-w C:\WINDOWS\system32\mqutil.dll - 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe + 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe + 2006-07-17 00:00:00 20,992 ----a-w C:\WINDOWS\system32\msacm32.drv - 2007-04-13 01:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll + 2007-10-23 23:47:38 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll - 2005-09-23 05:28:52 150,016 ----a-w C:\WINDOWS\system32\mscorier.dll + 2007-10-23 23:47:38 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll - 2005-09-23 05:28:52 74,240 ----a-w C:\WINDOWS\system32\mscories.dll + 2007-10-23 23:47:38 84,480 ----a-w C:\WINDOWS\system32\mscories.dll - 2007-08-20 09:55:32 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll + 2008-03-01 12:53:59 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll - 2007-08-20 09:55:32 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll + 2008-03-01 12:53:59 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll + 2004-08-04 11:00:00 192,512 ----a-w C:\WINDOWS\system32\msh261.drv + 2006-07-17 00:00:00 299,008 ----a-w C:\WINDOWS\system32\msh263.drv - 2007-08-20 09:55:33 3,584,512 ----a-w C:\WINDOWS\system32\mshtml.dll + 2008-03-01 16:24:04 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll - 2007-08-20 09:55:33 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll + 2008-03-01 12:54:02 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll - 2007-08-20 09:55:33 193,024 ----a-w C:\WINDOWS\system32\msrating.dll + 2008-03-01 12:54:03 193,024 ----a-w C:\WINDOWS\system32\msrating.dll - 2007-08-20 09:55:34 671,232 ----a-w C:\WINDOWS\system32\mstime.dll + 2008-03-01 12:54:03 671,232 ----a-w C:\WINDOWS\system32\mstime.dll - 2000-07-14 21:00:00 434,252 ----a-w C:\WINDOWS\system32\MSVCRTD.DLL + 2007-05-31 06:38:04 434,252 ----a-w C:\WINDOWS\system32\MSVCRTD.DLL + 2002-08-29 08:32:28 28,160 ------w C:\WINDOWS\system32\msxml3a.dll - 2005-09-23 05:29:00 6,144 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll + 2007-10-23 23:47:44 15,360 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll + 2006-07-17 00:00:00 2,656 ----a-w C:\WINDOWS\system32\netware.drv - 2007-08-20 09:55:34 102,400 ----a-w C:\WINDOWS\system32\occache.dll + 2008-03-01 12:54:03 102,912 ----a-w C:\WINDOWS\system32\occache.dll - 2003-05-30 12:12:30 151,552 ------w C:\WINDOWS\system32\OcfCopy.exe + 2007-05-31 06:38:00 151,552 ----a-w C:\WINDOWS\system32\OcfCopy.exe - 2001-06-12 07:55:04 41,472 ------w C:\WINDOWS\system32\ocfpcsc1.dll + 2007-05-31 06:38:00 41,472 ----a-w C:\WINDOWS\system32\ocfpcsc1.dll - 2007-05-17 11:28:50 549,376 ----a-w C:\WINDOWS\system32\oleaut32.dll + 2007-12-04 18:40:03 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll - 2007-11-15 08:48:05 147,288 ----a-w C:\WINDOWS\system32\perfc007.dat + 2008-05-19 16:02:55 149,198 ----a-w C:\WINDOWS\system32\perfc007.dat - 2007-11-15 08:48:05 119,906 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-05-19 16:02:55 121,090 ----a-w C:\WINDOWS\system32\perfc009.dat - 2007-11-15 08:48:05 593,390 ----a-w C:\WINDOWS\system32\perfh007.dat + 2008-05-19 16:02:55 599,538 ----a-w C:\WINDOWS\system32\perfh007.dat - 2007-11-15 08:48:05 543,006 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-05-19 16:02:55 548,270 ----a-w C:\WINDOWS\system32\perfh009.dat - 2006-10-17 11:58:08 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll + 2008-03-01 12:54:04 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll - 2007-01-30 05:03:40 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll + 2007-11-29 22:30:28 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll - 2006-07-17 00:00:00 1,292,800 ----a-w C:\WINDOWS\system32\quartz.dll + 2007-10-29 22:42:30 1,293,312 ----a-w C:\WINDOWS\system32\quartz.dll + 2006-06-14 12:37:04 23,040 ----a-w C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\cjusb.sys - 2006-12-19 14:14:18 266,240 ------w C:\WINDOWS\system32\rsct_pnp.dll + 2007-11-07 11:21:00 270,336 ----a-w C:\WINDOWS\system32\rsct_pnp.dll - 2006-08-23 09:30:04 143,360 ------w C:\WINDOWS\system32\rsct_pnp.exe + 2007-11-07 11:20:52 196,608 ----a-w C:\WINDOWS\system32\rsct_pnp.exe + 2006-12-05 08:27:04 184,320 ----a-w C:\WINDOWS\system32\SatSrv.exe - 2006-03-19 12:34:42 167,936 ------w C:\WINDOWS\system32\SerialXP.dll + 2007-05-31 06:38:16 167,936 ----a-w C:\WINDOWS\system32\SerialXP.dll - 2004-11-23 16:11:52 245,760 ------w C:\WINDOWS\system32\SetupHBCI.exe + 2007-11-07 11:20:46 344,064 ----a-w C:\WINDOWS\system32\SetupHBCI.exe + 2007-05-14 14:24:30 394,240 ----a-w C:\WINDOWS\system32\Smab.dll + 2006-07-17 00:00:00 1,744 ----a-w C:\WINDOWS\system32\sound.drv - 2006-10-16 14:10:58 14,640 ------w C:\WINDOWS\system32\spmsg.dll + 2006-10-08 20:51:14 14,640 ------w C:\WINDOWS\system32\spmsg.dll + 2003-05-23 03:16:00 2,560 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\vntuni.dll + 2008-05-19 17:05:29 992,753 ----a-w C:\WINDOWS\system32\spool\StreamLoad\PendingUploads.dat - 2006-10-16 14:10:58 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe + 2006-10-08 20:51:14 23,856 ----a-w C:\WINDOWS\system32\spupdsvc.exe - 2007-01-26 01:18:54 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll + 2007-11-29 22:30:16 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll + 2007-09-17 15:09:06 688,024 ----a-w C:\WINDOWS\system32\SWFToImage.dll + 2006-07-17 00:00:00 3,360 ----a-w C:\WINDOWS\system32\system.drv + 2006-07-17 00:00:00 4,048 ----a-w C:\WINDOWS\system32\timer.drv - 2007-07-18 12:42:22 60,416 ------w C:\WINDOWS\system32\tzchange.exe + 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe - 2007-08-20 09:55:34 105,984 ----a-w C:\WINDOWS\system32\url.dll + 2008-03-01 12:54:04 105,984 ----a-w C:\WINDOWS\system32\url.dll - 2007-08-20 09:55:34 1,152,000 ----a-w C:\WINDOWS\system32\urlmon.dll + 2008-03-01 12:54:04 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll + 2006-07-17 00:00:00 2,176 ----a-w C:\WINDOWS\system32\vga.drv + 2006-11-13 14:45:54 1,419,232 ----a-w C:\WINDOWS\system32\wdfcoinstaller01005.dll + 2006-07-17 00:00:00 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv - 2007-08-20 09:55:34 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll + 2008-03-01 12:54:05 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll + 2006-07-17 00:00:00 13,600 ----a-w C:\WINDOWS\system32\wfwnet.drv - 2006-11-05 13:55:50 27,648 ------w C:\WINDOWS\system32\win32com.dll + 2007-05-31 06:38:04 27,648 ----a-w C:\WINDOWS\system32\win32com.dll - 2007-03-08 15:32:24 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys + 2008-03-20 08:03:19 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys - 2007-08-20 09:55:34 824,832 ----a-w C:\WINDOWS\system32\wininet.dll + 2008-03-01 12:54:05 826,368 ----a-w C:\WINDOWS\system32\wininet.dll + 2006-07-17 00:00:00 2,864 ----a-w C:\WINDOWS\system32\winsock.dll + 2006-07-17 00:00:00 146,944 ----a-w C:\WINDOWS\system32\winspool.drv + 2006-07-17 00:00:00 2,112 ----a-w C:\WINDOWS\system32\winspool.exe - 2006-10-18 20:47:18 222,208 ----a-w C:\WINDOWS\system32\wmasf.dll + 2007-10-25 08:28:30 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll + 2006-07-17 00:00:00 2,736 ----a-w C:\WINDOWS\system32\wowdeb.exe + 2005-02-28 12:16:22 240,128 ----a-w C:\WINDOWS\system32\x.264.exe + 2004-01-24 23:00:00 70,656 ----a-w C:\WINDOWS\system32\yv12vfw.dll - 2005-04-18 11:49:26 57,344 ----a-w C:\WINDOWS\Unwash6.exe + 2007-11-26 13:47:34 194,888 ----a-w C:\WINDOWS\Unwash6.exe + 2000-08-31 06:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe + 2008-05-18 23:04:50 8,192 ----a-w C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll + 2007-10-23 23:47:56 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcm80.dll + 2007-10-23 23:47:56 558,080 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcp80.dll + 2007-10-23 23:47:56 635,904 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\msvcr80.dll + 2006-06-05 12:14:28 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll + 2006-06-05 12:14:28 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll + 2006-06-05 12:14:28 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll - 2007-07-11 08:18:26 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2008-05-18 23:05:03 258,048 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll - 2007-07-11 08:18:26 114,176 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2008-05-18 23:05:03 113,664 ----a-w C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll + 2006-10-07 16:43:42 502,784 -c--a-w C:\WINDOWS\x2.64.exe + 2000-08-31 06:00:00 68,096 ----a-w C:\WINDOWS\zip.exe . -- Snapshot reset to current date -- . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A2B8B714-495A-4CC9-BA8B-9EBC0FAE02C5}] 2008-05-19 12:57 371712 --a------ C:\WINDOWS\system32\geBrpmkI.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E707216F-6AFF-4BD4-962D-EC5CDBA812A1}] 2008-05-19 00:53 58368 --a------ C:\WINDOWS\system32\ssQgeccA.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-07-17 02:00 15360] "DeskCalc"="c:\programme\deskcalc pro\deskcalc.exe" [2006-07-25 19:58 2797568] "Voipwise"="C:\Programme\Voipwise.com\Voipwise\Voipwise.exe" [2007-09-06 11:24 7394608] "RoboForm"="C:\Programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-10-30 14:26 160592] "L07DXLRD_1003640"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ledpointer"="CNYHKey.exe" [2004-03-02 20:24 5576704 C:\WINDOWS\CNYHKey.exe] "Google Desktop Search"="C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-14 09:11 1838592] "SoundMan"="SOUNDMAN.EXE" [2005-06-20 21:42 77824 C:\WINDOWS\SOUNDMAN.EXE] "OSSelectorReinstall"="C:\Programme\Gemeinsame Dateien\Acronis\Acronis Disk Director\oss_reinstall.exe" [2006-04-12 15:15 1261475] "Babylon Client"="C:\Programme\Babylon\Babylon-Pro\Babylon.exe" [2006-12-13 16:15 2785256] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 21:07 7110656] "Outpost Firewall"="C:\Programme\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 16:56 94720] "OutpostFeedBack"="C:\Programme\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 13:18 335872] "egui"="C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-07-17 02:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 0 (0x0) "NoFileAssociate"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{E707216F-6AFF-4BD4-962D-EC5CDBA812A1}"= C:\WINDOWS\system32\ssQgeccA.dll [2008-05-19 00:53 58368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssQgeccA] ssQgeccA.dll 2008-05-19 00:53 58368 C:\WINDOWS\system32\ssQgeccA.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 relog_ap [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk] backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0] --a------ 2008-04-23 02:08 483328 C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2005-07-20 21:07 7110656 C:\WINDOWS\system32\NvCpl.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Window Washer"=C:\Programme\Webroot\Washer\wwDisp.exe "BitTorrent"="C:\Programme\BitTorrent\bittorrent.exe" --force_start_minimized "updateMgr"=C:\Programme\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_5 -reboot 1 "VoipDiscount"="C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" -nosplash -minimized "Skype"="C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized "WMPNSCFG"=C:\Programme\Windows Media Player\WMPNSCFG.exe "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe" "SecurityLayer"=C:\Programme\trustDesk\SecurityLayer.exe -autostart "Voipwise"="C:\Programme\Voipwise.com\Voipwise\Voipwise.exe" -nosplash -minimized "swg"=C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe "L07DXLRD_848718"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE" -m "L07DXLRD_29388296"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE" -m [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "RealTray"=C:\Programme\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER "Acrobat Assistant 7.0"="C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" "Acronis Scheduler2 Service"="C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe" "QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime "SunJavaUpdateSched"=C:\Programme\Java\jre1.5.0_10\bin\jusched.exe "PCMService"="C:\Programme\CyberLink\PowerCinema\PCMService.exe" "Ulead AutoDetector v2"=C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe "SMSERIAL"=sm56hlpr.exe "RemoteControl"=C:\Programme\CyberLink\PowerDVD\PDVDServ.exe "TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot "USBToolTip"="C:\Programme\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" "TrueImageMonitor.exe"=C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe "AcronisTimounterMonitor"=C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe "GrooveMonitor"="C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe" "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup "NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit "PWRISOVM.EXE"=C:\Programme\PowerISO\PWRISOVM.EXE "hpppta"=C:\Programme\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hpppta.exe /ICON "nwiz"=nwiz.exe /install "NVRaidService"=C:\WINDOWS\system32\nvraidservice.exe "HP Update 5370C"=D:\SAFE\Scanner\hpupdate.exe 5370C+ "SecurityLayer"=C:\Programme\trustDesk\securitylayer.exe "NeroFilterCheck"=C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe "InCD"=C:\Programme\Nero\Nero 7\InCD\InCD.exe "Realtime Audio Engine"="mmrtkrnl.exe" /i "CHotkey"=mHotkey.exe "3814c66d"=rundll32.exe "C:\WINDOWS\system32\tsmktvde.dll",b [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Programme\\LimeWire\\LimeWire.exe"= "C:\\Programme\\Voipwise.com\\Voipwise\\Voipwise.exe"= "C:\\Programme\\VoipDiscount.com\\VoipDiscount\\voipdiscount.exe"= "C:\\Programme\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R1 bizVSerial;Franson VSerial;C:\WINDOWS\system32\drivers\bizVSerialNT.sys [2007-05-31 08:38] R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52] R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS\system32\drivers\hcw88aud.sys [2005-05-31 12:34] R1 rsct_bus;REINER SCT PC/SC Bus;C:\WINDOWS\system32\DRIVERS\rsct_bus.sys [2004-09-10 17:35] R1 SandBox;Outpost Firewall Sandbox Driver;C:\Programme\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 19:01] R1 VFILT;Outpost Firewall Kernel Driver;C:\Programme\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 16:56] R2 Prvflder;Prvflder;C:\WINDOWS\system32\DRIVERS\prvflder.sys [2006-04-21 09:22] R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 16:57] R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\ARP.DLL [2007-04-05 16:57] R3 cjusb;REINER SCT cyberJack pinpad/e-com USB;C:\WINDOWS\system32\DRIVERS\cjusb.sys [2007-05-31 08:38] R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 16:57] R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 16:57] R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 16:57] R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS\system32\drivers\hcw88bda.sys [2005-05-31 12:34] R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS\system32\drivers\hcw88tse.sys [2005-05-31 15:43] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS\system32\drivers\hcw88tun.sys [2005-05-31 12:34] R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS\system32\drivers\hcw88vid.sys [2005-05-31 15:43] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS\system32\drivers\HCW88BAR.sys [2005-05-31 12:34] R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 16:57] R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 16:57] R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 16:57] R3 IMT0521;Inmax USB IMT-0521 Smartcard Reader;C:\WINDOWS\system32\Drivers\IMT0521.sys [2003-07-11 09:50] R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 16:57] R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 16:57] R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 16:57] R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 16:57] R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 16:57] S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0-Lizenzierungsdienst;"C:\Programme\ABBYY FineReader 9.0\NetworkLicenseServer.exe" -service [] S3 cjpcsc;cyberJack PC/SC COM Service ;C:\WINDOWS\system32\cjpcsc.exe [2008-01-07 13:19] S3 ITSPrinterService;IT Solution Signature Printer;C:\Programme\trustDesk\plugins\printer\itsprintersrv.exe [2007-04-16 22:06] S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-11-02 15:36] S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-22 20:33] S3 rsct_dev;REINER PC/SC SmartCard Reader Device Driver;C:\WINDOWS\system32\DRIVERS\rsct_dev.sys [2004-09-23 13:12] S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;C:\WINDOWS\system32\DRIVERS\SCR33X2K.sys [2003-12-03 04:22] S3 trustLogon;trustLogon;"C:\Programme\trustDesk\plugins\logon\trustlogon.exe" [2007-01-23 12:35] S3 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2006-07-17 02:00] S3 wwEngineSvc;Window Washer Engine;C:\Programme\Webroot\Washer\WasherSvc.exe [2007-11-26 15:47] S4 MSSQL$PRISO;MSSQL$PRISO;C:\Programme\Priso Datenbank\MSSQL$PRISO\Binn\sqlservr.exe [2002-12-17 17:55] S4 SQLAgent$PRISO;SQLAgent$PRISO;C:\Programme\Priso Datenbank\MSSQL$PRISO\Binn\sqlagent.EXE [2002-12-17 17:23] S4 UY;UY;C:\DOKUME~1\Robert\LOKALE~1\Temp\UY.exe [] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f859054-10cc-11da-b357-009027bfa409}] \Shell\AutoRun\command - E:\Autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b57571-157e-11da-acd9-000feaece007}] \Shell\AutoRun\command - M:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada67554-186e-11da-8373-000feaece007}] \Shell\AutoRun\command - L:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b606e90e-3bb6-11da-a3ce-0090d0404b34}] \Shell\AutoRun\command - G:\ie.exe \Shell\explore\Command - G:\ie.exe \Shell\open\Command - G:\ie.exe . Inhalt des "geplante Tasks" Ordners "2008-04-04 17:09:13 C:\WINDOWS\Tasks\1-Klick-Wartung.job" - C:\Programme\TuneUp Utilities 2007\SystemOptimizer.exe "2008-05-18 22:57:48 C:\WINDOWS\Tasks\User_Feed_Synchronization-{4FBD8FD6-1383-42F4-B3B8-6C1FF9715BF1}.job" - C:\WINDOWS\system32\msfeedssync.exe "2008-05-19 15:56:42 C:\WINDOWS\Tasks\XoftSpySE 2.job" - C:\Programme\XoftSpySE\XoftSpy.exe "2008-01-12 02:33:44 C:\WINDOWS\Tasks\XoftSpySE.job" - C:\Programme\XoftSpySE\XoftSpy.exe "2006-10-29 14:03:04 C:\WINDOWS\Tasks\_viceversapr2_task_BackUp.job" - C:\Programme\ViceVersa Pro 2\ViceVersa.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-19 20:01:11 Windows 5.1.2600 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostart Eintr„ge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\ssQgeccA.dll PROCESS: C:\WINDOWS\explorer.exe -> C:\programme\deskcalc pro\CalcHook.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\scardsvr.exe C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Programme\FolderSize\FolderSizeSvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\system32\fxssvc.exe C:\Programme\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Zeit der Fertigstellung: 2008-05-19 20:08:08 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-19 18:07:45 ComboFix2.txt 2007-11-15 14:48:40 25 Verzeichnis(se), 83,733,041,152 Bytes frei 32 Verzeichnis(se), 83,761,254,400 Bytes frei 1779 --- E O F --- 2008-05-18 23:06:20 |
|
|
||
20.05.2008, 00:19
Ehrenmitglied
Beiträge: 29434 |
#4
Hallo,
Virustotal http://www.virustotal.com/flash/index_en.html der USB-Stick auf G:\ scheint verseucht, überprüfe bitte die exe G:\ie.exe Auf Durchsuchen klicken --> Datei aussuchen (oder gleich die Datei mit korrektem Pfad einkopieren mit Strg V) --> Klick auf die zu prüfende Datei und öffnen--> klick auf "Senden der Datei"... jetzt abwarten - dann mit der rechten Maustaste den Text markieren -> kopieren ----------------------------- «« Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als cfscript.txt mit 'Speichern unter' auf dem Desktop. Gib an "Alle Dateien" - Speichern Zitat KILLALL::Man sollte jetzt auf dem Desktop diese Datei cfscript.txt finden. cfscript.txt und mit der rechten Maustaste auf das Symbol von Combofix ziehen danach: Combofix noch einmal anwenden ------------------------------------------------------- «« scanne mit malwarebytes , lasse entfernen, was gefunden wird + poste den report http://virus-protect.org/artikel/tools/malwarebytes.html «« lade dialfix, hale alles an, wie beschrieben , scanne + starte den Rechner neu + berichte, ob die windowsupdates wieder funktionieren http://virus-protect.org/artikel/tools/dial_a_fix.html «« poste den report von windowsscan http://virus-protect.org/artikel/tools/windowsscan.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
20.05.2008, 12:14
Member
Themenstarter Beiträge: 31 |
#5
Hallo
Automatische Updates wieder gestartet! - SUPER! - aber scheinbar einige Trojans am System. Den USB-Stick gibt es aber nicht mehr! Log von Malwarebytes: Malwarebytes' Anti-Malware 1.12 Datenbank Version: 768 Scan Art: Schnell Scan Objekte gescannt: 41934 Scan Dauer: 9 minute(s), 27 second(s) Infizierte Speicher Prozesse: 0 Infizierte Speicher Module: 3 Infizierte Registrierungsschlüssel: 11 Infizierte Registrierungswerte: 2 Infizierte Datei Objekte der Registrierung: 2 Infizierte Verzeichnisse: 0 Infizierte Dateien: 8 Infizierte Speicher Prozesse: (Keine Malware Objekte gefunden) Infizierte Speicher Module: C:\WINDOWS\system32\geBrpmkI.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\uoiknjot.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\ssQgeccA.dll (Trojan.Vundo) -> Unloaded module successfully. Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0c885ece-0f0c-49ed-bce3-508f345d070d} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{0c885ece-0f0c-49ed-bce3-508f345d070d} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e707216f-6aff-4bd4-962d-ec5cdba812a1} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e707216f-6aff-4bd4-962d-ec5cdba812a1} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqgecca (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3814c66d (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{e707216f-6aff-4bd4-962d-ec5cdba812a1} (Trojan.Vundo) -> Quarantined and deleted successfully. Infizierte Datei Objekte der Registrierung: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebrpmki -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebrpmki -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine Malware Objekte gefunden) Infizierte Dateien: C:\WINDOWS\system32\geBrpmkI.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\IkmprBeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\IkmprBeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\uoiknjot.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\tojnkiou.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mljjKDVL.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ssQgeccA.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\wvUoLeFu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. Log von dial-a_fix Notes about this log: 1) "->" denotes an external command being executed, and "-> (number)" indicates the return code from the previous command 2) Not all external command return codes are accurate, or useful 3) Sometimes commands return 0 (no error) even when they fail or crash 4) If an error occurs while registering an object, please send an email to: dial-a-fix@DjLizard.net and include a copy of this log DAF version: v0.60.0.24 --- System info --- OS: Microsoft Windows XP Service Pack 2 IE version: 7.0.5730.11 MPC: 55375-644 CPU: AMD Athlon(tm) 64 Processor 3700+ (~2220MHz) CPU: CPU is 64-bit or has 64-bit extensions BIOS: 31.08.2005 Memory (approx): 1023MB Uptime: 1 hour(s) Current directory: C:\Download\Dial-a-fix --- 20.05.2008 11:59:31 -- Dial-a-fix : [v0.60.0.24] -- started 11:59:31 | Policy scan started 11:59:31 | Policy scan ended - no restrictive policies were found --- Windows Update --- --- Registration: Windows Update/Automatic Update DLLs --- 11:59:54 | Unregistered: C:\WINDOWS\system32\msxml.dll 11:59:54 | Registered: C:\WINDOWS\system32\msxml.dll 11:59:54 | Unregistered: C:\WINDOWS\system32\msxml2.dll 11:59:55 | Registered: C:\WINDOWS\system32\msxml2.dll 12:00:10 | Error during unregistration of C:\WINDOWS\system32\msxml3.dll - version: . The error returned is: Unbekannter Fehler (-2147467259) 12:01:53 | Error during registration of C:\WINDOWS\system32\msxml3.dll - version: . The error returned is: Zugriff verweigert (-2147024891) 12:01:54 | Unregistered: C:\WINDOWS\system32\msxml4.dll 12:01:54 | Registered: C:\WINDOWS\system32\msxml4.dll 12:01:54 | Unregistered: C:\WINDOWS\system32\qmgr.dll 12:01:54 | Registered: C:\WINDOWS\system32\qmgr.dll 12:01:54 | Unregistered: C:\WINDOWS\system32\qmgrprxy.dll 12:01:54 | Registered: C:\WINDOWS\system32\qmgrprxy.dll 12:02:18 | Error during unregistration of C:\WINDOWS\system32\muweb.dll - version: . The error returned is: Zugriff verweigert (-2147024891) 12:02:34 | Error during registration of C:\WINDOWS\system32\muweb.dll - version: . The error returned is: Zugriff verweigert (-2147024891) 12:02:34 | Unregistered: C:\WINDOWS\system32\winhttp.dll 12:02:34 | Registered: C:\WINDOWS\system32\winhttp.dll 12:02:35 | Registered: C:\WINDOWS\system32\wuapi.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wuaueng.dll 12:02:35 | Registered: C:\WINDOWS\system32\wuaueng.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wuaueng1.dll 12:02:35 | Registered: C:\WINDOWS\system32\wuaueng1.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wucltui.dll 12:02:35 | Registered: C:\WINDOWS\system32\wucltui.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wups.dll 12:02:35 | Registered: C:\WINDOWS\system32\wups.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wups2.dll 12:02:35 | Registered: C:\WINDOWS\system32\wups2.dll 12:02:35 | Unregistered: C:\WINDOWS\system32\wuweb.dll 12:02:35 | Registered: C:\WINDOWS\system32\wuweb.dll 12:02:35 | Registered: C:\WINDOWS\system32\ole32.dll --- SSL/HTTPS/Cryptography --- 12:02:48 | Executed 'cmd.exe /c rmdir /q /s C:\WINDOWS\system32\Catroot2' --- Registration: SSL/HTTPS/Cryptography --- 12:02:53 | Unregistered: C:\WINDOWS\system32\cryptdlg.dll 12:02:53 | Registered: C:\WINDOWS\system32\cryptdlg.dll 12:02:53 | Unregistered: C:\WINDOWS\system32\cryptui.dll 12:02:53 | Registered: C:\WINDOWS\system32\cryptui.dll 12:02:53 | Unregistered: C:\WINDOWS\system32\cryptext.dll 12:02:53 | Registered: C:\WINDOWS\system32\cryptext.dll 12:02:53 | Unregistered: C:\WINDOWS\system32\dssenh.dll 12:02:53 | Registered: C:\WINDOWS\system32\dssenh.dll 12:02:53 | Unregistered: C:\WINDOWS\system32\gpkcsp.dll 12:02:53 | Registered: C:\WINDOWS\system32\gpkcsp.dll 12:02:54 | Unregistered: C:\WINDOWS\system32\initpki.dll 12:03:43 | Registered: C:\WINDOWS\system32\initpki.dll 12:03:43 | Unregistered: C:\WINDOWS\system32\licdll.dll 12:03:43 | Registered: C:\WINDOWS\system32\licdll.dll 12:03:43 | Unregistered: C:\WINDOWS\system32\mssign32.dll 12:03:43 | Registered: C:\WINDOWS\system32\mssign32.dll 12:03:43 | Unregistered: C:\WINDOWS\system32\mssip32.dll 12:03:44 | Registered: C:\WINDOWS\system32\mssip32.dll 12:03:44 | Unregistered: C:\WINDOWS\system32\scardssp.dll 12:03:44 | Registered: C:\WINDOWS\system32\scardssp.dll 12:03:44 | Unregistered: C:\WINDOWS\system32\sccbase.dll 12:03:44 | Registered: C:\WINDOWS\system32\sccbase.dll 12:03:44 | Unregistered: C:\WINDOWS\system32\scecli.dll 12:03:44 | Registered: C:\WINDOWS\system32\scecli.dll 12:03:44 | Unregistered: C:\WINDOWS\system32\softpub.dll 12:03:44 | Registered: C:\WINDOWS\system32\softpub.dll 12:03:44 | Unregistered: C:\WINDOWS\system32\slbcsp.dll 12:03:45 | Registered: C:\WINDOWS\system32\slbcsp.dll 12:03:45 | Unregistered: C:\WINDOWS\system32\regwizc.dll 12:03:45 | Registered: C:\WINDOWS\system32\regwizc.dll 12:03:45 | Unregistered: C:\WINDOWS\system32\rsaenh.dll 12:03:45 | Registered: C:\WINDOWS\system32\rsaenh.dll 12:03:45 | Unregistered: C:\WINDOWS\system32\winhttp.dll 12:03:45 | Registered: C:\WINDOWS\system32\winhttp.dll 12:03:45 | Unregistered: C:\WINDOWS\system32\wintrust.dll 12:03:45 | Registered: C:\WINDOWS\system32\wintrust.dll --- Registration: Programming cores/runtimes --- 12:03:45 | Registered: C:\WINDOWS\system32\atl.dll 12:03:45 | Registered: C:\WINDOWS\system32\corpol.dll 12:03:45 | Registered: C:\WINDOWS\system32\jscript.dll 12:03:45 | Registered: C:\WINDOWS\system32\dispex.dll 12:03:46 | Registered: C:\WINDOWS\system32\scrrun.dll 12:03:46 | Registered: C:\WINDOWS\system32\scrobj.dll 12:03:46 | Registered: C:\WINDOWS\system32\vbscript.dll 12:03:46 | Registered: C:\WINDOWS\system32\wshext.dll Log von Windowsscan: Die 30 neuesten Dateien im Ordner Windows: ***** ***** ***** ***** ***** ***** Scanning C:\WINDOWS ***** ***** ***** ***** ***** ***** 20.05.2008 WindowsUpdate.log 12 07:105.152 20.05.2008 bitssetup.log 12 07:7.766 20.05.2008 KB950749.log 12 05:19.040 20.05.2008 0.log 10 35:0 20.05.2008 ODBC.INI 10 35:640 SM56 20.05.2008 ModemLog_Motorola 10 35:4.090 20.05.2008 wiadebug.log 10 34:159 20.05.2008 wiaservc.log 10 34:50 20.05.2008 bootstat.dat 10 34:2.048 19.05.2008 NeroDigital.ini 22 06:69 19.05.2008 system.ini 20 01:227 19.05.2008 Deskcalc.INI 17 57:421 19.05.2008 QTFont.for 14 37:1.409 19.05.2008 QTFont.qfn 14 37:54.156 19.05.2008 win.ini 11 16:1.807 10.04.2008 Setup1.exe 21 50:253.952 10.04.2008 ST6UNST.EXE 21 50:74.752 03.04.2008 Iedit_.INI 11 52:30 02.04.2008 MegaManager.INI 17 04:50 20.03.2008 powermp3wavconverter.ini 21 06:401 USB 20.03.2008 ModemLog_Motorola 18 05:2.458 09.03.2008 AUTOLNCH.REG 23 53:1.880 PrecisionScan 09.03.2008 HP 23 46:20 USB 27.02.2008 ModemLog_Motorola 19 28:3.182 USB 27.02.2008 ModemLog_Motorola 18 59:23.568 31.01.2008 HBCIKRNL.INI 11 57:1.204 23.01.2008 cdplayer.ini 19 17:1.427 Die 50 neuesten Dateien im Ordner Windows\system32: ***** ***** ***** ***** ***** ***** Scanning C:\WINDOWS\system32 ***** ***** ***** ***** ***** ***** 20.05.2008 nscompat.tlb 11 58:23.392 20.05.2008 amcompat.tlb 11 58:16.832 20.05.2008 perfh009.dat 10 39:548.270 20.05.2008 perfc009.dat 10 39:121.090 20.05.2008 perfh007.dat 10 39:599.538 20.05.2008 perfc007.dat 10 39:149.198 20.05.2008 PerfStringBackup.INI 10 39:1.435.182 20.05.2008 nvapps.xml 10 34:29.204 20.05.2008 OODBS.lor 10 34:800.020 20.05.2008 uoiknjot.dll 10 30:114.688 19.05.2008 clkcnt.txt 21 10:0 19.05.2008 rjkqgatw.ini 20 16:1.489.608 19.05.2008 tsmktvde.dll 15 56:114.688 19.05.2008 wpa.dbl 00 38:1.202 10.04.2008 FNTCACHE.DAT 03 22:331.480 06.04.2008 MRT.exe 07 56:19.836.024 20.03.2008 win32k.sys 10 03:1.845.376 01.03.2008 mshtml.dll 18 24:3.591.680 01.03.2008 wininet.dll 14 54:826.368 01.03.2008 webcheck.dll 14 54:233.472 01.03.2008 url.dll 14 54:105.984 01.03.2008 pngfilt.dll 14 54:44.544 01.03.2008 urlmon.dll 14 54:1.159.680 01.03.2008 msrating.dll 14 54:193.024 01.03.2008 mstime.dll 14 54:671.232 01.03.2008 occache.dll 14 54:102.912 01.03.2008 mshtmled.dll 14 54:478.208 01.03.2008 msfeedsbs.dll 14 53:52.224 01.03.2008 msfeeds.dll 14 53:459.264 01.03.2008 inetcpl.cpl 14 53:1.831.424 01.03.2008 jsproxy.dll 14 53:27.648 01.03.2008 iernonce.dll 14 53:44.544 01.03.2008 iertutil.dll 14 53:267.776 01.03.2008 ieframe.dll 14 53:6.066.176 01.03.2008 iedkcs32.dll 14 53:384.512 01.03.2008 extmgr.dll 14 53:133.120 01.03.2008 ieaksie.dll 14 53:230.400 01.03.2008 ieakeng.dll 14 53:153.088 01.03.2008 icardie.dll 14 53:63.488 01.03.2008 ieapfltr.dll 14 53:383.488 01.03.2008 dxtrans.dll 14 53:214.528 01.03.2008 dxtmsft.dll 14 53:347.136 01.03.2008 advpack.dll 14 53:124.928 29.02.2008 ie4uinit.exe 10 54:70.656 22.02.2008 ieudinit.exe 12 00:13.824 20.02.2008 gdi32.dll 08 50:282.624 20.02.2008 dnsapi.dll 07 33:148.992 ***** ***** ***** ***** ***** ***** Scanning C:\WINDOWS\system32\drivers\etc\hosts ***** ***** ***** ***** ***** ***** 127.0.0.1 localhost ***** ***** ***** ***** ***** ***** Scanning Processe ***** ***** ***** ***** ***** ***** Abbildname PID Sitzungsname Sitz.-Nr. Speichernutzung ========================= ===== ================ ========== =============== System Idle Process 0 Console 0 28 K System 4 Console 0 248 K smss.exe 1224 Console 0 388 K csrss.exe 1316 Console 0 5.372 K winlogon.exe 1340 Console 0 4.644 K services.exe 1388 Console 0 3.888 K lsass.exe 1400 Console 0 2.596 K svchost.exe 1564 Console 0 5.364 K svchost.exe 1640 Console 0 5.064 K svchost.exe 1784 Console 0 46.328 K svchost.exe 1824 Console 0 3.476 K svchost.exe 1904 Console 0 4.084 K spoolsv.exe 316 Console 0 6.788 K scardsvr.exe 380 Console 0 3.164 K explorer.exe 672 Console 0 56.036 K svchost.exe 724 Console 0 6.028 K ekrn.exe 816 Console 0 30.888 K FolderSizeSvc.exe 840 Console 0 3.036 K svchost.exe 916 Console 0 3.572 K inetinfo.exe 948 Console 0 9.272 K nvsvc32.exe 1040 Console 0 3.764 K outpost.exe 1208 Console 0 55.536 K tcpsvcs.exe 1696 Console 0 3.640 K svchost.exe 2024 Console 0 6.844 K CNYHKey.exe 488 Console 0 15.632 K GoogleDesktop.exe 636 Console 0 6.744 K SOUNDMAN.EXE 508 Console 0 3.200 K Babylon.exe 864 Console 0 27.816 K egui.exe 1220 Console 0 6.672 K fxssvc.exe 1720 Console 0 4.100 K ctfmon.exe 2072 Console 0 3.624 K deskcalc.exe 2160 Console 0 4.472 K Voipwise.exe 2240 Console 0 6.800 K robotaskbaricon.exe 2256 Console 0 15.900 K wmpnetwk.exe 2336 Console 0 8.848 K GoogleDesktop.exe 2548 Console 0 4.400 K alg.exe 3928 Console 0 3.664 K iexplore.exe 1688 Console 0 49.716 K OUTLOOK.EXE 3800 Console 0 160.880 K acrotray.exe 2124 Console 0 5.432 K securitylayer.exe 3768 Console 0 13.764 K cjpcsc.exe 2112 Console 0 8.288 K ONENOTEM.EXE 1916 Console 0 1.432 K ONENOTE.EXE 2916 Console 0 5.940 K Dial-a-fix.exe 1776 Console 0 17.508 K wuauclt.exe 2740 Console 0 15.156 K wuauclt.exe 2416 Console 0 4.568 K cmd.exe 3176 Console 0 2.424 K tasklist.exe 2196 Console 0 4.984 K wmiprvse.exe 3652 Console 0 5.800 K Microsoft Windows XP [Version 5.1.2600] http://www.paules-pc-forum.de ***** Malware Team ***** ***** Ende des Scans 20.05.2008 um 12:10:17,06 *** |
|
|
||
20.05.2008, 12:33
Ehrenmitglied
Beiträge: 29434 |
#6
««
du hast das script für Combofix nicht korrekt angewendet, sonst hätte Malwarebytes ein wenig später nicht die gleichen dll gefunden. Also bitte noch mal die cfscript.txt korrekt erstellen (siehe Anleitung) - auf das Symbol von Combofix ziehen + combofix noch mal anwenden. poste dann nach Ausführung das neue Log von Combofix Zitat KILLALL:: __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
20.05.2008, 18:09
Member
Themenstarter Beiträge: 31 |
#7
jetzt das Log nochmals - entsprechend der Anweisung
ComboFix 08-05-15.3 - Robert 2008-05-20 17:13:08.6 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1031.18.567 [GMT 2:00] ausgeführt von:: C:\Dokumente und Einstellungen\Robert\Desktop\ComboFix.exe Command switches used :: C:\Dokumente und Einstellungen\Robert\Desktop\cfscript.txt * Neuer Wiederherstellungspunkt wurde erstellt * Resident AV is active [color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color] FILE :: C:\DOKUME~1\Robert\LOKALE~1\Temp\UY.exe C:\WINDOWS\system32\geBrpmkI.dll C:\WINDOWS\system32\mljjKDVL.dll C:\WINDOWS\system32\ssQgeccA.dll C:\WINDOWS\system32\tsmktvde.dll C:\WINDOWS\system32\wvUoLeFu.dll . ((((((((((((((((((((((( Dateien erstellt von 2008-04-20 bis 2008-05-20 )))))))))))))))))))))))))))))) . 2008-05-20 13:48 . 2008-05-20 13:48 3 --a------ C:\WINDOWS\system32\EUupdate.installed 2008-05-20 13:46 . 2006-12-04 01:34 1,698,048 --------- C:\WINDOWS\system32\XpsSvcs.dll 2008-05-20 13:46 . 2006-12-04 01:34 1,698,048 -----c--- C:\WINDOWS\system32\dllcache\XpsSvcs.dll 2008-05-20 13:46 . 2006-12-04 01:34 671,744 -----c--- C:\WINDOWS\system32\dllcache\PrintFilterPipelineSvc.exe 2008-05-20 13:46 . 2006-12-04 01:34 580,352 --------- C:\WINDOWS\system32\XPSSHHDR.dll 2008-05-20 13:46 . 2006-12-04 01:34 580,352 -----c--- C:\WINDOWS\system32\dllcache\XPSSHHDR.dll 2008-05-20 13:46 . 2006-12-04 01:34 124,416 --------- C:\WINDOWS\system32\prntvpt.dll 2008-05-20 13:46 . 2006-12-04 01:34 27,648 -----c--- C:\WINDOWS\system32\dllcache\FilterPipelinePrintProc.dll 2008-05-20 13:46 . 2006-12-04 01:34 14,048 --------- C:\WINDOWS\system32\spmsg2.dll 2008-05-20 13:41 . 2006-10-31 12:26 36,864 -----c--- C:\WINDOWS\system32\dllcache\hidclass.sys 2008-05-20 13:38 . 2006-10-23 13:14 143,488 -----c--- C:\WINDOWS\system32\dllcache\usbport.sys 2008-05-20 13:38 . 2006-11-08 10:51 62,336 --------- C:\WINDOWS\system32\drivers\rspndr.sys 2008-05-20 13:38 . 2006-10-23 13:14 59,264 -----c--- C:\WINDOWS\system32\dllcache\usbhub.sys 2008-05-20 13:38 . 2006-10-23 13:14 30,208 -----c--- C:\WINDOWS\system32\dllcache\usbehci.sys 2008-05-20 13:38 . 2006-10-23 13:14 20,608 -----c--- C:\WINDOWS\system32\dllcache\usbuhci.sys 2008-05-20 13:38 . 2006-10-23 13:14 17,152 -----c--- C:\WINDOWS\system32\dllcache\usbohci.sys 2008-05-20 13:38 . 2006-11-08 10:51 10,752 --------- C:\WINDOWS\system32\rspndr.exe 2008-05-20 13:38 . 2008-05-20 13:38 3 --a------ C:\WINDOWS\system32\vbrun60sp6.installed 2008-05-20 13:36 . 2006-08-18 14:38 476,160 -----c--- C:\WINDOWS\system32\dllcache\wzcsvc.dll 2008-05-20 13:36 . 2006-08-18 14:38 52,736 -----c--- C:\WINDOWS\system32\dllcache\wzcsapi.dll 2008-05-20 13:36 . 2006-08-18 11:36 14,592 -----c--- C:\WINDOWS\system32\dllcache\ndisuio.sys 2008-05-20 13:32 . 2008-05-20 13:32 3 --a------ C:\WINDOWS\system32\Wordpad-Converter-ZLib-update.installed 2008-05-20 13:30 . 2008-05-20 13:30 <DIR> d-------- C:\WINDOWS\system32\de 2008-05-20 13:30 . 2006-01-09 15:11 397,312 --------- C:\WINDOWS\system32\mmcex.dll 2008-05-20 13:30 . 2006-01-10 01:10 184,320 --------- C:\WINDOWS\system32\microsoft.managementconsole.dll 2008-05-20 13:30 . 2006-01-10 01:11 106,496 --------- C:\WINDOWS\system32\mmcfxcommon.dll 2008-05-20 13:30 . 2006-01-11 03:20 33,792 --------- C:\WINDOWS\system32\mmcperf.exe 2008-05-20 13:25 . 2005-07-30 02:01 121,856 --------- C:\WINDOWS\system32\drivers\usbvideo.sys 2008-05-20 13:04 . 2008-05-20 13:49 1,374 --a------ C:\WINDOWS\imsins.BAK 2008-05-20 12:07 . 2008-05-20 17:18 <DIR> d-------- C:\WINDOWS\system32\CatRoot2 2008-05-20 10:19 . 2008-05-20 10:19 <DIR> d-------- C:\Programme\Malwarebytes' Anti-Malware 2008-05-20 10:19 . 2008-05-20 10:19 <DIR> d-------- C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Malwarebytes 2008-05-20 10:19 . 2008-05-20 10:19 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2008-05-20 10:19 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-05-20 10:19 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-05-19 21:10 . 2008-05-20 10:30 114,688 --------- C:\WINDOWS\system32\uoiknjot.dll 2008-05-19 19:40 . 2008-05-19 19:40 <DIR> d-------- C:\Programme\CCleaner 2008-05-19 17:35 . 2008-05-19 17:35 <DIR> d-------- C:\Programme\Trend Micro 2008-05-19 14:37 . 2008-05-19 14:37 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-05-19 14:37 . 2008-05-19 14:37 1,409 --a------ C:\WINDOWS\QTFont.for . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-20 14:15 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Babylon 2008-05-20 12:00 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Babylon 2008-05-20 11:06 --------- d-----w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft Help 2008-05-20 09:27 --------- d-----w C:\Programme\ITSolution 2008-05-20 08:28 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Skype 2008-05-19 17:45 --------- d-----w C:\Programme\GetRight 2008-05-19 17:00 --------- d---a-w C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP 2008-05-19 16:09 --------- d-----w C:\Programme\Microsoft Works 2008-05-19 15:53 --------- d-----w C:\Programme\Bytescout Movies Extractor Scout 2008-05-19 12:50 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\AdobeUM 2008-05-19 11:37 --------- d-----w C:\Programme\Gemeinsame Dateien\Adobe 2008-04-10 19:50 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE 2008-04-10 19:50 253,952 ------w C:\WINDOWS\Setup1.exe 2008-04-03 18:19 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Good Keywords v2 2008-04-03 14:14 --------- d-----w C:\Programme\Softnik Technologies 2008-04-02 15:05 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\MegauploadToolbar 2008-04-02 15:02 --------- d-----w C:\Programme\MegauploadToolbar 2008-04-02 15:02 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\Megaupload 2008-04-02 15:01 --------- d--h--w C:\Programme\InstallShield Installation Information 2008-04-02 15:01 --------- d-----w C:\Programme\Megaupload 2008-03-29 17:52 --------- d-----w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\BitTorrent 2008-03-20 15:25 --------- d-----w C:\Programme\ImTOO 2008-03-20 11:01 --------- d-----w C:\Programme\Motorola Phone Tools 2008-03-09 21:53 1,880 ----a-w C:\WINDOWS\AUTOLNCH.REG 2008-01-13 20:38 49,958 ----a-w C:\Dokumente und Einstellungen\Robert\Anwendungsdaten\wklnhst.dat 2007-04-12 20:05 25,600 ----a-w C:\Dokumente und Einstellungen\Robert\usbsermptxp.sys 2007-04-12 20:05 22,768 ----a-w C:\Dokumente und Einstellungen\Robert\usbsermpt.sys 2007-01-08 09:44 774,144 ----a-w C:\Programme\RngInterstitial.dll 2006-04-25 19:39 46 ----a-w C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\wklnhst.dat 2007-04-09 20:09 278,528 ----a-w C:\Programme\internet explorer\plugins\PanoViewer.dll 2007-04-09 20:09 98,304 ----a-w C:\Programme\internet explorer\plugins\UPjpeg.dll 2007-07-01 20:42 23 --sha-w C:\WINDOWS\system32\daed_r.dll . ((((((((((((((((((((((((((((( snapshot_2008-05-20_16.20.02.96 ))))))))))))))))))))))))))))))))))))))))) . - 2008-05-20 14:10:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-20 15:20:03 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-05-20 14:11:15 224,608 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin + 2008-05-20 15:23:01 224,605 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin - 2008-05-20 12:03:45 149,198 ----a-w C:\WINDOWS\system32\perfc007.dat + 2008-05-20 14:16:33 149,198 ----a-w C:\WINDOWS\system32\perfc007.dat - 2008-05-20 12:03:45 121,090 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-05-20 14:16:33 121,090 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-05-20 12:03:45 599,538 ----a-w C:\WINDOWS\system32\perfh007.dat + 2008-05-20 14:16:33 599,538 ----a-w C:\WINDOWS\system32\perfh007.dat - 2008-05-20 12:03:45 548,270 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-05-20 14:16:33 548,270 ----a-w C:\WINDOWS\system32\perfh009.dat . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-07-17 02:00 15360] "DeskCalc"="c:\programme\deskcalc pro\deskcalc.exe" [2006-07-25 19:58 2797568] "Voipwise"="C:\Programme\Voipwise.com\Voipwise\Voipwise.exe" [2007-09-06 11:24 7394608] "RoboForm"="C:\Programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-10-30 14:26 160592] "L07DXLRD_1003640"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ledpointer"="CNYHKey.exe" [2004-03-02 20:24 5576704 C:\WINDOWS\CNYHKey.exe] "Google Desktop Search"="C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-14 09:11 1838592] "SoundMan"="SOUNDMAN.EXE" [2005-06-20 21:42 77824 C:\WINDOWS\SOUNDMAN.EXE] "OSSelectorReinstall"="C:\Programme\Gemeinsame Dateien\Acronis\Acronis Disk Director\oss_reinstall.exe" [2006-04-12 15:15 1261475] "Babylon Client"="C:\Programme\Babylon\Babylon-Pro\Babylon.exe" [2006-12-13 16:15 2785256] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 21:07 7110656] "Outpost Firewall"="C:\Programme\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 16:56 94720] "OutpostFeedBack"="C:\Programme\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 13:18 335872] "egui"="C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-07-17 02:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 0 (0x0) "NoFileAssociate"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli scecli scecli [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^Adobe Acrobat - Schnellstart.lnk] backup=C:\WINDOWS\pss\Adobe Acrobat - Schnellstart.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0] --a------ 2008-04-23 02:08 483328 C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2005-07-20 21:07 7110656 C:\WINDOWS\system32\NvCpl.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Window Washer"=C:\Programme\Webroot\Washer\wwDisp.exe "BitTorrent"="C:\Programme\BitTorrent\bittorrent.exe" --force_start_minimized "updateMgr"=C:\Programme\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_5 -reboot 1 "VoipDiscount"="C:\Programme\VoipDiscount.com\VoipDiscount\VoipDiscount.exe" -nosplash -minimized "Skype"="C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized "WMPNSCFG"=C:\Programme\Windows Media Player\WMPNSCFG.exe "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe" "SecurityLayer"=C:\Programme\trustDesk\SecurityLayer.exe -autostart "Voipwise"="C:\Programme\Voipwise.com\Voipwise\Voipwise.exe" -nosplash -minimized "swg"=C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe "L07DXLRD_848718"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE" -m "L07DXLRD_29388296"="D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE" -m [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "RealTray"=C:\Programme\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER "Acrobat Assistant 7.0"="C:\Programme\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" "Acronis Scheduler2 Service"="C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe" "QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime "SunJavaUpdateSched"=C:\Programme\Java\jre1.5.0_10\bin\jusched.exe "PCMService"="C:\Programme\CyberLink\PowerCinema\PCMService.exe" "Ulead AutoDetector v2"=C:\Programme\Gemeinsame Dateien\Ulead Systems\AutoDetector\monitor.exe "SMSERIAL"=sm56hlpr.exe "RemoteControl"=C:\Programme\CyberLink\PowerDVD\PDVDServ.exe "TkBellExe"="C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot "USBToolTip"="C:\Programme\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" "TrueImageMonitor.exe"=C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe "AcronisTimounterMonitor"=C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe "GrooveMonitor"="C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe" "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup "NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit "PWRISOVM.EXE"=C:\Programme\PowerISO\PWRISOVM.EXE "hpppta"=C:\Programme\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hpppta.exe /ICON "nwiz"=nwiz.exe /install "NVRaidService"=C:\WINDOWS\system32\nvraidservice.exe "HP Update 5370C"=D:\SAFE\Scanner\hpupdate.exe 5370C+ "SecurityLayer"=C:\Programme\trustDesk\securitylayer.exe "NeroFilterCheck"=C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe "InCD"=C:\Programme\Nero\Nero 7\InCD\InCD.exe "Realtime Audio Engine"="mmrtkrnl.exe" /i "CHotkey"=mHotkey.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Programme\\LimeWire\\LimeWire.exe"= "C:\\Programme\\Voipwise.com\\Voipwise\\Voipwise.exe"= "C:\\Programme\\VoipDiscount.com\\VoipDiscount\\voipdiscount.exe"= "C:\\Programme\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R1 bizVSerial;Franson VSerial;C:\WINDOWS\system32\drivers\bizVSerialNT.sys [2007-05-31 08:38] R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52] R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS\system32\drivers\hcw88aud.sys [2005-05-31 12:34] R1 rsct_bus;REINER SCT PC/SC Bus;C:\WINDOWS\system32\DRIVERS\rsct_bus.sys [2004-09-10 17:35] R1 SandBox;Outpost Firewall Sandbox Driver;C:\Programme\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 19:01] R1 VFILT;Outpost Firewall Kernel Driver;C:\Programme\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 16:56] R2 Prvflder;Prvflder;C:\WINDOWS\system32\DRIVERS\prvflder.sys [2006-04-21 09:22] R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 16:57] R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\ARP.DLL [2007-04-05 16:57] R3 cjusb;REINER SCT cyberJack pinpad/e-com USB;C:\WINDOWS\system32\DRIVERS\cjusb.sys [2007-05-31 08:38] R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 16:57] R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 16:57] R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 16:57] R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS\system32\drivers\hcw88bda.sys [2005-05-31 12:34] R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS\system32\drivers\hcw88tse.sys [2005-05-31 15:43] R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS\system32\drivers\hcw88tun.sys [2005-05-31 12:34] R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS\system32\drivers\hcw88vid.sys [2005-05-31 15:43] R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS\system32\drivers\HCW88BAR.sys [2005-05-31 12:34] R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 16:57] R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 16:57] R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 16:57] R3 IMT0521;Inmax USB IMT-0521 Smartcard Reader;C:\WINDOWS\system32\Drivers\IMT0521.sys [2003-07-11 09:50] R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 16:57] R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 16:57] R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 16:57] R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 16:57] R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\Programme\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 16:57] S3 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0-Lizenzierungsdienst;"C:\Programme\ABBYY FineReader 9.0\NetworkLicenseServer.exe" -service [] S3 cjpcsc;cyberJack PC/SC COM Service ;C:\WINDOWS\system32\cjpcsc.exe [2008-01-07 13:19] S3 ITSPrinterService;IT Solution Signature Printer;C:\Programme\trustDesk\plugins\printer\itsprintersrv.exe [2007-04-16 22:06] S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-11-02 15:36] S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-22 20:33] S3 rsct_dev;REINER PC/SC SmartCard Reader Device Driver;C:\WINDOWS\system32\DRIVERS\rsct_dev.sys [2004-09-23 13:12] S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;C:\WINDOWS\system32\DRIVERS\SCR33X2K.sys [2003-12-03 04:22] S3 trustLogon;trustLogon;"C:\Programme\trustDesk\plugins\logon\trustlogon.exe" [2007-01-23 12:35] S3 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2006-07-17 02:00] S3 wwEngineSvc;Window Washer Engine;C:\Programme\Webroot\Washer\WasherSvc.exe [2007-11-26 15:47] S4 MSSQL$PRISO;MSSQL$PRISO;C:\Programme\Priso Datenbank\MSSQL$PRISO\Binn\sqlservr.exe [2002-12-17 17:55] S4 SQLAgent$PRISO;SQLAgent$PRISO;C:\Programme\Priso Datenbank\MSSQL$PRISO\Binn\sqlagent.EXE [2002-12-17 17:23] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f859054-10cc-11da-b357-009027bfa409}] \Shell\AutoRun\command - E:\Autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b57571-157e-11da-acd9-000feaece007}] \Shell\AutoRun\command - M:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada67554-186e-11da-8373-000feaece007}] \Shell\AutoRun\command - L:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b606e90e-3bb6-11da-a3ce-0090d0404b34}] \Shell\AutoRun\command - G:\ie.exe \Shell\explore\Command - G:\ie.exe \Shell\open\Command - G:\ie.exe . Inhalt des "geplante Tasks" Ordners "2008-04-04 17:09:13 C:\WINDOWS\Tasks\1-Klick-Wartung.job" - C:\Programme\TuneUp Utilities 2007\SystemOptimizer.exe "2008-05-18 22:57:48 C:\WINDOWS\Tasks\User_Feed_Synchronization-{4FBD8FD6-1383-42F4-B3B8-6C1FF9715BF1}.job" - C:\WINDOWS\system32\msfeedssync.exe "2008-05-19 15:56:42 C:\WINDOWS\Tasks\XoftSpySE 2.job" - C:\Programme\XoftSpySE\XoftSpy.exe "2008-01-12 02:33:44 C:\WINDOWS\Tasks\XoftSpySE.job" - C:\Programme\XoftSpySE\XoftSpy.exe "2006-10-29 14:03:04 C:\WINDOWS\Tasks\_viceversapr2_task_BackUp.job" - C:\Programme\ViceVersa Pro 2\ViceVersa.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-20 17:20:36 Windows 5.1.2600 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostart Eintr„ge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe -> C:\programme\deskcalc pro\CalcHook.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\scardsvr.exe C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Programme\FolderSize\FolderSizeSvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\tcpsvcs.exe C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\fxssvc.exe C:\Programme\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Zeit der Fertigstellung: 2008-05-20 17:27:56 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-20 15:27:38 ComboFix2.txt 2008-05-20 14:20:41 ComboFix3.txt 2008-05-20 11:06:52 ComboFix4.txt 2008-05-19 18:08:10 25 Verzeichnis(se), 85,961,502,720 Bytes frei 31 Verzeichnis(se), 85,946,097,664 Bytes frei 295 --- E O F --- 2008-05-20 11:06:07 |
|
|
||
21.05.2008, 12:17
Ehrenmitglied
Beiträge: 29434 |
#8
Hallo
1. Virustotal http://www.virustotal.com/flash/index_en.html C:\WINDOWS\system32\uoiknjot.dll C:\WINDOWS\system32\daed_r.dll Auf Durchsuchen klicken --> Datei aussuchen (oder gleich die Datei mit korrektem Pfad einkopieren mit Strg V) --> Klick auf die zu prüfende Datei und öffnen--> klick auf "Senden der Datei"... jetzt abwarten - dann mit der rechten Maustaste den Text markieren -> hier kopieren 2. scanne mit Bitdefender + poste den report http://virus-protect.org/onlinescan.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
21.05.2008, 16:10
Member
Themenstarter Beiträge: 31 |
#9
hier der Report von Bitdefender - da taucht einiges auf...
;*********************************************************************************************************************************************************************************** ANALYSIS: 2008-05-21 16:07:01 PROTECTIONS: 1 MALWARE: 16 SUSPECTS: 0 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== ESET NOD32 Antivirus 3.0 3.0 Yes Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\system32\process.exe 00139535 Application/Processor HackTools No 0 Yes No D:\SAFE\Anti-Virus-Spy-Trojan_Firewall\Remove-Tools\SmitfraudFix\Process.exe 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Dokumente und Einstellungen\Robert\Cookies\robert@tradedoubler[1].txt 00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Dokumente und Einstellungen\Robert\Cookies\robert@statcounter[1].txt 00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Dokumente und Einstellungen\Robert\Cookies\robert@server.iad.liveperson[1].txt 00962932 Generic Malware Virus/Trojan No 0 Yes No D:\SAFE\Anti-Virus-Spy-Trojan_Firewall\AntiSpyware\XSOFTSPY\CRACK\ParetoLogic_Slayer_v1.2.exe 01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Download\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe] 01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Dokumente und Einstellungen\Robert\Desktop\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe] 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{9425ECD7-B6A2-494A-AFA0-780C9EDB461F}\RP78\A0001296.EXE 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{9425ECD7-B6A2-494A-AFA0-780C9EDB461F}\RP79\A0001376.EXE 01298698 Trj/Downloader.OFN Virus/Trojan No 0 No No D:\Limewire\[Full] roboform2go with Bonus.zip[setup.exe][²ÖÇ\setup_rightonadz.exe][■%%\gzmrotate.dll] 01335443 Adware/Zenosearch Adware No 0 No No D:\Limewire\[Full] roboform2go with Bonus.zip[setup.exe][²ÖÇ\TIP2D002.exe] 01893835 Trj/Downloader.MDW Virus/Trojan No 1 No No D:\Limewire\[Full] roboform2go with Bonus.zip[setup.exe][²ÖÇ\setup.exe][²ªÇ] 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No D:\SAFE\Anti-Virus-Spy-Trojan_Firewall\Remove-Tools\SmitfraudFix\Reboot.exe 02255763 Trj/Downloader.OFN Virus/Trojan No 0 No No D:\Limewire\[Full] roboform2go with Bonus.zip[setup.exe][²ÖÇ\setup_rightonadz.exe] 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{9425ECD7-B6A2-494A-AFA0-780C9EDB461F}\RP78\A0001269.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{9425ECD7-B6A2-494A-AFA0-780C9EDB461F}\RP79\A0001352.sys 02908785 Application/PerfectKeyLog.AT HackTools No 0 Yes No C:\Programme\SourceTec\Sothink DHTML Menu 8\Patch.exe 02918924 Trj/Downloader.TJQ Virus/Trojan No 0 Yes No D:\Limewire\ESET.NOD32.v2.70.23.WinNT2K2K3XP.Cracked-FYN.zip[ESET.NOD32.v2.70.23.WinNT2K2K3XP.Cracked-FYN/NOD32.FiX.v2.1.exe] 02918924 Trj/Downloader.TJQ Virus/Trojan No 0 Yes No D:\Limewire\ESET.NOD32.v2.70.23.WinNT2K2K3XP.Cracked-FYN.zip[ESET.NOD32.v2.70.23.WinNT2K2K3XP.Cracked-FYN/NOD32.patch/NOD32view_2.06.2.exe] 02922297 Generic Malware Virus/Trojan No 0 Yes No C:\Programme\ESET\ESET NOD32 Antivirus\nlv3mod.exe ;=================================================================================================================================================================================== SUSPECTS Sent Location ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description ;=================================================================================================================================================================================== 108742 MEDIUM MS06-006 ;=================================================================================================================================================================================== |
|
|
||
21.05.2008, 17:29
Ehrenmitglied
Beiträge: 29434 |
#10
Virustotal http://www.virustotal.com/flash/index_en.html
C:\WINDOWS\system32\uoiknjot.dll C:\WINDOWS\system32\daed_r.dll Auf Durchsuchen klicken --> Datei aussuchen (oder gleich die Datei mit korrektem Pfad einkopieren mit Strg V) --> Klick auf die zu prüfende Datei und öffnen--> klick auf "Senden der Datei"... jetzt abwarten - dann mit der rechten Maustaste den Text markieren -> hier kopieren __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
21.05.2008, 17:48
Member
Themenstarter Beiträge: 31 |
#11
C:\WINDOWS\system32\daed_r.dll = ok
Ergebnis zu: C:\WINDOWS\system32\uoiknjot.dll Antivirus Version letzte aktualisierung Ergebnis AhnLab-V3 2008.5.20.0 2008.05.21 - AntiVir 7.8.0.19 2008.05.21 ADSPY/SecProt.A Authentium 5.1.0.4 2008.05.21 - Avast 4.8.1195.0 2008.05.21 - AVG 7.5.0.516 2008.05.21 - BitDefender 7.2 2008.05.21 - CAT-QuickHeal 9.50 2008.05.21 - ClamAV 0.92.1 2008.05.21 - DrWeb 4.44.0.09170 2008.05.21 - eSafe 7.0.15.0 2008.05.21 - eTrust-Vet 31.4.5808 2008.05.21 - Ewido 4.0 2008.05.21 - F-Prot 4.4.2.54 2008.05.16 - F-Secure 6.70.13260.0 2008.05.21 - Fortinet 3.14.0.0 2008.05.21 - GData 2.0.7306.1023 2008.05.21 - Ikarus T3.1.1.26.0 2008.05.21 - Kaspersky 7.0.0.125 2008.05.21 - McAfee 5299 2008.05.20 - Microsoft 1.3520 2008.05.21 - NOD32v2 3117 2008.05.21 - Norman 5.80.02 2008.05.21 - Panda 9.0.0.4 2008.05.21 - Prevx1 V2 2008.05.21 - Rising 20.45.12.00 2008.05.21 - Sophos 4.29.0 2008.05.21 - Sunbelt 3.0.1123.1 2008.05.17 - Symantec 10 2008.05.21 - TheHacker 6.2.92.314 2008.05.20 - VBA32 3.12.6.6 2008.05.21 - VirusBuster 4.3.26:9 2008.05.21 - Webwasher-Gateway 6.6.2 2008.05.21 Ad-Spyware.SecProt.A |
|
|
||
21.05.2008, 19:39
Ehrenmitglied
Beiträge: 29434 |
||
|
||
23.05.2008, 11:30
Member
Themenstarter Beiträge: 31 |
#13
hier der Report zu C:\WINDOWS\system32\daed_r.dll
Antivirus Version letzte aktualisierung Ergebnis AhnLab-V3 2008.5.22.1 2008.05.23 - AntiVir 7.8.0.19 2008.05.23 - Authentium 5.1.0.4 2008.05.22 - Avast 4.8.1195.0 2008.05.22 - AVG 7.5.0.516 2008.05.23 - BitDefender 7.2 2008.05.23 - CAT-QuickHeal 9.50 2008.05.22 - ClamAV 0.92.1 2008.05.23 - DrWeb 4.44.0.09170 2008.05.23 - eSafe 7.0.15.0 2008.05.22 - eTrust-Vet 31.4.5814 2008.05.22 - Ewido 4.0 2008.05.22 - F-Prot 4.4.2.54 2008.05.16 - F-Secure 6.70.13260.0 2008.05.23 - Fortinet 3.14.0.0 2008.05.23 - GData 2.0.7306.1023 2008.05.23 - Ikarus T3.1.1.26.0 2008.05.23 - Kaspersky 7.0.0.125 2008.05.23 - McAfee 5301 2008.05.22 - Microsoft 1.3520 2008.05.23 - NOD32v2 3125 2008.05.23 - Norman 5.80.02 2008.05.22 - Panda 9.0.0.4 2008.05.22 - Prevx1 V2 2008.05.23 - Rising 20.45.40.00 2008.05.23 - Sophos 4.29.0 2008.05.23 - Sunbelt 3.0.1123.1 2008.05.17 - Symantec 10 2008.05.23 - TheHacker 6.2.92.318 2008.05.23 - VBA32 3.12.6.6 2008.05.22 - VirusBuster 4.3.26:9 2008.05.22 - Webwasher-Gateway 6.6.2 2008.05.23 - |
|
|
||
23.05.2008, 12:07
Ehrenmitglied
Beiträge: 29434 |
#14
««
http://virus-protect.org/artikel/tools/undll.html entzippe undll.zip « Doppeltklick: 'UNDLL'-Icon auf dem Desktop und starte UnDLL « klicke 'Select infected DLL' Button. « In 'Select infected dynamic library' window - kopiere rein (oder suchen) C:\WINDOWS\system32\uoiknjot.dll - dann klicke: Öffnen Dann folge den Anweisungen es wird gefragt, ob neugestartet werden soll - klicke: Yes wenn abgeschlossen - klicke: 'Click here to view log' Das Log erscheint in Textform - kann man finden auf dem Desktop im Ordner von 'undll-........'. Kopiere das Log ab (rechter Mausklick - kopieren - rechter Mausklick im Forum- einfügen) --------- « scanne mit Malwarebytes, lasse alles entfernen, was gefunden wird + poste hier den report http://virus-protect.org/artikel/tools/malwarebytes.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
23.05.2008, 12:16
Member
Themenstarter Beiträge: 31 |
#15
hier das LOg von undll:
05.23.2008 12:11:46 [SysLog]: UnDLL engine 1.0.0.2 initialized 05.23.2008 12:11:46 [SysLog]: OS: 5.1 build 2600 (Service Pack 2) 05.23.2008 12:12:37 [Action]: + Searching for infected threads... 05.23.2008 12:12:48 [Action]: Deleting file [C:\WINDOWS\system32\uoiknjot.dll] - OK 05.23.2008 12:12:50 [Action]: + Searching in AppInit_DLLs... 05.23.2008 12:12:53 [Action]: Writing AppInit_DLLs in the Registry: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL 05.23.2008 12:12:53 [Action]: + Searching in Winlogon Notify... 05.23.2008 12:12:53 [Action]: + Searching in Browser Helper Objects... |
|
|
||
verwende Win XP SP2
Der Dienst "Automatische Updates" lässt sich einfach nicht aktivieren. Erhalte beim Startversuch stets folgenden Fehlercode:
------------
Fehler: 1058: der Dienst kann nicht gestartet werden, da er deaktiviert ist oder mit keinen aktivierten Geräte verbunden.
-----------
Hier das Logfile dazu:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:16:42, on 19.05.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\cjpcsc.exe
C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Programme\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Programme\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Programme\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Programme\trustDesk\plugins\printer\itsprintersrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Programme\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\CNYHKey.exe
C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe
C:\Programme\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Streamload\MediaMax XL\StreamloadService.exe
C:\Programme\trustDesk\plugins\logon\trustlogon.exe
C:\Programme\Webroot\Washer\WasherSvc.exe
C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zinseszins.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zinseszins.net/
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar3.dll
O3 - Toolbar: Encarta Web-Begleiter - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Programme\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programme\MegauploadToolbar\megauploadtoolbar.dll
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programme\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Programme\Gemeinsame Dateien\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [Babylon Client] C:\Programme\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Outpost Firewall] C:\Programme\Agnitum\Outpost Firewall\outpost.exe /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Programme\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [egui] "C:\Programme\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DeskCalc] "c:\programme\deskcalc pro\deskcalc.exe" /hide
O4 - HKCU\..\Run: [Voipwise] "C:\Programme\Voipwise.com\Voipwise\Voipwise.exe" -nosplash -minimized
O4 - HKCU\..\Run: [RoboForm] "C:\Programme\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [L07DXLRD_1003640] "D:\Programme\Microsoft Lernen und Wissen\Microsoft Encarta 2007 – Lernen und Wissen DVD\EDICT.EXE" -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat - Schnellstart.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Link mit Mega Manager herunterladen... - C:\Programme\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: Mit dem LeechGet Wizard laden - file://C:\Programme\LeechGet 2007\\Wizard.html
O8 - Extra context menu item: Mit LeechGet herunterladen - file://C:\Programme\LeechGet 2007\\AddUrl.html
O8 - Extra context menu item: Mit LeechGet parsen - file://C:\Programme\LeechGet 2007\\Parser.html
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: RF - Formular ausfüllen - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RF - Formular speichern - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: RF - Menü anpassen - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: RF - Passwortgenerator - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComPasswordGenerator.html
O8 - Extra context menu item: RF - RoboForm-Leiste ein/aus - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Sothink SWF Catcher - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: Translate with &Babylon - res://C:\Programme\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: RF - Formular ausfüllen - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: RF - Formular speichern - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Programme\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RF - RoboForm-Leiste ein/aus - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Programme\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Encarta Suchleiste - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3911F463-03E8-45A5-B7BE-A89E096ACB79} (ClientCheckX Control) - http://www.a-trust.at/html/ClientCheck/ClientCheckX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124708231312
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {E8304464-1EA9-4F39-A031-522874AAC230} (ESD Object) -
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocx
O16 - DPF: {FCF77DBD-0AE7-4EA8-B9EF-A733F6879B4E} (KardToolX Control) - http://www.a-trust.at/html/CardCheck/KardToolX.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programme\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: ABBYY FineReader 9.0-Lizenzierungsdienst (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Programme\ABBYY FineReader
9.0\NetworkLicenseServer.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: cyberJack PC/SC COM Service (cjpcsc) - REINER SCT - C:\WINDOWS\system32\cjpcsc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programme\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programme\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programme\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Programme\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Programme\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IT Solution Signature Printer (ITSPrinterService) - IT Solution GmbH - C:\Programme\trustDesk\plugins\printer\itsprintersrv.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Programme\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Programme\Microsoft Private Folder 1.0\PrfldSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programme\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: Streamload Service (StreamloadService) - Streamload - C:\Programme\Streamload\MediaMax XL\StreamloadService.exe
O23 - Service: trustLogon - IT Solution GmbH - C:\Programme\trustDesk\plugins\logon\trustlogon.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - Unknown owner - C:\Programme\TuneUp Utilities 2006\WinStylerThemeSvc.exe (file missing)
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Programme\Webroot\Washer\WasherSvc.exe
O24 - Desktop Component 0: My Current Home Page - http://www.8ung.at/zinseszins/images/mitte2.jpg
--
End of file - 15168 bytes